Qsphinx.addnodesdocument)}( rawsourcechildren]( translations LanguagesNode)}(hhh](h pending_xref)}(hhh]docutils.nodesTextChinese (Simplified)}parenthsba attributes}(ids]classes]names]dupnames]backrefs] refdomainstdreftypedoc reftarget%/translations/zh_CN/security/landlockmodnameN classnameN refexplicitutagnamehhh ubh)}(hhh]hChinese (Traditional)}hh2sbah}(h]h ]h"]h$]h&] refdomainh)reftypeh+ reftarget%/translations/zh_TW/security/landlockmodnameN classnameN refexplicituh1hhh ubh)}(hhh]hItalian}hhFsbah}(h]h ]h"]h$]h&] refdomainh)reftypeh+ reftarget%/translations/it_IT/security/landlockmodnameN classnameN refexplicituh1hhh ubh)}(hhh]hJapanese}hhZsbah}(h]h ]h"]h$]h&] refdomainh)reftypeh+ reftarget%/translations/ja_JP/security/landlockmodnameN classnameN refexplicituh1hhh ubh)}(hhh]hKorean}hhnsbah}(h]h ]h"]h$]h&] refdomainh)reftypeh+ reftarget%/translations/ko_KR/security/landlockmodnameN classnameN refexplicituh1hhh ubh)}(hhh]hPortuguese (Brazilian)}hhsbah}(h]h ]h"]h$]h&] refdomainh)reftypeh+ reftarget%/translations/pt_BR/security/landlockmodnameN classnameN refexplicituh1hhh ubh)}(hhh]hSpanish}hhsbah}(h]h ]h"]h$]h&] refdomainh)reftypeh+ reftarget%/translations/sp_SP/security/landlockmodnameN classnameN refexplicituh1hhh ubeh}(h]h ]h"]h$]h&]current_languageEnglishuh1h hh _documenthsourceNlineNubhcomment)}(h SPDX-License-Identifier: GPL-2.0h]h SPDX-License-Identifier: GPL-2.0}hhsbah}(h]h ]h"]h$]h&] xml:spacepreserveuh1hhhhhh?/var/lib/git/docbuild/linux/Documentation/security/landlock.rsthKubh)}(h9Copyright © 2017-2020 Mickaël Salaün h]h9Copyright © 2017-2020 Mickaël Salaün }hhsbah}(h]h ]h"]h$]h&]hhuh1hhhhhhhhKubh)}(hCopyright © 2019-2020 ANSSIh]hCopyright © 2019-2020 ANSSI}hhsbah}(h]h ]h"]h$]h&]hhuh1hhhhhhhhKubh)}(h"Copyright © 2026 Cloudflare, Inc.h]h"Copyright © 2026 Cloudflare, Inc.}hhsbah}(h]h ]h"]h$]h&]hhuh1hhhhhhhhKubhsection)}(hhh](htitle)}(h"Landlock LSM: kernel documentationh]h"Landlock LSM: kernel documentation}(hhhhhNhNubah}(h]h ]h"]h$]h&]uh1hhhhhhhhKubh field_list)}(hhh](hfield)}(hhh](h field_name)}(hAuthorh]hAuthor}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjhhhKubh field_body)}(hMickaël Salaünh]h paragraph)}(hj%h]hMickaël Salaün}(hj)hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhK hj#ubah}(h]h ]h"]h$]h&]uh1j!hjubeh}(h]h ]h"]h$]h&]uh1j hhhK hj hhubj )}(hhh](j)}(hDateh]hDate}(hjEhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjBhhhKubj")}(h August 2026 h]j()}(h August 2026h]h August 2026}(hjWhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhK hjSubah}(h]h ]h"]h$]h&]uh1j!hjBubeh}(h]h ]h"]h$]h&]uh1j hhhK hj hhubeh}(h]h ]h"]h$]h&]uh1jhhhhhhhK ubj()}(hXLandlock's goal is to create scoped access-control (i.e. sandboxing). To harden a whole system, this feature should be available to any process, including unprivileged ones. Because such a process may be compromised or backdoored (i.e. untrusted), Landlock's features must be safe to use from the kernel and other processes point of view. Landlock's interface must therefore expose a minimal attack surface.h]hXLandlock’s goal is to create scoped access-control (i.e. sandboxing). To harden a whole system, this feature should be available to any process, including unprivileged ones. Because such a process may be compromised or backdoored (i.e. untrusted), Landlock’s features must be safe to use from the kernel and other processes point of view. Landlock’s interface must therefore expose a minimal attack surface.}(hjwhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhK hhhhubj()}(hXLandlock is designed to be usable by unprivileged processes while following the system security policy enforced by other access control mechanisms (e.g. DAC, LSM). A Landlock rule shall not interfere with other access-controls enforced on the system, only add more restrictions.h]hXLandlock is designed to be usable by unprivileged processes while following the system security policy enforced by other access control mechanisms (e.g. DAC, LSM). A Landlock rule shall not interfere with other access-controls enforced on the system, only add more restrictions.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhKhhhhubj()}(hAny user can enforce Landlock rulesets on their processes. They are merged and evaluated against inherited rulesets in a way that ensures that only more constraints can be added.h]hAny user can enforce Landlock rulesets on their processes. They are merged and evaluated against inherited rulesets in a way that ensures that only more constraints can be added.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhKhhhhubj()}(hUUser space documentation can be found here: Documentation/userspace-api/landlock.rst.h]hUUser space documentation can be found here: Documentation/userspace-api/landlock.rst.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhKhhhhubh)}(hhh](h)}(h+Guiding principles for safe access controlsh]h+Guiding principles for safe access controls}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1hhjhhhhhK!ubh bullet_list)}(hhh](h list_item)}(hA Landlock rule shall be focused on access control on kernel objects instead of syscall filtering (i.e. syscall arguments), which is the purpose of seccomp-bpf.h]j()}(hA Landlock rule shall be focused on access control on kernel objects instead of syscall filtering (i.e. syscall arguments), which is the purpose of seccomp-bpf.h]hA Landlock rule shall be focused on access control on kernel objects instead of syscall filtering (i.e. syscall arguments), which is the purpose of seccomp-bpf.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhK#hjubah}(h]h ]h"]h$]h&]uh1jhjhhhhhNubj)}(hTo avoid multiple kinds of side-channel attacks (e.g. leak of security policies, CPU-based attacks), Landlock rules shall not be able to programmatically communicate with user space.h]j()}(hTo avoid multiple kinds of side-channel attacks (e.g. leak of security policies, CPU-based attacks), Landlock rules shall not be able to programmatically communicate with user space.h]hTo avoid multiple kinds of side-channel attacks (e.g. leak of security policies, CPU-based attacks), Landlock rules shall not be able to programmatically communicate with user space.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhK&hjubah}(h]h ]h"]h$]h&]uh1jhjhhhhhNubj)}(hRKernel access check shall not slow down access request from unsandboxed processes.h]j()}(hRKernel access check shall not slow down access request from unsandboxed processes.h]hRKernel access check shall not slow down access request from unsandboxed processes.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhK)hjubah}(h]h ]h"]h$]h&]uh1jhjhhhhhNubj)}(hvComputation related to Landlock operations (e.g. enforcing a ruleset) shall only impact the processes requesting them.h]j()}(hvComputation related to Landlock operations (e.g. enforcing a ruleset) shall only impact the processes requesting them.h]hvComputation related to Landlock operations (e.g. enforcing a ruleset) shall only impact the processes requesting them.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhK+hjubah}(h]h ]h"]h$]h&]uh1jhjhhhhhNubj)}(hResources (e.g. file descriptors) directly obtained from the kernel by a sandboxed process shall retain their scoped accesses (at the time of resource acquisition) whatever process uses them. Cf. `File descriptor access rights`_.h]j()}(hResources (e.g. file descriptors) directly obtained from the kernel by a sandboxed process shall retain their scoped accesses (at the time of resource acquisition) whatever process uses them. Cf. `File descriptor access rights`_.h](hResources (e.g. file descriptors) directly obtained from the kernel by a sandboxed process shall retain their scoped accesses (at the time of resource acquisition) whatever process uses them. Cf. }(hj+hhhNhNubh reference)}(h `File descriptor access rights`_h]hFile descriptor access rights}(hj5hhhNhNubah}(h]h ]h"]h$]h&]nameFile descriptor access rightsrefidfile-descriptor-access-rightsuh1j3hj+resolvedKubh.}(hj+hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhK-hj'ubah}(h]h ]h"]h$]h&]uh1jhjhhhhhNubj)}(hX*Access denials shall be logged according to system and Landlock domain configurations. Log entries must contain information about the cause of the denial and the owner of the related security policy. Such log generation should have a negligible performance and memory impact on allowed requests. h]j()}(hX)Access denials shall be logged according to system and Landlock domain configurations. Log entries must contain information about the cause of the denial and the owner of the related security policy. Such log generation should have a negligible performance and memory impact on allowed requests.h]hX)Access denials shall be logged according to system and Landlock domain configurations. Log entries must contain information about the cause of the denial and the owner of the related security policy. Such log generation should have a negligible performance and memory impact on allowed requests.}(hj\hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhK1hjXubah}(h]h ]h"]h$]h&]uh1jhjhhhhhNubeh}(h]h ]h"]h$]h&]bullet*uh1jhhhK#hjhhubeh}(h]+guiding-principles-for-safe-access-controlsah ]h"]+guiding principles for safe access controlsah$]h&]uh1hhhhhhhhK!ubh)}(hhh](h)}(hDesign choicesh]hDesign choices}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1hhjhhhhhK7ubh)}(hhh](h)}(hInode access rightsh]hInode access rights}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1hhjhhhhhK:ubj()}(hX/All access rights are tied to an inode and what can be accessed through it. Reading the content of a directory does not imply to be allowed to read the content of a listed inode. Indeed, a file name is local to its parent directory, and an inode can be referenced by multiple file names thanks to (hard) links. Being able to unlink a file only has a direct impact on the directory, not the unlinked inode. This is the reason why ``LANDLOCK_ACCESS_FS_REMOVE_FILE`` or ``LANDLOCK_ACCESS_FS_REFER`` are not allowed to be tied to files but only to directories.h](hXAll access rights are tied to an inode and what can be accessed through it. Reading the content of a directory does not imply to be allowed to read the content of a listed inode. Indeed, a file name is local to its parent directory, and an inode can be referenced by multiple file names thanks to (hard) links. Being able to unlink a file only has a direct impact on the directory, not the unlinked inode. This is the reason why }(hjhhhNhNubhliteral)}(h"``LANDLOCK_ACCESS_FS_REMOVE_FILE``h]hLANDLOCK_ACCESS_FS_REMOVE_FILE}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubh or }(hjhhhNhNubj)}(h``LANDLOCK_ACCESS_FS_REFER``h]hLANDLOCK_ACCESS_FS_REFER}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubh= are not allowed to be tied to files but only to directories.}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhKhhhNhNubah}(h]h ]h"]h$]h&]uh1jhj;ubah}(h]h ]h"]h$]h&]uh1j'hhhKRhj7ubah}(h]h ]h"]h$]h&]uh1jhj4hhhhhNubj)}(h=``int fd = open(path, O_WRONLY); ftruncate(fd); close(fd);`` h]j()}(h<``int fd = open(path, O_WRONLY); ftruncate(fd); close(fd);``h]j)}(hj]h]h8int fd = open(path, O_WRONLY); ftruncate(fd); close(fd);}(hj_hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj[ubah}(h]h ]h"]h$]h&]uh1j'hhhKShjWubah}(h]h ]h"]h$]h&]uh1jhj4hhhhhNubeh}(h]h ]h"]h$]h&]jvjwuh1jhhhKRhjhhubj()}(hXSimilarly to file access modes (e.g. ``O_RDWR``), Landlock access rights attached to file descriptors are retained even if they are passed between processes (e.g. through a Unix domain socket). Such access rights will then be enforced even if the receiving process is not sandboxed by Landlock. Indeed, this is required to keep access controls consistent over the whole system, and this avoids unattended bypasses through file descriptor passing (i.e. confused deputy attack).h](h%Similarly to file access modes (e.g. }(hj~hhhNhNubj)}(h ``O_RDWR``h]hO_RDWR}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhj~ubhX), Landlock access rights attached to file descriptors are retained even if they are passed between processes (e.g. through a Unix domain socket). Such access rights will then be enforced even if the receiving process is not sandboxed by Landlock. Indeed, this is required to keep access controls consistent over the whole system, and this avoids unattended bypasses through file descriptor passing (i.e. confused deputy attack).}(hj~hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhKUhjhhubhtarget)}(h.. _scoped-flags-interaction:h]h}(h]h ]h"]h$]h&]jEscoped-flags-interactionuh1jhK]hjhhhhubeh}(h]jFah ]h"]file descriptor access rightsah$]h&]uh1hhjhhhhhKF referencedKubh)}(hhh](h)}(h8Interaction between scoped flags and other access rightsh]h8Interaction between scoped flags and other access rights}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1hhjhhhhhK`ubj()}(hThe ``scoped`` flags in &struct landlock_ruleset_attr restrict the use of *outgoing* IPC from the created Landlock domain, while they permit reaching out to IPC endpoints *within* the created Landlock domain.h](hThe }(hjhhhNhNubj)}(h ``scoped``h]hscoped}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubh< flags in &struct landlock_ruleset_attr restrict the use of }(hjhhhNhNubhemphasis)}(h *outgoing*h]houtgoing}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubhW IPC from the created Landlock domain, while they permit reaching out to IPC endpoints }(hjhhhNhNubj)}(h*within*h]hwithin}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubh the created Landlock domain.}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhKbhjhhubj()}(hIn the future, scoped flags *may* interact with other access rights, e.g. so that abstract UNIX sockets can be allow-listed by name, or so that signals can be allow-listed by signal number or target process.h](hIn the future, scoped flags }(hj hhhNhNubj)}(h*may*h]hmay}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhj ubh interact with other access rights, e.g. so that abstract UNIX sockets can be allow-listed by name, or so that signals can be allow-listed by signal number or target process.}(hj hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhKghjhhubj()}(hX1When introducing ``LANDLOCK_ACCESS_FS_RESOLVE_UNIX``, we defined it to implicitly have the same scoping semantics as a ``LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET`` flag would have: connecting to UNIX sockets within the same domain (where ``LANDLOCK_ACCESS_FS_RESOLVE_UNIX`` is used) is unconditionally allowed.h](hWhen introducing }(hj*hhhNhNubj)}(h#``LANDLOCK_ACCESS_FS_RESOLVE_UNIX``h]hLANDLOCK_ACCESS_FS_RESOLVE_UNIX}(hj2hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj*ubhC, we defined it to implicitly have the same scoping semantics as a }(hj*hhhNhNubj)}(h'``LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET``h]h#LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET}(hjDhhhNhNubah}(h]h ]h"]h$]h&]uh1jhj*ubhK flag would have: connecting to UNIX sockets within the same domain (where }(hj*hhhNhNubj)}(h#``LANDLOCK_ACCESS_FS_RESOLVE_UNIX``h]hLANDLOCK_ACCESS_FS_RESOLVE_UNIX}(hjVhhhNhNubah}(h]h ]h"]h$]h&]uh1jhj*ubh% is used) is unconditionally allowed.}(hj*hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhKkhjhhubj()}(hThe reasoning is:h]hThe reasoning is:}(hjnhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhKrhjhhubj)}(hhh](j)}(hLike other IPC mechanisms, connecting to named UNIX sockets in the same domain should be expected and harmless. (If needed, users can further refine their Landlock policies with nested domains or by restricting ``LANDLOCK_ACCESS_FS_MAKE_SOCK``.)h]j()}(hLike other IPC mechanisms, connecting to named UNIX sockets in the same domain should be expected and harmless. (If needed, users can further refine their Landlock policies with nested domains or by restricting ``LANDLOCK_ACCESS_FS_MAKE_SOCK``.)h](hLike other IPC mechanisms, connecting to named UNIX sockets in the same domain should be expected and harmless. (If needed, users can further refine their Landlock policies with nested domains or by restricting }(hjhhhNhNubj)}(h ``LANDLOCK_ACCESS_FS_MAKE_SOCK``h]hLANDLOCK_ACCESS_FS_MAKE_SOCK}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubh.)}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhKthjubah}(h]h ]h"]h$]h&]uh1jhj|hhhhhNubj)}(hWe reserve the option to still introduce ``LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET`` in the future. (This would be useful if we wanted to have a Landlock rule to permit IPC access to other Landlock domains.)h]j()}(hWe reserve the option to still introduce ``LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET`` in the future. (This would be useful if we wanted to have a Landlock rule to permit IPC access to other Landlock domains.)h](h)We reserve the option to still introduce }(hjhhhNhNubj)}(h'``LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET``h]h#LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubh| in the future. (This would be useful if we wanted to have a Landlock rule to permit IPC access to other Landlock domains.)}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhKxhjubah}(h]h ]h"]h$]h&]uh1jhj|hhhhhNubj)}(hBut we can postpone the point in time when users have to deal with two interacting flags visible in the userspace API. (In particular, it is possible that it won't be needed in practice, in which case we can avoid the second flag altogether.)h]j()}(hBut we can postpone the point in time when users have to deal with two interacting flags visible in the userspace API. (In particular, it is possible that it won't be needed in practice, in which case we can avoid the second flag altogether.)h]hBut we can postpone the point in time when users have to deal with two interacting flags visible in the userspace API. (In particular, it is possible that it won’t be needed in practice, in which case we can avoid the second flag altogether.)}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhK|hjubah}(h]h ]h"]h$]h&]uh1jhj|hhhhhNubj)}(hIf we *do* introduce ``LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET`` in the future, setting this scoped flag in a ruleset does *not reduce* the restrictions, because access within the same scope is already allowed based on ``LANDLOCK_ACCESS_FS_RESOLVE_UNIX``. h]j()}(hIf we *do* introduce ``LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET`` in the future, setting this scoped flag in a ruleset does *not reduce* the restrictions, because access within the same scope is already allowed based on ``LANDLOCK_ACCESS_FS_RESOLVE_UNIX``.h](hIf we }(hjhhhNhNubj)}(h*do*h]hdo}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubh introduce }(hjhhhNhNubj)}(h'``LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET``h]h#LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubh; in the future, setting this scoped flag in a ruleset does }(hjhhhNhNubj)}(h *not reduce*h]h not reduce}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubhT the restrictions, because access within the same scope is already allowed based on }(hjhhhNhNubj)}(h#``LANDLOCK_ACCESS_FS_RESOLVE_UNIX``h]hLANDLOCK_ACCESS_FS_RESOLVE_UNIX}(hj-hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubh.}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhKhjubah}(h]h ]h"]h$]h&]uh1jhj|hhhhhNubeh}(h]h ]h"]h$]h&]jvjwuh1jhhhKthjhhubeh}(h](8interaction-between-scoped-flags-and-other-access-rightsjeh ]h"](8interaction between scoped flags and other access rightsscoped-flags-interactioneh$]h&]uh1hhjhhhhhK`expect_referenced_by_name}jWjsexpect_referenced_by_id}jjsubeh}(h]design-choicesah ]h"]design choicesah$]h&]uh1hhhhhhhhK7ubh)}(hhh](h)}(hTestsh]hTests}(hjihhhNhNubah}(h]h ]h"]h$]h&]uh1hhjfhhhhhKubj()}(hUserspace tests for backward compatibility, ptrace restrictions and filesystem support can be found here: `tools/testing/selftests/landlock/`_.h](hjUserspace tests for backward compatibility, ptrace restrictions and filesystem support can be found here: }(hjwhhhNhNubj4)}(h$`tools/testing/selftests/landlock/`_h]h!tools/testing/selftests/landlock/}(hjhhhNhNubah}(h]h ]h"]h$]h&]name!tools/testing/selftests/landlock/refurighttps://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/tools/testing/selftests/landlock/uh1j3hjwjGKubh.}(hjwhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhKhjfhhubeh}(h]testsah ]h"]testsah$]h&]uh1hhhhhhhhKubh)}(hhh](h)}(hKernel structuresh]hKernel structures}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1hhjhhhhhKubh)}(hhh](h)}(hObjecth]hObject}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1hhjhhhhhKubhindex)}(hhh]h}(h]h ]h"]h$]h&]entries](single#landlock_object_underops (C struct)c.landlock_object_underopshNtauh1jhjhhh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhNubhdesc)}(hhh](hdesc_signature)}(hlandlock_object_underopsh]hdesc_signature_line)}(hstruct landlock_object_underopsh](hdesc_sig_keyword)}(hstructh]hstruct}(hjhhhNhNubah}(h]h ]kah"]h$]h&]uh1jhjhhh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKubhdesc_sig_space)}(h h]h }(hjhhhNhNubah}(h]h ]wah"]h$]h&]uh1jhjhhhjhKubh desc_name)}(hlandlock_object_underopsh]h desc_sig_name)}(hjh]hlandlock_object_underops}(hjhhhNhNubah}(h]h ]nah"]h$]h&]uh1jhj ubah}(h]h ](sig-namedescnameeh"]h$]h&]hhuh1j hjhhhjhKubeh}(h]h ]h"]h$]h&]hhƌ add_permalinkuh1jsphinx_line_type declaratorhjhhhjhKubah}(h]jah ](sig sig-objecteh"]h$]h&] is_multiline _toc_parts) _toc_namehuh1jhjhKhjhhubh desc_content)}(hhh]j()}(h"Operations on an underlying objecth]h"Operations on an underlying object}(hjBhhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKhj?hhubah}(h]h ]h"]h$]h&]uh1j=hjhhhjhKubeh}(h]h ](cstructeh"]h$]h&]domainjZobjtypej[desctypej[noindex noindexentrynocontentsentryuh1jhhhjhjhNubh container)}(h**Definition**:: struct landlock_object_underops { void (*release)(struct landlock_object *const object) __releases(object->lock); }; **Members** ``release`` Releases the underlying object (e.g. iput() for an inode).h](j()}(h**Definition**::h](hstrong)}(h**Definition**h]h Definition}(hjqhhhNhNubah}(h]h ]h"]h$]h&]uh1johjkubh:}(hjkhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKhjgubh literal_block)}(hxstruct landlock_object_underops { void (*release)(struct landlock_object *const object) __releases(object->lock); };h]hxstruct landlock_object_underops { void (*release)(struct landlock_object *const object) __releases(object->lock); };}hjsbah}(h]h ]h"]h$]h&]hhuh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKhjgubj()}(h **Members**h]jp)}(hjh]hMembers}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKhjgubhdefinition_list)}(hhh]hdefinition_list_item)}(hF``release`` Releases the underlying object (e.g. iput() for an inode).h](hterm)}(h ``release``h]j)}(hjh]hrelease}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKhjubh definition)}(hhh]j()}(h:Releases the underlying object (e.g. iput() for an inode).h]h:Releases the underlying object (e.g. iput() for an inode).}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKhjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhKhjubah}(h]h ]h"]h$]h&]uh1jhjgubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhjhNubj)}(hhh]h}(h]h ]h"]h$]h&]entries](jlandlock_object (C struct)c.landlock_objecthNtauh1jhjhhhjhNubj)}(hhh](j)}(hlandlock_objecth]j)}(hstruct landlock_objecth](j)}(hjh]hstruct}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKubj)}(h h]h }(hj,hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhj+hKubj )}(hlandlock_objecth]j)}(hjh]hlandlock_object}(hj>hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj:ubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hjhhhj+hKubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hjhhhj+hKubah}(h]jah ](j5j6eh"]h$]h&]j:j;)j<huh1jhj+hKhjhhubj>)}(hhh]j()}(h%Security blob tied to a kernel objecth]h%Security blob tied to a kernel object}(hj`hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKhj]hhubah}(h]h ]h"]h$]h&]uh1j=hjhhhj+hKubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`jxjajxjbjcjduh1jhhhjhjhNubjf)}(hX**Definition**:: struct landlock_object { refcount_t usage; spinlock_t lock; void *underobj; union { struct rcu_head rcu_free; const struct landlock_object_underops *underops; }; }; **Members** ``usage`` This counter is used to tie an object to the rules matching it or to keep it alive while adding a new rule. If this counter reaches zero, this struct must not be modified, but this counter can still be read from within an RCU read-side critical section. When adding a new rule to an object with a usage counter of zero, we must wait until the pointer to this object is set to NULL (or recycled). ``lock`` Protects against concurrent modifications. This lock must be held from the time **usage** drops to zero until any weak references from **underobj** to this object have been cleaned up. Lock ordering: inode->i_lock nests inside this. ``underobj`` Used when cleaning up an object and to mark an object as tied to its underlying kernel structure. This pointer is protected by **lock**. Cf. landlock_release_inodes() and release_inode(). ``{unnamed_union}`` anonymous ``rcu_free`` Enables lockless use of **usage**, **lock** and **underobj** from within an RCU read-side critical section. **rcu_free** and **underops** are only used by landlock_put_object(). ``underops`` Enables landlock_put_object() to release the underlying object (e.g. inode).h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubh:}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhK"hj|ubj)}(hstruct landlock_object { refcount_t usage; spinlock_t lock; void *underobj; union { struct rcu_head rcu_free; const struct landlock_object_underops *underops; }; };h]hstruct landlock_object { refcount_t usage; spinlock_t lock; void *underobj; union { struct rcu_head rcu_free; const struct landlock_object_underops *underops; }; };}hjsbah}(h]h ]h"]h$]h&]hhuh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhK$hj|ubj()}(h **Members**h]jp)}(hjh]hMembers}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhK.hj|ubj)}(hhh](j)}(hX``usage`` This counter is used to tie an object to the rules matching it or to keep it alive while adding a new rule. If this counter reaches zero, this struct must not be modified, but this counter can still be read from within an RCU read-side critical section. When adding a new rule to an object with a usage counter of zero, we must wait until the pointer to this object is set to NULL (or recycled). h](j)}(h ``usage``h]j)}(hjh]husage}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhK/hjubj)}(hhh]j()}(hXThis counter is used to tie an object to the rules matching it or to keep it alive while adding a new rule. If this counter reaches zero, this struct must not be modified, but this counter can still be read from within an RCU read-side critical section. When adding a new rule to an object with a usage counter of zero, we must wait until the pointer to this object is set to NULL (or recycled).h]hXThis counter is used to tie an object to the rules matching it or to keep it alive while adding a new rule. If this counter reaches zero, this struct must not be modified, but this counter can still be read from within an RCU read-side critical section. When adding a new rule to an object with a usage counter of zero, we must wait until the pointer to this object is set to NULL (or recycled).}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhK*hjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhK/hjubj)}(h``lock`` Protects against concurrent modifications. This lock must be held from the time **usage** drops to zero until any weak references from **underobj** to this object have been cleaned up. Lock ordering: inode->i_lock nests inside this. h](j)}(h``lock``h]j)}(hjh]hlock}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhK7hjubj)}(hhh](j()}(hProtects against concurrent modifications. This lock must be held from the time **usage** drops to zero until any weak references from **underobj** to this object have been cleaned up.h](hQProtects against concurrent modifications. This lock must be held from the time }(hj hhhNhNubjp)}(h **usage**h]husage}(hj(hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubh. drops to zero until any weak references from }(hj hhhNhNubjp)}(h **underobj**h]hunderobj}(hj:hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubh% to this object have been cleaned up.}(hj hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhK3hjubj()}(h/Lock ordering: inode->i_lock nests inside this.h]h/Lock ordering: inode->i_lock nests inside this.}(hjShhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjhK7hjubeh}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhK7hjubj)}(h``underobj`` Used when cleaning up an object and to mark an object as tied to its underlying kernel structure. This pointer is protected by **lock**. Cf. landlock_release_inodes() and release_inode(). h](j)}(h ``underobj``h]j)}(hjsh]hunderobj}(hjuhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjqubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhK=hjmubj)}(hhh]j()}(hUsed when cleaning up an object and to mark an object as tied to its underlying kernel structure. This pointer is protected by **lock**. Cf. landlock_release_inodes() and release_inode().h](hUsed when cleaning up an object and to mark an object as tied to its underlying kernel structure. This pointer is protected by }(hjhhhNhNubjp)}(h**lock**h]hlock}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubh5. Cf. landlock_release_inodes() and release_inode().}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhK;hjubah}(h]h ]h"]h$]h&]uh1jhjmubeh}(h]h ]h"]h$]h&]uh1jhjhK=hjubj)}(h``{unnamed_union}`` anonymous h](j)}(h``{unnamed_union}``h]j)}(hjh]h{unnamed_union}}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKhjubj)}(hhh]j()}(h anonymoush]h anonymous}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjhKhjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhKhjubj)}(h``rcu_free`` Enables lockless use of **usage**, **lock** and **underobj** from within an RCU read-side critical section. **rcu_free** and **underops** are only used by landlock_put_object(). h](j)}(h ``rcu_free``h]j)}(hjh]hrcu_free}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKEhjubj)}(hhh]j()}(hEnables lockless use of **usage**, **lock** and **underobj** from within an RCU read-side critical section. **rcu_free** and **underops** are only used by landlock_put_object().h](hEnables lockless use of }(hj hhhNhNubjp)}(h **usage**h]husage}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubh, }(hj hhhNhNubjp)}(h**lock**h]hlock}(hj+ hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubh and }(hj hhhNhNubjp)}(h **underobj**h]hunderobj}(hj= hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubh0 from within an RCU read-side critical section. }(hj hhhNhNubjp)}(h **rcu_free**h]hrcu_free}(hjO hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubh and }(hj hhhNhNubjp)}(h **underops**h]hunderops}(hja hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubh( are only used by landlock_put_object().}(hj hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKBhj ubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhj hKEhjubj)}(hY``underops`` Enables landlock_put_object() to release the underlying object (e.g. inode).h](j)}(h ``underops``h]j)}(hj h]hunderops}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKIhj ubj)}(hhh]j()}(hLEnables landlock_put_object() to release the underlying object (e.g. inode).h]hLEnables landlock_put_object() to release the underlying object (e.g. inode).}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hj hKIhj ubah}(h]h ]h"]h$]h&]uh1jhj ubeh}(h]h ]h"]h$]h&]uh1jhj hKIhjubeh}(h]h ]h"]h$]h&]uh1jhj|ubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhjhNubj()}(h**Description**h]jp)}(hj h]h Description}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKMhjhhubj()}(hThe goal of this structure is to enable to tie a set of ephemeral access rights (pertaining to different domains) to a kernel object (e.g an inode) in a safe way. This implies to handle concurrent use and modification.h]hThe goal of this structure is to enable to tie a set of ephemeral access rights (pertaining to different domains) to a kernel object (e.g an inode) in a safe way. This implies to handle concurrent use and modification.}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhKhjhhubj()}(hjThe lifetime of a :c:type:`struct landlock_object ` depends on the rules referring to it.h](hThe lifetime of a }(hj hhhNhNubh)}(h2:c:type:`struct landlock_object `h]j)}(hj h]hstruct landlock_object}(hj hhhNhNubah}(h]h ](xrefjZc-typeeh"]h$]h&]uh1jhj ubah}(h]h ]h"]h$]h&]refdocsecurity/landlock refdomainjZreftypetype refexplicitrefwarn c:parent_keysphinx.domains.c LookupKey)}data]sb reftargetlandlock_objectuh1hh]/var/lib/git/docbuild/linux/Documentation/security/landlock:145: ./security/landlock/object.hhK#hj ubh& depends on the rules referring to it.}(hj hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hj% hK#hjhhubeh}(h]objectah ]h"]objectah$]h&]uh1hhjhhhhhKubh)}(hhh](h)}(h Filesystemh]h Filesystem}(hj; hhhNhNubah}(h]h ]h"]h$]h&]uh1hhj8 hhhhhKubj)}(hhh]h}(h]h ]h"]h$]h&]entries](j"landlock_inode_security (C struct)c.landlock_inode_securityhNtauh1jhj8 hhhNhNubj)}(hhh](j)}(hlandlock_inode_securityh]j)}(hstruct landlock_inode_securityh](j)}(hjh]hstruct}(hjb hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj^ hhhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKubj)}(h h]h }(hjp hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj^ hhhjo hKubj )}(hlandlock_inode_securityh]j)}(hj\ h]hlandlock_inode_security}(hj hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj~ ubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hj^ hhhjo hKubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hjZ hhhjo hKubah}(h]jU ah ](j5j6eh"]h$]h&]j:j;)j<huh1jhjo hKhjW hhubj>)}(hhh]j()}(hInode security blobh]hInode security blob}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhj hhubah}(h]h ]h"]h$]h&]uh1j=hjW hhhjo hKubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`j jaj jbjcjduh1jhhhj8 hNhNubjf)}(hXz**Definition**:: struct landlock_inode_security { struct landlock_object *object; }; **Members** ``object`` Weak pointer to an allocated object. All assignments of a new object are protected by the underlying inode->i_lock. However, atomically disassociating **object** from the inode is only protected by **object->lock**, from the time **object**'s usage refcount drops to zero to the time this pointer is nulled out (cf. release_inode() and hook_sb_delete()). Indeed, such disassociation doesn't require inode->i_lock thanks to the careful rcu_access_pointer() check performed by get_inode_object().h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubh:}(hj hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhj ubj)}(hGstruct landlock_inode_security { struct landlock_object *object; };h]hGstruct landlock_inode_security { struct landlock_object *object; };}hj sbah}(h]h ]h"]h$]h&]hhuh1jhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK!hj ubj()}(h **Members**h]jp)}(hj h]hMembers}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK%hj ubj)}(hhh]j)}(hX``object`` Weak pointer to an allocated object. All assignments of a new object are protected by the underlying inode->i_lock. However, atomically disassociating **object** from the inode is only protected by **object->lock**, from the time **object**'s usage refcount drops to zero to the time this pointer is nulled out (cf. release_inode() and hook_sb_delete()). Indeed, such disassociation doesn't require inode->i_lock thanks to the careful rcu_access_pointer() check performed by get_inode_object().h](j)}(h ``object``h]j)}(hj h]hobject}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj ubah}(h]h ]h"]h$]h&]uh1jhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK)hj ubj)}(hhh]j()}(hXWeak pointer to an allocated object. All assignments of a new object are protected by the underlying inode->i_lock. However, atomically disassociating **object** from the inode is only protected by **object->lock**, from the time **object**'s usage refcount drops to zero to the time this pointer is nulled out (cf. release_inode() and hook_sb_delete()). Indeed, such disassociation doesn't require inode->i_lock thanks to the careful rcu_access_pointer() check performed by get_inode_object().h](hWeak pointer to an allocated object. All assignments of a new object are protected by the underlying inode->i_lock. However, atomically disassociating }(hj* hhhNhNubjp)}(h **object**h]hobject}(hj2 hhhNhNubah}(h]h ]h"]h$]h&]uh1johj* ubh% from the inode is only protected by }(hj* hhhNhNubjp)}(h**object->lock**h]h object->lock}(hjD hhhNhNubah}(h]h ]h"]h$]h&]uh1johj* ubh, from the time }(hj* hhhNhNubjp)}(h **object**h]hobject}(hjV hhhNhNubah}(h]h ]h"]h$]h&]uh1johj* ubhX’s usage refcount drops to zero to the time this pointer is nulled out (cf. release_inode() and hook_sb_delete()). Indeed, such disassociation doesn’t require inode->i_lock thanks to the careful rcu_access_pointer() check performed by get_inode_object().}(hj* hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK#hj' ubah}(h]h ]h"]h$]h&]uh1jhj ubeh}(h]h ]h"]h$]h&]uh1jhj& hK)hj ubah}(h]h ]h"]h$]h&]uh1jhj ubeh}(h]h ] kernelindentah"]h$]h&]uh1jehj8 hhhNhNubj()}(h**Description**h]jp)}(hj h]h Description}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK-hj8 hhubj()}(hsEnable to reference a :c:type:`struct landlock_object ` tied to an inode (i.e. underlying object).h](hEnable to reference a }(hj hhhNhNubh)}(h2:c:type:`struct landlock_object `h]j)}(hj h]hstruct landlock_object}(hj hhhNhNubah}(h]h ](j jZc-typeeh"]h$]h&]uh1jhj ubah}(h]h ]h"]h$]h&]refdocj refdomainjZreftypetype refexplicitrefwarnj j j# landlock_objectuh1hhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhj ubh+ tied to an inode (i.e. underlying object).}(hj hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hj hKhj8 hhubj)}(hhh]h}(h]h ]h"]h$]h&]entries](j!landlock_file_security (C struct)c.landlock_file_securityhNtauh1jhj8 hhhNhNubj)}(hhh](j)}(hlandlock_file_securityh]j)}(hstruct landlock_file_securityh](j)}(hjh]hstruct}(hj hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj hhhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK"ubj)}(h h]h }(hj hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj hhhj hK"ubj )}(hlandlock_file_securityh]j)}(hj h]hlandlock_file_security}(hj hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj ubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hj hhhj hK"ubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hj hhhj hK"ubah}(h]j ah ](j5j6eh"]h$]h&]j:j;)j<huh1jhj hK"hj hhubj>)}(hhh]j()}(hFile security blobh]hFile security blob}(hj- hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK/hj* hhubah}(h]h ]h"]h$]h&]uh1j=hj hhhj hK"ubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`jE jajE jbjcjduh1jhhhj8 hNhNubjf)}(hX**Definition**:: struct landlock_file_security { access_mask_t allowed_access; #ifdef CONFIG_SECURITY_LANDLOCK_LOG; deny_masks_t deny_masks; optional_access_t quiet_optional_accesses; u8 fown_layer; #endif ; struct landlock_cred_security fown_subject; struct pid *fown_tg; }; **Members** ``allowed_access`` Access rights that were available at the time of opening the file. This is not necessarily the full set of access rights available at that time, but it's the necessary subset as needed to authorize later operations on the open file. ``deny_masks`` Domain layer levels that deny an optional access (see _LANDLOCK_ACCESS_FS_OPTIONAL). ``quiet_optional_accesses`` Stores which optional accesses are covered by quiet rules within the layer referred to in deny_masks, one access per bit. Does not take into account whether the quiet access bits are actually set in the layer's corresponding landlock_hierarchy. ``fown_layer`` Layer level of **fown_subject->domain** with LANDLOCK_SCOPE_SIGNAL. ``fown_subject`` Landlock credential of the task that set the PID that may receive a signal e.g., SIGURG when writing MSG_OOB to the related socket. This pointer is protected by the related file->f_owner->lock, as for fown_struct's members: pid, uid, and euid. ``fown_tg`` Thread group of the task that set the file owner, pinned while **fown_subject** holds a domain. It lets hook_file_send_sigiotask() always allow a SIGIO delivered to the owner's own process -- e.g. the thread-group leader reached through a process-group owner -- matching the same-process exemption of hook_task_kill(). NULL when no domain is recorded. Protected by file->f_owner->lock, like **fown_subject**.h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hjQ hhhNhNubah}(h]h ]h"]h$]h&]uh1johjM ubh:}(hjM hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK3hjI ubj)}(hXstruct landlock_file_security { access_mask_t allowed_access; #ifdef CONFIG_SECURITY_LANDLOCK_LOG; deny_masks_t deny_masks; optional_access_t quiet_optional_accesses; u8 fown_layer; #endif ; struct landlock_cred_security fown_subject; struct pid *fown_tg; };h]hXstruct landlock_file_security { access_mask_t allowed_access; #ifdef CONFIG_SECURITY_LANDLOCK_LOG; deny_masks_t deny_masks; optional_access_t quiet_optional_accesses; u8 fown_layer; #endif ; struct landlock_cred_security fown_subject; struct pid *fown_tg; };}hjj sbah}(h]h ]h"]h$]h&]hhuh1jhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK5hjI ubj()}(h **Members**h]jp)}(hj{ h]hMembers}(hj} hhhNhNubah}(h]h ]h"]h$]h&]uh1johjy ubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK@hjI ubj)}(hhh](j)}(h``allowed_access`` Access rights that were available at the time of opening the file. This is not necessarily the full set of access rights available at that time, but it's the necessary subset as needed to authorize later operations on the open file. h](j)}(h``allowed_access``h]j)}(hj h]hallowed_access}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj ubah}(h]h ]h"]h$]h&]uh1jhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKdomain** with LANDLOCK_SCOPE_SIGNAL. h](j)}(h``fown_layer``h]j)}(hjH h]h fown_layer}(hjJ hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjF ubah}(h]h ]h"]h$]h&]uh1jhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKOhjB ubj)}(hhh]j()}(hCLayer level of **fown_subject->domain** with LANDLOCK_SCOPE_SIGNAL.h](hLayer level of }(hja hhhNhNubjp)}(h**fown_subject->domain**h]hfown_subject->domain}(hji hhhNhNubah}(h]h ]h"]h$]h&]uh1johja ubh with LANDLOCK_SCOPE_SIGNAL.}(hja hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKNhj^ ubah}(h]h ]h"]h$]h&]uh1jhjB ubeh}(h]h ]h"]h$]h&]uh1jhj] hKOhj ubj)}(hX``fown_subject`` Landlock credential of the task that set the PID that may receive a signal e.g., SIGURG when writing MSG_OOB to the related socket. This pointer is protected by the related file->f_owner->lock, as for fown_struct's members: pid, uid, and euid. h](j)}(h``fown_subject``h]j)}(hj h]h fown_subject}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj ubah}(h]h ]h"]h$]h&]uh1jhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKYhj ubj)}(hhh]j()}(hLandlock credential of the task that set the PID that may receive a signal e.g., SIGURG when writing MSG_OOB to the related socket. This pointer is protected by the related file->f_owner->lock, as for fown_struct's members: pid, uid, and euid.h]hLandlock credential of the task that set the PID that may receive a signal e.g., SIGURG when writing MSG_OOB to the related socket. This pointer is protected by the related file->f_owner->lock, as for fown_struct’s members: pid, uid, and euid.}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKUhj ubah}(h]h ]h"]h$]h&]uh1jhj ubeh}(h]h ]h"]h$]h&]uh1jhj hKYhj ubj)}(hX``fown_tg`` Thread group of the task that set the file owner, pinned while **fown_subject** holds a domain. It lets hook_file_send_sigiotask() always allow a SIGIO delivered to the owner's own process -- e.g. the thread-group leader reached through a process-group owner -- matching the same-process exemption of hook_task_kill(). NULL when no domain is recorded. Protected by file->f_owner->lock, like **fown_subject**.h](j)}(h ``fown_tg``h]j)}(hj h]hfown_tg}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj ubah}(h]h ]h"]h$]h&]uh1jhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKbhj ubj)}(hhh]j()}(hXThread group of the task that set the file owner, pinned while **fown_subject** holds a domain. It lets hook_file_send_sigiotask() always allow a SIGIO delivered to the owner's own process -- e.g. the thread-group leader reached through a process-group owner -- matching the same-process exemption of hook_task_kill(). NULL when no domain is recorded. Protected by file->f_owner->lock, like **fown_subject**.h](h?Thread group of the task that set the file owner, pinned while }(hj hhhNhNubjp)}(h**fown_subject**h]h fown_subject}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubhX= holds a domain. It lets hook_file_send_sigiotask() always allow a SIGIO delivered to the owner’s own process -- e.g. the thread-group leader reached through a process-group owner -- matching the same-process exemption of hook_task_kill(). NULL when no domain is recorded. Protected by file->f_owner->lock, like }(hj hhhNhNubjp)}(h**fown_subject**h]h fown_subject}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubh.}(hj hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK]hj ubah}(h]h ]h"]h$]h&]uh1jhj ubeh}(h]h ]h"]h$]h&]uh1jhj hKbhj ubeh}(h]h ]h"]h$]h&]uh1jhjI ubeh}(h]h ] kernelindentah"]h$]h&]uh1jehj8 hhhNhNubj()}(h**Description**h]jp)}(hj5h]h Description}(hj7hhhNhNubah}(h]h ]h"]h$]h&]uh1johj3ubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKfhj8 hhubj()}(hXThis information is populated when opening a file in hook_file_open, and tracks the relevant Landlock access rights that were available at the time of opening the file. Other LSM hooks use these rights in order to authorize operations on already opened files.h]hXThis information is populated when opening a file in hook_file_open, and tracks the relevant Landlock access rights that were available at the time of opening the file. Other LSM hooks use these rights in order to authorize operations on already opened files.}(hjKhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK0hj8 hhubj)}(hhh]h}(h]h ]h"]h$]h&]entries](j'landlock_superblock_security (C struct)c.landlock_superblock_securityhNtauh1jhj8 hhhNhNubj)}(hhh](j)}(hlandlock_superblock_securityh]j)}(h#struct landlock_superblock_securityh](j)}(hjh]hstruct}(hjshhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjohhhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK8ubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjohhhjhK8ubj )}(hlandlock_superblock_securityh]j)}(hjmh]hlandlock_superblock_security}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hjohhhjhK8ubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hjkhhhjhK8ubah}(h]jfah ](j5j6eh"]h$]h&]j:j;)j<huh1jhjhK8hjhhhubj>)}(hhh]j()}(hSuperblock security blobh]hSuperblock security blob}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKzhjhhubah}(h]h ]h"]h$]h&]uh1j=hjhhhhjhK8ubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`jjajjbjcjduh1jhhhj8 hNhNubjf)}(hX **Definition**:: struct landlock_superblock_security { atomic_long_t inode_refs; }; **Members** ``inode_refs`` Number of pending inodes (from this superblock) that are being released by release_inode(). Cf. struct super_block->s_fsnotify_inode_refs .h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubh:}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK~hjubj)}(hFstruct landlock_superblock_security { atomic_long_t inode_refs; };h]hFstruct landlock_superblock_security { atomic_long_t inode_refs; };}hjsbah}(h]h ]h"]h$]h&]hhuh1jhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhjubj()}(h **Members**h]jp)}(hjh]hMembers}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhjubj)}(hhh]j)}(h``inode_refs`` Number of pending inodes (from this superblock) that are being released by release_inode(). Cf. struct super_block->s_fsnotify_inode_refs .h](j)}(h``inode_refs``h]j)}(hj"h]h inode_refs}(hj$hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj ubah}(h]h ]h"]h$]h&]uh1jhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhjubj)}(hhh]j()}(hNumber of pending inodes (from this superblock) that are being released by release_inode(). Cf. struct super_block->s_fsnotify_inode_refs .h]hNumber of pending inodes (from this superblock) that are being released by release_inode(). Cf. struct super_block->s_fsnotify_inode_refs .}(hj;hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhj8ubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhj7hKhjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ] kernelindentah"]h$]h&]uh1jehj8 hhhNhNubj()}(h**Description**h]jp)}(hjeh]h Description}(hjghhhNhNubah}(h]h ]h"]h$]h&]uh1johjcubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhj8 hhubj()}(hHEnable hook_sb_delete() to wait for concurrent calls to release_inode().h]hHEnable hook_sb_delete() to wait for concurrent calls to release_inode().}(hj{hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhK{hj8 hhubj)}(hhh]h}(h]h ]h"]h$]h&]entries](j#resolve_path_for_trace (C function)c.resolve_path_for_tracehNtauh1jhj8 hhhNhNubj)}(hhh](j)}(hHconst char * resolve_path_for_trace (const struct path *path, char *buf)h]j)}(hFconst char *resolve_path_for_trace(const struct path *path, char *buf)h](j)}(hconsth]hconst}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhjhKubhdesc_sig_keyword_type)}(hcharh]hchar}(hjhhhNhNubah}(h]h ]ktah"]h$]h&]uh1jhjhhhjhKubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhjhKubhdesc_sig_punctuation)}(hjwh]h*}(hjhhhNhNubah}(h]h ]pah"]h$]h&]uh1jhjhhhjhKubj )}(hresolve_path_for_traceh]j)}(hresolve_path_for_traceh]hresolve_path_for_trace}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hjhhhjhKubhdesc_parameterlist)}(h$(const struct path *path, char *buf)h](hdesc_parameter)}(hconst struct path *pathh](j)}(hjh]hconst}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(h h]h }(hj hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(hjh]hstruct}(hj.hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(h h]h }(hj;hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubh)}(hhh]j)}(hpathh]hpath}(hjLhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjIubah}(h]h ]h"]h$]h&] refdomainjZreftype identifier reftargetjNmodnameN classnameNj j )}j! ]j ASTIdentifier)}jbjsbc.resolve_path_for_traceasbuh1hhjubj)}(h h]h }(hjohhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(hjwh]h*}(hj}hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(hpathh]hpath}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]noemphhhuh1j hj ubj)}(h char *bufh](j)}(hcharh]hchar}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(hjwh]h*}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(hbufh]hbuf}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]noemphhhuh1j hj ubeh}(h]h ]h"]h$]h&]hhuh1jhjhhhjhKubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hjhhhjhKubah}(h]jah ](j5j6eh"]h$]h&]j:j;)j<huh1jhjhKhjhhubj>)}(hhh]j()}(h%Resolve a path for tracepoint displayh]h%Resolve a path for tracepoint display}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhjhhubah}(h]h ]h"]h$]h&]uh1j=hjhhhjhKubeh}(h]h ](jZfunctioneh"]h$]h&]j_jZj`jjajjbjcjduh1jhhhj8 hNhNubjf)}(hX**Parameters** ``const struct path *path`` The path to resolve. ``char *buf`` A buffer of at least PATH_MAX bytes for the resolved path. **Description** Uses d_absolute_path() to produce a namespace-independent absolute path, unlike d_path() which resolves relative to the process's chroot. This ensures trace output is deterministic regardless of the tracer's mount namespace. **Return** A pointer into **buf** with the resolved path, or an error string ("", "").h](j()}(h**Parameters**h]jp)}(hjh]h Parameters}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhjubj)}(hhh](j)}(h1``const struct path *path`` The path to resolve. h](j)}(h``const struct path *path``h]j)}(hj7h]hconst struct path *path}(hj9hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj5ubah}(h]h ]h"]h$]h&]uh1jhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhj1ubj)}(hhh]j()}(hThe path to resolve.h]hThe path to resolve.}(hjPhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjLhKhjMubah}(h]h ]h"]h$]h&]uh1jhj1ubeh}(h]h ]h"]h$]h&]uh1jhjLhKhj.ubj)}(hI``char *buf`` A buffer of at least PATH_MAX bytes for the resolved path. h](j)}(h ``char *buf``h]j)}(hjph]h char *buf}(hjrhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjnubah}(h]h ]h"]h$]h&]uh1jhY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhjjubj)}(hhh]j()}(h:A buffer of at least PATH_MAX bytes for the resolved path.h]h:A buffer of at least PATH_MAX bytes for the resolved path.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjhKhjubah}(h]h ]h"]h$]h&]uh1jhjjubeh}(h]h ]h"]h$]h&]uh1jhjhKhj.ubeh}(h]h ]h"]h$]h&]uh1jhjubj()}(h**Description**h]jp)}(hjh]h Description}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhjubj()}(hUses d_absolute_path() to produce a namespace-independent absolute path, unlike d_path() which resolves relative to the process's chroot. This ensures trace output is deterministic regardless of the tracer's mount namespace.h]hUses d_absolute_path() to produce a namespace-independent absolute path, unlike d_path() which resolves relative to the process’s chroot. This ensures trace output is deterministic regardless of the tracer’s mount namespace.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhjubj()}(h **Return**h]jp)}(hjh]hReturn}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubah}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhjubj()}(hbA pointer into **buf** with the resolved path, or an error string ("", "").h](hA pointer into }(hjhhhNhNubjp)}(h**buf**h]hbuf}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubhT with the resolved path, or an error string (“”, “”).}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hY/var/lib/git/docbuild/linux/Documentation/security/landlock:151: ./security/landlock/fs.hhKhjubeh}(h]h ] kernelindentah"]h$]h&]uh1jehj8 hhhNhNubeh}(h] filesystemah ]h"] filesystemah$]h&]uh1hhjhhhhhKubh)}(hhh](h)}(hProcess credentialh]hProcess credential}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1hhjhhhhhKubj)}(hhh]h}(h]h ]h"]h$]h&]entries](j!landlock_cred_security (C struct)c.landlock_cred_securityhNtauh1jhjhhhNhNubj)}(hhh](j)}(hlandlock_cred_securityh]j)}(hstruct landlock_cred_securityh](j)}(hjh]hstruct}(hjBhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj>hhh[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKubj)}(h h]h }(hjPhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj>hhhjOhKubj )}(hlandlock_cred_securityh]j)}(hj<h]hlandlock_cred_security}(hjbhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj^ubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hj>hhhjOhKubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hj:hhhjOhKubah}(h]j5ah ](j5j6eh"]h$]h&]j:j;)j<huh1jhjOhKhj7hhubj>)}(hhh]j()}(hCredential security blobh]hCredential security blob}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKhjhhubah}(h]h ]h"]h$]h&]uh1j=hj7hhhjOhKubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`jjajjbjcjduh1jhhhjhNhNubjf)}(hX**Definition**:: struct landlock_cred_security { struct landlock_domain *domain; #ifdef CONFIG_SECURITY_LANDLOCK_LOG; u16 domain_exec; u8 log_subdomains_off : 1; #endif ; }; **Members** ``domain`` Immutable domain enforced on a task. ``domain_exec`` Bitmask identifying the domain layers that were enforced by the current task's executed file (i.e. no new execve(2) since landlock_restrict_self(2)). ``log_subdomains_off`` Set if the domain descendants's log_status should be set to ``LANDLOCK_LOG_DISABLED``. This is not a landlock_hierarchy configuration because it applies to future descendant domains and it does not require a current domain.h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubh:}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKhjubj)}(hstruct landlock_cred_security { struct landlock_domain *domain; #ifdef CONFIG_SECURITY_LANDLOCK_LOG; u16 domain_exec; u8 log_subdomains_off : 1; #endif ; };h]hstruct landlock_cred_security { struct landlock_domain *domain; #ifdef CONFIG_SECURITY_LANDLOCK_LOG; u16 domain_exec; u8 log_subdomains_off : 1; #endif ; };}hjsbah}(h]h ]h"]h$]h&]hhuh1jh[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKhjubj()}(h **Members**h]jp)}(hjh]hMembers}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubah}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhK'hjubj)}(hhh](j)}(h0``domain`` Immutable domain enforced on a task. h](j)}(h ``domain``h]j)}(hjh]hdomain}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhK$hjubj)}(hhh]j()}(h$Immutable domain enforced on a task.h]h$Immutable domain enforced on a task.}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjhK$hjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhK$hjubj)}(h``domain_exec`` Bitmask identifying the domain layers that were enforced by the current task's executed file (i.e. no new execve(2) since landlock_restrict_self(2)). h](j)}(h``domain_exec``h]j)}(hj*h]h domain_exec}(hj,hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj(ubah}(h]h ]h"]h$]h&]uh1jh[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhK,hj$ubj)}(hhh]j()}(hBitmask identifying the domain layers that were enforced by the current task's executed file (i.e. no new execve(2) since landlock_restrict_self(2)).h]hBitmask identifying the domain layers that were enforced by the current task’s executed file (i.e. no new execve(2) since landlock_restrict_self(2)).}(hjChhhNhNubah}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhK*hj@ubah}(h]h ]h"]h$]h&]uh1jhj$ubeh}(h]h ]h"]h$]h&]uh1jhj?hK,hjubj)}(h``log_subdomains_off`` Set if the domain descendants's log_status should be set to ``LANDLOCK_LOG_DISABLED``. This is not a landlock_hierarchy configuration because it applies to future descendant domains and it does not require a current domain.h](j)}(h``log_subdomains_off``h]j)}(hjdh]hlog_subdomains_off}(hjfhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjbubah}(h]h ]h"]h$]h&]uh1jh[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhK2hj^ubj)}(hhh]j()}(hSet if the domain descendants's log_status should be set to ``LANDLOCK_LOG_DISABLED``. This is not a landlock_hierarchy configuration because it applies to future descendant domains and it does not require a current domain.h](h>Set if the domain descendants’s log_status should be set to }(hj}hhhNhNubj)}(h``LANDLOCK_LOG_DISABLED``h]hLANDLOCK_LOG_DISABLED}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhj}ubh. This is not a landlock_hierarchy configuration because it applies to future descendant domains and it does not require a current domain.}(hj}hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhK0hjzubah}(h]h ]h"]h$]h&]uh1jhj^ubeh}(h]h ]h"]h$]h&]uh1jhjyhK2hjubeh}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubj()}(h**Description**h]jp)}(hjh]h Description}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubah}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhK6hjhhubj()}(hThis structure is packed to minimize the size of struct landlock_file_security. However, it is always aligned in the LSM cred blob, see lsm_set_blob_size().h]hThis structure is packed to minimize the size of struct landlock_file_security. However, it is always aligned in the LSM cred blob, see lsm_set_blob_size().}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKhjhhubj()}(h?When updating this, also update landlock_cred_copy() if needed.h]h?When updating this, also update landlock_cred_copy() if needed.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKhjhhubj)}(hhh]h}(h]h ]h"]h$]h&]entries](j,landlock_get_applicable_subject (C function)!c.landlock_get_applicable_subjecthNtauh1jhjhhhNhNubj)}(hhh](j)}(hconst struct landlock_cred_security * landlock_get_applicable_subject (const struct cred *const cred, const struct access_masks masks, size_t *const handle_layer)h]j)}(hconst struct landlock_cred_security *landlock_get_applicable_subject(const struct cred *const cred, const struct access_masks masks, size_t *const handle_layer)h](j)}(hjh]hconst}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhh[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKkubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhjhKkubj)}(hjh]hstruct}(hj"hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhjhKkubj)}(h h]h }(hj/hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhjhKkubh)}(hhh]j)}(hlandlock_cred_securityh]hlandlock_cred_security}(hj@hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj=ubah}(h]h ]h"]h$]h&] refdomainjZreftypejb reftargetjBmodnameN classnameNj j )}j! ]jj)}jblandlock_get_applicable_subjectsb!c.landlock_get_applicable_subjectasbuh1hhjhhhjhKkubj)}(h h]h }(hjahhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhjhKkubj)}(hjwh]h*}(hjohhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhjhKkubj )}(hlandlock_get_applicable_subjecth]j)}(hj^h]hlandlock_get_applicable_subject}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj|ubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hjhhhjhKkubj)}(h\(const struct cred *const cred, const struct access_masks masks, size_t *const handle_layer)h](j)}(hconst struct cred *const credh](j)}(hjh]hconst}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(hjh]hstruct}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubh)}(hhh]j)}(hcredh]hcred}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&] refdomainjZreftypejb reftargetjmodnameN classnameNj j )}j! ]j\!c.landlock_get_applicable_subjectasbuh1hhjubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(hjwh]h*}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(hjh]hconst}(hj hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(hcredh]hcred}(hj(hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]noemphhhuh1j hjubj)}(hconst struct access_masks masksh](j)}(hjh]hconst}(hjAhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj=ubj)}(h h]h }(hjNhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj=ubj)}(hjh]hstruct}(hj\hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj=ubj)}(h h]h }(hjihhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj=ubh)}(hhh]j)}(h access_masksh]h access_masks}(hjzhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjwubah}(h]h ]h"]h$]h&] refdomainjZreftypejb reftargetj|modnameN classnameNj j )}j! ]j\!c.landlock_get_applicable_subjectasbuh1hhj=ubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj=ubj)}(hmasksh]hmasks}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj=ubeh}(h]h ]h"]h$]h&]noemphhhuh1j hjubj)}(hsize_t *const handle_layerh](h)}(hhh]j)}(hsize_th]hsize_t}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&] refdomainjZreftypejb reftargetjmodnameN classnameNj j )}j! ]j\!c.landlock_get_applicable_subjectasbuh1hhjubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(hjwh]h*}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(hjh]hconst}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubj)}(h handle_layerh]h handle_layer}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]noemphhhuh1j hjubeh}(h]h ]h"]h$]h&]hhuh1jhjhhhjhKkubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hjhhhjhKkubah}(h]jah ](j5j6eh"]h$]h&]j:j;)j<huh1jhjhKkhjhhubj>)}(hhh]j()}(hReturn the subject's Landlock credential if its enforced domain applies to (i.e. handles) at least one of the access rights specified in **masks**h](hReturn the subject’s Landlock credential if its enforced domain applies to (i.e. handles) at least one of the access rights specified in }(hj@hhhNhNubjp)}(h **masks**h]hmasks}(hjHhhhNhNubah}(h]h ]h"]h$]h&]uh1johj@ubeh}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKkhj=hhubah}(h]h ]h"]h$]h&]uh1j=hjhhhjhKkubeh}(h]h ](jZfunctioneh"]h$]h&]j_jZj`jfjajfjbjcjduh1jhhhjhNhNubjf)}(hXe**Parameters** ``const struct cred *const cred`` credential ``const struct access_masks masks`` access masks ``size_t *const handle_layer`` returned youngest layer handling a subset of **masks**. Not set if the function returns NULL. **Return** landlock_cred(**cred**) if any access rights specified in **masks** is handled, or NULL otherwise.h](j()}(h**Parameters**h]jp)}(hjph]h Parameters}(hjrhhhNhNubah}(h]h ]h"]h$]h&]uh1johjnubah}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKohjjubj)}(hhh](j)}(h-``const struct cred *const cred`` credential h](j)}(h!``const struct cred *const cred``h]j)}(hjh]hconst struct cred *const cred}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKphjubj)}(hhh]j()}(h credentialh]h credential}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjhKphjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhKphjubj)}(h1``const struct access_masks masks`` access masks h](j)}(h#``const struct access_masks masks``h]j)}(hjh]hconst struct access_masks masks}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKqhjubj)}(hhh]j()}(h access masksh]h access masks}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjhKqhjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhKqhjubj)}(h~``size_t *const handle_layer`` returned youngest layer handling a subset of **masks**. Not set if the function returns NULL. h](j)}(h``size_t *const handle_layer``h]j)}(hjh]hsize_t *const handle_layer}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKshjubj)}(hhh]j()}(h^returned youngest layer handling a subset of **masks**. Not set if the function returns NULL.h](h-returned youngest layer handling a subset of }(hjhhhNhNubjp)}(h **masks**h]hmasks}(hj"hhhNhNubah}(h]h ]h"]h$]h&]uh1johjubh(. Not set if the function returns NULL.}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKrhjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhKshjubeh}(h]h ]h"]h$]h&]uh1jhjjubj()}(h **Return**h]jp)}(hjOh]hReturn}(hjQhhhNhNubah}(h]h ]h"]h$]h&]uh1johjMubah}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKuhjjubj()}(hblandlock_cred(**cred**) if any access rights specified in **masks** is handled, or NULL otherwise.h](hlandlock_cred(}(hjehhhNhNubjp)}(h**cred**h]hcred}(hjmhhhNhNubah}(h]h ]h"]h$]h&]uh1johjeubh$) if any access rights specified in }(hjehhhNhNubjp)}(h **masks**h]hmasks}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjeubh is handled, or NULL otherwise.}(hjehhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h[/var/lib/git/docbuild/linux/Documentation/security/landlock:157: ./security/landlock/cred.hhKuhjjubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubeh}(h]process-credentialah ]h"]process credentialah$]h&]uh1hhjhhhhhKubh)}(hhh](h)}(hRuleset and domainh]hRuleset and domain}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1hhjhhhhhKubj()}(hX4A domain is a read-only ruleset tied to a set of subjects (i.e. tasks' credentials). Each time a ruleset is enforced on a task, the current domain is duplicated and the ruleset is imported as a new layer of rules in the new domain. Indeed, once in a domain, each rule is tied to a layer level. To grant access to an object, at least one rule of each layer must allow the requested action on the object. A task can then only transit to a new domain that is the intersection of the constraints from the current domain and those of a ruleset provided by the task.h]hX6A domain is a read-only ruleset tied to a set of subjects (i.e. tasks’ credentials). Each time a ruleset is enforced on a task, the current domain is duplicated and the ruleset is imported as a new layer of rules in the new domain. Indeed, once in a domain, each rule is tied to a layer level. To grant access to an object, at least one rule of each layer must allow the requested action on the object. A task can then only transit to a new domain that is the intersection of the constraints from the current domain and those of a ruleset provided by the task.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhKhjhhubj()}(hThe definition of a subject is implicit for a task sandboxing itself, which makes the reasoning much easier and helps avoid pitfalls.h]hThe definition of a subject is implicit for a task sandboxing itself, which makes the reasoning much easier and helps avoid pitfalls.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhKhjhhubj)}(hhh]h}(h]h ]h"]h$]h&]entries](jlandlock_layer (C struct)c.landlock_layerhNtauh1jhjhhhNhNubj)}(hhh](j)}(hlandlock_layerh]j)}(hstruct landlock_layerh](j)}(hjh]hstruct}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhjhKubj )}(hlandlock_layerh]j)}(hjh]hlandlock_layer}(hj hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj ubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hjhhhjhKubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hjhhhjhKubah}(h]jah ](j5j6eh"]h$]h&]j:j;)j<huh1jhjhKhjhhubj>)}(hhh]j()}(hAccess rights for a given layerh]hAccess rights for a given layer}(hj/hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj,hhubah}(h]h ]h"]h$]h&]uh1j=hjhhhjhKubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`jGjajGjbjcjduh1jhhhjhNhNubjf)}(hXR**Definition**:: struct landlock_layer { u8 level; struct { u8 quiet : 1; } flags; access_mask_t access; }; **Members** ``level`` Position of this layer in the layer stack. Starts from 1. ``flags`` Bitfield for special flags attached to this rule. ``flags.quiet`` Suppresses denial logs for the object covered by this rule in this domain. For filesystem rules, this inherits down the file hierarchy. ``access`` Bitfield of allowed actions on the kernel object. They are relative to the object type (e.g. ``LANDLOCK_ACTION_FS_READ``).h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hjShhhNhNubah}(h]h ]h"]h$]h&]uh1johjOubh:}(hjOhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhjKubj)}(hrstruct landlock_layer { u8 level; struct { u8 quiet : 1; } flags; access_mask_t access; };h]hrstruct landlock_layer { u8 level; struct { u8 quiet : 1; } flags; access_mask_t access; };}hjlsbah}(h]h ]h"]h$]h&]hhuh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhjKubj()}(h **Members**h]jp)}(hj}h]hMembers}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johj{ubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK&hjKubj)}(hhh](j)}(hE``level`` Position of this layer in the layer stack. Starts from 1. h](j)}(h ``level``h]j)}(hjh]hlevel}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhjubj)}(hhh]j()}(h:Position of this layer in the layer stack. Starts from 1.h]h:Position of this layer in the layer stack. Starts from 1.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjhKhjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhKhjubj)}(h<``flags`` Bitfield for special flags attached to this rule. h](j)}(h ``flags``h]j)}(hjh]hflags}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK!hjubj)}(hhh]j()}(h1Bitfield for special flags attached to this rule.h]h1Bitfield for special flags attached to this rule.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjhK!hjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhK!hjubj)}(h``flags.quiet`` Suppresses denial logs for the object covered by this rule in this domain. For filesystem rules, this inherits down the file hierarchy. h](j)}(h``flags.quiet``h]j)}(hjh]h flags.quiet}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhj ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK'hjubj)}(hhh]j()}(hSuppresses denial logs for the object covered by this rule in this domain. For filesystem rules, this inherits down the file hierarchy.h]hSuppresses denial logs for the object covered by this rule in this domain. For filesystem rules, this inherits down the file hierarchy.}(hj'hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK%hj$ubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhj#hK'hjubj)}(h``access`` Bitfield of allowed actions on the kernel object. They are relative to the object type (e.g. ``LANDLOCK_ACTION_FS_READ``).h](j)}(h ``access``h]j)}(hjHh]haccess}(hjJhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjFubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK,hjBubj)}(hhh]j()}(h{Bitfield of allowed actions on the kernel object. They are relative to the object type (e.g. ``LANDLOCK_ACTION_FS_READ``).h](h^Bitfield of allowed actions on the kernel object. They are relative to the object type (e.g. }(hjahhhNhNubj)}(h``LANDLOCK_ACTION_FS_READ``h]hLANDLOCK_ACTION_FS_READ}(hjihhhNhNubah}(h]h ]h"]h$]h&]uh1jhjaubh).}(hjahhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hj]hK,hj^ubah}(h]h ]h"]h$]h&]uh1jhjBubeh}(h]h ]h"]h$]h&]uh1jhj]hK,hjubeh}(h]h ]h"]h$]h&]uh1jhjKubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubj)}(hhh]h}(h]h ]h"]h$]h&]entries](jlandlock_key (C union)c.landlock_keyhNtauh1jhjhhhNhNubj)}(hhh](j)}(h landlock_keyh]j)}(hunion landlock_keyh](j)}(hunionh]hunion}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK3ubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhjhK3ubj )}(h landlock_keyh]j)}(hjh]h landlock_key}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hjhhhjhK3ubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hjhhhjhK3ubah}(h]jah ](j5j6eh"]h$]h&]j:j;)j<huh1jhjhK3hjhhubj>)}(hhh]j()}(h!Key of a ruleset's red-black treeh]h#Key of a ruleset’s red-black tree}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK2hjhhubah}(h]h ]h"]h$]h&]uh1j=hjhhhjhK3ubeh}(h]h ](jZunioneh"]h$]h&]j_jZj`jjajjbjcjduh1jhhhjhNhNubjf)}(hX **Definition**:: union landlock_key { struct landlock_object *object; uintptr_t data; }; **Members** ``object`` Pointer to identify a kernel object (e.g. an inode). ``data`` Raw data to identify an arbitrary 32-bit value (e.g. a TCP port).h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubh:}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK6hjubj)}(hOunion landlock_key { struct landlock_object *object; uintptr_t data; };h]hOunion landlock_key { struct landlock_object *object; uintptr_t data; };}hj3sbah}(h]h ]h"]h$]h&]hhuh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK8hjubj()}(h **Members**h]jp)}(hjDh]hMembers}(hjFhhhNhNubah}(h]h ]h"]h$]h&]uh1johjBubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK=hjubj)}(hhh](j)}(h@``object`` Pointer to identify a kernel object (e.g. an inode). h](j)}(h ``object``h]j)}(hjch]hobject}(hjehhhNhNubah}(h]h ]h"]h$]h&]uh1jhjaubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK7hj]ubj)}(hhh]j()}(h4Pointer to identify a kernel object (e.g. an inode).h]h4Pointer to identify a kernel object (e.g. an inode).}(hj|hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjxhK7hjyubah}(h]h ]h"]h$]h&]uh1jhj]ubeh}(h]h ]h"]h$]h&]uh1jhjxhK7hjZubj)}(hJ``data`` Raw data to identify an arbitrary 32-bit value (e.g. a TCP port).h](j)}(h``data``h]j)}(hjh]hdata}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK;hjubj)}(hhh]j()}(hARaw data to identify an arbitrary 32-bit value (e.g. a TCP port).h]hARaw data to identify an arbitrary 32-bit value (e.g. a TCP port).}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjhK;hjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhK;hjZubeh}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubj)}(hhh]h}(h]h ]h"]h$]h&]entries](jlandlock_key_type (C enum)c.landlock_key_typehNtauh1jhjhhhNhNubj)}(hhh](j)}(hlandlock_key_typeh]j)}(henum landlock_key_typeh](j)}(henumh]henum}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKBubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhjhKBubj )}(hlandlock_key_typeh]j)}(hjh]hlandlock_key_type}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hjhhhjhKBubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hjhhhjhKBubah}(h]jah ](j5j6eh"]h$]h&]j:j;)j<huh1jhjhKBhjhhubj>)}(hhh]j()}(h3Type of :c:type:`union landlock_key `h](hType of }(hj8hhhNhNubh)}(h+:c:type:`union landlock_key `h]j)}(hjBh]hunion landlock_key}(hjDhhhNhNubah}(h]h ](j jZc-typeeh"]h$]h&]uh1jhj@ubah}(h]h ]h"]h$]h&]refdocj refdomainjZreftypetype refexplicitrefwarnj j )}j! ]jj)}jbjsbc.landlock_key_typeasbj# landlock_keyuh1hh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj8ubeh}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKAhj5hhubah}(h]h ]h"]h$]h&]uh1j=hjhhhjhKBubeh}(h]h ](jZenumeh"]h$]h&]j_jZj`jwjajwjbjcjduh1jhhhjhNhNubjf)}(h**Constants** ``LANDLOCK_KEY_INODE`` Type of :c:type:`landlock_rules.root_inode `'s node keys. ``LANDLOCK_KEY_NET_PORT`` Type of :c:type:`landlock_rules.root_net_port `'s node keys.h](j()}(h **Constants**h]jp)}(hjh]h Constants}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKEhj{ubj)}(hhh](j)}(ha``LANDLOCK_KEY_INODE`` Type of :c:type:`landlock_rules.root_inode `'s node keys. h](j)}(h``LANDLOCK_KEY_INODE``h]j)}(hjh]hLANDLOCK_KEY_INODE}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKHhjubj)}(hhh]j()}(hIType of :c:type:`landlock_rules.root_inode `'s node keys.h](hType of }(hjhhhNhNubh)}(h4:c:type:`landlock_rules.root_inode `h]j)}(hjh]hlandlock_rules.root_inode}(hjhhhNhNubah}(h]h ](j jZc-typeeh"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]refdocj refdomainjZreftypetype refexplicitrefwarnj j j# landlock_rulesuh1hhjhKHhjubh’s node keys.}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hjhKHhjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhKHhjubj)}(hf``LANDLOCK_KEY_NET_PORT`` Type of :c:type:`landlock_rules.root_net_port `'s node keys.h](j)}(h``LANDLOCK_KEY_NET_PORT``h]j)}(hjh]hLANDLOCK_KEY_NET_PORT}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKKhjubj)}(hhh]j()}(hLType of :c:type:`landlock_rules.root_net_port `'s node keys.h](hType of }(hjhhhNhNubh)}(h7:c:type:`landlock_rules.root_net_port `h]j)}(hjh]hlandlock_rules.root_net_port}(hj!hhhNhNubah}(h]h ](j jZc-typeeh"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]refdocj refdomainjZreftypetype refexplicitrefwarnj j j# landlock_rulesuh1hhjhKKhjubh’s node keys.}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hjhKKhjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhKKhjubeh}(h]h ]h"]h$]h&]uh1jhj{ubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubj)}(hhh]h}(h]h ]h"]h$]h&]entries](jlandlock_id (C struct) c.landlock_idhNtauh1jhjhhhNhNubj)}(hhh](j)}(h landlock_idh]j)}(hstruct landlock_idh](j)}(hjh]hstruct}(hjxhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjthhh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKQubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjthhhjhKQubj )}(h landlock_idh]j)}(hjrh]h landlock_id}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hjthhhjhKQubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hjphhhjhKQubah}(h]jkah ](j5j6eh"]h$]h&]j:j;)j<huh1jhjhKQhjmhhubj>)}(hhh]j()}(h$Unique rule identifier for a ruleseth]h$Unique rule identifier for a ruleset}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKPhjhhubah}(h]h ]h"]h$]h&]uh1j=hjmhhhjhKQubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`jjajjbjcjduh1jhhhjhNhNubjf)}(hX**Definition**:: struct landlock_id { union landlock_key key; const enum landlock_key_type type; }; **Members** ``key`` Identifies either a kernel object (e.g. an inode) or a raw value (e.g. a TCP port). ``type`` Type of a landlock_ruleset's root tree.h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubh:}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKThjubj)}(hZstruct landlock_id { union landlock_key key; const enum landlock_key_type type; };h]hZstruct landlock_id { union landlock_key key; const enum landlock_key_type type; };}hjsbah}(h]h ]h"]h$]h&]hhuh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKVhjubj()}(h **Members**h]jp)}(hjh]hMembers}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1johjubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK[hjubj)}(hhh](j)}(h\``key`` Identifies either a kernel object (e.g. an inode) or a raw value (e.g. a TCP port). h](j)}(h``key``h]j)}(hj'h]hkey}(hj)hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj%ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKVhj!ubj)}(hhh]j()}(hSIdentifies either a kernel object (e.g. an inode) or a raw value (e.g. a TCP port).h]hSIdentifies either a kernel object (e.g. an inode) or a raw value (e.g. a TCP port).}(hj@hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKUhj=ubah}(h]h ]h"]h$]h&]uh1jhj!ubeh}(h]h ]h"]h$]h&]uh1jhj<hKVhjubj)}(h0``type`` Type of a landlock_ruleset's root tree.h](j)}(h``type``h]j)}(hjah]htype}(hjchhhNhNubah}(h]h ]h"]h$]h&]uh1jhj_ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKYhj[ubj)}(hhh]j()}(h'Type of a landlock_ruleset's root tree.h]h)Type of a landlock_ruleset’s root tree.}(hjzhhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKZhjwubah}(h]h ]h"]h$]h&]uh1jhj[ubeh}(h]h ]h"]h$]h&]uh1jhjvhKYhjubeh}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubj)}(hhh]h}(h]h ]h"]h$]h&]entries](jlandlock_rule (C struct)c.landlock_rulehNtauh1jhjhhhNhNubj)}(hhh](j)}(h landlock_ruleh]j)}(hstruct landlock_ruleh](j)}(hjh]hstruct}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK`ubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjhhhjhK`ubj )}(h landlock_ruleh]j)}(hjh]h landlock_rule}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hjhhhjhK`ubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hjhhhjhK`ubah}(h]jah ](j5j6eh"]h$]h&]j:j;)j<huh1jhjhK`hjhhubj>)}(hhh]j()}(hAccess rights tied to an objecth]hAccess rights tied to an object}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK_hjhhubah}(h]h ]h"]h$]h&]uh1j=hjhhhjhK`ubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`jjajjbjcjduh1jhhhjhNhNubjf)}(hX**Definition**:: struct landlock_rule { struct rb_node node; union landlock_key key; u32 num_layers; struct landlock_layer layers[]; }; **Members** ``node`` Node in the ruleset's red-black tree. ``key`` A union to identify either a kernel object (e.g. an inode) or a raw data value (e.g. a network socket port). This is used as a key for this ruleset element. The pointer is set once and never modified. It always points to an allocated object because each rule increments the refcount of its object. ``num_layers`` Number of entries in **layers**. ``layers`` Stack of layers, from the latest to the newest, implemented as a flexible array member (FAM).h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hj!hhhNhNubah}(h]h ]h"]h$]h&]uh1johjubh:}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKchjubj)}(hstruct landlock_rule { struct rb_node node; union landlock_key key; u32 num_layers; struct landlock_layer layers[]; };h]hstruct landlock_rule { struct rb_node node; union landlock_key key; u32 num_layers; struct landlock_layer layers[]; };}hj:sbah}(h]h ]h"]h$]h&]hhuh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKehjubj()}(h **Members**h]jp)}(hjKh]hMembers}(hjMhhhNhNubah}(h]h ]h"]h$]h&]uh1johjIubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKlhjubj)}(hhh](j)}(h/``node`` Node in the ruleset's red-black tree. h](j)}(h``node``h]j)}(hjjh]hnode}(hjlhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjhubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKdhjdubj)}(hhh]j()}(h%Node in the ruleset's red-black tree.h]h'Node in the ruleset’s red-black tree.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjhKdhjubah}(h]h ]h"]h$]h&]uh1jhjdubeh}(h]h ]h"]h$]h&]uh1jhjhKdhjaubj)}(hX4``key`` A union to identify either a kernel object (e.g. an inode) or a raw data value (e.g. a network socket port). This is used as a key for this ruleset element. The pointer is set once and never modified. It always points to an allocated object because each rule increments the refcount of its object. h](j)}(h``key``h]j)}(hjh]hkey}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKlhjubj)}(hhh]j()}(hX+A union to identify either a kernel object (e.g. an inode) or a raw data value (e.g. a network socket port). This is used as a key for this ruleset element. The pointer is set once and never modified. It always points to an allocated object because each rule increments the refcount of its object.h]hX+A union to identify either a kernel object (e.g. an inode) or a raw data value (e.g. a network socket port). This is used as a key for this ruleset element. The pointer is set once and never modified. It always points to an allocated object because each rule increments the refcount of its object.}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhhjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhKlhjaubj)}(h0``num_layers`` Number of entries in **layers**. h](j)}(h``num_layers``h]j)}(hjh]h num_layers}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1jhjubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKphjubj)}(hhh]j()}(h Number of entries in **layers**.h](hNumber of entries in }(hjhhhNhNubjp)}(h **layers**h]hlayers}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubh.}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hjhKphjubah}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ]h"]h$]h&]uh1jhjhKphjaubj)}(hh``layers`` Stack of layers, from the latest to the newest, implemented as a flexible array member (FAM).h](j)}(h ``layers``h]j)}(hj(h]hlayers}(hj*hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj&ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKthj"ubj)}(hhh]j()}(h]Stack of layers, from the latest to the newest, implemented as a flexible array member (FAM).h]h]Stack of layers, from the latest to the newest, implemented as a flexible array member (FAM).}(hjAhhhNhNubah}(h]h ]h"]h$]h&]uh1j'hj=hKthj>ubah}(h]h ]h"]h$]h&]uh1jhj"ubeh}(h]h ]h"]h$]h&]uh1jhj=hKthjaubeh}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubj)}(hhh]h}(h]h ]h"]h$]h&]entries](jlandlock_rules (C struct)c.landlock_ruleshNtauh1jhjhhhNhNubj)}(hhh](j)}(hlandlock_rulesh]j)}(hstruct landlock_rulesh](j)}(hjh]hstruct}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj}hhh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK{ubj)}(h h]h }(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj}hhhjhK{ubj )}(hlandlock_rulesh]j)}(hj{h]hlandlock_rules}(hjhhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hj}hhhjhK{ubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hjyhhhjhK{ubah}(h]jtah ](j5j6eh"]h$]h&]j:j;)j<huh1jhjhK{hjvhhubj>)}(hhh]j()}(h)Red-black tree storage for Landlock rulesh]h)Red-black tree storage for Landlock rules}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKzhjhhubah}(h]h ]h"]h$]h&]uh1j=hjvhhhjhK{ubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`jjajjbjcjduh1jhhhjhNhNubjf)}(hX\**Definition**:: struct landlock_rules { struct rb_root root_inode; #if IS_ENABLED(CONFIG_INET); struct rb_root root_net_port; #endif ; u32 num_rules; }; **Members** ``root_inode`` Root of a red-black tree containing :c:type:`struct landlock_rule ` nodes with inode object. Immutable for domains. ``root_net_port`` Root of a red-black tree containing :c:type:`struct landlock_rule ` nodes with network port. Immutable for domains. ``num_rules`` Number of non-overlapping (i.e. not for the same object) rules in this tree storage.h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hjhhhNhNubah}(h]h ]h"]h$]h&]uh1johjubh:}(hjhhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK~hjubj)}(hstruct landlock_rules { struct rb_root root_inode; #if IS_ENABLED(CONFIG_INET); struct rb_root root_net_port; #endif ; u32 num_rules; };h]hstruct landlock_rules { struct rb_root root_inode; #if IS_ENABLED(CONFIG_INET); struct rb_root root_net_port; #endif ; u32 num_rules; };}hj sbah}(h]h ]h"]h$]h&]hhuh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhjubj()}(h **Members**h]jp)}(hj h]hMembers}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1johj ubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhjubj)}(hhh](j)}(h``root_inode`` Root of a red-black tree containing :c:type:`struct landlock_rule ` nodes with inode object. Immutable for domains. h](j)}(h``root_inode``h]j)}(hj0 h]h root_inode}(hj2 hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj. ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj* ubj)}(hhh]j()}(hRoot of a red-black tree containing :c:type:`struct landlock_rule ` nodes with inode object. Immutable for domains.h](h$Root of a red-black tree containing }(hjI hhhNhNubh)}(h.:c:type:`struct landlock_rule `h]j)}(hjS h]hstruct landlock_rule}(hjU hhhNhNubah}(h]h ](j jZc-typeeh"]h$]h&]uh1jhjQ ubah}(h]h ]h"]h$]h&]refdocj refdomainjZreftypetype refexplicitrefwarnj j j# landlock_ruleuh1hh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhjI ubh1 nodes with inode object. Immutable for domains.}(hjI hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hjp hKhjF ubah}(h]h ]h"]h$]h&]uh1jhj* ubeh}(h]h ]h"]h$]h&]uh1jhjE hKhj' ubj)}(h``root_net_port`` Root of a red-black tree containing :c:type:`struct landlock_rule ` nodes with network port. Immutable for domains. h](j)}(h``root_net_port``h]j)}(hj h]h root_net_port}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj ubj)}(hhh]j()}(hRoot of a red-black tree containing :c:type:`struct landlock_rule ` nodes with network port. Immutable for domains.h](h$Root of a red-black tree containing }(hj hhhNhNubh)}(h.:c:type:`struct landlock_rule `h]j)}(hj h]hstruct landlock_rule}(hj hhhNhNubah}(h]h ](j jZc-typeeh"]h$]h&]uh1jhj ubah}(h]h ]h"]h$]h&]refdocj refdomainjZreftypetype refexplicitrefwarnj j j# landlock_ruleuh1hh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj ubh1 nodes with network port. Immutable for domains.}(hj hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hj hKhj ubah}(h]h ]h"]h$]h&]uh1jhj ubeh}(h]h ]h"]h$]h&]uh1jhj hKhj' ubUj)}(hb``num_rules`` Number of non-overlapping (i.e. not for the same object) rules in this tree storage.h](j)}(h ``num_rules``h]j)}(hj h]h num_rules}(hj hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj ubj)}(hhh]j()}(hTNumber of non-overlapping (i.e. not for the same object) rules in this tree storage.h]hTNumber of non-overlapping (i.e. not for the same object) rules in this tree storage.}(hj!hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hj hKhj!ubah}(h]h ]h"]h$]h&]uh1jhj ubeh}(h]h ]h"]h$]h&]uh1jhj hKhj' ubeh}(h]h ]h"]h$]h&]uh1jhjubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubj()}(h**Description**h]jp)}(hj,!h]h Description}(hj.!hhhNhNubah}(h]h ]h"]h$]h&]uh1johj*!ubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhjhhubj()}(hHThis structure holds the rule trees shared by both rulesets and domains.h]hHThis structure holds the rule trees shared by both rulesets and domains.}(hjB!hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhK{hjhhubj)}(hhh]h}(h]h ]h"]h$]h&]entries](jlandlock_ruleset (C struct)c.landlock_rulesethNtauh1jhjhhhNhNubj)}(hhh](j)}(hlandlock_ruleseth]j)}(hstruct landlock_ruleseth](j)}(hjh]hstruct}(hjj!hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjf!hhh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKubj)}(h h]h }(hjx!hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjf!hhhjw!hKubj )}(hlandlock_ruleseth]j)}(hjd!h]hlandlock_ruleset}(hj!hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj!ubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hjf!hhhjw!hKubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hjb!hhhjw!hKubah}(h]j]!ah ](j5j6eh"]h$]h&]j:j;)j<huh1jhjw!hKhj_!hhubj>)}(hhh]j()}(hLandlock ruleseth]hLandlock ruleset}(hj!hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj!hhubah}(h]h ]h"]h$]h&]uh1j=hj_!hhhjw!hKubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`j!jaj!jbjcjduh1jhhhjhNhNubjf)}(hX\**Definition**:: struct landlock_ruleset { struct landlock_rules rules; struct mutex lock; refcount_t usage; #ifdef CONFIG_TRACEPOINTS; u32 version; u64 id; #endif ; struct access_masks quiet_masks; struct access_masks handled_masks; }; **Members** ``rules`` Red-black tree storage for rules. ``lock`` Protects against concurrent modifications of **rules**, if **usage** is greater than zero. ``usage`` Number of file descriptors referencing this ruleset. ``version`` Counter incremented on each successful landlock_add_rule(2), including when it only extends an existing rule's access rights. Used by tracepoints to correlate a domain with the exact ruleset state it was created from. Protected by **lock**. ``id`` Unique identifier for this ruleset, used for tracing. ``quiet_masks`` Stores the quiet flags for an unmerged ruleset. For a merged domain, this is stored in each layer's struct landlock_hierarchy instead. ``handled_masks`` Contains the subset of filesystem and network actions that are handled by this ruleset.h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hj!hhhNhNubah}(h]h ]h"]h$]h&]uh1johj!ubh:}(hj!hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj!ubj)}(hstruct landlock_ruleset { struct landlock_rules rules; struct mutex lock; refcount_t usage; #ifdef CONFIG_TRACEPOINTS; u32 version; u64 id; #endif ; struct access_masks quiet_masks; struct access_masks handled_masks; };h]hstruct landlock_ruleset { struct landlock_rules rules; struct mutex lock; refcount_t usage; #ifdef CONFIG_TRACEPOINTS; u32 version; u64 id; #endif ; struct access_masks quiet_masks; struct access_masks handled_masks; };}hj!sbah}(h]h ]h"]h$]h&]hhuh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj!ubj()}(h **Members**h]jp)}(hj!h]hMembers}(hj!hhhNhNubah}(h]h ]h"]h$]h&]uh1johj!ubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj!ubj)}(hhh](j)}(h,``rules`` Red-black tree storage for rules. h](j)}(h ``rules``h]j)}(hj"h]hrules}(hj"hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj"ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj"ubj)}(hhh]j()}(h!Red-black tree storage for rules.h]h!Red-black tree storage for rules.}(hj2"hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hj."hKhj/"ubah}(h]h ]h"]h$]h&]uh1jhj"ubeh}(h]h ]h"]h$]h&]uh1jhj."hKhj"ubj)}(hd``lock`` Protects against concurrent modifications of **rules**, if **usage** is greater than zero. h](j)}(h``lock``h]j)}(hjR"h]hlock}(hjT"hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjP"ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhjL"ubj)}(hhh]j()}(hZProtects against concurrent modifications of **rules**, if **usage** is greater than zero.h](h-Protects against concurrent modifications of }(hjk"hhhNhNubjp)}(h **rules**h]hrules}(hjs"hhhNhNubah}(h]h ]h"]h$]h&]uh1johjk"ubh, if }(hjk"hhhNhNubjp)}(h **usage**h]husage}(hj"hhhNhNubah}(h]h ]h"]h$]h&]uh1johjk"ubh is greater than zero.}(hjk"hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhjh"ubah}(h]h ]h"]h$]h&]uh1jhjL"ubeh}(h]h ]h"]h$]h&]uh1jhjg"hKhj"ubj)}(h?``usage`` Number of file descriptors referencing this ruleset. h](j)}(h ``usage``h]j)}(hj"h]husage}(hj"hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj"ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj"ubj)}(hhh]j()}(h4Number of file descriptors referencing this ruleset.h]h4Number of file descriptors referencing this ruleset.}(hj"hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hj"hKhj"ubah}(h]h ]h"]h$]h&]uh1jhj"ubeh}(h]h ]h"]h$]h&]uh1jhj"hKhj"ubj)}(h``version`` Counter incremented on each successful landlock_add_rule(2), including when it only extends an existing rule's access rights. Used by tracepoints to correlate a domain with the exact ruleset state it was created from. Protected by **lock**. h](j)}(h ``version``h]j)}(hj"h]hversion}(hj"hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj"ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj"ubj)}(hhh]j()}(hCounter incremented on each successful landlock_add_rule(2), including when it only extends an existing rule's access rights. Used by tracepoints to correlate a domain with the exact ruleset state it was created from. Protected by **lock**.h](hCounter incremented on each successful landlock_add_rule(2), including when it only extends an existing rule’s access rights. Used by tracepoints to correlate a domain with the exact ruleset state it was created from. Protected by }(hj#hhhNhNubjp)}(h**lock**h]hlock}(hj #hhhNhNubah}(h]h ]h"]h$]h&]uh1johj#ubh.}(hj#hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj"ubah}(h]h ]h"]h$]h&]uh1jhj"ubeh}(h]h ]h"]h$]h&]uh1jhj"hKhj"ubj)}(h=``id`` Unique identifier for this ruleset, used for tracing. h](j)}(h``id``h]j)}(hj5#h]hid}(hj7#hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj3#ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj/#ubj)}(hhh]j()}(h5Unique identifier for this ruleset, used for tracing.h]h5Unique identifier for this ruleset, used for tracing.}(hjN#hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjJ#hKhjK#ubah}(h]h ]h"]h$]h&]uh1jhj/#ubeh}(h]h ]h"]h$]h&]uh1jhjJ#hKhj"ubj)}(h``quiet_masks`` Stores the quiet flags for an unmerged ruleset. For a merged domain, this is stored in each layer's struct landlock_hierarchy instead. h](j)}(h``quiet_masks``h]j)}(hjn#h]h quiet_masks}(hjp#hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjl#ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhjh#ubj)}(hhh]j()}(hStores the quiet flags for an unmerged ruleset. For a merged domain, this is stored in each layer's struct landlock_hierarchy instead.h]hStores the quiet flags for an unmerged ruleset. For a merged domain, this is stored in each layer’s struct landlock_hierarchy instead.}(hj#hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj#ubah}(h]h ]h"]h$]h&]uh1jhjh#ubeh}(h]h ]h"]h$]h&]uh1jhj#hKhj"ubj)}(hi``handled_masks`` Contains the subset of filesystem and network actions that are handled by this ruleset.h](j)}(h``handled_masks``h]j)}(hj#h]h handled_masks}(hj#hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj#ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj#ubj)}(hhh]j()}(hWContains the subset of filesystem and network actions that are handled by this ruleset.h]hWContains the subset of filesystem and network actions that are handled by this ruleset.}(hj#hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hj#hKhj#ubah}(h]h ]h"]h$]h&]uh1jhj#ubeh}(h]h ]h"]h$]h&]uh1jhj#hKhj"ubeh}(h]h ]h"]h$]h&]uh1jhj!ubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubj()}(h**Description**h]jp)}(hj#h]h Description}(hj#hhhNhNubah}(h]h ]h"]h$]h&]uh1johj#ubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhjhhubj()}(h\This data structure must contain unique entries, be updatable, and quick to match an object.h]h\This data structure must contain unique entries, be updatable, and quick to match an object.}(hj$hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhjhhubj)}(hhh]h}(h]h ]h"]h$]h&]entries](j#landlock_get_rule_root (C function)c.landlock_get_rule_roothNtauh1jhjhhhNhNubj)}(hhh](j)}(hsstruct rb_root * landlock_get_rule_root (struct landlock_rules *const rules, const enum landlock_key_type key_type)h]j)}(hqstruct rb_root *landlock_get_rule_root(struct landlock_rules *const rules, const enum landlock_key_type key_type)h](j)}(hjh]hstruct}(hj($hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$$hhh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKubj)}(h h]h }(hj6$hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$$hhhj5$hKubh)}(hhh]j)}(hrb_rooth]hrb_root}(hjG$hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjD$ubah}(h]h ]h"]h$]h&] refdomainjZreftypejb reftargetjI$modnameN classnameNj j )}j! ]jj)}jblandlock_get_rule_rootsbc.landlock_get_rule_rootasbuh1hhj$$hhhj5$hKubj)}(h h]h }(hjh$hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$$hhhj5$hKubj)}(hjwh]h*}(hjv$hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$$hhhj5$hKubj )}(hlandlock_get_rule_rooth]j)}(hje$h]hlandlock_get_rule_root}(hj$hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$ubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hj$$hhhj5$hKubj)}(hK(struct landlock_rules *const rules, const enum landlock_key_type key_type)h](j)}(h"struct landlock_rules *const rulesh](j)}(hjh]hstruct}(hj$hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$ubj)}(h h]h }(hj$hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$ubh)}(hhh]j)}(hlandlock_rulesh]hlandlock_rules}(hj$hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$ubah}(h]h ]h"]h$]h&] refdomainjZreftypejb reftargetj$modnameN classnameNj j )}j! ]jc$c.landlock_get_rule_rootasbuh1hhj$ubj)}(h h]h }(hj$hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$ubj)}(hjwh]h*}(hj$hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$ubj)}(hjh]hconst}(hj$hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$ubj)}(h h]h }(hj%hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$ubj)}(hrulesh]hrules}(hj%hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj$ubeh}(h]h ]h"]h$]h&]noemphhhuh1j hj$ubj)}(h%const enum landlock_key_type key_typeh](j)}(hjh]hconst}(hj-%hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj)%ubj)}(h h]h }(hj:%hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj)%ubj)}(hjh]henum}(hjH%hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj)%ubj)}(h h]h }(hjU%hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj)%ubh)}(hhh]j)}(hlandlock_key_typeh]hlandlock_key_type}(hjf%hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjc%ubah}(h]h ]h"]h$]h&] refdomainjZreftypejb reftargetjh%modnameN classnameNj j )}j! ]jc$c.landlock_get_rule_rootasbuh1hhj)%ubj)}(h h]h }(hj%hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj)%ubj)}(hkey_typeh]hkey_type}(hj%hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj)%ubeh}(h]h ]h"]h$]h&]noemphhhuh1j hj$ubeh}(h]h ]h"]h$]h&]hhuh1jhj$$hhhj5$hKubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hj $hhhj5$hKubah}(h]j$ah ](j5j6eh"]h$]h&]j:j;)j<huh1jhj5$hKhj$hhubj>)}(hhh]j()}(h'Get the root of a rule tree by key typeh]h'Get the root of a rule tree by key type}(hj%hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj%hhubah}(h]h ]h"]h$]h&]uh1j=hj$hhhj5$hKubeh}(h]h ](jZfunctioneh"]h$]h&]j_jZj`j%jaj%jbjcjduh1jhhhjhNhNubjf)}(h**Parameters** ``struct landlock_rules *const rules`` The rules storage to look up. ``const enum landlock_key_type key_type`` The type of key to select the tree for. **Return** A pointer to the rb_root, or ERR_PTR(-EINVAL) on unknown type.h](j()}(h**Parameters**h]jp)}(hj%h]h Parameters}(hj%hhhNhNubah}(h]h ]h"]h$]h&]uh1johj%ubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj%ubj)}(hhh](j)}(hE``struct landlock_rules *const rules`` The rules storage to look up. h](j)}(h&``struct landlock_rules *const rules``h]j)}(hj%h]h"struct landlock_rules *const rules}(hj%hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj%ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj%ubj)}(hhh]j()}(hThe rules storage to look up.h]hThe rules storage to look up.}(hj&hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hj&hKhj&ubah}(h]h ]h"]h$]h&]uh1jhj%ubeh}(h]h ]h"]h$]h&]uh1jhj&hKhj%ubj)}(hR``const enum landlock_key_type key_type`` The type of key to select the tree for. h](j)}(h)``const enum landlock_key_type key_type``h]j)}(hj6&h]h%const enum landlock_key_type key_type}(hj8&hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj4&ubah}(h]h ]h"]h$]h&]uh1jh^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj0&ubj)}(hhh]j()}(h'The type of key to select the tree for.h]h'The type of key to select the tree for.}(hjO&hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjK&hKhjL&ubah}(h]h ]h"]h$]h&]uh1jhj0&ubeh}(h]h ]h"]h$]h&]uh1jhjK&hKhj%ubeh}(h]h ]h"]h$]h&]uh1jhj%ubj()}(h **Return**h]jp)}(hjq&h]hReturn}(hjs&hhhNhNubah}(h]h ]h"]h$]h&]uh1johjo&ubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj%ubj()}(h>A pointer to the rb_root, or ERR_PTR(-EINVAL) on unknown type.h]h>A pointer to the rb_root, or ERR_PTR(-EINVAL) on unknown type.}(hj&hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h^/var/lib/git/docbuild/linux/Documentation/security/landlock:175: ./security/landlock/ruleset.hhKhj%ubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubj)}(hhh]h}(h]h ]h"]h$]h&]entries](jlandlock_details (C struct)c.landlock_detailshNtauh1jhjhhhNhNubj)}(hhh](j)}(hlandlock_detailsh]j)}(hstruct landlock_detailsh](j)}(hjh]hstruct}(hj&hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj&hhh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKubj)}(h h]h }(hj&hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj&hhhj&hKubj )}(hlandlock_detailsh]j)}(hj&h]hlandlock_details}(hj&hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj&ubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hj&hhhj&hKubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hj&hhhj&hKubah}(h]j&ah ](j5j6eh"]h$]h&]j:j;)j<huh1jhj&hKhj&hhubj>)}(hhh]j()}(hDomain's creation informationh]hDomain’s creation information}(hj&hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK1hj&hhubah}(h]h ]h"]h$]h&]uh1j=hj&hhhj&hKubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`j'jaj'jbjcjduh1jhhhjhNhNubjf)}(hX**Definition**:: struct landlock_details { struct pid *pid; uid_t uid; char comm[TASK_COMM_LEN]; char exe_path[]; }; **Members** ``pid`` PID of the task that initially restricted itself. It still identifies the same task. Keeping a reference to this PID ensures that it will not be recycled. ``uid`` UID of the task that initially restricted itself, at creation time. ``comm`` Command line of the task that initially restricted itself, at creation time. Always NULL terminated. ``exe_path`` Executable path of the task that initially restricted itself, at creation time. Always NULL terminated, and never greater than LANDLOCK_PATH_MAX_SIZE.h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hj'hhhNhNubah}(h]h ]h"]h$]h&]uh1johj'ubh:}(hj'hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK5hj'ubj)}(hsstruct landlock_details { struct pid *pid; uid_t uid; char comm[TASK_COMM_LEN]; char exe_path[]; };h]hsstruct landlock_details { struct pid *pid; uid_t uid; char comm[TASK_COMM_LEN]; char exe_path[]; };}hj5'sbah}(h]h ]h"]h$]h&]hhuh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK7hj'ubj()}(h **Members**h]jp)}(hjF'h]hMembers}(hjH'hhhNhNubah}(h]h ]h"]h$]h&]uh1johjD'ubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK>hj'ubj)}(hhh](j)}(h``pid`` PID of the task that initially restricted itself. It still identifies the same task. Keeping a reference to this PID ensures that it will not be recycled. h](j)}(h``pid``h]j)}(hje'h]hpid}(hjg'hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjc'ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK=hj_'ubj)}(hhh]j()}(hPID of the task that initially restricted itself. It still identifies the same task. Keeping a reference to this PID ensures that it will not be recycled.h]hPID of the task that initially restricted itself. It still identifies the same task. Keeping a reference to this PID ensures that it will not be recycled.}(hj~'hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK;hj{'ubah}(h]h ]h"]h$]h&]uh1jhj_'ubeh}(h]h ]h"]h$]h&]uh1jhjz'hK=hj\'ubj)}(hL``uid`` UID of the task that initially restricted itself, at creation time. h](j)}(h``uid``h]j)}(hj'h]huid}(hj'hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj'ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKAhj'ubj)}(hhh]j()}(hCUID of the task that initially restricted itself, at creation time.h]hCUID of the task that initially restricted itself, at creation time.}(hj'hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hj'hKAhj'ubah}(h]h ]h"]h$]h&]uh1jhj'ubeh}(h]h ]h"]h$]h&]uh1jhj'hKAhj\'ubj)}(ho``comm`` Command line of the task that initially restricted itself, at creation time. Always NULL terminated. h](j)}(h``comm``h]j)}(hj'h]hcomm}(hj'hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj'ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKFhj'ubj)}(hhh]j()}(heCommand line of the task that initially restricted itself, at creation time. Always NULL terminated.h]heCommand line of the task that initially restricted itself, at creation time. Always NULL terminated.}(hj'hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKEhj'ubah}(h]h ]h"]h$]h&]uh1jhj'ubeh}(h]h ]h"]h$]h&]uh1jhj'hKFhj\'ubj)}(h``exe_path`` Executable path of the task that initially restricted itself, at creation time. Always NULL terminated, and never greater than LANDLOCK_PATH_MAX_SIZE.h](j)}(h ``exe_path``h]j)}(hj(h]hexe_path}(hj(hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj(ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKKhj (ubj)}(hhh]j()}(hExecutable path of the task that initially restricted itself, at creation time. Always NULL terminated, and never greater than LANDLOCK_PATH_MAX_SIZE.h]hExecutable path of the task that initially restricted itself, at creation time. Always NULL terminated, and never greater than LANDLOCK_PATH_MAX_SIZE.}(hj+(hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKJhj((ubah}(h]h ]h"]h$]h&]uh1jhj (ubeh}(h]h ]h"]h$]h&]uh1jhj'(hKKhj\'ubeh}(h]h ]h"]h$]h&]uh1jhj'ubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubj()}(h**Description**h]jp)}(hjU(h]h Description}(hjW(hhhNhNubah}(h]h ]h"]h$]h&]uh1johjS(ubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKOhjhhubj()}(h?Rarely accessed, mainly when logging the first domain's denial.h]hARarely accessed, mainly when logging the first domain’s denial.}(hjk(hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK2hjhhubj()}(h[The contained pointers are initialized at the domain creation time and never changed again.h]h[The contained pointers are initialized at the domain creation time and never changed again.}(hjz(hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK4hjhhubj)}(hhh]h}(h]h ]h"]h$]h&]entries](jlandlock_hierarchy (C struct)c.landlock_hierarchyhNtauh1jhjhhhNhNubj)}(hhh](j)}(hlandlock_hierarchyh]j)}(hstruct landlock_hierarchyh](j)}(hjh]hstruct}(hj(hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj(hhh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK:ubj)}(h h]h }(hj(hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj(hhhj(hK:ubj )}(hlandlock_hierarchyh]j)}(hj(h]hlandlock_hierarchy}(hj(hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj(ubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hj(hhhj(hK:ubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hj(hhhj(hK:ubah}(h]j(ah ](j5j6eh"]h$]h&]j:j;)j<huh1jhj(hK:hj(hhubj>)}(hhh]j()}(hNode in a domain hierarchyh]hNode in a domain hierarchy}(hj(hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKXhj(hhubah}(h]h ]h"]h$]h&]uh1j=hj(hhhj(hK:ubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`j(jaj(jbjcjduh1jhhhjhNhNubjf)}(hXt**Definition**:: struct landlock_hierarchy { struct landlock_hierarchy *parent; refcount_t usage; #ifdef CONFIG_SECURITY_LANDLOCK_LOG; enum landlock_log_status log_status; atomic64_t num_denials; u64 id; const struct landlock_details *details; u32 log_same_exec : 1, log_new_exec : 1; struct access_masks quiet_masks; #endif ; }; **Members** ``parent`` Pointer to the parent node, or NULL if it is a root Landlock domain. ``usage`` Number of potential children domains plus their parent domain. ``log_status`` Whether this domain should be logged or not. Because concurrent log entries may be created at the same time, it is still possible to have several domain records of the same domain. ``num_denials`` Number of access requests denied by this domain. Masked (i.e. never logged) denials are still counted. ``id`` Landlock domain ID, set once at domain creation time. ``details`` Information about the related domain. ``log_same_exec`` Set if the domain is *not* configured with ``LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF``. Set to true by default. ``log_new_exec`` Set if the domain is configured with ``LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON``. Set to false by default. ``quiet_masks`` Bitmasks of access that should be quieted (i.e. not logged) if the related object is marked as quiet.h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hj)hhhNhNubah}(h]h ]h"]h$]h&]uh1johj)ubh:}(hj)hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK\hj)ubj)}(hXXstruct landlock_hierarchy { struct landlock_hierarchy *parent; refcount_t usage; #ifdef CONFIG_SECURITY_LANDLOCK_LOG; enum landlock_log_status log_status; atomic64_t num_denials; u64 id; const struct landlock_details *details; u32 log_same_exec : 1, log_new_exec : 1; struct access_masks quiet_masks; #endif ; };h]hXXstruct landlock_hierarchy { struct landlock_hierarchy *parent; refcount_t usage; #ifdef CONFIG_SECURITY_LANDLOCK_LOG; enum landlock_log_status log_status; atomic64_t num_denials; u64 id; const struct landlock_details *details; u32 log_same_exec : 1, log_new_exec : 1; struct access_masks quiet_masks; #endif ; };}hj!)sbah}(h]h ]h"]h$]h&]hhuh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK^hj)ubj()}(h **Members**h]jp)}(hj2)h]hMembers}(hj4)hhhNhNubah}(h]h ]h"]h$]h&]uh1johj0)ubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKkhj)ubj)}(hhh](j)}(hP``parent`` Pointer to the parent node, or NULL if it is a root Landlock domain. h](j)}(h ``parent``h]j)}(hjQ)h]hparent}(hjS)hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjO)ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK^hjK)ubj)}(hhh]j()}(hDPointer to the parent node, or NULL if it is a root Landlock domain.h]hDPointer to the parent node, or NULL if it is a root Landlock domain.}(hjj)hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK]hjg)ubah}(h]h ]h"]h$]h&]uh1jhjK)ubeh}(h]h ]h"]h$]h&]uh1jhjf)hK^hjH)ubj)}(hI``usage`` Number of potential children domains plus their parent domain. h](j)}(h ``usage``h]j)}(hj)h]husage}(hj)hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj)ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKchj)ubj)}(hhh]j()}(h>Number of potential children domains plus their parent domain.h]h>Number of potential children domains plus their parent domain.}(hj)hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKbhj)ubah}(h]h ]h"]h$]h&]uh1jhj)ubeh}(h]h ]h"]h$]h&]uh1jhj)hKchjH)ubj)}(h``log_status`` Whether this domain should be logged or not. Because concurrent log entries may be created at the same time, it is still possible to have several domain records of the same domain. h](j)}(h``log_status``h]j)}(hj)h]h log_status}(hj)hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj)ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKkhj)ubj)}(hhh]j()}(hWhether this domain should be logged or not. Because concurrent log entries may be created at the same time, it is still possible to have several domain records of the same domain.h]hWhether this domain should be logged or not. Because concurrent log entries may be created at the same time, it is still possible to have several domain records of the same domain.}(hj)hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKihj)ubah}(h]h ]h"]h$]h&]uh1jhj)ubeh}(h]h ]h"]h$]h&]uh1jhj)hKkhjH)ubj)}(hw``num_denials`` Number of access requests denied by this domain. Masked (i.e. never logged) denials are still counted. h](j)}(h``num_denials``h]j)}(hj)h]h num_denials}(hj*hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj)ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKphj)ubj)}(hhh]j()}(hfNumber of access requests denied by this domain. Masked (i.e. never logged) denials are still counted.h]hfNumber of access requests denied by this domain. Masked (i.e. never logged) denials are still counted.}(hj*hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKohj*ubah}(h]h ]h"]h$]h&]uh1jhj)ubeh}(h]h ]h"]h$]h&]uh1jhj*hKphjH)ubj)}(h=``id`` Landlock domain ID, set once at domain creation time. h](j)}(h``id``h]j)}(hj9*h]hid}(hj;*hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj7*ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKthj3*ubj)}(hhh]j()}(h5Landlock domain ID, set once at domain creation time.h]h5Landlock domain ID, set once at domain creation time.}(hjR*hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjN*hKthjO*ubah}(h]h ]h"]h$]h&]uh1jhj3*ubeh}(h]h ]h"]h$]h&]uh1jhjN*hKthjH)ubj)}(h2``details`` Information about the related domain. h](j)}(h ``details``h]j)}(hjr*h]hdetails}(hjt*hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjp*ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKxhjl*ubj)}(hhh]j()}(h%Information about the related domain.h]h%Information about the related domain.}(hj*hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hj*hKxhj*ubah}(h]h ]h"]h$]h&]uh1jhjl*ubeh}(h]h ]h"]h$]h&]uh1jhj*hKxhjH)ubj)}(h``log_same_exec`` Set if the domain is *not* configured with ``LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF``. Set to true by default. h](j)}(h``log_same_exec``h]j)}(hj*h]h log_same_exec}(hj*hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj*ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK}hj*ubj)}(hhh]j()}(hqSet if the domain is *not* configured with ``LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF``. Set to true by default.h](hSet if the domain is }(hj*hhhNhNubj)}(h*not*h]hnot}(hj*hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj*ubh configured with }(hj*hhhNhNubj)}(h,``LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF``h]h(LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF}(hj*hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj*ubh. Set to true by default.}(hj*hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhK|hj*ubah}(h]h ]h"]h$]h&]uh1jhj*ubeh}(h]h ]h"]h$]h&]uh1jhj*hK}hjH)ubj)}(h|``log_new_exec`` Set if the domain is configured with ``LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON``. Set to false by default. h](j)}(h``log_new_exec``h]j)}(hj +h]h log_new_exec}(hj +hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj+ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj+ubj)}(hhh]j()}(hjSet if the domain is configured with ``LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON``. Set to false by default.h](h%Set if the domain is configured with }(hj"+hhhNhNubj)}(h*``LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON``h]h&LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON}(hj*+hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj"+ubh. Set to false by default.}(hj"+hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj+ubah}(h]h ]h"]h$]h&]uh1jhj+ubeh}(h]h ]h"]h$]h&]uh1jhj+hKhjH)ubj)}(hu``quiet_masks`` Bitmasks of access that should be quieted (i.e. not logged) if the related object is marked as quiet.h](j)}(h``quiet_masks``h]j)}(hjU+h]h quiet_masks}(hjW+hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjS+ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhjO+ubj)}(hhh]j()}(heBitmasks of access that should be quieted (i.e. not logged) if the related object is marked as quiet.h]heBitmasks of access that should be quieted (i.e. not logged) if the related object is marked as quiet.}(hjn+hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjj+hKhjk+ubah}(h]h ]h"]h$]h&]uh1jhjO+ubeh}(h]h ]h"]h$]h&]uh1jhjj+hKhjH)ubeh}(h]h ]h"]h$]h&]uh1jhj)ubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubj)}(hhh]h}(h]h ]h"]h$]h&]entries](jlandlock_domain (C struct)c.landlock_domainhNtauh1jhjhhhNhNubj)}(hhh](j)}(hlandlock_domainh]j)}(hstruct landlock_domainh](j)}(hjh]hstruct}(hj+hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj+hhh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKubj)}(h h]h }(hj+hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj+hhhj+hKubj )}(hlandlock_domainh]j)}(hj+h]hlandlock_domain}(hj+hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj+ubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hj+hhhj+hKubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hj+hhhj+hKubah}(h]j+ah ](j5j6eh"]h$]h&]j:j;)j<huh1jhj+hKhj+hhubj>)}(hhh]j()}(hImmutable Landlock domainh]hImmutable Landlock domain}(hj+hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj+hhubah}(h]h ]h"]h$]h&]uh1j=hj+hhhj+hKubeh}(h]h ](jZstructeh"]h$]h&]j_jZj`j,jaj,jbjcjduh1jhhhjhNhNubjf)}(hX**Definition**:: struct landlock_domain { struct landlock_rules rules; struct landlock_hierarchy *hierarchy; union { struct work_struct work_free; struct { refcount_t usage; u32 num_layers; struct access_masks handled_masks[]; }; }; }; **Members** ``rules`` Red-black tree storage for rules. ``hierarchy`` Enables hierarchy identification even when a parent domain vanishes. This is needed for the ptrace and scope restrictions. ``{unnamed_union}`` anonymous ``work_free`` Enables to free a domain within a lockless section. This is only used by landlock_put_domain_deferred() when **usage** reaches zero. The fields **usage**, **num_layers** and **handled_masks** are then unused. ``{unnamed_struct}`` anonymous ``usage`` Number of credentials referencing this domain. ``num_layers`` Number of layers that are used in this domain. This enables to check that all the layers allow an access request. ``handled_masks`` Contains the subset of filesystem and network actions that are restricted by a domain. A domain saves all layers of merged rulesets in a stack (FAM), starting from the first layer to the last one. These layers are used when merging rulesets, for user space backward compatibility (i.e. future-proof), and to properly handle merged rulesets without overlapping access rights. These layers are set once and never changed for the lifetime of the domain.h](j()}(h**Definition**::h](jp)}(h**Definition**h]h Definition}(hj,hhhNhNubah}(h]h ]h"]h$]h&]uh1johj,ubh:}(hj,hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj ,ubj)}(hX&struct landlock_domain { struct landlock_rules rules; struct landlock_hierarchy *hierarchy; union { struct work_struct work_free; struct { refcount_t usage; u32 num_layers; struct access_masks handled_masks[]; }; }; };h]hX&struct landlock_domain { struct landlock_rules rules; struct landlock_hierarchy *hierarchy; union { struct work_struct work_free; struct { refcount_t usage; u32 num_layers; struct access_masks handled_masks[]; }; }; };}hj-,sbah}(h]h ]h"]h$]h&]hhuh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj ,ubj()}(h **Members**h]jp)}(hj>,h]hMembers}(hj@,hhhNhNubah}(h]h ]h"]h$]h&]uh1johj<,ubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj ,ubj)}(hhh](j)}(h,``rules`` Red-black tree storage for rules. h](j)}(h ``rules``h]j)}(hj],h]hrules}(hj_,hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj[,ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhjW,ubj)}(hhh]j()}(h!Red-black tree storage for rules.h]h!Red-black tree storage for rules.}(hjv,hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjr,hKhjs,ubah}(h]h ]h"]h$]h&]uh1jhjW,ubeh}(h]h ]h"]h$]h&]uh1jhjr,hKhjT,ubj)}(h``hierarchy`` Enables hierarchy identification even when a parent domain vanishes. This is needed for the ptrace and scope restrictions. h](j)}(h ``hierarchy``h]j)}(hj,h]h hierarchy}(hj,hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj,ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj,ubj)}(hhh]j()}(h{Enables hierarchy identification even when a parent domain vanishes. This is needed for the ptrace and scope restrictions.h]h{Enables hierarchy identification even when a parent domain vanishes. This is needed for the ptrace and scope restrictions.}(hj,hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj,ubah}(h]h ]h"]h$]h&]uh1jhj,ubeh}(h]h ]h"]h$]h&]uh1jhj,hKhjT,ubj)}(h``{unnamed_union}`` anonymous h](j)}(h``{unnamed_union}``h]j)}(hj,h]h{unnamed_union}}(hj,hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj,ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj,ubj)}(hhh]j()}(h anonymoush]h anonymous}(hj,hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hj,hKhj,ubah}(h]h ]h"]h$]h&]uh1jhj,ubeh}(h]h ]h"]h$]h&]uh1jhj,hKhjT,ubj)}(h``work_free`` Enables to free a domain within a lockless section. This is only used by landlock_put_domain_deferred() when **usage** reaches zero. The fields **usage**, **num_layers** and **handled_masks** are then unused. h](j)}(h ``work_free``h]j)}(hj -h]h work_free}(hj -hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj-ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj-ubj)}(hhh]j()}(hEnables to free a domain within a lockless section. This is only used by landlock_put_domain_deferred() when **usage** reaches zero. The fields **usage**, **num_layers** and **handled_masks** are then unused.h](hnEnables to free a domain within a lockless section. This is only used by landlock_put_domain_deferred() when }(hj"-hhhNhNubjp)}(h **usage**h]husage}(hj*-hhhNhNubah}(h]h ]h"]h$]h&]uh1johj"-ubh reaches zero. The fields }(hj"-hhhNhNubjp)}(h **usage**h]husage}(hj<-hhhNhNubah}(h]h ]h"]h$]h&]uh1johj"-ubh, }(hj"-hhhNhNubjp)}(h**num_layers**h]h num_layers}(hjN-hhhNhNubah}(h]h ]h"]h$]h&]uh1johj"-ubh and }(hj"-hhhNhNubjp)}(h**handled_masks**h]h handled_masks}(hj`-hhhNhNubah}(h]h ]h"]h$]h&]uh1johj"-ubh are then unused.}(hj"-hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj-ubah}(h]h ]h"]h$]h&]uh1jhj-ubeh}(h]h ]h"]h$]h&]uh1jhj-hKhjT,ubj)}(h``{unnamed_struct}`` anonymous h](j)}(h``{unnamed_struct}``h]j)}(hj-h]h{unnamed_struct}}(hj-hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj-ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj-ubj)}(hhh]j()}(h anonymoush]h anonymous}(hj-hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hj-hKhj-ubah}(h]h ]h"]h$]h&]uh1jhj-ubeh}(h]h ]h"]h$]h&]uh1jhj-hKhjT,ubj)}(h9``usage`` Number of credentials referencing this domain. h](j)}(h ``usage``h]j)}(hj-h]husage}(hj-hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj-ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj-ubj)}(hhh]j()}(h.Number of credentials referencing this domain.h]h.Number of credentials referencing this domain.}(hj-hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj-ubah}(h]h ]h"]h$]h&]uh1jhj-ubeh}(h]h ]h"]h$]h&]uh1jhj-hKhjT,ubj)}(h``num_layers`` Number of layers that are used in this domain. This enables to check that all the layers allow an access request. h](j)}(h``num_layers``h]j)}(hj-h]h num_layers}(hj.hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj-ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj-ubj)}(hhh]j()}(hrNumber of layers that are used in this domain. This enables to check that all the layers allow an access request.h]hrNumber of layers that are used in this domain. This enables to check that all the layers allow an access request.}(hj.hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj.ubah}(h]h ]h"]h$]h&]uh1jhj-ubeh}(h]h ]h"]h$]h&]uh1jhj.hKhjT,ubj)}(hX``handled_masks`` Contains the subset of filesystem and network actions that are restricted by a domain. A domain saves all layers of merged rulesets in a stack (FAM), starting from the first layer to the last one. These layers are used when merging rulesets, for user space backward compatibility (i.e. future-proof), and to properly handle merged rulesets without overlapping access rights. These layers are set once and never changed for the lifetime of the domain.h](j)}(h``handled_masks``h]j)}(hj8.h]h handled_masks}(hj:.hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj6.ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj2.ubj)}(hhh]j()}(hXContains the subset of filesystem and network actions that are restricted by a domain. A domain saves all layers of merged rulesets in a stack (FAM), starting from the first layer to the last one. These layers are used when merging rulesets, for user space backward compatibility (i.e. future-proof), and to properly handle merged rulesets without overlapping access rights. These layers are set once and never changed for the lifetime of the domain.h]hXContains the subset of filesystem and network actions that are restricted by a domain. A domain saves all layers of merged rulesets in a stack (FAM), starting from the first layer to the last one. These layers are used when merging rulesets, for user space backward compatibility (i.e. future-proof), and to properly handle merged rulesets without overlapping access rights. These layers are set once and never changed for the lifetime of the domain.}(hjQ.hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhjN.ubah}(h]h ]h"]h$]h&]uh1jhj2.ubeh}(h]h ]h"]h$]h&]uh1jhjM.hKhjT,ubeh}(h]h ]h"]h$]h&]uh1jhj ,ubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubj()}(h**Description**h]jp)}(hj{.h]h Description}(hj}.hhhNhNubah}(h]h ]h"]h$]h&]uh1johjy.ubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhjhhubj()}(hA domain is created from a ruleset by landlock_merge_ruleset() and enforced on a task. Once created, its rules and access masks are immutable. Unlike :c:type:`struct landlock_ruleset `, a domain has no lock field.h](hA domain is created from a ruleset by landlock_merge_ruleset() and enforced on a task. Once created, its rules and access masks are immutable. Unlike }(hj.hhhNhNubh)}(h4:c:type:`struct landlock_ruleset `h]j)}(hj.h]hstruct landlock_ruleset}(hj.hhhNhNubah}(h]h ](j jZc-typeeh"]h$]h&]uh1jhj.ubah}(h]h ]h"]h$]h&]refdocj refdomainjZreftypetype refexplicitrefwarnj j j# landlock_rulesetuh1hh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhKhj.ubh, a domain has no lock field.}(hj.hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hj.hKhjhhubj)}(hhh]h}(h]h ]h"]h$]h&]entries](j(landlock_union_access_masks (C function)c.landlock_union_access_maskshNtauh1jhjhhhNhNubj)}(hhh](j)}(h\struct access_masks landlock_union_access_masks (const struct landlock_domain *const domain)h]j)}(h[struct access_masks landlock_union_access_masks(const struct landlock_domain *const domain)h](j)}(hjh]hstruct}(hj.hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj.hhh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhMubj)}(h h]h }(hj.hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj.hhhj.hMubh)}(hhh]j)}(h access_masksh]h access_masks}(hj.hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj.ubah}(h]h ]h"]h$]h&] refdomainjZreftypejb reftargetj.modnameN classnameNj j )}j! ]jj)}jblandlock_union_access_maskssbc.landlock_union_access_masksasbuh1hhj.hhhj.hMubj)}(h h]h }(hj/hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj.hhhj.hMubj )}(hlandlock_union_access_masksh]j)}(hj/h]hlandlock_union_access_masks}(hj./hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj*/ubah}(h]h ](j$j%eh"]h$]h&]hhuh1j hj.hhhj.hMubj)}(h,(const struct landlock_domain *const domain)h]j)}(h*const struct landlock_domain *const domainh](j)}(hjh]hconst}(hjI/hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjE/ubj)}(h h]h }(hjV/hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjE/ubj)}(hjh]hstruct}(hjd/hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjE/ubj)}(h h]h }(hjq/hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjE/ubh)}(hhh]j)}(hlandlock_domainh]hlandlock_domain}(hj/hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhj/ubah}(h]h ]h"]h$]h&] refdomainjZreftypejb reftargetj/modnameN classnameNj j )}j! ]j/c.landlock_union_access_masksasbuh1hhjE/ubj)}(h h]h }(hj/hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjE/ubj)}(hjwh]h*}(hj/hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjE/ubj)}(hjh]hconst}(hj/hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjE/ubj)}(h h]h }(hj/hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjE/ubj)}(hdomainh]hdomain}(hj/hhhNhNubah}(h]h ]jah"]h$]h&]uh1jhjE/ubeh}(h]h ]h"]h$]h&]noemphhhuh1j hjA/ubah}(h]h ]h"]h$]h&]hhuh1jhj.hhhj.hMubeh}(h]h ]h"]h$]h&]hhj/uh1jj0j1hj.hhhj.hMubah}(h]j.ah ](j5j6eh"]h$]h&]j:j;)j<huh1jhj.hMhj.hhubj>)}(hhh]j()}(h.Return all access rights handled in the domainh]h.Return all access rights handled in the domain}(hj0hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhMhj/hhubah}(h]h ]h"]h$]h&]uh1j=hj.hhhj.hMubeh}(h]h ](jZfunctioneh"]h$]h&]j_jZj`j0jaj0jbjcjduh1jhhhjhNhNubjf)}(h**Parameters** ``const struct landlock_domain *const domain`` Landlock domain **Return** An access_masks result of the OR of all the domain's access masks.h](j()}(h**Parameters**h]jp)}(hj"0h]h Parameters}(hj$0hhhNhNubah}(h]h ]h"]h$]h&]uh1johj 0ubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhMhj0ubj)}(hhh]j)}(h?``const struct landlock_domain *const domain`` Landlock domain h](j)}(h.``const struct landlock_domain *const domain``h]j)}(hjA0h]h*const struct landlock_domain *const domain}(hjC0hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj?0ubah}(h]h ]h"]h$]h&]uh1jh]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhMhj;0ubj)}(hhh]j()}(hLandlock domainh]hLandlock domain}(hjZ0hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hjV0hMhjW0ubah}(h]h ]h"]h$]h&]uh1jhj;0ubeh}(h]h ]h"]h$]h&]uh1jhjV0hMhj80ubah}(h]h ]h"]h$]h&]uh1jhj0ubj()}(h **Return**h]jp)}(hj|0h]hReturn}(hj~0hhhNhNubah}(h]h ]h"]h$]h&]uh1johjz0ubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhMhj0ubj()}(hBAn access_masks result of the OR of all the domain's access masks.h]hDAn access_masks result of the OR of all the domain’s access masks.}(hj0hhhNhNubah}(h]h ]h"]h$]h&]uh1j'h]/var/lib/git/docbuild/linux/Documentation/security/landlock:178: ./security/landlock/domain.hhMhj0ubeh}(h]h ] kernelindentah"]h$]h&]uh1jehjhhhNhNubeh}(h]ruleset-and-domainah ]h"]ruleset and domainah$]h&]uh1hhjhhhhhKubeh}(h]kernel-structuresah ]h"]kernel structuresah$]h&]uh1hhhhhhhhKubh)}(hhh](h)}(hDenial loggingh]hDenial logging}(hj0hhhNhNubah}(h]h ]h"]h$]h&]uh1hhj0hhhhhKubj()}(hXAccess denials are logged through two independent channels: audit records and tracepoints. Both are managed by the common denial framework in ``log.c``, compiled under ``CONFIG_SECURITY_LANDLOCK_LOG`` (automatically selected by ``CONFIG_AUDIT`` or ``CONFIG_TRACEPOINTS``).h](hAccess denials are logged through two independent channels: audit records and tracepoints. Both are managed by the common denial framework in }(hj0hhhNhNubj)}(h ``log.c``h]hlog.c}(hj0hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj0ubh, compiled under }(hj0hhhNhNubj)}(h ``CONFIG_SECURITY_LANDLOCK_LOG``h]hCONFIG_SECURITY_LANDLOCK_LOG}(hj0hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj0ubh (automatically selected by }(hj0hhhNhNubj)}(h``CONFIG_AUDIT``h]h CONFIG_AUDIT}(hj0hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj0ubh or }(hj0hhhNhNubj)}(h``CONFIG_TRACEPOINTS``h]hCONFIG_TRACEPOINTS}(hj1hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj0ubh).}(hj0hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhKhj0hhubj()}(hX Audit records respect audit configuration, the domain's Landlock log flags, and ``LANDLOCK_LOG_DISABLED``. Tracepoints fire unconditionally, independent of these settings. The denial counter (``num_denials``) is always incremented regardless of logging configuration.h](hRAudit records respect audit configuration, the domain’s Landlock log flags, and }(hj1hhhNhNubj)}(h``LANDLOCK_LOG_DISABLED``h]hLANDLOCK_LOG_DISABLED}(hj'1hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj1ubhY. Tracepoints fire unconditionally, independent of these settings. The denial counter (}(hj1hhhNhNubj)}(h``num_denials``h]h num_denials}(hj91hhhNhNubah}(h]h ]h"]h$]h&]uh1jhj1ubh<) is always incremented regardless of logging configuration.}(hj1hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhKhj0hhubj()}(hXEach denial tracepoint carries a ``logged`` field reporting the audit-logging verdict: whether the denial would be written to the audit log if audit were configured and active. This verdict is the same whether or not the kernel is built with audit support, so a tracepoints-only build reports the selection audit would make. A quiet rule (``LANDLOCK_ADD_RULE_QUIET`` with the access in the ``quiet_*`` fields of ``struct landlock_ruleset_attr``) suppresses logging by setting ``logged=0`` the same way.h](h!Each denial tracepoint carries a }(hjQ1hhhNhNubj)}(h ``logged``h]hlogged}(hjY1hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjQ1ubhX* field reporting the audit-logging verdict: whether the denial would be written to the audit log if audit were configured and active. This verdict is the same whether or not the kernel is built with audit support, so a tracepoints-only build reports the selection audit would make. A quiet rule (}(hjQ1hhhNhNubj)}(h``LANDLOCK_ADD_RULE_QUIET``h]hLANDLOCK_ADD_RULE_QUIET}(hjk1hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjQ1ubh with the access in the }(hjQ1hhhNhNubj)}(h ``quiet_*``h]hquiet_*}(hj}1hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjQ1ubh fields of }(hjQ1hhhNhNubj)}(h ``struct landlock_ruleset_attr``h]hstruct landlock_ruleset_attr}(hj1hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjQ1ubh ) suppresses logging by setting }(hjQ1hhhNhNubj)}(h ``logged=0``h]hlogged=0}(hj1hhhNhNubah}(h]h ]h"]h$]h&]uh1jhjQ1ubh the same way.}(hjQ1hhhNhNubeh}(h]h ]h"]h$]h&]uh1j'hhhKhj0hhubj()}(hqSee Documentation/admin-guide/LSM/landlock.rst for audit record format, tracepoint usage, and filtering examples.h]hqSee Documentation/admin-guide/LSM/landlock.rst for audit record format, tracepoint usage, and filtering examples.}(hj1hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhKhj0hhubh)}(hhh](h)}(h Trace eventsh]h Trace events}(hj1hhhNhNubah}(h]h ]h"]h$]h&]uh1hhj1hhhhhKubj()}(hSee Documentation/trace/events-landlock.rst for trace event usage and format details; the full event reference lives there and is not duplicated here.h]hSee Documentation/trace/events-landlock.rst for trace event usage and format details; the full event reference lives there and is not duplicated here.}(hj1hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhKhj1hhubeh}(h] trace-eventsah ]h"] trace eventsah$]h&]uh1hhj0hhhhhKubeh}(h]denial-loggingah ]h"]denial loggingah$]h&]uh1hhhhhhhhKubh)}(hhh](h)}(hAdditional documentationh]hAdditional documentation}(hj1hhhNhNubah}(h]h ]h"]h$]h&]uh1hhj1hhhhhKubj)}(hhh](j)}(h(Documentation/userspace-api/landlock.rsth]j()}(hj 2h]h(Documentation/userspace-api/landlock.rst}(hj2hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhKhj 2ubah}(h]h ]h"]h$]h&]uh1jhj2hhhhhNubj)}(h*Documentation/admin-guide/LSM/landlock.rsth]j()}(hj#2h]h*Documentation/admin-guide/LSM/landlock.rst}(hj%2hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhKhj!2ubah}(h]h ]h"]h$]h&]uh1jhj2hhhhhNubj)}(h'Documentation/trace/events-landlock.rsth]j()}(hj:2h]h'Documentation/trace/events-landlock.rst}(hj<2hhhNhNubah}(h]h ]h"]h$]h&]uh1j'hhhKhj82ubah}(h]h ]h"]h$]h&]uh1jhj2hhhhhNubj)}(hhttps://landlock.io h]j()}(hhttps://landlock.ioh]j4)}(hjU2h]hhttps://landlock.io}(hjW2hhhNhNubah}(h]h ]h"]h$]h&]refurijU2uh1j3hjS2ubah}(h]h ]h"]h$]h&]uh1j'hhhKhjO2ubah}(h]h ]h"]h$]h&]uh1jhj2hhhhhNubeh}(h]h ]h"]h$]h&]jvjwuh1jhhhKhj1hhubh)}(hLinksh]hLinks}hjw2sbah}(h]h ]h"]h$]h&]hhuh1hhj1hhhhhKubj)}(h.. _tools/testing/selftests/landlock/: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/tree/tools/testing/selftests/landlock/h]h}(h] tools-testing-selftests-landlockah ]h"]!tools/testing/selftests/landlock/ah$]h&]jjuh1jhKhj1hhhhjKubeh}(h]additional-documentationah ]h"]additional documentationah$]h&]uh1hhhhhhhhKubeh}(h]!landlock-lsm-kernel-documentationah ]h"]"landlock lsm: kernel documentationah$]h&]uh1hhhhhhhhKubeh}(h]h ]h"]h$]h&]sourcehuh1hcurrent_sourceN current_lineNsettingsdocutils.frontendValues)}(hN generatorN datestampN source_linkN source_urlN toc_backlinksentryfootnote_backlinksK sectnum_xformKstrip_commentsNstrip_elements_with_classesN strip_classesN report_levelK halt_levelKexit_status_levelKdebugNwarning_streamN tracebackinput_encoding utf-8-siginput_encoding_error_handlerstrictoutput_encodingutf-8output_encoding_error_handlerj2error_encodingutf-8error_encoding_error_handlerbackslashreplace language_codeenrecord_dependenciesNconfigN id_prefixhauto_id_prefixid dump_settingsNdump_internalsNdump_transformsNdump_pseudo_xmlNexpose_internalsNstrict_visitorN_disable_configN_sourcehnj _destinationN _config_files]7/var/lib/git/docbuild/linux/Documentation/docutils.confafile_insertion_enabled raw_enabledKline_length_limitM'pep_referencesN pep_base_urlhttps://peps.python.org/pep_file_url_templatepep-%04drfc_referencesN rfc_base_url&https://datatracker.ietf.org/doc/html/ tab_widthKtrim_footnote_reference_spacesyntax_highlightlong smart_quotessmartquotes_locales]character_level_inline_markupdoctitle_xform docinfo_xformKsectsubtitle_xform image_loadinglinkembed_stylesheetcloak_email_addressessection_self_linkenvNubreporterNindirect_targets]substitution_defs}substitution_names}refnames}(file descriptor access rights]j5a!tools/testing/selftests/landlock/]jaurefids}j]jasnameids}(j2j2j}jzjcj`jjjjFjWjjVjSjjj0j0j5 j2 jjjjj0j0j1j1j1j1j2j2j2j2u nametypes}(j2j}jcjjjWjVjj0j5 jjj0j1j1j2j2uh}(j2hjzjj`jjjjFjjjjSjjjfj0jj2 jjjjjjj8 jU jZ j j jfjkjjjjj5j:jjj0jjjjjjjjkjpjjjtjyj]!jb!j$j $j&j&j(j(j+j+j.j.j1j0j1j1j2j1j2j2u footnote_refs} citation_refs} autofootnotes]autofootnote_refs]symbol_footnotes]symbol_footnote_refs] footnotes] citations]autofootnote_startKsymbol_footnote_startK id_counter collectionsCounter}Rparse_messages]transform_messages]hsystem_message)}(hhh]j()}(hhh]h>Hyperlink target "scoped-flags-interaction" is not referenced.}hj23sbah}(h]h ]h"]h$]h&]uh1j'hj/3ubah}(h]h ]h"]h$]h&]levelKtypeINFOsourcehnjlineK]uh1j-3uba transformerN include_log] decorationNhhub.