Print this page
7029 want per-process exploit mitigation features (secflags)
7030 want basic address space layout randomization (aslr)
7031 noexec_user_stack should be a secflag
7032 want a means to forbid mappings around NULL.
Split |
Close |
Expand all |
Collapse all |
--- old/usr/src/head/libzonecfg.h
+++ new/usr/src/head/libzonecfg.h
1 1 /*
2 2 * CDDL HEADER START
3 3 *
4 4 * The contents of this file are subject to the terms of the
5 5 * Common Development and Distribution License (the "License").
6 6 * You may not use this file except in compliance with the License.
7 7 *
8 8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9 9 * or http://www.opensolaris.org/os/licensing.
10 10 * See the License for the specific language governing permissions
11 11 * and limitations under the License.
12 12 *
13 13 * When distributing Covered Code, include this CDDL HEADER in each
14 14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15 15 * If applicable, add the following below this CDDL HEADER, with the
16 16 * fields enclosed by brackets "[]" replaced with your own identifying
17 17 * information: Portions Copyright [yyyy] [name of copyright owner]
18 18 *
19 19 * CDDL HEADER END
20 20 */
21 21
22 22 /*
23 23 * Copyright (c) 2003, 2010, Oracle and/or its affiliates. All rights reserved.
24 24 */
25 25
26 26 #ifndef _LIBZONECFG_H
27 27 #define _LIBZONECFG_H
28 28
29 29 /*
30 30 * Zone configuration header file.
31 31 */
32 32
33 33 #ifdef __cplusplus
34 34 extern "C" {
35 35 #endif
36 36
37 37 /* sys/socket.h is required by net/if.h, which has a constant needed here */
38 38 #include <sys/param.h>
39 39 #include <sys/fstyp.h>
40 40 #include <sys/mount.h>
41 41 #include <priv.h>
42 42 #include <netinet/in.h>
43 43 #include <sys/socket.h>
44 44 #include <net/if.h>
45 45 #include <stdio.h>
46 46 #include <rctl.h>
47 47 #include <zone.h>
48 48 #include <libbrand.h>
49 49 #include <sys/uuid.h>
50 50 #include <libuutil.h>
51 51 #include <sys/mnttab.h>
52 52 #include <limits.h>
53 53 #include <utmpx.h>
54 54
55 55 #define ZONE_ID_UNDEFINED -1
56 56
57 57 #define Z_OK 0
58 58 #define Z_EMPTY_DOCUMENT 1 /* XML doc root element is null */
59 59 #define Z_WRONG_DOC_TYPE 2 /* top-level XML doc element != zone */
60 60 #define Z_BAD_PROPERTY 3 /* libxml-level property problem */
61 61 #define Z_TEMP_FILE 4 /* problem creating temporary file */
62 62 #define Z_SAVING_FILE 5 /* libxml error saving or validating */
63 63 #define Z_NO_ENTRY 6 /* no such entry */
64 64 #define Z_BOGUS_ZONE_NAME 7 /* illegal zone name */
65 65 #define Z_REQD_RESOURCE_MISSING 8 /* required resource missing */
66 66 #define Z_REQD_PROPERTY_MISSING 9 /* required property missing */
67 67 #define Z_BAD_HANDLE 10 /* bad document handle */
68 68 #define Z_NOMEM 11 /* out of memory (like ENOMEM) */
69 69 #define Z_INVAL 12 /* invalid argument (like EINVAL) */
70 70 #define Z_ACCES 13 /* permission denied (like EACCES) */
71 71 #define Z_TOO_BIG 14 /* string won't fit in char array */
72 72 #define Z_MISC_FS 15 /* miscellaneous file-system error */
73 73 #define Z_NO_ZONE 16 /* no such zone */
74 74 #define Z_NO_RESOURCE_TYPE 17 /* no/wrong resource type */
75 75 #define Z_NO_RESOURCE_ID 18 /* no/wrong resource id */
76 76 #define Z_NO_PROPERTY_TYPE 19 /* no/wrong property type */
77 77 #define Z_NO_PROPERTY_ID 20 /* no/wrong property id */
78 78 #define Z_BAD_ZONE_STATE 21 /* zone state invalid for given task */
79 79 #define Z_INVALID_DOCUMENT 22 /* libxml can't validate against DTD */
80 80 #define Z_NAME_IN_USE 23 /* zone name already in use (rename) */
81 81 #define Z_NO_SUCH_ID 24 /* delete_index: no old ID */
82 82 #define Z_UPDATING_INDEX 25 /* add/modify/delete_index problem */
83 83 #define Z_LOCKING_FILE 26 /* problem locking index file */
84 84 #define Z_UNLOCKING_FILE 27 /* problem unlocking index file */
85 85 #define Z_SYSTEM 28 /* consult errno instead */
86 86 #define Z_INSUFFICIENT_SPEC 29 /* resource insufficiently specified */
87 87 #define Z_RESOLVED_PATH 34 /* resolved path mismatch */
88 88 #define Z_IPV6_ADDR_PREFIX_LEN 35 /* IPv6 address prefix length needed */
89 89 #define Z_BOGUS_ADDRESS 36 /* not IPv[4|6] address or host name */
90 90 #define Z_PRIV_PROHIBITED 37 /* specified privilege is prohibited */
91 91 #define Z_PRIV_REQUIRED 38 /* required privilege is missing */
92 92 #define Z_PRIV_UNKNOWN 39 /* specified privilege is unknown */
93 93 #define Z_BRAND_ERROR 40 /* brand-specific error */
94 94 #define Z_INCOMPATIBLE 41 /* incompatible settings */
95 95 #define Z_ALIAS_DISALLOW 42 /* rctl alias disallowed */
96 96 #define Z_CLEAR_DISALLOW 43 /* clear property disallowed */
97 97 #define Z_POOL 44 /* generic libpool error */
98 98 #define Z_POOLS_NOT_ACTIVE 45 /* pool service not enabled */
99 99 #define Z_POOL_ENABLE 46 /* pools enable failed */
100 100 #define Z_NO_POOL 47 /* no such pool configured */
101 101 #define Z_POOL_CREATE 48 /* pool create failed */
102 102 #define Z_POOL_BIND 49 /* pool bind failed */
103 103 #define Z_INVALID_PROPERTY 50 /* invalid property value */
104 104
105 105 /*
106 106 * Warning: these are shared with the admin/install consolidation.
107 107 * Do not insert states between any of the currently defined states,
108 108 * and any new states must be evaluated for impact on range comparisons.
109 109 */
110 110 #define ZONE_STATE_CONFIGURED 0
111 111 #define ZONE_STATE_INCOMPLETE 1
112 112 #define ZONE_STATE_INSTALLED 2
113 113 #define ZONE_STATE_READY 3
114 114 #define ZONE_STATE_RUNNING 4
115 115 #define ZONE_STATE_SHUTTING_DOWN 5
116 116 #define ZONE_STATE_DOWN 6
117 117 #define ZONE_STATE_MOUNTED 7
118 118
119 119 #define ZONE_STATE_MAXSTRLEN 14
120 120
121 121 #define LIBZONECFG_PATH "libzonecfg.so.1"
122 122
123 123 #define ZONE_CONFIG_ROOT "/etc/zones"
124 124 #define ZONE_INDEX_FILE ZONE_CONFIG_ROOT "/index"
125 125
126 126 #define MAXUSERNAME (sizeof (((struct utmpx *)0)->ut_name))
127 127 #define MAXAUTHS 4096
128 128 #define ZONE_MGMT_PROF "Zone Management"
129 129
130 130 /* Owner, group, and mode (defined by packaging) for the config directory */
131 131 #define ZONE_CONFIG_UID 0 /* root */
132 132 #define ZONE_CONFIG_GID 3 /* sys */
133 133 #define ZONE_CONFIG_MODE 0755
134 134
135 135 /* Owner, group, and mode (defined by packaging) for the index file */
136 136 #define ZONE_INDEX_UID 0 /* root */
137 137 #define ZONE_INDEX_GID 3 /* sys */
138 138 #define ZONE_INDEX_MODE 0644
139 139
140 140 /* The maximum length of the VERSION string in the pkginfo(4) file. */
141 141 #define ZONE_PKG_VERSMAX 256
142 142
143 143 /*
144 144 * Shortened alias names for the zones rctls.
145 145 */
146 146 #define ALIAS_MAXLWPS "max-lwps"
147 147 #define ALIAS_MAXSHMMEM "max-shm-memory"
148 148 #define ALIAS_MAXSHMIDS "max-shm-ids"
149 149 #define ALIAS_MAXMSGIDS "max-msg-ids"
150 150 #define ALIAS_MAXSEMIDS "max-sem-ids"
151 151 #define ALIAS_MAXLOCKEDMEM "locked"
152 152 #define ALIAS_MAXSWAP "swap"
153 153 #define ALIAS_SHARES "cpu-shares"
154 154 #define ALIAS_CPUCAP "cpu-cap"
155 155 #define ALIAS_MAXPROCS "max-processes"
156 156
157 157 /* Default name for zone detached manifest */
158 158 #define ZONE_DETACHED "SUNWdetached.xml"
159 159
160 160 /*
161 161 * Bit flag definitions for passing into libzonecfg functions.
162 162 */
163 163 #define ZONE_DRY_RUN 0x01
164 164
165 165 /*
166 166 * The integer field expresses the current values on a get.
167 167 * On a put, it represents the new values if >= 0 or "don't change" if < 0.
168 168 */
169 169 struct zoneent {
170 170 char zone_name[ZONENAME_MAX]; /* name of the zone */
171 171 int zone_state; /* configured | incomplete | installed */
172 172 char zone_path[MAXPATHLEN]; /* path to zone storage */
173 173 uuid_t zone_uuid; /* unique ID for zone */
174 174 char zone_newname[ZONENAME_MAX]; /* for doing renames */
175 175 };
176 176
177 177 typedef struct zone_dochandle *zone_dochandle_t; /* opaque handle */
178 178
179 179 typedef uint_t zone_state_t;
180 180
181 181 typedef struct zone_fsopt {
182 182 struct zone_fsopt *zone_fsopt_next;
183 183 char zone_fsopt_opt[MAX_MNTOPT_STR];
184 184 } zone_fsopt_t;
185 185
186 186 struct zone_fstab {
187 187 char zone_fs_special[MAXPATHLEN]; /* special file */
188 188 char zone_fs_dir[MAXPATHLEN]; /* mount point */
189 189 char zone_fs_type[FSTYPSZ]; /* e.g. ufs */
190 190 zone_fsopt_t *zone_fs_options; /* mount options */
191 191 char zone_fs_raw[MAXPATHLEN]; /* device to fsck */
192 192 };
193 193
194 194 struct zone_nwiftab {
195 195 char zone_nwif_address[INET6_ADDRSTRLEN]; /* shared-ip only */
196 196 char zone_nwif_allowed_address[INET6_ADDRSTRLEN]; /* excl-ip only */
197 197 char zone_nwif_physical[LIFNAMSIZ];
198 198 char zone_nwif_defrouter[INET6_ADDRSTRLEN];
199 199 };
200 200
201 201 struct zone_devtab {
202 202 char zone_dev_match[MAXPATHLEN];
203 203 };
204 204
205 205 struct zone_rctlvaltab {
206 206 char zone_rctlval_priv[MAXNAMELEN];
207 207 char zone_rctlval_limit[MAXNAMELEN];
208 208 char zone_rctlval_action[MAXNAMELEN];
209 209 struct zone_rctlvaltab *zone_rctlval_next;
210 210 };
211 211
212 212 struct zone_rctltab {
213 213 char zone_rctl_name[MAXNAMELEN];
214 214 struct zone_rctlvaltab *zone_rctl_valptr;
215 215 };
216 216
217 217 struct zone_attrtab {
218 218 char zone_attr_name[MAXNAMELEN];
219 219 char zone_attr_type[MAXNAMELEN];
220 220 char zone_attr_value[2 * BUFSIZ];
221 221 };
222 222
223 223 struct zone_dstab {
224 224 char zone_dataset_name[MAXNAMELEN];
225 225 };
226 226
227 227 struct zone_psettab {
228 228 char zone_ncpu_min[MAXNAMELEN];
229 229 char zone_ncpu_max[MAXNAMELEN];
230 230 char zone_importance[MAXNAMELEN];
231 231 };
232 232
233 233 struct zone_mcaptab {
234 234 char zone_physmem_cap[MAXNAMELEN];
235 235 };
236 236
237 237 struct zone_pkgtab {
238 238 char zone_pkg_name[MAXNAMELEN];
239 239 char zone_pkg_version[ZONE_PKG_VERSMAX];
240 240 };
241 241
242 242 struct zone_devpermtab {
243 243 char zone_devperm_name[MAXPATHLEN];
244 244 uid_t zone_devperm_uid;
↓ open down ↓ |
244 lines elided |
↑ open up ↑ |
245 245 gid_t zone_devperm_gid;
246 246 mode_t zone_devperm_mode;
247 247 char *zone_devperm_acl;
248 248 };
249 249
250 250 struct zone_admintab {
251 251 char zone_admin_user[MAXUSERNAME];
252 252 char zone_admin_auths[MAXAUTHS];
253 253 };
254 254
255 +#define ZONECFG_SECFLAGS_MAX 1024
256 +struct zone_secflagstab {
257 + char zone_secflags_lower[ZONECFG_SECFLAGS_MAX];
258 + char zone_secflags_upper[ZONECFG_SECFLAGS_MAX];
259 + char zone_secflags_default[ZONECFG_SECFLAGS_MAX];
260 +};
261 +
255 262 typedef struct zone_userauths {
256 263 char user[MAXUSERNAME];
257 264 char zonename[ZONENAME_MAX];
258 265 struct zone_userauths *next;
259 266 } zone_userauths_t;
260 267
261 268 typedef struct {
262 269 uu_avl_node_t zpe_entry;
263 270 char *zpe_name;
264 271 char *zpe_vers;
265 272 } zone_pkg_entry_t;
266 273
267 274 typedef enum zone_iptype {
268 275 ZS_SHARED,
269 276 ZS_EXCLUSIVE
270 277 } zone_iptype_t;
271 278
272 279 /*
273 280 * Basic configuration management routines.
274 281 */
275 282 extern zone_dochandle_t zonecfg_init_handle(void);
276 283 extern int zonecfg_get_handle(const char *, zone_dochandle_t);
277 284 extern int zonecfg_get_snapshot_handle(const char *, zone_dochandle_t);
278 285 extern int zonecfg_get_template_handle(const char *, const char *,
279 286 zone_dochandle_t);
280 287 extern int zonecfg_get_xml_handle(const char *, zone_dochandle_t);
281 288 extern int zonecfg_check_handle(zone_dochandle_t);
282 289 extern void zonecfg_fini_handle(zone_dochandle_t);
283 290 extern int zonecfg_destroy(const char *, boolean_t);
284 291 extern int zonecfg_destroy_snapshot(const char *);
285 292 extern int zonecfg_save(zone_dochandle_t);
286 293 extern int zonecfg_create_snapshot(const char *);
287 294 extern char *zonecfg_strerror(int);
288 295 extern int zonecfg_access(const char *, int);
289 296 extern void zonecfg_set_root(const char *);
290 297 extern const char *zonecfg_get_root(void);
291 298 extern boolean_t zonecfg_in_alt_root(void);
292 299 extern int zonecfg_num_resources(zone_dochandle_t, char *);
293 300 extern int zonecfg_del_all_resources(zone_dochandle_t, char *);
294 301 extern boolean_t zonecfg_valid_ncpus(char *, char *);
295 302 extern boolean_t zonecfg_valid_importance(char *);
296 303 extern int zonecfg_str_to_bytes(char *, uint64_t *);
297 304 extern boolean_t zonecfg_valid_memlimit(char *, uint64_t *);
298 305 extern boolean_t zonecfg_valid_alias_limit(char *, char *, uint64_t *);
299 306
300 307 /*
301 308 * Zone name, path to zone directory, autoboot setting, pool, boot
302 309 * arguments, and scheduling-class.
303 310 */
304 311 extern int zonecfg_validate_zonename(const char *);
305 312 extern int zonecfg_get_name(zone_dochandle_t, char *, size_t);
306 313 extern int zonecfg_set_name(zone_dochandle_t, char *);
307 314 extern int zonecfg_get_zonepath(zone_dochandle_t, char *, size_t);
308 315 extern int zonecfg_set_zonepath(zone_dochandle_t, char *);
309 316 extern int zonecfg_get_autoboot(zone_dochandle_t, boolean_t *);
310 317 extern int zonecfg_set_autoboot(zone_dochandle_t, boolean_t);
311 318 extern int zonecfg_get_iptype(zone_dochandle_t, zone_iptype_t *);
312 319 extern int zonecfg_set_iptype(zone_dochandle_t, zone_iptype_t);
313 320 extern int zonecfg_get_pool(zone_dochandle_t, char *, size_t);
314 321 extern int zonecfg_set_pool(zone_dochandle_t, char *);
315 322 extern int zonecfg_get_bootargs(zone_dochandle_t, char *, size_t);
316 323 extern int zonecfg_set_bootargs(zone_dochandle_t, char *);
317 324 extern int zonecfg_get_sched_class(zone_dochandle_t, char *, size_t);
318 325 extern int zonecfg_set_sched(zone_dochandle_t, char *);
319 326 extern int zonecfg_get_dflt_sched_class(zone_dochandle_t, char *, int);
320 327
321 328 /*
322 329 * Set/retrieve the brand for the zone
323 330 */
324 331 extern int zonecfg_get_brand(zone_dochandle_t, char *, size_t);
325 332 extern int zonecfg_set_brand(zone_dochandle_t, char *);
326 333
327 334 /*
328 335 * Filesystem configuration.
329 336 */
330 337 extern int zonecfg_add_filesystem(zone_dochandle_t, struct zone_fstab *);
331 338 extern int zonecfg_delete_filesystem(zone_dochandle_t,
332 339 struct zone_fstab *);
333 340 extern int zonecfg_modify_filesystem(zone_dochandle_t,
334 341 struct zone_fstab *, struct zone_fstab *);
335 342 extern int zonecfg_lookup_filesystem(zone_dochandle_t,
336 343 struct zone_fstab *);
337 344 extern int zonecfg_add_fs_option(struct zone_fstab *, char *);
338 345 extern int zonecfg_remove_fs_option(struct zone_fstab *, char *);
339 346 extern void zonecfg_free_fs_option_list(zone_fsopt_t *);
340 347 extern int zonecfg_find_mounts(char *, int(*)(const struct mnttab *,
341 348 void *), void *);
342 349
343 350 /*
344 351 * Network interface configuration.
345 352 */
346 353 extern int zonecfg_add_nwif(zone_dochandle_t, struct zone_nwiftab *);
347 354 extern int zonecfg_delete_nwif(zone_dochandle_t, struct zone_nwiftab *);
348 355 extern int zonecfg_modify_nwif(zone_dochandle_t, struct zone_nwiftab *,
349 356 struct zone_nwiftab *);
350 357 extern int zonecfg_lookup_nwif(zone_dochandle_t, struct zone_nwiftab *);
351 358
352 359 /*
353 360 * Hostid emulation configuration.
354 361 */
355 362 extern int zonecfg_get_hostid(zone_dochandle_t, char *, size_t);
356 363 extern int zonecfg_set_hostid(zone_dochandle_t, const char *);
357 364
358 365 /*
359 366 * Allowed FS mounts configuration.
360 367 */
361 368 extern int zonecfg_get_fs_allowed(zone_dochandle_t, char *, size_t);
362 369 extern int zonecfg_set_fs_allowed(zone_dochandle_t, const char *);
363 370
364 371 /*
365 372 * Device configuration and rule matching.
366 373 */
367 374 extern int zonecfg_add_dev(zone_dochandle_t, struct zone_devtab *);
368 375 extern int zonecfg_delete_dev(zone_dochandle_t, struct zone_devtab *);
369 376 extern int zonecfg_modify_dev(zone_dochandle_t, struct zone_devtab *,
370 377 struct zone_devtab *);
371 378 extern int zonecfg_lookup_dev(zone_dochandle_t, struct zone_devtab *);
372 379
373 380 /*
374 381 * Resource control configuration.
375 382 */
376 383 extern int zonecfg_add_rctl(zone_dochandle_t, struct zone_rctltab *);
377 384 extern int zonecfg_delete_rctl(zone_dochandle_t, struct zone_rctltab *);
378 385 extern int zonecfg_modify_rctl(zone_dochandle_t, struct zone_rctltab *,
379 386 struct zone_rctltab *);
380 387 extern int zonecfg_lookup_rctl(zone_dochandle_t, struct zone_rctltab *);
381 388 extern int zonecfg_add_rctl_value(struct zone_rctltab *,
382 389 struct zone_rctlvaltab *);
383 390 extern int zonecfg_remove_rctl_value(struct zone_rctltab *,
384 391 struct zone_rctlvaltab *);
385 392 extern void zonecfg_free_rctl_value_list(struct zone_rctlvaltab *);
386 393 extern boolean_t zonecfg_aliased_rctl_ok(zone_dochandle_t, char *);
387 394 extern int zonecfg_set_aliased_rctl(zone_dochandle_t, char *, uint64_t);
388 395 extern int zonecfg_get_aliased_rctl(zone_dochandle_t, char *, uint64_t *);
389 396 extern int zonecfg_rm_aliased_rctl(zone_dochandle_t, char *);
390 397 extern int zonecfg_apply_rctls(char *, zone_dochandle_t);
391 398
392 399 /*
393 400 * Generic attribute configuration and type/value extraction.
394 401 */
395 402 extern int zonecfg_add_attr(zone_dochandle_t, struct zone_attrtab *);
396 403 extern int zonecfg_delete_attr(zone_dochandle_t, struct zone_attrtab *);
397 404 extern int zonecfg_modify_attr(zone_dochandle_t, struct zone_attrtab *,
398 405 struct zone_attrtab *);
399 406 extern int zonecfg_lookup_attr(zone_dochandle_t, struct zone_attrtab *);
400 407 extern int zonecfg_get_attr_boolean(const struct zone_attrtab *,
401 408 boolean_t *);
402 409 extern int zonecfg_get_attr_int(const struct zone_attrtab *, int64_t *);
403 410 extern int zonecfg_get_attr_string(const struct zone_attrtab *, char *,
404 411 size_t);
405 412 extern int zonecfg_get_attr_uint(const struct zone_attrtab *, uint64_t *);
406 413
407 414 /*
408 415 * ZFS configuration.
409 416 */
410 417 extern int zonecfg_add_ds(zone_dochandle_t, struct zone_dstab *);
411 418 extern int zonecfg_delete_ds(zone_dochandle_t, struct zone_dstab *);
412 419 extern int zonecfg_modify_ds(zone_dochandle_t, struct zone_dstab *,
413 420 struct zone_dstab *);
414 421 extern int zonecfg_lookup_ds(zone_dochandle_t, struct zone_dstab *);
415 422
416 423 /*
417 424 * cpu-set configuration.
418 425 */
419 426 extern int zonecfg_add_pset(zone_dochandle_t, struct zone_psettab *);
420 427 extern int zonecfg_delete_pset(zone_dochandle_t);
↓ open down ↓ |
156 lines elided |
↑ open up ↑ |
421 428 extern int zonecfg_modify_pset(zone_dochandle_t, struct zone_psettab *);
422 429 extern int zonecfg_lookup_pset(zone_dochandle_t, struct zone_psettab *);
423 430
424 431 /*
425 432 * mem-cap configuration.
426 433 */
427 434 extern int zonecfg_delete_mcap(zone_dochandle_t);
428 435 extern int zonecfg_modify_mcap(zone_dochandle_t, struct zone_mcaptab *);
429 436 extern int zonecfg_lookup_mcap(zone_dochandle_t, struct zone_mcaptab *);
430 437
438 +/* security-flags configuration */
439 +extern int zonecfg_add_secflags(zone_dochandle_t,
440 + struct zone_secflagstab *);
441 +extern int zonecfg_delete_secflags(zone_dochandle_t,
442 + struct zone_secflagstab *);
443 +extern int zonecfg_modify_secflags(zone_dochandle_t,
444 + struct zone_secflagstab *, struct zone_secflagstab *);
445 +extern int zonecfg_lookup_secflags(zone_dochandle_t,
446 + struct zone_secflagstab *);
447 +
431 448 /*
432 449 * Temporary pool support functions.
433 450 */
434 451 extern int zonecfg_destroy_tmp_pool(char *, char *, int);
435 452 extern int zonecfg_bind_tmp_pool(zone_dochandle_t, zoneid_t, char *, int);
436 453 extern int zonecfg_bind_pool(zone_dochandle_t, zoneid_t, char *, int);
437 454 extern boolean_t zonecfg_warn_poold(zone_dochandle_t);
438 455 extern int zonecfg_get_poolname(zone_dochandle_t, char *, char *, size_t);
439 456
440 457 /*
441 458 * Miscellaneous utility functions.
442 459 */
443 460 extern int zonecfg_enable_rcapd(char *, int);
444 461
445 462 /*
446 463 * attach/detach support.
447 464 */
448 465 extern int zonecfg_get_attach_handle(const char *, const char *,
449 466 const char *, boolean_t, zone_dochandle_t);
450 467 extern int zonecfg_attach_manifest(int, zone_dochandle_t,
451 468 zone_dochandle_t);
452 469 extern int zonecfg_detach_save(zone_dochandle_t, uint_t);
453 470 extern boolean_t zonecfg_detached(const char *);
454 471 extern void zonecfg_rm_detached(zone_dochandle_t, boolean_t forced);
455 472 extern int zonecfg_dev_manifest(zone_dochandle_t);
456 473 extern int zonecfg_devperms_apply(zone_dochandle_t, const char *,
457 474 uid_t, gid_t, mode_t, const char *);
458 475 extern void zonecfg_set_swinv(zone_dochandle_t);
459 476 extern int zonecfg_add_pkg(zone_dochandle_t, char *, char *);
460 477
461 478 /*
462 479 * External zone verification support.
463 480 */
464 481 extern int zonecfg_verify_save(zone_dochandle_t, char *);
465 482
466 483 /*
467 484 * '*ent' iterator routines.
468 485 */
469 486 extern int zonecfg_setfsent(zone_dochandle_t);
470 487 extern int zonecfg_getfsent(zone_dochandle_t, struct zone_fstab *);
471 488 extern int zonecfg_endfsent(zone_dochandle_t);
472 489 extern int zonecfg_setnwifent(zone_dochandle_t);
473 490 extern int zonecfg_getnwifent(zone_dochandle_t, struct zone_nwiftab *);
474 491 extern int zonecfg_endnwifent(zone_dochandle_t);
475 492 extern int zonecfg_setdevent(zone_dochandle_t);
476 493 extern int zonecfg_getdevent(zone_dochandle_t, struct zone_devtab *);
477 494 extern int zonecfg_enddevent(zone_dochandle_t);
478 495 extern int zonecfg_setattrent(zone_dochandle_t);
479 496 extern int zonecfg_getattrent(zone_dochandle_t, struct zone_attrtab *);
480 497 extern int zonecfg_endattrent(zone_dochandle_t);
481 498 extern int zonecfg_setrctlent(zone_dochandle_t);
482 499 extern int zonecfg_getrctlent(zone_dochandle_t, struct zone_rctltab *);
483 500 extern int zonecfg_endrctlent(zone_dochandle_t);
484 501 extern int zonecfg_setdsent(zone_dochandle_t);
485 502 extern int zonecfg_getdsent(zone_dochandle_t, struct zone_dstab *);
486 503 extern int zonecfg_enddsent(zone_dochandle_t);
487 504 extern int zonecfg_getpsetent(zone_dochandle_t, struct zone_psettab *);
↓ open down ↓ |
47 lines elided |
↑ open up ↑ |
488 505 extern int zonecfg_getmcapent(zone_dochandle_t, struct zone_mcaptab *);
489 506 extern int zonecfg_getpkgdata(zone_dochandle_t, uu_avl_pool_t *,
490 507 uu_avl_t *);
491 508 extern int zonecfg_setdevperment(zone_dochandle_t);
492 509 extern int zonecfg_getdevperment(zone_dochandle_t,
493 510 struct zone_devpermtab *);
494 511 extern int zonecfg_enddevperment(zone_dochandle_t);
495 512 extern int zonecfg_setadminent(zone_dochandle_t);
496 513 extern int zonecfg_getadminent(zone_dochandle_t, struct zone_admintab *);
497 514 extern int zonecfg_endadminent(zone_dochandle_t);
515 +extern int zonecfg_getsecflagsent(zone_dochandle_t,
516 + struct zone_secflagstab *);
498 517
499 518 /*
500 519 * Privilege-related functions.
501 520 */
502 521 extern int zonecfg_default_privset(priv_set_t *, const char *);
503 522 extern int zonecfg_get_privset(zone_dochandle_t, priv_set_t *,
504 523 char **);
505 524 extern int zonecfg_get_limitpriv(zone_dochandle_t, char **);
506 525 extern int zonecfg_set_limitpriv(zone_dochandle_t, char *);
507 526
508 527 /*
509 528 * Higher-level routines.
510 529 */
511 530 extern int zone_get_brand(char *, char *, size_t);
512 531 extern int zone_get_rootpath(char *, char *, size_t);
513 532 extern int zone_get_devroot(char *, char *, size_t);
514 533 extern int zone_get_zonepath(char *, char *, size_t);
515 534 extern int zone_get_state(char *, zone_state_t *);
516 535 extern int zone_set_state(char *, zone_state_t);
517 536 extern char *zone_state_str(zone_state_t);
518 537 extern int zonecfg_get_name_by_uuid(const uuid_t, char *, size_t);
519 538 extern int zonecfg_get_uuid(const char *, uuid_t);
520 539 extern int zonecfg_default_brand(char *, size_t);
521 540
522 541 /*
523 542 * Iterator for configured zones.
524 543 */
525 544 extern FILE *setzoneent(void);
526 545 extern char *getzoneent(FILE *);
527 546 extern struct zoneent *getzoneent_private(FILE *);
528 547 extern void endzoneent(FILE *);
529 548
530 549 /*
531 550 * File-system-related convenience functions.
532 551 */
533 552 extern boolean_t zonecfg_valid_fs_type(const char *);
534 553
535 554 /*
536 555 * Network-related convenience functions.
537 556 */
538 557 extern boolean_t zonecfg_same_net_address(char *, char *);
539 558 extern int zonecfg_valid_net_address(char *, struct lifreq *);
540 559 extern boolean_t zonecfg_ifname_exists(sa_family_t, char *);
541 560
542 561 /*
543 562 * Rctl-related common functions.
544 563 */
545 564 extern boolean_t zonecfg_is_rctl(const char *);
546 565 extern boolean_t zonecfg_valid_rctlname(const char *);
547 566 extern boolean_t zonecfg_valid_rctlblk(const rctlblk_t *);
548 567 extern boolean_t zonecfg_valid_rctl(const char *, const rctlblk_t *);
549 568 extern int zonecfg_construct_rctlblk(const struct zone_rctlvaltab *,
550 569 rctlblk_t *);
551 570
552 571 /*
553 572 * Live Upgrade support functions. Shared between ON and install gate.
554 573 */
555 574 extern FILE *zonecfg_open_scratch(const char *, boolean_t);
556 575 extern int zonecfg_lock_scratch(FILE *);
557 576 extern void zonecfg_close_scratch(FILE *);
558 577 extern int zonecfg_get_scratch(FILE *, char *, size_t, char *, size_t, char *,
559 578 size_t);
560 579 extern int zonecfg_find_scratch(FILE *, const char *, const char *, char *,
561 580 size_t);
562 581 extern int zonecfg_reverse_scratch(FILE *, const char *, char *, size_t,
563 582 char *, size_t);
564 583 extern int zonecfg_add_scratch(FILE *, const char *, const char *,
565 584 const char *);
566 585 extern int zonecfg_delete_scratch(FILE *, const char *);
567 586 extern boolean_t zonecfg_is_scratch(const char *);
568 587
569 588 /*
570 589 * zoneadmd support functions. Shared between zoneadm and brand hook code.
571 590 */
572 591 extern void zonecfg_init_lock_file(const char *, char **);
573 592 extern void zonecfg_release_lock_file(const char *, int);
574 593 extern int zonecfg_grab_lock_file(const char *, int *);
575 594 extern boolean_t zonecfg_lock_file_held(int *);
576 595 extern int zonecfg_ping_zoneadmd(const char *);
577 596 extern int zonecfg_call_zoneadmd(const char *, zone_cmd_arg_t *, char *,
578 597 boolean_t);
579 598 extern int zonecfg_insert_userauths(zone_dochandle_t, char *, char *);
580 599 extern int zonecfg_remove_userauths(zone_dochandle_t, char *, char *,
581 600 boolean_t);
582 601 extern int zonecfg_add_admin(zone_dochandle_t, struct zone_admintab *,
583 602 char *);
584 603 extern int zonecfg_delete_admin(zone_dochandle_t,
585 604 struct zone_admintab *, char *);
586 605 extern int zonecfg_modify_admin(zone_dochandle_t, struct zone_admintab *,
587 606 struct zone_admintab *, char *);
588 607 extern int zonecfg_delete_admins(zone_dochandle_t, char *);
589 608 extern int zonecfg_lookup_admin(zone_dochandle_t, struct zone_admintab *);
590 609 extern int zonecfg_authorize_users(zone_dochandle_t, char *);
591 610 extern int zonecfg_update_userauths(zone_dochandle_t, char *);
592 611 extern int zonecfg_deauthorize_user(zone_dochandle_t, char *, char *);
593 612 extern int zonecfg_deauthorize_users(zone_dochandle_t, char *);
594 613 extern boolean_t zonecfg_valid_auths(const char *, const char *);
595 614
596 615 #ifdef __cplusplus
597 616 }
598 617 #endif
599 618
600 619 #endif /* _LIBZONECFG_H */
↓ open down ↓ |
93 lines elided |
↑ open up ↑ |
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX