The Design and Implementation of the FreeBSD Operating System, Second Edition
Now available: The Design and Implementation of the FreeBSD Operating System (Second Edition)


[ source navigation ] [ diff markup ] [ identifier search ] [ freetext search ] [ file search ] [ list types ] [ track identifier ]

FreeBSD/Linux Kernel Cross Reference
sys/security/mac.h

Version: -  FREEBSD  -  FREEBSD-13-STABLE  -  FREEBSD-13-0  -  FREEBSD-12-STABLE  -  FREEBSD-12-0  -  FREEBSD-11-STABLE  -  FREEBSD-11-0  -  FREEBSD-10-STABLE  -  FREEBSD-10-0  -  FREEBSD-9-STABLE  -  FREEBSD-9-0  -  FREEBSD-8-STABLE  -  FREEBSD-8-0  -  FREEBSD-7-STABLE  -  FREEBSD-7-0  -  FREEBSD-6-STABLE  -  FREEBSD-6-0  -  FREEBSD-5-STABLE  -  FREEBSD-5-0  -  FREEBSD-4-STABLE  -  FREEBSD-3-STABLE  -  FREEBSD22  -  l41  -  OPENBSD  -  linux-2.6  -  MK84  -  PLAN9  -  xnu-8792 
SearchContext: -  none  -  3  -  10 

    1 /*
    2  * Copyright (c) 2007 Apple Inc. All rights reserved.
    3  *
    4  * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
    5  * 
    6  * This file contains Original Code and/or Modifications of Original Code
    7  * as defined in and that are subject to the Apple Public Source License
    8  * Version 2.0 (the 'License'). You may not use this file except in
    9  * compliance with the License. The rights granted to you under the License
   10  * may not be used to create, or enable the creation or redistribution of,
   11  * unlawful or unlicensed copies of an Apple operating system, or to
   12  * circumvent, violate, or enable the circumvention or violation of, any
   13  * terms of an Apple operating system software license agreement.
   14  * 
   15  * Please obtain a copy of the License at
   16  * http://www.opensource.apple.com/apsl/ and read it before using this file.
   17  * 
   18  * The Original Code and all software distributed under the License are
   19  * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
   20  * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
   21  * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
   22  * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
   23  * Please see the License for the specific language governing rights and
   24  * limitations under the License.
   25  * 
   26  * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
   27  */
   28 /*-
   29  * Copyright (c) 1999-2002 Robert N. M. Watson
   30  * Copyright (c) 2001-2005 Networks Associates Technology, Inc.
   31  * Copyright (c) 2005-2006 SPARTA, Inc.
   32  * All rights reserved.
   33  *
   34  * This software was developed by Robert Watson for the TrustedBSD Project.
   35  *
   36  * This software was developed for the FreeBSD Project in part by Network
   37  * Associates Laboratories, the Security Research Division of Network
   38  * Associates, Inc. under DARPA/SPAWAR contract N66001-01-C-8035 ("CBOSS"),
   39  * as part of the DARPA CHATS research program.
   40  *
   41  * This software was enhanced by SPARTA ISSO under SPAWAR contract
   42  * N66001-04-C-6019 ("SEFOS").
   43  *
   44  * Redistribution and use in source and binary forms, with or without
   45  * modification, are permitted provided that the following conditions
   46  * are met:
   47  * 1. Redistributions of source code must retain the above copyright
   48  *    notice, this list of conditions and the following disclaimer.
   49  * 2. Redistributions in binary form must reproduce the above copyright
   50  *    notice, this list of conditions and the following disclaimer in the
   51  *    documentation and/or other materials provided with the distribution.
   52  *
   53  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
   54  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
   55  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
   56  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
   57  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
   58  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
   59  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
   60  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
   61  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
   62  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
   63  * SUCH DAMAGE.
   64  *
   65  * $FreeBSD: src/sys/sys/mac.h,v 1.40 2003/04/18 19:57:37 rwatson Exp $
   66  */
   67 /*
   68  * Userland interface for Mandatory Access Control.
   69  *
   70  * The POSIX.1e implementation page may be reached at:
   71  * http://www.trustedbsd.org/
   72  */
   73 
   74 #ifndef _SECURITY_MAC_H_
   75 #define _SECURITY_MAC_H_
   76 
   77 #ifndef _POSIX_MAC
   78 #define _POSIX_MAC
   79 #endif
   80 
   81 #include <sys/types.h>
   82 
   83 /*
   84  * MAC framework-related constants and limits.
   85  */
   86 #define MAC_MAX_POLICY_NAME             32
   87 #define MAC_MAX_LABEL_ELEMENT_NAME      32
   88 #define MAC_MAX_LABEL_ELEMENT_DATA      4096
   89 #define MAC_MAX_LABEL_BUF_LEN           8192
   90 #define MAC_MAX_MANAGED_NAMESPACES      4
   91 
   92 struct mac {
   93         size_t           m_buflen;
   94         char            *m_string;
   95 };
   96 
   97 typedef struct mac      *mac_t;
   98 
   99 #ifdef KERNEL
  100 struct user_mac {
  101         user_size_t     m_buflen;
  102         user_addr_t     m_string;
  103 };
  104 
  105 struct user32_mac {
  106         uint32_t        m_buflen;
  107         uint32_t        m_string;
  108 };
  109 
  110 struct user64_mac {
  111         uint64_t        m_buflen;
  112         uint64_t        m_string;
  113 };
  114 #endif /* KERNEL */
  115 
  116 /*
  117  * Flags to control which MAC subsystems are enforced
  118  * on a per-process/thread/credential basis.
  119  */
  120 #define MAC_SYSTEM_ENFORCE      0x0001  /* system management */
  121 #define MAC_PROC_ENFORCE        0x0002  /* process management */
  122 #define MAC_MACH_ENFORCE        0x0004  /* mach interfaces */
  123 #define MAC_VM_ENFORCE          0x0008  /* VM interfaces */
  124 #define MAC_FILE_ENFORCE        0x0010  /* file operations */
  125 #define MAC_SOCKET_ENFORCE      0x0020  /* socket operations */
  126 #define MAC_PIPE_ENFORCE        0x0040  /* pipes */
  127 #define MAC_VNODE_ENFORCE       0x0080  /* vnode operations */
  128 #define MAC_NET_ENFORCE         0x0100  /* network management */
  129 #define MAC_MBUF_ENFORCE        0x0200  /* network traffic */
  130 #define MAC_POSIXSEM_ENFORCE    0x0400  /* posix semaphores */
  131 #define MAC_POSIXSHM_ENFORCE    0x0800  /* posix shared memory */
  132 #define MAC_SYSVMSG_ENFORCE     0x1000  /* SysV message queues */
  133 #define MAC_SYSVSEM_ENFORCE     0x2000  /* SysV semaphores */
  134 #define MAC_SYSVSHM_ENFORCE     0x4000  /* SysV shared memory */
  135 #define MAC_ALL_ENFORCE         0x7fff  /* enforce everything */
  136 
  137 /*
  138  * Device types for mac_iokit_check_device()
  139  */
  140 #define MAC_DEVICE_USB          "USB"
  141 #define MAC_DEVICE_FIREWIRE     "FireWire"
  142 #define MAC_DEVICE_TYPE_KEY     "DeviceType"
  143 
  144 /*
  145  * Flags for mac_proc_check_suspend_resume()
  146  */
  147 #define MAC_PROC_CHECK_SUSPEND                  0
  148 #define MAC_PROC_CHECK_RESUME                   1
  149 #define MAC_PROC_CHECK_HIBERNATE                2
  150 #define MAC_PROC_CHECK_SHUTDOWN_SOCKETS 3
  151 
  152 #ifndef KERNEL
  153 /*
  154  * Location of the userland MAC framework configuration file.  mac.conf
  155  * binds policy names to shared libraries that understand those policies,
  156  * as well as setting defaults for MAC-aware applications.
  157  */
  158 #define MAC_CONFFILE    "/etc/mac.conf"
  159 
  160 /*
  161  * Extended non-POSIX.1e interfaces that offer additional services
  162  * available from the userland and kernel MAC frameworks.
  163  */
  164 #ifdef __APPLE_API_PRIVATE
  165 __BEGIN_DECLS
  166 int      __mac_execve(char *fname, char **argv, char **envv, mac_t _label);
  167 int      __mac_get_fd(int _fd, mac_t _label);
  168 int      __mac_get_file(const char *_path, mac_t _label);
  169 int      __mac_get_lcid(pid_t _lcid, mac_t _label);
  170 int      __mac_get_lctx(mac_t _label);
  171 int      __mac_get_link(const char *_path, mac_t _label);
  172 int      __mac_get_pid(pid_t _pid, mac_t _label);
  173 int      __mac_get_proc(mac_t _label);
  174 int      __mac_set_fd(int _fildes, const mac_t _label);
  175 int      __mac_set_file(const char *_path, mac_t _label);
  176 int      __mac_set_lctx(mac_t _label);
  177 int      __mac_set_link(const char *_path, mac_t _label);
  178 int      __mac_mount(const char *type, const char *path, int flags, void *data,
  179     struct mac *label);
  180 int      __mac_get_mount(const char *path, struct mac *label);
  181 int      __mac_set_proc(const mac_t _label);
  182 int      __mac_syscall(const char *_policyname, int _call, void *_arg);
  183 __END_DECLS
  184 #endif /*__APPLE_API_PRIVATE*/
  185 
  186 #endif
  187 
  188 #endif /* !_SECURITY_MAC_H_ */

Cache object: bd3ecc975a373408c80006774829bc60


[ source navigation ] [ diff markup ] [ identifier search ] [ freetext search ] [ file search ] [ list types ] [ track identifier ]


This page is part of the FreeBSD/Linux Linux Kernel Cross-Reference, and was automatically generated using a modified version of the LXR engine.