landlock: Add user and kernel documentation

Add a first document describing userspace API: how to define and enforce
a Landlock security policy.  This is explained with a simple example.
The Landlock system calls are described with their expected behavior and
current limitations.

Another document is dedicated to kernel developers, describing guiding
principles and some important kernel structures.

This documentation can be built with the Sphinx framework.

Cc: James Morris <>
Cc: Jann Horn <>
Cc: Serge E. Hallyn <>
Signed-off-by: Mickaël Salaün <>
Reviewed-by: Vincent Dagonneau <>
Reviewed-by: Kees Cook <>
Signed-off-by: James Morris <>
5 files changed