Re: [PATCH RFC -next 03/12] fs: pass struct path to xattr helpers
From: Cai Xinchen
Date: Mon Sep 28 2026 - 04:56:24 EST
Thank you for review
I will switched to ovl_path_real in the next version.
ovl_creds is a prepare_creds() clone of the mounter, so unless
the mounter itself was sandboxed, the clone carries no Landlock
domain and every check short-circuits. The new rights are also
enforced at the security_inode_*xattr() call sites in fs/xattr.c,
which run with the user-visible overlay path.
The exception is an unprivileged overlay mount by an already
sandboxed mounter: the domain is inherited into
creator_cred through the cred_prepare hook, so the internal
real-path calls *do* get checked there. For this series that
means:
- ovl_xattr_get/set/ovl_listxattr() forwarding and the
ovl_setattr() -> ovl_do_notify_change() forwarding would be
checked against the upper/lower paths;
- copy-up would newly require the metadata rights on the backing
directories too (ovl_copy_xattr() calls the security-checking
vfs_listxattr()/vfs_setxattr());
- stat() is unaffected: ovl_getattr() goes through the _nosec
variant.
This is not Landlock-specific: every LSM
that keeps its state in the cred blob inherits the mounter's
context into creator_cred through cred_prepare.
On 9/24/2026 7:12 PM, Amir Goldstein wrote:
that's ovl_path_real()
I have no technical issue with the ovl patch bits in this series.
Anyway, I guess landlock is not going to enforce anything on the
private mnt with ovl_creds anyway?