]> www.infradead.org Git - users/jedix/linux-maple.git/commit
landlock: Log mount-related denials
authorMickaël Salaün <mic@digikod.net>
Thu, 20 Mar 2025 19:07:00 +0000 (20:07 +0100)
committerMickaël Salaün <mic@digikod.net>
Wed, 26 Mar 2025 12:59:39 +0000 (13:59 +0100)
commitc56f649646ecec3dd1a2e400e6e5ec83439d940f
tree3a3523fd3d5748cc111f37ba3f900db99ac4e153
parent1d636984e088b17e8587eb5ed9d9d7a80b656c4c
landlock: Log mount-related denials

Add audit support for sb_mount, move_mount, sb_umount, sb_remount, and
sb_pivot_root hooks.

The new related blocker is "fs.change_topology".

Audit event sample:

  type=LANDLOCK_DENY msg=audit(1729738800.349:44): domain=195ba459b blockers=fs.change_topology name="/" dev="tmpfs" ino=1

Remove landlock_get_applicable_domain() and get_current_fs_domain()
which are now fully replaced with landlock_get_applicable_subject().

Cc: Günther Noack <gnoack@google.com>
Link: https://lore.kernel.org/r/20250320190717.2287696-12-mic@digikod.net
Signed-off-by: Mickaël Salaün <mic@digikod.net>
security/landlock/audit.c
security/landlock/audit.h
security/landlock/fs.c
security/landlock/ruleset.h