OpenBSD system-call-origin verification
OpenBSD system-call-origin verification
Posted Dec 19, 2019 10:29 UTC (Thu) by Cyberax (✭ supporter ✭, #52523)In reply to: OpenBSD system-call-origin verification by marcH
Parent article: OpenBSD system-call-origin verification
Posted Dec 19, 2019 15:46 UTC (Thu)
by mathstuf (subscriber, #69389)
[Link] (9 responses)
Posted Dec 19, 2019 20:15 UTC (Thu)
by Cyberax (✭ supporter ✭, #52523)
[Link] (8 responses)
Posted Dec 20, 2019 17:06 UTC (Fri)
by cortana (subscriber, #24596)
[Link] (7 responses)
Posted Dec 20, 2019 20:31 UTC (Fri)
by Cyberax (✭ supporter ✭, #52523)
[Link] (5 responses)
Posted Dec 21, 2019 13:26 UTC (Sat)
by cortana (subscriber, #24596)
[Link] (3 responses)
Posted Dec 21, 2019 16:44 UTC (Sat)
by dezgeg (subscriber, #92243)
[Link] (2 responses)
Posted Dec 24, 2019 1:01 UTC (Tue)
by mathstuf (subscriber, #69389)
[Link]
Posted Dec 24, 2019 12:31 UTC (Tue)
by cortana (subscriber, #24596)
[Link]
And that NSS will tell you a host's addresses but not which interface they are reachable via, or whether the query was secured by DNSSEC, dns-over-tls, etc, which resolved does provide via its D-BUS API.
(As well as being able to do nifty things like LLMNR, or split-DNS. OTOH resolved does have its own bugs and limitations that drive me up the wall a bit...)
Posted Jan 8, 2020 11:20 UTC (Wed)
by nix (subscriber, #2304)
[Link]
This isn't to avoid libraries getting loaded behind your back into a running process so much as it is to allow removal of the incredibly convoluted and invasive statically-linked dlopen() feature, which is only really there so that statically linked programs can do name lookups. (But moving all the NSS stuff out of every process's address space into one more controllable domain is definitely a side benefit!)
(I am only an egg, but this is my understanding, anyway. My apologies if I'm mischaracterizing anything or accidentally mixing it up with my own ideas of obviously right implementations etc: human memory is a fallible thing...)
Posted Jan 9, 2020 1:34 UTC (Thu)
by anselm (subscriber, #2796)
[Link]
Probably not, given that the uses of NSS and those of systemd-resolved only overlap slightly.
OpenBSD system-call-origin verification
OpenBSD system-call-origin verification
OpenBSD system-call-origin verification
OpenBSD system-call-origin verification
OpenBSD system-call-origin verification
OpenBSD system-call-origin verification
OpenBSD system-call-origin verification
OpenBSD system-call-origin verification
OpenBSD system-call-origin verification
OpenBSD system-call-origin verification