Redbean Systems
redbean.systems
redbean.systems
"It's a SECCOMP + Landlock LSM implementation of OpenBSD pledge() and unveil(). Fully unprivileged sandboxing. No root or containers required."
1. pledge is a system call that a process can make that limits what subsequent system calls that process can execute, e.g. "I pledge to only call X, Y, Z": https://unix.stackexchange.com/questions/410056/what-is-open...
2. unveil is the analogous call to restrict filesystem paths: it limits which paths open is allowed to access: https://why-openbsd.rocks/fact/unveil/
In general the pledge syscall filters are very permissive, which makes it hard to be sure of security; Chromium libsandbox is insanely restrictive in contrast, because that's really what's needed to be confident in your attack surface, especially if you start worrying about kernel privilege escalation exploits like Chrome does. I wasn't aware of the landlock LSM before this, though, which seems pretty neat and a lot less intrusive than selinux for application specific white/blacklisting.
As for surface area, I expected people to rake me over the coals for blocking io_uring. I didn't anticipate support for Google's zeal. OpenBSD is actually even more permissive than me when it comes to letting stuff through pledge("stdio"). https://github.com/openbsd/src/blob/fb5793d3d4d0fd4795586dd9... Also surface area isn't a weakness, it's a paradigm. If a weakness actually exists, then you must exploit it. So long as you tell us what you did, for the post-mortem.
I haven't followed cosmopolitan / Linux pledge() too closely; but I notice your SERVER_PLEDGE and CLIENT_PLEDGE include stdio, so I expect you have write(2) (and could thus handle a pipe, and maybe even a passed-in AF_UNIX socket?)
Or is making the challenge more interesting - by actually including some networking - part of the fun?
[0]: https://news.ycombinator.com/item?id=34647121
[2]: Even for the languages that support WASM, you usually have to deal with incompatible dependencies, properly configuring your compiler, etc.
I would say game knows game but here barely game groks stratospheric game. I am again in awe.
An example of whitelisting would be a capability based OS like Fuchsia or a custom non-HTML markup like Markdown that you then allow to use specific safe features like formatting (yeah I know about HTML in Markdown).
That said, this approach is probably the best you can do in Linux by a long way. I can definitely see use cases - e.g. all those services that have to use ffmpeg to transcode videos should definitely use something like this.
- unveil(), based on the Landlock LSM, is a function which whitelists files.
- pledge(), based on SECCOMP BPF, is a function which whitelists system calls.
What are the effects of limiting a process priority?
#!/bin/sh
exec ionice -c3 nice "$@"
Since it uses SCHED_IDLE i/o priority too. It's intended to ensure that no matter how much you bog down the system with i/o and cpu usage, my Emacs session and login shells will remain interactive and in control.502 Bad Gateway
edit: I tried anyway but the "API" just 502s, and the only thing I've been able to get it to return is the HTML with the source you see from the browser (but then later, just 502s), so I'm not sure if somebody already beat me/borked it or if there is a bug or what.
If I had to guess what happened, someone borked the HTTP server handler processes in a way that's unrecoverable
You'll also enjoy the glory of being able to say you successfully hacked one of jart's services.