From nobody Sun Jul 12 14:25:42 2026 X-Original-To: dev-commits-doc-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4gynt35gTkz6lRZw for ; Sun, 12 Jul 2026 14:25:47 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4gynt359Nkz3qZF for ; Sun, 12 Jul 2026 14:25:47 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1783866347; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=/CgfoyM0yT6KUovRlsHydEdiXv0h81ZSOTdu/HDpBlk=; b=eiYrBYiKg4dMhq9Weo11+W0JZyq0w8d2o9h++50h/ny0ZJJ1rib7uUsc4Nj0PTQW0gAxYI xR+tiBquUPlZiu26jozWp7FkaGBF52G8+JsSZrDVfR1ZGVmYS0JxrU9NwV9Uxv0gJV/wcv aOG5klgB16YtW093cgaZnk7Xdk6NLbnV6DmFMf2Qvvt5jKAt7nz3F8TTTT/5zQyYI/Psbd IzXsZiMkyNja+W69tp0yv8Xsr9+yvQtSbmE0nJhyvXqeEwREyIl7r1KzJXdX7oCJm3AX6+ WzWMkMkFjBS7Zrmy70YD3kRU30c4qktpW8Nq2qsWMnMG3sWLl8maBr323i7EFA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1783866347; a=rsa-sha256; cv=none; b=kRS55IA8RL2MnZzan84b4Cdti3EJLTqGd9NMQXaIsLWxo9dRiipfavHdxpe0Rlp8Ovj0j3 s7HYEHjQkKsXvjEu7FIfIH1O5bQxVAV2njxFjADKm6TazcaPk55Lw7rQoz/n4xo7aaF5r0 jpHb+jBLLzxonT6ej995Wv1UPRzl2BLyzYy8NosMdrhUC+Seli4CghZwpg0Oxrjfhl5CXF yvjJwC1L1/Bl8wB9Eu6F2+PElmxGzljyCnke8cvkLIlXFQDXaXnuYcJG+vllVXhdJlJNCF pOWCVlI9l50SPfJZ69MQuyipgUh4at5tr4y1ASX+uVQlav5Qlh3T/aA0rZbxFA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1783866347; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=/CgfoyM0yT6KUovRlsHydEdiXv0h81ZSOTdu/HDpBlk=; b=qnEF6K9ENT5k7ElsHc6FN5hwKt2C3fyp3v82/aeyxfdps1flL8hV133uxJZATNIJLlmL+0 8fVU5YBmSNUNjmbpksakZPXSRfpML3kleOQjvvcUS+GYUheUTID7zM/Nbz8oo2TX06oCCs Q/00vrI5sOtn5GJY8iARSqr16ZeOhVousiKxUHQIRnY5/yXdq9Awiup77uXXDTJVNeqhND yMapHkY/GFz0Nn+ykGEAsFxlVq8fVBLiXhq9sLuNRzP58ZLVWZ/VMtWSUAMLzoQVuXtSo5 Z925/5Tnda6FxDvqLWp91qL8RsY84MJXrzHA0Uw5ufNgRfNad2VSUdHpncQ8FQ== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4gynt33k7Xz1Yd for ; Sun, 12 Jul 2026 14:25:47 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 38e5e by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sun, 12 Jul 2026 14:25:42 +0000 To: doc-committers@FreeBSD.org, dev-commits-doc-all@FreeBSD.org From: Konstantin Belousov Subject: git: 2ac8002351 - main - pdopenpid(2)/pddupfd(2)/execblock report List-Id: Commit messages for all branches of the doc repository List-Archive: https://lists.freebsd.org/archives/dev-commits-doc-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-doc-all@freebsd.org Sender: owner-dev-commits-doc-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kib X-Git-Repository: doc X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 2ac80023518f95ac2869935ecb3ca3bb90c678d4 Auto-Submitted: auto-generated Date: Sun, 12 Jul 2026 14:25:42 +0000 Message-Id: <6a53a3e6.38e5e.6278b543@gitrepo.freebsd.org> The branch main has been updated by kib: URL: https://cgit.FreeBSD.org/doc/commit/?id=2ac80023518f95ac2869935ecb3ca3bb90c678d4 commit 2ac80023518f95ac2869935ecb3ca3bb90c678d4 Author: Konstantin Belousov AuthorDate: 2026-06-09 01:14:36 +0000 Commit: Konstantin Belousov CommitDate: 2026-07-12 14:25:17 +0000 pdopenpid(2)/pddupfd(2)/execblock report Reviewed by: salvadore Sponsored by: The FreeBSD Foundation Differential revision: https://reviews.freebsd.org/D57935 --- .../status/report-2026-04-2026-06/pdopenpid.adoc | 33 ++++++++++++++++++++++ 1 file changed, 33 insertions(+) diff --git a/website/content/en/status/report-2026-04-2026-06/pdopenpid.adoc b/website/content/en/status/report-2026-04-2026-06/pdopenpid.adoc new file mode 100644 index 0000000000..8439605cf7 --- /dev/null +++ b/website/content/en/status/report-2026-04-2026-06/pdopenpid.adoc @@ -0,0 +1,33 @@ +=== Process Descriptor API completion 2 + +Contact: Konstantin Belousov + +Links: + +link:https://reviews.freebsd.org/D57124[sys: add pdopenpid(2)] URL: link:https://reviews.freebsd.org/D57124[] + +link https://reviews.freebsd.org/D57163[pddupfd(2)] https://reviews.freebsd.org/D57163[] + +Following the addition of man:pdwait[2] and man:pdrfork[2] system calls, I looked at the other missing features that are requested by application programmers. +The largest feature asked for seems to be an ability to obtain a process descriptor for an existing process. + +Currently only one file descriptor may reference an internal struct procdesc in kernel, which in part explains why the interface to open the process by pid is not yet done. +The work added the ability for procdescs to be pointed to by more than one file. +Attributes controlling the procdesc behavior, e.g. the daemon (closing the file does not terminate the process) were moved from procdesc to the file. + +This change allowed to extend the procdesc internal interfaces to implement the man:pdopenid(2) system call. + +A facility implemented e.g. by the Linux pidfd descriptors is the pidfd_getfd() system call, that duplicates specified file descriptor from the target process, into the caller. +The implementation of it for FreeBSD, named man:pddupfd(2) is relatively straightforward once we get the fget_remote(9) helper. + +A problem with it started when the algorithm to check for privileges required to allow the operation was developed. +The kernel checks the result of p_candebug() to see if something should be allowed that directly accesses programming resources of the remote process. +But p_candebug() result is only valid while the target process lock is owned. +Besides, p_candebug() denies actions if the target process changes the executing program with man:execve(2), which might change the privileges of the process if the image is set-uid or set-gid. +Overall, this makes the plain check with p_candebug() inadequate, because we cannot own the process lock over fget_remote(). + +For that, a facility was developed that provides mutual exclusion for execing in the target process vs. the caller, called execblock. +Also, helpers to reference the current vmspace for a process were added, to avoid using execblock when only a consistent target address space is required for the action, like reading of the process strings or copying the process memory. +Existing places in system that are affected by the race were identified, and the usage of execblock or vmspace referencing interfaces applied as needed. + +Then, the man:pddupfd(2) was implemented with the help of fget_remote() and execblock. + +Sponsor: The FreeBSD Foundation