From 1487eaaaa24cbeb70e145f079d701eee06d0abb7 Mon Sep 17 00:00:00 2001 From: Pradipta Banerjee Date: Thu, 21 May 2026 13:41:54 +0000 Subject: [PATCH] kernel: Enable landlock LSM Allows using landlock LSM for the container process Signed-off-by: Pradipta Banerjee --- .../packaging/kernel/configs/fragments/common/landlock.conf | 6 ++++++ tools/packaging/kernel/kata_config_version | 2 +- 2 files changed, 7 insertions(+), 1 deletion(-) create mode 100644 tools/packaging/kernel/configs/fragments/common/landlock.conf diff --git a/tools/packaging/kernel/configs/fragments/common/landlock.conf b/tools/packaging/kernel/configs/fragments/common/landlock.conf new file mode 100644 index 0000000000..6969b7840b --- /dev/null +++ b/tools/packaging/kernel/configs/fragments/common/landlock.conf @@ -0,0 +1,6 @@ +# Landlock LSM +# +# Enables the Landlock access-control LSM so that processes can apply +# filesystem and network sandboxing rules inside the kata guest VM. +# +CONFIG_SECURITY_LANDLOCK=y diff --git a/tools/packaging/kernel/kata_config_version b/tools/packaging/kernel/kata_config_version index 6bb2f98fb0..0f11735ff8 100644 --- a/tools/packaging/kernel/kata_config_version +++ b/tools/packaging/kernel/kata_config_version @@ -1 +1 @@ -195 +196