18c2ecf20Sopenharmony_ci/* SPDX-License-Identifier: GPL-2.0-or-later */
28c2ecf20Sopenharmony_ci/*
38c2ecf20Sopenharmony_ci * SELinux interface to the NetLabel subsystem
48c2ecf20Sopenharmony_ci *
58c2ecf20Sopenharmony_ci * Author: Paul Moore <paul@paul-moore.com>
68c2ecf20Sopenharmony_ci */
78c2ecf20Sopenharmony_ci
88c2ecf20Sopenharmony_ci/*
98c2ecf20Sopenharmony_ci * (c) Copyright Hewlett-Packard Development Company, L.P., 2006
108c2ecf20Sopenharmony_ci */
118c2ecf20Sopenharmony_ci
128c2ecf20Sopenharmony_ci#ifndef _SELINUX_NETLABEL_H_
138c2ecf20Sopenharmony_ci#define _SELINUX_NETLABEL_H_
148c2ecf20Sopenharmony_ci
158c2ecf20Sopenharmony_ci#include <linux/types.h>
168c2ecf20Sopenharmony_ci#include <linux/fs.h>
178c2ecf20Sopenharmony_ci#include <linux/net.h>
188c2ecf20Sopenharmony_ci#include <linux/skbuff.h>
198c2ecf20Sopenharmony_ci#include <net/sock.h>
208c2ecf20Sopenharmony_ci#include <net/request_sock.h>
218c2ecf20Sopenharmony_ci#include <net/sctp/structs.h>
228c2ecf20Sopenharmony_ci
238c2ecf20Sopenharmony_ci#include "avc.h"
248c2ecf20Sopenharmony_ci#include "objsec.h"
258c2ecf20Sopenharmony_ci
268c2ecf20Sopenharmony_ci#ifdef CONFIG_NETLABEL
278c2ecf20Sopenharmony_civoid selinux_netlbl_cache_invalidate(void);
288c2ecf20Sopenharmony_ci
298c2ecf20Sopenharmony_civoid selinux_netlbl_err(struct sk_buff *skb, u16 family, int error,
308c2ecf20Sopenharmony_ci			int gateway);
318c2ecf20Sopenharmony_ci
328c2ecf20Sopenharmony_civoid selinux_netlbl_sk_security_free(struct sk_security_struct *sksec);
338c2ecf20Sopenharmony_civoid selinux_netlbl_sk_security_reset(struct sk_security_struct *sksec);
348c2ecf20Sopenharmony_ci
358c2ecf20Sopenharmony_ciint selinux_netlbl_skbuff_getsid(struct sk_buff *skb,
368c2ecf20Sopenharmony_ci				 u16 family,
378c2ecf20Sopenharmony_ci				 u32 *type,
388c2ecf20Sopenharmony_ci				 u32 *sid);
398c2ecf20Sopenharmony_ciint selinux_netlbl_skbuff_setsid(struct sk_buff *skb,
408c2ecf20Sopenharmony_ci				 u16 family,
418c2ecf20Sopenharmony_ci				 u32 sid);
428c2ecf20Sopenharmony_ciint selinux_netlbl_sctp_assoc_request(struct sctp_endpoint *ep,
438c2ecf20Sopenharmony_ci				     struct sk_buff *skb);
448c2ecf20Sopenharmony_ciint selinux_netlbl_inet_conn_request(struct request_sock *req, u16 family);
458c2ecf20Sopenharmony_civoid selinux_netlbl_inet_csk_clone(struct sock *sk, u16 family);
468c2ecf20Sopenharmony_civoid selinux_netlbl_sctp_sk_clone(struct sock *sk, struct sock *newsk);
478c2ecf20Sopenharmony_ciint selinux_netlbl_socket_post_create(struct sock *sk, u16 family);
488c2ecf20Sopenharmony_ciint selinux_netlbl_sock_rcv_skb(struct sk_security_struct *sksec,
498c2ecf20Sopenharmony_ci				struct sk_buff *skb,
508c2ecf20Sopenharmony_ci				u16 family,
518c2ecf20Sopenharmony_ci				struct common_audit_data *ad);
528c2ecf20Sopenharmony_ciint selinux_netlbl_socket_setsockopt(struct socket *sock,
538c2ecf20Sopenharmony_ci				     int level,
548c2ecf20Sopenharmony_ci				     int optname);
558c2ecf20Sopenharmony_ciint selinux_netlbl_socket_connect(struct sock *sk, struct sockaddr *addr);
568c2ecf20Sopenharmony_ciint selinux_netlbl_socket_connect_locked(struct sock *sk,
578c2ecf20Sopenharmony_ci					 struct sockaddr *addr);
588c2ecf20Sopenharmony_ci
598c2ecf20Sopenharmony_ci#else
608c2ecf20Sopenharmony_cistatic inline void selinux_netlbl_cache_invalidate(void)
618c2ecf20Sopenharmony_ci{
628c2ecf20Sopenharmony_ci	return;
638c2ecf20Sopenharmony_ci}
648c2ecf20Sopenharmony_ci
658c2ecf20Sopenharmony_cistatic inline void selinux_netlbl_err(struct sk_buff *skb,
668c2ecf20Sopenharmony_ci				      u16 family,
678c2ecf20Sopenharmony_ci				      int error,
688c2ecf20Sopenharmony_ci				      int gateway)
698c2ecf20Sopenharmony_ci{
708c2ecf20Sopenharmony_ci	return;
718c2ecf20Sopenharmony_ci}
728c2ecf20Sopenharmony_ci
738c2ecf20Sopenharmony_cistatic inline void selinux_netlbl_sk_security_free(
748c2ecf20Sopenharmony_ci					       struct sk_security_struct *sksec)
758c2ecf20Sopenharmony_ci{
768c2ecf20Sopenharmony_ci	return;
778c2ecf20Sopenharmony_ci}
788c2ecf20Sopenharmony_ci
798c2ecf20Sopenharmony_cistatic inline void selinux_netlbl_sk_security_reset(
808c2ecf20Sopenharmony_ci					       struct sk_security_struct *sksec)
818c2ecf20Sopenharmony_ci{
828c2ecf20Sopenharmony_ci	return;
838c2ecf20Sopenharmony_ci}
848c2ecf20Sopenharmony_ci
858c2ecf20Sopenharmony_cistatic inline int selinux_netlbl_skbuff_getsid(struct sk_buff *skb,
868c2ecf20Sopenharmony_ci					       u16 family,
878c2ecf20Sopenharmony_ci					       u32 *type,
888c2ecf20Sopenharmony_ci					       u32 *sid)
898c2ecf20Sopenharmony_ci{
908c2ecf20Sopenharmony_ci	*type = NETLBL_NLTYPE_NONE;
918c2ecf20Sopenharmony_ci	*sid = SECSID_NULL;
928c2ecf20Sopenharmony_ci	return 0;
938c2ecf20Sopenharmony_ci}
948c2ecf20Sopenharmony_cistatic inline int selinux_netlbl_skbuff_setsid(struct sk_buff *skb,
958c2ecf20Sopenharmony_ci					       u16 family,
968c2ecf20Sopenharmony_ci					       u32 sid)
978c2ecf20Sopenharmony_ci{
988c2ecf20Sopenharmony_ci	return 0;
998c2ecf20Sopenharmony_ci}
1008c2ecf20Sopenharmony_ci
1018c2ecf20Sopenharmony_cistatic inline int selinux_netlbl_sctp_assoc_request(struct sctp_endpoint *ep,
1028c2ecf20Sopenharmony_ci						    struct sk_buff *skb)
1038c2ecf20Sopenharmony_ci{
1048c2ecf20Sopenharmony_ci	return 0;
1058c2ecf20Sopenharmony_ci}
1068c2ecf20Sopenharmony_cistatic inline int selinux_netlbl_inet_conn_request(struct request_sock *req,
1078c2ecf20Sopenharmony_ci						   u16 family)
1088c2ecf20Sopenharmony_ci{
1098c2ecf20Sopenharmony_ci	return 0;
1108c2ecf20Sopenharmony_ci}
1118c2ecf20Sopenharmony_cistatic inline void selinux_netlbl_inet_csk_clone(struct sock *sk, u16 family)
1128c2ecf20Sopenharmony_ci{
1138c2ecf20Sopenharmony_ci	return;
1148c2ecf20Sopenharmony_ci}
1158c2ecf20Sopenharmony_cistatic inline void selinux_netlbl_sctp_sk_clone(struct sock *sk,
1168c2ecf20Sopenharmony_ci						struct sock *newsk)
1178c2ecf20Sopenharmony_ci{
1188c2ecf20Sopenharmony_ci	return;
1198c2ecf20Sopenharmony_ci}
1208c2ecf20Sopenharmony_cistatic inline int selinux_netlbl_socket_post_create(struct sock *sk,
1218c2ecf20Sopenharmony_ci						    u16 family)
1228c2ecf20Sopenharmony_ci{
1238c2ecf20Sopenharmony_ci	return 0;
1248c2ecf20Sopenharmony_ci}
1258c2ecf20Sopenharmony_cistatic inline int selinux_netlbl_sock_rcv_skb(struct sk_security_struct *sksec,
1268c2ecf20Sopenharmony_ci					      struct sk_buff *skb,
1278c2ecf20Sopenharmony_ci					      u16 family,
1288c2ecf20Sopenharmony_ci					      struct common_audit_data *ad)
1298c2ecf20Sopenharmony_ci{
1308c2ecf20Sopenharmony_ci	return 0;
1318c2ecf20Sopenharmony_ci}
1328c2ecf20Sopenharmony_cistatic inline int selinux_netlbl_socket_setsockopt(struct socket *sock,
1338c2ecf20Sopenharmony_ci						   int level,
1348c2ecf20Sopenharmony_ci						   int optname)
1358c2ecf20Sopenharmony_ci{
1368c2ecf20Sopenharmony_ci	return 0;
1378c2ecf20Sopenharmony_ci}
1388c2ecf20Sopenharmony_cistatic inline int selinux_netlbl_socket_connect(struct sock *sk,
1398c2ecf20Sopenharmony_ci						struct sockaddr *addr)
1408c2ecf20Sopenharmony_ci{
1418c2ecf20Sopenharmony_ci	return 0;
1428c2ecf20Sopenharmony_ci}
1438c2ecf20Sopenharmony_cistatic inline int selinux_netlbl_socket_connect_locked(struct sock *sk,
1448c2ecf20Sopenharmony_ci						       struct sockaddr *addr)
1458c2ecf20Sopenharmony_ci{
1468c2ecf20Sopenharmony_ci	return 0;
1478c2ecf20Sopenharmony_ci}
1488c2ecf20Sopenharmony_ci#endif /* CONFIG_NETLABEL */
1498c2ecf20Sopenharmony_ci
1508c2ecf20Sopenharmony_ci#endif
151