Skip to content

Archive

Landlock

4 articles
Cybersecurity 18 Sep 2026 6 min read

Landlock Rulesets Add a Process-Scoped Filesystem Access Boundary

A service can begin with ordinary filesystem permissions that are broader than the files it needs during steady-state operation. Changing ownership or mount topology may be impractical because the same host resources are shared with other processes. Linux Landlock addresses this gap by letting a process add a kernel-enforced access restriction to itself and, through inheritance, to descendants. Landlock is a Linux Security Module designed for sandboxing. Its rules do not grant filesystem access that DAC, ACLs, capabilities, or another security mechanism would otherwise deny. They add another authorization layer. An operation succeeds only when the other applicable controls and the Landlock policy permit it.

Software Engineering 18 Sep 2026 4 min read

Landlock Handled Rights Define a Deny-by-Default Sandbox Boundary

A Landlock ruleset does not implicitly deny every operation known to the running kernel. It first declares which access rights it handles. Once the ruleset is enforced, those handled actions are denied by default unless a matching rule grants them. That explicit boundary is central to Landlock compatibility. User space can restrict rights it knows and has tested while a newer kernel may expose additional rights that an older binary never named.

Cybersecurity 17 Sep 2026 7 min read

Landlock Rulesets Restrict Future Path Access, Not Open File Authority

Landlock Rulesets Restrict Future Path Access, Not Open File Authority A process opens a writable configuration file, installs a restrictive Landlock ruleset, and then continues running code that should have access only to a small working directory. The later policy can block a fresh attempt to open that configuration path, yet the descriptor obtained before confinement remains usable. The filesystem view has narrowed, but authority already materialized as an open file has not vanished.

Cybersecurity 17 Sep 2026 6 min read

Landlock Rulesets Add Process-Local Filesystem Denial Boundaries

A service starts with ordinary filesystem access inherited from its credentials, loads configuration, opens several resources, then begins processing data that may be hostile. Changing UID or entering a container can alter the surrounding authority model, but neither action by itself expresses a narrow rule such as “from this point onward, new reads are limited to these hierarchies and writes are limited to that directory.” Linux Landlock provides a process-controlled restriction layer for this boundary. A process creates a ruleset, adds object rules, and enforces the ruleset on itself. The resulting Landlock domain is stacked with existing discretionary access control and other Linux Security Module decisions. Landlock can remove access that those mechanisms would otherwise permit; it does not grant access they deny.