/usr/include/linux
NameSizeModeActions
android/-0755rm
byteorder/-0755rm
caif/-0755rm
can/-0755rm
cifs/-0755rm
dvb/-0755rm
genwqe/-0755rm
hdlc/-0755rm
hsi/-0755rm
iio/-0755rm
isdn/-0755rm
misc/-0755rm
mmc/-0755rm
netfilter/-0755rm
netfilter_arp/-0755rm
netfilter_bridge/-0755rm
netfilter_ipv4/-0755rm
netfilter_ipv6/-0755rm
nfsd/-0755rm
raid/-0755rm
sched/-0755rm
spi/-0755rm
sunrpc/-0755rm
surface_aggregator/-0755rm
tc_act/-0755rm
tc_ematch/-0755rm
usb/-0755rm
a.out.h68920644editdlrm
acct.h39130644editdlrm
acrn.h166860644editdlrm
adb.h11400644editdlrm
adfs_fs.h9930644editdlrm
affs_hardblocks.h15780644editdlrm
agpgart.h39400644editdlrm
aio_abi.h33980644editdlrm
am437x-vpfe.h36810644editdlrm
apm_bios.h36830644editdlrm
arcfb.h2130644editdlrm
arm_sdei.h27510644editdlrm
aspeed-lpc-ctrl.h17800644editdlrm
aspeed-p2a-ctrl.h19060644editdlrm
atalk.h10230644editdlrm
atm.h78880644editdlrm
atmapi.h9520644editdlrm
atmarp.h12960644editdlrm
atmbr2684.h32710644editdlrm
atmclip.h5760644editdlrm
atmdev.h76770644editdlrm
atmioc.h16470644editdlrm
atmlec.h23810644editdlrm
atmmpc.h42260644editdlrm
atmppp.h6390644editdlrm
atmsap.h49700644editdlrm
atmsvc.h18530644editdlrm
atm_eni.h6480644editdlrm
atm_he.h4060644editdlrm
atm_idt77105.h9550644editdlrm
atm_nicstar.h12780644editdlrm
atm_tcp.h16220644editdlrm
atm_zatm.h15400644editdlrm
audit.h215700644editdlrm
auto_dev-ioctl.h49860644editdlrm
auto_fs.h64280644editdlrm
auto_fs4.h4510644editdlrm
auxvec.h15970644editdlrm
ax25.h28240644editdlrm
batadv_packet.h203450644editdlrm
batman_adv.h168870644editdlrm
baycom.h8830644editdlrm
bcm933xx_hcs.h4190644editdlrm
bfs_fs.h19050644editdlrm
binfmts.h7760644editdlrm
bits.h4470644editdlrm
blkdev.h3590644editdlrm
blkpg.h9040644editdlrm
blktrace_api.h47010644editdlrm
blkzoned.h64930644editdlrm
bpf.h2786730644editdlrm
bpfilter.h4650644editdlrm
bpf_common.h13670644editdlrm
bpf_perf_event.h5290644editdlrm
bpqether.h9810644editdlrm
bsg.h24940644editdlrm
bt-bmc.h5720644editdlrm
btf.h55910644editdlrm
btrfs.h305700644editdlrm
btrfs_tree.h258290644editdlrm
cachefiles.h16500644editdlrm
can.h114960644editdlrm
capability.h134910644editdlrm
capi.h31240644editdlrm
cciss_defs.h32810644editdlrm
cciss_ioctl.h27610644editdlrm
ccs.h7670644editdlrm
cdrom.h295610644editdlrm
cec-funcs.h544190644editdlrm
cec.h414370644editdlrm
cfm_bridge.h14560644editdlrm
cgroupstats.h22190644editdlrm
chio.h52820644editdlrm
close_range.h3770644editdlrm
cm4000_cs.h18060644editdlrm
cn_proc.h41490644editdlrm
coda.h182160644editdlrm
coff.h125490644editdlrm
connector.h22530644editdlrm
const.h9870644editdlrm
coresight-stm.h7470644editdlrm
cramfs_fs.h35550644editdlrm
cryptouser.h53210644editdlrm
cuda.h9050644editdlrm
cxl_mem.h79150644editdlrm
cycx_cfm.h29900644editdlrm
dcbnl.h252920644editdlrm
dccp.h64360644editdlrm
devlink.h238230644editdlrm
dlm.h25530644editdlrm
dlmconstants.h50800644editdlrm
dlm_device.h25430644editdlrm
dlm_netlink.h11590644editdlrm
dlm_plock.h8940644editdlrm
dm-ioctl.h117530644editdlrm
dm-log-userspace.h151910644editdlrm
dma-buf.h52470644editdlrm
dma-heap.h13940644editdlrm
dn.h46420644editdlrm
dns_resolver.h39490644editdlrm
dpll.h96690644editdlrm
dqblk_xfs.h93880644editdlrm
edd.h56040644editdlrm
efs_fs_sb.h22270644editdlrm
elf-em.h26270644editdlrm
elf-fdpic.h11240644editdlrm
elf.h153280644editdlrm
errno.h230644editdlrm
errqueue.h19830644editdlrm
erspan.h10590644editdlrm
ethtool.h1040920644editdlrm
ethtool_netlink.h63140644editdlrm
ethtool_netlink_generated.h196260644editdlrm
eventfd.h2640644editdlrm
eventpoll.h29130644editdlrm
f2fs.h33010644editdlrm
fadvise.h8420644editdlrm
falloc.h36430644editdlrm
fanotify.h78860644editdlrm
fb.h164770644editdlrm
fcntl.h43190644editdlrm
fd.h121170644editdlrm
fdreg.h53640644editdlrm
fib_rules.h20360644editdlrm
fiemap.h27750644editdlrm
filter.h22160644editdlrm
firewire-cdev.h442400644editdlrm
firewire-constants.h32310644editdlrm
fou.h8190644editdlrm
fpga-dfl.h87280644editdlrm
fs.h135470644editdlrm
fscrypt.h65650644editdlrm
fsi.h22550644editdlrm
fsl_hypervisor.h73010644editdlrm
fsl_mc.h7340644editdlrm
fsmap.h43930644editdlrm
fsverity.h31850644editdlrm
fuse.h259680644editdlrm
futex.h63770644editdlrm
gameport.h8970644editdlrm
genetlink.h22380644editdlrm
gen_stats.h15260644editdlrm
gfs2_ondisk.h147730644editdlrm
gpio.h199220644editdlrm
gsmmux.h45090644editdlrm
gtp.h7340644editdlrm
handshake.h16460644editdlrm
hash_info.h9710644editdlrm
hdlc.h6370644editdlrm
hdlcdrv.h29080644editdlrm
hdreg.h227030644editdlrm
hid.h20860644editdlrm
hiddev.h63450644editdlrm
hidraw.h19930644editdlrm
hpet.h7430644editdlrm
hsr_netlink.h11010644editdlrm
hw_breakpoint.h7420644editdlrm
hyperv.h111520644editdlrm
i2c-dev.h18750644editdlrm
i2c.h68900644editdlrm
i2o-dev.h115550644editdlrm
i8k.h15280644editdlrm
icmp.h47850644editdlrm
icmpv6.h43000644editdlrm
idxd.h93280644editdlrm
if.h109250644editdlrm
ife.h3510644editdlrm
if_addr.h18860644editdlrm
if_addrlabel.h7210644editdlrm
if_alg.h15660644editdlrm
if_arcnet.h37170644editdlrm
if_arp.h65650644editdlrm
if_bonding.h51450644editdlrm
if_bridge.h207550644editdlrm
if_cablemodem.h9860644editdlrm
if_eql.h13490644editdlrm
if_ether.h84100644editdlrm
if_fc.h17380644editdlrm
if_fddi.h43690644editdlrm
if_hippi.h42350644editdlrm
if_infiniband.h12450644editdlrm
if_link.h542440644editdlrm
if_ltalk.h2100644editdlrm
if_macsec.h65030644editdlrm
if_packet.h81830644editdlrm
if_phonet.h4240644editdlrm
if_plip.h6600644editdlrm
if_ppp.h290644editdlrm
if_pppol2tp.h33030644editdlrm
if_pppox.h48790644editdlrm
if_slip.h8720644editdlrm
if_team.h26000644editdlrm
if_tun.h40980644editdlrm
if_tunnel.h54880644editdlrm
if_vlan.h18310644editdlrm
if_x25.h8810644editdlrm
if_xdp.h54140644editdlrm
igmp.h30640644editdlrm
ila.h12460644editdlrm
in.h104860644editdlrm
in6.h75370644editdlrm
inet_diag.h50170644editdlrm
inotify.h32920644editdlrm
input-event-codes.h302710644editdlrm
input.h162400644editdlrm
in_route.h9360644editdlrm
ioctl.h1630644editdlrm
iommufd.h489220644editdlrm
ioprio.h41750644editdlrm
io_uring.h250630644editdlrm
ip.h48130644editdlrm
ip6_tunnel.h19530644editdlrm
ipc.h21010644editdlrm
ipmi.h154420644editdlrm
ipmi_bmc.h4880644editdlrm
ipmi_msgdefs.h34300644editdlrm
ipmi_ssif_bmc.h4410644editdlrm
ipsec.h9470644editdlrm
ipv6.h41690644editdlrm
ipv6_route.h19080644editdlrm
ipx.h23470644editdlrm
ip_vs.h141350644editdlrm
irqnr.h1040644editdlrm
iso_fs.h64850644editdlrm
isst_if.h161790644editdlrm
ivtv.h30220644editdlrm
ivtvfb.h12070644editdlrm
jffs2.h68150644editdlrm
joystick.h34340644editdlrm
kcm.h8220644editdlrm
kcmp.h5220644editdlrm
kcov.h19630644editdlrm
kd.h64520644editdlrm
kdev_t.h3830644editdlrm
kernel-page-flags.h9000644editdlrm
kernel.h1940644editdlrm
kernelcapi.h10190644editdlrm
kexec.h20970644editdlrm
keyboard.h134590644editdlrm
keyctl.h59960644editdlrm
kfd_ioctl.h585720644editdlrm
kfd_sysfs.h53790644editdlrm
kvm.h483720644editdlrm
kvm_para.h10010644editdlrm
l2tp.h57460644editdlrm
landlock.h118280644editdlrm
libc-compat.h82890644editdlrm
limits.h9370644editdlrm
lirc.h81440644editdlrm
llc.h31640644editdlrm
loadpin.h8340644editdlrm
loop.h33960644editdlrm
lp.h41900644editdlrm
lsm.h15490644editdlrm
lwtunnel.h23670644editdlrm
magic.h38700644editdlrm
major.h46570644editdlrm
map_to_7segment.h66080644editdlrm
matroxfb.h14640644editdlrm
max2175.h10350644editdlrm
mdio.h243920644editdlrm
media-bus-format.h69090644editdlrm
media.h127540644editdlrm
mei.h34790644editdlrm
mei_uuid.h7380644editdlrm
membarrier.h93620644editdlrm
memfd.h14670644editdlrm
mempolicy.h25680644editdlrm
meye.h25290644editdlrm
mii.h94960644editdlrm
minix_fs.h21220644editdlrm
mman.h17870644editdlrm
mmtimer.h21170644editdlrm
module.h2930644editdlrm
mount.h50190644editdlrm
mpls.h23020644editdlrm
mpls_iptunnel.h7610644editdlrm
mptcp.h37630644editdlrm
mptcp_pm.h44070644editdlrm
mqueue.h22010644editdlrm
mroute.h59220644editdlrm
mroute6.h49300644editdlrm
mrp_bridge.h17080644editdlrm
msdos_fs.h67310644editdlrm
msg.h33860644editdlrm
mshv.h81220644editdlrm
mtio.h81750644editdlrm
nbd-netlink.h24080644editdlrm
nbd.h38620644editdlrm
ncsi.h48280644editdlrm
ndctl.h68290644editdlrm
neighbour.h60540644editdlrm
net.h20850644editdlrm
netconf.h6140644editdlrm
netdev.h57860644editdlrm
netdevice.h22530644editdlrm
netfilter.h17310644editdlrm
netfilter_arp.h4450644editdlrm
netfilter_bridge.h11680644editdlrm
netfilter_decnet.h17580644editdlrm
netfilter_ipv4.h14880644editdlrm
netfilter_ipv6.h13830644editdlrm
netlink.h123810644editdlrm
netlink_diag.h15240644editdlrm
netrom.h8070644editdlrm
net_dropmon.h29220644editdlrm
net_namespace.h7150644editdlrm
net_shaper.h25830644editdlrm
net_tstamp.h64550644editdlrm
nexthop.h40660644editdlrm
nfc.h112090644editdlrm
nfs.h44630644editdlrm
nfs2.h14680644editdlrm
nfs3.h24530644editdlrm
nfs4.h66950644editdlrm
nfs4_mount.h19320644editdlrm
nfsacl.h7180644editdlrm
nfsd_netlink.h19950644editdlrm
nfs_fs.h16540644editdlrm
nfs_idmap.h22430644editdlrm
nfs_mount.h21420644editdlrm
nilfs2_api.h75890644editdlrm
nilfs2_ondisk.h180850644editdlrm
nitro_enclaves.h131610644editdlrm
nl80211.h3639480644editdlrm
nsfs.h6390644editdlrm
nubus.h81910644editdlrm
nvme_ioctl.h24900644editdlrm
nvram.h5320644editdlrm
omap3isp.h208530644editdlrm
omapfb.h59180644editdlrm
oom.h5110644editdlrm
openat2.h14500644editdlrm
openvswitch.h417330644editdlrm
packet_diag.h16720644editdlrm
param.h1410644editdlrm
parport.h36440644editdlrm
patchkey.h8920644editdlrm
pci.h13800644editdlrm
pcitest.h9200644editdlrm
pci_regs.h633740644editdlrm
perf_event.h437090644editdlrm
personality.h20970644editdlrm
pfkeyv2.h105690644editdlrm
pfrut.h80030644editdlrm
pg.h23940644editdlrm
phantom.h16540644editdlrm
phonet.h46770644editdlrm
pidfd.h30930644editdlrm
pktcdvd.h26980644editdlrm
pkt_cls.h190960644editdlrm
pkt_sched.h294430644editdlrm
pmu.h54440644editdlrm
poll.h220644editdlrm
posix_acl.h12540644editdlrm
posix_acl_xattr.h11150644editdlrm
posix_types.h10980644editdlrm
ppdev.h32850644editdlrm
ppp-comp.h25270644editdlrm
ppp-ioctl.h57290644editdlrm
ppp_defs.h55570644editdlrm
pps.h47340644editdlrm
pr.h16300644editdlrm
prctl.h111910644editdlrm
psample.h26340644editdlrm
psci.h53400644editdlrm
psp-dbc.h52790644editdlrm
psp-sev.h81590644editdlrm
ptp_clock.h75270644editdlrm
ptrace.h43960644editdlrm
qemu_fw_cfg.h24690644editdlrm
qnx4_fs.h23280644editdlrm
qnxtypes.h6240644editdlrm
qrtr.h8930644editdlrm
quota.h63120644editdlrm
radeonfb.h3600644editdlrm
random.h14150644editdlrm
rds.h111680644editdlrm
reboot.h13430644editdlrm
reiserfs_fs.h7750644editdlrm
reiserfs_xattr.h5330644editdlrm
remoteproc_cdev.h11020644editdlrm
resource.h23730644editdlrm
rfkill.h66080644editdlrm
rio_cm_cdev.h32480644editdlrm
rio_mport_cdev.h93300644editdlrm
rkisp1-config.h313620644editdlrm
romfs_fs.h12380644editdlrm
rose.h22320644editdlrm
route.h23320644editdlrm
rpl.h8140644editdlrm
rpl_iptunnel.h4240644editdlrm
rpmsg.h10540644editdlrm
rpmsg_types.h2880644editdlrm
rseq.h49040644editdlrm
rtc.h53160644editdlrm
rtnetlink.h213000644editdlrm
rxrpc.h49220644editdlrm
scc.h46240644editdlrm
sched.h62660644editdlrm
scif_ioctl.h63820644editdlrm
screen_info.h24790644editdlrm
sctp.h360220644editdlrm
seccomp.h57320644editdlrm
securebits.h27040644editdlrm
sed-opal.h54140644editdlrm
seg6.h11700644editdlrm
seg6_genl.h5890644editdlrm
seg6_hmac.h4230644editdlrm
seg6_iptunnel.h9840644editdlrm
seg6_local.h38670644editdlrm
selinux_netlink.h11950644editdlrm
sem.h30510644editdlrm
serial.h50190644editdlrm
serial_core.h50460644editdlrm
serial_reg.h160230644editdlrm
serio.h21390644editdlrm
sev-guest.h25260644editdlrm
shm.h37940644editdlrm
signal.h3880644editdlrm
signalfd.h12330644editdlrm
smc.h89010644editdlrm
smc_diag.h29510644editdlrm
smiapp.h10580644editdlrm
snmp.h143470644editdlrm
socket.h9190644editdlrm
sockios.h68460644editdlrm
sock_diag.h13010644editdlrm
sonet.h22900644editdlrm
sonypi.h53090644editdlrm
sound.h12370644editdlrm
soundcard.h460380644editdlrm
stat.h74040644editdlrm
stddef.h17260644editdlrm
stm.h12750644editdlrm
string.h2380644editdlrm
suspend_ioctls.h14310644editdlrm
swab.h69210644editdlrm
switchtec_ioctl.h52620644editdlrm
synclink.h89850644editdlrm
sync_file.h35780644editdlrm
sysctl.h259100644editdlrm
sysinfo.h10490644editdlrm
target_core_user.h46330644editdlrm
taskstats.h83220644editdlrm
tcp.h119860644editdlrm
tcp_metrics.h19850644editdlrm
tdx-guest.h13050644editdlrm
tee.h134050644editdlrm
termios.h1720644editdlrm
thermal.h33100644editdlrm
time.h17520644editdlrm
timerfd.h9360644editdlrm
times.h2780644editdlrm
timex.h78170644editdlrm
time_types.h12670644editdlrm
tiocl.h17290644editdlrm
tipc.h88250644editdlrm
tipc_config.h148640644editdlrm
tipc_netlink.h93950644editdlrm
tipc_sockets_diag.h4680644editdlrm
tls.h72260644editdlrm
toshiba.h19300644editdlrm
tps6594_pfsm.h11600644editdlrm
tty.h15850644editdlrm
tty_flags.h45010644editdlrm
types.h16360644editdlrm
udf_fs_i.h6970644editdlrm
udmabuf.h6430644editdlrm
udp.h16880644editdlrm
uhid.h46480644editdlrm
uinput.h92610644editdlrm
uio.h7320644editdlrm
uleds.h7980644editdlrm
ultrasound.h45620644editdlrm
um_timetravel.h39610644editdlrm
un.h3840644editdlrm
unistd.h2200644editdlrm
unix_diag.h13280644editdlrm
usbdevice_fs.h83170644editdlrm
usbip.h15030644editdlrm
userfaultfd.h109400644editdlrm
userio.h15160644editdlrm
utime.h2230644editdlrm
utsname.h6690644editdlrm
uuid.h280644editdlrm
uvcvideo.h26270644editdlrm
v4l2-common.h20560644editdlrm
v4l2-controls.h968600644editdlrm
v4l2-dv-timings.h311230644editdlrm
v4l2-mediabus.h54310644editdlrm
v4l2-subdev.h99980644editdlrm
vboxguest.h93680644editdlrm
vbox_err.h72570644editdlrm
vbox_vmmdev_types.h116510644editdlrm
vdpa.h17850644editdlrm
vduse.h98080644editdlrm
version.h3740644editdlrm
veth.h2240644editdlrm
vfio.h718400644editdlrm
vfio_ccw.h13170644editdlrm
vfio_zdev.h25420644editdlrm
vhost.h84380644editdlrm
vhost_types.h48820644editdlrm
videodev2.h1016850644editdlrm
virtio_9p.h20530644editdlrm
virtio_balloon.h52790644editdlrm
virtio_blk.h99790644editdlrm
virtio_bt.h9100644editdlrm
virtio_config.h44610644editdlrm
virtio_console.h31560644editdlrm
virtio_crypto.h138870644editdlrm
virtio_fs.h5730644editdlrm
virtio_gpio.h17380644editdlrm
virtio_gpu.h116060644editdlrm
virtio_i2c.h11860644editdlrm
virtio_ids.h37930644editdlrm
virtio_input.h25150644editdlrm
virtio_iommu.h39310644editdlrm
virtio_mem.h71570644editdlrm
virtio_mmio.h49690644editdlrm
virtio_net.h150780644editdlrm
virtio_pci.h74800644editdlrm
virtio_pcidev.h23890644editdlrm
virtio_pmem.h6410644editdlrm
virtio_ring.h87240644editdlrm
virtio_rng.h2650644editdlrm
virtio_scmi.h6370644editdlrm
virtio_scsi.h60850644editdlrm
virtio_snd.h131700644editdlrm
virtio_types.h21530644editdlrm
virtio_vsock.h33480644editdlrm
vmcore.h4550644editdlrm
vm_sockets.h73540644editdlrm
vm_sockets_diag.h9630644editdlrm
vsockmon.h18850644editdlrm
vt.h30590644editdlrm
vtpm_proxy.h17190644editdlrm
wait.h6820644editdlrm
watchdog.h23350644editdlrm
watch_queue.h34900644editdlrm
wireguard.h77480644editdlrm
wireless.h427040644editdlrm
wmi.h17610644editdlrm
wwan.h2950644editdlrm
x25.h35620644editdlrm
xattr.h30230644editdlrm
xdp_diag.h14680644editdlrm
xfrm.h126210644editdlrm
xilinx-v4l2-controls.h29760644editdlrm
zorro.h32960644editdlrm
zorro_ids.h299630644editdlrm
Edit: /usr/include/linux/landlock.h (11828B)
/* SPDX-License-Identifier: GPL-2.0 WITH Linux-syscall-note */ /* * Landlock - User space API * * Copyright © 2017-2020 Mickaël Salaün * Copyright © 2018-2020 ANSSI */ #ifndef _LINUX_LANDLOCK_H #define _LINUX_LANDLOCK_H #include /** * struct landlock_ruleset_attr - Ruleset definition. * * Argument of sys_landlock_create_ruleset(). * * This structure defines a set of *handled access rights*, a set of actions on * different object types, which should be denied by default when the ruleset is * enacted. Vice versa, access rights that are not specifically listed here are * not going to be denied by this ruleset when it is enacted. * * For historical reasons, the %LANDLOCK_ACCESS_FS_REFER right is always denied * by default, even when its bit is not set in @handled_access_fs. In order to * add new rules with this access right, the bit must still be set explicitly * (cf. `Filesystem flags`_). * * The explicit listing of *handled access rights* is required for backwards * compatibility reasons. In most use cases, processes that use Landlock will * *handle* a wide range or all access rights that they know about at build time * (and that they have tested with a kernel that supported them all). * * This structure can grow in future Landlock versions. */ struct landlock_ruleset_attr { /** * @handled_access_fs: Bitmask of handled filesystem actions * (cf. `Filesystem flags`_). */ __u64 handled_access_fs; /** * @handled_access_net: Bitmask of handled network actions (cf. `Network * flags`_). */ __u64 handled_access_net; /** * @scoped: Bitmask of scopes (cf. `Scope flags`_) * restricting a Landlock domain from accessing outside * resources (e.g. IPCs). */ __u64 scoped; }; /* * sys_landlock_create_ruleset() flags: * * - %LANDLOCK_CREATE_RULESET_VERSION: Get the highest supported Landlock ABI * version. * - %LANDLOCK_CREATE_RULESET_ERRATA: Get a bitmask of fixed issues. */ /* clang-format off */ #define LANDLOCK_CREATE_RULESET_VERSION (1U << 0) #define LANDLOCK_CREATE_RULESET_ERRATA (1U << 1) /* clang-format on */ /** * enum landlock_rule_type - Landlock rule type * * Argument of sys_landlock_add_rule(). */ enum landlock_rule_type { /** * @LANDLOCK_RULE_PATH_BENEATH: Type of a &struct * landlock_path_beneath_attr . */ LANDLOCK_RULE_PATH_BENEATH = 1, /** * @LANDLOCK_RULE_NET_PORT: Type of a &struct * landlock_net_port_attr . */ LANDLOCK_RULE_NET_PORT, }; /** * struct landlock_path_beneath_attr - Path hierarchy definition * * Argument of sys_landlock_add_rule(). */ struct landlock_path_beneath_attr { /** * @allowed_access: Bitmask of allowed actions for this file hierarchy * (cf. `Filesystem flags`_). */ __u64 allowed_access; /** * @parent_fd: File descriptor, preferably opened with ``O_PATH``, * which identifies the parent directory of a file hierarchy, or just a * file. */ __s32 parent_fd; /* * This struct is packed to avoid trailing reserved members. * Cf. security/landlock/syscalls.c:build_check_abi() */ } __attribute__((packed)); /** * struct landlock_net_port_attr - Network port definition * * Argument of sys_landlock_add_rule(). */ struct landlock_net_port_attr { /** * @allowed_access: Bitmask of allowed network actions for a port * (cf. `Network flags`_). */ __u64 allowed_access; /** * @port: Network port in host endianness. * * It should be noted that port 0 passed to :manpage:`bind(2)` will bind * to an available port from the ephemeral port range. This can be * configured with the ``/proc/sys/net/ipv4/ip_local_port_range`` sysctl * (also used for IPv6). * * A Landlock rule with port 0 and the ``LANDLOCK_ACCESS_NET_BIND_TCP`` * right means that requesting to bind on port 0 is allowed and it will * automatically translate to binding on the related port range. */ __u64 port; }; /** * DOC: fs_access * * A set of actions on kernel objects may be defined by an attribute (e.g. * &struct landlock_path_beneath_attr) including a bitmask of access. * * Filesystem flags * ~~~~~~~~~~~~~~~~ * * These flags enable to restrict a sandboxed process to a set of actions on * files and directories. Files or directories opened before the sandboxing * are not subject to these restrictions. * * The following access rights apply only to files: * * - %LANDLOCK_ACCESS_FS_EXECUTE: Execute a file. * - %LANDLOCK_ACCESS_FS_WRITE_FILE: Open a file with write access. When * opening files for writing, you will often additionally need the * %LANDLOCK_ACCESS_FS_TRUNCATE right. In many cases, these system calls * truncate existing files when overwriting them (e.g., :manpage:`creat(2)`). * - %LANDLOCK_ACCESS_FS_READ_FILE: Open a file with read access. * - %LANDLOCK_ACCESS_FS_TRUNCATE: Truncate a file with :manpage:`truncate(2)`, * :manpage:`ftruncate(2)`, :manpage:`creat(2)`, or :manpage:`open(2)` with * ``O_TRUNC``. This access right is available since the third version of the * Landlock ABI. * * Whether an opened file can be truncated with :manpage:`ftruncate(2)` or used * with `ioctl(2)` is determined during :manpage:`open(2)`, in the same way as * read and write permissions are checked during :manpage:`open(2)` using * %LANDLOCK_ACCESS_FS_READ_FILE and %LANDLOCK_ACCESS_FS_WRITE_FILE. * * A directory can receive access rights related to files or directories. The * following access right is applied to the directory itself, and the * directories beneath it: * * - %LANDLOCK_ACCESS_FS_READ_DIR: Open a directory or list its content. * * However, the following access rights only apply to the content of a * directory, not the directory itself: * * - %LANDLOCK_ACCESS_FS_REMOVE_DIR: Remove an empty directory or rename one. * - %LANDLOCK_ACCESS_FS_REMOVE_FILE: Unlink (or rename) a file. * - %LANDLOCK_ACCESS_FS_MAKE_CHAR: Create (or rename or link) a character * device. * - %LANDLOCK_ACCESS_FS_MAKE_DIR: Create (or rename) a directory. * - %LANDLOCK_ACCESS_FS_MAKE_REG: Create (or rename or link) a regular file. * - %LANDLOCK_ACCESS_FS_MAKE_SOCK: Create (or rename or link) a UNIX domain * socket. * - %LANDLOCK_ACCESS_FS_MAKE_FIFO: Create (or rename or link) a named pipe. * - %LANDLOCK_ACCESS_FS_MAKE_BLOCK: Create (or rename or link) a block device. * - %LANDLOCK_ACCESS_FS_MAKE_SYM: Create (or rename or link) a symbolic link. * - %LANDLOCK_ACCESS_FS_REFER: Link or rename a file from or to a different * directory (i.e. reparent a file hierarchy). * * This access right is available since the second version of the Landlock * ABI. * * This is the only access right which is denied by default by any ruleset, * even if the right is not specified as handled at ruleset creation time. * The only way to make a ruleset grant this right is to explicitly allow it * for a specific directory by adding a matching rule to the ruleset. * * In particular, when using the first Landlock ABI version, Landlock will * always deny attempts to reparent files between different directories. * * In addition to the source and destination directories having the * %LANDLOCK_ACCESS_FS_REFER access right, the attempted link or rename * operation must meet the following constraints: * * * The reparented file may not gain more access rights in the destination * directory than it previously had in the source directory. If this is * attempted, the operation results in an ``EXDEV`` error. * * * When linking or renaming, the ``LANDLOCK_ACCESS_FS_MAKE_*`` right for the * respective file type must be granted for the destination directory. * Otherwise, the operation results in an ``EACCES`` error. * * * When renaming, the ``LANDLOCK_ACCESS_FS_REMOVE_*`` right for the * respective file type must be granted for the source directory. Otherwise, * the operation results in an ``EACCES`` error. * * If multiple requirements are not met, the ``EACCES`` error code takes * precedence over ``EXDEV``. * * The following access right applies both to files and directories: * * - %LANDLOCK_ACCESS_FS_IOCTL_DEV: Invoke :manpage:`ioctl(2)` commands on an opened * character or block device. * * This access right applies to all `ioctl(2)` commands implemented by device * drivers. However, the following common IOCTL commands continue to be * invokable independent of the %LANDLOCK_ACCESS_FS_IOCTL_DEV right: * * * IOCTL commands targeting file descriptors (``FIOCLEX``, ``FIONCLEX``), * * IOCTL commands targeting file descriptions (``FIONBIO``, ``FIOASYNC``), * * IOCTL commands targeting file systems (``FIFREEZE``, ``FITHAW``, * ``FIGETBSZ``, ``FS_IOC_GETFSUUID``, ``FS_IOC_GETFSSYSFSPATH``) * * Some IOCTL commands which do not make sense when used with devices, but * whose implementations are safe and return the right error codes * (``FS_IOC_FIEMAP``, ``FICLONE``, ``FICLONERANGE``, ``FIDEDUPERANGE``) * * This access right is available since the fifth version of the Landlock * ABI. * * .. warning:: * * It is currently not possible to restrict some file-related actions * accessible through these syscall families: :manpage:`chdir(2)`, * :manpage:`stat(2)`, :manpage:`flock(2)`, :manpage:`chmod(2)`, * :manpage:`chown(2)`, :manpage:`setxattr(2)`, :manpage:`utime(2)`, * :manpage:`fcntl(2)`, :manpage:`access(2)`. * Future Landlock evolutions will enable to restrict them. */ /* clang-format off */ #define LANDLOCK_ACCESS_FS_EXECUTE (1ULL << 0) #define LANDLOCK_ACCESS_FS_WRITE_FILE (1ULL << 1) #define LANDLOCK_ACCESS_FS_READ_FILE (1ULL << 2) #define LANDLOCK_ACCESS_FS_READ_DIR (1ULL << 3) #define LANDLOCK_ACCESS_FS_REMOVE_DIR (1ULL << 4) #define LANDLOCK_ACCESS_FS_REMOVE_FILE (1ULL << 5) #define LANDLOCK_ACCESS_FS_MAKE_CHAR (1ULL << 6) #define LANDLOCK_ACCESS_FS_MAKE_DIR (1ULL << 7) #define LANDLOCK_ACCESS_FS_MAKE_REG (1ULL << 8) #define LANDLOCK_ACCESS_FS_MAKE_SOCK (1ULL << 9) #define LANDLOCK_ACCESS_FS_MAKE_FIFO (1ULL << 10) #define LANDLOCK_ACCESS_FS_MAKE_BLOCK (1ULL << 11) #define LANDLOCK_ACCESS_FS_MAKE_SYM (1ULL << 12) #define LANDLOCK_ACCESS_FS_REFER (1ULL << 13) #define LANDLOCK_ACCESS_FS_TRUNCATE (1ULL << 14) #define LANDLOCK_ACCESS_FS_IOCTL_DEV (1ULL << 15) /* clang-format on */ /** * DOC: net_access * * Network flags * ~~~~~~~~~~~~~~~~ * * These flags enable to restrict a sandboxed process to a set of network * actions. This is supported since the Landlock ABI version 4. * * The following access rights apply to TCP port numbers: * * - %LANDLOCK_ACCESS_NET_BIND_TCP: Bind a TCP socket to a local port. * - %LANDLOCK_ACCESS_NET_CONNECT_TCP: Connect an active TCP socket to * a remote port. */ /* clang-format off */ #define LANDLOCK_ACCESS_NET_BIND_TCP (1ULL << 0) #define LANDLOCK_ACCESS_NET_CONNECT_TCP (1ULL << 1) /* clang-format on */ /** * DOC: scope * * Scope flags * ~~~~~~~~~~~ * * These flags enable to isolate a sandboxed process from a set of IPC actions. * Setting a flag for a ruleset will isolate the Landlock domain to forbid * connections to resources outside the domain. * * Scopes: * * - %LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET: Restrict a sandboxed process from * connecting to an abstract UNIX socket created by a process outside the * related Landlock domain (e.g. a parent domain or a non-sandboxed process). * - %LANDLOCK_SCOPE_SIGNAL: Restrict a sandboxed process from sending a signal * to another process outside the domain. */ /* clang-format off */ #define LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET (1ULL << 0) #define LANDLOCK_SCOPE_SIGNAL (1ULL << 1) /* clang-format on*/ #endif /* _LINUX_LANDLOCK_H */