xref: /xnu-10002.61.3/bsd/kern/sysv_shm.c (revision 0f4c859e951fba394238ab619495c4e1d54d0f34)
1*0f4c859eSApple OSS Distributions /*
2*0f4c859eSApple OSS Distributions  * Copyright (c) 2000-2019 Apple Inc. All rights reserved.
3*0f4c859eSApple OSS Distributions  *
4*0f4c859eSApple OSS Distributions  * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5*0f4c859eSApple OSS Distributions  *
6*0f4c859eSApple OSS Distributions  * This file contains Original Code and/or Modifications of Original Code
7*0f4c859eSApple OSS Distributions  * as defined in and that are subject to the Apple Public Source License
8*0f4c859eSApple OSS Distributions  * Version 2.0 (the 'License'). You may not use this file except in
9*0f4c859eSApple OSS Distributions  * compliance with the License. The rights granted to you under the License
10*0f4c859eSApple OSS Distributions  * may not be used to create, or enable the creation or redistribution of,
11*0f4c859eSApple OSS Distributions  * unlawful or unlicensed copies of an Apple operating system, or to
12*0f4c859eSApple OSS Distributions  * circumvent, violate, or enable the circumvention or violation of, any
13*0f4c859eSApple OSS Distributions  * terms of an Apple operating system software license agreement.
14*0f4c859eSApple OSS Distributions  *
15*0f4c859eSApple OSS Distributions  * Please obtain a copy of the License at
16*0f4c859eSApple OSS Distributions  * http://www.opensource.apple.com/apsl/ and read it before using this file.
17*0f4c859eSApple OSS Distributions  *
18*0f4c859eSApple OSS Distributions  * The Original Code and all software distributed under the License are
19*0f4c859eSApple OSS Distributions  * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20*0f4c859eSApple OSS Distributions  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21*0f4c859eSApple OSS Distributions  * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22*0f4c859eSApple OSS Distributions  * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23*0f4c859eSApple OSS Distributions  * Please see the License for the specific language governing rights and
24*0f4c859eSApple OSS Distributions  * limitations under the License.
25*0f4c859eSApple OSS Distributions  *
26*0f4c859eSApple OSS Distributions  * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27*0f4c859eSApple OSS Distributions  */
28*0f4c859eSApple OSS Distributions /*	$NetBSD: sysv_shm.c,v 1.23 1994/07/04 23:25:12 glass Exp $	*/
29*0f4c859eSApple OSS Distributions 
30*0f4c859eSApple OSS Distributions /*
31*0f4c859eSApple OSS Distributions  * Copyright (c) 1994 Adam Glass and Charles Hannum.  All rights reserved.
32*0f4c859eSApple OSS Distributions  *
33*0f4c859eSApple OSS Distributions  * Redistribution and use in source and binary forms, with or without
34*0f4c859eSApple OSS Distributions  * modification, are permitted provided that the following conditions
35*0f4c859eSApple OSS Distributions  * are met:
36*0f4c859eSApple OSS Distributions  * 1. Redistributions of source code must retain the above copyright
37*0f4c859eSApple OSS Distributions  *    notice, this list of conditions and the following disclaimer.
38*0f4c859eSApple OSS Distributions  * 2. Redistributions in binary form must reproduce the above copyright
39*0f4c859eSApple OSS Distributions  *    notice, this list of conditions and the following disclaimer in the
40*0f4c859eSApple OSS Distributions  *    documentation and/or other materials provided with the distribution.
41*0f4c859eSApple OSS Distributions  * 3. All advertising materials mentioning features or use of this software
42*0f4c859eSApple OSS Distributions  *    must display the following acknowledgement:
43*0f4c859eSApple OSS Distributions  *	This product includes software developed by Adam Glass and Charles
44*0f4c859eSApple OSS Distributions  *	Hannum.
45*0f4c859eSApple OSS Distributions  * 4. The names of the authors may not be used to endorse or promote products
46*0f4c859eSApple OSS Distributions  *    derived from this software without specific prior written permission.
47*0f4c859eSApple OSS Distributions  *
48*0f4c859eSApple OSS Distributions  * THIS SOFTWARE IS PROVIDED BY THE AUTHORS ``AS IS'' AND ANY EXPRESS OR
49*0f4c859eSApple OSS Distributions  * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
50*0f4c859eSApple OSS Distributions  * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
51*0f4c859eSApple OSS Distributions  * IN NO EVENT SHALL THE AUTHORS BE LIABLE FOR ANY DIRECT, INDIRECT,
52*0f4c859eSApple OSS Distributions  * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
53*0f4c859eSApple OSS Distributions  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
54*0f4c859eSApple OSS Distributions  * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
55*0f4c859eSApple OSS Distributions  * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
56*0f4c859eSApple OSS Distributions  * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
57*0f4c859eSApple OSS Distributions  * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
58*0f4c859eSApple OSS Distributions  */
59*0f4c859eSApple OSS Distributions /*
60*0f4c859eSApple OSS Distributions  * NOTICE: This file was modified by McAfee Research in 2004 to introduce
61*0f4c859eSApple OSS Distributions  * support for mandatory and extensible security protections.  This notice
62*0f4c859eSApple OSS Distributions  * is included in support of clause 2.2 (b) of the Apple Public License,
63*0f4c859eSApple OSS Distributions  * Version 2.0.
64*0f4c859eSApple OSS Distributions  * Copyright (c) 2005-2006 SPARTA, Inc.
65*0f4c859eSApple OSS Distributions  */
66*0f4c859eSApple OSS Distributions 
67*0f4c859eSApple OSS Distributions 
68*0f4c859eSApple OSS Distributions #include <sys/appleapiopts.h>
69*0f4c859eSApple OSS Distributions #include <sys/param.h>
70*0f4c859eSApple OSS Distributions #include <sys/systm.h>
71*0f4c859eSApple OSS Distributions #include <sys/kernel.h>
72*0f4c859eSApple OSS Distributions #include <sys/shm_internal.h>
73*0f4c859eSApple OSS Distributions #include <sys/proc_internal.h>
74*0f4c859eSApple OSS Distributions #include <sys/kauth.h>
75*0f4c859eSApple OSS Distributions #include <sys/malloc.h>
76*0f4c859eSApple OSS Distributions #include <sys/mman.h>
77*0f4c859eSApple OSS Distributions #include <sys/stat.h>
78*0f4c859eSApple OSS Distributions #include <sys/sysctl.h>
79*0f4c859eSApple OSS Distributions #include <sys/ipcs.h>
80*0f4c859eSApple OSS Distributions #include <sys/sysent.h>
81*0f4c859eSApple OSS Distributions #include <sys/sysproto.h>
82*0f4c859eSApple OSS Distributions #if CONFIG_MACF
83*0f4c859eSApple OSS Distributions #include <security/mac_framework.h>
84*0f4c859eSApple OSS Distributions #endif
85*0f4c859eSApple OSS Distributions 
86*0f4c859eSApple OSS Distributions #include <security/audit/audit.h>
87*0f4c859eSApple OSS Distributions 
88*0f4c859eSApple OSS Distributions #include <mach/mach_types.h>
89*0f4c859eSApple OSS Distributions #include <mach/vm_inherit.h>
90*0f4c859eSApple OSS Distributions #include <mach/vm_map.h>
91*0f4c859eSApple OSS Distributions 
92*0f4c859eSApple OSS Distributions #include <mach/mach_vm.h>
93*0f4c859eSApple OSS Distributions 
94*0f4c859eSApple OSS Distributions #include <vm/vm_map.h>
95*0f4c859eSApple OSS Distributions #include <vm/vm_protos.h>
96*0f4c859eSApple OSS Distributions #include <vm/vm_kern.h>
97*0f4c859eSApple OSS Distributions 
98*0f4c859eSApple OSS Distributions #include <kern/locks.h>
99*0f4c859eSApple OSS Distributions #include <os/overflow.h>
100*0f4c859eSApple OSS Distributions 
101*0f4c859eSApple OSS Distributions /* Uncomment this line to see MAC debugging output. */
102*0f4c859eSApple OSS Distributions /* #define MAC_DEBUG */
103*0f4c859eSApple OSS Distributions #if CONFIG_MACF_DEBUG
104*0f4c859eSApple OSS Distributions #define MPRINTF(a)      printf a
105*0f4c859eSApple OSS Distributions #else
106*0f4c859eSApple OSS Distributions #define MPRINTF(a)
107*0f4c859eSApple OSS Distributions #endif
108*0f4c859eSApple OSS Distributions 
109*0f4c859eSApple OSS Distributions #if SYSV_SHM
110*0f4c859eSApple OSS Distributions static int shminit(void);
111*0f4c859eSApple OSS Distributions 
112*0f4c859eSApple OSS Distributions static LCK_GRP_DECLARE(sysv_shm_subsys_lck_grp, "sysv_shm_subsys_lock");
113*0f4c859eSApple OSS Distributions static LCK_MTX_DECLARE(sysv_shm_subsys_mutex, &sysv_shm_subsys_lck_grp);
114*0f4c859eSApple OSS Distributions 
115*0f4c859eSApple OSS Distributions #define SYSV_SHM_SUBSYS_LOCK() lck_mtx_lock(&sysv_shm_subsys_mutex)
116*0f4c859eSApple OSS Distributions #define SYSV_SHM_SUBSYS_UNLOCK() lck_mtx_unlock(&sysv_shm_subsys_mutex)
117*0f4c859eSApple OSS Distributions 
118*0f4c859eSApple OSS Distributions static int oshmctl(void *p, void *uap, void *retval);
119*0f4c859eSApple OSS Distributions static int shmget_allocate_segment(struct proc *p, struct shmget_args *uap, int mode, int * retval);
120*0f4c859eSApple OSS Distributions static int shmget_existing(struct shmget_args *uap, int mode, int segnum, int  * retval);
121*0f4c859eSApple OSS Distributions static void shmid_ds_64to32(struct user_shmid_ds *in, struct user32_shmid_ds *out);
122*0f4c859eSApple OSS Distributions static void shmid_ds_32to64(struct user32_shmid_ds *in, struct user_shmid_ds *out);
123*0f4c859eSApple OSS Distributions 
124*0f4c859eSApple OSS Distributions /* XXX casting to (sy_call_t *) is bogus, as usual. */
125*0f4c859eSApple OSS Distributions static sy_call_t* const shmcalls[] = {
126*0f4c859eSApple OSS Distributions 	(sy_call_t *)shmat, (sy_call_t *)oshmctl,
127*0f4c859eSApple OSS Distributions 	(sy_call_t *)shmdt, (sy_call_t *)shmget,
128*0f4c859eSApple OSS Distributions 	(sy_call_t *)shmctl
129*0f4c859eSApple OSS Distributions };
130*0f4c859eSApple OSS Distributions 
131*0f4c859eSApple OSS Distributions #define SHMSEG_FREE             0x0200
132*0f4c859eSApple OSS Distributions #define SHMSEG_REMOVED          0x0400
133*0f4c859eSApple OSS Distributions #define SHMSEG_ALLOCATED        0x0800
134*0f4c859eSApple OSS Distributions #define SHMSEG_WANTED           0x1000
135*0f4c859eSApple OSS Distributions 
136*0f4c859eSApple OSS Distributions static int shm_last_free, shm_nused, shm_committed;
137*0f4c859eSApple OSS Distributions struct shmid_kernel     *shmsegs;       /* 64 bit version */
138*0f4c859eSApple OSS Distributions static int shm_inited = 0;
139*0f4c859eSApple OSS Distributions 
140*0f4c859eSApple OSS Distributions /*
141*0f4c859eSApple OSS Distributions  * Since anonymous memory chunks are limited to ANON_MAX_SIZE bytes,
142*0f4c859eSApple OSS Distributions  * we have to keep a list of chunks when we want to handle a shared memory
143*0f4c859eSApple OSS Distributions  * segment bigger than ANON_MAX_SIZE.
144*0f4c859eSApple OSS Distributions  * Each chunk points to a VM named entry of up to ANON_MAX_SIZE bytes
145*0f4c859eSApple OSS Distributions  * of anonymous memory.
146*0f4c859eSApple OSS Distributions  */
147*0f4c859eSApple OSS Distributions struct shm_handle {
148*0f4c859eSApple OSS Distributions 	void * shm_object;                      /* named entry for this chunk*/
149*0f4c859eSApple OSS Distributions 	memory_object_size_t shm_handle_size;   /* size of this chunk */
150*0f4c859eSApple OSS Distributions 	struct shm_handle *shm_handle_next;     /* next chunk */
151*0f4c859eSApple OSS Distributions };
152*0f4c859eSApple OSS Distributions 
153*0f4c859eSApple OSS Distributions struct shmmap_state {
154*0f4c859eSApple OSS Distributions 	mach_vm_address_t va;           /* user address */
155*0f4c859eSApple OSS Distributions 	int shmid;                      /* segment id */
156*0f4c859eSApple OSS Distributions };
157*0f4c859eSApple OSS Distributions 
158*0f4c859eSApple OSS Distributions static void shm_deallocate_segment(struct shmid_kernel *);
159*0f4c859eSApple OSS Distributions static int shm_find_segment_by_key(key_t);
160*0f4c859eSApple OSS Distributions static struct shmid_kernel *shm_find_segment_by_shmid(int);
161*0f4c859eSApple OSS Distributions static int shm_delete_mapping(struct proc *, struct shmmap_state *, int);
162*0f4c859eSApple OSS Distributions 
163*0f4c859eSApple OSS Distributions #ifdef __APPLE_API_PRIVATE
164*0f4c859eSApple OSS Distributions #define DEFAULT_SHMMAX  (4 * 1024 * 1024)
165*0f4c859eSApple OSS Distributions #define DEFAULT_SHMMIN  1
166*0f4c859eSApple OSS Distributions #define DEFAULT_SHMMNI  32
167*0f4c859eSApple OSS Distributions #define DEFAULT_SHMSEG  8
168*0f4c859eSApple OSS Distributions #define DEFAULT_SHMALL  1024
169*0f4c859eSApple OSS Distributions 
170*0f4c859eSApple OSS Distributions struct shminfo shminfo = {
171*0f4c859eSApple OSS Distributions 	.shmmax = DEFAULT_SHMMAX,
172*0f4c859eSApple OSS Distributions 	.shmmin = DEFAULT_SHMMIN,
173*0f4c859eSApple OSS Distributions 	.shmmni = DEFAULT_SHMMNI,
174*0f4c859eSApple OSS Distributions 	.shmseg = DEFAULT_SHMSEG,
175*0f4c859eSApple OSS Distributions 	.shmall = DEFAULT_SHMALL
176*0f4c859eSApple OSS Distributions };
177*0f4c859eSApple OSS Distributions 
178*0f4c859eSApple OSS Distributions #define SHMID_IS_VALID(x) ((x) >= 0)
179*0f4c859eSApple OSS Distributions #define SHMID_UNALLOCATED (-1)
180*0f4c859eSApple OSS Distributions #define SHMID_SENTINEL    (-2)
181*0f4c859eSApple OSS Distributions 
182*0f4c859eSApple OSS Distributions #endif /* __APPLE_API_PRIVATE */
183*0f4c859eSApple OSS Distributions 
184*0f4c859eSApple OSS Distributions static __inline__ time_t
sysv_shmtime(void)185*0f4c859eSApple OSS Distributions sysv_shmtime(void)
186*0f4c859eSApple OSS Distributions {
187*0f4c859eSApple OSS Distributions 	struct timeval  tv;
188*0f4c859eSApple OSS Distributions 	microtime(&tv);
189*0f4c859eSApple OSS Distributions 	return tv.tv_sec;
190*0f4c859eSApple OSS Distributions }
191*0f4c859eSApple OSS Distributions 
192*0f4c859eSApple OSS Distributions /*
193*0f4c859eSApple OSS Distributions  * This conversion is safe, since if we are converting for a 32 bit process,
194*0f4c859eSApple OSS Distributions  * then it's value of (struct shmid_ds)->shm_segsz will never exceed 4G.
195*0f4c859eSApple OSS Distributions  *
196*0f4c859eSApple OSS Distributions  * NOTE: Source and target may *NOT* overlap! (target is smaller)
197*0f4c859eSApple OSS Distributions  */
198*0f4c859eSApple OSS Distributions static void
shmid_ds_64to32(struct user_shmid_ds * in,struct user32_shmid_ds * out)199*0f4c859eSApple OSS Distributions shmid_ds_64to32(struct user_shmid_ds *in, struct user32_shmid_ds *out)
200*0f4c859eSApple OSS Distributions {
201*0f4c859eSApple OSS Distributions 	out->shm_perm = in->shm_perm;
202*0f4c859eSApple OSS Distributions 	out->shm_segsz = in->shm_segsz;
203*0f4c859eSApple OSS Distributions 	out->shm_lpid = in->shm_lpid;
204*0f4c859eSApple OSS Distributions 	out->shm_cpid = in->shm_cpid;
205*0f4c859eSApple OSS Distributions 	out->shm_nattch = in->shm_nattch;
206*0f4c859eSApple OSS Distributions 	out->shm_atime = in->shm_atime;
207*0f4c859eSApple OSS Distributions 	out->shm_dtime = in->shm_dtime;
208*0f4c859eSApple OSS Distributions 	out->shm_ctime = in->shm_ctime;
209*0f4c859eSApple OSS Distributions 	out->shm_internal = CAST_DOWN_EXPLICIT(int, in->shm_internal);
210*0f4c859eSApple OSS Distributions }
211*0f4c859eSApple OSS Distributions 
212*0f4c859eSApple OSS Distributions /*
213*0f4c859eSApple OSS Distributions  * NOTE: Source and target may are permitted to overlap! (source is smaller);
214*0f4c859eSApple OSS Distributions  * this works because we copy fields in order from the end of the struct to
215*0f4c859eSApple OSS Distributions  * the beginning.
216*0f4c859eSApple OSS Distributions  */
217*0f4c859eSApple OSS Distributions static void
shmid_ds_32to64(struct user32_shmid_ds * in,struct user_shmid_ds * out)218*0f4c859eSApple OSS Distributions shmid_ds_32to64(struct user32_shmid_ds *in, struct user_shmid_ds *out)
219*0f4c859eSApple OSS Distributions {
220*0f4c859eSApple OSS Distributions 	out->shm_internal = in->shm_internal;
221*0f4c859eSApple OSS Distributions 	out->shm_ctime = in->shm_ctime;
222*0f4c859eSApple OSS Distributions 	out->shm_dtime = in->shm_dtime;
223*0f4c859eSApple OSS Distributions 	out->shm_atime = in->shm_atime;
224*0f4c859eSApple OSS Distributions 	out->shm_nattch = in->shm_nattch;
225*0f4c859eSApple OSS Distributions 	out->shm_cpid = in->shm_cpid;
226*0f4c859eSApple OSS Distributions 	out->shm_lpid = in->shm_lpid;
227*0f4c859eSApple OSS Distributions 	out->shm_segsz = in->shm_segsz;
228*0f4c859eSApple OSS Distributions 	out->shm_perm = in->shm_perm;
229*0f4c859eSApple OSS Distributions }
230*0f4c859eSApple OSS Distributions 
231*0f4c859eSApple OSS Distributions 
232*0f4c859eSApple OSS Distributions static int
shm_find_segment_by_key(key_t key)233*0f4c859eSApple OSS Distributions shm_find_segment_by_key(key_t key)
234*0f4c859eSApple OSS Distributions {
235*0f4c859eSApple OSS Distributions 	int i;
236*0f4c859eSApple OSS Distributions 
237*0f4c859eSApple OSS Distributions 	for (i = 0; i < shminfo.shmmni; i++) {
238*0f4c859eSApple OSS Distributions 		if ((shmsegs[i].u.shm_perm.mode & SHMSEG_ALLOCATED) &&
239*0f4c859eSApple OSS Distributions 		    shmsegs[i].u.shm_perm._key == key) {
240*0f4c859eSApple OSS Distributions 			return i;
241*0f4c859eSApple OSS Distributions 		}
242*0f4c859eSApple OSS Distributions 	}
243*0f4c859eSApple OSS Distributions 	return -1;
244*0f4c859eSApple OSS Distributions }
245*0f4c859eSApple OSS Distributions 
246*0f4c859eSApple OSS Distributions static struct shmid_kernel *
shm_find_segment_by_shmid(int shmid)247*0f4c859eSApple OSS Distributions shm_find_segment_by_shmid(int shmid)
248*0f4c859eSApple OSS Distributions {
249*0f4c859eSApple OSS Distributions 	int segnum;
250*0f4c859eSApple OSS Distributions 	struct shmid_kernel *shmseg;
251*0f4c859eSApple OSS Distributions 
252*0f4c859eSApple OSS Distributions 	segnum = IPCID_TO_IX(shmid);
253*0f4c859eSApple OSS Distributions 	if (segnum < 0 || segnum >= shminfo.shmmni) {
254*0f4c859eSApple OSS Distributions 		return NULL;
255*0f4c859eSApple OSS Distributions 	}
256*0f4c859eSApple OSS Distributions 	shmseg = &shmsegs[segnum];
257*0f4c859eSApple OSS Distributions 	if ((shmseg->u.shm_perm.mode & (SHMSEG_ALLOCATED | SHMSEG_REMOVED))
258*0f4c859eSApple OSS Distributions 	    != SHMSEG_ALLOCATED ||
259*0f4c859eSApple OSS Distributions 	    shmseg->u.shm_perm._seq != IPCID_TO_SEQ(shmid)) {
260*0f4c859eSApple OSS Distributions 		return NULL;
261*0f4c859eSApple OSS Distributions 	}
262*0f4c859eSApple OSS Distributions 	return shmseg;
263*0f4c859eSApple OSS Distributions }
264*0f4c859eSApple OSS Distributions 
265*0f4c859eSApple OSS Distributions static void
shm_deallocate_segment(struct shmid_kernel * shmseg)266*0f4c859eSApple OSS Distributions shm_deallocate_segment(struct shmid_kernel *shmseg)
267*0f4c859eSApple OSS Distributions {
268*0f4c859eSApple OSS Distributions 	struct shm_handle *shm_handle, *shm_handle_next;
269*0f4c859eSApple OSS Distributions 	mach_vm_size_t size;
270*0f4c859eSApple OSS Distributions 
271*0f4c859eSApple OSS Distributions 	for (shm_handle = CAST_DOWN(void *, shmseg->u.shm_internal); /* tunnel */
272*0f4c859eSApple OSS Distributions 	    shm_handle != NULL;
273*0f4c859eSApple OSS Distributions 	    shm_handle = shm_handle_next) {
274*0f4c859eSApple OSS Distributions 		shm_handle_next = shm_handle->shm_handle_next;
275*0f4c859eSApple OSS Distributions 		mach_memory_entry_port_release(shm_handle->shm_object);
276*0f4c859eSApple OSS Distributions 		kfree_type(struct shm_handle, shm_handle);
277*0f4c859eSApple OSS Distributions 	}
278*0f4c859eSApple OSS Distributions 	shmseg->u.shm_internal = USER_ADDR_NULL;                /* tunnel */
279*0f4c859eSApple OSS Distributions 	size = vm_map_round_page(shmseg->u.shm_segsz,
280*0f4c859eSApple OSS Distributions 	    vm_map_page_mask(current_map()));
281*0f4c859eSApple OSS Distributions 	shm_committed -= btoc(size);
282*0f4c859eSApple OSS Distributions 	shm_nused--;
283*0f4c859eSApple OSS Distributions 	shmseg->u.shm_perm.mode = SHMSEG_FREE;
284*0f4c859eSApple OSS Distributions #if CONFIG_MACF
285*0f4c859eSApple OSS Distributions 	/* Reset the MAC label */
286*0f4c859eSApple OSS Distributions 	mac_sysvshm_label_recycle(shmseg);
287*0f4c859eSApple OSS Distributions #endif
288*0f4c859eSApple OSS Distributions }
289*0f4c859eSApple OSS Distributions 
290*0f4c859eSApple OSS Distributions static int
shm_delete_mapping(__unused struct proc * p,struct shmmap_state * shmmap_s,int deallocate)291*0f4c859eSApple OSS Distributions shm_delete_mapping(__unused struct proc *p, struct shmmap_state *shmmap_s,
292*0f4c859eSApple OSS Distributions     int deallocate)
293*0f4c859eSApple OSS Distributions {
294*0f4c859eSApple OSS Distributions 	struct shmid_kernel *shmseg;
295*0f4c859eSApple OSS Distributions 	int segnum, result;
296*0f4c859eSApple OSS Distributions 	mach_vm_size_t size;
297*0f4c859eSApple OSS Distributions 
298*0f4c859eSApple OSS Distributions 	segnum = IPCID_TO_IX(shmmap_s->shmid);
299*0f4c859eSApple OSS Distributions 	shmseg = &shmsegs[segnum];
300*0f4c859eSApple OSS Distributions 	size = vm_map_round_page(shmseg->u.shm_segsz,
301*0f4c859eSApple OSS Distributions 	    vm_map_page_mask(current_map())); /* XXX done for us? */
302*0f4c859eSApple OSS Distributions 	if (deallocate) {
303*0f4c859eSApple OSS Distributions 		result = mach_vm_deallocate(current_map(), shmmap_s->va, size);
304*0f4c859eSApple OSS Distributions 		if (result != KERN_SUCCESS) {
305*0f4c859eSApple OSS Distributions 			return EINVAL;
306*0f4c859eSApple OSS Distributions 		}
307*0f4c859eSApple OSS Distributions 	}
308*0f4c859eSApple OSS Distributions 	shmmap_s->shmid = SHMID_UNALLOCATED;
309*0f4c859eSApple OSS Distributions 	shmseg->u.shm_dtime = sysv_shmtime();
310*0f4c859eSApple OSS Distributions 	if ((--shmseg->u.shm_nattch <= 0) &&
311*0f4c859eSApple OSS Distributions 	    (shmseg->u.shm_perm.mode & SHMSEG_REMOVED)) {
312*0f4c859eSApple OSS Distributions 		shm_deallocate_segment(shmseg);
313*0f4c859eSApple OSS Distributions 		shm_last_free = segnum;
314*0f4c859eSApple OSS Distributions 	}
315*0f4c859eSApple OSS Distributions 	return 0;
316*0f4c859eSApple OSS Distributions }
317*0f4c859eSApple OSS Distributions 
318*0f4c859eSApple OSS Distributions int
shmdt(struct proc * p,struct shmdt_args * uap,int32_t * retval)319*0f4c859eSApple OSS Distributions shmdt(struct proc *p, struct shmdt_args *uap, int32_t *retval)
320*0f4c859eSApple OSS Distributions {
321*0f4c859eSApple OSS Distributions #if CONFIG_MACF
322*0f4c859eSApple OSS Distributions 	struct shmid_kernel *shmsegptr;
323*0f4c859eSApple OSS Distributions #endif
324*0f4c859eSApple OSS Distributions 	struct shmmap_state *shmmap_s;
325*0f4c859eSApple OSS Distributions 	int i;
326*0f4c859eSApple OSS Distributions 	int shmdtret = 0;
327*0f4c859eSApple OSS Distributions 
328*0f4c859eSApple OSS Distributions 	AUDIT_ARG(svipc_addr, uap->shmaddr);
329*0f4c859eSApple OSS Distributions 
330*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_LOCK();
331*0f4c859eSApple OSS Distributions 
332*0f4c859eSApple OSS Distributions 	if ((shmdtret = shminit())) {
333*0f4c859eSApple OSS Distributions 		goto shmdt_out;
334*0f4c859eSApple OSS Distributions 	}
335*0f4c859eSApple OSS Distributions 
336*0f4c859eSApple OSS Distributions 	shmmap_s = (struct shmmap_state *)p->vm_shm;
337*0f4c859eSApple OSS Distributions 	if (shmmap_s == NULL) {
338*0f4c859eSApple OSS Distributions 		shmdtret = EINVAL;
339*0f4c859eSApple OSS Distributions 		goto shmdt_out;
340*0f4c859eSApple OSS Distributions 	}
341*0f4c859eSApple OSS Distributions 
342*0f4c859eSApple OSS Distributions 	for (; shmmap_s->shmid != SHMID_SENTINEL; shmmap_s++) {
343*0f4c859eSApple OSS Distributions 		if (SHMID_IS_VALID(shmmap_s->shmid) &&
344*0f4c859eSApple OSS Distributions 		    shmmap_s->va == (mach_vm_offset_t)uap->shmaddr) {
345*0f4c859eSApple OSS Distributions 			break;
346*0f4c859eSApple OSS Distributions 		}
347*0f4c859eSApple OSS Distributions 	}
348*0f4c859eSApple OSS Distributions 
349*0f4c859eSApple OSS Distributions 	if (!SHMID_IS_VALID(shmmap_s->shmid)) {
350*0f4c859eSApple OSS Distributions 		shmdtret = EINVAL;
351*0f4c859eSApple OSS Distributions 		goto shmdt_out;
352*0f4c859eSApple OSS Distributions 	}
353*0f4c859eSApple OSS Distributions 
354*0f4c859eSApple OSS Distributions #if CONFIG_MACF
355*0f4c859eSApple OSS Distributions 	/*
356*0f4c859eSApple OSS Distributions 	 * XXX: It might be useful to move this into the shm_delete_mapping
357*0f4c859eSApple OSS Distributions 	 * function
358*0f4c859eSApple OSS Distributions 	 */
359*0f4c859eSApple OSS Distributions 	shmsegptr = &shmsegs[IPCID_TO_IX(shmmap_s->shmid)];
360*0f4c859eSApple OSS Distributions 	shmdtret = mac_sysvshm_check_shmdt(kauth_cred_get(), shmsegptr);
361*0f4c859eSApple OSS Distributions 	if (shmdtret) {
362*0f4c859eSApple OSS Distributions 		goto shmdt_out;
363*0f4c859eSApple OSS Distributions 	}
364*0f4c859eSApple OSS Distributions #endif
365*0f4c859eSApple OSS Distributions 	i = shm_delete_mapping(p, shmmap_s, 1);
366*0f4c859eSApple OSS Distributions 
367*0f4c859eSApple OSS Distributions 	if (i == 0) {
368*0f4c859eSApple OSS Distributions 		*retval = 0;
369*0f4c859eSApple OSS Distributions 	}
370*0f4c859eSApple OSS Distributions 	shmdtret = i;
371*0f4c859eSApple OSS Distributions shmdt_out:
372*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_UNLOCK();
373*0f4c859eSApple OSS Distributions 	return shmdtret;
374*0f4c859eSApple OSS Distributions }
375*0f4c859eSApple OSS Distributions 
376*0f4c859eSApple OSS Distributions int
shmat(struct proc * p,struct shmat_args * uap,user_addr_t * retval)377*0f4c859eSApple OSS Distributions shmat(struct proc *p, struct shmat_args *uap, user_addr_t *retval)
378*0f4c859eSApple OSS Distributions {
379*0f4c859eSApple OSS Distributions 	int error, flags;
380*0f4c859eSApple OSS Distributions 	struct shmid_kernel     *shmseg;
381*0f4c859eSApple OSS Distributions 	struct shmmap_state     *shmmap_s = NULL;
382*0f4c859eSApple OSS Distributions 	struct shm_handle       *shm_handle;
383*0f4c859eSApple OSS Distributions 	mach_vm_address_t       attach_va;      /* attach address in/out */
384*0f4c859eSApple OSS Distributions 	mach_vm_address_t       shmlba;
385*0f4c859eSApple OSS Distributions 	mach_vm_size_t          map_size;       /* size of map entry */
386*0f4c859eSApple OSS Distributions 	mach_vm_size_t          mapped_size;
387*0f4c859eSApple OSS Distributions 	vm_prot_t               prot;
388*0f4c859eSApple OSS Distributions 	kern_return_t           rv;
389*0f4c859eSApple OSS Distributions 	int                     shmat_ret;
390*0f4c859eSApple OSS Distributions 	vm_map_kernel_flags_t   vmk_flags;
391*0f4c859eSApple OSS Distributions 
392*0f4c859eSApple OSS Distributions 	shmat_ret = 0;
393*0f4c859eSApple OSS Distributions 
394*0f4c859eSApple OSS Distributions 	AUDIT_ARG(svipc_id, uap->shmid);
395*0f4c859eSApple OSS Distributions 	AUDIT_ARG(svipc_addr, uap->shmaddr);
396*0f4c859eSApple OSS Distributions 
397*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_LOCK();
398*0f4c859eSApple OSS Distributions 
399*0f4c859eSApple OSS Distributions 	if ((shmat_ret = shminit())) {
400*0f4c859eSApple OSS Distributions 		goto shmat_out;
401*0f4c859eSApple OSS Distributions 	}
402*0f4c859eSApple OSS Distributions 
403*0f4c859eSApple OSS Distributions 	shmmap_s = (struct shmmap_state *)p->vm_shm;
404*0f4c859eSApple OSS Distributions 	if (shmmap_s == NULL) {
405*0f4c859eSApple OSS Distributions 		/* lazily allocate the shm map */
406*0f4c859eSApple OSS Distributions 
407*0f4c859eSApple OSS Distributions 		int nsegs = shminfo.shmseg;
408*0f4c859eSApple OSS Distributions 		if (nsegs <= 0) {
409*0f4c859eSApple OSS Distributions 			shmat_ret = EMFILE;
410*0f4c859eSApple OSS Distributions 			goto shmat_out;
411*0f4c859eSApple OSS Distributions 		}
412*0f4c859eSApple OSS Distributions 
413*0f4c859eSApple OSS Distributions 		/* +1 for the sentinel */
414*0f4c859eSApple OSS Distributions 		shmmap_s = kalloc_type(struct shmmap_state, nsegs + 1, Z_WAITOK);
415*0f4c859eSApple OSS Distributions 		if (shmmap_s == NULL) {
416*0f4c859eSApple OSS Distributions 			shmat_ret = ENOMEM;
417*0f4c859eSApple OSS Distributions 			goto shmat_out;
418*0f4c859eSApple OSS Distributions 		}
419*0f4c859eSApple OSS Distributions 
420*0f4c859eSApple OSS Distributions 		/* initialize the entries */
421*0f4c859eSApple OSS Distributions 		for (int i = 0; i < nsegs; i++) {
422*0f4c859eSApple OSS Distributions 			shmmap_s[i].shmid = SHMID_UNALLOCATED;
423*0f4c859eSApple OSS Distributions 		}
424*0f4c859eSApple OSS Distributions 		shmmap_s[nsegs].shmid = SHMID_SENTINEL;
425*0f4c859eSApple OSS Distributions 
426*0f4c859eSApple OSS Distributions 		p->vm_shm = (caddr_t)shmmap_s;
427*0f4c859eSApple OSS Distributions 	}
428*0f4c859eSApple OSS Distributions 
429*0f4c859eSApple OSS Distributions 	shmseg = shm_find_segment_by_shmid(uap->shmid);
430*0f4c859eSApple OSS Distributions 	if (shmseg == NULL) {
431*0f4c859eSApple OSS Distributions 		shmat_ret = EINVAL;
432*0f4c859eSApple OSS Distributions 		goto shmat_out;
433*0f4c859eSApple OSS Distributions 	}
434*0f4c859eSApple OSS Distributions 
435*0f4c859eSApple OSS Distributions 	AUDIT_ARG(svipc_perm, &shmseg->u.shm_perm);
436*0f4c859eSApple OSS Distributions 	error = ipcperm(kauth_cred_get(), &shmseg->u.shm_perm,
437*0f4c859eSApple OSS Distributions 	    (uap->shmflg & SHM_RDONLY) ? IPC_R : IPC_R | IPC_W);
438*0f4c859eSApple OSS Distributions 	if (error) {
439*0f4c859eSApple OSS Distributions 		shmat_ret = error;
440*0f4c859eSApple OSS Distributions 		goto shmat_out;
441*0f4c859eSApple OSS Distributions 	}
442*0f4c859eSApple OSS Distributions 
443*0f4c859eSApple OSS Distributions #if CONFIG_MACF
444*0f4c859eSApple OSS Distributions 	error = mac_sysvshm_check_shmat(kauth_cred_get(), shmseg, uap->shmflg);
445*0f4c859eSApple OSS Distributions 	if (error) {
446*0f4c859eSApple OSS Distributions 		shmat_ret = error;
447*0f4c859eSApple OSS Distributions 		goto shmat_out;
448*0f4c859eSApple OSS Distributions 	}
449*0f4c859eSApple OSS Distributions #endif
450*0f4c859eSApple OSS Distributions 
451*0f4c859eSApple OSS Distributions 	/* find a free shmid */
452*0f4c859eSApple OSS Distributions 	while (SHMID_IS_VALID(shmmap_s->shmid)) {
453*0f4c859eSApple OSS Distributions 		shmmap_s++;
454*0f4c859eSApple OSS Distributions 	}
455*0f4c859eSApple OSS Distributions 	if (shmmap_s->shmid != SHMID_UNALLOCATED) {
456*0f4c859eSApple OSS Distributions 		/* no free shmids */
457*0f4c859eSApple OSS Distributions 		shmat_ret = EMFILE;
458*0f4c859eSApple OSS Distributions 		goto shmat_out;
459*0f4c859eSApple OSS Distributions 	}
460*0f4c859eSApple OSS Distributions 
461*0f4c859eSApple OSS Distributions 	map_size = vm_map_round_page(shmseg->u.shm_segsz,
462*0f4c859eSApple OSS Distributions 	    vm_map_page_mask(current_map()));
463*0f4c859eSApple OSS Distributions 	prot = VM_PROT_READ;
464*0f4c859eSApple OSS Distributions 	if ((uap->shmflg & SHM_RDONLY) == 0) {
465*0f4c859eSApple OSS Distributions 		prot |= VM_PROT_WRITE;
466*0f4c859eSApple OSS Distributions 	}
467*0f4c859eSApple OSS Distributions 	flags = MAP_ANON | MAP_SHARED;
468*0f4c859eSApple OSS Distributions 	if (uap->shmaddr) {
469*0f4c859eSApple OSS Distributions 		flags |= MAP_FIXED;
470*0f4c859eSApple OSS Distributions 	}
471*0f4c859eSApple OSS Distributions 
472*0f4c859eSApple OSS Distributions 	attach_va = (mach_vm_address_t)uap->shmaddr;
473*0f4c859eSApple OSS Distributions 	shmlba = vm_map_page_size(current_map()); /* XXX instead of SHMLBA */
474*0f4c859eSApple OSS Distributions 	if (uap->shmflg & SHM_RND) {
475*0f4c859eSApple OSS Distributions 		attach_va &= ~(shmlba - 1);
476*0f4c859eSApple OSS Distributions 	} else if ((attach_va & (shmlba - 1)) != 0) {
477*0f4c859eSApple OSS Distributions 		shmat_ret = EINVAL;
478*0f4c859eSApple OSS Distributions 		goto shmat_out;
479*0f4c859eSApple OSS Distributions 	}
480*0f4c859eSApple OSS Distributions 
481*0f4c859eSApple OSS Distributions 	if (flags & MAP_FIXED) {
482*0f4c859eSApple OSS Distributions 		vmk_flags = VM_MAP_KERNEL_FLAGS_FIXED();
483*0f4c859eSApple OSS Distributions 	} else {
484*0f4c859eSApple OSS Distributions 		vmk_flags = VM_MAP_KERNEL_FLAGS_ANYWHERE();
485*0f4c859eSApple OSS Distributions 	}
486*0f4c859eSApple OSS Distributions 
487*0f4c859eSApple OSS Distributions 	mapped_size = 0;
488*0f4c859eSApple OSS Distributions 
489*0f4c859eSApple OSS Distributions 	/* first reserve enough space... */
490*0f4c859eSApple OSS Distributions 	rv = mach_vm_map_kernel(current_map(),
491*0f4c859eSApple OSS Distributions 	    &attach_va,
492*0f4c859eSApple OSS Distributions 	    map_size,
493*0f4c859eSApple OSS Distributions 	    0,
494*0f4c859eSApple OSS Distributions 	    vmk_flags,
495*0f4c859eSApple OSS Distributions 	    IPC_PORT_NULL,
496*0f4c859eSApple OSS Distributions 	    0,
497*0f4c859eSApple OSS Distributions 	    FALSE,
498*0f4c859eSApple OSS Distributions 	    VM_PROT_NONE,
499*0f4c859eSApple OSS Distributions 	    VM_PROT_NONE,
500*0f4c859eSApple OSS Distributions 	    VM_INHERIT_NONE);
501*0f4c859eSApple OSS Distributions 	if (rv != KERN_SUCCESS) {
502*0f4c859eSApple OSS Distributions 		goto out;
503*0f4c859eSApple OSS Distributions 	}
504*0f4c859eSApple OSS Distributions 
505*0f4c859eSApple OSS Distributions 	shmmap_s->va = attach_va;
506*0f4c859eSApple OSS Distributions 
507*0f4c859eSApple OSS Distributions 	/* ... then map the shared memory over the reserved space */
508*0f4c859eSApple OSS Distributions 	for (shm_handle = CAST_DOWN(void *, shmseg->u.shm_internal);/* tunnel */
509*0f4c859eSApple OSS Distributions 	    shm_handle != NULL;
510*0f4c859eSApple OSS Distributions 	    shm_handle = shm_handle->shm_handle_next) {
511*0f4c859eSApple OSS Distributions 		vm_map_size_t chunk_size;
512*0f4c859eSApple OSS Distributions 
513*0f4c859eSApple OSS Distributions 		assert(mapped_size < map_size);
514*0f4c859eSApple OSS Distributions 		chunk_size = shm_handle->shm_handle_size;
515*0f4c859eSApple OSS Distributions 		if (chunk_size > map_size - mapped_size) {
516*0f4c859eSApple OSS Distributions 			/*
517*0f4c859eSApple OSS Distributions 			 * Partial mapping of last chunk due to
518*0f4c859eSApple OSS Distributions 			 * page size mismatch.
519*0f4c859eSApple OSS Distributions 			 */
520*0f4c859eSApple OSS Distributions 			assert(vm_map_page_shift(current_map()) < PAGE_SHIFT);
521*0f4c859eSApple OSS Distributions 			assert(shm_handle->shm_handle_next == NULL);
522*0f4c859eSApple OSS Distributions 			chunk_size = map_size - mapped_size;
523*0f4c859eSApple OSS Distributions 		}
524*0f4c859eSApple OSS Distributions 		rv = vm_map_enter_mem_object(
525*0f4c859eSApple OSS Distributions 			current_map(),          /* process map */
526*0f4c859eSApple OSS Distributions 			&attach_va,             /* attach address */
527*0f4c859eSApple OSS Distributions 			chunk_size,             /* size to map */
528*0f4c859eSApple OSS Distributions 			(mach_vm_offset_t)0,    /* alignment mask */
529*0f4c859eSApple OSS Distributions 			VM_MAP_KERNEL_FLAGS_FIXED(.vmf_overwrite = true),
530*0f4c859eSApple OSS Distributions 			shm_handle->shm_object,
531*0f4c859eSApple OSS Distributions 			(mach_vm_offset_t)0,
532*0f4c859eSApple OSS Distributions 			FALSE,
533*0f4c859eSApple OSS Distributions 			prot,
534*0f4c859eSApple OSS Distributions 			prot,
535*0f4c859eSApple OSS Distributions 			VM_INHERIT_SHARE);
536*0f4c859eSApple OSS Distributions 		if (rv != KERN_SUCCESS) {
537*0f4c859eSApple OSS Distributions 			goto out;
538*0f4c859eSApple OSS Distributions 		}
539*0f4c859eSApple OSS Distributions 
540*0f4c859eSApple OSS Distributions 		mapped_size += chunk_size;
541*0f4c859eSApple OSS Distributions 		attach_va = attach_va + chunk_size;
542*0f4c859eSApple OSS Distributions 	}
543*0f4c859eSApple OSS Distributions 
544*0f4c859eSApple OSS Distributions 	shmmap_s->shmid = uap->shmid;
545*0f4c859eSApple OSS Distributions 	shmseg->u.shm_lpid = proc_getpid(p);
546*0f4c859eSApple OSS Distributions 	shmseg->u.shm_atime = sysv_shmtime();
547*0f4c859eSApple OSS Distributions 	shmseg->u.shm_nattch++;
548*0f4c859eSApple OSS Distributions 	*retval = shmmap_s->va; /* XXX return -1 on error */
549*0f4c859eSApple OSS Distributions 	shmat_ret = 0;
550*0f4c859eSApple OSS Distributions 	goto shmat_out;
551*0f4c859eSApple OSS Distributions out:
552*0f4c859eSApple OSS Distributions 	if (mapped_size > 0) {
553*0f4c859eSApple OSS Distributions 		(void) mach_vm_deallocate(current_map(),
554*0f4c859eSApple OSS Distributions 		    shmmap_s->va,
555*0f4c859eSApple OSS Distributions 		    mapped_size);
556*0f4c859eSApple OSS Distributions 	}
557*0f4c859eSApple OSS Distributions 	switch (rv) {
558*0f4c859eSApple OSS Distributions 	case KERN_INVALID_ADDRESS:
559*0f4c859eSApple OSS Distributions 	case KERN_NO_SPACE:
560*0f4c859eSApple OSS Distributions 		shmat_ret = ENOMEM;
561*0f4c859eSApple OSS Distributions 		break;
562*0f4c859eSApple OSS Distributions 	case KERN_PROTECTION_FAILURE:
563*0f4c859eSApple OSS Distributions 		shmat_ret = EACCES;
564*0f4c859eSApple OSS Distributions 		break;
565*0f4c859eSApple OSS Distributions 	default:
566*0f4c859eSApple OSS Distributions 		shmat_ret = EINVAL;
567*0f4c859eSApple OSS Distributions 		break;
568*0f4c859eSApple OSS Distributions 	}
569*0f4c859eSApple OSS Distributions shmat_out:
570*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_UNLOCK();
571*0f4c859eSApple OSS Distributions 	return shmat_ret;
572*0f4c859eSApple OSS Distributions }
573*0f4c859eSApple OSS Distributions 
574*0f4c859eSApple OSS Distributions static int
oshmctl(__unused void * p,__unused void * uap,__unused void * retval)575*0f4c859eSApple OSS Distributions oshmctl(__unused void *p, __unused void *uap, __unused void *retval)
576*0f4c859eSApple OSS Distributions {
577*0f4c859eSApple OSS Distributions 	return EINVAL;
578*0f4c859eSApple OSS Distributions }
579*0f4c859eSApple OSS Distributions 
580*0f4c859eSApple OSS Distributions /*
581*0f4c859eSApple OSS Distributions  * Returns:	0			Success
582*0f4c859eSApple OSS Distributions  *		EINVAL
583*0f4c859eSApple OSS Distributions  *	copyout:EFAULT
584*0f4c859eSApple OSS Distributions  *	copyin:EFAULT
585*0f4c859eSApple OSS Distributions  *	ipcperm:EPERM
586*0f4c859eSApple OSS Distributions  *	ipcperm:EACCES
587*0f4c859eSApple OSS Distributions  */
588*0f4c859eSApple OSS Distributions int
shmctl(__unused struct proc * p,struct shmctl_args * uap,int32_t * retval)589*0f4c859eSApple OSS Distributions shmctl(__unused struct proc *p, struct shmctl_args *uap, int32_t *retval)
590*0f4c859eSApple OSS Distributions {
591*0f4c859eSApple OSS Distributions 	int error;
592*0f4c859eSApple OSS Distributions 	kauth_cred_t cred = kauth_cred_get();
593*0f4c859eSApple OSS Distributions 	struct user_shmid_ds inbuf;
594*0f4c859eSApple OSS Distributions 	struct shmid_kernel *shmseg;
595*0f4c859eSApple OSS Distributions 
596*0f4c859eSApple OSS Distributions 	int shmctl_ret = 0;
597*0f4c859eSApple OSS Distributions 
598*0f4c859eSApple OSS Distributions 	AUDIT_ARG(svipc_cmd, uap->cmd);
599*0f4c859eSApple OSS Distributions 	AUDIT_ARG(svipc_id, uap->shmid);
600*0f4c859eSApple OSS Distributions 
601*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_LOCK();
602*0f4c859eSApple OSS Distributions 
603*0f4c859eSApple OSS Distributions 	if ((shmctl_ret = shminit())) {
604*0f4c859eSApple OSS Distributions 		goto shmctl_out;
605*0f4c859eSApple OSS Distributions 	}
606*0f4c859eSApple OSS Distributions 
607*0f4c859eSApple OSS Distributions 	shmseg = shm_find_segment_by_shmid(uap->shmid);
608*0f4c859eSApple OSS Distributions 	if (shmseg == NULL) {
609*0f4c859eSApple OSS Distributions 		shmctl_ret = EINVAL;
610*0f4c859eSApple OSS Distributions 		goto shmctl_out;
611*0f4c859eSApple OSS Distributions 	}
612*0f4c859eSApple OSS Distributions 
613*0f4c859eSApple OSS Distributions 	/* XXAUDIT: This is the perms BEFORE any change by this call. This
614*0f4c859eSApple OSS Distributions 	 * may not be what is desired.
615*0f4c859eSApple OSS Distributions 	 */
616*0f4c859eSApple OSS Distributions 	AUDIT_ARG(svipc_perm, &shmseg->u.shm_perm);
617*0f4c859eSApple OSS Distributions 
618*0f4c859eSApple OSS Distributions #if CONFIG_MACF
619*0f4c859eSApple OSS Distributions 	error = mac_sysvshm_check_shmctl(cred, shmseg, uap->cmd);
620*0f4c859eSApple OSS Distributions 	if (error) {
621*0f4c859eSApple OSS Distributions 		shmctl_ret = error;
622*0f4c859eSApple OSS Distributions 		goto shmctl_out;
623*0f4c859eSApple OSS Distributions 	}
624*0f4c859eSApple OSS Distributions #endif
625*0f4c859eSApple OSS Distributions 	switch (uap->cmd) {
626*0f4c859eSApple OSS Distributions 	case IPC_STAT:
627*0f4c859eSApple OSS Distributions 		error = ipcperm(cred, &shmseg->u.shm_perm, IPC_R);
628*0f4c859eSApple OSS Distributions 		if (error) {
629*0f4c859eSApple OSS Distributions 			shmctl_ret = error;
630*0f4c859eSApple OSS Distributions 			goto shmctl_out;
631*0f4c859eSApple OSS Distributions 		}
632*0f4c859eSApple OSS Distributions 
633*0f4c859eSApple OSS Distributions 		if (IS_64BIT_PROCESS(p)) {
634*0f4c859eSApple OSS Distributions 			struct user_shmid_ds shmid_ds = {};
635*0f4c859eSApple OSS Distributions 			memcpy(&shmid_ds, &shmseg->u, sizeof(struct user_shmid_ds));
636*0f4c859eSApple OSS Distributions 
637*0f4c859eSApple OSS Distributions 			/* Clear kernel reserved pointer before copying to user space */
638*0f4c859eSApple OSS Distributions 			shmid_ds.shm_internal = USER_ADDR_NULL;
639*0f4c859eSApple OSS Distributions 
640*0f4c859eSApple OSS Distributions 			error = copyout(&shmid_ds, uap->buf, sizeof(shmid_ds));
641*0f4c859eSApple OSS Distributions 		} else {
642*0f4c859eSApple OSS Distributions 			struct user32_shmid_ds shmid_ds32 = {};
643*0f4c859eSApple OSS Distributions 			shmid_ds_64to32(&shmseg->u, &shmid_ds32);
644*0f4c859eSApple OSS Distributions 
645*0f4c859eSApple OSS Distributions 			/* Clear kernel reserved pointer before copying to user space */
646*0f4c859eSApple OSS Distributions 			shmid_ds32.shm_internal = (user32_addr_t)0;
647*0f4c859eSApple OSS Distributions 
648*0f4c859eSApple OSS Distributions 			error = copyout(&shmid_ds32, uap->buf, sizeof(shmid_ds32));
649*0f4c859eSApple OSS Distributions 		}
650*0f4c859eSApple OSS Distributions 		if (error) {
651*0f4c859eSApple OSS Distributions 			shmctl_ret = error;
652*0f4c859eSApple OSS Distributions 			goto shmctl_out;
653*0f4c859eSApple OSS Distributions 		}
654*0f4c859eSApple OSS Distributions 		break;
655*0f4c859eSApple OSS Distributions 	case IPC_SET:
656*0f4c859eSApple OSS Distributions 		error = ipcperm(cred, &shmseg->u.shm_perm, IPC_M);
657*0f4c859eSApple OSS Distributions 		if (error) {
658*0f4c859eSApple OSS Distributions 			shmctl_ret = error;
659*0f4c859eSApple OSS Distributions 			goto shmctl_out;
660*0f4c859eSApple OSS Distributions 		}
661*0f4c859eSApple OSS Distributions 		if (IS_64BIT_PROCESS(p)) {
662*0f4c859eSApple OSS Distributions 			error = copyin(uap->buf, &inbuf, sizeof(struct user_shmid_ds));
663*0f4c859eSApple OSS Distributions 		} else {
664*0f4c859eSApple OSS Distributions 			struct user32_shmid_ds shmid_ds32;
665*0f4c859eSApple OSS Distributions 			error = copyin(uap->buf, &shmid_ds32, sizeof(shmid_ds32));
666*0f4c859eSApple OSS Distributions 			/* convert in place; ugly, but safe */
667*0f4c859eSApple OSS Distributions 			shmid_ds_32to64(&shmid_ds32, &inbuf);
668*0f4c859eSApple OSS Distributions 		}
669*0f4c859eSApple OSS Distributions 		if (error) {
670*0f4c859eSApple OSS Distributions 			shmctl_ret = error;
671*0f4c859eSApple OSS Distributions 			goto shmctl_out;
672*0f4c859eSApple OSS Distributions 		}
673*0f4c859eSApple OSS Distributions 		shmseg->u.shm_perm.uid = inbuf.shm_perm.uid;
674*0f4c859eSApple OSS Distributions 		shmseg->u.shm_perm.gid = inbuf.shm_perm.gid;
675*0f4c859eSApple OSS Distributions 		shmseg->u.shm_perm.mode =
676*0f4c859eSApple OSS Distributions 		    (shmseg->u.shm_perm.mode & ~ACCESSPERMS) |
677*0f4c859eSApple OSS Distributions 		    (inbuf.shm_perm.mode & ACCESSPERMS);
678*0f4c859eSApple OSS Distributions 		shmseg->u.shm_ctime = sysv_shmtime();
679*0f4c859eSApple OSS Distributions 		break;
680*0f4c859eSApple OSS Distributions 	case IPC_RMID:
681*0f4c859eSApple OSS Distributions 		error = ipcperm(cred, &shmseg->u.shm_perm, IPC_M);
682*0f4c859eSApple OSS Distributions 		if (error) {
683*0f4c859eSApple OSS Distributions 			shmctl_ret = error;
684*0f4c859eSApple OSS Distributions 			goto shmctl_out;
685*0f4c859eSApple OSS Distributions 		}
686*0f4c859eSApple OSS Distributions 		shmseg->u.shm_perm._key = IPC_PRIVATE;
687*0f4c859eSApple OSS Distributions 		shmseg->u.shm_perm.mode |= SHMSEG_REMOVED;
688*0f4c859eSApple OSS Distributions 		if (shmseg->u.shm_nattch <= 0) {
689*0f4c859eSApple OSS Distributions 			shm_deallocate_segment(shmseg);
690*0f4c859eSApple OSS Distributions 			shm_last_free = IPCID_TO_IX(uap->shmid);
691*0f4c859eSApple OSS Distributions 		}
692*0f4c859eSApple OSS Distributions 		break;
693*0f4c859eSApple OSS Distributions #if 0
694*0f4c859eSApple OSS Distributions 	case SHM_LOCK:
695*0f4c859eSApple OSS Distributions 	case SHM_UNLOCK:
696*0f4c859eSApple OSS Distributions #endif
697*0f4c859eSApple OSS Distributions 	default:
698*0f4c859eSApple OSS Distributions 		shmctl_ret = EINVAL;
699*0f4c859eSApple OSS Distributions 		goto shmctl_out;
700*0f4c859eSApple OSS Distributions 	}
701*0f4c859eSApple OSS Distributions 	*retval = 0;
702*0f4c859eSApple OSS Distributions 	shmctl_ret = 0;
703*0f4c859eSApple OSS Distributions shmctl_out:
704*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_UNLOCK();
705*0f4c859eSApple OSS Distributions 	return shmctl_ret;
706*0f4c859eSApple OSS Distributions }
707*0f4c859eSApple OSS Distributions 
708*0f4c859eSApple OSS Distributions static int
shmget_existing(struct shmget_args * uap,int mode,int segnum,int * retval)709*0f4c859eSApple OSS Distributions shmget_existing(struct shmget_args *uap, int mode, int segnum, int *retval)
710*0f4c859eSApple OSS Distributions {
711*0f4c859eSApple OSS Distributions 	struct shmid_kernel *shmseg;
712*0f4c859eSApple OSS Distributions 	int error = 0;
713*0f4c859eSApple OSS Distributions 
714*0f4c859eSApple OSS Distributions 	shmseg = &shmsegs[segnum];
715*0f4c859eSApple OSS Distributions 	if (shmseg->u.shm_perm.mode & SHMSEG_REMOVED) {
716*0f4c859eSApple OSS Distributions 		/*
717*0f4c859eSApple OSS Distributions 		 * This segment is in the process of being allocated.  Wait
718*0f4c859eSApple OSS Distributions 		 * until it's done, and look the key up again (in case the
719*0f4c859eSApple OSS Distributions 		 * allocation failed or it was freed).
720*0f4c859eSApple OSS Distributions 		 */
721*0f4c859eSApple OSS Distributions 		shmseg->u.shm_perm.mode |= SHMSEG_WANTED;
722*0f4c859eSApple OSS Distributions 		error = tsleep((caddr_t)shmseg, PLOCK | PCATCH, "shmget", 0);
723*0f4c859eSApple OSS Distributions 		if (error) {
724*0f4c859eSApple OSS Distributions 			return error;
725*0f4c859eSApple OSS Distributions 		}
726*0f4c859eSApple OSS Distributions 		return EAGAIN;
727*0f4c859eSApple OSS Distributions 	}
728*0f4c859eSApple OSS Distributions 
729*0f4c859eSApple OSS Distributions 	/*
730*0f4c859eSApple OSS Distributions 	 * The low 9 bits of shmflag are the mode bits being requested, which
731*0f4c859eSApple OSS Distributions 	 * are the actual mode bits desired on the segment, and not in IPC_R
732*0f4c859eSApple OSS Distributions 	 * form; therefore it would be incorrect to call ipcperm() to validate
733*0f4c859eSApple OSS Distributions 	 * them; instead, we AND the existing mode with the requested mode, and
734*0f4c859eSApple OSS Distributions 	 * verify that it matches the requested mode; otherwise, we fail with
735*0f4c859eSApple OSS Distributions 	 * EACCES (access denied).
736*0f4c859eSApple OSS Distributions 	 */
737*0f4c859eSApple OSS Distributions 	if ((shmseg->u.shm_perm.mode & mode) != mode) {
738*0f4c859eSApple OSS Distributions 		return EACCES;
739*0f4c859eSApple OSS Distributions 	}
740*0f4c859eSApple OSS Distributions 
741*0f4c859eSApple OSS Distributions #if CONFIG_MACF
742*0f4c859eSApple OSS Distributions 	error = mac_sysvshm_check_shmget(kauth_cred_get(), shmseg, uap->shmflg);
743*0f4c859eSApple OSS Distributions 	if (error) {
744*0f4c859eSApple OSS Distributions 		return error;
745*0f4c859eSApple OSS Distributions 	}
746*0f4c859eSApple OSS Distributions #endif
747*0f4c859eSApple OSS Distributions 
748*0f4c859eSApple OSS Distributions 	if (uap->size && uap->size > shmseg->u.shm_segsz) {
749*0f4c859eSApple OSS Distributions 		return EINVAL;
750*0f4c859eSApple OSS Distributions 	}
751*0f4c859eSApple OSS Distributions 
752*0f4c859eSApple OSS Distributions 	if ((uap->shmflg & (IPC_CREAT | IPC_EXCL)) == (IPC_CREAT | IPC_EXCL)) {
753*0f4c859eSApple OSS Distributions 		return EEXIST;
754*0f4c859eSApple OSS Distributions 	}
755*0f4c859eSApple OSS Distributions 
756*0f4c859eSApple OSS Distributions 	*retval = IXSEQ_TO_IPCID(segnum, shmseg->u.shm_perm);
757*0f4c859eSApple OSS Distributions 	return 0;
758*0f4c859eSApple OSS Distributions }
759*0f4c859eSApple OSS Distributions 
760*0f4c859eSApple OSS Distributions static int
shmget_allocate_segment(struct proc * p,struct shmget_args * uap,int mode,int * retval)761*0f4c859eSApple OSS Distributions shmget_allocate_segment(struct proc *p, struct shmget_args *uap, int mode,
762*0f4c859eSApple OSS Distributions     int *retval)
763*0f4c859eSApple OSS Distributions {
764*0f4c859eSApple OSS Distributions 	int i, segnum, shmid;
765*0f4c859eSApple OSS Distributions 	kauth_cred_t cred = kauth_cred_get();
766*0f4c859eSApple OSS Distributions 	struct shmid_kernel *shmseg;
767*0f4c859eSApple OSS Distributions 	struct shm_handle *shm_handle;
768*0f4c859eSApple OSS Distributions 	kern_return_t kret;
769*0f4c859eSApple OSS Distributions 	mach_vm_size_t total_size, size = 0, alloc_size;
770*0f4c859eSApple OSS Distributions 	void * mem_object;
771*0f4c859eSApple OSS Distributions 	struct shm_handle *shm_handle_next, **shm_handle_next_p;
772*0f4c859eSApple OSS Distributions 
773*0f4c859eSApple OSS Distributions 	if (uap->size <= 0 ||
774*0f4c859eSApple OSS Distributions 	    uap->size < (user_size_t)shminfo.shmmin ||
775*0f4c859eSApple OSS Distributions 	    uap->size > (user_size_t)shminfo.shmmax) {
776*0f4c859eSApple OSS Distributions 		return EINVAL;
777*0f4c859eSApple OSS Distributions 	}
778*0f4c859eSApple OSS Distributions 	if (shm_nused >= shminfo.shmmni) { /* any shmids left? */
779*0f4c859eSApple OSS Distributions 		return ENOSPC;
780*0f4c859eSApple OSS Distributions 	}
781*0f4c859eSApple OSS Distributions 	if (mach_vm_round_page_overflow(uap->size, &total_size)) {
782*0f4c859eSApple OSS Distributions 		return EINVAL;
783*0f4c859eSApple OSS Distributions 	}
784*0f4c859eSApple OSS Distributions 	if ((user_ssize_t)(shm_committed + btoc(total_size)) > shminfo.shmall) {
785*0f4c859eSApple OSS Distributions 		return ENOMEM;
786*0f4c859eSApple OSS Distributions 	}
787*0f4c859eSApple OSS Distributions 	if (shm_last_free < 0) {
788*0f4c859eSApple OSS Distributions 		for (i = 0; i < shminfo.shmmni; i++) {
789*0f4c859eSApple OSS Distributions 			if (shmsegs[i].u.shm_perm.mode & SHMSEG_FREE) {
790*0f4c859eSApple OSS Distributions 				break;
791*0f4c859eSApple OSS Distributions 			}
792*0f4c859eSApple OSS Distributions 		}
793*0f4c859eSApple OSS Distributions 		if (i == shminfo.shmmni) {
794*0f4c859eSApple OSS Distributions 			panic("shmseg free count inconsistent");
795*0f4c859eSApple OSS Distributions 		}
796*0f4c859eSApple OSS Distributions 		segnum = i;
797*0f4c859eSApple OSS Distributions 	} else {
798*0f4c859eSApple OSS Distributions 		segnum = shm_last_free;
799*0f4c859eSApple OSS Distributions 		shm_last_free = -1;
800*0f4c859eSApple OSS Distributions 	}
801*0f4c859eSApple OSS Distributions 	shmseg = &shmsegs[segnum];
802*0f4c859eSApple OSS Distributions 
803*0f4c859eSApple OSS Distributions 	/*
804*0f4c859eSApple OSS Distributions 	 * In case we sleep in malloc(), mark the segment present but deleted
805*0f4c859eSApple OSS Distributions 	 * so that noone else tries to create the same key.
806*0f4c859eSApple OSS Distributions 	 * XXX but we don't release the global lock !?
807*0f4c859eSApple OSS Distributions 	 */
808*0f4c859eSApple OSS Distributions 	shmseg->u.shm_perm.mode = SHMSEG_ALLOCATED | SHMSEG_REMOVED;
809*0f4c859eSApple OSS Distributions 	shmseg->u.shm_perm._key = uap->key;
810*0f4c859eSApple OSS Distributions 	shmseg->u.shm_perm._seq = (shmseg->u.shm_perm._seq + 1) & 0x7fff;
811*0f4c859eSApple OSS Distributions 
812*0f4c859eSApple OSS Distributions 	shm_handle_next_p = NULL;
813*0f4c859eSApple OSS Distributions 	for (alloc_size = 0;
814*0f4c859eSApple OSS Distributions 	    alloc_size < total_size;
815*0f4c859eSApple OSS Distributions 	    alloc_size += size) {
816*0f4c859eSApple OSS Distributions 		size = MIN(total_size - alloc_size, ANON_MAX_SIZE);
817*0f4c859eSApple OSS Distributions 		kret = mach_make_memory_entry_64(
818*0f4c859eSApple OSS Distributions 			VM_MAP_NULL,
819*0f4c859eSApple OSS Distributions 			(memory_object_size_t *) &size,
820*0f4c859eSApple OSS Distributions 			(memory_object_offset_t) 0,
821*0f4c859eSApple OSS Distributions 			MAP_MEM_NAMED_CREATE | VM_PROT_DEFAULT,
822*0f4c859eSApple OSS Distributions 			(ipc_port_t *) &mem_object, 0);
823*0f4c859eSApple OSS Distributions 		if (kret != KERN_SUCCESS) {
824*0f4c859eSApple OSS Distributions 			goto out;
825*0f4c859eSApple OSS Distributions 		}
826*0f4c859eSApple OSS Distributions 
827*0f4c859eSApple OSS Distributions 		shm_handle = kalloc_type(struct shm_handle, Z_WAITOK | Z_NOFAIL);
828*0f4c859eSApple OSS Distributions 		shm_handle->shm_object = mem_object;
829*0f4c859eSApple OSS Distributions 		shm_handle->shm_handle_size = size;
830*0f4c859eSApple OSS Distributions 		shm_handle->shm_handle_next = NULL;
831*0f4c859eSApple OSS Distributions 		if (shm_handle_next_p == NULL) {
832*0f4c859eSApple OSS Distributions 			shmseg->u.shm_internal = CAST_USER_ADDR_T(shm_handle);/* tunnel */
833*0f4c859eSApple OSS Distributions 		} else {
834*0f4c859eSApple OSS Distributions 			*shm_handle_next_p = shm_handle;
835*0f4c859eSApple OSS Distributions 		}
836*0f4c859eSApple OSS Distributions 		shm_handle_next_p = &shm_handle->shm_handle_next;
837*0f4c859eSApple OSS Distributions 	}
838*0f4c859eSApple OSS Distributions 
839*0f4c859eSApple OSS Distributions 	shmid = IXSEQ_TO_IPCID(segnum, shmseg->u.shm_perm);
840*0f4c859eSApple OSS Distributions 
841*0f4c859eSApple OSS Distributions 	shmseg->u.shm_perm.cuid = shmseg->u.shm_perm.uid = kauth_cred_getuid(cred);
842*0f4c859eSApple OSS Distributions 	shmseg->u.shm_perm.cgid = shmseg->u.shm_perm.gid = kauth_cred_getgid(cred);
843*0f4c859eSApple OSS Distributions 	shmseg->u.shm_perm.mode = (shmseg->u.shm_perm.mode & SHMSEG_WANTED) |
844*0f4c859eSApple OSS Distributions 	    (mode & ACCESSPERMS) | SHMSEG_ALLOCATED;
845*0f4c859eSApple OSS Distributions 	shmseg->u.shm_segsz = uap->size;
846*0f4c859eSApple OSS Distributions 	shmseg->u.shm_cpid = proc_getpid(p);
847*0f4c859eSApple OSS Distributions 	shmseg->u.shm_lpid = shmseg->u.shm_nattch = 0;
848*0f4c859eSApple OSS Distributions 	shmseg->u.shm_atime = shmseg->u.shm_dtime = 0;
849*0f4c859eSApple OSS Distributions #if CONFIG_MACF
850*0f4c859eSApple OSS Distributions 	mac_sysvshm_label_associate(cred, shmseg);
851*0f4c859eSApple OSS Distributions #endif
852*0f4c859eSApple OSS Distributions 	shmseg->u.shm_ctime = sysv_shmtime();
853*0f4c859eSApple OSS Distributions 	shm_committed += btoc(size);
854*0f4c859eSApple OSS Distributions 	shm_nused++;
855*0f4c859eSApple OSS Distributions 	AUDIT_ARG(svipc_perm, &shmseg->u.shm_perm);
856*0f4c859eSApple OSS Distributions 	if (shmseg->u.shm_perm.mode & SHMSEG_WANTED) {
857*0f4c859eSApple OSS Distributions 		/*
858*0f4c859eSApple OSS Distributions 		 * Somebody else wanted this key while we were asleep.  Wake
859*0f4c859eSApple OSS Distributions 		 * them up now.
860*0f4c859eSApple OSS Distributions 		 */
861*0f4c859eSApple OSS Distributions 		shmseg->u.shm_perm.mode &= ~SHMSEG_WANTED;
862*0f4c859eSApple OSS Distributions 		wakeup((caddr_t)shmseg);
863*0f4c859eSApple OSS Distributions 	}
864*0f4c859eSApple OSS Distributions 	*retval = shmid;
865*0f4c859eSApple OSS Distributions 	AUDIT_ARG(svipc_id, shmid);
866*0f4c859eSApple OSS Distributions 	return 0;
867*0f4c859eSApple OSS Distributions out:
868*0f4c859eSApple OSS Distributions 	if (kret != KERN_SUCCESS) {
869*0f4c859eSApple OSS Distributions 		for (shm_handle = CAST_DOWN(void *, shmseg->u.shm_internal); /* tunnel */
870*0f4c859eSApple OSS Distributions 		    shm_handle != NULL;
871*0f4c859eSApple OSS Distributions 		    shm_handle = shm_handle_next) {
872*0f4c859eSApple OSS Distributions 			shm_handle_next = shm_handle->shm_handle_next;
873*0f4c859eSApple OSS Distributions 			mach_memory_entry_port_release(shm_handle->shm_object);
874*0f4c859eSApple OSS Distributions 			kfree_type(struct shm_handle, shm_handle);
875*0f4c859eSApple OSS Distributions 		}
876*0f4c859eSApple OSS Distributions 		shmseg->u.shm_internal = USER_ADDR_NULL; /* tunnel */
877*0f4c859eSApple OSS Distributions 	}
878*0f4c859eSApple OSS Distributions 
879*0f4c859eSApple OSS Distributions 	switch (kret) {
880*0f4c859eSApple OSS Distributions 	case KERN_INVALID_ADDRESS:
881*0f4c859eSApple OSS Distributions 	case KERN_NO_SPACE:
882*0f4c859eSApple OSS Distributions 		return ENOMEM;
883*0f4c859eSApple OSS Distributions 	case KERN_PROTECTION_FAILURE:
884*0f4c859eSApple OSS Distributions 		return EACCES;
885*0f4c859eSApple OSS Distributions 	default:
886*0f4c859eSApple OSS Distributions 		return EINVAL;
887*0f4c859eSApple OSS Distributions 	}
888*0f4c859eSApple OSS Distributions }
889*0f4c859eSApple OSS Distributions 
890*0f4c859eSApple OSS Distributions int
shmget(struct proc * p,struct shmget_args * uap,int32_t * retval)891*0f4c859eSApple OSS Distributions shmget(struct proc *p, struct shmget_args *uap, int32_t *retval)
892*0f4c859eSApple OSS Distributions {
893*0f4c859eSApple OSS Distributions 	int segnum, mode, error;
894*0f4c859eSApple OSS Distributions 	int shmget_ret = 0;
895*0f4c859eSApple OSS Distributions 
896*0f4c859eSApple OSS Distributions 	/* Auditing is actually done in shmget_allocate_segment() */
897*0f4c859eSApple OSS Distributions 
898*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_LOCK();
899*0f4c859eSApple OSS Distributions 
900*0f4c859eSApple OSS Distributions 	if ((shmget_ret = shminit())) {
901*0f4c859eSApple OSS Distributions 		goto shmget_out;
902*0f4c859eSApple OSS Distributions 	}
903*0f4c859eSApple OSS Distributions 
904*0f4c859eSApple OSS Distributions 	mode = uap->shmflg & ACCESSPERMS;
905*0f4c859eSApple OSS Distributions 	if (uap->key != IPC_PRIVATE) {
906*0f4c859eSApple OSS Distributions again:
907*0f4c859eSApple OSS Distributions 		segnum = shm_find_segment_by_key(uap->key);
908*0f4c859eSApple OSS Distributions 		if (segnum >= 0) {
909*0f4c859eSApple OSS Distributions 			error = shmget_existing(uap, mode, segnum, retval);
910*0f4c859eSApple OSS Distributions 			if (error == EAGAIN) {
911*0f4c859eSApple OSS Distributions 				goto again;
912*0f4c859eSApple OSS Distributions 			}
913*0f4c859eSApple OSS Distributions 			shmget_ret = error;
914*0f4c859eSApple OSS Distributions 			goto shmget_out;
915*0f4c859eSApple OSS Distributions 		}
916*0f4c859eSApple OSS Distributions 		if ((uap->shmflg & IPC_CREAT) == 0) {
917*0f4c859eSApple OSS Distributions 			shmget_ret = ENOENT;
918*0f4c859eSApple OSS Distributions 			goto shmget_out;
919*0f4c859eSApple OSS Distributions 		}
920*0f4c859eSApple OSS Distributions 	}
921*0f4c859eSApple OSS Distributions 	shmget_ret = shmget_allocate_segment(p, uap, mode, retval);
922*0f4c859eSApple OSS Distributions shmget_out:
923*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_UNLOCK();
924*0f4c859eSApple OSS Distributions 	return shmget_ret;
925*0f4c859eSApple OSS Distributions }
926*0f4c859eSApple OSS Distributions 
927*0f4c859eSApple OSS Distributions /*
928*0f4c859eSApple OSS Distributions  * shmsys
929*0f4c859eSApple OSS Distributions  *
930*0f4c859eSApple OSS Distributions  * Entry point for all SHM calls: shmat, oshmctl, shmdt, shmget, shmctl
931*0f4c859eSApple OSS Distributions  *
932*0f4c859eSApple OSS Distributions  * Parameters:	p	Process requesting the call
933*0f4c859eSApple OSS Distributions  *              uap	User argument descriptor (see below)
934*0f4c859eSApple OSS Distributions  *              retval	Return value of the selected shm call
935*0f4c859eSApple OSS Distributions  *
936*0f4c859eSApple OSS Distributions  * Indirect parameters:	uap->which	msg call to invoke (index in array of shm calls)
937*0f4c859eSApple OSS Distributions  *                      uap->a2		User argument descriptor
938*0f4c859eSApple OSS Distributions  *
939*0f4c859eSApple OSS Distributions  * Returns:	0	Success
940*0f4c859eSApple OSS Distributions  *              !0	Not success
941*0f4c859eSApple OSS Distributions  *
942*0f4c859eSApple OSS Distributions  * Implicit returns: retval     Return value of the selected shm call
943*0f4c859eSApple OSS Distributions  *
944*0f4c859eSApple OSS Distributions  * DEPRECATED:  This interface should not be used to call the other SHM
945*0f4c859eSApple OSS Distributions  *              functions (shmat, oshmctl, shmdt, shmget, shmctl). The correct
946*0f4c859eSApple OSS Distributions  *              usage is to call the other SHM functions directly.
947*0f4c859eSApple OSS Distributions  */
948*0f4c859eSApple OSS Distributions int
shmsys(struct proc * p,struct shmsys_args * uap,int32_t * retval)949*0f4c859eSApple OSS Distributions shmsys(struct proc *p, struct shmsys_args *uap, int32_t *retval)
950*0f4c859eSApple OSS Distributions {
951*0f4c859eSApple OSS Distributions 	/* The routine that we are dispatching already does this */
952*0f4c859eSApple OSS Distributions 
953*0f4c859eSApple OSS Distributions 	if (uap->which >= sizeof(shmcalls) / sizeof(shmcalls[0])) {
954*0f4c859eSApple OSS Distributions 		return EINVAL;
955*0f4c859eSApple OSS Distributions 	}
956*0f4c859eSApple OSS Distributions 	return (*shmcalls[uap->which])(p, &uap->a2, retval);
957*0f4c859eSApple OSS Distributions }
958*0f4c859eSApple OSS Distributions 
959*0f4c859eSApple OSS Distributions /*
960*0f4c859eSApple OSS Distributions  * Return 0 on success, 1 on failure.
961*0f4c859eSApple OSS Distributions  */
962*0f4c859eSApple OSS Distributions int
shmfork(struct proc * p1,struct proc * p2)963*0f4c859eSApple OSS Distributions shmfork(struct proc *p1, struct proc *p2)
964*0f4c859eSApple OSS Distributions {
965*0f4c859eSApple OSS Distributions 	struct shmmap_state *shmmap_s;
966*0f4c859eSApple OSS Distributions 	int nsegs = 0;
967*0f4c859eSApple OSS Distributions 	int ret = 0;
968*0f4c859eSApple OSS Distributions 
969*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_LOCK();
970*0f4c859eSApple OSS Distributions 
971*0f4c859eSApple OSS Distributions 	if (shminit()) {
972*0f4c859eSApple OSS Distributions 		ret = 1;
973*0f4c859eSApple OSS Distributions 		goto shmfork_out;
974*0f4c859eSApple OSS Distributions 	}
975*0f4c859eSApple OSS Distributions 
976*0f4c859eSApple OSS Distributions 	struct shmmap_state *src = (struct shmmap_state *)p1->vm_shm;
977*0f4c859eSApple OSS Distributions 	assert(src);
978*0f4c859eSApple OSS Distributions 
979*0f4c859eSApple OSS Distributions 	/* count number of shmid entries in src */
980*0f4c859eSApple OSS Distributions 	for (struct shmmap_state *s = src; s->shmid != SHMID_SENTINEL; s++) {
981*0f4c859eSApple OSS Distributions 		nsegs++;
982*0f4c859eSApple OSS Distributions 	}
983*0f4c859eSApple OSS Distributions 
984*0f4c859eSApple OSS Distributions 	shmmap_s = kalloc_type(struct shmmap_state, nsegs + 1, Z_WAITOK);
985*0f4c859eSApple OSS Distributions 	if (shmmap_s == NULL) {
986*0f4c859eSApple OSS Distributions 		ret = 1;
987*0f4c859eSApple OSS Distributions 		goto shmfork_out;
988*0f4c859eSApple OSS Distributions 	}
989*0f4c859eSApple OSS Distributions 
990*0f4c859eSApple OSS Distributions 	bcopy(src, (caddr_t)shmmap_s, (nsegs + 1) * sizeof(struct shmmap_state));
991*0f4c859eSApple OSS Distributions 	p2->vm_shm = (caddr_t)shmmap_s;
992*0f4c859eSApple OSS Distributions 	for (; shmmap_s->shmid != SHMID_SENTINEL; shmmap_s++) {
993*0f4c859eSApple OSS Distributions 		if (SHMID_IS_VALID(shmmap_s->shmid)) {
994*0f4c859eSApple OSS Distributions 			shmsegs[IPCID_TO_IX(shmmap_s->shmid)].u.shm_nattch++;
995*0f4c859eSApple OSS Distributions 		}
996*0f4c859eSApple OSS Distributions 	}
997*0f4c859eSApple OSS Distributions 
998*0f4c859eSApple OSS Distributions shmfork_out:
999*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_UNLOCK();
1000*0f4c859eSApple OSS Distributions 	return ret;
1001*0f4c859eSApple OSS Distributions }
1002*0f4c859eSApple OSS Distributions 
1003*0f4c859eSApple OSS Distributions static void
shmcleanup(struct proc * p,int deallocate)1004*0f4c859eSApple OSS Distributions shmcleanup(struct proc *p, int deallocate)
1005*0f4c859eSApple OSS Distributions {
1006*0f4c859eSApple OSS Distributions 	struct shmmap_state *shmmap_s;
1007*0f4c859eSApple OSS Distributions 	int nsegs = 0;
1008*0f4c859eSApple OSS Distributions 
1009*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_LOCK();
1010*0f4c859eSApple OSS Distributions 
1011*0f4c859eSApple OSS Distributions 	shmmap_s = (struct shmmap_state *)p->vm_shm;
1012*0f4c859eSApple OSS Distributions 	for (; shmmap_s->shmid != SHMID_SENTINEL; shmmap_s++) {
1013*0f4c859eSApple OSS Distributions 		nsegs++;
1014*0f4c859eSApple OSS Distributions 		if (SHMID_IS_VALID(shmmap_s->shmid)) {
1015*0f4c859eSApple OSS Distributions 			/*
1016*0f4c859eSApple OSS Distributions 			 * XXX: Should the MAC framework enforce
1017*0f4c859eSApple OSS Distributions 			 * check here as well.
1018*0f4c859eSApple OSS Distributions 			 */
1019*0f4c859eSApple OSS Distributions 			shm_delete_mapping(p, shmmap_s, deallocate);
1020*0f4c859eSApple OSS Distributions 		}
1021*0f4c859eSApple OSS Distributions 	}
1022*0f4c859eSApple OSS Distributions 
1023*0f4c859eSApple OSS Distributions 	kfree_type(struct shmmap_state, nsegs + 1, p->vm_shm);
1024*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_UNLOCK();
1025*0f4c859eSApple OSS Distributions }
1026*0f4c859eSApple OSS Distributions 
1027*0f4c859eSApple OSS Distributions void
shmexit(struct proc * p)1028*0f4c859eSApple OSS Distributions shmexit(struct proc *p)
1029*0f4c859eSApple OSS Distributions {
1030*0f4c859eSApple OSS Distributions 	shmcleanup(p, 1);
1031*0f4c859eSApple OSS Distributions }
1032*0f4c859eSApple OSS Distributions 
1033*0f4c859eSApple OSS Distributions /*
1034*0f4c859eSApple OSS Distributions  * shmexec() is like shmexit(), only it doesn't delete the mappings,
1035*0f4c859eSApple OSS Distributions  * since the old address space has already been destroyed and the new
1036*0f4c859eSApple OSS Distributions  * one instantiated.  Instead, it just does the housekeeping work we
1037*0f4c859eSApple OSS Distributions  * need to do to keep the System V shared memory subsystem sane.
1038*0f4c859eSApple OSS Distributions  */
1039*0f4c859eSApple OSS Distributions __private_extern__ void
shmexec(struct proc * p)1040*0f4c859eSApple OSS Distributions shmexec(struct proc *p)
1041*0f4c859eSApple OSS Distributions {
1042*0f4c859eSApple OSS Distributions 	shmcleanup(p, 0);
1043*0f4c859eSApple OSS Distributions }
1044*0f4c859eSApple OSS Distributions 
1045*0f4c859eSApple OSS Distributions int
shminit(void)1046*0f4c859eSApple OSS Distributions shminit(void)
1047*0f4c859eSApple OSS Distributions {
1048*0f4c859eSApple OSS Distributions 	size_t sz;
1049*0f4c859eSApple OSS Distributions 	int i;
1050*0f4c859eSApple OSS Distributions 
1051*0f4c859eSApple OSS Distributions 	if (!shm_inited) {
1052*0f4c859eSApple OSS Distributions 		/*
1053*0f4c859eSApple OSS Distributions 		 * we store internally 64 bit, since if we didn't, we would
1054*0f4c859eSApple OSS Distributions 		 * be unable to represent a segment size in excess of 32 bits
1055*0f4c859eSApple OSS Distributions 		 * with the (struct shmid_ds)->shm_segsz field; also, POSIX
1056*0f4c859eSApple OSS Distributions 		 * dictates this filed be a size_t, which is 64 bits when
1057*0f4c859eSApple OSS Distributions 		 * running 64 bit binaries.
1058*0f4c859eSApple OSS Distributions 		 */
1059*0f4c859eSApple OSS Distributions 		if (os_mul_overflow(shminfo.shmmni, sizeof(struct shmid_kernel), &sz)) {
1060*0f4c859eSApple OSS Distributions 			return ENOMEM;
1061*0f4c859eSApple OSS Distributions 		}
1062*0f4c859eSApple OSS Distributions 
1063*0f4c859eSApple OSS Distributions 		shmsegs = zalloc_permanent(sz, ZALIGN_PTR);
1064*0f4c859eSApple OSS Distributions 		if (shmsegs == NULL) {
1065*0f4c859eSApple OSS Distributions 			return ENOMEM;
1066*0f4c859eSApple OSS Distributions 		}
1067*0f4c859eSApple OSS Distributions 		for (i = 0; i < shminfo.shmmni; i++) {
1068*0f4c859eSApple OSS Distributions 			shmsegs[i].u.shm_perm.mode = SHMSEG_FREE;
1069*0f4c859eSApple OSS Distributions 			shmsegs[i].u.shm_perm._seq = 0;
1070*0f4c859eSApple OSS Distributions #if CONFIG_MACF
1071*0f4c859eSApple OSS Distributions 			mac_sysvshm_label_init(&shmsegs[i]);
1072*0f4c859eSApple OSS Distributions #endif
1073*0f4c859eSApple OSS Distributions 		}
1074*0f4c859eSApple OSS Distributions 		shm_last_free = 0;
1075*0f4c859eSApple OSS Distributions 		shm_nused = 0;
1076*0f4c859eSApple OSS Distributions 		shm_committed = 0;
1077*0f4c859eSApple OSS Distributions 		shm_inited = 1;
1078*0f4c859eSApple OSS Distributions 	}
1079*0f4c859eSApple OSS Distributions 
1080*0f4c859eSApple OSS Distributions 	return 0;
1081*0f4c859eSApple OSS Distributions }
1082*0f4c859eSApple OSS Distributions 
1083*0f4c859eSApple OSS Distributions /* (struct sysctl_oid *oidp, void *arg1, int arg2, \
1084*0f4c859eSApple OSS Distributions  *       struct sysctl_req *req) */
1085*0f4c859eSApple OSS Distributions static int
sysctl_shminfo(__unused struct sysctl_oid * oidp,void * arg1,__unused int arg2,struct sysctl_req * req)1086*0f4c859eSApple OSS Distributions sysctl_shminfo(__unused struct sysctl_oid *oidp, void *arg1,
1087*0f4c859eSApple OSS Distributions     __unused int arg2, struct sysctl_req *req)
1088*0f4c859eSApple OSS Distributions {
1089*0f4c859eSApple OSS Distributions 	int error = 0;
1090*0f4c859eSApple OSS Distributions 	int sysctl_shminfo_ret = 0;
1091*0f4c859eSApple OSS Distributions 	int64_t saved_shmmax;
1092*0f4c859eSApple OSS Distributions 	int64_t saved_shmmin;
1093*0f4c859eSApple OSS Distributions 	int64_t saved_shmseg;
1094*0f4c859eSApple OSS Distributions 	int64_t saved_shmmni;
1095*0f4c859eSApple OSS Distributions 	int64_t saved_shmall;
1096*0f4c859eSApple OSS Distributions 
1097*0f4c859eSApple OSS Distributions 	error = SYSCTL_OUT(req, arg1, sizeof(int64_t));
1098*0f4c859eSApple OSS Distributions 	if (error || req->newptr == USER_ADDR_NULL) {
1099*0f4c859eSApple OSS Distributions 		return error;
1100*0f4c859eSApple OSS Distributions 	}
1101*0f4c859eSApple OSS Distributions 
1102*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_LOCK();
1103*0f4c859eSApple OSS Distributions 
1104*0f4c859eSApple OSS Distributions 	/* shmmni can not be changed after SysV SHM has been initialized */
1105*0f4c859eSApple OSS Distributions 	if (shm_inited && arg1 == &shminfo.shmmni) {
1106*0f4c859eSApple OSS Distributions 		sysctl_shminfo_ret = EPERM;
1107*0f4c859eSApple OSS Distributions 		goto sysctl_shminfo_out;
1108*0f4c859eSApple OSS Distributions 	}
1109*0f4c859eSApple OSS Distributions 	saved_shmmax = shminfo.shmmax;
1110*0f4c859eSApple OSS Distributions 	saved_shmmin = shminfo.shmmin;
1111*0f4c859eSApple OSS Distributions 	saved_shmseg = shminfo.shmseg;
1112*0f4c859eSApple OSS Distributions 	saved_shmmni = shminfo.shmmni;
1113*0f4c859eSApple OSS Distributions 	saved_shmall = shminfo.shmall;
1114*0f4c859eSApple OSS Distributions 
1115*0f4c859eSApple OSS Distributions 	if ((error = SYSCTL_IN(req, arg1, sizeof(int64_t))) != 0) {
1116*0f4c859eSApple OSS Distributions 		sysctl_shminfo_ret = error;
1117*0f4c859eSApple OSS Distributions 		goto sysctl_shminfo_out;
1118*0f4c859eSApple OSS Distributions 	}
1119*0f4c859eSApple OSS Distributions 
1120*0f4c859eSApple OSS Distributions 	if (arg1 == &shminfo.shmmax) {
1121*0f4c859eSApple OSS Distributions 		/* shmmax needs to be page-aligned */
1122*0f4c859eSApple OSS Distributions 		if (shminfo.shmmax & PAGE_MASK_64 || shminfo.shmmax < 0) {
1123*0f4c859eSApple OSS Distributions 			shminfo.shmmax = saved_shmmax;
1124*0f4c859eSApple OSS Distributions 			sysctl_shminfo_ret = EINVAL;
1125*0f4c859eSApple OSS Distributions 			goto sysctl_shminfo_out;
1126*0f4c859eSApple OSS Distributions 		}
1127*0f4c859eSApple OSS Distributions 	} else if (arg1 == &shminfo.shmmin) {
1128*0f4c859eSApple OSS Distributions 		if (shminfo.shmmin < 0) {
1129*0f4c859eSApple OSS Distributions 			shminfo.shmmin = saved_shmmin;
1130*0f4c859eSApple OSS Distributions 			sysctl_shminfo_ret = EINVAL;
1131*0f4c859eSApple OSS Distributions 			goto sysctl_shminfo_out;
1132*0f4c859eSApple OSS Distributions 		}
1133*0f4c859eSApple OSS Distributions 	} else if (arg1 == &shminfo.shmseg) {
1134*0f4c859eSApple OSS Distributions 		/* add a sanity check - 20847256 */
1135*0f4c859eSApple OSS Distributions 		if (shminfo.shmseg > INT32_MAX || shminfo.shmseg < 0) {
1136*0f4c859eSApple OSS Distributions 			shminfo.shmseg = saved_shmseg;
1137*0f4c859eSApple OSS Distributions 			sysctl_shminfo_ret = EINVAL;
1138*0f4c859eSApple OSS Distributions 			goto sysctl_shminfo_out;
1139*0f4c859eSApple OSS Distributions 		}
1140*0f4c859eSApple OSS Distributions 	} else if (arg1 == &shminfo.shmmni) {
1141*0f4c859eSApple OSS Distributions 		/* add a sanity check - 20847256 */
1142*0f4c859eSApple OSS Distributions 		if (shminfo.shmmni > INT32_MAX || shminfo.shmmni < 0) {
1143*0f4c859eSApple OSS Distributions 			shminfo.shmmni = saved_shmmni;
1144*0f4c859eSApple OSS Distributions 			sysctl_shminfo_ret = EINVAL;
1145*0f4c859eSApple OSS Distributions 			goto sysctl_shminfo_out;
1146*0f4c859eSApple OSS Distributions 		}
1147*0f4c859eSApple OSS Distributions 	} else if (arg1 == &shminfo.shmall) {
1148*0f4c859eSApple OSS Distributions 		/* add a sanity check - 20847256 */
1149*0f4c859eSApple OSS Distributions 		if (shminfo.shmall > INT32_MAX || shminfo.shmall < 0) {
1150*0f4c859eSApple OSS Distributions 			shminfo.shmall = saved_shmall;
1151*0f4c859eSApple OSS Distributions 			sysctl_shminfo_ret = EINVAL;
1152*0f4c859eSApple OSS Distributions 			goto sysctl_shminfo_out;
1153*0f4c859eSApple OSS Distributions 		}
1154*0f4c859eSApple OSS Distributions 	}
1155*0f4c859eSApple OSS Distributions 	sysctl_shminfo_ret = 0;
1156*0f4c859eSApple OSS Distributions sysctl_shminfo_out:
1157*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_UNLOCK();
1158*0f4c859eSApple OSS Distributions 	return sysctl_shminfo_ret;
1159*0f4c859eSApple OSS Distributions }
1160*0f4c859eSApple OSS Distributions 
1161*0f4c859eSApple OSS Distributions static int
IPCS_shm_sysctl(__unused struct sysctl_oid * oidp,__unused void * arg1,__unused int arg2,struct sysctl_req * req)1162*0f4c859eSApple OSS Distributions IPCS_shm_sysctl(__unused struct sysctl_oid *oidp, __unused void *arg1,
1163*0f4c859eSApple OSS Distributions     __unused int arg2, struct sysctl_req *req)
1164*0f4c859eSApple OSS Distributions {
1165*0f4c859eSApple OSS Distributions 	int error;
1166*0f4c859eSApple OSS Distributions 	int cursor;
1167*0f4c859eSApple OSS Distributions 	union {
1168*0f4c859eSApple OSS Distributions 		struct user32_IPCS_command u32;
1169*0f4c859eSApple OSS Distributions 		struct user_IPCS_command u64;
1170*0f4c859eSApple OSS Distributions 	} ipcs = { };
1171*0f4c859eSApple OSS Distributions 	struct user32_shmid_ds shmid_ds32 = { }; /* post conversion, 32 bit version */
1172*0f4c859eSApple OSS Distributions 	struct user_shmid_ds   shmid_ds = { };   /* 64 bit version */
1173*0f4c859eSApple OSS Distributions 	void *shmid_dsp;
1174*0f4c859eSApple OSS Distributions 	size_t ipcs_sz = sizeof(struct user_IPCS_command);
1175*0f4c859eSApple OSS Distributions 	size_t shmid_ds_sz = sizeof(struct user_shmid_ds);
1176*0f4c859eSApple OSS Distributions 	struct proc *p = current_proc();
1177*0f4c859eSApple OSS Distributions 
1178*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_LOCK();
1179*0f4c859eSApple OSS Distributions 
1180*0f4c859eSApple OSS Distributions 	if ((error = shminit())) {
1181*0f4c859eSApple OSS Distributions 		goto ipcs_shm_sysctl_out;
1182*0f4c859eSApple OSS Distributions 	}
1183*0f4c859eSApple OSS Distributions 
1184*0f4c859eSApple OSS Distributions 	if (!IS_64BIT_PROCESS(p)) {
1185*0f4c859eSApple OSS Distributions 		ipcs_sz = sizeof(struct user32_IPCS_command);
1186*0f4c859eSApple OSS Distributions 		shmid_ds_sz = sizeof(struct user32_shmid_ds);
1187*0f4c859eSApple OSS Distributions 	}
1188*0f4c859eSApple OSS Distributions 
1189*0f4c859eSApple OSS Distributions 	/* Copy in the command structure */
1190*0f4c859eSApple OSS Distributions 	if ((error = SYSCTL_IN(req, &ipcs, ipcs_sz)) != 0) {
1191*0f4c859eSApple OSS Distributions 		goto ipcs_shm_sysctl_out;
1192*0f4c859eSApple OSS Distributions 	}
1193*0f4c859eSApple OSS Distributions 
1194*0f4c859eSApple OSS Distributions 	if (!IS_64BIT_PROCESS(p)) {     /* convert in place */
1195*0f4c859eSApple OSS Distributions 		ipcs.u64.ipcs_data = CAST_USER_ADDR_T(ipcs.u32.ipcs_data);
1196*0f4c859eSApple OSS Distributions 	}
1197*0f4c859eSApple OSS Distributions 
1198*0f4c859eSApple OSS Distributions 	/* Let us version this interface... */
1199*0f4c859eSApple OSS Distributions 	if (ipcs.u64.ipcs_magic != IPCS_MAGIC) {
1200*0f4c859eSApple OSS Distributions 		error = EINVAL;
1201*0f4c859eSApple OSS Distributions 		goto ipcs_shm_sysctl_out;
1202*0f4c859eSApple OSS Distributions 	}
1203*0f4c859eSApple OSS Distributions 
1204*0f4c859eSApple OSS Distributions 	switch (ipcs.u64.ipcs_op) {
1205*0f4c859eSApple OSS Distributions 	case IPCS_SHM_CONF:     /* Obtain global configuration data */
1206*0f4c859eSApple OSS Distributions 		if (ipcs.u64.ipcs_datalen != sizeof(struct shminfo)) {
1207*0f4c859eSApple OSS Distributions 			if (ipcs.u64.ipcs_cursor != 0) { /* fwd. compat. */
1208*0f4c859eSApple OSS Distributions 				error = ENOMEM;
1209*0f4c859eSApple OSS Distributions 				break;
1210*0f4c859eSApple OSS Distributions 			}
1211*0f4c859eSApple OSS Distributions 			error = ERANGE;
1212*0f4c859eSApple OSS Distributions 			break;
1213*0f4c859eSApple OSS Distributions 		}
1214*0f4c859eSApple OSS Distributions 		error = copyout(&shminfo, ipcs.u64.ipcs_data, ipcs.u64.ipcs_datalen);
1215*0f4c859eSApple OSS Distributions 		break;
1216*0f4c859eSApple OSS Distributions 
1217*0f4c859eSApple OSS Distributions 	case IPCS_SHM_ITER:     /* Iterate over existing segments */
1218*0f4c859eSApple OSS Distributions 		cursor = ipcs.u64.ipcs_cursor;
1219*0f4c859eSApple OSS Distributions 		if (cursor < 0 || cursor >= shminfo.shmmni) {
1220*0f4c859eSApple OSS Distributions 			error = ERANGE;
1221*0f4c859eSApple OSS Distributions 			break;
1222*0f4c859eSApple OSS Distributions 		}
1223*0f4c859eSApple OSS Distributions 		if (ipcs.u64.ipcs_datalen != (int)shmid_ds_sz) {
1224*0f4c859eSApple OSS Distributions 			error = EINVAL;
1225*0f4c859eSApple OSS Distributions 			break;
1226*0f4c859eSApple OSS Distributions 		}
1227*0f4c859eSApple OSS Distributions 		for (; cursor < shminfo.shmmni; cursor++) {
1228*0f4c859eSApple OSS Distributions 			if (shmsegs[cursor].u.shm_perm.mode & SHMSEG_ALLOCATED) {
1229*0f4c859eSApple OSS Distributions 				break;
1230*0f4c859eSApple OSS Distributions 			}
1231*0f4c859eSApple OSS Distributions 			continue;
1232*0f4c859eSApple OSS Distributions 		}
1233*0f4c859eSApple OSS Distributions 		if (cursor == shminfo.shmmni) {
1234*0f4c859eSApple OSS Distributions 			error = ENOENT;
1235*0f4c859eSApple OSS Distributions 			break;
1236*0f4c859eSApple OSS Distributions 		}
1237*0f4c859eSApple OSS Distributions 
1238*0f4c859eSApple OSS Distributions 		shmid_dsp = &shmsegs[cursor];   /* default: 64 bit */
1239*0f4c859eSApple OSS Distributions 
1240*0f4c859eSApple OSS Distributions 		/*
1241*0f4c859eSApple OSS Distributions 		 * If necessary, convert the 64 bit kernel segment
1242*0f4c859eSApple OSS Distributions 		 * descriptor to a 32 bit user one.
1243*0f4c859eSApple OSS Distributions 		 */
1244*0f4c859eSApple OSS Distributions 		if (!IS_64BIT_PROCESS(p)) {
1245*0f4c859eSApple OSS Distributions 			shmid_ds_64to32(shmid_dsp, &shmid_ds32);
1246*0f4c859eSApple OSS Distributions 
1247*0f4c859eSApple OSS Distributions 			/* Clear kernel reserved pointer before copying to user space */
1248*0f4c859eSApple OSS Distributions 			shmid_ds32.shm_internal = (user32_addr_t)0;
1249*0f4c859eSApple OSS Distributions 
1250*0f4c859eSApple OSS Distributions 			shmid_dsp = &shmid_ds32;
1251*0f4c859eSApple OSS Distributions 		} else {
1252*0f4c859eSApple OSS Distributions 			memcpy(&shmid_ds, shmid_dsp, sizeof(shmid_ds));
1253*0f4c859eSApple OSS Distributions 
1254*0f4c859eSApple OSS Distributions 			/* Clear kernel reserved pointer before copying to user space */
1255*0f4c859eSApple OSS Distributions 			shmid_ds.shm_internal = USER_ADDR_NULL;
1256*0f4c859eSApple OSS Distributions 
1257*0f4c859eSApple OSS Distributions 			shmid_dsp = &shmid_ds;
1258*0f4c859eSApple OSS Distributions 		}
1259*0f4c859eSApple OSS Distributions 		error = copyout(shmid_dsp, ipcs.u64.ipcs_data, ipcs.u64.ipcs_datalen);
1260*0f4c859eSApple OSS Distributions 		if (!error) {
1261*0f4c859eSApple OSS Distributions 			/* update cursor */
1262*0f4c859eSApple OSS Distributions 			ipcs.u64.ipcs_cursor = cursor + 1;
1263*0f4c859eSApple OSS Distributions 
1264*0f4c859eSApple OSS Distributions 			if (!IS_64BIT_PROCESS(p)) { /* convert in place */
1265*0f4c859eSApple OSS Distributions 				ipcs.u32.ipcs_data = CAST_DOWN_EXPLICIT(user32_addr_t, ipcs.u64.ipcs_data);
1266*0f4c859eSApple OSS Distributions 			}
1267*0f4c859eSApple OSS Distributions 
1268*0f4c859eSApple OSS Distributions 			error = SYSCTL_OUT(req, &ipcs, ipcs_sz);
1269*0f4c859eSApple OSS Distributions 		}
1270*0f4c859eSApple OSS Distributions 		break;
1271*0f4c859eSApple OSS Distributions 
1272*0f4c859eSApple OSS Distributions 	default:
1273*0f4c859eSApple OSS Distributions 		error = EINVAL;
1274*0f4c859eSApple OSS Distributions 		break;
1275*0f4c859eSApple OSS Distributions 	}
1276*0f4c859eSApple OSS Distributions ipcs_shm_sysctl_out:
1277*0f4c859eSApple OSS Distributions 	SYSV_SHM_SUBSYS_UNLOCK();
1278*0f4c859eSApple OSS Distributions 	return error;
1279*0f4c859eSApple OSS Distributions }
1280*0f4c859eSApple OSS Distributions 
1281*0f4c859eSApple OSS Distributions SYSCTL_NODE(_kern, KERN_SYSV, sysv, CTLFLAG_RW | CTLFLAG_LOCKED | CTLFLAG_ANYBODY, 0, "SYSV");
1282*0f4c859eSApple OSS Distributions 
1283*0f4c859eSApple OSS Distributions SYSCTL_PROC(_kern_sysv, OID_AUTO, shmmax, CTLTYPE_QUAD | CTLFLAG_RW | CTLFLAG_LOCKED,
1284*0f4c859eSApple OSS Distributions     &shminfo.shmmax, 0, &sysctl_shminfo, "Q", "shmmax");
1285*0f4c859eSApple OSS Distributions 
1286*0f4c859eSApple OSS Distributions SYSCTL_PROC(_kern_sysv, OID_AUTO, shmmin, CTLTYPE_QUAD | CTLFLAG_RW | CTLFLAG_LOCKED,
1287*0f4c859eSApple OSS Distributions     &shminfo.shmmin, 0, &sysctl_shminfo, "Q", "shmmin");
1288*0f4c859eSApple OSS Distributions 
1289*0f4c859eSApple OSS Distributions SYSCTL_PROC(_kern_sysv, OID_AUTO, shmmni, CTLTYPE_QUAD | CTLFLAG_RW | CTLFLAG_LOCKED,
1290*0f4c859eSApple OSS Distributions     &shminfo.shmmni, 0, &sysctl_shminfo, "Q", "shmmni");
1291*0f4c859eSApple OSS Distributions 
1292*0f4c859eSApple OSS Distributions SYSCTL_PROC(_kern_sysv, OID_AUTO, shmseg, CTLTYPE_QUAD | CTLFLAG_RW | CTLFLAG_LOCKED,
1293*0f4c859eSApple OSS Distributions     &shminfo.shmseg, 0, &sysctl_shminfo, "Q", "shmseg");
1294*0f4c859eSApple OSS Distributions 
1295*0f4c859eSApple OSS Distributions SYSCTL_PROC(_kern_sysv, OID_AUTO, shmall, CTLTYPE_QUAD | CTLFLAG_RW | CTLFLAG_LOCKED,
1296*0f4c859eSApple OSS Distributions     &shminfo.shmall, 0, &sysctl_shminfo, "Q", "shmall");
1297*0f4c859eSApple OSS Distributions 
1298*0f4c859eSApple OSS Distributions SYSCTL_NODE(_kern_sysv, OID_AUTO, ipcs, CTLFLAG_RW | CTLFLAG_LOCKED | CTLFLAG_ANYBODY, 0, "SYSVIPCS");
1299*0f4c859eSApple OSS Distributions 
1300*0f4c859eSApple OSS Distributions SYSCTL_PROC(_kern_sysv_ipcs, OID_AUTO, shm, CTLFLAG_RW | CTLFLAG_ANYBODY | CTLFLAG_LOCKED,
1301*0f4c859eSApple OSS Distributions     0, 0, IPCS_shm_sysctl,
1302*0f4c859eSApple OSS Distributions     "S,IPCS_shm_command",
1303*0f4c859eSApple OSS Distributions     "ipcs shm command interface");
1304*0f4c859eSApple OSS Distributions #endif /* SYSV_SHM */
1305*0f4c859eSApple OSS Distributions 
1306*0f4c859eSApple OSS Distributions /* DSEP Review Done pl-20051108-v02 @2743,@2908,@2913,@3009 */
1307