Index: stable/10/lib/libc/posix1e/acl_create_entry.3 =================================================================== --- stable/10/lib/libc/posix1e/acl_create_entry.3 (revision 321148) +++ stable/10/lib/libc/posix1e/acl_create_entry.3 (revision 321149) @@ -1,98 +1,98 @@ .\"- .\" Copyright (c) 2001 Chris D. Faulhaber .\" All rights reserved. .\" .\" Redistribution and use in source and binary forms, with or without .\" modification, are permitted provided that the following conditions .\" are met: .\" 1. Redistributions of source code must retain the above copyright .\" notice, this list of conditions and the following disclaimer. .\" 2. Redistributions in binary form must reproduce the above copyright .\" notice, this list of conditions and the following disclaimer in the .\" documentation and/or other materials provided with the distribution. .\" .\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND .\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE .\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE .\" ARE DISCLAIMED. IN NO EVENT SHALL AUTHOR OR CONTRIBUTORS BE LIABLE .\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL .\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS .\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) .\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT .\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF .\" SUCH DAMAGE. .\" .\" $FreeBSD$ .\" .Dd June 25, 2009 .Dt ACL_CREATE_ENTRY 3 .Os .Sh NAME -.Nm acl_create_entry +.Nm acl_create_entry , .Nm acl_create_entry_np .Nd create a new ACL entry .Sh LIBRARY .Lb libc .Sh SYNOPSIS .In sys/types.h .In sys/acl.h .Ft int .Fn acl_create_entry "acl_t *acl_p" "acl_entry_t *entry_p" .Ft int .Fn acl_create_entry_np "acl_t *acl_p" "acl_entry_t *entry_p" "int index" .Sh DESCRIPTION The .Fn acl_create_entry function is a POSIX.1e call that creates a new ACL entry in the ACL pointed to by .Fa acl_p . The .Fn acl_create_entry_np function is a non-portable version that creates the ACL entry at position .Fa index . Positions are numbered starting from zero, i.e. calling .Fn acl_create_entry_np with .Fa index argument equal to zero will prepend the entry to the ACL. .Sh RETURN VALUES .Rv -std acl_create_entry .Sh ERRORS The .Fn acl_create_entry function fails if: .Bl -tag -width Er .It Bq Er EINVAL Argument .Fa acl_p does not point to a pointer to a valid ACL. Argument .Fa index is out of bounds. .It Bq Er ENOMEM The ACL working storage requires more memory than is allowed by the hardware or system-imposed memory management constraints. .El .Sh SEE ALSO .Xr acl 3 , .Xr acl_delete_entry 3 , .Xr acl_get_entry 3 , .Xr posix1e 3 .Sh STANDARDS POSIX.1e is described in IEEE POSIX.1e draft 17. .Sh HISTORY POSIX.1e support was introduced in .Fx 4.0 . The .Fn acl_create_entry function was added in .Fx 5.0 . .Sh AUTHORS The .Fn acl_create_entry function was written by .An Chris D. Faulhaber Aq jedgar@fxp.org . Index: stable/10/lib/libc/posix1e/acl_to_text.3 =================================================================== --- stable/10/lib/libc/posix1e/acl_to_text.3 (revision 321148) +++ stable/10/lib/libc/posix1e/acl_to_text.3 (revision 321149) @@ -1,158 +1,159 @@ .\"- .\" Copyright (c) 2000, 2002 Robert N. M. Watson .\" All rights reserved. .\" .\" This software was developed by Robert Watson for the TrustedBSD Project. .\" .\" Redistribution and use in source and binary forms, with or without .\" modification, are permitted provided that the following conditions .\" are met: .\" 1. Redistributions of source code must retain the above copyright .\" notice, this list of conditions and the following disclaimer. .\" 2. Redistributions in binary form must reproduce the above copyright .\" notice, this list of conditions and the following disclaimer in the .\" documentation and/or other materials provided with the distribution. .\" .\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND .\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE .\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE .\" ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE .\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL .\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS .\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) .\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT .\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF .\" SUCH DAMAGE. .\" .\" $FreeBSD$ .\" .Dd June 25, 2009 .Dt ACL_TO_TEXT 3 .Os .Sh NAME .Nm acl_to_text , .Nm acl_to_text_np .Nd convert an ACL to text .Sh LIBRARY .Lb libc .Sh SYNOPSIS .In sys/types.h .In sys/acl.h .Ft char * .Fn acl_to_text "acl_t acl" "ssize_t *len_p" .Ft char * .Fn acl_to_text_np "acl_t acl" "ssize_t *len_p" "int flags" .Sh DESCRIPTION The .Fn acl_to_text and .Fn acl_to_text_np functions translate the ACL pointed to by argument .Va acl into a NULL terminated character string. If the pointer .Va len_p is not NULL, then the function shall return the length of the string (not including the NULL terminator) in the location pointed to by .Va len_p . If the ACL is POSIX.1e, the format of the text string returned by .Fn acl_to_text -shall be the POSIX.1e long ACL form. If the ACL is NFSv4, the format -of the text string shall be the compact form, unless the +shall be the POSIX.1e long ACL form. +If the ACL is NFSv4, the format of the text string shall be the compact form, unless +the .Va ACL_TEXT_VERBOSE flag is given. .Pp The flags specified are formed by .Em or Ns 'ing the following values .Bl -column -offset 3n "ACL_TEXT_NUMERIC_IDS" .It ACL_TEXT_VERBOSE Ta "Format ACL using verbose form" .It ACL_TEXT_NUMERIC_IDS Ta "Do not resolve IDs into user or group names" .It ACL_TEXT_APPEND_ID Ta "In addition to user and group names, append numeric IDs" .El .Pp This function allocates any memory necessary to contain the string and returns a pointer to the string. The caller should free any releasable memory, when the new string is no longer required, by calling .Xr acl_free 3 with the .Va (void*)char as an argument. .Sh IMPLEMENTATION NOTES .Fx Ns 's support for POSIX.1e interfaces and features is still under development at this time. .Sh RETURN VALUES Upon successful completion, the function shall return a pointer to the long text form of an ACL. Otherwise, a value of .Va (char*)NULL shall be returned and .Va errno shall be set to indicate the error. .Sh ERRORS If any of the following conditions occur, the .Fn acl_to_text function shall return a value of .Va (acl_t)NULL and set .Va errno to the corresponding value: .Bl -tag -width Er .It Bq Er EINVAL Argument .Va acl does not point to a valid ACL. .Pp The ACL denoted by .Va acl contains one or more improperly formed ACL entries, or for some other reason cannot be translated into a text form of an ACL. .It Bq Er ENOMEM The character string to be returned requires more memory than is allowed by the hardware or software-imposed memory management constraints. .El .Sh SEE ALSO .Xr acl 3 , .Xr acl_free 3 , .Xr acl_from_text 3 , .Xr posix1e 3 .Sh STANDARDS POSIX.1e is described in IEEE POSIX.1e draft 17. Discussion of the draft continues on the cross-platform POSIX.1e implementation mailing list. To join this list, see the .Fx POSIX.1e implementation page for more information. .Sh HISTORY POSIX.1e support was introduced in .Fx 4.0 , and development continues. .Sh AUTHORS .An Robert N M Watson .Sh BUGS The .Fn acl_from_text and .Fn acl_to_text functions rely on the .Xr getpwent 3 library calls to manage username and uid mapping, as well as the .Xr getgrent 3 library calls to manage groupname and gid mapping. These calls are not thread safe, and so transitively, neither are .Fn acl_from_text and .Fn acl_to_text . These functions may also interfere with stateful calls associated with the .Fn getpwent and .Fn getgrent calls. Index: stable/10/lib/libc/posix1e/posix1e.3 =================================================================== --- stable/10/lib/libc/posix1e/posix1e.3 (revision 321148) +++ stable/10/lib/libc/posix1e/posix1e.3 (revision 321149) @@ -1,118 +1,118 @@ .\"- .\" Copyright (c) 2000, 2009 Robert N. M. Watson .\" All rights reserved. .\" .\" Redistribution and use in source and binary forms, with or without .\" modification, are permitted provided that the following conditions .\" are met: .\" 1. Redistributions of source code must retain the above copyright .\" notice, this list of conditions and the following disclaimer. .\" 2. Redistributions in binary form must reproduce the above copyright .\" notice, this list of conditions and the following disclaimer in the .\" documentation and/or other materials provided with the distribution. .\" .\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND .\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE .\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE .\" ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE .\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL .\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS .\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) .\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT .\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF .\" SUCH DAMAGE. .\" .\" $FreeBSD$ .\" .Dd April 15, 2014 .Dt POSIX1E 3 .Os .Sh NAME .Nm posix1e .Nd introduction to the POSIX.1e security API .Sh LIBRARY .Lb libc .Sh SYNOPSIS .In sys/types.h .In sys/acl.h .In sys/mac.h .Sh DESCRIPTION POSIX.1e describes five security extensions to the POSIX.1 API: Access Control Lists (ACLs), Auditing, Capabilities, Mandatory Access Control, and Information Flow Labels. While IEEE POSIX.1e D17 specification has not been standardized, several of its interfaces are widely used. .Pp .Fx implements POSIX.1e interface for access control lists, described in .Xr acl 3 , and supports ACLs on the .Xr ffs 7 file system; ACLs must be administratively enabled using .Xr tunefs 8 . .Pp .Fx implements a POSIX.1e-like mandatory access control interface, described in .Xr mac 3 , although with a number of extensions and important semantic differences. .Pp .Fx does not implement the POSIX.1e audit, privilege (capability), or information flow label APIs. However, .Fx does implement the -.Xr libbsm +.Xr libbsm 3 audit API. It also provides .Xr capsicum 4 , a lightweight OS capability and sandbox framework implementing a hybrid capability system model. .Sh ENVIRONMENT POSIX.1e assigns security attributes to all objects, extending the security functionality described in POSIX.1. These additional attributes store fine-grained discretionary access control information and mandatory access control labels; for files, they are stored in extended attributes, described in .Xr extattr 3 . .Pp POSIX.2c describes a set of userland utilities for manipulating these attributes, including .Xr getfacl 1 and .Xr setfacl 1 for access control lists, and .Xr getfmac 8 and .Xr setfmac 8 for mandatory access control labels. .Sh SEE ALSO .Xr getfacl 1 , .Xr setfacl 1 , .Xr extattr 2 , .Xr acl 3 , .Xr extattr 3 , .Xr libcapsicum 3 , .Xr libbsm 3 , .Xr mac 3 , .Xr capsicum 4 , .Xr ffs 7 , .Xr getfmac 8 , .Xr setfmac 8 , .Xr tunefs 8 , .Xr acl 9 , .Xr extattr 9 , .Xr mac 9 .Sh STANDARDS POSIX.1e is described in IEEE POSIX.1e draft 17. .Sh HISTORY POSIX.1e support was introduced in .Fx 4.0 ; most features were available as of .Fx 5.0 . .Sh AUTHORS .An Robert N M Watson .An Chris D. Faulhaber .An Thomas Moestl .An Ilmar S Habibulin Index: stable/10 =================================================================== --- stable/10 (revision 321148) +++ stable/10 (revision 321149) Property changes on: stable/10 ___________________________________________________________________ Modified: svn:mergeinfo ## -0,0 +0,1 ## Merged /head:r318704,318708-318709