Files
sousa-gecko/security/sandbox/linux/SandboxBrokerClient.h
T
Jed Davis 7538e5fa88 Bug 2040515 - Rip out the symlink brokering. r=Thinker
This is almost certainly unused.  Bug 1380701 comment #23 mentioned
PulseAudio in content processes, which is no longer supported.  (If
you flip `media.cubeb.sandbox` for testing, you'll need to turn off
sandboxing; you should not flip that pref for production use.)

In general there are very few places left where sandboxed processes can
create files, and none of them should need symlinks.  However, there
might be libraries which were calling symlink and silently failing.

Given all of that, this patch does not return symlink/symlinkat to being
unexpected syscalls (crash on Nightly, ENOSYS otherwise) but instead just
makes them quietly fail with EPERM.  (This happens to match macOS, it's a
reasonable error code, and tests can distinguish it from the EACCES of a
broker rejection.)

Differential Revision: https://phabricator.services.mozilla.com/D301463
2026-06-03 01:06:58 +00:00

53 lines
1.8 KiB
C++

/* This Source Code Form is subject to the terms of the Mozilla Public
* License, v. 2.0. If a copy of the MPL was not distributed with this file,
* You can obtain one at http://mozilla.org/MPL/2.0/. */
#ifndef mozilla_SandboxBrokerClient_h
#define mozilla_SandboxBrokerClient_h
#include "broker/SandboxBrokerCommon.h"
#include "broker/SandboxBrokerUtils.h"
// This is the client for the sandbox broker described in
// broker/SandboxBroker.h; its constructor takes the file descriptor
// returned by SandboxBroker::Create, passed to the child over IPC.
//
// The operations exposed here can be called from any thread and in
// async signal handlers, like the corresponding system calls. The
// intended use is from a seccomp-bpf SIGSYS handler, to transparently
// replace those syscalls, but they could also be used directly.
struct stat;
struct sockaddr_un;
namespace mozilla {
class SandboxBrokerClient final : private SandboxBrokerCommon {
public:
explicit SandboxBrokerClient(int aFd);
~SandboxBrokerClient();
int Open(const char* aPath, int aFlags);
int Access(const char* aPath, int aMode);
int Stat(const char* aPath, statstruct* aStat);
int LStat(const char* aPath, statstruct* aStat);
int Chmod(const char* aPath, int aMode);
int Link(const char* aPath, const char* aPath2);
int Mkdir(const char* aPath, int aMode);
int Rename(const char* aOldPath, const char* aNewPath);
int Unlink(const char* aPath);
int Rmdir(const char* aPath);
int Readlink(const char* aPath, void* aBuf, size_t aBufSize);
int Connect(const struct sockaddr_un* aAddr, size_t aLen, int aType);
private:
int mFileDesc;
int DoCall(const Request* aReq, const char* aPath, const char* aPath2,
void* aReponseBuff, bool expectFd);
};
} // namespace mozilla
#endif // mozilla_SandboxBrokerClient_h