From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yx1-f41.google.com (mail-yx1-f41.google.com [74.125.224.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E7EBB247291 for ; Mon, 3 Aug 2026 22:31:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.224.41 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785796278; cv=none; b=eeWY2JI7l1GUc7pvNksByvzntWJIwd684GO2GUcQ0E46YarbXFgRsE4MOOyYBOJFakdayeedwaIdl6+3RQU8HFG1HOp+W9kC63lmi3tHClCs2XI/CvCl5/FaGMb1v1y98aiFULOWLIifb5Tjx+qAY4DmAJJbu0iL6zM8s8fSEQQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785796278; c=relaxed/simple; bh=1+xNfeGufAfHIJ1KzuMNrtv9bAGT3aklmWVl5McL6ZU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=oPdSwCLi2JQ4OcHjEw+Dn8TWWhWvvTXTM0Hs2np8hvMKYwyLIsxbY82TIN81uTNtoWsxxw2foqN6nxGHK9TDXhUJCbSkkpvJlsdy5E8gURHmyudfH3xCrQE0MbcnQE1xzlgmjW4X6P724GIPXBzXDyZrfQxJZ4THQa1mtCSeLXY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=RUvSxo/l; arc=none smtp.client-ip=74.125.224.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="RUvSxo/l" Received: by mail-yx1-f41.google.com with SMTP id 956f58d0204a3-6688acd1a51so5699121d50.3 for ; Mon, 03 Aug 2026 15:31:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785796276; x=1786401076; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=afm3+c41sVqLp4fqwT0idATUxQKf9FXqPjm27Wnr+iM=; b=RUvSxo/lb82rK+L14opSMz5zml/R350Wh1/7lW1ZsndWxgyOpFweKTmi9lDaqQCLik Aanwe/AJvcIBGXI6dRjYzQSCzaQ21yNO4VDyTN7RCs4IBvCeyxyPh3XAJCro8Wt6tdyn QM6Plmnk5lxk+MkLctQrvRel1UeaBfIOSX5oVwpdSQNahhV3V4Qt1fvL4zjVyXzKqmyb 8elUOD3xacBufNXQkAuQUXAjb7W5VAbC0YH2H7blOZ/Vd7VtS5HSOAaWbt/nCMordLiQ 9Ob0oSC+tKZYjL6ytxEIoZdcic4f6TNUDR+0E3dNAhwVbx+dxh+b5VEW+6+6W72ba8vu DNdQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785796276; x=1786401076; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=afm3+c41sVqLp4fqwT0idATUxQKf9FXqPjm27Wnr+iM=; b=S21JifScvKABwGwoeQSldbQz+ELsacwV+plggm2Fnu5XcnVQi5Mw+itySCS/fnLPk5 shZ253OSpNGMHrqtRKVlIVKlt2SAWw2ZvaUJdJXOCka8RdYRwUpft0N/E9fsCuGPSj1q hlyyatMdHY9Ho6AViFVRtSSyV6qMX7SXe8vtxDwvqMIWnk5ATE1TU5F+KCzdiXduv7Wn oF89TFEOZNlbt1LiJI0KysdLdLxLkK/MpfnS6eDVkRWbz2MHTYsKEzEorAKIR268noiV lf4Cdi2sH7F4ylrepRzR4DAkUefYfUfXWJdwjesduBjfnElDBIHOZZ33Ana4gWsgtpT6 SHcw== X-Gm-Message-State: AOJu0YxRtH2B0dzCURADhc5xBgcvsEk7wh1Zd2MgWFGn4WtRIZ/T2sO2 TnBTrKyOdEC5p+e3mJSeLEtPI5cY8/Tm9wXIgzjYkAQFD5voCkKBjmq8 X-Gm-Gg: AR+sD10iM3EwO/OfvYLxWc5PpAu4rkDez50aiymY4eQla4M31qLkjbi5awT45LWljd8 nfjKdUkhlwB5ZI0YLAI3gHrZwdYDVX/XLyFtXbPf/p0IXMrjdf+DfM0NluM7zj/lpFLqB5AhtGC rZRYPFEOOlTegIUXCOcMIkUVwpCKHlS3RSKybYwPrFIyKxaN7YDdIiBi9uNufGRDujQDL8vj1ej 1vzrvon4y6Kv0ENNZE7mtQ7L9TVk8LkZH+8V2FpW1MgrNziuVmadIZtb1wZiH20Yg2lI2cg5YZ3 sk/lmZvPax2MGWupsKYEegRvi7sQCmZLvrrAVRaA7mrVv9MHU5BvX/Kzp0RZqHzd48YKEjCAB8c mIN0WFs+SCIa/9i0MEPcHeSTdouijXFYlqk3Yk37yZ/WAQVUqSpA+thTqITjdO1suouwcjn6AB5 YA5/7x08qNldw5mMo2Om/ZCZNEZnqvn5nWCarlMBgJmhh0GBi8yBcnvjApWkMDqpZZOLPYEBL6+ +WIJbmrgg1jCS1+lvilq3I= X-Received: by 2002:a05:690e:810:10b0:668:9b6a:652d with SMTP id 956f58d0204a3-6694efe0eb1mr11750066d50.3.1785796275754; Mon, 03 Aug 2026 15:31:15 -0700 (PDT) Received: from zenbox ([2600:1700:18fb:6011:6253:b407:801c:a745]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-6694903782fsm6420774d50.21.2026.08.03.15.31.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 15:31:15 -0700 (PDT) From: Justin Suess To: gnoack3000@gmail.com, mic@digikod.net Cc: linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, Justin Suess Subject: [PATCH v3 1/4] landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS Date: Mon, 3 Aug 2026 18:31:05 -0400 Message-ID: <20260803223109.707353-2-utilityemal77@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260803223109.707353-1-utilityemal77@gmail.com> References: <20260803223109.707353-1-utilityemal77@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Add a landlock_restrict_self(2) flag to set the no_new_privs attribute of the calling thread only after enforcement of the ruleset: no_new_privs is set if and only if the call succeeds. This removes the need for a prior prctl(2) PR_SET_NO_NEW_PRIVS call and guarantees that a failed enforcement leaves the attribute unchanged. Because no_new_privs is set by the call itself, the no_new_privs / CAP_SYS_ADMIN requirement of landlock_restrict_self(2) is fulfilled by construction, and the related EPERM check is skipped. As a consequence, an unprivileged caller passing unknown flags along with this flag gets EINVAL instead of EPERM. Unlike LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF, this flag always requires a valid ruleset: with a ruleset_fd of -1, such a call would be nothing more than a Landlock-flavored prctl(2) PR_SET_NO_NEW_PRIVS, and there is no valid use case for setting no_new_privs (possibly with LANDLOCK_RESTRICT_SELF_TSYNC) without also enforcing Landlock restrictions. Rejecting these calls also keeps the option of giving them a meaning later. The attribute is only set past the last point of failure, just before committing the new credentials. When combined with LANDLOCK_RESTRICT_SELF_TSYNC, no_new_privs is set on the sibling threads as well, in their commit phase, with the same ordering. Bump the Landlock ABI version to 11. Cc: Mickaël Salaün Signed-off-by: Justin Suess --- Notes: v2->v3: - Reword "atomically" to the ordering guarantee (no_new_privs is only set once enforcement succeeded) in the commit message and both kdocs - Explain in the commit message why the flag requires a valid ruleset include/uapi/linux/landlock.h | 13 +++++++++++++ security/landlock/limits.h | 2 +- security/landlock/syscalls.c | 28 +++++++++++++++++++++------- security/landlock/tsync.c | 8 ++++++-- security/landlock/tsync.h | 4 +++- 5 files changed, 44 insertions(+), 11 deletions(-) diff --git a/include/uapi/linux/landlock.h b/include/uapi/linux/landlock.h index 27ae3f39cafb..11bf600698f0 100644 --- a/include/uapi/linux/landlock.h +++ b/include/uapi/linux/landlock.h @@ -191,12 +191,25 @@ struct landlock_ruleset_attr { * * If the calling thread is running with no_new_privs, this operation * enables no_new_privs on the sibling threads as well. + * + * The following flag ties the no_new_privs attribute to the ruleset + * enforcement: + * + * %LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS + * Sets the no_new_privs attribute of the calling thread only once the + * enforcement of the ruleset succeeded: no_new_privs is set if and only + * if sys_landlock_restrict_self() succeeds. This removes the need for a + * prior :manpage:`prctl(2)` ``PR_SET_NO_NEW_PRIVS`` call, and with it the + * %CAP_SYS_ADMIN requirement. This flag requires a ruleset. When + * combined with %LANDLOCK_RESTRICT_SELF_TSYNC, no_new_privs is set on the + * sibling threads as well. */ /* clang-format off */ #define LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF (1U << 0) #define LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON (1U << 1) #define LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF (1U << 2) #define LANDLOCK_RESTRICT_SELF_TSYNC (1U << 3) +#define LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS (1U << 4) /* clang-format on */ /** diff --git a/security/landlock/limits.h b/security/landlock/limits.h index 08d5f2f6d321..1a7c5fb8f6fd 100644 --- a/security/landlock/limits.h +++ b/security/landlock/limits.h @@ -34,7 +34,7 @@ #define LANDLOCK_NUM_ACCESS_MAX \ MAX(MAX(LANDLOCK_NUM_ACCESS_FS, LANDLOCK_NUM_ACCESS_NET), LANDLOCK_NUM_SCOPE) -#define LANDLOCK_LAST_RESTRICT_SELF LANDLOCK_RESTRICT_SELF_TSYNC +#define LANDLOCK_LAST_RESTRICT_SELF LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS #define LANDLOCK_MASK_RESTRICT_SELF ((LANDLOCK_LAST_RESTRICT_SELF << 1) - 1) /* clang-format on */ diff --git a/security/landlock/syscalls.c b/security/landlock/syscalls.c index 36b02892c62f..e97f944109f9 100644 --- a/security/landlock/syscalls.c +++ b/security/landlock/syscalls.c @@ -169,7 +169,7 @@ static const struct file_operations ruleset_fops = { * If the change involves a fix that requires userspace awareness, also update * the errata documentation in Documentation/userspace-api/landlock.rst . */ -const int landlock_abi_version = 10; +const int landlock_abi_version = 11; /** * sys_landlock_create_ruleset - Create a new ruleset @@ -502,21 +502,28 @@ SYSCALL_DEFINE4(landlock_add_rule, const int, ruleset_fd, * - %LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON * - %LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF * - %LANDLOCK_RESTRICT_SELF_TSYNC + * - %LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS * * This system call enforces a Landlock ruleset on the current thread. * Enforcing a ruleset requires that the task has %CAP_SYS_ADMIN in its * namespace or is running with no_new_privs. This avoids scenarios where * unprivileged tasks can affect the behavior of privileged children. * + * With %LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS, the no_new_privs attribute of the + * calling thread is set only once the enforcement of the ruleset succeeded, + * which fulfills the above requirement: no_new_privs is set if and only if the + * call succeeds. + * * Return: 0 on success, or -errno on failure. Possible returned errors are: * * - %EOPNOTSUPP: Landlock is supported by the kernel but disabled at boot time; * - %EINVAL: @flags contains an unknown bit. * - %EBADF: @ruleset_fd is not a file descriptor for the current thread; * - %EBADFD: @ruleset_fd is not a ruleset file descriptor; - * - %EPERM: @ruleset_fd has no read access to the underlying ruleset, or the - * current thread is not running with no_new_privs, or it doesn't have - * %CAP_SYS_ADMIN in its namespace. + * - %EPERM: @ruleset_fd has no read access to the underlying ruleset, or + * %LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS is not set while the current thread + * is not running with no_new_privs and doesn't have %CAP_SYS_ADMIN in its + * namespace. * - %E2BIG: The maximum number of stacked rulesets is reached for the current * thread. * @@ -529,6 +536,8 @@ SYSCALL_DEFINE2(landlock_restrict_self, const int, ruleset_fd, const __u32, struct landlock_ruleset *ruleset __free(landlock_put_ruleset) = NULL; struct cred *new_cred; struct landlock_cred_security *new_llcred; + const bool set_no_new_privs = + !!(flags & LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS); bool __maybe_unused log_same_exec, log_new_exec, log_subdomains, prev_log_subdomains; @@ -537,9 +546,10 @@ SYSCALL_DEFINE2(landlock_restrict_self, const int, ruleset_fd, const __u32, /* * Similar checks as for seccomp(2), except that an -EPERM may be - * returned. + * returned. LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS fulfills this + * requirement. */ - if (!task_no_new_privs(current) && + if (!set_no_new_privs && !task_no_new_privs(current) && !ns_capable_noaudit(current_user_ns(), CAP_SYS_ADMIN)) return -EPERM; @@ -620,12 +630,16 @@ SYSCALL_DEFINE2(landlock_restrict_self, const int, ruleset_fd, const __u32, if (flags & LANDLOCK_RESTRICT_SELF_TSYNC) { const int err = landlock_restrict_sibling_threads( - current_cred(), new_cred); + current_cred(), new_cred, flags); if (err) { abort_creds(new_cred); return err; } } + /* Sets no_new_privs past the last point of failure. */ + if (set_no_new_privs) + task_set_no_new_privs(current); + return commit_creds(new_cred); } diff --git a/security/landlock/tsync.c b/security/landlock/tsync.c index c5730bbd9ed3..0b71e158c3f5 100644 --- a/security/landlock/tsync.c +++ b/security/landlock/tsync.c @@ -17,6 +17,7 @@ #include #include #include +#include #include "cred.h" #include "tsync.h" @@ -466,7 +467,8 @@ static void cancel_tsync_works(const struct tsync_works *works, * restrict_sibling_threads - enables a Landlock policy for all sibling threads */ int landlock_restrict_sibling_threads(const struct cred *old_cred, - const struct cred *new_cred) + const struct cred *new_cred, + const u32 restrict_flags) { int err; struct tsync_shared_context shared_ctx; @@ -481,7 +483,9 @@ int landlock_restrict_sibling_threads(const struct cred *old_cred, init_completion(&shared_ctx.all_finished); shared_ctx.old_cred = old_cred; shared_ctx.new_cred = new_cred; - shared_ctx.set_no_new_privs = task_no_new_privs(current); + shared_ctx.set_no_new_privs = + (restrict_flags & LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS) || + task_no_new_privs(current); /* * Serialize concurrent TSYNC operations to prevent deadlocks when diff --git a/security/landlock/tsync.h b/security/landlock/tsync.h index ef86bb61c2f6..2ae4f938ca00 100644 --- a/security/landlock/tsync.h +++ b/security/landlock/tsync.h @@ -9,8 +9,10 @@ #define _SECURITY_LANDLOCK_TSYNC_H #include +#include int landlock_restrict_sibling_threads(const struct cred *old_cred, - const struct cred *new_cred); + const struct cred *new_cred, + u32 restrict_flags); #endif /* _SECURITY_LANDLOCK_TSYNC_H */ -- 2.54.0