1 /* 2 * Copyright (C) 2007-2010 Lawrence Livermore National Security, LLC. 3 * Copyright (C) 2007 The Regents of the University of California. 4 * Produced at Lawrence Livermore National Laboratory (cf, DISCLAIMER). 5 * Written by Brian Behlendorf <behlendorf1@llnl.gov>. 6 * UCRL-CODE-235197 7 * 8 * This file is part of the SPL, Solaris Porting Layer. 9 * 10 * The SPL is free software; you can redistribute it and/or modify it 11 * under the terms of the GNU General Public License as published by the 12 * Free Software Foundation; either version 2 of the License, or (at your 13 * option) any later version. 14 * 15 * The SPL is distributed in the hope that it will be useful, but WITHOUT 16 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or 17 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License 18 * for more details. 19 * 20 * You should have received a copy of the GNU General Public License along 21 * with the SPL. If not, see <http://www.gnu.org/licenses/>. 22 */ 23 24 #ifndef _SPL_ACL_H 25 #define _SPL_ACL_H 26 27 #include <sys/types.h> 28 29 typedef struct ace { 30 uid_t a_who; 31 uint32_t a_access_mask; 32 uint16_t a_flags; 33 uint16_t a_type; 34 } ace_t; 35 36 typedef struct ace_object { 37 uid_t a_who; /* uid or gid */ 38 uint32_t a_access_mask; /* read,write,... */ 39 uint16_t a_flags; /* see below */ 40 uint16_t a_type; /* allow or deny */ 41 uint8_t a_obj_type[16]; /* obj type */ 42 uint8_t a_inherit_obj_type[16]; /* inherit obj */ 43 } ace_object_t; 44 45 #define MAX_ACL_ENTRIES 1024 46 47 #define ACE_READ_DATA 0x00000001 48 #define ACE_LIST_DIRECTORY 0x00000001 49 #define ACE_WRITE_DATA 0x00000002 50 #define ACE_ADD_FILE 0x00000002 51 #define ACE_APPEND_DATA 0x00000004 52 #define ACE_ADD_SUBDIRECTORY 0x00000004 53 #define ACE_READ_NAMED_ATTRS 0x00000008 54 #define ACE_WRITE_NAMED_ATTRS 0x00000010 55 #define ACE_EXECUTE 0x00000020 56 #define ACE_DELETE_CHILD 0x00000040 57 #define ACE_READ_ATTRIBUTES 0x00000080 58 #define ACE_WRITE_ATTRIBUTES 0x00000100 59 #define ACE_DELETE 0x00010000 60 #define ACE_READ_ACL 0x00020000 61 #define ACE_WRITE_ACL 0x00040000 62 #define ACE_WRITE_OWNER 0x00080000 63 #define ACE_SYNCHRONIZE 0x00100000 64 65 #define ACE_FILE_INHERIT_ACE 0x0001 66 #define ACE_DIRECTORY_INHERIT_ACE 0x0002 67 #define ACE_NO_PROPAGATE_INHERIT_ACE 0x0004 68 #define ACE_INHERIT_ONLY_ACE 0x0008 69 #define ACE_SUCCESSFUL_ACCESS_ACE_FLAG 0x0010 70 #define ACE_FAILED_ACCESS_ACE_FLAG 0x0020 71 #define ACE_IDENTIFIER_GROUP 0x0040 72 #define ACE_INHERITED_ACE 0x0080 73 #define ACE_OWNER 0x1000 74 #define ACE_GROUP 0x2000 75 #define ACE_EVERYONE 0x4000 76 77 #define ACE_ACCESS_ALLOWED_ACE_TYPE 0x0000 78 #define ACE_ACCESS_DENIED_ACE_TYPE 0x0001 79 #define ACE_SYSTEM_AUDIT_ACE_TYPE 0x0002 80 #define ACE_SYSTEM_ALARM_ACE_TYPE 0x0003 81 82 #define ACL_AUTO_INHERIT 0x0001 83 #define ACL_PROTECTED 0x0002 84 #define ACL_DEFAULTED 0x0004 85 #define ACL_FLAGS_ALL (ACL_AUTO_INHERIT|ACL_PROTECTED|ACL_DEFAULTED) 86 87 #define ACE_ACCESS_ALLOWED_COMPOUND_ACE_TYPE 0x04 88 #define ACE_ACCESS_ALLOWED_OBJECT_ACE_TYPE 0x05 89 #define ACE_ACCESS_DENIED_OBJECT_ACE_TYPE 0x06 90 #define ACE_SYSTEM_AUDIT_OBJECT_ACE_TYPE 0x07 91 #define ACE_SYSTEM_ALARM_OBJECT_ACE_TYPE 0x08 92 #define ACE_ACCESS_ALLOWED_CALLBACK_ACE_TYPE 0x09 93 #define ACE_ACCESS_DENIED_CALLBACK_ACE_TYPE 0x0A 94 #define ACE_ACCESS_ALLOWED_CALLBACK_OBJECT_ACE_TYPE 0x0B 95 #define ACE_ACCESS_DENIED_CALLBACK_OBJECT_ACE_TYPE 0x0C 96 #define ACE_SYSTEM_AUDIT_CALLBACK_ACE_TYPE 0x0D 97 #define ACE_SYSTEM_ALARM_CALLBACK_ACE_TYPE 0x0E 98 #define ACE_SYSTEM_AUDIT_CALLBACK_OBJECT_ACE_TYPE 0x0F 99 #define ACE_SYSTEM_ALARM_CALLBACK_OBJECT_ACE_TYPE 0x10 100 101 #define ACE_ALL_TYPES 0x001F 102 103 #define ACE_TYPE_FLAGS (ACE_OWNER|ACE_GROUP|ACE_EVERYONE|ACE_IDENTIFIER_GROUP) 104 105 #define ACE_ALL_PERMS (ACE_READ_DATA|ACE_LIST_DIRECTORY|ACE_WRITE_DATA| \ 106 ACE_ADD_FILE|ACE_APPEND_DATA|ACE_ADD_SUBDIRECTORY|ACE_READ_NAMED_ATTRS|\ 107 ACE_WRITE_NAMED_ATTRS|ACE_EXECUTE|ACE_DELETE_CHILD|ACE_READ_ATTRIBUTES|\ 108 ACE_WRITE_ATTRIBUTES|ACE_DELETE|ACE_READ_ACL|ACE_WRITE_ACL| \ 109 ACE_WRITE_OWNER|ACE_SYNCHRONIZE) 110 111 #define VSA_ACE 0x0010 112 #define VSA_ACECNT 0x0020 113 #define VSA_ACE_ALLTYPES 0x0040 114 #define VSA_ACE_ACLFLAGS 0x0080 115 116 #endif /* _SPL_ACL_H */ 117