From d07aad41e323fd36a1504809d1f9b89c0504f76c Mon Sep 17 00:00:00 2001
From: Karel Zak <kzak@redhat.com>
Date: Wed, 27 May 2026 11:12:17 +0200
Subject: [PATCH 07/12] libmount: ignore X-mount.nocanonicalize for restricted
 users

Paths must always be canonicalized in restricted (non-root) mode to
ensure safe target resolution before fd pinning.

Signed-off-by: Karel Zak <kzak@redhat.com>
---
 libmount/src/context.c | 3 +++
 sys-utils/mount.8.adoc | 2 +-
 2 files changed, 4 insertions(+), 1 deletion(-)

Index: util-linux-2.40.4/libmount/src/context.c
===================================================================
--- util-linux-2.40.4.orig/libmount/src/context.c
+++ util-linux-2.40.4/libmount/src/context.c
@@ -1943,6 +1943,9 @@ int mnt_context_prepare_srcpath(struct l
 	if (!path)
 		path = src;
 
+	if (mnt_context_is_restricted(cxt))
+		return 0;
+
 	ol = mnt_context_get_optlist(cxt);
 	if (!ol)
 		return -ENOMEM;
Index: util-linux-2.40.4/sys-utils/mount.8.adoc
===================================================================
--- util-linux-2.40.4.orig/sys-utils/mount.8.adoc
+++ util-linux-2.40.4/sys-utils/mount.8.adoc
@@ -319,7 +319,9 @@ Remount a subtree somewhere else (so tha
 *-c*, *--no-canonicalize*::
 Don't canonicalize paths. The *mount* command canonicalizes all paths (from the command line or _fstab_) by default. This option can be used together with the *-f* flag for already canonicalized absolute paths. The option is designed for mount helpers which call *mount -i*. It is strongly recommended to not use this command-line option for normal mount operations.
 +
-Note that *mount* does not pass this option to the **/sbin/mount.**__type__ helpers.
+Note that *mount* does not pass this option to the **/sbin/mount.**__type__ helpers. 
++
+Note that *mount* ignores this option for unprivileged (non-root) users. Paths are always canonicalized in restricted mode to ensure safe target resolution.
 
 *-F*, *--fork*::
 (Used in conjunction with *-a*.) Fork off a new incarnation of *mount* for each device. This will do the mounts on different devices or different NFS servers in parallel. This has the advantage that it is faster; also NFS timeouts proceed in parallel. A disadvantage is that the order of the mount operations is undefined. Thus, you cannot use this option if you want to mount both _/usr_ and _/usr/spool_.
