[PATCH v1 7/9] selftests/landlock: Test filesystem denial blockers
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Fri Sep 18 18:57:32 UTC 2026
> Filesystem denial traces identify the policy change needed to allow a
> request, so require exact blocker values rather than merely nonempty
> output. Pin a READ_DIR denial to exactly one event with
> blockers=read_dir. Pin a REFER-only mount denial to EPERM and exactly
> one event with blockers=change_topology.
>
> The mount child retains CAP_SYS_ADMIN so Landlock is the only expected
> source of EPERM. This prevents a later capability failure from masking
> a Landlock regression; the trace-collecting parent remains unsandboxed.
>
> Cc: Günther Noack <gnoack at google.com>
> Cc: Steven Rostedt <rostedt at goodmis.org>
> Signed-off-by: Mickaël Salaün <mic at digikod.net>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260918185036.608651-1-mic@digikod.net?part=7
More information about the Linux-security-module-archive
mailing list