sandbox: fail loudly when seccomp_unotify is requested but unusable#285
Open
h1-mrz wants to merge 1 commit into
Open
sandbox: fail loudly when seccomp_unotify is requested but unusable#285h1-mrz wants to merge 1 commit into
h1-mrz wants to merge 1 commit into
Conversation
applyPolicy() installed the seccomp-unotify listener only when pipefd != -1. In modes that pass pipefd == -1 (e.g. MODE_STANDALONE_EXECVE) the install was silently skipped, and prepareAndCommit() then returned early because the classic seccomp filter is empty -- so a sandboxee for which seccomp_unotify was explicitly requested ran with NO seccomp policy at all, with no error emitted. Refuse to continue instead of silently dropping the requested policy: if seccomp_unotify is set but there is no supervisor to receive the notification fd (pipefd == -1), log an error and fail. Verified: `nsjail -Me --seccomp_unotify --seccomp_string 'DEFAULT ALLOW' -- ...` now aborts with a clear error instead of launching the process unfiltered.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
applyPolicy() installed the seccomp-unotify listener only when pipefd != -1. In modes that pass pipefd == -1 (e.g. MODE_STANDALONE_EXECVE) the install was silently skipped, and prepareAndCommit() then returned early because the classic seccomp filter is empty -- so a sandboxee for which seccomp_unotify was explicitly requested ran with NO seccomp policy at all, with no error emitted.
Refuse to continue instead of silently dropping the requested policy: if seccomp_unotify is set but there is no supervisor to receive the notification fd (pipefd == -1), log an error and fail.
Verified:
nsjail -Me --seccomp_unotify --seccomp_string 'DEFAULT ALLOW' -- ...now aborts with a clear error instead of launching the process unfiltered.