From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f178.google.com (mail-yw1-f178.google.com [209.85.128.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1C7C1367B8B for ; Fri, 29 May 2026 01:52:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.178 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780019559; cv=none; b=DchRyBsURYnzQMJuARQNNGq4R8I40DAzNSyxTZoJL4WGOyklDhGwjueM3gnycIIH73s07bPGeaBlkojCkvucr5o8PMLG93PZPHw7ehe977iJofUC/1X8uPlDUJwd0l442PGR6N8cdVOEx141dlDpz4KedyBJ+xDUYokAs5xVUx0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780019559; c=relaxed/simple; bh=trxUybHguCoxohnEyn58jFksS/yEq5TOeiwsKGYCY7Q=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=HE35qQPTMiXhbGfUUhJxMadLVaCggERYOb5EBN2uk7g9FZff28j5znCtQHy9jIkhyJDhKyzCz1j3g2znPf7tmp9uiRPhdSsm/Jj5yFvQL8gRZEHHrodut5u2LL2YeIizHyE192n6mUhpK9XqlxH0ESTwIfCBxirHbcm/pueofbY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=aUbnCoZS; arc=none smtp.client-ip=209.85.128.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="aUbnCoZS" Received: by mail-yw1-f178.google.com with SMTP id 00721157ae682-7cb345cb5bfso114277067b3.0 for ; Thu, 28 May 2026 18:52:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780019557; x=1780624357; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=weKJSMUU3m3+uwtuJiUMz+guBFkag//BiZTgAufcbA0=; b=aUbnCoZSirKaIyvQ4P8dEJJuEPuKrBI2hAt0EJ0OuIzVxE7vC5XgPKCaZ+xCPgBHlk /YQtG82eTjzlHIk8ZluXWwqsOLa18Ih9unMgw8kIoWwrkMZZw1UDM7WeOU39pZ4sJfot ZM4LEoT4PbA7vRNX8TwpFPfCme3m/fw619BsICEcN969nowY0QMMSzzE/T9QjvE4ddk1 jSGrm3HdMd7idDnhQa3/abl3+9rEIdtHKAhpJTCZwzVWKHG8AE3UDWaAm6TOjAgC4YqT mAzf8pcnC2O8m7BLxGq7KogjXgqh0Xo45jg7kZIrkmH7C3mWuHCO9z7M2K54sq+osqc3 lucA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780019557; x=1780624357; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=weKJSMUU3m3+uwtuJiUMz+guBFkag//BiZTgAufcbA0=; b=EmRbfjfMq/BDzHXzQ+JRO4R5V4nlHeHpGSzruFZ/WKiPFFxuqFTxVjMcCJGoZeoaI0 p4fvZa3AhXqLboaeNB045sCoKM4jToj/+3O0x4Y5XnBa710x7x7ys1Bul2Uo+uvHaplE R5+0QB4KbUo/oPW6o6H/j+hWZJkpw7I6rB5nPM1c6xoO2KVnTytHDcokMTQ32R8KDbkY i7eBEymm+eAA4ylaFG5C/I1PGbKrC6Y8I9+5l6kwps0js/i2Du7Q1yLTEeMIus4UxMgC bGfrCqopX5x2XUJ5boemwUmL0zindQ1ck8n5gQFXmOxk9kh3f6codInxUV/PhCOJqBVH NdYA== X-Gm-Message-State: AOJu0Yx9QA0Kdh7QqddnPnaPpdbH9s3yby5jRg6nOJ7Ltoyj50EOxTNR kvCbaOete6cvjotj67+2dD0K9zkCcniNI1clsOzIl/IMa7203cXfMFML X-Gm-Gg: Acq92OEjUc7gaAnPE9pCIGQGzIG94NoVVkJ6aZBVxYOEGTyjOnbJKEY2H/XYUOukUPc Brv73gxYq38QCtrsxnXx2sEEF2KaiyuHI3enzenMLf9mfvS8WBC7CJllkwrBR1/lLD4iTw1hkD6 36puaeXl1m0POwwj2wUtSODtawDMi6/iWjm1sEyQdRD0E9b9JYUQ5jARi8s6Lx7MWlEmL+IUXbq 99fyM3+510cY2EDPnZ30FQJsWDK84PMLxH3fPgujAQMXeU1usmvNTMYq8D46J6pf4A6KB7906/Z xapoMXVHtIig3CnVZfqjrc8h6V3QPtQPy8dL4aAPj+d0+lS03taZzdP0h/32MDwLb5uHexihEPl LkOpX7WF73P7mau4rH8zrygaeJswcQyI42MuMea7/SRlLYah8fyYHowKqUcCDVeJrykf1g6PyIC f1bpDTmJR0koAIU9wWAhgNNAlY2KlPZTyeR4Cjo20rnDCUSTHeLYAZ6pCXThq3xfp3VAos1N/du YXOk+fjeHc= X-Received: by 2002:a05:690c:e3c8:b0:7dc:d9cd:1770 with SMTP id 00721157ae682-7de47474a55mr7395727b3.22.1780019557221; Thu, 28 May 2026 18:52:37 -0700 (PDT) Received: from zenbox.prizrak.me ([2600:1700:18fb:6011:7a41:d368:8442:1cb2]) by smtp.gmail.com with ESMTPSA id 00721157ae682-7de6d1f3943sm1284717b3.26.2026.05.28.18.52.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 28 May 2026 18:52:37 -0700 (PDT) From: Justin Suess To: gnoack3000@gmail.com, mic@digikod.net Cc: linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, Justin Suess Subject: [PATCH v8 07/10] landlock: Add documentation for LANDLOCK_ADD_RULE_NO_INHERIT Date: Thu, 28 May 2026 21:52:06 -0400 Message-ID: <20260529015210.500291-8-utilityemal77@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260529015210.500291-1-utilityemal77@gmail.com> References: <20260529015210.500291-1-utilityemal77@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Adds documentation of the flag to the userspace api, describing the functionality of the flag and parent directory protections. Signed-off-by: Justin Suess --- Notes: v7..v8 changes: * Minor wording polish in the new 'Filesystem inheritance suppression' documentation section; no semantic change. Documentation/userspace-api/landlock.rst | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/Documentation/userspace-api/landlock.rst b/Documentation/userspace-api/landlock.rst index 138d504cb498..ae3136461b18 100644 --- a/Documentation/userspace-api/landlock.rst +++ b/Documentation/userspace-api/landlock.rst @@ -733,6 +733,24 @@ struct landlock_ruleset_attr. It is also now possible to suppress audit logs for scope accesses via the ``quiet_scoped`` field of struct landlock_ruleset_attr. +Filesystem inheritance suppression (ABI < 10) +--------------------------------------------- + +Starting with the Landlock ABI version 10, it is possible to prevent a +directory or file from inheriting its parent's access grants by using the +``LANDLOCK_ADD_RULE_NO_INHERIT`` flag passed to sys_landlock_add_rule(). +This is useful for policies where a parent directory needs broader access +than its children. + +To mitigate sandbox-restart attacks, the tagged inode and all of its +ancestors up to the VFS root cannot be removed, renamed, reparented, or +linked into or out of other directories. + +Inheritance of access grants from descendants of an inode tagged with +``LANDLOCK_ADD_RULE_NO_INHERIT`` is unaffected: such descendants continue +to inherit from the tagged inode normally, unless they also carry this +flag. + .. _kernel_support: Kernel support -- 2.53.0