1 /*-
2  * Copyright (c) 2013 The FreeBSD Foundation
3  * All rights reserved.
4  *
5  * This software was developed by Pawel Jakub Dawidek under sponsorship from
6  * the FreeBSD Foundation.
7  *
8  * Redistribution and use in source and binary forms, with or without
9  * modification, are permitted provided that the following conditions
10  * are met:
11  * 1. Redistributions of source code must retain the above copyright
12  *    notice, this list of conditions and the following disclaimer.
13  * 2. Redistributions in binary form must reproduce the above copyright
14  *    notice, this list of conditions and the following disclaimer in the
15  *    documentation and/or other materials provided with the distribution.
16  *
17  * THIS SOFTWARE IS PROVIDED BY THE AUTHORS AND CONTRIBUTORS ``AS IS'' AND
18  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
19  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
20  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS BE LIABLE
21  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
22  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
23  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
24  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
25  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
26  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
27  * SUCH DAMAGE.
28  *
29  * $FreeBSD$
30  */
31 
32 #ifndef	_CAP_GRP_H_
33 #define	_CAP_GRP_H_
34 
35 #ifdef HAVE_CASPER
36 #define WITH_CASPER
37 #endif
38 
39 #ifdef WITH_CASPER
40 struct group *cap_getgrent(cap_channel_t *chan);
41 struct group *cap_getgrnam(cap_channel_t *chan, const char *name);
42 struct group *cap_getgrgid(cap_channel_t *chan, gid_t gid);
43 
44 int cap_getgrent_r(cap_channel_t *chan, struct group *grp, char *buffer,
45     size_t bufsize, struct group **result);
46 int cap_getgrnam_r(cap_channel_t *chan, const char *name, struct group *grp,
47     char *buffer, size_t bufsize, struct group **result);
48 int cap_getgrgid_r(cap_channel_t *chan, gid_t gid, struct group *grp,
49     char *buffer, size_t bufsize, struct group **result);
50 
51 int cap_setgroupent(cap_channel_t *chan, int stayopen);
52 int cap_setgrent(cap_channel_t *chan);
53 void cap_endgrent(cap_channel_t *chan);
54 
55 int cap_grp_limit_cmds(cap_channel_t *chan, const char * const *cmds,
56     size_t ncmds);
57 int cap_grp_limit_fields(cap_channel_t *chan, const char * const *fields,
58     size_t nfields);
59 int cap_grp_limit_groups(cap_channel_t *chan, const char * const *names,
60     size_t nnames, const gid_t *gids, size_t ngids);
61 #else
62 #define	cap_getgrent(chan)		getgrent()
63 #define	cap_getgrnam(chan, name)	getgrnam(name)
64 #define	cap_getgrgid(chan, gid)		getgrgid(gid)
65 
66 #define	cap_setgroupent(chan, stayopen) etgroupent(stayopen)
67 #define endgrent(chan)			endgrent()
68 static inline int
69 cap_setgrent(cap_channel_t *chan __unused)
70 {
71 
72 	setgrent();
73 	return(0);
74 }
75 
76 #define	cap_getgrent_r(chan, grp, buffer, bufsize, result)			\
77 	getgrent_r(grp, buffer, bufsize, result)
78 #define	cap_getgrnam_r(chan, name, grp, buffer, bufsize, result)		\
79 	getgrnam_r(name, grp, buffer, bufsize, result)
80 #define	cap_getgrgid_r(chan, gid, grp, buffer, bufsize, result)			\
81 	getgrgid_r(gid, grp, buffer, bufsize, result)
82 
83 #define	cap_grp_limit_cmds(chan, cmds, ncmds)			(0)
84 #define	cap_grp_limit_fields(chan, fields, nfields)		(0)
85 #define	cap_grp_limit_groups(chan, names, nnames, gids, ngids)	(0)
86 
87 #endif
88 
89 #endif	/* !_CAP_GRP_H_ */
90