Re: [PATCH] man/man2/link.2: Document new AT_EMPTY_PATH behavior

Alejandro Colomar <[email protected]> Thu, 16 Jul 2026 13:34:02 +0200
Newsgroups org.kernel.vger.linux-man
Message-ID <ali_j2Z8ASVyNThE@devuan>
[CC += the people involved in the linux.git patch]

Hi Runxi,

On 2026-07-16T09:05:36+0000, Runxi Yu wrote:
> From: Runxi Yu <[email protected]>
> 
> Signed-off-by: Runxi Yu <[email protected]>
> ---
> I'm not on the list, so please place my address in the SMTP envelope
> recipient.

Ack.

>  man/man2/link.2 | 32 +++++++++++++++++++++++++++-----
>  1 file changed, 27 insertions(+), 5 deletions(-)
> 
> diff --git a/man/man2/link.2 b/man/man2/link.2
> index effed3f74..a888da919 100644
> --- a/man/man2/link.2
> +++ b/man/man2/link.2
> @@ -115,9 +115,30 @@ created with
>  and without
>  .B O_EXCL
>  are an exception).
> -The caller must have the
> +.\" commit 42bd2af5950456d46fdaa91c3a8fb02e680f19f5
> +Since Linux 6.10,
> +no privilege is required to use this flag if the credentials under which
> +.I olddirfd
> +was opened match the caller's current credentials

The commit message says this is not enough.  The credentials must not
have changed since olddirfd was opened.  Restoring credentials wouldn't
work.

Here's what the commit message says:

    Note that the credential equality check is done by using pointer
    equality, which means that it's not enough that you have effectively the
    same user - they have to be literally identical, since our credentials
    are using copy-on-write semantics.

> +(as is normally the case when the caller opened
> +.I olddirfd
> +itself and has not since altered its credentials).

This is not the normal case where it happens, but actually the only case
that is allowed.

> +Otherwise
> +(for example, when
> +.I olddirfd
> +was received from another process,
> +or the caller's credentials have changed since
> +.I olddirfd
> +was opened),
> +the caller must have the
>  .B CAP_DAC_READ_SEARCH
> -capability in order to use this flag.
> +capability in the user namespace of the credentials under which

I feel this reads a bit weird.  Would it be better to remove
'of the credentials' in the line above?  Or should it stay?

> +.I olddirfd
> +was opened.
> +Before Linux 6.10,
> +the
> +.B CAP_DAC_READ_SEARCH
> +capability was required in all cases.

I think we can move this to HISTORY.

>  This flag is Linux-specific;
>  define
>  .B _GNU_SOURCE
> @@ -281,9 +302,10 @@ An invalid flag value was specified in
>  .B AT_EMPTY_PATH
>  was specified in
>  .IR flags ,
> -but the caller did not have the
> -.B CAP_DAC_READ_SEARCH
> -capability.
> +but the caller lacked the privilege required to create the link;
> +see the description of
> +.B AT_EMPTY_PATH
> +above.

Let's remove the last three lines.  This is of course implied when
talking about AT_EMPTY_PATH.


Have a lovely day!
Alex

>  .TP
>  .B ENOENT
>  An attempt was made to link to the
> -- 
> 2.55.0
> 
> 

-- 
<https://www.alejandro-colomar.es>
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEES7Jt9u9GbmlWADAi64mZXMKQwqkFAmpYwaQACgkQ64mZXMKQ
wqmGEg/+PFW1kDtAgReWSTfEturIG0WmqihGNrwYrDEy2EqM7Bt4PClP/g6lWtTU
jK/6wNzwklfAYGvpgBOG8ZrUBrYLbLT15gIsJ0EfLGg0o3tz1P5RFp6i5FYMdTf6
vyy3bK3bLMPc2hXq5H8ft7gKCFvuRy0r4z8WTx33/EKg89cJ/tEnYoajV/RFzbFN
nikpPFm1F48tts83nh7BtRmACX3Qe4QWJ119ZVXr5HcPR96dATlVJLmJHq5Nl7Et
/O8da2ZlhWOaf/SdbR3WwDLKjEY8KFQ10wi3Y3mkjZOwGGDz/IfaMGKBKQRiMw27
1aPV510Ryo971Azn/V3VJMXt6eLBjxC8c1QQ04pKujU0kjUIdtAh1ESBchFvpgZy
Hz1aLAKQXeZMKRF4p5Eg0jmxE6GrVdFEghOSqJEh1uvGQH0hrajMTz6y++yEDZxA
9Th2+zszXYA6w/QclOMIJQuceFau+AXQ7r68ZxPxgEiBqvLsN35AqAcb9d24GxHV
6pSqwJt9HuAb0K6VIrB4NQOpiiSJqwMVjw+ut1FZq+mlaY15hsK0QM+4Rpn8yHNP
7lpt5SCzwPrZX/sDzSfGPUBxiBXlbnQpIyv4ZaMkcp1E6pHrc0i1R5nKi4OWm9cS
ruwvRkALFassUmpgSZ1UyMqlTViogyraFAEI2G4Gy+K3V0yn5WU=
=RhGp
-----END PGP SIGNATURE-----