xref: /freebsd/sys/kern/imgact_binmisc.c (revision b888dae4c86e9f2989b3147f4411ae7cff5dcd5f)
16d756449SSean Bruno /*-
26d756449SSean Bruno  * Copyright (c) 2013, Stacey D. Son
36d756449SSean Bruno  * All rights reserved.
46d756449SSean Bruno  *
56d756449SSean Bruno  * Redistribution and use in source and binary forms, with or without
66d756449SSean Bruno  * modification, are permitted provided that the following conditions
76d756449SSean Bruno  * are met:
86d756449SSean Bruno  * 1. Redistributions of source code must retain the above copyright
96d756449SSean Bruno  *    notice, this list of conditions and the following disclaimer.
106d756449SSean Bruno  * 2. Redistributions in binary form must reproduce the above copyright
116d756449SSean Bruno  *    notice, this list of conditions and the following disclaimer in the
126d756449SSean Bruno  *    documentation and/or other materials provided with the distribution.
136d756449SSean Bruno  *
146d756449SSean Bruno  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
156d756449SSean Bruno  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
166d756449SSean Bruno  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
176d756449SSean Bruno  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
186d756449SSean Bruno  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
196d756449SSean Bruno  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
206d756449SSean Bruno  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
216d756449SSean Bruno  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
226d756449SSean Bruno  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
236d756449SSean Bruno  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
246d756449SSean Bruno  * SUCH DAMAGE.
256d756449SSean Bruno  */
266d756449SSean Bruno 
276d756449SSean Bruno #include <sys/cdefs.h>
286d756449SSean Bruno __FBSDID("$FreeBSD$");
296d756449SSean Bruno 
306d756449SSean Bruno #include <sys/param.h>
316d756449SSean Bruno #include <sys/ctype.h>
326d756449SSean Bruno #include <sys/sbuf.h>
336d756449SSean Bruno #include <sys/systm.h>
346d756449SSean Bruno #include <sys/sysproto.h>
356d756449SSean Bruno #include <sys/exec.h>
366d756449SSean Bruno #include <sys/imgact.h>
376d756449SSean Bruno #include <sys/imgact_binmisc.h>
386d756449SSean Bruno #include <sys/kernel.h>
396d756449SSean Bruno #include <sys/libkern.h>
406d756449SSean Bruno #include <sys/lock.h>
416d756449SSean Bruno #include <sys/malloc.h>
426d756449SSean Bruno #include <sys/mutex.h>
436d756449SSean Bruno #include <sys/sysctl.h>
446d756449SSean Bruno 
456d756449SSean Bruno /**
466d756449SSean Bruno  * Miscellaneous binary interpreter image activator.
476d756449SSean Bruno  *
486d756449SSean Bruno  * If the given target executable's header matches 'xbe_magic' field in the
496d756449SSean Bruno  * 'interpreter_list' then it will use the user-level interpreter specified in
506d756449SSean Bruno  * the 'xbe_interpreter' field to execute the binary. The 'xbe_magic' field may
516d756449SSean Bruno  * be adjusted to a given offset using the value in the 'xbe_moffset' field
526d756449SSean Bruno  * and bits of the header may be masked using the 'xbe_mask' field.  The
536d756449SSean Bruno  * 'interpreter_list' entries are managed using sysctl(3) as described in the
546d756449SSean Bruno  * <sys/imgact_binmisc.h> file.
556d756449SSean Bruno  */
566d756449SSean Bruno 
576d756449SSean Bruno /*
586d756449SSean Bruno  * Node of the interpreter list.
596d756449SSean Bruno  */
606d756449SSean Bruno typedef struct imgact_binmisc_entry {
616d756449SSean Bruno 	char				 *ibe_name;
626d756449SSean Bruno 	uint8_t				 *ibe_magic;
636d756449SSean Bruno 	uint32_t			  ibe_moffset;
646d756449SSean Bruno 	uint32_t			  ibe_msize;
656d756449SSean Bruno 	uint8_t				 *ibe_mask;
666d756449SSean Bruno 	uint8_t				 *ibe_interpreter;
676d756449SSean Bruno 	uint32_t			  ibe_interp_argcnt;
686d756449SSean Bruno 	uint32_t			  ibe_interp_length;
696d756449SSean Bruno 	uint32_t			  ibe_flags;
706d756449SSean Bruno 	SLIST_ENTRY(imgact_binmisc_entry) link;
716d756449SSean Bruno } imgact_binmisc_entry_t;
726d756449SSean Bruno 
736d756449SSean Bruno /*
746d756449SSean Bruno  * sysctl() commands.
756d756449SSean Bruno  */
766d756449SSean Bruno #define IBC_ADD		1	/* Add given entry. */
776d756449SSean Bruno #define IBC_REMOVE	2	/* Remove entry for a given name. */
786d756449SSean Bruno #define IBC_DISABLE	3	/* Disable entry for a given name. */
796d756449SSean Bruno #define IBC_ENABLE	4	/* Enable entry for a given name. */
806d756449SSean Bruno #define IBC_LOOKUP	5	/* Lookup and return entry for given name. */
816d756449SSean Bruno #define IBC_LIST	6	/* Get a snapshot of the interpretor list. */
826d756449SSean Bruno 
836d756449SSean Bruno /*
846d756449SSean Bruno  * Interpreter string macros.
856d756449SSean Bruno  *
866d756449SSean Bruno  * They all start with '#' followed by a single letter:
876d756449SSean Bruno  */
886d756449SSean Bruno #define	ISM_POUND	'#'	/* "##" is the escape sequence for single #. */
896d756449SSean Bruno #define	ISM_OLD_ARGV0	'a'	/* "#a" is replaced with the old argv0. */
906d756449SSean Bruno 
916d756449SSean Bruno MALLOC_DEFINE(M_BINMISC, KMOD_NAME, "misc binary image activator");
926d756449SSean Bruno 
936d756449SSean Bruno /* The interpreter list. */
946d756449SSean Bruno static SLIST_HEAD(, imgact_binmisc_entry) interpreter_list =
956d756449SSean Bruno 	SLIST_HEAD_INITIALIZER(interpreter_list);
966d756449SSean Bruno 
976d756449SSean Bruno static int interp_list_entry_count = 0;
986d756449SSean Bruno 
996d756449SSean Bruno static struct mtx interp_list_mtx;
1006d756449SSean Bruno 
1016d756449SSean Bruno int imgact_binmisc_exec(struct image_params *imgp);
1026d756449SSean Bruno 
1036d756449SSean Bruno 
1046d756449SSean Bruno /*
1056d756449SSean Bruno  * Populate the entry with the information about the interpreter.
1066d756449SSean Bruno  */
1076d756449SSean Bruno static void
1086d756449SSean Bruno imgact_binmisc_populate_interp(char *str, imgact_binmisc_entry_t *ibe)
1096d756449SSean Bruno {
1106d756449SSean Bruno 	uint32_t len = 0, argc = 1;
1116d756449SSean Bruno 	char t[IBE_INTERP_LEN_MAX];
1126d756449SSean Bruno 	char *sp, *tp;
1136d756449SSean Bruno 
1146d756449SSean Bruno 	bzero(t, sizeof(t));
1156d756449SSean Bruno 
1166d756449SSean Bruno 	/*
1176d756449SSean Bruno 	 * Normalize interpreter string. Replace white space between args with
1186d756449SSean Bruno 	 * single space.
1196d756449SSean Bruno 	 */
1206d756449SSean Bruno 	sp = str; tp = t;
1216d756449SSean Bruno 	while (*sp != '\0') {
1226d756449SSean Bruno 		if (*sp == ' ' || *sp == '\t') {
1236d756449SSean Bruno 			if (++len > IBE_INTERP_LEN_MAX)
1246d756449SSean Bruno 				break;
1256d756449SSean Bruno 			*tp++ = ' ';
1266d756449SSean Bruno 			argc++;
1276d756449SSean Bruno 			while (*sp == ' ' || *sp == '\t')
1286d756449SSean Bruno 				sp++;
1296d756449SSean Bruno 			continue;
1306d756449SSean Bruno 		} else {
1316d756449SSean Bruno 			*tp++ = *sp++;
1326d756449SSean Bruno 			len++;
1336d756449SSean Bruno 		}
1346d756449SSean Bruno 	}
1356d756449SSean Bruno 	*tp = '\0';
1366d756449SSean Bruno 	len++;
1376d756449SSean Bruno 
1386d756449SSean Bruno 	ibe->ibe_interpreter = malloc(len, M_BINMISC, M_WAITOK|M_ZERO);
1396d756449SSean Bruno 
1406d756449SSean Bruno 	/* Populate all the ibe fields for the interpreter. */
1416d756449SSean Bruno 	memcpy(ibe->ibe_interpreter, t, len);
1426d756449SSean Bruno 	ibe->ibe_interp_argcnt = argc;
1436d756449SSean Bruno 	ibe->ibe_interp_length = len;
1446d756449SSean Bruno }
1456d756449SSean Bruno 
1466d756449SSean Bruno /*
1476d756449SSean Bruno  * Allocate memory and populate a new entry for the interpreter table.
1486d756449SSean Bruno  */
1496d756449SSean Bruno static imgact_binmisc_entry_t *
1506d756449SSean Bruno imgact_binmisc_new_entry(ximgact_binmisc_entry_t *xbe)
1516d756449SSean Bruno {
1526d756449SSean Bruno 	imgact_binmisc_entry_t *ibe = NULL;
1536d756449SSean Bruno 	size_t namesz = min(strlen(xbe->xbe_name) + 1, IBE_NAME_MAX);
1546d756449SSean Bruno 
1556d756449SSean Bruno 	mtx_assert(&interp_list_mtx, MA_NOTOWNED);
1566d756449SSean Bruno 
1576d756449SSean Bruno 	ibe = malloc(sizeof(*ibe), M_BINMISC, M_WAITOK|M_ZERO);
1586d756449SSean Bruno 
1596d756449SSean Bruno 	ibe->ibe_name = malloc(namesz, M_BINMISC, M_WAITOK|M_ZERO);
1606d756449SSean Bruno 	strlcpy(ibe->ibe_name, xbe->xbe_name, namesz);
1616d756449SSean Bruno 
1626d756449SSean Bruno 	imgact_binmisc_populate_interp(xbe->xbe_interpreter, ibe);
1636d756449SSean Bruno 
1646d756449SSean Bruno 	ibe->ibe_magic = malloc(xbe->xbe_msize, M_BINMISC, M_WAITOK|M_ZERO);
1656d756449SSean Bruno 	memcpy(ibe->ibe_magic, xbe->xbe_magic, xbe->xbe_msize);
1666d756449SSean Bruno 
1676d756449SSean Bruno 	ibe->ibe_mask = malloc(xbe->xbe_msize, M_BINMISC, M_WAITOK|M_ZERO);
1686d756449SSean Bruno 	memcpy(ibe->ibe_mask, xbe->xbe_mask, xbe->xbe_msize);
1696d756449SSean Bruno 
1706d756449SSean Bruno 	ibe->ibe_moffset = xbe->xbe_moffset;
1716d756449SSean Bruno 	ibe->ibe_msize = xbe->xbe_msize;
1726d756449SSean Bruno 	ibe->ibe_flags = xbe->xbe_flags;
1736d756449SSean Bruno 
1746d756449SSean Bruno 	return (ibe);
1756d756449SSean Bruno }
1766d756449SSean Bruno 
1776d756449SSean Bruno /*
1786d756449SSean Bruno  * Free the allocated memory for a given list item.
1796d756449SSean Bruno  */
1806d756449SSean Bruno static void
1816d756449SSean Bruno imgact_binmisc_destroy_entry(imgact_binmisc_entry_t *ibe)
1826d756449SSean Bruno {
1836d756449SSean Bruno 	if (!ibe)
1846d756449SSean Bruno 		return;
185*b888dae4SSean Bruno 	if (ibe->ibe_magic)
1866d756449SSean Bruno 		free(ibe->ibe_magic, M_BINMISC);
1876d756449SSean Bruno 	if (ibe->ibe_mask)
1886d756449SSean Bruno 		free(ibe->ibe_mask, M_BINMISC);
1896d756449SSean Bruno 	if (ibe->ibe_interpreter)
1906d756449SSean Bruno 		free(ibe->ibe_interpreter, M_BINMISC);
1916d756449SSean Bruno 	if (ibe->ibe_name)
1926d756449SSean Bruno 		free(ibe->ibe_name, M_BINMISC);
1936d756449SSean Bruno 	if (ibe)
1946d756449SSean Bruno 		free(ibe, M_BINMISC);
1956d756449SSean Bruno }
1966d756449SSean Bruno 
1976d756449SSean Bruno /*
1986d756449SSean Bruno  * Find the interpreter in the list by the given name.  Return NULL if not
1996d756449SSean Bruno  * found.
2006d756449SSean Bruno  */
2016d756449SSean Bruno static imgact_binmisc_entry_t *
2026d756449SSean Bruno imgact_binmisc_find_entry(char *name)
2036d756449SSean Bruno {
2046d756449SSean Bruno 	imgact_binmisc_entry_t *ibe;
2056d756449SSean Bruno 
2066d756449SSean Bruno 	mtx_assert(&interp_list_mtx, MA_OWNED);
2076d756449SSean Bruno 
2086d756449SSean Bruno 	SLIST_FOREACH(ibe, &interpreter_list, link) {
2096d756449SSean Bruno 		if (strncmp(name, ibe->ibe_name, IBE_NAME_MAX) == 0)
2106d756449SSean Bruno 			return (ibe);
2116d756449SSean Bruno 	}
2126d756449SSean Bruno 
2136d756449SSean Bruno 	return (NULL);
2146d756449SSean Bruno }
2156d756449SSean Bruno 
2166d756449SSean Bruno /*
2176d756449SSean Bruno  * Add the given interpreter if it doesn't already exist.  Return EEXIST
2186d756449SSean Bruno  * if the name already exist in the interpreter list.
2196d756449SSean Bruno  */
2206d756449SSean Bruno static int
2216d756449SSean Bruno imgact_binmisc_add_entry(ximgact_binmisc_entry_t *xbe)
2226d756449SSean Bruno {
2236d756449SSean Bruno 	imgact_binmisc_entry_t *ibe;
2246d756449SSean Bruno 	char *p;
2256d756449SSean Bruno 
2266d756449SSean Bruno 	if (xbe->xbe_msize > IBE_MAGIC_MAX)
2276d756449SSean Bruno 		return (EINVAL);
2286d756449SSean Bruno 
2296d756449SSean Bruno 	for(p = xbe->xbe_name; *p != 0; p++)
2306d756449SSean Bruno 		if (!isascii((int)*p))
2316d756449SSean Bruno 			return (EINVAL);
2326d756449SSean Bruno 
2336d756449SSean Bruno 	for(p = xbe->xbe_interpreter; *p != 0; p++)
2346d756449SSean Bruno 		if (!isascii((int)*p))
2356d756449SSean Bruno 			return (EINVAL);
2366d756449SSean Bruno 
2376d756449SSean Bruno 	/* Make sure we don't have any invalid #'s. */
2386d756449SSean Bruno 	p = xbe->xbe_interpreter;
2396d756449SSean Bruno 	while (1) {
2406d756449SSean Bruno 		p = strchr(p, '#');
2416d756449SSean Bruno 		if (!p)
2426d756449SSean Bruno 			break;
2436d756449SSean Bruno 
2446d756449SSean Bruno 		p++;
2456d756449SSean Bruno 		switch(*p) {
2466d756449SSean Bruno 		case ISM_POUND:
2476d756449SSean Bruno 			/* "##" */
2486d756449SSean Bruno 			p++;
2496d756449SSean Bruno 			break;
2506d756449SSean Bruno 
2516d756449SSean Bruno 		case ISM_OLD_ARGV0:
2526d756449SSean Bruno 			/* "#a" */
2536d756449SSean Bruno 			p++;
2546d756449SSean Bruno 			break;
2556d756449SSean Bruno 
2566d756449SSean Bruno 		case 0:
2576d756449SSean Bruno 		default:
2586d756449SSean Bruno 			/* Anything besides the above is invalid. */
2596d756449SSean Bruno 			return (EINVAL);
2606d756449SSean Bruno 		}
2616d756449SSean Bruno 	}
2626d756449SSean Bruno 
2636d756449SSean Bruno 	mtx_lock(&interp_list_mtx);
2646d756449SSean Bruno 	if (imgact_binmisc_find_entry(xbe->xbe_name) != NULL) {
2656d756449SSean Bruno 		mtx_unlock(&interp_list_mtx);
2666d756449SSean Bruno 		return (EEXIST);
2676d756449SSean Bruno 	}
2686d756449SSean Bruno 	mtx_unlock(&interp_list_mtx);
2696d756449SSean Bruno 
2706d756449SSean Bruno 	ibe = imgact_binmisc_new_entry(xbe);
2716d756449SSean Bruno 	if (!ibe)
2726d756449SSean Bruno 		return (ENOMEM);
2736d756449SSean Bruno 
2746d756449SSean Bruno 	mtx_lock(&interp_list_mtx);
2756d756449SSean Bruno 	SLIST_INSERT_HEAD(&interpreter_list, ibe, link);
2766d756449SSean Bruno 	interp_list_entry_count++;
2776d756449SSean Bruno 	mtx_unlock(&interp_list_mtx);
2786d756449SSean Bruno 
2796d756449SSean Bruno 	return (0);
2806d756449SSean Bruno }
2816d756449SSean Bruno 
2826d756449SSean Bruno /*
2836d756449SSean Bruno  * Remove the interpreter in the list with the given name. Return ENOENT
2846d756449SSean Bruno  * if not found.
2856d756449SSean Bruno  */
2866d756449SSean Bruno static int
2876d756449SSean Bruno imgact_binmisc_remove_entry(char *name)
2886d756449SSean Bruno {
2896d756449SSean Bruno 	imgact_binmisc_entry_t *ibe;
2906d756449SSean Bruno 
2916d756449SSean Bruno 	mtx_lock(&interp_list_mtx);
2926d756449SSean Bruno 	if ((ibe = imgact_binmisc_find_entry(name)) == NULL) {
2936d756449SSean Bruno 		mtx_unlock(&interp_list_mtx);
2946d756449SSean Bruno 		return (ENOENT);
2956d756449SSean Bruno 	}
2966d756449SSean Bruno 	SLIST_REMOVE(&interpreter_list, ibe, imgact_binmisc_entry, link);
2976d756449SSean Bruno 	interp_list_entry_count--;
2986d756449SSean Bruno 	mtx_unlock(&interp_list_mtx);
2996d756449SSean Bruno 
3006d756449SSean Bruno 	imgact_binmisc_destroy_entry(ibe);
3016d756449SSean Bruno 
3026d756449SSean Bruno 	return (0);
3036d756449SSean Bruno }
3046d756449SSean Bruno 
3056d756449SSean Bruno /*
3066d756449SSean Bruno  * Disable the interpreter in the list with the given name. Return ENOENT
3076d756449SSean Bruno  * if not found.
3086d756449SSean Bruno  */
3096d756449SSean Bruno static int
3106d756449SSean Bruno imgact_binmisc_disable_entry(char *name)
3116d756449SSean Bruno {
3126d756449SSean Bruno 	imgact_binmisc_entry_t *ibe;
3136d756449SSean Bruno 
3146d756449SSean Bruno 	mtx_lock(&interp_list_mtx);
3156d756449SSean Bruno 	if ((ibe = imgact_binmisc_find_entry(name)) == NULL) {
3166d756449SSean Bruno 		mtx_unlock(&interp_list_mtx);
3176d756449SSean Bruno 		return (ENOENT);
3186d756449SSean Bruno 	}
3196d756449SSean Bruno 
3206d756449SSean Bruno 	ibe->ibe_flags &= ~IBF_ENABLED;
3216d756449SSean Bruno 	mtx_unlock(&interp_list_mtx);
3226d756449SSean Bruno 
3236d756449SSean Bruno 	return (0);
3246d756449SSean Bruno }
3256d756449SSean Bruno 
3266d756449SSean Bruno /*
3276d756449SSean Bruno  * Enable the interpreter in the list with the given name. Return ENOENT
3286d756449SSean Bruno  * if not found.
3296d756449SSean Bruno  */
3306d756449SSean Bruno static int
3316d756449SSean Bruno imgact_binmisc_enable_entry(char *name)
3326d756449SSean Bruno {
3336d756449SSean Bruno 	imgact_binmisc_entry_t *ibe;
3346d756449SSean Bruno 
3356d756449SSean Bruno 	mtx_lock(&interp_list_mtx);
3366d756449SSean Bruno 	if ((ibe = imgact_binmisc_find_entry(name)) == NULL) {
3376d756449SSean Bruno 		mtx_unlock(&interp_list_mtx);
3386d756449SSean Bruno 		return (ENOENT);
3396d756449SSean Bruno 	}
3406d756449SSean Bruno 
3416d756449SSean Bruno 	ibe->ibe_flags |= IBF_ENABLED;
3426d756449SSean Bruno 	mtx_unlock(&interp_list_mtx);
3436d756449SSean Bruno 
3446d756449SSean Bruno 	return (0);
3456d756449SSean Bruno }
3466d756449SSean Bruno 
3476d756449SSean Bruno static int
3486d756449SSean Bruno imgact_binmisc_populate_xbe(ximgact_binmisc_entry_t *xbe,
3496d756449SSean Bruno     imgact_binmisc_entry_t *ibe)
3506d756449SSean Bruno {
3516d756449SSean Bruno 	uint32_t i;
3526d756449SSean Bruno 
3536d756449SSean Bruno 	mtx_assert(&interp_list_mtx, MA_OWNED);
3546d756449SSean Bruno 
3556d756449SSean Bruno 	bzero(xbe, sizeof(*xbe));
3566d756449SSean Bruno 	strlcpy(xbe->xbe_name, ibe->ibe_name, IBE_NAME_MAX);
3576d756449SSean Bruno 
3586d756449SSean Bruno 	/* Copy interpreter string.  Replace NULL breaks with space. */
3596d756449SSean Bruno 	memcpy(xbe->xbe_interpreter, ibe->ibe_interpreter,
3606d756449SSean Bruno 	    ibe->ibe_interp_length);
3616d756449SSean Bruno 	for(i = 0; i < (ibe->ibe_interp_length - 1); i++)
3626d756449SSean Bruno 		if (xbe->xbe_interpreter[i] == '\0')
3636d756449SSean Bruno 			xbe->xbe_interpreter[i] = ' ';
3646d756449SSean Bruno 
3656d756449SSean Bruno 	memcpy(xbe->xbe_magic, ibe->ibe_magic, ibe->ibe_msize);
3666d756449SSean Bruno 	memcpy(xbe->xbe_mask, ibe->ibe_mask, ibe->ibe_msize);
3676d756449SSean Bruno 	xbe->xbe_version = IBE_VERSION;
3686d756449SSean Bruno 	xbe->xbe_flags = ibe->ibe_flags;
3696d756449SSean Bruno 	xbe->xbe_moffset = ibe->ibe_moffset;
3706d756449SSean Bruno 	xbe->xbe_msize = ibe->ibe_msize;
3716d756449SSean Bruno 
3726d756449SSean Bruno 	return (0);
3736d756449SSean Bruno }
3746d756449SSean Bruno 
3756d756449SSean Bruno /*
3766d756449SSean Bruno  * Retrieve the interpreter with the give name and populate the
3776d756449SSean Bruno  * ximgact_binmisc_entry structure.  Return ENOENT if not found.
3786d756449SSean Bruno  */
3796d756449SSean Bruno static int
3806d756449SSean Bruno imgact_binmisc_lookup_entry(char *name, ximgact_binmisc_entry_t *xbe)
3816d756449SSean Bruno {
3826d756449SSean Bruno 	imgact_binmisc_entry_t *ibe;
3836d756449SSean Bruno 	int error = 0;
3846d756449SSean Bruno 
3856d756449SSean Bruno 	mtx_lock(&interp_list_mtx);
3866d756449SSean Bruno 	if ((ibe = imgact_binmisc_find_entry(name)) == NULL) {
3876d756449SSean Bruno 		mtx_unlock(&interp_list_mtx);
3886d756449SSean Bruno 		return (ENOENT);
3896d756449SSean Bruno 	}
3906d756449SSean Bruno 
3916d756449SSean Bruno 	error = imgact_binmisc_populate_xbe(xbe, ibe);
3926d756449SSean Bruno 	mtx_unlock(&interp_list_mtx);
3936d756449SSean Bruno 
3946d756449SSean Bruno 	return (error);
3956d756449SSean Bruno }
3966d756449SSean Bruno 
3976d756449SSean Bruno /*
3986d756449SSean Bruno  * Get a snapshot of all the interpreter entries in the list.
3996d756449SSean Bruno  */
4006d756449SSean Bruno static int
4016d756449SSean Bruno imgact_binmisc_get_all_entries(struct sysctl_req *req)
4026d756449SSean Bruno {
4036d756449SSean Bruno 	ximgact_binmisc_entry_t *xbe, *xbep;
4046d756449SSean Bruno 	imgact_binmisc_entry_t *ibe;
4056d756449SSean Bruno 	int error = 0, count;
4066d756449SSean Bruno 
4076d756449SSean Bruno 	mtx_lock(&interp_list_mtx);
4086d756449SSean Bruno 	count = interp_list_entry_count;
4096d756449SSean Bruno 	/* Don't block in malloc() while holding lock. */
4106d756449SSean Bruno 	xbe = malloc(sizeof(*xbe) * count, M_BINMISC, M_NOWAIT|M_ZERO);
4116d756449SSean Bruno 	if (!xbe) {
4126d756449SSean Bruno 		mtx_unlock(&interp_list_mtx);
4136d756449SSean Bruno 		return (ENOMEM);
4146d756449SSean Bruno 	}
4156d756449SSean Bruno 
4166d756449SSean Bruno 	xbep = xbe;
4176d756449SSean Bruno 	SLIST_FOREACH(ibe, &interpreter_list, link) {
4186d756449SSean Bruno 		error = imgact_binmisc_populate_xbe(xbep++, ibe);
4196d756449SSean Bruno 		if (error)
4206d756449SSean Bruno 			break;
4216d756449SSean Bruno 	}
4226d756449SSean Bruno 	mtx_unlock(&interp_list_mtx);
4236d756449SSean Bruno 
4246d756449SSean Bruno 	if (!error)
4256d756449SSean Bruno 		error = SYSCTL_OUT(req, xbe, sizeof(*xbe) * count);
4266d756449SSean Bruno 
4276d756449SSean Bruno 	free(xbe, M_BINMISC);
4286d756449SSean Bruno 	return (error);
4296d756449SSean Bruno }
4306d756449SSean Bruno 
4316d756449SSean Bruno /*
4326d756449SSean Bruno  * sysctl() handler for munipulating interpretor table.
4336d756449SSean Bruno  * Not MP safe (locked by sysctl).
4346d756449SSean Bruno  */
4356d756449SSean Bruno static int
4366d756449SSean Bruno sysctl_kern_binmisc(SYSCTL_HANDLER_ARGS)
4376d756449SSean Bruno {
4386d756449SSean Bruno 	ximgact_binmisc_entry_t xbe;
4396d756449SSean Bruno 	int error = 0;
4406d756449SSean Bruno 
4416d756449SSean Bruno 	switch(arg2) {
4426d756449SSean Bruno 	case IBC_ADD:
4436d756449SSean Bruno 		/* Add an entry. Limited to IBE_MAX_ENTRIES. */
4446d756449SSean Bruno 		error = SYSCTL_IN(req, &xbe, sizeof(xbe));
4456d756449SSean Bruno 		if (error)
4466d756449SSean Bruno 			return (error);
4476d756449SSean Bruno 		if (IBE_VERSION != xbe.xbe_version)
4486d756449SSean Bruno 			return (EINVAL);
4496d756449SSean Bruno 		if (interp_list_entry_count == IBE_MAX_ENTRIES)
4506d756449SSean Bruno 			return (ENOSPC);
4516d756449SSean Bruno 		error = imgact_binmisc_add_entry(&xbe);
4526d756449SSean Bruno 		break;
4536d756449SSean Bruno 
4546d756449SSean Bruno 	case IBC_REMOVE:
4556d756449SSean Bruno 		/* Remove an entry. */
4566d756449SSean Bruno 		error = SYSCTL_IN(req, &xbe, sizeof(xbe));
4576d756449SSean Bruno 		if (error)
4586d756449SSean Bruno 			return (error);
4596d756449SSean Bruno 		if (IBE_VERSION != xbe.xbe_version)
4606d756449SSean Bruno 			return (EINVAL);
4616d756449SSean Bruno 		error = imgact_binmisc_remove_entry(xbe.xbe_name);
4626d756449SSean Bruno 		break;
4636d756449SSean Bruno 
4646d756449SSean Bruno 	case IBC_DISABLE:
4656d756449SSean Bruno 		/* Disable an entry. */
4666d756449SSean Bruno 		error = SYSCTL_IN(req, &xbe, sizeof(xbe));
4676d756449SSean Bruno 		if (error)
4686d756449SSean Bruno 			return (error);
4696d756449SSean Bruno 		if (IBE_VERSION != xbe.xbe_version)
4706d756449SSean Bruno 			return (EINVAL);
4716d756449SSean Bruno 		error = imgact_binmisc_disable_entry(xbe.xbe_name);
4726d756449SSean Bruno 		break;
4736d756449SSean Bruno 
4746d756449SSean Bruno 	case IBC_ENABLE:
4756d756449SSean Bruno 		/* Enable an entry. */
4766d756449SSean Bruno 		error = SYSCTL_IN(req, &xbe, sizeof(xbe));
4776d756449SSean Bruno 		if (error)
4786d756449SSean Bruno 			return (error);
4796d756449SSean Bruno 		if (IBE_VERSION != xbe.xbe_version)
4806d756449SSean Bruno 			return (EINVAL);
4816d756449SSean Bruno 		error = imgact_binmisc_enable_entry(xbe.xbe_name);
4826d756449SSean Bruno 		break;
4836d756449SSean Bruno 
4846d756449SSean Bruno 	case IBC_LOOKUP:
4856d756449SSean Bruno 		/* Lookup an entry. */
4866d756449SSean Bruno 		error = SYSCTL_IN(req, &xbe, sizeof(xbe));
4876d756449SSean Bruno 		if (error)
4886d756449SSean Bruno 			return (error);
4896d756449SSean Bruno 		if (IBE_VERSION != xbe.xbe_version)
4906d756449SSean Bruno 			return (EINVAL);
4916d756449SSean Bruno 		error = imgact_binmisc_lookup_entry(xbe.xbe_name, &xbe);
4926d756449SSean Bruno 		if (!error)
4936d756449SSean Bruno 			error = SYSCTL_OUT(req, &xbe, sizeof(xbe));
4946d756449SSean Bruno 		break;
4956d756449SSean Bruno 
4966d756449SSean Bruno 	case IBC_LIST:
4976d756449SSean Bruno 		/* Return a snapshot of the interpretor list. */
4986d756449SSean Bruno 
4996d756449SSean Bruno 		if (!req->oldptr) {
5006d756449SSean Bruno 			/* No pointer then just return the list size. */
5016d756449SSean Bruno 			error = SYSCTL_OUT(req, 0, interp_list_entry_count *
5026d756449SSean Bruno 			    sizeof(ximgact_binmisc_entry_t));
5036d756449SSean Bruno 			return (error);
5046d756449SSean Bruno 		} else
5056d756449SSean Bruno 			if (!req->oldlen)
5066d756449SSean Bruno 				return (EINVAL);
5076d756449SSean Bruno 
5086d756449SSean Bruno 		error = imgact_binmisc_get_all_entries(req);
5096d756449SSean Bruno 		break;
5106d756449SSean Bruno 
5116d756449SSean Bruno 	default:
5126d756449SSean Bruno 		return (EINVAL);
5136d756449SSean Bruno 	}
5146d756449SSean Bruno 
5156d756449SSean Bruno 	return (error);
5166d756449SSean Bruno }
5176d756449SSean Bruno 
5186d756449SSean Bruno SYSCTL_NODE(_kern, OID_AUTO, binmisc, CTLFLAG_RW, 0,
5196d756449SSean Bruno     "Image activator for miscellaneous binaries");
5206d756449SSean Bruno 
5216d756449SSean Bruno SYSCTL_PROC(_kern_binmisc, OID_AUTO, add,
5226d756449SSean Bruno     CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_ADD,
5236d756449SSean Bruno     sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
5246d756449SSean Bruno     "Add an activator entry");
5256d756449SSean Bruno 
5266d756449SSean Bruno SYSCTL_PROC(_kern_binmisc, OID_AUTO, remove,
5276d756449SSean Bruno     CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_REMOVE,
5286d756449SSean Bruno     sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
5296d756449SSean Bruno     "Remove an activator entry");
5306d756449SSean Bruno 
5316d756449SSean Bruno SYSCTL_PROC(_kern_binmisc, OID_AUTO, disable,
5326d756449SSean Bruno     CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_DISABLE,
5336d756449SSean Bruno     sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
5346d756449SSean Bruno     "Disable an activator entry");
5356d756449SSean Bruno 
5366d756449SSean Bruno SYSCTL_PROC(_kern_binmisc, OID_AUTO, enable,
5376d756449SSean Bruno     CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_WR, NULL, IBC_ENABLE,
5386d756449SSean Bruno     sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
5396d756449SSean Bruno     "Enable an activator entry");
5406d756449SSean Bruno 
5416d756449SSean Bruno SYSCTL_PROC(_kern_binmisc, OID_AUTO, lookup,
5426d756449SSean Bruno     CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_RW|CTLFLAG_ANYBODY, NULL, IBC_LOOKUP,
5436d756449SSean Bruno     sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
5446d756449SSean Bruno     "Lookup an activator entry");
5456d756449SSean Bruno 
5466d756449SSean Bruno SYSCTL_PROC(_kern_binmisc, OID_AUTO, list,
5476d756449SSean Bruno     CTLFLAG_MPSAFE|CTLTYPE_STRUCT|CTLFLAG_RD|CTLFLAG_ANYBODY, NULL, IBC_LIST,
5486d756449SSean Bruno     sysctl_kern_binmisc, "S,ximgact_binmisc_entry",
5496d756449SSean Bruno     "Get snapshot of all the activator entries");
5506d756449SSean Bruno 
5516d756449SSean Bruno static imgact_binmisc_entry_t *
5526d756449SSean Bruno imgact_binmisc_find_interpreter(const char *image_header)
5536d756449SSean Bruno {
5546d756449SSean Bruno 	imgact_binmisc_entry_t *ibe;
5556d756449SSean Bruno 	const char *p;
5566d756449SSean Bruno 	int i;
5576d756449SSean Bruno 	size_t sz;
5586d756449SSean Bruno 
5596d756449SSean Bruno 	mtx_assert(&interp_list_mtx, MA_OWNED);
5606d756449SSean Bruno 
5616d756449SSean Bruno 	SLIST_FOREACH(ibe, &interpreter_list, link) {
5626d756449SSean Bruno 		if (!(IBF_ENABLED & ibe->ibe_flags))
5636d756449SSean Bruno 			continue;
5646d756449SSean Bruno 
5656d756449SSean Bruno 		p = image_header + ibe->ibe_moffset;
5666d756449SSean Bruno 		sz = ibe->ibe_msize;
5676d756449SSean Bruno 		if (IBF_USE_MASK & ibe->ibe_flags) {
5686d756449SSean Bruno 			/* Compare using mask. */
5696d756449SSean Bruno 			for (i = 0; i < sz; i++)
5706d756449SSean Bruno 				if ((*p++ ^ ibe->ibe_magic[i]) &
5716d756449SSean Bruno 				    ibe->ibe_mask[i])
5726d756449SSean Bruno 					break;
5736d756449SSean Bruno 		} else {
5746d756449SSean Bruno 			for (i = 0; i < sz; i++)
5756d756449SSean Bruno 				if (*p++ ^ ibe->ibe_magic[i])
5766d756449SSean Bruno 					break;
5776d756449SSean Bruno 		}
5786d756449SSean Bruno 		if (i == ibe->ibe_msize)
5796d756449SSean Bruno 			return (ibe);
5806d756449SSean Bruno 	}
5816d756449SSean Bruno 	return (NULL);
5826d756449SSean Bruno }
5836d756449SSean Bruno 
5846d756449SSean Bruno int
5856d756449SSean Bruno imgact_binmisc_exec(struct image_params *imgp)
5866d756449SSean Bruno {
5876d756449SSean Bruno 	const char *image_header = imgp->image_header;
5886d756449SSean Bruno 	const char *fname = NULL;
5896d756449SSean Bruno 	int error = 0;
5906d756449SSean Bruno 	size_t offset, l;
5916d756449SSean Bruno 	imgact_binmisc_entry_t *ibe;
5926d756449SSean Bruno 	struct sbuf *sname;
5936d756449SSean Bruno 	char *s, *d;
5946d756449SSean Bruno 
5956d756449SSean Bruno 	/* Do we have an interpreter for the given image header? */
5966d756449SSean Bruno 	mtx_lock(&interp_list_mtx);
5976d756449SSean Bruno 	if ((ibe = imgact_binmisc_find_interpreter(image_header)) == NULL) {
5986d756449SSean Bruno 		mtx_unlock(&interp_list_mtx);
5996d756449SSean Bruno 		return (-1);
6006d756449SSean Bruno 	}
6016d756449SSean Bruno 
6026d756449SSean Bruno 	/* No interpreter nesting allowed. */
6036d756449SSean Bruno 	if (imgp->interpreted) {
6046d756449SSean Bruno 		mtx_unlock(&interp_list_mtx);
6056d756449SSean Bruno 		return (ENOEXEC);
6066d756449SSean Bruno 	}
6076d756449SSean Bruno 
6086d756449SSean Bruno 	imgp->interpreted = 1;
6096d756449SSean Bruno 
6106d756449SSean Bruno 	if (imgp->args->fname != NULL) {
6116d756449SSean Bruno 		fname = imgp->args->fname;
6126d756449SSean Bruno 		sname = NULL;
6136d756449SSean Bruno 	} else {
6146d756449SSean Bruno 		/* Use the fdescfs(5) path for fexecve(2). */
6156d756449SSean Bruno 		sname = sbuf_new_auto();
6166d756449SSean Bruno 		sbuf_printf(sname, "/dev/fd/%d", imgp->args->fd);
6176d756449SSean Bruno 		sbuf_finish(sname);
6186d756449SSean Bruno 		fname = sbuf_data(sname);
6196d756449SSean Bruno 	}
6206d756449SSean Bruno 
6216d756449SSean Bruno 
6226d756449SSean Bruno 	/*
6236d756449SSean Bruno 	 * We need to "push" the interpreter in the arg[] list.  To do this,
6246d756449SSean Bruno 	 * we first shift all the other values in the `begin_argv' area to
6256d756449SSean Bruno 	 * provide the exact amount of room for the values added.  Set up
6266d756449SSean Bruno 	 * `offset' as the number of bytes to be added to the `begin_argv'
6276d756449SSean Bruno 	 * area.
6286d756449SSean Bruno 	 */
6296d756449SSean Bruno 	offset = ibe->ibe_interp_length;
6306d756449SSean Bruno 
6316d756449SSean Bruno 	/* Adjust the offset for #'s. */
6326d756449SSean Bruno 	s = ibe->ibe_interpreter;
6336d756449SSean Bruno 	while (1) {
6346d756449SSean Bruno 		s = strchr(s, '#');
6356d756449SSean Bruno 		if (!s)
6366d756449SSean Bruno 			break;
6376d756449SSean Bruno 
6386d756449SSean Bruno 		s++;
6396d756449SSean Bruno 		switch(*s) {
6406d756449SSean Bruno 		case ISM_POUND:
6416d756449SSean Bruno 			/* "##" -> "#": reduce offset by one. */
6426d756449SSean Bruno 			offset--;
6436d756449SSean Bruno 			break;
6446d756449SSean Bruno 
6456d756449SSean Bruno 		case ISM_OLD_ARGV0:
6466d756449SSean Bruno 			/* "#a" -> (old argv0): increase offset to fit fname */
6476d756449SSean Bruno 			offset += strlen(fname) - 2;
6486d756449SSean Bruno 			break;
6496d756449SSean Bruno 
6506d756449SSean Bruno 		default:
6516d756449SSean Bruno 			/* Hmm... This shouldn't happen. */
6526d756449SSean Bruno 			mtx_unlock(&interp_list_mtx);
6536d756449SSean Bruno 			printf("%s: Unknown macro #%c sequence in "
6546d756449SSean Bruno 			    "interpreter string\n", KMOD_NAME, *(s + 1));
6556d756449SSean Bruno 			error = EINVAL;
6566d756449SSean Bruno 			goto done;
6576d756449SSean Bruno 		}
6586d756449SSean Bruno 		s++;
6596d756449SSean Bruno 	}
6606d756449SSean Bruno 
6616d756449SSean Bruno 	/* Check to make sure we won't overrun the stringspace. */
6626d756449SSean Bruno 	if (offset > imgp->args->stringspace) {
6636d756449SSean Bruno 		mtx_unlock(&interp_list_mtx);
6646d756449SSean Bruno 		error = E2BIG;
6656d756449SSean Bruno 		goto done;
6666d756449SSean Bruno 	}
6676d756449SSean Bruno 
6686d756449SSean Bruno 	/* Make room for the interpreter */
6696d756449SSean Bruno 	bcopy(imgp->args->begin_argv, imgp->args->begin_argv + offset,
6706d756449SSean Bruno 	    imgp->args->endp - imgp->args->begin_argv);
6716d756449SSean Bruno 
6726d756449SSean Bruno 	/* Adjust everything by the offset. */
6736d756449SSean Bruno 	imgp->args->begin_envv += offset;
6746d756449SSean Bruno 	imgp->args->endp += offset;
6756d756449SSean Bruno 	imgp->args->stringspace -= offset;
6766d756449SSean Bruno 
6776d756449SSean Bruno 	/* Add the new argument(s) in the count. */
6786d756449SSean Bruno 	imgp->args->argc += ibe->ibe_interp_argcnt;
6796d756449SSean Bruno 
6806d756449SSean Bruno 	/*
6816d756449SSean Bruno 	 * The original arg[] list has been shifted appropriately.  Copy in
6826d756449SSean Bruno 	 * the interpreter path.
6836d756449SSean Bruno 	 */
6846d756449SSean Bruno 	s = ibe->ibe_interpreter;
6856d756449SSean Bruno 	d = imgp->args->begin_argv;
6866d756449SSean Bruno 	while(*s != '\0') {
6876d756449SSean Bruno 		switch (*s) {
6886d756449SSean Bruno 		case '#':
6896d756449SSean Bruno 			/* Handle "#" in interpreter string. */
6906d756449SSean Bruno 			s++;
6916d756449SSean Bruno 			switch(*s) {
6926d756449SSean Bruno 			case ISM_POUND:
6936d756449SSean Bruno 				/* "##": Replace with a single '#' */
6946d756449SSean Bruno 				*d++ = '#';
6956d756449SSean Bruno 				break;
6966d756449SSean Bruno 
6976d756449SSean Bruno 			case ISM_OLD_ARGV0:
6986d756449SSean Bruno 				/* "#a": Replace with old arg0 (fname). */
6996d756449SSean Bruno 				if ((l = strlen(fname)) != 0) {
7006d756449SSean Bruno 					memcpy(d, fname, l);
7016d756449SSean Bruno 					d += l;
7026d756449SSean Bruno 				}
7036d756449SSean Bruno 				break;
7046d756449SSean Bruno 
7056d756449SSean Bruno 			default:
7066d756449SSean Bruno 				/* Shouldn't happen but skip it if it does. */
7076d756449SSean Bruno 				break;
7086d756449SSean Bruno 			}
7096d756449SSean Bruno 			break;
7106d756449SSean Bruno 
7116d756449SSean Bruno 		case ' ':
7126d756449SSean Bruno 			/* Replace space with NUL to seperate arguments. */
7136d756449SSean Bruno 			*d++ = '\0';
7146d756449SSean Bruno 			break;
7156d756449SSean Bruno 
7166d756449SSean Bruno 		default:
7176d756449SSean Bruno 			*d++ = *s;
7186d756449SSean Bruno 			break;
7196d756449SSean Bruno 		}
7206d756449SSean Bruno 		s++;
7216d756449SSean Bruno 	}
7226d756449SSean Bruno 	*d = '\0';
7236d756449SSean Bruno 	mtx_unlock(&interp_list_mtx);
7246d756449SSean Bruno 
7256d756449SSean Bruno 	if (!error)
7266d756449SSean Bruno 		imgp->interpreter_name = imgp->args->begin_argv;
7276d756449SSean Bruno 
7286d756449SSean Bruno 
7296d756449SSean Bruno done:
7306d756449SSean Bruno 	if (sname)
7316d756449SSean Bruno 		sbuf_delete(sname);
7326d756449SSean Bruno 	return (error);
7336d756449SSean Bruno }
7346d756449SSean Bruno 
7356d756449SSean Bruno static void
7366d756449SSean Bruno imgact_binmisc_init(void *arg)
7376d756449SSean Bruno {
7386d756449SSean Bruno 
7396d756449SSean Bruno 	mtx_init(&interp_list_mtx, KMOD_NAME, NULL, MTX_DEF);
7406d756449SSean Bruno }
7416d756449SSean Bruno 
7426d756449SSean Bruno static void
7436d756449SSean Bruno imgact_binmisc_fini(void *arg)
7446d756449SSean Bruno {
7456d756449SSean Bruno 	imgact_binmisc_entry_t *ibe, *ibe_tmp;
7466d756449SSean Bruno 
7476d756449SSean Bruno 	/* Free all the interpreters. */
7486d756449SSean Bruno 	mtx_lock(&interp_list_mtx);
7496d756449SSean Bruno 	SLIST_FOREACH_SAFE(ibe, &interpreter_list, link, ibe_tmp) {
7506d756449SSean Bruno 		SLIST_REMOVE(&interpreter_list, ibe, imgact_binmisc_entry,
7516d756449SSean Bruno 		    link);
7526d756449SSean Bruno 		imgact_binmisc_destroy_entry(ibe);
7536d756449SSean Bruno 	}
7546d756449SSean Bruno 	mtx_unlock(&interp_list_mtx);
7556d756449SSean Bruno 
7566d756449SSean Bruno 	mtx_destroy(&interp_list_mtx);
7576d756449SSean Bruno }
7586d756449SSean Bruno 
7596d756449SSean Bruno SYSINIT(imgact_binmisc, SI_SUB_EXEC, SI_ORDER_MIDDLE, imgact_binmisc_init, 0);
7606d756449SSean Bruno SYSUNINIT(imgact_binmisc, SI_SUB_EXEC, SI_ORDER_MIDDLE, imgact_binmisc_fini, 0);
7616d756449SSean Bruno 
7626d756449SSean Bruno /*
7636d756449SSean Bruno  * Tell kern_execve.c about it, with a little help from the linker.
7646d756449SSean Bruno  */
7656d756449SSean Bruno static struct execsw imgact_binmisc_execsw = { imgact_binmisc_exec, KMOD_NAME };
7666d756449SSean Bruno EXEC_SET(imgact_binmisc, imgact_binmisc_execsw);
767