xref: /freebsd/lib/libc/posix1e/acl_set.c (revision ae1add4e)
1515d7c92SRobert Watson /*-
26394f703SRobert Watson  * Copyright (c) 1999, 2000, 2001, 2002 Robert N. M. Watson
3515d7c92SRobert Watson  * All rights reserved.
4515d7c92SRobert Watson  *
56394f703SRobert Watson  * This software was developed by Robert Watson for the TrustedBSD Project.
66394f703SRobert Watson  *
7515d7c92SRobert Watson  * Redistribution and use in source and binary forms, with or without
8515d7c92SRobert Watson  * modification, are permitted provided that the following conditions
9515d7c92SRobert Watson  * are met:
10515d7c92SRobert Watson  * 1. Redistributions of source code must retain the above copyright
11515d7c92SRobert Watson  *    notice, this list of conditions and the following disclaimer.
12515d7c92SRobert Watson  * 2. Redistributions in binary form must reproduce the above copyright
13515d7c92SRobert Watson  *    notice, this list of conditions and the following disclaimer in the
14515d7c92SRobert Watson  *    documentation and/or other materials provided with the distribution.
15515d7c92SRobert Watson  *
16515d7c92SRobert Watson  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17515d7c92SRobert Watson  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18515d7c92SRobert Watson  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19515d7c92SRobert Watson  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20515d7c92SRobert Watson  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21515d7c92SRobert Watson  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22515d7c92SRobert Watson  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23515d7c92SRobert Watson  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24515d7c92SRobert Watson  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25515d7c92SRobert Watson  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26515d7c92SRobert Watson  * SUCH DAMAGE.
27515d7c92SRobert Watson  */
28515d7c92SRobert Watson /*
29515d7c92SRobert Watson  * acl_set_file -- set a file/directory ACL by name
30515d7c92SRobert Watson  */
31515d7c92SRobert Watson 
32333fc21eSDavid E. O'Brien #include <sys/cdefs.h>
33333fc21eSDavid E. O'Brien __FBSDID("$FreeBSD$");
34333fc21eSDavid E. O'Brien 
35515d7c92SRobert Watson #include <sys/types.h>
367bd44e92SThomas Moestl #include "namespace.h"
37515d7c92SRobert Watson #include <sys/acl.h>
387bd44e92SThomas Moestl #include "un-namespace.h"
394bf60dfaSChris D. Faulhaber 
40515d7c92SRobert Watson #include <errno.h>
414bf60dfaSChris D. Faulhaber #include <stdlib.h>
424bf60dfaSChris D. Faulhaber #include <string.h>
43515d7c92SRobert Watson 
44515d7c92SRobert Watson #include "acl_support.h"
45515d7c92SRobert Watson 
46515d7c92SRobert Watson /*
47515d7c92SRobert Watson  * For POSIX.1e-semantic ACLs, do a presort so the kernel doesn't have to
48515d7c92SRobert Watson  * (the POSIX.1e semantic code will reject unsorted ACL submission).  If it's
49515d7c92SRobert Watson  * not a semantic that the library knows about, just submit it flat and
50515d7c92SRobert Watson  * assume the caller knows what they're up to.
51515d7c92SRobert Watson  */
52515d7c92SRobert Watson int
53515d7c92SRobert Watson acl_set_file(const char *path_p, acl_type_t type, acl_t acl)
54515d7c92SRobert Watson {
55515d7c92SRobert Watson 	int	error;
56515d7c92SRobert Watson 
57e146d0bcSChris D. Faulhaber 	if (acl == NULL || path_p == NULL) {
58e146d0bcSChris D. Faulhaber 		errno = EINVAL;
59e146d0bcSChris D. Faulhaber 		return (-1);
60e146d0bcSChris D. Faulhaber 	}
61ae1add4eSEdward Tomasz Napierala 	type = _acl_type_unold(type);
622de14c39SRobert Watson 	if (_posix1e_acl(acl, type)) {
632de14c39SRobert Watson 		error = _posix1e_acl_sort(acl);
64515d7c92SRobert Watson 		if (error) {
65515d7c92SRobert Watson 			errno = error;
66515d7c92SRobert Watson 			return (-1);
67515d7c92SRobert Watson 		}
68515d7c92SRobert Watson 	}
69515d7c92SRobert Watson 
700f626307SChris D. Faulhaber 	acl->ats_cur_entry = 0;
710f626307SChris D. Faulhaber 
720f626307SChris D. Faulhaber 	return (__acl_set_file(path_p, type, &acl->ats_acl));
73515d7c92SRobert Watson }
74515d7c92SRobert Watson 
75515d7c92SRobert Watson int
766394f703SRobert Watson acl_set_link_np(const char *path_p, acl_type_t type, acl_t acl)
776394f703SRobert Watson {
786394f703SRobert Watson 	int	error;
796394f703SRobert Watson 
806394f703SRobert Watson 	if (acl == NULL || path_p == NULL) {
816394f703SRobert Watson 		errno = EINVAL;
826394f703SRobert Watson 		return (-1);
836394f703SRobert Watson 	}
84ae1add4eSEdward Tomasz Napierala 	type = _acl_type_unold(type);
856394f703SRobert Watson 	if (_posix1e_acl(acl, type)) {
866394f703SRobert Watson 		error = _posix1e_acl_sort(acl);
876394f703SRobert Watson 		if (error) {
886394f703SRobert Watson 			errno = error;
896394f703SRobert Watson 			return (-1);
906394f703SRobert Watson 		}
916394f703SRobert Watson 	}
926394f703SRobert Watson 
936394f703SRobert Watson 	acl->ats_cur_entry = 0;
946394f703SRobert Watson 
956394f703SRobert Watson 	return (__acl_set_link(path_p, type, &acl->ats_acl));
966394f703SRobert Watson }
976394f703SRobert Watson 
986394f703SRobert Watson int
998f45e8c0SRobert Watson acl_set_fd(int fd, acl_t acl)
100515d7c92SRobert Watson {
101515d7c92SRobert Watson 	int	error;
102515d7c92SRobert Watson 
1032de14c39SRobert Watson 	error = _posix1e_acl_sort(acl);
1048f45e8c0SRobert Watson 	if (error) {
1058f45e8c0SRobert Watson 		errno = error;
1068f45e8c0SRobert Watson 		return(-1);
1078f45e8c0SRobert Watson 	}
1088f45e8c0SRobert Watson 
1090f626307SChris D. Faulhaber 	acl->ats_cur_entry = 0;
1100f626307SChris D. Faulhaber 
1110f626307SChris D. Faulhaber 	return (___acl_set_fd(fd, ACL_TYPE_ACCESS, &acl->ats_acl));
1128f45e8c0SRobert Watson }
1138f45e8c0SRobert Watson 
1148f45e8c0SRobert Watson int
1158f45e8c0SRobert Watson acl_set_fd_np(int fd, acl_t acl, acl_type_t type)
1168f45e8c0SRobert Watson {
1178f45e8c0SRobert Watson 	int	error;
1188f45e8c0SRobert Watson 
119ae1add4eSEdward Tomasz Napierala 	type = _acl_type_unold(type);
1202de14c39SRobert Watson 	if (_posix1e_acl(acl, type)) {
1212de14c39SRobert Watson 		error = _posix1e_acl_sort(acl);
122515d7c92SRobert Watson 		if (error) {
123515d7c92SRobert Watson 			errno = error;
124515d7c92SRobert Watson 			return (-1);
125515d7c92SRobert Watson 		}
126515d7c92SRobert Watson 	}
127515d7c92SRobert Watson 
1280f626307SChris D. Faulhaber 	acl->ats_cur_entry = 0;
1290f626307SChris D. Faulhaber 
1300f626307SChris D. Faulhaber 	return (___acl_set_fd(fd, type, &acl->ats_acl));
131515d7c92SRobert Watson }
1324bf60dfaSChris D. Faulhaber 
1334bf60dfaSChris D. Faulhaber /*
1340f626307SChris D. Faulhaber  * acl_set_permset() (23.4.23): sets the permissions of ACL entry entry_d
1354bf60dfaSChris D. Faulhaber  * with the permissions in permset_d
1364bf60dfaSChris D. Faulhaber  */
1374bf60dfaSChris D. Faulhaber int
1384bf60dfaSChris D. Faulhaber acl_set_permset(acl_entry_t entry_d, acl_permset_t permset_d)
1394bf60dfaSChris D. Faulhaber {
1404bf60dfaSChris D. Faulhaber 
1414bf60dfaSChris D. Faulhaber 	if (!entry_d) {
1424bf60dfaSChris D. Faulhaber 		errno = EINVAL;
1439fd46b02SChris D. Faulhaber 		return (-1);
1444bf60dfaSChris D. Faulhaber 	}
1454bf60dfaSChris D. Faulhaber 
1464bf60dfaSChris D. Faulhaber 	entry_d->ae_perm = *permset_d;
1474bf60dfaSChris D. Faulhaber 
1489fd46b02SChris D. Faulhaber 	return (0);
1494bf60dfaSChris D. Faulhaber }
1504bf60dfaSChris D. Faulhaber 
1514bf60dfaSChris D. Faulhaber /*
1524bf60dfaSChris D. Faulhaber  * acl_set_qualifier() sets the qualifier (ae_id) of the tag for
1534bf60dfaSChris D. Faulhaber  * ACL entry entry_d to the value referred to by tag_qualifier_p
1544bf60dfaSChris D. Faulhaber  */
1554bf60dfaSChris D. Faulhaber int
1564bf60dfaSChris D. Faulhaber acl_set_qualifier(acl_entry_t entry_d, const void *tag_qualifier_p)
1574bf60dfaSChris D. Faulhaber {
1584bf60dfaSChris D. Faulhaber 	if (!entry_d || !tag_qualifier_p) {
1594bf60dfaSChris D. Faulhaber 		errno = EINVAL;
1609fd46b02SChris D. Faulhaber 		return (-1);
1614bf60dfaSChris D. Faulhaber 	}
1624bf60dfaSChris D. Faulhaber 
1634bf60dfaSChris D. Faulhaber 	switch(entry_d->ae_tag) {
1644bf60dfaSChris D. Faulhaber 	case ACL_USER:
1654bf60dfaSChris D. Faulhaber 	case ACL_GROUP:
166d5675fffSChris D. Faulhaber 		entry_d->ae_id = *(uid_t *)tag_qualifier_p;
1674bf60dfaSChris D. Faulhaber 		break;
1684bf60dfaSChris D. Faulhaber 	default:
1694bf60dfaSChris D. Faulhaber 		errno = EINVAL;
1709fd46b02SChris D. Faulhaber 		return (-1);
1714bf60dfaSChris D. Faulhaber 	}
1724bf60dfaSChris D. Faulhaber 
1739fd46b02SChris D. Faulhaber 	return (0);
1744bf60dfaSChris D. Faulhaber }
1754bf60dfaSChris D. Faulhaber 
1764bf60dfaSChris D. Faulhaber /*
1774bf60dfaSChris D. Faulhaber  * acl_set_tag_type() sets the tag type for ACL entry entry_d to the
1784bf60dfaSChris D. Faulhaber  * value of tag_type
1794bf60dfaSChris D. Faulhaber  */
1804bf60dfaSChris D. Faulhaber int
1814bf60dfaSChris D. Faulhaber acl_set_tag_type(acl_entry_t entry_d, acl_tag_t tag_type)
1824bf60dfaSChris D. Faulhaber {
1834bf60dfaSChris D. Faulhaber 
1849fd46b02SChris D. Faulhaber 	if (entry_d == NULL) {
1854bf60dfaSChris D. Faulhaber 		errno = EINVAL;
1869fd46b02SChris D. Faulhaber 		return (-1);
1874bf60dfaSChris D. Faulhaber 	}
1884bf60dfaSChris D. Faulhaber 
1894bf60dfaSChris D. Faulhaber 	switch(tag_type) {
1904bf60dfaSChris D. Faulhaber 	case ACL_USER_OBJ:
1914bf60dfaSChris D. Faulhaber 	case ACL_USER:
1924bf60dfaSChris D. Faulhaber 	case ACL_GROUP_OBJ:
1934bf60dfaSChris D. Faulhaber 	case ACL_GROUP:
1944bf60dfaSChris D. Faulhaber 	case ACL_MASK:
1954bf60dfaSChris D. Faulhaber 	case ACL_OTHER:
1964bf60dfaSChris D. Faulhaber 		entry_d->ae_tag = tag_type;
1979fd46b02SChris D. Faulhaber 		return (0);
1984bf60dfaSChris D. Faulhaber 	}
1994bf60dfaSChris D. Faulhaber 
2004bf60dfaSChris D. Faulhaber 	errno = EINVAL;
2019fd46b02SChris D. Faulhaber 	return (-1);
2024bf60dfaSChris D. Faulhaber }
203