-
-
Notifications
You must be signed in to change notification settings - Fork 14
linux: support protection keys for Chromium sandboxing #522
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
+721
−6
Merged
Changes from all commits
Commits
Show all changes
5 commits
Select commit
Hold shift + click to select a range
79f1605
linux: implement memory protection key syscalls
laffer1 ab3dd6c
UPDATING: note Linuxulator protection key support
laffer1 2c13119
linux: fix pkey syscall portability and feature checks
laffer1 3a32191
linux: include image activation definitions in emul MD files
laffer1 a09d98d
linux: prevalidate pkey_mprotect ranges
laffer1 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,52 @@ | ||
| # Linux Brave Sandbox Backport Plan | ||
|
|
||
| ## Goal | ||
|
|
||
| Backport FreeBSD's Linuxulator memory protection key support so | ||
| Chromium-based Linux applications, including Brave, can use the V8 heap and | ||
| JIT sandbox on MidnightBSD/amd64. | ||
|
|
||
| ## Upstream changes | ||
|
|
||
| 1. Backport FreeBSD commit `7bcaff05223e`, which exposes XSAVE feature and | ||
| save-area layout information. | ||
| 2. Backport FreeBSD commit `b9951017bab3`, which extends the XSAVE helpers to | ||
| account for supervisor-state components. | ||
| 3. Adapt FreeBSD commit `bdb561843e86`, which implements Linux | ||
| `pkey_alloc(2)`, `pkey_free(2)`, and `pkey_mprotect(2)` using native amd64 | ||
| PKU support. | ||
| 4. Treat FreeBSD commit `34718e01869b`, which maps `IFF_LOWER_UP` through | ||
| Linux `NETLINK_ROUTE`, as a separate follow-up because it fixes Brave | ||
| network detection rather than sandboxing. | ||
|
|
||
| ## Integration approach | ||
|
|
||
| - Preserve the upstream split between common Linux syscall validation and | ||
| machine-dependent PKU operations. | ||
| - Keep protection-key allocation state in Linux per-process emulation data, | ||
| inherited on fork and reset on exec. | ||
| - Initialize PKRU to Linux's `0x55555554` default during Linux exec. | ||
| - Retain Linux-compatible no-PKU behavior on unsupported architectures. | ||
| - Adapt source and module Makefiles to MidnightBSD's current tree instead of | ||
| applying conflicting upstream hunks mechanically. | ||
| - Preserve existing syscall numbers and replace only their ENOSYS stubs. | ||
|
|
||
| ## Validation | ||
|
|
||
| 1. Run the repository C static-analysis scripts on staged C and header files. | ||
| 2. Build the affected `linux_common`, Linux ABI modules, and amd64 kernel. | ||
| 3. Exercise allocation, protection changes, access-right changes, fork | ||
| inheritance, exec reset, key exhaustion, and protection-key faults with a | ||
| small Linux test program. | ||
| 4. Confirm protection-key faults translate to Linux `SEGV_PKUERR`. | ||
| 5. Start Linux Brave on PKU-capable amd64 hardware and inspect its sandbox | ||
| status. | ||
| 6. Test the no-PKU fallback where suitable hardware is available. | ||
|
|
||
| ## Commit structure | ||
|
|
||
| - XSAVE query helpers. | ||
| - Linuxulator protection-key syscall support. | ||
| - Tests, if kept separate by the existing test layout. | ||
| - `UPDATING` entry as an independently reviewable commit, after approval. | ||
| - Optional `IFF_LOWER_UP` compatibility fix as a separate change. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,35 @@ | ||
| /* | ||
| * SPDX-License-Identifier: BSD-2-Clause | ||
| * | ||
| * Copyright (c) 2026 Devin Teske <dteske@FreeBSD.org> | ||
| */ | ||
|
|
||
| #ifndef _AMD64_LINUX_EMUL_MD_H_ | ||
| #define _AMD64_LINUX_EMUL_MD_H_ | ||
|
|
||
| /* | ||
| * Machine-dependent part of the Linux process emuldata, embedded in | ||
| * struct linux_pemuldata as pem_md. | ||
| */ | ||
| struct linux_pemuldata_md { | ||
| uint32_t md_pkey_allocation_map; /* x86 protection keys */ | ||
| }; | ||
|
|
||
| /* | ||
| * Initial protection key allocation map: key 0 is the default key, | ||
| * implicitly allocated on Linux (mm_pkey_allocation_map is initialized | ||
| * to 0x1). Inherited on fork, reset on exec. | ||
| */ | ||
| #define LINUX_PKEY_INITIAL_MAP 0x1 | ||
|
|
||
| /* | ||
| * Initial PKRU at exec: access disabled for keys 1..15, key 0 open; | ||
| * the Linux init_pkru default. | ||
|
sourcery-ai[bot] marked this conversation as resolved.
|
||
| */ | ||
| #define LINUX_PKRU_INIT 0x55555554 | ||
|
|
||
| struct thread; | ||
|
|
||
| void linux_pkru_exec_init(struct thread *); | ||
|
|
||
| #endif /* !_AMD64_LINUX_EMUL_MD_H_ */ | ||
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Low:
xstate_bvisuint64_tbutffs()takesint, so any component bit >= 32 is silently dropped from the compact-offset walk. Not reachable today (the only caller passescompact=false, and no enabled component is above bit 31), but the loop is wrong as written: with a high component set inxstate_bvthe loop terminates early and returns a too-small offset.ffsl()(orffsll()) is the intended primitive.