From nobody Fri Aug 7 01:48:09 2026 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hGRqt3JH3z6nf8s for ; Fri, 07 Aug 2026 01:48:10 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hGRqt0F19z3pM9 for ; Fri, 07 Aug 2026 01:48:10 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1786067290; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=qMLDRwrcnedORK0ZjOiGrmfK9wPZDptUU7+HyWPyUEY=; b=mBi/EHBJG82giby7shCw3SUs4gtL0PE6eCmcX/tlBzuycU4abzR0+yIcG8UQ+gxCT4umxJ wxfMa2YXxSf1r1lPuFI1yOjRcDwkYHHuJabR9h53sCFw9IuIMlyvhiMzo2mVi1Rthqg1BF 6s2Mos6r7Ax+wkVeF2EeFAoNW3VzvYmQ0kd976h4FVYn2MBjr8+dxI9RxxOLxHlczPeKb8 aH/nNUSqCH0WbPvG2udOvNZTkCMwVHlrSN3axYrPcLBwCzFTKUqbAl9ED34XtOCAjfGUcj Ai2WOqT3sWSXc+rkdUSjartkScOIbYy9oYBNKBh8fP9qEkv2CraJdymWlfTXbQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1786067290; a=rsa-sha256; cv=none; b=byLt315q0uY9libDHKXFgwDk8jCdTA4leUZVLaZJl61umuLI3Bn8HkRYhWV2uANx9lWYnN mcVF+bmB5aBm1hll56/qxd8NvONRx6AHG1h5bcYeQpBozmtQ6L/PVjBSTj0/VPFckTQGt+ 0h4cbIaWf2cLV2DOOSL5XgIdksrBxA8qIgcEtvjvGBzuFyDuDzWSdPbH2ZbyFubo7ee2+Y Ik06OE6p9VrXHU7MvkboVjR6ZgzmZRgrGhgvzN6hE5VOV913pV3b80qmDsOu4NnGd91vyS aSshLloZCMUQKc3XjPu/Vs03fVyE8OTnOvRCloUsa419EmKitCumYnllq5JZxw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1786067290; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=qMLDRwrcnedORK0ZjOiGrmfK9wPZDptUU7+HyWPyUEY=; b=i/6wY0nbwC8VWYIFx7Gdm6XRu17Owqw6WCmBWS7GcC/BzyuTum7jNXoySwDm1EK91jPR1B nreuoCZqWQJFLxxY+ZUZtHKcOThD+TIlTNaocEVpfnshbz6LoWOhthKU0oFLFxmdD6Hv+0 0K/Ao4sMKAUhKF8Nlv6dWA37q6H0kOqOMZnd3LTJdxKeG6mYgl3jSBZRFJHpc4sITbvZtd KATV3xPY/0VePrx99fvmSKarlsyYPLS6+lrlTV5tchRTvMKqBn5fQXEK2Thre2owh6mqZD DJAMZmvN96VZQYZNmbdgdRqSRBlvVILLQaU8h64HEy+60ZQbOaXSlLnbtleJLg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hGRqs5msXzmnn for ; Fri, 07 Aug 2026 01:48:09 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3c120 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Fri, 07 Aug 2026 01:48:09 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Kyle Evans Subject: git: da9d26a215a6 - stable/15 - kern: add a security knob to disable unprivileged access to kenv List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kevans X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: da9d26a215a644e9e8a31f3c47309f6cce350380 Auto-Submitted: auto-generated Date: Fri, 07 Aug 2026 01:48:09 +0000 Message-Id: <6a753959.3c120.529b504a@gitrepo.freebsd.org> The branch stable/15 has been updated by kevans: URL: https://cgit.FreeBSD.org/src/commit/?id=da9d26a215a644e9e8a31f3c47309f6cce350380 commit da9d26a215a644e9e8a31f3c47309f6cce350380 Author: Kyle Evans AuthorDate: 2026-06-22 20:22:25 +0000 Commit: Kyle Evans CommitDate: 2026-08-06 23:35:30 +0000 kern: add a security knob to disable unprivileged access to kenv We sometimes store sensitive things in the kenv that get zapped, but we really shouldn't rely on that zapping to actually happen. Most unprivileged processes don't really need to read from the kernel environment in the first place, so add a knob that allows it to be disabled. Note that we consider jailed root to be unprivileged from this perspective; they have their own meta/env concepts and we should encourage users to take advantage of those for passing information to jails. Relnotes: yes (The capability to disable unpriv access exists) "Hey we should do something about that": dch Reviewed by: imp, ziaee, zlei (all slightly previous version) (cherry picked from commit 4fd518fcb2bbee4c8c41215d6993b923ef57a0e5) --- bin/kenv/kenv.1 | 10 +++++++++- lib/libsys/kenv.2 | 7 ++++++- share/man/man7/security.7 | 4 +++- sys/kern/kern_environment.c | 46 +++++++++++++++++++++++++++++++++++++++------ sys/sys/priv.h | 1 + 5 files changed, 59 insertions(+), 9 deletions(-) diff --git a/bin/kenv/kenv.1 b/bin/kenv/kenv.1 index 9b6d0e0b33f2..c0cf0c29cabe 100644 --- a/bin/kenv/kenv.1 +++ b/bin/kenv/kenv.1 @@ -22,7 +22,7 @@ .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF .\" SUCH DAMAGE. .\" -.Dd June 20, 2021 +.Dd June 22, 2026 .Dt KENV 1 .Os .Sh NAME @@ -166,3 +166,11 @@ The .Nm utility appeared in .Fx 4.1.1 . +.Sh SECURITY CONSIDERATIONS +Note that unprivileged users are allowed to read from the kernel environment, +unless the +.Va security.bsd.unprivileged_kenv_read +sysctl is set to 0. +This includes both listing the kernel environment, as well as getting a specific +.Va variable +from the environment. diff --git a/lib/libsys/kenv.2 b/lib/libsys/kenv.2 index 9f179ff2faa6..bdf4dd7f1386 100644 --- a/lib/libsys/kenv.2 +++ b/lib/libsys/kenv.2 @@ -24,7 +24,7 @@ .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH .\" DAMAGE. .\" -.Dd June 20, 2021 +.Dd June 22, 2026 .Dt KENV 2 .Os .Sh NAME @@ -161,6 +161,11 @@ The kernel is configured to destroy these environments by default. .It Bq Er EPERM A user other than the superuser attempted to set or unset a kernel environment variable. +.It Bq Er EPERM +A user other than the superuser attempted to get a variable from or dump the +kernel environment, and the +.Va security.bsd.unprivileged_kenv_read +sysctl is set to 0. .It Bq Er EFAULT A bad address was encountered while attempting to copy in user arguments or copy out value(s). diff --git a/share/man/man7/security.7 b/share/man/man7/security.7 index 395cf082c2fc..bec5c4f0b001 100644 --- a/share/man/man7/security.7 +++ b/share/man/man7/security.7 @@ -26,7 +26,7 @@ .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF .\" SUCH DAMAGE. .\" -.Dd March 22, 2026 +.Dd June 22, 2026 .Dt SECURITY 7 .Os .Sh NAME @@ -987,6 +987,8 @@ and usual termination signals like and .Dv SIGTERM , to the processes executing programs with changed uids. +.It Va security.bsd.unprivileged_kenv_read +Controls availability of kernel environment variables to non-root users. .It Va security.bsd.unprivileged_proc_debug Controls availability of the process debugging facilities to non-root users. See also diff --git a/sys/kern/kern_environment.c b/sys/kern/kern_environment.c index 7c0654769581..72c7544b4bac 100644 --- a/sys/kern/kern_environment.c +++ b/sys/kern/kern_environment.c @@ -49,6 +49,7 @@ #include #include #include +#include #include #include @@ -91,6 +92,11 @@ bool dynamic_kenv; #define KENV_CHECK if (!dynamic_kenv) \ panic("%s: called before SI_SUB_KMEM", __func__) +static int unprivileged_kenv_read = 1; +SYSCTL_INT(_security_bsd, OID_AUTO, unprivileged_kenv_read, CTLFLAG_RW, + &unprivileged_kenv_read, 1, + "Unprivileged processes can read the kernel environment"); + static int kenv_dump(struct thread *td, char **envp, int what, char *value, int len) { @@ -155,6 +161,33 @@ kenv_dump(struct thread *td, char **envp, int what, char *value, int len) return (error); } +static int +kenv_read_allowed(struct thread *td, int which) +{ + int error; + + if (!unprivileged_kenv_read) { + error = priv_check(td, PRIV_KENV_READ); + if (error) + return (error); + } + + switch (which) { + case KENV_DUMP: + case KENV_DUMP_LOADER: + case KENV_DUMP_STATIC: +#ifdef MAC + error = mac_kenv_check_dump(td->td_ucred); +#endif + break; + default: + error = 0; + break; + } + + return (error); +} + int sys_kenv(struct thread *td, struct kenv_args *uap) { @@ -168,19 +201,15 @@ sys_kenv(struct thread *td, struct kenv_args *uap) switch (uap->what) { case KENV_DUMP: -#ifdef MAC - error = mac_kenv_check_dump(td->td_ucred); + error = kenv_read_allowed(td, uap->what); if (error) return (error); -#endif return (kenv_dump(td, kenvp, uap->what, uap->value, uap->len)); case KENV_DUMP_LOADER: case KENV_DUMP_STATIC: -#ifdef MAC - error = mac_kenv_check_dump(td->td_ucred); + error = kenv_read_allowed(td, uap->what); if (error) return (error); -#endif #ifdef PRESERVE_EARLY_KENV return (kenv_dump(td, uap->what == KENV_DUMP_LOADER ? (char **)md_envp : @@ -199,6 +228,11 @@ sys_kenv(struct thread *td, struct kenv_args *uap) if (error) return (error); break; + case KENV_GET: + error = kenv_read_allowed(td, uap->what); + if (error) + return (error); + break; } name = malloc(KENV_MNAMELEN + 1, M_TEMP, M_WAITOK); diff --git a/sys/sys/priv.h b/sys/sys/priv.h index 1ad6a4882ffc..8df113adfd4c 100644 --- a/sys/sys/priv.h +++ b/sys/sys/priv.h @@ -141,6 +141,7 @@ */ #define PRIV_KENV_SET 120 /* Set kernel env. variables. */ #define PRIV_KENV_UNSET 121 /* Unset kernel env. variables. */ +#define PRIV_KENV_READ 122 /* Get/dump kernel env. variables. */ /* * Loadable kernel module privileges.