summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMickaël Salaün <mic@digikod.net>2026-09-07 12:36:08 +0200
committerMickaël Salaün <mic@digikod.net>2026-09-07 12:38:04 +0200
commite1e60f71f54f2cdff687fc7a6ca3f35ad7b9c75d (patch)
tree450ef3879d970a84ef7c7d3c0c06536f0b28fda7
parente7557b9ef7a87570cbd0873a163de05bde80c39b (diff)
downloadlinux-next-e1e60f71f54f2cdff687fc7a6ca3f35ad7b9c75d.tar.gz
linux-next-e1e60f71f54f2cdff687fc7a6ca3f35ad7b9c75d.zip
landlock: Clean up ruleset validation checks
landlock_merge_ruleset() checks for a NULL ruleset after dereferencing it in lockdep_assert_held(). Move the assertion after the check so the defensive path remains effective. The mask-validation comment originated in landlock_add_fs_access_mask() to explain that its WARN_ON_ONCE() checked a caller invariant. It became self-referential when this helper and its network and scope counterparts were inlined into landlock_create_ruleset(). Restate the invariant without naming the caller. Keep both as defensive callee checks. Moving the assertion preserves the NULL check's ability to warn and return -EINVAL, while invalid masks remain warned about and masked. Reported-by: Günther Noack <gnoack@google.com> Closes: https://patch.msgid.link/aobYhIt3vcs2xN0b@google.com Closes: https://patch.msgid.link/aobasxUDQ8b7GYXl@google.com Link: https://patch.msgid.link/20260907103609.113325-1-mic@digikod.net Signed-off-by: Mickaël Salaün <mic@digikod.net>
-rw-r--r--security/landlock/domain.c3
-rw-r--r--security/landlock/ruleset.c2
2 files changed, 3 insertions, 2 deletions
diff --git a/security/landlock/domain.c b/security/landlock/domain.c
index 93c7104fd6b2..4031b581be07 100644
--- a/security/landlock/domain.c
+++ b/security/landlock/domain.c
@@ -439,10 +439,11 @@ landlock_merge_ruleset(struct landlock_domain *const parent,
int err;
might_sleep();
- lockdep_assert_held(&ruleset->lock);
if (WARN_ON_ONCE(!ruleset))
return ERR_PTR(-EINVAL);
+ lockdep_assert_held(&ruleset->lock);
+
if (parent) {
if (parent->num_layers >= LANDLOCK_MAX_NUM_LAYERS)
return ERR_PTR(-E2BIG);
diff --git a/security/landlock/ruleset.c b/security/landlock/ruleset.c
index 0d07707523cd..a5d135d085cb 100644
--- a/security/landlock/ruleset.c
+++ b/security/landlock/ruleset.c
@@ -58,7 +58,7 @@ landlock_create_ruleset(const access_mask_t fs_access_mask,
new_ruleset->id = landlock_get_id_range(1);
#endif /* CONFIG_TRACEPOINTS */
- /* Should already be checked in landlock_create_ruleset(). */
+ /* The caller must only pass supported access rights and scopes. */
if (fs_access_mask) {
const access_mask_t mask = fs_access_mask &
LANDLOCK_MASK_ACCESS_FS;