policy_ns.h 4.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151
  1. /* SPDX-License-Identifier: GPL-2.0-only */
  2. /*
  3. * AppArmor security module
  4. *
  5. * This file contains AppArmor policy definitions.
  6. *
  7. * Copyright (C) 1998-2008 Novell/SUSE
  8. * Copyright 2009-2017 Canonical Ltd.
  9. */
  10. #ifndef __AA_NAMESPACE_H
  11. #define __AA_NAMESPACE_H
  12. #include <linux/kref.h>
  13. #include "apparmor.h"
  14. #include "apparmorfs.h"
  15. #include "label.h"
  16. #include "policy.h"
  17. /* struct aa_ns_acct - accounting of profiles in namespace
  18. * @max_size: maximum space allowed for all profiles in namespace
  19. * @max_count: maximum number of profiles that can be in this namespace
  20. * @size: current size of profiles
  21. * @count: current count of profiles (includes null profiles)
  22. */
  23. struct aa_ns_acct {
  24. int max_size;
  25. int max_count;
  26. int size;
  27. int count;
  28. };
  29. /* struct aa_ns - namespace for a set of profiles
  30. * @base: common policy
  31. * @parent: parent of namespace
  32. * @lock: lock for modifying the object
  33. * @acct: accounting for the namespace
  34. * @unconfined: special unconfined profile for the namespace
  35. * @sub_ns: list of namespaces under the current namespace.
  36. * @uniq_null: uniq value used for null learning profiles
  37. * @uniq_id: a unique id count for the profiles in the namespace
  38. * @level: level of ns within the tree hierarchy
  39. * @dents: dentries for the namespaces file entries in apparmorfs
  40. *
  41. * An aa_ns defines the set profiles that are searched to determine which
  42. * profile to attach to a task. Profiles can not be shared between aa_ns
  43. * and profile names within a namespace are guaranteed to be unique. When
  44. * profiles in separate namespaces have the same name they are NOT considered
  45. * to be equivalent.
  46. *
  47. * Namespaces are hierarchical and only namespaces and profiles below the
  48. * current namespace are visible.
  49. *
  50. * Namespace names must be unique and can not contain the characters :/\0
  51. */
  52. struct aa_ns {
  53. struct aa_policy base;
  54. struct aa_ns *parent;
  55. struct mutex lock;
  56. struct aa_ns_acct acct;
  57. struct aa_profile *unconfined;
  58. struct list_head sub_ns;
  59. atomic_t uniq_null;
  60. long uniq_id;
  61. int level;
  62. long revision;
  63. wait_queue_head_t wait;
  64. struct aa_labelset labels;
  65. struct list_head rawdata_list;
  66. struct dentry *dents[AAFS_NS_SIZEOF];
  67. };
  68. extern struct aa_label *kernel_t;
  69. extern struct aa_ns *root_ns;
  70. extern const char *aa_hidden_ns_name;
  71. #define ns_unconfined(NS) (&(NS)->unconfined->label)
  72. bool aa_ns_visible(struct aa_ns *curr, struct aa_ns *view, bool subns);
  73. const char *aa_ns_name(struct aa_ns *parent, struct aa_ns *child, bool subns);
  74. void aa_free_ns(struct aa_ns *ns);
  75. int aa_alloc_root_ns(void);
  76. void aa_free_root_ns(void);
  77. struct aa_ns *__aa_lookupn_ns(struct aa_ns *view, const char *hname, size_t n);
  78. struct aa_ns *aa_lookupn_ns(struct aa_ns *view, const char *name, size_t n);
  79. struct aa_ns *__aa_find_or_create_ns(struct aa_ns *parent, const char *name,
  80. struct dentry *dir);
  81. struct aa_ns *aa_prepare_ns(struct aa_ns *root, const char *name);
  82. void __aa_remove_ns(struct aa_ns *ns);
  83. static inline struct aa_profile *aa_deref_parent(struct aa_profile *p)
  84. {
  85. return rcu_dereference_protected(p->parent,
  86. mutex_is_locked(&p->ns->lock));
  87. }
  88. /**
  89. * aa_get_ns - increment references count on @ns
  90. * @ns: namespace to increment reference count of (MAYBE NULL)
  91. *
  92. * Returns: pointer to @ns, if @ns is NULL returns NULL
  93. * Requires: @ns must be held with valid refcount when called
  94. */
  95. static inline struct aa_ns *aa_get_ns(struct aa_ns *ns)
  96. {
  97. if (ns)
  98. aa_get_profile(ns->unconfined);
  99. return ns;
  100. }
  101. /**
  102. * aa_put_ns - decrement refcount on @ns
  103. * @ns: namespace to put reference of
  104. *
  105. * Decrement reference count of @ns and if no longer in use free it
  106. */
  107. static inline void aa_put_ns(struct aa_ns *ns)
  108. {
  109. if (ns)
  110. aa_put_profile(ns->unconfined);
  111. }
  112. /**
  113. * __aa_findn_ns - find a namespace on a list by @name
  114. * @head: list to search for namespace on (NOT NULL)
  115. * @name: name of namespace to look for (NOT NULL)
  116. * @n: length of @name
  117. * Returns: unrefcounted namespace
  118. *
  119. * Requires: rcu_read_lock be held
  120. */
  121. static inline struct aa_ns *__aa_findn_ns(struct list_head *head,
  122. const char *name, size_t n)
  123. {
  124. return (struct aa_ns *)__policy_strn_find(head, name, n);
  125. }
  126. static inline struct aa_ns *__aa_find_ns(struct list_head *head,
  127. const char *name)
  128. {
  129. return __aa_findn_ns(head, name, strlen(name));
  130. }
  131. #endif /* AA_NAMESPACE_H */