[roll] Roll fuchsia [starnix] Reland: Add ptrace access checks to /proc/<pid> This is a reland of CL Id186b7764bd92398420c3b80c1808e563981c882 with: 1. the SimpleFileNode API changes broken out into a prefactor CL. 2. "stat" checks are broken out to a follow-up CL. Nodes in /proc/pid that expose sensitive information about a task ("auxv", "environ", "maps", "smaps", "fd" and its contents) require a ptrace "read" access check to open(). The /proc/pid/mem node, which provides greater access to a task's address-space, requires a ptrace "attach" check to open(). Finally, the /proc/pid/stat file require a ptrace "read" check on open(), which determines the information that is exposed, rather than gating access. This check is made with the no-audit flag, to prevent the LSM (e.g. SELinux) from audit-logging denials. Original-Bug: 467438310, 438161520, 475912243 Test: starnix_gvisor_proc_test and procfs_test Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1486197 Original-Revision: 5f5f229d6900cf28e45a2bede1f2864df415bf91 GitOrigin-RevId: 72df2ba0d4fc3cf50f50bd7300ddbf24fd1ef85f Change-Id: Ib460e0dedb6928c1dc4e4f4a2f57b7a51b812bf3
This repository contains Fuchsia's Global Integration manifest files.
All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.
Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.
First install Jiri.
Next run:
$ jiri init $ jiri import minimal https://fuchsia.googlesource.com/integration $ jiri update
Third party projects should have their own subdirectory in ./third_party.