[PATCH RFC -next 12/12] Documentation: Update landlock doc for metadata rights
From: Cai Xinchen
Date: Thu Sep 24 2026 - 06:39:49 EST
Update the user space documentation to include the new
LANDLOCK_ACCESS_FS_READ_METADATA and
LANDLOCK_ACCESS_FS_WRITE_METADATA access rights in the example
ruleset attributes, and extend the ABI version fallback switch to
remove them for ABI < 12.
Assisted-by: opencode: glm-5.3
Signed-off-by: Cai Xinchen <caixinchen1@xxxxxxxxxx>
---
Documentation/userspace-api/landlock.rst | 11 ++++++++++-
1 file changed, 10 insertions(+), 1 deletion(-)
diff --git a/Documentation/userspace-api/landlock.rst b/Documentation/userspace-api/landlock.rst
index 84cb7bf6b3ed..f6389b9668b4 100644
--- a/Documentation/userspace-api/landlock.rst
+++ b/Documentation/userspace-api/landlock.rst
@@ -78,7 +78,9 @@ to be explicit about the denied-by-default access rights.
LANDLOCK_ACCESS_FS_REFER |
LANDLOCK_ACCESS_FS_TRUNCATE |
LANDLOCK_ACCESS_FS_IOCTL_DEV |
- LANDLOCK_ACCESS_FS_RESOLVE_UNIX,
+ LANDLOCK_ACCESS_FS_RESOLVE_UNIX |
+ LANDLOCK_ACCESS_FS_READ_METADATA |
+ LANDLOCK_ACCESS_FS_WRITE_METADATA,
.handled_access_net =
LANDLOCK_ACCESS_NET_BIND_TCP |
LANDLOCK_ACCESS_NET_CONNECT_TCP |
@@ -140,6 +142,13 @@ version, and only use the available subset of access rights:
ruleset_attr.handled_access_net &=
~(LANDLOCK_ACCESS_NET_BIND_UDP |
LANDLOCK_ACCESS_NET_CONNECT_SEND_UDP);
+ __attribute__((fallthrough));
+ case 10:
+ case 11:
+ /* Removes metadata rights for ABI < 12 */
+ ruleset_attr.handled_access_fs &=
+ ~(LANDLOCK_ACCESS_FS_READ_METADATA |
+ LANDLOCK_ACCESS_FS_WRITE_METADATA);
}
This enables the creation of an inclusive ruleset that will contain our rules.
--
2.18.0.huawei.25