aboutsummaryrefslogtreecommitdiff
path: root/usr.bin/proccontrol/proccontrol.1
blob: 5cb5d584f48082c7c72709502df2864ad102538c (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
.\" Copyright (c) 2019 The FreeBSD Foundation, Inc.
.\" All rights reserved.
.\"
.\" This documentation was written by
.\" Konstantin Belousov <kib@FreeBSD.org> under sponsorship
.\" from the FreeBSD Foundation.
.\"
.\" Redistribution and use in source and binary forms, with or without
.\" modification, are permitted provided that the following conditions
.\" are met:
.\" 1. Redistributions of source code must retain the above copyright
.\"    notice, this list of conditions and the following disclaimer.
.\" 2. Redistributions in binary form must reproduce the above copyright
.\"    notice, this list of conditions and the following disclaimer in the
.\"    documentation and/or other materials provided with the distribution.
.\"
.\" THIS SOFTWARE IS PROVIDED BY THE AUTHORS AND CONTRIBUTORS ``AS IS'' AND
.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
.\" ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS BE LIABLE
.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
.\" SUCH DAMAGE.
.\"
.Dd October 5, 2023
.Dt PROCCONTROL 1
.Os
.Sh NAME
.Nm proccontrol
.Nd Control some process execution aspects
.Sh SYNOPSIS
.Nm
.Fl m Ar mode
.Op Fl s Ar control
.Op Fl q
.Fl p Ar pid | command
.Sh DESCRIPTION
The
.Nm
command modifies the execution parameter of existing process
specified by the
.Ar pid
argument, or starts execution of the new program
.Ar command
with the execution parameter set for it.
.Pp
Which execution parameter is changed, selected by the mandatory
parameter
.Ar mode .
Possible values for
.Ar mode
are:
.Bl -tag -width trapcap
.It Ar aslr
Control the Address Space Layout Randomization.
Only applicable to the new process spawned.
.It Ar trace
Control the permission for debuggers to attach.
Note that process is only allowed to enable tracing for itself,
not for any other process.
.It Ar trapcap
Controls the signalling of capability mode access violations.
.It Ar protmax
Controls the implicit PROT_MAX application for
.Xr mmap 2 .
.It Ar nonewprivs
Controls disabling the setuid and sgid bits for
.Xr execve 2 .
.It Ar wxmap
Controls the write exclusive execute mode for mappings.
.It Ar kpti
Controls the KPTI enable, AMD64 only.
.It Ar la48
Control limiting usermode process address space to 48 bits of address,
AMD64 only, on machines capable of 57-bit addressing.
.El
.Pp
The
.Ar control
specifies if the selected
.Ar mode
should be enabled or disabled.
Possible values are
.Ar enable
and
.Ar disable ,
with the default value being
.Ar enable
if not specified.
See
.Xr procctl 2
for detailed description of each mode effects and interaction with other
process control facilities.
.Pp
The
.Fl q
switch makes the utility query and print the current setting for
the selected mode.
The
.Fl q
requires the query target process specification with
.Fl p .
.Sh EXIT STATUS
.Ex -std
.Sh EXAMPLES
.Bl -bullet
.It
To disable debuggers attachment to the process 1020, execute
.Dl "proccontrol -m trace -s disable -p 1020"
.It
To execute the
.Xr uniq 1
program in a mode where capability access violations cause
.Dv SIGTRAP
delivery, do
.Dl "proccontrol -m trapcap uniq"
.It
To query the current ASLR enablement mode for the running
process 1020, do
.Dl "proccontrol -m aslr -q -p 1020"
.El
.Sh SEE ALSO
.Xr kill 2 ,
.Xr procctl 2 ,
.Xr ptrace 2 ,
.Xr mitigations 7
.Sh HISTORY
The
.Nm
command appeared in
.Fx 10.0 .
.Sh AUTHORS
The
.Nm
command and this manual page were written by
.An Konstantin Belousov Aq Mt kib@freebsd.org
under sponsorship from The FreeBSD Foundation.