Skip to content

Bind Smart Policy entries to process instances to prevent PID reuse #156

Description

@coderabbitai

Summary

Bind Smart Policy authorization to a process instance instead of only a PID.

Rationale

SmartPolicyInterface::request_process_access checks that /proc/<pid> exists and then inserts a PID-only entry into the eBPF policy maps. The process can exit between the existence check and the insertion. If the PID is later reused, a stale policy entry can affect the new process.

Affected areas

  • crates/cardwire-daemon/src/interface/smart.rs
  • Smart Policy eBPF maps and their kernel enforcement logic

Required changes

  • Capture a kernel-verifiable process-instance identity when a Smart Policy entry is created. A process start-time identity is one possible mechanism.
  • Store this identity with the Smart Policy map entry.
  • Validate the stored identity against the current process identity during kernel enforcement.
  • Ignore or remove policy entries that do not match the current process instance.
  • Preserve the intended behavior for Allow_dGPU, Force_dGPU, and GPU-specific policies.

Acceptance criteria

  • A policy created for a process does not apply to a different process that later reuses the same PID.
  • Kernel enforcement verifies process-instance identity before it applies a Smart Policy entry.
  • The implementation includes tests or another documented validation method for PID reuse or stale-entry handling.

Backlinks

Requested by: @luytan

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

  • Status
    Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions