landlock: Explain file descriptor access rights
authorMickaël Salaün <mic@digikod.net>
Fri, 9 Dec 2022 19:38:13 +0000 (20:38 +0100)
committerMickaël Salaün <mic@digikod.net>
Fri, 13 Jan 2023 19:40:35 +0000 (20:40 +0100)
commit3e52e5b077f6c3e26801d87335aac35411744108
tree3989d20a25897edb392b7cb60717ae6b56d9e730
parentb7bfaa761d760e72a969d116517eaa12e404c262
landlock: Explain file descriptor access rights

Starting with LANDLOCK_ACCESS_FS_TRUNCATE, it is worth explaining why we
choose to restrict access checks at open time.  This new "File
descriptor access rights" section is complementary to the existing
"Inode access rights" section.  Add a new guiding principle related to
this section.

Reviewed-by: Günther Noack <gnoack3000@gmail.com>
Link: https://lore.kernel.org/r/20221209193813.972012-1-mic@digikod.net
[mic: Include the latest Günther's suggestion, and fix spelling]
Signed-off-by: Mickaël Salaün <mic@digikod.net>
Documentation/security/landlock.rst