3 ms·
That statement was comparing capsicum being applied to programs that were also pledged in around 2 lines of code. A few of the programs on the wiki as examples
by aomix 10y ago
That statement was comparing capsicum being applied to programs that were also pledged in around 2 lines of code. A few of the programs on the wiki as examples of capsicum applications originated from OpenBSD so they were primed and ready to go. Even those best cases are much more involved than pledge.
To use the example of the unix tr utility, the change to use pledge required the standard two line diff.
if (pledge("stdio", NULL) == -1)
err(1, "pledge");
tr.c was the one of the earliest programs pledged (back when it was called tame). The original diff was a one liner before they start doing the "pledge or error out".
http://marc.info/?l=openbsd-tech&m=144070638327053 http://marc.info/?l=openbsd-tech&m=144070638327053
+ tame(TAME_STDIO, NULL);
The capsicum diff required the following
https://reviews.freebsd.org/D7928 https://reviews.freebsd.org/D7928
https://reviews.freebsd.org/file/data/4exxbzvuc3dayrvdj6qe/PHID-FILE-2kbbfbdvu7dpl2u3ztnx/D7928.diff https://reviews.freebsd.org/file/data/4exxbzvuc3dayrvdj6qe/P...
+ cap_rights_t rights;
+ unsigned long cmd;
(...)
+ cap_rights_init(&rights, CAP_FSTAT, CAP_IOCTL, CAP_READ);
+ if (cap_rights_limit(STDIN_FILENO, &rights) < 0 && errno != ENOSYS)
+ err(1, "unable to limit rights for stdin");
+ cap_rights_init(&rights, CAP_FSTAT, CAP_IOCTL, CAP_WRITE);
+ if (cap_rights_limit(STDOUT_FILENO, &rights) < 0 && errno != ENOSYS)
+ err(1, "unable to limit rights for stdout");
+ if (cap_rights_limit(STDERR_FILENO, &rights) < 0 && errno != ENOSYS)
+ err(1, "unable to limit rights for stderr");
+
+ /* Required for isatty(3). */
+ cmd = TIOCGETA;
+ if (cap_ioctls_limit(STDIN_FILENO, &cmd, 1) < 0 && errno != ENOSYS)
+ err(1, "unable to limit ioctls for stdin");
+ if (cap_ioctls_limit(STDOUT_FILENO, &cmd, 1) < 0 && errno != ENOSYS)
+ err(1, "unable to limit ioctls for stdout");
+ if (cap_ioctls_limit(STDERR_FILENO, &cmd, 1) < 0 && errno != ENOSYS)
+ err(1, "unable to limit ioctls for stderr");
+
+ if (cap_enter() < 0 && errno != ENOSYS)
+ err(1, "unable to enter capability mode");
No one would dispute that capsicum is more capable but is significantly more complex. Pledge trades finer control over capabilities for the ability to have a "work or die" usage model. Capsicum requires that you be aware of all the potential failure cases and account for them.
- loeg 10y ago> The capsicum diff [to tr] required the following ... This is a slightly out of date example. We've since added simplifying wrappers for stdio. The current equivalent of if pledge("stdio", ...) / err is: if (caph_limit_stdio() < 0 || (cap_enter() < 0 && errno != ENOSYS)) err(); Some examples: https://reviews.freebsd.org/D8307 https://reviews.freebsd.org/D8307 > a "work or die" usage model This is an option (or will shortly become an option) in capsicum.
- aomix 10y agoThat's really cool, thanks.