1*8269e767SBrooks Davis.\" 2*8269e767SBrooks Davis.\" Copyright (c) 2012 The FreeBSD Foundation 3*8269e767SBrooks Davis.\" 4*8269e767SBrooks Davis.\" This documentation was written by Pawel Jakub Dawidek under sponsorship 5*8269e767SBrooks Davis.\" the FreeBSD Foundation. 6*8269e767SBrooks Davis.\" 7*8269e767SBrooks Davis.\" Redistribution and use in source and binary forms, with or without 8*8269e767SBrooks Davis.\" modification, are permitted provided that the following conditions 9*8269e767SBrooks Davis.\" are met: 10*8269e767SBrooks Davis.\" 1. Redistributions of source code must retain the above copyright 11*8269e767SBrooks Davis.\" notice, this list of conditions and the following disclaimer. 12*8269e767SBrooks Davis.\" 2. Redistributions in binary form must reproduce the above copyright 13*8269e767SBrooks Davis.\" notice, this list of conditions and the following disclaimer in the 14*8269e767SBrooks Davis.\" documentation and/or other materials provided with the distribution. 15*8269e767SBrooks Davis.\" 16*8269e767SBrooks Davis.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 17*8269e767SBrooks Davis.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 18*8269e767SBrooks Davis.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 19*8269e767SBrooks Davis.\" ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 20*8269e767SBrooks Davis.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 21*8269e767SBrooks Davis.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 22*8269e767SBrooks Davis.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 23*8269e767SBrooks Davis.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 24*8269e767SBrooks Davis.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 25*8269e767SBrooks Davis.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 26*8269e767SBrooks Davis.\" SUCH DAMAGE. 27*8269e767SBrooks Davis.\" 28*8269e767SBrooks Davis.Dd March 9, 2023 29*8269e767SBrooks Davis.Dt CAP_FCNTLS_LIMIT 2 30*8269e767SBrooks Davis.Os 31*8269e767SBrooks Davis.Sh NAME 32*8269e767SBrooks Davis.Nm cap_fcntls_limit , 33*8269e767SBrooks Davis.Nm cap_fcntls_get 34*8269e767SBrooks Davis.Nd manage allowed fcntl commands 35*8269e767SBrooks Davis.Sh LIBRARY 36*8269e767SBrooks Davis.Lb libc 37*8269e767SBrooks Davis.Sh SYNOPSIS 38*8269e767SBrooks Davis.In sys/capsicum.h 39*8269e767SBrooks Davis.Ft int 40*8269e767SBrooks Davis.Fn cap_fcntls_limit "int fd" "uint32_t fcntlrights" 41*8269e767SBrooks Davis.Ft int 42*8269e767SBrooks Davis.Fn cap_fcntls_get "int fd" "uint32_t *fcntlrightsp" 43*8269e767SBrooks Davis.Sh DESCRIPTION 44*8269e767SBrooks DavisIf a file descriptor is granted the 45*8269e767SBrooks Davis.Dv CAP_FCNTL 46*8269e767SBrooks Daviscapability right, the list of allowed 47*8269e767SBrooks Davis.Xr fcntl 2 48*8269e767SBrooks Daviscommands can be selectively reduced (but never expanded) with the 49*8269e767SBrooks Davis.Fn cap_fcntls_limit 50*8269e767SBrooks Davissystem call. 51*8269e767SBrooks Davis.Pp 52*8269e767SBrooks DavisA bitmask of allowed fcntls commands for a given file descriptor can be obtained 53*8269e767SBrooks Daviswith the 54*8269e767SBrooks Davis.Fn cap_fcntls_get 55*8269e767SBrooks Davissystem call. 56*8269e767SBrooks Davis.Sh FLAGS 57*8269e767SBrooks DavisThe following flags may be specified in the 58*8269e767SBrooks Davis.Fa fcntlrights 59*8269e767SBrooks Davisargument or returned in the 60*8269e767SBrooks Davis.Fa fcntlrightsp 61*8269e767SBrooks Davisargument: 62*8269e767SBrooks Davis.Bl -tag -width CAP_FCNTL_GETOWN 63*8269e767SBrooks Davis.It Dv CAP_FCNTL_GETFL 64*8269e767SBrooks DavisPermit 65*8269e767SBrooks Davis.Dv F_GETFL 66*8269e767SBrooks Daviscommand. 67*8269e767SBrooks Davis.It Dv CAP_FCNTL_SETFL 68*8269e767SBrooks DavisPermit 69*8269e767SBrooks Davis.Dv F_SETFL 70*8269e767SBrooks Daviscommand. 71*8269e767SBrooks Davis.It Dv CAP_FCNTL_GETOWN 72*8269e767SBrooks DavisPermit 73*8269e767SBrooks Davis.Dv F_GETOWN 74*8269e767SBrooks Daviscommand. 75*8269e767SBrooks Davis.It Dv CAP_FCNTL_SETOWN 76*8269e767SBrooks DavisPermit 77*8269e767SBrooks Davis.Dv F_SETOWN 78*8269e767SBrooks Daviscommand. 79*8269e767SBrooks Davis.El 80*8269e767SBrooks Davis.Sh RETURN VALUES 81*8269e767SBrooks Davis.Rv -std 82*8269e767SBrooks Davis.Sh ERRORS 83*8269e767SBrooks Davis.Fn cap_fcntls_limit 84*8269e767SBrooks Davissucceeds unless: 85*8269e767SBrooks Davis.Bl -tag -width Er 86*8269e767SBrooks Davis.It Bq Er EBADF 87*8269e767SBrooks DavisThe 88*8269e767SBrooks Davis.Fa fd 89*8269e767SBrooks Davisargument is not a valid descriptor. 90*8269e767SBrooks Davis.It Bq Er EINVAL 91*8269e767SBrooks DavisAn invalid flag has been passed in 92*8269e767SBrooks Davis.Fa fcntlrights . 93*8269e767SBrooks Davis.It Bq Er ENOTCAPABLE 94*8269e767SBrooks Davis.Fa fcntlrights 95*8269e767SBrooks Daviswould expand the list of allowed 96*8269e767SBrooks Davis.Xr fcntl 2 97*8269e767SBrooks Daviscommands. 98*8269e767SBrooks Davis.El 99*8269e767SBrooks Davis.Pp 100*8269e767SBrooks Davis.Fn cap_fcntls_get 101*8269e767SBrooks Davissucceeds unless: 102*8269e767SBrooks Davis.Bl -tag -width Er 103*8269e767SBrooks Davis.It Bq Er EBADF 104*8269e767SBrooks DavisThe 105*8269e767SBrooks Davis.Fa fd 106*8269e767SBrooks Davisargument is not a valid descriptor. 107*8269e767SBrooks Davis.It Bq Er EFAULT 108*8269e767SBrooks DavisThe 109*8269e767SBrooks Davis.Fa fcntlrightsp 110*8269e767SBrooks Davisargument points at an invalid address. 111*8269e767SBrooks Davis.It Bq Er ENOSYS 112*8269e767SBrooks DavisThe running kernel was compiled without 113*8269e767SBrooks Davis.Cd "options CAPABILITY_MODE" . 114*8269e767SBrooks Davis.El 115*8269e767SBrooks Davis.Sh SEE ALSO 116*8269e767SBrooks Davis.Xr cap_ioctls_limit 2 , 117*8269e767SBrooks Davis.Xr cap_rights_limit 2 , 118*8269e767SBrooks Davis.Xr fcntl 2 119*8269e767SBrooks Davis.Sh HISTORY 120*8269e767SBrooks DavisThe 121*8269e767SBrooks Davis.Fn cap_fcntls_get 122*8269e767SBrooks Davisand 123*8269e767SBrooks Davis.Fn cap_fcntls_limit 124*8269e767SBrooks Davissystem calls first appeared in 125*8269e767SBrooks Davis.Fx 8.3 . 126*8269e767SBrooks DavisSupport for capabilities and capabilities mode was developed as part of the 127*8269e767SBrooks Davis.Tn TrustedBSD 128*8269e767SBrooks DavisProject. 129*8269e767SBrooks Davis.Sh AUTHORS 130*8269e767SBrooks DavisThis function was created by 131*8269e767SBrooks Davis.An Pawel Jakub Dawidek Aq Mt pawel@dawidek.net 132*8269e767SBrooks Davisunder sponsorship of the FreeBSD Foundation. 133