[RFC PATCH bpf-next 03/12] landlock: convert ancestor walk to vfs_walk_ancestors()

bot+bpf-ci at kernel.org bot+bpf-ci at kernel.org
Tue Oct 6 01:10:52 UTC 2026


> landlock: convert ancestor walk to vfs_walk_ancestors()

TL;DR: Nit only: a comment in landlock's check_access_path_walk() refers to
"the old loop" that no longer exists; it should say why mountpoints reached on
a mount crossing are skipped.

> diff --git a/security/landlock/fs.c b/security/landlock/fs.c
> index cab43892ec2f..369e2e9c83ad 100644
> --- a/security/landlock/fs.c
> +++ b/security/landlock/fs.c

[ ... ]

> @@ -751,6 +751,107 @@ static void test_is_eacces_with_write(struct kunit *const test)
> +static int check_access_path_walk(const struct path *const ancestor,
> +				  const unsigned int pos_flags,
> +				  void *const data)
> +{
> +	struct landlock_walk_state *const state = data;
> +	struct landlock_id id = {
> +		.type = LANDLOCK_KEY_INODE,
> +	};
> +
> +	if (unlikely(pos_flags & VFS_WALK_POS_DISCONNECTED)) {

[ ... ]

> +		/*
> +		 * The old loop never visited the mountpoints a mount
> +		 * crossing lands on: don't match them against rules.  Other
> +		 * disconnected roots keep being matched below, as before.
> +		 */
> +		if (pos_flags & VFS_WALK_POS_MOUNTPOINT)
> +			return VFS_WALK_CONTINUE;
> +	}

This isn't a bug, but could this comment say why mountpoints reached on a
mount crossing are skipped (they are hidden under the mount above them)?

As written it refers to "The old loop" and to "as before", and once this
patch is applied there is no old loop left in the tree for a reader of
check_access_path_walk() to compare against.

The removed code stated the reason directly:

-				/* Ignores hidden mount points. */
-				goto jump_up;

The history of the conversion is already covered by the commit message.


---
AI reviewed your patch. Please fix the bug or email reply why it's not a bug.
See: https://github.com/kernel-patches/vmtest/blob/master/ci/claude/README.md

CI run summary: https://github.com/kernel-patches/bpf/actions/runs/37395354107


More information about the Linux-security-module-archive mailing list