From: "Mickaël Salaün" <mic@digikod.net>
To: "Günther Noack" <gnoack@google.com>
Cc: "Mickaël Salaün" <mic@digikod.net>,
"Masami Hiramatsu" <mhiramat@kernel.org>,
"Mathieu Desnoyers" <mathieu.desnoyers@efficios.com>,
"Paul Moore" <paul@paul-moore.com>,
"Steven Rostedt" <rostedt@goodmis.org>,
bpf@vger.kernel.org, kernel-team@cloudflare.com,
linux-security-module@vger.kernel.org,
linux-trace-kernel@vger.kernel.org
Subject: [PATCH v1 0/9] landlock: Fix tracepoint policy context
Date: Fri, 18 Sep 2026 20:50:23 +0200 [thread overview]
Message-ID: <20260918185036.608651-1-mic@digikod.net> (raw)
Hi,
The Landlock tracepoints added during this development cycle need
correction before their interface reaches a released kernel. For typed
BPF consumers, the number, order, and types of TP_PROTO arguments define
the callback contract and must be correct before release. Topology
denials render as an empty blocker mask, network denials encode one
checked endpoint through ambiguous source and destination port fields,
and callbacks omit the actual ptrace tracer, effective signal, and
add-rule flags.
This series keeps the events focused on Landlock policy context. It
uses kernel fixed-width aliases and derives trace blockers from the same
authoritative request state as audit. Successful add-rule callbacks
carry validated per-call flags and access rights, while growable masks
passed by value use fixed u64 carriers.
The rule events become landlock_add_rule_path_beneath,
landlock_add_rule_net_port, landlock_check_rule_inode, and
landlock_check_rule_net_port. These pre-release renames necessarily
update tracefs paths, typed-BPF attachments, selftests, and
documentation, but avoid carrying misleading names into the released
interface.
Network denial callbacks receive a sanitized copy of the checked
endpoint, and tracefs reports one signed port, with -1 meaning that no
port was checked. Ptrace and signal callbacks receive the actual tracer
and effective signal. Beyond the event-name churn, only blocker and
port rendering changes are visible through tracefs; the remaining
context is available to typed BPF.
The series changes no enforcement decision, UAPI, or audit output.
Event preparation remains behind the existing static-key checks.
Selftests cover the renamed events and both rendering changes, and the
documentation limits the contract to policy context while directing
consumers to generic tracepoints for operational context.
This series applies on top of v7.3-rc3.
Regards,
Mickaël Salaün (9):
landlock: Fix tracepoint fixed-width type names
landlock: Fix filesystem denial blocker reporting
landlock: Fix rule tracepoint context
landlock: Fix network denial trace context
landlock: Report the actual ptrace tracer
landlock: Report the effective signal number
selftests/landlock: Test filesystem denial blockers
selftests/landlock: Test network denial context
landlock: Fix tracepoint contract documentation
Documentation/trace/events-landlock.rst | 52 +--
include/trace/events/landlock.h | 291 ++++++++++-------
security/landlock/fs.c | 10 +-
security/landlock/log.h | 52 ++-
security/landlock/net.c | 42 ++-
security/landlock/task.c | 87 ++++--
security/landlock/trace.c | 71 ++++-
tools/testing/selftests/landlock/fs_test.c | 28 +-
tools/testing/selftests/landlock/net_test.c | 295 ++++++++++--------
tools/testing/selftests/landlock/trace.h | 59 ++--
.../selftests/landlock/trace_fs_test.c | 130 ++++++--
tools/testing/selftests/landlock/trace_test.c | 51 +--
12 files changed, 735 insertions(+), 433 deletions(-)
base-commit: fd73f4a6659897191fa0d40695fe370925dd3780
--
2.55.0
next reply other threads:[~2026-09-18 18:50 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 18:50 Mickaël Salaün [this message]
2026-09-18 18:50 ` [PATCH v1 1/9] landlock: Fix tracepoint fixed-width type names Mickaël Salaün
2026-09-18 18:54 ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 2/9] landlock: Fix filesystem denial blocker reporting Mickaël Salaün
2026-09-18 18:57 ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 3/9] landlock: Fix rule tracepoint context Mickaël Salaün
2026-09-18 19:00 ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 4/9] landlock: Fix network denial trace context Mickaël Salaün
2026-09-18 18:57 ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 5/9] landlock: Report the actual ptrace tracer Mickaël Salaün
2026-09-18 18:56 ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 6/9] landlock: Report the effective signal number Mickaël Salaün
2026-09-18 18:57 ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 7/9] selftests/landlock: Test filesystem denial blockers Mickaël Salaün
2026-09-18 18:57 ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 8/9] selftests/landlock: Test network denial context Mickaël Salaün
2026-09-18 18:58 ` sashiko-bot
2026-09-18 18:50 ` [PATCH v1 9/9] landlock: Fix tracepoint contract documentation Mickaël Salaün
2026-09-18 19:02 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918185036.608651-1-mic@digikod.net \
--to=mic@digikod.net \
--cc=bpf@vger.kernel.org \
--cc=gnoack@google.com \
--cc=kernel-team@cloudflare.com \
--cc=linux-security-module@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=mathieu.desnoyers@efficios.com \
--cc=mhiramat@kernel.org \
--cc=paul@paul-moore.com \
--cc=rostedt@goodmis.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox