d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe/*
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe * This file and its contents are supplied under the terms of the
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe * Common Development and Distribution License ("CDDL"), version 1.0.
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe * You may only use this file in accordance with the terms of version
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe * 1.0 of the CDDL.
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe *
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe * A full copy of the text of the CDDL should have accompanied this
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe * source. A copy of the CDDL is also available via the Internet at
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe * http://www.illumos.org/license/CDDL.
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe */
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe/* Copyright 2015, Richard Lowe. */
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe#include <sys/ddi.h>
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe#include <sys/errno.h>
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe#include <sys/policy.h>
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe#include <sys/proc.h>
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe#include <sys/procset.h>
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe#include <sys/systm.h>
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe#include <sys/types.h>
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe#include <c2/audit.h>
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowestruct psdargs {
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe psecflagwhich_t which;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe const secflagdelta_t *delta;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe};
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowevoid
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowesecflags_apply_delta(secflagset_t *set, const secflagdelta_t *delta)
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe{
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe if (delta->psd_ass_active) {
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe secflags_copy(set, &delta->psd_assign);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe } else {
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe if (!secflags_isempty(delta->psd_add)) {
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe secflags_union(set, &delta->psd_add);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe }
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe if (!secflags_isempty(delta->psd_rem)) {
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe secflags_difference(set, &delta->psd_rem);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe }
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe }
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe}
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowestatic int
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowepsecdo(proc_t *p, struct psdargs *args)
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe{
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe secflagset_t *set;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe int ret = 0;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe mutex_enter(&p->p_lock);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe if (secpolicy_psecflags(CRED(), p, curproc) != 0) {
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe ret = EPERM;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe goto out;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe }
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe ASSERT(args->which != PSF_EFFECTIVE);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe if (!psecflags_validate_delta(&p->p_secflags, args->delta)) {
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe ret = EINVAL;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe goto out;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe }
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe if (AU_AUDITING())
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe audit_psecflags(p, args->which, args->delta);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe switch (args->which) {
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe case PSF_INHERIT:
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe set = &p->p_secflags.psf_inherit;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe break;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe case PSF_LOWER:
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe set = &p->p_secflags.psf_lower;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe break;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe case PSF_UPPER:
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe set = &p->p_secflags.psf_upper;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe break;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe }
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe secflags_apply_delta(set, args->delta);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe /*
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe * Add any flag now in the lower that is not in the inheritable.
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe */
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe secflags_union(&p->p_secflags.psf_inherit, &p->p_secflags.psf_lower);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Loweout:
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe mutex_exit(&p->p_lock);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe return (ret);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe}
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Loweint
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowepsecflags(procset_t *psp, psecflagwhich_t which, secflagdelta_t *ap)
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe{
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe procset_t procset;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe secflagdelta_t args;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe int rv = 0;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe struct psdargs psd = {
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe .which = which,
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe };
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe /* Can never change the effective flags */
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe if (psd.which == PSF_EFFECTIVE)
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe return (EINVAL);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe if (copyin(psp, &procset, sizeof (procset)) != 0)
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe return (set_errno(EFAULT));
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe if (copyin(ap, &args, sizeof (secflagdelta_t)) != 0)
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe return (set_errno(EFAULT));
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe psd.delta = &args;
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe /* secflags are per-process, procset must be in terms of processes */
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe if ((procset.p_lidtype == P_LWPID) ||
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe (procset.p_ridtype == P_LWPID))
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe return (set_errno(EINVAL));
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe rv = dotoprocs(&procset, psecdo, (caddr_t)&psd);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe return (rv ? set_errno(rv) : 0);
d2a70789f056fc6c9ce3ab047b52126d80b0e3daRichard Lowe}