Landlock setup

Yves Rutschle <[email protected]> Mon, 7 Nov 2022 17:22:16 +0000
Newsgroups dev.linux.lists.landlock
Message-ID <[email protected]>
Hello everyone,

Following Mickael's presentation of Landlock at
Pass-the-Salt 2022, I intend to add support for it to sslh.

I'm starting from the beginning: compiling and running the
example, which so far complains the LSM is not loaded, when
the kernel tells me it is...

I'm running a stock Debian where I manually add landlock to
the command line:

[    0.000000] Command line: BOOT_IMAGE=/boot/vmlinuz-5.18.0-3-amd64 root=UUID=79c3bdf6-4be2-46d6-b006-bb17170247b1 ro quiet lsm=landlock

the kernel indicates the LSM is started:

[    0.076550] LSM: Security Framework initializing
[    0.076559] landlock: Up and running.


Yet running the example fails:

# LL_FS_RO="/bin:/lib:/usr:/proc:/etc:/dev/urandom" LL_FS_RW="/dev/null:/dev/full:/dev/zero:/dev/pts:/tmp" ./lock bash -i
Failed to check Landlock compatibility: Function not implemented
Hint: Landlock is not supported by the current kernel. To support it, build the kernel with CONFIG_SECURITY_LANDLOCK=y and prepend "landlock," to the content of CONFIG_LSM.



What would I be doing wrong?

Cheers,
Y.