git: a76e986470f8 - main - sysctl: Return ECAPMODE when trying to access sysctls in capability mode
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Tue, 29 Sep 2026 01:29:38 UTC
The branch main has been updated by markj:
URL: https://cgit.FreeBSD.org/src/commit/?id=a76e986470f86731dd3a5f9eeae1ba28b8b160fb
commit a76e986470f86731dd3a5f9eeae1ba28b8b160fb
Author: Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-28 21:59:40 +0000
Commit: Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-29 01:29:22 +0000
sysctl: Return ECAPMODE when trying to access sysctls in capability mode
We have always returned EPERM in this case, but it's incorrect, we
should return ECAPMODE for capability mode violations. Fix the errno
value.
Reviewed by: emaste
MFC after: 2 weeks
Differential Revision: https://reviews.freebsd.org/D59887
---
lib/libc/gen/sysctl.3 | 3 +++
sys/kern/kern_sysctl.c | 2 +-
2 files changed, 4 insertions(+), 1 deletion(-)
diff --git a/lib/libc/gen/sysctl.3 b/lib/libc/gen/sysctl.3
index 75fd6307bd30..4278888948fa 100644
--- a/lib/libc/gen/sysctl.3
+++ b/lib/libc/gen/sysctl.3
@@ -957,6 +957,9 @@ array specifies a value that is unknown.
An attempt is made to set a read-only value.
.It Bq Er EPERM
A process without appropriate privilege attempts to set a value.
+.It Bq Er ECAPMODE
+The process is in capability mode and the variable is not accessible
+in capability mode.
.El
.Sh SEE ALSO
.Xr confstr 3 ,
diff --git a/sys/kern/kern_sysctl.c b/sys/kern/kern_sysctl.c
index 423d792cb4ec..ad2d4ae22a77 100644
--- a/sys/kern/kern_sysctl.c
+++ b/sys/kern/kern_sysctl.c
@@ -2370,7 +2370,7 @@ sysctl_root(SYSCTL_HANDLER_ARGS)
if (IN_CAPABILITY_MODE(req->td)) {
if ((req->oldptr && !(oid->oid_kind & CTLFLAG_CAPRD)) ||
(req->newptr && !(oid->oid_kind & CTLFLAG_CAPWR))) {
- error = EPERM;
+ error = ECAPMODE;
goto out;
}
}