[PATCH v2 3/4] sample/Landlock: Support signal scoping restriction
From: Tahera Fahimi <hidden>
Date: 2024-08-06 18:11:21
Also in:
linux-security-module, lkml
Subsystem:
landlock security module, the rest · Maintainers:
Mickaël Salaün, Linus Torvalds
A sandboxer can receive the character "s" as input from the environment variable LL_SCOPE to restrict itself from sending a signal to a process outside its scoped domain. Example ======= Create a sandboxed shell and pass the character "s" to LL_SCOPED: LL_FS_RO=/ LL_FS_RW=. LL_SCOPED="s" ./sandboxer /bin/bash Try to send a SIGTRAP to a process with process ID <PID> through: kill -SIGTRAP <PID> The sandboxed process should not be able to send the signal. Signed-off-by: Tahera Fahimi <redacted> --- samples/landlock/sandboxer.c | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-)
diff --git a/samples/landlock/sandboxer.c b/samples/landlock/sandboxer.c
index 98132fd823ad..c3123f3ee8eb 100644
--- a/samples/landlock/sandboxer.c
+++ b/samples/landlock/sandboxer.c@@ -193,7 +193,8 @@ static bool check_ruleset_scope(const char *const env_var, bool ret = true; char *env_type_scope, *env_type_scope_next, *ipc_scoping_name; - ruleset_attr->scoped &= ~LANDLOCK_SCOPED_ABSTRACT_UNIX_SOCKET; + ruleset_attr->scoped &= ~(LANDLOCK_SCOPED_ABSTRACT_UNIX_SOCKET | + LANDLOCK_SCOPED_SIGNAL); env_type_scope = getenv(env_var); /* scoping is not supported by the user */ if (!env_type_scope)
@@ -207,6 +208,8 @@ static bool check_ruleset_scope(const char *const env_var, if (strcmp("a", ipc_scoping_name) == 0) { ruleset_attr->scoped |= LANDLOCK_SCOPED_ABSTRACT_UNIX_SOCKET; + } else if (strcmp("s", ipc_scoping_name) == 0) { + ruleset_attr->scoped |= LANDLOCK_SCOPED_SIGNAL; } else { fprintf(stderr, "Unsupported scoping \"%s\"\n", ipc_scoping_name);
@@ -258,7 +261,8 @@ int main(const int argc, char *const argv[], char *const *const envp) .handled_access_fs = access_fs_rw, .handled_access_net = LANDLOCK_ACCESS_NET_BIND_TCP | LANDLOCK_ACCESS_NET_CONNECT_TCP, - .scoped = LANDLOCK_SCOPED_ABSTRACT_UNIX_SOCKET, + .scoped = LANDLOCK_SCOPED_ABSTRACT_UNIX_SOCKET | + LANDLOCK_SCOPED_SIGNAL, }; if (argc < 2) {
@@ -295,7 +299,7 @@ int main(const int argc, char *const argv[], char *const *const envp) "%s=\"/dev/null:/dev/full:/dev/zero:/dev/pts:/tmp\" " "%s=\"9418\" " "%s=\"80:443\" " - "%s=\"a\" " + "%s=\"a:s\" " "%s bash -i\n\n", ENV_FS_RO_NAME, ENV_FS_RW_NAME, ENV_TCP_BIND_NAME, ENV_TCP_CONNECT_NAME, ENV_SCOPED_NAME, argv[0]);
@@ -369,7 +373,8 @@ int main(const int argc, char *const argv[], char *const *const envp) __attribute__((fallthrough)); case 5: /* Removes LANDLOCK_SCOPED_ABSTRACT_UNIX_SOCKET for ABI < 6 */ - ruleset_attr.scoped &= ~LANDLOCK_SCOPED_ABSTRACT_UNIX_SOCKET; + ruleset_attr.scoped &= ~(LANDLOCK_SCOPED_ABSTRACT_UNIX_SOCKET | + LANDLOCK_SCOPED_SIGNAL); fprintf(stderr, "Hint: You should update the running kernel " "to leverage Landlock features "
--
2.34.1