[PATCH v1 7/9] selftests/landlock: Test filesystem denial blockers

sashiko-bot at kernel.org sashiko-bot at kernel.org
Fri Sep 18 18:57:32 UTC 2026


> Filesystem denial traces identify the policy change needed to allow a
> request, so require exact blocker values rather than merely nonempty
> output. Pin a READ_DIR denial to exactly one event with
> blockers=read_dir. Pin a REFER-only mount denial to EPERM and exactly
> one event with blockers=change_topology.
> 
> The mount child retains CAP_SYS_ADMIN so Landlock is the only expected
> source of EPERM.  This prevents a later capability failure from masking
> a Landlock regression; the trace-collecting parent remains unsandboxed.
> 
> Cc: Günther Noack <gnoack at google.com>
> Cc: Steven Rostedt <rostedt at goodmis.org>
> Signed-off-by: Mickaël Salaün <mic at digikod.net>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260918185036.608651-1-mic@digikod.net?part=7




More information about the Linux-security-module-archive mailing list