[roll] Roll fuchsia [starnix] Clean up UID/GID, secure-exec and capability calculations Correct the execve() credential transition and capability calculation flows to match Linux semantics, and refactor the underlying implementation to improve lock safety. Functional Changes (Bug Fixes): * Ambient Capabilities Leak (b/512385677): Previously, cap_ambient clearing was only gated on SUID/SGID file bits. We now correctly gate it on the euid/egid delta against the pre-exec real IDs, preventing privilege retention leaks across execve() (e.g., in hardened containers like systemd or Android zygote) while preserving them for self-owned SUID binaries. Refactoring & Simplification: * SUID/SGID and Capability Resolution: Moved these preparation steps from finish_exec() (late phase) to exec() (early phase), before the LSM hook (bprm_creds_for_exec) runs. This ensures LSM/SELinux sees the final prepared credentials, matching Linux. * Ptrace Serialization (TOCTOU Fix): Acquired the credentials write lock (creds_lock) early in exec() and held it through finish_exec() to serialize the transition against ptrace_attach (which now uses lock_creds()). This prevents tracers from attaching mid-exec. * Deadlock Prevention: Avoided holding the TaskState lock during LSM checks, preventing deadlocks when SELinux queries the ptracer. Redefined lock order to be creds_lock before TaskState. * Ambient Capabilities & FSUID: Centralized and cleaned up these resets in Credentials::exec() to match Linux's cap_bprm_creds_from_file(). * Documentation: Updated and reformatted all comments in exec() and Credentials::exec() to use consistent block comments with execve(2), credentials(7), and capabilities(7) man page quotes. Also added test cases in capabilities_test.cc to verify ambient capability clearing and SUID/SGID capability transitions during exec. Original-Original-Bug: 512385677 Original-Original-Bug: 503338788 Test: fx test fuchsia-pkg://fuchsia.com/sestarnix_userspace_tests#meta/inherit.cm Test: fx test starnix_syscalls_cpp_tests TAG=agy CONV=96a08da1-3582-4ae9-bf8e-e0e201b6c680 Original-Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1648979 Original-Original-Revision: 0e96b3c7f6cfa4a793fd5e329869fa0d18c8d0be GitOrigin-RevId: b818769ff7097eb398344d4fb90d69e0cde15b52 Change-Id: Ib714ea2f2ac326c95eb3d24db80d45d03fbe5233 Reviewed-on: https://fuchsia-review.googlesource.com/c/integration/+/1651753 Cr-Commit-Position: refs/heads/main@{#194629}
This repository contains Fuchsia's Global Integration manifest files.
All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.
Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.
First install Jiri.
Next run:
$ jiri init $ jiri import minimal https://fuchsia.googlesource.com/integration $ jiri update
Third party projects should have their own subdirectory in ./third_party.