‹ BackHN Continuity

Thread

Software sandboxing: The basics (2025)

116 points · 24 comments · mococa

  1. jmclnx · · focus · HN ↗
    Interesting no mentioned about OpenBSD pledge(2), unveil(2). By far the easiest sandboxing out there. An example:

        #ifdef OpenBSD
          if(pledge("stdio rpath wpath cpath",NULL) == -1)
            err(1,"pledge\n");
        #endif
    
    Very easy, all the other examples seem rather complex to me. unveil(2) is just as easy.
    1. mitxela · · focus · HN ↗
      Works because OpenBSD has totalitarian control of the ecosystem, just like Windows. Wouldn't work on Linux because what do those flags even mean to the kernel?
      1. shiomiru · · focus · HN ↗
        This is often repeated in these kinds of threads, but I don't think it's true. You just have to implement it in glibc, which can map the flags to the actual syscalls used on the current architecture and restrict the process to those with a seccomp BPF filter.

        (Indeed, cosmo libc does exactly that, so it's definitely possible.)

        1. mitxela · · focus · HN ↗
          And then you run a program statically linked with a different version of glibc or musl and what happens?
          1. shiomiru · · focus · HN ↗
            Er... nothing? That's the point, if you statically link to glibc 2.51, then you get a version of pledge where "stdio" allows the stdio syscalls made by glibc 2.51 (say, "read" and "write"). Next time if you link to glibc 2.52, you get a pledge that allows stdio syscalls made by 2.52 (maybe "pread" and "pwrite"), etc. Nothing changes for the user because the libc wrappers for "read"/"write" are synchronized with the pledge promises.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.