Page MenuHomeFreeBSD

vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors
ClosedPublic

Authored by markj on Mon, Sep 21, 1:36 PM.
Tags
None
Referenced Files
F174049061: D59875.diff
Wed, Sep 30, 5:23 AM
F173989906: D59875.diff
Tue, Sep 29, 7:44 PM
F173930656: D59875.diff
Tue, Sep 29, 11:00 AM
F173918582: D59875.id187329.diff
Tue, Sep 29, 8:42 AM
F173910100: D59875.id187329.diff
Tue, Sep 29, 7:11 AM
Unknown Object (File)
Tue, Sep 29, 12:27 AM
Unknown Object (File)
Tue, Sep 29, 12:13 AM
Unknown Object (File)
Mon, Sep 28, 3:06 PM
Subscribers

Details

Summary

The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR
262179 without entirely disallowing fd passing between jails. However,
one can use renameat() to bypass the restriction: upon receiving a
directory fd with FD_RESOLVE_BENEATH set, a jailed process can still
move its CWD or one of its ancestors to the directory, and just cd
out of its jail root.

So disallow renameat() when either the source or destination directory
fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot()
to prevent similar escapes. I don't really see a better alternative
other than simply disallowing fd-sharing across a jail boundary.

Reported by: firk@cantconnect.ru

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77157
Build 74040: arc lint + arc unit

Event Timeline

markj requested review of this revision.Mon, Sep 21, 1:36 PM
This revision is now accepted and ready to land.Mon, Sep 21, 6:10 PM

fcnt.2 should list renameat(2) in FD_RENAME_BENEATH description

This revision now requires review to proceed.Tue, Sep 22, 1:22 PM
This revision is now accepted and ready to land.Tue, Sep 22, 2:39 PM