From jw137282@sac.sfbay.sun.com Mon Apr 27 19:23:17 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3S2NFna001377
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 27 Apr 2009 19:23:16 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n3S2N43Y018238;
	Tue, 28 Apr 2009 10:23:14 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIS00H01HAP6100@brm-avmta-1.central.sun.com>; Mon,
 27 Apr 2009 20:23:13 -0600 (MDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIS008J0HAOJA40@brm-avmta-1.central.sun.com>; Mon,
 27 Apr 2009 20:23:12 -0600 (MDT)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n3S2NBf2014014; Mon, 27 Apr 2009 19:23:11 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3S2MhWo001347; Mon,
 27 Apr 2009 19:22:43 -0700 (PDT)
Received: (from jw137282@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id n3S2Mfbn001343; Mon,
 27 Apr 2009 19:22:41 -0700 (PDT)
Date: Mon, 27 Apr 2009 19:22:41 -0700 (PDT)
From: James Walker <jw137282@sac.sfbay.sun.com>
Subject: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
To: PSARC-ext@sun.com
Cc: jason.zhao@sun.com
Message-id: <200904280222.n3S2Mfbn001343@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 14058

I'm sponsoring this familiarity case for Jason Zhao. The requested
release binding is minor. The man page has been posted in the
materials directory.

Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 snort
    1.2. Name of Document Author/Supplier:
	 Author:  Jason Zhao
    1.3  Date of This Document:
	27 April, 2009
4. Technical Description
Template Version: @(#)sac_nextcase 1.1 03/13/09 SMI
This information is Copyright 2009 Sun Microsystems

1. Introduction
   1.1. Project/Component Working Name:
        snort

   1.2. Name of Document Author/Supplier:
        Author: Jason Zhao

   1.3. Date of This Document:
        23 April 2009

4. Technical Description:
1.0 Project Information
1.1 Name of project/component
	snort

1.2 Author of document
	Jason.Zhao@Sun.COM

2.0 Project Summary
   2.1 Project Description

   SNORT is an open source network intrusion prevention and detection
   utility utilizing a rule-driven language, which combines the benefits
   of signature, protocol and anomaly based inspection methods. With 
   millions of downloads to date, Snort is the most widely deployed
   intrusion detection and prevention technology worldwide and has become
   the de facto standard for the industry.

   snort-2.8.4 will be integrated into the SFW consolidation as part of
   this proposal, and will be installed as SUNWsnortu and SUNWsnortr.

   The project requests a minor release binding.

  2.2 Release binding
      What is is the release binding?
      (see http://opensolaris.org/os/community/arc/policies/release-taxonomy/)
      [ ] Major
      [*] Minor
      [ ] Patch or Micro
      [ ] Unknown -- ARC review required

  2.3 Type of project
      Is this case a Linux Familiarity project?
      [*] Yes
      [ ] No

  2.4 Originating Community
    2.4.1 Community Name
      snort.org
    
    2.4.2 Community Involvement
      Indicate Sun's involvement in the community
      [ ] Maintainer
      [ ] Contributor
      [*] Monitoring
      
      Will the project team work with the upstream community to resolve
      architectural issues of interest to Sun?
      [*] Yes 
      [ ] No - briefly explain
      
      Will we or are we forking from the community?
      [ ] Yes - ARC review required prior to forking
      [*] No
      
3.0 Technical Description
  3.1 Installation & Sharable
    3.1.1S Solaris Installation - section only required for Solaris Software
      (see http://opensolaris.org/os/community/arc/policies/install-locations/ for details)
      Does this project follow the Install Locations best practice?
      [*] Yes 
      [ ] No - ARC review required
      
      Does this project install into /usr under [sbin|bin|lib|include|man|share]?
      [*] Yes
      [ ] No or N/A
      
      Does this project install into /opt?
      [ ] Yes - explain below
      [*] No or N/A
      
      Does this project install into a different directory structure?
      [ ] Yes - ARC review required
      [*] No or N/A
      
      Do any of the components of this project conflict with anything under /usr?
      (see http://opensolaris.org/os/community/arc/caselog/2007/047/ for details)
      [ ] Yes - explain below
      [*] No
      
      If conflicts exist then will this project install under /usr/gnu?
      [ ] Yes
      [ ] No - ARC review required
      [*] N/A
      
      Is this project installing into /usr/sfw?
      [ ] Yes - ARC review required
      [*] No
      
    3.1.1W Windows Installation - section only required for Windows Software
      (see http://sac.sfbay/WSARC/2002/494 for details)
      Does this project install software into a 
      <system drive>:\Program Files\Sun\<product> or <system drive>:\Sun\<product>
      directory?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use the Windows registry?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use 
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product>\<version>
      for the registry key?
      [ ] Yes
      [ ] No - ARC review required
      
      Is the project's stored location
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product id>\<version id>\Path?
      [ ] Yes
      [ ] No - ARC review required
      
    3.1.2 Share and Sharable
      Does the module include any components that are used or shared by 
      other projects?
      [ ] Yes
      [*] No
    
      If yes are these components packaged to be shared with the other FOSS?
      [ ] Yes
      [ ] No - ARC review required
      [*] N/A
    
      Are these components already in the Solaris WOS?
      [ ] Yes
      [*] No - continue with next section (section 3.2)
    
      If yes are these newer versions being delivered?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes are the newer versions replacing the existing versions?
      [ ] Yes
      [ ] No - ARC review required

  3.2 Exported Libraries
      Are libraries being delivered by this project?
      [*] Yes
      [ ] No - continue with next section (section 3.3)
      
      Are 64-bit versions of the libraries being delivered?
      [*] Yes
      [ ] No - ARC review required
    
      Are static versions of the libraries being delivered?
      [ ] Yes - ARC review required
      [*] No 
      
  3.3 Services and the /etc Directory
      (see http://opensolaris.org/os/community/arc/policies/SMF-policy/)
      Does the project integrate anything into /etc/init.d or /etc/rc?.d?
      [ ] Yes - ARC review required
      [*] No
      
      Does the project integrate any new entries into /etc/inittab or
      /etc/inetd.conf?
      [ ] Yes - ARC review required
      [*] No
      
      Does the project integrate any private non-public files into /etc/default
      or /etc/ configuration files?
      [ ] Yes - ARC review required
      [*] No
      
      Does the service manifests method context grant rights above that
      of the noaccess user and basic privilege set?
      [ ] Yes - ARC review required
      [*] No
        
  3.4 Security
    3.4.1 Secure By Default 
      (see http://opensolaris.org/os/community/arc/policies/secure-by-default/ for details)
      (see http://www.opensolaris.org/os/community/arc/policies/NITS-policy/ for details)
      (see parts of http://opensolaris.org/os/community/arc/policies/SMF-policy/ for
       addtional details)
      Are there any network services provided by this project?
      [ ] Yes
      [*] No - continue with the next section (section 3.4.2)
      
      Are network services enabled by default?
      [ ] Yes - ARC review required
      [ ] No
      [ ] N/A
      
      Are network services automatically enabled by the project during installation?
      [ ] Yes - ARC review required
      [ ] No
      [ ] N/A
      
      Are inbound network communications denied by default?
      [ ] Yes
      [ ] No - ARC review required
      [ ] N/A
      
      Is inbound data checked to prevent content-based attacks?
      [ ] Yes
      [ ] No - ARC review required
      [ ] N/A
      
      Is the outbound receiver authenticated?
      [ ] Yes
      [ ] No - ARC review required
      [ ] N/A
      
      Is the receiver authenticated prior to receiving any sensitive outbound communication?
      [ ] Yes
      [ ] No - ARC review required
      [ ] N/A
      
    3.4.2 Authorization
      (see http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
           for details)
      Are there any setuid/setgid privileged binaries in the project?
      [ ] Yes - ARC review required
      [*] No - continue with next section (section 3.4.3)
      
      If yes then are the setuid/setgid privileges handled by the use of roles?
      [ ] Yes
      [ ] No - ARC review required

    3.4.3 Auditing
      (see http://opensolaris.org/os/community/arc/policies/audit-policy/ for details)
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Does this component contain administrative or security enforcing software?
      [ ] Yes - ARC review required
      [*] No - continue to next section (section 3.4.4)
      
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Do the components create audit logs detailing what took place including what event
      took place, who was involved, when the event took place?
      [ ] Yes - ARC contract and Audit project team review required
      [ ] No - ARC review required
  
    3.4.4 Authentication
      (see http://opensolaris.org/os/community/arc/policies/PAM/)
      Do the components contain any authentication code?
      [ ] Yes
      [*] No - continue to next section (section 3.4.5)
      
      If yes do the components use PAM (plugable authentication modules) for authentication?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes is a single PAM session maintained during authentication?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes are the components sufficiently privileged to allow the requested 
      operations (authentication, password change, process credential manipulation, 
      audit state initialization)?
      [ ] Yes - briefly describe below
      [ ] No - ARC review required
      
    3.4.5 Passwords
      (see http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/ and
           http://opensolaris.org/os/community/arc/bestpractices/passwords-files/ for details)
      Do any of the components for the project deal with passwords?
      [ ] Yes
      [*] No - continue to next section (section 3.4.6)
      
      If yes are these passwords entered via the CLI or environment?
      [ ] Yes - ARC review required
      [ ] No
      
      Are passwords stored within the file system for the component?
      [ ] Yes
      [ ] No - continue to next section (section 3.4.6)
      
      If yes are the permissions on the file such to protect exposing the password(s)?
      [ ] Yes
      [ ] No - ARC review required
      
    3.4.6 General Security Questions
      (see http://opensolaris.org/os/community/arc/bestpractices/security-questions/ for details)
      Are there any network protocols used by this project?
      [*] Yes
      [ ] No - continue with the next section (section 3.5)
      
      Do the components use standard network protocols?
      [*] Yes
      [ ] No - ARC review required
      
      Do network services for the project make decisions based upon user, host or 
      service identities?
      [*] Yes - explain below
      [ ] No
      [ ] N/A
      
      snort can monitor the network based on host, interface and port

      Do the components make use of secret information during authentication and/or
      authorization?
      [ ] Yes - explain below
      [ ] No
      [*] N/A
  
  3.5 Networking
      Do the components access the network?
      [*] Yes
      [ ] No - continue with the next section (section 3.6)
      
      If yes do the components support IPv6?
      [*] Yes 
      [ ] No - ARC review required
          
  3.6 Core Solaris Components
      Do the components of this project compete with or duplicate core 
      Solaris components?
      [ ] Yes - ARC review required
      [*] No 
      
      Examples of Core Solaris Components include but are not limited to:
      
        Secure By Default
        Authorizations
        PAM -- Plugable Authentication Module
        Privilege
        PRM -- Process Rights Management -- Privilege
        Audit
        xVm -- Virtualization
        zones / Solaris Containers
        PRM -- Process Rights Management
        RBAC -- Role Based Access Control
        TX / Trusted Extensions
        ZFS
        SMF -- Service Management Facility
        FMA -- Fault Management Architecture
        SCF -- Smart Card Facility
        IPsec
        
4.0 Interfaces
  (see http://www.opensolaris.org/os/community/arc/policies/interface-taxonomy/ for details)

  (note: the 64 directory is shorthand for ${ISAINFO}, sparcv9 or amd64)

  4.1 Exported Interfaces

    Interface Name			 Classification	Comments
    ---------------------------		 --------------	-----------------------
    SUNWsnortr				 Uncommitted	Package
    /etc/snort.conf			 Uncommitted	Snort config file

    SUNWsnortu				 Uncommitted	Package
    /usr/bin/snort                       Uncommitted	Command
    /usr/bin/64/snort                    Uncommitted	64-bit Command

  4.2 Project Private Interfaces

    Interface Name			   Comments
    ---------------------------		   -----------------------
    /usr/lib/snort_dynamicengine/	   Dynamic Engine Handling Plugin
    /usr/lib/64/snort_dynamicengine/	   64-bit 

    /usr/lib/snort_dynamicpreprocessor/	   Dynamic Rule Preprocessor plugins
    /usr/lib/64/snort_dynamicpreprocessor/ 64-bit

    /usr/lib/snort_dynamicrules/	   Dynamic Rules Private plugin
    /usr/lib/64/snort_dynamicrules/	   64-bit 

  4.3 Imported Interfaces

   Interface Name  Classification  Comment
   --------------  --------------  ----------------------------------
   SUNWlibms       Committed	   Math and Microtasking Library (Usr)
   SUNWlibmsr	   Committed       Math and Microtasking Library (Root)
   SUNWlibpcap     Uncommitted	   Packet capture library
   SUNWpcre	   Uncommitted	   Perl-Compatible Regular Expression Library
   SUNWlibsasl     Committed	   SASL shared library and plugins
   SUNWpr	   Committed	   Netscape Portable Runtime Interface
   SUNWtls	   Committed	   Network Security Services


Appendix A - Reference
====================
[1] http://www.snort.org/

OSR ID# 10720
RFE ID# 6811043

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		SFW
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From gww@sac.sfbay.sun.com Mon Apr 27 23:16:53 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3S6Grxe001148
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 27 Apr 2009 23:16:53 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n3S6GoZk014840
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 27 Apr 2009 23:16:52 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIS00K19S44ML00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 27 Apr 2009 23:16:52 -0700 (PDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIS00KNWS44DI00@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 27 Apr 2009 23:16:52 -0700 (PDT)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n3S6Gomd044736; Mon, 27 Apr 2009 23:16:50 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3S6GorJ001146; Mon,
 27 Apr 2009 23:16:50 -0700 (PDT)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id n3S6GoeE001145; Mon, 27 Apr 2009 23:16:50 -0700 (PDT)
Date: Mon, 27 Apr 2009 23:16:50 -0700 (PDT)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
To: PSARC-ext@sun.com, jw137282@sac.sfbay.sun.com
Cc: jason.zhao@sun.com
Message-id: <200904280616.n3S6GoeE001145@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 865

>     3.4.2 Authorization
>       (see http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
> 	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/ and
> 	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
>            for details)
>       Are there any setuid/setgid privileged binaries in the project?
>       [ ] Yes - ARC review required
>       [*] No - continue with next section (section 3.4.3)
>       
>       If yes then are the setuid/setgid privileges handled by the use of roles?
>       [ ] Yes
>       [ ] No - ARC review required

	If it's not suid (as ping is), I presume that snort needs something
	like net_observibility or net_raw_access to run properly.  How does
	it get that or any other privileges it may need?
	What Rights Profile (and exec_attr(4) properties are required)?

Gary..

From Joep.Vesseur@sun.com Mon Apr 27 23:46:12 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3S6kCbX001712
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 27 Apr 2009 23:46:12 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n3S6kCPn013340
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 27 Apr 2009 23:46:12 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIS00M0RTGYE000@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 27 Apr 2009 23:46:10 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIS00K5XTGUDA30@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 27 Apr 2009 23:46:07 -0700 (PDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n3S6k6O4006447	for
 <PSARC-ext@sun.com>; Tue, 28 Apr 2009 06:46:06 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KIS00300TBHA600@fe-emea-10.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 28 Apr 2009 07:46:06 +0100 (BST)
Received: from [10.16.117.32] ([unknown] [10.16.117.32])
 by fe-emea-10.sun.com (Sun Java(tm) System Messaging Server 7.0-5.01 64bit
 (built Feb 19 2009)) with ESMTPSA id <0KIS00CUWTGMGH40@fe-emea-10.sun.com>;
 Tue, 28 Apr 2009 07:45:59 +0100 (BST)
Date: Tue, 28 Apr 2009 08:45:58 +0200
From: Joep Vesseur <Joep.Vesseur@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <200904280616.n3S6GoeE001145@sac.sfbay.sun.com>
Sender: Joep.Vesseur@sun.com
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com, jw137282@sac.sfbay.sun.com, Jason.Zhao@sun.com
Message-id: <49F6A626.7000601@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Enigmail-Version: 0.95.1
References: <200904280616.n3S6GoeE001145@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 1014

On 04/28/09 08:16, Gary Winiger wrote:
>>     3.4.2 Authorization
>>       (see http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
>> 	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/ and
>> 	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
>>            for details)
>>       Are there any setuid/setgid privileged binaries in the project?
>>       [ ] Yes - ARC review required
>>       [*] No - continue with next section (section 3.4.3)
>>       
>>       If yes then are the setuid/setgid privileges handled by the use of roles?
>>       [ ] Yes
>>       [ ] No - ARC review required
> 
> 	If it's not suid (as ping is), I presume that snort needs something
> 	like net_observibility or net_raw_access to run properly.  How does
> 	it get that or any other privileges it may need?
> 	What Rights Profile (and exec_attr(4) properties are required)?

sort monitors logfiles; if it can read those, there's no need for additional
privileges.

Joep

From carlsonj@phorcys.east.sun.com Tue Apr 28 06:28:46 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3SDSjIA001828
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 28 Apr 2009 06:28:46 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n3SDSZjY003693
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Tue, 28 Apr 2009 14:28:44 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIT00F0XC3V8X00@brm-avmta-1.central.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Tue, 28 Apr 2009 07:28:43 -0600 (MDT)
Received: from dm-east-02.east.sun.com ([129.148.13.5])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIT0060MC3UVS70@brm-avmta-1.central.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Tue,
 28 Apr 2009 07:28:43 -0600 (MDT)
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by dm-east-02.east.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n3SDSd1f031930; Tue, 28 Apr 2009 09:28:39 -0400 (EDT)
Received: from phorcys.east.sun.com (phorcys.local [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n3SDRwS9011125; Tue,
 28 Apr 2009 09:27:58 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n3SDRw0S011122; Tue,
 28 Apr 2009 09:27:58 -0400 (EDT)
Date: Tue, 28 Apr 2009 09:27:58 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <200904280222.n3S2Mfbn001343@sac.sfbay.sun.com>
To: James Walker <jw137282@sac.sfbay.sun.com>,
        Joep Vesseur <Joep.Vesseur@sun.com>
Cc: PSARC-ext@sun.com, Jason.Zhao@sun.com,
        Gary Winiger <gww@sac.sfbay.sun.com>
Message-id: <18935.1118.374789.911184@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200904280616.n3S6GoeE001145@sac.sfbay.sun.com>
 <49F6A626.7000601@Sun.COM> <200904280222.n3S2Mfbn001343@sac.sfbay.sun.com>
Status: RO
Content-Length: 2037

James Walker writes:
>     /usr/bin/64/snort                    Uncommitted	64-bit Command

What's this about?  What does the utility do that actually requires
64-bit operation?  (Does it read from kernel memory directly?)

Is snort ordinarily used in daemon mode?  If so, shouldn't there be an
SMF configuration for it?  Otherwise, users are forced to roll their
own, and the project seems incomplete.

The files that snort consumes have no stability at all.  It's designed
to read from system log files, and we simply place no controls on
those at all.  The messages it needs in order to do its analysis may
change incompatibly, at any time, and without notice.

I certainly understand the popularity of snort.  It partially fills an
important functional gap (simplifying administration by sifting
through system data, albeit only portions of the security aspects).
But given that it's designed to rely on things that are explicitly not
designed to be programmatic interfaces in OpenSolaris, it's unclear to
me how to the ARC could ever endorse it.

It may break, and there's nothing that any ARC review could do to
avoid that prospect.  I suspect we'll need to derail and review it
formally.

Joep Vesseur writes:
> > 	If it's not suid (as ping is), I presume that snort needs something
> > 	like net_observibility or net_raw_access to run properly.  How does
> > 	it get that or any other privileges it may need?
> > 	What Rights Profile (and exec_attr(4) properties are required)?
> 
> sort monitors logfiles; if it can read those, there's no need for additional
> privileges.

Snort does far more than just read files.  It links to libpcap and can
snoop on network interfaces in real time.  To do *that*, it will
require elevated privileges.

Do those come from RBAC, or is the user expected to use "sudo"?

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Joep.Vesseur@sun.com Tue Apr 28 06:53:07 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3SDr6u6002208
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 28 Apr 2009 06:53:06 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n3SDr2mI042045
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 28 Apr 2009 07:53:06 -0600 (MDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIT00H0FD8ILH00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Tue, 28 Apr 2009 07:53:06 -0600 (MDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIT006QGD8HVJB0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Tue,
 28 Apr 2009 07:53:05 -0600 (MDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n3SDr4qS016304	for
 <PSARC-ext@Sun.COM>; Tue, 28 Apr 2009 13:53:04 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KIT00A00BOXYW00@fe-emea-09.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Tue, 28 Apr 2009 14:53:04 +0100 (BST)
Received: from [10.16.117.32] ([unknown] [10.16.117.32])
 by fe-emea-09.sun.com (Sun Java(tm) System Messaging Server 7.0-5.01 64bit
 (built Feb 19 2009)) with ESMTPSA id <0KIT00KTZD7PORA0@fe-emea-09.sun.com>;
 Tue, 28 Apr 2009 14:52:39 +0100 (BST)
Date: Tue, 28 Apr 2009 15:52:37 +0200
From: Joep Vesseur <Joep.Vesseur@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <18935.1118.374789.911184@gargle.gargle.HOWL>
Sender: Joep.Vesseur@sun.com
To: James Carlson <James.D.Carlson@sun.com>
Cc: James Walker <jw137282@sac.sfbay.sun.com>, PSARC-ext@sun.com,
        Jason.Zhao@sun.com, Gary Winiger <gww@sac.sfbay.sun.com>
Message-id: <49F70A25.8080103@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Enigmail-Version: 0.95.1
References: <200904280616.n3S6GoeE001145@sac.sfbay.sun.com>
 <49F6A626.7000601@Sun.COM> <200904280222.n3S2Mfbn001343@sac.sfbay.sun.com>
 <18935.1118.374789.911184@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 694

On 04/28/09 15:27, James Carlson wrote:

> Joep Vesseur writes:
>> > 	If it's not suid (as ping is), I presume that snort needs something
>> > 	like net_observibility or net_raw_access to run properly.  How does
>> > 	it get that or any other privileges it may need?
>> > 	What Rights Profile (and exec_attr(4) properties are required)?
>> 
>> sort monitors logfiles; if it can read those, there's no need for additional
>> privileges.
> 
> Snort does far more than just read files.  It links to libpcap and can
> snoop on network interfaces in real time.  To do *that*, it will
> require elevated privileges.

Ah, ok, I guess my snort knowledge is out of date then. Sorry for the noise.

Joep

From gww@eng.sun.com Tue Apr 28 08:12:44 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3SFCiTu026516
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 28 Apr 2009 08:12:44 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n3SFChJY037898
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 28 Apr 2009 09:12:44 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIT0030BGX7V400@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 28 Apr 2009 08:12:43 -0700 (PDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIT00JSAGX6C3D0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 28 Apr 2009 08:12:42 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n3SFCdrq047989; Tue, 28 Apr 2009 08:12:39 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n3SFBs44012420; Tue,
 28 Apr 2009 08:11:54 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n3SFBsc5012419; Tue,
 28 Apr 2009 08:11:54 -0700 (PDT)
Date: Tue, 28 Apr 2009 08:11:54 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
To: gww@sac.sfbay.sun.com, Joep.Vesseur@sun.com
Cc: PSARC-ext@sun.com, jw137282@sac.sfbay.sun.com, Jason.Zhao@sun.com
Message-id: <200904281511.n3SFBsc5012419@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 179


> sort monitors logfiles; if it can read those, there's no need for additional
> privileges.

	OK, thanks.  I didn't get that from looking at the man page or
	website;-)

Gary..

From ro@techfak.uni-bielefeld.de Tue Apr 28 11:02:57 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3SI2to4012939
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 28 Apr 2009 11:02:55 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n3SI2Wtq016926;
	Tue, 28 Apr 2009 19:02:52 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIT00C1POSSL200@nwk-avmta-2.sfbay.sun.com>; Tue,
 28 Apr 2009 11:02:52 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIT00BQNOSQKQ10@nwk-avmta-2.sfbay.sun.com>; Tue,
 28 Apr 2009 11:02:50 -0700 (PDT)
Received: from relay43i.sun.com ([192.5.209.74])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n3SHu2rC024151; Tue,
 28 Apr 2009 18:02:50 +0000 (GMT)
Received: from mmp41es.mmp.us.syntegra.com ([160.41.221.10] [160.41.221.10])
 by relay43i.sun.com with ESMTP id BT-MMP-1872415; Tue,
 28 Apr 2009 18:02:50 +0000 (Z)
Received: from relay42i.sun.com (relay42i.sun.com [192.5.209.72])
 by mmp41es.mmp.us.syntegra.com with ESMTP id BT-MMP-33030332; Tue,
 28 Apr 2009 18:02:47 +0000 (Z)
Received: from smarthost.TechFak.Uni-Bielefeld.DE
 ([129.70.137.17] [129.70.137.17]) by relay4i.sun.com with ESMTP id
 BT-MMP-31889381; Tue, 28 Apr 2009 18:00:18 +0000 (Z)
Received: from manam.TechFak.Uni-Bielefeld.DE
 (manam.TechFak.Uni-Bielefeld.DE [129.70.137.47])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)	by smarthost.TechFak.Uni-Bielefeld.DE
 (Postfix) with ESMTP id C1CE8481F1; Tue, 28 Apr 2009 19:59:54 +0200 (CEST)
Date: Tue, 28 Apr 2009 19:59:53 +0200
From: Rainer Orth <ro@techfak.uni-bielefeld.de>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: James Walker's message of "Mon, 27 Apr 2009 19:22:41 -0700 (PDT)"
Sender: ro@techfak.uni-bielefeld.de
To: James Walker <jw137282@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com, jason.zhao@sun.com
Message-id: <yddocug8xra.fsf@manam.TechFak.Uni-Bielefeld.DE>
MIME-version: 1.0
X-Mailer: Gnus v5.6.44/Emacs 19.34
Content-type: text/plain; charset=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Antispam: No, score=0.0/5.0, scanned in 2.510sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
Lines: 23
References: <200904280222.n3S2Mfbn001343@sac.sfbay.sun.com>
Status: RO
Content-Length: 865

James Walker <jw137282@sac.sfbay.sun.com> writes:

>   4.2 Project Private Interfaces
> 
>     Interface Name			   Comments
>     ---------------------------		   -----------------------
>     /usr/lib/snort_dynamicengine/	   Dynamic Engine Handling Plugin
>     /usr/lib/64/snort_dynamicengine/	   64-bit 
> 
>     /usr/lib/snort_dynamicpreprocessor/	   Dynamic Rule Preprocessor plugins
>     /usr/lib/64/snort_dynamicpreprocessor/ 64-bit
> 
>     /usr/lib/snort_dynamicrules/	   Dynamic Rules Private plugin
>     /usr/lib/64/snort_dynamicrules/	   64-bit 

Just a nit: couldn't those directories be moved to /usr/lib/{, 64}/snort/{dynamicengine, dynamicpreprocessor, dynamicrules}
instead of cluttering /usr/lib?

	Rainer

-- 
-----------------------------------------------------------------------------
Rainer Orth, Faculty of Technology, Bielefeld University

From Jason.Zhao@Sun.COM Wed Apr 29 05:13:32 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3TCDUtQ018973
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 29 Apr 2009 05:13:31 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n3TCDTsJ029926
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 29 Apr 2009 13:13:30 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIV00I313AHGM00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Wed, 29 Apr 2009 05:13:29 -0700 (PDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIV00EVQ3ABW740@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Wed,
 29 Apr 2009 05:13:24 -0700 (PDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n3TCDMSG008314	for
 <PSARC-ext@Sun.COM>; Wed, 29 Apr 2009 12:13:22 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KIV0010036TDF00@mail-apac.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Wed, 29 Apr 2009 20:13:22 +0800 (SGT)
Received: from [129.158.218.22] ([unknown] [129.158.218.22])
 by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KIV00NED3A92NG0@mail-apac.sun.com>; Wed,
 29 Apr 2009 20:13:22 +0800 (SGT)
Date: Wed, 29 Apr 2009 20:14:09 +0800
From: Jason Zhao <Jason.Zhao@Sun.COM>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <18935.1118.374789.911184@gargle.gargle.HOWL>
Sender: Jason.Zhao@Sun.COM
To: James Carlson <James.D.Carlson@Sun.COM>
Cc: James Walker <jw137282@sac.sfbay.sun.com>,
        Joep Vesseur <Joep.Vesseur@Sun.COM>, PSARC-ext@Sun.COM,
        Gary Winiger <gww@sac.sfbay.sun.com>
Message-id: <49F84491.2030607@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200904280616.n3S6GoeE001145@sac.sfbay.sun.com>
 <49F6A626.7000601@Sun.COM> <200904280222.n3S2Mfbn001343@sac.sfbay.sun.com>
 <18935.1118.374789.911184@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 3638

Hi, James,

Thank you very much for your comments, please see in line.
> James Walker writes:
>   
>>     /usr/bin/64/snort                    Uncommitted	64-bit Command
>>     
>
> What's this about?  What does the utility do that actually requires
> 64-bit operation?  (Does it read from kernel memory directly?)
>   
It definitely does not read from kernel memory directly.

All the data comes from libpcap and it tries to handle it in
real time, as you said.

For me, 64-bit  /usr/bin/64/snort exists because snort also is
able to deliver 64bit plugin libraries(/usr/lib/64/snort_preprocessors/*),
I've asked developers about difference between these 64bit
and 32bit plugin libraries. The following is their answers.

####################################
.....

There isn't anything specific in Snort that is relying on
32 vs 64 bit.  Pointer sizes would change.

The only real restriction is that the Snort binary and
the shared libraries must be the same (64bit or 32bit),
otherwise data structure sizes will likely cause a core
or other bus error.

.....
####################################

And from function point of view, through my testing,there is no difference
between 64bit and 32bit. But on 64bit machines, it might be
required to use 64bit plugin libraries, so the 64bit /usr/bin/64/snort is
delivered.

In my test results, there is no difference between 64bit and 32bit.
> Is snort ordinarily used in daemon mode?  If so, shouldn't there be an
> SMF configuration for it?  Otherwise, users are forced to roll their
> own, and the project seems incomplete.
>   
I usually run the snort in bash by hands, not in daemon mode. However,
I could not say most of administrator may run it in daemon mode.

It definitely can support daemon, The following is an example
to run snort in daemon mode.
# snort -D -d -N -c /etc/snort.conf

It is possible user can run the command as their own, but if there is
no enough permission, the command line will exit with fail message.
> The files that snort consumes have no stability at all.  It's designed
> to read from system log files, and we simply place no controls on
> those at all.  The messages it needs in order to do its analysis may
> change incompatibly, at any time, and without notice.
>
> I certainly understand the popularity of snort.  It partially fills an
> important functional gap (simplifying administration by sifting
> through system data, albeit only portions of the security aspects).
> But given that it's designed to rely on things that are explicitly not
> designed to be programmatic interfaces in OpenSolaris, it's unclear to
> me how to the ARC could ever endorse it.
>   
So far, it mainly depends on libpcap.so and libpcre.so which has
been ported into OpenSolaris as SUNWlibpcap and SUNWpcre packages.
> It may break, and there's nothing that any ARC review could do to
> avoid that prospect.  I suspect we'll need to derail and review it
> formally.
>
> Joep Vesseur writes:
>   
>>> 	If it's not suid (as ping is), I presume that snort needs something
>>> 	like net_observibility or net_raw_access to run properly.  How does
>>> 	it get that or any other privileges it may need?
>>> 	What Rights Profile (and exec_attr(4) properties are required)?
>>>       
>> sort monitors logfiles; if it can read those, there's no need for additional
>> privileges.
>>     
>
> Snort does far more than just read files.  It links to libpcap and can
> snoop on network interfaces in real time.  To do *that*, it will
> require elevated privileges.
>   
Right.
> Do those come from RBAC, or is the user expected to use "sudo"?
>   
"sudo" could work.

Thanks
Jason

From gww@eng.sun.com Wed Apr 29 08:11:06 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3TFB51a028149
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 29 Apr 2009 08:11:05 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n3TFAxhW018967
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 29 Apr 2009 09:11:05 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KIV00G0TBIFVS00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 29 Apr 2009 08:11:03 -0700 (PDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KIV00ESNBIF9K10@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 29 Apr 2009 08:11:03 -0700 (PDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n3TFAxjs033546; Wed, 29 Apr 2009 08:10:59 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n3TFADSV013745; Wed,
 29 Apr 2009 08:10:13 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n3TFADTW013744; Wed,
 29 Apr 2009 08:10:13 -0700 (PDT)
Date: Wed, 29 Apr 2009 08:10:13 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
To: James.D.Carlson@sun.com, Jason.Zhao@sun.com
Cc: jw137282@sac.sfbay.sun.com, Joep.Vesseur@sun.com, PSARC-ext@sun.com,
        gww@sac.sfbay.sun.com
Message-id: <200904291510.n3TFADTW013744@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 387

> > Snort does far more than just read files.  It links to libpcap and can
> > snoop on network interfaces in real time.  To do *that*, it will
> > require elevated privileges.
> >   
> Right.

	What are those elevated privileges.

> > Do those come from RBAC, or is the user expected to use "sudo"?
> >   
> "sudo" could work.

	What will be delivered into what Rights Profile?

Gary..

From Jason.Zhao@sun.com Mon May  4 00:15:24 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n447FN0g013203
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 4 May 2009 00:15:23 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n447FKAu026950
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 4 May 2009 08:15:22 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ30030BYTM0N00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 04 May 2009 00:15:22 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ300IEMYTIOE90@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 04 May 2009 00:15:22 -0700 (PDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n447FIp5006420	for
 <PSARC-ext@sun.com>; Mon, 04 May 2009 07:15:18 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KJ300000YOR9400@mail-apac.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 04 May 2009 15:15:18 +0800 (SGT)
Received: from [129.158.218.22] ([unknown] [129.158.218.22])
 by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KJ300D7WYTDEII0@mail-apac.sun.com>; Mon,
 04 May 2009 15:15:18 +0800 (SGT)
Date: Mon, 04 May 2009 15:16:04 +0800
From: Jason Zhao <Jason.Zhao@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <200904291510.n3TFADTW013744@marduk.eng.sun.com>
Sender: Jason.Zhao@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: James.D.Carlson@sun.com, jw137282@sac.sfbay.sun.com, Joep.Vesseur@sun.com,
        PSARC-ext@sun.com, gww@sac.sfbay.sun.com
Message-id: <49FE9634.2050701@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200904291510.n3TFADTW013744@marduk.eng.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 1233

Hi, Gary,
>>> Snort does far more than just read files.  It links to libpcap and can
>>> snoop on network interfaces in real time.  To do *that*, it will
>>> require elevated privileges.
>>>   
>>>       
>> Right.
>>     
>
> 	What are those elevated privileges.
>   
For "privileges", I think you mean the auths of RBAC.

I believe "Network Management" is enough for snort.

"solaris.smf.*" if it needs to deliver SMF manifest;
"solaris.network.*" for network read or write.

>   
>>> Do those come from RBAC, or is the user expected to use "sudo"?
>>>   
>>>       
>> "sudo" could work.
>>     
>
> 	What will be delivered into what Rights Profile?
>   
It is very similiar to "wireshark" which has been delivered, since
both of the utilities take advantage of libpcap to read data and handle
them after set NIC to raw mode. For snort, it doesn't read data directly
from kernel memory, raw I/O from NIC is the way it works.

And I believe "Network Management" profile is enough.

The project will deliver SUNWsnortr and SUNWsnortu. On SUNWsnortr,
it will deliver profiles in /etc/security/exec_attr (added snort):

Network Management:solaris:cmd:::/usr/bin/snort:privs=net_rawaccess


Hope I answer your question.


Thanks
Jason

From Jason.Zhao@sun.com Mon May  4 00:57:18 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n447vHCV014195
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 4 May 2009 00:57:18 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n447ursE006549
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 4 May 2009 15:57:16 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ400K010RFCQ00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Mon, 04 May 2009 00:57:15 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ4005700RD95F0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Mon,
 04 May 2009 00:57:14 -0700 (PDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n447vD4k008663	for
 <PSARC-ext@Sun.COM>; Mon, 04 May 2009 07:57:13 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KJ4003000EX2A00@mail-apac.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Mon, 04 May 2009 15:57:13 +0800 (SGT)
Received: from [129.158.218.22] ([unknown] [129.158.218.22])
 by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KJ400D070RCEIK0@mail-apac.sun.com>; Mon,
 04 May 2009 15:57:13 +0800 (SGT)
Date: Mon, 04 May 2009 15:58:05 +0800
From: Jason Zhao <Jason.Zhao@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <18935.1118.374789.911184@gargle.gargle.HOWL>
Sender: Jason.Zhao@sun.com
To: James Carlson <James.D.Carlson@sun.com>
Cc: James Walker <jw137282@sac.sfbay.sun.com>,
        Joep Vesseur <Joep.Vesseur@sun.com>, PSARC-ext@sun.com,
        Gary Winiger <gww@sac.sfbay.sun.com>
Message-id: <49FEA00D.7030000@Sun.COM>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_dxiQAeAeW3hDl3izni3ODA)"
X-PMX-Version: 5.4.1.325704
References: <200904280616.n3S6GoeE001145@sac.sfbay.sun.com>
 <49F6A626.7000601@Sun.COM> <200904280222.n3S2Mfbn001343@sac.sfbay.sun.com>
 <18935.1118.374789.911184@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 5372

This is a multi-part message in MIME format.

--Boundary_(ID_dxiQAeAeW3hDl3izni3ODA)
Content-type: text/plain; format=flowed; charset=us-ascii
Content-transfer-encoding: 7BIT

Hi, James,
> James Walker writes:
>   
>>     /usr/bin/64/snort                    Uncommitted	64-bit Command
>>     
>
> What's this about?  What does the utility do that actually requires
> 64-bit operation?  (Does it read from kernel memory directly?)
>   
 From functions points of view, there is no difference between 32-bit
and 64-bit "snort" binaries. 64-bit snort is an optional choice when 
building
the binary. And if you really concern about it, I can remove 64-bit
part. Please tell me your idea.
> Is snort ordinarily used in daemon mode?  If so, shouldn't there be an
> SMF configuration for it?  Otherwise, users are forced to roll their
> own, and the project seems incomplete.
>   
I finished the SMF manifest in /var/svc/manifest/network/snort.xml;

And the related start script is "/lib/svc/method/snortd", it only contains
"start" option. And when "enable" the service, it will call 
"/usr/bin/snort -d
-D" to start the daemon.

Please see the attachment.

Through testing on my SPARC and X86 OpenSolaris 0906 machines, the SMF
manifest and snortd script could work well.


Thanks
Jason

--Boundary_(ID_dxiQAeAeW3hDl3izni3ODA)
Content-type: text/plain; name=snortd
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=snortd

#!/sbin/sh
#
# Copyright 2009 Sun Microsystems, Inc.  All rights reserved.
# Use is subject to license terms.
#

. /lib/svc/share/smf_include.sh

# This script is being used for two purposes: as part of an SMF
# start/stop/refresh method, and as a sysidconfig(1M)/sys-unconfig(1M)
# application.
#

case $1 in 
'start')
	/usr/bin/snort -d -D
	;;

*)
	echo "Usage: $0 { start | restart }"
	exit 1
	;;
esac	

exit $?

--Boundary_(ID_dxiQAeAeW3hDl3izni3ODA)
Content-type: text/xml; name=snort.xml
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=snort.xml

<?xml version="1.0"?>
<!DOCTYPE service_bundle SYSTEM "/usr/share/lib/xml/dtd/service_bundle.dtd.1">
<!--
	CDDL HEADER START

	The contents of this file are subject to the terms of the
	Common Development and Distribution License (the "License").
	You may not use this file except in compliance with the License.

	You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
	or http://www.opensolaris.org/os/licensing.
	See the License for the specific language governing permissions
	and limitations under the License.

	When distributing Covered Code, include this CDDL HEADER in each
	file and include the License file at usr/src/OPENSOLARIS.LICENSE.
	If applicable, add the following below this CDDL HEADER, with the
	fields enclosed by brackets "[]" replaced with your own identifying
	information: Portions Copyright [yyyy] [name of copyright owner]

	CDDL HEADER END

	Copyright 2009 Sun Microsystems, Inc.  All rights reserved.
	Use is subject to license terms.

	NOTE:  This service manifest is not editable; its contents will
	be overwritten by package or patch operations, including
	operating system upgrade.  Make customizations in a different
	file.
-->

<service_bundle type='manifest' name='SUNWsnortr:snort'>

<service
	name='network/snort'
	type='service'
	version='1'>

	<create_default_instance enabled='false' />

	<single_instance />

	<dependency name='fs-local'
		grouping='require_all'
		restart_on='none'
		type='service'>
		<service_fmri
			value='svc:/system/filesystem/local' />
	</dependency>

	<dependency name='fs-autofs'
		grouping='optional_all'
		restart_on='none'
		type='service'>
		<service_fmri value='svc:/system/filesystem/autofs' />
	</dependency>

	<dependency
                name='network'
                grouping='optional_all'
                restart_on='error'
                type='service'>
                <service_fmri value='svc:/milestone/network' />
        </dependency>

	<dependency name='net-loopback'
		grouping='require_all'
		restart_on='none'
		type='service'>
		<service_fmri value='svc:/network/loopback' />
	</dependency>

	<dependency name='net-physical'
		grouping='require_all'
		restart_on='none'
		type='service'>
		<service_fmri value='svc:/network/physical' />
	</dependency>

	<exec_method
		type='method'
		name='start'
		exec='/lib/svc/method/snortd start'
		timeout_seconds='60'/>

	<exec_method
		type='method'
		name='stop'
		exec=':kill'
		timeout_seconds='60' />

	<exec_method
		type='method'
		name='refresh'
		exec='/lib/svc/method/snortd restart'
		timeout_seconds='60' />

	<property_group name='startd'
		type='framework'>
		<!-- sub-process core dumps shouldn't restart session -->
		<propval name='ignore_error'
		    type='astring' value='core,signal' />
	</property_group>

        <property_group name='general' type='framework'>
                <!-- to start stop snortd -->
                <propval name='action_authorization' type='astring'
                        value='solaris.smf.manage.snort' />
        </property_group>

	<stability value='Unstable' />

	<template>
		<common_name>
			<loctext xml:lang='C'>
			Snort daemon 
			</loctext>
		</common_name>
		<documentation>
			<manpage title='snort' section='1M' manpath='/usr/share/man' />
		</documentation>
	</template>

</service>

</service_bundle>

--Boundary_(ID_dxiQAeAeW3hDl3izni3ODA)--

From carlsonj@phorcys.east.sun.com Mon May  4 04:20:59 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n44BKwO2015220
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 4 May 2009 04:20:59 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n44BKs9K012048
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Mon, 4 May 2009 12:20:58 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ400I03A6XJ800@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Mon, 04 May 2009 04:20:57 -0700 (PDT)
Received: from dm-east-01.east.sun.com ([129.148.9.192])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ400BL8A6WU070@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Mon,
 04 May 2009 04:20:56 -0700 (PDT)
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by dm-east-01.east.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n44BKqpb009361; Mon, 04 May 2009 07:20:52 -0400 (EDT)
Received: from phorcys.east.sun.com (phorcys.local [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n44BK7KX014124; Mon,
 04 May 2009 07:20:07 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n44BK7GL014121; Mon,
 04 May 2009 07:20:07 -0400 (EDT)
Date: Mon, 04 May 2009 07:20:07 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <49FEA00D.7030000@Sun.COM>
To: Jason Zhao <Jason.Zhao@sun.com>
Cc: James Walker <jw137282@sac.sfbay.sun.com>,
        Joep Vesseur <Joep.Vesseur@sun.com>, PSARC-ext@sun.com,
        Gary Winiger <gww@sac.sfbay.sun.com>
Message-id: <18942.53095.754877.627716@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200904280616.n3S6GoeE001145@sac.sfbay.sun.com>
 <49F6A626.7000601@Sun.COM> <200904280222.n3S2Mfbn001343@sac.sfbay.sun.com>
 <18935.1118.374789.911184@gargle.gargle.HOWL> <49FEA00D.7030000@Sun.COM>
Status: RO
Content-Length: 1954

Jason Zhao writes:
> Hi, James,
> > James Walker writes:
> >   
> >>     /usr/bin/64/snort                    Uncommitted	64-bit Command
> >>     
> >
> > What's this about?  What does the utility do that actually requires
> > 64-bit operation?  (Does it read from kernel memory directly?)
> >   
>  From functions points of view, there is no difference between 32-bit
> and 64-bit "snort" binaries. 64-bit snort is an optional choice when 
> building
> the binary. And if you really concern about it, I can remove 64-bit
> part. Please tell me your idea.

It's unclear to me why it's needed.  In general, getting 64-bit
versions of plugins sounds like a negative to me, as it forces
producers of those plugins to test twice.  Perhaps more importantly,
when developers choose not to include 64-bit binaries but include
32-bit only (as it's easier to do, and as we've seen with other 64-bit
objects), users will see (over time) that the 32-bit version of snort
is less capable than the 64-bit version.

So, why is it *required*?  Does something about snort work better that
way?  It seems like it shouldn't, and yet this project is forcing more
complexity into the user's hands, and it's unclear why that's a good
answer.

> > Is snort ordinarily used in daemon mode?  If so, shouldn't there be an
> > SMF configuration for it?  Otherwise, users are forced to roll their
> > own, and the project seems incomplete.
> >   
> I finished the SMF manifest in /var/svc/manifest/network/snort.xml;

It looks like the FMRI we were looking for will be:

	svc:/network/snort:default

That seems reasonable to me.  The rest of that material will need to
go through an actual code review.

I note that you're invoking the 32-bit version here.

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Jason.Zhao@sun.com Mon May  4 22:06:43 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n4556gGH001135
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 4 May 2009 22:06:42 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n4556gmt022522
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 4 May 2009 23:06:42 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ500105NJ69U00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Mon, 04 May 2009 22:06:42 -0700 (PDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ500B5XNJ5EL40@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Mon,
 04 May 2009 22:06:42 -0700 (PDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n4556eH2010332	for
 <PSARC-ext@Sun.COM>; Tue, 05 May 2009 05:06:40 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KJ500600NG7B800@mail-apac.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Tue, 05 May 2009 13:06:40 +0800 (SGT)
Received: from [129.158.218.22] ([unknown] [129.158.218.22])
 by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KJ500H64NIZVE40@mail-apac.sun.com>; Tue,
 05 May 2009 13:06:36 +0800 (SGT)
Date: Tue, 05 May 2009 13:07:26 +0800
From: Jason Zhao <Jason.Zhao@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <18942.53095.754877.627716@gargle.gargle.HOWL>
Sender: Jason.Zhao@sun.com
To: James Carlson <James.D.Carlson@sun.com>
Cc: James Walker <jw137282@sac.sfbay.sun.com>,
        Joep Vesseur <Joep.Vesseur@sun.com>, PSARC-ext@sun.com,
        Gary Winiger <gww@sac.sfbay.sun.com>
Message-id: <49FFC98E.9050507@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200904280616.n3S6GoeE001145@sac.sfbay.sun.com>
 <49F6A626.7000601@Sun.COM> <200904280222.n3S2Mfbn001343@sac.sfbay.sun.com>
 <18935.1118.374789.911184@gargle.gargle.HOWL> <49FEA00D.7030000@Sun.COM>
 <18942.53095.754877.627716@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 2440

Hi, James,
> Jason Zhao writes:
>   
>> Hi, James,
>>     
>>> James Walker writes:
>>>   
>>>       
>>>>     /usr/bin/64/snort                    Uncommitted	64-bit Command
>>>>     
>>>>         
>>> What's this about?  What does the utility do that actually requires
>>> 64-bit operation?  (Does it read from kernel memory directly?)
>>>   
>>>       
>>  From functions points of view, there is no difference between 32-bit
>> and 64-bit "snort" binaries. 64-bit snort is an optional choice when 
>> building
>> the binary. And if you really concern about it, I can remove 64-bit
>> part. Please tell me your idea.
>>     
>
> It's unclear to me why it's needed.  In general, getting 64-bit
> versions of plugins sounds like a negative to me, as it forces
> producers of those plugins to test twice.  Perhaps more importantly,
> when developers choose not to include 64-bit binaries but include
> 32-bit only (as it's easier to do, and as we've seen with other 64-bit
> objects), users will see (over time) that the 32-bit version of snort
> is less capable than the 64-bit version.
>
> So, why is it *required*?  Does something about snort work better that
> way?  It seems like it shouldn't, and yet this project is forcing more
> complexity into the user's hands, and it's unclear why that's a good
> answer.
>   
The developers of snort community suggested me that 64bit is
only optional. From function points of view, it will be OK as long
as the snort binary has been built same with plugins. Output data
types, such as unified2 and database, are logging pieces of data,
not specific data structures, so the utilities that read those don't
have to be built 64bit.

OK, I will remove the 64bit binaries and its related plugins. Then
I will send for code review first.
>   
>>> Is snort ordinarily used in daemon mode?  If so, shouldn't there be an
>>> SMF configuration for it?  Otherwise, users are forced to roll their
>>> own, and the project seems incomplete.
>>>   
>>>       
>> I finished the SMF manifest in /var/svc/manifest/network/snort.xml;
>>     
>
> It looks like the FMRI we were looking for will be:
>
> 	svc:/network/snort:default
>   
Yes, correct FMRI.
> That seems reasonable to me.  The rest of that material will need to
> go through an actual code review.
>   
I will send it for code review ASAP.
> I note that you're invoking the 32-bit version here.
>
>   
Yes, of course.

Thank you very much!

Jason


From gww@sac.sfbay.sun.com Tue May  5 15:06:51 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n45M6p1J013370
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 5 May 2009 15:06:51 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n45M6pL8003642
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 5 May 2009 15:06:51 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ600607YRFRC00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 05 May 2009 16:06:51 -0600 (MDT)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ600MIAYREWF50@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 05 May 2009 16:06:50 -0600 (MDT)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n45M6lsW060256; Tue, 05 May 2009 15:06:47 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n45M6lDU013365; Tue,
 05 May 2009 15:06:47 -0700 (PDT)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id n45M6lvM013364; Tue, 05 May 2009 15:06:47 -0700 (PDT)
Date: Tue, 05 May 2009 15:06:47 -0700 (PDT)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
To: Jason.Zhao@sun.com, gww@eng.sun.com
Cc: James.D.Carlson@sun.com, Joep.Vesseur@sun.com, PSARC-ext@sun.com,
        gww@sac.sfbay.sun.com, jw137282@sac.sfbay.sun.com
Message-id: <200905052206.n45M6lvM013364@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1262

> Hi, Gary,
> >>> Snort does far more than just read files.  It links to libpcap and can
> >>> snoop on network interfaces in real time.  To do *that*, it will
> >>> require elevated privileges.
> >>>   
> >>>       
> >> Right.
> >>     
> >
> > 	What are those elevated privileges.
> >   
> For "privileges", I think you mean the auths of RBAC.

	No, I mean privileges(5).  If it is a service then it also
	requires authorizations that follow the policy:
	http://opensolaris.org/os/community/arc/policies/SMF-policy/

	And a further question if run as a service is what is the
	method context?

> > 	What will be delivered into what Rights Profile?
> >   
> It is very similiar to "wireshark" which has been delivered, since
> both of the utilities take advantage of libpcap to read data and handle
> them after set NIC to raw mode. For snort, it doesn't read data directly
> from kernel memory, raw I/O from NIC is the way it works.
> 
> And I believe "Network Management" profile is enough.
> 
> The project will deliver SUNWsnortr and SUNWsnortu. On SUNWsnortr,
> it will deliver profiles in /etc/security/exec_attr (added snort):
> 
> Network Management:solaris:cmd:::/usr/bin/snort:privs=net_rawaccess

	Why isn't net_observibility be sufficient?

Gary..

From gww@sac.sfbay.sun.com Tue May  5 15:10:39 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n45MAck4013436
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 5 May 2009 15:10:39 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n45MAXSn027587
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 6 May 2009 06:10:37 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ60070BYXJ4Q00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 05 May 2009 16:10:31 -0600 (MDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ600M4QYXIWD60@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 05 May 2009 16:10:31 -0600 (MDT)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n45MAR8U011330; Tue, 05 May 2009 15:10:27 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n45MAQ3o013434; Tue,
 05 May 2009 15:10:26 -0700 (PDT)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id n45MAPdO013430; Tue, 05 May 2009 15:10:25 -0700 (PDT)
Date: Tue, 05 May 2009 15:10:25 -0700 (PDT)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
To: James.D.Carlson@sun.com, Jason.Zhao@sun.com
Cc: Joep.Vesseur@sun.com, PSARC-ext@sun.com, gww@sac.sfbay.sun.com,
        jw137282@sac.sfbay.sun.com
Message-id: <200905052210.n45MAPdO013430@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 403

>         <property_group name='general' type='framework'>
>                 <!-- to start stop snortd -->
>                 <propval name='action_authorization' type='astring'
>                         value='solaris.smf.manage.snort' />
>         </property_group>

	Don't you also want a value authorization?  See the SMF policy:
	http://opensolaris.org/os/community/arc/policies/SMF-policy/

Gary..

From Jason.Zhao@sun.com Tue May  5 23:54:38 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n466sa4r016549
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 5 May 2009 23:54:37 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n466sX4X005672
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 6 May 2009 14:54:35 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ700E0HN6U8G00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 05 May 2009 23:54:30 -0700 (PDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ7000DWN6S8KF0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 05 May 2009 23:54:29 -0700 (PDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n466sSYW004040	for
 <PSARC-ext@sun.com>; Wed, 06 May 2009 06:54:28 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KJ700J00MZKI200@mail-apac.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 06 May 2009 14:54:28 +0800 (SGT)
Received: from [129.158.218.22] ([unknown] [129.158.218.22])
 by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KJ7004A3N6ORLJ0@mail-apac.sun.com>; Wed,
 06 May 2009 14:54:25 +0800 (SGT)
Date: Wed, 06 May 2009 14:55:15 +0800
From: Jason Zhao <Jason.Zhao@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <200905052206.n45M6lvM013364@sac.sfbay.sun.com>
Sender: Jason.Zhao@sun.com
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: gww@eng.sun.com, James.D.Carlson@sun.com, Joep.Vesseur@sun.com,
        PSARC-ext@sun.com, jw137282@sac.sfbay.sun.com
Message-id: <4A013453.8060807@Sun.COM>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_V67c4YCGDVeWaPb6e9Q36g)"
X-PMX-Version: 5.4.1.325704
References: <200905052206.n45M6lvM013364@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 8414

This is a multi-part message in MIME format.

--Boundary_(ID_V67c4YCGDVeWaPb6e9Q36g)
Content-type: text/plain; charset=GB2312
Content-transfer-encoding: 7BIT

Hi, Gary,
>> Hi, Gary,
>>     
>>>>> Snort does far more than just read files.  It links to libpcap and can
>>>>> snoop on network interfaces in real time.  To do *that*, it will
>>>>> require elevated privileges.
>>>>>   
>>>>>       
>>>>>           
>>>> Right.
>>>>     
>>>>         
>>> 	What are those elevated privileges.
>>>   
>>>       
>> For "privileges", I think you mean the auths of RBAC.
>>     
>
> 	No, I mean privileges(5).  If it is a service then it also
> 	requires authorizations that follow the policy:
> 	http://opensolaris.org/os/community/arc/policies/SMF-policy/
>
> 	And a further question if run as a service is what is the
> 	method context?
>
>   
1. For privileges(5), PRIV_NET_RAWACCESS is least required since snort
depends on
libpcap which sets NIC to RAW mode in order to monitor the flow of the box.
And the "Network Management" profile is necessary. From definition of
"net_observability"
in priv_names in /etc/security, it says
#################################################
net_observability
Allows a process to access /dev/lo0 and the devices in /dev/ipnet/
while not requiring them to need PRIV_NET_RAWACCESS.
#################################################

But libpcap needs to set NIC to raw, so I think net_rawaccess is
required, not net_observability.
One note however: snort only read data packets from libpcap, and it
doesn't try to encapsulate
an IP/TCP/UDP/* packet to send because libpcap doesn't support it.


2. About the method context, I think user "root" and group "root" is
necessary. As following, please:
##################################################
<exec_method
type='method'
name='start'
exec='/lib/svc/method/snortd start'
timeout_seconds='60'>
<method_context>
<method_credential user='root' group='root' />
</method_context>
</exec_method>

<exec_method
type='method'
name='stop'
exec=':kill -9'
timeout_seconds='3'>
<method_context>
<method_credential user='root' group='root' />
</method_context>
</exec_method>
##################################################
>>> 	What will be delivered into what Rights Profile?
>>>   
>>>       
>> It is very similiar to "wireshark" which has been delivered, since
>> both of the utilities take advantage of libpcap to read data and handle
>> them after set NIC to raw mode. For snort, it doesn't read data directly
>> from kernel memory, raw I/O from NIC is the way it works.
>>
>> And I believe "Network Management" profile is enough.
>>
>> The project will deliver SUNWsnortr and SUNWsnortu. On SUNWsnortr,
>> it will deliver profiles in /etc/security/exec_attr (added snort):
>>
>> Network Management:solaris:cmd:::/usr/bin/snort:privs=net_rawaccess
>>     
>
> 	Why isn't net_observibility be sufficient?
>   
Please see above section about the reason and tell me if I misunderstand it.
Thank you in advance.
> >        <property_group name='general' type='framework'>
> >                <!-- to start stop snortd -->
> >                <propval name='action_authorization' type='astring'
> >                        value='solaris.smf.manage.snort' />
> >        </property_group>
>   

>	Don't you also want a value authorization?  See the SMF policy:
>	http://opensolaris.org/os/community/arc/policies/SMF-policy/


Sorry I was not quite familiar with the SMF, and in my understanding
about the SMF-policy after reading, it should be like following:

##################################################
<property_group name='general' type='framework'>
<propval name='action_authorization' type='astring'
value='solaris.smf.manage.snort' />
<propval name='value_authorization' type='astring'
value='solaris.smf.manage.snort' />
</property_group>
##################################################

In this way, auth_attr should be inserted one item:
##################################################
solaris.smf.manage.snort:::Manage Snort Service
States::help=ManageSnort.html
##################################################

In exec_attr, 1 item should be added.
The related exec_attr, auth_attr, snort.xml are in attachment.
##################################################
Network Management:solaris:cmd:::/usr/bin/snort:privs=net_rawaccess
##################################################

The snort.xml has been modified according to the above questions in
attachment.

Great Thanks
Jason

--Boundary_(ID_V67c4YCGDVeWaPb6e9Q36g)
Content-type: text/xml; name=snort.xml
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=snort.xml

<?xml version="1.0"?>
<!DOCTYPE service_bundle SYSTEM "/usr/share/lib/xml/dtd/service_bundle.dtd.1">
<!--
	CDDL HEADER START

	The contents of this file are subject to the terms of the
	Common Development and Distribution License (the "License").
	You may not use this file except in compliance with the License.

	You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
	or http://www.opensolaris.org/os/licensing.
	See the License for the specific language governing permissions
	and limitations under the License.

	When distributing Covered Code, include this CDDL HEADER in each
	file and include the License file at usr/src/OPENSOLARIS.LICENSE.
	If applicable, add the following below this CDDL HEADER, with the
	fields enclosed by brackets "[]" replaced with your own identifying
	information: Portions Copyright [yyyy] [name of copyright owner]

	CDDL HEADER END

	Copyright 2009 Sun Microsystems, Inc.  All rights reserved.
	Use is subject to license terms.

	NOTE:  This service manifest is not editable; its contents will
	be overwritten by package or patch operations, including
	operating system upgrade.  Make customizations in a different
	file.
-->

<service_bundle type='manifest' name='SUNWsnortr:snort'>

<service
	name='network/snort'
	type='service'
	version='1'>

	<create_default_instance enabled='false' />

	<single_instance />

	<dependency name='fs-local'
		grouping='require_all'
		restart_on='none'
		type='service'>
		<service_fmri
			value='svc:/system/filesystem/local' />
	</dependency>

	<dependency name='fs-autofs'
		grouping='optional_all'
		restart_on='none'
		type='service'>
		<service_fmri value='svc:/system/filesystem/autofs' />
	</dependency>

	<dependency
                name='network'
                grouping='optional_all'
                restart_on='error'
                type='service'>
                <service_fmri value='svc:/milestone/network' />
        </dependency>

	<dependency name='net-loopback'
		grouping='require_all'
		restart_on='none'
		type='service'>
		<service_fmri value='svc:/network/loopback' />
	</dependency>

	<dependency name='net-physical'
		grouping='require_all'
		restart_on='none'
		type='service'>
		<service_fmri value='svc:/network/physical' />
	</dependency>

	<exec_method
		type='method'
		name='start'
		exec='/lib/svc/method/snortd start'
		timeout_seconds='60'>
		<method_context>
                        <method_credential user='root' group='root' />
                </method_context>
	</exec_method>

	<exec_method
		type='method'
		name='stop'
		exec=':kill -9'
		timeout_seconds='60' />
		<method_context>
                        <method_credential user='root' group='root' />
                </method_context>
	</exec_method>

	<exec_method
		type='method'
		name='refresh'
		exec='/lib/svc/method/snortd restart'
		timeout_seconds='60' />

	<property_group name='startd'
		type='framework'>
		<!-- sub-process core dumps shouldn't restart session -->
		<propval name='ignore_error'
		    type='astring' value='core,signal' />
	</property_group>

        <property_group name='general' type='framework'>
                <!-- to start stop snortd -->
                <propval name='action_authorization' type='astring'
                        value='solaris.smf.manage.snort' />
                <propval name='value_authorization' type='astring'
                        value='solaris.smf.manage.snort' />
        </property_group>

	<stability value='Unstable' />

	<template>
		<common_name>
			<loctext xml:lang='C'>
			Snort daemon 
			</loctext>
		</common_name>
		<documentation>
			<manpage title='snort' section='1M' manpath='/usr/share/man' />
		</documentation>
	</template>

</service>

</service_bundle>

--Boundary_(ID_V67c4YCGDVeWaPb6e9Q36g)--

From James.Walker@sun.com Wed May  6 11:25:57 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n46IPvTO028876
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 May 2009 11:25:57 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n46IPueG019977
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 6 May 2009 11:25:56 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ800B09J78K700@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Wed, 06 May 2009 11:25:56 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ800E9WJ77ZVF0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Wed,
 06 May 2009 11:25:56 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n46IPtom013771	for
 <PSARC-ext@Sun.COM>; Wed, 06 May 2009 18:25:55 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KJ800300IHKZ400@mail-amer.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Wed, 06 May 2009 12:25:55 -0600 (MDT)
Received: from [172.20.25.153] ([unknown] [172.20.25.153])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7.0-5.01 64bit
 (built Feb 19 2009)) with ESMTPSA id <0KJ8005AGJ72WDD0@mail-amer.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Wed,
 06 May 2009 12:25:50 -0600 (MDT)
Date: Wed, 06 May 2009 12:35:33 -0600
From: Jim Walker <James.Walker@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <49FE9634.2050701@Sun.COM>
Sender: James.Walker@sun.com
To: PSARC-ext@sun.com
Cc: Jason Zhao <Jason.Zhao@sun.com>
Reply-to: James.Walker@sun.com
Message-id: <4A01D875.3060402@sun.com>
Organization: Sun Microsystems, Inc.
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200904291510.n3TFADTW013744@marduk.eng.sun.com>
 <49FE9634.2050701@Sun.COM>
User-Agent: Thunderbird 2.0.0.14 (X11/20080728)
Status: RO
Content-Length: 65

I'm extending the timeout on this case to 5/8/2009.

Cheers,
Jim

From gww@sac.sfbay.sun.com Wed May  6 13:23:24 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n46KNMJq000011
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 May 2009 13:23:22 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n46KNAFJ026748
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 7 May 2009 04:23:21 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ800D03OMWQE00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 06 May 2009 13:23:20 -0700 (PDT)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ800DE6OMWI600@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 06 May 2009 13:23:20 -0700 (PDT)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n46KNFXW018775; Wed, 06 May 2009 13:23:15 -0700 (PDT)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n46KNEld000008; Wed,
 06 May 2009 13:23:14 -0700 (PDT)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id n46KNDU4000006; Wed, 06 May 2009 13:23:13 -0700 (PDT)
Date: Wed, 06 May 2009 13:23:13 -0700 (PDT)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
To: Jason.Zhao@sun.com, gww@sac.sfbay.sun.com
Cc: James.D.Carlson@sun.com, Joep.Vesseur@sun.com, PSARC-ext@sun.com,
        Sebastien.Roy@sun.com, gww@eng.sun.com, jw137282@sac.sfbay.sun.com
Message-id: <200905062023.n46KNDU4000006@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 3221

	Explicitly copied Seb since he was case owner for libpcap.

> 1. For privileges(5), PRIV_NET_RAWACCESS is least required since snort
> depends on
> libpcap which sets NIC to RAW mode in order to monitor the flow of the box.
> And the "Network Management" profile is necessary. From definition of
> "net_observability"
> in priv_names in /etc/security, it says
> #################################################
> net_observability
> Allows a process to access /dev/lo0 and the devices in /dev/ipnet/
> while not requiring them to need PRIV_NET_RAWACCESS.
> #################################################
> 
> But libpcap needs to set NIC to raw, so I think net_rawaccess is
> required, not net_observability.
> One note however: snort only read data packets from libpcap, and it
> doesn't try to encapsulate
> an IP/TCP/UDP/* packet to send because libpcap doesn't support it.

	Not to belabor things here:  Should libpcap be fixed so that
	it only needs net_observibility when reading packets?

> 2. About the method context, I think user "root" and group "root" is
> necessary. As following, please:
	
	Why is that?  Why isn't noaccess:noaccess,
	privileges=net_raw_access (or net_observibility -- base on Seb's
	reply) sufficient?

	P.S.  I don't see a reason for your stop method to have a method
	context.  It appears to only be doing a :kill.

> >> Network Management:solaris:cmd:::/usr/bin/snort:privs=net_rawaccess
> >>     
> >
> > 	Why isn't net_observibility be sufficient?
> >   
> Please see above section about the reason and tell me if I misunderstand it.
> Thank you in advance.

	OK and see my reply.

> > >        <property_group name='general' type='framework'>
> > >                <!-- to start stop snortd -->
> > >                <propval name='action_authorization' type='astring'
> > >                        value='solaris.smf.manage.snort' />
> > >        </property_group>
> >   
> 
> >	Don't you also want a value authorization?  See the SMF policy:
> >	http://opensolaris.org/os/community/arc/policies/SMF-policy/
> 
> 
> Sorry I was not quite familiar with the SMF, and in my understanding
> about the SMF-policy after reading, it should be like following:

	Thus the policy.  Project teams are responsible for following
	applicable policies -;)

> ##################################################
> <property_group name='general' type='framework'>
> <propval name='action_authorization' type='astring'
> value='solaris.smf.manage.snort' />
> <propval name='value_authorization' type='astring'
> value='solaris.smf.manage.snort' />
> </property_group>
> ##################################################
> 
> In this way, auth_attr should be inserted one item:
> ##################################################
> solaris.smf.manage.snort:::Manage Snort Service
> States::help=ManageSnort.html
> ##################################################
> 
> In exec_attr, 1 item should be added.
> The related exec_attr, auth_attr, snort.xml are in attachment.
> ##################################################
> Network Management:solaris:cmd:::/usr/bin/snort:privs=net_rawaccess
> ##################################################

	Seem fine modulo the libpcap question.

Gary..

From Sebastien.Roy@sun.com Wed May  6 13:33:51 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n46KXo0K000177
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 May 2009 13:33:50 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n46KXe8D001970
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 7 May 2009 04:33:49 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ800301P49WB00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 06 May 2009 13:33:45 -0700 (PDT)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ800K4WP48EM40@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 06 May 2009 13:33:44 -0700 (PDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n46KXivQ013104	for
 <PSARC-ext@sun.com>; Wed, 06 May 2009 20:33:44 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KJ800000NUA2T00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 06 May 2009 14:33:44 -0600 (MDT)
Received: from [192.168.1.4] ([unknown] [173.76.18.185])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7.0-5.01 64bit
 (built Feb 19 2009)) with ESMTPSA id <0KJ8001BEP41JPD0@mail-amer.sun.com>; Wed,
 06 May 2009 14:33:38 -0600 (MDT)
Date: Wed, 06 May 2009 16:33:36 -0400
From: Sebastien Roy <Sebastien.Roy@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <200905062023.n46KNDU4000006@sac.sfbay.sun.com>
Sender: Sebastien.Roy@sun.com
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: Jason.Zhao@sun.com, James.D.Carlson@sun.com, Joep.Vesseur@sun.com,
        PSARC-ext@sun.com, gww@eng.sun.com, jw137282@sac.sfbay.sun.com
Message-id: <1241642016.14793.4.camel@seb>
Organization: Sun Microsystems
MIME-version: 1.0
X-Mailer: Evolution 2.24.2
Content-type: text/plain; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905062023.n46KNDU4000006@sac.sfbay.sun.com>
Status: RO
Content-Length: 1581


On Wed, 2009-05-06 at 13:23 -0700, Gary Winiger wrote:
> 	Explicitly copied Seb since he was case owner for libpcap.
> 
> > 1. For privileges(5), PRIV_NET_RAWACCESS is least required since snort
> > depends on
> > libpcap which sets NIC to RAW mode in order to monitor the flow of the box.
> > And the "Network Management" profile is necessary. From definition of
> > "net_observability"
> > in priv_names in /etc/security, it says
> > #################################################
> > net_observability
> > Allows a process to access /dev/lo0 and the devices in /dev/ipnet/
> > while not requiring them to need PRIV_NET_RAWACCESS.
> > #################################################
> > 
> > But libpcap needs to set NIC to raw, so I think net_rawaccess is
> > required, not net_observability.
> > One note however: snort only read data packets from libpcap, and it
> > doesn't try to encapsulate
> > an IP/TCP/UDP/* packet to send because libpcap doesn't support it.
> 
> 	Not to belabor things here:  Should libpcap be fixed so that
> 	it only needs net_observibility when reading packets?

Yes, and this is exactly why I suggested that /dev/bpf only require
net_observability for reading packets as part of the review for
2009/232.  If that happens, modifying libpcap to use /dev/bpf instead of
DLPI would result in all libpcap consumers only needing
net_observability.  That isn't this case, though, it's the BPF case.

As it stands today, because libpcap uses DLPI, consumers of libpcap need
net_rawaccess (it's what's required to interact with DLPI devices).

-Seb



From gww@eng.sun.com Wed May  6 14:42:25 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n46LgOuF001826
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 May 2009 14:42:24 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n46LgMl6018741
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 6 May 2009 14:42:24 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ800D0NSANZH00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 06 May 2009 15:42:23 -0600 (MDT)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ800JMHSAMD3C0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 06 May 2009 15:42:22 -0600 (MDT)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n46LgIdn007509; Wed, 06 May 2009 14:42:18 -0700 (PDT)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n46LfMoJ021148; Wed,
 06 May 2009 14:41:22 -0700 (PDT)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n46LfMGd021147; Wed,
 06 May 2009 14:41:22 -0700 (PDT)
Date: Wed, 06 May 2009 14:41:22 -0700 (PDT)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
To: gww@sac.sfbay.sun.com, Sebastien.Roy@sun.com
Cc: Jason.Zhao@sun.com, James.D.Carlson@sun.com, Joep.Vesseur@sun.com,
        PSARC-ext@sun.com, gww@eng.sun.com, jw137282@sac.sfbay.sun.com
Message-id: <200905062141.n46LfMGd021147@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 749

Seb,

> On Wed, 2009-05-06 at 13:23 -0700, Gary Winiger wrote:
> > 	Explicitly copied Seb since he was case owner for libpcap.

> Yes, and this is exactly why I suggested that /dev/bpf only require
> net_observability for reading packets as part of the review for
> 2009/232.  If that happens, modifying libpcap to use /dev/bpf instead of
> DLPI would result in all libpcap consumers only needing
> net_observability.  That isn't this case, though, it's the BPF case.
> 
> As it stands today, because libpcap uses DLPI, consumers of libpcap need
> net_rawaccess (it's what's required to interact with DLPI devices).

	If you're happy with that perhaps you want to give it a +1.
	My other comments were architecturally closer to code review.

Gary..

From Sebastien.Roy@sun.com Wed May  6 15:24:59 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n46MOwHc003371
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 May 2009 15:24:58 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n46MOwmV007211
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 6 May 2009 15:24:58 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJ800I0DU9MDC00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 06 May 2009 16:24:58 -0600 (MDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJ800HQKU9M8600@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 06 May 2009 16:24:58 -0600 (MDT)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n46MOvHg009442	for
 <psarc-ext@sun.com>; Wed, 06 May 2009 22:24:57 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KJ800700TXLRX00@mail-amer.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 06 May 2009 16:24:57 -0600 (MDT)
Received: from [192.168.1.4] ([unknown] [173.76.18.185])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7.0-5.01 64bit
 (built Feb 19 2009)) with ESMTPSA id <0KJ8000T7U9FV9A0@mail-amer.sun.com>; Wed,
 06 May 2009 16:24:53 -0600 (MDT)
Date: Wed, 06 May 2009 18:24:51 -0400
From: Sebastien Roy <Sebastien.Roy@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <200905062141.n46LfMGd021147@marduk.eng.sun.com>
Sender: Sebastien.Roy@sun.com
To: Gary Winiger <gww@eng.sun.com>
Cc: gww@sac.sfbay.sun.com, Jason.Zhao@sun.com, James.D.Carlson@sun.com,
        Joep.Vesseur@sun.com, psarc-ext@sun.com, jw137282@sac.sfbay.sun.com
Message-id: <1241648691.14793.7.camel@seb>
Organization: Sun Microsystems
MIME-version: 1.0
X-Mailer: Evolution 2.24.2
Content-type: text/plain; charset=UTF-8
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905062141.n46LfMGd021147@marduk.eng.sun.com>
Status: RO
Content-Length: 208

On Wed, 2009-05-06 at 14:41 -0700, Gary Winiger wrote:
> 	If you're happy with that perhaps you want to give it a +1.
> 	My other comments were architecturally closer to code review.

Yes, +1 from me.
-Seb



From Jason.Zhao@sun.com Thu May  7 09:54:48 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n47Gskf5011769
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 7 May 2009 09:54:46 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n47GsYUC007511
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 8 May 2009 00:54:45 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJA00I0J9N74P00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Thu, 07 May 2009 09:54:43 -0700 (PDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJA00DAA9N6EQ80@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Thu,
 07 May 2009 09:54:43 -0700 (PDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n47GsfMq022273	for
 <PSARC-ext@sun.com>; Thu, 07 May 2009 16:54:41 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KJA00K009AZUT00@mail-apac.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 08 May 2009 00:54:41 +0800 (SGT)
Received: from [192.168.0.100] ([unknown] [114.245.136.161])
 by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KJA006PF9MYE800@mail-apac.sun.com>; Fri,
 08 May 2009 00:54:41 +0800 (SGT)
Date: Fri, 08 May 2009 00:54:38 +0800
From: Jason Zhao <Jason.Zhao@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <200905062023.n46KNDU4000006@sac.sfbay.sun.com>
Sender: Jason.Zhao@sun.com
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: James.D.Carlson@sun.com, Joep.Vesseur@sun.com, PSARC-ext@sun.com,
        Sebastien.Roy@sun.com, gww@eng.sun.com, jw137282@sac.sfbay.sun.com
Message-id: <4A03124E.80909@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=GB2312
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905062023.n46KNDU4000006@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20090211)
Status: RO
Content-Length: 3475


> 	Explicitly copied Seb since he was case owner for libpcap.
>
>   
>> 1. For privileges(5), PRIV_NET_RAWACCESS is least required since snort
>> depends on
>> libpcap which sets NIC to RAW mode in order to monitor the flow of the box.
>> And the "Network Management" profile is necessary. From definition of
>> "net_observability"
>> in priv_names in /etc/security, it says
>> #################################################
>> net_observability
>> Allows a process to access /dev/lo0 and the devices in /dev/ipnet/
>> while not requiring them to need PRIV_NET_RAWACCESS.
>> #################################################
>>
>> But libpcap needs to set NIC to raw, so I think net_rawaccess is
>> required, not net_observability.
>> One note however: snort only read data packets from libpcap, and it
>> doesn't try to encapsulate
>> an IP/TCP/UDP/* packet to send because libpcap doesn't support it.
>>     
>
> 	Not to belabor things here:  Should libpcap be fixed so that
> 	it only needs net_observibility when reading packets?
>   
Thanks Seb for his answer.
>   
>> 2. About the method context, I think user "root" and group "root" is
>> necessary. As following, please:
>>     
> 	
> 	Why is that?  Why isn't noaccess:noaccess,
> 	privileges=net_raw_access (or net_observibility -- base on Seb's
> 	reply) sufficient?
>   
It fully depends on the device operation from libpcap
(open NIC device and set it to promisc mode). I am trying
it with noaccess:noaccess after give it certain auths.
> 	P.S.  I don't see a reason for your stop method to have a method
> 	context.  It appears to only be doing a :kill.
>   
Thanks, I will remove it.
>   
>>>> Network Management:solaris:cmd:::/usr/bin/snort:privs=net_rawaccess
>>>>         
>>>>        <property_group name='general' type='framework'>
>>>>                <!-- to start stop snortd -->
>>>>                <propval name='action_authorization' type='astring'
>>>>                        value='solaris.smf.manage.snort' />
>>>>        </property_group>
>>>>         
>>>   
>>>       
>>> 	Don't you also want a value authorization?  See the SMF policy:
>>> 	http://opensolaris.org/os/community/arc/policies/SMF-policy/
>>>       
>> Sorry I was not quite familiar with the SMF, and in my understanding
>> about the SMF-policy after reading, it should be like following:
>>     
>
> 	Thus the policy.  Project teams are responsible for following
> 	applicable policies -;)
>   
Thanks.
>   
>> ##################################################
>> <property_group name='general' type='framework'>
>> <propval name='action_authorization' type='astring'
>> value='solaris.smf.manage.snort' />
>> <propval name='value_authorization' type='astring'
>> value='solaris.smf.manage.snort' />
>> </property_group>
>> ##################################################
>>
>> In this way, auth_attr should be inserted one item:
>> ##################################################
>> solaris.smf.manage.snort:::Manage Snort Service
>> States::help=ManageSnort.html
>> ##################################################
>>
>> In exec_attr, 1 item should be added.
>> The related exec_attr, auth_attr, snort.xml are in attachment.
>> ##################################################
>> Network Management:solaris:cmd:::/usr/bin/snort:privs=net_rawaccess
>> ##################################################
>>     
>
> 	Seem fine modulo the libpcap question.
>   
Thank you very much for your help. :)

Thanks
Jason

From Jason.Zhao@sun.com Thu May  7 23:42:31 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n486gVTm018397
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 7 May 2009 23:42:31 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n486gQ1o021733
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 7 May 2009 23:42:30 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJB00C03BYUNL00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 08 May 2009 00:42:30 -0600 (MDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJB00HDXBYSH8C0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 08 May 2009 00:42:29 -0600 (MDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n486gS2q024168	for
 <PSARC-ext@sun.com>; Fri, 08 May 2009 06:42:28 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KJB00100BXOGA00@mail-apac.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 08 May 2009 14:42:28 +0800 (SGT)
Received: from [129.158.218.22] ([unknown] [129.158.218.22])
 by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KJB00BJDBYQCO20@mail-apac.sun.com>; Fri,
 08 May 2009 14:42:28 +0800 (SGT)
Date: Fri, 08 May 2009 14:43:18 +0800
From: Jason Zhao <Jason.Zhao@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <200905062023.n46KNDU4000006@sac.sfbay.sun.com>
Sender: Jason.Zhao@sun.com
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: James.D.Carlson@sun.com, Joep.Vesseur@sun.com, PSARC-ext@sun.com,
        Sebastien.Roy@sun.com, gww@eng.sun.com, jw137282@sac.sfbay.sun.com
Message-id: <4A03D486.1040908@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=GB2312
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200905062023.n46KNDU4000006@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 2076


> 	Explicitly copied Seb since he was case owner for libpcap.
>
>   
>> 1. For privileges(5), PRIV_NET_RAWACCESS is least required since snort
>> depends on
>> libpcap which sets NIC to RAW mode in order to monitor the flow of the box.
>> And the "Network Management" profile is necessary. From definition of
>> "net_observability"
>> in priv_names in /etc/security, it says
>> #################################################
>> net_observability
>> Allows a process to access /dev/lo0 and the devices in /dev/ipnet/
>> while not requiring them to need PRIV_NET_RAWACCESS.
>> #################################################
>>
>> But libpcap needs to set NIC to raw, so I think net_rawaccess is
>> required, not net_observability.
>> One note however: snort only read data packets from libpcap, and it
>> doesn't try to encapsulate
>> an IP/TCP/UDP/* packet to send because libpcap doesn't support it.
>>     
>
> 	Not to belabor things here:  Should libpcap be fixed so that
> 	it only needs net_observibility when reading packets?
>
>   
>> 2. About the method context, I think user "root" and group "root" is
>> necessary. As following, please:
>>     
> 	
> 	Why is that?  Why isn't noaccess:noaccess,
> 	privileges=net_raw_access (or net_observibility -- base on Seb's
> 	reply) sufficient?
>   
Yes, noaccess:noaccess method_context could work. But it needs another
privileges (basic), I think it is because of trying to write log.
So after this, the snort.xml start method is as following:
####################################
<exec_method
type='method'
name='start'
exec='/lib/svc/method/snortd start'
timeout_seconds='60'>
<method_context>
<method_credential
user='noaccess'
group='noaccess'
privileges='basic,net_rawaccess' />
</method_context>
</exec_method>
####################################
[root@beigai:/etc]# svccfg import /var/svc/manifest/network/snort.xml

[root@beigai:/etc]# svcadm disable snort
[root@beigai:/etc]# svcadm enable snort

[root@beigai:/etc]# ps -ef | grep snort
noaccess 28653 1 0 14:31:05 ? 0:00 /usr/bin/snort -d -D


Thanks
Jason

From James.Walker@sun.com Fri May  8 15:30:17 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n48MUGho024633
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 8 May 2009 15:30:16 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n48MUEbw007617
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 8 May 2009 23:30:15 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KJC00721JUETA00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Fri, 08 May 2009 15:30:14 -0700 (PDT)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KJC007TCJUDUBA0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Fri,
 08 May 2009 15:30:13 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n48MUDcV010254	for
 <PSARC-ext@Sun.COM>; Fri, 08 May 2009 22:30:13 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KJC00M00JLQDP00@mail-amer.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Fri, 08 May 2009 16:30:13 -0600 (MDT)
Received: from [172.20.25.153] ([unknown] [172.20.25.153])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7.0-5.01 64bit
 (built Feb 19 2009)) with ESMTPSA id <0KJC00GRNJU3FT90@mail-amer.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Fri,
 08 May 2009 16:30:03 -0600 (MDT)
Date: Fri, 08 May 2009 16:40:01 -0600
From: Jim Walker <James.Walker@sun.com>
Subject: Re: snort [PSARC/2009/256 FastTrack timeout 05/04/2009]
In-reply-to: <49FE9634.2050701@Sun.COM>
Sender: James.Walker@sun.com
To: PSARC-ext@sun.com
Cc: Jason Zhao <Jason.Zhao@sun.com>
Reply-to: James.Walker@sun.com
Message-id: <4A04B4C1.7000301@sun.com>
Organization: Sun Microsystems, Inc.
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200904291510.n3TFADTW013744@marduk.eng.sun.com>
 <49FE9634.2050701@Sun.COM>
User-Agent: Thunderbird 2.0.0.14 (X11/20080728)
Status: RO
Content-Length: 247

This case has come to resolution and the timeout extension of
05/08/2009 has been reached, and it has received a +1.
I'm marking it closed approved.

Cheers,
Jim

-- 
Jim Walker, http://blogs.sun.com/jwalker
Sun Microsystems, Broomfield, Colorado

