git: 2127135a22e3 - main - jail_{get,set}: user_ implementations

From: Brooks Davis <brooks_at_FreeBSD.org>
Date: Tue, 29 Sep 2026 18:14:29 UTC
The branch main has been updated by brooks:

URL: https://cgit.FreeBSD.org/src/commit/?id=2127135a22e3f9eafa4ba4ca819d4971b6e27125

commit 2127135a22e3f9eafa4ba4ca819d4971b6e27125
Author:     Brooks Davis <brooks@FreeBSD.org>
AuthorDate: 2026-09-29 17:30:40 +0000
Commit:     Brooks Davis <brooks@FreeBSD.org>
CommitDate: 2026-09-29 18:14:07 +0000

    jail_{get,set}: user_ implementations
    
    This will enable compat implementations in the future.
    
    Reviewed by:    jamie, jhb
    Effort:         CHERI upstreaming
    Sponsored by:   Innovate UK
    Differential Revision:  https://reviews.freebsd.org/D60026
---
 sys/kern/kern_jail.c  | 32 ++++++++++++++++++++++++--------
 sys/sys/syscallsubr.h |  5 +++++
 2 files changed, 29 insertions(+), 8 deletions(-)

diff --git a/sys/kern/kern_jail.c b/sys/kern/kern_jail.c
index 79922c3a0d38..3b9809671f21 100644
--- a/sys/kern/kern_jail.c
+++ b/sys/kern/kern_jail.c
@@ -575,18 +575,26 @@ kern_jail(struct thread *td, struct jail *j)
  */
 int
 sys_jail_set(struct thread *td, struct jail_set_args *uap)
+{
+	return (user_jail_set(td, uap->iovp, uap->iovcnt, uap->flags,
+	    copyinuio));
+}
+
+int
+user_jail_set(struct thread *td, struct iovec *iovp,
+    unsigned int iovcnt, int flags, copyinuio_t *copyinuio_f)
 {
 	struct uio *auio;
 	int error;
 
 	/* Check that we have an even number of iovecs. */
-	if (uap->iovcnt & 1)
+	if (iovcnt & 1)
 		return (EINVAL);
 
-	error = copyinuio(uap->iovp, uap->iovcnt, &auio);
+	error = copyinuio_f(iovp, iovcnt, &auio);
 	if (error)
 		return (error);
-	error = kern_jail_set(td, auio, uap->flags);
+	error = kern_jail_set(td, auio, flags);
 	freeuio(auio);
 	return (error);
 }
@@ -2560,21 +2568,29 @@ get_next_deadid(struct prison **dinsprp)
  */
 int
 sys_jail_get(struct thread *td, struct jail_get_args *uap)
+{
+	return (user_jail_get(td, uap->iovp, uap->iovcnt, uap->flags,
+	    copyinuio, updateiov));
+}
+
+int
+user_jail_get(struct thread *td, struct iovec *iovp,
+    unsigned int iovcnt, int flags, copyinuio_t *copyinuio_f,
+    updateiov_t *updateiov_f)
 {
 	struct uio *auio;
 	int error;
 
 	/* Check that we have an even number of iovecs. */
-	if (uap->iovcnt & 1)
+	if (iovcnt & 1)
 		return (EINVAL);
 
-	error = copyinuio(uap->iovp, uap->iovcnt, &auio);
+	error = copyinuio_f(iovp, iovcnt, &auio);
 	if (error)
 		return (error);
-	error = kern_jail_get(td, auio, uap->flags);
+	error = kern_jail_get(td, auio, flags);
 	if (error == 0)
-		error = copyout(auio->uio_iov, uap->iovp,
-		    uap->iovcnt * sizeof(struct iovec));
+		error = updateiov_f(auio, iovp);
 	freeuio(auio);
 	return (error);
 }
diff --git a/sys/sys/syscallsubr.h b/sys/sys/syscallsubr.h
index d38d10880ec8..d767ba29cdf6 100644
--- a/sys/sys/syscallsubr.h
+++ b/sys/sys/syscallsubr.h
@@ -445,6 +445,11 @@ int	user_cpuset_getaffinity(struct thread *td, cpulevel_t level,
 int	user_cpuset_setaffinity(struct thread *td, cpulevel_t level,
 	    cpuwhich_t which, id_t id, size_t cpusetsize,
 	    const cpuset_t *maskp, const struct cpuset_copy_cb *cb);
+int	user_jail_get(struct thread *td, struct iovec *iovp,
+	    unsigned int iovcnt, int flags, copyinuio_t *copyinuio_f,
+	    updateiov_t *updateiov_f);
+int	user_jail_set(struct thread *td, struct iovec *iovp,
+	    unsigned int iovcnt, int flags, copyinuio_t *copyinuio_f);
 
 /* flags for kern_sigaction */
 #define	KSA_OSIGSET	0x0001	/* uses osigact_t */