Fixing Races For Good

Xiang Cai, Rucha Lale, Xincheng Zhang, Robert Johnson · 2015

We present a system for performing arbitrary sequences of filesystem operations and provably detecting any violation of serializable isolation semantics, i.e. any interleaving of attacker and defender actions is equivalent to a non-interleaved sequence of attacker and defender actions. Thus, our system provides a provably secure defense against all UNIX file-name race conditions, including the infamous access/open race. Our solution operates entirely in user-space and is portable to any POSIX.1-2008 system, making it usable today. Developers can adopt our solution selectively, using it for security-critical code and using the standard POSIX interface for non-security-critical parts of their programs. Furthermore, the proofs of correctness suggest several simple improvements to the POSIX standard.

Read the paper · More papers on PaperTik