Blame view

net/netlabel/netlabel_unlabeled.c 7.18 KB
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
  /*
   * NetLabel Unlabeled Support
   *
   * This file defines functions for dealing with unlabeled packets for the
   * NetLabel system.  The NetLabel system manages static and dynamic label
   * mappings for network protocols such as CIPSO and RIPSO.
   *
   * Author: Paul Moore <paul.moore@hp.com>
   *
   */
  
  /*
   * (c) Copyright Hewlett-Packard Development Company, L.P., 2006
   *
   * This program is free software;  you can redistribute it and/or modify
   * it under the terms of the GNU General Public License as published by
   * the Free Software Foundation; either version 2 of the License, or
   * (at your option) any later version.
   *
   * This program is distributed in the hope that it will be useful,
   * but WITHOUT ANY WARRANTY;  without even the implied warranty of
   * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See
   * the GNU General Public License for more details.
   *
   * You should have received a copy of the GNU General Public License
   * along with this program;  if not, write to the Free Software
   * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
   *
   */
  
  #include <linux/types.h>
  #include <linux/rcupdate.h>
  #include <linux/list.h>
  #include <linux/spinlock.h>
  #include <linux/socket.h>
  #include <linux/string.h>
  #include <linux/skbuff.h>
de64688ff   Paul Moore   NetLabel: honor t...
38
  #include <linux/audit.h>
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
39
40
41
42
43
44
45
46
47
48
49
50
  #include <net/sock.h>
  #include <net/netlink.h>
  #include <net/genetlink.h>
  
  #include <net/netlabel.h>
  #include <asm/bug.h>
  
  #include "netlabel_user.h"
  #include "netlabel_domainhash.h"
  #include "netlabel_unlabeled.h"
  
  /* Accept unlabeled packets flag */
cd28786d6   Paul Moore   NetLabel: convert...
51
52
  static DEFINE_SPINLOCK(netlabel_unlabel_acceptflg_lock);
  static u8 netlabel_unlabel_acceptflg = 0;
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
53
54
55
56
57
58
59
  
  /* NetLabel Generic NETLINK CIPSOv4 family */
  static struct genl_family netlbl_unlabel_gnl_family = {
  	.id = GENL_ID_GENERATE,
  	.hdrsize = 0,
  	.name = NETLBL_NLTYPE_UNLABELED_NAME,
  	.version = NETLBL_PROTO_VERSION,
fd3858554   Paul Moore   [NetLabel]: rewor...
60
  	.maxattr = NLBL_UNLABEL_A_MAX,
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
61
  };
fd3858554   Paul Moore   [NetLabel]: rewor...
62
  /* NetLabel Netlink attribute policy */
ef7c79ed6   Patrick McHardy   [NETLINK]: Mark n...
63
  static const struct nla_policy netlbl_unlabel_genl_policy[NLBL_UNLABEL_A_MAX + 1] = {
fd3858554   Paul Moore   [NetLabel]: rewor...
64
65
  	[NLBL_UNLABEL_A_ACPTFLG] = { .type = NLA_U8 },
  };
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
66
67
  
  /*
32f50cdee   Paul Moore   [NetLabel]: add a...
68
69
70
71
72
73
   * Helper Functions
   */
  
  /**
   * netlbl_unlabel_acceptflg_set - Set the unlabeled accept flag
   * @value: desired value
95d4e6be2   Paul Moore   [NetLabel]: audit...
74
   * @audit_info: NetLabel audit information
32f50cdee   Paul Moore   [NetLabel]: add a...
75
76
77
78
79
   *
   * Description:
   * Set the value of the unlabeled accept flag to @value.
   *
   */
95d4e6be2   Paul Moore   [NetLabel]: audit...
80
81
  static void netlbl_unlabel_acceptflg_set(u8 value,
  					 struct netlbl_audit *audit_info)
32f50cdee   Paul Moore   [NetLabel]: add a...
82
  {
95d4e6be2   Paul Moore   [NetLabel]: audit...
83
84
  	struct audit_buffer *audit_buf;
  	u8 old_val;
cd28786d6   Paul Moore   NetLabel: convert...
85
86
87
88
89
90
  	rcu_read_lock();
  	old_val = netlabel_unlabel_acceptflg;
  	spin_lock(&netlabel_unlabel_acceptflg_lock);
  	netlabel_unlabel_acceptflg = value;
  	spin_unlock(&netlabel_unlabel_acceptflg_lock);
  	rcu_read_unlock();
95d4e6be2   Paul Moore   [NetLabel]: audit...
91
92
93
  
  	audit_buf = netlbl_audit_start_common(AUDIT_MAC_UNLBL_ALLOW,
  					      audit_info);
de64688ff   Paul Moore   NetLabel: honor t...
94
95
96
97
98
  	if (audit_buf != NULL) {
  		audit_log_format(audit_buf,
  				 " unlbl_accept=%u old=%u", value, old_val);
  		audit_log_end(audit_buf);
  	}
32f50cdee   Paul Moore   [NetLabel]: add a...
99
100
101
  }
  
  /*
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
   * NetLabel Command Handlers
   */
  
  /**
   * netlbl_unlabel_accept - Handle an ACCEPT message
   * @skb: the NETLINK buffer
   * @info: the Generic NETLINK info block
   *
   * Description:
   * Process a user generated ACCEPT message and set the accept flag accordingly.
   * Returns zero on success, negative values on failure.
   *
   */
  static int netlbl_unlabel_accept(struct sk_buff *skb, struct genl_info *info)
  {
fd3858554   Paul Moore   [NetLabel]: rewor...
117
  	u8 value;
95d4e6be2   Paul Moore   [NetLabel]: audit...
118
  	struct netlbl_audit audit_info;
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
119

fd3858554   Paul Moore   [NetLabel]: rewor...
120
121
  	if (info->attrs[NLBL_UNLABEL_A_ACPTFLG]) {
  		value = nla_get_u8(info->attrs[NLBL_UNLABEL_A_ACPTFLG]);
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
122
  		if (value == 1 || value == 0) {
95d4e6be2   Paul Moore   [NetLabel]: audit...
123
124
  			netlbl_netlink_auditinfo(skb, &audit_info);
  			netlbl_unlabel_acceptflg_set(value, &audit_info);
32f50cdee   Paul Moore   [NetLabel]: add a...
125
  			return 0;
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
126
127
  		}
  	}
32f50cdee   Paul Moore   [NetLabel]: add a...
128
  	return -EINVAL;
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
129
130
131
132
133
134
135
136
137
138
139
140
141
142
  }
  
  /**
   * netlbl_unlabel_list - Handle a LIST message
   * @skb: the NETLINK buffer
   * @info: the Generic NETLINK info block
   *
   * Description:
   * Process a user generated LIST message and respond with the current status.
   * Returns zero on success, negative values on failure.
   *
   */
  static int netlbl_unlabel_list(struct sk_buff *skb, struct genl_info *info)
  {
fd3858554   Paul Moore   [NetLabel]: rewor...
143
  	int ret_val = -EINVAL;
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
144
  	struct sk_buff *ans_skb;
fd3858554   Paul Moore   [NetLabel]: rewor...
145
  	void *data;
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
146

339bf98ff   Thomas Graf   [NETLINK]: Do pre...
147
  	ans_skb = nlmsg_new(NLMSG_DEFAULT_SIZE, GFP_KERNEL);
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
148
149
  	if (ans_skb == NULL)
  		goto list_failure;
17c157c88   Thomas Graf   [GENL]: Add genlm...
150
151
  	data = genlmsg_put_reply(ans_skb, info, &netlbl_unlabel_gnl_family,
  				 0, NLBL_UNLABEL_C_LIST);
fd3858554   Paul Moore   [NetLabel]: rewor...
152
153
  	if (data == NULL) {
  		ret_val = -ENOMEM;
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
154
  		goto list_failure;
fd3858554   Paul Moore   [NetLabel]: rewor...
155
  	}
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
156

cd28786d6   Paul Moore   NetLabel: convert...
157
  	rcu_read_lock();
fd3858554   Paul Moore   [NetLabel]: rewor...
158
159
  	ret_val = nla_put_u8(ans_skb,
  			     NLBL_UNLABEL_A_ACPTFLG,
cd28786d6   Paul Moore   NetLabel: convert...
160
161
  			     netlabel_unlabel_acceptflg);
  	rcu_read_unlock();
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
162
163
  	if (ret_val != 0)
  		goto list_failure;
fd3858554   Paul Moore   [NetLabel]: rewor...
164
  	genlmsg_end(ans_skb, data);
81878d27f   Thomas Graf   [GENL]: Add genlm...
165
  	ret_val = genlmsg_reply(ans_skb, info);
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
166
167
  	if (ret_val != 0)
  		goto list_failure;
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
168
169
170
  	return 0;
  
  list_failure:
b08d5840d   Patrick McHardy   [NET]: Fix kfree(...
171
  	kfree_skb(ans_skb);
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
172
173
174
175
176
177
178
179
180
181
  	return ret_val;
  }
  
  
  /*
   * NetLabel Generic NETLINK Command Definitions
   */
  
  static struct genl_ops netlbl_unlabel_genl_c_accept = {
  	.cmd = NLBL_UNLABEL_C_ACCEPT,
fd3858554   Paul Moore   [NetLabel]: rewor...
182
183
  	.flags = GENL_ADMIN_PERM,
  	.policy = netlbl_unlabel_genl_policy,
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
184
185
186
187
188
189
190
  	.doit = netlbl_unlabel_accept,
  	.dumpit = NULL,
  };
  
  static struct genl_ops netlbl_unlabel_genl_c_list = {
  	.cmd = NLBL_UNLABEL_C_LIST,
  	.flags = 0,
fd3858554   Paul Moore   [NetLabel]: rewor...
191
  	.policy = netlbl_unlabel_genl_policy,
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
  	.doit = netlbl_unlabel_list,
  	.dumpit = NULL,
  };
  
  
  /*
   * NetLabel Generic NETLINK Protocol Functions
   */
  
  /**
   * netlbl_unlabel_genl_init - Register the Unlabeled NetLabel component
   *
   * Description:
   * Register the unlabeled packet NetLabel component with the Generic NETLINK
   * mechanism.  Returns zero on success, negative values on failure.
   *
   */
  int netlbl_unlabel_genl_init(void)
  {
  	int ret_val;
  
  	ret_val = genl_register_family(&netlbl_unlabel_gnl_family);
  	if (ret_val != 0)
  		return ret_val;
  
  	ret_val = genl_register_ops(&netlbl_unlabel_gnl_family,
  				    &netlbl_unlabel_genl_c_accept);
  	if (ret_val != 0)
  		return ret_val;
  
  	ret_val = genl_register_ops(&netlbl_unlabel_gnl_family,
  				    &netlbl_unlabel_genl_c_list);
  	if (ret_val != 0)
  		return ret_val;
  
  	return 0;
  }
  
  /*
   * NetLabel KAPI Hooks
   */
  
  /**
   * netlbl_unlabel_getattr - Get the security attributes for an unlabled packet
   * @secattr: the security attributes
   *
   * Description:
   * Determine the security attributes, if any, for an unlabled packet and return
   * them in @secattr.  Returns zero on success and negative values on failure.
   *
   */
  int netlbl_unlabel_getattr(struct netlbl_lsm_secattr *secattr)
  {
cd28786d6   Paul Moore   NetLabel: convert...
245
246
247
248
249
250
251
252
253
  	int ret_val;
  
  	rcu_read_lock();
  	if (netlabel_unlabel_acceptflg == 1) {
  		netlbl_secattr_init(secattr);
  		ret_val = 0;
  	} else
  		ret_val = -ENOMSG;
  	rcu_read_unlock();
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
254

cd28786d6   Paul Moore   NetLabel: convert...
255
  	return ret_val;
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
256
257
258
259
260
261
262
263
264
265
266
267
268
269
  }
  
  /**
   * netlbl_unlabel_defconf - Set the default config to allow unlabeled packets
   *
   * Description:
   * Set the default NetLabel configuration to allow incoming unlabeled packets
   * and to send unlabeled network traffic by default.
   *
   */
  int netlbl_unlabel_defconf(void)
  {
  	int ret_val;
  	struct netlbl_dom_map *entry;
95d4e6be2   Paul Moore   [NetLabel]: audit...
270
  	struct netlbl_audit audit_info;
32f50cdee   Paul Moore   [NetLabel]: add a...
271

95d4e6be2   Paul Moore   [NetLabel]: audit...
272
273
274
275
276
  	/* Only the kernel is allowed to call this function and the only time
  	 * it is called is at bootup before the audit subsystem is reporting
  	 * messages so don't worry to much about these values. */
  	security_task_getsecid(current, &audit_info.secid);
  	audit_info.loginuid = 0;
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
277
278
279
280
281
  
  	entry = kzalloc(sizeof(*entry), GFP_KERNEL);
  	if (entry == NULL)
  		return -ENOMEM;
  	entry->type = NETLBL_NLTYPE_UNLABELED;
95d4e6be2   Paul Moore   [NetLabel]: audit...
282
  	ret_val = netlbl_domhsh_add_default(entry, &audit_info);
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
283
284
  	if (ret_val != 0)
  		return ret_val;
95d4e6be2   Paul Moore   [NetLabel]: audit...
285
  	netlbl_unlabel_acceptflg_set(1, &audit_info);
96cb8e331   Paul Moore   [NetLabel]: CIPSO...
286
287
288
  
  	return 0;
  }