[PATCH v2 6/6] landlock: Document LANDLOCK_SCOPE_SYSV_MSG_QUEUE
From: Justin Suess <hidden>
Date: 2026-07-27 23:08:52
Also in:
lkml
Subsystem:
documentation, landlock security module, the rest · Maintainers:
Jonathan Corbet, Mickaël Salaün, Linus Torvalds
Document the new SysV message queue scope restriction. Make clear that because these queues do not use persistent handles, subsequent operations on a queue already obtained via msgget (or any other means) may be restricted once this right is enforced. Also note that denials surface as -EACCES rather than -EPERM, since the generic SysV IPC permission path maps every LSM denial to -EACCES. Signed-off-by: Justin Suess <redacted> --- Documentation/admin-guide/LSM/landlock.rst | 1 + Documentation/userspace-api/landlock.rst | 30 +++++++++++++++++++++- 2 files changed, 30 insertions(+), 1 deletion(-)
diff --git a/Documentation/admin-guide/LSM/landlock.rst b/Documentation/admin-guide/LSM/landlock.rst
index 8eb85c9381ff..ce5f9653b69a 100644
--- a/Documentation/admin-guide/LSM/landlock.rst
+++ b/Documentation/admin-guide/LSM/landlock.rst@@ -63,6 +63,7 @@ AUDIT_LANDLOCK_ACCESS **scope.*** - IPC scoping restrictions (ABI 6+): - scope.abstract_unix_socket - Abstract UNIX socket connection denied - scope.signal - Signal sending denied + - scope.sysv_msg_queue - SysV message queue operation denied (ABI 11+) Multiple blockers can appear in a single event (comma-separated) when multiple access rights are missing. For example, creating a regular file
diff --git a/Documentation/userspace-api/landlock.rst b/Documentation/userspace-api/landlock.rst
index 5a63d4476c1c..7c5453747457 100644
--- a/Documentation/userspace-api/landlock.rst
+++ b/Documentation/userspace-api/landlock.rst@@ -86,7 +86,8 @@ to be explicit about the denied-by-default access rights. LANDLOCK_ACCESS_NET_CONNECT_SEND_UDP, .scoped = LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET | - LANDLOCK_SCOPE_SIGNAL, + LANDLOCK_SCOPE_SIGNAL | + LANDLOCK_SCOPE_SYSV_MSG_QUEUE, }; Because we may not know which kernel version an application will be executed
@@ -140,6 +141,10 @@ version, and only use the available subset of access rights: ruleset_attr.handled_access_net &= ~(LANDLOCK_ACCESS_NET_BIND_UDP | LANDLOCK_ACCESS_NET_CONNECT_SEND_UDP); + __attribute__((fallthrough)); + case 10: + /* Removes LANDLOCK_SCOPE_SYSV_MSG_QUEUE for ABI < 11 */ + ruleset_attr.scoped &= ~LANDLOCK_SCOPE_SYSV_MSG_QUEUE; } This enables the creation of an inclusive ruleset that will contain our rules.
@@ -420,6 +425,22 @@ The operations which can be scoped are: A :manpage:`sendto(2)` on a socket which was previously connected will not be restricted. This works for both datagram and stream sockets. +``LANDLOCK_SCOPE_SYSV_MSG_QUEUE`` + This limits the set of System V message queues to which we can perform + :manpage:`msgget(2)`, :manpage:`msgrcv(2)`, :manpage:`msgsnd(2)`, and + :manpage:`msgctl(2)` calls to only message queues which were created by a + process in the same or a nested Landlock domain. + + Since System V message queues are IPC namespace global constructs and do + not use file descriptors, enforcement of a ruleset with this scoping may + cause subsequent operations on an msqid that were allowed prior to + enforcement to be denied. + + Denials are reported as ``EACCES``. Unlike other Landlock scopes, + the check runs in the generic SysV IPC permission path (the kernel's + ``ipcperms()`` helper), whose callers map every denial to ``EACCES`` + before it reaches user space. + IPC scoping does not support exceptions via :manpage:`landlock_add_rule(2)`. If an operation is scoped within a domain, no rules can be added to allow access to resources or processes outside of the scope.
@@ -789,6 +810,13 @@ when at least one sys_landlock_add_rule() call is made for it with the ``LANDLOCK_ADD_RULE_QUIET`` flag, additional add-rule calls for the same object without this flag do not clear it. +System V message queue (ABI < 11) +--------------------------------- + +Starting with the Landlock ABI version 11, it is possible to restrict +operations on System V message queues by setting +``LANDLOCK_SCOPE_SYSV_MSG_QUEUE`` to the ``scoped`` ruleset attribute. + .. _kernel_support: Kernel support
--
2.54.0