4 Copyright (C) 1999, 2000
5 Andreas Gruenbacher, <a.gruenbacher@bestbits.at>
7 This program is free software; you can redistribute it and/or
8 modify it under the terms of the GNU Lesser General Public
9 License as published by the Free Software Foundation; either
10 version 2.1 of the License, or (at your option) any later version.
12 This program is distributed in the hope that it will be useful,
13 but WITHOUT ANY WARRANTY; without even the implied warranty of
14 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 Lesser General Public License for more details.
17 You should have received a copy of the GNU Lesser General Public
18 License along with this library; if not, write to the Free Software
19 Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
24 #include <acl/libacl.h>
28 #define FAIL_CHECK(error) \
29 do { return error; } while (0)
32 Check if an ACL is valid.
34 The e_id fields of ACL entries that don't use them are ignored.
37 contains the index of the last valid entry found
38 after acl_check returns.
40 0 on success, -1 on error, or an ACL_*_ERROR value for invalid ACLs.
44 acl_check(acl_t acl, int *last)
46 acl_obj *acl_obj_p = ext2int(acl, acl);
48 int state = ACL_USER_OBJ;
49 acl_entry_obj *entry_obj_p;
56 FOREACH_ACL_ENTRY(entry_obj_p, acl_obj_p) {
57 /* Check permissions for ~(ACL_READ|ACL_WRITE|ACL_EXECUTE) */
58 switch (entry_obj_p->etag) {
60 if (state == ACL_USER_OBJ) {
65 FAIL_CHECK(ACL_MULTI_ERROR);
68 if (state != ACL_USER)
69 FAIL_CHECK(ACL_MISS_ERROR);
70 if (qualifier_obj_id(entry_obj_p->eid) < qual ||
71 qualifier_obj_id(entry_obj_p->eid) ==
73 FAIL_CHECK(ACL_DUPLICATE_ERROR);
74 qual = qualifier_obj_id(entry_obj_p->eid)+1;
79 if (state == ACL_USER) {
84 if (state >= ACL_GROUP)
85 FAIL_CHECK(ACL_MULTI_ERROR);
86 FAIL_CHECK(ACL_MISS_ERROR);
89 if (state != ACL_GROUP)
90 FAIL_CHECK(ACL_MISS_ERROR);
91 if (qualifier_obj_id(entry_obj_p->eid) < qual ||
92 qualifier_obj_id(entry_obj_p->eid) ==
94 FAIL_CHECK(ACL_DUPLICATE_ERROR);
95 qual = qualifier_obj_id(entry_obj_p->eid)+1;
100 if (state == ACL_GROUP) {
104 if (state >= ACL_OTHER)
105 FAIL_CHECK(ACL_MULTI_ERROR);
106 FAIL_CHECK(ACL_MISS_ERROR);
109 if (state == ACL_OTHER ||
110 (state == ACL_GROUP && !needs_mask)) {
114 FAIL_CHECK(ACL_MISS_ERROR);
117 FAIL_CHECK(ACL_ENTRY_ERROR);
124 FAIL_CHECK(ACL_MISS_ERROR);