Blame view

net/netlabel/netlabel_cipso_v4.h 4.79 KB
d15c345fe   Paul Moore   [NetLabel]: core ...
1
2
3
4
5
6
7
  /*
   * NetLabel CIPSO/IPv4 Support
   *
   * This file defines the CIPSO/IPv4 functions for the NetLabel system.  The
   * NetLabel system manages static and dynamic label mappings for network
   * protocols such as CIPSO and RIPSO.
   *
82c21bfab   Paul Moore   doc: Update the e...
8
   * Author: Paul Moore <paul@paul-moore.com>
d15c345fe   Paul Moore   [NetLabel]: core ...
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
   *
   */
  
  /*
   * (c) Copyright Hewlett-Packard Development Company, L.P., 2006
   *
   * This program is free software;  you can redistribute it and/or modify
   * it under the terms of the GNU General Public License as published by
   * the Free Software Foundation; either version 2 of the License, or
   * (at your option) any later version.
   *
   * This program is distributed in the hope that it will be useful,
   * but WITHOUT ANY WARRANTY;  without even the implied warranty of
   * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See
   * the GNU General Public License for more details.
   *
   * You should have received a copy of the GNU General Public License
   * along with this program;  if not, write to the Free Software
   * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
   *
   */
  
  #ifndef _NETLABEL_CIPSO_V4
  #define _NETLABEL_CIPSO_V4
  
  #include <net/netlabel.h>
  
  /*
fd3858554   Paul Moore   [NetLabel]: rewor...
37
   * The following NetLabel payloads are supported by the CIPSO subsystem.
d15c345fe   Paul Moore   [NetLabel]: core ...
38
   *
fd3858554   Paul Moore   [NetLabel]: rewor...
39
40
   * o ADD:
   *   Sent by an application to add a new DOI mapping table.
d15c345fe   Paul Moore   [NetLabel]: core ...
41
   *
fd3858554   Paul Moore   [NetLabel]: rewor...
42
   *   Required attributes:
d15c345fe   Paul Moore   [NetLabel]: core ...
43
   *
fd3858554   Paul Moore   [NetLabel]: rewor...
44
45
46
   *     NLBL_CIPSOV4_A_DOI
   *     NLBL_CIPSOV4_A_MTYPE
   *     NLBL_CIPSOV4_A_TAGLST
d15c345fe   Paul Moore   [NetLabel]: core ...
47
   *
15c45f7b2   Paul Moore   cipso: Add suppor...
48
   *   If using CIPSO_V4_MAP_TRANS the following attributes are required:
fd3858554   Paul Moore   [NetLabel]: rewor...
49
50
51
52
   *
   *     NLBL_CIPSOV4_A_MLSLVLLST
   *     NLBL_CIPSOV4_A_MLSCATLST
   *
d91d40799   Paul Moore   netlabel: Add con...
53
54
   *   If using CIPSO_V4_MAP_PASS or CIPSO_V4_MAP_LOCAL no additional attributes
   *   are required.
d15c345fe   Paul Moore   [NetLabel]: core ...
55
56
57
   *
   * o REMOVE:
   *   Sent by an application to remove a specific DOI mapping table from the
fd3858554   Paul Moore   [NetLabel]: rewor...
58
   *   CIPSO V4 system.
d15c345fe   Paul Moore   [NetLabel]: core ...
59
   *
fd3858554   Paul Moore   [NetLabel]: rewor...
60
   *   Required attributes:
d15c345fe   Paul Moore   [NetLabel]: core ...
61
   *
fd3858554   Paul Moore   [NetLabel]: rewor...
62
   *     NLBL_CIPSOV4_A_DOI
d15c345fe   Paul Moore   [NetLabel]: core ...
63
64
   *
   * o LIST:
fd3858554   Paul Moore   [NetLabel]: rewor...
65
66
   *   Sent by an application to list the details of a DOI definition.  On
   *   success the kernel should send a response using the following format.
d15c345fe   Paul Moore   [NetLabel]: core ...
67
   *
fd3858554   Paul Moore   [NetLabel]: rewor...
68
   *   Required attributes:
d15c345fe   Paul Moore   [NetLabel]: core ...
69
   *
fd3858554   Paul Moore   [NetLabel]: rewor...
70
   *     NLBL_CIPSOV4_A_DOI
d15c345fe   Paul Moore   [NetLabel]: core ...
71
72
   *
   *   The valid response message format depends on the type of the DOI mapping,
fd3858554   Paul Moore   [NetLabel]: rewor...
73
   *   the defined formats are shown below.
d15c345fe   Paul Moore   [NetLabel]: core ...
74
   *
fd3858554   Paul Moore   [NetLabel]: rewor...
75
   *   Required attributes:
d15c345fe   Paul Moore   [NetLabel]: core ...
76
   *
fd3858554   Paul Moore   [NetLabel]: rewor...
77
78
   *     NLBL_CIPSOV4_A_MTYPE
   *     NLBL_CIPSOV4_A_TAGLST
d15c345fe   Paul Moore   [NetLabel]: core ...
79
   *
15c45f7b2   Paul Moore   cipso: Add suppor...
80
   *   If using CIPSO_V4_MAP_TRANS the following attributes are required:
d15c345fe   Paul Moore   [NetLabel]: core ...
81
   *
fd3858554   Paul Moore   [NetLabel]: rewor...
82
83
   *     NLBL_CIPSOV4_A_MLSLVLLST
   *     NLBL_CIPSOV4_A_MLSCATLST
d15c345fe   Paul Moore   [NetLabel]: core ...
84
   *
d91d40799   Paul Moore   netlabel: Add con...
85
86
   *   If using CIPSO_V4_MAP_PASS or CIPSO_V4_MAP_LOCAL no additional attributes
   *   are required.
d15c345fe   Paul Moore   [NetLabel]: core ...
87
88
89
   *
   * o LISTALL:
   *   This message is sent by an application to list the valid DOIs on the
fd3858554   Paul Moore   [NetLabel]: rewor...
90
91
92
   *   system.  When sent by an application there is no payload and the
   *   NLM_F_DUMP flag should be set.  The kernel should respond with a series of
   *   the following messages.
d15c345fe   Paul Moore   [NetLabel]: core ...
93
   *
fd3858554   Paul Moore   [NetLabel]: rewor...
94
   *   Required attributes:
d15c345fe   Paul Moore   [NetLabel]: core ...
95
   *
fd3858554   Paul Moore   [NetLabel]: rewor...
96
97
   *    NLBL_CIPSOV4_A_DOI
   *    NLBL_CIPSOV4_A_MTYPE
d15c345fe   Paul Moore   [NetLabel]: core ...
98
99
100
101
102
103
   *
   */
  
  /* NetLabel CIPSOv4 commands */
  enum {
  	NLBL_CIPSOV4_C_UNSPEC,
d15c345fe   Paul Moore   [NetLabel]: core ...
104
105
106
107
108
109
  	NLBL_CIPSOV4_C_ADD,
  	NLBL_CIPSOV4_C_REMOVE,
  	NLBL_CIPSOV4_C_LIST,
  	NLBL_CIPSOV4_C_LISTALL,
  	__NLBL_CIPSOV4_C_MAX,
  };
d15c345fe   Paul Moore   [NetLabel]: core ...
110

fd3858554   Paul Moore   [NetLabel]: rewor...
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
  /* NetLabel CIPSOv4 attributes */
  enum {
  	NLBL_CIPSOV4_A_UNSPEC,
  	NLBL_CIPSOV4_A_DOI,
  	/* (NLA_U32)
  	 * the DOI value */
  	NLBL_CIPSOV4_A_MTYPE,
  	/* (NLA_U32)
  	 * the mapping table type (defined in the cipso_ipv4.h header as
  	 * CIPSO_V4_MAP_*) */
  	NLBL_CIPSOV4_A_TAG,
  	/* (NLA_U8)
  	 * a CIPSO tag type, meant to be used within a NLBL_CIPSOV4_A_TAGLST
  	 * attribute */
  	NLBL_CIPSOV4_A_TAGLST,
  	/* (NLA_NESTED)
  	 * the CIPSO tag list for the DOI, there must be at least one
  	 * NLBL_CIPSOV4_A_TAG attribute, tags listed first are given higher
  	 * priorirty when sending packets */
  	NLBL_CIPSOV4_A_MLSLVLLOC,
  	/* (NLA_U32)
  	 * the local MLS sensitivity level */
  	NLBL_CIPSOV4_A_MLSLVLREM,
  	/* (NLA_U32)
  	 * the remote MLS sensitivity level */
  	NLBL_CIPSOV4_A_MLSLVL,
  	/* (NLA_NESTED)
  	 * a MLS sensitivity level mapping, must contain only one attribute of
  	 * each of the following types: NLBL_CIPSOV4_A_MLSLVLLOC and
  	 * NLBL_CIPSOV4_A_MLSLVLREM */
  	NLBL_CIPSOV4_A_MLSLVLLST,
  	/* (NLA_NESTED)
  	 * the CIPSO level mappings, there must be at least one
  	 * NLBL_CIPSOV4_A_MLSLVL attribute */
  	NLBL_CIPSOV4_A_MLSCATLOC,
  	/* (NLA_U32)
  	 * the local MLS category */
  	NLBL_CIPSOV4_A_MLSCATREM,
  	/* (NLA_U32)
  	 * the remote MLS category */
  	NLBL_CIPSOV4_A_MLSCAT,
  	/* (NLA_NESTED)
  	 * a MLS category mapping, must contain only one attribute of each of
  	 * the following types: NLBL_CIPSOV4_A_MLSCATLOC and
  	 * NLBL_CIPSOV4_A_MLSCATREM */
  	NLBL_CIPSOV4_A_MLSCATLST,
  	/* (NLA_NESTED)
  	 * the CIPSO category mappings, there must be at least one
  	 * NLBL_CIPSOV4_A_MLSCAT attribute */
  	__NLBL_CIPSOV4_A_MAX,
  };
  #define NLBL_CIPSOV4_A_MAX (__NLBL_CIPSOV4_A_MAX - 1)
d15c345fe   Paul Moore   [NetLabel]: core ...
163
164
  /* NetLabel protocol functions */
  int netlbl_cipsov4_genl_init(void);
eda61d32e   Paul Moore   NetLabel: introdu...
165
166
  /* Free the memory associated with a CIPSOv4 DOI definition */
  void netlbl_cipsov4_doi_free(struct rcu_head *entry);
d15c345fe   Paul Moore   [NetLabel]: core ...
167
  #endif