[PATCH v4 7/8] samples/landlock: Add capability and namespace restriction support
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Fri Oct 2 12:53:30 UTC 2026
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Low] build: sample landlock fails on systems without libcap-dev
- [Low] build: missing fallback for CLONE_NEWTIME breaks build on glibc < 2.33
--
commit c88aebdbd55f6c34b61885d4e3d918bc61983af0
Author: Mickaël Salaün <mic at digikod.net>
samples/landlock: Add capability and namespace restriction support
This commit extends the sandboxer sample to demonstrate new Landlock
capability and namespace restriction features. It allows parsing allowed
namespaces and capabilities using libcap, adding appropriate command line
arguments for testing.
> diff --git a/samples/Kconfig b/samples/Kconfig
> index a75e8e78330da..b18efc19b85d0 100644
> --- a/samples/Kconfig
> +++ b/samples/Kconfig
> @@ -166,8 +166,10 @@ config SAMPLE_LANDLOCK
> bool "Landlock example"
> depends on CC_CAN_LINK && HEADERS_INSTALL
> help
> - Build a simple Landlock sandbox manager able to start a process
> - restricted by a user-defined filesystem access control policy.
> + Build a Landlock sandbox manager able to start a process restricted
> + by user-defined filesystem, network, scope, namespace, and capability
> + policies. This sample requires the libcap development headers and
> + library.
>
> config SAMPLE_PIDFD
> bool "pidfd sample"
[ ... ]
> diff --git a/samples/landlock/Makefile b/samples/landlock/Makefile
> index 5d601e51c2ebf..b30239c8a281c 100644
> --- a/samples/landlock/Makefile
> +++ b/samples/landlock/Makefile
> @@ -3,6 +3,7 @@
> userprogs-always-y := sandboxer
>
> userccflags += -I usr/include
> +userldlibs += -lcap
[Severity: Low]
Does this unconditional linking cause build failures during make allmodconfig
or make samples if the host system lacks the libcap-dev library?
Since the Kconfig does not verify the presence of the libcap library (for
example, using a $(success,...) check), the build will unconditionally
attempt to link against it and fail when the dependency is missing. Could a
dependency check be added in the Kconfig to prevent breaking automated
testing on minimal host environments?
>
> .PHONY: all clean
[ ... ]
> diff --git a/samples/landlock/sandboxer.c b/samples/landlock/sandboxer.c
> index 030583273f3f7..4a86ae6d4552d 100644
> --- a/samples/landlock/sandboxer.c
> +++ b/samples/landlock/sandboxer.c
> @@ -232,6 +241,166 @@ static int populate_ruleset_net(const char *const env_var, const int ruleset_fd,
> return ret;
> }
>
> +static __u64 str2ns(const char *const name)
> +{
> + static const struct {
> + const char *name;
> + __u64 value;
> + } ns_map[] = {
> + /* clang-format off */
> + { "cgroup", CLONE_NEWCGROUP },
> + { "ipc", CLONE_NEWIPC },
> + { "mnt", CLONE_NEWNS },
> + { "net", CLONE_NEWNET },
> + { "pid", CLONE_NEWPID },
> + { "time", CLONE_NEWTIME },
[Severity: Low]
Will this missing fallback macro for CLONE_NEWTIME cause compilation failures
on older host environments?
The CLONE_NEWTIME macro was added to the glibc sched.h header starting in
version 2.33. If the sample is built on a system with an older glibc, it
fails to compile. Can we add a fallback preprocessor definition for
CLONE_NEWTIME so the sample can still build on older distributions?
> + { "user", CLONE_NEWUSER },
> + { "uts", CLONE_NEWUTS },
> + /* clang-format on */
> + };
> + size_t i;
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261002124409.1277970-1-mic@digikod.net?part=7
More information about the Linux-security-module-archive
mailing list