Thank you for review

I will switched to ovl_path_real in the next version.

ovl_creds is a prepare_creds() clone of the mounter, so unless
the mounter itself was sandboxed, the clone carries no Landlock
domain and every check short-circuits. The new rights are also
enforced at the security_inode_*xattr() call sites in fs/xattr.c,
which run with the user-visible overlay path.

The exception is an unprivileged overlay mount by an already
sandboxed mounter: the domain is inherited into
creator_cred through the cred_prepare hook, so the internal
real-path calls *do* get checked there.  For this series that
means:

- ovl_xattr_get/set/ovl_listxattr() forwarding and the
  ovl_setattr() -> ovl_do_notify_change() forwarding would be
  checked against the upper/lower paths;
- copy-up would newly require the metadata rights on the backing
  directories too (ovl_copy_xattr() calls the security-checking
  vfs_listxattr()/vfs_setxattr());
- stat() is unaffected: ovl_getattr() goes through the _nosec
  variant.

This is not Landlock-specific: every LSM
that keeps its state in the cred blob inherits the mounter's
context into creator_cred through cred_prepare.

On 9/24/2026 7:12 PM, Amir Goldstein wrote:
that's ovl_path_real()

I have no technical issue with the ovl patch bits in this series.
Anyway, I guess landlock is not going to enforce anything on the
private mnt with ovl_creds anyway?

Reply via email to