forked from torvalds/linux
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel…
…/git/jmorris/security-testing-2.6 * 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/security-testing-2.6: (44 commits) nommu: Provide mmap_min_addr definition. TOMOYO: Add description of lists and structures. TOMOYO: Remove unused field. integrity: ima audit dentry_open failure TOMOYO: Remove unused parameter. security: use mmap_min_addr indepedently of security models TOMOYO: Simplify policy reader. TOMOYO: Remove redundant markers. SELinux: define audit permissions for audit tree netlink messages TOMOYO: Remove unused mutex. tomoyo: avoid get+put of task_struct smack: Remove redundant initialization. integrity: nfsd imbalance bug fix rootplug: Remove redundant initialization. smack: do not beyond ARRAY_SIZE of data integrity: move ima_counts_get integrity: path_check update IMA: Add __init notation to ima functions IMA: Minimal IMA policy and boot param for TCB IMA policy selinux: remove obsolete read buffer limit from sel_read_bool ...
- Loading branch information
Showing
58 changed files
with
1,946 additions
and
477 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,111 @@ | ||
/* | ||
* Common LSM logging functions | ||
* Heavily borrowed from selinux/avc.h | ||
* | ||
* Author : Etienne BASSET <[email protected]> | ||
* | ||
* All credits to : Stephen Smalley, <[email protected]> | ||
* All BUGS to : Etienne BASSET <[email protected]> | ||
*/ | ||
#ifndef _LSM_COMMON_LOGGING_ | ||
#define _LSM_COMMON_LOGGING_ | ||
|
||
#include <linux/stddef.h> | ||
#include <linux/errno.h> | ||
#include <linux/kernel.h> | ||
#include <linux/kdev_t.h> | ||
#include <linux/spinlock.h> | ||
#include <linux/init.h> | ||
#include <linux/audit.h> | ||
#include <linux/in6.h> | ||
#include <linux/path.h> | ||
#include <linux/key.h> | ||
#include <linux/skbuff.h> | ||
#include <asm/system.h> | ||
|
||
|
||
/* Auxiliary data to use in generating the audit record. */ | ||
struct common_audit_data { | ||
char type; | ||
#define LSM_AUDIT_DATA_FS 1 | ||
#define LSM_AUDIT_DATA_NET 2 | ||
#define LSM_AUDIT_DATA_CAP 3 | ||
#define LSM_AUDIT_DATA_IPC 4 | ||
#define LSM_AUDIT_DATA_TASK 5 | ||
#define LSM_AUDIT_DATA_KEY 6 | ||
struct task_struct *tsk; | ||
union { | ||
struct { | ||
struct path path; | ||
struct inode *inode; | ||
} fs; | ||
struct { | ||
int netif; | ||
struct sock *sk; | ||
u16 family; | ||
__be16 dport; | ||
__be16 sport; | ||
union { | ||
struct { | ||
__be32 daddr; | ||
__be32 saddr; | ||
} v4; | ||
struct { | ||
struct in6_addr daddr; | ||
struct in6_addr saddr; | ||
} v6; | ||
} fam; | ||
} net; | ||
int cap; | ||
int ipc_id; | ||
struct task_struct *tsk; | ||
#ifdef CONFIG_KEYS | ||
struct { | ||
key_serial_t key; | ||
char *key_desc; | ||
} key_struct; | ||
#endif | ||
} u; | ||
const char *function; | ||
/* this union contains LSM specific data */ | ||
union { | ||
/* SMACK data */ | ||
struct smack_audit_data { | ||
char *subject; | ||
char *object; | ||
char *request; | ||
int result; | ||
} smack_audit_data; | ||
/* SELinux data */ | ||
struct { | ||
u32 ssid; | ||
u32 tsid; | ||
u16 tclass; | ||
u32 requested; | ||
u32 audited; | ||
struct av_decision *avd; | ||
int result; | ||
} selinux_audit_data; | ||
} lsm_priv; | ||
/* these callback will be implemented by a specific LSM */ | ||
void (*lsm_pre_audit)(struct audit_buffer *, void *); | ||
void (*lsm_post_audit)(struct audit_buffer *, void *); | ||
}; | ||
|
||
#define v4info fam.v4 | ||
#define v6info fam.v6 | ||
|
||
int ipv4_skb_to_auditdata(struct sk_buff *skb, | ||
struct common_audit_data *ad, u8 *proto); | ||
|
||
int ipv6_skb_to_auditdata(struct sk_buff *skb, | ||
struct common_audit_data *ad, u8 *proto); | ||
|
||
/* Initialize an LSM audit data structure. */ | ||
#define COMMON_AUDIT_DATA_INIT(_d, _t) \ | ||
{ memset((_d), 0, sizeof(struct common_audit_data)); \ | ||
(_d)->type = LSM_AUDIT_DATA_##_t; (_d)->function = __func__; } | ||
|
||
void common_lsm_audit(struct common_audit_data *a); | ||
|
||
#endif |
Oops, something went wrong.