xace: change the semantics of the return value of XACE hooks to allow

arbitrary X status codes instead of just TRUE/FALSE.

The dix layer in most cases still does not propagate the return value of
XACE hooks back to the client, however.  There is more error propagation
work to do.
This commit is contained in:
Eamon Walsh 2007-04-17 16:01:56 -04:00 • committed by Eamon Walsh
commit 9cee4ec5e6
14 changed files with 256 additions and 254 deletions

View file

@ -20,10 +20,10 @@ CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
#ifndef _XACE_H
#define _XACE_H
/* Hook return codes */
#define XaceErrorOperation 0
#define XaceAllowOperation 1
#define XaceIgnoreOperation 2
/* Special value used for ignore operation. This is a deprecated feature
* only for Security extension support. Do not use in new code.
*/
#define XaceIgnoreError BadRequest
#ifdef XACE
@ -97,10 +97,10 @@ extern void XaceCensorImage(
/* Define calls away when XACE is not being built. */
#ifdef __GNUC__
#define XaceHook(args...) XaceAllowOperation
#define XaceHook(args...) Success
#define XaceCensorImage(args...) { ; }
#else
#define XaceHook(...) XaceAllowOperation
#define XaceHook(...) Success
#define XaceCensorImage(...) { ; }
#endif