[roll] Roll fuchsia [starnix] Reland: Add ptrace access checks to /proc/<pid>

This is a reland of CL Id186b7764bd92398420c3b80c1808e563981c882
with:
1. the SimpleFileNode API changes broken out into a prefactor CL.
2. "stat" checks are broken out to a follow-up CL.

Nodes in /proc/pid that expose sensitive information about a task
("auxv", "environ", "maps", "smaps", "fd" and its contents) require
a ptrace "read" access check to open().

The /proc/pid/mem node, which provides greater access to a task's
address-space, requires a ptrace "attach" check to open().

Finally, the /proc/pid/stat file require a ptrace "read" check on
open(), which determines the information that is exposed, rather
than gating access. This check is made with the no-audit flag, to
prevent the LSM (e.g. SELinux) from audit-logging denials.

Original-Bug: 467438310, 438161520, 475912243
Test: starnix_gvisor_proc_test and procfs_test
Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1486197
Original-Revision: 5f5f229d6900cf28e45a2bede1f2864df415bf91
GitOrigin-RevId: 72df2ba0d4fc3cf50f50bd7300ddbf24fd1ef85f
Change-Id: Ib460e0dedb6928c1dc4e4f4a2f57b7a51b812bf3
1 file changed
tree: 476af38c0e8432c5d87e56d34bc0ae4622412cfb
  1. ctf/
  2. git-hooks/
  3. infra/
  4. third_party/
  5. flower
  6. jiri.lock
  7. MILESTONE
  8. minimal
  9. prebuilts
  10. README.md
  11. stem
  12. test_durations
README.md

Integration

This repository contains Fuchsia's Global Integration manifest files.

Making changes

All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.

Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.

Obtaining the source

First install Jiri.

Next run:

$ jiri init
$ jiri import minimal https://fuchsia.googlesource.com/integration
$ jiri update

Third party

Third party projects should have their own subdirectory in ./third_party.