From: "Mickaël Salaün" <mic@digikod.net>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: "Mickaël Salaün" <mic@digikod.net>,
"Christian Brauner" <brauner@kernel.org>,
"Doehyun Baek" <doehyunbaek@gmail.com>,
"Günther Noack" <gnoack3000@gmail.com>,
"Günther Noack" <gnoack@google.com>,
"Justin Suess" <utilityemal77@gmail.com>,
"Tingmao Wang" <m@maowtm.org>, "Wang Yan" <wangyan01@kylinos.cn>,
linux-kernel@vger.kernel.org,
linux-security-module@vger.kernel.org
Subject: [GIT PULL] Landlock update for v7.3-rc1
Date: Thu, 20 Aug 2026 11:12:08 +0200 [thread overview]
Message-ID: <20260820091208.1001980-1-mic@digikod.net> (raw)
Hi,
This PR improves observability with Landlock tracepoints support, which
required some refactoring for dedicated domain types and common helpers shared
with audit code. A LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS flag is also added to
improve process-wide domain enforcement consistency. Whiteout files are now
correctly handled and tested, and a few other fixes complete this PR.
Please pull these changes for v7.3-rc1 . These commits merge cleanly
with your master branch. Most kernel changes have been tested in the
latest linux-next releases for some weeks, and I recently updated commit
messages to reflect latest reviews.
Test coverage for security/landlock is 91.6% of 2571 lines according to
LLVM 22, and it was 91.8% of 2357 lines before this PR.
Regards,
Mickaël
--
The following changes since commit 075b74841bd0065a3bda3440873c747938e69b68:
Linux 7.2-rc6 (2026-08-02 16:24:24 -0700)
are available in the Git repository at:
https://git.kernel.org/pub/scm/linux/kernel/git/mic/linux.git tags/landlock-7.3-rc1
for you to fetch changes up to 172b6a6d8463562b0cbebfd66f770b078f81966b:
landlock: Document tracepoints (2026-08-17 10:17:19 +0200)
----------------------------------------------------------------
Landlock update for v7.3-rc1
----------------------------------------------------------------
Doehyun Baek (1):
landlock: Document fs.resolve_unix audit blocker
Günther Noack (7):
landlock: Documentation wording cleanups
selftests/landlock: Use an actual chardev for MAKE_CHAR audit test
landlock: Require LANDLOCK_ACCESS_FS_MAKE_REG for whiteout creation
selftests/landlock: Add tests for whiteout object creation
selftests/landlock: Add audit test for whiteout object creation
selftests/landlock: Test whiteout object behaviour in OverlayFS renames
landlock: Link the erratum documentation for whiteout objects
Justin Suess (5):
landlock: Check landlock_restrict_self(2)'s flags before privileges
landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
selftests/landlock: Test LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
landlock: Document LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS
samples/landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS to sampler
Mickaël Salaün (20):
landlock: Harden sock_is_scoped() against file-less sockets
landlock: Prepare ruleset and domain type split
landlock: Move domain query functions to domain.c
landlock: Split struct landlock_domain from struct landlock_ruleset
landlock: Split denial logging from audit into common framework
landlock: Decouple the per-denial logging decision from CONFIG_AUDIT
landlock: Consolidate access-right and scope names in a shared header
landlock: Add create_ruleset and free_ruleset tracepoints
landlock: Add landlock_add_rule_fs and landlock_add_rule_net tracepoints
landlock: Add create_domain and free_domain tracepoints
landlock: Add landlock_enforce_domain tracepoint
landlock: Add tracepoints for rule checking
landlock: Add landlock_deny_access_fs and landlock_deny_access_net
landlock: Add tracepoints for ptrace and scope denials
selftests/landlock: Add trace event test infrastructure and tests
selftests/landlock: Add filesystem tracepoint tests
selftests/landlock: Add network tracepoint tests
selftests/landlock: Add scope and ptrace tracepoint tests
selftests/landlock: Add landlock_enforce_domain trace tests
landlock: Document tracepoints
Wang Yan (1):
selftests/landlock: Fix spelling error in fs_test comment
Documentation/admin-guide/LSM/landlock.rst | 106 +-
Documentation/security/landlock.rst | 38 +-
Documentation/trace/events-landlock.rst | 326 ++++
Documentation/trace/index.rst | 1 +
Documentation/userspace-api/landlock.rst | 62 +-
MAINTAINERS | 3 +
include/linux/landlock.h | 56 +
include/trace/events/landlock.h | 965 ++++++++++++
include/uapi/linux/landlock.h | 22 +-
samples/landlock/sandboxer.c | 16 +-
security/landlock/Kconfig | 5 +
security/landlock/Makefile | 12 +-
security/landlock/access.h | 6 +-
security/landlock/audit.c | 641 +-------
security/landlock/audit.h | 57 +-
security/landlock/cred.c | 14 +-
security/landlock/cred.h | 29 +-
security/landlock/domain.c | 472 +++++-
security/landlock/domain.h | 163 +-
security/landlock/errata/abi-1.h | 23 +
security/landlock/fs.c | 259 +++-
security/landlock/fs.h | 40 +-
security/landlock/id.h | 6 +-
security/landlock/limits.h | 2 +-
security/landlock/log.c | 587 +++++++
security/landlock/log.h | 86 ++
security/landlock/net.c | 38 +-
security/landlock/ruleset.c | 546 +------
security/landlock/ruleset.h | 250 +--
security/landlock/syscalls.c | 125 +-
security/landlock/task.c | 87 +-
security/landlock/trace.c | 185 +++
security/landlock/trace.h | 44 +
security/landlock/tsync.c | 24 +-
security/landlock/tsync.h | 4 +-
tools/testing/selftests/landlock/audit.h | 35 -
tools/testing/selftests/landlock/base_test.c | 104 +-
tools/testing/selftests/landlock/common.h | 47 +
tools/testing/selftests/landlock/config | 2 +
tools/testing/selftests/landlock/fs_test.c | 738 ++++++++-
tools/testing/selftests/landlock/net_test.c | 590 ++++++-
tools/testing/selftests/landlock/ptrace_test.c | 402 +++++
.../selftests/landlock/scoped_abstract_unix_test.c | 264 ++++
.../selftests/landlock/scoped_signal_test.c | 404 +++++
tools/testing/selftests/landlock/trace.h | 639 ++++++++
tools/testing/selftests/landlock/trace_fs_test.c | 496 ++++++
tools/testing/selftests/landlock/trace_test.c | 1620 ++++++++++++++++++++
tools/testing/selftests/landlock/true.c | 10 +
tools/testing/selftests/landlock/tsync_test.c | 96 +-
49 files changed, 9244 insertions(+), 1503 deletions(-)
create mode 100644 Documentation/trace/events-landlock.rst
create mode 100644 include/linux/landlock.h
create mode 100644 include/trace/events/landlock.h
create mode 100644 security/landlock/log.c
create mode 100644 security/landlock/log.h
create mode 100644 security/landlock/trace.c
create mode 100644 security/landlock/trace.h
create mode 100644 tools/testing/selftests/landlock/trace.h
create mode 100644 tools/testing/selftests/landlock/trace_fs_test.c
create mode 100644 tools/testing/selftests/landlock/trace_test.c
reply other threads:[~2026-08-20 11:00 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260820091208.1001980-1-mic@digikod.net \
--to=mic@digikod.net \
--cc=brauner@kernel.org \
--cc=doehyunbaek@gmail.com \
--cc=gnoack3000@gmail.com \
--cc=gnoack@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=m@maowtm.org \
--cc=torvalds@linux-foundation.org \
--cc=utilityemal77@gmail.com \
--cc=wangyan01@kylinos.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox