github.com/google/syzkaller@v0.0.0-20251211124644-a066d2bc4b02/sys/linux/test/landlock_sb_delete (about)

     1  # Creates a new mount point.
     2  
     3  mkdirat(0xffffffffffffff9c, &AUTO='./file0\x00', 0x1c0)
     4  mount$tmpfs(0x0, &AUTO='./file0\x00', &AUTO='tmpfs\x00', 0x0, 0x0)
     5  mkdirat(0xffffffffffffff9c, &AUTO='./file0/file0\x00', 0x1c0)
     6  
     7  # Creates a simple directory.
     8  
     9  mkdirat(0xffffffffffffff9c, &AUTO='./file1\x00', 0x1c0)
    10  
    11  # Creates a ruleset with a reference to this mount point.
    12  
    13  r0 = landlock_create_ruleset(&AUTO={0x100, 0x0, 0x0}, AUTO, 0x0)
    14  r1 = openat$dir(0xffffffffffffff9c, &AUTO='./file0\x00', 0x200000, 0x0)
    15  landlock_add_rule$LANDLOCK_RULE_PATH_BENEATH(r0, AUTO, &AUTO={0x100, r1}, 0x0)
    16  
    17  # Add a second inode to cover both iput() calls.
    18  
    19  r2 = openat$dir(0xffffffffffffff9c, &AUTO='./file0/file0\x00', 0x200000, 0x0)
    20  landlock_add_rule$LANDLOCK_RULE_PATH_BENEATH(r0, AUTO, &AUTO={0x100, r2}, 0x0)
    21  
    22  # Removes other references to the mount point.
    23  
    24  close(r2)
    25  close(r1)
    26  umount2(&AUTO='./file0\x00', 0x0)
    27  
    28  # Extends this ruleset with a reference to a simple directory.
    29  
    30  r3 = openat$dir(0xffffffffffffff9c, &AUTO='./file1\x00', 0x200000, 0x0)
    31  landlock_add_rule$LANDLOCK_RULE_PATH_BENEATH(r0, AUTO, &AUTO={0x100, r3}, 0x0)
    32  
    33  # No need to close r3 for this test.
    34  
    35  # Enforces the ruleset tied to a deleted superblock.
    36  
    37  prctl$PR_SET_NO_NEW_PRIVS(0x26, 0x1)
    38  landlock_restrict_self(r0, 0x0)
    39  close(r0)
    40  
    41  # Creates a file: allowed by the ruleset.
    42  
    43  mknodat(0xffffffffffffff9c, &AUTO='./file1/file0\x00', 0x81c0, 0x0)
    44  
    45  # Tries to create a file: denied by the ruleset.
    46  
    47  mknodat(0xffffffffffffff9c, &AUTO='./file2\x00', 0x81c0, 0x0) # EACCES