diff options
| author | Alvar Penning <post@0x21.biz> | 2026-02-05 20:58:25 +0100 |
|---|---|---|
| committer | Alvar Penning <post@0x21.biz> | 2026-02-05 21:17:44 +0100 |
| commit | ea81780895702b08b0b93ff48bd1876330632b89 (patch) | |
| tree | 007d4ef16eb1c2d4c20410491754beb07319f610 /sandbox.c | |
| parent | 81e461395ed46687d92a3f78a2d42b2d7aa10e56 (diff) | |
strip_exif support for the OpenBSD sandbox
Change the strip_exif logic to work with the already existing OpenBSD
sandbox and allow ffmpeg and mogrify to be executed.
The previous strip_exif implementation relied on system(3), effectively
starting "/bin/sh" and executing the required tool within a shell
session. Making this work in the sandbox would require to allow
executing "/bin/sh", rendering the sandbox useless.
Thus, the code now starts determining the absolute path of the tools -
unless they are given as ffmpeg_path or mogrify_path - and allowing them
to be executed via unveil(2). Then, instead of the system(3) call, the
good old fork(2) and execve(2) dance is performed.
The sbox_enter code was made aware of strip_exif, which resulted in a
pledge(2) violation before when disable_email_notifications was set to
false. Furthermore, the detected paths of the tools are now allowed.
Diffstat (limited to 'sandbox.c')
| -rw-r--r-- | sandbox.c | 9 |
1 files changed, 8 insertions, 1 deletions
@@ -13,6 +13,8 @@ void sbox_enter(const char *basedir) return; } + const xs_val *strip_exif = xs_dict_get(srv_config, "strip_exif"); + int smail; const char *url = xs_dict_get(srv_config, "smtp_url"); @@ -33,6 +35,11 @@ void sbox_enter(const char *basedir) if (*address == '/') unveil(address, "rwc"); + if (strip_exif) { + unveil(xs_dict_get(srv_config, "ffmpeg_path"), "x"); + unveil(xs_dict_get(srv_config, "mogrify_path"), "x"); + } + if (smail) unveil("/usr/sbin/sendmail", "x"); @@ -45,7 +52,7 @@ void sbox_enter(const char *basedir) if (*address == '/') p = xs_str_cat(p, " unix"); - if (smail) + if (smail || strip_exif) p = xs_str_cat(p, " exec"); pledge(p, NULL); |