1*4882a593Smuzhiyun /* SPDX-License-Identifier: GPL-2.0-only */ 2*4882a593Smuzhiyun /* 3*4882a593Smuzhiyun * AppArmor security module 4*4882a593Smuzhiyun * 5*4882a593Smuzhiyun * This file contains AppArmor file mediation function definitions. 6*4882a593Smuzhiyun * 7*4882a593Smuzhiyun * Copyright 2017 Canonical Ltd. 8*4882a593Smuzhiyun */ 9*4882a593Smuzhiyun 10*4882a593Smuzhiyun #ifndef __AA_MOUNT_H 11*4882a593Smuzhiyun #define __AA_MOUNT_H 12*4882a593Smuzhiyun 13*4882a593Smuzhiyun #include <linux/fs.h> 14*4882a593Smuzhiyun #include <linux/path.h> 15*4882a593Smuzhiyun 16*4882a593Smuzhiyun #include "domain.h" 17*4882a593Smuzhiyun #include "policy.h" 18*4882a593Smuzhiyun 19*4882a593Smuzhiyun /* mount perms */ 20*4882a593Smuzhiyun #define AA_MAY_PIVOTROOT 0x01 21*4882a593Smuzhiyun #define AA_MAY_MOUNT 0x02 22*4882a593Smuzhiyun #define AA_MAY_UMOUNT 0x04 23*4882a593Smuzhiyun #define AA_AUDIT_DATA 0x40 24*4882a593Smuzhiyun #define AA_MNT_CONT_MATCH 0x40 25*4882a593Smuzhiyun 26*4882a593Smuzhiyun #define AA_MS_IGNORE_MASK (MS_KERNMOUNT | MS_NOSEC | MS_ACTIVE | MS_BORN) 27*4882a593Smuzhiyun 28*4882a593Smuzhiyun int aa_remount(struct aa_label *label, const struct path *path, 29*4882a593Smuzhiyun unsigned long flags, void *data); 30*4882a593Smuzhiyun 31*4882a593Smuzhiyun int aa_bind_mount(struct aa_label *label, const struct path *path, 32*4882a593Smuzhiyun const char *old_name, unsigned long flags); 33*4882a593Smuzhiyun 34*4882a593Smuzhiyun 35*4882a593Smuzhiyun int aa_mount_change_type(struct aa_label *label, const struct path *path, 36*4882a593Smuzhiyun unsigned long flags); 37*4882a593Smuzhiyun 38*4882a593Smuzhiyun int aa_move_mount(struct aa_label *label, const struct path *path, 39*4882a593Smuzhiyun const char *old_name); 40*4882a593Smuzhiyun 41*4882a593Smuzhiyun int aa_new_mount(struct aa_label *label, const char *dev_name, 42*4882a593Smuzhiyun const struct path *path, const char *type, unsigned long flags, 43*4882a593Smuzhiyun void *data); 44*4882a593Smuzhiyun 45*4882a593Smuzhiyun int aa_umount(struct aa_label *label, struct vfsmount *mnt, int flags); 46*4882a593Smuzhiyun 47*4882a593Smuzhiyun int aa_pivotroot(struct aa_label *label, const struct path *old_path, 48*4882a593Smuzhiyun const struct path *new_path); 49*4882a593Smuzhiyun 50*4882a593Smuzhiyun #endif /* __AA_MOUNT_H */ 51