/*-1* Copyright (c) 2000-2001 Robert N. M. Watson.2* All rights reserved.3*4* Redistribution and use in source and binary forms, with or without5* modification, are permitted provided that the following conditions6* are met:7* 1. Redistributions of source code must retain the above copyright8* notice, this list of conditions and the following disclaimer.9* 2. Redistributions in binary form must reproduce the above copyright10* notice, this list of conditions and the following disclaimer in the11* documentation and/or other materials provided with the distribution.12*13* THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND14* ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE15* IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE16* ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE17* FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL18* DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS19* OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)20* HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT21* LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY22* OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF23* SUCH DAMAGE.24*25*/2627/*28* Helpers related to visibility and protection of sockets and inpcb.29*/3031#include <sys/systm.h>32#include <sys/jail.h>33#include <sys/kernel.h>34#include <sys/lock.h>35#include <sys/mutex.h>36#include <sys/priv.h>37#include <sys/proc.h>38#include <sys/socket.h>3940#include <netinet/in.h>41#include <netinet/in_pcb.h>42#include <netinet/in_systm.h>4344#include <security/audit/audit.h>45#include <security/mac/mac_framework.h>4647/*-48* Determine whether the subject represented by cred can "see" a socket.49* Returns: 0 for permitted, ENOENT otherwise.50*/51int52cr_canseeinpcb(struct ucred *cred, struct inpcb *inp)53{54int error;5556error = prison_check(cred, inp->inp_cred);57if (error)58return (ENOENT);59#ifdef MAC60INP_LOCK_ASSERT(inp);61error = mac_inpcb_check_visible(cred, inp);62if (error)63return (error);64#endif65if (cr_bsd_visible(cred, inp->inp_cred))66return (ENOENT);6768return (0);69}7071bool72cr_canexport_ktlskeys(struct thread *td, struct inpcb *inp)73{74int error;7576if (cr_canseeinpcb(td->td_ucred, inp) == 0 &&77cr_xids_subset(td->td_ucred, inp->inp_cred))78return (true);79error = priv_check(td, PRIV_NETINET_KTLSKEYS);80return (error == 0);8182}838485