40 41#include "opt_posix.h" 42#include "opt_config.h" 43 44#include <sys/param.h> 45#include <sys/kernel.h> 46#include <sys/sbuf.h> 47#include <sys/systm.h> 48#include <sys/sysctl.h> 49#include <sys/proc.h> 50#include <sys/lock.h> 51#include <sys/mutex.h> 52#include <sys/jail.h> 53#include <sys/smp.h> 54#include <sys/unistd.h> 55 56SYSCTL_NODE(, 0, sysctl, CTLFLAG_RW, 0, 57 "Sysctl internal magic"); 58SYSCTL_NODE(, CTL_KERN, kern, CTLFLAG_RW, 0, 59 "High kernel, proc, limits &c"); 60SYSCTL_NODE(, CTL_VM, vm, CTLFLAG_RW, 0, 61 "Virtual memory"); 62SYSCTL_NODE(, CTL_VFS, vfs, CTLFLAG_RW, 0, 63 "File system"); 64SYSCTL_NODE(, CTL_NET, net, CTLFLAG_RW, 0, 65 "Network, (see socket.h)"); 66SYSCTL_NODE(, CTL_DEBUG, debug, CTLFLAG_RW, 0, 67 "Debugging"); 68SYSCTL_NODE(_debug, OID_AUTO, sizeof, CTLFLAG_RW, 0, 69 "Sizeof various things"); 70SYSCTL_NODE(, CTL_HW, hw, CTLFLAG_RW, 0, 71 "hardware"); 72SYSCTL_NODE(, CTL_MACHDEP, machdep, CTLFLAG_RW, 0, 73 "machine dependent"); 74SYSCTL_NODE(, CTL_USER, user, CTLFLAG_RW, 0, 75 "user-level"); 76SYSCTL_NODE(, CTL_P1003_1B, p1003_1b, CTLFLAG_RW, 0, 77 "p1003_1b, (see p1003_1b.h)"); 78 79SYSCTL_NODE(, OID_AUTO, compat, CTLFLAG_RW, 0, 80 "Compatibility code"); 81SYSCTL_NODE(, OID_AUTO, security, CTLFLAG_RW, 0, 82 "Security"); 83#ifdef REGRESSION 84SYSCTL_NODE(, OID_AUTO, regression, CTLFLAG_RW, 0, 85 "Regression test MIB"); 86#endif 87 88SYSCTL_STRING(_kern, OID_AUTO, ident, CTLFLAG_RD, 89 kern_ident, 0, "Kernel identifier"); 90 91SYSCTL_STRING(_kern, KERN_OSRELEASE, osrelease, CTLFLAG_RD, 92 osrelease, 0, "Operating system release"); 93 94SYSCTL_INT(_kern, KERN_OSREV, osrevision, CTLFLAG_RD, 95 0, BSD, "Operating system revision"); 96 97SYSCTL_STRING(_kern, KERN_VERSION, version, CTLFLAG_RD, 98 version, 0, "Kernel version"); 99 100SYSCTL_STRING(_kern, KERN_OSTYPE, ostype, CTLFLAG_RD, 101 ostype, 0, "Operating system type"); 102 103/* 104 * NOTICE: The *userland* release date is available in 105 * /usr/include/osreldate.h 106 */ 107extern int osreldate; 108SYSCTL_INT(_kern, KERN_OSRELDATE, osreldate, CTLFLAG_RD, 109 &osreldate, 0, "Kernel release date"); 110 111SYSCTL_INT(_kern, KERN_MAXPROC, maxproc, CTLFLAG_RDTUN, 112 &maxproc, 0, "Maximum number of processes"); 113 114SYSCTL_INT(_kern, KERN_MAXPROCPERUID, maxprocperuid, CTLFLAG_RW, 115 &maxprocperuid, 0, "Maximum processes allowed per userid"); 116 117SYSCTL_INT(_kern, OID_AUTO, maxusers, CTLFLAG_RDTUN, 118 &maxusers, 0, "Hint for kernel tuning"); 119 120SYSCTL_INT(_kern, KERN_ARGMAX, argmax, CTLFLAG_RD, 121 0, ARG_MAX, "Maximum bytes of argument to execve(2)"); 122 123SYSCTL_INT(_kern, KERN_POSIX1, posix1version, CTLFLAG_RD, 124 0, _POSIX_VERSION, "Version of POSIX attempting to comply to"); 125 126SYSCTL_INT(_kern, KERN_NGROUPS, ngroups, CTLFLAG_RD, 127 0, NGROUPS_MAX, "Maximum number of groups a user can belong to"); 128 129SYSCTL_INT(_kern, KERN_JOB_CONTROL, job_control, CTLFLAG_RD, 130 0, 1, "Whether job control is available"); 131 132#ifdef _POSIX_SAVED_IDS 133SYSCTL_INT(_kern, KERN_SAVED_IDS, saved_ids, CTLFLAG_RD, 134 0, 1, "Whether saved set-group/user ID is available"); 135#else 136SYSCTL_INT(_kern, KERN_SAVED_IDS, saved_ids, CTLFLAG_RD, 137 0, 0, "Whether saved set-group/user ID is available"); 138#endif 139 140char kernelname[MAXPATHLEN] = "/kernel"; /* XXX bloat */ 141 142SYSCTL_STRING(_kern, KERN_BOOTFILE, bootfile, CTLFLAG_RW, 143 kernelname, sizeof kernelname, "Name of kernel file booted"); 144 145SYSCTL_INT(_hw, HW_NCPU, ncpu, CTLFLAG_RD, 146 &mp_ncpus, 0, "Number of active CPUs"); 147 148SYSCTL_INT(_hw, HW_BYTEORDER, byteorder, CTLFLAG_RD, 149 0, BYTE_ORDER, "System byte order"); 150 151SYSCTL_INT(_hw, HW_PAGESIZE, pagesize, CTLFLAG_RD, 152 0, PAGE_SIZE, "System memory page size"); 153 154static int
|
167sysctl_hw_physmem(SYSCTL_HANDLER_ARGS) 168{ 169 u_long val; 170 171 val = ctob(physmem); 172 return (sysctl_handle_long(oidp, &val, 0, req)); 173} 174 175SYSCTL_PROC(_hw, HW_PHYSMEM, physmem, CTLTYPE_ULONG | CTLFLAG_RD, 176 0, 0, sysctl_hw_physmem, "LU", ""); 177 178static int 179sysctl_hw_realmem(SYSCTL_HANDLER_ARGS) 180{ 181 u_long val; 182 val = ctob(realmem); 183 return (sysctl_handle_long(oidp, &val, 0, req)); 184} 185SYSCTL_PROC(_hw, HW_REALMEM, realmem, CTLTYPE_ULONG | CTLFLAG_RD, 186 0, 0, sysctl_hw_realmem, "LU", ""); 187static int 188sysctl_hw_usermem(SYSCTL_HANDLER_ARGS) 189{ 190 u_long val; 191 192 val = ctob(physmem - VMCNT_GET(wire_count)); 193 return (sysctl_handle_long(oidp, &val, 0, req)); 194} 195 196SYSCTL_PROC(_hw, HW_USERMEM, usermem, CTLTYPE_ULONG | CTLFLAG_RD, 197 0, 0, sysctl_hw_usermem, "LU", ""); 198 199SYSCTL_ULONG(_hw, OID_AUTO, availpages, CTLFLAG_RD, &physmem, 0, ""); 200 201static char machine_arch[] = MACHINE_ARCH; 202SYSCTL_STRING(_hw, HW_MACHINE_ARCH, machine_arch, CTLFLAG_RD, 203 machine_arch, 0, "System architecture"); 204 205char hostname[MAXHOSTNAMELEN]; 206 207static int 208sysctl_hostname(SYSCTL_HANDLER_ARGS) 209{ 210 struct prison *pr; 211 char tmphostname[MAXHOSTNAMELEN]; 212 int error; 213 214 pr = req->td->td_ucred->cr_prison; 215 if (pr != NULL) { 216 if (!jail_set_hostname_allowed && req->newptr) 217 return (EPERM); 218 /* 219 * Process is in jail, so make a local copy of jail 220 * hostname to get/set so we don't have to hold the jail 221 * mutex during the sysctl copyin/copyout activities. 222 */ 223 mtx_lock(&pr->pr_mtx); 224 bcopy(pr->pr_host, tmphostname, MAXHOSTNAMELEN); 225 mtx_unlock(&pr->pr_mtx); 226 227 error = sysctl_handle_string(oidp, tmphostname, 228 sizeof pr->pr_host, req); 229 230 if (req->newptr != NULL && error == 0) { 231 /* 232 * Copy the locally set hostname to the jail, if 233 * appropriate. 234 */ 235 mtx_lock(&pr->pr_mtx); 236 bcopy(tmphostname, pr->pr_host, MAXHOSTNAMELEN); 237 mtx_unlock(&pr->pr_mtx); 238 } 239 } else 240 error = sysctl_handle_string(oidp, 241 hostname, sizeof hostname, req); 242 return (error); 243} 244 245SYSCTL_PROC(_kern, KERN_HOSTNAME, hostname, 246 CTLTYPE_STRING|CTLFLAG_RW|CTLFLAG_PRISON, 247 0, 0, sysctl_hostname, "A", "Hostname"); 248 249static int regression_securelevel_nonmonotonic = 0; 250 251#ifdef REGRESSION 252SYSCTL_INT(_regression, OID_AUTO, securelevel_nonmonotonic, CTLFLAG_RW, 253 ®ression_securelevel_nonmonotonic, 0, "securelevel may be lowered"); 254#endif 255 256int securelevel = -1; 257static struct mtx securelevel_mtx; 258 259MTX_SYSINIT(securelevel_lock, &securelevel_mtx, "securelevel mutex lock", 260 MTX_DEF); 261 262static int 263sysctl_kern_securelvl(SYSCTL_HANDLER_ARGS) 264{ 265 struct prison *pr; 266 int error, level; 267 268 pr = req->td->td_ucred->cr_prison; 269 270 /* 271 * If the process is in jail, return the maximum of the global and 272 * local levels; otherwise, return the global level. Perform a 273 * lockless read since the securelevel is an integer. 274 */ 275 if (pr != NULL) 276 level = imax(securelevel, pr->pr_securelevel); 277 else 278 level = securelevel; 279 error = sysctl_handle_int(oidp, &level, 0, req); 280 if (error || !req->newptr) 281 return (error); 282 /* 283 * Permit update only if the new securelevel exceeds the 284 * global level, and local level if any. 285 */ 286 if (pr != NULL) { 287 mtx_lock(&pr->pr_mtx); 288 if (!regression_securelevel_nonmonotonic && 289 (level < imax(securelevel, pr->pr_securelevel))) { 290 mtx_unlock(&pr->pr_mtx); 291 return (EPERM); 292 } 293 pr->pr_securelevel = level; 294 mtx_unlock(&pr->pr_mtx); 295 } else { 296 mtx_lock(&securelevel_mtx); 297 if (!regression_securelevel_nonmonotonic && 298 (level < securelevel)) { 299 mtx_unlock(&securelevel_mtx); 300 return (EPERM); 301 } 302 securelevel = level; 303 mtx_unlock(&securelevel_mtx); 304 } 305 return (error); 306} 307 308SYSCTL_PROC(_kern, KERN_SECURELVL, securelevel, 309 CTLTYPE_INT|CTLFLAG_RW|CTLFLAG_PRISON, 0, 0, sysctl_kern_securelvl, 310 "I", "Current secure level"); 311 312#ifdef INCLUDE_CONFIG_FILE 313/* Actual kernel configuration options. */ 314extern char kernconfstring[]; 315 316static int 317sysctl_kern_config(SYSCTL_HANDLER_ARGS) 318{ 319 struct sbuf *sb; 320 int error; 321 char *p; 322 323 sb = sbuf_new(NULL, NULL, 2048, SBUF_AUTOEXTEND); 324 if (sb == NULL) 325 return (ENOMEM); 326 sbuf_clear(sb); 327 p = kernconfstring; 328 if (p == NULL || *p == '\0') { 329 sbuf_printf(sb, "No kernel configuration\n"); 330 } else { 331 sbuf_printf(sb, "%s", p); 332 } 333 sbuf_trim(sb); 334 sbuf_putc(sb, '\n'); 335 sbuf_finish(sb); 336 error = sysctl_handle_string(oidp, sbuf_data(sb), sbuf_len(sb), req); 337 if (error) 338 return (error); 339 sbuf_delete(sb); 340 return (error); 341} 342SYSCTL_PROC(_kern, OID_AUTO, conftxt, CTLTYPE_STRING|CTLFLAG_RW, 343 0, 0, sysctl_kern_config, "", "Kernel configuration file"); 344#endif 345 346char domainname[MAXHOSTNAMELEN]; 347SYSCTL_STRING(_kern, KERN_NISDOMAINNAME, domainname, CTLFLAG_RW, 348 &domainname, sizeof(domainname), "Name of the current YP/NIS domain"); 349 350u_long hostid; 351SYSCTL_ULONG(_kern, KERN_HOSTID, hostid, CTLFLAG_RW, &hostid, 0, "Host ID"); 352char hostuuid[64] = "00000000-0000-0000-0000-000000000000"; 353SYSCTL_STRING(_kern, KERN_HOSTUUID, hostuuid, CTLFLAG_RW, hostuuid, 354 sizeof(hostuuid), "Host UUID"); 355 356/* 357 * This is really cheating. These actually live in the libc, something 358 * which I'm not quite sure is a good idea anyway, but in order for 359 * getnext and friends to actually work, we define dummies here. 360 */ 361SYSCTL_STRING(_user, USER_CS_PATH, cs_path, CTLFLAG_RD, 362 "", 0, "PATH that finds all the standard utilities"); 363SYSCTL_INT(_user, USER_BC_BASE_MAX, bc_base_max, CTLFLAG_RD, 364 0, 0, "Max ibase/obase values in bc(1)"); 365SYSCTL_INT(_user, USER_BC_DIM_MAX, bc_dim_max, CTLFLAG_RD, 366 0, 0, "Max array size in bc(1)"); 367SYSCTL_INT(_user, USER_BC_SCALE_MAX, bc_scale_max, CTLFLAG_RD, 368 0, 0, "Max scale value in bc(1)"); 369SYSCTL_INT(_user, USER_BC_STRING_MAX, bc_string_max, CTLFLAG_RD, 370 0, 0, "Max string length in bc(1)"); 371SYSCTL_INT(_user, USER_COLL_WEIGHTS_MAX, coll_weights_max, CTLFLAG_RD, 372 0, 0, "Maximum number of weights assigned to an LC_COLLATE locale entry"); 373SYSCTL_INT(_user, USER_EXPR_NEST_MAX, expr_nest_max, CTLFLAG_RD, 0, 0, ""); 374SYSCTL_INT(_user, USER_LINE_MAX, line_max, CTLFLAG_RD, 375 0, 0, "Max length (bytes) of a text-processing utility's input line"); 376SYSCTL_INT(_user, USER_RE_DUP_MAX, re_dup_max, CTLFLAG_RD, 377 0, 0, "Maximum number of repeats of a regexp permitted"); 378SYSCTL_INT(_user, USER_POSIX2_VERSION, posix2_version, CTLFLAG_RD, 379 0, 0, 380 "The version of POSIX 1003.2 with which the system attempts to comply"); 381SYSCTL_INT(_user, USER_POSIX2_C_BIND, posix2_c_bind, CTLFLAG_RD, 382 0, 0, "Whether C development supports the C bindings option"); 383SYSCTL_INT(_user, USER_POSIX2_C_DEV, posix2_c_dev, CTLFLAG_RD, 384 0, 0, "Whether system supports the C development utilities option"); 385SYSCTL_INT(_user, USER_POSIX2_CHAR_TERM, posix2_char_term, CTLFLAG_RD, 386 0, 0, ""); 387SYSCTL_INT(_user, USER_POSIX2_FORT_DEV, posix2_fort_dev, CTLFLAG_RD, 388 0, 0, "Whether system supports FORTRAN development utilities"); 389SYSCTL_INT(_user, USER_POSIX2_FORT_RUN, posix2_fort_run, CTLFLAG_RD, 390 0, 0, "Whether system supports FORTRAN runtime utilities"); 391SYSCTL_INT(_user, USER_POSIX2_LOCALEDEF, posix2_localedef, CTLFLAG_RD, 392 0, 0, "Whether system supports creation of locales"); 393SYSCTL_INT(_user, USER_POSIX2_SW_DEV, posix2_sw_dev, CTLFLAG_RD, 394 0, 0, "Whether system supports software development utilities"); 395SYSCTL_INT(_user, USER_POSIX2_UPE, posix2_upe, CTLFLAG_RD, 396 0, 0, "Whether system supports the user portability utilities"); 397SYSCTL_INT(_user, USER_STREAM_MAX, stream_max, CTLFLAG_RD, 398 0, 0, "Min Maximum number of streams a process may have open at one time"); 399SYSCTL_INT(_user, USER_TZNAME_MAX, tzname_max, CTLFLAG_RD, 400 0, 0, "Min Maximum number of types supported for timezone names"); 401 402#include <sys/vnode.h> 403SYSCTL_INT(_debug_sizeof, OID_AUTO, vnode, CTLFLAG_RD, 404 0, sizeof(struct vnode), "sizeof(struct vnode)"); 405 406SYSCTL_INT(_debug_sizeof, OID_AUTO, proc, CTLFLAG_RD, 407 0, sizeof(struct proc), "sizeof(struct proc)"); 408 409#include <sys/bio.h> 410#include <sys/buf.h> 411SYSCTL_INT(_debug_sizeof, OID_AUTO, bio, CTLFLAG_RD, 412 0, sizeof(struct bio), "sizeof(struct bio)"); 413SYSCTL_INT(_debug_sizeof, OID_AUTO, buf, CTLFLAG_RD, 414 0, sizeof(struct buf), "sizeof(struct buf)"); 415 416#include <sys/user.h> 417SYSCTL_INT(_debug_sizeof, OID_AUTO, kinfo_proc, CTLFLAG_RD, 418 0, sizeof(struct kinfo_proc), "sizeof(struct kinfo_proc)"); 419 420/* XXX compatibility, remove for 6.0 */ 421#include <sys/imgact.h> 422#include <sys/imgact_elf.h> 423SYSCTL_INT(_kern, OID_AUTO, fallback_elf_brand, CTLFLAG_RW, 424 &__elfN(fallback_brand), sizeof(__elfN(fallback_brand)), 425 "compatibility for kern.fallback_elf_brand");
|