2 * Copyright (c) 2015 Nuxi, https://nuxi.nl/
4 * Redistribution and use in source and binary forms, with or without
5 * modification, are permitted provided that the following conditions
7 * 1. Redistributions of source code must retain the above copyright
8 * notice, this list of conditions and the following disclaimer.
9 * 2. Redistributions in binary form must reproduce the above copyright
10 * notice, this list of conditions and the following disclaimer in the
11 * documentation and/or other materials provided with the distribution.
13 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
14 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
15 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
16 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
17 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
18 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
19 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
20 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
21 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
22 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26 #include <sys/cdefs.h>
27 __FBSDID("$FreeBSD$");
29 #include <sys/param.h>
30 #include <sys/capsicum.h>
31 #include <sys/filedesc.h>
33 #include <sys/socketvar.h>
34 #include <sys/syscallsubr.h>
35 #include <sys/sysproto.h>
36 #include <sys/systm.h>
37 #include <sys/unistd.h>
38 #include <sys/vnode.h>
40 #include <compat/cloudabi/cloudabi_proto.h>
41 #include <compat/cloudabi/cloudabi_syscalldefs.h>
42 #include <compat/cloudabi/cloudabi_util.h>
44 /* Translation between CloudABI and Capsicum rights. */
45 #define RIGHTS_MAPPINGS \
46 MAPPING(CLOUDABI_RIGHT_FD_DATASYNC, CAP_FSYNC) \
47 MAPPING(CLOUDABI_RIGHT_FD_READ, CAP_READ) \
48 MAPPING(CLOUDABI_RIGHT_FD_SEEK, CAP_SEEK) \
49 MAPPING(CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS, CAP_FCNTL) \
50 MAPPING(CLOUDABI_RIGHT_FD_SYNC, CAP_FSYNC) \
51 MAPPING(CLOUDABI_RIGHT_FD_TELL, CAP_SEEK_TELL) \
52 MAPPING(CLOUDABI_RIGHT_FD_WRITE, CAP_WRITE) \
53 MAPPING(CLOUDABI_RIGHT_FILE_ADVISE) \
54 MAPPING(CLOUDABI_RIGHT_FILE_ALLOCATE, CAP_WRITE) \
55 MAPPING(CLOUDABI_RIGHT_FILE_CREATE_DIRECTORY, CAP_MKDIRAT) \
56 MAPPING(CLOUDABI_RIGHT_FILE_CREATE_FILE, CAP_CREATE) \
57 MAPPING(CLOUDABI_RIGHT_FILE_CREATE_FIFO, CAP_MKFIFOAT) \
58 MAPPING(CLOUDABI_RIGHT_FILE_LINK_SOURCE, CAP_LOOKUP) \
59 MAPPING(CLOUDABI_RIGHT_FILE_LINK_TARGET, CAP_LINKAT) \
60 MAPPING(CLOUDABI_RIGHT_FILE_OPEN, CAP_LOOKUP) \
61 MAPPING(CLOUDABI_RIGHT_FILE_READDIR, CAP_READ) \
62 MAPPING(CLOUDABI_RIGHT_FILE_READLINK, CAP_LOOKUP) \
63 MAPPING(CLOUDABI_RIGHT_FILE_RENAME_SOURCE, CAP_RENAMEAT) \
64 MAPPING(CLOUDABI_RIGHT_FILE_RENAME_TARGET, CAP_LINKAT) \
65 MAPPING(CLOUDABI_RIGHT_FILE_STAT_FGET, CAP_FSTAT) \
66 MAPPING(CLOUDABI_RIGHT_FILE_STAT_FPUT_SIZE, CAP_FTRUNCATE) \
67 MAPPING(CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES, CAP_FUTIMES) \
68 MAPPING(CLOUDABI_RIGHT_FILE_STAT_GET, CAP_FSTATAT) \
69 MAPPING(CLOUDABI_RIGHT_FILE_STAT_PUT_TIMES, CAP_FUTIMESAT) \
70 MAPPING(CLOUDABI_RIGHT_FILE_SYMLINK, CAP_SYMLINKAT) \
71 MAPPING(CLOUDABI_RIGHT_FILE_UNLINK, CAP_UNLINKAT) \
72 MAPPING(CLOUDABI_RIGHT_MEM_MAP, CAP_MMAP) \
73 MAPPING(CLOUDABI_RIGHT_MEM_MAP_EXEC, CAP_MMAP_X) \
74 MAPPING(CLOUDABI_RIGHT_POLL_FD_READWRITE, CAP_EVENT) \
75 MAPPING(CLOUDABI_RIGHT_POLL_MODIFY, CAP_KQUEUE_CHANGE) \
76 MAPPING(CLOUDABI_RIGHT_POLL_PROC_TERMINATE, CAP_PDWAIT) \
77 MAPPING(CLOUDABI_RIGHT_POLL_WAIT, CAP_KQUEUE_EVENT) \
78 MAPPING(CLOUDABI_RIGHT_PROC_EXEC, CAP_FEXECVE) \
79 MAPPING(CLOUDABI_RIGHT_SOCK_ACCEPT, CAP_ACCEPT) \
80 MAPPING(CLOUDABI_RIGHT_SOCK_BIND_DIRECTORY, CAP_BINDAT) \
81 MAPPING(CLOUDABI_RIGHT_SOCK_BIND_SOCKET, CAP_BIND) \
82 MAPPING(CLOUDABI_RIGHT_SOCK_CONNECT_DIRECTORY, CAP_CONNECTAT) \
83 MAPPING(CLOUDABI_RIGHT_SOCK_CONNECT_SOCKET, CAP_CONNECT) \
84 MAPPING(CLOUDABI_RIGHT_SOCK_LISTEN, CAP_LISTEN) \
85 MAPPING(CLOUDABI_RIGHT_SOCK_SHUTDOWN, CAP_SHUTDOWN) \
86 MAPPING(CLOUDABI_RIGHT_SOCK_STAT_GET, CAP_GETPEERNAME, \
87 CAP_GETSOCKNAME, CAP_GETSOCKOPT)
90 cloudabi_sys_fd_close(struct thread *td, struct cloudabi_sys_fd_close_args *uap)
93 return (kern_close(td, uap->fd));
97 cloudabi_sys_fd_create1(struct thread *td,
98 struct cloudabi_sys_fd_create1_args *uap)
100 struct socket_args socket_args = {
105 case CLOUDABI_FILETYPE_SOCKET_DGRAM:
106 socket_args.type = SOCK_DGRAM;
107 return (sys_socket(td, &socket_args));
108 case CLOUDABI_FILETYPE_SOCKET_SEQPACKET:
109 socket_args.type = SOCK_SEQPACKET;
110 return (sys_socket(td, &socket_args));
111 case CLOUDABI_FILETYPE_SOCKET_STREAM:
112 socket_args.type = SOCK_STREAM;
113 return (sys_socket(td, &socket_args));
120 cloudabi_sys_fd_create2(struct thread *td,
121 struct cloudabi_sys_fd_create2_args *uap)
123 struct filecaps fcaps1 = {}, fcaps2 = {};
128 case CLOUDABI_FILETYPE_FIFO:
130 * CloudABI pipes are unidirectional. Restrict rights on
131 * the pipe to simulate this.
133 cap_rights_init(&fcaps1.fc_rights, CAP_EVENT, CAP_FCNTL,
134 CAP_FSTAT, CAP_READ);
135 fcaps1.fc_fcntls = CAP_FCNTL_SETFL;
136 cap_rights_init(&fcaps2.fc_rights, CAP_EVENT, CAP_FCNTL,
137 CAP_FSTAT, CAP_WRITE);
138 fcaps2.fc_fcntls = CAP_FCNTL_SETFL;
139 error = kern_pipe(td, fds, 0, &fcaps1, &fcaps2);
141 case CLOUDABI_FILETYPE_SOCKET_DGRAM:
142 error = kern_socketpair(td, AF_UNIX, SOCK_DGRAM, 0, fds);
144 case CLOUDABI_FILETYPE_SOCKET_SEQPACKET:
145 error = kern_socketpair(td, AF_UNIX, SOCK_SEQPACKET, 0, fds);
147 case CLOUDABI_FILETYPE_SOCKET_STREAM:
148 error = kern_socketpair(td, AF_UNIX, SOCK_STREAM, 0, fds);
155 td->td_retval[0] = fds[0];
156 td->td_retval[1] = fds[1];
162 cloudabi_sys_fd_datasync(struct thread *td,
163 struct cloudabi_sys_fd_datasync_args *uap)
165 struct fsync_args fsync_args = {
169 /* Call into fsync(), as FreeBSD lacks fdatasync(). */
170 return (sys_fsync(td, &fsync_args));
174 cloudabi_sys_fd_dup(struct thread *td, struct cloudabi_sys_fd_dup_args *uap)
177 return (kern_dup(td, FDDUP_NORMAL, 0, uap->from, 0));
181 cloudabi_sys_fd_replace(struct thread *td,
182 struct cloudabi_sys_fd_replace_args *uap)
187 * CloudABI's equivalent to dup2(). CloudABI processes should
188 * not depend on hardcoded file descriptor layouts, but simply
189 * use the file descriptor numbers that are allocated by the
190 * kernel. Duplicating file descriptors to arbitrary numbers
191 * should not be done.
193 * Invoke kern_dup() with FDDUP_MUSTREPLACE, so that we return
194 * EBADF when duplicating to a nonexistent file descriptor. Also
195 * clear the return value, as this system call yields no return
198 error = kern_dup(td, FDDUP_MUSTREPLACE, 0, uap->from, uap->to);
199 td->td_retval[0] = 0;
204 cloudabi_sys_fd_seek(struct thread *td, struct cloudabi_sys_fd_seek_args *uap)
206 struct lseek_args lseek_args = {
208 .offset = uap->offset
211 switch (uap->whence) {
212 case CLOUDABI_WHENCE_CUR:
213 lseek_args.whence = SEEK_CUR;
215 case CLOUDABI_WHENCE_END:
216 lseek_args.whence = SEEK_END;
218 case CLOUDABI_WHENCE_SET:
219 lseek_args.whence = SEEK_SET;
225 return (sys_lseek(td, &lseek_args));
228 /* Converts a file descriptor to a CloudABI file descriptor type. */
230 cloudabi_convert_filetype(const struct file *fp)
235 switch (fp->f_type) {
237 return (CLOUDABI_FILETYPE_FIFO);
239 return (CLOUDABI_FILETYPE_POLL);
241 return (CLOUDABI_FILETYPE_FIFO);
243 return (CLOUDABI_FILETYPE_PROCESS);
245 return (CLOUDABI_FILETYPE_SHARED_MEMORY);
248 switch (so->so_type) {
250 return (CLOUDABI_FILETYPE_SOCKET_DGRAM);
252 return (CLOUDABI_FILETYPE_SOCKET_SEQPACKET);
254 return (CLOUDABI_FILETYPE_SOCKET_STREAM);
256 return (CLOUDABI_FILETYPE_UNKNOWN);
260 switch (vp->v_type) {
262 return (CLOUDABI_FILETYPE_BLOCK_DEVICE);
264 return (CLOUDABI_FILETYPE_CHARACTER_DEVICE);
266 return (CLOUDABI_FILETYPE_DIRECTORY);
268 return (CLOUDABI_FILETYPE_FIFO);
270 return (CLOUDABI_FILETYPE_SYMBOLIC_LINK);
272 return (CLOUDABI_FILETYPE_REGULAR_FILE);
274 return (CLOUDABI_FILETYPE_SOCKET_STREAM);
276 return (CLOUDABI_FILETYPE_UNKNOWN);
279 return (CLOUDABI_FILETYPE_UNKNOWN);
283 /* Removes rights that conflict with the file descriptor type. */
285 cloudabi_remove_conflicting_rights(cloudabi_filetype_t filetype,
286 cloudabi_rights_t *base, cloudabi_rights_t *inheriting)
290 * CloudABI has a small number of additional rights bits to
291 * disambiguate between multiple purposes. Remove the bits that
292 * don't apply to the type of the file descriptor.
294 * As file descriptor access modes (O_ACCMODE) has been fully
295 * replaced by rights bits, CloudABI distinguishes between
296 * rights that apply to the file descriptor itself (base) versus
297 * rights of new file descriptors derived from them
298 * (inheriting). The code below approximates the pair by
299 * decomposing depending on the file descriptor type.
301 * We need to be somewhat accurate about which actions can
302 * actually be performed on the file descriptor, as functions
303 * like fcntl(fd, F_GETFL) are emulated on top of this.
306 case CLOUDABI_FILETYPE_DIRECTORY:
307 *base &= CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
308 CLOUDABI_RIGHT_FD_SYNC | CLOUDABI_RIGHT_FILE_ADVISE |
309 CLOUDABI_RIGHT_FILE_CREATE_DIRECTORY |
310 CLOUDABI_RIGHT_FILE_CREATE_FILE |
311 CLOUDABI_RIGHT_FILE_CREATE_FIFO |
312 CLOUDABI_RIGHT_FILE_LINK_SOURCE |
313 CLOUDABI_RIGHT_FILE_LINK_TARGET |
314 CLOUDABI_RIGHT_FILE_OPEN |
315 CLOUDABI_RIGHT_FILE_READDIR |
316 CLOUDABI_RIGHT_FILE_READLINK |
317 CLOUDABI_RIGHT_FILE_RENAME_SOURCE |
318 CLOUDABI_RIGHT_FILE_RENAME_TARGET |
319 CLOUDABI_RIGHT_FILE_STAT_FGET |
320 CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES |
321 CLOUDABI_RIGHT_FILE_STAT_GET |
322 CLOUDABI_RIGHT_FILE_STAT_PUT_TIMES |
323 CLOUDABI_RIGHT_FILE_SYMLINK |
324 CLOUDABI_RIGHT_FILE_UNLINK |
325 CLOUDABI_RIGHT_POLL_FD_READWRITE |
326 CLOUDABI_RIGHT_SOCK_BIND_DIRECTORY |
327 CLOUDABI_RIGHT_SOCK_CONNECT_DIRECTORY;
328 *inheriting &= CLOUDABI_RIGHT_FD_DATASYNC |
329 CLOUDABI_RIGHT_FD_READ |
330 CLOUDABI_RIGHT_FD_SEEK |
331 CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
332 CLOUDABI_RIGHT_FD_SYNC |
333 CLOUDABI_RIGHT_FD_TELL |
334 CLOUDABI_RIGHT_FD_WRITE |
335 CLOUDABI_RIGHT_FILE_ADVISE |
336 CLOUDABI_RIGHT_FILE_ALLOCATE |
337 CLOUDABI_RIGHT_FILE_CREATE_DIRECTORY |
338 CLOUDABI_RIGHT_FILE_CREATE_FILE |
339 CLOUDABI_RIGHT_FILE_CREATE_FIFO |
340 CLOUDABI_RIGHT_FILE_LINK_SOURCE |
341 CLOUDABI_RIGHT_FILE_LINK_TARGET |
342 CLOUDABI_RIGHT_FILE_OPEN |
343 CLOUDABI_RIGHT_FILE_READDIR |
344 CLOUDABI_RIGHT_FILE_READLINK |
345 CLOUDABI_RIGHT_FILE_RENAME_SOURCE |
346 CLOUDABI_RIGHT_FILE_RENAME_TARGET |
347 CLOUDABI_RIGHT_FILE_STAT_FGET |
348 CLOUDABI_RIGHT_FILE_STAT_FPUT_SIZE |
349 CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES |
350 CLOUDABI_RIGHT_FILE_STAT_GET |
351 CLOUDABI_RIGHT_FILE_STAT_PUT_TIMES |
352 CLOUDABI_RIGHT_FILE_SYMLINK |
353 CLOUDABI_RIGHT_FILE_UNLINK |
354 CLOUDABI_RIGHT_MEM_MAP |
355 CLOUDABI_RIGHT_MEM_MAP_EXEC |
356 CLOUDABI_RIGHT_POLL_FD_READWRITE |
357 CLOUDABI_RIGHT_PROC_EXEC |
358 CLOUDABI_RIGHT_SOCK_BIND_DIRECTORY |
359 CLOUDABI_RIGHT_SOCK_CONNECT_DIRECTORY;
361 case CLOUDABI_FILETYPE_FIFO:
362 *base &= CLOUDABI_RIGHT_FD_READ |
363 CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
364 CLOUDABI_RIGHT_FD_WRITE |
365 CLOUDABI_RIGHT_FILE_STAT_FGET |
366 CLOUDABI_RIGHT_POLL_FD_READWRITE;
369 case CLOUDABI_FILETYPE_POLL:
370 *base &= ~CLOUDABI_RIGHT_FILE_ADVISE;
373 case CLOUDABI_FILETYPE_PROCESS:
374 *base &= ~CLOUDABI_RIGHT_FILE_ADVISE;
377 case CLOUDABI_FILETYPE_REGULAR_FILE:
378 *base &= CLOUDABI_RIGHT_FD_DATASYNC |
379 CLOUDABI_RIGHT_FD_READ |
380 CLOUDABI_RIGHT_FD_SEEK |
381 CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
382 CLOUDABI_RIGHT_FD_SYNC |
383 CLOUDABI_RIGHT_FD_TELL |
384 CLOUDABI_RIGHT_FD_WRITE |
385 CLOUDABI_RIGHT_FILE_ADVISE |
386 CLOUDABI_RIGHT_FILE_ALLOCATE |
387 CLOUDABI_RIGHT_FILE_STAT_FGET |
388 CLOUDABI_RIGHT_FILE_STAT_FPUT_SIZE |
389 CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES |
390 CLOUDABI_RIGHT_MEM_MAP |
391 CLOUDABI_RIGHT_MEM_MAP_EXEC |
392 CLOUDABI_RIGHT_POLL_FD_READWRITE |
393 CLOUDABI_RIGHT_PROC_EXEC;
396 case CLOUDABI_FILETYPE_SHARED_MEMORY:
397 *base &= ~(CLOUDABI_RIGHT_FD_SEEK |
398 CLOUDABI_RIGHT_FD_TELL |
399 CLOUDABI_RIGHT_FILE_ADVISE |
400 CLOUDABI_RIGHT_FILE_ALLOCATE |
401 CLOUDABI_RIGHT_FILE_READDIR);
404 case CLOUDABI_FILETYPE_SOCKET_DGRAM:
405 case CLOUDABI_FILETYPE_SOCKET_SEQPACKET:
406 case CLOUDABI_FILETYPE_SOCKET_STREAM:
407 *base &= CLOUDABI_RIGHT_FD_READ |
408 CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
409 CLOUDABI_RIGHT_FD_WRITE |
410 CLOUDABI_RIGHT_FILE_STAT_FGET |
411 CLOUDABI_RIGHT_POLL_FD_READWRITE |
412 CLOUDABI_RIGHT_SOCK_ACCEPT |
413 CLOUDABI_RIGHT_SOCK_BIND_SOCKET |
414 CLOUDABI_RIGHT_SOCK_CONNECT_SOCKET |
415 CLOUDABI_RIGHT_SOCK_LISTEN |
416 CLOUDABI_RIGHT_SOCK_SHUTDOWN |
417 CLOUDABI_RIGHT_SOCK_STAT_GET;
425 /* Converts FreeBSD's Capsicum rights to CloudABI's set of rights. */
427 convert_capabilities(const cap_rights_t *capabilities,
428 cloudabi_filetype_t filetype, cloudabi_rights_t *base,
429 cloudabi_rights_t *inheriting)
431 cloudabi_rights_t rights;
433 /* Convert FreeBSD bits to CloudABI bits. */
435 #define MAPPING(cloudabi, ...) do { \
436 if (cap_rights_is_set(capabilities, ##__VA_ARGS__)) \
437 rights |= (cloudabi); \
443 *inheriting = rights;
444 cloudabi_remove_conflicting_rights(filetype, base, inheriting);
448 cloudabi_sys_fd_stat_get(struct thread *td,
449 struct cloudabi_sys_fd_stat_get_args *uap)
451 cloudabi_fdstat_t fsb = {};
452 struct filedesc *fdp;
459 /* Obtain file descriptor properties. */
460 fdp = td->td_proc->p_fd;
462 error = fget_unlocked(fdp, uap->fd, cap_rights_init(&rights),
466 if (fp->f_ops == &badfileops) {
471 rights = *cap_rights(fdp, uap->fd);
472 oflags = OFLAGS(fp->f_flag);
473 fsb.fs_filetype = cloudabi_convert_filetype(fp);
475 modified = fd_modified(fdp, uap->fd, seq);
479 /* Convert file descriptor flags. */
480 if (oflags & O_APPEND)
481 fsb.fs_flags |= CLOUDABI_FDFLAG_APPEND;
482 if (oflags & O_NONBLOCK)
483 fsb.fs_flags |= CLOUDABI_FDFLAG_NONBLOCK;
485 fsb.fs_flags |= CLOUDABI_FDFLAG_SYNC;
487 /* Convert capabilities to CloudABI rights. */
488 convert_capabilities(&rights, fsb.fs_filetype,
489 &fsb.fs_rights_base, &fsb.fs_rights_inheriting);
490 return (copyout(&fsb, (void *)uap->buf, sizeof(fsb)));
494 cloudabi_sys_fd_stat_put(struct thread *td,
495 struct cloudabi_sys_fd_stat_put_args *uap)
498 /* Not implemented. */
503 cloudabi_sys_fd_sync(struct thread *td, struct cloudabi_sys_fd_sync_args *uap)
505 struct fsync_args fsync_args = {
509 return (sys_fsync(td, &fsync_args));