1f0a75d27SPawel Jakub Dawidek /*- 2f0a75d27SPawel Jakub Dawidek * Copyright (c) 2007 Pawel Jakub Dawidek <pjd@FreeBSD.org> 3f0a75d27SPawel Jakub Dawidek * All rights reserved. 4f0a75d27SPawel Jakub Dawidek * 5f0a75d27SPawel Jakub Dawidek * Redistribution and use in source and binary forms, with or without 6f0a75d27SPawel Jakub Dawidek * modification, are permitted provided that the following conditions 7f0a75d27SPawel Jakub Dawidek * are met: 8f0a75d27SPawel Jakub Dawidek * 1. Redistributions of source code must retain the above copyright 9f0a75d27SPawel Jakub Dawidek * notice, this list of conditions and the following disclaimer. 10f0a75d27SPawel Jakub Dawidek * 2. Redistributions in binary form must reproduce the above copyright 11f0a75d27SPawel Jakub Dawidek * notice, this list of conditions and the following disclaimer in the 12f0a75d27SPawel Jakub Dawidek * documentation and/or other materials provided with the distribution. 13f0a75d27SPawel Jakub Dawidek * 14f0a75d27SPawel Jakub Dawidek * THIS SOFTWARE IS PROVIDED BY THE AUTHORS AND CONTRIBUTORS ``AS IS'' AND 15f0a75d27SPawel Jakub Dawidek * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 16f0a75d27SPawel Jakub Dawidek * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 17f0a75d27SPawel Jakub Dawidek * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS BE LIABLE 18f0a75d27SPawel Jakub Dawidek * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 19f0a75d27SPawel Jakub Dawidek * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 20f0a75d27SPawel Jakub Dawidek * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 21f0a75d27SPawel Jakub Dawidek * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 22f0a75d27SPawel Jakub Dawidek * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 23f0a75d27SPawel Jakub Dawidek * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 24f0a75d27SPawel Jakub Dawidek * SUCH DAMAGE. 25f0a75d27SPawel Jakub Dawidek * 26f0a75d27SPawel Jakub Dawidek */ 27f0a75d27SPawel Jakub Dawidek 28f0a75d27SPawel Jakub Dawidek #ifndef _OPENSOLARIS_SYS_POLICY_H_ 29f0a75d27SPawel Jakub Dawidek #define _OPENSOLARIS_SYS_POLICY_H_ 30f0a75d27SPawel Jakub Dawidek 31f0a75d27SPawel Jakub Dawidek #include <sys/param.h> 32f0a75d27SPawel Jakub Dawidek 33f0a75d27SPawel Jakub Dawidek #ifdef _KERNEL 34f0a75d27SPawel Jakub Dawidek 351ba4a712SPawel Jakub Dawidek #include <sys/vnode.h> 361ba4a712SPawel Jakub Dawidek 37f0a75d27SPawel Jakub Dawidek struct mount; 38f0a75d27SPawel Jakub Dawidek struct vattr; 39f0a75d27SPawel Jakub Dawidek 40*10b9d77bSPawel Jakub Dawidek int secpolicy_nfs(cred_t *cr); 41*10b9d77bSPawel Jakub Dawidek int secpolicy_zfs(cred_t *crd); 42*10b9d77bSPawel Jakub Dawidek int secpolicy_sys_config(cred_t *cr, int checkonly); 43*10b9d77bSPawel Jakub Dawidek int secpolicy_zinject(cred_t *cr); 44*10b9d77bSPawel Jakub Dawidek int secpolicy_fs_unmount(cred_t *cr, struct mount *vfsp); 45*10b9d77bSPawel Jakub Dawidek int secpolicy_basic_link(vnode_t *vp, cred_t *cr); 46*10b9d77bSPawel Jakub Dawidek int secpolicy_vnode_owner(vnode_t *vp, cred_t *cr, uid_t owner); 47*10b9d77bSPawel Jakub Dawidek int secpolicy_vnode_chown(vnode_t *vp, cred_t *cr, uid_t owner); 48*10b9d77bSPawel Jakub Dawidek int secpolicy_vnode_stky_modify(cred_t *cr); 49*10b9d77bSPawel Jakub Dawidek int secpolicy_vnode_remove(vnode_t *vp, cred_t *cr); 50*10b9d77bSPawel Jakub Dawidek int secpolicy_vnode_access(cred_t *cr, vnode_t *vp, uid_t owner, 51*10b9d77bSPawel Jakub Dawidek accmode_t accmode); 52*10b9d77bSPawel Jakub Dawidek int secpolicy_vnode_access2(cred_t *cr, vnode_t *vp, uid_t owner, 53*10b9d77bSPawel Jakub Dawidek accmode_t curmode, accmode_t wantmode); 54*10b9d77bSPawel Jakub Dawidek int secpolicy_vnode_any_access(cred_t *cr, vnode_t *vp, uid_t owner); 55*10b9d77bSPawel Jakub Dawidek int secpolicy_vnode_setdac(vnode_t *vp, cred_t *cr, uid_t owner); 56*10b9d77bSPawel Jakub Dawidek int secpolicy_vnode_setattr(cred_t *cr, vnode_t *vp, struct vattr *vap, 57*10b9d77bSPawel Jakub Dawidek const struct vattr *ovap, int flags, 58*10b9d77bSPawel Jakub Dawidek int unlocked_access(void *, int, cred_t *), void *node); 59*10b9d77bSPawel Jakub Dawidek int secpolicy_vnode_create_gid(cred_t *cr); 60*10b9d77bSPawel Jakub Dawidek int secpolicy_vnode_setids_setgids(vnode_t *vp, cred_t *cr, gid_t gid); 61*10b9d77bSPawel Jakub Dawidek int secpolicy_vnode_setid_retain(vnode_t *vp, cred_t *cr, 621ba4a712SPawel Jakub Dawidek boolean_t issuidroot); 63*10b9d77bSPawel Jakub Dawidek void secpolicy_setid_clear(struct vattr *vap, vnode_t *vp, cred_t *cr); 64*10b9d77bSPawel Jakub Dawidek int secpolicy_setid_setsticky_clear(vnode_t *vp, struct vattr *vap, 65*10b9d77bSPawel Jakub Dawidek const struct vattr *ovap, cred_t *cr); 66*10b9d77bSPawel Jakub Dawidek int secpolicy_fs_owner(struct mount *vfsp, cred_t *cr); 671ba4a712SPawel Jakub Dawidek int secpolicy_fs_mount(cred_t *cr, vnode_t *mvp, struct mount *vfsp); 681ba4a712SPawel Jakub Dawidek void secpolicy_fs_mount_clearopts(cred_t *cr, struct mount *vfsp); 69*10b9d77bSPawel Jakub Dawidek int secpolicy_xvattr(vnode_t *vp, xvattr_t *xvap, uid_t owner, cred_t *cr, 70*10b9d77bSPawel Jakub Dawidek vtype_t vtype); 718fc25799SMartin Matuska int secpolicy_smb(cred_t *cr); 72f0a75d27SPawel Jakub Dawidek 73f0a75d27SPawel Jakub Dawidek #endif /* _KERNEL */ 74f0a75d27SPawel Jakub Dawidek 75f0a75d27SPawel Jakub Dawidek #endif /* _OPENSOLARIS_SYS_POLICY_H_ */ 76