The Pedigree Project 0.1
landlock.h
1/* Copyright (c) 2026, Pedigree Developers. */
2#ifndef POSIX_LANDLOCK_H
3#define POSIX_LANDLOCK_H
4#include "pedigree/kernel/process/FilesystemAccess.h"
5#include "pedigree/kernel/process/FilesystemContext.h"
6#include "pedigree/kernel/utilities/Vector.h"
7
8namespace LandlockAccess = FilesystemAccess;
9
11 FilesystemPathRef anchor;
12 uint64_t inode = 0;
13 uint64_t access = 0;
14};
15
16// Enforced layers are snapshots: changing a ruleset fd cannot widen a domain.
18 public:
21 uint64_t handled = 0;
22 size_t depth = 1;
23 uint64_t layerAccess(const FilesystemPathRef* ancestry, size_t count) const;
24};
25
26int posix_landlock_create_ruleset(const void* attributes, size_t size, unsigned flags);
27int posix_landlock_add_rule(int ruleset, int type, const void* attributes, unsigned flags);
28int posix_landlock_restrict_self(int ruleset, unsigned flags);
29bool posix_landlock_check(const FilesystemPathRef& path, uint64_t requested);
30bool posix_landlock_open(const FilesystemPathRef& path, int flags, bool& allowTruncate);
31#endif
A vector / dynamic array.
Definition Vector.h:33