.\" Copyright 2017-2020, Mickaël Salaün .\" Copyright 2019-2020, ANSSI .\" Copyright 2021, Microsoft Corp. .\" Copyright, the authors of the Linux man-pages project .\" .\" SPDX-License-Identifier: Linux-man-pages-copyleft .\" .TH landlock_restrict_self 2 2026-04-21 "Linux man-pages 6.18" .SH NAME landlock_restrict_self \- enforce a Landlock ruleset .SH LIBRARY Standard C library .RI ( libc ,\~ \-lc ) .SH SYNOPSIS .nf .BR "#include " " /* Definition of " LANDLOCK_* " constants */" .BR "#include " " /* Definition of " SYS_* " constants */" .P .BI "int syscall(SYS_landlock_restrict_self, int " ruleset_fd , .BI " uint32_t " flags ); .SH DESCRIPTION Once a Landlock ruleset is populated with the desired rules, the .BR landlock_restrict_self () system call enforces this ruleset on the calling thread. See .BR landlock (7) for a global overview. .P A thread can be restricted with multiple rulesets that are then composed together to form the thread's Landlock domain. This can be seen as a stack of rulesets but it is implemented in a more efficient way. A domain can only be updated in such a way that the constraints of each past and future composed rulesets will restrict the thread and its future children for their entire life. It is then possible to gradually enforce tailored access control policies with multiple independent rulesets coming from different sources (e.g., init system configuration, user session policy, built-in application policy). However, most applications should only need one call to .BR landlock_restrict_self () and they should avoid arbitrary numbers of such calls because of the composed rulesets limit. Instead, developers are encouraged to build a single tailored ruleset with multiple calls to .BR landlock_add_rule (2). .P In order to enforce a ruleset, either the caller must have the .B CAP_SYS_ADMIN capability in its user namespace, or the thread must already have the .I no_new_privs bit set. As for .BR seccomp (2), this avoids scenarios where unprivileged processes can affect the behavior of privileged children (e.g., because of set-user-ID binaries). If that bit was not already set by an ancestor of this thread, the thread must make the following call: .IP .EX prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0); .EE .P .I ruleset_fd is a Landlock ruleset file descriptor obtained with .BR landlock_create_ruleset (2) and fully populated with a set of calls to .BR landlock_add_rule (2). .P By default, denied accesses originating from programs that sandbox themselves are logged via the audit subsystem. Such events typically indicate unexpected behavior, such as bugs or exploitation attempts. However, to avoid excessive logging, access requests denied by a domain not created by the originating program are not logged by default. The rationale is that programs should know their own behavior, but not necessarily the behavior of other programs. This default configuration is suitable for most programs that sandbox themselves. For specific use cases, the following flags allow programs to modify this default logging behavior. .P The .B LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF and .B LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON flags apply to the newly created Landlock domain. .TP .B LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF Disables logging of denied accesses originating from the thread creating the Landlock domain, as well as its children, as long as they continue running the same executable code (i.e., without an intervening .BR execve (2) call). This is intended for programs that execute unknown code without invoking .BR execve (2), such as script interpreters. Programs that only sandbox themselves should not set this flag, so users can be notified of unauthorized access attempts via system logs. .TP .B LANDLOCK_RESTRICT_SELF_LOG_NEW_EXEC_ON Enables logging of denied accesses after an .BR execve (2) call, providing visibility into unauthorized access attempts by newly executed programs within the created Landlock domain. This flag is recommended only when all potential executables in the domain are expected to comply with the access restrictions, as excessive audit log entries could make it more difficult to identify critical events. .TP .B LANDLOCK_RESTRICT_SELF_LOG_SUBDOMAINS_OFF Disables logging of denied accesses originating from nested Landlock domains created by the caller or its descendants. This flag should be set according to runtime configuration, not hardcoded, to avoid suppressing important security events. It is useful for container runtimes or sandboxing tools that may launch programs which themselves create Landlock domains and could otherwise generate excessive logs. Unlike .BR LANDLOCK_RESTRICT_SELF_LOG_SAME_EXEC_OFF , this flag only affects future nested domains, not the one being created. It can also be used with a .I ruleset_fd value of \-1 to mute subdomain logs without creating a domain. .P The following flag supports policy enforcement in multithreaded processes: .TP .BR LANDLOCK_RESTRICT_SELF_TSYNC " (since Landlock ABI version 8)" Applies the new Landlock configuration atomically to all threads of the current process, including the Landlock domain and logging configuration. This overrides the Landlock configuration of sibling threads, irrespective of previously established Landlock domains and logging configurations on those threads. .IP If the calling thread is running with .IR no_new_privs , this operation enables .I no_new_privs on the sibling threads as well. .SH RETURN VALUE On success, .BR landlock_restrict_self () returns 0. On error, \-1 is returned and .I errno is set to indicate the error. .SH ERRORS .BR landlock_restrict_self () can fail for the following reasons: .TP .B E2BIG The maximum number of composed rulesets is reached for the calling thread. This limit is currently 64. .TP .B EBADF .I ruleset_fd is not a file descriptor for the current thread. .TP .B EBADFD .I ruleset_fd is not a ruleset file descriptor. .TP .B EINVAL Invalid value in .IR flags . .TP .B EOPNOTSUPP Landlock is supported by the kernel but disabled at boot time. .TP .B EPERM .I ruleset_fd has no read access to the underlying ruleset, or the calling thread is not running with .IR no_new_privs , or it doesn't have the .B CAP_SYS_ADMIN in its user namespace. .SH STANDARDS Linux. .SH HISTORY Linux 5.13. .SH EXAMPLES See .BR landlock (7). .SH SEE ALSO .BR landlock_create_ruleset (2), .BR landlock_add_rule (2), .BR landlock (7)