2009-03-03 09:44:41 +00:00
|
|
|
/*
|
2010-03-01 23:38:28 +00:00
|
|
|
* Copyright (C) 2008, 2010 Red Hat, Inc.
|
2009-03-03 09:44:41 +00:00
|
|
|
*
|
|
|
|
* This library is free software; you can redistribute it and/or
|
|
|
|
* modify it under the terms of the GNU Lesser General Public
|
|
|
|
* License as published by the Free Software Foundation; either
|
|
|
|
* version 2.1 of the License, or (at your option) any later version.
|
|
|
|
*
|
|
|
|
* Authors:
|
|
|
|
* James Morris <jmorris@namei.org>
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
#ifndef __VIR_SECURITY_H__
|
|
|
|
#define __VIR_SECURITY_H__
|
|
|
|
|
|
|
|
#include "internal.h"
|
|
|
|
#include "domain_conf.h"
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Return values for security driver probing: the driver will determine
|
|
|
|
* whether it should be enabled or disabled.
|
|
|
|
*/
|
|
|
|
typedef enum {
|
|
|
|
SECURITY_DRIVER_ENABLE = 0,
|
|
|
|
SECURITY_DRIVER_ERROR = -1,
|
|
|
|
SECURITY_DRIVER_DISABLE = -2,
|
|
|
|
} virSecurityDriverStatus;
|
|
|
|
|
|
|
|
typedef struct _virSecurityDriver virSecurityDriver;
|
|
|
|
typedef virSecurityDriver *virSecurityDriverPtr;
|
|
|
|
typedef virSecurityDriverStatus (*virSecurityDriverProbe) (void);
|
2010-02-09 19:18:21 +00:00
|
|
|
typedef int (*virSecurityDriverOpen) (virSecurityDriverPtr drv);
|
|
|
|
typedef int (*virSecurityDomainRestoreImageLabel) (virDomainObjPtr vm,
|
2009-03-17 11:35:40 +00:00
|
|
|
virDomainDiskDefPtr disk);
|
2010-02-09 19:18:21 +00:00
|
|
|
typedef int (*virSecurityDomainSetImageLabel) (virDomainObjPtr vm,
|
2009-03-17 11:35:40 +00:00
|
|
|
virDomainDiskDefPtr disk);
|
2010-02-09 19:18:21 +00:00
|
|
|
typedef int (*virSecurityDomainRestoreHostdevLabel) (virDomainObjPtr vm,
|
2009-08-14 13:23:11 +00:00
|
|
|
virDomainHostdevDefPtr dev);
|
2010-02-09 19:18:21 +00:00
|
|
|
typedef int (*virSecurityDomainSetHostdevLabel) (virDomainObjPtr vm,
|
2009-08-14 13:23:11 +00:00
|
|
|
virDomainHostdevDefPtr dev);
|
2010-02-09 19:18:21 +00:00
|
|
|
typedef int (*virSecurityDomainSetSavedStateLabel) (virDomainObjPtr vm,
|
2009-11-11 12:07:00 +00:00
|
|
|
const char *savefile);
|
2010-02-09 19:18:21 +00:00
|
|
|
typedef int (*virSecurityDomainRestoreSavedStateLabel) (virDomainObjPtr vm,
|
2009-11-11 12:07:00 +00:00
|
|
|
const char *savefile);
|
2010-02-09 19:18:21 +00:00
|
|
|
typedef int (*virSecurityDomainGenLabel) (virDomainObjPtr sec);
|
|
|
|
typedef int (*virSecurityDomainReserveLabel) (virDomainObjPtr sec);
|
|
|
|
typedef int (*virSecurityDomainReleaseLabel) (virDomainObjPtr sec);
|
|
|
|
typedef int (*virSecurityDomainSetAllLabel) (virDomainObjPtr sec);
|
|
|
|
typedef int (*virSecurityDomainRestoreAllLabel) (virDomainObjPtr vm);
|
|
|
|
typedef int (*virSecurityDomainGetProcessLabel) (virDomainObjPtr vm,
|
2010-01-11 11:04:40 +00:00
|
|
|
virSecurityLabelPtr sec);
|
2010-02-09 19:18:21 +00:00
|
|
|
typedef int (*virSecurityDomainSetProcessLabel) (virSecurityDriverPtr drv,
|
2010-01-11 11:04:40 +00:00
|
|
|
virDomainObjPtr vm);
|
2010-02-09 19:18:21 +00:00
|
|
|
typedef int (*virSecurityDomainSecurityVerify) (virDomainDefPtr def);
|
2009-03-03 09:44:41 +00:00
|
|
|
|
|
|
|
struct _virSecurityDriver {
|
|
|
|
const char *name;
|
|
|
|
virSecurityDriverProbe probe;
|
|
|
|
virSecurityDriverOpen open;
|
2009-04-03 10:55:51 +00:00
|
|
|
virSecurityDomainSecurityVerify domainSecurityVerify;
|
2009-03-03 09:44:41 +00:00
|
|
|
virSecurityDomainRestoreImageLabel domainRestoreSecurityImageLabel;
|
|
|
|
virSecurityDomainSetImageLabel domainSetSecurityImageLabel;
|
|
|
|
virSecurityDomainGenLabel domainGenSecurityLabel;
|
2009-06-12 11:38:50 +00:00
|
|
|
virSecurityDomainReserveLabel domainReserveSecurityLabel;
|
2010-01-11 11:04:40 +00:00
|
|
|
virSecurityDomainReleaseLabel domainReleaseSecurityLabel;
|
|
|
|
virSecurityDomainGetProcessLabel domainGetSecurityProcessLabel;
|
|
|
|
virSecurityDomainSetProcessLabel domainSetSecurityProcessLabel;
|
|
|
|
virSecurityDomainSetAllLabel domainSetSecurityAllLabel;
|
|
|
|
virSecurityDomainRestoreAllLabel domainRestoreSecurityAllLabel;
|
2009-08-14 13:23:11 +00:00
|
|
|
virSecurityDomainRestoreHostdevLabel domainRestoreSecurityHostdevLabel;
|
|
|
|
virSecurityDomainSetHostdevLabel domainSetSecurityHostdevLabel;
|
2009-11-11 12:07:00 +00:00
|
|
|
virSecurityDomainSetSavedStateLabel domainSetSavedStateLabel;
|
|
|
|
virSecurityDomainRestoreSavedStateLabel domainRestoreSavedStateLabel;
|
2009-03-03 09:44:41 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* This is internally managed driver state and should only be accessed
|
|
|
|
* via helpers below.
|
|
|
|
*/
|
|
|
|
struct {
|
|
|
|
char doi[VIR_SECURITY_DOI_BUFLEN];
|
|
|
|
} _private;
|
|
|
|
};
|
|
|
|
|
|
|
|
/* Global methods */
|
|
|
|
int virSecurityDriverStartup(virSecurityDriverPtr *drv,
|
|
|
|
const char *name);
|
|
|
|
|
2009-04-03 10:55:51 +00:00
|
|
|
int
|
2010-02-09 19:18:21 +00:00
|
|
|
virSecurityDriverVerify(virDomainDefPtr def);
|
2009-04-03 10:55:51 +00:00
|
|
|
|
2010-03-01 23:38:28 +00:00
|
|
|
#define virSecurityReportError(code, ...) \
|
2010-02-11 23:18:54 +00:00
|
|
|
virReportErrorHelper(NULL, VIR_FROM_SECURITY, code, __FILE__, \
|
2010-03-01 23:38:28 +00:00
|
|
|
__FUNCTION__, __LINE__, __VA_ARGS__)
|
2009-03-03 09:44:41 +00:00
|
|
|
|
|
|
|
/* Helpers */
|
|
|
|
void virSecurityDriverInit(virSecurityDriverPtr drv);
|
2010-02-09 19:18:21 +00:00
|
|
|
int virSecurityDriverSetDOI(virSecurityDriverPtr drv,
|
2009-03-03 09:44:41 +00:00
|
|
|
const char *doi);
|
|
|
|
const char *virSecurityDriverGetDOI(virSecurityDriverPtr drv);
|
|
|
|
const char *virSecurityDriverGetModel(virSecurityDriverPtr drv);
|
|
|
|
|
|
|
|
#endif /* __VIR_SECURITY_H__ */
|