|
|
Log in / Subscribe / Register

landlock: documentation improvements

From:  Samasth Norway Ananda <samasth.norway.ananda-AT-oracle.com>
To:  gnoack-AT-google.com, mic-AT-digikod.net
Subject:  [PATCH v3 0/3] landlock: documentation improvements
Date:  Tue, 27 Jan 2026 19:18:09 -0800
Message-ID:  <20260128031814.2945394-1-samasth.norway.ananda@oracle.com>
Cc:  linux-security-module-AT-vger.kernel.org, linux-kernel-AT-vger.kernel.org, samasth.norway.ananda-AT-oracle.com
Archive-link:  Article

This patch series improves Landlock documentation by addressing gaps in
ABI compatibility examples, adding errata documentation, and documenting
the audit blockers field format.

Changes since v2:
=================

Patch 1/3:
- Handle restrict_flags in a separate code block, not in the switch
- Clear all three ABI v7 logging flags for a generic example
- Reference sys_landlock_restrict_self() for available flags
- Use restrict_flags in landlock_restrict_self()

Patch 2/3:
- Use kernel-doc directives to include errata from header files
- Move rephrased ABI version text before errata section

Patch 3/3:
- No changes

Changes since v1:
=================

Patch 1/3:
- Add backwards compatibility section for restrict flags
- Fix /usr rule description

Patch 2/3:
- Enhance existing DOC sections with Impact descriptions
- Add errata usage documentation

Patch 3/3:
- Document audit blocker field format

Samasth Norway Ananda (3):
  landlock: add backwards compatibility for restrict flags
  landlock: add errata documentation section
  landlock: document audit blockers field format

 Documentation/admin-guide/LSM/landlock.rst | 20 ++++-
 Documentation/userspace-api/landlock.rst   | 97 +++++++++++++++++++---
 security/landlock/errata/abi-1.h           |  8 ++
 security/landlock/errata/abi-4.h           |  7 ++
 security/landlock/errata/abi-6.h           | 10 +++
 security/landlock/syscalls.c               |  4 +-
 6 files changed, 131 insertions(+), 15 deletions(-)

-- 
2.50.1




Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds