]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/blob - sys/compat/cloudabi/cloudabi_fd.c
Merge from HEAD
[FreeBSD/FreeBSD.git] / sys / compat / cloudabi / cloudabi_fd.c
1 /*-
2  * Copyright (c) 2015 Nuxi, https://nuxi.nl/
3  *
4  * Redistribution and use in source and binary forms, with or without
5  * modification, are permitted provided that the following conditions
6  * are met:
7  * 1. Redistributions of source code must retain the above copyright
8  *    notice, this list of conditions and the following disclaimer.
9  * 2. Redistributions in binary form must reproduce the above copyright
10  *    notice, this list of conditions and the following disclaimer in the
11  *    documentation and/or other materials provided with the distribution.
12  *
13  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
14  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
15  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
16  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
17  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
18  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
19  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
20  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
21  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
22  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
23  * SUCH DAMAGE.
24  */
25
26 #include <sys/cdefs.h>
27 __FBSDID("$FreeBSD$");
28
29 #include <sys/param.h>
30 #include <sys/capsicum.h>
31 #include <sys/filedesc.h>
32 #include <sys/proc.h>
33 #include <sys/mman.h>
34 #include <sys/socketvar.h>
35 #include <sys/syscallsubr.h>
36 #include <sys/sysproto.h>
37 #include <sys/systm.h>
38 #include <sys/unistd.h>
39 #include <sys/vnode.h>
40
41 #include <compat/cloudabi/cloudabi_proto.h>
42 #include <compat/cloudabi/cloudabi_syscalldefs.h>
43 #include <compat/cloudabi/cloudabi_util.h>
44
45 /* Translation between CloudABI and Capsicum rights. */
46 #define RIGHTS_MAPPINGS \
47         MAPPING(CLOUDABI_RIGHT_FD_DATASYNC, CAP_FSYNC)                  \
48         MAPPING(CLOUDABI_RIGHT_FD_READ, CAP_READ)                       \
49         MAPPING(CLOUDABI_RIGHT_FD_SEEK, CAP_SEEK)                       \
50         MAPPING(CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS, CAP_FCNTL)            \
51         MAPPING(CLOUDABI_RIGHT_FD_SYNC, CAP_FSYNC)                      \
52         MAPPING(CLOUDABI_RIGHT_FD_TELL, CAP_SEEK_TELL)                  \
53         MAPPING(CLOUDABI_RIGHT_FD_WRITE, CAP_WRITE)                     \
54         MAPPING(CLOUDABI_RIGHT_FILE_ADVISE)                             \
55         MAPPING(CLOUDABI_RIGHT_FILE_ALLOCATE, CAP_WRITE)                \
56         MAPPING(CLOUDABI_RIGHT_FILE_CREATE_DIRECTORY, CAP_MKDIRAT)      \
57         MAPPING(CLOUDABI_RIGHT_FILE_CREATE_FILE, CAP_CREATE)            \
58         MAPPING(CLOUDABI_RIGHT_FILE_CREATE_FIFO, CAP_MKFIFOAT)          \
59         MAPPING(CLOUDABI_RIGHT_FILE_LINK_SOURCE, CAP_LOOKUP)            \
60         MAPPING(CLOUDABI_RIGHT_FILE_LINK_TARGET, CAP_LINKAT)            \
61         MAPPING(CLOUDABI_RIGHT_FILE_OPEN, CAP_LOOKUP)                   \
62         MAPPING(CLOUDABI_RIGHT_FILE_READDIR, CAP_READ)                  \
63         MAPPING(CLOUDABI_RIGHT_FILE_READLINK, CAP_LOOKUP)               \
64         MAPPING(CLOUDABI_RIGHT_FILE_RENAME_SOURCE, CAP_RENAMEAT)        \
65         MAPPING(CLOUDABI_RIGHT_FILE_RENAME_TARGET, CAP_LINKAT)          \
66         MAPPING(CLOUDABI_RIGHT_FILE_STAT_FGET, CAP_FSTAT)               \
67         MAPPING(CLOUDABI_RIGHT_FILE_STAT_FPUT_SIZE, CAP_FTRUNCATE)      \
68         MAPPING(CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES, CAP_FUTIMES)       \
69         MAPPING(CLOUDABI_RIGHT_FILE_STAT_GET, CAP_FSTATAT)              \
70         MAPPING(CLOUDABI_RIGHT_FILE_STAT_PUT_TIMES, CAP_FUTIMESAT)      \
71         MAPPING(CLOUDABI_RIGHT_FILE_SYMLINK, CAP_SYMLINKAT)             \
72         MAPPING(CLOUDABI_RIGHT_FILE_UNLINK, CAP_UNLINKAT)               \
73         MAPPING(CLOUDABI_RIGHT_MEM_MAP, CAP_MMAP)                       \
74         MAPPING(CLOUDABI_RIGHT_MEM_MAP_EXEC, CAP_MMAP_X)                \
75         MAPPING(CLOUDABI_RIGHT_POLL_FD_READWRITE, CAP_EVENT)            \
76         MAPPING(CLOUDABI_RIGHT_POLL_MODIFY, CAP_KQUEUE_CHANGE)          \
77         MAPPING(CLOUDABI_RIGHT_POLL_PROC_TERMINATE, CAP_EVENT)          \
78         MAPPING(CLOUDABI_RIGHT_POLL_WAIT, CAP_KQUEUE_EVENT)             \
79         MAPPING(CLOUDABI_RIGHT_PROC_EXEC, CAP_FEXECVE)                  \
80         MAPPING(CLOUDABI_RIGHT_SOCK_ACCEPT, CAP_ACCEPT)                 \
81         MAPPING(CLOUDABI_RIGHT_SOCK_BIND_DIRECTORY, CAP_BINDAT)         \
82         MAPPING(CLOUDABI_RIGHT_SOCK_BIND_SOCKET, CAP_BIND)              \
83         MAPPING(CLOUDABI_RIGHT_SOCK_CONNECT_DIRECTORY, CAP_CONNECTAT)   \
84         MAPPING(CLOUDABI_RIGHT_SOCK_CONNECT_SOCKET, CAP_CONNECT)        \
85         MAPPING(CLOUDABI_RIGHT_SOCK_LISTEN, CAP_LISTEN)                 \
86         MAPPING(CLOUDABI_RIGHT_SOCK_SHUTDOWN, CAP_SHUTDOWN)             \
87         MAPPING(CLOUDABI_RIGHT_SOCK_STAT_GET, CAP_GETPEERNAME,          \
88             CAP_GETSOCKNAME, CAP_GETSOCKOPT)
89
90 int
91 cloudabi_sys_fd_close(struct thread *td, struct cloudabi_sys_fd_close_args *uap)
92 {
93
94         return (kern_close(td, uap->fd));
95 }
96
97 int
98 cloudabi_sys_fd_create1(struct thread *td,
99     struct cloudabi_sys_fd_create1_args *uap)
100 {
101         struct filecaps fcaps = {};
102         struct socket_args socket_args = {
103                 .domain = AF_UNIX,
104         };
105
106         switch (uap->type) {
107         case CLOUDABI_FILETYPE_POLL:
108                 cap_rights_init(&fcaps.fc_rights, CAP_FSTAT, CAP_KQUEUE);
109                 return (kern_kqueue(td, 0, &fcaps));
110         case CLOUDABI_FILETYPE_SHARED_MEMORY:
111                 cap_rights_init(&fcaps.fc_rights, CAP_FSTAT, CAP_FTRUNCATE,
112                     CAP_MMAP_RWX);
113                 return (kern_shm_open(td, SHM_ANON, O_RDWR, 0, &fcaps));
114         case CLOUDABI_FILETYPE_SOCKET_DGRAM:
115                 socket_args.type = SOCK_DGRAM;
116                 return (sys_socket(td, &socket_args));
117         case CLOUDABI_FILETYPE_SOCKET_SEQPACKET:
118                 socket_args.type = SOCK_SEQPACKET;
119                 return (sys_socket(td, &socket_args));
120         case CLOUDABI_FILETYPE_SOCKET_STREAM:
121                 socket_args.type = SOCK_STREAM;
122                 return (sys_socket(td, &socket_args));
123         default:
124                 return (EINVAL);
125         }
126 }
127
128 int
129 cloudabi_sys_fd_create2(struct thread *td,
130     struct cloudabi_sys_fd_create2_args *uap)
131 {
132         struct filecaps fcaps1 = {}, fcaps2 = {};
133         int fds[2];
134         int error;
135
136         switch (uap->type) {
137         case CLOUDABI_FILETYPE_FIFO:
138                 /*
139                  * CloudABI pipes are unidirectional. Restrict rights on
140                  * the pipe to simulate this.
141                  */
142                 cap_rights_init(&fcaps1.fc_rights, CAP_EVENT, CAP_FCNTL,
143                     CAP_FSTAT, CAP_READ);
144                 fcaps1.fc_fcntls = CAP_FCNTL_SETFL;
145                 cap_rights_init(&fcaps2.fc_rights, CAP_EVENT, CAP_FCNTL,
146                     CAP_FSTAT, CAP_WRITE);
147                 fcaps2.fc_fcntls = CAP_FCNTL_SETFL;
148                 error = kern_pipe(td, fds, 0, &fcaps1, &fcaps2);
149                 break;
150         case CLOUDABI_FILETYPE_SOCKET_DGRAM:
151                 error = kern_socketpair(td, AF_UNIX, SOCK_DGRAM, 0, fds);
152                 break;
153         case CLOUDABI_FILETYPE_SOCKET_SEQPACKET:
154                 error = kern_socketpair(td, AF_UNIX, SOCK_SEQPACKET, 0, fds);
155                 break;
156         case CLOUDABI_FILETYPE_SOCKET_STREAM:
157                 error = kern_socketpair(td, AF_UNIX, SOCK_STREAM, 0, fds);
158                 break;
159         default:
160                 return (EINVAL);
161         }
162
163         if (error == 0) {
164                 td->td_retval[0] = fds[0];
165                 td->td_retval[1] = fds[1];
166         }
167         return (0);
168 }
169
170 int
171 cloudabi_sys_fd_datasync(struct thread *td,
172     struct cloudabi_sys_fd_datasync_args *uap)
173 {
174         struct fsync_args fsync_args = {
175                 .fd = uap->fd
176         };
177
178         /* Call into fsync(), as FreeBSD lacks fdatasync(). */
179         return (sys_fsync(td, &fsync_args));
180 }
181
182 int
183 cloudabi_sys_fd_dup(struct thread *td, struct cloudabi_sys_fd_dup_args *uap)
184 {
185
186         return (kern_dup(td, FDDUP_NORMAL, 0, uap->from, 0));
187 }
188
189 int
190 cloudabi_sys_fd_replace(struct thread *td,
191     struct cloudabi_sys_fd_replace_args *uap)
192 {
193         int error;
194
195         /*
196          * CloudABI's equivalent to dup2(). CloudABI processes should
197          * not depend on hardcoded file descriptor layouts, but simply
198          * use the file descriptor numbers that are allocated by the
199          * kernel. Duplicating file descriptors to arbitrary numbers
200          * should not be done.
201          *
202          * Invoke kern_dup() with FDDUP_MUSTREPLACE, so that we return
203          * EBADF when duplicating to a nonexistent file descriptor. Also
204          * clear the return value, as this system call yields no return
205          * value.
206          */
207         error = kern_dup(td, FDDUP_MUSTREPLACE, 0, uap->from, uap->to);
208         td->td_retval[0] = 0;
209         return (error);
210 }
211
212 int
213 cloudabi_sys_fd_seek(struct thread *td, struct cloudabi_sys_fd_seek_args *uap)
214 {
215         struct lseek_args lseek_args = {
216                 .fd     = uap->fd,
217                 .offset = uap->offset
218         };
219
220         switch (uap->whence) {
221         case CLOUDABI_WHENCE_CUR:
222                 lseek_args.whence = SEEK_CUR;
223                 break;
224         case CLOUDABI_WHENCE_END:
225                 lseek_args.whence = SEEK_END;
226                 break;
227         case CLOUDABI_WHENCE_SET:
228                 lseek_args.whence = SEEK_SET;
229                 break;
230         default:
231                 return (EINVAL);
232         }
233
234         return (sys_lseek(td, &lseek_args));
235 }
236
237 /* Converts a file descriptor to a CloudABI file descriptor type. */
238 cloudabi_filetype_t
239 cloudabi_convert_filetype(const struct file *fp)
240 {
241         struct socket *so;
242         struct vnode *vp;
243
244         switch (fp->f_type) {
245         case DTYPE_FIFO:
246                 return (CLOUDABI_FILETYPE_FIFO);
247         case DTYPE_KQUEUE:
248                 return (CLOUDABI_FILETYPE_POLL);
249         case DTYPE_PIPE:
250                 return (CLOUDABI_FILETYPE_FIFO);
251         case DTYPE_PROCDESC:
252                 return (CLOUDABI_FILETYPE_PROCESS);
253         case DTYPE_SHM:
254                 return (CLOUDABI_FILETYPE_SHARED_MEMORY);
255         case DTYPE_SOCKET:
256                 so = fp->f_data;
257                 switch (so->so_type) {
258                 case SOCK_DGRAM:
259                         return (CLOUDABI_FILETYPE_SOCKET_DGRAM);
260                 case SOCK_SEQPACKET:
261                         return (CLOUDABI_FILETYPE_SOCKET_SEQPACKET);
262                 case SOCK_STREAM:
263                         return (CLOUDABI_FILETYPE_SOCKET_STREAM);
264                 default:
265                         return (CLOUDABI_FILETYPE_UNKNOWN);
266                 }
267         case DTYPE_VNODE:
268                 vp = fp->f_vnode;
269                 switch (vp->v_type) {
270                 case VBLK:
271                         return (CLOUDABI_FILETYPE_BLOCK_DEVICE);
272                 case VCHR:
273                         return (CLOUDABI_FILETYPE_CHARACTER_DEVICE);
274                 case VDIR:
275                         return (CLOUDABI_FILETYPE_DIRECTORY);
276                 case VFIFO:
277                         return (CLOUDABI_FILETYPE_FIFO);
278                 case VLNK:
279                         return (CLOUDABI_FILETYPE_SYMBOLIC_LINK);
280                 case VREG:
281                         return (CLOUDABI_FILETYPE_REGULAR_FILE);
282                 case VSOCK:
283                         return (CLOUDABI_FILETYPE_SOCKET_STREAM);
284                 default:
285                         return (CLOUDABI_FILETYPE_UNKNOWN);
286                 }
287         default:
288                 return (CLOUDABI_FILETYPE_UNKNOWN);
289         }
290 }
291
292 /* Removes rights that conflict with the file descriptor type. */
293 void
294 cloudabi_remove_conflicting_rights(cloudabi_filetype_t filetype,
295     cloudabi_rights_t *base, cloudabi_rights_t *inheriting)
296 {
297
298         /*
299          * CloudABI has a small number of additional rights bits to
300          * disambiguate between multiple purposes. Remove the bits that
301          * don't apply to the type of the file descriptor.
302          *
303          * As file descriptor access modes (O_ACCMODE) has been fully
304          * replaced by rights bits, CloudABI distinguishes between
305          * rights that apply to the file descriptor itself (base) versus
306          * rights of new file descriptors derived from them
307          * (inheriting). The code below approximates the pair by
308          * decomposing depending on the file descriptor type.
309          *
310          * We need to be somewhat accurate about which actions can
311          * actually be performed on the file descriptor, as functions
312          * like fcntl(fd, F_GETFL) are emulated on top of this.
313          */
314         switch (filetype) {
315         case CLOUDABI_FILETYPE_DIRECTORY:
316                 *base &= CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
317                     CLOUDABI_RIGHT_FD_SYNC | CLOUDABI_RIGHT_FILE_ADVISE |
318                     CLOUDABI_RIGHT_FILE_CREATE_DIRECTORY |
319                     CLOUDABI_RIGHT_FILE_CREATE_FILE |
320                     CLOUDABI_RIGHT_FILE_CREATE_FIFO |
321                     CLOUDABI_RIGHT_FILE_LINK_SOURCE |
322                     CLOUDABI_RIGHT_FILE_LINK_TARGET |
323                     CLOUDABI_RIGHT_FILE_OPEN |
324                     CLOUDABI_RIGHT_FILE_READDIR |
325                     CLOUDABI_RIGHT_FILE_READLINK |
326                     CLOUDABI_RIGHT_FILE_RENAME_SOURCE |
327                     CLOUDABI_RIGHT_FILE_RENAME_TARGET |
328                     CLOUDABI_RIGHT_FILE_STAT_FGET |
329                     CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES |
330                     CLOUDABI_RIGHT_FILE_STAT_GET |
331                     CLOUDABI_RIGHT_FILE_STAT_PUT_TIMES |
332                     CLOUDABI_RIGHT_FILE_SYMLINK |
333                     CLOUDABI_RIGHT_FILE_UNLINK |
334                     CLOUDABI_RIGHT_POLL_FD_READWRITE |
335                     CLOUDABI_RIGHT_SOCK_BIND_DIRECTORY |
336                     CLOUDABI_RIGHT_SOCK_CONNECT_DIRECTORY;
337                 *inheriting &= CLOUDABI_RIGHT_FD_DATASYNC |
338                     CLOUDABI_RIGHT_FD_READ |
339                     CLOUDABI_RIGHT_FD_SEEK |
340                     CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
341                     CLOUDABI_RIGHT_FD_SYNC |
342                     CLOUDABI_RIGHT_FD_TELL |
343                     CLOUDABI_RIGHT_FD_WRITE |
344                     CLOUDABI_RIGHT_FILE_ADVISE |
345                     CLOUDABI_RIGHT_FILE_ALLOCATE |
346                     CLOUDABI_RIGHT_FILE_CREATE_DIRECTORY |
347                     CLOUDABI_RIGHT_FILE_CREATE_FILE |
348                     CLOUDABI_RIGHT_FILE_CREATE_FIFO |
349                     CLOUDABI_RIGHT_FILE_LINK_SOURCE |
350                     CLOUDABI_RIGHT_FILE_LINK_TARGET |
351                     CLOUDABI_RIGHT_FILE_OPEN |
352                     CLOUDABI_RIGHT_FILE_READDIR |
353                     CLOUDABI_RIGHT_FILE_READLINK |
354                     CLOUDABI_RIGHT_FILE_RENAME_SOURCE |
355                     CLOUDABI_RIGHT_FILE_RENAME_TARGET |
356                     CLOUDABI_RIGHT_FILE_STAT_FGET |
357                     CLOUDABI_RIGHT_FILE_STAT_FPUT_SIZE |
358                     CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES |
359                     CLOUDABI_RIGHT_FILE_STAT_GET |
360                     CLOUDABI_RIGHT_FILE_STAT_PUT_TIMES |
361                     CLOUDABI_RIGHT_FILE_SYMLINK |
362                     CLOUDABI_RIGHT_FILE_UNLINK |
363                     CLOUDABI_RIGHT_MEM_MAP |
364                     CLOUDABI_RIGHT_MEM_MAP_EXEC |
365                     CLOUDABI_RIGHT_POLL_FD_READWRITE |
366                     CLOUDABI_RIGHT_PROC_EXEC |
367                     CLOUDABI_RIGHT_SOCK_BIND_DIRECTORY |
368                     CLOUDABI_RIGHT_SOCK_CONNECT_DIRECTORY;
369                 break;
370         case CLOUDABI_FILETYPE_FIFO:
371                 *base &= CLOUDABI_RIGHT_FD_READ |
372                     CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
373                     CLOUDABI_RIGHT_FD_WRITE |
374                     CLOUDABI_RIGHT_FILE_STAT_FGET |
375                     CLOUDABI_RIGHT_POLL_FD_READWRITE;
376                 *inheriting = 0;
377                 break;
378         case CLOUDABI_FILETYPE_POLL:
379                 *base &= ~CLOUDABI_RIGHT_FILE_ADVISE;
380                 *inheriting = 0;
381                 break;
382         case CLOUDABI_FILETYPE_PROCESS:
383                 *base &= ~(CLOUDABI_RIGHT_FILE_ADVISE |
384                     CLOUDABI_RIGHT_POLL_FD_READWRITE);
385                 *inheriting = 0;
386                 break;
387         case CLOUDABI_FILETYPE_REGULAR_FILE:
388                 *base &= CLOUDABI_RIGHT_FD_DATASYNC |
389                     CLOUDABI_RIGHT_FD_READ |
390                     CLOUDABI_RIGHT_FD_SEEK |
391                     CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
392                     CLOUDABI_RIGHT_FD_SYNC |
393                     CLOUDABI_RIGHT_FD_TELL |
394                     CLOUDABI_RIGHT_FD_WRITE |
395                     CLOUDABI_RIGHT_FILE_ADVISE |
396                     CLOUDABI_RIGHT_FILE_ALLOCATE |
397                     CLOUDABI_RIGHT_FILE_STAT_FGET |
398                     CLOUDABI_RIGHT_FILE_STAT_FPUT_SIZE |
399                     CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES |
400                     CLOUDABI_RIGHT_MEM_MAP |
401                     CLOUDABI_RIGHT_MEM_MAP_EXEC |
402                     CLOUDABI_RIGHT_POLL_FD_READWRITE |
403                     CLOUDABI_RIGHT_PROC_EXEC;
404                 *inheriting = 0;
405                 break;
406         case CLOUDABI_FILETYPE_SHARED_MEMORY:
407                 *base &= ~(CLOUDABI_RIGHT_FD_SEEK |
408                     CLOUDABI_RIGHT_FD_TELL |
409                     CLOUDABI_RIGHT_FILE_ADVISE |
410                     CLOUDABI_RIGHT_FILE_ALLOCATE |
411                     CLOUDABI_RIGHT_FILE_READDIR);
412                 *inheriting = 0;
413                 break;
414         case CLOUDABI_FILETYPE_SOCKET_DGRAM:
415         case CLOUDABI_FILETYPE_SOCKET_SEQPACKET:
416         case CLOUDABI_FILETYPE_SOCKET_STREAM:
417                 *base &= CLOUDABI_RIGHT_FD_READ |
418                     CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
419                     CLOUDABI_RIGHT_FD_WRITE |
420                     CLOUDABI_RIGHT_FILE_STAT_FGET |
421                     CLOUDABI_RIGHT_POLL_FD_READWRITE |
422                     CLOUDABI_RIGHT_SOCK_ACCEPT |
423                     CLOUDABI_RIGHT_SOCK_BIND_SOCKET |
424                     CLOUDABI_RIGHT_SOCK_CONNECT_SOCKET |
425                     CLOUDABI_RIGHT_SOCK_LISTEN |
426                     CLOUDABI_RIGHT_SOCK_SHUTDOWN |
427                     CLOUDABI_RIGHT_SOCK_STAT_GET;
428                 break;
429         default:
430                 *inheriting = 0;
431                 break;
432         }
433 }
434
435 /* Converts FreeBSD's Capsicum rights to CloudABI's set of rights. */
436 static void
437 convert_capabilities(const cap_rights_t *capabilities,
438     cloudabi_filetype_t filetype, cloudabi_rights_t *base,
439     cloudabi_rights_t *inheriting)
440 {
441         cloudabi_rights_t rights;
442
443         /* Convert FreeBSD bits to CloudABI bits. */
444         rights = 0;
445 #define MAPPING(cloudabi, ...) do {                             \
446         if (cap_rights_is_set(capabilities, ##__VA_ARGS__))     \
447                 rights |= (cloudabi);                           \
448 } while (0);
449         RIGHTS_MAPPINGS
450 #undef MAPPING
451
452         *base = rights;
453         *inheriting = rights;
454         cloudabi_remove_conflicting_rights(filetype, base, inheriting);
455 }
456
457 int
458 cloudabi_sys_fd_stat_get(struct thread *td,
459     struct cloudabi_sys_fd_stat_get_args *uap)
460 {
461         cloudabi_fdstat_t fsb = {};
462         struct filedesc *fdp;
463         struct file *fp;
464         seq_t seq;
465         cap_rights_t rights;
466         int error, oflags;
467         bool modified;
468
469         /* Obtain file descriptor properties. */
470         fdp = td->td_proc->p_fd;
471         do {
472                 error = fget_unlocked(fdp, uap->fd, cap_rights_init(&rights),
473                     &fp, &seq);
474                 if (error != 0)
475                         return (error);
476                 if (fp->f_ops == &badfileops) {
477                         fdrop(fp, td);
478                         return (EBADF);
479                 }
480
481                 rights = *cap_rights(fdp, uap->fd);
482                 oflags = OFLAGS(fp->f_flag);
483                 fsb.fs_filetype = cloudabi_convert_filetype(fp);
484
485                 modified = fd_modified(fdp, uap->fd, seq);
486                 fdrop(fp, td);
487         } while (modified);
488
489         /* Convert file descriptor flags. */
490         if (oflags & O_APPEND)
491                 fsb.fs_flags |= CLOUDABI_FDFLAG_APPEND;
492         if (oflags & O_NONBLOCK)
493                 fsb.fs_flags |= CLOUDABI_FDFLAG_NONBLOCK;
494         if (oflags & O_SYNC)
495                 fsb.fs_flags |= CLOUDABI_FDFLAG_SYNC;
496
497         /* Convert capabilities to CloudABI rights. */
498         convert_capabilities(&rights, fsb.fs_filetype,
499             &fsb.fs_rights_base, &fsb.fs_rights_inheriting);
500         return (copyout(&fsb, (void *)uap->buf, sizeof(fsb)));
501 }
502
503 /* Converts CloudABI rights to a set of Capsicum capabilities. */
504 int
505 cloudabi_convert_rights(cloudabi_rights_t in, cap_rights_t *out)
506 {
507
508         cap_rights_init(out);
509 #define MAPPING(cloudabi, ...) do {                     \
510         if (in & (cloudabi)) {                          \
511                 cap_rights_set(out, ##__VA_ARGS__);     \
512                 in &= ~(cloudabi);                      \
513         }                                               \
514 } while (0);
515         RIGHTS_MAPPINGS
516 #undef MAPPING
517         if (in != 0)
518                 return (ENOTCAPABLE);
519         return (0);
520 }
521
522 int
523 cloudabi_sys_fd_stat_put(struct thread *td,
524     struct cloudabi_sys_fd_stat_put_args *uap)
525 {
526         cloudabi_fdstat_t fsb;
527         cap_rights_t rights;
528         int error, oflags;
529
530         error = copyin(uap->buf, &fsb, sizeof(fsb));
531         if (error != 0)
532                 return (error);
533
534         if (uap->flags == CLOUDABI_FDSTAT_FLAGS) {
535                 /* Convert flags. */
536                 oflags = 0;
537                 if (fsb.fs_flags & CLOUDABI_FDFLAG_APPEND)
538                         oflags |= O_APPEND;
539                 if (fsb.fs_flags & CLOUDABI_FDFLAG_NONBLOCK)
540                         oflags |= O_NONBLOCK;
541                 if (fsb.fs_flags & (CLOUDABI_FDFLAG_SYNC |
542                     CLOUDABI_FDFLAG_DSYNC | CLOUDABI_FDFLAG_RSYNC))
543                         oflags |= O_SYNC;
544                 return (kern_fcntl(td, uap->fd, F_SETFL, oflags));
545         } else if (uap->flags == CLOUDABI_FDSTAT_RIGHTS) {
546                 /* Convert rights. */
547                 error = cloudabi_convert_rights(
548                     fsb.fs_rights_base | fsb.fs_rights_inheriting, &rights);
549                 if (error != 0)
550                         return (error);
551                 return (kern_cap_rights_limit(td, uap->fd, &rights));
552         }
553         return (EINVAL);
554 }
555
556 int
557 cloudabi_sys_fd_sync(struct thread *td, struct cloudabi_sys_fd_sync_args *uap)
558 {
559         struct fsync_args fsync_args = {
560                 .fd = uap->fd
561         };
562
563         return (sys_fsync(td, &fsync_args));
564 }