47#include <sys/capsicum.h>
48#include <sys/condvar.h>
51#include <sys/filedesc.h>
52#include <sys/fnv_hash.h>
54#include <sys/kernel.h>
57#include <sys/malloc.h>
58#include <sys/module.h>
62#include <sys/posix4.h>
63#include <sys/_semaphore.h>
65#include <sys/syscall.h>
66#include <sys/syscallsubr.h>
67#include <sys/sysctl.h>
68#include <sys/sysent.h>
69#include <sys/sysproto.h>
75#include <security/audit/audit.h>
76#include <security/mac/mac_framework.h>
78FEATURE(p1003_1b_semaphores,
"POSIX P1003.1B semaphores support");
106static struct sx ksem_dict_lock;
107static struct mtx ksem_count_lock;
108static struct mtx sem_lock;
109static u_long ksem_hash;
112#define KSEM_HASH(fnv) (&ksem_dictionary[(fnv) & ksem_hash])
116SYSCTL_INT(_p1003_1b, OID_AUTO, nsems, CTLFLAG_RD, &nsems, 0,
117 "Number of active kernel POSIX semaphores");
119static int kern_sem_wait(
struct thread *td, semid_t
id,
int tryflag,
120 struct timespec *abstime);
121static int ksem_access(
struct ksem *ks,
struct ucred *ucred);
125 semid_t *semidp, mode_t
mode,
unsigned int value,
126 int flags,
int compat32);
128static int ksem_get(
struct thread *td, semid_t
id, cap_rights_t *rightsp,
130static struct ksem *
ksem_hold(
struct ksem *ks);
145static struct fileops ksem_ops = {
158 .fo_flags = DFLAG_PASSABLE
164ksem_stat(
struct file *fp,
struct stat *sb,
struct ucred *active_cred)
174 error = mac_posixsem_check_stat(active_cred, fp->f_cred, ks);
183 bzero(sb,
sizeof(*sb));
186 sb->st_atim = ks->ks_atime;
187 sb->st_ctim = ks->ks_ctime;
188 sb->st_mtim = ks->ks_mtime;
189 sb->st_birthtim = ks->ks_birthtime;
190 sb->st_uid = ks->ks_uid;
191 sb->st_gid = ks->ks_gid;
192 sb->st_mode = S_IFREG | ks->ks_mode;
193 mtx_unlock(&sem_lock);
209 error = mac_posixsem_check_setmode(active_cred, ks,
mode);
213 error =
vaccess(VREG, ks->ks_mode, ks->ks_uid, ks->ks_gid, VADMIN,
217 ks->ks_mode =
mode & ACCESSPERMS;
219 mtx_unlock(&sem_lock);
224ksem_chown(
struct file *fp, uid_t uid, gid_t gid,
struct ucred *active_cred,
234 error = mac_posixsem_check_setowner(active_cred, ks, uid, gid);
238 if (uid == (uid_t)-1)
240 if (gid == (gid_t)-1)
242 if (((uid != ks->ks_uid && uid != active_cred->cr_uid) ||
243 (gid != ks->ks_gid && !
groupmember(gid, active_cred))) &&
249 mtx_unlock(&sem_lock);
268 const char *
path, *pr_path;
272 kif->kf_type = KF_TYPE_SEM;
275 kif->kf_un.kf_sem.kf_sem_value = ks->ks_value;
276 kif->kf_un.kf_sem.kf_sem_mode = S_IFREG | ks->ks_mode;
277 mtx_unlock(&sem_lock);
278 if (ks->ks_path != NULL) {
279 sx_slock(&ksem_dict_lock);
280 if (ks->ks_path != NULL) {
282 pr_path = curthread->td_ucred->cr_prison->pr_path;
283 if (strcmp(pr_path,
"/") != 0) {
285 pr_pathlen = strlen(pr_path);
286 if (strncmp(
path, pr_path, pr_pathlen) == 0 &&
287 path[pr_pathlen] ==
'/')
290 strlcpy(kif->kf_path,
path,
sizeof(kif->kf_path));
292 sx_sunlock(&ksem_dict_lock);
306 mtx_lock(&ksem_count_lock);
307 if (nsems ==
p31b_getcfg(CTL_P1003_1B_SEM_NSEMS_MAX) || ksem_dead) {
308 mtx_unlock(&ksem_count_lock);
312 mtx_unlock(&ksem_count_lock);
313 ks =
malloc(
sizeof(*ks), M_KSEM, M_WAITOK | M_ZERO);
314 ks->ks_uid = ucred->cr_uid;
315 ks->ks_gid = ucred->cr_gid;
317 ks->ks_value =
value;
320 ks->ks_atime = ks->ks_mtime = ks->ks_ctime = ks->ks_birthtime;
321 refcount_init(&ks->ks_ref, 1);
323 mac_posixsem_init(ks);
324 mac_posixsem_create(ucred, ks);
334 refcount_acquire(&ks->ks_ref);
342 if (refcount_release(&ks->ks_ref)) {
344 mac_posixsem_destroy(ks);
348 mtx_lock(&ksem_count_lock);
350 mtx_unlock(&ksem_count_lock);
363 error =
vaccess(VREG, ks->ks_mode, ks->ks_uid, ks->ks_gid,
364 VREAD | VWRITE, ucred);
380 LIST_FOREACH(map,
KSEM_HASH(fnv), km_link) {
400 LIST_INSERT_HEAD(
KSEM_HASH(fnv), map, km_link);
409 LIST_FOREACH(map,
KSEM_HASH(fnv), km_link) {
414 error = mac_posixsem_check_unlink(ucred, map->
km_ksem);
422 LIST_REMOVE(map, km_link);
438#ifdef COMPAT_FREEBSD32
444#ifdef COMPAT_FREEBSD32
448 ptrs =
sizeof(semid32);
453 ptrs =
sizeof(semid);
455#ifdef COMPAT_FREEBSD32
459 return (copyout(ptr, semidp, ptrs));
476 AUDIT_ARG_FFLAGS(
flags);
477 AUDIT_ARG_MODE(
mode);
478 AUDIT_ARG_VALUE(
value);
480 if (
value > SEM_VALUE_MAX)
483 pdp = td->td_proc->p_pd;
484 mode = (
mode & ~pdp->pd_cmask) & ACCESSPERMS;
485 error = falloc(td, &fp, &
fd, O_CLOEXEC);
510 ks->ks_flags |= KS_ANONYMOUS;
513 pr_path = td->td_ucred->cr_prison->pr_path;
516 pr_pathlen = strcmp(pr_path,
"/") == 0 ? 0
517 : strlcpy(
path, pr_path, MAXPATHLEN);
518 error = copyinstr(
name,
path + pr_pathlen,
519 MAXPATHLEN - pr_pathlen, NULL);
522 if (error == 0 &&
path[pr_pathlen] !=
'/')
531 AUDIT_ARG_UPATH1_CANON(
path);
532 fnv = fnv_32_str(
path, FNV1_32_INIT);
533 sx_xlock(&ksem_dict_lock);
537 if (
flags & O_CREAT) {
552 if ((
flags & (O_CREAT | O_EXCL)) ==
557 error = mac_posixsem_check_open(td->td_ucred,
570 sx_xunlock(&ksem_dict_lock);
576 KASSERT(ks == NULL, (
"ksem_create error with a ksem"));
581 KASSERT(ks != NULL, (
"ksem_create w/o a ksem"));
583 finit(fp, FREAD | FWRITE, DTYPE_SEM, ks, &ksem_ops);
591ksem_get(
struct thread *td, semid_t
id, cap_rights_t *rightsp,
598 error =
fget(td,
id, rightsp, &fp);
601 if (fp->f_type != DTYPE_SEM) {
606 if (ks->ks_flags & KS_DEAD) {
615#ifndef _SYS_SYSPROTO_H_
629#ifndef _SYS_SYSPROTO_H_
642 DP((
">>> ksem_open start, pid=%d\n", (
int)td->td_proc->p_pid));
644 if ((uap->
oflag & ~(O_CREAT | O_EXCL)) != 0)
650#ifndef _SYS_SYSPROTO_H_
665 pr_path = td->td_ucred->cr_prison->pr_path;
666 pr_pathlen = strcmp(pr_path,
"/") == 0 ? 0
667 : strlcpy(
path, pr_path, MAXPATHLEN);
668 error = copyinstr(uap->
name,
path + pr_pathlen, MAXPATHLEN - pr_pathlen,
675 AUDIT_ARG_UPATH1_CANON(
path);
676 fnv = fnv_32_str(
path, FNV1_32_INIT);
677 sx_xlock(&ksem_dict_lock);
679 sx_xunlock(&ksem_dict_lock);
685#ifndef _SYS_SYSPROTO_H_
698 AUDIT_ARG_FD(uap->
id);
703 if (ks->ks_flags & KS_ANONYMOUS) {
712#ifndef _SYS_SYSPROTO_H_
725 AUDIT_ARG_FD(uap->
id);
727 cap_rights_init_one(&rights, CAP_SEM_POST), &fp);
734 error = mac_posixsem_check_post(td->td_ucred, fp->f_cred, ks);
738 if (ks->ks_value == SEM_VALUE_MAX) {
743 if (ks->ks_waiters > 0)
748 mtx_unlock(&sem_lock);
753#ifndef _SYS_SYSPROTO_H_
765#ifndef _SYS_SYSPROTO_H_
774 struct timespec abstime;
784 error = copyin(uap->
abstime, &abstime,
sizeof(abstime));
787 if (abstime.tv_nsec >= 1000000000 || abstime.tv_nsec < 0)
794#ifndef _SYS_SYSPROTO_H_
808 struct timespec *abstime)
810 struct timespec ts1, ts2;
817 DP((
">>> kern_sem_wait entered! pid=%d\n", (
int)td->td_proc->p_pid));
819 error =
ksem_get(td,
id, cap_rights_init_one(&rights, CAP_SEM_WAIT),
825 DP((
">>> kern_sem_wait critical section entered! pid=%d\n",
826 (
int)td->td_proc->p_pid));
828 error = mac_posixsem_check_wait(td->td_ucred, fp->f_cred, ks);
830 DP((
"kern_sem_wait mac failed\n"));
834 DP((
"kern_sem_wait value = %d, tryflag %d\n", ks->ks_value, tryflag));
836 while (ks->ks_value == 0) {
840 else if (abstime == NULL)
841 error = cv_wait_sig(&ks->ks_cv, &sem_lock);
846 timespecsub(&ts1, &ts2, &ts1);
847 TIMESPEC_TO_TIMEVAL(&tv, &ts1);
852 error = cv_timedwait_sig(&ks->ks_cv,
854 if (error != EWOULDBLOCK)
863 DP((
"kern_sem_wait value post-decrement = %d\n", ks->ks_value));
866 mtx_unlock(&sem_lock);
868 DP((
"<<< kern_sem_wait leaving, pid=%d, error = %d\n",
869 (
int)td->td_proc->p_pid, error));
873#ifndef _SYS_SYSPROTO_H_
887 AUDIT_ARG_FD(uap->
id);
889 cap_rights_init_one(&rights, CAP_SEM_GETVALUE), &fp);
896 error = mac_posixsem_check_getvalue(td->td_ucred, fp->f_cred, ks);
898 mtx_unlock(&sem_lock);
905 mtx_unlock(&sem_lock);
907 error = copyout(&val, uap->
val,
sizeof(val));
911#ifndef _SYS_SYSPROTO_H_
924 AUDIT_ARG_FD(uap->
id);
929 if (!(ks->ks_flags & KS_ANONYMOUS)) {
934 if (ks->ks_waiters != 0) {
935 mtx_unlock(&sem_lock);
939 ks->ks_flags |= KS_DEAD;
940 mtx_unlock(&sem_lock);
949 SYSCALL_INIT_HELPER(ksem_init),
950 SYSCALL_INIT_HELPER(ksem_open),
951 SYSCALL_INIT_HELPER(ksem_unlink),
952 SYSCALL_INIT_HELPER(ksem_close),
953 SYSCALL_INIT_HELPER(ksem_post),
954 SYSCALL_INIT_HELPER(ksem_wait),
955 SYSCALL_INIT_HELPER(ksem_timedwait),
956 SYSCALL_INIT_HELPER(ksem_trywait),
957 SYSCALL_INIT_HELPER(ksem_getvalue),
958 SYSCALL_INIT_HELPER(ksem_destroy),
962#ifdef COMPAT_FREEBSD32
963#include <compat/freebsd32/freebsd32.h>
964#include <compat/freebsd32/freebsd32_proto.h>
965#include <compat/freebsd32/freebsd32_signal.h>
966#include <compat/freebsd32/freebsd32_syscall.h>
967#include <compat/freebsd32/freebsd32_util.h>
970freebsd32_ksem_init(
struct thread *td,
struct freebsd32_ksem_init_args *uap)
973 return (
ksem_create(td, NULL, (semid_t *)uap->idp, S_IRWXU | S_IRWXG, uap->value,
978freebsd32_ksem_open(
struct thread *td,
struct freebsd32_ksem_open_args *uap)
981 if ((uap->oflag & ~(O_CREAT | O_EXCL)) != 0)
983 return (
ksem_create(td, uap->name, (semid_t *)uap->idp, uap->mode, uap->value,
988freebsd32_ksem_timedwait(
struct thread *td,
989 struct freebsd32_ksem_timedwait_args *uap)
991 struct timespec32 abstime32;
992 struct timespec *
ts, abstime;
998 if (uap->abstime == NULL)
1001 error = copyin(uap->abstime, &abstime32,
sizeof(abstime32));
1004 CP(abstime32, abstime, tv_sec);
1005 CP(abstime32, abstime, tv_nsec);
1006 if (abstime.tv_nsec >= 1000000000 || abstime.tv_nsec < 0)
1013static struct syscall_helper_data ksem32_syscalls[] = {
1014 SYSCALL32_INIT_HELPER(freebsd32_ksem_init),
1015 SYSCALL32_INIT_HELPER(freebsd32_ksem_open),
1016 SYSCALL32_INIT_HELPER_COMPAT(ksem_unlink),
1017 SYSCALL32_INIT_HELPER_COMPAT(ksem_close),
1018 SYSCALL32_INIT_HELPER_COMPAT(ksem_post),
1019 SYSCALL32_INIT_HELPER_COMPAT(ksem_wait),
1020 SYSCALL32_INIT_HELPER(freebsd32_ksem_timedwait),
1021 SYSCALL32_INIT_HELPER_COMPAT(ksem_trywait),
1022 SYSCALL32_INIT_HELPER_COMPAT(ksem_getvalue),
1023 SYSCALL32_INIT_HELPER_COMPAT(ksem_destroy),
1033 mtx_init(&sem_lock,
"sem", NULL, MTX_DEF);
1034 mtx_init(&ksem_count_lock,
"ksem count", NULL, MTX_DEF);
1035 sx_init(&ksem_dict_lock,
"ksem dictionary");
1036 ksem_dictionary =
hashinit(1024, M_KSEM, &ksem_hash);
1039 p31b_setcfg(CTL_P1003_1B_SEM_VALUE_MAX, SEM_VALUE_MAX);
1044#ifdef COMPAT_FREEBSD32
1045 error = syscall32_helper_register(ksem32_syscalls, SY_THR_STATIC_KLD);
1056#ifdef COMPAT_FREEBSD32
1057 syscall32_helper_unregister(ksem32_syscalls);
1064 mtx_destroy(&ksem_count_lock);
1065 mtx_destroy(&sem_lock);
1083 mtx_lock(&ksem_count_lock);
1086 mtx_unlock(&ksem_count_lock);
1090 mtx_unlock(&ksem_count_lock);
SYSCTL_INT(ASLR_NODE_OID, OID_AUTO, enable, CTLFLAG_RWTUN, &__elfN(aslr_enabled), 0, ": enable address map randomization")
int tvtohz(struct timeval *tv)
void cv_init(struct cv *cvp, const char *desc)
void cv_destroy(struct cv *cvp)
void cv_signal(struct cv *cvp)
int invfo_ioctl(struct file *fp, u_long com, void *data, struct ucred *active_cred, struct thread *td)
int invfo_truncate(struct file *fp, off_t length, struct ucred *active_cred, struct thread *td)
void fdclose(struct thread *td, struct file *fp, int idx)
int kern_close(struct thread *td, int fd)
int invfo_poll(struct file *fp, int events, struct ucred *active_cred, struct thread *td)
int fget(struct thread *td, int fd, cap_rights_t *rightsp, struct file **fpp)
void finit(struct file *fp, u_int flag, short type, void *data, struct fileops *ops)
int invfo_sendfile(struct file *fp, int sockfd, struct uio *hdr_uio, struct uio *trl_uio, off_t offset, size_t nbytes, off_t *sent, int flags, struct thread *td)
int invfo_rdwr(struct file *fp, struct uio *uio, struct ucred *active_cred, int flags, struct thread *td)
int invfo_kqfilter(struct file *fp, struct knote *kn)
void *() malloc(size_t size, struct malloc_type *mtp, int flags)
void free(void *addr, struct malloc_type *mtp)
int priv_check_cred(struct ucred *cred, int priv)
int groupmember(gid_t gid, struct ucred *cred)
void sx_destroy(struct sx *sx)
int syscall_helper_unregister(struct syscall_helper_data *sd)
int syscall_helper_register(struct syscall_helper_data *sd, int flags)
void getnanotime(struct timespec *tsp)
void p31b_setcfg(int num, int value)
void p31b_unsetcfg(int num)
const struct timespec * abstime
__read_mostly cap_rights_t cap_no_rights
void hashdestroy(void *vhashtbl, struct malloc_type *type, u_long hashmask)
void * hashinit(int elements, struct malloc_type *type, u_long *hashmask)
int sys_ksem_init(struct thread *td, struct ksem_init_args *uap)
int sys_ksem_timedwait(struct thread *td, struct ksem_timedwait_args *uap)
int sys_ksem_unlink(struct thread *td, struct ksem_unlink_args *uap)
int sys_ksem_post(struct thread *td, struct ksem_post_args *uap)
static void ksem_insert(char *path, Fnv32_t fnv, struct ksem *ks)
static void ksem_module_destroy(void)
static int ksem_create_copyout_semid(struct thread *td, semid_t *semidp, int fd, int compat32)
static moduledata_t sem_mod
static int sem_modload(struct module *module, int cmd, void *arg)
static int ksem_remove(char *path, Fnv32_t fnv, struct ucred *ucred)
static int ksem_stat(struct file *fp, struct stat *sb, struct ucred *active_cred)
static LIST_HEAD(ksem_mapping)
static int ksem_create(struct thread *td, const char *name, semid_t *semidp, mode_t mode, unsigned int value, int flags, int compat32)
static void ksem_drop(struct ksem *ks)
static int ksem_module_init(void)
int sys_ksem_destroy(struct thread *td, struct ksem_destroy_args *uap)
static struct ksem * ksem_alloc(struct ucred *ucred, mode_t mode, unsigned int value)
int sys_ksem_trywait(struct thread *td, struct ksem_trywait_args *uap)
static int ksem_chmod(struct file *fp, mode_t mode, struct ucred *active_cred, struct thread *td)
static struct ksem * ksem_hold(struct ksem *ks)
int sys_ksem_wait(struct thread *td, struct ksem_wait_args *uap)
FEATURE(p1003_1b_semaphores, "POSIX P1003.1B semaphores support")
static int ksem_closef(struct file *fp, struct thread *td)
static int ksem_access(struct ksem *ks, struct ucred *ucred)
static int ksem_chown(struct file *fp, uid_t uid, gid_t gid, struct ucred *active_cred, struct thread *td)
int sys_ksem_open(struct thread *td, struct ksem_open_args *uap)
static struct syscall_helper_data ksem_syscalls[]
static int ksem_get(struct thread *td, semid_t id, cap_rights_t *rightsp, struct file **fpp)
static int ksem_fill_kinfo(struct file *fp, struct kinfo_file *kif, struct filedesc *fdp)
DECLARE_MODULE(sem, sem_mod, SI_SUB_SYSV_SEM, SI_ORDER_FIRST)
static struct ksem * ksem_lookup(char *path, Fnv32_t fnv)
int sys_ksem_getvalue(struct thread *td, struct ksem_getvalue_args *uap)
static MALLOC_DEFINE(M_KSEM, "ksem", "semaphore file descriptor")
static int kern_sem_wait(struct thread *td, semid_t id, int tryflag, struct timespec *abstime)
int sys_ksem_close(struct thread *td, struct ksem_close_args *uap)
int vaccess(enum vtype type, mode_t file_mode, uid_t file_uid, gid_t file_gid, accmode_t accmode, struct ucred *cred)
void vfs_timestamp(struct timespec *tsp)