netlabel_kapi.c 30.2 KB
Newer Older
P
Paul Moore 已提交
1 2 3 4 5 6 7
/*
 * NetLabel Kernel API
 *
 * This file defines the kernel API for the NetLabel system.  The NetLabel
 * system manages static and dynamic label mappings for network protocols such
 * as CIPSO and RIPSO.
 *
8
 * Author: Paul Moore <paul@paul-moore.com>
P
Paul Moore 已提交
9 10 11 12
 *
 */

/*
13
 * (c) Copyright Hewlett-Packard Development Company, L.P., 2006, 2008
P
Paul Moore 已提交
14 15 16 17 18 19 20 21 22 23 24 25
 *
 * This program is free software;  you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation; either version 2 of the License, or
 * (at your option) any later version.
 *
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY;  without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See
 * the GNU General Public License for more details.
 *
 * You should have received a copy of the GNU General Public License
26
 * along with this program;  if not, see <http://www.gnu.org/licenses/>.
P
Paul Moore 已提交
27 28 29 30 31
 *
 */

#include <linux/init.h>
#include <linux/types.h>
32
#include <linux/slab.h>
33
#include <linux/audit.h>
34 35
#include <linux/in.h>
#include <linux/in6.h>
P
Paul Moore 已提交
36
#include <net/ip.h>
37
#include <net/ipv6.h>
P
Paul Moore 已提交
38 39 40
#include <net/netlabel.h>
#include <net/cipso_ipv4.h>
#include <asm/bug.h>
A
Arun Sharma 已提交
41
#include <linux/atomic.h>
P
Paul Moore 已提交
42 43 44

#include "netlabel_domainhash.h"
#include "netlabel_unlabeled.h"
45
#include "netlabel_cipso_v4.h"
P
Paul Moore 已提交
46
#include "netlabel_user.h"
47
#include "netlabel_mgmt.h"
48
#include "netlabel_addrlist.h"
P
Paul Moore 已提交
49

50 51 52 53 54 55 56
/*
 * Configuration Functions
 */

/**
 * netlbl_cfg_map_del - Remove a NetLabel/LSM domain mapping
 * @domain: the domain mapping to remove
57 58 59
 * @family: address family
 * @addr: IP address
 * @mask: IP address mask
60 61 62 63 64 65 66 67
 * @audit_info: NetLabel audit information
 *
 * Description:
 * Removes a NetLabel/LSM domain mapping.  A @domain value of NULL causes the
 * default domain mapping to be removed.  Returns zero on success, negative
 * values on failure.
 *
 */
68 69 70 71 72
int netlbl_cfg_map_del(const char *domain,
		       u16 family,
		       const void *addr,
		       const void *mask,
		       struct netlbl_audit *audit_info)
73
{
74 75 76 77 78 79 80 81 82 83 84 85
	if (addr == NULL && mask == NULL) {
		return netlbl_domhsh_remove(domain, audit_info);
	} else if (addr != NULL && mask != NULL) {
		switch (family) {
		case AF_INET:
			return netlbl_domhsh_remove_af4(domain, addr, mask,
							audit_info);
		default:
			return -EPFNOSUPPORT;
		}
	} else
		return -EINVAL;
86 87 88
}

/**
89
 * netlbl_cfg_unlbl_map_add - Add a new unlabeled mapping
90
 * @domain: the domain mapping to add
91 92 93
 * @family: address family
 * @addr: IP address
 * @mask: IP address mask
94 95 96 97 98 99 100 101
 * @audit_info: NetLabel audit information
 *
 * Description:
 * Adds a new unlabeled NetLabel/LSM domain mapping.  A @domain value of NULL
 * causes a new default domain mapping to be added.  Returns zero on success,
 * negative values on failure.
 *
 */
102 103 104 105
int netlbl_cfg_unlbl_map_add(const char *domain,
			     u16 family,
			     const void *addr,
			     const void *mask,
106 107 108 109
			     struct netlbl_audit *audit_info)
{
	int ret_val = -ENOMEM;
	struct netlbl_dom_map *entry;
110 111 112
	struct netlbl_domaddr_map *addrmap = NULL;
	struct netlbl_domaddr4_map *map4 = NULL;
	struct netlbl_domaddr6_map *map6 = NULL;
113 114 115

	entry = kzalloc(sizeof(*entry), GFP_ATOMIC);
	if (entry == NULL)
116
		return -ENOMEM;
117 118 119
	if (domain != NULL) {
		entry->domain = kstrdup(domain, GFP_ATOMIC);
		if (entry->domain == NULL)
120 121 122 123
			goto cfg_unlbl_map_add_failure;
	}

	if (addr == NULL && mask == NULL)
124
		entry->def.type = NETLBL_NLTYPE_UNLABELED;
125 126 127 128 129 130 131 132
	else if (addr != NULL && mask != NULL) {
		addrmap = kzalloc(sizeof(*addrmap), GFP_ATOMIC);
		if (addrmap == NULL)
			goto cfg_unlbl_map_add_failure;
		INIT_LIST_HEAD(&addrmap->list4);
		INIT_LIST_HEAD(&addrmap->list6);

		switch (family) {
133 134 135
		case AF_INET: {
			const struct in_addr *addr4 = addr;
			const struct in_addr *mask4 = mask;
136 137 138
			map4 = kzalloc(sizeof(*map4), GFP_ATOMIC);
			if (map4 == NULL)
				goto cfg_unlbl_map_add_failure;
139
			map4->def.type = NETLBL_NLTYPE_UNLABELED;
140 141 142 143 144 145 146 147
			map4->list.addr = addr4->s_addr & mask4->s_addr;
			map4->list.mask = mask4->s_addr;
			map4->list.valid = 1;
			ret_val = netlbl_af4list_add(&map4->list,
						     &addrmap->list4);
			if (ret_val != 0)
				goto cfg_unlbl_map_add_failure;
			break;
148
			}
E
Eric Dumazet 已提交
149
#if IS_ENABLED(CONFIG_IPV6)
150 151 152
		case AF_INET6: {
			const struct in6_addr *addr6 = addr;
			const struct in6_addr *mask6 = mask;
153
			map6 = kzalloc(sizeof(*map6), GFP_ATOMIC);
154
			if (map6 == NULL)
155
				goto cfg_unlbl_map_add_failure;
156
			map6->def.type = NETLBL_NLTYPE_UNLABELED;
A
Alexey Dobriyan 已提交
157
			map6->list.addr = *addr6;
158 159 160 161
			map6->list.addr.s6_addr32[0] &= mask6->s6_addr32[0];
			map6->list.addr.s6_addr32[1] &= mask6->s6_addr32[1];
			map6->list.addr.s6_addr32[2] &= mask6->s6_addr32[2];
			map6->list.addr.s6_addr32[3] &= mask6->s6_addr32[3];
A
Alexey Dobriyan 已提交
162
			map6->list.mask = *mask6;
163
			map6->list.valid = 1;
164 165
			ret_val = netlbl_af6list_add(&map6->list,
						     &addrmap->list6);
166 167 168
			if (ret_val != 0)
				goto cfg_unlbl_map_add_failure;
			break;
169 170
			}
#endif /* IPv6 */
171 172 173 174
		default:
			goto cfg_unlbl_map_add_failure;
		}

175 176
		entry->def.addrsel = addrmap;
		entry->def.type = NETLBL_NLTYPE_ADDRSELECT;
177 178 179
	} else {
		ret_val = -EINVAL;
		goto cfg_unlbl_map_add_failure;
180 181 182 183
	}

	ret_val = netlbl_domhsh_add(entry, audit_info);
	if (ret_val != 0)
184
		goto cfg_unlbl_map_add_failure;
185 186 187

	return 0;

188
cfg_unlbl_map_add_failure:
189
	kfree(entry->domain);
190
	kfree(entry);
191 192 193
	kfree(addrmap);
	kfree(map4);
	kfree(map6);
194 195 196
	return ret_val;
}

197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227

/**
 * netlbl_cfg_unlbl_static_add - Adds a new static label
 * @net: network namespace
 * @dev_name: interface name
 * @addr: IP address in network byte order (struct in[6]_addr)
 * @mask: address mask in network byte order (struct in[6]_addr)
 * @family: address family
 * @secid: LSM secid value for the entry
 * @audit_info: NetLabel audit information
 *
 * Description:
 * Adds a new NetLabel static label to be used when protocol provided labels
 * are not present on incoming traffic.  If @dev_name is NULL then the default
 * interface will be used.  Returns zero on success, negative values on failure.
 *
 */
int netlbl_cfg_unlbl_static_add(struct net *net,
				const char *dev_name,
				const void *addr,
				const void *mask,
				u16 family,
				u32 secid,
				struct netlbl_audit *audit_info)
{
	u32 addr_len;

	switch (family) {
	case AF_INET:
		addr_len = sizeof(struct in_addr);
		break;
E
Eric Dumazet 已提交
228
#if IS_ENABLED(CONFIG_IPV6)
229 230 231
	case AF_INET6:
		addr_len = sizeof(struct in6_addr);
		break;
232
#endif /* IPv6 */
233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269
	default:
		return -EPFNOSUPPORT;
	}

	return netlbl_unlhsh_add(net,
				 dev_name, addr, mask, addr_len,
				 secid, audit_info);
}

/**
 * netlbl_cfg_unlbl_static_del - Removes an existing static label
 * @net: network namespace
 * @dev_name: interface name
 * @addr: IP address in network byte order (struct in[6]_addr)
 * @mask: address mask in network byte order (struct in[6]_addr)
 * @family: address family
 * @audit_info: NetLabel audit information
 *
 * Description:
 * Removes an existing NetLabel static label used when protocol provided labels
 * are not present on incoming traffic.  If @dev_name is NULL then the default
 * interface will be used.  Returns zero on success, negative values on failure.
 *
 */
int netlbl_cfg_unlbl_static_del(struct net *net,
				const char *dev_name,
				const void *addr,
				const void *mask,
				u16 family,
				struct netlbl_audit *audit_info)
{
	u32 addr_len;

	switch (family) {
	case AF_INET:
		addr_len = sizeof(struct in_addr);
		break;
E
Eric Dumazet 已提交
270
#if IS_ENABLED(CONFIG_IPV6)
271 272 273
	case AF_INET6:
		addr_len = sizeof(struct in6_addr);
		break;
274
#endif /* IPv6 */
275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314
	default:
		return -EPFNOSUPPORT;
	}

	return netlbl_unlhsh_remove(net,
				    dev_name, addr, mask, addr_len,
				    audit_info);
}

/**
 * netlbl_cfg_cipsov4_add - Add a new CIPSOv4 DOI definition
 * @doi_def: CIPSO DOI definition
 * @audit_info: NetLabel audit information
 *
 * Description:
 * Add a new CIPSO DOI definition as defined by @doi_def.  Returns zero on
 * success and negative values on failure.
 *
 */
int netlbl_cfg_cipsov4_add(struct cipso_v4_doi *doi_def,
			   struct netlbl_audit *audit_info)
{
	return cipso_v4_doi_add(doi_def, audit_info);
}

/**
 * netlbl_cfg_cipsov4_del - Remove an existing CIPSOv4 DOI definition
 * @doi: CIPSO DOI
 * @audit_info: NetLabel audit information
 *
 * Description:
 * Remove an existing CIPSO DOI definition matching @doi.  Returns zero on
 * success and negative values on failure.
 *
 */
void netlbl_cfg_cipsov4_del(u32 doi, struct netlbl_audit *audit_info)
{
	cipso_v4_doi_remove(doi, audit_info);
}

315
/**
316 317
 * netlbl_cfg_cipsov4_map_add - Add a new CIPSOv4 DOI mapping
 * @doi: the CIPSO DOI
318
 * @domain: the domain mapping to add
319 320
 * @addr: IP address
 * @mask: IP address mask
321 322 323
 * @audit_info: NetLabel audit information
 *
 * Description:
324 325 326
 * Add a new NetLabel/LSM domain mapping for the given CIPSO DOI to the NetLabel
 * subsystem.  A @domain value of NULL adds a new default domain mapping.
 * Returns zero on success, negative values on failure.
327 328
 *
 */
329
int netlbl_cfg_cipsov4_map_add(u32 doi,
330
			       const char *domain,
331 332
			       const struct in_addr *addr,
			       const struct in_addr *mask,
333 334 335
			       struct netlbl_audit *audit_info)
{
	int ret_val = -ENOMEM;
336
	struct cipso_v4_doi *doi_def;
337
	struct netlbl_dom_map *entry;
338 339
	struct netlbl_domaddr_map *addrmap = NULL;
	struct netlbl_domaddr4_map *addrinfo = NULL;
340

341 342 343
	doi_def = cipso_v4_doi_getdef(doi);
	if (doi_def == NULL)
		return -ENOENT;
344

345 346
	entry = kzalloc(sizeof(*entry), GFP_ATOMIC);
	if (entry == NULL)
347
		goto out_entry;
348 349 350
	if (domain != NULL) {
		entry->domain = kstrdup(domain, GFP_ATOMIC);
		if (entry->domain == NULL)
351
			goto out_domain;
352 353
	}

354
	if (addr == NULL && mask == NULL) {
355 356
		entry->def.cipso = doi_def;
		entry->def.type = NETLBL_NLTYPE_CIPSOV4;
357 358 359
	} else if (addr != NULL && mask != NULL) {
		addrmap = kzalloc(sizeof(*addrmap), GFP_ATOMIC);
		if (addrmap == NULL)
360
			goto out_addrmap;
361 362 363 364 365
		INIT_LIST_HEAD(&addrmap->list4);
		INIT_LIST_HEAD(&addrmap->list6);

		addrinfo = kzalloc(sizeof(*addrinfo), GFP_ATOMIC);
		if (addrinfo == NULL)
366
			goto out_addrinfo;
367 368
		addrinfo->def.cipso = doi_def;
		addrinfo->def.type = NETLBL_NLTYPE_CIPSOV4;
369 370 371 372 373 374 375
		addrinfo->list.addr = addr->s_addr & mask->s_addr;
		addrinfo->list.mask = mask->s_addr;
		addrinfo->list.valid = 1;
		ret_val = netlbl_af4list_add(&addrinfo->list, &addrmap->list4);
		if (ret_val != 0)
			goto cfg_cipsov4_map_add_failure;

376 377
		entry->def.addrsel = addrmap;
		entry->def.type = NETLBL_NLTYPE_ADDRSELECT;
378 379
	} else {
		ret_val = -EINVAL;
380
		goto out_addrmap;
381
	}
382

383 384
	ret_val = netlbl_domhsh_add(entry, audit_info);
	if (ret_val != 0)
385
		goto cfg_cipsov4_map_add_failure;
386

387
	return 0;
388

389
cfg_cipsov4_map_add_failure:
390 391 392 393
	kfree(addrinfo);
out_addrinfo:
	kfree(addrmap);
out_addrmap:
394
	kfree(entry->domain);
395
out_domain:
396
	kfree(entry);
397 398
out_entry:
	cipso_v4_doi_putdef(doi_def);
399
	return ret_val;
400 401
}

402 403 404 405
/*
 * Security Attribute Functions
 */

406 407
#define _CM_F_NONE	0x00000000
#define _CM_F_ALLOC	0x00000001
408
#define _CM_F_WALK	0x00000002
409 410

/**
411
 * _netlbl_catmap_getnode - Get a individual node from a catmap
412 413 414 415 416 417
 * @catmap: pointer to the category bitmap
 * @offset: the requested offset
 * @cm_flags: catmap flags, see _CM_F_*
 * @gfp_flags: memory allocation flags
 *
 * Description:
418 419 420 421 422
 * Iterate through the catmap looking for the node associated with @offset.
 * If the _CM_F_ALLOC flag is set in @cm_flags and there is no associated node,
 * one will be created and inserted into the catmap.  If the _CM_F_WALK flag is
 * set in @cm_flags and there is no associated node, the next highest node will
 * be returned.  Returns a pointer to the node on success, NULL on failure.
423 424
 *
 */
425 426 427 428 429
static struct netlbl_lsm_catmap *_netlbl_catmap_getnode(
					     struct netlbl_lsm_catmap **catmap,
					     u32 offset,
					     unsigned int cm_flags,
					     gfp_t gfp_flags)
430
{
431 432
	struct netlbl_lsm_catmap *iter = *catmap;
	struct netlbl_lsm_catmap *prev = NULL;
433

434
	if (iter == NULL)
435
		goto catmap_getnode_alloc;
436
	if (offset < iter->startbit)
437
		goto catmap_getnode_walk;
438 439 440 441 442
	while (iter && offset >= (iter->startbit + NETLBL_CATMAP_SIZE)) {
		prev = iter;
		iter = iter->next;
	}
	if (iter == NULL || offset < iter->startbit)
443
		goto catmap_getnode_walk;
444 445 446

	return iter;

447
catmap_getnode_walk:
448 449
	if (cm_flags & _CM_F_WALK)
		return iter;
450
catmap_getnode_alloc:
451 452 453
	if (!(cm_flags & _CM_F_ALLOC))
		return NULL;

454
	iter = netlbl_catmap_alloc(gfp_flags);
455 456 457 458 459 460 461 462 463 464 465 466 467 468 469
	if (iter == NULL)
		return NULL;
	iter->startbit = offset & ~(NETLBL_CATMAP_SIZE - 1);

	if (prev == NULL) {
		iter->next = *catmap;
		*catmap = iter;
	} else {
		iter->next = prev->next;
		prev->next = iter;
	}

	return iter;
}

470
/**
471
 * netlbl_catmap_walk - Walk a LSM secattr catmap looking for a bit
472 473 474 475 476 477 478 479
 * @catmap: the category bitmap
 * @offset: the offset to start searching at, in bits
 *
 * Description:
 * This function walks a LSM secattr category bitmap starting at @offset and
 * returns the spot of the first set bit or -ENOENT if no bits are set.
 *
 */
480
int netlbl_catmap_walk(struct netlbl_lsm_catmap *catmap, u32 offset)
481
{
482
	struct netlbl_lsm_catmap *iter = catmap;
483 484
	u32 idx;
	u32 bit;
485 486
	NETLBL_CATMAP_MAPTYPE bitmap;

487
	iter = _netlbl_catmap_getnode(&catmap, offset, _CM_F_WALK, 0);
488 489
	if (iter == NULL)
		return -ENOENT;
490
	if (offset > iter->startbit) {
491 492 493
		offset -= iter->startbit;
		idx = offset / NETLBL_CATMAP_MAPSIZE;
		bit = offset % NETLBL_CATMAP_MAPSIZE;
494
	} else {
495 496
		idx = 0;
		bit = 0;
497
	}
498
	bitmap = iter->bitmap[idx] >> bit;
499 500 501 502 503

	for (;;) {
		if (bitmap != 0) {
			while ((bitmap & NETLBL_CATMAP_BIT) == 0) {
				bitmap >>= 1;
504
				bit++;
505 506
			}
			return iter->startbit +
507
			       (NETLBL_CATMAP_MAPSIZE * idx) + bit;
508
		}
509
		if (++idx >= NETLBL_CATMAP_MAPCNT) {
510 511
			if (iter->next != NULL) {
				iter = iter->next;
512
				idx = 0;
513 514 515
			} else
				return -ENOENT;
		}
516 517
		bitmap = iter->bitmap[idx];
		bit = 0;
518 519 520 521 522 523
	}

	return -ENOENT;
}

/**
524
 * netlbl_catmap_walkrng - Find the end of a string of set bits
525 526 527 528 529 530 531 532 533
 * @catmap: the category bitmap
 * @offset: the offset to start searching at, in bits
 *
 * Description:
 * This function walks a LSM secattr category bitmap starting at @offset and
 * returns the spot of the first cleared bit or -ENOENT if the offset is past
 * the end of the bitmap.
 *
 */
534
int netlbl_catmap_walkrng(struct netlbl_lsm_catmap *catmap, u32 offset)
535
{
536 537
	struct netlbl_lsm_catmap *iter;
	struct netlbl_lsm_catmap *prev = NULL;
538 539
	u32 idx;
	u32 bit;
540 541 542
	NETLBL_CATMAP_MAPTYPE bitmask;
	NETLBL_CATMAP_MAPTYPE bitmap;

543
	iter = _netlbl_catmap_getnode(&catmap, offset, _CM_F_WALK, 0);
544 545
	if (iter == NULL)
		return -ENOENT;
546
	if (offset > iter->startbit) {
547 548 549
		offset -= iter->startbit;
		idx = offset / NETLBL_CATMAP_MAPSIZE;
		bit = offset % NETLBL_CATMAP_MAPSIZE;
550
	} else {
551 552
		idx = 0;
		bit = 0;
553
	}
554
	bitmask = NETLBL_CATMAP_BIT << bit;
555 556

	for (;;) {
557
		bitmap = iter->bitmap[idx];
558 559
		while (bitmask != 0 && (bitmap & bitmask) != 0) {
			bitmask <<= 1;
560
			bit++;
561 562
		}

563 564 565
		if (prev && idx == 0 && bit == 0)
			return prev->startbit + NETLBL_CATMAP_SIZE - 1;
		else if (bitmask != 0)
566
			return iter->startbit +
567 568
				(NETLBL_CATMAP_MAPSIZE * idx) + bit - 1;
		else if (++idx >= NETLBL_CATMAP_MAPCNT) {
569
			if (iter->next == NULL)
570 571
				return iter->startbit + NETLBL_CATMAP_SIZE - 1;
			prev = iter;
572
			iter = iter->next;
573
			idx = 0;
574 575
		}
		bitmask = NETLBL_CATMAP_BIT;
576
		bit = 0;
577 578 579 580 581
	}

	return -ENOENT;
}

582
/**
583
 * netlbl_catmap_getlong - Export an unsigned long bitmap
584 585 586 587 588 589 590 591 592 593 594 595
 * @catmap: pointer to the category bitmap
 * @offset: pointer to the requested offset
 * @bitmap: the exported bitmap
 *
 * Description:
 * Export a bitmap with an offset greater than or equal to @offset and return
 * it in @bitmap.  The @offset must be aligned to an unsigned long and will be
 * updated on return if different from what was requested; if the catmap is
 * empty at the requested offset and beyond, the @offset is set to (u32)-1.
 * Returns zero on sucess, negative values on failure.
 *
 */
596 597 598
int netlbl_catmap_getlong(struct netlbl_lsm_catmap *catmap,
			  u32 *offset,
			  unsigned long *bitmap)
599
{
600
	struct netlbl_lsm_catmap *iter;
601 602 603 604 605 606 607 608 609 610 611
	u32 off = *offset;
	u32 idx;

	/* only allow aligned offsets */
	if ((off & (BITS_PER_LONG - 1)) != 0)
		return -EINVAL;

	if (off < catmap->startbit) {
		off = catmap->startbit;
		*offset = off;
	}
612
	iter = _netlbl_catmap_getnode(&catmap, off, _CM_F_NONE, 0);
613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629
	if (iter == NULL) {
		*offset = (u32)-1;
		return 0;
	}

	if (off < iter->startbit) {
		off = iter->startbit;
		*offset = off;
	} else
		off -= iter->startbit;

	idx = off / NETLBL_CATMAP_MAPSIZE;
	*bitmap = iter->bitmap[idx] >> (off % NETLBL_CATMAP_SIZE);

	return 0;
}

630
/**
631
 * netlbl_catmap_setbit - Set a bit in a LSM secattr catmap
632
 * @catmap: pointer to the category bitmap
633 634 635 636 637 638 639 640
 * @bit: the bit to set
 * @flags: memory allocation flags
 *
 * Description:
 * Set the bit specified by @bit in @catmap.  Returns zero on success,
 * negative values on failure.
 *
 */
641 642 643
int netlbl_catmap_setbit(struct netlbl_lsm_catmap **catmap,
			 u32 bit,
			 gfp_t flags)
644
{
645
	struct netlbl_lsm_catmap *iter;
646
	u32 idx;
647

648
	iter = _netlbl_catmap_getnode(catmap, bit, _CM_F_ALLOC, flags);
649 650
	if (iter == NULL)
		return -ENOMEM;
651

652 653 654
	bit -= iter->startbit;
	idx = bit / NETLBL_CATMAP_MAPSIZE;
	iter->bitmap[idx] |= NETLBL_CATMAP_BIT << (bit % NETLBL_CATMAP_MAPSIZE);
655 656 657 658 659

	return 0;
}

/**
660
 * netlbl_catmap_setrng - Set a range of bits in a LSM secattr catmap
661
 * @catmap: pointer to the category bitmap
662 663 664 665 666 667 668 669 670
 * @start: the starting bit
 * @end: the last bit in the string
 * @flags: memory allocation flags
 *
 * Description:
 * Set a range of bits, starting at @start and ending with @end.  Returns zero
 * on success, negative values on failure.
 *
 */
671 672 673 674
int netlbl_catmap_setrng(struct netlbl_lsm_catmap **catmap,
			 u32 start,
			 u32 end,
			 gfp_t flags)
675
{
676 677 678 679 680 681
	int rc = 0;
	u32 spot = start;

	while (rc == 0 && spot <= end) {
		if (((spot & (BITS_PER_LONG - 1)) != 0) &&
		    ((end - spot) > BITS_PER_LONG)) {
682 683 684 685
			rc = netlbl_catmap_setlong(catmap,
						   spot,
						   (unsigned long)-1,
						   flags);
686 687
			spot += BITS_PER_LONG;
		} else
688
			rc = netlbl_catmap_setbit(catmap, spot++, flags);
689 690
	}

691 692 693 694
	return rc;
}

/**
695
 * netlbl_catmap_setlong - Import an unsigned long bitmap
696 697 698 699 700 701 702 703 704 705 706
 * @catmap: pointer to the category bitmap
 * @offset: offset to the start of the imported bitmap
 * @bitmap: the bitmap to import
 * @flags: memory allocation flags
 *
 * Description:
 * Import the bitmap specified in @bitmap into @catmap, using the offset
 * in @offset.  The offset must be aligned to an unsigned long.  Returns zero
 * on success, negative values on failure.
 *
 */
707 708 709 710
int netlbl_catmap_setlong(struct netlbl_lsm_catmap **catmap,
			  u32 offset,
			  unsigned long bitmap,
			  gfp_t flags)
711
{
712
	struct netlbl_lsm_catmap *iter;
713 714 715 716 717 718
	u32 idx;

	/* only allow aligned offsets */
	if ((offset & (BITS_PER_LONG - 1)) != 0)
		return -EINVAL;

719
	iter = _netlbl_catmap_getnode(catmap, offset, _CM_F_ALLOC, flags);
720 721 722 723 724 725 726 727
	if (iter == NULL)
		return -ENOMEM;

	offset -= iter->startbit;
	idx = offset / NETLBL_CATMAP_MAPSIZE;
	iter->bitmap[idx] |= bitmap << (offset % NETLBL_CATMAP_MAPSIZE);

	return 0;
728 729
}

P
Paul Moore 已提交
730 731 732 733
/*
 * LSM Functions
 */

734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750
/**
 * netlbl_enabled - Determine if the NetLabel subsystem is enabled
 *
 * Description:
 * The LSM can use this function to determine if it should use NetLabel
 * security attributes in it's enforcement mechanism.  Currently, NetLabel is
 * considered to be enabled when it's configuration contains a valid setup for
 * at least one labeled protocol (i.e. NetLabel can understand incoming
 * labeled packets of at least one type); otherwise NetLabel is considered to
 * be disabled.
 *
 */
int netlbl_enabled(void)
{
	/* At some point we probably want to expose this mechanism to the user
	 * as well so that admins can toggle NetLabel regardless of the
	 * configuration */
751
	return (atomic_read(&netlabel_mgmt_protocount) > 0);
752 753
}

P
Paul Moore 已提交
754
/**
755
 * netlbl_sock_setattr - Label a socket using the correct protocol
756
 * @sk: the socket to label
757
 * @family: protocol family
P
Paul Moore 已提交
758 759 760 761
 * @secattr: the security attributes
 *
 * Description:
 * Attach the correct label to the given socket using the security attributes
762 763
 * specified in @secattr.  This function requires exclusive access to @sk,
 * which means it either needs to be in the process of being created or locked.
764 765 766
 * Returns zero on success, -EDESTADDRREQ if the domain is configured to use
 * network address selectors (can't blindly label the socket), and negative
 * values on all other failures.
P
Paul Moore 已提交
767 768
 *
 */
769
int netlbl_sock_setattr(struct sock *sk,
770
			u16 family,
771
			const struct netlbl_lsm_secattr *secattr)
P
Paul Moore 已提交
772
{
773
	int ret_val;
P
Paul Moore 已提交
774 775 776 777
	struct netlbl_dom_map *dom_entry;

	rcu_read_lock();
	dom_entry = netlbl_domhsh_getentry(secattr->domain);
778 779
	if (dom_entry == NULL) {
		ret_val = -ENOENT;
P
Paul Moore 已提交
780
		goto socket_setattr_return;
781 782 783
	}
	switch (family) {
	case AF_INET:
784
		switch (dom_entry->def.type) {
785 786 787 788 789
		case NETLBL_NLTYPE_ADDRSELECT:
			ret_val = -EDESTADDRREQ;
			break;
		case NETLBL_NLTYPE_CIPSOV4:
			ret_val = cipso_v4_sock_setattr(sk,
790 791
							dom_entry->def.cipso,
							secattr);
792 793 794 795 796 797 798
			break;
		case NETLBL_NLTYPE_UNLABELED:
			ret_val = 0;
			break;
		default:
			ret_val = -ENOENT;
		}
P
Paul Moore 已提交
799
		break;
E
Eric Dumazet 已提交
800
#if IS_ENABLED(CONFIG_IPV6)
801 802 803
	case AF_INET6:
		/* since we don't support any IPv6 labeling protocols right
		 * now we can optimize everything away until we do */
P
Paul Moore 已提交
804 805
		ret_val = 0;
		break;
806
#endif /* IPv6 */
P
Paul Moore 已提交
807
	default:
808
		ret_val = -EPROTONOSUPPORT;
P
Paul Moore 已提交
809 810 811 812 813 814 815
	}

socket_setattr_return:
	rcu_read_unlock();
	return ret_val;
}

816 817 818 819 820 821 822 823 824 825 826 827 828 829
/**
 * netlbl_sock_delattr - Delete all the NetLabel labels on a socket
 * @sk: the socket
 *
 * Description:
 * Remove all the NetLabel labeling from @sk.  The caller is responsible for
 * ensuring that @sk is locked.
 *
 */
void netlbl_sock_delattr(struct sock *sk)
{
	cipso_v4_sock_delattr(sk);
}

830 831 832 833 834 835
/**
 * netlbl_sock_getattr - Determine the security attributes of a sock
 * @sk: the sock
 * @secattr: the security attributes
 *
 * Description:
836
 * Examines the given sock to see if any NetLabel style labeling has been
837 838 839 840 841
 * applied to the sock, if so it parses the socket label and returns the
 * security attributes in @secattr.  Returns zero on success, negative values
 * on failure.
 *
 */
842 843
int netlbl_sock_getattr(struct sock *sk,
			struct netlbl_lsm_secattr *secattr)
844
{
845 846 847 848 849 850
	int ret_val;

	switch (sk->sk_family) {
	case AF_INET:
		ret_val = cipso_v4_sock_getattr(sk, secattr);
		break;
E
Eric Dumazet 已提交
851
#if IS_ENABLED(CONFIG_IPV6)
852 853 854 855 856 857 858 859 860
	case AF_INET6:
		ret_val = -ENOMSG;
		break;
#endif /* IPv6 */
	default:
		ret_val = -EPROTONOSUPPORT;
	}

	return ret_val;
861 862
}

863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880
/**
 * netlbl_conn_setattr - Label a connected socket using the correct protocol
 * @sk: the socket to label
 * @addr: the destination address
 * @secattr: the security attributes
 *
 * Description:
 * Attach the correct label to the given connected socket using the security
 * attributes specified in @secattr.  The caller is responsible for ensuring
 * that @sk is locked.  Returns zero on success, negative values on failure.
 *
 */
int netlbl_conn_setattr(struct sock *sk,
			struct sockaddr *addr,
			const struct netlbl_lsm_secattr *secattr)
{
	int ret_val;
	struct sockaddr_in *addr4;
881
	struct netlbl_dommap_def *entry;
882 883 884 885 886

	rcu_read_lock();
	switch (addr->sa_family) {
	case AF_INET:
		addr4 = (struct sockaddr_in *)addr;
887 888 889
		entry = netlbl_domhsh_getentry_af4(secattr->domain,
						   addr4->sin_addr.s_addr);
		if (entry == NULL) {
890 891 892
			ret_val = -ENOENT;
			goto conn_setattr_return;
		}
893
		switch (entry->type) {
894 895
		case NETLBL_NLTYPE_CIPSOV4:
			ret_val = cipso_v4_sock_setattr(sk,
896
							entry->cipso, secattr);
897 898 899 900 901 902 903 904 905 906 907
			break;
		case NETLBL_NLTYPE_UNLABELED:
			/* just delete the protocols we support for right now
			 * but we could remove other protocols if needed */
			cipso_v4_sock_delattr(sk);
			ret_val = 0;
			break;
		default:
			ret_val = -ENOENT;
		}
		break;
E
Eric Dumazet 已提交
908
#if IS_ENABLED(CONFIG_IPV6)
909 910 911 912 913 914 915
	case AF_INET6:
		/* since we don't support any IPv6 labeling protocols right
		 * now we can optimize everything away until we do */
		ret_val = 0;
		break;
#endif /* IPv6 */
	default:
916
		ret_val = -EPROTONOSUPPORT;
917 918 919 920 921 922 923
	}

conn_setattr_return:
	rcu_read_unlock();
	return ret_val;
}

924 925 926 927 928 929 930 931 932 933 934 935 936 937
/**
 * netlbl_req_setattr - Label a request socket using the correct protocol
 * @req: the request socket to label
 * @secattr: the security attributes
 *
 * Description:
 * Attach the correct label to the given socket using the security attributes
 * specified in @secattr.  Returns zero on success, negative values on failure.
 *
 */
int netlbl_req_setattr(struct request_sock *req,
		       const struct netlbl_lsm_secattr *secattr)
{
	int ret_val;
938
	struct netlbl_dommap_def *entry;
939 940 941 942

	rcu_read_lock();
	switch (req->rsk_ops->family) {
	case AF_INET:
943
		entry = netlbl_domhsh_getentry_af4(secattr->domain,
944
						   inet_rsk(req)->ir_rmt_addr);
945 946 947
		if (entry == NULL) {
			ret_val = -ENOENT;
			goto req_setattr_return;
948
		}
949
		switch (entry->type) {
950
		case NETLBL_NLTYPE_CIPSOV4:
951 952
			ret_val = cipso_v4_req_setattr(req,
						       entry->cipso, secattr);
953 954 955 956 957 958 959 960 961 962 963
			break;
		case NETLBL_NLTYPE_UNLABELED:
			/* just delete the protocols we support for right now
			 * but we could remove other protocols if needed */
			cipso_v4_req_delattr(req);
			ret_val = 0;
			break;
		default:
			ret_val = -ENOENT;
		}
		break;
E
Eric Dumazet 已提交
964
#if IS_ENABLED(CONFIG_IPV6)
965 966 967 968 969 970 971 972 973 974 975 976 977 978 979
	case AF_INET6:
		/* since we don't support any IPv6 labeling protocols right
		 * now we can optimize everything away until we do */
		ret_val = 0;
		break;
#endif /* IPv6 */
	default:
		ret_val = -EPROTONOSUPPORT;
	}

req_setattr_return:
	rcu_read_unlock();
	return ret_val;
}

980 981 982 983 984 985 986 987 988 989 990 991 992
/**
* netlbl_req_delattr - Delete all the NetLabel labels on a socket
* @req: the socket
*
* Description:
* Remove all the NetLabel labeling from @req.
*
*/
void netlbl_req_delattr(struct request_sock *req)
{
	cipso_v4_req_delattr(req);
}

993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009
/**
 * netlbl_skbuff_setattr - Label a packet using the correct protocol
 * @skb: the packet
 * @family: protocol family
 * @secattr: the security attributes
 *
 * Description:
 * Attach the correct label to the given packet using the security attributes
 * specified in @secattr.  Returns zero on success, negative values on failure.
 *
 */
int netlbl_skbuff_setattr(struct sk_buff *skb,
			  u16 family,
			  const struct netlbl_lsm_secattr *secattr)
{
	int ret_val;
	struct iphdr *hdr4;
1010
	struct netlbl_dommap_def *entry;
1011 1012 1013 1014 1015

	rcu_read_lock();
	switch (family) {
	case AF_INET:
		hdr4 = ip_hdr(skb);
1016 1017
		entry = netlbl_domhsh_getentry_af4(secattr->domain,hdr4->daddr);
		if (entry == NULL) {
1018 1019 1020
			ret_val = -ENOENT;
			goto skbuff_setattr_return;
		}
1021
		switch (entry->type) {
1022
		case NETLBL_NLTYPE_CIPSOV4:
1023 1024
			ret_val = cipso_v4_skbuff_setattr(skb, entry->cipso,
							  secattr);
1025 1026 1027 1028 1029 1030 1031 1032 1033 1034
			break;
		case NETLBL_NLTYPE_UNLABELED:
			/* just delete the protocols we support for right now
			 * but we could remove other protocols if needed */
			ret_val = cipso_v4_skbuff_delattr(skb);
			break;
		default:
			ret_val = -ENOENT;
		}
		break;
E
Eric Dumazet 已提交
1035
#if IS_ENABLED(CONFIG_IPV6)
1036 1037 1038 1039 1040 1041 1042
	case AF_INET6:
		/* since we don't support any IPv6 labeling protocols right
		 * now we can optimize everything away until we do */
		ret_val = 0;
		break;
#endif /* IPv6 */
	default:
1043
		ret_val = -EPROTONOSUPPORT;
1044 1045 1046 1047 1048 1049 1050
	}

skbuff_setattr_return:
	rcu_read_unlock();
	return ret_val;
}

P
Paul Moore 已提交
1051 1052 1053
/**
 * netlbl_skbuff_getattr - Determine the security attributes of a packet
 * @skb: the packet
1054
 * @family: protocol family
P
Paul Moore 已提交
1055 1056 1057 1058 1059 1060 1061 1062 1063 1064
 * @secattr: the security attributes
 *
 * Description:
 * Examines the given packet to see if a recognized form of packet labeling
 * is present, if so it parses the packet label and returns the security
 * attributes in @secattr.  Returns zero on success, negative values on
 * failure.
 *
 */
int netlbl_skbuff_getattr(const struct sk_buff *skb,
1065
			  u16 family,
P
Paul Moore 已提交
1066 1067
			  struct netlbl_lsm_secattr *secattr)
{
1068 1069 1070 1071 1072 1073
	switch (family) {
	case AF_INET:
		if (CIPSO_V4_OPTEXIST(skb) &&
		    cipso_v4_skbuff_getattr(skb, secattr) == 0)
			return 0;
		break;
E
Eric Dumazet 已提交
1074
#if IS_ENABLED(CONFIG_IPV6)
1075 1076 1077 1078
	case AF_INET6:
		break;
#endif /* IPv6 */
	}
P
Paul Moore 已提交
1079

1080
	return netlbl_unlabel_getattr(skb, family, secattr);
P
Paul Moore 已提交
1081 1082 1083 1084 1085 1086
}

/**
 * netlbl_skbuff_err - Handle a LSM error on a sk_buff
 * @skb: the packet
 * @error: the error code
1087
 * @gateway: true if host is acting as a gateway, false otherwise
P
Paul Moore 已提交
1088 1089 1090 1091 1092 1093 1094
 *
 * Description:
 * Deal with a LSM problem when handling the packet in @skb, typically this is
 * a permission denied problem (-EACCES).  The correct action is determined
 * according to the packet's labeling protocol.
 *
 */
1095
void netlbl_skbuff_err(struct sk_buff *skb, int error, int gateway)
P
Paul Moore 已提交
1096 1097
{
	if (CIPSO_V4_OPTEXIST(skb))
1098
		cipso_v4_error(skb, error, gateway);
P
Paul Moore 已提交
1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127 1128
}

/**
 * netlbl_cache_invalidate - Invalidate all of the NetLabel protocol caches
 *
 * Description:
 * For all of the NetLabel protocols that support some form of label mapping
 * cache, invalidate the cache.  Returns zero on success, negative values on
 * error.
 *
 */
void netlbl_cache_invalidate(void)
{
	cipso_v4_cache_invalidate();
}

/**
 * netlbl_cache_add - Add an entry to a NetLabel protocol cache
 * @skb: the packet
 * @secattr: the packet's security attributes
 *
 * Description:
 * Add the LSM security attributes for the given packet to the underlying
 * NetLabel protocol's label mapping cache.  Returns zero on success, negative
 * values on error.
 *
 */
int netlbl_cache_add(const struct sk_buff *skb,
		     const struct netlbl_lsm_secattr *secattr)
{
1129
	if ((secattr->flags & NETLBL_SECATTR_CACHE) == 0)
P
Paul Moore 已提交
1130 1131 1132 1133 1134 1135 1136 1137
		return -ENOMSG;

	if (CIPSO_V4_OPTEXIST(skb))
		return cipso_v4_cache_add(skb, secattr);

	return -ENOMSG;
}

1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148 1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159
/*
 * Protocol Engine Functions
 */

/**
 * netlbl_audit_start - Start an audit message
 * @type: audit message type
 * @audit_info: NetLabel audit information
 *
 * Description:
 * Start an audit message using the type specified in @type and fill the audit
 * message with some fields common to all NetLabel audit messages.  This
 * function should only be used by protocol engines, not LSMs.  Returns a
 * pointer to the audit buffer on success, NULL on failure.
 *
 */
struct audit_buffer *netlbl_audit_start(int type,
					struct netlbl_audit *audit_info)
{
	return netlbl_audit_start_common(type, audit_info);
}

P
Paul Moore 已提交
1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186
/*
 * Setup Functions
 */

/**
 * netlbl_init - Initialize NetLabel
 *
 * Description:
 * Perform the required NetLabel initialization before first use.
 *
 */
static int __init netlbl_init(void)
{
	int ret_val;

	printk(KERN_INFO "NetLabel: Initializing\n");
	printk(KERN_INFO "NetLabel:  domain hash size = %u\n",
	       (1 << NETLBL_DOMHSH_BITSIZE));
	printk(KERN_INFO "NetLabel:  protocols ="
	       " UNLABELED"
	       " CIPSOv4"
	       "\n");

	ret_val = netlbl_domhsh_init(NETLBL_DOMHSH_BITSIZE);
	if (ret_val != 0)
		goto init_failure;

1187 1188 1189 1190
	ret_val = netlbl_unlabel_init(NETLBL_UNLHSH_BITSIZE);
	if (ret_val != 0)
		goto init_failure;

P
Paul Moore 已提交
1191 1192 1193 1194 1195 1196 1197 1198 1199 1200 1201 1202 1203 1204 1205 1206
	ret_val = netlbl_netlink_init();
	if (ret_val != 0)
		goto init_failure;

	ret_val = netlbl_unlabel_defconf();
	if (ret_val != 0)
		goto init_failure;
	printk(KERN_INFO "NetLabel:  unlabeled traffic allowed by default\n");

	return 0;

init_failure:
	panic("NetLabel: failed to initialize properly (%d)\n", ret_val);
}

subsys_initcall(netlbl_init);