BPF List
 help / color / mirror / Atom feed
From: "Mickaël Salaün" <mic@digikod.net>
To: "Günther Noack" <gnoack@google.com>
Cc: "Mickaël Salaün" <mic@digikod.net>,
	"Masami Hiramatsu" <mhiramat@kernel.org>,
	"Mathieu Desnoyers" <mathieu.desnoyers@efficios.com>,
	"Paul Moore" <paul@paul-moore.com>,
	"Steven Rostedt" <rostedt@goodmis.org>,
	bpf@vger.kernel.org, kernel-team@cloudflare.com,
	linux-security-module@vger.kernel.org,
	linux-trace-kernel@vger.kernel.org
Subject: [PATCH v1 7/9] selftests/landlock: Test filesystem denial blockers
Date: Fri, 18 Sep 2026 20:50:30 +0200	[thread overview]
Message-ID: <20260918185036.608651-8-mic@digikod.net> (raw)
In-Reply-To: <20260918185036.608651-1-mic@digikod.net>

Filesystem denial traces identify the policy change needed to allow a
request, so require exact blocker values rather than merely nonempty
output. Pin a READ_DIR denial to exactly one event with
blockers=read_dir. Pin a REFER-only mount denial to EPERM and exactly
one event with blockers=change_topology.

The mount child retains CAP_SYS_ADMIN so Landlock is the only expected
source of EPERM.  This prevents a later capability failure from masking
a Landlock regression; the trace-collecting parent remains unsandboxed.

Cc: Günther Noack <gnoack@google.com>
Cc: Steven Rostedt <rostedt@goodmis.org>
Signed-off-by: Mickaël Salaün <mic@digikod.net>
---
 .../selftests/landlock/trace_fs_test.c        | 76 ++++++++++++++++++-
 1 file changed, 73 insertions(+), 3 deletions(-)

diff --git a/tools/testing/selftests/landlock/trace_fs_test.c b/tools/testing/selftests/landlock/trace_fs_test.c
index 6666d4746cb1..64014ade3a0e 100644
--- a/tools/testing/selftests/landlock/trace_fs_test.c
+++ b/tools/testing/selftests/landlock/trace_fs_test.c
@@ -548,7 +548,8 @@ TEST_F(trace_fs, check_rule_nested)
  */
 TEST_F(trace_fs, deny_access_fs_denied)
 {
-	char *buf;
+	const char *const event_regex = REGEX_DENY_ACCESS_FS(TRACE_TASK);
+	char *buf, blockers[64];
 	int count;
 
 	ASSERT_EQ(0, tracefs_clear_buf());
@@ -564,8 +565,77 @@ TEST_F(trace_fs, deny_access_fs_denied)
 	buf = tracefs_read_buf();
 	ASSERT_NE(NULL, buf);
 
-	count = tracefs_count_matches(buf, REGEX_DENY_ACCESS_FS(TRACE_TASK));
-	EXPECT_LE(1, count);
+	count = tracefs_count_matches(buf, event_regex);
+	EXPECT_EQ(1, count)
+	{
+		TH_LOG("Expected 1 access denial, got %d\n%s", count, buf);
+	}
+	ASSERT_EQ(0, tracefs_extract_field(buf, event_regex, "blockers",
+					   blockers, sizeof(blockers)));
+	EXPECT_STREQ("read_dir", blockers);
+
+	free(buf);
+}
+
+/*
+ * Verifies that a denied mount reports the singleton topology blocker rather
+ * than an empty access mask.
+ */
+TEST_F(trace_fs, deny_change_topology)
+{
+	const char *const event_regex = REGEX_DENY_ACCESS_FS(TRACE_TASK);
+	const struct landlock_ruleset_attr ruleset_attr = {
+		.handled_access_fs = LANDLOCK_ACCESS_FS_REFER,
+	};
+	char *buf, blockers[64];
+	int count, ruleset_fd, status;
+	pid_t pid;
+
+	ruleset_fd =
+		landlock_create_ruleset(&ruleset_attr, sizeof(ruleset_attr), 0);
+	ASSERT_LE(0, ruleset_fd);
+	ASSERT_EQ(0, tracefs_clear_buf());
+
+	/* Ensure that Landlock is the only expected mount denial. */
+	set_cap(_metadata, CAP_SYS_ADMIN);
+	pid = fork();
+	ASSERT_LE(0, pid);
+	if (pid == 0) {
+		if (prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0)) {
+			close(ruleset_fd);
+			_exit(1);
+		}
+		if (landlock_restrict_self(ruleset_fd, 0)) {
+			close(ruleset_fd);
+			_exit(2);
+		}
+		close(ruleset_fd);
+
+		if (mount(NULL, "/", NULL, MS_PRIVATE | MS_REC, NULL) != -1)
+			_exit(3);
+
+		if (errno != EPERM)
+			_exit(4);
+
+		_exit(0);
+	}
+	close(ruleset_fd);
+	clear_cap(_metadata, CAP_SYS_ADMIN);
+
+	ASSERT_EQ(pid, waitpid(pid, &status, 0));
+	ASSERT_TRUE(WIFEXITED(status));
+	EXPECT_EQ(0, WEXITSTATUS(status));
+
+	buf = tracefs_read_buf();
+	ASSERT_NE(NULL, buf);
+	count = tracefs_count_matches(buf, event_regex);
+	EXPECT_EQ(1, count)
+	{
+		TH_LOG("Expected 1 topology denial, got %d\n%s", count, buf);
+	}
+	ASSERT_EQ(0, tracefs_extract_field(buf, event_regex, "blockers",
+					   blockers, sizeof(blockers)));
+	EXPECT_STREQ("change_topology", blockers);
 
 	free(buf);
 }
-- 
2.55.0


  parent reply	other threads:[~2026-09-18 18:51 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-18 18:50 [PATCH v1 0/9] landlock: Fix tracepoint policy context Mickaël Salaün
2026-09-18 18:50 ` [PATCH v1 1/9] landlock: Fix tracepoint fixed-width type names Mickaël Salaün
2026-09-18 18:54   ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 2/9] landlock: Fix filesystem denial blocker reporting Mickaël Salaün
2026-09-18 18:57   ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 3/9] landlock: Fix rule tracepoint context Mickaël Salaün
2026-09-18 19:00   ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 4/9] landlock: Fix network denial trace context Mickaël Salaün
2026-09-18 18:57   ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 5/9] landlock: Report the actual ptrace tracer Mickaël Salaün
2026-09-18 18:56   ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 6/9] landlock: Report the effective signal number Mickaël Salaün
2026-09-18 18:57   ` sashiko-bot
2026-09-18 18:50 ` Mickaël Salaün [this message]
2026-09-18 18:57   ` [PATCH v1 7/9] selftests/landlock: Test filesystem denial blockers sashiko-bot
2026-09-18 18:50 ` [PATCH v1 8/9] selftests/landlock: Test network denial context Mickaël Salaün
2026-09-18 18:58   ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 9/9] landlock: Fix tracepoint contract documentation Mickaël Salaün
2026-09-18 19:02   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260918185036.608651-8-mic@digikod.net \
    --to=mic@digikod.net \
    --cc=bpf@vger.kernel.org \
    --cc=gnoack@google.com \
    --cc=kernel-team@cloudflare.com \
    --cc=linux-security-module@vger.kernel.org \
    --cc=linux-trace-kernel@vger.kernel.org \
    --cc=mathieu.desnoyers@efficios.com \
    --cc=mhiramat@kernel.org \
    --cc=paul@paul-moore.com \
    --cc=rostedt@goodmis.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox