[PATCH v4 4/8] landlock: Enforce capability restrictions
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Fri Oct 2 12:53:09 UTC 2026
> Add Landlock enforcement for capability use via the LSM capable hook.
> This lets a sandboxed process restrict which Linux capabilities it can
> exercise, using LANDLOCK_PERMISSION_CAPABILITY_USE and per-capability
> rules.
>
> The check is a flat per-layer allowed-capabilities test, with no
> domain-ancestry bypass, no cross-namespace discriminant, and no
> dependency on the target user namespace. These categorical denials
> return -EPERM, like the namespace permission introduced by the previous
> commit, and they mirror its per-capability allowed and quiet masks, so
> LANDLOCK_ADD_RULE_QUIET stays rejected for this rule type. Successful
> capability rules and denials are traced as the previous commit
> describes.
>
> Enforce only at capability exercise time rather than modifying the
> [ ... ]
> Cc: Christian Brauner <brauner at kernel.org>
> Cc: Günther Noack <gnoack at google.com>
> Cc: Paul Moore <paul at paul-moore.com>
> Cc: Serge E. Hallyn <serge at hallyn.com>
> Signed-off-by: Mickaël Salaün <mic at digikod.net>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261002124409.1277970-1-mic@digikod.net?part=4
More information about the Linux-security-module-archive
mailing list