[PATCH v4 4/8] landlock: Enforce capability restrictions

sashiko-bot at kernel.org sashiko-bot at kernel.org
Fri Oct 2 12:53:09 UTC 2026


> Add Landlock enforcement for capability use via the LSM capable hook.
> This lets a sandboxed process restrict which Linux capabilities it can
> exercise, using LANDLOCK_PERMISSION_CAPABILITY_USE and per-capability
> rules.
> 
> The check is a flat per-layer allowed-capabilities test, with no
> domain-ancestry bypass, no cross-namespace discriminant, and no
> dependency on the target user namespace.  These categorical denials
> return -EPERM, like the namespace permission introduced by the previous
> commit, and they mirror its per-capability allowed and quiet masks, so
> LANDLOCK_ADD_RULE_QUIET stays rejected for this rule type.  Successful
> capability rules and denials are traced as the previous commit
> describes.
> 
> Enforce only at capability exercise time rather than modifying the
> [ ... ]
> Cc: Christian Brauner <brauner at kernel.org>
> Cc: Günther Noack <gnoack at google.com>
> Cc: Paul Moore <paul at paul-moore.com>
> Cc: Serge E. Hallyn <serge at hallyn.com>
> Signed-off-by: Mickaël Salaün <mic at digikod.net>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002124409.1277970-1-mic@digikod.net?part=4




More information about the Linux-security-module-archive mailing list