aboutsummaryrefslogtreecommitdiffstats
path: root/include/linux/security.h
diff options
context:
space:
mode:
authorDavid Quigley <dpquigl@davequigley.com>2013-05-22 12:50:35 -0400
committerTrond Myklebust <Trond.Myklebust@netapp.com>2013-06-08 16:20:11 -0400
commit746df9b59c8a5f162c907796c7295d3c4c0d8995 (patch)
tree6c0e7ae018bfb33f482afdc74d0c77d6b9edd152 /include/linux/security.h
parentd47be3dfecaf20255af89a57460285c82d5271ad (diff)
Security: Add Hook to test if the particular xattr is part of a MAC model.
The interface to request security labels from user space is the xattr interface. When requesting the security label from an NFS server it is important to make sure the requested xattr actually is a MAC label. This allows us to make sure that we get the desired semantics from the attribute instead of something else such as capabilities or a time based LSM. Acked-by: Eric Paris <eparis@redhat.com> Acked-by: James Morris <james.l.morris@oracle.com> Signed-off-by: Matthew N. Dodd <Matthew.Dodd@sparta.com> Signed-off-by: Miguel Rodel Felipe <Rodel_FM@dsi.a-star.edu.sg> Signed-off-by: Phua Eu Gene <PHUA_Eu_Gene@dsi.a-star.edu.sg> Signed-off-by: Khin Mi Mi Aung <Mi_Mi_AUNG@dsi.a-star.edu.sg> Signed-off-by: Trond Myklebust <Trond.Myklebust@netapp.com>
Diffstat (limited to 'include/linux/security.h')
-rw-r--r--include/linux/security.h14
1 files changed, 14 insertions, 0 deletions
diff --git a/include/linux/security.h b/include/linux/security.h
index c2af46264ae0..cff3e4fc4281 100644
--- a/include/linux/security.h
+++ b/include/linux/security.h
@@ -1323,6 +1323,13 @@ static inline void security_free_mnt_opts(struct security_mnt_opts *opts)
1323 * @pages contains the number of pages. 1323 * @pages contains the number of pages.
1324 * Return 0 if permission is granted. 1324 * Return 0 if permission is granted.
1325 * 1325 *
1326 * @ismaclabel:
1327 * Check if the extended attribute specified by @name
1328 * represents a MAC label. Returns 1 if name is a MAC
1329 * attribute otherwise returns 0.
1330 * @name full extended attribute name to check against
1331 * LSM as a MAC label.
1332 *
1326 * @secid_to_secctx: 1333 * @secid_to_secctx:
1327 * Convert secid to security context. If secdata is NULL the length of 1334 * Convert secid to security context. If secdata is NULL the length of
1328 * the result will be returned in seclen, but no secdata will be returned. 1335 * the result will be returned in seclen, but no secdata will be returned.
@@ -1604,6 +1611,7 @@ struct security_operations {
1604 1611
1605 int (*getprocattr) (struct task_struct *p, char *name, char **value); 1612 int (*getprocattr) (struct task_struct *p, char *name, char **value);
1606 int (*setprocattr) (struct task_struct *p, char *name, void *value, size_t size); 1613 int (*setprocattr) (struct task_struct *p, char *name, void *value, size_t size);
1614 int (*ismaclabel) (const char *name);
1607 int (*secid_to_secctx) (u32 secid, char **secdata, u32 *seclen); 1615 int (*secid_to_secctx) (u32 secid, char **secdata, u32 *seclen);
1608 int (*secctx_to_secid) (const char *secdata, u32 seclen, u32 *secid); 1616 int (*secctx_to_secid) (const char *secdata, u32 seclen, u32 *secid);
1609 void (*release_secctx) (char *secdata, u32 seclen); 1617 void (*release_secctx) (char *secdata, u32 seclen);
@@ -1857,6 +1865,7 @@ void security_d_instantiate(struct dentry *dentry, struct inode *inode);
1857int security_getprocattr(struct task_struct *p, char *name, char **value); 1865int security_getprocattr(struct task_struct *p, char *name, char **value);
1858int security_setprocattr(struct task_struct *p, char *name, void *value, size_t size); 1866int security_setprocattr(struct task_struct *p, char *name, void *value, size_t size);
1859int security_netlink_send(struct sock *sk, struct sk_buff *skb); 1867int security_netlink_send(struct sock *sk, struct sk_buff *skb);
1868int security_ismaclabel(const char *name);
1860int security_secid_to_secctx(u32 secid, char **secdata, u32 *seclen); 1869int security_secid_to_secctx(u32 secid, char **secdata, u32 *seclen);
1861int security_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid); 1870int security_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid);
1862void security_release_secctx(char *secdata, u32 seclen); 1871void security_release_secctx(char *secdata, u32 seclen);
@@ -2547,6 +2556,11 @@ static inline int security_netlink_send(struct sock *sk, struct sk_buff *skb)
2547 return cap_netlink_send(sk, skb); 2556 return cap_netlink_send(sk, skb);
2548} 2557}
2549 2558
2559static inline int security_ismaclabel(const char *name)
2560{
2561 return 0;
2562}
2563
2550static inline int security_secid_to_secctx(u32 secid, char **secdata, u32 *seclen) 2564static inline int security_secid_to_secctx(u32 secid, char **secdata, u32 *seclen)
2551{ 2565{
2552 return -EOPNOTSUPP; 2566 return -EOPNOTSUPP;