xref: /freebsd/sys/compat/linux/linux_uid16.c (revision 5ab1c5846ff41be24b1f6beb0317bf8258cd4409)
1 /*-
2  * SPDX-License-Identifier: BSD-2-Clause-FreeBSD
3  *
4  * Copyright (c) 2001  The FreeBSD Project
5  * All rights reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted provided that the following conditions
9  * are met:
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  *
16  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26  * SUCH DAMAGE.
27  */
28 
29 #include <sys/cdefs.h>
30 __FBSDID("$FreeBSD$");
31 
32 #include "opt_compat.h"
33 
34 #include <sys/fcntl.h>
35 #include <sys/param.h>
36 #include <sys/kernel.h>
37 #include <sys/lock.h>
38 #include <sys/malloc.h>
39 #include <sys/mutex.h>
40 #include <sys/priv.h>
41 #include <sys/proc.h>
42 #include <sys/sdt.h>
43 #include <sys/syscallsubr.h>
44 #include <sys/sysproto.h>
45 #include <sys/systm.h>
46 
47 #ifdef COMPAT_LINUX32
48 #include <machine/../linux32/linux.h>
49 #include <machine/../linux32/linux32_proto.h>
50 #else
51 #include <machine/../linux/linux.h>
52 #include <machine/../linux/linux_proto.h>
53 #endif
54 
55 #include <compat/linux/linux_dtrace.h>
56 #include <compat/linux/linux_util.h>
57 
58 /* DTrace init */
59 LIN_SDT_PROVIDER_DECLARE(LINUX_DTRACE);
60 
61 /**
62  * DTrace probes in this module.
63  */
64 LIN_SDT_PROBE_DEFINE3(uid16, linux_chown16, entry, "char *", "l_uid16_t",
65     "l_gid16_t");
66 LIN_SDT_PROBE_DEFINE1(uid16, linux_chown16, conv_path, "char *");
67 LIN_SDT_PROBE_DEFINE1(uid16, linux_chown16, return, "int");
68 LIN_SDT_PROBE_DEFINE3(uid16, linux_lchown16, entry, "char *", "l_uid16_t",
69     "l_gid16_t");
70 LIN_SDT_PROBE_DEFINE1(uid16, linux_lchown16, conv_path, "char *");
71 LIN_SDT_PROBE_DEFINE1(uid16, linux_lchown16, return, "int");
72 LIN_SDT_PROBE_DEFINE2(uid16, linux_setgroups16, entry, "l_uint", "l_gid16_t *");
73 LIN_SDT_PROBE_DEFINE1(uid16, linux_setgroups16, copyin_error, "int");
74 LIN_SDT_PROBE_DEFINE1(uid16, linux_setgroups16, priv_check_cred_error, "int");
75 LIN_SDT_PROBE_DEFINE1(uid16, linux_setgroups16, return, "int");
76 LIN_SDT_PROBE_DEFINE2(uid16, linux_getgroups16, entry, "l_uint", "l_gid16_t *");
77 LIN_SDT_PROBE_DEFINE1(uid16, linux_getgroups16, copyout_error, "int");
78 LIN_SDT_PROBE_DEFINE1(uid16, linux_getgroups16, return, "int");
79 LIN_SDT_PROBE_DEFINE0(uid16, linux_getgid16, entry);
80 LIN_SDT_PROBE_DEFINE1(uid16, linux_getgid16, return, "int");
81 LIN_SDT_PROBE_DEFINE0(uid16, linux_getuid16, entry);
82 LIN_SDT_PROBE_DEFINE1(uid16, linux_getuid16, return, "int");
83 LIN_SDT_PROBE_DEFINE0(uid16, linux_getegid16, entry);
84 LIN_SDT_PROBE_DEFINE1(uid16, linux_getegid16, return, "int");
85 LIN_SDT_PROBE_DEFINE0(uid16, linux_geteuid16, entry);
86 LIN_SDT_PROBE_DEFINE1(uid16, linux_geteuid16, return, "int");
87 LIN_SDT_PROBE_DEFINE1(uid16, linux_setgid16, entry, "l_gid16_t");
88 LIN_SDT_PROBE_DEFINE1(uid16, linux_setgid16, return, "int");
89 LIN_SDT_PROBE_DEFINE1(uid16, linux_setuid16, entry, "l_uid16_t");
90 LIN_SDT_PROBE_DEFINE1(uid16, linux_setuid16, return, "int");
91 LIN_SDT_PROBE_DEFINE2(uid16, linux_setregid16, entry, "l_gid16_t", "l_gid16_t");
92 LIN_SDT_PROBE_DEFINE1(uid16, linux_setregid16, return, "int");
93 LIN_SDT_PROBE_DEFINE2(uid16, linux_setreuid16, entry, "l_uid16_t", "l_uid16_t");
94 LIN_SDT_PROBE_DEFINE1(uid16, linux_setreuid16, return, "int");
95 LIN_SDT_PROBE_DEFINE3(uid16, linux_setresgid16, entry, "l_gid16_t", "l_gid16_t",
96     "l_gid16_t");
97 LIN_SDT_PROBE_DEFINE1(uid16, linux_setresgid16, return, "int");
98 LIN_SDT_PROBE_DEFINE3(uid16, linux_setresuid16, entry, "l_uid16_t", "l_uid16_t",
99     "l_uid16_t");
100 LIN_SDT_PROBE_DEFINE1(uid16, linux_setresuid16, return, "int");
101 
102 DUMMY(setfsuid16);
103 DUMMY(setfsgid16);
104 DUMMY(getresuid16);
105 DUMMY(getresgid16);
106 
107 #define	CAST_NOCHG(x)	((x == 0xFFFF) ? -1 : x)
108 
109 int
110 linux_chown16(struct thread *td, struct linux_chown16_args *args)
111 {
112 	char *path;
113 	int error;
114 
115 	LCONVPATHEXIST(td, args->path, &path);
116 
117 	/*
118 	 * The DTrace probes have to be after the LCONVPATHEXIST, as
119 	 * LCONVPATHEXIST may return on its own and we do not want to
120 	 * have a stray entry without the corresponding return.
121 	 */
122 	LIN_SDT_PROBE3(uid16, linux_chown16, entry, args->path, args->uid,
123 	    args->gid);
124 	LIN_SDT_PROBE1(uid16, linux_chown16, conv_path, path);
125 
126 	error = kern_fchownat(td, AT_FDCWD, path, UIO_SYSSPACE,
127 	    CAST_NOCHG(args->uid), CAST_NOCHG(args->gid), 0);
128 	LFREEPATH(path);
129 
130 	LIN_SDT_PROBE1(uid16, linux_chown16, return, error);
131 	return (error);
132 }
133 
134 int
135 linux_lchown16(struct thread *td, struct linux_lchown16_args *args)
136 {
137 	char *path;
138 	int error;
139 
140 	LCONVPATHEXIST(td, args->path, &path);
141 
142 	/*
143 	 * The DTrace probes have to be after the LCONVPATHEXIST, as
144 	 * LCONVPATHEXIST may return on its own and we do not want to
145 	 * have a stray entry without the corresponding return.
146 	 */
147 	LIN_SDT_PROBE3(uid16, linux_lchown16, entry, args->path, args->uid,
148 	    args->gid);
149 	LIN_SDT_PROBE1(uid16, linux_lchown16, conv_path, path);
150 
151 	error = kern_fchownat(td, AT_FDCWD, path, UIO_SYSSPACE,
152 	    CAST_NOCHG(args->uid), CAST_NOCHG(args->gid), AT_SYMLINK_NOFOLLOW);
153 	LFREEPATH(path);
154 
155 	LIN_SDT_PROBE1(uid16, linux_lchown16, return, error);
156 	return (error);
157 }
158 
159 int
160 linux_setgroups16(struct thread *td, struct linux_setgroups16_args *args)
161 {
162 	struct ucred *newcred, *oldcred;
163 	l_gid16_t *linux_gidset;
164 	gid_t *bsd_gidset;
165 	int ngrp, error;
166 	struct proc *p;
167 
168 	LIN_SDT_PROBE2(uid16, linux_setgroups16, entry, args->gidsetsize,
169 	    args->gidset);
170 
171 	ngrp = args->gidsetsize;
172 	if (ngrp < 0 || ngrp >= ngroups_max + 1) {
173 		LIN_SDT_PROBE1(uid16, linux_setgroups16, return, EINVAL);
174 		return (EINVAL);
175 	}
176 	linux_gidset = malloc(ngrp * sizeof(*linux_gidset), M_LINUX, M_WAITOK);
177 	error = copyin(args->gidset, linux_gidset, ngrp * sizeof(l_gid16_t));
178 	if (error) {
179 		LIN_SDT_PROBE1(uid16, linux_setgroups16, copyin_error, error);
180 		LIN_SDT_PROBE1(uid16, linux_setgroups16, return, error);
181 		free(linux_gidset, M_LINUX);
182 		return (error);
183 	}
184 	newcred = crget();
185 	p = td->td_proc;
186 	PROC_LOCK(p);
187 	oldcred = crcopysafe(p, newcred);
188 
189 	/*
190 	 * cr_groups[0] holds egid. Setting the whole set from
191 	 * the supplied set will cause egid to be changed too.
192 	 * Keep cr_groups[0] unchanged to prevent that.
193 	 */
194 
195 	if ((error = priv_check_cred(oldcred, PRIV_CRED_SETGROUPS)) != 0) {
196 		PROC_UNLOCK(p);
197 		crfree(newcred);
198 
199 		LIN_SDT_PROBE1(uid16, linux_setgroups16, priv_check_cred_error,
200 		    error);
201 		goto out;
202 	}
203 
204 	if (ngrp > 0) {
205 		newcred->cr_ngroups = ngrp + 1;
206 
207 		bsd_gidset = newcred->cr_groups;
208 		ngrp--;
209 		while (ngrp >= 0) {
210 			bsd_gidset[ngrp + 1] = linux_gidset[ngrp];
211 			ngrp--;
212 		}
213 	}
214 	else
215 		newcred->cr_ngroups = 1;
216 
217 	setsugid(td->td_proc);
218 	proc_set_cred(p, newcred);
219 	PROC_UNLOCK(p);
220 	crfree(oldcred);
221 	error = 0;
222 out:
223 	free(linux_gidset, M_LINUX);
224 
225 	LIN_SDT_PROBE1(uid16, linux_setgroups16, return, error);
226 	return (error);
227 }
228 
229 int
230 linux_getgroups16(struct thread *td, struct linux_getgroups16_args *args)
231 {
232 	struct ucred *cred;
233 	l_gid16_t *linux_gidset;
234 	gid_t *bsd_gidset;
235 	int bsd_gidsetsz, ngrp, error;
236 
237 	LIN_SDT_PROBE2(uid16, linux_getgroups16, entry, args->gidsetsize,
238 	    args->gidset);
239 
240 	cred = td->td_ucred;
241 	bsd_gidset = cred->cr_groups;
242 	bsd_gidsetsz = cred->cr_ngroups - 1;
243 
244 	/*
245 	 * cr_groups[0] holds egid. Returning the whole set
246 	 * here will cause a duplicate. Exclude cr_groups[0]
247 	 * to prevent that.
248 	 */
249 
250 	if ((ngrp = args->gidsetsize) == 0) {
251 		td->td_retval[0] = bsd_gidsetsz;
252 
253 		LIN_SDT_PROBE1(uid16, linux_getgroups16, return, 0);
254 		return (0);
255 	}
256 
257 	if (ngrp < bsd_gidsetsz) {
258 		LIN_SDT_PROBE1(uid16, linux_getgroups16, return, EINVAL);
259 		return (EINVAL);
260 	}
261 
262 	ngrp = 0;
263 	linux_gidset = malloc(bsd_gidsetsz * sizeof(*linux_gidset),
264 	    M_LINUX, M_WAITOK);
265 	while (ngrp < bsd_gidsetsz) {
266 		linux_gidset[ngrp] = bsd_gidset[ngrp + 1];
267 		ngrp++;
268 	}
269 
270 	error = copyout(linux_gidset, args->gidset, ngrp * sizeof(l_gid16_t));
271 	free(linux_gidset, M_LINUX);
272 	if (error) {
273 		LIN_SDT_PROBE1(uid16, linux_getgroups16, copyout_error, error);
274 		LIN_SDT_PROBE1(uid16, linux_getgroups16, return, error);
275 		return (error);
276 	}
277 
278 	td->td_retval[0] = ngrp;
279 
280 	LIN_SDT_PROBE1(uid16, linux_getgroups16, return, 0);
281 	return (0);
282 }
283 
284 int
285 linux_getgid16(struct thread *td, struct linux_getgid16_args *args)
286 {
287 
288 	LIN_SDT_PROBE0(uid16, linux_getgid16, entry);
289 
290 	td->td_retval[0] = td->td_ucred->cr_rgid;
291 
292 	LIN_SDT_PROBE1(uid16, linux_getgid16, return, 0);
293 	return (0);
294 }
295 
296 int
297 linux_getuid16(struct thread *td, struct linux_getuid16_args *args)
298 {
299 
300 	LIN_SDT_PROBE0(uid16, linux_getuid16, entry);
301 
302 	td->td_retval[0] = td->td_ucred->cr_ruid;
303 
304 	LIN_SDT_PROBE1(uid16, linux_getuid16, return, 0);
305 	return (0);
306 }
307 
308 int
309 linux_getegid16(struct thread *td, struct linux_getegid16_args *args)
310 {
311 	struct getegid_args bsd;
312 	int error;
313 
314 	LIN_SDT_PROBE0(uid16, linux_getegid16, entry);
315 
316 	error = sys_getegid(td, &bsd);
317 
318 	LIN_SDT_PROBE1(uid16, linux_getegid16, return, error);
319 	return (error);
320 }
321 
322 int
323 linux_geteuid16(struct thread *td, struct linux_geteuid16_args *args)
324 {
325 	struct geteuid_args bsd;
326 	int error;
327 
328 	LIN_SDT_PROBE0(uid16, linux_geteuid16, entry);
329 
330 	error = sys_geteuid(td, &bsd);
331 
332 	LIN_SDT_PROBE1(uid16, linux_geteuid16, return, error);
333 	return (error);
334 }
335 
336 int
337 linux_setgid16(struct thread *td, struct linux_setgid16_args *args)
338 {
339 	struct setgid_args bsd;
340 	int error;
341 
342 	LIN_SDT_PROBE1(uid16, linux_setgid16, entry, args->gid);
343 
344 	bsd.gid = args->gid;
345 	error = sys_setgid(td, &bsd);
346 
347 	LIN_SDT_PROBE1(uid16, linux_setgid16, return, error);
348 	return (error);
349 }
350 
351 int
352 linux_setuid16(struct thread *td, struct linux_setuid16_args *args)
353 {
354 	struct setuid_args bsd;
355 	int error;
356 
357 	LIN_SDT_PROBE1(uid16, linux_setuid16, entry, args->uid);
358 
359 	bsd.uid = args->uid;
360 	error = sys_setuid(td, &bsd);
361 
362 	LIN_SDT_PROBE1(uid16, linux_setuid16, return, error);
363 	return (error);
364 }
365 
366 int
367 linux_setregid16(struct thread *td, struct linux_setregid16_args *args)
368 {
369 	struct setregid_args bsd;
370 	int error;
371 
372 	LIN_SDT_PROBE2(uid16, linux_setregid16, entry, args->rgid, args->egid);
373 
374 	bsd.rgid = CAST_NOCHG(args->rgid);
375 	bsd.egid = CAST_NOCHG(args->egid);
376 	error = sys_setregid(td, &bsd);
377 
378 	LIN_SDT_PROBE1(uid16, linux_setregid16, return, error);
379 	return (error);
380 }
381 
382 int
383 linux_setreuid16(struct thread *td, struct linux_setreuid16_args *args)
384 {
385 	struct setreuid_args bsd;
386 	int error;
387 
388 	LIN_SDT_PROBE2(uid16, linux_setreuid16, entry, args->ruid, args->euid);
389 
390 	bsd.ruid = CAST_NOCHG(args->ruid);
391 	bsd.euid = CAST_NOCHG(args->euid);
392 	error = sys_setreuid(td, &bsd);
393 
394 	LIN_SDT_PROBE1(uid16, linux_setreuid16, return, error);
395 	return (error);
396 }
397 
398 int
399 linux_setresgid16(struct thread *td, struct linux_setresgid16_args *args)
400 {
401 	struct setresgid_args bsd;
402 	int error;
403 
404 	LIN_SDT_PROBE3(uid16, linux_setresgid16, entry, args->rgid, args->egid,
405 	    args->sgid);
406 
407 	bsd.rgid = CAST_NOCHG(args->rgid);
408 	bsd.egid = CAST_NOCHG(args->egid);
409 	bsd.sgid = CAST_NOCHG(args->sgid);
410 	error = sys_setresgid(td, &bsd);
411 
412 	LIN_SDT_PROBE1(uid16, linux_setresgid16, return, error);
413 	return (error);
414 }
415 
416 int
417 linux_setresuid16(struct thread *td, struct linux_setresuid16_args *args)
418 {
419 	struct setresuid_args bsd;
420 	int error;
421 
422 	LIN_SDT_PROBE3(uid16, linux_setresuid16, entry, args->ruid, args->euid,
423 	    args->suid);
424 
425 	bsd.ruid = CAST_NOCHG(args->ruid);
426 	bsd.euid = CAST_NOCHG(args->euid);
427 	bsd.suid = CAST_NOCHG(args->suid);
428 	error = sys_setresuid(td, &bsd);
429 
430 	LIN_SDT_PROBE1(uid16, linux_setresuid16, return, error);
431 	return (error);
432 }
433