Skip to content

Archive

Filesystem Security

6 articles
Cybersecurity 19 Sep 2026 6 min read

fscrypt Policies Bind Directory Trees to Filesystem Encryption Keys

A directory can remain fully visible in a mounted Linux filesystem while its regular-file contents and filenames are unusable without a particular key. With fscrypt, that boundary is attached to filesystem objects rather than created by mounting a second encrypted filesystem. An encryption policy assigned to an empty directory is inherited by regular files, directories, and symbolic links created beneath it. The property is narrower than full filesystem secrecy. fscrypt encrypts file contents and filenames, but most filesystem metadata remains visible, and ordinary permission checks continue to define who may access objects once the relevant key is present. Encryption policy and access control are therefore separate boundaries.

Cybersecurity 18 Sep 2026 6 min read

openat2 Makes Path Resolution an Explicit Security Boundary

A privileged service may accept a relative pathname from a less trusted component while intending to access only files below a designated directory. Checking the string for .., rejecting an initial slash, or inspecting symbolic links before a later open() does not bind the check to the kernel lookup that acquires the file. Directory entries can change between operations, symbolic links can redirect traversal, and mount topology can alter the namespace reached by a path.

Cybersecurity 18 Sep 2026 6 min read

Fanotify Permission Events Put File Access Behind a Userspace Decision

A process calls execve() for a binary on a monitored filesystem, but the kernel does not immediately complete the execution open. A fanotify group has requested FAN_OPEN_EXEC_PERM, so the access waits while a userspace listener receives an event and returns FAN_ALLOW or FAN_DENY. The mechanism inserts a synchronous userspace decision into a filesystem operation that would otherwise proceed after ordinary kernel permission checks. That interception point is useful for policy engines that need information outside normal inode permissions, but it creates a distinct enforcement boundary. Availability now depends on a userspace responder, event coverage depends on the selected fanotify marks and event classes, and the mechanism does not convert every form of file use into a mediated operation.

Cybersecurity 17 Sep 2026 6 min read

Landlock Rulesets Add Process-Local Filesystem Denial Boundaries

A service starts with ordinary filesystem access inherited from its credentials, loads configuration, opens several resources, then begins processing data that may be hostile. Changing UID or entering a container can alter the surrounding authority model, but neither action by itself expresses a narrow rule such as “from this point onward, new reads are limited to these hierarchies and writes are limited to that directory.” Linux Landlock provides a process-controlled restriction layer for this boundary. A process creates a ruleset, adds object rules, and enforces the ruleset on itself. The resulting Landlock domain is stacked with existing discretionary access control and other Linux Security Module decisions. Landlock can remove access that those mechanisms would otherwise permit; it does not grant access they deny.

Cybersecurity 17 Sep 2026 7 min read

fs-verity Makes File Data Integrity a Read-Time Property

A host may need to keep independently updated executables, packages, models, or data on a writable filesystem while still detecting modification of file contents after an artifact has been accepted. A one-time userspace hash can identify the bytes at one moment, but it does not make later reads depend on that measurement. The file may be opened again, pages may be evicted and reloaded, and storage below the page cache may return different data.

Cybersecurity 14 Sep 2026 6 min read

Filesystem Races Break the Link Between Checks and Use

A process checks that a path is safe, records a reassuring result, then opens the path a fraction of a second later. Those two operations can look like one security decision in source code. The filesystem sees two separate events, with an interval in which names, links, directories, mounts, or permissions may change. That interval is the basis of time-of-check to time-of-use races. The issue is not limited to unusually slow systems or large timing gaps. When an attacker can influence the relevant namespace concurrently, even a small gap can separate the object that passed a check from the object that receives the privileged operation.