Skip to content

Test that denied paths stay hidden through their aliases in the native-host backend - #421

Closed
Enrique Saurez (esaurez) wants to merge 1 commit into
esaurez/nvxhost-edge-proxyfrom
esaurez/nvxhost-edge-denied-aliases
Closed

Enrique Saurez (esaurez) wants to merge 1 commit into
esaurez/nvxhost-edge-proxyfrom
esaurez/nvxhost-edge-denied-aliases

Conversation

@esaurez

Copy link
Copy Markdown
Contributor

Replaces #416 on the rebased stack. Stacked on #420. Adds a native-host guest test that denied paths stay hidden through their aliases, the cases MXC lists for the direct runtime, and documents what it shows. There is no code change.

Summary

  • New ignored guest test denied_paths_stay_hidden_through_aliases. One read-write mapping holds a denied directory and a denied file. The guest's report must match exactly:
    • .. into the denied directory, and back in from above the mapping: EACCES;
    • host links: a relative control link to an allowed file reads it; relative links into the denied directory and to the denied paths fail with EACCES; an absolute link fails with EACCES on Linux and EPERM on Windows, where OpenVMM never reads absolute targets for the guest; a Windows junction fails with EPERM;
    • a host hard link to the denied file: EACCES, because OpenVMM also refuses the denied object's identity;
    • links and a hard link that the workload creates in the mapping;
    • renaming over or away from the denied file, removing it, and creating a directory inside the denied directory: EACCES, and the host files are unchanged afterwards.
  • Two limits the test pins down. OpenVMM knows only the denied objects themselves:
    • a host hard link that joins a file inside a denied directory to a name outside it stays readable through that name;
    • a directory that holds a host hard link to a denied file may fail to list with EACCES, because a listing can look up every entry; the test accepts that or a listing that shows the name.
  • README. The native section describes the alias behavior and both limits. The shared "Host paths" section no longer says that denied paths are inaccessible through every name.

Changes since #416

None: the commit replays onto the rebased stack unchanged.

Validation

  • Each PR head in this stack passes cargo test --all-features and Clippy with -D warnings on all targets with --all-features, on Windows with Rust 1.93 (135, 137, 139, 139, and 140 unit tests).
  • At the top of the stack (5b0a315), on Windows and on Linux with Rust 1.93: the crate's CI checks, which are fmt, Clippy with --all-features and with --no-default-features, tests with --all-features and with default features, docs with -D warnings, cargo +1.89 check, and, on Linux, the macOS build check. The pinned library test passes against freshly built nvxhost.dll and libnvxhost.so.
  • Guest suite at the top of the stack, 20 tests, --release --test-threads=1, each checking that no OpenVMM process outlives its sandbox, with dev's Linux 6.18.38 kernel:
    • Windows/WHP on an AMD EPYC 7763, which amd.milan.v1 serves: all pass, in about 100 s, and again with a host profile;
    • Linux/MSHV on an AMD EPYC 9V74, which no built-in profile serves: all pass with a host profile, in about 82 s.

Notes

  • On Windows the test creates symbolic links, which needs Developer Mode or the symbolic-link privilege; it fails with that message otherwise.

A new guest test maps a read-write directory that holds a denied directory and
a denied file. It adds host links, a junction on Windows, and host hard links,
and has the workload try `..`, those aliases, links of its own, and renames,
removals, and creations at the denied names. The guest resolves every link
itself, so each lookup of a denied path, or of another name for a denied
object, fails, and absolute Windows links and junctions cannot be followed.

OpenVMM knows only the denied objects themselves: a host hard link to a file
inside a denied directory stays readable, and a directory that holds a host
hard link to a denied file cannot always be listed. The README says so, and
no longer claims that a denied path is inaccessible through every name.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@esaurez

Copy link
Copy Markdown
Contributor Author

Folded into #418, which now carries the whole change. The native library implements this feature behind the model types that #418 adds, and its guest tests are part of the end-to-end suite there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant