[PATCH v5 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Mickaël Salaün
mic at digikod.net
Fri Jul 31 21:35:14 UTC 2026
On Fri, Jul 31, 2026 at 05:43:50PM +0200, Günther Noack wrote:
> Whiteout objects are used in the upper layer of an OverlayFS to
> indicate that the file with this name does not exist in the unified
> view, even if it is present in one of the lower layer file systems.
>
> For the userspace implementations of OverlayFS (fuse-overlayfs),
> whiteout objects can be created from userspace as well:
>
> * mknod(2) with S_IFCHR and makedev(0, 0)
> * renameat2(2) with RENAME_WHITEOUT,
> creating the whiteout in the old place of the moved file.
>
> This commit guards whiteout creation in both of these cases with
> LANDLOCK_ACCESS_FS_MAKE_REG. Whiteout objects are *not* considered
> character devices and are not bound to a driver.
>
> For the mknod(2) case, introduce a Landlock erratum. The creation of
> whiteout objects through mknod(2) was previously guarded using
> LANDLOCK_ACCESS_FS_MAKE_CHAR, and it is now guarded using
> LANDLOCK_ACCESS_MAKE_REG.
>
> For the renameat2(2) case, fix a bug: Before this commit, renameat2(2)
> with RENAME_WHITEOUT would create a directory entry even when all
> LANDLOCK_ACCESS_FS_MAKE_* rights were denied.
>
> This does not affect normal renames within layered OverlayFS mounts:
> When doing a regular rename() on a mounted fuse-overlayfs, it is the
> fuse-overlayfs daemon that exercises renameat2() with RENAME_WHITEOUT,
> and only the Landlock domain of that daemon is checked there.
>
> Suggested-by: Christian Brauner <brauner at kernel.org>
> Suggested-by: Mickaël Salaün <mic at digikod.net>
> Cc: stable at vger.kernel.org
> Fixes: cb2c7d1a1776 ("landlock: Support filesystem access-control")
> Depends-on: 49c9e09d9610 ("landlock: Fix handling of disconnected directories")
> Depends-on: fe72ce6710cb ("landlock: Add errata documentation section")
> Signed-off-by: Günther Noack <gnoack at google.com>
> ---
> include/uapi/linux/landlock.h | 1 +
> security/landlock/errata/abi-1.h | 23 ++++++++++++++++++
> security/landlock/fs.c | 41 +++++++++++++++++++++++++-------
> 3 files changed, 56 insertions(+), 9 deletions(-)
>
> diff --git a/include/uapi/linux/landlock.h b/include/uapi/linux/landlock.h
> index 7ffe2ef127ee..9c1102ebf06e 100644
> --- a/include/uapi/linux/landlock.h
> +++ b/include/uapi/linux/landlock.h
> @@ -351,6 +351,7 @@ struct landlock_net_port_attr {
> * device.
> * - %LANDLOCK_ACCESS_FS_MAKE_DIR: Create (or rename) a directory.
> * - %LANDLOCK_ACCESS_FS_MAKE_REG: Create (or rename or link) a regular file.
> + * This also guards the creation of whiteout objects as used in OverlayFS.
> * - %LANDLOCK_ACCESS_FS_MAKE_SOCK: Create (or rename or link) a UNIX domain
> * socket.
> * - %LANDLOCK_ACCESS_FS_MAKE_FIFO: Create (or rename or link) a named pipe.
> diff --git a/security/landlock/errata/abi-1.h b/security/landlock/errata/abi-1.h
> index 3f099555f059..e0d543d9d508 100644
> --- a/security/landlock/errata/abi-1.h
> +++ b/security/landlock/errata/abi-1.h
> @@ -22,3 +22,26 @@
> * from their original mount points.
> */
> LANDLOCK_ERRATUM(3)
> +
> +/**
> + * DOC: erratum_4
> + *
> + * Erratum 4: Creation of whiteout objects
> + * ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
> + *
> + * This fix changes the access rights required for the creation of whiteout
> + * objects through :manpage:`mknod(2)` or :manpage:`renameat2(2)`. Creating
> + * whiteout objects is now guarded by ``LANDLOCK_ACCESS_FS_MAKE_REG`` instead of
> + * ``LANDLOCK_ACCESS_FS_MAKE_CHAR``.
> + *
> + * Whiteout objects are used in OverlayFS to mark the absence of a file in an
> + * upper file system. Despite being created with ``S_IFCHR``, whiteout objects
> + * do not count as character devices.
> + *
> + * Impact:
> + *
> + * Sandboxed programs that create OverlayFS whiteouts (such as fuse-overlayfs)
> + * now require ``LANDLOCK_ACCESS_FS_MAKE_REG`` instead of
> + * ``LANDLOCK_ACCESS_FS_MAKE_CHAR``.
> + */
> +LANDLOCK_ERRATUM(4)
> diff --git a/security/landlock/fs.c b/security/landlock/fs.c
> index f7e5e4ef9eac..c12af17cac9e 100644
> --- a/security/landlock/fs.c
> +++ b/security/landlock/fs.c
> @@ -20,6 +20,7 @@
> #include <linux/falloc.h>
> #include <linux/fs.h>
> #include <linux/init.h>
> +#include <linux/kdev_t.h>
> #include <linux/kernel.h>
> #include <linux/limits.h>
> #include <linux/list.h>
> @@ -983,7 +984,8 @@ static int current_check_access_path(const struct path *const path,
> return -EACCES;
> }
>
> -static __attribute_const__ access_mask_t get_mode_access(const umode_t mode)
> +static __attribute_const__ access_mask_t get_mode_access(const umode_t mode,
> + const dev_t dev)
> {
> switch (mode & S_IFMT) {
> case S_IFLNK:
> @@ -991,6 +993,9 @@ static __attribute_const__ access_mask_t get_mode_access(const umode_t mode)
> case S_IFDIR:
> return LANDLOCK_ACCESS_FS_MAKE_DIR;
> case S_IFCHR:
> + /* Whiteout objects are guarded with MAKE_REG. */
> + if (dev == WHITEOUT_DEV)
> + return LANDLOCK_ACCESS_FS_MAKE_REG;
> return LANDLOCK_ACCESS_FS_MAKE_CHAR;
> case S_IFBLK:
> return LANDLOCK_ACCESS_FS_MAKE_BLOCK;
> @@ -1007,6 +1012,13 @@ static __attribute_const__ access_mask_t get_mode_access(const umode_t mode)
> }
> }
>
> +static __attribute_const__ access_mask_t
The __attribute_const__ is incorrect here, you can just drop it.
> +get_dentry_access(const struct dentry *const dentry)
> +{
const struct inode *const inode = d_backing_inode(dentry);
> + return get_mode_access(d_backing_inode(dentry)->i_mode,
> + d_backing_inode(dentry)->i_rdev);
> +}
> +
> static access_mask_t maybe_remove(const struct dentry *const dentry)
> {
> if (d_is_negative(dentry))
More information about the Linux-security-module-archive
mailing list