1*1031c584SApple OSS Distributions /*
2*1031c584SApple OSS Distributions * Copyright (c) 2000-2019 Apple Inc. All rights reserved.
3*1031c584SApple OSS Distributions *
4*1031c584SApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*1031c584SApple OSS Distributions *
6*1031c584SApple OSS Distributions * This file contains Original Code and/or Modifications of Original Code
7*1031c584SApple OSS Distributions * as defined in and that are subject to the Apple Public Source License
8*1031c584SApple OSS Distributions * Version 2.0 (the 'License'). You may not use this file except in
9*1031c584SApple OSS Distributions * compliance with the License. The rights granted to you under the License
10*1031c584SApple OSS Distributions * may not be used to create, or enable the creation or redistribution of,
11*1031c584SApple OSS Distributions * unlawful or unlicensed copies of an Apple operating system, or to
12*1031c584SApple OSS Distributions * circumvent, violate, or enable the circumvention or violation of, any
13*1031c584SApple OSS Distributions * terms of an Apple operating system software license agreement.
14*1031c584SApple OSS Distributions *
15*1031c584SApple OSS Distributions * Please obtain a copy of the License at
16*1031c584SApple OSS Distributions * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*1031c584SApple OSS Distributions *
18*1031c584SApple OSS Distributions * The Original Code and all software distributed under the License are
19*1031c584SApple OSS Distributions * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*1031c584SApple OSS Distributions * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*1031c584SApple OSS Distributions * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*1031c584SApple OSS Distributions * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*1031c584SApple OSS Distributions * Please see the License for the specific language governing rights and
24*1031c584SApple OSS Distributions * limitations under the License.
25*1031c584SApple OSS Distributions *
26*1031c584SApple OSS Distributions * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*1031c584SApple OSS Distributions */
28*1031c584SApple OSS Distributions /*
29*1031c584SApple OSS Distributions * Implementation of SVID messages
30*1031c584SApple OSS Distributions *
31*1031c584SApple OSS Distributions * Author: Daniel Boulet
32*1031c584SApple OSS Distributions *
33*1031c584SApple OSS Distributions * Copyright 1993 Daniel Boulet and RTMX Inc.
34*1031c584SApple OSS Distributions *
35*1031c584SApple OSS Distributions * This system call was implemented by Daniel Boulet under contract from RTMX.
36*1031c584SApple OSS Distributions *
37*1031c584SApple OSS Distributions * Redistribution and use in source forms, with and without modification,
38*1031c584SApple OSS Distributions * are permitted provided that this entire comment appears intact.
39*1031c584SApple OSS Distributions *
40*1031c584SApple OSS Distributions * Redistribution in binary form may occur without any restrictions.
41*1031c584SApple OSS Distributions * Obviously, it would be nice if you gave credit where credit is due
42*1031c584SApple OSS Distributions * but requiring it would be too onerous.
43*1031c584SApple OSS Distributions *
44*1031c584SApple OSS Distributions * This software is provided ``AS IS'' without any warranties of any kind.
45*1031c584SApple OSS Distributions */
46*1031c584SApple OSS Distributions /*
47*1031c584SApple OSS Distributions * NOTICE: This file was modified by SPARTA, Inc. in 2005 to introduce
48*1031c584SApple OSS Distributions * support for mandatory and extensible security protections. This notice
49*1031c584SApple OSS Distributions * is included in support of clause 2.2 (b) of the Apple Public License,
50*1031c584SApple OSS Distributions * Version 2.0.
51*1031c584SApple OSS Distributions */
52*1031c584SApple OSS Distributions
53*1031c584SApple OSS Distributions #include <sys/param.h>
54*1031c584SApple OSS Distributions #include <sys/systm.h>
55*1031c584SApple OSS Distributions #include <sys/kernel.h>
56*1031c584SApple OSS Distributions #include <sys/proc_internal.h>
57*1031c584SApple OSS Distributions #include <sys/kauth.h>
58*1031c584SApple OSS Distributions #include <sys/msg.h>
59*1031c584SApple OSS Distributions #include <sys/malloc.h>
60*1031c584SApple OSS Distributions #include <mach/mach_types.h>
61*1031c584SApple OSS Distributions
62*1031c584SApple OSS Distributions #include <security/audit/audit.h>
63*1031c584SApple OSS Distributions
64*1031c584SApple OSS Distributions #include <sys/filedesc.h>
65*1031c584SApple OSS Distributions #include <sys/file_internal.h>
66*1031c584SApple OSS Distributions #include <sys/sysctl.h>
67*1031c584SApple OSS Distributions #include <sys/sysproto.h>
68*1031c584SApple OSS Distributions #include <sys/ipcs.h>
69*1031c584SApple OSS Distributions
70*1031c584SApple OSS Distributions #if CONFIG_MACF
71*1031c584SApple OSS Distributions #include <security/mac_framework.h>
72*1031c584SApple OSS Distributions #endif
73*1031c584SApple OSS Distributions
74*1031c584SApple OSS Distributions #if SYSV_MSG
75*1031c584SApple OSS Distributions
76*1031c584SApple OSS Distributions static int msginit(void *);
77*1031c584SApple OSS Distributions
78*1031c584SApple OSS Distributions #define MSG_DEBUG
79*1031c584SApple OSS Distributions #undef MSG_DEBUG_OK
80*1031c584SApple OSS Distributions
81*1031c584SApple OSS Distributions /* Uncomment this line to see MAC debugging output. */
82*1031c584SApple OSS Distributions /* #define MAC_DEBUG */
83*1031c584SApple OSS Distributions #if CONFIG_MACF_DEBUG
84*1031c584SApple OSS Distributions #define MPRINTF(a) printf(a)
85*1031c584SApple OSS Distributions #else
86*1031c584SApple OSS Distributions #define MPRINTF(a)
87*1031c584SApple OSS Distributions #endif
88*1031c584SApple OSS Distributions static void msg_freehdr(struct msg *msghdr);
89*1031c584SApple OSS Distributions
90*1031c584SApple OSS Distributions typedef int sy_call_t(struct proc *, void *, int *);
91*1031c584SApple OSS Distributions
92*1031c584SApple OSS Distributions /* XXX casting to (sy_call_t *) is bogus, as usual. */
93*1031c584SApple OSS Distributions static sy_call_t* const msgcalls[] = {
94*1031c584SApple OSS Distributions (sy_call_t *)msgctl, (sy_call_t *)msgget,
95*1031c584SApple OSS Distributions (sy_call_t *)msgsnd, (sy_call_t *)msgrcv
96*1031c584SApple OSS Distributions };
97*1031c584SApple OSS Distributions
98*1031c584SApple OSS Distributions static int nfree_msgmaps; /* # of free map entries */
99*1031c584SApple OSS Distributions static short free_msgmaps; /* free map entries list head */
100*1031c584SApple OSS Distributions static struct msg *free_msghdrs; /* list of free msg headers */
101*1031c584SApple OSS Distributions char *msgpool; /* MSGMAX byte long msg buffer pool */
102*1031c584SApple OSS Distributions struct msgmap *msgmaps; /* MSGSEG msgmap structures */
103*1031c584SApple OSS Distributions struct msg *msghdrs; /* MSGTQL msg headers */
104*1031c584SApple OSS Distributions struct msqid_kernel *msqids; /* MSGMNI msqid_kernel structs (wrapping user_msqid_ds structs) */
105*1031c584SApple OSS Distributions
106*1031c584SApple OSS Distributions static LCK_GRP_DECLARE(sysv_msg_subsys_lck_grp, "sysv_msg_subsys_lock");
107*1031c584SApple OSS Distributions static LCK_MTX_DECLARE(sysv_msg_subsys_mutex, &sysv_msg_subsys_lck_grp);
108*1031c584SApple OSS Distributions
109*1031c584SApple OSS Distributions #define SYSV_MSG_SUBSYS_LOCK() lck_mtx_lock(&sysv_msg_subsys_mutex)
110*1031c584SApple OSS Distributions #define SYSV_MSG_SUBSYS_UNLOCK() lck_mtx_unlock(&sysv_msg_subsys_mutex)
111*1031c584SApple OSS Distributions
112*1031c584SApple OSS Distributions #ifdef __APPLE_API_PRIVATE
113*1031c584SApple OSS Distributions int msgmax, /* max chars in a message */
114*1031c584SApple OSS Distributions msgmni, /* max message queue identifiers */
115*1031c584SApple OSS Distributions msgmnb, /* max chars in a queue */
116*1031c584SApple OSS Distributions msgtql, /* max messages in system */
117*1031c584SApple OSS Distributions msgssz, /* size of a message segment (see notes above) */
118*1031c584SApple OSS Distributions msgseg; /* number of message segments */
119*1031c584SApple OSS Distributions struct msginfo msginfo = {
120*1031c584SApple OSS Distributions .msgmax = MSGMAX, /* = (MSGSSZ*MSGSEG) : max chars in a message */
121*1031c584SApple OSS Distributions .msgmni = MSGMNI, /* = 40 : max message queue identifiers */
122*1031c584SApple OSS Distributions .msgmnb = MSGMNB, /* = 2048 : max chars in a queue */
123*1031c584SApple OSS Distributions .msgtql = MSGTQL, /* = 40 : max messages in system */
124*1031c584SApple OSS Distributions .msgssz = MSGSSZ, /* = 8 : size of a message segment (2^N long) */
125*1031c584SApple OSS Distributions .msgseg = MSGSEG /* = 2048 : number of message segments */
126*1031c584SApple OSS Distributions };
127*1031c584SApple OSS Distributions #endif /* __APPLE_API_PRIVATE */
128*1031c584SApple OSS Distributions
129*1031c584SApple OSS Distributions static __inline__ user_time_t
sysv_msgtime(void)130*1031c584SApple OSS Distributions sysv_msgtime(void)
131*1031c584SApple OSS Distributions {
132*1031c584SApple OSS Distributions struct timeval tv;
133*1031c584SApple OSS Distributions microtime(&tv);
134*1031c584SApple OSS Distributions return tv.tv_sec;
135*1031c584SApple OSS Distributions }
136*1031c584SApple OSS Distributions
137*1031c584SApple OSS Distributions /*
138*1031c584SApple OSS Distributions * NOTE: Source and target may *NOT* overlap! (target is smaller)
139*1031c584SApple OSS Distributions */
140*1031c584SApple OSS Distributions static void
msqid_ds_kerneltouser32(struct user_msqid_ds * in,struct user32_msqid_ds * out)141*1031c584SApple OSS Distributions msqid_ds_kerneltouser32(struct user_msqid_ds *in, struct user32_msqid_ds *out)
142*1031c584SApple OSS Distributions {
143*1031c584SApple OSS Distributions out->msg_perm = in->msg_perm;
144*1031c584SApple OSS Distributions out->msg_qnum = in->msg_qnum;
145*1031c584SApple OSS Distributions out->msg_cbytes = in->msg_cbytes; /* for ipcs */
146*1031c584SApple OSS Distributions out->msg_qbytes = in->msg_qbytes;
147*1031c584SApple OSS Distributions out->msg_lspid = in->msg_lspid;
148*1031c584SApple OSS Distributions out->msg_lrpid = in->msg_lrpid;
149*1031c584SApple OSS Distributions out->msg_stime = in->msg_stime; /* XXX loss of range */
150*1031c584SApple OSS Distributions out->msg_rtime = in->msg_rtime; /* XXX loss of range */
151*1031c584SApple OSS Distributions out->msg_ctime = in->msg_ctime; /* XXX loss of range */
152*1031c584SApple OSS Distributions }
153*1031c584SApple OSS Distributions
154*1031c584SApple OSS Distributions static void
msqid_ds_kerneltouser64(struct user_msqid_ds * in,struct user64_msqid_ds * out)155*1031c584SApple OSS Distributions msqid_ds_kerneltouser64(struct user_msqid_ds *in, struct user64_msqid_ds *out)
156*1031c584SApple OSS Distributions {
157*1031c584SApple OSS Distributions out->msg_perm = in->msg_perm;
158*1031c584SApple OSS Distributions out->msg_qnum = in->msg_qnum;
159*1031c584SApple OSS Distributions out->msg_cbytes = in->msg_cbytes; /* for ipcs */
160*1031c584SApple OSS Distributions out->msg_qbytes = in->msg_qbytes;
161*1031c584SApple OSS Distributions out->msg_lspid = in->msg_lspid;
162*1031c584SApple OSS Distributions out->msg_lrpid = in->msg_lrpid;
163*1031c584SApple OSS Distributions out->msg_stime = in->msg_stime; /* XXX loss of range */
164*1031c584SApple OSS Distributions out->msg_rtime = in->msg_rtime; /* XXX loss of range */
165*1031c584SApple OSS Distributions out->msg_ctime = in->msg_ctime; /* XXX loss of range */
166*1031c584SApple OSS Distributions }
167*1031c584SApple OSS Distributions
168*1031c584SApple OSS Distributions /*
169*1031c584SApple OSS Distributions * NOTE: Source and target may are permitted to overlap! (source is smaller);
170*1031c584SApple OSS Distributions * this works because we copy fields in order from the end of the struct to
171*1031c584SApple OSS Distributions * the beginning.
172*1031c584SApple OSS Distributions */
173*1031c584SApple OSS Distributions static void
msqid_ds_user32tokernel(struct user32_msqid_ds * in,struct user_msqid_ds * out)174*1031c584SApple OSS Distributions msqid_ds_user32tokernel(struct user32_msqid_ds *in, struct user_msqid_ds *out)
175*1031c584SApple OSS Distributions {
176*1031c584SApple OSS Distributions out->msg_ctime = in->msg_ctime;
177*1031c584SApple OSS Distributions out->msg_rtime = in->msg_rtime;
178*1031c584SApple OSS Distributions out->msg_stime = in->msg_stime;
179*1031c584SApple OSS Distributions out->msg_lrpid = in->msg_lrpid;
180*1031c584SApple OSS Distributions out->msg_lspid = in->msg_lspid;
181*1031c584SApple OSS Distributions out->msg_qbytes = in->msg_qbytes;
182*1031c584SApple OSS Distributions out->msg_cbytes = in->msg_cbytes; /* for ipcs */
183*1031c584SApple OSS Distributions out->msg_qnum = in->msg_qnum;
184*1031c584SApple OSS Distributions out->msg_perm = in->msg_perm;
185*1031c584SApple OSS Distributions }
186*1031c584SApple OSS Distributions
187*1031c584SApple OSS Distributions static void
msqid_ds_user64tokernel(struct user64_msqid_ds * in,struct user_msqid_ds * out)188*1031c584SApple OSS Distributions msqid_ds_user64tokernel(struct user64_msqid_ds *in, struct user_msqid_ds *out)
189*1031c584SApple OSS Distributions {
190*1031c584SApple OSS Distributions out->msg_ctime = in->msg_ctime;
191*1031c584SApple OSS Distributions out->msg_rtime = in->msg_rtime;
192*1031c584SApple OSS Distributions out->msg_stime = in->msg_stime;
193*1031c584SApple OSS Distributions out->msg_lrpid = in->msg_lrpid;
194*1031c584SApple OSS Distributions out->msg_lspid = in->msg_lspid;
195*1031c584SApple OSS Distributions out->msg_qbytes = in->msg_qbytes;
196*1031c584SApple OSS Distributions out->msg_cbytes = in->msg_cbytes; /* for ipcs */
197*1031c584SApple OSS Distributions out->msg_qnum = in->msg_qnum;
198*1031c584SApple OSS Distributions out->msg_perm = in->msg_perm;
199*1031c584SApple OSS Distributions }
200*1031c584SApple OSS Distributions
201*1031c584SApple OSS Distributions /* This routine assumes the system is locked prior to calling this routine */
202*1031c584SApple OSS Distributions static int
msginit(__unused void * dummy)203*1031c584SApple OSS Distributions msginit(__unused void *dummy)
204*1031c584SApple OSS Distributions {
205*1031c584SApple OSS Distributions static int initted = 0;
206*1031c584SApple OSS Distributions int i;
207*1031c584SApple OSS Distributions
208*1031c584SApple OSS Distributions /* Lazy initialization on first system call; we don't have SYSINIT(). */
209*1031c584SApple OSS Distributions if (initted) {
210*1031c584SApple OSS Distributions return initted;
211*1031c584SApple OSS Distributions }
212*1031c584SApple OSS Distributions
213*1031c584SApple OSS Distributions /*
214*1031c584SApple OSS Distributions * msginfo.msgssz should be a power of two for efficiency reasons.
215*1031c584SApple OSS Distributions * It is also pretty silly if msginfo.msgssz is less than 8
216*1031c584SApple OSS Distributions * or greater than about 256 so ...
217*1031c584SApple OSS Distributions */
218*1031c584SApple OSS Distributions i = 8;
219*1031c584SApple OSS Distributions while (i < 1024 && i != msginfo.msgssz) {
220*1031c584SApple OSS Distributions i <<= 1;
221*1031c584SApple OSS Distributions }
222*1031c584SApple OSS Distributions if (i != msginfo.msgssz) {
223*1031c584SApple OSS Distributions printf("msginfo.msgssz=%d (0x%x) not a small power of 2; resetting to %d\n", msginfo.msgssz, msginfo.msgssz, MSGSSZ);
224*1031c584SApple OSS Distributions msginfo.msgssz = MSGSSZ;
225*1031c584SApple OSS Distributions }
226*1031c584SApple OSS Distributions
227*1031c584SApple OSS Distributions if (msginfo.msgseg > 32767) {
228*1031c584SApple OSS Distributions printf("msginfo.msgseg=%d (> 32767); resetting to %d\n", msginfo.msgseg, MSGSEG);
229*1031c584SApple OSS Distributions msginfo.msgseg = MSGSEG;
230*1031c584SApple OSS Distributions }
231*1031c584SApple OSS Distributions
232*1031c584SApple OSS Distributions
233*1031c584SApple OSS Distributions /*
234*1031c584SApple OSS Distributions * Allocate memory for message pool, maps, headers, and queue IDs;
235*1031c584SApple OSS Distributions * if this fails, fail safely and leave it uninitialized (related
236*1031c584SApple OSS Distributions * system calls will fail).
237*1031c584SApple OSS Distributions */
238*1031c584SApple OSS Distributions msgpool = kalloc_data(msginfo.msgmax, Z_WAITOK);
239*1031c584SApple OSS Distributions if (msgpool == NULL) {
240*1031c584SApple OSS Distributions printf("msginit: can't allocate msgpool");
241*1031c584SApple OSS Distributions goto bad;
242*1031c584SApple OSS Distributions }
243*1031c584SApple OSS Distributions msgmaps = kalloc_data(sizeof(struct msgmap) * msginfo.msgseg, Z_WAITOK);
244*1031c584SApple OSS Distributions if (msgmaps == NULL) {
245*1031c584SApple OSS Distributions printf("msginit: can't allocate msgmaps");
246*1031c584SApple OSS Distributions goto bad;
247*1031c584SApple OSS Distributions }
248*1031c584SApple OSS Distributions
249*1031c584SApple OSS Distributions msghdrs = kalloc_type(struct msg, msginfo.msgtql, Z_WAITOK);
250*1031c584SApple OSS Distributions if (msghdrs == NULL) {
251*1031c584SApple OSS Distributions printf("msginit: can't allocate msghdrs");
252*1031c584SApple OSS Distributions goto bad;
253*1031c584SApple OSS Distributions }
254*1031c584SApple OSS Distributions
255*1031c584SApple OSS Distributions msqids = kalloc_type(struct msqid_kernel, msginfo.msgmni, Z_WAITOK);
256*1031c584SApple OSS Distributions if (msqids == NULL) {
257*1031c584SApple OSS Distributions printf("msginit: can't allocate msqids");
258*1031c584SApple OSS Distributions goto bad;
259*1031c584SApple OSS Distributions }
260*1031c584SApple OSS Distributions
261*1031c584SApple OSS Distributions
262*1031c584SApple OSS Distributions /* init msgmaps */
263*1031c584SApple OSS Distributions for (i = 0; i < msginfo.msgseg; i++) {
264*1031c584SApple OSS Distributions if (i > 0) {
265*1031c584SApple OSS Distributions msgmaps[i - 1].next = i;
266*1031c584SApple OSS Distributions }
267*1031c584SApple OSS Distributions msgmaps[i].next = -1; /* implies entry is available */
268*1031c584SApple OSS Distributions }
269*1031c584SApple OSS Distributions free_msgmaps = 0;
270*1031c584SApple OSS Distributions nfree_msgmaps = msginfo.msgseg;
271*1031c584SApple OSS Distributions
272*1031c584SApple OSS Distributions
273*1031c584SApple OSS Distributions /* init msghdrs */
274*1031c584SApple OSS Distributions for (i = 0; i < msginfo.msgtql; i++) {
275*1031c584SApple OSS Distributions msghdrs[i].msg_type = 0;
276*1031c584SApple OSS Distributions if (i > 0) {
277*1031c584SApple OSS Distributions msghdrs[i - 1].msg_next = &msghdrs[i];
278*1031c584SApple OSS Distributions }
279*1031c584SApple OSS Distributions msghdrs[i].msg_next = NULL;
280*1031c584SApple OSS Distributions #if CONFIG_MACF
281*1031c584SApple OSS Distributions mac_sysvmsg_label_init(&msghdrs[i]);
282*1031c584SApple OSS Distributions #endif
283*1031c584SApple OSS Distributions }
284*1031c584SApple OSS Distributions free_msghdrs = &msghdrs[0];
285*1031c584SApple OSS Distributions
286*1031c584SApple OSS Distributions /* init msqids */
287*1031c584SApple OSS Distributions for (i = 0; i < msginfo.msgmni; i++) {
288*1031c584SApple OSS Distributions msqids[i].u.msg_qbytes = 0; /* implies entry is available */
289*1031c584SApple OSS Distributions msqids[i].u.msg_perm._seq = 0; /* reset to a known value */
290*1031c584SApple OSS Distributions msqids[i].u.msg_perm.mode = 0;
291*1031c584SApple OSS Distributions #if CONFIG_MACF
292*1031c584SApple OSS Distributions mac_sysvmsq_label_init(&msqids[i]);
293*1031c584SApple OSS Distributions #endif
294*1031c584SApple OSS Distributions }
295*1031c584SApple OSS Distributions
296*1031c584SApple OSS Distributions initted = 1;
297*1031c584SApple OSS Distributions bad:
298*1031c584SApple OSS Distributions if (!initted) {
299*1031c584SApple OSS Distributions kfree_data(msgpool, sizeof(struct msgmap) * msginfo.msgseg);
300*1031c584SApple OSS Distributions kfree_data(msgmaps, sizeof(struct msgmap) * msginfo.msgseg);
301*1031c584SApple OSS Distributions kfree_type(struct msg, msginfo.msgtql, msghdrs);
302*1031c584SApple OSS Distributions kfree_type(struct msqid_kernel, msginfo.msgmni, msqids);
303*1031c584SApple OSS Distributions }
304*1031c584SApple OSS Distributions return initted;
305*1031c584SApple OSS Distributions }
306*1031c584SApple OSS Distributions
307*1031c584SApple OSS Distributions /*
308*1031c584SApple OSS Distributions * msgsys
309*1031c584SApple OSS Distributions *
310*1031c584SApple OSS Distributions * Entry point for all MSG calls: msgctl, msgget, msgsnd, msgrcv
311*1031c584SApple OSS Distributions *
312*1031c584SApple OSS Distributions * Parameters: p Process requesting the call
313*1031c584SApple OSS Distributions * uap User argument descriptor (see below)
314*1031c584SApple OSS Distributions * retval Return value of the selected msg call
315*1031c584SApple OSS Distributions *
316*1031c584SApple OSS Distributions * Indirect parameters: uap->which msg call to invoke (index in array of msg calls)
317*1031c584SApple OSS Distributions * uap->a2 User argument descriptor
318*1031c584SApple OSS Distributions *
319*1031c584SApple OSS Distributions * Returns: 0 Success
320*1031c584SApple OSS Distributions * !0 Not success
321*1031c584SApple OSS Distributions *
322*1031c584SApple OSS Distributions * Implicit returns: retval Return value of the selected msg call
323*1031c584SApple OSS Distributions *
324*1031c584SApple OSS Distributions * DEPRECATED: This interface should not be used to call the other MSG
325*1031c584SApple OSS Distributions * functions (msgctl, msgget, msgsnd, msgrcv). The correct
326*1031c584SApple OSS Distributions * usage is to call the other MSG functions directly.
327*1031c584SApple OSS Distributions *
328*1031c584SApple OSS Distributions */
329*1031c584SApple OSS Distributions int
msgsys(struct proc * p,struct msgsys_args * uap,int32_t * retval)330*1031c584SApple OSS Distributions msgsys(struct proc *p, struct msgsys_args *uap, int32_t *retval)
331*1031c584SApple OSS Distributions {
332*1031c584SApple OSS Distributions if (uap->which >= sizeof(msgcalls) / sizeof(msgcalls[0])) {
333*1031c584SApple OSS Distributions return EINVAL;
334*1031c584SApple OSS Distributions }
335*1031c584SApple OSS Distributions return (*msgcalls[uap->which])(p, &uap->a2, retval);
336*1031c584SApple OSS Distributions }
337*1031c584SApple OSS Distributions
338*1031c584SApple OSS Distributions static void
msg_freehdr(struct msg * msghdr)339*1031c584SApple OSS Distributions msg_freehdr(struct msg *msghdr)
340*1031c584SApple OSS Distributions {
341*1031c584SApple OSS Distributions while (msghdr->msg_ts > 0) {
342*1031c584SApple OSS Distributions short next;
343*1031c584SApple OSS Distributions if (msghdr->msg_spot < 0 || msghdr->msg_spot >= msginfo.msgseg) {
344*1031c584SApple OSS Distributions panic("msghdr->msg_spot out of range");
345*1031c584SApple OSS Distributions }
346*1031c584SApple OSS Distributions next = msgmaps[msghdr->msg_spot].next;
347*1031c584SApple OSS Distributions msgmaps[msghdr->msg_spot].next = free_msgmaps;
348*1031c584SApple OSS Distributions free_msgmaps = msghdr->msg_spot;
349*1031c584SApple OSS Distributions nfree_msgmaps++;
350*1031c584SApple OSS Distributions msghdr->msg_spot = next;
351*1031c584SApple OSS Distributions if (msghdr->msg_ts >= msginfo.msgssz) {
352*1031c584SApple OSS Distributions msghdr->msg_ts -= msginfo.msgssz;
353*1031c584SApple OSS Distributions } else {
354*1031c584SApple OSS Distributions msghdr->msg_ts = 0;
355*1031c584SApple OSS Distributions }
356*1031c584SApple OSS Distributions }
357*1031c584SApple OSS Distributions if (msghdr->msg_spot != -1) {
358*1031c584SApple OSS Distributions panic("msghdr->msg_spot != -1");
359*1031c584SApple OSS Distributions }
360*1031c584SApple OSS Distributions msghdr->msg_next = free_msghdrs;
361*1031c584SApple OSS Distributions free_msghdrs = msghdr;
362*1031c584SApple OSS Distributions #if CONFIG_MACF
363*1031c584SApple OSS Distributions mac_sysvmsg_label_recycle(msghdr);
364*1031c584SApple OSS Distributions #endif
365*1031c584SApple OSS Distributions /*
366*1031c584SApple OSS Distributions * Notify waiters that there are free message headers and segments
367*1031c584SApple OSS Distributions * now available.
368*1031c584SApple OSS Distributions */
369*1031c584SApple OSS Distributions wakeup((caddr_t)&free_msghdrs);
370*1031c584SApple OSS Distributions }
371*1031c584SApple OSS Distributions
372*1031c584SApple OSS Distributions int
msgctl(struct proc * p,struct msgctl_args * uap,int32_t * retval)373*1031c584SApple OSS Distributions msgctl(struct proc *p, struct msgctl_args *uap, int32_t *retval)
374*1031c584SApple OSS Distributions {
375*1031c584SApple OSS Distributions int msqid = uap->msqid;
376*1031c584SApple OSS Distributions int cmd = uap->cmd;
377*1031c584SApple OSS Distributions kauth_cred_t cred = kauth_cred_get();
378*1031c584SApple OSS Distributions int rval, eval;
379*1031c584SApple OSS Distributions struct user_msqid_ds msqbuf;
380*1031c584SApple OSS Distributions struct msqid_kernel *msqptr;
381*1031c584SApple OSS Distributions
382*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
383*1031c584SApple OSS Distributions
384*1031c584SApple OSS Distributions if (!msginit(0)) {
385*1031c584SApple OSS Distributions eval = ENOMEM;
386*1031c584SApple OSS Distributions goto msgctlout;
387*1031c584SApple OSS Distributions }
388*1031c584SApple OSS Distributions
389*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
390*1031c584SApple OSS Distributions printf("call to msgctl(%d, %d, 0x%qx)\n", msqid, cmd, uap->buf);
391*1031c584SApple OSS Distributions #endif
392*1031c584SApple OSS Distributions
393*1031c584SApple OSS Distributions AUDIT_ARG(svipc_cmd, cmd);
394*1031c584SApple OSS Distributions AUDIT_ARG(svipc_id, msqid);
395*1031c584SApple OSS Distributions msqid = IPCID_TO_IX(msqid);
396*1031c584SApple OSS Distributions
397*1031c584SApple OSS Distributions if (msqid < 0 || msqid >= msginfo.msgmni) {
398*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
399*1031c584SApple OSS Distributions printf("msqid (%d) out of range (0<=msqid<%d)\n", msqid,
400*1031c584SApple OSS Distributions msginfo.msgmni);
401*1031c584SApple OSS Distributions #endif
402*1031c584SApple OSS Distributions eval = EINVAL;
403*1031c584SApple OSS Distributions goto msgctlout;
404*1031c584SApple OSS Distributions }
405*1031c584SApple OSS Distributions
406*1031c584SApple OSS Distributions msqptr = &msqids[msqid];
407*1031c584SApple OSS Distributions
408*1031c584SApple OSS Distributions if (msqptr->u.msg_qbytes == 0) {
409*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
410*1031c584SApple OSS Distributions printf("no such msqid\n");
411*1031c584SApple OSS Distributions #endif
412*1031c584SApple OSS Distributions eval = EINVAL;
413*1031c584SApple OSS Distributions goto msgctlout;
414*1031c584SApple OSS Distributions }
415*1031c584SApple OSS Distributions if (msqptr->u.msg_perm._seq != IPCID_TO_SEQ(uap->msqid)) {
416*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
417*1031c584SApple OSS Distributions printf("wrong sequence number\n");
418*1031c584SApple OSS Distributions #endif
419*1031c584SApple OSS Distributions eval = EINVAL;
420*1031c584SApple OSS Distributions goto msgctlout;
421*1031c584SApple OSS Distributions }
422*1031c584SApple OSS Distributions #if CONFIG_MACF
423*1031c584SApple OSS Distributions eval = mac_sysvmsq_check_msqctl(kauth_cred_get(), msqptr, cmd);
424*1031c584SApple OSS Distributions if (eval) {
425*1031c584SApple OSS Distributions goto msgctlout;
426*1031c584SApple OSS Distributions }
427*1031c584SApple OSS Distributions #endif
428*1031c584SApple OSS Distributions
429*1031c584SApple OSS Distributions eval = 0;
430*1031c584SApple OSS Distributions rval = 0;
431*1031c584SApple OSS Distributions
432*1031c584SApple OSS Distributions switch (cmd) {
433*1031c584SApple OSS Distributions case IPC_RMID:
434*1031c584SApple OSS Distributions {
435*1031c584SApple OSS Distributions struct msg *msghdr;
436*1031c584SApple OSS Distributions if ((eval = ipcperm(cred, &msqptr->u.msg_perm, IPC_M))) {
437*1031c584SApple OSS Distributions goto msgctlout;
438*1031c584SApple OSS Distributions }
439*1031c584SApple OSS Distributions #if CONFIG_MACF
440*1031c584SApple OSS Distributions /*
441*1031c584SApple OSS Distributions * Check that the thread has MAC access permissions to
442*1031c584SApple OSS Distributions * individual msghdrs. Note: We need to do this in a
443*1031c584SApple OSS Distributions * separate loop because the actual loop alters the
444*1031c584SApple OSS Distributions * msq/msghdr info as it progresses, and there is no going
445*1031c584SApple OSS Distributions * back if half the way through we discover that the
446*1031c584SApple OSS Distributions * thread cannot free a certain msghdr. The msq will get
447*1031c584SApple OSS Distributions * into an inconsistent state.
448*1031c584SApple OSS Distributions */
449*1031c584SApple OSS Distributions for (msghdr = msqptr->u.msg_first; msghdr != NULL;
450*1031c584SApple OSS Distributions msghdr = msghdr->msg_next) {
451*1031c584SApple OSS Distributions eval = mac_sysvmsq_check_msgrmid(kauth_cred_get(), msghdr);
452*1031c584SApple OSS Distributions if (eval) {
453*1031c584SApple OSS Distributions goto msgctlout;
454*1031c584SApple OSS Distributions }
455*1031c584SApple OSS Distributions }
456*1031c584SApple OSS Distributions #endif
457*1031c584SApple OSS Distributions /* Free the message headers */
458*1031c584SApple OSS Distributions msghdr = msqptr->u.msg_first;
459*1031c584SApple OSS Distributions while (msghdr != NULL) {
460*1031c584SApple OSS Distributions struct msg *msghdr_tmp;
461*1031c584SApple OSS Distributions
462*1031c584SApple OSS Distributions /* Free the segments of each message */
463*1031c584SApple OSS Distributions msqptr->u.msg_cbytes -= msghdr->msg_ts;
464*1031c584SApple OSS Distributions msqptr->u.msg_qnum--;
465*1031c584SApple OSS Distributions msghdr_tmp = msghdr;
466*1031c584SApple OSS Distributions msghdr = msghdr->msg_next;
467*1031c584SApple OSS Distributions msg_freehdr(msghdr_tmp);
468*1031c584SApple OSS Distributions }
469*1031c584SApple OSS Distributions
470*1031c584SApple OSS Distributions if (msqptr->u.msg_cbytes != 0) {
471*1031c584SApple OSS Distributions panic("msg_cbytes is messed up");
472*1031c584SApple OSS Distributions }
473*1031c584SApple OSS Distributions if (msqptr->u.msg_qnum != 0) {
474*1031c584SApple OSS Distributions panic("msg_qnum is messed up");
475*1031c584SApple OSS Distributions }
476*1031c584SApple OSS Distributions
477*1031c584SApple OSS Distributions msqptr->u.msg_qbytes = 0; /* Mark it as free */
478*1031c584SApple OSS Distributions #if CONFIG_MACF
479*1031c584SApple OSS Distributions mac_sysvmsq_label_recycle(msqptr);
480*1031c584SApple OSS Distributions #endif
481*1031c584SApple OSS Distributions
482*1031c584SApple OSS Distributions wakeup((caddr_t)msqptr);
483*1031c584SApple OSS Distributions }
484*1031c584SApple OSS Distributions
485*1031c584SApple OSS Distributions break;
486*1031c584SApple OSS Distributions
487*1031c584SApple OSS Distributions case IPC_SET:
488*1031c584SApple OSS Distributions if ((eval = ipcperm(cred, &msqptr->u.msg_perm, IPC_M))) {
489*1031c584SApple OSS Distributions goto msgctlout;
490*1031c584SApple OSS Distributions }
491*1031c584SApple OSS Distributions
492*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
493*1031c584SApple OSS Distributions
494*1031c584SApple OSS Distributions if (IS_64BIT_PROCESS(p)) {
495*1031c584SApple OSS Distributions struct user64_msqid_ds tmpds;
496*1031c584SApple OSS Distributions eval = copyin(uap->buf, &tmpds, sizeof(tmpds));
497*1031c584SApple OSS Distributions
498*1031c584SApple OSS Distributions msqid_ds_user64tokernel(&tmpds, &msqbuf);
499*1031c584SApple OSS Distributions } else {
500*1031c584SApple OSS Distributions struct user32_msqid_ds tmpds;
501*1031c584SApple OSS Distributions
502*1031c584SApple OSS Distributions eval = copyin(uap->buf, &tmpds, sizeof(tmpds));
503*1031c584SApple OSS Distributions
504*1031c584SApple OSS Distributions msqid_ds_user32tokernel(&tmpds, &msqbuf);
505*1031c584SApple OSS Distributions }
506*1031c584SApple OSS Distributions if (eval) {
507*1031c584SApple OSS Distributions return eval;
508*1031c584SApple OSS Distributions }
509*1031c584SApple OSS Distributions
510*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
511*1031c584SApple OSS Distributions
512*1031c584SApple OSS Distributions if (msqbuf.msg_qbytes > msqptr->u.msg_qbytes) {
513*1031c584SApple OSS Distributions eval = suser(cred, &p->p_acflag);
514*1031c584SApple OSS Distributions if (eval) {
515*1031c584SApple OSS Distributions goto msgctlout;
516*1031c584SApple OSS Distributions }
517*1031c584SApple OSS Distributions }
518*1031c584SApple OSS Distributions
519*1031c584SApple OSS Distributions
520*1031c584SApple OSS Distributions /* compare (msglen_t) value against restrict (int) value */
521*1031c584SApple OSS Distributions if (msqbuf.msg_qbytes > (user_msglen_t)msginfo.msgmnb) {
522*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
523*1031c584SApple OSS Distributions printf("can't increase msg_qbytes beyond %d (truncating)\n",
524*1031c584SApple OSS Distributions msginfo.msgmnb);
525*1031c584SApple OSS Distributions #endif
526*1031c584SApple OSS Distributions msqbuf.msg_qbytes = msginfo.msgmnb; /* silently restrict qbytes to system limit */
527*1031c584SApple OSS Distributions }
528*1031c584SApple OSS Distributions if (msqbuf.msg_qbytes == 0) {
529*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
530*1031c584SApple OSS Distributions printf("can't reduce msg_qbytes to 0\n");
531*1031c584SApple OSS Distributions #endif
532*1031c584SApple OSS Distributions eval = EINVAL;
533*1031c584SApple OSS Distributions goto msgctlout;
534*1031c584SApple OSS Distributions }
535*1031c584SApple OSS Distributions msqptr->u.msg_perm.uid = msqbuf.msg_perm.uid; /* change the owner */
536*1031c584SApple OSS Distributions msqptr->u.msg_perm.gid = msqbuf.msg_perm.gid; /* change the owner */
537*1031c584SApple OSS Distributions msqptr->u.msg_perm.mode = (msqptr->u.msg_perm.mode & ~0777) |
538*1031c584SApple OSS Distributions (msqbuf.msg_perm.mode & 0777);
539*1031c584SApple OSS Distributions msqptr->u.msg_qbytes = msqbuf.msg_qbytes;
540*1031c584SApple OSS Distributions msqptr->u.msg_ctime = sysv_msgtime();
541*1031c584SApple OSS Distributions break;
542*1031c584SApple OSS Distributions
543*1031c584SApple OSS Distributions case IPC_STAT:
544*1031c584SApple OSS Distributions if ((eval = ipcperm(cred, &msqptr->u.msg_perm, IPC_R))) {
545*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
546*1031c584SApple OSS Distributions printf("requester doesn't have read access\n");
547*1031c584SApple OSS Distributions #endif
548*1031c584SApple OSS Distributions goto msgctlout;
549*1031c584SApple OSS Distributions }
550*1031c584SApple OSS Distributions
551*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
552*1031c584SApple OSS Distributions if (IS_64BIT_PROCESS(p)) {
553*1031c584SApple OSS Distributions struct user64_msqid_ds msqid_ds64 = {};
554*1031c584SApple OSS Distributions msqid_ds_kerneltouser64(&msqptr->u, &msqid_ds64);
555*1031c584SApple OSS Distributions eval = copyout(&msqid_ds64, uap->buf, sizeof(msqid_ds64));
556*1031c584SApple OSS Distributions } else {
557*1031c584SApple OSS Distributions struct user32_msqid_ds msqid_ds32 = {};
558*1031c584SApple OSS Distributions msqid_ds_kerneltouser32(&msqptr->u, &msqid_ds32);
559*1031c584SApple OSS Distributions eval = copyout(&msqid_ds32, uap->buf, sizeof(msqid_ds32));
560*1031c584SApple OSS Distributions }
561*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
562*1031c584SApple OSS Distributions break;
563*1031c584SApple OSS Distributions
564*1031c584SApple OSS Distributions default:
565*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
566*1031c584SApple OSS Distributions printf("invalid command %d\n", cmd);
567*1031c584SApple OSS Distributions #endif
568*1031c584SApple OSS Distributions eval = EINVAL;
569*1031c584SApple OSS Distributions goto msgctlout;
570*1031c584SApple OSS Distributions }
571*1031c584SApple OSS Distributions
572*1031c584SApple OSS Distributions if (eval == 0) {
573*1031c584SApple OSS Distributions *retval = rval;
574*1031c584SApple OSS Distributions }
575*1031c584SApple OSS Distributions msgctlout:
576*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
577*1031c584SApple OSS Distributions return eval;
578*1031c584SApple OSS Distributions }
579*1031c584SApple OSS Distributions
580*1031c584SApple OSS Distributions int
msgget(__unused struct proc * p,struct msgget_args * uap,int32_t * retval)581*1031c584SApple OSS Distributions msgget(__unused struct proc *p, struct msgget_args *uap, int32_t *retval)
582*1031c584SApple OSS Distributions {
583*1031c584SApple OSS Distributions int msqid, eval;
584*1031c584SApple OSS Distributions int key = uap->key;
585*1031c584SApple OSS Distributions int msgflg = uap->msgflg;
586*1031c584SApple OSS Distributions kauth_cred_t cred = kauth_cred_get();
587*1031c584SApple OSS Distributions struct msqid_kernel *msqptr = NULL;
588*1031c584SApple OSS Distributions
589*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
590*1031c584SApple OSS Distributions
591*1031c584SApple OSS Distributions if (!msginit(0)) {
592*1031c584SApple OSS Distributions eval = ENOMEM;
593*1031c584SApple OSS Distributions goto msggetout;
594*1031c584SApple OSS Distributions }
595*1031c584SApple OSS Distributions
596*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
597*1031c584SApple OSS Distributions printf("msgget(0x%x, 0%o)\n", key, msgflg);
598*1031c584SApple OSS Distributions #endif
599*1031c584SApple OSS Distributions
600*1031c584SApple OSS Distributions if (key != IPC_PRIVATE) {
601*1031c584SApple OSS Distributions for (msqid = 0; msqid < msginfo.msgmni; msqid++) {
602*1031c584SApple OSS Distributions msqptr = &msqids[msqid];
603*1031c584SApple OSS Distributions if (msqptr->u.msg_qbytes != 0 &&
604*1031c584SApple OSS Distributions msqptr->u.msg_perm._key == key) {
605*1031c584SApple OSS Distributions break;
606*1031c584SApple OSS Distributions }
607*1031c584SApple OSS Distributions }
608*1031c584SApple OSS Distributions if (msqid < msginfo.msgmni) {
609*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
610*1031c584SApple OSS Distributions printf("found public key\n");
611*1031c584SApple OSS Distributions #endif
612*1031c584SApple OSS Distributions if ((msgflg & IPC_CREAT) && (msgflg & IPC_EXCL)) {
613*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
614*1031c584SApple OSS Distributions printf("not exclusive\n");
615*1031c584SApple OSS Distributions #endif
616*1031c584SApple OSS Distributions eval = EEXIST;
617*1031c584SApple OSS Distributions goto msggetout;
618*1031c584SApple OSS Distributions }
619*1031c584SApple OSS Distributions if ((eval = ipcperm(cred, &msqptr->u.msg_perm, msgflg & 0700 ))) {
620*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
621*1031c584SApple OSS Distributions printf("requester doesn't have 0%o access\n",
622*1031c584SApple OSS Distributions msgflg & 0700);
623*1031c584SApple OSS Distributions #endif
624*1031c584SApple OSS Distributions goto msggetout;
625*1031c584SApple OSS Distributions }
626*1031c584SApple OSS Distributions #if CONFIG_MACF
627*1031c584SApple OSS Distributions eval = mac_sysvmsq_check_msqget(cred, msqptr);
628*1031c584SApple OSS Distributions if (eval) {
629*1031c584SApple OSS Distributions goto msggetout;
630*1031c584SApple OSS Distributions }
631*1031c584SApple OSS Distributions #endif
632*1031c584SApple OSS Distributions goto found;
633*1031c584SApple OSS Distributions }
634*1031c584SApple OSS Distributions }
635*1031c584SApple OSS Distributions
636*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
637*1031c584SApple OSS Distributions printf("need to allocate the user_msqid_ds\n");
638*1031c584SApple OSS Distributions #endif
639*1031c584SApple OSS Distributions if (key == IPC_PRIVATE || (msgflg & IPC_CREAT)) {
640*1031c584SApple OSS Distributions for (msqid = 0; msqid < msginfo.msgmni; msqid++) {
641*1031c584SApple OSS Distributions /*
642*1031c584SApple OSS Distributions * Look for an unallocated and unlocked user_msqid_ds.
643*1031c584SApple OSS Distributions * user_msqid_ds's can be locked by msgsnd or msgrcv
644*1031c584SApple OSS Distributions * while they are copying the message in/out. We
645*1031c584SApple OSS Distributions * can't re-use the entry until they release it.
646*1031c584SApple OSS Distributions */
647*1031c584SApple OSS Distributions msqptr = &msqids[msqid];
648*1031c584SApple OSS Distributions if (msqptr->u.msg_qbytes == 0 &&
649*1031c584SApple OSS Distributions (msqptr->u.msg_perm.mode & MSG_LOCKED) == 0) {
650*1031c584SApple OSS Distributions break;
651*1031c584SApple OSS Distributions }
652*1031c584SApple OSS Distributions }
653*1031c584SApple OSS Distributions if (msqid == msginfo.msgmni) {
654*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
655*1031c584SApple OSS Distributions printf("no more user_msqid_ds's available\n");
656*1031c584SApple OSS Distributions #endif
657*1031c584SApple OSS Distributions eval = ENOSPC;
658*1031c584SApple OSS Distributions goto msggetout;
659*1031c584SApple OSS Distributions }
660*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
661*1031c584SApple OSS Distributions printf("msqid %d is available\n", msqid);
662*1031c584SApple OSS Distributions #endif
663*1031c584SApple OSS Distributions msqptr->u.msg_perm._key = key;
664*1031c584SApple OSS Distributions msqptr->u.msg_perm.cuid = kauth_cred_getuid(cred);
665*1031c584SApple OSS Distributions msqptr->u.msg_perm.uid = kauth_cred_getuid(cred);
666*1031c584SApple OSS Distributions msqptr->u.msg_perm.cgid = kauth_cred_getgid(cred);
667*1031c584SApple OSS Distributions msqptr->u.msg_perm.gid = kauth_cred_getgid(cred);
668*1031c584SApple OSS Distributions msqptr->u.msg_perm.mode = (msgflg & 0777);
669*1031c584SApple OSS Distributions /* Make sure that the returned msqid is unique */
670*1031c584SApple OSS Distributions msqptr->u.msg_perm._seq++;
671*1031c584SApple OSS Distributions msqptr->u.msg_first = NULL;
672*1031c584SApple OSS Distributions msqptr->u.msg_last = NULL;
673*1031c584SApple OSS Distributions msqptr->u.msg_cbytes = 0;
674*1031c584SApple OSS Distributions msqptr->u.msg_qnum = 0;
675*1031c584SApple OSS Distributions msqptr->u.msg_qbytes = msginfo.msgmnb;
676*1031c584SApple OSS Distributions msqptr->u.msg_lspid = 0;
677*1031c584SApple OSS Distributions msqptr->u.msg_lrpid = 0;
678*1031c584SApple OSS Distributions msqptr->u.msg_stime = 0;
679*1031c584SApple OSS Distributions msqptr->u.msg_rtime = 0;
680*1031c584SApple OSS Distributions msqptr->u.msg_ctime = sysv_msgtime();
681*1031c584SApple OSS Distributions #if CONFIG_MACF
682*1031c584SApple OSS Distributions mac_sysvmsq_label_associate(cred, msqptr);
683*1031c584SApple OSS Distributions #endif
684*1031c584SApple OSS Distributions } else {
685*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
686*1031c584SApple OSS Distributions printf("didn't find it and wasn't asked to create it\n");
687*1031c584SApple OSS Distributions #endif
688*1031c584SApple OSS Distributions eval = ENOENT;
689*1031c584SApple OSS Distributions goto msggetout;
690*1031c584SApple OSS Distributions }
691*1031c584SApple OSS Distributions
692*1031c584SApple OSS Distributions found:
693*1031c584SApple OSS Distributions /* Construct the unique msqid */
694*1031c584SApple OSS Distributions *retval = IXSEQ_TO_IPCID(msqid, msqptr->u.msg_perm);
695*1031c584SApple OSS Distributions AUDIT_ARG(svipc_id, *retval);
696*1031c584SApple OSS Distributions eval = 0;
697*1031c584SApple OSS Distributions msggetout:
698*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
699*1031c584SApple OSS Distributions return eval;
700*1031c584SApple OSS Distributions }
701*1031c584SApple OSS Distributions
702*1031c584SApple OSS Distributions
703*1031c584SApple OSS Distributions int
msgsnd(struct proc * p,struct msgsnd_args * uap,int32_t * retval)704*1031c584SApple OSS Distributions msgsnd(struct proc *p, struct msgsnd_args *uap, int32_t *retval)
705*1031c584SApple OSS Distributions {
706*1031c584SApple OSS Distributions __pthread_testcancel(1);
707*1031c584SApple OSS Distributions return msgsnd_nocancel(p, (struct msgsnd_nocancel_args *)uap, retval);
708*1031c584SApple OSS Distributions }
709*1031c584SApple OSS Distributions
710*1031c584SApple OSS Distributions int
msgsnd_nocancel(struct proc * p,struct msgsnd_nocancel_args * uap,int32_t * retval)711*1031c584SApple OSS Distributions msgsnd_nocancel(struct proc *p, struct msgsnd_nocancel_args *uap, int32_t *retval)
712*1031c584SApple OSS Distributions {
713*1031c584SApple OSS Distributions int msqid = uap->msqid;
714*1031c584SApple OSS Distributions user_addr_t user_msgp = uap->msgp;
715*1031c584SApple OSS Distributions size_t msgsz = (size_t)uap->msgsz; /* limit to 4G */
716*1031c584SApple OSS Distributions int msgflg = uap->msgflg;
717*1031c584SApple OSS Distributions int segs_needed, eval;
718*1031c584SApple OSS Distributions struct msqid_kernel *msqptr;
719*1031c584SApple OSS Distributions struct msg *msghdr;
720*1031c584SApple OSS Distributions short next;
721*1031c584SApple OSS Distributions user_long_t msgtype;
722*1031c584SApple OSS Distributions
723*1031c584SApple OSS Distributions
724*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
725*1031c584SApple OSS Distributions
726*1031c584SApple OSS Distributions if (!msginit(0)) {
727*1031c584SApple OSS Distributions eval = ENOMEM;
728*1031c584SApple OSS Distributions goto msgsndout;
729*1031c584SApple OSS Distributions }
730*1031c584SApple OSS Distributions
731*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
732*1031c584SApple OSS Distributions printf("call to msgsnd(%d, 0x%qx, %ld, %d)\n", msqid, user_msgp, msgsz,
733*1031c584SApple OSS Distributions msgflg);
734*1031c584SApple OSS Distributions #endif
735*1031c584SApple OSS Distributions
736*1031c584SApple OSS Distributions AUDIT_ARG(svipc_id, msqid);
737*1031c584SApple OSS Distributions msqid = IPCID_TO_IX(msqid);
738*1031c584SApple OSS Distributions
739*1031c584SApple OSS Distributions if (msqid < 0 || msqid >= msginfo.msgmni) {
740*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
741*1031c584SApple OSS Distributions printf("msqid (%d) out of range (0<=msqid<%d)\n", msqid,
742*1031c584SApple OSS Distributions msginfo.msgmni);
743*1031c584SApple OSS Distributions #endif
744*1031c584SApple OSS Distributions eval = EINVAL;
745*1031c584SApple OSS Distributions goto msgsndout;
746*1031c584SApple OSS Distributions }
747*1031c584SApple OSS Distributions
748*1031c584SApple OSS Distributions msqptr = &msqids[msqid];
749*1031c584SApple OSS Distributions if (msqptr->u.msg_qbytes == 0) {
750*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
751*1031c584SApple OSS Distributions printf("no such message queue id\n");
752*1031c584SApple OSS Distributions #endif
753*1031c584SApple OSS Distributions eval = EINVAL;
754*1031c584SApple OSS Distributions goto msgsndout;
755*1031c584SApple OSS Distributions }
756*1031c584SApple OSS Distributions if (msqptr->u.msg_perm._seq != IPCID_TO_SEQ(uap->msqid)) {
757*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
758*1031c584SApple OSS Distributions printf("wrong sequence number\n");
759*1031c584SApple OSS Distributions #endif
760*1031c584SApple OSS Distributions eval = EINVAL;
761*1031c584SApple OSS Distributions goto msgsndout;
762*1031c584SApple OSS Distributions }
763*1031c584SApple OSS Distributions
764*1031c584SApple OSS Distributions if ((eval = ipcperm(kauth_cred_get(), &msqptr->u.msg_perm, IPC_W))) {
765*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
766*1031c584SApple OSS Distributions printf("requester doesn't have write access\n");
767*1031c584SApple OSS Distributions #endif
768*1031c584SApple OSS Distributions goto msgsndout;
769*1031c584SApple OSS Distributions }
770*1031c584SApple OSS Distributions
771*1031c584SApple OSS Distributions #if CONFIG_MACF
772*1031c584SApple OSS Distributions eval = mac_sysvmsq_check_msqsnd(kauth_cred_get(), msqptr);
773*1031c584SApple OSS Distributions if (eval) {
774*1031c584SApple OSS Distributions goto msgsndout;
775*1031c584SApple OSS Distributions }
776*1031c584SApple OSS Distributions #endif
777*1031c584SApple OSS Distributions segs_needed = (msgsz + msginfo.msgssz - 1) / msginfo.msgssz;
778*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
779*1031c584SApple OSS Distributions printf("msgsz=%ld, msgssz=%d, segs_needed=%d\n", msgsz, msginfo.msgssz,
780*1031c584SApple OSS Distributions segs_needed);
781*1031c584SApple OSS Distributions #endif
782*1031c584SApple OSS Distributions
783*1031c584SApple OSS Distributions /*
784*1031c584SApple OSS Distributions * If we suffer resource starvation, we will sleep in this loop and
785*1031c584SApple OSS Distributions * wait for more resources to become available. This is a loop to
786*1031c584SApple OSS Distributions * ensure reacquisition of the mutex following any sleep, since there
787*1031c584SApple OSS Distributions * are multiple resources under contention.
788*1031c584SApple OSS Distributions */
789*1031c584SApple OSS Distributions for (;;) {
790*1031c584SApple OSS Distributions void *blocking_resource = NULL;
791*1031c584SApple OSS Distributions
792*1031c584SApple OSS Distributions /*
793*1031c584SApple OSS Distributions * Check that we have not had the maximum message size change
794*1031c584SApple OSS Distributions * out from under us and render our message invalid while we
795*1031c584SApple OSS Distributions * slept waiting for some resource.
796*1031c584SApple OSS Distributions */
797*1031c584SApple OSS Distributions if (msgsz > msqptr->u.msg_qbytes) {
798*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
799*1031c584SApple OSS Distributions printf("msgsz > msqptr->msg_qbytes\n");
800*1031c584SApple OSS Distributions #endif
801*1031c584SApple OSS Distributions eval = EINVAL;
802*1031c584SApple OSS Distributions goto msgsndout;
803*1031c584SApple OSS Distributions }
804*1031c584SApple OSS Distributions
805*1031c584SApple OSS Distributions /*
806*1031c584SApple OSS Distributions * If the user_msqid_ds is already locked, we need to sleep on
807*1031c584SApple OSS Distributions * the queue until it's unlocked.
808*1031c584SApple OSS Distributions */
809*1031c584SApple OSS Distributions if (msqptr->u.msg_perm.mode & MSG_LOCKED) {
810*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
811*1031c584SApple OSS Distributions printf("msqid is locked\n");
812*1031c584SApple OSS Distributions #endif
813*1031c584SApple OSS Distributions blocking_resource = msqptr;
814*1031c584SApple OSS Distributions }
815*1031c584SApple OSS Distributions
816*1031c584SApple OSS Distributions /*
817*1031c584SApple OSS Distributions * If our message plus the messages already in the queue would
818*1031c584SApple OSS Distributions * cause us to exceed the maximum number of bytes wer are
819*1031c584SApple OSS Distributions * permitted to queue, then block on the queue until it drains.
820*1031c584SApple OSS Distributions */
821*1031c584SApple OSS Distributions if (msgsz + msqptr->u.msg_cbytes > msqptr->u.msg_qbytes) {
822*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
823*1031c584SApple OSS Distributions printf("msgsz + msg_cbytes > msg_qbytes\n");
824*1031c584SApple OSS Distributions #endif
825*1031c584SApple OSS Distributions blocking_resource = msqptr;
826*1031c584SApple OSS Distributions }
827*1031c584SApple OSS Distributions
828*1031c584SApple OSS Distributions /*
829*1031c584SApple OSS Distributions * Both message maps and message headers are protected by
830*1031c584SApple OSS Distributions * sleeping on the address of the pointer to the list of free
831*1031c584SApple OSS Distributions * message headers, since they are allocated and freed in
832*1031c584SApple OSS Distributions * tandem.
833*1031c584SApple OSS Distributions */
834*1031c584SApple OSS Distributions if (segs_needed > nfree_msgmaps) {
835*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
836*1031c584SApple OSS Distributions printf("segs_needed > nfree_msgmaps\n");
837*1031c584SApple OSS Distributions #endif
838*1031c584SApple OSS Distributions blocking_resource = &free_msghdrs;
839*1031c584SApple OSS Distributions }
840*1031c584SApple OSS Distributions if (free_msghdrs == NULL) {
841*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
842*1031c584SApple OSS Distributions printf("no more msghdrs\n");
843*1031c584SApple OSS Distributions #endif
844*1031c584SApple OSS Distributions blocking_resource = &free_msghdrs;
845*1031c584SApple OSS Distributions }
846*1031c584SApple OSS Distributions
847*1031c584SApple OSS Distributions if (blocking_resource != NULL) {
848*1031c584SApple OSS Distributions int we_own_it;
849*1031c584SApple OSS Distributions
850*1031c584SApple OSS Distributions if ((msgflg & IPC_NOWAIT) != 0) {
851*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
852*1031c584SApple OSS Distributions printf("need more resources but caller doesn't want to wait\n");
853*1031c584SApple OSS Distributions #endif
854*1031c584SApple OSS Distributions eval = EAGAIN;
855*1031c584SApple OSS Distributions goto msgsndout;
856*1031c584SApple OSS Distributions }
857*1031c584SApple OSS Distributions
858*1031c584SApple OSS Distributions if ((msqptr->u.msg_perm.mode & MSG_LOCKED) != 0) {
859*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
860*1031c584SApple OSS Distributions printf("we don't own the user_msqid_ds\n");
861*1031c584SApple OSS Distributions #endif
862*1031c584SApple OSS Distributions we_own_it = 0;
863*1031c584SApple OSS Distributions } else {
864*1031c584SApple OSS Distributions /* Force later arrivals to wait for our
865*1031c584SApple OSS Distributions * request */
866*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
867*1031c584SApple OSS Distributions printf("we own the user_msqid_ds\n");
868*1031c584SApple OSS Distributions #endif
869*1031c584SApple OSS Distributions msqptr->u.msg_perm.mode |= MSG_LOCKED;
870*1031c584SApple OSS Distributions we_own_it = 1;
871*1031c584SApple OSS Distributions }
872*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
873*1031c584SApple OSS Distributions printf("goodnight\n");
874*1031c584SApple OSS Distributions #endif
875*1031c584SApple OSS Distributions eval = msleep(blocking_resource, &sysv_msg_subsys_mutex, (PZERO - 4) | PCATCH,
876*1031c584SApple OSS Distributions "msgwait", 0);
877*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
878*1031c584SApple OSS Distributions printf("good morning, eval=%d\n", eval);
879*1031c584SApple OSS Distributions #endif
880*1031c584SApple OSS Distributions if (we_own_it) {
881*1031c584SApple OSS Distributions msqptr->u.msg_perm.mode &= ~MSG_LOCKED;
882*1031c584SApple OSS Distributions }
883*1031c584SApple OSS Distributions if (eval != 0) {
884*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
885*1031c584SApple OSS Distributions printf("msgsnd: interrupted system call\n");
886*1031c584SApple OSS Distributions #endif
887*1031c584SApple OSS Distributions eval = EINTR;
888*1031c584SApple OSS Distributions goto msgsndout;
889*1031c584SApple OSS Distributions }
890*1031c584SApple OSS Distributions
891*1031c584SApple OSS Distributions /*
892*1031c584SApple OSS Distributions * Make sure that the msq queue still exists
893*1031c584SApple OSS Distributions */
894*1031c584SApple OSS Distributions
895*1031c584SApple OSS Distributions if (msqptr->u.msg_qbytes == 0) {
896*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
897*1031c584SApple OSS Distributions printf("msqid deleted\n");
898*1031c584SApple OSS Distributions #endif
899*1031c584SApple OSS Distributions eval = EIDRM;
900*1031c584SApple OSS Distributions goto msgsndout;
901*1031c584SApple OSS Distributions }
902*1031c584SApple OSS Distributions } else {
903*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
904*1031c584SApple OSS Distributions printf("got all the resources that we need\n");
905*1031c584SApple OSS Distributions #endif
906*1031c584SApple OSS Distributions break;
907*1031c584SApple OSS Distributions }
908*1031c584SApple OSS Distributions }
909*1031c584SApple OSS Distributions
910*1031c584SApple OSS Distributions /*
911*1031c584SApple OSS Distributions * We have the resources that we need.
912*1031c584SApple OSS Distributions * Make sure!
913*1031c584SApple OSS Distributions */
914*1031c584SApple OSS Distributions
915*1031c584SApple OSS Distributions if (msqptr->u.msg_perm.mode & MSG_LOCKED) {
916*1031c584SApple OSS Distributions panic("msg_perm.mode & MSG_LOCKED");
917*1031c584SApple OSS Distributions }
918*1031c584SApple OSS Distributions if (segs_needed > nfree_msgmaps) {
919*1031c584SApple OSS Distributions panic("segs_needed > nfree_msgmaps");
920*1031c584SApple OSS Distributions }
921*1031c584SApple OSS Distributions if (msgsz + msqptr->u.msg_cbytes > msqptr->u.msg_qbytes) {
922*1031c584SApple OSS Distributions panic("msgsz + msg_cbytes > msg_qbytes");
923*1031c584SApple OSS Distributions }
924*1031c584SApple OSS Distributions if (free_msghdrs == NULL) {
925*1031c584SApple OSS Distributions panic("no more msghdrs");
926*1031c584SApple OSS Distributions }
927*1031c584SApple OSS Distributions
928*1031c584SApple OSS Distributions /*
929*1031c584SApple OSS Distributions * Re-lock the user_msqid_ds in case we page-fault when copying in
930*1031c584SApple OSS Distributions * the message
931*1031c584SApple OSS Distributions */
932*1031c584SApple OSS Distributions if ((msqptr->u.msg_perm.mode & MSG_LOCKED) != 0) {
933*1031c584SApple OSS Distributions panic("user_msqid_ds is already locked");
934*1031c584SApple OSS Distributions }
935*1031c584SApple OSS Distributions msqptr->u.msg_perm.mode |= MSG_LOCKED;
936*1031c584SApple OSS Distributions
937*1031c584SApple OSS Distributions /*
938*1031c584SApple OSS Distributions * Allocate a message header
939*1031c584SApple OSS Distributions */
940*1031c584SApple OSS Distributions msghdr = free_msghdrs;
941*1031c584SApple OSS Distributions free_msghdrs = msghdr->msg_next;
942*1031c584SApple OSS Distributions msghdr->msg_spot = -1;
943*1031c584SApple OSS Distributions msghdr->msg_ts = msgsz;
944*1031c584SApple OSS Distributions
945*1031c584SApple OSS Distributions #if CONFIG_MACF
946*1031c584SApple OSS Distributions mac_sysvmsg_label_associate(kauth_cred_get(), msqptr, msghdr);
947*1031c584SApple OSS Distributions #endif
948*1031c584SApple OSS Distributions /*
949*1031c584SApple OSS Distributions * Allocate space for the message
950*1031c584SApple OSS Distributions */
951*1031c584SApple OSS Distributions
952*1031c584SApple OSS Distributions while (segs_needed > 0) {
953*1031c584SApple OSS Distributions if (nfree_msgmaps <= 0) {
954*1031c584SApple OSS Distributions panic("not enough msgmaps");
955*1031c584SApple OSS Distributions }
956*1031c584SApple OSS Distributions if (free_msgmaps == -1) {
957*1031c584SApple OSS Distributions panic("nil free_msgmaps");
958*1031c584SApple OSS Distributions }
959*1031c584SApple OSS Distributions next = free_msgmaps;
960*1031c584SApple OSS Distributions if (next <= -1) {
961*1031c584SApple OSS Distributions panic("next too low #1");
962*1031c584SApple OSS Distributions }
963*1031c584SApple OSS Distributions if (next >= msginfo.msgseg) {
964*1031c584SApple OSS Distributions panic("next out of range #1");
965*1031c584SApple OSS Distributions }
966*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
967*1031c584SApple OSS Distributions printf("allocating segment %d to message\n", next);
968*1031c584SApple OSS Distributions #endif
969*1031c584SApple OSS Distributions free_msgmaps = msgmaps[next].next;
970*1031c584SApple OSS Distributions nfree_msgmaps--;
971*1031c584SApple OSS Distributions msgmaps[next].next = msghdr->msg_spot;
972*1031c584SApple OSS Distributions msghdr->msg_spot = next;
973*1031c584SApple OSS Distributions segs_needed--;
974*1031c584SApple OSS Distributions }
975*1031c584SApple OSS Distributions
976*1031c584SApple OSS Distributions /*
977*1031c584SApple OSS Distributions * Copy in the message type. For a 64 bit process, this is 64 bits,
978*1031c584SApple OSS Distributions * but we only ever use the low 32 bits, so the cast is OK.
979*1031c584SApple OSS Distributions */
980*1031c584SApple OSS Distributions if (IS_64BIT_PROCESS(p)) {
981*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
982*1031c584SApple OSS Distributions eval = copyin(user_msgp, &msgtype, sizeof(msgtype));
983*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
984*1031c584SApple OSS Distributions msghdr->msg_type = CAST_DOWN(long, msgtype);
985*1031c584SApple OSS Distributions user_msgp = user_msgp + sizeof(msgtype); /* ptr math */
986*1031c584SApple OSS Distributions } else {
987*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
988*1031c584SApple OSS Distributions int32_t msg_type32;
989*1031c584SApple OSS Distributions eval = copyin(user_msgp, &msg_type32, sizeof(msg_type32));
990*1031c584SApple OSS Distributions msghdr->msg_type = msg_type32;
991*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
992*1031c584SApple OSS Distributions user_msgp = user_msgp + sizeof(msg_type32); /* ptr math */
993*1031c584SApple OSS Distributions }
994*1031c584SApple OSS Distributions
995*1031c584SApple OSS Distributions if (eval != 0) {
996*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
997*1031c584SApple OSS Distributions printf("error %d copying the message type\n", eval);
998*1031c584SApple OSS Distributions #endif
999*1031c584SApple OSS Distributions msg_freehdr(msghdr);
1000*1031c584SApple OSS Distributions msqptr->u.msg_perm.mode &= ~MSG_LOCKED;
1001*1031c584SApple OSS Distributions wakeup((caddr_t)msqptr);
1002*1031c584SApple OSS Distributions goto msgsndout;
1003*1031c584SApple OSS Distributions }
1004*1031c584SApple OSS Distributions
1005*1031c584SApple OSS Distributions
1006*1031c584SApple OSS Distributions /*
1007*1031c584SApple OSS Distributions * Validate the message type
1008*1031c584SApple OSS Distributions */
1009*1031c584SApple OSS Distributions if (msghdr->msg_type < 1) {
1010*1031c584SApple OSS Distributions msg_freehdr(msghdr);
1011*1031c584SApple OSS Distributions msqptr->u.msg_perm.mode &= ~MSG_LOCKED;
1012*1031c584SApple OSS Distributions wakeup((caddr_t)msqptr);
1013*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1014*1031c584SApple OSS Distributions printf("mtype (%ld) < 1\n", msghdr->msg_type);
1015*1031c584SApple OSS Distributions #endif
1016*1031c584SApple OSS Distributions eval = EINVAL;
1017*1031c584SApple OSS Distributions goto msgsndout;
1018*1031c584SApple OSS Distributions }
1019*1031c584SApple OSS Distributions
1020*1031c584SApple OSS Distributions /*
1021*1031c584SApple OSS Distributions * Copy in the message body
1022*1031c584SApple OSS Distributions */
1023*1031c584SApple OSS Distributions next = msghdr->msg_spot;
1024*1031c584SApple OSS Distributions while (msgsz > 0) {
1025*1031c584SApple OSS Distributions size_t tlen;
1026*1031c584SApple OSS Distributions /* compare input (size_t) value against restrict (int) value */
1027*1031c584SApple OSS Distributions if (msgsz > (size_t)msginfo.msgssz) {
1028*1031c584SApple OSS Distributions tlen = msginfo.msgssz;
1029*1031c584SApple OSS Distributions } else {
1030*1031c584SApple OSS Distributions tlen = msgsz;
1031*1031c584SApple OSS Distributions }
1032*1031c584SApple OSS Distributions if (next <= -1) {
1033*1031c584SApple OSS Distributions panic("next too low #2");
1034*1031c584SApple OSS Distributions }
1035*1031c584SApple OSS Distributions if (next >= msginfo.msgseg) {
1036*1031c584SApple OSS Distributions panic("next out of range #2");
1037*1031c584SApple OSS Distributions }
1038*1031c584SApple OSS Distributions
1039*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
1040*1031c584SApple OSS Distributions eval = copyin(user_msgp, &msgpool[next * msginfo.msgssz], tlen);
1041*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
1042*1031c584SApple OSS Distributions
1043*1031c584SApple OSS Distributions if (eval != 0) {
1044*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1045*1031c584SApple OSS Distributions printf("error %d copying in message segment\n", eval);
1046*1031c584SApple OSS Distributions #endif
1047*1031c584SApple OSS Distributions msg_freehdr(msghdr);
1048*1031c584SApple OSS Distributions msqptr->u.msg_perm.mode &= ~MSG_LOCKED;
1049*1031c584SApple OSS Distributions wakeup((caddr_t)msqptr);
1050*1031c584SApple OSS Distributions
1051*1031c584SApple OSS Distributions goto msgsndout;
1052*1031c584SApple OSS Distributions }
1053*1031c584SApple OSS Distributions msgsz -= tlen;
1054*1031c584SApple OSS Distributions user_msgp = user_msgp + tlen; /* ptr math */
1055*1031c584SApple OSS Distributions next = msgmaps[next].next;
1056*1031c584SApple OSS Distributions }
1057*1031c584SApple OSS Distributions if (next != -1) {
1058*1031c584SApple OSS Distributions panic("didn't use all the msg segments");
1059*1031c584SApple OSS Distributions }
1060*1031c584SApple OSS Distributions
1061*1031c584SApple OSS Distributions /*
1062*1031c584SApple OSS Distributions * We've got the message. Unlock the user_msqid_ds.
1063*1031c584SApple OSS Distributions */
1064*1031c584SApple OSS Distributions
1065*1031c584SApple OSS Distributions msqptr->u.msg_perm.mode &= ~MSG_LOCKED;
1066*1031c584SApple OSS Distributions
1067*1031c584SApple OSS Distributions /*
1068*1031c584SApple OSS Distributions * Make sure that the user_msqid_ds is still allocated.
1069*1031c584SApple OSS Distributions */
1070*1031c584SApple OSS Distributions
1071*1031c584SApple OSS Distributions if (msqptr->u.msg_qbytes == 0) {
1072*1031c584SApple OSS Distributions msg_freehdr(msghdr);
1073*1031c584SApple OSS Distributions wakeup((caddr_t)msqptr);
1074*1031c584SApple OSS Distributions /* The SVID says to return EIDRM. */
1075*1031c584SApple OSS Distributions #ifdef EIDRM
1076*1031c584SApple OSS Distributions eval = EIDRM;
1077*1031c584SApple OSS Distributions #else
1078*1031c584SApple OSS Distributions /* Unfortunately, BSD doesn't define that code yet! */
1079*1031c584SApple OSS Distributions eval = EINVAL;
1080*1031c584SApple OSS Distributions #endif
1081*1031c584SApple OSS Distributions goto msgsndout;
1082*1031c584SApple OSS Distributions }
1083*1031c584SApple OSS Distributions
1084*1031c584SApple OSS Distributions #if CONFIG_MACF
1085*1031c584SApple OSS Distributions /*
1086*1031c584SApple OSS Distributions * Note: Since the task/thread allocates the msghdr and usually
1087*1031c584SApple OSS Distributions * primes it with its own MAC label, for a majority of policies, it
1088*1031c584SApple OSS Distributions * won't be necessary to check whether the msghdr has access
1089*1031c584SApple OSS Distributions * permissions to the msgq. The mac_sysvmsq_check_msqsnd check would
1090*1031c584SApple OSS Distributions * suffice in that case. However, this hook may be required where
1091*1031c584SApple OSS Distributions * individual policies derive a non-identical label for the msghdr
1092*1031c584SApple OSS Distributions * from the current thread label and may want to check the msghdr
1093*1031c584SApple OSS Distributions * enqueue permissions, along with read/write permissions to the
1094*1031c584SApple OSS Distributions * msgq.
1095*1031c584SApple OSS Distributions */
1096*1031c584SApple OSS Distributions eval = mac_sysvmsq_check_enqueue(kauth_cred_get(), msghdr, msqptr);
1097*1031c584SApple OSS Distributions if (eval) {
1098*1031c584SApple OSS Distributions msg_freehdr(msghdr);
1099*1031c584SApple OSS Distributions wakeup((caddr_t) msqptr);
1100*1031c584SApple OSS Distributions goto msgsndout;
1101*1031c584SApple OSS Distributions }
1102*1031c584SApple OSS Distributions #endif
1103*1031c584SApple OSS Distributions /*
1104*1031c584SApple OSS Distributions * Put the message into the queue
1105*1031c584SApple OSS Distributions */
1106*1031c584SApple OSS Distributions
1107*1031c584SApple OSS Distributions if (msqptr->u.msg_first == NULL) {
1108*1031c584SApple OSS Distributions msqptr->u.msg_first = msghdr;
1109*1031c584SApple OSS Distributions msqptr->u.msg_last = msghdr;
1110*1031c584SApple OSS Distributions } else {
1111*1031c584SApple OSS Distributions msqptr->u.msg_last->msg_next = msghdr;
1112*1031c584SApple OSS Distributions msqptr->u.msg_last = msghdr;
1113*1031c584SApple OSS Distributions }
1114*1031c584SApple OSS Distributions msqptr->u.msg_last->msg_next = NULL;
1115*1031c584SApple OSS Distributions
1116*1031c584SApple OSS Distributions msqptr->u.msg_cbytes += msghdr->msg_ts;
1117*1031c584SApple OSS Distributions msqptr->u.msg_qnum++;
1118*1031c584SApple OSS Distributions msqptr->u.msg_lspid = proc_getpid(p);
1119*1031c584SApple OSS Distributions msqptr->u.msg_stime = sysv_msgtime();
1120*1031c584SApple OSS Distributions
1121*1031c584SApple OSS Distributions wakeup((caddr_t)msqptr);
1122*1031c584SApple OSS Distributions *retval = 0;
1123*1031c584SApple OSS Distributions eval = 0;
1124*1031c584SApple OSS Distributions
1125*1031c584SApple OSS Distributions msgsndout:
1126*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
1127*1031c584SApple OSS Distributions return eval;
1128*1031c584SApple OSS Distributions }
1129*1031c584SApple OSS Distributions
1130*1031c584SApple OSS Distributions
1131*1031c584SApple OSS Distributions int
msgrcv(struct proc * p,struct msgrcv_args * uap,user_ssize_t * retval)1132*1031c584SApple OSS Distributions msgrcv(struct proc *p, struct msgrcv_args *uap, user_ssize_t *retval)
1133*1031c584SApple OSS Distributions {
1134*1031c584SApple OSS Distributions __pthread_testcancel(1);
1135*1031c584SApple OSS Distributions return msgrcv_nocancel(p, (struct msgrcv_nocancel_args *)uap, retval);
1136*1031c584SApple OSS Distributions }
1137*1031c584SApple OSS Distributions
1138*1031c584SApple OSS Distributions int
msgrcv_nocancel(struct proc * p,struct msgrcv_nocancel_args * uap,user_ssize_t * retval)1139*1031c584SApple OSS Distributions msgrcv_nocancel(struct proc *p, struct msgrcv_nocancel_args *uap, user_ssize_t *retval)
1140*1031c584SApple OSS Distributions {
1141*1031c584SApple OSS Distributions int msqid = uap->msqid;
1142*1031c584SApple OSS Distributions user_addr_t user_msgp = uap->msgp;
1143*1031c584SApple OSS Distributions size_t msgsz = (size_t)uap->msgsz; /* limit to 4G */
1144*1031c584SApple OSS Distributions long msgtyp = (long)uap->msgtyp; /* limit to 32 bits */
1145*1031c584SApple OSS Distributions int msgflg = uap->msgflg;
1146*1031c584SApple OSS Distributions size_t len;
1147*1031c584SApple OSS Distributions struct msqid_kernel *msqptr;
1148*1031c584SApple OSS Distributions struct msg *msghdr;
1149*1031c584SApple OSS Distributions int eval;
1150*1031c584SApple OSS Distributions short next;
1151*1031c584SApple OSS Distributions user_long_t msgtype;
1152*1031c584SApple OSS Distributions int32_t msg_type32;
1153*1031c584SApple OSS Distributions
1154*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
1155*1031c584SApple OSS Distributions
1156*1031c584SApple OSS Distributions if (!msginit(0)) {
1157*1031c584SApple OSS Distributions eval = ENOMEM;
1158*1031c584SApple OSS Distributions goto msgrcvout;
1159*1031c584SApple OSS Distributions }
1160*1031c584SApple OSS Distributions
1161*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1162*1031c584SApple OSS Distributions printf("call to msgrcv(%d, 0x%qx, %ld, %ld, %d)\n", msqid, user_msgp,
1163*1031c584SApple OSS Distributions msgsz, msgtyp, msgflg);
1164*1031c584SApple OSS Distributions #endif
1165*1031c584SApple OSS Distributions
1166*1031c584SApple OSS Distributions AUDIT_ARG(svipc_id, msqid);
1167*1031c584SApple OSS Distributions msqid = IPCID_TO_IX(msqid);
1168*1031c584SApple OSS Distributions
1169*1031c584SApple OSS Distributions if (msqid < 0 || msqid >= msginfo.msgmni) {
1170*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1171*1031c584SApple OSS Distributions printf("msqid (%d) out of range (0<=msqid<%d)\n", msqid,
1172*1031c584SApple OSS Distributions msginfo.msgmni);
1173*1031c584SApple OSS Distributions #endif
1174*1031c584SApple OSS Distributions eval = EINVAL;
1175*1031c584SApple OSS Distributions goto msgrcvout;
1176*1031c584SApple OSS Distributions }
1177*1031c584SApple OSS Distributions
1178*1031c584SApple OSS Distributions msqptr = &msqids[msqid];
1179*1031c584SApple OSS Distributions if (msqptr->u.msg_qbytes == 0) {
1180*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1181*1031c584SApple OSS Distributions printf("no such message queue id\n");
1182*1031c584SApple OSS Distributions #endif
1183*1031c584SApple OSS Distributions eval = EINVAL;
1184*1031c584SApple OSS Distributions goto msgrcvout;
1185*1031c584SApple OSS Distributions }
1186*1031c584SApple OSS Distributions if (msqptr->u.msg_perm._seq != IPCID_TO_SEQ(uap->msqid)) {
1187*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1188*1031c584SApple OSS Distributions printf("wrong sequence number\n");
1189*1031c584SApple OSS Distributions #endif
1190*1031c584SApple OSS Distributions eval = EINVAL;
1191*1031c584SApple OSS Distributions goto msgrcvout;
1192*1031c584SApple OSS Distributions }
1193*1031c584SApple OSS Distributions
1194*1031c584SApple OSS Distributions if ((eval = ipcperm(kauth_cred_get(), &msqptr->u.msg_perm, IPC_R))) {
1195*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1196*1031c584SApple OSS Distributions printf("requester doesn't have read access\n");
1197*1031c584SApple OSS Distributions #endif
1198*1031c584SApple OSS Distributions goto msgrcvout;
1199*1031c584SApple OSS Distributions }
1200*1031c584SApple OSS Distributions
1201*1031c584SApple OSS Distributions #if CONFIG_MACF
1202*1031c584SApple OSS Distributions eval = mac_sysvmsq_check_msqrcv(kauth_cred_get(), msqptr);
1203*1031c584SApple OSS Distributions if (eval) {
1204*1031c584SApple OSS Distributions goto msgrcvout;
1205*1031c584SApple OSS Distributions }
1206*1031c584SApple OSS Distributions #endif
1207*1031c584SApple OSS Distributions msghdr = NULL;
1208*1031c584SApple OSS Distributions while (msghdr == NULL) {
1209*1031c584SApple OSS Distributions if (msgtyp == 0) {
1210*1031c584SApple OSS Distributions msghdr = msqptr->u.msg_first;
1211*1031c584SApple OSS Distributions if (msghdr != NULL) {
1212*1031c584SApple OSS Distributions if (msgsz < msghdr->msg_ts &&
1213*1031c584SApple OSS Distributions (msgflg & MSG_NOERROR) == 0) {
1214*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1215*1031c584SApple OSS Distributions printf("first message on the queue is too big (want %ld, got %d)\n",
1216*1031c584SApple OSS Distributions msgsz, msghdr->msg_ts);
1217*1031c584SApple OSS Distributions #endif
1218*1031c584SApple OSS Distributions eval = E2BIG;
1219*1031c584SApple OSS Distributions goto msgrcvout;
1220*1031c584SApple OSS Distributions }
1221*1031c584SApple OSS Distributions #if CONFIG_MACF
1222*1031c584SApple OSS Distributions eval = mac_sysvmsq_check_msgrcv(kauth_cred_get(),
1223*1031c584SApple OSS Distributions msghdr);
1224*1031c584SApple OSS Distributions if (eval) {
1225*1031c584SApple OSS Distributions goto msgrcvout;
1226*1031c584SApple OSS Distributions }
1227*1031c584SApple OSS Distributions #endif
1228*1031c584SApple OSS Distributions if (msqptr->u.msg_first == msqptr->u.msg_last) {
1229*1031c584SApple OSS Distributions msqptr->u.msg_first = NULL;
1230*1031c584SApple OSS Distributions msqptr->u.msg_last = NULL;
1231*1031c584SApple OSS Distributions } else {
1232*1031c584SApple OSS Distributions msqptr->u.msg_first = msghdr->msg_next;
1233*1031c584SApple OSS Distributions if (msqptr->u.msg_first == NULL) {
1234*1031c584SApple OSS Distributions panic("msg_first/last messed up #1");
1235*1031c584SApple OSS Distributions }
1236*1031c584SApple OSS Distributions }
1237*1031c584SApple OSS Distributions }
1238*1031c584SApple OSS Distributions } else {
1239*1031c584SApple OSS Distributions struct msg *previous;
1240*1031c584SApple OSS Distributions struct msg **prev;
1241*1031c584SApple OSS Distributions
1242*1031c584SApple OSS Distributions previous = NULL;
1243*1031c584SApple OSS Distributions prev = &(msqptr->u.msg_first);
1244*1031c584SApple OSS Distributions while ((msghdr = *prev) != NULL) {
1245*1031c584SApple OSS Distributions /*
1246*1031c584SApple OSS Distributions * Is this message's type an exact match or is
1247*1031c584SApple OSS Distributions * this message's type less than or equal to
1248*1031c584SApple OSS Distributions * the absolute value of a negative msgtyp?
1249*1031c584SApple OSS Distributions * Note that the second half of this test can
1250*1031c584SApple OSS Distributions * NEVER be true if msgtyp is positive since
1251*1031c584SApple OSS Distributions * msg_type is always positive!
1252*1031c584SApple OSS Distributions */
1253*1031c584SApple OSS Distributions
1254*1031c584SApple OSS Distributions if (msgtyp == msghdr->msg_type ||
1255*1031c584SApple OSS Distributions msghdr->msg_type <= -msgtyp) {
1256*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1257*1031c584SApple OSS Distributions printf("found message type %ld, requested %ld\n",
1258*1031c584SApple OSS Distributions msghdr->msg_type, msgtyp);
1259*1031c584SApple OSS Distributions #endif
1260*1031c584SApple OSS Distributions if (msgsz < msghdr->msg_ts &&
1261*1031c584SApple OSS Distributions (msgflg & MSG_NOERROR) == 0) {
1262*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1263*1031c584SApple OSS Distributions printf("requested message on the queue is too big (want %ld, got %d)\n",
1264*1031c584SApple OSS Distributions msgsz, msghdr->msg_ts);
1265*1031c584SApple OSS Distributions #endif
1266*1031c584SApple OSS Distributions eval = E2BIG;
1267*1031c584SApple OSS Distributions goto msgrcvout;
1268*1031c584SApple OSS Distributions }
1269*1031c584SApple OSS Distributions #if CONFIG_MACF
1270*1031c584SApple OSS Distributions eval = mac_sysvmsq_check_msgrcv(
1271*1031c584SApple OSS Distributions kauth_cred_get(), msghdr);
1272*1031c584SApple OSS Distributions if (eval) {
1273*1031c584SApple OSS Distributions goto msgrcvout;
1274*1031c584SApple OSS Distributions }
1275*1031c584SApple OSS Distributions #endif
1276*1031c584SApple OSS Distributions *prev = msghdr->msg_next;
1277*1031c584SApple OSS Distributions if (msghdr == msqptr->u.msg_last) {
1278*1031c584SApple OSS Distributions if (previous == NULL) {
1279*1031c584SApple OSS Distributions if (prev !=
1280*1031c584SApple OSS Distributions &msqptr->u.msg_first) {
1281*1031c584SApple OSS Distributions panic("msg_first/last messed up #2");
1282*1031c584SApple OSS Distributions }
1283*1031c584SApple OSS Distributions msqptr->u.msg_first =
1284*1031c584SApple OSS Distributions NULL;
1285*1031c584SApple OSS Distributions msqptr->u.msg_last =
1286*1031c584SApple OSS Distributions NULL;
1287*1031c584SApple OSS Distributions } else {
1288*1031c584SApple OSS Distributions if (prev ==
1289*1031c584SApple OSS Distributions &msqptr->u.msg_first) {
1290*1031c584SApple OSS Distributions panic("msg_first/last messed up #3");
1291*1031c584SApple OSS Distributions }
1292*1031c584SApple OSS Distributions msqptr->u.msg_last =
1293*1031c584SApple OSS Distributions previous;
1294*1031c584SApple OSS Distributions }
1295*1031c584SApple OSS Distributions }
1296*1031c584SApple OSS Distributions break;
1297*1031c584SApple OSS Distributions }
1298*1031c584SApple OSS Distributions previous = msghdr;
1299*1031c584SApple OSS Distributions prev = &(msghdr->msg_next);
1300*1031c584SApple OSS Distributions }
1301*1031c584SApple OSS Distributions }
1302*1031c584SApple OSS Distributions
1303*1031c584SApple OSS Distributions /*
1304*1031c584SApple OSS Distributions * We've either extracted the msghdr for the appropriate
1305*1031c584SApple OSS Distributions * message or there isn't one.
1306*1031c584SApple OSS Distributions * If there is one then bail out of this loop.
1307*1031c584SApple OSS Distributions */
1308*1031c584SApple OSS Distributions
1309*1031c584SApple OSS Distributions if (msghdr != NULL) {
1310*1031c584SApple OSS Distributions break;
1311*1031c584SApple OSS Distributions }
1312*1031c584SApple OSS Distributions
1313*1031c584SApple OSS Distributions /*
1314*1031c584SApple OSS Distributions * Hmph! No message found. Does the user want to wait?
1315*1031c584SApple OSS Distributions */
1316*1031c584SApple OSS Distributions
1317*1031c584SApple OSS Distributions if ((msgflg & IPC_NOWAIT) != 0) {
1318*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1319*1031c584SApple OSS Distributions printf("no appropriate message found (msgtyp=%ld)\n",
1320*1031c584SApple OSS Distributions msgtyp);
1321*1031c584SApple OSS Distributions #endif
1322*1031c584SApple OSS Distributions /* The SVID says to return ENOMSG. */
1323*1031c584SApple OSS Distributions #ifdef ENOMSG
1324*1031c584SApple OSS Distributions eval = ENOMSG;
1325*1031c584SApple OSS Distributions #else
1326*1031c584SApple OSS Distributions /* Unfortunately, BSD doesn't define that code yet! */
1327*1031c584SApple OSS Distributions eval = EAGAIN;
1328*1031c584SApple OSS Distributions #endif
1329*1031c584SApple OSS Distributions goto msgrcvout;
1330*1031c584SApple OSS Distributions }
1331*1031c584SApple OSS Distributions
1332*1031c584SApple OSS Distributions /*
1333*1031c584SApple OSS Distributions * Wait for something to happen
1334*1031c584SApple OSS Distributions */
1335*1031c584SApple OSS Distributions
1336*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1337*1031c584SApple OSS Distributions printf("msgrcv: goodnight\n");
1338*1031c584SApple OSS Distributions #endif
1339*1031c584SApple OSS Distributions eval = msleep((caddr_t)msqptr, &sysv_msg_subsys_mutex, (PZERO - 4) | PCATCH, "msgwait",
1340*1031c584SApple OSS Distributions 0);
1341*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1342*1031c584SApple OSS Distributions printf("msgrcv: good morning (eval=%d)\n", eval);
1343*1031c584SApple OSS Distributions #endif
1344*1031c584SApple OSS Distributions
1345*1031c584SApple OSS Distributions if (eval != 0) {
1346*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1347*1031c584SApple OSS Distributions printf("msgsnd: interrupted system call\n");
1348*1031c584SApple OSS Distributions #endif
1349*1031c584SApple OSS Distributions eval = EINTR;
1350*1031c584SApple OSS Distributions goto msgrcvout;
1351*1031c584SApple OSS Distributions }
1352*1031c584SApple OSS Distributions
1353*1031c584SApple OSS Distributions /*
1354*1031c584SApple OSS Distributions * Make sure that the msq queue still exists
1355*1031c584SApple OSS Distributions */
1356*1031c584SApple OSS Distributions
1357*1031c584SApple OSS Distributions if (msqptr->u.msg_qbytes == 0 ||
1358*1031c584SApple OSS Distributions msqptr->u.msg_perm._seq != IPCID_TO_SEQ(uap->msqid)) {
1359*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1360*1031c584SApple OSS Distributions printf("msqid deleted\n");
1361*1031c584SApple OSS Distributions #endif
1362*1031c584SApple OSS Distributions /* The SVID says to return EIDRM. */
1363*1031c584SApple OSS Distributions #ifdef EIDRM
1364*1031c584SApple OSS Distributions eval = EIDRM;
1365*1031c584SApple OSS Distributions #else
1366*1031c584SApple OSS Distributions /* Unfortunately, BSD doesn't define that code yet! */
1367*1031c584SApple OSS Distributions eval = EINVAL;
1368*1031c584SApple OSS Distributions #endif
1369*1031c584SApple OSS Distributions goto msgrcvout;
1370*1031c584SApple OSS Distributions }
1371*1031c584SApple OSS Distributions }
1372*1031c584SApple OSS Distributions
1373*1031c584SApple OSS Distributions /*
1374*1031c584SApple OSS Distributions * Return the message to the user.
1375*1031c584SApple OSS Distributions *
1376*1031c584SApple OSS Distributions * First, do the bookkeeping (before we risk being interrupted).
1377*1031c584SApple OSS Distributions */
1378*1031c584SApple OSS Distributions
1379*1031c584SApple OSS Distributions msqptr->u.msg_cbytes -= msghdr->msg_ts;
1380*1031c584SApple OSS Distributions msqptr->u.msg_qnum--;
1381*1031c584SApple OSS Distributions msqptr->u.msg_lrpid = proc_getpid(p);
1382*1031c584SApple OSS Distributions msqptr->u.msg_rtime = sysv_msgtime();
1383*1031c584SApple OSS Distributions
1384*1031c584SApple OSS Distributions /*
1385*1031c584SApple OSS Distributions * Make msgsz the actual amount that we'll be returning.
1386*1031c584SApple OSS Distributions * Note that this effectively truncates the message if it is too long
1387*1031c584SApple OSS Distributions * (since msgsz is never increased).
1388*1031c584SApple OSS Distributions */
1389*1031c584SApple OSS Distributions
1390*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1391*1031c584SApple OSS Distributions printf("found a message, msgsz=%ld, msg_ts=%d\n", msgsz,
1392*1031c584SApple OSS Distributions msghdr->msg_ts);
1393*1031c584SApple OSS Distributions #endif
1394*1031c584SApple OSS Distributions if (msgsz > msghdr->msg_ts) {
1395*1031c584SApple OSS Distributions msgsz = msghdr->msg_ts;
1396*1031c584SApple OSS Distributions }
1397*1031c584SApple OSS Distributions
1398*1031c584SApple OSS Distributions /*
1399*1031c584SApple OSS Distributions * Return the type to the user.
1400*1031c584SApple OSS Distributions */
1401*1031c584SApple OSS Distributions
1402*1031c584SApple OSS Distributions /*
1403*1031c584SApple OSS Distributions * Copy out the message type. For a 64 bit process, this is 64 bits,
1404*1031c584SApple OSS Distributions * but we only ever use the low 32 bits, so the cast is OK.
1405*1031c584SApple OSS Distributions */
1406*1031c584SApple OSS Distributions if (IS_64BIT_PROCESS(p)) {
1407*1031c584SApple OSS Distributions msgtype = msghdr->msg_type;
1408*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
1409*1031c584SApple OSS Distributions eval = copyout(&msgtype, user_msgp, sizeof(msgtype));
1410*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
1411*1031c584SApple OSS Distributions user_msgp = user_msgp + sizeof(msgtype); /* ptr math */
1412*1031c584SApple OSS Distributions } else {
1413*1031c584SApple OSS Distributions msg_type32 = msghdr->msg_type;
1414*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
1415*1031c584SApple OSS Distributions eval = copyout(&msg_type32, user_msgp, sizeof(msg_type32));
1416*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
1417*1031c584SApple OSS Distributions user_msgp = user_msgp + sizeof(msg_type32); /* ptr math */
1418*1031c584SApple OSS Distributions }
1419*1031c584SApple OSS Distributions
1420*1031c584SApple OSS Distributions if (eval != 0) {
1421*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1422*1031c584SApple OSS Distributions printf("error (%d) copying out message type\n", eval);
1423*1031c584SApple OSS Distributions #endif
1424*1031c584SApple OSS Distributions msg_freehdr(msghdr);
1425*1031c584SApple OSS Distributions wakeup((caddr_t)msqptr);
1426*1031c584SApple OSS Distributions
1427*1031c584SApple OSS Distributions goto msgrcvout;
1428*1031c584SApple OSS Distributions }
1429*1031c584SApple OSS Distributions
1430*1031c584SApple OSS Distributions
1431*1031c584SApple OSS Distributions /*
1432*1031c584SApple OSS Distributions * Return the segments to the user
1433*1031c584SApple OSS Distributions */
1434*1031c584SApple OSS Distributions
1435*1031c584SApple OSS Distributions next = msghdr->msg_spot;
1436*1031c584SApple OSS Distributions for (len = 0; len < msgsz; len += msginfo.msgssz) {
1437*1031c584SApple OSS Distributions size_t tlen;
1438*1031c584SApple OSS Distributions
1439*1031c584SApple OSS Distributions /*
1440*1031c584SApple OSS Distributions * copy the full segment, or less if we're at the end
1441*1031c584SApple OSS Distributions * of the message
1442*1031c584SApple OSS Distributions */
1443*1031c584SApple OSS Distributions tlen = MIN(msgsz - len, (size_t)msginfo.msgssz);
1444*1031c584SApple OSS Distributions if (next <= -1) {
1445*1031c584SApple OSS Distributions panic("next too low #3");
1446*1031c584SApple OSS Distributions }
1447*1031c584SApple OSS Distributions if (next >= msginfo.msgseg) {
1448*1031c584SApple OSS Distributions panic("next out of range #3");
1449*1031c584SApple OSS Distributions }
1450*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
1451*1031c584SApple OSS Distributions eval = copyout(&msgpool[next * msginfo.msgssz],
1452*1031c584SApple OSS Distributions user_msgp, tlen);
1453*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
1454*1031c584SApple OSS Distributions if (eval != 0) {
1455*1031c584SApple OSS Distributions #ifdef MSG_DEBUG_OK
1456*1031c584SApple OSS Distributions printf("error (%d) copying out message segment\n",
1457*1031c584SApple OSS Distributions eval);
1458*1031c584SApple OSS Distributions #endif
1459*1031c584SApple OSS Distributions msg_freehdr(msghdr);
1460*1031c584SApple OSS Distributions wakeup((caddr_t)msqptr);
1461*1031c584SApple OSS Distributions goto msgrcvout;
1462*1031c584SApple OSS Distributions }
1463*1031c584SApple OSS Distributions user_msgp = user_msgp + tlen; /* ptr math */
1464*1031c584SApple OSS Distributions next = msgmaps[next].next;
1465*1031c584SApple OSS Distributions }
1466*1031c584SApple OSS Distributions
1467*1031c584SApple OSS Distributions /*
1468*1031c584SApple OSS Distributions * Done, return the actual number of bytes copied out.
1469*1031c584SApple OSS Distributions */
1470*1031c584SApple OSS Distributions
1471*1031c584SApple OSS Distributions msg_freehdr(msghdr);
1472*1031c584SApple OSS Distributions wakeup((caddr_t)msqptr);
1473*1031c584SApple OSS Distributions *retval = msgsz;
1474*1031c584SApple OSS Distributions eval = 0;
1475*1031c584SApple OSS Distributions msgrcvout:
1476*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
1477*1031c584SApple OSS Distributions return eval;
1478*1031c584SApple OSS Distributions }
1479*1031c584SApple OSS Distributions
1480*1031c584SApple OSS Distributions static int
IPCS_msg_sysctl(__unused struct sysctl_oid * oidp,__unused void * arg1,__unused int arg2,struct sysctl_req * req)1481*1031c584SApple OSS Distributions IPCS_msg_sysctl(__unused struct sysctl_oid *oidp, __unused void *arg1,
1482*1031c584SApple OSS Distributions __unused int arg2, struct sysctl_req *req)
1483*1031c584SApple OSS Distributions {
1484*1031c584SApple OSS Distributions int error;
1485*1031c584SApple OSS Distributions int cursor;
1486*1031c584SApple OSS Distributions union {
1487*1031c584SApple OSS Distributions struct user32_IPCS_command u32;
1488*1031c584SApple OSS Distributions struct user_IPCS_command u64;
1489*1031c584SApple OSS Distributions } ipcs = { };
1490*1031c584SApple OSS Distributions struct user32_msqid_ds msqid_ds32 = {}; /* post conversion, 32 bit version */
1491*1031c584SApple OSS Distributions struct user64_msqid_ds msqid_ds64 = {}; /* post conversion, 64 bit version */
1492*1031c584SApple OSS Distributions void *msqid_dsp;
1493*1031c584SApple OSS Distributions size_t ipcs_sz;
1494*1031c584SApple OSS Distributions size_t msqid_ds_sz;
1495*1031c584SApple OSS Distributions struct proc *p = current_proc();
1496*1031c584SApple OSS Distributions
1497*1031c584SApple OSS Distributions if (IS_64BIT_PROCESS(p)) {
1498*1031c584SApple OSS Distributions ipcs_sz = sizeof(struct user_IPCS_command);
1499*1031c584SApple OSS Distributions msqid_ds_sz = sizeof(struct user64_msqid_ds);
1500*1031c584SApple OSS Distributions } else {
1501*1031c584SApple OSS Distributions ipcs_sz = sizeof(struct user32_IPCS_command);
1502*1031c584SApple OSS Distributions msqid_ds_sz = sizeof(struct user32_msqid_ds);
1503*1031c584SApple OSS Distributions }
1504*1031c584SApple OSS Distributions
1505*1031c584SApple OSS Distributions /* Copy in the command structure */
1506*1031c584SApple OSS Distributions if ((error = SYSCTL_IN(req, &ipcs, ipcs_sz)) != 0) {
1507*1031c584SApple OSS Distributions return error;
1508*1031c584SApple OSS Distributions }
1509*1031c584SApple OSS Distributions
1510*1031c584SApple OSS Distributions if (!IS_64BIT_PROCESS(p)) { /* convert in place */
1511*1031c584SApple OSS Distributions ipcs.u64.ipcs_data = CAST_USER_ADDR_T(ipcs.u32.ipcs_data);
1512*1031c584SApple OSS Distributions }
1513*1031c584SApple OSS Distributions
1514*1031c584SApple OSS Distributions /* Let us version this interface... */
1515*1031c584SApple OSS Distributions if (ipcs.u64.ipcs_magic != IPCS_MAGIC) {
1516*1031c584SApple OSS Distributions return EINVAL;
1517*1031c584SApple OSS Distributions }
1518*1031c584SApple OSS Distributions
1519*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
1520*1031c584SApple OSS Distributions
1521*1031c584SApple OSS Distributions switch (ipcs.u64.ipcs_op) {
1522*1031c584SApple OSS Distributions case IPCS_MSG_CONF: /* Obtain global configuration data */
1523*1031c584SApple OSS Distributions if (ipcs.u64.ipcs_datalen != sizeof(struct msginfo)) {
1524*1031c584SApple OSS Distributions error = ERANGE;
1525*1031c584SApple OSS Distributions break;
1526*1031c584SApple OSS Distributions }
1527*1031c584SApple OSS Distributions if (ipcs.u64.ipcs_cursor != 0) { /* fwd. compat. */
1528*1031c584SApple OSS Distributions error = EINVAL;
1529*1031c584SApple OSS Distributions break;
1530*1031c584SApple OSS Distributions }
1531*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
1532*1031c584SApple OSS Distributions error = copyout(&msginfo, ipcs.u64.ipcs_data, ipcs.u64.ipcs_datalen);
1533*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
1534*1031c584SApple OSS Distributions break;
1535*1031c584SApple OSS Distributions
1536*1031c584SApple OSS Distributions case IPCS_MSG_ITER: /* Iterate over existing segments */
1537*1031c584SApple OSS Distributions /* Not done up top so we can set limits via sysctl (later) */
1538*1031c584SApple OSS Distributions if (!msginit(0)) {
1539*1031c584SApple OSS Distributions error = ENOMEM;
1540*1031c584SApple OSS Distributions break;
1541*1031c584SApple OSS Distributions }
1542*1031c584SApple OSS Distributions
1543*1031c584SApple OSS Distributions cursor = ipcs.u64.ipcs_cursor;
1544*1031c584SApple OSS Distributions if (cursor < 0 || cursor >= msginfo.msgmni) {
1545*1031c584SApple OSS Distributions error = ERANGE;
1546*1031c584SApple OSS Distributions break;
1547*1031c584SApple OSS Distributions }
1548*1031c584SApple OSS Distributions if (ipcs.u64.ipcs_datalen != (int)msqid_ds_sz) {
1549*1031c584SApple OSS Distributions error = EINVAL;
1550*1031c584SApple OSS Distributions break;
1551*1031c584SApple OSS Distributions }
1552*1031c584SApple OSS Distributions for (; cursor < msginfo.msgmni; cursor++) {
1553*1031c584SApple OSS Distributions if (msqids[cursor].u.msg_qbytes != 0) { /* allocated */
1554*1031c584SApple OSS Distributions break;
1555*1031c584SApple OSS Distributions }
1556*1031c584SApple OSS Distributions continue;
1557*1031c584SApple OSS Distributions }
1558*1031c584SApple OSS Distributions if (cursor == msginfo.msgmni) {
1559*1031c584SApple OSS Distributions error = ENOENT;
1560*1031c584SApple OSS Distributions break;
1561*1031c584SApple OSS Distributions }
1562*1031c584SApple OSS Distributions
1563*1031c584SApple OSS Distributions msqid_dsp = &msqids[cursor]; /* default: 64 bit */
1564*1031c584SApple OSS Distributions
1565*1031c584SApple OSS Distributions /*
1566*1031c584SApple OSS Distributions * If necessary, convert the 64 bit kernel segment
1567*1031c584SApple OSS Distributions * descriptor to a 32 bit user one.
1568*1031c584SApple OSS Distributions */
1569*1031c584SApple OSS Distributions if (IS_64BIT_PROCESS(p)) {
1570*1031c584SApple OSS Distributions msqid_ds_kerneltouser64(msqid_dsp, &msqid_ds64);
1571*1031c584SApple OSS Distributions msqid_dsp = &msqid_ds64;
1572*1031c584SApple OSS Distributions } else {
1573*1031c584SApple OSS Distributions msqid_ds_kerneltouser32(msqid_dsp, &msqid_ds32);
1574*1031c584SApple OSS Distributions msqid_dsp = &msqid_ds32;
1575*1031c584SApple OSS Distributions }
1576*1031c584SApple OSS Distributions
1577*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
1578*1031c584SApple OSS Distributions error = copyout(msqid_dsp, ipcs.u64.ipcs_data, ipcs.u64.ipcs_datalen);
1579*1031c584SApple OSS Distributions if (!error) {
1580*1031c584SApple OSS Distributions /* update cursor */
1581*1031c584SApple OSS Distributions ipcs.u64.ipcs_cursor = cursor + 1;
1582*1031c584SApple OSS Distributions
1583*1031c584SApple OSS Distributions if (!IS_64BIT_PROCESS(p)) { /* convert in place */
1584*1031c584SApple OSS Distributions ipcs.u32.ipcs_data = CAST_DOWN_EXPLICIT(user32_addr_t, ipcs.u64.ipcs_data);
1585*1031c584SApple OSS Distributions }
1586*1031c584SApple OSS Distributions error = SYSCTL_OUT(req, &ipcs, ipcs_sz);
1587*1031c584SApple OSS Distributions }
1588*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_LOCK();
1589*1031c584SApple OSS Distributions break;
1590*1031c584SApple OSS Distributions
1591*1031c584SApple OSS Distributions default:
1592*1031c584SApple OSS Distributions error = EINVAL;
1593*1031c584SApple OSS Distributions break;
1594*1031c584SApple OSS Distributions }
1595*1031c584SApple OSS Distributions
1596*1031c584SApple OSS Distributions SYSV_MSG_SUBSYS_UNLOCK();
1597*1031c584SApple OSS Distributions return error;
1598*1031c584SApple OSS Distributions }
1599*1031c584SApple OSS Distributions
1600*1031c584SApple OSS Distributions SYSCTL_DECL(_kern_sysv_ipcs);
1601*1031c584SApple OSS Distributions SYSCTL_PROC(_kern_sysv_ipcs, OID_AUTO, msg, CTLFLAG_RW | CTLFLAG_ANYBODY | CTLFLAG_LOCKED,
1602*1031c584SApple OSS Distributions 0, 0, IPCS_msg_sysctl,
1603*1031c584SApple OSS Distributions "S,IPCS_msg_command",
1604*1031c584SApple OSS Distributions "ipcs msg command interface");
1605*1031c584SApple OSS Distributions
1606*1031c584SApple OSS Distributions #endif /* SYSV_MSG */
1607