Add option to hide application data in strace logs.

This is helpful in disabling printing sensitive application data when strace is
enabled.

PiperOrigin-RevId: 451946198
This commit is contained in:
Ayush Ranjan
2022-05-30 19:52:27 -07:00
committed by gVisor bot
parent 4fa85fb6f7
commit c7690e05c1
3 changed files with 18 additions and 8 deletions
+1 -1
View File
@@ -462,7 +462,7 @@ func sockOptVal(t *kernel.Task, level, optname uint64, optVal hostarch.Addr, opt
}
return fmt.Sprintf("%#x {value=%v}", optVal, v)
default:
return dump(t, optVal, uint(optLen), maximumBlobSize)
return dump(t, optVal, uint(optLen), maximumBlobSize, true /* content */)
}
}
+14 -7
View File
@@ -48,6 +48,10 @@ var LogMaximumSize uint = DefaultLogMaximumSize
// do anything useful with binary text dump of byte array arguments.
var EventMaximumSize uint
// LogAppDataAllowed is set to true when printing application data in strace
// logs is allowed.
var LogAppDataAllowed = true
// ItimerTypes are the possible itimer types.
var ItimerTypes = abi.ValueSet{
linux.ITIMER_REAL: "ITIMER_REAL",
@@ -108,7 +112,10 @@ func iovecs(t *kernel.Task, addr hostarch.Addr, iovcnt int, printContent bool, m
return fmt.Sprintf("%#x %s", addr, strings.Join(iovs, ", "))
}
func dump(t *kernel.Task, addr hostarch.Addr, size uint, maximumBlobSize uint) string {
func dump(t *kernel.Task, addr hostarch.Addr, size uint, maximumBlobSize uint, printContent bool) string {
if !printContent {
return fmt.Sprintf("{base=%#x, len=%d}", addr, size)
}
origSize := size
if size > maximumBlobSize {
size = maximumBlobSize
@@ -415,13 +422,13 @@ func (i *SyscallInfo) pre(t *kernel.Task, args arch.SyscallArguments, maximumBlo
case FD:
output = append(output, fd(t, args[arg].Int()))
case WriteBuffer:
output = append(output, dump(t, args[arg].Pointer(), args[arg+1].SizeT(), maximumBlobSize))
output = append(output, dump(t, args[arg].Pointer(), args[arg+1].SizeT(), maximumBlobSize, LogAppDataAllowed /* content */))
case WriteIOVec:
output = append(output, iovecs(t, args[arg].Pointer(), int(args[arg+1].Int()), true /* content */, uint64(maximumBlobSize)))
output = append(output, iovecs(t, args[arg].Pointer(), int(args[arg+1].Int()), LogAppDataAllowed /* content */, uint64(maximumBlobSize)))
case IOVec:
output = append(output, iovecs(t, args[arg].Pointer(), int(args[arg+1].Int()), false /* content */, uint64(maximumBlobSize)))
case SendMsgHdr:
output = append(output, msghdr(t, args[arg].Pointer(), true /* content */, uint64(maximumBlobSize)))
output = append(output, msghdr(t, args[arg].Pointer(), LogAppDataAllowed /* content */, uint64(maximumBlobSize)))
case RecvMsgHdr:
output = append(output, msghdr(t, args[arg].Pointer(), false /* content */, uint64(maximumBlobSize)))
case Path:
@@ -520,20 +527,20 @@ func (i *SyscallInfo) post(t *kernel.Task, args arch.SyscallArguments, rval uint
}
switch i.format[arg] {
case ReadBuffer:
output[arg] = dump(t, args[arg].Pointer(), uint(rval), maximumBlobSize)
output[arg] = dump(t, args[arg].Pointer(), uint(rval), maximumBlobSize, LogAppDataAllowed /* content */)
case ReadIOVec:
printLength := uint64(rval)
if printLength > uint64(maximumBlobSize) {
printLength = uint64(maximumBlobSize)
}
output[arg] = iovecs(t, args[arg].Pointer(), int(args[arg+1].Int()), true /* content */, printLength)
output[arg] = iovecs(t, args[arg].Pointer(), int(args[arg+1].Int()), LogAppDataAllowed /* content */, printLength)
case WriteIOVec, IOVec, WriteBuffer:
// We already have a big blast from write.
output[arg] = "..."
case SendMsgHdr:
output[arg] = msghdr(t, args[arg].Pointer(), false /* content */, uint64(maximumBlobSize))
case RecvMsgHdr:
output[arg] = msghdr(t, args[arg].Pointer(), true /* content */, uint64(maximumBlobSize))
output[arg] = msghdr(t, args[arg].Pointer(), LogAppDataAllowed /* content */, uint64(maximumBlobSize))
case PostPath:
output[arg] = path(t, args[arg].Pointer())
case PipeFDs:
+3
View File
@@ -29,6 +29,9 @@ func enableStrace(conf *config.Config) error {
return nil
}
// For now runsc always allows logging application buffers in strace logs.
strace.LogAppDataAllowed = true
max := conf.StraceLogSize
if max == 0 {
max = 1024