From: "Mickaël Salaün" <mic@digikod.net>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: "Mickaël Salaün" <mic@digikod.net>,
"Christian Brauner" <brauner@kernel.org>,
"Doehyun Baek" <doehyunbaek@gmail.com>,
"Günther Noack" <gnoack3000@gmail.com>,
"Günther Noack" <gnoack@google.com>,
"Justin Suess" <utilityemal77@gmail.com>,
"Tingmao Wang" <m@maowtm.org>, "Wang Yan" <wangyan01@kylinos.cn>,
linux-kernel@vger.kernel.org,
linux-security-module@vger.kernel.org
Subject: [GIT PULL] Landlock update for v7.3-rc1
Date: Thu, 20 Aug 2026 11:12:08 +0200 [thread overview]
Message-ID: <20260820091208.1001980-1-mic@digikod.net> (raw)
Hi,
This PR improves observability with Landlock tracepoints support, which
required some refactoring for dedicated domain types and common helpers shared
with audit code. A LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS flag is also added to
improve process-wide domain enforcement consistency. Whiteout files are now
correctly handled and tested, and a few other fixes complete this PR.
Please pull these changes for v7.3-rc1 . These commits merge cleanly
with your master branch. Most kernel changes have been tested in the
latest linux-next releases for some weeks, and I recently updated commit
messages to reflect latest reviews.
Test coverage for security/landlock is 91.6% of 2571 lines according to
LLVM 22, and it was 91.8% of 2357 lines before this PR.
Regards,
Mickaël
--
The following changes since commit 075b74841bd0065a3bda3440873c747938e69b68:
Linux 7.2-rc6 (2026-08-02 16:24:24 -0700)
are available in the Git repository at:
https://git.kernel.org/pub/scm/linux/kernel/git/mic/linux.git tags/landlock-7.3-rc1
for you to fetch changes up to 172b6a6d8463562b0cbebfd66f770b078f81966b:
landlock: Document tracepoints (2026-08-17 10:17:19 +0200)
----------------------------------------------------------------
Landlock update for v7.3-rc1
----------------------------------------------------------------
Doehyun Baek (1):
landlock: Document fs.resolve_unix audit blocker
Günther Noack (7):
landlock: Documentation wording cleanups
selftests/landlock: Use an actual chardev for MAKE_CHAR audit test
landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
selftests/landlock: Add tests for whiteout object creation
selftests/landlock: Add audit test for whiteout object creation
selftests/landlock: Test whiteout object behaviour in OverlayFS renames
landlock: Link the erratum documentation for whiteout objects
Justin Suess (5):
landlock: Check landlock_restrict_self(2)'s flags before privileges
landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
selftests/landlock: Test LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
landlock: Document LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
samples/landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS to sampler
Mickaël Salaün (20):
landlock: Harden sock_is_scoped() against file-less sockets
landlock: Prepare ruleset and domain type split
landlock: Move domain query functions to domain.c
landlock: Split struct landlock_domain from struct landlock_ruleset
landlock: Split denial logging from audit into common framework
landlock: Decouple the per-denial logging decision from CONFIG_AUDIT
landlock: Consolidate access-right and scope names in a shared header
landlock: Add create_ruleset and free_ruleset tracepoints
landlock: Add landlock_add_rule_fs and landlock_add_rule_net tracepoints
landlock: Add create_domain and free_domain tracepoints
landlock: Add landlock_enforce_domain tracepoint
landlock: Add tracepoints for rule checking
landlock: Add landlock_deny_access_fs and landlock_deny_access_net
landlock: Add tracepoints for ptrace and scope denials
selftests/landlock: Add trace event test infrastructure and tests
selftests/landlock: Add filesystem tracepoint tests
selftests/landlock: Add network tracepoint tests
selftests/landlock: Add scope and ptrace tracepoint tests
selftests/landlock: Add landlock_enforce_domain trace tests
landlock: Document tracepoints
Wang Yan (1):
selftests/landlock: Fix spelling error in fs_test comment
Documentation/admin-guide/LSM/landlock.rst | 106 +-
Documentation/security/landlock.rst | 38 +-
Documentation/trace/events-landlock.rst | 326 ++++
Documentation/trace/index.rst | 1 +
Documentation/userspace-api/landlock.rst | 62 +-
MAINTAINERS | 3 +
include/linux/landlock.h | 56 +
include/trace/events/landlock.h | 965 ++++++++++++
include/uapi/linux/landlock.h | 22 +-
samples/landlock/sandboxer.c | 16 +-
security/landlock/Kconfig | 5 +
security/landlock/Makefile | 12 +-
security/landlock/access.h | 6 +-
security/landlock/audit.c | 641 +-------
security/landlock/audit.h | 57 +-
security/landlock/cred.c | 14 +-
security/landlock/cred.h | 29 +-
security/landlock/domain.c | 472 +++++-
security/landlock/domain.h | 163 +-
security/landlock/errata/abi-1.h | 23 +
security/landlock/fs.c | 259 +++-
security/landlock/fs.h | 40 +-
security/landlock/id.h | 6 +-
security/landlock/limits.h | 2 +-
security/landlock/log.c | 587 +++++++
security/landlock/log.h | 86 ++
security/landlock/net.c | 38 +-
security/landlock/ruleset.c | 546 +------
security/landlock/ruleset.h | 250 +--
security/landlock/syscalls.c | 125 +-
security/landlock/task.c | 87 +-
security/landlock/trace.c | 185 +++
security/landlock/trace.h | 44 +
security/landlock/tsync.c | 24 +-
security/landlock/tsync.h | 4 +-
tools/testing/selftests/landlock/audit.h | 35 -
tools/testing/selftests/landlock/base_test.c | 104 +-
tools/testing/selftests/landlock/common.h | 47 +
tools/testing/selftests/landlock/config | 2 +
tools/testing/selftests/landlock/fs_test.c | 738 ++++++++-
tools/testing/selftests/landlock/net_test.c | 590 ++++++-
tools/testing/selftests/landlock/ptrace_test.c | 402 +++++
.../selftests/landlock/scoped_abstract_unix_test.c | 264 ++++
.../selftests/landlock/scoped_signal_test.c | 404 +++++
tools/testing/selftests/landlock/trace.h | 639 ++++++++
tools/testing/selftests/landlock/trace_fs_test.c | 496 ++++++
tools/testing/selftests/landlock/trace_test.c | 1620 ++++++++++++++++++++
tools/testing/selftests/landlock/true.c | 10 +
tools/testing/selftests/landlock/tsync_test.c | 96 +-
49 files changed, 9244 insertions(+), 1503 deletions(-)
create mode 100644 Documentation/trace/events-landlock.rst
create mode 100644 include/linux/landlock.h
create mode 100644 include/trace/events/landlock.h
create mode 100644 security/landlock/log.c
create mode 100644 security/landlock/log.h
create mode 100644 security/landlock/trace.c
create mode 100644 security/landlock/trace.h
create mode 100644 tools/testing/selftests/landlock/trace.h
create mode 100644 tools/testing/selftests/landlock/trace_fs_test.c
create mode 100644 tools/testing/selftests/landlock/trace_test.c
next reply other threads:[~2026-08-20 9:20 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-20 9:12 Mickaël Salaün [this message]
2026-08-21 20:26 ` [GIT PULL] Landlock update for v7.3-rc1 pr-tracker-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260820091208.1001980-1-mic@digikod.net \
--to=mic@digikod.net \
--cc=brauner@kernel.org \
--cc=doehyunbaek@gmail.com \
--cc=gnoack3000@gmail.com \
--cc=gnoack@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=m@maowtm.org \
--cc=torvalds@linux-foundation.org \
--cc=utilityemal77@gmail.com \
--cc=wangyan01@kylinos.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.