mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git
synced 2024-12-28 16:52:18 +00:00
2d470c7781
Replace the (secctx,seclen) pointer pair with a single lsm_context pointer to allow return of the LSM identifier along with the context and context length. This allows security_release_secctx() to know how to release the context. Callers have been modified to use or save the returned data from the new structure. security_secid_to_secctx() and security_lsmproc_to_secctx() will now return the length value on success instead of 0. Cc: netdev@vger.kernel.org Cc: audit@vger.kernel.org Cc: netfilter-devel@vger.kernel.org Cc: Todd Kjos <tkjos@google.com> Signed-off-by: Casey Schaufler <casey@schaufler-ca.com> [PM: subject tweak, kdoc fix, signedness fix from Dan Carpenter] Signed-off-by: Paul Moore <paul@paul-moore.com>
108 lines
2.5 KiB
C
108 lines
2.5 KiB
C
// SPDX-License-Identifier: GPL-2.0-or-later
|
|
/*
|
|
* NetLabel NETLINK Interface
|
|
*
|
|
* This file defines the NETLINK interface for the NetLabel system. The
|
|
* NetLabel system manages static and dynamic label mappings for network
|
|
* protocols such as CIPSO and RIPSO.
|
|
*
|
|
* Author: Paul Moore <paul@paul-moore.com>
|
|
*/
|
|
|
|
/*
|
|
* (c) Copyright Hewlett-Packard Development Company, L.P., 2006
|
|
*/
|
|
|
|
#include <linux/init.h>
|
|
#include <linux/types.h>
|
|
#include <linux/list.h>
|
|
#include <linux/socket.h>
|
|
#include <linux/audit.h>
|
|
#include <linux/tty.h>
|
|
#include <linux/security.h>
|
|
#include <linux/gfp.h>
|
|
#include <net/sock.h>
|
|
#include <net/netlink.h>
|
|
#include <net/genetlink.h>
|
|
#include <net/netlabel.h>
|
|
#include <asm/bug.h>
|
|
|
|
#include "netlabel_mgmt.h"
|
|
#include "netlabel_unlabeled.h"
|
|
#include "netlabel_cipso_v4.h"
|
|
#include "netlabel_calipso.h"
|
|
#include "netlabel_user.h"
|
|
|
|
/*
|
|
* NetLabel NETLINK Setup Functions
|
|
*/
|
|
|
|
/**
|
|
* netlbl_netlink_init - Initialize the NETLINK communication channel
|
|
*
|
|
* Description:
|
|
* Call out to the NetLabel components so they can register their families and
|
|
* commands with the Generic NETLINK mechanism. Returns zero on success and
|
|
* non-zero on failure.
|
|
*
|
|
*/
|
|
int __init netlbl_netlink_init(void)
|
|
{
|
|
int ret_val;
|
|
|
|
ret_val = netlbl_mgmt_genl_init();
|
|
if (ret_val != 0)
|
|
return ret_val;
|
|
|
|
ret_val = netlbl_cipsov4_genl_init();
|
|
if (ret_val != 0)
|
|
return ret_val;
|
|
|
|
ret_val = netlbl_calipso_genl_init();
|
|
if (ret_val != 0)
|
|
return ret_val;
|
|
|
|
return netlbl_unlabel_genl_init();
|
|
}
|
|
|
|
/*
|
|
* NetLabel Audit Functions
|
|
*/
|
|
|
|
/**
|
|
* netlbl_audit_start_common - Start an audit message
|
|
* @type: audit message type
|
|
* @audit_info: NetLabel audit information
|
|
*
|
|
* Description:
|
|
* Start an audit message using the type specified in @type and fill the audit
|
|
* message with some fields common to all NetLabel audit messages. Returns
|
|
* a pointer to the audit buffer on success, NULL on failure.
|
|
*
|
|
*/
|
|
struct audit_buffer *netlbl_audit_start_common(int type,
|
|
struct netlbl_audit *audit_info)
|
|
{
|
|
struct audit_buffer *audit_buf;
|
|
struct lsm_context ctx;
|
|
|
|
if (audit_enabled == AUDIT_OFF)
|
|
return NULL;
|
|
|
|
audit_buf = audit_log_start(audit_context(), GFP_ATOMIC, type);
|
|
if (audit_buf == NULL)
|
|
return NULL;
|
|
|
|
audit_log_format(audit_buf, "netlabel: auid=%u ses=%u",
|
|
from_kuid(&init_user_ns, audit_info->loginuid),
|
|
audit_info->sessionid);
|
|
|
|
if (lsmprop_is_set(&audit_info->prop) &&
|
|
security_lsmprop_to_secctx(&audit_info->prop, &ctx) > 0) {
|
|
audit_log_format(audit_buf, " subj=%s", ctx.context);
|
|
security_release_secctx(&ctx);
|
|
}
|
|
|
|
return audit_buf;
|
|
}
|