NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #2463 most downloaded on crates.io
Landlock LSM helpers
Last release 2 months ago
27 Jul 2026
Release timing varies
gaps range from 2 months to 1.8 years
Nearly every release is documented
notes for 11 of 12 stable releases
Nothing withdrawn
no release was ever pulled
5 years old
12 releases · first in 2021
One column per quarter.
See crate's metadata and related documentation .
See crate's metadata and related documentation.
See summary in CHANGELOG.md
Full Changelog: v0.4.6...v0.4.7
AccessFs::ResolveUnix
right (PR #135).See crate's metadata and related documentation .
See crate's metadata and related documentation.
See summary in CHANGELOG.md
Full Changelog: v0.4.5...v0.4.6
all_threads()
(shared between
RulesetCreated and
RestrictSelf)
(PR #130).See crate's metadata and related documentation .
See crate's metadata and related documentation.
See summary in CHANGELOG.md
Full Changelog: v0.4.4...v0.4.5
log_same_exec(),
log_new_exec()
(domain-specific), and
log_subdomains()
(shared between
RulesetCreated and
RestrictSelf)
(PR #120).RestrictSelf
builder for calling landlock_restrict_self() without creating a
Landlock domain (e.g., muting subdomain audit logs).RestrictionStatus
with three new public fields (log_same_exec, log_new_exec,
log_subdomains) reporting the effective audit-logging flag state after
restrict_self()
and apply().Erratum
bitflags enum and
Erratum::current()
for querying fixed kernel bugs before building a ruleset
(PR #119).Deprecate the set_no_new_privs()
method and replace it with
no_new_privs()
(PR #122).
From<ABI> mapping matches CI kernel errata.SoftRequirement test coverage for scope() and restrict_self flags.try_compat_binary() unit tests for the binary compat dispatch.sandboxer.c:
added LL_FORCE_LOG environment variable for audit logging
(PR #120).See crate's metadata and related documentation .
See crate's metadata and related documentation.
See summary in CHANGELOG.md
Full Changelog: v0.4.3...v0.4.4
LandlockStatus type to query the running kernel and display information about available Landlock features (PR #103 and PR #113).See crate's metadata and related documentation .
See crate's metadata and related documentation.
See summary in CHANGELOG.md
Full Changelog: v0.4.2...v0.4.3
Debug) for public types (PR #108).path_beneath_rules() documentation (PR #94).AccessFs::from_file() method (PR #92).See crate's metadata and related documentation .
See crate's metadata and related documentation.
See summary in CHANGELOG.md
Full Changelog: v0.4.1...v0.4.2
Ruleset::scope() method taking a Scope enum (PR #96 and PR #98).From<RulesetCreated> implementation for Option<OwnedFd> (PR #104)HandledAccess trait specific to AccessFs and AccessNet (commit 554217dda0b7).Errno type to improve FFI support (PR #86 and PR #102).From<i32> implementation for ABI (PR #88).AccessFs::WriteFile behavior and path_beneath_rules usage (PR #80).LANDLOCK_CRATE_TEST_ABI to match the current kernel for more convenient local testing (PR #76).See crate's metadata and related documentation .
See crate's metadata and related documentation.
See summary in CHANGELOG.md
Full Changelog: v0.4.0...v0.4.1
Add support for Landlock ABI 5: control IOCTL commands on character and block devices with the new AccessFs::IoctlDev right (PR #74).
Improved the CI to better test against different kernel versions (PR #72).
See crate's metadata and related documentation .
See crate's metadata and related documentation.
See summary in CHANGELOG.md
Full Changelog: v0.3.1...v0.4.0
Add support for Landlock ABI 4: control TCP binding and connection according to specified network ports.
This is now possible with the AccessNet rights and
the NetPort rule
(PR #55).
The from_read() and from_write() methods moved from the Access trait to the AccessFs struct
(commit 68f066eba571).
Improve compatibility consistency and prioritize runtime errors against compatibility errors (PR #67).
Fixed a corner case where a ruleset was created on a kernel not supporting Landlock, while requesting to add a rule with an access right handled by the ruleset (BestEffort).
When trying to enforce this ruleset, this led to a runtime error (i.e. wrong file descriptor) instead of a compatibility error.
To simplify compatibility management, always call prctl(PR_SET_NO_NEW_PRIVS, 1) by default (see set_no_new_privs()).
This was required to get a consistent compatibility management and it should not be an issue given that this feature is supported by all LTS kernels
(commit d99f75155bec).
See crate's metadata and related documentation .
See crate's metadata and related documentation.
See summary in CHANGELOG.md
Full Changelog: v0.3.0...v0.3.1
See crate's metadata and related documentation .
See crate's metadata and related documentation.
See summary in CHANGELOG.md
Full Changelog: v0.2.0...v0.3.0
Add support for Landlock ABI 3: control truncate operations with the new
AccessFs::Truncate
right (PR #40).
Revamp the compatibility handling and add a new
set_compatibility()
method for Ruleset, RulesetCreated, and PathBeneath.
We can now fine-tune the compatibility behavior according to the running kernel
and then the supported features thanks to three compatible levels:
best effort, soft requirement and hard requirement
(PR #12).
Add a new AccessFs::from_file()
helper (commit 0b3238c6dd70).
Deprecate the set_best_effort()
method and replace it with set_compatibility()
(PR #12).
Deprecate Ruleset::new()
and replace it with Ruleset::default()
(PR #44).
We now check that a ruleset really handles at least one access right,
which can now cause Ruleset::create() to return an error if the ruleset compatibility level is
HardRequirement or set_best_effort(false)
(commit 95addc13b4a8).
We now check that access rights passed to add_rule() make sense according to the file type.
To handle most use cases,
path_beneath_rules() now automatically check and downgrade access rights for files
(i.e. remove superfluous directory-only access rights,
commit 8e47940b3722).
Test coverage in the CI is greatly improved by running all tests on all relevant kernel versions: Linux 5.10, 5.15, 6.1, and 6.4 (PR #41).
Run each test in a dedicated thread to avoid inconsistent behavior (PR #46).
This is the first major release of this crate. It brings a high-level interface to the Landlock kernel interface.
This is the first major release of this crate. It brings a high-level interface to the Landlock kernel interface.
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →