Skip to content

Daemon binary anti-tamper beyond PR_SET_DUMPABLE #27

Description

@Brad-Edwards

Problem

Daemon self-protection is limited to `prctl(PR_SET_DUMPABLE, 0)` which blocks ptrace attachment. A sophisticated attacker can still:

  1. Kill and replace the daemon — no integrity check on the daemon binary itself
  2. Modify the daemon on disk — no signature verification at startup
  3. LD_PRELOAD the daemon — the daemon detects LD_PRELOAD on the game but not on itself
  4. Signal injection — only SIGINT/SIGTERM are handled; other signals could disrupt operation
  5. /proc/self/mem writes — PR_SET_DUMPABLE doesn't prevent all /proc/self/mem access paths

Proposal

Layered hardening (pick based on threat model):

  1. Self-hash at startup — HMAC-SHA256 of own .text segment, periodic re-check (reuse existing integrity.c infrastructure)
  2. LD_PRELOAD self-check — scan own /proc/self/environ at startup
  3. Signal hardening — block or handle additional signals (SIGUSR1/2, SIGPIPE, etc.)
  4. Namespace isolation — optionally run in a mount/PID namespace
  5. seccomp self-filter — restrict daemon's own syscall surface (ties into WP7, issue WP7: Seccomp game filter #13)

Acceptance

  • At minimum: daemon verifies its own .text integrity at startup
  • Daemon checks its own environment for LD_PRELOAD
  • Additional signal handlers installed

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions