Landlock setup
Yves Rutschle <[email protected]> Mon, 7 Nov 2022 17:22:16 +0000
| Newsgroups | dev.linux.lists.landlock |
|---|---|
| Message-ID | <[email protected]> |
Hello everyone, Following Mickael's presentation of Landlock at Pass-the-Salt 2022, I intend to add support for it to sslh. I'm starting from the beginning: compiling and running the example, which so far complains the LSM is not loaded, when the kernel tells me it is... I'm running a stock Debian where I manually add landlock to the command line: [ 0.000000] Command line: BOOT_IMAGE=/boot/vmlinuz-5.18.0-3-amd64 root=UUID=79c3bdf6-4be2-46d6-b006-bb17170247b1 ro quiet lsm=landlock the kernel indicates the LSM is started: [ 0.076550] LSM: Security Framework initializing [ 0.076559] landlock: Up and running. Yet running the example fails: # LL_FS_RO="/bin:/lib:/usr:/proc:/etc:/dev/urandom" LL_FS_RW="/dev/null:/dev/full:/dev/zero:/dev/pts:/tmp" ./lock bash -i Failed to check Landlock compatibility: Function not implemented Hint: Landlock is not supported by the current kernel. To support it, build the kernel with CONFIG_SECURITY_LANDLOCK=y and prepend "landlock," to the content of CONFIG_LSM. What would I be doing wrong? Cheers, Y.