Problem
Daemon self-protection is limited to `prctl(PR_SET_DUMPABLE, 0)` which blocks ptrace attachment. A sophisticated attacker can still:
Kill and replace the daemon — no integrity check on the daemon binary itself
Modify the daemon on disk — no signature verification at startup
LD_PRELOAD the daemon — the daemon detects LD_PRELOAD on the game but not on itself
Signal injection — only SIGINT/SIGTERM are handled; other signals could disrupt operation
/proc/self/mem writes — PR_SET_DUMPABLE doesn't prevent all /proc/self/mem access paths
Proposal
Layered hardening (pick based on threat model):
Self-hash at startup — HMAC-SHA256 of own .text segment, periodic re-check (reuse existing integrity.c infrastructure)
LD_PRELOAD self-check — scan own /proc/self/environ at startup
Signal hardening — block or handle additional signals (SIGUSR1/2, SIGPIPE, etc.)
Namespace isolation — optionally run in a mount/PID namespace
seccomp self-filter — restrict daemon's own syscall surface (ties into WP7, issue WP7: Seccomp game filter #13 )
Acceptance
At minimum: daemon verifies its own .text integrity at startup
Daemon checks its own environment for LD_PRELOAD
Additional signal handlers installed
Problem
Daemon self-protection is limited to `prctl(PR_SET_DUMPABLE, 0)` which blocks ptrace attachment. A sophisticated attacker can still:
Proposal
Layered hardening (pick based on threat model):
Acceptance