Re: [PATCH] landlock: Move the domain layer counter out of the anonymous union
From: Abel Vesa
Date: Thu Oct 08 2026 - 07:51:29 EST
On 26-10-07 14:49:28, Nick Desaulniers wrote:
> On Wed, Oct 7, 2026 at 9:28 AM Abel Vesa <abel.vesa@xxxxxxxxxxxxxxxx> wrote:
> >
> > With Clang 20 and CONFIG_FORTIFY_SOURCE, stacking Landlock domains can
> > trigger a fortify panic in the handled_masks copy in inherit_ruleset():
> >
> > __fortify_panic
> > landlock_merge_ruleset
> > __arm64_sys_landlock_restrict_self
> >
> > Clang miscalculates the location of the __counted_by counter in the
>
> Thanks for the patch.
>
> Would you consider this a bug in clang, or an error in how the
> __counted_by attribute is applied?
>
> If the former, then a bug report against upstream llvm-project/ and a
> link to that bug report would be appreciated. Then Bill can take a
> look.
>
> Or if this was a known issue specific to clang 20, then we should have
> a link to the fix (or consider bumping counted_by support to the
> compiler version that is bug free).
This is a Clang code generation bug, and it is not limited to Clang 20.
I checked a reduced reproducer with Clang 20.1.2, 21.1.8, 22.1.8 and
23.1.2. All four reproduce it at both -O0 and -O2.
The native x86_64 runtime test returns zero for the dynamic object size
of the zero-initialized array, despite num_layers being set. The AArch64
assembly also shows the count being loaded from offset 40 rather than
num_layers at offset 36. Moving the counter and array out of the union
makes the reproducer pass with all four versions.
It turns out Amaan Qureshi has already reported exactly this Landlock
issue and proposed an LLVM fix:
https://github.com/llvm/llvm-project/pull/228309
Thanks,
Abel