From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yw1-f181.google.com (mail-yw1-f181.google.com [209.85.128.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 901F33DB658 for ; Fri, 17 Jul 2026 22:03:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.181 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784325820; cv=none; b=UxnCJsR+G0KegKlQsIUwWITTTJg0VRHbAy8dBTMKb7AheDRwr0O3cHHDPHRMNhaFuNAblp6SNV4GFMzZ57xTM3EZs/DirXvTklVPjrqGUAZ8ggWYlY9pOsjynMktwWBCaizmyeCW+hBTNM5J6GM4wRQmiEnfLLvGXRnKT5IH9vI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784325820; c=relaxed/simple; bh=3poomQvjnpiX7997GNYVbUJUsBdzosz9y/dadMphQQo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=fotl1/nL1c0nDbgBxXEgtikK8bt+hqw6wLetKz4qX2h5hc/Lw9idZZ6htAPV23yzXOloxrthphWIlhTkHLammMBPZpoDHMxZzWadqtFeXyzpMbIWLJRizmpfwS7gmua/poy29ekk0EFPtu4I4AgLPXWlJl0UqTr6uW0RcvSWvPw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=HVx/MtE2; arc=none smtp.client-ip=209.85.128.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="HVx/MtE2" Received: by mail-yw1-f181.google.com with SMTP id 00721157ae682-81ec29f1d07so58011657b3.1 for ; Fri, 17 Jul 2026 15:03:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784325814; x=1784930614; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=BotXlHoC1KXrTMIu+7NHh3EH2wogMGqSsV6pAxUtFzQ=; b=HVx/MtE25U9X189aYcv5jTdse8mjs3Uz3YbACwtNP9btF6bvtaWuhSWmr9BxzgapTV uwcadxtnCxcqufQpQ+EhnVEneB75WzS9lkWCfeB/7m5LeNPsKMOoX5PlRkaBYILTnSlL +sfJdEKRj5ii1jB9N721EWVop56hbn0fyrq/Skk3t0x28H1uQMvXs7RLmxH1Z2+j3z+4 P1UctmWW+IghtrL8aH36xtG1+WwrGDOtWkNP5G/Ja8C1BPckO7MrT0tSyZfPEe3VXdyR pL3O1IP/I+nGPT9y5NEYlBUqh4W0x2nVUdSCSEAs4SqXDYTCXI6e2ufMJUsfHHBN1ZQp FOJQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784325814; x=1784930614; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=BotXlHoC1KXrTMIu+7NHh3EH2wogMGqSsV6pAxUtFzQ=; b=icb8PlzB+lw5syFdjznrMkNM71e67epuw+nrr/98aetMDEnu7X2lxX/Equr1ADcxL6 tDOykM1RY5V6o9vUtlUSNOJhRda+mPc9V4P8l6roL6kpr9AZqi4YKInaHYfM9Why8u3D VWepU8KGBuDBFGFpDTyRYfMWvUQTFGatOjG5cmxyvt3ccA04oUmaqjwZpVDYM4LfQPRY jOw/Fkm1VxJ9v7Y0kVO8G+0tltc0MiGh3rtzbkhTh6SzFmJ+Q//hXUDXNHU2iMDbhxHw yycVmQ5mDszaNKtnhGWzuDKqrwPBH5rKP1JiMfXya9osje00J1u170Ipa3jM/vUw38N3 yWyg== X-Gm-Message-State: AOJu0YyuvpCulMuB02GpabYRzfSgcuxjs3VGSXCrOzkV78+DgPTzjTlN PWLRaHO4GKyCV2G1qMCR2imp0i/MXjIsdmec3a6suB34enU/gcGMKI5HxP4ZD74B X-Gm-Gg: AfdE7ckfoqj/CgAvwnw+qsVs+dMBBpJnxa+1ZOod8SQXHmT9VZbX+U4kWpHbSOnLkOo AhvY9ornvYACujGqUKzIZxRe7XfFuR/ua7FHOVZIB6NBPtbdBFx51meJCmKxqrLaHA67N8yutlC 8Vp3YAwjS+/rxkw5ApttwV0OXl479U6QptUn+oVdkxysk+plCVda6XlE4OMnCibgU2zb08tKNwA P40F1wehuyu2y2O/7jrNPtwsRy9iF9g7sb8JCeK+NZdy4+GVqkPcCg0I2JLsGJ/+E6n/6Na3pxQ VHrRohTW7l0wrOC2ffGB6Z6WQsOqS3Xi2ne4XTUvDUTjr8plIQvi0zSjYQ549Sa5uZ58wCWAUgm KPfkYjeqdtBIhsDQs6R/UiDLsGuaxCrE/sEniOcK3wjY336gaoL8QFrmBWccfmru4AHcBNCodzT av61N2w2+VQ0yEHa+Thm3Kd/lG+0kuV9qZcoY= X-Received: by 2002:a05:690c:690b:b0:81e:ad1:8e5b with SMTP id 00721157ae682-81ef26a5cefmr15353267b3.33.1784325814348; Fri, 17 Jul 2026 15:03:34 -0700 (PDT) Received: from zenbox ([2600:1700:18fb:6011:ee56:9b10:53f4:188]) by smtp.gmail.com with ESMTPSA id 00721157ae682-81ef401728asm20572037b3.9.2026.07.17.15.03.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 15:03:33 -0700 (PDT) From: Justin Suess To: gnoack3000@gmail.com, mic@digikod.net Cc: linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, Justin Suess Subject: [PATCH v2 3/3] landlock: Document LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS Date: Fri, 17 Jul 2026 18:03:19 -0400 Message-ID: <20260717220320.1030123-4-utilityemal77@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260717220320.1030123-1-utilityemal77@gmail.com> References: <20260717220320.1030123-1-utilityemal77@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Document atomically setting no_new_privs with ruleset enforcement, following the same compatibility section style as previous ABI additions. Signed-off-by: Justin Suess --- Documentation/userspace-api/landlock.rst | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/Documentation/userspace-api/landlock.rst b/Documentation/userspace-api/landlock.rst index 5a63d4476c1c..ec87d35f4715 100644 --- a/Documentation/userspace-api/landlock.rst +++ b/Documentation/userspace-api/landlock.rst @@ -8,7 +8,7 @@ Landlock: unprivileged access control ===================================== :Author: Mickaël Salaün -:Date: June 2026 +:Date: July 2026 The goal of Landlock is to enable restriction of ambient rights (e.g. global filesystem or network access) for a set of processes. Because Landlock @@ -789,6 +789,18 @@ when at least one sys_landlock_add_rule() call is made for it with the ``LANDLOCK_ADD_RULE_QUIET`` flag, additional add-rule calls for the same object without this flag do not clear it. +Atomic no_new_privs (ABI < 11) +------------------------------ + +Starting with the Landlock ABI version 11, sys_landlock_restrict_self() +accepts the ``LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS`` flag, which sets the +no_new_privs attribute of the calling thread atomically with the enforcement +of the ruleset: no_new_privs is set if and only if the call succeeds. This +removes the need for a prior :manpage:`prctl(2)` ``PR_SET_NO_NEW_PRIVS`` +call, and with it the ``CAP_SYS_ADMIN`` requirement. When combined with +``LANDLOCK_RESTRICT_SELF_TSYNC``, no_new_privs is set on all threads of the +process. + .. _kernel_support: Kernel support -- 2.54.0