Lines Matching +full:srp +full:- +full:capable

1 // SPDX-License-Identifier: GPL-2.0-only
3 * Copyright (C) 2007 Casey Schaufler <casey@schaufler-ca.com>
6 * Casey Schaufler <casey@schaufler-ca.com>
38 SMK_CIPSO = 4, /* load label -> CIPSO mapping */
43 SMK_ONLYCAP = 9, /* the only "capable" label */
51 SMK_CIPSO2 = 17, /* load long label -> CIPSO mapping */
52 SMK_REVOKE_SUBJ = 18, /* set rules with subject label to '-' */
99 * debugging and application bring-up purposes only.
162 #define SMK_OACCESSLEN (sizeof(SMK_OACCESS) - 1)
163 #define SMK_ACCESSLEN (sizeof(SMK_ACCESS) - 1)
176 catsetp[(cat - 1) / 8] |= 0x80 >> ((cat - 1) % 8); in smack_catset_bit()
180 * smk_netlabel_audit_set - fill a netlbl_audit struct
185 nap->loginuid = audit_get_loginuid(current); in smk_netlabel_audit_set()
186 nap->sessionid = audit_get_sessionid(current); in smk_netlabel_audit_set()
187 nap->prop.smack.skp = smk_of_current(); in smk_netlabel_audit_set()
197 * smk_set_access - add a rule to the rule list or replace an old rule
198 * @srp: the rule to add or replace
207 * Returns 0 if nothing goes wrong or -ENOMEM if it fails
210 static int smk_set_access(struct smack_parsed_rule *srp, in smk_set_access() argument
225 if (sp->smk_object == srp->smk_object && in smk_set_access()
226 sp->smk_subject == srp->smk_subject) { in smk_set_access()
228 sp->smk_access |= srp->smk_access1; in smk_set_access()
229 sp->smk_access &= ~srp->smk_access2; in smk_set_access()
237 rc = -ENOMEM; in smk_set_access()
241 sp->smk_subject = srp->smk_subject; in smk_set_access()
242 sp->smk_object = srp->smk_object; in smk_set_access()
243 sp->smk_access = srp->smk_access1 & ~srp->smk_access2; in smk_set_access()
245 list_add_rcu(&sp->list, rule_list); in smk_set_access()
254 * smk_perm_from_str - parse smack accesses from a text string
266 case '-': in smk_perm_from_str()
302 * smk_fill_rule - Fill Smack rule from strings
308 * @import: if non-zero, import labels
322 rule->smk_subject = smk_import_entry(subject, len); in smk_fill_rule()
323 if (IS_ERR(rule->smk_subject)) in smk_fill_rule()
324 return PTR_ERR(rule->smk_subject); in smk_fill_rule()
326 rule->smk_object = smk_import_entry(object, len); in smk_fill_rule()
327 if (IS_ERR(rule->smk_object)) in smk_fill_rule()
328 return PTR_ERR(rule->smk_object); in smk_fill_rule()
336 return -ENOENT; in smk_fill_rule()
337 rule->smk_subject = skp; in smk_fill_rule()
345 return -ENOENT; in smk_fill_rule()
346 rule->smk_object = skp; in smk_fill_rule()
349 rule->smk_access1 = smk_perm_from_str(access1); in smk_fill_rule()
351 rule->smk_access2 = smk_perm_from_str(access2); in smk_fill_rule()
353 rule->smk_access2 = ~rule->smk_access1; in smk_fill_rule()
359 * smk_parse_rule - parse Smack rule from load string
362 * @import: if non-zero, import labels
364 * Returns 0 on success, -1 on errors.
378 * smk_parse_long_rule - parse Smack rule from rule string
381 * @import: if non-zero, import labels
384 * Returns number of processed bytes on success, -ERRNO on failure.
395 * Parsing the rule in-place, filling all white-spaces with '\0' in smk_parse_long_rule()
403 return -EINVAL; in smk_parse_long_rule()
424 * smk_write_rules_list - write() for any /smack rule file
428 * @ppos: where to start - must be 0
431 * @format: /smack/load or /smack/load2 or /smack/change-rule format.
459 return -EINVAL; in smk_write_rules_list()
466 return -EINVAL; in smk_write_rules_list()
469 count = PAGE_SIZE - 1; in smk_write_rules_list()
483 while (count > 0 && (data[count - 1] != '\n')) in smk_write_rules_list()
484 --count; in smk_write_rules_list()
486 rc = -EINVAL; in smk_write_rules_list()
504 rc = -EINVAL; in smk_write_rules_list()
511 rc = smk_set_access(&rule, &rule.smk_subject->smk_rules, in smk_write_rules_list()
512 &rule.smk_subject->smk_rules_lock); in smk_write_rules_list()
540 if (i-- == 0) in smk_seq_start()
563 static void smk_rule_show(struct seq_file *s, struct smack_rule *srp, int max) in smk_rule_show() argument
571 if (strlen(srp->smk_subject->smk_known) >= max || in smk_rule_show()
572 strlen(srp->smk_object->smk_known) >= max) in smk_rule_show()
575 if (srp->smk_access == 0) in smk_rule_show()
579 srp->smk_subject->smk_known, in smk_rule_show()
580 srp->smk_object->smk_known); in smk_rule_show()
584 if (srp->smk_access & MAY_READ) in smk_rule_show()
586 if (srp->smk_access & MAY_WRITE) in smk_rule_show()
588 if (srp->smk_access & MAY_EXEC) in smk_rule_show()
590 if (srp->smk_access & MAY_APPEND) in smk_rule_show()
592 if (srp->smk_access & MAY_TRANSMUTE) in smk_rule_show()
594 if (srp->smk_access & MAY_LOCK) in smk_rule_show()
596 if (srp->smk_access & MAY_BRINGUP) in smk_rule_show()
619 struct smack_rule *srp; in load_seq_show() local
623 list_for_each_entry_rcu(srp, &skp->smk_rules, list) in load_seq_show()
624 smk_rule_show(s, srp, SMK_LABELLEN); in load_seq_show()
637 * smk_open_load - open() for /smack/load
649 * smk_write_load - write() for /smack/load
653 * @ppos: where to start - must be 0
665 return -EPERM; in smk_write_load()
680 * smk_cipso_doi - initialize the CIPSO domain
696 doip->map.std = NULL; in smk_cipso_doi()
697 doip->doi = smk_cipso_doi_value; in smk_cipso_doi()
698 doip->type = CIPSO_V4_MAP_PASS; in smk_cipso_doi()
699 doip->tags[0] = CIPSO_V4_TAG_RBITMAP; in smk_cipso_doi()
701 doip->tags[rc] = CIPSO_V4_TAG_INVALID; in smk_cipso_doi()
710 rc = netlbl_cfg_cipsov4_map_add(doip->doi, NULL, NULL, NULL, &nai); in smk_cipso_doi()
714 netlbl_cfg_cipsov4_del(doip->doi, &nai); in smk_cipso_doi()
720 * smk_unlbl_ambient - initialize the unlabeled domain
739 rc = netlbl_cfg_unlbl_map_add(smack_net_ambient->smk_known, PF_INET, in smk_unlbl_ambient()
769 struct netlbl_lsm_catmap *cmp = skp->smk_netlabel.attr.mls.cat; in cipso_seq_show()
781 if (strlen(skp->smk_known) >= SMK_LABELLEN) in cipso_seq_show()
784 seq_printf(s, "%s %3d", skp->smk_known, skp->smk_netlabel.attr.mls.lvl); in cipso_seq_show()
805 * smk_open_cipso - open() for /smack/cipso
818 * smk_set_cipso - do the work for write() for cipso and cipso2
838 ssize_t rc = -EINVAL; in smk_set_cipso()
850 return -EPERM; in smk_set_cipso()
852 return -EINVAL; in smk_set_cipso()
855 return -EINVAL; in smk_set_cipso()
857 return -EINVAL; in smk_set_cipso()
879 rule += strlen(skp->smk_known) + 1; in smk_set_cipso()
882 rc = -EOVERFLOW; in smk_set_cipso()
892 rc = -EOVERFLOW; in smk_set_cipso()
909 rc = -EOVERFLOW; in smk_set_cipso()
924 new_cat->next = ncats.attr.mls.cat; in smk_set_cipso()
926 skp->smk_netlabel.flags &= ~(1U << 3); in smk_set_cipso()
932 old_cat = skp->smk_netlabel.attr.mls.cat; in smk_set_cipso()
933 rcu_assign_pointer(skp->smk_netlabel.attr.mls.cat, ncats.attr.mls.cat); in smk_set_cipso()
934 skp->smk_netlabel.attr.mls.lvl = ncats.attr.mls.lvl; in smk_set_cipso()
951 * smk_write_cipso - write() for /smack/cipso
987 struct netlbl_lsm_catmap *cmp = skp->smk_netlabel.attr.mls.cat; in cipso2_seq_show()
991 seq_printf(s, "%s %3d", skp->smk_known, skp->smk_netlabel.attr.mls.lvl); in cipso2_seq_show()
1012 * smk_open_cipso2 - open() for /smack/cipso2
1025 * smk_write_cipso2 - write() for /smack/cipso2
1072 if (skp->smk_label != NULL) in net4addr_seq_show()
1073 kp = skp->smk_label->smk_known; in net4addr_seq_show()
1074 seq_printf(s, "%pI4/%d %s\n", &skp->smk_host.s_addr, in net4addr_seq_show()
1075 skp->smk_masks, kp); in net4addr_seq_show()
1088 * smk_open_net4addr - open() for /smack/netlabel
1115 list_add_rcu(&new->list, &smk_net4addr_list); in smk_net4addr_insert()
1123 if (new->smk_masks > m->smk_masks) { in smk_net4addr_insert()
1124 list_add_rcu(&new->list, &smk_net4addr_list); in smk_net4addr_insert()
1129 if (list_is_last(&m->list, &smk_net4addr_list)) { in smk_net4addr_insert()
1130 list_add_rcu(&new->list, &m->list); in smk_net4addr_insert()
1133 m_next = list_entry_rcu(m->list.next, in smk_net4addr_insert()
1135 if (new->smk_masks > m_next->smk_masks) { in smk_net4addr_insert()
1136 list_add_rcu(&new->list, &m->list); in smk_net4addr_insert()
1144 * smk_write_net4addr - write() for /smack/netlabel
1180 return -EPERM; in smk_write_net4addr()
1182 return -EINVAL; in smk_write_net4addr()
1183 if (count < SMK_NETLBLADDRMIN || count > PAGE_SIZE - 1) in smk_write_net4addr()
1184 return -EINVAL; in smk_write_net4addr()
1192 rc = -ENOMEM; in smk_write_net4addr()
1202 rc = -EINVAL; in smk_write_net4addr()
1208 rc = -EINVAL; in smk_write_net4addr()
1213 * If smack begins with '-', it is an option, don't import it in smk_write_net4addr()
1215 if (smack[0] != '-') { in smk_write_net4addr()
1223 * Only the -CIPSO option is supported for IPv4 in smk_write_net4addr()
1226 rc = -EINVAL; in smk_write_net4addr()
1231 for (m = masks, temp_mask = 0; m > 0; m--) { in smk_write_net4addr()
1248 if (snp->smk_host.s_addr == nsa && snp->smk_masks == masks) { in smk_write_net4addr()
1258 rc = -ENOMEM; in smk_write_net4addr()
1261 snp->smk_host.s_addr = newname.sin_addr.s_addr; in smk_write_net4addr()
1262 snp->smk_mask.s_addr = mask.s_addr; in smk_write_net4addr()
1263 snp->smk_label = skp; in smk_write_net4addr()
1264 snp->smk_masks = masks; in smk_write_net4addr()
1272 if (snp->smk_label != NULL) in smk_write_net4addr()
1274 &snp->smk_host, &snp->smk_mask, in smk_write_net4addr()
1278 snp->smk_label = skp; in smk_write_net4addr()
1288 &snp->smk_host, &snp->smk_mask, PF_INET, in smk_write_net4addr()
1289 snp->smk_label->smk_secid, &audit_info); in smk_write_net4addr()
1336 if (skp->smk_label != NULL) in net6addr_seq_show()
1337 seq_printf(s, "%pI6/%d %s\n", &skp->smk_host, skp->smk_masks, in net6addr_seq_show()
1338 skp->smk_label->smk_known); in net6addr_seq_show()
1351 * smk_open_net6addr - open() for /smack/netlabel
1378 list_add_rcu(&new->list, &smk_net6addr_list); in smk_net6addr_insert()
1385 if (new->smk_masks > m->smk_masks) { in smk_net6addr_insert()
1386 list_add_rcu(&new->list, &smk_net6addr_list); in smk_net6addr_insert()
1391 if (list_is_last(&m->list, &smk_net6addr_list)) { in smk_net6addr_insert()
1392 list_add_rcu(&new->list, &m->list); in smk_net6addr_insert()
1395 m_next = list_entry_rcu(m->list.next, in smk_net6addr_insert()
1397 if (new->smk_masks > m_next->smk_masks) { in smk_net6addr_insert()
1398 list_add_rcu(&new->list, &m->list); in smk_net6addr_insert()
1406 * smk_write_net6addr - write() for /smack/netlabel
1439 return -EPERM; in smk_write_net6addr()
1441 return -EINVAL; in smk_write_net6addr()
1442 if (count < SMK_NETLBLADDRMIN || count > PAGE_SIZE - 1) in smk_write_net6addr()
1443 return -EINVAL; in smk_write_net6addr()
1451 rc = -ENOMEM; in smk_write_net6addr()
1465 rc = -EINVAL; in smk_write_net6addr()
1470 rc = -EINVAL; in smk_write_net6addr()
1475 rc = -EINVAL; in smk_write_net6addr()
1482 * If smack begins with '-', it is an option, don't import it in smk_write_net6addr()
1484 if (smack[0] != '-') { in smk_write_net6addr()
1492 * Only -DELETE is supported for IPv6 in smk_write_net6addr()
1495 rc = -EINVAL; in smk_write_net6addr()
1503 m -= 16; in smk_write_net6addr()
1505 fullmask.s6_addr16[i] = (1 << m) - 1; in smk_write_net6addr()
1521 if (mask != snp->smk_masks) in smk_write_net6addr()
1525 snp->smk_host.s6_addr16[i]) { in smk_write_net6addr()
1536 rc = -ENOMEM; in smk_write_net6addr()
1538 snp->smk_host = newname; in smk_write_net6addr()
1539 snp->smk_mask = fullmask; in smk_write_net6addr()
1540 snp->smk_masks = mask; in smk_write_net6addr()
1541 snp->smk_label = skp; in smk_write_net6addr()
1545 snp->smk_label = skp; in smk_write_net6addr()
1571 * smk_read_doi - read() for /smack/doi
1595 * smk_write_doi - write() for /smack/doi
1610 return -EPERM; in smk_write_doi()
1613 return -EINVAL; in smk_write_doi()
1616 return -EFAULT; in smk_write_doi()
1621 return -EINVAL; in smk_write_doi()
1637 * smk_read_direct - read() for /smack/direct
1661 * smk_write_direct - write() for /smack/direct
1677 return -EPERM; in smk_write_direct()
1680 return -EINVAL; in smk_write_direct()
1683 return -EFAULT; in smk_write_direct()
1688 return -EINVAL; in smk_write_direct()
1698 if (skp->smk_netlabel.attr.mls.lvl == in smk_write_direct()
1700 skp->smk_netlabel.attr.mls.lvl = i; in smk_write_direct()
1715 * smk_read_mapped - read() for /smack/mapped
1739 * smk_write_mapped - write() for /smack/mapped
1755 return -EPERM; in smk_write_mapped()
1758 return -EINVAL; in smk_write_mapped()
1761 return -EFAULT; in smk_write_mapped()
1766 return -EINVAL; in smk_write_mapped()
1776 if (skp->smk_netlabel.attr.mls.lvl == in smk_write_mapped()
1778 skp->smk_netlabel.attr.mls.lvl = i; in smk_write_mapped()
1793 * smk_read_ambient - read() for /smack/ambient
1815 asize = strlen(smack_net_ambient->smk_known) + 1; in smk_read_ambient()
1819 smack_net_ambient->smk_known, in smk_read_ambient()
1822 rc = -EINVAL; in smk_read_ambient()
1830 * smk_write_ambient - write() for /smack/ambient
1847 return -EPERM; in smk_write_ambient()
1851 return -EINVAL; in smk_write_ambient()
1865 oldambient = smack_net_ambient->smk_known; in smk_write_ambient()
1901 seq_puts(s, sklep->smk_label->smk_known); in onlycap_seq_show()
1920 * smk_list_swap_rcu - swap public list with a private one in RCU-safe way
1937 first = public->next; in smk_list_swap_rcu()
1938 last = public->prev; in smk_list_swap_rcu()
1940 /* Publish private list in place of public in RCU-safe way */ in smk_list_swap_rcu()
1941 private->prev->next = public; in smk_list_swap_rcu()
1942 private->next->prev = public; in smk_list_swap_rcu()
1943 rcu_assign_pointer(public->next, private->next); in smk_list_swap_rcu()
1944 public->prev = private->prev; in smk_list_swap_rcu()
1950 private->next = first; in smk_list_swap_rcu()
1951 private->prev = last; in smk_list_swap_rcu()
1952 first->prev = private; in smk_list_swap_rcu()
1953 last->next = private; in smk_list_swap_rcu()
1958 * smk_parse_label_list - parse list of Smack labels, separated by spaces
1981 return -ENOMEM; in smk_parse_label_list()
1983 sklep->smk_label = skp; in smk_parse_label_list()
1984 list_add(&sklep->list, list); in smk_parse_label_list()
1991 * smk_destroy_label_list - destroy a list of smack_known_list_elem
2006 * smk_write_onlycap - write() for smackfs/onlycap
2022 return -EPERM; in smk_write_onlycap()
2025 return -EINVAL; in smk_write_onlycap()
2038 * Importing will also reject a label beginning with '-', in smk_write_onlycap()
2039 * so "-usecapabilities" will also work. in smk_write_onlycap()
2044 if (!rc || (rc == -EINVAL && list_empty(&list_tmp))) { in smk_write_onlycap()
2066 * smk_read_unconfined - read() for smackfs/unconfined
2078 ssize_t rc = -EINVAL; in smk_read_unconfined()
2085 smack = smack_unconfined->smk_known; in smk_read_unconfined()
2096 * smk_write_unconfined - write() for smackfs/unconfined
2112 return -EPERM; in smk_write_unconfined()
2115 return -EINVAL; in smk_write_unconfined()
2125 * Importing will also reject a label beginning with '-', in smk_write_unconfined()
2126 * so "-confine" will also work. in smk_write_unconfined()
2131 if (PTR_ERR(skp) == -EINVAL) in smk_write_unconfined()
2153 * smk_read_logging - read() for /smack/logging
2176 * smk_write_logging - write() for /smack/logging
2191 return -EPERM; in smk_write_logging()
2194 return -EINVAL; in smk_write_logging()
2197 return -EFAULT; in smk_write_logging()
2202 return -EINVAL; in smk_write_logging()
2204 return -EINVAL; in smk_write_logging()
2218 * Seq_file read operations for /smack/load-self
2225 return smk_seq_start(s, pos, &tsp->smk_rules); in load_self_seq_start()
2232 return smk_seq_next(s, v, pos, &tsp->smk_rules); in load_self_seq_next()
2238 struct smack_rule *srp = in load_self_seq_show() local
2241 smk_rule_show(s, srp, SMK_LABELLEN); in load_self_seq_show()
2255 * smk_open_load_self - open() for /smack/load-self2
2267 * smk_write_load_self - write() for /smack/load-self
2271 * @ppos: where to start - must be 0
2279 return smk_write_rules_list(file, buf, count, ppos, &tsp->smk_rules, in smk_write_load_self()
2280 &tsp->smk_rules_lock, SMK_FIXED24_FMT); in smk_write_load_self()
2292 * smk_user_access - handle access check transaction
2296 * @ppos: where to start - must be 0
2297 * @format: /smack/load or /smack/load2 or /smack/change-rule format.
2312 return -EINVAL; in smk_user_access()
2316 * simple_transaction_get() returns null-terminated data in smk_user_access()
2324 else if (res != -ENOENT) in smk_user_access()
2341 * smk_write_access - handle access check transaction
2345 * @ppos: where to start - must be 0
2368 struct smack_rule *srp; in load2_seq_show() local
2372 list_for_each_entry_rcu(srp, &skp->smk_rules, list) in load2_seq_show()
2373 smk_rule_show(s, srp, SMK_LONGLABEL); in load2_seq_show()
2386 * smk_open_load2 - open() for /smack/load2
2398 * smk_write_load2 - write() for /smack/load2
2402 * @ppos: where to start - must be 0
2412 return -EPERM; in smk_write_load2()
2427 * Seq_file read operations for /smack/load-self2
2434 return smk_seq_start(s, pos, &tsp->smk_rules); in load_self2_seq_start()
2441 return smk_seq_next(s, v, pos, &tsp->smk_rules); in load_self2_seq_next()
2447 struct smack_rule *srp = in load_self2_seq_show() local
2450 smk_rule_show(s, srp, SMK_LONGLABEL); in load_self2_seq_show()
2463 * smk_open_load_self2 - open() for /smack/load-self2
2475 * smk_write_load_self2 - write() for /smack/load-self2
2479 * @ppos: where to start - must be 0
2487 return smk_write_rules_list(file, buf, count, ppos, &tsp->smk_rules, in smk_write_load_self2()
2488 &tsp->smk_rules_lock, SMK_LONG_FMT); in smk_write_load_self2()
2500 * smk_write_access2 - handle access check transaction
2504 * @ppos: where to start - must be 0
2520 * smk_write_revoke_subj - write() for /smack/revoke-subject
2524 * @ppos: where to start - must be 0
2538 return -EINVAL; in smk_write_revoke_subj()
2541 return -EPERM; in smk_write_revoke_subj()
2544 return -EINVAL; in smk_write_revoke_subj()
2560 rule_list = &skp->smk_rules; in smk_write_revoke_subj()
2561 rule_lock = &skp->smk_rules_lock; in smk_write_revoke_subj()
2566 sp->smk_access = 0; in smk_write_revoke_subj()
2586 * smk_init_sysfs - initialize /sys/fs/smackfs
2595 * smk_write_change_rule - write() for /smack/change-rule
2599 * @ppos: where to start - must be 0
2608 return -EPERM; in smk_write_change_rule()
2622 * smk_read_syslog - read() for smackfs/syslog
2634 ssize_t rc = -EINVAL; in smk_read_syslog()
2645 asize = strlen(skp->smk_known) + 1; in smk_read_syslog()
2648 rc = simple_read_from_buffer(buf, cn, ppos, skp->smk_known, in smk_read_syslog()
2655 * smk_write_syslog - write() for smackfs/syslog
2671 return -EPERM; in smk_write_syslog()
2675 return -EINVAL; in smk_write_syslog()
2698 * Seq_file read operations for /smack/relabel-self
2705 return smk_seq_start(s, pos, &tsp->smk_relabel); in relabel_self_seq_start()
2712 return smk_seq_next(s, v, pos, &tsp->smk_relabel); in relabel_self_seq_next()
2721 seq_puts(s, sklep->smk_label->smk_known); in relabel_self_seq_show()
2735 * smk_open_relabel_self - open() for /smack/relabel-self
2737 * @file: "relabel-self" file pointer
2739 * Connect our relabel_self_seq_* operations with /smack/relabel-self
2748 * smk_write_relabel_self - write() for /smack/relabel-self
2752 * @ppos: where to start - must be 0
2766 return -EPERM; in smk_write_relabel_self()
2773 return -EINVAL; in smk_write_relabel_self()
2775 return -EINVAL; in smk_write_relabel_self()
2784 if (!rc || (rc == -EINVAL && list_empty(&list_tmp))) { in smk_write_relabel_self()
2790 rc = -ENOMEM; in smk_write_relabel_self()
2794 smk_destroy_label_list(&tsp->smk_relabel); in smk_write_relabel_self()
2795 list_splice(&list_tmp, &tsp->smk_relabel); in smk_write_relabel_self()
2813 * smk_read_ptrace - read() for /smack/ptrace
2836 * smk_write_ptrace - write() for /smack/ptrace
2840 * @ppos: where to start - must be 0
2849 return -EPERM; in smk_write_ptrace()
2852 return -EINVAL; in smk_write_ptrace()
2855 return -EFAULT; in smk_write_ptrace()
2860 return -EINVAL; in smk_write_ptrace()
2862 return -EINVAL; in smk_write_ptrace()
2875 * smk_fill_super - fill the smackfs superblock
2905 "load-self", &smk_load_self_ops, S_IRUGO|S_IWUGO}, in smk_fill_super()
2913 "load-self2", &smk_load_self2_ops, S_IRUGO|S_IWUGO}, in smk_fill_super()
2919 "revoke-subject", &smk_revoke_subj_ops, in smk_fill_super()
2922 "change-rule", &smk_change_rule_ops, S_IRUGO|S_IWUSR}, in smk_fill_super()
2936 "relabel-self", &smk_relabel_self_ops, in smk_fill_super()
2953 * smk_get_tree - get the smackfs superblock
2970 * smk_init_fs_context - Initialise a filesystem context for smackfs
2975 fc->ops = &smk_context_ops; in smk_init_fs_context()
2988 * init_smk_fs - get the smackfs superblock