/
usr
/
include
/
bind9
/
isc
/
/usr/include/bind9/isc
mkdir
upload
Name
Size
Mode
Actions
aes.h
1080
0644
edit
dl
rm
app.h
10478
0644
edit
dl
rm
assertions.h
2907
0644
edit
dl
rm
atomic.h
4168
0644
edit
dl
rm
backtrace.h
3891
0644
edit
dl
rm
base32.h
4453
0644
edit
dl
rm
base64.h
2866
0644
edit
dl
rm
bind9.h
830
0644
edit
dl
rm
boolean.h
594
0644
edit
dl
rm
buffer.h
26268
0644
edit
dl
rm
bufferlist.h
1452
0644
edit
dl
rm
cmocka.h
1383
0644
edit
dl
rm
commandline.h
1713
0644
edit
dl
rm
condition.h
1478
0644
edit
dl
rm
counter.h
1926
0644
edit
dl
rm
crc64.h
998
0644
edit
dl
rm
deprecated.h
623
0644
edit
dl
rm
dir.h
1598
0644
edit
dl
rm
endian.h
4778
0644
edit
dl
rm
entropy.h
10373
0644
edit
dl
rm
errno.h
659
0644
edit
dl
rm
errno2result.h
902
0644
edit
dl
rm
error.h
1430
0644
edit
dl
rm
event.h
3053
0644
edit
dl
rm
eventclass.h
1381
0644
edit
dl
rm
file.h
11667
0644
edit
dl
rm
formatcheck.h
893
0644
edit
dl
rm
fsaccess.h
7442
0644
edit
dl
rm
hash.h
7662
0644
edit
dl
rm
heap.h
5264
0644
edit
dl
rm
hex.h
2806
0644
edit
dl
rm
hmacmd5.h
1787
0644
edit
dl
rm
hmacsha.h
4511
0644
edit
dl
rm
ht.h
4396
0644
edit
dl
rm
httpd.h
2318
0644
edit
dl
rm
int.h
1088
0644
edit
dl
rm
interfaceiter.h
3120
0644
edit
dl
rm
iterated_hash.h
1046
0644
edit
dl
rm
json.h
1459
0644
edit
dl
rm
keyboard.h
989
0644
edit
dl
rm
lang.h
637
0644
edit
dl
rm
lex.h
9771
0644
edit
dl
rm
lfsr.h
2958
0644
edit
dl
rm
lib.h
1068
0644
edit
dl
rm
likely.h
818
0644
edit
dl
rm
list.h
5751
0644
edit
dl
rm
log.h
28734
0644
edit
dl
rm
magic.h
994
0644
edit
dl
rm
md5.h
2380
0644
edit
dl
rm
mem.h
21110
0644
edit
dl
rm
meminfo.h
710
0644
edit
dl
rm
msgcat.h
2726
0644
edit
dl
rm
msgs.h
8422
0644
edit
dl
rm
mutex.h
3524
0644
edit
dl
rm
mutexblock.h
1375
0644
edit
dl
rm
net.h
10534
0644
edit
dl
rm
netaddr.h
4590
0644
edit
dl
rm
netdb.h
863
0644
edit
dl
rm
netscope.h
967
0644
edit
dl
rm
offset.h
700
0644
edit
dl
rm
once.h
983
0644
edit
dl
rm
ondestroy.h
2799
0644
edit
dl
rm
os.h
671
0644
edit
dl
rm
parseint.h
1542
0644
edit
dl
rm
platform.h
9717
0644
edit
dl
rm
pool.h
3502
0644
edit
dl
rm
portset.h
3295
0644
edit
dl
rm
print.h
2475
0644
edit
dl
rm
queue.h
5204
0644
edit
dl
rm
quota.h
2440
0644
edit
dl
rm
radix.h
6491
0644
edit
dl
rm
random.h
3582
0644
edit
dl
rm
ratelimiter.h
3497
0644
edit
dl
rm
refcount.h
8193
0644
edit
dl
rm
regex.h
767
0644
edit
dl
rm
region.h
2034
0644
edit
dl
rm
resource.h
2862
0644
edit
dl
rm
result.h
4982
0644
edit
dl
rm
resultclass.h
1599
0644
edit
dl
rm
rwlock.h
3807
0644
edit
dl
rm
safe.h
1352
0644
edit
dl
rm
serial.h
1368
0644
edit
dl
rm
sha1.h
1556
0644
edit
dl
rm
sha2.h
5733
0644
edit
dl
rm
siphash.h
734
0644
edit
dl
rm
sockaddr.h
6039
0644
edit
dl
rm
socket.h
36655
0644
edit
dl
rm
stat.h
806
0644
edit
dl
rm
stats.h
3709
0644
edit
dl
rm
stdatomic.h
5250
0644
edit
dl
rm
stdio.h
1787
0644
edit
dl
rm
stdlib.h
704
0644
edit
dl
rm
stdtime.h
1065
0644
edit
dl
rm
strerror.h
777
0644
edit
dl
rm
string.h
6019
0644
edit
dl
rm
symtab.h
4326
0644
edit
dl
rm
syslog.h
844
0644
edit
dl
rm
task.h
21544
0644
edit
dl
rm
taskpool.h
3709
0644
edit
dl
rm
thread.h
1506
0644
edit
dl
rm
time.h
8876
0644
edit
dl
rm
timer.h
10795
0644
edit
dl
rm
tm.h
895
0644
edit
dl
rm
types.h
5780
0644
edit
dl
rm
utf8.h
928
0644
edit
dl
rm
util.h
10537
0644
edit
dl
rm
version.h
689
0644
edit
dl
rm
xml.h
1094
0644
edit
dl
rm
Edit:
/usr/include/bind9/isc/fsaccess.h
(7442B)
/* * Copyright (C) Internet Systems Consortium, Inc. ("ISC") * * This Source Code Form is subject to the terms of the Mozilla Public * License, v. 2.0. If a copy of the MPL was not distributed with this * file, you can obtain one at https://mozilla.org/MPL/2.0/. * * See the COPYRIGHT file distributed with this work for additional * information regarding copyright ownership. */ #ifndef ISC_FSACCESS_H #define ISC_FSACCESS_H 1 /*! \file isc/fsaccess.h * \brief The ISC filesystem access module encapsulates the setting of file * and directory access permissions into one API that is meant to be * portable to multiple operating systems. * * The two primary operating system flavors that are initially accommodated * are POSIX and Windows NT 4.0 and later. The Windows NT access model is * considerable more flexible than POSIX's model (as much as I am loathe to * admit it), and so the ISC API has a higher degree of complexity than would * be needed to simply address POSIX's needs. * * The full breadth of NT's flexibility is not available either, for the * present time. Much of it is to provide compatibility with what Unix * programmers are expecting. This is also due to not yet really needing all * of the functionality of an NT system (or, for that matter, a POSIX system) * in BIND9, and so resolving how to handle the various incompatibilities has * been a purely theoretical exercise with no operational experience to * indicate how flawed the thinking may be. * * Some of the more notable dumbing down of NT for this API includes: * *\li Each of FILE_READ_DATA and FILE_READ_EA are set with #ISC_FSACCESS_READ. * * \li All of FILE_WRITE_DATA, FILE_WRITE_EA and FILE_APPEND_DATA are * set with #ISC_FSACCESS_WRITE. FILE_WRITE_ATTRIBUTES is not set * so as to be consistent with Unix, where only the owner of the file * or the superuser can change the attributes/mode of a file. * * \li Both of FILE_ADD_FILE and FILE_ADD_SUBDIRECTORY are set with * #ISC_FSACCESS_CREATECHILD. This is similar to setting the WRITE * permission on a Unix directory. * * \li SYNCHRONIZE is always set for files and directories, unless someone * can give me a reason why this is a bad idea. * * \li READ_CONTROL and FILE_READ_ATTRIBUTES are always set; this is * consistent with Unix, where any file or directory can be stat()'d * unless the directory path disallows complete access somewhere along * the way. * * \li WRITE_DAC is only set for the owner. This too is consistent with * Unix, and is tighter security than allowing anyone else to be * able to set permissions. * * \li DELETE is only set for the owner. On Unix the ability to delete * a file is controlled by the directory permissions, but it isn't * currently clear to me what happens on NT if the directory has * FILE_DELETE_CHILD set but a file within it does not have DELETE * set. Always setting DELETE on the file/directory for the owner * gives maximum flexibility to the owner without exposing the * file to deletion by others. * * \li WRITE_OWNER is never set. This too is consistent with Unix, * and is also tighter security than allowing anyone to change the * ownership of the file apart from the superu..ahem, Administrator. * * \li Inheritance is set to NO_INHERITANCE. * * Unix's dumbing down includes: * * \li The sticky bit cannot be set. * * \li setuid and setgid cannot be set. * * \li Only regular files and directories can be set. * * The rest of this comment discusses a few of the incompatibilities * between the two systems that need more thought if this API is to * be extended to accommodate them. * * The Windows standard access right "DELETE" doesn't have a direct * equivalent in the Unix world, so it isn't clear what should be done * with it. * * The Unix sticky bit is not supported. While NT does have a concept * of allowing users to create files in a directory but not delete or * rename them, it does not have a concept of allowing them to be deleted * if they are owned by the user trying to delete/rename. While it is * probable that something could be cobbled together in NT 5 with inheritance, * it can't really be done in NT 4 as a single property that you could * set on a directory. You'd need to coordinate something with file creation * so that every file created had DELETE set for the owner but no one else. * * On Unix systems, setting #ISC_FSACCESS_LISTDIRECTORY sets READ. * ... setting either #ISC_FSACCESS_CREATECHILD or #ISC_FSACCESS_DELETECHILD * sets WRITE. * ... setting #ISC_FSACCESS_ACCESSCHILD sets EXECUTE. * * On NT systems, setting #ISC_FSACCESS_LISTDIRECTORY sets FILE_LIST_DIRECTORY. * ... setting #ISC_FSACCESS_CREATECHILD sets FILE_CREATE_CHILD independently. * ... setting #ISC_FSACCESS_DELETECHILD sets FILE_DELETE_CHILD independently. * ... setting #ISC_FSACCESS_ACCESSCHILD sets FILE_TRAVERSE. * * Unresolved: XXXDCL * \li What NT access right controls the ability to rename a file? * \li How does DELETE work? If a directory has FILE_DELETE_CHILD but a * file or directory within it does not have DELETE, is that file * or directory deletable? * \li To implement isc_fsaccess_get(), mapping an existing Unix permission * mode_t back to an isc_fsaccess_t is pretty trivial; however, mapping * an NT DACL could be impossible to do in a responsible way. * \li Similarly, trying to implement the functionality of being able to * say "add group writability to whatever permissions already exist" * could be tricky on NT because of the order-of-entry issue combined * with possibly having one or more matching ACEs already explicitly * granting or denying access. Because this functionality is * not yet needed by the ISC, no code has been written to try to * solve this problem. */ #include <inttypes.h> #include <isc/lang.h> #include <isc/types.h> /* * Trustees. */ #define ISC_FSACCESS_OWNER 0x1 /*%< User account. */ #define ISC_FSACCESS_GROUP 0x2 /*%< Primary group owner. */ #define ISC_FSACCESS_OTHER 0x4 /*%< Not the owner or the group owner. */ #define ISC_FSACCESS_WORLD 0x7 /*%< User, Group, Other. */ /* * Types of permission. */ #define ISC_FSACCESS_READ 0x00000001 /*%< File only. */ #define ISC_FSACCESS_WRITE 0x00000002 /*%< File only. */ #define ISC_FSACCESS_EXECUTE 0x00000004 /*%< File only. */ #define ISC_FSACCESS_CREATECHILD 0x00000008 /*%< Dir only. */ #define ISC_FSACCESS_DELETECHILD 0x00000010 /*%< Dir only. */ #define ISC_FSACCESS_LISTDIRECTORY 0x00000020 /*%< Dir only. */ #define ISC_FSACCESS_ACCESSCHILD 0x00000040 /*%< Dir only. */ /*% * Adding any permission bits beyond 0x200 would mean typedef'ing * isc_fsaccess_t as uint64_t, and redefining this value to * reflect the new range of permission types, Probably to 21 for * maximum flexibility. The number of bits has to accommodate all of * the permission types, and three full sets of them have to fit * within an isc_fsaccess_t. */ #define ISC__FSACCESS_PERMISSIONBITS 10 ISC_LANG_BEGINDECLS void isc_fsaccess_add(int trustee, int permission, isc_fsaccess_t *access); void isc_fsaccess_remove(int trustee, int permission, isc_fsaccess_t *access); isc_result_t isc_fsaccess_set(const char *path, isc_fsaccess_t access); ISC_LANG_ENDDECLS #endif /* ISC_FSACCESS_H */
Save
cmd:
run