capabilities: introduce per-process capability bounding set
[safe/jmp/linux-2.6] / include / linux / init_task.h
1 #ifndef _LINUX__INIT_TASK_H
2 #define _LINUX__INIT_TASK_H
3
4 #include <linux/file.h>
5 #include <linux/rcupdate.h>
6 #include <linux/irqflags.h>
7 #include <linux/utsname.h>
8 #include <linux/lockdep.h>
9 #include <linux/ipc.h>
10 #include <linux/pid_namespace.h>
11 #include <linux/user_namespace.h>
12 #include <net/net_namespace.h>
13
14 #define INIT_FDTABLE \
15 {                                                       \
16         .max_fds        = NR_OPEN_DEFAULT,              \
17         .fd             = &init_files.fd_array[0],      \
18         .close_on_exec  = (fd_set *)&init_files.close_on_exec_init, \
19         .open_fds       = (fd_set *)&init_files.open_fds_init,  \
20         .rcu            = RCU_HEAD_INIT,                \
21         .next           = NULL,                         \
22 }
23
24 #define INIT_FILES \
25 {                                                       \
26         .count          = ATOMIC_INIT(1),               \
27         .fdt            = &init_files.fdtab,            \
28         .fdtab          = INIT_FDTABLE,                 \
29         .file_lock      = __SPIN_LOCK_UNLOCKED(init_task.file_lock), \
30         .next_fd        = 0,                            \
31         .close_on_exec_init = { { 0, } },               \
32         .open_fds_init  = { { 0, } },                   \
33         .fd_array       = { NULL, }                     \
34 }
35
36 #define INIT_KIOCTX(name, which_mm) \
37 {                                                       \
38         .users          = ATOMIC_INIT(1),               \
39         .dead           = 0,                            \
40         .mm             = &which_mm,                    \
41         .user_id        = 0,                            \
42         .next           = NULL,                         \
43         .wait           = __WAIT_QUEUE_HEAD_INITIALIZER(name.wait), \
44         .ctx_lock       = __SPIN_LOCK_UNLOCKED(name.ctx_lock), \
45         .reqs_active    = 0U,                           \
46         .max_reqs       = ~0U,                          \
47 }
48
49 #define INIT_MM(name) \
50 {                                                               \
51         .mm_rb          = RB_ROOT,                              \
52         .pgd            = swapper_pg_dir,                       \
53         .mm_users       = ATOMIC_INIT(2),                       \
54         .mm_count       = ATOMIC_INIT(1),                       \
55         .mmap_sem       = __RWSEM_INITIALIZER(name.mmap_sem),   \
56         .page_table_lock =  __SPIN_LOCK_UNLOCKED(name.page_table_lock), \
57         .mmlist         = LIST_HEAD_INIT(name.mmlist),          \
58         .cpu_vm_mask    = CPU_MASK_ALL,                         \
59 }
60
61 #define INIT_SIGNALS(sig) {                                             \
62         .count          = ATOMIC_INIT(1),                               \
63         .wait_chldexit  = __WAIT_QUEUE_HEAD_INITIALIZER(sig.wait_chldexit),\
64         .shared_pending = {                                             \
65                 .list = LIST_HEAD_INIT(sig.shared_pending.list),        \
66                 .signal =  {{0}}},                                      \
67         .posix_timers    = LIST_HEAD_INIT(sig.posix_timers),            \
68         .cpu_timers     = INIT_CPU_TIMERS(sig.cpu_timers),              \
69         .rlim           = INIT_RLIMITS,                                 \
70 }
71
72 extern struct nsproxy init_nsproxy;
73 #define INIT_NSPROXY(nsproxy) {                                         \
74         .pid_ns         = &init_pid_ns,                                 \
75         .count          = ATOMIC_INIT(1),                               \
76         .uts_ns         = &init_uts_ns,                                 \
77         .mnt_ns         = NULL,                                         \
78         INIT_NET_NS(net_ns)                                             \
79         INIT_IPC_NS(ipc_ns)                                             \
80         .user_ns        = &init_user_ns,                                \
81 }
82
83 #define INIT_SIGHAND(sighand) {                                         \
84         .count          = ATOMIC_INIT(1),                               \
85         .action         = { { { .sa_handler = NULL, } }, },             \
86         .siglock        = __SPIN_LOCK_UNLOCKED(sighand.siglock),        \
87         .signalfd_wqh   = __WAIT_QUEUE_HEAD_INITIALIZER(sighand.signalfd_wqh),  \
88 }
89
90 extern struct group_info init_groups;
91
92 #define INIT_STRUCT_PID {                                               \
93         .count          = ATOMIC_INIT(1),                               \
94         .tasks          = {                                             \
95                 { .first = &init_task.pids[PIDTYPE_PID].node },         \
96                 { .first = &init_task.pids[PIDTYPE_PGID].node },        \
97                 { .first = &init_task.pids[PIDTYPE_SID].node },         \
98         },                                                              \
99         .rcu            = RCU_HEAD_INIT,                                \
100         .level          = 0,                                            \
101         .numbers        = { {                                           \
102                 .nr             = 0,                                    \
103                 .ns             = &init_pid_ns,                         \
104                 .pid_chain      = { .next = NULL, .pprev = NULL },      \
105         }, }                                                            \
106 }
107
108 #define INIT_PID_LINK(type)                                     \
109 {                                                               \
110         .node = {                                               \
111                 .next = NULL,                                   \
112                 .pprev = &init_struct_pid.tasks[type].first,    \
113         },                                                      \
114         .pid = &init_struct_pid,                                \
115 }
116
117 #ifdef CONFIG_AUDITSYSCALL
118 #define INIT_IDS \
119         .loginuid = -1, \
120         .sessionid = -1,
121 #else
122 #define INIT_IDS
123 #endif
124
125 #ifdef CONFIG_SECURITY_FILE_CAPABILITIES
126 /*
127  * Because of the reduced scope of CAP_SETPCAP when filesystem
128  * capabilities are in effect, it is safe to allow CAP_SETPCAP to
129  * be available in the default configuration.
130  */
131 # define CAP_INIT_BSET  CAP_FULL_SET
132 #else
133 # define CAP_INIT_BSET  CAP_INIT_EFF_SET
134 #endif
135
136 /*
137  *  INIT_TASK is used to set up the first task table, touch at
138  * your own risk!. Base=0, limit=0x1fffff (=2MB)
139  */
140 #define INIT_TASK(tsk)  \
141 {                                                                       \
142         .state          = 0,                                            \
143         .stack          = &init_thread_info,                            \
144         .usage          = ATOMIC_INIT(2),                               \
145         .flags          = 0,                                            \
146         .lock_depth     = -1,                                           \
147         .prio           = MAX_PRIO-20,                                  \
148         .static_prio    = MAX_PRIO-20,                                  \
149         .normal_prio    = MAX_PRIO-20,                                  \
150         .policy         = SCHED_NORMAL,                                 \
151         .cpus_allowed   = CPU_MASK_ALL,                                 \
152         .mm             = NULL,                                         \
153         .active_mm      = &init_mm,                                     \
154         .rt             = {                                             \
155                 .run_list       = LIST_HEAD_INIT(tsk.rt.run_list),      \
156                 .time_slice     = HZ,                                   \
157                 .nr_cpus_allowed = NR_CPUS,                             \
158         },                                                              \
159         .tasks          = LIST_HEAD_INIT(tsk.tasks),                    \
160         .ptrace_children= LIST_HEAD_INIT(tsk.ptrace_children),          \
161         .ptrace_list    = LIST_HEAD_INIT(tsk.ptrace_list),              \
162         .real_parent    = &tsk,                                         \
163         .parent         = &tsk,                                         \
164         .children       = LIST_HEAD_INIT(tsk.children),                 \
165         .sibling        = LIST_HEAD_INIT(tsk.sibling),                  \
166         .group_leader   = &tsk,                                         \
167         .group_info     = &init_groups,                                 \
168         .cap_effective  = CAP_INIT_EFF_SET,                             \
169         .cap_inheritable = CAP_INIT_INH_SET,                            \
170         .cap_permitted  = CAP_FULL_SET,                                 \
171         .cap_bset       = CAP_INIT_BSET,                                \
172         .keep_capabilities = 0,                                         \
173         .user           = INIT_USER,                                    \
174         .comm           = "swapper",                                    \
175         .thread         = INIT_THREAD,                                  \
176         .fs             = &init_fs,                                     \
177         .files          = &init_files,                                  \
178         .signal         = &init_signals,                                \
179         .sighand        = &init_sighand,                                \
180         .nsproxy        = &init_nsproxy,                                \
181         .pending        = {                                             \
182                 .list = LIST_HEAD_INIT(tsk.pending.list),               \
183                 .signal = {{0}}},                                       \
184         .blocked        = {{0}},                                        \
185         .alloc_lock     = __SPIN_LOCK_UNLOCKED(tsk.alloc_lock),         \
186         .journal_info   = NULL,                                         \
187         .cpu_timers     = INIT_CPU_TIMERS(tsk.cpu_timers),              \
188         .fs_excl        = ATOMIC_INIT(0),                               \
189         .pi_lock        = __SPIN_LOCK_UNLOCKED(tsk.pi_lock),            \
190         .pids = {                                                       \
191                 [PIDTYPE_PID]  = INIT_PID_LINK(PIDTYPE_PID),            \
192                 [PIDTYPE_PGID] = INIT_PID_LINK(PIDTYPE_PGID),           \
193                 [PIDTYPE_SID]  = INIT_PID_LINK(PIDTYPE_SID),            \
194         },                                                              \
195         .dirties = INIT_PROP_LOCAL_SINGLE(dirties),                     \
196         INIT_IDS                                                        \
197         INIT_TRACE_IRQFLAGS                                             \
198         INIT_LOCKDEP                                                    \
199 }
200
201
202 #define INIT_CPU_TIMERS(cpu_timers)                                     \
203 {                                                                       \
204         LIST_HEAD_INIT(cpu_timers[0]),                                  \
205         LIST_HEAD_INIT(cpu_timers[1]),                                  \
206         LIST_HEAD_INIT(cpu_timers[2]),                                  \
207 }
208
209
210 #endif