1*4882a593Smuzhiyun /* SPDX-License-Identifier: GPL-2.0-or-later */
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun * NetLabel Network Address Lists
4*4882a593Smuzhiyun *
5*4882a593Smuzhiyun * This file contains network address list functions used to manage ordered
6*4882a593Smuzhiyun * lists of network addresses for use by the NetLabel subsystem. The NetLabel
7*4882a593Smuzhiyun * system manages static and dynamic label mappings for network protocols such
8*4882a593Smuzhiyun * as CIPSO and RIPSO.
9*4882a593Smuzhiyun *
10*4882a593Smuzhiyun * Author: Paul Moore <paul@paul-moore.com>
11*4882a593Smuzhiyun */
12*4882a593Smuzhiyun
13*4882a593Smuzhiyun /*
14*4882a593Smuzhiyun * (c) Copyright Hewlett-Packard Development Company, L.P., 2008
15*4882a593Smuzhiyun */
16*4882a593Smuzhiyun
17*4882a593Smuzhiyun #ifndef _NETLABEL_ADDRLIST_H
18*4882a593Smuzhiyun #define _NETLABEL_ADDRLIST_H
19*4882a593Smuzhiyun
20*4882a593Smuzhiyun #include <linux/types.h>
21*4882a593Smuzhiyun #include <linux/rcupdate.h>
22*4882a593Smuzhiyun #include <linux/list.h>
23*4882a593Smuzhiyun #include <linux/in6.h>
24*4882a593Smuzhiyun #include <linux/audit.h>
25*4882a593Smuzhiyun
26*4882a593Smuzhiyun /**
27*4882a593Smuzhiyun * struct netlbl_af4list - NetLabel IPv4 address list
28*4882a593Smuzhiyun * @addr: IPv4 address
29*4882a593Smuzhiyun * @mask: IPv4 address mask
30*4882a593Smuzhiyun * @valid: valid flag
31*4882a593Smuzhiyun * @list: list structure, used internally
32*4882a593Smuzhiyun */
33*4882a593Smuzhiyun struct netlbl_af4list {
34*4882a593Smuzhiyun __be32 addr;
35*4882a593Smuzhiyun __be32 mask;
36*4882a593Smuzhiyun
37*4882a593Smuzhiyun u32 valid;
38*4882a593Smuzhiyun struct list_head list;
39*4882a593Smuzhiyun };
40*4882a593Smuzhiyun
41*4882a593Smuzhiyun /**
42*4882a593Smuzhiyun * struct netlbl_af6list - NetLabel IPv6 address list
43*4882a593Smuzhiyun * @addr: IPv6 address
44*4882a593Smuzhiyun * @mask: IPv6 address mask
45*4882a593Smuzhiyun * @valid: valid flag
46*4882a593Smuzhiyun * @list: list structure, used internally
47*4882a593Smuzhiyun */
48*4882a593Smuzhiyun struct netlbl_af6list {
49*4882a593Smuzhiyun struct in6_addr addr;
50*4882a593Smuzhiyun struct in6_addr mask;
51*4882a593Smuzhiyun
52*4882a593Smuzhiyun u32 valid;
53*4882a593Smuzhiyun struct list_head list;
54*4882a593Smuzhiyun };
55*4882a593Smuzhiyun
56*4882a593Smuzhiyun #define __af4list_entry(ptr) container_of(ptr, struct netlbl_af4list, list)
57*4882a593Smuzhiyun
__af4list_valid(struct list_head * s,struct list_head * h)58*4882a593Smuzhiyun static inline struct netlbl_af4list *__af4list_valid(struct list_head *s,
59*4882a593Smuzhiyun struct list_head *h)
60*4882a593Smuzhiyun {
61*4882a593Smuzhiyun struct list_head *i = s;
62*4882a593Smuzhiyun struct netlbl_af4list *n = __af4list_entry(s);
63*4882a593Smuzhiyun while (i != h && !n->valid) {
64*4882a593Smuzhiyun i = i->next;
65*4882a593Smuzhiyun n = __af4list_entry(i);
66*4882a593Smuzhiyun }
67*4882a593Smuzhiyun return n;
68*4882a593Smuzhiyun }
69*4882a593Smuzhiyun
__af4list_valid_rcu(struct list_head * s,struct list_head * h)70*4882a593Smuzhiyun static inline struct netlbl_af4list *__af4list_valid_rcu(struct list_head *s,
71*4882a593Smuzhiyun struct list_head *h)
72*4882a593Smuzhiyun {
73*4882a593Smuzhiyun struct list_head *i = s;
74*4882a593Smuzhiyun struct netlbl_af4list *n = __af4list_entry(s);
75*4882a593Smuzhiyun while (i != h && !n->valid) {
76*4882a593Smuzhiyun i = rcu_dereference(list_next_rcu(i));
77*4882a593Smuzhiyun n = __af4list_entry(i);
78*4882a593Smuzhiyun }
79*4882a593Smuzhiyun return n;
80*4882a593Smuzhiyun }
81*4882a593Smuzhiyun
82*4882a593Smuzhiyun #define netlbl_af4list_foreach(iter, head) \
83*4882a593Smuzhiyun for (iter = __af4list_valid((head)->next, head); \
84*4882a593Smuzhiyun &iter->list != (head); \
85*4882a593Smuzhiyun iter = __af4list_valid(iter->list.next, head))
86*4882a593Smuzhiyun
87*4882a593Smuzhiyun #define netlbl_af4list_foreach_rcu(iter, head) \
88*4882a593Smuzhiyun for (iter = __af4list_valid_rcu((head)->next, head); \
89*4882a593Smuzhiyun &iter->list != (head); \
90*4882a593Smuzhiyun iter = __af4list_valid_rcu(iter->list.next, head))
91*4882a593Smuzhiyun
92*4882a593Smuzhiyun #define netlbl_af4list_foreach_safe(iter, tmp, head) \
93*4882a593Smuzhiyun for (iter = __af4list_valid((head)->next, head), \
94*4882a593Smuzhiyun tmp = __af4list_valid(iter->list.next, head); \
95*4882a593Smuzhiyun &iter->list != (head); \
96*4882a593Smuzhiyun iter = tmp, tmp = __af4list_valid(iter->list.next, head))
97*4882a593Smuzhiyun
98*4882a593Smuzhiyun int netlbl_af4list_add(struct netlbl_af4list *entry,
99*4882a593Smuzhiyun struct list_head *head);
100*4882a593Smuzhiyun struct netlbl_af4list *netlbl_af4list_remove(__be32 addr, __be32 mask,
101*4882a593Smuzhiyun struct list_head *head);
102*4882a593Smuzhiyun void netlbl_af4list_remove_entry(struct netlbl_af4list *entry);
103*4882a593Smuzhiyun struct netlbl_af4list *netlbl_af4list_search(__be32 addr,
104*4882a593Smuzhiyun struct list_head *head);
105*4882a593Smuzhiyun struct netlbl_af4list *netlbl_af4list_search_exact(__be32 addr,
106*4882a593Smuzhiyun __be32 mask,
107*4882a593Smuzhiyun struct list_head *head);
108*4882a593Smuzhiyun
109*4882a593Smuzhiyun #ifdef CONFIG_AUDIT
110*4882a593Smuzhiyun void netlbl_af4list_audit_addr(struct audit_buffer *audit_buf,
111*4882a593Smuzhiyun int src, const char *dev,
112*4882a593Smuzhiyun __be32 addr, __be32 mask);
113*4882a593Smuzhiyun #else
netlbl_af4list_audit_addr(struct audit_buffer * audit_buf,int src,const char * dev,__be32 addr,__be32 mask)114*4882a593Smuzhiyun static inline void netlbl_af4list_audit_addr(struct audit_buffer *audit_buf,
115*4882a593Smuzhiyun int src, const char *dev,
116*4882a593Smuzhiyun __be32 addr, __be32 mask)
117*4882a593Smuzhiyun {
118*4882a593Smuzhiyun }
119*4882a593Smuzhiyun #endif
120*4882a593Smuzhiyun
121*4882a593Smuzhiyun #if IS_ENABLED(CONFIG_IPV6)
122*4882a593Smuzhiyun
123*4882a593Smuzhiyun #define __af6list_entry(ptr) container_of(ptr, struct netlbl_af6list, list)
124*4882a593Smuzhiyun
__af6list_valid(struct list_head * s,struct list_head * h)125*4882a593Smuzhiyun static inline struct netlbl_af6list *__af6list_valid(struct list_head *s,
126*4882a593Smuzhiyun struct list_head *h)
127*4882a593Smuzhiyun {
128*4882a593Smuzhiyun struct list_head *i = s;
129*4882a593Smuzhiyun struct netlbl_af6list *n = __af6list_entry(s);
130*4882a593Smuzhiyun while (i != h && !n->valid) {
131*4882a593Smuzhiyun i = i->next;
132*4882a593Smuzhiyun n = __af6list_entry(i);
133*4882a593Smuzhiyun }
134*4882a593Smuzhiyun return n;
135*4882a593Smuzhiyun }
136*4882a593Smuzhiyun
__af6list_valid_rcu(struct list_head * s,struct list_head * h)137*4882a593Smuzhiyun static inline struct netlbl_af6list *__af6list_valid_rcu(struct list_head *s,
138*4882a593Smuzhiyun struct list_head *h)
139*4882a593Smuzhiyun {
140*4882a593Smuzhiyun struct list_head *i = s;
141*4882a593Smuzhiyun struct netlbl_af6list *n = __af6list_entry(s);
142*4882a593Smuzhiyun while (i != h && !n->valid) {
143*4882a593Smuzhiyun i = rcu_dereference(list_next_rcu(i));
144*4882a593Smuzhiyun n = __af6list_entry(i);
145*4882a593Smuzhiyun }
146*4882a593Smuzhiyun return n;
147*4882a593Smuzhiyun }
148*4882a593Smuzhiyun
149*4882a593Smuzhiyun #define netlbl_af6list_foreach(iter, head) \
150*4882a593Smuzhiyun for (iter = __af6list_valid((head)->next, head); \
151*4882a593Smuzhiyun &iter->list != (head); \
152*4882a593Smuzhiyun iter = __af6list_valid(iter->list.next, head))
153*4882a593Smuzhiyun
154*4882a593Smuzhiyun #define netlbl_af6list_foreach_rcu(iter, head) \
155*4882a593Smuzhiyun for (iter = __af6list_valid_rcu((head)->next, head); \
156*4882a593Smuzhiyun &iter->list != (head); \
157*4882a593Smuzhiyun iter = __af6list_valid_rcu(iter->list.next, head))
158*4882a593Smuzhiyun
159*4882a593Smuzhiyun #define netlbl_af6list_foreach_safe(iter, tmp, head) \
160*4882a593Smuzhiyun for (iter = __af6list_valid((head)->next, head), \
161*4882a593Smuzhiyun tmp = __af6list_valid(iter->list.next, head); \
162*4882a593Smuzhiyun &iter->list != (head); \
163*4882a593Smuzhiyun iter = tmp, tmp = __af6list_valid(iter->list.next, head))
164*4882a593Smuzhiyun
165*4882a593Smuzhiyun int netlbl_af6list_add(struct netlbl_af6list *entry,
166*4882a593Smuzhiyun struct list_head *head);
167*4882a593Smuzhiyun struct netlbl_af6list *netlbl_af6list_remove(const struct in6_addr *addr,
168*4882a593Smuzhiyun const struct in6_addr *mask,
169*4882a593Smuzhiyun struct list_head *head);
170*4882a593Smuzhiyun void netlbl_af6list_remove_entry(struct netlbl_af6list *entry);
171*4882a593Smuzhiyun struct netlbl_af6list *netlbl_af6list_search(const struct in6_addr *addr,
172*4882a593Smuzhiyun struct list_head *head);
173*4882a593Smuzhiyun struct netlbl_af6list *netlbl_af6list_search_exact(const struct in6_addr *addr,
174*4882a593Smuzhiyun const struct in6_addr *mask,
175*4882a593Smuzhiyun struct list_head *head);
176*4882a593Smuzhiyun
177*4882a593Smuzhiyun #ifdef CONFIG_AUDIT
178*4882a593Smuzhiyun void netlbl_af6list_audit_addr(struct audit_buffer *audit_buf,
179*4882a593Smuzhiyun int src,
180*4882a593Smuzhiyun const char *dev,
181*4882a593Smuzhiyun const struct in6_addr *addr,
182*4882a593Smuzhiyun const struct in6_addr *mask);
183*4882a593Smuzhiyun #else
netlbl_af6list_audit_addr(struct audit_buffer * audit_buf,int src,const char * dev,const struct in6_addr * addr,const struct in6_addr * mask)184*4882a593Smuzhiyun static inline void netlbl_af6list_audit_addr(struct audit_buffer *audit_buf,
185*4882a593Smuzhiyun int src,
186*4882a593Smuzhiyun const char *dev,
187*4882a593Smuzhiyun const struct in6_addr *addr,
188*4882a593Smuzhiyun const struct in6_addr *mask)
189*4882a593Smuzhiyun {
190*4882a593Smuzhiyun }
191*4882a593Smuzhiyun #endif
192*4882a593Smuzhiyun #endif /* IPV6 */
193*4882a593Smuzhiyun
194*4882a593Smuzhiyun #endif
195