2017-01-29 05:48:03 +01:00
|
|
|
{ config, lib, pkgs, ... }:
|
|
|
|
let
|
|
|
|
|
|
|
|
inherit (config.security) wrapperDir;
|
|
|
|
|
2017-01-29 08:07:12 +01:00
|
|
|
wrappers = config.security.wrappers;
|
|
|
|
mkWrapper = { program, source ? null, ...}: ''
|
|
|
|
if ! source=${if source != null then source else "$(readlink -f $(PATH=$WRAPPER_PATH type -tP ${program}))"}; then
|
|
|
|
# If we can't find the program, fall back to the
|
|
|
|
# system profile.
|
|
|
|
source=/nix/var/nix/profiles/default/bin/${program}
|
|
|
|
fi
|
|
|
|
|
|
|
|
gcc -Wall -O2 -DSOURCE_PROG=\"$source\" -DWRAPPER_DIR=\"${config.security.wrapperDir}\" \
|
2017-01-29 08:08:36 +01:00
|
|
|
-lcap-ng -lcap ${./wrapper.c} -o $out/bin/${program}.wrapper -L ${pkgs.libcap.lib}/lib -L ${pkgs.libcap_ng}/lib \
|
2017-01-29 08:07:12 +01:00
|
|
|
-I ${pkgs.libcap.dev}/include -I ${pkgs.libcap_ng}/include -I ${pkgs.linuxHeaders}/include
|
|
|
|
'';
|
|
|
|
|
|
|
|
wrappedPrograms = pkgs.stdenv.mkDerivation {
|
|
|
|
name = "permissions-wrapper";
|
|
|
|
unpackPhase = "true";
|
|
|
|
installPhase = ''
|
|
|
|
mkdir -p $out/bin
|
|
|
|
${lib.concatMapStrings mkWrapper wrappers}
|
|
|
|
'';
|
2017-01-29 08:16:04 +01:00
|
|
|
};
|
2017-01-29 05:48:03 +01:00
|
|
|
|
|
|
|
###### Activation script for the setcap wrappers
|
|
|
|
mkSetcapProgram =
|
|
|
|
{ program
|
|
|
|
, capabilities
|
|
|
|
, source ? null
|
|
|
|
, owner ? "nobody"
|
|
|
|
, group ? "nogroup"
|
2017-01-29 08:20:02 +01:00
|
|
|
, ...
|
2017-01-29 08:07:12 +01:00
|
|
|
}:
|
|
|
|
assert (lib.versionAtLeast (lib.getVersion config.boot.kernelPackages.kernel) "4.3");
|
|
|
|
''
|
|
|
|
cp ${wrappedPrograms}/bin/${program}.wrapper $wrapperDir/${program}
|
2017-01-29 05:48:03 +01:00
|
|
|
|
|
|
|
# Prevent races
|
|
|
|
chmod 0000 $wrapperDir/${program}
|
|
|
|
chown ${owner}.${group} $wrapperDir/${program}
|
|
|
|
|
|
|
|
# Set desired capabilities on the file plus cap_setpcap so
|
|
|
|
# the wrapper program can elevate the capabilities set on
|
|
|
|
# its file into the Ambient set.
|
|
|
|
${pkgs.libcap.out}/bin/setcap "cap_setpcap,${capabilities}" $wrapperDir/${program}
|
|
|
|
|
|
|
|
# Set the executable bit
|
|
|
|
chmod u+rx,g+x,o+x $wrapperDir/${program}
|
|
|
|
'';
|
|
|
|
|
|
|
|
###### Activation script for the setuid wrappers
|
|
|
|
mkSetuidProgram =
|
|
|
|
{ program
|
|
|
|
, source ? null
|
|
|
|
, owner ? "nobody"
|
|
|
|
, group ? "nogroup"
|
|
|
|
, setuid ? false
|
|
|
|
, setgid ? false
|
|
|
|
, permissions ? "u+rx,g+x,o+x"
|
2017-01-29 08:20:02 +01:00
|
|
|
, ...
|
2017-01-29 05:48:03 +01:00
|
|
|
}: ''
|
2017-01-29 08:07:12 +01:00
|
|
|
cp ${wrappedPrograms}/bin/${program}.wrapper $wrapperDir/${program}
|
2017-01-29 05:48:03 +01:00
|
|
|
|
|
|
|
# Prevent races
|
|
|
|
chmod 0000 $wrapperDir/${program}
|
|
|
|
chown ${owner}.${group} $wrapperDir/${program}
|
|
|
|
|
|
|
|
chmod "u${if setuid then "+" else "-"}s,g${if setgid then "+" else "-"}s,${permissions}" $wrapperDir/${program}
|
|
|
|
'';
|
|
|
|
in
|
|
|
|
{
|
|
|
|
|
|
|
|
###### interface
|
|
|
|
|
|
|
|
options = {
|
2017-01-29 08:22:47 +01:00
|
|
|
security.setuidPrograms = lib.mkOption {
|
2017-01-29 08:23:10 +01:00
|
|
|
type = lib.types.listOf lib.types.str;
|
2017-01-29 05:48:03 +01:00
|
|
|
default = [];
|
|
|
|
example = ["passwd"];
|
|
|
|
description = ''
|
|
|
|
The Nix store cannot contain setuid/setgid programs directly.
|
|
|
|
For this reason, NixOS can automatically generate wrapper
|
|
|
|
programs that have the necessary privileges. This option
|
|
|
|
lists the names of programs in the system environment for
|
|
|
|
which setuid root wrappers should be created.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
security.wrappers = lib.mkOption {
|
|
|
|
type = lib.types.attrs;
|
|
|
|
default = {};
|
|
|
|
example = {
|
|
|
|
sendmail.source = "/nix/store/.../bin/sendmail";
|
2017-01-29 08:22:19 +01:00
|
|
|
ping = {
|
|
|
|
source = "${pkgs.iputils.out}/bin/ping";
|
|
|
|
owner = "nobody";
|
|
|
|
group = "nogroup";
|
|
|
|
capabilities = "cap_net_raw+ep";
|
|
|
|
};
|
2017-01-29 05:48:03 +01:00
|
|
|
};
|
|
|
|
description = ''
|
|
|
|
This option allows the ownership and permissions on the setuid
|
|
|
|
wrappers for specific programs to be overridden from the
|
|
|
|
default (setuid root, but not setgid root).
|
2017-01-29 08:22:19 +01:00
|
|
|
|
|
|
|
Additionally, this option can set capabilities on a wrapper
|
|
|
|
program that propagates those capabilities down to the
|
|
|
|
wrapped, real program.
|
|
|
|
|
|
|
|
The <literal>program</literal> attribute is the name of the
|
|
|
|
program to be wrapped. If no <literal>source</literal>
|
|
|
|
attribute is provided, specifying the absolute path to the
|
|
|
|
program, then the program will be searched for in the path
|
|
|
|
environment variable.
|
|
|
|
|
|
|
|
NOTE: cap_setpcap, which is required for the wrapper program
|
|
|
|
to be able to raise caps into the Ambient set is NOT raised to
|
|
|
|
the Ambient set so that the real program cannot modify its own
|
|
|
|
capabilities!! This may be too restrictive for cases in which
|
|
|
|
the real program needs cap_setpcap but it at least leans on
|
|
|
|
the side security paranoid vs. too relaxed.
|
2017-01-29 05:48:03 +01:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
security.old-wrapperDir = lib.mkOption {
|
|
|
|
type = lib.types.path;
|
|
|
|
default = "/var/setuid-wrappers";
|
|
|
|
internal = true;
|
|
|
|
description = ''
|
|
|
|
This option defines the path to the wrapper programs. It
|
|
|
|
should not be overriden.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
|
|
|
|
security.wrapperDir = lib.mkOption {
|
|
|
|
type = lib.types.path;
|
|
|
|
default = "/run/wrappers";
|
|
|
|
internal = true;
|
|
|
|
description = ''
|
|
|
|
This option defines the path to the wrapper programs. It
|
|
|
|
should not be overriden.
|
|
|
|
'';
|
|
|
|
};
|
|
|
|
};
|
|
|
|
|
|
|
|
###### implementation
|
|
|
|
config = {
|
2017-01-29 08:07:12 +01:00
|
|
|
# Make sure our wrapperDir exports to the PATH env variable when
|
|
|
|
# initializing the shell
|
2017-01-29 05:48:03 +01:00
|
|
|
environment.extraInit = ''
|
2017-01-29 08:07:12 +01:00
|
|
|
# Wrappers override other bin directories.
|
2017-01-29 05:48:03 +01:00
|
|
|
export PATH="${wrapperDir}:$PATH"
|
|
|
|
'';
|
|
|
|
|
|
|
|
###### setcap activation script
|
|
|
|
system.activationScripts.wrappers =
|
|
|
|
let
|
|
|
|
programs =
|
|
|
|
(map (x: { program = x; owner = "root"; group = "root"; setuid = true; })
|
|
|
|
config.security.setuidPrograms)
|
|
|
|
++ lib.mapAttrsToList
|
|
|
|
(n: v: (if v ? "program" then v else v // {program=n;}))
|
2017-01-29 08:07:12 +01:00
|
|
|
wrappers;
|
2017-01-29 05:48:03 +01:00
|
|
|
|
2017-01-29 08:07:12 +01:00
|
|
|
mkWrappedPrograms =
|
2017-01-29 05:48:03 +01:00
|
|
|
builtins.map
|
2017-01-29 08:07:12 +01:00
|
|
|
(s: if (s ? "capabilities")
|
|
|
|
then mkSetcapProgram s
|
|
|
|
else if
|
|
|
|
(s ? "setuid" && s.setuid == true) ||
|
2017-01-29 05:48:03 +01:00
|
|
|
(s ? "setguid" && s.setguid == true) ||
|
|
|
|
(s ? "permissions")
|
|
|
|
then mkSetuidProgram s
|
|
|
|
else ""
|
|
|
|
) programs;
|
|
|
|
|
|
|
|
in lib.stringAfter [ "users" ]
|
|
|
|
''
|
|
|
|
# Look in the system path and in the default profile for
|
|
|
|
# programs to be wrapped.
|
|
|
|
WRAPPER_PATH=${config.system.path}/bin:${config.system.path}/sbin
|
|
|
|
|
|
|
|
mkdir -p ${wrapperDir}
|
|
|
|
wrapperDir=$(mktemp --directory --tmpdir=${wrapperDir} wrappers.XXXXXXXXXX)
|
|
|
|
chmod a+rx $wrapperDir
|
|
|
|
|
2017-01-29 08:07:12 +01:00
|
|
|
${lib.concatStringsSep "\n" mkWrappedPrograms}
|
2017-01-29 05:48:03 +01:00
|
|
|
'';
|
|
|
|
};
|
|
|
|
}
|