| 1 | # ChangeLog for Path Sandbox |
1 | # ChangeLog for Path Sandbox |
| 2 | # Copyright 1999-2004 Gentoo Foundation; Distributed under the GPL v2 |
2 | # Copyright 1999-2005 Gentoo Foundation; Distributed under the GPL v2 |
| 3 | # $Header$ |
3 | # $Header$ |
| 4 | |
4 | |
|
|
5 | 06 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.h, sandbox_futils.c, |
|
|
6 | libsandbox.c: |
|
|
7 | - Change log dir to /var/log/sandbox/. Make sure the sandboxed process cannot |
|
|
8 | write to it. |
|
|
9 | |
|
|
10 | 05 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h, |
|
|
11 | sandbox_futils.c, libsandbox.c: |
|
|
12 | Remove unused 'pids file' code. |
|
|
13 | |
|
|
14 | * sandbox-1.2.10 (2005/07/03) |
|
|
15 | |
|
|
16 | 03 July 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c: |
|
|
17 | Add PREDICT items for nss-db, bug #92079. Patch from Robin Johnson. |
|
|
18 | |
|
|
19 | 17 June 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c: |
|
|
20 | General cleanups: |
|
|
21 | - Remove fooling around with exit codes - we error out on presence of a log |
|
|
22 | anyhow. |
|
|
23 | - Move get_sandbox_*_envvar() to sandbox_setup_environ(), as its more |
|
|
24 | appropriate there. |
|
|
25 | |
|
|
26 | 12 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
27 | Cleanup the fail_nametoolong stuff a bit more. |
|
|
28 | |
|
|
29 | 11 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
30 | Remove hopefully the last ld.so.preload bits we do not use anymore. |
|
|
31 | |
|
|
32 | 11 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
33 | Remove the unneeded canonicalize() calls in the wrappers - we do it anyhow |
|
|
34 | in check_syscall(). Should speed things up a bit (at least for the getcwd() |
|
|
35 | and long path name test it goes down to under a second, and not 10+ seconds |
|
|
36 | like before). Also warn if we skip checking due to the canonicalized path |
|
|
37 | being too long. |
|
|
38 | |
|
|
39 | 11 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
40 | More comment/readability cleanups. |
|
|
41 | |
|
|
42 | 10 June 2005; Martin Schlemmer <azarah@gentoo.org> canonicalize.c, getcwd.c, |
|
|
43 | sandbox_futils.c, libsandbox.c: |
|
|
44 | Some strncpy/strncat and other cleanups. |
|
|
45 | |
|
|
46 | * sandbox-1.2.9 (2005/06/09) |
|
|
47 | |
|
|
48 | 09 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
49 | Move symlink hack down a bit to try and minimize on the amount of lstat() |
|
|
50 | calls we do. |
|
|
51 | |
|
|
52 | 09 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c: |
|
|
53 | Add hack to allow writing to /proc/self/fd (or /dev/fd), bug #91516. |
|
|
54 | |
|
|
55 | 09 June 2005; Martin Schlemmer <azarah@gentoo.org> symbols.in, libsandbox.c: |
|
|
56 | Add wrapper for access() function, bug #85413. |
|
|
57 | |
|
|
58 | 09 June 2005; Martin Schlemmer <azarah@gentoo.org> getcwd.c: |
|
|
59 | Use generic getcwd() implementation from uclibc - should be more portable |
|
|
60 | and looks a bit cleaner. |
|
|
61 | |
|
|
62 | 09 June 2005; Martin Schlemmer <azarah@gentoo.org> getcwd.c, libsandbox.c: |
|
|
63 | Make sure our true_* pointers are initialized to NULL, and that we check for |
|
|
64 | all references that they are valid. |
|
|
65 | |
|
|
66 | 09 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
67 | Be default we will fail if the path name we try to canonicalize is too long. |
|
|
68 | This however could cause issues with some things (bug #94630 and #21766), so |
|
|
69 | if fail_nametoolong == 0, canonicalize() will return a null length string and |
|
|
70 | do not fail. |
|
|
71 | |
|
|
72 | 08 June 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox_futils.c: |
|
|
73 | Do not abort if TMPDIR is not valid, but rather use '/tmp', bug #94360. Also |
|
|
74 | make sure we re-export the new TMPDIR environment variable. |
|
|
75 | |
|
|
76 | 08 June 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
77 | Fix incorrect free of non-malloc'd array, bug #92313 and #94020. Fix noted |
|
|
78 | by Marcus D. Hanwell <cryos@gentoo.org>. |
|
|
79 | |
|
|
80 | 08 June 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c: |
|
|
81 | Add /dev/console to write list, bug #38588. |
|
|
82 | |
|
|
83 | * sandbox-1.2.8 (2005/05/13) |
|
|
84 | |
|
|
85 | 13 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c, |
|
|
86 | sandbox.h, sandbox_futils.c: |
|
|
87 | General cleanups. |
|
|
88 | |
|
|
89 | 13 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c, |
|
|
90 | sandbox.h: |
|
|
91 | Various LD_PRELOAD cleanups. Do not unset LD_PRELOAD for parent. |
|
|
92 | |
|
|
93 | 13 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c, |
|
|
94 | sandbox.h, sandbox_futils.c: |
|
|
95 | Modify get_sandbox_pids_file(), get_sandbox_log() and get_sandbox_debug_log() |
|
|
96 | to use TMPDIR if present in environment. |
|
|
97 | |
|
|
98 | 13 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c: |
|
|
99 | Remove sandbox_log_file from main() as its no longer used. |
|
|
100 | |
|
|
101 | 13 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h, |
|
|
102 | sandbox_futils.c: |
|
|
103 | Add get_sandbox_debug_log(), and use it (add behaviour similar to SANDBOX_LOG |
|
|
104 | if already exported when sandbox started). Fix get_sandbox_log() and new |
|
|
105 | get_sandbox_debug_log() to not use already exported environment variables if |
|
|
106 | they have '/' in them. Use snprintf()'s instead of strncpy()'s. More |
|
|
107 | SB_PATH_MAX fixes. |
|
|
108 | |
|
|
109 | * sandbox-1.2.7 (2005/05/12) |
|
|
110 | |
|
|
111 | 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h, |
|
|
112 | sandbox_futils.c: |
|
|
113 | More path limit fixes. Declare SB_BUF_LEN global and use it where needed. |
|
|
114 | |
|
|
115 | 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox_futils.c: |
|
|
116 | Fix paths limited to 255 chars. Fix get_sandbox_dir() returning a string |
|
|
117 | with '(null)' in it if we did not call sandbox with absolute path. |
|
|
118 | |
|
|
119 | 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c: |
|
|
120 | Set SANDBOX_ON *before* doing the child's env stuff, else its not set |
|
|
121 | for the child. |
|
|
122 | |
|
|
123 | 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c: |
|
|
124 | Remove global preload_adaptable as it is no longer used. |
|
|
125 | |
|
|
126 | 12 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c: |
|
|
127 | Rewrite environment stuff to only be set when execve'ing the child process |
|
|
128 | to try and avoid issues like bug #91541 that causes sandbox to crash if |
|
|
129 | we set LD_PRELOAD sandbox side already. |
|
|
130 | |
|
|
131 | 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c: |
|
|
132 | Move print_sandbox_log() up to make things neater. |
|
|
133 | |
|
|
134 | 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c: |
|
|
135 | Remove load_preload_libs(), as its not used anymore. |
|
|
136 | |
|
|
137 | 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h: |
|
|
138 | Remove NO_FORK stuff, as its not used, and 'strace -f' works just fine. |
|
|
139 | |
|
|
140 | 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h: |
|
|
141 | Remove USE_SYSTEM_SHELL stuff, as it is not secure, and not in use. |
|
|
142 | |
|
|
143 | 11 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h: |
|
|
144 | Remove ld.so.preload crap - we are not going to use it again. |
|
|
145 | |
|
|
146 | 10 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox_futils.c: |
|
|
147 | Fix typo in code that checks if we got valid group information, causing a |
|
|
148 | segmentation fault, bug #91637. |
|
|
149 | |
|
|
150 | * sandbox-1.2.6 (2005/05/10) |
|
|
151 | |
|
|
152 | 10 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c: |
|
|
153 | Do not use LD_PRELOAD if it contains libtsocks.so, as it breaks sandbox |
|
|
154 | for some odd reason, bug #91541. |
|
|
155 | |
|
|
156 | 09 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c: |
|
|
157 | Fix typo (sizeof -> strlen). |
|
|
158 | |
|
|
159 | 08 May 2005; Brian Harring <ferringb@gentoo.org> libsandbox.c: |
|
|
160 | rewrote the sbcontext caching code so it accounts for env changes since lib |
|
|
161 | initialization. |
|
|
162 | |
|
|
163 | 05 May 2005; Martin Schlemmer <azarah@gentoo.org> configure.in, libctest.c: |
|
|
164 | We create libctest.c via configure, so no need to keep it around. Do some |
|
|
165 | cleanup related to libctest.c and libctest during configure. |
|
|
166 | |
|
|
167 | 04 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
168 | Add rename support of symlinks pointing to protected files/directories. |
|
|
169 | |
|
|
170 | * sandbox-1.2.5 (2005/05/04) |
|
|
171 | |
|
|
172 | 04 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c, |
|
|
173 | sandbox.bashrc: |
|
|
174 | Do not reset already set LD_PRELOAD when starting sandbox. If LD_PRELOAD is |
|
|
175 | already set, init of the env vars fails for some reason, so do this later on, |
|
|
176 | and do not warn (bug #91431). |
|
|
177 | |
|
|
178 | 03 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c, sandbox.h, |
|
|
179 | sandbox.bashrc: |
|
|
180 | Fixup sandbox and sandbox.bashrc to call bash with the proper .bashrc. |
|
|
181 | |
|
|
182 | * sandbox-1.2.4 (2005/05/03) |
|
|
183 | |
|
|
184 | 03 May 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
185 | Do not init the env entries with each call, as it creates too many calls to |
|
|
186 | lstat, etc. Should speedup things a bit, bug #91040. |
|
|
187 | |
|
|
188 | 03 May 2005; Martin Schlemmer <azarah@gentoo.org> sandbox.c: |
|
|
189 | Add /dev/pty to default write list. Noticed by Morfic. |
|
|
190 | |
|
|
191 | 02 May 2005; Mike Frysinger <vapier@gentoo.org> configure.in, localdecls.h, |
|
|
192 | sandbox.h: |
|
|
193 | uClibc doesn't support dlvsym() so add a configure check to make sure it doesn't |
|
|
194 | exist. Also update localdecls.h so BROKEN_RTLD_NEXT isn't defined in uClibc. |
|
|
195 | |
|
|
196 | * sandbox-1.2.3 (2005/04/29) |
|
|
197 | |
|
|
198 | 29 Apr 2005; Martin Schlemmer <azarah@gentoo.org> configure.in: |
|
|
199 | Do not check for (*&#$(* CXX or F77. |
|
|
200 | |
|
|
201 | 29 Apr 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
202 | Do not append '/' to pathname in filter_path() if it already ends with it. |
|
|
203 | |
|
|
204 | 28 Apr 2005; Mike Frysinger <vapier@gentoo.org> Makefile.am, configure.in: |
|
|
205 | With az's help, clean up autotools to work with cross-compiling. |
|
|
206 | |
|
|
207 | * sandbox-1.2.2 (2005/04/28) |
|
|
208 | |
|
|
209 | 28 Apr 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
210 | Only check for /dev/{null,zero} for unlink hack, else ricers using /dev/shm |
|
|
211 | have issues; bug #90592. |
|
|
212 | |
|
|
213 | * sandbox-1.2.1 (2005/04/23) |
|
|
214 | |
|
|
215 | 23 Apr 2005; Martin Schlemmer <azarah@gentoo.org> Makefile.am, canonicalize.c, |
|
|
216 | getcwd.c, libsandbox.c, localdecls.h, sandbox.h, sandbox_futils.c: |
|
|
217 | Make sure all functions used in libsandbox.c is declared static. Define |
|
|
218 | SB_STATIC in localdecls.h for this. Include sandbox_futils.c rather than |
|
|
219 | linking with its object. Hopefully this will fix bug #90153. |
|
|
220 | |
|
|
221 | * sandbox-1.2 (2005/04/23) |
|
|
222 | |
|
|
223 | 22 Mar 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
224 | Allow lchown a symlink in write-allowed path pointing to write-denied |
|
|
225 | target. |
|
|
226 | |
|
|
227 | 21 Mar 2005; Marius Mauch <genone@gentoo.org> libsandbox.c: |
|
|
228 | Also show resolved symlink names in the log. |
|
|
229 | |
|
|
230 | 14 Mar 2005; Martin Schlemmer <azarah@gentoo.org> Makefile.am, libsandbox.c: |
|
|
231 | Seems -nostdlib was the problem with the constructor/destructor - remove it |
|
|
232 | from Makefile.am, and change the constructor/destructor names again. |
|
|
233 | |
|
|
234 | 14 Mar 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
235 | Also rename the _init() and _fini() declarations. |
|
|
236 | |
|
|
237 | 14 Mar 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c, sandbox.c: |
|
|
238 | Fixup the constructor/destructor function names again (they should be _init() |
|
|
239 | and _fini() it seems, and not being called caused sandbox_lib_path to be |
|
|
240 | unset, and thus breaking the execve() wrapper's LD_PRELOAD protection). |
|
|
241 | Add both the path in given SANDBOX_x variable, as well as its symlink |
|
|
242 | resolved path in init_env_entries(). Modify filter_path() to be able to |
|
|
243 | resolve paths without resolving symlinks, as well as to be able to resolve |
|
|
244 | symlinks. Fix a possible segfault in check_access(). Add symlink resolving |
|
|
245 | to check_access() resolving bug #31019. Add 'hack' for unlink, as the fix |
|
|
246 | for bug #31019 cause access violations if we try to remove a symlink that is |
|
|
247 | not in protected path, but points to a protected path. Fix a memory leak in |
|
|
248 | sandbox.c (sandbox_pids_file in main()). Fix the realpath() calls in main() |
|
|
249 | (sandbox.c) being unchecked. Fix the debug logname not having the pid in it |
|
|
250 | (pid_string was uninitialized). General syntax cleanups. |
|
|
251 | |
|
|
252 | 09 Mar 2005; Brian Harring <ferringb@gentoo.org> sandbox.c: Fixed the |
|
|
253 | infamous "pids file is not a regular file" w/out newline bug. |
|
|
254 | |
|
|
255 | 09 Mar 2005; Brian Harring <ferringb@gentoo.org> Makefile.am, configure.in: |
|
|
256 | Correct libc_version path detection, since it was screwing up if libdir != |
|
|
257 | "/lib/". |
|
|
258 | |
|
|
259 | 02 Mar 2005; Martin Schlemmer <azarah@gentoo.org> libsandbox.c: |
|
|
260 | Hack to make sure sandboxed process cannot remove a device node, bug #79836. |
|
|
261 | |
|
|
262 | 02 Mar 2005; Martin Schlemmer <azarah@gentoo.org> Makefile.am: |
|
|
263 | Fix symbols.in not added to dist. |
|
|
264 | |
|
|
265 | 02 Mar 2005; Martin Schlemmer <azarah@gentoo.org> Makefile.am, canonicalize.c, |
|
|
266 | getcwd.c, libsandbox.c, sandbox.c, sandbox.h, sandbox_futils.c: |
|
|
267 | White space fixes. |
|
|
268 | |
|
|
269 | 02 Mar 2005; Martin Schlemmer <azarah@gentoo.org> Makefile.am, canonicalize.c, |
|
|
270 | configure.in, getcwd.c, libsandbox.c, symbols.in: |
|
|
271 | Fix inverse test logic in canonicalize.c, use a strncpy. Fix gcc warning in |
|
|
272 | getcwd.c. Add symbols.in and logic to Makefile.am to generate symbol versions |
|
|
273 | for glibc and other libc's that use this. Update libsandbox.c to use these |
|
|
274 | symbol versions if available. Fix exec wrapper to re-export LD_PRELOAD if the |
|
|
275 | process unset it. |
|
|
276 | |
| 5 | 01 May 2005; Brian Harring <ferringb@gentoo.org> libsandbox.c: |
277 | 01 Mar 2005; Brian Harring <ferringb@gentoo.org> libsandbox.c: |
| 6 | killed off _init and _fini in favor of |
278 | killed off _init and _fini in favor of |
| 7 | void __attribute__ ((constructor)) init_func and |
279 | void __attribute__ ((constructor)) init_func and |
| 8 | void __attribute__ ((destructor)) closing_func. _(init|func) were deprecated. |
280 | void __attribute__ ((destructor)) closing_func. _(init|func) were deprecated. |
| 9 | |
281 | |
| 10 | 06 Dec 2004; Brian Harring <ferringb@gentoo.org> Makefile.am, libsandbox.c, |
282 | 06 Dec 2004; Brian Harring <ferringb@gentoo.org> Makefile.am, libsandbox.c, |