Linux 3.8 Released
kernelnewbies.org
kernelnewbies.org
But after spending a lot of time with it recently (e.g. getting LXC running last night), I've concluded that it would be very hard to design a system with a security API that is worse than Linux.
The issue is that Linus doesn't design ANYTHING. He doesn't believe in design; he only believes in evolution.
Unix was designed, whereas Linux is mostly a bunch of code bolted on top of Unix. It's not sustainable in the long term. Someone needs to actually design something eventually, so there is a stable base for more evolution.
Spend some time looking through these:
- traditional Unix ACL-based security
- traditional resource limits
- chroot (not secure, but used as a "part" of many security solutions)
- capabilities
- seccomp
- LSM-based
- SELinux
- AppArmor
- ...
- LXC
- cgroups
- namespaces (apparently completed with this kernel release)
- LXC user space tools
- ptrace sandboxing
- (at least a dozen projects use this)
- user mode linux
And you'll realize it's just a huge mess. I'm sure the complexity makes Linux measurably more insecure in practice. Or it just provides employment for a lot of people -- who knows.There's never going to be a way to clean this all up, since people are relying on all of it.
I don't have that much experience with the alternatives; I'm sure they're messy in their own right. (I've used many OSes, but not security-wise.) But this definitely has me looking towards FreeBSD and such. Too bad it is more expensive on EC2.
I mentioned Minix 3 here before -- it's probably a pipe dream, but being a microkernel, it seems like a good basis for a future secure Unix. It actually was designed in some sense.
From what I gather people take the existence of root escalation exploits on Linux for granted. If that weren't so (and it shouldn't be with a microkernel), then traditional Unix security might actually cover a lot of cases that all these hacks on top are patching up.
EDIT: Also, Linux should look to DJB for guidance. Out of all the hairiniess, how do you even do this on Linux (or any Unix)? http://cr.yp.to/unix/disablenetwork.html It just seems crazy.
[1] http://smartos.org/2011/12/15/fork-yeah-the-rise-and-develop...
What sort of disappointed me about LXC is that you end up with an init process and 7 or 8 children of it in each container. I am more interested in sandboxing at the level of a single process. In a lot of cases you just want to run somebody else's Python code and look at its stdout; you don't need to spin up init and family do that.
There are a hundred and one projects like this but most of them seem half-baked.
Capsicum [1] looks like what I'm interested in; there seemed to be effort around a Linux port a couple years ago but I don't think it happened. Does Illumos/SmartOS provide anything like this?
But yeah I think I just need the underlying cgroups, and possibly some of the namespaces. Although I don't car aell that much if untrusted code can see what processes are running; just as long as it can't affect them.
Just curious what you were using containers for from Lua? Sounds interesting.
https://lwn.net/Articles/538221/ (ctrl-f spender)
There's QNX for that: http://www.qnx.com/products/neutrino-rtos/secure-kernel.html It's used in industries such as automotive, nuclear, etc.
Perhaps you meant "future secure open-source Unix" ;) (QNX source was closed the day RIM announced the purchase)
Read about the currently decades old POSIX TTY subsystem to see how bad it is: http://www.linusakesson.net/programming/tty/
ioctls and fcntl? Quick hacks to make things work. Fcntl lock files? Insane semantics that were quickly hacked on. Etc etc.
A miracle is something you are grateful for. This is something we should all be proud of.
That said the scheduler does pretty well, it beats manually binding without a lot of experimentation.
http://www.phoronix.com/scan.php?page=article&item=linux...
I'd generally say you shouldn't use a just-merged filesystem on anything really critical, though.
To others, where would I report such an issue if it's still broken?