2 * SPDX-License-Identifier: BSD-2-Clause
4 * Copyright (c) 2013 FreeBSD Foundation
6 * This software was developed by Pawel Jakub Dawidek under sponsorship from
7 * the FreeBSD Foundation.
9 * Redistribution and use in source and binary forms, with or without
10 * modification, are permitted provided that the following conditions
12 * 1. Redistributions of source code must retain the above copyright
13 * notice, this list of conditions and the following disclaimer.
14 * 2. Redistributions in binary form must reproduce the above copyright
15 * notice, this list of conditions and the following disclaimer in the
16 * documentation and/or other materials provided with the distribution.
18 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
19 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
20 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
21 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
22 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
23 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
24 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
25 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
26 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
27 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
31 #include <sys/cdefs.h>
33 * Note that this file is compiled into the kernel and into libc.
36 #include <sys/types.h>
37 #include <sys/capsicum.h>
40 #include <sys/systm.h>
41 #include <sys/kernel.h>
42 #include <machine/stdarg.h>
52 #define assert(exp) KASSERT((exp), ("%s:%u", __func__, __LINE__))
53 __read_mostly cap_rights_t cap_accept_rights;
54 __read_mostly cap_rights_t cap_bind_rights;
55 __read_mostly cap_rights_t cap_chflags_rights;
56 __read_mostly cap_rights_t cap_connect_rights;
57 __read_mostly cap_rights_t cap_event_rights;
58 __read_mostly cap_rights_t cap_fchdir_rights;
59 __read_mostly cap_rights_t cap_fchflags_rights;
60 __read_mostly cap_rights_t cap_fchmod_rights;
61 __read_mostly cap_rights_t cap_fchown_rights;
62 __read_mostly cap_rights_t cap_fcntl_rights;
63 __read_mostly cap_rights_t cap_fexecve_rights;
64 __read_mostly cap_rights_t cap_flock_rights;
65 __read_mostly cap_rights_t cap_fpathconf_rights;
66 __read_mostly cap_rights_t cap_fstat_rights;
67 __read_mostly cap_rights_t cap_fstatfs_rights;
68 __read_mostly cap_rights_t cap_fsync_rights;
69 __read_mostly cap_rights_t cap_ftruncate_rights;
70 __read_mostly cap_rights_t cap_futimes_rights;
71 __read_mostly cap_rights_t cap_getpeername_rights;
72 __read_mostly cap_rights_t cap_getsockopt_rights;
73 __read_mostly cap_rights_t cap_getsockname_rights;
74 __read_mostly cap_rights_t cap_ioctl_rights;
75 __read_mostly cap_rights_t cap_listen_rights;
76 __read_mostly cap_rights_t cap_linkat_source_rights;
77 __read_mostly cap_rights_t cap_linkat_target_rights;
78 __read_mostly cap_rights_t cap_mmap_rights;
79 __read_mostly cap_rights_t cap_mkdirat_rights;
80 __read_mostly cap_rights_t cap_mkfifoat_rights;
81 __read_mostly cap_rights_t cap_mknodat_rights;
82 __read_mostly cap_rights_t cap_pdgetpid_rights;
83 __read_mostly cap_rights_t cap_pdkill_rights;
84 __read_mostly cap_rights_t cap_pread_rights;
85 __read_mostly cap_rights_t cap_pwrite_rights;
86 __read_mostly cap_rights_t cap_read_rights;
87 __read_mostly cap_rights_t cap_recv_rights;
88 __read_mostly cap_rights_t cap_renameat_source_rights;
89 __read_mostly cap_rights_t cap_renameat_target_rights;
90 __read_mostly cap_rights_t cap_seek_rights;
91 __read_mostly cap_rights_t cap_send_rights;
92 __read_mostly cap_rights_t cap_send_connect_rights;
93 __read_mostly cap_rights_t cap_setsockopt_rights;
94 __read_mostly cap_rights_t cap_shutdown_rights;
95 __read_mostly cap_rights_t cap_symlinkat_rights;
96 __read_mostly cap_rights_t cap_unlinkat_rights;
97 __read_mostly cap_rights_t cap_write_rights;
98 __read_mostly cap_rights_t cap_no_rights;
101 cap_rights_sysinit(void *arg)
103 cap_rights_init_one(&cap_accept_rights, CAP_ACCEPT);
104 cap_rights_init_one(&cap_bind_rights, CAP_BIND);
105 cap_rights_init_one(&cap_connect_rights, CAP_CONNECT);
106 cap_rights_init_one(&cap_event_rights, CAP_EVENT);
107 cap_rights_init_one(&cap_fchdir_rights, CAP_FCHDIR);
108 cap_rights_init_one(&cap_fchflags_rights, CAP_FCHFLAGS);
109 cap_rights_init_one(&cap_fchmod_rights, CAP_FCHMOD);
110 cap_rights_init_one(&cap_fchown_rights, CAP_FCHOWN);
111 cap_rights_init_one(&cap_fcntl_rights, CAP_FCNTL);
112 cap_rights_init_one(&cap_fexecve_rights, CAP_FEXECVE);
113 cap_rights_init_one(&cap_flock_rights, CAP_FLOCK);
114 cap_rights_init_one(&cap_fpathconf_rights, CAP_FPATHCONF);
115 cap_rights_init_one(&cap_fstat_rights, CAP_FSTAT);
116 cap_rights_init_one(&cap_fstatfs_rights, CAP_FSTATFS);
117 cap_rights_init_one(&cap_fsync_rights, CAP_FSYNC);
118 cap_rights_init_one(&cap_ftruncate_rights, CAP_FTRUNCATE);
119 cap_rights_init_one(&cap_futimes_rights, CAP_FUTIMES);
120 cap_rights_init_one(&cap_getpeername_rights, CAP_GETPEERNAME);
121 cap_rights_init_one(&cap_getsockname_rights, CAP_GETSOCKNAME);
122 cap_rights_init_one(&cap_getsockopt_rights, CAP_GETSOCKOPT);
123 cap_rights_init_one(&cap_ioctl_rights, CAP_IOCTL);
124 cap_rights_init_one(&cap_linkat_source_rights, CAP_LINKAT_SOURCE);
125 cap_rights_init_one(&cap_linkat_target_rights, CAP_LINKAT_TARGET);
126 cap_rights_init_one(&cap_listen_rights, CAP_LISTEN);
127 cap_rights_init_one(&cap_mkdirat_rights, CAP_MKDIRAT);
128 cap_rights_init_one(&cap_mkfifoat_rights, CAP_MKFIFOAT);
129 cap_rights_init_one(&cap_mknodat_rights, CAP_MKNODAT);
130 cap_rights_init_one(&cap_mmap_rights, CAP_MMAP);
131 cap_rights_init_one(&cap_pdgetpid_rights, CAP_PDGETPID);
132 cap_rights_init_one(&cap_pdkill_rights, CAP_PDKILL);
133 cap_rights_init_one(&cap_pread_rights, CAP_PREAD);
134 cap_rights_init_one(&cap_pwrite_rights, CAP_PWRITE);
135 cap_rights_init_one(&cap_read_rights, CAP_READ);
136 cap_rights_init_one(&cap_recv_rights, CAP_RECV);
137 cap_rights_init_one(&cap_renameat_source_rights, CAP_RENAMEAT_SOURCE);
138 cap_rights_init_one(&cap_renameat_target_rights, CAP_RENAMEAT_TARGET);
139 cap_rights_init_one(&cap_seek_rights, CAP_SEEK);
140 cap_rights_init_one(&cap_send_rights, CAP_SEND);
141 cap_rights_init(&cap_send_connect_rights, CAP_SEND, CAP_CONNECT);
142 cap_rights_init_one(&cap_setsockopt_rights, CAP_SETSOCKOPT);
143 cap_rights_init_one(&cap_shutdown_rights, CAP_SHUTDOWN);
144 cap_rights_init_one(&cap_symlinkat_rights, CAP_SYMLINKAT);
145 cap_rights_init_one(&cap_unlinkat_rights, CAP_UNLINKAT);
146 cap_rights_init_one(&cap_write_rights, CAP_WRITE);
147 cap_rights_init(&cap_no_rights);
149 SYSINIT(cap_rights_sysinit, SI_SUB_COPYRIGHT, SI_ORDER_ANY, cap_rights_sysinit,
154 #define CAPARSIZE_MIN (CAP_RIGHTS_VERSION_00 + 2)
155 #define CAPARSIZE_MAX (CAP_RIGHTS_VERSION + 2)
158 right_to_index(uint64_t right)
160 static const int bit2idx[] = {
161 -1, 0, 1, -1, 2, -1, -1, -1, 3, -1, -1, -1, -1, -1, -1, -1,
162 4, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1, -1
166 idx = CAPIDXBIT(right);
167 assert(idx >= 0 && idx < sizeof(bit2idx) / sizeof(bit2idx[0]));
168 return (bit2idx[idx]);
172 cap_rights_vset(cap_rights_t *rights, va_list ap)
177 assert(CAPVER(rights) == CAP_RIGHTS_VERSION_00);
179 n = CAPARSIZE(rights);
180 assert(n >= CAPARSIZE_MIN && n <= CAPARSIZE_MAX);
183 right = (uint64_t)va_arg(ap, unsigned long long);
186 assert(CAPRVER(right) == 0);
187 i = right_to_index(right);
190 assert(CAPIDXBIT(rights->cr_rights[i]) == CAPIDXBIT(right));
191 rights->cr_rights[i] |= right;
192 assert(CAPIDXBIT(rights->cr_rights[i]) == CAPIDXBIT(right));
197 cap_rights_vclear(cap_rights_t *rights, va_list ap)
202 assert(CAPVER(rights) == CAP_RIGHTS_VERSION_00);
204 n = CAPARSIZE(rights);
205 assert(n >= CAPARSIZE_MIN && n <= CAPARSIZE_MAX);
208 right = (uint64_t)va_arg(ap, unsigned long long);
211 assert(CAPRVER(right) == 0);
212 i = right_to_index(right);
215 assert(CAPIDXBIT(rights->cr_rights[i]) == CAPIDXBIT(right));
216 rights->cr_rights[i] &= ~(right & 0x01FFFFFFFFFFFFFFULL);
217 assert(CAPIDXBIT(rights->cr_rights[i]) == CAPIDXBIT(right));
222 cap_rights_is_vset(const cap_rights_t *rights, va_list ap)
227 assert(CAPVER(rights) == CAP_RIGHTS_VERSION_00);
229 n = CAPARSIZE(rights);
230 assert(n >= CAPARSIZE_MIN && n <= CAPARSIZE_MAX);
233 right = (uint64_t)va_arg(ap, unsigned long long);
236 assert(CAPRVER(right) == 0);
237 i = right_to_index(right);
240 assert(CAPIDXBIT(rights->cr_rights[i]) == CAPIDXBIT(right));
241 if ((rights->cr_rights[i] & right) != right)
249 __cap_rights_init(int version, cap_rights_t *rights, ...)
251 unsigned int n __unused;
254 assert(version == CAP_RIGHTS_VERSION_00);
257 assert(n >= CAPARSIZE_MIN && n <= CAPARSIZE_MAX);
259 va_start(ap, rights);
260 cap_rights_vset(rights, ap);
267 __cap_rights_set(cap_rights_t *rights, ...)
271 assert(CAPVER(rights) == CAP_RIGHTS_VERSION_00);
273 va_start(ap, rights);
274 cap_rights_vset(rights, ap);
281 __cap_rights_clear(cap_rights_t *rights, ...)
285 assert(CAPVER(rights) == CAP_RIGHTS_VERSION_00);
287 va_start(ap, rights);
288 cap_rights_vclear(rights, ap);
295 __cap_rights_is_set(const cap_rights_t *rights, ...)
300 assert(CAPVER(rights) == CAP_RIGHTS_VERSION_00);
302 va_start(ap, rights);
303 ret = cap_rights_is_vset(rights, ap);
310 cap_rights_is_valid(const cap_rights_t *rights)
312 cap_rights_t allrights;
315 if (CAPVER(rights) != CAP_RIGHTS_VERSION_00)
317 if (CAPARSIZE(rights) < CAPARSIZE_MIN ||
318 CAPARSIZE(rights) > CAPARSIZE_MAX) {
322 if (!cap_rights_contains(&allrights, rights))
324 for (i = 0; i < CAPARSIZE(rights); i++) {
325 j = right_to_index(rights->cr_rights[i]);
329 if (CAPRVER(rights->cr_rights[i]) != 0)
338 cap_rights_merge(cap_rights_t *dst, const cap_rights_t *src)
342 assert(CAPVER(dst) == CAP_RIGHTS_VERSION_00);
343 assert(CAPVER(src) == CAP_RIGHTS_VERSION_00);
344 assert(CAPVER(dst) == CAPVER(src));
345 assert(cap_rights_is_valid(src));
346 assert(cap_rights_is_valid(dst));
349 assert(n >= CAPARSIZE_MIN && n <= CAPARSIZE_MAX);
351 for (i = 0; i < n; i++)
352 dst->cr_rights[i] |= src->cr_rights[i];
354 assert(cap_rights_is_valid(src));
355 assert(cap_rights_is_valid(dst));
361 cap_rights_remove(cap_rights_t *dst, const cap_rights_t *src)
365 assert(CAPVER(dst) == CAP_RIGHTS_VERSION_00);
366 assert(CAPVER(src) == CAP_RIGHTS_VERSION_00);
367 assert(CAPVER(dst) == CAPVER(src));
368 assert(cap_rights_is_valid(src));
369 assert(cap_rights_is_valid(dst));
372 assert(n >= CAPARSIZE_MIN && n <= CAPARSIZE_MAX);
374 for (i = 0; i < n; i++) {
376 ~(src->cr_rights[i] & 0x01FFFFFFFFFFFFFFULL);
379 assert(cap_rights_is_valid(src));
380 assert(cap_rights_is_valid(dst));
387 cap_rights_contains(const cap_rights_t *big, const cap_rights_t *little)
391 assert(CAPVER(big) == CAP_RIGHTS_VERSION_00);
392 assert(CAPVER(little) == CAP_RIGHTS_VERSION_00);
393 assert(CAPVER(big) == CAPVER(little));
396 assert(n >= CAPARSIZE_MIN && n <= CAPARSIZE_MAX);
398 for (i = 0; i < n; i++) {
399 if ((big->cr_rights[i] & little->cr_rights[i]) !=
400 little->cr_rights[i]) {