bk99.de entertain the web since 1997

OpenBSD pledge() for Linux

Summary

Justine Tunney implements OpenBSD's pledge concept on Linux with seccomp-BPF and other kernel mechanisms. OpenBSD originally introduced pledge as a security feature of its own. The Linux implementation mainly uses seccomp-BPF.

Ideas

  • Applications declare permitted groups of capabilities with understandable promises.
  • Later pledge calls can reduce rights further but never extend them again.
  • Linux syscalls are hidden behind portable promise categories.
  • Seccomp-BPF enforces the resulting system call restrictions in the kernel.
  • Self-restriction reduces the consequences of program bugs that are exploited later.

Insights

  • Security APIs are used more often when their rules match application concepts.
  • Coarse, understandable boundaries can be more valuable than perfect, unmaintainable policies.
  • Portability requires stable semantics above different kernel mechanisms.

Facts

  • Promise groups describe capabilities such as file access, networking or starting processes.

Recommendations

  • Call pledge after initialisation and reduce rights again afterwards.
  • Test all error paths, updates and optional features under the policy.

References

Read the original article

Search the Web Archive