Files
Jim Meyer 62df64625b fix(identity): assess leaf and ancestor executable identities (#3633)
* fix(security): pin supplied executable identity chains

Signed-off-by: Jim Meyer <jimeyer@nvidia.com>

* docs(security): document executable identity chain pinning

Signed-off-by: Jim Meyer <jimeyer@nvidia.com>

* fix(binary-identity): compile Linux ancestry hashing

Signed-off-by: Jim Meyer <jimeyer@nvidia.com>

* test(binary-identity): avoid cross-label ancestry fixture

Signed-off-by: Jim Meyer <jimeyer@nvidia.com>

* test(e2e): choose distinct denied TCP port

Fix flaky test due to sequential port assignment on MacOS

Signed-off-by: Jim Meyer <jimeyer@nvidia.com>

* fix(identity): bound executable evidence cache

Reject identity chains atomically when the supervisor cache reaches its hard limit, and preserve existing pins without eviction. Classify malformed or conflicting evidence separately from policy denials at the staged TCP boundary.

Signed-off-by: Jim Meyer <jimeyer@nvidia.com>

---------

Signed-off-by: Jim Meyer <jimeyer@nvidia.com>
2026-09-23 21:07:24 +00:00

1.1 KiB

Binary identity

openshell-binary-identity provides shared executable-identity resolution for RFC 0012 isolation backends. Runtime-specific observers remain in their backend: Docker obtains an authoritative thread ID from seccomp notification, while the co-located Linux path maps an accepted socket to its owning processes.

Given an authoritative Linux PID and an optional trusted process-tree root, the crate opens the leaf and bounded ancestor /proc/<pid>/exe objects, hashes those already-open live objects, and returns path-and-digest evidence for the whole executable chain. It also collects diagnostic command-line paths, which never authorize network access. Resolution fails without returning a partial identity if any executable cannot be opened, hashed, or validated after hashing. The caller receives ResolveError and denies the associated connection.

The crate does not intercept connections, authenticate remote observers, or evaluate policy. The isolation backend remains responsible for binding the resolved identity to the active boundary and exact accepted connection before constructing PendingTcpOpen.