NAME |LIBRARY |SYNOPSIS |DESCRIPTION |RETURN VALUE |VERSIONS |STANDARDS |HISTORY |SEE ALSO |COLOPHON | |
KEYCTL_GET_SECURITY(2const)KEYCTL_GET_SECURITY(2const)KEYCTL_GET_SECURITY - manipulate the kernel's key management facility
Standard C library (libc,-lc)
#include <linux/keyctl.h>/* Definition ofKEY*constants */#include <sys/syscall.h>/* Definition ofSYS_*constants */#include <unistd.h>long syscall(size_t n;SYS_keyctl, KEYCTL_GET_SECURITY, key_serial_tkey,charbuf[_Nullablen], size_tn);
KEYCTL_GET_SECURITY(since Linux 2.6.26) Get the LSM (Linux Security Module) security label of the specified key. The ID of the key whose security label is to be fetched is specified inkey. The security label (terminated by a null byte) will be placed in the buffer pointed to bybuf argument; the size of the buffer must be provided inn. Ifbuf is specified as NULL or the buffer size specified inn is too small, the full size of the security label string (including the terminating null byte) is returned as the function result, and nothing is copied to the buffer. The caller must haveview permission on the specified key. The returned security label string will be rendered in a form appropriate to the LSM in force. For example, with SELinux, it may look like: unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 If no LSM is currently in force, then an empty string is placed in the buffer.
On success, the size of the LSM security label string (including the terminating null byte), irrespective of the provided buffer size. On error, -1 is returned, anderrno is set to indicate the error.
A wrapper is provided in thelibkeyutils library:keyctl_get_security(3).
Linux.
Linux 2.6.26.
keyctl(2),keyctl_get_security(3),keyctl_get_security_alloc(3)
This page is part of theman-pages (Linux kernel and C library user-space interface documentation) project. Information about the project can be found at ⟨https://www.kernel.org/doc/man-pages/⟩. If you have a bug report for this manual page, see ⟨https://git.kernel.org/pub/scm/docs/man-pages/man-pages.git/tree/CONTRIBUTING⟩. This page was obtained from the tarball man-pages-6.15.tar.gz fetched from ⟨https://mirrors.edge.kernel.org/pub/linux/docs/man-pages/⟩ on 2025-08-11. If you discover any rendering problems in this HTML version of the page, or you believe there is a better or more up- to-date source for the page, or you have corrections or improvements to the information in this COLOPHON (which isnot part of the original manual page), send a mail to man-pages@man7.orgLinux man-pages 6.15 2025-06-28KEYCTL_GET_SECURITY(2const)Pages that refer to this page:keyctl(2)
HTML rendering created 2025-09-06 byMichael Kerrisk, author ofThe Linux Programming Interface. For details of in-depthLinux/UNIX system programming training courses that I teach, lookhere. Hosting byjambit GmbH. | ![]() |