Harden chroot named Unix socket targets and exec freeze enumeration - #273
Draft
jamesboyzj-design wants to merge 2 commits into
Draft
jamesboyzj-design wants to merge 2 commits into
jamesboyzj-design wants to merge 2 commits into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Named AF_UNIX operations in the virtual chroot could authorize a lexical pathname and then return
Continue, allowing the kernel to resolve a different target. This draft preserves raw Unix pathname bytes, distinguishes malformed addresses from pathless addresses, resolves targets through the virtual mount/COW view, and executes named connect/send operations against a pinned inode. The sendmmsg chroot path uses copied headers and destinations.A separate commit makes exec freeze enumeration fail closed on errors other than a disappeared task directory, cleans up already frozen tasks, and corrects documentation that overstated argv TOCTOU protection.
Related: #143 and #27. This is a staged implementation for author review, not a request to close either issue.
Validation
Base:
1e697ce90f2e345a130f2626e23a209f40c97eac; tested final tree is unchanged by the two commits.7.0.14-orbstack-00380-ga7e0a2dc9535; local Docker, uid/gid 65534, Docker seccomp unconfined (not privileged).git diff --checkpassed.Build with
cargo test --locked -p sandlock-core --lib --no-runandcargo test --locked -p sandlock-core --test integration --no-run, then run the generated binaries as an unprivileged user. Integration filter:test_network::test_connected_unix_sendmsg --test-threads=1.Remaining work before merge
Continuemutable-memory boundary and rename-across-policy-boundary semantics. Inode-retention coverage alone does not establish those guarantees.