17c478bd9Sstevel@tonic-gate /* 27c478bd9Sstevel@tonic-gate * CDDL HEADER START 37c478bd9Sstevel@tonic-gate * 47c478bd9Sstevel@tonic-gate * The contents of this file are subject to the terms of the 5dd29fa4aSprabahar * Common Development and Distribution License (the "License"). 6dd29fa4aSprabahar * You may not use this file except in compliance with the License. 77c478bd9Sstevel@tonic-gate * 87c478bd9Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 97c478bd9Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing. 107c478bd9Sstevel@tonic-gate * See the License for the specific language governing permissions 117c478bd9Sstevel@tonic-gate * and limitations under the License. 127c478bd9Sstevel@tonic-gate * 137c478bd9Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each 147c478bd9Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 157c478bd9Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the 167c478bd9Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying 177c478bd9Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner] 187c478bd9Sstevel@tonic-gate * 197c478bd9Sstevel@tonic-gate * CDDL HEADER END 207c478bd9Sstevel@tonic-gate */ 217c478bd9Sstevel@tonic-gate /* 2248011479Ssn199410 * Copyright 2007 Sun Microsystems, Inc. All rights reserved. 237c478bd9Sstevel@tonic-gate * Use is subject to license terms. 247c478bd9Sstevel@tonic-gate */ 257c478bd9Sstevel@tonic-gate 267c478bd9Sstevel@tonic-gate /* Copyright (c) 1983, 1984, 1985, 1986, 1987, 1988, 1989 AT&T */ 277c478bd9Sstevel@tonic-gate /* All Rights Reserved */ 287c478bd9Sstevel@tonic-gate 297c478bd9Sstevel@tonic-gate /* 307c478bd9Sstevel@tonic-gate * Portions of this source code were derived from Berkeley 4.3 BSD 317c478bd9Sstevel@tonic-gate * under license from the Regents of the University of California. 327c478bd9Sstevel@tonic-gate */ 337c478bd9Sstevel@tonic-gate 347c478bd9Sstevel@tonic-gate #pragma ident "%Z%%M% %I% %E% SMI" 357c478bd9Sstevel@tonic-gate 367c478bd9Sstevel@tonic-gate #include <sys/param.h> 377c478bd9Sstevel@tonic-gate #include <sys/isa_defs.h> 387c478bd9Sstevel@tonic-gate #include <sys/types.h> 397c478bd9Sstevel@tonic-gate #include <sys/sysmacros.h> 407c478bd9Sstevel@tonic-gate #include <sys/cred_impl.h> 417c478bd9Sstevel@tonic-gate #include <sys/systm.h> 427c478bd9Sstevel@tonic-gate #include <sys/errno.h> 437c478bd9Sstevel@tonic-gate #include <sys/pathname.h> 447c478bd9Sstevel@tonic-gate #include <sys/vnode.h> 457c478bd9Sstevel@tonic-gate #include <sys/uio.h> 467c478bd9Sstevel@tonic-gate #include <sys/cmn_err.h> 477c478bd9Sstevel@tonic-gate #include <sys/debug.h> 4848011479Ssn199410 #include <sys/file.h> 49dd29fa4aSprabahar #include <fs/fs_subr.h> 5048011479Ssn199410 #include <c2/audit.h> 517c478bd9Sstevel@tonic-gate 527c478bd9Sstevel@tonic-gate /* 537c478bd9Sstevel@tonic-gate * Determine accessibility of file. 547c478bd9Sstevel@tonic-gate */ 557c478bd9Sstevel@tonic-gate 567c478bd9Sstevel@tonic-gate #define E_OK 010 /* use effective ids */ 577c478bd9Sstevel@tonic-gate #define R_OK 004 587c478bd9Sstevel@tonic-gate #define W_OK 002 597c478bd9Sstevel@tonic-gate #define X_OK 001 607c478bd9Sstevel@tonic-gate 6148011479Ssn199410 static int 6248011479Ssn199410 caccess(char *fname, int fmode, vnode_t *startvp) 637c478bd9Sstevel@tonic-gate { 647c478bd9Sstevel@tonic-gate vnode_t *vp; 657c478bd9Sstevel@tonic-gate cred_t *tmpcr; 667c478bd9Sstevel@tonic-gate int error; 677c478bd9Sstevel@tonic-gate int mode; 687c478bd9Sstevel@tonic-gate int eok; 697c478bd9Sstevel@tonic-gate cred_t *cr; 70dd29fa4aSprabahar int estale_retry = 0; 717c478bd9Sstevel@tonic-gate 727c478bd9Sstevel@tonic-gate if (fmode & ~(E_OK|R_OK|W_OK|X_OK)) 737c478bd9Sstevel@tonic-gate return (set_errno(EINVAL)); 747c478bd9Sstevel@tonic-gate 757c478bd9Sstevel@tonic-gate mode = ((fmode & (R_OK|W_OK|X_OK)) << 6); 767c478bd9Sstevel@tonic-gate 777c478bd9Sstevel@tonic-gate cr = CRED(); 787c478bd9Sstevel@tonic-gate 797c478bd9Sstevel@tonic-gate /* OK to use effective uid/gid, i.e., no need to crdup(CRED())? */ 807c478bd9Sstevel@tonic-gate eok = (fmode & E_OK) || 817c478bd9Sstevel@tonic-gate (cr->cr_uid == cr->cr_ruid && cr->cr_gid == cr->cr_rgid); 827c478bd9Sstevel@tonic-gate 837c478bd9Sstevel@tonic-gate if (eok) 847c478bd9Sstevel@tonic-gate tmpcr = cr; 857c478bd9Sstevel@tonic-gate else { 867c478bd9Sstevel@tonic-gate tmpcr = crdup(cr); 877c478bd9Sstevel@tonic-gate tmpcr->cr_uid = cr->cr_ruid; 887c478bd9Sstevel@tonic-gate tmpcr->cr_gid = cr->cr_rgid; 897c478bd9Sstevel@tonic-gate tmpcr->cr_ruid = cr->cr_uid; 907c478bd9Sstevel@tonic-gate tmpcr->cr_rgid = cr->cr_gid; 917c478bd9Sstevel@tonic-gate } 927c478bd9Sstevel@tonic-gate 937c478bd9Sstevel@tonic-gate lookup: 9448011479Ssn199410 if (error = lookupnameat(fname, UIO_USERSPACE, FOLLOW, NULLVPP, &vp, 9548011479Ssn199410 startvp)) { 96dd29fa4aSprabahar if ((error == ESTALE) && fs_need_estale_retry(estale_retry++)) 977c478bd9Sstevel@tonic-gate goto lookup; 987c478bd9Sstevel@tonic-gate if (!eok) 997c478bd9Sstevel@tonic-gate crfree(tmpcr); 1007c478bd9Sstevel@tonic-gate return (set_errno(error)); 1017c478bd9Sstevel@tonic-gate } 1027c478bd9Sstevel@tonic-gate 1037c478bd9Sstevel@tonic-gate if (mode) { 104*da6c28aaSamw error = VOP_ACCESS(vp, mode, 0, tmpcr, NULL); 1057c478bd9Sstevel@tonic-gate if (error) { 106dd29fa4aSprabahar if ((error == ESTALE) && 107dd29fa4aSprabahar fs_need_estale_retry(estale_retry++)) { 1087c478bd9Sstevel@tonic-gate VN_RELE(vp); 1097c478bd9Sstevel@tonic-gate goto lookup; 1107c478bd9Sstevel@tonic-gate } 1117c478bd9Sstevel@tonic-gate (void) set_errno(error); 1127c478bd9Sstevel@tonic-gate } 1137c478bd9Sstevel@tonic-gate } 1147c478bd9Sstevel@tonic-gate 1157c478bd9Sstevel@tonic-gate if (!eok) 1167c478bd9Sstevel@tonic-gate crfree(tmpcr); 1177c478bd9Sstevel@tonic-gate VN_RELE(vp); 1187c478bd9Sstevel@tonic-gate return (error); 1197c478bd9Sstevel@tonic-gate } 12048011479Ssn199410 12148011479Ssn199410 int 12248011479Ssn199410 access(char *fname, int fmode) 12348011479Ssn199410 { 12448011479Ssn199410 return (caccess(fname, fmode, NULL)); 12548011479Ssn199410 } 12648011479Ssn199410 12748011479Ssn199410 int 12848011479Ssn199410 accessat(int fd, char *fname, int fmode) 12948011479Ssn199410 { 13048011479Ssn199410 file_t *dirfp; 13148011479Ssn199410 vnode_t *dirvp; 13248011479Ssn199410 int error; 13348011479Ssn199410 char startchar; 13448011479Ssn199410 13548011479Ssn199410 if (fd == AT_FDCWD && fname == NULL) 13648011479Ssn199410 return (set_errno(EFAULT)); 13748011479Ssn199410 13848011479Ssn199410 if (fname != NULL) { 13948011479Ssn199410 if (copyin(fname, &startchar, sizeof (char))) 14048011479Ssn199410 return (set_errno(EFAULT)); 14148011479Ssn199410 } else 14248011479Ssn199410 startchar = '\0'; 14348011479Ssn199410 14448011479Ssn199410 if (fd == AT_FDCWD) { 14548011479Ssn199410 dirvp = NULL; 14648011479Ssn199410 } else { 14748011479Ssn199410 if (startchar != '/') { 14848011479Ssn199410 if ((dirfp = getf(fd)) == NULL) { 14948011479Ssn199410 return (set_errno(EBADF)); 15048011479Ssn199410 } 15148011479Ssn199410 dirvp = dirfp->f_vnode; 15248011479Ssn199410 VN_HOLD(dirvp); 15348011479Ssn199410 releasef(fd); 15448011479Ssn199410 } else { 15548011479Ssn199410 dirvp = NULL; 15648011479Ssn199410 } 15748011479Ssn199410 } 15848011479Ssn199410 15948011479Ssn199410 #ifdef C2_AUDIT 16048011479Ssn199410 if (audit_active) 16148011479Ssn199410 audit_setfsat_path(1); 16248011479Ssn199410 #endif /* C2_AUDIT */ 16348011479Ssn199410 16448011479Ssn199410 error = caccess(fname, fmode, dirvp); 16548011479Ssn199410 if (dirvp != NULL) 16648011479Ssn199410 VN_RELE(dirvp); 16748011479Ssn199410 16848011479Ssn199410 return (error); 16948011479Ssn199410 } 170