diff --git a/.gitmodules b/.gitmodules index f966d27f9..b42dee9f0 100644 --- a/.gitmodules +++ b/.gitmodules @@ -120,3 +120,15 @@ path = src/external/libauto url = ../darling-libauto.git branch = darling +[submodule "src/external/coretls"] + path = src/external/coretls + url = ../darling-coretls.git + branch = darling +[submodule "src/external/security"] + path = src/external/security + url = ../darling-security.git + branch = darling +[submodule "src/external/libxpc"] + path = src/external/libxpc + url = ../darling-libxpc.git + branch = darling diff --git a/etc/dylib.conf b/etc/dylib.conf index 27b623545..286f5d62b 100644 --- a/etc/dylib.conf +++ b/etc/dylib.conf @@ -58,6 +58,9 @@ /usr/lib/libsqlite3.dylib=libsqlite3.so /usr/lib/libsqlite3.0.dylib=libsqlite3.so /usr/lib/libauto.dylib=libauto.so +/usr/lib/libsandbox.dylib=libsandbox.so +/usr/lib/libsandbox.1.dylib=libsandbox.so +/usr/lib/libauto.dylib=libauto.so [CoreFoundation.framework] A=libCFFExtra.so diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt index 0009797f1..249335031 100644 --- a/src/CMakeLists.txt +++ b/src/CMakeLists.txt @@ -19,8 +19,8 @@ if (NOT BITS) message(FATAL_ERROR "BITS is not specified (32/64)") endif (NOT BITS) -SET(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -m${BITS}") -SET(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -m${BITS}") +SET(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -m${BITS} -D__APPLE_CC__") +SET(CMAKE_CXX_FLAGS "${CMAKE_CXX_FLAGS} -m${BITS} -D__APPLE_CPP__") SET(CMAKE_ASM_FLAGS "-m${BITS}") SET(CMAKE_ASM-ATT_FLAGS "-m${BITS}") @@ -125,6 +125,8 @@ add_subdirectory(csu) add_subdirectory(external/python/2.6/Python-2.6.9) add_subdirectory(external/expat) add_subdirectory(external/libauto) +#add_subdirectory(external/security) # work in progress +add_subdirectory(sandbox) add_subdirectory(Cocoa) if (NOT DARLING_NO_EXECUTABLES) diff --git a/src/CoreServices/DriverServices.cpp b/src/CoreServices/DriverServices.cpp index f9b920cd6..3ec3da0a4 100644 --- a/src/CoreServices/DriverServices.cpp +++ b/src/CoreServices/DriverServices.cpp @@ -27,83 +27,116 @@ AbsoluteTime UpTime() struct timeval boottime, now; size_t len = sizeof(boottime); int mib[2] = { CTL_KERN, KERN_BOOTTIME }; + uint64_t value; if (sysctl(mib, 2, &boottime, &len, NULL, 0) < 0) - return 0; + return { 0, 0}; gettimeofday(&now, NULL); - return (now.tv_sec-boottime.tv_sec) * 1000000000ll + value = (now.tv_sec-boottime.tv_sec) * 1000000000ll + (now.tv_usec-boottime.tv_usec) * 1000ll; + return *reinterpret_cast(&value); } Nanoseconds AbsoluteToNanoseconds(AbsoluteTime absTime) { - return absTime; + return *reinterpret_cast(&absTime); } Duration AbsoluteToDuration(AbsoluteTime absTime) { - return Duration(absTime / 1000000ll); + return Duration(*reinterpret_cast(&absTime) / 1000000ll); } AbsoluteTime NanosecondsToAbsolute(Nanoseconds ns) { - return ns; + uint64_t value = *reinterpret_cast(&ns); + return *reinterpret_cast(&value); } AbsoluteTime DurationToAbsolute(Duration duration) { - return duration * 1000000ll; + int64_t value = duration * 1000000ll; + return *reinterpret_cast(&value); } AbsoluteTime AddAbsoluteToAbsolute(AbsoluteTime time1, AbsoluteTime time2) { - return time1+time2; + int64_t value; + value = *reinterpret_cast(&time1); + value += *reinterpret_cast(&time2); + return *reinterpret_cast(&value); } AbsoluteTime SubAbsoluteFromAbsolute(AbsoluteTime time1, AbsoluteTime time2) { - return time1-time2; + int64_t value; + value = *reinterpret_cast(&time1); + value -= *reinterpret_cast(&time2); + return *reinterpret_cast(&value); } AbsoluteTime AddNanosecondsToAbsolute(Nanoseconds ns, AbsoluteTime absTime) { - return absTime + NanosecondsToAbsolute(ns); + int64_t value; + value = *reinterpret_cast(&absTime); + value += *reinterpret_cast(&ns); + return *reinterpret_cast(&value); } AbsoluteTime AddDurationToAbsolute(Duration duration, AbsoluteTime absTime) { - return absTime + DurationToAbsolute(duration); + int64_t value; + AbsoluteTime at2 = DurationToAbsolute(duration); + + value = *reinterpret_cast(&absTime); + value += *reinterpret_cast(&at2); + + return *reinterpret_cast(&value); } AbsoluteTime SubNanosecondsFromAbsolute(Nanoseconds ns, AbsoluteTime absTime) { - return absTime - NanosecondsToAbsolute(ns); + int64_t value; + value = *reinterpret_cast(&absTime); + value -= *reinterpret_cast(&ns); + return *reinterpret_cast(&value); } AbsoluteTime SubDurationFromAbsolute(Duration duration, AbsoluteTime absTime) { - return absTime - DurationToAbsolute(duration); + int64_t value; + AbsoluteTime at2 = DurationToAbsolute(duration); + + value = *reinterpret_cast(&absTime); + value -= *reinterpret_cast(&at2); + + return *reinterpret_cast(&value); } Nanoseconds AbsoluteDeltaToNanoseconds(AbsoluteTime time1, AbsoluteTime time2) { - return AbsoluteToNanoseconds(time1 - time2); + int64_t value = *reinterpret_cast(&time1) + - *reinterpret_cast(&time2); + + return AbsoluteToNanoseconds(*reinterpret_cast(&value)); } Duration AbsoluteDeltaToDuration(AbsoluteTime time1, AbsoluteTime time2) { - return AbsoluteToDuration(time1 - time2); + return AbsoluteToDuration(SubAbsoluteFromAbsolute(time1, time2)); } Nanoseconds DurationToNanoseconds(Duration duration) { - return duration * 1000000ll; + uint64_t value = duration * 1000000ll; + return *reinterpret_cast(&value); } Duration NanosecondsToDuration(Nanoseconds ns) { - return Duration(ns / 1000000ll); + uint64_t value = *reinterpret_cast(&ns); + return Duration(value / 1000000ll); } diff --git a/src/CoreServices/FixMath.cpp b/src/CoreServices/FixMath.cpp index c9e9bc8c2..6abf9578f 100644 --- a/src/CoreServices/FixMath.cpp +++ b/src/CoreServices/FixMath.cpp @@ -135,9 +135,9 @@ Fract X2Frac(double d) short WideCompare(const wide* a, const wide* b) { - if (*a > *b) + if (*reinterpret_cast(a) > *reinterpret_cast(b)) return 1; - else if (*a < *b) + else if (*reinterpret_cast(a) < *reinterpret_cast(b)) return -1; else return 0; @@ -145,70 +145,70 @@ short WideCompare(const wide* a, const wide* b) wide* WideAdd(wide* dst, const wide* val) { - *dst += *val; + *reinterpret_cast(dst) += *reinterpret_cast(val); return dst; } wide* WideSubtract(wide* dst, const wide* val) { - *dst -= *val; + *reinterpret_cast(dst) -= *reinterpret_cast(val); return dst; } wide* WideNegate(wide* val) { - *val = -*val; + *reinterpret_cast(val) = -*reinterpret_cast(val); return val; } wide* WideShift(wide* dst, int32_t shift) // rounds upwards { - wide result, mask; + int64_t result, mask; bool round; if (shift >= 0) { - result = *dst >> shift; + result = *(reinterpret_cast(dst)) >> shift; mask = result << shift; } else { - result = *dst << (-shift); + result = *(reinterpret_cast(dst)) << (-shift); mask = result >> (-shift); } - round = ((*dst) & ~mask) != 0; + round = ((*reinterpret_cast(dst)) & ~mask) != 0; if (round) result++; - *dst = result; + *reinterpret_cast(dst) = result; return dst; } uint32_t WideSquareRoot(const wide* val) { - return (uint32_t) sqrt(*val); + return (uint32_t) sqrt(*reinterpret_cast(val)); } wide* WideMultiply(int32_t a, int32_t b, wide* dst) { - *dst = int64_t(a) * int64_t(b); + *reinterpret_cast(dst) = int64_t(a) * int64_t(b); return dst; } int32_t WideDivide(const wide* divd, int32_t divs, int32_t* remainder) { if (remainder) - *remainder = *divd % divs; - return int32_t(*divd / divs); + *remainder = *reinterpret_cast(divd) % divs; + return int32_t(*reinterpret_cast(divd) / divs); } wide* WideWideDivide(wide* divd, int32_t divs, int32_t* remainder) { if (remainder) - *remainder = *divd % divs; - *divd /= divs; + *remainder = *reinterpret_cast(divd) % divs; + *reinterpret_cast(divd) /= divs; return divd; } @@ -218,9 +218,9 @@ wide* WideBitShift(wide* dst, int32_t shift) // negative -> left if (shift >= 0) - *dst >>= shift; + *reinterpret_cast(dst) >>= shift; else - *dst <<= (-shift); + *reinterpret_cast(dst) <<= (-shift); return dst; } diff --git a/src/CoreServices/MacTypes.h b/src/CoreServices/MacTypes.h index 52f4488bb..9ca6f1827 100644 --- a/src/CoreServices/MacTypes.h +++ b/src/CoreServices/MacTypes.h @@ -27,9 +27,9 @@ typedef uint32_t UnsignedFixed; // 16u/16 typedef UnsignedFixed* UnsignedFixedPtr; typedef short ShortFixed; typedef ShortFixed * ShortFixedPtr; // 8/8 -typedef int64_t wide; -typedef uint64_t UnsignedWide; -typedef uint64_t AbsoluteTime; +//typedef int64_t wide; +//typedef uint64_t UnsignedWide; +//typedef uint64_t AbsoluteTime; typedef int32_t Duration; // milliseconds typedef uint8_t Boolean; diff --git a/src/CoreServices/Multiprocessing.cpp b/src/CoreServices/Multiprocessing.cpp index 0cce31d2f..eff60c1b6 100644 --- a/src/CoreServices/Multiprocessing.cpp +++ b/src/CoreServices/Multiprocessing.cpp @@ -11,7 +11,7 @@ Boolean _MPIsFullyInitialized() OSStatus MPDelayUntil(AbsoluteTime* time) { - struct timespec ts = { time_t(*time / 1000000000ll), long(*time % 1000000000ll) }; + struct timespec ts = { time_t(*reinterpret_cast(time) / 1000000000ll), long(*reinterpret_cast(time) % 1000000000ll) }; nanosleep(&ts, nullptr); return noErr; } diff --git a/src/CoreServices/Processes.h b/src/CoreServices/Processes.h index e8d1ebf17..98d49a616 100644 --- a/src/CoreServices/Processes.h +++ b/src/CoreServices/Processes.h @@ -6,13 +6,6 @@ #include #include -struct ProcessSerialNumber -{ - unsigned long highLongOfPSN; - unsigned long lowLongOfPSN; -}; -typedef ProcessSerialNumber* ProcessSerialNumberPtr; - struct ProcessInfoRec { unsigned long processInfoLength; diff --git a/src/CoreServices/Timer.cpp b/src/CoreServices/Timer.cpp index ac92cad55..79c646b1f 100644 --- a/src/CoreServices/Timer.cpp +++ b/src/CoreServices/Timer.cpp @@ -8,9 +8,9 @@ void Microseconds(UnsignedWide* tickCount) time = mach_absolute_time(); - *tickCount = time / 1000000000ll; - time -= *tickCount * 1000000000ll; + *reinterpret_cast(tickCount) = time / 1000000000ll; + time -= *reinterpret_cast(tickCount) * 1000000000ll; - *tickCount += time / 1000; + *reinterpret_cast(tickCount) += time / 1000; } diff --git a/src/IOKit/CMakeLists.txt b/src/IOKit/CMakeLists.txt index 4965e78ca..43c6b7074 100644 --- a/src/IOKit/CMakeLists.txt +++ b/src/IOKit/CMakeLists.txt @@ -15,6 +15,7 @@ include_directories(${DARLING_TOP_DIRECTORY}/src/external/libobjc2) include_directories(${DARLING_TOP_DIRECTORY}/src/external/corefoundation/Headers) include_directories(${CMAKE_BINARY_DIR}/src/external/corefoundation/Headers) include_directories(${DARLING_TOP_DIRECTORY}/src/external/foundation/Headers) +include_directories(${DARLING_TOP_DIRECTORY}/basic-headers) add_definitions(-DOBJC2RUNTIME) diff --git a/src/external/corefoundation b/src/external/corefoundation index 9f75398eb..cf8c7a2f2 160000 --- a/src/external/corefoundation +++ b/src/external/corefoundation @@ -1 +1 @@ -Subproject commit 9f75398ebb3afdeaf8f351e11bc611f43ff86157 +Subproject commit cf8c7a2f2576eae269753e6f8b75c7cc47339651 diff --git a/src/external/coretls b/src/external/coretls new file mode 160000 index 000000000..5a08cee00 --- /dev/null +++ b/src/external/coretls @@ -0,0 +1 @@ +Subproject commit 5a08cee002cbb404a283e41f67c591a329ca7a72 diff --git a/src/external/foundation b/src/external/foundation index f694ef53f..cfd059762 160000 --- a/src/external/foundation +++ b/src/external/foundation @@ -1 +1 @@ -Subproject commit f694ef53f540cd77134ca8dc42257b0c24ad09a2 +Subproject commit cfd059762cf2bc88d96cb125025b2a21ff48d60c diff --git a/src/external/libauto b/src/external/libauto index 7d2ce9c7a..afb4f4825 160000 --- a/src/external/libauto +++ b/src/external/libauto @@ -1 +1 @@ -Subproject commit 7d2ce9c7a8906ee7c05d372e8f80d3544c7e6f87 +Subproject commit afb4f4825356586740afe8761f38832627fc0aea diff --git a/src/external/libdispatch b/src/external/libdispatch index eeef4804a..c6dbaf46d 160000 --- a/src/external/libdispatch +++ b/src/external/libdispatch @@ -1 +1 @@ -Subproject commit eeef4804aee38cc39f5ce1c1d838d28d6e1948ad +Subproject commit c6dbaf46dbdb711a3b09d786d38f963e4a626bab diff --git a/src/external/libobjc2 b/src/external/libobjc2 index 94d8584dd..ee23eae1e 160000 --- a/src/external/libobjc2 +++ b/src/external/libobjc2 @@ -1 +1 @@ -Subproject commit 94d8584dd7f9410e97fce9611afe6c6164ea9135 +Subproject commit ee23eae1e3e3fb127844abda3d24da876a008e2d diff --git a/src/external/libxpc b/src/external/libxpc new file mode 160000 index 000000000..c70dc7d15 --- /dev/null +++ b/src/external/libxpc @@ -0,0 +1 @@ +Subproject commit c70dc7d15ae429ae62522e7566aa25772a09b0aa diff --git a/src/external/python b/src/external/python index 42faa3f37..dbff40fba 160000 --- a/src/external/python +++ b/src/external/python @@ -1 +1 @@ -Subproject commit 42faa3f37f5a5bd247de7ccbe2fa3a6ff4b54157 +Subproject commit dbff40fba379d939b8a833f3ed4b861ae8a8eb7e diff --git a/src/external/security b/src/external/security new file mode 160000 index 000000000..9b7bb1f5f --- /dev/null +++ b/src/external/security @@ -0,0 +1 @@ +Subproject commit 9b7bb1f5f97a77ac92c5766b8cfeb5c091554a0f diff --git a/src/sandbox/CMakeLists.txt b/src/sandbox/CMakeLists.txt new file mode 100644 index 000000000..002f7ec38 --- /dev/null +++ b/src/sandbox/CMakeLists.txt @@ -0,0 +1,24 @@ +project(libsandbox) + +cmake_minimum_required(VERSION 2.4.0) + +if(COMMAND cmake_policy) + cmake_policy(SET CMP0003 NEW) +endif(COMMAND cmake_policy) + +add_definitions(-D__APPLE__ -D__MACH__) +add_definitions(-DTARGET_OS_MAC=1) +add_definitions(-D__APPLE__ -D__DYNAMIC__) +add_definitions(-D__ENVIRONMENT_MAC_OS_X_VERSION_MIN_REQUIRED__=1080) + +set(CMAKE_C_FLAGS "${CMAKE_C_FLAGS} -nostdinc -D__DARWIN_UNIX03 -fPIC -w") +set(CMAKE_SHARED_LINKER_FLAGS "${CMAKE_SHARED_LINKER_FLAGS} -nostdlib -Wl,--version-script=${DARLING_TOP_DIRECTORY}/darwin.map") + +SET(CMAKE_INSTALL_RPATH "${CMAKE_INSTALL_PREFIX}/${CMAKE_INSTALL_LIBDIR}/darling") +SET(CMAKE_BUILD_WITH_INSTALL_RPATH TRUE) +SET(CMAKE_INSTALL_RPATH_USE_LINK_PATH TRUE) + +add_library(sandbox SHARED sandbox.c) +target_link_libraries(sandbox PRIVATE system) + +install(TARGETS sandbox DESTINATION ${CMAKE_INSTALL_LIBDIR}/darling) diff --git a/src/sandbox/sandbox.c b/src/sandbox/sandbox.c new file mode 100644 index 000000000..b42d3509a --- /dev/null +++ b/src/sandbox/sandbox.c @@ -0,0 +1,115 @@ +#include "sandbox.h" +#include +#include + +// DUMMY implementation + +int sandbox_init(const char *profile, uint64_t flags, char **errorbuf) +{ + *errorbuf = strdup("Not implemented"); + return -1; +} + +const char kSBXProfileNoInternet[] = "no_internet"; + +const char kSBXProfileNoNetwork[] = "no_network"; + +const char kSBXProfileNoWrite[] = "no_write"; + +const char kSBXProfileNoWriteExceptTemporary[] = "no_write_except_temporary"; + +const char kSBXProfilePureComputation[] = "pure_computation"; + +void sandbox_free_error(char *errorbuf) +{ + free(errorbuf); +} + +int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf) +{ + *errorbuf = strdup("Not implemented"); + return -1; +} + +int sandbox_init_with_extensions(const char *profile, uint64_t flags, const char *const extensions[], char **errorbuf) +{ + *errorbuf = strdup("Not implemented"); + return -1; +} + +int sandbox_check(pid_t pid, const char *operation, enum sandbox_filter_type type, ...) +{ + return -1; +} + +int sandbox_note(const char *note) +{ + return -1; +} + +int sandbox_suspend(pid_t pid) +{ + return -1; +} + +int sandbox_unsuspend(void) +{ + return -1; +} + +int sandbox_issue_extension(const char *path, char **ext_token) +{ + return -1; +} + +int sandbox_issue_fs_extension(const char *path, uint64_t flags, char **ext_token) +{ + return -1; +} + +int sandbox_issue_fs_rw_extension(const char *path, char **ext_token) +{ + return -1; +} + +int sandbox_issue_mach_extension(const char *name, char **ext_token) +{ + return -1; +} + +int sandbox_consume_extension(const char *path, const char *ext_token) +{ + return -1; +} + +int sandbox_consume_fs_extension(const char *ext_token, char **path) +{ + return -1; +} + +int sandbox_consume_mach_extension(const char *ext_token, char **name) +{ + return -1; +} + +int sandbox_release_fs_extension(const char *ext_token) +{ + return -1; +} + +int sandbox_container_path_for_pid(pid_t pid, char *buffer, size_t bufsize) +{ + return -1; +} + +int sandbox_wakeup_daemon(char **errorbuf) +{ + *errorbuf = strdup("Not implemented"); + return -1; +} + +const char *_amkrtemp(const char *unused) +{ + return NULL; +} + diff --git a/src/sandbox/sandbox.h b/src/sandbox/sandbox.h new file mode 100644 index 000000000..ad38b0b6b --- /dev/null +++ b/src/sandbox/sandbox.h @@ -0,0 +1,181 @@ +/* + * Copyright (c) 2006-2010 Apple Inc. All rights reserved. + * + * @APPLE_LICENSE_HEADER_START@ + * + * This file contains Original Code and/or Modifications of Original Code + * as defined in and that are subject to the Apple Public Source License + * Version 2.0 (the 'License'). You may not use this file except in + * compliance with the License. Please obtain a copy of the License at + * http://www.opensource.apple.com/apsl/ and read it before using this + * file. + * + * The Original Code and all software distributed under the License are + * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER + * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, + * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, + * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. + * Please see the License for the specific language governing rights and + * limitations under the License. + * + * @APPLE_LICENSE_HEADER_END@ + */ +#ifndef _SANDBOX_H_ +#define _SANDBOX_H_ + +#include +#include +#include + +__BEGIN_DECLS +/* + * @function sandbox_init + * Places the current process in a sandbox with a profile as + * specified. If the process is already in a sandbox, the new profile + * is ignored and sandbox_init() returns an error. + * + * @param profile (input) The Sandbox profile to be used. The format + * and meaning of this parameter is modified by the `flags' parameter. + * + * @param flags (input) Must be SANDBOX_NAMED. All other + * values are reserved. + * + * @param errorbuf (output) In the event of an error, sandbox_init + * will set `*errorbuf' to a pointer to a NUL-terminated string + * describing the error. This string may contain embedded newlines. + * This error information is suitable for developers and is not + * intended for end users. + * + * If there are no errors, `*errorbuf' will be set to NULL. The + * buffer `*errorbuf' should be deallocated with `sandbox_free_error'. + * + * @result 0 on success, -1 otherwise. + */ +int sandbox_init(const char *profile, uint64_t flags, char **errorbuf); + +/* + * @define SANDBOX_NAMED The `profile' argument specifies a Sandbox + * profile named by one of the kSBXProfile* string constants. + */ +#define SANDBOX_NAMED 0x0001 + +#ifdef __APPLE_API_PRIVATE + +/* The following flags are reserved for Mac OS X. Developers should not + * depend on their availability. + */ + +/* + * @define SANDBOX_NAMED_BUILTIN The `profile' argument specifies the + * name of a builtin profile that is statically compiled into the + * system. + */ +#define SANDBOX_NAMED_BUILTIN 0x0002 + +/* + * @define SANDBOX_NAMED_EXTERNAL The `profile' argument specifies the + * pathname of a Sandbox profile. The pathname may be abbreviated: If + * the name does not start with a `/' it is treated as relative to + * /usr/share/sandbox and a `.sb' suffix is appended. + */ +#define SANDBOX_NAMED_EXTERNAL 0x0003 + +/* + * @define SANDBOX_NAMED_MASK Mask for name types: 4 bits, 15 possible + * name types, 3 currently defined. + */ +#define SANDBOX_NAMED_MASK 0x000f + +#endif /* __APPLE_API_PRIVATE */ + +/* + * Available Sandbox profiles. + */ + +/* TCP/IP networking is prohibited. */ +extern const char kSBXProfileNoInternet[]; + +/* All sockets-based networking is prohibited. */ +extern const char kSBXProfileNoNetwork[]; + +/* File system writes are prohibited. */ +extern const char kSBXProfileNoWrite[]; + +/* File system writes are restricted to temporary folders /var/tmp and + * confstr(_CS_DARWIN_USER_DIR, ...). + */ +extern const char kSBXProfileNoWriteExceptTemporary[]; + +/* All operating system services are prohibited. */ +extern const char kSBXProfilePureComputation[]; + +/* + * @function sandbox_free_error + * Deallocates an error string previously allocated by sandbox_init. + * + * @param errorbuf (input) The buffer to be freed. Must be a pointer + * previously returned by sandbox_init in the `errorbuf' argument, or NULL. + * + * @result void + */ +void sandbox_free_error(char *errorbuf); + + +#ifdef __APPLE_API_PRIVATE + +/* The following definitions are reserved for Mac OS X. Developers should not + * depend on their availability. + */ + +int sandbox_init_with_parameters(const char *profile, uint64_t flags, const char *const parameters[], char **errorbuf); + +int sandbox_init_with_extensions(const char *profile, uint64_t flags, const char *const extensions[], char **errorbuf); + +enum sandbox_filter_type { + SANDBOX_FILTER_NONE, + SANDBOX_FILTER_PATH, + SANDBOX_FILTER_GLOBAL_NAME, + SANDBOX_FILTER_LOCAL_NAME, + SANDBOX_FILTER_APPLEEVENT_DESTINATION, + SANDBOX_FILTER_RIGHT_NAME, +}; + +extern const enum sandbox_filter_type SANDBOX_CHECK_NO_REPORT __attribute__((weak_import)); + +enum sandbox_extension_flags { + FS_EXT_DEFAULTS = 0, + FS_EXT_FOR_PATH = (1 << 0), + FS_EXT_FOR_FILE = (1 << 1), + FS_EXT_READ = (1 << 2), + FS_EXT_WRITE = (1 << 3), + FS_EXT_PREFER_FILEID = (1 << 4), +}; + +int sandbox_check(pid_t pid, const char *operation, enum sandbox_filter_type type, ...); + +int sandbox_note(const char *note); + +int sandbox_suspend(pid_t pid); +int sandbox_unsuspend(void); + +int sandbox_issue_extension(const char *path, char **ext_token); +int sandbox_issue_fs_extension(const char *path, uint64_t flags, char **ext_token); +int sandbox_issue_fs_rw_extension(const char *path, char **ext_token); +int sandbox_issue_mach_extension(const char *name, char **ext_token); + +int sandbox_consume_extension(const char *path, const char *ext_token); +int sandbox_consume_fs_extension(const char *ext_token, char **path); +int sandbox_consume_mach_extension(const char *ext_token, char **name); + +int sandbox_release_fs_extension(const char *ext_token); + +int sandbox_container_path_for_pid(pid_t pid, char *buffer, size_t bufsize); + +int sandbox_wakeup_daemon(char **errorbuf); + +const char *_amkrtemp(const char *); + +#endif /* __APPLE_API_PRIVATE */ + +__END_DECLS +#endif /* _SANDBOX_H_ */