3 ms·
EDIT: Article seems to have been updated to remove mention of Chromium. This article contains a lot of errors, for example Chromium on FreeBSD does NOT use Cap
by brynet 7mo ago
EDIT: Article seems to have been updated to remove mention of Chromium.
This article contains a lot of errors, for example Chromium on FreeBSD does NOT use Capsicum, it never has. That was experimental and invasive work done 17 years ago that was NEVER committed to their official ports repository. In fact, not a single browser on FreeBSD uses Capsicum or any form of sandboxing _at all_.
https://github.com/rwatson/chromium-capsicum https://github.com/rwatson/chromium-capsicum
https://www.freshports.org/www/chromium/ https://www.freshports.org/www/chromium/
https://cgit.freebsd.org/ports/log/www/chromium/Makefile?qt=grep&q=capsicum https://cgit.freebsd.org/ports/log/www/chromium/Makefile?qt=...
Contrast that with OpenBSD, where the Chromium port has used pledge(2) since January 2016, and unveil(2) since 2018. Both are enabled by default. Mozilla Firefox ports also use both pledge and unveil since 2018-2019, with refinements over the years.
https://marc.info/?l=openbsd-ports-cvs&m=145211683609002&w=2 https://marc.info/?l=openbsd-ports-cvs&m=145211683609002&w=2
https://marc.info/?l=openbsd-ports-cvs&m=153250162128188&w=2 https://marc.info/?l=openbsd-ports-cvs&m=153250162128188&w=2
OpenBSD's fork of tcpdump has been privsep for ~22 years, and its packet parser runs with no privileges. It's pledged tightly "stdio" and has no network/filesystem access, and uses OpenBSD specific innovations like bpf descriptor locking (BIOCLOCK) missing from both FreeBSD/Linux tcpdump today (despite FreeBSD adding the ioctl in 2005).
In the years since it was added, the reason Capsicum has only been applied to a handful of utilities is because it's a tree barren of decades worth of incremental work on privilege separation and security research.
- limagnolia 7mo agoI would like to see a comparison of capsicum and pledge/unveil. Is capsicum much more difficult to use? Is it inherently less secure?
- brynet 7mo agoIt's very difficult to reason about, for instance compare the OpenSSH sshd sandbox implementations. https://github.com/openssh/openssh-portable/blob/master/sshd-auth.c#L209 https://github.com/openssh/openssh-portable/blob/master/sshd... https://github.com/openssh/openssh-portable/blob/master/sandbox-darwin.c#L64 https://github.com/openssh/openssh-portable/blob/master/sand... https://github.com/openssh/openssh-portable/blob/master/sandbox-seccomp-filter.c https://github.com/openssh/openssh-portable/blob/master/sand... https://github.com/openssh/openssh-portable/blob/master/sandbox-solaris.c https://github.com/openssh/openssh-portable/blob/master/sand... w/ Capsicum, beyond faffing around with some file descriptors, it's unclear what security cap_enter() adds: https://github.com/openssh/openssh-portable/blob/master/sandbox-capsicum.c https://github.com/openssh/openssh-portable/blob/master/sand...
- brynet 7mo ago> EDIT: Article seems to have been updated to remove mention of Chromium. Archive: https://archive.ph/rLmTq https://archive.ph/rLmTq