All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Mickaël Salaün" <mic@digikod.net>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: "Mickaël Salaün" <mic@digikod.net>,
	"Christian Brauner" <brauner@kernel.org>,
	"Doehyun Baek" <doehyunbaek@gmail.com>,
	"Günther Noack" <gnoack3000@gmail.com>,
	"Günther Noack" <gnoack@google.com>,
	"Justin Suess" <utilityemal77@gmail.com>,
	"Tingmao Wang" <m@maowtm.org>, "Wang Yan" <wangyan01@kylinos.cn>,
	linux-kernel@vger.kernel.org,
	linux-security-module@vger.kernel.org
Subject: [GIT PULL] Landlock update for v7.3-rc1
Date: Thu, 20 Aug 2026 11:12:08 +0200	[thread overview]
Message-ID: <20260820091208.1001980-1-mic@digikod.net> (raw)

Hi,

This PR improves observability with Landlock tracepoints support, which
required some refactoring for dedicated domain types and common helpers shared
with audit code.  A LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS flag is also added to
improve process-wide domain enforcement consistency.  Whiteout files are now
correctly handled and tested, and a few other fixes complete this PR.

Please pull these changes for v7.3-rc1 .  These commits merge cleanly
with your master branch.  Most kernel changes have been tested in the
latest linux-next releases for some weeks, and I recently updated commit
messages to reflect latest reviews.

Test coverage for security/landlock is 91.6% of 2571 lines according to
LLVM 22, and it was 91.8% of 2357 lines before this PR.

Regards,
 Mickaël

--
The following changes since commit 075b74841bd0065a3bda3440873c747938e69b68:

  Linux 7.2-rc6 (2026-08-02 16:24:24 -0700)

are available in the Git repository at:

  https://git.kernel.org/pub/scm/linux/kernel/git/mic/linux.git tags/landlock-7.3-rc1

for you to fetch changes up to 172b6a6d8463562b0cbebfd66f770b078f81966b:

  landlock: Document tracepoints (2026-08-17 10:17:19 +0200)

----------------------------------------------------------------
Landlock update for v7.3-rc1

----------------------------------------------------------------
Doehyun Baek (1):
      landlock: Document fs.resolve_unix audit blocker

Günther Noack (7):
      landlock: Documentation wording cleanups
      selftests/landlock: Use an actual chardev for MAKE_CHAR audit test
      landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
      selftests/landlock: Add tests for whiteout object creation
      selftests/landlock: Add audit test for whiteout object creation
      selftests/landlock: Test whiteout object behaviour in OverlayFS renames
      landlock: Link the erratum documentation for whiteout objects

Justin Suess (5):
      landlock: Check landlock_restrict_self(2)'s flags before privileges
      landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
      selftests/landlock: Test LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
      landlock: Document LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
      samples/landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS to sampler

Mickaël Salaün (20):
      landlock: Harden sock_is_scoped() against file-less sockets
      landlock: Prepare ruleset and domain type split
      landlock: Move domain query functions to domain.c
      landlock: Split struct landlock_domain from struct landlock_ruleset
      landlock: Split denial logging from audit into common framework
      landlock: Decouple the per-denial logging decision from CONFIG_AUDIT
      landlock: Consolidate access-right and scope names in a shared header
      landlock: Add create_ruleset and free_ruleset tracepoints
      landlock: Add landlock_add_rule_fs and landlock_add_rule_net tracepoints
      landlock: Add create_domain and free_domain tracepoints
      landlock: Add landlock_enforce_domain tracepoint
      landlock: Add tracepoints for rule checking
      landlock: Add landlock_deny_access_fs and landlock_deny_access_net
      landlock: Add tracepoints for ptrace and scope denials
      selftests/landlock: Add trace event test infrastructure and tests
      selftests/landlock: Add filesystem tracepoint tests
      selftests/landlock: Add network tracepoint tests
      selftests/landlock: Add scope and ptrace tracepoint tests
      selftests/landlock: Add landlock_enforce_domain trace tests
      landlock: Document tracepoints

Wang Yan (1):
      selftests/landlock: Fix spelling error in fs_test comment

 Documentation/admin-guide/LSM/landlock.rst         |  106 +-
 Documentation/security/landlock.rst                |   38 +-
 Documentation/trace/events-landlock.rst            |  326 ++++
 Documentation/trace/index.rst                      |    1 +
 Documentation/userspace-api/landlock.rst           |   62 +-
 MAINTAINERS                                        |    3 +
 include/linux/landlock.h                           |   56 +
 include/trace/events/landlock.h                    |  965 ++++++++++++
 include/uapi/linux/landlock.h                      |   22 +-
 samples/landlock/sandboxer.c                       |   16 +-
 security/landlock/Kconfig                          |    5 +
 security/landlock/Makefile                         |   12 +-
 security/landlock/access.h                         |    6 +-
 security/landlock/audit.c                          |  641 +-------
 security/landlock/audit.h                          |   57 +-
 security/landlock/cred.c                           |   14 +-
 security/landlock/cred.h                           |   29 +-
 security/landlock/domain.c                         |  472 +++++-
 security/landlock/domain.h                         |  163 +-
 security/landlock/errata/abi-1.h                   |   23 +
 security/landlock/fs.c                             |  259 +++-
 security/landlock/fs.h                             |   40 +-
 security/landlock/id.h                             |    6 +-
 security/landlock/limits.h                         |    2 +-
 security/landlock/log.c                            |  587 +++++++
 security/landlock/log.h                            |   86 ++
 security/landlock/net.c                            |   38 +-
 security/landlock/ruleset.c                        |  546 +------
 security/landlock/ruleset.h                        |  250 +--
 security/landlock/syscalls.c                       |  125 +-
 security/landlock/task.c                           |   87 +-
 security/landlock/trace.c                          |  185 +++
 security/landlock/trace.h                          |   44 +
 security/landlock/tsync.c                          |   24 +-
 security/landlock/tsync.h                          |    4 +-
 tools/testing/selftests/landlock/audit.h           |   35 -
 tools/testing/selftests/landlock/base_test.c       |  104 +-
 tools/testing/selftests/landlock/common.h          |   47 +
 tools/testing/selftests/landlock/config            |    2 +
 tools/testing/selftests/landlock/fs_test.c         |  738 ++++++++-
 tools/testing/selftests/landlock/net_test.c        |  590 ++++++-
 tools/testing/selftests/landlock/ptrace_test.c     |  402 +++++
 .../selftests/landlock/scoped_abstract_unix_test.c |  264 ++++
 .../selftests/landlock/scoped_signal_test.c        |  404 +++++
 tools/testing/selftests/landlock/trace.h           |  639 ++++++++
 tools/testing/selftests/landlock/trace_fs_test.c   |  496 ++++++
 tools/testing/selftests/landlock/trace_test.c      | 1620 ++++++++++++++++++++
 tools/testing/selftests/landlock/true.c            |   10 +
 tools/testing/selftests/landlock/tsync_test.c      |   96 +-
 49 files changed, 9244 insertions(+), 1503 deletions(-)
 create mode 100644 Documentation/trace/events-landlock.rst
 create mode 100644 include/linux/landlock.h
 create mode 100644 include/trace/events/landlock.h
 create mode 100644 security/landlock/log.c
 create mode 100644 security/landlock/log.h
 create mode 100644 security/landlock/trace.c
 create mode 100644 security/landlock/trace.h
 create mode 100644 tools/testing/selftests/landlock/trace.h
 create mode 100644 tools/testing/selftests/landlock/trace_fs_test.c
 create mode 100644 tools/testing/selftests/landlock/trace_test.c

             reply	other threads:[~2026-08-20  9:20 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-20  9:12 Mickaël Salaün [this message]
2026-08-21 20:26 ` [GIT PULL] Landlock update for v7.3-rc1 pr-tracker-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260820091208.1001980-1-mic@digikod.net \
    --to=mic@digikod.net \
    --cc=brauner@kernel.org \
    --cc=doehyunbaek@gmail.com \
    --cc=gnoack3000@gmail.com \
    --cc=gnoack@google.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-security-module@vger.kernel.org \
    --cc=m@maowtm.org \
    --cc=torvalds@linux-foundation.org \
    --cc=utilityemal77@gmail.com \
    --cc=wangyan01@kylinos.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.