Re: [PATCH v4 2/5] landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
Mickaël Salaün <[email protected]> Fri, 31 Jul 2026 17:14:49 +0200
| Newsgroups | gmane.linux.kernel.lsm |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Jul 31, 2026 at 04:21:14PM +0200, Günther Noack wrote: > On Fri, Jul 31, 2026 at 01:07:57PM +0200, Mickaël Salaün wrote: > > On Fri, Jul 24, 2026 at 06:10:01PM +0200, Günther Noack wrote: > > > + > > > +/** > > > + * DOC: erratum_4 > > > + * > > > + * Erratum 4: Creation of whiteout objects > > > + * ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > > > + * > > > + * This fix addresses an issue through which it was possible to create whiteout > > > + * objects, even when all file creation is restricted using Landlock. > > > + * > > > + * With this fix, the creation of whiteout objects is now guarded using > > > + * ``LANDLOCK_ACCESS_FS_MAKE_REG``, both when it is done through > > > + * :manpage:`renameat2(2)` with `RENAME_WHITEOUT`, and when it is done through > > > + * :manpage:`mknod(2)` with ``S_IFCHR`` and ``makedev(0, 0)`` (which previously > > > + * required ``LANDLOCK_ACCESS_FS_MAKE_CHAR``). > > > + * > > > + * Whiteout objects are special file types used in OverlayFS to mark the absence > > > + * of a file in an upper file system, even when the lower (often read-only) file > > > + * system does have a file with the same name. > > > + * > > > + * Impact: > > > + * > > > + * Without this fix, it was possible to create whiteout files from userspace > > > + * using :manpage:`renameat2(2)` with the ``RENAME_WHITEOUT`` flag. > > > > The errata should focus on the change of access rights which are needed > > (and could potentially break some use cases), not to talk about the > > RENAME_WHITEOUT (bypass) fix. Most fixes don't get a Landlock errata > > bit. The impact should then be explicit that this is for sandboxed > > programs such as fuse-overlayfs. > > > > This patch does two things: > > - fix the RENAME_WHITEOUT creating a whitout without being controlled > > (no errata, just a fix), > > - and repurpose the MAKE_REG to control whitetout creation instead of > > relying on MAKE_CHAR (which needs an errata because it could break > > legitimate use cases/policies). > > FYI, I'm thinking to change the phrasing to this: > > /** > * DOC: erratum_4 > * > * Erratum 4: Creation of whiteout objects > * ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ > * > * This fix changes the access rights required for the creation of whiteout > * objects through :manpage:`mknod(2)` with ``S_IFCHR`` and ``makedev(0, 0)``. Adding renameat2 + RENAME_WHITEOUT would be better too. > * This way of creating whiteout objects is now guarded by > * ``LANDLOCK_ACCESS_FS_MAKE_REG`` instead of ``LANDLOCK_ACCESS_FS_MAKE_CHAR``. > * > * Whiteout objects are used in OverlayFS to mark the absence of a file in an > * upper file system. Despite being created with ``S_IFCHR``, whiteout objects > * do not count as character devices. > * > * Impact: > * > * Sandboxed programs that create OverlayFS whiteouts (such as fuse-overlayfs) > * now require ``LANDLOCK_ACCESS_FS_MAKE_REG`` instead of > * ``LANDLOCK_ACCESS_FS_MAKE_CHAR``. > */ > LANDLOCK_ERRATUM(4) > > Please let me know whether that sounds better. This looks good, thanks!