uidgid.h 4.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190
  1. #ifndef _LINUX_UIDGID_H
  2. #define _LINUX_UIDGID_H
  3. /*
  4. * A set of types for the internal kernel types representing uids and gids.
  5. *
  6. * The types defined in this header allow distinguishing which uids and gids in
  7. * the kernel are values used by userspace and which uid and gid values are
  8. * the internal kernel values. With the addition of user namespaces the values
  9. * can be different. Using the type system makes it possible for the compiler
  10. * to detect when we overlook these differences.
  11. *
  12. */
  13. #include <linux/types.h>
  14. #include <linux/highuid.h>
  15. struct user_namespace;
  16. extern struct user_namespace init_user_ns;
  17. typedef struct {
  18. uid_t val;
  19. } kuid_t;
  20. typedef struct {
  21. gid_t val;
  22. } kgid_t;
  23. #define KUIDT_INIT(value) (kuid_t){ value }
  24. #define KGIDT_INIT(value) (kgid_t){ value }
  25. #ifdef CONFIG_MULTIUSER
  26. static inline uid_t __kuid_val(kuid_t uid)
  27. {
  28. return uid.val;
  29. }
  30. static inline gid_t __kgid_val(kgid_t gid)
  31. {
  32. return gid.val;
  33. }
  34. #else
  35. static inline uid_t __kuid_val(kuid_t uid)
  36. {
  37. return 0;
  38. }
  39. static inline gid_t __kgid_val(kgid_t gid)
  40. {
  41. return 0;
  42. }
  43. #endif
  44. #define GLOBAL_ROOT_UID KUIDT_INIT(0)
  45. #define GLOBAL_ROOT_GID KGIDT_INIT(0)
  46. #define INVALID_UID KUIDT_INIT(-1)
  47. #define INVALID_GID KGIDT_INIT(-1)
  48. static inline bool uid_eq(kuid_t left, kuid_t right)
  49. {
  50. return __kuid_val(left) == __kuid_val(right);
  51. }
  52. static inline bool gid_eq(kgid_t left, kgid_t right)
  53. {
  54. return __kgid_val(left) == __kgid_val(right);
  55. }
  56. static inline bool uid_gt(kuid_t left, kuid_t right)
  57. {
  58. return __kuid_val(left) > __kuid_val(right);
  59. }
  60. static inline bool gid_gt(kgid_t left, kgid_t right)
  61. {
  62. return __kgid_val(left) > __kgid_val(right);
  63. }
  64. static inline bool uid_gte(kuid_t left, kuid_t right)
  65. {
  66. return __kuid_val(left) >= __kuid_val(right);
  67. }
  68. static inline bool gid_gte(kgid_t left, kgid_t right)
  69. {
  70. return __kgid_val(left) >= __kgid_val(right);
  71. }
  72. static inline bool uid_lt(kuid_t left, kuid_t right)
  73. {
  74. return __kuid_val(left) < __kuid_val(right);
  75. }
  76. static inline bool gid_lt(kgid_t left, kgid_t right)
  77. {
  78. return __kgid_val(left) < __kgid_val(right);
  79. }
  80. static inline bool uid_lte(kuid_t left, kuid_t right)
  81. {
  82. return __kuid_val(left) <= __kuid_val(right);
  83. }
  84. static inline bool gid_lte(kgid_t left, kgid_t right)
  85. {
  86. return __kgid_val(left) <= __kgid_val(right);
  87. }
  88. static inline bool uid_valid(kuid_t uid)
  89. {
  90. return __kuid_val(uid) != (uid_t) -1;
  91. }
  92. static inline bool gid_valid(kgid_t gid)
  93. {
  94. return __kgid_val(gid) != (gid_t) -1;
  95. }
  96. #ifdef CONFIG_USER_NS
  97. extern kuid_t make_kuid(struct user_namespace *from, uid_t uid);
  98. extern kgid_t make_kgid(struct user_namespace *from, gid_t gid);
  99. extern uid_t from_kuid(struct user_namespace *to, kuid_t uid);
  100. extern gid_t from_kgid(struct user_namespace *to, kgid_t gid);
  101. extern uid_t from_kuid_munged(struct user_namespace *to, kuid_t uid);
  102. extern gid_t from_kgid_munged(struct user_namespace *to, kgid_t gid);
  103. static inline bool kuid_has_mapping(struct user_namespace *ns, kuid_t uid)
  104. {
  105. return from_kuid(ns, uid) != (uid_t) -1;
  106. }
  107. static inline bool kgid_has_mapping(struct user_namespace *ns, kgid_t gid)
  108. {
  109. return from_kgid(ns, gid) != (gid_t) -1;
  110. }
  111. #else
  112. static inline kuid_t make_kuid(struct user_namespace *from, uid_t uid)
  113. {
  114. return KUIDT_INIT(uid);
  115. }
  116. static inline kgid_t make_kgid(struct user_namespace *from, gid_t gid)
  117. {
  118. return KGIDT_INIT(gid);
  119. }
  120. static inline uid_t from_kuid(struct user_namespace *to, kuid_t kuid)
  121. {
  122. return __kuid_val(kuid);
  123. }
  124. static inline gid_t from_kgid(struct user_namespace *to, kgid_t kgid)
  125. {
  126. return __kgid_val(kgid);
  127. }
  128. static inline uid_t from_kuid_munged(struct user_namespace *to, kuid_t kuid)
  129. {
  130. uid_t uid = from_kuid(to, kuid);
  131. if (uid == (uid_t)-1)
  132. uid = overflowuid;
  133. return uid;
  134. }
  135. static inline gid_t from_kgid_munged(struct user_namespace *to, kgid_t kgid)
  136. {
  137. gid_t gid = from_kgid(to, kgid);
  138. if (gid == (gid_t)-1)
  139. gid = overflowgid;
  140. return gid;
  141. }
  142. static inline bool kuid_has_mapping(struct user_namespace *ns, kuid_t uid)
  143. {
  144. return uid_valid(uid);
  145. }
  146. static inline bool kgid_has_mapping(struct user_namespace *ns, kgid_t gid)
  147. {
  148. return gid_valid(gid);
  149. }
  150. #endif /* CONFIG_USER_NS */
  151. #endif /* _LINUX_UIDGID_H */