27 ms·
File descriptor passing has been a common technique used in privilege separated design, used quite extensively in OpenBSD software. Other notable examples inclu
by notaplumber 6y ago
File descriptor passing has been a common technique used in privilege separated design, used quite extensively in OpenBSD software. Other notable examples include Google's Chrome browser. It's quite telling how it's not mentioned once in this article.
Combined with OS security features like pledge(2) on OpenBSD, which has separate sendfd/recvfd promises, and unveil(2), an unprivileged process can have its access to the filesytem and other system attack surfaces (system calls, ioctls) removed completely or restricted and only be able to act on file descriptors passed by a privileged parent.
https://man.openbsd.org/pledge.2 https://man.openbsd.org/pledge.2
https://man.openbsd.org/unveil.2 https://man.openbsd.org/unveil.2
A skeleton example of a common style for OpenBSD privsep daemons, which uses 3 processes
https://github.com/krwesterback/newdctl https://github.com/krwesterback/newdctl
https://github.com/krwesterback/newd https://github.com/krwesterback/newd
This uses OpenBSD's imsg(3) API, an abstraction around the underlying Unix sendmsg/SCM_RIGHTS functionality, along with other IPC abstractions.
https://man.openbsd.org/imsg_init.3 https://man.openbsd.org/imsg_init.3
https://github.com/tmux/tmux/blob/master/compat/imsg.c https://github.com/tmux/tmux/blob/master/compat/imsg.c
https://github.com/tmux/tmux/blob/master/compat/imsg.h https://github.com/tmux/tmux/blob/master/compat/imsg.h