[PATCH v1 4/9] landlock: Fix network denial trace context

sashiko-bot at kernel.org sashiko-bot at kernel.org
Fri Sep 18 18:57:58 UTC 2026


> Network denial events report source and destination ports reconstructed
> from audit data. Their zero values are ambiguous, and neither identifies
> the complete endpoint that Landlock checked.
> 
> Carry the checked sockaddr and its signed length in a private trace-only
> context. For an enabled event, validate the length and copy only the
> initialized prefix into zeroed local storage. This prevents a typed BPF
> program from reading uninitialized bytes while exposing the socket
> family, socket, address, and length.
> 
> Replace the source and destination trace-record fields with one signed
> port derived from the checked address. A value of -1 means that no port
> was checked, zero is a valid port, and positive values use host
> endianness. Bind blockers select the bind address; connect and send
> blockers select the destination.
> 
> Cc: Günther Noack <gnoack at google.com>
> Cc: Steven Rostedt <rostedt at goodmis.org>
> Fixes: 01ce260f5ccf ("landlock: Add landlock_deny_access_fs and landlock_deny_access_net")
> Signed-off-by: Mickaël Salaün <mic at digikod.net>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260918185036.608651-1-mic@digikod.net?part=4




More information about the Linux-security-module-archive mailing list