3 ms·
> The names of the promises are obvious and their intention is clear. There are subsets of POSIX. That's true, but not really the whole truth. Take "dns", for
by markjdb 8y ago
> The names of the promises are obvious and their intention is clear. There are subsets of POSIX.
That's true, but not really the whole truth. Take "dns", for instance. It enables a number of system calls needed to perform DNS resolution. But as far as I understand, those system calls (sendto(2) for example) can then be used arbitrarily. So "dns" actually permits more than the name implies.
On the other hand, when a program is running in capability mode, we know exactly what is permitted and what isn't.
> Capsicum has no solution for this, and as such these programs cannot be sandboxed on FreeBSD.
... they can't be sandboxed on OpenBSD either. pledge("proc exec") doesn't give you a sandbox.
- brynet 8y agoHi, that is not true. The "dns" promise only allows sockets with the SOCK_DNS option, the kernel restricts access to only DNS type operations and port numbers (enough for libc to do DNS). The kernel tries to separate pledges as tightly as possible, with many checks: SOCK_DNS For domains AF_INET or AF_INET6, only allow connect(2), sendto(2), or sendmsg(2) to the DNS port (typically 53). https://man.openbsd.org/socket https://man.openbsd.org/socket
- markjdb 8y agoOk, so that's tighter than what I said, but my point still stands.