Coverage Report

Created: 2026-09-07 06:08

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/SockFuzzer/third_party/xnu/security/mac_system.c
Line
Count
Source
1
/*
2
 * Copyright (c) 2007 Apple Inc. All rights reserved.
3
 *
4
 * @APPLE_OSREFERENCE_LICENSE_HEADER_START@
5
 *
6
 * This file contains Original Code and/or Modifications of Original Code
7
 * as defined in and that are subject to the Apple Public Source License
8
 * Version 2.0 (the 'License'). You may not use this file except in
9
 * compliance with the License. The rights granted to you under the License
10
 * may not be used to create, or enable the creation or redistribution of,
11
 * unlawful or unlicensed copies of an Apple operating system, or to
12
 * circumvent, violate, or enable the circumvention or violation of, any
13
 * terms of an Apple operating system software license agreement.
14
 *
15
 * Please obtain a copy of the License at
16
 * http://www.opensource.apple.com/apsl/ and read it before using this file.
17
 *
18
 * The Original Code and all software distributed under the License are
19
 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
20
 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
21
 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
22
 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
23
 * Please see the License for the specific language governing rights and
24
 * limitations under the License.
25
 *
26
 * @APPLE_OSREFERENCE_LICENSE_HEADER_END@
27
 */
28
29
/*-
30
 * Copyright (c) 1999, 2000, 2001, 2002 Robert N. M. Watson
31
 * Copyright (c) 2001 Ilmar S. Habibulin
32
 * Copyright (c) 2001, 2002, 2003, 2004 Networks Associates Technology, Inc.
33
 *
34
 * This software was developed by Robert Watson and Ilmar Habibulin for the
35
 * TrustedBSD Project.
36
 *
37
 * This software was developed for the FreeBSD Project in part by Network
38
 * Associates Laboratories, the Security Research Division of Network
39
 * Associates, Inc. under DARPA/SPAWAR contract N66001-01-C-8035 ("CBOSS"),
40
 * as part of the DARPA CHATS research program.
41
 *
42
 * Redistribution and use in source and binary forms, with or without
43
 * modification, are permitted provided that the following conditions
44
 * are met:
45
 * 1. Redistributions of source code must retain the above copyright
46
 *    notice, this list of conditions and the following disclaimer.
47
 * 2. Redistributions in binary form must reproduce the above copyright
48
 *    notice, this list of conditions and the following disclaimer in the
49
 *    documentation and/or other materials provided with the distribution.
50
 *
51
 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
52
 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
53
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
54
 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
55
 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
56
 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
57
 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
58
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
59
 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
60
 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
61
 * SUCH DAMAGE.
62
 *
63
 */
64
65
#include <sys/param.h>
66
#include <sys/vnode.h>
67
#include <sys/vnode_internal.h>
68
69
#include <security/mac_internal.h>
70
71
72
int
73
mac_system_check_acct(kauth_cred_t cred, struct vnode *vp)
74
0
{
75
0
  int error;
76
77
0
#if SECURITY_MAC_CHECK_ENFORCE
78
  /* 21167099 - only check if we allow write */
79
0
  if (!mac_system_enforce) {
80
0
    return 0;
81
0
  }
82
0
#endif
83
84
0
  MAC_CHECK(system_check_acct, cred, vp,
85
0
      vp != NULL ? vp->v_label : NULL);
86
87
0
  return error;
88
0
}
89
90
int
91
mac_system_check_host_priv(kauth_cred_t cred)
92
0
{
93
0
  int error;
94
95
0
#if SECURITY_MAC_CHECK_ENFORCE
96
  /* 21167099 - only check if we allow write */
97
0
  if (!mac_system_enforce) {
98
0
    return 0;
99
0
  }
100
0
#endif
101
102
0
  MAC_CHECK(system_check_host_priv, cred);
103
104
0
  return error;
105
0
}
106
107
int
108
mac_system_check_info(kauth_cred_t cred, const char *info_type)
109
0
{
110
0
  int error;
111
112
0
#if SECURITY_MAC_CHECK_ENFORCE
113
  /* 21167099 - only check if we allow write */
114
0
  if (!mac_system_enforce) {
115
0
    return 0;
116
0
  }
117
0
#endif
118
119
0
  MAC_CHECK(system_check_info, cred, info_type);
120
121
0
  return error;
122
0
}
123
124
int
125
mac_system_check_nfsd(kauth_cred_t cred)
126
0
{
127
0
  int error;
128
129
0
#if SECURITY_MAC_CHECK_ENFORCE
130
  /* 21167099 - only check if we allow write */
131
0
  if (!mac_system_enforce) {
132
0
    return 0;
133
0
  }
134
0
#endif
135
136
0
  MAC_CHECK(system_check_nfsd, cred);
137
138
0
  return error;
139
0
}
140
141
int
142
mac_system_check_reboot(kauth_cred_t cred, int howto)
143
0
{
144
0
  int error;
145
146
0
#if SECURITY_MAC_CHECK_ENFORCE
147
  /* 21167099 - only check if we allow write */
148
0
  if (!mac_system_enforce) {
149
0
    return 0;
150
0
  }
151
0
#endif
152
153
0
  MAC_CHECK(system_check_reboot, cred, howto);
154
155
0
  return error;
156
0
}
157
158
159
int
160
mac_system_check_settime(kauth_cred_t cred)
161
0
{
162
0
  int error;
163
164
0
#if SECURITY_MAC_CHECK_ENFORCE
165
  /* 21167099 - only check if we allow write */
166
0
  if (!mac_system_enforce) {
167
0
    return 0;
168
0
  }
169
0
#endif
170
171
0
  MAC_CHECK(system_check_settime, cred);
172
173
0
  return error;
174
0
}
175
176
int
177
mac_system_check_swapon(kauth_cred_t cred, struct vnode *vp)
178
0
{
179
0
  int error;
180
181
0
#if SECURITY_MAC_CHECK_ENFORCE
182
  /* 21167099 - only check if we allow write */
183
0
  if (!mac_system_enforce) {
184
0
    return 0;
185
0
  }
186
0
#endif
187
188
0
  MAC_CHECK(system_check_swapon, cred, vp, vp->v_label);
189
0
  return error;
190
0
}
191
192
int
193
mac_system_check_swapoff(kauth_cred_t cred, struct vnode *vp)
194
0
{
195
0
  int error;
196
197
0
#if SECURITY_MAC_CHECK_ENFORCE
198
  /* 21167099 - only check if we allow write */
199
0
  if (!mac_system_enforce) {
200
0
    return 0;
201
0
  }
202
0
#endif
203
204
0
  MAC_CHECK(system_check_swapoff, cred, vp, vp->v_label);
205
0
  return error;
206
0
}
207
208
int
209
mac_system_check_sysctlbyname(kauth_cred_t cred, const char *namestring, int *name,
210
    size_t namelen, user_addr_t oldctl, size_t oldlen,
211
    user_addr_t newctl, size_t newlen)
212
0
{
213
0
  int error;
214
215
0
#if SECURITY_MAC_CHECK_ENFORCE
216
  /* 21167099 - only check if we allow write */
217
0
  if (!mac_system_enforce) {
218
0
    return 0;
219
0
  }
220
0
#endif
221
222
0
  MAC_CHECK(system_check_sysctlbyname, cred, namestring,
223
0
      name, namelen, oldctl, oldlen, newctl, newlen);
224
225
0
  return error;
226
0
}
227
228
int
229
mac_system_check_kas_info(kauth_cred_t cred, int selector)
230
0
{
231
0
  int error;
232
233
0
#if SECURITY_MAC_CHECK_ENFORCE
234
  /* 21167099 - only check if we allow write */
235
0
  if (!mac_system_enforce) {
236
0
    return 0;
237
0
  }
238
0
#endif
239
240
0
  MAC_CHECK(system_check_kas_info, cred, selector);
241
242
0
  return error;
243
0
}