[PATCH v5 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation

Mickaël Salaün mic at digikod.net
Fri Jul 31 21:35:14 UTC 2026


On Fri, Jul 31, 2026 at 05:43:50PM +0200, Günther Noack wrote:
> Whiteout objects are used in the upper layer of an OverlayFS to
> indicate that the file with this name does not exist in the unified
> view, even if it is present in one of the lower layer file systems.
> 
> For the userspace implementations of OverlayFS (fuse-overlayfs),
> whiteout objects can be created from userspace as well:
> 
> * mknod(2) with S_IFCHR and makedev(0, 0)
> * renameat2(2) with RENAME_WHITEOUT,
>   creating the whiteout in the old place of the moved file.
> 
> This commit guards whiteout creation in both of these cases with
> LANDLOCK_ACCESS_FS_MAKE_REG.  Whiteout objects are *not* considered
> character devices and are not bound to a driver.
> 
> For the mknod(2) case, introduce a Landlock erratum.  The creation of
> whiteout objects through mknod(2) was previously guarded using
> LANDLOCK_ACCESS_FS_MAKE_CHAR, and it is now guarded using
> LANDLOCK_ACCESS_MAKE_REG.
> 
> For the renameat2(2) case, fix a bug: Before this commit, renameat2(2)
> with RENAME_WHITEOUT would create a directory entry even when all
> LANDLOCK_ACCESS_FS_MAKE_* rights were denied.
> 
> This does not affect normal renames within layered OverlayFS mounts:
> When doing a regular rename() on a mounted fuse-overlayfs, it is the
> fuse-overlayfs daemon that exercises renameat2() with RENAME_WHITEOUT,
> and only the Landlock domain of that daemon is checked there.
> 
> Suggested-by: Christian Brauner <brauner at kernel.org>
> Suggested-by: Mickaël Salaün <mic at digikod.net>
> Cc: stable at vger.kernel.org
> Fixes: cb2c7d1a1776 ("landlock: Support filesystem access-control")
> Depends-on: 49c9e09d9610 ("landlock: Fix handling of disconnected directories")
> Depends-on: fe72ce6710cb ("landlock: Add errata documentation section")
> Signed-off-by: Günther Noack <gnoack at google.com>
> ---
>  include/uapi/linux/landlock.h    |  1 +
>  security/landlock/errata/abi-1.h | 23 ++++++++++++++++++
>  security/landlock/fs.c           | 41 +++++++++++++++++++++++++-------
>  3 files changed, 56 insertions(+), 9 deletions(-)
> 
> diff --git a/include/uapi/linux/landlock.h b/include/uapi/linux/landlock.h
> index 7ffe2ef127ee..9c1102ebf06e 100644
> --- a/include/uapi/linux/landlock.h
> +++ b/include/uapi/linux/landlock.h
> @@ -351,6 +351,7 @@ struct landlock_net_port_attr {
>   *   device.
>   * - %LANDLOCK_ACCESS_FS_MAKE_DIR: Create (or rename) a directory.
>   * - %LANDLOCK_ACCESS_FS_MAKE_REG: Create (or rename or link) a regular file.
> + *   This also guards the creation of whiteout objects as used in OverlayFS.
>   * - %LANDLOCK_ACCESS_FS_MAKE_SOCK: Create (or rename or link) a UNIX domain
>   *   socket.
>   * - %LANDLOCK_ACCESS_FS_MAKE_FIFO: Create (or rename or link) a named pipe.
> diff --git a/security/landlock/errata/abi-1.h b/security/landlock/errata/abi-1.h
> index 3f099555f059..e0d543d9d508 100644
> --- a/security/landlock/errata/abi-1.h
> +++ b/security/landlock/errata/abi-1.h
> @@ -22,3 +22,26 @@
>   * from their original mount points.
>   */
>  LANDLOCK_ERRATUM(3)
> +
> +/**
> + * DOC: erratum_4
> + *
> + * Erratum 4: Creation of whiteout objects
> + * ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> + *
> + * This fix changes the access rights required for the creation of whiteout
> + * objects through :manpage:`mknod(2)` or :manpage:`renameat2(2)`.  Creating
> + * whiteout objects is now guarded by ``LANDLOCK_ACCESS_FS_MAKE_REG`` instead of
> + * ``LANDLOCK_ACCESS_FS_MAKE_CHAR``.
> + *
> + * Whiteout objects are used in OverlayFS to mark the absence of a file in an
> + * upper file system.  Despite being created with ``S_IFCHR``, whiteout objects
> + * do not count as character devices.
> + *
> + * Impact:
> + *
> + * Sandboxed programs that create OverlayFS whiteouts (such as fuse-overlayfs)
> + * now require ``LANDLOCK_ACCESS_FS_MAKE_REG`` instead of
> + * ``LANDLOCK_ACCESS_FS_MAKE_CHAR``.
> + */
> +LANDLOCK_ERRATUM(4)
> diff --git a/security/landlock/fs.c b/security/landlock/fs.c
> index f7e5e4ef9eac..c12af17cac9e 100644
> --- a/security/landlock/fs.c
> +++ b/security/landlock/fs.c
> @@ -20,6 +20,7 @@
>  #include <linux/falloc.h>
>  #include <linux/fs.h>
>  #include <linux/init.h>
> +#include <linux/kdev_t.h>
>  #include <linux/kernel.h>
>  #include <linux/limits.h>
>  #include <linux/list.h>
> @@ -983,7 +984,8 @@ static int current_check_access_path(const struct path *const path,
>  	return -EACCES;
>  }
>  
> -static __attribute_const__ access_mask_t get_mode_access(const umode_t mode)
> +static __attribute_const__ access_mask_t get_mode_access(const umode_t mode,
> +							 const dev_t dev)
>  {
>  	switch (mode & S_IFMT) {
>  	case S_IFLNK:
> @@ -991,6 +993,9 @@ static __attribute_const__ access_mask_t get_mode_access(const umode_t mode)
>  	case S_IFDIR:
>  		return LANDLOCK_ACCESS_FS_MAKE_DIR;
>  	case S_IFCHR:
> +		/* Whiteout objects are guarded with MAKE_REG. */
> +		if (dev == WHITEOUT_DEV)
> +			return LANDLOCK_ACCESS_FS_MAKE_REG;
>  		return LANDLOCK_ACCESS_FS_MAKE_CHAR;
>  	case S_IFBLK:
>  		return LANDLOCK_ACCESS_FS_MAKE_BLOCK;
> @@ -1007,6 +1012,13 @@ static __attribute_const__ access_mask_t get_mode_access(const umode_t mode)
>  	}
>  }
>  
> +static __attribute_const__ access_mask_t

The __attribute_const__ is incorrect here, you can just drop it.

> +get_dentry_access(const struct dentry *const dentry)
> +{

const struct inode *const inode = d_backing_inode(dentry);

> +	return get_mode_access(d_backing_inode(dentry)->i_mode,
> +			       d_backing_inode(dentry)->i_rdev);
> +}
> +
>  static access_mask_t maybe_remove(const struct dentry *const dentry)
>  {
>  	if (d_is_negative(dentry))



More information about the Linux-security-module-archive mailing list