13 ms·
How sandboxing works in Fuchsia
- pjjhdog 9y agoSo I'm not clear what the puropse of fuchsia is. I understand it's an os which may replace android or chomeos but why the move away from linux based systems? Both are open source platforms.
- joshumax 9y agoI can't say everything I've heard for NDA reasons but I've been under the impression its use is in future resource-constrained IoT devices, which tend to lack a secure, lightweight OS with a unified API. Reverse engineering a certain "smart" nightlight uncovered a minimal Linux 2.6.xx rootfs with telnet open and enabled by default
- awordnot 9y agoWhat does that have to do with Linux though? Surely it's the manufacturer's fault for leaving telnet open and not updating? How would a new OS solve any of these issues?
- remir 9y agoTake a look at the repo. Fuchsia is an OS for mobile devices. The UI is clearly made for phones, they use the Flutter framework, which was made specifically for mobile app development and can target iOS and Android too.
- tyingq 9y agoPerhaps. The current set of boot instructions are for a NUC desktop, a laptop, and 2 ARM dev boards though. https://fuchsia.googlesource.com/magenta/+/master/docs/targets/ https://fuchsia.googlesource.com/magenta/+/master/docs/targe...
- dikaiosune 9y agoThe hardware in that Acer laptop looks surprisingly similar to what a current flagship phone has in terms of resources if not exact architecture.
- tyingq 9y agoI guess generically in that it has a touchscreen, limited hdd size, etc. It's an i5 Intel x64 CPU though.
- dikaiosune 9y agoI believe my phone runs a 64bit ARM with eight 2.3ghz cores and has the same amount of ram as the base Acer model?
- tyingq 9y agoThe i5 has 2 cores, different memory bus setup, cache setup, etc. If you're saying it has the same rough level of horsepower, that makes sense. Not at all the same architecture though.
- dikaiosune 9y ago> similar to what a current flagship phone has in terms of resources if not exact architecture. :)
- bitmapbrother 9y ago>Take a look at the repo. Fuchsia is an OS for mobile devices. The UI is clearly made for phones No it's not. Fuchsia is device agnostic. It's for mobile devices, personal computers, IOT devices, etc. Just because it uses Flutter does not restrict it to mobile devices.
- bitmapbrother 9y ago>I can't say everything I've heard for NDA reasons but I've been under the impression its use is in future resource-constrained IoT devices. I highly doubt that. "Magenta targets modern phones and modern personal computers with fast processors, non-trivial amounts of ram with arbitrary peripherals doing open ended computation" Magenta is the name of the Fuchsia kernel. https://fuchsia.googlesource.com/magenta/+/HEAD/docs/mg_and_lk.md https://fuchsia.googlesource.com/magenta/+/HEAD/docs/mg_and_...
- mythz 9y agoIt's not clear because its purpose has not been made public. Google has the resources to undertake developing a new OS, which they obviously believe will have benefits over being based on Linux like ChromeOS is. Being free of legacy constraints gives them the freedom to explore better ways to achieve they're objectives, e.g Security and UI performance.
- awqrre 9y agosecurity and UI performance... color me doubtful...
- catern 9y ago>open source platforms Part of the motivation is certainly to get away from the GPL requirements of using Linux, so that Google and its partners can release products to users that have proprietary modifications to the kernel, without giving those same users access to the source code of the kernel. That would of course be a disaster for user autonomy and freedom, but why should Google care about that... Edit: This isn't just about the license, but also about the structure of the code. Fuschia is based on a microkernel. "Microkernel" doesn't just mean "modular kernel"[1] it also means "run drivers and systems in a separate process with a separate executable". That imposes performance penalties, but it can enforce a better programming style... and it also allows low-quality proprietary vendor code to be isolated from the base system and not have to pass quality checks or open its source. [1] Linux is very modular despite being monolithic, and there have been academic operating systems like https://en.wikipedia.org/wiki/Language-based_system https://en.wikipedia.org/wiki/Language-based_system which are extremely modular and well designed despite (or perhaps because of) operating entirely in ring 0. Microkernels of course require modularity; but modularity doesn't require microkernel. The key problem with having all your code linked into one executable, of course, is that it requires you to have all your code...
- djsumdog 9y agoCompanies are embracing open source these days, but not the GPL. We see that with gcc and clang, or in the way MacOS uses older versions of tools just to avoid GPLv3: http://penguindreams.org/blog/the-philosophy-of-open-source-in-community-and-enterprise-software/ http://penguindreams.org/blog/the-philosophy-of-open-source-... The OSS utopia pushed in the the 1990s, with tools like Gimp being one day comparable to Photoshop, never really happened.
- catern 9y agoOK, but that's irrelevant. Kernels are an entirely different class of thing. I'm fine with permissive licenses for higher-level software such as clang or GIMP. But I'm not looking forward to a world where I can't get the source code for a kernel that will actually run on real hardware. It's already painful to compile and run Android from source. Fuschia will make it just impossible.
- mehrdada 9y agoProbably the same purpose Singularity served for Microsoft. Researchers gotta research.
- themacguffinman 9y agoFuchsia uses a microkernel (Magenta) which is more secure and technically elegant, but usually comes at the cost of performance. Google's position as the primary/sole developer of Fuchsia also gives them the control to build the OS in commercially lucrative ways that don't necessarily earn the approval of the Linux open source community (programming shortcuts, proprietary/non-GPL extensions, etc).
- kjksf 9y agoI'm guessing that you think it's a bad thing but I don't quite understand your position. Is it a new standard that if company develops code, they are morally required to seek "approval of the Linux open source community" ? Are we applying this standard only to Google, or all companies? If writing and open-sourcing code under permissive license is bad if it's done without "approval of Linux open source community", then how bad, in comparison, is what e.g. Apple or Microsoft do (not open sourcing iOS or Windows)?
- nxtrafalgar 9y agoAs I interpreted it, that's not their position. They're saying that if Google were to pursue their OS goals, specifically using Linux as a base, then they would likely end up doing things that would earn the scorn of the Linux community (at least; it's more likely that what they want to do is GPL-violating).
- geofft 9y agoI don't think that comment was expressing a clear opinion either way, just stating that as long as Google is basing their software on Linux they are definitely legally obligated to follow certain rules (e.g., no direct linking of proprietary drivers provided by a vendor) and vaguely politically obligated to follow others (e.g., there's a fair bit of C++ in Magenta; adding C++ to a fork of Linux is technically straightforward but would upset people and also make it hard for patches to your fork to go upstream).
- sitkack 9y agoThe other way we get separation is run multiple VMs under KVM which also has an overhead. The Microkernel arch that Linus never wanted is in fact, what we have right now. Exokernels and safe languages are necessity for getting having a good lifetime under battery power and having decent level of security.
- jnwatson 9y agoIt looks to be a capability-based microkernel in the spirit of L4 and Green Hills' Integrity.
- klodolph 9y agoI don't know what Google's purpose for Fuchsia is, but Linux was originally designed for a security model which is uncommon these days. The Linux security model protects different users from each other, but these days it's much more common that a computer will only have one user, and you want to protect that one user from potentially harmful code. Capability-based security is a big step in that direction. I don't know what "they're both open-source" has to do with it, obviously there are other reasons to choose between different pieces of software besides the license.
- armitron 9y agoLinux is a disaster security-wise (look at how massive things like grsecurity are) and that won't change anytime soon. Android has inherited all of that and it's by far the shittiest mobile OS out there in terms of how easy it is to own. It makes sense that Google would like to move away from Linux given how important mobile security is and will become in the future. They certainly have the resources to get it right, starting from a clean slate.
- bitmapbrother 9y ago>Android has inherited all of that and it's by far the shittiest mobile OS out there in terms of how easy it is to own. Then why don't you try? Google has $200,000 USD waiting for you to exploit a fully patched Pixel. Or are you too rich to make it worth your while? If you're going to say something that silly at least have the technical prowess to walk the talk.
- armitron 9y agoFirst, is there a point that you are trying to make because I didn't see any. Second, 200k USD for a vulnerability of such caliber is peanuts. Third, you must have missed this: http://blog.trendmicro.com/results-mobile-pwn2own-2016/ http://blog.trendmicro.com/results-mobile-pwn2own-2016/
- bitmapbrother 9y agoI think my point is pretty clear - your comments regarding the state of Android security are very lacking. I suggest you watch this video by Adrian Ludwig at Next 2017 for an overview: https://www.youtube.com/watch?v=Zm6ziX5pqt8 https://www.youtube.com/watch?v=Zm6ziX5pqt8 >Second, 200k USD for a vulnerability of such caliber is peanuts. I think that's the going rate offered by companies that buy exploits like Zerodium. Do you know of a company offering a better price? >Third, you must have missed this: http://blog.trendmicro.com/results-mobile-pwn2own-2016/ http://blog.trendmicro.com/results-mobile-pwn2own-2016/ First, the hack was impressive because of all of the exploits they had to chain. Perhaps this gives you an understanding of just how difficult it really is and why I called your comments regarding Android security silly. Secondly, I don't believe their hack was possible via RCE and needed physical access to the device. Third, you neglected to mention that not only was the iPhone hacked, but it was done so twice. Additionally, the 2 iPhone hacks earned more money than the Nexus 6P hack. Did you also want to comment on the state of iOS security?
- bitmapbrother 9y agoI think it's pretty clear. They want an OS that can scale to any device. Whether Fuchsia replaces Android is unclear, but having their own PC OS in which Android can seamlessly integrate with much like iOS and MacOS can is very appealing.
- dingo_bat 9y agoIntegration between iOS and Mac OS may just be because Apple controls both of them tightly. It doesn't tell us much about OS similarity or any deeply shared code. You can make two very different OSes integrate seamlessly with each other given full control over the OS code.
- izacus 9y agoThe other explanation is that it would be easier to maintain - right now Android kernel is not the same as mainline kernel and has a few rather large functional patches (things like Binder, some modified permissions, wakelock system, support for BIG.little) which are really tough to port ahead. This is why most of devices are still running rather old kernels - e.g. even Pixel is on 3.18. Patches for these largest features weren't accepted into mailine - they're not really fully fit for a general-purpose kernel and Google's and Linux kernel teams differ in opinions if they're even required and how they should be implemented. As such, it probably makes sense for Google to use their own, fully internally developed, kernel which is built from ground up to handle IPC, security and mobile chips in the way Android/ChromeOS expect it to.
- cwp 9y agoI'm interested in it from a purely technological point of view. Linux is almost 30 years old, and it's architecture is almost 50 years old. Xnu, which is the kernel of iOS is a bit more modern, but Apple has gradually moved it back towards a monolithic BSDish, posix-compliant kernel over the years. We've actually learned a few things about operating systems since 1970, and today's hardware vastly different from the time-sharing systems of that day. It would be really useful to just implement an OS based on more modern ideas and see where it goes. I have no idea what Google is planning for Fuscia, but I hope that's part of it.
- coldtea 9y ago>but why the move away from linux based systems? Both are open source platforms Perhaps because whether it's "open source" is not that much of a concern, but rather whether it has the kind of control (over its evolution) and/or next generation design they want?
- naiveattack 9y agoProprietary drivers allow a lock in to fuschia os and devices allowing Google more control over the platform. We probably need open source hardware for this to go away and to be free.
- DonbunEf7 9y agoIf you're going to have capability-based security, please be louder and prouder about it.
- nickpsecurity 9y agoMaybe. They start with names. However, the description looks more like access control lists than what I saw in KeyKOS, LOCK, EROS, E, or Combex's work.
- stefankomatsu 9y ago> An empty process has nothing > Namespaces are the gateway to the world Sounds like capability security to me. Although I wish they had said more about how these namespaces work. If they are inheritable and you can virtualize them for child processes (as you can in Plan 9/Inferno) then I'd say it qualifies.
- abarth 9y agoWhen you create a child process, you can clone your namespace or you can construct a new one for the child. (Disclosure: I wrote the doc linked above.)
- nickpsecurity 9y agoSomeone told me there were ex-devs of QNX microkernel doing Google's. Is that true?
- bitmapbrother 9y agoNot sure about QNX, but the lead developers are ex Be, Danger, Palm and Apple.
- nickpsecurity 9y agoThanks for that clarification. That is an interesting mix.
- throw2016 9y agoAndroid for all practical purposes is as good as a closed ecosystem with apps tied to closed source Google services and the inability to run Linux on your Android phones. This kind of lip service and self serving tip toeing around the spirit of open source in many ways does more harm to open source than closed source. How is it that devices drivers that work on Android perfectly are not available for use on Linux? What purpose does this kind of 'open source' then serve? Between Arm, its licensees and Google the ball is kicked around with open source devs struggling for years to make things work. Yet the narrative is this is no one's fault least of all Google and Arm, the 2 most powerful forces in the Android ecosystem. Google the planet's largest spyware and adware company is now making its own kernel. More power to them but given their track record healthy skepticism of their objectives and agenda is called for.
- ocdtrekkie 9y agoThis is definitely true, and I have a lot of issues with Google and their lip service to open source. (People reading my history will attest, I'm sure.) But at the very least, Fuchsia will be a lot more secure by design than Android, and Android is the dominant OS platform on earth. The state we are right now, where 85% of mobile devices run Android, and 0.7% of them are actually up to date, is a terrifying place to be from a security standpoint.
- bitmapbrother 9y agoWhy am I not surprised that you can't even get your percentages correct.
- IshKebab 9y agoDid you mean he was exaggerating? Because it's actually 0.6%.
- ocdtrekkie 9y agoSorry, unfortunately I did get my numbers wrong. Based on a chart of Android versions taken from the Google site, it will probably be at least a month or two before 0.7% of Androids are running the latest version. My bad! I keep a running copy of the stats here: https://oasis.sandstorm.io/shared/UtPbpOAW2OaV4QpkgwIclqGeGC0tC5dYfqg4_c17r3Y https://oasis.sandstorm.io/shared/UtPbpOAW2OaV4QpkgwIclqGeGC...
- omarforgotpwd 9y agoSounds kind of like the rebirth of plan9
- digitalzombie 9y agoWell they got the same artist that made glen the rabbit to make the gopher for Go. Maybe they can get that artist to do a mascot for Fuchsia.
- stock_toaster 9y agoRenée French is the artist. She is married to Rob Pike.
- unlmtd 9y agoExactly my thought. I'm so excited about this.
- bitmapbrother 9y agoHere are a couple of YouTube video's showing the early stages of the Fuchsia UI: https://www.youtube.com/watch?v=MPhQ-8fXft8 https://www.youtube.com/watch?v=MPhQ-8fXft8 https://www.youtube.com/watch?v=Vu0VGj5xf60 https://www.youtube.com/watch?v=Vu0VGj5xf60
- Apofis 9y agoLooks like they are already pretty far ahead. Wonder if they plan to replace both android and ChromeOS with Fuchsia.
- negus 9y ago"dev, gn, /svc, /pkg, PA_VMAR_ROOT" Hate this old unix approach for name shortening, what makes them unreadable and non intuitive. If they break compatibility anyway, they could name things in a way, that people can read like a book.
- lloydjatkinson 9y agoFully agree. No need for the shitty parts of UNIX to be in a new OS. Use full names. I've never used OSX/macOS but I do admire how they've gone about doing the whole UNIX thing, there seems to actually be some standard to it unlike the LSB and from what I gather to uninstall a program you just delete it's directory. Try doing that on literally any other mainstream OS!
- maccard 9y agoDoesn't always work. Lots of apps end up leaving data Lyon around in Library, and some of the "big name" apps require a full installer and uninstalled, along with admin privileges (see adobe, autodesk, Microsoft)
- resf 9y agoUnfortunately not. You also have to delete from ~/Library/Caches at the least. If you want to delete the user data then you will need to delete from ~/Library/Application Support, Preferences, Containers, etc, etc...
- mda 9y agoI agree, I would much prefer short but full names (lowercase). svc is especially cringy.
- gigatexal 9y agoMy take is that Fuchsia is Google's attempt to unify their mobile ecosystem under one proprietary OS like Apple does with iOS (yes, yes I hear you, "But Darwin is OSS..." try making that into iOS though...): which is a good move for Google.
- umren 9y ago> under one proprietary OS fuchsia and all it's components are licensed under BSD 3 clause, MIT, Apache 2.0
- jhasse 9y agoWhich means they can fork it anytime into a proprietary one.
- alexvoda 9y agoThey can do that regardless of the license since they own the copyright. As long as they do not accept external contributions or require a CLA it does not matter what license they offer, they can still make future versions proprietary.
- jhasse 9y agoTrue, that's why there needs to be a distinction between "GPL" and "GPL with CLA".
- zer0tonin 9y ago> they do not accept external contributions They do tho.
- Matumio 9y agoEven if they accept contributions normally (e.g. under the same license), the above licences will allow them (or anyone else) to make a proprietary fork.
- sametmax 9y ago
- legulere 9y agoHow to request capabilities at run time? Android has shown that the approach of asking for a list of capabilities while installing does not work for user-facing applications. Apps will grab just as much as capabilities as possible and users will blindly accept the long list without reading.
- geocar 9y agoThe same way mach does it. You send a message to a process that dishes out capabilities and it responds with a handle/port/object that encodes those capabilities.
- bigato 9y agoIf the only options available are granting all requested permissions at once or not installing at all, they'll often blindly accept, yes.
- mtgx 9y agoToo bad Fuchsia isn't also written in Rust.
- naasking 9y agoExcept you can't sandbox or virtualize the clock because mx_time_get() doesn't require a handle, which makes timing attacks easier. You also can't sandbox event and channel creation for the same reason. It looks like these can also DoS the kernel. In general, any operation you can perform without a handle tends to be subject to DoS and you can't virtualize it. They're also subject to a different access control policy than the rest of the system which is based around handles. And it's not really necessary. Just reserve the first few handles in a process table for a clock handle, a channel constructor/factory handle and an event constructor/factory handle, and now these operations can be fully virtualized and they aren't subject to DoS because they can be rate-limited or at least traced back to specific handles which can be revoked. Without tracing every operation to a handle, you have to pollute your model with more infrastructure to track this information, as with channels and events in Fuschia. [1] https://fuchsia.googlesource.com/magenta/+/master/docs/concepts.md https://fuchsia.googlesource.com/magenta/+/master/docs/conce...
- kyrra 9y agoI'd be interested if this has been brought up with the dev team via IRC, mailing list, or some other medium so they can explain their reasoning?
- naasking 9y agoI'm sure they're at least familiar with past capability operating systems given their design. Shapiro covered many of these issues in his EROS work.
- swetland 9y agoThe creation syscalls operated under the execution constraints of the Job in which your Process is contained. The APIs aren't fully landed, but it will (very soon) be possible to create Jobs where-in none of the kernel object creation syscalls will be allowed. You can think of the creation syscalls as taking an implied handle to the Process's Job, which is an "object factory" similar to what you suggest. There are mechanisms in the works to allow the VDSO to be customized per-Job along similar lines (providing a way of addressing mx_time_get(), etc). mx_time_get() is actually provided entirely in userspace in the default VDSO, but of course we want to allow for runtime environments where we don't allow direct access to the TSC or equivalent. There aren't any "known" handles in the Magenta design, as handles are not small integers nor aggressively reused (as fds are in unixen). The intention there is to make use-after-free errors with handles more difficult and to make guessing what handles a process has harder. It's definitely not a "pure" capability design or a "pure" (read/write/exit) microkernel underneath. The goal is to try to be pragmatic and balance performance and api usability/convenience with the benefits of a capability system. It's also a system in development and the shape of things has changed and almost certainly will change further before we're done.
- czeidler 9y agoSound like Genode: http://genode.org/documentation/general-overview/index http://genode.org/documentation/general-overview/index