From nobody Fri Jul 24 22:59:13 2026 Received: from mail-ej1-f54.google.com (mail-ej1-f54.google.com [209.85.218.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ADE4C1A9F8C for ; Wed, 22 Jul 2026 12:30:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.54 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723404; cv=none; b=bIe+le2XeKqE3x6PD0FB3e8PHPCAfyna7UnahNSve+AofJIVPnV4OdXlb4PUwXquRBi8IdGH3BAOicjw0pUDRFeUsA3bWv2X9L5cBv1Gl7YXGc5E70B0uQnvWM2KcpEKY7yl8xEKJcepNsylvTvb7g+64y59QYYJoeuar5NITkY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723404; c=relaxed/simple; bh=DcewT6Rnluc335PT2aXE0Wv72BuQ8CQjZHSyv3sDep0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=uc5Z8TOnEf6m4q/VTRhiaJxKlCSt0nOYDjaAHPHzkcES8v0YzQtB934hlMRB/5im0REnBYcuYLNqi8RzMLXXlGx4ZClv2F32jgm/bpQVlH7XjWoPRjXD6KEteSWmI/MPGM5uTADys9fNrYeah3+EnPrdLu0dfRtA977MiAhKYwQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com; spf=pass smtp.mailfrom=cloudflare.com; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b=F4HhKkxu; arc=none smtp.client-ip=209.85.218.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b="F4HhKkxu" Received: by mail-ej1-f54.google.com with SMTP id a640c23a62f3a-c15cd3fd760so1406173366b.2 for ; Wed, 22 Jul 2026 05:30:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google09082023; t=1784723401; x=1785328201; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=XlYJYH6aD7SifBzyICcO1b3gqicM14HLRDoAfRS7bAs=; b=F4HhKkxubrP5IfYypdUWulBrpxiwND9O+XC6dPY3X1iBohJwthRsoLmHWGKC/caKax jArbpVqhc5TTV1Cn/wFSQKmcTYYUd+qt4NcWD9B/U+TRav1vRXGHq+LKzILUpHLD9bIa Z/DrURuJuA2g5gCU2u3WVCuCRFqABc8RHQaCrenh58RCum/iilCcfZYoselnrURYmVSp nob2Pt+9NmJZnqZPQqZ8EHsmvMxMGNh1xb77sXMnk6uYp2dHDCTxbmqVzDHLQsGGGNy6 Rzaj9QQXuEwrIEQSqlMSdk4zBv3bfH/3MykqmZLsbocZG0K+p4lAJhydsiBDpfOz0vmE jsyg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723401; x=1785328201; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=XlYJYH6aD7SifBzyICcO1b3gqicM14HLRDoAfRS7bAs=; b=XXFKbwopt0h6xAaEgB1HjC7mAXcFPepiAs+8V9koiTMZ92fcIRls/3F9t6Tt+S/z53 1EChpHA4d9Y+vGsOeOilW+gNWb++aY0PiyoOJtub0sQTZSudP0ZSl3n6dgbGSEUxFlt9 Pc/SoZF8b3QhsujlkloUFTKGa3uc+3xVLo7P8YNwj443GKLjzX5WCOiMuruqicAMnqXz nqxz3a6nlgBba7YqCuAiqrMmf+0I4SI3OSy6MVoVQE/Q7xVSL6h4H732+NcIUSgtw7oI kt2GWTZlltwIP1N624wiT9ZzTEZ5HpCOrg9UdRjWh91p2E3OE+Ap2qC42UCuH53fmYUw SKYg== X-Forwarded-Encrypted: i=1; AHgh+Rpj1Pg7iTz47FcRWkXDEUCwEiH2WekSdtZwak+5OKxnDbv5sn9kz9fY5jHH/QdFBMd1La6C+xLNSazRR6I=@vger.kernel.org X-Gm-Message-State: AOJu0YwlN8gGQDHlklCItJU/TyjLdFdAdKPLyHhinZsvJzBUdxGjGsD5 QB0JTW8FCJE5HXFdAAp/mHQSIE/2VCVPEHCRIT6R7ffbhxwFajqQ35jBr4aLeQ9Et8E= X-Gm-Gg: AR+sD11V7EWmA5PNKkQxI9Q09wBYTAV8wfgplDFKtO8ao26Fg2Z77M4u5E6GUcScfTk GfNviqtlCte3lcZdXPoRFQCnIxx4Zmv0Cq35v5Kj40UQPTzc2pLtwiWey3Kj0Ki2bDDRCcs9QcF dJy+Ases2W9HGNtB+APmacvIWN2AYQJ1m8z6vtxLsXNziZGQPKmlUE0ORqG68xvp0XVUP0FUlC+ j/N8rb09hVXIlmVcz31TXpamy0exwWXsX5f9n47K+xyD+LIZ9kT2xPe/MmM2mAZcR0dCoHdXa6O PNYO7kFNE+TQoIoJKT/PQ+hgnGh7VafFtl7JdsShmhuPYMiVG8rt80wOMGm5rl/rSweIgSQIjWW jQ6rFcWmxxdrMf02aovWvmQhkS/ej+n209Odf3gvQZgkP9pqv2hBCIPoRtKoY5sE= X-Received: by 2002:a17:907:c012:b0:c11:ff2c:4f33 with SMTP id a640c23a62f3a-c16b47c7127mr818780066b.45.1784723400878; Wed, 22 Jul 2026 05:30:00 -0700 (PDT) Received: from DW927H4LGF ([2a09:bac6:37e6:1e5a::306:2]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-69f34f1b867sm835007a12.14.2026.07.22.05.29.58 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 22 Jul 2026 05:29:59 -0700 (PDT) From: Oxana Kharitonova To: mic@digikod.net, gnoack@google.com Cc: paul@paul-moore.com, jmorris@namei.or, serge@hallyn.com, wangyan01@kylinos.cn, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, landlock@lists.linux.dev, oxana@cloudflare.com, webprosto@gmail.com Subject: [PATCH 1/6] ipc: Move mqueue fs magic to uapi magic header Date: Wed, 22 Jul 2026 13:29:37 +0100 Message-ID: <20260722122952.42149-2-oxana@cloudflare.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260722122952.42149-1-oxana@cloudflare.com> References: <20260722122952.42149-1-oxana@cloudflare.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Move MQUEUE_MAGIC from ipc/mqueue.c to include/uapi/linux/magic.h so it can be shared by code outside of ipc/mqueue.c without duplicating the constant. Signed-off-by: Oxana Kharitonova --- include/uapi/linux/magic.h | 2 ++ ipc/mqueue.c | 2 +- 2 files changed, 3 insertions(+), 1 deletion(-) diff --git a/include/uapi/linux/magic.h b/include/uapi/linux/magic.h index 4f2da935a76c..8e5d33bb1453 100644 --- a/include/uapi/linux/magic.h +++ b/include/uapi/linux/magic.h @@ -78,6 +78,8 @@ =20 #define V9FS_MAGIC 0x01021997 =20 +#define MQUEUE_MAGIC 0x19800202 + #define BDEVFS_MAGIC 0x62646576 #define DAXFS_MAGIC 0x64646178 #define BINFMTFS_MAGIC 0x42494e4d diff --git a/ipc/mqueue.c b/ipc/mqueue.c index 4798b375972b..9515597d45ce 100644 --- a/ipc/mqueue.c +++ b/ipc/mqueue.c @@ -22,6 +22,7 @@ #include #include #include +#include #include #include #include @@ -47,7 +48,6 @@ struct mqueue_fs_context { bool newns; /* Set if newly created ipc namespace */ }; =20 -#define MQUEUE_MAGIC 0x19800202 #define DIRENT_SIZE 20 #define FILENT_SIZE 80 =20 --=20 2.50.1 (Apple Git-155) From nobody Fri Jul 24 22:59:13 2026 Received: from mail-ej1-f52.google.com (mail-ej1-f52.google.com [209.85.218.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BA5952BEFF5 for ; Wed, 22 Jul 2026 12:30:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723406; cv=none; b=JqANow8RHc4yPCQvQFO6eK5Recl45+Bwm99R+6V6GcKQLnejVgjRZnJDlxNgLczG8/Xil8MS3QtH9vgsqAcrRqwuPKFcImJdafxjdB573mYbBUdLjVbzBQc/1slRmpMqMqIVh6+u9o4890ILJgIZ6tk9KW2HbwRXMjzn1QSIX/E= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723406; c=relaxed/simple; bh=vX8NKo3tbkJYOQsFzvM0VcQFAQ/YMO+PXjFya3Ljz74=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=kvJNg8JxCjBey2oJwWPvaZ+Fs0oZdTfkjx6iYJFj+S2cTglhmHx0I78DeQv5RgSajOozFKAASygbFU6336A25piMkPbLUyCi/fPxa0+8JtiZ0WV42ztSLTpiBcp+ZBU1rfj880DQUToOVgoqqg/lMN861xYcQ+IVVTT/7Ms0xeM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com; spf=pass smtp.mailfrom=cloudflare.com; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b=aR9fo65Y; arc=none smtp.client-ip=209.85.218.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b="aR9fo65Y" Received: by mail-ej1-f52.google.com with SMTP id a640c23a62f3a-c167aa9500dso1015393466b.3 for ; Wed, 22 Jul 2026 05:30:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google09082023; t=1784723403; x=1785328203; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=KFGI0FiCjKbyURDhEKHwGm5SarWbwG22EAg474C66q0=; b=aR9fo65YM5ZdSIDWrOKneGwLsXypNxJXRp3ihz9CVUZ8pbF7w0/DN6nYiuxi8dUmLJ rSdi42VHktrsFNxq+gVyWBTfTWYbvqJm5EooLsT6wSUK+j11G3EoRPYuvS7K7qymcdv9 v5MB8UDuGAQcCJeSF7z9LUx2HSrbgRTO2H5NgjUlxIHdVGMkBYsTWwSqBzQdUfS9g/B8 of1vmNpdgBEC6DipzYU/Mm86CqAejRxRzXRPnAFQ/vRLc4MbF3qXPFMpafuCbRyycbgk 3ZzOLXOGUHLvWmOtOiql90UQKkKCsVQyIjL5pcta7CbvrFOtG0mqt9IcmWugzHmaDkR8 +PTA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723403; x=1785328203; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=KFGI0FiCjKbyURDhEKHwGm5SarWbwG22EAg474C66q0=; b=B0KEhkzqbtIKwa15nSiF7yU7BWJiodLcq7vAQDbRe/QhHSotkMwVRaYeER48JCQzSc dhzaObJG7I4bCuJYasCZKJRna7zJE3F+B5o0iS1P6XwJnYSES3zetWMKEeQOMx1vbzpK e/A0jtuiuR7GO+h1tTFeQwlLNzquTp3P/UdDxGY3DyPh1SIDm6A4GNIdnVlS91eZYD32 NDLZESSolH6rF8pOwe5eXr8DblY9JMR12mrK6k84mY1RFZyXKUGxVjPOoANqBLRTlzeB tbn1MBISIxgZ4k/AOkcrXxso3h4yjBYSH+Uwvq4u2QqnwM29bknXGn3hnSb3MpduGRog 37/g== X-Forwarded-Encrypted: i=1; AHgh+RolP0A1cqM0mGSHXEmY5eNxk0am12ZmKBkyL/w3qVVQEk5ngQHrP3vrG7soDtS7QTt/2z33xivpVLFuepE=@vger.kernel.org X-Gm-Message-State: AOJu0YzjP9MNfFoZFEt9HE+q9jWjxOdKFcARN2X32teNkvrrbYIfSKoK X1YOFKOBmVRLSVsRWyRbhxHMSfC+l92ChL+9GCygehf9XKn83EOMv6Wv84eGdagVM9JFVBURpQQ ODClR3nq0yA== X-Gm-Gg: AR+sD12U0a16Hh9KzTf/dNOiuRXsi4WeACRKj4RpAp2Kc3LiYav2sft63rk57IF4DPn lZKH1M8GS5b7lSwS6PYHLlZidngr1GrW/EhXaLF5j1zTXUd9F0oTivUTNiP9T2zT52Okr+3GbX0 YxjtWi6yjX8RXyzano7KE1Fh4tjMZY/y9BDEIedX34n/HEPALPLQ5sXWO6MRT3Tij1HZkan5bAy sGzXaLT67lcBMwnWa6T3FL1HljVjFaHAeJIF8DowYtvbctM9nG3uCTwvOudBgEpYLqVBBtCIsXl vbfZOw/FaQn5bjYJ3hWD8g4LF/w7Wp7MZT8792pJ229zZPEKGiQ3uiNUEHJniRdMNnXwXxnr52C FzDeiHZcgEL7yJHHXYG5FIxfvdQnzZAZeR7BbrMSgK7laTYZ74Wf9Ze/GiV1YKrw= X-Received: by 2002:a17:907:3f8b:b0:c12:5e3d:4023 with SMTP id a640c23a62f3a-c16b457b127mr1033077166b.10.1784723402875; Wed, 22 Jul 2026 05:30:02 -0700 (PDT) Received: from DW927H4LGF ([2a09:bac6:37e6:1e5a::306:2]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-69f34f1b867sm835007a12.14.2026.07.22.05.30.01 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 22 Jul 2026 05:30:01 -0700 (PDT) From: Oxana Kharitonova To: mic@digikod.net, gnoack@google.com Cc: paul@paul-moore.com, jmorris@namei.or, serge@hallyn.com, wangyan01@kylinos.cn, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, landlock@lists.linux.dev, oxana@cloudflare.com, webprosto@gmail.com Subject: [PATCH 2/6] landlock: Scope POSIX message queue opens Date: Wed, 22 Jul 2026 13:29:38 +0100 Message-ID: <20260722122952.42149-3-oxana@cloudflare.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260722122952.42149-1-oxana@cloudflare.com> References: <20260722122952.42149-1-oxana@cloudflare.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Add support for enforcing LANDLOCK_SCOPE_POSIX_MSG_QUEUE when opening POSIX message queues. Tag mqueuefs inodes at instantiation time with the landlock domain of the task that created the queue. This domain is stored in the landlock inode security blob and kept alive until the inode security blob is released. On file open, detect mqueuefs regular files and compare the queue creator's domain with the opener's scoped domain. Deny the open when the opener is restricted by LANDLOCK_SCOPE_POSIX_MSG_QUEUE and the queue was created outside of an allowed parent domain. This makes POSIX message queues follow the same scoped-domain model as the existing landlock IPC restrictions, while keeping the queue creator domain tied to the lifetime of the queue inode. Signed-off-by: Oxana Kharitonova --- include/uapi/linux/landlock.h | 1 + security/landlock/audit.c | 9 ++++++++ security/landlock/audit.h | 1 + security/landlock/fs.c | 35 ++++++++++++++++++++++++++++ security/landlock/fs.h | 15 ++++++++++++ security/landlock/limits.h | 2 +- security/landlock/ruleset.c | 1 - security/landlock/task.c | 43 +++++++++++++++++++++++++++++++++++ security/landlock/task.h | 4 ++++ 9 files changed, 109 insertions(+), 2 deletions(-) diff --git a/include/uapi/linux/landlock.h b/include/uapi/linux/landlock.h index 272f047df438..96d0c3b423ac 100644 --- a/include/uapi/linux/landlock.h +++ b/include/uapi/linux/landlock.h @@ -491,6 +491,7 @@ struct landlock_net_port_attr { /* clang-format off */ #define LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET (1ULL << 0) #define LANDLOCK_SCOPE_SIGNAL (1ULL << 1) +#define LANDLOCK_SCOPE_POSIX_MSG_QUEUE (1ULL << 2) /* clang-format on*/ =20 #endif /* _UAPI_LINUX_LANDLOCK_H */ diff --git a/security/landlock/audit.c b/security/landlock/audit.c index 50536c568526..895397b5cbca 100644 --- a/security/landlock/audit.c +++ b/security/landlock/audit.c @@ -82,6 +82,10 @@ get_blocker(const enum landlock_request_type type, case LANDLOCK_REQUEST_SCOPE_SIGNAL: WARN_ON_ONCE(access_bit !=3D -1); return "scope.signal"; + + case LANDLOCK_REQUEST_SCOPE_POSIX_MSG_QUEUE: + WARN_ON_ONCE(access_bit !=3D -1); + return "scope.posix_msg_queue"; } =20 WARN_ON_ONCE(1); @@ -646,6 +650,11 @@ void landlock_log_denial(const struct landlock_cred_se= curity *const subject, !!(quiet_mask & LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET); break; + case LANDLOCK_REQUEST_SCOPE_POSIX_MSG_QUEUE: + quiet_applicable_to_access =3D + !!(quiet_mask & + LANDLOCK_SCOPE_POSIX_MSG_QUEUE); + break; /* * Leave LANDLOCK_REQUEST_PTRACE and * LANDLOCK_REQUEST_FS_CHANGE_TOPOLOGY unhandled for now - they diff --git a/security/landlock/audit.h b/security/landlock/audit.h index 620f8a24291d..ce85417548fa 100644 --- a/security/landlock/audit.h +++ b/security/landlock/audit.h @@ -21,6 +21,7 @@ enum landlock_request_type { LANDLOCK_REQUEST_NET_ACCESS, LANDLOCK_REQUEST_SCOPE_ABSTRACT_UNIX_SOCKET, LANDLOCK_REQUEST_SCOPE_SIGNAL, + LANDLOCK_REQUEST_SCOPE_POSIX_MSG_QUEUE, }; =20 /* diff --git a/security/landlock/fs.c b/security/landlock/fs.c index f7e5e4ef9eac..c6558b448a06 100644 --- a/security/landlock/fs.c +++ b/security/landlock/fs.c @@ -51,6 +51,7 @@ #include "object.h" #include "ruleset.h" #include "setup.h" +#include "task.h" =20 /* Underlying object management */ =20 @@ -1268,6 +1269,33 @@ static void hook_inode_free_security_rcu(void *inode= _security) */ inode_sec =3D inode_security + landlock_blob_sizes.lbs_inode; WARN_ON_ONCE(inode_sec->object); + + landlock_put_ruleset_deferred(inode_sec->mq_domain); +} + +/* + * Tag a newly created POSIX message queue with its creator's domain. + * + * This is the earliest reachable point with both the creator's context an= d a + * fully initialized inode. + */ +static void hook_d_instantiate(struct dentry *const dentry, + struct inode *const inode) +{ + struct landlock_ruleset *dom; + + if (!landlock_is_posix_mqueue_inode(inode)) + return; + + dom =3D landlock_get_current_domain(); + if (!dom) + return; + + if (WARN_ON_ONCE(landlock_inode(inode)->mq_domain)) + return; + + landlock_get_ruleset(dom); + landlock_inode(inode)->mq_domain =3D dom; } =20 /* Super-block hooks */ @@ -1756,6 +1784,12 @@ static int hook_file_open(struct file *const file) const struct landlock_cred_security *const subject =3D landlock_get_applicable_subject(file->f_cred, any_fs, NULL); struct landlock_request request =3D {}; + int err; + + /* POSIX message queue scoping is independent of FS access rights. */ + err =3D landlock_check_posix_mqueue_open(file); + if (err) + return err; =20 if (!subject) return 0; @@ -1979,6 +2013,7 @@ static void hook_file_free_security(struct file *file) =20 static struct security_hook_list landlock_hooks[] __ro_after_init =3D { LSM_HOOK_INIT(inode_free_security_rcu, hook_inode_free_security_rcu), + LSM_HOOK_INIT(d_instantiate, hook_d_instantiate), =20 LSM_HOOK_INIT(sb_delete, hook_sb_delete), LSM_HOOK_INIT(sb_mount, hook_sb_mount), diff --git a/security/landlock/fs.h b/security/landlock/fs.h index b4421d9df68f..aefe078845fa 100644 --- a/security/landlock/fs.h +++ b/security/landlock/fs.h @@ -14,6 +14,7 @@ #include #include #include +#include =20 #include "access.h" #include "cred.h" @@ -38,6 +39,14 @@ struct landlock_inode_security { * performed by get_inode_object(). */ struct landlock_object __rcu *object; + /** + * @mq_domain: Domain of the task that created POSIX message queue. + * Only set for mqueuefs inodes (i.e. s_magic =3D=3D MQUEUE_MAGIC) at + * creation time by hook_d_instantiate(), never modified afterwards. + * Used to check LANDLOCK_SCOPE_POSIX_MSG_QUEUE against the + * accessing task's domain. + */ + struct landlock_ruleset *mq_domain; }; =20 /** @@ -141,6 +150,12 @@ landlock_inode(const struct inode *const inode) return inode->i_security + landlock_blob_sizes.lbs_inode; } =20 +static inline bool +landlock_is_posix_mqueue_inode(const struct inode *const inode) +{ + return S_ISREG(inode->i_mode) && inode->i_sb->s_magic =3D=3D MQUEUE_MAGIC; +} + static inline struct landlock_superblock_security * landlock_superblock(const struct super_block *const superblock) { diff --git a/security/landlock/limits.h b/security/landlock/limits.h index 08d5f2f6d321..70a7c5c7af85 100644 --- a/security/landlock/limits.h +++ b/security/landlock/limits.h @@ -27,7 +27,7 @@ #define LANDLOCK_MASK_ACCESS_NET ((LANDLOCK_LAST_ACCESS_NET << 1) - 1) #define LANDLOCK_NUM_ACCESS_NET __const_hweight64(LANDLOCK_MASK_ACCESS_NE= T) =20 -#define LANDLOCK_LAST_SCOPE LANDLOCK_SCOPE_SIGNAL +#define LANDLOCK_LAST_SCOPE LANDLOCK_SCOPE_POSIX_MSG_QUEUE #define LANDLOCK_MASK_SCOPE ((LANDLOCK_LAST_SCOPE << 1) - 1) #define LANDLOCK_NUM_SCOPE __const_hweight64(LANDLOCK_MASK_SCOPE) =20 diff --git a/security/landlock/ruleset.c b/security/landlock/ruleset.c index 4dd09ea22c84..aa37d50ead87 100644 --- a/security/landlock/ruleset.c +++ b/security/landlock/ruleset.c @@ -520,7 +520,6 @@ static void free_ruleset_work(struct work_struct *const= work) free_ruleset(ruleset); } =20 -/* Only called by hook_cred_free(). */ void landlock_put_ruleset_deferred(struct landlock_ruleset *const ruleset) { if (ruleset && refcount_dec_and_test(&ruleset->usage)) { diff --git a/security/landlock/task.c b/security/landlock/task.c index 55522a601367..d65e43550b26 100644 --- a/security/landlock/task.c +++ b/security/landlock/task.c @@ -453,6 +453,49 @@ static int hook_file_send_sigiotask(struct task_struct= *tsk, return -EPERM; } =20 +static const struct access_masks posix_mqueue_scope =3D { + .scope =3D LANDLOCK_SCOPE_POSIX_MSG_QUEUE, +}; + +/** + * landlock_check_posix_mqueue_open - Deny opening a POSIX message queue + * created by a task from a different (non-ancestor) domain + * + * @file: The mqueuefs file being opened. + * + * Return: -EPERM if the open must be denied, 0 otherwise. + */ +int landlock_check_posix_mqueue_open(struct file *const file) +{ + const struct inode *const inode =3D file_inode(file); + const struct landlock_cred_security *subject; + size_t handle_layer; + + if (!landlock_is_posix_mqueue_inode(inode)) + return 0; + + subject =3D landlock_get_applicable_subject(file->f_cred, + posix_mqueue_scope, + &handle_layer); + if (!subject) + return 0; + + if (!domain_is_scoped(subject->domain, + landlock_inode(inode)->mq_domain, + LANDLOCK_SCOPE_POSIX_MSG_QUEUE)) + return 0; + + landlock_log_denial(subject, &(struct landlock_request) { + .type =3D LANDLOCK_REQUEST_SCOPE_POSIX_MSG_QUEUE, + .audit =3D { + .type =3D LSM_AUDIT_DATA_FILE, + .u.file =3D file, + }, + .layer_plus_one =3D handle_layer + 1, + }); + return -EPERM; +} + static struct security_hook_list landlock_hooks[] __ro_after_init =3D { LSM_HOOK_INIT(ptrace_access_check, hook_ptrace_access_check), LSM_HOOK_INIT(ptrace_traceme, hook_ptrace_traceme), diff --git a/security/landlock/task.h b/security/landlock/task.h index 7c00360219a2..0b031dc17bbf 100644 --- a/security/landlock/task.h +++ b/security/landlock/task.h @@ -9,6 +9,10 @@ #ifndef _SECURITY_LANDLOCK_TASK_H #define _SECURITY_LANDLOCK_TASK_H =20 +#include + __init void landlock_add_task_hooks(void); =20 +int landlock_check_posix_mqueue_open(struct file *const file); + #endif /* _SECURITY_LANDLOCK_TASK_H */ --=20 2.50.1 (Apple Git-155) From nobody Fri Jul 24 22:59:13 2026 Received: from mail-ej1-f46.google.com (mail-ej1-f46.google.com [209.85.218.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8D647284662 for ; Wed, 22 Jul 2026 12:30:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.46 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723409; cv=none; b=QA8OT5WMuzMr5ZWeoO0+rNdc4N3x/UnmC01Hjupap9RCyvxtlnzo2gHOjNqXw3IPXbPcqEFtJAtNBY6pj2JLmecy7w17JtMD2Y9OrUVwmN12KKd08BYWOZf0wVeBIk7euClukQALGYqfPoVWNZuerJy9Ev63xsTm7YdmSoe0GLU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723409; c=relaxed/simple; bh=JAKHu8YyBELteSv8ooj1Pp3j9g6YVHHeCe1BMryEs6o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=A6WSn8mPd3tt46wNREYN1Fo1SqjiO/k/jAWh+M/52yiDUzaHOftZqmWe0LJka67uPG8NCmz1vqGhRqdtWPEtpMtjGVkXdH/lVkLphtNmWRrwKT+p0vAlMBNm5Uzy4G/gh1uLsw+8vEOO+ZJ0BD8PQVdta6fedJkuBwDMB3rI40Q= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com; spf=pass smtp.mailfrom=cloudflare.com; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b=Q7EDhFzL; arc=none smtp.client-ip=209.85.218.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b="Q7EDhFzL" Received: by mail-ej1-f46.google.com with SMTP id a640c23a62f3a-c15b33f7b23so1811116066b.3 for ; Wed, 22 Jul 2026 05:30:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google09082023; t=1784723406; x=1785328206; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=zbtWhBehxkVPlnfWLUPZXxKYcYCTq6s9Hilnw7lNtrM=; b=Q7EDhFzLq0BUjEzbs327ym00ev6EGesE9NmxaxStxDVRojFfYslNn8V+HoApNu2tyf U+tZDMwZ1sv5sz0SHREGjZ1bnUgR5ru+KAf3YB+TlMNT1HW6LpFgqY881uaSjmP/tpUq 8nve/jd237y8oz0K2YK405+p7pg8+w1qpiApyS1SO5HEEdJ0nL4tevHfiUus08wLhP4f mZhxzK1WsCCBWgbk2LiLqu7ynSO65OtTEGkz7s3d+vynjKrNbItJZwAYyqLUCqP1xbXT NNcTp32f/ApMzW3/KfhHQ/9OAhyiDkqfQ7329CwnNOeAakQKzzkL3obK67diwDzClzjy P/bA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723406; x=1785328206; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=zbtWhBehxkVPlnfWLUPZXxKYcYCTq6s9Hilnw7lNtrM=; b=XmISk4AQJLLE89WS/YsSqvu9LVLM52EiQj5bAIE6vnEyGe2+v0Fc3KxPf3kwgzVDTk Hl2plKO6B3O8xTXIiLvRp7Bs6AYjy61chL90TXQ66ErFz+/6tnLlDO7zCGXteDqLEnw2 ey9XjCLgoqUtt0t5GZA+0WI0VJrRGiBXxWeSxRkA0oqbBGECgbRKI/Io8VhC9NLNodcf s0qB8RF46LZrYDFc0ehahYXCxsGrURExvPAn+of3ddqiCAiXku1XwzFdYqhGwCt2QeIS Rq7vLN+ZyOotV9tfUmXSedACxU3FyQ3hiZYvtHPwjbNT3gxZuEl+Vyuva9YbtJykrC8L zUVA== X-Forwarded-Encrypted: i=1; AHgh+RrZ5KD7ZKd04vSEJ4vq8WaKvnjucpd0KdOc3LrP4+zgRbWXwKXOHtzcQK8oJZWaT+W71LWg+2TRny7lq08=@vger.kernel.org X-Gm-Message-State: AOJu0Yx6zkAkpA2YQkSmoCStrk/INfYhamwkzlaAp0vj75wp0pTeRNH4 YDX/kXsdpxIeLqrK4M1G+nt+9g564IzH/Aio8wKoNkvfi1Kq3W+f4NCWACK4WyBU/Rg= X-Gm-Gg: AR+sD11Y5fWUo2NJwAl5kqufeWfsV2xDV1JGl4OYfE8GAP5nTAhehKEPn6i8B2F0HPT Ryp6sfrld+BVVRWOlKcdQofVC0KS/NZFQiZD9iXLECZ5Us6mc0OKo22SmWFIBS6uBsH3loDpXfr 1sxui6anMtIbmBcF5nUWkHek5N/w33+dF55QDHEEsRok0lLk5zA47GrMuzAn6PDQ8PhIsXPjYEd OEJg2CzRZNSOSV1CKid0a7rz8V+nL/9s1tXzwBUYu3tcbOHm+oJ5QIzIu2+lYx+hQwaJTd44QUg /YeviG/VMtVZzS9KODIEPu2qh4n8eOdnty4gDmK7VS+rIluOO/YCIKfAVLAZqNIutNgNArtj6ko 0fsHu+xjoXqZUjOvehArdjmDSRs8y3vaKQCOkniBOagSSujUfkxrBb+NlB7/9D30= X-Received: by 2002:a17:907:980a:b0:c16:2f5d:6153 with SMTP id a640c23a62f3a-c16b46d2c3dmr987958966b.20.1784723405581; Wed, 22 Jul 2026 05:30:05 -0700 (PDT) Received: from DW927H4LGF ([2a09:bac6:37e6:1e5a::306:2]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-69f34f1b867sm835007a12.14.2026.07.22.05.30.03 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 22 Jul 2026 05:30:04 -0700 (PDT) From: Oxana Kharitonova To: mic@digikod.net, gnoack@google.com Cc: paul@paul-moore.com, jmorris@namei.or, serge@hallyn.com, wangyan01@kylinos.cn, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, landlock@lists.linux.dev, oxana@cloudflare.com, webprosto@gmail.com Subject: [PATCH 3/6] landlock: Bump ABI for LANDLOCK_SCOPE_POSIX_MSG_QUEUE Date: Wed, 22 Jul 2026 13:29:39 +0100 Message-ID: <20260722122952.42149-4-oxana@cloudflare.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260722122952.42149-1-oxana@cloudflare.com> References: <20260722122952.42149-1-oxana@cloudflare.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Increase the landlock ABI version so userspace can detect support for LANDLOCK_SCOPE_POSIX_MSG_QUEUE. Signed-off-by: Oxana Kharitonova --- security/landlock/syscalls.c | 2 +- tools/testing/selftests/landlock/base_test.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/security/landlock/syscalls.c b/security/landlock/syscalls.c index 36b02892c62f..84521a31bf75 100644 --- a/security/landlock/syscalls.c +++ b/security/landlock/syscalls.c @@ -169,7 +169,7 @@ static const struct file_operations ruleset_fops =3D { * If the change involves a fix that requires userspace awareness, also up= date * the errata documentation in Documentation/userspace-api/landlock.rst . */ -const int landlock_abi_version =3D 10; +const int landlock_abi_version =3D 11; =20 /** * sys_landlock_create_ruleset - Create a new ruleset diff --git a/tools/testing/selftests/landlock/base_test.c b/tools/testing/s= elftests/landlock/base_test.c index cbd3c1669951..b8b5fa1042ba 100644 --- a/tools/testing/selftests/landlock/base_test.c +++ b/tools/testing/selftests/landlock/base_test.c @@ -76,7 +76,7 @@ TEST(abi_version) const struct landlock_ruleset_attr ruleset_attr =3D { .handled_access_fs =3D LANDLOCK_ACCESS_FS_READ_FILE, }; - ASSERT_EQ(10, landlock_create_ruleset(NULL, 0, + ASSERT_EQ(11, landlock_create_ruleset(NULL, 0, LANDLOCK_CREATE_RULESET_VERSION)); =20 ASSERT_EQ(-1, landlock_create_ruleset(&ruleset_attr, 0, --=20 2.50.1 (Apple Git-155) From nobody Fri Jul 24 22:59:13 2026 Received: from mail-ed1-f43.google.com (mail-ed1-f43.google.com [209.85.208.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E4401352034 for ; Wed, 22 Jul 2026 12:30:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723412; cv=none; b=hng8ZbBiSWIlCAg4cCL7zwWfhoELtC57wuTL2PO4S6fSixhADCbop7exjXVpvRyN1kPCaXsiT3Z8Vk7fAEwL2BfX+N8j/CGpg/McBvg6Lg3GGujZ18Ph6zfQGxTYja/b4FgQCCYMJtoEXIpp2Imr45gztdaQjD+3UzKY8Fgr3mw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723412; c=relaxed/simple; bh=YR2dh10ivQfLZOGXOR0YDRUBJQfvgY5D+ot0FwvSBHQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Q+HHadAHjnaQHF/hDIeqONt6Mfk8x2FaaiTh6C/IH6kUouBWdUvx7d4xXaFcz8lVQp8Aasxehamo2VBPCmMbmZ3g49S/erTTyJKP+eUaIJnfyikz7x+KE/I/G8r0++T6BxzMLJWplcqRsFreEQBtDr0EDwkX4Bl9MsA4vXId1f0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com; spf=pass smtp.mailfrom=cloudflare.com; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b=LvMoaC6F; arc=none smtp.client-ip=209.85.208.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b="LvMoaC6F" Received: by mail-ed1-f43.google.com with SMTP id 4fb4d7f45d1cf-69e8ea2783aso6151379a12.3 for ; Wed, 22 Jul 2026 05:30:09 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google09082023; t=1784723408; x=1785328208; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=pCH9TsY6JjijtowAyR28vJoTPq1XXv7UbsDDuJ5wjzE=; b=LvMoaC6FYktPJKtCVMEod50E1DExWVG/Alx7avZfHuSmArPvQfr9zQ2BvVu9OPi3Tq Tjs0u2Mfk5yhTSG5gWtAD0rZpSvtVsxMElAJK7fhSe9WUe8/WK77ithC4X8A8+ffCEp3 CdHMl0WxXLA6t9SKI8mJFvrSCp8cbya3aDR/x/LAHkxcK0sIYHMUHzB+qi04tSIXP/J9 j1a2eSVs3SMUeREoLeieh0h54GQgFGoLq30NUJ6b2PVOGb1ie1P4THkeXiOC5a7Gzlso 4bVlrVRuePWffottrIiwUIDTMJovFxzZIykAlzkaF62oLrFkDko9U3wzSlH6Z4W+6K+4 G/qg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723408; x=1785328208; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=pCH9TsY6JjijtowAyR28vJoTPq1XXv7UbsDDuJ5wjzE=; b=bxKDoeB70TyeP0EoWK0JqaMWqR80087E2po94M+hEb0calAdzuCh7if0e3Ss16434k Rm9pNqTc7Dn8kt3u1e0o2G73vkiG0yphFIPIywt2/1j2M6k46cupTFejnNKCv2pqXA4w TMvMlN/u5PFaRBRYsc6js/VqjFK9TSS4JelNsJF7UzKLXpOdMZxqCVteXvl5yd+i5yk4 1125EqOlAH3IanqvYB2WVqx8MPFVKbAKlTLMoYt193uxaeWgd3qLIJUS0AiqkT1H3F2J A71Vwi/GhNyQqKwnieDIdVt+0zytUYIi1DL6IEg4qWAbQBHF+ax7BCEyJmre6q/h1/K6 n8Mg== X-Forwarded-Encrypted: i=1; AHgh+Rrum4Ji74ewuFFOS/y5hXGeuiQfX5h98JtFiV7HhUid1v3j54tZpgtES1TC4E0IrzICTLsVerMU1YKAg0s=@vger.kernel.org X-Gm-Message-State: AOJu0Yw+IhLUAv8ryKNZH3uMWhaJVG4sCNwNz8faRjs05KCwGNv0e1PL 8u85x7N6P2u9pFwPZYJufpJsEIS0z+gsSLxpE+0oX0l7j1ogkZlrLQ1fuEhZoLBNJdk= X-Gm-Gg: AR+sD13zJ2m3OuUE4ciTPF9rV4mHC+fRdagaTidSBf69m7l3HCNT8PcXFwduSoH2bKf iXULR9CtpgECoLujjgQdLeYuzAi83bjEbZZACWydv6RGWRfIisg1bFo8GkaVWjtpTbOxWKtLs1D J0g88pFkFoOeNFs4msCR+b2YkDvmg0tMW/06+vhPvQSrsAf1O306OMuDU7WHZEl0QPkN6n4Wq2m 1yPjsa+XyVuwKMKQGyuFSyvU+Er1cqOe4WbDGP3BhVPN5qLnXpcMcUQaKIwLMd42Hrj+g0+ZBur hvPAaX2CslqyrAhMQ9tYjho21I4Tlej5V4Ct09uhagbfmlfaBQfxnZgLqqnem4sVu9AitMPkLJE jCGJ1vy0mm7QNZDa6C969RBFsEMPJhUotTNCUO4KwST1tPuLyC12gcC+Dzm0KtRE= X-Received: by 2002:a05:6402:4590:b0:69c:2ffe:114a with SMTP id 4fb4d7f45d1cf-69e65327a22mr7487794a12.39.1784723407932; Wed, 22 Jul 2026 05:30:07 -0700 (PDT) Received: from DW927H4LGF ([2a09:bac6:37e6:1e5a::306:2]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-69f34f1b867sm835007a12.14.2026.07.22.05.30.05 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 22 Jul 2026 05:30:06 -0700 (PDT) From: Oxana Kharitonova To: mic@digikod.net, gnoack@google.com Cc: paul@paul-moore.com, jmorris@namei.or, serge@hallyn.com, wangyan01@kylinos.cn, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, landlock@lists.linux.dev, oxana@cloudflare.com, webprosto@gmail.com Subject: [PATCH 4/6] selftests/landlock: Test POSIX message queue scoping Date: Wed, 22 Jul 2026 13:29:40 +0100 Message-ID: <20260722122952.42149-5-oxana@cloudflare.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260722122952.42149-1-oxana@cloudflare.com> References: <20260722122952.42149-1-oxana@cloudflare.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Add tests for LANDLOCK_SCOPE_POSIX_MSG_QUEUE. Verify that opening a queue created outside the current scoped domain is denied, and that opening a queue created within the same domain remains allowed. Signed-off-by: Oxana Kharitonova --- .../landlock/scoped_posix_msg_queue_test.c | 223 ++++++++++++++++++ .../testing/selftests/landlock/scoped_test.c | 2 +- 2 files changed, 224 insertions(+), 1 deletion(-) create mode 100644 tools/testing/selftests/landlock/scoped_posix_msg_queue= _test.c diff --git a/tools/testing/selftests/landlock/scoped_posix_msg_queue_test.c= b/tools/testing/selftests/landlock/scoped_posix_msg_queue_test.c new file mode 100644 index 000000000000..602ba5c7a83d --- /dev/null +++ b/tools/testing/selftests/landlock/scoped_posix_msg_queue_test.c @@ -0,0 +1,223 @@ +// SPDX-License-Identifier: GPL-2.0 +/* + * Landlock tests - POSIX message queue scoping + * + * Copyright =C2=A9 2024-2026 Microsoft Corporation + */ + +#define _GNU_SOURCE +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include +#include + +#include "common.h" +#include "scoped_common.h" + +static void set_mq_name(char *const name, const size_t size) +{ + snprintf(name, size, "/selftests-landlock-mq-tid%d", sys_gettid()); +} + +FIXTURE(scoped_domains) +{ + char mq_name[NAME_MAX]; +}; + +#include "scoped_base_variants.h" + +FIXTURE_SETUP(scoped_domains) +{ + drop_caps(_metadata); + + set_mq_name(self->mq_name, sizeof(self->mq_name)); + /* Removes a possibly stale queue from a previous run. */ + mq_unlink(self->mq_name); +} + +FIXTURE_TEARDOWN(scoped_domains) +{ +} + +/* + * The parent creates the message queue, then the child tries + * to open it, with scoped domain(s) or no domain at all. + */ +TEST_F(scoped_domains, open_parent_queue) +{ + pid_t child; + int status; + int pipe_parent[2], pipe_child[2]; + char buf; + mqd_t mq; + + ASSERT_EQ(0, pipe2(pipe_parent, O_CLOEXEC)); + ASSERT_EQ(0, pipe2(pipe_child, O_CLOEXEC)); + + if (variant->domain_both) + create_scoped_domain(_metadata, LANDLOCK_SCOPE_POSIX_MSG_QUEUE); + + child =3D fork(); + ASSERT_LE(0, child); + if (child =3D=3D 0) { + mqd_t mq_child; + + EXPECT_EQ(0, close(pipe_parent[1])); + EXPECT_EQ(0, close(pipe_child[0])); + + if (variant->domain_child) + create_scoped_domain(_metadata, + LANDLOCK_SCOPE_POSIX_MSG_QUEUE); + + /* Waits for the parent to create the queue. */ + ASSERT_EQ(1, read(pipe_parent[0], &buf, 1)); + + mq_child =3D mq_open(self->mq_name, O_RDWR); + if (!variant->domain_child) { + EXPECT_LE(0, mq_child); + if (mq_child >=3D 0) + EXPECT_EQ(0, mq_close(mq_child)); + } else { + EXPECT_EQ(-1, mq_child); + EXPECT_EQ(EPERM, errno); + } + + ASSERT_EQ(1, write(pipe_child[1], ".", 1)); + _exit(_metadata->exit_code); + return; + } + EXPECT_EQ(0, close(pipe_parent[0])); + EXPECT_EQ(0, close(pipe_child[1])); + + if (variant->domain_parent) + create_scoped_domain(_metadata, LANDLOCK_SCOPE_POSIX_MSG_QUEUE); + + mq =3D mq_open(self->mq_name, O_CREAT | O_RDWR, 0600, NULL); + ASSERT_LE(0, mq); + + ASSERT_EQ(1, write(pipe_parent[1], ".", 1)); + ASSERT_EQ(1, read(pipe_child[0], &buf, 1)); + + ASSERT_EQ(child, waitpid(child, &status, 0)); + EXPECT_EQ(0, mq_close(mq)); + EXPECT_EQ(0, mq_unlink(self->mq_name)); + + if (WIFSIGNALED(status) || !WIFEXITED(status) || + WEXITSTATUS(status) !=3D EXIT_SUCCESS) + _metadata->exit_code =3D KSFT_FAIL; +} + +/* + * The child creates the message queue, then the parent tries + * to open it, with scoped domain(s) or no domain at all. + */ +TEST_F(scoped_domains, open_child_queue) +{ + pid_t child; + bool can_open_child_queue; + int status; + int pipe_parent[2], pipe_child[2]; + char buf; + mqd_t mq; + + can_open_child_queue =3D !variant->domain_parent; + + ASSERT_EQ(0, pipe2(pipe_parent, O_CLOEXEC)); + ASSERT_EQ(0, pipe2(pipe_child, O_CLOEXEC)); + + if (variant->domain_both) + create_scoped_domain(_metadata, LANDLOCK_SCOPE_POSIX_MSG_QUEUE); + + child =3D fork(); + ASSERT_LE(0, child); + if (child =3D=3D 0) { + mqd_t mq_child; + + EXPECT_EQ(0, close(pipe_parent[1])); + EXPECT_EQ(0, close(pipe_child[0])); + + if (variant->domain_child) + create_scoped_domain(_metadata, + LANDLOCK_SCOPE_POSIX_MSG_QUEUE); + + /* Waits for the parent to be in a domain, if any. */ + ASSERT_EQ(1, read(pipe_parent[0], &buf, 1)); + + mq_child =3D mq_open(self->mq_name, O_CREAT | O_RDWR, 0600, NULL); + ASSERT_LE(0, mq_child); + + ASSERT_EQ(1, write(pipe_child[1], ".", 1)); + + ASSERT_EQ(1, read(pipe_parent[0], &buf, 1)); + EXPECT_EQ(0, mq_close(mq_child)); + EXPECT_EQ(0, mq_unlink(self->mq_name)); + _exit(_metadata->exit_code); + return; + } + EXPECT_EQ(0, close(pipe_parent[0])); + EXPECT_EQ(0, close(pipe_child[1])); + + if (variant->domain_parent) + create_scoped_domain(_metadata, LANDLOCK_SCOPE_POSIX_MSG_QUEUE); + + /* Signals that the parent is in a domain, if any. */ + ASSERT_EQ(1, write(pipe_parent[1], ".", 1)); + + /* Waits for the child to create the queue. */ + ASSERT_EQ(1, read(pipe_child[0], &buf, 1)); + + mq =3D mq_open(self->mq_name, O_RDWR); + if (can_open_child_queue) { + EXPECT_LE(0, mq); + if (mq >=3D 0) + EXPECT_EQ(0, mq_close(mq)); + } else { + EXPECT_EQ(-1, mq); + EXPECT_EQ(EPERM, errno); + } + + /* Signals to the child that the open attempt is done. */ + ASSERT_EQ(1, write(pipe_parent[1], ".", 1)); + + ASSERT_EQ(child, waitpid(child, &status, 0)); + if (WIFSIGNALED(status) || !WIFEXITED(status) || + WEXITSTATUS(status) !=3D EXIT_SUCCESS) + _metadata->exit_code =3D KSFT_FAIL; +} + +/* + * A process must always be able to open a queue it created within its own + * domain, whatever the enforced scope is. + */ +TEST(create_and_open_same_domain) +{ + char mq_name[NAME_MAX]; + mqd_t mq_create, mq_open_again; + + drop_caps(_metadata); + set_mq_name(mq_name, sizeof(mq_name)); + mq_unlink(mq_name); + + create_scoped_domain(_metadata, LANDLOCK_SCOPE_POSIX_MSG_QUEUE); + + mq_create =3D mq_open(mq_name, O_CREAT | O_RDWR, 0600, NULL); + ASSERT_LE(0, mq_create); + + mq_open_again =3D mq_open(mq_name, O_RDWR); + EXPECT_LE(0, mq_open_again); + if (mq_open_again >=3D 0) + EXPECT_EQ(0, mq_close(mq_open_again)); + + EXPECT_EQ(0, mq_close(mq_create)); + EXPECT_EQ(0, mq_unlink(mq_name)); +} + +TEST_HARNESS_MAIN diff --git a/tools/testing/selftests/landlock/scoped_test.c b/tools/testing= /selftests/landlock/scoped_test.c index b90f76ed0d9c..c530baa50948 100644 --- a/tools/testing/selftests/landlock/scoped_test.c +++ b/tools/testing/selftests/landlock/scoped_test.c @@ -12,7 +12,7 @@ =20 #include "common.h" =20 -#define ACCESS_LAST LANDLOCK_SCOPE_SIGNAL +#define ACCESS_LAST LANDLOCK_SCOPE_POSIX_MSG_QUEUE =20 TEST(ruleset_with_unknown_scope) { --=20 2.50.1 (Apple Git-155) From nobody Fri Jul 24 22:59:13 2026 Received: from mail-ed1-f43.google.com (mail-ed1-f43.google.com [209.85.208.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EFCE63537FE for ; Wed, 22 Jul 2026 12:30:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723412; cv=none; b=Of+4SLl3nYbAZkTclI3hplW745IIxDlqxH/hjAYrY+2jGyV/gYwpqCy8gzOi6D17faKmW/xGy3d+XWWiJUWNVJbzF/RxUWp/svrkbZSePInpNdnem0zVsNyzEkdKf3PXNQ8XxJakebCQR6pduUeXtj9tD5mai9hIenN8I4eDyKk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723412; c=relaxed/simple; bh=BH9Q/nb1SHbVfJKmzTYY61p3CrQmGn4nLgNrkig4qI4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=F0NLesxmzrNJj1TXvYXrvxqFmCrnL2TZJwSU4lUwwmAIHgDXFmi7bd5kE026/vWZVRyBAYVJyg5ohlBu1GzmBjAVuoNcKHrEgG39YDi+1+J4rBKLPtFSkSDzACkouD+UGbp/ITaqyQHWzmGrC8zQpFxzVqKxm4cv89SqySXV6qc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com; spf=pass smtp.mailfrom=cloudflare.com; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b=Bc+dA8D6; arc=none smtp.client-ip=209.85.208.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b="Bc+dA8D6" Received: by mail-ed1-f43.google.com with SMTP id 4fb4d7f45d1cf-69eae037da1so6410418a12.3 for ; Wed, 22 Jul 2026 05:30:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google09082023; t=1784723409; x=1785328209; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=10OEZDPHkj5hzFYDRyfra44GxaMnslQ2JStk6ORVQZA=; b=Bc+dA8D6hBoktrCwxeAx5BTN3fCqD/KJ3k1RXR3aDaRAVVIs5fuc5YZqfyXCiSuapu WLMOFxr3uA8UtAYVPI5FTNqo5nzJijSE6Aq5PAytKIRiCOkIRw07keJgkDtx2UeF/kVG xX9kieUgfEXUofRZjVNzSpXOekMOo6wYWrThO57+t570Q8r7lHa1aL86VkpiFB6OJnqh fkRttijeBJoMmsIg4/SpI40aiNojj9OeiHWBm15jhkhabT1v23mbVFyONOurz3mIwzJl F4PljIUoX440sHMziSulfsanrcwSPun0E7eXhcdu0RVn7q7YrvESmd9gybdI/ZfcDt8H lFDA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723409; x=1785328209; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=10OEZDPHkj5hzFYDRyfra44GxaMnslQ2JStk6ORVQZA=; b=r2wWWDbRxLeujUpGNXnwgg1KtTRlFiOAxWa2tH9cXWYUYr6waWGIxsFubSin6WFv/Z Q7ktjt+9tVPjJ9s8PhbZQ8WbfeBsLppee+KgyhTQuhmjbF4UtT4Jrd7d1vC5kQKTT48T Ju6N8iw4A/4Ihj7znMRQLOyurud11u33LjNbN8l3Ao+99XC/M8aQx2eLacEXy5/4ohK1 DmFD0k52EHZxo4vlZwBohuTp7HEQMsUdd11b0JZIzIP/Lkv18fuXghSeWbbMRk5Bup2l mDbnjwn8NyjKTk3BmaRKn86FvXahv5tki5FSce8uNjWlzVcxSw4zHbK05T1fLzHmAZEt N1OA== X-Forwarded-Encrypted: i=1; AHgh+RrhgS/uIXWfJlzSFT+q3vNQVtYZ8Bi1quQw077udSm81nKY2ZE4uXLaoXtLK/tICwp0/6Ig6sSeRtjBKwk=@vger.kernel.org X-Gm-Message-State: AOJu0Yyc8g1/7FZyknRqSrFB8uJbIPjpOO16gTm1pX4gQbB4of//RVD7 pUJtvbxkL3eAdcZW1mFvsc1XhcAX8rIwjuTy/nOWS/9dSPO9tfRwev8ZcxyR3cQxwug= X-Gm-Gg: AR+sD12lnIOH868obrkcaasaZuxGrK+K8xtXvhUzPCFCVgkR1E0Gzv344zzoO33sZTI izd25xeoCjO2M+ZSiIr1riULRQQXl/Ygsg45gX4AKlMsyh80I6b6if4b2tw6pdm4W6Ir+/TSMv2 NAY2uS/QgXebDdwOvPJ5b4E85HPkoz2LE0CAtt7s9R0NJCTESF+pA6N6wAw6J0yYY+W8EUn04vO vMNDpoKbKkqzSlQiugmrF3Ta0BhdCYJSzz8akRiBkfliTQaEX4eTBOTQiV8E6SmIRfoHPhDAXz4 fGSjbk9RIJEDtafEYY7rEf8RJV5WyXpzEQwlnKSmXFwkLgULP33jSnG2qpxSjE8pLGFvwmrijl3 s1uyMF9yyeNNV/vHMwngjXH0kzo6JyrFir7BKSrnWQ4vfiET40ubqWj3vNgTFBP8= X-Received: by 2002:a05:6402:5054:b0:69a:2ee6:4c95 with SMTP id 4fb4d7f45d1cf-69e65163b60mr7350547a12.0.1784723409282; Wed, 22 Jul 2026 05:30:09 -0700 (PDT) Received: from DW927H4LGF ([2a09:bac6:37e6:1e5a::306:2]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-69f34f1b867sm835007a12.14.2026.07.22.05.30.08 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 22 Jul 2026 05:30:08 -0700 (PDT) From: Oxana Kharitonova To: mic@digikod.net, gnoack@google.com Cc: paul@paul-moore.com, jmorris@namei.or, serge@hallyn.com, wangyan01@kylinos.cn, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, landlock@lists.linux.dev, oxana@cloudflare.com, webprosto@gmail.com Subject: [PATCH 5/6] samples/landlock: Support POSIX message queue scoping Date: Wed, 22 Jul 2026 13:29:41 +0100 Message-ID: <20260722122952.42149-6-oxana@cloudflare.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260722122952.42149-1-oxana@cloudflare.com> References: <20260722122952.42149-1-oxana@cloudflare.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Teach the sandboxer sample to request LANDLOCK_SCOPE_POSIX_MSG_QUEUE through LL_SCOPED. Add the "q" scope selector for POSIX message queues and document it in the sample help text. Also allow POSIX message queue denials to be quieted with "posix_msg_queue" through LL_QUIET_ACCESS. Signed-off-by: Oxana Kharitonova --- samples/landlock/sandboxer.c | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/samples/landlock/sandboxer.c b/samples/landlock/sandboxer.c index ac71019e6212..59024ca53398 100644 --- a/samples/landlock/sandboxer.c +++ b/samples/landlock/sandboxer.c @@ -240,10 +240,12 @@ static bool check_ruleset_scope(const char *const env= _var, bool error =3D false; bool abstract_scoping =3D false; bool signal_scoping =3D false; + bool posix_mqueue_scoping =3D false; =20 /* Scoping is not supported by Landlock ABI */ if (!(ruleset_attr->scoped & - (LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET | LANDLOCK_SCOPE_SIGNAL))) + (LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET | LANDLOCK_SCOPE_SIGNAL | + LANDLOCK_SCOPE_POSIX_MSG_QUEUE))) goto out_unset; =20 env_type_scope =3D getenv(env_var); @@ -260,6 +262,9 @@ static bool check_ruleset_scope(const char *const env_v= ar, } else if (strcmp("s", ipc_scoping_name) =3D=3D 0 && !signal_scoping) { signal_scoping =3D true; + } else if (strcmp("q", ipc_scoping_name) =3D=3D 0 && + !posix_mqueue_scoping) { + posix_mqueue_scoping =3D true; } else { fprintf(stderr, "Unknown or duplicate scope \"%s\"\n", ipc_scoping_name); @@ -276,6 +281,8 @@ static bool check_ruleset_scope(const char *const env_v= ar, ruleset_attr->scoped &=3D ~LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET; if (!signal_scoping) ruleset_attr->scoped &=3D ~LANDLOCK_SCOPE_SIGNAL; + if (!posix_mqueue_scoping) + ruleset_attr->scoped &=3D ~LANDLOCK_SCOPE_POSIX_MSG_QUEUE; =20 unsetenv(env_var); return error; @@ -354,6 +361,9 @@ static int add_quiet_access(const char *const env_var, LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET; else if (strcmp(str_access, "signal") =3D=3D 0) ruleset_attr->quiet_scoped |=3D LANDLOCK_SCOPE_SIGNAL; + else if (strcmp(str_access, "posix_msg_queue") =3D=3D 0) + ruleset_attr->quiet_scoped |=3D + LANDLOCK_SCOPE_POSIX_MSG_QUEUE; else { fprintf(stderr, "Unknown quiet access \"%s\"\n", str_access); @@ -400,6 +410,7 @@ static const char help[] =3D "* " ENV_SCOPED_NAME ": actions denied on the outside of the landlock dom= ain\n" " - \"a\" to restrict opening abstract unix sockets\n" " - \"s\" to restrict sending signals\n" + " - \"q\" to restrict opening POSIX message queues\n" "\n" "A sandboxer should not log denied access requests to avoid spamming logs= , " "but to test audit we can set " ENV_FORCE_LOG_NAME "=3D1\n" @@ -416,6 +427,7 @@ static const char help[] =3D " - \"udp_connect\" to quiet udp connect / send denials\n" " - \"abstract_unix_socket\" to quiet abstract unix socket denials\n" " - \"signal\" to quiet signal denials\n" + " - \"posix_msg_queue\" to quiet POSIX message queue denials\n" "\n" "Example:\n" ENV_FS_RO_NAME "=3D\"${PATH}:/lib:/usr:/proc:/etc:/dev/urandom\" " @@ -423,7 +435,7 @@ static const char help[] =3D ENV_TCP_BIND_NAME "=3D\"9418\" " ENV_TCP_CONNECT_NAME "=3D\"80:443\" " ENV_UDP_CONNECT_SEND_NAME "=3D\"53\" " - ENV_SCOPED_NAME "=3D\"a:s\" " + ENV_SCOPED_NAME "=3D\"a:s:q\" " "%1$s bash -i\n" "\n" "This sandboxer can use Landlock features up to ABI version " --=20 2.50.1 (Apple Git-155) From nobody Fri Jul 24 22:59:13 2026 Received: from mail-ed1-f54.google.com (mail-ed1-f54.google.com [209.85.208.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 358FC375F65 for ; Wed, 22 Jul 2026 12:30:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.54 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723415; cv=none; b=ZHIXVSEeTqWEqOlqhCGQlnPLSFHhnVahMbk2mvjEc5LHLlPrphHxGSG2EXndHwZ/WayGgbGcXMlNWyDB8UGbGtsiMDsHhsRDIso3DKlKIjY8QTxzoMIB+BwADWXbGjB/unXiQ37reH2DqsDpUs8Kd/3XiDqhllxpzHa+shpMCc0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784723415; c=relaxed/simple; bh=XXP6So6EytIRNbavWUyVFlypJEjg8u4P/XJmPMsD3mg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=XHyS03eJgEHr2HilL7NqVNrUqCJ6J4Kl8foJkUJQoxih1UyO69ieaoFLu3RjObGx3DH2s9Og05hmt6G+VOpTELkFD0p5iA/W5p7sE0lr4X5jLUoMD5fe6arnKelXVvsSQrnCqmzJlUs7O5GikpY5ld0Uau7USmo474hIAAEF2tY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com; spf=pass smtp.mailfrom=cloudflare.com; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b=OvNL3QxQ; arc=none smtp.client-ip=209.85.208.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cloudflare.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cloudflare.com header.i=@cloudflare.com header.b="OvNL3QxQ" Received: by mail-ed1-f54.google.com with SMTP id 4fb4d7f45d1cf-6986287534eso22872055a12.3 for ; Wed, 22 Jul 2026 05:30:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cloudflare.com; s=google09082023; t=1784723411; x=1785328211; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=P42HCFpkq11qC2COB01ikocfGvftDj76wdm0yvbU3UM=; b=OvNL3QxQTxJ4/10TiccCe/IxeCcHtK6AT+Z+TrFFD7NYOk1VTYL9HrAYj0pG4KXWpa ndu8vHarLB5XaXIxwlT8geiWSr2XR5jE7GV/EwF15dq9RhJzSbVlwr6XxGmShMBwIfv9 ehthctNHUnxiJHES0GHpal0AaOOsMGSXD+LwQjJX7F+u5PRsD/Z6WIn3xNEthEhdbufF SQJxbtRM7CitP2JtOMjYT6806tlGaVjTLP57w/LjayU41YLa95mwPI6CmnLaQsNZTDGU xz8ZlEAlHdmIp26Yk9h3hbTcZDfUZLp/jSEUIxlfl/Ii/0SWLfT5YC2DiRWVN0wB6Dhm gDIQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784723411; x=1785328211; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=P42HCFpkq11qC2COB01ikocfGvftDj76wdm0yvbU3UM=; b=SjrkLrtAgcvA1QIqtlFRyOD9K3tfiK4ie1g204F/Xf3OeJvq7TghV17JuLvteDV64E VO4SgGNdcUSuxUNACUpKhCjno3YefgjeqMk8hyXGXwKkI2LtT9lZVjAW3xMGAUC7/t9Z 32gmdyuuIqBE5O1QZGQC21CsjtOT6GUTRG4KeBUmTil9FeOpdE5TsUgKybipZu0R9KDC 5Ad0Umj8E+C1ePDriymzwS2mm1QwDjRISIT3mXFse45V9kyIJxWGH08IEELPpu1Uq3GT p4z1E3aE5AS8OVVAAJb/q5ccR9OIinipA/tWIzSlpiU1H8vDbEcdhRA48BCwJz8AVrJz HseQ== X-Forwarded-Encrypted: i=1; AHgh+RrRq11vhwz+jmOo449lK3ufosCj8d/QDWpNolaGYppr0sDN0sSdpU4ujZ/cWqCqS6MWjfhiMSWzBRGjt0Y=@vger.kernel.org X-Gm-Message-State: AOJu0YxTFu4mq+bzmB3QLprX+Fq3/FSZ4kezlmyUsX+V4zwtoEfCLr9a ra30Ga9GCqmAvgVb5ZwYusbfmZGOH5W8PqkLqRbEfVhIntnamCBq6YMqcXCumN3p/bM= X-Gm-Gg: AR+sD11vk0O1DO0yHeGOTAxORCZslL6RQF2jcJlSDMBG0D5noWBi2v7iVBFesmQslSD 8ab+IdgwiWTQEgCu5qKOTICKm8BT5wgqhSCeXvYQwpQtpV66ACZ+WoeGBvqKK+IGYVw+1TwwC86 LPS/4O8QUxM/V4cr1pTA87ji7GQ6y7NDnNYXLjCO+fic5nyL+V31/vnn/OBQ7mjRwn9qd0tv7Qr W0BEsr8rM9gKh5vJoU6a0CYi+8Bxf4sJhDRhx66myvHTlxDi90WOEzHo+/3ua+wwyoXMqSpHAMw gs9wOsyJlnTcH239Zhbqsna4UFJyxjkrx+9tu7b+J91MJz6abZX/RCqkooVG1xZDLJhE33zBoLX KyCzmjx+EwDljJfAi7hyCsbYi9hqy4bZ9Cyc+TydeDjeXmH8rQiYt02xX0MKFijc8FyLzDBVHIQ == X-Received: by 2002:a05:6402:4402:b0:69c:9197:4413 with SMTP id 4fb4d7f45d1cf-69e652dfccemr9233139a12.36.1784723410993; Wed, 22 Jul 2026 05:30:10 -0700 (PDT) Received: from DW927H4LGF ([2a09:bac6:37e6:1e5a::306:2]) by smtp.gmail.com with ESMTPSA id 4fb4d7f45d1cf-69f34f1b867sm835007a12.14.2026.07.22.05.30.09 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 22 Jul 2026 05:30:10 -0700 (PDT) From: Oxana Kharitonova To: mic@digikod.net, gnoack@google.com Cc: paul@paul-moore.com, jmorris@namei.or, serge@hallyn.com, wangyan01@kylinos.cn, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, landlock@lists.linux.dev, oxana@cloudflare.com, webprosto@gmail.com Subject: [PATCH 6/6] landlock: Document POSIX message queue scoping Date: Wed, 22 Jul 2026 13:29:42 +0100 Message-ID: <20260722122952.42149-7-oxana@cloudflare.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260722122952.42149-1-oxana@cloudflare.com> References: <20260722122952.42149-1-oxana@cloudflare.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Document LANDLOCK_SCOPE_POSIX_MSG_QUEUE in the userspace API and UAPI kernel-doc. Signed-off-by: Oxana Kharitonova --- Documentation/admin-guide/LSM/landlock.rst | 6 ++++-- Documentation/userspace-api/landlock.rst | 11 ++++++++++- include/uapi/linux/landlock.h | 6 +++++- 3 files changed, 19 insertions(+), 4 deletions(-) diff --git a/Documentation/admin-guide/LSM/landlock.rst b/Documentation/adm= in-guide/LSM/landlock.rst index 8eb85c9381ff..1ecb2017271b 100644 --- a/Documentation/admin-guide/LSM/landlock.rst +++ b/Documentation/admin-guide/LSM/landlock.rst @@ -60,9 +60,11 @@ AUDIT_LANDLOCK_ACCESS - net.bind_udp - UDP port binding was denied - net.connect_send_udp - UDP connection and send was denied =20 - **scope.*** - IPC scoping restrictions (ABI 6+): + **scope.*** - IPC scoping restrictions: - scope.abstract_unix_socket - Abstract UNIX socket connection den= ied - - scope.signal - Signal sending denied + (ABI 6+) + - scope.signal - Signal sending denied (ABI 6+) + - scope.posix_msg_queue - POSIX message queue opening denied (ABI = 11+) =20 Multiple blockers can appear in a single event (comma-separated) when multiple access rights are missing. For example, creating a regular fi= le diff --git a/Documentation/userspace-api/landlock.rst b/Documentation/users= pace-api/landlock.rst index 5a63d4476c1c..c4fa84e6d281 100644 --- a/Documentation/userspace-api/landlock.rst +++ b/Documentation/userspace-api/landlock.rst @@ -86,7 +86,8 @@ to be explicit about the denied-by-default access rights. LANDLOCK_ACCESS_NET_CONNECT_SEND_UDP, .scoped =3D LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET | - LANDLOCK_SCOPE_SIGNAL, + LANDLOCK_SCOPE_SIGNAL | + LANDLOCK_SCOPE_POSIX_MSG_QUEUE, }; =20 Because we may not know which kernel version an application will be execut= ed @@ -140,6 +141,10 @@ version, and only use the available subset of access r= ights: ruleset_attr.handled_access_net &=3D ~(LANDLOCK_ACCESS_NET_BIND_UDP | LANDLOCK_ACCESS_NET_CONNECT_SEND_UDP); + __attribute__((fallthrough)); + case 10: + /* Removes LANDLOCK_SCOPE_POSIX_MSG_QUEUE for ABI < 11 */ + ruleset_attr.scoped &=3D ~LANDLOCK_SCOPE_POSIX_MSG_QUEUE; } =20 This enables the creation of an inclusive ruleset that will contain our ru= les. @@ -420,6 +425,10 @@ The operations which can be scoped are: A :manpage:`sendto(2)` on a socket which was previously connected will= not be restricted. This works for both datagram and stream sockets. =20 +``LANDLOCK_SCOPE_POSIX_MSG_QUEUE`` + This limits opening POSIX message queues to queues created by a proces= s in + the same or a nested Landlock domain. + IPC scoping does not support exceptions via :manpage:`landlock_add_rule(2)= `. If an operation is scoped within a domain, no rules can be added to allow = access to resources or processes outside of the scope. diff --git a/include/uapi/linux/landlock.h b/include/uapi/linux/landlock.h index 96d0c3b423ac..21ba31ad4d4b 100644 --- a/include/uapi/linux/landlock.h +++ b/include/uapi/linux/landlock.h @@ -478,7 +478,9 @@ struct landlock_net_port_attr { * Setting a flag for a ruleset will isolate the Landlock domain to forbid * connections to resources outside the domain. * - * This is supported since Landlock ABI version 6. + * This is supported since Landlock ABI version 6. The + * %LANDLOCK_SCOPE_POSIX_MSG_QUEUE scope is supported since Landlock ABI v= ersion + * 11. * * Scopes: * @@ -487,6 +489,8 @@ struct landlock_net_port_attr { * related Landlock domain (e.g., a parent domain or a non-sandboxed pro= cess). * - %LANDLOCK_SCOPE_SIGNAL: Restrict a sandboxed process from sending a s= ignal * to another process outside the domain. + * - %LANDLOCK_SCOPE_POSIX_MSG_QUEUE: Restrict a sandboxed process from op= ening + * a POSIX message queue created outside the domain. */ /* clang-format off */ #define LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET (1ULL << 0) --=20 2.50.1 (Apple Git-155)