Home
last modified time | relevance | path

Searched refs:secid (Results 1 – 25 of 49) sorted by relevance

12

/Linux-v5.15/security/apparmor/
Dsecid.c46 void aa_secid_update(u32 secid, struct aa_label *label) in aa_secid_update() argument
51 idr_replace(&aa_secids, label, secid); in aa_secid_update()
59 struct aa_label *aa_secid_to_label(u32 secid) in aa_secid_to_label() argument
64 label = idr_find(&aa_secids, secid); in aa_secid_to_label()
70 int apparmor_secid_to_secctx(u32 secid, char **secdata, u32 *seclen) in apparmor_secid_to_secctx() argument
73 struct aa_label *label = aa_secid_to_label(secid); in apparmor_secid_to_secctx()
98 int apparmor_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid) in apparmor_secctx_to_secid() argument
106 *secid = label->secid; in apparmor_secctx_to_secid()
136 label->secid = AA_SECID_INVALID; in aa_alloc_secid()
141 label->secid = ret; in aa_alloc_secid()
[all …]
Dnet.c197 secmark->secid = AA_SECID_WILDCARD; in apparmor_secmark_init()
208 secmark->secid = label->secid; in apparmor_secmark_init()
213 static int aa_secmark_perm(struct aa_profile *profile, u32 request, u32 secid, in aa_secmark_perm() argument
223 if (!profile->secmark[i].secid) { in aa_secmark_perm()
229 if (profile->secmark[i].secid == secid || in aa_secmark_perm()
230 profile->secmark[i].secid == AA_SECID_WILDCARD) { in aa_secmark_perm()
247 u32 secid, const struct sock *sk) in apparmor_secmark_check() argument
253 aa_secmark_perm(profile, request, secid, in apparmor_secmark_check()
/Linux-v5.15/net/netfilter/
Dxt_SECMARK.c33 secmark = info->secid; in secmark_tg()
48 info->secid = 0; in checkentry_lsm()
51 &info->secid); in checkentry_lsm()
59 if (!info->secid) { in checkentry_lsm()
65 err = security_secmark_relabel_packet(info->secid); in checkentry_lsm()
129 info->secid = newinfo.secid; in secmark_tg_check_v0()
139 .secid = info->secid, in secmark_tg_v0()
175 .usersize = offsetof(struct xt_secmark_target_info_v1, secid),
/Linux-v5.15/security/apparmor/include/
Dsecid.h24 struct aa_label *aa_secid_to_label(u32 secid);
25 int apparmor_secid_to_secctx(u32 secid, char **secdata, u32 *seclen);
26 int apparmor_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid);
31 void aa_free_secid(u32 secid);
32 void aa_secid_update(u32 secid, struct aa_label *label);
Dnet.h85 u32 secid; member
110 u32 secid, const struct sock *sk);
/Linux-v5.15/security/integrity/ima/
Dima_main.c202 u32 secid, char *buf, loff_t size, int mask, in process_measurement() argument
227 action = ima_get_action(file_mnt_user_ns(file), inode, cred, secid, in process_measurement()
408 u32 secid; in ima_file_mmap() local
411 security_task_getsecid_subj(current, &secid); in ima_file_mmap()
412 return process_measurement(file, current_cred(), secid, NULL, in ima_file_mmap()
441 u32 secid; in ima_file_mprotect() local
449 security_task_getsecid_subj(current, &secid); in ima_file_mprotect()
452 current_cred(), secid, MAY_EXEC, MMAP_CHECK, in ima_file_mprotect()
488 u32 secid; in ima_bprm_check() local
490 security_task_getsecid_subj(current, &secid); in ima_bprm_check()
[all …]
Dima.h258 const struct cred *cred, u32 secid, int mask,
289 const struct cred *cred, u32 secid, enum ima_hooks func,
440 static inline int ima_filter_rule_match(u32 secid, u32 field, u32 op, in ima_filter_rule_match() argument
/Linux-v5.15/net/netlabel/
Dnetlabel_unlabeled.c69 u32 secid; member
77 u32 secid; member
234 u32 secid) in netlbl_unlhsh_add_addr4() argument
246 entry->secid = secid; in netlbl_unlhsh_add_addr4()
274 u32 secid) in netlbl_unlhsh_add_addr6() argument
290 entry->secid = secid; in netlbl_unlhsh_add_addr6()
369 u32 secid, in netlbl_unlhsh_add() argument
411 ret_val = netlbl_unlhsh_add_addr4(iface, addr4, mask4, secid); in netlbl_unlhsh_add()
424 ret_val = netlbl_unlhsh_add_addr6(iface, addr6, mask6, secid); in netlbl_unlhsh_add()
441 if (security_secid_to_secctx(secid, in netlbl_unlhsh_add()
[all …]
Dnetlabel_user.c101 if (audit_info->secid != 0 && in netlbl_audit_start_common()
102 security_secid_to_secctx(audit_info->secid, in netlbl_audit_start_common()
Dnetlabel_user.h35 security_task_getsecid_subj(current, &audit_info->secid); in netlbl_netlink_auditinfo()
Dnetlabel_unlabeled.h214 u32 secid,
/Linux-v5.15/drivers/dio/
Ddio.c119 u_char prid, secid, i; in dio_find() local
148 secid = DIO_SECID(va); in dio_find()
149 id = DIO_ENCODE_ID(prid, secid); in dio_find()
195 u_char prid, secid = 0; /* primary, secondary ID bytes */ in dio_init() local
236 secid = DIO_SECID(va); in dio_init()
237 dev->id = DIO_ENCODE_ID(prid, secid); in dio_init()
245 printk(":%02X", secid); in dio_init()
/Linux-v5.15/include/linux/
Dsecurity.h374 void security_inode_getsecid(struct inode *inode, u32 *secid);
401 void security_cred_getsecid(const struct cred *c, u32 *secid);
402 int security_kernel_act_as(struct cred *new, u32 secid);
420 void security_task_getsecid_subj(struct task_struct *p, u32 *secid);
421 void security_task_getsecid_obj(struct task_struct *p, u32 *secid);
438 void security_ipc_getsecid(struct kern_ipc_perm *ipcp, u32 *secid);
467 int security_secid_to_secctx(u32 secid, char **secdata, u32 *seclen);
468 int security_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid);
924 static inline void security_inode_getsecid(struct inode *inode, u32 *secid) in security_inode_getsecid() argument
926 *secid = 0; in security_inode_getsecid()
[all …]
Dlsm_hook_defs.h158 LSM_HOOK(void, LSM_RET_VOID, inode_getsecid, struct inode *inode, u32 *secid)
190 LSM_HOOK(void, LSM_RET_VOID, cred_getsecid, const struct cred *c, u32 *secid)
191 LSM_HOOK(int, 0, kernel_act_as, struct cred *new, u32 secid)
209 struct task_struct *p, u32 *secid)
211 struct task_struct *p, u32 *secid)
230 u32 *secid)
261 LSM_HOOK(int, -EOPNOTSUPP, secid_to_secctx, u32 secid, char **secdata,
263 LSM_HOOK(int, 0, secctx_to_secid, const char *secdata, u32 seclen, u32 *secid)
307 struct sk_buff *skb, u32 *secid)
312 LSM_HOOK(void, LSM_RET_VOID, sk_getsecid, struct sock *sk, u32 *secid)
[all …]
/Linux-v5.15/include/uapi/linux/netfilter/
Dxt_SECMARK.h19 __u32 secid; member
26 __u32 secid; member
/Linux-v5.15/security/
Dsecurity.c1464 void security_inode_getsecid(struct inode *inode, u32 *secid) in security_inode_getsecid() argument
1466 call_void_hook(inode_getsecid, inode, secid); in security_inode_getsecid()
1707 void security_cred_getsecid(const struct cred *c, u32 *secid) in security_cred_getsecid() argument
1709 *secid = 0; in security_cred_getsecid()
1710 call_void_hook(cred_getsecid, c, secid); in security_cred_getsecid()
1714 int security_kernel_act_as(struct cred *new, u32 secid) in security_kernel_act_as() argument
1716 return call_int_hook(kernel_act_as, 0, new, secid); in security_kernel_act_as()
1810 void security_task_getsecid_subj(struct task_struct *p, u32 *secid) in security_task_getsecid_subj() argument
1812 *secid = 0; in security_task_getsecid_subj()
1813 call_void_hook(task_getsecid_subj, p, secid); in security_task_getsecid_subj()
[all …]
/Linux-v5.15/include/net/
Dscm.h36 u32 secid; /* Passed security ID */ member
49 security_socket_getpeersec_dgram(sock, NULL, &scm->secid); in unix_get_peersec_dgram()
100 err = security_secid_to_secctx(scm->secid, &secdata, &seclen); in scm_passec()
Dnetlabel.h100 u32 secid; member
204 u32 secid; member
418 u32 secid,
526 u32 secid, in netlbl_cfg_unlbl_static_add() argument
/Linux-v5.15/Documentation/networking/
Dsecid.rst4 LSM/SeLinux secid
9 The secid member in the flow structure is used in LSMs (e.g. SELinux) to indicate
/Linux-v5.15/security/selinux/
Dxfrm.c345 struct xfrm_sec_ctx *polsec, u32 secid) in selinux_xfrm_state_alloc_acquire() argument
355 if (secid == 0) in selinux_xfrm_state_alloc_acquire()
358 rc = security_sid_to_context(&selinux_state, secid, &ctx_str, in selinux_xfrm_state_alloc_acquire()
371 ctx->ctx_sid = secid; in selinux_xfrm_state_alloc_acquire()
Dnetlabel.c110 (secattr->attr.secid == sid)) in selinux_netlbl_sock_getattr()
286 ep->secid, &secattr); in selinux_netlbl_sctp_assoc_request()
333 rc = security_netlbl_sid_to_secattr(&selinux_state, req->secid, in selinux_netlbl_inet_conn_request()
/Linux-v5.15/kernel/
Dcred.c781 int set_security_override(struct cred *new, u32 secid) in set_security_override() argument
783 return security_kernel_act_as(new, secid); in set_security_override()
799 u32 secid; in set_security_override_from_ctx() local
802 ret = security_secctx_to_secid(secctx, strlen(secctx), &secid); in set_security_override_from_ctx()
806 return set_security_override(new, secid); in set_security_override_from_ctx()
/Linux-v5.15/security/smack/
Dsmack_lsm.c1474 static void smack_inode_getsecid(struct inode *inode, u32 *secid) in smack_inode_getsecid() argument
1478 *secid = skp->smk_secid; in smack_inode_getsecid()
1963 static void smack_cred_getsecid(const struct cred *cred, u32 *secid) in smack_cred_getsecid() argument
1969 *secid = skp->smk_secid; in smack_cred_getsecid()
1980 static int smack_kernel_act_as(struct cred *new, u32 secid) in smack_kernel_act_as() argument
1984 new_tsp->smk_task = smack_from_secid(secid); in smack_kernel_act_as()
2070 static void smack_task_getsecid_subj(struct task_struct *p, u32 *secid) in smack_task_getsecid_subj() argument
2074 *secid = skp->smk_secid; in smack_task_getsecid_subj()
2084 static void smack_task_getsecid_obj(struct task_struct *p, u32 *secid) in smack_task_getsecid_obj() argument
2088 *secid = skp->smk_secid; in smack_task_getsecid_obj()
[all …]
Dsmack_access.c527 skp->smk_netlabel.attr.secid = skp->smk_secid; in smack_populate_secattr()
613 struct smack_known *smack_from_secid(const u32 secid) in smack_from_secid() argument
619 if (skp->smk_secid == secid) { in smack_from_secid()
/Linux-v5.15/security/selinux/include/
Dxfrm.h23 struct xfrm_sec_ctx *polsec, u32 secid);

12