1f5bde65dSMarcel Moolenaar /*-
24d846d26SWarner Losh * SPDX-License-Identifier: BSD-2-Clause
37f2d13d6SPedro F. Giffuni *
4f5bde65dSMarcel Moolenaar * Copyright (c) 2001 The FreeBSD Project
5f5bde65dSMarcel Moolenaar * All rights reserved.
6f5bde65dSMarcel Moolenaar *
7f5bde65dSMarcel Moolenaar * Redistribution and use in source and binary forms, with or without
8f5bde65dSMarcel Moolenaar * modification, are permitted provided that the following conditions
9f5bde65dSMarcel Moolenaar * are met:
10f5bde65dSMarcel Moolenaar * 1. Redistributions of source code must retain the above copyright
11f5bde65dSMarcel Moolenaar * notice, this list of conditions and the following disclaimer.
12f5bde65dSMarcel Moolenaar * 2. Redistributions in binary form must reproduce the above copyright
13f5bde65dSMarcel Moolenaar * notice, this list of conditions and the following disclaimer in the
14f5bde65dSMarcel Moolenaar * documentation and/or other materials provided with the distribution.
15f5bde65dSMarcel Moolenaar *
16f5bde65dSMarcel Moolenaar * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17f5bde65dSMarcel Moolenaar * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18f5bde65dSMarcel Moolenaar * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19f5bde65dSMarcel Moolenaar * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20f5bde65dSMarcel Moolenaar * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21f5bde65dSMarcel Moolenaar * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22f5bde65dSMarcel Moolenaar * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23f5bde65dSMarcel Moolenaar * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24f5bde65dSMarcel Moolenaar * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25f5bde65dSMarcel Moolenaar * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26f5bde65dSMarcel Moolenaar * SUCH DAMAGE.
27f5bde65dSMarcel Moolenaar */
28f5bde65dSMarcel Moolenaar
29f5bde65dSMarcel Moolenaar #include <sys/param.h>
30d8e53d94SDmitry Chagin #include <sys/fcntl.h>
31094a9455SJohn Baldwin #include <sys/lock.h>
3285422e62SBruce Evans #include <sys/malloc.h>
33094a9455SJohn Baldwin #include <sys/mutex.h>
34acd3428bSRobert Watson #include <sys/priv.h>
35f5bde65dSMarcel Moolenaar #include <sys/proc.h>
36206a5d3aSIan Dowse #include <sys/syscallsubr.h>
37f5bde65dSMarcel Moolenaar #include <sys/sysproto.h>
38f5bde65dSMarcel Moolenaar
391997c537SDavid E. O'Brien #ifdef COMPAT_LINUX32
404af27623STim J. Robbins #include <machine/../linux32/linux.h>
414af27623STim J. Robbins #include <machine/../linux32/linux32_proto.h>
421997c537SDavid E. O'Brien #else
431997c537SDavid E. O'Brien #include <machine/../linux/linux.h>
441997c537SDavid E. O'Brien #include <machine/../linux/linux_proto.h>
454af27623STim J. Robbins #endif
4685422e62SBruce Evans
4719e252baSAlexander Leidinger #include <compat/linux/linux_dtrace.h>
48f5bde65dSMarcel Moolenaar #include <compat/linux/linux_util.h>
49f5bde65dSMarcel Moolenaar
5019e252baSAlexander Leidinger /* DTrace init */
5119e252baSAlexander Leidinger LIN_SDT_PROVIDER_DECLARE(LINUX_DTRACE);
5219e252baSAlexander Leidinger
5319e252baSAlexander Leidinger /**
5419e252baSAlexander Leidinger * DTrace probes in this module.
5519e252baSAlexander Leidinger */
5619e252baSAlexander Leidinger LIN_SDT_PROBE_DEFINE1(uid16, linux_chown16, conv_path, "char *");
5719e252baSAlexander Leidinger LIN_SDT_PROBE_DEFINE1(uid16, linux_lchown16, conv_path, "char *");
5819e252baSAlexander Leidinger LIN_SDT_PROBE_DEFINE1(uid16, linux_setgroups16, copyin_error, "int");
5919e252baSAlexander Leidinger LIN_SDT_PROBE_DEFINE1(uid16, linux_setgroups16, priv_check_cred_error, "int");
6019e252baSAlexander Leidinger LIN_SDT_PROBE_DEFINE1(uid16, linux_getgroups16, copyout_error, "int");
6119e252baSAlexander Leidinger
62f5bde65dSMarcel Moolenaar DUMMY(setfsuid16);
63f5bde65dSMarcel Moolenaar DUMMY(setfsgid16);
64f5bde65dSMarcel Moolenaar DUMMY(getresuid16);
65f5bde65dSMarcel Moolenaar DUMMY(getresgid16);
66f5bde65dSMarcel Moolenaar
67206a5d3aSIan Dowse #define CAST_NOCHG(x) ((x == 0xFFFF) ? -1 : x)
68c640a5f5SMarcel Moolenaar
69f5bde65dSMarcel Moolenaar int
linux_chown16(struct thread * td,struct linux_chown16_args * args)70b40ce416SJulian Elischer linux_chown16(struct thread *td, struct linux_chown16_args *args)
71f5bde65dSMarcel Moolenaar {
72f5bde65dSMarcel Moolenaar
73*fd745e1dSDmitry Chagin return (kern_fchownat(td, AT_FDCWD, args->path, UIO_USERSPACE,
74*fd745e1dSDmitry Chagin CAST_NOCHG(args->uid), CAST_NOCHG(args->gid), 0));
75f5bde65dSMarcel Moolenaar }
76f5bde65dSMarcel Moolenaar
77f5bde65dSMarcel Moolenaar int
linux_lchown16(struct thread * td,struct linux_lchown16_args * args)78b40ce416SJulian Elischer linux_lchown16(struct thread *td, struct linux_lchown16_args *args)
79f5bde65dSMarcel Moolenaar {
80f5bde65dSMarcel Moolenaar
81*fd745e1dSDmitry Chagin return (kern_fchownat(td, AT_FDCWD, args->path, UIO_USERSPACE,
82*fd745e1dSDmitry Chagin CAST_NOCHG(args->uid), CAST_NOCHG(args->gid), AT_SYMLINK_NOFOLLOW));
83f5bde65dSMarcel Moolenaar }
84f5bde65dSMarcel Moolenaar
85f5bde65dSMarcel Moolenaar int
linux_setgroups16(struct thread * td,struct linux_setgroups16_args * args)86b40ce416SJulian Elischer linux_setgroups16(struct thread *td, struct linux_setgroups16_args *args)
87f5bde65dSMarcel Moolenaar {
88f5bde65dSMarcel Moolenaar struct ucred *newcred, *oldcred;
89838d9858SBrooks Davis l_gid16_t *linux_gidset;
90f5bde65dSMarcel Moolenaar gid_t *bsd_gidset;
91f5bde65dSMarcel Moolenaar int ngrp, error;
92094a9455SJohn Baldwin struct proc *p;
93f5bde65dSMarcel Moolenaar
94f5bde65dSMarcel Moolenaar ngrp = args->gidsetsize;
955e8caee2SEdward Tomasz Napierala if (ngrp < 0 || ngrp >= ngroups_max + 1)
96094a9455SJohn Baldwin return (EINVAL);
97e0d3ea8cSDmitry Chagin linux_gidset = malloc(ngrp * sizeof(*linux_gidset), M_LINUX, M_WAITOK);
984b7ef73dSDag-Erling Smørgrav error = copyin(args->gidset, linux_gidset, ngrp * sizeof(l_gid16_t));
99796fa5e4SChristian Brueffer if (error) {
10019e252baSAlexander Leidinger LIN_SDT_PROBE1(uid16, linux_setgroups16, copyin_error, error);
101e0d3ea8cSDmitry Chagin free(linux_gidset, M_LINUX);
102094a9455SJohn Baldwin return (error);
103796fa5e4SChristian Brueffer }
104094a9455SJohn Baldwin newcred = crget();
105094a9455SJohn Baldwin p = td->td_proc;
106094a9455SJohn Baldwin PROC_LOCK(p);
107838d9858SBrooks Davis oldcred = crcopysafe(p, newcred);
108f5bde65dSMarcel Moolenaar
109f5bde65dSMarcel Moolenaar /*
110f5bde65dSMarcel Moolenaar * cr_groups[0] holds egid. Setting the whole set from
111f5bde65dSMarcel Moolenaar * the supplied set will cause egid to be changed too.
112f5bde65dSMarcel Moolenaar * Keep cr_groups[0] unchanged to prevent that.
113f5bde65dSMarcel Moolenaar */
114f5bde65dSMarcel Moolenaar
115cc426dd3SMateusz Guzik if ((error = priv_check_cred(oldcred, PRIV_CRED_SETGROUPS)) != 0) {
116094a9455SJohn Baldwin PROC_UNLOCK(p);
117094a9455SJohn Baldwin crfree(newcred);
11819e252baSAlexander Leidinger
11919e252baSAlexander Leidinger LIN_SDT_PROBE1(uid16, linux_setgroups16, priv_check_cred_error,
12019e252baSAlexander Leidinger error);
121838d9858SBrooks Davis goto out;
122094a9455SJohn Baldwin }
123f5bde65dSMarcel Moolenaar
124f5bde65dSMarcel Moolenaar if (ngrp > 0) {
125f5bde65dSMarcel Moolenaar newcred->cr_ngroups = ngrp + 1;
126f5bde65dSMarcel Moolenaar
127f5bde65dSMarcel Moolenaar bsd_gidset = newcred->cr_groups;
128f5bde65dSMarcel Moolenaar ngrp--;
129f5bde65dSMarcel Moolenaar while (ngrp >= 0) {
130f5bde65dSMarcel Moolenaar bsd_gidset[ngrp + 1] = linux_gidset[ngrp];
131f5bde65dSMarcel Moolenaar ngrp--;
132f5bde65dSMarcel Moolenaar }
133f5bde65dSMarcel Moolenaar }
134f5bde65dSMarcel Moolenaar else
135f5bde65dSMarcel Moolenaar newcred->cr_ngroups = 1;
136f5bde65dSMarcel Moolenaar
137b40ce416SJulian Elischer setsugid(td->td_proc);
138daf63fd2SMateusz Guzik proc_set_cred(p, newcred);
139094a9455SJohn Baldwin PROC_UNLOCK(p);
140f5bde65dSMarcel Moolenaar crfree(oldcred);
141838d9858SBrooks Davis error = 0;
142838d9858SBrooks Davis out:
143e0d3ea8cSDmitry Chagin free(linux_gidset, M_LINUX);
14419e252baSAlexander Leidinger
145838d9858SBrooks Davis return (error);
146f5bde65dSMarcel Moolenaar }
147f5bde65dSMarcel Moolenaar
148f5bde65dSMarcel Moolenaar int
linux_getgroups16(struct thread * td,struct linux_getgroups16_args * args)149b40ce416SJulian Elischer linux_getgroups16(struct thread *td, struct linux_getgroups16_args *args)
150f5bde65dSMarcel Moolenaar {
151f5bde65dSMarcel Moolenaar struct ucred *cred;
152838d9858SBrooks Davis l_gid16_t *linux_gidset;
153f5bde65dSMarcel Moolenaar gid_t *bsd_gidset;
154f5bde65dSMarcel Moolenaar int bsd_gidsetsz, ngrp, error;
155f5bde65dSMarcel Moolenaar
156a854ed98SJohn Baldwin cred = td->td_ucred;
157f5bde65dSMarcel Moolenaar bsd_gidset = cred->cr_groups;
158f5bde65dSMarcel Moolenaar bsd_gidsetsz = cred->cr_ngroups - 1;
159f5bde65dSMarcel Moolenaar
160f5bde65dSMarcel Moolenaar /*
161f5bde65dSMarcel Moolenaar * cr_groups[0] holds egid. Returning the whole set
162f5bde65dSMarcel Moolenaar * here will cause a duplicate. Exclude cr_groups[0]
163f5bde65dSMarcel Moolenaar * to prevent that.
164f5bde65dSMarcel Moolenaar */
165f5bde65dSMarcel Moolenaar
166f5bde65dSMarcel Moolenaar if ((ngrp = args->gidsetsize) == 0) {
167b40ce416SJulian Elischer td->td_retval[0] = bsd_gidsetsz;
168f5bde65dSMarcel Moolenaar return (0);
169f5bde65dSMarcel Moolenaar }
170f5bde65dSMarcel Moolenaar
1715e8caee2SEdward Tomasz Napierala if (ngrp < bsd_gidsetsz)
172f5bde65dSMarcel Moolenaar return (EINVAL);
173f5bde65dSMarcel Moolenaar
174f5bde65dSMarcel Moolenaar ngrp = 0;
175838d9858SBrooks Davis linux_gidset = malloc(bsd_gidsetsz * sizeof(*linux_gidset),
176e0d3ea8cSDmitry Chagin M_LINUX, M_WAITOK);
177f5bde65dSMarcel Moolenaar while (ngrp < bsd_gidsetsz) {
178f5bde65dSMarcel Moolenaar linux_gidset[ngrp] = bsd_gidset[ngrp + 1];
179f5bde65dSMarcel Moolenaar ngrp++;
180f5bde65dSMarcel Moolenaar }
181f5bde65dSMarcel Moolenaar
1824b7ef73dSDag-Erling Smørgrav error = copyout(linux_gidset, args->gidset, ngrp * sizeof(l_gid16_t));
183e0d3ea8cSDmitry Chagin free(linux_gidset, M_LINUX);
18419e252baSAlexander Leidinger if (error) {
18519e252baSAlexander Leidinger LIN_SDT_PROBE1(uid16, linux_getgroups16, copyout_error, error);
186f5bde65dSMarcel Moolenaar return (error);
18719e252baSAlexander Leidinger }
188f5bde65dSMarcel Moolenaar
189b40ce416SJulian Elischer td->td_retval[0] = ngrp;
19019e252baSAlexander Leidinger
191f5bde65dSMarcel Moolenaar return (0);
192f5bde65dSMarcel Moolenaar }
193f5bde65dSMarcel Moolenaar
194f5bde65dSMarcel Moolenaar int
linux_getgid16(struct thread * td,struct linux_getgid16_args * args)195b40ce416SJulian Elischer linux_getgid16(struct thread *td, struct linux_getgid16_args *args)
196f5bde65dSMarcel Moolenaar {
197b40ce416SJulian Elischer
198a854ed98SJohn Baldwin td->td_retval[0] = td->td_ucred->cr_rgid;
19919e252baSAlexander Leidinger
200f5bde65dSMarcel Moolenaar return (0);
201f5bde65dSMarcel Moolenaar }
202f5bde65dSMarcel Moolenaar
203f5bde65dSMarcel Moolenaar int
linux_getuid16(struct thread * td,struct linux_getuid16_args * args)204b40ce416SJulian Elischer linux_getuid16(struct thread *td, struct linux_getuid16_args *args)
205f5bde65dSMarcel Moolenaar {
206b40ce416SJulian Elischer
207a854ed98SJohn Baldwin td->td_retval[0] = td->td_ucred->cr_ruid;
20819e252baSAlexander Leidinger
209f5bde65dSMarcel Moolenaar return (0);
210f5bde65dSMarcel Moolenaar }
211f5bde65dSMarcel Moolenaar
212f5bde65dSMarcel Moolenaar int
linux_getegid16(struct thread * td,struct linux_getegid16_args * args)213b40ce416SJulian Elischer linux_getegid16(struct thread *td, struct linux_getegid16_args *args)
214f5bde65dSMarcel Moolenaar {
215f5bde65dSMarcel Moolenaar struct getegid_args bsd;
21619e252baSAlexander Leidinger int error;
217f5bde65dSMarcel Moolenaar
21819e252baSAlexander Leidinger error = sys_getegid(td, &bsd);
21919e252baSAlexander Leidinger
22019e252baSAlexander Leidinger return (error);
221f5bde65dSMarcel Moolenaar }
222f5bde65dSMarcel Moolenaar
223f5bde65dSMarcel Moolenaar int
linux_geteuid16(struct thread * td,struct linux_geteuid16_args * args)224b40ce416SJulian Elischer linux_geteuid16(struct thread *td, struct linux_geteuid16_args *args)
225f5bde65dSMarcel Moolenaar {
226f5bde65dSMarcel Moolenaar struct geteuid_args bsd;
22719e252baSAlexander Leidinger int error;
228f5bde65dSMarcel Moolenaar
22919e252baSAlexander Leidinger error = sys_geteuid(td, &bsd);
23019e252baSAlexander Leidinger
23119e252baSAlexander Leidinger return (error);
232f5bde65dSMarcel Moolenaar }
233f5bde65dSMarcel Moolenaar
234f5bde65dSMarcel Moolenaar int
linux_setgid16(struct thread * td,struct linux_setgid16_args * args)235b40ce416SJulian Elischer linux_setgid16(struct thread *td, struct linux_setgid16_args *args)
236f5bde65dSMarcel Moolenaar {
237f5bde65dSMarcel Moolenaar struct setgid_args bsd;
23819e252baSAlexander Leidinger int error;
23919e252baSAlexander Leidinger
240f5bde65dSMarcel Moolenaar bsd.gid = args->gid;
24119e252baSAlexander Leidinger error = sys_setgid(td, &bsd);
24219e252baSAlexander Leidinger
24319e252baSAlexander Leidinger return (error);
244f5bde65dSMarcel Moolenaar }
245f5bde65dSMarcel Moolenaar
246f5bde65dSMarcel Moolenaar int
linux_setuid16(struct thread * td,struct linux_setuid16_args * args)247b40ce416SJulian Elischer linux_setuid16(struct thread *td, struct linux_setuid16_args *args)
248f5bde65dSMarcel Moolenaar {
249f5bde65dSMarcel Moolenaar struct setuid_args bsd;
25019e252baSAlexander Leidinger int error;
25119e252baSAlexander Leidinger
252f5bde65dSMarcel Moolenaar bsd.uid = args->uid;
25319e252baSAlexander Leidinger error = sys_setuid(td, &bsd);
25419e252baSAlexander Leidinger
25519e252baSAlexander Leidinger return (error);
256f5bde65dSMarcel Moolenaar }
257f5bde65dSMarcel Moolenaar
258f5bde65dSMarcel Moolenaar int
linux_setregid16(struct thread * td,struct linux_setregid16_args * args)259b40ce416SJulian Elischer linux_setregid16(struct thread *td, struct linux_setregid16_args *args)
260f5bde65dSMarcel Moolenaar {
261f5bde65dSMarcel Moolenaar struct setregid_args bsd;
26219e252baSAlexander Leidinger int error;
26319e252baSAlexander Leidinger
264c640a5f5SMarcel Moolenaar bsd.rgid = CAST_NOCHG(args->rgid);
265c640a5f5SMarcel Moolenaar bsd.egid = CAST_NOCHG(args->egid);
26619e252baSAlexander Leidinger error = sys_setregid(td, &bsd);
26719e252baSAlexander Leidinger
26819e252baSAlexander Leidinger return (error);
269f5bde65dSMarcel Moolenaar }
270f5bde65dSMarcel Moolenaar
271f5bde65dSMarcel Moolenaar int
linux_setreuid16(struct thread * td,struct linux_setreuid16_args * args)272b40ce416SJulian Elischer linux_setreuid16(struct thread *td, struct linux_setreuid16_args *args)
273f5bde65dSMarcel Moolenaar {
274f5bde65dSMarcel Moolenaar struct setreuid_args bsd;
27519e252baSAlexander Leidinger int error;
27619e252baSAlexander Leidinger
277c640a5f5SMarcel Moolenaar bsd.ruid = CAST_NOCHG(args->ruid);
278c640a5f5SMarcel Moolenaar bsd.euid = CAST_NOCHG(args->euid);
27919e252baSAlexander Leidinger error = sys_setreuid(td, &bsd);
28019e252baSAlexander Leidinger
28119e252baSAlexander Leidinger return (error);
282f5bde65dSMarcel Moolenaar }
283f5bde65dSMarcel Moolenaar
284f5bde65dSMarcel Moolenaar int
linux_setresgid16(struct thread * td,struct linux_setresgid16_args * args)285b40ce416SJulian Elischer linux_setresgid16(struct thread *td, struct linux_setresgid16_args *args)
286f5bde65dSMarcel Moolenaar {
287f5bde65dSMarcel Moolenaar struct setresgid_args bsd;
28819e252baSAlexander Leidinger int error;
28919e252baSAlexander Leidinger
290c640a5f5SMarcel Moolenaar bsd.rgid = CAST_NOCHG(args->rgid);
291c640a5f5SMarcel Moolenaar bsd.egid = CAST_NOCHG(args->egid);
292c640a5f5SMarcel Moolenaar bsd.sgid = CAST_NOCHG(args->sgid);
29319e252baSAlexander Leidinger error = sys_setresgid(td, &bsd);
29419e252baSAlexander Leidinger
29519e252baSAlexander Leidinger return (error);
296f5bde65dSMarcel Moolenaar }
297f5bde65dSMarcel Moolenaar
298f5bde65dSMarcel Moolenaar int
linux_setresuid16(struct thread * td,struct linux_setresuid16_args * args)299b40ce416SJulian Elischer linux_setresuid16(struct thread *td, struct linux_setresuid16_args *args)
300f5bde65dSMarcel Moolenaar {
301f5bde65dSMarcel Moolenaar struct setresuid_args bsd;
30219e252baSAlexander Leidinger int error;
30319e252baSAlexander Leidinger
304c640a5f5SMarcel Moolenaar bsd.ruid = CAST_NOCHG(args->ruid);
305c640a5f5SMarcel Moolenaar bsd.euid = CAST_NOCHG(args->euid);
306c640a5f5SMarcel Moolenaar bsd.suid = CAST_NOCHG(args->suid);
30719e252baSAlexander Leidinger error = sys_setresuid(td, &bsd);
30819e252baSAlexander Leidinger
30919e252baSAlexander Leidinger return (error);
310f5bde65dSMarcel Moolenaar }
311