Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 0 additions & 39 deletions MODULE.bazel
Original file line number Diff line number Diff line change
Expand Up @@ -185,45 +185,6 @@ http_file(
urls = ["https://raw.githubusercontent.com/SchemaStore/schemastore/166136b96a14f103a948053903e9339e63ad9170/src/schemas/json/github-workflow.json"],
)

# Statically-linked QEMU user-mode emulators.
QEMU_USER_EXPORTS = 'exports_files(["usr/bin/qemu-aarch64", "usr/bin/qemu-riscv64", "usr/bin/qemu-x86_64"])'

deb_data = use_repo_rule("//tools/bazeldefs:extensions/deb_data.bzl", "deb_data")

http_archive(
name = "qemu_user_amd64",
build_file_content = 'exports_files(["data.tar.xz"])',
sha256 = "ca6ede739327a20ae5a3498230c8a3a9a072c586e131bc6bcc1201eb1725e336",
type = "deb",
urls = [
"https://snapshot.debian.org/archive/debian/20260905T205002Z/pool/main/q/qemu/qemu-user_10.0.13%2Bds-0%2Bdeb13u1_amd64.deb",
"https://deb.debian.org/debian/pool/main/q/qemu/qemu-user_10.0.13%2Bds-0%2Bdeb13u1_amd64.deb",
],
)

deb_data(
name = "qemu_user_amd64_files",
build_file_content = QEMU_USER_EXPORTS,
data = "@qemu_user_amd64//:data.tar.xz",
)

http_archive(
name = "qemu_user_arm64",
build_file_content = 'exports_files(["data.tar.xz"])',
sha256 = "c73711af02b97cd5e2667e735d9c06890c57165517110ca4e646c95a7083158d",
type = "deb",
urls = [
"https://snapshot.debian.org/archive/debian/20260905T205002Z/pool/main/q/qemu/qemu-user_10.0.13%2Bds-0%2Bdeb13u1_arm64.deb",
"https://deb.debian.org/debian/pool/main/q/qemu/qemu-user_10.0.13%2Bds-0%2Bdeb13u1_arm64.deb",
],
)

deb_data(
name = "qemu_user_arm64_files",
build_file_content = QEMU_USER_EXPORTS,
data = "@qemu_user_arm64//:data.tar.xz",
)

# Root certificates.
#
# Note that the sha256 hash is omitted here intentionally. This should not be
Expand Down
11 changes: 5 additions & 6 deletions SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -84,8 +84,8 @@ We distinguish the following type of issues, listed from most to least severe:
alone, or any host directory explicitly mounted into the sandbox per
the sandbox configuration.
- `Lateral`: **Sandbox-to-sandbox lateral movement**. Issues that allow an
attacker to execute arbitrary code execution in a sandbox on the same
host other than the one they started with.
attacker to execute arbitrary code in a sandbox on the same host other
than the one they started with.
- `HostDoS`: **Denial-of-service attacks** that affect **the host kernel**
(e.g. trigger a host kernel panic).
- `PeerDoS`: **Denial-of-service attacks** that affect **other sandboxes
Expand Down Expand Up @@ -208,7 +208,7 @@ non-gVisor sandbox):
- **CVE**: ✔️ Yes.
- An attacker exposes the host's `/var/run/docker.sock` UDS within a sandbox,
then creates unsandboxed containers by using this UDS.
- **Classification**: `SandboxConf / Escape`.
- **Classification**: `SandboxSpec / Escape`.
- **CVE**: ❌ No. While the attacker is able to get out of the sandbox,
they required access to the host's `/var/run/docker.sock` to do so,
which secure deployments of gVisor do not expose. Additionally, running
Expand Down Expand Up @@ -281,9 +281,8 @@ disclosure are outlined in the [governance policy](GOVERNANCE.md).

- High-level summary of the issue
- Type of issue, e.g. "sandbox escape", "DoS", ...
- Prerequisites, e.g. "the attacker requires the ability to set these special
flags to be set".
- Classification code as per the above scheme (e.g. "`Sandboxed / Escape`").
- Prerequisites, e.g. "the attacker requires these special flags to be set".
- Classification code as per the above scheme (e.g. "`SandboxRoot / Escape`").
- Explanation of gVisor-specificity, aka behavior and reproducibility when
executing the attack in an unsandboxed context, everything else being equal
(e.g. running with `runc` instead of `runsc`).
Expand Down
12 changes: 0 additions & 12 deletions governance/licensing.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -53,15 +53,3 @@ exceptions:
distributed with gVisor. The LLVM exception only relaxes
Apache-2.0's requirements, and the MIT match comes from third-party
notices embedded in LICENSE.TXT.
- dependency: qemu_user_amd64
license: GPL-2.0-only
exception_rationale: >-
QEMU user-mode emulators for x86_64 build machines, run as a build tool
to execute binaries built for the target architecture when
cross-compiling. QEMU is neither linked into nor distributed with gVisor.
- dependency: qemu_user_arm64
license: GPL-2.0-only
exception_rationale: >-
QEMU user-mode emulators for arm64 build machines, run as a build tool
to execute binaries built for the target architecture when
cross-compiling. QEMU is neither linked into nor distributed with gVisor.
1 change: 1 addition & 0 deletions pkg/seccomp/BUILD
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@ go_library(
"//pkg/abi/linux",
"//pkg/bpf",
"//pkg/log",
"//pkg/sync",
"//pkg/timing",
"@org_golang_x_sys//unix:go_default_library",
],
Expand Down
66 changes: 13 additions & 53 deletions pkg/seccomp/precompiledseccomp/defs.bzl
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
"""Macro for precompiling seccomp-bpf programs."""

load("//tools:defs.bzl", "go_binary", "select_arch", "target_emulator")
load("//tools:defs.bzl", "go_binary")

def precompiled_seccomp_rules(
name,
Expand Down Expand Up @@ -114,9 +114,6 @@ def precompiled_seccomp_rules(
embedsrcs = [
":" + out + ".gen.lib.tmpl.go",
],
pure = True,
noasan = True,
race = "off",
)
if exclude_in_fastbuild:
go_binary(
Expand All @@ -130,67 +127,30 @@ def precompiled_seccomp_rules(

# This genrule actually runs the go_binary we just declared, and writes
# its output (containing the precompiled rules) to the desired `out` file.
#
# The generator is a source (rather than a tool) of this genrule, so that
# it is built for the target platform rather than for the execution
# platform. If the execution platform's architecture differs from the
# target's (i.e. when cross-compiling), it is run under a user-mode
# emulator. If no emulator is configured for the target architecture, it
# is run directly, which works if the kernel is configured to run foreign
# binaries (binfmt_misc) and fails otherwise.
#
# Execution platform constraints are deliberately not used here: they would
# make cross-architecture configurations fail analysis wherever no
# execution platform for the target architecture is available.
emulator = target_emulator()
out_args = " --package='" + out_package_name + "' --out=$@"
run_gen_cmd = (
"GEN=$(location :" + name + "_gen_bin); " +
"RUN=; " +
"if [ -n \"$$TARGET_ARCH\" ] && [ \"$$(uname -m)\" != \"$$TARGET_ARCH\" ]; then " +
" RUN=\"$$EMULATOR\"; " +
"fi; " +
"$$RUN \"$$GEN\"" + out_args + " || { " +
" echo \"Failed to run $$GEN (built for $$TARGET_ARCH) on $$(uname -m)" +
" (emulator: $${RUN:-none}).\" >&2; " +
" exit 1; " +
"}"
)
run_gen_env = (
"TARGET_ARCH=" + select_arch(
amd64 = "x86_64",
arm64 = "aarch64",
riscv64 = "riscv64",
default = "",
) + "; " +
"EMULATOR='" + emulator.cmd + "'; "
)
out_cmd = "$(location :" + name + "_gen_bin) --package='" + out_package_name + "' --out=$@"
if exclude_in_fastbuild:
native.genrule(
name = name,
outs = [out],
srcs = select({
":" + name + "_fastbuild_cond": [],
"//conditions:default": [":" + name + "_gen_bin"],
}),
# The stubbed generator's output does not depend on the
# architecture, so it is built for the execution platform.
cmd = run_gen_env + select({
":" + name + "_fastbuild_cond": "$(location :" + name + "_gen_stubbed_bin)" + out_args,
"//conditions:default": run_gen_cmd,
cmd = select({
":" + name + "_fastbuild_cond": (
"$(location :" + name + "_gen_stubbed_bin) --package='" + out_package_name + "' --out=$@"
),
"//conditions:default": out_cmd,
}),
tools = select({
":" + name + "_fastbuild_cond": [":" + name + "_gen_stubbed_bin"],
"//conditions:default": [],
}) + emulator.tools,
"//conditions:default": [":" + name + "_gen_bin"],
}),
tags = tags + ["requires-mem:16g"],
)
else:
native.genrule(
name = name,
outs = [out],
srcs = [":" + name + "_gen_bin"],
cmd = run_gen_env + run_gen_cmd,
tools = emulator.tools,
cmd = (
"$(location :" + name + "_gen_bin) --package='" + out_package_name + "' --out=$@"
),
tools = [":" + name + "_gen_bin"],
tags = tags + ["requires-mem:16g"],
)
4 changes: 0 additions & 4 deletions pkg/seccomp/precompiledseccomp/precompile_gen.go
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,6 @@ import (
_ "embed"
"fmt"
"os"
"runtime/debug"
"sort"
"strings"

Expand Down Expand Up @@ -57,9 +56,6 @@ var loadProgramsFn = example.PrecompiledPrograms // PROGRAMS_FUNC_THIS_IS_A_LOAD
func main() {
flag.Parse()

debug.SetGCPercent(1000)
debug.SetMemoryLimit(2 << 30)

// Get a sorted list of programs.
var programs []precompiledseccomp.Program
disabledAtBuildTime := loadProgramsFn == nil
Expand Down
10 changes: 0 additions & 10 deletions pkg/seccomp/precompiledseccomp/precompiledseccomp.go
Original file line number Diff line number Diff line change
Expand Up @@ -20,7 +20,6 @@ import (
"encoding/binary"
"fmt"
"maps"
"runtime"
"sort"
"strings"

Expand Down Expand Up @@ -101,15 +100,6 @@ func (v Values) Copy() Values {
return v2
}

// maxParallelism is the maximum value returned by Parallelism.
const maxParallelism = 8

// Parallelism returns the number of programs that `PrecompiledPrograms`
// implementations should compile concurrently.
func Parallelism() int {
return min(runtime.GOMAXPROCS(0), maxParallelism)
}

// Precompile compiles a `seccomp.Program` with the given values.
// It supports the notion of "variables", which are named in `vars`.
// Variables are uint32s which are only known at runtime, and whose value
Expand Down
Loading
Loading