From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yx1-f48.google.com (mail-yx1-f48.google.com [74.125.224.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F2684221546 for ; Sun, 9 Aug 2026 15:45:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.224.48 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786290351; cv=none; b=AKmXsCvfJpCO2omB0MLbQ0nneVcG5RKsF4vQViQMYVsJlYiGhlRnxqYirGnKmqj1LAXoWLIRfSL8omk+iXa9lCYfBSWNtKft18xfbu7pN1aliymsKLD4DnVRY5zMSEas7kk35McZybdwVvkYbXLg7zH6q0f5qobqylBYkFJbvDE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786290351; c=relaxed/simple; bh=ysnBicCDwxuO81IecwMGK1tcJiUcuObz1V1IN1LAf14=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-Type; b=amD7yq/6E7i2uGKKW6VXLj+HbMttzRcCS0hpcqkLcrQjnqOW99o9XO52eMHAGWytG7tLLX9DsK5LaLfcJCZ9wDvTkoBuKxgWRLJNX2v8Dw5dD4Q0GMYO4Kl4PVP/KBDZPthU22ypMXvhZw+5Kv+lFItfmtfMQHKxAqSu8Q4EMxs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=pPxFqeg9; arc=none smtp.client-ip=74.125.224.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="pPxFqeg9" Received: by mail-yx1-f48.google.com with SMTP id 956f58d0204a3-66ac4d40da4so1562373d50.2 for ; Sun, 09 Aug 2026 08:45:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786290348; x=1786895148; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=dNmZ44RSWlW8pQ+b91zrT+hdXn4Kmnq58HEKWqOPuH8=; b=pPxFqeg94gwt8ApXbCG8BfwyElgilyIHlampedc4wFC/DJip/4i9k28uqz31167BVq zfAVxtZFod2yABbgOYU8+ZncmdQKNAYd3fqzxcsdgw86V5aO/pv2PBI0z1kSGMM7Pswh BSVD4ubNk/FrF7F7XsRQ6DwLkMVWr/Z1r0Jmpsh5vN7HqKbteeC8C0J+G1wxPkDjGPBj 4/xo5DEsQJcEaEPyVnAJEDoMQmI1SOU62ZWdCHYBzn5MkPZlW1Jpxn+rlfjCvwAb3Y79 lwLd1HBt9VFaSBgxrvQauyW2SvKHass61Qv18nGJltf52QXEp4Pk3blhUFr7qQG/wCjI MlxQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786290348; x=1786895148; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=dNmZ44RSWlW8pQ+b91zrT+hdXn4Kmnq58HEKWqOPuH8=; b=LClgOopt9uOkYKroV7JaXXU2LWNbhJ31artkjc8lQ5AMya92CIwbZbqhz44JGY414V ylKtxev2ND9c64bQFJdZb+mJo2AJ69Wc/TEqXgjh+Mi9JGuO88lHXSlbT3akheiKBtcu Pk5+9T2c5RVimrs6Uc9EPObPyOubDiOgawpMQqKI8/yCowJLtU+04NCMwJtRXvNpHbB3 6EWuxImBruhiFV1wnsDQ13IdLRmvE3DsPDwpLapxP9VZ7ySlRVVwIZdJsjk1nZzXc0lS AjcA1FBv1Z4WJBzVyXk1xRN7sSkTdCKJ+zg+5RCNElnoM0MhDYEbFUinJN0auMJ5WeET NMiQ== X-Gm-Message-State: AOJu0Yy//FchFLMP4NEmHWnfqwzlZhgda/IKcMStKO2eKSNRoVyakTD/ GS8tEuxRrrMJE/g2HvxYoF1kyOlmMZ1neu1OgZYbCG8jHx4dmuJgSmog X-Gm-Gg: AR+sD107nZIWYmqJ0dGfiwIT9GcMNh/a0Uc8UhtROsPxp84yrvluUwi+l8svJHMS3kD Hs1doRQqSjjvD1Xp5afM0DBzvvfjLK7gb07lkDG50SyCpY4NVsmkvuKwIFX37T3V3w67JPfVQw2 dVqRqLnpaHA3Y5JwBYoL7ZRQgQElQWCKuhROSQ/grwAK/uIkCHlQn6r5zvZwNsv8flLBbPvvBxV bhnoNzpHi4JyM1xI3fA3PqwNSC3mpYx4vGFNdxLXtm51Y1PbnbPj3ieqkUZsKlKhOagPoV5j7bn Qnv9+HbPyceg3sgdPhEmYUbs3CLbHA3lvaDlHPIiBYTqzmunBkoHrqNUoxA3/RdNc0va9R+UYoH jgqs7g414p31EcBH4a3BzMt7Hyae8oZj0V67SDxsnNlXCKjYX61ARxDgCURV7zqyClWe2v8fPTQ 2aOVvC8ZSM2bYAo8WxGJIKWStzu2Kdd1/4qZFpwM1fkAkEYuxQGBda058sxh+mgzTelVGxcQ8r0 u/V5yDlLY941ZfpByXT/kxAJDgYOu5Rxg== X-Received: by 2002:a05:690e:408d:b0:667:c09c:4a40 with SMTP id 956f58d0204a3-6699ab8eaf8mr24054809d50.51.1786290347851; Sun, 09 Aug 2026 08:45:47 -0700 (PDT) Received: from zenbox ([2600:1700:18fb:6011:4665:53b0:3ac9:3545]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-66acacdbea9sm4838001d50.3.2026.08.09.08.45.47 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 09 Aug 2026 08:45:47 -0700 (PDT) From: Justin Suess To: gnoack3000@gmail.com, mic@digikod.net Cc: linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, Justin Suess Subject: [PATCH v4 0/5] Implement LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS Date: Sun, 9 Aug 2026 11:45:18 -0400 Message-ID: <20260809154544.1253100-1-utilityemal77@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Howdy This series adds a new landlock_restrict_self(2) flag: LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS. The flag sets the no_new_privs attribute of the calling thread only once the enforcement of the ruleset succeeded: no_new_privs is set if and only if the landlock_restrict_self(2) call succeeds. Semantics: A single call replaces the usual prctl(PR_SET_NO_NEW_PRIVS) + landlock_restrict_self(2) pair. Because no_new_privs is set by the call itself, the no_new_privs/CAP_SYS_ADMIN precondition is fulfilled by construction, so the flag is usable by unprivileged processes. This is safe for the same reason the prctl(2) pair is: the executed programs can either gain privileges or be restricted, never both. The two states cannot diverge. A failed call (invalid ruleset FD, E2BIG, ENOMEM, interrupted TSYNC, ...) leaves no_new_privs unchanged, and a successful call never returns without no_new_privs set: the attribute is set past the last point of failure, right before commit_creds(), which cannot fail. Combined with LANDLOCK_RESTRICT_SELF_TSYNC, no_new_privs is set on all threads with the same guarantee: each sibling thread sets it in the commit phase of the TSYNC protocol, after its all-or-nothing barrier, so either every thread gets both the domain and no_new_privs, or none does. This also makes it possible to set no_new_privs process-wide in one call, which prctl(2) cannot do. The flag requires a ruleset: calls with a ruleset_fd of -1 are rejected. Such a call would be nothing more than a Landlock-flavored prctl(PR_SET_NO_NEW_PRIVS), and rejecting it keeps the option of giving it a meaning later. Following Mickaël's feedback on v3 [1], a new preparatory patch first moves the no_new_privs/CAP_SYS_ADMIN check after the flags check, in the same order as seccomp(2). Unprivileged callers passing unknown flag bits now consistently get EINVAL instead of EPERM, whether or not the new flag is involved; the selftests pin this error ordering. The Landlock ABI version is bumped to 11. Test coverage: base_test checks that a successful call sets no_new_privs without a prior prctl(2) nor CAP_SYS_ADMIN, that a failed call (invalid ruleset FD or layer maximum) leaves it unchanged, that the flag requires a ruleset FD, and the flags-before-privileges error ordering. tsync_test checks, through variants of a common multi_threaded fixture, that TSYNC sets no_new_privs on sibling threads along with the domain, and that a TSYNC call failing on the layer maximum leaves it unset on every thread. Changes since v3: - New preparatory patch: check the landlock_restrict_self(2) flags before the no_new_privs/CAP_SYS_ADMIN requirement, like seccomp(2), per Mickaël's feedback. The EINVAL/EPERM visible change now stems from this patch instead of the new flag. - Folded the minimal selftest changes (ABI version, last-flag, and checks-ordering updates) into the main patch to keep the series bisectable, following the commit tweaked by Mickaël in his next branch. - Dropped the set_no_new_privs local variable; the flag is now checked directly at both use sites. - Turned the multi_threaded_{success,no_new_privs, no_new_privs_max_layers} tests into variants of a common multi_threaded fixture. - Reworded the documentation: removed the ambiguous "it"s in the tutorial paragraph on CAP_SYS_ADMIN, and used the suggested "call (or CAP_SYS_ADMIN use)" wording in both the compatibility section and the uapi kdoc. Per-patch changelogs are below each patch. [1] https://lore.kernel.org/linux-security-module/20260803223109.707353-1-utilityemal77@gmail.com/ Justin Suess (5): landlock: Check landlock_restrict_self(2)'s flags before privileges landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS selftests/landlock: Test LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS landlock: Document LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS samples/landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS to sampler Documentation/userspace-api/landlock.rst | 47 +++++++- include/uapi/linux/landlock.h | 13 +++ samples/landlock/sandboxer.c | 16 ++- security/landlock/limits.h | 2 +- security/landlock/syscalls.c | 35 ++++-- security/landlock/tsync.c | 8 +- security/landlock/tsync.h | 4 +- tools/testing/selftests/landlock/base_test.c | 104 +++++++++++++++++- tools/testing/selftests/landlock/tsync_test.c | 96 ++++++++++++++-- 9 files changed, 283 insertions(+), 42 deletions(-) -- 2.55.0