From nobody Tue Sep 29 15:56:24 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hvN890Crwz6tl8k for ; Tue, 29 Sep 2026 15:56:25 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hvN8839nNz4Vd8 for ; Tue, 29 Sep 2026 15:56:24 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790697384; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=f0m3GygGj1Le1OWAeU3r6H0igMosI173/dEy+x2IRW4=; b=L6qbeTzzoU8MVxosW+r5hJUz/l4XfgYUC4PcmEzZvThHV5vdJ4qBfjByo1fdt9MeqrYEEW yEUEhIfv5/coIzSz0if/LC6f7EDoQYMB1f4lv4+hkm5DjkZD0gTJgR929BQE9t3FP4ttQb sm4zAphB0pKUJnsf50rTOeY5BhffervMGY0iB2URYBu7TC0rEPWBQ/8yjeF+epceAq9fJP jcHjvhz/xY14PD07jhwA7fb/UMCCVWvhQNRy3bfDHQgmGmzKhHRZh7mQSMfK5W/359Weyl 7KDS3BfKr0CA7ABeqJF6vP6llH/z92CYfQ0l/KRd+v4lMNSlTS6Cj51PhCGpNw== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790697384; b=xFc3F7XgAXpufqQ3rZHyXttXG1SJ9z00J3Sr7a1ieZECWU7Wx3xGOQBp12+kx1Bu0y44XB /DWAMoM29YwbtBoNVCI3DYx0uuJg3s0SQvoGApYZhk0mKHfLvo03gJy+/p4Avfr0sZw5dM 4U/5qyiLzGrvpYR/D1NCZh64He6q5aDpPRNBDHrmtTHbpYbEe42THwySVvPqloyowo4EJd kLpFD/zHtTseEc6tJZ+EXI1Q9bnnHBV94bGbtiizjuQuaH8VcG0blD8eF+Xv3q8FLloqVJ UOnMaTrQZ+ft02A1KvPxGFmots2Sw13naj5X6aEB86JAtCrV7AtzqQxin0QVaQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790697384; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=f0m3GygGj1Le1OWAeU3r6H0igMosI173/dEy+x2IRW4=; b=AAbIVYbC+9Z9K7r6flkhZx3FKCvXI+HsI4PvbPuYtc0vXNaSIvhh7VsL6nj9aVLPVBvHST T7V2Dd7JjtZ+vDomKkdSGuQf2dFp9kUUixr+UjRcjbQdwxCUsKhvV4okvwrPQNsWKDuNyi KzgtsccPWw7M6eHJWGsXNY2Gk5dkPF7pq6Xj5cqExtje6E/TSiRNPpPBExGaF7RNJZPWkh z/2VrgqAI98cgIj0868WZqp8SNJ0tPlfRFIp+xOI+m9jkieLaDq/tmNoP4DlSwII+FhiF8 1SIW33ixcxfAF/3a4yMI07OluWC1S3DuWrdVjrn1Y8w8xHKhhbQen9THCBI+9Q== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hvN882GPTz1KTx for ; Tue, 29 Sep 2026 15:56:24 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 27325 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 29 Sep 2026 15:56:24 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Mark Johnston Subject: git: 6c9ee5f02548 - stable/15 - vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/stable/15 X-Git-Reftype: branch X-Git-Commit: 6c9ee5f02548c1c742c38c69e7f2164eee128320 Auto-Submitted: auto-generated Date: Tue, 29 Sep 2026 15:56:24 +0000 Message-Id: <6abbdfa8.27325.14764d0d@gitrepo.freebsd.org> The branch stable/15 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=6c9ee5f02548c1c742c38c69e7f2164eee128320 commit 6c9ee5f02548c1c742c38c69e7f2164eee128320 Author: Mark Johnston AuthorDate: 2026-09-28 16:47:56 +0000 Commit: Mark Johnston CommitDate: 2026-09-29 15:56:01 +0000 vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR 262179 without entirely disallowing fd passing between jails. However, one can use renameat() to bypass the restriction: upon receiving a directory fd with FD_RESOLVE_BENEATH set, a jailed process can still move its CWD or one of its ancestors to the directory, and just cd out of its jail root. So disallow renameat() when either the source or destination directory fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot() to prevent similar escapes. Approved by: so Security: FreeBSD-SA-26:66.jail Security: CVE-2026-101305 PR: 262179 Reported by: firk@cantconnect.ru Reviewed by: olce, kib Differential Revision: https://reviews.freebsd.org/D59875 --- lib/libsys/fcntl.2 | 9 ++++++++- sys/kern/vfs_syscalls.c | 9 +++++++++ 2 files changed, 17 insertions(+), 1 deletion(-) diff --git a/lib/libsys/fcntl.2 b/lib/libsys/fcntl.2 index b919e1b8674b..123dd5543ab2 100644 --- a/lib/libsys/fcntl.2 +++ b/lib/libsys/fcntl.2 @@ -25,7 +25,7 @@ .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF .\" SUCH DAMAGE. .\" -.Dd June 24, 2025 +.Dd September 22, 2026 .Dt FCNTL 2 .Os .Sh NAME @@ -173,6 +173,13 @@ and similar operations, and opening a directory with .Xr openat 2 where the directory descriptor has the flag set causes the new directory descriptor to also have the flag set. +A file descriptor with the +.Dv FD_RESOLVE_BENEATH +set cannot be used as either the source or target descriptor in +.Xr renameat 2 +or +.Xr renameat2 2 +system calls. .El .It Dv F_SETFD Set flags associated with diff --git a/sys/kern/vfs_syscalls.c b/sys/kern/vfs_syscalls.c index 8096ffc7be6c..5bc8dd5c5f91 100644 --- a/sys/kern/vfs_syscalls.c +++ b/sys/kern/vfs_syscalls.c @@ -3869,6 +3869,15 @@ again: error = EEXIST; goto out; } + if (fvp->v_type == VDIR && + ((fromnd.ni_resflags | tond.ni_resflags) & NIRES_BENEATH) != 0) { + /* + * We must not rename a directory relative to FD_RESOLVE_BENEATH + * descriptors. + */ + error = ENOTCAPABLE; + goto out; + } if (exchange) { if (tvp == NULL) { error = ENOENT;