1 /* $NetBSD: capability.h,v 1.3 2021/12/19 01:22:01 riastradh Exp $ */ 2 3 /*- 4 * Copyright (c) 2020 The NetBSD Foundation, Inc. 5 * All rights reserved. 6 * 7 * Redistribution and use in source and binary forms, with or without 8 * modification, are permitted provided that the following conditions 9 * are met: 10 * 1. Redistributions of source code must retain the above copyright 11 * notice, this list of conditions and the following disclaimer. 12 * 2. Redistributions in binary form must reproduce the above copyright 13 * notice, this list of conditions and the following disclaimer in the 14 * documentation and/or other materials provided with the distribution. 15 * 16 * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS 17 * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED 18 * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 19 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS 20 * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 21 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 22 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 23 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 24 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 25 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 26 * POSSIBILITY OF SUCH DAMAGE. 27 */ 28 29 #ifndef _LINUX_CAPABILITY_H_ 30 #define _LINUX_CAPABILITY_H_ 31 32 #include <sys/kauth.h> 33 34 enum linux_capability { 35 LINUX_CAP_SYS_ADMIN, 36 LINUX_CAP_SYS_NICE, 37 #define CAP_SYS_ADMIN LINUX_CAP_SYS_ADMIN 38 #define CAP_SYS_NICE LINUX_CAP_SYS_NICE 39 }; 40 41 static inline bool 42 capable(enum linux_capability cap) 43 { 44 switch (cap) { 45 case CAP_SYS_ADMIN: 46 case CAP_SYS_NICE: 47 return (kauth_authorize_generic(kauth_cred_get(), 48 KAUTH_GENERIC_ISSUSER, NULL) == 0); 49 default: 50 panic("unknown cap %d", cap); 51 } 52 } 53 54 #endif /* _LINUX_CAPABILITY_H_ */ 55