Re: [PATCH v4 4/8] landlock: Enforce capability restrictions
flat view
From: sashiko-bot@kernel.org
Date: 2026-10-02 12:53:10
Add Landlock enforcement for capability use via the LSM capable hook. This lets a sandboxed process restrict which Linux capabilities it can exercise, using LANDLOCK_PERMISSION_CAPABILITY_USE and per-capability rules. The check is a flat per-layer allowed-capabilities test, with no domain-ancestry bypass, no cross-namespace discriminant, and no dependency on the target user namespace. These categorical denials return -EPERM, like the namespace permission introduced by the previous commit, and they mirror its per-capability allowed and quiet masks, so LANDLOCK_ADD_RULE_QUIET stays rejected for this rule type. Successful capability rules and denials are traced as the previous commit describes. Enforce only at capability exercise time rather than modifying the [ ... ] Cc: Christian Brauner <brauner@kernel.org> Cc: Günther Noack <gnoack@google.com> Cc: Paul Moore <paul@paul-moore.com> Cc: Serge E. Hallyn <serge@hallyn.com> Signed-off-by: Mickaël Salaün <mic@digikod.net>
Sashiko has reviewed this patch and found no issues. It looks great! -- Sashiko AI review · https://sashiko.dev/#/patchset/20261002124409.1277970-1-mic@digikod.net?part=4