2017-11-01 15:07:57 +01:00
|
|
|
/* SPDX-License-Identifier: GPL-2.0 */
|
2011-03-09 14:38:26 -05:00
|
|
|
/*
|
|
|
|
|
* evm.h
|
|
|
|
|
*
|
|
|
|
|
* Copyright (c) 2009 IBM Corporation
|
|
|
|
|
* Author: Mimi Zohar <zohar@us.ibm.com>
|
|
|
|
|
*/
|
|
|
|
|
|
|
|
|
|
#ifndef _LINUX_EVM_H
|
|
|
|
|
#define _LINUX_EVM_H
|
|
|
|
|
|
|
|
|
|
#include <linux/integrity.h>
|
2011-03-09 14:40:44 -05:00
|
|
|
#include <linux/xattr.h>
|
2011-03-09 14:38:26 -05:00
|
|
|
|
2011-05-06 11:34:13 +03:00
|
|
|
struct integrity_iint_cache;
|
|
|
|
|
|
2011-03-09 14:38:26 -05:00
|
|
|
#ifdef CONFIG_EVM
|
2015-10-22 21:26:32 +03:00
|
|
|
extern int evm_set_key(void *key, size_t keylen);
|
2011-03-09 14:38:26 -05:00
|
|
|
extern enum integrity_status evm_verifyxattr(struct dentry *dentry,
|
|
|
|
|
const char *xattr_name,
|
|
|
|
|
void *xattr_value,
|
2011-05-06 11:34:13 +03:00
|
|
|
size_t xattr_value_len,
|
|
|
|
|
struct integrity_iint_cache *iint);
|
2023-01-13 12:49:11 +01:00
|
|
|
extern int evm_inode_setattr(struct mnt_idmap *idmap,
|
2022-06-21 16:14:53 +02:00
|
|
|
struct dentry *dentry, struct iattr *attr);
|
2011-03-09 14:39:57 -05:00
|
|
|
extern void evm_inode_post_setattr(struct dentry *dentry, int ia_valid);
|
2023-01-13 12:49:23 +01:00
|
|
|
extern int evm_inode_setxattr(struct mnt_idmap *idmap,
|
2021-05-14 17:27:48 +02:00
|
|
|
struct dentry *dentry, const char *name,
|
2011-03-09 14:38:26 -05:00
|
|
|
const void *value, size_t size);
|
|
|
|
|
extern void evm_inode_post_setxattr(struct dentry *dentry,
|
|
|
|
|
const char *xattr_name,
|
|
|
|
|
const void *xattr_value,
|
|
|
|
|
size_t xattr_value_len);
|
2023-01-13 12:49:23 +01:00
|
|
|
extern int evm_inode_removexattr(struct mnt_idmap *idmap,
|
2021-05-14 17:27:48 +02:00
|
|
|
struct dentry *dentry, const char *xattr_name);
|
2011-03-09 14:39:18 -05:00
|
|
|
extern void evm_inode_post_removexattr(struct dentry *dentry,
|
|
|
|
|
const char *xattr_name);
|
2023-01-13 12:49:24 +01:00
|
|
|
static inline void evm_inode_post_remove_acl(struct mnt_idmap *idmap,
|
2022-09-22 17:17:14 +02:00
|
|
|
struct dentry *dentry,
|
|
|
|
|
const char *acl_name)
|
|
|
|
|
{
|
|
|
|
|
evm_inode_post_removexattr(dentry, acl_name);
|
|
|
|
|
}
|
2023-01-13 12:49:24 +01:00
|
|
|
extern int evm_inode_set_acl(struct mnt_idmap *idmap,
|
2022-09-22 17:17:10 +02:00
|
|
|
struct dentry *dentry, const char *acl_name,
|
|
|
|
|
struct posix_acl *kacl);
|
2023-01-13 12:49:24 +01:00
|
|
|
static inline int evm_inode_remove_acl(struct mnt_idmap *idmap,
|
2022-09-22 17:17:10 +02:00
|
|
|
struct dentry *dentry,
|
|
|
|
|
const char *acl_name)
|
|
|
|
|
{
|
2023-01-13 12:49:24 +01:00
|
|
|
return evm_inode_set_acl(idmap, dentry, acl_name, NULL);
|
2022-09-22 17:17:10 +02:00
|
|
|
}
|
2022-09-28 13:34:00 +02:00
|
|
|
static inline void evm_inode_post_set_acl(struct dentry *dentry,
|
|
|
|
|
const char *acl_name,
|
|
|
|
|
struct posix_acl *kacl)
|
|
|
|
|
{
|
|
|
|
|
return evm_inode_post_setxattr(dentry, acl_name, NULL, 0);
|
|
|
|
|
}
|
2023-06-10 09:57:37 +02:00
|
|
|
|
|
|
|
|
int evm_inode_init_security(struct inode *inode, struct inode *dir,
|
|
|
|
|
const struct qstr *qstr, struct xattr *xattrs,
|
|
|
|
|
int *xattr_count);
|
2021-05-14 17:27:45 +02:00
|
|
|
extern bool evm_revalidate_status(const char *xattr_name);
|
2021-05-28 09:38:09 +02:00
|
|
|
extern int evm_protected_xattr_if_enabled(const char *req_xattr_name);
|
2021-06-01 10:23:38 +02:00
|
|
|
extern int evm_read_protected_xattrs(struct dentry *dentry, u8 *buffer,
|
|
|
|
|
int buffer_size, char type,
|
|
|
|
|
bool canonical_fmt);
|
2011-08-18 18:07:44 -04:00
|
|
|
#ifdef CONFIG_FS_POSIX_ACL
|
|
|
|
|
extern int posix_xattr_acl(const char *xattrname);
|
|
|
|
|
#else
|
|
|
|
|
static inline int posix_xattr_acl(const char *xattrname)
|
|
|
|
|
{
|
|
|
|
|
return 0;
|
|
|
|
|
}
|
|
|
|
|
#endif
|
2011-03-09 14:38:26 -05:00
|
|
|
#else
|
2015-10-22 21:26:32 +03:00
|
|
|
|
|
|
|
|
static inline int evm_set_key(void *key, size_t keylen)
|
|
|
|
|
{
|
|
|
|
|
return -EOPNOTSUPP;
|
|
|
|
|
}
|
|
|
|
|
|
2011-03-09 14:38:26 -05:00
|
|
|
#ifdef CONFIG_INTEGRITY
|
|
|
|
|
static inline enum integrity_status evm_verifyxattr(struct dentry *dentry,
|
|
|
|
|
const char *xattr_name,
|
|
|
|
|
void *xattr_value,
|
2011-05-06 11:34:13 +03:00
|
|
|
size_t xattr_value_len,
|
|
|
|
|
struct integrity_iint_cache *iint)
|
2011-03-09 14:38:26 -05:00
|
|
|
{
|
|
|
|
|
return INTEGRITY_UNKNOWN;
|
|
|
|
|
}
|
|
|
|
|
#endif
|
|
|
|
|
|
2023-01-13 12:49:11 +01:00
|
|
|
static inline int evm_inode_setattr(struct mnt_idmap *idmap,
|
2022-06-21 16:14:53 +02:00
|
|
|
struct dentry *dentry, struct iattr *attr)
|
2011-05-13 12:53:38 -04:00
|
|
|
{
|
|
|
|
|
return 0;
|
|
|
|
|
}
|
|
|
|
|
|
2011-03-09 14:39:57 -05:00
|
|
|
static inline void evm_inode_post_setattr(struct dentry *dentry, int ia_valid)
|
|
|
|
|
{
|
|
|
|
|
return;
|
|
|
|
|
}
|
|
|
|
|
|
2023-01-13 12:49:23 +01:00
|
|
|
static inline int evm_inode_setxattr(struct mnt_idmap *idmap,
|
2021-05-14 17:27:48 +02:00
|
|
|
struct dentry *dentry, const char *name,
|
2011-03-09 14:38:26 -05:00
|
|
|
const void *value, size_t size)
|
|
|
|
|
{
|
|
|
|
|
return 0;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
static inline void evm_inode_post_setxattr(struct dentry *dentry,
|
|
|
|
|
const char *xattr_name,
|
|
|
|
|
const void *xattr_value,
|
|
|
|
|
size_t xattr_value_len)
|
|
|
|
|
{
|
|
|
|
|
return;
|
|
|
|
|
}
|
|
|
|
|
|
2023-01-13 12:49:23 +01:00
|
|
|
static inline int evm_inode_removexattr(struct mnt_idmap *idmap,
|
2021-05-14 17:27:48 +02:00
|
|
|
struct dentry *dentry,
|
2011-03-09 14:38:26 -05:00
|
|
|
const char *xattr_name)
|
|
|
|
|
{
|
|
|
|
|
return 0;
|
|
|
|
|
}
|
2011-03-09 14:39:18 -05:00
|
|
|
|
|
|
|
|
static inline void evm_inode_post_removexattr(struct dentry *dentry,
|
|
|
|
|
const char *xattr_name)
|
|
|
|
|
{
|
|
|
|
|
return;
|
2022-09-22 17:17:14 +02:00
|
|
|
}
|
|
|
|
|
|
2023-01-13 12:49:24 +01:00
|
|
|
static inline void evm_inode_post_remove_acl(struct mnt_idmap *idmap,
|
2022-09-22 17:17:14 +02:00
|
|
|
struct dentry *dentry,
|
|
|
|
|
const char *acl_name)
|
|
|
|
|
{
|
|
|
|
|
return;
|
2011-03-09 14:39:18 -05:00
|
|
|
}
|
|
|
|
|
|
2023-01-13 12:49:24 +01:00
|
|
|
static inline int evm_inode_set_acl(struct mnt_idmap *idmap,
|
2022-09-22 17:17:10 +02:00
|
|
|
struct dentry *dentry, const char *acl_name,
|
|
|
|
|
struct posix_acl *kacl)
|
|
|
|
|
{
|
|
|
|
|
return 0;
|
|
|
|
|
}
|
|
|
|
|
|
2023-01-13 12:49:24 +01:00
|
|
|
static inline int evm_inode_remove_acl(struct mnt_idmap *idmap,
|
2022-09-22 17:17:10 +02:00
|
|
|
struct dentry *dentry,
|
|
|
|
|
const char *acl_name)
|
|
|
|
|
{
|
|
|
|
|
return 0;
|
|
|
|
|
}
|
|
|
|
|
|
2022-09-28 13:34:00 +02:00
|
|
|
static inline void evm_inode_post_set_acl(struct dentry *dentry,
|
|
|
|
|
const char *acl_name,
|
|
|
|
|
struct posix_acl *kacl)
|
|
|
|
|
{
|
|
|
|
|
return;
|
|
|
|
|
}
|
|
|
|
|
|
2023-06-10 09:57:37 +02:00
|
|
|
static inline int evm_inode_init_security(struct inode *inode, struct inode *dir,
|
|
|
|
|
const struct qstr *qstr,
|
|
|
|
|
struct xattr *xattrs,
|
|
|
|
|
int *xattr_count)
|
2011-03-09 14:40:44 -05:00
|
|
|
{
|
2011-08-11 00:22:52 -04:00
|
|
|
return 0;
|
2011-03-09 14:40:44 -05:00
|
|
|
}
|
|
|
|
|
|
2021-05-14 17:27:45 +02:00
|
|
|
static inline bool evm_revalidate_status(const char *xattr_name)
|
|
|
|
|
{
|
|
|
|
|
return false;
|
|
|
|
|
}
|
|
|
|
|
|
2021-05-28 09:38:09 +02:00
|
|
|
static inline int evm_protected_xattr_if_enabled(const char *req_xattr_name)
|
|
|
|
|
{
|
|
|
|
|
return false;
|
|
|
|
|
}
|
|
|
|
|
|
2021-06-01 10:23:38 +02:00
|
|
|
static inline int evm_read_protected_xattrs(struct dentry *dentry, u8 *buffer,
|
|
|
|
|
int buffer_size, char type,
|
|
|
|
|
bool canonical_fmt)
|
|
|
|
|
{
|
|
|
|
|
return -EOPNOTSUPP;
|
|
|
|
|
}
|
|
|
|
|
|
2013-03-25 21:12:27 +01:00
|
|
|
#endif /* CONFIG_EVM */
|
2011-03-09 14:38:26 -05:00
|
|
|
#endif /* LINUX_EVM_H */
|