From owner-svn-src-all@freebsd.org Thu Jun 28 07:42:31 2018 Return-Path: Delivered-To: svn-src-all@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 84AE41022A1C for ; Thu, 28 Jun 2018 07:42:31 +0000 (UTC) (envelope-from wlosh@bsdimp.com) Received: from mail-io0-x232.google.com (mail-io0-x232.google.com [IPv6:2607:f8b0:4001:c06::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 0B6468F3C3 for ; Thu, 28 Jun 2018 07:42:31 +0000 (UTC) (envelope-from wlosh@bsdimp.com) Received: by mail-io0-x232.google.com with SMTP id d185-v6so4323529ioe.0 for ; Thu, 28 Jun 2018 00:42:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=bsdimp-com.20150623.gappssmtp.com; s=20150623; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=tvbvrvX7MBUSXLMiGqLZGJtZI2aA8QsYx6TBugRx4vw=; b=Dd68UdJVhQZi7HkkKVfnX5CaG+rsX83mmgqMUSXzlWT9Pb2kBFc7X4l7OJVDHZtzNf zyA+ttGGvqJ0zZh2lYHv1C1eX6pif676S8tGu/03DO4n5t2pNNEZwFPo9UmVMFltcs7K U+Sc/YZfP2SLjcVIIu8u/Ag+7KrA+sqHT+wJLaiUv4pzrBOgVGSr81kR+Pbg2MDKAngM /WYBQtwwT79dDER1cLTM6+LAh3Ym1OPdhTVVcXPHeqis+fVIgJoemiK3zIhUSKC/2bbe iPbqOdE/KH8qrubdr1RwloS5L2t1bOs/oW0s4EMgoK+iKxs1FSmnC/xfN4mf6/8CR0Sd WLdQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=tvbvrvX7MBUSXLMiGqLZGJtZI2aA8QsYx6TBugRx4vw=; b=ecQemdnTU7cinABCjDBU43KxO2M5tQ3jqwWyvGTdx+TI4PhMUdkGmA2Pw6lu9afvAu kZPHzh3d+2JJeUJHGvxvYKWzCovsm634Ms0QAepU2gC23lrvlRfZzeAM+nnNWFI0aN9L iifmmZMV0SW6nDDZWf072zO1+i4SWLROvLmV63cz8AQTr/i4hKucvR0TZ60H6ApwW/hl S1VNGp3re+hMD6YxASBgVM4CPzxs39lJqpS7Orn4deUNP5YnRV3+lEQ653bZJrFni1HD aj26GJSXuLkEszpBQleh88sz3V5k/9rhqy8C6gGrAvg24W8az6AmiLFzp2lG4psMglCS byUQ== X-Gm-Message-State: APt69E0IhbrrBqUk2/B34QUWUGaCA91V7kpXbT6dFeXlWnR6t3sv7I4Z jGlHOsqg066zXAvNrbp6HUEKzsh4vKgAANeZ8twhgD3+ X-Google-Smtp-Source: AAOMgpcU1aEv6A6SG9350z3YVTlQVZzO8jWet7oxLu4z4J6BBhDKftaSCipj8iXCn3cAArhxY60f6YyysrhnqqHsVYw= X-Received: by 2002:a6b:29c4:: with SMTP id p187-v6mr7436827iop.299.1530171750197; Thu, 28 Jun 2018 00:42:30 -0700 (PDT) MIME-Version: 1.0 Sender: wlosh@bsdimp.com Received: by 2002:a4f:5945:0:0:0:0:0 with HTTP; Thu, 28 Jun 2018 00:42:29 -0700 (PDT) X-Originating-IP: [2603:300b:6:5100:1052:acc7:f9de:2b6d] In-Reply-To: References: <201806270411.w5R4B9ZB078994@repo.freebsd.org> <20180627134455.k6jvum4pnuejas3x@mutt-hbsd> From: Warner Losh Date: Thu, 28 Jun 2018 01:42:29 -0600 X-Google-Sender-Auth: g7mW4Z70OGXF8w8RPL235-uKKVI Message-ID: Subject: Re: svn commit: r335690 - head/sys/kern To: Shawn Webb Cc: Oliver Pinter , "svn-src-head@freebsd.org" , "svn-src-all@freebsd.org" , "src-committers@freebsd.org" , Warner Losh Content-Type: text/plain; charset="UTF-8" X-Content-Filtered-By: Mailman/MimeDel 2.1.26 X-BeenThere: svn-src-all@freebsd.org X-Mailman-Version: 2.1.26 Precedence: list List-Id: "SVN commit messages for the entire src tree \(except for " user" and " projects" \)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 28 Jun 2018 07:42:31 -0000 On Wed, Jun 27, 2018 at 7:46 AM, Warner Losh wrote: > > > On Wed, Jun 27, 2018 at 7:44 AM, Shawn Webb > wrote: > >> On Wed, Jun 27, 2018 at 07:42:52AM -0600, Warner Losh wrote: >> > On Wed, Jun 27, 2018 at 12:59 AM, Oliver Pinter < >> > oliver.pinter@hardenedbsd.org> wrote: >> > >> > > >> > > >> > > On Wednesday, June 27, 2018, Warner Losh wrote: >> > > >> > >> Author: imp >> > >> Date: Wed Jun 27 04:11:09 2018 >> > >> New Revision: 335690 >> > >> URL: https://svnweb.freebsd.org/changeset/base/335690 >> > >> >> > >> Log: >> > >> Fix devctl generation for core files. >> > >> >> > >> We have a problem with vn_fullpath_global when the file exists. >> Work >> > >> around it by printing the full path if the core file name starts >> with /, >> > >> or current working directory followed by the filename if not. >> > >> >> > >> Sponsored by: Netflix >> > >> Differential Review: https://reviews.freebsd.org/D16026 >> > >> >> > >> Modified: >> > >> head/sys/kern/kern_sig.c >> > >> >> > >> Modified: head/sys/kern/kern_sig.c >> > >> ============================================================ >> > >> ================== >> > >> --- head/sys/kern/kern_sig.c Wed Jun 27 04:10:48 2018 >> (r335689) >> > >> +++ head/sys/kern/kern_sig.c Wed Jun 27 04:11:09 2018 >> (r335690) >> > >> @@ -3431,24 +3431,6 @@ out: >> > >> return (0); >> > >> } >> > >> >> > >> -static int >> > >> -coredump_sanitise_path(const char *path) >> > >> -{ >> > >> - size_t i; >> > >> - >> > >> - /* >> > >> - * Only send a subset of ASCII to devd(8) because it >> > >> - * might pass these strings to sh -c. >> > >> - */ >> > >> - for (i = 0; path[i]; i++) >> > >> - if (!(isalpha(path[i]) || isdigit(path[i])) && >> > >> - path[i] != '/' && path[i] != '.' && >> > >> - path[i] != '-') >> > >> - return (0); >> > > >> > > >> > > This part of code existed to prevent shell code injection via file >> names. >> > > After this commit we lose this. >> > > >> > >> > It's devd's job to prevent that, not the kernel's. >> >> Has devd been updated? Or is this particular vulnerability manifest >> again? >> > > devd is fine as far as I know, apart from the default action. I'm fixing > that now. > As of r335756 the quoting issue that this code was for was fixed. I thought I'd jumped through these hoops years ago, but I can't find the tree I did it in, and it's clear I never committed it. Warner