Repository navigation
seccomp: authorize prepared network operations before executing them - #283
Open
congwang-mk wants to merge 1 commit into
Open
congwang-mk wants to merge 1 commit into
congwang-mk wants to merge 1 commit into
Conversation
The supervisor called policy_fn after dispatch had already connected or sent on the child's socket. Returning EPERM could leave a usable connection behind or report a denial after a datagram reached its peer. Have connect and send handlers return owned, prepared operations with captured destination metadata. The supervisor asks the callback before executing them and drops the operation on denial. Without a callback it executes immediately. Keep deferred completion separate so a blocking send can defer without producing a nested deferral that becomes EIO. Prepare sendmmsg entries before sending and bound their combined payload to 64 MiB. This can shorten a large batch even without a callback. Add regressions for denied connects and sends reaching their peers, and for an approved partial send completing through the deferred path. All 901 unit tests and 526 integration tests passed, with reduced concurrency for the full integration run. Signed-off-by: Cong Wang <cwang@multikernel.io>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The supervisor previously called
policy_fnafter network dispatch had already connected or sent on the child's socket. A denied connect could return EPERM while leaving a usable connection, and a denied send could still reach its peer.Have connect and send handlers return prepared operations containing owned arguments and destination metadata. The supervisor authorizes them before execution and drops them on denial. Deferred completion remains separate, so an approved blocking send can defer without nesting deferrals.
This covers IP and Unix connects, single sends, and send batches. Without a callback, prepared operations execute immediately. Preparing
sendmmsgbatches introduces a 64 MiB aggregate payload cap, which can shorten large batches even without a callback.Validation: 901 unit tests and 526 integration tests passed. The full integration suite passed with reduced concurrency after earlier failures. Regressions check that denied connects and sends do not reach peers and that an approved partial send completes through the deferred path.