[PATCH v4 8/8] landlock: Add documentation for capability and namespace restrictions

sashiko-bot at kernel.org sashiko-bot at kernel.org
Fri Oct 2 12:59:04 UTC 2026


> Document the two new Landlock permission categories, introduced with ABI
> 12, in the userspace API guide, admin guide, trace-event guide, UAPI
> comments, and kernel security documentation.
> 
> The kernel security documentation generalizes the existing per-object
> access-rights framing into three restriction models (handled_access_*,
> handled_permissions, scoped) and states criteria for choosing among
> them, so future permission or scope additions have a documented place to
> land.
> 
> Cc: Christian Brauner <brauner at kernel.org>
> Cc: Günther Noack <gnoack at google.com>
> Cc: Paul Moore <paul at paul-moore.com>
> Cc: Serge E. Hallyn <serge at hallyn.com>
> Signed-off-by: Mickaël Salaün <mic at digikod.net>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002124409.1277970-1-mic@digikod.net?part=8




More information about the Linux-security-module-archive mailing list