diff options
Diffstat (limited to 'security/selinux/include')
| -rw-r--r-- | security/selinux/include/netnode.h | 32 | ||||
| -rw-r--r-- | security/selinux/include/objsec.h | 9 | 
2 files changed, 41 insertions, 0 deletions
diff --git a/security/selinux/include/netnode.h b/security/selinux/include/netnode.h new file mode 100644 index 00000000000..1b94450d11d --- /dev/null +++ b/security/selinux/include/netnode.h @@ -0,0 +1,32 @@ +/* + * Network node table + * + * SELinux must keep a mapping of network nodes to labels/SIDs.  This + * mapping is maintained as part of the normal policy but a fast cache is + * needed to reduce the lookup overhead since most of these queries happen on + * a per-packet basis. + * + * Author: Paul Moore <paul.moore@hp.com> + * + */ + +/* + * (c) Copyright Hewlett-Packard Development Company, L.P., 2007 + * + * This program is free software: you can redistribute it and/or modify + * it under the terms of version 2 of the GNU General Public License as + * published by the Free Software Foundation. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the + * GNU General Public License for more details. + * + */ + +#ifndef _SELINUX_NETNODE_H +#define _SELINUX_NETNODE_H + +int sel_netnode_sid(void *addr, u16 family, u32 *sid); + +#endif diff --git a/security/selinux/include/objsec.h b/security/selinux/include/objsec.h index 2d0a92e97d5..95fb5ec1735 100644 --- a/security/selinux/include/objsec.h +++ b/security/selinux/include/objsec.h @@ -100,6 +100,15 @@ struct netif_security_struct {  	u32 sid;			/* SID for this interface */  }; +struct netnode_security_struct { +	union { +		__be32 ipv4;		/* IPv4 node address */ +		struct in6_addr ipv6;	/* IPv6 node address */ +	} addr; +	u32 sid;			/* SID for this node */ +	u16 family;			/* address family */ +}; +  struct sk_security_struct {  	struct sock *sk;		/* back pointer to sk object */  	u32 sid;			/* SID of this object */  |