14ac21b4fSStephen J. Kiernan /*-
24ac21b4fSStephen J. Kiernan * Copyright (c) 2000-2001 Robert N. M. Watson.
34ac21b4fSStephen J. Kiernan * All rights reserved.
44ac21b4fSStephen J. Kiernan *
54ac21b4fSStephen J. Kiernan * Redistribution and use in source and binary forms, with or without
64ac21b4fSStephen J. Kiernan * modification, are permitted provided that the following conditions
74ac21b4fSStephen J. Kiernan * are met:
84ac21b4fSStephen J. Kiernan * 1. Redistributions of source code must retain the above copyright
94ac21b4fSStephen J. Kiernan * notice, this list of conditions and the following disclaimer.
104ac21b4fSStephen J. Kiernan * 2. Redistributions in binary form must reproduce the above copyright
114ac21b4fSStephen J. Kiernan * notice, this list of conditions and the following disclaimer in the
124ac21b4fSStephen J. Kiernan * documentation and/or other materials provided with the distribution.
134ac21b4fSStephen J. Kiernan *
14f11ec798SStephen J. Kiernan * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
154ac21b4fSStephen J. Kiernan * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
164ac21b4fSStephen J. Kiernan * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
17f11ec798SStephen J. Kiernan * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
184ac21b4fSStephen J. Kiernan * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
194ac21b4fSStephen J. Kiernan * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
204ac21b4fSStephen J. Kiernan * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
214ac21b4fSStephen J. Kiernan * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
224ac21b4fSStephen J. Kiernan * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
234ac21b4fSStephen J. Kiernan * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
244ac21b4fSStephen J. Kiernan * SUCH DAMAGE.
254ac21b4fSStephen J. Kiernan *
264ac21b4fSStephen J. Kiernan */
274ac21b4fSStephen J. Kiernan
284ac21b4fSStephen J. Kiernan /*
294ac21b4fSStephen J. Kiernan * System calls related to processes and protection
304ac21b4fSStephen J. Kiernan */
314ac21b4fSStephen J. Kiernan
324ac21b4fSStephen J. Kiernan #include <sys/cdefs.h>
334ac21b4fSStephen J. Kiernan #include "opt_inet.h"
344ac21b4fSStephen J. Kiernan #include "opt_inet6.h"
354ac21b4fSStephen J. Kiernan
364ac21b4fSStephen J. Kiernan #include <sys/param.h>
374ac21b4fSStephen J. Kiernan #include <sys/systm.h>
384ac21b4fSStephen J. Kiernan #include <sys/kernel.h>
394ac21b4fSStephen J. Kiernan #include <sys/lock.h>
404ac21b4fSStephen J. Kiernan #include <sys/mutex.h>
414ac21b4fSStephen J. Kiernan #include <sys/proc.h>
424ac21b4fSStephen J. Kiernan #include <sys/socket.h>
434ac21b4fSStephen J. Kiernan #include <sys/jail.h>
444ac21b4fSStephen J. Kiernan
454ac21b4fSStephen J. Kiernan #include <netinet/in.h>
464ac21b4fSStephen J. Kiernan #include <netinet/in_pcb.h>
474ac21b4fSStephen J. Kiernan #include <netinet/in_systm.h>
484ac21b4fSStephen J. Kiernan
494ac21b4fSStephen J. Kiernan #include <security/audit/audit.h>
504ac21b4fSStephen J. Kiernan #include <security/mac/mac_framework.h>
514ac21b4fSStephen J. Kiernan
524ac21b4fSStephen J. Kiernan /*-
534ac21b4fSStephen J. Kiernan * Determine whether the subject represented by cred can "see" a socket.
544ac21b4fSStephen J. Kiernan * Returns: 0 for permitted, ENOENT otherwise.
554ac21b4fSStephen J. Kiernan */
564ac21b4fSStephen J. Kiernan int
cr_canseeinpcb(struct ucred * cred,struct inpcb * inp)574ac21b4fSStephen J. Kiernan cr_canseeinpcb(struct ucred *cred, struct inpcb *inp)
584ac21b4fSStephen J. Kiernan {
594ac21b4fSStephen J. Kiernan int error;
604ac21b4fSStephen J. Kiernan
614ac21b4fSStephen J. Kiernan error = prison_check(cred, inp->inp_cred);
624ac21b4fSStephen J. Kiernan if (error)
634ac21b4fSStephen J. Kiernan return (ENOENT);
644ac21b4fSStephen J. Kiernan #ifdef MAC
654ac21b4fSStephen J. Kiernan INP_LOCK_ASSERT(inp);
664ac21b4fSStephen J. Kiernan error = mac_inpcb_check_visible(cred, inp);
674ac21b4fSStephen J. Kiernan if (error)
684ac21b4fSStephen J. Kiernan return (error);
694ac21b4fSStephen J. Kiernan #endif
70*5817169bSOlivier Certner if (cr_bsd_visible(cred, inp->inp_cred))
714ac21b4fSStephen J. Kiernan return (ENOENT);
724ac21b4fSStephen J. Kiernan
734ac21b4fSStephen J. Kiernan return (0);
744ac21b4fSStephen J. Kiernan }
75