From casper@sac.sfbay.sun.com Tue Dec 22 06:26:24 2009
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBMEQOJn020285
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 22 Dec 2009 06:26:24 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBMEQKcd002459;
	Tue, 22 Dec 2009 08:26:23 -0600 (CST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV200G075FZ5O00@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 22 Dec 2009 06:26:23 -0800 (PST)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV200AEL5FYRA20@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 22 Dec 2009 06:26:22 -0800 (PST)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBMEQMPr011228; Tue, 22 Dec 2009 06:26:22 -0800 (PST)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBMEQLd5020269; Tue,
 22 Dec 2009 06:26:21 -0800 (PST)
Received: (from casper@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id nBMEQLYD020265; Tue,
 22 Dec 2009 06:26:21 -0800 (PST)
Date: Tue, 22 Dec 2009 06:26:21 -0800 (PST)
From: Casper Dik <casper@sac.sfbay.sun.com>
Subject: Basic Network Privilege [PSARC/2009/685 FastTrack timeout 01/01/2010]
To: PSARC-ext@sun.com
Message-id: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1835


Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 Basic Network Privilege
    1.2. Name of Document Author/Supplier:
	 Author:  Casper Dik
    1.3  Date of This Document:
	22 December, 2009
4. Technical Description
I'm sponsoring this fasttrack for myself.

This project proposes one new "basic" privilege.

NET_ACCESS
	Allows a process to open a network connection.

The purpose of this privilege is the ability to create a process
confined to the current system.

The NET_ACCESS basic privilege is required for opening any IP endpoint
(socket(), t_open()) except those which already require a different
privilege, e.g., raw sockets.

Note: a "basic" privilege is a privilege which is part of the
default I, P and E privilege set.  Basic privileges should never be
removed from I, P and E unless it is known that the specific privilege
is not used in the application.

Requested binding: patch/minor


There is no need to update the socket(3*) and t_open(3nsl) manual pages
as both calls already cater for a permission error.

--- privileges.5        Mon Dec 21 11:46:34 2009
+++ privileges.5.new    Mon Dec 21 11:53:27 2009
@@ -180,6 +180,9 @@
          remove, change ownership of, or change permission bits of the
          Message Queue, Semaphore Set, or Shared Memory Segment.
 
+     PRIV_NET_ACCESS
+       Allows a process to open a network connection.
+
      PRIV_NET_BINDMLP
          Allow a process to bind to a port that  is  configured  as  a
          multi-level port (MLP) for the process's zone. This privilege

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		osnet
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From carlsonj@workingcode.com Tue Dec 22 06:40:47 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBMEelFQ020558
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 22 Dec 2009 06:40:47 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBMEelTa002002
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 22 Dec 2009 06:40:47 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV200J2R63ZB300@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 22 Dec 2009 06:40:47 -0800 (PST)
Received: from sca-ea-mail-1.sun.com ([192.18.43.24])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV200A0063XR860@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 22 Dec 2009 06:40:45 -0800 (PST)
Received: from relay43i.sun.com ([192.5.209.74])
	by sca-ea-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id nBMEedDb026147	for
 <PSARC-ext@sun.com>; Tue, 22 Dec 2009 14:40:45 +0000 (GMT)
Received: from mms49es.mms.us.syntegra.com ([160.41.221.232] [160.41.221.232])
 by relay43i.sun.com with ESMTP id BT-MMP-9044988 for PSARC-ext@sun.com; Tue,
 22 Dec 2009 14:40:39 +0000 (Z)
Received: from relay45i.sun.com (relay45i.sun.com [192.5.209.94])
 by mms49es.mms.us.syntegra.com with ESMTP id BT-MMP-10420563; Tue,
 22 Dec 2009 14:40:38 +0000 (Z)
Received: from carlson.workingcode.com ([75.150.68.97] [75.150.68.97])
 by relay4i.sun.com with ESMTP id BT-MMP-23690580; Tue,
 22 Dec 2009 14:40:38 +0000 (Z)
Received: from [10.50.24.188] (gate.abinitio.com [65.170.40.132])
	(authenticated bits=0)	by carlson.workingcode.com (8.14.2+Sun/8.14.3)
 with ESMTP id nBMEeYnx023518
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue,
 22 Dec 2009 09:40:35 -0500 (EST)
Date: Tue, 22 Dec 2009 09:40:33 -0500
From: James Carlson <carlsonj@workingcode.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
To: Casper Dik <casper@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com
Message-id: <4B30DA61.3030308@workingcode.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-DCC-dmv.com-Metrics: carlson; whitelist
X-Antispam: No, score=0.0/5.0, scanned in 0.357sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.22 (X11/20090605)
Status: RO
Content-Length: 364

Casper Dik wrote:
> This project proposes one new "basic" privilege.
> 
> NET_ACCESS
> 	Allows a process to open a network connection.

Looks pretty reasonable to me, though you may want to reconsider the
timeout.  The fast-track running period is mostly occupied by the
holiday break.

-- 
James Carlson         42.703N 71.076W         <carlsonj@workingcode.com>

From gdamore@sun.com Tue Dec 22 07:15:02 2009
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBMFF2RW021224
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 22 Dec 2009 07:15:02 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBMFF15S001974
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 22 Dec 2009 09:15:01 -0600 (CST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV2004377P16D00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 22 Dec 2009 07:15:01 -0800 (PST)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV200AR37OZR8A0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 22 Dec 2009 07:14:59 -0800 (PST)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id nBMFExgI006957	for
 <PSARC-ext@sun.com>; Tue, 22 Dec 2009 07:14:59 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KV200D007JHHC00@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 22 Dec 2009 07:14:59 -0800 (PST)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KV200ISV7OZ1BE0@fe-sfbay-09.sun.com>; Tue,
 22 Dec 2009 07:14:59 -0800 (PST)
Date: Tue, 22 Dec 2009 07:14:58 -0800
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
Sender: Garrett.Damore@sun.com
To: Casper Dik <casper@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com
Message-id: <4B30E272.3060202@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20091013)
Status: RO
Content-Length: 2062

This seems like a good idea, but out of curiosity, is there a specific 
motivation here?

    - Garrett

Casper Dik wrote:
> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
> This information is Copyright 2009 Sun Microsystems
> 1. Introduction
>     1.1. Project/Component Working Name:
> 	 Basic Network Privilege
>     1.2. Name of Document Author/Supplier:
> 	 Author:  Casper Dik
>     1.3  Date of This Document:
> 	22 December, 2009
> 4. Technical Description
> I'm sponsoring this fasttrack for myself.
>
> This project proposes one new "basic" privilege.
>
> NET_ACCESS
> 	Allows a process to open a network connection.
>
> The purpose of this privilege is the ability to create a process
> confined to the current system.
>
> The NET_ACCESS basic privilege is required for opening any IP endpoint
> (socket(), t_open()) except those which already require a different
> privilege, e.g., raw sockets.
>
> Note: a "basic" privilege is a privilege which is part of the
> default I, P and E privilege set.  Basic privileges should never be
> removed from I, P and E unless it is known that the specific privilege
> is not used in the application.
>
> Requested binding: patch/minor
>
>
> There is no need to update the socket(3*) and t_open(3nsl) manual pages
> as both calls already cater for a permission error.
>
> --- privileges.5        Mon Dec 21 11:46:34 2009
> +++ privileges.5.new    Mon Dec 21 11:53:27 2009
> @@ -180,6 +180,9 @@
>           remove, change ownership of, or change permission bits of the
>           Message Queue, Semaphore Set, or Shared Memory Segment.
>  
> +     PRIV_NET_ACCESS
> +       Allows a process to open a network connection.
> +
>       PRIV_NET_BINDMLP
>           Allow a process to bind to a port that  is  configured  as  a
>           multi-level port (MLP) for the process's zone. This privilege
>
> 6. Resources and Schedule
>     6.4. Steering Committee requested information
>    	6.4.1. Consolidation C-team Name:
> 		osnet
>     6.5. ARC review type: FastTrack
>     6.6. ARC Exposure: open
>
>   


From casper@holland.sun.com Tue Dec 22 07:51:48 2009
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBMFpm5B021669
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 22 Dec 2009 07:51:48 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBMFpjY0025371
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 22 Dec 2009 09:51:48 -0600 (CST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV20090T9EBQC00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 22 Dec 2009 08:51:47 -0700 (MST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV200GNB9E951D0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 22 Dec 2009 08:51:46 -0700 (MST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBMFpgvx027691; Tue, 22 Dec 2009 15:51:42 +0000 (GMT)
Date: Tue, 22 Dec 2009 16:51:42 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <4B30DA61.3030308@workingcode.com>
Sender: casper@holland.sun.com
To: James Carlson <carlsonj@workingcode.com>
Cc: Casper Dik <casper@sac.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <200912221551.nBMFpgvx027691@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
 <4B30DA61.3030308@workingcode.com>
Status: RO
Content-Length: 342


>Casper Dik wrote:
>> This project proposes one new "basic" privilege.
>> 
>> NET_ACCESS
>> 	Allows a process to open a network connection.
>
>Looks pretty reasonable to me, though you may want to reconsider the
>timeout.  The fast-track running period is mostly occupied by the
>holiday break.


Changed the timeout to 01/06/2010.

Casper


From Sebastien.Roy@sun.com Tue Dec 22 08:24:23 2009
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBMGONTS022775
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 22 Dec 2009 08:24:23 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBMGOKnr018859
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 22 Dec 2009 10:24:22 -0600 (CST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV200203AWM6C00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.Com); Tue, 22 Dec 2009 08:24:22 -0800 (PST)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV200INSAWMOPB0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.Com); Tue,
 22 Dec 2009 08:24:22 -0800 (PST)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id nBMGOMYS003665	for
 <PSARC-ext@Sun.Com>; Tue, 22 Dec 2009 16:24:22 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KV200E009JPXD00@mail-amer.sun.com> for PSARC-ext@Sun.Com
 (ORCPT PSARC-ext@Sun.Com); Tue, 22 Dec 2009 09:24:22 -0700 (MST)
Received: from [129.148.174.103] ([unknown] [129.148.174.103])
 by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KV200AE6AW93T20@mail-amer.sun.com>; Tue,
 22 Dec 2009 09:24:09 -0700 (MST)
Date: Tue, 22 Dec 2009 11:21:19 -0500
From: Sebastien Roy <Sebastien.Roy@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
Sender: Sebastien.Roy@sun.com
To: Casper Dik <casper@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com
Message-id: <1261498879.14792.109.camel@strat>
Organization: Sun Microsystems
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
Status: RO
Content-Length: 674

On Tue, 2009-12-22 at 06:26 -0800, Casper Dik wrote:
> This project proposes one new "basic" privilege.
> 
> NET_ACCESS
> 	Allows a process to open a network connection.
> 
> The purpose of this privilege is the ability to create a process
> confined to the current system.

Semantic nit: This mechanism accomplishes that and more.  For example,
without this privilege, a process also cannot open a PF_INET* socket to
communicate locally using the loopback address.  I assume that this is
an acceptable situation for the intended consumer, otherwise one would
need some more complex mechanism (perhaps involving the proposed socket
filter framework PSARC 2009/590).

-Seb



From casper@holland.sun.com Tue Dec 22 08:27:16 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBMGRGgt022798
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 22 Dec 2009 08:27:16 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id nBMGR2eD014419
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Tue, 22 Dec 2009 09:27:15 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV20020DB1EBZ00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Tue, 22 Dec 2009 08:27:14 -0800 (PST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV200IJNB1COTA0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Tue,
 22 Dec 2009 08:27:13 -0800 (PST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBMGRA1c008727; Tue, 22 Dec 2009 16:27:10 +0000 (GMT)
Date: Tue, 22 Dec 2009 17:27:10 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <1261498879.14792.109.camel@strat>
Sender: casper@holland.sun.com
To: Sebastien Roy <Sebastien.Roy@sun.com>
Cc: Casper Dik <casper@sac.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <200912221627.nBMGRA1c008727@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
 <1261498879.14792.109.camel@strat>
Status: RO
Content-Length: 854


>On Tue, 2009-12-22 at 06:26 -0800, Casper Dik wrote:
>> This project proposes one new "basic" privilege.
>> 
>> NET_ACCESS
>> 	Allows a process to open a network connection.
>> 
>> The purpose of this privilege is the ability to create a process
>> confined to the current system.
>
>Semantic nit: This mechanism accomplishes that and more.  For example,
>without this privilege, a process also cannot open a PF_INET* socket to
>communicate locally using the loopback address.  I assume that this is
>an acceptable situation for the intended consumer, otherwise one would
>need some more complex mechanism (perhaps involving the proposed socket
>filter framework PSARC 2009/590).


True; however, we have sufficient local transport available and we also 
have nscd; no need for ordinary applications to directly call the NIS/LDAP/
DNS server.

Casper


From Darren.Moffat@sun.com Tue Dec 22 09:23:59 2009
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBMHNxSE023636
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 22 Dec 2009 09:23:59 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBMHNt0w027828
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 22 Dec 2009 11:23:59 -0600 (CST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV200A11DNYAV00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 22 Dec 2009 09:23:58 -0800 (PST)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV200CANDNXQ580@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 22 Dec 2009 09:23:58 -0800 (PST)
Received: from fe-emea-10.sun.com
 (gmp-eb-lb-1-fe1.eu.sun.com [192.18.6.7] (may be forged))
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id nBMHNvZ7013814	for
 <PSARC-ext@sun.com>; Tue, 22 Dec 2009 17:23:57 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KV200D00BS36300@fe-emea-10.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 22 Dec 2009 17:23:50 +0000 (GMT)
Received: from [192.168.2.108]
 (99-52-200-208.lightspeed.snjsca.sbcglobal.net [99.52.200.208])
 by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KV200C0MDNNFX70@fe-emea-10.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 22 Dec 2009 17:23:50 +0000 (GMT)
Date: Mon, 21 Dec 2009 09:27:43 -0800
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <200912221551.nBMFpgvx027691@dm-holland-02.uk.sun.com>
Sender: Darren.Moffat@sun.com
To: Casper.Dik@sun.com
Cc: James Carlson <carlsonj@workingcode.com>, PSARC-ext@sun.com
Message-id: <4B2FB00F.103@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
 <4B30DA61.3030308@workingcode.com>
 <200912221551.nBMFpgvx027691@dm-holland-02.uk.sun.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20091109)
Status: RO
Content-Length: 210

I'm happy with this case as specified, this is my +1.  I hope to see a 
future case where this privilege and net_privaddr can be constrained to 
individual port numbers - but not this case.

--
Darren J Moffat

From Sebastien.Roy@sun.com Tue Dec 22 11:35:07 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBMJZ7Os025224
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 22 Dec 2009 11:35:07 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBMJZ75X021463
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 22 Dec 2009 11:35:07 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV20080DJQJF100@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 22 Dec 2009 12:35:07 -0700 (MST)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV200CWDJQI3QF0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 22 Dec 2009 12:35:06 -0700 (MST)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id nBMJZ51J011378	for
 <PSARC-ext@sun.com>; Tue, 22 Dec 2009 19:35:05 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KV200100JA9V000@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 22 Dec 2009 12:35:05 -0700 (MST)
Received: from [129.148.174.103] ([unknown] [129.148.174.103])
 by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KV2004XUJQHY420@mail-amer.sun.com>; Tue,
 22 Dec 2009 12:35:05 -0700 (MST)
Date: Tue, 22 Dec 2009 14:32:13 -0500
From: Sebastien Roy <Sebastien.Roy@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912221627.nBMGRA1c008727@dm-holland-02.uk.sun.com>
Sender: Sebastien.Roy@sun.com
To: casper.dik@sun.com
Cc: Casper Dik <casper@sac.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <1261510333.14792.154.camel@strat>
Organization: Sun Microsystems
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
 <1261498879.14792.109.camel@strat>
 <200912221627.nBMGRA1c008727@dm-holland-02.uk.sun.com>
Status: RO
Content-Length: 1885

On Tue, 2009-12-22 at 17:27 +0100, Casper.Dik@Sun.COM wrote:
> >On Tue, 2009-12-22 at 06:26 -0800, Casper Dik wrote:
> >> This project proposes one new "basic" privilege.
> >> 
> >> NET_ACCESS
> >> 	Allows a process to open a network connection.
> >> 
> >> The purpose of this privilege is the ability to create a process
> >> confined to the current system.
> >
> >Semantic nit: This mechanism accomplishes that and more.  For example,
> >without this privilege, a process also cannot open a PF_INET* socket to
> >communicate locally using the loopback address.  I assume that this is
> >an acceptable situation for the intended consumer, otherwise one would
> >need some more complex mechanism (perhaps involving the proposed socket
> >filter framework PSARC 2009/590).
> 
> 
> True; however, we have sufficient local transport available

Sure, however that won't allow this mechanism to be used to restrict
existing unmodified PF_INET* applications to loopback communication.  I
don't have a problem with that, it's simply a side-effect of the
proposed solution.

> and we also 
> have nscd; no need for ordinary applications to directly call the NIS/LDAP/
> DNS server.

Right, and I think you may also have discovered libnsl's use of socket
ioctls to get local address information while processing name lookup
calls.  It does that because nscd's address lists are unsorted, and
getaddrinfo() and friends return a sorted address list using an
algorithm that uses the local address list as input (this was introduced
by PSARC 2002/390).  That said, given that applications without the
proposed privilege won't be able to communicate with the returned
addresses, their sort order is quite meaningless.  In that case,
ignoring the failed socket() call and returning the unsorted address
list directly from nscd would likely be the right thing to do.

In any case, +1 from me.

-Seb



From casper@holland.sun.com Tue Dec 22 12:26:36 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBMKQaA5026409
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 22 Dec 2009 12:26:36 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBMKQaxn014977
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Tue, 22 Dec 2009 12:26:36 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV200F03M4CUF00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Tue, 22 Dec 2009 12:26:36 -0800 (PST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV200FIBM4BHO00@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Tue,
 22 Dec 2009 12:26:35 -0800 (PST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBMKQWLX011926; Tue, 22 Dec 2009 20:26:32 +0000 (GMT)
Date: Tue, 22 Dec 2009 21:26:32 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <1261510333.14792.154.camel@strat>
Sender: casper@holland.sun.com
To: Sebastien Roy <Sebastien.Roy@sun.com>
Cc: Casper Dik <casper@sac.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <200912222026.nBMKQWLX011926@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
 <1261498879.14792.109.camel@strat>
 <200912221627.nBMGRA1c008727@dm-holland-02.uk.sun.com>
 <1261510333.14792.154.camel@strat>
Status: RO
Content-Length: 971




>Right, and I think you may also have discovered libnsl's use of socket
>ioctls to get local address information while processing name lookup
>calls.  It does that because nscd's address lists are unsorted, and
>getaddrinfo() and friends return a sorted address list using an
>algorithm that uses the local address list as input (this was introduced
>by PSARC 2002/390).  That said, given that applications without the
>proposed privilege won't be able to communicate with the returned
>addresses, their sort order is quite meaningless.  In that case,
>ignoring the failed socket() call and returning the unsorted address
>list directly from nscd would likely be the right thing to do.

I indeed discovered this; I do prefer fixing that, though, because I prefer
this:

 finger @localhost
[localhost] socket: Permission denied

to this:
finger @localhost 
unknown host: localhost

So why is nscd not sorting the addresses?

>In any case, +1 from me.

Thanks.

Casper


From Sebastien.Roy@sun.com Tue Dec 22 13:44:22 2009
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBMLiLD0028145
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 22 Dec 2009 13:44:22 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBMLiL22009799
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 22 Dec 2009 15:44:21 -0600 (CST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV200107PPXU400@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Tue, 22 Dec 2009 13:44:21 -0800 (PST)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV20048WPPWVJC0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Tue,
 22 Dec 2009 13:44:20 -0800 (PST)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id nBMLiKrH009943	for
 <PSARC-ext@Sun.COM>; Tue, 22 Dec 2009 21:44:20 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KV200H00PE3KJ00@mail-amer.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Tue, 22 Dec 2009 14:44:20 -0700 (MST)
Received: from [129.148.174.103] ([unknown] [129.148.174.103])
 by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KV200GE3PPVCC10@mail-amer.sun.com>; Tue,
 22 Dec 2009 14:44:20 -0700 (MST)
Date: Tue, 22 Dec 2009 16:41:28 -0500
From: Sebastien Roy <Sebastien.Roy@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912222026.nBMKQWLX011926@dm-holland-02.uk.sun.com>
Sender: Sebastien.Roy@sun.com
To: Casper.Dik@sun.com
Cc: Casper Dik <casper@sac.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <1261518088.14792.241.camel@strat>
Organization: Sun Microsystems
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
 <1261498879.14792.109.camel@strat>
 <200912221627.nBMGRA1c008727@dm-holland-02.uk.sun.com>
 <1261510333.14792.154.camel@strat>
 <200912222026.nBMKQWLX011926@dm-holland-02.uk.sun.com>
Status: RO
Content-Length: 1612

On Tue, 2009-12-22 at 21:26 +0100, Casper.Dik@Sun.COM wrote:
> 
> 
> >Right, and I think you may also have discovered libnsl's use of socket
> >ioctls to get local address information while processing name lookup
> >calls.  It does that because nscd's address lists are unsorted, and
> >getaddrinfo() and friends return a sorted address list using an
> >algorithm that uses the local address list as input (this was introduced
> >by PSARC 2002/390).  That said, given that applications without the
> >proposed privilege won't be able to communicate with the returned
> >addresses, their sort order is quite meaningless.  In that case,
> >ignoring the failed socket() call and returning the unsorted address
> >list directly from nscd would likely be the right thing to do.
> 
> I indeed discovered this; I do prefer fixing that, though, because I prefer
> this:
> 
>  finger @localhost
> [localhost] socket: Permission denied
> 
> to this:
> finger @localhost 
> unknown host: localhost

Indeed.

> 
> So why is nscd not sorting the addresses?

I stand corrected, nscd does keep a sorted list (I should remember these
things, it's only been 10 years). ;-)  I believe the issue is that
getipnodebyname() could potentially obtain separate IPv4 and IPv6
results after having done two separate calls to nscd (one for NSS_HOST
and another for NSS_HOST6), and it then needs to sort the resulting
merged set of addresses.

The libnsl/nscd interactions could stand to be simplified so that the
sorting only ever needs to be done by nscd, but we're straying a bit
from relevancy as far as this case is concerned.

-Seb



From peter.memishian@sun.com Wed Dec 23 10:41:19 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNIfI4V025845
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 10:41:19 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNIfIAE023663
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 23 Dec 2009 10:41:18 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400G03BWUR300@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 23 Dec 2009 11:41:18 -0700 (MST)
Received: from triplex.local ([129.146.108.208]) by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400C4EBWT1M30@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 23 Dec 2009 11:41:17 -0700 (MST)
Received: from triplex.local (triplex [127.0.0.1])
	by triplex.local (8.14.3+Sun/8.14.3) with ESMTP id nBNIfHgq675501	for
 <psarc-ext@sun.com>; Wed, 23 Dec 2009 10:41:17 -0800 (PST)
Received: (from meem@localhost)	by triplex.local (8.14.3+Sun/8.14.3/Submit)
 id nBNIfHRx675489; Wed, 23 Dec 2009 10:41:17 -0800 (PST)
Date: Wed, 23 Dec 2009 10:41:17 -0800
From: Peter Memishian <peter.memishian@sun.com>
Subject: re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
To: PSARC-ext@sun.com
Message-id: <19250.25677.542375.150640@gargle.gargle.HOWL>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Authentication-warning: triplex.local: meem set sender to
 peter.memishian@sun.com using -f
Status: RO
Content-Length: 513

X-Mailer: VM 7.19 under 21.4 (patch 21) "Educational Television" XEmacs Lucid
Reply-To: peter.memishian@sun.com
FCC: MAILED


Further to what Seb said, in general, loopback sockets are treated as an
IPC mechanism and may be used by any random set of applications that have
no interest in actually using the network.  That is, not having the
proposed NET_ACCESS privilege may cause random applications to fail even
though they never attempted to access the network.  Is this really the
desired behavior?

-- 
meem

From erik.nordmark@sun.com Wed Dec 23 12:16:15 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNKGFXu027268
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 12:16:15 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNKGCXS019245;
	Wed, 23 Dec 2009 12:16:15 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV40031JGB2CA00@brm-avmta-1.central.sun.com>; Wed,
 23 Dec 2009 13:16:14 -0700 (MST)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400CQ5GB11P90@brm-avmta-1.central.sun.com>; Wed,
 23 Dec 2009 13:16:13 -0700 (MST)
Received: from [10.7.251.248] (punchin-nordmark.SFBay.Sun.COM [10.7.251.248])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id nBNKGC9c206163
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed,
 23 Dec 2009 12:16:13 -0800 (PST)
Date: Wed, 23 Dec 2009 12:16:12 -0800
From: Erik Nordmark <erik.nordmark@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
To: Casper Dik <casper@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com
Message-id: <4B327A8C.90704@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20091124)
Status: RO
Content-Length: 1160

Casper Dik wrote:

> This project proposes one new "basic" privilege.
> 
> NET_ACCESS
> 	Allows a process to open a network connection.
> 
> The purpose of this privilege is the ability to create a process
> confined to the current system.
> 
> The NET_ACCESS basic privilege is required for opening any IP endpoint
> (socket(), t_open()) except those which already require a different
> privilege, e.g., raw sockets.

I don't understand the motivation for excluding the raw sockets and/or 
icmp sockets from checking NET_ACCESS. It seems simpler from a user 
perspective if removing NET_ACCESS has the effect of making the user no 
longer be able to open any TCP, UDP, SCTP, or RAW sockets.

Thus I think it makes sense removing the above exception.


Do we know if there is any impact to getaddrinfo() and friends? I 
believe the library code opens a UDP socket to issue SIOC ioctls (done 
as part of verifying whether IPv4 and/or IPv6 is configured on the 
system). Perhaps that isn't an architectural issue, but we need to make 
sure there aren't any confusing failures or error messages when 
NET_ACCESS has been removed from the privilege set.

    Erik

From casper@holland.sun.com Wed Dec 23 12:54:29 2009
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNKsTAc027995
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 12:54:29 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNKsSaV005825
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Wed, 23 Dec 2009 14:54:28 -0600 (CST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400I0FI2STO00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Wed, 23 Dec 2009 12:54:28 -0800 (PST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400C7LI2RHK70@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Wed,
 23 Dec 2009 12:54:28 -0800 (PST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBNKsQXZ009466; Wed, 23 Dec 2009 20:54:26 +0000 (GMT)
Date: Wed, 23 Dec 2009 21:54:26 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <19250.25677.542375.150640@gargle.gargle.HOWL>
Sender: casper@holland.sun.com
To: Peter Memishian <Peter.Memishian@sun.com>
Cc: PSARC-ext@sun.com
Message-id: <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
Status: RO
Content-Length: 644


>X-Mailer: VM 7.19 under 21.4 (patch 21) "Educational Television" XEmacs Lucid
>Reply-To: peter.memishian@sun.com
>FCC: MAILED
>
>
>Further to what Seb said, in general, loopback sockets are treated as an
>IPC mechanism and may be used by any random set of applications that have
>no interest in actually using the network.  That is, not having the
>proposed NET_ACCESS privilege may cause random applications to fail even
>though they never attempted to access the network.  Is this really the
>desired behavior?

Yes.   I wouldn't call it random; they're still INET sockets.  The use is 
limited and specific for containing users.


Casper


From carlsonj@workingcode.com Wed Dec 23 13:01:25 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNL1Ppo028194
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 13:01:25 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNL1MCt029534;
	Wed, 23 Dec 2009 13:01:22 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV40080DIEA6900@brm-avmta-1.central.sun.com>; Wed,
 23 Dec 2009 14:01:22 -0700 (MST)
Received: from sca-ea-mail-1.sun.com ([192.18.43.24])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400C9IIEA1FC0@brm-avmta-1.central.sun.com>; Wed,
 23 Dec 2009 14:01:22 -0700 (MST)
Received: from relay11i.sun.com
 (ip121.net129179-4.block1.us.syntegra.com [129.179.4.121])
	by sca-ea-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id nBNL1Ll1017949;
 Wed, 23 Dec 2009 21:01:21 +0000 (GMT)
Received: from mmp13es.mmp.us.syntegra.com ([160.41.208.13] [160.41.208.13])
 by relay11i.sun.com with ESMTP id BT-MMP-9598536; Wed,
 23 Dec 2009 21:01:21 +0000 (Z)
Received: from relay13i.sun.com (relay13i.sun.com [129.179.4.123])
 by mmp13es.mmp.us.syntegra.com with ESMTP id BT-MMP-16835762; Wed,
 23 Dec 2009 21:01:20 +0000 (Z)
Received: from carlson.workingcode.com ([75.150.68.97] [75.150.68.97])
 by relay1i.sun.com with ESMTP id BT-MMP-17218319; Wed,
 23 Dec 2009 21:01:20 +0000 (Z)
Received: from [10.50.24.188] (gate.abinitio.com [65.170.40.132])
	(authenticated bits=0)	by carlson.workingcode.com (8.14.2+Sun/8.14.3)
 with ESMTP id nBNL1HLW001555
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed,
 23 Dec 2009 16:01:17 -0500 (EST)
Date: Wed, 23 Dec 2009 16:01:17 -0500
From: James Carlson <carlsonj@workingcode.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
To: Casper.Dik@sun.com
Cc: Peter Memishian <Peter.Memishian@sun.com>, PSARC-ext@sun.com
Message-id: <4B32851D.1040408@workingcode.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-DCC-dmv.com-Metrics: carlson; whitelist
X-Antispam: No, score=0.0/5.0, scanned in 0.304sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
User-Agent: Thunderbird 2.0.0.22 (X11/20090605)
Status: RO
Content-Length: 938

Casper.Dik@sun.com wrote:
>> Further to what Seb said, in general, loopback sockets are treated as an
>> IPC mechanism and may be used by any random set of applications that have
>> no interest in actually using the network.  That is, not having the
>> proposed NET_ACCESS privilege may cause random applications to fail even
>> though they never attempted to access the network.  Is this really the
>> desired behavior?
> 
> Yes.   I wouldn't call it random; they're still INET sockets.  The use is 
> limited and specific for containing users.

I think that still leaves meem's question unanswered.

Isn't whether the application uses loopback sockets or (say) SysV
message queues merely an implementation detail?  Why would one means of
purely local communication among cooperating processes be allowed and
the other denied?

What's the principle involved?

-- 
James Carlson         42.703N 71.076W         <carlsonj@workingcode.com>

From peter.memishian@sun.com Wed Dec 23 13:09:52 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNL9q2C028229
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 13:09:52 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNL9nLd012997;
	Wed, 23 Dec 2009 13:09:50 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400H0LISDRR00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 13:09:49 -0800 (PST)
Received: from triplex.local ([129.146.108.208]) by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV40004YISD50C0@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 13:09:49 -0800 (PST)
Received: from triplex.local (triplex [127.0.0.1])
	by triplex.local (8.14.3+Sun/8.14.3) with ESMTP id nBNL9npe476664; Wed,
 23 Dec 2009 13:09:49 -0800 (PST)
Received: (from meem@localhost)	by triplex.local (8.14.3+Sun/8.14.3/Submit)
 id nBNL9ng6476652; Wed, 23 Dec 2009 13:09:49 -0800 (PST)
Date: Wed, 23 Dec 2009 13:09:49 -0800
From: Peter Memishian <peter.memishian@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
To: Casper.Dik@sun.com
Cc: Peter Memishian <peter.memishian@sun.com>, PSARC-ext@sun.com
Reply-to: peter.memishian@sun.com
Message-id: <19250.34589.40454.646037@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.19 under 21.4 (patch 21) "Educational Television" XEmacs Lucid
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
X-Authentication-warning: triplex.local: meem set sender to
 peter.memishian@sun.com using -f
Status: RO
Content-Length: 1020


 > >Further to what Seb said, in general, loopback sockets are treated as an
 > >IPC mechanism and may be used by any random set of applications that have
 > >no interest in actually using the network.  That is, not having the
 > >proposed NET_ACCESS privilege may cause random applications to fail even
 > >though they never attempted to access the network.  Is this really the
 > >desired behavior?
 > 
 > Yes.   I wouldn't call it random; they're still INET sockets.

They are inet sockets as an IPC mechanism that has nothing to do with
networking per se.  Same with AF_UNIX sockets.  That is, this privilege
will both prevent use of the network and prevent applications that happen
to use loopback and AF_UNIX sockets for IPC from working.  We have no
control over what applications those may be.

In the case of loopback IPC: we do not support a system with lo0 unplumbed
because we do not know what applications will break.  This proposal seems
to result in a system that is at least as unsupportable.

-- 
meem

From casper@holland.sun.com Wed Dec 23 13:10:09 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNLA8ax028252
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 13:10:09 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id nBNLA7gx037501
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Wed, 23 Dec 2009 14:10:08 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400J09ISWZ300@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Wed, 23 Dec 2009 13:10:08 -0800 (PST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400CHVISVHI60@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Wed,
 23 Dec 2009 13:10:08 -0800 (PST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBNLA3o3012841; Wed, 23 Dec 2009 21:10:03 +0000 (GMT)
Date: Wed, 23 Dec 2009 22:10:03 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <4B327A8C.90704@sun.com>
Sender: casper@holland.sun.com
To: Erik Nordmark <Erik.Nordmark@sun.com>
Cc: Casper Dik <casper@sac.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <200912232110.nBNLA3o3012841@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
 <4B327A8C.90704@sun.com>
Status: RO
Content-Length: 1024



>I don't understand the motivation for excluding the raw sockets and/or 
>icmp sockets from checking NET_ACCESS. It seems simpler from a user 
>perspective if removing NET_ACCESS has the effect of making the user no 
>longer be able to open any TCP, UDP, SCTP, or RAW sockets.

Because you already need a privilege and there's no need to remove those 
privileges?

>Thus I think it makes sense removing the above exception.
>
>
>Do we know if there is any impact to getaddrinfo() and friends? I 
>believe the library code opens a UDP socket to issue SIOC ioctls (done 
>as part of verifying whether IPv4 and/or IPv6 is configured on the 
>system). Perhaps that isn't an architectural issue, but we need to make 
>sure there aren't any confusing failures or error messages when 
>NET_ACCESS has been removed from the privilege set.

If the library detects that opening /dev/udp{,6} fails it will pretend that 
there are IP/IP6 interfaces and the application will find the hostname but 
won't be able to connect.  

Casper


From casper@holland.sun.com Wed Dec 23 13:28:31 2009
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNLSVoV028367
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 13:28:31 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNLSVrM025635
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Wed, 23 Dec 2009 15:28:31 -0600 (CST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400A03JNIYF00@brm-avmta-1.central.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Wed, 23 Dec 2009 14:28:30 -0700 (MST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400CMDJNH1MC0@brm-avmta-1.central.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Wed,
 23 Dec 2009 14:28:30 -0700 (MST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBNLSShg015888; Wed, 23 Dec 2009 21:28:28 +0000 (GMT)
Date: Wed, 23 Dec 2009 22:28:28 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <19250.34589.40454.646037@gargle.gargle.HOWL>
Sender: casper@holland.sun.com
To: Peter.Memishian@sun.com
Cc: PSARC-ext@sun.com
Message-id: <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
Status: RO
Content-Length: 1903


>
> > >Further to what Seb said, in general, loopback sockets are treated as an
> > >IPC mechanism and may be used by any random set of applications that have
> > >no interest in actually using the network.  That is, not having the
> > >proposed NET_ACCESS privilege may cause random applications to fail even
> > >though they never attempted to access the network.  Is this really the
> > >desired behavior?
> > 
> > Yes.   I wouldn't call it random; they're still INET sockets.
>
>They are inet sockets as an IPC mechanism that has nothing to do with
>networking per se.  Same with AF_UNIX sockets.  That is, this privilege
>will both prevent use of the network and prevent applications that happen
>to use loopback and AF_UNIX sockets for IPC from working.  We have no
>control over what applications those may be.

Why would this affect AF_UNIX sockets?

>In the case of loopback IPC: we do not support a system with lo0 unplumbed
>because we do not know what applications will break.  This proposal seems
>to result in a system that is at least as unsupportable.

No, because it is a basic privilege and so all applications will have
the basic privileges unless they want to run without them.

It is similar to all the other basic privileges: we can't tell whether an 
ordinary applications will or will not work without a specific basic privilege.

The basic privileges have added a new class of users, "subusers".
You can use it to contain applications (can't "call home") or users (can't
squirrel data away on the Internet).  When removing a basic privilege,
the onus is on the administrator to determine that it will work for
the particular user.

Follow on projects will allow us to select what INET connections can be 
made; I do not believe that a carte blanche for "localhost" connections is 
warranted: it allows sending email out through sendmail using the 
submission port.

Casper





From peter.memishian@sun.com Wed Dec 23 13:42:55 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNLgtql028527
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 13:42:55 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNLgq0q027398;
	Wed, 23 Dec 2009 13:42:53 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV40030FKBH4300@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 13:42:53 -0800 (PST)
Received: from triplex.local ([129.146.108.208]) by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV4000EPKBG4PD0@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 13:42:52 -0800 (PST)
Received: from triplex.local (triplex [127.0.0.1])
	by triplex.local (8.14.3+Sun/8.14.3) with ESMTP id nBNLgqDE833324; Wed,
 23 Dec 2009 13:42:52 -0800 (PST)
Received: (from meem@localhost)	by triplex.local (8.14.3+Sun/8.14.3/Submit)
 id nBNLgqwh833311; Wed, 23 Dec 2009 13:42:52 -0800 (PST)
Date: Wed, 23 Dec 2009 13:42:52 -0800
From: Peter Memishian <peter.memishian@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
To: Casper.Dik@sun.com
Cc: peter.memishian@sun.com, PSARC-ext@sun.com
Reply-to: peter.memishian@sun.com
Message-id: <19250.36572.222057.29285@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.19 under 21.4 (patch 21) "Educational Television" XEmacs Lucid
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
X-Authentication-warning: triplex.local: meem set sender to
 peter.memishian@sun.com using -f
Status: RO
Content-Length: 1545


 > >They are inet sockets as an IPC mechanism that has nothing to do with
 > >networking per se.  Same with AF_UNIX sockets.  That is, this privilege
 > >will both prevent use of the network and prevent applications that happen
 > >to use loopback and AF_UNIX sockets for IPC from working.  We have no
 > >control over what applications those may be.
 > 
 > Why would this affect AF_UNIX sockets?

Does your proposal allow socket() calls for AF_UNIX even without basic
network privilege?  If so, then no problem for AF_UNIX.

 > The basic privileges have added a new class of users, "subusers".
 > You can use it to contain applications (can't "call home") or users (can't
 > squirrel data away on the Internet).  When removing a basic privilege,
 > the onus is on the administrator to determine that it will work for
 > the particular user.

This itself is a supportability problem, but things become much worse if
other (unrelated) functionality is ensnared by the privilege checks.

 > Follow on projects will allow us to select what INET connections can be 
 > made; I do not believe that a carte blanche for "localhost" connections is 
 > warranted: it allows sending email out through sendmail using the 
 > submission port.

I don't follow.  How would mail actually be sent off the machine?  Why
should not having "network privileges" prevent applications from being
used for local purposes?  Further, the set of impacted applications will
be essentially random based on the whim of the IPC mechanism used by its
implementors.

-- 
meem

From Nicolas.Williams@sun.com Wed Dec 23 13:44:08 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNLi7jo028539
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 13:44:07 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNLi4DP019529;
	Wed, 23 Dec 2009 13:44:05 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV40030DKDGES00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 13:44:04 -0800 (PST)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV4000OKKDF4PD0@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 13:44:04 -0800 (PST)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id nBNLi3FL012561;
 Wed, 23 Dec 2009 15:44:03 -0600 (CST)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id nBNLi3Ti012560; Wed,
 23 Dec 2009 15:44:03 -0600 (CST)
Date: Wed, 23 Dec 2009 15:44:03 -0600
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
To: Casper.Dik@sun.com
Cc: peter.memishian@sun.com, PSARC-ext@sun.com
Message-id: <20091223214403.GZ1516@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 1567

On Wed, Dec 23, 2009 at 10:28:28PM +0100, Casper.Dik@Sun.COM wrote:
> >In the case of loopback IPC: we do not support a system with lo0 unplumbed
> >because we do not know what applications will break.  This proposal seems
> >to result in a system that is at least as unsupportable.
> 
> No, because it is a basic privilege and so all applications will have
> the basic privileges unless they want to run without them.
> 
> Follow on projects will allow us to select what INET connections can be 
> made; I do not believe that a carte blanche for "localhost" connections is 
> warranted: it allows sending email out through sendmail using the 
> submission port.

Just the ability to exec() sendmail suffices for sending e-mail; no need
to talk to sendmail via a socket.  Sure, you could then remove PROC_EXEC
and PROC_NETWORK from a process' privilege sets, but that's pretty
constraining when all you wanted initially was to disallow network
communication.

Also, even without this privilege one could use name services as a
covert channel.  Maybe nscd should not allow a calling process without
this new basic privilege to do host lookups for anything other than
localhost and its aliases as they appear in /etc/inet/hosts.

I do agree that privileges are not suitable for fine-grained access
controls on specific programs, that that's the land of FGAP and FMAC.
This, not by itself but coupled with the simplicity of implementing the
new privilege in socket()/t_open(), is the best rationale for this basic
privilege to apply to all inet/inet6 sockets.

Nico
-- 

From carlsonj@workingcode.com Wed Dec 23 13:57:49 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNLvnoj028929
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 13:57:49 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNLvliN003964;
	Wed, 23 Dec 2009 13:57:47 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400E05L0B2W00@brm-avmta-1.central.sun.com>; Wed,
 23 Dec 2009 14:57:47 -0700 (MST)
Received: from sca-ea-mail-3.sun.com ([192.18.43.21])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400C2NL0A17D0@brm-avmta-1.central.sun.com>; Wed,
 23 Dec 2009 14:57:47 -0700 (MST)
Received: from relay15i.sun.com
 (ip125.net129179-4.block1.us.syntegra.com [129.179.4.125])
	by sca-ea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id nBNLvjZS022305;
 Wed, 23 Dec 2009 21:57:46 +0000 (GMT)
Received: from mmp13es.mmp.us.syntegra.com ([160.41.208.13] [160.41.208.13])
 by relay15i.sun.com with ESMTP id BT-MMP-5314771; Wed,
 23 Dec 2009 21:57:45 +0000 (Z)
Received: from relay13i.sun.com (relay13i.sun.com [129.179.4.123])
 by mmp13es.mmp.us.syntegra.com with ESMTP id BT-MMP-16933573; Wed,
 23 Dec 2009 21:57:45 +0000 (Z)
Received: from carlson.workingcode.com ([75.150.68.97] [75.150.68.97])
 by relay1i.sun.com with ESMTP id BT-MMP-17327114; Wed,
 23 Dec 2009 21:57:45 +0000 (Z)
Received: from [10.50.24.188] (gate.abinitio.com [65.170.40.132])
	(authenticated bits=0)	by carlson.workingcode.com (8.14.2+Sun/8.14.3)
 with ESMTP id nBNLve9v009468
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed,
 23 Dec 2009 16:57:41 -0500 (EST)
Date: Wed, 23 Dec 2009 16:57:40 -0500
From: James Carlson <carlsonj@workingcode.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <19250.36572.222057.29285@gargle.gargle.HOWL>
To: peter.memishian@sun.com
Cc: Casper.Dik@sun.com, PSARC-ext@sun.com
Message-id: <4B329254.4030204@workingcode.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-DCC-dmv.com-Metrics: carlson; whitelist
X-Antispam: No, score=0.0/5.0, scanned in 0.061sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.22 (X11/20090605)
Status: RO
Content-Length: 1016

Peter Memishian wrote:
>  > Follow on projects will allow us to select what INET connections can be 
>  > made; I do not believe that a carte blanche for "localhost" connections is 
>  > warranted: it allows sending email out through sendmail using the 
>  > submission port.
> 
> I don't follow.  How would mail actually be sent off the machine?

Connect to 127.1 port 587 and blast away.

>  Why
> should not having "network privileges" prevent applications from being
> used for local purposes?  Further, the set of impacted applications will
> be essentially random based on the whim of the IPC mechanism used by its
> implementors.

I think what Casper is arguing is that this doesn't actually matter.
Someone who wants to revoke this privilege for some process will need to
test the application (and perhaps examine its source code) in order to
determine whether doing so is feasible.  If that's done right, you'd
have no problems.

-- 
James Carlson         42.703N 71.076W         <carlsonj@workingcode.com>

From peter.memishian@sun.com Wed Dec 23 14:27:13 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNMRDjF029227
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 14:27:13 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNMRA1q009161;
	Wed, 23 Dec 2009 14:27:10 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400205MDA1400@nwk-avmta-2.sfbay.sun.com>; Wed,
 23 Dec 2009 14:27:10 -0800 (PST)
Received: from triplex.local ([129.146.108.208]) by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400CQ7MD9HG90@nwk-avmta-2.sfbay.sun.com>; Wed,
 23 Dec 2009 14:27:09 -0800 (PST)
Received: from triplex.local (triplex [127.0.0.1])
	by triplex.local (8.14.3+Sun/8.14.3) with ESMTP id nBNMR9Gf411237; Wed,
 23 Dec 2009 14:27:09 -0800 (PST)
Received: (from meem@localhost)	by triplex.local (8.14.3+Sun/8.14.3/Submit)
 id nBNMR9gK411222; Wed, 23 Dec 2009 14:27:09 -0800 (PST)
Date: Wed, 23 Dec 2009 14:27:09 -0800
From: Peter Memishian <peter.memishian@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <4B329254.4030204@workingcode.com>
To: James Carlson <carlsonj@workingcode.com>
Cc: peter.memishian@sun.com, Casper.Dik@sun.com, PSARC-ext@sun.com
Reply-to: peter.memishian@sun.com
Message-id: <19250.39229.677.800898@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.19 under 21.4 (patch 21) "Educational Television" XEmacs Lucid
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com>
X-Authentication-warning: triplex.local: meem set sender to
 peter.memishian@sun.com using -f
Status: RO
Content-Length: 1235


 > > should not having "network privileges" prevent applications from being
 > > used for local purposes?  Further, the set of impacted applications will
 > > be essentially random based on the whim of the IPC mechanism used by its
 > > implementors.
 > 
 > I think what Casper is arguing is that this doesn't actually matter.
 > Someone who wants to revoke this privilege for some process will need to
 > test the application (and perhaps examine its source code) in order to
 > determine whether doing so is feasible.  If that's done right, you'd
 > have no problems.

... and repeat the exhaustive evaluation every time it's patched.

I could see doing this on a subset of well-controlled applications, but
what happens when a customer using this facility wants some Sun-supported
application that happens to use loopback inet IPC to "work"?  Are we going
to change the code to accommodate their need, or tell them they're off the
reservation?  So long as it's the latter, and this is made clear up-front,
I don't have a strong objection to Casper's proposal, though I still fear
that the loopback inet IPC restriction will cause unexpected problems for
applications that just happen to use that mechanism for their IPC.

-- 
meem

From Alan.Coopersmith@sun.com Wed Dec 23 14:34:21 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNMYLVk029264
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 14:34:21 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id nBNMYKOH024970
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 23 Dec 2009 15:34:20 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400H03MP87Y00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 23 Dec 2009 14:34:20 -0800 (PST)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400FTCMP83G20@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 23 Dec 2009 14:34:20 -0800 (PST)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id nBNMYJT8008348	for
 <PSARC-ext@sun.com>; Wed, 23 Dec 2009 14:34:19 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KV400K00MM0QI00@fe-sfbay-10.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 23 Dec 2009 14:34:19 -0800 (PST)
Received: from [10.6.102.27] ([unknown] [10.6.102.27])
 by fe-sfbay-10.sun.com (Sun Java(tm) System Messaging Server 7u2-7.04 64bit
 (built Jul  2 2009)) with ESMTPSA id <0KV400G91MP7HN90@fe-sfbay-10.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 23 Dec 2009 14:34:19 -0800 (PST)
Date: Wed, 23 Dec 2009 14:34:19 -0800
From: Alan Coopersmith <Alan.Coopersmith@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <19250.39229.677.800898@gargle.gargle.HOWL>
Sender: Alan.Coopersmith@sun.com
To: peter.memishian@sun.com
Cc: James Carlson <carlsonj@workingcode.com>, Casper.Dik@sun.com,
        PSARC-ext@sun.com
Message-id: <4B329AEB.708@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Enigmail-Version: 0.95.1
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.23 (X11/20090926)
Status: RO
Content-Length: 663

Peter Memishian wrote:
> I could see doing this on a subset of well-controlled applications, but
> what happens when a customer using this facility wants some Sun-supported
> application that happens to use loopback inet IPC to "work"?  Are we going
> to change the code to accommodate their need, or tell them they're off the
> reservation? 

How would this be any different than if they tried removing other basic
privileges, like the ability to fork() or exec(), from apps that really
needed it?   If customers break their system, it's broken.

-- 
	-Alan Coopersmith-           alan.coopersmith@sun.com
	 Sun Microsystems, Inc. - X Window System Engineering


From peter.memishian@sun.com Wed Dec 23 14:40:19 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNMeJik029280
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 14:40:19 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNMeGDL014355;
	Wed, 23 Dec 2009 14:40:16 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400I0VMZ4YP00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 14:40:16 -0800 (PST)
Received: from triplex.local ([129.146.108.208]) by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400FV7MZ33G40@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 14:40:15 -0800 (PST)
Received: from triplex.local (triplex [127.0.0.1])
	by triplex.local (8.14.3+Sun/8.14.3) with ESMTP id nBNMeFbr552772; Wed,
 23 Dec 2009 14:40:15 -0800 (PST)
Received: (from meem@localhost)	by triplex.local (8.14.3+Sun/8.14.3/Submit)
 id nBNMeFh2552759; Wed, 23 Dec 2009 14:40:15 -0800 (PST)
Date: Wed, 23 Dec 2009 14:40:15 -0800
From: Peter Memishian <peter.memishian@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <4B329AEB.708@sun.com>
To: Alan Coopersmith <Alan.Coopersmith@sun.com>
Cc: peter.memishian@sun.com, James Carlson <carlsonj@workingcode.com>,
        Casper.Dik@sun.com, PSARC-ext@sun.com
Reply-to: peter.memishian@sun.com
Message-id: <19250.40015.608964.681216@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.19 under 21.4 (patch 21) "Educational Television" XEmacs Lucid
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com>
X-Authentication-warning: triplex.local: meem set sender to
 peter.memishian@sun.com using -f
Status: RO
Content-Length: 825


 > > I could see doing this on a subset of well-controlled applications, but
 > > what happens when a customer using this facility wants some Sun-supported
 > > application that happens to use loopback inet IPC to "work"?  Are we going
 > > to change the code to accommodate their need, or tell them they're off the
 > > reservation? 
 > 
 > How would this be any different than if they tried removing other basic
 > privileges, like the ability to fork() or exec(), from apps that really
 > needed it?   If customers break their system, it's broken.

The difference is that removing the ability to fork() and exec() does
exactly that.  This privilege removes the ability to communicate on the
network, and removes one of the mechanisms for IPC that has nothing
inherently to do with communicating on the network.

-- 
meem

From carlsonj@workingcode.com Wed Dec 23 14:43:46 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNMhjmV029315
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 14:43:46 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNMhhWe022409;
	Wed, 23 Dec 2009 14:43:43 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400J05N4VWW00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 14:43:43 -0800 (PST)
Received: from sca-ea-mail-2.sun.com ([192.18.43.25])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400FZ8N4V3G50@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 14:43:43 -0800 (PST)
Received: from relay44i.sun.com ([192.5.209.118])
	by sca-ea-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id nBNMcUKp023897;
 Wed, 23 Dec 2009 22:43:43 +0000 (GMT)
Received: from mmp43es.mmp.us.syntegra.com ([160.41.221.12] [160.41.221.12])
 by relay44i.sun.com with ESMTP id BT-MMP-4628243; Wed,
 23 Dec 2009 22:43:42 +0000 (Z)
Received: from relay43i.sun.com (relay43i.sun.com [192.5.209.74])
 by mmp43es.mmp.us.syntegra.com with ESMTP id BT-MMP-12019440; Wed,
 23 Dec 2009 22:43:42 +0000 (Z)
Received: from carlson.workingcode.com ([75.150.68.97] [75.150.68.97])
 by relay4i.sun.com with ESMTP id BT-MMP-19279933; Wed,
 23 Dec 2009 22:43:42 +0000 (Z)
Received: from [10.50.24.188] (gate.abinitio.com [65.170.40.132])
	(authenticated bits=0)	by carlson.workingcode.com (8.14.2+Sun/8.14.3)
 with ESMTP id nBNMhfem015795
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed,
 23 Dec 2009 17:43:41 -0500 (EST)
Date: Wed, 23 Dec 2009 17:43:41 -0500
From: James Carlson <carlsonj@workingcode.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <19250.39229.677.800898@gargle.gargle.HOWL>
To: peter.memishian@sun.com
Cc: Casper.Dik@sun.com, PSARC-ext@sun.com
Message-id: <4B329D1D.4010205@workingcode.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-DCC-dmv.com-Metrics: carlson; whitelist
X-Antispam: No, score=-0.2/5.0, scanned in 0.067sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.22 (X11/20090605)
Status: RO
Content-Length: 1811

Peter Memishian wrote:
>  > > should not having "network privileges" prevent applications from being
>  > > used for local purposes?  Further, the set of impacted applications will
>  > > be essentially random based on the whim of the IPC mechanism used by its
>  > > implementors.
>  > 
>  > I think what Casper is arguing is that this doesn't actually matter.
>  > Someone who wants to revoke this privilege for some process will need to
>  > test the application (and perhaps examine its source code) in order to
>  > determine whether doing so is feasible.  If that's done right, you'd
>  > have no problems.
> 
> ... and repeat the exhaustive evaluation every time it's patched.

Yep.  That's LP for you.  It gets right into the implementation details.

> I could see doing this on a subset of well-controlled applications, but
> what happens when a customer using this facility wants some Sun-supported
> application that happens to use loopback inet IPC to "work"?  Are we going
> to change the code to accommodate their need, or tell them they're off the
> reservation?

Good question; I have no idea.  I suspect it would be an RFE, like any
other, and the priority set based on how important the customer is, how
motivated you are to fix it, and so on.

>  So long as it's the latter, and this is made clear up-front,
> I don't have a strong objection to Casper's proposal, though I still fear
> that the loopback inet IPC restriction will cause unexpected problems for
> applications that just happen to use that mechanism for their IPC.

Sure.  But that's true of just about all of the LP bits, particularly
those things (like this one) in the "basic" privilege set.  Anything
less than "basic" isn't really UNIX anymore.

-- 
James Carlson         42.703N 71.076W         <carlsonj@workingcode.com>

From john.plocher@gmail.com Wed Dec 23 15:01:12 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNN1Bl7029757
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 15:01:12 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id nBNN19TT040419;
	Wed, 23 Dec 2009 16:01:09 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV40011XNXXNO00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 15:01:09 -0800 (PST)
Received: from sca-ea-mail-3.sun.com ([192.18.43.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400FJ4NXV3GC0@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 15:01:07 -0800 (PST)
Received: from relay11i.sun.com
 (ip121.net129179-4.block1.us.syntegra.com [129.179.4.121])
	by sca-ea-mail-3.sun.com (8.13.6+Sun/8.12.9) with ESMTP id nBNMu2ol002047;
 Wed, 23 Dec 2009 23:01:07 +0000 (GMT)
Received: from mmp14es.mmp.us.syntegra.com ([160.41.208.14] [160.41.208.14])
 by relay11i.sun.com with ESMTP id BT-MMP-9604995; Wed,
 23 Dec 2009 23:01:06 +0000 (Z)
Received: from relay13i.sun.com (relay13i.sun.com [129.179.4.123])
 by mmp14es.mmp.us.syntegra.com with ESMTP id BT-MMP-187105; Wed,
 23 Dec 2009 23:01:06 +0000 (Z)
Received: from mail-qy0-f179.google.com ([209.85.221.179] [209.85.221.179])
 by relay1i.sun.com with ESMTP id BT-MMP-17439865; Wed,
 23 Dec 2009 23:01:06 +0000 (Z)
Received: by qyk9 with SMTP id 9so3713894qyk.30 for <multiple recipients>; Wed,
 23 Dec 2009 15:01:00 -0800 (PST)
Received: by 10.229.9.85 with SMTP id k21mr265505qck.69.1261609260789; Wed,
 23 Dec 2009 15:01:00 -0800 (PST)
Date: Wed, 23 Dec 2009 15:01:00 -0800
From: John Plocher <john.plocher@gmail.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <4B329AEB.708@sun.com>
To: Alan Coopersmith <Alan.Coopersmith@sun.com>
Cc: peter.memishian@sun.com, PSARC-ext@sun.com, Casper.Dik@sun.com
Message-id: <acff61d30912231501j5b374cddya0b89fb17e336984@mail.gmail.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com;
 s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references
 :date:message-id:subject:from:to:cc:content-type;
 bh=TrveOJT4jKc87xTmGq3IxtcN4p44zZO6YAqOqvtt8tU=;
 b=JICNWvdF0mTfEciIdo/Hk5wB1Z/fVqedv0DE+brdP2RHYprsV43CUFb0AzvD/GZ9PE
 oIc84abQmBE3Ts6VEipiD3IhtOkWnaeoJRyC3aeOUdBYTSRDSM2ZvPwNnyoud5ui78Eb
 j0yq3tluo6jrXjFhXKk8grpi+fDCPrr8NzDtA=
DomainKey-Signature: a=rsa-sha1; c=nofws;        d=gmail.com; s=gamma;
 h=mime-version:in-reply-to:references:date:message-id:subject:from:to
 :cc:content-type;
 b=Lr5UXesyYtY3o81PKRvSy0qbP148J705O6zbw/3i/RoDn63q1x1H1ZLb+sRHEQALZh
 V1RhYXPJ1bRKiDINDomcyijBGxZ2EWhs2Tq41l89WyQ3qvLVwi/+EJYY9Ze1Wjof2/mu
 LbqyfbmG2Nn0RguemtGTfdcBdUUErOx/7TPhA=
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Antispam: No, score=0.0/5.0, scanned in 0.062sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com>
Status: RO
Content-Length: 1246

What is the basic use case for this priv?  Is it to let the admin
"sandbox" somebody away from the network for security reasons, or is
it a simple debugging tool to force-fail programs that use any form of
networking? If the former,  if it also disables key parts of the
system that happen to use IPC in their implementation, it won't
actually be useful; if the latter,  have you characterized what parts
of the system are disabled by it?  Will a JVM even run?  What about a
graphical desktop?  Is there anything that can be usefully done on the
system if this priv is not available?

Maybe there needs to be both a "Local IPC Priv" for loopback usage and
a "Network Priv" for all others...


On Wed, Dec 23, 2009 at 2:34 PM, Alan Coopersmith
<Alan.Coopersmith@sun.com> wrote:
> How would this be any different than if they tried removing other basic
> privileges, like the ability to fork() or exec(), from apps that really
> needed it?   If customers break their system, it's broken.


I think the difference is that for those, the set of system middleware
we provide doesn't silently rely on them for proper operation;
loopback IPC isn't something (like exec()) that is an obvious side
effect or implementation detail in a library...

  -John

From Sebastien.Roy@sun.com Wed Dec 23 15:02:01 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNN20FZ029770
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 15:02:00 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNN1xiM008386
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 23 Dec 2009 15:02:00 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400C0JNZCI800@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 23 Dec 2009 15:02:00 -0800 (PST)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400CJCNZAHID0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 23 Dec 2009 15:01:59 -0800 (PST)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id nBNN1wXM000895	for
 <PSARC-ext@sun.com>; Wed, 23 Dec 2009 23:01:58 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KV400D00NFE4G00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 23 Dec 2009 16:01:58 -0700 (MST)
Received: from [192.168.1.5] ([unknown] [173.76.16.34])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.04 64bit
 (built Jul  2 2009)) with ESMTPSA id <0KV4005RZNYC7C50@mail-amer.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 23 Dec 2009 16:01:25 -0700 (MST)
Date: Wed, 23 Dec 2009 18:01:23 -0500
From: Sebastien Roy <Sebastien.Roy@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <19250.40015.608964.681216@gargle.gargle.HOWL>
Sender: Sebastien.Roy@sun.com
To: Peter.Memishian@sun.com
Cc: Alan Coopersmith <Alan.Coopersmith@sun.com>, PSARC-ext@sun.com,
        Casper.Dik@sun.com
Message-id: <1261609283.1060.35.camel@seb>
Organization: Sun Microsystems
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
Status: RO
Content-Length: 1316

On Wed, 2009-12-23 at 14:40 -0800, Peter Memishian wrote:
> > > I could see doing this on a subset of well-controlled applications, but
>  > > what happens when a customer using this facility wants some Sun-supported
>  > > application that happens to use loopback inet IPC to "work"?  Are we going
>  > > to change the code to accommodate their need, or tell them they're off the
>  > > reservation? 
>  > 
>  > How would this be any different than if they tried removing other basic
>  > privileges, like the ability to fork() or exec(), from apps that really
>  > needed it?   If customers break their system, it's broken.
> 
> The difference is that removing the ability to fork() and exec() does
> exactly that.  This privilege removes the ability to communicate on the
> network, and removes one of the mechanisms for IPC that has nothing
> inherently to do with communicating on the network.

That is essentially the point I was initially making.

I personally don't have any issue with the privilege as defined assuming
that it's part of the basic privilege set.  There would be a fundamental
problem with the proposal if the problem that needed to be solved by the
project teem included allowing local network access.

This proposal doesn't prevent solving that problem in a different way,
however.

-Seb



From Alan.Coopersmith@sun.com Wed Dec 23 15:20:36 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNNKa9e029840
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 15:20:36 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNNKZdk017072
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 23 Dec 2009 15:20:36 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400N03OUB2B00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 23 Dec 2009 16:20:35 -0700 (MST)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400G9TOUBE430@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 23 Dec 2009 16:20:35 -0700 (MST)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id nBNNKYva011744	for
 <PSARC-ext@sun.com>; Wed, 23 Dec 2009 15:20:34 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KV400700ONEVG00@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 23 Dec 2009 15:20:34 -0800 (PST)
Received: from [10.6.102.27] ([unknown] [10.6.102.27])
 by fe-sfbay-09.sun.com (Sun Java(tm) System Messaging Server 7u2-7.04 64bit
 (built Jul  2 2009)) with ESMTPSA id <0KV4000VAOUA5P30@fe-sfbay-09.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 23 Dec 2009 15:20:34 -0800 (PST)
Date: Wed, 23 Dec 2009 15:20:34 -0800
From: Alan Coopersmith <Alan.Coopersmith@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <acff61d30912231501j5b374cddya0b89fb17e336984@mail.gmail.com>
Sender: Alan.Coopersmith@sun.com
To: John Plocher <john.plocher@gmail.com>
Cc: Peter.Memishian@sun.com, PSARC-ext@sun.com, Casper.Dik@sun.com
Message-id: <4B32A5C2.7030202@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Enigmail-Version: 0.95.1
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com>
 <acff61d30912231501j5b374cddya0b89fb17e336984@mail.gmail.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20090926)
Status: RO
Content-Length: 1022

John Plocher wrote:
> What is the basic use case for this priv?

I assumed it was to let setuid programs have one more thing they could
give up, to reduce the number of things an exploit could do if you did
find a security hole in them that allowed running arbitrary code, like
most of the rest of the "basic" privileges.

> On Wed, Dec 23, 2009 at 2:34 PM, Alan Coopersmith
> <Alan.Coopersmith@sun.com> wrote:
>> How would this be any different than if they tried removing other basic
>> privileges, like the ability to fork() or exec(), from apps that really
>> needed it?   If customers break their system, it's broken.
> 
> I think the difference is that for those, the set of system middleware
> we provide doesn't silently rely on them for proper operation;

Just various non-obvious functions in libc().   (Do you think most programmers
realize wordexp(), pututxline() or grantpt() call fork+exec?)

-- 
	-Alan Coopersmith-           alan.coopersmith@sun.com
	 Sun Microsystems, Inc. - X Window System Engineering


From erik.nordmark@sun.com Wed Dec 23 15:55:59 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBNNtx2w000289
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 15:55:59 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBNNtvdh018167;
	Wed, 23 Dec 2009 15:55:57 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400305QH9WL00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 15:55:57 -0800 (PST)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV4002K3QH75F00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 23 Dec 2009 15:55:55 -0800 (PST)
Received: from [10.7.251.248] (punchin-nordmark.SFBay.Sun.COM [10.7.251.248])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id nBNNts51236786
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed,
 23 Dec 2009 15:55:55 -0800 (PST)
Date: Wed, 23 Dec 2009 15:55:54 -0800
From: Erik Nordmark <erik.nordmark@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912232110.nBNLA3o3012841@dm-holland-02.uk.sun.com>
To: Casper.Dik@sun.com
Cc: Casper Dik <casper@sac.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <4B32AE0A.50005@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
 <4B327A8C.90704@sun.com> <200912232110.nBNLA3o3012841@dm-holland-02.uk.sun.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20091124)
Status: RO
Content-Length: 1399

Casper.Dik@Sun.COM wrote:
> 
>> I don't understand the motivation for excluding the raw sockets and/or 
>> icmp sockets from checking NET_ACCESS. It seems simpler from a user 
>> perspective if removing NET_ACCESS has the effect of making the user no 
>> longer be able to open any TCP, UDP, SCTP, or RAW sockets.
> 
> Because you already need a privilege and there's no need to remove those 
> privileges?

But it makes the description of NET_ACCESS much more complicated; not 
only do we have PRIV_NET_RAWACCESS but also PRIV_NET_ICMPACCESS.

If we uniformly apply NET_ACCESS for all IP based transports then there 
is a single privilege that needs to be removed to ensure that IP 
networking can not be used.

>> Thus I think it makes sense removing the above exception.
>>
>>
>> Do we know if there is any impact to getaddrinfo() and friends? I 
>> believe the library code opens a UDP socket to issue SIOC ioctls (done 
>> as part of verifying whether IPv4 and/or IPv6 is configured on the 
>> system). Perhaps that isn't an architectural issue, but we need to make 
>> sure there aren't any confusing failures or error messages when 
>> NET_ACCESS has been removed from the privilege set.
> 
> If the library detects that opening /dev/udp{,6} fails it will pretend that 
> there are IP/IP6 interfaces and the application will find the hostname but 
> won't be able to connect.  

OK

    Erik

From john.plocher@gmail.com Wed Dec 23 16:05:23 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBO05NUb000437
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 16:05:23 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBO05NWf006276;
	Wed, 23 Dec 2009 16:05:23 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400407QWZQV00@brm-avmta-1.central.sun.com>; Wed,
 23 Dec 2009 17:05:23 -0700 (MST)
Received: from sca-ea-mail-2.sun.com ([192.18.43.25])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400G24QWYDT50@brm-avmta-1.central.sun.com>; Wed,
 23 Dec 2009 17:05:22 -0700 (MST)
Received: from relay11i.sun.com
 (ip121.net129179-4.block1.us.syntegra.com [129.179.4.121])
	by sca-ea-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id nBNNvTct005838;
 Thu, 24 Dec 2009 00:05:22 +0000 (GMT)
Received: from mmp12es.mmp.us.syntegra.com ([160.41.208.12] [160.41.208.12])
 by relay11i.sun.com with ESMTP id BT-MMP-9607907; Thu,
 24 Dec 2009 00:05:22 +0000 (Z)
Received: from relay14i.sun.com (relay14i.sun.com [129.179.4.124])
 by mmp12es.mmp.us.syntegra.com with ESMTP id BT-MMP-16004867; Thu,
 24 Dec 2009 00:05:21 +0000 (Z)
Received: from mail-qy0-f179.google.com ([209.85.221.179] [209.85.221.179])
 by relay1i.sun.com with ESMTP id BT-MMP-17477291; Thu,
 24 Dec 2009 00:05:21 +0000 (Z)
Received: by qyk9 with SMTP id 9so3759586qyk.30 for <multiple recipients>; Wed,
 23 Dec 2009 16:05:12 -0800 (PST)
Received: by 10.229.39.69 with SMTP id f5mr4618201qce.107.1261613112297; Wed,
 23 Dec 2009 16:05:12 -0800 (PST)
Date: Wed, 23 Dec 2009 16:05:12 -0800
From: John Plocher <john.plocher@gmail.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <4B32A5C2.7030202@sun.com>
To: Alan Coopersmith <Alan.Coopersmith@sun.com>
Cc: PSARC-ext@sun.com
Message-id: <acff61d30912231605m33c94afbpa8971650aa10d171@mail.gmail.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com;
 s=gamma; h=domainkey-signature:mime-version:received:in-reply-to:references
 :date:message-id:subject:from:to:cc:content-type :content-transfer-encoding;
 bh=cyc6ZE+9fPjpGXz1xy6E/p8p6fRybLk8f7gBFz25kKA=;
 b=DoTyq+m0iEnCXaIG7oL5bSgXL5IGD9epdNGjIzMcvquZlISKmCJIQPSy2SYbO4l2Ud
 62R9M8C86b07swuEa7B8IhlcHo5nUcBS+VgxwN5ICp/sx8gWN/xuqHaHjVPmzl1zJEt0
 ubYtNRIYPA6y/jBQT3SdCSBCf1ybtfzhEcfF8=
DomainKey-Signature: a=rsa-sha1; c=nofws;        d=gmail.com; s=gamma;
 h=mime-version:in-reply-to:references:date:message-id:subject:from:to
 :cc:content-type:content-transfer-encoding;
 b=xLfl8rRIrTOttOVJBXcz1cCc7x6gHuno+JGiCWuguY4RRjeM1mT+Ren+Iai/oIi2Ih
 9JKLZy5yX5PiWE/xtbPhrySLo9XrPnbWrMXBVda2uuqe/znYhvTRW4IZi8B3/ku60ziC
 y60ibV5FToqkIRSRhkCfB/cv2SjSMsLhfFXog=
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Antispam: No, score=0.0/5.0, scanned in 0.062sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com>
 <acff61d30912231501j5b374cddya0b89fb17e336984@mail.gmail.com>
 <4B32A5C2.7030202@sun.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by sac.sfbay.sun.com id nBO05NUb000437
Status: RO
Content-Length: 1487

> Just various non-obvious functions in libc().   (Do you think most programmers
> realize wordexp(), pututxline() or grantpt() call fork+exec?)

This is a reasonable characterization of what happens if you lose the
fork and exec privs - a few things break, some of which are obvious
(i.e., fork() no longer works) and some less so.  Somewhere there is a
list of things in the system that fail if you don't have those privs
AND there is nothing on that list that causes angst.

Is there a similar list of OpenSolaris-provided lib routines that will
fail if you don't have network privs?  Is there anything on that list
that comes as a surprise?  Without a list (which doesn't need to be
exhaustive, just typical), how can we evaluate the usefulness/impact
of this priv? At an extreme, if  lose_priv("networking") is
effectively equivalent to halt() because nothing in the system works
without it, then I'd question the usefulness of this priv.  I don't
believe things are that ridiculously extreme, but the discussions
about loopback and IF_UNIX make me wonder what the real, effective
impact is.  What system lib routines will now fail unexpectedly
without network privs in the same way that wordexp() fails without
fork()/exec() privs?

The bottom line, to me, is:

    If I need to disable networking privs in my app, but doing so
disables other
    OpenSolaris things that I can't live without as a side effect,
then the networking
    priv isn't as useful as it could be.

  -John


From peter.memishian@sun.com Wed Dec 23 16:20:41 2009
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBO0KfB1000519
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 16:20:41 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBO0KcVB005633;
	Wed, 23 Dec 2009 18:20:38 -0600 (CST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400J03RMES700@nwk-avmta-2.sfbay.sun.com>; Wed,
 23 Dec 2009 16:20:38 -0800 (PST)
Received: from triplex.local ([129.146.108.208]) by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400FPHRMEW220@nwk-avmta-2.sfbay.sun.com>; Wed,
 23 Dec 2009 16:20:38 -0800 (PST)
Received: from triplex.local (triplex [127.0.0.1])
	by triplex.local (8.14.3+Sun/8.14.3) with ESMTP id nBO0KcTF750250; Wed,
 23 Dec 2009 16:20:38 -0800 (PST)
Received: (from meem@localhost)	by triplex.local (8.14.3+Sun/8.14.3/Submit)
 id nBO0KcMt750237; Wed, 23 Dec 2009 16:20:38 -0800 (PST)
Date: Wed, 23 Dec 2009 16:20:38 -0800
From: Peter Memishian <peter.memishian@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <4B329D1D.4010205@workingcode.com>
To: James Carlson <carlsonj@workingcode.com>
Cc: peter.memishian@sun.com, Casper.Dik@sun.com, PSARC-ext@sun.com
Reply-to: peter.memishian@sun.com
Message-id: <19250.46038.400919.651012@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.19 under 21.4 (patch 21) "Educational Television" XEmacs Lucid
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329D1D.4010205@workingcode.com>
X-Authentication-warning: triplex.local: meem set sender to
 peter.memishian@sun.com using -f
Status: RO
Content-Length: 815


 > Sure.  But that's true of just about all of the LP bits, particularly
 > those things (like this one) in the "basic" privilege set.  Anything
 > less than "basic" isn't really UNIX anymore.

Yes, but my concern isn't about whether it's UNIX, it's about whether it's
reasonable to expect that an application's local IPC mechanism stops
working because one wants to control the ability for that application to
access the network.  Personally, I don't find it reasonable and I supect
we're only having this discussion because separating the two cases is more
difficult implementation-wise.  Of course, I'm not on PSARC and thus my
personal opinion is irrelevant.  As such, rather than argue this one in
circles, I'll defer to those on the ARC to decide whether is a big enough
issue to hold up the case.

-- 
meem

From peter.memishian@sun.com Wed Dec 23 16:26:48 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBO0QmrV000629
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 16:26:48 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBO0Qj6l015106;
	Wed, 23 Dec 2009 16:26:45 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV400K01RWL7B00@nwk-avmta-2.sfbay.sun.com>; Wed,
 23 Dec 2009 16:26:45 -0800 (PST)
Received: from triplex.local ([129.146.108.208]) by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV400FVHRWLW020@nwk-avmta-2.sfbay.sun.com>; Wed,
 23 Dec 2009 16:26:45 -0800 (PST)
Received: from triplex.local (triplex [127.0.0.1])
	by triplex.local (8.14.3+Sun/8.14.3) with ESMTP id nBO0QjUt816366; Wed,
 23 Dec 2009 16:26:45 -0800 (PST)
Received: (from meem@localhost)	by triplex.local (8.14.3+Sun/8.14.3/Submit)
 id nBO0QjHV816353; Wed, 23 Dec 2009 16:26:45 -0800 (PST)
Date: Wed, 23 Dec 2009 16:26:44 -0800
From: Peter Memishian <peter.memishian@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <1261609283.1060.35.camel@seb>
To: Sebastien Roy <Sebastien.Roy@sun.com>
Cc: peter.memishian@sun.com, Alan Coopersmith <Alan.Coopersmith@sun.com>,
        PSARC-ext@sun.com, Casper.Dik@sun.com
Reply-to: peter.memishian@sun.com
Message-id: <19250.46404.991443.341753@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.19 under 21.4 (patch 21) "Educational Television" XEmacs Lucid
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <1261609283.1060.35.camel@seb>
X-Authentication-warning: triplex.local: meem set sender to
 peter.memishian@sun.com using -f
Status: RO
Content-Length: 832


 > I personally don't have any issue with the privilege as defined assuming
 > that it's part of the basic privilege set.  There would be a fundamental
 > problem with the proposal if the problem that needed to be solved by the
 > project teem included allowing local network access.

Regardless of whether it's in the basic privilege set, the question
remains of how we would handle a support call from a customer trying to
use this privilege to restrict network communication and tripping over the
IPC issue.  If we support that, then we have effectively added a new
constraint that all future projects need to consider when selecting their
IPC mechanism[1].

[1] Loopback inet IPC is actually a fairly useful beast since it allows
    cooperating applications to rendezvous without requiring a writable
    fileystem.

-- 
meem

From Scott.Rotondo@sun.com Wed Dec 23 22:49:22 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBO6nMEp005028
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 23 Dec 2009 22:49:22 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBO6nMeO012452
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 23 Dec 2009 22:49:22 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV50020B9MA3G00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 23 Dec 2009 22:49:22 -0800 (PST)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV500FNC9M9IYE0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 23 Dec 2009 22:49:22 -0800 (PST)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id nBO6nLOn011654	for
 <PSARC-ext@sun.com>; Thu, 24 Dec 2009 06:49:21 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KV5005009C8PM00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 23 Dec 2009 23:49:21 -0700 (MST)
Received: from viaggio.local ([unknown] [69.226.236.206])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.04 64bit
 (built Jul  2 2009)) with ESMTPSA id <0KV5000IJ9M8NH20@mail-amer.sun.com>; Wed,
 23 Dec 2009 23:49:21 -0700 (MST)
Date: Wed, 23 Dec 2009 22:49:35 -0800
From: Scott Rotondo <Scott.Rotondo@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <4B30E272.3060202@sun.com>
Sender: Scott.Rotondo@sun.com
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: Casper Dik <casper@sac.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <4B330EFF.10206@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
 <4B30E272.3060202@sun.com>
User-Agent: Thunderbird 2.0.0.23 (Macintosh/20090812)
Status: RO
Content-Length: 1037

Garrett D'Amore wrote:
> This seems like a good idea, but out of curiosity, is there a specific 
> motivation here?

For any basic privilege, the high-level motivation is to be able to 
limit processes (or users) by removing functionality that normally 
requires no privileges. In this case, that functionality is the ability 
to open network connections.

I know of at least one customer who used to accomplish this in previous 
Solaris releases by restricting the permission bits on /dev/tcp. [1] 
It's worth re-examining Meem's objection about IPC in light of customers 
like this. When this basic privilege is available, they might well 
remove it from all user processes in order to get the same effect they 
had before. How much IPC breakage is likely to follow from this action?

	Scott


[1] This technique doesn't work any more because socket() operations do 
not open /dev/tcp.

-- 
Scott Rotondo
Principal Engineer, Solaris Security Technologies
President, Trusted Computing Group
Phone/FAX: +1 408 850 3655 (Internal x68278)

From casper@holland.sun.com Thu Dec 24 01:43:58 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBO9hwoH021190
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 24 Dec 2009 01:43:58 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id nBO9hvu7053448
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Thu, 24 Dec 2009 02:43:57 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV500D01HP98100@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Thu, 24 Dec 2009 01:43:57 -0800 (PST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV5003ABHP81P60@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Thu,
 24 Dec 2009 01:43:57 -0800 (PST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBO9hrwf023965; Thu, 24 Dec 2009 09:43:53 +0000 (GMT)
Date: Thu, 24 Dec 2009 10:43:53 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <4B32A5C2.7030202@sun.com>
Sender: casper@holland.sun.com
To: Alan Coopersmith <Alan.Coopersmith@sun.com>
Cc: John Plocher <john.plocher@gmail.com>, Peter.Memishian@sun.com,
        PSARC-ext@sun.com
Message-id: <200912240943.nBO9hrwf023965@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com>
 <acff61d30912231501j5b374cddya0b89fb17e336984@mail.gmail.com>
 <4B32A5C2.7030202@sun.com>
Status: RO
Content-Length: 1466


>John Plocher wrote:
>> What is the basic use case for this priv?
>
>I assumed it was to let setuid programs have one more thing they could
>give up, to reduce the number of things an exploit could do if you did
>find a security hole in them that allowed running arbitrary code, like
>most of the rest of the "basic" privileges.

It is also possible to contain users in a "can't break out" shell; they 
can run their application but they cannot copy data outside of the machine.

In Solaris 8 you can get this functionality by adding an ACL to /dev/tcp;


>> I think the difference is that for those, the set of system middleware
>> we provide doesn't silently rely on them for proper operation;
>
>Just various non-obvious functions in libc().   (Do you think most programmers
>realize wordexp(), pututxline() or grantpt() call fork+exec?)


Absolutely; I think, though, that grantpt() no longer calls exec: pt_chmod 
is gone (or is it now running devfsadm).

Having testing the net_access privilege, I can say that few library calls 
use AF_INET sockets for IPC.  Note that localhost RPC will not use AF_INET;
name service lookups will use sockets but you nscd will do it for you.

With cscope, I wasn't able to find a library routine which uses networking
as IPC without clearly being a network function.

But even such interface exists, I don't believe that that is fatal to this 
proposal; similarly to issues with wordexp(), pututxline(), grantpt().

Casper


From casper@holland.sun.com Thu Dec 24 01:57:24 2009
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBO9vOW7021527
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 24 Dec 2009 01:57:24 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBO9vLoQ029360
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Thu, 24 Dec 2009 03:57:24 -0600 (CST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV50010HIBNHC00@brm-avmta-1.central.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Thu, 24 Dec 2009 02:57:23 -0700 (MST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV500LYZIBM7N10@brm-avmta-1.central.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Thu,
 24 Dec 2009 02:57:22 -0700 (MST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBO9vI30027046; Thu, 24 Dec 2009 09:57:19 +0000 (GMT)
Date: Thu, 24 Dec 2009 10:57:18 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <19250.46404.991443.341753@gargle.gargle.HOWL>
Sender: casper@holland.sun.com
To: Peter.Memishian@sun.com
Cc: Sebastien Roy <Sebastien.Roy@sun.com>,
        Alan Coopersmith <Alan.Coopersmith@sun.com>, PSARC-ext@sun.com
Message-id: <200912240957.nBO9vI30027046@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <1261609283.1060.35.camel@seb> <19250.46404.991443.341753@gargle.gargle.HOWL>
Status: RO
Content-Length: 779



>[1] Loopback inet IPC is actually a fairly useful beast since it allows
>    cooperating applications to rendezvous without requiring a writable
>    fileystem.

Much of our stack uses loopback RPC and this works fine; loopback inet is 
more difficult to use, particularly because it requires a well-known port.

I would love to see an example of current use of AF_INET  loopback as an IPC 
mechanism.  Note also that we try to make sure that non of the internal 
IPC mechanisms don't listen to the world; AF_INET isn't the easiest way to 
achieve that)

Note that the current RFE 6434380 was initially filed for both network
and IPC; but since there are so many way to construct local IPC, e.g.,
using a mmap'ed queue, there seems to be no easy way to enforce this.

Casper


From casper@holland.sun.com Thu Dec 24 02:17:31 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBOAHVp8021760
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 24 Dec 2009 02:17:31 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id nBOAHUXv009691;
	Thu, 24 Dec 2009 03:17:30 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV500A01J95R500@nwk-avmta-1.sfbay.Sun.COM>; Thu,
 24 Dec 2009 02:17:29 -0800 (PST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV500N9SJ940Q20@nwk-avmta-1.sfbay.Sun.COM>; Thu,
 24 Dec 2009 02:17:29 -0800 (PST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBOAHQpa002514; Thu, 24 Dec 2009 10:17:26 +0000 (GMT)
Date: Thu, 24 Dec 2009 11:17:26 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <4B330EFF.10206@sun.com>
Sender: casper@holland.sun.com
To: Scott Rotondo <Scott.Rotondo@sun.com>
Cc: "Garrett D'Amore" <gdamore@sun.com>, Casper Dik <casper@sac.sfbay.sun.com>,
        PSARC-ext@sun.com
Message-id: <200912241017.nBOAHQpa002514@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
 <4B30E272.3060202@sun.com> <4B330EFF.10206@sun.com>
Status: RO
Content-Length: 710



>I know of at least one customer who used to accomplish this in previous 
>Solaris releases by restricting the permission bits on /dev/tcp. [1] 
>It's worth re-examining Meem's objection about IPC in light of customers 
>like this. When this basic privilege is available, they might well 
>remove it from all user processes in order to get the same effect they 
>had before. How much IPC breakage is likely to follow from this action?

My experience is that there is very little, if any, breakage.



>[1] This technique doesn't work any more because socket() operations do 
>not open /dev/tcp.


In Solaris 10, we still open evaluate the device policy; but in Volo, we 
never get near to /dev/tcp.

Casper


From casper@holland.sun.com Thu Dec 24 02:51:57 2009
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBOApvBm021837
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 24 Dec 2009 02:51:57 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBOApuUS029032
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Thu, 24 Dec 2009 04:51:57 -0600 (CST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV500H09KUKXG00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Thu, 24 Dec 2009 02:51:56 -0800 (PST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV5003NXKUJ1O90@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Thu,
 24 Dec 2009 02:51:56 -0800 (PST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBOAprSu010669; Thu, 24 Dec 2009 10:51:53 +0000 (GMT)
Date: Thu, 24 Dec 2009 11:51:53 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <4B32AE0A.50005@sun.com>
Sender: casper@holland.sun.com
To: Erik Nordmark <Erik.Nordmark@sun.com>
Cc: PSARC-ext@sun.com
Message-id: <200912241051.nBOAprSu010669@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
 <4B327A8C.90704@sun.com>
 <200912232110.nBNLA3o3012841@dm-holland-02.uk.sun.com> <4B32AE0A.50005@sun.com>
Status: RO
Content-Length: 609



>But it makes the description of NET_ACCESS much more complicated; not 
>only do we have PRIV_NET_RAWACCESS but also PRIV_NET_ICMPACCESS.

I'm not sure that this more complicated by any stretch of imagination.

+     PRIV_NET_ACCESS
+       Allows a process to open an unprivileged network connection.
+


>If we uniformly apply NET_ACCESS for all IP based transports then there 
>is a single privilege that needs to be removed to ensure that IP 
>networking can not be used.

Requiring multiple privileges for a specific operation runs against the 
grain of the Solaris privilege implementation.


Casper


From peter.memishian@sun.com Thu Dec 24 08:26:45 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBOGQjUY025385
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 24 Dec 2009 08:26:45 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBOGQgsq021227;
	Thu, 24 Dec 2009 08:26:43 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV600L010CG4E00@brm-avmta-1.central.sun.com>; Thu,
 24 Dec 2009 09:26:40 -0700 (MST)
Received: from triplex.local ([129.146.108.208]) by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV600F2O0CGW930@brm-avmta-1.central.sun.com>; Thu,
 24 Dec 2009 09:26:40 -0700 (MST)
Received: from triplex.local (triplex [127.0.0.1])
	by triplex.local (8.14.3+Sun/8.14.3) with ESMTP id nBOGQdmL442422; Thu,
 24 Dec 2009 08:26:39 -0800 (PST)
Received: (from meem@localhost)	by triplex.local (8.14.3+Sun/8.14.3/Submit)
 id nBOGQdxN442409; Thu, 24 Dec 2009 08:26:39 -0800 (PST)
Date: Thu, 24 Dec 2009 08:26:39 -0800
From: Peter Memishian <peter.memishian@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912240957.nBO9vI30027046@dm-holland-02.uk.sun.com>
To: Casper.Dik@sun.com
Cc: peter.memishian@sun.com, Sebastien Roy <Sebastien.Roy@sun.com>,
        Alan Coopersmith <Alan.Coopersmith@sun.com>, PSARC-ext@sun.com
Reply-to: peter.memishian@sun.com
Message-id: <19251.38463.817988.397644@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.19 under 21.4 (patch 21) "Educational Television" XEmacs Lucid
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <1261609283.1060.35.camel@seb> <19250.46404.991443.341753@gargle.gargle.HOWL>
 <200912240957.nBO9vI30027046@dm-holland-02.uk.sun.com>
X-Authentication-warning: triplex.local: meem set sender to
 peter.memishian@sun.com using -f
Status: RO
Content-Length: 276


 > I would love to see an example of current use of AF_INET  loopback as an IPC 
 > mechanism.

Both in.mpathd and dhcpagent use this mechanism.  Of course, they are both
networking daemons, but the IPC channel has nothing to do with them being
networking daemons.

-- 
meem

From casper@holland.sun.com Thu Dec 24 09:07:10 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBOH7Axt026016
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 24 Dec 2009 09:07:10 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBOH7ADo028217
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Thu, 24 Dec 2009 09:07:10 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV60070F27XR000@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Thu, 24 Dec 2009 09:07:09 -0800 (PST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV600JGN27WYTE0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Thu,
 24 Dec 2009 09:07:09 -0800 (PST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBOH75Je006250; Thu, 24 Dec 2009 17:07:05 +0000 (GMT)
Date: Thu, 24 Dec 2009 18:07:05 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <19251.38463.817988.397644@gargle.gargle.HOWL>
Sender: casper@holland.sun.com
To: Peter.Memishian@sun.com
Cc: Sebastien Roy <Sebastien.Roy@sun.com>,
        Alan Coopersmith <Alan.Coopersmith@sun.com>, PSARC-ext@sun.com
Message-id: <200912241707.nBOH75Je006250@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <1261609283.1060.35.camel@seb> <19250.46404.991443.341753@gargle.gargle.HOWL>
 <200912240957.nBO9vI30027046@dm-holland-02.uk.sun.com>
 <19251.38463.817988.397644@gargle.gargle.HOWL>
Status: RO
Content-Length: 403


>
> > I would love to see an example of current use of AF_INET  loopback as an IPC 
> > mechanism.
>
>Both in.mpathd and dhcpagent use this mechanism.  Of course, they are both
>networking daemons, but the IPC channel has nothing to do with them being
>networking daemons.

Right, but neither are applications, rather they're system tools.  I was 
thinking more of a application or a library.

Casper


From Nicolas.Williams@sun.com Thu Dec 24 13:03:10 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBOL3AaU028346
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 24 Dec 2009 13:03:10 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBOL37wd008406;
	Thu, 24 Dec 2009 13:03:07 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KV600D09D574400@brm-avmta-1.central.sun.com>; Thu,
 24 Dec 2009 14:03:07 -0700 (MST)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KV600AUDD56O360@brm-avmta-1.central.sun.com>; Thu,
 24 Dec 2009 14:03:06 -0700 (MST)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id nBOKta7l013014;
 Thu, 24 Dec 2009 14:55:36 -0600 (CST)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id nBOKtaU9013013; Thu,
 24 Dec 2009 14:55:36 -0600 (CST)
Date: Thu, 24 Dec 2009 14:55:36 -0600
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912240943.nBO9hrwf023965@dm-holland-02.uk.sun.com>
To: Casper.Dik@sun.com
Cc: Alan Coopersmith <Alan.Coopersmith@sun.com>,
        John Plocher <john.plocher@gmail.com>, Peter.Memishian@sun.com,
        PSARC-ext@sun.com
Message-id: <20091224205535.GE1516@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com>
 <acff61d30912231501j5b374cddya0b89fb17e336984@mail.gmail.com>
 <4B32A5C2.7030202@sun.com>
 <200912240943.nBO9hrwf023965@dm-holland-02.uk.sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 667

On Thu, Dec 24, 2009 at 10:43:53AM +0100, Casper.Dik@Sun.COM wrote:
> >John Plocher wrote:
> >> What is the basic use case for this priv?
> 
> It is also possible to contain users in a "can't break out" shell; they 
> can run their application but they cannot copy data outside of the machine.

To be fair, if you allow name service calls, with nscd doing the
networking, you have a subliminal channel...

	if (gethostbyname("byte0is123.docFOO.peer.example") != NULL)
		/* peer got the message */

nscd could, of course, see that a client lacks this basic privilege and
limit the caller to queries against the files backend.  We should
consider doing that.

Nico
-- 

From erik.nordmark@sun.com Sun Dec 27 14:44:40 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBRMieE7022320
	for <psarc-ext@sac.sfbay.sun.com>; Sun, 27 Dec 2009 14:44:40 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBRMicR0003815;
	Sun, 27 Dec 2009 14:44:38 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVC00B011UEL300@brm-avmta-1.central.sun.com>; Sun,
 27 Dec 2009 15:44:38 -0700 (MST)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVC009QT1UDQ980@brm-avmta-1.central.sun.com>; Sun,
 27 Dec 2009 15:44:37 -0700 (MST)
Received: from [10.7.251.248] (punchin-nordmark.SFBay.Sun.COM [10.7.251.248])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id nBRMib58663457
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sun,
 27 Dec 2009 14:44:37 -0800 (PST)
Date: Sun, 27 Dec 2009 14:44:36 -0800
From: Erik Nordmark <erik.nordmark@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912241051.nBOAprSu010669@dm-holland-02.uk.sun.com>
To: Casper.Dik@sun.com
Cc: PSARC-ext@sun.com
Message-id: <4B37E354.2010001@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200912221426.nBMEQLYD020265@sac.sfbay.sun.com>
 <4B327A8C.90704@sun.com>
 <200912232110.nBNLA3o3012841@dm-holland-02.uk.sun.com>
 <4B32AE0A.50005@sun.com> <200912241051.nBOAprSu010669@dm-holland-02.uk.sun.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20091124)
Status: RO
Content-Length: 1513

Casper.Dik@Sun.COM wrote:
> 
>> But it makes the description of NET_ACCESS much more complicated; not 
>> only do we have PRIV_NET_RAWACCESS but also PRIV_NET_ICMPACCESS.
> 
> I'm not sure that this more complicated by any stretch of imagination.
> 
> +     PRIV_NET_ACCESS
> +       Allows a process to open an unprivileged network connection.

You're kidding, right? You have a circular definition with a negation in 
it. Hence self-conflicting. For example.
Since one requires PRIV_NET_ACCESS to open a TCP socket, that makes a 
TCP socket a privileged network connection. Hence by the above 
description a TCP socket doesn't require PRIV_NET_ACCESS.

>> If we uniformly apply NET_ACCESS for all IP based transports then there 
>> is a single privilege that needs to be removed to ensure that IP 
>> networking can not be used.
> 
> Requiring multiple privileges for a specific operation runs against the 
> grain of the Solaris privilege implementation.

It is just about "implementation", or something more fundamental?

It sounded from the case that you wanted to provide a single privileged 
that could be removed to prevent opening any INET/INET6 socket. But you 
are not providing that since the user would also have to make sure 
PRIV_NET_*ACCESS is removed.

If we really can't have an umbrella PRIV_NET_ACCESS apply to all INET* 
endpoints, then it would make more sense to introduce finder grain ones 
like PRIV_NET_{TCP,UDP,SCTP}ACCESS which follows the pattern of the RAW 
and ICMP ones.

    Erik

From gdamore@sun.com Wed Dec 30 12:50:34 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBUKoYxe016010
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 30 Dec 2009 12:50:34 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id nBUKoUv7032201
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 30 Dec 2009 13:50:33 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVH00325GK8MQ00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 30 Dec 2009 12:50:32 -0800 (PST)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVH00JO8GK6XN90@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 30 Dec 2009 12:50:31 -0800 (PST)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id nBUKoUGT023234	for
 <PSARC-ext@sun.com>; Wed, 30 Dec 2009 12:50:30 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KVH00M00GIUB000@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 30 Dec 2009 12:50:30 -0800 (PST)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KVH00CSAGK5HF30@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 30 Dec 2009 12:50:30 -0800 (PST)
Date: Wed, 30 Dec 2009 12:50:29 -0800
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <19250.40015.608964.681216@gargle.gargle.HOWL>
Sender: Garrett.Damore@sun.com
To: Peter.Memishian@sun.com
Cc: Alan Coopersmith <Alan.Coopersmith@sun.com>,
        James Carlson <carlsonj@workingcode.com>, Casper.Dik@sun.com,
        PSARC-ext@sun.com
Message-id: <4B3BBD15.607@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.23 (X11/20091013)
Status: RO
Content-Length: 1968

Peter Memishian wrote:
>  > > I could see doing this on a subset of well-controlled applications, but
>  > > what happens when a customer using this facility wants some Sun-supported
>  > > application that happens to use loopback inet IPC to "work"?  Are we going
>  > > to change the code to accommodate their need, or tell them they're off the
>  > > reservation? 
>  > 
>  > How would this be any different than if they tried removing other basic
>  > privileges, like the ability to fork() or exec(), from apps that really
>  > needed it?   If customers break their system, it's broken.
>
> The difference is that removing the ability to fork() and exec() does
> exactly that.  This privilege removes the ability to communicate on the
> network, and removes one of the mechanisms for IPC that has nothing
> inherently to do with communicating on the network.
>   

Its unfortunate that applications use loopback to do their own local 
IPC.  Such applications are inherently busted IMO (unless they are 
*intended* to operate over the network as well as locally), since they 
rely on a correct network configuration and wind up utilizing a lot of 
extra overhead associated with TCP/IP that a simpler IPC could elide.

I am starting to think that this well-intentioned idea needs to be 
rethought, but I'm not sure how to best to deal with it.   (I can think 
of some unusual mechanisms ... like only allowing programs to 
communicate to non-privileged local host ports if they lack the 
necessary privilege), but I'm pretty sure that there are holes in these, 
and the challenge of making this work "correctly" without either making 
it "hard to understand", or not-useful seems not-obvious to me.

I'm starting to think a derail might be in order, but I'd like to know 
how the other members feel.  I'm neither the foremost security nor the 
foremost networking member of PSARC, so I'll just defer to the 
decision(s) made by those individuals.

    - Garrett



From Andrew.Gabriel@sun.com Wed Dec 30 13:20:24 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBULKO2u016493
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 30 Dec 2009 13:20:24 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id nBULKNPQ047209
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 30 Dec 2009 14:20:23 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVH00C0JHXZ7200@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 30 Dec 2009 13:20:23 -0800 (PST)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVH00J1WHXXXNC0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 30 Dec 2009 13:20:21 -0800 (PST)
Received: from fe-emea-09.sun.com
 (gmp-eb-lb-1-fe1.eu.sun.com [192.18.6.7] (may be forged))
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id nBULKK8w028135	for
 <PSARC-ext@sun.com>; Wed, 30 Dec 2009 21:20:20 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KVH00F00HULQI00@fe-emea-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 30 Dec 2009 21:20:05 +0000 (GMT)
Received: from [81.187.162.109] ([unknown] [81.187.162.109])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KVH006EGHXGZ840@fe-emea-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 30 Dec 2009 21:20:05 +0000 (GMT)
Date: Wed, 30 Dec 2009 21:20:14 +0000
From: Andrew Gabriel <Andrew.Gabriel@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <4B3BBD15.607@sun.com>
Sender: Andrew.Gabriel@sun.com
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: Peter.Memishian@sun.com, Alan Coopersmith <Alan.Coopersmith@sun.com>,
        James Carlson <carlsonj@workingcode.com>, Casper.Dik@sun.com,
        PSARC-ext@sun.com
Message-id: <4B3BC40E.7020702@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <4B3BBD15.607@sun.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20090929)
Status: RO
Content-Length: 2904

Garrett D'Amore wrote:
> Peter Memishian wrote:
>>  > > I could see doing this on a subset of well-controlled 
>> applications, but
>>  > > what happens when a customer using this facility wants some 
>> Sun-supported
>>  > > application that happens to use loopback inet IPC to "work"?  
>> Are we going
>>  > > to change the code to accommodate their need, or tell them 
>> they're off the
>>  > > reservation?  >  > How would this be any different than if they 
>> tried removing other basic
>>  > privileges, like the ability to fork() or exec(), from apps that 
>> really
>>  > needed it?   If customers break their system, it's broken.
>>
>> The difference is that removing the ability to fork() and exec() does
>> exactly that.  This privilege removes the ability to communicate on the
>> network, and removes one of the mechanisms for IPC that has nothing
>> inherently to do with communicating on the network.
>>   
>
> Its unfortunate that applications use loopback to do their own local 
> IPC.  Such applications are inherently busted IMO (unless they are 
> *intended* to operate over the network as well as locally), since they 
> rely on a correct network configuration and wind up utilizing a lot of 
> extra overhead associated with TCP/IP that a simpler IPC could elide.

We spent many years telling ISV's to rewrite their apps to use loopback, 
rather than use things like unix domain sockets/named pipes, in response 
to complaints about very poor performance of unix domain sockets, verses 
loopback.

IIRC, this was in part because things like SO_SNDBUF/SO_RCVBUF were 
ignored on unix domain sockets, and because that code path never got the 
same attention to performance tuning as the IP loopback path did. I 
don't know if these are still factors today, but that's largely 
irrelevant - we already told ISVs to change (or design) their apps to 
use loopback, and it's not reasonable to tell them we changed our minds 
after they already did it.

> I am starting to think that this well-intentioned idea needs to be 
> rethought, but I'm not sure how to best to deal with it.   (I can 
> think of some unusual mechanisms ... like only allowing programs to 
> communicate to non-privileged local host ports if they lack the 
> necessary privilege), but I'm pretty sure that there are holes in 
> these, and the challenge of making this work "correctly" without 
> either making it "hard to understand", or not-useful seems not-obvious 
> to me.

Yes, it's messy. Even simply splitting this into two bits (loopback, and 
non-loopback) doesn't get you where you want to be (although it may be 
part of a solution).

> I'm starting to think a derail might be in order, but I'd like to know 
> how the other members feel.  I'm neither the foremost security nor the 
> foremost networking member of PSARC, so I'll just defer to the 
> decision(s) made by those individuals.
-- 
Andrew

From peter.memishian@sun.com Wed Dec 30 15:39:52 2009
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBUNdpM1017734
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 30 Dec 2009 15:39:52 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBUNdnSu016039;
	Wed, 30 Dec 2009 17:39:49 -0600 (CST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVH00501OEDIO00@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 30 Dec 2009 15:39:49 -0800 (PST)
Received: from triplex.local ([129.146.108.208]) by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVH00FZCOECPZ10@nwk-avmta-1.sfbay.Sun.COM>; Wed,
 30 Dec 2009 15:39:48 -0800 (PST)
Received: from triplex.local (triplex [127.0.0.1])
	by triplex.local (8.14.3+Sun/8.14.3) with ESMTP id nBUNdmHT195147; Wed,
 30 Dec 2009 15:39:48 -0800 (PST)
Received: (from meem@localhost)	by triplex.local (8.14.3+Sun/8.14.3/Submit)
 id nBUNdmip195092; Wed, 30 Dec 2009 15:39:48 -0800 (PST)
Date: Wed, 30 Dec 2009 15:39:48 -0800
From: Peter Memishian <peter.memishian@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
	01/01/2010]
In-reply-to: <4B3BBD15.607@sun.com>
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: peter.memishian@sun.com, Alan Coopersmith <Alan.Coopersmith@sun.com>,
        James Carlson <carlsonj@workingcode.com>, Casper.Dik@sun.com,
        PSARC-ext@sun.com
Reply-to: peter.memishian@sun.com
Message-id: <19259.58564.190894.285778@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.19 under 21.4 (patch 21) "Educational Television" XEmacs Lucid
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <4B3BBD15.607@sun.com>
X-Authentication-warning: triplex.local: meem set sender to
 peter.memishian@sun.com using -f
Status: RO
Content-Length: 1343


 > Its unfortunate that applications use loopback to do their own local 
 > IPC.  Such applications are inherently busted IMO (unless they are 
 > *intended* to operate over the network as well as locally), since they 
 > rely on a correct network configuration and wind up utilizing a lot of 
 > extra overhead associated with TCP/IP that a simpler IPC could elide.

I don't think such applications are "inherently busted".  Given that the
operating system itself sets up loopback and moreover that loopback
configuration has nothing to do with broader network configuration, it
seems perfectly reasonable to assume it to be correct, and Solaris
features like TCP fusion make it quite fast.  However, this is also an
irrelevant debate: the fact is that applications have been free to use
loopback AF_INET for IPC for decades and invariably some have done so.
Those applications will be broken by this privilege that was never
intended to restrict IPC.

I see two paths forward: redefine the privilege to include the wart of
restricting loopback AF_INET IPC (and to rework impacted applications as
the need arises -- including third-party applications), or to design a
different mechanism to implement this restriction.  FWIW, I do not
consider leaving this matter an undocumented side effect and crossing
our fingers as an option.

-- 
meem

From casper@holland.sun.com Thu Dec 31 03:34:05 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBVBY5ar009363
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 31 Dec 2009 03:34:05 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id nBVBY35N022265;
	Thu, 31 Dec 2009 04:34:04 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVI00J01LGR2F00@nwk-avmta-1.sfbay.Sun.COM>; Thu,
 31 Dec 2009 03:34:03 -0800 (PST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVI009UPLGQ2910@nwk-avmta-1.sfbay.Sun.COM>; Thu,
 31 Dec 2009 03:34:03 -0800 (PST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id nBVBXvX8006307; Thu, 31 Dec 2009 11:33:58 +0000 (GMT)
Date: Thu, 31 Dec 2009 12:33:57 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <4B3BBD15.607@sun.com>
Sender: casper@holland.sun.com
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: Peter.Memishian@sun.com, Alan Coopersmith <Alan.Coopersmith@sun.com>,
        James Carlson <carlsonj@workingcode.com>, PSARC-ext@sun.com
Message-id: <200912311133.nBVBXvX8006307@dm-holland-02.uk.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <4B3BBD15.607@sun.com>
Status: RO
Content-Length: 1396



>I'm starting to think a derail might be in order, but I'd like to know 
>how the other members feel.  I'm neither the foremost security nor the 
>foremost networking member of PSARC, so I'll just defer to the 
>decision(s) made by those individuals.

I still haven't seen any application which uses inet sockets and which 
isn't a system tool; even the X server can work without tcp sockets.

In theory, I can see that this might be an issue, but note that an 
application with one or more basic privileges missing is no longer running 
in a POSIX environment.  It is similar to the FILE_READ and the FILE_WRITE
privileges: a file cannot open a file for read or write.

I want to clarify the definition of the NET_ACCESS privilege as follows:

privilege  NET_ACCESS

     Allows a process to open a TCP, UDP or SCTP network endpoint.


This makes clear that ICMP and RAW sockets do not require more than the
NET_ICMPACCESS or NET_RAWACCESS.

While I'm not against derailing, per se.  I will understand that a fine 
grained access control may serve all users better and we are actually 
working on that.

This is a simple mechanism and similar mechanisms have been tested by 
customers, using artifacts of earlier Solaris implementation.  These
artifacts no longer exist and so the customer has a problem.

In theory, this might not be the best but in practice it seems to work 
well.

Casper


From carlsonj@workingcode.com Thu Dec 31 07:07:47 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nBVF7lFC011550
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 31 Dec 2009 07:07:47 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id nBVF7jTO000596;
	Thu, 31 Dec 2009 07:07:45 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVI00J01VCXQ900@nwk-avmta-2.sfbay.sun.com>; Thu,
 31 Dec 2009 07:07:45 -0800 (PST)
Received: from sca-ea-mail-2.sun.com ([192.18.43.25])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVI00DNLVCX0P30@nwk-avmta-2.sfbay.sun.com>; Thu,
 31 Dec 2009 07:07:45 -0800 (PST)
Received: from relay44i.sun.com ([192.5.209.118])
	by sca-ea-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id nBVF7eCl002122;
 Thu, 31 Dec 2009 15:07:45 +0000 (GMT)
Received: from mms49es.mms.us.syntegra.com ([160.41.221.232] [160.41.221.232])
 by relay44i.sun.com with ESMTP id BT-MMP-5018107; Thu,
 31 Dec 2009 15:07:40 +0000 (Z)
Received: from relay41i.sun.com (relay41i.sun.com [192.5.209.70])
 by mms49es.mms.us.syntegra.com with ESMTP id BT-MMP-26406866; Thu,
 31 Dec 2009 15:07:40 +0000 (Z)
Received: from carlson.workingcode.com ([75.150.68.97] [75.150.68.97])
 by relay4i.sun.com with ESMTP id BT-MMP-6815758; Thu,
 31 Dec 2009 15:07:39 +0000 (Z)
Received: from [192.168.254.178] (dhcp-178 [192.168.254.178])
	(authenticated bits=0)	by carlson.workingcode.com (8.14.2+Sun/8.14.3)
 with ESMTP id nBVF7YRH026898
	(version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NO); Thu,
 31 Dec 2009 10:07:35 -0500 (EST)
Date: Thu, 31 Dec 2009 10:07:09 -0500
From: James Carlson <carlsonj@workingcode.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <200912311133.nBVBXvX8006307@dm-holland-02.uk.sun.com>
To: "Casper.Dik@sun.com" <Casper.Dik@sun.com>
Cc: "PSARC-ext@sun.com" <PSARC-ext@sun.com>
Message-id: <12F0E9D6-4171-4ABF-A871-B6AEBF6A3548@workingcode.com>
MIME-version: 1.0
X-Mailer: iPod Mail (7D11)
Content-type: text/plain; charset=us-ascii; format=flowed; delsp=yes
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-DCC-dmv.com-Metrics: carlson; whitelist
X-Antispam: No, score=-0.7/5.0, scanned in 0.114sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <4B3BBD15.607@sun.com> <200912311133.nBVBXvX8006307@dm-holland-02.uk.sun.com>
Status: RO
Content-Length: 1334

On Dec 31, 2009, at 6:33 AM, Casper.Dik@sun.com wrote:

>
>
>> I'm starting to think a derail might be in order, but I'd like to  
>> know
>> how the other members feel.  I'm neither the foremost security nor  
>> the
>> foremost networking member of PSARC, so I'll just defer to the
>> decision(s) made by those individuals.
>
> I still haven't seen any application which uses inet sockets and which
> isn't a system tool; even the X server can work without tcp sockets.

There are many that do this, but I'm uncertain what would not be a  
system tool.

Among them are vnc (often used with localhost) and tunneled X and  
other ports with ssh.

But I think this is all irrelevant. Cutting out the ability to open  
sockets is like cutting out other basic privileges, such as opening  
files or forking. To do it, you must have detailed information about  
the design of the program you're affecting.

Without the source code, you might get away with some hacks, like  
using privilege debug to find "all" of the needed flags, but doing it  
right means knowing the code. As those are the only safe users, I see  
no problem allowing them to remove unused OS features at run time.

For all others, a simple "removing privileges set by the original  
designer may have unpredictable consequences" warning seems sufficient  
to me.
  

From Sebastien.Roy@sun.com Mon Jan  4 08:31:51 2010
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o04GVpic017336
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 4 Jan 2010 08:31:51 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o04GV2cl009065
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 4 Jan 2010 08:31:51 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVQ00C3TDWMHH00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 04 Jan 2010 09:31:34 -0700 (MST)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVQ00BD9DWKZ300@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 04 Jan 2010 09:31:33 -0700 (MST)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o04GVWGs002893	for
 <PSARC-ext@sun.com>; Mon, 04 Jan 2010 16:31:32 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KVQ00G00DNS7500@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 04 Jan 2010 09:31:32 -0700 (MST)
Received: from [129.148.174.103] ([unknown] [129.148.174.103])
 by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KVQ00I7SDWH1RF0@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 04 Jan 2010 09:31:30 -0700 (MST)
Date: Mon, 04 Jan 2010 11:28:58 -0500
From: Sebastien Roy <Sebastien.Roy@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <4B3BBD15.607@sun.com>
Sender: Sebastien.Roy@sun.com
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: Peter.Memishian@sun.com, Alan Coopersmith <Alan.Coopersmith@sun.com>,
        James Carlson <carlsonj@workingcode.com>, Casper.Dik@sun.com,
        PSARC-ext@sun.com
Message-id: <1262622538.4018.30.camel@strat>
Organization: Sun Microsystems
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <4B3BBD15.607@sun.com>
Status: RO
Content-Length: 1835

On Wed, 2009-12-30 at 12:50 -0800, Garrett D'Amore wrote:
> Its unfortunate that applications use loopback to do their own local 
> IPC.  Such applications are inherently busted IMO (unless they are 
> *intended* to operate over the network as well as locally), since they 
> rely on a correct network configuration and wind up utilizing a lot of 
> extra overhead associated with TCP/IP that a simpler IPC could elide.

IMO the debate of whether or not such applications are using an optimal
IPC is irrelevant.  Let's assess this architecture assuming that such
applications exist.

> I am starting to think that this well-intentioned idea needs to be 
> rethought, but I'm not sure how to best to deal with it.   (I can think 
> of some unusual mechanisms ... like only allowing programs to 
> communicate to non-privileged local host ports if they lack the 
> necessary privilege), but I'm pretty sure that there are holes in these, 
> and the challenge of making this work "correctly" without either making 
> it "hard to understand", or not-useful seems not-obvious to me.
> 
> I'm starting to think a derail might be in order, but I'd like to know 
> how the other members feel.  I'm neither the foremost security nor the 
> foremost networking member of PSARC, so I'll just defer to the 
> decision(s) made by those individuals.

I don't have any issues with the proposal given appropriate
documentation that accurately states the scope of the privilege.  Its
utility is severely limited, obviously, but that doesn't make the
proposal invalid.

We have room on the agenda this week and we could simply have a verbal
conversation to bring this fast-track to convergence without necessarily
derailing it.  I think such a discussion would be most productive if
Casper, Erik, and Meem could attend.  Would that be possible?

-Seb



From casper@holland.sun.com Mon Jan  4 08:33:39 2010
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o04GXd33017392
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 4 Jan 2010 08:33:39 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o04GXQld017020;
	Mon, 4 Jan 2010 08:33:39 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVQ0032XDZVDM00@nwk-avmta-2.sfbay.sun.com>; Mon,
 04 Jan 2010 08:33:31 -0800 (PST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVQ0006HDZTDG40@nwk-avmta-2.sfbay.sun.com>; Mon,
 04 Jan 2010 08:33:30 -0800 (PST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id o04GXOXq007437; Mon, 04 Jan 2010 16:33:25 +0000 (GMT)
Date: Mon, 04 Jan 2010 17:33:24 +0100
From: casper.dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <1262622538.4018.30.camel@strat>
Sender: casper@holland.sun.com
To: Sebastien Roy <Sebastien.Roy@sun.com>
Cc: "Garrett D'Amore" <gdamore@sun.com>, Peter.Memishian@sun.com,
        Alan Coopersmith <Alan.Coopersmith@sun.com>,
        James Carlson <carlsonj@workingcode.com>, PSARC-ext@sun.com
Message-id: <201001041633.o04GXOXq007437@dm-holland-02.uk.sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <4B3BBD15.607@sun.com> <1262622538.4018.30.camel@strat>
Status: RO
Content-Length: 315


>We have room on the agenda this week and we could simply have a verbal
>conversation to bring this fast-track to convergence without necessarily
>derailing it.  I think such a discussion would be most productive if
>Casper, Erik, and Meem could attend.  Would that be possible?

Ok, that'll work for me.

Casper


From erik.nordmark@sun.com Mon Jan  4 09:35:35 2010
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o04HZYmp018420
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 4 Jan 2010 09:35:35 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id o04HZWRk013306;
	Mon, 4 Jan 2010 10:35:32 -0700 (MST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVQ00I0DGV8ZH00@brm-avmta-1.central.sun.com>; Mon,
 04 Jan 2010 10:35:32 -0700 (MST)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVQ00B1VGV7Z550@brm-avmta-1.central.sun.com>; Mon,
 04 Jan 2010 10:35:32 -0700 (MST)
Received: from [10.7.251.248] (punchin-nordmark.SFBay.Sun.COM [10.7.251.248])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id o04HZV9h129176
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon,
 04 Jan 2010 09:35:31 -0800 (PST)
Date: Mon, 04 Jan 2010 09:35:31 -0800
From: Erik Nordmark <erik.nordmark@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <1262622538.4018.30.camel@strat>
To: Sebastien Roy <Sebastien.Roy@sun.com>
Cc: "Garrett D'Amore" <gdamore@sun.com>, Peter.Memishian@sun.com,
        Alan Coopersmith <Alan.Coopersmith@sun.com>,
        James Carlson <carlsonj@workingcode.com>, Casper.Dik@sun.com,
        PSARC-ext@sun.com
Message-id: <4B4226E3.20700@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <4B3BBD15.607@sun.com> <1262622538.4018.30.camel@strat>
User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.9.1.5) Gecko/20091207
 Lightning/1.0pre Thunderbird/3.0
Status: RO
Content-Length: 367

On 01/ 4/10 08:28 AM, Sebastien Roy wrote:

> We have room on the agenda this week and we could simply have a verbal
> conversation to bring this fast-track to convergence without necessarily
> derailing it.  I think such a discussion would be most productive if
> Casper, Erik, and Meem could attend.  Would that be possible?

I'll be around on Wednesday.

    Erik

From Sebastien.Roy@Sun.COM Mon Jan  4 10:45:10 2010
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o04IjAuJ020214
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 4 Jan 2010 10:45:10 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o04Ij9x5018871
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 4 Jan 2010 10:45:09 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVQ00B0ZK39CW00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 04 Jan 2010 10:45:09 -0800 (PST)
Received: from brmea-mail-1.sun.com ([192.18.98.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVQ000OKK39DHD0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 04 Jan 2010 10:45:09 -0800 (PST)
Received: from fe-amer-10.sun.com ([192.18.109.80])
	by brmea-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o04Ij98h013144	for
 <PSARC-ext@sun.com>; Mon, 04 Jan 2010 18:45:09 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KVQ00B00JKWLR00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 04 Jan 2010 11:45:09 -0700 (MST)
Received: from [129.148.174.103] ([unknown] [129.148.174.103])
 by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KVQ00I7VK2V4AA0@mail-amer.sun.com>; Mon,
 04 Jan 2010 11:44:56 -0700 (MST)
Date: Mon, 04 Jan 2010 13:42:24 -0500
From: Sebastien Roy <Sebastien.Roy@Sun.COM>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <4B4226E3.20700@sun.com>
Sender: Sebastien.Roy@Sun.COM
To: Erik Nordmark <Erik.Nordmark@Sun.COM>
Cc: "Garrett D'Amore" <gdamore@Sun.COM>, Peter.Memishian@Sun.COM,
        Alan Coopersmith <Alan.Coopersmith@Sun.COM>,
        James Carlson <carlsonj@workingcode.com>, Casper.Dik@Sun.COM,
        PSARC-ext@Sun.COM
Message-id: <1262630544.4018.122.camel@strat>
Organization: Sun Microsystems
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <4B3BBD15.607@sun.com> <1262622538.4018.30.camel@strat>
 <4B4226E3.20700@sun.com>
Status: RO
Content-Length: 585

On Mon, 2010-01-04 at 09:35 -0800, Erik Nordmark wrote:
> On 01/ 4/10 08:28 AM, Sebastien Roy wrote:
> 
> > We have room on the agenda this week and we could simply have a verbal
> > conversation to bring this fast-track to convergence without necessarily
> > derailing it.  I think such a discussion would be most productive if
> > Casper, Erik, and Meem could attend.  Would that be possible?
> 
> I'll be around on Wednesday.

Okay, let's discuss this case at the end of fast-tracks this Wednesday:

http://hub.opensolaris.org/bin/view/Community+Group+arc/ARCAgenda

Thanks,
-Seb



From gww@sac.sfbay.sun.com Mon Jan  4 11:52:48 2010
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o04Jqmg4022391
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 4 Jan 2010 11:52:48 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o04Jqla4019706;
	Mon, 4 Jan 2010 11:52:48 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVQ0090FN7ZH000@brm-avmta-1.central.sun.com>; Mon,
 04 Jan 2010 12:52:47 -0700 (MST)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVQ00BHYN7YZ6D0@brm-avmta-1.central.sun.com>; Mon,
 04 Jan 2010 12:52:46 -0700 (MST)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id o04JqgHH014387; Mon, 04 Jan 2010 11:52:42 -0800 (PST)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o04JqgFd022388; Mon,
 04 Jan 2010 11:52:42 -0800 (PST)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id o04JqgLK022387; Mon, 04 Jan 2010 11:52:42 -0800 (PST)
Date: Mon, 04 Jan 2010 11:52:42 -0800 (PST)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
To: Casper.Dik@sun.com, gdamore@sun.com
Cc: Alan.Coopersmith@sun.com, PSARC-ext@sun.com, Peter.Memishian@sun.com,
        carlsonj@workingcode.com
Message-id: <201001041952.o04JqgLK022387@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 300

> I want to clarify the definition of the NET_ACCESS privilege as follows:
> 
> privilege  NET_ACCESS
> 
>      Allows a process to open a TCP, UDP or SCTP network endpoint.
> 
> 
> This makes clear that ICMP and RAW sockets do not require more than the
> NET_ICMPACCESS or NET_RAWACCESS.

+1
Gary..

From peter.memishian@sun.com Mon Jan  4 13:42:06 2010
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o04Lg62a026577
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 4 Jan 2010 13:42:06 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o04Lg2IS001679;
	Mon, 4 Jan 2010 15:42:02 -0600 (CST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVQ00M09SA2GT00@nwk-avmta-2.sfbay.sun.com>; Mon,
 04 Jan 2010 13:42:02 -0800 (PST)
Received: from triplex.local ([129.146.108.208]) by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVQ00EF9SA0RO50@nwk-avmta-2.sfbay.sun.com>; Mon,
 04 Jan 2010 13:42:00 -0800 (PST)
Received: from triplex.local (triplex [127.0.0.1])
	by triplex.local (8.14.3+Sun/8.14.3) with ESMTP id o04Lg0V4934272; Mon,
 04 Jan 2010 13:42:00 -0800 (PST)
Received: (from meem@localhost)	by triplex.local (8.14.3+Sun/8.14.3/Submit)
 id o04Lg0ov934260; Mon, 04 Jan 2010 13:42:00 -0800 (PST)
Date: Mon, 04 Jan 2010 13:42:00 -0800
From: Peter Memishian <peter.memishian@sun.com>
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <1262630544.4018.122.camel@strat>
To: Sebastien Roy <Sebastien.Roy@sun.com>
Cc: Erik Nordmark <Erik.Nordmark@sun.com>, "Garrett D'Amore" <gdamore@sun.com>,
        peter.memishian@sun.com, Alan Coopersmith <Alan.Coopersmith@sun.com>,
        James Carlson <carlsonj@workingcode.com>, Casper.Dik@sun.com,
        PSARC-ext@sun.com
Reply-to: peter.memishian@sun.com
Message-id: <19266.24744.327895.980411@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.19 under 21.4 (patch 21) "Educational Television" XEmacs Lucid
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com> <19250.40015.608964.681216@gargle.gargle.HOWL>
 <4B3BBD15.607@sun.com> <1262622538.4018.30.camel@strat>
 <4B4226E3.20700@sun.com> <1262630544.4018.122.camel@strat>
X-Authentication-warning: triplex.local: meem set sender to
 peter.memishian@sun.com using -f
Status: RO
Content-Length: 631


 > > On 01/ 4/10 08:28 AM, Sebastien Roy wrote:
 > > 
 > > > We have room on the agenda this week and we could simply have a verbal
 > > > conversation to bring this fast-track to convergence without necessarily
 > > > derailing it.  I think such a discussion would be most productive if
 > > > Casper, Erik, and Meem could attend.  Would that be possible?
 > > 
 > > I'll be around on Wednesday.
 > 
 > Okay, let's discuss this case at the end of fast-tracks this Wednesday:
 > 
 > http://hub.opensolaris.org/bin/view/Community+Group+arc/ARCAgenda

I may be running for a train at that time, but I will try to call in.

-- 
meem

From Joerg.Schilling9ab33xy531fokus.fraunhofer.de@bounce.antispameurope.com Wed Jan  6 05:21:19 2010
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o06DLI2i027069
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 Jan 2010 05:21:18 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id o06DLHWj025918
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 6 Jan 2010 06:21:18 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVT00J05UFHZT00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 06 Jan 2010 05:21:17 -0800 (PST)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVT00EHQUFH5R50@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 06 Jan 2010 05:21:17 -0800 (PST)
Received: from relay13i.sun.com
 (ip123.net129179-4.block1.us.syntegra.com [129.179.4.123])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o06D9LUq015770	for
 <PSARC-ext@sun.com>; Wed, 06 Jan 2010 13:21:16 +0000 (GMT)
Received: from mmp12es.mmp.us.syntegra.com ([160.41.208.12] [160.41.208.12])
 by relay13i.sun.com with ESMTP id BT-MMP-10274664 for PSARC-ext@sun.com; Wed,
 06 Jan 2010 13:21:16 +0000 (Z)
Received: from relay14i.sun.com (relay14i.sun.com [129.179.4.124])
 by mmp12es.mmp.us.syntegra.com with ESMTP id BT-MMP-46902885 for
 PSARC-ext@sun.com; Wed, 06 Jan 2010 13:21:13 +0000 (Z)
Received: from relay02-haj2.antispameurope.com ([83.246.65.52] [83.246.65.52])
 by relay1i.sun.com with ESMTP id BT-MMP-13850077 for PSARC-ext@sun.com; Wed,
 06 Jan 2010 13:21:13 +0000 (Z)
Received: by relay02-haj2.antispameurope.com (ASE-Secure-MTA, from userid 1000)
	id 2AF7F6F052E; Wed, 06 Jan 2010 14:21:01 +0100 (CET)
Received: from pluto.fokus.fraunhofer.de
 (pluto.fokus.fraunhofer.de [195.37.77.164])
	(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)	by relay02-haj2.antispameurope.com
 (ASE-Secure-MTA) with ESMTP id 8ADD66F052E; Wed,
 06 Jan 2010 14:20:59 +0100 (CET)
Received: from EXCHSRV.fokus.fraunhofer.de
 (bohr.fokus.fraunhofer.de [10.147.9.231])	by pluto.fokus.fraunhofer.de
 (8.14.2/8.14.2) with SMTP id o06DKxcL016056; Wed,
 06 Jan 2010 14:20:59 +0100 (MET)
Received: from rigel ([10.147.65.195]) by EXCHSRV.fokus.fraunhofer.de with
 Microsoft SMTPSVC(6.0.3790.3959); Wed, 06 Jan 2010 14:20:59 +0100
Date: Wed, 06 Jan 2010 14:20:59 +0100
From: Joerg.Schilling@fokus.fraunhofer.de (Joerg Schilling)
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <acff61d30912231605m33c94afbpa8971650aa10d171@mail.gmail.com>
Sender: Joerg.Schilling9ab33xy531fokus.fraunhofer.de@bounce.antispameurope.com
To: john.plocher@gmail.com, Alan.Coopersmith@sun.com
Cc: PSARC-ext@sun.com
Message-id: <4b448e3b.19KalkqIul6bQXZ+%Joerg.Schilling@fokus.fraunhofer.de>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
X-Brightmail-Tracker: AAAAAA==
X-Antispam: No, score=3.2/5.0, scanned in 2.176sec at (localhost [127.0.0.1])
	by smf-spamd v1.3.1 - http://smfs.sf.net/
References: <19250.25677.542375.150640@gargle.gargle.HOWL>
 <200912232054.nBNKsQXZ009466@dm-holland-02.uk.sun.com>
 <19250.34589.40454.646037@gargle.gargle.HOWL>
 <200912232128.nBNLSShg015888@dm-holland-02.uk.sun.com>
 <19250.36572.222057.29285@gargle.gargle.HOWL>
 <4B329254.4030204@workingcode.com> <19250.39229.677.800898@gargle.gargle.HOWL>
 <4B329AEB.708@sun.com>
 <acff61d30912231501j5b374cddya0b89fb17e336984@mail.gmail.com>
 <4B32A5C2.7030202@sun.com>
 <acff61d30912231605m33c94afbpa8971650aa10d171@mail.gmail.com>
User-Agent: nail 11.22 3/20/05
X-OriginalArrivalTime: 06 Jan 2010 13:20:59.0101 (UTC)
 FILETIME=[15F398D0:01CA8ED3]
Status: RO
Content-Length: 1163

John Plocher <john.plocher@gmail.com> wrote:

> > Just various non-obvious functions in libc().   (Do you think most programmers
> > realize wordexp(), pututxline() or grantpt() call fork+exec?)
>
> This is a reasonable characterization of what happens if you lose the
> fork and exec privs - a few things break, some of which are obvious
> (i.e., fork() no longer works) and some less so.  Somewhere there is a
> list of things in the system that fail if you don't have those privs
> AND there is nothing on that list that causes angst.

A good reason to require such thing to be documented in the related man page.
Before I realized in 2005, that e.g. wordexp() did not work on OpenSolaris 
because it depended on a non-distributable hacked version of ksh88, verry few 
people did realize that a libc function other than e.g. system() or popen() 
would call fork.

Jörg

-- 
 EMail:joerg@schily.isdn.cs.tu-berlin.de (home) Jörg Schilling D-13353 Berlin
       js@cs.tu-berlin.de                (uni)  
       joerg.schilling@fokus.fraunhofer.de (work) Blog: http://schily.blogspot.com/
 URL:  http://cdrecord.berlios.de/private/ ftp://ftp.berlios.de/pub/schily

From casper@holland.sun.com Mon Jan 11 01:26:49 2010
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o0B9QnV5022321
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 11 Jan 2010 01:26:49 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o0B9QmwA029369
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 11 Jan 2010 03:26:48 -0600 (CST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KW200A01SWOPW00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 11 Jan 2010 02:26:48 -0700 (MST)
Received: from dm-holland-02.uk.sun.com ([129.156.101.225])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KW20073RSWNV310@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 11 Jan 2010 02:26:48 -0700 (MST)
Received: from holland (room101.Holland.Sun.COM [10.16.117.40])
	by dm-holland-02.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id o0B9Qlq3010343	for <PSARC-ext@sun.com>; Mon,
 11 Jan 2010 09:26:47 +0000 (GMT)
Date: Mon, 11 Jan 2010 10:26:47 +0100
From: Casper.Dik@sun.com
Subject: Re: Basic Network Privilege [PSARC/2009/685 FastTrack timeout
 01/01/2010]
In-reply-to: <201001041952.o04JqgLK022387@sac.sfbay.sun.com>
Sender: casper@holland.sun.com
To: PSARC-ext@sun.com
Message-id: <201001110926.o0B9Qlq3010343@dm-holland-02.uk.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <201001041952.o04JqgLK022387@sac.sfbay.sun.com>
Status: RO
Content-Length: 528



This case was approved at the 6 Jan PSAR Cmeeting.

During discussion and code review, the definition of NET_ACCESS
was changed to:

privilege NET_ACCESS
	Allows a process to open a TCP, UDP, SDP or SCTP network endpoint.


We also decided that the privileges documentation should more clearly
point out that removing a basic privilege from any set leaves a process
in a non-standard compliant state,  may case unexpected application
failures and should only be done with full knowledge of the potential
side effects.

Casper

