[PATCH v1 6/9] landlock: Report the effective signal number

sashiko-bot at kernel.org sashiko-bot at kernel.org
Fri Sep 18 18:57:37 UTC 2026


> The signal-scope denial callback identifies its target but not the
> effective signal. This loses permission-probe signal zero and makes the
> file-owner hook's zero sentinel ambiguous.
> 
> Append an int signal argument to the typed-BPF callback. Preserve sig,
> including zero, in hook_task_kill(). In hook_file_send_sigiotask(),
> translate signum zero to SIGIO at the producer, where its meaning is
> known.
> 
> Carry the effective signal and target domain ID in a private,
> stack-backed context consumed synchronously. This requires no allocation
> or task reference in the interrupt-capable file-owner path. Gate this
> context and the remaining scope-only domain IDs with CONFIG_TRACEPOINTS.
> 
> Keep the tracefs record and audit output unchanged.
> 
> Cc: Günther Noack <gnoack at google.com>
> Cc: Steven Rostedt <rostedt at goodmis.org>
> Fixes: bb91730f16c0 ("landlock: Add tracepoints for ptrace and scope denials")
> Signed-off-by: Mickaël Salaün <mic at digikod.net>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260918185036.608651-1-mic@digikod.net?part=6




More information about the Linux-security-module-archive mailing list