1 .\" Copyright (c) 1996 Doug Rabson
3 .\" All rights reserved.
5 .\" This program is free software.
7 .\" Redistribution and use in source and binary forms, with or without
8 .\" modification, are permitted provided that the following conditions
10 .\" 1. Redistributions of source code must retain the above copyright
11 .\" notice, this list of conditions and the following disclaimer.
12 .\" 2. Redistributions in binary form must reproduce the above copyright
13 .\" notice, this list of conditions and the following disclaimer in the
14 .\" documentation and/or other materials provided with the distribution.
16 .\" THIS SOFTWARE IS PROVIDED BY THE DEVELOPERS ``AS IS'' AND ANY EXPRESS OR
17 .\" IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
18 .\" OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
19 .\" IN NO EVENT SHALL THE DEVELOPERS BE LIABLE FOR ANY DIRECT, INDIRECT,
20 .\" INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
21 .\" NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
22 .\" DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
23 .\" THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
24 .\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
25 .\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
27 .\" $FreeBSD: src/share/man/man9/VOP_ACCESS.9,v 1.7.2.4 2001/12/17 11:30:18 ru Exp $
28 .\" $DragonFly: src/share/man/man9/VOP_ACCESS.9,v 1.3 2004/06/01 11:36:53 hmp Exp $
35 .Nd "check access permissions of a file or Unix domain socket"
40 .Fn VOP_ACCESS "struct vnode *vp" "int mode" "struct ucred *cred" "struct proc *p"
42 This entry point checks the access permissions of the file against the
48 the vnode of the file to check
50 the type of access required
52 the user credentials to check
54 the process which is checking
59 is a mask which can contain
65 The vnode will be locked on entry and should remain locked on return.
67 If the file is accessible in the specified way, then zero is returned,
68 otherwise an appropriate error code is returned.
72 vop_access(struct vnode *vp, int mode, struct ucred *cred, struct proc *p)
77 * Disallow write attempts on read-only file systems;
78 * unless the file is a socket, fifo, or a block or
79 * character device resident on the file system.
86 if (vp->v_mount->mnt_flag & MNT_RDONLY)
93 /* If immutable bit set, nobody gets to write it. */
94 if ((mode & VWRITE) && vp has immutable bit set)
97 /* Otherwise, user id 0 always gets access. */
98 if (cred->cr_uid == 0)
103 /* Otherwise, check the owner. */
104 if (cred->cr_uid == owner of vp) {
111 return (((mode of vp) & mask) == mask ? 0 : EACCES);
114 /* Otherwise, check the groups. */
115 for (i = 0, gp = cred->cr_groups; i < cred->cr_ngroups; i++, gp++)
116 if (group of vp == *gp) {
123 return (((mode of vp) & mask) == mask ? 0 : EACCES);
126 /* Otherwise, check everyone else. */
133 return (((mode of vp) & mask) == mask ? 0 : EACCES);
139 An attempt was made to change an immutable file
146 This man page was written by