xref: /OK3568_Linux_fs/kernel/net/netlabel/netlabel_addrlist.h (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun /* SPDX-License-Identifier: GPL-2.0-or-later */
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun  * NetLabel Network Address Lists
4*4882a593Smuzhiyun  *
5*4882a593Smuzhiyun  * This file contains network address list functions used to manage ordered
6*4882a593Smuzhiyun  * lists of network addresses for use by the NetLabel subsystem.  The NetLabel
7*4882a593Smuzhiyun  * system manages static and dynamic label mappings for network protocols such
8*4882a593Smuzhiyun  * as CIPSO and RIPSO.
9*4882a593Smuzhiyun  *
10*4882a593Smuzhiyun  * Author: Paul Moore <paul@paul-moore.com>
11*4882a593Smuzhiyun  */
12*4882a593Smuzhiyun 
13*4882a593Smuzhiyun /*
14*4882a593Smuzhiyun  * (c) Copyright Hewlett-Packard Development Company, L.P., 2008
15*4882a593Smuzhiyun  */
16*4882a593Smuzhiyun 
17*4882a593Smuzhiyun #ifndef _NETLABEL_ADDRLIST_H
18*4882a593Smuzhiyun #define _NETLABEL_ADDRLIST_H
19*4882a593Smuzhiyun 
20*4882a593Smuzhiyun #include <linux/types.h>
21*4882a593Smuzhiyun #include <linux/rcupdate.h>
22*4882a593Smuzhiyun #include <linux/list.h>
23*4882a593Smuzhiyun #include <linux/in6.h>
24*4882a593Smuzhiyun #include <linux/audit.h>
25*4882a593Smuzhiyun 
26*4882a593Smuzhiyun /**
27*4882a593Smuzhiyun  * struct netlbl_af4list - NetLabel IPv4 address list
28*4882a593Smuzhiyun  * @addr: IPv4 address
29*4882a593Smuzhiyun  * @mask: IPv4 address mask
30*4882a593Smuzhiyun  * @valid: valid flag
31*4882a593Smuzhiyun  * @list: list structure, used internally
32*4882a593Smuzhiyun  */
33*4882a593Smuzhiyun struct netlbl_af4list {
34*4882a593Smuzhiyun 	__be32 addr;
35*4882a593Smuzhiyun 	__be32 mask;
36*4882a593Smuzhiyun 
37*4882a593Smuzhiyun 	u32 valid;
38*4882a593Smuzhiyun 	struct list_head list;
39*4882a593Smuzhiyun };
40*4882a593Smuzhiyun 
41*4882a593Smuzhiyun /**
42*4882a593Smuzhiyun  * struct netlbl_af6list - NetLabel IPv6 address list
43*4882a593Smuzhiyun  * @addr: IPv6 address
44*4882a593Smuzhiyun  * @mask: IPv6 address mask
45*4882a593Smuzhiyun  * @valid: valid flag
46*4882a593Smuzhiyun  * @list: list structure, used internally
47*4882a593Smuzhiyun  */
48*4882a593Smuzhiyun struct netlbl_af6list {
49*4882a593Smuzhiyun 	struct in6_addr addr;
50*4882a593Smuzhiyun 	struct in6_addr mask;
51*4882a593Smuzhiyun 
52*4882a593Smuzhiyun 	u32 valid;
53*4882a593Smuzhiyun 	struct list_head list;
54*4882a593Smuzhiyun };
55*4882a593Smuzhiyun 
56*4882a593Smuzhiyun #define __af4list_entry(ptr) container_of(ptr, struct netlbl_af4list, list)
57*4882a593Smuzhiyun 
__af4list_valid(struct list_head * s,struct list_head * h)58*4882a593Smuzhiyun static inline struct netlbl_af4list *__af4list_valid(struct list_head *s,
59*4882a593Smuzhiyun 						     struct list_head *h)
60*4882a593Smuzhiyun {
61*4882a593Smuzhiyun 	struct list_head *i = s;
62*4882a593Smuzhiyun 	struct netlbl_af4list *n = __af4list_entry(s);
63*4882a593Smuzhiyun 	while (i != h && !n->valid) {
64*4882a593Smuzhiyun 		i = i->next;
65*4882a593Smuzhiyun 		n = __af4list_entry(i);
66*4882a593Smuzhiyun 	}
67*4882a593Smuzhiyun 	return n;
68*4882a593Smuzhiyun }
69*4882a593Smuzhiyun 
__af4list_valid_rcu(struct list_head * s,struct list_head * h)70*4882a593Smuzhiyun static inline struct netlbl_af4list *__af4list_valid_rcu(struct list_head *s,
71*4882a593Smuzhiyun 							 struct list_head *h)
72*4882a593Smuzhiyun {
73*4882a593Smuzhiyun 	struct list_head *i = s;
74*4882a593Smuzhiyun 	struct netlbl_af4list *n = __af4list_entry(s);
75*4882a593Smuzhiyun 	while (i != h && !n->valid) {
76*4882a593Smuzhiyun 		i = rcu_dereference(list_next_rcu(i));
77*4882a593Smuzhiyun 		n = __af4list_entry(i);
78*4882a593Smuzhiyun 	}
79*4882a593Smuzhiyun 	return n;
80*4882a593Smuzhiyun }
81*4882a593Smuzhiyun 
82*4882a593Smuzhiyun #define netlbl_af4list_foreach(iter, head)				\
83*4882a593Smuzhiyun 	for (iter = __af4list_valid((head)->next, head);		\
84*4882a593Smuzhiyun 	     &iter->list != (head);					\
85*4882a593Smuzhiyun 	     iter = __af4list_valid(iter->list.next, head))
86*4882a593Smuzhiyun 
87*4882a593Smuzhiyun #define netlbl_af4list_foreach_rcu(iter, head)				\
88*4882a593Smuzhiyun 	for (iter = __af4list_valid_rcu((head)->next, head);		\
89*4882a593Smuzhiyun 	     &iter->list != (head);					\
90*4882a593Smuzhiyun 	     iter = __af4list_valid_rcu(iter->list.next, head))
91*4882a593Smuzhiyun 
92*4882a593Smuzhiyun #define netlbl_af4list_foreach_safe(iter, tmp, head)			\
93*4882a593Smuzhiyun 	for (iter = __af4list_valid((head)->next, head),		\
94*4882a593Smuzhiyun 		     tmp = __af4list_valid(iter->list.next, head);	\
95*4882a593Smuzhiyun 	     &iter->list != (head);					\
96*4882a593Smuzhiyun 	     iter = tmp, tmp = __af4list_valid(iter->list.next, head))
97*4882a593Smuzhiyun 
98*4882a593Smuzhiyun int netlbl_af4list_add(struct netlbl_af4list *entry,
99*4882a593Smuzhiyun 		       struct list_head *head);
100*4882a593Smuzhiyun struct netlbl_af4list *netlbl_af4list_remove(__be32 addr, __be32 mask,
101*4882a593Smuzhiyun 					     struct list_head *head);
102*4882a593Smuzhiyun void netlbl_af4list_remove_entry(struct netlbl_af4list *entry);
103*4882a593Smuzhiyun struct netlbl_af4list *netlbl_af4list_search(__be32 addr,
104*4882a593Smuzhiyun 					     struct list_head *head);
105*4882a593Smuzhiyun struct netlbl_af4list *netlbl_af4list_search_exact(__be32 addr,
106*4882a593Smuzhiyun 						   __be32 mask,
107*4882a593Smuzhiyun 						   struct list_head *head);
108*4882a593Smuzhiyun 
109*4882a593Smuzhiyun #ifdef CONFIG_AUDIT
110*4882a593Smuzhiyun void netlbl_af4list_audit_addr(struct audit_buffer *audit_buf,
111*4882a593Smuzhiyun 			       int src, const char *dev,
112*4882a593Smuzhiyun 			       __be32 addr, __be32 mask);
113*4882a593Smuzhiyun #else
netlbl_af4list_audit_addr(struct audit_buffer * audit_buf,int src,const char * dev,__be32 addr,__be32 mask)114*4882a593Smuzhiyun static inline void netlbl_af4list_audit_addr(struct audit_buffer *audit_buf,
115*4882a593Smuzhiyun 					     int src, const char *dev,
116*4882a593Smuzhiyun 					     __be32 addr, __be32 mask)
117*4882a593Smuzhiyun {
118*4882a593Smuzhiyun }
119*4882a593Smuzhiyun #endif
120*4882a593Smuzhiyun 
121*4882a593Smuzhiyun #if IS_ENABLED(CONFIG_IPV6)
122*4882a593Smuzhiyun 
123*4882a593Smuzhiyun #define __af6list_entry(ptr) container_of(ptr, struct netlbl_af6list, list)
124*4882a593Smuzhiyun 
__af6list_valid(struct list_head * s,struct list_head * h)125*4882a593Smuzhiyun static inline struct netlbl_af6list *__af6list_valid(struct list_head *s,
126*4882a593Smuzhiyun 						     struct list_head *h)
127*4882a593Smuzhiyun {
128*4882a593Smuzhiyun 	struct list_head *i = s;
129*4882a593Smuzhiyun 	struct netlbl_af6list *n = __af6list_entry(s);
130*4882a593Smuzhiyun 	while (i != h && !n->valid) {
131*4882a593Smuzhiyun 		i = i->next;
132*4882a593Smuzhiyun 		n = __af6list_entry(i);
133*4882a593Smuzhiyun 	}
134*4882a593Smuzhiyun 	return n;
135*4882a593Smuzhiyun }
136*4882a593Smuzhiyun 
__af6list_valid_rcu(struct list_head * s,struct list_head * h)137*4882a593Smuzhiyun static inline struct netlbl_af6list *__af6list_valid_rcu(struct list_head *s,
138*4882a593Smuzhiyun 							 struct list_head *h)
139*4882a593Smuzhiyun {
140*4882a593Smuzhiyun 	struct list_head *i = s;
141*4882a593Smuzhiyun 	struct netlbl_af6list *n = __af6list_entry(s);
142*4882a593Smuzhiyun 	while (i != h && !n->valid) {
143*4882a593Smuzhiyun 		i = rcu_dereference(list_next_rcu(i));
144*4882a593Smuzhiyun 		n = __af6list_entry(i);
145*4882a593Smuzhiyun 	}
146*4882a593Smuzhiyun 	return n;
147*4882a593Smuzhiyun }
148*4882a593Smuzhiyun 
149*4882a593Smuzhiyun #define netlbl_af6list_foreach(iter, head)				\
150*4882a593Smuzhiyun 	for (iter = __af6list_valid((head)->next, head);		\
151*4882a593Smuzhiyun 	     &iter->list != (head);					\
152*4882a593Smuzhiyun 	     iter = __af6list_valid(iter->list.next, head))
153*4882a593Smuzhiyun 
154*4882a593Smuzhiyun #define netlbl_af6list_foreach_rcu(iter, head)				\
155*4882a593Smuzhiyun 	for (iter = __af6list_valid_rcu((head)->next, head);		\
156*4882a593Smuzhiyun 	     &iter->list != (head);					\
157*4882a593Smuzhiyun 	     iter = __af6list_valid_rcu(iter->list.next, head))
158*4882a593Smuzhiyun 
159*4882a593Smuzhiyun #define netlbl_af6list_foreach_safe(iter, tmp, head)			\
160*4882a593Smuzhiyun 	for (iter = __af6list_valid((head)->next, head),		\
161*4882a593Smuzhiyun 		     tmp = __af6list_valid(iter->list.next, head);	\
162*4882a593Smuzhiyun 	     &iter->list != (head);					\
163*4882a593Smuzhiyun 	     iter = tmp, tmp = __af6list_valid(iter->list.next, head))
164*4882a593Smuzhiyun 
165*4882a593Smuzhiyun int netlbl_af6list_add(struct netlbl_af6list *entry,
166*4882a593Smuzhiyun 		       struct list_head *head);
167*4882a593Smuzhiyun struct netlbl_af6list *netlbl_af6list_remove(const struct in6_addr *addr,
168*4882a593Smuzhiyun 					     const struct in6_addr *mask,
169*4882a593Smuzhiyun 					     struct list_head *head);
170*4882a593Smuzhiyun void netlbl_af6list_remove_entry(struct netlbl_af6list *entry);
171*4882a593Smuzhiyun struct netlbl_af6list *netlbl_af6list_search(const struct in6_addr *addr,
172*4882a593Smuzhiyun 					     struct list_head *head);
173*4882a593Smuzhiyun struct netlbl_af6list *netlbl_af6list_search_exact(const struct in6_addr *addr,
174*4882a593Smuzhiyun 						   const struct in6_addr *mask,
175*4882a593Smuzhiyun 						   struct list_head *head);
176*4882a593Smuzhiyun 
177*4882a593Smuzhiyun #ifdef CONFIG_AUDIT
178*4882a593Smuzhiyun void netlbl_af6list_audit_addr(struct audit_buffer *audit_buf,
179*4882a593Smuzhiyun 			       int src,
180*4882a593Smuzhiyun 			       const char *dev,
181*4882a593Smuzhiyun 			       const struct in6_addr *addr,
182*4882a593Smuzhiyun 			       const struct in6_addr *mask);
183*4882a593Smuzhiyun #else
netlbl_af6list_audit_addr(struct audit_buffer * audit_buf,int src,const char * dev,const struct in6_addr * addr,const struct in6_addr * mask)184*4882a593Smuzhiyun static inline void netlbl_af6list_audit_addr(struct audit_buffer *audit_buf,
185*4882a593Smuzhiyun 					     int src,
186*4882a593Smuzhiyun 					     const char *dev,
187*4882a593Smuzhiyun 					     const struct in6_addr *addr,
188*4882a593Smuzhiyun 					     const struct in6_addr *mask)
189*4882a593Smuzhiyun {
190*4882a593Smuzhiyun }
191*4882a593Smuzhiyun #endif
192*4882a593Smuzhiyun #endif /* IPV6 */
193*4882a593Smuzhiyun 
194*4882a593Smuzhiyun #endif
195