From nobody Wed Feb 26 14:24:28 2025 X-Original-To: freebsd-hackers@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Z2xb00Y2jz5qBHf for ; Wed, 26 Feb 2025 14:25:32 +0000 (UTC) (envelope-from vini.ipsmaker@gmail.com) Received: from mail-lj1-x22f.google.com (mail-lj1-x22f.google.com [IPv6:2a00:1450:4864:20::22f]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (2048 bits) client-digest SHA256) (Client CN "smtp.gmail.com", Issuer "WR4" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Z2xZz4WZdz45Hn; Wed, 26 Feb 2025 14:25:31 +0000 (UTC) (envelope-from vini.ipsmaker@gmail.com) Authentication-Results: mx1.freebsd.org; none Received: by mail-lj1-x22f.google.com with SMTP id 38308e7fff4ca-30a69c1a8d3so40163161fa.3; Wed, 26 Feb 2025 06:25:31 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1740579929; x=1741184729; darn=freebsd.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=mTCHs/W1PsAr6KHaFir6aRYhAtBiIqp/7amNqHPxILQ=; b=VbomjtSYTH2cjXw8xeFm+0VOrBNAKDurpFMrm2WXIq5g4SnOoaK11quFmmHUkbtXOD 8tOHu0k31Vl4zALr3nivXh2CGK7v4VnTkHEYR7Rb3mSmUrQWJJ7XLZJLjgf4FxGC9CTx YLKKdutxWtUzkc1tTE6tYQwWHcWqgWyulny5vKWcwlMbwHr/Q35l03C0WiB0AIB30B6B mPEp7FjIwUxWzaPFr2JeafBGgvZD88OH90o+JlxuJtBK09WG//yt6L0KcrpdoA2unOO3 CKWZNgZx83z8CbTCZpEdiHFLhDurXfGV1gJa84dM4bxhxT//9P/I5/UdvAr4+UXZ2ddT 2FyQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1740579929; x=1741184729; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=mTCHs/W1PsAr6KHaFir6aRYhAtBiIqp/7amNqHPxILQ=; b=S8JXvKxTM3L0BD1juGKaC9oLhfkgxMV82k4S0TnvgSFVs5TvwjGY5TvNcVobALvMte D9EaabcQQKMwLe5v0cWo57H/vCdk/WaZ8StmiUxOm9cM3yd4xKNz+30speoh/Aifx7Xl ngdn/YcwDKsT9vTeTaBrGR6ZtZjacAYJWpQ35NiaOA1a5FA4zWGp/TI4ZrzWzmD4PsXN CeGsGQd807a78E7jle4b0RGBSnMfhMbU2yt19+2FoTbvL+VcYK48EzRyGGBwrN7T9Cgz ZJqWGX64oZJF6gU9tKQR97BYwH05i8mBq0m1hLLPERvfx6pNUh6XuqEOVWIhmX87tWEj 4IHQ== X-Forwarded-Encrypted: i=1; AJvYcCW2g9ecCCjEtRFlcBkYHTMYvLhiQCDrkIahebyqotrlfg6pN7sIFxW0yfqvwoWuNoxquQ2qI5mC+nnE+h+A4VQ=@freebsd.org X-Gm-Message-State: AOJu0YwrF8SXl4tp/zqr4btb/7gXDVqiVOC1G+lEmHOkliCfoHmT9FPi WzuKOPs0n3N6BL7xMDKh6w3bUFfyWjWWE7F6kPM5/9xAfBlXmwUAU7+AoQv4avZnC2Y3Spa9awM 1k27S23ZCUE+S0Wo2A4hmhRBOYv1TJLvq X-Gm-Gg: ASbGncv+xbq6JYlB1SVuYx+jqlRmPUCbKbDToOSxe85PWfcfYvPg9llNBU0/5E67vC1 FIQttmP9YDq8GCk1p1bsvWuSgfzw9S6RvKO76PGjecQE4odv/7JVOKBv4+5OpmlMz+xOa/joYEN lXHN27s5A63ntERVsIgSab1q+8N8hT+okQ2o7kjiEOnA== X-Google-Smtp-Source: AGHT+IE8clxC6NKw4s0iTJdCEi0uGYmS/rC1TusiOrhOkMX+ws4Enub2O59qTLLf/NmXDWaalUAJh+qAjxWj7B8MZjU= X-Received: by 2002:a2e:808c:0:b0:308:ed4d:6297 with SMTP id 38308e7fff4ca-30a59899cbdmr93150411fa.11.1740579928875; Wed, 26 Feb 2025 06:25:28 -0800 (PST) List-Id: Technical discussions relating to FreeBSD List-Archive: https://lists.freebsd.org/archives/freebsd-hackers List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-hackers@FreeBSD.org MIME-Version: 1.0 References: In-Reply-To: From: =?UTF-8?Q?Vin=C3=ADcius_dos_Santos_Oliveira?= Date: Wed, 26 Feb 2025 11:24:28 -0300 X-Gm-Features: AQ5f1JoejtBqdx8Xvoo5kIrCgZtH-2MOZGBvjWcSCDjA4lM0lbKnI4fJDWPVQRQ Message-ID: Subject: Re: Capsicum and weak libc symbols To: David Chisnall Cc: Konstantin Belousov , FreeBSD Hackers Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Rspamd-Pre-Result: action=no action; module=replies; Message is reply to one we originated X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[]; TAGGED_FROM(0.00)[]; ASN(0.00)[asn:15169, ipnet:2a00:1450::/32, country:US] X-Rspamd-Queue-Id: 4Z2xZz4WZdz45Hn X-Spamd-Bar: ---- Em qua., 26 de fev. de 2025 =C3=A0s 10:51, David Chisnall escreveu: > Did you look at the repository I shared earlier? It intercepts getaddrin= fo for libraries and exposes hooks in the parent for exposing policies. It= works on FreeBSD and Linux. It seems to rely on ELF tricks. I don't know how it copes with static binaries (e.g. linked against /usr/lib/libc.a). Aside from that, the interposition design doesn't seem too different from what I've been doing. --=20 Vin=C3=ADcius dos Santos Oliveira https://vinipsmaker.github.io/