Changelog
Unreleased
- Docs now build with Zensical instead of mkdocs-material. The site gains a light/dark/system palette toggle and the modern theme variant.
0.2.0 - 2026-09-26
- Add landlockpy.mute_subdomain_logs() wrapping the landlock_restrict_self(-1) call that suppresses audit logging for nested domains without creating a new one.
- probe() now reports non-OSError child exceptions through ProbeResult.exception instead of a synthetic errno 255.
- restrict() rejects flags the kernel does not support with UnsupportedError in strict mode (best_effort=False) instead of silently dropping them.
- Ruleset now rejects pickling. The ruleset fd is closed if initialization fails partway, and close() marks the ruleset closed before releasing the descriptor.
- allow_port() rejects non-integer ports with TypeError via operator.index.
- abi_version(), errata() and supported() now report 0/False on non-Linux platforms instead of raising UnsupportedError.
- Document the ctypes layout of all three kernel structs explicitly.
- Build API documentation with mkdocs-material and mkdocstrings (make docs, enforced in CI). Pushes to master publish it to GitHub Pages at https://quad4-software.github.io/landlockpy/
0.1.1 - 2026-09-22
- Add landlockpy.testing with probe() and probe_path() for running a callable under a ruleset in a forked child without enforcing it in the caller.
- Ruleset: add repr, reject copy/deepcopy, raise ValueError from fileno() when closed, raise RuntimeError when entering a closed ruleset.
- Fix quiet rule flag on allow_path() and allow_port(): dropped in best-effort mode and rejected in strict mode on kernels below ABI 10.
- Declare explicit ctypes layout on the packed path_beneath struct. The implicit default is deprecated since Python 3.14.
0.1.0 - 2026-09-22
Initial release.
- Ruleset construction with handled filesystem, network and scope rights.
- Path-hierarchy rules and TCP/UDP port rules, including quiet rules (ABI 10).
- Scoped domains for abstract UNIX sockets and signals (ABI 6).
- Restrict flags covering audit logging, TSYNC and atomic no_new_privs (ABI 11, prctl fallback on older kernels).
- Best-effort masking to the running kernel, strict mode via best_effort=False.
- Kernel probes: abi_version(), errata(), supported(), and the for_abi helpers for computing which rights a given ABI supports.