Florian Obser: slaacd(8)   BSDCan 2018 @BsdcanOrg
Florian Obser: slaacd(8)   BSDCan 2018  @BsdcanOrg
Uploaded August 2018 | Updated September 2026, 44 minutes ago
For IPv6 stateless address auto configuration the KAME IPv6 stack, shared by all the BSDs, parses router advertisement messages in the kernel. These messages are fairly complicated, with optional parts and varying lengths. Parsing them is dangerously close to string handling in the kernel. If a mistake is made only a few mitigations stand in the way of a full-system compromise.

Moving this functionality to user land with much more powerful mitigations is prudent.

We present slaacd, the stateless address auto configuration daemon. It was written from scratch following the well established pattern of privilege separated OpenBSD daemons.

We will show how pledge(2) annotations guided the privilege separation, leading to a secure design. Other systems that lack OpenBSD's pledge annotations and kernel enforcement can still benefit from the secure design when slaacd gets ported to them.

bsdcan.org/2018/schedule/events/929.en.html
Florian Obser: slaacd(8)   BSDCan 2018Road Warrior Disaster Recovery by Aaron PoffenbergerZFS Direct IO Benchmarking Pitfalls by Mateusz PiotrowskiCheriBSD on Morello, the second CHERI: Andrew TurnerBSDCan 2023 Opening session by: Dan LangilleBSD networking BoF Tom SmythLightning Talk: Do you have a Red Pill by Andrew Cagney LibreswanRunning a root DNS server on FreeBSD    from Alpha to Now by Daniel MahoneyFlipping Bits Memory Errors in the Machine by Taylor CampbellNetflix and FreeBSD Reflections on Running FreeBSD Head in Production by Jonathan LooneyABI stability in FreeBSD By ShengYi Hungquiz: tiny VMs for kernel development By: Rob Norris
BSDCan |

Florian Obser: slaacd(8) -- BSDCan 2018

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER