Landlock: Unprivileged Access Control
docs.kernel.org
docs.kernel.org
That said, does GCC accept every non-printing character as whitespace? If not, they could probably have achieved the same thing with a narrow-nonbreaking-space character or similar.
~/t [main L|…1]$ gcc test.c
~/t [main L|…1]$ vi test.c
~/t [main L| 1…1]$ git diff
diff --git a/test.c b/test.c
index 33c14ce..dc93007 100644
--- a/test.c
+++ b/test.c
@@ -1,3 +1,3 @@
int main() {
- return 0;
+ return 0;
}
~/t [main L| 1…1]$ gcc test.c
test.c:2:5: error: expected expression
<U+0008>return 0;
^
1 error generated.
So, yes, this could have been made to look exactly like a meaningless whitespace change.* Seccomp intercepts syscalls, and paths are passed to syscalls as pointers. So your code that has to decide "is this syscall allowed?" doesn't get the path, it gets a pointer to a path in another process's address space. That means you have to then pretty much debug that process to find the string. However IIRC there are potential races between when you read the string and when the kernel does.
* Symlinks mean you can't just do a lexical check on the path. Hell you can't even lexically normalise it (remove all `../foo`) because symlinks are crazy. For something like creating files/directories IIRC you have to walk up the path starting from root and read every directory from disk. Like open `/foo`, ok? now open `/foo/bar`, now `/foo/bar/baz`...
Total nightmare. Landlock is much saner for filesystem sandboxing.