[PATCH v4 3/8] landlock: Enforce namespace use restrictions
sashiko-bot at kernel.org
sashiko-bot at kernel.org
Fri Oct 2 12:52:24 UTC 2026
> Add Landlock enforcement for namespace use through the LSM
> namespace_init and namespace_install hooks. This lets a sandboxed
> process restrict which namespace types it can create, join, or acquire a
> file descriptor for, using LANDLOCK_PERMISSION_NAMESPACE_USE and
> per-type rules.
>
> Introduce the handled_permissions field in struct landlock_ruleset_attr:
> each permission gates every use of a kernel-defined category (CLONE_NEW*
> namespace types, CAP_* capabilities) with complete deny-by-default
> coverage, so unknown member values need no validation, being denied
> until a rule allows them. This UAPI extension advances the Landlock ABI
> from 11 to 12.
>
> There is no domain-ancestry bypass and no namespace-creator tracking,
> only a flat per-layer allowed-types bitmask: hook_namespace_init()
> [ ... ]
> Cc: Christian Brauner <brauner at kernel.org>
> Cc: Günther Noack <gnoack at google.com>
> Cc: Paul Moore <paul at paul-moore.com>
> Cc: Serge E. Hallyn <serge at hallyn.com>
> Signed-off-by: Mickaël Salaün <mic at digikod.net>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261002124409.1277970-1-mic@digikod.net?part=3
More information about the Linux-security-module-archive
mailing list