[PATCH v4 3/8] landlock: Enforce namespace use restrictions

sashiko-bot at kernel.org sashiko-bot at kernel.org
Fri Oct 2 12:52:24 UTC 2026


> Add Landlock enforcement for namespace use through the LSM
> namespace_init and namespace_install hooks.  This lets a sandboxed
> process restrict which namespace types it can create, join, or acquire a
> file descriptor for, using LANDLOCK_PERMISSION_NAMESPACE_USE and
> per-type rules.
> 
> Introduce the handled_permissions field in struct landlock_ruleset_attr:
> each permission gates every use of a kernel-defined category (CLONE_NEW*
> namespace types, CAP_* capabilities) with complete deny-by-default
> coverage, so unknown member values need no validation, being denied
> until a rule allows them.  This UAPI extension advances the Landlock ABI
> from 11 to 12.
> 
> There is no domain-ancestry bypass and no namespace-creator tracking,
> only a flat per-layer allowed-types bitmask: hook_namespace_init()
> [ ... ]
> Cc: Christian Brauner <brauner at kernel.org>
> Cc: Günther Noack <gnoack at google.com>
> Cc: Paul Moore <paul at paul-moore.com>
> Cc: Serge E. Hallyn <serge at hallyn.com>
> Signed-off-by: Mickaël Salaün <mic at digikod.net>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002124409.1277970-1-mic@digikod.net?part=3




More information about the Linux-security-module-archive mailing list