Re: [bitbake-devel] [PATCH [RFC] 1/2] utils: Add landlock_restrict_network function

Alexander Kanavin <[email protected]> Sat, 13 Jun 2026 13:52:15 +0200
Newsgroups org.openembedded.lists.bitbake-devel
Message-ID <CANNYZj_gX=vNggcmyS0CtPoE+dYc0AjOf4=Z0QwcU46-Ccx4EA@mail.gmail.com>
On Fri, 12 Jun 2026 at 14:01, David Nyström via lists.openembedded.org
<[email protected]> wrote:
> +def landlock_restrict_network():
> +    """Block TCP bind/connect using Landlock LSM (ABI v4+, kernel 6.7+).
> +    Gracefully skipped on older kernels. Stacks with disable_network()."""
> +
> +    NR_CREATE = 444  # landlock_create_ruleset
> +    NR_SELF   = 446  # landlock_restrict_self
> +    NET_TCP   = 0x3  # BIND_TCP | CONNECT_TCP
> +
> +    libc = ctypes.CDLL('libc.so.6')
> +
> +    abi = libc.syscall(NR_CREATE, 0, 0, 1)
> +    if abi < 4:
> +        return False
> +
> +    attr = struct.pack("QQ", 0, NET_TCP)
> +    buf = ctypes.create_string_buffer(attr)
> +    fd = libc.syscall(NR_CREATE, buf, len(attr), 0)
> +    if fd < 0:
> +        return False
> +
> +    libc.prctl(38, 1, 0, 0, 0)  # PR_SET_NO_NEW_PRIVS
> +    r = libc.syscall(NR_SELF, fd, 0)
> +    os.close(fd)
> +    return r == 0

Far too many magic numbers. I would really want to do this with an API.

This also needs some kind of test, e.g. that the function indeed has
the desired effect.

Alex