Changeset View
Changeset View
Standalone View
Standalone View
usr.bin/proccontrol/proccontrol.c
Show All 39 Lines | |||||
enum { | enum { | ||||
MODE_ASLR, | MODE_ASLR, | ||||
MODE_INVALID, | MODE_INVALID, | ||||
MODE_TRACE, | MODE_TRACE, | ||||
MODE_TRAPCAP, | MODE_TRAPCAP, | ||||
MODE_PROTMAX, | MODE_PROTMAX, | ||||
MODE_STACKGAP, | MODE_STACKGAP, | ||||
MODE_NO_NEW_PRIVS, | |||||
#ifdef PROC_KPTI_CTL | #ifdef PROC_KPTI_CTL | ||||
MODE_KPTI, | MODE_KPTI, | ||||
#endif | #endif | ||||
#ifdef PROC_LA_CTL | #ifdef PROC_LA_CTL | ||||
MODE_LA57, | MODE_LA57, | ||||
MODE_LA48, | MODE_LA48, | ||||
#endif | #endif | ||||
}; | }; | ||||
Show All 23 Lines | |||||
#define LA_USAGE | #define LA_USAGE | ||||
#endif | #endif | ||||
static void __dead2 | static void __dead2 | ||||
usage(void) | usage(void) | ||||
{ | { | ||||
fprintf(stderr, "Usage: proccontrol -m (aslr|protmax|trace|trapcap|" | fprintf(stderr, "Usage: proccontrol -m (aslr|protmax|trace|trapcap|" | ||||
"stackgap"KPTI_USAGE LA_USAGE") [-q] " | "stackgap|nonewprivs"KPTI_USAGE LA_USAGE") [-q] " | ||||
"[-s (enable|disable)] [-p pid | command]\n"); | "[-s (enable|disable)] [-p pid | command]\n"); | ||||
exit(1); | exit(1); | ||||
} | } | ||||
int | int | ||||
main(int argc, char *argv[]) | main(int argc, char *argv[]) | ||||
{ | { | ||||
int arg, ch, error, mode; | int arg, ch, error, mode; | ||||
Show All 12 Lines | case 'm': | ||||
else if (strcmp(optarg, "protmax") == 0) | else if (strcmp(optarg, "protmax") == 0) | ||||
mode = MODE_PROTMAX; | mode = MODE_PROTMAX; | ||||
else if (strcmp(optarg, "trace") == 0) | else if (strcmp(optarg, "trace") == 0) | ||||
mode = MODE_TRACE; | mode = MODE_TRACE; | ||||
else if (strcmp(optarg, "trapcap") == 0) | else if (strcmp(optarg, "trapcap") == 0) | ||||
mode = MODE_TRAPCAP; | mode = MODE_TRAPCAP; | ||||
else if (strcmp(optarg, "stackgap") == 0) | else if (strcmp(optarg, "stackgap") == 0) | ||||
mode = MODE_STACKGAP; | mode = MODE_STACKGAP; | ||||
else if (strcmp(optarg, "nonewprivs") == 0) | |||||
mode = MODE_NO_NEW_PRIVS; | |||||
#ifdef PROC_KPTI_CTL | #ifdef PROC_KPTI_CTL | ||||
else if (strcmp(optarg, "kpti") == 0) | else if (strcmp(optarg, "kpti") == 0) | ||||
mode = MODE_KPTI; | mode = MODE_KPTI; | ||||
#endif | #endif | ||||
#ifdef PROC_LA_CTL | #ifdef PROC_LA_CTL | ||||
else if (strcmp(optarg, "la57") == 0) | else if (strcmp(optarg, "la57") == 0) | ||||
mode = MODE_LA57; | mode = MODE_LA57; | ||||
else if (strcmp(optarg, "la48") == 0) | else if (strcmp(optarg, "la48") == 0) | ||||
▲ Show 20 Lines • Show All 45 Lines • ▼ Show 20 Lines | case MODE_TRAPCAP: | ||||
error = procctl(P_PID, pid, PROC_TRAPCAP_STATUS, &arg); | error = procctl(P_PID, pid, PROC_TRAPCAP_STATUS, &arg); | ||||
break; | break; | ||||
case MODE_PROTMAX: | case MODE_PROTMAX: | ||||
error = procctl(P_PID, pid, PROC_PROTMAX_STATUS, &arg); | error = procctl(P_PID, pid, PROC_PROTMAX_STATUS, &arg); | ||||
break; | break; | ||||
case MODE_STACKGAP: | case MODE_STACKGAP: | ||||
error = procctl(P_PID, pid, PROC_STACKGAP_STATUS, &arg); | error = procctl(P_PID, pid, PROC_STACKGAP_STATUS, &arg); | ||||
break; | break; | ||||
case MODE_NO_NEW_PRIVS: | |||||
error = procctl(P_PID, pid, PROC_NO_NEW_PRIVS_STATUS, &arg); | |||||
break; | |||||
#ifdef PROC_KPTI_CTL | #ifdef PROC_KPTI_CTL | ||||
case MODE_KPTI: | case MODE_KPTI: | ||||
error = procctl(P_PID, pid, PROC_KPTI_STATUS, &arg); | error = procctl(P_PID, pid, PROC_KPTI_STATUS, &arg); | ||||
break; | break; | ||||
#endif | #endif | ||||
#ifdef PROC_LA_CTL | #ifdef PROC_LA_CTL | ||||
case MODE_LA57: | case MODE_LA57: | ||||
case MODE_LA48: | case MODE_LA48: | ||||
▲ Show 20 Lines • Show All 74 Lines • ▼ Show 20 Lines | case MODE_STACKGAP: | ||||
case PROC_STACKGAP_ENABLE_EXEC: | case PROC_STACKGAP_ENABLE_EXEC: | ||||
printf("enabled after exec\n"); | printf("enabled after exec\n"); | ||||
break; | break; | ||||
case PROC_STACKGAP_DISABLE_EXEC: | case PROC_STACKGAP_DISABLE_EXEC: | ||||
printf("disabled after exec\n"); | printf("disabled after exec\n"); | ||||
break; | break; | ||||
} | } | ||||
break; | break; | ||||
case MODE_NO_NEW_PRIVS: | |||||
switch (arg) { | |||||
case PROC_NO_NEW_PRIVS_ENABLE: | |||||
printf("enabled\n"); | |||||
break; | |||||
case PROC_NO_NEW_PRIVS_DISABLE: | |||||
printf("disabled\n"); | |||||
break; | |||||
} | |||||
break; | |||||
#ifdef PROC_KPTI_CTL | #ifdef PROC_KPTI_CTL | ||||
case MODE_KPTI: | case MODE_KPTI: | ||||
switch (arg & ~PROC_KPTI_STATUS_ACTIVE) { | switch (arg & ~PROC_KPTI_STATUS_ACTIVE) { | ||||
case PROC_KPTI_CTL_ENABLE_ON_EXEC: | case PROC_KPTI_CTL_ENABLE_ON_EXEC: | ||||
printf("enabled"); | printf("enabled"); | ||||
break; | break; | ||||
case PROC_KPTI_CTL_DISABLE_ON_EXEC: | case PROC_KPTI_CTL_DISABLE_ON_EXEC: | ||||
printf("disabled"); | printf("disabled"); | ||||
▲ Show 20 Lines • Show All 49 Lines • ▼ Show 20 Lines | case MODE_PROTMAX: | ||||
PROC_PROTMAX_FORCE_DISABLE; | PROC_PROTMAX_FORCE_DISABLE; | ||||
error = procctl(P_PID, pid, PROC_PROTMAX_CTL, &arg); | error = procctl(P_PID, pid, PROC_PROTMAX_CTL, &arg); | ||||
break; | break; | ||||
case MODE_STACKGAP: | case MODE_STACKGAP: | ||||
arg = enable ? PROC_STACKGAP_ENABLE_EXEC : | arg = enable ? PROC_STACKGAP_ENABLE_EXEC : | ||||
(PROC_STACKGAP_DISABLE | | (PROC_STACKGAP_DISABLE | | ||||
PROC_STACKGAP_DISABLE_EXEC); | PROC_STACKGAP_DISABLE_EXEC); | ||||
error = procctl(P_PID, pid, PROC_STACKGAP_CTL, &arg); | error = procctl(P_PID, pid, PROC_STACKGAP_CTL, &arg); | ||||
break; | |||||
case MODE_NO_NEW_PRIVS: | |||||
arg = enable ? PROC_NO_NEW_PRIVS_ENABLE : | |||||
PROC_NO_NEW_PRIVS_DISABLE; | |||||
error = procctl(P_PID, pid, PROC_NO_NEW_PRIVS_CTL, &arg); | |||||
break; | break; | ||||
#ifdef PROC_KPTI_CTL | #ifdef PROC_KPTI_CTL | ||||
case MODE_KPTI: | case MODE_KPTI: | ||||
arg = enable ? PROC_KPTI_CTL_ENABLE_ON_EXEC : | arg = enable ? PROC_KPTI_CTL_ENABLE_ON_EXEC : | ||||
PROC_KPTI_CTL_DISABLE_ON_EXEC; | PROC_KPTI_CTL_DISABLE_ON_EXEC; | ||||
error = procctl(P_PID, pid, PROC_KPTI_CTL, &arg); | error = procctl(P_PID, pid, PROC_KPTI_CTL, &arg); | ||||
break; | break; | ||||
#endif | #endif | ||||
Show All 25 Lines |