1 /*
   2  * CDDL HEADER START
   3  *
   4  * The contents of this file are subject to the terms of the
   5  * Common Development and Distribution License (the "License").
   6  * You may not use this file except in compliance with the License.
   7  *
   8  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
   9  * or http://www.opensolaris.org/os/licensing.
  10  * See the License for the specific language governing permissions
  11  * and limitations under the License.
  12  *
  13  * When distributing Covered Code, include this CDDL HEADER in each
  14  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
  15  * If applicable, add the following below this CDDL HEADER, with the
  16  * fields enclosed by brackets "[]" replaced with your own identifying
  17  * information: Portions Copyright [yyyy] [name of copyright owner]
  18  *
  19  * CDDL HEADER END
  20  */
  21 
  22 /*
  23  * Copyright (c) 2003, 2010, Oracle and/or its affiliates. All rights reserved.
  24  * Copyright 2015, Joyent, Inc.
  25  */
  26 
  27 #ifndef _LIBZONECFG_H
  28 #define _LIBZONECFG_H
  29 
  30 /*
  31  * Zone configuration header file.
  32  */
  33 
  34 #ifdef __cplusplus
  35 extern "C" {
  36 #endif
  37 
  38 /* sys/socket.h is required by net/if.h, which has a constant needed here */
  39 #include <sys/param.h>
  40 #include <sys/fstyp.h>
  41 #include <sys/mount.h>
  42 #include <priv.h>
  43 #include <netinet/in.h>
  44 #include <sys/socket.h>
  45 #include <net/if.h>
  46 #include <sys/mac.h>
  47 #include <stdio.h>
  48 #include <rctl.h>
  49 #include <zone.h>
  50 #include <libbrand.h>
  51 #include <sys/uuid.h>
  52 #include <libuutil.h>
  53 #include <sys/mnttab.h>
  54 #include <limits.h>
  55 #include <utmpx.h>
  56 
  57 #define ZONE_ID_UNDEFINED       -1
  58 
  59 #define Z_OK                    0
  60 #define Z_EMPTY_DOCUMENT        1       /* XML doc root element is null */
  61 #define Z_WRONG_DOC_TYPE        2       /* top-level XML doc element != zone */
  62 #define Z_BAD_PROPERTY          3       /* libxml-level property problem */
  63 #define Z_TEMP_FILE             4       /* problem creating temporary file */
  64 #define Z_SAVING_FILE           5       /* libxml error saving or validating */
  65 #define Z_NO_ENTRY              6       /* no such entry */
  66 #define Z_BOGUS_ZONE_NAME       7       /* illegal zone name */
  67 #define Z_REQD_RESOURCE_MISSING 8       /* required resource missing */
  68 #define Z_REQD_PROPERTY_MISSING 9       /* required property missing */
  69 #define Z_BAD_HANDLE            10      /* bad document handle */
  70 #define Z_NOMEM                 11      /* out of memory (like ENOMEM) */
  71 #define Z_INVAL                 12      /* invalid argument (like EINVAL) */
  72 #define Z_ACCES                 13      /* permission denied (like EACCES) */
  73 #define Z_TOO_BIG               14      /* string won't fit in char array */
  74 #define Z_MISC_FS               15      /* miscellaneous file-system error */
  75 #define Z_NO_ZONE               16      /* no such zone */
  76 #define Z_NO_RESOURCE_TYPE      17      /* no/wrong resource type */
  77 #define Z_NO_RESOURCE_ID        18      /* no/wrong resource id */
  78 #define Z_NO_PROPERTY_TYPE      19      /* no/wrong property type */
  79 #define Z_NO_PROPERTY_ID        20      /* no/wrong property id */
  80 #define Z_BAD_ZONE_STATE        21      /* zone state invalid for given task */
  81 #define Z_INVALID_DOCUMENT      22      /* libxml can't validate against DTD */
  82 #define Z_NAME_IN_USE           23      /* zone name already in use (rename) */
  83 #define Z_NO_SUCH_ID            24      /* delete_index: no old ID */
  84 #define Z_UPDATING_INDEX        25      /* add/modify/delete_index problem */
  85 #define Z_LOCKING_FILE          26      /* problem locking index file */
  86 #define Z_UNLOCKING_FILE        27      /* problem unlocking index file */
  87 #define Z_SYSTEM                28      /* consult errno instead */
  88 #define Z_INSUFFICIENT_SPEC     29      /* resource insufficiently specified */
  89 #define Z_RESOLVED_PATH         34      /* resolved path mismatch */
  90 #define Z_IPV6_ADDR_PREFIX_LEN  35      /* IPv6 address prefix length needed */
  91 #define Z_BOGUS_ADDRESS         36      /* not IPv[4|6] address or host name */
  92 #define Z_PRIV_PROHIBITED       37      /* specified privilege is prohibited */
  93 #define Z_PRIV_REQUIRED         38      /* required privilege is missing */
  94 #define Z_PRIV_UNKNOWN          39      /* specified privilege is unknown */
  95 #define Z_BRAND_ERROR           40      /* brand-specific error */
  96 #define Z_INCOMPATIBLE          41      /* incompatible settings */
  97 #define Z_ALIAS_DISALLOW        42      /* rctl alias disallowed */
  98 #define Z_CLEAR_DISALLOW        43      /* clear property disallowed */
  99 #define Z_POOL                  44      /* generic libpool error */
 100 #define Z_POOLS_NOT_ACTIVE      45      /* pool service not enabled */
 101 #define Z_POOL_ENABLE           46      /* pools enable failed */
 102 #define Z_NO_POOL               47      /* no such pool configured */
 103 #define Z_POOL_CREATE           48      /* pool create failed */
 104 #define Z_POOL_BIND             49      /* pool bind failed */
 105 #define Z_INVALID_PROPERTY      50      /* invalid property value */
 106 
 107 /*
 108  * Warning: these are shared with the admin/install consolidation.
 109  * Do not insert states between any of the currently defined states,
 110  * and any new states must be evaluated for impact on range comparisons.
 111  */
 112 #define ZONE_STATE_CONFIGURED           0
 113 #define ZONE_STATE_INCOMPLETE           1
 114 #define ZONE_STATE_INSTALLED            2
 115 #define ZONE_STATE_READY                3
 116 #define ZONE_STATE_RUNNING              4
 117 #define ZONE_STATE_SHUTTING_DOWN        5
 118 #define ZONE_STATE_DOWN                 6
 119 #define ZONE_STATE_MOUNTED              7
 120 
 121 #define ZONE_STATE_MAXSTRLEN    14
 122 
 123 #define ZONE_PROP_MAXSTRLEN     1024
 124 
 125 #define LIBZONECFG_PATH         "libzonecfg.so.1"
 126 
 127 #define ZONE_CONFIG_ROOT        "/etc/zones"
 128 #define ZONE_INDEX_FILE         ZONE_CONFIG_ROOT "/index"
 129 
 130 #define MAXUSERNAME             (sizeof (((struct utmpx *)0)->ut_name))
 131 #define MAXAUTHS                4096
 132 #define ZONE_MGMT_PROF          "Zone Management"
 133 
 134 #define ZONE_INT32SZ            11              /* string to hold 32bit int. */
 135 
 136 /* Owner, group, and mode (defined by packaging) for the config directory */
 137 #define ZONE_CONFIG_UID         0               /* root */
 138 #define ZONE_CONFIG_GID         3               /* sys */
 139 #define ZONE_CONFIG_MODE        0755
 140 
 141 /* Owner, group, and mode (defined by packaging) for the index file */
 142 #define ZONE_INDEX_UID          0               /* root */
 143 #define ZONE_INDEX_GID          3               /* sys */
 144 #define ZONE_INDEX_MODE         0644
 145 
 146 /* The maximum length of the VERSION string in the pkginfo(4) file. */
 147 #define ZONE_PKG_VERSMAX        256
 148 
 149 /*
 150  * Shortened alias names for the zones rctls.
 151  */
 152 #define ALIAS_MAXLWPS           "max-lwps"
 153 #define ALIAS_MAXSHMMEM         "max-shm-memory"
 154 #define ALIAS_MAXSHMIDS         "max-shm-ids"
 155 #define ALIAS_MAXMSGIDS         "max-msg-ids"
 156 #define ALIAS_MAXSEMIDS         "max-sem-ids"
 157 #define ALIAS_MAXLOCKEDMEM      "locked"
 158 #define ALIAS_MAXSWAP           "swap"
 159 #define ALIAS_MAXPHYSMEM        "physical"
 160 #define ALIAS_SHARES            "cpu-shares"
 161 #define ALIAS_CPUCAP            "cpu-cap"
 162 #define ALIAS_MAXPROCS          "max-processes"
 163 #define ALIAS_ZFSPRI            "zfs-io-priority"
 164 
 165 /* Default name for zone detached manifest */
 166 #define ZONE_DETACHED   "SUNWdetached.xml"
 167 
 168 /*
 169  * Bit flag definitions for passing into libzonecfg functions.
 170  */
 171 #define ZONE_DRY_RUN            0x01
 172 
 173 typedef enum zone_iptype {
 174         ZS_SHARED,
 175         ZS_EXCLUSIVE
 176 } zone_iptype_t;
 177 
 178 /*
 179  * The integer field expresses the current values on a get.
 180  * On a put, it represents the new values if >= 0 or "don't change" if < 0.
 181  */
 182 struct zoneent {
 183         char    zone_name[ZONENAME_MAX];        /* name of the zone */
 184         int     zone_state;     /* configured | incomplete | installed */
 185         char    zone_path[MAXPATHLEN];          /* path to zone storage */
 186         uuid_t  zone_uuid;                      /* unique ID for zone */
 187         char    zone_newname[ZONENAME_MAX];     /* for doing renames */
 188         char    zone_brand[MAXNAMELEN];         /* zone's brand */
 189         zone_iptype_t zone_iptype;              /* zone's IP type */
 190         zoneid_t zone_did;                      /* persistent debug ID */
 191 };
 192 
 193 typedef struct zone_dochandle *zone_dochandle_t;        /* opaque handle */
 194 
 195 typedef uint_t zone_state_t;
 196 
 197 typedef struct zone_fsopt {
 198         struct zone_fsopt *zone_fsopt_next;
 199         char               zone_fsopt_opt[MAX_MNTOPT_STR];
 200 } zone_fsopt_t;
 201 
 202 struct zone_fstab {
 203         char            zone_fs_special[MAXPATHLEN];    /* special file */
 204         char            zone_fs_dir[MAXPATHLEN];        /* mount point */
 205         char            zone_fs_type[FSTYPSZ];          /* e.g. ufs */
 206         zone_fsopt_t   *zone_fs_options;                /* mount options */
 207         char            zone_fs_raw[MAXPATHLEN];        /* device to fsck */
 208 };
 209 
 210 /*
 211  * Generic resource attribute list.
 212  * Key/value resource that can be attached to net or device.
 213  */
 214 struct zone_res_attrtab {
 215         char    zone_res_attr_name[MAXNAMELEN];
 216         char    zone_res_attr_value[ZONE_PROP_MAXSTRLEN];
 217         struct zone_res_attrtab *zone_res_attr_next;
 218 };
 219 
 220 struct zone_nwiftab {
 221         char    zone_nwif_address[INET6_ADDRSTRLEN]; /* shared-ip only */
 222         char    zone_nwif_allowed_address[INET6_ADDRSTRLEN]; /* excl-ip only */
 223         char    zone_nwif_physical[LIFNAMSIZ];
 224         char    zone_nwif_mac[MAXMACADDRLEN];           /* excl-ip only */
 225         char    zone_nwif_vlan_id[ZONE_INT32SZ];        /* excl-ip only */
 226         char    zone_nwif_gnic[LIFNAMSIZ];              /* excl-ip only */
 227         char    zone_nwif_defrouter[INET6_ADDRSTRLEN];
 228         struct zone_res_attrtab *zone_nwif_attrp;
 229 };
 230 
 231 struct zone_devtab {
 232         char    zone_dev_match[MAXPATHLEN];
 233         struct zone_res_attrtab *zone_dev_attrp;
 234 };
 235 
 236 struct zone_rctlvaltab {
 237         char    zone_rctlval_priv[MAXNAMELEN];
 238         char    zone_rctlval_limit[MAXNAMELEN];
 239         char    zone_rctlval_action[MAXNAMELEN];
 240         struct zone_rctlvaltab *zone_rctlval_next;
 241 };
 242 
 243 struct zone_rctltab {
 244         char    zone_rctl_name[MAXNAMELEN];
 245         struct zone_rctlvaltab *zone_rctl_valptr;
 246 };
 247 
 248 struct zone_attrtab {
 249         char    zone_attr_name[MAXNAMELEN];
 250         char    zone_attr_type[MAXNAMELEN];
 251         char    zone_attr_value[2 * BUFSIZ];
 252 };
 253 
 254 struct zone_dstab {
 255         char    zone_dataset_name[MAXNAMELEN];
 256 };
 257 
 258 struct zone_psettab {
 259         char    zone_ncpu_min[MAXNAMELEN];
 260         char    zone_ncpu_max[MAXNAMELEN];
 261         char    zone_importance[MAXNAMELEN];
 262 };
 263 
 264 struct zone_pkgtab {
 265         char    zone_pkg_name[MAXNAMELEN];
 266         char    zone_pkg_version[ZONE_PKG_VERSMAX];
 267 };
 268 
 269 struct zone_devpermtab {
 270         char    zone_devperm_name[MAXPATHLEN];
 271         uid_t   zone_devperm_uid;
 272         gid_t   zone_devperm_gid;
 273         mode_t  zone_devperm_mode;
 274         char    *zone_devperm_acl;
 275 };
 276 
 277 struct zone_admintab {
 278         char    zone_admin_user[MAXUSERNAME];
 279         char    zone_admin_auths[MAXAUTHS];
 280 };
 281 
 282 typedef struct zone_userauths {
 283         char                    user[MAXUSERNAME];
 284         char                    zonename[ZONENAME_MAX];
 285         struct zone_userauths   *next;
 286 } zone_userauths_t;
 287 
 288 typedef struct {
 289         uu_avl_node_t   zpe_entry;
 290         char            *zpe_name;
 291         char            *zpe_vers;
 292 } zone_pkg_entry_t;
 293 
 294 /*
 295  * Basic configuration management routines.
 296  */
 297 extern  zone_dochandle_t        zonecfg_init_handle(void);
 298 extern  int     zonecfg_get_handle(const char *, zone_dochandle_t);
 299 extern  int     zonecfg_get_snapshot_handle(const char *, zone_dochandle_t);
 300 extern  int     zonecfg_get_template_handle(const char *, const char *,
 301     zone_dochandle_t);
 302 extern  int     zonecfg_get_xml_handle(const char *, zone_dochandle_t);
 303 extern  int     zonecfg_check_handle(zone_dochandle_t);
 304 extern  void    zonecfg_fini_handle(zone_dochandle_t);
 305 extern  int     zonecfg_destroy(const char *, boolean_t);
 306 extern  int     zonecfg_destroy_snapshot(const char *);
 307 extern  int     zonecfg_save(zone_dochandle_t);
 308 extern  int     zonecfg_create_snapshot(const char *);
 309 extern  char    *zonecfg_strerror(int);
 310 extern  int     zonecfg_access(const char *, int);
 311 extern  void    zonecfg_set_root(const char *);
 312 extern  const char *zonecfg_get_root(void);
 313 extern  boolean_t zonecfg_in_alt_root(void);
 314 extern  int     zonecfg_num_resources(zone_dochandle_t, char *);
 315 extern  int     zonecfg_del_all_resources(zone_dochandle_t, char *);
 316 extern  boolean_t zonecfg_valid_ncpus(char *, char *);
 317 extern  boolean_t zonecfg_valid_importance(char *);
 318 extern  int     zonecfg_str_to_bytes(char *, uint64_t *);
 319 extern  boolean_t zonecfg_valid_memlimit(char *, uint64_t *);
 320 extern  boolean_t zonecfg_valid_alias_limit(char *, char *, uint64_t *);
 321 extern  void    zonecfg_notify_create(zone_dochandle_t);
 322 
 323 /*
 324  * Zone name, path to zone directory, autoboot setting, pool, boot
 325  * arguments, and scheduling-class.
 326  */
 327 extern  int     zonecfg_validate_zonename(const char *);
 328 extern  int     zonecfg_get_name(zone_dochandle_t, char *, size_t);
 329 extern  int     zonecfg_set_name(zone_dochandle_t, char *);
 330 extern  int     zonecfg_get_zonepath(zone_dochandle_t, char *, size_t);
 331 extern  int     zonecfg_set_zonepath(zone_dochandle_t, char *);
 332 extern  int     zonecfg_get_autoboot(zone_dochandle_t, boolean_t *);
 333 extern  int     zonecfg_set_autoboot(zone_dochandle_t, boolean_t);
 334 extern  int     zonecfg_get_iptype(zone_dochandle_t, zone_iptype_t *);
 335 extern  int     zonecfg_set_iptype(zone_dochandle_t, zone_iptype_t);
 336 extern  int     zonecfg_get_pool(zone_dochandle_t, char *, size_t);
 337 extern  int     zonecfg_set_pool(zone_dochandle_t, char *);
 338 extern  int     zonecfg_get_bootargs(zone_dochandle_t, char *, size_t);
 339 extern  int     zonecfg_set_bootargs(zone_dochandle_t, char *);
 340 extern  int     zonecfg_get_sched_class(zone_dochandle_t, char *, size_t);
 341 extern  int     zonecfg_set_sched(zone_dochandle_t, char *);
 342 extern  int     zonecfg_get_dflt_sched_class(zone_dochandle_t, char *, int);
 343 extern  zoneid_t zonecfg_get_did(zone_dochandle_t);
 344 extern  void    zonecfg_set_did(zone_dochandle_t);
 345 
 346 /*
 347  * Set/retrieve the brand for the zone
 348  */
 349 extern  int     zonecfg_get_brand(zone_dochandle_t, char *, size_t);
 350 extern  int     zonecfg_set_brand(zone_dochandle_t, char *);
 351 
 352 /*
 353  * Filesystem configuration.
 354  */
 355 extern  int     zonecfg_add_filesystem(zone_dochandle_t, struct zone_fstab *);
 356 extern  int     zonecfg_delete_filesystem(zone_dochandle_t,
 357     struct zone_fstab *);
 358 extern  int     zonecfg_modify_filesystem(zone_dochandle_t,
 359     struct zone_fstab *, struct zone_fstab *);
 360 extern  int     zonecfg_lookup_filesystem(zone_dochandle_t,
 361     struct zone_fstab *);
 362 extern  int     zonecfg_add_fs_option(struct zone_fstab *, char *);
 363 extern  int     zonecfg_remove_fs_option(struct zone_fstab *, char *);
 364 extern  void    zonecfg_free_fs_option_list(zone_fsopt_t *);
 365 extern  int     zonecfg_find_mounts(char *, int(*)(const struct mnttab *,
 366     void *), void *);
 367 
 368 /*
 369  * Resource key/value attributes (properties).
 370  */
 371 extern  int     zonecfg_add_res_attr(struct zone_res_attrtab **,
 372     struct zone_res_attrtab *);
 373 extern  void    zonecfg_free_res_attr_list(struct zone_res_attrtab *);
 374 extern  int     zonecfg_remove_res_attr(struct zone_res_attrtab **,
 375     struct zone_res_attrtab *);
 376 
 377 /*
 378  * Network interface configuration.
 379  */
 380 extern  int     zonecfg_add_nwif(zone_dochandle_t, struct zone_nwiftab *);
 381 extern  int     zonecfg_delete_nwif(zone_dochandle_t, struct zone_nwiftab *);
 382 extern  int     zonecfg_modify_nwif(zone_dochandle_t, struct zone_nwiftab *,
 383     struct zone_nwiftab *);
 384 extern  int     zonecfg_lookup_nwif(zone_dochandle_t, struct zone_nwiftab *);
 385 
 386 /*
 387  * Hostid emulation configuration.
 388  */
 389 extern  int     zonecfg_get_hostid(zone_dochandle_t, char *, size_t);
 390 extern  int     zonecfg_set_hostid(zone_dochandle_t, const char *);
 391 
 392 /*
 393  * Allowed FS mounts configuration.
 394  */
 395 extern int      zonecfg_get_fs_allowed(zone_dochandle_t, char *, size_t);
 396 extern int      zonecfg_set_fs_allowed(zone_dochandle_t, const char *);
 397 
 398 /*
 399  * Device configuration and rule matching.
 400  */
 401 extern  int     zonecfg_add_dev(zone_dochandle_t, struct zone_devtab *);
 402 extern  int     zonecfg_delete_dev(zone_dochandle_t, struct zone_devtab *);
 403 extern  int     zonecfg_modify_dev(zone_dochandle_t, struct zone_devtab *,
 404     struct zone_devtab *);
 405 extern  int     zonecfg_lookup_dev(zone_dochandle_t, struct zone_devtab *);
 406 
 407 /*
 408  * Resource control configuration.
 409  */
 410 extern  int     zonecfg_add_rctl(zone_dochandle_t, struct zone_rctltab *);
 411 extern  int     zonecfg_delete_rctl(zone_dochandle_t, struct zone_rctltab *);
 412 extern  int     zonecfg_modify_rctl(zone_dochandle_t, struct zone_rctltab *,
 413     struct zone_rctltab *);
 414 extern  int     zonecfg_lookup_rctl(zone_dochandle_t, struct zone_rctltab *);
 415 extern  int     zonecfg_add_rctl_value(struct zone_rctltab *,
 416     struct zone_rctlvaltab *);
 417 extern  int     zonecfg_remove_rctl_value(struct zone_rctltab *,
 418     struct zone_rctlvaltab *);
 419 extern  void    zonecfg_free_rctl_value_list(struct zone_rctlvaltab *);
 420 extern  boolean_t zonecfg_aliased_rctl_ok(zone_dochandle_t, char *);
 421 extern  int     zonecfg_set_aliased_rctl(zone_dochandle_t, char *, uint64_t);
 422 extern  int     zonecfg_get_aliased_rctl(zone_dochandle_t, char *, uint64_t *);
 423 extern  int     zonecfg_rm_aliased_rctl(zone_dochandle_t, char *);
 424 extern  int     zonecfg_apply_rctls(char *, zone_dochandle_t);
 425 
 426 /*
 427  * Generic attribute configuration and type/value extraction.
 428  */
 429 extern  int     zonecfg_add_attr(zone_dochandle_t, struct zone_attrtab *);
 430 extern  int     zonecfg_delete_attr(zone_dochandle_t, struct zone_attrtab *);
 431 extern  int     zonecfg_modify_attr(zone_dochandle_t, struct zone_attrtab *,
 432     struct zone_attrtab *);
 433 extern  int     zonecfg_lookup_attr(zone_dochandle_t, struct zone_attrtab *);
 434 extern  int     zonecfg_get_attr_boolean(const struct zone_attrtab *,
 435     boolean_t *);
 436 extern  int     zonecfg_get_attr_int(const struct zone_attrtab *, int64_t *);
 437 extern  int     zonecfg_get_attr_string(const struct zone_attrtab *, char *,
 438     size_t);
 439 extern  int     zonecfg_get_attr_uint(const struct zone_attrtab *, uint64_t *);
 440 
 441 /*
 442  * ZFS configuration.
 443  */
 444 extern  int     zonecfg_add_ds(zone_dochandle_t, struct zone_dstab *);
 445 extern  int     zonecfg_delete_ds(zone_dochandle_t, struct zone_dstab *);
 446 extern  int     zonecfg_modify_ds(zone_dochandle_t, struct zone_dstab *,
 447     struct zone_dstab *);
 448 extern  int     zonecfg_lookup_ds(zone_dochandle_t, struct zone_dstab *);
 449 
 450 /*
 451  * cpu-set configuration.
 452  */
 453 extern  int     zonecfg_add_pset(zone_dochandle_t, struct zone_psettab *);
 454 extern  int     zonecfg_delete_pset(zone_dochandle_t);
 455 extern  int     zonecfg_modify_pset(zone_dochandle_t, struct zone_psettab *);
 456 extern  int     zonecfg_lookup_pset(zone_dochandle_t, struct zone_psettab *);
 457 
 458 /*
 459  * Temporary pool support functions.
 460  */
 461 extern  int     zonecfg_destroy_tmp_pool(char *, char *, int);
 462 extern  int     zonecfg_bind_tmp_pool(zone_dochandle_t, zoneid_t, char *, int);
 463 extern  int     zonecfg_bind_pool(zone_dochandle_t, zoneid_t, char *, int);
 464 extern  boolean_t zonecfg_warn_poold(zone_dochandle_t);
 465 extern  int     zonecfg_get_poolname(zone_dochandle_t, char *, char *, size_t);
 466 
 467 /*
 468  * Miscellaneous utility functions.
 469  */
 470 extern  int     zonecfg_enable_rcapd(char *, int);
 471 
 472 /*
 473  * attach/detach support.
 474  */
 475 extern  int     zonecfg_get_attach_handle(const char *, const char *,
 476     const char *, boolean_t, zone_dochandle_t);
 477 extern  int     zonecfg_attach_manifest(int, zone_dochandle_t,
 478     zone_dochandle_t);
 479 extern  int     zonecfg_detach_save(zone_dochandle_t, uint_t);
 480 extern  boolean_t zonecfg_detached(const char *);
 481 extern  void    zonecfg_rm_detached(zone_dochandle_t, boolean_t forced);
 482 extern  int     zonecfg_dev_manifest(zone_dochandle_t);
 483 extern  int     zonecfg_devperms_apply(zone_dochandle_t, const char *,
 484     uid_t, gid_t, mode_t, const char *);
 485 extern  void    zonecfg_set_swinv(zone_dochandle_t);
 486 extern  int     zonecfg_add_pkg(zone_dochandle_t, char *, char *);
 487 
 488 /*
 489  * External zone verification support.
 490  */
 491 extern  int     zonecfg_verify_save(zone_dochandle_t, char *);
 492 
 493 /*
 494  * '*ent' iterator routines.
 495  */
 496 extern  int     zonecfg_setfsent(zone_dochandle_t);
 497 extern  int     zonecfg_getfsent(zone_dochandle_t, struct zone_fstab *);
 498 extern  int     zonecfg_endfsent(zone_dochandle_t);
 499 extern  int     zonecfg_setnwifent(zone_dochandle_t);
 500 extern  int     zonecfg_getnwifent(zone_dochandle_t, struct zone_nwiftab *);
 501 extern  int     zonecfg_endnwifent(zone_dochandle_t);
 502 extern  int     zonecfg_setdevent(zone_dochandle_t);
 503 extern  int     zonecfg_getdevent(zone_dochandle_t, struct zone_devtab *);
 504 extern  int     zonecfg_enddevent(zone_dochandle_t);
 505 extern  int     zonecfg_setattrent(zone_dochandle_t);
 506 extern  int     zonecfg_getattrent(zone_dochandle_t, struct zone_attrtab *);
 507 extern  int     zonecfg_endattrent(zone_dochandle_t);
 508 extern  int     zonecfg_setrctlent(zone_dochandle_t);
 509 extern  int     zonecfg_getrctlent(zone_dochandle_t, struct zone_rctltab *);
 510 extern  int     zonecfg_endrctlent(zone_dochandle_t);
 511 extern  int     zonecfg_setdsent(zone_dochandle_t);
 512 extern  int     zonecfg_getdsent(zone_dochandle_t, struct zone_dstab *);
 513 extern  int     zonecfg_enddsent(zone_dochandle_t);
 514 extern  int     zonecfg_getpsetent(zone_dochandle_t, struct zone_psettab *);
 515 extern  int     zonecfg_getpkgdata(zone_dochandle_t, uu_avl_pool_t *,
 516     uu_avl_t *);
 517 extern  int     zonecfg_setdevperment(zone_dochandle_t);
 518 extern  int     zonecfg_getdevperment(zone_dochandle_t,
 519     struct zone_devpermtab *);
 520 extern  int     zonecfg_enddevperment(zone_dochandle_t);
 521 extern  int     zonecfg_setadminent(zone_dochandle_t);
 522 extern  int     zonecfg_getadminent(zone_dochandle_t, struct zone_admintab *);
 523 extern  int     zonecfg_endadminent(zone_dochandle_t);
 524 
 525 /*
 526  * Privilege-related functions.
 527  */
 528 extern  int     zonecfg_default_privset(priv_set_t *, const char *);
 529 extern  int     zonecfg_get_privset(zone_dochandle_t, priv_set_t *,
 530     char **);
 531 extern  int     zonecfg_get_limitpriv(zone_dochandle_t, char **);
 532 extern  int     zonecfg_set_limitpriv(zone_dochandle_t, char *);
 533 
 534 /*
 535  * Higher-level routines.
 536  */
 537 extern  int     zone_get_brand(char *, char *, size_t);
 538 extern  zoneid_t zone_get_did(char *);
 539 extern  int     zone_get_rootpath(char *, char *, size_t);
 540 extern  int     zone_get_devroot(char *, char *, size_t);
 541 extern  int     zone_get_zonepath(char *, char *, size_t);
 542 extern  int     zone_get_state(char *, zone_state_t *);
 543 extern  int     zone_set_state(char *, zone_state_t);
 544 extern  char    *zone_state_str(zone_state_t);
 545 extern  int     zonecfg_get_name_by_uuid(const uuid_t, char *, size_t);
 546 extern  int     zonecfg_get_uuid(const char *, uuid_t);
 547 extern  int     zonecfg_set_uuid(const char *, const char *, const char *);
 548 extern  int     zonecfg_default_brand(char *, size_t);
 549 extern  int     zonecfg_fix_obsolete(zone_dochandle_t);
 550 
 551 /*
 552  * Iterator for configured zones.
 553  */
 554 extern FILE             *setzoneent(void);
 555 extern char             *getzoneent(FILE *);
 556 extern struct zoneent   *getzoneent_private(FILE *);
 557 extern void             endzoneent(FILE *);
 558 
 559 /*
 560  * File-system-related convenience functions.
 561  */
 562 extern boolean_t zonecfg_valid_fs_type(const char *);
 563 
 564 /*
 565  * Network-related convenience functions.
 566  */
 567 extern boolean_t zonecfg_same_net_address(char *, char *);
 568 extern int zonecfg_valid_net_address(char *, struct lifreq *);
 569 extern boolean_t zonecfg_ifname_exists(sa_family_t, char *);
 570 
 571 /*
 572  * Rctl-related common functions.
 573  */
 574 extern boolean_t zonecfg_is_rctl(const char *);
 575 extern boolean_t zonecfg_valid_rctlname(const char *);
 576 extern boolean_t zonecfg_valid_rctlblk(const rctlblk_t *);
 577 extern boolean_t zonecfg_valid_rctl(const char *, const rctlblk_t *);
 578 extern int zonecfg_construct_rctlblk(const struct zone_rctlvaltab *,
 579     rctlblk_t *);
 580 
 581 /*
 582  * Live Upgrade support functions.  Shared between ON and install gate.
 583  */
 584 extern FILE *zonecfg_open_scratch(const char *, boolean_t);
 585 extern int zonecfg_lock_scratch(FILE *);
 586 extern void zonecfg_close_scratch(FILE *);
 587 extern int zonecfg_get_scratch(FILE *, char *, size_t, char *, size_t, char *,
 588     size_t);
 589 extern int zonecfg_find_scratch(FILE *, const char *, const char *, char *,
 590     size_t);
 591 extern int zonecfg_reverse_scratch(FILE *, const char *, char *, size_t,
 592     char *, size_t);
 593 extern int zonecfg_add_scratch(FILE *, const char *, const char *,
 594     const char *);
 595 extern int zonecfg_delete_scratch(FILE *, const char *);
 596 extern boolean_t zonecfg_is_scratch(const char *);
 597 
 598 /*
 599  * zoneadmd support functions.  Shared between zoneadm and brand hook code.
 600  */
 601 extern void zonecfg_init_lock_file(const char *, char **);
 602 extern void zonecfg_release_lock_file(const char *, int);
 603 extern int zonecfg_grab_lock_file(const char *, int *);
 604 extern boolean_t zonecfg_lock_file_held(int *);
 605 extern int zonecfg_ping_zoneadmd(const char *);
 606 extern int zonecfg_call_zoneadmd(const char *, zone_cmd_arg_t *, char *,
 607     boolean_t);
 608 extern int zonecfg_insert_userauths(zone_dochandle_t, char *, char *);
 609 extern int zonecfg_remove_userauths(zone_dochandle_t, char *, char *,
 610     boolean_t);
 611 extern int zonecfg_add_admin(zone_dochandle_t, struct zone_admintab *,
 612     char *);
 613 extern int zonecfg_delete_admin(zone_dochandle_t,
 614     struct zone_admintab *, char *);
 615 extern int zonecfg_modify_admin(zone_dochandle_t, struct zone_admintab *,
 616     struct zone_admintab *, char *);
 617 extern int zonecfg_delete_admins(zone_dochandle_t, char *);
 618 extern int zonecfg_lookup_admin(zone_dochandle_t, struct zone_admintab *);
 619 extern int zonecfg_authorize_users(zone_dochandle_t, char *);
 620 extern int zonecfg_update_userauths(zone_dochandle_t, char *);
 621 extern int zonecfg_deauthorize_user(zone_dochandle_t, char *, char *);
 622 extern int zonecfg_deauthorize_users(zone_dochandle_t, char *);
 623 extern boolean_t zonecfg_valid_auths(const char *, const char *);
 624 
 625 #ifdef __cplusplus
 626 }
 627 #endif
 628 
 629 #endif  /* _LIBZONECFG_H */