1 /*
2 * CDDL HEADER START
3 *
4 * The contents of this file are subject to the terms of the
5 * Common Development and Distribution License (the "License").
6 * You may not use this file except in compliance with the License.
7 *
8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9 * or http://www.opensolaris.org/os/licensing.
10 * See the License for the specific language governing permissions
11 * and limitations under the License.
12 *
13 * When distributing Covered Code, include this CDDL HEADER in each
14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15 * If applicable, add the following below this CDDL HEADER, with the
16 * fields enclosed by brackets "[]" replaced with your own identifying
17 * information: Portions Copyright [yyyy] [name of copyright owner]
18 *
19 * CDDL HEADER END
20 */
21 /*
22 * Copyright 2009 Sun Microsystems, Inc. All rights reserved.
23 * Use is subject to license terms.
24 */
25
26 /* Copyright (c) 1983, 1984, 1985, 1986, 1987, 1988, 1989 AT&T */
27 /* All Rights Reserved */
28
29 /*
30 * Portions of this source code were derived from Berkeley 4.3 BSD
31 * under license from the Regents of the University of California.
32 */
33
34 #ifndef _SYS_CRED_H
35 #define _SYS_CRED_H
36
37 #include <sys/types.h>
38
39 #ifdef __cplusplus
40 extern "C" {
41 #endif
42
43 /*
44 * The credential is an opaque kernel private data structure defined in
45 * <sys/cred_impl.h>.
46 */
47
48 typedef struct cred cred_t;
49
50 #ifdef _KERNEL
51
52 #define CRED() curthread->t_cred
53
54 struct proc; /* cred.h is included in proc.h */
55 struct prcred;
56 struct ksid;
57 struct ksidlist;
58 struct credklpd;
59 struct credgrp;
60
61 struct auditinfo_addr; /* cred.h is included in audit.h */
62
63 extern int ngroups_max;
64 /*
65 * kcred is used when you need all privileges.
66 */
67 extern struct cred *kcred;
68
69 extern void cred_init(void);
70 extern void crhold(cred_t *);
71 extern void crfree(cred_t *);
72 extern cred_t *cralloc(void); /* all but ref uninitialized */
73 extern cred_t *cralloc_ksid(void); /* cralloc() + ksid alloc'ed */
74 extern cred_t *crget(void); /* initialized */
75 extern cred_t *crcopy(cred_t *);
76 extern void crcopy_to(cred_t *, cred_t *);
77 extern cred_t *crdup(cred_t *);
78 extern void crdup_to(cred_t *, cred_t *);
79 extern cred_t *crgetcred(void);
80 extern void crset(struct proc *, cred_t *);
81 extern void crset_zone_privall(cred_t *);
82 extern int groupmember(gid_t, const cred_t *);
83 extern int supgroupmember(gid_t, const cred_t *);
84 extern int hasprocperm(const cred_t *, const cred_t *);
85 extern int prochasprocperm(struct proc *, struct proc *, const cred_t *);
86 extern int crcmp(const cred_t *, const cred_t *);
87 extern cred_t *zone_kcred(void);
88
89 extern uid_t crgetuid(const cred_t *);
90 extern uid_t crgetruid(const cred_t *);
91 extern uid_t crgetsuid(const cred_t *);
92 extern gid_t crgetgid(const cred_t *);
93 extern gid_t crgetrgid(const cred_t *);
94 extern gid_t crgetsgid(const cred_t *);
95 extern zoneid_t crgetzoneid(const cred_t *);
96 extern zoneid_t crgetzonedid(const cred_t *);
97 extern projid_t crgetprojid(const cred_t *);
98
99 extern cred_t *crgetmapped(const cred_t *);
100
101
102 extern const struct auditinfo_addr *crgetauinfo(const cred_t *);
103 extern struct auditinfo_addr *crgetauinfo_modifiable(cred_t *);
104
105 extern uint_t crgetref(const cred_t *);
106
107 extern const gid_t *crgetgroups(const cred_t *);
108 extern const gid_t *crgetggroups(const struct credgrp *);
109
110 extern int crgetngroups(const cred_t *);
111
112 /*
113 * Sets real, effective and/or saved uid/gid;
114 * -1 argument accepted as "no change".
115 */
116 extern int crsetresuid(cred_t *, uid_t, uid_t, uid_t);
117 extern int crsetresgid(cred_t *, gid_t, gid_t, gid_t);
118
119 /*
120 * Sets real, effective and saved uids/gids all to the same
121 * values. Both values must be non-negative and <= MAXUID
122 */
123 extern int crsetugid(cred_t *, uid_t, gid_t);
124
125 /*
126 * Functions to handle the supplemental group list.
127 */
128 extern int crsetgroups(cred_t *, int, gid_t *);
129 extern struct credgrp *crgrpcopyin(int, gid_t *);
130 extern void crgrprele(struct credgrp *);
131 extern void crsetcredgrp(cred_t *, struct credgrp *);
132
133 /*
134 * Private interface for setting zone association of credential.
135 */
136 struct zone;
137 extern void crsetzone(cred_t *, struct zone *);
138 extern struct zone *crgetzone(const cred_t *);
139
140 /*
141 * Private interface for setting project id in credential.
142 */
143 extern void crsetprojid(cred_t *, projid_t);
144
145 /*
146 * Private interface for nfs.
147 */
148 extern cred_t *crnetadjust(cred_t *);
149
150 /*
151 * Private interface for procfs.
152 */
153 extern void cred2prcred(const cred_t *, struct prcred *);
154
155 /*
156 * Private interfaces for Rampart Trusted Solaris.
157 */
158 struct ts_label_s;
159 extern struct ts_label_s *crgetlabel(const cred_t *);
160 extern boolean_t crisremote(const cred_t *);
161
162 /*
163 * Private interfaces for ephemeral uids.
164 */
165 #define VALID_UID(id, zn) \
166 ((id) <= MAXUID || valid_ephemeral_uid((zn), (id)))
167
168 #define VALID_GID(id, zn) \
169 ((id) <= MAXUID || valid_ephemeral_gid((zn), (id)))
170
171 extern boolean_t valid_ephemeral_uid(struct zone *, uid_t);
172 extern boolean_t valid_ephemeral_gid(struct zone *, gid_t);
173
174 extern int eph_uid_alloc(struct zone *, int, uid_t *, int);
175 extern int eph_gid_alloc(struct zone *, int, gid_t *, int);
176
177 extern void crsetsid(cred_t *, struct ksid *, int);
178 extern void crsetsidlist(cred_t *, struct ksidlist *);
179
180 extern struct ksid *crgetsid(const cred_t *, int);
181 extern struct ksidlist *crgetsidlist(const cred_t *);
182
183 extern int crsetpriv(cred_t *, ...);
184
185 extern struct credklpd *crgetcrklpd(const cred_t *);
186 extern void crsetcrklpd(cred_t *, struct credklpd *);
187
188 #endif /* _KERNEL */
189
190 #ifdef __cplusplus
191 }
192 #endif
193
194 #endif /* _SYS_CRED_H */