4 * The contents of this file are subject to the terms of the
5 * Common Development and Distribution License (the "License").
6 * You may not use this file except in compliance with the License.
8 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
9 * or http://www.opensolaris.org/os/licensing.
10 * See the License for the specific language governing permissions
11 * and limitations under the License.
13 * When distributing Covered Code, include this CDDL HEADER in each
14 * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
15 * If applicable, add the following below this CDDL HEADER, with the
16 * fields enclosed by brackets "[]" replaced with your own identifying
17 * information: Portions Copyright [yyyy] [name of copyright owner]
22 * Copyright 2006 Sun Microsystems, Inc. All rights reserved.
23 * Use is subject to license terms.
26 /* Copyright (c) 1983, 1984, 1985, 1986, 1987, 1988, 1989 AT&T */
27 /* All Rights Reserved */
30 * Portions of this source code were derived from Berkeley 4.3 BSD
31 * under license from the Regents of the University of California.
37 #pragma ident "%Z%%M% %I% %E% SMI"
39 #include <sys/types.h>
46 * The credential is an opaque kernel private data structure defined in
50 typedef struct cred cred_t;
54 #define CRED() curthread->t_cred
56 struct proc; /* cred.h is included in proc.h */
59 struct auditinfo_addr; /* cred.h is included in audit.h */
61 extern int ngroups_max;
63 * kcred is used when you need all privileges.
65 extern struct cred *kcred;
67 extern void cred_init(void);
68 extern void crhold(cred_t *);
69 extern void crfree(cred_t *);
70 extern cred_t *cralloc(void); /* all but ref uninitialized */
71 extern cred_t *crget(void); /* initialized */
72 extern cred_t *crcopy(cred_t *);
73 extern void crcopy_to(cred_t *, cred_t *);
74 extern cred_t *crdup(cred_t *);
75 extern void crdup_to(cred_t *, cred_t *);
76 extern cred_t *crgetcred(void);
77 extern void crset(struct proc *, cred_t *);
78 extern int groupmember(gid_t, const cred_t *);
79 extern int supgroupmember(gid_t, const cred_t *);
80 extern int hasprocperm(const cred_t *, const cred_t *);
81 extern int prochasprocperm(struct proc *, struct proc *, const cred_t *);
82 extern int crcmp(const cred_t *, const cred_t *);
83 extern cred_t *zone_kcred(void);
85 extern uid_t crgetuid(const cred_t *);
86 extern uid_t crgetruid(const cred_t *);
87 extern uid_t crgetsuid(const cred_t *);
88 extern gid_t crgetgid(const cred_t *);
89 extern gid_t crgetrgid(const cred_t *);
90 extern gid_t crgetsgid(const cred_t *);
91 extern zoneid_t crgetzoneid(const cred_t *);
92 extern projid_t crgetprojid(const cred_t *);
95 extern const struct auditinfo_addr *crgetauinfo(const cred_t *);
96 extern struct auditinfo_addr *crgetauinfo_modifiable(cred_t *);
98 extern uint_t crgetref(const cred_t *);
100 extern const gid_t *crgetgroups(const cred_t *);
102 extern int crgetngroups(const cred_t *);
105 * Sets real, effective and/or saved uid/gid;
106 * -1 argument accepted as "no change".
108 extern int crsetresuid(cred_t *, uid_t, uid_t, uid_t);
109 extern int crsetresgid(cred_t *, gid_t, gid_t, gid_t);
112 * Sets real, effective and saved uids/gids all to the same
113 * values. Both values must be non-negative and <= MAXUID
115 extern int crsetugid(cred_t *, uid_t, gid_t);
117 extern int crsetgroups(cred_t *, int, gid_t *);
120 * Private interface for setting zone association of credential.
123 extern void crsetzone(cred_t *, struct zone *);
124 extern struct zone *crgetzone(const cred_t *);
127 * Private interface for setting project id in credential.
129 extern void crsetprojid(cred_t *, projid_t);
132 * Private interface for nfs.
134 extern cred_t *crnetadjust(cred_t *);
137 * Private interface for procfs.
139 extern void cred2prcred(const cred_t *, struct prcred *);
142 * Private interfaces for Rampart Trusted Solaris.
145 extern struct ts_label_s *crgetlabel(const cred_t *);
146 extern boolean_t crisremote(const cred_t *);
154 #endif /* _SYS_CRED_H */