The Pedigree Project 0.1
user-namespace.h
1/* Copyright (c) 2026, Pedigree Developers. */
2#ifndef POSIX_USER_NAMESPACE_H
3#define POSIX_USER_NAMESPACE_H
4
5#include "pedigree/kernel/compiler.h"
6#include "pedigree/kernel/process/Mutex.h"
7#include "pedigree/kernel/processor/types.h"
8#include "pedigree/kernel/utilities/SharedPointer.h"
9
10class Thread;
13
14namespace PosixCapabilities {
15enum : unsigned {
16 Chown = 0,
17 DacOverride = 1,
18 DacReadSearch = 2,
19 Fowner = 3,
20 Fsetid = 4,
21 Kill = 5,
22 Setgid = 6,
23 Setuid = 7,
24 Setpcap = 8,
25 NetBindService = 10,
26 NetAdmin = 12,
27 NetRaw = 13,
28 SysChroot = 18,
29 SysPtrace = 19,
30 SysAdmin = 21,
31 SysBoot = 22,
32 SysNice = 23,
33 SysResource = 24,
34 SysTime = 25,
35 Mknod = 27,
36 Setfcap = 31,
37 Last = 40
38};
39constexpr uint64_t All = (uint64_t(1) << (Last + 1)) - 1;
40} // namespace PosixCapabilities
41
42// Published through Thread::SecurityState. Updates replace the entire snapshot.
43class EXPORTED_PUBLIC PosixTaskCredentials {
44 public:
45 UserNamespaceRef userNamespace;
46 uint64_t permitted = 0, effective = 0, inheritable = 0;
47 uint64_t bounding = PosixCapabilities::All, ambient = 0;
48 uint32_t secureBits = 0;
49};
51
52class EXPORTED_PUBLIC PosixUserNamespace {
53 public:
54 static constexpr size_t MaximumRanges = 340;
55 struct Range {
56 uint32_t inside, outside, count, global;
57 };
58
59 PosixUserNamespace(const UserNamespaceRef& parent, uint32_t owner, uint32_t group,
60 bool creatorSetfcap);
61 const UserNamespaceRef& parent() const {
62 return m_Parent;
63 }
64 uint32_t owner() const {
65 return m_Owner;
66 }
67 unsigned depth() const {
68 return m_Depth;
69 }
70 uint64_t identity() const {
71 return m_Identity;
72 }
73 bool toGlobal(bool group, uint32_t id, uint32_t& global, uint32_t count = 1) const;
74 bool fromGlobal(bool group, uint32_t global, uint32_t& id) const;
75 bool groupsAllowed() const;
76 int writeMap(bool group, const char* bytes, size_t length);
77 size_t readMap(bool group, const UserNamespaceRef& viewer, char* bytes, size_t capacity) const;
78 int writeSetgroups(const char* bytes, size_t length);
79
80 private:
81 struct Map {
82 Range ranges[MaximumRanges] = {};
83 size_t count = 0;
84 };
85 const UserNamespaceRef m_Parent;
86 const uint32_t m_Owner, m_Group;
87 const unsigned m_Depth;
88 const uint64_t m_Identity;
89 const bool m_CreatorSetfcap;
90 mutable Mutex m_Lock;
91 Map m_Uids, m_Gids;
92 bool m_GroupsAllowed;
93};
94
95EXPORTED_PUBLIC PosixTaskCredentials posix_task_credentials(Thread& task);
96EXPORTED_PUBLIC UserNamespaceRef posix_user_namespace(Thread& task);
97EXPORTED_PUBLIC bool posix_user_namespace_prepare(Thread& creator, TaskCredentialsRef& result);
98EXPORTED_PUBLIC bool posix_capable(unsigned capability);
99EXPORTED_PUBLIC bool posix_global_capable(unsigned capability);
100EXPORTED_PUBLIC bool posix_namespace_capable(const UserNamespaceRef& space, unsigned capability);
101EXPORTED_PUBLIC bool posix_namespace_capable(Thread& task, const UserNamespaceRef& space,
102 unsigned capability);
103EXPORTED_PUBLIC uint32_t posix_visible_id(bool group, uint32_t global);
104EXPORTED_PUBLIC bool posix_global_id(bool group, uint32_t visible, uint32_t& global);
105EXPORTED_PUBLIC int posix_capability_prctl(int option, unsigned long arg2, unsigned long arg3,
106 unsigned long arg4, unsigned long arg5);
107EXPORTED_PUBLIC bool posix_capabilities_exec(Thread& task, uint32_t globalUid);
108EXPORTED_PUBLIC bool posix_capabilities_uid_change(Thread& task, uint32_t oldReal,
109 uint32_t oldEffective, uint32_t oldSaved,
110 uint32_t newReal, uint32_t newEffective,
111 uint32_t newSaved, uint32_t namespaceRoot);
112EXPORTED_PUBLIC bool posix_capabilities_fsuid_change(Thread& task, uint32_t oldUid, uint32_t newUid,
113 uint32_t namespaceRoot);
114
115#endif
Definition Mutex.h:56