4 * The contents of this file are subject to the terms of the
5 * Common Development and Distribution License (the "License").
6 * You may not use this file except in compliance with the License.
8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9 * or http://www.opensolaris.org/os/licensing.
10 * See the License for the specific language governing permissions
11 * and limitations under the License.
13 * When distributing Covered Code, include this CDDL HEADER in each
14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15 * If applicable, add the following below this CDDL HEADER, with the
16 * fields enclosed by brackets "[]" replaced with your own identifying
17 * information: Portions Copyright [yyyy] [name of copyright owner]
22 * Copyright 2009 Sun Microsystems, Inc. All rights reserved.
23 * Use is subject to license terms.
26 /* Copyright (c) 1983, 1984, 1985, 1986, 1987, 1988, 1989 AT&T */
27 /* All Rights Reserved */
30 * Portions of this source code were derived from Berkeley 4.3 BSD
31 * under license from the Regents of the University of California.
37 #include <sys/types.h>
44 * The credential is an opaque kernel private data structure defined in
48 typedef struct cred cred_t
;
52 #define CRED() curthread->t_cred
54 struct proc
; /* cred.h is included in proc.h */
61 struct auditinfo_addr
; /* cred.h is included in audit.h */
63 extern int ngroups_max
;
65 * kcred is used when you need all privileges.
67 extern struct cred
*kcred
;
69 extern void cred_init(void);
70 extern void crhold(cred_t
*);
71 extern void crfree(cred_t
*);
72 extern cred_t
*cralloc(void); /* all but ref uninitialized */
73 extern cred_t
*cralloc_ksid(void); /* cralloc() + ksid alloc'ed */
74 extern cred_t
*crget(void); /* initialized */
75 extern cred_t
*crcopy(cred_t
*);
76 extern void crcopy_to(cred_t
*, cred_t
*);
77 extern cred_t
*crdup(cred_t
*);
78 extern void crdup_to(cred_t
*, cred_t
*);
79 extern cred_t
*crgetcred(void);
80 extern void crset(struct proc
*, cred_t
*);
81 extern void crset_zone_privall(cred_t
*);
82 extern int groupmember(gid_t
, const cred_t
*);
83 extern int supgroupmember(gid_t
, const cred_t
*);
84 extern int hasprocperm(const cred_t
*, const cred_t
*);
85 extern int prochasprocperm(struct proc
*, struct proc
*, const cred_t
*);
86 extern int crcmp(const cred_t
*, const cred_t
*);
87 extern cred_t
*zone_kcred(void);
89 extern uid_t
crgetuid(const cred_t
*);
90 extern uid_t
crgetruid(const cred_t
*);
91 extern uid_t
crgetsuid(const cred_t
*);
92 extern gid_t
crgetgid(const cred_t
*);
93 extern gid_t
crgetrgid(const cred_t
*);
94 extern gid_t
crgetsgid(const cred_t
*);
95 extern zoneid_t
crgetzoneid(const cred_t
*);
96 extern projid_t
crgetprojid(const cred_t
*);
98 extern cred_t
*crgetmapped(const cred_t
*);
101 extern const struct auditinfo_addr
*crgetauinfo(const cred_t
*);
102 extern struct auditinfo_addr
*crgetauinfo_modifiable(cred_t
*);
104 extern uint_t
crgetref(const cred_t
*);
106 extern const gid_t
*crgetgroups(const cred_t
*);
107 extern const gid_t
*crgetggroups(const struct credgrp
*);
109 extern int crgetngroups(const cred_t
*);
112 * Sets real, effective and/or saved uid/gid;
113 * -1 argument accepted as "no change".
115 extern int crsetresuid(cred_t
*, uid_t
, uid_t
, uid_t
);
116 extern int crsetresgid(cred_t
*, gid_t
, gid_t
, gid_t
);
119 * Sets real, effective and saved uids/gids all to the same
120 * values. Both values must be non-negative and <= MAXUID
122 extern int crsetugid(cred_t
*, uid_t
, gid_t
);
125 * Functions to handle the supplemental group list.
127 extern int crsetgroups(cred_t
*, int, gid_t
*);
128 extern struct credgrp
*crgrpcopyin(int, gid_t
*);
129 extern void crgrprele(struct credgrp
*);
130 extern void crsetcredgrp(cred_t
*, struct credgrp
*);
133 * Private interface for setting zone association of credential.
136 extern void crsetzone(cred_t
*, struct zone
*);
137 extern struct zone
*crgetzone(const cred_t
*);
140 * Private interface for setting project id in credential.
142 extern void crsetprojid(cred_t
*, projid_t
);
145 * Private interface for nfs.
147 extern cred_t
*crnetadjust(cred_t
*);
150 * Private interface for procfs.
152 extern void cred2prcred(const cred_t
*, struct prcred
*);
155 * Private interfaces for ephemeral uids.
157 #define VALID_UID(id, zn) \
158 ((id) <= MAXUID || valid_ephemeral_uid((zn), (id)))
160 #define VALID_GID(id, zn) \
161 ((id) <= MAXUID || valid_ephemeral_gid((zn), (id)))
163 extern boolean_t
valid_ephemeral_uid(struct zone
*, uid_t
);
164 extern boolean_t
valid_ephemeral_gid(struct zone
*, gid_t
);
166 extern int eph_uid_alloc(struct zone
*, int, uid_t
*, int);
167 extern int eph_gid_alloc(struct zone
*, int, gid_t
*, int);
169 extern void crsetsid(cred_t
*, struct ksid
*, int);
170 extern void crsetsidlist(cred_t
*, struct ksidlist
*);
172 extern struct ksid
*crgetsid(const cred_t
*, int);
173 extern struct ksidlist
*crgetsidlist(const cred_t
*);
175 extern int crsetpriv(cred_t
*, ...);
177 extern struct credklpd
*crgetcrklpd(const cred_t
*);
178 extern void crsetcrklpd(cred_t
*, struct credklpd
*);
186 #endif /* _SYS_CRED_H */