4 ms·
I'm not sure it's even accurate to say that Wayland closes one of the holes when the hole Wayland closes isn't part of the system's security boundaries. It's li
by skymt 6y ago
I'm not sure it's even accurate to say that Wayland closes one of the holes when the hole Wayland closes isn't part of the system's security boundaries. It's like installing a deadbolt in a door standing in the middle of a room.
- Spivak 6y agoThe "user is the only security boundary" ship sailed long ago with, chroot, SELinux, AppArmor, Snap, Flatpak, namespacing. It will continue to be a bumpy ride retrofitting an ecosystem not made for the tighter boundaries but it's still the goal.
- Blikkentrekker 6y agoMany of those work by running processes under what is effectively a subuser. The problem with it is, that it works fine when one purely speak of being able to write and read from files, but the moment servers such as display servers or Pulsaudio and DBus come into play, the picture becomes more difficult. All of those technologies work on a simple binary level where the subuser has access to the socket, or it does not, for finer grained control the kernel is required to speak the protocol, which will obviously not happen. So, those services themselves must come with a means to filter communication appropriately, and sandboxing technology is beholden to the extent thereof. Flatpak had to provide an alternative DBus-proxy server to do this with DBus, similar to using nested X11 servers; no solution has been reached for Pulseaudio, whereof I know, and no plans even exist for a variety of more obscure servers that software might need to communicate. For instance, ZNC can be instructed from the IRC client to load modules that contain arbitrary code. Therefore, any IRC client that has acces to ZNC has ZNC's full capabilities, as it does not come with such finer granulation as of this moment. If any sandboxing technology is to be effective, a large number of servers that are in common use often need to provide specific support for that specific sandboxing technology, or simply not be accessible at all from within it.
- cycloptic 6y agoD-Bus is a special case because the protocol is not particularly complicated and the proxy can be used by any sandbox to implement various types of filtering on any other service that uses D-Bus. That's one of those things where if your application uses D-Bus to communicate with a service, you might just end up getting sandboxing support there "for free." Pulseaudio is not getting much work these days, I believe the work currently is happening in Pipewire, which was built to have a fine-grained permission system that can work with any sandbox and is backwards-compatible with Pulseaudio. I'm not sure how your IRC bouncer would work there, but presumably if you sandboxed that, it only needs to talk to the IRC socket and nothing else. For other obscure servers that have no concept of security, I'm not sure what can be done about that if nobody wants to modify them or replace them. You might just have to accept that they will need to run at elevated privileges and can clobber your system or home directory.
- Spivak 6y agoOr they run in their own sandbox and so at worst an app can only clobber the ZNC server’s sandbox.