From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ed1-f49.google.com (mail-ed1-f49.google.com [209.85.208.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 04F0922068D for ; Wed, 22 Jul 2026 12:29:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723401; cv=none; b=Qy0A0367zDZ0BJ7SHf9XNM7+H6ToUca6YJEdbf10cEWQR016SZdNctFgq5uGKCXY2crFT1kDDq1Zeuya2xoCaRTBnfM9LMCY8XOtzx/w7OnLwN5V+zck+0/uO8Y/2FdezNIGD3wGW1ruQu95zKHdLQBGe0RutHvBSF+lDhmGsdc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723401; c=relaxed/simple; bh=BGaFEx/f8mWLlH9deEEI1cp74nO5obRywMCSftusmHc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=pX9HVRvK7uhKy02O9TaoN7NRZcgq1fkOuCDQhR2PRGMdMr/7uZavkMDSAZU4r6p2BD2N7Byrw/m+n3YTyP+ZbcsBiD6iWQzyl7kbCWQDzfgZuu5jEexjrzn/qOWysJsdwjud3jbQ23aTqEUFWk3sOzoIuqZ8hL/7sLZs5R6s6Zw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com; spf=pass smtp.mailfrom=cloudflare.com; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b=T5B0zMsG; arc=none smtp.client-ip=209.85.208.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b="T5B0zMsG" Received: by mail-ed1-f49.google.com with SMTP id 4fb4d7f45d1cf-69e8ea2783aso6151133a12.3 for ; Wed, 22 Jul 2026 05:29:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google09082023; t=1784723398; x=1785328198; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=CGBJ0cI+WS5k0v0KKJxbb2IZYZWx9jLy469rhtaxBA8=; b=T5B0zMsGhDp8h/zU5gSGORVftzSWVKFuYjh/YSM4glmpHM4g+CX6YzH/741YKaJFCJ g/vX7bcMf7i9Yt7SsL/7nqIGzxdSMb1EbwIrzlW5bgRCcdRCUdLg+ZX9tfiZ0yTY+daI YFS9OTpvj2qOJ1JOJoZTOlS+o0W/WbBFOHqwkQpi6tUpcjs9sTAnS5O7zX7Sveng/Xd8 ic/wWn0rAqorlT3KxyQDyYcsbaLcx4tOWzrlJg7OIMxsiM7+c5nX8rBMYlEG6Fes/AnZ HOhN5Xg/RtgsvscSGRIf6t3aWH1YEx/iDn+BkNbs3aHgtUcvESgFc6asLETy+qN8eDn7 Zomw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723398; x=1785328198; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=CGBJ0cI+WS5k0v0KKJxbb2IZYZWx9jLy469rhtaxBA8=; b=rAGWpmI6ytOWesEntNXLXvlF6rHSiRw7vPAO9oZ2tmn/NkArQ8sjAz6ncxaBHEEuIQ OcVe4q0jJWqq//jDaY+PRTAyXEKQhZn4HyTHQ4ZnIY97pSTWB1y/5fiksL82dIDAuqhX xAYvno/Z8AIkN+HrFaC4Oa1LBJt+hNIP5eFBxizUBnoUVp4rw3HKduy+hM8RKHT612Wb SIbGDf2D1rAVOt9Flyj0onYyjzE7BF1Ka94l536H9J5JrpcN4rql46bLI1G22WNe8cRd 5lXa+AxK8YjLxW+zxICVUPkfsxlfhR7s5+A+84gJr3mE5IThQXzrFmg0kW4tdRQkMdJj eEFQ== X-Forwarded-Encrypted: i=1; AHgh+RoLsMRHaZTVuXvXVIQL+ugqmdO2w8EIfHNaYBQHs7YeG89cplPGmglWfj9HK9ldmorgAWR3UeEyVrZC390=@vger.kernel.org X-Gm-Message-State: AOJu0YwYXipzdmNqAnL6UcujaW+b7CmjZAzvS37cMrgOUVaFjnbfCUyT DOXs/zP7jERMWX0/0caMsC6vpRijIkJqErLYBBQPo5LorLtV29MQpg0jeIMBfr2UK1E= X-Gm-Gg: AR+sD13p+ZoqCRTqBr15737q1CXIWdDdf79zW2HMh1O0iDOTTXvYSmZlFaWGuIKDnQS tHRV7mp8fgid67sClZQiq6tstrQ4v84uhT6iSUKTxTYKzA6tw3mHhHtqbzEPS/V+ElMeyb+xwgB B21TSOFAXfnPPgpyzbUlCd5Wj5f/uCf3QT7rhim+/81ld9JhlINHT1dz+qVJE1Kf3TLxNWu0jFE 9/GW6X6WXZRT6sFpr8m4wycgH0FPQSf01I7TUDTdv/X6mQJ4xg4I24F/z9h6nH2ew0udm/jvORX GWOEnqQLY7u3BAvsXIfepgNTj5pyrtNtmtMe1LQj4c/cvAlP9vdPdx5/K/V59q9EPODpI9C3AGY HZ/Nury6byD/pxAWPNN+vHCkwtUDxnAcTLJOSmX5R+ha+jsFxByhPQ1MahyRBF8A= X-Received: by 2002:a05:6402:324c:b0:69a:9c4a:3d63 with SMTP id 4fb4d7f45d1cf-69e652995cfmr5743320a12.17.1784723398316; Wed, 22 Jul 2026 05:29:58 -0700 (PDT) Received: from DW927H4LGF ([2a09:bac6:37e6:1e5a::306:2]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-69f34f1b867sm835007a12.14.2026.07.22.05.29.55 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 22 Jul 2026 05:29:57 -0700 (PDT) From: Oxana Kharitonova To: mic@digikod.net, gnoack@google.com Cc: paul@paul-moore.com, jmorris@namei.or, serge@hallyn.com, wangyan01@kylinos.cn, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, landlock@lists.linux.dev, oxana@cloudflare.com, webprosto@gmail.com Subject: [PATCH 0/6] landlock: Add POSIX message queue scoping Date: Wed, 22 Jul 2026 13:29:36 +0100 Message-ID: <20260722122952.42149-1-oxana@cloudflare.com> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Hi, This series adds landlock support for scoping POSIX message queuesi [1]. Landlock already supports scoped IPC restrictions for signals and abstract UNIX sockets. These restrictions make it possible to prevent a sandboxed task from interacting with IPC objects outside of its Landlock domain, while still allowing communication within the same domain or with nested domains. This series extends the same model to POSIX message queues with a new LANDLOCK_SCOPE_POSIX_MSG_QUEUE scope. When this scope is enforced, a task can only open POSIX message queues that were created by a task in the same landlock domain or in a nested domain. The implementation tags mqueuefs inodes at creation time with the creator's landlock domain. This domain is kept alive for the lifetime of the inode and is checked when the queue is opened. The series also exposes the mqueuefs magic number through the shared UAPI magic header, bumps the Landlock ABI, updates documentation, adds sandboxer support, and adds selftests. The new behavior is: - a task restricted with LANDLOCK_SCOPE_POSIX_MSG_QUEUE cannot open a queue created outside of its Landlock scope; - a task can still open a queue created within its own Landlock domain; - queues created outside of any Landlock domain are treated as outside the scope for a scoped opener. [1] https://man7.org/linux/man-pages/man7/mq_overview.7.html Oxana Kharitonova (6): ipc: Move mqueue fs magic to uapi magic header landlock: Scope POSIX message queue opens landlock: Bump ABI for LANDLOCK_SCOPE_POSIX_MSG_QUEUE selftests/landlock: Test POSIX message queue scoping samples/landlock: Support POSIX message queue scoping landlock: Document POSIX message queue scoping Documentation/admin-guide/LSM/landlock.rst | 6 +- Documentation/userspace-api/landlock.rst | 11 +- include/uapi/linux/landlock.h | 7 +- include/uapi/linux/magic.h | 2 + ipc/mqueue.c | 2 +- samples/landlock/sandboxer.c | 16 +- security/landlock/audit.c | 9 + security/landlock/audit.h | 1 + security/landlock/fs.c | 35 +++ security/landlock/fs.h | 15 ++ security/landlock/limits.h | 2 +- security/landlock/ruleset.c | 1 - security/landlock/syscalls.c | 2 +- security/landlock/task.c | 43 ++++ security/landlock/task.h | 4 + tools/testing/selftests/landlock/base_test.c | 2 +- .../landlock/scoped_posix_msg_queue_test.c | 223 ++++++++++++++++++ .../testing/selftests/landlock/scoped_test.c | 2 +- 18 files changed, 371 insertions(+), 12 deletions(-) create mode 100644 tools/testing/selftests/landlock/scoped_posix_msg_queue_test.c -- 2.50.1 (Apple Git-155)