€•Œsphinx.addnodes”Œdocument”“”)�”}”(Œ rawsource”Œ”Œchildren”]”(Œ translations”Œ LanguagesNode”“”)�”}”(hhh]”(hŒ pending_xref”“”)�”}”(hhh]”Œdocutils.nodes”ŒText”“”ŒChinese (Simplified)”…”�”}”Œparent”hsbaŒ attributes”}”(Œids”]”Œclasses”]”Œnames”]”Œdupnames”]”Œbackrefs”]”Œ refdomain”Œstd”Œreftype”Œdoc”Œ reftarget”Œ)/translations/zh_CN/trace/events-landlock”Œmodname”NŒ classname”NŒ refexplicit”ˆuŒtagname”hhh ubh)�”}”(hhh]”hŒChinese (Traditional)”…”�”}”hh2sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ)/translations/zh_TW/trace/events-landlock”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒItalian”…”�”}”hhFsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ)/translations/it_IT/trace/events-landlock”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒJapanese”…”�”}”hhZsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ)/translations/ja_JP/trace/events-landlock”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒKorean”…”�”}”hhnsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ)/translations/ko_KR/trace/events-landlock”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒPortuguese (Brazilian)”…”�”}”hh‚sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ)/translations/pt_BR/trace/events-landlock”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)�”}”(hhh]”hŒSpanish”…”�”}”hh–sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ)/translations/sp_SP/trace/events-landlock”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubeh}”(h]”h ]”h"]”h$]”h&]”Œcurrent_language”ŒEnglish”uh1h hhŒ _document”hŒsource”NŒline”NubhŒcomment”“”)�”}”(hŒ SPDX-License-Identifier: GPL-2.0”h]”hŒ SPDX-License-Identifier: GPL-2.0”…”�”}”hh·sbah}”(h]”h ]”h"]”h$]”h&]”Œ xml:space”Œpreserve”uh1hµhhh²hh³ŒC/var/lib/git/docbuild/linux/Documentation/trace/events-landlock.rst”h´Kubh¶)�”}”(hŒ"Copyright © 2026 Cloudflare, Inc.”h]”hŒ"Copyright © 2026 Cloudflare, Inc.”…”�”}”hhÈsbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1hµhhh²hh³hÇh´KubhŒsection”“”)�”}”(hhh]”(hŒtitle”“”)�”}”(hŒLandlock Trace Events”h]”hŒLandlock Trace Events”…”�”}”(hhÝh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhhØh²hh³hÇh´KubhŒ field_list”“”)�”}”(hhh]”(hŒfield”“”)�”}”(hhh]”(hŒ field_name”“”)�”}”(hŒAuthor”h]”hŒAuthor”…”�”}”(hh÷h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hõhhòh³hÇh´KubhŒ field_body”“”)�”}”(hŒMickaël Salaün”h]”hŒ paragraph”“”)�”}”(hj h]”hŒMickaël Salaün”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Khjubah}”(h]”h ]”h"]”h$]”h&]”uh1jhhòubeh}”(h]”h ]”h"]”h$]”h&]”uh1hðh³hÇh´Khhíh²hubhñ)�”}”(hhh]”(hö)�”}”(hŒDate”h]”hŒDate”…”�”}”(hj)h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hõhj&h³hÇh´Kubj)�”}”(hŒSeptember 2026 ”h]”j )�”}”(hŒSeptember 2026”h]”hŒSeptember 2026”…”�”}”(hj;h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K hj7ubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj&ubeh}”(h]”h ]”h"]”h$]”h&]”uh1hðh³hÇh´K hhíh²hubeh}”(h]”h ]”h"]”h$]”h&]”uh1hëhhØh²hh³hÇh´Kubj )�”}”(hŒçLandlock emits trace events for sandbox lifecycle operations and access denials. These events can be consumed by ftrace (for human-readable trace output and filtering) and by eBPF programs (for programmatic introspection via BTF).”h]”hŒçLandlock emits trace events for sandbox lifecycle operations and access denials. These events can be consumed by ftrace (for human-readable trace output and filtering) and by eBPF programs (for programmatic introspection via BTF).”…”�”}”(hj[h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K hhØh²hubj )�”}”(hŒTUser space documentation can be found here: Documentation/userspace-api/landlock.rst”h]”hŒTUser space documentation can be found here: Documentation/userspace-api/landlock.rst”…”�”}”(hjih²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KhhØh²hubhŒwarning”“”)�”}”(hŒØLandlock trace events, like audit records, expose sensitive information about all sandboxed processes on the system. See :ref:`landlock_observability_security` for security considerations and privilege requirements.”h]”j )�”}”(hŒØLandlock trace events, like audit records, expose sensitive information about all sandboxed processes on the system. See :ref:`landlock_observability_security` for security considerations and privilege requirements.”h]”(hŒzLandlock trace events, like audit records, expose sensitive information about all sandboxed processes on the system. See ”…”�”}”(hj}h²hh³Nh´Nubh)�”}”(hŒ&:ref:`landlock_observability_security`”h]”hŒinline”“”)�”}”(hj‡h]”hŒlandlock_observability_security”…”�”}”(hj‹h²hh³Nh´Nubah}”(h]”h ]”(Œxref”Œstd”Œstd-ref”eh"]”h$]”h&]”uh1j‰hj…ubah}”(h]”h ]”h"]”h$]”h&]”Œrefdoc”Œtrace/events-landlock”Œ refdomain”j–Œreftype”Œref”Œ refexplicit”‰Œrefwarn”ˆŒ reftarget”Œlandlock_observability_security”uh1hh³hÇh´Khj}ubhŒ8 for security considerations and privilege requirements.”…”�”}”(hj}h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Khjyubah}”(h]”h ]”h"]”h$]”h&]”uh1jwhhØh²hh³hÇh´Nubh×)�”}”(hhh]”(hÜ)�”}”(hŒEvent overview”h]”hŒEvent overview”…”�”}”(hj½h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjºh²hh³hÇh´Kubj )�”}”(hŒ7Landlock trace events are organized in four categories:”h]”hŒ7Landlock trace events are organized in four categories:”…”�”}”(hjËh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Khjºh²hubj )�”}”(hŒ<**Syscall events** are emitted during Landlock system calls:”h]”(hŒstrong”“”)�”}”(hŒ**Syscall events**”h]”hŒSyscall events”…”�”}”(hjßh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjÙubhŒ* are emitted during Landlock system calls:”…”�”}”(hjÙh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Khjºh²hubhŒ bullet_list”“”)�”}”(hhh]”(hŒ list_item”“”)�”}”(hŒ5``landlock_create_ruleset``: a new ruleset is created”h]”j )�”}”(hjh]”(hŒliteral”“”)�”}”(hŒ``landlock_create_ruleset``”h]”hŒlandlock_create_ruleset”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubhŒ: a new ruleset is created”…”�”}”(hjh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K!hjþubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjùh²hh³hÇh´Nubjý)�”}”(hŒK``landlock_add_rule_path_beneath``: a filesystem rule is added to a ruleset”h]”j )�”}”(hj'h]”(j)�”}”(hŒ"``landlock_add_rule_path_beneath``”h]”hŒlandlock_add_rule_path_beneath”…”�”}”(hj,h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj)ubhŒ): a filesystem rule is added to a ruleset”…”�”}”(hj)h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K"hj%ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjùh²hh³hÇh´Nubjý)�”}”(hŒI``landlock_add_rule_net_port``: a network port rule is added to a ruleset”h]”j )�”}”(hjLh]”(j)�”}”(hŒ``landlock_add_rule_net_port``”h]”hŒlandlock_add_rule_net_port”…”�”}”(hjQh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjNubhŒ+: a network port rule is added to a ruleset”…”�”}”(hjNh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K#hjJubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjùh²hh³hÇh´Nubjý)�”}”(hŒB``landlock_create_domain``: a new domain is created from a ruleset”h]”j )�”}”(hjqh]”(j)�”}”(hŒ``landlock_create_domain``”h]”hŒlandlock_create_domain”…”�”}”(hjvh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjsubhŒ(: a new domain is created from a ruleset”…”�”}”(hjsh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K$hjoubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjùh²hh³hÇh´Nubjý)�”}”(hŒ>``landlock_enforce_domain``: a domain is enforced on a thread ”h]”j )�”}”(hŒ=``landlock_enforce_domain``: a domain is enforced on a thread”h]”(j)�”}”(hŒ``landlock_enforce_domain``”h]”hŒlandlock_enforce_domain”…”�”}”(hjœh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj˜ubhŒ": a domain is enforced on a thread”…”�”}”(hj˜h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K%hj”ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjùh²hh³hÇh´Nubeh}”(h]”h ]”h"]”h$]”h&]”Œbullet”Œ-”uh1j÷h³hÇh´K!hjºh²hubj )�”}”(hŒ7**Denial events** are emitted when an access is denied:”h]”(jÞ)�”}”(hŒ**Denial events**”h]”hŒ Denial events”…”�”}”(hjÆh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjÂubhŒ& are emitted when an access is denied:”…”�”}”(hjÂh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K'hjºh²hubjø)�”}”(hhh]”(jý)�”}”(hŒ5``landlock_deny_access_fs``: filesystem access denied”h]”j )�”}”(hjãh]”(j)�”}”(hŒ``landlock_deny_access_fs``”h]”hŒlandlock_deny_access_fs”…”�”}”(hjèh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjåubhŒ: filesystem access denied”…”�”}”(hjåh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K)hjáubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjÞh²hh³hÇh´Nubjý)�”}”(hŒ3``landlock_deny_access_net``: network access denied”h]”j )�”}”(hjh]”(j)�”}”(hŒ``landlock_deny_access_net``”h]”hŒlandlock_deny_access_net”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ: network access denied”…”�”}”(hj h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K*hjubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjÞh²hh³hÇh´Nubjý)�”}”(hŒ.``landlock_deny_ptrace``: ptrace access denied”h]”j )�”}”(hj-h]”(j)�”}”(hŒ``landlock_deny_ptrace``”h]”hŒlandlock_deny_ptrace”…”�”}”(hj2h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj/ubhŒ: ptrace access denied”…”�”}”(hj/h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K+hj+ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjÞh²hh³hÇh´Nubjý)�”}”(hŒ6``landlock_deny_scope_signal``: signal delivery denied”h]”j )�”}”(hjRh]”(j)�”}”(hŒ``landlock_deny_scope_signal``”h]”hŒlandlock_deny_scope_signal”…”�”}”(hjWh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjTubhŒ: signal delivery denied”…”�”}”(hjTh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K,hjPubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjÞh²hh³hÇh´Nubjý)�”}”(hŒQ``landlock_deny_scope_abstract_unix_socket``: abstract unix socket access denied ”h]”j )�”}”(hŒP``landlock_deny_scope_abstract_unix_socket``: abstract unix socket access denied”h]”(j)�”}”(hŒ,``landlock_deny_scope_abstract_unix_socket``”h]”hŒ(landlock_deny_scope_abstract_unix_socket”…”�”}”(hj}h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjyubhŒ$: abstract unix socket access denied”…”�”}”(hjyh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K-hjuubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjÞh²hh³hÇh´Nubeh}”(h]”h ]”h"]”h$]”h&]”jÀjÁuh1j÷h³hÇh´K)hjºh²hubj )�”}”(hŒ<**Rule evaluation events** are emitted during rule matching:”h]”(jÞ)�”}”(hŒ**Rule evaluation events**”h]”hŒRule evaluation events”…”�”}”(hj¥h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj¡ubhŒ" are emitted during rule matching:”…”�”}”(hj¡h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K0hjºh²hubjø)�”}”(hhh]”(jý)�”}”(hŒ?``landlock_check_rule_inode``: an inode-keyed rule is evaluated”h]”j )�”}”(hjÂh]”(j)�”}”(hŒ``landlock_check_rule_inode``”h]”hŒlandlock_check_rule_inode”…”�”}”(hjÇh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÄubhŒ": an inode-keyed rule is evaluated”…”�”}”(hjÄh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K2hjÀubah}”(h]”h ]”h"]”h$]”h&]”uh1jühj½h²hh³hÇh´Nubjý)�”}”(hŒI``landlock_check_rule_net_port``: a network-port-keyed rule is evaluated ”h]”j )�”}”(hŒH``landlock_check_rule_net_port``: a network-port-keyed rule is evaluated”h]”(j)�”}”(hŒ ``landlock_check_rule_net_port``”h]”hŒlandlock_check_rule_net_port”…”�”}”(hjíh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjéubhŒ(: a network-port-keyed rule is evaluated”…”�”}”(hjéh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K3hjåubah}”(h]”h ]”h"]”h$]”h&]”uh1jühj½h²hh³hÇh´Nubeh}”(h]”h ]”h"]”h$]”h&]”jÀjÁuh1j÷h³hÇh´K2hjºh²hubj )�”}”(hŒ**Lifecycle events**:”h]”(jÞ)�”}”(hŒ**Lifecycle events**”h]”hŒLifecycle events”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjubhŒ:”…”�”}”(hjh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K5hjºh²hubjø)�”}”(hhh]”(jý)�”}”(hŒ+``landlock_free_domain``: a domain is freed”h]”j )�”}”(hj2h]”(j)�”}”(hŒ``landlock_free_domain``”h]”hŒlandlock_free_domain”…”�”}”(hj7h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj4ubhŒ: a domain is freed”…”�”}”(hj4h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K7hj0ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühj-h²hh³hÇh´Nubjý)�”}”(hŒ.``landlock_free_ruleset``: a ruleset is freed ”h]”j )�”}”(hŒ-``landlock_free_ruleset``: a ruleset is freed”h]”(j)�”}”(hŒ``landlock_free_ruleset``”h]”hŒlandlock_free_ruleset”…”�”}”(hj]h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjYubhŒ: a ruleset is freed”…”�”}”(hjYh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K8hjUubah}”(h]”h ]”h"]”h$]”h&]”uh1jühj-h²hh³hÇh´Nubeh}”(h]”h ]”h"]”h$]”h&]”jÀjÁuh1j÷h³hÇh´K7hjºh²hubeh}”(h]”Œevent-overview”ah ]”h"]”Œevent overview”ah$]”h&]”uh1hÖhhØh²hh³hÇh´Kubh×)�”}”(hhh]”(hÜ)�”}”(hŒEnabling events”h]”hŒEnabling events”…”�”}”(hjŒh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhj‰h²hh³hÇh´K;ubj )�”}”(hŒEnable all Landlock events::”h]”hŒEnable all Landlock events:”…”�”}”(hjšh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K=hj‰h²hubhŒ literal_block”“”)�”}”(hŒ3echo 1 > /sys/kernel/tracing/events/landlock/enable”h]”hŒ3echo 1 > /sys/kernel/tracing/events/landlock/enable”…”�”}”hjªsbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j¨h³hÇh´K?hj‰h²hubj )�”}”(hŒEnable a specific event::”h]”hŒEnable a specific event:”…”�”}”(hj¸h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KAhj‰h²hubj©)�”}”(hŒKecho 1 > /sys/kernel/tracing/events/landlock/landlock_deny_access_fs/enable”h]”hŒKecho 1 > /sys/kernel/tracing/events/landlock/landlock_deny_access_fs/enable”…”�”}”hjÆsbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j¨h³hÇh´KChj‰h²hubj )�”}”(hŒRead the trace output::”h]”hŒRead the trace output:”…”�”}”(hjÔh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KEhj‰h²hubj©)�”}”(hŒ"cat /sys/kernel/tracing/trace_pipe”h]”hŒ"cat /sys/kernel/tracing/trace_pipe”…”�”}”hjâsbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j¨h³hÇh´KGhj‰h²hubeh}”(h]”Œenabling-events”ah ]”h"]”Œenabling events”ah$]”h&]”uh1hÖhhØh²hh³hÇh´K;ubh×)�”}”(hhh]”(hÜ)�”}”(hŒ Event samples”h]”hŒ Event samples”…”�”}”(hjûh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjøh²hh³hÇh´KJubj )�”}”(hXNA fully unprivileged program is sandboxed so that it can still run (its binary and shared libraries stay readable) and write only ``/tmp``, then it is denied reading ``/etc/passwd``, which lies outside its read-only set. ``/etc/passwd`` is world-readable, so the denial comes solely from Landlock, not from regular file permissions::”h]”(hŒ‚A fully unprivileged program is sandboxed so that it can still run (its binary and shared libraries stay readable) and write only ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``/tmp``”h]”hŒ/tmp”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ, then it is denied reading ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``/etc/passwd``”h]”hŒ /etc/passwd”…”�”}”(hj#h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ), which lies outside its read-only set. ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``/etc/passwd``”h]”hŒ /etc/passwd”…”�”}”(hj5h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ` is world-readable, so the denial comes solely from Landlock, not from regular file permissions:”…”�”}”(hj h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KLhjøh²hubj©)�”}”(hX¯$ cd /sys/kernel/tracing/events/landlock/ $ echo 1 | tee landlock_{create_ruleset,create_domain,enforce_domain,deny_access_fs,free_domain}/enable >/dev/null $ LC_ALL=C LL_FS_RO=/usr:/lib:/lib64:/bin:/etc/ld.so.cache LL_FS_RW=/tmp \ ./sandboxer cat /etc/passwd $ cat /sys/kernel/tracing/trace_pipe cat-127 [...] landlock_create_ruleset: ruleset=195cc6b76.0 handled_fs=execute|write_file|read_file|read_dir|remove_dir|remove_file|make_char|make_dir|make_reg|make_sock|make_fifo|make_block|make_sym|refer|truncate|ioctl_dev|resolve_unix handled_net= scoped= cat-127 [...] landlock_create_domain: domain=195cc6b7c parent=0 ruleset=195cc6b76.6 cat-127 [...] landlock_enforce_domain: domain=195cc6b7c complete=1 process_wide=1 no_new_privs=1 cat-127 [...] landlock_deny_access_fs: domain=195cc6b7c same_exec=0 logged=0 blockers=read_file dev=0:17 ino=5901179 path=/etc/passwd kworker/0:1-11 [...] landlock_free_domain: domain=195cc6b7c denials=1”h]”hX¯$ cd /sys/kernel/tracing/events/landlock/ $ echo 1 | tee landlock_{create_ruleset,create_domain,enforce_domain,deny_access_fs,free_domain}/enable >/dev/null $ LC_ALL=C LL_FS_RO=/usr:/lib:/lib64:/bin:/etc/ld.so.cache LL_FS_RW=/tmp \ ./sandboxer cat /etc/passwd $ cat /sys/kernel/tracing/trace_pipe cat-127 [...] landlock_create_ruleset: ruleset=195cc6b76.0 handled_fs=execute|write_file|read_file|read_dir|remove_dir|remove_file|make_char|make_dir|make_reg|make_sock|make_fifo|make_block|make_sym|refer|truncate|ioctl_dev|resolve_unix handled_net= scoped= cat-127 [...] landlock_create_domain: domain=195cc6b7c parent=0 ruleset=195cc6b76.6 cat-127 [...] landlock_enforce_domain: domain=195cc6b7c complete=1 process_wide=1 no_new_privs=1 cat-127 [...] landlock_deny_access_fs: domain=195cc6b7c same_exec=0 logged=0 blockers=read_file dev=0:17 ino=5901179 path=/etc/passwd kworker/0:1-11 [...] landlock_free_domain: domain=195cc6b7c denials=1”…”�”}”hjMsbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j¨h³hÇh´KRhjøh²hubj )�”}”(hX~The ``[...]`` replaces the ftrace CPU, flags, and timestamp columns. The first four events share the ``cat`` command name and PID because the sandboxer replaces itself with ``cat`` via ``execve()`` before the denial, and ftrace resolves a recorded PID to its latest command name. ``landlock_free_domain`` fires later from a kworker thread, so it carries that thread's name instead.”h]”(hŒThe ”…”�”}”(hj[h²hh³Nh´Nubj)�”}”(hŒ ``[...]``”h]”hŒ[...]”…”�”}”(hjch²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj[ubhŒY replaces the ftrace CPU, flags, and timestamp columns. The first four events share the ”…”�”}”(hj[h²hh³Nh´Nubj)�”}”(hŒ``cat``”h]”hŒcat”…”�”}”(hjuh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj[ubhŒA command name and PID because the sandboxer replaces itself with ”…”�”}”(hj[h²hh³Nh´Nubj)�”}”(hŒ``cat``”h]”hŒcat”…”�”}”(hj‡h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj[ubhŒ via ”…”�”}”(hj[h²hh³Nh´Nubj)�”}”(hŒ ``execve()``”h]”hŒexecve()”…”�”}”(hj™h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj[ubhŒS before the denial, and ftrace resolves a recorded PID to its latest command name. ”…”�”}”(hj[h²hh³Nh´Nubj)�”}”(hŒ``landlock_free_domain``”h]”hŒlandlock_free_domain”…”�”}”(hj«h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj[ubhŒO fires later from a kworker thread, so it carries that thread’s name instead.”…”�”}”(hj[h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K]hjøh²hubj )�”}”(hŒ˜Here ``logged=0`` shows that audit would not record this cross-execution denial under the default flags, yet the ``deny_access_fs`` event still appears.”h]”(hŒHere ”…”�”}”(hjÃh²hh³Nh´Nubj)�”}”(hŒ ``logged=0``”h]”hŒlogged=0”…”�”}”(hjËh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÃubhŒ` shows that audit would not record this cross-execution denial under the default flags, yet the ”…”�”}”(hjÃh²hh³Nh´Nubj)�”}”(hŒ``deny_access_fs``”h]”hŒdeny_access_fs”…”�”}”(hjÝh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÃubhŒ event still appears.”…”�”}”(hjÃh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Kdhjøh²hubeh}”(h]”Œ event-samples”ah ]”h"]”Œ event samples”ah$]”h&]”uh1hÖhhØh²hh³hÇh´KJubh×)�”}”(hhh]”(hÜ)�”}”(hŒDifferences from audit records”h]”hŒDifferences from audit records”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjýh²hh³hÇh´Kiubj )�”}”(hŒZTracepoints and audit records both log Landlock denials, but differ in some field formats:”h]”hŒZTracepoints and audit records both log Landlock denials, but differ in some field formats:”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Kkhjýh²hubjø)�”}”(hhh]”(jý)�”}”(hX»**Paths**: Most filesystem tracepoints resolve the path with ``d_absolute_path()`` (namespace-independent absolute paths), while mount-topology denials that carry only a dentry use ``dentry_path_raw()``. Audit uses ``d_path()`` (relative to the process's chroot). A resolution failure is reported as ````, ````, or ````. Path-based tracepoint output is deterministic regardless of the tracer's mount namespace. ”h]”j )�”}”(hXº**Paths**: Most filesystem tracepoints resolve the path with ``d_absolute_path()`` (namespace-independent absolute paths), while mount-topology denials that carry only a dentry use ``dentry_path_raw()``. Audit uses ``d_path()`` (relative to the process's chroot). A resolution failure is reported as ````, ````, or ````. Path-based tracepoint output is deterministic regardless of the tracer's mount namespace.”h]”(jÞ)�”}”(hŒ **Paths**”h]”hŒPaths”…”�”}”(hj'h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj#ubhŒ4: Most filesystem tracepoints resolve the path with ”…”�”}”(hj#h²hh³Nh´Nubj)�”}”(hŒ``d_absolute_path()``”h]”hŒd_absolute_path()”…”�”}”(hj9h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj#ubhŒc (namespace-independent absolute paths), while mount-topology denials that carry only a dentry use ”…”�”}”(hj#h²hh³Nh´Nubj)�”}”(hŒ``dentry_path_raw()``”h]”hŒdentry_path_raw()”…”�”}”(hjKh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj#ubhŒ . Audit uses ”…”�”}”(hj#h²hh³Nh´Nubj)�”}”(hŒ ``d_path()``”h]”hŒd_path()”…”�”}”(hj]h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj#ubhŒL (relative to the process’s chroot). A resolution failure is reported as ”…”�”}”(hj#h²hh³Nh´Nubj)�”}”(hŒ ````”h]”hŒ”…”�”}”(hjoh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj#ubhŒ, ”…”�”}”(hj#h²hh³Nh´Nubj)�”}”(hŒ````”h]”hŒ ”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj#ubhŒ, or ”…”�”}”(hj#h²hh³Nh´Nubj)�”}”(hŒ````”h]”hŒ ”…”�”}”(hj“h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj#ubhŒ]. Path-based tracepoint output is deterministic regardless of the tracer’s mount namespace.”…”�”}”(hj#h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Knhjubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjh²hh³hÇh´Nubjý)�”}”(hŒœ**Device names**: Tracepoints use numeric ``dev=:``. Audit uses string ``dev=""``. Numeric format is more precise for machine parsing. ”h]”j )�”}”(hŒ›**Device names**: Tracepoints use numeric ``dev=:``. Audit uses string ``dev=""``. Numeric format is more precise for machine parsing.”h]”(jÞ)�”}”(hŒ**Device names**”h]”hŒ Device names”…”�”}”(hj¹h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjµubhŒ: Tracepoints use numeric ”…”�”}”(hjµh²hh³Nh´Nubj)�”}”(hŒ``dev=:``”h]”hŒdev=:”…”�”}”(hjËh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjµubhŒ. Audit uses string ”…”�”}”(hjµh²hh³Nh´Nubj)�”}”(hŒ``dev=""``”h]”hŒ dev=""”…”�”}”(hjÝh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjµubhŒ6. Numeric format is more precise for machine parsing.”…”�”}”(hjµh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Kvhj±ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjh²hh³hÇh´Nubjý)�”}”(hXï**Denied access field**: The ``deny_access_fs`` and ``deny_access_net`` tracepoints use the ``blockers=`` field name (same as audit). Both render the blocked access rights as names: audit prefixes the category and separates with commas (e.g., ``blockers=fs.read_file``), while the tracepoints omit the category (carried by the event name) and separate with ``|`` (e.g., ``blockers=read_file``). Scope and ptrace tracepoints omit ``blockers`` because the event name identifies the denial type. ”h]”j )�”}”(hXî**Denied access field**: The ``deny_access_fs`` and ``deny_access_net`` tracepoints use the ``blockers=`` field name (same as audit). Both render the blocked access rights as names: audit prefixes the category and separates with commas (e.g., ``blockers=fs.read_file``), while the tracepoints omit the category (carried by the event name) and separate with ``|`` (e.g., ``blockers=read_file``). Scope and ptrace tracepoints omit ``blockers`` because the event name identifies the denial type.”h]”(jÞ)�”}”(hŒ**Denied access field**”h]”hŒDenied access field”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjÿubhŒ: The ”…”�”}”(hjÿh²hh³Nh´Nubj)�”}”(hŒ``deny_access_fs``”h]”hŒdeny_access_fs”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÿubhŒ and ”…”�”}”(hjÿh²hh³Nh´Nubj)�”}”(hŒ``deny_access_net``”h]”hŒdeny_access_net”…”�”}”(hj'h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÿubhŒ tracepoints use the ”…”�”}”(hjÿh²hh³Nh´Nubj)�”}”(hŒ ``blockers=``”h]”hŒ blockers=”…”�”}”(hj9h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÿubhŒ‹ field name (same as audit). Both render the blocked access rights as names: audit prefixes the category and separates with commas (e.g., ”…”�”}”(hjÿh²hh³Nh´Nubj)�”}”(hŒ``blockers=fs.read_file``”h]”hŒblockers=fs.read_file”…”�”}”(hjKh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÿubhŒY), while the tracepoints omit the category (carried by the event name) and separate with ”…”�”}”(hjÿh²hh³Nh´Nubj)�”}”(hŒ``|``”h]”hŒ|”…”�”}”(hj]h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÿubhŒ (e.g., ”…”�”}”(hjÿh²hh³Nh´Nubj)�”}”(hŒ``blockers=read_file``”h]”hŒblockers=read_file”…”�”}”(hjoh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÿubhŒ&). Scope and ptrace tracepoints omit ”…”�”}”(hjÿh²hh³Nh´Nubj)�”}”(hŒ ``blockers``”h]”hŒblockers”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÿubhŒ3 because the event name identifies the denial type.”…”�”}”(hjÿh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Kzhjûubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjh²hh³hÇh´Nubjý)�”}”(hX**Scope and ptrace target names**: Tracepoints use role-specific field names (``tracee_pid``, ``target_pid``, ``peer_pid``) that reflect the semantic of each event. Audit uses generic names (``opid``, ``ocomm``) because the audit log format is not event-type-specific. ”h]”j )�”}”(hX **Scope and ptrace target names**: Tracepoints use role-specific field names (``tracee_pid``, ``target_pid``, ``peer_pid``) that reflect the semantic of each event. Audit uses generic names (``opid``, ``ocomm``) because the audit log format is not event-type-specific.”h]”(jÞ)�”}”(hŒ!**Scope and ptrace target names**”h]”hŒScope and ptrace target names”…”�”}”(hj§h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj£ubhŒ-: Tracepoints use role-specific field names (”…”�”}”(hj£h²hh³Nh´Nubj)�”}”(hŒ``tracee_pid``”h]”hŒ tracee_pid”…”�”}”(hj¹h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj£ubhŒ, ”…”�”}”(hj£h²hh³Nh´Nubj)�”}”(hŒ``target_pid``”h]”hŒ target_pid”…”�”}”(hjËh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj£ubhŒ, ”…”�”}”hj£sbj)�”}”(hŒ ``peer_pid``”h]”hŒpeer_pid”…”�”}”(hjÝh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj£ubhŒF) that reflect the semantic of each event. Audit uses generic names (”…”�”}”(hj£h²hh³Nh´Nubj)�”}”(hŒ``opid``”h]”hŒopid”…”�”}”(hjïh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj£ubhŒ, ”…”�”}”hj£sbj)�”}”(hŒ ``ocomm``”h]”hŒocomm”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj£ubhŒ:) because the audit log format is not event-type-specific.”…”�”}”(hj£h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KƒhjŸubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjh²hh³hÇh´Nubjý)�”}”(hXÍ**Process name**: The ptrace and signal denial tracepoints include the role-prefixed ``tracee_comm=`` and ``target_comm=`` labels in the printk output for stateless consumers (each matches its sibling ``tracee_pid=``/``target_pid=`` field). eBPF consumers can read ``comm`` directly from the task_struct via BTF. The ``comm`` value is treated as untrusted input and escaped in the trace text output so it cannot inject field separators or control characters. ”h]”j )�”}”(hXÌ**Process name**: The ptrace and signal denial tracepoints include the role-prefixed ``tracee_comm=`` and ``target_comm=`` labels in the printk output for stateless consumers (each matches its sibling ``tracee_pid=``/``target_pid=`` field). eBPF consumers can read ``comm`` directly from the task_struct via BTF. The ``comm`` value is treated as untrusted input and escaped in the trace text output so it cannot inject field separators or control characters.”h]”(jÞ)�”}”(hŒ**Process name**”h]”hŒ Process name”…”�”}”(hj'h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj#ubhŒE: The ptrace and signal denial tracepoints include the role-prefixed ”…”�”}”(hj#h²hh³Nh´Nubj)�”}”(hŒ``tracee_comm=``”h]”hŒ tracee_comm=”…”�”}”(hj9h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj#ubhŒ and ”…”�”}”(hj#h²hh³Nh´Nubj)�”}”(hŒ``target_comm=``”h]”hŒ target_comm=”…”�”}”(hjKh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj#ubhŒO labels in the printk output for stateless consumers (each matches its sibling ”…”�”}”(hj#h²hh³Nh´Nubj)�”}”(hŒ``tracee_pid=``”h]”hŒ tracee_pid=”…”�”}”(hj]h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj#ubhŒ/”…”�”}”(hj#h²hh³Nh´Nubj)�”}”(hŒ``target_pid=``”h]”hŒ target_pid=”…”�”}”(hjoh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj#ubhŒ" field). eBPF consumers can read ”…”�”}”(hj#h²hh³Nh´Nubj)�”}”(hŒ``comm``”h]”hŒcomm”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj#ubhŒ- directly from the task_struct via BTF. The ”…”�”}”(hj#h²hh³Nh´Nubj)�”}”(hŒ``comm``”h]”hŒcomm”…”�”}”(hj“h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj#ubhŒ… value is treated as untrusted input and escaped in the trace text output so it cannot inject field separators or control characters.”…”�”}”(hj#h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Kˆhjubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjh²hh³hÇh´Nubjý)�”}”(hX±**Other party's domain**: A scope or ptrace denial compares the subject's denying domain (``domain=``), which is the enforcing domain and not necessarily the current task's domain, with the other party's domain. These tracepoints also report the other party's domain as a scalar ID: ``tracee_domain=`` (ptrace), ``target_domain=`` (signal), and ``peer_domain=`` (abstract unix socket). It is ``0`` when the other party is unsandboxed, and otherwise a domain ID that a consumer resolves against the ``landlock_create_ruleset`` and ``landlock_create_domain`` events it recorded. Because a scope or ptrace verdict is decided by comparing the two domains, resolving both the subject ``domain=`` and this other-party ID against those lifecycle events lets a consumer verify or reproduce the verdict by redoing the same two-domain comparison, rather than only noting which boundary was crossed. Audit records do not carry the other party's domain. ”h]”j )�”}”(hX°**Other party's domain**: A scope or ptrace denial compares the subject's denying domain (``domain=``), which is the enforcing domain and not necessarily the current task's domain, with the other party's domain. These tracepoints also report the other party's domain as a scalar ID: ``tracee_domain=`` (ptrace), ``target_domain=`` (signal), and ``peer_domain=`` (abstract unix socket). It is ``0`` when the other party is unsandboxed, and otherwise a domain ID that a consumer resolves against the ``landlock_create_ruleset`` and ``landlock_create_domain`` events it recorded. Because a scope or ptrace verdict is decided by comparing the two domains, resolving both the subject ``domain=`` and this other-party ID against those lifecycle events lets a consumer verify or reproduce the verdict by redoing the same two-domain comparison, rather than only noting which boundary was crossed. Audit records do not carry the other party's domain.”h]”(jÞ)�”}”(hŒ**Other party's domain**”h]”hŒOther party’s domain”…”�”}”(hj¹h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjµubhŒD: A scope or ptrace denial compares the subject’s denying domain (”…”�”}”(hjµh²hh³Nh´Nubj)�”}”(hŒ ``domain=``”h]”hŒdomain=”…”�”}”(hjËh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjµubhŒ¼), which is the enforcing domain and not necessarily the current task’s domain, with the other party’s domain. These tracepoints also report the other party’s domain as a scalar ID: ”…”�”}”(hjµh²hh³Nh´Nubj)�”}”(hŒ``tracee_domain=``”h]”hŒtracee_domain=”…”�”}”(hjÝh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjµubhŒ (ptrace), ”…”�”}”(hjµh²hh³Nh´Nubj)�”}”(hŒ``target_domain=``”h]”hŒtarget_domain=”…”�”}”(hjïh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjµubhŒ (signal), and ”…”�”}”(hjµh²hh³Nh´Nubj)�”}”(hŒ``peer_domain=``”h]”hŒ peer_domain=”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjµubhŒ (abstract unix socket). It is ”…”�”}”(hjµh²hh³Nh´Nubj)�”}”(hŒ``0``”h]”hŒ0”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjµubhŒe when the other party is unsandboxed, and otherwise a domain ID that a consumer resolves against the ”…”�”}”(hjµh²hh³Nh´Nubj)�”}”(hŒ``landlock_create_ruleset``”h]”hŒlandlock_create_ruleset”…”�”}”(hj% h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjµubhŒ and ”…”�”}”(hjµh²hh³Nh´Nubj)�”}”(hŒ``landlock_create_domain``”h]”hŒlandlock_create_domain”…”�”}”(hj7 h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjµubhŒ| events it recorded. Because a scope or ptrace verdict is decided by comparing the two domains, resolving both the subject ”…”�”}”(hjµh²hh³Nh´Nubj)�”}”(hŒ ``domain=``”h]”hŒdomain=”…”�”}”(hjI h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjµubhŒþ and this other-party ID against those lifecycle events lets a consumer verify or reproduce the verdict by redoing the same two-domain comparison, rather than only noting which boundary was crossed. Audit records do not carry the other party’s domain.”…”�”}”(hjµh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K�hj±ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjh²hh³hÇh´Nubeh}”(h]”h ]”h"]”h$]”h&]”jÀjÁuh1j÷h³hÇh´Knhjýh²hubeh}”(h]”Œdifferences-from-audit-records”ah ]”h"]”Œdifferences from audit records”ah$]”h&]”uh1hÖhhØh²hh³hÇh´Kiubh×)�”}”(hhh]”(hÜ)�”}”(hŒRuleset versioning”h]”hŒRuleset versioning”…”�”}”(hjx h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhju h²hh³hÇh´K ubj )�”}”(hXVSyscall events include a ruleset version (``ruleset=.``) that tracks the number of rules added to the ruleset. The version is incremented on each ``landlock_add_rule()`` call and frozen at ``landlock_restrict_self()`` time. This enables trace consumers to correlate a domain with the exact set of rules it was created from.”h]”(hŒ*Syscall events include a ruleset version (”…”�”}”(hj† h²hh³Nh´Nubj)�”}”(hŒ``ruleset=.``”h]”hŒruleset=.”…”�”}”(hjŽ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj† ubhŒ\) that tracks the number of rules added to the ruleset. The version is incremented on each ”…”�”}”(hj† h²hh³Nh´Nubj)�”}”(hŒ``landlock_add_rule()``”h]”hŒlandlock_add_rule()”…”�”}”(hj  h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj† ubhŒ call and frozen at ”…”�”}”(hj† h²hh³Nh´Nubj)�”}”(hŒ``landlock_restrict_self()``”h]”hŒlandlock_restrict_self()”…”�”}”(hj² h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj† ubhŒk time. This enables trace consumers to correlate a domain with the exact set of rules it was created from.”…”�”}”(hj† h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K¢hju h²hubeh}”(h]”Œruleset-versioning”ah ]”h"]”Œruleset versioning”ah$]”h&]”uh1hÖhhØh²hh³hÇh´K ubh×)�”}”(hhh]”(hÜ)�”}”(hŒDomain enforcement”h]”hŒDomain enforcement”…”�”}”(hjÕ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjÒ h²hh³hÇh´K©ubj )�”}”(hXThe whole-process-enforced guarantee (``complete=1 && process_wide=1``) is the observable outcome of a successful ``landlock_restrict_self(..., LANDLOCK_RESTRICT_SELF_TSYNC)``; see the thread synchronization section of Documentation/userspace-api/landlock.rst.”h]”(hŒ&The whole-process-enforced guarantee (”…”�”}”(hjã h²hh³Nh´Nubj)�”}”(hŒ ``complete=1 && process_wide=1``”h]”hŒcomplete=1 && process_wide=1”…”�”}”(hjë h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjã ubhŒ,) is the observable outcome of a successful ”…”�”}”(hjã h²hh³Nh´Nubj)�”}”(hŒ=``landlock_restrict_self(..., LANDLOCK_RESTRICT_SELF_TSYNC)``”h]”hŒ9landlock_restrict_self(..., LANDLOCK_RESTRICT_SELF_TSYNC)”…”�”}”(hjý h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjã ubhŒU; see the thread synchronization section of Documentation/userspace-api/landlock.rst.”…”�”}”(hjã h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K«hjÒ h²hubj )�”}”(hXÈThe Landlock events and the generic syscall tracepoints are complementary: the Landlock events expose the *semantic effect* of an operation (the domain, its scope, the resulting ``no_new_privs`` state), while ``raw_syscalls:sys_enter``/``sys_exit`` (or the per-syscall ``syscalls:sys_{enter,exit}_landlock_*`` under ``CONFIG_FTRACE_SYSCALLS``) expose the *raw API* -- the exact ``landlock_restrict_self()`` flags, arguments, and return value. Correlate them by thread; a ``LANDLOCK_RESTRICT_SELF_TSYNC`` operation also enforces the domain on the sibling threads, whose ``landlock_enforce_domain`` events fire in each sibling's own context rather than the caller's, so correlate those to the syscall by domain ID.”h]”(hŒjThe Landlock events and the generic syscall tracepoints are complementary: the Landlock events expose the ”…”�”}”(hj h²hh³Nh´NubhŒemphasis”“”)�”}”(hŒ*semantic effect*”h]”hŒsemantic effect”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j hj ubhŒ7 of an operation (the domain, its scope, the resulting ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``no_new_privs``”h]”hŒ no_new_privs”…”�”}”(hj1 h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ state), while ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``raw_syscalls:sys_enter``”h]”hŒraw_syscalls:sys_enter”…”�”}”(hjC h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ/”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ ``sys_exit``”h]”hŒsys_exit”…”�”}”(hjU h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ (or the per-syscall ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ(``syscalls:sys_{enter,exit}_landlock_*``”h]”hŒ$syscalls:sys_{enter,exit}_landlock_*”…”�”}”(hjg h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ under ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``CONFIG_FTRACE_SYSCALLS``”h]”hŒCONFIG_FTRACE_SYSCALLS”…”�”}”(hjy h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ ) expose the ”…”�”}”(hj h²hh³Nh´Nubj )�”}”(hŒ *raw API*”h]”hŒraw API”…”�”}”(hj‹ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j hj ubhŒ -- the exact ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``landlock_restrict_self()``”h]”hŒlandlock_restrict_self()”…”�”}”(hj� h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒA flags, arguments, and return value. Correlate them by thread; a ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ ``LANDLOCK_RESTRICT_SELF_TSYNC``”h]”hŒLANDLOCK_RESTRICT_SELF_TSYNC”…”�”}”(hj¯ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒB operation also enforces the domain on the sibling threads, whose ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``landlock_enforce_domain``”h]”hŒlandlock_enforce_domain”…”�”}”(hjÁ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒx events fire in each sibling’s own context rather than the caller’s, so correlate those to the syscall by domain ID.”…”�”}”(hj h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K±hjÒ h²hubeh}”(h]”Œdomain-enforcement”ah ]”h"]”Œdomain enforcement”ah$]”h&]”uh1hÖhhØh²hh³hÇh´K©ubh×)�”}”(hhh]”(hÜ)�”}”(hŒInterpreting check_rule events”h]”hŒInterpreting check_rule events”…”�”}”(hjä h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjá h²hh³hÇh´K¾ubj )�”}”(hŒ±The ``check_rule_inode`` and ``check_rule_net_port`` events expose the per-layer rule evaluation, which is useful for understanding *why* a specific access is allowed or denied.”h]”(hŒThe ”…”�”}”(hjò h²hh³Nh´Nubj)�”}”(hŒ``check_rule_inode``”h]”hŒcheck_rule_inode”…”�”}”(hjú h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjò ubhŒ and ”…”�”}”(hjò h²hh³Nh´Nubj)�”}”(hŒ``check_rule_net_port``”h]”hŒcheck_rule_net_port”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjò ubhŒP events expose the per-layer rule evaluation, which is useful for understanding ”…”�”}”(hjò h²hh³Nh´Nubj )�”}”(hŒ*why*”h]”hŒwhy”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j hjò ubhŒ( a specific access is allowed or denied.”…”�”}”(hjò h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KÀhjá h²hubjx)�”}”(hX@These events fire on the access-check hot path, once per matching rule per check. On a busy sandboxed workload this can be very high frequency. Enable them only for targeted debugging, ideally combined with an ftrace filter (for example on ``ino`` or ``domain_id``), and expect tracing overhead while they are enabled.”h]”j )�”}”(hX@These events fire on the access-check hot path, once per matching rule per check. On a busy sandboxed workload this can be very high frequency. Enable them only for targeted debugging, ideally combined with an ftrace filter (for example on ``ino`` or ``domain_id``), and expect tracing overhead while they are enabled.”h]”(hŒòThese events fire on the access-check hot path, once per matching rule per check. On a busy sandboxed workload this can be very high frequency. Enable them only for targeted debugging, ideally combined with an ftrace filter (for example on ”…”�”}”(hj: h²hh³Nh´Nubj)�”}”(hŒ``ino``”h]”hŒino”…”�”}”(hjB h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj: ubhŒ or ”…”�”}”(hj: h²hh³Nh´Nubj)�”}”(hŒ ``domain_id``”h]”hŒ domain_id”…”�”}”(hjT h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj: ubhŒ6), and expect tracing overhead while they are enabled.”…”�”}”(hj: h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KÆhj6 ubah}”(h]”h ]”h"]”h$]”h&]”uh1jwhjá h²hh³hÇh´Nubj )�”}”(hŒ'Two output fields carry the evaluation:”h]”hŒ'Two output fields carry the evaluation:”…”�”}”(hjr h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KÌhjá h²hubjø)�”}”(hhh]”(jý)�”}”(hXH``access_request=`` is the set of access rights being evaluated against the rule, rendered as ``|``-separated names. For most checks this is the access the operation requested. For filesystem ``rename`` and ``link`` double-checks it is the domain's full handled mask, because those operations re-evaluate every handled right. ”h]”j )�”}”(hXG``access_request=`` is the set of access rights being evaluated against the rule, rendered as ``|``-separated names. For most checks this is the access the operation requested. For filesystem ``rename`` and ``link`` double-checks it is the domain's full handled mask, because those operations re-evaluate every handled right.”h]”(j)�”}”(hŒ``access_request=``”h]”hŒaccess_request=”…”�”}”(hj‹ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj‡ ubhŒK is the set of access rights being evaluated against the rule, rendered as ”…”�”}”(hj‡ h²hh³Nh´Nubj)�”}”(hŒ``|``”h]”hŒ|”…”�”}”(hj� h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj‡ ubhŒ_-separated names. For most checks this is the access the operation requested. For filesystem ”…”�”}”(hj‡ h²hh³Nh´Nubj)�”}”(hŒ ``rename``”h]”hŒrename”…”�”}”(hj¯ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj‡ ubhŒ and ”…”�”}”(hj‡ h²hh³Nh´Nubj)�”}”(hŒ``link``”h]”hŒlink”…”�”}”(hjÁ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj‡ ubhŒp double-checks it is the domain’s full handled mask, because those operations re-evaluate every handled right.”…”�”}”(hj‡ h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KÎhjƒ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühj€ h²hh³hÇh´Nubjý)�”}”(hXô``grants=`` is a per-layer breakdown of the requested rights that this rule grants, in the form ``{,,...}``: - The braces wrap one comma-separated group per domain layer, ordered from the outermost (least nested) sandbox layer to the innermost. - Each group lists the requested rights the rule grants at that layer, joined by ``|``. - An empty group (for example the middle layer in ``{read_file,,read_file}``) means the rule grants none of the requested rights at that layer. ”h]”(j )�”}”(hŒz``grants=`` is a per-layer breakdown of the requested rights that this rule grants, in the form ``{,,...}``:”h]”(j)�”}”(hŒ ``grants=``”h]”hŒgrants=”…”�”}”(hjç h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjã ubhŒU is a per-layer breakdown of the requested rights that this rule grants, in the form ”…”�”}”(hjã h²hh³Nh´Nubj)�”}”(hŒ``{,,...}``”h]”hŒ{,,...}”…”�”}”(hjù h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjã ubhŒ:”…”�”}”(hjã h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KÔhjß ubjø)�”}”(hhh]”(jý)�”}”(hŒ…The braces wrap one comma-separated group per domain layer, ordered from the outermost (least nested) sandbox layer to the innermost.”h]”j )�”}”(hŒ…The braces wrap one comma-separated group per domain layer, ordered from the outermost (least nested) sandbox layer to the innermost.”h]”hŒ…The braces wrap one comma-separated group per domain layer, ordered from the outermost (least nested) sandbox layer to the innermost.”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´K×hj ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühj ubjý)�”}”(hŒUEach group lists the requested rights the rule grants at that layer, joined by ``|``.”h]”j )�”}”(hŒUEach group lists the requested rights the rule grants at that layer, joined by ``|``.”h]”(hŒOEach group lists the requested rights the rule grants at that layer, joined by ”…”�”}”(hj0 h²hh³Nh´Nubj)�”}”(hŒ``|``”h]”hŒ|”…”�”}”(hj8 h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj0 ubhŒ.”…”�”}”(hj0 h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KÙhj, ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühj ubjý)�”}”(hŒŽAn empty group (for example the middle layer in ``{read_file,,read_file}``) means the rule grants none of the requested rights at that layer. ”h]”j )�”}”(hŒ�An empty group (for example the middle layer in ``{read_file,,read_file}``) means the rule grants none of the requested rights at that layer.”h]”(hŒ0An empty group (for example the middle layer in ”…”�”}”(hjZ h²hh³Nh´Nubj)�”}”(hŒ``{read_file,,read_file}``”h]”hŒ{read_file,,read_file}”…”�”}”(hjb h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjZ ubhŒC) means the rule grants none of the requested rights at that layer.”…”�”}”(hjZ h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KÛhjV ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühj ubeh}”(h]”h ]”h"]”h$]”h&]”jÀjÁuh1j÷h³hÇh´K×hjß ubeh}”(h]”h ]”h"]”h$]”h&]”uh1jühj€ h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”jÀjÁuh1j÷h³hÇh´KÎhjá h²hubj )�”}”(hŒøA Landlock domain allows an access only when, for every requested right, every layer that handles that right has at least one matching rule granting it. A single ``check_rule`` event therefore shows one rule's contribution, not the final decision:”h]”(hŒ£A Landlock domain allows an access only when, for every requested right, every layer that handles that right has at least one matching rule granting it. A single ”…”�”}”(hj’ h²hh³Nh´Nubj)�”}”(hŒ``check_rule``”h]”hŒ check_rule”…”�”}”(hjš h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj’ ubhŒI event therefore shows one rule’s contribution, not the final decision:”…”�”}”(hj’ h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Kßhjá h²hubjø)�”}”(hhh]”(jý)�”}”(hŒ]If a right appears in every layer's group, this rule alone is sufficient to allow that right.”h]”j )�”}”(hŒ]If a right appears in every layer's group, this rule alone is sufficient to allow that right.”h]”hŒ_If a right appears in every layer’s group, this rule alone is sufficient to allow that right.”…”�”}”(hj¹ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Kähjµ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühj² h²hh³hÇh´Nubjý)�”}”(hŒÑIf a right is missing from some layer's group, that layer must grant it through another matching rule, or the right is denied and appears in the ``blockers=`` field of the corresponding ``deny_access`` event. ”h]”j )�”}”(hŒÐIf a right is missing from some layer's group, that layer must grant it through another matching rule, or the right is denied and appears in the ``blockers=`` field of the corresponding ``deny_access`` event.”h]”(hŒ“If a right is missing from some layer’s group, that layer must grant it through another matching rule, or the right is denied and appears in the ”…”�”}”(hjÑ h²hh³Nh´Nubj)�”}”(hŒ ``blockers=``”h]”hŒ blockers=”…”�”}”(hjÙ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÑ ubhŒ field of the corresponding ”…”�”}”(hjÑ h²hh³Nh´Nubj)�”}”(hŒ``deny_access``”h]”hŒ deny_access”…”�”}”(hjë h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÑ ubhŒ event.”…”�”}”(hjÑ h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KæhjÍ ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühj² h²hh³hÇh´Nubeh}”(h]”h ]”h"]”h$]”h&]”jÀjÁuh1j÷h³hÇh´Kähjá h²hubj )�”}”(hXFor an access check that a consumer can delimit, aggregate the ``grants=`` groups of all matching ``check_rule`` events. These events do not carry a request ID; use their execution context and generic tracepoints to separate concurrent or successive checks of the same object.”h]”(hŒ?For an access check that a consumer can delimit, aggregate the ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ ``grants=``”h]”hŒgrants=”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ groups of all matching ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``check_rule``”h]”hŒ check_rule”…”�”}”(hj) h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ¥ events. These events do not carry a request ID; use their execution context and generic tracepoints to separate concurrent or successive checks of the same object.”…”�”}”(hj h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Kêhjá h²hubhŒnote”“”)�”}”(hŒÔBecause a verdict requires aggregating ``grants=`` across all matching rules of one access check, a stateless ftrace filter on a single ``check_rule`` event cannot distinguish an allowed access from a denied one.”h]”j )�”}”(hŒÔBecause a verdict requires aggregating ``grants=`` across all matching rules of one access check, a stateless ftrace filter on a single ``check_rule`` event cannot distinguish an allowed access from a denied one.”h]”(hŒ'Because a verdict requires aggregating ”…”�”}”(hjG h²hh³Nh´Nubj)�”}”(hŒ ``grants=``”h]”hŒgrants=”…”�”}”(hjO h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjG ubhŒV across all matching rules of one access check, a stateless ftrace filter on a single ”…”�”}”(hjG h²hh³Nh´Nubj)�”}”(hŒ``check_rule``”h]”hŒ check_rule”…”�”}”(hja h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjG ubhŒ> event cannot distinguish an allowed access from a denied one.”…”�”}”(hjG h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´KñhjC ubah}”(h]”h ]”h"]”h$]”h&]”uh1jA hjá h²hh³hÇh´Nubj )�”}”(hXõFor example, a program sandboxed with read and execute access to the whole filesystem reads ``/etc/passwd``; both the ``execve()`` and the read match the rule covering ``/`` (inode 2), so ``check_rule_inode`` fires with the requested rights intersected against what that rule grants. The ``access_request=`` mask includes ``truncate`` because the file-open hook evaluates that optional right alongside the required access, but the rule does not grant it, so ``truncate`` never appears in ``grants=``::”h]”(hŒ\For example, a program sandboxed with read and execute access to the whole filesystem reads ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``/etc/passwd``”h]”hŒ /etc/passwd”…”�”}”(hj‡ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ ; both the ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ ``execve()``”h]”hŒexecve()”…”�”}”(hj™ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ& and the read match the rule covering ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``/``”h]”hŒ/”…”�”}”(hj« h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ (inode 2), so ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``check_rule_inode``”h]”hŒcheck_rule_inode”…”�”}”(hj½ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒP fires with the requested rights intersected against what that rule grants. The ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ``access_request=``”h]”hŒaccess_request=”…”�”}”(hjÏ h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ mask includes ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ ``truncate``”h]”hŒtruncate”…”�”}”(hjá h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ| because the file-open hook evaluates that optional right alongside the required access, but the rule does not grant it, so ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ ``truncate``”h]”hŒtruncate”…”�”}”(hjó h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ never appears in ”…”�”}”(hj h²hh³Nh´Nubj)�”}”(hŒ ``grants=``”h]”hŒgrants=”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubhŒ:”…”�”}”(hj h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Köhjá h²hubj©)�”}”(hX cat-127 [...] landlock_check_rule_inode: domain=1e40cb56f access_request=execute|read_file|truncate dev=0:17 ino=2 grants={execute|read_file} cat-127 [...] landlock_check_rule_inode: domain=1e40cb56f access_request=read_file|truncate dev=0:17 ino=2 grants={read_file}”h]”hX cat-127 [...] landlock_check_rule_inode: domain=1e40cb56f access_request=execute|read_file|truncate dev=0:17 ino=2 grants={execute|read_file} cat-127 [...] landlock_check_rule_inode: domain=1e40cb56f access_request=read_file|truncate dev=0:17 ino=2 grants={read_file}”…”�”}”hjsbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j¨h³hÇh´Kþhjá h²hubj )�”}”(hX The ``[...]`` replaces the ftrace CPU, flags, and timestamp columns. A single ``grants=`` group means the enforcing domain has one layer. With two nested sandboxes that each grant the same rights, the rule spans both layers, so ``grants=`` has one group per layer::”h]”(hŒThe ”…”�”}”(hj+h²hh³Nh´Nubj)�”}”(hŒ ``[...]``”h]”hŒ[...]”…”�”}”(hj3h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj+ubhŒB replaces the ftrace CPU, flags, and timestamp columns. A single ”…”�”}”(hj+h²hh³Nh´Nubj)�”}”(hŒ ``grants=``”h]”hŒgrants=”…”�”}”(hjEh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj+ubhŒŒ group means the enforcing domain has one layer. With two nested sandboxes that each grant the same rights, the rule spans both layers, so ”…”�”}”(hj+h²hh³Nh´Nubj)�”}”(hŒ ``grants=``”h]”hŒgrants=”…”�”}”(hjWh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj+ubhŒ has one group per layer:”…”�”}”(hj+h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Mhjá h²hubj©)�”}”(hX'cat-128 [...] landlock_check_rule_inode: domain=184788b52 access_request=execute|read_file|truncate dev=0:17 ino=2 grants={execute|read_file,execute|read_file} cat-128 [...] landlock_check_rule_inode: domain=184788b52 access_request=read_file|truncate dev=0:17 ino=2 grants={read_file,read_file}”h]”hX'cat-128 [...] landlock_check_rule_inode: domain=184788b52 access_request=execute|read_file|truncate dev=0:17 ino=2 grants={execute|read_file,execute|read_file} cat-128 [...] landlock_check_rule_inode: domain=184788b52 access_request=read_file|truncate dev=0:17 ino=2 grants={read_file,read_file}”…”�”}”hjosbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j¨h³hÇh´Mhjá h²hubeh}”(h]”Œinterpreting-check-rule-events”ah ]”h"]”Œinterpreting check_rule events”ah$]”h&]”uh1hÖhhØh²hh³hÇh´K¾ubh×)�”}”(hhh]”(hÜ)�”}”(hŒ eBPF access”h]”hŒ eBPF access”…”�”}”(hjˆh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhj…h²hh³hÇh´M ubj )�”}”(hXBTF-enabled raw tracepoint programs attached through libbpf ``SEC("tp_btf/...")`` sections receive typed callback arguments. The event prototypes in `Event reference`_ document their argument layouts. The arguments include both standard kernel objects and Landlock-internal objects:”h]”(hŒh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj6ubhŒ, ”…”�”}”(hj6h²hh³Nh´Nubj)�”}”(hŒ``struct landlock_ruleset``”h]”hŒstruct landlock_ruleset”…”�”}”(hjPh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj6ubhŒ, ”…”�”}”(hj6h²hh³Nh´Nubj)�”}”(hŒ``struct landlock_rule``”h]”hŒstruct landlock_rule”…”�”}”(hjbh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj6ubhŒ, ”…”�”}”hj6sbj)�”}”(hŒ``struct landlock_hierarchy``”h]”hŒstruct landlock_hierarchy”…”�”}”(hjth²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj6ubhŒ) can be read via ”…”�”}”(hj6h²hh³Nh´Nubj)�”}”(hŒ``BPF_CORE_READ``”h]”hŒ BPF_CORE_READ”…”�”}”(hj†h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj6ubhŒ]. Internal struct layouts may change between kernel versions; use CO-RE for field relocation.”…”�”}”(hj6h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Mhj2ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjÏh²hh³hÇh´Nubeh}”(h]”h ]”h"]”h$]”h&]”jÀjÁuh1j÷h³hÇh´Mhj…h²hubj )�”}”(hŒgA stateful eBPF program attached before sandbox construction can maintain per-domain state in BPF maps:”h]”hŒgA stateful eBPF program attached before sandbox construction can maintain per-domain state in BPF maps:”…”�”}”(hjªh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Mhj…h²hubhŒenumerated_list”“”)�”}”(hhh]”(jý)�”}”(hŒ¸On ``landlock_create_domain``: record the domain ID and parent (the per-domain Landlock log flags are not event fields; read them from ``struct landlock_hierarchy`` via BTF if needed).”h]”j )�”}”(hŒ¸On ``landlock_create_domain``: record the domain ID and parent (the per-domain Landlock log flags are not event fields; read them from ``struct landlock_hierarchy`` via BTF if needed).”h]”(hŒOn ”…”�”}”(hjÁh²hh³Nh´Nubj)�”}”(hŒ``landlock_create_domain``”h]”hŒlandlock_create_domain”…”�”}”(hjÉh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÁubhŒj: record the domain ID and parent (the per-domain Landlock log flags are not event fields; read them from ”…”�”}”(hjÁh²hh³Nh´Nubj)�”}”(hŒ``struct landlock_hierarchy``”h]”hŒstruct landlock_hierarchy”…”�”}”(hjÛh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÁubhŒ via BTF if needed).”…”�”}”(hjÁh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´Mhj½ubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjºh²hh³hÇh´Nubjý)�”}”(hŒëOn ``landlock_enforce_domain``: record the sandboxed thread under the ``domain=`` key (join to the ``create_domain`` recorded in step 1), building the per-domain thread set; filter ``complete==1`` for a one-event-per-operation summary.”h]”j )�”}”(hŒëOn ``landlock_enforce_domain``: record the sandboxed thread under the ``domain=`` key (join to the ``create_domain`` recorded in step 1), building the per-domain thread set; filter ``complete==1`` for a one-event-per-operation summary.”h]”(hŒOn ”…”�”}”(hjýh²hh³Nh´Nubj)�”}”(hŒ``landlock_enforce_domain``”h]”hŒlandlock_enforce_domain”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjýubhŒ(: record the sandboxed thread under the ”…”�”}”(hjýh²hh³Nh´Nubj)�”}”(hŒ ``domain=``”h]”hŒdomain=”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjýubhŒ key (join to the ”…”�”}”(hjýh²hh³Nh´Nubj)�”}”(hŒ``create_domain``”h]”hŒ create_domain”…”�”}”(hj)h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjýubhŒA recorded in step 1), building the per-domain thread set; filter ”…”�”}”(hjýh²hh³Nh´Nubj)�”}”(hŒ``complete==1``”h]”hŒ complete==1”…”�”}”(hj;h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjýubhŒ' for a one-event-per-operation summary.”…”�”}”(hjýh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´M!hjùubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjºh²hh³hÇh´Nubjý)�”}”(hŒOn ``landlock_deny_access_*``: look up the domain, decide whether to count, alert, or ignore the denial based on custom policy.”h]”j )�”}”(hŒOn ``landlock_deny_access_*``: look up the domain, decide whether to count, alert, or ignore the denial based on custom policy.”h]”(hŒOn ”…”�”}”(hj]h²hh³Nh´Nubj)�”}”(hŒ``landlock_deny_access_*``”h]”hŒlandlock_deny_access_*”…”�”}”(hjeh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj]ubhŒb: look up the domain, decide whether to count, alert, or ignore the denial based on custom policy.”…”�”}”(hj]h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´M%hjYuba•h}”(h]”h ]”h"]”h$]”h&]”uh1jühjºh²hh³hÇh´Nubjý)�”}”(hŒROn ``landlock_free_domain``: clean up the per-domain state, log final statistics. ”h]”j )�”}”(hŒQOn ``landlock_free_domain``: clean up the per-domain state, log final statistics.”h]”(hŒOn ”…”�”}”(hj‡h²hh³Nh´Nubj)�”}”(hŒ``landlock_free_domain``”h]”hŒlandlock_free_domain”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj‡ubhŒ6: clean up the per-domain state, log final statistics.”…”�”}”(hj‡h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´M'hjƒubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjºh²hh³hÇh´Nubeh}”(h]”h ]”h"]”h$]”h&]”Œenumtype”Œarabic”Œprefix”hŒsuffix”Œ.”uh1j¸hj…h²hh³hÇh´Mubj )�”}”(hX<This approach requires no kernel modification and no Landlock-specific BPF helpers. Landlock IDs serve as correlation keys within one boot. Records exported through tracing or BPF buffers can be lost, and records from different CPUs are not globally ordered, so consumers must detect and reconcile incomplete state.”h]”hX<This approach requires no kernel modification and no Landlock-specific BPF helpers. Landlock IDs serve as correlation keys within one boot. Records exported through tracing or BPF buffers can be lost, and records from different CPUs are not globally ordered, so consumers must detect and reconcile incomplete state.”…”�”}”(hj¸h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´M*hj…h²hubeh}”(h]”Œ ebpf-access”ah ]”h"]”Œ ebpf access”ah$]”h&]”uh1hÖhhØh²hh³hÇh´M ubh×)�”}”(hhh]”(hÜ)�”}”(hŒAudit filtering equivalence”h]”hŒAudit filtering equivalence”…”�”}”(hjÑh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjÎh²hh³hÇh´M1ubj )�”}”(hX_The ``logged`` field reflects the domain's log policy but not the global ``audit_enabled`` toggle, so it does not change when audit is turned on or off. When audit is enabled, ``logged==1`` selects the denials the domain submits to audit (audit-side rate-limiting and exclude rules may still drop some), so a stateless ftrace filter can select them::”h]”(hŒThe ”…”�”}”(hjßh²hh³Nh´Nubj)�”}”(hŒ ``logged``”h]”hŒlogged”…”�”}”(hjçh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjßubhŒ= field reflects the domain’s log policy but not the global ”…”�”}”(hjßh²hh³Nh´Nubj)�”}”(hŒ``audit_enabled``”h]”hŒ audit_enabled”…”�”}”(hjùh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjßubhŒW toggle, so it does not change when audit is turned on or off. When audit is enabled, ”…”�”}”(hjßh²hh³Nh´Nubj)�”}”(hŒ ``logged==1``”h]”hŒ logged==1”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjßubhŒ  selects the denials the domain submits to audit (audit-side rate-limiting and exclude rules may still drop some), so a stateless ftrace filter can select them:”…”�”}”(hjßh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´M3hjÎh²hubj©)�”}”(hŒŠ# Show only denials that audit would also log: echo 'logged==1' > \ /sys/kernel/tracing/events/landlock/landlock_deny_access_fs/filter”h]”hŒŠ# Show only denials that audit would also log: echo 'logged==1' > \ /sys/kernel/tracing/events/landlock/landlock_deny_access_fs/filter”…”�”}”hj#sbah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j¨h³hÇh´M9hjÎh²hubeh}”(h]”Œaudit-filtering-equivalence”ah ]”h"]”Œaudit filtering equivalence”ah$]”h&]”uh1hÖhhØh²hh³hÇh´M1ubh×)�”}”(hhh]”(hÜ)�”}”(hŒEvent reference”h]”hŒEvent reference”…”�”}”(hj<h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhj9h²hh³hÇh´M>ubj )�”}”(hŒŽThese guarantees and constraints hold for every Landlock tracepoint. A new tracepoint must uphold them, and an eBPF consumer can rely on them.”h]”hŒŽThese guarantees and constraints hold for every Landlock tracepoint. A new tracepoint must uphold them, and an eBPF consumer can rely on them.”…”�”}”(hjJh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:320: ./include/trace/events/landlock.h”h´KÈhj9h²hubh×)�”}”(hhh]”(hÜ)�”}”(hŒDecision context”h]”hŒDecision context”…”�”}”(hj\h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjYh³Nh´Nubj )�”}”(hXçA denial event identifies the domain whose policy denied the request, the Landlock operation and policy object that were checked, and the blocker or domain relationship responsible for the denial. When tracing starts with sandbox construction, ruleset and domain events provide the policy history needed to interpret these identifiers. The denying domain is the subject that enforced the policy, not necessarily current. Generic tracepoints can provide additional operational context.”h]”hXçA denial event identifies the domain whose policy denied the request, the Landlock operation and policy object that were checked, and the blocker or domain relationship responsible for the denial. When tracing starts with sandbox construction, ruleset and domain events provide the policy history needed to interpret these identifiers. The denying domain is the subject that enforced the policy, not necessarily current. Generic tracepoints can provide additional operational context.”…”�”}”(hjjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:320: ./include/trace/events/landlock.h”h´KÏhjYubeh}”(h]”Œdecision-context”ah ]”h"]”Œdecision context”ah$]”h&]”uh1hÖhj9h²hh³Nh´Nubh×)�”}”(hhh]”(hÜ)�”}”(hŒLifecycle consistency”h]”hŒLifecycle consistency”…”�”}”(hj„h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhj�h³Nh´Nubj )�”}”(hXáLifecycle emission is balanced: a creation event always has a matching deallocation event and vice versa. A consumer that observes an object's complete lifetime can model it from this pair; one that attaches late or loses exported records must reconcile incomplete state. A creation event fires while the object is still private to the calling thread (landlock_create_ruleset fires before the ruleset's file descriptor is installed, so it cannot race a concurrent :manpage:`close(2)`); if fd installation later fails and the ruleset is freed, free_ruleset still fires, keeping the pair balanced. The domain pair (create_domain and free_domain) is balanced the same way: create_domain fires when the domain is created (under the ruleset lock, before thread-sync), and free_domain fires when it is freed. A rare thread-sync failure aborts the just-created domain, which then emits both events (its creation, then an immediate free). Denial events fire only for denials that actually happen.”h]”(hXÖLifecycle emission is balanced: a creation event always has a matching deallocation event and vice versa. A consumer that observes an object’s complete lifetime can model it from this pair; one that attaches late or loses exported records must reconcile incomplete state. A creation event fires while the object is still private to the calling thread (landlock_create_ruleset fires before the ruleset’s file descriptor is installed, so it cannot race a concurrent ”…”�”}”(hj’h²hh³Nh´NubhŒmanpage”“”)�”}”(hŒ:manpage:`close(2)`”h]”hŒclose(2)”…”�”}”(hjœh²hh³Nh´Nubah}”(h]”h ]”jšah"]”h$]”h&]”hÅhÆŒpath”Œclose(2)”Œpage”Œclose”Œsection”Œ2”uh1jšhj’ubhXü); if fd installation later fails and the ruleset is freed, free_ruleset still fires, keeping the pair balanced. The domain pair (create_domain and free_domain) is balanced the same way: create_domain fires when the domain is created (under the ruleset lock, before thread-sync), and free_domain fires when it is freed. A rare thread-sync failure aborts the just-created domain, which then emits both events (its creation, then an immediate free). Denial events fire only for denials that actually happen.”…”�”}”(hj’h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:320: ./include/trace/events/landlock.h”h´KÚhj�ubeh}”(h]”Œlifecycle-consistency”ah ]”h"]”Œlifecycle consistency”ah$]”h&]”uh1hÖhj9h²hh³Nh´Nubh×)�”}”(hhh]”(hÜ)�”}”(hŒPointer access”h]”hŒPointer access”…”�”}”(hjÆh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjÃh³Nh´Nubj )�”}”(hXFAll pointer arguments in TP_PROTO are guaranteed non-NULL by the caller, but pointers reached through them may still be NULL (e.g., hierarchy->parent at a root domain) and must be checked. eBPF programs read these pointers via BTF for richer introspection than the TP_STRUCT__entry fields, which serve TP_printk display only.”h]”hXFAll pointer arguments in TP_PROTO are guaranteed non-NULL by the caller, but pointers reached through them may still be NULL (e.g., hierarchy->parent at a root domain) and must be checked. eBPF programs read these pointers via BTF for richer introspection than the TP_STRUCT__entry fields, which serve TP_printk display only.”…”�”}”(hjÔh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:320: ./include/trace/events/landlock.h”h´KíhjÃubj )�”}”(hXéMutable object pointers are passed while the caller holds the object's lock, so TP_fast_assign and a BTF reader see the exact object the event reports, a snapshot no concurrent writer can change: add_rule holds the modified ruleset's lock, and create_domain holds the ruleset lock across the emission (before the thread-sync wait) so the inspected ruleset is the one merged into the domain. Objects immutable at the emission site (a domain after creation, a hierarchy at its last reference) need no lock. A few values that no held lock protects are a best-effort lockless snapshot instead: a task's comm, and the deny_access_net struct sock (whose network hook holds no socket lock), matching how the sched and signal trace events sample comm.”h]”hXïMutable object pointers are passed while the caller holds the object’s lock, so TP_fast_assign and a BTF reader see the exact object the event reports, a snapshot no concurrent writer can change: add_rule holds the modified ruleset’s lock, and create_domain holds the ruleset lock across the emission (before the thread-sync wait) so the inspected ruleset is the one merged into the domain. Objects immutable at the emission site (a domain after creation, a hierarchy at its last reference) need no lock. A few values that no held lock protects are a best-effort lockless snapshot instead: a task’s comm, and the deny_access_net struct sock (whose network hook holds no socket lock), matching how the sched and signal trace events sample comm.”…”�”}”(hjãh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:320: ./include/trace/events/landlock.h”h´KóhjÃubeh}”(h]”Œpointer-access”ah ]”h"]”Œpointer access”ah$]”h&]”uh1hÖhj9h²hh³Nh´Nubh×)�”}”(hhh]”(hÜ)�”}”(hŒField encoding”h]”hŒField encoding”…”�”}”(hjýh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjúh³Nh´Nubj )�”}”(hŒõFields that mirror the Landlock UAPI preserve their widths and endianness (e.g. network ports are u64 in host endianness, like landlock_net_port_attr.port). Per-event details, such as where a value is byte-swapped, live in the field's own kdoc.”h]”hŒ÷Fields that mirror the Landlock UAPI preserve their widths and endianness (e.g. network ports are u64 in host endianness, like landlock_net_port_attr.port). Per-event details, such as where a value is byte-swapped, live in the field’s own kdoc.”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:320: ./include/trace/events/landlock.h”h´Mhjúubeh}”(h]”Œfield-encoding”ah ]”h"]”Œfield encoding”ah$]”h&]”uh1hÖhj9h²hh³Nh´Nubh×)�”}”(hhh]”(hÜ)�”}”(hŒRule-check fields”h]”hŒRule-check fields”…”�”}”(hj%h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhj"h³Nh´Nubj )�”}”(hXThe check_rule events fire during an access check, once per matching rule, before the final allow-or-deny verdict. They share domain (the enforcing domain being evaluated), access_request (the access mask being checked), and rule (the matching rule, with per-layer access masks).”h]”hXThe check_rule events fire during an access check, once per matching rule, before the final allow-or-deny verdict. They share domain (the enforcing domain being evaluated), access_request (the access mask being checked), and rule (the matching rule, with per-layer access masks).”…”�”}”(hj3h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:320: ./include/trace/events/landlock.h”h´M hj"ubeh}”(h]”Œrule-check-fields”ah ]”h"]”Œrule-check fields”ah$]”h&]”uh1hÖhj9h²hh³Nh´Nubh×)�”}”(hhh]”(hÜ)�”}”(hŒ Denial fields”h]”hŒ Denial fields”…”�”}”(hjMh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjJh³Nh´Nubj )�”}”(hX¡Every denial event shares three fields. domain is the ID of the innermost domain that blocked the access. same_exec tells whether the current task is the same executable that entered that domain. logged is the domain's audit-logging decision for this denial (its log_status is enabled and the per-execution flag selected by same_exec is set); a stateless ftrace filter can select the denials the domain submits to audit with logged==1, without reconstructing it from the per-execution log flags. Denial events order their fields as domain, same_exec, logged, then blockers (deny_access events only), then the type-specific object fields, then any variable-length field.”h]”hX£Every denial event shares three fields. domain is the ID of the innermost domain that blocked the access. same_exec tells whether the current task is the same executable that entered that domain. logged is the domain’s audit-logging decision for this denial (its log_status is enabled and the per-execution flag selected by same_exec is set); a stateless ftrace filter can select the denials the domain submits to audit with logged==1, without reconstructing it from the per-execution log flags. Denial events order their fields as domain, same_exec, logged, then blockers (deny_access events only), then the type-specific object fields, then any variable-length field.”…”�”}”(hj[h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:320: ./include/trace/events/landlock.h”h´MhjJubeh}”(h]”Œ denial-fields”ah ]”h"]”Œ denial fields”ah$]”h&]”uh1hÖhj9h²hh³Nh´Nubh×)�”}”(hhh]”(hÜ)�”}”(hŒRelational referents”h]”hŒRelational referents”…”�”}”(hjuh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjrh³Nh´Nubj )�”}”(hXÂA scope or ptrace verdict compares two domains, so the other party's domain is part of the decision context. It is exposed as a scalar domain ID (0 when that party is unsandboxed): target_domain (signal), peer_domain (abstract unix socket), tracee_domain (ptrace). With both IDs in the stream, a consumer that tracked domain creation can relate the two parties without kernel-internal state. The ID is a scalar snapshot, not a live domain pointer that could dangle: an optional relational referent is a scalar (0 sentinel), not a nullable pointer. Nonzero IDs are unique within one boot. For ptrace, same_exec instead describes the tracer, even for PTRACE_TRACEME, and may differ from the current task.”h]”hXÄA scope or ptrace verdict compares two domains, so the other party’s domain is part of the decision context. It is exposed as a scalar domain ID (0 when that party is unsandboxed): target_domain (signal), peer_domain (abstract unix socket), tracee_domain (ptrace). With both IDs in the stream, a consumer that tracked domain creation can relate the two parties without kernel-internal state. The ID is a scalar snapshot, not a live domain pointer that could dangle: an optional relational referent is a scalar (0 sentinel), not a nullable pointer. Nonzero IDs are unique within one boot. For ptrace, same_exec instead describes the tracer, even for PTRACE_TRACEME, and may differ from the current task.”…”�”}”(hjƒh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:320: ./include/trace/events/landlock.h”h´M hjrubeh}”(h]”Œrelational-referents”ah ]”h"]”Œrelational referents”ah$]”h&]”uh1hÖhj9h²hh³Nh´Nubh×)�”}”(hhh]”(hÜ)�”}”(hŒBlocker fields”h]”hŒBlocker fields”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjšh³Nh´Nubj )�”}”(hŒ¹The filesystem and network blocker arguments identify the request type and carry its final missing access subset when applicable. The type determines how to interpret the access value.”h]”hŒ¹The filesystem and network blocker arguments identify the request type and carry its final missing access subset when applicable. The type determines how to interpret the access value.”…”�”}”(hj«h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:320: ./include/trace/events/landlock.h”h´M/hjšubeh}”(h]”Œblocker-fields”ah ]”h"]”Œblocker fields”ah$]”h&]”uh1hÖhj9h²hh³Nh´NubhŒindex”“”)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(Œsingle”Œ*trace_landlock_create_ruleset (C function)”Œc.trace_landlock_create_ruleset”hNt”auh1jÂhj9h²hh³Nh´NubhŒdesc”“”)�”}”(hhh]”(hŒdesc_signature”“”)�”}”(hŒKvoid trace_landlock_create_ruleset (const struct landlock_ruleset *ruleset)”h]”hŒdesc_signature_line”“”)�”}”(hŒJvoid trace_landlock_create_ruleset(const struct landlock_ruleset *ruleset)”h]”(hŒdesc_sig_keyword_type”“”)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hjæh²hh³Nh´Nubah}”(h]”h ]”Œkt”ah"]”h$]”h&]”uh1jähjàh²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MIubhŒdesc_sig_space”“”)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjøh²hh³Nh´Nubah}”(h]”h ]”Œw”ah"]”h$]”h&]”uh1jöhjàh²hh³jõh´MIubhŒ desc_name”“”)�”}”(hŒtrace_landlock_create_ruleset”h]”hŒ desc_sig_name”“”)�”}”(hŒtrace_landlock_create_ruleset”h]”hŒtrace_landlock_create_ruleset”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”Œn”ah"]”h$]”h&]”uh1j hj ubah}”(h]”h ]”(Œsig-name”Œdescname”eh"]”h$]”h&]”hÅhÆuh1jhjàh²hh³jõh´MIubhŒdesc_parameterlist”“”)�”}”(hŒ((const struct landlock_ruleset *ruleset)”h]”hŒdesc_parameter”“”)�”}”(hŒ&const struct landlock_ruleset *ruleset”h]”(hŒdesc_sig_keyword”“”)�”}”(hŒconst”h]”hŒconst”…”�”}”(hj4h²hh³Nh´Nubah}”(h]”h ]”Œk”ah"]”h$]”h&]”uh1j2hj.ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjCh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj.ubj3)�”}”(hŒstruct”h]”hŒstruct”…”�”}”(hjQh²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj.ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj_h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj.ubh)�”}”(hhh]”j)�”}”(hŒlandlock_ruleset”h]”hŒlandlock_ruleset”…”�”}”(hjph²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjmubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”Œc”Œreftype”Œ identifier”Œ reftarget”jrŒmodname”NŒ classname”NŒ c:parent_key”Œsphinx.domains.c”Œ LookupKey”“”)�”}”Œdata”]”jŒŒ ASTIdentifier”“”)�”}”j‡jsbŒc.trace_landlock_create_ruleset”†”asbuh1hhj.ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj™h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj.ubhŒdesc_sig_punctuation”“”)�”}”(hŒ*”h]”hŒ*”…”�”}”(hj©h²hh³Nh´Nubah}”(h]”h ]”Œp”ah"]”h$]”h&]”uh1j§hj.ubj)�”}”(hŒruleset”h]”hŒruleset”…”�”}”(hj¸h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj.ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj(ubah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hjàh²hh³jõh´MIubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆŒ add_permalink”ˆuh1jÞŒsphinx_line_type”Œ declarator”hjÚh²hh³jõh´MIubah}”(h]”jÑah ]”(Œsig”Œ sig-object”eh"]”h$]”h&]”Œ is_multiline”ˆŒ _toc_parts”)Œ _toc_name”huh1jØh³jõh´MIhjÕh²hubhŒ desc_content”“”)�”}”(hhh]”j )�”}”(hŒNew ruleset created”h]”hŒNew ruleset created”…”�”}”(hjìh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MIhjéh²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhjÕh²hh³jõh´MIubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”Œdomain”j…Œobjtype”jŒdesctype”jŒnoindex”‰Œ noindexentry”‰Œnocontentsentry”‰uh1jÓh²hhj9h³Nh´NubhŒ container”“”)�”}”(hX�**Parameters** ``const struct landlock_ruleset *ruleset`` Newly created ruleset (never NULL); not yet shared via an fd, so no lock is needed. **Description** Emitted by sys_landlock_create_ruleset() while the new ruleset is still private to the calling thread, before its file descriptor is installed, so it cannot race a concurrent :manpage:`close(2)`. Balanced by a matching landlock_free_ruleset event.”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hjh]”hŒ Parameters”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MMhjubhŒdefinition_list”“”)�”}”(hhh]”hŒdefinition_list_item”“”)�”}”(hŒ``const struct landlock_ruleset *ruleset`` Newly created ruleset (never NULL); not yet shared via an fd, so no lock is needed. ”h]”(hŒterm”“”)�”}”(hŒ*``const struct landlock_ruleset *ruleset``”h]”j)�”}”(hj;h]”hŒ&const struct landlock_ruleset *ruleset”…”�”}”(hj=h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj9ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MLhj3ubhŒ definition”“”)�”}”(hhh]”j )�”}”(hŒSNewly created ruleset (never NULL); not yet shared via an fd, so no lock is needed.”h]”hŒSNewly created ruleset (never NULL); not yet shared via an fd, so no lock is needed.”…”�”}”(hjVh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MKhjSubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj3ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jPh´MLhj.ubah}”(h]”h ]”h"]”h$]”h&]”uh1j,hjubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hjyh]”hŒ Description”…”�”}”(hj{h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjwubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MNhjubj )�”}”(hŒøEmitted by sys_landlock_create_ruleset() while the new ruleset is still private to the calling thread, before its file descriptor is installed, so it cannot race a concurrent :manpage:`close(2)`. Balanced by a matching landlock_free_ruleset event.”h]”(hŒ¯Emitted by sys_landlock_create_ruleset() while the new ruleset is still private to the calling thread, before its file descriptor is installed, so it cannot race a concurrent ”…”�”}”(hj�h²hh³Nh´Nubj›)�”}”(hŒ:manpage:`close(2)`”h]”hŒclose(2)”…”�”}”(hj—h²hh³Nh´Nubah}”(h]”h ]”jšah"]”h$]”h&]”hÅhÆjªŒclose(2)”j¬Œclose”j®j¯uh1jšhj�ubhŒ6. Balanced by a matching landlock_free_ruleset event.”…”�”}”(hj�h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MMhjubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ(trace_landlock_free_ruleset (C function)”Œc.trace_landlock_free_ruleset”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒIvoid trace_landlock_free_ruleset (const struct landlock_ruleset *ruleset)”h]”jß)�”}”(hŒHvoid trace_landlock_free_ruleset(const struct landlock_ruleset *ruleset)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hjÒh²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähjÎh²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mqubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjáh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjÎh²hh³jàh´Mqubj)�”}”(hŒtrace_landlock_free_ruleset”h]”j)�”}”(hŒtrace_landlock_free_ruleset”h]”hŒtrace_landlock_free_ruleset”…”�”}”(hjóh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjïubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhjÎh²hh³jàh´Mqubj')�”}”(hŒ((const struct landlock_ruleset *ruleset)”h]”j-)�”}”(hŒ&const struct landlock_ruleset *ruleset”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj*h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj7h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj ubh)�”}”(hhh]”j)�”}”(hŒlandlock_ruleset”h]”hŒlandlock_ruleset”…”�”}”(hjHh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjEubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jJŒmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡jõsbŒc.trace_landlock_free_ruleset”†”asbuh1hhj ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjhh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjvh²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj ubj)�”}”(hŒruleset”h]”hŒruleset”…”�”}”(hjƒh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjubah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hjÎh²hh³jàh´Mqubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhjÊh²hh³jàh´Mqubah}”(h]”jÅah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³jàh´MqhjÇh²hubjè)�”}”(hhh]”j )�”}”(hŒ Ruleset freed”h]”hŒ Ruleset freed”…”�”}”(hj­h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mqhjªh²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhjÇh²hh³jàh´Mqubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j jÅj jÅj ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hXˆ**Parameters** ``const struct landlock_ruleset *ruleset`` Ruleset being freed (never NULL); at its last reference, so no lock is needed. **Description** Emitted when a ruleset's last reference is dropped (typically when the creating process closes the ruleset file descriptor). Fires even when file-descriptor installation failed after creation, keeping the create/free pair balanced.”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hjÏh]”hŒ Parameters”…”�”}”(hjÑh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjÍubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MuhjÉubj-)�”}”(hhh]”j2)�”}”(hŒz``const struct landlock_ruleset *ruleset`` Ruleset being freed (never NULL); at its last reference, so no lock is needed. ”h]”(j8)�”}”(hŒ*``const struct landlock_ruleset *ruleset``”h]”j)�”}”(hjîh]”hŒ&const struct landlock_ruleset *ruleset”…”�”}”(hjðh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjìubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MthjèubjR)�”}”(hhh]”j )�”}”(hŒNRuleset being freed (never NULL); at its last reference, so no lock is needed.”h]”hŒNRuleset being freed (never NULL); at its last reference, so no lock is needed.”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mshjubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjèubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jh´Mthjåubah}”(h]”h ]”h"]”h$]”h&]”uh1j,hjÉubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hj*h]”hŒ Description”…”�”}”(hj,h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj(ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MvhjÉubj )�”}”(hŒèEmitted when a ruleset's last reference is dropped (typically when the creating process closes the ruleset file descriptor). Fires even when file-descriptor installation failed after creation, keeping the create/free pair balanced.”h]”hŒêEmitted when a ruleset’s last reference is dropped (typically when the creating process closes the ruleset file descriptor). Fires even when file-descriptor installation failed after creation, keeping the create/free pair balanced.”…”�”}”(hj@h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MuhjÉubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ1trace_landlock_add_rule_path_beneath (C function)”Œ&c.trace_landlock_add_rule_path_beneath”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒŸvoid trace_landlock_add_rule_path_beneath (const struct landlock_ruleset *ruleset, u32 flags, u64 access_rights, const struct path *path, const char *pathname)”h]”jß)�”}”(hŒžvoid trace_landlock_add_rule_path_beneath(const struct landlock_ruleset *ruleset, u32 flags, u64 access_rights, const struct path *path, const char *pathname)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hjoh²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähjkh²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M�ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj~h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjkh²hh³j}h´M�ubj)�”}”(hŒ$trace_landlock_add_rule_path_beneath”h]”j)�”}”(hŒ$trace_landlock_add_rule_path_beneath”h]”hŒ$trace_landlock_add_rule_path_beneath”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjŒubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhjkh²hh³j}h´M�ubj')�”}”(hŒu(const struct landlock_ruleset *ruleset, u32 flags, u64 access_rights, const struct path *path, const char *pathname)”h]”(j-)�”}”(hŒ&const struct landlock_ruleset *ruleset”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj¬h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj¨ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj¹h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj¨ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hjÇh²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj¨ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÔh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj¨ubh)�”}”(hhh]”j)�”}”(hŒlandlock_ruleset”h]”hŒlandlock_ruleset”…”�”}”(hjåh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjâubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jçŒmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡j’sbŒ&c.trace_landlock_add_rule_path_beneath”†”asbuh1hhj¨ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj¨ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj¨ubj)�”}”(hŒruleset”h]”hŒruleset”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj¨ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¤ubj-)�”}”(hŒ u32 flags”h]”(h)�”}”(hhh]”j)�”}”(hŒu32”h]”hŒu32”…”�”}”(hj<h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj9ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j>Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jŒ&c.trace_landlock_add_rule_path_beneath”†”asbuh1hhj5ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjZh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj5ubj)�”}”(hŒflags”h]”hŒflags”…”�”}”(hjhh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj5ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¤ubj-)�”}”(hŒu64 access_rights”h]”(h)�”}”(hhh]”j)�”}”(hŒu64”h]”hŒu64”…”�”}”(hj„h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj�ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j†Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jŒ&c.trace_landlock_add_rule_path_beneath”†”asbuh1hhj}ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj¢h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj}ubj)�”}”(hŒ access_rights”h]”hŒ access_rights”…”�”}”(hj°h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj}ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¤ubj-)�”}”(hŒconst struct path *path”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjÉh²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjÅubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÖh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjÅubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hjäh²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjÅubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjñh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjÅubh)�”}”(hhh]”j)�”}”(hŒpath”h]”hŒpath”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjÿubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jŒmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jŒ&c.trace_landlock_add_rule_path_beneath”†”asbuh1hhjÅubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjÅubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hj.h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hjÅubj)�”}”(hŒpath”h]”hŒpath”…”�”}”(hj;h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjÅubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¤ubj-)�”}”(hŒconst char *pathname”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjTh²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjPubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjah²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjPubjå)�”}”(hŒchar”h]”hŒchar”…”�”}”(hjoh²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähjPubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj}h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjPubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hj‹h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hjPubj)�”}”(hŒpathname”h]”hŒpathname”…”�”}”(hj˜h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjPubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¤ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hjkh²hh³j}h´M�ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhjgh²hh³j}h´M�ubah}”(h]”jbah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³j}h´M�hjdh²hubjè)�”}”(hhh]”j )�”}”(hŒ$Path-beneath rule added to a ruleset”h]”hŒ$Path-beneath rule added to a ruleset”…”�”}”(hjÂh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M�hj¿h²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhjdh²hh³j}h´M�ubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j jÚj jÚj ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hX**Parameters** ``const struct landlock_ruleset *ruleset`` Source ruleset (never NULL). ``u32 flags`` Complete validated landlock_add_rule_flags value supplied by this successful call, not the rule's accumulated quiet state. ``u64 access_rights`` Canonical per-call access mask passed to landlock_insert_rule() after normalization, not the raw sys_landlock_add_rule() argument or accumulated rule. ``const struct path *path`` Filesystem path for the rule (never NULL). ``const char *pathname`` Resolved absolute path string (never NULL; error placeholder on resolution failure). **Description** Emitted by sys_landlock_add_rule() under the modified ruleset's lock, so the reported ruleset is a stable snapshot that no concurrent writer can change.”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hjäh]”hŒ Parameters”…”�”}”(hjæh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjâubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M”hjÞubj-)�”}”(hhh]”(j2)�”}”(hŒH``const struct landlock_ruleset *ruleset`` Source ruleset (never NULL). ”h]”(j8)�”}”(hŒ*``const struct landlock_ruleset *ruleset``”h]”j)�”}”(hjh]”hŒ&const struct landlock_ruleset *ruleset”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M’hjýubjR)�”}”(hhh]”j )�”}”(hŒSource ruleset (never NULL).”h]”hŒSource ruleset (never NULL).”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jh´M’hjubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjýubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jh´M’hjúubj2)�”}”(hŒ‰``u32 flags`` Complete validated landlock_add_rule_flags value supplied by this successful call, not the rule's accumulated quiet state. ”h]”(j8)�”}”(hŒ ``u32 flags``”h]”j)�”}”(hj<h]”hŒ u32 flags”…”�”}”(hj>h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj:ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M”hj6ubjR)�”}”(hhh]”j )�”}”(hŒzComplete validated landlock_add_rule_flags value supplied by this successful call, not the rule's accumulated quiet state.”h]”hŒ|Complete validated landlock_add_rule_flags value supplied by this successful call, not the rule’s accumulated quiet state.”…”�”}”(hjUh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M“hjRubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj6ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jQh´M”hjúubj2)�”}”(hŒ­``u64 access_rights`` Canonical per-call access mask passed to landlock_insert_rule() after normalization, not the raw sys_landlock_add_rule() argument or accumulated rule. ”h]”(j8)�”}”(hŒ``u64 access_rights``”h]”j)�”}”(hjvh]”hŒu64 access_rights”…”�”}”(hjxh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjtubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M—hjpubjR)�”}”(hhh]”j )�”}”(hŒ–Canonical per-call access mask passed to landlock_insert_rule() after normalization, not the raw sys_landlock_add_rule() argument or accumulated rule.”h]”hŒ–Canonical per-call access mask passed to landlock_insert_rule() after normalization, not the raw sys_landlock_add_rule() argument or accumulated rule.”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M•hjŒubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjpubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j‹h´M—hjúubj2)�”}”(hŒG``const struct path *path`` Filesystem path for the rule (never NULL). ”h]”(j8)�”}”(hŒ``const struct path *path``”h]”j)�”}”(hj°h]”hŒconst struct path *path”…”�”}”(hj²h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj®ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M˜hjªubjR)�”}”(hhh]”j )�”}”(hŒ*Filesystem path for the rule (never NULL).”h]”hŒ*Filesystem path for the rule (never NULL).”…”�”}”(hjÉh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jÅh´M˜hjÆubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjªubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jÅh´M˜hjúubj2)�”}”(hŒn``const char *pathname`` Resolved absolute path string (never NULL; error placeholder on resolution failure). ”h]”(j8)�”}”(hŒ``const char *pathname``”h]”j)�”}”(hjéh]”hŒconst char *pathname”…”�”}”(hjëh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjçubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MšhjãubjR)�”}”(hhh]”j )�”}”(hŒTResolved absolute path string (never NULL; error placeholder on resolution failure).”h]”hŒTResolved absolute path string (never NULL; error placeholder on resolution failure).”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M™hjÿubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjãubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jþh´Mšhjúubeh}”(h]”h ]”h"]”h$]”h&]”uh1j,hjÞubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hj%h]”hŒ Description”…”�”}”(hj'h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj#ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MœhjÞubj )�”}”(hŒ˜Emitted by sys_landlock_add_rule() under the modified ruleset's lock, so the reported ruleset is a stable snapshot that no concurrent writer can change.”h]”hŒšEmitted by sys_landlock_add_rule() under the modified ruleset’s lock, so the reported ruleset is a stable snapshot that no concurrent writer can change.”…”�”}”(hj;h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M›hjÞubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ-trace_landlock_add_rule_net_port (C function)”Œ"c.trace_landlock_add_rule_net_port”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒvvoid trace_landlock_add_rule_net_port (const struct landlock_ruleset *ruleset, u32 flags, u64 access_rights, u64 port)”h]”jß)�”}”(hŒuvoid trace_landlock_add_rule_net_port(const struct landlock_ruleset *ruleset, u32 flags, u64 access_rights, u64 port)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hjjh²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähjfh²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÈubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjyh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjfh²hh³jxh´MÈubj)�”}”(hŒ trace_landlock_add_rule_net_port”h]”j)�”}”(hŒ trace_landlock_add_rule_net_port”h]”hŒ trace_landlock_add_rule_net_port”…”�”}”(hj‹h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj‡ubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhjfh²hh³jxh´MÈubj')�”}”(hŒP(const struct landlock_ruleset *ruleset, u32 flags, u64 access_rights, u64 port)”h]”(j-)�”}”(hŒ&const struct landlock_ruleset *ruleset”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj§h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj£ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj´h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj£ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hjÂh²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj£ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÏh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj£ubh)�”}”(hhh]”j)�”}”(hŒlandlock_ruleset”h]”hŒlandlock_ruleset”…”�”}”(hjàh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjÝubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jâŒmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡j�sbŒ"c.trace_landlock_add_rule_net_port”†”asbuh1hhj£ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj£ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj£ubj)�”}”(hŒruleset”h]”hŒruleset”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj£ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjŸubj-)�”}”(hŒ u32 flags”h]”(h)�”}”(hhh]”j)�”}”(hŒu32”h]”hŒu32”…”�”}”(hj7h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj4ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j9Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jüŒ"c.trace_landlock_add_rule_net_port”†”asbuh1hhj0ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjUh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj0ubj)�”}”(hŒflags”h]”hŒflags”…”�”}”(hjch²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj0ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjŸubj-)�”}”(hŒu64 access_rights”h]”(h)�”}”(hhh]”j)�”}”(hŒu64”h]”hŒu64”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj|ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j�Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jüŒ"c.trace_landlock_add_rule_net_port”†”asbuh1hhjxubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj�h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjxubj)�”}”(hŒ access_rights”h]”hŒ access_rights”…”�”}”(hj«h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjxubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjŸubj-)�”}”(hŒu64 port”h]”(h)�”}”(hhh]”j)�”}”(hŒu64”h]”hŒu64”…”�”}”(hjÇh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjÄubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jÉŒmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jüŒ"c.trace_landlock_add_rule_net_port”†”asbuh1hhjÀubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjåh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjÀubj)�”}”(hŒport”h]”hŒport”…”�”}”(hjóh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjÀubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjŸubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hjfh²hh³jxh´MÈubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhjbh²hh³jxh´MÈubah}”(h]”j]ah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³jxh´MÈhj_h²hubjè)�”}”(hhh]”j )�”}”(hŒ$Network-port rule added to a ruleset”h]”hŒ$Network-port rule added to a ruleset”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÈhjh²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhj_h²hh³jxh´MÈubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j j5j j5j ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hXÑ**Parameters** ``const struct landlock_ruleset *ruleset`` Source ruleset (never NULL). ``u32 flags`` Complete validated landlock_add_rule_flags value supplied by this successful call, not the rule's accumulated quiet state. ``u64 access_rights`` Canonical per-call access mask passed to landlock_insert_rule() after normalization, not the raw sys_landlock_add_rule() argument or accumulated rule. ``u64 port`` Network port in host endianness, forwarded directly from :c:type:`landlock_net_port_attr.port `. **Description** Emitted by sys_landlock_add_rule() under the modified ruleset's lock, so the reported ruleset is a stable snapshot that no concurrent writer can change.”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hj?h]”hŒ Parameters”…”�”}”(hjAh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj=ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÌhj9ubj-)�”}”(hhh]”(j2)�”}”(hŒH``const struct landlock_ruleset *ruleset`` Source ruleset (never NULL). ”h]”(j8)�”}”(hŒ*``const struct landlock_ruleset *ruleset``”h]”j)�”}”(hj^h]”hŒ&const struct landlock_ruleset *ruleset”…”�”}”(hj`h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj\ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÊhjXubjR)�”}”(hhh]”j )�”}”(hŒSource ruleset (never NULL).”h]”hŒSource ruleset (never NULL).”…”�”}”(hjwh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jsh´MÊhjtubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjXubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jsh´MÊhjUubj2)�”}”(hŒ‰``u32 flags`` Complete validated landlock_add_rule_flags value supplied by this successful call, not the rule's accumulated quiet state. ”h]”(j8)�”}”(hŒ ``u32 flags``”h]”j)�”}”(hj—h]”hŒ u32 flags”…”�”}”(hj™h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj•ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÌhj‘ubjR)�”}”(hhh]”j )�”}”(hŒzComplete validated landlock_add_rule_flags value supplied by this successful call, not the rule's accumulated quiet state.”h]”hŒ|Complete validated landlock_add_rule_flags value supplied by this successful call, not the rule’s accumulated quiet state.”…”�”}”(hj°h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MËhj­ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj‘ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j¬h´MÌhjUubj2)�”}”(hŒ­``u64 access_rights`` Canonical per-call access mask passed to landlock_insert_rule() after normalization, not the raw sys_landlock_add_rule() argument or accumulated rule. ”h]”(j8)�”}”(hŒ``u64 access_rights``”h]”j)�”}”(hjÑh]”hŒu64 access_rights”…”�”}”(hjÓh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÏubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÏhjËubjR)�”}”(hhh]”j )�”}”(hŒ–Canonical per-call access mask passed to landlock_insert_rule() after normalization, not the raw sys_landlock_add_rule() argument or accumulated rule.”h]”hŒ–Canonical per-call access mask passed to landlock_insert_rule() after normalization, not the raw sys_landlock_add_rule() argument or accumulated rule.”…”�”}”(hjêh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÍhjçubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjËubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jæh´MÏhjUubj2)�”}”(hŒ†``u64 port`` Network port in host endianness, forwarded directly from :c:type:`landlock_net_port_attr.port `. ”h]”(j8)�”}”(hŒ ``u64 port``”h]”j)�”}”(hj h]”hŒu64 port”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÑhjubjR)�”}”(hhh]”j )�”}”(hŒxNetwork port in host endianness, forwarded directly from :c:type:`landlock_net_port_attr.port `.”h]”(hŒ9Network port in host endianness, forwarded directly from ”…”�”}”(hj$h²hh³Nh´Nubh)�”}”(hŒ>:c:type:`landlock_net_port_attr.port `”h]”j)�”}”(hj.h]”hŒlandlock_net_port_attr.port”…”�”}”(hj0h²hh³Nh´Nubah}”(h]”h ]”(j•j…Œc-type”eh"]”h$]”h&]”uh1jhj,ubah}”(h]”h ]”h"]”h$]”h&]”Œrefdoc”j¢Œ refdomain”j…Œreftype”Œtype”Œ refexplicit”ˆŒrefwarn”‰j‹jŽ)�”}”j‘]”sbj¨Œlandlock_net_port_attr”uh1hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÐhj$ubhŒ.”…”�”}”(hj$h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³jNh´MÐhj!ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j h´MÑhjUubeh}”(h]”h ]”h"]”h$]”h&]”uh1j,hj9ubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hjmh]”hŒ Description”…”�”}”(hjoh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjkubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÓhj9ubj )�”}”(hŒ˜Emitted by sys_landlock_add_rule() under the modified ruleset's lock, so the reported ruleset is a stable snapshot that no concurrent writer can change.”h]”hŒšEmitted by sys_landlock_add_rule() under the modified ruleset’s lock, so the reported ruleset is a stable snapshot that no concurrent writer can change.”…”�”}”(hjƒh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÒhj9ubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ)trace_landlock_create_domain (C function)”Œc.trace_landlock_create_domain”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒpvoid trace_landlock_create_domain (const struct landlock_domain *domain, const struct landlock_ruleset *ruleset)”h]”jß)�”}”(hŒovoid trace_landlock_create_domain(const struct landlock_domain *domain, const struct landlock_ruleset *ruleset)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hj²h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj®h²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Môubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÁh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj®h²hh³jÀh´Môubj)�”}”(hŒtrace_landlock_create_domain”h]”j)�”}”(hŒtrace_landlock_create_domain”h]”hŒtrace_landlock_create_domain”…”�”}”(hjÓh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjÏubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhj®h²hh³jÀh´Môubj')�”}”(hŒN(const struct landlock_domain *domain, const struct landlock_ruleset *ruleset)”h]”(j-)�”}”(hŒ$const struct landlock_domain *domain”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjïh²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjëubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjüh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjëubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjëubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjëubh)�”}”(hhh]”j)�”}”(hŒlandlock_domain”h]”hŒlandlock_domain”…”�”}”(hj(h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj%ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j*Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡jÕsbŒc.trace_landlock_create_domain”†”asbuh1hhjëubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjHh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjëubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjVh²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hjëubj)�”}”(hŒdomain”h]”hŒdomain”…”�”}”(hjch²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjëubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjçubj-)�”}”(hŒ&const struct landlock_ruleset *ruleset”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj|h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjxubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj‰h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjxubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj—h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjxubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj¤h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjxubh)�”}”(hhh]”j)�”}”(hŒlandlock_ruleset”h]”hŒlandlock_ruleset”…”�”}”(hjµh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj²ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j·Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jDŒc.trace_landlock_create_domain”†”asbuh1hhjxubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÓh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjxubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjáh²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hjxubj)�”}”(hŒruleset”h]”hŒruleset”…”�”}”(hjîh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjxubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjçubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hj®h²hh³jÀh´Môubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhjªh²hh³jÀh´Môubah}”(h]”j¥ah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³jÀh´Môhj§h²hubjè)�”}”(hhh]”j )�”}”(hŒNew domain created”h]”hŒNew domain created”…”�”}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Môhjh²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhj§h²hh³jÀh´Môubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j j0j j0j ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hX¶**Parameters** ``const struct landlock_domain *domain`` Newly created domain (never NULL, immutable after creation). **domain->hierarchy->id** is its unique ID, shared with the landlock_enforce_domain and landlock_free_domain events; **domain->hierarchy->details** holds the requesting process. ``const struct landlock_ruleset *ruleset`` Source ruleset frozen into the domain (never NULL). The ruleset lock is held across the emission, so a BPF program reading it via BTF sees the exact merged ruleset; **ruleset->id** / **ruleset->version** identify it. **Description** Emitted by sys_landlock_restrict_self() once, in the requesting thread's context, right after the merge and before thread-sync. The flags-only path (ruleset_fd == -1) creates no domain and does not emit this event. Paired with the per-thread landlock_enforce_domain (join on **domain->hierarchy->id**) and balanced by a matching landlock_free_domain event.”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hj:h]”hŒ Parameters”…”�”}”(hj<h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj8ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Møhj4ubj-)�”}”(hhh]”(j2)�”}”(hX``const struct landlock_domain *domain`` Newly created domain (never NULL, immutable after creation). **domain->hierarchy->id** is its unique ID, shared with the landlock_enforce_domain and landlock_free_domain events; **domain->hierarchy->details** holds the requesting process. ”h]”(j8)�”}”(hŒ(``const struct landlock_domain *domain``”h]”j)�”}”(hjYh]”hŒ$const struct landlock_domain *domain”…”�”}”(hj[h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjWubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MùhjSubjR)�”}”(hhh]”j )�”}”(hŒîNewly created domain (never NULL, immutable after creation). **domain->hierarchy->id** is its unique ID, shared with the landlock_enforce_domain and landlock_free_domain events; **domain->hierarchy->details** holds the requesting process.”h]”(hŒ=Newly created domain (never NULL, immutable after creation). ”…”�”}”(hjrh²hh³Nh´NubjÞ)�”}”(hŒ**domain->hierarchy->id**”h]”hŒdomain->hierarchy->id”…”�”}”(hjzh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjrubhŒ\ is its unique ID, shared with the landlock_enforce_domain and landlock_free_domain events; ”…”�”}”(hjrh²hh³Nh´NubjÞ)�”}”(hŒ**domain->hierarchy->details**”h]”hŒdomain->hierarchy->details”…”�”}”(hjŒh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjrubhŒ holds the requesting process.”…”�”}”(hjrh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Möhjoubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjSubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jnh´MùhjPubj2)�”}”(hX``const struct landlock_ruleset *ruleset`` Source ruleset frozen into the domain (never NULL). The ruleset lock is held across the emission, so a BPF program reading it via BTF sees the exact merged ruleset; **ruleset->id** / **ruleset->version** identify it. ”h]”(j8)�”}”(hŒ*``const struct landlock_ruleset *ruleset``”h]”j)�”}”(hj·h]”hŒ&const struct landlock_ruleset *ruleset”…”�”}”(hj¹h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjµubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mýhj±ubjR)�”}”(hhh]”j )�”}”(hŒÙSource ruleset frozen into the domain (never NULL). The ruleset lock is held across the emission, so a BPF program reading it via BTF sees the exact merged ruleset; **ruleset->id** / **ruleset->version** identify it.”h]”(hŒ¦Source ruleset frozen into the domain (never NULL). The ruleset lock is held across the emission, so a BPF program reading it via BTF sees the exact merged ruleset; ”…”�”}”(hjÐh²hh³Nh´NubjÞ)�”}”(hŒ**ruleset->id**”h]”hŒ ruleset->id”…”�”}”(hjØh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjÐubhŒ / ”…”�”}”(hjÐh²hh³Nh´NubjÞ)�”}”(hŒ**ruleset->version**”h]”hŒruleset->version”…”�”}”(hjêh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjÐubhŒ identify it.”…”�”}”(hjÐh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MúhjÍubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj±ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jÌh´MýhjPubeh}”(h]”h ]”h"]”h$]”h&]”uh1j,hj4ubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hj h]”hŒ Description”…”�”}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mÿhj4ubj )�”}”(hXfEmitted by sys_landlock_restrict_self() once, in the requesting thread's context, right after the merge and before thread-sync. The flags-only path (ruleset_fd == -1) creates no domain and does not emit this event. Paired with the per-thread landlock_enforce_domain (join on **domain->hierarchy->id**) and balanced by a matching landlock_free_domain event.”h]”(hXEmitted by sys_landlock_restrict_self() once, in the requesting thread’s context, right after the merge and before thread-sync. The flags-only path (ruleset_fd == -1) creates no domain and does not emit this event. Paired with the per-thread landlock_enforce_domain (join on ”…”�”}”(hj- h²hh³Nh´NubjÞ)�”}”(hŒ**domain->hierarchy->id**”h]”hŒdomain->hierarchy->id”…”�”}”(hj5 h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj- ubhŒ8) and balanced by a matching landlock_free_domain event.”…”�”}”(hj- h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mþhj4ubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ*trace_landlock_enforce_domain (C function)”Œc.trace_landlock_enforce_domain”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒ~void trace_landlock_enforce_domain (const struct landlock_domain *domain, bool complete, bool process_wide, bool no_new_privs)”h]”jß)�”}”(hŒ}void trace_landlock_enforce_domain(const struct landlock_domain *domain, bool complete, bool process_wide, bool no_new_privs)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hjn h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähjj h²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M#ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj} h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjj h²hh³j| h´M#ubj)�”}”(hŒtrace_landlock_enforce_domain”h]”j)�”}”(hŒtrace_landlock_enforce_domain”h]”hŒtrace_landlock_enforce_domain”…”�”}”(hj� h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj‹ ubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhjj h²hh³j| h´M#ubj')�”}”(hŒ[(const struct landlock_domain *domain, bool complete, bool process_wide, bool no_new_privs)”h]”(j-)�”}”(hŒ$const struct landlock_domain *domain”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj« h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj§ ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj¸ h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj§ ubj3)�”}”(hjS•sh]”hŒstruct”…”�”}”(hjÆ h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj§ ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÓ h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj§ ubh)�”}”(hhh]”j)�”}”(hŒlandlock_domain”h]”hŒlandlock_domain”…”�”}”(hjä h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjá ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jæ Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡j‘ sbŒc.trace_landlock_enforce_domain”†”asbuh1hhj§ ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj!h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj§ ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hj!h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj§ ubj)�”}”(hŒdomain”h]”hŒdomain”…”�”}”(hj!h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj§ ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj£ ubj-)�”}”(hŒ bool complete”h]”(jå)�”}”(hŒbool”h]”hŒbool”…”�”}”(hj8!h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj4!ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjF!h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj4!ubj)�”}”(hŒcomplete”h]”hŒcomplete”…”�”}”(hjT!h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj4!ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj£ ubj-)�”}”(hŒbool process_wide”h]”(jå)�”}”(hj:!h]”hŒbool”…”�”}”(hjm!h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähji!ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjz!h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhji!ubj)�”}”(hŒ process_wide”h]”hŒ process_wide”…”�”}”(hjˆ!h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hji!ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj£ ubj-)�”}”(hŒbool no_new_privs”h]”(jå)�”}”(hj:!h]”hŒbool”…”�”}”(hj¡!h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj�!ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj®!h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj�!ubj)�”}”(hŒ no_new_privs”h]”hŒ no_new_privs”…”�”}”(hj¼!h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj�!ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj£ ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hjj h²hh³j| h´M#ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhjf h²hh³j| h´M#ubah}”(h]”ja ah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³j| h´M#hjc h²hubjè)�”}”(hhh]”j )�”}”(hŒDomain enforced on a thread”h]”hŒDomain enforced on a thread”…”�”}”(hjæ!h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M#hjã!h²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhjc h²hh³j| h´M#ubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j jþ!j jþ!j ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hXk**Parameters** ``const struct landlock_domain *domain`` Domain now enforced on the current thread (never NULL, immutable; read locklessly). Correlate to landlock_create_domain via **domain->hierarchy->id** for the source ruleset and requesting thread, or read **domain->hierarchy->details** for the requesting process. ``bool complete`` Set on the single event that concludes the operation, after all its other enforcements; filter on it for one event per operation. ``bool process_wide`` The enforcement covers every eligible (non-exiting) thread of the process: set when the caller used ``LANDLOCK_RESTRICT_SELF_TSYNC`` or the process is single-threaded. A lone thread whose group still holds a zombie leader is not counted single-threaded, so process_wide == 0 never proves the opposite. ``bool no_new_privs`` The enforcing thread's no_new_privs state at enforcement time: 1 if set (by a prior :manpage:`prctl(2)` ``PR_SET_NO_NEW_PRIVS`` or by ``LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS``), 0 if the domain was enforced with ``CAP_SYS_ADMIN`` instead. **Description** Emitted for each thread sys_landlock_restrict_self() enforces the domain on, in that thread's own context, right after its commit_creds(), so it fires only once the thread is irreversibly enforcing the domain (aborted operations emit none). Not balanced; every enforcement falls between the domain's landlock_create_domain and landlock_free_domain events. **complete** == 1 && **process_wide** == 1 means the whole process is sandboxed by **domain**, durably (Landlock domains are monotonic and inherited on :manpage:`clone(2)`).”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hj"h]”hŒ Parameters”…”�”}”(hj "h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj"ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M'hj"ubj-)�”}”(hhh]”(j2)�”}”(hX1``const struct landlock_domain *domain`` Domain now enforced on the current thread (never NULL, immutable; read locklessly). Correlate to landlock_create_domain via **domain->hierarchy->id** for the source ruleset and requesting thread, or read **domain->hierarchy->details** for the requesting process. ”h]”(j8)�”}”(hŒ(``const struct landlock_domain *domain``”h]”j)�”}”(hj'"h]”hŒ$const struct landlock_domain *domain”…”�”}”(hj)"h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj%"ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M)hj!"ubjR)�”}”(hhh]”j )�”}”(hXDomain now enforced on the current thread (never NULL, immutable; read locklessly). Correlate to landlock_create_domain via **domain->hierarchy->id** for the source ruleset and requesting thread, or read **domain->hierarchy->details** for the requesting process.”h]”(hŒ}Domain now enforced on the current thread (never NULL, immutable; read locklessly). Correlate to landlock_create_domain via ”…”�”}”(hj@"h²hh³Nh´NubjÞ)�”}”(hŒ**domain->hierarchy->id**”h]”hŒdomain->hierarchy->id”…”�”}”(hjH"h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj@"ubhŒ7 for the source ruleset and requesting thread, or read ”…”�”}”(hj@"h²hh³Nh´NubjÞ)�”}”(hŒ**domain->hierarchy->details**”h]”hŒdomain->hierarchy->details”…”�”}”(hjZ"h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj@"ubhŒ for the requesting process.”…”�”}”(hj@"h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M%hj="ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj!"ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j<"h´M)hj"ubj2)�”}”(hŒ”``bool complete`` Set on the single event that concludes the operation, after all its other enforcements; filter on it for one event per operation. ”h]”(j8)�”}”(hŒ``bool complete``”h]”j)�”}”(hj…"h]”hŒ bool complete”…”�”}”(hj‡"h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjƒ"ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M,hj"ubjR)�”}”(hhh]”j )�”}”(hŒ�Set on the single event that concludes the operation, after all its other enforcements; filter on it for one event per operation.”h]”hŒ�Set on the single event that concludes the operation, after all its other enforcements; filter on it for one event per operation.”…”�”}”(hjž"h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M*hj›"ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj"ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jš"h´M,hj"ubj2)�”}”(hXE``bool process_wide`` The enforcement covers every eligible (non-exiting) thread of the process: set when the caller used ``LANDLOCK_RESTRICT_SELF_TSYNC`` or the process is single-threaded. A lone thread whose group still holds a zombie leader is not counted single-threaded, so process_wide == 0 never proves the opposite. ”h]”(j8)�”}”(hŒ``bool process_wide``”h]”j)�”}”(hj¿"h]”hŒbool process_wide”…”�”}”(hjÁ"h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj½"ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M2hj¹"ubjR)�”}”(hhh]”j )�”}”(hX.The enforcement covers every eligible (non-exiting) thread of the process: set when the caller used ``LANDLOCK_RESTRICT_SELF_TSYNC`` or the process is single-threaded. A lone thread whose group still holds a zombie leader is not counted single-threaded, so process_wide == 0 never proves the opposite.”h]”(hŒdThe enforcement covers every eligible (non-exiting) thread of the process: set when the caller used ”…”�”}”(hjØ"h²hh³Nh´Nubj)�”}”(hŒ ``LANDLOCK_RESTRICT_SELF_TSYNC``”h]”hŒLANDLOCK_RESTRICT_SELF_TSYNC”…”�”}”(hjà"h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjØ"ubhŒª or the process is single-threaded. A lone thread whose group still holds a zombie leader is not counted single-threaded, so process_wide == 0 never proves the opposite.”…”�”}”(hjØ"h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M-hjÕ"ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj¹"ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jÔ"h´M2hj"ubj2)�”}”(hX``bool no_new_privs`` The enforcing thread's no_new_privs state at enforcement time: 1 if set (by a prior :manpage:`prctl(2)` ``PR_SET_NO_NEW_PRIVS`` or by ``LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS``), 0 if the domain was enforced with ``CAP_SYS_ADMIN`` instead. ”h]”(j8)�”}”(hŒ``bool no_new_privs``”h]”j)�”}”(hj #h]”hŒbool no_new_privs”…”�”}”(hj #h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj #ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M7hj#ubjR)�”}”(hhh]”j )�”}”(hŒìThe enforcing thread's no_new_privs state at enforcement time: 1 if set (by a prior :manpage:`prctl(2)` ``PR_SET_NO_NEW_PRIVS`` or by ``LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS``), 0 if the domain was enforced with ``CAP_SYS_ADMIN`` instead.”h]”(hŒVThe enforcing thread’s no_new_privs state at enforcement time: 1 if set (by a prior ”…”�”}”(hj$#h²hh³Nh´Nubj›)�”}”(hŒ:manpage:`prctl(2)`”h]”hŒprctl(2)”…”�”}”(hj,#h²hh³Nh´Nubah}”(h]”h ]”jšah"]”h$]”h&]”hÅhÆjªŒprctl(2)”j¬Œprctl”j®j¯uh1jšhj$#ubhŒ ”…”�”}”(hj$#h²hh³Nh´Nubj)�”}”(hŒ``PR_SET_NO_NEW_PRIVS``”h]”hŒPR_SET_NO_NEW_PRIVS”…”�”}”(hj@#h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj$#ubhŒ or by ”…”�”}”(hj$#h²hh³Nh´Nubj)�”}”(hŒ'``LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS``”h]”hŒ#LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS”…”�”}”(hjR#h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj$#ubhŒ%), 0 if the domain was enforced with ”…”�”}”(hj$#h²hh³Nh´Nubj)�”}”(hŒ``CAP_SYS_ADMIN``”h]”hŒ CAP_SYS_ADMIN”…”�”}”(hjd#h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj$#ubhŒ instead.”…”�”}”(hj$#h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M3hj!#ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj#ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j #h´M7hj"ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j,hj"ubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hj‘#h]”hŒ Description”…”�”}”(hj“#h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj�#ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M9hj"ubj )�”}”(hXdEmitted for each thread sys_landlock_restrict_self() enforces the domain on, in that thread's own context, right after its commit_creds(), so it fires only once the thread is irreversibly enforcing the domain (aborted operations emit none). Not balanced; every enforcement falls between the domain's landlock_create_domain and landlock_free_domain events.”h]”hXhEmitted for each thread sys_landlock_restrict_self() enforces the domain on, in that thread’s own context, right after its commit_creds(), so it fires only once the thread is irreversibly enforcing the domain (aborted operations emit none). Not balanced; every enforcement falls between the domain’s landlock_create_domain and landlock_free_domain events.”…”�”}”(hj§#h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M8hj"ubj )�”}”(hŒ­**complete** == 1 && **process_wide** == 1 means the whole process is sandboxed by **domain**, durably (Landlock domains are monotonic and inherited on :manpage:`clone(2)`).”h]”(jÞ)�”}”(hŒ **complete**”h]”hŒcomplete”…”�”}”(hjº#h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj¶#ubhŒ == 1 && ”…”�”}”(hj¶#h²hh³Nh´NubjÞ)�”}”(hŒ**process_wide**”h]”hŒ process_wide”…”�”}”(hjÌ#h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj¶#ubhŒ. == 1 means the whole process is sandboxed by ”…”�”}”(hj¶#h²hh³Nh´NubjÞ)�”}”(hŒ **domain**”h]”hŒdomain”…”�”}”(hjÞ#h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj¶#ubhŒ;, durably (Landlock domains are monotonic and inherited on ”…”�”}”(hj¶#h²hh³Nh´Nubj›)�”}”(hŒ:manpage:`clone(2)`”h]”hŒclone(2)”…”�”}”(hjð#h²hh³Nh´Nubah}”(h]”h ]”jšah"]”h$]”h&]”hÅhÆjªŒclone(2)”j¬Œclone”j®j¯uh1jšhj¶#ubhŒ).”…”�”}”(hj¶#h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M?hj"ubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ'trace_landlock_free_domain (C function)”Œc.trace_landlock_free_domain”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒLvoid trace_landlock_free_domain (const struct landlock_hierarchy *hierarchy)”h]”jß)�”}”(hŒKvoid trace_landlock_free_domain(const struct landlock_hierarchy *hierarchy)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hj+$h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj'$h²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M_ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj:$h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj'$h²hh³j9$h´M_ubj)�”}”(hŒtrace_landlock_free_domain”h]”j)�”}”(hŒtrace_landlock_free_domain”h]”hŒtrace_landlock_free_domain”…”�”}”(hjL$h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjH$ubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhj'$h²hh³j9$h´M_ubj')�”}”(hŒ,(const struct landlock_hierarchy *hierarchy)”h]”j-)�”}”(hŒ*const struct landlock_hierarchy *hierarchy”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjh$h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjd$ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hju$h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjd$ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hjƒ$h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjd$ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj�$h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjd$ubh)�”}”(hhh]”j)�”}”(hŒlandlock_hierarchy”h]”hŒlandlock_hierarchy”…”�”}”(hj¡$h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjž$ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j£$Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡jN$sbŒc.trace_landlock_free_domain”†”asbuh1hhjd$ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÁ$h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjd$ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjÏ$h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hjd$ubj)�”}”(hŒ hierarchy”h]”hŒ hierarchy”…”�”}”(hjÜ$h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjd$ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj`$ubah}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hj'$h²hh³j9$h´M_ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhj#$h²hh³j9$h´M_ubah}”(h]”j$ah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³j9$h´M_hj $h²hubjè)�”}”(hhh]”j )�”}”(hŒ Domain freed”h]”hŒ Domain freed”…”�”}”(hj%h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M_hj%h²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhj $h²hh³j9$h´M_ubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j j%j j%j ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hX)**Parameters** ``const struct landlock_hierarchy *hierarchy`` Hierarchy node being freed (never NULL). **Description** Emitted when the hierarchy node's last reference is dropped: its refcount reaches zero after all child domains have released their parent reference. A committed domain is freed from a kworker via landlock_put_domain_deferred() (the credential free path runs in RCU context, where sleeping is forbidden), so the current task is not the sandboxed task that triggered the free. Balanced by a matching landlock_create_domain event.”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hj(%h]”hŒ Parameters”…”�”}”(hj*%h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj&%ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mchj"%ubj-)�”}”(hhh]”j2)�”}”(hŒX``const struct landlock_hierarchy *hierarchy`` Hierarchy node being freed (never NULL). ”h]”(j8)�”}”(hŒ.``const struct landlock_hierarchy *hierarchy``”h]”j)�”}”(hjG%h]”hŒ*const struct landlock_hierarchy *hierarchy”…”�”}”(hjI%h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjE%ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MahjA%ubjR)�”}”(hhh]”j )�”}”(hŒ(Hierarchy node being freed (never NULL).”h]”hŒ(Hierarchy node being freed (never NULL).”…”�”}”(hj`%h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³j\%h´Mahj]%ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjA%ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j\%h´Mahj>%ubah}”(h]”h ]”h"]”h$]”h&]”uh1j,hj"%ubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hj‚%h]”hŒ Description”…”�”}”(hj„%h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj€%ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mchj"%ubj )�”}”(hX­Emitted when the hierarchy node's last reference is dropped: its refcount reaches zero after all child domains have released their parent reference. A committed domain is freed from a kworker via landlock_put_domain_deferred() (the credential free path runs in RCU context, where sleeping is forbidden), so the current task is not the sandboxed task that triggered the free. Balanced by a matching landlock_create_domain event.”h]”hX¯Emitted when the hierarchy node’s last reference is dropped: its refcount reaches zero after all child domains have released their parent reference. A committed domain is freed from a kworker via landlock_put_domain_deferred() (the credential free path runs in RCU context, where sleeping is forbidden), so the current task is not the sandboxed task that triggered the free. Balanced by a matching landlock_create_domain event.”…”�”}”(hj˜%h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mbhj"%ubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ,trace_landlock_check_rule_inode (C function)”Œ!c.trace_landlock_check_rule_inode”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒžvoid trace_landlock_check_rule_inode (const struct landlock_domain *domain, const struct landlock_rule *rule, u64 access_request, const struct dentry *dentry)”h]”jß)�”}”(hŒ�void trace_landlock_check_rule_inode(const struct landlock_domain *domain, const struct landlock_rule *rule, u64 access_request, const struct dentry *dentry)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hjÇ%h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähjÃ%h²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M€ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÖ%h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjÃ%h²hh³jÕ%h´M€ubj)�”}”(hŒtrace_landlock_check_rule_inode”h]”j)�”}”(hŒtrace_landlock_check_rule_inode”h]”hŒtrace_landlock_check_rule_inode”…”�”}”(hjè%h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjä%ubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhjÃ%h²hh³jÕ%h´M€ubj')�”}”(hŒy(const struct landlock_domain *domain, const struct landlock_rule *rule, u64 access_request, const struct dentry *dentry)”h]”(j-)�”}”(hŒ$const struct landlock_domain *domain”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj&h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj&ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj&h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj&ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj&h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj&ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj,&h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj&ubh)�”}”(hhh]”j)�”}”(hŒlandlock_domain”h]”hŒlandlock_domain”…”�”}”(hj=&h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj:&ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j?&Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡jê%sbŒ!c.trace_landlock_check_rule_inode”†”asbuh1hhj&ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj]&h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj&ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjk&h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj&ubj)�”}”(hŒdomain”h]”hŒdomain”…”�”}”(hjx&h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj&ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjü%ubj-)�”}”(hŒ const struct landlock_rule *rule”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj‘&h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj�&ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjž&h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj�&ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj¬&h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj�&ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj¹&h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj�&ubh)�”}”(hhh]”j)�”}”(hŒ landlock_rule”h]”hŒ landlock_rule”…”�”}”(hjÊ&h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjÇ&ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jÌ&Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jY&Œ!c.trace_landlock_check_rule_inode”†”asbuh1hhj�&ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjè&h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj�&ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjö&h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj�&ubj)�”}”(hŒrule”h]”hŒrule”…”�”}”(hj'h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj�&ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjü%ubj-)�”}”(hŒu64 access_request”h]”(h)�”}”(hhh]”j)�”}”(hŒu64”h]”hŒu64”…”�”}”(hj'h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj'ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j!'Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jY&Œ!c.trace_landlock_check_rule_inode”†”asbuh1hhj'ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj='h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj'ubj)�”}”(hŒaccess_request”h]”hŒaccess_request”…”�”}”(hjK'h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj'ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjü%ubj-)�”}”(hŒconst struct dentry *dentry”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjd'h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj`'ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjq'h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj`'ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj'h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj`'ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjŒ'h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj`'ubh)�”}”(hhh]”j)�”}”(hŒdentry”h]”hŒdentry”…”�”}”(hj�'h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjš'ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jŸ'Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jY&Œ!c.trace_landlock_check_rule_inode”†”asbuh1hhj`'ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj»'h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj`'ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjÉ'h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj`'ubj)�”}”(hŒdentry”h]”hŒdentry”…”�”}”(hjÖ'h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj`'ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjü%ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hjÃ%h²hh³jÕ%h´M€ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhj¿%h²hh³jÕ%h´M€ubah}”(h]”jº%ah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³jÕ%h´M€hj¼%h²hubjè)�”}”(hhh]”j )�”}”(hŒ(Inode rule evaluated during access check”h]”hŒ(Inode rule evaluated during access check”…”�”}”(hj(h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M€hjý'h²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhj¼%h²hh³jÕ%h´M€ubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j j(j j(j ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hXz**Parameters** ``const struct landlock_domain *domain`` Enforcing domain (never NULL). ``const struct landlock_rule *rule`` Matching rule with per-layer access masks (never NULL). ``u64 access_request`` Access mask evaluated against the rule (the domain's handled mask during rename/link double-checks). ``const struct dentry *dentry`` Filesystem dentry being checked (never NULL). **Description** Emitted for each rule that matches during a filesystem access check. The grants array shows the requested rights the rule grants at each domain layer. See Documentation/trace/events-landlock.rst for how to interpret it.”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hj"(h]”hŒ Parameters”…”�”}”(hj$(h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj (ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M„hj(ubj-)�”}”(hhh]”(j2)�”}”(hŒH``const struct landlock_domain *domain`` Enforcing domain (never NULL). ”h]”(j8)�”}”(hŒ(``const struct landlock_domain *domain``”h]”j)�”}”(hjA(h]”hŒ$const struct landlock_domain *domain”…”�”}”(hjC(h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj?(ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M‚hj;(ubjR)�”}”(hhh]”j )�”}”(hŒEnforcing domain (never NULL).”h]”hŒEnforcing domain (never NULL).”…”�”}”(hjZ(h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jV(h´M‚hjW(ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj;(ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jV(h´M‚hj8(ubj2)�”}”(hŒ]``const struct landlock_rule *rule`` Matching rule with per-layer access masks (never NULL). ”h]”(j8)�”}”(hŒ$``const struct landlock_rule *rule``”h]”j)�”}”(hjz(h]”hŒ const struct landlock_rule *rule”…”�”}”(hj|(h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjx(ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mƒhjt(ubjR)�”}”(hhh]”j )�”}”(hŒ7Matching rule with per-layer access masks (never NULL).”h]”hŒ7Matching rule with per-layer access masks (never NULL).”…”�”}”(hj“(h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³j�(h´Mƒhj�(ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjt(ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j�(h´Mƒhj8(ubj2)�”}”(hŒ|``u64 access_request`` Access mask evaluated against the rule (the domain's handled mask during rename/link double-checks). ”h]”(j8)�”}”(hŒ``u64 access_request``”h]”j)�”}”(hj³(h]”hŒu64 access_request”…”�”}”(hjµ(h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj±(ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M…hj­(ubjR)�”}”(hhh]”j )�”}”(hŒdAccess mask evaluated against the rule (the domain's handled mask during rename/link double-checks).”h]”hŒfAccess mask evaluated against the rule (the domain’s handled mask during rename/link double-checks).”…”�”}”(hjÌ(h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M„hjÉ(ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj­(ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jÈ(h´M…hj8(ubj2)�”}”(hŒN``const struct dentry *dentry`` Filesystem dentry being checked (never NULL). ”h]”(j8)�”}”(hŒ``const struct dentry *dentry``”h]”j)�”}”(hjí(h]”hŒconst struct dentry *dentry”…”�”}”(hjï(h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjë(ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M†hjç(ubjR)�”}”(hhh]”j )�”}”(hŒ-Filesystem dentry being checked (never NULL).”h]”hŒ-Filesystem dentry being checked (never NULL).”…”�”}”(hj)h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³j)h´M†hj)ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjç(ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j)h´M†hj8(ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j,hj(ubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hj()h]”hŒ Description”…”�”}”(hj*)h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj&)ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mˆhj(ubj )�”}”(hŒÜEmitted for each rule that matches during a filesystem access check. The grants array shows the requested rights the rule grants at each domain layer. See Documentation/trace/events-landlock.rst for how to interpret it.”h]”hŒÜEmitted for each rule that matches during a filesystem access check. The grants array shows the requested rights the rule grants at each domain layer. See Documentation/trace/events-landlock.rst for how to interpret it.”…”�”}”(hj>)h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M‡hj(ubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ/trace_landlock_check_rule_net_port (C function)”Œ$c.trace_landlock_check_rule_net_port”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒŽvoid trace_landlock_check_rule_net_port (const struct landlock_domain *domain, const struct landlock_rule *rule, u64 access_request, u64 port)”h]”jß)�”}”(hŒ�void trace_landlock_check_rule_net_port(const struct landlock_domain *domain, const struct landlock_rule *rule, u64 access_request, u64 port)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hjm)h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähji)h²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M³ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj|)h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhji)h²hh³j{)h´M³ubj)�”}”(hŒ"trace_landlock_check_rule_net_port”h]”j)�”}”(hŒ"trace_landlock_check_rule_net_port”h]”hŒ"trace_landlock_check_rule_net_port”…”�”}”(hjŽ)h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjŠ)ubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhji)h²hh³j{)h´M³ubj')�”}”(hŒf(const struct landlock_domain *domain, const struct landlock_rule *rule, u64 access_request, u64 port)”h]”(j-)�”}”(hŒ$const struct landlock_domain *domain”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjª)h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj¦)ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj·)h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj¦)ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hjÅ)h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj¦)ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÒ)h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj¦)ubh)�”}”(hhh]”j)�”}”(hŒlandlock_domain”h]”hŒlandlock_domain”…”�”}”(hjã)h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjà)ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jå)Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡j�)sbŒ$c.trace_landlock_check_rule_net_port”†”asbuh1hhj¦)ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj*h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj¦)ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hj*h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj¦)ubj)�”}”(hŒdomain”h]”hŒdomain”…”�”}”(hj*h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj¦)ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¢)ubj-)�”}”(hŒ const struct landlock_rule *rule”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj7*h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj3*ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjD*h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj3*ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hjR*h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj3*ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj_*h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj3*ubh)�”}”(hhh]”j)�”}”(hŒ landlock_rule”h]”hŒ landlock_rule”…”�”}”(hjp*h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjm*ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jr*Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jÿ)Œ$c.trace_landlock_check_rule_net_port”†”asbuh1hhj3*ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjŽ*h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj3*ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjœ*h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj3*ubj)�”}”(hŒrule”h]”hŒrule”…”�”}”(hj©*h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj3*ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¢)ubj-)�”}”(hŒu64 access_request”h]”(h)�”}”(hhh]”j)�”}”(hŒu64”h]”hŒu64”…”�”}”(hjÅ*h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjÂ*ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jÇ*Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jÿ)Œ$c.trace_landlock_check_rule_net_port”†”asbuh1hhj¾*ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjã*h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj¾*ubj)�”}”(hŒaccess_request”h]”hŒaccess_request”…”�”}”(hjñ*h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj¾*ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¢)ubj-)�”}”(hŒu64 port”h]”(h)�”}”(hhh]”j)�”}”(hŒu64”h]”hŒu64”…”�”}”(hj +h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj +ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j+Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jÿ)Œ$c.trace_landlock_check_rule_net_port”†”asbuh1hhj+ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj++h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj+ubj)�”}”(hŒport”h]”hŒport”…”�”}”(hj9+h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj+ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¢)ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hji)h²hh³j{)h´M³ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhje)h²hh³j{)h´M³ubah}”(h]”j`)ah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³j{)h´M³hjb)h²hubjè)�”}”(hhh]”j )�”}”(hŒNetwork port rule evaluated”h]”hŒNetwork port rule evaluated”…”�”}”(hjc+h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M³hj`+h²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhjb)h²hh³j{)h´M³ubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j j{+j j{+j ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hX**Parameters** ``const struct landlock_domain *domain`` Enforcing domain (never NULL). ``const struct landlock_rule *rule`` Matching rule with per-layer access masks (never NULL). ``u64 access_request`` Access mask being requested. ``u64 port`` Network port being checked (host endianness). **Description** Emitted for each rule that matches during a network access check. The grants array shows the requested rights the rule grants at each domain layer. See Documentation/trace/events-landlock.rst for how to interpret it.”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hj…+h]”hŒ Parameters”…”�”}”(hj‡+h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjƒ+ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M·hj+ubj-)�”}”(hhh]”(j2)�”}”(hŒH``const struct landlock_domain *domain`` Enforcing domain (never NULL). ”h]”(j8)�”}”(hŒ(``const struct landlock_domain *domain``”h]”j)�”}”(hj¤+h]”hŒ$const struct landlock_domain *domain”…”�”}”(hj¦+h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj¢+ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mµhjž+ubjR)�”}”(hhh]”j )�”}”(hŒEnforcing domain (never NULL).”h]”hŒEnforcing domain (never NULL).”…”�”}”(hj½+h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³j¹+h´Mµhjº+ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjž+ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j¹+h´Mµhj›+ubj2)�”}”(hŒ]``const struct landlock_rule *rule`` Matching rule with per-layer access masks (never NULL). ”h]”(j8)�”}”(hŒ$``const struct landlock_rule *rule``”h]”j)�”}”(hjÝ+h]”hŒ const struct landlock_rule *rule”…”�”}”(hjß+h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÛ+ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M¶hj×+ubjR)�”}”(hhh]”j )�”}”(hŒ7Matching rule with per-layer access masks (never NULL).”h]”hŒ7Matching rule with per-layer access masks (never NULL).”…”�”}”(hjö+h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jò+h´M¶hjó+ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj×+ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jò+h´M¶hj›+ubj2)�”}”(hŒ4``u64 access_request`` Access mask being requested. ”h]”(j8)�”}”(hŒ``u64 access_request``”h]”j)�”}”(hj,h]”hŒu64 access_request”…”�”}”(hj,h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj,ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M·hj,ubjR)�”}”(hhh]”j )�”}”(hŒAccess mask being requested.”h]”hŒAccess mask being requested.”…”�”}”(hj/,h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³j+,h´M·hj,,ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj,ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j+,h´M·hj›+ubj2)�”}”(hŒ;``u64 port`` Network port being checked (host endianness). ”h]”(j8)�”}”(hŒ ``u64 port``”h]”j)�”}”(hjO,h]”hŒu64 port”…”�”}”(hjQ,h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjM,ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M¸hjI,ubjR)�”}”(hhh]”j )�”}”(hŒ-Network port being checked (host endianness).”h]”hŒ-Network port being checked (host endianness).”…”�”}”(hjh,h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jd,h´M¸hje,ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjI,ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jd,h´M¸hj›+ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j,hj+ubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hjŠ,h]”hŒ Description”…”�”}”(hjŒ,h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjˆ,ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mºhj+ubj )�”}”(hŒÚEmitted for each rule that matches during a network access check. The grants array shows the requested rights the rule grants at each domain layer. See Documentation/trace/events-landlock.rst for how to interpret it.”h]”hŒÚEmitted for each rule that matches during a network access check. The grants array shows the requested rights the rule grants at each domain layer. See Documentation/trace/events-landlock.rst for how to interpret it.”…”�”}”(hj ,h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M¹hj+ubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ*trace_landlock_deny_access_fs (C function)”Œc.trace_landlock_deny_access_fs”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒÅvoid trace_landlock_deny_access_fs (const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, const struct landlock_blockers *blockers, const struct path *path, const char *pathname)”h]”jß)�”}”(hŒÄvoid trace_landlock_deny_access_fs(const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, const struct landlock_blockers *blockers, const struct path *path, const char *pathname)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hjÏ,h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähjË,h²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mãubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÞ,h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjË,h²hh³jÝ,h´Mãubj)�”}”(hŒtrace_landlock_deny_access_fs”h]”j)�”}”(hŒtrace_landlock_deny_access_fs”h]”hŒtrace_landlock_deny_access_fs”…”�”}”(hjð,h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjì,ubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhjË,h²hh³jÝ,h´Mãubj')�”}”(hŒ¢(const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, const struct landlock_blockers *blockers, const struct path *path, const char *pathname)”h]”(j-)�”}”(hŒ*const struct landlock_hierarchy *hierarchy”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj -h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj-ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj-h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj-ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj'-h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj-ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj4-h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj-ubh)�”}”(hhh]”j)�”}”(hŒlandlock_hierarchy”h]”hŒlandlock_hierarchy”…”�”}”(hjE-h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjB-ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jG-Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡jò,sbŒc.trace_landlock_deny_access_fs”†”asbuh1hhj-ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hje-h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj-ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjs-h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj-ubj)�”}”(hŒ hierarchy”h]”hŒ hierarchy”…”�”}”(hj€-h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj-ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj-ubj-)�”}”(hŒbool same_exec”h]”(jå)�”}”(hj:!h]”hŒbool”…”�”}”(hj™-h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj•-ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj¦-h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj•-ubj)�”}”(hŒ same_exec”h]”hŒ same_exec”…”�”}”(hj´-h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj•-ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj-ubj-)�”}”(hŒ bool logged”h]”(jå)�”}”(hj:!h]”hŒbool”…”�”}”(hjÍ-h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähjÉ-ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÚ-h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjÉ-ubj)�”}”(hŒlogged”h]”hŒlogged”…”�”}”(hjè-h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjÉ-ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj-ubj-)�”}”(hŒ(const struct landlock_blockers *blockers”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj.h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjý-ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj.h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjý-ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj.h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjý-ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj).h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjý-ubh)�”}”(hhh]”j)�”}”(hŒlandlock_blockers”h]”hŒlandlock_blockers”…”�”}”(hj:.h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj7.ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j<.Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”ja-Œc.trace_landlock_deny_access_fs”†”asbuh1hhjý-ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjX.h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjý-ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjf.h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hjý-ubj)�”}”(hŒblockers”h]”hŒblockers”…”�”}”(hjs.h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjý-ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj-ubj-)�”}”(hŒconst struct path *path”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjŒ.h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjˆ.ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj™.h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjˆ.ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj§.h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjˆ.ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj´.h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjˆ.ubh)�”}”(hhh]”j)�”}”(hŒpath”h]”hŒpath”…”�”}”(hjÅ.h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjÂ.ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jÇ.Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”ja-Œc.trace_landlock_deny_access_fs”†”asbuh1hhjˆ.ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjã.h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjˆ.ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjñ.h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hjˆ.ubj)�”}”(hŒpath”h]”hŒpath”…”�”}”(hjþ.h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjˆ.ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj-ubj-)�”}”(hŒconst char *pathname”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj/h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj/ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj$/h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj/ubjå)�”}”(hŒchar”h]”hŒchar”…”�”}”(hj2/h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj/ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj@/h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj/ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjN/h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj/ubj)�”}”(hŒpathname”h]”hŒpathname”…”�”}”(hj[/h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj/ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj-ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hjË,h²hh³jÝ,h´Mãubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhjÇ,h²hh³jÝ,h´Mãubah}”(h]”jÂ,ah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³jÝ,h´MãhjÄ,h²hubjè)�”}”(hhh]”j )�”}”(hŒFilesystem access denied”h]”hŒFilesystem access denied”…”�”}”(hj…/h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mãhj‚/h²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhjÄ,h²hh³jÝ,h´Mãubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j j�/j j�/j ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hX˜**Parameters** ``const struct landlock_hierarchy *hierarchy`` Denying domain's hierarchy node (never NULL); its id is the domain field. ``bool same_exec`` Whether the current task entered the denying domain itself. ``bool logged`` The domain's audit-logging decision for this denial. ``const struct landlock_blockers *blockers`` Request type and final missing access subset (never NULL). ``const struct path *path`` Filesystem path that was denied (never NULL). ``const char *pathname`` Resolved path string (never NULL; an error placeholder on resolution failure). **Description** Emitted when a Landlock domain denies a filesystem access.”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hj§/h]”hŒ Parameters”…”�”}”(hj©/h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj¥/ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mçhj¡/ubj-)�”}”(hhh]”(j2)�”}”(hŒy``const struct landlock_hierarchy *hierarchy`` Denying domain's hierarchy node (never NULL); its id is the domain field. ”h]”(j8)�”}”(hŒ.``const struct landlock_hierarchy *hierarchy``”h]”j)�”}”(hjÆ/h]”hŒ*const struct landlock_hierarchy *hierarchy”…”�”}”(hjÈ/h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÄ/ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MæhjÀ/ubjR)�”}”(hhh]”j )�”}”(hŒIDenying domain's hierarchy node (never NULL); its id is the domain field.”h]”hŒKDenying domain’s hierarchy node (never NULL); its id is the domain field.”…”�”}”(hjß/h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MåhjÜ/ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjÀ/ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jÛ/h´Mæhj½/ubj2)�”}”(hŒO``bool same_exec`` Whether the current task entered the denying domain itself. ”h]”(j8)�”}”(hŒ``bool same_exec``”h]”j)�”}”(hj0h]”hŒbool same_exec”…”�”}”(hj0h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjþ/ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mçhjú/ubjR)�”}”(hhh]”j )�”}”(hŒ;Whether the current task entered the denying domain itself.”h]”hŒ;Whether the current task entered the denying domain itself.”…”�”}”(hj0h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³j0h´Mçhj0ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjú/ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j0h´Mçhj½/ubj2)�”}”(hŒE``bool logged`` The domain's audit-logging decision for this denial. ”h]”(j8)�”}”(hŒ``bool logged``”h]”j)�”}”(hj90h]”hŒ bool logged”…”�”}”(hj;0h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj70ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mèhj30ubjR)�”}”(hhh]”j )�”}”(hŒ4The domain's audit-logging decision for this denial.”h]”hŒ6The domain’s audit-logging decision for this denial.”…”�”}”(hjR0h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jN0h´MèhjO0ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj30ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jN0h´Mèhj½/ubj2)�”}”(hŒh``const struct landlock_blockers *blockers`` Request type and final missing access subset (never NULL). ”h]”(j8)�”}”(hŒ,``const struct landlock_blockers *blockers``”h]”j)�”}”(hjr0h]”hŒ(const struct landlock_blockers *blockers”…”�”}”(hjt0h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjp0ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Méhjl0ubjR)�”}”(hhh]”j )�”}”(hŒ:Request type and final missing access subset (never NULL).”h]”hŒ:Request type and final missing access subset (never NULL).”…”�”}”(hj‹0h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³j‡0h´Méhjˆ0ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjl0ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j‡0h´Méhj½/ubj2)�”}”(hŒJ``const struct path *path`` Filesystem path that was denied (never NULL). ”h]”(j8)�”}”(hŒ``const struct path *path``”h]”j)�”}”(hj«0h]”hŒconst struct path *path”…”�”}”(hj­0h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj©0ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mêhj¥0ubjR)�”}”(hhh]”j )�”}”(hŒ-Filesystem path that was denied (never NULL).”h]”hŒ-Filesystem path that was denied (never NULL).”…”�”}”(hjÄ0h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jÀ0h´MêhjÁ0ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj¥0ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jÀ0h´Mêhj½/ubj2)�”}”(hŒh``const char *pathname`` Resolved path string (never NULL; an error placeholder on resolution failure). ”h]”(j8)�”}”(hŒ``const char *pathname``”h]”j)�”}”(hjä0h]”hŒconst char *pathname”…”�”}”(hjæ0h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjâ0ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MìhjÞ0ubjR)�”}”(hhh]”j )�”}”(hŒNResolved path string (never NULL; an error placeholder on resolution failure).”h]”hŒNResolved path string (never NULL; an error placeholder on resolution failure).”…”�”}”(hjý0h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mëhjú0ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjÞ0ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jù0h´Mìhj½/ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j,hj¡/ubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hj 1h]”hŒ Description”…”�”}”(hj"1h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj1ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mîhj¡/ubj )�”}”(hŒ:Emitted when a Landlock domain denies a filesystem access.”h]”hŒ:Emitted when a Landlock domain denies a filesystem access.”…”�”}”(hj61h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Míhj¡/ubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ+trace_landlock_deny_access_net (C function)”Œ c.trace_landlock_deny_access_net”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒövoid trace_landlock_deny_access_net (const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, const struct landlock_blockers *blockers, const struct sock *sk, u16 socket_family, const struct sockaddr_storage *address, int addrlen)”h]”jß)�”}”(hŒõvoid trace_landlock_deny_access_net(const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, const struct landlock_blockers *blockers, const struct sock *sk, u16 socket_family, const struct sockaddr_storage *address, int addrlen)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hje1h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähja1h²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M%ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjt1h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhja1h²hh³js1h´M%ubj)�”}”(hŒtrace_landlock_deny_access_net”h]”j)�”}”(hŒtrace_landlock_deny_access_net”h]”hŒtrace_landlock_deny_access_net”…”�”}”(hj†1h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj‚1ubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhja1h²hh³js1h´M%ubj')�”}”(hŒÒ(const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, const struct landlock_blockers *blockers, const struct sock *sk, u16 socket_family, const struct sockaddr_storage *address, int addrlen)”h]”(j-)�”}”(hŒ*const struct landlock_hierarchy *hierarchy”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj¢1h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjž1ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj¯1h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjž1ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj½1h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjž1ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÊ1h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjž1ubh)�”}”(hhh]”j)�”}”(hŒlandlock_hierarchy”h]”hŒlandlock_hierarchy”…”�”}”(hjÛ1h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjØ1ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jÝ1Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡jˆ1sbŒ c.trace_landlock_deny_access_net”†”asbuh1hhjž1ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjû1h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjž1ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hj 2h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hjž1ubj)�”}”(hŒ hierarchy”h]”hŒ hierarchy”…”�”}”(hj2h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjž1ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjš1ubj-)�”}”(hŒbool same_exec”h]”(jå)�”}”(hj:!h]”hŒbool”…”�”}”(hj/2h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj+2ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj<2h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj+2ubj)�”}”(hŒ same_exec”h]”hŒ same_exec”…”�”}”(hjJ2h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj+2ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjš1ubj-)�”}”(hŒ bool logged”h]”(jå)�”}”(hj:!h]”hŒbool”…”�”}”(hjc2h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj_2ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjp2h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj_2ubj)�”}”(hŒlogged”h]”hŒlogged”…”�”}”(hj~2h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj_2ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjš1ubj-)�”}”(hŒ(const struct landlock_blockers *blockers”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj—2h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj“2ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj¤2h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj“2ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj²2h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj“2ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj¿2h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj“2ubh)�”}”(hhh]”j)�”}”(hŒlandlock_blockers”h]”hŒlandlock_blockers”…”�”}”(hjÐ2h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjÍ2ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jÒ2Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j÷1Œ c.trace_landlock_deny_access_net”†”asbuh1hhj“2ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjî2h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj“2ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjü2h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj“2ubj)�”}”(hŒblockers”h]”hŒblockers”…”�”}”(hj 3h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj“2ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjš1ubj-)�”}”(hŒconst struct sock *sk”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj"3h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj3ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj/3h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj3ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj=3h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj3ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjJ3h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj3ubh)�”}”(hhh]”j)�”}”(hŒsock”h]”hŒsock”…”�”}”(hj[3h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjX3ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j]3Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j÷1Œ c.trace_landlock_deny_access_net”†”asbuh1hhj3ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjy3h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj3ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hj‡3h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj3ubj)�”}”(hŒsk”h]”hŒsk”…”�”}”(hj”3h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj3ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjš1ubj-)�”}”(hŒu16 socket_family”h]”(h)�”}”(hhh]”j)�”}”(hŒu16”h]”hŒu16”…”�”}”(hj°3h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj­3ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j²3Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j÷1Œ c.trace_landlock_deny_access_net”†”asbuh1hhj©3ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÎ3h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj©3ubj)�”}”(hŒ socket_family”h]”hŒ socket_family”…”�”}”(hjÜ3h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj©3ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjš1ubj-)�”}”(hŒ&const struct sockaddr_storage *address”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjõ3h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjñ3ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj4h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjñ3ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj4h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjñ3ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj4h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjñ3ubh)�”}”(hhh]”j)�”}”(hŒsockaddr_storage”h]”hŒsockaddr_storage”…”�”}”(hj.4h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj+4ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j04Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j÷1Œ c.trace_landlock_deny_access_net”†”asbuh1hhjñ3ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjL4h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjñ3ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjZ4h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hjñ3ubj)�”}”(hŒaddress”h]”hŒaddress”…”�”}”(hjg4h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjñ3ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjš1ubj-)�”}”(hŒ int addrlen”h]”(jå)�”}”(hŒint”h]”hŒint”…”�”}”(hj€4h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj|4ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjŽ4h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj|4ubj)�”}”(hŒaddrlen”h]”hŒaddrlen”…”�”}”(hjœ4h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj|4ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjš1ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hja1h²hh³js1h´M%ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhj]1h²hh³js1h´M%ubah}”(h]”jX1ah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³js1h´M%hjZ1h²hubjè)�”}”(hhh]”j )�”}”(hŒNetwork access denied”h]”hŒNetwork access denied”…”�”}”(hjÆ4h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M%hjÃ4h²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhjZ1h²hh³js1h´M%ubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j jÞ4j jÞ4j ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hXE**Parameters** ``const struct landlock_hierarchy *hierarchy`` Denying domain's hierarchy node (never NULL); its id is the domain field. ``bool same_exec`` Whether the current task entered the denying domain itself. ``bool logged`` The domain's audit-logging decision for this denial. ``const struct landlock_blockers *blockers`` Request type and final missing access subset (never NULL). ``const struct sock *sk`` Socket object (never NULL), read without a socket lock, so its fields are a best-effort snapshot. ``u16 socket_family`` Socket-family snapshot used by the verdict. ``const struct sockaddr_storage *address`` Authoritative address checked by the verdict (never NULL). The producer copies **addrlen** bytes from the checked address and zeroes the remaining storage before emission. The :c:type:`sockaddr_in.sin_port ` or :c:type:`sockaddr_in6.sin6_port ` member, when present, remains in network endianness. ``int addrlen`` Validated signed length of **address**. **Description** Emitted when a Landlock domain denies a network operation. The blocker identifies whether the address is a bind or connect/send policy object. The flattened port field is converted from the checked address to host endianness, or is -1 when no port was checked. Zero is a valid checked port.”•¬Óh]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hjè4h]”hŒ Parameters”…”�”}”(hjê4h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjæ4ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M)hjâ4ubj-)�”}”(hhh]”(j2)�”}”(hŒy``const struct landlock_hierarchy *hierarchy`` Denying domain's hierarchy node (never NULL); its id is the domain field. ”h]”(j8)�”}”(hŒ.``const struct landlock_hierarchy *hierarchy``”h]”j)�”}”(hj5h]”hŒ*const struct landlock_hierarchy *hierarchy”…”�”}”(hj 5h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj5ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M(hj5ubjR)�”}”(hhh]”j )�”}”(hŒIDenying domain's hierarchy node (never NULL); its id is the domain field.”h]”hŒKDenying domain’s hierarchy node (never NULL); its id is the domain field.”…”�”}”(hj 5h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M'hj5ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj5ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j5h´M(hjþ4ubj2)�”}”(hŒO``bool same_exec`` Whether the current task entered the denying domain itself. ”h]”(j8)�”}”(hŒ``bool same_exec``”h]”j)�”}”(hjA5h]”hŒbool same_exec”…”�”}”(hjC5h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj?5ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M)hj;5ubjR)�”}”(hhh]”j )�”}”(hŒ;Whether the current task entered the denying domain itself.”h]”hŒ;Whether the current task entered the denying domain itself.”…”�”}”(hjZ5h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jV5h´M)hjW5ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj;5ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jV5h´M)hjþ4ubj2)�”}”(hŒE``bool logged`` The domain's audit-logging decision for this denial. ”h]”(j8)�”}”(hŒ``bool logged``”h]”j)�”}”(hjz5h]”hŒ bool logged”…”�”}”(hj|5h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjx5ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M*hjt5ubjR)�”}”(hhh]”j )�”}”(hŒ4The domain's audit-logging decision for this denial.”h]”hŒ6The domain’s audit-logging decision for this denial.”…”�”}”(hj“5h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³j�5h´M*hj�5ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjt5ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j�5h´M*hjþ4ubj2)�”}”(hŒh``const struct landlock_blockers *blockers`` Request type and final missing access subset (never NULL). ”h]”(j8)�”}”(hŒ,``const struct landlock_blockers *blockers``”h]”j)�”}”(hj³5h]”hŒ(const struct landlock_blockers *blockers”…”�”}”(hjµ5h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj±5ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M+hj­5ubjR)�”}”(hhh]”j )�”}”(hŒ:Request type and final missing access subset (never NULL).”h]”hŒ:Request type and final missing access subset (never NULL).”…”�”}”(hjÌ5h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jÈ5h´M+hjÉ5ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj­5ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jÈ5h´M+hjþ4ubj2)�”}”(hŒ|``const struct sock *sk`` Socket object (never NULL), read without a socket lock, so its fields are a best-effort snapshot. ”h]”(j8)�”}”(hŒ``const struct sock *sk``”h]”j)�”}”(hjì5h]”hŒconst struct sock *sk”…”�”}”(hjî5h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjê5ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M-hjæ5ubjR)�”}”(hhh]”j )�”}”(hŒaSocket object (never NULL), read without a socket lock, so its fields are a best-effort snapshot.”h]”hŒaSocket object (never NULL), read without a socket lock, so its fields are a best-effort snapshot.”…”�”}”(hj6h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M,hj6ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjæ5ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j6h´M-hjþ4ubj2)�”}”(hŒB``u16 socket_family`` Socket-family snapshot used by the verdict. ”h]”(j8)�”}”(hŒ``u16 socket_family``”h]”j)�”}”(hj&6h]”hŒu16 socket_family”…”�”}”(hj(6h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj$6ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M.hj 6ubjR)�”}”(hhh]”j )�”}”(hŒ+Socket-family snapshot used by the verdict.”h]”hŒ+Socket-family snapshot used by the verdict.”…”�”}”(hj?6h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³j;6h´M.hj<6ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj 6ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j;6h´M.hjþ4ubj2)�”}”(hXq``const struct sockaddr_storage *address`` Authoritative address checked by the verdict (never NULL). The producer copies **addrlen** bytes from the checked address and zeroes the remaining storage before emission. The :c:type:`sockaddr_in.sin_port ` or :c:type:`sockaddr_in6.sin6_port ` member, when present, remains in network endianness. ”h]”(j8)�”}”(hŒ*``const struct sockaddr_storage *address``”h]”j)�”}”(hj_6h]”hŒ&const struct sockaddr_storage *address”…”�”}”(hja6h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj]6ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M3hjY6ubjR)�”}”(hhh]”j )�”}”(hXEAuthoritative address checked by the verdict (never NULL). The producer copies **addrlen** bytes from the checked address and zeroes the remaining storage before emission. The :c:type:`sockaddr_in.sin_port ` or :c:type:`sockaddr_in6.sin6_port ` member, when present, remains in network endianness.”h]”(hŒOAuthoritative address checked by the verdict (never NULL). The producer copies ”…”�”}”(hjx6h²hh³Nh´NubjÞ)�”}”(hŒ **addrlen**”h]”hŒaddrlen”…”�”}”(hj€6h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjx6ubhŒW bytes from the checked address and zeroes the remaining storage before emission. The ”…”�”}”(hjx6h²hh³Nh´Nubh)�”}”(hŒ,:c:type:`sockaddr_in.sin_port `”h]”j)�”}”(hj”6h]”hŒsockaddr_in.sin_port”…”�”}”(hj–6h²hh³Nh´Nubah}”(h]”h ]”(j•j…Œc-type”eh"]”h$]”h&]”uh1jhj’6ubah}”(h]”h ]”h"]”h$]”h&]”Œrefdoc”j¢Œ refdomain”j…Œreftype”Œtype”Œ refexplicit”ˆŒrefwarn”‰j‹jJj¨Œ sockaddr_in”uh1hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M/hjx6ubhŒ or ”…”�”}”(hjx6h²hh³Nh´Nubh)�”}”(hŒ/:c:type:`sockaddr_in6.sin6_port `”h]”j)�”}”(hj¸6h]”hŒsockaddr_in6.sin6_port”…”�”}”(hjº6h²hh³Nh´Nubah}”(h]”h ]”(j•j…Œc-type”eh"]”h$]”h&]”uh1jhj¶6ubah}”(h]”h ]”h"]”h$]”h&]”Œrefdoc”j¢Œ refdomain”j…Œreftype”Œtype”Œ refexplicit”ˆŒrefwarn”‰j‹jJj¨Œ sockaddr_in6”uh1hh³j±6h´M/hjx6ubhŒ5 member, when present, remains in network endianness.”…”�”}”(hjx6h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³j±6h´M/hju6ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjY6ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jt6h´M3hjþ4ubj2)�”}”(hŒ8``int addrlen`` Validated signed length of **address**. ”h]”(j8)�”}”(hŒ``int addrlen``”h]”j)�”}”(hjñ6h]”hŒ int addrlen”…”�”}”(hjó6h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjï6ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M4hjë6ubjR)�”}”(hhh]”j )�”}”(hŒ'Validated signed length of **address**.”h]”(hŒValidated signed length of ”…”�”}”(hj 7h²hh³Nh´NubjÞ)�”}”(hŒ **address**”h]”hŒaddress”…”�”}”(hj7h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj 7ubhŒ.”…”�”}”(hj 7h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1j h³j7h´M4hj7ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjë6ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j7h´M4hjþ4ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j,hjâ4ubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hj>7h]”hŒ Description”…”�”}”(hj@7h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj<7ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M6hjâ4ubj )�”}”(hX$Emitted when a Landlock domain denies a network operation. The blocker identifies whether the address is a bind or connect/send policy object. The flattened port field is converted from the checked address to host endianness, or is -1 when no port was checked. Zero is a valid checked port.”h]”hX$Emitted when a Landlock domain denies a network operation. The blocker identifies whether the address is a bind or connect/send policy object. The flattened port field is converted from the checked address to host endianness, or is -1 when no port was checked. Zero is a valid checked port.”…”�”}”(hjT7h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M5hjâ4ubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ'trace_landlock_deny_ptrace (C function)”Œc.trace_landlock_deny_ptrace”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒÃvoid trace_landlock_deny_ptrace (const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, u64 tracee_domain_id, const struct task_struct *tracee, const struct task_struct *tracer)”h]”jß)�”}”(hŒÂvoid trace_landlock_deny_ptrace(const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, u64 tracee_domain_id, const struct task_struct *tracee, const struct task_struct *tracer)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hjƒ7h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj7h²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mmubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj’7h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj7h²hh³j‘7h´Mmubj)�”}”(hŒtrace_landlock_deny_ptrace”h]”j)�”}”(hŒtrace_landlock_deny_ptrace”h]”hŒtrace_landlock_deny_ptrace”…”�”}”(hj¤7h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj 7ubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhj7h²hh³j‘7h´Mmubj')�”}”(hŒ£(const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, u64 tracee_domain_id, const struct task_struct *tracee, const struct task_struct *tracer)”h]”(j-)�”}”(hŒ*const struct landlock_hierarchy *hierarchy”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjÀ7h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj¼7ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÍ7h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj¼7ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hjÛ7h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj¼7ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjè7h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj¼7ubh)�”}”(hhh]”j)�”}”(hŒlandlock_hierarchy”h]”hŒlandlock_hierarchy”…”�”}”(hjù7h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjö7ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jû7Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡j¦7sbŒc.trace_landlock_deny_ptrace”†”asbuh1hhj¼7ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj8h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj¼7ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hj'8h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj¼7ubj)�”}”(hŒ hierarchy”h]”hŒ hierarchy”…”�”}”(hj48h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj¼7ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¸7ubj-)�”}”(hŒbool same_exec”h]”(jå)�”}”(hj:!h]”hŒbool”…”�”}”(hjM8h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähjI8ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjZ8h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjI8ubj)�”}”(hŒ same_exec”h]”hŒ same_exec”…”�”}”(hjh8h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjI8ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¸7ubj-)�”}”(hŒ bool logged”h]”(jå)�”}”(hj:!h]”hŒbool”…”�”}”(hj�8h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj}8ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjŽ8h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj}8ubj)�”}”(hŒlogged”h]”hŒlogged”…”�”}”(hjœ8h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj}8ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¸7ubj-)�”}”(hŒu64 tracee_domain_id”h]”(h)�”}”(hhh]”j)�”}”(hŒu64”h]”hŒu64”…”�”}”(hj¸8h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjµ8ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jº8Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j8Œc.trace_landlock_deny_ptrace”†”asbuh1hhj±8ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÖ8h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj±8ubj)�”}”(hŒtracee_domain_id”h]”hŒtracee_domain_id”…”�”}”(hjä8h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj±8ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¸7ubj-)�”}”(hŒ const struct task_struct *tracee”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjý8h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjù8ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj 9h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjù8ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj9h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjù8ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj%9h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjù8ubh)�”}”(hhh]”j)�”}”(hŒ task_struct”h]”hŒ task_struct”…”�”}”(hj69h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj39ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j89Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j8Œc.trace_landlock_deny_ptrace”†”asbuh1hhjù8ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjT9h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjù8ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjb9h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hjù8ubj)�”}”(hŒtracee”h]”hŒtracee”…”�”}”(hjo9h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjù8ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¸7ubj-)�”}”(hŒ const struct task_struct *tracer”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjˆ9h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj„9ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj•9h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj„9ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj£9h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj„9ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj°9h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj„9ubh)�”}”(hhh]”j)�”}”(hŒ task_struct”h]”hŒ task_struct”…”�”}”(hjÁ9h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj¾9ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jÃ9Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j8Œc.trace_landlock_deny_ptrace”†”asbuh1hhj„9ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjß9h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj„9ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjí9h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj„9ubj)�”}”(hŒtracer”h]”hŒtracer”…”�”}”(hjú9h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj„9ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj¸7ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hj7h²hh³j‘7h´Mmubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhj{7h²hh³j‘7h´Mmubah}”(h]”jv7ah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³j‘7h´Mmhjx7h²hubjè)�”}”(hhh]”j )�”}”(hŒ)Ptrace access denied by a Landlock domain”h]”hŒ)Ptrace access denied by a Landlock domain”…”�”}”(hj$:h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mmhj!:h²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhjx7h²hh³j‘7h´Mmubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j j<:j j<:j ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hX÷**Parameters** ``const struct landlock_hierarchy *hierarchy`` Denying domain's hierarchy node (never NULL); its id is the domain field. ``bool same_exec`` Whether the tracer entered the denying domain itself. ``bool logged`` The domain's audit-logging decision for this denial. ``u64 tracee_domain_id`` The tracee's Landlock domain ID, or 0 if the tracee is unsandboxed. ``const struct task_struct *tracee`` The target task ptrace acted on (never NULL). tracee_pid is the init-namespace TGID (like audit's opid). ``const struct task_struct *tracer`` The tracer or proposed tracer (never NULL); for PTRACE_TRACEME this is the parent, not the syscall caller. **Description** Emitted when a Landlock domain denies a ptrace operation.”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hjF:h]”hŒ Parameters”…”�”}”(hjH:h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjD:ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mqhj@:ubj-)�”}”(hhh]”(j2)�”}”(hŒy``const struct landlock_hierarchy *hierarchy`` Denying domain's hierarchy node (never NULL); its id is the domain field. ”h]”(j8)�”}”(hŒ.``const struct landlock_hierarchy *hierarchy``”h]”j)�”}”(hje:h]”hŒ*const struct landlock_hierarchy *hierarchy”…”�”}”(hjg:h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjc:ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mphj_:ubjR)�”}”(hhh]”j )�”}”(hŒIDenying domain's hierarchy node (never NULL); its id is the domain field.”h]”hŒKDenying domain’s hierarchy node (never NULL); its id is the domain field.”…”�”}”(hj~:h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mohj{:ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj_:ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jz:h´Mphj\:ubj2)�”}”(hŒI``bool same_exec`` Whether the tracer entered the denying domain itself. ”h]”(j8)�”}”(hŒ``bool same_exec``”h]”j)�”}”(hjŸ:h]”hŒbool same_exec”…”�”}”(hj¡:h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj�:ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mqhj™:ubjR)�”}”(hhh]”j )�”}”(hŒ5Whether the tracer entered the denying domain itself.”h]”hŒ5Whether the tracer entered the denying domain itself.”…”�”}”(hj¸:h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³j´:h´Mqhjµ:ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj™:ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j´:h´Mqhj\:ubj2)�”}”(hŒE``bool logged`` The domain's audit-logging decision for this denial. ”h]”(j8)�”}”(hŒ``bool logged``”h]”j)�”}”(hjØ:h]”hŒ bool logged”…”�”}”(hjÚ:h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÖ:ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MrhjÒ:ubjR)�”}”(hhh]”j )�”}”(hŒ4The domain's audit-logging decision for this denial.”h]”hŒ6The domain’s audit-logging decision for this denial.”…”�”}”(hjñ:h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jí:h´Mrhjî:ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjÒ:ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jí:h´Mrhj\:ubj2)�”}”(hŒ]``u64 tracee_domain_id`` The tracee's Landlock domain ID, or 0 if the tracee is unsandboxed. ”h]”(j8)�”}”(hŒ``u64 tracee_domain_id``”h]”j)�”}”(hj;h]”hŒu64 tracee_domain_id”…”�”}”(hj;h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj;ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mthj ;ubjR)�”}”(hhh]”j )�”}”(hŒCThe tracee's Landlock domain ID, or 0 if the tracee is unsandboxed.”h]”hŒEThe tracee’s Landlock domain ID, or 0 if the tracee is unsandboxed.”…”�”}”(hj*;h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mshj';ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj ;ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j&;h´Mthj\:ubj2)�”}”(hŒ�``const struct task_struct *tracee`` The target task ptrace acted on (never NULL). tracee_pid is the init-namespace TGID (like audit's opid). ”h]”(j8)�”}”(hŒ$``const struct task_struct *tracee``”h]”j)�”}”(hjK;h]”hŒ const struct task_struct *tracee”…”�”}”(hjM;h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjI;ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MvhjE;ubjR)�”}”(hhh]”j )�”}”(hŒiThe target task ptrace acted on (never NULL). tracee_pid is the init-namespace TGID (like audit's opid).”h]”hŒkThe target task ptrace acted on (never NULL). tracee_pid is the init-namespace TGID (like audit’s opid).”…”�”}”(hjd;h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Muhja;ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjE;ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j`;h´Mvhj\:ubj2)�”}”(hŒ�``const struct task_struct *tracer`` The tracer or proposed tracer (never NULL); for PTRACE_TRACEME this is the parent, not the syscall caller. ”h]”(j8)�”}”(hŒ$``const struct task_struct *tracer``”h]”j)�”}”(hj…;h]”hŒ const struct task_struct *tracer”…”�”}”(hj‡;h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjƒ;ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mxhj;ubjR)�”}”(hhh]”j )�”}”(hŒjThe tracer or proposed tracer (never NULL); for PTRACE_TRACEME this is the parent, not the syscall caller.”h]”hŒjThe tracer or proposed tracer (never NULL); for PTRACE_TRACEME this is the parent, not the syscall caller.”…”�”}”(hjž;h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mwhj›;ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj;ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jš;h´Mxhj\:ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j,hj@:ubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hjÁ;h]”hŒ Description”…”�”}”(hjÃ;h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhj¿;ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Mzhj@:ubj )�”}”(hŒ9Emitted when a Landlock domain denies a ptrace operation.”h]”hŒ9Emitted when a Landlock domain denies a ptrace operation.”…”�”}”(hj×;h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´Myhj@:ubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ-trace_landlock_deny_scope_signal (C function)”Œ"c.trace_landlock_deny_scope_signal”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒ³void trace_landlock_deny_scope_signal (const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, u64 target_domain_id, const struct task_struct *target, int signal)”h]”jß)�”}”(hŒ²void trace_landlock_deny_scope_signal(const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, u64 target_domain_id, const struct task_struct *target, int signal)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hj<h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj<h²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MŸubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj<h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj<h²hh³j<h´MŸubj)�”}”(hŒ trace_landlock_deny_scope_signal”h]”j)�”}”(hŒ trace_landlock_deny_scope_signal”h]”hŒ trace_landlock_deny_scope_signal”…”�”}”(hj'<h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj#<ubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhj<h²hh³j<h´MŸubj')�”}”(hŒ�(const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, u64 target_domain_id, const struct task_struct *target, int signal)”h]”(j-)�”}”(hŒ*const struct landlock_hierarchy *hierarchy”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjC<h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj?<ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjP<h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj?<ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj^<h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj?<ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjk<h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj?<ubh)�”}”(hhh]”j)�”}”(hŒlandlock_hierarchy”h]”hŒlandlock_hierarchy”…”�”}”(hj|<h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjy<ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j~<Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡j)<sbŒ"c.trace_landlock_deny_scope_signal”†”asbuh1hhj?<ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjœ<h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj?<ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjª<h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj?<ubj)�”}”(hŒ hierarchy”h]”hŒ hierarchy”…”�”}”(hj·<h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj?<ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj;<ubj-)�”}”(hŒbool same_exec”h]”(jå)�”}”(hj:!h]”hŒbool”…”�”}”(hjÐ<h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähjÌ<ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÝ<h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjÌ<ubj)�”}”(hŒ same_exec”h]”hŒ same_exec”…”�”}”(hjë<h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjÌ<ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj;<ubj-)�”}”(hŒ bool logged”h]”(jå)�”}”(hj:!h]”hŒbool”…”�”}”(hj=h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj=ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj=h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj=ubj)�”}”(hŒlogged”h]”hŒlogged”…”�”}”(hj=h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj=ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj;<ubj-)�”}”(hŒu64 target_domain_id”h]”(h)�”}”(hhh]”j)�”}”(hŒu64”h]”hŒu64”…”�”}”(hj;=h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj8=ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j==Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j˜<Œ"c.trace_landlock_deny_scope_signal”†”asbuh1hhj4=ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjY=h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj4=ubj)�”}”(hŒtarget_domain_id”h]”hŒtarget_domain_id”…”�”}”(hjg=h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj4=ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj;<ubj-)�”}”(hŒ const struct task_struct *target”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj€=h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj|=ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj�=h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj|=ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj›=h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj|=ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj¨=h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj|=ubh)�”}”(hhh]”j)�”}”(hŒ task_struct”h]”hŒ task_struct”…”�”}”(hj¹=h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj¶=ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j»=Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j˜<Œ"c.trace_landlock_deny_scope_signal”†”asbuh1hhj|=ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj×=h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj|=ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjå=h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj|=ubj)�”}”(hŒtarget”h]”hŒtarget”…”�”}”(hjò=h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj|=ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj;<ubj-)�”}”(hŒ int signal”h]”(jå)�”}”(hŒint”h]”hŒint”…”�”}”(hj >h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj>ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj>h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj>ubj)�”}”(hŒsignal”h]”hŒsignal”…”�”}”(hj'>h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj>ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hj;<ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hj<h²hh³j<h´MŸubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhjþ;h²hh³j<h´MŸubah}”(h]”jù;ah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³j<h´MŸhjû;h²hubjè)�”}”(hhh]”j )�”}”(hŒ/Signal delivery denied by LANDLOCK_SCOPE_SIGNAL”h]”hŒ/Signal delivery denied by LANDLOCK_SCOPE_SIGNAL”…”�”}”(hjQ>h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MŸhjN>h²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhjû;h²hh³j<h´MŸubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j ji>j ji>j ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hXî**Parameters** ``const struct landlock_hierarchy *hierarchy`` Denying domain's hierarchy node (never NULL); its id is the domain field. ``bool same_exec`` Whether the policy subject entered the denying domain itself. ``bool logged`` The domain's audit-logging decision for this denial. ``u64 target_domain_id`` The target's Landlock domain ID, or 0 if the target is unsandboxed. ``const struct task_struct *target`` The task the signal was aimed at (never NULL). target_pid is the init-namespace TGID (like audit's opid). ``int signal`` The signal selected by the denied check. Zero is a permission probe, not an absent value. **Description** Emitted when a Landlock domain denies signal delivery to a scoped-out target.”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hjs>h]”hŒ Parameters”…”�”}”(hju>h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjq>ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M£hjm>ubj-)�”}”(hhh]”(j2)�”}”(hŒy``const struct landlock_hierarchy *hierarchy`` Denying domain's hierarchy node (never NULL); its id is the domain field. ”h]”(j8)�”}”(hŒ.``const struct landlock_hierarchy *hierarchy``”h]”j)�”}”(hj’>h]”hŒ*const struct landlock_hierarchy *hierarchy”…”�”}”(hj”>h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj�>ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M£hjŒ>ubjR)�”}”(hhh]”j )�”}”(hŒIDenying domain's hierarchy node (never NULL); its id is the domain field.”h]”hŒKDenying domain’s hierarchy node (never NULL); its id is the domain field.”…”�”}”(hj«>h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M¢hj¨>ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjŒ>ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j§>h´M£hj‰>ubj2)�”}”(hŒQ``bool same_exec`` Whether the policy subject entered the denying domain itself. ”h]”(j8)�”}”(hŒ``bool same_exec``”h]”j)�”}”(hjÌ>h]”hŒbool same_exec”…”�”}”(hjÎ>h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÊ>ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M¤hjÆ>ubjR)�”}”(hhh]”j )�”}”(hŒ=Whether the policy subject entered the denying domain itself.”h]”hŒ=Whether the policy subject entered the denying domain itself.”…”�”}”(hjå>h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³já>h´M¤hjâ>ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjÆ>ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³já>h´M¤hj‰>ubj2)�”}”(hŒE``bool logged`` The domain's audit-logging decision for this denial. ”h]”(j8)�”}”(hŒ``bool logged``”h]”j)�”}”(hj?h]”hŒ bool logged”…”�”}”(hj?h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj?ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M¥hjÿ>ubjR)�”}”(hhh]”j )�”}”(hŒ4The domain's audit-logging decision for this denial.”h]”hŒ6The domain’s audit-logging decision for this denial.”…”�”}”(hj?h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³j?h´M¥hj?ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjÿ>ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j?h´M¥hj‰>ubj2)�”}”(hŒ]``u64 target_domain_id`` The target's Landlock domain ID, or 0 if the target is unsandboxed. ”h]”(j8)�”}”(hŒ``u64 target_domain_id``”h]”j)�”}”(hj>?h]”hŒu64 target_domain_id”…”�”}”(hj@?h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjubj2)�”}”(hŒ�``const struct task_struct *target`` The task the signal was aimed at (never NULL). target_pid is the init-namespace TGID (like audit's opid). ”h]”(j8)�”}”(hŒ$``const struct task_struct *target``”h]”j)�”}”(hjx?h]”hŒ const struct task_struct *target”…”�”}”(hjz?h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjv?ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M©hjr?ubjR)�”}”(hhh]”j )�”}”(hŒjThe task the signal was aimed at (never NULL). target_pid is the init-namespace TGID (like audit's opid).”h]”hŒlThe task the signal was aimed at (never NULL). target_pid is the init-namespace TGID (like audit’s opid).”…”�”}”(hj‘?h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M¨hjŽ?ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjr?ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j�?h´M©hj‰>ubj2)�”}”(hŒj``int signal`` The signal selected by the denied check. Zero is a permission probe, not an absent value. ”h]”(j8)�”}”(hŒ``int signal``”h]”j)�”}”(hj²?h]”hŒ int signal”…”�”}”(hj´?h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj°?ubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M«hj¬?ubjR)�”}”(hhh]”j )�”}”(hŒZThe signal selected by the denied check. Zero is a permission probe, not an absent value.”h]”hŒZThe signal selected by the denied check. Zero is a permission probe, not an absent value.”…”�”}”(hjË?h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MªhjÈ?ubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj¬?ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jÇ?h´M«hj‰>ubeh}”(h]”h ]”h"]”h$]”h&]”uh1j,hjm>ubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hjî?h]”hŒ Description”…”�”}”(hjð?h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjì?ubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M­hjm>ubj )�”}”(hŒMEmitted when a Landlock domain denies signal delivery to a scoped-out target.”h]”hŒMEmitted when a Landlock domain denies signal delivery to a scoped-out target.”…”�”}”(hj@h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M¬hjm>ubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´NubjÃ)�”}”(hhh]”h}”(h]”h ]”h"]”h$]”h&]”Œentries”]”(jÏŒ;trace_landlock_deny_scope_abstract_unix_socket (C function)”Œ0c.trace_landlock_deny_scope_abstract_unix_socket”hNt”auh1jÂhj9h²hh³Nh´NubjÔ)�”}”(hhh]”(jÙ)�”}”(hŒªvoid trace_landlock_deny_scope_abstract_unix_socket (const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, u64 peer_domain_id, const struct sock *peer)”h]”jß)�”}”(hŒ©void trace_landlock_deny_scope_abstract_unix_socket(const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, u64 peer_domain_id, const struct sock *peer)”h]”(jå)�”}”(hŒvoid”h]”hŒvoid”…”�”}”(hj3@h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj/@h²hh³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÒubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjB@h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj/@h²hh³jA@h´MÒubj)�”}”(hŒ.trace_landlock_deny_scope_abstract_unix_socket”h]”j)�”}”(hŒ.trace_landlock_deny_scope_abstract_unix_socket”h]”hŒ.trace_landlock_deny_scope_abstract_unix_socket”…”�”}”(hjT@h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjP@ubah}”(h]”h ]”(j!j"eh"]”h$]”h&]”hÅhÆuh1jhj/@h²hh³jA@h´MÒubj')�”}”(hŒv(const struct landlock_hierarchy *hierarchy, bool same_exec, bool logged, u64 peer_domain_id, const struct sock *peer)”h]”(j-)�”}”(hŒ*const struct landlock_hierarchy *hierarchy”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hjp@h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjl@ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj}@h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjl@ubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hj‹@h²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hjl@ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj˜@h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjl@ubh)�”}”(hhh]”j)�”}”(hŒlandlock_hierarchy”h]”hŒlandlock_hierarchy”…”�”}”(hj©@h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj¦@ubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”j«@Œmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”j”)�”}”j‡jV@sbŒ0c.trace_landlock_deny_scope_abstract_unix_socket”†”asbuh1hhjl@ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÉ@h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjl@ubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hj×@h²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hjl@ubj)�”}”(hŒ hierarchy”h]”hŒ hierarchy”…”�”}”(hjä@h²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjl@ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjh@ubj-)�”}”(hŒbool same_exec”h]”(jå)�”}”(hj:!h]”hŒbool”…”�”}”(hjý@h²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähjù@ubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj Ah²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjù@ubj)�”}”(hŒ same_exec”h]”hŒ same_exec”…”�”}”(hjAh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjù@ubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjh@ubj-)�”}”(hŒ bool logged”h]”(jå)�”}”(hj:!h]”hŒbool”…”�”}”(hj1Ah²hh³Nh´Nubah}”(h]”h ]”jñah"]”h$]”h&]”uh1jähj-Aubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj>Ah²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj-Aubj)�”}”(hŒlogged”h]”hŒlogged”…”�”}”(hjLAh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj-Aubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjh@ubj-)�”}”(hŒu64 peer_domain_id”h]”(h)�”}”(hhh]”j)�”}”(hŒu64”h]”hŒu64”…”�”}”(hjhAh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjeAubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jjAŒmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jÅ@Œ0c.trace_landlock_deny_scope_abstract_unix_socket”†”asbuh1hhjaAubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hj†Ah²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhjaAubj)�”}”(hŒpeer_domain_id”h]”hŒpeer_domain_id”…”�”}”(hj”Ah²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjaAubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjh@ubj-)�”}”(hŒconst struct sock *peer”h]”(j3)�”}”(hj6h]”hŒconst”…”�”}”(hj­Ah²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj©Aubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjºAh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj©Aubj3)�”}”(hjSh]”hŒstruct”…”�”}”(hjÈAh²hh³Nh´Nubah}”(h]”h ]”j?ah"]”h$]”h&]”uh1j2hj©Aubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjÕAh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj©Aubh)�”}”(hhh]”j)�”}”(hŒsock”h]”hŒsock”…”�”}”(hjæAh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hjãAubah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”j…Œreftype”j‡Œ reftarget”jèAŒmodname”NŒ classname”Nj‹jŽ)�”}”j‘]”jÅ@Œ0c.trace_landlock_deny_scope_abstract_unix_socket”†”asbuh1hhj©Aubj÷)�”}”(hŒ ”h]”hŒ ”…”�”}”(hjBh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1jöhj©Aubj¨)�”}”(hj«h]”hŒ*”…”�”}”(hjBh²hh³Nh´Nubah}”(h]”h ]”j´ah"]”h$]”h&]”uh1j§hj©Aubj)�”}”(hŒpeer”h]”hŒpeer”…”�”}”(hjBh²hh³Nh´Nubah}”(h]”h ]”jah"]”h$]”h&]”uh1j hj©Aubeh}”(h]”h ]”h"]”h$]”h&]”Œnoemph”ˆhÅhÆuh1j,hjh@ubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆuh1j&hj/@h²hh³jA@h´MÒubeh}”(h]”h ]”h"]”h$]”h&]”hÅhÆjÙˆuh1jÞjÚjÛhj+@h²hh³jA@h´MÒubah}”(h]”j&@ah ]”(jßjàeh"]”h$]”h&]”jäˆjå)jæhuh1jØh³jA@h´MÒhj(@h²hubjè)�”}”(hhh]”j )�”}”(hŒIAbstract unix socket access denied by LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET”h]”hŒIAbstract unix socket access denied by LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET”…”�”}”(hjIBh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÒhjFBh²hubah}”(h]”h ]”h"]”h$]”h&]”uh1jçhj(@h²hh³jA@h´MÒubeh}”(h]”h ]”(j…Œfunction”eh"]”h$]”h&]”jj…j jaBj jaBj ‰j ‰j ‰uh1jÓh²hhj9h³Nh´Nubj)�”}”(hX™**Parameters** ``const struct landlock_hierarchy *hierarchy`` Denying domain's hierarchy node (never NULL); its id is the domain field. ``bool same_exec`` Whether the current task entered the denying domain itself. ``bool logged`` The domain's audit-logging decision for this denial. ``u64 peer_domain_id`` The peer's Landlock domain ID, or 0 if the peer is unsandboxed. ``const struct sock *peer`` Peer socket (never NULL). peer_pid is best-effort: it is 0 for a datagram peer (no SO_PEERCRED), so sun_path is the reliable peer identifier. **Description** Emitted when a Landlock domain denies access to a scoped-out abstract unix socket.”h]”(j )�”}”(hŒ**Parameters**”h]”jÞ)�”}”(hjkBh]”hŒ Parameters”…”�”}”(hjmBh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjiBubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÖhjeBubj-)�”}”(hhh]”(j2)�”}”(hŒy``const struct landlock_hierarchy *hierarchy`` Denying domain's hierarchy node (never NULL); its id is the domain field. ”h]”(j8)�”}”(hŒ.``const struct landlock_hierarchy *hierarchy``”h]”j)�”}”(hjŠBh]”hŒ*const struct landlock_hierarchy *hierarchy”…”�”}”(hjŒBh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjˆBubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÖhj„BubjR)�”}”(hhh]”j )�”}”(hŒIDenying domain's hierarchy node (never NULL); its id is the domain field.”h]”hŒKDenying domain’s hierarchy node (never NULL); its id is the domain field.”…”�”}”(hj£Bh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÕhj Bubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj„Bubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jŸBh´MÖhj�Bubj2)�”}”(hŒO``bool same_exec`` Whether the current task entered the denying domain itself. ”h]”(j8)�”}”(hŒ``bool same_exec``”h]”j)�”}”(hjÄBh]”hŒbool same_exec”…”�”}”(hjÆBh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjÂBubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´M×hj¾BubjR)�”}”(hhh]”j )�”}”(hŒ;Whether the current task entered the denying domain itself.”h]”hŒ;Whether the current task entered the denying domain itself.”…”�”}”(hjÝBh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jÙBh´M×hjÚBubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj¾Bubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jÙBh´M×hj�Bubj2)�”}”(hŒE``bool logged`` The domain's audit-logging decision for this denial. ”h]”(j8)�”}”(hŒ``bool logged``”h]”j)�”}”(hjýBh]”hŒ bool logged”…”�”}”(hjÿBh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjûBubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MØhj÷BubjR)�”}”(hhh]”j )�”}”(hŒ4The domain's audit-logging decision for this denial.”h]”hŒ6The domain’s audit-logging decision for this denial.”…”�”}”(hjCh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³jCh´MØhjCubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj÷Bubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jCh´MØhj�Bubj2)�”}”(hŒW``u64 peer_domain_id`` The peer's Landlock domain ID, or 0 if the peer is unsandboxed. ”h]”(j8)�”}”(hŒ``u64 peer_domain_id``”h]”j)�”}”(hj6Ch]”hŒu64 peer_domain_id”…”�”}”(hj8Ch²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhj4Cubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÚhj0CubjR)�”}”(hhh]”j )�”}”(hŒ?The peer's Landlock domain ID, or 0 if the peer is unsandboxed.”h]”hŒAThe peer’s Landlock domain ID, or 0 if the peer is unsandboxed.”…”�”}”(hjOCh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÙhjLCubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhj0Cubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³jKCh´MÚhj�Bubj2)�”}”(hŒ«``const struct sock *peer`` Peer socket (never NULL). peer_pid is best-effort: it is 0 for a datagram peer (no SO_PEERCRED), so sun_path is the reliable peer identifier. ”h]”(j8)�”}”(hŒ``const struct sock *peer``”h]”j)�”}”(hjpCh]”hŒconst struct sock *peer”…”�”}”(hjrCh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jhjnCubah}”(h]”h ]”h"]”h$]”h&]”uh1j7h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÝhjjCubjR)�”}”(hhh]”j )�”}”(hŒŽPeer socket (never NULL). peer_pid is best-effort: it is 0 for a datagram peer (no SO_PEERCRED), so sun_path is the reliable peer identifier.”h]”hŒŽPeer socket (never NULL). peer_pid is best-effort: it is 0 for a datagram peer (no SO_PEERCRED), so sun_path is the reliable peer identifier.”…”�”}”(hj‰Ch²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÛhj†Cubah}”(h]”h ]”h"]”h$]”h&]”uh1jQhjjCubeh}”(h]”h ]”h"]”h$]”h&]”uh1j1h³j…Ch´MÝhj�Bubeh}”(h]”h ]”h"]”h$]”h&]”uh1j,hjeBubj )�”}”(hŒ**Description**”h]”jÞ)�”}”(hj¬Ch]”hŒ Description”…”�”}”(hj®Ch²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1jÝhjªCubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MßhjeBubj )�”}”(hŒREmitted when a Landlock domain denies access to a scoped-out abstract unix socket.”h]”hŒREmitted when a Landlock domain denies access to a scoped-out abstract unix socket.”…”�”}”(hjÂCh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³Œf/var/lib/git/docbuild/linux/Documentation/trace/events-landlock:323: ./include/trace/events/landlock.h”h´MÞhjeBubeh}”(h]”h ]”Œ kernelindent”ah"]”h$]”h&]”uh1jhj9h²hh³Nh´Nubeh}”(h]”jÃah ]”h"]”Œevent reference”ah$]”h&]”uh1hÖhhØh²hh³hÇh´M>Œ referenced”Kubh×)�”}”(hhh]”(hÜ)�”}”(hŒAdditional documentation”h]”hŒAdditional documentation”…”�”}”(hjãCh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÛhjàCh²hh³hÇh´MGubjø)�”}”(hhh]”(jý)�”}”(hŒ(Documentation/userspace-api/landlock.rst”h]”j )�”}”(hjöCh]”hŒ(Documentation/userspace-api/landlock.rst”…”�”}”(hjøCh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´MIhjôCubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjñCh²hh³hÇh´Nubjý)�”}”(hŒ*Documentation/admin-guide/LSM/landlock.rst”h]”j )�”}”(hj Dh]”hŒ*Documentation/admin-guide/LSM/landlock.rst”…”�”}”(hjDh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´MJhj Dubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjñCh²hh³hÇh´Nubjý)�”}”(hŒ#Documentation/security/landlock.rst”h]”j )�”}”(hj$Dh]”hŒ#Documentation/security/landlock.rst”…”�”}”(hj&Dh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´MKhj"Dubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjñCh²hh³hÇh´Nubjý)�”}”(hŒhttps://landlock.io”h]”j )�”}”(hj;Dh]”j±)�”}”(hj;Dh]”hŒhttps://landlock.io”…”�”}”(hj@Dh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”Œrefuri”j;Duh1j°hj=Dubah}”(h]”h ]”h"]”h$]”h&]”uh1j h³hÇh´MLhj9Dubah}”(h]”h ]”h"]”h$]”h&]”uh1jühjñCh²hh³hÇh´Nubeh}”(h]”h ]”h"]”h$]”h&]”jÀj«uh1j÷h³hÇh´MIhjàCh²hubeh}”(h]”Œadditional-documentation”ah ]”h"]”Œadditional documentation”ah$]”h&]”uh1hÖhhØh²hh³hÇh´MGubeh}”(h]”Œlandlock-trace-events”ah ]”h"]”Œlandlock trace events”ah$]”h&]”uh1hÖhhh²hh³hÇh´Kubeh}”(h]”h ]”h"]”h$]”h&]”Œsource”hÇuh1hŒcurrent_source”NŒ current_line”NŒsettings”Œdocutils.frontend”ŒValues”“”)�”}”(hÛNŒ generator”NŒ datestamp”NŒ source_link”NŒ source_url”NŒ toc_backlinks”Œentry”Œfootnote_backlinks”KŒ sectnum_xform”KŒstrip_comments”NŒstrip_elements_with_classes”NŒ strip_classes”NŒ report_level”KŒ halt_level”KŒexit_status_level”KŒdebug”NŒwarning_stream”NŒ traceback”ˆŒinput_encoding”Œ utf-8-sig”Œinput_encoding_error_handler”Œstrict”Œoutput_encoding”Œutf-8”Œoutput_encoding_error_handler”j“DŒerror_encoding”Œutf-8”Œerror_encoding_error_handler”Œbackslashreplace”Œ language_code”Œen”Œrecord_dependencies”NŒconfig”NŒ id_prefix”hŒauto_id_prefix”Œid”Œ dump_settings”NŒdump_internals”NŒdump_transforms”NŒdump_pseudo_xml”NŒexpose_internals”NŒstrict_visitor”NŒ_disable_config”NŒ_source”hÇŒ _destination”NŒ _config_files”]”Œ7/var/lib/git/docbuild/linux/Documentation/docutils.conf”aŒfile_insertion_enabled”ˆŒ raw_enabled”KŒline_length_limit”M'Œpep_references”NŒ pep_base_url”Œhttps://peps.python.org/”Œpep_file_url_template”Œpep-%04d”Œrfc_references”NŒ rfc_base_url”Œ&https://datatracker.ietf.org/doc/html/”Œ tab_width”KŒtrim_footnote_reference_space”‰Œsyntax_highlight”Œlong”Œ smart_quotes”ˆŒsmartquotes_locales”]”Œcharacter_level_inline_markup”‰Œdoctitle_xform”‰Œ docinfo_xform”KŒsectsubtitle_xform”‰Œ image_loading”Œlink”Œembed_stylesheet”‰Œcloak_email_addresses”ˆŒsection_self_link”‰Œenv”NubŒreporter”NŒindirect_targets”]”Œsubstitution_defs”}”Œsubstitution_names”}”Œrefnames”}”Œevent reference”]”j²asŒrefids”}”Œnameids”}”(jmDjjDj†jƒjõjòjúj÷jr jo jÏ jÌ jÞ jÛ j‚jjËjÈj6j3jÜCjÃj~j{jÀj½j÷jôjjjGjDjojlj—j”j¿j¼jeDjbDuŒ nametypes”}”(jmD‰j†‰jõ‰jú‰jr ‰jÏ ‰jÞ ‰j‚‰jˉj6‰jÜC‰j~‰jÀ‰j÷‰j‰jG‰jo‰j—‰j¿‰jeD‰uh}”(jjDhØjƒjºjòj‰j÷jøjo jýjÌ ju jÛ jÒ jjá jÈj…j3jÎjÃj9j{jYj½j�jôjÃjjújDj"jljJj”jrj¼jšjÑjÚjÅjÊjbjgj]jbj¥jªja jf j$j#$jº%j¿%j`)je)jÂ,jÇ,jX1j]1jv7j{7jù;jþ;j&@j+@jbDjàCuŒ footnote_refs”}”Œ citation_refs”}”Œ autofootnotes”]”Œautofootnote_refs”]”Œsymbol_footnotes”]”Œsymbol_footnote_refs”]”Œ footnotes”]”Œ citations”]”Œautofootnote_start”KŒsymbol_footnote_start”KŒ id_counter”Œ collections”ŒCounter”“”}”…”R”Œparse_messages”]”Œtransform_messages”]”Œ transformer”NŒ include_log”]”Œ decoration”Nh²hub.