xref: /NextBSD/sys/compat/cloudabi/cloudabi_fd.c (revision c21ffb8d6aca32c9584cfa072f309a5890a21aea)
1 /*-
2  * Copyright (c) 2015 Nuxi, https://nuxi.nl/
3  *
4  * Redistribution and use in source and binary forms, with or without
5  * modification, are permitted provided that the following conditions
6  * are met:
7  * 1. Redistributions of source code must retain the above copyright
8  *    notice, this list of conditions and the following disclaimer.
9  * 2. Redistributions in binary form must reproduce the above copyright
10  *    notice, this list of conditions and the following disclaimer in the
11  *    documentation and/or other materials provided with the distribution.
12  *
13  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
14  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
15  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
16  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
17  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
18  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
19  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
20  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
21  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
22  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
23  * SUCH DAMAGE.
24  */
25 
26 #include <sys/cdefs.h>
27 __FBSDID("$FreeBSD$");
28 
29 #include <sys/param.h>
30 #include <sys/capsicum.h>
31 #include <sys/filedesc.h>
32 #include <sys/proc.h>
33 #include <sys/mman.h>
34 #include <sys/socketvar.h>
35 #include <sys/syscallsubr.h>
36 #include <sys/sysproto.h>
37 #include <sys/systm.h>
38 #include <sys/unistd.h>
39 #include <sys/vnode.h>
40 
41 #include <compat/cloudabi/cloudabi_proto.h>
42 #include <compat/cloudabi/cloudabi_syscalldefs.h>
43 #include <compat/cloudabi/cloudabi_util.h>
44 
45 /* Translation between CloudABI and Capsicum rights. */
46 #define RIGHTS_MAPPINGS \
47 	MAPPING(CLOUDABI_RIGHT_FD_DATASYNC, CAP_FSYNC)			\
48 	MAPPING(CLOUDABI_RIGHT_FD_READ, CAP_READ)			\
49 	MAPPING(CLOUDABI_RIGHT_FD_SEEK, CAP_SEEK)			\
50 	MAPPING(CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS, CAP_FCNTL)		\
51 	MAPPING(CLOUDABI_RIGHT_FD_SYNC, CAP_FSYNC)			\
52 	MAPPING(CLOUDABI_RIGHT_FD_TELL, CAP_SEEK_TELL)			\
53 	MAPPING(CLOUDABI_RIGHT_FD_WRITE, CAP_WRITE)			\
54 	MAPPING(CLOUDABI_RIGHT_FILE_ADVISE)				\
55 	MAPPING(CLOUDABI_RIGHT_FILE_ALLOCATE, CAP_WRITE)		\
56 	MAPPING(CLOUDABI_RIGHT_FILE_CREATE_DIRECTORY, CAP_MKDIRAT)	\
57 	MAPPING(CLOUDABI_RIGHT_FILE_CREATE_FILE, CAP_CREATE)		\
58 	MAPPING(CLOUDABI_RIGHT_FILE_CREATE_FIFO, CAP_MKFIFOAT)		\
59 	MAPPING(CLOUDABI_RIGHT_FILE_LINK_SOURCE, CAP_LINKAT_SOURCE)	\
60 	MAPPING(CLOUDABI_RIGHT_FILE_LINK_TARGET, CAP_LINKAT_TARGET)	\
61 	MAPPING(CLOUDABI_RIGHT_FILE_OPEN, CAP_LOOKUP)			\
62 	MAPPING(CLOUDABI_RIGHT_FILE_READDIR, CAP_READ)			\
63 	MAPPING(CLOUDABI_RIGHT_FILE_READLINK, CAP_LOOKUP)		\
64 	MAPPING(CLOUDABI_RIGHT_FILE_RENAME_SOURCE, CAP_RENAMEAT_SOURCE)	\
65 	MAPPING(CLOUDABI_RIGHT_FILE_RENAME_TARGET, CAP_RENAMEAT_TARGET)	\
66 	MAPPING(CLOUDABI_RIGHT_FILE_STAT_FGET, CAP_FSTAT)		\
67 	MAPPING(CLOUDABI_RIGHT_FILE_STAT_FPUT_SIZE, CAP_FTRUNCATE)	\
68 	MAPPING(CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES, CAP_FUTIMES)	\
69 	MAPPING(CLOUDABI_RIGHT_FILE_STAT_GET, CAP_FSTATAT)		\
70 	MAPPING(CLOUDABI_RIGHT_FILE_STAT_PUT_TIMES, CAP_FUTIMESAT)	\
71 	MAPPING(CLOUDABI_RIGHT_FILE_SYMLINK, CAP_SYMLINKAT)		\
72 	MAPPING(CLOUDABI_RIGHT_FILE_UNLINK, CAP_UNLINKAT)		\
73 	MAPPING(CLOUDABI_RIGHT_MEM_MAP, CAP_MMAP)			\
74 	MAPPING(CLOUDABI_RIGHT_MEM_MAP_EXEC, CAP_MMAP_X)		\
75 	MAPPING(CLOUDABI_RIGHT_POLL_FD_READWRITE, CAP_EVENT)		\
76 	MAPPING(CLOUDABI_RIGHT_POLL_MODIFY, CAP_KQUEUE_CHANGE)		\
77 	MAPPING(CLOUDABI_RIGHT_POLL_PROC_TERMINATE, CAP_EVENT)		\
78 	MAPPING(CLOUDABI_RIGHT_POLL_WAIT, CAP_KQUEUE_EVENT)		\
79 	MAPPING(CLOUDABI_RIGHT_PROC_EXEC, CAP_FEXECVE)			\
80 	MAPPING(CLOUDABI_RIGHT_SOCK_ACCEPT, CAP_ACCEPT)			\
81 	MAPPING(CLOUDABI_RIGHT_SOCK_BIND_DIRECTORY, CAP_BINDAT)		\
82 	MAPPING(CLOUDABI_RIGHT_SOCK_BIND_SOCKET, CAP_BIND)		\
83 	MAPPING(CLOUDABI_RIGHT_SOCK_CONNECT_DIRECTORY, CAP_CONNECTAT)	\
84 	MAPPING(CLOUDABI_RIGHT_SOCK_CONNECT_SOCKET, CAP_CONNECT)	\
85 	MAPPING(CLOUDABI_RIGHT_SOCK_LISTEN, CAP_LISTEN)			\
86 	MAPPING(CLOUDABI_RIGHT_SOCK_SHUTDOWN, CAP_SHUTDOWN)		\
87 	MAPPING(CLOUDABI_RIGHT_SOCK_STAT_GET, CAP_GETPEERNAME,		\
88 	    CAP_GETSOCKNAME, CAP_GETSOCKOPT)
89 
90 int
cloudabi_sys_fd_close(struct thread * td,struct cloudabi_sys_fd_close_args * uap)91 cloudabi_sys_fd_close(struct thread *td, struct cloudabi_sys_fd_close_args *uap)
92 {
93 
94 	return (kern_close(td, uap->fd));
95 }
96 
97 int
cloudabi_sys_fd_create1(struct thread * td,struct cloudabi_sys_fd_create1_args * uap)98 cloudabi_sys_fd_create1(struct thread *td,
99     struct cloudabi_sys_fd_create1_args *uap)
100 {
101 	struct filecaps fcaps = {};
102 	struct socket_args socket_args = {
103 		.domain = AF_UNIX,
104 	};
105 
106 	switch (uap->type) {
107 	case CLOUDABI_FILETYPE_POLL:
108 		cap_rights_init(&fcaps.fc_rights, CAP_FSTAT, CAP_KQUEUE);
109 		return (kern_kqueue(td, 0, &fcaps));
110 	case CLOUDABI_FILETYPE_SHARED_MEMORY:
111 		cap_rights_init(&fcaps.fc_rights, CAP_FSTAT, CAP_FTRUNCATE,
112 		    CAP_MMAP_RWX);
113 		return (kern_shm_open(td, SHM_ANON, O_RDWR, 0, &fcaps));
114 	case CLOUDABI_FILETYPE_SOCKET_DGRAM:
115 		socket_args.type = SOCK_DGRAM;
116 		return (sys_socket(td, &socket_args));
117 	case CLOUDABI_FILETYPE_SOCKET_SEQPACKET:
118 		socket_args.type = SOCK_SEQPACKET;
119 		return (sys_socket(td, &socket_args));
120 	case CLOUDABI_FILETYPE_SOCKET_STREAM:
121 		socket_args.type = SOCK_STREAM;
122 		return (sys_socket(td, &socket_args));
123 	default:
124 		return (EINVAL);
125 	}
126 }
127 
128 int
cloudabi_sys_fd_create2(struct thread * td,struct cloudabi_sys_fd_create2_args * uap)129 cloudabi_sys_fd_create2(struct thread *td,
130     struct cloudabi_sys_fd_create2_args *uap)
131 {
132 	struct filecaps fcaps1 = {}, fcaps2 = {};
133 	int fds[2];
134 	int error;
135 
136 	switch (uap->type) {
137 	case CLOUDABI_FILETYPE_FIFO:
138 		/*
139 		 * CloudABI pipes are unidirectional. Restrict rights on
140 		 * the pipe to simulate this.
141 		 */
142 		cap_rights_init(&fcaps1.fc_rights, CAP_EVENT, CAP_FCNTL,
143 		    CAP_FSTAT, CAP_READ);
144 		fcaps1.fc_fcntls = CAP_FCNTL_SETFL;
145 		cap_rights_init(&fcaps2.fc_rights, CAP_EVENT, CAP_FCNTL,
146 		    CAP_FSTAT, CAP_WRITE);
147 		fcaps2.fc_fcntls = CAP_FCNTL_SETFL;
148 		error = kern_pipe(td, fds, 0, &fcaps1, &fcaps2);
149 		break;
150 	case CLOUDABI_FILETYPE_SOCKET_DGRAM:
151 		error = kern_socketpair(td, AF_UNIX, SOCK_DGRAM, 0, fds);
152 		break;
153 	case CLOUDABI_FILETYPE_SOCKET_SEQPACKET:
154 		error = kern_socketpair(td, AF_UNIX, SOCK_SEQPACKET, 0, fds);
155 		break;
156 	case CLOUDABI_FILETYPE_SOCKET_STREAM:
157 		error = kern_socketpair(td, AF_UNIX, SOCK_STREAM, 0, fds);
158 		break;
159 	default:
160 		return (EINVAL);
161 	}
162 
163 	if (error == 0) {
164 		td->td_retval[0] = fds[0];
165 		td->td_retval[1] = fds[1];
166 	}
167 	return (0);
168 }
169 
170 int
cloudabi_sys_fd_datasync(struct thread * td,struct cloudabi_sys_fd_datasync_args * uap)171 cloudabi_sys_fd_datasync(struct thread *td,
172     struct cloudabi_sys_fd_datasync_args *uap)
173 {
174 	struct fsync_args fsync_args = {
175 		.fd = uap->fd
176 	};
177 
178 	/* Call into fsync(), as FreeBSD lacks fdatasync(). */
179 	return (sys_fsync(td, &fsync_args));
180 }
181 
182 int
cloudabi_sys_fd_dup(struct thread * td,struct cloudabi_sys_fd_dup_args * uap)183 cloudabi_sys_fd_dup(struct thread *td, struct cloudabi_sys_fd_dup_args *uap)
184 {
185 
186 	return (kern_dup(td, FDDUP_NORMAL, 0, uap->from, 0));
187 }
188 
189 int
cloudabi_sys_fd_replace(struct thread * td,struct cloudabi_sys_fd_replace_args * uap)190 cloudabi_sys_fd_replace(struct thread *td,
191     struct cloudabi_sys_fd_replace_args *uap)
192 {
193 	int error;
194 
195 	/*
196 	 * CloudABI's equivalent to dup2(). CloudABI processes should
197 	 * not depend on hardcoded file descriptor layouts, but simply
198 	 * use the file descriptor numbers that are allocated by the
199 	 * kernel. Duplicating file descriptors to arbitrary numbers
200 	 * should not be done.
201 	 *
202 	 * Invoke kern_dup() with FDDUP_MUSTREPLACE, so that we return
203 	 * EBADF when duplicating to a nonexistent file descriptor. Also
204 	 * clear the return value, as this system call yields no return
205 	 * value.
206 	 */
207 	error = kern_dup(td, FDDUP_MUSTREPLACE, 0, uap->from, uap->to);
208 	td->td_retval[0] = 0;
209 	return (error);
210 }
211 
212 int
cloudabi_sys_fd_seek(struct thread * td,struct cloudabi_sys_fd_seek_args * uap)213 cloudabi_sys_fd_seek(struct thread *td, struct cloudabi_sys_fd_seek_args *uap)
214 {
215 	struct lseek_args lseek_args = {
216 		.fd	= uap->fd,
217 		.offset	= uap->offset
218 	};
219 
220 	switch (uap->whence) {
221 	case CLOUDABI_WHENCE_CUR:
222 		lseek_args.whence = SEEK_CUR;
223 		break;
224 	case CLOUDABI_WHENCE_END:
225 		lseek_args.whence = SEEK_END;
226 		break;
227 	case CLOUDABI_WHENCE_SET:
228 		lseek_args.whence = SEEK_SET;
229 		break;
230 	default:
231 		return (EINVAL);
232 	}
233 
234 	return (sys_lseek(td, &lseek_args));
235 }
236 
237 /* Converts a file descriptor to a CloudABI file descriptor type. */
238 cloudabi_filetype_t
cloudabi_convert_filetype(const struct file * fp)239 cloudabi_convert_filetype(const struct file *fp)
240 {
241 	struct socket *so;
242 	struct vnode *vp;
243 
244 	switch (fp->f_type) {
245 	case DTYPE_FIFO:
246 		return (CLOUDABI_FILETYPE_FIFO);
247 	case DTYPE_KQUEUE:
248 		return (CLOUDABI_FILETYPE_POLL);
249 	case DTYPE_PIPE:
250 		return (CLOUDABI_FILETYPE_FIFO);
251 	case DTYPE_PROCDESC:
252 		return (CLOUDABI_FILETYPE_PROCESS);
253 	case DTYPE_SHM:
254 		return (CLOUDABI_FILETYPE_SHARED_MEMORY);
255 	case DTYPE_SOCKET:
256 		so = fp->f_data;
257 		switch (so->so_type) {
258 		case SOCK_DGRAM:
259 			return (CLOUDABI_FILETYPE_SOCKET_DGRAM);
260 		case SOCK_SEQPACKET:
261 			return (CLOUDABI_FILETYPE_SOCKET_SEQPACKET);
262 		case SOCK_STREAM:
263 			return (CLOUDABI_FILETYPE_SOCKET_STREAM);
264 		default:
265 			return (CLOUDABI_FILETYPE_UNKNOWN);
266 		}
267 	case DTYPE_VNODE:
268 		vp = fp->f_vnode;
269 		switch (vp->v_type) {
270 		case VBLK:
271 			return (CLOUDABI_FILETYPE_BLOCK_DEVICE);
272 		case VCHR:
273 			return (CLOUDABI_FILETYPE_CHARACTER_DEVICE);
274 		case VDIR:
275 			return (CLOUDABI_FILETYPE_DIRECTORY);
276 		case VFIFO:
277 			return (CLOUDABI_FILETYPE_FIFO);
278 		case VLNK:
279 			return (CLOUDABI_FILETYPE_SYMBOLIC_LINK);
280 		case VREG:
281 			return (CLOUDABI_FILETYPE_REGULAR_FILE);
282 		case VSOCK:
283 			return (CLOUDABI_FILETYPE_SOCKET_STREAM);
284 		default:
285 			return (CLOUDABI_FILETYPE_UNKNOWN);
286 		}
287 	default:
288 		return (CLOUDABI_FILETYPE_UNKNOWN);
289 	}
290 }
291 
292 /* Removes rights that conflict with the file descriptor type. */
293 void
cloudabi_remove_conflicting_rights(cloudabi_filetype_t filetype,cloudabi_rights_t * base,cloudabi_rights_t * inheriting)294 cloudabi_remove_conflicting_rights(cloudabi_filetype_t filetype,
295     cloudabi_rights_t *base, cloudabi_rights_t *inheriting)
296 {
297 
298 	/*
299 	 * CloudABI has a small number of additional rights bits to
300 	 * disambiguate between multiple purposes. Remove the bits that
301 	 * don't apply to the type of the file descriptor.
302 	 *
303 	 * As file descriptor access modes (O_ACCMODE) has been fully
304 	 * replaced by rights bits, CloudABI distinguishes between
305 	 * rights that apply to the file descriptor itself (base) versus
306 	 * rights of new file descriptors derived from them
307 	 * (inheriting). The code below approximates the pair by
308 	 * decomposing depending on the file descriptor type.
309 	 *
310 	 * We need to be somewhat accurate about which actions can
311 	 * actually be performed on the file descriptor, as functions
312 	 * like fcntl(fd, F_GETFL) are emulated on top of this.
313 	 */
314 	switch (filetype) {
315 	case CLOUDABI_FILETYPE_DIRECTORY:
316 		*base &= CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
317 		    CLOUDABI_RIGHT_FD_SYNC | CLOUDABI_RIGHT_FILE_ADVISE |
318 		    CLOUDABI_RIGHT_FILE_CREATE_DIRECTORY |
319 		    CLOUDABI_RIGHT_FILE_CREATE_FILE |
320 		    CLOUDABI_RIGHT_FILE_CREATE_FIFO |
321 		    CLOUDABI_RIGHT_FILE_LINK_SOURCE |
322 		    CLOUDABI_RIGHT_FILE_LINK_TARGET |
323 		    CLOUDABI_RIGHT_FILE_OPEN |
324 		    CLOUDABI_RIGHT_FILE_READDIR |
325 		    CLOUDABI_RIGHT_FILE_READLINK |
326 		    CLOUDABI_RIGHT_FILE_RENAME_SOURCE |
327 		    CLOUDABI_RIGHT_FILE_RENAME_TARGET |
328 		    CLOUDABI_RIGHT_FILE_STAT_FGET |
329 		    CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES |
330 		    CLOUDABI_RIGHT_FILE_STAT_GET |
331 		    CLOUDABI_RIGHT_FILE_STAT_PUT_TIMES |
332 		    CLOUDABI_RIGHT_FILE_SYMLINK |
333 		    CLOUDABI_RIGHT_FILE_UNLINK |
334 		    CLOUDABI_RIGHT_POLL_FD_READWRITE |
335 		    CLOUDABI_RIGHT_SOCK_BIND_DIRECTORY |
336 		    CLOUDABI_RIGHT_SOCK_CONNECT_DIRECTORY;
337 		*inheriting &= CLOUDABI_RIGHT_FD_DATASYNC |
338 		    CLOUDABI_RIGHT_FD_READ |
339 		    CLOUDABI_RIGHT_FD_SEEK |
340 		    CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
341 		    CLOUDABI_RIGHT_FD_SYNC |
342 		    CLOUDABI_RIGHT_FD_TELL |
343 		    CLOUDABI_RIGHT_FD_WRITE |
344 		    CLOUDABI_RIGHT_FILE_ADVISE |
345 		    CLOUDABI_RIGHT_FILE_ALLOCATE |
346 		    CLOUDABI_RIGHT_FILE_CREATE_DIRECTORY |
347 		    CLOUDABI_RIGHT_FILE_CREATE_FILE |
348 		    CLOUDABI_RIGHT_FILE_CREATE_FIFO |
349 		    CLOUDABI_RIGHT_FILE_LINK_SOURCE |
350 		    CLOUDABI_RIGHT_FILE_LINK_TARGET |
351 		    CLOUDABI_RIGHT_FILE_OPEN |
352 		    CLOUDABI_RIGHT_FILE_READDIR |
353 		    CLOUDABI_RIGHT_FILE_READLINK |
354 		    CLOUDABI_RIGHT_FILE_RENAME_SOURCE |
355 		    CLOUDABI_RIGHT_FILE_RENAME_TARGET |
356 		    CLOUDABI_RIGHT_FILE_STAT_FGET |
357 		    CLOUDABI_RIGHT_FILE_STAT_FPUT_SIZE |
358 		    CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES |
359 		    CLOUDABI_RIGHT_FILE_STAT_GET |
360 		    CLOUDABI_RIGHT_FILE_STAT_PUT_TIMES |
361 		    CLOUDABI_RIGHT_FILE_SYMLINK |
362 		    CLOUDABI_RIGHT_FILE_UNLINK |
363 		    CLOUDABI_RIGHT_MEM_MAP |
364 		    CLOUDABI_RIGHT_MEM_MAP_EXEC |
365 		    CLOUDABI_RIGHT_POLL_FD_READWRITE |
366 		    CLOUDABI_RIGHT_PROC_EXEC |
367 		    CLOUDABI_RIGHT_SOCK_BIND_DIRECTORY |
368 		    CLOUDABI_RIGHT_SOCK_CONNECT_DIRECTORY;
369 		break;
370 	case CLOUDABI_FILETYPE_FIFO:
371 		*base &= CLOUDABI_RIGHT_FD_READ |
372 		    CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
373 		    CLOUDABI_RIGHT_FD_WRITE |
374 		    CLOUDABI_RIGHT_FILE_STAT_FGET |
375 		    CLOUDABI_RIGHT_POLL_FD_READWRITE;
376 		*inheriting = 0;
377 		break;
378 	case CLOUDABI_FILETYPE_POLL:
379 		*base &= ~CLOUDABI_RIGHT_FILE_ADVISE;
380 		*inheriting = 0;
381 		break;
382 	case CLOUDABI_FILETYPE_PROCESS:
383 		*base &= ~(CLOUDABI_RIGHT_FILE_ADVISE |
384 		    CLOUDABI_RIGHT_POLL_FD_READWRITE);
385 		*inheriting = 0;
386 		break;
387 	case CLOUDABI_FILETYPE_REGULAR_FILE:
388 		*base &= CLOUDABI_RIGHT_FD_DATASYNC |
389 		    CLOUDABI_RIGHT_FD_READ |
390 		    CLOUDABI_RIGHT_FD_SEEK |
391 		    CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
392 		    CLOUDABI_RIGHT_FD_SYNC |
393 		    CLOUDABI_RIGHT_FD_TELL |
394 		    CLOUDABI_RIGHT_FD_WRITE |
395 		    CLOUDABI_RIGHT_FILE_ADVISE |
396 		    CLOUDABI_RIGHT_FILE_ALLOCATE |
397 		    CLOUDABI_RIGHT_FILE_STAT_FGET |
398 		    CLOUDABI_RIGHT_FILE_STAT_FPUT_SIZE |
399 		    CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES |
400 		    CLOUDABI_RIGHT_MEM_MAP |
401 		    CLOUDABI_RIGHT_MEM_MAP_EXEC |
402 		    CLOUDABI_RIGHT_POLL_FD_READWRITE |
403 		    CLOUDABI_RIGHT_PROC_EXEC;
404 		*inheriting = 0;
405 		break;
406 	case CLOUDABI_FILETYPE_SHARED_MEMORY:
407 		*base &= ~(CLOUDABI_RIGHT_FD_SEEK |
408 		    CLOUDABI_RIGHT_FD_TELL |
409 		    CLOUDABI_RIGHT_FILE_ADVISE |
410 		    CLOUDABI_RIGHT_FILE_ALLOCATE |
411 		    CLOUDABI_RIGHT_FILE_READDIR);
412 		*inheriting = 0;
413 		break;
414 	case CLOUDABI_FILETYPE_SOCKET_DGRAM:
415 	case CLOUDABI_FILETYPE_SOCKET_SEQPACKET:
416 	case CLOUDABI_FILETYPE_SOCKET_STREAM:
417 		*base &= CLOUDABI_RIGHT_FD_READ |
418 		    CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
419 		    CLOUDABI_RIGHT_FD_WRITE |
420 		    CLOUDABI_RIGHT_FILE_STAT_FGET |
421 		    CLOUDABI_RIGHT_POLL_FD_READWRITE |
422 		    CLOUDABI_RIGHT_SOCK_ACCEPT |
423 		    CLOUDABI_RIGHT_SOCK_BIND_SOCKET |
424 		    CLOUDABI_RIGHT_SOCK_CONNECT_SOCKET |
425 		    CLOUDABI_RIGHT_SOCK_LISTEN |
426 		    CLOUDABI_RIGHT_SOCK_SHUTDOWN |
427 		    CLOUDABI_RIGHT_SOCK_STAT_GET;
428 		break;
429 	default:
430 		*inheriting = 0;
431 		break;
432 	}
433 }
434 
435 /* Converts FreeBSD's Capsicum rights to CloudABI's set of rights. */
436 static void
convert_capabilities(const cap_rights_t * capabilities,cloudabi_filetype_t filetype,cloudabi_rights_t * base,cloudabi_rights_t * inheriting)437 convert_capabilities(const cap_rights_t *capabilities,
438     cloudabi_filetype_t filetype, cloudabi_rights_t *base,
439     cloudabi_rights_t *inheriting)
440 {
441 	cloudabi_rights_t rights;
442 
443 	/* Convert FreeBSD bits to CloudABI bits. */
444 	rights = 0;
445 #define MAPPING(cloudabi, ...) do {				\
446 	if (cap_rights_is_set(capabilities, ##__VA_ARGS__))	\
447 		rights |= (cloudabi);				\
448 } while (0);
449 	RIGHTS_MAPPINGS
450 #undef MAPPING
451 
452 	*base = rights;
453 	*inheriting = rights;
454 	cloudabi_remove_conflicting_rights(filetype, base, inheriting);
455 }
456 
457 int
cloudabi_sys_fd_stat_get(struct thread * td,struct cloudabi_sys_fd_stat_get_args * uap)458 cloudabi_sys_fd_stat_get(struct thread *td,
459     struct cloudabi_sys_fd_stat_get_args *uap)
460 {
461 	cloudabi_fdstat_t fsb = {};
462 	struct filedesc *fdp;
463 	struct file *fp;
464 	seq_t seq;
465 	cap_rights_t rights;
466 	int error, oflags;
467 	bool modified;
468 
469 	/* Obtain file descriptor properties. */
470 	fdp = td->td_proc->p_fd;
471 	do {
472 		error = fget_unlocked(fdp, uap->fd, cap_rights_init(&rights),
473 		    &fp, &seq);
474 		if (error != 0)
475 			return (error);
476 		if (fp->f_ops == &badfileops) {
477 			fdrop(fp, td);
478 			return (EBADF);
479 		}
480 
481 		rights = *cap_rights(fdp, uap->fd);
482 		oflags = OFLAGS(fp->f_flag);
483 		fsb.fs_filetype = cloudabi_convert_filetype(fp);
484 
485 		modified = fd_modified(fdp, uap->fd, seq);
486 		fdrop(fp, td);
487 	} while (modified);
488 
489 	/* Convert file descriptor flags. */
490 	if (oflags & O_APPEND)
491 		fsb.fs_flags |= CLOUDABI_FDFLAG_APPEND;
492 	if (oflags & O_NONBLOCK)
493 		fsb.fs_flags |= CLOUDABI_FDFLAG_NONBLOCK;
494 	if (oflags & O_SYNC)
495 		fsb.fs_flags |= CLOUDABI_FDFLAG_SYNC;
496 
497 	/* Convert capabilities to CloudABI rights. */
498 	convert_capabilities(&rights, fsb.fs_filetype,
499 	    &fsb.fs_rights_base, &fsb.fs_rights_inheriting);
500 	return (copyout(&fsb, (void *)uap->buf, sizeof(fsb)));
501 }
502 
503 /* Converts CloudABI rights to a set of Capsicum capabilities. */
504 int
cloudabi_convert_rights(cloudabi_rights_t in,cap_rights_t * out)505 cloudabi_convert_rights(cloudabi_rights_t in, cap_rights_t *out)
506 {
507 
508 	cap_rights_init(out);
509 #define MAPPING(cloudabi, ...) do {			\
510 	if (in & (cloudabi)) {				\
511 		cap_rights_set(out, ##__VA_ARGS__);	\
512 		in &= ~(cloudabi);			\
513 	}						\
514 } while (0);
515 	RIGHTS_MAPPINGS
516 #undef MAPPING
517 	if (in != 0)
518 		return (ENOTCAPABLE);
519 	return (0);
520 }
521 
522 int
cloudabi_sys_fd_stat_put(struct thread * td,struct cloudabi_sys_fd_stat_put_args * uap)523 cloudabi_sys_fd_stat_put(struct thread *td,
524     struct cloudabi_sys_fd_stat_put_args *uap)
525 {
526 	cloudabi_fdstat_t fsb;
527 	cap_rights_t rights;
528 	int error, oflags;
529 
530 	error = copyin(uap->buf, &fsb, sizeof(fsb));
531 	if (error != 0)
532 		return (error);
533 
534 	if (uap->flags == CLOUDABI_FDSTAT_FLAGS) {
535 		/* Convert flags. */
536 		oflags = 0;
537 		if (fsb.fs_flags & CLOUDABI_FDFLAG_APPEND)
538 			oflags |= O_APPEND;
539 		if (fsb.fs_flags & CLOUDABI_FDFLAG_NONBLOCK)
540 			oflags |= O_NONBLOCK;
541 		if (fsb.fs_flags & (CLOUDABI_FDFLAG_SYNC |
542 		    CLOUDABI_FDFLAG_DSYNC | CLOUDABI_FDFLAG_RSYNC))
543 			oflags |= O_SYNC;
544 		return (kern_fcntl(td, uap->fd, F_SETFL, oflags));
545 	} else if (uap->flags == CLOUDABI_FDSTAT_RIGHTS) {
546 		/* Convert rights. */
547 		error = cloudabi_convert_rights(
548 		    fsb.fs_rights_base | fsb.fs_rights_inheriting, &rights);
549 		if (error != 0)
550 			return (error);
551 		return (kern_cap_rights_limit(td, uap->fd, &rights));
552 	}
553 	return (EINVAL);
554 }
555 
556 int
cloudabi_sys_fd_sync(struct thread * td,struct cloudabi_sys_fd_sync_args * uap)557 cloudabi_sys_fd_sync(struct thread *td, struct cloudabi_sys_fd_sync_args *uap)
558 {
559 	struct fsync_args fsync_args = {
560 		.fd = uap->fd
561 	};
562 
563 	return (sys_fsync(td, &fsync_args));
564 }
565