From nobody Tue Sep 29 15:57:34 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hvN9V5lJNz6tlPH for ; Tue, 29 Sep 2026 15:57:34 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hvN9V2hV0z4YXb for ; Tue, 29 Sep 2026 15:57:34 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790697454; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=sWySkm/JI0g3PAbv4KmdfiNZGruWaiM9sIcbBDqDxBc=; b=tfW7kE+VQrdxfy6jV0rF2q89oefoCme9xzLi85H0tc1pPqIttiswoKKP3PYt7Lzr7cGIIn HB3e2KyePH6jNxIgnp/WJAOktrDMEqHrYIdBpkkG4azw8QIUH54W/s0892msCXhsYb12zr o1OYzCFXeu4LRshOzk8GZGVI9xw72yOfPLTWLhRgmV0CpDyZ1WTgf8WaIRH2C4+t1ha+YT SyKL5x1RZRVEpxQFvfylD0n0qHT5AHZmmFd0RithzrYlhzva5jGjE3XZZZm4wLs1jTRnF2 45gmewj1c7V/5fWTOD4REHSLX/to+Hb/xUt0VFJiOxemckzr4PrroNmRyKy7gw== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790697454; b=Ne0TjV0AwIf50M9qrt8zshzkhFUu3kzZadF4YtOP12fw1vHf7jlmhz2RhZl/v43nV7Hat3 +9Z1VHT8gxkH097yOKco2l1YypYoMTN7t51W7ZFJYHsvAE3gDsJTJtGqLBUPsGU0cggJDt vw6sFtnSmOpQe8VcTbb6z/zu75WgU2y1xZ//RPK3E36EWrWgKOmt+aPItbV2TDUt4Ck9lj 5km8t5Dhgq1aZlrzOBdHFWkEkbt55zL7bHepkQgtCC9hL7R6EzGYwLpSsl97cdF6STr1gc 6T7v14NXSPzB+1Tj0i0DKdPP+7aN07rAA4wbr+R9WerPSkCCLBMdmHyFLpCGKw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790697454; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=sWySkm/JI0g3PAbv4KmdfiNZGruWaiM9sIcbBDqDxBc=; b=sB92WOzK5kt9ktmpWYw0px8HG5BGTorJf/5X66CwmzdLbrA44KNutUqpGpULjIJkvtdSEu WAt78M5lwzD+/MKeAPYK39/obUFsqdP+1StcvDQEuZPg8foDYKeJOrN3hp8eH9z0NJPYL1 SYlTXVRojgP42E+u8t/mBsoNabeIYQ7cTn/TL8i5y4VsG4UoWVt6AUoOkA9x1merr8lfU9 BVMzSfz2dJrJDr2d1IdYMw0ORBxVGWd9io1RZHZXBFgVNyr/WG+AiX9sRl+L2gJHPfWCLm 9wdP/9LBu4oN7RosPmA5th/O74TK6ELljmF/8au4Izs4GWw4FyD4kcoVBzyCWw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hvN9V1bkMz1KNQ for ; Tue, 29 Sep 2026 15:57:34 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 26be5 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 29 Sep 2026 15:57:34 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Mark Johnston Subject: git: 1c1575015cc0 - releng/14.4 - vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/releng/14.4 X-Git-Reftype: branch X-Git-Commit: 1c1575015cc09b3021a72af1d86f9549a546c246 Auto-Submitted: auto-generated Date: Tue, 29 Sep 2026 15:57:34 +0000 Message-Id: <6abbdfee.26be5.1313d371@gitrepo.freebsd.org> The branch releng/14.4 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=1c1575015cc09b3021a72af1d86f9549a546c246 commit 1c1575015cc09b3021a72af1d86f9549a546c246 Author: Mark Johnston AuthorDate: 2026-09-28 16:47:56 +0000 Commit: Mark Johnston CommitDate: 2026-09-28 18:17:20 +0000 vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR 262179 without entirely disallowing fd passing between jails. However, one can use renameat() to bypass the restriction: upon receiving a directory fd with FD_RESOLVE_BENEATH set, a jailed process can still move its CWD or one of its ancestors to the directory, and just cd out of its jail root. So disallow renameat() when either the source or destination directory fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot() to prevent similar escapes. Approved by: so Security: FreeBSD-SA-26:66.jail Security: CVE-2026-101305 PR: 262179 Reported by: firk@cantconnect.ru Reviewed by: olce, kib Differential Revision: https://reviews.freebsd.org/D59875 --- lib/libc/sys/fcntl.2 | 9 ++++++++- sys/kern/vfs_syscalls.c | 9 +++++++++ 2 files changed, 17 insertions(+), 1 deletion(-) diff --git a/lib/libc/sys/fcntl.2 b/lib/libc/sys/fcntl.2 index fdd29c9f5d78..427ae28dcfd6 100644 --- a/lib/libc/sys/fcntl.2 +++ b/lib/libc/sys/fcntl.2 @@ -27,7 +27,7 @@ .\" .\" @(#)fcntl.2 8.2 (Berkeley) 1/12/94 .\" -.Dd June 5, 2025 +.Dd September 22, 2026 .Dt FCNTL 2 .Os .Sh NAME @@ -150,6 +150,13 @@ and similar operations, and opening a directory with .Xr openat 2 where the directory descriptor has the flag set causes the new directory descriptor to also have the flag set. +A file descriptor with the +.Dv FD_RESOLVE_BENEATH +set cannot be used as either the source or target descriptor in +.Xr renameat 2 +or +.Xr renameat2 2 +system calls. .El .It Dv F_SETFD Set flags associated with diff --git a/sys/kern/vfs_syscalls.c b/sys/kern/vfs_syscalls.c index de2261256875..f261e3457122 100644 --- a/sys/kern/vfs_syscalls.c +++ b/sys/kern/vfs_syscalls.c @@ -3725,6 +3725,15 @@ again: } tdvp = tond.ni_dvp; tvp = tond.ni_vp; + if (fvp->v_type == VDIR && + ((fromnd.ni_resflags | tond.ni_resflags) & NIRES_BENEATH) != 0) { + /* + * We must not rename a directory relative to FD_RESOLVE_BENEATH + * descriptors. + */ + error = ENOTCAPABLE; + goto out; + } error = vn_start_write(fvp, &mp, V_NOWAIT); if (error != 0) { NDFREE_PNBUF(&fromnd);