Re: [PATCH v4 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Günther Noack <[email protected]> Fri, 31 Jul 2026 16:21:14 +0200
| Newsgroups | gmane.linux.kernel.lsm |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Jul 31, 2026 at 01:07:57PM +0200, Mickaël Salaün wrote: > On Fri, Jul 24, 2026 at 06:10:01PM +0200, Günther Noack wrote: > > + > > +/** > > + * DOC: erratum_4 > > + * > > + * Erratum 4: Creation of whiteout objects > > + * ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > + * > > + * This fix addresses an issue through which it was possible to create whiteout > > + * objects, even when all file creation is restricted using Landlock. > > + * > > + * With this fix, the creation of whiteout objects is now guarded using > > + * ``LANDLOCK_ACCESS_FS_MAKE_REG``, both when it is done through > > + * :manpage:`renameat2(2)` with `RENAME_WHITEOUT`, and when it is done through > > + * :manpage:`mknod(2)` with ``S_IFCHR`` and ``makedev(0, 0)`` (which previously > > + * required ``LANDLOCK_ACCESS_FS_MAKE_CHAR``). > > + * > > + * Whiteout objects are special file types used in OverlayFS to mark the absence > > + * of a file in an upper file system, even when the lower (often read-only) file > > + * system does have a file with the same name. > > + * > > + * Impact: > > + * > > + * Without this fix, it was possible to create whiteout files from userspace > > + * using :manpage:`renameat2(2)` with the ``RENAME_WHITEOUT`` flag. > > The errata should focus on the change of access rights which are needed > (and could potentially break some use cases), not to talk about the > RENAME_WHITEOUT (bypass) fix. Most fixes don't get a Landlock errata > bit. The impact should then be explicit that this is for sandboxed > programs such as fuse-overlayfs. > > This patch does two things: > - fix the RENAME_WHITEOUT creating a whitout without being controlled > (no errata, just a fix), > - and repurpose the MAKE_REG to control whitetout creation instead of > relying on MAKE_CHAR (which needs an errata because it could break > legitimate use cases/policies). FYI, I'm thinking to change the phrasing to this: /** * DOC: erratum_4 * * Erratum 4: Creation of whiteout objects * ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ * * This fix changes the access rights required for the creation of whiteout * objects through :manpage:`mknod(2)` with ``S_IFCHR`` and ``makedev(0, 0)``. * This way of creating whiteout objects is now guarded by * ``LANDLOCK_ACCESS_FS_MAKE_REG`` instead of ``LANDLOCK_ACCESS_FS_MAKE_CHAR``. * * Whiteout objects are used in OverlayFS to mark the absence of a file in an * upper file system. Despite being created with ``S_IFCHR``, whiteout objects * do not count as character devices. * * Impact: * * Sandboxed programs that create OverlayFS whiteouts (such as fuse-overlayfs) * now require ``LANDLOCK_ACCESS_FS_MAKE_REG`` instead of * ``LANDLOCK_ACCESS_FS_MAKE_CHAR``. */ LANDLOCK_ERRATUM(4) Please let me know whether that sounds better. —Günther