xref: /OK3568_Linux_fs/kernel/security/selinux/ss/services.h (revision 4882a59341e53eb6f0b4789bf948001014eff981)
1*4882a593Smuzhiyun /* SPDX-License-Identifier: GPL-2.0 */
2*4882a593Smuzhiyun /*
3*4882a593Smuzhiyun  * Implementation of the security services.
4*4882a593Smuzhiyun  *
5*4882a593Smuzhiyun  * Author : Stephen Smalley, <sds@tycho.nsa.gov>
6*4882a593Smuzhiyun  */
7*4882a593Smuzhiyun #ifndef _SS_SERVICES_H_
8*4882a593Smuzhiyun #define _SS_SERVICES_H_
9*4882a593Smuzhiyun 
10*4882a593Smuzhiyun #include "policydb.h"
11*4882a593Smuzhiyun 
12*4882a593Smuzhiyun /* Mapping for a single class */
13*4882a593Smuzhiyun struct selinux_mapping {
14*4882a593Smuzhiyun 	u16 value; /* policy value for class */
15*4882a593Smuzhiyun 	unsigned int num_perms; /* number of permissions in class */
16*4882a593Smuzhiyun 	u32 perms[sizeof(u32) * 8]; /* policy values for permissions */
17*4882a593Smuzhiyun };
18*4882a593Smuzhiyun 
19*4882a593Smuzhiyun /* Map for all of the classes, with array size */
20*4882a593Smuzhiyun struct selinux_map {
21*4882a593Smuzhiyun 	struct selinux_mapping *mapping; /* indexed by class */
22*4882a593Smuzhiyun 	u16 size; /* array size of mapping */
23*4882a593Smuzhiyun };
24*4882a593Smuzhiyun 
25*4882a593Smuzhiyun struct selinux_policy {
26*4882a593Smuzhiyun 	struct sidtab *sidtab;
27*4882a593Smuzhiyun 	struct policydb policydb;
28*4882a593Smuzhiyun 	struct selinux_map map;
29*4882a593Smuzhiyun 	u32 latest_granting;
30*4882a593Smuzhiyun } __randomize_layout;
31*4882a593Smuzhiyun 
32*4882a593Smuzhiyun void services_compute_xperms_drivers(struct extended_perms *xperms,
33*4882a593Smuzhiyun 				struct avtab_node *node);
34*4882a593Smuzhiyun 
35*4882a593Smuzhiyun void services_compute_xperms_decision(struct extended_perms_decision *xpermd,
36*4882a593Smuzhiyun 					struct avtab_node *node);
37*4882a593Smuzhiyun 
38*4882a593Smuzhiyun #endif	/* _SS_SERVICES_H_ */
39