3 ms·
While this looks like a nice idea on paper, I would not recommend to use the current implementation of 'maybe' on a system that hosts valuable data. The tool s
by paulasmuth 11y ago
While this looks like a nice idea on paper, I would not recommend to use the current implementation of 'maybe' on a system that hosts valuable data.
The tool seems to work by intercepting individual "blacklisted" system calls and then - instead of executing them - returning a nonsense value.
The issue is that this breaks every single POSIX spec and will therefore break any program that does more than a few trivial IO operations and relies on those operations to behave as specified.
So it might work for a simple demo case where a small script only does a single file modification and never checks the results, but for any serious program (think a database, a complex on-disk format or really anything that does network IO) this will lead to corruption and undefined behaviour as system calls will return erroneous success values or invalid file descriptors.
I think to actually make this work one would have to emulate the system calls and make sure everything stays POSIX compliant. Doing this correctly for calls like mmap might get tricky though (and won't be possible from within a python runtime). And even then it isn't obvious how something like network IO would be handled.
- bcook 11y agoMy simple Perl todo script (either writing or reading a text file) causes the "maybe" program to fail while partially reading/outputting the todo archive file.
- paulasmuth 11y agoYes, the current 'maybe' implementation should practically break almost any properly written IO code. At this point, it will only work for the most trivial of demo cases. Still IMO it's a cool demonstration of the linux ptrace facility. And if the author implements the missing sandboxing/emulation layer in a future version and switches to whitelisting instead of blacklisting syscalls I think it could actually run a limited number of programs (forbidding stuff like mmap and network IO).
- bcook 11y agoAn absolutely cool project, but I fear the amount of work required to bring it out of the beta stage. Python seems to be a good choice for a fun project, but I do not see this project evolving much without resorting to lower-level languages.
- DavideNL 11y agoObviously, that's why the Github description says: > That being said, maybe should :warning: NEVER :warning: be used to run untrusted code on a system you care about! A process running under maybe can still do serious damage to your system because only a handful of syscalls are blocked. Currently, maybe is best thought of as an (alpha-quality) "what exactly will this command I typed myself do?" tool.
- jacobparker 11y agoYou've missed Paul's point I think. Even running trusted code is unlikely to work as desired (and could still have negative consequences due to what isn't included in the "sandbox") for anything other than trivial programs.
- DavideNL 11y agoI understood. Obviously the author knows about these limitations, otherwise he wouldn't be able to write such a tool... but still it can be useful; It's alpha, the tool can be used on trivial programs and you should be aware of its limitations.