Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 26 Sep 2017 18:42:01 -0400
From:      Shawn Webb <shawn.webb@hardenedbsd.org>
To:        freebsd-security@freebsd.org
Subject:   Re: Capsicum and connect(2)
Message-ID:  <20170926224201.tp6pndwkvcuishcr@mutt-hbsd>
In-Reply-To: <20170926193753.eolxa6lk5qvejtgc@mutt-hbsd>
References:  <20170926193753.eolxa6lk5qvejtgc@mutt-hbsd>

next in thread | previous in thread | raw e-mail | index | archive | help

--waykogcjrf24npyj
Content-Type: multipart/mixed; boundary="qo7b23ct5fr7e35b"
Content-Disposition: inline


--qo7b23ct5fr7e35b
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Tue, Sep 26, 2017 at 07:37:53PM +0000, Shawn Webb wrote:
> Hey All,
>=20
> I'm working on applying Capsicum to Tor. I've got a PoC design for how
> I'm going to do it posted here:
>=20
> https://github.com/lattera/PoCs/tree/master/capsicum_fdpassing
>=20
> Note that the above code might have ugly spots. It's mostly just a brain
> dump.
>=20
> Essentially, the child process creates the socket and passes the
> socket's file descriptor back to the parent. The socket file descriptor
> has the capabilities sets already applied to it before it goes back to
> the parent. The socket creation and file descriptor passing seems to
> work well.
>=20
> However, what isn't working is calling connect(2) on the socket file
> descriptor in the parent. errno gets set to ECAPMODE. This is puzzling
> to me since CAP_CONNECT is set on the descriptor.
>=20
> Any help would be appreciated.

It turns out that connect(2) isn't annotated with SYF_CAPENABLED, even
though the CAP_CONNECT capability exists.

I've fixed it in HardenedBSD:
https://github.com/HardenedBSD/hardenedBSD/commit/1b1b6b8f1ec1fbbefc5de82f0=
b15bb470beda370

I've also filed a bug report:
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D222632

Thanks,

--=20
Shawn Webb
Cofounder and Security Engineer
HardenedBSD

GPG Key ID:          0x6A84658F52456EEE
GPG Key Fingerprint: 2ABA B6BD EF6A F486 BE89  3D9E 6A84 658F 5245 6EEE

--qo7b23ct5fr7e35b
Content-Type: text/x-diff; charset=us-ascii
Content-Disposition: attachment; filename="capsicum_connect_r01.patch"

diff --git a/sys/kern/init_sysent.c b/sys/kern/init_sysent.c
index 125587d5057..3e216996c94 100644
--- a/sys/kern/init_sysent.c
+++ b/sys/kern/init_sysent.c
@@ -149,7 +149,7 @@ struct sysent sysent[] = {
 	{ AS(fsync_args), (sy_call_t *)sys_fsync, AUE_FSYNC, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC },	/* 95 = fsync */
 	{ AS(setpriority_args), (sy_call_t *)sys_setpriority, AUE_SETPRIORITY, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC },	/* 96 = setpriority */
 	{ AS(socket_args), (sy_call_t *)sys_socket, AUE_SOCKET, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC },	/* 97 = socket */
-	{ AS(connect_args), (sy_call_t *)sys_connect, AUE_CONNECT, NULL, 0, 0, 0, SY_THR_STATIC },	/* 98 = connect */
+	{ AS(connect_args), (sy_call_t *)sys_connect, AUE_CONNECT, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC },	/* 98 = connect */
 	{ compat(AS(accept_args),accept), AUE_ACCEPT, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC },	/* 99 = old accept */
 	{ AS(getpriority_args), (sy_call_t *)sys_getpriority, AUE_GETPRIORITY, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC },	/* 100 = getpriority */
 	{ compat(AS(osend_args),send), AUE_SEND, NULL, 0, 0, SYF_CAPENABLED, SY_THR_STATIC },	/* 101 = old send */

--qo7b23ct5fr7e35b--

--waykogcjrf24npyj
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEKrq2ve9q9Ia+iT2eaoRlj1JFbu4FAlnK17YACgkQaoRlj1JF
bu68lRAAqilzz3/s3wwtZEd6dG8hDb8nUpRcbxNveXOXaT63rznI4/c6BE51xsnh
DEY3heWX4CUQSLEpWiijPgRw0e8tFUZ8QPukkzXqp1W5zuRK0S7P4O3Ol4nKulY0
Kl/3KJibHTaSjHWlkblLljlU7nTH0+jMFmilMftBmTOVeNIcqvNUTw4eHhRlnJYw
bes0Ds9cjALE3/Ht4eyx8bzDjAkvZ97EJ8G2QF5FzNE38yyUYubJ4OeOkHZyavyq
ZNW3ULe0bzHeVDVIqBrK6GQJxq1lXr4SzggMmHWZ9OEjoGYHXKdeUoszRdwb8xmI
UXE5HtX5VRuRZsEyMxhafR6bo4ZAJ1ITDj9gRSJKshMCxR8Epl4go4pGJuwCLtPE
XcW39RSR+o3i1xiPPt1hcx9KTlHIV9x0ycfniNi0lrdPluVdt6mDDgm5NEnrZ5/q
FvUU4wEx/xbGMthONe+GVY9wvXW7UejQ1NHrNzGb5pyqoqZYRO6RXndI7Y2B+8GT
c6ZbaiZ7GXdJEGm8PVkESFnakrnJ8SPZ9SrPJpZSUetPi+2URa32cnzTYz/5h9f1
UzqiEcKqvc7nz3gCMQtiE/LxBTaiyyiX9x7/6lTA7FWOUWJcYETSZu9JDCGDjOFp
czW24LfpNzID5LJ6doFeAB9ALiD/a7HeoMrJIyaq41aGZ557q7A=
=KkY0
-----END PGP SIGNATURE-----

--waykogcjrf24npyj--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20170926224201.tp6pndwkvcuishcr>