[PATCH v4 1/8] landlock: Rename quiet_masks to quiet_access

Mickaël Salaün mic at digikod.net
Fri Oct 2 12:43:54 UTC 2026


The base stores the fs/net/scope quiet bitmasks in a struct access_masks
field named quiet_masks.  A following commit adds the sibling struct
permission_masks field quiet_permission for capabilities and namespaces.
quiet_masks drops the access category and keeps the type half ("masks"),
while quiet_permission keeps the category and drops the type half, so
the two read as an inconsistent pair.

Rename the base field to quiet_access, giving the symmetric,
category-named pair quiet_access/quiet_permission that also matches the
UAPI handled_access_*/quiet_access_* naming.  This is a
no-functional-change rename.

Cc: Günther Noack <gnoack at google.com>
Cc: Tingmao Wang <m at maowtm.org>
Reviewed-by: Tingmao Wang <m at maowtm.org>
Signed-off-by: Mickaël Salaün <mic at digikod.net>
---

Changes since v3:
https://patch.msgid.link/20260726161400.3010511-5-mic@digikod.net
- Adapt the rename to the split ruleset/domain and logging code.
- Add Reviewed-by: Tingmao Wang.

Changes since v2:
- New patch.
---
 security/landlock/domain.c   |  2 +-
 security/landlock/domain.h   |  4 ++--
 security/landlock/log.c      |  6 +++---
 security/landlock/ruleset.h  |  4 ++--
 security/landlock/syscalls.c | 10 +++++-----
 5 files changed, 13 insertions(+), 13 deletions(-)

diff --git a/security/landlock/domain.c b/security/landlock/domain.c
index 4031b581be07..c66663f8cd8b 100644
--- a/security/landlock/domain.c
+++ b/security/landlock/domain.c
@@ -479,7 +479,7 @@ landlock_merge_ruleset(struct landlock_domain *const parent,
 		return ERR_PTR(err);
 
 #ifdef CONFIG_SECURITY_LANDLOCK_LOG
-	new_dom->hierarchy->quiet_masks = ruleset->quiet_masks;
+	new_dom->hierarchy->quiet_access = ruleset->quiet_access;
 #endif /* CONFIG_SECURITY_LANDLOCK_LOG */
 
 	return no_free_ptr(new_dom);
diff --git a/security/landlock/domain.h b/security/landlock/domain.h
index caa3d19d2c43..03f24382537c 100644
--- a/security/landlock/domain.h
+++ b/security/landlock/domain.h
@@ -130,10 +130,10 @@ struct landlock_hierarchy {
 		 */
 		log_new_exec : 1;
 	/**
-	 * @quiet_masks: Bitmasks of access that should be quieted (i.e. not
+	 * @quiet_access: Bitmasks of access that should be quieted (i.e. not
 	 * logged) if the related object is marked as quiet.
 	 */
-	struct access_masks quiet_masks;
+	struct access_masks quiet_access;
 #endif /* CONFIG_SECURITY_LANDLOCK_LOG */
 };
 
diff --git a/security/landlock/log.c b/security/landlock/log.c
index a8578a6f2ce9..3f9ae1bacb23 100644
--- a/security/landlock/log.c
+++ b/security/landlock/log.c
@@ -436,7 +436,7 @@ is_denial_quieted(const struct landlock_request *const request,
 	if (object_quiet_flag) {
 		const access_mask_t quiet_mask =
 			pick_access_mask_for_request_type(
-				request->type, youngest_denied->quiet_masks);
+				request->type, youngest_denied->quiet_access);
 
 		return (quiet_mask & missing) == missing;
 	}
@@ -447,10 +447,10 @@ is_denial_quieted(const struct landlock_request *const request,
 	 */
 	switch (request->type) {
 	case LANDLOCK_REQUEST_SCOPE_SIGNAL:
-		return !!(youngest_denied->quiet_masks.scope &
+		return !!(youngest_denied->quiet_access.scope &
 			  LANDLOCK_SCOPE_SIGNAL);
 	case LANDLOCK_REQUEST_SCOPE_ABSTRACT_UNIX_SOCKET:
-		return !!(youngest_denied->quiet_masks.scope &
+		return !!(youngest_denied->quiet_access.scope &
 			  LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET);
 	/*
 	 * Leave LANDLOCK_REQUEST_PTRACE and LANDLOCK_REQUEST_FS_CHANGE_TOPOLOGY
diff --git a/security/landlock/ruleset.h b/security/landlock/ruleset.h
index cf77f1806a95..8ebdd4fa098f 100644
--- a/security/landlock/ruleset.h
+++ b/security/landlock/ruleset.h
@@ -182,11 +182,11 @@ struct landlock_ruleset {
 #endif /* CONFIG_TRACEPOINTS */
 
 	/**
-	 * @quiet_masks: Stores the quiet flags for an unmerged ruleset.  For a
+	 * @quiet_access: Stores the quiet flags for an unmerged ruleset.  For a
 	 * merged domain, this is stored in each layer's struct
 	 * landlock_hierarchy instead.
 	 */
-	struct access_masks quiet_masks;
+	struct access_masks quiet_access;
 	/**
 	 * @handled_masks: Contains the subset of filesystem and network actions
 	 * that are handled by this ruleset.
diff --git a/security/landlock/syscalls.c b/security/landlock/syscalls.c
index 1d02d57f4c48..17d8e9b7b0c6 100644
--- a/security/landlock/syscalls.c
+++ b/security/landlock/syscalls.c
@@ -280,9 +280,9 @@ SYSCALL_DEFINE3(landlock_create_ruleset,
 	if (IS_ERR(ruleset))
 		return PTR_ERR(ruleset);
 
-	ruleset->quiet_masks.fs = ruleset_attr.quiet_access_fs;
-	ruleset->quiet_masks.net = ruleset_attr.quiet_access_net;
-	ruleset->quiet_masks.scope = ruleset_attr.quiet_scoped;
+	ruleset->quiet_access.fs = ruleset_attr.quiet_access_fs;
+	ruleset->quiet_access.net = ruleset_attr.quiet_access_net;
+	ruleset->quiet_access.scope = ruleset_attr.quiet_scoped;
 
 	/*
 	 * Emits before anon_inode_getfd() installs the file descriptor, while
@@ -382,7 +382,7 @@ static int add_rule_path_beneath(struct landlock_ruleset *const ruleset,
 		return -EINVAL;
 
 	/* Checks for useless quiet flag. */
-	if (flags & LANDLOCK_ADD_RULE_QUIET && !ruleset->quiet_masks.fs)
+	if (flags & LANDLOCK_ADD_RULE_QUIET && !ruleset->quiet_access.fs)
 		return -EINVAL;
 
 	/* Gets and checks the new rule. */
@@ -423,7 +423,7 @@ static int add_rule_net_port(struct landlock_ruleset *ruleset,
 		return -EINVAL;
 
 	/* Checks for useless quiet flag. */
-	if (flags & LANDLOCK_ADD_RULE_QUIET && !ruleset->quiet_masks.net)
+	if (flags & LANDLOCK_ADD_RULE_QUIET && !ruleset->quiet_access.net)
 		return -EINVAL;
 
 	/* Denies inserting a rule with port greater than 65535. */
-- 
2.55.0




More information about the Linux-security-module-archive mailing list