- SET(p->p_flag, P_TRACED);
- /* Non-attached case, our tracer is our parent. */
- t->p_oppid = t->p_pptr->p_pid;
- return(0);
+retry_trace_me:;
+ proc_t pproc = proc_parent(p);
+ if (pproc == NULL)
+ return (EINVAL);
+#if CONFIG_MACF
+ /*
+ * NB: Cannot call kauth_authorize_process(..., KAUTH_PROCESS_CANTRACE, ...)
+ * since that assumes the process being checked is the current process
+ * when, in this case, it is the current process's parent.
+ * Most of the other checks in cantrace() don't apply either.
+ */
+ if ((error = mac_proc_check_debug(pproc, p)) == 0) {
+#endif
+ proc_lock(p);
+ /* Make sure the process wasn't re-parented. */
+ if (p->p_ppid != pproc->p_pid) {
+ proc_unlock(p);
+ proc_rele(pproc);
+ goto retry_trace_me;
+ }
+ SET(p->p_lflag, P_LTRACED);
+ /* Non-attached case, our tracer is our parent. */
+ p->p_oppid = p->p_ppid;
+ proc_unlock(p);
+ /* Child and parent will have to be able to run modified code. */
+ cs_allow_invalid(p);
+ cs_allow_invalid(pproc);
+#if CONFIG_MACF
+ }
+#endif
+ proc_rele(pproc);
+ return (error);