6 ms·
Pledge and Unveil in OpenBSD [pdf]
- teamhappy 8y agoDoes anybody here know when the videos will be up?
- akavel 8y agoThe PDF has no introduction section, seems to be aimed at people who already know what it's talking about. Can anyone shed some light on what is the idea here? I honestly don't understand what's going on, apart from that it seems to be some security-related feature (or actually two of them?)
- beefhash 8y agopledge(2) on OpenBSD is used to drop the privileges of a process. Processes are meant to call pledge(2) to drop their own privileges. The way pledge(2) works is that the system calls of that process get limited. If a process calls a system call outside the allowed range after calling pledge(2), it gets killed. Starting with OpenBSD 6.3, it is also possible to configure pledge to make the kernel return ENOSYS instead of killing the process when violating the pledge. For example: /* Only the system calls required * for the standard I/O library and * for accessing /dev/tty are allowed * by the kernel from this point on. */ pledge("stdio tty", NULL); The second argument is the execpromises, i.e., the pledges enforced for child processes. This does not need to be specified if you pledge in a way that does not include any way of spawning a new process. What's new in the slides linked is unveil(2). This seems to be used to limit the exact paths a process can access and with what access flags (rwxc).
- Fnoord 8y agoWasn't there some kind of equiv in OpenBSD long ago, by Niels Provos? Or was it the Stephanie patch? [1] At the bottom they mention Qmail which was immediately my first thought as an example as well, since it breaks up MTA tasks to different daemons. [1] http://packetfactory.openwall.net/projects/stephanie/index.html http://packetfactory.openwall.net/projects/stephanie/index.h...
- nbe 8y agoI think you're refering to systrace. It was removed in OpenBSD 6.0. http://www.citi.umich.edu/u/provos/systrace/ http://www.citi.umich.edu/u/provos/systrace/
- Fnoord 8y agoThanks, that's exactly what I meant. Why was it removed? I did notice pledge(2) first appeared in 5.9 [1] How do other Unices such as Linux deal with this issue (IIRC systrace was ported to other Unices)? Is Pledge ported to other BSDs? [1] http://man.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man2/pledge.2 http://man.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man2/...
- 4ad 8y agoSystrace was removed because it's unsafe for multi-threaded programs because of TOCTOU.
- gpvos 8y agoTOCTOU = time-of-check time-of-use
- wahern 8y agoThe race only existed for path strings. systrace was no worse than seccomp in this respect (which doesn't even permit filtering on paths precisely because of the systrace exploit), yet still much easier to use. systrace was removed because it went largely unused. Theoretically powerful, in practice it made the wrong compromises. seccomp recapitulated the same compromises, and it's not surprising seccomp uptake has been similarly weak.
- nbe 8y agoFrom what I understand it was not maintained anymore, and it was also hard to keep up to date lists of allowed or forbidden system calls for the binaries that had to be run under systrace. [1] [2] Linux provide seccomp-bpf for system call restrictions. [3] [1] https://marc.info/?l=openbsd-misc&m=146170224108205&w=2 https://marc.info/?l=openbsd-misc&m=146170224108205&w=2 [2] http://www.openbsd.org/papers/hackfest2015-pledge/mgp00009.html http://www.openbsd.org/papers/hackfest2015-pledge/mgp00009.h... [3] https://lwn.net/Articles/656307/ https://lwn.net/Articles/656307/
- sigjuice 8y agopledge is seccomp
- lkurusa 8y agoNot really; seccomp(2) is for _specific_ system calls, pledge(2) is for more broad functionalities.
- deleted 8y ago[deleted]
- sigjuice 8y agoI didn’t say they are bug-for-bug compatible and 100% interchangeable. Seccomp was not mentioned anywhere in the thread. People who are interested can look up the specific details.
- brynet 8y agoNot at all, for example you can't implement the ratcheting down semantics of pledge() using seccomp. Say starting with a broader promise set "stdio rpath recvfd", and then dropping to "stdio" after full init. pledge() can also be found in over 85% of OpenBSD's base system.
- kworker 8y agoOn linux you can use firejail if it's necessary (or a container if it's needed).
- staticassertion 8y agoThis doesn't address what they just said - dropping privileges incrementally. Firejail is just a whole process filter applied at process start.
- agumonkey 8y agobrings me to the next question: are there linux equivalent ?
- zdw 8y agoNice. Back in earlier versions of pledge(2), there was another argument that took paths to allow fs access on, as unveil(2) is doing, but it was never supported/implemented. (see http://man.openbsd.org/OpenBSD-6.0/pledge.2 http://man.openbsd.org/OpenBSD-6.0/pledge.2 for the old syntax)
- brynet 8y agoThese are the slides from Bob Beck (beck@'s) talk at BSDCan 2018 (Jun 8-9th), apparently missing its first page.. [0] http://www.bsdcan.org/2018/schedule/events/968.en.html http://www.bsdcan.org/2018/schedule/events/968.en.html Video should eventually show up on YouTube. [0] https://twitter.com/bob_beck/status/1005162340956794880 https://twitter.com/bob_beck/status/1005162340956794880 ;-)
- brynet 8y agoA somewhat related talk from BSDCan was Florian Obser's slaacd(8) - "A privilege separated and sandboxed IPv6 Stateless Address AutoConfiguration Daemon" https://www.openbsd.org/papers/florian_slaacd_bsdcan2018.pdf https://www.openbsd.org/papers/florian_slaacd_bsdcan2018.pdf http://www.bsdcan.org/2018/schedule/events/929.en.html http://www.bsdcan.org/2018/schedule/events/929.en.html
- Panino 8y agoAwesome! Given the Chrome example starting on page 6, here's my guess as to how pledge and unveil will contain Chrome to e.g. protect SSH keys. First, 3 of the 5 Chrome processes are already pledged to disallow filesystem reads. The two remaining ones (RenderProcess and UtilityProcess) can be unveiled to allow directories like * ~/.config/chromium * ~/.cache/chromium * ~/Downloads * /tmp * and anything important I don't know of Additionally, if unveil works like pledge and can be further restricted after e.g. reading files into memory, unveils can then be undone. Anyone know if the following would work to first allow access to /tmp and then revoke that access? unveil("/tmp", "rw"); /* do some work */ unveil("/tmp", "");
- notaplumber 8y agoIndeed! The full unveil semantics aren't known yet, may be worth proposing! But for the specific case of /tmp, there is already a tmppath promise.
- toxik 8y agoShouldn't it be veil()?
- badsectoracula 8y agoThe idea is that everything is "veiled" and you "unveil" the stuff you need access to.
- gpvos 8y agoYes, but the weird thing is that before you call unveil, everything is already unveiled, which is not in sync with the dictionary definition of unveiling. I hope a better name is found.
- notaplumber 8y agoIt's unveiling in the context of pledge, as you explicitly declare the things to be unveiled.