[PATCH 3/3] landlock: Document LANDLOCK_RESTRICT_SELF_NNP_ON_EXEC

Justin Suess <[email protected]>
Newsgroups org.kernel.vger.linux-security-module
Message-ID <[email protected]>
Document staged no_new_privs on exec, following the same compatibility
section style as previous ABI additions.

Signed-off-by: Justin Suess <[email protected]>
---
 Documentation/userspace-api/landlock.rst | 21 ++++++++++++++++++++-
 1 file changed, 20 insertions(+), 1 deletion(-)

diff --git a/Documentation/userspace-api/landlock.rst b/Documentation/userspace-api/landlock.rst
index 5a63d4476c1c..1d779dd7bb5f 100644
--- a/Documentation/userspace-api/landlock.rst
+++ b/Documentation/userspace-api/landlock.rst
@@ -8,7 +8,7 @@ Landlock: unprivileged access control
 =====================================
 
 :Author: Mickaël Salaün
-:Date: June 2026
+:Date: July 2026
 
 The goal of Landlock is to enable restriction of ambient rights (e.g. global
 filesystem or network access) for a set of processes.  Because Landlock
@@ -789,6 +789,25 @@ when at least one sys_landlock_add_rule() call is made for it with the
 ``LANDLOCK_ADD_RULE_QUIET`` flag, additional add-rule calls for the same
 object without this flag do not clear it.
 
+Staged no_new_privs on exec (ABI < 11)
+--------------------------------------
+
+Starting with the Landlock ABI version 11, it is possible to stage
+no_new_privs so that it is only set at the next :manpage:`execve(2)` of the
+calling thread, past its point of no return, using the
+``LANDLOCK_RESTRICT_SELF_NNP_ON_EXEC`` flag passed to
+sys_landlock_restrict_self().  This flag may be used with a ``ruleset_fd``
+value of -1 to stage no_new_privs without enforcing a ruleset, and does not
+relax the no_new_privs / ``CAP_SYS_ADMIN`` requirement of the system call.
+This flag does not change how the next :manpage:`execve(2)` itself computes
+credentials: set-user-ID, set-group-ID and file capabilities are still
+honored for that execution.  The executed program then runs with
+no_new_privs set, with its usual effect on subsequent :manpage:`execve(2)`
+calls.  Staging is per-thread by default: when combined with
+``LANDLOCK_RESTRICT_SELF_TSYNC``, the staged no_new_privs is propagated to
+the sibling threads along with the rest of the Landlock configuration, and
+each thread then sets no_new_privs at its own next :manpage:`execve(2)`.
+
 .. _kernel_support:
 
 Kernel support
-- 
2.54.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.