The Design and Implementation of the FreeBSD Operating System, Second Edition
Now available: The Design and Implementation of the FreeBSD Operating System (Second Edition)


[ source navigation ] [ diff markup ] [ identifier search ] [ freetext search ] [ file search ] [ list types ] [ track identifier ]

FreeBSD/Linux Kernel Cross Reference
sys/security/mac_bsdextended/mac_bsdextended.h

Version: -  FREEBSD  -  FREEBSD-13-STABLE  -  FREEBSD-13-0  -  FREEBSD-12-STABLE  -  FREEBSD-12-0  -  FREEBSD-11-STABLE  -  FREEBSD-11-0  -  FREEBSD-10-STABLE  -  FREEBSD-10-0  -  FREEBSD-9-STABLE  -  FREEBSD-9-0  -  FREEBSD-8-STABLE  -  FREEBSD-8-0  -  FREEBSD-7-STABLE  -  FREEBSD-7-0  -  FREEBSD-6-STABLE  -  FREEBSD-6-0  -  FREEBSD-5-STABLE  -  FREEBSD-5-0  -  FREEBSD-4-STABLE  -  FREEBSD-3-STABLE  -  FREEBSD22  -  l41  -  OPENBSD  -  linux-2.6  -  MK84  -  PLAN9  -  xnu-8792 
SearchContext: -  none  -  3  -  10 

    1 /*-
    2  * Copyright (c) 1999-2002 Robert N. M. Watson
    3  * Copyright (c) 2001-2004 Networks Associates Technology, Inc.
    4  * All rights reserved.
    5  *
    6  * This software was developed by Robert Watson for the TrustedBSD Project.
    7  *
    8  * This software was developed for the FreeBSD Project in part by Network
    9  * Associates Laboratories, the Security Research Division of Network
   10  * Associates, Inc. under DARPA/SPAWAR contract N66001-01-C-8035 ("CBOSS"),
   11  * as part of the DARPA CHATS research program.
   12  *
   13  * Redistribution and use in source and binary forms, with or without
   14  * modification, are permitted provided that the following conditions
   15  * are met:
   16  * 1. Redistributions of source code must retain the above copyright
   17  *    notice, this list of conditions and the following disclaimer.
   18  * 2. Redistributions in binary form must reproduce the above copyright
   19  *    notice, this list of conditions and the following disclaimer in the
   20  *    documentation and/or other materials provided with the distribution.
   21  *
   22  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
   23  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
   24  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
   25  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
   26  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
   27  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
   28  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
   29  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
   30  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
   31  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
   32  * SUCH DAMAGE.
   33  *
   34  * $FreeBSD: releng/12.0/sys/security/mac_bsdextended/mac_bsdextended.h 171253 2007-07-05 13:16:04Z rwatson $
   35  */
   36 
   37 #ifndef _SYS_SECURITY_MAC_BSDEXTENDED_H
   38 #define _SYS_SECURITY_MAC_BSDEXTENDED_H
   39 
   40 #define MB_VERSION 2 /* Used to check library and kernel are the same. */
   41 
   42 /*
   43  * Rights that can be represented in mbr_mode.  These have the same values as
   44  * the V* rights in vnode.h, but in order to avoid sharing user and kernel
   45  * constants, we define them here.  That will also improve ABI stability if
   46  * the in-kernel values change.
   47  */
   48 #define MBI_EXEC        000100
   49 #define MBI_WRITE       000200
   50 #define MBI_READ        000400
   51 #define MBI_ADMIN       010000
   52 #define MBI_STAT        020000
   53 #define MBI_APPEND      040000
   54 #define MBI_ALLPERM     (MBI_EXEC | MBI_WRITE | MBI_READ | MBI_ADMIN | \
   55                             MBI_STAT | MBI_APPEND)
   56 
   57 #define MBS_UID_DEFINED 0x00000001      /* uid field should be matched */
   58 #define MBS_GID_DEFINED 0x00000002      /* gid field should be matched */
   59 #define MBS_PRISON_DEFINED 0x00000004   /* prison field should be matched */
   60 
   61 #define MBS_ALL_FLAGS (MBS_UID_DEFINED | MBS_GID_DEFINED | MBS_PRISON_DEFINED)
   62 
   63 struct mac_bsdextended_subject {
   64         int     mbs_flags;
   65         int     mbs_neg;
   66         uid_t   mbs_uid_min;
   67         uid_t   mbs_uid_max;
   68         gid_t   mbs_gid_min;
   69         gid_t   mbs_gid_max;
   70         int     mbs_prison;
   71 };
   72 
   73 #define MBO_UID_DEFINED 0x00000001      /* uid field should be matched */
   74 #define MBO_GID_DEFINED 0x00000002      /* gid field should be matched */
   75 #define MBO_FSID_DEFINED 0x00000004     /* fsid field should be matched */
   76 #define MBO_SUID        0x00000008      /* object must be suid */
   77 #define MBO_SGID        0x00000010      /* object must be sgid */
   78 #define MBO_UID_SUBJECT 0x00000020      /* uid must match subject */
   79 #define MBO_GID_SUBJECT 0x00000040      /* gid must match subject */
   80 #define MBO_TYPE_DEFINED 0x00000080     /* object type should be matched */
   81 
   82 #define MBO_ALL_FLAGS (MBO_UID_DEFINED | MBO_GID_DEFINED | MBO_FSID_DEFINED | \
   83             MBO_SUID | MBO_SGID | MBO_UID_SUBJECT | MBO_GID_SUBJECT | \
   84             MBO_TYPE_DEFINED)
   85 
   86 #define MBO_TYPE_REG    0x00000001
   87 #define MBO_TYPE_DIR    0x00000002
   88 #define MBO_TYPE_BLK    0x00000004
   89 #define MBO_TYPE_CHR    0x00000008
   90 #define MBO_TYPE_LNK    0x00000010
   91 #define MBO_TYPE_SOCK   0x00000020
   92 #define MBO_TYPE_FIFO   0x00000040
   93 
   94 #define MBO_ALL_TYPE    (MBO_TYPE_REG | MBO_TYPE_DIR | MBO_TYPE_BLK | \
   95             MBO_TYPE_CHR | MBO_TYPE_LNK | MBO_TYPE_SOCK | MBO_TYPE_FIFO)
   96 
   97 struct mac_bsdextended_object {
   98         int     mbo_flags;
   99         int     mbo_neg;
  100         uid_t   mbo_uid_min;
  101         uid_t   mbo_uid_max;
  102         gid_t   mbo_gid_min;
  103         gid_t   mbo_gid_max;
  104         struct fsid mbo_fsid;
  105         int     mbo_type;
  106 };
  107 
  108 struct mac_bsdextended_rule {
  109         struct mac_bsdextended_subject  mbr_subject;
  110         struct mac_bsdextended_object   mbr_object;
  111         mode_t                          mbr_mode;       /* maximum access */
  112 };
  113 
  114 #endif /* _SYS_SECURITY_MAC_BSDEXTENDED_H */

Cache object: face6882841444c07f62f022265d531e


[ source navigation ] [ diff markup ] [ identifier search ] [ freetext search ] [ file search ] [ list types ] [ track identifier ]


This page is part of the FreeBSD/Linux Linux Kernel Cross-Reference, and was automatically generated using a modified version of the LXR engine.