From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f177.google.com (mail-yw1-f177.google.com [209.85.128.177]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 21A0D361640 for ; Fri, 29 May 2026 01:52:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.177 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780019550; cv=none; b=QGuNxaPb3I/kZuCPuf0iZNifugR+6TolxlWkLUgOIv+2q7j3wmKVeJfbeax9d630origfkzbZ6RhU/SSiGMnHbjIiitpLcmofI/npj+fqmA+6r446PdQsSWwAAACU7h0B2JHYBjhqlRk7/+QafXUiwlXib9k5Xs40e8vUuYleVQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780019550; c=relaxed/simple; bh=IJxeqyvQtrG7azVvLM4HbRy2GIShu6mc8HVuzDsthyw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=MJE9rNFu/KW5St02CiOSFYQAdTkSXTVZcQPNaZY1LpnmAtJKcen79ISbCGA1iiEw4tOYsI+wG8PNTssgKGtLrFctID7bxOJ8mFX5YYmSMm15K1p6s/K+mjkl1m7dNCp+WFkZbHjuTZQHR97oB/cDGflaWhXkS9P2XuOjMXBCXEs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=gd+4g6up; arc=none smtp.client-ip=209.85.128.177 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="gd+4g6up" Received: by mail-yw1-f177.google.com with SMTP id 00721157ae682-7c58e6eb2c8so136930527b3.1 for ; Thu, 28 May 2026 18:52:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780019546; x=1780624346; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=2kEiKlLtYvS3U2wrQqnl+tM6yv07t9VLzyTDJ7RzJ6w=; b=gd+4g6upVDq4eexNco3Rm2m3FKLk8XuaCqEByPSu+BRX409nb6FrBenv+mXhQ2gO/R gbLEQOHYgYZmCwWpFlnvrwLquUCGqQXllte6vuDebZStD74acD8phUQPl9ZRwSiYCaO5 Im8kTVOIAHaXVQBCU/qKSFcArTmZZIZyxcoBKupfgpPdhKK6ZGQ3/RiWtWfjnAfEa4eD 0tpLemoLoeWKfOjOm3BcMM5/1arJHEZv7NUtwkylHtQzRZQ2u2c6g01z1G/eEMZp7jm0 3k9khnb8zVnzZTVVoLrg/iAbUOlWGCn5mVIDeB6IfSRwHhfZuGoYR3t58YBL6CsfFKzx FqwQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780019546; x=1780624346; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=2kEiKlLtYvS3U2wrQqnl+tM6yv07t9VLzyTDJ7RzJ6w=; b=alUBXmOUr0Z1WF0eiATSP2pCjYQOcncdPF7Y/LfzxgowOUwkeQjRkmLqC97D0+tcfL 93Q18ckKaNLp143pxw2+xk9Z5nn6Yg5lEk44K4NG/e6btKfholg3mupA71fnyS16ZTew KlOTYnxS7A1TrOVBhlbOz9HiHJ9mrNaMvVJlqvfimtpRp0VdHwtLibEcK9ZMK+lDXmcQ v/P602lhedd0I4/S1zQfBgWQHxQCDva4M/ww7HpmjeT6mTfkmPR7y3RGILBup2h5ONqP w/rTYcQJ+eQL1TSOAKhUqA2nW0v+nyl3wwngMJKV/8DTyl5QH589F89evTOGJrXcmE5N lFtA== X-Gm-Message-State: AOJu0YzmFFHex1COR7RFy3G1so+1zUlMoRH6mbl0IyRInhUS20NPh2XB Z6f0g54YQrWLajpY26+x/eo30ocF3DxuKkk/jyiBvmZQ2v+3lR0pHJK5QjRYmQ== X-Gm-Gg: Acq92OF8XeRbanDbHN4LJL/1TNnw6PFzgaj0WoFbRYy61qvw19eX8y7uEJlGGLbg7da Yuv6v3c+536Gw4LcbGuZuU7vUK2x7B7Zq3joRwsEPMQ9OJ9p/pFzM/waYcSFTu0FmDo2RvDimqL /cFa5uMISvdWv+bbhD9EWW+I/CbomdtyLv7muSjR4dqUTVulMR+Jc2JK58wREswJqKbW5H8bGr2 AhNEuC3dLVM91pA9mmDBjLPQHE9lnE/x9tMFkW7CHcE4Ok4+/9LyKvR6FyZGEy5aE2FE+dgSp1Q AHdLDmJxtcYMBZp6WTtm7/VY0ZGL9QrlZr/m5cvYU3mz28S8OdVzS+tB37uvQHgubLMjW406blV 6O3uYmwKUSyklLy2RgJJS/gNR4zZ45DnySrm8wRS15eMlxs/OzoM5RcQlVOtQbb9C40F9hjZtL/ VPGSoLRmHAuCwBzjr6UuicbwdZq3XqHbagl8eHckKtTrYYFX5FbtFS8vCfvsjve3mG4KZO+LtT0 Zo0b5P2nac= X-Received: by 2002:a05:690c:e361:b0:7d3:cf30:efbf with SMTP id 00721157ae682-7de466e551emr6975567b3.17.1780019546080; Thu, 28 May 2026 18:52:26 -0700 (PDT) Received: from zenbox.prizrak.me ([2600:1700:18fb:6011:7a41:d368:8442:1cb2]) by smtp.gmail.com with ESMTPSA id 00721157ae682-7de6d1f3943sm1284717b3.26.2026.05.28.18.52.25 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 28 May 2026 18:52:25 -0700 (PDT) From: Justin Suess To: gnoack3000@gmail.com, mic@digikod.net Cc: linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, Justin Suess Subject: [PATCH v8 02/10] landlock: Use landlock_walk_path_up() in is_access_to_paths_allowed() Date: Thu, 28 May 2026 21:52:01 -0400 Message-ID: <20260529015210.500291-3-utilityemal77@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260529015210.500291-1-utilityemal77@gmail.com> References: <20260529015210.500291-1-utilityemal77@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Replace the open-coded path-walk loop with the new landlock_walk_path_up() helper. This removes the backward goto and keeps the traversal logic in a single place. No functional change intended. Signed-off-by: Justin Suess --- Notes: v7..v8 changes: * Reworded commit message. * Reordered switch arms so the LANDLOCK_WALK_CONTINUE fast path comes first, and moved the per-case explanatory comments inside the case bodies. No functional change. security/landlock/fs.c | 55 ++++++++++++++---------------------------- 1 file changed, 18 insertions(+), 37 deletions(-) diff --git a/security/landlock/fs.c b/security/landlock/fs.c index 8e75583c3ca7..8fb0aa59e180 100644 --- a/security/landlock/fs.c +++ b/security/landlock/fs.c @@ -921,46 +921,27 @@ is_access_to_paths_allowed(const struct landlock_ruleset *const domain, if (allowed_parent1 && allowed_parent2) break; -jump_up: - if (walker_path.dentry == walker_path.mnt->mnt_root) { - if (follow_up(&walker_path)) { - /* Ignores hidden mount points. */ - goto jump_up; - } else { - /* - * Stops at the real root. Denies access - * because not all layers have granted access. - */ - break; - } - } - - if (unlikely(IS_ROOT(walker_path.dentry))) { - if (likely(walker_path.mnt->mnt_flags & MNT_INTERNAL)) { - /* - * Stops and allows access when reaching disconnected root - * directories that are part of internal filesystems (e.g. nsfs, - * which is reachable through /proc//ns/). - */ - allowed_parent1 = true; - allowed_parent2 = true; - break; - } - + switch (landlock_walk_path_up(&walker_path)) { + case LANDLOCK_WALK_CONTINUE: + continue; + case LANDLOCK_WALK_INTERNAL: /* - * We reached a disconnected root directory from a bind mount. - * Let's continue the walk with the mount point we missed. + * Stops and allows access when reaching disconnected + * root directories that are part of internal + * filesystems (e.g. nsfs, which is reachable through + * /proc//ns/). */ - dput(walker_path.dentry); - walker_path.dentry = walker_path.mnt->mnt_root; - dget(walker_path.dentry); - } else { - struct dentry *const parent_dentry = - dget_parent(walker_path.dentry); - - dput(walker_path.dentry); - walker_path.dentry = parent_dentry; + allowed_parent1 = true; + allowed_parent2 = true; + break; + case LANDLOCK_WALK_STOP_REAL_ROOT: + /* + * Stops at the real root. Denies access because not + * all layers have granted access. + */ + break; } + break; } path_put(&walker_path); -- 2.53.0