X-Git-Url: http://review.tizen.org/git/?a=blobdiff_plain;f=bus%2Fpolicy.h;h=d1d3e72b7f1b10d1430648c315f027747dace547;hb=61d97215c317a4154df47fbfb882aab60b92fbab;hp=194bd0014fbd76a741d7bae55266ee231c4d90e0;hpb=bc983ecf15455f49e7a92d038c93e181ae2cb438;p=platform%2Fupstream%2Fdbus.git diff --git a/bus/policy.h b/bus/policy.h index 194bd00..d1d3e72 100644 --- a/bus/policy.h +++ b/bus/policy.h @@ -1,9 +1,9 @@ -/* -*- mode: C; c-file-style: "gnu" -*- */ +/* -*- mode: C; c-file-style: "gnu"; indent-tabs-mode: nil; -*- */ /* policy.h Bus security policy * * Copyright (C) 2003 Red Hat, Inc. * - * Licensed under the Academic Free License version 1.2 + * Licensed under the Academic Free License version 2.1 * * This program is free software; you can redistribute it and/or modify * it under the terms of the GNU General Public License as published by @@ -17,7 +17,7 @@ * * You should have received a copy of the GNU General Public License * along with this program; if not, write to the Free Software - * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA + * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA * */ @@ -26,6 +26,8 @@ #include #include +#include +#include #include "bus.h" typedef enum @@ -37,6 +39,10 @@ typedef enum BUS_POLICY_RULE_GROUP } BusPolicyRuleType; +/** determines whether the rule affects a connection, or some global item */ +#define BUS_POLICY_RULE_IS_PER_CLIENT(rule) (!((rule)->type == BUS_POLICY_RULE_USER || \ + (rule)->type == BUS_POLICY_RULE_GROUP)) + struct BusPolicyRule { int refcount; @@ -49,69 +55,115 @@ struct BusPolicyRule { struct { - /* either can be NULL meaning "any" */ - char *message_name; + /* message type can be DBUS_MESSAGE_TYPE_INVALID meaning "any" */ + int message_type; + /* any of these can be NULL meaning "any" */ + char *path; + char *interface; + char *member; + char *error; char *destination; + unsigned int eavesdrop : 1; + unsigned int requested_reply : 1; + unsigned int log : 1; } send; struct { - /* either can be NULL meaning "any" */ - char *message_name; + /* message type can be DBUS_MESSAGE_TYPE_INVALID meaning "any" */ + int message_type; + /* any of these can be NULL meaning "any" */ + char *path; + char *interface; + char *member; + char *error; char *origin; + unsigned int eavesdrop : 1; + unsigned int requested_reply : 1; } receive; struct { /* can be NULL meaning "any" */ char *service_name; + /* if prefix is set, any name starting with service_name can be owned */ + unsigned int prefix : 1; } own; struct { - char *user; - unsigned long uid; + /* can be DBUS_UID_UNSET meaning "any" */ + dbus_uid_t uid; } user; struct { - char *group; - unsigned long gid; + /* can be DBUS_GID_UNSET meaning "any" */ + dbus_gid_t gid; } group; - + } d; }; BusPolicyRule* bus_policy_rule_new (BusPolicyRuleType type, dbus_bool_t allow); -void bus_policy_rule_ref (BusPolicyRule *rule); +BusPolicyRule* bus_policy_rule_ref (BusPolicyRule *rule); void bus_policy_rule_unref (BusPolicyRule *rule); -BusPolicy* bus_policy_new (void); -void bus_policy_ref (BusPolicy *policy); -void bus_policy_unref (BusPolicy *policy); -BusClientPolicy* bus_policy_create_client_policy (BusPolicy *policy, - DBusConnection *connection); -dbus_bool_t bus_policy_allow_user (BusPolicy *policy, - unsigned long uid); +BusPolicy* bus_policy_new (void); +BusPolicy* bus_policy_ref (BusPolicy *policy); +void bus_policy_unref (BusPolicy *policy); +BusClientPolicy* bus_policy_create_client_policy (BusPolicy *policy, + DBusConnection *connection, + DBusError *error); +dbus_bool_t bus_policy_allow_unix_user (BusPolicy *policy, + unsigned long uid); +dbus_bool_t bus_policy_allow_windows_user (BusPolicy *policy, + const char *windows_sid); +dbus_bool_t bus_policy_append_default_rule (BusPolicy *policy, + BusPolicyRule *rule); +dbus_bool_t bus_policy_append_mandatory_rule (BusPolicy *policy, + BusPolicyRule *rule); +dbus_bool_t bus_policy_append_user_rule (BusPolicy *policy, + dbus_uid_t uid, + BusPolicyRule *rule); +dbus_bool_t bus_policy_append_group_rule (BusPolicy *policy, + dbus_gid_t gid, + BusPolicyRule *rule); +dbus_bool_t bus_policy_append_console_rule (BusPolicy *policy, + dbus_bool_t at_console, + BusPolicyRule *rule); + +dbus_bool_t bus_policy_merge (BusPolicy *policy, + BusPolicy *to_absorb); BusClientPolicy* bus_client_policy_new (void); -void bus_client_policy_ref (BusClientPolicy *policy); +BusClientPolicy* bus_client_policy_ref (BusClientPolicy *policy); void bus_client_policy_unref (BusClientPolicy *policy); dbus_bool_t bus_client_policy_check_can_send (BusClientPolicy *policy, BusRegistry *registry, + dbus_bool_t requested_reply, DBusConnection *receiver, - DBusMessage *message); + DBusMessage *message, + dbus_int32_t *toggles, + dbus_bool_t *log); dbus_bool_t bus_client_policy_check_can_receive (BusClientPolicy *policy, BusRegistry *registry, + dbus_bool_t requested_reply, DBusConnection *sender, - DBusMessage *message); + DBusConnection *addressed_recipient, + DBusConnection *proposed_recipient, + DBusMessage *message, + dbus_int32_t *toggles); dbus_bool_t bus_client_policy_check_can_own (BusClientPolicy *policy, - DBusConnection *connection, const DBusString *service_name); dbus_bool_t bus_client_policy_append_rule (BusClientPolicy *policy, BusPolicyRule *rule); void bus_client_policy_optimize (BusClientPolicy *policy); +#ifdef DBUS_ENABLE_EMBEDDED_TESTS +dbus_bool_t bus_policy_check_can_own (BusPolicy *policy, + const DBusString *service_name); +#endif #endif /* BUS_POLICY_H */