diff --git a/sys/linux/landlock.txt b/sys/linux/landlock.txt index fb81d38db8c8..abde9c3d31c6 100644 --- a/sys/linux/landlock.txt +++ b/sys/linux/landlock.txt @@ -34,10 +34,10 @@ define LANDLOCK_ACCESS_FS_IOCTL_DEV (1ULL << 15) landlock_create_ruleset_flags = LANDLOCK_CREATE_RULESET_VERSION, LANDLOCK_CREATE_RULESET_ERRATA -landlock_restrict_self_flags = LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF, LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON, LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF +landlock_restrict_self_flags = LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF, LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON, LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF, LANDLOCK_RESTRICT_SELF_TSYNC landlock_access_fs_flags = LANDLOCK_ACCESS_FS_EXECUTE, LANDLOCK_ACCESS_FS_WRITE_FILE, LANDLOCK_ACCESS_FS_READ_FILE, LANDLOCK_ACCESS_FS_READ_DIR, LANDLOCK_ACCESS_FS_REMOVE_DIR, LANDLOCK_ACCESS_FS_REMOVE_FILE, LANDLOCK_ACCESS_FS_MAKE_CHAR, LANDLOCK_ACCESS_FS_MAKE_DIR, LANDLOCK_ACCESS_FS_MAKE_REG, LANDLOCK_ACCESS_FS_MAKE_SOCK, LANDLOCK_ACCESS_FS_MAKE_FIFO, LANDLOCK_ACCESS_FS_MAKE_BLOCK, LANDLOCK_ACCESS_FS_MAKE_SYM, LANDLOCK_ACCESS_FS_REFER, LANDLOCK_ACCESS_FS_TRUNCATE, LANDLOCK_ACCESS_FS_IOCTL_DEV -landlock_access_net_flags = LANDLOCK_ACCESS_NET_BIND_TCP, LANDLOCK_ACCESS_NET_CONNECT_TCP +landlock_access_net_flags = LANDLOCK_ACCESS_NET_BIND_TCP, LANDLOCK_ACCESS_NET_CONNECT_TCP, LANDLOCK_ACCESS_NET_BIND_UDP, LANDLOCK_ACCESS_NET_CONNECT_UDP, LANDLOCK_ACCESS_NET_SENDTO_UDP -landlock_scope_flags = LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET, LANDLOCK_SCOPE_SIGNAL +landlock_scope_flags = LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET, LANDLOCK_SCOPE_SIGNAL, LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET diff --git a/sys/linux/landlock.txt.const b/sys/linux/landlock.txt.const index 23b776c461ef..9334e5987382 100644 --- a/sys/linux/landlock.txt.const +++ b/sys/linux/landlock.txt.const @@ -17,15 +17,20 @@ LANDLOCK_ACCESS_FS_REMOVE_FILE = 32 LANDLOCK_ACCESS_FS_TRUNCATE = 16384 LANDLOCK_ACCESS_FS_WRITE_FILE = 2 LANDLOCK_ACCESS_NET_BIND_TCP = 1 +LANDLOCK_ACCESS_NET_BIND_UDP = 4 LANDLOCK_ACCESS_NET_CONNECT_TCP = 2 +LANDLOCK_ACCESS_NET_CONNECT_UDP = 8 +LANDLOCK_ACCESS_NET_SENDTO_UDP = 16 LANDLOCK_CREATE_RULESET_ERRATA = 2 LANDLOCK_CREATE_RULESET_VERSION = 1 LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON = 2 LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF = 1 LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF = 4 +LANDLOCK_RESTRICT_SELF_TSYNC = 8 LANDLOCK_RULE_NET_PORT = 2 LANDLOCK_RULE_PATH_BENEATH = 1 LANDLOCK_SCOPE_ABSTRACT_UNIX_SOCKET = 1 +LANDLOCK_SCOPE_PATHNAME_UNIX_SOCKET = 4 LANDLOCK_SCOPE_SIGNAL = 2 __NR_landlock_add_rule = 445, mips64le:5445 __NR_landlock_create_ruleset = 444, mips64le:5444