Skip to content

Commit 0124680

Browse files
chore(sandbox): remove unused capability dependency and refresh Landlock comments
Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
1 parent 4efd52d commit 0124680

4 files changed

Lines changed: 40 additions & 56 deletions

File tree

‎Cargo.lock‎

Lines changed: 24 additions & 42 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎crates/openshell-sandbox/Cargo.toml‎

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,6 @@ russh-sftp = "3.0"
7373
uuid = { workspace = true }
7474

7575
[target.'cfg(target_os = "linux")'.dependencies]
76-
capctl = "0.2.4"
7776
landlock = "0.4"
7877
seccompiler = "0.5"
7978
socket2 = { workspace = true }

‎crates/openshell-sandbox/src/sandbox/linux/landlock.rs‎

Lines changed: 11 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -88,9 +88,10 @@ pub fn probe_availability() -> LandlockAvailability {
8888

8989
/// A prepared Landlock ruleset ready to be enforced via `restrict_self()`.
9090
///
91-
/// Created by [`prepare`] while running as root (so `PathFd::new()` can open
92-
/// any path regardless of DAC permissions). Enforced by [`enforce`] after
93-
/// `drop_privileges()` — `restrict_self()` does not require elevated privileges.
91+
/// Path FDs are opened before enforcement. The capability-free launch path
92+
/// prepares the baseline and user rules as the workload identity, then calls
93+
/// [`enforce`] in the child before exec. `restrict_self()` does not require
94+
/// elevated privileges.
9495
pub struct PreparedRuleset {
9596
ruleset: landlock::RulesetCreated,
9697
compatibility: LandlockCompatibility,
@@ -102,10 +103,11 @@ enum PathOpenMode {
102103
CurrentUser,
103104
}
104105

105-
/// Phase 1: Open `PathFds` and build the Landlock ruleset **as root**.
106+
/// Phase 1: Open `PathFds` and build the Landlock ruleset with strict path opening.
106107
///
107-
/// This must run before `drop_privileges()` so that `PathFd::new()` can open
108-
/// paths that are only accessible to root (e.g. mode 700 directories).
108+
/// Opens configured paths as the calling identity. Inaccessible paths fail in
109+
/// hard-requirement mode and are skipped in best-effort mode. Unlike
110+
/// [`prepare_current_user`], this does not always omit inaccessible paths.
109111
///
110112
/// Returns `None` if there are no filesystem paths to restrict (no-op).
111113
/// Returns `Some(PreparedRuleset)` on success, or an error.
@@ -394,9 +396,9 @@ fn prepare_with_path_open_mode(
394396

395397
/// Phase 2: Enforce a prepared Landlock ruleset by calling `restrict_self()`.
396398
///
397-
/// This runs **after** `drop_privileges()`. The `restrict_self()` syscall does
398-
/// not require root — it only restricts the calling thread (and its future
399-
/// children), which is always permitted.
399+
/// The capability-free launch path calls this in the child before exec, already
400+
/// running as the workload identity. `restrict_self()` does not require root;
401+
/// it restricts the calling thread and its future children.
400402
///
401403
/// Respects the same `best_effort` / `hard_requirement` compatibility as
402404
/// [`prepare`]: if `restrict_self()` fails and the policy is `best_effort`,

‎crates/openshell-sandbox/src/sandbox/linux/mod.rs‎

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -18,10 +18,11 @@ pub struct PreparedSandbox {
1818
policy: SandboxPolicy,
1919
}
2020

21-
/// Phase 1: Prepare sandbox restrictions **as root** (before `drop_privileges`).
21+
/// Phase 1: Prepare sandbox restrictions with strict path opening.
2222
///
23-
/// Opens Landlock `PathFds` while the process still has root privileges,
24-
/// ensuring paths like mode-700 directories are accessible.
23+
/// Opens configured paths as the calling identity and handles failures according
24+
/// to the policy's Landlock compatibility mode.
25+
/// The capability-free launch path uses [`prepare_capability_free`] instead.
2526
pub fn prepare(policy: &SandboxPolicy, workdir: Option<&str>) -> Result<PreparedSandbox> {
2627
let landlock = landlock::prepare(policy, workdir)?;
2728
Ok(PreparedSandbox {
@@ -66,7 +67,7 @@ pub fn prepare_capability_free(
6667
})
6768
}
6869

69-
/// Phase 2: Enforce prepared sandbox restrictions (after `drop_privileges`).
70+
/// Phase 2: Enforce prepared sandbox restrictions in the child before exec.
7071
///
7172
/// Calls `restrict_self()` for Landlock and applies seccomp filters.
7273
/// Neither operation requires root privileges.

0 commit comments

Comments
 (0)