adt.h revision 2
843e19887f64dde75055cf8842fc4db2171eff45johnlev/*
843e19887f64dde75055cf8842fc4db2171eff45johnlev * CDDL HEADER START
843e19887f64dde75055cf8842fc4db2171eff45johnlev *
843e19887f64dde75055cf8842fc4db2171eff45johnlev * The contents of this file are subject to the terms of the
843e19887f64dde75055cf8842fc4db2171eff45johnlev * Common Development and Distribution License (the "License").
843e19887f64dde75055cf8842fc4db2171eff45johnlev * You may not use this file except in compliance with the License.
843e19887f64dde75055cf8842fc4db2171eff45johnlev *
843e19887f64dde75055cf8842fc4db2171eff45johnlev * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
843e19887f64dde75055cf8842fc4db2171eff45johnlev * or http://www.opensolaris.org/os/licensing.
843e19887f64dde75055cf8842fc4db2171eff45johnlev * See the License for the specific language governing permissions
843e19887f64dde75055cf8842fc4db2171eff45johnlev * and limitations under the License.
843e19887f64dde75055cf8842fc4db2171eff45johnlev *
843e19887f64dde75055cf8842fc4db2171eff45johnlev * When distributing Covered Code, include this CDDL HEADER in each
843e19887f64dde75055cf8842fc4db2171eff45johnlev * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
843e19887f64dde75055cf8842fc4db2171eff45johnlev * If applicable, add the following below this CDDL HEADER, with the
843e19887f64dde75055cf8842fc4db2171eff45johnlev * fields enclosed by brackets "[]" replaced with your own identifying
843e19887f64dde75055cf8842fc4db2171eff45johnlev * information: Portions Copyright [yyyy] [name of copyright owner]
843e19887f64dde75055cf8842fc4db2171eff45johnlev *
843e19887f64dde75055cf8842fc4db2171eff45johnlev * CDDL HEADER END
843e19887f64dde75055cf8842fc4db2171eff45johnlev */
843e19887f64dde75055cf8842fc4db2171eff45johnlev/*
843e19887f64dde75055cf8842fc4db2171eff45johnlev * adt.h
843e19887f64dde75055cf8842fc4db2171eff45johnlev *
843e19887f64dde75055cf8842fc4db2171eff45johnlev * Copyright (c) 2001, 2011, Oracle and/or its affiliates. All rights reserved.
843e19887f64dde75055cf8842fc4db2171eff45johnlev *
843e19887f64dde75055cf8842fc4db2171eff45johnlev * This is a contract private interface and is subject to change
843e19887f64dde75055cf8842fc4db2171eff45johnlev */
843e19887f64dde75055cf8842fc4db2171eff45johnlev
843e19887f64dde75055cf8842fc4db2171eff45johnlev#ifndef _ADT_H
843e19887f64dde75055cf8842fc4db2171eff45johnlev#define _ADT_H
843e19887f64dde75055cf8842fc4db2171eff45johnlev
843e19887f64dde75055cf8842fc4db2171eff45johnlev#include <bsm/audit.h>
843e19887f64dde75055cf8842fc4db2171eff45johnlev#include <bsm/libbsm.h>
843e19887f64dde75055cf8842fc4db2171eff45johnlev#include <bsm/audit_record.h>
843e19887f64dde75055cf8842fc4db2171eff45johnlev#include <bsm/audit_uevents.h>
843e19887f64dde75055cf8842fc4db2171eff45johnlev#include <door.h>
843e19887f64dde75055cf8842fc4db2171eff45johnlev
843e19887f64dde75055cf8842fc4db2171eff45johnlev#ifdef __cplusplus
843e19887f64dde75055cf8842fc4db2171eff45johnlevextern "C" {
843e19887f64dde75055cf8842fc4db2171eff45johnlev#endif
843e19887f64dde75055cf8842fc4db2171eff45johnlev
843e19887f64dde75055cf8842fc4db2171eff45johnlev#define ADT_STRING_MAX 511 /* max non-null characters */
843e19887f64dde75055cf8842fc4db2171eff45johnlev#define ADT_NO_ATTRIB (uid_t)-1 /* unattributed user */
843e19887f64dde75055cf8842fc4db2171eff45johnlev#define ADT_NO_CHANGE (uid_t)-2 /* no update for this parameter */
843e19887f64dde75055cf8842fc4db2171eff45johnlev#define ADT_NO_AUDIT (uid_t)-3 /* unaudited user */
843e19887f64dde75055cf8842fc4db2171eff45johnlev
843e19887f64dde75055cf8842fc4db2171eff45johnlev/*
843e19887f64dde75055cf8842fc4db2171eff45johnlev * terminal id types
843e19887f64dde75055cf8842fc4db2171eff45johnlev */
843e19887f64dde75055cf8842fc4db2171eff45johnlev#define ADT_IPv4 1
843e19887f64dde75055cf8842fc4db2171eff45johnlev#define ADT_IPv6 2
843e19887f64dde75055cf8842fc4db2171eff45johnlev
843e19887f64dde75055cf8842fc4db2171eff45johnlev/*
843e19887f64dde75055cf8842fc4db2171eff45johnlev * for adt_set_user(): ADT_NEW if creating a session for a newly
843e19887f64dde75055cf8842fc4db2171eff45johnlev * authenticated user -- login -- and ADT_UPDATE if an authenticated
843e19887f64dde75055cf8842fc4db2171eff45johnlev * user is changing uid/gid -- e.g., su. ADT_USER changes only the
843e19887f64dde75055cf8842fc4db2171eff45johnlev * ruid / euid / rgid / egid values and is appropriate for login-like
843e19887f64dde75055cf8842fc4db2171eff45johnlev * operations where PAM has already set the audit context in the cred.
843e19887f64dde75055cf8842fc4db2171eff45johnlev * ADT_SETTID is for the special case where it is necessary to store
843e19887f64dde75055cf8842fc4db2171eff45johnlev * the terminal id in the credential before forking to the login or
843e19887f64dde75055cf8842fc4db2171eff45johnlev * login-like process.
843e19887f64dde75055cf8842fc4db2171eff45johnlev */
843e19887f64dde75055cf8842fc4db2171eff45johnlevenum adt_user_context {ADT_NEW, ADT_UPDATE, ADT_USER, ADT_SETTID};
843e19887f64dde75055cf8842fc4db2171eff45johnlev
843e19887f64dde75055cf8842fc4db2171eff45johnlevtypedef ulong_t adt_session_flags_t;
843e19887f64dde75055cf8842fc4db2171eff45johnlevtypedef struct adt_session_data adt_session_data_t;
843e19887f64dde75055cf8842fc4db2171eff45johnlevtypedef struct adt_export_data adt_export_data_t;
843e19887f64dde75055cf8842fc4db2171eff45johnlevtypedef union adt_event_data adt_event_data_t;
843e19887f64dde75055cf8842fc4db2171eff45johnlevtypedef struct adt_termid adt_termid_t;
843e19887f64dde75055cf8842fc4db2171eff45johnlevtypedef struct translation adt_translation_t;
843e19887f64dde75055cf8842fc4db2171eff45johnlevtypedef struct stat64 adt_stat_t;
843e19887f64dde75055cf8842fc4db2171eff45johnlev
843e19887f64dde75055cf8842fc4db2171eff45johnlev/*
843e19887f64dde75055cf8842fc4db2171eff45johnlev * flag defs for the flags argument of adt_start_session()
843e19887f64dde75055cf8842fc4db2171eff45johnlev */
843e19887f64dde75055cf8842fc4db2171eff45johnlev
843e19887f64dde75055cf8842fc4db2171eff45johnlev#define ADT_BUFFER_RECORDS 0x2 /* server buffering */
843e19887f64dde75055cf8842fc4db2171eff45johnlev#define ADT_USE_PROC_DATA 0x1 /* copy audit char's from proc */
843e19887f64dde75055cf8842fc4db2171eff45johnlev /* | all of above = ADT_FLAGS_ALL */
843e19887f64dde75055cf8842fc4db2171eff45johnlev#define ADT_FLAGS_ALL ADT_BUFFER_RECORDS | \
843e19887f64dde75055cf8842fc4db2171eff45johnlev ADT_USE_PROC_DATA
843e19887f64dde75055cf8842fc4db2171eff45johnlev
843e19887f64dde75055cf8842fc4db2171eff45johnlev/*
843e19887f64dde75055cf8842fc4db2171eff45johnlev * Functions
843e19887f64dde75055cf8842fc4db2171eff45johnlev */
843e19887f64dde75055cf8842fc4db2171eff45johnlev
843e19887f64dde75055cf8842fc4db2171eff45johnlevextern int adt_start_session(adt_session_data_t **,
843e19887f64dde75055cf8842fc4db2171eff45johnlev const adt_export_data_t *,
843e19887f64dde75055cf8842fc4db2171eff45johnlev adt_session_flags_t);
843e19887f64dde75055cf8842fc4db2171eff45johnlevextern int adt_end_session(adt_session_data_t *);
843e19887f64dde75055cf8842fc4db2171eff45johnlevextern int adt_dup_session(const adt_session_data_t *,
843e19887f64dde75055cf8842fc4db2171eff45johnlev adt_session_data_t **);
extern int adt_set_proc(const adt_session_data_t *);
extern int adt_set_user(const adt_session_data_t *, uid_t, gid_t,
uid_t, gid_t, const adt_termid_t *,
enum adt_user_context);
extern int adt_set_from_ucred(const adt_session_data_t *,
const ucred_t *,
enum adt_user_context);
extern size_t adt_get_session_id(const adt_session_data_t *, char **);
extern size_t adt_export_session_data(const adt_session_data_t *,
adt_export_data_t **);
extern adt_event_data_t
*adt_alloc_event(const adt_session_data_t *, au_event_t);
extern int adt_put_event(const adt_event_data_t *, int, int);
extern void adt_free_event(adt_event_data_t *);
extern int adt_load_termid(int, adt_termid_t **);
extern int adt_load_hostname(const char *, adt_termid_t **);
extern int adt_load_ttyname(const char *, adt_termid_t **);
extern boolean_t adt_audit_state(int);
/*
* Special typedefs for translations.
*/
typedef int fd_t; /* file descriptor */
#ifdef __cplusplus
}
#endif
#endif /* _ADT_H */