From nobody Sat Jul 25 04:54:17 2026 Received: from mail-yx1-f47.google.com (mail-yx1-f47.google.com [74.125.224.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 808883D955B for ; Fri, 17 Jul 2026 22:03:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.224.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784325814; cv=none; b=j+zlf0TOgAWNhaN+pEwTkxOxN70zExKF5+v0H87PirKWljYEJnXMgXnZakToOclKfMRLj7TgopWoAHi9x8sLJZIWBMnVHmhLnoEl1IS6sBnVpGrRQECnBIuKNZHaUI+5QHlKbRB0+kuaL3+upkmGyhyWCju7BrN8obiRs6VSfJM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784325814; c=relaxed/simple; bh=Tr06TgVRa+MWduu5HOXY/09bGtYQpJWzDpIVVe7QQeQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=LEkZTP9X/6E0QOekJdbma9nPA49vZFsgSZ6NuCan5jbMWcT+w0hw3b5NMZQ3tkrT4jLf0PAx0f0hzZq+J8QNhOLvQkwMg3XVNPqCLgyEYBt7mNkCZQTt+nxgK1BCkIpLqyC+rjcJLTBrsW1GcGb+WUjrbOA1x+9TfDU0RDCOPCM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=RxLL4M3u; arc=none smtp.client-ip=74.125.224.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="RxLL4M3u" Received: by mail-yx1-f47.google.com with SMTP id 956f58d0204a3-66826484b67so3209617d50.1 for ; Fri, 17 Jul 2026 15:03:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784325811; x=1784930611; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=Zm+0aM2mDwgivCRHDxKtZ8YT8LqEvq7lvhw4cFbQwWA=; b=RxLL4M3uHQ2Rwux2EmIT0ioElPCFQ4UljaXR5/Ad7uiCxe0HDhxt0KxrYXf6kQiQmc AiNag2rcNQlo3Y104JAQOgl+B4vMr2PJRWN2vdT3bw0zf0F3qcD22UeX121oGcIWt7JR 0OyPW2hG6OPxX/qcouIB8j7s7BBP6lGQTrTXw1izy2rFudFROFtS3kFCCeHGJ+ZiXWLd 4yDVNK63qxFxNv0/BjWMzR9DDS7X1BZqeHYrc9G3vKphdcSXUQW4V0zQ5iZWCoDfKxNU 9ljQnNjQjm8qn88pkJHsWrH9JptlJJHiIEwrtoqUkeigxI6C+pPE9cjcmzfkjOT5EBoP LnNA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784325811; x=1784930611; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Zm+0aM2mDwgivCRHDxKtZ8YT8LqEvq7lvhw4cFbQwWA=; b=cN+9AQTuuDNMTqlzRlPhjq5D5hbRtrKX37TaEkTPdg+rlQEUaR6KNUfo3xWd1dinID PrUhLcSvk1cEnIR3eQKH1ydautAipKzYMlmjWxCa/roqcud4a147pN9mQrMW3yZyHiHJ 06meIV+GSKejxSLtn9MaUwAoRQ+bnPQI6v9uaHD+nWgWHaQX8zpIvI/WTwUfWOwPBx4h 3jA0fD7ovvFkm5vFjHCUFlJxt4t2/Nuqb7ljMXLy8N0d+mcHW6Ad/6yJHElHJ0SCPr4f xoqXdxdciNMNz7gSa4H5IAug2b7Yb+wHYh/+Tqs8/uXPXm8B4Tc+3nHjZu8QJ2b+WHLG hdbw== X-Gm-Message-State: AOJu0YwrIpFZf8H6KaFiXAQWOE5Gcw6SvBhZVuf2zfCJrT+AP699FILO wORZxXfebsfeO4U+BHgZbkgGJeI3aE/U/D3n80Jp5JV8S7cS246YDvAs X-Gm-Gg: AfdE7cm71ZxD2xG+L2q0swNs8btJyZNqxloMtKoyPI+v0Oqov/Mo+HUBMQgHb7PNnp8 /dCzGaXpeTFnyPqyd1a9R2yb+7toNg25UJTBJ3Idl0DkBReI/q/LIroBk6y1P+K5jFYrGemxg/j sjAY85q4dh3V70uy3iVDzJVT6qnOwD+PxKBxAzMX16m8aqZbvEvhhKJiH5bM+RHzKmuDEEoy5Ce SpbxbR84FYJej+ASYxLtgQHRacZRADHax/SJfs6xdLtAX3H3/ndWLkgTqvQ3h+pKEETG9/hJXEM E1EsN9FFebg4NfDZTuPktwme+eXC00+5iuuJah5ZMXV60N4cAA4XdEh1LiXqEtzt9kczr2SC4Pr G3ryY6TWoLdgwSzhpy+CsqNN7Ll9jbIHIEdbDeqeYqIzP9raM23GOfWDpO19240zAVnudaNH3Nq g7zZdyEC23dHguFEetv7aapemJWL521kIMqI8= X-Received: by 2002:a53:e035:0:b0:667:e9e1:f971 with SMTP id 956f58d0204a3-6683bb257e8mr1061106d50.4.1784325811088; Fri, 17 Jul 2026 15:03:31 -0700 (PDT) Received: from zenbox ([2600:1700:18fb:6011:ee56:9b10:53f4:188]) by smtp.gmail.com with ESMTPSA id 00721157ae682-81ef401728asm20572037b3.9.2026.07.17.15.03.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 15:03:30 -0700 (PDT) From: Justin Suess To: gnoack3000@gmail.com, mic@digikod.net Cc: linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, Justin Suess Subject: [PATCH v2 1/3] landlock: Add LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS Date: Fri, 17 Jul 2026 18:03:17 -0400 Message-ID: <20260717220320.1030123-2-utilityemal77@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260717220320.1030123-1-utilityemal77@gmail.com> References: <20260717220320.1030123-1-utilityemal77@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Add a landlock_restrict_self(2) flag to set the no_new_privs attribute of the calling thread atomically with the enforcement of the ruleset: no_new_privs is set if and only if the call succeeds. This removes the need for a prior prctl(2) PR_SET_NO_NEW_PRIVS call and guarantees that a failed enforcement leaves the attribute unchanged. Because no_new_privs is set by the call itself, the no_new_privs / CAP_SYS_ADMIN requirement of landlock_restrict_self(2) is fulfilled by construction, and the related EPERM check is skipped. As a consequence, an unprivileged caller passing unknown flags along with this flag gets EINVAL instead of EPERM. The attribute is only set past the last point of failure, just before committing the new credentials. When combined with LANDLOCK_RESTRICT_SELF_TSYNC, no_new_privs is set on the sibling threads as well, in their commit phase, with the same atomicity. Bump the Landlock ABI version to 11. Cc: Micka=C3=ABl Sala=C3=BCn Signed-off-by: Justin Suess --- include/uapi/linux/landlock.h | 13 +++++++++++++ security/landlock/limits.h | 2 +- security/landlock/syscalls.c | 28 +++++++++++++++++++++------- security/landlock/tsync.c | 8 ++++++-- security/landlock/tsync.h | 4 +++- 5 files changed, 44 insertions(+), 11 deletions(-) diff --git a/include/uapi/linux/landlock.h b/include/uapi/linux/landlock.h index 272f047df438..77820e430ab8 100644 --- a/include/uapi/linux/landlock.h +++ b/include/uapi/linux/landlock.h @@ -191,12 +191,25 @@ struct landlock_ruleset_attr { * * If the calling thread is running with no_new_privs, this operation * enables no_new_privs on the sibling threads as well. + * + * The following flag ties the no_new_privs attribute to the ruleset + * enforcement: + * + * %LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS + * Sets the no_new_privs attribute of the calling thread atomically wi= th + * the enforcement of the ruleset: no_new_privs is set if and only if + * sys_landlock_restrict_self() succeeds. This removes the need for a + * prior :manpage:`prctl(2)` ``PR_SET_NO_NEW_PRIVS`` call, and with it= the + * %CAP_SYS_ADMIN requirement. This flag requires a ruleset. When + * combined with %LANDLOCK_RESTRICT_SELF_TSYNC, no_new_privs is set on= the + * sibling threads as well. */ /* clang-format off */ #define LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF (1U << 0) #define LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON (1U << 1) #define LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF (1U << 2) #define LANDLOCK_RESTRICT_SELF_TSYNC (1U << 3) +#define LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS (1U << 4) /* clang-format on */ =20 /** diff --git a/security/landlock/limits.h b/security/landlock/limits.h index 08d5f2f6d321..1a7c5fb8f6fd 100644 --- a/security/landlock/limits.h +++ b/security/landlock/limits.h @@ -34,7 +34,7 @@ #define LANDLOCK_NUM_ACCESS_MAX \ MAX(MAX(LANDLOCK_NUM_ACCESS_FS, LANDLOCK_NUM_ACCESS_NET), LANDLOCK_NUM_SC= OPE) =20 -#define LANDLOCK_LAST_RESTRICT_SELF LANDLOCK_RESTRICT_SELF_TSYNC +#define LANDLOCK_LAST_RESTRICT_SELF LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS #define LANDLOCK_MASK_RESTRICT_SELF ((LANDLOCK_LAST_RESTRICT_SELF << 1) - = 1) =20 /* clang-format on */ diff --git a/security/landlock/syscalls.c b/security/landlock/syscalls.c index 36b02892c62f..36b8a3fb506f 100644 --- a/security/landlock/syscalls.c +++ b/security/landlock/syscalls.c @@ -169,7 +169,7 @@ static const struct file_operations ruleset_fops =3D { * If the change involves a fix that requires userspace awareness, also up= date * the errata documentation in Documentation/userspace-api/landlock.rst . */ -const int landlock_abi_version =3D 10; +const int landlock_abi_version =3D 11; =20 /** * sys_landlock_create_ruleset - Create a new ruleset @@ -502,21 +502,28 @@ SYSCALL_DEFINE4(landlock_add_rule, const int, ruleset= _fd, * - %LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON * - %LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF * - %LANDLOCK_RESTRICT_SELF_TSYNC + * - %LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS * * This system call enforces a Landlock ruleset on the current thread. * Enforcing a ruleset requires that the task has %CAP_SYS_ADMIN in its * namespace or is running with no_new_privs. This avoids scenarios where * unprivileged tasks can affect the behavior of privileged children. * + * With %LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS, the no_new_privs attribute o= f the + * calling thread is set atomically with the enforcement of the ruleset, w= hich + * fulfills the above requirement: no_new_privs is set if and only if the = call + * succeeds. + * * Return: 0 on success, or -errno on failure. Possible returned errors a= re: * * - %EOPNOTSUPP: Landlock is supported by the kernel but disabled at boot= time; * - %EINVAL: @flags contains an unknown bit. * - %EBADF: @ruleset_fd is not a file descriptor for the current thread; * - %EBADFD: @ruleset_fd is not a ruleset file descriptor; - * - %EPERM: @ruleset_fd has no read access to the underlying ruleset, or = the - * current thread is not running with no_new_privs, or it doesn't have - * %CAP_SYS_ADMIN in its namespace. + * - %EPERM: @ruleset_fd has no read access to the underlying ruleset, or + * %LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS is not set while the current thr= ead + * is not running with no_new_privs and doesn't have %CAP_SYS_ADMIN in i= ts + * namespace. * - %E2BIG: The maximum number of stacked rulesets is reached for the cur= rent * thread. * @@ -529,6 +536,8 @@ SYSCALL_DEFINE2(landlock_restrict_self, const int, rule= set_fd, const __u32, struct landlock_ruleset *ruleset __free(landlock_put_ruleset) =3D NULL; struct cred *new_cred; struct landlock_cred_security *new_llcred; + const bool set_no_new_privs =3D + !!(flags & LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS); bool __maybe_unused log_same_exec, log_new_exec, log_subdomains, prev_log_subdomains; =20 @@ -537,9 +546,10 @@ SYSCALL_DEFINE2(landlock_restrict_self, const int, rul= eset_fd, const __u32, =20 /* * Similar checks as for seccomp(2), except that an -EPERM may be - * returned. + * returned. LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS fulfills this + * requirement. */ - if (!task_no_new_privs(current) && + if (!set_no_new_privs && !task_no_new_privs(current) && !ns_capable_noaudit(current_user_ns(), CAP_SYS_ADMIN)) return -EPERM; =20 @@ -620,12 +630,16 @@ SYSCALL_DEFINE2(landlock_restrict_self, const int, ru= leset_fd, const __u32, =20 if (flags & LANDLOCK_RESTRICT_SELF_TSYNC) { const int err =3D landlock_restrict_sibling_threads( - current_cred(), new_cred); + current_cred(), new_cred, flags); if (err) { abort_creds(new_cred); return err; } } =20 + /* Sets no_new_privs past the last point of failure. */ + if (set_no_new_privs) + task_set_no_new_privs(current); + return commit_creds(new_cred); } diff --git a/security/landlock/tsync.c b/security/landlock/tsync.c index c5730bbd9ed3..0b71e158c3f5 100644 --- a/security/landlock/tsync.c +++ b/security/landlock/tsync.c @@ -17,6 +17,7 @@ #include #include #include +#include =20 #include "cred.h" #include "tsync.h" @@ -466,7 +467,8 @@ static void cancel_tsync_works(const struct tsync_works= *works, * restrict_sibling_threads - enables a Landlock policy for all sibling th= reads */ int landlock_restrict_sibling_threads(const struct cred *old_cred, - const struct cred *new_cred) + const struct cred *new_cred, + const u32 restrict_flags) { int err; struct tsync_shared_context shared_ctx; @@ -481,7 +483,9 @@ int landlock_restrict_sibling_threads(const struct cred= *old_cred, init_completion(&shared_ctx.all_finished); shared_ctx.old_cred =3D old_cred; shared_ctx.new_cred =3D new_cred; - shared_ctx.set_no_new_privs =3D task_no_new_privs(current); + shared_ctx.set_no_new_privs =3D + (restrict_flags & LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS) || + task_no_new_privs(current); =20 /* * Serialize concurrent TSYNC operations to prevent deadlocks when diff --git a/security/landlock/tsync.h b/security/landlock/tsync.h index ef86bb61c2f6..2ae4f938ca00 100644 --- a/security/landlock/tsync.h +++ b/security/landlock/tsync.h @@ -9,8 +9,10 @@ #define _SECURITY_LANDLOCK_TSYNC_H =20 #include +#include =20 int landlock_restrict_sibling_threads(const struct cred *old_cred, - const struct cred *new_cred); + const struct cred *new_cred, + u32 restrict_flags); =20 #endif /* _SECURITY_LANDLOCK_TSYNC_H */ --=20 2.54.0 From nobody Sat Jul 25 04:54:17 2026 Received: from mail-yw1-f175.google.com (mail-yw1-f175.google.com [209.85.128.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F3F673BE15F for ; Fri, 17 Jul 2026 22:03:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784325815; cv=none; b=jxZw0EtRexfKduyd4NsRtm/Ke+Ds7tSeDn2spLC1GKBHPmfGriZiBco8fhtRsJy+UvxbfyyBXL+Gafsp54j/rd858gAEB2eU5+Wo1blpJGnEHHBPrwc8v6HI2GdiwVSGJaeLWvTEEQJboXJr+cx6tlLk177duXg79L09SB5kvLU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784325815; c=relaxed/simple; bh=m4Jclk5YNxQi2TwcRbnqEtYX1BSm+HxO+6jHh+k55kI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=riSUOje44aBOsWVaFEbsyt7JcfTwmX78xE8cOXPa0cRB/ER6QcH6VX9KHetjqaCtzA4QGbFHw2HGsbAyQQyizUZFpwiw8O9PbhiCgNsGBsWFsFvUOE2DwDtO41gDLaq58WhGBSGeZ3ikmMfNqToyvRNRJPoPDoO3Qyf8uI+GRB0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=T3Scat0F; arc=none smtp.client-ip=209.85.128.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="T3Scat0F" Received: by mail-yw1-f175.google.com with SMTP id 00721157ae682-81e9d8f3289so62017427b3.1 for ; Fri, 17 Jul 2026 15:03:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784325813; x=1784930613; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ama0SVn97k9iAkAOQhRx4hyF+HPcsesIUw/q/aLtCKc=; b=T3Scat0F/iQVnQOFAwpJlHVZqMEsf1nndbhQt44fg6TARJaOyxEFMAPYv4tlVGAD0R 1rXfH6gFy+nrTrobHjdoFPueE7m+Mk3NPh30RkE3p3EsdshM1yY6SdZ03pm7ereEsTy1 CAFGrvrqN8DxcR0uar1g+i6fAxHnWKEVWFQmKDBO84bh21QyoPs4bGNmKThkK9mRq6fd 0dyTNEsF3CVh+O9nFRF0hXDlFs6+CWRWKc12VtnD0iNN6kS+bzUfNl0dB8bDxATRVcPV AalnWW8+DRrHdTiGjy1gMgpZURLWwGH1FCcXs8ZvXVCz4W1DbVgYPAAXUoIuRLtsWTKs huMg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784325813; x=1784930613; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ama0SVn97k9iAkAOQhRx4hyF+HPcsesIUw/q/aLtCKc=; b=XS7kUJ97Pn/cFYrOCRfhXBe0u0Jxpiez817X35Oi5LU/QmuISRoTIoQsUi0Wi8p8oL qEBRQBKkAcv2Eq1xlCN+jiU5w4jdkP8fYHYlMzFeAKNAYC2SeJy4dd44UqEM/xXdyX65 0pMiWg973CRUUcYyc3LRirWtm6EgyPN0Sma9WGODOcjxi8a0LkHBxO1vAxmKBVEuyhXS bDiq1F9KYSfUEQlN/e+lK8lhpbVgmdgXuEnBmzqofuoNxJdl8bXj3G01RU/nN43yYqfr FO+fmStQ1escLL7AquKh0vnrd3oV/efk9NqDIGapsb4LsklQznef5sQZTCGWkPQcjI2y Wx4A== X-Gm-Message-State: AOJu0YxoDWzS4LB5rbyAvPTd/LHdE3KaDW0LB44YEKJbkGZaXU77OxPV ia2QY5kXf08hHtXwrdI8J6aFh02UJOVR4axkKYh2IvAoLGyAbkhCfe1W X-Gm-Gg: AfdE7cmRrasg61p8nl7qlv1xFSMov0niVic3KRrpEpXULwtYP2u0n2vg8sHd/JYoils BcqGdAcK4I3M2vS5tp9KJ3TEfiXCIZt4PfKmQ2aUC7vRTLXF4YGaJvuCDXpuAoHgIv27p3zjEtI i1XzQSJeDZYvtvJKh52RqtPvqxxp+TL+tyn1kRFVoifpOpoMCnnjNHnlH4ZdnqrxCfAj7ob0Qa8 EuWbUzsolhnGO0qS4Kx9a/qs7/zbIyF9bWbpvdvysr06RUOisk1xxjJ86wiY3x7TUBSqH4XeeI8 emu8qc76eTR42JyC9ZRvgahTq6WJDM3BWd7HJz5z9GPyJW+15ZAtYQZ8GoUsWMmQKL1DHIUPLCt gC4eE1XUbEH+ccrikzwOlGfbIUDkk7lGSC3maJU534Nr9Un1J+4MhOqIALIQ74kB30A3ucIGg8X 4AggW9haWk9ZlS2LiYJG3hwSXlYCXjTwjkAvY= X-Received: by 2002:a05:690c:e:b0:81e:3e2c:6fea with SMTP id 00721157ae682-81ef2697592mr15117697b3.70.1784325812642; Fri, 17 Jul 2026 15:03:32 -0700 (PDT) Received: from zenbox ([2600:1700:18fb:6011:ee56:9b10:53f4:188]) by smtp.gmail.com with ESMTPSA id 00721157ae682-81ef401728asm20572037b3.9.2026.07.17.15.03.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 15:03:32 -0700 (PDT) From: Justin Suess To: gnoack3000@gmail.com, mic@digikod.net Cc: linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, Justin Suess Subject: [PATCH v2 2/3] selftests/landlock: Test LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS Date: Fri, 17 Jul 2026 18:03:18 -0400 Message-ID: <20260717220320.1030123-3-utilityemal77@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260717220320.1030123-1-utilityemal77@gmail.com> References: <20260717220320.1030123-1-utilityemal77@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Check that a successful landlock_restrict_self(2) call with LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS sets no_new_privs without a prior prctl(2) call nor CAP_SYS_ADMIN, that a failed call leaves the attribute unchanged, and that LANDLOCK_RESTRICT_SELF_TSYNC extends it to sibling threads. Also check that this flag requires a ruleset, and update the restrict_self_checks_ordering EPERM checks since this flag is now checked before the flags validity. Update the ABI version and last-flag checks accordingly. Signed-off-by: Justin Suess --- tools/testing/selftests/landlock/base_test.c | 65 +++++++++++++++++-- tools/testing/selftests/landlock/tsync_test.c | 33 ++++++++++ 2 files changed, 93 insertions(+), 5 deletions(-) diff --git a/tools/testing/selftests/landlock/base_test.c b/tools/testing/s= elftests/landlock/base_test.c index cbd3c1669951..2d4903588903 100644 --- a/tools/testing/selftests/landlock/base_test.c +++ b/tools/testing/selftests/landlock/base_test.c @@ -76,7 +76,7 @@ TEST(abi_version) const struct landlock_ruleset_attr ruleset_attr =3D { .handled_access_fs =3D LANDLOCK_ACCESS_FS_READ_FILE, }; - ASSERT_EQ(10, landlock_create_ruleset(NULL, 0, + ASSERT_EQ(11, landlock_create_ruleset(NULL, 0, LANDLOCK_CREATE_RULESET_VERSION)); =20 ASSERT_EQ(-1, landlock_create_ruleset(&ruleset_attr, 0, @@ -255,8 +255,15 @@ TEST(restrict_self_checks_ordering) =20 /* Checks unprivileged enforcement without no_new_privs. */ drop_caps(_metadata); - ASSERT_EQ(-1, landlock_restrict_self(-1, -1)); + ASSERT_EQ(-1, landlock_restrict_self( + -1, ~LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS)); ASSERT_EQ(EPERM, errno); + /* + * LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS fulfills the no_new_privs / + * CAP_SYS_ADMIN requirement, so the invalid flags are checked first. + */ + ASSERT_EQ(-1, landlock_restrict_self(-1, -1)); + ASSERT_EQ(EINVAL, errno); ASSERT_EQ(-1, landlock_restrict_self(-1, 0)); ASSERT_EQ(EPERM, errno); ASSERT_EQ(-1, landlock_restrict_self(ruleset_fd, 0)); @@ -288,7 +295,7 @@ TEST(restrict_self_fd) EXPECT_EQ(EBADFD, errno); } =20 -TEST(restrict_self_fd_logging_flags) +TEST(restrict_self_fd_flags) { int fd; =20 @@ -302,11 +309,16 @@ TEST(restrict_self_fd_logging_flags) EXPECT_EQ(-1, landlock_restrict_self( fd, LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF)); EXPECT_EQ(EBADFD, errno); + + /* LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS requires a ruleset FD. */ + EXPECT_EQ(-1, landlock_restrict_self( + fd, LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS)); + EXPECT_EQ(EBADFD, errno); } =20 -TEST(restrict_self_logging_flags) +TEST(restrict_self_flags) { - const __u32 last_flag =3D LANDLOCK_RESTRICT_SELF_TSYNC; + const __u32 last_flag =3D LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS; =20 /* Tests invalid flag combinations. */ =20 @@ -349,6 +361,18 @@ TEST(restrict_self_logging_flags) LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON)); EXPECT_EQ(EBADF, errno); =20 + /* LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS requires a ruleset FD. */ + + EXPECT_EQ(-1, landlock_restrict_self( + -1, LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS)); + EXPECT_EQ(EBADF, errno); + + EXPECT_EQ(-1, + landlock_restrict_self( + -1, LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF | + LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS)); + EXPECT_EQ(EBADF, errno); + /* Tests with an invalid ruleset_fd. */ =20 EXPECT_EQ(-1, landlock_restrict_self( @@ -359,6 +383,37 @@ TEST(restrict_self_logging_flags) -1, LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF)); } =20 +TEST(restrict_self_no_new_privs) +{ + const struct landlock_ruleset_attr ruleset_attr =3D { + .handled_access_fs =3D LANDLOCK_ACCESS_FS_READ_FILE, + }; + const int ruleset_fd =3D + landlock_create_ruleset(&ruleset_attr, sizeof(ruleset_attr), 0); + + ASSERT_LE(0, ruleset_fd); + + /* + * The calling thread does not need CAP_SYS_ADMIN nor an explicit + * prctl(2) PR_SET_NO_NEW_PRIVS call. + */ + drop_caps(_metadata); + ASSERT_EQ(0, prctl(PR_GET_NO_NEW_PRIVS, 0, 0, 0, 0)); + + /* Checks that a failed call does not set no_new_privs. */ + EXPECT_EQ(-1, landlock_restrict_self( + -1, LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS)); + EXPECT_EQ(EBADF, errno); + EXPECT_EQ(0, prctl(PR_GET_NO_NEW_PRIVS, 0, 0, 0, 0)); + + /* Checks that a successful call sets no_new_privs. */ + ASSERT_EQ(0, landlock_restrict_self( + ruleset_fd, LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS)); + EXPECT_EQ(1, prctl(PR_GET_NO_NEW_PRIVS, 0, 0, 0, 0)); + + EXPECT_EQ(0, close(ruleset_fd)); +} + TEST(ruleset_fd_io) { struct landlock_ruleset_attr ruleset_attr =3D { diff --git a/tools/testing/selftests/landlock/tsync_test.c b/tools/testing/= selftests/landlock/tsync_test.c index 9cf1491bbaaf..d5336186b2c7 100644 --- a/tools/testing/selftests/landlock/tsync_test.c +++ b/tools/testing/selftests/landlock/tsync_test.c @@ -90,6 +90,39 @@ TEST(multi_threaded_success) EXPECT_EQ(0, close(ruleset_fd)); } =20 +TEST(multi_threaded_no_new_privs) +{ + pthread_t t1, t2; + bool no_new_privs1, no_new_privs2; + const int ruleset_fd =3D create_ruleset(_metadata); + + disable_caps(_metadata); + + ASSERT_EQ(0, pthread_create(&t1, NULL, idle, &no_new_privs1)); + ASSERT_EQ(0, pthread_create(&t2, NULL, idle, &no_new_privs2)); + + /* No prior prctl(2) PR_SET_NO_NEW_PRIVS call. */ + ASSERT_EQ(0, prctl(PR_GET_NO_NEW_PRIVS, 0, 0, 0, 0)); + + EXPECT_EQ(0, landlock_restrict_self( + ruleset_fd, + LANDLOCK_RESTRICT_SELF_TSYNC | + LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS)); + + EXPECT_EQ(1, prctl(PR_GET_NO_NEW_PRIVS, 0, 0, 0, 0)); + + ASSERT_EQ(0, pthread_cancel(t1)); + ASSERT_EQ(0, pthread_cancel(t2)); + ASSERT_EQ(0, pthread_join(t1, NULL)); + ASSERT_EQ(0, pthread_join(t2, NULL)); + + /* The no_new_privs flag was enabled on all threads. */ + EXPECT_TRUE(no_new_privs1); + EXPECT_TRUE(no_new_privs2); + + EXPECT_EQ(0, close(ruleset_fd)); +} + TEST(multi_threaded_success_despite_diverging_domains) { pthread_t t1, t2; --=20 2.54.0 From nobody Sat Jul 25 04:54:17 2026 Received: from mail-yw1-f181.google.com (mail-yw1-f181.google.com [209.85.128.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 901F33DB658 for ; Fri, 17 Jul 2026 22:03:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.181 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784325820; cv=none; b=UxnCJsR+G0KegKlQsIUwWITTTJg0VRHbAy8dBTMKb7AheDRwr0O3cHHDPHRMNhaFuNAblp6SNV4GFMzZ57xTM3EZs/DirXvTklVPjrqGUAZ8ggWYlY9pOsjynMktwWBCaizmyeCW+hBTNM5J6GM4wRQmiEnfLLvGXRnKT5IH9vI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784325820; c=relaxed/simple; bh=3poomQvjnpiX7997GNYVbUJUsBdzosz9y/dadMphQQo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=fotl1/nL1c0nDbgBxXEgtikK8bt+hqw6wLetKz4qX2h5hc/Lw9idZZ6htAPV23yzXOloxrthphWIlhTkHLammMBPZpoDHMxZzWadqtFeXyzpMbIWLJRizmpfwS7gmua/poy29ekk0EFPtu4I4AgLPXWlJl0UqTr6uW0RcvSWvPw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=HVx/MtE2; arc=none smtp.client-ip=209.85.128.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="HVx/MtE2" Received: by mail-yw1-f181.google.com with SMTP id 00721157ae682-81ec29f1d07so58011657b3.1 for ; Fri, 17 Jul 2026 15:03:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784325814; x=1784930614; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=BotXlHoC1KXrTMIu+7NHh3EH2wogMGqSsV6pAxUtFzQ=; b=HVx/MtE25U9X189aYcv5jTdse8mjs3Uz3YbACwtNP9btF6bvtaWuhSWmr9BxzgapTV uwcadxtnCxcqufQpQ+EhnVEneB75WzS9lkWCfeB/7m5LeNPsKMOoX5PlRkaBYILTnSlL +sfJdEKRj5ii1jB9N721EWVop56hbn0fyrq/Skk3t0x28H1uQMvXs7RLmxH1Z2+j3z+4 P1UctmWW+IghtrL8aH36xtG1+WwrGDOtWkNP5G/Ja8C1BPckO7MrT0tSyZfPEe3VXdyR pL3O1IP/I+nGPT9y5NEYlBUqh4W0x2nVUdSCSEAs4SqXDYTCXI6e2ufMJUsfHHBN1ZQp FOJQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784325814; x=1784930614; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=BotXlHoC1KXrTMIu+7NHh3EH2wogMGqSsV6pAxUtFzQ=; b=icb8PlzB+lw5syFdjznrMkNM71e67epuw+nrr/98aetMDEnu7X2lxX/Equr1ADcxL6 tDOykM1RY5V6o9vUtlUSNOJhRda+mPc9V4P8l6roL6kpr9AZqi4YKInaHYfM9Why8u3D VWepU8KGBuDBFGFpDTyRYfMWvUQTFGatOjG5cmxyvt3ccA04oUmaqjwZpVDYM4LfQPRY jOw/Fkm1VxJ9v7Y0kVO8G+0tltc0MiGh3rtzbkhTh6SzFmJ+Q//hXUDXNHU2iMDbhxHw yycVmQ5mDszaNKtnhGWzuDKqrwPBH5rKP1JiMfXya9osje00J1u170Ipa3jM/vUw38N3 yWyg== X-Gm-Message-State: AOJu0YyuvpCulMuB02GpabYRzfSgcuxjs3VGSXCrOzkV78+DgPTzjTlN PWLRaHO4GKyCV2G1qMCR2imp0i/MXjIsdmec3a6suB34enU/gcGMKI5HxP4ZD74B X-Gm-Gg: AfdE7ckfoqj/CgAvwnw+qsVs+dMBBpJnxa+1ZOod8SQXHmT9VZbX+U4kWpHbSOnLkOo AhvY9ornvYACujGqUKzIZxRe7XfFuR/ua7FHOVZIB6NBPtbdBFx51meJCmKxqrLaHA67N8yutlC 8Vp3YAwjS+/rxkw5ApttwV0OXl479U6QptUn+oVdkxysk+plCVda6XlE4OMnCibgU2zb08tKNwA P40F1wehuyu2y2O/7jrNPtwsRy9iF9g7sb8JCeK+NZdy4+GVqkPcCg0I2JLsGJ/+E6n/6Na3pxQ VHrRohTW7l0wrOC2ffGB6Z6WQsOqS3Xi2ne4XTUvDUTjr8plIQvi0zSjYQ549Sa5uZ58wCWAUgm KPfkYjeqdtBIhsDQs6R/UiDLsGuaxCrE/sEniOcK3wjY336gaoL8QFrmBWccfmru4AHcBNCodzT av61N2w2+VQ0yEHa+Thm3Kd/lG+0kuV9qZcoY= X-Received: by 2002:a05:690c:690b:b0:81e:ad1:8e5b with SMTP id 00721157ae682-81ef26a5cefmr15353267b3.33.1784325814348; Fri, 17 Jul 2026 15:03:34 -0700 (PDT) Received: from zenbox ([2600:1700:18fb:6011:ee56:9b10:53f4:188]) by smtp.gmail.com with ESMTPSA id 00721157ae682-81ef401728asm20572037b3.9.2026.07.17.15.03.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 17 Jul 2026 15:03:33 -0700 (PDT) From: Justin Suess To: gnoack3000@gmail.com, mic@digikod.net Cc: linux-kernel@vger.kernel.org, linux-security-module@vger.kernel.org, Justin Suess Subject: [PATCH v2 3/3] landlock: Document LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS Date: Fri, 17 Jul 2026 18:03:19 -0400 Message-ID: <20260717220320.1030123-4-utilityemal77@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260717220320.1030123-1-utilityemal77@gmail.com> References: <20260717220320.1030123-1-utilityemal77@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Document atomically setting no_new_privs with ruleset enforcement, following the same compatibility section style as previous ABI additions. Signed-off-by: Justin Suess --- Documentation/userspace-api/landlock.rst | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/Documentation/userspace-api/landlock.rst b/Documentation/users= pace-api/landlock.rst index 5a63d4476c1c..ec87d35f4715 100644 --- a/Documentation/userspace-api/landlock.rst +++ b/Documentation/userspace-api/landlock.rst @@ -8,7 +8,7 @@ Landlock: unprivileged access control =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =20 :Author: Micka=C3=ABl Sala=C3=BCn -:Date: June 2026 +:Date: July 2026 =20 The goal of Landlock is to enable restriction of ambient rights (e.g. glob= al filesystem or network access) for a set of processes. Because Landlock @@ -789,6 +789,18 @@ when at least one sys_landlock_add_rule() call is made= for it with the ``LANDLOCK_ADD_RULE_QUIET`` flag, additional add-rule calls for the same object without this flag do not clear it. =20 +Atomic no_new_privs (ABI < 11) +------------------------------ + +Starting with the Landlock ABI version 11, sys_landlock_restrict_self() +accepts the ``LANDLOCK_RESTRICT_SELF_NO_NEW_PRIVS`` flag, which sets the +no_new_privs attribute of the calling thread atomically with the enforceme= nt +of the ruleset: no_new_privs is set if and only if the call succeeds. This +removes the need for a prior :manpage:`prctl(2)` ``PR_SET_NO_NEW_PRIVS`` +call, and with it the ``CAP_SYS_ADMIN`` requirement. When combined with +``LANDLOCK_RESTRICT_SELF_TSYNC``, no_new_privs is set on all threads of the +process. + .. _kernel_support: =20 Kernel support --=20 2.54.0