git: e024dcebb54b - releng/14.5 - file: Add a helper function to check whether filecaps are full

From: Mark Johnston <markj_at_FreeBSD.org>
Date: Tue, 29 Sep 2026 16:09:05 UTC
The branch releng/14.5 has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=e024dcebb54b77a22d935bc713a26fc49d808456

commit e024dcebb54b77a22d935bc713a26fc49d808456
Author:     Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-28 14:42:29 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-28 18:20:13 +0000

    file: Add a helper function to check whether filecaps are full
    
    In a couple of places we want to know whether someone has limited rights
    on an fd.  There, we want a predicate which determines whether the set
    of rights is smaller than CAP_ALL, and whether there are explicit ioctl
    or fcntl lists.  Factor this out into a helper function, in preparation
    for use elsewhere.
    
    No functional change intended.
    
    Approved by:    so
    Security:       FreeBSD-SA-26:66.jail
    Reviewed by:    kib
    Sponsored by:   The FreeBSD Foundation
    Differential Revision:  https://reviews.freebsd.org/D59884
---
 sys/kern/kern_descrip.c | 20 ++++++++++++--------
 sys/sys/filedesc.h      |  1 +
 2 files changed, 13 insertions(+), 8 deletions(-)

diff --git a/sys/kern/kern_descrip.c b/sys/kern/kern_descrip.c
index 9980c4c9a99d..e551944b638b 100644
--- a/sys/kern/kern_descrip.c
+++ b/sys/kern/kern_descrip.c
@@ -1844,6 +1844,16 @@ filecaps_free(struct filecaps *fcaps)
 	bzero(fcaps, sizeof(*fcaps));
 }
 
+bool
+filecaps_full(const struct filecaps *fcaps)
+{
+	cap_rights_t allrights;
+
+	CAP_ALL(&allrights);
+	return (cap_rights_contains(&fcaps->fc_rights, &allrights) &&
+	    fcaps->fc_fcntls == CAP_FCNTL_ALL && fcaps->fc_nioctls == -1);
+}
+
 static u_long *
 filecaps_free_prep(struct filecaps *fcaps)
 {
@@ -3113,10 +3123,7 @@ fgetvp_lookup_smr(struct nameidata *ndp, struct vnode **vpp, int *flagsp)
 	 *
 	 * Not yet supported by fast path.
 	 */
-	CAP_ALL(&rights);
-	if (!cap_rights_contains(&ndp->ni_filecaps.fc_rights, &rights) ||
-	    ndp->ni_filecaps.fc_fcntls != CAP_FCNTL_ALL ||
-	    ndp->ni_filecaps.fc_nioctls != -1) {
+	if (!filecaps_full(&ndp->ni_filecaps)) {
 #ifdef notyet
 		ndp->ni_lcf |= NI_LCF_STRICTREL;
 #else
@@ -3218,10 +3225,7 @@ fgetvp_lookup(struct nameidata *ndp, struct vnode **vpp)
 	 * all lookups relative to it must also be
 	 * strictly relative.
 	 */
-	CAP_ALL(&rights);
-	if (!cap_rights_contains(&ndp->ni_filecaps.fc_rights, &rights) ||
-	    ndp->ni_filecaps.fc_fcntls != CAP_FCNTL_ALL ||
-	    ndp->ni_filecaps.fc_nioctls != -1) {
+	if (!filecaps_full(&ndp->ni_filecaps)) {
 		ndp->ni_lcf |= NI_LCF_STRICTREL;
 		ndp->ni_resflags |= NIRES_STRICTREL;
 	}
diff --git a/sys/sys/filedesc.h b/sys/sys/filedesc.h
index 18077d11150d..c6d9add81a6c 100644
--- a/sys/sys/filedesc.h
+++ b/sys/sys/filedesc.h
@@ -244,6 +244,7 @@ bool	filecaps_copy(const struct filecaps *src, struct filecaps *dst,
 	    bool locked);
 void	filecaps_move(struct filecaps *src, struct filecaps *dst);
 void	filecaps_free(struct filecaps *fcaps);
+bool	filecaps_full(const struct filecaps *fcaps);
 
 int	closef(struct file *fp, struct thread *td);
 void	closef_nothread(struct file *fp);