* [PATCH RFC 0/2] bitbake: Add basic landlock support
@ 2026-06-12 11:38 David Nyström
2026-06-12 11:38 ` [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function David Nyström
` (2 more replies)
0 siblings, 3 replies; 10+ messages in thread
From: David Nyström @ 2026-06-12 11:38 UTC (permalink / raw)
To: bitbake-devel; +Cc: David Nyström
When current implementation runs in an unprivileged docker container,
basic networking will be allowed by default in all steps, ignoring the
network varflags intention.
Introduce support for landlock blocking of bind and connect, providing
basic support for blocking TCP.
UDP is corrently beeing worked on upstream, but not yet supported.
Landlock requires PR_SET_NO_NEW_PRIVS to prevent escape,
which is also attempted, this prevents privilege escalation from child.
devshell and related are already tagged with network varflag and
can sudo at will.
syscall ABI is asm-generic, 5.13+ for all archs except alpha.
On alpha, we leak 2 fd:s in the childs context before graceful exit,
which is cleaned up at child termination.
Don't have an alpha target, so this is not tested, evaluated via
static analysis only.
Landlock also provides a future possibility for filesystem
limitations with the purpose of catching bugs, and preventing
persistance of supply chain releated payloads. writes to f.ex.
.bashrc and friends.
Signed-off-by: David Nyström <david.nystrom@est.tech>
---
David Nyström (2):
utils: Add landlock_restrict_network function
bitbake-worker: Call landlock_restrict_network for tasks without network
bin/bitbake-worker | 2 ++
lib/bb/utils.py | 26 ++++++++++++++++++++++++++
2 files changed, 28 insertions(+)
---
base-commit: a0158cc8d8f29233a9ade63a4c3ce2e939c4bf16
change-id: 20260611-landlock-621bc1a15305
Best regards,
--
David Nyström <david.nystrom@est.tech>
^ permalink raw reply [flat|nested] 10+ messages in thread* [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function 2026-06-12 11:38 [PATCH RFC 0/2] bitbake: Add basic landlock support David Nyström @ 2026-06-12 11:38 ` David Nyström 2026-06-13 11:52 ` [bitbake-devel] " Alexander Kanavin 2026-06-15 8:28 ` Paul Barker 2026-06-12 11:38 ` [PATCH [RFC] 2/2] bitbake-worker: Call landlock_restrict_network for tasks without network David Nyström 2026-07-16 15:44 ` [bitbake-devel] [PATCH RFC 0/2] bitbake: Add basic landlock support Richard Purdie 2 siblings, 2 replies; 10+ messages in thread From: David Nyström @ 2026-06-12 11:38 UTC (permalink / raw) To: bitbake-devel; +Cc: David Nyström Add landlock_restrict_network() which blocks TCP bind/connect using Landlock LSM (ABI v4+, kernel 6.7+). Designed to stack with the existing disable_network() namespace isolation, covering the case where disable_network() is skipped for non-local UIDs. Gracefully returns False on older kernels (ABI < 4). Signed-off-by: David Nyström <david.nystrom@est.tech> --- lib/bb/utils.py | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/lib/bb/utils.py b/lib/bb/utils.py index 181082c95..1347c29d0 100644 --- a/lib/bb/utils.py +++ b/lib/bb/utils.py @@ -2054,6 +2054,32 @@ def disable_network(uid=None, gid=None): with open("/proc/self/gid_map", "w") as f: f.write("%s %s 1" % (gid, gid)) +def landlock_restrict_network(): + """Block TCP bind/connect using Landlock LSM (ABI v4+, kernel 6.7+). + Gracefully skipped on older kernels. Stacks with disable_network().""" + + NR_CREATE = 444 # landlock_create_ruleset + NR_SELF = 446 # landlock_restrict_self + NET_TCP = 0x3 # BIND_TCP | CONNECT_TCP + + libc = ctypes.CDLL('libc.so.6') + + abi = libc.syscall(NR_CREATE, 0, 0, 1) + if abi < 4: + return False + + attr = struct.pack("QQ", 0, NET_TCP) + buf = ctypes.create_string_buffer(attr) + fd = libc.syscall(NR_CREATE, buf, len(attr), 0) + if fd < 0: + return False + + libc.prctl(38, 1, 0, 0, 0) # PR_SET_NO_NEW_PRIVS + r = libc.syscall(NR_SELF, fd, 0) + os.close(fd) + return r == 0 + + def export_proxies(d): from bb.fetch2 import get_fetcher_environment """ export common proxies variables from datastore to environment """ -- 2.53.0 ^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [bitbake-devel] [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function 2026-06-12 11:38 ` [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function David Nyström @ 2026-06-13 11:52 ` Alexander Kanavin 2026-06-13 14:26 ` Richard Purdie 2026-06-15 8:28 ` Paul Barker 1 sibling, 1 reply; 10+ messages in thread From: Alexander Kanavin @ 2026-06-13 11:52 UTC (permalink / raw) To: david.nystrom; +Cc: bitbake-devel On Fri, 12 Jun 2026 at 14:01, David Nyström via lists.openembedded.org <david.nystrom=est.tech@lists.openembedded.org> wrote: > +def landlock_restrict_network(): > + """Block TCP bind/connect using Landlock LSM (ABI v4+, kernel 6.7+). > + Gracefully skipped on older kernels. Stacks with disable_network().""" > + > + NR_CREATE = 444 # landlock_create_ruleset > + NR_SELF = 446 # landlock_restrict_self > + NET_TCP = 0x3 # BIND_TCP | CONNECT_TCP > + > + libc = ctypes.CDLL('libc.so.6') > + > + abi = libc.syscall(NR_CREATE, 0, 0, 1) > + if abi < 4: > + return False > + > + attr = struct.pack("QQ", 0, NET_TCP) > + buf = ctypes.create_string_buffer(attr) > + fd = libc.syscall(NR_CREATE, buf, len(attr), 0) > + if fd < 0: > + return False > + > + libc.prctl(38, 1, 0, 0, 0) # PR_SET_NO_NEW_PRIVS > + r = libc.syscall(NR_SELF, fd, 0) > + os.close(fd) > + return r == 0 Far too many magic numbers. I would really want to do this with an API. This also needs some kind of test, e.g. that the function indeed has the desired effect. Alex ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [bitbake-devel] [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function 2026-06-13 11:52 ` [bitbake-devel] " Alexander Kanavin @ 2026-06-13 14:26 ` Richard Purdie 0 siblings, 0 replies; 10+ messages in thread From: Richard Purdie @ 2026-06-13 14:26 UTC (permalink / raw) To: alex.kanavin, david.nystrom; +Cc: bitbake-devel On Sat, 2026-06-13 at 13:52 +0200, Alexander Kanavin via lists.openembedded.org wrote: > On Fri, 12 Jun 2026 at 14:01, David Nyström via > lists.openembedded.org > <david.nystrom=est.tech@lists.openembedded.org> wrote: > > +def landlock_restrict_network(): > > + """Block TCP bind/connect using Landlock LSM (ABI v4+, kernel > > 6.7+). > > + Gracefully skipped on older kernels. Stacks with > > disable_network().""" > > + > > + NR_CREATE = 444 # landlock_create_ruleset > > + NR_SELF = 446 # landlock_restrict_self > > + NET_TCP = 0x3 # BIND_TCP | CONNECT_TCP > > + > > + libc = ctypes.CDLL('libc.so.6') > > + > > + abi = libc.syscall(NR_CREATE, 0, 0, 1) > > + if abi < 4: > > + return False > > + > > + attr = struct.pack("QQ", 0, NET_TCP) > > + buf = ctypes.create_string_buffer(attr) > > + fd = libc.syscall(NR_CREATE, buf, len(attr), 0) > > + if fd < 0: > > + return False > > + > > + libc.prctl(38, 1, 0, 0, 0) # PR_SET_NO_NEW_PRIVS > > + r = libc.syscall(NR_SELF, fd, 0) > > + os.close(fd) > > + return r == 0 > > Far too many magic numbers. I would really want to do this with an > API. > > This also needs some kind of test, e.g. that the function indeed has > the desired effect. Unfortunately, to use tech like this, we do end up needing to do something like that and utils.py already has quite a bit of it. The plus side is that the kernel is really good about maintaining these APIs so the numbers are unlikely to change. I wouldn't take something like this unless there was a really good case for using it. Network isolation in more builds probably is a strong enough use case... Cheers, Richard ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [bitbake-devel] [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function 2026-06-12 11:38 ` [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function David Nyström 2026-06-13 11:52 ` [bitbake-devel] " Alexander Kanavin @ 2026-06-15 8:28 ` Paul Barker 2026-07-17 18:11 ` David Nyström 1 sibling, 1 reply; 10+ messages in thread From: Paul Barker @ 2026-06-15 8:28 UTC (permalink / raw) To: David Nyström, bitbake-devel [-- Attachment #1: Type: text/plain, Size: 2976 bytes --] On Fri, 2026-06-12 at 13:38 +0200, David Nyström wrote: > Add landlock_restrict_network() which blocks TCP bind/connect using > Landlock LSM (ABI v4+, kernel 6.7+). Designed to stack with the > existing disable_network() namespace isolation, covering the case > where disable_network() is skipped for non-local UIDs. > > Gracefully returns False on older kernels (ABI < 4). > > Signed-off-by: David Nyström <david.nystrom@est.tech> Hi David, I think adding this is a good idea, but the code needs a few changes to ensure it is maintainable. > --- > lib/bb/utils.py | 26 ++++++++++++++++++++++++++ > 1 file changed, 26 insertions(+) > > diff --git a/lib/bb/utils.py b/lib/bb/utils.py > index 181082c95..1347c29d0 100644 > --- a/lib/bb/utils.py > +++ b/lib/bb/utils.py > @@ -2054,6 +2054,32 @@ def disable_network(uid=None, gid=None): > with open("/proc/self/gid_map", "w") as f: > f.write("%s %s 1" % (gid, gid)) > > +def landlock_restrict_network(): > + """Block TCP bind/connect using Landlock LSM (ABI v4+, kernel 6.7+). > + Gracefully skipped on older kernels. Stacks with disable_network().""" > + > + NR_CREATE = 444 # landlock_create_ruleset > + NR_SELF = 446 # landlock_restrict_self > + NET_TCP = 0x3 # BIND_TCP | CONNECT_TCP We should base these on the names used in the Linux kernel so it's easy to search for things and compare with example C code in the docs. So, NR_landlock_create_ruleset = 444 NR_landlock_add_rule = 445 LANDLOCK_ACCESS_NET_BIND_TCP = 0x1 LANDLOCK_ACCESS_NET_CONNECT_TCP = 0x2 LANDLOCK_CREATE_RULESET_VERSION = 1 > + > + libc = ctypes.CDLL('libc.so.6') > + > + abi = libc.syscall(NR_CREATE, 0, 0, 1) > + if abi < 4: > + return False # Check that landlock is enabled and supports network access # restriction (added in ABI version 4) abi = libc.syscall(NR_landlock_create_ruleset, 0, 0, LANDLOCK_CREATE_RULESET_VERSION) if abi < 4: logger.debug("System doesn't support disabling network via landlock") return False That's a little more verbose, but much clearer. > + > + attr = struct.pack("QQ", 0, NET_TCP) > + buf = ctypes.create_string_buffer(attr) > + fd = libc.syscall(NR_CREATE, buf, len(attr), 0) > + if fd < 0: > + return False We probably also want a logger.debug() call to log the failure here as well. > + > + libc.prctl(38, 1, 0, 0, 0) # PR_SET_NO_NEW_PRIVS The commit message only describes use of landlock, not no_new_privs. We need constants for this call as well. > + r = libc.syscall(NR_SELF, fd, 0) > + os.close(fd) > + return r == 0 > + > + > def export_proxies(d): > from bb.fetch2 import get_fetcher_environment > """ export common proxies variables from datastore to environment """ Thanks, -- Paul Barker [-- Attachment #2: This is a digitally signed message part --] [-- Type: application/pgp-signature, Size: 252 bytes --] ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [bitbake-devel] [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function 2026-06-15 8:28 ` Paul Barker @ 2026-07-17 18:11 ` David Nyström 0 siblings, 0 replies; 10+ messages in thread From: David Nyström @ 2026-07-17 18:11 UTC (permalink / raw) To: Paul Barker; +Cc: David Nyström, bitbake-devel [-- Attachment #1: Type: text/plain, Size: 3903 bytes --] On Mon, 15 Jun 2026, Paul Barker wrote: > On Fri, 2026-06-12 at 13:38 +0200, David Nyström wrote: >> Add landlock_restrict_network() which blocks TCP bind/connect using >> Landlock LSM (ABI v4+, kernel 6.7+). Designed to stack with the >> existing disable_network() namespace isolation, covering the case >> where disable_network() is skipped for non-local UIDs. >> >> Gracefully returns False on older kernels (ABI < 4). >> >> Signed-off-by: David Nyström <david.nystrom@est.tech> > > Hi David, > > I think adding this is a good idea, but the code needs a few changes to > ensure it is maintainable. Thanks for the review, and good comments. My comments below. >> --- >> lib/bb/utils.py | 26 ++++++++++++++++++++++++++ >> 1 file changed, 26 insertions(+) >> >> diff --git a/lib/bb/utils.py b/lib/bb/utils.py >> index 181082c95..1347c29d0 100644 >> --- a/lib/bb/utils.py >> +++ b/lib/bb/utils.py >> @@ -2054,6 +2054,32 @@ def disable_network(uid=None, gid=None): >> with open("/proc/self/gid_map", "w") as f: >> f.write("%s %s 1" % (gid, gid)) >> >> +def landlock_restrict_network(): >> + """Block TCP bind/connect using Landlock LSM (ABI v4+, kernel 6.7+). >> + Gracefully skipped on older kernels. Stacks with disable_network().""" >> + >> + NR_CREATE = 444 # landlock_create_ruleset >> + NR_SELF = 446 # landlock_restrict_self >> + NET_TCP = 0x3 # BIND_TCP | CONNECT_TCP > > We should base these on the names used in the Linux kernel so it's easy > to search for things and compare with example C code in the docs. So, > > NR_landlock_create_ruleset = 444 > NR_landlock_add_rule = 445 > > LANDLOCK_ACCESS_NET_BIND_TCP = 0x1 > LANDLOCK_ACCESS_NET_CONNECT_TCP = 0x2 > > LANDLOCK_CREATE_RULESET_VERSION = 1 +1. >> + >> + libc = ctypes.CDLL('libc.so.6') >> + >> + abi = libc.syscall(NR_CREATE, 0, 0, 1) >> + if abi < 4: >> + return False > > # Check that landlock is enabled and supports network access > # restriction (added in ABI version 4) > abi = libc.syscall(NR_landlock_create_ruleset, > 0, 0, > LANDLOCK_CREATE_RULESET_VERSION) > if abi < 4: > logger.debug("System doesn't support disabling network via landlock") > return False > > That's a litte more verbose, but much clearer. Good point. >> + >> + attr = struct.pack("QQ", 0, NET_TCP) >> + buf = ctypes.create_string_buffer(attr) >> + fd = libc.syscall(NR_CREATE, buf, len(attr), 0) >> + if fd < 0: >> + return False > > We probably also want a logger.debug() call to log the failure here as > well. > >> + >> + libc.prctl(38, 1, 0, 0, 0) # PR_SET_NO_NEW_PRIVS > > The commit message only describes use of landlock, not no_new_privs. We > need constants for this call as well. Also a very good point, setuid/gid and setcap:ed binaries will silently run without privs, which should be documented also in the commit message. This is a landlock requirement for unpriv use, and the main source of potential sideeffects I would expect from this approach. Since there is no way do disable it, without setting the "network" flag on a failing task, I'd really want to gain more confidence about the potential sideeffects of no_new_privs on various edge cases before I send a non-RFC patch. Testing is ongoing with your comments addressed, but I will not be able to finish before my vacation starts(tomorrow). If considered urgent, feel free to use idea only. >> + r = libc.syscall(NR_SELF, fd, 0) >> + os.close(fd) >> + return r == 0 >> + >> + >> def export_proxies(d): >> from bb.fetch2 import get_fetcher_environment >> """ export common proxies variables from datastore to environment """ > > Thanks, > > -- > Paul Barker > > > ^ permalink raw reply [flat|nested] 10+ messages in thread
* [PATCH [RFC] 2/2] bitbake-worker: Call landlock_restrict_network for tasks without network 2026-06-12 11:38 [PATCH RFC 0/2] bitbake: Add basic landlock support David Nyström 2026-06-12 11:38 ` [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function David Nyström @ 2026-06-12 11:38 ` David Nyström 2026-06-15 8:30 ` [bitbake-devel] " Paul Barker 2026-07-16 15:44 ` [bitbake-devel] [PATCH RFC 0/2] bitbake: Add basic landlock support Richard Purdie 2 siblings, 1 reply; 10+ messages in thread From: David Nyström @ 2026-06-12 11:38 UTC (permalink / raw) To: bitbake-devel; +Cc: David Nyström Call bb.utils.landlock_restrict_network() for tasks without the 'network' varflag. This to support basic network restrictions in unprivileged docker containers. Signed-off-by: David Nyström <david.nystrom@est.tech> --- bin/bitbake-worker | 2 ++ 1 file changed, 2 insertions(+) diff --git a/bin/bitbake-worker b/bin/bitbake-worker index aa14ef191..5f3fd9933 100755 --- a/bin/bitbake-worker +++ b/bin/bitbake-worker @@ -287,6 +287,8 @@ def fork_off_task(cfg, data, databuilder, workerdata, extraconfigdata, runtask): bb.utils.disable_network(uid, gid) else: logger.debug("Skipping disable network for %s since %s is not a local uid." % (taskname, uid)) + if not bb.utils.landlock_restrict_network(): + logger.debug("Skipping Landlock network restriction for %s since kernel lacks ABI v4+ support." % taskname) # exported_vars() returns a generator which *cannot* be passed to os.environ.update() # successfully. We also need to unset anything from the environment which shouldn't be there -- 2.53.0 ^ permalink raw reply related [flat|nested] 10+ messages in thread
* Re: [bitbake-devel] [PATCH [RFC] 2/2] bitbake-worker: Call landlock_restrict_network for tasks without network 2026-06-12 11:38 ` [PATCH [RFC] 2/2] bitbake-worker: Call landlock_restrict_network for tasks without network David Nyström @ 2026-06-15 8:30 ` Paul Barker 0 siblings, 0 replies; 10+ messages in thread From: Paul Barker @ 2026-06-15 8:30 UTC (permalink / raw) To: David Nyström, bitbake-devel [-- Attachment #1: Type: text/plain, Size: 1557 bytes --] On Fri, 2026-06-12 at 13:38 +0200, David Nyström wrote: > Call bb.utils.landlock_restrict_network() for tasks without the 'network' > varflag. This to support basic network restrictions in unprivileged > docker containers. > > Signed-off-by: David Nyström <david.nystrom@est.tech> > --- > bin/bitbake-worker | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/bin/bitbake-worker b/bin/bitbake-worker > index aa14ef191..5f3fd9933 100755 > --- a/bin/bitbake-worker > +++ b/bin/bitbake-worker > @@ -287,6 +287,8 @@ def fork_off_task(cfg, data, databuilder, workerdata, extraconfigdata, runtask): > bb.utils.disable_network(uid, gid) > else: > logger.debug("Skipping disable network for %s since %s is not a local uid." % (taskname, uid)) > + if not bb.utils.landlock_restrict_network(): > + logger.debug("Skipping Landlock network restriction for %s since kernel lacks ABI v4+ support." % taskname) In disable_network, the logger.debug() calls for failure are handled within the function instead of by the caller. We should do the same for landlock_restrict_network() as suggested in my reply to patch 1/2 and drop the debug print from here. > > # exported_vars() returns a generator which *cannot* be passed to os.environ.update() > # successfully. We also need to unset anything from the environment which shouldn't be there Best regards, -- Paul Barker [-- Attachment #2: This is a digitally signed message part --] [-- Type: application/pgp-signature, Size: 252 bytes --] ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [bitbake-devel] [PATCH RFC 0/2] bitbake: Add basic landlock support 2026-06-12 11:38 [PATCH RFC 0/2] bitbake: Add basic landlock support David Nyström 2026-06-12 11:38 ` [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function David Nyström 2026-06-12 11:38 ` [PATCH [RFC] 2/2] bitbake-worker: Call landlock_restrict_network for tasks without network David Nyström @ 2026-07-16 15:44 ` Richard Purdie 2026-07-16 15:50 ` David Nyström 2 siblings, 1 reply; 10+ messages in thread From: Richard Purdie @ 2026-07-16 15:44 UTC (permalink / raw) To: david.nystrom, bitbake-devel Hi David, On Fri, 2026-06-12 at 13:38 +0200, David Nyström via lists.openembedded.org wrote: > When current implementation runs in an unprivileged docker container, > basic networking will be allowed by default in all steps, ignoring the > network varflags intention. > Introduce support for landlock blocking of bind and connect, providing > basic support for blocking TCP. > UDP is corrently beeing worked on upstream, but not yet supported. > > Landlock requires PR_SET_NO_NEW_PRIVS to prevent escape, > which is also attempted, this prevents privilege escalation from child. > devshell and related are already tagged with network varflag and > can sudo at will. > > syscall ABI is asm-generic, 5.13+ for all archs except alpha. > On alpha, we leak 2 fd:s in the childs context before graceful exit, > which is cleaned up at child termination. > Don't have an alpha target, so this is not tested, evaluated via > static analysis only. > > Landlock also provides a future possibility for filesystem > limitations with the purpose of catching bugs, and preventing > persistance of supply chain releated payloads. writes to f.ex. > .bashrc and friends. > > Signed-off-by: David Nyström <david.nystrom@est.tech> > --- > David Nyström (2): > utils: Add landlock_restrict_network function > bitbake-worker: Call landlock_restrict_network for tasks without network > > bin/bitbake-worker | 2 ++ > lib/bb/utils.py | 26 ++++++++++++++++++++++++++ > 2 files changed, 28 insertions(+) I think this has generally has positive comments, we just need to take Paul's review comments into account about the magic numbers. Would you be able to send a version with those tweaks? Thanks, Richard ^ permalink raw reply [flat|nested] 10+ messages in thread
* Re: [bitbake-devel] [PATCH RFC 0/2] bitbake: Add basic landlock support 2026-07-16 15:44 ` [bitbake-devel] [PATCH RFC 0/2] bitbake: Add basic landlock support Richard Purdie @ 2026-07-16 15:50 ` David Nyström 0 siblings, 0 replies; 10+ messages in thread From: David Nyström @ 2026-07-16 15:50 UTC (permalink / raw) To: Richard Purdie; +Cc: david.nystrom, bitbake-devel [-- Attachment #1: Type: text/plain, Size: 1955 bytes --] On Thu, 16 Jul 2026, Richard Purdie wrote: > Hi David, > > On Fri, 2026-06-12 at 13:38 +0200, David Nyström via lists.openembedded.org wrote: >> When current implementation runs in an unprivileged docker container, >> basic networking will be allowed by default in all steps, ignoring the >> network varflags intention. >> Introduce support for landlock blocking of bind and connect, providing >> basic support for blocking TCP. >> UDP is corrently beeing worked on upstream, but not yet supported. >> >> Landlock requires PR_SET_NO_NEW_PRIVS to prevent escape, >> which is also attempted, this prevents privilege escalation from child. >> devshell and related are already tagged with network varflag and >> can sudo at will. >> >> syscall ABI is asm-generic, 5.13+ for all archs except alpha. >> On alpha, we leak 2 fd:s in the childs context before graceful exit, >> which is cleaned up at child termination. >> Don't have an alpha target, so this is not tested, evaluated via >> static analysis only. >> >> Landlock also provides a future possibility for filesystem >> limitations with the purpose of catching bugs, and preventing >> persistance of supply chain releated payloads. writes to f.ex. >> .bashrc and friends. >> >> Signed-off-by: David Nyström <david.nystrom@est.tech> >> --- >> David Nyström (2): >> utils: Add landlock_restrict_network function >> bitbake-worker: Call landlock_restrict_network for tasks without network >> >> bin/bitbake-worker | 2 ++ >> lib/bb/utils.py | 26 ++++++++++++++++++++++++++ >> 2 files changed, 28 insertions(+) > > I think this has generally has positive comments, we just need to take > Paul's review comments into account about the magic numbers. Would you > be able to send a version with those tweaks? Yes, thanks for the review, and sorry for the late reply. Will reroll with comments. > Thanks, > > Richard > ^ permalink raw reply [flat|nested] 10+ messages in thread
end of thread, other threads:[~2026-07-17 18:29 UTC | newest] Thread overview: 10+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-06-12 11:38 [PATCH RFC 0/2] bitbake: Add basic landlock support David Nyström 2026-06-12 11:38 ` [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function David Nyström 2026-06-13 11:52 ` [bitbake-devel] " Alexander Kanavin 2026-06-13 14:26 ` Richard Purdie 2026-06-15 8:28 ` Paul Barker 2026-07-17 18:11 ` David Nyström 2026-06-12 11:38 ` [PATCH [RFC] 2/2] bitbake-worker: Call landlock_restrict_network for tasks without network David Nyström 2026-06-15 8:30 ` [bitbake-devel] " Paul Barker 2026-07-16 15:44 ` [bitbake-devel] [PATCH RFC 0/2] bitbake: Add basic landlock support Richard Purdie 2026-07-16 15:50 ` David Nyström
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.