1 /* -*- mode: C; c-file-style: "gnu" -*- */
2 /* policy.h Bus security policy
4 * Copyright (C) 2003 Red Hat, Inc.
6 * Licensed under the Academic Free License version 2.0
8 * This program is free software; you can redistribute it and/or modify
9 * it under the terms of the GNU General Public License as published by
10 * the Free Software Foundation; either version 2 of the License, or
11 * (at your option) any later version.
13 * This program is distributed in the hope that it will be useful,
14 * but WITHOUT ANY WARRANTY; without even the implied warranty of
15 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 * GNU General Public License for more details.
18 * You should have received a copy of the GNU General Public License
19 * along with this program; if not, write to the Free Software
20 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
27 #include <dbus/dbus.h>
28 #include <dbus/dbus-string.h>
29 #include <dbus/dbus-sysdeps.h>
35 BUS_POLICY_RULE_RECEIVE,
41 /** determines whether the rule affects a connection, or some global item */
42 #define BUS_POLICY_RULE_IS_PER_CLIENT(rule) (!((rule)->type == BUS_POLICY_RULE_USER || \
43 (rule)->type == BUS_POLICY_RULE_GROUP))
49 BusPolicyRuleType type;
51 unsigned int allow : 1; /**< #TRUE if this allows, #FALSE if it denies */
57 /* message type can be DBUS_MESSAGE_TYPE_INVALID meaning "any" */
59 /* any of these can be NULL meaning "any" */
65 unsigned int requested_reply : 1;
70 /* message type can be DBUS_MESSAGE_TYPE_INVALID meaning "any" */
72 /* any of these can be NULL meaning "any" */
78 unsigned int eavesdrop : 1;
79 unsigned int requested_reply : 1;
84 /* can be NULL meaning "any" */
90 /* can be DBUS_UID_UNSET meaning "any" */
96 /* can be DBUS_GID_UNSET meaning "any" */
103 BusPolicyRule* bus_policy_rule_new (BusPolicyRuleType type,
105 BusPolicyRule* bus_policy_rule_ref (BusPolicyRule *rule);
106 void bus_policy_rule_unref (BusPolicyRule *rule);
108 BusPolicy* bus_policy_new (void);
109 BusPolicy* bus_policy_ref (BusPolicy *policy);
110 void bus_policy_unref (BusPolicy *policy);
111 BusClientPolicy* bus_policy_create_client_policy (BusPolicy *policy,
112 DBusConnection *connection,
114 dbus_bool_t bus_policy_allow_user (BusPolicy *policy,
115 DBusUserDatabase *user_database,
117 dbus_bool_t bus_policy_append_default_rule (BusPolicy *policy,
118 BusPolicyRule *rule);
119 dbus_bool_t bus_policy_append_mandatory_rule (BusPolicy *policy,
120 BusPolicyRule *rule);
121 dbus_bool_t bus_policy_append_user_rule (BusPolicy *policy,
123 BusPolicyRule *rule);
124 dbus_bool_t bus_policy_append_group_rule (BusPolicy *policy,
126 BusPolicyRule *rule);
127 dbus_bool_t bus_policy_merge (BusPolicy *policy,
128 BusPolicy *to_absorb);
130 BusClientPolicy* bus_client_policy_new (void);
131 BusClientPolicy* bus_client_policy_ref (BusClientPolicy *policy);
132 void bus_client_policy_unref (BusClientPolicy *policy);
133 dbus_bool_t bus_client_policy_check_can_send (BusClientPolicy *policy,
134 BusRegistry *registry,
135 dbus_bool_t requested_reply,
136 DBusConnection *receiver,
137 DBusMessage *message);
138 dbus_bool_t bus_client_policy_check_can_receive (BusClientPolicy *policy,
139 BusRegistry *registry,
140 dbus_bool_t requested_reply,
141 DBusConnection *sender,
142 DBusConnection *addressed_recipient,
143 DBusConnection *proposed_recipient,
144 DBusMessage *message);
145 dbus_bool_t bus_client_policy_check_can_own (BusClientPolicy *policy,
146 DBusConnection *connection,
147 const DBusString *service_name);
148 dbus_bool_t bus_client_policy_append_rule (BusClientPolicy *policy,
149 BusPolicyRule *rule);
150 void bus_client_policy_optimize (BusClientPolicy *policy);
153 #endif /* BUS_POLICY_H */