xref: /dragonfly/sys/sys/jail.h (revision 5e83d98b)
1 /*
2  * ----------------------------------------------------------------------------
3  * "THE BEER-WARE LICENSE" (Revision 42):
4  * <phk@FreeBSD.org> wrote this file.  As long as you retain this notice you
5  * can do whatever you want with this stuff. If we meet some day, and you think
6  * this stuff is worth it, you can buy me a beer in return.   Poul-Henning Kamp
7  * ----------------------------------------------------------------------------
8  *
9  * $FreeBSD: src/sys/sys/jail.h,v 1.8.2.2 2000/11/01 17:58:06 rwatson Exp $
10  */
11 
12 #ifndef _SYS_JAIL_H_
13 #define _SYS_JAIL_H_
14 
15 #ifndef _SYS_TYPES_H_
16 #include <sys/types.h>
17 #endif
18 #ifndef _SYS_PARAM_H_
19 #include <sys/param.h>
20 #endif
21 #ifndef _SYS_QUEUE_H_
22 #include <sys/queue.h>
23 #endif
24 #ifndef _SYS_UCRED_H_
25 #include <sys/ucred.h>
26 #endif
27 #ifndef _NET_IF_H_
28 #include <net/if.h>
29 #endif
30 
31 struct jail {
32 	uint32_t	version;
33 	char		*path;
34 	char		*hostname;
35 	uint32_t	n_ips;     /* Number of ips */
36 	struct sockaddr_storage *ips;
37 };
38 
39 struct jail_v0 {
40 	uint32_t	version;
41 	char		*path;
42 	char		*hostname;
43 	uint32_t	ip_number;
44 };
45 
46 #ifndef _KERNEL
47 
48 int jail(struct jail *);
49 int jail_attach(int);
50 
51 #endif
52 
53 #ifdef _KERNEL
54 
55 #ifndef _SYS_NAMECACHE_H_
56 #include <sys/namecache.h>
57 #endif
58 #ifndef _SYS_VARSYM_H_
59 #include <sys/varsym.h>
60 #endif
61 
62 #ifdef MALLOC_DECLARE
63 MALLOC_DECLARE(M_PRISON);
64 #endif
65 
66 #endif	/* _KERNEL */
67 
68 #if defined(_KERNEL) || defined(_KERNEL_STRUCTURES)
69 
70 #define	JAIL_MAX	999999
71 
72 /* Used to store the IPs of the jail */
73 
74 struct jail_ip_storage {
75 	struct sockaddr_storage ip;
76 	SLIST_ENTRY(jail_ip_storage) entries;
77 };
78 
79 /*
80  * This structure describes a prison.  It is pointed to by all struct
81  * ucred's of the inmates.  pr_ref keeps track of them and is used to
82  * delete the struture when the last inmate is dead.
83  */
84 struct sysctl_ctx_list;
85 struct sysctl_oid;
86 
87 struct prison {
88 	LIST_ENTRY(prison) pr_list;			/* all prisons */
89 	int		pr_id;				/* prison id */
90 	int		pr_ref;				/* reference count */
91 	struct nchandle pr_root;			/* namecache entry of root */
92 	char 		pr_host[MAXHOSTNAMELEN];	/* host name */
93 	SLIST_HEAD(iplist, jail_ip_storage) pr_ips;	/* list of IP addresses */
94 	struct sockaddr_in	*local_ip4;		/* cache for a loopback ipv4 address */
95 	struct sockaddr_in	*nonlocal_ip4;		/* cache for a non loopback ipv4 address */
96 	struct sockaddr_in6	*local_ip6;		/* cache for a loopback ipv6 address */
97 	struct sockaddr_in6	*nonlocal_ip6;		/* cache for a non loopback ipv6 address */
98 	void		*pr_linux;			/* Linux ABI emulation */
99 	int		 pr_securelevel;		/* jail securelevel */
100 	struct varsymset pr_varsymset;			/* jail varsyms */
101 
102 	struct sysctl_ctx_list *pr_sysctl_ctx;
103 	struct sysctl_oid *pr_sysctl_tree;
104 
105 	int8_t		pr_set_hostname_allowed;
106 	int8_t		pr_socket_unixiproute_only;
107 	int8_t		pr_sysvipc_allowed;
108 	int8_t		pr_chflags_allowed;
109 	int8_t		pr_allow_raw_sockets;
110 };
111 
112 /*
113  * Sysctl-set variables that determine global jail policy
114  */
115 extern int	jail_set_hostname_allowed;
116 extern int	jail_socket_unixiproute_only;
117 extern int	jail_sysvipc_allowed;
118 extern int	jail_chflags_allowed;
119 extern int	jail_allow_raw_sockets;
120 
121 /*
122  * Kernel support functions for jail.
123  */
124 int	jailed_ip(struct prison *, struct sockaddr *);
125 void	prison_free(struct prison *);
126 void	prison_hold(struct prison *);
127 int	prison_if(struct ucred *cred, struct sockaddr *sa);
128 struct sockaddr *
129 	prison_get_local(struct prison *pr, sa_family_t, struct sockaddr *);
130 struct sockaddr *
131 	prison_get_nonlocal(struct prison *pr, sa_family_t, struct sockaddr *);
132 int	prison_priv_check(struct ucred *cred, int priv);
133 int	prison_remote_ip(struct thread *td, struct sockaddr *ip);
134 int	prison_replace_wildcards(struct thread *td, struct sockaddr *ip);
135 int	prison_sysctl_create(struct prison *);
136 int	prison_sysctl_done(struct prison *);
137 
138 /*
139  * Return 1 if the passed credential is in a jail, otherwise 0.
140  *
141  * MPSAFE
142  */
143 static __inline int
144 jailed(struct ucred *cred)
145 {
146 	return(cred->cr_prison != NULL);
147 }
148 
149 #endif /* _KERNEL || _KERNEL_STRUCTURES */
150 #endif /* !_SYS_JAIL_H_ */
151