From 8b6454b84e11937059d8fe7dc63c1d6e38ec7368 Mon Sep 17 00:00:00 2001
From: Karel Zak <kzak@redhat.com>
Date: Wed, 27 May 2026 12:20:06 +0200
Subject: [PATCH 09/12] libmount: restrict X-mount.subdir for non-root

The old-kernel subdirectory path uses namespace unsharing and
string-based move_mount(), which is unsafe for restricted users
(TOCTOU). The safe detached subdirectory open requires Linux >= 6.15
and libmount support, which is not available in v2.41.

Signed-off-by: Karel Zak <kzak@redhat.com>
---
 libmount/src/hook_subdir.c | 6 ++++++
 sys-utils/mount.8.adoc     | 2 ++
 2 files changed, 8 insertions(+)

diff --git a/libmount/src/hook_subdir.c b/libmount/src/hook_subdir.c
index 7cbb2c88d..d085d29ab 100644
--- a/libmount/src/hook_subdir.c
+++ b/libmount/src/hook_subdir.c
@@ -288,6 +288,12 @@ static int hook_mount_pre(
 	if (!hsd)
 		return 0;
 
+	if (mnt_context_target_fd_required(cxt)) {
+		DBG(HOOK, ul_debugobj(hs,
+			"subdir mount refused for non-root user"));
+		return -ENOTSUP;
+	}
+
 	/* create unhared temporary target */
 	hsd->org_target = strdup(mnt_fs_get_target(cxt->fs));
 	if (!hsd->org_target)
diff --git a/sys-utils/mount.8.adoc b/sys-utils/mount.8.adoc
index 4538bcb6b..8876c402f 100644
--- a/sys-utils/mount.8.adoc
+++ b/sys-utils/mount.8.adoc
@@ -770,6 +770,8 @@ For now, this feature is implemented by a temporary filesystem root-directory mo
 +
 Note that this feature will not work in session with an unshared private mount namespace (after *unshare --mount*) on old kernels or with *mount*(8) without support for file-descriptors-based mount kernel API. In this case, you need *unshare --mount --propagation shared*.
 +
+For unprivileged (non-root) users, this feature is currently not supported.
++
 This feature is EXPERIMENTAL.
 
 *X-mount.owner*=_username_|_UID_, *X-mount.group*=_group_|_GID_::
-- 
2.54.0

