Changeset View
Changeset View
Standalone View
Standalone View
usr.bin/proccontrol/proccontrol.c
Show First 20 Lines • Show All 42 Lines • ▼ Show 20 Lines | enum { | ||||
MODE_INVALID, | MODE_INVALID, | ||||
MODE_TRACE, | MODE_TRACE, | ||||
MODE_TRAPCAP, | MODE_TRAPCAP, | ||||
MODE_PROTMAX, | MODE_PROTMAX, | ||||
MODE_STACKGAP, | MODE_STACKGAP, | ||||
#ifdef PROC_KPTI_CTL | #ifdef PROC_KPTI_CTL | ||||
MODE_KPTI, | MODE_KPTI, | ||||
#endif | #endif | ||||
MODE_LOGSIGEXIT, | |||||
}; | }; | ||||
static pid_t | static pid_t | ||||
str2pid(const char *str) | str2pid(const char *str) | ||||
{ | { | ||||
pid_t res; | pid_t res; | ||||
char *tail; | char *tail; | ||||
Show All 11 Lines | |||||
#define KPTI_USAGE | #define KPTI_USAGE | ||||
#endif | #endif | ||||
static void __dead2 | static void __dead2 | ||||
usage(void) | usage(void) | ||||
{ | { | ||||
fprintf(stderr, "Usage: proccontrol -m (aslr|protmax|trace|trapcap|" | fprintf(stderr, "Usage: proccontrol -m (aslr|protmax|trace|trapcap|" | ||||
"stackgap"KPTI_USAGE") [-q] " | "stackgap"KPTI_USAGE"|logsigexit) [-q] " | ||||
"[-s (enable|disable)] [-p pid | command]\n"); | "[-s (enable|disable)] [-p pid | command]\n"); | ||||
exit(1); | exit(1); | ||||
} | } | ||||
int | int | ||||
main(int argc, char *argv[]) | main(int argc, char *argv[]) | ||||
{ | { | ||||
int arg, ch, error, mode; | int arg, ch, error, mode; | ||||
Show All 16 Lines | case 'm': | ||||
else if (strcmp(optarg, "trapcap") == 0) | else if (strcmp(optarg, "trapcap") == 0) | ||||
mode = MODE_TRAPCAP; | mode = MODE_TRAPCAP; | ||||
else if (strcmp(optarg, "stackgap") == 0) | else if (strcmp(optarg, "stackgap") == 0) | ||||
mode = MODE_STACKGAP; | mode = MODE_STACKGAP; | ||||
#ifdef PROC_KPTI_CTL | #ifdef PROC_KPTI_CTL | ||||
else if (strcmp(optarg, "kpti") == 0) | else if (strcmp(optarg, "kpti") == 0) | ||||
mode = MODE_KPTI; | mode = MODE_KPTI; | ||||
#endif | #endif | ||||
else if (strcmp(optarg, "logsigexit") == 0) | |||||
mode = MODE_LOGSIGEXIT; | |||||
else | else | ||||
usage(); | usage(); | ||||
break; | break; | ||||
case 's': | case 's': | ||||
if (strcmp(optarg, "enable") == 0) | if (strcmp(optarg, "enable") == 0) | ||||
enable = true; | enable = true; | ||||
else if (strcmp(optarg, "disable") == 0) | else if (strcmp(optarg, "disable") == 0) | ||||
enable = false; | enable = false; | ||||
Show All 40 Lines | if (query) { | ||||
case MODE_STACKGAP: | case MODE_STACKGAP: | ||||
error = procctl(P_PID, pid, PROC_STACKGAP_STATUS, &arg); | error = procctl(P_PID, pid, PROC_STACKGAP_STATUS, &arg); | ||||
break; | break; | ||||
#ifdef PROC_KPTI_CTL | #ifdef PROC_KPTI_CTL | ||||
case MODE_KPTI: | case MODE_KPTI: | ||||
error = procctl(P_PID, pid, PROC_KPTI_STATUS, &arg); | error = procctl(P_PID, pid, PROC_KPTI_STATUS, &arg); | ||||
break; | break; | ||||
#endif | #endif | ||||
case MODE_LOGSIGEXIT: | |||||
error = procctl(P_PID, pid, PROC_LOGSIGEXIT_STATUS, | |||||
&arg); | |||||
break; | |||||
default: | default: | ||||
usage(); | usage(); | ||||
break; | break; | ||||
} | } | ||||
if (error != 0) | if (error != 0) | ||||
err(1, "procctl status"); | err(1, "procctl status"); | ||||
switch (mode) { | switch (mode) { | ||||
case MODE_ASLR: | case MODE_ASLR: | ||||
▲ Show 20 Lines • Show All 79 Lines • ▼ Show 20 Lines | case MODE_KPTI: | ||||
break; | break; | ||||
} | } | ||||
if ((arg & PROC_KPTI_STATUS_ACTIVE) != 0) | if ((arg & PROC_KPTI_STATUS_ACTIVE) != 0) | ||||
printf(", active\n"); | printf(", active\n"); | ||||
else | else | ||||
printf(", not active\n"); | printf(", not active\n"); | ||||
break; | break; | ||||
#endif | #endif | ||||
case MODE_LOGSIGEXIT: | |||||
switch (arg) { | |||||
case PROC_LOGSIGEXIT_CTL_NOFORCE: | |||||
printf("not forced\n"); | |||||
break; | |||||
case PROC_LOGSIGEXIT_CTL_FORCE_ENABLE: | |||||
printf("force enabled\n"); | |||||
break; | |||||
case PROC_LOGSIGEXIT_CTL_FORCE_DISABLE: | |||||
printf("force disabled\n"); | |||||
break; | |||||
} | } | ||||
break; | |||||
} | |||||
} else { | } else { | ||||
switch (mode) { | switch (mode) { | ||||
case MODE_ASLR: | case MODE_ASLR: | ||||
arg = enable ? PROC_ASLR_FORCE_ENABLE : | arg = enable ? PROC_ASLR_FORCE_ENABLE : | ||||
PROC_ASLR_FORCE_DISABLE; | PROC_ASLR_FORCE_DISABLE; | ||||
error = procctl(P_PID, pid, PROC_ASLR_CTL, &arg); | error = procctl(P_PID, pid, PROC_ASLR_CTL, &arg); | ||||
break; | break; | ||||
case MODE_TRACE: | case MODE_TRACE: | ||||
Show All 19 Lines | case MODE_STACKGAP: | ||||
break; | break; | ||||
#ifdef PROC_KPTI_CTL | #ifdef PROC_KPTI_CTL | ||||
case MODE_KPTI: | case MODE_KPTI: | ||||
arg = enable ? PROC_KPTI_CTL_ENABLE_ON_EXEC : | arg = enable ? PROC_KPTI_CTL_ENABLE_ON_EXEC : | ||||
PROC_KPTI_CTL_DISABLE_ON_EXEC; | PROC_KPTI_CTL_DISABLE_ON_EXEC; | ||||
error = procctl(P_PID, pid, PROC_KPTI_CTL, &arg); | error = procctl(P_PID, pid, PROC_KPTI_CTL, &arg); | ||||
break; | break; | ||||
#endif | #endif | ||||
case MODE_LOGSIGEXIT: | |||||
arg = enable ? PROC_LOGSIGEXIT_CTL_FORCE_ENABLE : | |||||
PROC_LOGSIGEXIT_CTL_FORCE_DISABLE; | |||||
error = procctl(P_PID, pid, PROC_LOGSIGEXIT_CTL, &arg); | |||||
break; | |||||
default: | default: | ||||
usage(); | usage(); | ||||
break; | break; | ||||
} | } | ||||
if (error != 0) | if (error != 0) | ||||
err(1, "procctl ctl"); | err(1, "procctl ctl"); | ||||
if (do_command) { | if (do_command) { | ||||
error = execvp(argv[0], argv); | error = execvp(argv[0], argv); | ||||
err(1, "exec"); | err(1, "exec"); | ||||
} | } | ||||
} | } | ||||
exit(0); | exit(0); | ||||
} | } |