xref: /titanic_51/usr/src/uts/common/sys/cred.h (revision 7c478bd95313f5f23a4c958a745db2134aa03244)
1*7c478bd9Sstevel@tonic-gate /*
2*7c478bd9Sstevel@tonic-gate  * CDDL HEADER START
3*7c478bd9Sstevel@tonic-gate  *
4*7c478bd9Sstevel@tonic-gate  * The contents of this file are subject to the terms of the
5*7c478bd9Sstevel@tonic-gate  * Common Development and Distribution License, Version 1.0 only
6*7c478bd9Sstevel@tonic-gate  * (the "License").  You may not use this file except in compliance
7*7c478bd9Sstevel@tonic-gate  * with the License.
8*7c478bd9Sstevel@tonic-gate  *
9*7c478bd9Sstevel@tonic-gate  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
10*7c478bd9Sstevel@tonic-gate  * or http://www.opensolaris.org/os/licensing.
11*7c478bd9Sstevel@tonic-gate  * See the License for the specific language governing permissions
12*7c478bd9Sstevel@tonic-gate  * and limitations under the License.
13*7c478bd9Sstevel@tonic-gate  *
14*7c478bd9Sstevel@tonic-gate  * When distributing Covered Code, include this CDDL HEADER in each
15*7c478bd9Sstevel@tonic-gate  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
16*7c478bd9Sstevel@tonic-gate  * If applicable, add the following below this CDDL HEADER, with the
17*7c478bd9Sstevel@tonic-gate  * fields enclosed by brackets "[]" replaced with your own identifying
18*7c478bd9Sstevel@tonic-gate  * information: Portions Copyright [yyyy] [name of copyright owner]
19*7c478bd9Sstevel@tonic-gate  *
20*7c478bd9Sstevel@tonic-gate  * CDDL HEADER END
21*7c478bd9Sstevel@tonic-gate  */
22*7c478bd9Sstevel@tonic-gate /*
23*7c478bd9Sstevel@tonic-gate  * Copyright 2004 Sun Microsystems, Inc.  All rights reserved.
24*7c478bd9Sstevel@tonic-gate  * Use is subject to license terms.
25*7c478bd9Sstevel@tonic-gate  */
26*7c478bd9Sstevel@tonic-gate 
27*7c478bd9Sstevel@tonic-gate /*	Copyright (c) 1983, 1984, 1985, 1986, 1987, 1988, 1989 AT&T	*/
28*7c478bd9Sstevel@tonic-gate /*	  All Rights Reserved  	*/
29*7c478bd9Sstevel@tonic-gate 
30*7c478bd9Sstevel@tonic-gate /*
31*7c478bd9Sstevel@tonic-gate  * Portions of this source code were derived from Berkeley 4.3 BSD
32*7c478bd9Sstevel@tonic-gate  * under license from the Regents of the University of California.
33*7c478bd9Sstevel@tonic-gate  */
34*7c478bd9Sstevel@tonic-gate 
35*7c478bd9Sstevel@tonic-gate #ifndef _SYS_CRED_H
36*7c478bd9Sstevel@tonic-gate #define	_SYS_CRED_H
37*7c478bd9Sstevel@tonic-gate 
38*7c478bd9Sstevel@tonic-gate #pragma ident	"%Z%%M%	%I%	%E% SMI"
39*7c478bd9Sstevel@tonic-gate 
40*7c478bd9Sstevel@tonic-gate #include <sys/types.h>
41*7c478bd9Sstevel@tonic-gate 
42*7c478bd9Sstevel@tonic-gate #ifdef	__cplusplus
43*7c478bd9Sstevel@tonic-gate extern "C" {
44*7c478bd9Sstevel@tonic-gate #endif
45*7c478bd9Sstevel@tonic-gate 
46*7c478bd9Sstevel@tonic-gate /*
47*7c478bd9Sstevel@tonic-gate  * The credential is an opaque kernel private data structure defined in
48*7c478bd9Sstevel@tonic-gate  * <sys/cred_impl.h>.
49*7c478bd9Sstevel@tonic-gate  */
50*7c478bd9Sstevel@tonic-gate 
51*7c478bd9Sstevel@tonic-gate typedef struct cred cred_t;
52*7c478bd9Sstevel@tonic-gate 
53*7c478bd9Sstevel@tonic-gate #ifdef _KERNEL
54*7c478bd9Sstevel@tonic-gate 
55*7c478bd9Sstevel@tonic-gate #define	CRED()		curthread->t_cred
56*7c478bd9Sstevel@tonic-gate 
57*7c478bd9Sstevel@tonic-gate struct proc;				/* cred.h is included in proc.h */
58*7c478bd9Sstevel@tonic-gate struct prcred;
59*7c478bd9Sstevel@tonic-gate 
60*7c478bd9Sstevel@tonic-gate struct auditinfo_addr;			/* cred.h is included in audit.h */
61*7c478bd9Sstevel@tonic-gate 
62*7c478bd9Sstevel@tonic-gate extern int ngroups_max;
63*7c478bd9Sstevel@tonic-gate /*
64*7c478bd9Sstevel@tonic-gate  * kcred is used when you need all privileges.
65*7c478bd9Sstevel@tonic-gate  */
66*7c478bd9Sstevel@tonic-gate extern struct cred *kcred;
67*7c478bd9Sstevel@tonic-gate 
68*7c478bd9Sstevel@tonic-gate extern void cred_init(void);
69*7c478bd9Sstevel@tonic-gate extern void crhold(cred_t *);
70*7c478bd9Sstevel@tonic-gate extern void crfree(cred_t *);
71*7c478bd9Sstevel@tonic-gate extern cred_t *cralloc(void);		/* all but ref uninitialized */
72*7c478bd9Sstevel@tonic-gate extern cred_t *crget(void);		/* initialized */
73*7c478bd9Sstevel@tonic-gate extern cred_t *crcopy(cred_t *);
74*7c478bd9Sstevel@tonic-gate extern void crcopy_to(cred_t *, cred_t *);
75*7c478bd9Sstevel@tonic-gate extern cred_t *crdup(cred_t *);
76*7c478bd9Sstevel@tonic-gate extern void crdup_to(cred_t *, cred_t *);
77*7c478bd9Sstevel@tonic-gate extern cred_t *crgetcred(void);
78*7c478bd9Sstevel@tonic-gate extern void crset(struct proc *, cred_t *);
79*7c478bd9Sstevel@tonic-gate extern int groupmember(gid_t, const cred_t *);
80*7c478bd9Sstevel@tonic-gate extern int supgroupmember(gid_t, const cred_t *);
81*7c478bd9Sstevel@tonic-gate extern int hasprocperm(const cred_t *, const cred_t *);
82*7c478bd9Sstevel@tonic-gate extern int prochasprocperm(struct proc *, struct proc *, const cred_t *);
83*7c478bd9Sstevel@tonic-gate extern int crcmp(const cred_t *, const cred_t *);
84*7c478bd9Sstevel@tonic-gate 
85*7c478bd9Sstevel@tonic-gate extern uid_t crgetuid(const cred_t *);
86*7c478bd9Sstevel@tonic-gate extern uid_t crgetruid(const cred_t *);
87*7c478bd9Sstevel@tonic-gate extern uid_t crgetsuid(const cred_t *);
88*7c478bd9Sstevel@tonic-gate extern gid_t crgetgid(const cred_t *);
89*7c478bd9Sstevel@tonic-gate extern gid_t crgetrgid(const cred_t *);
90*7c478bd9Sstevel@tonic-gate extern gid_t crgetsgid(const cred_t *);
91*7c478bd9Sstevel@tonic-gate extern zoneid_t crgetzoneid(const cred_t *);
92*7c478bd9Sstevel@tonic-gate extern projid_t crgetprojid(const cred_t *);
93*7c478bd9Sstevel@tonic-gate 
94*7c478bd9Sstevel@tonic-gate extern const struct auditinfo_addr *crgetauinfo(const cred_t *);
95*7c478bd9Sstevel@tonic-gate extern struct auditinfo_addr *crgetauinfo_modifiable(cred_t *);
96*7c478bd9Sstevel@tonic-gate 
97*7c478bd9Sstevel@tonic-gate extern uint_t crgetref(const cred_t *);
98*7c478bd9Sstevel@tonic-gate 
99*7c478bd9Sstevel@tonic-gate extern const gid_t *crgetgroups(const cred_t *);
100*7c478bd9Sstevel@tonic-gate 
101*7c478bd9Sstevel@tonic-gate extern int crgetngroups(const cred_t *);
102*7c478bd9Sstevel@tonic-gate 
103*7c478bd9Sstevel@tonic-gate /*
104*7c478bd9Sstevel@tonic-gate  * Sets real, effective and/or saved uid/gid;
105*7c478bd9Sstevel@tonic-gate  * -1 argument accepted as "no change".
106*7c478bd9Sstevel@tonic-gate  */
107*7c478bd9Sstevel@tonic-gate extern int crsetresuid(cred_t *, uid_t, uid_t, uid_t);
108*7c478bd9Sstevel@tonic-gate extern int crsetresgid(cred_t *, gid_t, gid_t, gid_t);
109*7c478bd9Sstevel@tonic-gate 
110*7c478bd9Sstevel@tonic-gate /*
111*7c478bd9Sstevel@tonic-gate  * Sets real, effective and saved uids/gids all to the same
112*7c478bd9Sstevel@tonic-gate  * values.  Both values must be non-negative and <= MAXUID
113*7c478bd9Sstevel@tonic-gate  */
114*7c478bd9Sstevel@tonic-gate extern int crsetugid(cred_t *, uid_t, gid_t);
115*7c478bd9Sstevel@tonic-gate 
116*7c478bd9Sstevel@tonic-gate extern int crsetgroups(cred_t *, int, gid_t *);
117*7c478bd9Sstevel@tonic-gate 
118*7c478bd9Sstevel@tonic-gate /*
119*7c478bd9Sstevel@tonic-gate  * Private interface for setting zone association of credential.
120*7c478bd9Sstevel@tonic-gate  */
121*7c478bd9Sstevel@tonic-gate struct zone;
122*7c478bd9Sstevel@tonic-gate extern void crsetzone(cred_t *, struct zone *);
123*7c478bd9Sstevel@tonic-gate 
124*7c478bd9Sstevel@tonic-gate /*
125*7c478bd9Sstevel@tonic-gate  * Private interface for setting project id in credential.
126*7c478bd9Sstevel@tonic-gate  */
127*7c478bd9Sstevel@tonic-gate extern void crsetprojid(cred_t *, projid_t);
128*7c478bd9Sstevel@tonic-gate 
129*7c478bd9Sstevel@tonic-gate /*
130*7c478bd9Sstevel@tonic-gate  * Private interface for nfs.
131*7c478bd9Sstevel@tonic-gate  */
132*7c478bd9Sstevel@tonic-gate extern cred_t *crnetadjust(cred_t *);
133*7c478bd9Sstevel@tonic-gate 
134*7c478bd9Sstevel@tonic-gate /*
135*7c478bd9Sstevel@tonic-gate  * Private interface for procfs.
136*7c478bd9Sstevel@tonic-gate  */
137*7c478bd9Sstevel@tonic-gate extern void cred2prcred(const cred_t *, struct prcred *);
138*7c478bd9Sstevel@tonic-gate 
139*7c478bd9Sstevel@tonic-gate #endif	/* _KERNEL */
140*7c478bd9Sstevel@tonic-gate 
141*7c478bd9Sstevel@tonic-gate #ifdef	__cplusplus
142*7c478bd9Sstevel@tonic-gate }
143*7c478bd9Sstevel@tonic-gate #endif
144*7c478bd9Sstevel@tonic-gate 
145*7c478bd9Sstevel@tonic-gate #endif	/* _SYS_CRED_H */
146