1f48205beScasper /* 2f48205beScasper * CDDL HEADER START 3f48205beScasper * 4f48205beScasper * The contents of this file are subject to the terms of the 5f48205beScasper * Common Development and Distribution License (the "License"). 6f48205beScasper * You may not use this file except in compliance with the License. 7f48205beScasper * 8f48205beScasper * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 9f48205beScasper * or http://www.opensolaris.org/os/licensing. 10f48205beScasper * See the License for the specific language governing permissions 11f48205beScasper * and limitations under the License. 12f48205beScasper * 13f48205beScasper * When distributing Covered Code, include this CDDL HEADER in each 14f48205beScasper * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 15f48205beScasper * If applicable, add the following below this CDDL HEADER, with the 16f48205beScasper * fields enclosed by brackets "[]" replaced with your own identifying 17f48205beScasper * information: Portions Copyright [yyyy] [name of copyright owner] 18f48205beScasper * 19f48205beScasper * CDDL HEADER END 20f48205beScasper */ 21f48205beScasper 22f48205beScasper /* 23*bda89588Sjp151216 * Copyright 2008 Sun Microsystems, Inc. All rights reserved. 24f48205beScasper * Use is subject to license terms. 25f48205beScasper */ 26f48205beScasper 27f48205beScasper #ifndef _SYS_SID_H 28f48205beScasper #define _SYS_SID_H 29f48205beScasper 30f48205beScasper #pragma ident "%Z%%M% %I% %E% SMI" 31f48205beScasper 32f48205beScasper #include <sys/types.h> 33f48205beScasper #include <sys/avl.h> 34*bda89588Sjp151216 #ifdef _KERNEL 35*bda89588Sjp151216 #include <sys/zone.h> 36*bda89588Sjp151216 #endif 37f48205beScasper 38f48205beScasper /* 39f48205beScasper * Kernel SID data structure and functions. 40f48205beScasper */ 41f48205beScasper #ifdef __cplusplus 42f48205beScasper extern "C" { 43f48205beScasper #endif 44f48205beScasper 45f48205beScasper /* sidsys subcodes */ 46f48205beScasper #define SIDSYS_ALLOC_IDS 0 47f48205beScasper /* Flags for ALLOC_IDS */ 48f48205beScasper #define SID_EXTEND_RANGE 0 49f48205beScasper #define SID_NEW_RANGE 1 50f48205beScasper 51f48205beScasper #define SIDSYS_IDMAP_REG 1 52f48205beScasper #define SIDSYS_IDMAP_UNREG 2 53f48205beScasper 54f48205beScasper #define SIDSYS_SID2ID 0 55f48205beScasper #define SIDSYS_ID2SID 1 56f48205beScasper 57f48205beScasper #ifdef _KERNEL 58da6c28aaSamw #define KSIDLIST_MEM(n) (sizeof (ksidlist_t) + ((n) - 1) * sizeof (ksid_t)) 59da6c28aaSamw 60f48205beScasper /* Domains are stored in AVL trees so we can share them among SIDs */ 61f48205beScasper typedef struct ksiddomain { 62f48205beScasper uint_t kd_ref; 63f48205beScasper uint_t kd_len; 64f48205beScasper char *kd_name; /* Domain part of SID */ 65f48205beScasper avl_node_t kd_link; 66f48205beScasper } ksiddomain_t; 67f48205beScasper 68f48205beScasper typedef struct ksid { 69f48205beScasper uid_t ks_id; /* Cache of (ephemeral) uid */ 70f48205beScasper uint32_t ks_rid; /* Rid part of the name */ 71f48205beScasper uint32_t ks_attr; /* Attribute */ 72f48205beScasper ksiddomain_t *ks_domain; /* Domain descsriptor */ 73f48205beScasper } ksid_t; 74f48205beScasper 75f48205beScasper typedef enum ksid_index { 76f48205beScasper KSID_USER, 77f48205beScasper KSID_GROUP, 78f48205beScasper KSID_OWNER, 79f48205beScasper KSID_COUNT /* Must be last */ 80f48205beScasper } ksid_index_t; 81f48205beScasper 82f48205beScasper /* 83f48205beScasper * As no memory may be allocated for credentials while holding p_crlock, 84f48205beScasper * all sub data structures need to be ref counted. 85f48205beScasper */ 86f48205beScasper 87f48205beScasper typedef struct ksidlist { 88f48205beScasper uint_t ksl_ref; 89f48205beScasper uint_t ksl_nsid; 90f48205beScasper uint_t ksl_neid; /* Number of ids which are ephemeral */ 91f48205beScasper ksid_t ksl_sids[1]; /* Allocate ksl_nsid times */ 92f48205beScasper } ksidlist_t; 93f48205beScasper 94f48205beScasper typedef struct credsid { 95f48205beScasper uint_t kr_ref; /* Reference count */ 96f48205beScasper ksid_t kr_sidx[KSID_COUNT]; /* User, group, default owner */ 97f48205beScasper ksidlist_t *kr_sidlist; /* List of SIDS */ 98f48205beScasper } credsid_t; 99f48205beScasper 100f48205beScasper const char *ksid_getdomain(ksid_t *); 101f48205beScasper uint_t ksid_getrid(ksid_t *); 102f48205beScasper 103*bda89588Sjp151216 int ksid_lookupbyuid(zone_t *, uid_t, ksid_t *); 104*bda89588Sjp151216 int ksid_lookupbygid(zone_t *, gid_t, ksid_t *); 105f48205beScasper void ksid_rele(ksid_t *); 106f48205beScasper 107f48205beScasper credsid_t *kcrsid_alloc(void); 108f48205beScasper 109f48205beScasper credsid_t *kcrsid_setsid(credsid_t *, ksid_t *, ksid_index_t); 110f48205beScasper credsid_t *kcrsid_setsidlist(credsid_t *, ksidlist_t *); 111f48205beScasper 112f48205beScasper void kcrsid_rele(credsid_t *); 113f48205beScasper void kcrsid_hold(credsid_t *); 114f48205beScasper void kcrsidcopy_to(const credsid_t *okcr, credsid_t *nkcr); 115f48205beScasper 116f48205beScasper void ksiddomain_rele(ksiddomain_t *); 117f48205beScasper void ksiddomain_hold(ksiddomain_t *); 118f48205beScasper void ksidlist_rele(ksidlist_t *); 119f48205beScasper void ksidlist_hold(ksidlist_t *); 120f48205beScasper 121f48205beScasper ksiddomain_t *ksid_lookupdomain(const char *); 122f48205beScasper 123*bda89588Sjp151216 ksidlist_t *kcrsid_gidstosids(zone_t *, int, gid_t *); 124f48205beScasper 125f48205beScasper #else 126f48205beScasper 127f48205beScasper int allocids(int, int, uid_t *, int, gid_t *); 128f48205beScasper int idmap_reg(int); 129f48205beScasper int idmap_unreg(int); 130f48205beScasper 131f48205beScasper #endif /* _KERNEL */ 132f48205beScasper 133f48205beScasper #ifdef __cplusplus 134f48205beScasper } 135f48205beScasper #endif 136f48205beScasper 137f48205beScasper #endif /* _SYS_SID_H */ 138