aboutsummaryrefslogtreecommitdiff
path: root/src/lib/sandbox
diff options
context:
space:
mode:
authorNick Mathewson <nickm@torproject.org>2021-05-07 13:08:25 -0400
committerNick Mathewson <nickm@torproject.org>2021-05-07 13:08:25 -0400
commit4e62c171144c1b4a1cb1447d86a177655f90c0b6 (patch)
tree2b4d84cf6815d2641cdf94914fd7fd9e4104b971 /src/lib/sandbox
parenta4c8591c351358e18897f038efbea27cfd295ce6 (diff)
parente4f2b52debc727fc35806adc889227d8aaf975a8 (diff)
downloadtor-4e62c171144c1b4a1cb1447d86a177655f90c0b6.tar.gz
tor-4e62c171144c1b4a1cb1447d86a177655f90c0b6.zip
Merge branch 'maint-0.4.6'
Diffstat (limited to 'src/lib/sandbox')
-rw-r--r--src/lib/sandbox/sandbox.c22
1 files changed, 22 insertions, 0 deletions
diff --git a/src/lib/sandbox/sandbox.c b/src/lib/sandbox/sandbox.c
index 6ee90b8ff2..02222e5a1c 100644
--- a/src/lib/sandbox/sandbox.c
+++ b/src/lib/sandbox/sandbox.c
@@ -1608,6 +1608,28 @@ add_noparam_filter(scmp_filter_ctx ctx)
}
}
+ if (is_libc_at_least(2, 33)) {
+#ifdef __NR_newfstatat
+ // Libc 2.33 uses this syscall to implement both fstat() and stat().
+ //
+ // The trouble is that to implement fstat(fd, &st), it calls:
+ // newfstatat(fs, "", &st, AT_EMPTY_PATH)
+ // We can't detect this usage in particular, because "" is a pointer
+ // we don't control. And we can't just look for AT_EMPTY_PATH, since
+ // AT_EMPTY_PATH only has effect when the path string is empty.
+ //
+ // So our only solution seems to be allowing all fstatat calls, which
+ // means that an attacker can stat() anything on the filesystem. That's
+ // not a great solution, but I can't find a better one.
+ rc = seccomp_rule_add_0(ctx, SCMP_ACT_ALLOW, SCMP_SYS(newfstatat));
+ if (rc != 0) {
+ log_err(LD_BUG,"(Sandbox) failed to add newfstatat() syscall; "
+ "received libseccomp error %d", rc);
+ return rc;
+ }
+#endif
+ }
+
return 0;
}