4 ms·
I still want dynamic linking, but only a few trusted library files would be allowed to make system calls. Like libc. Sorry but golang would have to change to us
by timtzm 2y ago
I still want dynamic linking, but only a few trusted library files would be allowed to make system calls. Like libc. Sorry but golang would have to change to use libc.
This breaks the ABI, but it breaks it for naughty programs the most.
- jiveturkey 2y agoI'm not sure how it's relevant exactly to TFA. The mechanism of propagation is an existing feature of libdl that uses an environment variable. With this worm, the loader still runs exactly as before, from libc and libdl. As to restricting syscalls from certain calling libraries, macOS has this via entitlements, and I believe OpenBSD and/or NetBSD has this in some form as well.
- saagarjha 2y agoEntitlements cannot protect against things in your own process. They are always used to gate clients either across a kernel-user or XPC boundary.
- jiveturkey 2y agoisn't that exactly what the parent was asking for? limiting syscalls. EDIT: oh. but not limited to the caller from a specific system library.
- saagarjha 2y agoOpenBSD does this; it’s not very useful unless you have strong CFI to prevent people from doing a return-oriented attack into those libraries that are in your address space. And also note that there is a lot that you can without system calls to mess with stuff :)
- jdsalaro 2y ago> CFI They're referring to Control Flow Integrity [1] [1] https://en.m.wikipedia.org/wiki/Control-flow_integrity https://en.m.wikipedia.org/wiki/Control-flow_integrity
- rfoo 2y ago> but only a few trusted library files would be allowed to make system calls. Like libc This is impossible (without having to do libc.so.7) on Linux, as: $ nm -D /lib/x86_64-linux-gnu/libc.so.6 | grep syscall 000000000011b520 T syscall https://elixir.bootlin.com/glibc/glibc-2.39/source/sysdeps/unix/sysv/linux/syscall.c#L23 https://elixir.bootlin.com/glibc/glibc-2.39/source/sysdeps/u...