[PATCH v4 8/8] landlock: Add documentation for capability and namespace restrictions
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Fri Oct 2 12:59:04 UTC 2026
> Document the two new Landlock permission categories, introduced with ABI
> 12, in the userspace API guide, admin guide, trace-event guide, UAPI
> comments, and kernel security documentation.
>
> The kernel security documentation generalizes the existing per-object
> access-rights framing into three restriction models (handled_access_*,
> handled_permissions, scoped) and states criteria for choosing among
> them, so future permission or scope additions have a documented place to
> land.
>
> Cc: Christian Brauner <brauner at kernel.org>
> Cc: Günther Noack <gnoack at google.com>
> Cc: Paul Moore <paul at paul-moore.com>
> Cc: Serge E. Hallyn <serge at hallyn.com>
> Signed-off-by: Mickaël Salaün <mic at digikod.net>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261002124409.1277970-1-mic@digikod.net?part=8
More information about the Linux-security-module-archive
mailing list