Extended security SECCOMP filters
This commit is contained in:
parent
2127270559
commit
5a9dae8104
|
|
@ -39,6 +39,7 @@ void SunshineBindingInit(){
|
||||||
rb_const_set(module, rb_intern("SDLVersion_major"), INT2NUM(SDL_MAJOR_VERSION));
|
rb_const_set(module, rb_intern("SDLVersion_major"), INT2NUM(SDL_MAJOR_VERSION));
|
||||||
rb_const_set(module, rb_intern("SDLVersion_minor"), INT2NUM(SDL_MINOR_VERSION));
|
rb_const_set(module, rb_intern("SDLVersion_minor"), INT2NUM(SDL_MINOR_VERSION));
|
||||||
rb_const_set(module, rb_intern("SDLVersion_micro"), INT2NUM(SDL_MICRO_VERSION));
|
rb_const_set(module, rb_intern("SDLVersion_micro"), INT2NUM(SDL_MICRO_VERSION));
|
||||||
|
rb_const_set(module, rb_intern("SECURITYSTATE"), rb_str_new_cstr(securitystate));
|
||||||
|
|
||||||
//если методы доступны то просто не перезаписываем их
|
//если методы доступны то просто не перезаписываем их
|
||||||
if (!rb_respond_to(rb_cObject, rb_intern("class"))) {
|
if (!rb_respond_to(rb_cObject, rb_intern("class"))) {
|
||||||
|
|
|
||||||
|
|
@ -85,6 +85,8 @@ class Scene_Title
|
||||||
@debug.bitmap.draw_text(5, 5, 200, 20, tr("Ruby #{RUBY_VERSION}"))
|
@debug.bitmap.draw_text(5, 5, 200, 20, tr("Ruby #{RUBY_VERSION}"))
|
||||||
@debug.bitmap.draw_text(5, 25, 200, 20, tr("SDL #{SDLVer}"))
|
@debug.bitmap.draw_text(5, 25, 200, 20, tr("SDL #{SDLVer}"))
|
||||||
@debug.bitmap.draw_text(5, 45, 200, 20, tr("Sunshine #{SunshineVer}"))
|
@debug.bitmap.draw_text(5, 45, 200, 20, tr("Sunshine #{SunshineVer}"))
|
||||||
|
@debug.bitmap.draw_text(5, 65, 200, 20, tr("sec_#{Sunshine::SECURITYSTATE}"))
|
||||||
|
|
||||||
if ModLoader::IS_ENABLED
|
if ModLoader::IS_ENABLED
|
||||||
@debug.bitmap.draw_text(5, 65, 200, 20, tr("Mods loaded: #{ModLoader::COUNT}"))
|
@debug.bitmap.draw_text(5, 65, 200, 20, tr("Mods loaded: #{ModLoader::COUNT}"))
|
||||||
end
|
end
|
||||||
|
|
|
||||||
|
|
@ -7,6 +7,7 @@
|
||||||
// In the future, we plan to add a mod loader, so this component is needed to protect users from mod attacks.
|
// In the future, we plan to add a mod loader, so this component is needed to protect users from mod attacks.
|
||||||
|
|
||||||
#ifdef __linux__
|
#ifdef __linux__
|
||||||
|
#include <sys/socket.h>
|
||||||
#include <seccomp.h>
|
#include <seccomp.h>
|
||||||
//Yes its not best way, anyway better than nothing.
|
//Yes its not best way, anyway better than nothing.
|
||||||
scmp_filter_ctx ctx;
|
scmp_filter_ctx ctx;
|
||||||
|
|
@ -15,7 +16,7 @@
|
||||||
SCMP_SYS(pidfd_getfd), SCMP_SYS(kcmp), SCMP_SYS(delete_module), SCMP_SYS(init_module), SCMP_SYS(init_module), SCMP_SYS(chroot), SCMP_SYS(reboot), SCMP_SYS(unshare),
|
SCMP_SYS(pidfd_getfd), SCMP_SYS(kcmp), SCMP_SYS(delete_module), SCMP_SYS(init_module), SCMP_SYS(init_module), SCMP_SYS(chroot), SCMP_SYS(reboot), SCMP_SYS(unshare),
|
||||||
SCMP_SYS(umount2), SCMP_SYS(umount), SCMP_SYS(setns), SCMP_SYS(sethostname), SCMP_SYS(setdomainname), SCMP_SYS(bpf), SCMP_SYS(quotactl_fd), SCMP_SYS(quotactl),
|
SCMP_SYS(umount2), SCMP_SYS(umount), SCMP_SYS(setns), SCMP_SYS(sethostname), SCMP_SYS(setdomainname), SCMP_SYS(bpf), SCMP_SYS(quotactl_fd), SCMP_SYS(quotactl),
|
||||||
SCMP_SYS(move_mount), SCMP_SYS(mount_setattr), SCMP_SYS(mount), SCMP_SYS(lsm_set_self_attr), SCMP_SYS(lsm_list_modules), SCMP_SYS(lsm_get_self_attr),
|
SCMP_SYS(move_mount), SCMP_SYS(mount_setattr), SCMP_SYS(mount), SCMP_SYS(lsm_set_self_attr), SCMP_SYS(lsm_list_modules), SCMP_SYS(lsm_get_self_attr),
|
||||||
SCMP_SYS(process_vm_readv), SCMP_SYS(process_vm_writev), SCMP_SYS(ptrace), SCMP_SYS(swapon), SCMP_SYS(swapoff), SCMP_SYS(shutdown), SCMP_SYS(settimeofday),
|
SCMP_SYS(process_vm_readv), SCMP_SYS(process_vm_writev), SCMP_SYS(ptrace), SCMP_SYS(swapon), SCMP_SYS(swapoff), SCMP_SYS(settimeofday),
|
||||||
SCMP_SYS(sethostname), SCMP_SYS(umount), SCMP_SYS(umount2), SCMP_SYS(vm86old), SCMP_SYS(vm86), SCMP_SYS(setgroups), SCMP_SYS(setgid), SCMP_SYS(setfsuid),
|
SCMP_SYS(sethostname), SCMP_SYS(umount), SCMP_SYS(umount2), SCMP_SYS(vm86old), SCMP_SYS(vm86), SCMP_SYS(setgroups), SCMP_SYS(setgid), SCMP_SYS(setfsuid),
|
||||||
SCMP_SYS(setfsgid), SCMP_SYS(setdomainname), SCMP_SYS(setns), SCMP_SYS(setpgid), SCMP_SYS(pciconfig_write)};
|
SCMP_SYS(setfsgid), SCMP_SYS(setdomainname), SCMP_SYS(setns), SCMP_SYS(setpgid), SCMP_SYS(pciconfig_write)};
|
||||||
#endif
|
#endif
|
||||||
|
|
@ -23,7 +24,7 @@
|
||||||
void SecurityManagerInit(){
|
void SecurityManagerInit(){
|
||||||
Debug() << "[SECURITY] Initializing SecurityEngine";
|
Debug() << "[SECURITY] Initializing SecurityEngine";
|
||||||
#ifdef __linux__
|
#ifdef __linux__
|
||||||
printf("[SECURITY] initializing SECCOMP filter...\n");
|
Debug() << "[SECURITY] initializing SECCOMP filter...";
|
||||||
ctx = seccomp_init(SCMP_ACT_ALLOW); // Default action: Kill the process
|
ctx = seccomp_init(SCMP_ACT_ALLOW); // Default action: Kill the process
|
||||||
if(ctx == NULL) {
|
if(ctx == NULL) {
|
||||||
WarnMsg("Warning: Failed to load SECCOMP! If you receive this warning, IT IS NOT RECOMMENDED to add any third-party modifications to Sunshine!");
|
WarnMsg("Warning: Failed to load SECCOMP! If you receive this warning, IT IS NOT RECOMMENDED to add any third-party modifications to Sunshine!");
|
||||||
|
|
@ -35,11 +36,24 @@ void SecurityManagerInit(){
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
//Extra rules
|
||||||
|
//Deny all network connections
|
||||||
|
if(seccomp_rule_add(ctx, SCMP_ACT_ERRNO(EPERM), SCMP_SYS(socket), 1, SCMP_CMP(0, SCMP_CMP_NE, AF_UNIX))){
|
||||||
|
Debug() << "seccomp_rule_add failed for extra rules";
|
||||||
|
}
|
||||||
|
if(seccomp_rule_add(ctx, SCMP_ACT_ERRNO(EPERM), SCMP_SYS(socketpair), 1, SCMP_CMP(0, SCMP_CMP_NE, AF_UNIX))){
|
||||||
|
Debug() << "seccomp_rule_add failed for extra rules";
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
if(seccomp_load(ctx) < 0) {
|
if(seccomp_load(ctx) < 0) {
|
||||||
WarnMsg("Warning: Failed to load SECCOMP! If you receive this warning, IT IS NOT RECOMMENDED to add any third-party modifications to Sunshine!");
|
WarnMsg("Warning: Failed to load SECCOMP! If you receive this warning, IT IS NOT RECOMMENDED to add any third-party modifications to Sunshine!");
|
||||||
seccomp_release(ctx);
|
seccomp_release(ctx);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
securitystate = "sandboxed_SECCOMP";
|
||||||
|
|
||||||
#elif
|
#elif
|
||||||
Debug() << "[SECURITY] SecurityManager doesn't support this platform.";
|
Debug() << "[SECURITY] SecurityManager doesn't support this platform.";
|
||||||
#endif
|
#endif
|
||||||
|
|
|
||||||
|
|
@ -1,2 +1,3 @@
|
||||||
|
inline char* securitystate = "unsandboxed";
|
||||||
void SecurityManagerInit();
|
void SecurityManagerInit();
|
||||||
void SecurityManagerDeInit();
|
void SecurityManagerDeInit();
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue