2
* Copyright (c) 2003-2008 Novell, Inc. (All rights reserved)
3
* Copyright 2009-2010 Canonical Ltd.
5
* The libapparmor library is licensed under the terms of the GNU
6
* Lesser General Public License, version 2.1. Please see the file
9
* This library is distributed in the hope that it will be useful,
10
* but WITHOUT ANY WARRANTY; without even the implied warranty of
11
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12
* GNU Lesser General Public License for more details.
14
* You should have received a copy of the GNU Lesser General Public License
15
* along with this program. If not, see <http://www.gnu.org/licenses/>.
18
#ifndef _SYS_APPARMOR_H_
19
#define _SYS_APPARMOR_H 1
22
#include <sys/types.h>
27
* Class of mediation types in the AppArmor policy db
29
#define AA_CLASS_COND 0
30
#define AA_CLASS_UNKNOWN 1
31
#define AA_CLASS_FILE 2
32
#define AA_CLASS_CAP 3
33
#define AA_CLASS_NET 4
34
#define AA_CLASS_RLIMITS 5
35
#define AA_CLASS_DOMAIN 6
36
#define AA_CLASS_MOUNT 7
37
#define AA_CLASS_NS_DOMAIN 8
38
#define AA_CLASS_PTRACE 9
40
#define AA_CLASS_ENV 16
42
#define AA_CLASS_DBUS 32
46
/* Permission Flags for Mediation classes */
47
#define AA_MAY_WRITE (1 << 1)
48
#define AA_MAY_READ (1 << 2)
49
#define AA_MAY_BIND (1 << 6)
51
#define AA_DBUS_SEND AA_MAY_WRITE
52
#define AA_DBUS_RECEIVE AA_MAY_READ
53
#define AA_DBUS_BIND AA_MAY_BIND
56
/* Prototypes for apparmor state queries */
57
extern int aa_is_enabled(void);
58
extern int aa_find_mountpoint(char **mnt);
60
/* Prototypes for self directed domain transitions
61
* see <http://apparmor.net>
62
* Please see the change_hat(2) manpage for information.
65
#define change_hat(X, Y) aa_change_hat((X), (Y))
66
extern int (change_hat)(const char *subprofile, unsigned int magic_token);
67
extern int aa_change_hat(const char *subprofile, unsigned long magic_token);
68
extern int aa_change_profile(const char *profile);
69
extern int aa_change_onexec(const char *profile);
71
extern int aa_change_hatv(const char *subprofiles[], unsigned long token);
72
extern int (aa_change_hat_vargs)(unsigned long token, int count, ...);
74
/* Protypes for introspecting task confinement
75
* Please see the aa_getcon(2) manpage for information
77
extern int aa_getprocattr_raw(pid_t tid, const char *attr, char *buf, int len,
79
extern int aa_getprocattr(pid_t tid, const char *attr, char **buf, char **mode);
80
extern int aa_gettaskcon(pid_t target, char **con, char **mode);
81
extern int aa_getcon(char **con, char **mode);
82
extern int aa_getpeercon_raw(int fd, char *buf, int *len, char **mode);
83
extern int aa_getpeercon(int fd, char **con, char **mode);
85
/* A NUL character is used to separate the query command prefix string from the
86
* rest of the query string. The query command sizes intentionally include the
87
* NUL-terminator in their values.
89
#define AA_QUERY_CMD_LABEL "label"
90
#define AA_QUERY_CMD_LABEL_SIZE sizeof(AA_QUERY_CMD_LABEL)
92
extern int aa_query_label(uint32_t mask, char *query, size_t size, int *allow,
95
#define __macroarg_counter(Y...) __macroarg_count1 ( , ##Y)
96
#define __macroarg_count1(Y...) __macroarg_count2 (Y, 16,15,14,13,12,11,10,9,8,7,6,5,4,3,2,1,0)
97
#define __macroarg_count2(_,x0,x1,x2,x3,x4,x5,x6,x7,x8,x9,x10,x11,x12,x13,x14,x15,n,Y...) n
100
* change_hat_vargs - a wrapper macro for change_hat_vargs
101
* @T: the magic token
102
* @X...: the parameter list of hats being passed
104
* The change_hat_vargs macro makes it so the caller doesn't have to
105
* specify the number of hats passed as parameters to the change_hat_vargs
109
* change_hat_vargs(10, hat1, hat2, hat3, hat4);
111
* (change_hat_vargs)(10, 4, hat1, hat2, hat3, hat4);
113
* to call change_hat_vargs direction do
114
* (change_hat_vargs)(token, nhats, hat1, hat2...)
116
#define aa_change_hat_vargs(T, X...) \
117
(aa_change_hat_vargs)(T, __macroarg_counter(X), X)
121
#endif /* sys/apparmor.h */