@@ -88,9 +88,10 @@ pub fn probe_availability() -> LandlockAvailability {
8888
8989/// A prepared Landlock ruleset ready to be enforced via `restrict_self()`.
9090///
91- /// Created by [`prepare`] while running as root (so `PathFd::new()` can open
92- /// any path regardless of DAC permissions). Enforced by [`enforce`] after
93- /// `drop_privileges()` — `restrict_self()` does not require elevated privileges.
91+ /// Path FDs are opened before enforcement. The capability-free launch path
92+ /// prepares the baseline and user rules as the workload identity, then calls
93+ /// [`enforce`] in the child before exec. `restrict_self()` does not require
94+ /// elevated privileges.
9495pub struct PreparedRuleset {
9596 ruleset : landlock:: RulesetCreated ,
9697 compatibility : LandlockCompatibility ,
@@ -102,10 +103,11 @@ enum PathOpenMode {
102103 CurrentUser ,
103104}
104105
105- /// Phase 1: Open `PathFds` and build the Landlock ruleset **as root** .
106+ /// Phase 1: Open `PathFds` and build the Landlock ruleset with strict path opening .
106107///
107- /// This must run before `drop_privileges()` so that `PathFd::new()` can open
108- /// paths that are only accessible to root (e.g. mode 700 directories).
108+ /// Opens configured paths as the calling identity. Inaccessible paths fail in
109+ /// hard-requirement mode and are skipped in best-effort mode. Unlike
110+ /// [`prepare_current_user`], this does not always omit inaccessible paths.
109111///
110112/// Returns `None` if there are no filesystem paths to restrict (no-op).
111113/// Returns `Some(PreparedRuleset)` on success, or an error.
@@ -394,9 +396,9 @@ fn prepare_with_path_open_mode(
394396
395397/// Phase 2: Enforce a prepared Landlock ruleset by calling `restrict_self()`.
396398///
397- /// This runs **after** `drop_privileges()`. The `restrict_self()` syscall does
398- /// not require root — it only restricts the calling thread (and its future
399- /// children), which is always permitted .
399+ /// The capability-free launch path calls this in the child before exec, already
400+ /// running as the workload identity. `restrict_self()` does not require root;
401+ /// it restricts the calling thread and its future children .
400402///
401403/// Respects the same `best_effort` / `hard_requirement` compatibility as
402404/// [`prepare`]: if `restrict_self()` fails and the policy is `best_effort`,
0 commit comments