From nobody Thu Aug 6 23:21:35 2026 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hGNZs3gfnz6nRX7 for ; Thu, 06 Aug 2026 23:21:41 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR1" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hGNZr4LNYz3Y2W for ; Thu, 06 Aug 2026 23:21:40 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1786058500; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=68pfGbt8eDaPUGuiaMf9S+qTcOIbNN1C5udOFvu5GBg=; b=G6CCdklXIJQFE/Kf+meEklDlmu23AorxYNN3/JL+d/4YzwdYqLb2wNSlw+YCDmPpswol54 R3mFclJtg5jDl0BbsmwsI5Aq2+VWfzGWj3wVZ8/QFN6S4IeBTwWkhHdcedMVan84NRJ+MP KvxE0YHFMIlILRIVNY9/zw6a9zpeWqUECMUamSkcxu3DObebJCaq77Wia0BWUzCcI3O/XB 2RNZNm1cyF2jTSvzhyoVDeeKOlVkxfgUSsh4rIe2uPx00C7QOAFBI4C3VTF8ANJUCQKpBr bgOP4iqlgAZTIaipN+AA0ExJEnT06qas06hwNZuJCwJr1RinEhNut98WF+JMbA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1786058500; a=rsa-sha256; cv=none; b=ej6nYyWoh0YBiLuDUHj+l0HTfaJUYvX4+kLqiCk17lgW+hV96mS7dI6n8MCZeHsOVo6GO5 uuRKOUeRYTJ7Tp3/syRwBIQ5sPl0Tp1L9J3nYIsnIX3WE/qheLpCXlAR2mDIdlHd6feALu RVe4MU65QF4CcymqYrF9DJTBwVZIbWkR55fCgGq9EESTlxINxhr6SPWyZ02iFnIwUoUN1K 8/aL9a/GyAL5gtqRIKoNJQKR4ZXyUecmBJo0INTYO9gLevjkVdLshXSW1sNfk0DbqeeWw3 kbMeVUxzB63RMEgv+EmTAh9OWeA6vQG2cuCFoxlM5DxDg5KRhuUQ9PbO6grMXw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1786058500; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=68pfGbt8eDaPUGuiaMf9S+qTcOIbNN1C5udOFvu5GBg=; b=DTr/BnSqoTHosBudx//plJF4t+Vu6oB8jOU29bRL+nmj9Eb6AdHdLDzwMvyww2tSzFCha3 otIyK0nILODaJEEh0CZSsEdEl/pDP26ElTQY7zu+hNRulMjhk6dns2/b6dk01sgEqzxvNX 70CpIOp9Fe+MQURIZfA28fH4gXx9WNRS8uWR1FGcxU2nvca1P9R+1dQ3Ko60IROcMo4rAz mDKlNJO7Ui838MRpZmox2FwBfHYtywjP6JPAz84xH4/YIJOdwNOtfYwRLC5SCKS87XVx8w pEGoc79t9OFQIwBs6ekL7eQQXVnDp6rhETlkgwrcirx/D1zd/ARDkQhhmP4VTA== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hGNZr34VtzhkJ for ; Thu, 06 Aug 2026 23:21:40 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 24861 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Thu, 06 Aug 2026 23:21:35 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Kyle Evans Subject: git: 8ab54c5d7dd9 - stable/14 - rights(4): fix our representation of the unused bits List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-branches@freebsd.org Sender: owner-dev-commits-src-branches@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kevans X-Git-Repository: src X-Git-Refname: refs/heads/stable/14 X-Git-Reftype: branch X-Git-Commit: 8ab54c5d7dd9e83a450c96742e4c1f229459fab2 Auto-Submitted: auto-generated Date: Thu, 06 Aug 2026 23:21:35 +0000 Message-Id: <6a7516ff.24861.24d2a055@gitrepo.freebsd.org> The branch stable/14 has been updated by kevans: URL: https://cgit.FreeBSD.org/src/commit/?id=8ab54c5d7dd9e83a450c96742e4c1f229459fab2 commit 8ab54c5d7dd9e83a450c96742e4c1f229459fab2 Author: Kyle Evans AuthorDate: 2026-06-20 13:55:26 +0000 Commit: Kyle Evans CommitDate: 2026-08-06 22:51:51 +0000 rights(4): fix our representation of the unused bits The current format seems to be a little confusing, and the version of it for index 0 was broken by the below-referenced commit. Break our UNUSED macros out into one per unused bit to enumerate the entirety of the space and make it easier to claim an unused one. Reviewed by: oshogbo (previous version), kib, markj (cherry picked from commit 57fefbee1f959d0c65376dbdad309d01c182d710) --- sys/sys/capsicum.h | 67 ++++++++++++++++++++++++++++++++++++++++++++++-------- 1 file changed, 57 insertions(+), 10 deletions(-) diff --git a/sys/sys/capsicum.h b/sys/sys/capsicum.h index 2393a39fecb9..255451881de1 100644 --- a/sys/sys/capsicum.h +++ b/sys/sys/capsicum.h @@ -52,6 +52,13 @@ #define CAPRIGHT(idx, bit) ((1ULL << (57 + (idx))) | (bit)) +/* + * The top 7 bits are reserved in all indices. + * Index 0 - 2 bit array size + 5 bit array element + * Index N - 2 bits of 0 + 5 bit array element + */ +#define CAP_RESERVED 0xFE00000000000000ULL + /* * Possible rights on capabilities. * @@ -210,14 +217,24 @@ CAP_GETSOCKOPT | CAP_LISTEN | CAP_PEELOFF | CAP_RECV | CAP_SEND | \ CAP_SETSOCKOPT | CAP_SHUTDOWN) -/* All used bits for index 0. */ -#define CAP_ALL0 CAPRIGHT(0, 0x000007FFFFFFFFFFULL) - -/* Available bits for index 0. */ #define CAP_UNUSED0_44 CAPRIGHT(0, 0x0000080000000000ULL) -/* ... */ +#define CAP_UNUSED0_45 CAPRIGHT(0, 0x0000100000000000ULL) +#define CAP_UNUSED0_46 CAPRIGHT(0, 0x0000200000000000ULL) +#define CAP_UNUSED0_47 CAPRIGHT(0, 0x0000400000000000ULL) +#define CAP_UNUSED0_48 CAPRIGHT(0, 0x0000800000000000ULL) +#define CAP_UNUSED0_49 CAPRIGHT(0, 0x0001000000000000ULL) +#define CAP_UNUSED0_50 CAPRIGHT(0, 0x0002000000000000ULL) +#define CAP_UNUSED0_51 CAPRIGHT(0, 0x0004000000000000ULL) +#define CAP_UNUSED0_52 CAPRIGHT(0, 0x0008000000000000ULL) +#define CAP_UNUSED0_53 CAPRIGHT(0, 0x0010000000000000ULL) +#define CAP_UNUSED0_54 CAPRIGHT(0, 0x0020000000000000ULL) +#define CAP_UNUSED0_55 CAPRIGHT(0, 0x0040000000000000ULL) +#define CAP_UNUSED0_56 CAPRIGHT(0, 0x0080000000000000ULL) #define CAP_UNUSED0_57 CAPRIGHT(0, 0x0100000000000000ULL) +/* All used bits for index 0. */ +#define CAP_ALL0 CAPRIGHT(0, 0x000007FFFFFFFFFFULL) + /* INDEX 1 */ /* Mandatory Access Control. */ @@ -283,14 +300,44 @@ #define CAP_INOTIFY_ADD CAPRIGHT(1, 0x0000000000200000ULL) #define CAP_INOTIFY_RM CAPRIGHT(1, 0x0000000000400000ULL) +#define CAP_UNUSED1_24 CAPRIGHT(1, 0x0000000000800000ULL) +#define CAP_UNUSED1_25 CAPRIGHT(1, 0x0000000001000000ULL) +#define CAP_UNUSED1_26 CAPRIGHT(1, 0x0000000002000000ULL) +#define CAP_UNUSED1_27 CAPRIGHT(1, 0x0000000004000000ULL) +#define CAP_UNUSED1_28 CAPRIGHT(1, 0x0000000008000000ULL) +#define CAP_UNUSED1_29 CAPRIGHT(1, 0x0000000010000000ULL) +#define CAP_UNUSED1_30 CAPRIGHT(1, 0x0000000020000000ULL) +#define CAP_UNUSED1_31 CAPRIGHT(1, 0x0000000040000000ULL) +#define CAP_UNUSED1_32 CAPRIGHT(1, 0x0000000080000000ULL) +#define CAP_UNUSED1_33 CAPRIGHT(1, 0x0000000100000000ULL) +#define CAP_UNUSED1_34 CAPRIGHT(1, 0x0000000200000000ULL) +#define CAP_UNUSED1_35 CAPRIGHT(1, 0x0000000400000000ULL) +#define CAP_UNUSED1_36 CAPRIGHT(1, 0x0000000800000000ULL) +#define CAP_UNUSED1_37 CAPRIGHT(1, 0x0000001000000000ULL) +#define CAP_UNUSED1_38 CAPRIGHT(1, 0x0000002000000000ULL) +#define CAP_UNUSED1_39 CAPRIGHT(1, 0x0000004000000000ULL) +#define CAP_UNUSED1_40 CAPRIGHT(1, 0x0000008000000000ULL) +#define CAP_UNUSED1_41 CAPRIGHT(1, 0x0000010000000000ULL) +#define CAP_UNUSED1_42 CAPRIGHT(1, 0x0000020000000000ULL) +#define CAP_UNUSED1_43 CAPRIGHT(1, 0x0000040000000000ULL) +#define CAP_UNUSED1_44 CAPRIGHT(1, 0x0000080000000000ULL) +#define CAP_UNUSED1_45 CAPRIGHT(1, 0x0000100000000000ULL) +#define CAP_UNUSED1_46 CAPRIGHT(1, 0x0000200000000000ULL) +#define CAP_UNUSED1_47 CAPRIGHT(1, 0x0000400000000000ULL) +#define CAP_UNUSED1_48 CAPRIGHT(1, 0x0000800000000000ULL) +#define CAP_UNUSED1_49 CAPRIGHT(1, 0x0001000000000000ULL) +#define CAP_UNUSED1_50 CAPRIGHT(1, 0x0002000000000000ULL) +#define CAP_UNUSED1_51 CAPRIGHT(1, 0x0004000000000000ULL) +#define CAP_UNUSED1_52 CAPRIGHT(1, 0x0008000000000000ULL) +#define CAP_UNUSED1_53 CAPRIGHT(1, 0x0010000000000000ULL) +#define CAP_UNUSED1_54 CAPRIGHT(1, 0x0020000000000000ULL) +#define CAP_UNUSED1_55 CAPRIGHT(1, 0x0040000000000000ULL) +#define CAP_UNUSED1_56 CAPRIGHT(1, 0x0080000000000000ULL) +#define CAP_UNUSED1_57 CAPRIGHT(1, 0x0100000000000000ULL) + /* All used bits for index 1. */ #define CAP_ALL1 CAPRIGHT(1, 0x00000000007FFFFFULL) -/* Available bits for index 1. */ -#define CAP_UNUSED1_22 CAPRIGHT(1, 0x0000000000800000ULL) -/* ... */ -#define CAP_UNUSED1_57 CAPRIGHT(1, 0x0100000000000000ULL) - /* Backward compatibility. */ #define CAP_POLL_EVENT CAP_EVENT