diff options
| author | Chad Sellers <csellers@tresys.com> | 2006-11-06 12:38:16 -0500 |
|---|---|---|
| committer | James Morris <jmorris@namei.org> | 2006-11-28 12:04:36 -0500 |
| commit | 5c45899879e8caadb78f04c9c639f4c2025b9f00 (patch) | |
| tree | ee47228ccb816e523ac1051cfe41927059bc5ef9 | |
| parent | 5a64d4438ed1e759ccd30d9e90842bf360f19298 (diff) | |
SELinux: export object class and permission definitions
Moves the definition of the 3 structs containing object class and
permission definitions from avc.c to avc_ss.h so that the security
server can access them for validation on policy load. This also adds
a new struct type, defined_classes_perms_t, suitable for allowing the
security server to access these data structures from the avc.
Signed-off-by: Chad Sellers <csellers@tresys.com>
Acked-by: Stephen Smalley <sds@tycho.nsa.gov>
Signed-off-by: James Morris <jmorris@namei.org>
| -rw-r--r-- | security/selinux/avc.c | 23 | ||||
| -rw-r--r-- | security/selinux/include/avc_ss.h | 24 |
2 files changed, 35 insertions, 12 deletions
diff --git a/security/selinux/avc.c b/security/selinux/avc.c index a300702da527..74c0319c417e 100644 --- a/security/selinux/avc.c +++ b/security/selinux/avc.c | |||
| @@ -32,12 +32,7 @@ | |||
| 32 | #include "avc.h" | 32 | #include "avc.h" |
| 33 | #include "avc_ss.h" | 33 | #include "avc_ss.h" |
| 34 | 34 | ||
| 35 | static const struct av_perm_to_string | 35 | static const struct av_perm_to_string av_perm_to_string[] = { |
| 36 | { | ||
| 37 | u16 tclass; | ||
| 38 | u32 value; | ||
| 39 | const char *name; | ||
| 40 | } av_perm_to_string[] = { | ||
| 41 | #define S_(c, v, s) { c, v, s }, | 36 | #define S_(c, v, s) { c, v, s }, |
| 42 | #include "av_perm_to_string.h" | 37 | #include "av_perm_to_string.h" |
| 43 | #undef S_ | 38 | #undef S_ |
| @@ -57,17 +52,21 @@ static const char *class_to_string[] = { | |||
| 57 | #undef TE_ | 52 | #undef TE_ |
| 58 | #undef S_ | 53 | #undef S_ |
| 59 | 54 | ||
| 60 | static const struct av_inherit | 55 | static const struct av_inherit av_inherit[] = { |
| 61 | { | ||
| 62 | u16 tclass; | ||
| 63 | const char **common_pts; | ||
| 64 | u32 common_base; | ||
| 65 | } av_inherit[] = { | ||
| 66 | #define S_(c, i, b) { c, common_##i##_perm_to_string, b }, | 56 | #define S_(c, i, b) { c, common_##i##_perm_to_string, b }, |
| 67 | #include "av_inherit.h" | 57 | #include "av_inherit.h" |
| 68 | #undef S_ | 58 | #undef S_ |
| 69 | }; | 59 | }; |
| 70 | 60 | ||
| 61 | const struct selinux_class_perm selinux_class_perm = { | ||
| 62 | av_perm_to_string, | ||
| 63 | ARRAY_SIZE(av_perm_to_string), | ||
| 64 | class_to_string, | ||
| 65 | ARRAY_SIZE(class_to_string), | ||
| 66 | av_inherit, | ||
| 67 | ARRAY_SIZE(av_inherit) | ||
| 68 | }; | ||
| 69 | |||
| 71 | #define AVC_CACHE_SLOTS 512 | 70 | #define AVC_CACHE_SLOTS 512 |
| 72 | #define AVC_DEF_CACHE_THRESHOLD 512 | 71 | #define AVC_DEF_CACHE_THRESHOLD 512 |
| 73 | #define AVC_CACHE_RECLAIM 16 | 72 | #define AVC_CACHE_RECLAIM 16 |
diff --git a/security/selinux/include/avc_ss.h b/security/selinux/include/avc_ss.h index 450a2831e2e3..ff869e8b6f4a 100644 --- a/security/selinux/include/avc_ss.h +++ b/security/selinux/include/avc_ss.h | |||
| @@ -10,5 +10,29 @@ | |||
| 10 | 10 | ||
| 11 | int avc_ss_reset(u32 seqno); | 11 | int avc_ss_reset(u32 seqno); |
| 12 | 12 | ||
| 13 | struct av_perm_to_string | ||
| 14 | { | ||
| 15 | u16 tclass; | ||
| 16 | u32 value; | ||
| 17 | const char *name; | ||
| 18 | }; | ||
| 19 | |||
| 20 | struct av_inherit | ||
| 21 | { | ||
| 22 | u16 tclass; | ||
| 23 | const char **common_pts; | ||
| 24 | u32 common_base; | ||
| 25 | }; | ||
| 26 | |||
| 27 | struct selinux_class_perm | ||
| 28 | { | ||
| 29 | const struct av_perm_to_string *av_perm_to_string; | ||
| 30 | u32 av_pts_len; | ||
| 31 | const char **class_to_string; | ||
| 32 | u32 cts_len; | ||
| 33 | const struct av_inherit *av_inherit; | ||
| 34 | u32 av_inherit_len; | ||
| 35 | }; | ||
| 36 | |||
| 13 | #endif /* _SELINUX_AVC_SS_H_ */ | 37 | #endif /* _SELINUX_AVC_SS_H_ */ |
| 14 | 38 | ||
