]> git.ipfire.org Git - thirdparty/linux.git/commit
landlock: Clarify documentation for the IOCTL access right
authorGünther Noack <gnoack3000@gmail.com>
Sun, 11 Jan 2026 17:52:04 +0000 (18:52 +0100)
committerMickaël Salaün <mic@digikod.net>
Mon, 12 Jan 2026 16:07:21 +0000 (17:07 +0100)
commit6abbb8703aeeb645a681ab6ad155e0b450413787
treeba215e911f70671eb8f3b6a2ab24e227e4b309d8
parent15e8d739fda1084d81f7d3813e9600eba6e0f134
landlock: Clarify documentation for the IOCTL access right

Move the description of the LANDLOCK_ACCESS_FS_IOCTL_DEV access right
together with the file access rights.

This group of access rights applies to files (in this case device
files), and they can be added to file or directory inodes using
landlock_add_rule(2).  The check for that works the same for all file
access rights, including LANDLOCK_ACCESS_FS_IOCTL_DEV.

Invoking ioctl(2) on directory FDs can not currently be restricted
with Landlock.  Having it grouped separately in the documentation is a
remnant from earlier revisions of the LANDLOCK_ACCESS_FS_IOCTL_DEV
patch set.

Link: https://lore.kernel.org/all/20260108.Thaex5ruach2@digikod.net/
Signed-off-by: Günther Noack <gnoack3000@gmail.com>
Link: https://lore.kernel.org/r/20260111175203.6545-2-gnoack3000@gmail.com
Signed-off-by: Mickaël Salaün <mic@digikod.net>
include/uapi/linux/landlock.h