Re: [and paxctl] RT linker, rpath and security

[email protected]
Newsgroups gmane.os.netbsd.devel.toolchain
Message-ID <[email protected]>
Le Thu, May 11, 2023 at 10:37:17AM +0200, Martin Husemann a écrit :
> On Thu, May 11, 2023 at 10:22:08AM +0200, [email protected] wrote:
> > Would you mind specifying what "admin decisions" you are referring to?
> 
> Installing a binary with an untrusted RPATH

Are the rpath of the dynamically shared ELF executables installed by 
pkgsrc verified? Is it the responsability of "root" to verify them?

> or making some directories writable that should not be.

I can add a /home/Someone directory in the rpath that is only writable
by Someone. If I have access to Someone's account, I do whatever
I want.

What you are saying is that ALL directories should be read-only. And
this must include mounted mfs ones.

BTW paxctl(1) is modifying the behavior, for security/safety, of an
ELF program.

Is this one not a candidate for something settable by paxctl?
-- 
        Thierry Laronde <tlaronde +AT+ polynum +dot+ com>
                     http://www.kergis.com/
                    http://kertex.kergis.com/
Key fingerprint = 0FF7 E906 FBAF FE95 FD89  250D 52B1 AE95 6006 F40C
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.