1 /*-
2 * Copyright (c) 2015 Nuxi, https://nuxi.nl/
3 *
4 * Redistribution and use in source and binary forms, with or without
5 * modification, are permitted provided that the following conditions
6 * are met:
7 * 1. Redistributions of source code must retain the above copyright
8 * notice, this list of conditions and the following disclaimer.
9 * 2. Redistributions in binary form must reproduce the above copyright
10 * notice, this list of conditions and the following disclaimer in the
11 * documentation and/or other materials provided with the distribution.
12 *
13 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
14 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
15 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
16 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
17 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
18 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
19 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
20 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
21 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
22 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
23 * SUCH DAMAGE.
24 */
25
26 #include <sys/cdefs.h>
27 #include <sys/param.h>
28 #include <sys/capsicum.h>
29 #include <sys/fcntl.h>
30 #include <sys/filedesc.h>
31 #include <sys/proc.h>
32 #include <sys/mman.h>
33 #include <sys/socketvar.h>
34 #include <sys/syscallsubr.h>
35 #include <sys/sysproto.h>
36 #include <sys/systm.h>
37 #include <sys/unistd.h>
38 #include <sys/vnode.h>
39
40 #include <contrib/cloudabi/cloudabi_types_common.h>
41
42 #include <compat/cloudabi/cloudabi_proto.h>
43 #include <compat/cloudabi/cloudabi_util.h>
44
45 /* Translation between CloudABI and Capsicum rights. */
46 #define RIGHTS_MAPPINGS \
47 MAPPING(CLOUDABI_RIGHT_FD_DATASYNC, CAP_FSYNC) \
48 MAPPING(CLOUDABI_RIGHT_FD_READ, CAP_READ) \
49 MAPPING(CLOUDABI_RIGHT_FD_SEEK, CAP_SEEK) \
50 MAPPING(CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS, CAP_FCNTL) \
51 MAPPING(CLOUDABI_RIGHT_FD_SYNC, CAP_FSYNC) \
52 MAPPING(CLOUDABI_RIGHT_FD_TELL, CAP_SEEK_TELL) \
53 MAPPING(CLOUDABI_RIGHT_FD_WRITE, CAP_WRITE) \
54 MAPPING(CLOUDABI_RIGHT_FILE_ADVISE) \
55 MAPPING(CLOUDABI_RIGHT_FILE_ALLOCATE, CAP_WRITE) \
56 MAPPING(CLOUDABI_RIGHT_FILE_CREATE_DIRECTORY, CAP_MKDIRAT) \
57 MAPPING(CLOUDABI_RIGHT_FILE_CREATE_FILE, CAP_CREATE) \
58 MAPPING(CLOUDABI_RIGHT_FILE_LINK_SOURCE, CAP_LINKAT_SOURCE) \
59 MAPPING(CLOUDABI_RIGHT_FILE_LINK_TARGET, CAP_LINKAT_TARGET) \
60 MAPPING(CLOUDABI_RIGHT_FILE_OPEN, CAP_LOOKUP) \
61 MAPPING(CLOUDABI_RIGHT_FILE_READDIR, CAP_READ) \
62 MAPPING(CLOUDABI_RIGHT_FILE_READLINK, CAP_LOOKUP) \
63 MAPPING(CLOUDABI_RIGHT_FILE_RENAME_SOURCE, CAP_RENAMEAT_SOURCE) \
64 MAPPING(CLOUDABI_RIGHT_FILE_RENAME_TARGET, CAP_RENAMEAT_TARGET) \
65 MAPPING(CLOUDABI_RIGHT_FILE_STAT_FGET, CAP_FSTAT) \
66 MAPPING(CLOUDABI_RIGHT_FILE_STAT_FPUT_SIZE, CAP_FTRUNCATE) \
67 MAPPING(CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES, CAP_FUTIMES) \
68 MAPPING(CLOUDABI_RIGHT_FILE_STAT_GET, CAP_FSTATAT) \
69 MAPPING(CLOUDABI_RIGHT_FILE_STAT_PUT_TIMES, CAP_FUTIMESAT) \
70 MAPPING(CLOUDABI_RIGHT_FILE_SYMLINK, CAP_SYMLINKAT) \
71 MAPPING(CLOUDABI_RIGHT_FILE_UNLINK, CAP_UNLINKAT) \
72 MAPPING(CLOUDABI_RIGHT_MEM_MAP, CAP_MMAP) \
73 MAPPING(CLOUDABI_RIGHT_MEM_MAP_EXEC, CAP_MMAP_X) \
74 MAPPING(CLOUDABI_RIGHT_POLL_FD_READWRITE, CAP_EVENT) \
75 MAPPING(CLOUDABI_RIGHT_POLL_PROC_TERMINATE, CAP_EVENT) \
76 MAPPING(CLOUDABI_RIGHT_PROC_EXEC, CAP_FEXECVE) \
77 MAPPING(CLOUDABI_RIGHT_SOCK_SHUTDOWN, CAP_SHUTDOWN) \
78
79 int
cloudabi_sys_fd_close(struct thread * td,struct cloudabi_sys_fd_close_args * uap)80 cloudabi_sys_fd_close(struct thread *td, struct cloudabi_sys_fd_close_args *uap)
81 {
82
83 return (kern_close(td, uap->fd));
84 }
85
86 int
cloudabi_sys_fd_create1(struct thread * td,struct cloudabi_sys_fd_create1_args * uap)87 cloudabi_sys_fd_create1(struct thread *td,
88 struct cloudabi_sys_fd_create1_args *uap)
89 {
90 struct filecaps fcaps = {};
91
92 switch (uap->type) {
93 case CLOUDABI_FILETYPE_SHARED_MEMORY:
94 cap_rights_init(&fcaps.fc_rights, CAP_FSTAT, CAP_FTRUNCATE,
95 CAP_MMAP_RWX);
96 return (kern_shm_open(td, SHM_ANON, O_RDWR | O_CLOEXEC, 0,
97 &fcaps));
98 default:
99 return (EINVAL);
100 }
101 }
102
103 int
cloudabi_sys_fd_create2(struct thread * td,struct cloudabi_sys_fd_create2_args * uap)104 cloudabi_sys_fd_create2(struct thread *td,
105 struct cloudabi_sys_fd_create2_args *uap)
106 {
107 int fds[2];
108 int error, type;
109
110 switch (uap->type) {
111 case CLOUDABI_FILETYPE_SOCKET_DGRAM:
112 type = SOCK_DGRAM;
113 break;
114 case CLOUDABI_FILETYPE_SOCKET_STREAM:
115 type = SOCK_STREAM;
116 break;
117 default:
118 return (EINVAL);
119 }
120
121 error = kern_socketpair(td, AF_UNIX, type, 0, fds);
122 if (error == 0) {
123 td->td_retval[0] = fds[0];
124 td->td_retval[1] = fds[1];
125 }
126 return (0);
127 }
128
129 int
cloudabi_sys_fd_datasync(struct thread * td,struct cloudabi_sys_fd_datasync_args * uap)130 cloudabi_sys_fd_datasync(struct thread *td,
131 struct cloudabi_sys_fd_datasync_args *uap)
132 {
133
134 return (kern_fsync(td, uap->fd, false));
135 }
136
137 int
cloudabi_sys_fd_dup(struct thread * td,struct cloudabi_sys_fd_dup_args * uap)138 cloudabi_sys_fd_dup(struct thread *td, struct cloudabi_sys_fd_dup_args *uap)
139 {
140
141 return (kern_dup(td, FDDUP_NORMAL, 0, uap->from, 0));
142 }
143
144 int
cloudabi_sys_fd_replace(struct thread * td,struct cloudabi_sys_fd_replace_args * uap)145 cloudabi_sys_fd_replace(struct thread *td,
146 struct cloudabi_sys_fd_replace_args *uap)
147 {
148 int error;
149
150 /*
151 * CloudABI's equivalent to dup2(). CloudABI processes should
152 * not depend on hardcoded file descriptor layouts, but simply
153 * use the file descriptor numbers that are allocated by the
154 * kernel. Duplicating file descriptors to arbitrary numbers
155 * should not be done.
156 *
157 * Invoke kern_dup() with FDDUP_MUSTREPLACE, so that we return
158 * EBADF when duplicating to a nonexistent file descriptor. Also
159 * clear the return value, as this system call yields no return
160 * value.
161 */
162 error = kern_dup(td, FDDUP_MUSTREPLACE, 0, uap->from, uap->to);
163 td->td_retval[0] = 0;
164 return (error);
165 }
166
167 int
cloudabi_sys_fd_seek(struct thread * td,struct cloudabi_sys_fd_seek_args * uap)168 cloudabi_sys_fd_seek(struct thread *td, struct cloudabi_sys_fd_seek_args *uap)
169 {
170 int whence;
171
172 switch (uap->whence) {
173 case CLOUDABI_WHENCE_CUR:
174 whence = SEEK_CUR;
175 break;
176 case CLOUDABI_WHENCE_END:
177 whence = SEEK_END;
178 break;
179 case CLOUDABI_WHENCE_SET:
180 whence = SEEK_SET;
181 break;
182 default:
183 return (EINVAL);
184 }
185
186 return (kern_lseek(td, uap->fd, uap->offset, whence));
187 }
188
189 /* Converts a file descriptor to a CloudABI file descriptor type. */
190 cloudabi_filetype_t
cloudabi_convert_filetype(const struct file * fp)191 cloudabi_convert_filetype(const struct file *fp)
192 {
193 struct socket *so;
194 struct vnode *vp;
195
196 switch (fp->f_type) {
197 case DTYPE_FIFO:
198 return (CLOUDABI_FILETYPE_SOCKET_STREAM);
199 case DTYPE_PIPE:
200 return (CLOUDABI_FILETYPE_SOCKET_STREAM);
201 case DTYPE_PROCDESC:
202 return (CLOUDABI_FILETYPE_PROCESS);
203 case DTYPE_SHM:
204 return (CLOUDABI_FILETYPE_SHARED_MEMORY);
205 case DTYPE_SOCKET:
206 so = fp->f_data;
207 switch (so->so_type) {
208 case SOCK_DGRAM:
209 return (CLOUDABI_FILETYPE_SOCKET_DGRAM);
210 case SOCK_STREAM:
211 return (CLOUDABI_FILETYPE_SOCKET_STREAM);
212 default:
213 return (CLOUDABI_FILETYPE_UNKNOWN);
214 }
215 case DTYPE_VNODE:
216 vp = fp->f_vnode;
217 switch (vp->v_type) {
218 case VBLK:
219 return (CLOUDABI_FILETYPE_BLOCK_DEVICE);
220 case VCHR:
221 return (CLOUDABI_FILETYPE_CHARACTER_DEVICE);
222 case VDIR:
223 return (CLOUDABI_FILETYPE_DIRECTORY);
224 case VFIFO:
225 return (CLOUDABI_FILETYPE_SOCKET_STREAM);
226 case VLNK:
227 return (CLOUDABI_FILETYPE_SYMBOLIC_LINK);
228 case VREG:
229 return (CLOUDABI_FILETYPE_REGULAR_FILE);
230 case VSOCK:
231 return (CLOUDABI_FILETYPE_SOCKET_STREAM);
232 default:
233 return (CLOUDABI_FILETYPE_UNKNOWN);
234 }
235 default:
236 return (CLOUDABI_FILETYPE_UNKNOWN);
237 }
238 }
239
240 /* Removes rights that conflict with the file descriptor type. */
241 void
cloudabi_remove_conflicting_rights(cloudabi_filetype_t filetype,cloudabi_rights_t * base,cloudabi_rights_t * inheriting)242 cloudabi_remove_conflicting_rights(cloudabi_filetype_t filetype,
243 cloudabi_rights_t *base, cloudabi_rights_t *inheriting)
244 {
245
246 /*
247 * CloudABI has a small number of additional rights bits to
248 * disambiguate between multiple purposes. Remove the bits that
249 * don't apply to the type of the file descriptor.
250 *
251 * As file descriptor access modes (O_ACCMODE) has been fully
252 * replaced by rights bits, CloudABI distinguishes between
253 * rights that apply to the file descriptor itself (base) versus
254 * rights of new file descriptors derived from them
255 * (inheriting). The code below approximates the pair by
256 * decomposing depending on the file descriptor type.
257 *
258 * We need to be somewhat accurate about which actions can
259 * actually be performed on the file descriptor, as functions
260 * like fcntl(fd, F_GETFL) are emulated on top of this.
261 */
262 switch (filetype) {
263 case CLOUDABI_FILETYPE_DIRECTORY:
264 *base &= CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
265 CLOUDABI_RIGHT_FD_SYNC | CLOUDABI_RIGHT_FILE_ADVISE |
266 CLOUDABI_RIGHT_FILE_CREATE_DIRECTORY |
267 CLOUDABI_RIGHT_FILE_CREATE_FILE |
268 CLOUDABI_RIGHT_FILE_LINK_SOURCE |
269 CLOUDABI_RIGHT_FILE_LINK_TARGET |
270 CLOUDABI_RIGHT_FILE_OPEN |
271 CLOUDABI_RIGHT_FILE_READDIR |
272 CLOUDABI_RIGHT_FILE_READLINK |
273 CLOUDABI_RIGHT_FILE_RENAME_SOURCE |
274 CLOUDABI_RIGHT_FILE_RENAME_TARGET |
275 CLOUDABI_RIGHT_FILE_STAT_FGET |
276 CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES |
277 CLOUDABI_RIGHT_FILE_STAT_GET |
278 CLOUDABI_RIGHT_FILE_STAT_PUT_TIMES |
279 CLOUDABI_RIGHT_FILE_SYMLINK |
280 CLOUDABI_RIGHT_FILE_UNLINK |
281 CLOUDABI_RIGHT_POLL_FD_READWRITE;
282 *inheriting &= CLOUDABI_RIGHT_FD_DATASYNC |
283 CLOUDABI_RIGHT_FD_READ |
284 CLOUDABI_RIGHT_FD_SEEK |
285 CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
286 CLOUDABI_RIGHT_FD_SYNC |
287 CLOUDABI_RIGHT_FD_TELL |
288 CLOUDABI_RIGHT_FD_WRITE |
289 CLOUDABI_RIGHT_FILE_ADVISE |
290 CLOUDABI_RIGHT_FILE_ALLOCATE |
291 CLOUDABI_RIGHT_FILE_CREATE_DIRECTORY |
292 CLOUDABI_RIGHT_FILE_CREATE_FILE |
293 CLOUDABI_RIGHT_FILE_LINK_SOURCE |
294 CLOUDABI_RIGHT_FILE_LINK_TARGET |
295 CLOUDABI_RIGHT_FILE_OPEN |
296 CLOUDABI_RIGHT_FILE_READDIR |
297 CLOUDABI_RIGHT_FILE_READLINK |
298 CLOUDABI_RIGHT_FILE_RENAME_SOURCE |
299 CLOUDABI_RIGHT_FILE_RENAME_TARGET |
300 CLOUDABI_RIGHT_FILE_STAT_FGET |
301 CLOUDABI_RIGHT_FILE_STAT_FPUT_SIZE |
302 CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES |
303 CLOUDABI_RIGHT_FILE_STAT_GET |
304 CLOUDABI_RIGHT_FILE_STAT_PUT_TIMES |
305 CLOUDABI_RIGHT_FILE_SYMLINK |
306 CLOUDABI_RIGHT_FILE_UNLINK |
307 CLOUDABI_RIGHT_MEM_MAP |
308 CLOUDABI_RIGHT_MEM_MAP_EXEC |
309 CLOUDABI_RIGHT_POLL_FD_READWRITE |
310 CLOUDABI_RIGHT_PROC_EXEC;
311 break;
312 case CLOUDABI_FILETYPE_PROCESS:
313 *base &= ~(CLOUDABI_RIGHT_FILE_ADVISE |
314 CLOUDABI_RIGHT_POLL_FD_READWRITE);
315 *inheriting = 0;
316 break;
317 case CLOUDABI_FILETYPE_REGULAR_FILE:
318 *base &= CLOUDABI_RIGHT_FD_DATASYNC |
319 CLOUDABI_RIGHT_FD_READ |
320 CLOUDABI_RIGHT_FD_SEEK |
321 CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
322 CLOUDABI_RIGHT_FD_SYNC |
323 CLOUDABI_RIGHT_FD_TELL |
324 CLOUDABI_RIGHT_FD_WRITE |
325 CLOUDABI_RIGHT_FILE_ADVISE |
326 CLOUDABI_RIGHT_FILE_ALLOCATE |
327 CLOUDABI_RIGHT_FILE_STAT_FGET |
328 CLOUDABI_RIGHT_FILE_STAT_FPUT_SIZE |
329 CLOUDABI_RIGHT_FILE_STAT_FPUT_TIMES |
330 CLOUDABI_RIGHT_MEM_MAP |
331 CLOUDABI_RIGHT_MEM_MAP_EXEC |
332 CLOUDABI_RIGHT_POLL_FD_READWRITE |
333 CLOUDABI_RIGHT_PROC_EXEC;
334 *inheriting = 0;
335 break;
336 case CLOUDABI_FILETYPE_SHARED_MEMORY:
337 *base &= ~(CLOUDABI_RIGHT_FD_SEEK |
338 CLOUDABI_RIGHT_FD_TELL |
339 CLOUDABI_RIGHT_FILE_ADVISE |
340 CLOUDABI_RIGHT_FILE_ALLOCATE |
341 CLOUDABI_RIGHT_FILE_READDIR);
342 *inheriting = 0;
343 break;
344 case CLOUDABI_FILETYPE_SOCKET_DGRAM:
345 case CLOUDABI_FILETYPE_SOCKET_STREAM:
346 *base &= CLOUDABI_RIGHT_FD_READ |
347 CLOUDABI_RIGHT_FD_STAT_PUT_FLAGS |
348 CLOUDABI_RIGHT_FD_WRITE |
349 CLOUDABI_RIGHT_FILE_STAT_FGET |
350 CLOUDABI_RIGHT_POLL_FD_READWRITE |
351 CLOUDABI_RIGHT_SOCK_SHUTDOWN;
352 break;
353 default:
354 *inheriting = 0;
355 break;
356 }
357 }
358
359 /* Converts FreeBSD's Capsicum rights to CloudABI's set of rights. */
360 static void
convert_capabilities(const cap_rights_t * capabilities,cloudabi_filetype_t filetype,cloudabi_rights_t * base,cloudabi_rights_t * inheriting)361 convert_capabilities(const cap_rights_t *capabilities,
362 cloudabi_filetype_t filetype, cloudabi_rights_t *base,
363 cloudabi_rights_t *inheriting)
364 {
365 cloudabi_rights_t rights;
366
367 /* Convert FreeBSD bits to CloudABI bits. */
368 rights = 0;
369 #define MAPPING(cloudabi, ...) do { \
370 if (cap_rights_is_set(capabilities, ##__VA_ARGS__)) \
371 rights |= (cloudabi); \
372 } while (0);
373 RIGHTS_MAPPINGS
374 #undef MAPPING
375
376 *base = rights;
377 *inheriting = rights;
378 cloudabi_remove_conflicting_rights(filetype, base, inheriting);
379 }
380
381 int
cloudabi_sys_fd_stat_get(struct thread * td,struct cloudabi_sys_fd_stat_get_args * uap)382 cloudabi_sys_fd_stat_get(struct thread *td,
383 struct cloudabi_sys_fd_stat_get_args *uap)
384 {
385 cloudabi_fdstat_t fsb = {0};
386 struct file *fp;
387 cap_rights_t rights;
388 struct filecaps fcaps;
389 int error, oflags;
390
391 /* Obtain file descriptor properties. */
392 error = fget_cap(td, uap->fd, cap_rights_init(&rights), &fp,
393 &fcaps);
394 if (error != 0)
395 return (error);
396 oflags = OFLAGS(fp->f_flag);
397 fsb.fs_filetype = cloudabi_convert_filetype(fp);
398 fdrop(fp, td);
399
400 /* Convert file descriptor flags. */
401 if (oflags & O_APPEND)
402 fsb.fs_flags |= CLOUDABI_FDFLAG_APPEND;
403 if (oflags & O_NONBLOCK)
404 fsb.fs_flags |= CLOUDABI_FDFLAG_NONBLOCK;
405 if (oflags & O_SYNC)
406 fsb.fs_flags |= CLOUDABI_FDFLAG_SYNC;
407
408 /* Convert capabilities to CloudABI rights. */
409 convert_capabilities(&fcaps.fc_rights, fsb.fs_filetype,
410 &fsb.fs_rights_base, &fsb.fs_rights_inheriting);
411 filecaps_free(&fcaps);
412 return (copyout(&fsb, (void *)uap->buf, sizeof(fsb)));
413 }
414
415 /* Converts CloudABI rights to a set of Capsicum capabilities. */
416 int
cloudabi_convert_rights(cloudabi_rights_t in,cap_rights_t * out)417 cloudabi_convert_rights(cloudabi_rights_t in, cap_rights_t *out)
418 {
419
420 cap_rights_init(out);
421 #define MAPPING(cloudabi, ...) do { \
422 if (in & (cloudabi)) { \
423 cap_rights_set(out, ##__VA_ARGS__); \
424 in &= ~(cloudabi); \
425 } \
426 } while (0);
427 RIGHTS_MAPPINGS
428 #undef MAPPING
429 if (in != 0)
430 return (ENOTCAPABLE);
431 return (0);
432 }
433
434 int
cloudabi_sys_fd_stat_put(struct thread * td,struct cloudabi_sys_fd_stat_put_args * uap)435 cloudabi_sys_fd_stat_put(struct thread *td,
436 struct cloudabi_sys_fd_stat_put_args *uap)
437 {
438 cloudabi_fdstat_t fsb;
439 cap_rights_t rights;
440 int error, oflags;
441
442 error = copyin(uap->buf, &fsb, sizeof(fsb));
443 if (error != 0)
444 return (error);
445
446 if (uap->flags == CLOUDABI_FDSTAT_FLAGS) {
447 /* Convert flags. */
448 oflags = 0;
449 if (fsb.fs_flags & CLOUDABI_FDFLAG_APPEND)
450 oflags |= O_APPEND;
451 if (fsb.fs_flags & CLOUDABI_FDFLAG_NONBLOCK)
452 oflags |= O_NONBLOCK;
453 if (fsb.fs_flags & (CLOUDABI_FDFLAG_SYNC |
454 CLOUDABI_FDFLAG_DSYNC | CLOUDABI_FDFLAG_RSYNC))
455 oflags |= O_SYNC;
456 return (kern_fcntl(td, uap->fd, F_SETFL, oflags));
457 } else if (uap->flags == CLOUDABI_FDSTAT_RIGHTS) {
458 /* Convert rights. */
459 error = cloudabi_convert_rights(
460 fsb.fs_rights_base | fsb.fs_rights_inheriting, &rights);
461 if (error != 0)
462 return (error);
463 return (kern_cap_rights_limit(td, uap->fd, &rights));
464 }
465 return (EINVAL);
466 }
467
468 int
cloudabi_sys_fd_sync(struct thread * td,struct cloudabi_sys_fd_sync_args * uap)469 cloudabi_sys_fd_sync(struct thread *td, struct cloudabi_sys_fd_sync_args *uap)
470 {
471
472 return (kern_fsync(td, uap->fd, true));
473 }
474