| @@ -1,14 +1,14 @@ | | | @@ -1,14 +1,14 @@ |
1 | /* $NetBSD: procfs_vfsops.c,v 1.83 2009/03/15 17:22:38 cegger Exp $ */ | | 1 | /* $NetBSD: procfs_vfsops.c,v 1.84 2009/10/02 23:00:02 elad Exp $ */ |
2 | | | 2 | |
3 | /* | | 3 | /* |
4 | * Copyright (c) 1993 | | 4 | * Copyright (c) 1993 |
5 | * The Regents of the University of California. All rights reserved. | | 5 | * The Regents of the University of California. All rights reserved. |
6 | * | | 6 | * |
7 | * This code is derived from software contributed to Berkeley by | | 7 | * This code is derived from software contributed to Berkeley by |
8 | * Jan-Simon Pendry. | | 8 | * Jan-Simon Pendry. |
9 | * | | 9 | * |
10 | * Redistribution and use in source and binary forms, with or without | | 10 | * Redistribution and use in source and binary forms, with or without |
11 | * modification, are permitted provided that the following conditions | | 11 | * modification, are permitted provided that the following conditions |
12 | * are met: | | 12 | * are met: |
13 | * 1. Redistributions of source code must retain the above copyright | | 13 | * 1. Redistributions of source code must retain the above copyright |
14 | * notice, this list of conditions and the following disclaimer. | | 14 | * notice, this list of conditions and the following disclaimer. |
| @@ -66,27 +66,27 @@ | | | @@ -66,27 +66,27 @@ |
66 | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT | | 66 | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT |
67 | * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY | | 67 | * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY |
68 | * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF | | 68 | * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF |
69 | * SUCH DAMAGE. | | 69 | * SUCH DAMAGE. |
70 | * | | 70 | * |
71 | * @(#)procfs_vfsops.c 8.7 (Berkeley) 5/10/95 | | 71 | * @(#)procfs_vfsops.c 8.7 (Berkeley) 5/10/95 |
72 | */ | | 72 | */ |
73 | | | 73 | |
74 | /* | | 74 | /* |
75 | * procfs VFS interface | | 75 | * procfs VFS interface |
76 | */ | | 76 | */ |
77 | | | 77 | |
78 | #include <sys/cdefs.h> | | 78 | #include <sys/cdefs.h> |
79 | __KERNEL_RCSID(0, "$NetBSD: procfs_vfsops.c,v 1.83 2009/03/15 17:22:38 cegger Exp $"); | | 79 | __KERNEL_RCSID(0, "$NetBSD: procfs_vfsops.c,v 1.84 2009/10/02 23:00:02 elad Exp $"); |
80 | | | 80 | |
81 | #if defined(_KERNEL_OPT) | | 81 | #if defined(_KERNEL_OPT) |
82 | #include "opt_compat_netbsd.h" | | 82 | #include "opt_compat_netbsd.h" |
83 | #endif | | 83 | #endif |
84 | | | 84 | |
85 | #include <sys/param.h> | | 85 | #include <sys/param.h> |
86 | #include <sys/time.h> | | 86 | #include <sys/time.h> |
87 | #include <sys/kernel.h> | | 87 | #include <sys/kernel.h> |
88 | #include <sys/systm.h> | | 88 | #include <sys/systm.h> |
89 | #include <sys/sysctl.h> | | 89 | #include <sys/sysctl.h> |
90 | #include <sys/proc.h> | | 90 | #include <sys/proc.h> |
91 | #include <sys/buf.h> | | 91 | #include <sys/buf.h> |
92 | #include <sys/syslog.h> | | 92 | #include <sys/syslog.h> |
| @@ -100,26 +100,28 @@ __KERNEL_RCSID(0, "$NetBSD: procfs_vfsop | | | @@ -100,26 +100,28 @@ __KERNEL_RCSID(0, "$NetBSD: procfs_vfsop |
100 | | | 100 | |
101 | #include <miscfs/genfs/genfs.h> | | 101 | #include <miscfs/genfs/genfs.h> |
102 | | | 102 | |
103 | #include <miscfs/procfs/procfs.h> | | 103 | #include <miscfs/procfs/procfs.h> |
104 | | | 104 | |
105 | #include <uvm/uvm_extern.h> /* for PAGE_SIZE */ | | 105 | #include <uvm/uvm_extern.h> /* for PAGE_SIZE */ |
106 | | | 106 | |
107 | MODULE(MODULE_CLASS_VFS, procfs, NULL); | | 107 | MODULE(MODULE_CLASS_VFS, procfs, NULL); |
108 | | | 108 | |
109 | VFS_PROTOS(procfs); | | 109 | VFS_PROTOS(procfs); |
110 | | | 110 | |
111 | static struct sysctllog *procfs_sysctl_log; | | 111 | static struct sysctllog *procfs_sysctl_log; |
112 | | | 112 | |
| | | 113 | static kauth_listener_t procfs_listener; |
| | | 114 | |
113 | /* | | 115 | /* |
114 | * VFS Operations. | | 116 | * VFS Operations. |
115 | * | | 117 | * |
116 | * mount system call | | 118 | * mount system call |
117 | */ | | 119 | */ |
118 | /* ARGSUSED */ | | 120 | /* ARGSUSED */ |
119 | int | | 121 | int |
120 | procfs_mount( | | 122 | procfs_mount( |
121 | struct mount *mp, | | 123 | struct mount *mp, |
122 | const char *path, | | 124 | const char *path, |
123 | void *data, | | 125 | void *data, |
124 | size_t *data_len) | | 126 | size_t *data_len) |
125 | { | | 127 | { |
| @@ -295,52 +297,96 @@ struct vfsops procfs_vfsops = { | | | @@ -295,52 +297,96 @@ struct vfsops procfs_vfsops = { |
295 | NULL, /* vfs_mountroot */ | | 297 | NULL, /* vfs_mountroot */ |
296 | (int (*)(struct mount *, struct vnode *, struct timespec *)) eopnotsupp, | | 298 | (int (*)(struct mount *, struct vnode *, struct timespec *)) eopnotsupp, |
297 | vfs_stdextattrctl, | | 299 | vfs_stdextattrctl, |
298 | (void *)eopnotsupp, /* vfs_suspendctl */ | | 300 | (void *)eopnotsupp, /* vfs_suspendctl */ |
299 | genfs_renamelock_enter, | | 301 | genfs_renamelock_enter, |
300 | genfs_renamelock_exit, | | 302 | genfs_renamelock_exit, |
301 | (void *)eopnotsupp, | | 303 | (void *)eopnotsupp, |
302 | procfs_vnodeopv_descs, | | 304 | procfs_vnodeopv_descs, |
303 | 0, | | 305 | 0, |
304 | { NULL, NULL }, | | 306 | { NULL, NULL }, |
305 | }; | | 307 | }; |
306 | | | 308 | |
307 | static int | | 309 | static int |
| | | 310 | procfs_listener_cb(kauth_cred_t cred, kauth_action_t action, void *cookie, |
| | | 311 | void *arg0, void *arg1, void *arg2, void *arg3) |
| | | 312 | { |
| | | 313 | struct proc *p; |
| | | 314 | struct pfsnode *pfs; |
| | | 315 | enum kauth_process_req req; |
| | | 316 | int result; |
| | | 317 | |
| | | 318 | result = KAUTH_RESULT_DEFER; |
| | | 319 | p = arg0; |
| | | 320 | pfs = arg1; |
| | | 321 | req = (enum kauth_process_req)(unsigned long)arg2; |
| | | 322 | |
| | | 323 | if (action != KAUTH_PROCESS_PROCFS) |
| | | 324 | return result; |
| | | 325 | |
| | | 326 | /* Privileged; let secmodel handle that. */ |
| | | 327 | if (req == KAUTH_REQ_PROCESS_PROCFS_CTL) |
| | | 328 | return result; |
| | | 329 | |
| | | 330 | switch (pfs->pfs_type) { |
| | | 331 | case PFSregs: |
| | | 332 | case PFSfpregs: |
| | | 333 | case PFSmem: |
| | | 334 | if (kauth_cred_getuid(cred) != kauth_cred_getuid(p->p_cred) || |
| | | 335 | ISSET(p->p_flag, PK_SUGID)) |
| | | 336 | break; |
| | | 337 | |
| | | 338 | /*FALLTHROUGH*/ |
| | | 339 | default: |
| | | 340 | result = KAUTH_RESULT_ALLOW; |
| | | 341 | break; |
| | | 342 | } |
| | | 343 | |
| | | 344 | return result; |
| | | 345 | } |
| | | 346 | |
| | | 347 | |
| | | 348 | static int |
308 | procfs_modcmd(modcmd_t cmd, void *arg) | | 349 | procfs_modcmd(modcmd_t cmd, void *arg) |
309 | { | | 350 | { |
310 | int error; | | 351 | int error; |
311 | | | 352 | |
312 | switch (cmd) { | | 353 | switch (cmd) { |
313 | case MODULE_CMD_INIT: | | 354 | case MODULE_CMD_INIT: |
314 | error = vfs_attach(&procfs_vfsops); | | 355 | error = vfs_attach(&procfs_vfsops); |
315 | if (error != 0) | | 356 | if (error != 0) |
316 | break; | | 357 | break; |
317 | sysctl_createv(&procfs_sysctl_log, 0, NULL, NULL, | | 358 | sysctl_createv(&procfs_sysctl_log, 0, NULL, NULL, |
318 | CTLFLAG_PERMANENT, | | 359 | CTLFLAG_PERMANENT, |
319 | CTLTYPE_NODE, "vfs", NULL, | | 360 | CTLTYPE_NODE, "vfs", NULL, |
320 | NULL, 0, NULL, 0, | | 361 | NULL, 0, NULL, 0, |
321 | CTL_VFS, CTL_EOL); | | 362 | CTL_VFS, CTL_EOL); |
322 | sysctl_createv(&procfs_sysctl_log, 0, NULL, NULL, | | 363 | sysctl_createv(&procfs_sysctl_log, 0, NULL, NULL, |
323 | CTLFLAG_PERMANENT, | | 364 | CTLFLAG_PERMANENT, |
324 | CTLTYPE_NODE, "procfs", | | 365 | CTLTYPE_NODE, "procfs", |
325 | SYSCTL_DESCR("Process file system"), | | 366 | SYSCTL_DESCR("Process file system"), |
326 | NULL, 0, NULL, 0, | | 367 | NULL, 0, NULL, 0, |
327 | CTL_VFS, 12, CTL_EOL); | | 368 | CTL_VFS, 12, CTL_EOL); |
328 | /* | | 369 | /* |
329 | * XXX the "12" above could be dynamic, thereby eliminating | | 370 | * XXX the "12" above could be dynamic, thereby eliminating |
330 | * one more instance of the "number to vfs" mapping problem, | | 371 | * one more instance of the "number to vfs" mapping problem, |
331 | * but "12" is the order as taken from sys/mount.h | | 372 | * but "12" is the order as taken from sys/mount.h |
332 | */ | | 373 | */ |
| | | 374 | |
| | | 375 | procfs_listener = kauth_listen_scope(KAUTH_SCOPE_PROCESS, |
| | | 376 | procfs_listener_cb, NULL); |
| | | 377 | |
333 | break; | | 378 | break; |
334 | case MODULE_CMD_FINI: | | 379 | case MODULE_CMD_FINI: |
335 | error = vfs_detach(&procfs_vfsops); | | 380 | error = vfs_detach(&procfs_vfsops); |
336 | if (error != 0) | | 381 | if (error != 0) |
337 | break; | | 382 | break; |
338 | sysctl_teardown(&procfs_sysctl_log); | | 383 | sysctl_teardown(&procfs_sysctl_log); |
| | | 384 | kauth_unlisten_scope(procfs_listener); |
339 | break; | | 385 | break; |
340 | default: | | 386 | default: |
341 | error = ENOTTY; | | 387 | error = ENOTTY; |
342 | break; | | 388 | break; |
343 | } | | 389 | } |
344 | | | 390 | |
345 | return (error); | | 391 | return (error); |
346 | } | | 392 | } |