1 /*-
2  * SPDX-License-Identifier: BSD-2-Clause-FreeBSD
3  *
4  * Copyright (c) 1995 Søren Schmidt
5  * All rights reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted provided that the following conditions
9  * are met:
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  *
16  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26  * SUCH DAMAGE.
27  */
28 
29 #include <sys/cdefs.h>
30 __FBSDID("$FreeBSD$");
31 
32 /* XXX we use functions that might not exist. */
33 #include "opt_compat.h"
34 #include "opt_inet6.h"
35 
36 #include <sys/param.h>
37 #include <sys/proc.h>
38 #include <sys/systm.h>
39 #include <sys/sysproto.h>
40 #include <sys/capsicum.h>
41 #include <sys/fcntl.h>
42 #include <sys/file.h>
43 #include <sys/limits.h>
44 #include <sys/lock.h>
45 #include <sys/malloc.h>
46 #include <sys/mutex.h>
47 #include <sys/mbuf.h>
48 #include <sys/socket.h>
49 #include <sys/socketvar.h>
50 #include <sys/syscallsubr.h>
51 #include <sys/uio.h>
52 #include <sys/stat.h>
53 #include <sys/syslog.h>
54 #include <sys/un.h>
55 #include <sys/unistd.h>
56 
57 #include <security/audit/audit.h>
58 
59 #include <net/if.h>
60 #include <net/vnet.h>
61 #include <netinet/in.h>
62 #include <netinet/in_systm.h>
63 #include <netinet/ip.h>
64 #include <netinet/tcp.h>
65 #ifdef INET6
66 #include <netinet/ip6.h>
67 #include <netinet6/ip6_var.h>
68 #endif
69 
70 #ifdef COMPAT_LINUX32
71 #include <machine/../linux32/linux.h>
72 #include <machine/../linux32/linux32_proto.h>
73 #else
74 #include <machine/../linux/linux.h>
75 #include <machine/../linux/linux_proto.h>
76 #endif
77 #include <compat/linux/linux_common.h>
78 #include <compat/linux/linux_file.h>
79 #include <compat/linux/linux_mib.h>
80 #include <compat/linux/linux_socket.h>
81 #include <compat/linux/linux_timer.h>
82 #include <compat/linux/linux_util.h>
83 
84 static int linux_sendmsg_common(struct thread *, l_int, struct l_msghdr *,
85 					l_uint);
86 static int linux_recvmsg_common(struct thread *, l_int, struct l_msghdr *,
87 					l_uint, struct msghdr *);
88 static int linux_set_socket_flags(int, int *);
89 
90 
91 static int
92 linux_to_bsd_sockopt_level(int level)
93 {
94 
95 	switch (level) {
96 	case LINUX_SOL_SOCKET:
97 		return (SOL_SOCKET);
98 	}
99 	return (level);
100 }
101 
102 static int
103 bsd_to_linux_sockopt_level(int level)
104 {
105 
106 	switch (level) {
107 	case SOL_SOCKET:
108 		return (LINUX_SOL_SOCKET);
109 	}
110 	return (level);
111 }
112 
113 static int
114 linux_to_bsd_ip_sockopt(int opt)
115 {
116 
117 	switch (opt) {
118 	case LINUX_IP_TOS:
119 		return (IP_TOS);
120 	case LINUX_IP_TTL:
121 		return (IP_TTL);
122 	case LINUX_IP_OPTIONS:
123 		return (IP_OPTIONS);
124 	case LINUX_IP_MULTICAST_IF:
125 		return (IP_MULTICAST_IF);
126 	case LINUX_IP_MULTICAST_TTL:
127 		return (IP_MULTICAST_TTL);
128 	case LINUX_IP_MULTICAST_LOOP:
129 		return (IP_MULTICAST_LOOP);
130 	case LINUX_IP_ADD_MEMBERSHIP:
131 		return (IP_ADD_MEMBERSHIP);
132 	case LINUX_IP_DROP_MEMBERSHIP:
133 		return (IP_DROP_MEMBERSHIP);
134 	case LINUX_IP_HDRINCL:
135 		return (IP_HDRINCL);
136 	}
137 	return (-1);
138 }
139 
140 static int
141 linux_to_bsd_ip6_sockopt(int opt)
142 {
143 
144 	switch (opt) {
145 	case LINUX_IPV6_NEXTHOP:
146 		return (IPV6_NEXTHOP);
147 	case LINUX_IPV6_UNICAST_HOPS:
148 		return (IPV6_UNICAST_HOPS);
149 	case LINUX_IPV6_MULTICAST_IF:
150 		return (IPV6_MULTICAST_IF);
151 	case LINUX_IPV6_MULTICAST_HOPS:
152 		return (IPV6_MULTICAST_HOPS);
153 	case LINUX_IPV6_MULTICAST_LOOP:
154 		return (IPV6_MULTICAST_LOOP);
155 	case LINUX_IPV6_ADD_MEMBERSHIP:
156 		return (IPV6_JOIN_GROUP);
157 	case LINUX_IPV6_DROP_MEMBERSHIP:
158 		return (IPV6_LEAVE_GROUP);
159 	case LINUX_IPV6_V6ONLY:
160 		return (IPV6_V6ONLY);
161 	case LINUX_IPV6_DONTFRAG:
162 		return (IPV6_DONTFRAG);
163 #if 0
164 	case LINUX_IPV6_CHECKSUM:
165 		return (IPV6_CHECKSUM);
166 	case LINUX_IPV6_RECVPKTINFO:
167 		return (IPV6_RECVPKTINFO);
168 	case LINUX_IPV6_PKTINFO:
169 		return (IPV6_PKTINFO);
170 	case LINUX_IPV6_RECVHOPLIMIT:
171 		return (IPV6_RECVHOPLIMIT);
172 	case LINUX_IPV6_HOPLIMIT:
173 		return (IPV6_HOPLIMIT);
174 	case LINUX_IPV6_RECVHOPOPTS:
175 		return (IPV6_RECVHOPOPTS);
176 	case LINUX_IPV6_HOPOPTS:
177 		return (IPV6_HOPOPTS);
178 	case LINUX_IPV6_RTHDRDSTOPTS:
179 		return (IPV6_RTHDRDSTOPTS);
180 	case LINUX_IPV6_RECVRTHDR:
181 		return (IPV6_RECVRTHDR);
182 	case LINUX_IPV6_RTHDR:
183 		return (IPV6_RTHDR);
184 	case LINUX_IPV6_RECVDSTOPTS:
185 		return (IPV6_RECVDSTOPTS);
186 	case LINUX_IPV6_DSTOPTS:
187 		return (IPV6_DSTOPTS);
188 	case LINUX_IPV6_RECVPATHMTU:
189 		return (IPV6_RECVPATHMTU);
190 	case LINUX_IPV6_PATHMTU:
191 		return (IPV6_PATHMTU);
192 #endif
193 	}
194 	return (-1);
195 }
196 
197 static int
198 linux_to_bsd_so_sockopt(int opt)
199 {
200 
201 	switch (opt) {
202 	case LINUX_SO_DEBUG:
203 		return (SO_DEBUG);
204 	case LINUX_SO_REUSEADDR:
205 		return (SO_REUSEADDR);
206 	case LINUX_SO_TYPE:
207 		return (SO_TYPE);
208 	case LINUX_SO_ERROR:
209 		return (SO_ERROR);
210 	case LINUX_SO_DONTROUTE:
211 		return (SO_DONTROUTE);
212 	case LINUX_SO_BROADCAST:
213 		return (SO_BROADCAST);
214 	case LINUX_SO_SNDBUF:
215 	case LINUX_SO_SNDBUFFORCE:
216 		return (SO_SNDBUF);
217 	case LINUX_SO_RCVBUF:
218 	case LINUX_SO_RCVBUFFORCE:
219 		return (SO_RCVBUF);
220 	case LINUX_SO_KEEPALIVE:
221 		return (SO_KEEPALIVE);
222 	case LINUX_SO_OOBINLINE:
223 		return (SO_OOBINLINE);
224 	case LINUX_SO_LINGER:
225 		return (SO_LINGER);
226 	case LINUX_SO_PEERCRED:
227 		return (LOCAL_PEERCRED);
228 	case LINUX_SO_RCVLOWAT:
229 		return (SO_RCVLOWAT);
230 	case LINUX_SO_SNDLOWAT:
231 		return (SO_SNDLOWAT);
232 	case LINUX_SO_RCVTIMEO:
233 		return (SO_RCVTIMEO);
234 	case LINUX_SO_SNDTIMEO:
235 		return (SO_SNDTIMEO);
236 	case LINUX_SO_TIMESTAMP:
237 		return (SO_TIMESTAMP);
238 	case LINUX_SO_ACCEPTCONN:
239 		return (SO_ACCEPTCONN);
240 	}
241 	return (-1);
242 }
243 
244 static int
245 linux_to_bsd_tcp_sockopt(int opt)
246 {
247 
248 	switch (opt) {
249 	case LINUX_TCP_NODELAY:
250 		return (TCP_NODELAY);
251 	case LINUX_TCP_MAXSEG:
252 		return (TCP_MAXSEG);
253 	case LINUX_TCP_CORK:
254 		return (TCP_NOPUSH);
255 	case LINUX_TCP_KEEPIDLE:
256 		return (TCP_KEEPIDLE);
257 	case LINUX_TCP_KEEPINTVL:
258 		return (TCP_KEEPINTVL);
259 	case LINUX_TCP_KEEPCNT:
260 		return (TCP_KEEPCNT);
261 	case LINUX_TCP_MD5SIG:
262 		return (TCP_MD5SIG);
263 	}
264 	return (-1);
265 }
266 
267 static int
268 linux_to_bsd_msg_flags(int flags)
269 {
270 	int ret_flags = 0;
271 
272 	if (flags & LINUX_MSG_OOB)
273 		ret_flags |= MSG_OOB;
274 	if (flags & LINUX_MSG_PEEK)
275 		ret_flags |= MSG_PEEK;
276 	if (flags & LINUX_MSG_DONTROUTE)
277 		ret_flags |= MSG_DONTROUTE;
278 	if (flags & LINUX_MSG_CTRUNC)
279 		ret_flags |= MSG_CTRUNC;
280 	if (flags & LINUX_MSG_TRUNC)
281 		ret_flags |= MSG_TRUNC;
282 	if (flags & LINUX_MSG_DONTWAIT)
283 		ret_flags |= MSG_DONTWAIT;
284 	if (flags & LINUX_MSG_EOR)
285 		ret_flags |= MSG_EOR;
286 	if (flags & LINUX_MSG_WAITALL)
287 		ret_flags |= MSG_WAITALL;
288 	if (flags & LINUX_MSG_NOSIGNAL)
289 		ret_flags |= MSG_NOSIGNAL;
290 #if 0 /* not handled */
291 	if (flags & LINUX_MSG_PROXY)
292 		;
293 	if (flags & LINUX_MSG_FIN)
294 		;
295 	if (flags & LINUX_MSG_SYN)
296 		;
297 	if (flags & LINUX_MSG_CONFIRM)
298 		;
299 	if (flags & LINUX_MSG_RST)
300 		;
301 	if (flags & LINUX_MSG_ERRQUEUE)
302 		;
303 #endif
304 	return (ret_flags);
305 }
306 
307 static int
308 linux_to_bsd_cmsg_type(int cmsg_type)
309 {
310 
311 	switch (cmsg_type) {
312 	case LINUX_SCM_RIGHTS:
313 		return (SCM_RIGHTS);
314 	case LINUX_SCM_CREDENTIALS:
315 		return (SCM_CREDS);
316 	}
317 	return (-1);
318 }
319 
320 static int
321 bsd_to_linux_cmsg_type(int cmsg_type)
322 {
323 
324 	switch (cmsg_type) {
325 	case SCM_RIGHTS:
326 		return (LINUX_SCM_RIGHTS);
327 	case SCM_CREDS:
328 		return (LINUX_SCM_CREDENTIALS);
329 	case SCM_TIMESTAMP:
330 		return (LINUX_SCM_TIMESTAMP);
331 	}
332 	return (-1);
333 }
334 
335 static int
336 linux_to_bsd_msghdr(struct msghdr *bhdr, const struct l_msghdr *lhdr)
337 {
338 	if (lhdr->msg_controllen > INT_MAX)
339 		return (ENOBUFS);
340 
341 	bhdr->msg_name		= PTRIN(lhdr->msg_name);
342 	bhdr->msg_namelen	= lhdr->msg_namelen;
343 	bhdr->msg_iov		= PTRIN(lhdr->msg_iov);
344 	bhdr->msg_iovlen	= lhdr->msg_iovlen;
345 	bhdr->msg_control	= PTRIN(lhdr->msg_control);
346 
347 	/*
348 	 * msg_controllen is skipped since BSD and LINUX control messages
349 	 * are potentially different sizes (e.g. the cred structure used
350 	 * by SCM_CREDS is different between the two operating system).
351 	 *
352 	 * The caller can set it (if necessary) after converting all the
353 	 * control messages.
354 	 */
355 
356 	bhdr->msg_flags		= linux_to_bsd_msg_flags(lhdr->msg_flags);
357 	return (0);
358 }
359 
360 static int
361 bsd_to_linux_msghdr(const struct msghdr *bhdr, struct l_msghdr *lhdr)
362 {
363 	lhdr->msg_name		= PTROUT(bhdr->msg_name);
364 	lhdr->msg_namelen	= bhdr->msg_namelen;
365 	lhdr->msg_iov		= PTROUT(bhdr->msg_iov);
366 	lhdr->msg_iovlen	= bhdr->msg_iovlen;
367 	lhdr->msg_control	= PTROUT(bhdr->msg_control);
368 
369 	/*
370 	 * msg_controllen is skipped since BSD and LINUX control messages
371 	 * are potentially different sizes (e.g. the cred structure used
372 	 * by SCM_CREDS is different between the two operating system).
373 	 *
374 	 * The caller can set it (if necessary) after converting all the
375 	 * control messages.
376 	 */
377 
378 	/* msg_flags skipped */
379 	return (0);
380 }
381 
382 static int
383 linux_set_socket_flags(int lflags, int *flags)
384 {
385 
386 	if (lflags & ~(LINUX_SOCK_CLOEXEC | LINUX_SOCK_NONBLOCK))
387 		return (EINVAL);
388 	if (lflags & LINUX_SOCK_NONBLOCK)
389 		*flags |= SOCK_NONBLOCK;
390 	if (lflags & LINUX_SOCK_CLOEXEC)
391 		*flags |= SOCK_CLOEXEC;
392 	return (0);
393 }
394 
395 static int
396 linux_sendit(struct thread *td, int s, struct msghdr *mp, int flags,
397     struct mbuf *control, enum uio_seg segflg)
398 {
399 	struct sockaddr *to;
400 	int error, len;
401 
402 	if (mp->msg_name != NULL) {
403 		len = mp->msg_namelen;
404 		error = linux_to_bsd_sockaddr(mp->msg_name, &to, &len);
405 		if (error != 0)
406 			return (error);
407 		mp->msg_name = to;
408 	} else
409 		to = NULL;
410 
411 	error = kern_sendit(td, s, mp, linux_to_bsd_msg_flags(flags), control,
412 	    segflg);
413 
414 	if (to)
415 		free(to, M_SONAME);
416 	return (error);
417 }
418 
419 /* Return 0 if IP_HDRINCL is set for the given socket. */
420 static int
421 linux_check_hdrincl(struct thread *td, int s)
422 {
423 	int error, optval;
424 	socklen_t size_val;
425 
426 	size_val = sizeof(optval);
427 	error = kern_getsockopt(td, s, IPPROTO_IP, IP_HDRINCL,
428 	    &optval, UIO_SYSSPACE, &size_val);
429 	if (error != 0)
430 		return (error);
431 
432 	return (optval == 0);
433 }
434 
435 /*
436  * Updated sendto() when IP_HDRINCL is set:
437  * tweak endian-dependent fields in the IP packet.
438  */
439 static int
440 linux_sendto_hdrincl(struct thread *td, struct linux_sendto_args *linux_args)
441 {
442 /*
443  * linux_ip_copysize defines how many bytes we should copy
444  * from the beginning of the IP packet before we customize it for BSD.
445  * It should include all the fields we modify (ip_len and ip_off).
446  */
447 #define linux_ip_copysize	8
448 
449 	struct ip *packet;
450 	struct msghdr msg;
451 	struct iovec aiov[1];
452 	int error;
453 
454 	/* Check that the packet isn't too big or too small. */
455 	if (linux_args->len < linux_ip_copysize ||
456 	    linux_args->len > IP_MAXPACKET)
457 		return (EINVAL);
458 
459 	packet = (struct ip *)malloc(linux_args->len, M_LINUX, M_WAITOK);
460 
461 	/* Make kernel copy of the packet to be sent */
462 	if ((error = copyin(PTRIN(linux_args->msg), packet,
463 	    linux_args->len)))
464 		goto goout;
465 
466 	/* Convert fields from Linux to BSD raw IP socket format */
467 	packet->ip_len = linux_args->len;
468 	packet->ip_off = ntohs(packet->ip_off);
469 
470 	/* Prepare the msghdr and iovec structures describing the new packet */
471 	msg.msg_name = PTRIN(linux_args->to);
472 	msg.msg_namelen = linux_args->tolen;
473 	msg.msg_iov = aiov;
474 	msg.msg_iovlen = 1;
475 	msg.msg_control = NULL;
476 	msg.msg_flags = 0;
477 	aiov[0].iov_base = (char *)packet;
478 	aiov[0].iov_len = linux_args->len;
479 	error = linux_sendit(td, linux_args->s, &msg, linux_args->flags,
480 	    NULL, UIO_SYSSPACE);
481 goout:
482 	free(packet, M_LINUX);
483 	return (error);
484 }
485 
486 int
487 linux_socket(struct thread *td, struct linux_socket_args *args)
488 {
489 	int domain, retval_socket, type;
490 
491 	type = args->type & LINUX_SOCK_TYPE_MASK;
492 	if (type < 0 || type > LINUX_SOCK_MAX)
493 		return (EINVAL);
494 	retval_socket = linux_set_socket_flags(args->type & ~LINUX_SOCK_TYPE_MASK,
495 		&type);
496 	if (retval_socket != 0)
497 		return (retval_socket);
498 	domain = linux_to_bsd_domain(args->domain);
499 	if (domain == -1)
500 		return (EAFNOSUPPORT);
501 
502 	retval_socket = kern_socket(td, domain, type, args->protocol);
503 	if (retval_socket)
504 		return (retval_socket);
505 
506 	if (type == SOCK_RAW
507 	    && (args->protocol == IPPROTO_RAW || args->protocol == 0)
508 	    && domain == PF_INET) {
509 		/* It's a raw IP socket: set the IP_HDRINCL option. */
510 		int hdrincl;
511 
512 		hdrincl = 1;
513 		/* We ignore any error returned by kern_setsockopt() */
514 		kern_setsockopt(td, td->td_retval[0], IPPROTO_IP, IP_HDRINCL,
515 		    &hdrincl, UIO_SYSSPACE, sizeof(hdrincl));
516 	}
517 #ifdef INET6
518 	/*
519 	 * Linux AF_INET6 socket has IPV6_V6ONLY setsockopt set to 0 by default
520 	 * and some apps depend on this. So, set V6ONLY to 0 for Linux apps.
521 	 * For simplicity we do this unconditionally of the net.inet6.ip6.v6only
522 	 * sysctl value.
523 	 */
524 	if (domain == PF_INET6) {
525 		int v6only;
526 
527 		v6only = 0;
528 		/* We ignore any error returned by setsockopt() */
529 		kern_setsockopt(td, td->td_retval[0], IPPROTO_IPV6, IPV6_V6ONLY,
530 		    &v6only, UIO_SYSSPACE, sizeof(v6only));
531 	}
532 #endif
533 
534 	return (retval_socket);
535 }
536 
537 int
538 linux_bind(struct thread *td, struct linux_bind_args *args)
539 {
540 	struct sockaddr *sa;
541 	int error;
542 
543 	error = linux_to_bsd_sockaddr(PTRIN(args->name), &sa,
544 	    &args->namelen);
545 	if (error != 0)
546 		return (error);
547 
548 	error = kern_bindat(td, AT_FDCWD, args->s, sa);
549 	free(sa, M_SONAME);
550 
551 	/* XXX */
552 	if (error == EADDRNOTAVAIL && args->namelen != sizeof(struct sockaddr_in))
553 		return (EINVAL);
554 	return (error);
555 }
556 
557 int
558 linux_connect(struct thread *td, struct linux_connect_args *args)
559 {
560 	struct socket *so;
561 	struct sockaddr *sa;
562 	struct file *fp;
563 	u_int fflag;
564 	int error;
565 
566 	error = linux_to_bsd_sockaddr(PTRIN(args->name), &sa,
567 	    &args->namelen);
568 	if (error != 0)
569 		return (error);
570 
571 	error = kern_connectat(td, AT_FDCWD, args->s, sa);
572 	free(sa, M_SONAME);
573 	if (error != EISCONN)
574 		return (error);
575 
576 	/*
577 	 * Linux doesn't return EISCONN the first time it occurs,
578 	 * when on a non-blocking socket. Instead it returns the
579 	 * error getsockopt(SOL_SOCKET, SO_ERROR) would return on BSD.
580 	 */
581 	error = getsock_cap(td, args->s, &cap_connect_rights,
582 	    &fp, &fflag, NULL);
583 	if (error != 0)
584 		return (error);
585 
586 	error = EISCONN;
587 	so = fp->f_data;
588 	if (fflag & FNONBLOCK) {
589 		SOCK_LOCK(so);
590 		if (so->so_emuldata == 0)
591 			error = so->so_error;
592 		so->so_emuldata = (void *)1;
593 		SOCK_UNLOCK(so);
594 	}
595 	fdrop(fp, td);
596 
597 	return (error);
598 }
599 
600 int
601 linux_listen(struct thread *td, struct linux_listen_args *args)
602 {
603 
604 	return (kern_listen(td, args->s, args->backlog));
605 }
606 
607 static int
608 linux_accept_common(struct thread *td, int s, l_uintptr_t addr,
609     l_uintptr_t namelen, int flags)
610 {
611 	struct l_sockaddr *lsa;
612 	struct sockaddr *sa;
613 	struct file *fp;
614 	int bflags, len;
615 	struct socket *so;
616 	int error, error1;
617 
618 	bflags = 0;
619 	error = linux_set_socket_flags(flags, &bflags);
620 	if (error != 0)
621 		return (error);
622 
623 	sa = NULL;
624 	if (PTRIN(addr) == NULL) {
625 		len = 0;
626 		error = kern_accept4(td, s, NULL, NULL, bflags, NULL);
627 	} else {
628 		error = copyin(PTRIN(namelen), &len, sizeof(len));
629 		if (error != 0)
630 			return (error);
631 		if (len < 0)
632 			return (EINVAL);
633 		error = kern_accept4(td, s, &sa, &len, bflags, &fp);
634 		if (error == 0)
635 			fdrop(fp, td);
636 	}
637 
638 	if (error != 0) {
639 		/*
640 		 * XXX. This is wrong, different sockaddr structures
641 		 * have different sizes.
642 		 */
643 		if (error == EFAULT && namelen != sizeof(struct sockaddr_in))
644 		{
645 			error = EINVAL;
646 			goto out;
647 		}
648 		if (error == EINVAL) {
649 			error1 = getsock_cap(td, s, &cap_accept_rights, &fp, NULL, NULL);
650 			if (error1 != 0) {
651 				error = error1;
652 				goto out;
653 			}
654 			so = fp->f_data;
655 			if (so->so_type == SOCK_DGRAM)
656 				error = EOPNOTSUPP;
657 			fdrop(fp, td);
658 		}
659 		goto out;
660 	}
661 
662 	if (len != 0 && error == 0) {
663 		error = bsd_to_linux_sockaddr(sa, &lsa, len);
664 		if (error == 0)
665 			error = copyout(lsa, PTRIN(addr), len);
666 		free(lsa, M_SONAME);
667 	}
668 
669 	free(sa, M_SONAME);
670 
671 out:
672 	if (error != 0) {
673 		(void)kern_close(td, td->td_retval[0]);
674 		td->td_retval[0] = 0;
675 	}
676 	return (error);
677 }
678 
679 int
680 linux_accept(struct thread *td, struct linux_accept_args *args)
681 {
682 
683 	return (linux_accept_common(td, args->s, args->addr,
684 	    args->namelen, 0));
685 }
686 
687 int
688 linux_accept4(struct thread *td, struct linux_accept4_args *args)
689 {
690 
691 	return (linux_accept_common(td, args->s, args->addr,
692 	    args->namelen, args->flags));
693 }
694 
695 int
696 linux_getsockname(struct thread *td, struct linux_getsockname_args *args)
697 {
698 	struct l_sockaddr *lsa;
699 	struct sockaddr *sa;
700 	int len, error;
701 
702 	error = copyin(PTRIN(args->namelen), &len, sizeof(len));
703 	if (error != 0)
704 		return (error);
705 
706 	error = kern_getsockname(td, args->s, &sa, &len);
707 	if (error != 0)
708 		return (error);
709 
710 	if (len != 0) {
711 		error = bsd_to_linux_sockaddr(sa, &lsa, len);
712 		if (error == 0)
713 			error = copyout(lsa, PTRIN(args->addr),
714 			    len);
715 		free(lsa, M_SONAME);
716 	}
717 
718 	free(sa, M_SONAME);
719 	if (error == 0)
720 		error = copyout(&len, PTRIN(args->namelen), sizeof(len));
721 	return (error);
722 }
723 
724 int
725 linux_getpeername(struct thread *td, struct linux_getpeername_args *args)
726 {
727 	struct l_sockaddr *lsa;
728 	struct sockaddr *sa;
729 	int len, error;
730 
731 	error = copyin(PTRIN(args->namelen), &len, sizeof(len));
732 	if (error != 0)
733 		return (error);
734 	if (len < 0)
735 		return (EINVAL);
736 
737 	error = kern_getpeername(td, args->s, &sa, &len);
738 	if (error != 0)
739 		return (error);
740 
741 	if (len != 0) {
742 		error = bsd_to_linux_sockaddr(sa, &lsa, len);
743 		if (error == 0)
744 			error = copyout(lsa, PTRIN(args->addr),
745 			    len);
746 		free(lsa, M_SONAME);
747 	}
748 
749 	free(sa, M_SONAME);
750 	if (error == 0)
751 		error = copyout(&len, PTRIN(args->namelen), sizeof(len));
752 	return (error);
753 }
754 
755 int
756 linux_socketpair(struct thread *td, struct linux_socketpair_args *args)
757 {
758 	int domain, error, sv[2], type;
759 
760 	domain = linux_to_bsd_domain(args->domain);
761 	if (domain != PF_LOCAL)
762 		return (EAFNOSUPPORT);
763 	type = args->type & LINUX_SOCK_TYPE_MASK;
764 	if (type < 0 || type > LINUX_SOCK_MAX)
765 		return (EINVAL);
766 	error = linux_set_socket_flags(args->type & ~LINUX_SOCK_TYPE_MASK,
767 	    &type);
768 	if (error != 0)
769 		return (error);
770 	if (args->protocol != 0 && args->protocol != PF_UNIX) {
771 
772 		/*
773 		 * Use of PF_UNIX as protocol argument is not right,
774 		 * but Linux does it.
775 		 * Do not map PF_UNIX as its Linux value is identical
776 		 * to FreeBSD one.
777 		 */
778 		return (EPROTONOSUPPORT);
779 	}
780 	error = kern_socketpair(td, domain, type, 0, sv);
781 	if (error != 0)
782                 return (error);
783         error = copyout(sv, PTRIN(args->rsv), 2 * sizeof(int));
784         if (error != 0) {
785                 (void)kern_close(td, sv[0]);
786                 (void)kern_close(td, sv[1]);
787         }
788 	return (error);
789 }
790 
791 #if defined(__i386__) || (defined(__amd64__) && defined(COMPAT_LINUX32))
792 struct linux_send_args {
793 	register_t s;
794 	register_t msg;
795 	register_t len;
796 	register_t flags;
797 };
798 
799 static int
800 linux_send(struct thread *td, struct linux_send_args *args)
801 {
802 	struct sendto_args /* {
803 		int s;
804 		caddr_t buf;
805 		int len;
806 		int flags;
807 		caddr_t to;
808 		int tolen;
809 	} */ bsd_args;
810 	struct file *fp;
811 	int error, fflag;
812 
813 	bsd_args.s = args->s;
814 	bsd_args.buf = (caddr_t)PTRIN(args->msg);
815 	bsd_args.len = args->len;
816 	bsd_args.flags = args->flags;
817 	bsd_args.to = NULL;
818 	bsd_args.tolen = 0;
819 	error = sys_sendto(td, &bsd_args);
820 	if (error == ENOTCONN) {
821 		/*
822 		 * Linux doesn't return ENOTCONN for non-blocking sockets.
823 		 * Instead it returns the EAGAIN.
824 		 */
825 		error = getsock_cap(td, args->s, &cap_send_rights, &fp,
826 		    &fflag, NULL);
827 		if (error == 0) {
828 			if (fflag & FNONBLOCK)
829 				error = EAGAIN;
830 			fdrop(fp, td);
831 		}
832 	}
833 	return (error);
834 }
835 
836 struct linux_recv_args {
837 	register_t s;
838 	register_t msg;
839 	register_t len;
840 	register_t flags;
841 };
842 
843 static int
844 linux_recv(struct thread *td, struct linux_recv_args *args)
845 {
846 	struct recvfrom_args /* {
847 		int s;
848 		caddr_t buf;
849 		int len;
850 		int flags;
851 		struct sockaddr *from;
852 		socklen_t fromlenaddr;
853 	} */ bsd_args;
854 
855 	bsd_args.s = args->s;
856 	bsd_args.buf = (caddr_t)PTRIN(args->msg);
857 	bsd_args.len = args->len;
858 	bsd_args.flags = linux_to_bsd_msg_flags(args->flags);
859 	bsd_args.from = NULL;
860 	bsd_args.fromlenaddr = 0;
861 	return (sys_recvfrom(td, &bsd_args));
862 }
863 #endif /* __i386__ || (__amd64__ && COMPAT_LINUX32) */
864 
865 int
866 linux_sendto(struct thread *td, struct linux_sendto_args *args)
867 {
868 	struct msghdr msg;
869 	struct iovec aiov;
870 
871 	if (linux_check_hdrincl(td, args->s) == 0)
872 		/* IP_HDRINCL set, tweak the packet before sending */
873 		return (linux_sendto_hdrincl(td, args));
874 
875 	msg.msg_name = PTRIN(args->to);
876 	msg.msg_namelen = args->tolen;
877 	msg.msg_iov = &aiov;
878 	msg.msg_iovlen = 1;
879 	msg.msg_control = NULL;
880 	msg.msg_flags = 0;
881 	aiov.iov_base = PTRIN(args->msg);
882 	aiov.iov_len = args->len;
883 	return (linux_sendit(td, args->s, &msg, args->flags, NULL,
884 	    UIO_USERSPACE));
885 }
886 
887 int
888 linux_recvfrom(struct thread *td, struct linux_recvfrom_args *args)
889 {
890 	struct l_sockaddr *lsa;
891 	struct sockaddr *sa;
892 	struct msghdr msg;
893 	struct iovec aiov;
894 	int error, fromlen;
895 
896 	if (PTRIN(args->fromlen) != NULL) {
897 		error = copyin(PTRIN(args->fromlen), &fromlen,
898 		    sizeof(fromlen));
899 		if (error != 0)
900 			return (error);
901 		if (fromlen < 0)
902 			return (EINVAL);
903 		sa = malloc(fromlen, M_SONAME, M_WAITOK);
904 	} else {
905 		fromlen = 0;
906 		sa = NULL;
907 	}
908 
909 	msg.msg_name = sa;
910 	msg.msg_namelen = fromlen;
911 	msg.msg_iov = &aiov;
912 	msg.msg_iovlen = 1;
913 	aiov.iov_base = PTRIN(args->buf);
914 	aiov.iov_len = args->len;
915 	msg.msg_control = 0;
916 	msg.msg_flags = linux_to_bsd_msg_flags(args->flags);
917 
918 	error = kern_recvit(td, args->s, &msg, UIO_SYSSPACE, NULL);
919 	if (error != 0)
920 		goto out;
921 
922 	if (PTRIN(args->from) != NULL) {
923 		error = bsd_to_linux_sockaddr(sa, &lsa, msg.msg_namelen);
924 		if (error == 0)
925 			error = copyout(lsa, PTRIN(args->from),
926 			    msg.msg_namelen);
927 		free(lsa, M_SONAME);
928 	}
929 
930 	if (error == 0 && PTRIN(args->fromlen) != NULL)
931 		error = copyout(&msg.msg_namelen, PTRIN(args->fromlen),
932 		    sizeof(msg.msg_namelen));
933 out:
934 	free(sa, M_SONAME);
935 	return (error);
936 }
937 
938 static int
939 linux_sendmsg_common(struct thread *td, l_int s, struct l_msghdr *msghdr,
940     l_uint flags)
941 {
942 	struct cmsghdr *cmsg;
943 	struct mbuf *control;
944 	struct msghdr msg;
945 	struct l_cmsghdr linux_cmsg;
946 	struct l_cmsghdr *ptr_cmsg;
947 	struct l_msghdr linux_msg;
948 	struct iovec *iov;
949 	socklen_t datalen;
950 	struct sockaddr *sa;
951 	struct socket *so;
952 	sa_family_t sa_family;
953 	struct file *fp;
954 	void *data;
955 	l_size_t len;
956 	l_size_t clen;
957 	int error, fflag;
958 
959 	error = copyin(msghdr, &linux_msg, sizeof(linux_msg));
960 	if (error != 0)
961 		return (error);
962 
963 	/*
964 	 * Some Linux applications (ping) define a non-NULL control data
965 	 * pointer, but a msg_controllen of 0, which is not allowed in the
966 	 * FreeBSD system call interface.  NULL the msg_control pointer in
967 	 * order to handle this case.  This should be checked, but allows the
968 	 * Linux ping to work.
969 	 */
970 	if (PTRIN(linux_msg.msg_control) != NULL && linux_msg.msg_controllen == 0)
971 		linux_msg.msg_control = PTROUT(NULL);
972 
973 	error = linux_to_bsd_msghdr(&msg, &linux_msg);
974 	if (error != 0)
975 		return (error);
976 
977 #ifdef COMPAT_LINUX32
978 	error = linux32_copyiniov(PTRIN(msg.msg_iov), msg.msg_iovlen,
979 	    &iov, EMSGSIZE);
980 #else
981 	error = copyiniov(msg.msg_iov, msg.msg_iovlen, &iov, EMSGSIZE);
982 #endif
983 	if (error != 0)
984 		return (error);
985 
986 	control = NULL;
987 
988 	error = kern_getsockname(td, s, &sa, &datalen);
989 	if (error != 0)
990 		goto bad;
991 	sa_family = sa->sa_family;
992 	free(sa, M_SONAME);
993 
994 	if (flags & LINUX_MSG_OOB) {
995 		error = EOPNOTSUPP;
996 		if (sa_family == AF_UNIX)
997 			goto bad;
998 
999 		error = getsock_cap(td, s, &cap_send_rights, &fp,
1000 		    &fflag, NULL);
1001 		if (error != 0)
1002 			goto bad;
1003 		so = fp->f_data;
1004 		if (so->so_type != SOCK_STREAM)
1005 			error = EOPNOTSUPP;
1006 		fdrop(fp, td);
1007 		if (error != 0)
1008 			goto bad;
1009 	}
1010 
1011 	if (linux_msg.msg_controllen >= sizeof(struct l_cmsghdr)) {
1012 
1013 		error = ENOBUFS;
1014 		control = m_get(M_WAITOK, MT_CONTROL);
1015 		MCLGET(control, M_WAITOK);
1016 		data = mtod(control, void *);
1017 		datalen = 0;
1018 
1019 		ptr_cmsg = PTRIN(linux_msg.msg_control);
1020 		clen = linux_msg.msg_controllen;
1021 		do {
1022 			error = copyin(ptr_cmsg, &linux_cmsg,
1023 			    sizeof(struct l_cmsghdr));
1024 			if (error != 0)
1025 				goto bad;
1026 
1027 			error = EINVAL;
1028 			if (linux_cmsg.cmsg_len < sizeof(struct l_cmsghdr) ||
1029 			    linux_cmsg.cmsg_len > clen)
1030 				goto bad;
1031 
1032 			if (datalen + CMSG_HDRSZ > MCLBYTES)
1033 				goto bad;
1034 
1035 			/*
1036 			 * Now we support only SCM_RIGHTS and SCM_CRED,
1037 			 * so return EINVAL in any other cmsg_type
1038 			 */
1039 			cmsg = data;
1040 			cmsg->cmsg_type =
1041 			    linux_to_bsd_cmsg_type(linux_cmsg.cmsg_type);
1042 			cmsg->cmsg_level =
1043 			    linux_to_bsd_sockopt_level(linux_cmsg.cmsg_level);
1044 			if (cmsg->cmsg_type == -1
1045 			    || cmsg->cmsg_level != SOL_SOCKET)
1046 				goto bad;
1047 
1048 			/*
1049 			 * Some applications (e.g. pulseaudio) attempt to
1050 			 * send ancillary data even if the underlying protocol
1051 			 * doesn't support it which is not allowed in the
1052 			 * FreeBSD system call interface.
1053 			 */
1054 			if (sa_family != AF_UNIX)
1055 				continue;
1056 
1057 			if (cmsg->cmsg_type == SCM_CREDS) {
1058 				len = sizeof(struct cmsgcred);
1059 				if (datalen + CMSG_SPACE(len) > MCLBYTES)
1060 					goto bad;
1061 
1062 				/*
1063 				 * The lower levels will fill in the structure
1064 				 */
1065 				memset(CMSG_DATA(data), 0, len);
1066 			} else {
1067 				len = linux_cmsg.cmsg_len - L_CMSG_HDRSZ;
1068 				if (datalen + CMSG_SPACE(len) < datalen ||
1069 				    datalen + CMSG_SPACE(len) > MCLBYTES)
1070 					goto bad;
1071 
1072 				error = copyin(LINUX_CMSG_DATA(ptr_cmsg),
1073 				    CMSG_DATA(data), len);
1074 				if (error != 0)
1075 					goto bad;
1076 			}
1077 
1078 			cmsg->cmsg_len = CMSG_LEN(len);
1079 			data = (char *)data + CMSG_SPACE(len);
1080 			datalen += CMSG_SPACE(len);
1081 
1082 			if (clen <= LINUX_CMSG_ALIGN(linux_cmsg.cmsg_len))
1083 				break;
1084 
1085 			clen -= LINUX_CMSG_ALIGN(linux_cmsg.cmsg_len);
1086 			ptr_cmsg = (struct l_cmsghdr *)((char *)ptr_cmsg +
1087 			    LINUX_CMSG_ALIGN(linux_cmsg.cmsg_len));
1088 		} while(clen >= sizeof(struct l_cmsghdr));
1089 
1090 		control->m_len = datalen;
1091 		if (datalen == 0) {
1092 			m_freem(control);
1093 			control = NULL;
1094 		}
1095 	}
1096 
1097 	msg.msg_iov = iov;
1098 	msg.msg_flags = 0;
1099 	error = linux_sendit(td, s, &msg, flags, control, UIO_USERSPACE);
1100 	control = NULL;
1101 
1102 bad:
1103 	m_freem(control);
1104 	free(iov, M_IOV);
1105 	return (error);
1106 }
1107 
1108 int
1109 linux_sendmsg(struct thread *td, struct linux_sendmsg_args *args)
1110 {
1111 
1112 	return (linux_sendmsg_common(td, args->s, PTRIN(args->msg),
1113 	    args->flags));
1114 }
1115 
1116 int
1117 linux_sendmmsg(struct thread *td, struct linux_sendmmsg_args *args)
1118 {
1119 	struct l_mmsghdr *msg;
1120 	l_uint retval;
1121 	int error, datagrams;
1122 
1123 	if (args->vlen > UIO_MAXIOV)
1124 		args->vlen = UIO_MAXIOV;
1125 
1126 	msg = PTRIN(args->msg);
1127 	datagrams = 0;
1128 	while (datagrams < args->vlen) {
1129 		error = linux_sendmsg_common(td, args->s, &msg->msg_hdr,
1130 		    args->flags);
1131 		if (error != 0)
1132 			break;
1133 
1134 		retval = td->td_retval[0];
1135 		error = copyout(&retval, &msg->msg_len, sizeof(msg->msg_len));
1136 		if (error != 0)
1137 			break;
1138 		++msg;
1139 		++datagrams;
1140 	}
1141 	if (error == 0)
1142 		td->td_retval[0] = datagrams;
1143 	return (error);
1144 }
1145 
1146 static int
1147 linux_recvmsg_common(struct thread *td, l_int s, struct l_msghdr *msghdr,
1148     l_uint flags, struct msghdr *msg)
1149 {
1150 	struct cmsghdr *cm;
1151 	struct cmsgcred *cmcred;
1152 	struct l_cmsghdr *linux_cmsg = NULL;
1153 	struct l_ucred linux_ucred;
1154 	socklen_t datalen, maxlen, outlen;
1155 	struct l_msghdr linux_msg;
1156 	struct iovec *iov, *uiov;
1157 	struct mbuf *control = NULL;
1158 	struct mbuf **controlp;
1159 	struct timeval *ftmvl;
1160 	struct l_sockaddr *lsa;
1161 	struct sockaddr *sa;
1162 	l_timeval ltmvl;
1163 	caddr_t outbuf;
1164 	void *data;
1165 	int error, i, fd, fds, *fdp;
1166 
1167 	error = copyin(msghdr, &linux_msg, sizeof(linux_msg));
1168 	if (error != 0)
1169 		return (error);
1170 
1171 	error = linux_to_bsd_msghdr(msg, &linux_msg);
1172 	if (error != 0)
1173 		return (error);
1174 
1175 #ifdef COMPAT_LINUX32
1176 	error = linux32_copyiniov(PTRIN(msg->msg_iov), msg->msg_iovlen,
1177 	    &iov, EMSGSIZE);
1178 #else
1179 	error = copyiniov(msg->msg_iov, msg->msg_iovlen, &iov, EMSGSIZE);
1180 #endif
1181 	if (error != 0)
1182 		return (error);
1183 
1184 	if (msg->msg_name) {
1185 		sa = malloc(msg->msg_namelen, M_SONAME, M_WAITOK);
1186 		msg->msg_name = sa;
1187 	} else
1188 		sa = NULL;
1189 
1190 	uiov = msg->msg_iov;
1191 	msg->msg_iov = iov;
1192 	controlp = (msg->msg_control != NULL) ? &control : NULL;
1193 	error = kern_recvit(td, s, msg, UIO_SYSSPACE, controlp);
1194 	msg->msg_iov = uiov;
1195 	if (error != 0)
1196 		goto bad;
1197 
1198 	if (msg->msg_name) {
1199 		msg->msg_name = PTRIN(linux_msg.msg_name);
1200 		error = bsd_to_linux_sockaddr(sa, &lsa, msg->msg_namelen);
1201 		if (error == 0)
1202 			error = copyout(lsa, PTRIN(msg->msg_name),
1203 			    msg->msg_namelen);
1204 		free(lsa, M_SONAME);
1205 		if (error != 0)
1206 			goto bad;
1207 	}
1208 
1209 	error = bsd_to_linux_msghdr(msg, &linux_msg);
1210 	if (error != 0)
1211 		goto bad;
1212 
1213 	maxlen = linux_msg.msg_controllen;
1214 	linux_msg.msg_controllen = 0;
1215 	if (control) {
1216 		linux_cmsg = malloc(L_CMSG_HDRSZ, M_LINUX, M_WAITOK | M_ZERO);
1217 
1218 		msg->msg_control = mtod(control, struct cmsghdr *);
1219 		msg->msg_controllen = control->m_len;
1220 
1221 		cm = CMSG_FIRSTHDR(msg);
1222 		outbuf = PTRIN(linux_msg.msg_control);
1223 		outlen = 0;
1224 		while (cm != NULL) {
1225 			linux_cmsg->cmsg_type =
1226 			    bsd_to_linux_cmsg_type(cm->cmsg_type);
1227 			linux_cmsg->cmsg_level =
1228 			    bsd_to_linux_sockopt_level(cm->cmsg_level);
1229 			if (linux_cmsg->cmsg_type == -1 ||
1230 			    cm->cmsg_level != SOL_SOCKET) {
1231 				error = EINVAL;
1232 				goto bad;
1233 			}
1234 
1235 			data = CMSG_DATA(cm);
1236 			datalen = (caddr_t)cm + cm->cmsg_len - (caddr_t)data;
1237 
1238 			switch (cm->cmsg_type) {
1239 			case SCM_RIGHTS:
1240 				if (flags & LINUX_MSG_CMSG_CLOEXEC) {
1241 					fds = datalen / sizeof(int);
1242 					fdp = data;
1243 					for (i = 0; i < fds; i++) {
1244 						fd = *fdp++;
1245 						(void)kern_fcntl(td, fd,
1246 						    F_SETFD, FD_CLOEXEC);
1247 					}
1248 				}
1249 				break;
1250 
1251 			case SCM_CREDS:
1252 				/*
1253 				 * Currently LOCAL_CREDS is never in
1254 				 * effect for Linux so no need to worry
1255 				 * about sockcred
1256 				 */
1257 				if (datalen != sizeof(*cmcred)) {
1258 					error = EMSGSIZE;
1259 					goto bad;
1260 				}
1261 				cmcred = (struct cmsgcred *)data;
1262 				bzero(&linux_ucred, sizeof(linux_ucred));
1263 				linux_ucred.pid = cmcred->cmcred_pid;
1264 				linux_ucred.uid = cmcred->cmcred_uid;
1265 				linux_ucred.gid = cmcred->cmcred_gid;
1266 				data = &linux_ucred;
1267 				datalen = sizeof(linux_ucred);
1268 				break;
1269 
1270 			case SCM_TIMESTAMP:
1271 				if (datalen != sizeof(struct timeval)) {
1272 					error = EMSGSIZE;
1273 					goto bad;
1274 				}
1275 				ftmvl = (struct timeval *)data;
1276 				ltmvl.tv_sec = ftmvl->tv_sec;
1277 				ltmvl.tv_usec = ftmvl->tv_usec;
1278 				data = &ltmvl;
1279 				datalen = sizeof(ltmvl);
1280 				break;
1281 			}
1282 
1283 			if (outlen + LINUX_CMSG_LEN(datalen) > maxlen) {
1284 				if (outlen == 0) {
1285 					error = EMSGSIZE;
1286 					goto bad;
1287 				} else {
1288 					linux_msg.msg_flags |= LINUX_MSG_CTRUNC;
1289 					m_dispose_extcontrolm(control);
1290 					goto out;
1291 				}
1292 			}
1293 
1294 			linux_cmsg->cmsg_len = LINUX_CMSG_LEN(datalen);
1295 
1296 			error = copyout(linux_cmsg, outbuf, L_CMSG_HDRSZ);
1297 			if (error != 0)
1298 				goto bad;
1299 			outbuf += L_CMSG_HDRSZ;
1300 
1301 			error = copyout(data, outbuf, datalen);
1302 			if (error != 0)
1303 				goto bad;
1304 
1305 			outbuf += LINUX_CMSG_ALIGN(datalen);
1306 			outlen += LINUX_CMSG_LEN(datalen);
1307 
1308 			cm = CMSG_NXTHDR(msg, cm);
1309 		}
1310 		linux_msg.msg_controllen = outlen;
1311 	}
1312 
1313 out:
1314 	error = copyout(&linux_msg, msghdr, sizeof(linux_msg));
1315 
1316 bad:
1317 	if (control != NULL) {
1318 		if (error != 0)
1319 			m_dispose_extcontrolm(control);
1320 		m_freem(control);
1321 	}
1322 	free(iov, M_IOV);
1323 	free(linux_cmsg, M_LINUX);
1324 	free(sa, M_SONAME);
1325 
1326 	return (error);
1327 }
1328 
1329 int
1330 linux_recvmsg(struct thread *td, struct linux_recvmsg_args *args)
1331 {
1332 	struct msghdr bsd_msg;
1333 
1334 	return (linux_recvmsg_common(td, args->s, PTRIN(args->msg),
1335 	    args->flags, &bsd_msg));
1336 }
1337 
1338 int
1339 linux_recvmmsg(struct thread *td, struct linux_recvmmsg_args *args)
1340 {
1341 	struct l_mmsghdr *msg;
1342 	struct msghdr bsd_msg;
1343 	struct l_timespec lts;
1344 	struct timespec ts, tts;
1345 	l_uint retval;
1346 	int error, datagrams;
1347 
1348 	if (args->timeout) {
1349 		error = copyin(args->timeout, &lts, sizeof(struct l_timespec));
1350 		if (error != 0)
1351 			return (error);
1352 		error = linux_to_native_timespec(&ts, &lts);
1353 		if (error != 0)
1354 			return (error);
1355 		getnanotime(&tts);
1356 		timespecadd(&tts, &ts, &tts);
1357 	}
1358 
1359 	msg = PTRIN(args->msg);
1360 	datagrams = 0;
1361 	while (datagrams < args->vlen) {
1362 		error = linux_recvmsg_common(td, args->s, &msg->msg_hdr,
1363 		    args->flags & ~LINUX_MSG_WAITFORONE, &bsd_msg);
1364 		if (error != 0)
1365 			break;
1366 
1367 		retval = td->td_retval[0];
1368 		error = copyout(&retval, &msg->msg_len, sizeof(msg->msg_len));
1369 		if (error != 0)
1370 			break;
1371 		++msg;
1372 		++datagrams;
1373 
1374 		/*
1375 		 * MSG_WAITFORONE turns on MSG_DONTWAIT after one packet.
1376 		 */
1377 		if (args->flags & LINUX_MSG_WAITFORONE)
1378 			args->flags |= LINUX_MSG_DONTWAIT;
1379 
1380 		/*
1381 		 * See BUGS section of recvmmsg(2).
1382 		 */
1383 		if (args->timeout) {
1384 			getnanotime(&ts);
1385 			timespecsub(&ts, &tts, &ts);
1386 			if (!timespecisset(&ts) || ts.tv_sec > 0)
1387 				break;
1388 		}
1389 		/* Out of band data, return right away. */
1390 		if (bsd_msg.msg_flags & MSG_OOB)
1391 			break;
1392 	}
1393 	if (error == 0)
1394 		td->td_retval[0] = datagrams;
1395 	return (error);
1396 }
1397 
1398 int
1399 linux_shutdown(struct thread *td, struct linux_shutdown_args *args)
1400 {
1401 
1402 	return (kern_shutdown(td, args->s, args->how));
1403 }
1404 
1405 int
1406 linux_setsockopt(struct thread *td, struct linux_setsockopt_args *args)
1407 {
1408 	l_timeval linux_tv;
1409 	struct sockaddr *sa;
1410 	struct timeval tv;
1411 	socklen_t len;
1412 	int error, level, name;
1413 
1414 	level = linux_to_bsd_sockopt_level(args->level);
1415 	switch (level) {
1416 	case SOL_SOCKET:
1417 		name = linux_to_bsd_so_sockopt(args->optname);
1418 		switch (name) {
1419 		case SO_RCVTIMEO:
1420 			/* FALLTHROUGH */
1421 		case SO_SNDTIMEO:
1422 			error = copyin(PTRIN(args->optval), &linux_tv,
1423 			    sizeof(linux_tv));
1424 			if (error != 0)
1425 				return (error);
1426 			tv.tv_sec = linux_tv.tv_sec;
1427 			tv.tv_usec = linux_tv.tv_usec;
1428 			return (kern_setsockopt(td, args->s, level,
1429 			    name, &tv, UIO_SYSSPACE, sizeof(tv)));
1430 			/* NOTREACHED */
1431 		default:
1432 			break;
1433 		}
1434 		break;
1435 	case IPPROTO_IP:
1436 		if (args->optname == LINUX_IP_RECVERR &&
1437 		    linux_ignore_ip_recverr) {
1438 			/*
1439 			 * XXX: This is a hack to unbreak DNS resolution
1440 			 *	with glibc 2.30 and above.
1441 			 */
1442 			return (0);
1443 		}
1444 		name = linux_to_bsd_ip_sockopt(args->optname);
1445 		break;
1446 	case IPPROTO_IPV6:
1447 		name = linux_to_bsd_ip6_sockopt(args->optname);
1448 		break;
1449 	case IPPROTO_TCP:
1450 		name = linux_to_bsd_tcp_sockopt(args->optname);
1451 		break;
1452 	default:
1453 		name = -1;
1454 		break;
1455 	}
1456 	if (name == -1) {
1457 		linux_msg(curthread,
1458 		    "unsupported setsockopt level %d optname %d",
1459 		    args->level, args->optname);
1460 		return (ENOPROTOOPT);
1461 	}
1462 
1463 	if (name == IPV6_NEXTHOP) {
1464 		len = args->optlen;
1465 		error = linux_to_bsd_sockaddr(PTRIN(args->optval), &sa, &len);
1466 		if (error != 0)
1467 			return (error);
1468 
1469 		error = kern_setsockopt(td, args->s, level,
1470 		    name, sa, UIO_SYSSPACE, len);
1471 		free(sa, M_SONAME);
1472 	} else {
1473 		error = kern_setsockopt(td, args->s, level,
1474 		    name, PTRIN(args->optval), UIO_USERSPACE, args->optlen);
1475 	}
1476 
1477 	return (error);
1478 }
1479 
1480 int
1481 linux_getsockopt(struct thread *td, struct linux_getsockopt_args *args)
1482 {
1483 	l_timeval linux_tv;
1484 	struct timeval tv;
1485 	socklen_t tv_len, xulen, len;
1486 	struct l_sockaddr *lsa;
1487 	struct sockaddr *sa;
1488 	struct xucred xu;
1489 	struct l_ucred lxu;
1490 	int error, level, name, newval;
1491 
1492 	level = linux_to_bsd_sockopt_level(args->level);
1493 	switch (level) {
1494 	case SOL_SOCKET:
1495 		name = linux_to_bsd_so_sockopt(args->optname);
1496 		switch (name) {
1497 		case SO_RCVTIMEO:
1498 			/* FALLTHROUGH */
1499 		case SO_SNDTIMEO:
1500 			tv_len = sizeof(tv);
1501 			error = kern_getsockopt(td, args->s, level,
1502 			    name, &tv, UIO_SYSSPACE, &tv_len);
1503 			if (error != 0)
1504 				return (error);
1505 			linux_tv.tv_sec = tv.tv_sec;
1506 			linux_tv.tv_usec = tv.tv_usec;
1507 			return (copyout(&linux_tv, PTRIN(args->optval),
1508 			    sizeof(linux_tv)));
1509 			/* NOTREACHED */
1510 		case LOCAL_PEERCRED:
1511 			if (args->optlen < sizeof(lxu))
1512 				return (EINVAL);
1513 			/*
1514 			 * LOCAL_PEERCRED is not served at the SOL_SOCKET level,
1515 			 * but by the Unix socket's level 0.
1516 			 */
1517 			level = 0;
1518 			xulen = sizeof(xu);
1519 			error = kern_getsockopt(td, args->s, level,
1520 			    name, &xu, UIO_SYSSPACE, &xulen);
1521 			if (error != 0)
1522 				return (error);
1523 			lxu.pid = xu.cr_pid;
1524 			lxu.uid = xu.cr_uid;
1525 			lxu.gid = xu.cr_gid;
1526 			return (copyout(&lxu, PTRIN(args->optval), sizeof(lxu)));
1527 			/* NOTREACHED */
1528 		case SO_ERROR:
1529 			len = sizeof(newval);
1530 			error = kern_getsockopt(td, args->s, level,
1531 			    name, &newval, UIO_SYSSPACE, &len);
1532 			if (error != 0)
1533 				return (error);
1534 			newval = -SV_ABI_ERRNO(td->td_proc, newval);
1535 			return (copyout(&newval, PTRIN(args->optval), len));
1536 			/* NOTREACHED */
1537 		default:
1538 			break;
1539 		}
1540 		break;
1541 	case IPPROTO_IP:
1542 		name = linux_to_bsd_ip_sockopt(args->optname);
1543 		break;
1544 	case IPPROTO_IPV6:
1545 		name = linux_to_bsd_ip6_sockopt(args->optname);
1546 		break;
1547 	case IPPROTO_TCP:
1548 		name = linux_to_bsd_tcp_sockopt(args->optname);
1549 		break;
1550 	default:
1551 		name = -1;
1552 		break;
1553 	}
1554 	if (name == -1) {
1555 		linux_msg(curthread,
1556 		    "unsupported getsockopt level %d optname %d",
1557 		    args->level, args->optname);
1558 		return (EINVAL);
1559 	}
1560 
1561 	if (name == IPV6_NEXTHOP) {
1562 		error = copyin(PTRIN(args->optlen), &len, sizeof(len));
1563                 if (error != 0)
1564                         return (error);
1565 		sa = malloc(len, M_SONAME, M_WAITOK);
1566 
1567 		error = kern_getsockopt(td, args->s, level,
1568 		    name, sa, UIO_SYSSPACE, &len);
1569 		if (error != 0)
1570 			goto out;
1571 
1572 		error = bsd_to_linux_sockaddr(sa, &lsa, len);
1573 		if (error == 0)
1574 			error = copyout(lsa, PTRIN(args->optval), len);
1575 		free(lsa, M_SONAME);
1576 		if (error == 0)
1577 			error = copyout(&len, PTRIN(args->optlen),
1578 			    sizeof(len));
1579 out:
1580 		free(sa, M_SONAME);
1581 	} else {
1582 		if (args->optval) {
1583 			error = copyin(PTRIN(args->optlen), &len, sizeof(len));
1584 			if (error != 0)
1585 				return (error);
1586 		}
1587 		error = kern_getsockopt(td, args->s, level,
1588 		    name, PTRIN(args->optval), UIO_USERSPACE, &len);
1589 		if (error == 0)
1590 			error = copyout(&len, PTRIN(args->optlen),
1591 			    sizeof(len));
1592 	}
1593 
1594 	return (error);
1595 }
1596 
1597 static int
1598 linux_sendfile_common(struct thread *td, l_int out, l_int in,
1599     l_loff_t *offset, l_size_t count)
1600 {
1601 	off_t bytes_read;
1602 	int error;
1603 	l_loff_t current_offset;
1604 	struct file *fp;
1605 
1606 	AUDIT_ARG_FD(in);
1607 	error = fget_read(td, in, &cap_pread_rights, &fp);
1608 	if (error != 0)
1609 		return (error);
1610 
1611 	if (offset != NULL) {
1612 		current_offset = *offset;
1613 	} else {
1614 		error = (fp->f_ops->fo_flags & DFLAG_SEEKABLE) != 0 ?
1615 		    fo_seek(fp, 0, SEEK_CUR, td) : ESPIPE;
1616 		if (error != 0)
1617 			goto drop;
1618 		current_offset = td->td_uretoff.tdu_off;
1619 	}
1620 
1621 	bytes_read = 0;
1622 
1623 	/* Linux cannot have 0 count. */
1624 	if (count <= 0 || current_offset < 0) {
1625 		error = EINVAL;
1626 		goto drop;
1627 	}
1628 
1629 	error = fo_sendfile(fp, out, NULL, NULL, current_offset, count,
1630 	    &bytes_read, 0, td);
1631 	if (error != 0)
1632 		goto drop;
1633 	current_offset += bytes_read;
1634 
1635 	if (offset != NULL) {
1636 		*offset = current_offset;
1637 	} else {
1638 		error = fo_seek(fp, current_offset, SEEK_SET, td);
1639 		if (error != 0)
1640 			goto drop;
1641 	}
1642 
1643 	td->td_retval[0] = (ssize_t)bytes_read;
1644 drop:
1645 	fdrop(fp, td);
1646 	return (error);
1647 }
1648 
1649 int
1650 linux_sendfile(struct thread *td, struct linux_sendfile_args *arg)
1651 {
1652 	/*
1653 	 * Differences between FreeBSD and Linux sendfile:
1654 	 * - Linux doesn't send anything when count is 0 (FreeBSD uses 0 to
1655 	 *   mean send the whole file.)  In linux_sendfile given fds are still
1656 	 *   checked for validity when the count is 0.
1657 	 * - Linux can send to any fd whereas FreeBSD only supports sockets.
1658 	 *   The same restriction follows for linux_sendfile.
1659 	 * - Linux doesn't have an equivalent for FreeBSD's flags and sf_hdtr.
1660 	 * - Linux takes an offset pointer and updates it to the read location.
1661 	 *   FreeBSD takes in an offset and a 'bytes read' parameter which is
1662 	 *   only filled if it isn't NULL.  We use this parameter to update the
1663 	 *   offset pointer if it exists.
1664 	 * - Linux sendfile returns bytes read on success while FreeBSD
1665 	 *   returns 0.  We use the 'bytes read' parameter to get this value.
1666 	 */
1667 
1668 	l_loff_t offset64;
1669 	l_long offset;
1670 	int ret;
1671 	int error;
1672 
1673 	if (arg->offset != NULL) {
1674 		error = copyin(arg->offset, &offset, sizeof(offset));
1675 		if (error != 0)
1676 			return (error);
1677 		offset64 = (l_loff_t)offset;
1678 	}
1679 
1680 	ret = linux_sendfile_common(td, arg->out, arg->in,
1681 	    arg->offset != NULL ? &offset64 : NULL, arg->count);
1682 
1683 	if (arg->offset != NULL) {
1684 #if defined(__i386__) || defined(__arm__) || \
1685     (defined(__amd64__) && defined(COMPAT_LINUX32))
1686 		if (offset64 > INT32_MAX)
1687 			return (EOVERFLOW);
1688 #endif
1689 		offset = (l_long)offset64;
1690 		error = copyout(&offset, arg->offset, sizeof(offset));
1691 		if (error != 0)
1692 			return (error);
1693 	}
1694 
1695 	return (ret);
1696 }
1697 
1698 #if defined(__i386__) || defined(__arm__) || \
1699     (defined(__amd64__) && defined(COMPAT_LINUX32))
1700 
1701 int
1702 linux_sendfile64(struct thread *td, struct linux_sendfile64_args *arg)
1703 {
1704 	l_loff_t offset;
1705 	int ret;
1706 	int error;
1707 
1708 	if (arg->offset != NULL) {
1709 		error = copyin(arg->offset, &offset, sizeof(offset));
1710 		if (error != 0)
1711 			return (error);
1712 	}
1713 
1714 	ret = linux_sendfile_common(td, arg->out, arg->in,
1715 		arg->offset != NULL ? &offset : NULL, arg->count);
1716 
1717 	if (arg->offset != NULL) {
1718 		error = copyout(&offset, arg->offset, sizeof(offset));
1719 		if (error != 0)
1720 			return (error);
1721 	}
1722 
1723 	return (ret);
1724 }
1725 
1726 /* Argument list sizes for linux_socketcall */
1727 static const unsigned char lxs_args_cnt[] = {
1728 	0 /* unused*/,		3 /* socket */,
1729 	3 /* bind */,		3 /* connect */,
1730 	2 /* listen */,		3 /* accept */,
1731 	3 /* getsockname */,	3 /* getpeername */,
1732 	4 /* socketpair */,	4 /* send */,
1733 	4 /* recv */,		6 /* sendto */,
1734 	6 /* recvfrom */,	2 /* shutdown */,
1735 	5 /* setsockopt */,	5 /* getsockopt */,
1736 	3 /* sendmsg */,	3 /* recvmsg */,
1737 	4 /* accept4 */,	5 /* recvmmsg */,
1738 	4 /* sendmmsg */,	4 /* sendfile */
1739 };
1740 #define	LINUX_ARGS_CNT		(nitems(lxs_args_cnt) - 1)
1741 #define	LINUX_ARG_SIZE(x)	(lxs_args_cnt[x] * sizeof(l_ulong))
1742 
1743 int
1744 linux_socketcall(struct thread *td, struct linux_socketcall_args *args)
1745 {
1746 	l_ulong a[6];
1747 #if defined(__amd64__) && defined(COMPAT_LINUX32)
1748 	register_t l_args[6];
1749 #endif
1750 	void *arg;
1751 	int error;
1752 
1753 	if (args->what < LINUX_SOCKET || args->what > LINUX_ARGS_CNT)
1754 		return (EINVAL);
1755 	error = copyin(PTRIN(args->args), a, LINUX_ARG_SIZE(args->what));
1756 	if (error != 0)
1757 		return (error);
1758 
1759 #if defined(__amd64__) && defined(COMPAT_LINUX32)
1760 	for (int i = 0; i < lxs_args_cnt[args->what]; ++i)
1761 		l_args[i] = a[i];
1762 	arg = l_args;
1763 #else
1764 	arg = a;
1765 #endif
1766 	switch (args->what) {
1767 	case LINUX_SOCKET:
1768 		return (linux_socket(td, arg));
1769 	case LINUX_BIND:
1770 		return (linux_bind(td, arg));
1771 	case LINUX_CONNECT:
1772 		return (linux_connect(td, arg));
1773 	case LINUX_LISTEN:
1774 		return (linux_listen(td, arg));
1775 	case LINUX_ACCEPT:
1776 		return (linux_accept(td, arg));
1777 	case LINUX_GETSOCKNAME:
1778 		return (linux_getsockname(td, arg));
1779 	case LINUX_GETPEERNAME:
1780 		return (linux_getpeername(td, arg));
1781 	case LINUX_SOCKETPAIR:
1782 		return (linux_socketpair(td, arg));
1783 	case LINUX_SEND:
1784 		return (linux_send(td, arg));
1785 	case LINUX_RECV:
1786 		return (linux_recv(td, arg));
1787 	case LINUX_SENDTO:
1788 		return (linux_sendto(td, arg));
1789 	case LINUX_RECVFROM:
1790 		return (linux_recvfrom(td, arg));
1791 	case LINUX_SHUTDOWN:
1792 		return (linux_shutdown(td, arg));
1793 	case LINUX_SETSOCKOPT:
1794 		return (linux_setsockopt(td, arg));
1795 	case LINUX_GETSOCKOPT:
1796 		return (linux_getsockopt(td, arg));
1797 	case LINUX_SENDMSG:
1798 		return (linux_sendmsg(td, arg));
1799 	case LINUX_RECVMSG:
1800 		return (linux_recvmsg(td, arg));
1801 	case LINUX_ACCEPT4:
1802 		return (linux_accept4(td, arg));
1803 	case LINUX_RECVMMSG:
1804 		return (linux_recvmmsg(td, arg));
1805 	case LINUX_SENDMMSG:
1806 		return (linux_sendmmsg(td, arg));
1807 	case LINUX_SENDFILE:
1808 		return (linux_sendfile(td, arg));
1809 	}
1810 
1811 	uprintf("LINUX: 'socket' typ=%d not implemented\n", args->what);
1812 	return (ENOSYS);
1813 }
1814 #endif /* __i386__ || __arm__ || (__amd64__ && COMPAT_LINUX32) */
1815