Re: [and paxctl] RT linker, rpath and security
| Newsgroups | gmane.os.netbsd.devel.toolchain |
|---|---|
| Message-ID | <[email protected]> |
Le Thu, May 11, 2023 at 10:37:17AM +0200, Martin Husemann a écrit : > On Thu, May 11, 2023 at 10:22:08AM +0200, [email protected] wrote: > > Would you mind specifying what "admin decisions" you are referring to? > > Installing a binary with an untrusted RPATH Are the rpath of the dynamically shared ELF executables installed by pkgsrc verified? Is it the responsability of "root" to verify them? > or making some directories writable that should not be. I can add a /home/Someone directory in the rpath that is only writable by Someone. If I have access to Someone's account, I do whatever I want. What you are saying is that ALL directories should be read-only. And this must include mounted mfs ones. BTW paxctl(1) is modifying the behavior, for security/safety, of an ELF program. Is this one not a candidate for something settable by paxctl? -- Thierry Laronde <tlaronde +AT+ polynum +dot+ com> http://www.kergis.com/ http://kertex.kergis.com/ Key fingerprint = 0FF7 E906 FBAF FE95 FD89 250D 52B1 AE95 6006 F40C