From owner-freebsd-security@freebsd.org Tue Sep 26 22:42:12 2017 Return-Path: Delivered-To: freebsd-security@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 92B1FE244A1 for ; Tue, 26 Sep 2017 22:42:12 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: from mail-ua0-x231.google.com (mail-ua0-x231.google.com [IPv6:2607:f8b0:400c:c08::231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4105A7E120 for ; Tue, 26 Sep 2017 22:42:12 +0000 (UTC) (envelope-from shawn.webb@hardenedbsd.org) Received: by mail-ua0-x231.google.com with SMTP id q29so7412532uaf.3 for ; Tue, 26 Sep 2017 15:42:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hardenedbsd-org.20150623.gappssmtp.com; s=20150623; h=date:from:to:subject:message-id:references:mime-version :content-disposition:in-reply-to:user-agent; bh=AYaLmVFw8eXxu2EkkwWj7pCa35P+YCgZqS7c/hdTakA=; b=GZhRgY8Lrg5Ze+1Tuujw+18kYHUqA8j3yCL6hmvkCm3GndJLGEfnWDzDt8kS86uXGV ZvjxnvCRwA5D+C56v/rl5sbUJ6EC2zGXl8OqTMhBX/0EbrjeZ3ibqVbs6NAwGpjF752C Uo56KKyBxZKwKtNg0TqEiPWdCPS7YBqoT0HRGd6THTp7QEtksJbFFGdyyZQRhPalwGCX G3eDbDoMxqTMKpHI5byaFXnVQ6M0T7bAL9tLMNAWfmmbkNHhLCADEz2v9ehZE1qtb6lJ 0DydWFLzkKBHXEV9I4n5c9Gs7MOh41DzRfnGLyTAS9D/PrYd0EueoSZArNhodvSBHb7S BR2g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:from:to:subject:message-id:references :mime-version:content-disposition:in-reply-to:user-agent; bh=AYaLmVFw8eXxu2EkkwWj7pCa35P+YCgZqS7c/hdTakA=; b=uhVoecGS1VlLTK0/Z76ManvaNypbFtX9tr8cs4gBKnmlaf/U46sWiH57Dmv1jT3SKA JKyL5S2ZFu4HpSOMPRnZdbquACS0Nlm6pT55rIpXipMS9q0wSKP+lqzG2ap1bEOZizuo jf1Sts4cN6N/VL/UuhnYsHv9PX20dxnghwo5p8fxz/57/Queu5dftBh/RVMSMy/8ykcW pon3pHvxXQq8vQMWVi/hslOQrtIjwf9nkpreXXVmL5NFp6ZQSmME1HYOEx71vpRGO9TS z21LrcHQvPNTrmROSpIaxDTggnQj4dORngATwrbZsU8MqjA0T39ACBWSxh7nhDbpBl2b 14Ug== X-Gm-Message-State: AHPjjUh5W9QpmmPqqJvgUokQg0dA4btnAgkNMWkbakB+79ffRNebYY4p ywL+mAOJZhoxhKAO16SW/4BDR3rZil9nLsAdmCvCSXepx1FXepu4tLrpbSVOkliY491uzeBxMES Y+oeaiFEDgNLwF4PdaqDdjnYc6NnTpkCAfMuexmNDfDoKxeMGtN5Yy9heKUxfUUKanw/HZQexA/ NMTRLxzCKj X-Google-Smtp-Source: AOwi7QB6gOqDG+V6yAEwdnYH3vxIK0wpsN+mW9tX0fGiyqh5VOnegVfpyIwJK9NG72jUwwBiMYUTPQ== X-Received: by 10.176.78.221 with SMTP id x29mr11304070uah.134.1506465730383; Tue, 26 Sep 2017 15:42:10 -0700 (PDT) Received: from mutt-hbsd (exit1.ipredator.se. [197.231.221.211]) by smtp.gmail.com with ESMTPSA id n186sm2266078vkc.53.2017.09.26.15.42.07 for (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Tue, 26 Sep 2017 15:42:09 -0700 (PDT) Date: Tue, 26 Sep 2017 18:42:01 -0400 From: Shawn Webb To: freebsd-security@freebsd.org Subject: Re: Capsicum and connect(2) Message-ID: <20170926224201.tp6pndwkvcuishcr@mutt-hbsd> References: <20170926193753.eolxa6lk5qvejtgc@mutt-hbsd> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="waykogcjrf24npyj" Content-Disposition: inline In-Reply-To: <20170926193753.eolxa6lk5qvejtgc@mutt-hbsd> X-Operating-System: FreeBSD mutt-hbsd 12.0-CURRENT FreeBSD 12.0-CURRENT X-PGP-Key: http://pgp.mit.edu/pks/lookup?op=vindex&search=0x6A84658F52456EEE User-Agent: NeoMutt/20170912 (1.9.0) X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 26 Sep 2017 22:42:12 -0000 --waykogcjrf24npyj Content-Type: multipart/mixed; boundary="qo7b23ct5fr7e35b" Content-Disposition: inline --qo7b23ct5fr7e35b Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Tue, Sep 26, 2017 at 07:37:53PM +0000, Shawn Webb wrote: > Hey All, >=20 > I'm working on applying Capsicum to Tor. I've got a PoC design for how > I'm going to do it posted here: >=20 > https://github.com/lattera/PoCs/tree/master/capsicum_fdpassing >=20 > Note that the above code might have ugly spots. It's mostly just a brain > dump. >=20 > Essentially, the child process creates the socket and passes the > socket's file descriptor back to the parent. The socket file descriptor > has the capabilities sets already applied to it before it goes back to > the parent. The socket creation and file descriptor passing seems to > work well. >=20 > However, what isn't working is calling connect(2) on the socket file > descriptor in the parent. errno gets set to ECAPMODE. This is puzzling > to me since CAP_CONNECT is set on the descriptor. >=20 > Any help would be appreciated. It turns out that connect(2) isn't annotated with SYF_CAPENABLED, even though the CAP_CONNECT capability exists. I've fixed it in HardenedBSD: https://github.com/HardenedBSD/hardenedBSD/commit/1b1b6b8f1ec1fbbefc5de82f0= b15bb470beda370 I've also filed a bug report: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D222632 Thanks, --=20 Shawn Webb Cofounder and Security Engineer HardenedBSD GPG Key ID: 0x6A84658F52456EEE GPG Key Fingerprint: 2ABA B6BD EF6A F486 BE89 3D9E 6A84 658F 5245 6EEE --qo7b23ct5fr7e35b Content-Type: text/x-diff; charset=us-ascii Content-Disposition: attachment; filename="capsicum_connect_r01.patch" diff --git a/sys/kern/init_sysent.c b/sys/kern/init_sysent.c index 125587d5057..3e216996c94 100644 --- a/sys/kern/init_sysent.c +++ b/sys/kern/init_sysent.c @@ -149,7 +149,7 @@ struct sysent sysent[] = { { AS(fsync_args), (sy_call_t *)sys_fsync, AUE_FSYNC, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC }, /* 95 = fsync */ { AS(setpriority_args), (sy_call_t *)sys_setpriority, AUE_SETPRIORITY, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC }, /* 96 = setpriority */ { AS(socket_args), (sy_call_t *)sys_socket, AUE_SOCKET, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC }, /* 97 = socket */ - { AS(connect_args), (sy_call_t *)sys_connect, AUE_CONNECT, NULL, 0, 0, 0, SY_THR_STATIC }, /* 98 = connect */ + { AS(connect_args), (sy_call_t *)sys_connect, AUE_CONNECT, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC }, /* 98 = connect */ { compat(AS(accept_args),accept), AUE_ACCEPT, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC }, /* 99 = old accept */ { AS(getpriority_args), (sy_call_t *)sys_getpriority, AUE_GETPRIORITY, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC }, /* 100 = getpriority */ { compat(AS(osend_args),send), AUE_SEND, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC }, /* 101 = old send */ --qo7b23ct5fr7e35b-- --waykogcjrf24npyj Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEKrq2ve9q9Ia+iT2eaoRlj1JFbu4FAlnK17YACgkQaoRlj1JF bu68lRAAqilzz3/s3wwtZEd6dG8hDb8nUpRcbxNveXOXaT63rznI4/c6BE51xsnh DEY3heWX4CUQSLEpWiijPgRw0e8tFUZ8QPukkzXqp1W5zuRK0S7P4O3Ol4nKulY0 Kl/3KJibHTaSjHWlkblLljlU7nTH0+jMFmilMftBmTOVeNIcqvNUTw4eHhRlnJYw bes0Ds9cjALE3/Ht4eyx8bzDjAkvZ97EJ8G2QF5FzNE38yyUYubJ4OeOkHZyavyq ZNW3ULe0bzHeVDVIqBrK6GQJxq1lXr4SzggMmHWZ9OEjoGYHXKdeUoszRdwb8xmI UXE5HtX5VRuRZsEyMxhafR6bo4ZAJ1ITDj9gRSJKshMCxR8Epl4go4pGJuwCLtPE XcW39RSR+o3i1xiPPt1hcx9KTlHIV9x0ycfniNi0lrdPluVdt6mDDgm5NEnrZ5/q FvUU4wEx/xbGMthONe+GVY9wvXW7UejQ1NHrNzGb5pyqoqZYRO6RXndI7Y2B+8GT c6ZbaiZ7GXdJEGm8PVkESFnakrnJ8SPZ9SrPJpZSUetPi+2URa32cnzTYz/5h9f1 UzqiEcKqvc7nz3gCMQtiE/LxBTaiyyiX9x7/6lTA7FWOUWJcYETSZu9JDCGDjOFp czW24LfpNzID5LJ6doFeAB9ALiD/a7HeoMrJIyaq41aGZ557q7A= =KkY0 -----END PGP SIGNATURE----- --waykogcjrf24npyj--