diff --git a/support/rrsync b/support/rrsync index d69c17cf..a5618b73 100755 --- a/support/rrsync +++ b/support/rrsync @@ -132,9 +132,37 @@ long_opts = { ### END of options data produced by the cull-options script. ### -import os, sys, re, argparse, glob, socket, time, subprocess +import os, sys, re, argparse, glob, socket, stat, time, subprocess from argparse import RawTextHelpFormatter +# Held open across exec so rsync inherits them. Each entry pins a path +# validated_arg() approved; the corresponding arg passed to rsync is +# rewritten to /proc/self/fd/N so rsync's path resolution cannot be +# race-flipped after rrsync's realpath check, closing the realpath-vs-exec +# TOCTOU. +pinned_fds = [] + +# The inode-pin trick needs /proc/self/fd/N to be a Linux-style magic symlink +# whose readlink yields the open file's real path. macOS/BSD lack the directory +# entirely; Solaris HAS /proc/self/fd but its entries are not such symlinks (its +# readlink does not return the path), so an isdir() check is not enough -- probe +# the actual behaviour once against a known fd. Where it works we pin (and a +# later readlink failure is an anomaly that fails closed); where it does not we +# fall through to the unhardened path. +def _probe_proc_self_fd(): + try: + fd = os.open('/', os.O_RDONLY) + except OSError: + return False + try: + return os.readlink('/proc/self/fd/%d' % fd) == '/' + except OSError: + return False + finally: + os.close(fd) + +HAVE_PROC_SELF_FD = _probe_proc_self_fd() + try: from braceexpand import braceexpand except: @@ -144,6 +172,24 @@ HAS_DOT_DOT_RE = re.compile(r'(^|/)\.\.(/|$)') LONG_OPT_RE = re.compile(r'^--([^=]+)(?:=(.*))?$') DE_BACKSLASH_RE = re.compile(r'\\(.)') +def safe_open_logfile(): + nofollow = getattr(os, 'O_NOFOLLOW', 0) + try: + st = os.lstat(LOGFILE) + except OSError: + return None + if not stat.S_ISREG(st.st_mode): + return None + try: + fd = os.open(LOGFILE, os.O_WRONLY | os.O_APPEND | nofollow) + except OSError: + return None + st2 = os.fstat(fd) + if not stat.S_ISREG(st2.st_mode) or st.st_dev != st2.st_dev or st.st_ino != st2.st_ino: + os.close(fd) + return None + return os.fdopen(fd, 'a') + def main(): if not os.path.isdir(args.dir): die("Restricted directory does not exist!") @@ -188,6 +234,7 @@ def main(): if args.dir != '/': global short_disabled short_disabled += short_disabled_subdir + long_opts['copy-unsafe-links'] = -1 short_no_arg_re = short_no_arg short_with_num_re = short_with_num @@ -199,7 +246,7 @@ def main(): short_no_arg_re = re.compile(r'^-(?=.)[%s]*(e\d*\.\w*)?$' % short_no_arg_re) short_with_num_re = re.compile(r'^-[%s]\d+$' % short_with_num_re) - log_fh = open(LOGFILE, 'a') if os.path.isfile(LOGFILE) else None + log_fh = safe_open_logfile() try: os.chdir(args.dir) @@ -262,6 +309,15 @@ def main(): if not saw_the_dot_arg: die("invalid rsync-command syntax or options") + if args.dir != '/': + # A restricted dir denies device/special creation, but `-a` (-rlptgoD) + # bundles -D into the client's short-option string, so rejecting -D + # outright would break every `rsync -a` to/from a restricted rrsync. + # Force --no-D instead: it follows the client's options, so it strips + # the device/special semantics (devices/specials are skipped, not + # created) while the rest of the transfer proceeds normally. + rsync_opts.append('--no-D') + if args.munge: rsync_opts.append('--munge-links') @@ -289,7 +345,10 @@ def main(): if args.no_lock: os.execlp(RSYNC, *cmd) die("execlp(", RSYNC, *cmd, ') failed') - child = subprocess.run(cmd) + # pass_fds keeps the inode-pinning O_PATH fds open across the spawn so + # /proc/self/fd/N in the cmd resolves correctly in the child. See the + # pinned_fds comment near the top. + child = subprocess.run(cmd, pass_fds=tuple(pinned_fds)) if child.returncode != 0: sys.exit(child.returncode) @@ -330,6 +389,113 @@ def validated_arg(opt, arg, typ=3, wild=False): if arg != real_arg and not real_arg.startswith(args.dir_slash): if not (is_absolute_arg and real_arg == args.dir): die('unsafe arg:', orig_arg, [arg, real_arg]) + # Inode-pin the validated path so an attacker cannot flip a + # path component AFTER realpath validates it but BEFORE the + # exec'd rsync resolves it. + # + # CRITICAL: open with O_RDONLY (not O_PATH). An O_PATH fd + # holds a path/dentry reference and /proc/self/fd/N for an + # O_PATH fd re-resolves the path on open -- which means the + # race window stays open across the exec. A regular + # O_RDONLY fd holds an open file (inode-bound), and + # /proc/self/fd/N for a regular fd references the inode + # directly -- exactly the race-closing primitive we need. + # + # O_NOFOLLOW on this open means a symlink that raced into + # place between realpath and this open is refused at the + # leaf. A subsequent fstat() + readlink-of-fd verifies the + # pinned inode is still within the restricted tree (a + # parent-component race that landed on an in-tree symlink + # but outside-tree target would surface here). + # + # /proc/self/fd/N then routes the exec'd rsync's open + # through the kernel's magic link to the SAME pinned inode + # regardless of any subsequent flip; the race is closed. + # + # Linux-only (O_PATH/proc trick is Linux specific); on + # non-Linux fall through to the unhardened path. For paths + # that don't exist yet (receiver-side new dest) os.open + # fails -- we skip pinning there; the new-dest race is a + # separate concern. + try: + try: + fd = os.open(real_arg, os.O_RDONLY | os.O_NOFOLLOW) + except IsADirectoryError: + fd = os.open(real_arg, + os.O_RDONLY | os.O_NOFOLLOW | os.O_DIRECTORY) + except FileNotFoundError: + # In --sender mode the path MUST exist (we're reading + # from it) -- ENOENT here means the rename-based race + # caught a transient gap in the flipper's swap. Die. + if am_sender: + die('post-realpath open failed (race detected):', + orig_arg, 'No such file or directory') + # Receiver-side new destination: the leaf has no inode to pin + # yet, but pin its existing PARENT directory and route the + # exec'd rsync's creation through /proc/self/fd//, + # so a parent-component flip after realpath can't redirect the + # new file/dir out of the tree. Linux-only (the /proc magic + # link); elsewhere, or if the parent itself doesn't exist yet + # (a deeper -R new path), fall through unpinned as before. + fd = None + leaf = os.path.basename(real_arg) + if HAVE_PROC_SELF_FD and leaf and leaf not in ('.', '..'): + try: + pfd = os.open(os.path.dirname(real_arg) or '/', + os.O_RDONLY | os.O_NOFOLLOW | os.O_DIRECTORY) + except OSError: + pfd = -1 + if pfd >= 0: + try: + ppath = os.readlink('/proc/self/fd/%d' % pfd) + except OSError as e: + os.close(pfd) + die('post-pin readlink failed (race?):', + orig_arg, e.strerror) + # The pinned parent must be the tree root or under it. + if ppath != args.dir and not ppath.startswith(args.dir_slash): + os.close(pfd) + die('post-pin path escaped tree (race?):', + orig_arg, ppath) + os.set_inheritable(pfd, True) + pinned_fds.append(pfd) + arg = '/proc/self/fd/%d/%s' % (pfd, leaf) + except OSError as e: + # ELOOP or anything else is a race signal: realpath + # validated the path moments ago, but the open just + # failed -- something flipped between the check and + # the pin (typically a symlink-flip on the leaf). + die('post-realpath open failed (race detected):', + orig_arg, e.strerror) + if fd is not None: + # The inode-pin trick (verify + route the exec'd rsync's open via + # the /proc/self/fd magic link) is Linux-only. Where /proc/self/fd + # does not exist at all (the BSDs, Solaris, macOS, Cygwin, or a + # /proc-less namespace) we cannot pin -- fall through to the + # unhardened path (close the fd, keep the realpath-validated arg) + # per the design note above. But where /proc/self/fd DOES exist + # (Linux), a readlink failure is an anomaly (sandbox/seccomp), not + # a no-proc platform: fail CLOSED rather than silently unharden. + if not HAVE_PROC_SELF_FD: + os.close(fd) # no /proc/self/fd: run unpinned + else: + try: + pinned_path = os.readlink('/proc/self/fd/%d' % fd) + except OSError as e: + os.close(fd) + die('post-pin readlink failed (race?):', + orig_arg, e.strerror) + # The pinned inode must live under args.dir_slash (or BE + # args.dir). Catches a parent-component flip that landed + # inside an in-tree path but pointed outside. + if (not pinned_path.startswith(args.dir_slash) + and pinned_path != args.dir): + os.close(fd) + die('post-pin path escaped tree (race?):', + orig_arg, pinned_path) + os.set_inheritable(fd, True) + pinned_fds.append(fd) + arg = '/proc/self/fd/%d' % fd if arg_has_trailing_slash: arg += '/' elif arg_has_trailing_slash_dot: @@ -346,13 +512,20 @@ def validated_arg(opt, arg, typ=3, wild=False): def lock_or_die(dirname): - import fcntl + import fcntl, errno global lock_handle lock_handle = os.open(dirname, os.O_RDONLY) try: fcntl.flock(lock_handle, fcntl.LOCK_EX | fcntl.LOCK_NB) - except: - die('Another instance of rrsync is already accessing this directory.') + except OSError as e: + if e.errno in (errno.EWOULDBLOCK, errno.EAGAIN, errno.EACCES): + die('Another instance of rrsync is already accessing this directory.') + # flock() is unavailable on this fd/platform -- e.g. Solaris returns + # EBADF for flock() on a directory fd. The single-run lock is a + # best-effort convenience (cf. -no-lock), not a security control, so + # proceed without it rather than abort every transfer. + os.close(lock_handle) + lock_handle = None def die(*msg):