Deleted Added
full compact
kern_mib.c (127911) kern_mib.c (140676)
1/*-
2 * Copyright (c) 1982, 1986, 1989, 1993
3 * The Regents of the University of California. All rights reserved.
4 *
5 * This code is derived from software contributed to Berkeley by
6 * Mike Karels at Berkeley Software Design, Inc.
7 *
8 * Quite extensively rewritten by Poul-Henning Kamp of the FreeBSD
9 * project, to make these variables more userfriendly.
10 *
11 * Redistribution and use in source and binary forms, with or without
12 * modification, are permitted provided that the following conditions
13 * are met:
14 * 1. Redistributions of source code must retain the above copyright
15 * notice, this list of conditions and the following disclaimer.
16 * 2. Redistributions in binary form must reproduce the above copyright
17 * notice, this list of conditions and the following disclaimer in the
18 * documentation and/or other materials provided with the distribution.
19 * 4. Neither the name of the University nor the names of its contributors
20 * may be used to endorse or promote products derived from this software
21 * without specific prior written permission.
22 *
23 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
24 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
27 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33 * SUCH DAMAGE.
34 *
35 * @(#)kern_sysctl.c 8.4 (Berkeley) 4/14/94
36 */
37
38#include <sys/cdefs.h>
1/*-
2 * Copyright (c) 1982, 1986, 1989, 1993
3 * The Regents of the University of California. All rights reserved.
4 *
5 * This code is derived from software contributed to Berkeley by
6 * Mike Karels at Berkeley Software Design, Inc.
7 *
8 * Quite extensively rewritten by Poul-Henning Kamp of the FreeBSD
9 * project, to make these variables more userfriendly.
10 *
11 * Redistribution and use in source and binary forms, with or without
12 * modification, are permitted provided that the following conditions
13 * are met:
14 * 1. Redistributions of source code must retain the above copyright
15 * notice, this list of conditions and the following disclaimer.
16 * 2. Redistributions in binary form must reproduce the above copyright
17 * notice, this list of conditions and the following disclaimer in the
18 * documentation and/or other materials provided with the distribution.
19 * 4. Neither the name of the University nor the names of its contributors
20 * may be used to endorse or promote products derived from this software
21 * without specific prior written permission.
22 *
23 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
24 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
27 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33 * SUCH DAMAGE.
34 *
35 * @(#)kern_sysctl.c 8.4 (Berkeley) 4/14/94
36 */
37
38#include <sys/cdefs.h>
39__FBSDID("$FreeBSD: head/sys/kern/kern_mib.c 127911 2004-04-05 21:03:37Z imp $");
39__FBSDID("$FreeBSD: head/sys/kern/kern_mib.c 140676 2005-01-23 20:59:19Z rwatson $");
40
41#include "opt_posix.h"
42
43#include <sys/param.h>
44#include <sys/kernel.h>
45#include <sys/systm.h>
46#include <sys/sysctl.h>
47#include <sys/proc.h>
48#include <sys/lock.h>
49#include <sys/mutex.h>
50#include <sys/jail.h>
51#include <sys/smp.h>
52#include <sys/unistd.h>
53
54SYSCTL_NODE(, 0, sysctl, CTLFLAG_RW, 0,
55 "Sysctl internal magic");
56SYSCTL_NODE(, CTL_KERN, kern, CTLFLAG_RW, 0,
57 "High kernel, proc, limits &c");
58SYSCTL_NODE(, CTL_VM, vm, CTLFLAG_RW, 0,
59 "Virtual memory");
60SYSCTL_NODE(, CTL_VFS, vfs, CTLFLAG_RW, 0,
61 "File system");
62SYSCTL_NODE(, CTL_NET, net, CTLFLAG_RW, 0,
63 "Network, (see socket.h)");
64SYSCTL_NODE(, CTL_DEBUG, debug, CTLFLAG_RW, 0,
65 "Debugging");
66SYSCTL_NODE(_debug, OID_AUTO, sizeof, CTLFLAG_RW, 0,
67 "Sizeof various things");
68SYSCTL_NODE(, CTL_HW, hw, CTLFLAG_RW, 0,
69 "hardware");
70SYSCTL_NODE(, CTL_MACHDEP, machdep, CTLFLAG_RW, 0,
71 "machine dependent");
72SYSCTL_NODE(, CTL_USER, user, CTLFLAG_RW, 0,
73 "user-level");
74SYSCTL_NODE(, CTL_P1003_1B, p1003_1b, CTLFLAG_RW, 0,
75 "p1003_1b, (see p1003_1b.h)");
76
77SYSCTL_NODE(, OID_AUTO, compat, CTLFLAG_RW, 0,
78 "Compatibility code");
79SYSCTL_NODE(, OID_AUTO, security, CTLFLAG_RW, 0,
80 "Security");
81#ifdef REGRESSION
82SYSCTL_NODE(, OID_AUTO, regression, CTLFLAG_RW, 0,
83 "Regression test MIB");
84#endif
85
86SYSCTL_STRING(_kern, OID_AUTO, ident, CTLFLAG_RD,
87 kern_ident, 0, "Kernel identifier");
88
89SYSCTL_STRING(_kern, KERN_OSRELEASE, osrelease, CTLFLAG_RD,
90 osrelease, 0, "Operating system release");
91
92SYSCTL_INT(_kern, KERN_OSREV, osrevision, CTLFLAG_RD,
93 0, BSD, "Operating system revision");
94
95SYSCTL_STRING(_kern, KERN_VERSION, version, CTLFLAG_RD,
96 version, 0, "Kernel version");
97
98SYSCTL_STRING(_kern, KERN_OSTYPE, ostype, CTLFLAG_RD,
99 ostype, 0, "Operating system type");
100
101/*
102 * NOTICE: The *userland* release date is available in
103 * /usr/include/osreldate.h
104 */
105extern int osreldate;
106SYSCTL_INT(_kern, KERN_OSRELDATE, osreldate, CTLFLAG_RD,
107 &osreldate, 0, "Kernel release date");
108
109SYSCTL_INT(_kern, KERN_MAXPROC, maxproc, CTLFLAG_RDTUN,
110 &maxproc, 0, "Maximum number of processes");
111
112SYSCTL_INT(_kern, KERN_MAXPROCPERUID, maxprocperuid, CTLFLAG_RW,
113 &maxprocperuid, 0, "Maximum processes allowed per userid");
114
115SYSCTL_INT(_kern, OID_AUTO, maxusers, CTLFLAG_RDTUN,
116 &maxusers, 0, "Hint for kernel tuning");
117
118SYSCTL_INT(_kern, KERN_ARGMAX, argmax, CTLFLAG_RD,
119 0, ARG_MAX, "Maximum bytes of argument to execve(2)");
120
121SYSCTL_INT(_kern, KERN_POSIX1, posix1version, CTLFLAG_RD,
122 0, _POSIX_VERSION, "Version of POSIX attempting to comply to");
123
124SYSCTL_INT(_kern, KERN_NGROUPS, ngroups, CTLFLAG_RD,
125 0, NGROUPS_MAX, "Maximum number of groups a user can belong to");
126
127SYSCTL_INT(_kern, KERN_JOB_CONTROL, job_control, CTLFLAG_RD,
128 0, 1, "Whether job control is available");
129
130#ifdef _POSIX_SAVED_IDS
131SYSCTL_INT(_kern, KERN_SAVED_IDS, saved_ids, CTLFLAG_RD,
132 0, 1, "Whether saved set-group/user ID is available");
133#else
134SYSCTL_INT(_kern, KERN_SAVED_IDS, saved_ids, CTLFLAG_RD,
135 0, 0, "Whether saved set-group/user ID is available");
136#endif
137
138char kernelname[MAXPATHLEN] = "/kernel"; /* XXX bloat */
139
140SYSCTL_STRING(_kern, KERN_BOOTFILE, bootfile, CTLFLAG_RW,
141 kernelname, sizeof kernelname, "Name of kernel file booted");
142
143#ifdef SMP
144SYSCTL_INT(_hw, HW_NCPU, ncpu, CTLFLAG_RD,
145 &mp_ncpus, 0, "Number of active CPUs");
146#else
147SYSCTL_INT(_hw, HW_NCPU, ncpu, CTLFLAG_RD,
148 0, 1, "Number of active CPUs");
149#endif
150
151SYSCTL_INT(_hw, HW_BYTEORDER, byteorder, CTLFLAG_RD,
152 0, BYTE_ORDER, "System byte order");
153
154SYSCTL_INT(_hw, HW_PAGESIZE, pagesize, CTLFLAG_RD,
155 0, PAGE_SIZE, "System memory page size");
156
157static int
158sysctl_hw_physmem(SYSCTL_HANDLER_ARGS)
159{
160 u_long val;
161
162 val = ctob(physmem);
163 return (sysctl_handle_long(oidp, &val, 0, req));
164}
165
166SYSCTL_PROC(_hw, HW_PHYSMEM, physmem, CTLTYPE_ULONG | CTLFLAG_RD,
167 0, 0, sysctl_hw_physmem, "LU", "");
168
169static int
170sysctl_hw_usermem(SYSCTL_HANDLER_ARGS)
171{
172 u_long val;
173
174 val = ctob(physmem - cnt.v_wire_count);
175 return (sysctl_handle_long(oidp, &val, 0, req));
176}
177
178SYSCTL_PROC(_hw, HW_USERMEM, usermem, CTLTYPE_ULONG | CTLFLAG_RD,
179 0, 0, sysctl_hw_usermem, "LU", "");
180
181SYSCTL_ULONG(_hw, OID_AUTO, availpages, CTLFLAG_RD, &physmem, 0, "");
182
183static char machine_arch[] = MACHINE_ARCH;
184SYSCTL_STRING(_hw, HW_MACHINE_ARCH, machine_arch, CTLFLAG_RD,
185 machine_arch, 0, "System architecture");
186
187char hostname[MAXHOSTNAMELEN];
188
189static int
190sysctl_hostname(SYSCTL_HANDLER_ARGS)
191{
192 struct prison *pr;
193 char tmphostname[MAXHOSTNAMELEN];
194 int error;
195
196 pr = req->td->td_ucred->cr_prison;
197 if (pr != NULL) {
198 if (!jail_set_hostname_allowed && req->newptr)
199 return (EPERM);
200 /*
201 * Process is in jail, so make a local copy of jail
202 * hostname to get/set so we don't have to hold the jail
203 * mutex during the sysctl copyin/copyout activities.
204 */
205 mtx_lock(&pr->pr_mtx);
206 bcopy(pr->pr_host, tmphostname, MAXHOSTNAMELEN);
207 mtx_unlock(&pr->pr_mtx);
208
209 error = sysctl_handle_string(oidp, tmphostname,
210 sizeof pr->pr_host, req);
211
212 if (req->newptr != NULL && error == 0) {
213 /*
214 * Copy the locally set hostname to the jail, if
215 * appropriate.
216 */
217 mtx_lock(&pr->pr_mtx);
218 bcopy(tmphostname, pr->pr_host, MAXHOSTNAMELEN);
219 mtx_unlock(&pr->pr_mtx);
220 }
221 } else
222 error = sysctl_handle_string(oidp,
223 hostname, sizeof hostname, req);
224 return (error);
225}
226
227SYSCTL_PROC(_kern, KERN_HOSTNAME, hostname,
228 CTLTYPE_STRING|CTLFLAG_RW|CTLFLAG_PRISON,
229 0, 0, sysctl_hostname, "A", "Hostname");
230
231static int regression_securelevel_nonmonotonic = 0;
232
233#ifdef REGRESSION
234SYSCTL_INT(_regression, OID_AUTO, securelevel_nonmonotonic, CTLFLAG_RW,
235 &regression_securelevel_nonmonotonic, 0, "securelevel may be lowered");
236#endif
237
238int securelevel = -1;
239static struct mtx securelevel_mtx;
240
241MTX_SYSINIT(securelevel_lock, &securelevel_mtx, "securelevel mutex lock",
242 MTX_DEF);
243
244static int
245sysctl_kern_securelvl(SYSCTL_HANDLER_ARGS)
246{
247 struct prison *pr;
248 int error, level;
249
250 pr = req->td->td_ucred->cr_prison;
251
252 /*
253 * If the process is in jail, return the maximum of the global and
40
41#include "opt_posix.h"
42
43#include <sys/param.h>
44#include <sys/kernel.h>
45#include <sys/systm.h>
46#include <sys/sysctl.h>
47#include <sys/proc.h>
48#include <sys/lock.h>
49#include <sys/mutex.h>
50#include <sys/jail.h>
51#include <sys/smp.h>
52#include <sys/unistd.h>
53
54SYSCTL_NODE(, 0, sysctl, CTLFLAG_RW, 0,
55 "Sysctl internal magic");
56SYSCTL_NODE(, CTL_KERN, kern, CTLFLAG_RW, 0,
57 "High kernel, proc, limits &c");
58SYSCTL_NODE(, CTL_VM, vm, CTLFLAG_RW, 0,
59 "Virtual memory");
60SYSCTL_NODE(, CTL_VFS, vfs, CTLFLAG_RW, 0,
61 "File system");
62SYSCTL_NODE(, CTL_NET, net, CTLFLAG_RW, 0,
63 "Network, (see socket.h)");
64SYSCTL_NODE(, CTL_DEBUG, debug, CTLFLAG_RW, 0,
65 "Debugging");
66SYSCTL_NODE(_debug, OID_AUTO, sizeof, CTLFLAG_RW, 0,
67 "Sizeof various things");
68SYSCTL_NODE(, CTL_HW, hw, CTLFLAG_RW, 0,
69 "hardware");
70SYSCTL_NODE(, CTL_MACHDEP, machdep, CTLFLAG_RW, 0,
71 "machine dependent");
72SYSCTL_NODE(, CTL_USER, user, CTLFLAG_RW, 0,
73 "user-level");
74SYSCTL_NODE(, CTL_P1003_1B, p1003_1b, CTLFLAG_RW, 0,
75 "p1003_1b, (see p1003_1b.h)");
76
77SYSCTL_NODE(, OID_AUTO, compat, CTLFLAG_RW, 0,
78 "Compatibility code");
79SYSCTL_NODE(, OID_AUTO, security, CTLFLAG_RW, 0,
80 "Security");
81#ifdef REGRESSION
82SYSCTL_NODE(, OID_AUTO, regression, CTLFLAG_RW, 0,
83 "Regression test MIB");
84#endif
85
86SYSCTL_STRING(_kern, OID_AUTO, ident, CTLFLAG_RD,
87 kern_ident, 0, "Kernel identifier");
88
89SYSCTL_STRING(_kern, KERN_OSRELEASE, osrelease, CTLFLAG_RD,
90 osrelease, 0, "Operating system release");
91
92SYSCTL_INT(_kern, KERN_OSREV, osrevision, CTLFLAG_RD,
93 0, BSD, "Operating system revision");
94
95SYSCTL_STRING(_kern, KERN_VERSION, version, CTLFLAG_RD,
96 version, 0, "Kernel version");
97
98SYSCTL_STRING(_kern, KERN_OSTYPE, ostype, CTLFLAG_RD,
99 ostype, 0, "Operating system type");
100
101/*
102 * NOTICE: The *userland* release date is available in
103 * /usr/include/osreldate.h
104 */
105extern int osreldate;
106SYSCTL_INT(_kern, KERN_OSRELDATE, osreldate, CTLFLAG_RD,
107 &osreldate, 0, "Kernel release date");
108
109SYSCTL_INT(_kern, KERN_MAXPROC, maxproc, CTLFLAG_RDTUN,
110 &maxproc, 0, "Maximum number of processes");
111
112SYSCTL_INT(_kern, KERN_MAXPROCPERUID, maxprocperuid, CTLFLAG_RW,
113 &maxprocperuid, 0, "Maximum processes allowed per userid");
114
115SYSCTL_INT(_kern, OID_AUTO, maxusers, CTLFLAG_RDTUN,
116 &maxusers, 0, "Hint for kernel tuning");
117
118SYSCTL_INT(_kern, KERN_ARGMAX, argmax, CTLFLAG_RD,
119 0, ARG_MAX, "Maximum bytes of argument to execve(2)");
120
121SYSCTL_INT(_kern, KERN_POSIX1, posix1version, CTLFLAG_RD,
122 0, _POSIX_VERSION, "Version of POSIX attempting to comply to");
123
124SYSCTL_INT(_kern, KERN_NGROUPS, ngroups, CTLFLAG_RD,
125 0, NGROUPS_MAX, "Maximum number of groups a user can belong to");
126
127SYSCTL_INT(_kern, KERN_JOB_CONTROL, job_control, CTLFLAG_RD,
128 0, 1, "Whether job control is available");
129
130#ifdef _POSIX_SAVED_IDS
131SYSCTL_INT(_kern, KERN_SAVED_IDS, saved_ids, CTLFLAG_RD,
132 0, 1, "Whether saved set-group/user ID is available");
133#else
134SYSCTL_INT(_kern, KERN_SAVED_IDS, saved_ids, CTLFLAG_RD,
135 0, 0, "Whether saved set-group/user ID is available");
136#endif
137
138char kernelname[MAXPATHLEN] = "/kernel"; /* XXX bloat */
139
140SYSCTL_STRING(_kern, KERN_BOOTFILE, bootfile, CTLFLAG_RW,
141 kernelname, sizeof kernelname, "Name of kernel file booted");
142
143#ifdef SMP
144SYSCTL_INT(_hw, HW_NCPU, ncpu, CTLFLAG_RD,
145 &mp_ncpus, 0, "Number of active CPUs");
146#else
147SYSCTL_INT(_hw, HW_NCPU, ncpu, CTLFLAG_RD,
148 0, 1, "Number of active CPUs");
149#endif
150
151SYSCTL_INT(_hw, HW_BYTEORDER, byteorder, CTLFLAG_RD,
152 0, BYTE_ORDER, "System byte order");
153
154SYSCTL_INT(_hw, HW_PAGESIZE, pagesize, CTLFLAG_RD,
155 0, PAGE_SIZE, "System memory page size");
156
157static int
158sysctl_hw_physmem(SYSCTL_HANDLER_ARGS)
159{
160 u_long val;
161
162 val = ctob(physmem);
163 return (sysctl_handle_long(oidp, &val, 0, req));
164}
165
166SYSCTL_PROC(_hw, HW_PHYSMEM, physmem, CTLTYPE_ULONG | CTLFLAG_RD,
167 0, 0, sysctl_hw_physmem, "LU", "");
168
169static int
170sysctl_hw_usermem(SYSCTL_HANDLER_ARGS)
171{
172 u_long val;
173
174 val = ctob(physmem - cnt.v_wire_count);
175 return (sysctl_handle_long(oidp, &val, 0, req));
176}
177
178SYSCTL_PROC(_hw, HW_USERMEM, usermem, CTLTYPE_ULONG | CTLFLAG_RD,
179 0, 0, sysctl_hw_usermem, "LU", "");
180
181SYSCTL_ULONG(_hw, OID_AUTO, availpages, CTLFLAG_RD, &physmem, 0, "");
182
183static char machine_arch[] = MACHINE_ARCH;
184SYSCTL_STRING(_hw, HW_MACHINE_ARCH, machine_arch, CTLFLAG_RD,
185 machine_arch, 0, "System architecture");
186
187char hostname[MAXHOSTNAMELEN];
188
189static int
190sysctl_hostname(SYSCTL_HANDLER_ARGS)
191{
192 struct prison *pr;
193 char tmphostname[MAXHOSTNAMELEN];
194 int error;
195
196 pr = req->td->td_ucred->cr_prison;
197 if (pr != NULL) {
198 if (!jail_set_hostname_allowed && req->newptr)
199 return (EPERM);
200 /*
201 * Process is in jail, so make a local copy of jail
202 * hostname to get/set so we don't have to hold the jail
203 * mutex during the sysctl copyin/copyout activities.
204 */
205 mtx_lock(&pr->pr_mtx);
206 bcopy(pr->pr_host, tmphostname, MAXHOSTNAMELEN);
207 mtx_unlock(&pr->pr_mtx);
208
209 error = sysctl_handle_string(oidp, tmphostname,
210 sizeof pr->pr_host, req);
211
212 if (req->newptr != NULL && error == 0) {
213 /*
214 * Copy the locally set hostname to the jail, if
215 * appropriate.
216 */
217 mtx_lock(&pr->pr_mtx);
218 bcopy(tmphostname, pr->pr_host, MAXHOSTNAMELEN);
219 mtx_unlock(&pr->pr_mtx);
220 }
221 } else
222 error = sysctl_handle_string(oidp,
223 hostname, sizeof hostname, req);
224 return (error);
225}
226
227SYSCTL_PROC(_kern, KERN_HOSTNAME, hostname,
228 CTLTYPE_STRING|CTLFLAG_RW|CTLFLAG_PRISON,
229 0, 0, sysctl_hostname, "A", "Hostname");
230
231static int regression_securelevel_nonmonotonic = 0;
232
233#ifdef REGRESSION
234SYSCTL_INT(_regression, OID_AUTO, securelevel_nonmonotonic, CTLFLAG_RW,
235 &regression_securelevel_nonmonotonic, 0, "securelevel may be lowered");
236#endif
237
238int securelevel = -1;
239static struct mtx securelevel_mtx;
240
241MTX_SYSINIT(securelevel_lock, &securelevel_mtx, "securelevel mutex lock",
242 MTX_DEF);
243
244static int
245sysctl_kern_securelvl(SYSCTL_HANDLER_ARGS)
246{
247 struct prison *pr;
248 int error, level;
249
250 pr = req->td->td_ucred->cr_prison;
251
252 /*
253 * If the process is in jail, return the maximum of the global and
254 * local levels; otherwise, return the global level.
254 * local levels; otherwise, return the global level. Perform a
255 * lockless read since the securelevel is an interger.
255 */
256 */
256 if (pr != NULL) {
257 mtx_lock(&pr->pr_mtx);
257 if (pr != NULL)
258 level = imax(securelevel, pr->pr_securelevel);
258 level = imax(securelevel, pr->pr_securelevel);
259 mtx_unlock(&pr->pr_mtx);
260 } else
259 else
261 level = securelevel;
262 error = sysctl_handle_int(oidp, &level, 0, req);
263 if (error || !req->newptr)
264 return (error);
265 /*
266 * Permit update only if the new securelevel exceeds the
267 * global level, and local level if any.
268 */
269 if (pr != NULL) {
270 mtx_lock(&pr->pr_mtx);
271 if (!regression_securelevel_nonmonotonic &&
272 (level < imax(securelevel, pr->pr_securelevel))) {
273 mtx_unlock(&pr->pr_mtx);
274 return (EPERM);
275 }
276 pr->pr_securelevel = level;
277 mtx_unlock(&pr->pr_mtx);
278 } else {
279 mtx_lock(&securelevel_mtx);
280 if (!regression_securelevel_nonmonotonic &&
281 (level < securelevel)) {
282 mtx_unlock(&securelevel_mtx);
283 return (EPERM);
284 }
285 securelevel = level;
286 mtx_unlock(&securelevel_mtx);
287 }
288 return (error);
289}
290
291SYSCTL_PROC(_kern, KERN_SECURELVL, securelevel,
292 CTLTYPE_INT|CTLFLAG_RW|CTLFLAG_PRISON, 0, 0, sysctl_kern_securelvl,
293 "I", "Current secure level");
294
295char domainname[MAXHOSTNAMELEN];
296SYSCTL_STRING(_kern, KERN_NISDOMAINNAME, domainname, CTLFLAG_RW,
297 &domainname, sizeof(domainname), "Name of the current YP/NIS domain");
298
299u_long hostid;
300SYSCTL_ULONG(_kern, KERN_HOSTID, hostid, CTLFLAG_RW, &hostid, 0, "Host ID");
301
302/*
303 * This is really cheating. These actually live in the libc, something
304 * which I'm not quite sure is a good idea anyway, but in order for
305 * getnext and friends to actually work, we define dummies here.
306 */
307SYSCTL_STRING(_user, USER_CS_PATH, cs_path, CTLFLAG_RD,
308 "", 0, "PATH that finds all the standard utilities");
309SYSCTL_INT(_user, USER_BC_BASE_MAX, bc_base_max, CTLFLAG_RD,
310 0, 0, "Max ibase/obase values in bc(1)");
311SYSCTL_INT(_user, USER_BC_DIM_MAX, bc_dim_max, CTLFLAG_RD,
312 0, 0, "Max array size in bc(1)");
313SYSCTL_INT(_user, USER_BC_SCALE_MAX, bc_scale_max, CTLFLAG_RD,
314 0, 0, "Max scale value in bc(1)");
315SYSCTL_INT(_user, USER_BC_STRING_MAX, bc_string_max, CTLFLAG_RD,
316 0, 0, "Max string length in bc(1)");
317SYSCTL_INT(_user, USER_COLL_WEIGHTS_MAX, coll_weights_max, CTLFLAG_RD,
318 0, 0, "Maximum number of weights assigned to an LC_COLLATE locale entry");
319SYSCTL_INT(_user, USER_EXPR_NEST_MAX, expr_nest_max, CTLFLAG_RD, 0, 0, "");
320SYSCTL_INT(_user, USER_LINE_MAX, line_max, CTLFLAG_RD,
321 0, 0, "Max length (bytes) of a text-processing utility's input line");
322SYSCTL_INT(_user, USER_RE_DUP_MAX, re_dup_max, CTLFLAG_RD,
323 0, 0, "Maximum number of repeats of a regexp permitted");
324SYSCTL_INT(_user, USER_POSIX2_VERSION, posix2_version, CTLFLAG_RD,
325 0, 0,
326 "The version of POSIX 1003.2 with which the system attempts to comply");
327SYSCTL_INT(_user, USER_POSIX2_C_BIND, posix2_c_bind, CTLFLAG_RD,
328 0, 0, "Whether C development supports the C bindings option");
329SYSCTL_INT(_user, USER_POSIX2_C_DEV, posix2_c_dev, CTLFLAG_RD,
330 0, 0, "Whether system supports the C development utilities option");
331SYSCTL_INT(_user, USER_POSIX2_CHAR_TERM, posix2_char_term, CTLFLAG_RD,
332 0, 0, "");
333SYSCTL_INT(_user, USER_POSIX2_FORT_DEV, posix2_fort_dev, CTLFLAG_RD,
334 0, 0, "Whether system supports FORTRAN development utilities");
335SYSCTL_INT(_user, USER_POSIX2_FORT_RUN, posix2_fort_run, CTLFLAG_RD,
336 0, 0, "Whether system supports FORTRAN runtime utilities");
337SYSCTL_INT(_user, USER_POSIX2_LOCALEDEF, posix2_localedef, CTLFLAG_RD,
338 0, 0, "Whether system supports creation of locales");
339SYSCTL_INT(_user, USER_POSIX2_SW_DEV, posix2_sw_dev, CTLFLAG_RD,
340 0, 0, "Whether system supports software development utilities");
341SYSCTL_INT(_user, USER_POSIX2_UPE, posix2_upe, CTLFLAG_RD,
342 0, 0, "Whether system supports the user portability utilities");
343SYSCTL_INT(_user, USER_STREAM_MAX, stream_max, CTLFLAG_RD,
344 0, 0, "Min Maximum number of streams a process may have open at one time");
345SYSCTL_INT(_user, USER_TZNAME_MAX, tzname_max, CTLFLAG_RD,
346 0, 0, "Min Maximum number of types supported for timezone names");
347
348#include <sys/vnode.h>
349SYSCTL_INT(_debug_sizeof, OID_AUTO, vnode, CTLFLAG_RD,
350 0, sizeof(struct vnode), "sizeof(struct vnode)");
351
352SYSCTL_INT(_debug_sizeof, OID_AUTO, proc, CTLFLAG_RD,
353 0, sizeof(struct proc), "sizeof(struct proc)");
354
355#include <sys/conf.h>
356SYSCTL_INT(_debug_sizeof, OID_AUTO, cdev, CTLFLAG_RD,
357 0, sizeof(struct cdev), "sizeof(struct cdev)");
358
359#include <sys/bio.h>
360#include <sys/buf.h>
361SYSCTL_INT(_debug_sizeof, OID_AUTO, bio, CTLFLAG_RD,
362 0, sizeof(struct bio), "sizeof(struct bio)");
363SYSCTL_INT(_debug_sizeof, OID_AUTO, buf, CTLFLAG_RD,
364 0, sizeof(struct buf), "sizeof(struct buf)");
365
366#include <sys/user.h>
367SYSCTL_INT(_debug_sizeof, OID_AUTO, kinfo_proc, CTLFLAG_RD,
368 0, sizeof(struct kinfo_proc), "sizeof(struct kinfo_proc)");
369
370/* XXX compatibility, remove for 6.0 */
371#include <sys/imgact.h>
372#include <sys/imgact_elf.h>
373SYSCTL_INT(_kern, OID_AUTO, fallback_elf_brand, CTLFLAG_RW,
374 &__elfN(fallback_brand), sizeof(__elfN(fallback_brand)),
375 "compatibility for kern.fallback_elf_brand");
260 level = securelevel;
261 error = sysctl_handle_int(oidp, &level, 0, req);
262 if (error || !req->newptr)
263 return (error);
264 /*
265 * Permit update only if the new securelevel exceeds the
266 * global level, and local level if any.
267 */
268 if (pr != NULL) {
269 mtx_lock(&pr->pr_mtx);
270 if (!regression_securelevel_nonmonotonic &&
271 (level < imax(securelevel, pr->pr_securelevel))) {
272 mtx_unlock(&pr->pr_mtx);
273 return (EPERM);
274 }
275 pr->pr_securelevel = level;
276 mtx_unlock(&pr->pr_mtx);
277 } else {
278 mtx_lock(&securelevel_mtx);
279 if (!regression_securelevel_nonmonotonic &&
280 (level < securelevel)) {
281 mtx_unlock(&securelevel_mtx);
282 return (EPERM);
283 }
284 securelevel = level;
285 mtx_unlock(&securelevel_mtx);
286 }
287 return (error);
288}
289
290SYSCTL_PROC(_kern, KERN_SECURELVL, securelevel,
291 CTLTYPE_INT|CTLFLAG_RW|CTLFLAG_PRISON, 0, 0, sysctl_kern_securelvl,
292 "I", "Current secure level");
293
294char domainname[MAXHOSTNAMELEN];
295SYSCTL_STRING(_kern, KERN_NISDOMAINNAME, domainname, CTLFLAG_RW,
296 &domainname, sizeof(domainname), "Name of the current YP/NIS domain");
297
298u_long hostid;
299SYSCTL_ULONG(_kern, KERN_HOSTID, hostid, CTLFLAG_RW, &hostid, 0, "Host ID");
300
301/*
302 * This is really cheating. These actually live in the libc, something
303 * which I'm not quite sure is a good idea anyway, but in order for
304 * getnext and friends to actually work, we define dummies here.
305 */
306SYSCTL_STRING(_user, USER_CS_PATH, cs_path, CTLFLAG_RD,
307 "", 0, "PATH that finds all the standard utilities");
308SYSCTL_INT(_user, USER_BC_BASE_MAX, bc_base_max, CTLFLAG_RD,
309 0, 0, "Max ibase/obase values in bc(1)");
310SYSCTL_INT(_user, USER_BC_DIM_MAX, bc_dim_max, CTLFLAG_RD,
311 0, 0, "Max array size in bc(1)");
312SYSCTL_INT(_user, USER_BC_SCALE_MAX, bc_scale_max, CTLFLAG_RD,
313 0, 0, "Max scale value in bc(1)");
314SYSCTL_INT(_user, USER_BC_STRING_MAX, bc_string_max, CTLFLAG_RD,
315 0, 0, "Max string length in bc(1)");
316SYSCTL_INT(_user, USER_COLL_WEIGHTS_MAX, coll_weights_max, CTLFLAG_RD,
317 0, 0, "Maximum number of weights assigned to an LC_COLLATE locale entry");
318SYSCTL_INT(_user, USER_EXPR_NEST_MAX, expr_nest_max, CTLFLAG_RD, 0, 0, "");
319SYSCTL_INT(_user, USER_LINE_MAX, line_max, CTLFLAG_RD,
320 0, 0, "Max length (bytes) of a text-processing utility's input line");
321SYSCTL_INT(_user, USER_RE_DUP_MAX, re_dup_max, CTLFLAG_RD,
322 0, 0, "Maximum number of repeats of a regexp permitted");
323SYSCTL_INT(_user, USER_POSIX2_VERSION, posix2_version, CTLFLAG_RD,
324 0, 0,
325 "The version of POSIX 1003.2 with which the system attempts to comply");
326SYSCTL_INT(_user, USER_POSIX2_C_BIND, posix2_c_bind, CTLFLAG_RD,
327 0, 0, "Whether C development supports the C bindings option");
328SYSCTL_INT(_user, USER_POSIX2_C_DEV, posix2_c_dev, CTLFLAG_RD,
329 0, 0, "Whether system supports the C development utilities option");
330SYSCTL_INT(_user, USER_POSIX2_CHAR_TERM, posix2_char_term, CTLFLAG_RD,
331 0, 0, "");
332SYSCTL_INT(_user, USER_POSIX2_FORT_DEV, posix2_fort_dev, CTLFLAG_RD,
333 0, 0, "Whether system supports FORTRAN development utilities");
334SYSCTL_INT(_user, USER_POSIX2_FORT_RUN, posix2_fort_run, CTLFLAG_RD,
335 0, 0, "Whether system supports FORTRAN runtime utilities");
336SYSCTL_INT(_user, USER_POSIX2_LOCALEDEF, posix2_localedef, CTLFLAG_RD,
337 0, 0, "Whether system supports creation of locales");
338SYSCTL_INT(_user, USER_POSIX2_SW_DEV, posix2_sw_dev, CTLFLAG_RD,
339 0, 0, "Whether system supports software development utilities");
340SYSCTL_INT(_user, USER_POSIX2_UPE, posix2_upe, CTLFLAG_RD,
341 0, 0, "Whether system supports the user portability utilities");
342SYSCTL_INT(_user, USER_STREAM_MAX, stream_max, CTLFLAG_RD,
343 0, 0, "Min Maximum number of streams a process may have open at one time");
344SYSCTL_INT(_user, USER_TZNAME_MAX, tzname_max, CTLFLAG_RD,
345 0, 0, "Min Maximum number of types supported for timezone names");
346
347#include <sys/vnode.h>
348SYSCTL_INT(_debug_sizeof, OID_AUTO, vnode, CTLFLAG_RD,
349 0, sizeof(struct vnode), "sizeof(struct vnode)");
350
351SYSCTL_INT(_debug_sizeof, OID_AUTO, proc, CTLFLAG_RD,
352 0, sizeof(struct proc), "sizeof(struct proc)");
353
354#include <sys/conf.h>
355SYSCTL_INT(_debug_sizeof, OID_AUTO, cdev, CTLFLAG_RD,
356 0, sizeof(struct cdev), "sizeof(struct cdev)");
357
358#include <sys/bio.h>
359#include <sys/buf.h>
360SYSCTL_INT(_debug_sizeof, OID_AUTO, bio, CTLFLAG_RD,
361 0, sizeof(struct bio), "sizeof(struct bio)");
362SYSCTL_INT(_debug_sizeof, OID_AUTO, buf, CTLFLAG_RD,
363 0, sizeof(struct buf), "sizeof(struct buf)");
364
365#include <sys/user.h>
366SYSCTL_INT(_debug_sizeof, OID_AUTO, kinfo_proc, CTLFLAG_RD,
367 0, sizeof(struct kinfo_proc), "sizeof(struct kinfo_proc)");
368
369/* XXX compatibility, remove for 6.0 */
370#include <sys/imgact.h>
371#include <sys/imgact_elf.h>
372SYSCTL_INT(_kern, OID_AUTO, fallback_elf_brand, CTLFLAG_RW,
373 &__elfN(fallback_brand), sizeof(__elfN(fallback_brand)),
374 "compatibility for kern.fallback_elf_brand");