From nobody Tue Sep 29 15:57:30 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hvN9R3lZfz6tl9j for ; Tue, 29 Sep 2026 15:57:31 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hvN9R0LXPz4YBD for ; Tue, 29 Sep 2026 15:57:31 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790697451; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=1cFYa7qFr9bkXbwG7IYxiFMAw1bn/1wp8OY77ejo5BM=; b=HSCx+06ztPCG7zSwFeFljMBSV37wY6JHQ8FnFwHaTb3Rj4lP90A5WpAkjIliRRSI7asjIN DVv0uY4SQvQ0sXt9x61/yur6JkaJu83D+hd3IMHF1schqO4gBLGacwXUK7uIERBS/t/fI9 GjtQ5pVgLT58hFBK3UmAveZ3o0s+fKW5EF0oHz39tdAqemv0cXmOLGN6SMO9vkgeseQR1B 05di/9+zM5RDqeU5C872DqYx24UC5lpC2cW7EDfLrFbIwhc9H6X8yAO04Yl2ObUUekCCx0 JTFeMcCo15yXfb0ZNfqNvFSXpqKfGxj2o0/JBIW1WtZuHK8JNd1yHfsjORKkng== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790697451; b=Y+S1JmSIe6cR04CManmZjXS+VyuoLFpCNtzo58yHp2eVM//UZARZS39TrA39eCqrW7qfhu 0blrC/B+z0+qQJqOIHBz10d5zC29w+thSR6/N9rvbCDXunG215FJtmJm9q3p7my6FHEhj5 Tkv5vf7fNh4kv2eBzCdtULl2ffk8UdaWrnVvIh2VoVJNKHAMoEU/cXR/qZvTu70BFEQCzf 7+Kg1gs9uoS5EKSWB/5/dtKRtQru54N8az9a7X4ccjO+Azr9YzhbHWiZAlFCcBV4uj5CMF +bJlQjoiAYm8yz98p/e+npRZfewSGdDB6PCaSwugeEqCz/Fzvmlt64mqt0xjjQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790697451; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=1cFYa7qFr9bkXbwG7IYxiFMAw1bn/1wp8OY77ejo5BM=; b=LqrYzNRbRYx7D5ulKsblS94Uru2fhTScJ+sExdCwdHT8M1hcJOXTb3FwvBGau4wtogeiui x30qlfu0v4VY+fICwe+S19vCnH5b1RJoIcD21ZuFNXkMKnxt30f6DfPJYJFhRmsmQLCoeV gTvLBNFjYGuuYZ3txafT5IG7BG4UmWI8Aup43FhVMcUhn6nj1BMp3vN05WiQNl0VKXi8Gb FuLXyrygZ6FxNBJL3zHRr19/vUHnNQw4K7qJWC7+rGBgRDcN1GFN9HIWcy+eJzmoGQh+07 80VFZJjhBur2i9ddxKT7FFM22H+IkPUAaikPkpDpwQ8TY55y2aPrX6Hbwgd2Ig== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hvN9Q6XCcz1Jb4 for ; Tue, 29 Sep 2026 15:57:30 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 25a6b by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Tue, 29 Sep 2026 15:57:30 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Mark Johnston Subject: git: 4c3de56d2819 - releng/14.4 - file: Add a helper function to check whether filecaps are full List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/releng/14.4 X-Git-Reftype: branch X-Git-Commit: 4c3de56d28199fced38dc05c740d95cade9a6e1e Auto-Submitted: auto-generated Date: Tue, 29 Sep 2026 15:57:30 +0000 Message-Id: <6abbdfea.25a6b.5b9eb659@gitrepo.freebsd.org> The branch releng/14.4 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=4c3de56d28199fced38dc05c740d95cade9a6e1e commit 4c3de56d28199fced38dc05c740d95cade9a6e1e Author: Mark Johnston AuthorDate: 2026-09-28 14:42:29 +0000 Commit: Mark Johnston CommitDate: 2026-09-28 17:53:18 +0000 file: Add a helper function to check whether filecaps are full In a couple of places we want to know whether someone has limited rights on an fd. There, we want a predicate which determines whether the set of rights is smaller than CAP_ALL, and whether there are explicit ioctl or fcntl lists. Factor this out into a helper function, in preparation for use elsewhere. No functional change intended. Approved by: so Security: FreeBSD-SA-26:66.jail Reviewed by: kib Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D59884 --- sys/kern/kern_descrip.c | 20 ++++++++++++-------- sys/sys/filedesc.h | 1 + 2 files changed, 13 insertions(+), 8 deletions(-) diff --git a/sys/kern/kern_descrip.c b/sys/kern/kern_descrip.c index 51752aa8ab33..19d038fec651 100644 --- a/sys/kern/kern_descrip.c +++ b/sys/kern/kern_descrip.c @@ -1844,6 +1844,16 @@ filecaps_free(struct filecaps *fcaps) bzero(fcaps, sizeof(*fcaps)); } +bool +filecaps_full(const struct filecaps *fcaps) +{ + cap_rights_t allrights; + + CAP_ALL(&allrights); + return (cap_rights_contains(&fcaps->fc_rights, &allrights) && + fcaps->fc_fcntls == CAP_FCNTL_ALL && fcaps->fc_nioctls == -1); +} + static u_long * filecaps_free_prep(struct filecaps *fcaps) { @@ -3113,10 +3123,7 @@ fgetvp_lookup_smr(struct nameidata *ndp, struct vnode **vpp, int *flagsp) * * Not yet supported by fast path. */ - CAP_ALL(&rights); - if (!cap_rights_contains(&ndp->ni_filecaps.fc_rights, &rights) || - ndp->ni_filecaps.fc_fcntls != CAP_FCNTL_ALL || - ndp->ni_filecaps.fc_nioctls != -1) { + if (!filecaps_full(&ndp->ni_filecaps)) { #ifdef notyet ndp->ni_lcf |= NI_LCF_STRICTREL; #else @@ -3218,10 +3225,7 @@ fgetvp_lookup(struct nameidata *ndp, struct vnode **vpp) * all lookups relative to it must also be * strictly relative. */ - CAP_ALL(&rights); - if (!cap_rights_contains(&ndp->ni_filecaps.fc_rights, &rights) || - ndp->ni_filecaps.fc_fcntls != CAP_FCNTL_ALL || - ndp->ni_filecaps.fc_nioctls != -1) { + if (!filecaps_full(&ndp->ni_filecaps)) { ndp->ni_lcf |= NI_LCF_STRICTREL; ndp->ni_resflags |= NIRES_STRICTREL; } diff --git a/sys/sys/filedesc.h b/sys/sys/filedesc.h index 440c5d3d15f9..48c90823343a 100644 --- a/sys/sys/filedesc.h +++ b/sys/sys/filedesc.h @@ -242,6 +242,7 @@ bool filecaps_copy(const struct filecaps *src, struct filecaps *dst, bool locked); void filecaps_move(struct filecaps *src, struct filecaps *dst); void filecaps_free(struct filecaps *fcaps); +bool filecaps_full(const struct filecaps *fcaps); int closef(struct file *fp, struct thread *td); void closef_nothread(struct file *fp);