[RFC PATCH bpf-next 03/12] landlock: convert ancestor walk to vfs_walk_ancestors()
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Tue Oct 6 00:27:44 UTC 2026
> Replace the open-coded jump_up/follow_up loop of
> is_access_to_paths_allowed() with one vfs_walk_ancestors() call, moving
> the loop state into a struct passed to the callback.
>
> follow_up() ignores the mount's disappearance, so a concurrent umount
> could make the walk operate on an unaccounted mount. The walker steps
> with choose_mountpoint(), which revalidates against mount_lock. The
> disconnected-directory handling is otherwise preserved: MNT_INTERNAL
> roots allow and stop, other disconnected roots resume at their mount
> root. Rule evaluation is preserved exactly: disconnected roots that
> were positions of the old loop (the walk's start, the parent of a
> disconnected subtree) keep being matched against rules, while the
> disconnected mountpoints the walker newly visits on a mount crossing
> are skipped via VFS_WALK_POS_MOUNTPOINT, as the old loop never
> consulted them.
>
> Co-developed-by: Song Liu <song at kernel.org>
> Signed-off-by: Song Liu <song at kernel.org>
> Reported-by: Al Viro <viro at zeniv.linux.org.uk>
> Closes: https://lore.kernel.org/r/20250529231018.GP2023217@ZenIV
> Fixes: cb2c7d1a1776 ("landlock: Support filesystem access-control")
> Signed-off-by: Justin Suess <utilityemal77 at gmail.com>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261006002020.2890858-1-utilityemal77@gmail.com?part=3
More information about the Linux-security-module-archive
mailing list