[roll] Roll fuchsia [starnix] Clean up UID/GID, secure-exec and capability calculations

Correct the execve() credential transition and capability calculation
flows to match Linux semantics, and refactor the underlying
implementation to improve lock safety.

Functional Changes (Bug Fixes):
* Ambient Capabilities Leak (b/512385677): Previously, cap_ambient
  clearing was only gated on SUID/SGID file bits. We now correctly gate
  it on the euid/egid delta against the pre-exec real IDs, preventing
  privilege retention leaks across execve() (e.g., in hardened
  containers like systemd or Android zygote) while preserving them
  for self-owned SUID binaries.

Refactoring & Simplification:
* SUID/SGID and Capability Resolution: Moved these preparation steps
  from finish_exec() (late phase) to exec() (early phase), before the
  LSM hook (bprm_creds_for_exec) runs. This ensures LSM/SELinux sees
  the final prepared credentials, matching Linux.
* Ptrace Serialization (TOCTOU Fix): Acquired the credentials write
  lock (creds_lock) early in exec() and held it through finish_exec() to
  serialize the transition against ptrace_attach (which now uses
  lock_creds()). This prevents tracers from attaching mid-exec.
* Deadlock Prevention: Avoided holding the TaskState lock during LSM
  checks, preventing deadlocks when SELinux queries the ptracer.
  Redefined lock order to be creds_lock before TaskState.
* Ambient Capabilities & FSUID: Centralized and cleaned up these resets
  in Credentials::exec() to match Linux's cap_bprm_creds_from_file().
* Documentation: Updated and reformatted all comments in exec() and
  Credentials::exec() to use consistent block comments with execve(2),
  credentials(7), and capabilities(7) man page quotes.

Also added test cases in capabilities_test.cc to verify ambient
capability clearing and SUID/SGID capability transitions during exec.

Original-Original-Bug: 512385677
Original-Original-Bug: 503338788
Test: fx test fuchsia-pkg://fuchsia.com/sestarnix_userspace_tests#meta/inherit.cm
Test: fx test starnix_syscalls_cpp_tests
TAG=agy
CONV=96a08da1-3582-4ae9-bf8e-e0e201b6c680

Original-Original-Reviewed-on: https://fuchsia-review.googlesource.com/c/fuchsia/+/1648979
Original-Original-Revision: 0e96b3c7f6cfa4a793fd5e329869fa0d18c8d0be
GitOrigin-RevId: b818769ff7097eb398344d4fb90d69e0cde15b52
Change-Id: Ib714ea2f2ac326c95eb3d24db80d45d03fbe5233
Reviewed-on: https://fuchsia-review.googlesource.com/c/integration/+/1651753
Cr-Commit-Position: refs/heads/main@{#194629}
1 file changed
tree: 12254ffce4fd2210d0434d790b1259a0b3fea417
  1. ctf/
  2. git-hooks/
  3. infra/
  4. third_party/
  5. cobalt
  6. flower
  7. jiri.lock
  8. MILESTONE
  9. minimal
  10. prebuilts
  11. README.md
  12. stem
  13. test_durations
README.md

Integration

This repository contains Fuchsia's Global Integration manifest files.

Making changes

All changes should be made to the internal version of this repository. Our infrastructure automatically updates this version when the internal one changes.

Currently all changes must be made by a Google employee. Non-Google employees wishing to make a change can ask for assistance in one of the communication channels documented at get involved.

Obtaining the source

First install Jiri.

Next run:

$ jiri init
$ jiri import minimal https://fuchsia.googlesource.com/integration
$ jiri update

Third party

Third party projects should have their own subdirectory in ./third_party.