5 ms·
Local unprivileged shell is not an unreasonable thing to get on linux since most people are building random software regularly. Among the things i know i should
by lapinot 3y ago
Local unprivileged shell is not an unreasonable thing to get on linux since most people are building random software regularly. Among the things i know i should be doing but i don't: using a dedicated user for building everything; sandboxing the build process using some bwrap/container.
- insanitybit 3y agoPrivesc is also trivial on desktop linux :P so if your barrier is "but I'm an unprivileged user" it's likely not enough. You need a proper sandbox if you want to make escalation difficult. ex: Desktop Linux's running X have a trivial escalation path; any program can read all keystrokes across all users. You type your sudo password in, you're screwed. Or if the attacker is running as your user they can just modify your bashrc, aliases, etc, to do a whole bunch of things - like having `sudo` go to an attacker controlled binary - that one will work on the server, too! So yeah sandboxing builds is super important because "unprivileged users" are almost always one trivial step away from full root.
- tedunangst 3y agoThere's no reason for your build user to require access to X.
- bravetraveler 3y agoOr even most (all) namespaces of the host! Beyond just minding privileges of the user, building in a container/chroot/etc is nice from a cleanliness/repeatability perspective. For those interested in the Fedora packaging ecosystem -- look into fedpkg and mock https://docs.fedoraproject.org/en-US/package-maintainers/Package_Maintenance_Guide/ https://docs.fedoraproject.org/en-US/package-maintainers/Pac...