diff --git a/CHANGELOG.md b/CHANGELOG.md
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -1,5 +1,9 @@
 # Revision history for landlock
 
+## 0.2.1.1 -- 2023-02-28
+
+* Extend API documentation with links to man-pages.
+
 ## 0.2.1.0 -- 2023-02-22
 
 * Use vendored `linux/landlock.h` instead of system-provided header during
diff --git a/internal/System/Landlock/Flags.hs b/internal/System/Landlock/Flags.hs
--- a/internal/System/Landlock/Flags.hs
+++ b/internal/System/Landlock/Flags.hs
@@ -83,38 +83,63 @@
 -- - 'AccessFsRefer'
 --
 -- __Warning:__ It is currently not possible to restrict some file-related
--- actions acessible through these syscall families: @chdir@,
--- @stat@, @flock@, @chmod@, @chown@, @setxattr@, @utime@, @ioctl@, @fcntl@,
--- @access@. Future Landlock evolutions will enable to restrict them.
+-- actions acessible through these syscall families:
+-- [@chdir@](https://man.archlinux.org/man/chdir.2),
+-- [@stat@](https://man.archlinux.org/man/stat.2),
+-- [@flock@](https://man.archlinux.org/man/flock.2),
+-- [@chmod@](https://man.archlinux.org/man/chmod.2),
+-- [@chown@](https://man.archlinux.org/man/chown.2),
+-- [@setxattr@](https://man.archlinux.org/man/setxattr.2),
+-- [@utime@](https://man.archlinux.org/man/utime.2),
+-- [@ioctl@](https://man.archlinux.org/man/ioctl.2),
+-- [@fcntl@](https://man.archlinux.org/man/fcntl.2),
+-- [@access@](https://man.archlinux.org/man/access.2).
+-- Future Landlock evolutions will enable to restrict them.
 data AccessFsFlag
-  = -- | Execute a file.
+  = -- | Execute a file
+    -- ([@LANDLOCK_ACCESS_FS_EXECUTE@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_EXECUTE)).
     AccessFsExecute
-  | -- | Open a file with write access.
+  | -- | Open a file with write access
+    -- ([@LANDLOCK_ACCESS_FS_WRITE_FILE@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_WRITE_FILE)).
+    --
+    -- Note that you might additionally need the @LANDLOCK_ACCESS_FS_TRUNCATE@
+    -- right in order to overwrite files with
+    -- [@open@](https://man.archlinux.org/man/open.2) using
+    -- [@O_TRUNC@](https://man.archlinux.org/man/open.2#O_TRUNC) or
+    -- [@creat@](https://man.archlinux.org/man/creat.2).
     AccessFsWriteFile
-  | -- | Open a file with read access. Note that
-    --   you might additionally need the @LANDLOCK_ACCESS_FS_TRUNCATE@ right in order
-    --   to overwrite files with @open@ using @O_TRUNC@ or
-    --   @creat@.
+  | -- | Open a file with read access
+    -- ([@LANDLOCK_ACCESS_FS_READ_FILE@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_READ_FILE)).
     AccessFsReadFile
-  | -- | Open a directory or list its content.
+  | -- | Open a directory or list its content
+    -- ([@LANDLOCK_ACCESS_FS_READ_DIR@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_READ_DIR)).
     AccessFsReadDir
   | -- | Remove an empty directory or rename one
+    -- ([@LANDLOCK_ACCESS_FS_REMOVE_DIR@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_REMOVE_DIR)).
     AccessFsRemoveDir
-  | -- | Unlink (or rename) a file.
+  | -- | Unlink (or rename) a file
+    -- ([@LANDLOCK_ACCESS_FS_REMOVE_FILE@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_REMOVE_FILE)).
     AccessFsRemoveFile
-  | -- | Create (or rename or link) a character device.
+  | -- | Create (or rename or link) a character device
+    -- ([@LANDLOCK_ACCESS_FS_MAKE_CHAR@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_MAKE_CHAR)).
     AccessFsMakeChar
-  | -- | Create (or rename) a directory.
+  | -- | Create (or rename) a directory
+    -- ([@LANDLOCK_ACCESS_FS_MAKE_DIR@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_MAKE_DIR)).
     AccessFsMakeDir
-  | -- | Create (or rename or link) a regular file.
+  | -- | Create (or rename or link) a regular file
+    -- ([@LANDLOCK_ACCESS_FS_MAKE_REG@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_MAKE_REG)).
     AccessFsMakeReg
-  | -- | Create (or rename or link) a UNIX domain socket.
+  | -- | Create (or rename or link) a UNIX domain socket
+    -- ([@LANDLOCK_ACCESS_FS_MAKE_SOCK@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_MAKE_SOCK)).
     AccessFsMakeSock
-  | -- | Create (or rename or link) a named pipe.
+  | -- | Create (or rename or link) a named pipe
+    -- ([@LANDLOCK_ACCESS_FS_MAKE_FIFO@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_MAKE_FIFO)).
     AccessFsMakeFifo
-  | -- | Create (or rename or link) a block device.
+  | -- | Create (or rename or link) a block device
+    -- ([@LANDLOCK_ACCESS_FS_MAKE_BLOCK@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_MAKE_BLOCK)).
     AccessFsMakeBlock
-  | -- | Create (or rename or link) a symbolic link.
+  | -- | Create (or rename or link) a symbolic link
+    -- ([@LANDLOCK_ACCESS_FS_MAKE_SYM@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_MAKE_SYM)).
     AccessFsMakeSym
   | -- | Link or rename a file from or to a different
     --   directory (i.e. reparent a file hierarchy).  This access right is
@@ -125,22 +150,34 @@
     --   access right.  When linking or renaming a file, the destination directory
     --   hierarchy must also always have the same or a superset of restrictions of
     --   the source hierarchy.  If it is not the case, or if the domain doesn't
-    --   handle this access right, such actions are denied by default with @errno@
-    --   set to @EXDEV@.  Linking also requires a @LANDLOCK_ACCESS_FS_MAKE_*@ access
-    --   right on the destination directory, and renaming also requires a
+    --   handle this access right, such actions are denied by default with
+    --   [@errno@](https://man.archlinux.org/man/errno.3)
+    --   set to [@EXDEV@](https://man.archlinux.org/man/errno.3#EXDEV).  Linking
+    --   also requires a @LANDLOCK_ACCESS_FS_MAKE_*@ access right on the
+    --   destination directory, and renaming also requires a
     --   @LANDLOCK_ACCESS_FS_REMOVE_*@ access right on the source's (file or
-    --   directory) parent.  Otherwise, such actions are denied with @errno@ set to
-    --   @EACCES@.  The @EACCES@ @errno@ prevails over @EXDEV@ to let user space
-    --   efficiently deal with an unrecoverable error.
+    --   directory) parent.  Otherwise, such actions are denied with
+    --   [@errno@](https://man.archlinux.org/man/errno.3) set to
+    --   [@EACCES@](https://man.archlinux.org/man/errno.3#EACCES).
+    --   The [@EACCES@](https://man.archlinux.org/man/errno.3#EACCES)
+    --   [@errno@](https://man.archlinux.org/man/errno.3) prevails over
+    --   [@EXDEV@](https://man.archlinux.org/man/errno.3#EXDEV) to let user
+    --   space efficiently deal with an unrecoverable error.
     AccessFsRefer
-  | -- | Truncate a file with @truncate@,
-    --   @ftruncate@, @creat@, or @open@ with
-    --   @O_TRUNC@. Whether an opened file can be truncated with
-    --   @ftruncate@ is determined during @open@, in the
-    --   same way as read and write permissions are checked during
-    --   @open@ using @LANDLOCK_ACCESS_FS_READ_FILE@ and
-    --   @LANDLOCK_ACCESS_FS_WRITE_FILE@. This access right is available since the
-    --   third version of the Landlock ABI.
+  | -- | Truncate a file with
+    -- [@truncate@](https://man.archlinux.org/man/truncate.2),
+    -- [@ftruncate@](https://man.archlinux.org/man/ftruncate.2),
+    -- [@creat@](https://man.archlinux.org/man/creat.2), or
+    -- [@open@](https://man.archlinux.org/man/open.2) with
+    -- [@O_TRUNC@](https://man.archlinux.org/man/open.2#O_TRUNC). Whether an
+    -- opened file can be truncated with
+    -- [@ftruncate@](https://man.archlinux.org/man/ftruncate.2) is determined
+    -- during @open@, in the same way as read and write permissions are checked
+    -- during [@open@](https://man.archlinux.org/man/open.2) using
+    -- [@LANDLOCK_ACCESS_FS_READ_FILE@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_READ_FILE)
+    -- and
+    -- [@LANDLOCK_ACCESS_FS_WRITE_FILE@](https://man.archlinux.org/man/landlock.7.en#LANDLOCK_ACCESS_FS_WRITE_FILE).
+    -- This access right is available since the third version of the Landlock ABI.
     AccessFsTruncate
   -- Note: when adding new flags, this likely means a new ABI version is
   -- available. Hence, add this to 'System.Landlock.Version' (and export it
diff --git a/internal/System/Landlock/OpenPath.hs b/internal/System/Landlock/OpenPath.hs
--- a/internal/System/Landlock/OpenPath.hs
+++ b/internal/System/Landlock/OpenPath.hs
@@ -41,13 +41,14 @@
   throwErrnoPathIfMinus1Retry "openat" pathname $
     fromIntegral <$> _openat (fromIntegral dirfd) pathnamep flags
 
--- | Extra flags used by 'withOpenPathAt' in the call to @openat@.
+-- | Extra flags used by 'withOpenPathAt' in the call to
+-- [@openat@](https://man.archlinux.org/man/openat.2).
 data OpenPathFlags = OpenPathFlags
-  { -- | Set @O_DIRECTORY@.
+  { -- | Set [@O_DIRECTORY@](https://man.archlinux.org/man/openat.2#O_DIRECTORY).
     directory :: Bool,
-    -- | Set @O_NOFOLLOW@.
+    -- | Set [@O_NOFOLLOW@](https://man.archlinux.org/man/openat.2#O_NOFOLLOW).
     nofollow :: Bool,
-    -- | Set @O_CLOEXEC@.
+    -- | Set [@O_CLOEXEC@](https://man.archlinux.org/man/openat.2#O_CLOEXEC).
     cloexec :: Bool
   }
   deriving (Show, Eq)
@@ -65,14 +66,16 @@
       cloexec = True
     }
 
--- | Perform an action with a path @open@ed using @O_PATH@.
+-- | Perform an action with a path opened using
+-- [@O_PATH@](https://man.archlinux.org/man/openat.2#O_PATH).
 --
--- The file descriptor provided to the action will be @close@d when the
--- function returns.
+-- The file descriptor provided to the action will be
+-- [@close@](https://man.archlinux.org/man/close.2)d when the function returns.
 --
--- This internally calls @openat@ with @AT_FDCWD@ and the @O_PATH@ and
--- @O_RDONLY@ flags set, next to any flags specified in the 'OpenPathFlags'
--- argument.
+-- This internally calls [@openat@](https://man.archlinux.org/man/openat.2) with
+-- @AT_FDCWD@ and the [@O_PATH@](https://man.archlinux.org/man/openat.2#O_PATH)
+-- and [@O_RDONLY@](https://man.archlinux.org/man/open.2#File_access_mode) flags
+-- set, next to any flags specified in the 'OpenPathFlags' argument.
 withOpenPath ::
   (MonadIO m, MonadMask m) =>
   -- | Path to open.
@@ -85,18 +88,25 @@
   m a
 withOpenPath = withOpenPathAt (fromIntegral aT_FDCWD)
 
--- | Perform an action with a path @openat@ed using @O_PATH@.
+-- | Perform an action with a path
+-- [@openat@](https://man.archlinux.org/man/openat.2)ed using
+-- [@O_PATH@](https://man.archlinux.org/man/openat.2#O_PATH).
 --
--- Like 'withOpenPath', exposing the @openat@ @dirfd@ argument.
+-- Like 'withOpenPath', exposing the
+-- [@openat@](https://man.archlinux.org/man/openat.2#O_PATH) @dirfd@ argument.
 --
--- The file descriptor provided to the action will be @close@d when the
+-- The file descriptor provided to the action will be
+-- [@close@](https://man.archlinux.org/man/close.2)d when the
 -- function returns.
 --
--- This internally calls @openat@ with the @O_PATH@ and @O_RDONLY@ flags set,
--- next to any flags specified in the 'OpenPathFlags' argument.
+-- This internally calls
+-- [@openat@](https://man.archlinux.org/man/openat.2) with the
+-- [@O_PATH@](https://man.archlinux.org/man/openat.2#O_PATH) and
+-- [@O_RDONLY@](https://man.archlinux.org/man/openat.2#File_access_mode) flags
+-- set, next to any flags specified in the 'OpenPathFlags' argument.
 withOpenPathAt ::
   (MonadIO m, MonadMask m) =>
-  -- | @dirfd@ argument to @openat@.
+  -- | @dirfd@ argument to [@openat@](https://man.archlinux.org/man/openat.2).
   Fd ->
   -- | Path to open.
   FilePath ->
diff --git a/internal/System/Landlock/Rules.hs b/internal/System/Landlock/Rules.hs
--- a/internal/System/Landlock/Rules.hs
+++ b/internal/System/Landlock/Rules.hs
@@ -69,12 +69,14 @@
 
 -- | Construct a path hierarchy rule definition.
 --
--- This corresponds to a rule of type @LANDLOCK_RULE_PATH_BENEATH@, with
--- attributes defined in a @struct landlock_path_beneath_attr@.
+-- This corresponds to a rule of type
+-- [@LANDLOCK_RULE_PATH_BENEATH@](https://man.archlinux.org/man/landlock_add_rule.2.en#LANDLOCK_RULE_PATH_BENEATH),
+-- with attributes defined in a @struct landlock_path_beneath_attr@.
 pathBeneath ::
-  -- | File descriptor, preferably opened with @O_PATH@, which
-  --   identifies the parent directory of a file hierarchy, or
-  --   just a file.
+  -- | File descriptor, preferably opened with
+  -- [@O_PATH@](https://man.archlinux.org/man/open.2#O_PATH), which
+  -- identifies the parent directory of a file hierarchy, or
+  -- just a file.
   Fd ->
   -- | Allowed actions for this file hierarchy
   --   (cf. 'AccessFsFlag').
diff --git a/landlock.cabal b/landlock.cabal
--- a/landlock.cabal
+++ b/landlock.cabal
@@ -1,7 +1,7 @@
 cabal-version:      2.2
 build-type:         Simple
 name:               landlock
-version:            0.2.1.0
+version:            0.2.1.1
 synopsis:           Haskell bindings for the Linux Landlock API
 description:
   This library exposes Haskell bindings for the Linux kernel Landlock API.
@@ -37,7 +37,8 @@
   cbits/hs-landlock.h
   cbits/linux/landlock.h
 
-tested-with:        GHC ==8.10.7 || ==9.0.2 || ==9.2.4 || ==9.4.2
+tested-with:
+  GHC ==8.10.7 || ==9.0.2 || ==9.2.4 || ==9.4.2 || ==9.6.1
 
 source-repository head
   type:     git
@@ -76,7 +77,7 @@
   import:           common-settings
   exposed-modules:  System.Landlock
   build-depends:
-    , base               >=4.14.2.0 && <4.17 || ^>=4.17
+    , base               >=4.14.2.0 && <4.18
     , exceptions         ^>=0.10.4
     , landlock-internal
     , unix               >=2.7.2.2  && <2.8  || ^>=2.8
@@ -99,7 +100,7 @@
   include-dirs:       cbits
   c-sources:          cbits/hs-landlock.c
   build-depends:
-    , base        >=4.14.2.0 && <4.17 || ^>=4.17
+    , base        >=4.14.2.0 && <4.18
     , exceptions  ^>=0.10.4
     , psx         ^>=0.1
     , unix        >=2.7.2.2  && <2.8  || ^>=2.8
@@ -128,7 +129,7 @@
   autogen-modules: Paths_landlock
   hs-source-dirs:  bin
   build-depends:
-    , base                  >=4.14.2.0 && <4.17 || ^>=4.17
+    , base                  >=4.14.2.0 && <4.18
     , exceptions            ^>=0.10.4
     , landlock
     , optparse-applicative  >=0.16.1.0 && <0.17 || ^>=0.17
@@ -142,7 +143,7 @@
   other-modules:    ThreadedScenario
   build-depends:
     , async                    ^>=2.2.3
-    , base                     >=4.14.2.0  && <4.17 || ^>=4.17
+    , base                     >=4.14.2.0  && <4.18
     , filepath                 ^>=1.4.2.1
     , landlock
     , landlock-internal
@@ -168,7 +169,7 @@
   other-modules:    ThreadedScenario
   build-depends:
     , async        ^>=2.2.3
-    , base         >=4.14.2.0  && <4.17 || ^>=4.17
+    , base         >=4.14.2.0  && <4.18
     , landlock
     , tasty        ^>=1.4.1
     , tasty-hunit  ^>=0.10.0.3
@@ -183,7 +184,7 @@
   other-modules:      ReadmeUtils
   hs-source-dirs:     . test
   build-depends:
-    , base       >=4.14.2.0 && <4.17 || ^>=4.17
+    , base       >=4.14.2.0 && <4.18
     , directory  ^>=1.3.6.0
     , filepath   ^>=1.4.2.1
     , landlock
@@ -203,7 +204,7 @@
   hs-source-dirs:     test
   main-is:            landlocked-test.hs
   build-depends:
-    , base         >=4.14.2.0  && <4.17 || ^>=4.17
+    , base         >=4.14.2.0  && <4.18
     , filepath     ^>=1.4.2.1
     , process      ^>=1.6.9.0
     , tasty        ^>=1.4.1
diff --git a/src/System/Landlock.hs b/src/System/Landlock.hs
--- a/src/System/Landlock.hs
+++ b/src/System/Landlock.hs
@@ -21,13 +21,12 @@
 -- behaviors in user space applications. Landlock empowers any process,
 -- including unprivileged ones, to securely restrict themselves.
 --
--- For more information, see the [Landlock homepage](https://landlock.io/) and its
--- [kernel documentation](https://docs.kernel.org/userspace-api/landlock.html).
+-- For more information, see the [Landlock homepage](https://landlock.io/), its
+-- [kernel documentation](https://docs.kernel.org/userspace-api/landlock.html)
+-- and its [manual page](https://man.archlinux.org/man/landlock.7.en).
 module System.Landlock
   ( -- * Core API
 
-    --
-
     -- | Use 'landlock' to sandbox a process.
     -- $example
     landlock,
@@ -35,8 +34,6 @@
 
     -- ** Filesystem Access Flags
 
-    --
-
     -- | Filesystem access flags to sandbox filesystem access.
     AccessFsFlag (..),
     accessFsFlags,
@@ -44,23 +41,17 @@
 
     -- * Sandboxing Rules
 
-    --
-
     -- | Sandboxing rules to apply.
     Rule,
     pathBeneath,
 
     -- * Utility Functions
 
-    --
-
     -- | Various utility functions.
     isSupported,
 
     -- ** Landlock ABI Version
 
-    --
-
     -- | Retrieve and handle the kernel's Landlock ABI version.
     abiVersion,
     Version,
@@ -71,11 +62,10 @@
 
     -- ** Opening paths using @O_PATH@
 
-    --
-
     -- | When creating a 'pathBeneath' rule, a file descriptor to a directory
-    -- or file is needed. These can be safely @open@ed using the @O_PATH@ flag
-    -- using the following functions.
+    -- or file is needed. These can be safely opened using the
+    -- [@O_PATH@](https://man.archlinux.org/man/openat.2#O_PATH) flag using the
+    -- following functions.
     withOpenPath,
     withOpenPathAt,
     OpenPathFlags (..),
@@ -105,7 +95,12 @@
     restrictSelfFlagToBit,
     toBits,
   )
-import System.Landlock.OpenPath (OpenPathFlags (..), defaultOpenPathFlags, withOpenPath, withOpenPathAt)
+import System.Landlock.OpenPath
+  ( OpenPathFlags (..),
+    defaultOpenPathFlags,
+    withOpenPath,
+    withOpenPathAt,
+  )
 import System.Landlock.Rules (Rule, pathBeneath, ruleType)
 import System.Landlock.Syscalls
   ( LandlockRulesetAttr (..),
@@ -122,6 +117,12 @@
 
 -- | Retrieve the Landlock ABI version of the running system.
 --
+-- This invokes
+-- [@landlock_create_ruleset@](https://man.archlinux.org/man/landlock_create_ruleset.2.en)
+-- with the
+-- [@LANDLOCK_CREATE_RULESET_VERSION@](https://man.archlinux.org/man/landlock_create_ruleset.2.en#LANDLOCK_CREATE_RULESET_VERSION)
+-- option.
+--
 -- __Warning:__ calling this on a system without Landlock support, or with
 -- Landlock disabled, will result in an exception.
 abiVersion :: IO Version
@@ -130,26 +131,31 @@
     flags = toBits createRulesetFlagToBit [CreateRulesetVersion]
 
 -- | Check whether Landlock is supported and enabled on the running system.
+--
+-- This calls 'abiVersion', catching relevant exceptions to return 'False' when
+-- applicable.
 isSupported :: IO Bool
 isSupported = handleJust unsupportedOperation (\() -> return False) $ do
   void abiVersion
   return True
   where
-    unsupportedOperation exc = if isUnsupportedOperationError exc then Just () else Nothing
-    isUnsupportedOperationError = isUnsupportedOperationErrorType . ioeGetErrorType
+    unsupportedOperation exc =
+      if isUnsupportedOperationError exc then Just () else Nothing
+    isUnsupportedOperationError =
+      isUnsupportedOperationErrorType . ioeGetErrorType
     isUnsupportedOperationErrorType = (== UnsupportedOperation)
 
 -- | Ruleset attributes.
 --
 -- This represents a @struct landlock_ruleset_attr@ as passed to
--- @landlock_create_ruleset@.
+-- [@landlock_create_ruleset@](https://man.archlinux.org/man/landlock_create_ruleset.2.en).
 
 {- HLINT ignore "Use newtype instead of data" -}
 data RulesetAttr = RulesetAttr
   { -- | Actions (cf. 'AccessFsFlag') that ought to
     -- be handled by a ruleset and should be
     -- forbidden if no rule explicitly allow them.
-    -- This is needed forbackward compatibility
+    -- This is needed for backward compatibility
     -- reasons.
     rulesetAttrHandledAccessFs :: [AccessFsFlag]
   }
@@ -160,10 +166,14 @@
   deriving (Show, Eq)
 
 createRuleset :: RulesetAttr -> [CreateRulesetFlag] -> IO LandlockFd
-createRuleset attr flags = with attr' $ \attrp -> wrap <$> landlock_create_ruleset attrp (fromIntegral $ sizeOf attr') flags'
+createRuleset attr flags = with attr' $ \attrp ->
+  wrap <$> landlock_create_ruleset attrp (fromIntegral $ sizeOf attr') flags'
   where
     wrap = LandlockFd . fromIntegral
-    attr' = LandlockRulesetAttr {landlockRulesetAttrHandledAccessFs = handledAccessFs}
+    attr' =
+      LandlockRulesetAttr
+        { landlockRulesetAttrHandledAccessFs = handledAccessFs
+        }
     handledAccessFs = toBits accessFsFlagToBit (rulesetAttrHandledAccessFs attr)
     flags' = toBits createRulesetFlagToBit flags
 
@@ -179,38 +189,48 @@
 -- instance (see 'addRule').
 --
 -- Once this returns, the Landlock sandbox will be in effect (see
--- @landlock_restrict_self@), and no privileged processes can be spawned
--- (@prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0)@ has been invoked).
+-- [@landlock_restrict_self@](https://man.archlinux.org/man/landlock_restrict_self.2.en)),
+-- and no privileged processes can be spawned
+-- (@[prctl](https://man.archlinux.org/man/prctl.2)([PR_SET_NO_NEW_PRIVS](https://man.archlinux.org/man/prctl.2#PR_SET_NO_NEW_PRIVS), 1, 0, 0, 0)@
+-- has been invoked).
 --
 -- __Warning:__ calling this on a system without Landlock support, or with
 -- Landlock disabled, will result in an exception.
 landlock ::
   (MonadMask m, MonadIO m) =>
-  -- | Ruleset attribute passed to @landlock_create_ruleset@.
+  -- | Ruleset attribute passed to
+  -- [@landlock_create_ruleset@](https://man.archlinux.org/man/landlock_create_ruleset.2.en).
   RulesetAttr ->
-  -- | Flags passed to @landlock_create_ruleset@. Since no flags but
-  --   'CreateRulesetVersion' (@LANDLOCK_CREATE_RULESET_VERSION@) are
-  --   defined, and this flag must not be used when creating an actual
-  --   ruleset, this should be an empty list.
+  -- | Flags passed to
+  -- [@landlock_create_ruleset@](https://man.archlinux.org/man/landlock_create_ruleset.2.en).
+  -- Since no flags but 'CreateRulesetVersion'
+  -- ([@LANDLOCK_CREATE_RULESET_VERSION@](https://man.archlinux.org/man/landlock_create_ruleset.2.en#LANDLOCK_CREATE_RULESET_VERSION))
+  -- are defined, and this flag must not be used when creating an actual
+  -- ruleset, this should be an empty list.
   [CreateRulesetFlag] ->
-  -- | Flags passed to @landlock_restrict_self@. Since no flags are
-  -- defined, this should be an empty list.
+  -- | Flags passed to
+  -- [@landlock_restrict_self@](https://man.archlinux.org/man/landlock_restrict_self.2.en).
+  -- Since no flags are defined, this should be an empty list.
   [RestrictSelfFlag] ->
   -- | Action that will be called before the Landlock sandbox is
   -- enforced. The provided function can be used to register
-  -- sandboxing rules (internally using @landlock_add_rule@),
+  -- sandboxing rules (internally using
+  -- [@landlock_add_rule@](https://man.archlinux.org/man/landlock_add_rule.2.en)),
   -- given a 'Rule' and a set of 'AddRuleFlag's. However, since no
   -- flags are currently defined, this should be an empty list.
-  ((Storable (Rule r) => Rule r -> [AddRuleFlag] -> m ()) -> m a) ->
+  (((Storable (Rule r)) => Rule r -> [AddRuleFlag] -> m ()) -> m a) ->
   -- | Result of the given action.
   m a
 landlock attr createRulesetFlags restrictSelfFlags act =
-  bracket (liftIO $ createRuleset attr createRulesetFlags) (liftIO . closeFd . unLandlockFd) $ \fd -> do
-    res <- act (addRule fd)
-    liftIO $ do
-      throwIfNonZero "prtcl" $ prctl pR_SET_NO_NEW_PRIVS 1 0 0 0
-      restrictSelf fd restrictSelfFlags
-    return res
+  bracket
+    (liftIO $ createRuleset attr createRulesetFlags)
+    (liftIO . closeFd . unLandlockFd)
+    $ \fd -> do
+      res <- act (addRule fd)
+      liftIO $ do
+        throwIfNonZero "prtcl" $ prctl pR_SET_NO_NEW_PRIVS 1 0 0 0
+        restrictSelf fd restrictSelfFlags
+      return res
 
 -- | Register a new 'Rule' with a Landlock instance.
 addRule ::
@@ -225,7 +245,11 @@
   m ()
 addRule fd rule flags = liftIO $
   with rule $ \ruleAttrp ->
-    landlock_add_rule (fromIntegral $ unLandlockFd fd) (ruleType rule) ruleAttrp flags'
+    landlock_add_rule
+      (fromIntegral $ unLandlockFd fd)
+      (ruleType rule)
+      ruleAttrp
+      flags'
   where
     flags' = toBits addRuleFlagToBit flags
 
