OpenBSD pledge() for Linux
Summary
Justine Tunney implements OpenBSD's pledge concept on Linux with seccomp-BPF and other kernel mechanisms. OpenBSD originally introduced pledge as a security feature of its own. The Linux implementation mainly uses seccomp-BPF.
Ideas
- Applications declare permitted groups of capabilities with understandable promises.
- Later pledge calls can reduce rights further but never extend them again.
- Linux syscalls are hidden behind portable promise categories.
- Seccomp-BPF enforces the resulting system call restrictions in the kernel.
- Self-restriction reduces the consequences of program bugs that are exploited later.
Insights
- Security APIs are used more often when their rules match application concepts.
- Coarse, understandable boundaries can be more valuable than perfect, unmaintainable policies.
- Portability requires stable semantics above different kernel mechanisms.
Facts
- Promise groups describe capabilities such as file access, networking or starting processes.
Recommendations
- Call pledge after initialisation and reduce rights again afterwards.
- Test all error paths, updates and optional features under the policy.
References
Links to the original source and the Web Archive open in a new tab.