xref: /freebsd/lib/libsys/cap_fcntls_limit.2 (revision 8269e7673cf033aba67dab8264fe719920c70f87)
1*8269e767SBrooks Davis.\"
2*8269e767SBrooks Davis.\" Copyright (c) 2012 The FreeBSD Foundation
3*8269e767SBrooks Davis.\"
4*8269e767SBrooks Davis.\" This documentation was written by Pawel Jakub Dawidek under sponsorship
5*8269e767SBrooks Davis.\" the FreeBSD Foundation.
6*8269e767SBrooks Davis.\"
7*8269e767SBrooks Davis.\" Redistribution and use in source and binary forms, with or without
8*8269e767SBrooks Davis.\" modification, are permitted provided that the following conditions
9*8269e767SBrooks Davis.\" are met:
10*8269e767SBrooks Davis.\" 1. Redistributions of source code must retain the above copyright
11*8269e767SBrooks Davis.\"    notice, this list of conditions and the following disclaimer.
12*8269e767SBrooks Davis.\" 2. Redistributions in binary form must reproduce the above copyright
13*8269e767SBrooks Davis.\"    notice, this list of conditions and the following disclaimer in the
14*8269e767SBrooks Davis.\"    documentation and/or other materials provided with the distribution.
15*8269e767SBrooks Davis.\"
16*8269e767SBrooks Davis.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17*8269e767SBrooks Davis.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18*8269e767SBrooks Davis.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19*8269e767SBrooks Davis.\" ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20*8269e767SBrooks Davis.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21*8269e767SBrooks Davis.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22*8269e767SBrooks Davis.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23*8269e767SBrooks Davis.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24*8269e767SBrooks Davis.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25*8269e767SBrooks Davis.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26*8269e767SBrooks Davis.\" SUCH DAMAGE.
27*8269e767SBrooks Davis.\"
28*8269e767SBrooks Davis.Dd March 9, 2023
29*8269e767SBrooks Davis.Dt CAP_FCNTLS_LIMIT 2
30*8269e767SBrooks Davis.Os
31*8269e767SBrooks Davis.Sh NAME
32*8269e767SBrooks Davis.Nm cap_fcntls_limit ,
33*8269e767SBrooks Davis.Nm cap_fcntls_get
34*8269e767SBrooks Davis.Nd manage allowed fcntl commands
35*8269e767SBrooks Davis.Sh LIBRARY
36*8269e767SBrooks Davis.Lb libc
37*8269e767SBrooks Davis.Sh SYNOPSIS
38*8269e767SBrooks Davis.In sys/capsicum.h
39*8269e767SBrooks Davis.Ft int
40*8269e767SBrooks Davis.Fn cap_fcntls_limit "int fd" "uint32_t fcntlrights"
41*8269e767SBrooks Davis.Ft int
42*8269e767SBrooks Davis.Fn cap_fcntls_get "int fd" "uint32_t *fcntlrightsp"
43*8269e767SBrooks Davis.Sh DESCRIPTION
44*8269e767SBrooks DavisIf a file descriptor is granted the
45*8269e767SBrooks Davis.Dv CAP_FCNTL
46*8269e767SBrooks Daviscapability right, the list of allowed
47*8269e767SBrooks Davis.Xr fcntl 2
48*8269e767SBrooks Daviscommands can be selectively reduced (but never expanded) with the
49*8269e767SBrooks Davis.Fn cap_fcntls_limit
50*8269e767SBrooks Davissystem call.
51*8269e767SBrooks Davis.Pp
52*8269e767SBrooks DavisA bitmask of allowed fcntls commands for a given file descriptor can be obtained
53*8269e767SBrooks Daviswith the
54*8269e767SBrooks Davis.Fn cap_fcntls_get
55*8269e767SBrooks Davissystem call.
56*8269e767SBrooks Davis.Sh FLAGS
57*8269e767SBrooks DavisThe following flags may be specified in the
58*8269e767SBrooks Davis.Fa fcntlrights
59*8269e767SBrooks Davisargument or returned in the
60*8269e767SBrooks Davis.Fa fcntlrightsp
61*8269e767SBrooks Davisargument:
62*8269e767SBrooks Davis.Bl -tag -width CAP_FCNTL_GETOWN
63*8269e767SBrooks Davis.It Dv CAP_FCNTL_GETFL
64*8269e767SBrooks DavisPermit
65*8269e767SBrooks Davis.Dv F_GETFL
66*8269e767SBrooks Daviscommand.
67*8269e767SBrooks Davis.It Dv CAP_FCNTL_SETFL
68*8269e767SBrooks DavisPermit
69*8269e767SBrooks Davis.Dv F_SETFL
70*8269e767SBrooks Daviscommand.
71*8269e767SBrooks Davis.It Dv CAP_FCNTL_GETOWN
72*8269e767SBrooks DavisPermit
73*8269e767SBrooks Davis.Dv F_GETOWN
74*8269e767SBrooks Daviscommand.
75*8269e767SBrooks Davis.It Dv CAP_FCNTL_SETOWN
76*8269e767SBrooks DavisPermit
77*8269e767SBrooks Davis.Dv F_SETOWN
78*8269e767SBrooks Daviscommand.
79*8269e767SBrooks Davis.El
80*8269e767SBrooks Davis.Sh RETURN VALUES
81*8269e767SBrooks Davis.Rv -std
82*8269e767SBrooks Davis.Sh ERRORS
83*8269e767SBrooks Davis.Fn cap_fcntls_limit
84*8269e767SBrooks Davissucceeds unless:
85*8269e767SBrooks Davis.Bl -tag -width Er
86*8269e767SBrooks Davis.It Bq Er EBADF
87*8269e767SBrooks DavisThe
88*8269e767SBrooks Davis.Fa fd
89*8269e767SBrooks Davisargument is not a valid descriptor.
90*8269e767SBrooks Davis.It Bq Er EINVAL
91*8269e767SBrooks DavisAn invalid flag has been passed in
92*8269e767SBrooks Davis.Fa fcntlrights .
93*8269e767SBrooks Davis.It Bq Er ENOTCAPABLE
94*8269e767SBrooks Davis.Fa fcntlrights
95*8269e767SBrooks Daviswould expand the list of allowed
96*8269e767SBrooks Davis.Xr fcntl 2
97*8269e767SBrooks Daviscommands.
98*8269e767SBrooks Davis.El
99*8269e767SBrooks Davis.Pp
100*8269e767SBrooks Davis.Fn cap_fcntls_get
101*8269e767SBrooks Davissucceeds unless:
102*8269e767SBrooks Davis.Bl -tag -width Er
103*8269e767SBrooks Davis.It Bq Er EBADF
104*8269e767SBrooks DavisThe
105*8269e767SBrooks Davis.Fa fd
106*8269e767SBrooks Davisargument is not a valid descriptor.
107*8269e767SBrooks Davis.It Bq Er EFAULT
108*8269e767SBrooks DavisThe
109*8269e767SBrooks Davis.Fa fcntlrightsp
110*8269e767SBrooks Davisargument points at an invalid address.
111*8269e767SBrooks Davis.It Bq Er ENOSYS
112*8269e767SBrooks DavisThe running kernel was compiled without
113*8269e767SBrooks Davis.Cd "options CAPABILITY_MODE" .
114*8269e767SBrooks Davis.El
115*8269e767SBrooks Davis.Sh SEE ALSO
116*8269e767SBrooks Davis.Xr cap_ioctls_limit 2 ,
117*8269e767SBrooks Davis.Xr cap_rights_limit 2 ,
118*8269e767SBrooks Davis.Xr fcntl 2
119*8269e767SBrooks Davis.Sh HISTORY
120*8269e767SBrooks DavisThe
121*8269e767SBrooks Davis.Fn cap_fcntls_get
122*8269e767SBrooks Davisand
123*8269e767SBrooks Davis.Fn cap_fcntls_limit
124*8269e767SBrooks Davissystem calls first appeared in
125*8269e767SBrooks Davis.Fx 8.3 .
126*8269e767SBrooks DavisSupport for capabilities and capabilities mode was developed as part of the
127*8269e767SBrooks Davis.Tn TrustedBSD
128*8269e767SBrooks DavisProject.
129*8269e767SBrooks Davis.Sh AUTHORS
130*8269e767SBrooks DavisThis function was created by
131*8269e767SBrooks Davis.An Pawel Jakub Dawidek Aq Mt pawel@dawidek.net
132*8269e767SBrooks Davisunder sponsorship of the FreeBSD Foundation.
133