Skip to content

Commit cfdae68

Browse files
l0koda-nogikh
authored andcommitted
sys/linux: add Landlock UDP access rigths
Add the new LANDLOCK_ACCESS_NET_BIND_UDP, LANDLOCK_ACCESS_NET_CONNECT_UDP, and LANDLOCK_ACCESS_NET_SENDTO_UDP access rights. Signed-off-by: Mickaël Salaün <mic@digikod.net>
1 parent e5e2587 commit cfdae68

File tree

2 files changed

+4
-1
lines changed

2 files changed

+4
-1
lines changed

sys/linux/landlock.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,6 @@ landlock_restrict_self_flags = LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF, LANDLOC
3838

3939
landlock_access_fs_flags = LANDLOCK_ACCESS_FS_EXECUTE, LANDLOCK_ACCESS_FS_WRITE_FILE, LANDLOCK_ACCESS_FS_READ_FILE, LANDLOCK_ACCESS_FS_READ_DIR, LANDLOCK_ACCESS_FS_REMOVE_DIR, LANDLOCK_ACCESS_FS_REMOVE_FILE, LANDLOCK_ACCESS_FS_MAKE_CHAR, LANDLOCK_ACCESS_FS_MAKE_DIR, LANDLOCK_ACCESS_FS_MAKE_REG, LANDLOCK_ACCESS_FS_MAKE_SOCK, LANDLOCK_ACCESS_FS_MAKE_FIFO, LANDLOCK_ACCESS_FS_MAKE_BLOCK, LANDLOCK_ACCESS_FS_MAKE_SYM, LANDLOCK_ACCESS_FS_REFER, LANDLOCK_ACCESS_FS_TRUNCATE, LANDLOCK_ACCESS_FS_IOCTL_DEV
4040

41-
landlock_access_net_flags = LANDLOCK_ACCESS_NET_BIND_TCP, LANDLOCK_ACCESS_NET_CONNECT_TCP
41+
landlock_access_net_flags = LANDLOCK_ACCESS_NET_BIND_TCP, LANDLOCK_ACCESS_NET_CONNECT_TCP, LANDLOCK_ACCESS_NET_BIND_UDP, LANDLOCK_ACCESS_NET_CONNECT_UDP, LANDLOCK_ACCESS_NET_SENDTO_UDP
4242

4343
landlock_scope_flags = LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET, LANDLOCK_SCOPE_SIGNAL, LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET

sys/linux/landlock.txt.const

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,10 @@ LANDLOCK_ACCESS_FS_REMOVE_FILE = 32
1717
LANDLOCK_ACCESS_FS_TRUNCATE = 16384
1818
LANDLOCK_ACCESS_FS_WRITE_FILE = 2
1919
LANDLOCK_ACCESS_NET_BIND_TCP = 1
20+
LANDLOCK_ACCESS_NET_BIND_UDP = 4
2021
LANDLOCK_ACCESS_NET_CONNECT_TCP = 2
22+
LANDLOCK_ACCESS_NET_CONNECT_UDP = 8
23+
LANDLOCK_ACCESS_NET_SENDTO_UDP = 16
2124
LANDLOCK_CREATE_RULESET_ERRATA = 2
2225
LANDLOCK_CREATE_RULESET_VERSION = 1
2326
LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON = 2

0 commit comments

Comments
 (0)