scothis/componentized-sockets

collection of utility components that remix wasi:sockets types and interfaces

★ 0Forks 0GitHub ↗Compare

README

Socket components

A collection of utility components that remix wasi:sockets types and interfaces.

Components

Access control for wasi:sockets is split between gates and latches. A gate wraps the sockets interfaces and consults a latch before each operation, a latch decides whether the operation may proceed. Latches are small and single purpose, combine them to build a policy. Tracing components log socket activity without changing it.

Gates

Put wasi:sockets behind a latch. Each operation is authorized before it reaches the underlying socket, denied operations fail, and denied inbound traffic is dropped before it reaches the guest.

Caution

Interfering with network sockets can have dramatic, unintended consequences. A denied operation surfaces to the guest as a network failure, and dropped inbound traffic looks like a peer that never answers, which can trigger retries, timeouts and fallbacks far from the operation that was denied. A policy that looks correct can still cut off traffic a component depends on, for example name lookups or return traffic. Install new latches, and new configurations of existing latches, cautiously and monitor the result: roll out with latch-dry-run, watch decisions with latch-trace, and review the denials the gate logs.

Latches

Decide which socket operations are allowed. A latch defers or denies, an operation proceeds unless a latch denies it.

Blanket restrictions

Deny a whole category of operations, without configuration.

Name lookups

Control which host names can be resolved, and tie connections to names that were resolved.

Network ranges

Restrict which remote addresses traffic can originate from or be sent to, by CIDR range and optionally port range, while allowing return traffic.

  • latch-cidr: restricts traffic originating in either direction
  • latch-cidr-bind: restricts which local addresses and ports sockets are bound to
  • latch-cidr-egress: restricts outbound traffic the guest originates
  • latch-cidr-ingress: restricts inbound traffic remote peers originate
  • latch-deny-private-networks-cidr-config: config for latch-cidr-egress denying outbound traffic to private, loopback, link local and other addresses that are not globally reachable, a baseline against server side request forgery that can be refined before use

Combining latches

Build a policy from several latches, apply a latch to only part of the traffic, for example to configure tcp and udp differently, or try a policy before enforcing it.

Fault injection

Deny operations on purpose, to prove a component is resilient to failures in a hostile environment.

  • latch-deny-random: randomly denies a configurable fraction of operations, reproducible with a seed

Tracing

Log wasi:sockets calls and latch decisions, for debugging or auditing, without affecting them.

Build

Prereqs:

  • a rust toolchain
  • cargo-binstall, optional, to download prebuilt tools instead of building them
make components

The cli tools the build uses, static-config, wasm-tools, wac and wkg, are pinned in tools/Cargo.toml and installed into target/tools as needed, or ahead of time with make tools. Dependabot bumps the pinned versions.

Community

Code of Conduct

The Componentized project follow the Contributor Covenant Code of Conduct. In short, be kind and treat others with respect.

Communication

General discussion and questions about the project can occur in the project's GitHub discussions.

Contributing

The Componentized project team welcomes contributions from the community. A contributor license agreement (CLA) is not required. You own full rights to your contribution and agree to license the work to the community under the Apache License v2.0, via a Developer Certificate of Origin (DCO). For more detailed information, refer to CONTRIBUTING.md.

Acknowledgements

This project was conceived in discussion between Mark Fisher and Scott Andrews.

License

Apache License v2.0: see LICENSE for details.

Contributors

scothis

Issues