Skip to content

Record in F-09 that izbad.sock is Medium-only by construction and proven unreachable from a Low-IL VMM (#248), and guard it #281

Description

@Lupus

What

Update the F-09 register entry (izbad control socket, <data>/daemon/izbad.sock) to record as measured fact, not assumption, that the control socket keeps the implicit Medium integrity label — it is not among VmSpec::confined_write_surfaces, so it never receives the inheritable Low label — and therefore, per spike #248's result (AF_UNIX connect() requires write access), a Low-IL process such as the confined VMM cannot connect to it at all. Cite the spike doc and the build tested.

Why

F-09's Windows residual currently says only that izba does not harden the control socket and that it inherits the %LOCALAPPDATA% DACL. That is true but incomplete: the spike turned the label/connect relationship into a proven barrier, and the control socket happens to sit on the right side of it. The CLI and the desktop app run as the user at Medium, so they are unaffected; the VMM at Low is structurally excluded from the control plane. This is the one place where the #248 result strengthens the register, and it should be written down so a future change (e.g. adding the daemon dir to the labelled surfaces "for convenience") is recognised as removing a proven barrier.

In Scope

  • F-09 entry: add the proven Medium-only status of izbad.sock, the mechanism (not a confined write surface → no Low label → Low-IL connect() denied), and the citation.
  • A guard test or doc-comment on confined_write_surfaces stating that the daemon dir must never be included, so the barrier is not lost silently.

Out of Scope

  • Any change to what the control socket enforces (peer auth on Windows stays F-09's open residual for Medium peers).
  • Any change to the label scheme.

Acceptance Criteria

  • F-09's Windows residual paragraph states that izbad.sock is Medium-labelled by construction and that a Low-IL peer's connect() is denied, citing docs/spikes/0001-windows-afunix-connect-write-access.md and build 26100.4349.
  • A unit test asserts confined_write_surfaces() never yields the daemon dir (or a path under it), with a comment naming this finding as the reason.
  • Threat-model row B2 (control socket) references the updated entry.

INVEST Notes

Independent — depends only on merged code and PR #277's spike doc.
Negotiable — test vs doc-comment guard is open; the register text is fixed in substance.
Valuable — converts an assumption into recorded evidence and protects it with a guard.
Estimable — one paragraph, one small test.
Small — effort XS.
Testable — the guard test is the check.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    effort:XSTrivial: config tweak, one-liner, or doc editpriority:P3Low: nice-to-have; easily deferred without consequencetype:securityVulnerability, auth gap, data-exposure risk, or compliance hardening

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions