summaryrefslogtreecommitdiff
path: root/check/check.h
blob: e37fd1a5d8f2dc5b93e05659005173d85bb6ab9c (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
#ifndef PRIVEXEC_CHECK_H
#define PRIVEXEC_CHECK_H

#ifndef CONFIG_PATH
#define CONFIG_PATH		"/etc/privexec.conf"
#endif

#ifndef PAM_SERVICE_NAME
#define PAM_SERVICE_NAME	"privexec"
#endif

#ifndef PRIVEXEC_LOG_ID
#define PRIVEXEC_LOG_ID		"privexec"
#endif

enum permission_keyword {
	PERM_PASS = 0x1,
	PERM_AUTH = 0x2,
	PERM_DENY = 0x3,
};

enum permission_principal {
	PERM_GROUP = 0x100,
	PERM_USER = 0x200,
};

enum permission_command {
	PERM_ALL = 0x10,
	PERM_CMD = 0x20,
};

enum permission {
	UNKNOWN,

	PASS_GROUP_ALL = PERM_PASS | PERM_GROUP | PERM_ALL,
	AUTH_GROUP_ALL = PERM_AUTH | PERM_GROUP | PERM_ALL,
	DENY_GROUP_ALL = PERM_DENY | PERM_GROUP | PERM_ALL,

	PASS_GROUP_CMD = PERM_PASS | PERM_GROUP | PERM_CMD,
	AUTH_GROUP_CMD = PERM_AUTH | PERM_GROUP | PERM_CMD,
	DENY_GROUP_CMD = PERM_DENY | PERM_GROUP | PERM_CMD,

	PASS_USER_ALL = PERM_PASS | PERM_USER | PERM_ALL,
	AUTH_USER_ALL = PERM_AUTH | PERM_USER | PERM_ALL,
	DENY_USER_ALL = PERM_DENY | PERM_USER | PERM_ALL,

	PASS_USER_CMD = PERM_PASS | PERM_USER | PERM_CMD,
	AUTH_USER_CMD = PERM_AUTH | PERM_USER | PERM_CMD,
	DENY_USER_CMD = PERM_DENY | PERM_USER | PERM_CMD,
};


void fatal(int include_errno, char *fmt, ...);
enum permission get_permission(const char *user, const char *group, const char *cmd);
int authenticate(const char *user);

#endif