1*4882a593Smuzhiyun /* SPDX-License-Identifier: GPL-2.0 */ 2*4882a593Smuzhiyun /* 3*4882a593Smuzhiyun * Implementation of the security services. 4*4882a593Smuzhiyun * 5*4882a593Smuzhiyun * Author : Stephen Smalley, <sds@tycho.nsa.gov> 6*4882a593Smuzhiyun */ 7*4882a593Smuzhiyun #ifndef _SS_SERVICES_H_ 8*4882a593Smuzhiyun #define _SS_SERVICES_H_ 9*4882a593Smuzhiyun 10*4882a593Smuzhiyun #include "policydb.h" 11*4882a593Smuzhiyun 12*4882a593Smuzhiyun /* Mapping for a single class */ 13*4882a593Smuzhiyun struct selinux_mapping { 14*4882a593Smuzhiyun u16 value; /* policy value for class */ 15*4882a593Smuzhiyun unsigned int num_perms; /* number of permissions in class */ 16*4882a593Smuzhiyun u32 perms[sizeof(u32) * 8]; /* policy values for permissions */ 17*4882a593Smuzhiyun }; 18*4882a593Smuzhiyun 19*4882a593Smuzhiyun /* Map for all of the classes, with array size */ 20*4882a593Smuzhiyun struct selinux_map { 21*4882a593Smuzhiyun struct selinux_mapping *mapping; /* indexed by class */ 22*4882a593Smuzhiyun u16 size; /* array size of mapping */ 23*4882a593Smuzhiyun }; 24*4882a593Smuzhiyun 25*4882a593Smuzhiyun struct selinux_policy { 26*4882a593Smuzhiyun struct sidtab *sidtab; 27*4882a593Smuzhiyun struct policydb policydb; 28*4882a593Smuzhiyun struct selinux_map map; 29*4882a593Smuzhiyun u32 latest_granting; 30*4882a593Smuzhiyun } __randomize_layout; 31*4882a593Smuzhiyun 32*4882a593Smuzhiyun void services_compute_xperms_drivers(struct extended_perms *xperms, 33*4882a593Smuzhiyun struct avtab_node *node); 34*4882a593Smuzhiyun 35*4882a593Smuzhiyun void services_compute_xperms_decision(struct extended_perms_decision *xpermd, 36*4882a593Smuzhiyun struct avtab_node *node); 37*4882a593Smuzhiyun 38*4882a593Smuzhiyun #endif /* _SS_SERVICES_H_ */ 39