123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171 |
- /*
- * SELinux interface to the NetLabel subsystem
- *
- * Author: Paul Moore <paul@paul-moore.com>
- *
- */
- /*
- * (c) Copyright Hewlett-Packard Development Company, L.P., 2006
- *
- * This program is free software; you can redistribute it and/or modify
- * it under the terms of the GNU General Public License as published by
- * the Free Software Foundation; either version 2 of the License, or
- * (at your option) any later version.
- *
- * This program is distributed in the hope that it will be useful,
- * but WITHOUT ANY WARRANTY; without even the implied warranty of
- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See
- * the GNU General Public License for more details.
- *
- * You should have received a copy of the GNU General Public License
- * along with this program. If not, see <http://www.gnu.org/licenses/>.
- *
- */
- #ifndef _SELINUX_NETLABEL_H_
- #define _SELINUX_NETLABEL_H_
- #include <linux/types.h>
- #include <linux/fs.h>
- #include <linux/net.h>
- #include <linux/skbuff.h>
- #include <net/sock.h>
- #include <net/request_sock.h>
- #include <net/sctp/structs.h>
- #include "avc.h"
- #include "objsec.h"
- #ifdef CONFIG_NETLABEL
- void selinux_netlbl_cache_invalidate(void);
- void selinux_netlbl_err(struct sk_buff *skb, u16 family, int error,
- int gateway);
- void selinux_netlbl_sk_security_free(struct sk_security_struct *sksec);
- void selinux_netlbl_sk_security_reset(struct sk_security_struct *sksec);
- int selinux_netlbl_skbuff_getsid(struct sk_buff *skb,
- u16 family,
- u32 *type,
- u32 *sid);
- int selinux_netlbl_skbuff_setsid(struct sk_buff *skb,
- u16 family,
- u32 sid);
- int selinux_netlbl_sctp_assoc_request(struct sctp_endpoint *ep,
- struct sk_buff *skb);
- int selinux_netlbl_inet_conn_request(struct request_sock *req, u16 family);
- void selinux_netlbl_inet_csk_clone(struct sock *sk, u16 family);
- void selinux_netlbl_sctp_sk_clone(struct sock *sk, struct sock *newsk);
- int selinux_netlbl_socket_post_create(struct sock *sk, u16 family);
- int selinux_netlbl_sock_rcv_skb(struct sk_security_struct *sksec,
- struct sk_buff *skb,
- u16 family,
- struct common_audit_data *ad);
- int selinux_netlbl_socket_setsockopt(struct socket *sock,
- int level,
- int optname);
- int selinux_netlbl_socket_connect(struct sock *sk, struct sockaddr *addr);
- int selinux_netlbl_socket_connect_locked(struct sock *sk,
- struct sockaddr *addr);
- #else
- static inline void selinux_netlbl_cache_invalidate(void)
- {
- return;
- }
- static inline void selinux_netlbl_err(struct sk_buff *skb,
- u16 family,
- int error,
- int gateway)
- {
- return;
- }
- static inline void selinux_netlbl_sk_security_free(
- struct sk_security_struct *sksec)
- {
- return;
- }
- static inline void selinux_netlbl_sk_security_reset(
- struct sk_security_struct *sksec)
- {
- return;
- }
- static inline int selinux_netlbl_skbuff_getsid(struct sk_buff *skb,
- u16 family,
- u32 *type,
- u32 *sid)
- {
- *type = NETLBL_NLTYPE_NONE;
- *sid = SECSID_NULL;
- return 0;
- }
- static inline int selinux_netlbl_skbuff_setsid(struct sk_buff *skb,
- u16 family,
- u32 sid)
- {
- return 0;
- }
- static inline int selinux_netlbl_conn_setsid(struct sock *sk,
- struct sockaddr *addr)
- {
- return 0;
- }
- static inline int selinux_netlbl_sctp_assoc_request(struct sctp_endpoint *ep,
- struct sk_buff *skb)
- {
- return 0;
- }
- static inline int selinux_netlbl_inet_conn_request(struct request_sock *req,
- u16 family)
- {
- return 0;
- }
- static inline void selinux_netlbl_inet_csk_clone(struct sock *sk, u16 family)
- {
- return;
- }
- static inline void selinux_netlbl_sctp_sk_clone(struct sock *sk,
- struct sock *newsk)
- {
- return;
- }
- static inline int selinux_netlbl_socket_post_create(struct sock *sk,
- u16 family)
- {
- return 0;
- }
- static inline int selinux_netlbl_sock_rcv_skb(struct sk_security_struct *sksec,
- struct sk_buff *skb,
- u16 family,
- struct common_audit_data *ad)
- {
- return 0;
- }
- static inline int selinux_netlbl_socket_setsockopt(struct socket *sock,
- int level,
- int optname)
- {
- return 0;
- }
- static inline int selinux_netlbl_socket_connect(struct sock *sk,
- struct sockaddr *addr)
- {
- return 0;
- }
- static inline int selinux_netlbl_socket_connect_locked(struct sock *sk,
- struct sockaddr *addr)
- {
- return 0;
- }
- #endif /* CONFIG_NETLABEL */
- #endif
|