Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1411792

Re: [PATCH] seccomp: plug syscall-dodging ptrace hole

Path csiph.com!xmission!news.glorb.com!diesel.cu.mi.it!bofh.it!news.nic.it!robomod
From Kees Cook <keescook@chromium.org>
Newsgroups linux.kernel
Subject Re: [PATCH] seccomp: plug syscall-dodging ptrace hole
Date Thu, 02 Jun 2016 05:10:01 +0200
Message-ID <rFrbb-uw-1@gated-at.bofh.it> (permalink)
References <rDaHw-2Xq-5@gated-at.bofh.it> <rDfxv-5W2-5@gated-at.bofh.it> <rDg0x-65I-3@gated-at.bofh.it> <rDhSF-7hl-5@gated-at.bofh.it> <rDuZA-71l-13@gated-at.bofh.it> <rDw5k-7Db-33@gated-at.bofh.it> <rDwoG-7YU-9@gated-at.bofh.it>
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=AalIpsFmA4Ec7K+/rqPILwApD5hmSXZAWx6lQeuGEaU=; b=KlP6qaOH8i7yg6JoVsxx1MvMPeQNIdRKg6L1pUPdNb+3noGkVxHHL+InFXIxgGHPXV 6R8e59kb/FBXqiDMMgrGYeEqOFWozy0YRIFIsXWFtC6mHMT+fVc1Jqz0MBaCwnLGxKEM 1iZhOEMSlqk+XRao6gq2PvLZLo2+2brwtrss9aG0Meu/VOzddUNygv14OvrlN/kfs0Lc QX7pMQU9+qu+oa66Wlom4w8mPe02ueZya3PUb4ULsBp7BkRSwsH75pJg+UmXKrUkSUYG trmIRiZXJ1H8KyragIkQbGf/8poAUjYheAczbJbru+bOwfBkCjw6MEUX7ws6wgVZePqX Vy0Q==
Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:cc; bh=AalIpsFmA4Ec7K+/rqPILwApD5hmSXZAWx6lQeuGEaU=; b=PAyPnu35q8JcKYfFm7e6NUsofvTDhrekYAKu8l3ZtWls96d2ZGA2e9DwbPw8O9D38C GY/tBzPhRX5JeLTRKbJ/oKWl/I8elO36TcpQOxCNoMXCKZcp0jco9r83l1qr6XgV+4/d bBucdPuDUWarG9vJfwlEizHKFHruaFGi7x8wE=
X-Google-Dkim-Signature v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:sender:in-reply-to:references:from :date:message-id:subject:to:cc; bh=AalIpsFmA4Ec7K+/rqPILwApD5hmSXZAWx6lQeuGEaU=; b=jm5Z4z0ZTOS/G/GpIzjOJ+TigUPQZGu3ojdToo75MfrwKkJ3bHGXcsMd3OqVqDjWhc ngZU5XHIoqWTS2LgW1Jg15cV9cVmOt2GnRRI1kQEofaLQtSflfpNMum4WK8qVcfqIhN6 d8rUGZmGaLmtPsyheOkxUqF7Xm6AfYqbf5KmXa8fDE9cappTsY/9jZrF+SvIz/9sxYsu 41tKtT5d06DuZDKvu5275jioOSi+/8gNkt5WsyCc7Pf4CjDxy6bqvqDmjd9YJ4SGnc3Z zJznc+oEV1ATjTYU8YIPIDicLppNA6jvwXTbf4hN8lM3biGe6tqC0ijfwiZf84RCJO/R LDIw==
X-Gm-Message-State ALyK8tJJusf2yGfY9DaSaTqvobDzF17m1r8tfIVxgFZb1Dg4vwvvE8+jkQHo1YZKGlb+E3XubzXCKtRtY8VKSDc8
X-Received by 10.194.10.69 with SMTP id g5mr6167619wjb.7.1464836642039; Wed, 01 Jun 2016 20:04:02 -0700 (PDT)
MIME-Version 1.0
X-Google-Sender-Auth pZCfb4evE-q7QBu_bSbdSQGmrnw
Content-Type text/plain; charset=UTF-8
Sender robomod@news.nic.it
List-ID <linux-kernel.vger.kernel.org>
X-Mailing-List linux-kernel@vger.kernel.org
Approved robomod@news.nic.it
Lines 33
Organization linux.* mail to news gateway
X-Original-Cc Stephane Graber <stgraber@ubuntu.com>, "linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>, Jann Horn <jann@thejh.net>, Will Drewry <wad@chromium.org>
X-Original-Date Wed, 1 Jun 2016 20:04:00 -0700
X-Original-Message-ID <CAGXu5jL5NVw-1hwHWir856rxj9o8Qu4k68VUkACC-3kOdOLakQ@mail.gmail.com>
X-Original-References <20160526210450.GA31203@www.outflux.net> <CALCETrXQ75kPc0jWdWGK8xjKcywPGL8x-fN2tzmhQSUBB9wcAA@mail.gmail.com> <CAGXu5j+0cMj7ig8u2DCbh9FJiAxZ+-q6nkiZuC7pwxeFGeS7vg@mail.gmail.com> <CALCETrVhPgaFDHooGNsqGs=M_myTTJA8NmH8M_ytt8ORRck-PA@mail.gmail.com> <CAGXu5j+xq2eT3kXjAL14P5HQg3t_VhbOKnM--ZD3ZMANbjUsrg@mail.gmail.com> <CALCETrWhP0Z8oH2oWBYcnpEW3hzEniFV26o4G4AnxLLUjByeaA@mail.gmail.com> <CALCETrXMyb3m-szQjrXk2mWthHmGpKCbqJia3s7yk6GwFUULsA@mail.gmail.com>
X-Original-Sender linux-kernel-owner@vger.kernel.org
Xref csiph.com linux.kernel:1411792

Show key headers only | View raw


On Fri, May 27, 2016 at 1:14 PM, Andy Lutomirski <luto@amacapital.net> wrote:
> On Fri, May 27, 2016 at 12:52 PM, Andy Lutomirski <luto@amacapital.net> wrote:
>>> Right, I know, it's aesthetically much nicer that way, but I really
>>> want to stay totally paranoid and keep seccomp absolutely first on the
>>> path.
>>>
>>> How about this: we'll use this patch as-is for now, since I'd like to
>>> be able to start getting feedback from the container-using folks ASAP,
>>> and then we can redesign the 2-phase system going forward from there.
>>>
>>
>> I think I'd rather change the ABI as few times as possible.  On the
>> other hand, it's still early, and I see nothing wrong with adding it
>> to -next.
>
> To get the ball rolling:
>
> https://git.kernel.org/cgit/linux/kernel/git/luto/linux.git/log/?h=seccomp
>
> It's incomplete, but it should be straightforward to finish it.  The
> only interesting bit is dealing with SECCOMP_RET_TRACE.

I did a bit more from there (though it needs further cleanup, I see my
"const" fixes landed in the wrong patch), this passes my tests on x86,
the other architectures need reordering and testing:

http://git.kernel.org/cgit/linux/kernel/git/kees/linux.git/log/?h=seccomp/reorder-ptrace

-Kees

-- 
Kees Cook
Chrome OS & Brillo Security

Back to linux.kernel | Previous | Next | Find similar | Unroll thread


Thread

Re: [PATCH] seccomp: plug syscall-dodging ptrace hole Kees Cook <keescook@chromium.org> - 2016-06-02 05:10 +0200

csiph-web