From sacadmin Mon Oct  5 07:37:43 2009
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n95Ebh9s022508;
	Mon, 5 Oct 2009 07:37:43 -0700 (PDT)
Received: (from richb@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id n95EbhRG022504;
	Mon, 5 Oct 2009 07:37:43 -0700 (PDT)
Date: Mon, 5 Oct 2009 07:37:43 -0700 (PDT)
From: Rich Burridge <richb@sac.sfbay.sun.com>
Message-Id: <200910051437.n95EbhRG022504@sac.sfbay.sun.com>
To: PSARC-record@sac.sfbay.sun.com
Subject: Python interface to privileges(5) & rbac(5) [PSARC/2009/529 FastTrack timeout 10/12/2009]
Status: RO
Content-Length: 585


Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 Python interface to privileges(5) & rbac(5)
    1.2. Name of Document Author/Supplier:
	 Author:  John Sonnenschein
    1.3  Date of This Document:
	05 October, 2009
4. Technical Description
    See the case directory for more detail

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		JDS
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From Rich.Burridge@sun.com Mon Oct  5 07:47:09 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n95El8Ho022574
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 5 Oct 2009 07:47:08 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n95El6Tp029095
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 5 Oct 2009 15:47:07 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KR100K1LQEIGJ00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 05 Oct 2009 07:47:06 -0700 (PDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KR100JM9QEHF430@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 05 Oct 2009 07:47:05 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n95El5PX008845	for
 <PSARC-ext@sun.com>; Mon, 05 Oct 2009 07:47:05 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KR100A00Q23HI00@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 05 Oct 2009 07:47:05 -0700 (PDT)
Received: from [129.146.228.20] ([unknown] [129.146.228.20])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KR1001KGQEGHS50@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 05 Oct 2009 07:47:05 -0700 (PDT)
Date: Mon, 05 Oct 2009 07:44:49 -0700
From: Rich Burridge <Rich.Burridge@sun.com>
Subject: Python interface to privileges(5) & rbac(5) [PSARC/2009/529 FastTrack
 timeout 10/12/2009]
Sender: Rich.Burridge@sun.com
To: PSARC-ext@sun.com
Cc: John Sonnenschein <John.Sonnenschein@sun.com>
Message-id: <4ACA0661.30105@sun.com>
MIME-version: 1.0
Content-type: multipart/mixed; boundary="Boundary_(ID_+7KbSsp/bz8VAF2iMkit6Q)"
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.22 (X11/20090909)
Status: RO
Content-Length: 7569

This is a multi-part message in MIME format.

--Boundary_(ID_+7KbSsp/bz8VAF2iMkit6Q)
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT

I'm sponsoring this case for John Sonnenschein. The requested
release binding is minor. The fast track times out on 10/12/2009.






--Boundary_(ID_+7KbSsp/bz8VAF2iMkit6Q)
Content-type: text/plain; name=proposal.txt
Content-transfer-encoding: 7BIT
Content-disposition: inline; filename=proposal.txt

Template Version: @(#)sac_nextcase 1.64 07/13/07 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
   1.1. Project/Component Working Name:
	 Python interface to privileges(5) & rbac(5)
   1.2. Name of Document Author/Supplier:
	 Author:  John Sonnenschein
   1.3  Date of This Document:
	05 October, 2009
4. Technical Description

4.1.  Introduction

   Forthcoming work requires access to the privileges(5) and family of
   functions and user/exec/auth attr databases from Python. This case 
   introduces the privileges and rbac Python modules. This case will
   deliver for Python 2.6 as well as 2.4 despite it's obsolescence, such
   that it may be used in projects depending on 2.4 ( such as pkg(5) )

   minor binding is requested.

4.2. 

   Python docstrings will reflect the following interface descriptions:

   Python 'privileges' module
   --------------------------
   Classification is 'Committed'. 
   Provides functions for interacting with the Solaris privileges(5) framework

   FUNCTIONS

   setppriv: 
   Facilitates setting the permitted/inheritable/limit/effective privileges set
      Arguments:
           one of (PRIV_ON|PRIV_OFF|PRIV_SET), 
           one of (PRIV_PERMITTED|PRIV_INHERITABLE|PRIV_LIMIT|PRIV_EFFECTIVE),
           set of privileges: a Python list of strings
      Returns: True on success, False on failure

      getppriv:
         Arguments: 
            one of (PRIV_PERMITTED|PRIV_INHERITABLE|PRIV_LIMIT|PRIV_EFFECTIVE)
         Returns: a Python list of strings

      priv_ineffect:
         Arguments:
            a Python string
         Returns: True if the privilege is in effect, False otherwise

      priv_inverse:
         Arguments:
            a Python list of strings
         Returns:
            a Python list of strings, an inverted priv set from argument 0

   Many of the privileges(5) functions are not provided, as standard Python
   set operations provide the functionality natively.

   Python 'rbac' module
   --------------------
   Classification is 'Committed'
   Provides functions for interacting with the Solaris RBAC(5) framework
   via interfacing with the user_attr, auth_attr & exec_attr databases

   CLASSES

   authattr - provides interfaces to the auth_attr database
      may be iterated over to return all auth_attr entries,
      ie "for entry in authattr:"

   FUNCTIONS
      setauthattr:
      "rewinds" the auth_attr functions to the first entry in the db.
      Called automatically by the constructor
         Arguments: None
         Returns: None

      endauthattr:
      closes the auth_attr database, cleans up storage. called
      automatically by the destructor
         Arguments: None
         Returns: None

      chkauthattr:
      verifies if a user has a given authorization.
         Arguments: 2 Python strings, 'authname' and 'username'
         Returns: True if the user is authorized, False otherwise

      getauthattr:
      return one entry from the auth_attr database
      Arguments: None
      Returns: a dict representing the authattr_t struct, explained thusly:
             "name": Authorization Name,
             "res1": reserved,
             "res2": reserved,
             "short": Short Description,
             "long": Long Description,
             "attributes": A Python dict keyed by attribute & valued as
                either a list or a string depending on value

      getauthnam:
      searches the auth_attr database for a given authorization name
      Arguments: a Python string containing the auth name
      Returns: an auth_attr entry in the form of a dict, explained as
         above

   execattr - provides interfaces to the exec_attr database
      may be iterated over to return all exec_attr entries

   FUNCTIONS
      setexecattr:
      "rewinds" the exec_attr functions to the first entry in the db.
      Called automatically by the constructor
         Arguments: None
         Returns: None

      endexecattr:
      closes the exec_attr database, cleans up storage. called
      automatically by the destructor
         Arguments: None
         Returns: None

      getexecattr:
      return a single exec_attr entry
      Arguments: None
      Returns: a dict representation of an execattr_t struct:
             "name": Authorization Name,
             "type": Profile Type
             "policy": Policy attributes are relevant in
             "res1": reserved,
             "res2": reserved,
             "id": unique identifier,
             "attributes": A Python dict keyed by attribute & valued as
                either a list or a string depending on value

      getexecuser: returns a list of entries that match the type and id 
      arguments and have a profile that has been assigned to the user specified
      by username
      Arguments: 3 Python strings, 'username', 'type', and 'id'
      Returns: a Python list with elements of the dict described above

      getexecprof:returns a linked list of entries that match the type and id
      arguments and have the profile specified by the profname argument. 
      Arguments: 3 Python strings, 'profname', 'type', and 'id'
      Returns: a Python list with elements of the dict described above

   userattr - provides interfaces to the user_attr database
      may be iterated over to return all user_attr entries

   FUNCTIONS
      setuserattr:
      "rewinds" the user_attr functions to the first entry in the db.
      Called automatically by the constructor
         Arguments: None
         Returns: None

      enduserattr:
      closes the user_attr database, cleans up storage. called
      automatically by the destructor
         Arguments: None
         Returns: None

      getuserattr:
      return a single user_attr entry
         Arguments: None
         Returns: a dict representation of a userattr_t struct:
            "name": username
            "qualifier": reserved
            "res1": reserved
            "res2": reserved
            "attributes": A Python dict keyed by attribute & valued as
                either a list or a string depending on value

      fgetuserattr:
      return a single user_attr entry from a file, bypassing nsswitch.conf
         Arguments: a Python string representing the path of the file
         Returns: a userattr_t struct dict as above

      getusernam: searches for a user_attr entry with a given user name
         Arguments: a Python string
         Returns: a userattr_t struct dict as above

     getuseruid: searches for a user_attr entry with a given uid
         Arguments: a Python Int
         Returns: a userattr_t struct dict as above
	 
4.3.  References

 PSARC/2005/532 - Python migration from /usr/sfw to /usr and upgrade to v2.4.x
 PSARC/2008/243 - Python interface to ucred_get(3C)/getpeerucred(3C)
 PSARC/2008/514 Python interface to dlpi(7P)

6. Resources and Schedule
   6.4. Steering Committee requested information
  	6.4.1. Consolidation C-team Name:
		JDS
   6.5. ARC review type: FastTrack
   6.6. ARC Exposure: open

--Boundary_(ID_+7KbSsp/bz8VAF2iMkit6Q)--

From gdamore@sun.com Wed Oct  7 08:33:39 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n97FXc7e001120
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 7 Oct 2009 08:33:38 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n97FXUEq017122
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 7 Oct 2009 16:33:37 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KR500G05HW0ZV00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 07 Oct 2009 09:33:36 -0600 (MDT)
Received: from sca-es-mail-2.sun.com ([192.18.43.133])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KR500LSOHW0IP82@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 07 Oct 2009 09:33:36 -0600 (MDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n97FXaCk006440	for
 <PSARC-ext@sun.com>; Wed, 07 Oct 2009 08:33:36 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KR500E00HEMS400@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 07 Oct 2009 08:33:36 -0700 (PDT)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KR500JIDHVMT490@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 07 Oct 2009 08:33:22 -0700 (PDT)
Date: Wed, 07 Oct 2009 08:33:21 -0700
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: Python interface to privileges(5) & rbac(5) [PSARC/2009/529
 FastTrack timeout 10/12/2009]
In-reply-to: <4ACA0661.30105@sun.com>
Sender: Garrett.Damore@sun.com
To: Rich Burridge <Rich.Burridge@sun.com>
Cc: PSARC-ext@sun.com, John Sonnenschein <John.Sonnenschein@sun.com>
Message-id: <4ACCB4C1.5050502@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4ACA0661.30105@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 390

Rich Burridge wrote:
> I'm sponsoring this case for John Sonnenschein. The requested
> release binding is minor. The fast track times out on 10/12/2009.
>
>

I'm just starting to teach myself Python, but this case looks fairly 
straight-forward.  As far as I can see, it just provides thin wrappers 
over the existing C API for privileges and rbac.  With that in mind, +1.

    -- Garrett


