14ac21b4fSStephen J. Kiernan /*- 24ac21b4fSStephen J. Kiernan * Copyright (c) 2000-2001 Robert N. M. Watson. 34ac21b4fSStephen J. Kiernan * All rights reserved. 44ac21b4fSStephen J. Kiernan * 54ac21b4fSStephen J. Kiernan * Redistribution and use in source and binary forms, with or without 64ac21b4fSStephen J. Kiernan * modification, are permitted provided that the following conditions 74ac21b4fSStephen J. Kiernan * are met: 84ac21b4fSStephen J. Kiernan * 1. Redistributions of source code must retain the above copyright 94ac21b4fSStephen J. Kiernan * notice, this list of conditions and the following disclaimer. 104ac21b4fSStephen J. Kiernan * 2. Redistributions in binary form must reproduce the above copyright 114ac21b4fSStephen J. Kiernan * notice, this list of conditions and the following disclaimer in the 124ac21b4fSStephen J. Kiernan * documentation and/or other materials provided with the distribution. 134ac21b4fSStephen J. Kiernan * 14f11ec798SStephen J. Kiernan * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 154ac21b4fSStephen J. Kiernan * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 164ac21b4fSStephen J. Kiernan * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 17f11ec798SStephen J. Kiernan * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 184ac21b4fSStephen J. Kiernan * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 194ac21b4fSStephen J. Kiernan * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 204ac21b4fSStephen J. Kiernan * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 214ac21b4fSStephen J. Kiernan * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 224ac21b4fSStephen J. Kiernan * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 234ac21b4fSStephen J. Kiernan * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 244ac21b4fSStephen J. Kiernan * SUCH DAMAGE. 254ac21b4fSStephen J. Kiernan * 264ac21b4fSStephen J. Kiernan */ 274ac21b4fSStephen J. Kiernan 284ac21b4fSStephen J. Kiernan /* 294ac21b4fSStephen J. Kiernan * System calls related to processes and protection 304ac21b4fSStephen J. Kiernan */ 314ac21b4fSStephen J. Kiernan 324ac21b4fSStephen J. Kiernan #include <sys/cdefs.h> 334ac21b4fSStephen J. Kiernan #include "opt_inet.h" 344ac21b4fSStephen J. Kiernan #include "opt_inet6.h" 354ac21b4fSStephen J. Kiernan 364ac21b4fSStephen J. Kiernan #include <sys/param.h> 374ac21b4fSStephen J. Kiernan #include <sys/systm.h> 384ac21b4fSStephen J. Kiernan #include <sys/kernel.h> 394ac21b4fSStephen J. Kiernan #include <sys/lock.h> 404ac21b4fSStephen J. Kiernan #include <sys/mutex.h> 414ac21b4fSStephen J. Kiernan #include <sys/proc.h> 424ac21b4fSStephen J. Kiernan #include <sys/socket.h> 434ac21b4fSStephen J. Kiernan #include <sys/jail.h> 444ac21b4fSStephen J. Kiernan 454ac21b4fSStephen J. Kiernan #include <netinet/in.h> 464ac21b4fSStephen J. Kiernan #include <netinet/in_pcb.h> 474ac21b4fSStephen J. Kiernan #include <netinet/in_systm.h> 484ac21b4fSStephen J. Kiernan 494ac21b4fSStephen J. Kiernan #include <security/audit/audit.h> 504ac21b4fSStephen J. Kiernan #include <security/mac/mac_framework.h> 514ac21b4fSStephen J. Kiernan 524ac21b4fSStephen J. Kiernan /*- 534ac21b4fSStephen J. Kiernan * Determine whether the subject represented by cred can "see" a socket. 544ac21b4fSStephen J. Kiernan * Returns: 0 for permitted, ENOENT otherwise. 554ac21b4fSStephen J. Kiernan */ 564ac21b4fSStephen J. Kiernan int 574ac21b4fSStephen J. Kiernan cr_canseeinpcb(struct ucred *cred, struct inpcb *inp) 584ac21b4fSStephen J. Kiernan { 594ac21b4fSStephen J. Kiernan int error; 604ac21b4fSStephen J. Kiernan 614ac21b4fSStephen J. Kiernan error = prison_check(cred, inp->inp_cred); 624ac21b4fSStephen J. Kiernan if (error) 634ac21b4fSStephen J. Kiernan return (ENOENT); 644ac21b4fSStephen J. Kiernan #ifdef MAC 654ac21b4fSStephen J. Kiernan INP_LOCK_ASSERT(inp); 664ac21b4fSStephen J. Kiernan error = mac_inpcb_check_visible(cred, inp); 674ac21b4fSStephen J. Kiernan if (error) 684ac21b4fSStephen J. Kiernan return (error); 694ac21b4fSStephen J. Kiernan #endif 70*5817169bSOlivier Certner if (cr_bsd_visible(cred, inp->inp_cred)) 714ac21b4fSStephen J. Kiernan return (ENOENT); 724ac21b4fSStephen J. Kiernan 734ac21b4fSStephen J. Kiernan return (0); 744ac21b4fSStephen J. Kiernan } 75