Skip to content

Harden chroot named Unix socket targets and exec freeze enumeration - #273

Draft
jamesboyzj-design wants to merge 2 commits into
multikernel:mainfrom
jamesboyzj-design:review/unix-gate-freeze-20261003
Draft

jamesboyzj-design wants to merge 2 commits into
multikernel:mainfrom
jamesboyzj-design:review/unix-gate-freeze-20261003

Conversation

@jamesboyzj-design

Copy link
Copy Markdown
Contributor

Named AF_UNIX operations in the virtual chroot could authorize a lexical pathname and then return Continue, allowing the kernel to resolve a different target. This draft preserves raw Unix pathname bytes, distinguishes malformed addresses from pathless addresses, resolves targets through the virtual mount/COW view, and executes named connect/send operations against a pinned inode. The sendmmsg chroot path uses copied headers and destinations.

A separate commit makes exec freeze enumeration fail closed on errors other than a disappeared task directory, cleans up already frozen tasks, and corrects documentation that overstated argv TOCTOU protection.

Related: #143 and #27. This is a staged implementation for author review, not a request to close either issue.

Validation

Base: 1e697ce90f2e345a130f2626e23a209f40c97eac; tested final tree is unchanged by the two commits.

  • Linux aarch64, Rust 1.96, kernel 7.0.14-orbstack-00380-ga7e0a2dc9535; local Docker, uid/gid 65534, Docker seccomp unconfined (not privileged).
  • Full sandlock-core unit suite: 890 passed, 0 failed. Matching unmodified baseline: 880 passed, 0 failed.
  • Existing connected Unix sendmsg and SCM_RIGHTS integration cases: 2 passed, 0 failed (521 other integration cases filtered out).
  • Added coverage includes raw-byte names, malformed/oversized sockaddr boundaries, mount selection, virtual symlink resolution, mmsghdr snapshot parsing, and connecting through a retained inode after the socket pathname is replaced.
  • git diff --check passed.
  • Initial root/default-Docker-seccomp runs had three baseline-matched permission/pidfd failures; both suites passed under the configuration above.

Build with cargo test --locked -p sandlock-core --lib --no-run and cargo test --locked -p sandlock-core --test integration --no-run, then run the generated binaries as an unprivileged user. Integration filter: test_network::test_connected_unix_sendmsg --test-threads=1.

Remaining work before merge

  • Complete the Chroot named-AF_UNIX gate bypass: lexical check + Continue (symlink/TOCTOU) and non-UTF-8 None-collapse (fail-open) #143 four-syscall acceptance matrix across chroot/non-chroot, grants/denials, relative paths, COW, mount aliases, fd/msgvec mutation and partial batches.
  • Resolve the pathless/abstract Continue mutable-memory boundary and rename-across-policy-boundary semantics. Inode-retention coverage alone does not establish those guarantees.
  • For Sandbox escape by racing seccomp notifications? #27, establish a valid post-Continue exec argument-consumption boundary and cover external MAP_SHARED writers, CLONE_VM/vfork and failure/cleanup cases. The enumeration fix does not close those broader races.
  • COW non-UTF-8 paths and abstract entries in supervisor-executed named-socket batches currently fail closed; compatibility needs further review.
  • Checkpoint restore was not validated; restore-stub is unavailable on this aarch64 build. Full integration suite and upstream CI are not claimed as passed.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant