1/*
2 * Copyright (c) 2012-2013 Apple Inc. All rights reserved.
3 *
4 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5 *
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. The rights granted to you under the License
10 * may not be used to create, or enable the creation or redistribution of,
11 * unlawful or unlicensed copies of an Apple operating system, or to
12 * circumvent, violate, or enable the circumvention or violation of, any
13 * terms of an Apple operating system software license agreement.
14 *
15 * Please obtain a copy of the License at
16 * http://www.opensource.apple.com/apsl/ and read it before using this file.
17 *
18 * The Original Code and all software distributed under the License are
19 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23 * Please see the License for the specific language governing rights and
24 * limitations under the License.
25 *
26 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27 */
28
29#ifndef _BANK_BANK_TYPES_H_
30#define _BANK_BANK_TYPES_H_
31
32#include <os/base.h>
33#include <stdint.h>
34#include <mach/mach_types.h>
35
36#define MACH_VOUCHER_ATTR_BANK_NULL ((mach_voucher_attr_recipe_command_t)601)
37#define MACH_VOUCHER_ATTR_BANK_CREATE ((mach_voucher_attr_recipe_command_t)610)
38#define MACH_VOUCHER_ATTR_BANK_MODIFY_PERSONA ((mach_voucher_attr_recipe_command_t)611)
39
40#define MACH_VOUCHER_BANK_CONTENT_SIZE (500)
41
42typedef uint32_t bank_action_t;
43#define BANK_ORIGINATOR_PID 0x1
44#define BANK_PERSONA_TOKEN 0x2
45#define BANK_PERSONA_ID 0x3
46#define BANK_PERSONA_ADOPT_ANY 0x4
47#define BANK_ORIGINATOR_PROXIMATE_PID 0x5
48
49
50#define PROC_PERSONA_INFO_FLAG_ADOPTION_ALLOWED 0x1
51
52struct proc_persona_info {
53 uint64_t unique_pid;
54 int32_t pid;
55 uint32_t flags;
56 uint32_t pidversion;
57 uint32_t persona_id;
58 uint32_t uid;
59 uint32_t gid;
60 uint8_t macho_uuid[16];
61};
62
63struct persona_token {
64 struct proc_persona_info originator;
65 struct proc_persona_info proximate;
66};
67
68struct persona_modify_info {
69 uint32_t persona_id;
70 uint64_t unique_pid;
71};
72
73#ifdef PRIVATE
74/* Redeem bank voucher on behalf of another process while changing the persona */
75#define ENTITLEMENT_PERSONA_MODIFY "com.apple.private.persona.modify"
76#define ENTITLEMENT_PERSONA_NO_PROPAGATE "com.apple.private.personas.no.propagate"
77/* Allow to adopt any persona when spawned in no-persona */
78#define ENTITLEMENT_PERSONA_ADOPT_ANY "com.apple.private.persona.adopt.any"
79#endif /* PRIVATE */
80
81#endif /* _BANK_BANK_TYPES_H_ */
82