Skip to content

lsm/file: policy paths longer than 64 bytes are silently skipped #108

Description

@sixtoad

Discovered by the local Walk #84 linked-worktree Docker regression against Leash native-v0.3.11. No credential was mounted or read.

The public policy pipeline and MAX_PATH_LEN accept path rules up to 255 bytes, but the BPF file-open policy scan contains if (len == 0 || len > 64) continue. Any permit or forbid whose encoded path is longer than 64 bytes is therefore silently ignored. A governed write to a long Git metadata pointer succeeded because its exact forbid was skipped; the same hidden limit means earlier long-path success cases did not prove that their permits were enforced.

Expected: every accepted policy path is enforced consistently, or policy loading rejects lengths the kernel program cannot enforce. No accepted rule may silently disappear.

Acceptance:

  • Remove the silent 64-byte rule skip or fail policy loading before attachment for unsupported lengths; align parser, map encoding, BPF matcher, and documented limit.
  • Preserve ordered forbid/permit semantics, read-vs-write operation matching, default deny, and audit events for paths through the declared maximum.
  • Add focused boundary coverage at 64, 65, and the maximum supported length for both permit and forbid.
  • Add a real fail-closed BPF-LSM load/enforcement regression proving a >64-byte exact write forbid blocks the operation and a >64-byte permit authorizes only its declared path.
  • Keep the program below the real kernel verifier budget; do not weaken matching, truncate paths, or broaden prefixes.
  • Rerun the Walk release: native CLI must select a matching manager image #84 linked-worktree UID1001 Docker boundary with a fixed local manager before release.

Blocks Walk #84, which in turn blocks Walk #83 dogfood.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions