From nobody Tue Jan 16 14:40:40 2024
X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org
Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1])
	by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4TDsBK0NQ7z57Lc8;
	Tue, 16 Jan 2024 14:40:41 +0000 (UTC)
	(envelope-from git@FreeBSD.org)
Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256
	 client-signature RSA-PSS (4096 bits) client-digest SHA256)
	(Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK))
	by mx1.freebsd.org (Postfix) with ESMTPS id 4TDsBJ73XNz4HJD;
	Tue, 16 Jan 2024 14:40:40 +0000 (UTC)
	(envelope-from git@FreeBSD.org)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim;
	t=1705416041;
	h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
	 to:to:cc:mime-version:mime-version:content-type:content-type:
	 content-transfer-encoding:content-transfer-encoding;
	bh=nCj2v+BlWbIjoFDwF8rzRw0BM6THMD+P9G3vXLRO+hQ=;
	b=dFPmAQm1uBaTlkr2PPrIWJ8i4yhBtdhrSuCFbGSsG/XmeAl3jV3BlbPFB283rE8JwQQrtx
	UiXfrIyC3sGxsckpO7CQFJrxv+kj57nwyflJJtsxLBMLt/ZHL5msfPzUfQVyJfTWhzdjSn
	X+Erf/yFqX8xQ9MF/BeY6VcysrUWhOkSkJamwMo6btxDLjTUumGk7E1KPCdtG93psn6HhQ
	uAh/iqBDvYxzgIs2jtwPhvYHSNjFbORweITRrciAaab7LmCwErGpCKr1XqCZs6qC2x+Wpd
	JRyZyDmYLUHTERG2dmQHc4IEfv+Ozqp9BasNByrk7n29XU2k4r3HabZHro1m6w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org;
	s=dkim; t=1705416041;
	h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
	 to:to:cc:mime-version:mime-version:content-type:content-type:
	 content-transfer-encoding:content-transfer-encoding;
	bh=nCj2v+BlWbIjoFDwF8rzRw0BM6THMD+P9G3vXLRO+hQ=;
	b=TPM7Xfawyvly7STfNoN8SSH+PMR6OX94x9SWRghcfGgsK1LVburtjMZMhCS8Py9KF+bnW/
	qN4e4yX8j0nJk5gVOXiJxP7dTXhK5kqNqZ2eNmLOa0Jc7ikV97KezPLCv2JLhdjbgiP/1T
	IlPHnlmZm7lxsl+ESv5BtfoK3uhdBTwJreZ7W69NbWcgx8NTbXl2l/9OzWBHVD8xid16Hz
	o0LOd/9jFSyiOqQ3dc4u5fQbBvoXG2HQKUk8yh5QiW7jrR29YLpToWBzGFNqiXix8cZLkp
	vJQD9m+1iG/0uB+aLlJu9IfDKYSqoHsBY6b0zgx9W2rau/seNwkNayL7Q6COhw==
ARC-Authentication-Results: i=1;
	mx1.freebsd.org;
	none
ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1705416041; a=rsa-sha256; cv=none;
	b=DY/shlUpXSH+apxe9LvtGEUPf3I2lGojTRhg/7PFGMnTIdopU2vzebyF+ZIa4P5WdKz2Vy
	jC0KU5+Nj88WNLc94hh2GB4/+j+BGYJDQOFz6+L34zPjy4SVVUZOAlGJcCIDbQCsWbLUct
	DOzEqtYuAUW5mZWZUieQiyve+V0FkQlFb6u+gpOSY2HUAZww6iSWl+fFHfjX860F7nTOle
	QF/1ISMKy0BdQOeJFXQw78Q1Bp3d6Rcq9uuly5+jM7VO/apbIvgNPQpFBqIeY+VNPt4OeX
	oxvwyX4yxd1IYSAwvo4gA+Nd1TE5Ql31TC0ZVeOlJSyWE3pMJQ0i10OLk+A2ZA==
Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5])
	(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
	 key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256)
	(Client did not present a certificate)
	by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4TDsBJ67Jfzkrc;
	Tue, 16 Jan 2024 14:40:40 +0000 (UTC)
	(envelope-from git@FreeBSD.org)
Received: from gitrepo.freebsd.org ([127.0.1.44])
	by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 40GEeeoX063820;
	Tue, 16 Jan 2024 14:40:40 GMT
	(envelope-from git@gitrepo.freebsd.org)
Received: (from git@localhost)
	by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 40GEeeVw063817;
	Tue, 16 Jan 2024 14:40:40 GMT
	(envelope-from git)
Date: Tue, 16 Jan 2024 14:40:40 GMT
Message-Id: <202401161440.40GEeeVw063817@gitrepo.freebsd.org>
To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org,
        dev-commits-src-main@FreeBSD.org
From: Mark Johnston <markj@FreeBSD.org>
Subject: git: 9b20849bc5f1 - main - md5: Enter capability mode
  earlier
List-Id: Commit messages for all branches of the src repository <dev-commits-src-all.freebsd.org>
List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all
List-Help: <mailto:dev-commits-src-all+help@freebsd.org>
List-Post: <mailto:dev-commits-src-all@freebsd.org>
List-Subscribe: <mailto:dev-commits-src-all+subscribe@freebsd.org>
List-Unsubscribe: <mailto:dev-commits-src-all+unsubscribe@freebsd.org>
Sender: owner-dev-commits-src-all@freebsd.org
X-BeenThere: dev-commits-src-all@freebsd.org
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 8bit
X-Git-Committer: markj
X-Git-Repository: src
X-Git-Refname: refs/heads/main
X-Git-Reftype: branch
X-Git-Commit: 9b20849bc5f1b500f2de7aeca77f0e6556069bbb
Auto-Submitted: auto-generated

The branch main has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=9b20849bc5f1b500f2de7aeca77f0e6556069bbb

commit 9b20849bc5f1b500f2de7aeca77f0e6556069bbb
Author:     Ricardo Branco <rbranco@suse.de>
AuthorDate: 2024-01-03 18:00:47 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2024-01-16 14:38:53 +0000

    md5: Enter capability mode earlier
    
    Reviewed by:    markj
    MFC after:      1 month
    Pull Request:   https://github.com/freebsd/freebsd-src/pull/988
---
 sbin/md5/Makefile |  9 ++++++---
 sbin/md5/md5.c    | 57 +++++++++++++++++++++++++++++++------------------------
 2 files changed, 38 insertions(+), 28 deletions(-)

diff --git a/sbin/md5/Makefile b/sbin/md5/Makefile
index c9bf16796459..f91e84323b04 100644
--- a/sbin/md5/Makefile
+++ b/sbin/md5/Makefile
@@ -58,16 +58,19 @@ MLINKS=	md5.1 md5sum.1 \
 
 LIBADD=	md
 
-.ifndef(BOOTSTRAPPING)
+.include <src.opts.mk>
+
+.if ${MK_CASPER} != "no" && !defined(RESCUE) && !defined(BOOTSTRAPPING)
 # Avoid depending on capsicum during bootstrap. caph_limit_stdout() is not
 # available when building for Linux/MacOS or older FreeBSD hosts.
 # We need to bootstrap md5 when building on Linux since the md5sum command there
 # produces different output.
 CFLAGS+=-DHAVE_CAPSICUM
+CFLAGS+=-DWITH_CASPER
+LIBADD+=	casper
+LIBADD+=	cap_fileargs
 .endif
 
-.include <src.opts.mk>
-
 HAS_TESTS=
 SUBDIR.${MK_TESTS}+= tests
 
diff --git a/sbin/md5/md5.c b/sbin/md5/md5.c
index abaadb12f3ee..c8292fe2f692 100644
--- a/sbin/md5/md5.c
+++ b/sbin/md5/md5.c
@@ -46,6 +46,8 @@
 #ifdef HAVE_CAPSICUM
 #include <sys/capsicum.h>
 #include <capsicum_helpers.h>
+#include <libcasper.h>
+#include <casper/cap_fileargs.h>
 #endif
 
 /*
@@ -310,6 +312,7 @@ gnu_check(const char *checksumsfile)
 	const char	*digestname;
 	size_t	digestnamelen;
 	size_t	hashstrlen;
+	struct stat st;
 
 	if (strcmp(checksumsfile, "-") == 0)
 		inp = stdin;
@@ -357,6 +360,15 @@ gnu_check(const char *checksumsfile)
 		rec = malloc(sizeof(*rec));
 		if (rec == NULL)
 			errx(1, "malloc failed");
+
+		if (*filename == '*' ||
+		    *filename == ' ' ||
+		    *filename == 'U' ||
+		    *filename == '^') {
+			if (lstat(filename, &st) != 0)
+				filename++;
+		}
+
 		rec->chksum = strdup(hashstr);
 		rec->filename = strdup(filename);
 		if (rec->chksum == NULL || rec->filename == NULL)
@@ -384,6 +396,7 @@ main(int argc, char *argv[])
 {
 #ifdef HAVE_CAPSICUM
 	cap_rights_t	rights;
+	fileargs_t	*fa = NULL;
 #endif
 	const struct option *longopts;
 	const char *shortopts;
@@ -584,24 +597,25 @@ main(int argc, char *argv[])
 		rec = head;
 	}
 
+#ifdef HAVE_CAPSICUM
+	fa = fileargs_init(argc, argv, O_RDONLY, 0,
+	    cap_rights_init(&rights, CAP_READ, CAP_FSTAT, CAP_FCNTL), FA_OPEN | FA_LSTAT);
+	if (fa == NULL)
+		err(1, "Unable to initialize casper");
+	if (caph_enter_casper() < 0)
+		err(1, "Unable to enter capability mode");
+#endif
+
 	if (*argv) {
 		do {
-			struct stat st;
 			const char *filename = *argv;
 			const char *filemode = "rb";
 
-			if (*filename == '*' ||
-			    *filename == ' ' ||
-			    *filename == 'U' ||
-			    *filename == '^') {
-				if (lstat(filename, &st) != 0) {
-					input_mode = (int)*filename;
-					filename++;
-				}
-			}
-			if (input_mode == input_text)
-				filemode = "r";
+#ifdef HAVE_CAPSICUM
+			if ((f = fileargs_fopen(fa, filename, filemode)) == NULL) {
+#else
 			if ((f = fopen(filename, filemode)) == NULL) {
+#endif
 				if (errno != ENOENT || !(cflag && ignoreMissing)) {
 					warn("%s", filename);
 					failed = true;
@@ -610,20 +624,10 @@ main(int argc, char *argv[])
 					rec = rec->next;
 				continue;
 			}
-			/*
-			 * XXX Enter capability mode on the last argv file.
-			 * When a casper file service or other approach is
-			 * available, switch to that and enter capability mode
-			 * earlier.
-			 */
-			if (*(argv + 1) == NULL) {
 #ifdef HAVE_CAPSICUM
-				cap_rights_init(&rights, CAP_READ, CAP_FSTAT);
-				if (caph_rights_limit(fileno(f), &rights) < 0 ||
-				    caph_enter() < 0)
-					err(1, "capsicum");
+			if (caph_rights_limit(fileno(f), &rights) < 0)
+				err(1, "capsicum");
 #endif
-			}
 			if (cflag && mode != mode_bsd) {
 				checkAgainst = rec->chksum;
 				rec = rec->next;
@@ -634,7 +638,7 @@ main(int argc, char *argv[])
 		} while (*++argv);
 	} else if (!cflag && string == NULL && !skip) {
 #ifdef HAVE_CAPSICUM
-		if (caph_limit_stdin() < 0 || caph_enter() < 0)
+		if (caph_limit_stdin() < 0)
 			err(1, "capsicum");
 #endif
 		if (mode == mode_bsd)
@@ -658,6 +662,9 @@ main(int argc, char *argv[])
 		if (checksFailed != 0 || (strict && malformed > 0))
 			return (1);
 	}
+#ifdef HAVE_CAPSICUM
+	fileargs_free(fa);
+#endif
 	if (failed)
 		return (1);
 	if (checksFailed > 0)