From nobody Sun Sep 06 07:50:26 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hd2S245YLz6qPGQ for ; Sun, 06 Sep 2026 07:50:26 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hd2S22yhDz485H for ; Sun, 06 Sep 2026 07:50:26 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788681026; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=YOHSP0jtaTGAlxA9PzmeJa5lJ2Xw0AWwUpGR6Gas+O0=; b=t57HF96x1c7vIlJ42PX+A0BU6/G/ZcuiuNAyUUL/3g/bMLWnJgEoyWpY7Ybg2UWKcYofh/ 1rIDu+VlPfpYS8vHnVuuOdJ9U/0Mp5IF008E1c9rdyby1DhGGOdRpD7ll4Cq8pOmmPoiqN 3o9WRIzW6T2Ix7zCavld/gfKd/hTb1b3quq+KCwrNiqjU0wl/f6Nlr6rMEitJ7GTW0VVTV Z/3c1ftFIAXxToI39eQwtLMbJgmmYHzGE6i8YsM1h+4dy76aJckWAwXohnXmc16ed2twrK l+EIcrG9Ke76cvUUZL8C4bhvChwRNWK9VzE+ZtufqIDQZ1kCQg94SMj7d0Jfzg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1788681026; a=rsa-sha256; cv=none; b=FLloOdkYdtjOhRym2GFEbN0ac8yrOhIPZwQCjICHhfXv3X+dF9d1Pf3o77bhO0tUTr0GJV iGCIFjgYHexcKNrDNhKRym0sXCVdZmczwRm4wphM2zhLfnrNYQnyaHX7jcnAUACa0szPjL Y5GoC+oZTE03UngN0TKAdiD1jY8BMCadsOyr8klz2dA702sGNTd/nA/EYCzqjLACClJ3pl 6cKWg3b1x3gNo1TnUBdYQlkkgpQ1KU5clQOhtcLBpRzNtXfUpV9RVGMxsn4laIUxTU9zQv zPuo82x4bq1FIvia/bmIeIVi4nmh9/wX65R8UlEsvrbUdQmeuuM2jCZCGhcTDw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788681026; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=YOHSP0jtaTGAlxA9PzmeJa5lJ2Xw0AWwUpGR6Gas+O0=; b=voAdV5VTZteTpN/tOXiVws0FC0Nrscx3l/dSvwsA+Q8bpxGla/DAdmzm5yyMM+L1HeALsg YwE8qRPPw20RJPdBevBbs7VgDa8iHyVdMsumeoKtHpUIBe9muCKpmFPAltc4elTLtgJ8wc tFsKi8JimRlyZUU5RjvMI3FXu+qqrpDvo2z7+epsGXQqiaMoAZiZf+TH49lNCBTx68GarQ E1yFS12iSezfbQvVVMrfHQRkQul8gGwTQNCRdNmFvdOQioA8ldZ9tjhZCJ/UU+QI+UJ5R7 D99WQHVGefW+J30h65U9hlu5dgOKh8EzJCAFENoriA/Rq6BvowSg9vmOHm7UHA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hd2S21gVnz6dQ for ; Sun, 06 Sep 2026 07:50:26 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 39288 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sun, 06 Sep 2026 07:50:26 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Faraz Vahedi Subject: git: f66c8680e804 - main - look(1): Capsicumise List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kfv X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: f66c8680e804c282af66c93b13766801c6f85e7f Auto-Submitted: auto-generated Date: Sun, 06 Sep 2026 07:50:26 +0000 Message-Id: <6a9d1b42.39288.5ff2cba3@gitrepo.freebsd.org> The branch main has been updated by kfv: URL: https://cgit.FreeBSD.org/src/commit/?id=f66c8680e804c282af66c93b13766801c6f85e7f commit f66c8680e804c282af66c93b13766801c6f85e7f Author: Faraz Vahedi AuthorDate: 2024-11-01 11:05:15 +0000 Commit: Faraz Vahedi CommitDate: 2026-09-06 07:47:10 +0000 look(1): Capsicumise Reviewed by: fuz, oshogbo Approved by: fuz (mentor) Pull Request: https://github.com/freebsd/freebsd-src/pull/1489 --- usr.bin/look/look.c | 59 ++++++++++++++++++++++++++++++++++++++++------------- 1 file changed, 45 insertions(+), 14 deletions(-) diff --git a/usr.bin/look/look.c b/usr.bin/look/look.c index 9486fed65b56..5f99ba95c82e 100644 --- a/usr.bin/look/look.c +++ b/usr.bin/look/look.c @@ -41,9 +41,11 @@ */ #include +#include #include #include +#include #include #include #include @@ -85,19 +87,26 @@ static struct option longopts[] = { { NULL, 0, NULL, 0 }, }; +struct files { + int fd; + int err; + const char *path; +}; + int main(int argc, char *argv[]) { struct stat sb; - int ch, fd, match; + int ch, match; + size_t nfiles; wchar_t termchar; + cap_rights_t rights; + struct files *files; unsigned char *back, *front; - unsigned const char *file; wchar_t *key; (void) setlocale(LC_CTYPE, ""); - file = _path_words; termchar = L'\0'; while ((ch = getopt_long(argc, argv, "+adft:", longopts, NULL)) != -1) switch(ch) { @@ -127,27 +136,49 @@ main(int argc, char *argv[]) if (argc == 1) /* But set -df by default. */ dflag = fflag = 1; key = prepkey(*argv++, termchar); - if (argc >= 2) - file = *argv++; + argc--; match = 1; - do { - if ((fd = open(file, O_RDONLY, 0)) < 0 || fstat(fd, &sb)) - err(2, "%s", file); + cap_rights_init(&rights, CAP_MMAP_R, CAP_READ, CAP_FSTAT); + nfiles = !argc ? 1 : argc; + if ((files = malloc(nfiles * sizeof(struct files))) == NULL) + err(2, NULL); + for (size_t idx = 0; idx < nfiles; idx++) { + files[idx].path = !argc ? _path_words : argv[idx]; + if ((files[idx].fd = open(files[idx].path, O_RDONLY, 0)) < 0) { + files[idx].err = errno; + continue; + } + files[idx].err = 0; + if (caph_rights_limit(files[idx].fd, &rights) != 0) + err(2, "unable to limit rights for %s", files[idx].path); + } + + caph_cache_catpages(); + if (caph_enter() != 0) + err(EXIT_FAILURE, "failed to enter capability mode"); + + for (size_t idx = 0; idx < nfiles; idx++) { + if (files[idx].err) + errc(2, files[idx].err, "%s", files[idx].path); + if (fstat(files[idx].fd, &sb)) + err(2, "%s", files[idx].path); if ((uintmax_t)sb.st_size > (uintmax_t)SIZE_T_MAX) - errx(2, "%s: %s", file, strerror(EFBIG)); + errx(2, "%s: %s", files[idx].path, strerror(EFBIG)); if (sb.st_size == 0) { - close(fd); + close(files[idx].fd); continue; } - if ((front = mmap(NULL, (size_t)sb.st_size, PROT_READ, MAP_SHARED, fd, (off_t)0)) == MAP_FAILED) - err(2, "%s", file); + if ((front = mmap(NULL, (size_t)sb.st_size, PROT_READ, + MAP_SHARED, files[idx].fd, (off_t)0)) == MAP_FAILED) + err(2, "%s", files[idx].path); back = front + sb.st_size; match *= (look(key, front, back)); - close(fd); - } while (argc-- > 2 && (file = *argv++)); + close(files[idx].fd); + } + free(files); exit(match); }