2017-08-03 09:29:32 +08:00
Why an applet can't be NOFORK or NOEXEC?
Why can't be NOFORK:
interactive: may wait for user input, ^C has to work
2017-08-04 22:01:39 +08:00
spawner: "tool PROG ARGS" which changes program state and execs - must fork
2017-08-03 09:29:32 +08:00
changes state: e.g. environment, signal handlers
2017-08-04 20:28:16 +08:00
alloc+xfunc: xmalloc, then xfunc - leaks memory if xfunc dies
open+xfunc: opens fd, then calls xfunc - fd is leaked if xfunc dies
2017-08-04 22:01:39 +08:00
leaks: does not free allocated memory or opened fds
2017-08-04 01:00:01 +08:00
runner: sometimes may run for long(ish) time, and/or works with network:
2017-08-03 09:29:32 +08:00
^C has to work (cat BIGFILE, chmod -R, ftpget, nc)
2017-08-04 22:01:39 +08:00
"runners" can become eligible after shell is taught ^C to interrupt NOFORKs,
2017-08-04 23:36:16 +08:00
need to be inspected that they do not fall into alloc+xfunc, open+xfunc,
leak categories.
2017-08-03 09:29:32 +08:00
Why can't be NOEXEC:
suid: runs under different uid - must fork+exec
Why shouldn't be NOFORK/NOEXEC:
2017-08-04 22:01:39 +08:00
rare: not started often enough to bother optimizing (example: poweroff)
daemon: runs indefinitely; these are also always fit "rare" category
2017-08-05 01:55:01 +08:00
longterm: often runs for a long time (many seconds), execing makes
2017-08-04 01:00:01 +08:00
memory footprint smaller
2017-08-04 22:01:39 +08:00
complex: no immediately obvious reason why NOFORK wouldn't work,
2017-08-04 23:36:16 +08:00
but does some non-obvoius operations (example: fuser, lsof, losetup);
detailed audit often turns out that it's a leaker
Interesting example of "interactive" applet which is nevertheless can be
(and is) NOEXEC is "rm". Yes, "rm -i" is interactive - but it's not that typical
for users to keep it waiting for many minutes, whereas running "rm" in shell
is very typical, and speeding up this common use via NOEXEC is useful.
IOW: rm is "interactive", but not "longterm".
2017-08-03 09:29:32 +08:00
[ - NOFORK
[[ - NOFORK
acpid - daemon
add-shell
addgroup
adduser
adjtimex
ar - runner
arch - NOFORK
2017-08-04 23:36:16 +08:00
arp - complex, rare
2017-08-03 09:29:32 +08:00
arping - runner
2017-08-04 23:36:16 +08:00
ash - interactive, longterm
2017-08-04 01:00:01 +08:00
awk - noexec. runner
2017-08-03 09:29:32 +08:00
base64 - runner
basename - NOFORK
beep
blkdiscard
blkid
2017-08-05 07:29:12 +08:00
blockdev - noexec. leaks fd
2017-08-03 09:29:32 +08:00
bootchartd - daemon
brctl
bunzip2 - runner
busybox
bzcat - runner
bzip2 - runner
2017-08-04 01:00:01 +08:00
cal - runner: cal -n9999
2017-08-03 09:29:32 +08:00
cat - runner
2017-08-04 23:36:16 +08:00
chat - needs ^C to work
2017-08-06 02:38:04 +08:00
chattr - noexec. runner
2017-08-04 01:00:01 +08:00
chgrp - noexec. runner
chmod - noexec. runner
chown - noexec. runner
2017-08-03 09:29:32 +08:00
chpasswd - runner (list of "user:password"s from stdin)
2017-08-05 01:55:01 +08:00
chpst - noexec. spawner
chroot - noexec. spawner
chrt - noexec. spawner
2017-08-05 08:02:31 +08:00
chvt - noexec. leaks: get_console_fd_or_die() may open a new fd, or return one of stdio fds
2017-08-04 01:00:01 +08:00
cksum - noexec. runner
2017-08-03 09:29:32 +08:00
clear - NOFORK
cmp - runner
comm - runner
2017-08-04 23:59:46 +08:00
conspy - interactive, longterm
2017-08-04 01:00:01 +08:00
cp - noexec. runner
2017-08-03 09:29:32 +08:00
cpio - runner
crond - daemon
2017-08-06 23:14:09 +08:00
crontab - longterm (runs $EDITOR), leaks: open+xasprintf
2017-08-05 08:08:23 +08:00
cryptpw - noexec. changes state: with --password-fd=N, moves N to stdin
2017-08-05 01:55:01 +08:00
cttyhack - noexec. spawner
2017-08-04 01:00:01 +08:00
cut - noexec. runner
date - noexec. nofork candidate(needs to stop messing up env, free xasprintf result, not use xfuncs after xasprintf)
2017-08-03 09:29:32 +08:00
dc - runner (eats stdin if no params)
2017-08-04 01:00:01 +08:00
dd - noexec. runner
2017-08-05 08:02:31 +08:00
deallocvt - noexec. leaks: get_console_fd_or_die() may open a new fd, or return one of stdio fds
2017-08-03 09:29:32 +08:00
delgroup
deluser
2017-08-04 23:36:16 +08:00
depmod - complex, rare
2017-08-04 01:00:01 +08:00
devmem - runner, complex (access to device memory may hang)
2017-08-04 23:59:46 +08:00
df - leaks: nested allocs
2017-08-03 09:29:32 +08:00
dhcprelay - daemon
diff - runner
dirname - NOFORK
2017-08-04 01:00:01 +08:00
dmesg - runner
2017-08-03 09:29:32 +08:00
dnsd - daemon
2017-08-04 23:36:16 +08:00
dnsdomainname - needs ^C (may talk to DNS servers, which may be down)
2017-08-04 01:00:01 +08:00
dos2unix - noexec. runner
2017-08-03 09:29:32 +08:00
dpkg - runner
2017-08-04 01:00:01 +08:00
du - runner
2017-08-05 08:02:31 +08:00
dumpkmap - noexec. leaks: get_console_fd_or_die() may open a new fd, or return one of stdio fds
2017-08-05 01:16:01 +08:00
dumpleases - leaks: open+xread
2017-08-03 09:29:32 +08:00
echo - NOFORK
2017-08-04 23:36:16 +08:00
ed - interactive, longterm
egrep - longterm runner ("CMD | egrep ..." may run indefinitely, better to exec to conserve memory)
eject - leaks: open+ioctl_or_perror_and_die, changes state (moves fds)
2017-08-04 23:59:46 +08:00
env - noexec. spawner, changes state (env)
2017-08-05 01:55:01 +08:00
envdir - noexec. spawner
envuidgid - noexec. spawner
2017-08-03 09:29:32 +08:00
expand - runner
2017-08-04 23:59:46 +08:00
expr - leaks: nested allocs
2017-08-03 09:29:32 +08:00
factor - runner (eats stdin if no params)
fakeidentd - daemon
false - NOFORK
2017-08-04 23:59:46 +08:00
fatattr - leaks: open+xioctl, complex
2017-08-04 23:36:16 +08:00
fbset - leaks: open+xfunc, complex, rare
fbsplash - runner, longterm
fdflush - leaks: open+ioctl_or_perror_and_die, needs ^C (floppy may be unresponsive), rare
fdformat - needs ^C (floppy may be unresponsive), longterm, rare
fdisk - interactive, longterm
2017-08-05 08:02:31 +08:00
fgconsole - noexec. leaks: get_console_fd_or_die() may open a new fd, or return one of stdio fds
2017-08-04 23:36:16 +08:00
fgrep - longterm runner ("CMD | fgrep ..." may run indefinitely, better to exec to conserve memory)
2017-08-04 01:00:01 +08:00
find - noexec. runner
2017-08-03 09:29:32 +08:00
findfs - suid
flash_eraseall
flash_lock
flash_unlock
flashcp
2017-08-05 01:55:01 +08:00
flock - spawner, changes state (file locks), let's play safe and not be noexec
2017-08-04 01:00:01 +08:00
fold - noexec. runner
free - nofork candidate(struct globals, needs to close /proc/meminfo fd)
2017-08-04 23:36:16 +08:00
freeramdisk - leaks: open+ioctl_or_perror_and_die
fsck - interactive, longterm
2017-08-05 01:16:01 +08:00
fsck.minix - needs ^C
2017-08-05 07:29:12 +08:00
fsfreeze - noexec. leaks: open+xioctl
fstrim - noexec. leaks: open+xioctl, find_block_device -> readdir+xstrdup
2017-08-03 09:29:32 +08:00
fsync - NOFORK
ftpd - daemon
ftpget - runner
ftpput - runner
fuser - complex
2017-08-04 23:59:46 +08:00
getopt - noexec. leaks: many allocs
2017-08-04 23:36:16 +08:00
getty - interactive, longterm
grep - longterm runner ("CMD | grep ..." may run indefinitely, better to exec to conserve memory)
2017-08-03 09:29:32 +08:00
groups - noexec
gunzip - runner
gzip - runner
halt - rare
2017-08-04 01:00:01 +08:00
hd - noexec. runner
2017-08-03 09:29:32 +08:00
hdparm - complex, rare
2017-08-04 01:00:01 +08:00
head - noexec. runner
hexdump - noexec. runner
2017-08-03 09:29:32 +08:00
hostid - NOFORK
2017-08-05 00:36:55 +08:00
hostname - needs ^C (may talk to DNS servers, which may be down)
2017-08-03 09:29:32 +08:00
httpd - daemon
2017-08-04 23:36:16 +08:00
hush - interactive, longterm
2017-08-04 23:59:46 +08:00
hwclock - talks to hardware (xioctl(RTC_RD_TIME)) - needs ^C
2017-08-03 09:29:32 +08:00
i2cdetect
i2cdump
i2cget
i2cset
id - noexec
2017-08-05 01:16:01 +08:00
ifconfig - leaks: xsocket+ioctl_or_perror_and_die
ifenslave - leaks: xsocket+bb_perror_msg_and_die
2017-08-03 09:29:32 +08:00
ifplugd - daemon
inetd - daemon
init - daemon
inotifyd - daemon
2017-08-04 08:56:39 +08:00
insmod - noexec
2017-08-03 09:29:32 +08:00
install - runner
2017-08-05 01:55:01 +08:00
ionice - noexec. spawner
2017-08-03 09:29:32 +08:00
iostat - runner
2017-08-04 01:30:21 +08:00
ip - noexec candidate
ipaddr - noexec candidate
ipcalc - noexec candidate
ipcrm - noexec candidate
ipcs - noexec candidate
iplink - noexec candidate
ipneigh - noexec candidate
iproute - noexec candidate
iprule - noexec candidate
iptunnel - noexec candidate
2017-08-06 18:28:00 +08:00
kbd_mode - noexec. leaks: xopen_nonblocking+xioctl
2017-08-04 01:00:01 +08:00
kill - NOFORK
killall - NOFORK
killall5 - NOFORK
2017-08-03 09:29:32 +08:00
klogd - daemon
2017-08-04 01:00:01 +08:00
last - runner (I've got 1300 lines of output when tried it)
2017-08-04 23:36:16 +08:00
less - interactive, longterm
2017-08-03 09:29:32 +08:00
link - NOFORK
2017-08-05 01:55:01 +08:00
linux32 - noexec. spawner
linux64 - noexec. spawner
2017-08-03 09:29:32 +08:00
linuxrc - daemon
ln - noexec
2017-08-05 01:16:01 +08:00
loadfont - leaks: config_open+bb_error_msg_and_die("map format")
2017-08-05 08:02:31 +08:00
loadkmap - noexec. leaks: get_console_fd_or_die() may open a new fd, or return one of stdio fds
2017-08-03 09:29:32 +08:00
logger - runner
2017-08-04 23:36:16 +08:00
login - suid, interactive, longterm
2017-08-03 09:29:32 +08:00
logname - NOFORK
losetup - complex
lpd - daemon
lpq - runner
lpr - runner
2017-08-04 01:00:01 +08:00
ls - noexec. runner
2017-08-06 02:38:04 +08:00
lsattr - noexec. runner
2017-08-04 08:56:39 +08:00
lsmod - noexec
2017-08-03 09:29:32 +08:00
lsof - complex
2017-08-06 05:28:19 +08:00
lspci - noexec. too rare to bother for nofork
lsscsi - noexec. too rare to bother for nofork
lsusb - noexec. too rare to bother for nofork
2017-08-03 09:29:32 +08:00
lzcat - runner
lzma - runner
lzop - runner
lzopcat - runner
makedevs
makemime - runner
2017-08-04 23:36:16 +08:00
man - spawner, interactive, longterm
2017-08-04 01:00:01 +08:00
md5sum - noexec. runner
2017-08-03 09:29:32 +08:00
mdev - daemon
2017-08-05 01:16:01 +08:00
mesg - NOFORK
2017-08-04 23:36:16 +08:00
microcom - interactive, longterm
2017-08-03 09:29:32 +08:00
mkdir - NOFORK
2017-08-05 00:36:55 +08:00
mkdosfs - needs ^C
mke2fs - needs ^C
2017-08-03 09:29:32 +08:00
mkfifo - noexec
2017-08-05 00:36:55 +08:00
mkfs.ext2 - needs ^C
mkfs.minix - needs ^C
mkfs.vfat - needs ^C
2017-08-03 09:29:32 +08:00
mknod - noexec
2017-08-05 08:08:23 +08:00
mkpasswd - noexec. changes state: with --password-fd=N, moves N to stdin
2017-08-05 00:36:55 +08:00
mkswap - needs ^C
2017-08-04 23:39:05 +08:00
mktemp - noexec. leaks: xstrdup+concat_path_file
2017-08-04 08:56:39 +08:00
modinfo - noexec
modprobe - noexec
2017-08-04 23:36:16 +08:00
more - interactive, longterm
2017-08-03 09:29:32 +08:00
mount - suid
2017-08-05 07:29:12 +08:00
mountpoint - noexec. leaks: option -n "print dev name": find_block_device -> readdir+xstrdup
2017-08-06 20:15:24 +08:00
mpstat - longterm: "mpstat 1" runs indefinitely
2017-08-05 00:36:55 +08:00
mt - rare
2017-08-05 01:16:01 +08:00
mv - noexec candidate, runner
2017-08-06 20:15:24 +08:00
nameif - noexec. openlog(), leaks: config_open2+ioctl_or_perror_and_die
2017-08-03 09:29:32 +08:00
nbd-client
nc - runner
2017-08-04 01:00:01 +08:00
netstat - runner with -c
2017-08-05 02:07:19 +08:00
nice - noexec. spawner
2017-08-03 09:29:32 +08:00
nl - runner
2017-08-05 00:36:55 +08:00
nmeter - longterm
2017-08-05 01:55:01 +08:00
nohup - noexec. spawner
2017-08-03 09:29:32 +08:00
nproc - NOFORK
ntpd - daemon
od - runner
2017-08-05 01:55:01 +08:00
openvt - longterm: spawns a child and waits for it
2017-08-05 07:46:39 +08:00
partprobe - noexec. leaks: open+ioctl_or_perror_and_die(BLKRRPART)
2017-08-03 09:29:32 +08:00
passwd - suid
2017-08-04 01:00:01 +08:00
paste - noexec. runner
2017-08-05 00:36:55 +08:00
patch - needs ^C
2017-08-04 01:00:01 +08:00
pgrep - nofork candidate(xregcomp, procps_scan - are they ok?)
pidof - nofork candidate(uses find_pid_by_name, is that ok?)
2017-08-03 09:29:32 +08:00
ping - suid, runner
ping6 - suid, runner
2017-08-05 01:16:01 +08:00
pipe_progress - longterm
2017-08-05 07:51:12 +08:00
pivot_root - NOFORK
2017-08-04 01:00:01 +08:00
pkill - nofork candidate(xregcomp, procps_scan - are they ok?)
2017-08-05 00:36:55 +08:00
pmap - noexec candidate, leaks: open+xstrdup
2017-08-03 09:29:32 +08:00
popmaildir - runner
poweroff - rare
2017-08-04 01:00:01 +08:00
powertop - interactive, longterm
2017-08-03 09:29:32 +08:00
printenv - NOFORK
printf - NOFORK
2017-08-06 04:25:00 +08:00
ps - looks for AT_CLKTCK elf aux vector, therefore can't be noexec
2017-08-04 01:30:21 +08:00
pscan - longterm
2017-08-06 04:25:00 +08:00
pstree - noexec
2017-08-03 09:29:32 +08:00
pwd - NOFORK
2017-08-04 01:00:01 +08:00
pwdx - NOFORK
2017-08-03 09:29:32 +08:00
raidautorun
2017-08-05 00:36:55 +08:00
rdate - needs ^C (may talk to DNS servers, which may be down)
rdev - leaks: find_block_device -> readdir+xstrdup
2017-08-04 01:00:01 +08:00
readlink - NOFORK
2017-08-03 09:29:32 +08:00
readprofile
2017-08-04 01:00:01 +08:00
realpath - NOFORK
2017-08-03 09:29:32 +08:00
reboot - rare
reformime - runner
remove-shell
2017-08-04 01:00:01 +08:00
renice - nofork candidate(uses getpwnam, is that ok?)
2017-08-05 02:07:19 +08:00
reset - noexec. spawner (execs "stty")
2017-08-04 01:00:01 +08:00
resize - noexec. changes state (signal handlers)
2017-08-03 09:29:32 +08:00
rev - runner
2017-08-04 01:00:01 +08:00
rm - noexec. rm -i interactive
2017-08-03 09:29:32 +08:00
rmdir - NOFORK
2017-08-04 08:56:39 +08:00
rmmod - noexec
2017-08-05 00:36:55 +08:00
route - needs ^C (may talk to DNS servers, which may be down)
2017-08-03 09:29:32 +08:00
rpm - runner
rpm2cpio - runner
2017-08-05 00:36:55 +08:00
rtcwake - longterm: puts system to sleep, optimizing this for speed is pointless
2017-08-03 09:29:32 +08:00
run-parts
2017-08-04 23:59:46 +08:00
runlevel - noexec. can be nofork if "endutxent()" is called unconditionally, but too rare to bother?
2017-08-03 09:29:32 +08:00
runsv - daemon
runsvdir - daemon
rx - runner
script
scriptreplay
sed - runner
sendmail - runner
2017-08-04 01:00:01 +08:00
seq - noexec. runner
2017-08-05 01:55:01 +08:00
setarch - noexec. spawner
2017-08-03 09:29:32 +08:00
setconsole
setfont
setkeycodes
setlogcons
2017-08-05 01:55:01 +08:00
setpriv - spawner, changes state, let's play safe and not be noexec
2017-08-03 09:29:32 +08:00
setserial
2017-08-06 23:14:09 +08:00
setsid - spawner, uses fork_or_rexec() [not audited to work in noexec], let's play safe and not be noexec
2017-08-05 01:55:01 +08:00
setuidgid - noexec. spawner
2017-08-04 01:00:01 +08:00
sha1sum - noexec. runner
sha256sum - noexec. runner
sha3sum - noexec. runner
sha512sum - noexec. runner
2017-08-04 23:36:16 +08:00
showkey - interactive, longterm
2017-08-03 09:29:32 +08:00
shred - runner
2017-08-04 01:00:01 +08:00
shuf - noexec. runner
2017-08-06 23:14:09 +08:00
slattach - longterm (may sleep forever), uses bb_common_bufsiz1
2017-08-05 00:36:55 +08:00
sleep - runner, longterm
2017-08-03 09:29:32 +08:00
smemcap - runner
2017-08-05 01:55:01 +08:00
softlimit - noexec. spawner
2017-08-04 01:00:01 +08:00
sort - noexec. runner
2017-08-03 09:29:32 +08:00
split - runner
2017-08-05 00:36:55 +08:00
ssl_client - longterm
2017-08-03 09:29:32 +08:00
start-stop-daemon
2017-08-04 01:00:01 +08:00
stat - nofork candidate(needs fewer allocs)
2017-08-03 09:29:32 +08:00
strings - runner
2017-08-05 02:07:19 +08:00
stty - noexec. nofork candidate: has no allocs or opens except xmove_fd(xopen("-F DEVICE"),STDIN). tcsetattr(STDIN) is not a problem: it would work the same across processes sharing this fd
2017-08-03 09:29:32 +08:00
su - suid, spawner
2017-08-05 01:55:01 +08:00
sulogin - noexec. spawner
2017-08-03 09:29:32 +08:00
sum - runner
2017-08-05 07:42:08 +08:00
sv - noexec. needs ^C (uses usleep(420000))
svc - noexec. needs ^C (uses usleep(420000))
2017-08-03 09:29:32 +08:00
svlogd - daemon
swapoff - rare
swapon - rare
2017-08-05 01:55:01 +08:00
switch_root - spawner, rare, changes state (oh yes), execing may be important to free binary's inode
2017-08-03 09:29:32 +08:00
sync - NOFORK
2017-08-06 00:23:10 +08:00
sysctl - noexec. leaks: xstrdup+xmalloc_read
2017-08-03 09:29:32 +08:00
syslogd - daemon
2017-08-04 01:00:01 +08:00
tac - noexec. runner
2017-08-03 09:29:32 +08:00
tail - runner
tar - runner
2017-08-05 01:55:01 +08:00
taskset - noexec. spawner
2017-08-03 09:29:32 +08:00
tcpsvd - daemon
tee - runner
2017-08-04 23:36:16 +08:00
telnet - interactive, longterm
2017-08-03 09:29:32 +08:00
telnetd - daemon
test - NOFORK
tftp - runner
tftpd - daemon
2017-08-05 01:55:01 +08:00
time - spawner, longterm, changes state (signals)
timeout - spawner, longterm, changes state (signals)
2017-08-04 01:00:01 +08:00
top - interactive, longterm
2017-08-03 09:29:32 +08:00
touch - NOFORK
tr - runner
traceroute - suid, runner
traceroute6 - suid, runner
true - NOFORK
truncate - NOFORK
tty - NOFORK
2017-08-04 01:00:01 +08:00
ttysize - NOFORK
2017-08-06 18:28:00 +08:00
tunctl - noexec
2017-08-06 02:38:04 +08:00
tune2fs - noexec. leaks: open+xfunc
2017-08-03 09:29:32 +08:00
ubiattach
ubidetach
ubimkvol
ubirename
ubirmvol
ubirsvol
ubiupdatevol
udhcpc - daemon
udhcpd - daemon
udpsvd - daemon
uevent - daemon
2017-08-06 05:21:02 +08:00
umount - noexec. leaks: nested xmalloc
2017-08-03 09:29:32 +08:00
uname - NOFORK
uncompress - runner
unexpand - runner
uniq - runner
2017-08-04 01:00:01 +08:00
unix2dos - noexec. runner
2017-08-03 09:29:32 +08:00
unlink - NOFORK
unlzma - runner
unlzop - runner
unxz - runner
unzip - runner
2017-08-04 01:00:01 +08:00
uptime - nofork candidate(is getutxent ok?)
users - nofork candidate(is getutxent ok?)
2017-08-03 09:29:32 +08:00
usleep - NOFORK
uudecode - runner
uuencode - runner
2017-08-04 23:36:16 +08:00
vconfig - leaks: xsocket+ioctl_or_perror_and_die
vi - interactive, longterm
2017-08-03 09:29:32 +08:00
vlock - suid
volname - runner
2017-08-05 01:16:01 +08:00
w - nofork candidate(is getutxent ok?)
2017-08-03 09:29:32 +08:00
wall - suid
2017-08-04 23:59:46 +08:00
watch - longterm
2017-08-03 09:29:32 +08:00
watchdog - daemon
wc - runner
2017-08-04 23:59:46 +08:00
wget - longterm
2017-08-03 09:29:32 +08:00
which - NOFORK
2017-08-05 01:16:01 +08:00
who - nofork candidate(is getutxent ok?)
2017-08-03 09:29:32 +08:00
whoami - NOFORK
2017-08-05 01:16:01 +08:00
whois - needs ^C
2017-08-04 01:00:01 +08:00
xargs - noexec. spawner
xxd - noexec. runner
2017-08-03 09:29:32 +08:00
xz - runner
xzcat - runner
2017-08-04 01:00:01 +08:00
yes - noexec. runner
2017-08-03 09:29:32 +08:00
zcat - runner
zcip - daemon