1c6dfea0eSMarcel Moolenaar /*-
2*4d846d26SWarner Losh * SPDX-License-Identifier: BSD-2-Clause
37f2d13d6SPedro F. Giffuni *
4c6dfea0eSMarcel Moolenaar * Copyright (c) 1999 Marcel Moolenaar
5c6dfea0eSMarcel Moolenaar * All rights reserved.
6c6dfea0eSMarcel Moolenaar *
7c6dfea0eSMarcel Moolenaar * Redistribution and use in source and binary forms, with or without
8c6dfea0eSMarcel Moolenaar * modification, are permitted provided that the following conditions
9c6dfea0eSMarcel Moolenaar * are met:
10c6dfea0eSMarcel Moolenaar * 1. Redistributions of source code must retain the above copyright
110ba1b365SEd Maste * notice, this list of conditions and the following disclaimer.
12c6dfea0eSMarcel Moolenaar * 2. Redistributions in binary form must reproduce the above copyright
13c6dfea0eSMarcel Moolenaar * notice, this list of conditions and the following disclaimer in the
14c6dfea0eSMarcel Moolenaar * documentation and/or other materials provided with the distribution.
15c6dfea0eSMarcel Moolenaar *
160ba1b365SEd Maste * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
170ba1b365SEd Maste * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
180ba1b365SEd Maste * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
190ba1b365SEd Maste * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
200ba1b365SEd Maste * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
210ba1b365SEd Maste * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
220ba1b365SEd Maste * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
230ba1b365SEd Maste * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
240ba1b365SEd Maste * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
250ba1b365SEd Maste * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
260ba1b365SEd Maste * SUCH DAMAGE.
27c6dfea0eSMarcel Moolenaar */
28c6dfea0eSMarcel Moolenaar
29c6dfea0eSMarcel Moolenaar #include <sys/param.h>
30d8e53d94SDmitry Chagin #include <sys/lock.h>
31c6dfea0eSMarcel Moolenaar #include <sys/malloc.h>
327ae27ff4SJamie Gritton #include <sys/mount.h>
33c6dfea0eSMarcel Moolenaar #include <sys/jail.h>
34d8e53d94SDmitry Chagin #include <sys/proc.h>
357ae27ff4SJamie Gritton #include <sys/sx.h>
36c6dfea0eSMarcel Moolenaar
37607d46efSMarcel Moolenaar #include <compat/linux/linux_mib.h>
38d825ce0aSJohn Baldwin #include <compat/linux/linux_misc.h>
39c6dfea0eSMarcel Moolenaar
40c6dfea0eSMarcel Moolenaar struct linux_prison {
41c6dfea0eSMarcel Moolenaar char pr_osname[LINUX_MAX_UTSNAME];
42c6dfea0eSMarcel Moolenaar char pr_osrelease[LINUX_MAX_UTSNAME];
43c6dfea0eSMarcel Moolenaar int pr_oss_version;
44580dd797SDmitry Chagin int pr_osrel;
45c6dfea0eSMarcel Moolenaar };
46c6dfea0eSMarcel Moolenaar
470304c731SJamie Gritton static struct linux_prison lprison0 = {
480304c731SJamie Gritton .pr_osname = "Linux",
49a6326909SDmitry Chagin .pr_osrelease = LINUX_VERSION_STR,
500304c731SJamie Gritton .pr_oss_version = 0x030600,
51a6326909SDmitry Chagin .pr_osrel = LINUX_VERSION_CODE
520304c731SJamie Gritton };
530304c731SJamie Gritton
547ae27ff4SJamie Gritton static unsigned linux_osd_jail_slot;
557ae27ff4SJamie Gritton
567029da5cSPawel Biernacki SYSCTL_NODE(_compat, OID_AUTO, linux, CTLFLAG_RW | CTLFLAG_MPSAFE, 0,
577029da5cSPawel Biernacki "Linux mode");
58c6dfea0eSMarcel Moolenaar
598ec6c4a3SAlexander Leidinger int linux_debug = 3;
60462171d9SEdward Tomasz Napierala SYSCTL_INT(_compat_linux, OID_AUTO, debug, CTLFLAG_RWTUN,
61462171d9SEdward Tomasz Napierala &linux_debug, 0, "Log warnings from linux(4); or 0 to disable");
62462171d9SEdward Tomasz Napierala
638c5059e9SEdward Tomasz Napierala int linux_default_openfiles = 1024;
648c5059e9SEdward Tomasz Napierala SYSCTL_INT(_compat_linux, OID_AUTO, default_openfiles, CTLFLAG_RWTUN,
658c5059e9SEdward Tomasz Napierala &linux_default_openfiles, 0,
668c5059e9SEdward Tomasz Napierala "Default soft openfiles resource limit, or -1 for unlimited");
678c5059e9SEdward Tomasz Napierala
681c34dcb5SEdward Tomasz Napierala int linux_default_stacksize = 8 * 1024 * 1024;
691c34dcb5SEdward Tomasz Napierala SYSCTL_INT(_compat_linux, OID_AUTO, default_stacksize, CTLFLAG_RWTUN,
701c34dcb5SEdward Tomasz Napierala &linux_default_stacksize, 0,
711c34dcb5SEdward Tomasz Napierala "Default soft stack size resource limit, or -1 for unlimited");
721c34dcb5SEdward Tomasz Napierala
7354669eb7SEdward Tomasz Napierala int linux_dummy_rlimits = 0;
7454669eb7SEdward Tomasz Napierala SYSCTL_INT(_compat_linux, OID_AUTO, dummy_rlimits, CTLFLAG_RWTUN,
7554669eb7SEdward Tomasz Napierala &linux_dummy_rlimits, 0,
7654669eb7SEdward Tomasz Napierala "Return dummy values for unsupported Linux-specific rlimits");
7754669eb7SEdward Tomasz Napierala
78da6d8ae6SEdward Tomasz Napierala int linux_ignore_ip_recverr = 1;
79da6d8ae6SEdward Tomasz Napierala SYSCTL_INT(_compat_linux, OID_AUTO, ignore_ip_recverr, CTLFLAG_RWTUN,
80da6d8ae6SEdward Tomasz Napierala &linux_ignore_ip_recverr, 0, "Ignore enabling IP_RECVERR");
81da6d8ae6SEdward Tomasz Napierala
82b896bdb8SEdward Tomasz Napierala int linux_preserve_vstatus = 1;
832cf9eb6cSEdward Tomasz Napierala SYSCTL_INT(_compat_linux, OID_AUTO, preserve_vstatus, CTLFLAG_RWTUN,
842cf9eb6cSEdward Tomasz Napierala &linux_preserve_vstatus, 0, "Preserve VSTATUS termios(4) flag");
852cf9eb6cSEdward Tomasz Napierala
86b4147bf6STijl Coosemans bool linux_map_sched_prio = true;
87b4147bf6STijl Coosemans SYSCTL_BOOL(_compat_linux, OID_AUTO, map_sched_prio, CTLFLAG_RDTUN,
88b4147bf6STijl Coosemans &linux_map_sched_prio, 0, "Map scheduler priorities to Linux priorities "
89b4147bf6STijl Coosemans "(not POSIX compliant)");
90b4147bf6STijl Coosemans
91598f6fb4SKonstantin Belousov static bool linux_setid_allowed = true;
92598f6fb4SKonstantin Belousov SYSCTL_BOOL(_compat_linux, OID_AUTO, setid_allowed, CTLFLAG_RWTUN,
93598f6fb4SKonstantin Belousov &linux_setid_allowed, 0,
94598f6fb4SKonstantin Belousov "Allow setuid/setgid on execve of Linux binary");
95598f6fb4SKonstantin Belousov
9662b8258aSKonstantin Belousov int
linux_setid_allowed_query(struct thread * td __unused,struct image_params * imgp __unused)97598f6fb4SKonstantin Belousov linux_setid_allowed_query(struct thread *td __unused,
98598f6fb4SKonstantin Belousov struct image_params *imgp __unused)
99598f6fb4SKonstantin Belousov {
100598f6fb4SKonstantin Belousov return (linux_setid_allowed);
101598f6fb4SKonstantin Belousov }
102598f6fb4SKonstantin Belousov
1030d7b5e54SAlexander Leidinger static int linux_set_osname(struct thread *td, char *osname);
1040d7b5e54SAlexander Leidinger static int linux_set_osrelease(struct thread *td, char *osrelease);
1050d7b5e54SAlexander Leidinger static int linux_set_oss_version(struct thread *td, int oss_version);
1060d7b5e54SAlexander Leidinger
107c6dfea0eSMarcel Moolenaar static int
linux_sysctl_osname(SYSCTL_HANDLER_ARGS)10882d9ae4eSPoul-Henning Kamp linux_sysctl_osname(SYSCTL_HANDLER_ARGS)
109c6dfea0eSMarcel Moolenaar {
110c6dfea0eSMarcel Moolenaar char osname[LINUX_MAX_UTSNAME];
111c6dfea0eSMarcel Moolenaar int error;
112c6dfea0eSMarcel Moolenaar
113b62f75cfSJohn Baldwin linux_get_osname(req->td, osname);
114c6dfea0eSMarcel Moolenaar error = sysctl_handle_string(oidp, osname, LINUX_MAX_UTSNAME, req);
11567d39748SDmitry Chagin if (error != 0 || req->newptr == NULL)
116c6dfea0eSMarcel Moolenaar return (error);
117b62f75cfSJohn Baldwin error = linux_set_osname(req->td, osname);
11819e252baSAlexander Leidinger
119c6dfea0eSMarcel Moolenaar return (error);
120c6dfea0eSMarcel Moolenaar }
121c6dfea0eSMarcel Moolenaar
122c6dfea0eSMarcel Moolenaar SYSCTL_PROC(_compat_linux, OID_AUTO, osname,
12384a8cad0SJamie Gritton CTLTYPE_STRING | CTLFLAG_RW | CTLFLAG_PRISON | CTLFLAG_MPSAFE,
124c6dfea0eSMarcel Moolenaar 0, 0, linux_sysctl_osname, "A",
125c6dfea0eSMarcel Moolenaar "Linux kernel OS name");
126c6dfea0eSMarcel Moolenaar
127c6dfea0eSMarcel Moolenaar static int
linux_sysctl_osrelease(SYSCTL_HANDLER_ARGS)12882d9ae4eSPoul-Henning Kamp linux_sysctl_osrelease(SYSCTL_HANDLER_ARGS)
129c6dfea0eSMarcel Moolenaar {
130c6dfea0eSMarcel Moolenaar char osrelease[LINUX_MAX_UTSNAME];
131c6dfea0eSMarcel Moolenaar int error;
132c6dfea0eSMarcel Moolenaar
133b62f75cfSJohn Baldwin linux_get_osrelease(req->td, osrelease);
134c6dfea0eSMarcel Moolenaar error = sysctl_handle_string(oidp, osrelease, LINUX_MAX_UTSNAME, req);
13567d39748SDmitry Chagin if (error != 0 || req->newptr == NULL)
136c6dfea0eSMarcel Moolenaar return (error);
137b62f75cfSJohn Baldwin error = linux_set_osrelease(req->td, osrelease);
13819e252baSAlexander Leidinger
139c6dfea0eSMarcel Moolenaar return (error);
140c6dfea0eSMarcel Moolenaar }
141c6dfea0eSMarcel Moolenaar
142c6dfea0eSMarcel Moolenaar SYSCTL_PROC(_compat_linux, OID_AUTO, osrelease,
14384a8cad0SJamie Gritton CTLTYPE_STRING | CTLFLAG_RW | CTLFLAG_PRISON | CTLFLAG_MPSAFE,
144c6dfea0eSMarcel Moolenaar 0, 0, linux_sysctl_osrelease, "A",
145c6dfea0eSMarcel Moolenaar "Linux kernel OS release");
146c6dfea0eSMarcel Moolenaar
147c6dfea0eSMarcel Moolenaar static int
linux_sysctl_oss_version(SYSCTL_HANDLER_ARGS)14882d9ae4eSPoul-Henning Kamp linux_sysctl_oss_version(SYSCTL_HANDLER_ARGS)
149c6dfea0eSMarcel Moolenaar {
150c6dfea0eSMarcel Moolenaar int oss_version;
151c6dfea0eSMarcel Moolenaar int error;
152c6dfea0eSMarcel Moolenaar
153b62f75cfSJohn Baldwin oss_version = linux_get_oss_version(req->td);
154c6dfea0eSMarcel Moolenaar error = sysctl_handle_int(oidp, &oss_version, 0, req);
15567d39748SDmitry Chagin if (error != 0 || req->newptr == NULL)
156c6dfea0eSMarcel Moolenaar return (error);
157b62f75cfSJohn Baldwin error = linux_set_oss_version(req->td, oss_version);
15819e252baSAlexander Leidinger
159c6dfea0eSMarcel Moolenaar return (error);
160c6dfea0eSMarcel Moolenaar }
161c6dfea0eSMarcel Moolenaar
162c6dfea0eSMarcel Moolenaar SYSCTL_PROC(_compat_linux, OID_AUTO, oss_version,
16384a8cad0SJamie Gritton CTLTYPE_INT | CTLFLAG_RW | CTLFLAG_PRISON | CTLFLAG_MPSAFE,
164c6dfea0eSMarcel Moolenaar 0, 0, linux_sysctl_oss_version, "I",
165c6dfea0eSMarcel Moolenaar "Linux OSS version");
166c6dfea0eSMarcel Moolenaar
16701137630SRobert Watson /*
168580dd797SDmitry Chagin * Map the osrelease into integer
169580dd797SDmitry Chagin */
170580dd797SDmitry Chagin static int
linux_map_osrel(char * osrelease,int * osrel)171580dd797SDmitry Chagin linux_map_osrel(char *osrelease, int *osrel)
172580dd797SDmitry Chagin {
173580dd797SDmitry Chagin char *sep, *eosrelease;
174580dd797SDmitry Chagin int len, v0, v1, v2, v;
175580dd797SDmitry Chagin
176580dd797SDmitry Chagin len = strlen(osrelease);
177580dd797SDmitry Chagin eosrelease = osrelease + len;
178580dd797SDmitry Chagin v0 = strtol(osrelease, &sep, 10);
17967d39748SDmitry Chagin if (osrelease == sep || sep + 1 >= eosrelease || *sep != '.')
180580dd797SDmitry Chagin return (EINVAL);
181580dd797SDmitry Chagin osrelease = sep + 1;
182580dd797SDmitry Chagin v1 = strtol(osrelease, &sep, 10);
18367d39748SDmitry Chagin if (osrelease == sep || sep + 1 >= eosrelease || *sep != '.')
184580dd797SDmitry Chagin return (EINVAL);
185580dd797SDmitry Chagin osrelease = sep + 1;
186580dd797SDmitry Chagin v2 = strtol(osrelease, &sep, 10);
1877a8cbc52SEdward Tomasz Napierala if (osrelease == sep ||
1887a8cbc52SEdward Tomasz Napierala (sep != eosrelease && (sep + 1 >= eosrelease || *sep != '-')))
189580dd797SDmitry Chagin return (EINVAL);
190580dd797SDmitry Chagin
19135755049SChuck Tuffli v = LINUX_KERNVER(v0, v1, v2);
19235755049SChuck Tuffli if (v < LINUX_KERNVER(1, 0, 0))
193580dd797SDmitry Chagin return (EINVAL);
194580dd797SDmitry Chagin
195d56cf22dSJamie Gritton if (osrel != NULL)
196580dd797SDmitry Chagin *osrel = v;
19719e252baSAlexander Leidinger
198580dd797SDmitry Chagin return (0);
199580dd797SDmitry Chagin }
200580dd797SDmitry Chagin
201580dd797SDmitry Chagin /*
2020304c731SJamie Gritton * Find a prison with Linux info.
2030304c731SJamie Gritton * Return the Linux info and the (locked) prison.
20401137630SRobert Watson */
2057ae27ff4SJamie Gritton static struct linux_prison *
linux_find_prison(struct prison * spr,struct prison ** prp)2060304c731SJamie Gritton linux_find_prison(struct prison *spr, struct prison **prp)
207c6dfea0eSMarcel Moolenaar {
2087ae27ff4SJamie Gritton struct prison *pr;
2097ae27ff4SJamie Gritton struct linux_prison *lpr;
210c6dfea0eSMarcel Moolenaar
2110304c731SJamie Gritton for (pr = spr;; pr = pr->pr_parent) {
212b62f75cfSJohn Baldwin mtx_lock(&pr->pr_mtx);
2130304c731SJamie Gritton lpr = (pr == &prison0)
2140304c731SJamie Gritton ? &lprison0
2150304c731SJamie Gritton : osd_jail_get(pr, linux_osd_jail_slot);
2160304c731SJamie Gritton if (lpr != NULL)
2170304c731SJamie Gritton break;
2187ae27ff4SJamie Gritton mtx_unlock(&pr->pr_mtx);
2190304c731SJamie Gritton }
2200304c731SJamie Gritton *prp = pr;
22119e252baSAlexander Leidinger
2227ae27ff4SJamie Gritton return (lpr);
2237ae27ff4SJamie Gritton }
2247ae27ff4SJamie Gritton
22501137630SRobert Watson /*
2260304c731SJamie Gritton * Ensure a prison has its own Linux info. If lprp is non-null, point it to
2270304c731SJamie Gritton * the Linux info and lock the prison.
2287ae27ff4SJamie Gritton */
2297ab25e3dSJamie Gritton static void
linux_alloc_prison(struct prison * pr,struct linux_prison ** lprp)2307ae27ff4SJamie Gritton linux_alloc_prison(struct prison *pr, struct linux_prison **lprp)
2317ae27ff4SJamie Gritton {
2320304c731SJamie Gritton struct prison *ppr;
2337ae27ff4SJamie Gritton struct linux_prison *lpr, *nlpr;
234aa90aec2SConrad Meyer void **rsv;
2357ae27ff4SJamie Gritton
2367ae27ff4SJamie Gritton /* If this prison already has Linux info, return that. */
2370304c731SJamie Gritton lpr = linux_find_prison(pr, &ppr);
2380304c731SJamie Gritton if (ppr == pr)
2397ae27ff4SJamie Gritton goto done;
2407ae27ff4SJamie Gritton /*
2417ae27ff4SJamie Gritton * Allocate a new info record. Then check again, in case something
2427ae27ff4SJamie Gritton * changed during the allocation.
24301137630SRobert Watson */
2440304c731SJamie Gritton mtx_unlock(&ppr->pr_mtx);
2457ae27ff4SJamie Gritton nlpr = malloc(sizeof(struct linux_prison), M_PRISON, M_WAITOK);
2467ab25e3dSJamie Gritton rsv = osd_reserve(linux_osd_jail_slot);
2470304c731SJamie Gritton lpr = linux_find_prison(pr, &ppr);
2480304c731SJamie Gritton if (ppr == pr) {
2497ae27ff4SJamie Gritton free(nlpr, M_PRISON);
2507ab25e3dSJamie Gritton osd_free_reserved(rsv);
2517ae27ff4SJamie Gritton goto done;
25201137630SRobert Watson }
2530304c731SJamie Gritton /* Inherit the initial values from the ancestor. */
2540304c731SJamie Gritton mtx_lock(&pr->pr_mtx);
2557ab25e3dSJamie Gritton (void)osd_jail_set_reserved(pr, linux_osd_jail_slot, rsv, nlpr);
2560304c731SJamie Gritton bcopy(lpr, nlpr, sizeof(*lpr));
2577ae27ff4SJamie Gritton lpr = nlpr;
2580304c731SJamie Gritton mtx_unlock(&ppr->pr_mtx);
2597ae27ff4SJamie Gritton done:
2607ae27ff4SJamie Gritton if (lprp != NULL)
2617ae27ff4SJamie Gritton *lprp = lpr;
2620304c731SJamie Gritton else
2630304c731SJamie Gritton mtx_unlock(&pr->pr_mtx);
2647ae27ff4SJamie Gritton }
2657ae27ff4SJamie Gritton
2667ae27ff4SJamie Gritton /*
2677ae27ff4SJamie Gritton * Jail OSD methods for Linux prison data.
2687ae27ff4SJamie Gritton */
2697ae27ff4SJamie Gritton static int
linux_prison_create(void * obj,void * data)2707ae27ff4SJamie Gritton linux_prison_create(void *obj, void *data)
2717ae27ff4SJamie Gritton {
2727ae27ff4SJamie Gritton struct prison *pr = obj;
2737ae27ff4SJamie Gritton struct vfsoptlist *opts = data;
27467d39748SDmitry Chagin int jsys;
2757ae27ff4SJamie Gritton
27667d39748SDmitry Chagin if (vfs_copyopt(opts, "linux", &jsys, sizeof(jsys)) == 0 &&
27767d39748SDmitry Chagin jsys == JAIL_SYS_INHERIT)
2787ae27ff4SJamie Gritton return (0);
2797ae27ff4SJamie Gritton /*
2807ae27ff4SJamie Gritton * Inherit a prison's initial values from its parent
2817cbf7213SJamie Gritton * (different from JAIL_SYS_INHERIT which also inherits changes).
2827ae27ff4SJamie Gritton */
2837ab25e3dSJamie Gritton linux_alloc_prison(pr, NULL);
2847ab25e3dSJamie Gritton return (0);
2857ae27ff4SJamie Gritton }
2867ae27ff4SJamie Gritton
2877ae27ff4SJamie Gritton static int
linux_prison_check(void * obj __unused,void * data)2887ae27ff4SJamie Gritton linux_prison_check(void *obj __unused, void *data)
2897ae27ff4SJamie Gritton {
2907ae27ff4SJamie Gritton struct vfsoptlist *opts = data;
2917ae27ff4SJamie Gritton char *osname, *osrelease;
292d56cf22dSJamie Gritton int error, jsys, len, oss_version;
2937ae27ff4SJamie Gritton
2947ae27ff4SJamie Gritton /* Check that the parameters are correct. */
2957cbf7213SJamie Gritton error = vfs_copyopt(opts, "linux", &jsys, sizeof(jsys));
2967cbf7213SJamie Gritton if (error != ENOENT) {
29767d39748SDmitry Chagin if (error != 0)
2987cbf7213SJamie Gritton return (error);
29967d39748SDmitry Chagin if (jsys != JAIL_SYS_NEW && jsys != JAIL_SYS_INHERIT)
3007cbf7213SJamie Gritton return (EINVAL);
3017cbf7213SJamie Gritton }
3027ae27ff4SJamie Gritton error = vfs_getopt(opts, "linux.osname", (void **)&osname, &len);
3037ae27ff4SJamie Gritton if (error != ENOENT) {
30467d39748SDmitry Chagin if (error != 0)
3057ae27ff4SJamie Gritton return (error);
30667d39748SDmitry Chagin if (len == 0 || osname[len - 1] != '\0')
3077ae27ff4SJamie Gritton return (EINVAL);
3087ae27ff4SJamie Gritton if (len > LINUX_MAX_UTSNAME) {
3097ae27ff4SJamie Gritton vfs_opterror(opts, "linux.osname too long");
3107ae27ff4SJamie Gritton return (ENAMETOOLONG);
3117ae27ff4SJamie Gritton }
3127ae27ff4SJamie Gritton }
3137ae27ff4SJamie Gritton error = vfs_getopt(opts, "linux.osrelease", (void **)&osrelease, &len);
3147ae27ff4SJamie Gritton if (error != ENOENT) {
31567d39748SDmitry Chagin if (error != 0)
3167ae27ff4SJamie Gritton return (error);
31767d39748SDmitry Chagin if (len == 0 || osrelease[len - 1] != '\0')
3187ae27ff4SJamie Gritton return (EINVAL);
3197ae27ff4SJamie Gritton if (len > LINUX_MAX_UTSNAME) {
3207ae27ff4SJamie Gritton vfs_opterror(opts, "linux.osrelease too long");
3217ae27ff4SJamie Gritton return (ENAMETOOLONG);
3227ae27ff4SJamie Gritton }
323d56cf22dSJamie Gritton error = linux_map_osrel(osrelease, NULL);
3240304c731SJamie Gritton if (error != 0) {
3250304c731SJamie Gritton vfs_opterror(opts, "linux.osrelease format error");
3260304c731SJamie Gritton return (error);
3270304c731SJamie Gritton }
3287ae27ff4SJamie Gritton }
3297ae27ff4SJamie Gritton error = vfs_copyopt(opts, "linux.oss_version", &oss_version,
3307ae27ff4SJamie Gritton sizeof(oss_version));
33119e252baSAlexander Leidinger
33219e252baSAlexander Leidinger if (error == ENOENT)
33319e252baSAlexander Leidinger error = 0;
33419e252baSAlexander Leidinger return (error);
3357ae27ff4SJamie Gritton }
3367ae27ff4SJamie Gritton
3377ae27ff4SJamie Gritton static int
linux_prison_set(void * obj,void * data)3387ae27ff4SJamie Gritton linux_prison_set(void *obj, void *data)
3397ae27ff4SJamie Gritton {
3407ae27ff4SJamie Gritton struct linux_prison *lpr;
3417ae27ff4SJamie Gritton struct prison *pr = obj;
3427ae27ff4SJamie Gritton struct vfsoptlist *opts = data;
3437ae27ff4SJamie Gritton char *osname, *osrelease;
3447cbf7213SJamie Gritton int error, gotversion, jsys, len, oss_version;
3457ae27ff4SJamie Gritton
3467ae27ff4SJamie Gritton /* Set the parameters, which should be correct. */
3477cbf7213SJamie Gritton error = vfs_copyopt(opts, "linux", &jsys, sizeof(jsys));
3487cbf7213SJamie Gritton if (error == ENOENT)
3497cbf7213SJamie Gritton jsys = -1;
3507ae27ff4SJamie Gritton error = vfs_getopt(opts, "linux.osname", (void **)&osname, &len);
3517ae27ff4SJamie Gritton if (error == ENOENT)
3527ae27ff4SJamie Gritton osname = NULL;
3537ae27ff4SJamie Gritton else
3547cbf7213SJamie Gritton jsys = JAIL_SYS_NEW;
3557ae27ff4SJamie Gritton error = vfs_getopt(opts, "linux.osrelease", (void **)&osrelease, &len);
3567ae27ff4SJamie Gritton if (error == ENOENT)
3577ae27ff4SJamie Gritton osrelease = NULL;
3587ae27ff4SJamie Gritton else
3597cbf7213SJamie Gritton jsys = JAIL_SYS_NEW;
3607ae27ff4SJamie Gritton error = vfs_copyopt(opts, "linux.oss_version", &oss_version,
3617ae27ff4SJamie Gritton sizeof(oss_version));
3627cbf7213SJamie Gritton if (error == ENOENT)
3637cbf7213SJamie Gritton gotversion = 0;
3647cbf7213SJamie Gritton else {
3657cbf7213SJamie Gritton gotversion = 1;
3667cbf7213SJamie Gritton jsys = JAIL_SYS_NEW;
3677cbf7213SJamie Gritton }
3687cbf7213SJamie Gritton switch (jsys) {
3697cbf7213SJamie Gritton case JAIL_SYS_INHERIT:
3707cbf7213SJamie Gritton /* "linux=inherit": inherit the parent's Linux info. */
3717ae27ff4SJamie Gritton mtx_lock(&pr->pr_mtx);
3727ae27ff4SJamie Gritton osd_jail_del(pr, linux_osd_jail_slot);
3737ae27ff4SJamie Gritton mtx_unlock(&pr->pr_mtx);
3747cbf7213SJamie Gritton break;
3757cbf7213SJamie Gritton case JAIL_SYS_NEW:
3767ae27ff4SJamie Gritton /*
3777cbf7213SJamie Gritton * "linux=new" or "linux.*":
3787ae27ff4SJamie Gritton * the prison gets its own Linux info.
3797ae27ff4SJamie Gritton */
3807ab25e3dSJamie Gritton linux_alloc_prison(pr, &lpr);
3817ae27ff4SJamie Gritton if (osrelease) {
382d56cf22dSJamie Gritton (void)linux_map_osrel(osrelease, &lpr->pr_osrel);
3837ae27ff4SJamie Gritton strlcpy(lpr->pr_osrelease, osrelease,
3847ae27ff4SJamie Gritton LINUX_MAX_UTSNAME);
3857ae27ff4SJamie Gritton }
386580dd797SDmitry Chagin if (osname)
387580dd797SDmitry Chagin strlcpy(lpr->pr_osname, osname, LINUX_MAX_UTSNAME);
3887ae27ff4SJamie Gritton if (gotversion)
3897ae27ff4SJamie Gritton lpr->pr_oss_version = oss_version;
3907ae27ff4SJamie Gritton mtx_unlock(&pr->pr_mtx);
3917ae27ff4SJamie Gritton }
39219e252baSAlexander Leidinger
3937ae27ff4SJamie Gritton return (0);
3947ae27ff4SJamie Gritton }
3957ae27ff4SJamie Gritton
3967cbf7213SJamie Gritton SYSCTL_JAIL_PARAM_SYS_NODE(linux, CTLFLAG_RW, "Jail Linux parameters");
3977ae27ff4SJamie Gritton SYSCTL_JAIL_PARAM_STRING(_linux, osname, CTLFLAG_RW, LINUX_MAX_UTSNAME,
3987ae27ff4SJamie Gritton "Jail Linux kernel OS name");
3997ae27ff4SJamie Gritton SYSCTL_JAIL_PARAM_STRING(_linux, osrelease, CTLFLAG_RW, LINUX_MAX_UTSNAME,
4007ae27ff4SJamie Gritton "Jail Linux kernel OS release");
4017ae27ff4SJamie Gritton SYSCTL_JAIL_PARAM(_linux, oss_version, CTLTYPE_INT | CTLFLAG_RW,
4027ae27ff4SJamie Gritton "I", "Jail Linux OSS version");
4037ae27ff4SJamie Gritton
4047ae27ff4SJamie Gritton static int
linux_prison_get(void * obj,void * data)4057ae27ff4SJamie Gritton linux_prison_get(void *obj, void *data)
4067ae27ff4SJamie Gritton {
4077ae27ff4SJamie Gritton struct linux_prison *lpr;
4080304c731SJamie Gritton struct prison *ppr;
4097ae27ff4SJamie Gritton struct prison *pr = obj;
4107ae27ff4SJamie Gritton struct vfsoptlist *opts = data;
4117ae27ff4SJamie Gritton int error, i;
4127ae27ff4SJamie Gritton
4130304c731SJamie Gritton static int version0;
4140304c731SJamie Gritton
4150304c731SJamie Gritton /* See if this prison is the one with the Linux info. */
4160304c731SJamie Gritton lpr = linux_find_prison(pr, &ppr);
4177cbf7213SJamie Gritton i = (ppr == pr) ? JAIL_SYS_NEW : JAIL_SYS_INHERIT;
4187ae27ff4SJamie Gritton error = vfs_setopt(opts, "linux", &i, sizeof(i));
41967d39748SDmitry Chagin if (error != 0 && error != ENOENT)
4207ae27ff4SJamie Gritton goto done;
4217cbf7213SJamie Gritton if (i) {
4227cbf7213SJamie Gritton error = vfs_setopts(opts, "linux.osname", lpr->pr_osname);
42367d39748SDmitry Chagin if (error != 0 && error != ENOENT)
4247ae27ff4SJamie Gritton goto done;
4257cbf7213SJamie Gritton error = vfs_setopts(opts, "linux.osrelease", lpr->pr_osrelease);
42667d39748SDmitry Chagin if (error != 0 && error != ENOENT)
4277cbf7213SJamie Gritton goto done;
4287cbf7213SJamie Gritton error = vfs_setopt(opts, "linux.oss_version",
4297cbf7213SJamie Gritton &lpr->pr_oss_version, sizeof(lpr->pr_oss_version));
43067d39748SDmitry Chagin if (error != 0 && error != ENOENT)
4317cbf7213SJamie Gritton goto done;
4327cbf7213SJamie Gritton } else {
4337ae27ff4SJamie Gritton /*
4340304c731SJamie Gritton * If this prison is inheriting its Linux info, report
4350304c731SJamie Gritton * empty/zero parameters.
4367ae27ff4SJamie Gritton */
4370304c731SJamie Gritton error = vfs_setopts(opts, "linux.osname", "");
43867d39748SDmitry Chagin if (error != 0 && error != ENOENT)
4390304c731SJamie Gritton goto done;
4400304c731SJamie Gritton error = vfs_setopts(opts, "linux.osrelease", "");
44167d39748SDmitry Chagin if (error != 0 && error != ENOENT)
4420304c731SJamie Gritton goto done;
4430304c731SJamie Gritton error = vfs_setopt(opts, "linux.oss_version", &version0,
4440304c731SJamie Gritton sizeof(lpr->pr_oss_version));
44567d39748SDmitry Chagin if (error != 0 && error != ENOENT)
4460304c731SJamie Gritton goto done;
4477ae27ff4SJamie Gritton }
4487ae27ff4SJamie Gritton error = 0;
4497ae27ff4SJamie Gritton
4507ae27ff4SJamie Gritton done:
4510304c731SJamie Gritton mtx_unlock(&ppr->pr_mtx);
45219e252baSAlexander Leidinger
4537ae27ff4SJamie Gritton return (error);
4547ae27ff4SJamie Gritton }
4557ae27ff4SJamie Gritton
4567ae27ff4SJamie Gritton static void
linux_prison_destructor(void * data)4577ae27ff4SJamie Gritton linux_prison_destructor(void *data)
4587ae27ff4SJamie Gritton {
4597ae27ff4SJamie Gritton
4607ae27ff4SJamie Gritton free(data, M_PRISON);
4617ae27ff4SJamie Gritton }
4627ae27ff4SJamie Gritton
4637ae27ff4SJamie Gritton void
linux_osd_jail_register(void)4647ae27ff4SJamie Gritton linux_osd_jail_register(void)
4657ae27ff4SJamie Gritton {
4667ae27ff4SJamie Gritton struct prison *pr;
4677ae27ff4SJamie Gritton osd_method_t methods[PR_MAXMETHOD] = {
4687ae27ff4SJamie Gritton [PR_METHOD_CREATE] = linux_prison_create,
4697ae27ff4SJamie Gritton [PR_METHOD_GET] = linux_prison_get,
4707ae27ff4SJamie Gritton [PR_METHOD_SET] = linux_prison_set,
4717ae27ff4SJamie Gritton [PR_METHOD_CHECK] = linux_prison_check
4727ae27ff4SJamie Gritton };
4737ae27ff4SJamie Gritton
4747ae27ff4SJamie Gritton linux_osd_jail_slot =
4757ae27ff4SJamie Gritton osd_jail_register(linux_prison_destructor, methods);
476eae594f7SEd Maste /* Copy the system Linux info to any current prisons. */
4777ab25e3dSJamie Gritton sx_slock(&allprison_lock);
4780304c731SJamie Gritton TAILQ_FOREACH(pr, &allprison, pr_list)
4797ab25e3dSJamie Gritton linux_alloc_prison(pr, NULL);
4807ab25e3dSJamie Gritton sx_sunlock(&allprison_lock);
4817ae27ff4SJamie Gritton }
4827ae27ff4SJamie Gritton
4837ae27ff4SJamie Gritton void
linux_osd_jail_deregister(void)4847ae27ff4SJamie Gritton linux_osd_jail_deregister(void)
4857ae27ff4SJamie Gritton {
4867ae27ff4SJamie Gritton
4877ae27ff4SJamie Gritton osd_jail_deregister(linux_osd_jail_slot);
488c6dfea0eSMarcel Moolenaar }
489c6dfea0eSMarcel Moolenaar
49001137630SRobert Watson void
linux_get_osname(struct thread * td,char * dst)491b62f75cfSJohn Baldwin linux_get_osname(struct thread *td, char *dst)
492c6dfea0eSMarcel Moolenaar {
4937ae27ff4SJamie Gritton struct prison *pr;
4947ae27ff4SJamie Gritton struct linux_prison *lpr;
495c6dfea0eSMarcel Moolenaar
4960304c731SJamie Gritton lpr = linux_find_prison(td->td_ucred->cr_prison, &pr);
49701137630SRobert Watson bcopy(lpr->pr_osname, dst, LINUX_MAX_UTSNAME);
49801137630SRobert Watson mtx_unlock(&pr->pr_mtx);
4997ae27ff4SJamie Gritton }
500c6dfea0eSMarcel Moolenaar
5010d7b5e54SAlexander Leidinger static int
linux_set_osname(struct thread * td,char * osname)502b62f75cfSJohn Baldwin linux_set_osname(struct thread *td, char *osname)
503c6dfea0eSMarcel Moolenaar {
504b62f75cfSJohn Baldwin struct prison *pr;
505b62f75cfSJohn Baldwin struct linux_prison *lpr;
506c6dfea0eSMarcel Moolenaar
5070304c731SJamie Gritton lpr = linux_find_prison(td->td_ucred->cr_prison, &pr);
5087ae27ff4SJamie Gritton strlcpy(lpr->pr_osname, osname, LINUX_MAX_UTSNAME);
509b62f75cfSJohn Baldwin mtx_unlock(&pr->pr_mtx);
51019e252baSAlexander Leidinger
511c6dfea0eSMarcel Moolenaar return (0);
512c6dfea0eSMarcel Moolenaar }
513c6dfea0eSMarcel Moolenaar
51401137630SRobert Watson void
linux_get_osrelease(struct thread * td,char * dst)515b62f75cfSJohn Baldwin linux_get_osrelease(struct thread *td, char *dst)
516c6dfea0eSMarcel Moolenaar {
5177ae27ff4SJamie Gritton struct prison *pr;
51801137630SRobert Watson struct linux_prison *lpr;
519c6dfea0eSMarcel Moolenaar
5200304c731SJamie Gritton lpr = linux_find_prison(td->td_ucred->cr_prison, &pr);
5217ae27ff4SJamie Gritton bcopy(lpr->pr_osrelease, dst, LINUX_MAX_UTSNAME);
52201137630SRobert Watson mtx_unlock(&pr->pr_mtx);
5237ae27ff4SJamie Gritton }
524c6dfea0eSMarcel Moolenaar
525c6dfea0eSMarcel Moolenaar int
linux_kernver(struct thread * td)526580dd797SDmitry Chagin linux_kernver(struct thread *td)
5279ce8f9bcSAlexander Leidinger {
5289ce8f9bcSAlexander Leidinger struct prison *pr;
5299ce8f9bcSAlexander Leidinger struct linux_prison *lpr;
530580dd797SDmitry Chagin int osrel;
5319ce8f9bcSAlexander Leidinger
5320304c731SJamie Gritton lpr = linux_find_prison(td->td_ucred->cr_prison, &pr);
533580dd797SDmitry Chagin osrel = lpr->pr_osrel;
5347ae27ff4SJamie Gritton mtx_unlock(&pr->pr_mtx);
53519e252baSAlexander Leidinger
536580dd797SDmitry Chagin return (osrel);
5379ce8f9bcSAlexander Leidinger }
5389ce8f9bcSAlexander Leidinger
5390d7b5e54SAlexander Leidinger static int
linux_set_osrelease(struct thread * td,char * osrelease)540b62f75cfSJohn Baldwin linux_set_osrelease(struct thread *td, char *osrelease)
541c6dfea0eSMarcel Moolenaar {
542b62f75cfSJohn Baldwin struct prison *pr;
543b62f75cfSJohn Baldwin struct linux_prison *lpr;
544580dd797SDmitry Chagin int error;
5459ce8f9bcSAlexander Leidinger
5460304c731SJamie Gritton lpr = linux_find_prison(td->td_ucred->cr_prison, &pr);
547580dd797SDmitry Chagin error = linux_map_osrel(osrelease, &lpr->pr_osrel);
5480304c731SJamie Gritton if (error == 0)
5497ae27ff4SJamie Gritton strlcpy(lpr->pr_osrelease, osrelease, LINUX_MAX_UTSNAME);
550b62f75cfSJohn Baldwin mtx_unlock(&pr->pr_mtx);
55119e252baSAlexander Leidinger
552580dd797SDmitry Chagin return (error);
553580dd797SDmitry Chagin }
554c6dfea0eSMarcel Moolenaar
555c6dfea0eSMarcel Moolenaar int
linux_get_oss_version(struct thread * td)556b62f75cfSJohn Baldwin linux_get_oss_version(struct thread *td)
557c6dfea0eSMarcel Moolenaar {
5587ae27ff4SJamie Gritton struct prison *pr;
5597ae27ff4SJamie Gritton struct linux_prison *lpr;
56001137630SRobert Watson int version;
56101137630SRobert Watson
5620304c731SJamie Gritton lpr = linux_find_prison(td->td_ucred->cr_prison, &pr);
56301137630SRobert Watson version = lpr->pr_oss_version;
564b62f75cfSJohn Baldwin mtx_unlock(&pr->pr_mtx);
56519e252baSAlexander Leidinger
56601137630SRobert Watson return (version);
567c6dfea0eSMarcel Moolenaar }
568c6dfea0eSMarcel Moolenaar
5690d7b5e54SAlexander Leidinger static int
linux_set_oss_version(struct thread * td,int oss_version)570b62f75cfSJohn Baldwin linux_set_oss_version(struct thread *td, int oss_version)
571c6dfea0eSMarcel Moolenaar {
572b62f75cfSJohn Baldwin struct prison *pr;
573b62f75cfSJohn Baldwin struct linux_prison *lpr;
574c6dfea0eSMarcel Moolenaar
5750304c731SJamie Gritton lpr = linux_find_prison(td->td_ucred->cr_prison, &pr);
576c6dfea0eSMarcel Moolenaar lpr->pr_oss_version = oss_version;
577b62f75cfSJohn Baldwin mtx_unlock(&pr->pr_mtx);
57819e252baSAlexander Leidinger
579c6dfea0eSMarcel Moolenaar return (0);
580c6dfea0eSMarcel Moolenaar }
581