[RFC PATCH bpf-next 03/12] landlock: convert ancestor walk to vfs_walk_ancestors()

sashiko-bot at kernel.org sashiko-bot at kernel.org
Tue Oct 6 00:27:44 UTC 2026


> Replace the open-coded jump_up/follow_up loop of
> is_access_to_paths_allowed() with one vfs_walk_ancestors() call, moving
> the loop state into a struct passed to the callback.
> 
> follow_up() ignores the mount's disappearance, so a concurrent umount
> could make the walk operate on an unaccounted mount.  The walker steps
> with choose_mountpoint(), which revalidates against mount_lock.  The
> disconnected-directory handling is otherwise preserved: MNT_INTERNAL
> roots allow and stop, other disconnected roots resume at their mount
> root.  Rule evaluation is preserved exactly: disconnected roots that
> were positions of the old loop (the walk's start, the parent of a
> disconnected subtree) keep being matched against rules, while the
> disconnected mountpoints the walker newly visits on a mount crossing
> are skipped via VFS_WALK_POS_MOUNTPOINT, as the old loop never
> consulted them.
> 
> Co-developed-by: Song Liu <song at kernel.org>
> Signed-off-by: Song Liu <song at kernel.org>
> Reported-by: Al Viro <viro at zeniv.linux.org.uk>
> Closes: https://lore.kernel.org/r/20250529231018.GP2023217@ZenIV
> Fixes: cb2c7d1a1776 ("landlock: Support filesystem access-control")
> Signed-off-by: Justin Suess <utilityemal77 at gmail.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261006002020.2890858-1-utilityemal77@gmail.com?part=3




More information about the Linux-security-module-archive mailing list