Skip to content

Commit e5e2587

Browse files
l0koda-nogikh
authored andcommitted
sys/linux: add Landlock tsync flag
Add the new LANDLOCK_RESTRICT_SELF_TSYNC flag for landlock_restrict_self(2). Signed-off-by: Mickaël Salaün <mic@digikod.net>
1 parent 46cab38 commit e5e2587

File tree

2 files changed

+2
-1
lines changed

2 files changed

+2
-1
lines changed

sys/linux/landlock.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ define LANDLOCK_ACCESS_FS_IOCTL_DEV (1ULL << 15)
3434

3535
landlock_create_ruleset_flags = LANDLOCK_CREATE_RULESET_VERSION, LANDLOCK_CREATE_RULESET_ERRATA
3636

37-
landlock_restrict_self_flags = LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF, LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON, LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF
37+
landlock_restrict_self_flags = LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF, LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON, LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF, LANDLOCK_RESTRICT_SELF_TSYNC
3838

3939
landlock_access_fs_flags = LANDLOCK_ACCESS_FS_EXECUTE, LANDLOCK_ACCESS_FS_WRITE_FILE, LANDLOCK_ACCESS_FS_READ_FILE, LANDLOCK_ACCESS_FS_READ_DIR, LANDLOCK_ACCESS_FS_REMOVE_DIR, LANDLOCK_ACCESS_FS_REMOVE_FILE, LANDLOCK_ACCESS_FS_MAKE_CHAR, LANDLOCK_ACCESS_FS_MAKE_DIR, LANDLOCK_ACCESS_FS_MAKE_REG, LANDLOCK_ACCESS_FS_MAKE_SOCK, LANDLOCK_ACCESS_FS_MAKE_FIFO, LANDLOCK_ACCESS_FS_MAKE_BLOCK, LANDLOCK_ACCESS_FS_MAKE_SYM, LANDLOCK_ACCESS_FS_REFER, LANDLOCK_ACCESS_FS_TRUNCATE, LANDLOCK_ACCESS_FS_IOCTL_DEV
4040

sys/linux/landlock.txt.const

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,7 @@ LANDLOCK_CREATE_RULESET_VERSION = 1
2323
LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON = 2
2424
LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF = 1
2525
LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF = 4
26+
LANDLOCK_RESTRICT_SELF_TSYNC = 8
2627
LANDLOCK_RULE_NET_PORT = 2
2728
LANDLOCK_RULE_PATH_BENEATH = 1
2829
LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET = 1

0 commit comments

Comments
 (0)