From nobody Tue Sep 29 16:00:08 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hvNDS6VGqz6tlbW for ; Tue, 29 Sep 2026 16:00:08 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hvNDS3vlJz4gsZ for ; Tue, 29 Sep 2026 16:00:08 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790697608; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=SZ8TN5BhlRZkvs8NqkZqFm4bN6G2WrEt39rR3sXcJMo=; b=B9/gaof0AwWyZYsxBXWF0oPbZqCEiX/Cku9DxZpmFfrOZ+4onVMQg/iBZn6+FqMzSLq09M whvkGaAE7CwPoKqNF8hh/Ssb51kZbEi6M+7viml1VaEU4BTaOEkad7DQx6wO8204HIhLHU l7i09qzvpOSi5dBlgmZNbfcnTS6y2mNM2zxXr+AS56Xo/lvaz7bMojrAJpU8km5lckFLTa BywBj4RSLcO2CeRBBxdX4k22Y4WPXtEn94A9Rp1GS3dyjAs+cPKOXIXP/FQgglMfxqI5EE 3cH7rFkU6vHXUtzSfBSXmaLb7hAbNh05P4HyenwMmTXMgQUtGBOO3maA50cH5g== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790697608; b=ASnfH7+UHwVslfuhOiyXUyoo0zAttfG3XP1mlArHyI2rZa5UxXKScCGJfUgrNaNecAJMn2 aHs4yoj0Ewpi8tzEcGFYp/ifqysXjdbR7S3qBw5PsfBQuppn7F2gJWKWoh5AJyi5n/B6xe gfD4UwhZCiRNYI+24GdRUqplDJQQtz9ZYFWbXMGYQpvrJ3A2GfP5vLEZmDbt1AT3BckBJ8 gs2EzDDHOoAps8ibBuJoQsJkyiM7Dmf45Z94AOa82z40sskKe1LOHkZrqBEqIbrEkrkn0q qBxKrPIRyGJBB2agD8Dm8Sd2pOza96jl/Bgwp/CNRTVvtdU9XenDjaKUoy1a3g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790697608; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=SZ8TN5BhlRZkvs8NqkZqFm4bN6G2WrEt39rR3sXcJMo=; b=Jz2TatYtwkUEHFd/HN1Q49RUq4BFb++5JFIA5P1XCn+aYTRm1lqbNgIGbsUAFJ+CP6KuLi IKXjnvj4mpT8opLDS9QvpHq/YXfPYjypSmHF6PAMhsayKnl1SjIvH+GUdAz/7rMXOme14x VE1SbHbTUQPWSiVZ0lj/phu0UPT3+nz+SC8Zhga2xGPdf+7rImJ7W95BMIChkblXa01HCJ 51WIK6AoK6PlmI5ICA5DuJX0vQuHYJkVcai5h6tI9+Ie33qHT0KUzeYOdk9reId00QmVBZ uhdbZ+cxBZQJ4K2eSoSq0xpgRQd6LoN28lIJvIcQ6ZQT4sDmFMt1hVYkWlJGEw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hvNDS30Gjz1JbN for ; Tue, 29 Sep 2026 16:00:08 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3031c by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 29 Sep 2026 16:00:08 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Mark Johnston Subject: git: 84feda1967c9 - releng/15.1 - vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/releng/15.1 X-Git-Reftype: branch X-Git-Commit: 84feda1967c9f6f7dd404dcf015f4d791fa2b658 Auto-Submitted: auto-generated Date: Tue, 29 Sep 2026 16:00:08 +0000 Message-Id: <6abbe088.3031c.74c15306@gitrepo.freebsd.org> The branch releng/15.1 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=84feda1967c9f6f7dd404dcf015f4d791fa2b658 commit 84feda1967c9f6f7dd404dcf015f4d791fa2b658 Author: Mark Johnston AuthorDate: 2026-09-28 16:47:56 +0000 Commit: Mark Johnston CommitDate: 2026-09-29 01:01:48 +0000 vfs: Disallow renameat() with FD_RESOLVE_BENEATH descriptors The FD_RESOLVE_BENEATH flag was intended to try to resolve bugzilla PR 262179 without entirely disallowing fd passing between jails. However, one can use renameat() to bypass the restriction: upon receiving a directory fd with FD_RESOLVE_BENEATH set, a jailed process can still move its CWD or one of its ancestors to the directory, and just cd out of its jail root. So disallow renameat() when either the source or destination directory fds has FD_RESOLVE_BENEATH set, like we do with fchdir() and fchroot() to prevent similar escapes. Approved by: so Security: FreeBSD-SA-26:66.jail Security: CVE-2026-101305 PR: 262179 Reported by: firk@cantconnect.ru Reviewed by: olce, kib Differential Revision: https://reviews.freebsd.org/D59875 --- lib/libsys/fcntl.2 | 9 ++++++++- sys/kern/vfs_syscalls.c | 9 +++++++++ 2 files changed, 17 insertions(+), 1 deletion(-) diff --git a/lib/libsys/fcntl.2 b/lib/libsys/fcntl.2 index d67c38cfbc6c..8777222798d8 100644 --- a/lib/libsys/fcntl.2 +++ b/lib/libsys/fcntl.2 @@ -25,7 +25,7 @@ .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF .\" SUCH DAMAGE. .\" -.Dd June 24, 2025 +.Dd September 22, 2026 .Dt FCNTL 2 .Os .Sh NAME @@ -173,6 +173,13 @@ and similar operations, and opening a directory with .Xr openat 2 where the directory descriptor has the flag set causes the new directory descriptor to also have the flag set. +A file descriptor with the +.Dv FD_RESOLVE_BENEATH +set cannot be used as either the source or target descriptor in +.Xr renameat 2 +or +.Xr renameat2 2 +system calls. .El .It Dv F_SETFD Set flags associated with diff --git a/sys/kern/vfs_syscalls.c b/sys/kern/vfs_syscalls.c index a7e708181cdf..8306508f4b26 100644 --- a/sys/kern/vfs_syscalls.c +++ b/sys/kern/vfs_syscalls.c @@ -3837,6 +3837,15 @@ again: error = EEXIST; goto out; } + if (fvp->v_type == VDIR && + ((fromnd.ni_resflags | tond.ni_resflags) & NIRES_BENEATH) != 0) { + /* + * We must not rename a directory relative to FD_RESOLVE_BENEATH + * descriptors. + */ + error = ENOTCAPABLE; + goto out; + } error = vn_start_write(fvp, &mp, V_NOWAIT); if (error != 0) { again1: