blob: 75686d53df074fcf542d5ae11518528148d4a0e7 [file] [log] [blame]
Venkat Yekkirala7420ed22006-08-04 23:17:57 -07001/*
2 * SELinux interface to the NetLabel subsystem
3 *
Paul Moore82c21bf2011-08-01 11:10:33 +00004 * Author: Paul Moore <paul@paul-moore.com>
Venkat Yekkirala7420ed22006-08-04 23:17:57 -07005 *
6 */
7
8/*
9 * (c) Copyright Hewlett-Packard Development Company, L.P., 2006
10 *
11 * This program is free software; you can redistribute it and/or modify
12 * it under the terms of the GNU General Public License as published by
13 * the Free Software Foundation; either version 2 of the License, or
14 * (at your option) any later version.
15 *
16 * This program is distributed in the hope that it will be useful,
17 * but WITHOUT ANY WARRANTY; without even the implied warranty of
18 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See
19 * the GNU General Public License for more details.
20 *
21 * You should have received a copy of the GNU General Public License
22 * along with this program; if not, write to the Free Software
23 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
24 *
25 */
26
27#ifndef _SELINUX_NETLABEL_H_
28#define _SELINUX_NETLABEL_H_
29
Paul Moore7a0e1d62006-08-29 17:56:04 -070030#include <linux/types.h>
31#include <linux/fs.h>
32#include <linux/net.h>
33#include <linux/skbuff.h>
34#include <net/sock.h>
Paul Moore389fb8002009-03-27 17:10:34 -040035#include <net/request_sock.h>
Paul Moore7a0e1d62006-08-29 17:56:04 -070036
37#include "avc.h"
38#include "objsec.h"
39
Venkat Yekkirala7420ed22006-08-04 23:17:57 -070040#ifdef CONFIG_NETLABEL
41void selinux_netlbl_cache_invalidate(void);
Paul Moore5778eab2007-02-28 15:14:22 -050042
Huw Daviesa04e71f2016-06-27 15:06:16 -040043void selinux_netlbl_err(struct sk_buff *skb, u16 family, int error,
44 int gateway);
Paul Mooredfaebe92008-10-10 10:16:31 -040045
Eric Parisdd3e7832010-04-07 15:08:46 -040046void selinux_netlbl_sk_security_free(struct sk_security_struct *sksec);
47void selinux_netlbl_sk_security_reset(struct sk_security_struct *sksec);
Paul Moore5778eab2007-02-28 15:14:22 -050048
Paul Moore75e22912008-01-29 08:38:04 -050049int selinux_netlbl_skbuff_getsid(struct sk_buff *skb,
50 u16 family,
Paul Moore220deb92008-01-29 08:38:23 -050051 u32 *type,
Paul Moore75e22912008-01-29 08:38:04 -050052 u32 *sid);
Paul Moore948bf852008-10-10 10:16:32 -040053int selinux_netlbl_skbuff_setsid(struct sk_buff *skb,
54 u16 family,
55 u32 sid);
Paul Moore5778eab2007-02-28 15:14:22 -050056
Paul Moore389fb8002009-03-27 17:10:34 -040057int selinux_netlbl_inet_conn_request(struct request_sock *req, u16 family);
58void selinux_netlbl_inet_csk_clone(struct sock *sk, u16 family);
59int selinux_netlbl_socket_post_create(struct sock *sk, u16 family);
Paul Moore5778eab2007-02-28 15:14:22 -050060int selinux_netlbl_sock_rcv_skb(struct sk_security_struct *sksec,
61 struct sk_buff *skb,
Paul Moore75e22912008-01-29 08:38:04 -050062 u16 family,
Thomas Liu2bf49692009-07-14 12:14:09 -040063 struct common_audit_data *ad);
Paul Mooref8687af2006-10-30 15:22:15 -080064int selinux_netlbl_socket_setsockopt(struct socket *sock,
65 int level,
66 int optname);
Paul Moore014ab192008-10-10 10:16:33 -040067int selinux_netlbl_socket_connect(struct sock *sk, struct sockaddr *addr);
68
Venkat Yekkirala7420ed22006-08-04 23:17:57 -070069#else
70static inline void selinux_netlbl_cache_invalidate(void)
71{
72 return;
73}
74
Paul Mooredfaebe92008-10-10 10:16:31 -040075static inline void selinux_netlbl_err(struct sk_buff *skb,
Huw Daviesa04e71f2016-06-27 15:06:16 -040076 u16 family,
Paul Mooredfaebe92008-10-10 10:16:31 -040077 int error,
78 int gateway)
79{
80 return;
81}
82
Paul Moore6c5b3fc2008-10-10 10:16:33 -040083static inline void selinux_netlbl_sk_security_free(
Eric Parisdd3e7832010-04-07 15:08:46 -040084 struct sk_security_struct *sksec)
Paul Moore6c5b3fc2008-10-10 10:16:33 -040085{
86 return;
87}
88
Paul Moore5778eab2007-02-28 15:14:22 -050089static inline void selinux_netlbl_sk_security_reset(
Eric Parisdd3e7832010-04-07 15:08:46 -040090 struct sk_security_struct *sksec)
Paul Moore5778eab2007-02-28 15:14:22 -050091{
92 return;
93}
Paul Moore5778eab2007-02-28 15:14:22 -050094
Paul Moore3de4bab2006-11-17 17:38:54 -050095static inline int selinux_netlbl_skbuff_getsid(struct sk_buff *skb,
Paul Moore75e22912008-01-29 08:38:04 -050096 u16 family,
Paul Moore220deb92008-01-29 08:38:23 -050097 u32 *type,
Paul Moore3de4bab2006-11-17 17:38:54 -050098 u32 *sid)
99{
Paul Moore220deb92008-01-29 08:38:23 -0500100 *type = NETLBL_NLTYPE_NONE;
Paul Moore3de4bab2006-11-17 17:38:54 -0500101 *sid = SECSID_NULL;
102 return 0;
103}
Paul Moore948bf852008-10-10 10:16:32 -0400104static inline int selinux_netlbl_skbuff_setsid(struct sk_buff *skb,
105 u16 family,
106 u32 sid)
107{
108 return 0;
109}
Paul Moore3de4bab2006-11-17 17:38:54 -0500110
Paul Moore014ab192008-10-10 10:16:33 -0400111static inline int selinux_netlbl_conn_setsid(struct sock *sk,
112 struct sockaddr *addr)
113{
114 return 0;
115}
116
Paul Moore389fb8002009-03-27 17:10:34 -0400117static inline int selinux_netlbl_inet_conn_request(struct request_sock *req,
118 u16 family)
Paul Moore5778eab2007-02-28 15:14:22 -0500119{
120 return 0;
121}
Paul Moore389fb8002009-03-27 17:10:34 -0400122static inline void selinux_netlbl_inet_csk_clone(struct sock *sk, u16 family)
123{
124 return;
125}
126static inline int selinux_netlbl_socket_post_create(struct sock *sk,
127 u16 family)
Paul Moore5778eab2007-02-28 15:14:22 -0500128{
129 return 0;
130}
Venkat Yekkirala7420ed22006-08-04 23:17:57 -0700131static inline int selinux_netlbl_sock_rcv_skb(struct sk_security_struct *sksec,
132 struct sk_buff *skb,
Paul Moore75e22912008-01-29 08:38:04 -0500133 u16 family,
Thomas Liu2bf49692009-07-14 12:14:09 -0400134 struct common_audit_data *ad)
Venkat Yekkirala7420ed22006-08-04 23:17:57 -0700135{
136 return 0;
137}
Paul Mooref8687af2006-10-30 15:22:15 -0800138static inline int selinux_netlbl_socket_setsockopt(struct socket *sock,
139 int level,
140 int optname)
141{
142 return 0;
143}
Paul Moore014ab192008-10-10 10:16:33 -0400144static inline int selinux_netlbl_socket_connect(struct sock *sk,
145 struct sockaddr *addr)
146{
147 return 0;
148}
Venkat Yekkirala7420ed22006-08-04 23:17:57 -0700149#endif /* CONFIG_NETLABEL */
150
151#endif