5 ms·
I wonder why did Apple block tracing SIP protected programs? Like, wasn't SIP supposed to protect against their modification on disk, like NetBSD's veriexec? Ho
by floatboth 8y ago
I wonder why did Apple block tracing SIP protected programs? Like, wasn't SIP supposed to protect against their modification on disk, like NetBSD's veriexec? How would DTracing rm be dangerous?
- saagarjha 8y agoBecause then people could trace rm in a way that allowed them to run arbitrary code in that process. It's the same issue you'd have if you attached a debugger to the process or loaded a dynamic library in their address space.
- lathiat 8y agoThat is not true, dtrace cannot modify data and is specifically designed not to do so. It can however be used to leak information or read info out of other processes. I was going to say that for this reason even on linux you can't ptrace processes that are not children of the current process (e.g. you can run something under strace, but not attach to an existing process unless you twiddle a flag or do it as root). Having said that, you CAN modify data with ptrace, unlike dtrace. So that's kindof an aside. In any case the idea is that one process can't hijack another even from the same user for ptrace.
- saagarjha 8y agoAs far as I was aware, dtrace lets you perform essentially arbitrary reads/writes of process memory using copyin and copyout. Is this not true?
- lathiat 8y agoIt appears you are correct. TIL. There are a few “destructive actions” that can be enabled with a DTrace flag and also require appropriate system permissions. Never the less.