#include <linux/init.h>
#include <linux/kd.h>
#include <linux/kernel.h>
#include <linux/kernel_read_file.h>
#include <linux/errno.h>
#include <linux/sched/signal.h>
#include <linux/sched/task.h>
#include <linux/lsm_hooks.h>
#include <linux/xattr.h>
#include <linux/capability.h>
#include <linux/unistd.h>
#include <linux/mm.h>
#include <linux/mman.h>
#include <linux/slab.h>
#include <linux/pagemap.h>
#include <linux/proc_fs.h>
#include <linux/swap.h>
#include <linux/spinlock.h>
#include <linux/syscalls.h>
#include <linux/dcache.h>
#include <linux/file.h>
#include <linux/fdtable.h>
#include <linux/namei.h>
#include <linux/mount.h>
#include <linux/fs_context.h>
#include <linux/fs_parser.h>
#include <linux/netfilter_ipv4.h>
#include <linux/netfilter_ipv6.h>
#include <linux/tty.h>
#include <net/icmp.h>
#include <net/ip.h>
#include <net/tcp.h>
#include <net/inet_connection_sock.h>
#include <net/net_namespace.h>
#include <net/netlabel.h>
#include <linux/uaccess.h>
#include <asm/ioctls.h>
#include <linux/atomic.h>
#include <linux/bitops.h>
#include <linux/interrupt.h>
#include <linux/netdevice.h>
#include <net/netlink.h>
#include <linux/tcp.h>
#include <linux/udp.h>
#include <linux/dccp.h>
#include <linux/sctp.h>
#include <net/sctp/structs.h>
#include <linux/quota.h>
#include <linux/un.h>
#include <net/af_unix.h>
#include <linux/parser.h>
#include <linux/nfs_mount.h>
#include <net/ipv6.h>
#include <linux/hugetlb.h>
#include <linux/personality.h>
#include <linux/audit.h>
#include <linux/string.h>
#include <linux/mutex.h>
#include <linux/posix-timers.h>
#include <linux/syslog.h>
#include <linux/user_namespace.h>
#include <linux/export.h>
#include <linux/msg.h>
#include <linux/shm.h>
#include <uapi/linux/shm.h>
#include <linux/bpf.h>
#include <linux/kernfs.h>
#include <linux/stringhash.h>
#include <uapi/linux/mount.h>
#include <linux/fsnotify.h>
#include <linux/fanotify.h>
#include <linux/io_uring/cmd.h>
#include <uapi/linux/lsm.h>
#include "avc.h"
#include "objsec.h"
#include "netif.h"
#include "netnode.h"
#include "netport.h"
#include "ibpkey.h"
#include "xfrm.h"
#include "netlabel.h"
#include "audit.h"
#include "avc_ss.h"
#define SELINUX_INODE_INIT_XATTRS …
struct selinux_state selinux_state;
static atomic_t selinux_secmark_refcount = …;
#ifdef CONFIG_SECURITY_SELINUX_DEVELOP
static int selinux_enforcing_boot __initdata;
static int __init enforcing_setup(char *str)
{ … }
__setup(…);
#else
#define selinux_enforcing_boot …
#endif
int selinux_enabled_boot __initdata = …;
#ifdef CONFIG_SECURITY_SELINUX_BOOTPARAM
static int __init selinux_enabled_setup(char *str)
{ … }
__setup(…);
#endif
static int __init checkreqprot_setup(char *str)
{ … }
__setup(…);
static int selinux_secmark_enabled(void)
{ … }
static int selinux_peerlbl_enabled(void)
{ … }
static int selinux_netcache_avc_callback(u32 event)
{ … }
static int selinux_lsm_notifier_avc_callback(u32 event)
{ … }
static void cred_init_security(void)
{ … }
static inline u32 cred_sid(const struct cred *cred)
{ … }
static void __ad_net_init(struct common_audit_data *ad,
struct lsm_network_audit *net,
int ifindex, struct sock *sk, u16 family)
{ … }
static void ad_net_init_from_sk(struct common_audit_data *ad,
struct lsm_network_audit *net,
struct sock *sk)
{ … }
static void ad_net_init_from_iif(struct common_audit_data *ad,
struct lsm_network_audit *net,
int ifindex, u16 family)
{ … }
static inline u32 task_sid_obj(const struct task_struct *task)
{ … }
static int inode_doinit_with_dentry(struct inode *inode, struct dentry *opt_dentry);
static int __inode_security_revalidate(struct inode *inode,
struct dentry *dentry,
bool may_sleep)
{ … }
static struct inode_security_struct *inode_security_novalidate(struct inode *inode)
{ … }
static struct inode_security_struct *inode_security_rcu(struct inode *inode, bool rcu)
{ … }
static struct inode_security_struct *inode_security(struct inode *inode)
{ … }
static struct inode_security_struct *backing_inode_security_novalidate(struct dentry *dentry)
{ … }
static struct inode_security_struct *backing_inode_security(struct dentry *dentry)
{ … }
static void inode_free_security(struct inode *inode)
{ … }
struct selinux_mnt_opts { … };
static void selinux_free_mnt_opts(void *mnt_opts)
{ … }
enum { … };
#define A …
static const struct { … } tokens[] = …;
#undef A
static int match_opt_prefix(char *s, int l, char **arg)
{ … }
#define SEL_MOUNT_FAIL_MSG …
static int may_context_mount_sb_relabel(u32 sid,
struct superblock_security_struct *sbsec,
const struct cred *cred)
{ … }
static int may_context_mount_inode_relabel(u32 sid,
struct superblock_security_struct *sbsec,
const struct cred *cred)
{ … }
static int selinux_is_genfs_special_handling(struct super_block *sb)
{ … }
static int selinux_is_sblabel_mnt(struct super_block *sb)
{ … }
static int sb_check_xattr_support(struct super_block *sb)
{ … }
static int sb_finish_set_opts(struct super_block *sb)
{ … }
static int bad_option(struct superblock_security_struct *sbsec, char flag,
u32 old_sid, u32 new_sid)
{ … }
static int selinux_set_mnt_opts(struct super_block *sb,
void *mnt_opts,
unsigned long kern_flags,
unsigned long *set_kern_flags)
{ … }
static int selinux_cmp_sb_context(const struct super_block *oldsb,
const struct super_block *newsb)
{ … }
static int selinux_sb_clone_mnt_opts(const struct super_block *oldsb,
struct super_block *newsb,
unsigned long kern_flags,
unsigned long *set_kern_flags)
{ … }
static int selinux_add_opt(int token, const char *s, void **mnt_opts)
{ … }
static int show_sid(struct seq_file *m, u32 sid)
{ … }
static int selinux_sb_show_options(struct seq_file *m, struct super_block *sb)
{ … }
static inline u16 inode_mode_to_security_class(umode_t mode)
{ … }
static inline int default_protocol_stream(int protocol)
{ … }
static inline int default_protocol_dgram(int protocol)
{ … }
static inline u16 socket_type_to_security_class(int family, int type, int protocol)
{ … }
static int selinux_genfs_get_sid(struct dentry *dentry,
u16 tclass,
u16 flags,
u32 *sid)
{ … }
static int inode_doinit_use_xattr(struct inode *inode, struct dentry *dentry,
u32 def_sid, u32 *sid)
{ … }
static int inode_doinit_with_dentry(struct inode *inode, struct dentry *opt_dentry)
{ … }
static inline u32 signal_to_av(int sig)
{ … }
#if CAP_LAST_CAP > 63
#error Fix SELinux to handle capabilities > 63.
#endif
static int cred_has_capability(const struct cred *cred,
int cap, unsigned int opts, bool initns)
{ … }
static int inode_has_perm(const struct cred *cred,
struct inode *inode,
u32 perms,
struct common_audit_data *adp)
{ … }
static inline int dentry_has_perm(const struct cred *cred,
struct dentry *dentry,
u32 av)
{ … }
static inline int path_has_perm(const struct cred *cred,
const struct path *path,
u32 av)
{ … }
static inline int file_path_has_perm(const struct cred *cred,
struct file *file,
u32 av)
{ … }
#ifdef CONFIG_BPF_SYSCALL
static int bpf_fd_pass(const struct file *file, u32 sid);
#endif
static int file_has_perm(const struct cred *cred,
struct file *file,
u32 av)
{ … }
static int
selinux_determine_inode_label(const struct task_security_struct *tsec,
struct inode *dir,
const struct qstr *name, u16 tclass,
u32 *_new_isid)
{ … }
static int may_create(struct inode *dir,
struct dentry *dentry,
u16 tclass)
{ … }
#define MAY_LINK …
#define MAY_UNLINK …
#define MAY_RMDIR …
static int may_link(struct inode *dir,
struct dentry *dentry,
int kind)
{ … }
static inline int may_rename(struct inode *old_dir,
struct dentry *old_dentry,
struct inode *new_dir,
struct dentry *new_dentry)
{ … }
static int superblock_has_perm(const struct cred *cred,
const struct super_block *sb,
u32 perms,
struct common_audit_data *ad)
{ … }
static inline u32 file_mask_to_av(int mode, int mask)
{ … }
static inline u32 file_to_av(const struct file *file)
{ … }
static inline u32 open_file_to_av(struct file *file)
{ … }
static int selinux_binder_set_context_mgr(const struct cred *mgr)
{ … }
static int selinux_binder_transaction(const struct cred *from,
const struct cred *to)
{ … }
static int selinux_binder_transfer_binder(const struct cred *from,
const struct cred *to)
{ … }
static int selinux_binder_transfer_file(const struct cred *from,
const struct cred *to,
const struct file *file)
{ … }
static int selinux_ptrace_access_check(struct task_struct *child,
unsigned int mode)
{ … }
static int selinux_ptrace_traceme(struct task_struct *parent)
{ … }
static int selinux_capget(const struct task_struct *target, kernel_cap_t *effective,
kernel_cap_t *inheritable, kernel_cap_t *permitted)
{ … }
static int selinux_capset(struct cred *new, const struct cred *old,
const kernel_cap_t *effective,
const kernel_cap_t *inheritable,
const kernel_cap_t *permitted)
{ … }
static int selinux_capable(const struct cred *cred, struct user_namespace *ns,
int cap, unsigned int opts)
{ … }
static int selinux_quotactl(int cmds, int type, int id, const struct super_block *sb)
{ … }
static int selinux_quota_on(struct dentry *dentry)
{ … }
static int selinux_syslog(int type)
{ … }
static int selinux_vm_enough_memory(struct mm_struct *mm, long pages)
{ … }
static u32 ptrace_parent_sid(void)
{ … }
static int check_nnp_nosuid(const struct linux_binprm *bprm,
const struct task_security_struct *old_tsec,
const struct task_security_struct *new_tsec)
{ … }
static int selinux_bprm_creds_for_exec(struct linux_binprm *bprm)
{ … }
static int match_file(const void *p, struct file *file, unsigned fd)
{ … }
static inline void flush_unauthorized_files(const struct cred *cred,
struct files_struct *files)
{ … }
static void selinux_bprm_committing_creds(const struct linux_binprm *bprm)
{ … }
static void selinux_bprm_committed_creds(const struct linux_binprm *bprm)
{ … }
static int selinux_sb_alloc_security(struct super_block *sb)
{ … }
static inline int opt_len(const char *s)
{ … }
static int selinux_sb_eat_lsm_opts(char *options, void **mnt_opts)
{ … }
static int selinux_sb_mnt_opts_compat(struct super_block *sb, void *mnt_opts)
{ … }
static int selinux_sb_remount(struct super_block *sb, void *mnt_opts)
{ … }
static int selinux_sb_kern_mount(const struct super_block *sb)
{ … }
static int selinux_sb_statfs(struct dentry *dentry)
{ … }
static int selinux_mount(const char *dev_name,
const struct path *path,
const char *type,
unsigned long flags,
void *data)
{ … }
static int selinux_move_mount(const struct path *from_path,
const struct path *to_path)
{ … }
static int selinux_umount(struct vfsmount *mnt, int flags)
{ … }
static int selinux_fs_context_submount(struct fs_context *fc,
struct super_block *reference)
{ … }
static int selinux_fs_context_dup(struct fs_context *fc,
struct fs_context *src_fc)
{ … }
static const struct fs_parameter_spec selinux_fs_parameters[] = …;
static int selinux_fs_context_parse_param(struct fs_context *fc,
struct fs_parameter *param)
{ … }
static int selinux_inode_alloc_security(struct inode *inode)
{ … }
static void selinux_inode_free_security(struct inode *inode)
{ … }
static int selinux_dentry_init_security(struct dentry *dentry, int mode,
const struct qstr *name,
const char **xattr_name, void **ctx,
u32 *ctxlen)
{ … }
static int selinux_dentry_create_files_as(struct dentry *dentry, int mode,
struct qstr *name,
const struct cred *old,
struct cred *new)
{ … }
static int selinux_inode_init_security(struct inode *inode, struct inode *dir,
const struct qstr *qstr,
struct xattr *xattrs, int *xattr_count)
{ … }
static int selinux_inode_init_security_anon(struct inode *inode,
const struct qstr *name,
const struct inode *context_inode)
{ … }
static int selinux_inode_create(struct inode *dir, struct dentry *dentry, umode_t mode)
{ … }
static int selinux_inode_link(struct dentry *old_dentry, struct inode *dir, struct dentry *new_dentry)
{ … }
static int selinux_inode_unlink(struct inode *dir, struct dentry *dentry)
{ … }
static int selinux_inode_symlink(struct inode *dir, struct dentry *dentry, const char *name)
{ … }
static int selinux_inode_mkdir(struct inode *dir, struct dentry *dentry, umode_t mask)
{ … }
static int selinux_inode_rmdir(struct inode *dir, struct dentry *dentry)
{ … }
static int selinux_inode_mknod(struct inode *dir, struct dentry *dentry, umode_t mode, dev_t dev)
{ … }
static int selinux_inode_rename(struct inode *old_inode, struct dentry *old_dentry,
struct inode *new_inode, struct dentry *new_dentry)
{ … }
static int selinux_inode_readlink(struct dentry *dentry)
{ … }
static int selinux_inode_follow_link(struct dentry *dentry, struct inode *inode,
bool rcu)
{ … }
static noinline int audit_inode_permission(struct inode *inode,
u32 perms, u32 audited, u32 denied,
int result)
{ … }
static int selinux_inode_permission(struct inode *inode, int mask)
{ … }
static int selinux_inode_setattr(struct mnt_idmap *idmap, struct dentry *dentry,
struct iattr *iattr)
{ … }
static int selinux_inode_getattr(const struct path *path)
{ … }
static bool has_cap_mac_admin(bool audit)
{ … }
static int selinux_inode_xattr_skipcap(const char *name)
{ … }
static int selinux_inode_setxattr(struct mnt_idmap *idmap,
struct dentry *dentry, const char *name,
const void *value, size_t size, int flags)
{ … }
static int selinux_inode_set_acl(struct mnt_idmap *idmap,
struct dentry *dentry, const char *acl_name,
struct posix_acl *kacl)
{ … }
static int selinux_inode_get_acl(struct mnt_idmap *idmap,
struct dentry *dentry, const char *acl_name)
{ … }
static int selinux_inode_remove_acl(struct mnt_idmap *idmap,
struct dentry *dentry, const char *acl_name)
{ … }
static void selinux_inode_post_setxattr(struct dentry *dentry, const char *name,
const void *value, size_t size,
int flags)
{ … }
static int selinux_inode_getxattr(struct dentry *dentry, const char *name)
{ … }
static int selinux_inode_listxattr(struct dentry *dentry)
{ … }
static int selinux_inode_removexattr(struct mnt_idmap *idmap,
struct dentry *dentry, const char *name)
{ … }
static int selinux_path_notify(const struct path *path, u64 mask,
unsigned int obj_type)
{ … }
static int selinux_inode_getsecurity(struct mnt_idmap *idmap,
struct inode *inode, const char *name,
void **buffer, bool alloc)
{ … }
static int selinux_inode_setsecurity(struct inode *inode, const char *name,
const void *value, size_t size, int flags)
{ … }
static int selinux_inode_listsecurity(struct inode *inode, char *buffer, size_t buffer_size)
{ … }
static void selinux_inode_getsecid(struct inode *inode, u32 *secid)
{ … }
static int selinux_inode_copy_up(struct dentry *src, struct cred **new)
{ … }
static int selinux_inode_copy_up_xattr(struct dentry *dentry, const char *name)
{ … }
static int selinux_kernfs_init_security(struct kernfs_node *kn_dir,
struct kernfs_node *kn)
{ … }
static int selinux_revalidate_file_permission(struct file *file, int mask)
{ … }
static int selinux_file_permission(struct file *file, int mask)
{ … }
static int selinux_file_alloc_security(struct file *file)
{ … }
static int ioctl_has_perm(const struct cred *cred, struct file *file,
u32 requested, u16 cmd)
{ … }
static int selinux_file_ioctl(struct file *file, unsigned int cmd,
unsigned long arg)
{ … }
static int selinux_file_ioctl_compat(struct file *file, unsigned int cmd,
unsigned long arg)
{ … }
static int default_noexec __ro_after_init;
static int file_map_prot_check(struct file *file, unsigned long prot, int shared)
{ … }
static int selinux_mmap_addr(unsigned long addr)
{ … }
static int selinux_mmap_file(struct file *file,
unsigned long reqprot __always_unused,
unsigned long prot, unsigned long flags)
{ … }
static int selinux_file_mprotect(struct vm_area_struct *vma,
unsigned long reqprot __always_unused,
unsigned long prot)
{ … }
static int selinux_file_lock(struct file *file, unsigned int cmd)
{ … }
static int selinux_file_fcntl(struct file *file, unsigned int cmd,
unsigned long arg)
{ … }
static void selinux_file_set_fowner(struct file *file)
{ … }
static int selinux_file_send_sigiotask(struct task_struct *tsk,
struct fown_struct *fown, int signum)
{ … }
static int selinux_file_receive(struct file *file)
{ … }
static int selinux_file_open(struct file *file)
{ … }
static int selinux_task_alloc(struct task_struct *task,
unsigned long clone_flags)
{ … }
static int selinux_cred_prepare(struct cred *new, const struct cred *old,
gfp_t gfp)
{ … }
static void selinux_cred_transfer(struct cred *new, const struct cred *old)
{ … }
static void selinux_cred_getsecid(const struct cred *c, u32 *secid)
{ … }
static int selinux_kernel_act_as(struct cred *new, u32 secid)
{ … }
static int selinux_kernel_create_files_as(struct cred *new, struct inode *inode)
{ … }
static int selinux_kernel_module_request(char *kmod_name)
{ … }
static int selinux_kernel_module_from_file(struct file *file)
{ … }
static int selinux_kernel_read_file(struct file *file,
enum kernel_read_file_id id,
bool contents)
{ … }
static int selinux_kernel_load_data(enum kernel_load_data_id id, bool contents)
{ … }
static int selinux_task_setpgid(struct task_struct *p, pid_t pgid)
{ … }
static int selinux_task_getpgid(struct task_struct *p)
{ … }
static int selinux_task_getsid(struct task_struct *p)
{ … }
static void selinux_current_getsecid_subj(u32 *secid)
{ … }
static void selinux_task_getsecid_obj(struct task_struct *p, u32 *secid)
{ … }
static int selinux_task_setnice(struct task_struct *p, int nice)
{ … }
static int selinux_task_setioprio(struct task_struct *p, int ioprio)
{ … }
static int selinux_task_getioprio(struct task_struct *p)
{ … }
static int selinux_task_prlimit(const struct cred *cred, const struct cred *tcred,
unsigned int flags)
{ … }
static int selinux_task_setrlimit(struct task_struct *p, unsigned int resource,
struct rlimit *new_rlim)
{ … }
static int selinux_task_setscheduler(struct task_struct *p)
{ … }
static int selinux_task_getscheduler(struct task_struct *p)
{ … }
static int selinux_task_movememory(struct task_struct *p)
{ … }
static int selinux_task_kill(struct task_struct *p, struct kernel_siginfo *info,
int sig, const struct cred *cred)
{ … }
static void selinux_task_to_inode(struct task_struct *p,
struct inode *inode)
{ … }
static int selinux_userns_create(const struct cred *cred)
{ … }
static int selinux_parse_skb_ipv4(struct sk_buff *skb,
struct common_audit_data *ad, u8 *proto)
{ … }
#if IS_ENABLED(CONFIG_IPV6)
static int selinux_parse_skb_ipv6(struct sk_buff *skb,
struct common_audit_data *ad, u8 *proto)
{ … }
#endif
static int selinux_parse_skb(struct sk_buff *skb, struct common_audit_data *ad,
char **_addrp, int src, u8 *proto)
{ … }
static int selinux_skb_peerlbl_sid(struct sk_buff *skb, u16 family, u32 *sid)
{ … }
static int selinux_conn_sid(u32 sk_sid, u32 skb_sid, u32 *conn_sid)
{ … }
static int socket_sockcreate_sid(const struct task_security_struct *tsec,
u16 secclass, u32 *socksid)
{ … }
static int sock_has_perm(struct sock *sk, u32 perms)
{ … }
static int selinux_socket_create(int family, int type,
int protocol, int kern)
{ … }
static int selinux_socket_post_create(struct socket *sock, int family,
int type, int protocol, int kern)
{ … }
static int selinux_socket_socketpair(struct socket *socka,
struct socket *sockb)
{ … }
static int selinux_socket_bind(struct socket *sock, struct sockaddr *address, int addrlen)
{ … }
static int selinux_socket_connect_helper(struct socket *sock,
struct sockaddr *address, int addrlen)
{ … }
static int selinux_socket_connect(struct socket *sock,
struct sockaddr *address, int addrlen)
{ … }
static int selinux_socket_listen(struct socket *sock, int backlog)
{ … }
static int selinux_socket_accept(struct socket *sock, struct socket *newsock)
{ … }
static int selinux_socket_sendmsg(struct socket *sock, struct msghdr *msg,
int size)
{ … }
static int selinux_socket_recvmsg(struct socket *sock, struct msghdr *msg,
int size, int flags)
{ … }
static int selinux_socket_getsockname(struct socket *sock)
{ … }
static int selinux_socket_getpeername(struct socket *sock)
{ … }
static int selinux_socket_setsockopt(struct socket *sock, int level, int optname)
{ … }
static int selinux_socket_getsockopt(struct socket *sock, int level,
int optname)
{ … }
static int selinux_socket_shutdown(struct socket *sock, int how)
{ … }
static int selinux_socket_unix_stream_connect(struct sock *sock,
struct sock *other,
struct sock *newsk)
{ … }
static int selinux_socket_unix_may_send(struct socket *sock,
struct socket *other)
{ … }
static int selinux_inet_sys_rcv_skb(struct net *ns, int ifindex,
char *addrp, u16 family, u32 peer_sid,
struct common_audit_data *ad)
{ … }
static int selinux_sock_rcv_skb_compat(struct sock *sk, struct sk_buff *skb,
u16 family)
{ … }
static int selinux_socket_sock_rcv_skb(struct sock *sk, struct sk_buff *skb)
{ … }
static int selinux_socket_getpeersec_stream(struct socket *sock,
sockptr_t optval, sockptr_t optlen,
unsigned int len)
{ … }
static int selinux_socket_getpeersec_dgram(struct socket *sock,
struct sk_buff *skb, u32 *secid)
{ … }
static int selinux_sk_alloc_security(struct sock *sk, int family, gfp_t priority)
{ … }
static void selinux_sk_free_security(struct sock *sk)
{ … }
static void selinux_sk_clone_security(const struct sock *sk, struct sock *newsk)
{ … }
static void selinux_sk_getsecid(const struct sock *sk, u32 *secid)
{ … }
static void selinux_sock_graft(struct sock *sk, struct socket *parent)
{ … }
static int selinux_sctp_process_new_assoc(struct sctp_association *asoc,
struct sk_buff *skb)
{ … }
static int selinux_sctp_assoc_request(struct sctp_association *asoc,
struct sk_buff *skb)
{ … }
static int selinux_sctp_assoc_established(struct sctp_association *asoc,
struct sk_buff *skb)
{ … }
static int selinux_sctp_bind_connect(struct sock *sk, int optname,
struct sockaddr *address,
int addrlen)
{ … }
static void selinux_sctp_sk_clone(struct sctp_association *asoc, struct sock *sk,
struct sock *newsk)
{ … }
static int selinux_mptcp_add_subflow(struct sock *sk, struct sock *ssk)
{ … }
static int selinux_inet_conn_request(const struct sock *sk, struct sk_buff *skb,
struct request_sock *req)
{ … }
static void selinux_inet_csk_clone(struct sock *newsk,
const struct request_sock *req)
{ … }
static void selinux_inet_conn_established(struct sock *sk, struct sk_buff *skb)
{ … }
static int selinux_secmark_relabel_packet(u32 sid)
{ … }
static void selinux_secmark_refcount_inc(void)
{ … }
static void selinux_secmark_refcount_dec(void)
{ … }
static void selinux_req_classify_flow(const struct request_sock *req,
struct flowi_common *flic)
{ … }
static int selinux_tun_dev_alloc_security(void *security)
{ … }
static int selinux_tun_dev_create(void)
{ … }
static int selinux_tun_dev_attach_queue(void *security)
{ … }
static int selinux_tun_dev_attach(struct sock *sk, void *security)
{ … }
static int selinux_tun_dev_open(void *security)
{ … }
#ifdef CONFIG_NETFILTER
static unsigned int selinux_ip_forward(void *priv, struct sk_buff *skb,
const struct nf_hook_state *state)
{ … }
static unsigned int selinux_ip_output(void *priv, struct sk_buff *skb,
const struct nf_hook_state *state)
{ … }
static unsigned int selinux_ip_postroute_compat(struct sk_buff *skb,
const struct nf_hook_state *state)
{ … }
static unsigned int selinux_ip_postroute(void *priv,
struct sk_buff *skb,
const struct nf_hook_state *state)
{ … }
#endif
static int selinux_netlink_send(struct sock *sk, struct sk_buff *skb)
{ … }
static void ipc_init_security(struct ipc_security_struct *isec, u16 sclass)
{ … }
static int ipc_has_perm(struct kern_ipc_perm *ipc_perms,
u32 perms)
{ … }
static int selinux_msg_msg_alloc_security(struct msg_msg *msg)
{ … }
static int selinux_msg_queue_alloc_security(struct kern_ipc_perm *msq)
{ … }
static int selinux_msg_queue_associate(struct kern_ipc_perm *msq, int msqflg)
{ … }
static int selinux_msg_queue_msgctl(struct kern_ipc_perm *msq, int cmd)
{ … }
static int selinux_msg_queue_msgsnd(struct kern_ipc_perm *msq, struct msg_msg *msg, int msqflg)
{ … }
static int selinux_msg_queue_msgrcv(struct kern_ipc_perm *msq, struct msg_msg *msg,
struct task_struct *target,
long type, int mode)
{ … }
static int selinux_shm_alloc_security(struct kern_ipc_perm *shp)
{ … }
static int selinux_shm_associate(struct kern_ipc_perm *shp, int shmflg)
{ … }
static int selinux_shm_shmctl(struct kern_ipc_perm *shp, int cmd)
{ … }
static int selinux_shm_shmat(struct kern_ipc_perm *shp,
char __user *shmaddr, int shmflg)
{ … }
static int selinux_sem_alloc_security(struct kern_ipc_perm *sma)
{ … }
static int selinux_sem_associate(struct kern_ipc_perm *sma, int semflg)
{ … }
static int selinux_sem_semctl(struct kern_ipc_perm *sma, int cmd)
{ … }
static int selinux_sem_semop(struct kern_ipc_perm *sma,
struct sembuf *sops, unsigned nsops, int alter)
{ … }
static int selinux_ipc_permission(struct kern_ipc_perm *ipcp, short flag)
{ … }
static void selinux_ipc_getsecid(struct kern_ipc_perm *ipcp, u32 *secid)
{ … }
static void selinux_d_instantiate(struct dentry *dentry, struct inode *inode)
{ … }
static int selinux_lsm_getattr(unsigned int attr, struct task_struct *p,
char **value)
{ … }
static int selinux_lsm_setattr(u64 attr, void *value, size_t size)
{ … }
static int selinux_getselfattr(unsigned int attr, struct lsm_ctx __user *ctx,
u32 *size, u32 flags)
{ … }
static int selinux_setselfattr(unsigned int attr, struct lsm_ctx *ctx,
u32 size, u32 flags)
{ … }
static int selinux_getprocattr(struct task_struct *p,
const char *name, char **value)
{ … }
static int selinux_setprocattr(const char *name, void *value, size_t size)
{ … }
static int selinux_ismaclabel(const char *name)
{ … }
static int selinux_secid_to_secctx(u32 secid, char **secdata, u32 *seclen)
{ … }
static int selinux_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid)
{ … }
static void selinux_release_secctx(char *secdata, u32 seclen)
{ … }
static void selinux_inode_invalidate_secctx(struct inode *inode)
{ … }
static int selinux_inode_notifysecctx(struct inode *inode, void *ctx, u32 ctxlen)
{ … }
static int selinux_inode_setsecctx(struct dentry *dentry, void *ctx, u32 ctxlen)
{ … }
static int selinux_inode_getsecctx(struct inode *inode, void **ctx, u32 *ctxlen)
{ … }
#ifdef CONFIG_KEYS
static int selinux_key_alloc(struct key *k, const struct cred *cred,
unsigned long flags)
{ … }
static int selinux_key_permission(key_ref_t key_ref,
const struct cred *cred,
enum key_need_perm need_perm)
{ … }
static int selinux_key_getsecurity(struct key *key, char **_buffer)
{ … }
#ifdef CONFIG_KEY_NOTIFICATIONS
static int selinux_watch_key(struct key *key)
{ … }
#endif
#endif
#ifdef CONFIG_SECURITY_INFINIBAND
static int selinux_ib_pkey_access(void *ib_sec, u64 subnet_prefix, u16 pkey_val)
{ … }
static int selinux_ib_endport_manage_subnet(void *ib_sec, const char *dev_name,
u8 port_num)
{ … }
static int selinux_ib_alloc_security(void *ib_sec)
{ … }
#endif
#ifdef CONFIG_BPF_SYSCALL
static int selinux_bpf(int cmd, union bpf_attr *attr,
unsigned int size)
{ … }
static u32 bpf_map_fmode_to_av(fmode_t fmode)
{ … }
static int bpf_fd_pass(const struct file *file, u32 sid)
{ … }
static int selinux_bpf_map(struct bpf_map *map, fmode_t fmode)
{ … }
static int selinux_bpf_prog(struct bpf_prog *prog)
{ … }
static int selinux_bpf_map_create(struct bpf_map *map, union bpf_attr *attr,
struct bpf_token *token)
{ … }
static void selinux_bpf_map_free(struct bpf_map *map)
{ … }
static int selinux_bpf_prog_load(struct bpf_prog *prog, union bpf_attr *attr,
struct bpf_token *token)
{ … }
static void selinux_bpf_prog_free(struct bpf_prog *prog)
{ … }
static int selinux_bpf_token_create(struct bpf_token *token, union bpf_attr *attr,
const struct path *path)
{ … }
static void selinux_bpf_token_free(struct bpf_token *token)
{ … }
#endif
struct lsm_blob_sizes selinux_blob_sizes __ro_after_init = …;
#ifdef CONFIG_PERF_EVENTS
static int selinux_perf_event_open(struct perf_event_attr *attr, int type)
{ … }
static int selinux_perf_event_alloc(struct perf_event *event)
{ … }
static int selinux_perf_event_read(struct perf_event *event)
{ … }
static int selinux_perf_event_write(struct perf_event *event)
{ … }
#endif
#ifdef CONFIG_IO_URING
static int selinux_uring_override_creds(const struct cred *new)
{ … }
static int selinux_uring_sqpoll(void)
{ … }
static int selinux_uring_cmd(struct io_uring_cmd *ioucmd)
{ … }
#endif
static const struct lsm_id selinux_lsmid = …;
static struct security_hook_list selinux_hooks[] __ro_after_init = …;
static __init int selinux_init(void)
{ … }
static void delayed_superblock_init(struct super_block *sb, void *unused)
{ … }
void selinux_complete_init(void)
{ … }
DEFINE_LSM(selinux) = …;
#if defined(CONFIG_NETFILTER)
static const struct nf_hook_ops selinux_nf_ops[] = …;
static int __net_init selinux_nf_register(struct net *net)
{ … }
static void __net_exit selinux_nf_unregister(struct net *net)
{ … }
static struct pernet_operations selinux_net_ops = …;
static int __init selinux_nf_ip_init(void)
{ … }
__initcall(selinux_nf_ip_init);
#endif