Home | History | Annotate | Download | only in common
      1 /*
      2  * CDDL HEADER START
      3  *
      4  * The contents of this file are subject to the terms of the
      5  * Common Development and Distribution License (the "License").
      6  * You may not use this file except in compliance with the License.
      7  *
      8  * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
      9  * or http://www.opensolaris.org/os/licensing.
     10  * See the License for the specific language governing permissions
     11  * and limitations under the License.
     12  *
     13  * When distributing Covered Code, include this CDDL HEADER in each
     14  * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
     15  * If applicable, add the following below this CDDL HEADER, with the
     16  * fields enclosed by brackets "[]" replaced with your own identifying
     17  * information: Portions Copyright [yyyy] [name of copyright owner]
     18  *
     19  * CDDL HEADER END
     20  */
     21 
     22 /*
     23  * Copyright 2010 Sun Microsystems, Inc.  All rights reserved.
     24  * Use is subject to license terms.
     25  */
     26 
     27 #include <libsysevent.h>
     28 #include <pthread.h>
     29 #include <stdlib.h>
     30 #include <errno.h>
     31 #include <fnmatch.h>
     32 #include <strings.h>
     33 #include <unistd.h>
     34 #include <assert.h>
     35 #include <libgen.h>
     36 #include <libintl.h>
     37 #include <alloca.h>
     38 #include <ctype.h>
     39 #include <sys/acl.h>
     40 #include <sys/stat.h>
     41 #include <sys/brand.h>
     42 #include <sys/mntio.h>
     43 #include <sys/mnttab.h>
     44 #include <sys/nvpair.h>
     45 #include <sys/types.h>
     46 #include <sys/sockio.h>
     47 #include <sys/systeminfo.h>
     48 #include <ftw.h>
     49 #include <pool.h>
     50 #include <libscf.h>
     51 #include <libproc.h>
     52 #include <sys/priocntl.h>
     53 #include <libuutil.h>
     54 #include <wait.h>
     55 #include <bsm/adt.h>
     56 
     57 #include <arpa/inet.h>
     58 #include <netdb.h>
     59 
     60 #include <libxml/xmlmemory.h>
     61 #include <libxml/parser.h>
     62 
     63 #include <libdevinfo.h>
     64 #include <uuid/uuid.h>
     65 #include <dirent.h>
     66 #include <libbrand.h>
     67 
     68 #include <libzonecfg.h>
     69 #include "zonecfg_impl.h"
     70 
     71 #define	_PATH_TMPFILE	"/zonecfg.XXXXXX"
     72 #define	ZONE_CB_RETRY_COUNT		10
     73 #define	ZONE_EVENT_PING_SUBCLASS	"ping"
     74 #define	ZONE_EVENT_PING_PUBLISHER	"solaris"
     75 
     76 /* Hard-code the DTD element/attribute/entity names just once, here. */
     77 #define	DTD_ELEM_ATTR		(const xmlChar *) "attr"
     78 #define	DTD_ELEM_COMMENT	(const xmlChar *) "comment"
     79 #define	DTD_ELEM_DEVICE		(const xmlChar *) "device"
     80 #define	DTD_ELEM_FS		(const xmlChar *) "filesystem"
     81 #define	DTD_ELEM_FSOPTION	(const xmlChar *) "fsoption"
     82 #define	DTD_ELEM_IPD		(const xmlChar *) "inherited-pkg-dir"
     83 #define	DTD_ELEM_NET		(const xmlChar *) "network"
     84 #define	DTD_ELEM_RCTL		(const xmlChar *) "rctl"
     85 #define	DTD_ELEM_RCTLVALUE	(const xmlChar *) "rctl-value"
     86 #define	DTD_ELEM_ZONE		(const xmlChar *) "zone"
     87 #define	DTD_ELEM_DATASET	(const xmlChar *) "dataset"
     88 #define	DTD_ELEM_TMPPOOL	(const xmlChar *) "tmp_pool"
     89 #define	DTD_ELEM_PSET		(const xmlChar *) "pset"
     90 #define	DTD_ELEM_MCAP		(const xmlChar *) "mcap"
     91 #define	DTD_ELEM_PACKAGE	(const xmlChar *) "package"
     92 #define	DTD_ELEM_PATCH		(const xmlChar *) "patch"
     93 #define	DTD_ELEM_OBSOLETES	(const xmlChar *) "obsoletes"
     94 #define	DTD_ELEM_DEV_PERM	(const xmlChar *) "dev-perm"
     95 
     96 #define	DTD_ATTR_ACTION		(const xmlChar *) "action"
     97 #define	DTD_ATTR_ADDRESS	(const xmlChar *) "address"
     98 #define	DTD_ATTR_AUTOBOOT	(const xmlChar *) "autoboot"
     99 #define	DTD_ATTR_IPTYPE		(const xmlChar *) "ip-type"
    100 #define	DTD_ATTR_DEFROUTER	(const xmlChar *) "defrouter"
    101 #define	DTD_ATTR_DIR		(const xmlChar *) "directory"
    102 #define	DTD_ATTR_LIMIT		(const xmlChar *) "limit"
    103 #define	DTD_ATTR_LIMITPRIV	(const xmlChar *) "limitpriv"
    104 #define	DTD_ATTR_BOOTARGS	(const xmlChar *) "bootargs"
    105 #define	DTD_ATTR_SCHED		(const xmlChar *) "scheduling-class"
    106 #define	DTD_ATTR_MATCH		(const xmlChar *) "match"
    107 #define	DTD_ATTR_NAME		(const xmlChar *) "name"
    108 #define	DTD_ATTR_PHYSICAL	(const xmlChar *) "physical"
    109 #define	DTD_ATTR_POOL		(const xmlChar *) "pool"
    110 #define	DTD_ATTR_PRIV		(const xmlChar *) "priv"
    111 #define	DTD_ATTR_RAW		(const xmlChar *) "raw"
    112 #define	DTD_ATTR_SPECIAL	(const xmlChar *) "special"
    113 #define	DTD_ATTR_TYPE		(const xmlChar *) "type"
    114 #define	DTD_ATTR_VALUE		(const xmlChar *) "value"
    115 #define	DTD_ATTR_ZONEPATH	(const xmlChar *) "zonepath"
    116 #define	DTD_ATTR_NCPU_MIN	(const xmlChar *) "ncpu_min"
    117 #define	DTD_ATTR_NCPU_MAX	(const xmlChar *) "ncpu_max"
    118 #define	DTD_ATTR_IMPORTANCE	(const xmlChar *) "importance"
    119 #define	DTD_ATTR_PHYSCAP	(const xmlChar *) "physcap"
    120 #define	DTD_ATTR_VERSION	(const xmlChar *) "version"
    121 #define	DTD_ATTR_ID		(const xmlChar *) "id"
    122 #define	DTD_ATTR_UID		(const xmlChar *) "uid"
    123 #define	DTD_ATTR_GID		(const xmlChar *) "gid"
    124 #define	DTD_ATTR_MODE		(const xmlChar *) "mode"
    125 #define	DTD_ATTR_ACL		(const xmlChar *) "acl"
    126 #define	DTD_ATTR_BRAND		(const xmlChar *) "brand"
    127 #define	DTD_ATTR_HOSTID		(const xmlChar *) "hostid"
    128 
    129 #define	DTD_ENTITY_BOOLEAN	"boolean"
    130 #define	DTD_ENTITY_DEVPATH	"devpath"
    131 #define	DTD_ENTITY_DRIVER	"driver"
    132 #define	DTD_ENTITY_DRVMIN	"drv_min"
    133 #define	DTD_ENTITY_FALSE	"false"
    134 #define	DTD_ENTITY_INT		"int"
    135 #define	DTD_ENTITY_STRING	"string"
    136 #define	DTD_ENTITY_TRUE		"true"
    137 #define	DTD_ENTITY_UINT		"uint"
    138 
    139 #define	DTD_ENTITY_BOOL_LEN	6	/* "false" */
    140 
    141 #define	ATTACH_FORCED	"SUNWattached.xml"
    142 
    143 #define	TMP_POOL_NAME	"SUNWtmp_%s"
    144 #define	MAX_TMP_POOL_NAME	(ZONENAME_MAX + 9)
    145 #define	RCAP_SERVICE	"system/rcap:default"
    146 #define	POOLD_SERVICE	"system/pools/dynamic:default"
    147 
    148 /*
    149  * rctl alias definitions
    150  *
    151  * This holds the alias, the full rctl name, the default priv value, action
    152  * and lower limit.  The functions that handle rctl aliases step through
    153  * this table, matching on the alias, and using the full values for setting
    154  * the rctl entry as well the limit for validation.
    155  */
    156 static struct alias {
    157 	char *shortname;
    158 	char *realname;
    159 	char *priv;
    160 	char *action;
    161 	uint64_t low_limit;
    162 } aliases[] = {
    163 	{ALIAS_MAXLWPS, "zone.max-lwps", "privileged", "deny", 100},
    164 	{ALIAS_MAXSHMMEM, "zone.max-shm-memory", "privileged", "deny", 0},
    165 	{ALIAS_MAXSHMIDS, "zone.max-shm-ids", "privileged", "deny", 0},
    166 	{ALIAS_MAXMSGIDS, "zone.max-msg-ids", "privileged", "deny", 0},
    167 	{ALIAS_MAXSEMIDS, "zone.max-sem-ids", "privileged", "deny", 0},
    168 	{ALIAS_MAXLOCKEDMEM, "zone.max-locked-memory", "privileged", "deny", 0},
    169 	{ALIAS_MAXSWAP, "zone.max-swap", "privileged", "deny", 0},
    170 	{ALIAS_SHARES, "zone.cpu-shares", "privileged", "none", 0},
    171 	{ALIAS_CPUCAP, "zone.cpu-cap", "privileged", "deny", 0},
    172 	{NULL, NULL, NULL, NULL, 0}
    173 };
    174 
    175 /*
    176  * Structure for applying rctls to a running zone.  It allows important
    177  * process values to be passed together easily.
    178  */
    179 typedef struct pr_info_handle {
    180 	struct ps_prochandle *pr;
    181 	pid_t pid;
    182 } pr_info_handle_t;
    183 
    184 struct zone_dochandle {
    185 	char		*zone_dh_rootdir;
    186 	xmlDocPtr	zone_dh_doc;
    187 	xmlNodePtr	zone_dh_cur;
    188 	xmlNodePtr	zone_dh_top;
    189 	boolean_t	zone_dh_newzone;
    190 	boolean_t	zone_dh_snapshot;
    191 	boolean_t	zone_dh_sw_inv;
    192 	char		zone_dh_delete_name[ZONENAME_MAX];
    193 };
    194 
    195 struct znotify {
    196 	void * zn_private;
    197 	evchan_t *zn_eventchan;
    198 	int (*zn_callback)(const  char *zonename, zoneid_t zid,
    199 	    const char *newstate, const char *oldstate, hrtime_t when, void *p);
    200 	pthread_mutex_t zn_mutex;
    201 	pthread_cond_t zn_cond;
    202 	pthread_mutex_t zn_bigmutex;
    203 	volatile enum {ZN_UNLOCKED, ZN_LOCKED, ZN_PING_INFLIGHT,
    204 	    ZN_PING_RECEIVED} zn_state;
    205 	char zn_subscriber_id[MAX_SUBID_LEN];
    206 	volatile boolean_t zn_failed;
    207 	int zn_failure_count;
    208 };
    209 
    210 /* used to track nested zone-lock operations */
    211 static int zone_lock_cnt = 0;
    212 
    213 /* used to communicate lock status to children */
    214 #define	LOCK_ENV_VAR	"_ZONEADM_LOCK_HELD"
    215 static char zoneadm_lock_held[] = LOCK_ENV_VAR"=1";
    216 static char zoneadm_lock_not_held[] = LOCK_ENV_VAR"=0";
    217 
    218 char *zonecfg_root = "";
    219 
    220 /*
    221  * For functions which return int, which is most of the functions herein,
    222  * the return values should be from the Z_foo set defined in <libzonecfg.h>.
    223  * In some instances, we take pains mapping some libc errno values to Z_foo
    224  * values from this set.
    225  */
    226 
    227 /*
    228  * Set the root (/) path for all zonecfg configuration files.  This is a
    229  * private interface used by Live Upgrade extensions to access zone
    230  * configuration inside mounted alternate boot environments.
    231  */
    232 void
    233 zonecfg_set_root(const char *rootpath)
    234 {
    235 	if (*zonecfg_root != '\0')
    236 		free(zonecfg_root);
    237 	if (rootpath == NULL || rootpath[0] == '\0' || rootpath[1] == '\0' ||
    238 	    (zonecfg_root = strdup(rootpath)) == NULL)
    239 		zonecfg_root = "";
    240 }
    241 
    242 const char *
    243 zonecfg_get_root(void)
    244 {
    245 	return (zonecfg_root);
    246 }
    247 
    248 boolean_t
    249 zonecfg_in_alt_root(void)
    250 {
    251 	return (*zonecfg_root != '\0');
    252 }
    253 
    254 /*
    255  * Callers of the _file_path() functions are expected to have the second
    256  * parameter be a (char foo[MAXPATHLEN]).
    257  */
    258 
    259 static boolean_t
    260 config_file_path(const char *zonename, char *answer)
    261 {
    262 	return (snprintf(answer, MAXPATHLEN, "%s%s/%s.xml", zonecfg_root,
    263 	    ZONE_CONFIG_ROOT, zonename) < MAXPATHLEN);
    264 }
    265 
    266 static boolean_t
    267 snap_file_path(const char *zonename, char *answer)
    268 {
    269 	return (snprintf(answer, MAXPATHLEN, "%s%s/%s.snapshot.xml",
    270 	    zonecfg_root, ZONE_SNAPSHOT_ROOT, zonename) < MAXPATHLEN);
    271 }
    272 
    273 /*ARGSUSED*/
    274 static void
    275 zonecfg_error_func(void *ctx, const char *msg, ...)
    276 {
    277 	/*
    278 	 * This function does nothing by design.  Its purpose is to prevent
    279 	 * libxml from dumping unwanted messages to stdout/stderr.
    280 	 */
    281 }
    282 
    283 zone_dochandle_t
    284 zonecfg_init_handle(void)
    285 {
    286 	zone_dochandle_t handle = calloc(1, sizeof (struct zone_dochandle));
    287 	if (handle == NULL) {
    288 		errno = Z_NOMEM;
    289 		return (NULL);
    290 	}
    291 
    292 	/* generic libxml initialization */
    293 	(void) xmlLineNumbersDefault(1);
    294 	xmlLoadExtDtdDefaultValue |= XML_DETECT_IDS;
    295 	xmlDoValidityCheckingDefaultValue = 1;
    296 	(void) xmlKeepBlanksDefault(0);
    297 	xmlGetWarningsDefaultValue = 0;
    298 	xmlSetGenericErrorFunc(NULL, zonecfg_error_func);
    299 
    300 	return (handle);
    301 }
    302 
    303 int
    304 zonecfg_check_handle(zone_dochandle_t handle)
    305 {
    306 	if (handle == NULL || handle->zone_dh_doc == NULL)
    307 		return (Z_BAD_HANDLE);
    308 	return (Z_OK);
    309 }
    310 
    311 void
    312 zonecfg_fini_handle(zone_dochandle_t handle)
    313 {
    314 	if (zonecfg_check_handle(handle) == Z_OK)
    315 		xmlFreeDoc(handle->zone_dh_doc);
    316 	if (handle != NULL)
    317 		free(handle);
    318 }
    319 
    320 static int
    321 zonecfg_destroy_impl(char *filename)
    322 {
    323 	if (unlink(filename) == -1) {
    324 		if (errno == EACCES)
    325 			return (Z_ACCES);
    326 		if (errno == ENOENT)
    327 			return (Z_NO_ZONE);
    328 		return (Z_MISC_FS);
    329 	}
    330 	return (Z_OK);
    331 }
    332 
    333 int
    334 zonecfg_destroy(const char *zonename, boolean_t force)
    335 {
    336 	char path[MAXPATHLEN];
    337 	struct zoneent ze;
    338 	int err, state_err;
    339 	zone_state_t state;
    340 
    341 	if (!config_file_path(zonename, path))
    342 		return (Z_MISC_FS);
    343 
    344 	state_err = zone_get_state((char *)zonename, &state);
    345 	err = access(path, W_OK);
    346 
    347 	/*
    348 	 * If there is no file, and no index entry, reliably indicate that no
    349 	 * such zone exists.
    350 	 */
    351 	if ((state_err == Z_NO_ZONE) && (err == -1) && (errno == ENOENT))
    352 		return (Z_NO_ZONE);
    353 
    354 	/*
    355 	 * Handle any other filesystem related errors (except if the XML
    356 	 * file is missing, which we treat silently), unless we're forcing,
    357 	 * in which case we plow on.
    358 	 */
    359 	if (err == -1 && errno != ENOENT) {
    360 		if (errno == EACCES)
    361 			return (Z_ACCES);
    362 		else if (!force)
    363 			return (Z_MISC_FS);
    364 	}
    365 
    366 	if (state > ZONE_STATE_INSTALLED)
    367 		return (Z_BAD_ZONE_STATE);
    368 
    369 	if (!force && state > ZONE_STATE_CONFIGURED)
    370 		return (Z_BAD_ZONE_STATE);
    371 
    372 	/*
    373 	 * Index deletion succeeds even if the entry doesn't exist.  So this
    374 	 * will fail only if we've had some more severe problem.
    375 	 */
    376 	bzero(&ze, sizeof (ze));
    377 	(void) strlcpy(ze.zone_name, zonename, sizeof (ze.zone_name));
    378 	if ((err = putzoneent(&ze, PZE_REMOVE)) != Z_OK)
    379 		if (!force)
    380 			return (err);
    381 
    382 	err = zonecfg_destroy_impl(path);
    383 
    384 	/*
    385 	 * Treat failure to find the XML file silently, since, well, it's
    386 	 * gone, and with the index file cleaned up, we're done.
    387 	 */
    388 	if (err == Z_OK || err == Z_NO_ZONE)
    389 		return (Z_OK);
    390 	return (err);
    391 }
    392 
    393 int
    394 zonecfg_destroy_snapshot(const char *zonename)
    395 {
    396 	char path[MAXPATHLEN];
    397 
    398 	if (!snap_file_path(zonename, path))
    399 		return (Z_MISC_FS);
    400 	return (zonecfg_destroy_impl(path));
    401 }
    402 
    403 static int
    404 getroot(zone_dochandle_t handle, xmlNodePtr *root)
    405 {
    406 	if (zonecfg_check_handle(handle) == Z_BAD_HANDLE)
    407 		return (Z_BAD_HANDLE);
    408 
    409 	*root = xmlDocGetRootElement(handle->zone_dh_doc);
    410 
    411 	if (*root == NULL)
    412 		return (Z_EMPTY_DOCUMENT);
    413 
    414 	if (xmlStrcmp((*root)->name, DTD_ELEM_ZONE))
    415 		return (Z_WRONG_DOC_TYPE);
    416 
    417 	return (Z_OK);
    418 }
    419 
    420 static int
    421 operation_prep(zone_dochandle_t handle)
    422 {
    423 	xmlNodePtr root;
    424 	int err;
    425 
    426 	if ((err = getroot(handle, &root)) != 0)
    427 		return (err);
    428 
    429 	handle->zone_dh_cur = root;
    430 	handle->zone_dh_top = root;
    431 	return (Z_OK);
    432 }
    433 
    434 static int
    435 fetchprop(xmlNodePtr cur, const xmlChar *propname, char *dst, size_t dstsize)
    436 {
    437 	xmlChar *property;
    438 	size_t srcsize;
    439 
    440 	if ((property = xmlGetProp(cur, propname)) == NULL)
    441 		return (Z_BAD_PROPERTY);
    442 	srcsize = strlcpy(dst, (char *)property, dstsize);
    443 	xmlFree(property);
    444 	if (srcsize >= dstsize)
    445 		return (Z_TOO_BIG);
    446 	return (Z_OK);
    447 }
    448 
    449 static int
    450 fetch_alloc_prop(xmlNodePtr cur, const xmlChar *propname, char **dst)
    451 {
    452 	xmlChar *property;
    453 
    454 	if ((property = xmlGetProp(cur, propname)) == NULL)
    455 		return (Z_BAD_PROPERTY);
    456 	if ((*dst = strdup((char *)property)) == NULL) {
    457 		xmlFree(property);
    458 		return (Z_NOMEM);
    459 	}
    460 	xmlFree(property);
    461 	return (Z_OK);
    462 }
    463 
    464 static int
    465 getrootattr(zone_dochandle_t handle, const xmlChar *propname,
    466     char *propval, size_t propsize)
    467 {
    468 	xmlNodePtr root;
    469 	int err;
    470 
    471 	if ((err = getroot(handle, &root)) != 0)
    472 		return (err);
    473 
    474 	return (fetchprop(root, propname, propval, propsize));
    475 }
    476 
    477 static int
    478 get_alloc_rootattr(zone_dochandle_t handle, const xmlChar *propname,
    479     char **propval)
    480 {
    481 	xmlNodePtr root;
    482 	int err;
    483 
    484 	if ((err = getroot(handle, &root)) != 0)
    485 		return (err);
    486 
    487 	return (fetch_alloc_prop(root, propname, propval));
    488 }
    489 
    490 static int
    491 setrootattr(zone_dochandle_t handle, const xmlChar *propname,
    492     const char *propval)
    493 {
    494 	int err;
    495 	xmlNodePtr root;
    496 
    497 	if ((err = getroot(handle, &root)) != Z_OK)
    498 		return (err);
    499 
    500 	/*
    501 	 * If we get a null propval remove the property (ignore return since it
    502 	 * may not be set to begin with).
    503 	 */
    504 	if (propval == NULL) {
    505 		(void) xmlUnsetProp(root, propname);
    506 	} else {
    507 		if (xmlSetProp(root, propname, (const xmlChar *) propval)
    508 		    == NULL)
    509 			return (Z_INVAL);
    510 	}
    511 	return (Z_OK);
    512 }
    513 
    514 static void
    515 addcomment(zone_dochandle_t handle, const char *comment)
    516 {
    517 	xmlNodePtr node;
    518 	node = xmlNewComment((xmlChar *) comment);
    519 
    520 	if (node != NULL)
    521 		(void) xmlAddPrevSibling(handle->zone_dh_top, node);
    522 }
    523 
    524 static void
    525 stripcomments(zone_dochandle_t handle)
    526 {
    527 	xmlDocPtr top;
    528 	xmlNodePtr child, next;
    529 
    530 	top = handle->zone_dh_doc;
    531 	for (child = top->xmlChildrenNode; child != NULL; child = next) {
    532 		next = child->next;
    533 		if (child->name == NULL)
    534 			continue;
    535 		if (xmlStrcmp(child->name, DTD_ELEM_COMMENT) == 0) {
    536 			next = child->next;
    537 			xmlUnlinkNode(child);
    538 			xmlFreeNode(child);
    539 		}
    540 	}
    541 }
    542 
    543 static void
    544 strip_sw_inv(zone_dochandle_t handle)
    545 {
    546 	xmlNodePtr root, child, next;
    547 
    548 	root = xmlDocGetRootElement(handle->zone_dh_doc);
    549 	for (child = root->xmlChildrenNode; child != NULL; child = next) {
    550 		next = child->next;
    551 		if (child->name == NULL)
    552 			continue;
    553 		if (xmlStrcmp(child->name, DTD_ELEM_PACKAGE) == 0 ||
    554 		    xmlStrcmp(child->name, DTD_ELEM_PATCH) == 0) {
    555 			next = child->next;
    556 			xmlUnlinkNode(child);
    557 			xmlFreeNode(child);
    558 		}
    559 	}
    560 }
    561 
    562 static int
    563 zonecfg_get_handle_impl(const char *zonename, const char *filename,
    564     zone_dochandle_t handle)
    565 {
    566 	xmlValidCtxtPtr cvp;
    567 	struct stat statbuf;
    568 	int valid;
    569 
    570 	if (zonename == NULL)
    571 		return (Z_NO_ZONE);
    572 
    573 	if ((handle->zone_dh_doc = xmlParseFile(filename)) == NULL) {
    574 		/* distinguish file not found vs. found but not parsed */
    575 		if (stat(filename, &statbuf) == 0)
    576 			return (Z_INVALID_DOCUMENT);
    577 		return (Z_NO_ZONE);
    578 	}
    579 	if ((cvp = xmlNewValidCtxt()) == NULL)
    580 		return (Z_NOMEM);
    581 	cvp->error = zonecfg_error_func;
    582 	cvp->warning = zonecfg_error_func;
    583 	valid = xmlValidateDocument(cvp, handle->zone_dh_doc);
    584 	xmlFreeValidCtxt(cvp);
    585 	if (valid == 0)
    586 		return (Z_INVALID_DOCUMENT);
    587 
    588 	/* delete any comments such as inherited Sun copyright / ident str */
    589 	stripcomments(handle);
    590 	return (Z_OK);
    591 }
    592 
    593 int
    594 zonecfg_get_handle(const char *zonename, zone_dochandle_t handle)
    595 {
    596 	char path[MAXPATHLEN];
    597 
    598 	if (!config_file_path(zonename, path))
    599 		return (Z_MISC_FS);
    600 	handle->zone_dh_newzone = B_FALSE;
    601 
    602 	return (zonecfg_get_handle_impl(zonename, path, handle));
    603 }
    604 
    605 int
    606 zonecfg_get_attach_handle(const char *path, const char *fname,
    607     const char *zonename, boolean_t preserve_sw, zone_dochandle_t handle)
    608 {
    609 	char		migpath[MAXPATHLEN];
    610 	int		err;
    611 	struct stat	buf;
    612 
    613 	if (snprintf(migpath, sizeof (migpath), "%s/root", path) >=
    614 	    sizeof (migpath))
    615 		return (Z_NOMEM);
    616 
    617 	if (stat(migpath, &buf) == -1 || !S_ISDIR(buf.st_mode))
    618 		return (Z_NO_ZONE);
    619 
    620 	if (snprintf(migpath, sizeof (migpath), "%s/%s", path, fname) >=
    621 	    sizeof (migpath))
    622 		return (Z_NOMEM);
    623 
    624 	if ((err = zonecfg_get_handle_impl(zonename, migpath, handle)) != Z_OK)
    625 		return (err);
    626 
    627 	if (!preserve_sw)
    628 		strip_sw_inv(handle);
    629 
    630 	handle->zone_dh_newzone = B_TRUE;
    631 	if ((err = setrootattr(handle, DTD_ATTR_ZONEPATH, path)) != Z_OK)
    632 		return (err);
    633 
    634 	return (setrootattr(handle, DTD_ATTR_NAME, zonename));
    635 }
    636 
    637 int
    638 zonecfg_get_snapshot_handle(const char *zonename, zone_dochandle_t handle)
    639 {
    640 	char path[MAXPATHLEN];
    641 
    642 	if (!snap_file_path(zonename, path))
    643 		return (Z_MISC_FS);
    644 	handle->zone_dh_newzone = B_FALSE;
    645 	return (zonecfg_get_handle_impl(zonename, path, handle));
    646 }
    647 
    648 int
    649 zonecfg_get_template_handle(const char *template, const char *zonename,
    650     zone_dochandle_t handle)
    651 {
    652 	char path[MAXPATHLEN];
    653 	int err;
    654 
    655 	if (!config_file_path(template, path))
    656 		return (Z_MISC_FS);
    657 
    658 	if ((err = zonecfg_get_handle_impl(template, path, handle)) != Z_OK)
    659 		return (err);
    660 	handle->zone_dh_newzone = B_TRUE;
    661 	return (setrootattr(handle, DTD_ATTR_NAME, zonename));
    662 }
    663 
    664 int
    665 zonecfg_get_xml_handle(const char *path, zone_dochandle_t handle)
    666 {
    667 	struct stat buf;
    668 	int err;
    669 
    670 	if (stat(path, &buf) == -1)
    671 		return (Z_MISC_FS);
    672 
    673 	if ((err = zonecfg_get_handle_impl("xml", path, handle)) != Z_OK)
    674 		return (err);
    675 	handle->zone_dh_newzone = B_TRUE;
    676 	return (Z_OK);
    677 }
    678 
    679 /*
    680  * Initialize two handles from the manifest read on fd.  The rem_handle
    681  * is initialized from the input file, including the sw inventory.  The
    682  * local_handle is initialized with the same zone configuration but with
    683  * no sw inventory.
    684  */
    685 int
    686 zonecfg_attach_manifest(int fd, zone_dochandle_t local_handle,
    687     zone_dochandle_t rem_handle)
    688 {
    689 	xmlValidCtxtPtr cvp;
    690 	int valid;
    691 
    692 	/* load the manifest into the handle for the remote system */
    693 	if ((rem_handle->zone_dh_doc = xmlReadFd(fd, NULL, NULL, 0)) == NULL) {
    694 		return (Z_INVALID_DOCUMENT);
    695 	}
    696 	if ((cvp = xmlNewValidCtxt()) == NULL)
    697 		return (Z_NOMEM);
    698 	cvp->error = zonecfg_error_func;
    699 	cvp->warning = zonecfg_error_func;
    700 	valid = xmlValidateDocument(cvp, rem_handle->zone_dh_doc);
    701 	xmlFreeValidCtxt(cvp);
    702 	if (valid == 0)
    703 		return (Z_INVALID_DOCUMENT);
    704 
    705 	/* delete any comments such as inherited Sun copyright / ident str */
    706 	stripcomments(rem_handle);
    707 
    708 	rem_handle->zone_dh_newzone = B_TRUE;
    709 	rem_handle->zone_dh_sw_inv = B_TRUE;
    710 
    711 	/*
    712 	 * Now use the remote system handle to generate a local system handle
    713 	 * with an identical zones configuration but no sw inventory.
    714 	 */
    715 	if ((local_handle->zone_dh_doc = xmlCopyDoc(rem_handle->zone_dh_doc,
    716 	    1)) == NULL) {
    717 		return (Z_INVALID_DOCUMENT);
    718 	}
    719 
    720 	/*
    721 	 * We need to re-run xmlValidateDocument on local_handle to properly
    722 	 * update the in-core representation of the configuration.
    723 	 */
    724 	if ((cvp = xmlNewValidCtxt()) == NULL)
    725 		return (Z_NOMEM);
    726 	cvp->error = zonecfg_error_func;
    727 	cvp->warning = zonecfg_error_func;
    728 	valid = xmlValidateDocument(cvp, local_handle->zone_dh_doc);
    729 	xmlFreeValidCtxt(cvp);
    730 	if (valid == 0)
    731 		return (Z_INVALID_DOCUMENT);
    732 
    733 	strip_sw_inv(local_handle);
    734 
    735 	local_handle->zone_dh_newzone = B_TRUE;
    736 	local_handle->zone_dh_sw_inv = B_FALSE;
    737 
    738 	return (Z_OK);
    739 }
    740 
    741 static boolean_t
    742 is_renaming(zone_dochandle_t handle)
    743 {
    744 	if (handle->zone_dh_newzone)
    745 		return (B_FALSE);
    746 	if (strlen(handle->zone_dh_delete_name) > 0)
    747 		return (B_TRUE);
    748 	return (B_FALSE);
    749 }
    750 
    751 static boolean_t
    752 is_new(zone_dochandle_t handle)
    753 {
    754 	return (handle->zone_dh_newzone || handle->zone_dh_snapshot);
    755 }
    756 
    757 static boolean_t
    758 is_snapshot(zone_dochandle_t handle)
    759 {
    760 	return (handle->zone_dh_snapshot);
    761 }
    762 
    763 /*
    764  * It would be great to be able to use libc's ctype(3c) macros, but we
    765  * can't, as they are locale sensitive, and it would break our limited thread
    766  * safety if this routine had to change the app locale on the fly.
    767  */
    768 int
    769 zonecfg_validate_zonename(const char *zone)
    770 {
    771 	int i;
    772 
    773 	if (strcmp(zone, GLOBAL_ZONENAME) == 0)
    774 		return (Z_BOGUS_ZONE_NAME);
    775 
    776 	if (strlen(zone) >= ZONENAME_MAX)
    777 		return (Z_BOGUS_ZONE_NAME);
    778 
    779 	if (!((zone[0] >= 'a' && zone[0] <= 'z') ||
    780 	    (zone[0] >= 'A' && zone[0] <= 'Z') ||
    781 	    (zone[0] >= '0' && zone[0] <= '9')))
    782 		return (Z_BOGUS_ZONE_NAME);
    783 
    784 	for (i = 1; zone[i] != '\0'; i++) {
    785 		if (!((zone[i] >= 'a' && zone[i] <= 'z') ||
    786 		    (zone[i] >= 'A' && zone[i] <= 'Z') ||
    787 		    (zone[i] >= '0' && zone[i] <= '9') ||
    788 		    (zone[i] == '-') || (zone[i] == '_') || (zone[i] == '.')))
    789 			return (Z_BOGUS_ZONE_NAME);
    790 	}
    791 
    792 	return (Z_OK);
    793 }
    794 
    795 /*
    796  * Changing the zone name requires us to track both the old and new
    797  * name of the zone until commit time.
    798  */
    799 int
    800 zonecfg_get_name(zone_dochandle_t handle, char *name, size_t namesize)
    801 {
    802 	return (getrootattr(handle, DTD_ATTR_NAME, name, namesize));
    803 }
    804 
    805 int
    806 zonecfg_set_name(zone_dochandle_t handle, char *name)
    807 {
    808 	zone_state_t state;
    809 	char curname[ZONENAME_MAX], old_delname[ZONENAME_MAX];
    810 	int err;
    811 
    812 	if ((err = getrootattr(handle, DTD_ATTR_NAME, curname,
    813 	    sizeof (curname))) != Z_OK)
    814 		return (err);
    815 
    816 	if (strcmp(name, curname) == 0)
    817 		return (Z_OK);
    818 
    819 	/*
    820 	 * Switching zone names to one beginning with SUNW is not permitted.
    821 	 */
    822 	if (strncmp(name, "SUNW", 4) == 0)
    823 		return (Z_BOGUS_ZONE_NAME);
    824 
    825 	if ((err = zonecfg_validate_zonename(name)) != Z_OK)
    826 		return (err);
    827 
    828 	/*
    829 	 * Setting the name back to the original name (effectively a revert of
    830 	 * the name) is fine.  But if we carry on, we'll falsely identify the
    831 	 * name as "in use," so special case here.
    832 	 */
    833 	if (strcmp(name, handle->zone_dh_delete_name) == 0) {
    834 		err = setrootattr(handle, DTD_ATTR_NAME, name);
    835 		handle->zone_dh_delete_name[0] = '\0';
    836 		return (err);
    837 	}
    838 
    839 	/* Check to see if new name chosen is already in use */
    840 	if (zone_get_state(name, &state) != Z_NO_ZONE)
    841 		return (Z_NAME_IN_USE);
    842 
    843 	/*
    844 	 * If this isn't already "new" or in a renaming transition, then
    845 	 * we're initiating a rename here; so stash the "delete name"
    846 	 * (i.e. the name of the zone we'll be removing) for the rename.
    847 	 */
    848 	(void) strlcpy(old_delname, handle->zone_dh_delete_name,
    849 	    sizeof (old_delname));
    850 	if (!is_new(handle) && !is_renaming(handle)) {
    851 		/*
    852 		 * Name change is allowed only when the zone we're altering
    853 		 * is not ready or running.
    854 		 */
    855 		err = zone_get_state(curname, &state);
    856 		if (err == Z_OK) {
    857 			if (state > ZONE_STATE_INSTALLED)
    858 				return (Z_BAD_ZONE_STATE);
    859 		} else if (err != Z_NO_ZONE) {
    860 			return (err);
    861 		}
    862 
    863 		(void) strlcpy(handle->zone_dh_delete_name, curname,
    864 		    sizeof (handle->zone_dh_delete_name));
    865 		assert(is_renaming(handle));
    866 	} else if (is_renaming(handle)) {
    867 		err = zone_get_state(handle->zone_dh_delete_name, &state);
    868 		if (err == Z_OK) {
    869 			if (state > ZONE_STATE_INSTALLED)
    870 				return (Z_BAD_ZONE_STATE);
    871 		} else if (err != Z_NO_ZONE) {
    872 			return (err);
    873 		}
    874 	}
    875 
    876 	if ((err = setrootattr(handle, DTD_ATTR_NAME, name)) != Z_OK) {
    877 		/*
    878 		 * Restore the deletename to whatever it was at the
    879 		 * top of the routine, since we've had a failure.
    880 		 */
    881 		(void) strlcpy(handle->zone_dh_delete_name, old_delname,
    882 		    sizeof (handle->zone_dh_delete_name));
    883 		return (err);
    884 	}
    885 
    886 	return (Z_OK);
    887 }
    888 
    889 int
    890 zonecfg_get_zonepath(zone_dochandle_t handle, char *path, size_t pathsize)
    891 {
    892 	size_t len;
    893 
    894 	if ((len = strlcpy(path, zonecfg_root, pathsize)) >= pathsize)
    895 		return (Z_TOO_BIG);
    896 	return (getrootattr(handle, DTD_ATTR_ZONEPATH, path + len,
    897 	    pathsize - len));
    898 }
    899 
    900 int
    901 zonecfg_set_zonepath(zone_dochandle_t handle, char *zonepath)
    902 {
    903 	size_t len;
    904 
    905 	/*
    906 	 * The user deals in absolute paths in the running global zone, but the
    907 	 * internal configuration files deal with boot environment relative
    908 	 * paths.  Strip out the alternate root when specified.
    909 	 */
    910 	len = strlen(zonecfg_root);
    911 	if (strncmp(zonepath, zonecfg_root, len) != 0 || zonepath[len] != '/')
    912 		return (Z_BAD_PROPERTY);
    913 	zonepath += len;
    914 	return (setrootattr(handle, DTD_ATTR_ZONEPATH, zonepath));
    915 }
    916 
    917 static int
    918 i_zonecfg_get_brand(zone_dochandle_t handle, char *brand, size_t brandsize,
    919     boolean_t default_query)
    920 {
    921 	int ret, sz;
    922 
    923 	ret = getrootattr(handle, DTD_ATTR_BRAND, brand, brandsize);
    924 
    925 	/*
    926 	 * If the lookup failed, or succeeded in finding a non-null brand
    927 	 * string then return.
    928 	 */
    929 	if (ret != Z_OK || brand[0] != '\0')
    930 		return (ret);
    931 
    932 	if (!default_query) {
    933 		/* If the zone has no brand, it is the default brand. */
    934 		return (zonecfg_default_brand(brand, brandsize));
    935 	}
    936 
    937 	/* if SUNWdefault didn't specify a brand, fallback to "native" */
    938 	sz = strlcpy(brand, NATIVE_BRAND_NAME, brandsize);
    939 	if (sz >= brandsize)
    940 		return (Z_TOO_BIG);
    941 	return (Z_OK);
    942 }
    943 
    944 int
    945 zonecfg_get_brand(zone_dochandle_t handle, char *brand, size_t brandsize)
    946 {
    947 	return (i_zonecfg_get_brand(handle, brand, brandsize, B_FALSE));
    948 }
    949 
    950 int
    951 zonecfg_set_brand(zone_dochandle_t handle, char *brand)
    952 {
    953 	return (setrootattr(handle, DTD_ATTR_BRAND, brand));
    954 }
    955 
    956 int
    957 zonecfg_get_autoboot(zone_dochandle_t handle, boolean_t *autoboot)
    958 {
    959 	char autobootstr[DTD_ENTITY_BOOL_LEN];
    960 	int ret;
    961 
    962 	if ((ret = getrootattr(handle, DTD_ATTR_AUTOBOOT, autobootstr,
    963 	    sizeof (autobootstr))) != Z_OK)
    964 		return (ret);
    965 
    966 	if (strcmp(autobootstr, DTD_ENTITY_TRUE) == 0)
    967 		*autoboot = B_TRUE;
    968 	else if (strcmp(autobootstr, DTD_ENTITY_FALSE) == 0)
    969 		*autoboot = B_FALSE;
    970 	else
    971 		ret = Z_BAD_PROPERTY;
    972 	return (ret);
    973 }
    974 
    975 int
    976 zonecfg_set_autoboot(zone_dochandle_t handle, boolean_t autoboot)
    977 {
    978 	return (setrootattr(handle, DTD_ATTR_AUTOBOOT,
    979 	    autoboot ? DTD_ENTITY_TRUE : DTD_ENTITY_FALSE));
    980 }
    981 
    982 int
    983 zonecfg_get_pool(zone_dochandle_t handle, char *pool, size_t poolsize)
    984 {
    985 	return (getrootattr(handle, DTD_ATTR_POOL, pool, poolsize));
    986 }
    987 
    988 int
    989 zonecfg_set_pool(zone_dochandle_t handle, char *pool)
    990 {
    991 	return (setrootattr(handle, DTD_ATTR_POOL, pool));
    992 }
    993 
    994 int
    995 zonecfg_get_limitpriv(zone_dochandle_t handle, char **limitpriv)
    996 {
    997 	return (get_alloc_rootattr(handle, DTD_ATTR_LIMITPRIV, limitpriv));
    998 }
    999 
   1000 int
   1001 zonecfg_set_limitpriv(zone_dochandle_t handle, char *limitpriv)
   1002 {
   1003 	return (setrootattr(handle, DTD_ATTR_LIMITPRIV, limitpriv));
   1004 }
   1005 
   1006 int
   1007 zonecfg_get_bootargs(zone_dochandle_t handle, char *bargs, size_t bargssize)
   1008 {
   1009 	return (getrootattr(handle, DTD_ATTR_BOOTARGS, bargs, bargssize));
   1010 }
   1011 
   1012 int
   1013 zonecfg_set_bootargs(zone_dochandle_t handle, char *bargs)
   1014 {
   1015 	return (setrootattr(handle, DTD_ATTR_BOOTARGS, bargs));
   1016 }
   1017 
   1018 int
   1019 zonecfg_get_sched_class(zone_dochandle_t handle, char *sched, size_t schedsize)
   1020 {
   1021 	return (getrootattr(handle, DTD_ATTR_SCHED, sched, schedsize));
   1022 }
   1023 
   1024 int
   1025 zonecfg_set_sched(zone_dochandle_t handle, char *sched)
   1026 {
   1027 	return (setrootattr(handle, DTD_ATTR_SCHED, sched));
   1028 }
   1029 
   1030 /*
   1031  * /etc/zones/index caches a vital piece of information which is also
   1032  * in the <zonename>.xml file: the path to the zone.  This is for performance,
   1033  * since we need to walk all zonepath's in order to be able to detect conflicts
   1034  * (see crosscheck_zonepaths() in the zoneadm command).
   1035  *
   1036  * An additional complexity is that when doing a rename, we'd like the entire
   1037  * index update operation (rename, and potential state changes) to be atomic.
   1038  * In general, the operation of this function should succeed or fail as
   1039  * a unit.
   1040  */
   1041 int
   1042 zonecfg_refresh_index_file(zone_dochandle_t handle)
   1043 {
   1044 	char name[ZONENAME_MAX], zonepath[MAXPATHLEN];
   1045 	struct zoneent ze;
   1046 	int err;
   1047 	int opcode;
   1048 	char *zn;
   1049 
   1050 	bzero(&ze, sizeof (ze));
   1051 	ze.zone_state = -1;	/* Preserve existing state in index */
   1052 
   1053 	if ((err = zonecfg_get_name(handle, name, sizeof (name))) != Z_OK)
   1054 		return (err);
   1055 	(void) strlcpy(ze.zone_name, name, sizeof (ze.zone_name));
   1056 
   1057 	if ((err = zonecfg_get_zonepath(handle, zonepath,
   1058 	    sizeof (zonepath))) != Z_OK)
   1059 		return (err);
   1060 	(void) strlcpy(ze.zone_path, zonepath + strlen(zonecfg_root),
   1061 	    sizeof (ze.zone_path));
   1062 
   1063 	if (is_renaming(handle)) {
   1064 		opcode = PZE_MODIFY;
   1065 		(void) strlcpy(ze.zone_name, handle->zone_dh_delete_name,
   1066 		    sizeof (ze.zone_name));
   1067 		(void) strlcpy(ze.zone_newname, name, sizeof (ze.zone_newname));
   1068 	} else if (is_new(handle)) {
   1069 		FILE *cookie;
   1070 		/*
   1071 		 * Be tolerant of the zone already existing in the index file,
   1072 		 * since we might be forcibly overwriting an existing
   1073 		 * configuration with a new one (for example 'create -F'
   1074 		 * in zonecfg).
   1075 		 */
   1076 		opcode = PZE_ADD;
   1077 		cookie = setzoneent();
   1078 		while ((zn = getzoneent(cookie)) != NULL) {
   1079 			if (strcmp(zn, name) == 0) {
   1080 				opcode = PZE_MODIFY;
   1081 				free(zn);
   1082 				break;
   1083 			}
   1084 			free(zn);
   1085 		}
   1086 		endzoneent(cookie);
   1087 		ze.zone_state = ZONE_STATE_CONFIGURED;
   1088 	} else {
   1089 		opcode = PZE_MODIFY;
   1090 	}
   1091 
   1092 	if ((err = putzoneent(&ze, opcode)) != Z_OK)
   1093 		return (err);
   1094 
   1095 	return (Z_OK);
   1096 }
   1097 
   1098 /*
   1099  * The goal of this routine is to cause the index file update and the
   1100  * document save to happen as an atomic operation.  We do the document
   1101  * first, saving a backup copy using a hard link; if that succeeds, we go
   1102  * on to the index.  If that fails, we roll the document back into place.
   1103  *
   1104  * Strategy:
   1105  *
   1106  * New zone 'foo' configuration:
   1107  * 	Create tmpfile (zonecfg.xxxxxx)
   1108  * 	Write XML to tmpfile
   1109  * 	Rename tmpfile to xmlfile (zonecfg.xxxxxx -> foo.xml)
   1110  * 	Add entry to index file
   1111  * 	If it fails, delete foo.xml, leaving nothing behind.
   1112  *
   1113  * Save existing zone 'foo':
   1114  * 	Make backup of foo.xml -> .backup
   1115  * 	Create tmpfile (zonecfg.xxxxxx)
   1116  * 	Write XML to tmpfile
   1117  * 	Rename tmpfile to xmlfile (zonecfg.xxxxxx -> foo.xml)
   1118  * 	Modify index file as needed
   1119  * 	If it fails, recover from .backup -> foo.xml
   1120  *
   1121  * Rename 'foo' to 'bar':
   1122  * 	Create tmpfile (zonecfg.xxxxxx)
   1123  * 	Write XML to tmpfile
   1124  * 	Rename tmpfile to xmlfile (zonecfg.xxxxxx -> bar.xml)
   1125  * 	Add entry for 'bar' to index file, Remove entry for 'foo' (refresh)
   1126  * 	If it fails, delete bar.xml; foo.xml is left behind.
   1127  */
   1128 static int
   1129 zonecfg_save_impl(zone_dochandle_t handle, char *filename)
   1130 {
   1131 	char tmpfile[MAXPATHLEN];
   1132 	char bakdir[MAXPATHLEN], bakbase[MAXPATHLEN], bakfile[MAXPATHLEN];
   1133 	int tmpfd, err, valid;
   1134 	xmlValidCtxt cvp = { NULL };
   1135 	boolean_t backup;
   1136 
   1137 	(void) strlcpy(tmpfile, filename, sizeof (tmpfile));
   1138 	(void) dirname(tmpfile);
   1139 	(void) strlcat(tmpfile, _PATH_TMPFILE, sizeof (tmpfile));
   1140 
   1141 	tmpfd = mkstemp(tmpfile);
   1142 	if (tmpfd == -1) {
   1143 		(void) unlink(tmpfile);
   1144 		return (Z_TEMP_FILE);
   1145 	}
   1146 	(void) close(tmpfd);
   1147 
   1148 	cvp.error = zonecfg_error_func;
   1149 	cvp.warning = zonecfg_error_func;
   1150 
   1151 	/*
   1152 	 * We do a final validation of the document.  Since the library has
   1153 	 * malfunctioned if it fails to validate, we follow-up with an
   1154 	 * assert() that the doc is valid.
   1155 	 */
   1156 	valid = xmlValidateDocument(&cvp, handle->zone_dh_doc);
   1157 	assert(valid != 0);
   1158 
   1159 	if (xmlSaveFormatFile(tmpfile, handle->zone_dh_doc, 1) <= 0)
   1160 		goto err;
   1161 
   1162 	(void) chmod(tmpfile, 0644);
   1163 
   1164 	/*
   1165 	 * In the event we are doing a standard save, hard link a copy of the
   1166 	 * original file in .backup.<pid>.filename so we can restore it if
   1167 	 * something goes wrong.
   1168 	 */
   1169 	if (!is_new(handle) && !is_renaming(handle)) {
   1170 		backup = B_TRUE;
   1171 
   1172 		(void) strlcpy(bakdir, filename, sizeof (bakdir));
   1173 		(void) strlcpy(bakbase, filename, sizeof (bakbase));
   1174 		(void) snprintf(bakfile, sizeof (bakfile), "%s/.backup.%d.%s",
   1175 		    dirname(bakdir), getpid(), basename(bakbase));
   1176 
   1177 		if (link(filename, bakfile) == -1) {
   1178 			err = errno;
   1179 			(void) unlink(tmpfile);
   1180 			if (errno == EACCES)
   1181 				return (Z_ACCES);
   1182 			return (Z_MISC_FS);
   1183 		}
   1184 	}
   1185 
   1186 	/*
   1187 	 * Move the new document over top of the old.
   1188 	 * i.e.:   zonecfg.XXXXXX  ->  myzone.xml
   1189 	 */
   1190 	if (rename(tmpfile, filename) == -1) {
   1191 		err = errno;
   1192 		(void) unlink(tmpfile);
   1193 		if (backup)
   1194 			(void) unlink(bakfile);
   1195 		if (err == EACCES)
   1196 			return (Z_ACCES);
   1197 		return (Z_MISC_FS);
   1198 	}
   1199 
   1200 	/*
   1201 	 * If this is a snapshot, we're done-- don't add an index entry.
   1202 	 */
   1203 	if (is_snapshot(handle))
   1204 		return (Z_OK);
   1205 
   1206 	/* now update the index file to reflect whatever we just did */
   1207 	if ((err = zonecfg_refresh_index_file(handle)) != Z_OK) {
   1208 		if (backup) {
   1209 			/*
   1210 			 * Try to restore from our backup.
   1211 			 */
   1212 			(void) unlink(filename);
   1213 			(void) rename(bakfile, filename);
   1214 		} else {
   1215 			/*
   1216 			 * Either the zone is new, in which case we can delete
   1217 			 * new.xml, or we're doing a rename, so ditto.
   1218 			 */
   1219 			assert(is_new(handle) || is_renaming(handle));
   1220 			(void) unlink(filename);
   1221 		}
   1222 		return (Z_UPDATING_INDEX);
   1223 	}
   1224 
   1225 	if (backup)
   1226 		(void) unlink(bakfile);
   1227 
   1228 	return (Z_OK);
   1229 
   1230 err:
   1231 	(void) unlink(tmpfile);
   1232 	return (Z_SAVING_FILE);
   1233 }
   1234 
   1235 int
   1236 zonecfg_save(zone_dochandle_t handle)
   1237 {
   1238 	char zname[ZONENAME_MAX], path[MAXPATHLEN];
   1239 	char delpath[MAXPATHLEN];
   1240 	int err = Z_SAVING_FILE;
   1241 
   1242 	if (zonecfg_check_handle(handle) != Z_OK)
   1243 		return (Z_BAD_HANDLE);
   1244 
   1245 	/*
   1246 	 * We don't support saving snapshots or a tree containing a sw
   1247 	 * inventory at this time.
   1248 	 */
   1249 	if (handle->zone_dh_snapshot || handle->zone_dh_sw_inv)
   1250 		return (Z_INVAL);
   1251 
   1252 	if ((err = zonecfg_get_name(handle, zname, sizeof (zname))) != Z_OK)
   1253 		return (err);
   1254 
   1255 	if (!config_file_path(zname, path))
   1256 		return (Z_MISC_FS);
   1257 
   1258 	addcomment(handle, "\n    DO NOT EDIT THIS "
   1259 	    "FILE.  Use zonecfg(1M) instead.\n");
   1260 
   1261 	err = zonecfg_save_impl(handle, path);
   1262 
   1263 	stripcomments(handle);
   1264 
   1265 	if (err != Z_OK)
   1266 		return (err);
   1267 
   1268 	handle->zone_dh_newzone = B_FALSE;
   1269 
   1270 	if (is_renaming(handle)) {
   1271 		if (config_file_path(handle->zone_dh_delete_name, delpath))
   1272 			(void) unlink(delpath);
   1273 		handle->zone_dh_delete_name[0] = '\0';
   1274 	}
   1275 
   1276 	return (Z_OK);
   1277 }
   1278 
   1279 int
   1280 zonecfg_verify_save(zone_dochandle_t handle, char *filename)
   1281 {
   1282 	int valid;
   1283 
   1284 	xmlValidCtxt cvp = { NULL };
   1285 
   1286 	if (zonecfg_check_handle(handle) != Z_OK)
   1287 		return (Z_BAD_HANDLE);
   1288 
   1289 	cvp.error = zonecfg_error_func;
   1290 	cvp.warning = zonecfg_error_func;
   1291 
   1292 	/*
   1293 	 * We do a final validation of the document.  Since the library has
   1294 	 * malfunctioned if it fails to validate, we follow-up with an
   1295 	 * assert() that the doc is valid.
   1296 	 */
   1297 	valid = xmlValidateDocument(&cvp, handle->zone_dh_doc);
   1298 	assert(valid != 0);
   1299 
   1300 	if (xmlSaveFormatFile(filename, handle->zone_dh_doc, 1) <= 0)
   1301 		return (Z_SAVING_FILE);
   1302 
   1303 	return (Z_OK);
   1304 }
   1305 
   1306 int
   1307 zonecfg_detach_save(zone_dochandle_t handle, uint_t flags)
   1308 {
   1309 	char zname[ZONENAME_MAX];
   1310 	char path[MAXPATHLEN];
   1311 	char migpath[MAXPATHLEN];
   1312 	xmlValidCtxt cvp = { NULL };
   1313 	int err = Z_SAVING_FILE;
   1314 	int valid;
   1315 
   1316 	if (zonecfg_check_handle(handle) != Z_OK)
   1317 		return (Z_BAD_HANDLE);
   1318 
   1319 	if (flags & ZONE_DRY_RUN) {
   1320 		(void) strlcpy(migpath, "-", sizeof (migpath));
   1321 	} else {
   1322 		if ((err = zonecfg_get_name(handle, zname, sizeof (zname)))
   1323 		    != Z_OK)
   1324 			return (err);
   1325 
   1326 		if ((err = zone_get_zonepath(zname, path, sizeof (path)))
   1327 		    != Z_OK)
   1328 			return (err);
   1329 
   1330 		if (snprintf(migpath, sizeof (migpath), "%s/%s", path,
   1331 		    ZONE_DETACHED) >= sizeof (migpath))
   1332 			return (Z_NOMEM);
   1333 	}
   1334 
   1335 	if ((err = operation_prep(handle)) != Z_OK)
   1336 		return (err);
   1337 
   1338 	addcomment(handle, "\n    DO NOT EDIT THIS FILE.  "
   1339 	    "Use zonecfg(1M) and zoneadm(1M) attach.\n");
   1340 
   1341 	cvp.error = zonecfg_error_func;
   1342 	cvp.warning = zonecfg_error_func;
   1343 
   1344 	/*
   1345 	 * We do a final validation of the document.  Since the library has
   1346 	 * malfunctioned if it fails to validate, we follow-up with an
   1347 	 * assert() that the doc is valid.
   1348 	 */
   1349 	valid = xmlValidateDocument(&cvp, handle->zone_dh_doc);
   1350 	assert(valid != 0);
   1351 
   1352 	if (xmlSaveFormatFile(migpath, handle->zone_dh_doc, 1) <= 0)
   1353 		return (Z_SAVING_FILE);
   1354 
   1355 	if (!(flags & ZONE_DRY_RUN))
   1356 		(void) chmod(migpath, 0644);
   1357 
   1358 	stripcomments(handle);
   1359 
   1360 	handle->zone_dh_newzone = B_FALSE;
   1361 
   1362 	return (Z_OK);
   1363 }
   1364 
   1365 boolean_t
   1366 zonecfg_detached(const char *path)
   1367 {
   1368 	char		migpath[MAXPATHLEN];
   1369 	struct stat	buf;
   1370 
   1371 	if (snprintf(migpath, sizeof (migpath), "%s/%s", path, ZONE_DETACHED) >=
   1372 	    sizeof (migpath))
   1373 		return (B_FALSE);
   1374 
   1375 	if (stat(migpath, &buf) != -1)
   1376 		return (B_TRUE);
   1377 
   1378 	return (B_FALSE);
   1379 }
   1380 
   1381 void
   1382 zonecfg_rm_detached(zone_dochandle_t handle, boolean_t forced)
   1383 {
   1384 	char zname[ZONENAME_MAX];
   1385 	char path[MAXPATHLEN];
   1386 	char detached[MAXPATHLEN];
   1387 	char attached[MAXPATHLEN];
   1388 
   1389 	if (zonecfg_check_handle(handle) != Z_OK)
   1390 		return;
   1391 
   1392 	if (zonecfg_get_name(handle, zname, sizeof (zname)) != Z_OK)
   1393 		return;
   1394 
   1395 	if (zone_get_zonepath(zname, path, sizeof (path)) != Z_OK)
   1396 		return;
   1397 
   1398 	(void) snprintf(detached, sizeof (detached), "%s/%s", path,
   1399 	    ZONE_DETACHED);
   1400 	(void) snprintf(attached, sizeof (attached), "%s/%s", path,
   1401 	    ATTACH_FORCED);
   1402 
   1403 	if (forced) {
   1404 		(void) rename(detached, attached);
   1405 	} else {
   1406 		(void) unlink(attached);
   1407 		(void) unlink(detached);
   1408 	}
   1409 }
   1410 
   1411 /*
   1412  * Special case: if access(2) fails with ENOENT, then try again using
   1413  * ZONE_CONFIG_ROOT instead of config_file_path(zonename).  This is how we
   1414  * work around the case of a config file which has not been created yet:
   1415  * the user will need access to the directory so use that as a heuristic.
   1416  */
   1417 
   1418 int
   1419 zonecfg_access(const char *zonename, int amode)
   1420 {
   1421 	char path[MAXPATHLEN];
   1422 
   1423 	if (!config_file_path(zonename, path))
   1424 		return (Z_INVAL);
   1425 	if (access(path, amode) == 0)
   1426 		return (Z_OK);
   1427 	if (errno == ENOENT) {
   1428 		if (snprintf(path, sizeof (path), "%s%s", zonecfg_root,
   1429 		    ZONE_CONFIG_ROOT) >= sizeof (path))
   1430 			return (Z_INVAL);
   1431 		if (access(path, amode) == 0)
   1432 			return (Z_OK);
   1433 	}
   1434 	if (errno == EACCES)
   1435 		return (Z_ACCES);
   1436 	if (errno == EINVAL)
   1437 		return (Z_INVAL);
   1438 	return (Z_MISC_FS);
   1439 }
   1440 
   1441 int
   1442 zonecfg_create_snapshot(const char *zonename)
   1443 {
   1444 	zone_dochandle_t handle;
   1445 	char path[MAXPATHLEN], zonepath[MAXPATHLEN], rpath[MAXPATHLEN];
   1446 	int error = Z_OK, res;
   1447 
   1448 	if ((handle = zonecfg_init_handle()) == NULL) {
   1449 		return (Z_NOMEM);
   1450 	}
   1451 
   1452 	handle->zone_dh_newzone = B_TRUE;
   1453 	handle->zone_dh_snapshot = B_TRUE;
   1454 
   1455 	if ((error = zonecfg_get_handle(zonename, handle)) != Z_OK)
   1456 		goto out;
   1457 	if ((error = operation_prep(handle)) != Z_OK)
   1458 		goto out;
   1459 	error = zonecfg_get_zonepath(handle, zonepath, sizeof (zonepath));
   1460 	if (error != Z_OK)
   1461 		goto out;
   1462 	if ((res = resolvepath(zonepath, rpath, sizeof (rpath))) == -1) {
   1463 		error = Z_RESOLVED_PATH;
   1464 		goto out;
   1465 	}
   1466 	/*
   1467 	 * If the resolved path is not the same as the original path, then
   1468 	 * save the resolved path in the snapshot, thus preventing any
   1469 	 * potential problems down the line when zoneadmd goes to unmount
   1470 	 * file systems and depends on initial string matches with resolved
   1471 	 * paths.
   1472 	 */
   1473 	rpath[res] = '\0';
   1474 	if (strcmp(zonepath, rpath) != 0) {
   1475 		if ((error = zonecfg_set_zonepath(handle, rpath)) != Z_OK)
   1476 			goto out;
   1477 	}
   1478 	if (snprintf(path, sizeof (path), "%s%s", zonecfg_root,
   1479 	    ZONE_SNAPSHOT_ROOT) >= sizeof (path)) {
   1480 		error = Z_MISC_FS;
   1481 		goto out;
   1482 	}
   1483 	if ((mkdir(path, S_IRWXU) == -1) && (errno != EEXIST)) {
   1484 		error = Z_MISC_FS;
   1485 		goto out;
   1486 	}
   1487 
   1488 	if (!snap_file_path(zonename, path)) {
   1489 		error = Z_MISC_FS;
   1490 		goto out;
   1491 	}
   1492 
   1493 	addcomment(handle, "\n    DO NOT EDIT THIS FILE.  "
   1494 	    "It is a snapshot of running zone state.\n");
   1495 
   1496 	error = zonecfg_save_impl(handle, path);
   1497 
   1498 	stripcomments(handle);
   1499 
   1500 out:
   1501 	zonecfg_fini_handle(handle);
   1502 	return (error);
   1503 }
   1504 
   1505 int
   1506 zonecfg_get_iptype(zone_dochandle_t handle, zone_iptype_t *iptypep)
   1507 {
   1508 	char property[10]; /* 10 is big enough for "shared"/"exclusive" */
   1509 	int err;
   1510 
   1511 	err = getrootattr(handle, DTD_ATTR_IPTYPE, property, sizeof (property));
   1512 	if (err == Z_BAD_PROPERTY) {
   1513 		/* Return default value */
   1514 		*iptypep = ZS_SHARED;
   1515 		return (Z_OK);
   1516 	} else if (err != Z_OK) {
   1517 		return (err);
   1518 	}
   1519 
   1520 	if (strlen(property) == 0 ||
   1521 	    strcmp(property, "shared") == 0)
   1522 		*iptypep = ZS_SHARED;
   1523 	else if (strcmp(property, "exclusive") == 0)
   1524 		*iptypep = ZS_EXCLUSIVE;
   1525 	else
   1526 		return (Z_INVAL);
   1527 
   1528 	return (Z_OK);
   1529 }
   1530 
   1531 int
   1532 zonecfg_set_iptype(zone_dochandle_t handle, zone_iptype_t iptype)
   1533 {
   1534 	xmlNodePtr cur;
   1535 
   1536 	if (handle == NULL)
   1537 		return (Z_INVAL);
   1538 
   1539 	cur = xmlDocGetRootElement(handle->zone_dh_doc);
   1540 	if (cur == NULL) {
   1541 		return (Z_EMPTY_DOCUMENT);
   1542 	}
   1543 
   1544 	if (xmlStrcmp(cur->name, DTD_ELEM_ZONE) != 0) {
   1545 		return (Z_WRONG_DOC_TYPE);
   1546 	}
   1547 	switch (iptype) {
   1548 	case ZS_SHARED:
   1549 		/*
   1550 		 * Since "shared" is the default, we don't write it to the
   1551 		 * configuration file, so that it's easier to migrate those
   1552 		 * zones elsewhere, eg., to systems which are not IP-Instances
   1553 		 * aware.
   1554 		 * xmlUnsetProp only fails when the attribute doesn't exist,
   1555 		 * which we don't care.
   1556 		 */
   1557 		(void) xmlUnsetProp(cur, DTD_ATTR_IPTYPE);
   1558 		break;
   1559 	case ZS_EXCLUSIVE:
   1560 		if (xmlSetProp(cur, DTD_ATTR_IPTYPE,
   1561 		    (const xmlChar *) "exclusive") == NULL)
   1562 			return (Z_INVAL);
   1563 		break;
   1564 	}
   1565 	return (Z_OK);
   1566 }
   1567 
   1568 static int
   1569 newprop(xmlNodePtr node, const xmlChar *attrname, char *src)
   1570 {
   1571 	xmlAttrPtr newattr;
   1572 
   1573 	newattr = xmlNewProp(node, attrname, (xmlChar *)src);
   1574 	if (newattr == NULL) {
   1575 		xmlUnlinkNode(node);
   1576 		xmlFreeNode(node);
   1577 		return (Z_BAD_PROPERTY);
   1578 	}
   1579 	return (Z_OK);
   1580 }
   1581 
   1582 static int
   1583 zonecfg_add_filesystem_core(zone_dochandle_t handle, struct zone_fstab *tabptr)
   1584 {
   1585 	xmlNodePtr newnode, cur = handle->zone_dh_cur, options_node;
   1586 	zone_fsopt_t *ptr;
   1587 	int err;
   1588 
   1589 	newnode = xmlNewTextChild(cur, NULL, DTD_ELEM_FS, NULL);
   1590 	if ((err = newprop(newnode, DTD_ATTR_SPECIAL,
   1591 	    tabptr->zone_fs_special)) != Z_OK)
   1592 		return (err);
   1593 	if (tabptr->zone_fs_raw[0] != '\0' &&
   1594 	    (err = newprop(newnode, DTD_ATTR_RAW, tabptr->zone_fs_raw)) != Z_OK)
   1595 		return (err);
   1596 	if ((err = newprop(newnode, DTD_ATTR_DIR, tabptr->zone_fs_dir)) != Z_OK)
   1597 		return (err);
   1598 	if ((err = newprop(newnode, DTD_ATTR_TYPE,
   1599 	    tabptr->zone_fs_type)) != Z_OK)
   1600 		return (err);
   1601 	if (tabptr->zone_fs_options != NULL) {
   1602 		for (ptr = tabptr->zone_fs_options; ptr != NULL;
   1603 		    ptr = ptr->zone_fsopt_next) {
   1604 			options_node = xmlNewTextChild(newnode, NULL,
   1605 			    DTD_ELEM_FSOPTION, NULL);
   1606 			if ((err = newprop(options_node, DTD_ATTR_NAME,
   1607 			    ptr->zone_fsopt_opt)) != Z_OK)
   1608 				return (err);
   1609 		}
   1610 	}
   1611 	return (Z_OK);
   1612 }
   1613 
   1614 int
   1615 zonecfg_add_filesystem(zone_dochandle_t handle, struct zone_fstab *tabptr)
   1616 {
   1617 	int err;
   1618 
   1619 	if (tabptr == NULL)
   1620 		return (Z_INVAL);
   1621 
   1622 	if ((err = operation_prep(handle)) != Z_OK)
   1623 		return (err);
   1624 
   1625 	if ((err = zonecfg_add_filesystem_core(handle, tabptr)) != Z_OK)
   1626 		return (err);
   1627 
   1628 	return (Z_OK);
   1629 }
   1630 
   1631 static int
   1632 zonecfg_add_ipd_core(zone_dochandle_t handle, struct zone_fstab *tabptr)
   1633 {
   1634 	xmlNodePtr newnode, cur = handle->zone_dh_cur;
   1635 	int err;
   1636 
   1637 	newnode = xmlNewTextChild(cur, NULL, DTD_ELEM_IPD, NULL);
   1638 	if ((err = newprop(newnode, DTD_ATTR_DIR, tabptr->zone_fs_dir)) != Z_OK)
   1639 		return (err);
   1640 	return (Z_OK);
   1641 }
   1642 
   1643 int
   1644 zonecfg_add_ipd(zone_dochandle_t handle, struct zone_fstab *tabptr)
   1645 {
   1646 	int err;
   1647 
   1648 	if (tabptr == NULL)
   1649 		return (Z_INVAL);
   1650 
   1651 	if ((err = operation_prep(handle)) != Z_OK)
   1652 		return (err);
   1653 
   1654 	if ((err = zonecfg_add_ipd_core(handle, tabptr)) != Z_OK)
   1655 		return (err);
   1656 
   1657 	return (Z_OK);
   1658 }
   1659 
   1660 int
   1661 zonecfg_add_fs_option(struct zone_fstab *tabptr, char *option)
   1662 {
   1663 	zone_fsopt_t *last, *old, *new;
   1664 
   1665 	last = tabptr->zone_fs_options;
   1666 	for (old = last; old != NULL; old = old->zone_fsopt_next)
   1667 		last = old;	/* walk to the end of the list */
   1668 	new = (zone_fsopt_t *)malloc(sizeof (zone_fsopt_t));
   1669 	if (new == NULL)
   1670 		return (Z_NOMEM);
   1671 	(void) strlcpy(new->zone_fsopt_opt, option,
   1672 	    sizeof (new->zone_fsopt_opt));
   1673 	new->zone_fsopt_next = NULL;
   1674 	if (last == NULL)
   1675 		tabptr->zone_fs_options = new;
   1676 	else
   1677 		last->zone_fsopt_next = new;
   1678 	return (Z_OK);
   1679 }
   1680 
   1681 int
   1682 zonecfg_remove_fs_option(struct zone_fstab *tabptr, char *option)
   1683 {
   1684 	zone_fsopt_t *last, *this, *next;
   1685 
   1686 	last = tabptr->zone_fs_options;
   1687 	for (this = last; this != NULL; this = this->zone_fsopt_next) {
   1688 		if (strcmp(this->zone_fsopt_opt, option) == 0) {
   1689 			next = this->zone_fsopt_next;
   1690 			if (this == tabptr->zone_fs_options)
   1691 				tabptr->zone_fs_options = next;
   1692 			else
   1693 				last->zone_fsopt_next = next;
   1694 			free(this);
   1695 			return (Z_OK);
   1696 		} else
   1697 			last = this;
   1698 	}
   1699 	return (Z_NO_PROPERTY_ID);
   1700 }
   1701 
   1702 void
   1703 zonecfg_free_fs_option_list(zone_fsopt_t *list)
   1704 {
   1705 	zone_fsopt_t *this, *next;
   1706 
   1707 	for (this = list; this != NULL; this = next) {
   1708 		next = this->zone_fsopt_next;
   1709 		free(this);
   1710 	}
   1711 }
   1712 
   1713 void
   1714 zonecfg_free_rctl_value_list(struct zone_rctlvaltab *valtab)
   1715 {
   1716 	if (valtab == NULL)
   1717 		return;
   1718 	zonecfg_free_rctl_value_list(valtab->zone_rctlval_next);
   1719 	free(valtab);
   1720 }
   1721 
   1722 static boolean_t
   1723 match_prop(xmlNodePtr cur, const xmlChar *attr, char *user_prop)
   1724 {
   1725 	xmlChar *gotten_prop;
   1726 	int prop_result;
   1727 
   1728 	gotten_prop = xmlGetProp(cur, attr);
   1729 	if (gotten_prop == NULL)	/* shouldn't happen */
   1730 		return (B_FALSE);
   1731 	prop_result = xmlStrcmp(gotten_prop, (const xmlChar *) user_prop);
   1732 	xmlFree(gotten_prop);
   1733 	return ((prop_result == 0));
   1734 }
   1735 
   1736 static int
   1737 zonecfg_delete_filesystem_core(zone_dochandle_t handle,
   1738     struct zone_fstab *tabptr)
   1739 {
   1740 	xmlNodePtr cur = handle->zone_dh_cur;
   1741 	boolean_t dir_match, spec_match, raw_match, type_match;
   1742 
   1743 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   1744 		if (xmlStrcmp(cur->name, DTD_ELEM_FS))
   1745 			continue;
   1746 		dir_match = match_prop(cur, DTD_ATTR_DIR, tabptr->zone_fs_dir);
   1747 		spec_match = match_prop(cur, DTD_ATTR_SPECIAL,
   1748 		    tabptr->zone_fs_special);
   1749 		raw_match = match_prop(cur, DTD_ATTR_RAW,
   1750 		    tabptr->zone_fs_raw);
   1751 		type_match = match_prop(cur, DTD_ATTR_TYPE,
   1752 		    tabptr->zone_fs_type);
   1753 		if (dir_match && spec_match && raw_match && type_match) {
   1754 			xmlUnlinkNode(cur);
   1755 			xmlFreeNode(cur);
   1756 			return (Z_OK);
   1757 		}
   1758 	}
   1759 	return (Z_NO_RESOURCE_ID);
   1760 }
   1761 
   1762 int
   1763 zonecfg_delete_filesystem(zone_dochandle_t handle, struct zone_fstab *tabptr)
   1764 {
   1765 	int err;
   1766 
   1767 	if (tabptr == NULL)
   1768 		return (Z_INVAL);
   1769 
   1770 	if ((err = operation_prep(handle)) != Z_OK)
   1771 		return (err);
   1772 
   1773 	if ((err = zonecfg_delete_filesystem_core(handle, tabptr)) != Z_OK)
   1774 		return (err);
   1775 
   1776 	return (Z_OK);
   1777 }
   1778 
   1779 int
   1780 zonecfg_modify_filesystem(
   1781 	zone_dochandle_t handle,
   1782 	struct zone_fstab *oldtabptr,
   1783 	struct zone_fstab *newtabptr)
   1784 {
   1785 	int err;
   1786 
   1787 	if (oldtabptr == NULL || newtabptr == NULL)
   1788 		return (Z_INVAL);
   1789 
   1790 	if ((err = operation_prep(handle)) != Z_OK)
   1791 		return (err);
   1792 
   1793 	if ((err = zonecfg_delete_filesystem_core(handle, oldtabptr)) != Z_OK)
   1794 		return (err);
   1795 
   1796 	if ((err = zonecfg_add_filesystem_core(handle, newtabptr)) != Z_OK)
   1797 		return (err);
   1798 
   1799 	return (Z_OK);
   1800 }
   1801 
   1802 static int
   1803 zonecfg_delete_ipd_core(zone_dochandle_t handle, struct zone_fstab *tabptr)
   1804 {
   1805 	xmlNodePtr cur = handle->zone_dh_cur;
   1806 
   1807 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   1808 		if (xmlStrcmp(cur->name, DTD_ELEM_IPD))
   1809 			continue;
   1810 		if (match_prop(cur, DTD_ATTR_DIR, tabptr->zone_fs_dir)) {
   1811 			xmlUnlinkNode(cur);
   1812 			xmlFreeNode(cur);
   1813 			return (Z_OK);
   1814 		}
   1815 	}
   1816 	return (Z_NO_RESOURCE_ID);
   1817 }
   1818 
   1819 int
   1820 zonecfg_delete_ipd(zone_dochandle_t handle, struct zone_fstab *tabptr)
   1821 {
   1822 	int err;
   1823 
   1824 	if (tabptr == NULL)
   1825 		return (Z_INVAL);
   1826 
   1827 	if ((err = operation_prep(handle)) != Z_OK)
   1828 		return (err);
   1829 
   1830 	if ((err = zonecfg_delete_ipd_core(handle, tabptr)) != Z_OK)
   1831 		return (err);
   1832 
   1833 	return (Z_OK);
   1834 }
   1835 
   1836 int
   1837 zonecfg_modify_ipd(zone_dochandle_t handle, struct zone_fstab *oldtabptr,
   1838     struct zone_fstab *newtabptr)
   1839 {
   1840 	int err;
   1841 
   1842 	if (oldtabptr == NULL || newtabptr == NULL)
   1843 		return (Z_INVAL);
   1844 
   1845 	if ((err = operation_prep(handle)) != Z_OK)
   1846 		return (err);
   1847 
   1848 	if ((err = zonecfg_delete_ipd_core(handle, oldtabptr)) != Z_OK)
   1849 		return (err);
   1850 
   1851 	if ((err = zonecfg_add_ipd_core(handle, newtabptr)) != Z_OK)
   1852 		return (err);
   1853 
   1854 	return (Z_OK);
   1855 }
   1856 
   1857 int
   1858 zonecfg_lookup_filesystem(
   1859 	zone_dochandle_t handle,
   1860 	struct zone_fstab *tabptr)
   1861 {
   1862 	xmlNodePtr cur, options, firstmatch;
   1863 	int err;
   1864 	char dirname[MAXPATHLEN], special[MAXPATHLEN], raw[MAXPATHLEN];
   1865 	char type[FSTYPSZ];
   1866 	char options_str[MAX_MNTOPT_STR];
   1867 
   1868 	if (tabptr == NULL)
   1869 		return (Z_INVAL);
   1870 
   1871 	if ((err = operation_prep(handle)) != Z_OK)
   1872 		return (err);
   1873 
   1874 	/*
   1875 	 * Walk the list of children looking for matches on any properties
   1876 	 * specified in the fstab parameter.  If more than one resource
   1877 	 * matches, we return Z_INSUFFICIENT_SPEC; if none match, we return
   1878 	 * Z_NO_RESOURCE_ID.
   1879 	 */
   1880 	cur = handle->zone_dh_cur;
   1881 	firstmatch = NULL;
   1882 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   1883 		if (xmlStrcmp(cur->name, DTD_ELEM_FS))
   1884 			continue;
   1885 		if (strlen(tabptr->zone_fs_dir) > 0) {
   1886 			if ((fetchprop(cur, DTD_ATTR_DIR, dirname,
   1887 			    sizeof (dirname)) == Z_OK) &&
   1888 			    (strcmp(tabptr->zone_fs_dir, dirname) == 0)) {
   1889 				if (firstmatch == NULL)
   1890 					firstmatch = cur;
   1891 				else
   1892 					return (Z_INSUFFICIENT_SPEC);
   1893 			}
   1894 		}
   1895 		if (strlen(tabptr->zone_fs_special) > 0) {
   1896 			if ((fetchprop(cur, DTD_ATTR_SPECIAL, special,
   1897 			    sizeof (special)) == Z_OK)) {
   1898 				if (strcmp(tabptr->zone_fs_special,
   1899 				    special) == 0) {
   1900 					if (firstmatch == NULL)
   1901 						firstmatch = cur;
   1902 					else if (firstmatch != cur)
   1903 						return (Z_INSUFFICIENT_SPEC);
   1904 				} else {
   1905 					/*
   1906 					 * If another property matched but this
   1907 					 * one doesn't then reset firstmatch.
   1908 					 */
   1909 					if (firstmatch == cur)
   1910 						firstmatch = NULL;
   1911 				}
   1912 			}
   1913 		}
   1914 		if (strlen(tabptr->zone_fs_raw) > 0) {
   1915 			if ((fetchprop(cur, DTD_ATTR_RAW, raw,
   1916 			    sizeof (raw)) == Z_OK)) {
   1917 				if (strcmp(tabptr->zone_fs_raw, raw) == 0) {
   1918 					if (firstmatch == NULL)
   1919 						firstmatch = cur;
   1920 					else if (firstmatch != cur)
   1921 						return (Z_INSUFFICIENT_SPEC);
   1922 				} else {
   1923 					/*
   1924 					 * If another property matched but this
   1925 					 * one doesn't then reset firstmatch.
   1926 					 */
   1927 					if (firstmatch == cur)
   1928 						firstmatch = NULL;
   1929 				}
   1930 			}
   1931 		}
   1932 		if (strlen(tabptr->zone_fs_type) > 0) {
   1933 			if ((fetchprop(cur, DTD_ATTR_TYPE, type,
   1934 			    sizeof (type)) == Z_OK)) {
   1935 				if (strcmp(tabptr->zone_fs_type, type) == 0) {
   1936 					if (firstmatch == NULL)
   1937 						firstmatch = cur;
   1938 					else if (firstmatch != cur)
   1939 						return (Z_INSUFFICIENT_SPEC);
   1940 				} else {
   1941 					/*
   1942 					 * If another property matched but this
   1943 					 * one doesn't then reset firstmatch.
   1944 					 */
   1945 					if (firstmatch == cur)
   1946 						firstmatch = NULL;
   1947 				}
   1948 			}
   1949 		}
   1950 	}
   1951 
   1952 	if (firstmatch == NULL)
   1953 		return (Z_NO_RESOURCE_ID);
   1954 
   1955 	cur = firstmatch;
   1956 
   1957 	if ((err = fetchprop(cur, DTD_ATTR_DIR, tabptr->zone_fs_dir,
   1958 	    sizeof (tabptr->zone_fs_dir))) != Z_OK)
   1959 		return (err);
   1960 
   1961 	if ((err = fetchprop(cur, DTD_ATTR_SPECIAL, tabptr->zone_fs_special,
   1962 	    sizeof (tabptr->zone_fs_special))) != Z_OK)
   1963 		return (err);
   1964 
   1965 	if ((err = fetchprop(cur, DTD_ATTR_RAW, tabptr->zone_fs_raw,
   1966 	    sizeof (tabptr->zone_fs_raw))) != Z_OK)
   1967 		return (err);
   1968 
   1969 	if ((err = fetchprop(cur, DTD_ATTR_TYPE, tabptr->zone_fs_type,
   1970 	    sizeof (tabptr->zone_fs_type))) != Z_OK)
   1971 		return (err);
   1972 
   1973 	/* options are optional */
   1974 	tabptr->zone_fs_options = NULL;
   1975 	for (options = cur->xmlChildrenNode; options != NULL;
   1976 	    options = options->next) {
   1977 		if ((fetchprop(options, DTD_ATTR_NAME, options_str,
   1978 		    sizeof (options_str)) != Z_OK))
   1979 			break;
   1980 		if (zonecfg_add_fs_option(tabptr, options_str) != Z_OK)
   1981 			break;
   1982 	}
   1983 	return (Z_OK);
   1984 }
   1985 
   1986 int
   1987 zonecfg_lookup_ipd(zone_dochandle_t handle, struct zone_fstab *tabptr)
   1988 {
   1989 	xmlNodePtr cur, match;
   1990 	int err;
   1991 	char dirname[MAXPATHLEN];
   1992 
   1993 	if (tabptr == NULL)
   1994 		return (Z_INVAL);
   1995 
   1996 	if ((err = operation_prep(handle)) != Z_OK)
   1997 		return (err);
   1998 
   1999 	/*
   2000 	 * General algorithm:
   2001 	 * Walk the list of children looking for matches on any properties
   2002 	 * specified in the fstab parameter.  If more than one resource
   2003 	 * matches, we return Z_INSUFFICIENT_SPEC; if none match, we return
   2004 	 * Z_NO_RESOURCE_ID.
   2005 	 */
   2006 	cur = handle->zone_dh_cur;
   2007 	match = NULL;
   2008 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   2009 		if (xmlStrcmp(cur->name, DTD_ELEM_IPD))
   2010 			continue;
   2011 		if (strlen(tabptr->zone_fs_dir) > 0) {
   2012 			if ((fetchprop(cur, DTD_ATTR_DIR, dirname,
   2013 			    sizeof (dirname)) == Z_OK) &&
   2014 			    (strcmp(tabptr->zone_fs_dir, dirname) == 0)) {
   2015 				if (match == NULL)
   2016 					match = cur;
   2017 				else
   2018 					return (Z_INSUFFICIENT_SPEC);
   2019 			}
   2020 		}
   2021 	}
   2022 
   2023 	if (match == NULL)
   2024 		return (Z_NO_RESOURCE_ID);
   2025 
   2026 	cur = match;
   2027 
   2028 	if ((err = fetchprop(cur, DTD_ATTR_DIR, tabptr->zone_fs_dir,
   2029 	    sizeof (tabptr->zone_fs_dir))) != Z_OK)
   2030 		return (err);
   2031 
   2032 	return (Z_OK);
   2033 }
   2034 
   2035 /*
   2036  * Compare two IP addresses in string form.  Allow for the possibility that
   2037  * one might have "/<prefix-length>" at the end: allow a match on just the
   2038  * IP address (or host name) part.
   2039  */
   2040 
   2041 boolean_t
   2042 zonecfg_same_net_address(char *a1, char *a2)
   2043 {
   2044 	char *slashp, *slashp1, *slashp2;
   2045 	int result;
   2046 
   2047 	if (strcmp(a1, a2) == 0)
   2048 		return (B_TRUE);
   2049 
   2050 	/*
   2051 	 * If neither has a slash or both do, they need to match to be
   2052 	 * considered the same, but they did not match above, so fail.
   2053 	 */
   2054 	slashp1 = strchr(a1, '/');
   2055 	slashp2 = strchr(a2, '/');
   2056 	if ((slashp1 == NULL && slashp2 == NULL) ||
   2057 	    (slashp1 != NULL && slashp2 != NULL))
   2058 		return (B_FALSE);
   2059 
   2060 	/*
   2061 	 * Only one had a slash: pick that one, zero out the slash, compare
   2062 	 * the "address only" strings, restore the slash, and return the
   2063 	 * result of the comparison.
   2064 	 */
   2065 	slashp = (slashp1 == NULL) ? slashp2 : slashp1;
   2066 	*slashp = '\0';
   2067 	result = strcmp(a1, a2);
   2068 	*slashp = '/';
   2069 	return ((result == 0));
   2070 }
   2071 
   2072 int
   2073 zonecfg_valid_net_address(char *address, struct lifreq *lifr)
   2074 {
   2075 	struct sockaddr_in *sin4;
   2076 	struct sockaddr_in6 *sin6;
   2077 	struct addrinfo hints, *result;
   2078 	char *slashp = strchr(address, '/');
   2079 
   2080 	bzero(lifr, sizeof (struct lifreq));
   2081 	sin4 = (struct sockaddr_in *)&lifr->lifr_addr;
   2082 	sin6 = (struct sockaddr_in6 *)&lifr->lifr_addr;
   2083 	if (slashp != NULL)
   2084 		*slashp = '\0';
   2085 	if (inet_pton(AF_INET, address, &sin4->sin_addr) == 1) {
   2086 		sin4->sin_family = AF_INET;
   2087 	} else if (inet_pton(AF_INET6, address, &sin6->sin6_addr) == 1) {
   2088 		if (slashp == NULL)
   2089 			return (Z_IPV6_ADDR_PREFIX_LEN);
   2090 		sin6->sin6_family = AF_INET6;
   2091 	} else {
   2092 		/* "address" may be a host name */
   2093 		(void) memset(&hints, 0, sizeof (hints));
   2094 		hints.ai_family = PF_INET;
   2095 		if (getaddrinfo(address, NULL, &hints, &result) != 0)
   2096 			return (Z_BOGUS_ADDRESS);
   2097 		sin4->sin_family = result->ai_family;
   2098 
   2099 		(void) memcpy(&sin4->sin_addr,
   2100 		    /* LINTED E_BAD_PTR_CAST_ALIGN */
   2101 		    &((struct sockaddr_in *)result->ai_addr)->sin_addr,
   2102 		    sizeof (struct in_addr));
   2103 
   2104 		freeaddrinfo(result);
   2105 	}
   2106 	return (Z_OK);
   2107 }
   2108 
   2109 boolean_t
   2110 zonecfg_ifname_exists(sa_family_t af, char *ifname)
   2111 {
   2112 	struct lifreq lifr;
   2113 	int so;
   2114 	int save_errno;
   2115 
   2116 	(void) memset(&lifr, 0, sizeof (lifr));
   2117 	(void) strlcpy(lifr.lifr_name, ifname, sizeof (lifr.lifr_name));
   2118 	lifr.lifr_addr.ss_family = af;
   2119 	if ((so = socket(af, SOCK_DGRAM, 0)) < 0) {
   2120 		/* Odd - can't tell if the ifname exists */
   2121 		return (B_FALSE);
   2122 	}
   2123 	if (ioctl(so, SIOCGLIFFLAGS, (caddr_t)&lifr) < 0) {
   2124 		save_errno = errno;
   2125 		(void) close(so);
   2126 		errno = save_errno;
   2127 		return (B_FALSE);
   2128 	}
   2129 	(void) close(so);
   2130 	return (B_TRUE);
   2131 }
   2132 
   2133 /*
   2134  * Determines whether there is a net resource with the physical interface, IP
   2135  * address, and default router specified by 'tabptr' in the zone configuration
   2136  * to which 'handle' refers.  'tabptr' must have an interface, an address, a
   2137  * default router, or a combination of the three.  This function returns Z_OK
   2138  * iff there is exactly one net resource matching the query specified by
   2139  * 'tabptr'.  The function returns Z_INSUFFICIENT_SPEC if there are multiple
   2140  * matches or 'tabptr' does not specify a physical interface, address, or
   2141  * default router.  The function returns Z_NO_RESOURCE_ID if are no matches.
   2142  *
   2143  * Errors might also be returned if the entry that exactly matches the
   2144  * query lacks critical network resource information.
   2145  *
   2146  * If there is a single match, then the matching entry's physical interface, IP
   2147  * address, and default router information are stored in 'tabptr'.
   2148  */
   2149 int
   2150 zonecfg_lookup_nwif(zone_dochandle_t handle, struct zone_nwiftab *tabptr)
   2151 {
   2152 	xmlNodePtr cur;
   2153 	xmlNodePtr firstmatch;
   2154 	int err;
   2155 	char address[INET6_ADDRSTRLEN];
   2156 	char physical[LIFNAMSIZ];
   2157 	size_t addrspec;		/* nonzero if tabptr has IP addr */
   2158 	size_t physspec;		/* nonzero if tabptr has interface */
   2159 	size_t defrouterspec;		/* nonzero if tabptr has def. router */
   2160 
   2161 	if (tabptr == NULL)
   2162 		return (Z_INVAL);
   2163 
   2164 	/*
   2165 	 * Determine the fields that will be searched.  There must be at least
   2166 	 * one.
   2167 	 *
   2168 	 * zone_nwif_address, zone_nwif_physical, and zone_nwif_defrouter are
   2169 	 * arrays, so no NULL checks are necessary.
   2170 	 */
   2171 	addrspec = strlen(tabptr->zone_nwif_address);
   2172 	physspec = strlen(tabptr->zone_nwif_physical);
   2173 	defrouterspec = strlen(tabptr->zone_nwif_defrouter);
   2174 	if (addrspec == 0 && physspec == 0 && defrouterspec == 0)
   2175 		return (Z_INSUFFICIENT_SPEC);
   2176 
   2177 	if ((err = operation_prep(handle)) != Z_OK)
   2178 		return (err);
   2179 
   2180 	/*
   2181 	 * Iterate over the configuration's elements and look for net elements
   2182 	 * that match the query.
   2183 	 */
   2184 	firstmatch = NULL;
   2185 	cur = handle->zone_dh_cur;
   2186 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   2187 		/* Skip non-net elements */
   2188 		if (xmlStrcmp(cur->name, DTD_ELEM_NET))
   2189 			continue;
   2190 
   2191 		/*
   2192 		 * If any relevant fields don't match the query, then skip
   2193 		 * the current net element.
   2194 		 */
   2195 		if (physspec != 0 && (fetchprop(cur, DTD_ATTR_PHYSICAL,
   2196 		    physical, sizeof (physical)) != Z_OK ||
   2197 		    strcmp(tabptr->zone_nwif_physical, physical) != 0))
   2198 			continue;
   2199 		if (addrspec != 0 && (fetchprop(cur, DTD_ATTR_ADDRESS, address,
   2200 		    sizeof (address)) != Z_OK ||
   2201 		    !zonecfg_same_net_address(tabptr->zone_nwif_address,
   2202 		    address)))
   2203 			continue;
   2204 		if (defrouterspec != 0 && (fetchprop(cur, DTD_ATTR_DEFROUTER,
   2205 		    address, sizeof (address)) != Z_OK ||
   2206 		    !zonecfg_same_net_address(tabptr->zone_nwif_defrouter,
   2207 		    address)))
   2208 			continue;
   2209 
   2210 		/*
   2211 		 * The current net element matches the query.  Select it if
   2212 		 * it's the first match; otherwise, abort the search.
   2213 		 */
   2214 		if (firstmatch == NULL)
   2215 			firstmatch = cur;
   2216 		else
   2217 			return (Z_INSUFFICIENT_SPEC);
   2218 	}
   2219 	if (firstmatch == NULL)
   2220 		return (Z_NO_RESOURCE_ID);
   2221 
   2222 	cur = firstmatch;
   2223 
   2224 	if ((err = fetchprop(cur, DTD_ATTR_PHYSICAL, tabptr->zone_nwif_physical,
   2225 	    sizeof (tabptr->zone_nwif_physical))) != Z_OK)
   2226 		return (err);
   2227 
   2228 	if ((err = fetchprop(cur, DTD_ATTR_ADDRESS, tabptr->zone_nwif_address,
   2229 	    sizeof (tabptr->zone_nwif_address))) != Z_OK)
   2230 		return (err);
   2231 
   2232 	if ((err = fetchprop(cur, DTD_ATTR_DEFROUTER,
   2233 	    tabptr->zone_nwif_defrouter,
   2234 	    sizeof (tabptr->zone_nwif_defrouter))) != Z_OK)
   2235 		return (err);
   2236 
   2237 	return (Z_OK);
   2238 }
   2239 
   2240 static int
   2241 zonecfg_add_nwif_core(zone_dochandle_t handle, struct zone_nwiftab *tabptr)
   2242 {
   2243 	xmlNodePtr newnode, cur = handle->zone_dh_cur;
   2244 	int err;
   2245 
   2246 	newnode = xmlNewTextChild(cur, NULL, DTD_ELEM_NET, NULL);
   2247 	if ((err = newprop(newnode, DTD_ATTR_ADDRESS,
   2248 	    tabptr->zone_nwif_address)) != Z_OK)
   2249 		return (err);
   2250 	if ((err = newprop(newnode, DTD_ATTR_PHYSICAL,
   2251 	    tabptr->zone_nwif_physical)) != Z_OK)
   2252 		return (err);
   2253 	/*
   2254 	 * Do not add this property when it is not set, for backwards
   2255 	 * compatibility and because it is optional.
   2256 	 */
   2257 	if ((strlen(tabptr->zone_nwif_defrouter) > 0) &&
   2258 	    ((err = newprop(newnode, DTD_ATTR_DEFROUTER,
   2259 	    tabptr->zone_nwif_defrouter)) != Z_OK))
   2260 		return (err);
   2261 	return (Z_OK);
   2262 }
   2263 
   2264 int
   2265 zonecfg_add_nwif(zone_dochandle_t handle, struct zone_nwiftab *tabptr)
   2266 {
   2267 	int err;
   2268 
   2269 	if (tabptr == NULL)
   2270 		return (Z_INVAL);
   2271 
   2272 	if ((err = operation_prep(handle)) != Z_OK)
   2273 		return (err);
   2274 
   2275 	if ((err = zonecfg_add_nwif_core(handle, tabptr)) != Z_OK)
   2276 		return (err);
   2277 
   2278 	return (Z_OK);
   2279 }
   2280 
   2281 static int
   2282 zonecfg_delete_nwif_core(zone_dochandle_t handle, struct zone_nwiftab *tabptr)
   2283 {
   2284 	xmlNodePtr cur = handle->zone_dh_cur;
   2285 	boolean_t addr_match, phys_match;
   2286 
   2287 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   2288 		if (xmlStrcmp(cur->name, DTD_ELEM_NET))
   2289 			continue;
   2290 
   2291 		addr_match = match_prop(cur, DTD_ATTR_ADDRESS,
   2292 		    tabptr->zone_nwif_address);
   2293 		phys_match = match_prop(cur, DTD_ATTR_PHYSICAL,
   2294 		    tabptr->zone_nwif_physical);
   2295 
   2296 		if (addr_match && phys_match) {
   2297 			xmlUnlinkNode(cur);
   2298 			xmlFreeNode(cur);
   2299 			return (Z_OK);
   2300 		}
   2301 	}
   2302 	return (Z_NO_RESOURCE_ID);
   2303 }
   2304 
   2305 int
   2306 zonecfg_delete_nwif(zone_dochandle_t handle, struct zone_nwiftab *tabptr)
   2307 {
   2308 	int err;
   2309 
   2310 	if (tabptr == NULL)
   2311 		return (Z_INVAL);
   2312 
   2313 	if ((err = operation_prep(handle)) != Z_OK)
   2314 		return (err);
   2315 
   2316 	if ((err = zonecfg_delete_nwif_core(handle, tabptr)) != Z_OK)
   2317 		return (err);
   2318 
   2319 	return (Z_OK);
   2320 }
   2321 
   2322 int
   2323 zonecfg_modify_nwif(
   2324 	zone_dochandle_t handle,
   2325 	struct zone_nwiftab *oldtabptr,
   2326 	struct zone_nwiftab *newtabptr)
   2327 {
   2328 	int err;
   2329 
   2330 	if (oldtabptr == NULL || newtabptr == NULL)
   2331 		return (Z_INVAL);
   2332 
   2333 	if ((err = operation_prep(handle)) != Z_OK)
   2334 		return (err);
   2335 
   2336 	if ((err = zonecfg_delete_nwif_core(handle, oldtabptr)) != Z_OK)
   2337 		return (err);
   2338 
   2339 	if ((err = zonecfg_add_nwif_core(handle, newtabptr)) != Z_OK)
   2340 		return (err);
   2341 
   2342 	return (Z_OK);
   2343 }
   2344 
   2345 /*
   2346  * Gets the zone hostid string stored in the specified zone configuration
   2347  * document.  This function returns Z_OK on success.  Z_BAD_PROPERTY is returned
   2348  * if the config file doesn't specify a hostid or if the hostid is blank.
   2349  *
   2350  * Note that buflen should be at least HW_HOSTID_LEN.
   2351  */
   2352 int
   2353 zonecfg_get_hostid(zone_dochandle_t handle, char *bufp, size_t buflen)
   2354 {
   2355 	int err;
   2356 
   2357 	if ((err = getrootattr(handle, DTD_ATTR_HOSTID, bufp, buflen)) != Z_OK)
   2358 		return (err);
   2359 	if (bufp[0] == '\0')
   2360 		return (Z_BAD_PROPERTY);
   2361 	return (Z_OK);
   2362 }
   2363 
   2364 /*
   2365  * Sets the hostid string in the specified zone config document to the given
   2366  * string value.  If 'hostidp' is NULL, then the config document's hostid
   2367  * attribute is cleared.  Non-NULL hostids are validated.  This function returns
   2368  * Z_OK on success.  Any other return value indicates failure.
   2369  */
   2370 int
   2371 zonecfg_set_hostid(zone_dochandle_t handle, const char *hostidp)
   2372 {
   2373 	int err;
   2374 
   2375 	/*
   2376 	 * A NULL hostid string is interpreted as a request to clear the
   2377 	 * hostid.
   2378 	 */
   2379 	if (hostidp == NULL || (err = zonecfg_valid_hostid(hostidp)) == Z_OK)
   2380 		return (setrootattr(handle, DTD_ATTR_HOSTID, hostidp));
   2381 	return (err);
   2382 }
   2383 
   2384 /*
   2385  * Determines if the specified string is a valid hostid string.  This function
   2386  * returns Z_OK if the string is a valid hostid string.  It returns Z_INVAL if
   2387  * 'hostidp' is NULL, Z_TOO_BIG if 'hostidp' refers to a string buffer
   2388  * containing a hex string with more than 8 digits, and Z_HOSTID_FUBAR if the
   2389  * string has an invalid format.
   2390  */
   2391 int
   2392 zonecfg_valid_hostid(const char *hostidp)
   2393 {
   2394 	char *currentp;
   2395 	u_longlong_t hostidval;
   2396 	size_t len;
   2397 
   2398 	if (hostidp == NULL)
   2399 		return (Z_INVAL);
   2400 
   2401 	/* Empty strings and strings with whitespace are invalid. */
   2402 	if (*hostidp == '\0')
   2403 		return (Z_HOSTID_FUBAR);
   2404 	for (currentp = (char *)hostidp; *currentp != '\0'; ++currentp) {
   2405 		if (isspace(*currentp))
   2406 			return (Z_HOSTID_FUBAR);
   2407 	}
   2408 	len = (size_t)(currentp - hostidp);
   2409 
   2410 	/*
   2411 	 * The caller might pass a hostid that is larger than the maximum
   2412 	 * unsigned 32-bit integral value.  Check for this!  Also, make sure
   2413 	 * that the whole string is converted (this helps us find illegal
   2414 	 * characters) and that the whole string fits within a buffer of size
   2415 	 * HW_HOSTID_LEN.
   2416 	 */
   2417 	currentp = (char *)hostidp;
   2418 	if (strncmp(hostidp, "0x", 2) == 0 || strncmp(hostidp, "0X", 2) == 0)
   2419 		currentp += 2;
   2420 	hostidval = strtoull(currentp, &currentp, 16);
   2421 	if ((size_t)(currentp - hostidp) >= HW_HOSTID_LEN)
   2422 		return (Z_TOO_BIG);
   2423 	if (hostidval > UINT_MAX || hostidval == HW_INVALID_HOSTID ||
   2424 	    currentp != hostidp + len)
   2425 		return (Z_HOSTID_FUBAR);
   2426 	return (Z_OK);
   2427 }
   2428 
   2429 int
   2430 zonecfg_lookup_dev(zone_dochandle_t handle, struct zone_devtab *tabptr)
   2431 {
   2432 	xmlNodePtr cur, firstmatch;
   2433 	int err;
   2434 	char match[MAXPATHLEN];
   2435 
   2436 	if (tabptr == NULL)
   2437 		return (Z_INVAL);
   2438 
   2439 	if ((err = operation_prep(handle)) != Z_OK)
   2440 		return (err);
   2441 
   2442 	cur = handle->zone_dh_cur;
   2443 	firstmatch = NULL;
   2444 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   2445 		if (xmlStrcmp(cur->name, DTD_ELEM_DEVICE))
   2446 			continue;
   2447 		if (strlen(tabptr->zone_dev_match) == 0)
   2448 			continue;
   2449 
   2450 		if ((fetchprop(cur, DTD_ATTR_MATCH, match,
   2451 		    sizeof (match)) == Z_OK)) {
   2452 			if (strcmp(tabptr->zone_dev_match,
   2453 			    match) == 0) {
   2454 				if (firstmatch == NULL)
   2455 					firstmatch = cur;
   2456 				else if (firstmatch != cur)
   2457 					return (Z_INSUFFICIENT_SPEC);
   2458 			} else {
   2459 				/*
   2460 				 * If another property matched but this
   2461 				 * one doesn't then reset firstmatch.
   2462 				 */
   2463 				if (firstmatch == cur)
   2464 					firstmatch = NULL;
   2465 			}
   2466 		}
   2467 	}
   2468 	if (firstmatch == NULL)
   2469 		return (Z_NO_RESOURCE_ID);
   2470 
   2471 	cur = firstmatch;
   2472 
   2473 	if ((err = fetchprop(cur, DTD_ATTR_MATCH, tabptr->zone_dev_match,
   2474 	    sizeof (tabptr->zone_dev_match))) != Z_OK)
   2475 		return (err);
   2476 
   2477 	return (Z_OK);
   2478 }
   2479 
   2480 static int
   2481 zonecfg_add_dev_core(zone_dochandle_t handle, struct zone_devtab *tabptr)
   2482 {
   2483 	xmlNodePtr newnode, cur = handle->zone_dh_cur;
   2484 	int err;
   2485 
   2486 	newnode = xmlNewTextChild(cur, NULL, DTD_ELEM_DEVICE, NULL);
   2487 
   2488 	if ((err = newprop(newnode, DTD_ATTR_MATCH,
   2489 	    tabptr->zone_dev_match)) != Z_OK)
   2490 		return (err);
   2491 
   2492 	return (Z_OK);
   2493 }
   2494 
   2495 int
   2496 zonecfg_add_dev(zone_dochandle_t handle, struct zone_devtab *tabptr)
   2497 {
   2498 	int err;
   2499 
   2500 	if (tabptr == NULL)
   2501 		return (Z_INVAL);
   2502 
   2503 	if ((err = operation_prep(handle)) != Z_OK)
   2504 		return (err);
   2505 
   2506 	if ((err = zonecfg_add_dev_core(handle, tabptr)) != Z_OK)
   2507 		return (err);
   2508 
   2509 	return (Z_OK);
   2510 }
   2511 
   2512 static int
   2513 zonecfg_delete_dev_core(zone_dochandle_t handle, struct zone_devtab *tabptr)
   2514 {
   2515 	xmlNodePtr cur = handle->zone_dh_cur;
   2516 	int match_match;
   2517 
   2518 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   2519 		if (xmlStrcmp(cur->name, DTD_ELEM_DEVICE))
   2520 			continue;
   2521 
   2522 		match_match = match_prop(cur, DTD_ATTR_MATCH,
   2523 		    tabptr->zone_dev_match);
   2524 
   2525 		if (match_match) {
   2526 			xmlUnlinkNode(cur);
   2527 			xmlFreeNode(cur);
   2528 			return (Z_OK);
   2529 		}
   2530 	}
   2531 	return (Z_NO_RESOURCE_ID);
   2532 }
   2533 
   2534 int
   2535 zonecfg_delete_dev(zone_dochandle_t handle, struct zone_devtab *tabptr)
   2536 {
   2537 	int err;
   2538 
   2539 	if (tabptr == NULL)
   2540 		return (Z_INVAL);
   2541 
   2542 	if ((err = operation_prep(handle)) != Z_OK)
   2543 		return (err);
   2544 
   2545 	if ((err = zonecfg_delete_dev_core(handle, tabptr)) != Z_OK)
   2546 		return (err);
   2547 
   2548 	return (Z_OK);
   2549 }
   2550 
   2551 int
   2552 zonecfg_modify_dev(
   2553 	zone_dochandle_t handle,
   2554 	struct zone_devtab *oldtabptr,
   2555 	struct zone_devtab *newtabptr)
   2556 {
   2557 	int err;
   2558 
   2559 	if (oldtabptr == NULL || newtabptr == NULL)
   2560 		return (Z_INVAL);
   2561 
   2562 	if ((err = operation_prep(handle)) != Z_OK)
   2563 		return (err);
   2564 
   2565 	if ((err = zonecfg_delete_dev_core(handle, oldtabptr)) != Z_OK)
   2566 		return (err);
   2567 
   2568 	if ((err = zonecfg_add_dev_core(handle, newtabptr)) != Z_OK)
   2569 		return (err);
   2570 
   2571 	return (Z_OK);
   2572 }
   2573 
   2574 /* Lock to serialize all devwalks */
   2575 static pthread_mutex_t zonecfg_devwalk_lock = PTHREAD_MUTEX_INITIALIZER;
   2576 /*
   2577  * Global variables used to pass data from zonecfg_dev_manifest to the nftw
   2578  * call-back (zonecfg_devwalk_cb).  g_devwalk_data is really the void*
   2579  * parameter and g_devwalk_cb is really the *cb parameter from
   2580  * zonecfg_dev_manifest.
   2581  */
   2582 typedef struct __g_devwalk_data *g_devwalk_data_t;
   2583 static g_devwalk_data_t g_devwalk_data;
   2584 static int (*g_devwalk_cb)(const char *, uid_t, gid_t, mode_t, const char *,
   2585     void *);
   2586 static size_t g_devwalk_skip_prefix;
   2587 
   2588 /*
   2589  * zonecfg_dev_manifest call-back function used during detach to generate the
   2590  * dev info in the manifest.
   2591  */
   2592 static int
   2593 get_detach_dev_entry(const char *name, uid_t uid, gid_t gid, mode_t mode,
   2594     const char *acl, void *hdl)
   2595 {
   2596 	zone_dochandle_t handle = (zone_dochandle_t)hdl;
   2597 	xmlNodePtr newnode;
   2598 	xmlNodePtr cur;
   2599 	int err;
   2600 	char buf[128];
   2601 
   2602 	if ((err = operation_prep(handle)) != Z_OK)
   2603 		return (err);
   2604 
   2605 	cur = handle->zone_dh_cur;
   2606 	newnode = xmlNewTextChild(cur, NULL, DTD_ELEM_DEV_PERM, NULL);
   2607 	if ((err = newprop(newnode, DTD_ATTR_NAME, (char *)name)) != Z_OK)
   2608 		return (err);
   2609 	(void) snprintf(buf, sizeof (buf), "%lu", uid);
   2610 	if ((err = newprop(newnode, DTD_ATTR_UID, buf)) != Z_OK)
   2611 		return (err);
   2612 	(void) snprintf(buf, sizeof (buf), "%lu", gid);
   2613 	if ((err = newprop(newnode, DTD_ATTR_GID, buf)) != Z_OK)
   2614 		return (err);
   2615 	(void) snprintf(buf, sizeof (buf), "%o", mode);
   2616 	if ((err = newprop(newnode, DTD_ATTR_MODE, buf)) != Z_OK)
   2617 		return (err);
   2618 	if ((err = newprop(newnode, DTD_ATTR_ACL, (char *)acl)) != Z_OK)
   2619 		return (err);
   2620 	return (Z_OK);
   2621 }
   2622 
   2623 /*
   2624  * This is the nftw call-back function used by zonecfg_dev_manifest.  It is
   2625  * responsible for calling the actual call-back.
   2626  */
   2627 /* ARGSUSED2 */
   2628 static int
   2629 zonecfg_devwalk_cb(const char *path, const struct stat *st, int f,
   2630     struct FTW *ftw)
   2631 {
   2632 	acl_t *acl;
   2633 	char *acl_txt = NULL;
   2634 
   2635 	/* skip all but character and block devices */
   2636 	if (!S_ISBLK(st->st_mode) && !S_ISCHR(st->st_mode))
   2637 		return (0);
   2638 
   2639 	if ((acl_get(path, ACL_NO_TRIVIAL, &acl) == 0) &&
   2640 	    acl != NULL) {
   2641 		acl_txt = acl_totext(acl, ACL_NORESOLVE);
   2642 		acl_free(acl);
   2643 	}
   2644 
   2645 	if (strlen(path) <= g_devwalk_skip_prefix)
   2646 		return (0);
   2647 
   2648 	g_devwalk_cb(path + g_devwalk_skip_prefix, st->st_uid, st->st_gid,
   2649 	    st->st_mode & S_IAMB, acl_txt != NULL ? acl_txt : "",
   2650 	    g_devwalk_data);
   2651 	free(acl_txt);
   2652 	return (0);
   2653 }
   2654 
   2655 /*
   2656  * Walk the dev tree for the zone specified by hdl and call the
   2657  * get_detach_dev_entry call-back function for each entry in the tree.  The
   2658  * call-back will be passed the name, uid, gid, mode, acl string and the
   2659  * handle input parameter for each dev entry.
   2660  *
   2661  * Data is passed to get_detach_dev_entry through the global variables
   2662  * g_devwalk_data, *g_devwalk_cb, and g_devwalk_skip_prefix.  The
   2663  * zonecfg_devwalk_cb function will actually call get_detach_dev_entry.
   2664  */
   2665 int
   2666 zonecfg_dev_manifest(zone_dochandle_t hdl)
   2667 {
   2668 	char path[MAXPATHLEN];
   2669 	int ret;
   2670 
   2671 	if ((ret = zonecfg_get_zonepath(hdl, path, sizeof (path))) != Z_OK)
   2672 		return (ret);
   2673 
   2674 	if (strlcat(path, "/dev", sizeof (path)) >= sizeof (path))
   2675 		return (Z_TOO_BIG);
   2676 
   2677 	/*
   2678 	 * We have to serialize all devwalks in the same process
   2679 	 * (which should be fine), since nftw() is so badly designed.
   2680 	 */
   2681 	(void) pthread_mutex_lock(&zonecfg_devwalk_lock);
   2682 
   2683 	g_devwalk_skip_prefix = strlen(path) + 1;
   2684 	g_devwalk_data = (g_devwalk_data_t)hdl;
   2685 	g_devwalk_cb = get_detach_dev_entry;
   2686 	(void) nftw(path, zonecfg_devwalk_cb, 0, FTW_PHYS);
   2687 
   2688 	(void) pthread_mutex_unlock(&zonecfg_devwalk_lock);
   2689 	return (Z_OK);
   2690 }
   2691 
   2692 /*
   2693  * Update the owner, group, mode and acl on the specified dev (inpath) for
   2694  * the zone (hdl).  This function can be used to fix up the dev tree after
   2695  * attaching a migrated zone.
   2696  */
   2697 int
   2698 zonecfg_devperms_apply(zone_dochandle_t hdl, const char *inpath, uid_t owner,
   2699     gid_t group, mode_t mode, const char *acltxt)
   2700 {
   2701 	int ret;
   2702 	char path[MAXPATHLEN];
   2703 	struct stat st;
   2704 	acl_t *aclp;
   2705 
   2706 	if ((ret = zonecfg_get_zonepath(hdl, path, sizeof (path))) != Z_OK)
   2707 		return (ret);
   2708 
   2709 	if (strlcat(path, "/dev/", sizeof (path)) >= sizeof (path))
   2710 		return (Z_TOO_BIG);
   2711 	if (strlcat(path, inpath, sizeof (path)) >= sizeof (path))
   2712 		return (Z_TOO_BIG);
   2713 
   2714 	if (stat(path, &st) == -1)
   2715 		return (Z_INVAL);
   2716 
   2717 	/* make sure we're only touching device nodes */
   2718 	if (!S_ISCHR(st.st_mode) && !S_ISBLK(st.st_mode))
   2719 		return (Z_INVAL);
   2720 
   2721 	if (chown(path, owner, group) == -1)
   2722 		return (Z_SYSTEM);
   2723 
   2724 	if (chmod(path, mode) == -1)
   2725 		return (Z_SYSTEM);
   2726 
   2727 	if ((acltxt == NULL) || (strcmp(acltxt, "") == 0))
   2728 		return (Z_OK);
   2729 
   2730 	if (acl_fromtext(acltxt, &aclp) != 0) {
   2731 		errno = EINVAL;
   2732 		return (Z_SYSTEM);
   2733 	}
   2734 
   2735 	errno = 0;
   2736 	if (acl_set(path, aclp) == -1) {
   2737 		free(aclp);
   2738 		return (Z_SYSTEM);
   2739 	}
   2740 
   2741 	free(aclp);
   2742 	return (Z_OK);
   2743 }
   2744 
   2745 /*
   2746  * This function finds everything mounted under a zone's rootpath.
   2747  * This returns the number of mounts under rootpath, or -1 on error.
   2748  * callback is called once per mount found with the first argument
   2749  * pointing to a mnttab structure containing the mount's information.
   2750  *
   2751  * If the callback function returns non-zero zonecfg_find_mounts
   2752  * aborts with an error.
   2753  */
   2754 int
   2755 zonecfg_find_mounts(char *rootpath, int (*callback)(const struct mnttab *,
   2756     void *), void *priv) {
   2757 	FILE *mnttab;
   2758 	struct mnttab m;
   2759 	size_t l;
   2760 	int zfsl;
   2761 	int rv = 0;
   2762 	char zfs_path[MAXPATHLEN];
   2763 
   2764 	assert(rootpath != NULL);
   2765 
   2766 	if ((zfsl = snprintf(zfs_path, sizeof (zfs_path), "%s/.zfs/", rootpath))
   2767 	    >= sizeof (zfs_path))
   2768 		return (-1);
   2769 
   2770 	l = strlen(rootpath);
   2771 
   2772 	mnttab = fopen("/etc/mnttab", "r");
   2773 
   2774 	if (mnttab == NULL)
   2775 		return (-1);
   2776 
   2777 	if (ioctl(fileno(mnttab), MNTIOC_SHOWHIDDEN, NULL) < 0)  {
   2778 		rv = -1;
   2779 		goto out;
   2780 	}
   2781 
   2782 	while (!getmntent(mnttab, &m)) {
   2783 		if ((strncmp(rootpath, m.mnt_mountp, l) == 0) &&
   2784 		    (m.mnt_mountp[l] == '/') &&
   2785 		    (strncmp(zfs_path, m.mnt_mountp, zfsl) != 0)) {
   2786 			rv++;
   2787 			if (callback == NULL)
   2788 				continue;
   2789 			if (callback(&m, priv)) {
   2790 				rv = -1;
   2791 				goto out;
   2792 
   2793 			}
   2794 		}
   2795 	}
   2796 
   2797 out:
   2798 	(void) fclose(mnttab);
   2799 	return (rv);
   2800 }
   2801 
   2802 int
   2803 zonecfg_lookup_attr(zone_dochandle_t handle, struct zone_attrtab *tabptr)
   2804 {
   2805 	xmlNodePtr cur, firstmatch;
   2806 	int err;
   2807 	char name[MAXNAMELEN], type[MAXNAMELEN], value[MAXNAMELEN];
   2808 
   2809 	if (tabptr == NULL)
   2810 		return (Z_INVAL);
   2811 
   2812 	if ((err = operation_prep(handle)) != Z_OK)
   2813 		return (err);
   2814 
   2815 	cur = handle->zone_dh_cur;
   2816 	firstmatch = NULL;
   2817 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   2818 		if (xmlStrcmp(cur->name, DTD_ELEM_ATTR))
   2819 			continue;
   2820 		if (strlen(tabptr->zone_attr_name) > 0) {
   2821 			if ((fetchprop(cur, DTD_ATTR_NAME, name,
   2822 			    sizeof (name)) == Z_OK) &&
   2823 			    (strcmp(tabptr->zone_attr_name, name) == 0)) {
   2824 				if (firstmatch == NULL)
   2825 					firstmatch = cur;
   2826 				else
   2827 					return (Z_INSUFFICIENT_SPEC);
   2828 			}
   2829 		}
   2830 		if (strlen(tabptr->zone_attr_type) > 0) {
   2831 			if ((fetchprop(cur, DTD_ATTR_TYPE, type,
   2832 			    sizeof (type)) == Z_OK)) {
   2833 				if (strcmp(tabptr->zone_attr_type, type) == 0) {
   2834 					if (firstmatch == NULL)
   2835 						firstmatch = cur;
   2836 					else if (firstmatch != cur)
   2837 						return (Z_INSUFFICIENT_SPEC);
   2838 				} else {
   2839 					/*
   2840 					 * If another property matched but this
   2841 					 * one doesn't then reset firstmatch.
   2842 					 */
   2843 					if (firstmatch == cur)
   2844 						firstmatch = NULL;
   2845 				}
   2846 			}
   2847 		}
   2848 		if (strlen(tabptr->zone_attr_value) > 0) {
   2849 			if ((fetchprop(cur, DTD_ATTR_VALUE, value,
   2850 			    sizeof (value)) == Z_OK)) {
   2851 				if (strcmp(tabptr->zone_attr_value, value) ==
   2852 				    0) {
   2853 					if (firstmatch == NULL)
   2854 						firstmatch = cur;
   2855 					else if (firstmatch != cur)
   2856 						return (Z_INSUFFICIENT_SPEC);
   2857 				} else {
   2858 					/*
   2859 					 * If another property matched but this
   2860 					 * one doesn't then reset firstmatch.
   2861 					 */
   2862 					if (firstmatch == cur)
   2863 						firstmatch = NULL;
   2864 				}
   2865 			}
   2866 		}
   2867 	}
   2868 	if (firstmatch == NULL)
   2869 		return (Z_NO_RESOURCE_ID);
   2870 
   2871 	cur = firstmatch;
   2872 
   2873 	if ((err = fetchprop(cur, DTD_ATTR_NAME, tabptr->zone_attr_name,
   2874 	    sizeof (tabptr->zone_attr_name))) != Z_OK)
   2875 		return (err);
   2876 
   2877 	if ((err = fetchprop(cur, DTD_ATTR_TYPE, tabptr->zone_attr_type,
   2878 	    sizeof (tabptr->zone_attr_type))) != Z_OK)
   2879 		return (err);
   2880 
   2881 	if ((err = fetchprop(cur, DTD_ATTR_VALUE, tabptr->zone_attr_value,
   2882 	    sizeof (tabptr->zone_attr_value))) != Z_OK)
   2883 		return (err);
   2884 
   2885 	return (Z_OK);
   2886 }
   2887 
   2888 static int
   2889 zonecfg_add_attr_core(zone_dochandle_t handle, struct zone_attrtab *tabptr)
   2890 {
   2891 	xmlNodePtr newnode, cur = handle->zone_dh_cur;
   2892 	int err;
   2893 
   2894 	newnode = xmlNewTextChild(cur, NULL, DTD_ELEM_ATTR, NULL);
   2895 	err = newprop(newnode, DTD_ATTR_NAME, tabptr->zone_attr_name);
   2896 	if (err != Z_OK)
   2897 		return (err);
   2898 	err = newprop(newnode, DTD_ATTR_TYPE, tabptr->zone_attr_type);
   2899 	if (err != Z_OK)
   2900 		return (err);
   2901 	err = newprop(newnode, DTD_ATTR_VALUE, tabptr->zone_attr_value);
   2902 	if (err != Z_OK)
   2903 		return (err);
   2904 	return (Z_OK);
   2905 }
   2906 
   2907 int
   2908 zonecfg_add_attr(zone_dochandle_t handle, struct zone_attrtab *tabptr)
   2909 {
   2910 	int err;
   2911 
   2912 	if (tabptr == NULL)
   2913 		return (Z_INVAL);
   2914 
   2915 	if ((err = operation_prep(handle)) != Z_OK)
   2916 		return (err);
   2917 
   2918 	if ((err = zonecfg_add_attr_core(handle, tabptr)) != Z_OK)
   2919 		return (err);
   2920 
   2921 	return (Z_OK);
   2922 }
   2923 
   2924 static int
   2925 zonecfg_delete_attr_core(zone_dochandle_t handle, struct zone_attrtab *tabptr)
   2926 {
   2927 	xmlNodePtr cur = handle->zone_dh_cur;
   2928 	int name_match, type_match, value_match;
   2929 
   2930 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   2931 		if (xmlStrcmp(cur->name, DTD_ELEM_ATTR))
   2932 			continue;
   2933 
   2934 		name_match = match_prop(cur, DTD_ATTR_NAME,
   2935 		    tabptr->zone_attr_name);
   2936 		type_match = match_prop(cur, DTD_ATTR_TYPE,
   2937 		    tabptr->zone_attr_type);
   2938 		value_match = match_prop(cur, DTD_ATTR_VALUE,
   2939 		    tabptr->zone_attr_value);
   2940 
   2941 		if (name_match && type_match && value_match) {
   2942 			xmlUnlinkNode(cur);
   2943 			xmlFreeNode(cur);
   2944 			return (Z_OK);
   2945 		}
   2946 	}
   2947 	return (Z_NO_RESOURCE_ID);
   2948 }
   2949 
   2950 int
   2951 zonecfg_delete_attr(zone_dochandle_t handle, struct zone_attrtab *tabptr)
   2952 {
   2953 	int err;
   2954 
   2955 	if (tabptr == NULL)
   2956 		return (Z_INVAL);
   2957 
   2958 	if ((err = operation_prep(handle)) != Z_OK)
   2959 		return (err);
   2960 
   2961 	if ((err = zonecfg_delete_attr_core(handle, tabptr)) != Z_OK)
   2962 		return (err);
   2963 
   2964 	return (Z_OK);
   2965 }
   2966 
   2967 int
   2968 zonecfg_modify_attr(
   2969 	zone_dochandle_t handle,
   2970 	struct zone_attrtab *oldtabptr,
   2971 	struct zone_attrtab *newtabptr)
   2972 {
   2973 	int err;
   2974 
   2975 	if (oldtabptr == NULL || newtabptr == NULL)
   2976 		return (Z_INVAL);
   2977 
   2978 	if ((err = operation_prep(handle)) != Z_OK)
   2979 		return (err);
   2980 
   2981 	if ((err = zonecfg_delete_attr_core(handle, oldtabptr)) != Z_OK)
   2982 		return (err);
   2983 
   2984 	if ((err = zonecfg_add_attr_core(handle, newtabptr)) != Z_OK)
   2985 		return (err);
   2986 
   2987 	return (Z_OK);
   2988 }
   2989 
   2990 int
   2991 zonecfg_get_attr_boolean(const struct zone_attrtab *attr, boolean_t *value)
   2992 {
   2993 	if (attr == NULL)
   2994 		return (Z_INVAL);
   2995 
   2996 	if (strcmp(attr->zone_attr_type, DTD_ENTITY_BOOLEAN) != 0)
   2997 		return (Z_INVAL);
   2998 
   2999 	if (strcmp(attr->zone_attr_value, DTD_ENTITY_TRUE) == 0) {
   3000 		*value = B_TRUE;
   3001 		return (Z_OK);
   3002 	}
   3003 	if (strcmp(attr->zone_attr_value, DTD_ENTITY_FALSE) == 0) {
   3004 		*value = B_FALSE;
   3005 		return (Z_OK);
   3006 	}
   3007 	return (Z_INVAL);
   3008 }
   3009 
   3010 int
   3011 zonecfg_get_attr_int(const struct zone_attrtab *attr, int64_t *value)
   3012 {
   3013 	long long result;
   3014 	char *endptr;
   3015 
   3016 	if (attr == NULL)
   3017 		return (Z_INVAL);
   3018 
   3019 	if (strcmp(attr->zone_attr_type, DTD_ENTITY_INT) != 0)
   3020 		return (Z_INVAL);
   3021 
   3022 	errno = 0;
   3023 	result = strtoll(attr->zone_attr_value, &endptr, 10);
   3024 	if (errno != 0 || *endptr != '\0')
   3025 		return (Z_INVAL);
   3026 	*value = result;
   3027 	return (Z_OK);
   3028 }
   3029 
   3030 int
   3031 zonecfg_get_attr_string(const struct zone_attrtab *attr, char *value,
   3032     size_t val_sz)
   3033 {
   3034 	if (attr == NULL)
   3035 		return (Z_INVAL);
   3036 
   3037 	if (strcmp(attr->zone_attr_type, DTD_ENTITY_STRING) != 0)
   3038 		return (Z_INVAL);
   3039 
   3040 	if (strlcpy(value, attr->zone_attr_value, val_sz) >= val_sz)
   3041 		return (Z_TOO_BIG);
   3042 	return (Z_OK);
   3043 }
   3044 
   3045 int
   3046 zonecfg_get_attr_uint(const struct zone_attrtab *attr, uint64_t *value)
   3047 {
   3048 	unsigned long long result;
   3049 	long long neg_result;
   3050 	char *endptr;
   3051 
   3052 	if (attr == NULL)
   3053 		return (Z_INVAL);
   3054 
   3055 	if (strcmp(attr->zone_attr_type, DTD_ENTITY_UINT) != 0)
   3056 		return (Z_INVAL);
   3057 
   3058 	errno = 0;
   3059 	result = strtoull(attr->zone_attr_value, &endptr, 10);
   3060 	if (errno != 0 || *endptr != '\0')
   3061 		return (Z_INVAL);
   3062 	errno = 0;
   3063 	neg_result = strtoll(attr->zone_attr_value, &endptr, 10);
   3064 	/*
   3065 	 * Incredibly, strtoull("<negative number>", ...) will not fail but
   3066 	 * return whatever (negative) number cast as a u_longlong_t, so we
   3067 	 * need to look for this here.
   3068 	 */
   3069 	if (errno == 0 && neg_result < 0)
   3070 		return (Z_INVAL);
   3071 	*value = result;
   3072 	return (Z_OK);
   3073 }
   3074 
   3075 int
   3076 zonecfg_lookup_rctl(zone_dochandle_t handle, struct zone_rctltab *tabptr)
   3077 {
   3078 	xmlNodePtr cur, val;
   3079 	char savedname[MAXNAMELEN];
   3080 	struct zone_rctlvaltab *valptr;
   3081 	int err;
   3082 
   3083 	if (strlen(tabptr->zone_rctl_name) == 0)
   3084 		return (Z_INVAL);
   3085 
   3086 	if ((err = operation_prep(handle)) != Z_OK)
   3087 		return (err);
   3088 
   3089 	cur = handle->zone_dh_cur;
   3090 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   3091 		if (xmlStrcmp(cur->name, DTD_ELEM_RCTL))
   3092 			continue;
   3093 		if ((fetchprop(cur, DTD_ATTR_NAME, savedname,
   3094 		    sizeof (savedname)) == Z_OK) &&
   3095 		    (strcmp(savedname, tabptr->zone_rctl_name) == 0)) {
   3096 			tabptr->zone_rctl_valptr = NULL;
   3097 			for (val = cur->xmlChildrenNode; val != NULL;
   3098 			    val = val->next) {
   3099 				valptr = (struct zone_rctlvaltab *)malloc(
   3100 				    sizeof (struct zone_rctlvaltab));
   3101 				if (valptr == NULL)
   3102 					return (Z_NOMEM);
   3103 				if ((fetchprop(val, DTD_ATTR_PRIV,
   3104 				    valptr->zone_rctlval_priv,
   3105 				    sizeof (valptr->zone_rctlval_priv)) !=
   3106 				    Z_OK))
   3107 					break;
   3108 				if ((fetchprop(val, DTD_ATTR_LIMIT,
   3109 				    valptr->zone_rctlval_limit,
   3110 				    sizeof (valptr->zone_rctlval_limit)) !=
   3111 				    Z_OK))
   3112 					break;
   3113 				if ((fetchprop(val, DTD_ATTR_ACTION,
   3114 				    valptr->zone_rctlval_action,
   3115 				    sizeof (valptr->zone_rctlval_action)) !=
   3116 				    Z_OK))
   3117 					break;
   3118 				if (zonecfg_add_rctl_value(tabptr, valptr) !=
   3119 				    Z_OK)
   3120 					break;
   3121 			}
   3122 			return (Z_OK);
   3123 		}
   3124 	}
   3125 	return (Z_NO_RESOURCE_ID);
   3126 }
   3127 
   3128 static int
   3129 zonecfg_add_rctl_core(zone_dochandle_t handle, struct zone_rctltab *tabptr)
   3130 {
   3131 	xmlNodePtr newnode, cur = handle->zone_dh_cur, valnode;
   3132 	struct zone_rctlvaltab *valptr;
   3133 	int err;
   3134 
   3135 	newnode = xmlNewTextChild(cur, NULL, DTD_ELEM_RCTL, NULL);
   3136 	err = newprop(newnode, DTD_ATTR_NAME, tabptr->zone_rctl_name);
   3137 	if (err != Z_OK)
   3138 		return (err);
   3139 	for (valptr = tabptr->zone_rctl_valptr; valptr != NULL;
   3140 	    valptr = valptr->zone_rctlval_next) {
   3141 		valnode = xmlNewTextChild(newnode, NULL,
   3142 		    DTD_ELEM_RCTLVALUE, NULL);
   3143 		err = newprop(valnode, DTD_ATTR_PRIV,
   3144 		    valptr->zone_rctlval_priv);
   3145 		if (err != Z_OK)
   3146 			return (err);
   3147 		err = newprop(valnode, DTD_ATTR_LIMIT,
   3148 		    valptr->zone_rctlval_limit);
   3149 		if (err != Z_OK)
   3150 			return (err);
   3151 		err = newprop(valnode, DTD_ATTR_ACTION,
   3152 		    valptr->zone_rctlval_action);
   3153 		if (err != Z_OK)
   3154 			return (err);
   3155 	}
   3156 	return (Z_OK);
   3157 }
   3158 
   3159 int
   3160 zonecfg_add_rctl(zone_dochandle_t handle, struct zone_rctltab *tabptr)
   3161 {
   3162 	int err;
   3163 
   3164 	if (tabptr == NULL)
   3165 		return (Z_INVAL);
   3166 
   3167 	if ((err = operation_prep(handle)) != Z_OK)
   3168 		return (err);
   3169 
   3170 	if ((err = zonecfg_add_rctl_core(handle, tabptr)) != Z_OK)
   3171 		return (err);
   3172 
   3173 	return (Z_OK);
   3174 }
   3175 
   3176 static int
   3177 zonecfg_delete_rctl_core(zone_dochandle_t handle, struct zone_rctltab *tabptr)
   3178 {
   3179 	xmlNodePtr cur = handle->zone_dh_cur;
   3180 	xmlChar *savedname;
   3181 	int name_result;
   3182 
   3183 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   3184 		if (xmlStrcmp(cur->name, DTD_ELEM_RCTL))
   3185 			continue;
   3186 
   3187 		savedname = xmlGetProp(cur, DTD_ATTR_NAME);
   3188 		if (savedname == NULL)	/* shouldn't happen */
   3189 			continue;
   3190 		name_result = xmlStrcmp(savedname,
   3191 		    (const xmlChar *) tabptr->zone_rctl_name);
   3192 		xmlFree(savedname);
   3193 
   3194 		if (name_result == 0) {
   3195 			xmlUnlinkNode(cur);
   3196 			xmlFreeNode(cur);
   3197 			return (Z_OK);
   3198 		}
   3199 	}
   3200 	return (Z_NO_RESOURCE_ID);
   3201 }
   3202 
   3203 int
   3204 zonecfg_delete_rctl(zone_dochandle_t handle, struct zone_rctltab *tabptr)
   3205 {
   3206 	int err;
   3207 
   3208 	if (tabptr == NULL)
   3209 		return (Z_INVAL);
   3210 
   3211 	if ((err = operation_prep(handle)) != Z_OK)
   3212 		return (err);
   3213 
   3214 	if ((err = zonecfg_delete_rctl_core(handle, tabptr)) != Z_OK)
   3215 		return (err);
   3216 
   3217 	return (Z_OK);
   3218 }
   3219 
   3220 int
   3221 zonecfg_modify_rctl(
   3222 	zone_dochandle_t handle,
   3223 	struct zone_rctltab *oldtabptr,
   3224 	struct zone_rctltab *newtabptr)
   3225 {
   3226 	int err;
   3227 
   3228 	if (oldtabptr == NULL || newtabptr == NULL)
   3229 		return (Z_INVAL);
   3230 
   3231 	if ((err = operation_prep(handle)) != Z_OK)
   3232 		return (err);
   3233 
   3234 	if ((err = zonecfg_delete_rctl_core(handle, oldtabptr)) != Z_OK)
   3235 		return (err);
   3236 
   3237 	if ((err = zonecfg_add_rctl_core(handle, newtabptr)) != Z_OK)
   3238 		return (err);
   3239 
   3240 	return (Z_OK);
   3241 }
   3242 
   3243 int
   3244 zonecfg_add_rctl_value(
   3245 	struct zone_rctltab *tabptr,
   3246 	struct zone_rctlvaltab *valtabptr)
   3247 {
   3248 	struct zone_rctlvaltab *last, *old, *new;
   3249 	rctlblk_t *rctlblk = alloca(rctlblk_size());
   3250 
   3251 	last = tabptr->zone_rctl_valptr;
   3252 	for (old = last; old != NULL; old = old->zone_rctlval_next)
   3253 		last = old;	/* walk to the end of the list */
   3254 	new = valtabptr;	/* alloc'd by caller */
   3255 	new->zone_rctlval_next = NULL;
   3256 	if (zonecfg_construct_rctlblk(valtabptr, rctlblk) != Z_OK)
   3257 		return (Z_INVAL);
   3258 	if (!zonecfg_valid_rctlblk(rctlblk))
   3259 		return (Z_INVAL);
   3260 	if (last == NULL)
   3261 		tabptr->zone_rctl_valptr = new;
   3262 	else
   3263 		last->zone_rctlval_next = new;
   3264 	return (Z_OK);
   3265 }
   3266 
   3267 int
   3268 zonecfg_remove_rctl_value(
   3269 	struct zone_rctltab *tabptr,
   3270 	struct zone_rctlvaltab *valtabptr)
   3271 {
   3272 	struct zone_rctlvaltab *last, *this, *next;
   3273 
   3274 	last = tabptr->zone_rctl_valptr;
   3275 	for (this = last; this != NULL; this = this->zone_rctlval_next) {
   3276 		if (strcmp(this->zone_rctlval_priv,
   3277 		    valtabptr->zone_rctlval_priv) == 0 &&
   3278 		    strcmp(this->zone_rctlval_limit,
   3279 		    valtabptr->zone_rctlval_limit) == 0 &&
   3280 		    strcmp(this->zone_rctlval_action,
   3281 		    valtabptr->zone_rctlval_action) == 0) {
   3282 			next = this->zone_rctlval_next;
   3283 			if (this == tabptr->zone_rctl_valptr)
   3284 				tabptr->zone_rctl_valptr = next;
   3285 			else
   3286 				last->zone_rctlval_next = next;
   3287 			free(this);
   3288 			return (Z_OK);
   3289 		} else
   3290 			last = this;
   3291 	}
   3292 	return (Z_NO_PROPERTY_ID);
   3293 }
   3294 
   3295 void
   3296 zonecfg_set_swinv(zone_dochandle_t handle)
   3297 {
   3298 	handle->zone_dh_sw_inv = B_TRUE;
   3299 }
   3300 
   3301 /*
   3302  * Add the pkg to the sw inventory on the handle.
   3303  */
   3304 int
   3305 zonecfg_add_pkg(zone_dochandle_t handle, char *name, char *version)
   3306 {
   3307 	xmlNodePtr newnode;
   3308 	xmlNodePtr cur;
   3309 	int err;
   3310 
   3311 	if ((err = operation_prep(handle)) != Z_OK)
   3312 		return (err);
   3313 
   3314 	cur = handle->zone_dh_cur;
   3315 	newnode = xmlNewTextChild(cur, NULL, DTD_ELEM_PACKAGE, NULL);
   3316 	if ((err = newprop(newnode, DTD_ATTR_NAME, name)) != Z_OK)
   3317 		return (err);
   3318 	if ((err = newprop(newnode, DTD_ATTR_VERSION, version)) != Z_OK)
   3319 		return (err);
   3320 	return (Z_OK);
   3321 }
   3322 
   3323 int
   3324 zonecfg_add_patch(zone_dochandle_t handle, char *id, void **pnode)
   3325 {
   3326 	xmlNodePtr node = (xmlNodePtr)*pnode;
   3327 	xmlNodePtr cur;
   3328 	int err;
   3329 
   3330 	if ((err = operation_prep(handle)) != Z_OK)
   3331 		return (err);
   3332 
   3333 	cur = handle->zone_dh_cur;
   3334 	node = xmlNewTextChild(cur, NULL, DTD_ELEM_PATCH, NULL);
   3335 	if ((err = newprop(node, DTD_ATTR_ID, id)) != Z_OK)
   3336 		return (err);
   3337 	*pnode = (void *)node;
   3338 	return (Z_OK);
   3339 }
   3340 
   3341 int
   3342 zonecfg_add_patch_obs(char *id, void *cur)
   3343 {
   3344 	xmlNodePtr	node;
   3345 	int err;
   3346 
   3347 	node = xmlNewTextChild((xmlNodePtr)cur, NULL, DTD_ELEM_OBSOLETES, NULL);
   3348 	if ((err = newprop(node, DTD_ATTR_ID, id)) != Z_OK)
   3349 		return (err);
   3350 	return (Z_OK);
   3351 }
   3352 
   3353 char *
   3354 zonecfg_strerror(int errnum)
   3355 {
   3356 	switch (errnum) {
   3357 	case Z_OK:
   3358 		return (dgettext(TEXT_DOMAIN, "OK"));
   3359 	case Z_EMPTY_DOCUMENT:
   3360 		return (dgettext(TEXT_DOMAIN, "Empty document"));
   3361 	case Z_WRONG_DOC_TYPE:
   3362 		return (dgettext(TEXT_DOMAIN, "Wrong document type"));
   3363 	case Z_BAD_PROPERTY:
   3364 		return (dgettext(TEXT_DOMAIN, "Bad document property"));
   3365 	case Z_TEMP_FILE:
   3366 		return (dgettext(TEXT_DOMAIN,
   3367 		    "Problem creating temporary file"));
   3368 	case Z_SAVING_FILE:
   3369 		return (dgettext(TEXT_DOMAIN, "Problem saving file"));
   3370 	case Z_NO_ENTRY:
   3371 		return (dgettext(TEXT_DOMAIN, "No such entry"));
   3372 	case Z_BOGUS_ZONE_NAME:
   3373 		return (dgettext(TEXT_DOMAIN, "Bogus zone name"));
   3374 	case Z_REQD_RESOURCE_MISSING:
   3375 		return (dgettext(TEXT_DOMAIN, "Required resource missing"));
   3376 	case Z_REQD_PROPERTY_MISSING:
   3377 		return (dgettext(TEXT_DOMAIN, "Required property missing"));
   3378 	case Z_BAD_HANDLE:
   3379 		return (dgettext(TEXT_DOMAIN, "Bad handle"));
   3380 	case Z_NOMEM:
   3381 		return (dgettext(TEXT_DOMAIN, "Out of memory"));
   3382 	case Z_INVAL:
   3383 		return (dgettext(TEXT_DOMAIN, "Invalid argument"));
   3384 	case Z_ACCES:
   3385 		return (dgettext(TEXT_DOMAIN, "Permission denied"));
   3386 	case Z_TOO_BIG:
   3387 		return (dgettext(TEXT_DOMAIN, "Argument list too long"));
   3388 	case Z_MISC_FS:
   3389 		return (dgettext(TEXT_DOMAIN,
   3390 		    "Miscellaneous file system error"));
   3391 	case Z_NO_ZONE:
   3392 		return (dgettext(TEXT_DOMAIN, "No such zone configured"));
   3393 	case Z_NO_RESOURCE_TYPE:
   3394 		return (dgettext(TEXT_DOMAIN, "No such resource type"));
   3395 	case Z_NO_RESOURCE_ID:
   3396 		return (dgettext(TEXT_DOMAIN, "No such resource with that id"));
   3397 	case Z_NO_PROPERTY_TYPE:
   3398 		return (dgettext(TEXT_DOMAIN, "No such property type"));
   3399 	case Z_NO_PROPERTY_ID:
   3400 		return (dgettext(TEXT_DOMAIN, "No such property with that id"));
   3401 	case Z_BAD_ZONE_STATE:
   3402 		return (dgettext(TEXT_DOMAIN,
   3403 		    "Zone state is invalid for the requested operation"));
   3404 	case Z_INVALID_DOCUMENT:
   3405 		return (dgettext(TEXT_DOMAIN, "Invalid document"));
   3406 	case Z_NAME_IN_USE:
   3407 		return (dgettext(TEXT_DOMAIN, "Zone name already in use"));
   3408 	case Z_NO_SUCH_ID:
   3409 		return (dgettext(TEXT_DOMAIN, "No such zone ID"));
   3410 	case Z_UPDATING_INDEX:
   3411 		return (dgettext(TEXT_DOMAIN, "Problem updating index file"));
   3412 	case Z_LOCKING_FILE:
   3413 		return (dgettext(TEXT_DOMAIN, "Locking index file"));
   3414 	case Z_UNLOCKING_FILE:
   3415 		return (dgettext(TEXT_DOMAIN, "Unlocking index file"));
   3416 	case Z_INSUFFICIENT_SPEC:
   3417 		return (dgettext(TEXT_DOMAIN, "Insufficient specification"));
   3418 	case Z_RESOLVED_PATH:
   3419 		return (dgettext(TEXT_DOMAIN, "Resolved path mismatch"));
   3420 	case Z_IPV6_ADDR_PREFIX_LEN:
   3421 		return (dgettext(TEXT_DOMAIN,
   3422 		    "IPv6 address missing required prefix length"));
   3423 	case Z_BOGUS_ADDRESS:
   3424 		return (dgettext(TEXT_DOMAIN,
   3425 		    "Neither an IPv4 nor an IPv6 address nor a host name"));
   3426 	case Z_PRIV_PROHIBITED:
   3427 		return (dgettext(TEXT_DOMAIN,
   3428 		    "Specified privilege is prohibited"));
   3429 	case Z_PRIV_REQUIRED:
   3430 		return (dgettext(TEXT_DOMAIN,
   3431 		    "Required privilege is missing"));
   3432 	case Z_PRIV_UNKNOWN:
   3433 		return (dgettext(TEXT_DOMAIN,
   3434 		    "Specified privilege is unknown"));
   3435 	case Z_BRAND_ERROR:
   3436 		return (dgettext(TEXT_DOMAIN,
   3437 		    "Brand-specific error"));
   3438 	case Z_INCOMPATIBLE:
   3439 		return (dgettext(TEXT_DOMAIN, "Incompatible settings"));
   3440 	case Z_ALIAS_DISALLOW:
   3441 		return (dgettext(TEXT_DOMAIN,
   3442 		    "An incompatible rctl already exists for this property"));
   3443 	case Z_CLEAR_DISALLOW:
   3444 		return (dgettext(TEXT_DOMAIN,
   3445 		    "Clearing this property is not allowed"));
   3446 	case Z_POOL:
   3447 		return (dgettext(TEXT_DOMAIN, "libpool(3LIB) error"));
   3448 	case Z_POOLS_NOT_ACTIVE:
   3449 		return (dgettext(TEXT_DOMAIN, "Pools facility not active; "
   3450 		    "zone will not be bound to pool"));
   3451 	case Z_POOL_ENABLE:
   3452 		return (dgettext(TEXT_DOMAIN,
   3453 		    "Could not enable pools facility"));
   3454 	case Z_NO_POOL:
   3455 		return (dgettext(TEXT_DOMAIN,
   3456 		    "Pool not found; using default pool"));
   3457 	case Z_POOL_CREATE:
   3458 		return (dgettext(TEXT_DOMAIN,
   3459 		    "Could not create a temporary pool"));
   3460 	case Z_POOL_BIND:
   3461 		return (dgettext(TEXT_DOMAIN, "Could not bind zone to pool"));
   3462 	case Z_HOSTID_FUBAR:
   3463 		return (dgettext(TEXT_DOMAIN, "Specified hostid is invalid"));
   3464 	case Z_SYSTEM:
   3465 		return (strerror(errno));
   3466 	default:
   3467 		return (dgettext(TEXT_DOMAIN, "Unknown error"));
   3468 	}
   3469 }
   3470 
   3471 /*
   3472  * Note that the zonecfg_setXent() and zonecfg_endXent() calls are all the
   3473  * same, as they just turn around and call zonecfg_setent() / zonecfg_endent().
   3474  */
   3475 
   3476 static int
   3477 zonecfg_setent(zone_dochandle_t handle)
   3478 {
   3479 	xmlNodePtr cur;
   3480 	int err;
   3481 
   3482 	if (handle == NULL)
   3483 		return (Z_INVAL);
   3484 
   3485 	if ((err = operation_prep(handle)) != Z_OK) {
   3486 		handle->zone_dh_cur = NULL;
   3487 		return (err);
   3488 	}
   3489 	cur = handle->zone_dh_cur;
   3490 	cur = cur->xmlChildrenNode;
   3491 	handle->zone_dh_cur = cur;
   3492 	return (Z_OK);
   3493 }
   3494 
   3495 static int
   3496 zonecfg_endent(zone_dochandle_t handle)
   3497 {
   3498 	if (handle == NULL)
   3499 		return (Z_INVAL);
   3500 
   3501 	handle->zone_dh_cur = handle->zone_dh_top;
   3502 	return (Z_OK);
   3503 }
   3504 
   3505 /*
   3506  * Do the work required to manipulate a process through libproc.
   3507  * If grab_process() returns no errors (0), then release_process()
   3508  * must eventually be called.
   3509  *
   3510  * Return values:
   3511  *      0 Successful creation of agent thread
   3512  *      1 Error grabbing
   3513  *      2 Error creating agent
   3514  */
   3515 static int
   3516 grab_process(pr_info_handle_t *p)
   3517 {
   3518 	int ret;
   3519 
   3520 	if ((p->pr = Pgrab(p->pid, 0, &ret)) != NULL) {
   3521 
   3522 		if (Psetflags(p->pr, PR_RLC) != 0) {
   3523 			Prelease(p->pr, 0);
   3524 			return (1);
   3525 		}
   3526 		if (Pcreate_agent(p->pr) == 0) {
   3527 			return (0);
   3528 
   3529 		} else {
   3530 			Prelease(p->pr, 0);
   3531 			return (2);
   3532 		}
   3533 	} else {
   3534 		return (1);
   3535 	}
   3536 }
   3537 
   3538 /*
   3539  * Release the specified process. This destroys the agent
   3540  * and releases the process. If the process is NULL, nothing
   3541  * is done. This function should only be called if grab_process()
   3542  * has previously been called and returned success.
   3543  *
   3544  * This function is Pgrab-safe.
   3545  */
   3546 static void
   3547 release_process(struct ps_prochandle *Pr)
   3548 {
   3549 	if (Pr == NULL)
   3550 		return;
   3551 
   3552 	Pdestroy_agent(Pr);
   3553 	Prelease(Pr, 0);
   3554 }
   3555 
   3556 static boolean_t
   3557 grab_zone_proc(char *zonename, pr_info_handle_t *p)
   3558 {
   3559 	DIR *dirp;
   3560 	struct dirent *dentp;
   3561 	zoneid_t zoneid;
   3562 	int pid_self;
   3563 	psinfo_t psinfo;
   3564 
   3565 	if (zone_get_id(zonename, &zoneid) != 0)
   3566 		return (B_FALSE);
   3567 
   3568 	pid_self = getpid();
   3569 
   3570 	if ((dirp = opendir("/proc")) == NULL)
   3571 		return (B_FALSE);
   3572 
   3573 	while (dentp = readdir(dirp)) {
   3574 		p->pid = atoi(dentp->d_name);
   3575 
   3576 		/* Skip self */
   3577 		if (p->pid == pid_self)
   3578 			continue;
   3579 
   3580 		if (proc_get_psinfo(p->pid, &psinfo) != 0)
   3581 			continue;
   3582 
   3583 		if (psinfo.pr_zoneid != zoneid)
   3584 			continue;
   3585 
   3586 		/* attempt to grab process */
   3587 		if (grab_process(p) != 0)
   3588 			continue;
   3589 
   3590 		if (pr_getzoneid(p->pr) != zoneid) {
   3591 			release_process(p->pr);
   3592 			continue;
   3593 		}
   3594 
   3595 		(void) closedir(dirp);
   3596 		return (B_TRUE);
   3597 	}
   3598 
   3599 	(void) closedir(dirp);
   3600 	return (B_FALSE);
   3601 }
   3602 
   3603 static boolean_t
   3604 get_priv_rctl(struct ps_prochandle *pr, char *name, rctlblk_t *rblk)
   3605 {
   3606 	if (pr_getrctl(pr, name, NULL, rblk, RCTL_FIRST))
   3607 		return (B_FALSE);
   3608 
   3609 	if (rctlblk_get_privilege(rblk) == RCPRIV_PRIVILEGED)
   3610 		return (B_TRUE);
   3611 
   3612 	while (pr_getrctl(pr, name, rblk, rblk, RCTL_NEXT) == 0) {
   3613 		if (rctlblk_get_privilege(rblk) == RCPRIV_PRIVILEGED)
   3614 			return (B_TRUE);
   3615 	}
   3616 
   3617 	return (B_FALSE);
   3618 }
   3619 
   3620 /*
   3621  * Apply the current rctl settings to the specified, running zone.
   3622  */
   3623 int
   3624 zonecfg_apply_rctls(char *zone_name, zone_dochandle_t handle)
   3625 {
   3626 	int err;
   3627 	int res = Z_OK;
   3628 	rctlblk_t *rblk;
   3629 	pr_info_handle_t p;
   3630 	struct zone_rctltab rctl;
   3631 
   3632 	if ((err = zonecfg_setrctlent(handle)) != Z_OK)
   3633 		return (err);
   3634 
   3635 	if ((rblk = (rctlblk_t *)malloc(rctlblk_size())) == NULL) {
   3636 		(void) zonecfg_endrctlent(handle);
   3637 		return (Z_NOMEM);
   3638 	}
   3639 
   3640 	if (!grab_zone_proc(zone_name, &p)) {
   3641 		(void) zonecfg_endrctlent(handle);
   3642 		free(rblk);
   3643 		return (Z_SYSTEM);
   3644 	}
   3645 
   3646 	while (zonecfg_getrctlent(handle, &rctl) == Z_OK) {
   3647 		char *rname;
   3648 		struct zone_rctlvaltab *valptr;
   3649 
   3650 		rname = rctl.zone_rctl_name;
   3651 
   3652 		/* first delete all current privileged settings for this rctl */
   3653 		while (get_priv_rctl(p.pr, rname, rblk)) {
   3654 			if (pr_setrctl(p.pr, rname, NULL, rblk, RCTL_DELETE) !=
   3655 			    0) {
   3656 				res = Z_SYSTEM;
   3657 				goto done;
   3658 			}
   3659 		}
   3660 
   3661 		/* now set each new value for the rctl */
   3662 		for (valptr = rctl.zone_rctl_valptr; valptr != NULL;
   3663 		    valptr = valptr->zone_rctlval_next) {
   3664 			if ((err = zonecfg_construct_rctlblk(valptr, rblk))
   3665 			    != Z_OK) {
   3666 				res = errno = err;
   3667 				goto done;
   3668 			}
   3669 
   3670 			if (pr_setrctl(p.pr, rname, NULL, rblk, RCTL_INSERT)) {
   3671 				res = Z_SYSTEM;
   3672 				goto done;
   3673 			}
   3674 		}
   3675 	}
   3676 
   3677 done:
   3678 	release_process(p.pr);
   3679 	free(rblk);
   3680 	(void) zonecfg_endrctlent(handle);
   3681 
   3682 	return (res);
   3683 }
   3684 
   3685 static const xmlChar *
   3686 nm_to_dtd(char *nm)
   3687 {
   3688 	if (strcmp(nm, "device") == 0)
   3689 		return (DTD_ELEM_DEVICE);
   3690 	if (strcmp(nm, "fs") == 0)
   3691 		return (DTD_ELEM_FS);
   3692 	if (strcmp(nm, "inherit-pkg-dir") == 0)
   3693 		return (DTD_ELEM_IPD);
   3694 	if (strcmp(nm, "net") == 0)
   3695 		return (DTD_ELEM_NET);
   3696 	if (strcmp(nm, "attr") == 0)
   3697 		return (DTD_ELEM_ATTR);
   3698 	if (strcmp(nm, "rctl") == 0)
   3699 		return (DTD_ELEM_RCTL);
   3700 	if (strcmp(nm, "dataset") == 0)
   3701 		return (DTD_ELEM_DATASET);
   3702 
   3703 	return (NULL);
   3704 }
   3705 
   3706 int
   3707 zonecfg_num_resources(zone_dochandle_t handle, char *rsrc)
   3708 {
   3709 	int num = 0;
   3710 	const xmlChar *dtd;
   3711 	xmlNodePtr cur;
   3712 
   3713 	if ((dtd = nm_to_dtd(rsrc)) == NULL)
   3714 		return (num);
   3715 
   3716 	if (zonecfg_setent(handle) != Z_OK)
   3717 		return (num);
   3718 
   3719 	for (cur = handle->zone_dh_cur; cur != NULL; cur = cur->next)
   3720 		if (xmlStrcmp(cur->name, dtd) == 0)
   3721 			num++;
   3722 
   3723 	(void) zonecfg_endent(handle);
   3724 
   3725 	return (num);
   3726 }
   3727 
   3728 int
   3729 zonecfg_del_all_resources(zone_dochandle_t handle, char *rsrc)
   3730 {
   3731 	int err;
   3732 	const xmlChar *dtd;
   3733 	xmlNodePtr cur;
   3734 
   3735 	if ((dtd = nm_to_dtd(rsrc)) == NULL)
   3736 		return (Z_NO_RESOURCE_TYPE);
   3737 
   3738 	if ((err = zonecfg_setent(handle)) != Z_OK)
   3739 		return (err);
   3740 
   3741 	cur = handle->zone_dh_cur;
   3742 	while (cur != NULL) {
   3743 		xmlNodePtr tmp;
   3744 
   3745 		if (xmlStrcmp(cur->name, dtd)) {
   3746 			cur = cur->next;
   3747 			continue;
   3748 		}
   3749 
   3750 		tmp = cur->next;
   3751 		xmlUnlinkNode(cur);
   3752 		xmlFreeNode(cur);
   3753 		cur = tmp;
   3754 	}
   3755 
   3756 	(void) zonecfg_endent(handle);
   3757 	return (Z_OK);
   3758 }
   3759 
   3760 static boolean_t
   3761 valid_uint(char *s, uint64_t *n)
   3762 {
   3763 	char *endp;
   3764 
   3765 	/* strtoull accepts '-'?! so we want to flag that as an error */
   3766 	if (strchr(s, '-') != NULL)
   3767 		return (B_FALSE);
   3768 
   3769 	errno = 0;
   3770 	*n = strtoull(s, &endp, 10);
   3771 
   3772 	if (errno != 0 || *endp != '\0')
   3773 		return (B_FALSE);
   3774 	return (B_TRUE);
   3775 }
   3776 
   3777 /*
   3778  * Convert a string representing a number (possibly a fraction) into an integer.
   3779  * The string can have a modifier (K, M, G or T).   The modifiers are treated
   3780  * as powers of two (not 10).
   3781  */
   3782 int
   3783 zonecfg_str_to_bytes(char *str, uint64_t *bytes)
   3784 {
   3785 	long double val;
   3786 	char *unitp;
   3787 	uint64_t scale;
   3788 
   3789 	if ((val = strtold(str, &unitp)) < 0)
   3790 		return (-1);
   3791 
   3792 	/* remove any leading white space from units string */
   3793 	while (isspace(*unitp) != 0)
   3794 		++unitp;
   3795 
   3796 	/* if no units explicitly set, error */
   3797 	if (unitp == NULL || *unitp == '\0') {
   3798 		scale = 1;
   3799 	} else {
   3800 		int i;
   3801 		char *units[] = {"K", "M", "G", "T", NULL};
   3802 
   3803 		scale = 1024;
   3804 
   3805 		/* update scale based on units */
   3806 		for (i = 0; units[i] != NULL; i++) {
   3807 			if (strcasecmp(unitp, units[i]) == 0)
   3808 				break;
   3809 			scale <<= 10;
   3810 		}
   3811 
   3812 		if (units[i] == NULL)
   3813 			return (-1);
   3814 	}
   3815 
   3816 	*bytes = (uint64_t)(val * scale);
   3817 	return (0);
   3818 }
   3819 
   3820 boolean_t
   3821 zonecfg_valid_ncpus(char *lowstr, char *highstr)
   3822 {
   3823 	uint64_t low, high;
   3824 
   3825 	if (!valid_uint(lowstr, &low) || !valid_uint(highstr, &high) ||
   3826 	    low < 1 || low > high)
   3827 		return (B_FALSE);
   3828 
   3829 	return (B_TRUE);
   3830 }
   3831 
   3832 boolean_t
   3833 zonecfg_valid_importance(char *impstr)
   3834 {
   3835 	uint64_t num;
   3836 
   3837 	if (!valid_uint(impstr, &num))
   3838 		return (B_FALSE);
   3839 
   3840 	return (B_TRUE);
   3841 }
   3842 
   3843 boolean_t
   3844 zonecfg_valid_alias_limit(char *name, char *limitstr, uint64_t *limit)
   3845 {
   3846 	int i;
   3847 
   3848 	for (i = 0; aliases[i].shortname != NULL; i++)
   3849 		if (strcmp(name, aliases[i].shortname) == 0)
   3850 			break;
   3851 
   3852 	if (aliases[i].shortname == NULL)
   3853 		return (B_FALSE);
   3854 
   3855 	if (!valid_uint(limitstr, limit) || *limit < aliases[i].low_limit)
   3856 		return (B_FALSE);
   3857 
   3858 	return (B_TRUE);
   3859 }
   3860 
   3861 boolean_t
   3862 zonecfg_valid_memlimit(char *memstr, uint64_t *mem_val)
   3863 {
   3864 	if (zonecfg_str_to_bytes(memstr, mem_val) != 0)
   3865 		return (B_FALSE);
   3866 
   3867 	return (B_TRUE);
   3868 }
   3869 
   3870 static int
   3871 zerr_pool(char *pool_err, int err_size, int res)
   3872 {
   3873 	(void) strlcpy(pool_err, pool_strerror(pool_error()), err_size);
   3874 	return (res);
   3875 }
   3876 
   3877 static int
   3878 create_tmp_pset(char *pool_err, int err_size, pool_conf_t *pconf, pool_t *pool,
   3879     char *name, int min, int max)
   3880 {
   3881 	pool_resource_t *res;
   3882 	pool_elem_t *elem;
   3883 	pool_value_t *val;
   3884 
   3885 	if ((res = pool_resource_create(pconf, "pset", name)) == NULL)
   3886 		return (zerr_pool(pool_err, err_size, Z_POOL));
   3887 
   3888 	if (pool_associate(pconf, pool, res) != PO_SUCCESS)
   3889 		return (zerr_pool(pool_err, err_size, Z_POOL));
   3890 
   3891 	if ((elem = pool_resource_to_elem(pconf, res)) == NULL)
   3892 		return (zerr_pool(pool_err, err_size, Z_POOL));
   3893 
   3894 	if ((val = pool_value_alloc()) == NULL)
   3895 		return (zerr_pool(pool_err, err_size, Z_POOL));
   3896 
   3897 	/* set the maximum number of cpus for the pset */
   3898 	pool_value_set_uint64(val, (uint64_t)max);
   3899 
   3900 	if (pool_put_property(pconf, elem, "pset.max", val) != PO_SUCCESS) {
   3901 		pool_value_free(val);
   3902 		return (zerr_pool(pool_err, err_size, Z_POOL));
   3903 	}
   3904 
   3905 	/* set the minimum number of cpus for the pset */
   3906 	pool_value_set_uint64(val, (uint64_t)min);
   3907 
   3908 	if (pool_put_property(pconf, elem, "pset.min", val) != PO_SUCCESS) {
   3909 		pool_value_free(val);
   3910 		return (zerr_pool(pool_err, err_size, Z_POOL));
   3911 	}
   3912 
   3913 	pool_value_free(val);
   3914 
   3915 	return (Z_OK);
   3916 }
   3917 
   3918 static int
   3919 create_tmp_pool(char *pool_err, int err_size, pool_conf_t *pconf, char *name,
   3920     struct zone_psettab *pset_tab)
   3921 {
   3922 	pool_t *pool;
   3923 	int res = Z_OK;
   3924 
   3925 	/* create a temporary pool configuration */
   3926 	if (pool_conf_open(pconf, NULL, PO_TEMP) != PO_SUCCESS) {
   3927 		res = zerr_pool(pool_err, err_size, Z_POOL);
   3928 		return (res);
   3929 	}
   3930 
   3931 	if ((pool = pool_create(pconf, name)) == NULL) {
   3932 		res = zerr_pool(pool_err, err_size, Z_POOL_CREATE);
   3933 		goto done;
   3934 	}
   3935 
   3936 	/* set pool importance */
   3937 	if (pset_tab->zone_importance[0] != '\0') {
   3938 		pool_elem_t *elem;
   3939 		pool_value_t *val;
   3940 
   3941 		if ((elem = pool_to_elem(pconf, pool)) == NULL) {
   3942 			res = zerr_pool(pool_err, err_size, Z_POOL);
   3943 			goto done;
   3944 		}
   3945 
   3946 		if ((val = pool_value_alloc()) == NULL) {
   3947 			res = zerr_pool(pool_err, err_size, Z_POOL);
   3948 			goto done;
   3949 		}
   3950 
   3951 		pool_value_set_int64(val,
   3952 		    (int64_t)atoi(pset_tab->zone_importance));
   3953 
   3954 		if (pool_put_property(pconf, elem, "pool.importance", val)
   3955 		    != PO_SUCCESS) {
   3956 			res = zerr_pool(pool_err, err_size, Z_POOL);
   3957 			pool_value_free(val);
   3958 			goto done;
   3959 		}
   3960 
   3961 		pool_value_free(val);
   3962 	}
   3963 
   3964 	if ((res = create_tmp_pset(pool_err, err_size, pconf, pool, name,
   3965 	    atoi(pset_tab->zone_ncpu_min),
   3966 	    atoi(pset_tab->zone_ncpu_max))) != Z_OK)
   3967 		goto done;
   3968 
   3969 	/* validation */
   3970 	if (pool_conf_status(pconf) == POF_INVALID) {
   3971 		res = zerr_pool(pool_err, err_size, Z_POOL);
   3972 		goto done;
   3973 	}
   3974 
   3975 	/*
   3976 	 * This validation is the one we expect to fail if the user specified
   3977 	 * an invalid configuration (too many cpus) for this system.
   3978 	 */
   3979 	if (pool_conf_validate(pconf, POV_RUNTIME) != PO_SUCCESS) {
   3980 		res = zerr_pool(pool_err, err_size, Z_POOL_CREATE);
   3981 		goto done;
   3982 	}
   3983 
   3984 	/*
   3985 	 * Commit the dynamic configuration but not the pool configuration
   3986 	 * file.
   3987 	 */
   3988 	if (pool_conf_commit(pconf, 1) != PO_SUCCESS)
   3989 		res = zerr_pool(pool_err, err_size, Z_POOL);
   3990 
   3991 done:
   3992 	(void) pool_conf_close(pconf);
   3993 	return (res);
   3994 }
   3995 
   3996 static int
   3997 get_running_tmp_pset(pool_conf_t *pconf, pool_t *pool, pool_resource_t *pset,
   3998     struct zone_psettab *pset_tab)
   3999 {
   4000 	int nfound = 0;
   4001 	pool_elem_t *pe;
   4002 	pool_value_t *pv = pool_value_alloc();
   4003 	uint64_t val_uint;
   4004 
   4005 	if (pool != NULL) {
   4006 		pe = pool_to_elem(pconf, pool);
   4007 		if (pool_get_property(pconf, pe, "pool.importance", pv)
   4008 		    != POC_INVAL) {
   4009 			int64_t val_int;
   4010 
   4011 			(void) pool_value_get_int64(pv, &val_int);
   4012 			(void) snprintf(pset_tab->zone_importance,
   4013 			    sizeof (pset_tab->zone_importance), "%d", val_int);
   4014 			nfound++;
   4015 		}
   4016 	}
   4017 
   4018 	if (pset != NULL) {
   4019 		pe = pool_resource_to_elem(pconf, pset);
   4020 		if (pool_get_property(pconf, pe, "pset.min", pv) != POC_INVAL) {
   4021 			(void) pool_value_get_uint64(pv, &val_uint);
   4022 			(void) snprintf(pset_tab->zone_ncpu_min,
   4023 			    sizeof (pset_tab->zone_ncpu_min), "%u", val_uint);
   4024 			nfound++;
   4025 		}
   4026 
   4027 		if (pool_get_property(pconf, pe, "pset.max", pv) != POC_INVAL) {
   4028 			(void) pool_value_get_uint64(pv, &val_uint);
   4029 			(void) snprintf(pset_tab->zone_ncpu_max,
   4030 			    sizeof (pset_tab->zone_ncpu_max), "%u", val_uint);
   4031 			nfound++;
   4032 		}
   4033 	}
   4034 
   4035 	pool_value_free(pv);
   4036 
   4037 	if (nfound == 3)
   4038 		return (PO_SUCCESS);
   4039 
   4040 	return (PO_FAIL);
   4041 }
   4042 
   4043 /*
   4044  * Determine if a tmp pool is configured and if so, if the configuration is
   4045  * still valid or if it has been changed since the tmp pool was created.
   4046  * If the tmp pool configuration is no longer valid, delete the tmp pool.
   4047  *
   4048  * Set *valid=B_TRUE if there is an existing, valid tmp pool configuration.
   4049  */
   4050 static int
   4051 verify_del_tmp_pool(pool_conf_t *pconf, char *tmp_name, char *pool_err,
   4052     int err_size, struct zone_psettab *pset_tab, boolean_t *exists)
   4053 {
   4054 	int res = Z_OK;
   4055 	pool_t *pool;
   4056 	pool_resource_t *pset;
   4057 	struct zone_psettab pset_current;
   4058 
   4059 	*exists = B_FALSE;
   4060 
   4061 	if (pool_conf_open(pconf, pool_dynamic_location(), PO_RDWR)
   4062 	    != PO_SUCCESS) {
   4063 		res = zerr_pool(pool_err, err_size, Z_POOL);
   4064 		return (res);
   4065 	}
   4066 
   4067 	pool = pool_get_pool(pconf, tmp_name);
   4068 	pset = pool_get_resource(pconf, "pset", tmp_name);
   4069 
   4070 	if (pool == NULL && pset == NULL) {
   4071 		/* no tmp pool configured */
   4072 		goto done;
   4073 	}
   4074 
   4075 	/*
   4076 	 * If an existing tmp pool for this zone is configured with the proper
   4077 	 * settings, then the tmp pool is valid.
   4078 	 */
   4079 	if (get_running_tmp_pset(pconf, pool, pset, &pset_current)
   4080 	    == PO_SUCCESS &&
   4081 	    strcmp(pset_tab->zone_ncpu_min,
   4082 	    pset_current.zone_ncpu_min) == 0 &&
   4083 	    strcmp(pset_tab->zone_ncpu_max,
   4084 	    pset_current.zone_ncpu_max) == 0 &&
   4085 	    strcmp(pset_tab->zone_importance,
   4086 	    pset_current.zone_importance) == 0) {
   4087 		*exists = B_TRUE;
   4088 
   4089 	} else {
   4090 		/*
   4091 		 * An out-of-date tmp pool configuration exists.  Delete it
   4092 		 * so that we can create the correct tmp pool config.
   4093 		 */
   4094 		if (pset != NULL &&
   4095 		    pool_resource_destroy(pconf, pset) != PO_SUCCESS) {
   4096 			res = zerr_pool(pool_err, err_size, Z_POOL);
   4097 			goto done;
   4098 		}
   4099 
   4100 		if (pool != NULL &&
   4101 		    pool_destroy(pconf, pool) != PO_SUCCESS) {
   4102 			res = zerr_pool(pool_err, err_size, Z_POOL);
   4103 			goto done;
   4104 		}
   4105 
   4106 		/* commit dynamic config */
   4107 		if (pool_conf_commit(pconf, 0) != PO_SUCCESS)
   4108 			res = zerr_pool(pool_err, err_size, Z_POOL);
   4109 	}
   4110 
   4111 done:
   4112 	(void) pool_conf_close(pconf);
   4113 
   4114 	return (res);
   4115 }
   4116 
   4117 /*
   4118  * Destroy any existing tmp pool.
   4119  */
   4120 int
   4121 zonecfg_destroy_tmp_pool(char *zone_name, char *pool_err, int err_size)
   4122 {
   4123 	int status;
   4124 	int res = Z_OK;
   4125 	pool_conf_t *pconf;
   4126 	pool_t *pool;
   4127 	pool_resource_t *pset;
   4128 	char tmp_name[MAX_TMP_POOL_NAME];
   4129 
   4130 	/* if pools not enabled then nothing to do */
   4131 	if (pool_get_status(&status) != PO_SUCCESS || status != POOL_ENABLED)
   4132 		return (Z_OK);
   4133 
   4134 	if ((pconf = pool_conf_alloc()) == NULL)
   4135 		return (zerr_pool(pool_err, err_size, Z_POOL));
   4136 
   4137 	(void) snprintf(tmp_name, sizeof (tmp_name), TMP_POOL_NAME, zone_name);
   4138 
   4139 	if (pool_conf_open(pconf, pool_dynamic_location(), PO_RDWR)
   4140 	    != PO_SUCCESS) {
   4141 		res = zerr_pool(pool_err, err_size, Z_POOL);
   4142 		pool_conf_free(pconf);
   4143 		return (res);
   4144 	}
   4145 
   4146 	pool = pool_get_pool(pconf, tmp_name);
   4147 	pset = pool_get_resource(pconf, "pset", tmp_name);
   4148 
   4149 	if (pool == NULL && pset == NULL) {
   4150 		/* nothing to destroy, we're done */
   4151 		goto done;
   4152 	}
   4153 
   4154 	if (pset != NULL && pool_resource_destroy(pconf, pset) != PO_SUCCESS) {
   4155 		res = zerr_pool(pool_err, err_size, Z_POOL);
   4156 		goto done;
   4157 	}
   4158 
   4159 	if (pool != NULL && pool_destroy(pconf, pool) != PO_SUCCESS) {
   4160 		res = zerr_pool(pool_err, err_size, Z_POOL);
   4161 		goto done;
   4162 	}
   4163 
   4164 	/* commit dynamic config */
   4165 	if (pool_conf_commit(pconf, 0) != PO_SUCCESS)
   4166 		res = zerr_pool(pool_err, err_size, Z_POOL);
   4167 
   4168 done:
   4169 	(void) pool_conf_close(pconf);
   4170 	pool_conf_free(pconf);
   4171 
   4172 	return (res);
   4173 }
   4174 
   4175 /*
   4176  * Attempt to bind to a tmp pool for this zone.  If there is no tmp pool
   4177  * configured, we just return Z_OK.
   4178  *
   4179  * We either attempt to create the tmp pool for this zone or rebind to an
   4180  * existing tmp pool for this zone.
   4181  *
   4182  * Rebinding is used when a zone with a tmp pool reboots so that we don't have
   4183  * to recreate the tmp pool.  To do this we need to be sure we work correctly
   4184  * for the following cases:
   4185  *
   4186  *	- there is an existing, properly configured tmp pool.
   4187  *	- zonecfg added tmp pool after zone was booted, must now create.
   4188  *	- zonecfg updated tmp pool config after zone was booted, in this case
   4189  *	  we destroy the old tmp pool and create a new one.
   4190  */
   4191 int
   4192 zonecfg_bind_tmp_pool(zone_dochandle_t handle, zoneid_t zoneid, char *pool_err,
   4193     int err_size)
   4194 {
   4195 	struct zone_psettab pset_tab;
   4196 	int err;
   4197 	int status;
   4198 	pool_conf_t *pconf;
   4199 	boolean_t exists;
   4200 	char zone_name[ZONENAME_MAX];
   4201 	char tmp_name[MAX_TMP_POOL_NAME];
   4202 
   4203 	(void) getzonenamebyid(zoneid, zone_name, sizeof (zone_name));
   4204 
   4205 	err = zonecfg_lookup_pset(handle, &pset_tab);
   4206 
   4207 	/* if no temporary pool configured, we're done */
   4208 	if (err == Z_NO_ENTRY)
   4209 		return (Z_OK);
   4210 
   4211 	/*
   4212 	 * importance might not have a value but we need to validate it here,
   4213 	 * so set the default.
   4214 	 */
   4215 	if (pset_tab.zone_importance[0] == '\0')
   4216 		(void) strlcpy(pset_tab.zone_importance, "1",
   4217 		    sizeof (pset_tab.zone_importance));
   4218 
   4219 	/* if pools not enabled, enable them now */
   4220 	if (pool_get_status(&status) != PO_SUCCESS || status != POOL_ENABLED) {
   4221 		if (pool_set_status(POOL_ENABLED) != PO_SUCCESS)
   4222 			return (Z_POOL_ENABLE);
   4223 	}
   4224 
   4225 	if ((pconf = pool_conf_alloc()) == NULL)
   4226 		return (zerr_pool(pool_err, err_size, Z_POOL));
   4227 
   4228 	(void) snprintf(tmp_name, sizeof (tmp_name), TMP_POOL_NAME, zone_name);
   4229 
   4230 	/*
   4231 	 * Check if a valid tmp pool/pset already exists.  If so, we just
   4232 	 * reuse it.
   4233 	 */
   4234 	if ((err = verify_del_tmp_pool(pconf, tmp_name, pool_err, err_size,
   4235 	    &pset_tab, &exists)) != Z_OK) {
   4236 		pool_conf_free(pconf);
   4237 		return (err);
   4238 	}
   4239 
   4240 	if (!exists)
   4241 		err = create_tmp_pool(pool_err, err_size, pconf, tmp_name,
   4242 		    &pset_tab);
   4243 
   4244 	pool_conf_free(pconf);
   4245 
   4246 	if (err != Z_OK)
   4247 		return (err);
   4248 
   4249 	/* Bind the zone to the pool. */
   4250 	if (pool_set_binding(tmp_name, P_ZONEID, zoneid) != PO_SUCCESS)
   4251 		return (zerr_pool(pool_err, err_size, Z_POOL_BIND));
   4252 
   4253 	return (Z_OK);
   4254 }
   4255 
   4256 /*
   4257  * Attempt to bind to a permanent pool for this zone.  If there is no
   4258  * permanent pool configured, we just return Z_OK.
   4259  */
   4260 int
   4261 zonecfg_bind_pool(zone_dochandle_t handle, zoneid_t zoneid, char *pool_err,
   4262     int err_size)
   4263 {
   4264 	pool_conf_t *poolconf;
   4265 	pool_t *pool;
   4266 	char poolname[MAXPATHLEN];
   4267 	int status;
   4268 	int error;
   4269 
   4270 	/*
   4271 	 * Find the pool mentioned in the zone configuration, and bind to it.
   4272 	 */
   4273 	error = zonecfg_get_pool(handle, poolname, sizeof (poolname));
   4274 	if (error == Z_NO_ENTRY || (error == Z_OK && strlen(poolname) == 0)) {
   4275 		/*
   4276 		 * The property is not set on the zone, so the pool
   4277 		 * should be bound to the default pool.  But that's
   4278 		 * already done by the kernel, so we can just return.
   4279 		 */
   4280 		return (Z_OK);
   4281 	}
   4282 	if (error != Z_OK) {
   4283 		/*
   4284 		 * Not an error, even though it shouldn't be happening.
   4285 		 */
   4286 		return (Z_OK);
   4287 	}
   4288 	/*
   4289 	 * Don't do anything if pools aren't enabled.
   4290 	 */
   4291 	if (pool_get_status(&status) != PO_SUCCESS || status != POOL_ENABLED)
   4292 		return (Z_POOLS_NOT_ACTIVE);
   4293 
   4294 	/*
   4295 	 * Try to provide a sane error message if the requested pool doesn't
   4296 	 * exist.
   4297 	 */
   4298 	if ((poolconf = pool_conf_alloc()) == NULL)
   4299 		return (zerr_pool(pool_err, err_size, Z_POOL));
   4300 
   4301 	if (pool_conf_open(poolconf, pool_dynamic_location(), PO_RDONLY) !=
   4302 	    PO_SUCCESS) {
   4303 		pool_conf_free(poolconf);
   4304 		return (zerr_pool(pool_err, err_size, Z_POOL));
   4305 	}
   4306 	pool = pool_get_pool(poolconf, poolname);
   4307 	(void) pool_conf_close(poolconf);
   4308 	pool_conf_free(poolconf);
   4309 	if (pool == NULL)
   4310 		return (Z_NO_POOL);
   4311 
   4312 	/*
   4313 	 * Bind the zone to the pool.
   4314 	 */
   4315 	if (pool_set_binding(poolname, P_ZONEID, zoneid) != PO_SUCCESS) {
   4316 		/* if bind fails, return poolname for the error msg */
   4317 		(void) strlcpy(pool_err, poolname, err_size);
   4318 		return (Z_POOL_BIND);
   4319 	}
   4320 
   4321 	return (Z_OK);
   4322 }
   4323 
   4324 
   4325 static boolean_t
   4326 svc_enabled(char *svc_name)
   4327 {
   4328 	scf_simple_prop_t	*prop;
   4329 	boolean_t		found = B_FALSE;
   4330 
   4331 	prop = scf_simple_prop_get(NULL, svc_name, SCF_PG_GENERAL,
   4332 	    SCF_PROPERTY_ENABLED);
   4333 
   4334 	if (scf_simple_prop_numvalues(prop) == 1 &&
   4335 	    *scf_simple_prop_next_boolean(prop) != 0)
   4336 		found = B_TRUE;
   4337 
   4338 	scf_simple_prop_free(prop);
   4339 
   4340 	return (found);
   4341 }
   4342 
   4343 /*
   4344  * If the zone has capped-memory, make sure the rcap service is enabled.
   4345  */
   4346 int
   4347 zonecfg_enable_rcapd(char *err, int size)
   4348 {
   4349 	if (!svc_enabled(RCAP_SERVICE) &&
   4350 	    smf_enable_instance(RCAP_SERVICE, 0) == -1) {
   4351 		(void) strlcpy(err, scf_strerror(scf_error()), size);
   4352 		return (Z_SYSTEM);
   4353 	}
   4354 
   4355 	return (Z_OK);
   4356 }
   4357 
   4358 /*
   4359  * Return true if pset has cpu range specified and poold is not enabled.
   4360  */
   4361 boolean_t
   4362 zonecfg_warn_poold(zone_dochandle_t handle)
   4363 {
   4364 	struct zone_psettab pset_tab;
   4365 	int min, max;
   4366 	int err;
   4367 
   4368 	err = zonecfg_lookup_pset(handle, &pset_tab);
   4369 
   4370 	/* if no temporary pool configured, we're done */
   4371 	if (err == Z_NO_ENTRY)
   4372 		return (B_FALSE);
   4373 
   4374 	min = atoi(pset_tab.zone_ncpu_min);
   4375 	max = atoi(pset_tab.zone_ncpu_max);
   4376 
   4377 	/* range not specified, no need for poold */
   4378 	if (min == max)
   4379 		return (B_FALSE);
   4380 
   4381 	/* we have a range, check if poold service is enabled */
   4382 	if (svc_enabled(POOLD_SERVICE))
   4383 		return (B_FALSE);
   4384 
   4385 	return (B_TRUE);
   4386 }
   4387 
   4388 /*
   4389  * Retrieve the specified pool's thread scheduling class.  'poolname' must
   4390  * refer to the name of a configured resource pool.  The thread scheduling
   4391  * class specified by the pool will be stored in the buffer to which 'class'
   4392  * points.  'clsize' is the byte size of the buffer to which 'class' points.
   4393  *
   4394  * This function returns Z_OK if it successfully stored the specified pool's
   4395  * thread scheduling class into the buffer to which 'class' points.  It returns
   4396  * Z_NO_POOL if resource pools are not enabled, the function is unable to
   4397  * access the system's resource pools configuration, or the specified pool
   4398  * does not exist.  The function returns Z_TOO_BIG if the buffer to which
   4399  * 'class' points is not large enough to contain the thread scheduling class'
   4400  * name.  The function returns Z_NO_ENTRY if the pool does not specify a thread
   4401  * scheduling class.
   4402  */
   4403 static int
   4404 get_pool_sched_class(char *poolname, char *class, int clsize)
   4405 {
   4406 	int status;
   4407 	pool_conf_t *poolconf;
   4408 	pool_t *pool;
   4409 	pool_elem_t *pe;
   4410 	pool_value_t *pv = pool_value_alloc();
   4411 	const char *sched_str;
   4412 
   4413 	if (pool_get_status(&status) != PO_SUCCESS || status != POOL_ENABLED)
   4414 		return (Z_NO_POOL);
   4415 
   4416 	if ((poolconf = pool_conf_alloc()) == NULL)
   4417 		return (Z_NO_POOL);
   4418 
   4419 	if (pool_conf_open(poolconf, pool_dynamic_location(), PO_RDONLY) !=
   4420 	    PO_SUCCESS) {
   4421 		pool_conf_free(poolconf);
   4422 		return (Z_NO_POOL);
   4423 	}
   4424 
   4425 	if ((pool = pool_get_pool(poolconf, poolname)) == NULL) {
   4426 		(void) pool_conf_close(poolconf);
   4427 		pool_conf_free(poolconf);
   4428 		return (Z_NO_POOL);
   4429 	}
   4430 
   4431 	pe = pool_to_elem(poolconf, pool);
   4432 	if (pool_get_property(poolconf, pe, "pool.scheduler", pv) !=
   4433 	    POC_STRING) {
   4434 		(void) pool_conf_close(poolconf);
   4435 		pool_conf_free(poolconf);
   4436 		return (Z_NO_ENTRY);
   4437 	}
   4438 	(void) pool_value_get_string(pv, &sched_str);
   4439 	(void) pool_conf_close(poolconf);
   4440 	pool_conf_free(poolconf);
   4441 	if (strlcpy(class, sched_str, clsize) >= clsize)
   4442 		return (Z_TOO_BIG);
   4443 	return (Z_OK);
   4444 }
   4445 
   4446 /*
   4447  * Get the default scheduling class for the zone.  This will either be the
   4448  * class set on the zone's pool or the system default scheduling class.
   4449  */
   4450 int
   4451 zonecfg_get_dflt_sched_class(zone_dochandle_t handle, char *class, int clsize)
   4452 {
   4453 	char poolname[MAXPATHLEN];
   4454 
   4455 	if (zonecfg_get_pool(handle, poolname, sizeof (poolname)) == Z_OK) {
   4456 		/* check if the zone's pool specified a sched class */
   4457 		if (get_pool_sched_class(poolname, class, clsize) == Z_OK)
   4458 			return (Z_OK);
   4459 	}
   4460 
   4461 	if (priocntl(0, 0, PC_GETDFLCL, class, (uint64_t)clsize) == -1)
   4462 		return (Z_TOO_BIG);
   4463 
   4464 	return (Z_OK);
   4465 }
   4466 
   4467 int
   4468 zonecfg_setfsent(zone_dochandle_t handle)
   4469 {
   4470 	return (zonecfg_setent(handle));
   4471 }
   4472 
   4473 int
   4474 zonecfg_getfsent(zone_dochandle_t handle, struct zone_fstab *tabptr)
   4475 {
   4476 	xmlNodePtr cur, options;
   4477 	char options_str[MAX_MNTOPT_STR];
   4478 	int err;
   4479 
   4480 	if (handle == NULL)
   4481 		return (Z_INVAL);
   4482 
   4483 	if ((cur = handle->zone_dh_cur) == NULL)
   4484 		return (Z_NO_ENTRY);
   4485 
   4486 	for (; cur != NULL; cur = cur->next)
   4487 		if (!xmlStrcmp(cur->name, DTD_ELEM_FS))
   4488 			break;
   4489 	if (cur == NULL) {
   4490 		handle->zone_dh_cur = handle->zone_dh_top;
   4491 		return (Z_NO_ENTRY);
   4492 	}
   4493 
   4494 	if ((err = fetchprop(cur, DTD_ATTR_SPECIAL, tabptr->zone_fs_special,
   4495 	    sizeof (tabptr->zone_fs_special))) != Z_OK) {
   4496 		handle->zone_dh_cur = handle->zone_dh_top;
   4497 		return (err);
   4498 	}
   4499 
   4500 	if ((err = fetchprop(cur, DTD_ATTR_RAW, tabptr->zone_fs_raw,
   4501 	    sizeof (tabptr->zone_fs_raw))) != Z_OK) {
   4502 		handle->zone_dh_cur = handle->zone_dh_top;
   4503 		return (err);
   4504 	}
   4505 
   4506 	if ((err = fetchprop(cur, DTD_ATTR_DIR, tabptr->zone_fs_dir,
   4507 	    sizeof (tabptr->zone_fs_dir))) != Z_OK) {
   4508 		handle->zone_dh_cur = handle->zone_dh_top;
   4509 		return (err);
   4510 	}
   4511 
   4512 	if ((err = fetchprop(cur, DTD_ATTR_TYPE, tabptr->zone_fs_type,
   4513 	    sizeof (tabptr->zone_fs_type))) != Z_OK) {
   4514 		handle->zone_dh_cur = handle->zone_dh_top;
   4515 		return (err);
   4516 	}
   4517 
   4518 	/* OK for options to be NULL */
   4519 	tabptr->zone_fs_options = NULL;
   4520 	for (options = cur->xmlChildrenNode; options != NULL;
   4521 	    options = options->next) {
   4522 		if (fetchprop(options, DTD_ATTR_NAME, options_str,
   4523 		    sizeof (options_str)) != Z_OK)
   4524 			break;
   4525 		if (zonecfg_add_fs_option(tabptr, options_str) != Z_OK)
   4526 			break;
   4527 	}
   4528 
   4529 	handle->zone_dh_cur = cur->next;
   4530 	return (Z_OK);
   4531 }
   4532 
   4533 int
   4534 zonecfg_endfsent(zone_dochandle_t handle)
   4535 {
   4536 	return (zonecfg_endent(handle));
   4537 }
   4538 
   4539 int
   4540 zonecfg_setipdent(zone_dochandle_t handle)
   4541 {
   4542 	return (zonecfg_setent(handle));
   4543 }
   4544 
   4545 int
   4546 zonecfg_getipdent(zone_dochandle_t handle, struct zone_fstab *tabptr)
   4547 {
   4548 	xmlNodePtr cur;
   4549 	int err;
   4550 
   4551 	if (handle == NULL)
   4552 		return (Z_INVAL);
   4553 
   4554 	if ((cur = handle->zone_dh_cur) == NULL)
   4555 		return (Z_NO_ENTRY);
   4556 
   4557 	for (; cur != NULL; cur = cur->next)
   4558 		if (!xmlStrcmp(cur->name, DTD_ELEM_IPD))
   4559 			break;
   4560 	if (cur == NULL) {
   4561 		handle->zone_dh_cur = handle->zone_dh_top;
   4562 		return (Z_NO_ENTRY);
   4563 	}
   4564 
   4565 	if ((err = fetchprop(cur, DTD_ATTR_DIR, tabptr->zone_fs_dir,
   4566 	    sizeof (tabptr->zone_fs_dir))) != Z_OK) {
   4567 		handle->zone_dh_cur = handle->zone_dh_top;
   4568 		return (err);
   4569 	}
   4570 
   4571 	handle->zone_dh_cur = cur->next;
   4572 	return (Z_OK);
   4573 }
   4574 
   4575 int
   4576 zonecfg_endipdent(zone_dochandle_t handle)
   4577 {
   4578 	return (zonecfg_endent(handle));
   4579 }
   4580 
   4581 int
   4582 zonecfg_setnwifent(zone_dochandle_t handle)
   4583 {
   4584 	return (zonecfg_setent(handle));
   4585 }
   4586 
   4587 int
   4588 zonecfg_getnwifent(zone_dochandle_t handle, struct zone_nwiftab *tabptr)
   4589 {
   4590 	xmlNodePtr cur;
   4591 	int err;
   4592 
   4593 	if (handle == NULL)
   4594 		return (Z_INVAL);
   4595 
   4596 	if ((cur = handle->zone_dh_cur) == NULL)
   4597 		return (Z_NO_ENTRY);
   4598 
   4599 	for (; cur != NULL; cur = cur->next)
   4600 		if (!xmlStrcmp(cur->name, DTD_ELEM_NET))
   4601 			break;
   4602 	if (cur == NULL) {
   4603 		handle->zone_dh_cur = handle->zone_dh_top;
   4604 		return (Z_NO_ENTRY);
   4605 	}
   4606 
   4607 	if ((err = fetchprop(cur, DTD_ATTR_ADDRESS, tabptr->zone_nwif_address,
   4608 	    sizeof (tabptr->zone_nwif_address))) != Z_OK) {
   4609 		handle->zone_dh_cur = handle->zone_dh_top;
   4610 		return (err);
   4611 	}
   4612 
   4613 	if ((err = fetchprop(cur, DTD_ATTR_PHYSICAL, tabptr->zone_nwif_physical,
   4614 	    sizeof (tabptr->zone_nwif_physical))) != Z_OK) {
   4615 		handle->zone_dh_cur = handle->zone_dh_top;
   4616 		return (err);
   4617 	}
   4618 
   4619 	if ((err = fetchprop(cur, DTD_ATTR_DEFROUTER,
   4620 	    tabptr->zone_nwif_defrouter,
   4621 	    sizeof (tabptr->zone_nwif_defrouter))) != Z_OK) {
   4622 		handle->zone_dh_cur = handle->zone_dh_top;
   4623 		return (err);
   4624 	}
   4625 
   4626 	handle->zone_dh_cur = cur->next;
   4627 	return (Z_OK);
   4628 }
   4629 
   4630 int
   4631 zonecfg_endnwifent(zone_dochandle_t handle)
   4632 {
   4633 	return (zonecfg_endent(handle));
   4634 }
   4635 
   4636 int
   4637 zonecfg_setdevent(zone_dochandle_t handle)
   4638 {
   4639 	return (zonecfg_setent(handle));
   4640 }
   4641 
   4642 int
   4643 zonecfg_getdevent(zone_dochandle_t handle, struct zone_devtab *tabptr)
   4644 {
   4645 	xmlNodePtr cur;
   4646 	int err;
   4647 
   4648 	if (handle == NULL)
   4649 		return (Z_INVAL);
   4650 
   4651 	if ((cur = handle->zone_dh_cur) == NULL)
   4652 		return (Z_NO_ENTRY);
   4653 
   4654 	for (; cur != NULL; cur = cur->next)
   4655 		if (!xmlStrcmp(cur->name, DTD_ELEM_DEVICE))
   4656 			break;
   4657 	if (cur == NULL) {
   4658 		handle->zone_dh_cur = handle->zone_dh_top;
   4659 		return (Z_NO_ENTRY);
   4660 	}
   4661 
   4662 	if ((err = fetchprop(cur, DTD_ATTR_MATCH, tabptr->zone_dev_match,
   4663 	    sizeof (tabptr->zone_dev_match))) != Z_OK) {
   4664 		handle->zone_dh_cur = handle->zone_dh_top;
   4665 		return (err);
   4666 	}
   4667 
   4668 	handle->zone_dh_cur = cur->next;
   4669 	return (Z_OK);
   4670 }
   4671 
   4672 int
   4673 zonecfg_enddevent(zone_dochandle_t handle)
   4674 {
   4675 	return (zonecfg_endent(handle));
   4676 }
   4677 
   4678 int
   4679 zonecfg_setrctlent(zone_dochandle_t handle)
   4680 {
   4681 	return (zonecfg_setent(handle));
   4682 }
   4683 
   4684 int
   4685 zonecfg_getrctlent(zone_dochandle_t handle, struct zone_rctltab *tabptr)
   4686 {
   4687 	xmlNodePtr cur, val;
   4688 	struct zone_rctlvaltab *valptr;
   4689 	int err;
   4690 
   4691 	if (handle == NULL)
   4692 		return (Z_INVAL);
   4693 
   4694 	if ((cur = handle->zone_dh_cur) == NULL)
   4695 		return (Z_NO_ENTRY);
   4696 
   4697 	for (; cur != NULL; cur = cur->next)
   4698 		if (!xmlStrcmp(cur->name, DTD_ELEM_RCTL))
   4699 			break;
   4700 	if (cur == NULL) {
   4701 		handle->zone_dh_cur = handle->zone_dh_top;
   4702 		return (Z_NO_ENTRY);
   4703 	}
   4704 
   4705 	if ((err = fetchprop(cur, DTD_ATTR_NAME, tabptr->zone_rctl_name,
   4706 	    sizeof (tabptr->zone_rctl_name))) != Z_OK) {
   4707 		handle->zone_dh_cur = handle->zone_dh_top;
   4708 		return (err);
   4709 	}
   4710 
   4711 	tabptr->zone_rctl_valptr = NULL;
   4712 	for (val = cur->xmlChildrenNode; val != NULL; val = val->next) {
   4713 		valptr = (struct zone_rctlvaltab *)malloc(
   4714 		    sizeof (struct zone_rctlvaltab));
   4715 		if (valptr == NULL)
   4716 			return (Z_NOMEM);
   4717 		if (fetchprop(val, DTD_ATTR_PRIV, valptr->zone_rctlval_priv,
   4718 		    sizeof (valptr->zone_rctlval_priv)) != Z_OK)
   4719 			break;
   4720 		if (fetchprop(val, DTD_ATTR_LIMIT, valptr->zone_rctlval_limit,
   4721 		    sizeof (valptr->zone_rctlval_limit)) != Z_OK)
   4722 			break;
   4723 		if (fetchprop(val, DTD_ATTR_ACTION, valptr->zone_rctlval_action,
   4724 		    sizeof (valptr->zone_rctlval_action)) != Z_OK)
   4725 			break;
   4726 		if (zonecfg_add_rctl_value(tabptr, valptr) != Z_OK)
   4727 			break;
   4728 	}
   4729 
   4730 	handle->zone_dh_cur = cur->next;
   4731 	return (Z_OK);
   4732 }
   4733 
   4734 int
   4735 zonecfg_endrctlent(zone_dochandle_t handle)
   4736 {
   4737 	return (zonecfg_endent(handle));
   4738 }
   4739 
   4740 int
   4741 zonecfg_setattrent(zone_dochandle_t handle)
   4742 {
   4743 	return (zonecfg_setent(handle));
   4744 }
   4745 
   4746 int
   4747 zonecfg_getattrent(zone_dochandle_t handle, struct zone_attrtab *tabptr)
   4748 {
   4749 	xmlNodePtr cur;
   4750 	int err;
   4751 
   4752 	if (handle == NULL)
   4753 		return (Z_INVAL);
   4754 
   4755 	if ((cur = handle->zone_dh_cur) == NULL)
   4756 		return (Z_NO_ENTRY);
   4757 
   4758 	for (; cur != NULL; cur = cur->next)
   4759 		if (!xmlStrcmp(cur->name, DTD_ELEM_ATTR))
   4760 			break;
   4761 	if (cur == NULL) {
   4762 		handle->zone_dh_cur = handle->zone_dh_top;
   4763 		return (Z_NO_ENTRY);
   4764 	}
   4765 
   4766 	if ((err = fetchprop(cur, DTD_ATTR_NAME, tabptr->zone_attr_name,
   4767 	    sizeof (tabptr->zone_attr_name))) != Z_OK) {
   4768 		handle->zone_dh_cur = handle->zone_dh_top;
   4769 		return (err);
   4770 	}
   4771 
   4772 	if ((err = fetchprop(cur, DTD_ATTR_TYPE, tabptr->zone_attr_type,
   4773 	    sizeof (tabptr->zone_attr_type))) != Z_OK) {
   4774 		handle->zone_dh_cur = handle->zone_dh_top;
   4775 		return (err);
   4776 	}
   4777 
   4778 	if ((err = fetchprop(cur, DTD_ATTR_VALUE, tabptr->zone_attr_value,
   4779 	    sizeof (tabptr->zone_attr_value))) != Z_OK) {
   4780 		handle->zone_dh_cur = handle->zone_dh_top;
   4781 		return (err);
   4782 	}
   4783 
   4784 	handle->zone_dh_cur = cur->next;
   4785 	return (Z_OK);
   4786 }
   4787 
   4788 int
   4789 zonecfg_endattrent(zone_dochandle_t handle)
   4790 {
   4791 	return (zonecfg_endent(handle));
   4792 }
   4793 
   4794 /*
   4795  * The privileges available on the system and described in privileges(5)
   4796  * fall into four categories with respect to non-global zones:
   4797  *
   4798  *      Default set of privileges considered safe for all non-global
   4799  *      zones.  These privileges are "safe" in the sense that a
   4800  *      privileged process in the zone cannot affect processes in any
   4801  *      other zone on the system.
   4802  *
   4803  *      Set of privileges not currently permitted within a non-global
   4804  *      zone.  These privileges are considered by default, "unsafe,"
   4805  *      and include ones which affect global resources (such as the
   4806  *      system clock or physical memory) or are overly broad and cover
   4807  *      more than one mechanism in the system.  In other cases, there
   4808  *      has not been sufficient virtualization in the parts of the
   4809  *      system the privilege covers to allow its use within a
   4810  *      non-global zone.
   4811  *
   4812  *      Set of privileges required in order to get a zone booted and
   4813  *      init(1M) started.  These cannot be removed from the zone's
   4814  *      privilege set.
   4815  *
   4816  * All other privileges are optional and are potentially useful for
   4817  * processes executing inside a non-global zone.
   4818  *
   4819  * When privileges are added to the system, a determination needs to be
   4820  * made as to which category the privilege belongs to.  Ideally,
   4821  * privileges should be fine-grained enough and the mechanisms they cover
   4822  * virtualized enough so that they can be made available to non-global
   4823  * zones.
   4824  */
   4825 
   4826 /*
   4827  * Define some of the tokens that priv_str_to_set(3C) recognizes.  Since
   4828  * the privilege string separator can be any character, although it is
   4829  * usually a comma character, define these here as well in the event that
   4830  * they change or are augmented in the future.
   4831  */
   4832 #define	BASIC_TOKEN		"basic"
   4833 #define	DEFAULT_TOKEN		"default"
   4834 #define	ZONE_TOKEN		"zone"
   4835 #define	TOKEN_PRIV_CHAR		','
   4836 #define	TOKEN_PRIV_STR		","
   4837 
   4838 typedef struct priv_node {
   4839 	struct priv_node	*pn_next;	/* Next privilege */
   4840 	char			*pn_priv;	/* Privileges name */
   4841 } priv_node_t;
   4842 
   4843 /* Privileges lists can differ across brands */
   4844 typedef struct priv_lists {
   4845 	/* Privileges considered safe for all non-global zones of a brand */
   4846 	struct priv_node	*pl_default;
   4847 
   4848 	/* Privileges not permitted for all non-global zones of a brand */
   4849 	struct priv_node	*pl_prohibited;
   4850 
   4851 	/* Privileges required for all non-global zones of a brand */
   4852 	struct priv_node	*pl_required;
   4853 
   4854 	/*
   4855 	 * ip-type of the zone these privileges lists apply to.
   4856 	 * It is used to pass ip-type to the callback function,
   4857 	 * priv_lists_cb, which has no way of getting the ip-type.
   4858 	 */
   4859 	const char		*pl_iptype;
   4860 } priv_lists_t;
   4861 
   4862 static int
   4863 priv_lists_cb(void *data, priv_iter_t *priv_iter)
   4864 {
   4865 	priv_lists_t *plp = (priv_lists_t *)data;
   4866 	priv_node_t *pnp;
   4867 
   4868 	/* Skip this privilege if ip-type does not match */
   4869 	if ((strcmp(priv_iter->pi_iptype, "all") != 0) &&
   4870 	    (strcmp(priv_iter->pi_iptype, plp->pl_iptype) != 0))
   4871 		return (0);
   4872 
   4873 	/* Allocate a new priv list node. */
   4874 	if ((pnp = malloc(sizeof (*pnp))) == NULL)
   4875 		return (-1);
   4876 	if ((pnp->pn_priv = strdup(priv_iter->pi_name)) == NULL) {
   4877 		free(pnp);
   4878 		return (-1);
   4879 	}
   4880 
   4881 	/* Insert the new priv list node into the right list */
   4882 	if (strcmp(priv_iter->pi_set, "default") == 0) {
   4883 		pnp->pn_next = plp->pl_default;
   4884 		plp->pl_default = pnp;
   4885 	} else if (strcmp(priv_iter->pi_set, "prohibited") == 0) {
   4886 		pnp->pn_next = plp->pl_prohibited;
   4887 		plp->pl_prohibited = pnp;
   4888 	} else if (strcmp(priv_iter->pi_set, "required") == 0) {
   4889 		pnp->pn_next = plp->pl_required;
   4890 		plp->pl_required = pnp;
   4891 	} else {
   4892 		free(pnp->pn_priv);
   4893 		free(pnp);
   4894 		return (-1);
   4895 	}
   4896 	return (0);
   4897 }
   4898 
   4899 static void
   4900 priv_lists_destroy(priv_lists_t *plp)
   4901 {
   4902 	priv_node_t *pnp;
   4903 
   4904 	assert(plp != NULL);
   4905 
   4906 	while ((pnp = plp->pl_default) != NULL) {
   4907 		plp->pl_default = pnp->pn_next;
   4908 		free(pnp->pn_priv);
   4909 		free(pnp);
   4910 	}
   4911 	while ((pnp = plp->pl_prohibited) != NULL) {
   4912 		plp->pl_prohibited = pnp->pn_next;
   4913 		free(pnp->pn_priv);
   4914 		free(pnp);
   4915 	}
   4916 	while ((pnp = plp->pl_required) != NULL) {
   4917 		plp->pl_required = pnp->pn_next;
   4918 		free(pnp->pn_priv);
   4919 		free(pnp);
   4920 	}
   4921 	free(plp);
   4922 }
   4923 
   4924 static int
   4925 priv_lists_create(zone_dochandle_t handle, char *brand, priv_lists_t **plpp,
   4926     const char *curr_iptype)
   4927 {
   4928 	priv_lists_t *plp;
   4929 	brand_handle_t bh;
   4930 	char brand_str[MAXNAMELEN];
   4931 
   4932 	/* handle or brand must be set, but never both */
   4933 	assert((handle != NULL) || (brand != NULL));
   4934 	assert((handle == NULL) || (brand == NULL));
   4935 
   4936 	if (handle != NULL) {
   4937 		brand = brand_str;
   4938 		if (zonecfg_get_brand(handle, brand, sizeof (brand_str)) != 0)
   4939 			return (Z_BRAND_ERROR);
   4940 	}
   4941 
   4942 	if ((bh = brand_open(brand)) == NULL)
   4943 		return (Z_BRAND_ERROR);
   4944 
   4945 	if ((plp = calloc(1, sizeof (priv_lists_t))) == NULL) {
   4946 		brand_close(bh);
   4947 		return (Z_NOMEM);
   4948 	}
   4949 
   4950 	plp->pl_iptype = curr_iptype;
   4951 
   4952 	/* construct the privilege lists */
   4953 	if (brand_config_iter_privilege(bh, priv_lists_cb, plp) != 0) {
   4954 		priv_lists_destroy(plp);
   4955 		brand_close(bh);
   4956 		return (Z_BRAND_ERROR);
   4957 	}
   4958 
   4959 	brand_close(bh);
   4960 	*plpp = plp;
   4961 	return (Z_OK);
   4962 }
   4963 
   4964 static int
   4965 get_default_privset(priv_set_t *privs, priv_lists_t *plp)
   4966 {
   4967 	priv_node_t *pnp;
   4968 	priv_set_t *basic;
   4969 
   4970 	basic = priv_str_to_set(BASIC_TOKEN, TOKEN_PRIV_STR, NULL);
   4971 	if (basic == NULL)
   4972 		return (errno == ENOMEM ? Z_NOMEM : Z_INVAL);
   4973 
   4974 	priv_union(basic, privs);
   4975 	priv_freeset(basic);
   4976 
   4977 	for (pnp = plp->pl_default; pnp != NULL; pnp = pnp->pn_next) {
   4978 		if (priv_addset(privs, pnp->pn_priv) != 0)
   4979 			return (Z_INVAL);
   4980 	}
   4981 
   4982 	return (Z_OK);
   4983 }
   4984 
   4985 int
   4986 zonecfg_default_brand(char *brand, size_t brandsize)
   4987 {
   4988 	zone_dochandle_t handle;
   4989 	int myzoneid = getzoneid();
   4990 	int ret;
   4991 
   4992 	/*
   4993 	 * If we're running within a zone, then the default brand is the
   4994 	 * current zone's brand.
   4995 	 */
   4996 	if (myzoneid != GLOBAL_ZONEID) {
   4997 		ret = zone_getattr(myzoneid, ZONE_ATTR_BRAND, brand, brandsize);
   4998 		if (ret < 0)
   4999 			return ((errno == EFAULT) ? Z_TOO_BIG : Z_INVAL);
   5000 		return (Z_OK);
   5001 	}
   5002 
   5003 	if ((handle = zonecfg_init_handle()) == NULL)
   5004 		return (Z_NOMEM);
   5005 	if ((ret = zonecfg_get_handle("SUNWdefault", handle)) == Z_OK) {
   5006 		ret = i_zonecfg_get_brand(handle, brand, brandsize, B_TRUE);
   5007 		zonecfg_fini_handle(handle);
   5008 		return (ret);
   5009 	}
   5010 	return (ret);
   5011 }
   5012 
   5013 int
   5014 zonecfg_default_privset(priv_set_t *privs, const char *curr_iptype)
   5015 {
   5016 	priv_lists_t *plp;
   5017 	char buf[MAXNAMELEN];
   5018 	int ret;
   5019 
   5020 	if ((ret = zonecfg_default_brand(buf, sizeof (buf))) != Z_OK)
   5021 		return (ret);
   5022 	if ((ret = priv_lists_create(NULL, buf, &plp, curr_iptype)) != Z_OK)
   5023 		return (ret);
   5024 	ret = get_default_privset(privs, plp);
   5025 	priv_lists_destroy(plp);
   5026 	return (ret);
   5027 }
   5028 
   5029 void
   5030 append_priv_token(char *priv, char *str, size_t strlen)
   5031 {
   5032 	if (*str != '\0')
   5033 		(void) strlcat(str, TOKEN_PRIV_STR, strlen);
   5034 	(void) strlcat(str, priv, strlen);
   5035 }
   5036 
   5037 /*
   5038  * Verify that the supplied string is a valid privilege limit set for a
   5039  * non-global zone.  This string must not only be acceptable to
   5040  * priv_str_to_set(3C) which parses it, but it also must resolve to a
   5041  * privilege set that includes certain required privileges and lacks
   5042  * certain prohibited privileges.
   5043  */
   5044 static int
   5045 verify_privset(char *privbuf, priv_set_t *privs, char **privname,
   5046     boolean_t add_default, priv_lists_t *plp)
   5047 {
   5048 	priv_node_t *pnp;
   5049 	char *tmp, *cp, *lasts;
   5050 	size_t len;
   5051 	priv_set_t *mergeset;
   5052 	const char *token;
   5053 
   5054 	/*
   5055 	 * The verification of the privilege string occurs in several
   5056 	 * phases.  In the first phase, the supplied string is scanned for
   5057 	 * the ZONE_TOKEN token which is not support as part of the
   5058 	 * "limitpriv" property.
   5059 	 *
   5060 	 * Duplicate the supplied privilege string since strtok_r(3C)
   5061 	 * tokenizes its input by null-terminating the tokens.
   5062 	 */
   5063 	if ((tmp = strdup(privbuf)) == NULL)
   5064 		return (Z_NOMEM);
   5065 	for (cp = strtok_r(tmp, TOKEN_PRIV_STR, &lasts); cp != NULL;
   5066 	    cp = strtok_r(NULL, TOKEN_PRIV_STR, &lasts)) {
   5067 		if (strcmp(cp, ZONE_TOKEN) == 0) {
   5068 			free(tmp);
   5069 			if ((*privname = strdup(ZONE_TOKEN)) == NULL)
   5070 				return (Z_NOMEM);
   5071 			else
   5072 				return (Z_PRIV_UNKNOWN);
   5073 		}
   5074 	}
   5075 	free(tmp);
   5076 
   5077 	if (add_default) {
   5078 		/*
   5079 		 * If DEFAULT_TOKEN was specified, a string needs to be
   5080 		 * built containing the privileges from the default, safe
   5081 		 * set along with those of the "limitpriv" property.
   5082 		 */
   5083 		len = strlen(privbuf) + sizeof (BASIC_TOKEN) + 2;
   5084 
   5085 		for (pnp = plp->pl_default; pnp != NULL; pnp = pnp->pn_next)
   5086 			len += strlen(pnp->pn_priv) + 1;
   5087 		tmp = alloca(len);
   5088 		*tmp = '\0';
   5089 
   5090 		append_priv_token(BASIC_TOKEN, tmp, len);
   5091 		for (pnp = plp->pl_default; pnp != NULL; pnp = pnp->pn_next)
   5092 			append_priv_token(pnp->pn_priv, tmp, len);
   5093 		(void) strlcat(tmp, TOKEN_PRIV_STR, len);
   5094 		(void) strlcat(tmp, privbuf, len);
   5095 	} else {
   5096 		tmp = privbuf;
   5097 	}
   5098 
   5099 
   5100 	/*
   5101 	 * In the next phase, attempt to convert the merged privilege
   5102 	 * string into a privilege set.  In the case of an error, either
   5103 	 * there was a memory allocation failure or there was an invalid
   5104 	 * privilege token in the string.  In either case, return an
   5105 	 * appropriate error code but in the event of an invalid token,
   5106 	 * allocate a string containing its name and return that back to
   5107 	 * the caller.
   5108 	 */
   5109 	mergeset = priv_str_to_set(tmp, TOKEN_PRIV_STR, &token);
   5110 	if (mergeset == NULL) {
   5111 		if (token == NULL)
   5112 			return (Z_NOMEM);
   5113 		if ((cp = strchr(token, TOKEN_PRIV_CHAR)) != NULL)
   5114 			*cp = '\0';
   5115 		if ((*privname = strdup(token)) == NULL)
   5116 			return (Z_NOMEM);
   5117 		else
   5118 			return (Z_PRIV_UNKNOWN);
   5119 	}
   5120 
   5121 	/*
   5122 	 * Next, verify that none of the prohibited zone privileges are
   5123 	 * present in the merged privilege set.
   5124 	 */
   5125 	for (pnp = plp->pl_prohibited; pnp != NULL; pnp = pnp->pn_next) {
   5126 		if (priv_ismember(mergeset, pnp->pn_priv)) {
   5127 			priv_freeset(mergeset);
   5128 			if ((*privname = strdup(pnp->pn_priv)) == NULL)
   5129 				return (Z_NOMEM);
   5130 			else
   5131 				return (Z_PRIV_PROHIBITED);
   5132 		}
   5133 	}
   5134 
   5135 	/*
   5136 	 * Finally, verify that all of the required zone privileges are
   5137 	 * present in the merged privilege set.
   5138 	 */
   5139 	for (pnp = plp->pl_required; pnp != NULL; pnp = pnp->pn_next) {
   5140 		if (!priv_ismember(mergeset, pnp->pn_priv)) {
   5141 			priv_freeset(mergeset);
   5142 			if ((*privname = strdup(pnp->pn_priv)) == NULL)
   5143 				return (Z_NOMEM);
   5144 			else
   5145 				return (Z_PRIV_REQUIRED);
   5146 		}
   5147 	}
   5148 
   5149 	priv_copyset(mergeset, privs);
   5150 	priv_freeset(mergeset);
   5151 	return (Z_OK);
   5152 }
   5153 
   5154 /*
   5155  * Fill in the supplied privilege set with either the default, safe set of
   5156  * privileges suitable for a non-global zone, or one based on the
   5157  * "limitpriv" property in the zone's configuration.
   5158  *
   5159  * In the event of an invalid privilege specification in the
   5160  * configuration, a string is allocated and returned containing the
   5161  * "privilege" causing the issue.  It is the caller's responsibility to
   5162  * free this memory when it is done with it.
   5163  */
   5164 int
   5165 zonecfg_get_privset(zone_dochandle_t handle, priv_set_t *privs,
   5166     char **privname)
   5167 {
   5168 	priv_lists_t *plp;
   5169 	char *cp, *limitpriv = NULL;
   5170 	int err, limitlen;
   5171 	zone_iptype_t iptype;
   5172 	const char *curr_iptype;
   5173 
   5174 	/*
   5175 	 * Attempt to lookup the "limitpriv" property.  If it does not
   5176 	 * exist or matches the string DEFAULT_TOKEN exactly, then the
   5177 	 * default, safe privilege set is returned.
   5178 	 */
   5179 	if ((err = zonecfg_get_limitpriv(handle, &limitpriv)) != Z_OK)
   5180 		return (err);
   5181 
   5182 	if ((err = zonecfg_get_iptype(handle, &iptype)) != Z_OK)
   5183 		return (err);
   5184 
   5185 	switch (iptype) {
   5186 	case ZS_SHARED:
   5187 		curr_iptype = "shared";
   5188 		break;
   5189 	case ZS_EXCLUSIVE:
   5190 		curr_iptype = "exclusive";
   5191 		break;
   5192 	}
   5193 
   5194 	if ((err = priv_lists_create(handle, NULL, &plp, curr_iptype)) != Z_OK)
   5195 		return (err);
   5196 
   5197 	limitlen = strlen(limitpriv);
   5198 	if (limitlen == 0 || strcmp(limitpriv, DEFAULT_TOKEN) == 0) {
   5199 		free(limitpriv);
   5200 		err = get_default_privset(privs, plp);
   5201 		priv_lists_destroy(plp);
   5202 		return (err);
   5203 	}
   5204 
   5205 	/*
   5206 	 * Check if the string DEFAULT_TOKEN is the first token in a list
   5207 	 * of privileges.
   5208 	 */
   5209 	cp = strchr(limitpriv, TOKEN_PRIV_CHAR);
   5210 	if (cp != NULL &&
   5211 	    strncmp(limitpriv, DEFAULT_TOKEN, cp - limitpriv) == 0)
   5212 		err = verify_privset(cp + 1, privs, privname, B_TRUE, plp);
   5213 	else
   5214 		err = verify_privset(limitpriv, privs, privname, B_FALSE, plp);
   5215 
   5216 	free(limitpriv);
   5217 	priv_lists_destroy(plp);
   5218 	return (err);
   5219 }
   5220 
   5221 int
   5222 zone_get_zonepath(char *zone_name, char *zonepath, size_t rp_sz)
   5223 {
   5224 	zone_dochandle_t handle;
   5225 	boolean_t found = B_FALSE;
   5226 	struct zoneent *ze;
   5227 	FILE *cookie;
   5228 	int err;
   5229 	char *cp;
   5230 
   5231 	if (zone_name == NULL)
   5232 		return (Z_INVAL);
   5233 
   5234 	(void) strlcpy(zonepath, zonecfg_root, rp_sz);
   5235 	cp = zonepath + strlen(zonepath);
   5236 	while (cp > zonepath && cp[-1] == '/')
   5237 		*--cp = '\0';
   5238 
   5239 	if (strcmp(zone_name, GLOBAL_ZONENAME) == 0) {
   5240 		if (zonepath[0] == '\0')
   5241 			(void) strlcpy(zonepath, "/", rp_sz);
   5242 		return (Z_OK);
   5243 	}
   5244 
   5245 	/*
   5246 	 * First check the index file.  Because older versions did not have
   5247 	 * a copy of the zone path, allow for it to be zero length, in which
   5248 	 * case we ignore this result and fall back to the XML files.
   5249 	 */
   5250 	cookie = setzoneent();
   5251 	while ((ze = getzoneent_private(cookie)) != NULL) {
   5252 		if (strcmp(ze->zone_name, zone_name) == 0) {
   5253 			found = B_TRUE;
   5254 			if (ze->zone_path[0] != '\0')
   5255 				(void) strlcpy(cp, ze->zone_path,
   5256 				    rp_sz - (cp - zonepath));
   5257 		}
   5258 		free(ze);
   5259 		if (found)
   5260 			break;
   5261 	}
   5262 	endzoneent(cookie);
   5263 	if (found && *cp != '\0')
   5264 		return (Z_OK);
   5265 
   5266 	/* Fall back to the XML files. */
   5267 	if ((handle = zonecfg_init_handle()) == NULL)
   5268 		return (Z_NOMEM);
   5269 
   5270 	/*
   5271 	 * Check the snapshot first: if a zone is running, its zonepath
   5272 	 * may have changed.
   5273 	 */
   5274 	if (zonecfg_get_snapshot_handle(zone_name, handle) != Z_OK) {
   5275 		if ((err = zonecfg_get_handle(zone_name, handle)) != Z_OK) {
   5276 			zonecfg_fini_handle(handle);
   5277 			return (err);
   5278 		}
   5279 	}
   5280 	err = zonecfg_get_zonepath(handle, zonepath, rp_sz);
   5281 	zonecfg_fini_handle(handle);
   5282 	return (err);
   5283 }
   5284 
   5285 int
   5286 zone_get_rootpath(char *zone_name, char *rootpath, size_t rp_sz)
   5287 {
   5288 	int err;
   5289 
   5290 	/* This function makes sense for non-global zones only. */
   5291 	if (strcmp(zone_name, GLOBAL_ZONENAME) == 0)
   5292 		return (Z_BOGUS_ZONE_NAME);
   5293 	if ((err = zone_get_zonepath(zone_name, rootpath, rp_sz)) != Z_OK)
   5294 		return (err);
   5295 	if (strlcat(rootpath, "/root", rp_sz) >= rp_sz)
   5296 		return (Z_TOO_BIG);
   5297 	return (Z_OK);
   5298 }
   5299 
   5300 int
   5301 zone_get_brand(char *zone_name, char *brandname, size_t rp_sz)
   5302 {
   5303 	int err;
   5304 	zone_dochandle_t handle;
   5305 	char myzone[MAXNAMELEN];
   5306 	int myzoneid = getzoneid();
   5307 
   5308 	/*
   5309 	 * If we are not in the global zone, then we don't have the zone
   5310 	 * .xml files with the brand name available.  Thus, we are going to
   5311 	 * have to ask the kernel for the information.
   5312 	 */
   5313 	if (myzoneid != GLOBAL_ZONEID) {
   5314 		if (is_system_labeled()) {
   5315 			(void) strlcpy(brandname, NATIVE_BRAND_NAME, rp_sz);
   5316 			return (Z_OK);
   5317 		}
   5318 		if (zone_getattr(myzoneid, ZONE_ATTR_NAME, myzone,
   5319 		    sizeof (myzone)) < 0)
   5320 			return (Z_NO_ZONE);
   5321 		if (!zonecfg_is_scratch(myzone)) {
   5322 			if (strncmp(zone_name, myzone, MAXNAMELEN) != 0)
   5323 				return (Z_NO_ZONE);
   5324 		}
   5325 		err = zone_getattr(myzoneid, ZONE_ATTR_BRAND, brandname, rp_sz);
   5326 		if (err < 0)
   5327 			return ((errno == EFAULT) ? Z_TOO_BIG : Z_INVAL);
   5328 
   5329 		return (Z_OK);
   5330 	}
   5331 
   5332 	if (strcmp(zone_name, "global") == 0)
   5333 		return (zonecfg_default_brand(brandname, rp_sz));
   5334 
   5335 	if ((handle = zonecfg_init_handle()) == NULL)
   5336 		return (Z_NOMEM);
   5337 
   5338 	err = zonecfg_get_handle((char *)zone_name, handle);
   5339 	if (err == Z_OK)
   5340 		err = zonecfg_get_brand(handle, brandname, rp_sz);
   5341 
   5342 	zonecfg_fini_handle(handle);
   5343 	return (err);
   5344 }
   5345 
   5346 /*
   5347  * Return the appropriate root for the active /dev.
   5348  * For normal zone, the path is $ZONEPATH/root;
   5349  * for scratch zone, the dev path is $ZONEPATH/lu.
   5350  */
   5351 int
   5352 zone_get_devroot(char *zone_name, char *devroot, size_t rp_sz)
   5353 {
   5354 	int err;
   5355 	char *suffix;
   5356 	zone_state_t state;
   5357 
   5358 	/* This function makes sense for non-global zones only. */
   5359 	if (strcmp(zone_name, GLOBAL_ZONENAME) == 0)
   5360 		return (Z_BOGUS_ZONE_NAME);
   5361 	if ((err = zone_get_zonepath(zone_name, devroot, rp_sz)) != Z_OK)
   5362 		return (err);
   5363 
   5364 	if (zone_get_state(zone_name, &state) == Z_OK &&
   5365 	    state == ZONE_STATE_MOUNTED)
   5366 		suffix = "/lu";
   5367 	else
   5368 		suffix = "/root";
   5369 	if (strlcat(devroot, suffix, rp_sz) >= rp_sz)
   5370 		return (Z_TOO_BIG);
   5371 	return (Z_OK);
   5372 }
   5373 
   5374 static zone_state_t
   5375 kernel_state_to_user_state(zoneid_t zoneid, zone_status_t kernel_state)
   5376 {
   5377 	char zoneroot[MAXPATHLEN];
   5378 	size_t zlen;
   5379 
   5380 	assert(kernel_state <= ZONE_MAX_STATE);
   5381 	switch (kernel_state) {
   5382 		case ZONE_IS_UNINITIALIZED:
   5383 		case ZONE_IS_INITIALIZED:
   5384 			/* The kernel will not return these two states */
   5385 			return (ZONE_STATE_READY);
   5386 		case ZONE_IS_READY:
   5387 			/*
   5388 			 * If the zone's root is mounted on $ZONEPATH/lu, then
   5389 			 * it's a mounted scratch zone.
   5390 			 */
   5391 			if (zone_getattr(zoneid, ZONE_ATTR_ROOT, zoneroot,
   5392 			    sizeof (zoneroot)) >= 0) {
   5393 				zlen = strlen(zoneroot);
   5394 				if (zlen > 3 &&
   5395 				    strcmp(zoneroot + zlen - 3, "/lu") == 0)
   5396 					return (ZONE_STATE_MOUNTED);
   5397 			}
   5398 			return (ZONE_STATE_READY);
   5399 		case ZONE_IS_BOOTING:
   5400 		case ZONE_IS_RUNNING:
   5401 			return (ZONE_STATE_RUNNING);
   5402 		case ZONE_IS_SHUTTING_DOWN:
   5403 		case ZONE_IS_EMPTY:
   5404 			return (ZONE_STATE_SHUTTING_DOWN);
   5405 		case ZONE_IS_DOWN:
   5406 		case ZONE_IS_DYING:
   5407 		case ZONE_IS_DEAD:
   5408 		default:
   5409 			return (ZONE_STATE_DOWN);
   5410 	}
   5411 	/* NOTREACHED */
   5412 }
   5413 
   5414 int
   5415 zone_get_state(char *zone_name, zone_state_t *state_num)
   5416 {
   5417 	zone_status_t status;
   5418 	zoneid_t zone_id;
   5419 	struct zoneent *ze;
   5420 	boolean_t found = B_FALSE;
   5421 	FILE *cookie;
   5422 	char kernzone[ZONENAME_MAX];
   5423 	FILE *fp;
   5424 
   5425 	if (zone_name == NULL)
   5426 		return (Z_INVAL);
   5427 
   5428 	/*
   5429 	 * If we're looking at an alternate root, then we need to query the
   5430 	 * kernel using the scratch zone name.
   5431 	 */
   5432 	zone_id = -1;
   5433 	if (*zonecfg_root != '\0' && !zonecfg_is_scratch(zone_name)) {
   5434 		if ((fp = zonecfg_open_scratch("", B_FALSE)) != NULL) {
   5435 			if (zonecfg_find_scratch(fp, zone_name, zonecfg_root,
   5436 			    kernzone, sizeof (kernzone)) == 0)
   5437 				zone_id = getzoneidbyname(kernzone);
   5438 			zonecfg_close_scratch(fp);
   5439 		}
   5440 	} else {
   5441 		zone_id = getzoneidbyname(zone_name);
   5442 	}
   5443 
   5444 	/* check to see if zone is running */
   5445 	if (zone_id != -1 &&
   5446 	    zone_getattr(zone_id, ZONE_ATTR_STATUS, &status,
   5447 	    sizeof (status)) >= 0) {
   5448 		*state_num = kernel_state_to_user_state(zone_id, status);
   5449 		return (Z_OK);
   5450 	}
   5451 
   5452 	cookie = setzoneent();
   5453 	while ((ze = getzoneent_private(cookie)) != NULL) {
   5454 		if (strcmp(ze->zone_name, zone_name) == 0) {
   5455 			found = B_TRUE;
   5456 			*state_num = ze->zone_state;
   5457 		}
   5458 		free(ze);
   5459 		if (found)
   5460 			break;
   5461 	}
   5462 	endzoneent(cookie);
   5463 	return ((found) ? Z_OK : Z_NO_ZONE);
   5464 }
   5465 
   5466 int
   5467 zone_set_state(char *zone, zone_state_t state)
   5468 {
   5469 	struct zoneent ze;
   5470 
   5471 	if (state != ZONE_STATE_CONFIGURED && state != ZONE_STATE_INSTALLED &&
   5472 	    state != ZONE_STATE_INCOMPLETE)
   5473 		return (Z_INVAL);
   5474 
   5475 	bzero(&ze, sizeof (ze));
   5476 	(void) strlcpy(ze.zone_name, zone, sizeof (ze.zone_name));
   5477 	ze.zone_state = state;
   5478 	(void) strlcpy(ze.zone_path, "", sizeof (ze.zone_path));
   5479 	return (putzoneent(&ze, PZE_MODIFY));
   5480 }
   5481 
   5482 /*
   5483  * Get id (if any) for specified zone.  There are four possible outcomes:
   5484  * - If the string corresponds to the numeric id of an active (booted)
   5485  *   zone, sets *zip to the zone id and returns 0.
   5486  * - If the string corresponds to the name of an active (booted) zone,
   5487  *   sets *zip to the zone id and returns 0.
   5488  * - If the string is a name in the configuration but is not booted,
   5489  *   sets *zip to ZONE_ID_UNDEFINED and returns 0.
   5490  * - Otherwise, leaves *zip unchanged and returns -1.
   5491  *
   5492  * This function acts as an auxiliary filter on the function of the same
   5493  * name in libc; the linker binds to this version if libzonecfg exists,
   5494  * and the libc version if it doesn't.  Any changes to this version of
   5495  * the function should probably be reflected in the libc version as well.
   5496  */
   5497 int
   5498 zone_get_id(const char *str, zoneid_t *zip)
   5499 {
   5500 	zone_dochandle_t hdl;
   5501 	zoneid_t zoneid;
   5502 	char *cp;
   5503 	int err;
   5504 
   5505 	/* first try looking for active zone by id */
   5506 	errno = 0;
   5507 	zoneid = (zoneid_t)strtol(str, &cp, 0);
   5508 	if (errno == 0 && cp != str && *cp == '\0' &&
   5509 	    getzonenamebyid(zoneid, NULL, 0) != -1) {
   5510 		*zip = zoneid;
   5511 		return (0);
   5512 	}
   5513 
   5514 	/* then look for active zone by name */
   5515 	if ((zoneid = getzoneidbyname(str)) != -1) {
   5516 		*zip = zoneid;
   5517 		return (0);
   5518 	}
   5519 
   5520 	/* if in global zone, try looking up name in configuration database */
   5521 	if (getzoneid() != GLOBAL_ZONEID ||
   5522 	    (hdl = zonecfg_init_handle()) == NULL)
   5523 		return (-1);
   5524 
   5525 	if (zonecfg_get_handle(str, hdl) == Z_OK) {
   5526 		/* zone exists but isn't active */
   5527 		*zip = ZONE_ID_UNDEFINED;
   5528 		err = 0;
   5529 	} else {
   5530 		err = -1;
   5531 	}
   5532 
   5533 	zonecfg_fini_handle(hdl);
   5534 	return (err);
   5535 }
   5536 
   5537 char *
   5538 zone_state_str(zone_state_t state_num)
   5539 {
   5540 	switch (state_num) {
   5541 	case ZONE_STATE_CONFIGURED:
   5542 		return (ZONE_STATE_STR_CONFIGURED);
   5543 	case ZONE_STATE_INCOMPLETE:
   5544 		return (ZONE_STATE_STR_INCOMPLETE);
   5545 	case ZONE_STATE_INSTALLED:
   5546 		return (ZONE_STATE_STR_INSTALLED);
   5547 	case ZONE_STATE_READY:
   5548 		return (ZONE_STATE_STR_READY);
   5549 	case ZONE_STATE_MOUNTED:
   5550 		return (ZONE_STATE_STR_MOUNTED);
   5551 	case ZONE_STATE_RUNNING:
   5552 		return (ZONE_STATE_STR_RUNNING);
   5553 	case ZONE_STATE_SHUTTING_DOWN:
   5554 		return (ZONE_STATE_STR_SHUTTING_DOWN);
   5555 	case ZONE_STATE_DOWN:
   5556 		return (ZONE_STATE_STR_DOWN);
   5557 	default:
   5558 		return ("unknown");
   5559 	}
   5560 }
   5561 
   5562 /*
   5563  * Given a UUID value, find an associated zone name.  This is intended to be
   5564  * used by callers who set up some 'default' name (corresponding to the
   5565  * expected name for the zone) in the zonename buffer, and thus the function
   5566  * doesn't touch this buffer on failure.
   5567  */
   5568 int
   5569 zonecfg_get_name_by_uuid(const uuid_t uuidin, char *zonename, size_t namelen)
   5570 {
   5571 	FILE *fp;
   5572 	struct zoneent *ze;
   5573 	uchar_t *uuid;
   5574 
   5575 	/*
   5576 	 * A small amount of subterfuge via casts is necessary here because
   5577 	 * libuuid doesn't use const correctly, but we don't want to export
   5578 	 * this brokenness to our clients.
   5579 	 */
   5580 	uuid = (uchar_t *)uuidin;
   5581 	if (uuid_is_null(uuid))
   5582 		return (Z_NO_ZONE);
   5583 	if ((fp = setzoneent()) == NULL)
   5584 		return (Z_NO_ZONE);
   5585 	while ((ze = getzoneent_private(fp)) != NULL) {
   5586 		if (uuid_compare(uuid, ze->zone_uuid) == 0)
   5587 			break;
   5588 		free(ze);
   5589 	}
   5590 	endzoneent(fp);
   5591 	if (ze != NULL) {
   5592 		(void) strlcpy(zonename, ze->zone_name, namelen);
   5593 		free(ze);
   5594 		return (Z_OK);
   5595 	} else {
   5596 		return (Z_NO_ZONE);
   5597 	}
   5598 }
   5599 
   5600 /*
   5601  * Given a zone name, get its UUID.  Returns a "NULL" UUID value if the zone
   5602  * exists but the file doesn't have a value set yet.  Returns an error if the
   5603  * zone cannot be located.
   5604  */
   5605 int
   5606 zonecfg_get_uuid(const char *zonename, uuid_t uuid)
   5607 {
   5608 	FILE *fp;
   5609 	struct zoneent *ze;
   5610 
   5611 	if ((fp = setzoneent()) == NULL)
   5612 		return (Z_NO_ZONE);
   5613 	while ((ze = getzoneent_private(fp)) != NULL) {
   5614 		if (strcmp(ze->zone_name, zonename) == 0)
   5615 			break;
   5616 		free(ze);
   5617 	}
   5618 	endzoneent(fp);
   5619 	if (ze != NULL) {
   5620 		uuid_copy(uuid, ze->zone_uuid);
   5621 		free(ze);
   5622 		return (Z_OK);
   5623 	} else {
   5624 		return (Z_NO_ZONE);
   5625 	}
   5626 }
   5627 
   5628 /*
   5629  * File-system convenience functions.
   5630  */
   5631 boolean_t
   5632 zonecfg_valid_fs_type(const char *type)
   5633 {
   5634 	/*
   5635 	 * We already know which FS types don't work.
   5636 	 */
   5637 	if (strcmp(type, "proc") == 0 ||
   5638 	    strcmp(type, "mntfs") == 0 ||
   5639 	    strcmp(type, "autofs") == 0 ||
   5640 	    strncmp(type, "nfs", sizeof ("nfs") - 1) == 0 ||
   5641 	    strcmp(type, "cachefs") == 0)
   5642 		return (B_FALSE);
   5643 	/*
   5644 	 * The caller may do more detailed verification to make sure other
   5645 	 * aspects of this filesystem type make sense.
   5646 	 */
   5647 	return (B_TRUE);
   5648 }
   5649 
   5650 /*
   5651  * Generally uninteresting rctl convenience functions.
   5652  */
   5653 
   5654 int
   5655 zonecfg_construct_rctlblk(const struct zone_rctlvaltab *rctlval,
   5656     rctlblk_t *rctlblk)
   5657 {
   5658 	unsigned long long ull;
   5659 	char *endp;
   5660 	rctl_priv_t priv;
   5661 	rctl_qty_t limit;
   5662 	uint_t action;
   5663 
   5664 	/* Get the privilege */
   5665 	if (strcmp(rctlval->zone_rctlval_priv, "basic") == 0) {
   5666 		priv = RCPRIV_BASIC;
   5667 	} else if (strcmp(rctlval->zone_rctlval_priv, "privileged") == 0) {
   5668 		priv = RCPRIV_PRIVILEGED;
   5669 	} else {
   5670 		/* Invalid privilege */
   5671 		return (Z_INVAL);
   5672 	}
   5673 
   5674 	/* deal with negative input; strtoull(3c) doesn't do what we want */
   5675 	if (rctlval->zone_rctlval_limit[0] == '-')
   5676 		return (Z_INVAL);
   5677 	/* Get the limit */
   5678 	errno = 0;
   5679 	ull = strtoull(rctlval->zone_rctlval_limit, &endp, 0);
   5680 	if (errno != 0 || *endp != '\0') {
   5681 		/* parse failed */
   5682 		return (Z_INVAL);
   5683 	}
   5684 	limit = (rctl_qty_t)ull;
   5685 
   5686 	/* Get the action */
   5687 	if (strcmp(rctlval->zone_rctlval_action, "none") == 0) {
   5688 		action = RCTL_LOCAL_NOACTION;
   5689 	} else if (strcmp(rctlval->zone_rctlval_action, "signal") == 0) {
   5690 		action = RCTL_LOCAL_SIGNAL;
   5691 	} else if (strcmp(rctlval->zone_rctlval_action, "deny") == 0) {
   5692 		action = RCTL_LOCAL_DENY;
   5693 	} else {
   5694 		/* Invalid Action */
   5695 		return (Z_INVAL);
   5696 	}
   5697 	rctlblk_set_local_action(rctlblk, action, 0);
   5698 	rctlblk_set_privilege(rctlblk, priv);
   5699 	rctlblk_set_value(rctlblk, limit);
   5700 	return (Z_OK);
   5701 }
   5702 
   5703 static int
   5704 rctl_check(const char *rctlname, void *arg)
   5705 {
   5706 	const char *attrname = arg;
   5707 
   5708 	/*
   5709 	 * Returning 1 here is our signal to zonecfg_is_rctl() that it is
   5710 	 * indeed an rctl name recognized by the system.
   5711 	 */
   5712 	return (strcmp(rctlname, attrname) == 0 ? 1 : 0);
   5713 }
   5714 
   5715 boolean_t
   5716 zonecfg_is_rctl(const char *name)
   5717 {
   5718 	return (rctl_walk(rctl_check, (void *)name) == 1);
   5719 }
   5720 
   5721 boolean_t
   5722 zonecfg_valid_rctlname(const char *name)
   5723 {
   5724 	const char *c;
   5725 
   5726 	if (strncmp(name, "zone.", sizeof ("zone.") - 1) != 0)
   5727 		return (B_FALSE);
   5728 	if (strlen(name) == sizeof ("zone.") - 1)
   5729 		return (B_FALSE);
   5730 	for (c = name + sizeof ("zone.") - 1; *c != '\0'; c++) {
   5731 		if (!isalpha(*c) && *c != '-')
   5732 			return (B_FALSE);
   5733 	}
   5734 	return (B_TRUE);
   5735 }
   5736 
   5737 boolean_t
   5738 zonecfg_valid_rctlblk(const rctlblk_t *rctlblk)
   5739 {
   5740 	rctl_priv_t priv = rctlblk_get_privilege((rctlblk_t *)rctlblk);
   5741 	uint_t action = rctlblk_get_local_action((rctlblk_t *)rctlblk, NULL);
   5742 
   5743 	if (priv != RCPRIV_PRIVILEGED)
   5744 		return (B_FALSE);
   5745 	if (action != RCTL_LOCAL_NOACTION && action != RCTL_LOCAL_DENY)
   5746 		return (B_FALSE);
   5747 	return (B_TRUE);
   5748 }
   5749 
   5750 boolean_t
   5751 zonecfg_valid_rctl(const char *name, const rctlblk_t *rctlblk)
   5752 {
   5753 	rctlblk_t *current, *next;
   5754 	rctl_qty_t limit = rctlblk_get_value((rctlblk_t *)rctlblk);
   5755 	uint_t action = rctlblk_get_local_action((rctlblk_t *)rctlblk, NULL);
   5756 	uint_t global_flags;
   5757 
   5758 	if (!zonecfg_valid_rctlblk(rctlblk))
   5759 		return (B_FALSE);
   5760 	if (!zonecfg_valid_rctlname(name))
   5761 		return (B_FALSE);
   5762 
   5763 	current = alloca(rctlblk_size());
   5764 	if (getrctl(name, NULL, current, RCTL_FIRST) != 0)
   5765 		return (B_TRUE);	/* not an rctl on this system */
   5766 	/*
   5767 	 * Make sure the proposed value isn't greater than the current system
   5768 	 * value.
   5769 	 */
   5770 	next = alloca(rctlblk_size());
   5771 	while (rctlblk_get_privilege(current) != RCPRIV_SYSTEM) {
   5772 		rctlblk_t *tmp;
   5773 
   5774 		if (getrctl(name, current, next, RCTL_NEXT) != 0)
   5775 			return (B_FALSE);	/* shouldn't happen */
   5776 		tmp = current;
   5777 		current = next;
   5778 		next = tmp;
   5779 	}
   5780 	if (limit > rctlblk_get_value(current))
   5781 		return (B_FALSE);
   5782 
   5783 	/*
   5784 	 * Make sure the proposed action is allowed.
   5785 	 */
   5786 	global_flags = rctlblk_get_global_flags(current);
   5787 	if ((global_flags & RCTL_GLOBAL_DENY_NEVER) &&
   5788 	    action == RCTL_LOCAL_DENY)
   5789 		return (B_FALSE);
   5790 	if ((global_flags & RCTL_GLOBAL_DENY_ALWAYS) &&
   5791 	    action == RCTL_LOCAL_NOACTION)
   5792 		return (B_FALSE);
   5793 
   5794 	return (B_TRUE);
   5795 }
   5796 
   5797 /*
   5798  * There is always a race condition between reading the initial copy of
   5799  * a zones state and its state changing.  We address this by providing
   5800  * zonecfg_notify_critical_enter and zonecfg_noticy_critical_exit functions.
   5801  * When zonecfg_critical_enter is called, sets the state field to LOCKED
   5802  * and aquires biglock. Biglock protects against other threads executing
   5803  * critical_enter and the state field protects against state changes during
   5804  * the critical period.
   5805  *
   5806  * If any state changes occur, zn_cb will set the failed field of the znotify
   5807  * structure.  This will cause the critical_exit function to re-lock the
   5808  * channel and return an error. Since evsnts may be delayed, the critical_exit
   5809  * function "flushes" the queue by putting an event on the queue and waiting for
   5810  * zn_cb to notify critical_exit that it received the ping event.
   5811  */
   5812 static const char *
   5813 string_get_tok(const char *in, char delim, int num)
   5814 {
   5815 	int i = 0;
   5816 
   5817 	for (; i < num; in++) {
   5818 		if (*in == delim)
   5819 			i++;
   5820 		if (*in == 0)
   5821 			return (NULL);
   5822 	}
   5823 	return (in);
   5824 }
   5825 
   5826 static boolean_t
   5827 is_ping(sysevent_t *ev)
   5828 {
   5829 	if (strcmp(sysevent_get_subclass_name(ev),
   5830 	    ZONE_EVENT_PING_SUBCLASS) == 0) {
   5831 		return (B_TRUE);
   5832 	} else {
   5833 		return (B_FALSE);
   5834 	}
   5835 }
   5836 
   5837 static boolean_t
   5838 is_my_ping(sysevent_t *ev)
   5839 {
   5840 	const char *sender;
   5841 	char mypid[sizeof (pid_t) * 3 + 1];
   5842 
   5843 	(void) snprintf(mypid, sizeof (mypid), "%i", getpid());
   5844 	sender = string_get_tok(sysevent_get_pub(ev), ':', 3);
   5845 	if (sender == NULL)
   5846 		return (B_FALSE);
   5847 	if (strcmp(sender, mypid) != 0)
   5848 		return (B_FALSE);
   5849 	return (B_TRUE);
   5850 }
   5851 
   5852 static int
   5853 do_callback(struct znotify *zevtchan, sysevent_t *ev)
   5854 {
   5855 	nvlist_t *l;
   5856 	int zid;
   5857 	char *zonename;
   5858 	char *newstate;
   5859 	char *oldstate;
   5860 	int ret;
   5861 	hrtime_t when;
   5862 
   5863 	if (strcmp(sysevent_get_subclass_name(ev),
   5864 	    ZONE_EVENT_STATUS_SUBCLASS) == 0) {
   5865 
   5866 		if (sysevent_get_attr_list(ev, &l) != 0) {
   5867 			if (errno == ENOMEM) {
   5868 				zevtchan->zn_failure_count++;
   5869 				return (EAGAIN);
   5870 			}
   5871 			return (0);
   5872 		}
   5873 		ret = 0;
   5874 
   5875 		if ((nvlist_lookup_string(l, ZONE_CB_NAME, &zonename) == 0) &&
   5876 		    (nvlist_lookup_string(l, ZONE_CB_NEWSTATE, &newstate)
   5877 		    == 0) &&
   5878 		    (nvlist_lookup_string(l, ZONE_CB_OLDSTATE, &oldstate)
   5879 		    == 0) &&
   5880 		    (nvlist_lookup_uint64(l, ZONE_CB_TIMESTAMP,
   5881 		    (uint64_t *)&when) == 0) &&
   5882 		    (nvlist_lookup_int32(l, ZONE_CB_ZONEID, &zid) == 0)) {
   5883 			ret = zevtchan->zn_callback(zonename, zid, newstate,
   5884 			    oldstate, when, zevtchan->zn_private);
   5885 		}
   5886 
   5887 		zevtchan->zn_failure_count = 0;
   5888 		nvlist_free(l);
   5889 		return (ret);
   5890 	} else {
   5891 		/*
   5892 		 * We have received an event in an unknown subclass. Ignore.
   5893 		 */
   5894 		zevtchan->zn_failure_count = 0;
   5895 		return (0);
   5896 	}
   5897 }
   5898 
   5899 static int
   5900 zn_cb(sysevent_t *ev, void *p)
   5901 {
   5902 	struct znotify *zevtchan = p;
   5903 	int error;
   5904 
   5905 	(void) pthread_mutex_lock(&(zevtchan->zn_mutex));
   5906 
   5907 	if (is_ping(ev) && !is_my_ping(ev)) {
   5908 		(void) pthread_mutex_unlock((&zevtchan->zn_mutex));
   5909 		return (0);
   5910 	}
   5911 
   5912 	if (zevtchan->zn_state == ZN_LOCKED) {
   5913 		assert(!is_ping(ev));
   5914 		zevtchan->zn_failed = B_TRUE;
   5915 		(void) pthread_mutex_unlock(&(zevtchan->zn_mutex));
   5916 		return (0);
   5917 	}
   5918 
   5919 	if (zevtchan->zn_state == ZN_PING_INFLIGHT) {
   5920 		if (is_ping(ev)) {
   5921 			zevtchan->zn_state = ZN_PING_RECEIVED;
   5922 			(void) pthread_cond_signal(&(zevtchan->zn_cond));
   5923 			(void) pthread_mutex_unlock(&(zevtchan->zn_mutex));
   5924 			return (0);
   5925 		} else {
   5926 			zevtchan->zn_failed = B_TRUE;
   5927 			(void) pthread_mutex_unlock(&(zevtchan->zn_mutex));
   5928 			return (0);
   5929 		}
   5930 	}
   5931 
   5932 	if (zevtchan->zn_state == ZN_UNLOCKED) {
   5933 
   5934 		error = do_callback(zevtchan, ev);
   5935 		(void) pthread_mutex_unlock(&(zevtchan->zn_mutex));
   5936 		/*
   5937 		 * Every ENOMEM failure causes do_callback to increment
   5938 		 * zn_failure_count and every success causes it to
   5939 		 * set zn_failure_count to zero.  If we got EAGAIN,
   5940 		 * we will sleep for zn_failure_count seconds and return
   5941 		 * EAGAIN to gpec to try again.
   5942 		 *
   5943 		 * After 55 seconds, or 10 try's we give up and drop the
   5944 		 * event.
   5945 		 */
   5946 		if (error == EAGAIN) {
   5947 			if (zevtchan->zn_failure_count > ZONE_CB_RETRY_COUNT) {
   5948 				return (0);
   5949 			}
   5950 			(void) sleep(zevtchan->zn_failure_count);
   5951 		}
   5952 		return (error);
   5953 	}
   5954 
   5955 	if (zevtchan->zn_state == ZN_PING_RECEIVED) {
   5956 		(void) pthread_mutex_unlock(&(zevtchan->zn_mutex));
   5957 		return (0);
   5958 	}
   5959 
   5960 	abort();
   5961 	return (0);
   5962 }
   5963 
   5964 void
   5965 zonecfg_notify_critical_enter(void *h)
   5966 {
   5967 	struct znotify *zevtchan = h;
   5968 
   5969 	(void) pthread_mutex_lock(&(zevtchan->zn_bigmutex));
   5970 	zevtchan->zn_state = ZN_LOCKED;
   5971 }
   5972 
   5973 int
   5974 zonecfg_notify_critical_exit(void * h)
   5975 {
   5976 
   5977 	struct znotify *zevtchan = h;
   5978 
   5979 	if (zevtchan->zn_state == ZN_UNLOCKED)
   5980 		return (0);
   5981 
   5982 	(void) pthread_mutex_lock(&(zevtchan->zn_mutex));
   5983 	zevtchan->zn_state = ZN_PING_INFLIGHT;
   5984 
   5985 	(void) sysevent_evc_publish(zevtchan->zn_eventchan,
   5986 	    ZONE_EVENT_STATUS_CLASS,
   5987 	    ZONE_EVENT_PING_SUBCLASS, ZONE_EVENT_PING_PUBLISHER,
   5988 	    zevtchan->zn_subscriber_id, NULL, EVCH_SLEEP);
   5989 
   5990 	while (zevtchan->zn_state != ZN_PING_RECEIVED) {
   5991 		(void) pthread_cond_wait(&(zevtchan->zn_cond),
   5992 		    &(zevtchan->zn_mutex));
   5993 	}
   5994 
   5995 	if (zevtchan->zn_failed == B_TRUE) {
   5996 		zevtchan->zn_state = ZN_LOCKED;
   5997 		zevtchan->zn_failed = B_FALSE;
   5998 		(void) pthread_mutex_unlock(&(zevtchan->zn_mutex));
   5999 		return (1);
   6000 	}
   6001 
   6002 	zevtchan->zn_state = ZN_UNLOCKED;
   6003 	(void) pthread_mutex_unlock(&(zevtchan->zn_mutex));
   6004 	(void) pthread_mutex_unlock(&(zevtchan->zn_bigmutex));
   6005 	return (0);
   6006 }
   6007 
   6008 void
   6009 zonecfg_notify_critical_abort(void *h)
   6010 {
   6011 	struct znotify *zevtchan = h;
   6012 
   6013 	zevtchan->zn_state = ZN_UNLOCKED;
   6014 	zevtchan->zn_failed = B_FALSE;
   6015 	/*
   6016 	 * Don't do anything about zn_lock. If it is held, it could only be
   6017 	 * held by zn_cb and it will be unlocked soon.
   6018 	 */
   6019 	(void) pthread_mutex_unlock(&(zevtchan->zn_bigmutex));
   6020 }
   6021 
   6022 void *
   6023 zonecfg_notify_bind(int(*func)(const char *zonename, zoneid_t zid,
   6024     const char *newstate, const char *oldstate, hrtime_t when, void *p),
   6025     void *p)
   6026 {
   6027 	struct znotify *zevtchan;
   6028 	int i = 1;
   6029 	int r;
   6030 
   6031 	zevtchan = malloc(sizeof (struct znotify));
   6032 
   6033 	if (zevtchan == NULL)
   6034 		return (NULL);
   6035 
   6036 	zevtchan->zn_private = p;
   6037 	zevtchan->zn_callback = func;
   6038 	zevtchan->zn_state = ZN_UNLOCKED;
   6039 	zevtchan->zn_failed = B_FALSE;
   6040 
   6041 	if (pthread_mutex_init(&(zevtchan->zn_mutex), NULL))
   6042 		goto out3;
   6043 	if (pthread_cond_init(&(zevtchan->zn_cond), NULL)) {
   6044 		(void) pthread_mutex_destroy(&(zevtchan->zn_mutex));
   6045 		goto out3;
   6046 	}
   6047 	if (pthread_mutex_init(&(zevtchan->zn_bigmutex), NULL)) {
   6048 		(void) pthread_mutex_destroy(&(zevtchan->zn_mutex));
   6049 		(void) pthread_cond_destroy(&(zevtchan->zn_cond));
   6050 		goto out3;
   6051 	}
   6052 
   6053 	if (sysevent_evc_bind(ZONE_EVENT_CHANNEL, &(zevtchan->zn_eventchan),
   6054 	    0) != 0)
   6055 		goto out2;
   6056 
   6057 	do {
   6058 		/*
   6059 		 * At 4 digits the subscriber ID gets too long and we have
   6060 		 * no chance of successfully registering.
   6061 		 */
   6062 		if (i > 999)
   6063 			goto out1;
   6064 
   6065 		(void) sprintf(zevtchan->zn_subscriber_id, "zone_%li_%i",
   6066 		    getpid() % 999999l, i);
   6067 
   6068 		r = sysevent_evc_subscribe(zevtchan->zn_eventchan,
   6069 		    zevtchan->zn_subscriber_id, ZONE_EVENT_STATUS_CLASS, zn_cb,
   6070 		    zevtchan, 0);
   6071 
   6072 		i++;
   6073 
   6074 	} while (r);
   6075 
   6076 	return (zevtchan);
   6077 out1:
   6078 	(void) sysevent_evc_unbind(zevtchan->zn_eventchan);
   6079 out2:
   6080 	(void) pthread_mutex_destroy(&zevtchan->zn_mutex);
   6081 	(void) pthread_cond_destroy(&zevtchan->zn_cond);
   6082 	(void) pthread_mutex_destroy(&(zevtchan->zn_bigmutex));
   6083 out3:
   6084 	free(zevtchan);
   6085 
   6086 	return (NULL);
   6087 }
   6088 
   6089 void
   6090 zonecfg_notify_unbind(void *handle)
   6091 {
   6092 
   6093 	int ret;
   6094 
   6095 	(void) sysevent_evc_unbind(((struct znotify *)handle)->zn_eventchan);
   6096 	/*
   6097 	 * Check that all evc threads have gone away. This should be
   6098 	 * enforced by sysevent_evc_unbind.
   6099 	 */
   6100 	ret = pthread_mutex_trylock(&((struct znotify *)handle)->zn_mutex);
   6101 
   6102 	if (ret)
   6103 		abort();
   6104 
   6105 	(void) pthread_mutex_unlock(&((struct znotify *)handle)->zn_mutex);
   6106 	(void) pthread_mutex_destroy(&((struct znotify *)handle)->zn_mutex);
   6107 	(void) pthread_cond_destroy(&((struct znotify *)handle)->zn_cond);
   6108 	(void) pthread_mutex_destroy(&((struct znotify *)handle)->zn_bigmutex);
   6109 
   6110 	free(handle);
   6111 }
   6112 
   6113 static int
   6114 zonecfg_add_ds_core(zone_dochandle_t handle, struct zone_dstab *tabptr)
   6115 {
   6116 	xmlNodePtr newnode, cur = handle->zone_dh_cur;
   6117 	int err;
   6118 
   6119 	newnode = xmlNewTextChild(cur, NULL, DTD_ELEM_DATASET, NULL);
   6120 	if ((err = newprop(newnode, DTD_ATTR_NAME,
   6121 	    tabptr->zone_dataset_name)) != Z_OK)
   6122 		return (err);
   6123 	return (Z_OK);
   6124 }
   6125 
   6126 int
   6127 zonecfg_add_ds(zone_dochandle_t handle, struct zone_dstab *tabptr)
   6128 {
   6129 	int err;
   6130 
   6131 	if (tabptr == NULL)
   6132 		return (Z_INVAL);
   6133 
   6134 	if ((err = operation_prep(handle)) != Z_OK)
   6135 		return (err);
   6136 
   6137 	if ((err = zonecfg_add_ds_core(handle, tabptr)) != Z_OK)
   6138 		return (err);
   6139 
   6140 	return (Z_OK);
   6141 }
   6142 
   6143 static int
   6144 zonecfg_delete_ds_core(zone_dochandle_t handle, struct zone_dstab *tabptr)
   6145 {
   6146 	xmlNodePtr cur = handle->zone_dh_cur;
   6147 
   6148 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   6149 		if (xmlStrcmp(cur->name, DTD_ELEM_DATASET))
   6150 			continue;
   6151 
   6152 		if (match_prop(cur, DTD_ATTR_NAME,
   6153 		    tabptr->zone_dataset_name)) {
   6154 			xmlUnlinkNode(cur);
   6155 			xmlFreeNode(cur);
   6156 			return (Z_OK);
   6157 		}
   6158 	}
   6159 	return (Z_NO_RESOURCE_ID);
   6160 }
   6161 
   6162 int
   6163 zonecfg_delete_ds(zone_dochandle_t handle, struct zone_dstab *tabptr)
   6164 {
   6165 	int err;
   6166 
   6167 	if (tabptr == NULL)
   6168 		return (Z_INVAL);
   6169 
   6170 	if ((err = operation_prep(handle)) != Z_OK)
   6171 		return (err);
   6172 
   6173 	if ((err = zonecfg_delete_ds_core(handle, tabptr)) != Z_OK)
   6174 		return (err);
   6175 
   6176 	return (Z_OK);
   6177 }
   6178 
   6179 int
   6180 zonecfg_modify_ds(
   6181 	zone_dochandle_t handle,
   6182 	struct zone_dstab *oldtabptr,
   6183 	struct zone_dstab *newtabptr)
   6184 {
   6185 	int err;
   6186 
   6187 	if (oldtabptr == NULL || newtabptr == NULL)
   6188 		return (Z_INVAL);
   6189 
   6190 	if ((err = operation_prep(handle)) != Z_OK)
   6191 		return (err);
   6192 
   6193 	if ((err = zonecfg_delete_ds_core(handle, oldtabptr)) != Z_OK)
   6194 		return (err);
   6195 
   6196 	if ((err = zonecfg_add_ds_core(handle, newtabptr)) != Z_OK)
   6197 		return (err);
   6198 
   6199 	return (Z_OK);
   6200 }
   6201 
   6202 int
   6203 zonecfg_lookup_ds(zone_dochandle_t handle, struct zone_dstab *tabptr)
   6204 {
   6205 	xmlNodePtr cur, firstmatch;
   6206 	int err;
   6207 	char dataset[MAXNAMELEN];
   6208 
   6209 	if (tabptr == NULL)
   6210 		return (Z_INVAL);
   6211 
   6212 	if ((err = operation_prep(handle)) != Z_OK)
   6213 		return (err);
   6214 
   6215 	cur = handle->zone_dh_cur;
   6216 	firstmatch = NULL;
   6217 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   6218 		if (xmlStrcmp(cur->name, DTD_ELEM_DATASET))
   6219 			continue;
   6220 		if (strlen(tabptr->zone_dataset_name) > 0) {
   6221 			if ((fetchprop(cur, DTD_ATTR_NAME, dataset,
   6222 			    sizeof (dataset)) == Z_OK) &&
   6223 			    (strcmp(tabptr->zone_dataset_name,
   6224 			    dataset) == 0)) {
   6225 				if (firstmatch == NULL)
   6226 					firstmatch = cur;
   6227 				else
   6228 					return (Z_INSUFFICIENT_SPEC);
   6229 			}
   6230 		}
   6231 	}
   6232 	if (firstmatch == NULL)
   6233 		return (Z_NO_RESOURCE_ID);
   6234 
   6235 	cur = firstmatch;
   6236 
   6237 	if ((err = fetchprop(cur, DTD_ATTR_NAME, tabptr->zone_dataset_name,
   6238 	    sizeof (tabptr->zone_dataset_name))) != Z_OK)
   6239 		return (err);
   6240 
   6241 	return (Z_OK);
   6242 }
   6243 
   6244 int
   6245 zonecfg_setdsent(zone_dochandle_t handle)
   6246 {
   6247 	return (zonecfg_setent(handle));
   6248 }
   6249 
   6250 int
   6251 zonecfg_getdsent(zone_dochandle_t handle, struct zone_dstab *tabptr)
   6252 {
   6253 	xmlNodePtr cur;
   6254 	int err;
   6255 
   6256 	if (handle == NULL)
   6257 		return (Z_INVAL);
   6258 
   6259 	if ((cur = handle->zone_dh_cur) == NULL)
   6260 		return (Z_NO_ENTRY);
   6261 
   6262 	for (; cur != NULL; cur = cur->next)
   6263 		if (!xmlStrcmp(cur->name, DTD_ELEM_DATASET))
   6264 			break;
   6265 	if (cur == NULL) {
   6266 		handle->zone_dh_cur = handle->zone_dh_top;
   6267 		return (Z_NO_ENTRY);
   6268 	}
   6269 
   6270 	if ((err = fetchprop(cur, DTD_ATTR_NAME, tabptr->zone_dataset_name,
   6271 	    sizeof (tabptr->zone_dataset_name))) != Z_OK) {
   6272 		handle->zone_dh_cur = handle->zone_dh_top;
   6273 		return (err);
   6274 	}
   6275 
   6276 	handle->zone_dh_cur = cur->next;
   6277 	return (Z_OK);
   6278 }
   6279 
   6280 int
   6281 zonecfg_enddsent(zone_dochandle_t handle)
   6282 {
   6283 	return (zonecfg_endent(handle));
   6284 }
   6285 
   6286 /*
   6287  * Support for aliased rctls; that is, rctls that have simplified names in
   6288  * zonecfg.  For example, max-lwps is an alias for a well defined zone.max-lwps
   6289  * rctl.  If there are multiple existing values for one of these rctls or if
   6290  * there is a single value that does not match the well defined template (i.e.
   6291  * it has a different action) then we cannot treat the rctl as having an alias
   6292  * so we return Z_ALIAS_DISALLOW.  That means that the rctl cannot be
   6293  * managed in zonecfg via an alias and that the standard rctl syntax must be
   6294  * used.
   6295  *
   6296  * The possible return values are:
   6297  *	Z_NO_PROPERTY_ID - invalid alias name
   6298  *	Z_ALIAS_DISALLOW - pre-existing, incompatible rctl definition
   6299  *	Z_NO_ENTRY - no rctl is configured for this alias
   6300  *	Z_OK - we got a valid rctl for the specified alias
   6301  */
   6302 int
   6303 zonecfg_get_aliased_rctl(zone_dochandle_t handle, char *name, uint64_t *rval)
   6304 {
   6305 	boolean_t found = B_FALSE;
   6306 	boolean_t found_val = B_FALSE;
   6307 	xmlNodePtr cur, val;
   6308 	char savedname[MAXNAMELEN];
   6309 	struct zone_rctlvaltab rctl;
   6310 	int i;
   6311 	int err;
   6312 
   6313 	for (i = 0; aliases[i].shortname != NULL; i++)
   6314 		if (strcmp(name, aliases[i].shortname) == 0)
   6315 			break;
   6316 
   6317 	if (aliases[i].shortname == NULL)
   6318 		return (Z_NO_PROPERTY_ID);
   6319 
   6320 	if ((err = operation_prep(handle)) != Z_OK)
   6321 		return (err);
   6322 
   6323 	cur = handle->zone_dh_cur;
   6324 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   6325 		if (xmlStrcmp(cur->name, DTD_ELEM_RCTL) != 0)
   6326 			continue;
   6327 		if ((fetchprop(cur, DTD_ATTR_NAME, savedname,
   6328 		    sizeof (savedname)) == Z_OK) &&
   6329 		    (strcmp(savedname, aliases[i].realname) == 0)) {
   6330 
   6331 			/*
   6332 			 * If we already saw one of these, we can't have an
   6333 			 * alias since we just found another.
   6334 			 */
   6335 			if (found)
   6336 				return (Z_ALIAS_DISALLOW);
   6337 			found = B_TRUE;
   6338 
   6339 			for (val = cur->xmlChildrenNode; val != NULL;
   6340 			    val = val->next) {
   6341 				/*
   6342 				 * If we already have one value, we can't have
   6343 				 * an alias since we just found another.
   6344 				 */
   6345 				if (found_val)
   6346 					return (Z_ALIAS_DISALLOW);
   6347 				found_val = B_TRUE;
   6348 
   6349 				if ((fetchprop(val, DTD_ATTR_PRIV,
   6350 				    rctl.zone_rctlval_priv,
   6351 				    sizeof (rctl.zone_rctlval_priv)) != Z_OK))
   6352 					break;
   6353 				if ((fetchprop(val, DTD_ATTR_LIMIT,
   6354 				    rctl.zone_rctlval_limit,
   6355 				    sizeof (rctl.zone_rctlval_limit)) != Z_OK))
   6356 					break;
   6357 				if ((fetchprop(val, DTD_ATTR_ACTION,
   6358 				    rctl.zone_rctlval_action,
   6359 				    sizeof (rctl.zone_rctlval_action)) != Z_OK))
   6360 					break;
   6361 			}
   6362 
   6363 			/* check priv and action match the expected vals */
   6364 			if (strcmp(rctl.zone_rctlval_priv,
   6365 			    aliases[i].priv) != 0 ||
   6366 			    strcmp(rctl.zone_rctlval_action,
   6367 			    aliases[i].action) != 0)
   6368 				return (Z_ALIAS_DISALLOW);
   6369 		}
   6370 	}
   6371 
   6372 	if (found) {
   6373 		*rval = strtoull(rctl.zone_rctlval_limit, NULL, 10);
   6374 		return (Z_OK);
   6375 	}
   6376 
   6377 	return (Z_NO_ENTRY);
   6378 }
   6379 
   6380 int
   6381 zonecfg_rm_aliased_rctl(zone_dochandle_t handle, char *name)
   6382 {
   6383 	int i;
   6384 	uint64_t val;
   6385 	struct zone_rctltab rctltab;
   6386 
   6387 	/*
   6388 	 * First check that we have a valid aliased rctl to remove.
   6389 	 * This will catch an rctl entry with non-standard values or
   6390 	 * multiple rctl values for this name.  We need to ignore those
   6391 	 * rctl entries.
   6392 	 */
   6393 	if (zonecfg_get_aliased_rctl(handle, name, &val) != Z_OK)
   6394 		return (Z_OK);
   6395 
   6396 	for (i = 0; aliases[i].shortname != NULL; i++)
   6397 		if (strcmp(name, aliases[i].shortname) == 0)
   6398 			break;
   6399 
   6400 	if (aliases[i].shortname == NULL)
   6401 		return (Z_NO_RESOURCE_ID);
   6402 
   6403 	(void) strlcpy(rctltab.zone_rctl_name, aliases[i].realname,
   6404 	    sizeof (rctltab.zone_rctl_name));
   6405 
   6406 	return (zonecfg_delete_rctl(handle, &rctltab));
   6407 }
   6408 
   6409 boolean_t
   6410 zonecfg_aliased_rctl_ok(zone_dochandle_t handle, char *name)
   6411 {
   6412 	uint64_t tmp_val;
   6413 
   6414 	switch (zonecfg_get_aliased_rctl(handle, name, &tmp_val)) {
   6415 	case Z_OK:
   6416 		/*FALLTHRU*/
   6417 	case Z_NO_ENTRY:
   6418 		return (B_TRUE);
   6419 	default:
   6420 		return (B_FALSE);
   6421 	}
   6422 }
   6423 
   6424 int
   6425 zonecfg_set_aliased_rctl(zone_dochandle_t handle, char *name, uint64_t val)
   6426 {
   6427 	int i;
   6428 	int err;
   6429 	struct zone_rctltab rctltab;
   6430 	struct zone_rctlvaltab *rctlvaltab;
   6431 	char buf[128];
   6432 
   6433 	if (!zonecfg_aliased_rctl_ok(handle, name))
   6434 		return (Z_ALIAS_DISALLOW);
   6435 
   6436 	for (i = 0; aliases[i].shortname != NULL; i++)
   6437 		if (strcmp(name, aliases[i].shortname) == 0)
   6438 			break;
   6439 
   6440 	if (aliases[i].shortname == NULL)
   6441 		return (Z_NO_RESOURCE_ID);
   6442 
   6443 	/* remove any pre-existing definition for this rctl */
   6444 	(void) zonecfg_rm_aliased_rctl(handle, name);
   6445 
   6446 	(void) strlcpy(rctltab.zone_rctl_name, aliases[i].realname,
   6447 	    sizeof (rctltab.zone_rctl_name));
   6448 
   6449 	rctltab.zone_rctl_valptr = NULL;
   6450 
   6451 	if ((rctlvaltab = calloc(1, sizeof (struct zone_rctlvaltab))) == NULL)
   6452 		return (Z_NOMEM);
   6453 
   6454 	(void) snprintf(buf, sizeof (buf), "%llu", (long long)val);
   6455 
   6456 	(void) strlcpy(rctlvaltab->zone_rctlval_priv, aliases[i].priv,
   6457 	    sizeof (rctlvaltab->zone_rctlval_priv));
   6458 	(void) strlcpy(rctlvaltab->zone_rctlval_limit, buf,
   6459 	    sizeof (rctlvaltab->zone_rctlval_limit));
   6460 	(void) strlcpy(rctlvaltab->zone_rctlval_action, aliases[i].action,
   6461 	    sizeof (rctlvaltab->zone_rctlval_action));
   6462 
   6463 	rctlvaltab->zone_rctlval_next = NULL;
   6464 
   6465 	if ((err = zonecfg_add_rctl_value(&rctltab, rctlvaltab)) != Z_OK)
   6466 		return (err);
   6467 
   6468 	return (zonecfg_add_rctl(handle, &rctltab));
   6469 }
   6470 
   6471 static int
   6472 delete_tmp_pool(zone_dochandle_t handle)
   6473 {
   6474 	int err;
   6475 	xmlNodePtr cur = handle->zone_dh_cur;
   6476 
   6477 	if ((err = operation_prep(handle)) != Z_OK)
   6478 		return (err);
   6479 
   6480 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   6481 		if (xmlStrcmp(cur->name, DTD_ELEM_TMPPOOL) == 0) {
   6482 			xmlUnlinkNode(cur);
   6483 			xmlFreeNode(cur);
   6484 			return (Z_OK);
   6485 		}
   6486 	}
   6487 
   6488 	return (Z_NO_RESOURCE_ID);
   6489 }
   6490 
   6491 static int
   6492 modify_tmp_pool(zone_dochandle_t handle, char *pool_importance)
   6493 {
   6494 	int err;
   6495 	xmlNodePtr cur = handle->zone_dh_cur;
   6496 	xmlNodePtr newnode;
   6497 
   6498 	err = delete_tmp_pool(handle);
   6499 	if (err != Z_OK && err != Z_NO_RESOURCE_ID)
   6500 		return (err);
   6501 
   6502 	if (*pool_importance != '\0') {
   6503 		if ((err = operation_prep(handle)) != Z_OK)
   6504 			return (err);
   6505 
   6506 		newnode = xmlNewTextChild(cur, NULL, DTD_ELEM_TMPPOOL, NULL);
   6507 		if ((err = newprop(newnode, DTD_ATTR_IMPORTANCE,
   6508 		    pool_importance)) != Z_OK)
   6509 			return (err);
   6510 	}
   6511 
   6512 	return (Z_OK);
   6513 }
   6514 
   6515 static int
   6516 add_pset_core(zone_dochandle_t handle, struct zone_psettab *tabptr)
   6517 {
   6518 	xmlNodePtr newnode, cur = handle->zone_dh_cur;
   6519 	int err;
   6520 
   6521 	newnode = xmlNewTextChild(cur, NULL, DTD_ELEM_PSET, NULL);
   6522 	if ((err = newprop(newnode, DTD_ATTR_NCPU_MIN,
   6523 	    tabptr->zone_ncpu_min)) != Z_OK)
   6524 		return (err);
   6525 	if ((err = newprop(newnode, DTD_ATTR_NCPU_MAX,
   6526 	    tabptr->zone_ncpu_max)) != Z_OK)
   6527 		return (err);
   6528 
   6529 	if ((err = modify_tmp_pool(handle, tabptr->zone_importance)) != Z_OK)
   6530 		return (err);
   6531 
   6532 	return (Z_OK);
   6533 }
   6534 
   6535 int
   6536 zonecfg_add_pset(zone_dochandle_t handle, struct zone_psettab *tabptr)
   6537 {
   6538 	int err;
   6539 
   6540 	if (tabptr == NULL)
   6541 		return (Z_INVAL);
   6542 
   6543 	if ((err = operation_prep(handle)) != Z_OK)
   6544 		return (err);
   6545 
   6546 	if ((err = add_pset_core(handle, tabptr)) != Z_OK)
   6547 		return (err);
   6548 
   6549 	return (Z_OK);
   6550 }
   6551 
   6552 int
   6553 zonecfg_delete_pset(zone_dochandle_t handle)
   6554 {
   6555 	int err;
   6556 	int res = Z_NO_RESOURCE_ID;
   6557 	xmlNodePtr cur = handle->zone_dh_cur;
   6558 
   6559 	if ((err = operation_prep(handle)) != Z_OK)
   6560 		return (err);
   6561 
   6562 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   6563 		if (xmlStrcmp(cur->name, DTD_ELEM_PSET) == 0) {
   6564 			xmlUnlinkNode(cur);
   6565 			xmlFreeNode(cur);
   6566 			res = Z_OK;
   6567 			break;
   6568 		}
   6569 	}
   6570 
   6571 	/*
   6572 	 * Once we have msets, we should check that a mset
   6573 	 * do not exist before we delete the tmp_pool data.
   6574 	 */
   6575 	err = delete_tmp_pool(handle);
   6576 	if (err != Z_OK && err != Z_NO_RESOURCE_ID)
   6577 		return (err);
   6578 
   6579 	return (res);
   6580 }
   6581 
   6582 int
   6583 zonecfg_modify_pset(zone_dochandle_t handle, struct zone_psettab *tabptr)
   6584 {
   6585 	int err;
   6586 
   6587 	if (tabptr == NULL)
   6588 		return (Z_INVAL);
   6589 
   6590 	if ((err = zonecfg_delete_pset(handle)) != Z_OK)
   6591 		return (err);
   6592 
   6593 	if ((err = add_pset_core(handle, tabptr)) != Z_OK)
   6594 		return (err);
   6595 
   6596 	return (Z_OK);
   6597 }
   6598 
   6599 int
   6600 zonecfg_lookup_pset(zone_dochandle_t handle, struct zone_psettab *tabptr)
   6601 {
   6602 	xmlNodePtr cur;
   6603 	int err;
   6604 	int res = Z_NO_ENTRY;
   6605 
   6606 	if (tabptr == NULL)
   6607 		return (Z_INVAL);
   6608 
   6609 	if ((err = operation_prep(handle)) != Z_OK)
   6610 		return (err);
   6611 
   6612 	/* this is an optional component */
   6613 	tabptr->zone_importance[0] = '\0';
   6614 
   6615 	cur = handle->zone_dh_cur;
   6616 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   6617 		if (xmlStrcmp(cur->name, DTD_ELEM_PSET) == 0) {
   6618 			if ((err = fetchprop(cur, DTD_ATTR_NCPU_MIN,
   6619 			    tabptr->zone_ncpu_min,
   6620 			    sizeof (tabptr->zone_ncpu_min))) != Z_OK) {
   6621 				handle->zone_dh_cur = handle->zone_dh_top;
   6622 				return (err);
   6623 			}
   6624 
   6625 			if ((err = fetchprop(cur, DTD_ATTR_NCPU_MAX,
   6626 			    tabptr->zone_ncpu_max,
   6627 			    sizeof (tabptr->zone_ncpu_max))) != Z_OK) {
   6628 				handle->zone_dh_cur = handle->zone_dh_top;
   6629 				return (err);
   6630 			}
   6631 
   6632 			res = Z_OK;
   6633 
   6634 		} else if (xmlStrcmp(cur->name, DTD_ELEM_TMPPOOL) == 0) {
   6635 			if ((err = fetchprop(cur, DTD_ATTR_IMPORTANCE,
   6636 			    tabptr->zone_importance,
   6637 			    sizeof (tabptr->zone_importance))) != Z_OK) {
   6638 				handle->zone_dh_cur = handle->zone_dh_top;
   6639 				return (err);
   6640 			}
   6641 		}
   6642 	}
   6643 
   6644 	return (res);
   6645 }
   6646 
   6647 int
   6648 zonecfg_getpsetent(zone_dochandle_t handle, struct zone_psettab *tabptr)
   6649 {
   6650 	int err;
   6651 
   6652 	if ((err = zonecfg_setent(handle)) != Z_OK)
   6653 		return (err);
   6654 
   6655 	err = zonecfg_lookup_pset(handle, tabptr);
   6656 
   6657 	(void) zonecfg_endent(handle);
   6658 
   6659 	return (err);
   6660 }
   6661 
   6662 static int
   6663 add_mcap(zone_dochandle_t handle, struct zone_mcaptab *tabptr)
   6664 {
   6665 	xmlNodePtr newnode, cur = handle->zone_dh_cur;
   6666 	int err;
   6667 
   6668 	newnode = xmlNewTextChild(cur, NULL, DTD_ELEM_MCAP, NULL);
   6669 	if ((err = newprop(newnode, DTD_ATTR_PHYSCAP, tabptr->zone_physmem_cap))
   6670 	    != Z_OK)
   6671 		return (err);
   6672 
   6673 	return (Z_OK);
   6674 }
   6675 
   6676 int
   6677 zonecfg_delete_mcap(zone_dochandle_t handle)
   6678 {
   6679 	int err;
   6680 	xmlNodePtr cur = handle->zone_dh_cur;
   6681 
   6682 	if ((err = operation_prep(handle)) != Z_OK)
   6683 		return (err);
   6684 
   6685 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   6686 		if (xmlStrcmp(cur->name, DTD_ELEM_MCAP) != 0)
   6687 			continue;
   6688 
   6689 		xmlUnlinkNode(cur);
   6690 		xmlFreeNode(cur);
   6691 		return (Z_OK);
   6692 	}
   6693 	return (Z_NO_RESOURCE_ID);
   6694 }
   6695 
   6696 int
   6697 zonecfg_modify_mcap(zone_dochandle_t handle, struct zone_mcaptab *tabptr)
   6698 {
   6699 	int err;
   6700 
   6701 	if (tabptr == NULL)
   6702 		return (Z_INVAL);
   6703 
   6704 	err = zonecfg_delete_mcap(handle);
   6705 	/* it is ok if there is no mcap entry */
   6706 	if (err != Z_OK && err != Z_NO_RESOURCE_ID)
   6707 		return (err);
   6708 
   6709 	if ((err = add_mcap(handle, tabptr)) != Z_OK)
   6710 		return (err);
   6711 
   6712 	return (Z_OK);
   6713 }
   6714 
   6715 int
   6716 zonecfg_lookup_mcap(zone_dochandle_t handle, struct zone_mcaptab *tabptr)
   6717 {
   6718 	xmlNodePtr cur;
   6719 	int err;
   6720 
   6721 	if (tabptr == NULL)
   6722 		return (Z_INVAL);
   6723 
   6724 	if ((err = operation_prep(handle)) != Z_OK)
   6725 		return (err);
   6726 
   6727 	cur = handle->zone_dh_cur;
   6728 	for (cur = cur->xmlChildrenNode; cur != NULL; cur = cur->next) {
   6729 		if (xmlStrcmp(cur->name, DTD_ELEM_MCAP) != 0)
   6730 			continue;
   6731 		if ((err = fetchprop(cur, DTD_ATTR_PHYSCAP,
   6732 		    tabptr->zone_physmem_cap,
   6733 		    sizeof (tabptr->zone_physmem_cap))) != Z_OK) {
   6734 			handle->zone_dh_cur = handle->zone_dh_top;
   6735 			return (err);
   6736 		}
   6737 
   6738 		return (Z_OK);
   6739 	}
   6740 
   6741 	return (Z_NO_ENTRY);
   6742 }
   6743 
   6744 static int
   6745 getmcapent_core(zone_dochandle_t handle, struct zone_mcaptab *tabptr)
   6746 {
   6747 	xmlNodePtr cur;
   6748 	int err;
   6749 
   6750 	if (handle == NULL)
   6751 		return (Z_INVAL);
   6752 
   6753 	if ((cur = handle->zone_dh_cur) == NULL)
   6754 		return (Z_NO_ENTRY);
   6755 
   6756 	for (; cur != NULL; cur = cur->next)
   6757 		if (xmlStrcmp(cur->name, DTD_ELEM_MCAP) == 0)
   6758 			break;
   6759 	if (cur == NULL) {
   6760 		handle->zone_dh_cur = handle->zone_dh_top;
   6761 		return (Z_NO_ENTRY);
   6762 	}
   6763 
   6764 	if ((err = fetchprop(cur, DTD_ATTR_PHYSCAP, tabptr->zone_physmem_cap,
   6765 	    sizeof (tabptr->zone_physmem_cap))) != Z_OK) {
   6766 		handle->zone_dh_cur = handle->zone_dh_top;
   6767 		return (err);
   6768 	}
   6769 
   6770 	handle->zone_dh_cur = cur->next;
   6771 	return (Z_OK);
   6772 }
   6773 
   6774 int
   6775 zonecfg_getmcapent(zone_dochandle_t handle, struct zone_mcaptab *tabptr)
   6776 {
   6777 	int err;
   6778 
   6779 	if ((err = zonecfg_setent(handle)) != Z_OK)
   6780 		return (err);
   6781 
   6782 	err = getmcapent_core(handle, tabptr);
   6783 
   6784 	(void) zonecfg_endent(handle);
   6785 
   6786 	return (err);
   6787 }
   6788 
   6789 /*
   6790  * Get the full tree of pkg/patch metadata in a set of nested AVL trees.
   6791  * pkgs_avl is an AVL tree of pkgs.  Each pkg element contains a
   6792  * zpe_patches_avl member which holds an AVL tree of patches for that pkg.
   6793  * The patch elements have the same zpe_patches_avl member, each of which can
   6794  * hold an AVL tree of patches that are obsoleted by the patch.
   6795  *
   6796  * The zone xml data contains DTD_ELEM_PACKAGE elements, followed by
   6797  * DTD_ELEM_PATCH elements.  The DTD_ELEM_PATCH patch element applies to the
   6798  * DTD_ELEM_PACKAGE that precedes it.  The DTD_ELEM_PATCH element may have
   6799  * child DTD_ELEM_OBSOLETES nodes associated with it.  The DTD_ELEM_PACKAGE
   6800  * really should have had the DTD_ELEM_PATCH elements as children but it
   6801  * was not defined that way initially so we are stuck with the DTD definition
   6802  * now.  However, we can safely assume the ordering for compatibility.
   6803  */
   6804 int
   6805 zonecfg_getpkgdata(zone_dochandle_t handle, uu_avl_pool_t *pkg_pool,
   6806     uu_avl_t *pkgs_avl)
   6807 {
   6808 	xmlNodePtr cur;
   6809 	int res;
   6810 	zone_pkg_entry_t *pkg;
   6811 	char name[MAXNAMELEN];
   6812 	char version[ZONE_PKG_VERSMAX];
   6813 
   6814 	if (handle == NULL)
   6815 		return (Z_INVAL);
   6816 
   6817 	if ((res = zonecfg_setent(handle)) != Z_OK)
   6818 		return (res);
   6819 
   6820 	if ((cur = handle->zone_dh_cur) == NULL) {
   6821 		res = Z_NO_ENTRY;
   6822 		goto done;
   6823 	}
   6824 
   6825 	for (; cur != NULL; cur = cur->next) {
   6826 		if (xmlStrcmp(cur->name, DTD_ELEM_PACKAGE) == 0) {
   6827 			uu_avl_index_t where;
   6828 
   6829 			if ((res = fetchprop(cur, DTD_ATTR_NAME, name,
   6830 			    sizeof (name))) != Z_OK)
   6831 				goto done;
   6832 
   6833 			if ((res = fetchprop(cur, DTD_ATTR_VERSION, version,
   6834 			    sizeof (version))) != Z_OK)
   6835 				goto done;
   6836 
   6837 			if ((pkg = (zone_pkg_entry_t *)
   6838 			    malloc(sizeof (zone_pkg_entry_t))) == NULL) {
   6839 				res = Z_NOMEM;
   6840 				goto done;
   6841 			}
   6842 
   6843 			if ((pkg->zpe_name = strdup(name)) == NULL) {
   6844 				free(pkg);
   6845 				res = Z_NOMEM;
   6846 				goto done;
   6847 			}
   6848 
   6849 			if ((pkg->zpe_vers = strdup(version)) == NULL) {
   6850 				free(pkg->zpe_name);
   6851 				free(pkg);
   6852 				res = Z_NOMEM;
   6853 				goto done;
   6854 			}
   6855 
   6856 			pkg->zpe_patches_avl = NULL;
   6857 
   6858 			uu_avl_node_init(pkg, &pkg->zpe_entry, pkg_pool);
   6859 			if (uu_avl_find(pkgs_avl, pkg, NULL, &where) != NULL) {
   6860 				free(pkg->zpe_name);
   6861 				free(pkg->zpe_vers);
   6862 				free(pkg);
   6863 			} else {
   6864 				uu_avl_insert(pkgs_avl, pkg, where);
   6865 			}
   6866 
   6867 		} else if (xmlStrcmp(cur->name, DTD_ELEM_PATCH) == 0) {
   6868 			zone_pkg_entry_t *patch;
   6869 			uu_avl_index_t where;
   6870 			char *p;
   6871 			char *dashp = NULL;
   6872 			xmlNodePtr child;
   6873 
   6874 			if ((res = fetchprop(cur, DTD_ATTR_ID, name,
   6875 			    sizeof (name))) != Z_OK)
   6876 				goto done;
   6877 
   6878 			if ((patch = (zone_pkg_entry_t *)
   6879 			    malloc(sizeof (zone_pkg_entry_t))) == NULL) {
   6880 				res = Z_NOMEM;
   6881 				goto done;
   6882 			}
   6883 
   6884 			if ((p = strchr(name, '-')) != NULL) {
   6885 				dashp = p;
   6886 				*p++ = '\0';
   6887 			} else {
   6888 				p = "";
   6889 			}
   6890 
   6891 			if ((patch->zpe_name = strdup(name)) == NULL) {
   6892 				free(patch);
   6893 				res = Z_NOMEM;
   6894 				goto done;
   6895 			}
   6896 
   6897 			if ((patch->zpe_vers = strdup(p)) == NULL) {
   6898 				free(patch->zpe_name);
   6899 				free(patch);
   6900 				res = Z_NOMEM;
   6901 				goto done;
   6902 			}
   6903 
   6904 			if (dashp != NULL)
   6905 				*dashp = '-';
   6906 
   6907 			patch->zpe_patches_avl = NULL;
   6908 
   6909 			if (pkg->zpe_patches_avl == NULL) {
   6910 				pkg->zpe_patches_avl = uu_avl_create(pkg_pool,
   6911 				    NULL, UU_DEFAULT);
   6912 				if (pkg->zpe_patches_avl == NULL) {
   6913 					free(patch->zpe_name);
   6914 					free(patch->zpe_vers);
   6915 					free(patch);
   6916 					res = Z_NOMEM;
   6917 					goto done;
   6918 				}
   6919 			}
   6920 
   6921 			uu_avl_node_init(patch, &patch->zpe_entry, pkg_pool);
   6922 			if (uu_avl_find(pkg->zpe_patches_avl, patch, NULL,
   6923 			    &where) != NULL) {
   6924 				free(patch->zpe_name);
   6925 				free(patch->zpe_vers);
   6926 				free(patch);
   6927 			} else {
   6928 				uu_avl_insert(pkg->zpe_patches_avl, patch,
   6929 				    where);
   6930 			}
   6931 
   6932 			/* Add any patches this patch obsoletes. */
   6933 			for (child = cur->xmlChildrenNode; child != NULL;
   6934 			    child = child->next) {
   6935 				zone_pkg_entry_t *obs;
   6936 
   6937 				if (xmlStrcmp(child->name, DTD_ELEM_OBSOLETES)
   6938 				    != 0)
   6939 					continue;
   6940 
   6941 				if ((res = fetchprop(child, DTD_ATTR_ID,
   6942 				    name, sizeof (name))) != Z_OK)
   6943 					goto done;
   6944 
   6945 				if ((obs = (zone_pkg_entry_t *)malloc(
   6946 				    sizeof (zone_pkg_entry_t))) == NULL) {
   6947 					res = Z_NOMEM;
   6948 					goto done;
   6949 				}
   6950 
   6951 				if ((obs->zpe_name = strdup(name)) == NULL) {
   6952 					free(obs);
   6953 					res = Z_NOMEM;
   6954 					goto done;
   6955 				}
   6956 				/*
   6957 				 * The version doesn't matter for obsoleted
   6958 				 * patches.
   6959 				 */
   6960 				obs->zpe_vers = NULL;
   6961 				obs->zpe_patches_avl = NULL;
   6962 
   6963 				/*
   6964 				 * If this is the first obsolete patch, add an
   6965 				 * AVL tree to the parent patch element.
   6966 				 */
   6967 				if (patch->zpe_patches_avl == NULL) {
   6968 					patch->zpe_patches_avl =
   6969 					    uu_avl_create(pkg_pool, NULL,
   6970 					    UU_DEFAULT);
   6971 					if (patch->zpe_patches_avl == NULL) {
   6972 						free(obs->zpe_name);
   6973 						free(obs);
   6974 						res = Z_NOMEM;
   6975 						goto done;
   6976 					}
   6977 				}
   6978 
   6979 				/* Insert obsolete patch into the AVL tree. */
   6980 				uu_avl_node_init(obs, &obs->zpe_entry,
   6981 				    pkg_pool);
   6982 				if (uu_avl_find(patch->zpe_patches_avl, obs,
   6983 				    NULL, &where) != NULL) {
   6984 					free(obs->zpe_name);
   6985 					free(obs);
   6986 				} else {
   6987 					uu_avl_insert(patch->zpe_patches_avl,
   6988 					    obs, where);
   6989 				}
   6990 			}
   6991 		}
   6992 	}
   6993 
   6994 done:
   6995 	(void) zonecfg_endent(handle);
   6996 	return (res);
   6997 }
   6998 
   6999 int
   7000 zonecfg_setdevperment(zone_dochandle_t handle)
   7001 {
   7002 	return (zonecfg_setent(handle));
   7003 }
   7004 
   7005 int
   7006 zonecfg_getdevperment(zone_dochandle_t handle, struct zone_devpermtab *tabptr)
   7007 {
   7008 	xmlNodePtr cur;
   7009 	int err;
   7010 	char buf[128];
   7011 
   7012 	tabptr->zone_devperm_acl = NULL;
   7013 
   7014 	if (handle == NULL)
   7015 		return (Z_INVAL);
   7016 
   7017 	if ((cur = handle->zone_dh_cur) == NULL)
   7018 		return (Z_NO_ENTRY);
   7019 
   7020 	for (; cur != NULL; cur = cur->next)
   7021 		if (!xmlStrcmp(cur->name, DTD_ELEM_DEV_PERM))
   7022 			break;
   7023 	if (cur == NULL) {
   7024 		handle->zone_dh_cur = handle->zone_dh_top;
   7025 		return (Z_NO_ENTRY);
   7026 	}
   7027 
   7028 	if ((err = fetchprop(cur, DTD_ATTR_NAME, tabptr->zone_devperm_name,
   7029 	    sizeof (tabptr->zone_devperm_name))) != Z_OK) {
   7030 		handle->zone_dh_cur = handle->zone_dh_top;
   7031 		return (err);
   7032 	}
   7033 
   7034 	if ((err = fetchprop(cur, DTD_ATTR_UID, buf, sizeof (buf))) != Z_OK) {
   7035 		handle->zone_dh_cur = handle->zone_dh_top;
   7036 		return (err);
   7037 	}
   7038 	tabptr->zone_devperm_uid = (uid_t)atol(buf);
   7039 
   7040 	if ((err = fetchprop(cur, DTD_ATTR_GID, buf, sizeof (buf))) != Z_OK) {
   7041 		handle->zone_dh_cur = handle->zone_dh_top;
   7042 		return (err);
   7043 	}
   7044 	tabptr->zone_devperm_gid = (gid_t)atol(buf);
   7045 
   7046 	if ((err = fetchprop(cur, DTD_ATTR_MODE, buf, sizeof (buf))) != Z_OK) {
   7047 		handle->zone_dh_cur = handle->zone_dh_top;
   7048 		return (err);
   7049 	}
   7050 	tabptr->zone_devperm_mode = (mode_t)strtol(buf, (char **)NULL, 8);
   7051 
   7052 	if ((err = fetch_alloc_prop(cur, DTD_ATTR_ACL,
   7053 	    &(tabptr->zone_devperm_acl))) != Z_OK) {
   7054 		handle->zone_dh_cur = handle->zone_dh_top;
   7055 		return (err);
   7056 	}
   7057 
   7058 	handle->zone_dh_cur = cur->next;
   7059 	return (Z_OK);
   7060 }
   7061 
   7062 int
   7063 zonecfg_enddevperment(zone_dochandle_t handle)
   7064 {
   7065 	return (zonecfg_endent(handle));
   7066 }
   7067 
   7068 /* PRINTFLIKE1 */
   7069 static void
   7070 zerror(const char *zone_name, const char *fmt, ...)
   7071 {
   7072 	va_list alist;
   7073 
   7074 	va_start(alist, fmt);
   7075 	(void) fprintf(stderr, "zone '%s': ", zone_name);
   7076 	(void) vfprintf(stderr, fmt, alist);
   7077 	(void) fprintf(stderr, "\n");
   7078 	va_end(alist);
   7079 }
   7080 
   7081 static void
   7082 zperror(const char *str)
   7083 {
   7084 	(void) fprintf(stderr, "%s: %s\n", str, strerror(errno));
   7085 }
   7086 
   7087 /*
   7088  * The following three routines implement a simple locking mechanism to
   7089  * ensure that only one instance of zoneadm at a time is able to manipulate
   7090  * a given zone.  The lock is built on top of an fcntl(2) lock of
   7091  * [<altroot>]/var/run/zones/<zonename>.zoneadm.lock.  If a zoneadm instance
   7092  * can grab that lock, it is allowed to manipulate the zone.
   7093  *
   7094  * Since zoneadm may call external applications which in turn invoke
   7095  * zoneadm again, we introduce the notion of "lock inheritance".  Any
   7096  * instance of zoneadm that has another instance in its ancestry is assumed
   7097  * to be acting on behalf of the original zoneadm, and is thus allowed to
   7098  * manipulate its zone.
   7099  *
   7100  * This inheritance is implemented via the _ZONEADM_LOCK_HELD environment
   7101  * variable.  When zoneadm is granted a lock on its zone, this environment
   7102  * variable is set to 1.  When it releases the lock, the variable is set to
   7103  * 0.  Since a child process inherits its parent's environment, checking
   7104  * the state of this variable indicates whether or not any ancestor owns
   7105  * the lock.
   7106  */
   7107 void
   7108 zonecfg_init_lock_file(const char *zone_name, char **lock_env)
   7109 {
   7110 	*lock_env = getenv(LOCK_ENV_VAR);
   7111 	if (*lock_env == NULL) {
   7112 		if (putenv(zoneadm_lock_not_held) != 0) {
   7113 			zerror(zone_name, gettext("could not set env: %s"),
   7114 			    strerror(errno));
   7115 			exit(1);
   7116 		}
   7117 	} else {
   7118 		if (atoi(*lock_env) == 1)
   7119 			zone_lock_cnt = 1;
   7120 	}
   7121 }
   7122 
   7123 void
   7124 zonecfg_release_lock_file(const char *zone_name, int lockfd)
   7125 {
   7126 	/*
   7127 	 * If we are cleaning up from a failed attempt to lock the zone for
   7128 	 * the first time, we might have a zone_lock_cnt of 0.  In that
   7129 	 * error case, we don't want to do anything but close the lock
   7130 	 * file.
   7131 	 */
   7132 	assert(zone_lock_cnt >= 0);
   7133 	if (zone_lock_cnt > 0) {
   7134 		assert(getenv(LOCK_ENV_VAR) != NULL);
   7135 		assert(atoi(getenv(LOCK_ENV_VAR)) == 1);
   7136 		if (--zone_lock_cnt > 0) {
   7137 			assert(lockfd == -1);
   7138 			return;
   7139 		}
   7140 		if (putenv(zoneadm_lock_not_held) != 0) {
   7141 			zerror(zone_name, gettext("could not set env: %s"),
   7142 			    strerror(errno));
   7143 			exit(1);
   7144 		}
   7145 	}
   7146 	assert(lockfd >= 0);
   7147 	(void) close(lockfd);
   7148 }
   7149 
   7150 int
   7151 zonecfg_grab_lock_file(const char *zone_name, int *lockfd)
   7152 {
   7153 	char pathbuf[PATH_MAX];
   7154 	struct flock flock;
   7155 
   7156 	/*
   7157 	 * If we already have the lock, we can skip this expensive song
   7158 	 * and dance.
   7159 	 */
   7160 	assert(zone_lock_cnt >= 0);
   7161 	assert(getenv(LOCK_ENV_VAR) != NULL);
   7162 	if (zone_lock_cnt > 0) {
   7163 		assert(atoi(getenv(LOCK_ENV_VAR)) == 1);
   7164 		zone_lock_cnt++;
   7165 		*lockfd = -1;
   7166 		return (Z_OK);
   7167 	}
   7168 	assert(getenv(LOCK_ENV_VAR) != NULL);
   7169 	assert(atoi(getenv(LOCK_ENV_VAR)) == 0);
   7170 
   7171 	if (snprintf(pathbuf, sizeof (pathbuf), "%s%s", zonecfg_get_root(),
   7172 	    ZONES_TMPDIR) >= sizeof (pathbuf)) {
   7173 		zerror(zone_name, gettext("alternate root path is too long"));
   7174 		return (-1);
   7175 	}
   7176 	if (mkdir(pathbuf, S_IRWXU) < 0 && errno != EEXIST) {
   7177 		zerror(zone_name, gettext("could not mkdir %s: %s"), pathbuf,
   7178 		    strerror(errno));
   7179 		return (-1);
   7180 	}
   7181 	(void) chmod(pathbuf, S_IRWXU);
   7182 
   7183 	/*
   7184 	 * One of these lock files is created for each zone (when needed).
   7185 	 * The lock files are not cleaned up (except on system reboot),
   7186 	 * but since there is only one per zone, there is no resource
   7187 	 * starvation issue.
   7188 	 */
   7189 	if (snprintf(pathbuf, sizeof (pathbuf), "%s%s/%s.zoneadm.lock",
   7190 	    zonecfg_get_root(), ZONES_TMPDIR, zone_name) >= sizeof (pathbuf)) {
   7191 		zerror(zone_name, gettext("alternate root path is too long"));
   7192 		return (-1);
   7193 	}
   7194 	if ((*lockfd = open(pathbuf, O_RDWR|O_CREAT, S_IRUSR|S_IWUSR)) < 0) {
   7195 		zerror(zone_name, gettext("could not open %s: %s"), pathbuf,
   7196 		    strerror(errno));
   7197 		return (-1);
   7198 	}
   7199 	/*
   7200 	 * Lock the file to synchronize with other zoneadmds
   7201 	 */
   7202 	flock.l_type = F_WRLCK;
   7203 	flock.l_whence = SEEK_SET;
   7204 	flock.l_start = (off_t)0;
   7205 	flock.l_len = (off_t)0;
   7206 	if ((fcntl(*lockfd, F_SETLKW, &flock) < 0) ||
   7207 	    (putenv(zoneadm_lock_held) != 0)) {
   7208 		zerror(zone_name, gettext("unable to lock %s: %s"), pathbuf,
   7209 		    strerror(errno));
   7210 		zonecfg_release_lock_file(zone_name, *lockfd);
   7211 		return (-1);
   7212 	}
   7213 	zone_lock_cnt = 1;
   7214 	return (Z_OK);
   7215 }
   7216 
   7217 boolean_t
   7218 zonecfg_lock_file_held(int *lockfd)
   7219 {
   7220 	if (*lockfd >= 0 || zone_lock_cnt > 0)
   7221 		return (B_TRUE);
   7222 	return (B_FALSE);
   7223 }
   7224 
   7225 static boolean_t
   7226 get_doorname(const char *zone_name, char *buffer)
   7227 {
   7228 	return (snprintf(buffer, PATH_MAX, "%s" ZONE_DOOR_PATH,
   7229 	    zonecfg_get_root(), zone_name) < PATH_MAX);
   7230 }
   7231 
   7232 /*
   7233  * system daemons are not audited.  For the global zone, this occurs
   7234  * "naturally" since init is started with the default audit
   7235  * characteristics.  Since zoneadmd is a system daemon and it starts
   7236  * init for a zone, it is necessary to clear out the audit
   7237  * characteristics inherited from whomever started zoneadmd.  This is
   7238  * indicated by the audit id, which is set from the ruid parameter of
   7239  * adt_set_user(), below.
   7240  */
   7241 
   7242 static void
   7243 prepare_audit_context(const char *zone_name)
   7244 {
   7245 	adt_session_data_t	*ah;
   7246 	char			*failure = gettext("audit failure: %s");
   7247 
   7248 	if (adt_start_session(&ah, NULL, 0)) {
   7249 		zerror(zone_name, failure, strerror(errno));
   7250 		return;
   7251 	}
   7252 	if (adt_set_user(ah, ADT_NO_AUDIT, ADT_NO_AUDIT,
   7253 	    ADT_NO_AUDIT, ADT_NO_AUDIT, NULL, ADT_NEW)) {
   7254 		zerror(zone_name, failure, strerror(errno));
   7255 		(void) adt_end_session(ah);
   7256 		return;
   7257 	}
   7258 	if (adt_set_proc(ah))
   7259 		zerror(zone_name, failure, strerror(errno));
   7260 
   7261 	(void) adt_end_session(ah);
   7262 }
   7263 
   7264 static int
   7265 start_zoneadmd(const char *zone_name, boolean_t lock)
   7266 {
   7267 	char doorpath[PATH_MAX];
   7268 	pid_t child_pid;
   7269 	int error = -1;
   7270 	int doorfd, lockfd;
   7271 	struct door_info info;
   7272 
   7273 	if (!get_doorname(zone_name, doorpath))
   7274 		return (-1);
   7275 
   7276 	if (lock)
   7277 		if (zonecfg_grab_lock_file(zone_name, &lockfd) != Z_OK)
   7278 			return (-1);
   7279 
   7280 	/*
   7281 	 * Now that we have the lock, re-confirm that the daemon is
   7282 	 * *not* up and working fine.  If it is still down, we have a green
   7283 	 * light to start it.
   7284 	 */
   7285 	if ((doorfd = open(doorpath, O_RDONLY)) < 0) {
   7286 		if (errno != ENOENT) {
   7287 			zperror(doorpath);
   7288 			goto out;
   7289 		}
   7290 	} else {
   7291 		if (door_info(doorfd, &info) == 0 &&
   7292 		    ((info.di_attributes & DOOR_REVOKED) == 0)) {
   7293 			error = Z_OK;
   7294 			(void) close(doorfd);
   7295 			goto out;
   7296 		}
   7297 		(void) close(doorfd);
   7298 	}
   7299 
   7300 	if ((child_pid = fork()) == -1) {
   7301 		zperror(gettext("could not fork"));
   7302 		goto out;
   7303 	}
   7304 
   7305 	if (child_pid == 0) {
   7306 		const char *argv[6], **ap;
   7307 
   7308 		/* child process */
   7309 		prepare_audit_context(zone_name);
   7310 
   7311 		ap = argv;
   7312 		*ap++ = "zoneadmd";
   7313 		*ap++ = "-z";
   7314 		*ap++ = zone_name;
   7315 		if (zonecfg_in_alt_root()) {
   7316 			*ap++ = "-R";
   7317 			*ap++ = zonecfg_get_root();
   7318 		}
   7319 		*ap = NULL;
   7320 
   7321 		(void) execv("/usr/lib/zones/zoneadmd", (char * const *)argv);
   7322 		/*
   7323 		 * TRANSLATION_NOTE
   7324 		 * zoneadmd is a literal that should not be translated.
   7325 		 */
   7326 		zperror(gettext("could not exec zoneadmd"));
   7327 		_exit(1);
   7328 	} else {
   7329 		/* parent process */
   7330 		pid_t retval;
   7331 		int pstatus = 0;
   7332 
   7333 		do {
   7334 			retval = waitpid(child_pid, &pstatus, 0);
   7335 		} while (retval != child_pid);
   7336 		if (WIFSIGNALED(pstatus) || (WIFEXITED(pstatus) &&
   7337 		    WEXITSTATUS(pstatus) != 0)) {
   7338 			zerror(zone_name, gettext("could not start %s"),
   7339 			    "zoneadmd");
   7340 			goto out;
   7341 		}
   7342 	}
   7343 	error = Z_OK;
   7344 out:
   7345 	if (lock)
   7346 		zonecfg_release_lock_file(zone_name, lockfd);
   7347 	return (error);
   7348 }
   7349 
   7350 int
   7351 zonecfg_ping_zoneadmd(const char *zone_name)
   7352 {
   7353 	char doorpath[PATH_MAX];
   7354 	int doorfd;
   7355 	struct door_info info;
   7356 
   7357 	if (!get_doorname(zone_name, doorpath))
   7358 		return (-1);
   7359 
   7360 	if ((doorfd = open(doorpath, O_RDONLY)) < 0) {
   7361 		return (-1);
   7362 	}
   7363 	if (door_info(doorfd, &info) == 0 &&
   7364 	    ((info.di_attributes & DOOR_REVOKED) == 0)) {
   7365 		(void) close(doorfd);
   7366 		return (Z_OK);
   7367 	}
   7368 	(void) close(doorfd);
   7369 	return (-1);
   7370 }
   7371 
   7372 int
   7373 zonecfg_call_zoneadmd(const char *zone_name, zone_cmd_arg_t *arg, char *locale,
   7374     boolean_t lock)
   7375 {
   7376 	char doorpath[PATH_MAX];
   7377 	int doorfd, result;
   7378 	door_arg_t darg;
   7379 
   7380 	zoneid_t zoneid;
   7381 	uint64_t uniqid = 0;
   7382 
   7383 	zone_cmd_rval_t *rvalp;
   7384 	size_t rlen;
   7385 	char *cp, *errbuf;
   7386 
   7387 	rlen = getpagesize();
   7388 	if ((rvalp = malloc(rlen)) == NULL) {
   7389 		zerror(zone_name, gettext("failed to allocate %lu bytes: %s"),
   7390 		    rlen, strerror(errno));
   7391 		return (-1);
   7392 	}
   7393 
   7394 	if ((zoneid = getzoneidbyname(zone_name)) != ZONE_ID_UNDEFINED) {
   7395 		(void) zone_getattr(zoneid, ZONE_ATTR_UNIQID, &uniqid,
   7396 		    sizeof (uniqid));
   7397 	}
   7398 	arg->uniqid = uniqid;
   7399 	(void) strlcpy(arg->locale, locale, sizeof (arg->locale));
   7400 	if (!get_doorname(zone_name, doorpath)) {
   7401 		zerror(zone_name, gettext("alternate root path is too long"));
   7402 		free(rvalp);
   7403 		return (-1);
   7404 	}
   7405 
   7406 	/*
   7407 	 * Loop trying to start zoneadmd; if something goes seriously
   7408 	 * wrong we break out and fail.
   7409 	 */
   7410 	for (;;) {
   7411 		if (start_zoneadmd(zone_name, lock) != Z_OK)
   7412 			break;
   7413 
   7414 		if ((doorfd = open(doorpath, O_RDONLY)) < 0) {
   7415 			zperror(gettext("failed to open zone door"));
   7416 			break;
   7417 		}
   7418 
   7419 		darg.data_ptr = (char *)arg;
   7420 		darg.data_size = sizeof (*arg);
   7421 		darg.desc_ptr = NULL;
   7422 		darg.desc_num = 0;
   7423 		darg.rbuf = (char *)rvalp;
   7424 		darg.rsize = rlen;
   7425 		if (door_call(doorfd, &darg) != 0) {
   7426 			(void) close(doorfd);
   7427 			/*
   7428 			 * We'll get EBADF if the door has been revoked.
   7429 			 */
   7430 			if (errno != EBADF) {
   7431 				zperror(gettext("door_call failed"));
   7432 				break;
   7433 			}
   7434 			continue;	/* take another lap */
   7435 		}
   7436 		(void) close(doorfd);
   7437 
   7438 		if (darg.data_size == 0) {
   7439 			/* Door server is going away; kick it again. */
   7440 			continue;
   7441 		}
   7442 
   7443 		errbuf = rvalp->errbuf;
   7444 		while (*errbuf != '\0') {
   7445 			/*
   7446 			 * Remove any newlines since zerror()
   7447 			 * will append one automatically.
   7448 			 */
   7449 			cp = strchr(errbuf, '\n');
   7450 			if (cp != NULL)
   7451 				*cp = '\0';
   7452 			zerror(zone_name, "%s", errbuf);
   7453 			if (cp == NULL)
   7454 				break;
   7455 			errbuf = cp + 1;
   7456 		}
   7457 		result = rvalp->rval == 0 ? 0 : -1;
   7458 		free(rvalp);
   7459 		return (result);
   7460 	}
   7461 
   7462 	free(rvalp);
   7463 	return (-1);
   7464 }
   7465