xref: /linux/security/selinux/hooks.c (revision 28b7260548af3d35773477993ad4e4de41578dd7)
1 // SPDX-License-Identifier: GPL-2.0-only
2 /*
3  *  Security-Enhanced Linux (SELinux) security module
4  *
5  *  This file contains the SELinux hook function implementations.
6  *
7  *  Authors:  Stephen Smalley, <stephen.smalley.work@gmail.com>
8  *	      Chris Vance, <cvance@nai.com>
9  *	      Wayne Salamon, <wsalamon@nai.com>
10  *	      James Morris <jmorris@redhat.com>
11  *
12  *  Copyright (C) 2001,2002 Networks Associates Technology, Inc.
13  *  Copyright (C) 2003-2008 Red Hat, Inc., James Morris <jmorris@redhat.com>
14  *					   Eric Paris <eparis@redhat.com>
15  *  Copyright (C) 2004-2005 Trusted Computer Solutions, Inc.
16  *			    <dgoeddel@trustedcs.com>
17  *  Copyright (C) 2006, 2007, 2009 Hewlett-Packard Development Company, L.P.
18  *	Paul Moore <paul@paul-moore.com>
19  *  Copyright (C) 2007 Hitachi Software Engineering Co., Ltd.
20  *		       Yuichi Nakamura <ynakam@hitachisoft.jp>
21  *  Copyright (C) 2016 Mellanox Technologies
22  */
23 
24 #include <linux/init.h>
25 #include <linux/kd.h>
26 #include <linux/kernel.h>
27 #include <linux/kernel_read_file.h>
28 #include <linux/errno.h>
29 #include <linux/sched/signal.h>
30 #include <linux/sched/task.h>
31 #include <linux/lsm_hooks.h>
32 #include <linux/xattr.h>
33 #include <linux/capability.h>
34 #include <linux/unistd.h>
35 #include <linux/mm.h>
36 #include <linux/mman.h>
37 #include <linux/slab.h>
38 #include <linux/pagemap.h>
39 #include <linux/proc_fs.h>
40 #include <linux/swap.h>
41 #include <linux/spinlock.h>
42 #include <linux/syscalls.h>
43 #include <linux/dcache.h>
44 #include <linux/file.h>
45 #include <linux/fdtable.h>
46 #include <linux/namei.h>
47 #include <linux/mount.h>
48 #include <linux/fs_context.h>
49 #include <linux/fs_parser.h>
50 #include <linux/netfilter_ipv4.h>
51 #include <linux/netfilter_ipv6.h>
52 #include <linux/tty.h>
53 #include <net/icmp.h>
54 #include <net/ip.h>		/* for local_port_range[] */
55 #include <net/tcp.h>		/* struct or_callable used in sock_rcv_skb */
56 #include <net/inet_connection_sock.h>
57 #include <net/net_namespace.h>
58 #include <net/netlabel.h>
59 #include <linux/uaccess.h>
60 #include <asm/ioctls.h>
61 #include <linux/atomic.h>
62 #include <linux/bitops.h>
63 #include <linux/interrupt.h>
64 #include <linux/netdevice.h>	/* for network interface checks */
65 #include <net/netlink.h>
66 #include <linux/tcp.h>
67 #include <linux/udp.h>
68 #include <linux/sctp.h>
69 #include <net/sctp/structs.h>
70 #include <linux/quota.h>
71 #include <linux/un.h>		/* for Unix socket types */
72 #include <net/af_unix.h>	/* for Unix socket types */
73 #include <linux/parser.h>
74 #include <linux/nfs_mount.h>
75 #include <net/ipv6.h>
76 #include <linux/hugetlb.h>
77 #include <linux/personality.h>
78 #include <linux/audit.h>
79 #include <linux/string.h>
80 #include <linux/mutex.h>
81 #include <linux/posix-timers.h>
82 #include <linux/syslog.h>
83 #include <linux/user_namespace.h>
84 #include <linux/export.h>
85 #include <linux/msg.h>
86 #include <linux/shm.h>
87 #include <uapi/linux/shm.h>
88 #include <linux/bpf.h>
89 #include <linux/kernfs.h>
90 #include <linux/stringhash.h>	/* for hashlen_string() */
91 #include <uapi/linux/mount.h>
92 #include <linux/fsnotify.h>
93 #include <linux/fanotify.h>
94 #include <linux/io_uring/cmd.h>
95 #include <uapi/linux/lsm.h>
96 #include <linux/memfd.h>
97 #include <uapi/linux/inet_diag.h>
98 
99 #include "initcalls.h"
100 #include "avc.h"
101 #include "objsec.h"
102 #include "netif.h"
103 #include "netnode.h"
104 #include "netport.h"
105 #include "ibpkey.h"
106 #include "xfrm.h"
107 #include "netlabel.h"
108 #include "audit.h"
109 #include "avc_ss.h"
110 #include "ima.h"
111 
112 #define SELINUX_INODE_INIT_XATTRS 1
113 
114 struct selinux_state selinux_state;
115 
116 /* SECMARK reference count */
117 static atomic_t selinux_secmark_refcount = ATOMIC_INIT(0);
118 
119 #ifdef CONFIG_SECURITY_SELINUX_DEVELOP
120 static int selinux_enforcing_boot __initdata;
121 
122 static int __init enforcing_setup(char *str)
123 {
124 	unsigned long enforcing;
125 	if (!kstrtoul(str, 0, &enforcing))
126 		selinux_enforcing_boot = enforcing ? 1 : 0;
127 	return 1;
128 }
129 __setup("enforcing=", enforcing_setup);
130 #else
131 #define selinux_enforcing_boot 1
132 #endif
133 
134 int selinux_enabled_boot __initdata = 1;
135 #ifdef CONFIG_SECURITY_SELINUX_BOOTPARAM
136 static int __init selinux_enabled_setup(char *str)
137 {
138 	unsigned long enabled;
139 	if (!kstrtoul(str, 0, &enabled))
140 		selinux_enabled_boot = enabled ? 1 : 0;
141 	return 1;
142 }
143 __setup("selinux=", selinux_enabled_setup);
144 #endif
145 
146 static int __init checkreqprot_setup(char *str)
147 {
148 	unsigned long checkreqprot;
149 
150 	if (!kstrtoul(str, 0, &checkreqprot)) {
151 		if (checkreqprot)
152 			pr_err("SELinux: checkreqprot set to 1 via kernel parameter.  This is no longer supported.\n");
153 	}
154 	return 1;
155 }
156 __setup("checkreqprot=", checkreqprot_setup);
157 
158 /**
159  * selinux_secmark_enabled - Check to see if SECMARK is currently enabled
160  *
161  * Description:
162  * This function checks the SECMARK reference counter to see if any SECMARK
163  * targets are currently configured, if the reference counter is greater than
164  * zero SECMARK is considered to be enabled.  Returns true (1) if SECMARK is
165  * enabled, false (0) if SECMARK is disabled.  If the always_check_network
166  * policy capability is enabled, SECMARK is always considered enabled.
167  *
168  */
169 static int selinux_secmark_enabled(void)
170 {
171 	return (selinux_policycap_alwaysnetwork() ||
172 		atomic_read(&selinux_secmark_refcount));
173 }
174 
175 /**
176  * selinux_peerlbl_enabled - Check to see if peer labeling is currently enabled
177  *
178  * Description:
179  * This function checks if NetLabel or labeled IPSEC is enabled.  Returns true
180  * (1) if any are enabled or false (0) if neither are enabled.  If the
181  * always_check_network policy capability is enabled, peer labeling
182  * is always considered enabled.
183  *
184  */
185 static int selinux_peerlbl_enabled(void)
186 {
187 	return (selinux_policycap_alwaysnetwork() ||
188 		netlbl_enabled() || selinux_xfrm_enabled());
189 }
190 
191 static int selinux_netcache_avc_callback(u32 event)
192 {
193 	if (event == AVC_CALLBACK_RESET) {
194 		sel_netif_flush();
195 		sel_netnode_flush();
196 		sel_netport_flush();
197 		synchronize_net();
198 	}
199 	return 0;
200 }
201 
202 static int selinux_lsm_notifier_avc_callback(u32 event)
203 {
204 	if (event == AVC_CALLBACK_RESET) {
205 		sel_ib_pkey_flush();
206 		call_blocking_lsm_notifier(LSM_POLICY_CHANGE, NULL);
207 	}
208 
209 	return 0;
210 }
211 
212 /*
213  * initialise the security for the init task
214  */
215 static void cred_init_security(void)
216 {
217 	struct cred_security_struct *crsec;
218 
219 	/* NOTE: the lsm framework zeros out the buffer on allocation */
220 
221 	crsec = selinux_cred(unrcu_pointer(current->real_cred));
222 	crsec->osid = crsec->sid = SECINITSID_KERNEL;
223 }
224 
225 /*
226  * get the security ID of a set of credentials
227  */
228 static inline u32 cred_sid(const struct cred *cred)
229 {
230 	const struct cred_security_struct *crsec;
231 
232 	crsec = selinux_cred(cred);
233 	return crsec->sid;
234 }
235 
236 static void __ad_net_init(struct common_audit_data *ad,
237 			  struct lsm_network_audit *net,
238 			  int ifindex, struct sock *sk, u16 family)
239 {
240 	ad->type = LSM_AUDIT_DATA_NET;
241 	ad->u.net = net;
242 	net->netif = ifindex;
243 	net->sk = sk;
244 	net->family = family;
245 }
246 
247 static void ad_net_init_from_sk(struct common_audit_data *ad,
248 				struct lsm_network_audit *net,
249 				struct sock *sk)
250 {
251 	__ad_net_init(ad, net, 0, sk, 0);
252 }
253 
254 static void ad_net_init_from_iif(struct common_audit_data *ad,
255 				 struct lsm_network_audit *net,
256 				 int ifindex, u16 family)
257 {
258 	__ad_net_init(ad, net, ifindex, NULL, family);
259 }
260 
261 /*
262  * get the objective security ID of a task
263  */
264 static inline u32 task_sid_obj(const struct task_struct *task)
265 {
266 	u32 sid;
267 
268 	rcu_read_lock();
269 	sid = cred_sid(__task_cred(task));
270 	rcu_read_unlock();
271 	return sid;
272 }
273 
274 static int inode_doinit_with_dentry(struct inode *inode, struct dentry *opt_dentry);
275 
276 /*
277  * Try reloading inode security labels that have been marked as invalid.  The
278  * @may_sleep parameter indicates when sleeping and thus reloading labels is
279  * allowed; when set to false, returns -ECHILD when the label is
280  * invalid.  The @dentry parameter should be set to a dentry of the inode.
281  */
282 static int __inode_security_revalidate(struct inode *inode,
283 				       struct dentry *dentry,
284 				       bool may_sleep)
285 {
286 	if (!selinux_initialized())
287 		return 0;
288 
289 	if (may_sleep)
290 		might_sleep();
291 	else
292 		return -ECHILD;
293 
294 	/*
295 	 * Check to ensure that an inode's SELinux state is valid and try
296 	 * reloading the inode security label if necessary.  This will fail if
297 	 * @dentry is NULL and no dentry for this inode can be found; in that
298 	 * case, continue using the old label.
299 	 */
300 	inode_doinit_with_dentry(inode, dentry);
301 	return 0;
302 }
303 
304 static struct inode_security_struct *inode_security_novalidate(struct inode *inode)
305 {
306 	return selinux_inode(inode);
307 }
308 
309 static inline struct inode_security_struct *inode_security_rcu(struct inode *inode,
310 							       bool rcu)
311 {
312 	int rc;
313 	struct inode_security_struct *isec = selinux_inode(inode);
314 
315 	/* check below is racy, but revalidate will recheck with lock held */
316 	if (data_race(likely(isec->initialized == LABEL_INITIALIZED)))
317 		return isec;
318 	rc = __inode_security_revalidate(inode, NULL, !rcu);
319 	if (rc)
320 		return ERR_PTR(rc);
321 	return isec;
322 }
323 
324 /*
325  * Get the security label of an inode.
326  */
327 static inline struct inode_security_struct *inode_security(struct inode *inode)
328 {
329 	struct inode_security_struct *isec = selinux_inode(inode);
330 
331 	/* check below is racy, but revalidate will recheck with lock held */
332 	if (data_race(likely(isec->initialized == LABEL_INITIALIZED)))
333 		return isec;
334 	__inode_security_revalidate(inode, NULL, true);
335 	return isec;
336 }
337 
338 static inline struct inode_security_struct *backing_inode_security_novalidate(struct dentry *dentry)
339 {
340 	return selinux_inode(d_backing_inode(dentry));
341 }
342 
343 /*
344  * Get the security label of a dentry's backing inode.
345  */
346 static inline struct inode_security_struct *backing_inode_security(struct dentry *dentry)
347 {
348 	struct inode *inode = d_backing_inode(dentry);
349 	struct inode_security_struct *isec = selinux_inode(inode);
350 
351 	/* check below is racy, but revalidate will recheck with lock held */
352 	if (data_race(likely(isec->initialized == LABEL_INITIALIZED)))
353 		return isec;
354 	__inode_security_revalidate(inode, dentry, true);
355 	return isec;
356 }
357 
358 static void inode_free_security(struct inode *inode)
359 {
360 	struct inode_security_struct *isec = selinux_inode(inode);
361 	struct superblock_security_struct *sbsec;
362 
363 	if (!isec)
364 		return;
365 	sbsec = selinux_superblock(inode->i_sb);
366 	/*
367 	 * As not all inode security structures are in a list, we check for
368 	 * empty list outside of the lock to make sure that we won't waste
369 	 * time taking a lock doing nothing.
370 	 *
371 	 * The list_del_init() function can be safely called more than once.
372 	 * It should not be possible for this function to be called with
373 	 * concurrent list_add(), but for better safety against future changes
374 	 * in the code, we use list_empty_careful() here.
375 	 */
376 	if (!list_empty_careful(&isec->list)) {
377 		spin_lock(&sbsec->isec_lock);
378 		list_del_init(&isec->list);
379 		spin_unlock(&sbsec->isec_lock);
380 	}
381 }
382 
383 struct selinux_mnt_opts {
384 	u32 fscontext_sid;
385 	u32 context_sid;
386 	u32 rootcontext_sid;
387 	u32 defcontext_sid;
388 };
389 
390 static void selinux_free_mnt_opts(void *mnt_opts)
391 {
392 	kfree(mnt_opts);
393 }
394 
395 enum {
396 	Opt_error = -1,
397 	Opt_context = 0,
398 	Opt_defcontext = 1,
399 	Opt_fscontext = 2,
400 	Opt_rootcontext = 3,
401 	Opt_seclabel = 4,
402 };
403 
404 #define A(s, has_arg) {#s, sizeof(#s) - 1, Opt_##s, has_arg}
405 static const struct {
406 	const char *name;
407 	int len;
408 	int opt;
409 	bool has_arg;
410 } tokens[] = {
411 	A(context, true),
412 	A(fscontext, true),
413 	A(defcontext, true),
414 	A(rootcontext, true),
415 	A(seclabel, false),
416 };
417 #undef A
418 
419 static int match_opt_prefix(char *s, int l, char **arg)
420 {
421 	unsigned int i;
422 
423 	for (i = 0; i < ARRAY_SIZE(tokens); i++) {
424 		size_t len = tokens[i].len;
425 		if (len > l || memcmp(s, tokens[i].name, len))
426 			continue;
427 		if (tokens[i].has_arg) {
428 			if (len == l || s[len] != '=')
429 				continue;
430 			*arg = s + len + 1;
431 		} else if (len != l)
432 			continue;
433 		return tokens[i].opt;
434 	}
435 	return Opt_error;
436 }
437 
438 #define SEL_MOUNT_FAIL_MSG "SELinux:  duplicate or incompatible mount options\n"
439 
440 static int may_context_mount_sb_relabel(u32 sid,
441 			struct superblock_security_struct *sbsec,
442 			const struct cred *cred)
443 {
444 	const struct cred_security_struct *crsec = selinux_cred(cred);
445 	int rc;
446 
447 	rc = avc_has_perm(crsec->sid, sbsec->sid, SECCLASS_FILESYSTEM,
448 			  FILESYSTEM__RELABELFROM, NULL);
449 	if (rc)
450 		return rc;
451 
452 	rc = avc_has_perm(crsec->sid, sid, SECCLASS_FILESYSTEM,
453 			  FILESYSTEM__RELABELTO, NULL);
454 	return rc;
455 }
456 
457 static int may_context_mount_inode_relabel(u32 sid,
458 			struct superblock_security_struct *sbsec,
459 			const struct cred *cred)
460 {
461 	const struct cred_security_struct *crsec = selinux_cred(cred);
462 	int rc;
463 	rc = avc_has_perm(crsec->sid, sbsec->sid, SECCLASS_FILESYSTEM,
464 			  FILESYSTEM__RELABELFROM, NULL);
465 	if (rc)
466 		return rc;
467 
468 	rc = avc_has_perm(sid, sbsec->sid, SECCLASS_FILESYSTEM,
469 			  FILESYSTEM__ASSOCIATE, NULL);
470 	return rc;
471 }
472 
473 static int selinux_is_genfs_special_handling(struct super_block *sb)
474 {
475 	/* Special handling. Genfs but also in-core setxattr handler */
476 	return	!strcmp(sb->s_type->name, "sysfs") ||
477 		!strcmp(sb->s_type->name, "pstore") ||
478 		!strcmp(sb->s_type->name, "debugfs") ||
479 		!strcmp(sb->s_type->name, "tracefs") ||
480 		!strcmp(sb->s_type->name, "rootfs") ||
481 		(selinux_policycap_cgroupseclabel() &&
482 		 (!strcmp(sb->s_type->name, "cgroup") ||
483 		  !strcmp(sb->s_type->name, "cgroup2"))) ||
484 		(selinux_policycap_functionfs_seclabel() &&
485 		 !strcmp(sb->s_type->name, "functionfs"));
486 }
487 
488 static int selinux_is_sblabel_mnt(struct super_block *sb)
489 {
490 	struct superblock_security_struct *sbsec = selinux_superblock(sb);
491 
492 	/*
493 	 * IMPORTANT: Double-check logic in this function when adding a new
494 	 * SECURITY_FS_USE_* definition!
495 	 */
496 	BUILD_BUG_ON(SECURITY_FS_USE_MAX != 7);
497 
498 	switch (sbsec->behavior) {
499 	case SECURITY_FS_USE_XATTR:
500 	case SECURITY_FS_USE_TRANS:
501 	case SECURITY_FS_USE_TASK:
502 	case SECURITY_FS_USE_NATIVE:
503 		return 1;
504 
505 	case SECURITY_FS_USE_GENFS:
506 		return selinux_is_genfs_special_handling(sb);
507 
508 	/* Never allow relabeling on context mounts */
509 	case SECURITY_FS_USE_MNTPOINT:
510 	case SECURITY_FS_USE_NONE:
511 	default:
512 		return 0;
513 	}
514 }
515 
516 static int sb_check_xattr_support(struct super_block *sb)
517 {
518 	struct superblock_security_struct *sbsec = selinux_superblock(sb);
519 	struct dentry *root = sb->s_root;
520 	struct inode *root_inode = d_backing_inode(root);
521 	u32 sid;
522 	int rc;
523 
524 	/*
525 	 * Make sure that the xattr handler exists and that no
526 	 * error other than -ENODATA is returned by getxattr on
527 	 * the root directory.  -ENODATA is ok, as this may be
528 	 * the first boot of the SELinux kernel before we have
529 	 * assigned xattr values to the filesystem.
530 	 */
531 	if (!(root_inode->i_opflags & IOP_XATTR)) {
532 		pr_warn("SELinux: (dev %s, type %s) has no xattr support\n",
533 			sb->s_id, sb->s_type->name);
534 		goto fallback;
535 	}
536 
537 	rc = __vfs_getxattr(root, root_inode, XATTR_NAME_SELINUX, NULL, 0);
538 	if (rc < 0 && rc != -ENODATA) {
539 		if (rc == -EOPNOTSUPP) {
540 			pr_warn("SELinux: (dev %s, type %s) has no security xattr handler\n",
541 				sb->s_id, sb->s_type->name);
542 			goto fallback;
543 		} else {
544 			pr_warn("SELinux: (dev %s, type %s) getxattr errno %d\n",
545 				sb->s_id, sb->s_type->name, -rc);
546 			return rc;
547 		}
548 	}
549 	return 0;
550 
551 fallback:
552 	/* No xattr support - try to fallback to genfs if possible. */
553 	rc = security_genfs_sid(sb->s_type->name, "/",
554 				SECCLASS_DIR, &sid);
555 	if (rc)
556 		return -EOPNOTSUPP;
557 
558 	pr_warn("SELinux: (dev %s, type %s) falling back to genfs\n",
559 		sb->s_id, sb->s_type->name);
560 	sbsec->behavior = SECURITY_FS_USE_GENFS;
561 	sbsec->sid = sid;
562 	return 0;
563 }
564 
565 static int sb_finish_set_opts(struct super_block *sb)
566 {
567 	struct superblock_security_struct *sbsec = selinux_superblock(sb);
568 	struct dentry *root = sb->s_root;
569 	struct inode *root_inode = d_backing_inode(root);
570 	int rc = 0;
571 
572 	if (sbsec->behavior == SECURITY_FS_USE_XATTR) {
573 		rc = sb_check_xattr_support(sb);
574 		if (rc)
575 			return rc;
576 	}
577 
578 	sbsec->flags |= SE_SBINITIALIZED;
579 
580 	/*
581 	 * Explicitly set or clear SBLABEL_MNT.  It's not sufficient to simply
582 	 * leave the flag untouched because sb_clone_mnt_opts might be handing
583 	 * us a superblock that needs the flag to be cleared.
584 	 */
585 	if (selinux_is_sblabel_mnt(sb))
586 		sbsec->flags |= SBLABEL_MNT;
587 	else
588 		sbsec->flags &= ~SBLABEL_MNT;
589 
590 	/* Initialize the root inode. */
591 	rc = inode_doinit_with_dentry(root_inode, root);
592 
593 	/* Initialize any other inodes associated with the superblock, e.g.
594 	   inodes created prior to initial policy load or inodes created
595 	   during get_sb by a pseudo filesystem that directly
596 	   populates itself. */
597 	spin_lock(&sbsec->isec_lock);
598 	while (!list_empty(&sbsec->isec_head)) {
599 		struct inode_security_struct *isec =
600 				list_first_entry(&sbsec->isec_head,
601 					   struct inode_security_struct, list);
602 		struct inode *inode = isec->inode;
603 		list_del_init(&isec->list);
604 		spin_unlock(&sbsec->isec_lock);
605 		inode = igrab(inode);
606 		if (inode) {
607 			if (!IS_PRIVATE(inode))
608 				inode_doinit_with_dentry(inode, NULL);
609 			iput(inode);
610 		}
611 		spin_lock(&sbsec->isec_lock);
612 	}
613 	spin_unlock(&sbsec->isec_lock);
614 	return rc;
615 }
616 
617 static int bad_option(struct superblock_security_struct *sbsec, char flag,
618 		      u32 old_sid, u32 new_sid)
619 {
620 	char mnt_flags = sbsec->flags & SE_MNTMASK;
621 
622 	/* check if the old mount command had the same options */
623 	if (sbsec->flags & SE_SBINITIALIZED)
624 		if (!(sbsec->flags & flag) ||
625 		    (old_sid != new_sid))
626 			return 1;
627 
628 	/* check if we were passed the same options twice,
629 	 * aka someone passed context=a,context=b
630 	 */
631 	if (!(sbsec->flags & SE_SBINITIALIZED))
632 		if (mnt_flags & flag)
633 			return 1;
634 	return 0;
635 }
636 
637 /*
638  * Allow filesystems with binary mount data to explicitly set mount point
639  * labeling information.
640  */
641 static int selinux_set_mnt_opts(struct super_block *sb,
642 				void *mnt_opts,
643 				unsigned long kern_flags,
644 				unsigned long *set_kern_flags)
645 {
646 	const struct cred *cred = current_cred();
647 	struct superblock_security_struct *sbsec = selinux_superblock(sb);
648 	struct dentry *root = sb->s_root;
649 	struct selinux_mnt_opts *opts = mnt_opts;
650 	struct inode_security_struct *root_isec;
651 	u32 fscontext_sid = 0, context_sid = 0, rootcontext_sid = 0;
652 	u32 defcontext_sid = 0;
653 	int rc = 0;
654 
655 	/*
656 	 * Specifying internal flags without providing a place to
657 	 * place the results is not allowed
658 	 */
659 	if (kern_flags && !set_kern_flags)
660 		return -EINVAL;
661 
662 	mutex_lock(&sbsec->lock);
663 
664 	if (!selinux_initialized()) {
665 		if (!opts) {
666 			/* Defer initialization until selinux_complete_init,
667 			   after the initial policy is loaded and the security
668 			   server is ready to handle calls. */
669 			if (kern_flags & SECURITY_LSM_NATIVE_LABELS) {
670 				sbsec->flags |= SE_SBNATIVE;
671 				*set_kern_flags |= SECURITY_LSM_NATIVE_LABELS;
672 			}
673 			goto out;
674 		}
675 		rc = -EINVAL;
676 		pr_warn("SELinux: Unable to set superblock options "
677 			"before the security server is initialized\n");
678 		goto out;
679 	}
680 
681 	/*
682 	 * Binary mount data FS will come through this function twice.  Once
683 	 * from an explicit call and once from the generic calls from the vfs.
684 	 * Since the generic VFS calls will not contain any security mount data
685 	 * we need to skip the double mount verification.
686 	 *
687 	 * This does open a hole in which we will not notice if the first
688 	 * mount using this sb set explicit options and a second mount using
689 	 * this sb does not set any security options.  (The first options
690 	 * will be used for both mounts)
691 	 */
692 	if ((sbsec->flags & SE_SBINITIALIZED) && (sb->s_type->fs_flags & FS_BINARY_MOUNTDATA)
693 		&& !opts) {
694 		if ((kern_flags & SECURITY_LSM_NATIVE_LABELS) &&
695 		    sbsec->behavior == SECURITY_FS_USE_NATIVE)
696 			*set_kern_flags |= SECURITY_LSM_NATIVE_LABELS;
697 		goto out;
698 	}
699 
700 	root_isec = backing_inode_security_novalidate(root);
701 
702 	/*
703 	 * parse the mount options, check if they are valid sids.
704 	 * also check if someone is trying to mount the same sb more
705 	 * than once with different security options.
706 	 */
707 	if (opts) {
708 		if (opts->fscontext_sid) {
709 			fscontext_sid = opts->fscontext_sid;
710 			if (bad_option(sbsec, FSCONTEXT_MNT, sbsec->sid,
711 					fscontext_sid))
712 				goto out_double_mount;
713 			sbsec->flags |= FSCONTEXT_MNT;
714 		}
715 		if (opts->context_sid) {
716 			context_sid = opts->context_sid;
717 			if (bad_option(sbsec, CONTEXT_MNT, sbsec->mntpoint_sid,
718 					context_sid))
719 				goto out_double_mount;
720 			sbsec->flags |= CONTEXT_MNT;
721 		}
722 		if (opts->rootcontext_sid) {
723 			rootcontext_sid = opts->rootcontext_sid;
724 			if (bad_option(sbsec, ROOTCONTEXT_MNT, root_isec->sid,
725 					rootcontext_sid))
726 				goto out_double_mount;
727 			sbsec->flags |= ROOTCONTEXT_MNT;
728 		}
729 		if (opts->defcontext_sid) {
730 			defcontext_sid = opts->defcontext_sid;
731 			if (bad_option(sbsec, DEFCONTEXT_MNT, sbsec->def_sid,
732 					defcontext_sid))
733 				goto out_double_mount;
734 			sbsec->flags |= DEFCONTEXT_MNT;
735 		}
736 	}
737 
738 	if (sbsec->flags & SE_SBINITIALIZED) {
739 		/* previously mounted with options, but not on this attempt? */
740 		if ((sbsec->flags & SE_MNTMASK) && !opts)
741 			goto out_double_mount;
742 		if ((kern_flags & SECURITY_LSM_NATIVE_LABELS) &&
743 		    sbsec->behavior == SECURITY_FS_USE_NATIVE)
744 			*set_kern_flags |= SECURITY_LSM_NATIVE_LABELS;
745 		rc = 0;
746 		goto out;
747 	}
748 
749 	sbsec->creator_sid = current_sid();
750 
751 	if (strcmp(sb->s_type->name, "proc") == 0)
752 		sbsec->flags |= SE_SBPROC | SE_SBGENFS;
753 
754 	if (!strcmp(sb->s_type->name, "debugfs") ||
755 	    !strcmp(sb->s_type->name, "tracefs") ||
756 	    !strcmp(sb->s_type->name, "binder") ||
757 	    !strcmp(sb->s_type->name, "bpf") ||
758 	    !strcmp(sb->s_type->name, "pstore") ||
759 	    !strcmp(sb->s_type->name, "securityfs") ||
760 	    (selinux_policycap_functionfs_seclabel() &&
761 	     !strcmp(sb->s_type->name, "functionfs")))
762 		sbsec->flags |= SE_SBGENFS;
763 
764 	if (!strcmp(sb->s_type->name, "sysfs") ||
765 	    !strcmp(sb->s_type->name, "cgroup") ||
766 	    !strcmp(sb->s_type->name, "cgroup2"))
767 		sbsec->flags |= SE_SBGENFS | SE_SBGENFS_XATTR;
768 
769 	if (!sbsec->behavior) {
770 		/*
771 		 * Determine the labeling behavior to use for this
772 		 * filesystem type.
773 		 */
774 		rc = security_fs_use(sb);
775 		if (rc) {
776 			pr_warn("%s: security_fs_use(%s) returned %d\n",
777 					__func__, sb->s_type->name, rc);
778 			goto out;
779 		}
780 	}
781 
782 	/*
783 	 * If this is a user namespace mount and the filesystem type is not
784 	 * explicitly whitelisted, then no contexts are allowed on the command
785 	 * line and security labels must be ignored.
786 	 */
787 	if (sb->s_user_ns != &init_user_ns &&
788 	    strcmp(sb->s_type->name, "tmpfs") &&
789 	    strcmp(sb->s_type->name, "ramfs") &&
790 	    strcmp(sb->s_type->name, "devpts") &&
791 	    strcmp(sb->s_type->name, "overlay")) {
792 		if (context_sid || fscontext_sid || rootcontext_sid ||
793 		    defcontext_sid) {
794 			rc = -EACCES;
795 			goto out;
796 		}
797 		if (sbsec->behavior == SECURITY_FS_USE_XATTR) {
798 			sbsec->behavior = SECURITY_FS_USE_MNTPOINT;
799 			rc = security_transition_sid(current_sid(),
800 						     current_sid(),
801 						     SECCLASS_FILE, NULL,
802 						     &sbsec->mntpoint_sid);
803 			if (rc)
804 				goto out;
805 		}
806 		goto out_set_opts;
807 	}
808 
809 	/* sets the context of the superblock for the fs being mounted. */
810 	if (fscontext_sid) {
811 		rc = may_context_mount_sb_relabel(fscontext_sid, sbsec, cred);
812 		if (rc)
813 			goto out;
814 
815 		sbsec->sid = fscontext_sid;
816 	}
817 
818 	/*
819 	 * Switch to using mount point labeling behavior.
820 	 * sets the label used on all file below the mountpoint, and will set
821 	 * the superblock context if not already set.
822 	 */
823 	if (sbsec->flags & SE_SBNATIVE) {
824 		/*
825 		 * This means we are initializing a superblock that has been
826 		 * mounted before the SELinux was initialized and the
827 		 * filesystem requested native labeling. We had already
828 		 * returned SECURITY_LSM_NATIVE_LABELS in *set_kern_flags
829 		 * in the original mount attempt, so now we just need to set
830 		 * the SECURITY_FS_USE_NATIVE behavior.
831 		 */
832 		sbsec->behavior = SECURITY_FS_USE_NATIVE;
833 	} else if (kern_flags & SECURITY_LSM_NATIVE_LABELS && !context_sid) {
834 		sbsec->behavior = SECURITY_FS_USE_NATIVE;
835 		*set_kern_flags |= SECURITY_LSM_NATIVE_LABELS;
836 	}
837 
838 	if (context_sid) {
839 		if (!fscontext_sid) {
840 			rc = may_context_mount_sb_relabel(context_sid, sbsec,
841 							  cred);
842 			if (rc)
843 				goto out;
844 			sbsec->sid = context_sid;
845 		} else {
846 			rc = may_context_mount_inode_relabel(context_sid, sbsec,
847 							     cred);
848 			if (rc)
849 				goto out;
850 		}
851 		if (!rootcontext_sid)
852 			rootcontext_sid = context_sid;
853 
854 		sbsec->mntpoint_sid = context_sid;
855 		sbsec->behavior = SECURITY_FS_USE_MNTPOINT;
856 	}
857 
858 	if (rootcontext_sid) {
859 		rc = may_context_mount_inode_relabel(rootcontext_sid, sbsec,
860 						     cred);
861 		if (rc)
862 			goto out;
863 
864 		root_isec->sid = rootcontext_sid;
865 		root_isec->initialized = LABEL_INITIALIZED;
866 	}
867 
868 	if (defcontext_sid) {
869 		if (sbsec->behavior != SECURITY_FS_USE_XATTR &&
870 			sbsec->behavior != SECURITY_FS_USE_NATIVE) {
871 			rc = -EINVAL;
872 			pr_warn("SELinux: defcontext option is "
873 			       "invalid for this filesystem type\n");
874 			goto out;
875 		}
876 
877 		if (defcontext_sid != sbsec->def_sid) {
878 			rc = may_context_mount_inode_relabel(defcontext_sid,
879 							     sbsec, cred);
880 			if (rc)
881 				goto out;
882 		}
883 
884 		sbsec->def_sid = defcontext_sid;
885 	}
886 
887 out_set_opts:
888 	rc = sb_finish_set_opts(sb);
889 out:
890 	mutex_unlock(&sbsec->lock);
891 	return rc;
892 out_double_mount:
893 	rc = -EINVAL;
894 	pr_warn("SELinux: mount invalid.  Same superblock, different "
895 	       "security settings for (dev %s, type %s)\n", sb->s_id,
896 	       sb->s_type->name);
897 	goto out;
898 }
899 
900 static int selinux_cmp_sb_context(const struct super_block *oldsb,
901 				    const struct super_block *newsb)
902 {
903 	struct superblock_security_struct *old = selinux_superblock(oldsb);
904 	struct superblock_security_struct *new = selinux_superblock(newsb);
905 	char oldflags = old->flags & SE_MNTMASK;
906 	char newflags = new->flags & SE_MNTMASK;
907 
908 	if (oldflags != newflags)
909 		goto mismatch;
910 	if ((oldflags & FSCONTEXT_MNT) && old->sid != new->sid)
911 		goto mismatch;
912 	if ((oldflags & CONTEXT_MNT) && old->mntpoint_sid != new->mntpoint_sid)
913 		goto mismatch;
914 	if ((oldflags & DEFCONTEXT_MNT) && old->def_sid != new->def_sid)
915 		goto mismatch;
916 	if (oldflags & ROOTCONTEXT_MNT) {
917 		struct inode_security_struct *oldroot = backing_inode_security(oldsb->s_root);
918 		struct inode_security_struct *newroot = backing_inode_security(newsb->s_root);
919 		if (oldroot->sid != newroot->sid)
920 			goto mismatch;
921 	}
922 	if (old->creator_sid != new->creator_sid)
923 		goto mismatch;
924 	return 0;
925 mismatch:
926 	pr_warn("SELinux: mount invalid.  Same superblock, "
927 			    "different security settings for (dev %s, "
928 			    "type %s)\n", newsb->s_id, newsb->s_type->name);
929 	return -EBUSY;
930 }
931 
932 static int selinux_sb_clone_mnt_opts(const struct super_block *oldsb,
933 					struct super_block *newsb,
934 					unsigned long kern_flags,
935 					unsigned long *set_kern_flags)
936 {
937 	int rc = 0;
938 	const struct superblock_security_struct *oldsbsec =
939 						selinux_superblock(oldsb);
940 	struct superblock_security_struct *newsbsec = selinux_superblock(newsb);
941 
942 	int set_fscontext =	(oldsbsec->flags & FSCONTEXT_MNT);
943 	int set_context =	(oldsbsec->flags & CONTEXT_MNT);
944 	int set_rootcontext =	(oldsbsec->flags & ROOTCONTEXT_MNT);
945 
946 	/*
947 	 * Specifying internal flags without providing a place to
948 	 * place the results is not allowed.
949 	 */
950 	if (kern_flags && !set_kern_flags)
951 		return -EINVAL;
952 
953 	mutex_lock(&newsbsec->lock);
954 
955 	/*
956 	 * if the parent was able to be mounted it clearly had no special lsm
957 	 * mount options.  thus we can safely deal with this superblock later
958 	 */
959 	if (!selinux_initialized()) {
960 		if (kern_flags & SECURITY_LSM_NATIVE_LABELS) {
961 			newsbsec->flags |= SE_SBNATIVE;
962 			*set_kern_flags |= SECURITY_LSM_NATIVE_LABELS;
963 		}
964 		goto out;
965 	}
966 
967 	/* how can we clone if the old one wasn't set up?? */
968 	BUG_ON(!(oldsbsec->flags & SE_SBINITIALIZED));
969 
970 	/* if fs is reusing a sb, make sure that the contexts match */
971 	if (newsbsec->flags & SE_SBINITIALIZED) {
972 		mutex_unlock(&newsbsec->lock);
973 		if ((kern_flags & SECURITY_LSM_NATIVE_LABELS) && !set_context)
974 			*set_kern_flags |= SECURITY_LSM_NATIVE_LABELS;
975 		return selinux_cmp_sb_context(oldsb, newsb);
976 	}
977 
978 	newsbsec->flags = oldsbsec->flags;
979 
980 	newsbsec->sid = oldsbsec->sid;
981 	newsbsec->def_sid = oldsbsec->def_sid;
982 	newsbsec->behavior = oldsbsec->behavior;
983 	newsbsec->creator_sid = oldsbsec->creator_sid;
984 
985 	if (newsbsec->behavior == SECURITY_FS_USE_NATIVE &&
986 		!(kern_flags & SECURITY_LSM_NATIVE_LABELS) && !set_context) {
987 		rc = security_fs_use(newsb);
988 		if (rc)
989 			goto out;
990 	}
991 
992 	if (kern_flags & SECURITY_LSM_NATIVE_LABELS && !set_context) {
993 		newsbsec->behavior = SECURITY_FS_USE_NATIVE;
994 		*set_kern_flags |= SECURITY_LSM_NATIVE_LABELS;
995 	}
996 
997 	if (set_context) {
998 		u32 sid = oldsbsec->mntpoint_sid;
999 
1000 		if (!set_fscontext)
1001 			newsbsec->sid = sid;
1002 		if (!set_rootcontext) {
1003 			struct inode_security_struct *newisec = backing_inode_security(newsb->s_root);
1004 			newisec->sid = sid;
1005 		}
1006 		newsbsec->mntpoint_sid = sid;
1007 	}
1008 	if (set_rootcontext) {
1009 		const struct inode_security_struct *oldisec = backing_inode_security(oldsb->s_root);
1010 		struct inode_security_struct *newisec = backing_inode_security(newsb->s_root);
1011 
1012 		newisec->sid = oldisec->sid;
1013 	}
1014 
1015 	sb_finish_set_opts(newsb);
1016 out:
1017 	mutex_unlock(&newsbsec->lock);
1018 	return rc;
1019 }
1020 
1021 /*
1022  * NOTE: the caller is responsible for freeing the memory even if on error.
1023  */
1024 static int selinux_add_opt(int token, const char *s, void **mnt_opts)
1025 {
1026 	struct selinux_mnt_opts *opts = *mnt_opts;
1027 	u32 *dst_sid;
1028 	int rc;
1029 
1030 	if (token == Opt_seclabel)
1031 		/* eaten and completely ignored */
1032 		return 0;
1033 	if (!s)
1034 		return -EINVAL;
1035 
1036 	if (!selinux_initialized()) {
1037 		pr_warn("SELinux: Unable to set superblock options before the security server is initialized\n");
1038 		return -EINVAL;
1039 	}
1040 
1041 	if (!opts) {
1042 		opts = kzalloc_obj(*opts);
1043 		if (!opts)
1044 			return -ENOMEM;
1045 		*mnt_opts = opts;
1046 	}
1047 
1048 	switch (token) {
1049 	case Opt_context:
1050 		if (opts->context_sid || opts->defcontext_sid)
1051 			goto err;
1052 		dst_sid = &opts->context_sid;
1053 		break;
1054 	case Opt_fscontext:
1055 		if (opts->fscontext_sid)
1056 			goto err;
1057 		dst_sid = &opts->fscontext_sid;
1058 		break;
1059 	case Opt_rootcontext:
1060 		if (opts->rootcontext_sid)
1061 			goto err;
1062 		dst_sid = &opts->rootcontext_sid;
1063 		break;
1064 	case Opt_defcontext:
1065 		if (opts->context_sid || opts->defcontext_sid)
1066 			goto err;
1067 		dst_sid = &opts->defcontext_sid;
1068 		break;
1069 	default:
1070 		WARN_ON(1);
1071 		return -EINVAL;
1072 	}
1073 	rc = security_context_str_to_sid(s, dst_sid, GFP_KERNEL);
1074 	if (rc)
1075 		pr_warn("SELinux: security_context_str_to_sid (%s) failed with errno=%d\n",
1076 			s, rc);
1077 	return rc;
1078 
1079 err:
1080 	pr_warn(SEL_MOUNT_FAIL_MSG);
1081 	return -EINVAL;
1082 }
1083 
1084 static int show_sid(struct seq_file *m, u32 sid)
1085 {
1086 	char *context = NULL;
1087 	u32 len;
1088 	int rc;
1089 
1090 	rc = security_sid_to_context(sid, &context, &len);
1091 	if (!rc) {
1092 		bool has_comma = strchr(context, ',');
1093 
1094 		seq_putc(m, '=');
1095 		if (has_comma)
1096 			seq_putc(m, '\"');
1097 		seq_escape(m, context, "\"\n\\");
1098 		if (has_comma)
1099 			seq_putc(m, '\"');
1100 	}
1101 	kfree(context);
1102 	return rc;
1103 }
1104 
1105 static int selinux_sb_show_options(struct seq_file *m, struct super_block *sb)
1106 {
1107 	struct superblock_security_struct *sbsec = selinux_superblock(sb);
1108 	int rc;
1109 
1110 	if (!(sbsec->flags & SE_SBINITIALIZED))
1111 		return 0;
1112 
1113 	if (!selinux_initialized())
1114 		return 0;
1115 
1116 	if (sbsec->flags & FSCONTEXT_MNT) {
1117 		seq_putc(m, ',');
1118 		seq_puts(m, FSCONTEXT_STR);
1119 		rc = show_sid(m, sbsec->sid);
1120 		if (rc)
1121 			return rc;
1122 	}
1123 	if (sbsec->flags & CONTEXT_MNT) {
1124 		seq_putc(m, ',');
1125 		seq_puts(m, CONTEXT_STR);
1126 		rc = show_sid(m, sbsec->mntpoint_sid);
1127 		if (rc)
1128 			return rc;
1129 	}
1130 	if (sbsec->flags & DEFCONTEXT_MNT) {
1131 		seq_putc(m, ',');
1132 		seq_puts(m, DEFCONTEXT_STR);
1133 		rc = show_sid(m, sbsec->def_sid);
1134 		if (rc)
1135 			return rc;
1136 	}
1137 	if (sbsec->flags & ROOTCONTEXT_MNT) {
1138 		struct dentry *root = sb->s_root;
1139 		struct inode_security_struct *isec = backing_inode_security(root);
1140 		seq_putc(m, ',');
1141 		seq_puts(m, ROOTCONTEXT_STR);
1142 		rc = show_sid(m, isec->sid);
1143 		if (rc)
1144 			return rc;
1145 	}
1146 	if (sbsec->flags & SBLABEL_MNT) {
1147 		seq_putc(m, ',');
1148 		seq_puts(m, SECLABEL_STR);
1149 	}
1150 	return 0;
1151 }
1152 
1153 static inline u16 inode_mode_to_security_class(umode_t mode)
1154 {
1155 	switch (mode & S_IFMT) {
1156 	case S_IFSOCK:
1157 		return SECCLASS_SOCK_FILE;
1158 	case S_IFLNK:
1159 		return SECCLASS_LNK_FILE;
1160 	case S_IFREG:
1161 		return SECCLASS_FILE;
1162 	case S_IFBLK:
1163 		return SECCLASS_BLK_FILE;
1164 	case S_IFDIR:
1165 		return SECCLASS_DIR;
1166 	case S_IFCHR:
1167 		return SECCLASS_CHR_FILE;
1168 	case S_IFIFO:
1169 		return SECCLASS_FIFO_FILE;
1170 
1171 	}
1172 
1173 	return SECCLASS_FILE;
1174 }
1175 
1176 static inline int default_protocol_stream(int protocol)
1177 {
1178 	return (protocol == IPPROTO_IP || protocol == IPPROTO_TCP ||
1179 		protocol == IPPROTO_MPTCP);
1180 }
1181 
1182 static inline int default_protocol_dgram(int protocol)
1183 {
1184 	return (protocol == IPPROTO_IP || protocol == IPPROTO_UDP);
1185 }
1186 
1187 static inline u16 socket_type_to_security_class(int family, int type, int protocol)
1188 {
1189 	bool extsockclass = selinux_policycap_extsockclass();
1190 
1191 	switch (family) {
1192 	case PF_UNIX:
1193 		switch (type) {
1194 		case SOCK_STREAM:
1195 		case SOCK_SEQPACKET:
1196 			return SECCLASS_UNIX_STREAM_SOCKET;
1197 		case SOCK_DGRAM:
1198 		case SOCK_RAW:
1199 			return SECCLASS_UNIX_DGRAM_SOCKET;
1200 		}
1201 		break;
1202 	case PF_INET:
1203 	case PF_INET6:
1204 		switch (type) {
1205 		case SOCK_STREAM:
1206 		case SOCK_SEQPACKET:
1207 			if (default_protocol_stream(protocol))
1208 				return SECCLASS_TCP_SOCKET;
1209 			else if (extsockclass && protocol == IPPROTO_SCTP)
1210 				return SECCLASS_SCTP_SOCKET;
1211 			else
1212 				return SECCLASS_RAWIP_SOCKET;
1213 		case SOCK_DGRAM:
1214 			if (default_protocol_dgram(protocol))
1215 				return SECCLASS_UDP_SOCKET;
1216 			else if (extsockclass && (protocol == IPPROTO_ICMP ||
1217 						  protocol == IPPROTO_ICMPV6))
1218 				return SECCLASS_ICMP_SOCKET;
1219 			else
1220 				return SECCLASS_RAWIP_SOCKET;
1221 		default:
1222 			return SECCLASS_RAWIP_SOCKET;
1223 		}
1224 		break;
1225 	case PF_NETLINK:
1226 		switch (protocol) {
1227 		case NETLINK_ROUTE:
1228 			return SECCLASS_NETLINK_ROUTE_SOCKET;
1229 		case NETLINK_SOCK_DIAG:
1230 			return SECCLASS_NETLINK_TCPDIAG_SOCKET;
1231 		case NETLINK_NFLOG:
1232 			return SECCLASS_NETLINK_NFLOG_SOCKET;
1233 		case NETLINK_XFRM:
1234 			return SECCLASS_NETLINK_XFRM_SOCKET;
1235 		case NETLINK_SELINUX:
1236 			return SECCLASS_NETLINK_SELINUX_SOCKET;
1237 		case NETLINK_ISCSI:
1238 			return SECCLASS_NETLINK_ISCSI_SOCKET;
1239 		case NETLINK_AUDIT:
1240 			return SECCLASS_NETLINK_AUDIT_SOCKET;
1241 		case NETLINK_FIB_LOOKUP:
1242 			return SECCLASS_NETLINK_FIB_LOOKUP_SOCKET;
1243 		case NETLINK_CONNECTOR:
1244 			return SECCLASS_NETLINK_CONNECTOR_SOCKET;
1245 		case NETLINK_NETFILTER:
1246 			return SECCLASS_NETLINK_NETFILTER_SOCKET;
1247 		case NETLINK_DNRTMSG:
1248 			return SECCLASS_NETLINK_DNRT_SOCKET;
1249 		case NETLINK_KOBJECT_UEVENT:
1250 			return SECCLASS_NETLINK_KOBJECT_UEVENT_SOCKET;
1251 		case NETLINK_GENERIC:
1252 			return SECCLASS_NETLINK_GENERIC_SOCKET;
1253 		case NETLINK_SCSITRANSPORT:
1254 			return SECCLASS_NETLINK_SCSITRANSPORT_SOCKET;
1255 		case NETLINK_RDMA:
1256 			return SECCLASS_NETLINK_RDMA_SOCKET;
1257 		case NETLINK_CRYPTO:
1258 			return SECCLASS_NETLINK_CRYPTO_SOCKET;
1259 		default:
1260 			return SECCLASS_NETLINK_SOCKET;
1261 		}
1262 	case PF_PACKET:
1263 		return SECCLASS_PACKET_SOCKET;
1264 	case PF_KEY:
1265 		return SECCLASS_KEY_SOCKET;
1266 	case PF_APPLETALK:
1267 		return SECCLASS_APPLETALK_SOCKET;
1268 	}
1269 
1270 	if (extsockclass) {
1271 		switch (family) {
1272 		case PF_AX25:
1273 			return SECCLASS_AX25_SOCKET;
1274 		case PF_IPX:
1275 			return SECCLASS_IPX_SOCKET;
1276 		case PF_NETROM:
1277 			return SECCLASS_NETROM_SOCKET;
1278 		case PF_ATMPVC:
1279 			return SECCLASS_ATMPVC_SOCKET;
1280 		case PF_X25:
1281 			return SECCLASS_X25_SOCKET;
1282 		case PF_ROSE:
1283 			return SECCLASS_ROSE_SOCKET;
1284 		case PF_DECnet:
1285 			return SECCLASS_DECNET_SOCKET;
1286 		case PF_ATMSVC:
1287 			return SECCLASS_ATMSVC_SOCKET;
1288 		case PF_RDS:
1289 			return SECCLASS_RDS_SOCKET;
1290 		case PF_IRDA:
1291 			return SECCLASS_IRDA_SOCKET;
1292 		case PF_PPPOX:
1293 			return SECCLASS_PPPOX_SOCKET;
1294 		case PF_LLC:
1295 			return SECCLASS_LLC_SOCKET;
1296 		case PF_CAN:
1297 			return SECCLASS_CAN_SOCKET;
1298 		case PF_TIPC:
1299 			return SECCLASS_TIPC_SOCKET;
1300 		case PF_BLUETOOTH:
1301 			return SECCLASS_BLUETOOTH_SOCKET;
1302 		case PF_IUCV:
1303 			return SECCLASS_IUCV_SOCKET;
1304 		case PF_RXRPC:
1305 			return SECCLASS_RXRPC_SOCKET;
1306 		case PF_ISDN:
1307 			return SECCLASS_ISDN_SOCKET;
1308 		case PF_PHONET:
1309 			return SECCLASS_PHONET_SOCKET;
1310 		case PF_IEEE802154:
1311 			return SECCLASS_IEEE802154_SOCKET;
1312 		case PF_CAIF:
1313 			return SECCLASS_CAIF_SOCKET;
1314 		case PF_ALG:
1315 			return SECCLASS_ALG_SOCKET;
1316 		case PF_NFC:
1317 			return SECCLASS_NFC_SOCKET;
1318 		case PF_VSOCK:
1319 			return SECCLASS_VSOCK_SOCKET;
1320 		case PF_KCM:
1321 			return SECCLASS_KCM_SOCKET;
1322 		case PF_QIPCRTR:
1323 			return SECCLASS_QIPCRTR_SOCKET;
1324 		case PF_SMC:
1325 			return SECCLASS_SMC_SOCKET;
1326 		case PF_XDP:
1327 			return SECCLASS_XDP_SOCKET;
1328 		case PF_MCTP:
1329 			return SECCLASS_MCTP_SOCKET;
1330 #if PF_MAX > 46
1331 #error New address family defined, please update this function.
1332 #endif
1333 		}
1334 	}
1335 
1336 	return SECCLASS_SOCKET;
1337 }
1338 
1339 static int selinux_genfs_get_sid(struct dentry *dentry,
1340 				 u16 tclass,
1341 				 u16 flags,
1342 				 u32 *sid)
1343 {
1344 	int rc;
1345 	struct super_block *sb = dentry->d_sb;
1346 	char *buffer, *path;
1347 
1348 	buffer = kmalloc(PATH_MAX, GFP_KERNEL);
1349 	if (!buffer)
1350 		return -ENOMEM;
1351 
1352 	path = dentry_path_raw(dentry, buffer, PATH_MAX);
1353 	if (IS_ERR(path))
1354 		rc = PTR_ERR(path);
1355 	else {
1356 		if (flags & SE_SBPROC) {
1357 			/* each process gets a /proc/PID/ entry. Strip off the
1358 			 * PID part to get a valid selinux labeling.
1359 			 * e.g. /proc/1/net/rpc/nfs -> /net/rpc/nfs */
1360 			while (path[1] >= '0' && path[1] <= '9') {
1361 				path[1] = '/';
1362 				path++;
1363 			}
1364 		}
1365 		rc = security_genfs_sid(sb->s_type->name,
1366 					path, tclass, sid);
1367 		if (rc == -ENOENT) {
1368 			/* No match in policy, mark as unlabeled. */
1369 			*sid = SECINITSID_UNLABELED;
1370 			rc = 0;
1371 		}
1372 	}
1373 	kfree(buffer);
1374 	return rc;
1375 }
1376 
1377 static int inode_doinit_use_xattr(struct inode *inode, struct dentry *dentry,
1378 				  u32 def_sid, u32 *sid)
1379 {
1380 #define INITCONTEXTLEN 255
1381 	char *context;
1382 	unsigned int len;
1383 	int rc;
1384 
1385 	len = INITCONTEXTLEN;
1386 	context = kmalloc(len + 1, GFP_NOFS);
1387 	if (!context)
1388 		return -ENOMEM;
1389 
1390 	context[len] = '\0';
1391 	rc = __vfs_getxattr(dentry, inode, XATTR_NAME_SELINUX, context, len);
1392 	if (rc == -ERANGE) {
1393 		kfree(context);
1394 
1395 		/* Need a larger buffer.  Query for the right size. */
1396 		rc = __vfs_getxattr(dentry, inode, XATTR_NAME_SELINUX, NULL, 0);
1397 		if (rc < 0)
1398 			return rc;
1399 
1400 		len = rc;
1401 		context = kmalloc(len + 1, GFP_NOFS);
1402 		if (!context)
1403 			return -ENOMEM;
1404 
1405 		context[len] = '\0';
1406 		rc = __vfs_getxattr(dentry, inode, XATTR_NAME_SELINUX,
1407 				    context, len);
1408 	}
1409 	if (rc < 0) {
1410 		kfree(context);
1411 		if (rc != -ENODATA) {
1412 			pr_warn("SELinux: %s:  getxattr returned %d for dev=%s ino=%llu\n",
1413 				__func__, -rc, inode->i_sb->s_id, inode->i_ino);
1414 			return rc;
1415 		}
1416 		*sid = def_sid;
1417 		return 0;
1418 	}
1419 
1420 	rc = security_context_to_sid_default(context, rc, sid,
1421 					     def_sid, GFP_NOFS);
1422 	if (rc) {
1423 		char *dev = inode->i_sb->s_id;
1424 		u64 ino = inode->i_ino;
1425 
1426 		if (rc == -EINVAL) {
1427 			pr_notice_ratelimited("SELinux: inode=%llu on dev=%s was found to have an invalid context=%s.  This indicates you may need to relabel the inode or the filesystem in question.\n",
1428 					      ino, dev, context);
1429 		} else {
1430 			pr_warn("SELinux: %s:  context_to_sid(%s) returned %d for dev=%s ino=%llu\n",
1431 				__func__, context, -rc, dev, ino);
1432 		}
1433 	}
1434 	kfree(context);
1435 	return 0;
1436 }
1437 
1438 /* The inode's security attributes must be initialized before first use. */
1439 static int inode_doinit_with_dentry(struct inode *inode, struct dentry *opt_dentry)
1440 {
1441 	struct superblock_security_struct *sbsec = NULL;
1442 	struct inode_security_struct *isec = selinux_inode(inode);
1443 	u32 task_sid, sid = 0;
1444 	u16 sclass;
1445 	struct dentry *dentry;
1446 	int rc = 0;
1447 
1448 	/* check below is racy, but we will recheck with lock held */
1449 	if (data_race(isec->initialized == LABEL_INITIALIZED))
1450 		return 0;
1451 
1452 	spin_lock(&isec->lock);
1453 	if (isec->initialized == LABEL_INITIALIZED)
1454 		goto out_unlock;
1455 
1456 	if (isec->sclass == SECCLASS_FILE)
1457 		isec->sclass = inode_mode_to_security_class(inode->i_mode);
1458 
1459 	sbsec = selinux_superblock(inode->i_sb);
1460 	if (!(sbsec->flags & SE_SBINITIALIZED)) {
1461 		/* Defer initialization until selinux_complete_init,
1462 		   after the initial policy is loaded and the security
1463 		   server is ready to handle calls. */
1464 		spin_lock(&sbsec->isec_lock);
1465 		if (list_empty(&isec->list))
1466 			list_add(&isec->list, &sbsec->isec_head);
1467 		spin_unlock(&sbsec->isec_lock);
1468 		goto out_unlock;
1469 	}
1470 
1471 	sclass = isec->sclass;
1472 	task_sid = isec->task_sid;
1473 	sid = isec->sid;
1474 	isec->initialized = LABEL_PENDING;
1475 	spin_unlock(&isec->lock);
1476 
1477 	switch (sbsec->behavior) {
1478 	/*
1479 	 * In case of SECURITY_FS_USE_NATIVE we need to re-fetch the labels
1480 	 * via xattr when called from delayed_superblock_init().
1481 	 */
1482 	case SECURITY_FS_USE_NATIVE:
1483 	case SECURITY_FS_USE_XATTR:
1484 		if (!(inode->i_opflags & IOP_XATTR)) {
1485 			sid = sbsec->def_sid;
1486 			break;
1487 		}
1488 		/* Need a dentry, since the xattr API requires one.
1489 		   Life would be simpler if we could just pass the inode. */
1490 		if (opt_dentry) {
1491 			/* Called from d_instantiate or d_splice_alias. */
1492 			dentry = dget(opt_dentry);
1493 		} else {
1494 			/*
1495 			 * Called from selinux_complete_init, try to find a dentry.
1496 			 * Some filesystems really want a connected one, so try
1497 			 * that first.  We could split SECURITY_FS_USE_XATTR in
1498 			 * two, depending upon that...
1499 			 */
1500 			dentry = d_find_alias(inode);
1501 			if (!dentry)
1502 				dentry = d_find_any_alias(inode);
1503 		}
1504 		if (!dentry) {
1505 			/*
1506 			 * this is can be hit on boot when a file is accessed
1507 			 * before the policy is loaded.  When we load policy we
1508 			 * may find inodes that have no dentry on the
1509 			 * sbsec->isec_head list.  No reason to complain as these
1510 			 * will get fixed up the next time we go through
1511 			 * inode_doinit with a dentry, before these inodes could
1512 			 * be used again by userspace.
1513 			 */
1514 			goto out_invalid;
1515 		}
1516 
1517 		rc = inode_doinit_use_xattr(inode, dentry, sbsec->def_sid,
1518 					    &sid);
1519 		dput(dentry);
1520 		if (rc)
1521 			goto out;
1522 		break;
1523 	case SECURITY_FS_USE_TASK:
1524 		sid = task_sid;
1525 		break;
1526 	case SECURITY_FS_USE_TRANS:
1527 		/* Default to the fs SID. */
1528 		sid = sbsec->sid;
1529 
1530 		/* Try to obtain a transition SID. */
1531 		rc = security_transition_sid(task_sid, sid,
1532 					     sclass, NULL, &sid);
1533 		if (rc)
1534 			goto out;
1535 		break;
1536 	case SECURITY_FS_USE_MNTPOINT:
1537 		sid = sbsec->mntpoint_sid;
1538 		break;
1539 	default:
1540 		/* Default to the fs superblock SID. */
1541 		sid = sbsec->sid;
1542 
1543 		if ((sbsec->flags & SE_SBGENFS) &&
1544 		     (!S_ISLNK(inode->i_mode) ||
1545 		      selinux_policycap_genfs_seclabel_symlinks())) {
1546 			/* We must have a dentry to determine the label on
1547 			 * procfs inodes */
1548 			if (opt_dentry) {
1549 				/* Called from d_instantiate or
1550 				 * d_splice_alias. */
1551 				dentry = dget(opt_dentry);
1552 			} else {
1553 				/* Called from selinux_complete_init, try to
1554 				 * find a dentry.  Some filesystems really want
1555 				 * a connected one, so try that first.
1556 				 */
1557 				dentry = d_find_alias(inode);
1558 				if (!dentry)
1559 					dentry = d_find_any_alias(inode);
1560 			}
1561 			/*
1562 			 * This can be hit on boot when a file is accessed
1563 			 * before the policy is loaded.  When we load policy we
1564 			 * may find inodes that have no dentry on the
1565 			 * sbsec->isec_head list.  No reason to complain as
1566 			 * these will get fixed up the next time we go through
1567 			 * inode_doinit() with a dentry, before these inodes
1568 			 * could be used again by userspace.
1569 			 */
1570 			if (!dentry)
1571 				goto out_invalid;
1572 			rc = selinux_genfs_get_sid(dentry, sclass,
1573 						   sbsec->flags, &sid);
1574 			if (rc) {
1575 				dput(dentry);
1576 				goto out;
1577 			}
1578 
1579 			if ((sbsec->flags & SE_SBGENFS_XATTR) &&
1580 			    (inode->i_opflags & IOP_XATTR)) {
1581 				rc = inode_doinit_use_xattr(inode, dentry,
1582 							    sid, &sid);
1583 				if (rc) {
1584 					dput(dentry);
1585 					goto out;
1586 				}
1587 			}
1588 			dput(dentry);
1589 		}
1590 		break;
1591 	}
1592 
1593 out:
1594 	spin_lock(&isec->lock);
1595 	if (isec->initialized == LABEL_PENDING) {
1596 		if (rc) {
1597 			isec->initialized = LABEL_INVALID;
1598 			goto out_unlock;
1599 		}
1600 		isec->initialized = LABEL_INITIALIZED;
1601 		isec->sid = sid;
1602 	}
1603 
1604 out_unlock:
1605 	spin_unlock(&isec->lock);
1606 	return rc;
1607 
1608 out_invalid:
1609 	spin_lock(&isec->lock);
1610 	if (isec->initialized == LABEL_PENDING) {
1611 		isec->initialized = LABEL_INVALID;
1612 		isec->sid = sid;
1613 	}
1614 	spin_unlock(&isec->lock);
1615 	return 0;
1616 }
1617 
1618 /* Convert a Linux signal to an access vector. */
1619 static inline u32 signal_to_av(int sig)
1620 {
1621 	u32 perm = 0;
1622 
1623 	switch (sig) {
1624 	case SIGCHLD:
1625 		/* Commonly granted from child to parent. */
1626 		perm = PROCESS__SIGCHLD;
1627 		break;
1628 	case SIGKILL:
1629 		/* Cannot be caught or ignored */
1630 		perm = PROCESS__SIGKILL;
1631 		break;
1632 	case SIGSTOP:
1633 		/* Cannot be caught or ignored */
1634 		perm = PROCESS__SIGSTOP;
1635 		break;
1636 	default:
1637 		/* All other signals. */
1638 		perm = PROCESS__SIGNAL;
1639 		break;
1640 	}
1641 
1642 	return perm;
1643 }
1644 
1645 #if CAP_LAST_CAP > 63
1646 #error Fix SELinux to handle capabilities > 63.
1647 #endif
1648 
1649 /* Check whether a task is allowed to use a capability. */
1650 static int cred_has_capability(const struct cred *cred,
1651 			       int cap, unsigned int opts, bool initns)
1652 {
1653 	struct common_audit_data ad;
1654 	struct av_decision avd;
1655 	u16 sclass;
1656 	u32 sid = cred_sid(cred);
1657 	u32 av = CAP_TO_MASK(cap);
1658 	int rc;
1659 
1660 	ad.type = LSM_AUDIT_DATA_CAP;
1661 	ad.u.cap = cap;
1662 
1663 	switch (CAP_TO_INDEX(cap)) {
1664 	case 0:
1665 		sclass = initns ? SECCLASS_CAPABILITY : SECCLASS_CAP_USERNS;
1666 		break;
1667 	case 1:
1668 		sclass = initns ? SECCLASS_CAPABILITY2 : SECCLASS_CAP2_USERNS;
1669 		break;
1670 	default:
1671 		pr_err("SELinux:  out of range capability %d\n", cap);
1672 		return -EINVAL;
1673 	}
1674 
1675 	rc = avc_has_perm_noaudit(sid, sid, sclass, av, 0, &avd);
1676 	if (!(opts & CAP_OPT_NOAUDIT)) {
1677 		int rc2 = avc_audit(sid, sid, sclass, av, &avd, rc, &ad);
1678 		if (rc2)
1679 			return rc2;
1680 	}
1681 	return rc;
1682 }
1683 
1684 /*
1685  * Check whether a SID has a particular permission to an inode.  The 'adp'
1686  * parameter is optional and allows other audit data to be passed (e.g. the
1687  * dentry).
1688  */
1689 static int inode_sid_has_perm(u32 sid, struct inode *inode, u32 perms,
1690 			      struct common_audit_data *adp)
1691 {
1692 	struct inode_security_struct *isec;
1693 
1694 	if (unlikely(IS_PRIVATE(inode)))
1695 		return 0;
1696 
1697 	isec = selinux_inode(inode);
1698 
1699 	return avc_has_perm(sid, isec->sid, isec->sclass, perms, adp);
1700 }
1701 
1702 static int inode_has_perm(const struct cred *cred,
1703 			  struct inode *inode,
1704 			  u32 perms,
1705 			  struct common_audit_data *adp)
1706 {
1707 	return inode_sid_has_perm(cred_sid(cred), inode, perms, adp);
1708 }
1709 
1710 /* Same as inode_has_perm, but pass explicit audit data containing
1711    the dentry to help the auditing code to more easily generate the
1712    pathname if needed. */
1713 static inline int dentry_has_perm(const struct cred *cred,
1714 				  struct dentry *dentry,
1715 				  u32 av)
1716 {
1717 	struct common_audit_data ad;
1718 	struct inode *inode = d_backing_inode(dentry);
1719 	struct inode_security_struct *isec = selinux_inode(inode);
1720 
1721 	ad.type = LSM_AUDIT_DATA_DENTRY;
1722 	ad.u.dentry = dentry;
1723 	/* check below is racy, but revalidate will recheck with lock held */
1724 	if (data_race(unlikely(isec->initialized != LABEL_INITIALIZED)))
1725 		__inode_security_revalidate(inode, dentry, true);
1726 	return inode_has_perm(cred, inode, av, &ad);
1727 }
1728 
1729 /* Same as inode_has_perm, but pass explicit audit data containing
1730    the path to help the auditing code to more easily generate the
1731    pathname if needed. */
1732 static inline int path_has_perm(const struct cred *cred,
1733 				const struct path *path,
1734 				u32 av)
1735 {
1736 	struct common_audit_data ad;
1737 	struct inode *inode = d_backing_inode(path->dentry);
1738 	struct inode_security_struct *isec = selinux_inode(inode);
1739 
1740 	ad.type = LSM_AUDIT_DATA_PATH;
1741 	ad.u.path = *path;
1742 	/* check below is racy, but revalidate will recheck with lock held */
1743 	if (data_race(unlikely(isec->initialized != LABEL_INITIALIZED)))
1744 		__inode_security_revalidate(inode, path->dentry, true);
1745 	return inode_has_perm(cred, inode, av, &ad);
1746 }
1747 
1748 /* Same as path_has_perm, but uses the inode from the file struct. */
1749 static inline int file_path_has_perm(const struct cred *cred,
1750 				     struct file *file,
1751 				     u32 av)
1752 {
1753 	struct common_audit_data ad;
1754 
1755 	ad.type = LSM_AUDIT_DATA_FILE;
1756 	ad.u.file = file;
1757 	return inode_has_perm(cred, file_inode(file), av, &ad);
1758 }
1759 
1760 #ifdef CONFIG_BPF_SYSCALL
1761 static int bpf_fd_pass(const struct file *file, u32 sid);
1762 #endif
1763 
1764 static int __file_has_perm(const struct cred *cred, const struct file *file,
1765 			   u32 av, bool bf_user_file)
1766 
1767 {
1768 	struct common_audit_data ad;
1769 	struct inode *inode;
1770 	u32 ssid = cred_sid(cred);
1771 	u32 tsid_fd;
1772 	int rc;
1773 
1774 	if (bf_user_file) {
1775 		struct backing_file_security_struct *bfsec;
1776 		const struct path *path;
1777 
1778 		if (WARN_ON(!(file->f_mode & FMODE_BACKING)))
1779 			return -EIO;
1780 
1781 		bfsec = selinux_backing_file(file);
1782 		path = backing_file_user_path(file);
1783 		tsid_fd = bfsec->uf_sid;
1784 		inode = d_inode(path->dentry);
1785 
1786 		ad.type = LSM_AUDIT_DATA_PATH;
1787 		ad.u.path = *path;
1788 	} else {
1789 		struct file_security_struct *fsec = selinux_file(file);
1790 
1791 		tsid_fd = fsec->sid;
1792 		inode = file_inode(file);
1793 
1794 		ad.type = LSM_AUDIT_DATA_FILE;
1795 		ad.u.file = file;
1796 	}
1797 
1798 	if (ssid != tsid_fd) {
1799 		rc = avc_has_perm(ssid, tsid_fd, SECCLASS_FD, FD__USE, &ad);
1800 		if (rc)
1801 			return rc;
1802 	}
1803 
1804 #ifdef CONFIG_BPF_SYSCALL
1805 	/* regardless of backing vs user file, use the underlying file here */
1806 	rc = bpf_fd_pass(file, ssid);
1807 	if (rc)
1808 		return rc;
1809 #endif
1810 
1811 	/* av is zero if only checking access to the descriptor. */
1812 	if (av)
1813 		return inode_has_perm(cred, inode, av, &ad);
1814 
1815 	return 0;
1816 }
1817 
1818 /* Check whether a task can use an open file descriptor to
1819    access an inode in a given way.  Check access to the
1820    descriptor itself, and then use dentry_has_perm to
1821    check a particular permission to the file.
1822    Access to the descriptor is implicitly granted if it
1823    has the same SID as the process.  If av is zero, then
1824    access to the file is not checked, e.g. for cases
1825    where only the descriptor is affected like seek. */
1826 static inline int file_has_perm(const struct cred *cred,
1827 				const struct file *file, u32 av)
1828 {
1829 	return __file_has_perm(cred, file, av, false);
1830 }
1831 
1832 /*
1833  * Determine the label for an inode that might be unioned.
1834  */
1835 static int
1836 selinux_determine_inode_label(const struct cred_security_struct *crsec,
1837 				 struct inode *dir,
1838 				 const struct qstr *name, u16 tclass,
1839 				 u32 *_new_isid)
1840 {
1841 	const struct superblock_security_struct *sbsec =
1842 						selinux_superblock(dir->i_sb);
1843 
1844 	if ((sbsec->flags & SE_SBINITIALIZED) &&
1845 	    (sbsec->behavior == SECURITY_FS_USE_MNTPOINT)) {
1846 		*_new_isid = sbsec->mntpoint_sid;
1847 	} else if ((sbsec->flags & SBLABEL_MNT) &&
1848 		   crsec->create_sid) {
1849 		*_new_isid = crsec->create_sid;
1850 	} else {
1851 		const struct inode_security_struct *dsec = inode_security(dir);
1852 		return security_transition_sid(crsec->sid,
1853 					       dsec->sid, tclass,
1854 					       name, _new_isid);
1855 	}
1856 
1857 	return 0;
1858 }
1859 
1860 /* Check whether a task can create a file. */
1861 static int may_create(struct inode *dir,
1862 		      struct dentry *dentry,
1863 		      u16 tclass)
1864 {
1865 	const struct cred_security_struct *crsec = selinux_cred(current_cred());
1866 	struct inode_security_struct *dsec;
1867 	struct superblock_security_struct *sbsec;
1868 	u32 sid, newsid;
1869 	struct common_audit_data ad;
1870 	int rc;
1871 
1872 	dsec = inode_security(dir);
1873 	sbsec = selinux_superblock(dir->i_sb);
1874 
1875 	sid = crsec->sid;
1876 
1877 	ad.type = LSM_AUDIT_DATA_DENTRY;
1878 	ad.u.dentry = dentry;
1879 
1880 	rc = avc_has_perm(sid, dsec->sid, SECCLASS_DIR,
1881 			  DIR__ADD_NAME | DIR__SEARCH,
1882 			  &ad);
1883 	if (rc)
1884 		return rc;
1885 
1886 	rc = selinux_determine_inode_label(crsec, dir, &dentry->d_name, tclass,
1887 					   &newsid);
1888 	if (rc)
1889 		return rc;
1890 
1891 	rc = avc_has_perm(sid, newsid, tclass, FILE__CREATE, &ad);
1892 	if (rc)
1893 		return rc;
1894 
1895 	return avc_has_perm(newsid, sbsec->sid,
1896 			    SECCLASS_FILESYSTEM,
1897 			    FILESYSTEM__ASSOCIATE, &ad);
1898 }
1899 
1900 #define MAY_LINK	0
1901 #define MAY_UNLINK	1
1902 #define MAY_RMDIR	2
1903 
1904 /* Check whether a task can link, unlink, or rmdir a file/directory. */
1905 static int may_link(struct inode *dir,
1906 		    struct dentry *dentry,
1907 		    int kind)
1908 
1909 {
1910 	struct inode_security_struct *dsec, *isec;
1911 	struct common_audit_data ad;
1912 	u32 sid = current_sid();
1913 	u32 av;
1914 	int rc;
1915 
1916 	dsec = inode_security(dir);
1917 	isec = backing_inode_security(dentry);
1918 
1919 	ad.type = LSM_AUDIT_DATA_DENTRY;
1920 	ad.u.dentry = dentry;
1921 
1922 	av = DIR__SEARCH;
1923 	av |= (kind ? DIR__REMOVE_NAME : DIR__ADD_NAME);
1924 	rc = avc_has_perm(sid, dsec->sid, SECCLASS_DIR, av, &ad);
1925 	if (rc)
1926 		return rc;
1927 
1928 	switch (kind) {
1929 	case MAY_LINK:
1930 		av = FILE__LINK;
1931 		break;
1932 	case MAY_UNLINK:
1933 		av = FILE__UNLINK;
1934 		break;
1935 	case MAY_RMDIR:
1936 		av = DIR__RMDIR;
1937 		break;
1938 	default:
1939 		pr_warn("SELinux: %s:  unrecognized kind %d\n",
1940 			__func__, kind);
1941 		return 0;
1942 	}
1943 
1944 	rc = avc_has_perm(sid, isec->sid, isec->sclass, av, &ad);
1945 	return rc;
1946 }
1947 
1948 static inline int may_rename(struct inode *old_dir,
1949 			     struct dentry *old_dentry,
1950 			     struct inode *new_dir,
1951 			     struct dentry *new_dentry)
1952 {
1953 	struct inode_security_struct *old_dsec, *new_dsec, *old_isec, *new_isec;
1954 	struct common_audit_data ad;
1955 	u32 sid = current_sid();
1956 	u32 av;
1957 	int old_is_dir, new_is_dir;
1958 	int rc;
1959 
1960 	old_dsec = inode_security(old_dir);
1961 	old_isec = backing_inode_security(old_dentry);
1962 	old_is_dir = d_is_dir(old_dentry);
1963 	new_dsec = inode_security(new_dir);
1964 
1965 	ad.type = LSM_AUDIT_DATA_DENTRY;
1966 
1967 	ad.u.dentry = old_dentry;
1968 	rc = avc_has_perm(sid, old_dsec->sid, SECCLASS_DIR,
1969 			  DIR__REMOVE_NAME | DIR__SEARCH, &ad);
1970 	if (rc)
1971 		return rc;
1972 	rc = avc_has_perm(sid, old_isec->sid,
1973 			  old_isec->sclass, FILE__RENAME, &ad);
1974 	if (rc)
1975 		return rc;
1976 	if (old_is_dir && new_dir != old_dir) {
1977 		rc = avc_has_perm(sid, old_isec->sid,
1978 				  old_isec->sclass, DIR__REPARENT, &ad);
1979 		if (rc)
1980 			return rc;
1981 	}
1982 
1983 	ad.u.dentry = new_dentry;
1984 	av = DIR__ADD_NAME | DIR__SEARCH;
1985 	if (d_is_positive(new_dentry))
1986 		av |= DIR__REMOVE_NAME;
1987 	rc = avc_has_perm(sid, new_dsec->sid, SECCLASS_DIR, av, &ad);
1988 	if (rc)
1989 		return rc;
1990 	if (d_is_positive(new_dentry)) {
1991 		new_isec = backing_inode_security(new_dentry);
1992 		new_is_dir = d_is_dir(new_dentry);
1993 		rc = avc_has_perm(sid, new_isec->sid,
1994 				  new_isec->sclass,
1995 				  (new_is_dir ? DIR__RMDIR : FILE__UNLINK), &ad);
1996 		if (rc)
1997 			return rc;
1998 	}
1999 
2000 	return 0;
2001 }
2002 
2003 /* Check whether a task can perform a filesystem operation. */
2004 static int superblock_has_perm(const struct cred *cred,
2005 			       const struct super_block *sb,
2006 			       u32 perms,
2007 			       struct common_audit_data *ad)
2008 {
2009 	struct superblock_security_struct *sbsec;
2010 	u32 sid = cred_sid(cred);
2011 
2012 	sbsec = selinux_superblock(sb);
2013 	return avc_has_perm(sid, sbsec->sid, SECCLASS_FILESYSTEM, perms, ad);
2014 }
2015 
2016 /* Convert a Linux mode and permission mask to an access vector. */
2017 static inline u32 file_mask_to_av(int mode, int mask)
2018 {
2019 	u32 av = 0;
2020 
2021 	if (!S_ISDIR(mode)) {
2022 		if (mask & MAY_EXEC)
2023 			av |= FILE__EXECUTE;
2024 		if (mask & MAY_READ)
2025 			av |= FILE__READ;
2026 
2027 		if (mask & MAY_APPEND)
2028 			av |= FILE__APPEND;
2029 		else if (mask & MAY_WRITE)
2030 			av |= FILE__WRITE;
2031 
2032 	} else {
2033 		if (mask & MAY_EXEC)
2034 			av |= DIR__SEARCH;
2035 		if (mask & MAY_WRITE)
2036 			av |= DIR__WRITE;
2037 		if (mask & MAY_READ)
2038 			av |= DIR__READ;
2039 	}
2040 
2041 	return av;
2042 }
2043 
2044 /* Convert a Linux file to an access vector. */
2045 static inline u32 file_to_av(const struct file *file)
2046 {
2047 	u32 av = 0;
2048 
2049 	if (file->f_mode & FMODE_READ)
2050 		av |= FILE__READ;
2051 	if (file->f_mode & FMODE_WRITE) {
2052 		if (file->f_flags & O_APPEND)
2053 			av |= FILE__APPEND;
2054 		else
2055 			av |= FILE__WRITE;
2056 	}
2057 	if (!av) {
2058 		/*
2059 		 * Special file opened with flags 3 for ioctl-only use.
2060 		 */
2061 		av = FILE__IOCTL;
2062 	}
2063 
2064 	return av;
2065 }
2066 
2067 /*
2068  * Convert a file to an access vector and include the correct
2069  * open permission.
2070  */
2071 static inline u32 open_file_to_av(struct file *file)
2072 {
2073 	u32 av = file_to_av(file);
2074 	struct inode *inode = file_inode(file);
2075 
2076 	if (selinux_policycap_openperm() &&
2077 	    inode->i_sb->s_magic != SOCKFS_MAGIC)
2078 		av |= FILE__OPEN;
2079 
2080 	return av;
2081 }
2082 
2083 /* Hook functions begin here. */
2084 
2085 static int selinux_binder_set_context_mgr(const struct cred *mgr)
2086 {
2087 	return avc_has_perm(current_sid(), cred_sid(mgr), SECCLASS_BINDER,
2088 			    BINDER__SET_CONTEXT_MGR, NULL);
2089 }
2090 
2091 static int selinux_binder_transaction(const struct cred *from,
2092 				      const struct cred *to)
2093 {
2094 	u32 mysid = current_sid();
2095 	u32 fromsid = cred_sid(from);
2096 	u32 tosid = cred_sid(to);
2097 	int rc;
2098 
2099 	if (mysid != fromsid) {
2100 		rc = avc_has_perm(mysid, fromsid, SECCLASS_BINDER,
2101 				  BINDER__IMPERSONATE, NULL);
2102 		if (rc)
2103 			return rc;
2104 	}
2105 
2106 	return avc_has_perm(fromsid, tosid,
2107 			    SECCLASS_BINDER, BINDER__CALL, NULL);
2108 }
2109 
2110 static int selinux_binder_transfer_binder(const struct cred *from,
2111 					  const struct cred *to)
2112 {
2113 	return avc_has_perm(cred_sid(from), cred_sid(to),
2114 			    SECCLASS_BINDER, BINDER__TRANSFER,
2115 			    NULL);
2116 }
2117 
2118 static int selinux_binder_transfer_file(const struct cred *from,
2119 					const struct cred *to,
2120 					const struct file *file)
2121 {
2122 	u32 sid = cred_sid(to);
2123 	struct file_security_struct *fsec = selinux_file(file);
2124 	struct dentry *dentry = file->f_path.dentry;
2125 	struct inode_security_struct *isec;
2126 	struct common_audit_data ad;
2127 	int rc;
2128 
2129 	ad.type = LSM_AUDIT_DATA_PATH;
2130 	ad.u.path = file->f_path;
2131 
2132 	if (sid != fsec->sid) {
2133 		rc = avc_has_perm(sid, fsec->sid,
2134 				  SECCLASS_FD,
2135 				  FD__USE,
2136 				  &ad);
2137 		if (rc)
2138 			return rc;
2139 	}
2140 
2141 #ifdef CONFIG_BPF_SYSCALL
2142 	rc = bpf_fd_pass(file, sid);
2143 	if (rc)
2144 		return rc;
2145 #endif
2146 
2147 	if (unlikely(IS_PRIVATE(d_backing_inode(dentry))))
2148 		return 0;
2149 
2150 	isec = backing_inode_security(dentry);
2151 	return avc_has_perm(sid, isec->sid, isec->sclass, file_to_av(file),
2152 			    &ad);
2153 }
2154 
2155 static int selinux_ptrace_access_check(struct task_struct *child,
2156 				       unsigned int mode)
2157 {
2158 	u32 sid = current_sid();
2159 	u32 csid = task_sid_obj(child);
2160 
2161 	if (mode & PTRACE_MODE_READ)
2162 		return avc_has_perm(sid, csid, SECCLASS_FILE, FILE__READ,
2163 				NULL);
2164 
2165 	return avc_has_perm(sid, csid, SECCLASS_PROCESS, PROCESS__PTRACE,
2166 			NULL);
2167 }
2168 
2169 static int selinux_ptrace_traceme(struct task_struct *parent)
2170 {
2171 	return avc_has_perm(task_sid_obj(parent), task_sid_obj(current),
2172 			    SECCLASS_PROCESS, PROCESS__PTRACE, NULL);
2173 }
2174 
2175 static int selinux_capget(const struct task_struct *target, kernel_cap_t *effective,
2176 			  kernel_cap_t *inheritable, kernel_cap_t *permitted)
2177 {
2178 	return avc_has_perm(current_sid(), task_sid_obj(target),
2179 			SECCLASS_PROCESS, PROCESS__GETCAP, NULL);
2180 }
2181 
2182 static int selinux_capset(struct cred *new, const struct cred *old,
2183 			  const kernel_cap_t *effective,
2184 			  const kernel_cap_t *inheritable,
2185 			  const kernel_cap_t *permitted)
2186 {
2187 	return avc_has_perm(cred_sid(old), cred_sid(new), SECCLASS_PROCESS,
2188 			    PROCESS__SETCAP, NULL);
2189 }
2190 
2191 /*
2192  * (This comment used to live with the selinux_task_setuid hook,
2193  * which was removed).
2194  *
2195  * Since setuid only affects the current process, and since the SELinux
2196  * controls are not based on the Linux identity attributes, SELinux does not
2197  * need to control this operation.  However, SELinux does control the use of
2198  * the CAP_SETUID and CAP_SETGID capabilities using the capable hook.
2199  */
2200 
2201 static int selinux_capable(const struct cred *cred, struct user_namespace *ns,
2202 			   int cap, unsigned int opts)
2203 {
2204 	return cred_has_capability(cred, cap, opts, ns == &init_user_ns);
2205 }
2206 
2207 static int selinux_quotactl(int cmds, int type, int id, const struct super_block *sb)
2208 {
2209 	const struct cred *cred = current_cred();
2210 	int rc = 0;
2211 
2212 	if (!sb)
2213 		return 0;
2214 
2215 	switch (cmds) {
2216 	case Q_SYNC:
2217 	case Q_QUOTAON:
2218 	case Q_QUOTAOFF:
2219 	case Q_SETINFO:
2220 	case Q_SETQUOTA:
2221 	case Q_XQUOTAOFF:
2222 	case Q_XQUOTAON:
2223 	case Q_XSETQLIM:
2224 		rc = superblock_has_perm(cred, sb, FILESYSTEM__QUOTAMOD, NULL);
2225 		break;
2226 	case Q_GETFMT:
2227 	case Q_GETINFO:
2228 	case Q_GETQUOTA:
2229 	case Q_XGETQUOTA:
2230 	case Q_XGETQSTAT:
2231 	case Q_XGETQSTATV:
2232 	case Q_XGETNEXTQUOTA:
2233 		rc = superblock_has_perm(cred, sb, FILESYSTEM__QUOTAGET, NULL);
2234 		break;
2235 	default:
2236 		rc = 0;  /* let the kernel handle invalid cmds */
2237 		break;
2238 	}
2239 	return rc;
2240 }
2241 
2242 static int selinux_quota_on(struct dentry *dentry)
2243 {
2244 	const struct cred *cred = current_cred();
2245 
2246 	return dentry_has_perm(cred, dentry, FILE__QUOTAON);
2247 }
2248 
2249 static int selinux_syslog(int type)
2250 {
2251 	switch (type) {
2252 	case SYSLOG_ACTION_READ_ALL:	/* Read last kernel messages */
2253 	case SYSLOG_ACTION_SIZE_BUFFER:	/* Return size of the log buffer */
2254 		return avc_has_perm(current_sid(), SECINITSID_KERNEL,
2255 				    SECCLASS_SYSTEM, SYSTEM__SYSLOG_READ, NULL);
2256 	case SYSLOG_ACTION_CONSOLE_OFF:	/* Disable logging to console */
2257 	case SYSLOG_ACTION_CONSOLE_ON:	/* Enable logging to console */
2258 	/* Set level of messages printed to console */
2259 	case SYSLOG_ACTION_CONSOLE_LEVEL:
2260 		return avc_has_perm(current_sid(), SECINITSID_KERNEL,
2261 				    SECCLASS_SYSTEM, SYSTEM__SYSLOG_CONSOLE,
2262 				    NULL);
2263 	}
2264 	/* All other syslog types */
2265 	return avc_has_perm(current_sid(), SECINITSID_KERNEL,
2266 			    SECCLASS_SYSTEM, SYSTEM__SYSLOG_MOD, NULL);
2267 }
2268 
2269 /*
2270  * Check permission for allocating a new virtual mapping. Returns
2271  * 0 if permission is granted, negative error code if not.
2272  *
2273  * Do not audit the selinux permission check, as this is applied to all
2274  * processes that allocate mappings.
2275  */
2276 static int selinux_vm_enough_memory(struct mm_struct *mm, long pages)
2277 {
2278 	return cred_has_capability(current_cred(), CAP_SYS_ADMIN,
2279 				   CAP_OPT_NOAUDIT, true);
2280 }
2281 
2282 /* binprm security operations */
2283 
2284 static u32 ptrace_parent_sid(void)
2285 {
2286 	u32 sid = 0;
2287 	struct task_struct *tracer;
2288 
2289 	rcu_read_lock();
2290 	tracer = ptrace_parent(current);
2291 	if (tracer)
2292 		sid = task_sid_obj(tracer);
2293 	rcu_read_unlock();
2294 
2295 	return sid;
2296 }
2297 
2298 static int check_nnp_nosuid(const struct linux_binprm *bprm,
2299 			    const struct cred_security_struct *old_crsec,
2300 			    const struct cred_security_struct *new_crsec)
2301 {
2302 	int nnp = (bprm->unsafe & LSM_UNSAFE_NO_NEW_PRIVS);
2303 	int nosuid = !mnt_may_suid(bprm->file->f_path.mnt);
2304 	int rc;
2305 	u32 av;
2306 
2307 	if (!nnp && !nosuid)
2308 		return 0; /* neither NNP nor nosuid */
2309 
2310 	if (new_crsec->sid == old_crsec->sid)
2311 		return 0; /* No change in credentials */
2312 
2313 	/*
2314 	 * If the policy enables the nnp_nosuid_transition policy capability,
2315 	 * then we permit transitions under NNP or nosuid if the
2316 	 * policy allows the corresponding permission between
2317 	 * the old and new contexts.
2318 	 */
2319 	if (selinux_policycap_nnp_nosuid_transition()) {
2320 		av = 0;
2321 		if (nnp)
2322 			av |= PROCESS2__NNP_TRANSITION;
2323 		if (nosuid)
2324 			av |= PROCESS2__NOSUID_TRANSITION;
2325 		rc = avc_has_perm(old_crsec->sid, new_crsec->sid,
2326 				  SECCLASS_PROCESS2, av, NULL);
2327 		if (!rc)
2328 			return 0;
2329 	}
2330 
2331 	/*
2332 	 * We also permit NNP or nosuid transitions to bounded SIDs,
2333 	 * i.e. SIDs that are guaranteed to only be allowed a subset
2334 	 * of the permissions of the current SID.
2335 	 */
2336 	rc = security_bounded_transition(old_crsec->sid,
2337 					 new_crsec->sid);
2338 	if (!rc)
2339 		return 0;
2340 
2341 	/*
2342 	 * On failure, preserve the errno values for NNP vs nosuid.
2343 	 * NNP:  Operation not permitted for caller.
2344 	 * nosuid:  Permission denied to file.
2345 	 */
2346 	if (nnp)
2347 		return -EPERM;
2348 	return -EACCES;
2349 }
2350 
2351 static int selinux_bprm_creds_for_exec(struct linux_binprm *bprm)
2352 {
2353 	const struct cred_security_struct *old_crsec;
2354 	struct cred_security_struct *new_crsec;
2355 	struct inode_security_struct *isec;
2356 	struct common_audit_data ad;
2357 	struct inode *inode = file_inode(bprm->file);
2358 	int rc;
2359 
2360 	/* SELinux context only depends on initial program or script and not
2361 	 * the script interpreter */
2362 
2363 	old_crsec = selinux_cred(current_cred());
2364 	new_crsec = selinux_cred(bprm->cred);
2365 	isec = inode_security(inode);
2366 
2367 	if (WARN_ON(isec->sclass != SECCLASS_FILE &&
2368 		    isec->sclass != SECCLASS_MEMFD_FILE))
2369 		return -EACCES;
2370 
2371 	/* Default to the current task SID. */
2372 	new_crsec->sid = old_crsec->sid;
2373 	new_crsec->osid = old_crsec->sid;
2374 
2375 	/* Reset fs, key, and sock SIDs on execve. */
2376 	new_crsec->create_sid = 0;
2377 	new_crsec->keycreate_sid = 0;
2378 	new_crsec->sockcreate_sid = 0;
2379 
2380 	/*
2381 	 * Before policy is loaded, label any task outside kernel space
2382 	 * as SECINITSID_INIT, so that any userspace tasks surviving from
2383 	 * early boot end up with a label different from SECINITSID_KERNEL
2384 	 * (if the policy chooses to set SECINITSID_INIT != SECINITSID_KERNEL).
2385 	 */
2386 	if (!selinux_initialized()) {
2387 		new_crsec->sid = SECINITSID_INIT;
2388 		/* also clear the exec_sid just in case */
2389 		new_crsec->exec_sid = 0;
2390 		return 0;
2391 	}
2392 
2393 	if (old_crsec->exec_sid) {
2394 		new_crsec->sid = old_crsec->exec_sid;
2395 		/* Reset exec SID on execve. */
2396 		new_crsec->exec_sid = 0;
2397 
2398 		/* Fail on NNP or nosuid if not an allowed transition. */
2399 		rc = check_nnp_nosuid(bprm, old_crsec, new_crsec);
2400 		if (rc)
2401 			return rc;
2402 	} else {
2403 		/* Check for a default transition on this program. */
2404 		rc = security_transition_sid(old_crsec->sid,
2405 					     isec->sid, SECCLASS_PROCESS, NULL,
2406 					     &new_crsec->sid);
2407 		if (rc)
2408 			return rc;
2409 
2410 		/*
2411 		 * Fallback to old SID on NNP or nosuid if not an allowed
2412 		 * transition.
2413 		 */
2414 		rc = check_nnp_nosuid(bprm, old_crsec, new_crsec);
2415 		if (rc)
2416 			new_crsec->sid = old_crsec->sid;
2417 	}
2418 
2419 	ad.type = LSM_AUDIT_DATA_FILE;
2420 	ad.u.file = bprm->file;
2421 
2422 	if (new_crsec->sid == old_crsec->sid) {
2423 		rc = avc_has_perm(old_crsec->sid, isec->sid, isec->sclass,
2424 				  FILE__EXECUTE_NO_TRANS, &ad);
2425 		if (rc)
2426 			return rc;
2427 	} else {
2428 		/* Check permissions for the transition. */
2429 		rc = avc_has_perm(old_crsec->sid, new_crsec->sid,
2430 				  SECCLASS_PROCESS, PROCESS__TRANSITION, &ad);
2431 		if (rc)
2432 			return rc;
2433 
2434 		rc = avc_has_perm(new_crsec->sid, isec->sid, isec->sclass,
2435 				  FILE__ENTRYPOINT, &ad);
2436 		if (rc)
2437 			return rc;
2438 
2439 		/* Check for shared state */
2440 		if (bprm->unsafe & LSM_UNSAFE_SHARE) {
2441 			rc = avc_has_perm(old_crsec->sid, new_crsec->sid,
2442 					  SECCLASS_PROCESS, PROCESS__SHARE,
2443 					  NULL);
2444 			if (rc)
2445 				return -EPERM;
2446 		}
2447 
2448 		/* Make sure that anyone attempting to ptrace over a task that
2449 		 * changes its SID has the appropriate permit */
2450 		if (bprm->unsafe & LSM_UNSAFE_PTRACE) {
2451 			u32 ptsid = ptrace_parent_sid();
2452 			if (ptsid != 0) {
2453 				rc = avc_has_perm(ptsid, new_crsec->sid,
2454 						  SECCLASS_PROCESS,
2455 						  PROCESS__PTRACE, NULL);
2456 				if (rc)
2457 					return -EPERM;
2458 			}
2459 		}
2460 
2461 		/* Clear any possibly unsafe personality bits on exec: */
2462 		bprm->per_clear |= PER_CLEAR_ON_SETID;
2463 
2464 		/* Enable secure mode for SIDs transitions unless
2465 		   the noatsecure permission is granted between
2466 		   the two SIDs, i.e. ahp returns 0. */
2467 		rc = avc_has_perm(old_crsec->sid, new_crsec->sid,
2468 				  SECCLASS_PROCESS, PROCESS__NOATSECURE,
2469 				  NULL);
2470 		bprm->secureexec |= !!rc;
2471 	}
2472 
2473 	return 0;
2474 }
2475 
2476 static int match_file(const void *p, struct file *file, unsigned fd)
2477 {
2478 	return file_has_perm(p, file, file_to_av(file)) ? fd + 1 : 0;
2479 }
2480 
2481 /* Derived from fs/exec.c:flush_old_files. */
2482 static inline void flush_unauthorized_files(const struct cred *cred,
2483 					    struct files_struct *files)
2484 {
2485 	struct file *file, *devnull = NULL;
2486 	struct tty_struct *tty;
2487 	int drop_tty = 0;
2488 	unsigned n;
2489 
2490 	tty = get_current_tty();
2491 	if (tty) {
2492 		spin_lock(&tty->files_lock);
2493 		if (!list_empty(&tty->tty_files)) {
2494 			struct tty_file_private *file_priv;
2495 
2496 			/* Revalidate access to controlling tty.
2497 			   Use file_path_has_perm on the tty path directly
2498 			   rather than using file_has_perm, as this particular
2499 			   open file may belong to another process and we are
2500 			   only interested in the inode-based check here. */
2501 			file_priv = list_first_entry(&tty->tty_files,
2502 						struct tty_file_private, list);
2503 			file = file_priv->file;
2504 			if (file_path_has_perm(cred, file, FILE__READ | FILE__WRITE))
2505 				drop_tty = 1;
2506 		}
2507 		spin_unlock(&tty->files_lock);
2508 		tty_kref_put(tty);
2509 	}
2510 	/* Reset controlling tty. */
2511 	if (drop_tty)
2512 		no_tty();
2513 
2514 	/* Revalidate access to inherited open files. */
2515 	n = iterate_fd(files, 0, match_file, cred);
2516 	if (!n) /* none found? */
2517 		return;
2518 
2519 	devnull = dentry_open(&selinux_null, O_RDWR, cred);
2520 	if (IS_ERR(devnull))
2521 		devnull = NULL;
2522 	/* replace all the matching ones with this */
2523 	do {
2524 		replace_fd(n - 1, devnull, 0);
2525 	} while ((n = iterate_fd(files, n, match_file, cred)) != 0);
2526 	if (devnull)
2527 		fput(devnull);
2528 }
2529 
2530 /*
2531  * Prepare a process for imminent new credential changes due to exec
2532  */
2533 static void selinux_bprm_committing_creds(const struct linux_binprm *bprm)
2534 {
2535 	struct cred_security_struct *new_crsec;
2536 	struct rlimit *rlim, *initrlim;
2537 	int rc, i;
2538 
2539 	new_crsec = selinux_cred(bprm->cred);
2540 	if (new_crsec->sid == new_crsec->osid)
2541 		return;
2542 
2543 	/* Close files for which the new task SID is not authorized. */
2544 	flush_unauthorized_files(bprm->cred, current->files);
2545 
2546 	/* Always clear parent death signal on SID transitions. */
2547 	current->pdeath_signal = 0;
2548 
2549 	/* Check whether the new SID can inherit resource limits from the old
2550 	 * SID.  If not, reset all soft limits to the lower of the current
2551 	 * task's hard limit and the init task's soft limit.
2552 	 *
2553 	 * Note that the setting of hard limits (even to lower them) can be
2554 	 * controlled by the setrlimit check.  The inclusion of the init task's
2555 	 * soft limit into the computation is to avoid resetting soft limits
2556 	 * higher than the default soft limit for cases where the default is
2557 	 * lower than the hard limit, e.g. RLIMIT_CORE or RLIMIT_STACK.
2558 	 */
2559 	rc = avc_has_perm(new_crsec->osid, new_crsec->sid, SECCLASS_PROCESS,
2560 			  PROCESS__RLIMITINH, NULL);
2561 	if (rc) {
2562 		/* protect against do_prlimit() */
2563 		task_lock(current);
2564 		for (i = 0; i < RLIM_NLIMITS; i++) {
2565 			rlim = current->signal->rlim + i;
2566 			initrlim = init_task.signal->rlim + i;
2567 			rlim->rlim_cur = min(rlim->rlim_max, initrlim->rlim_cur);
2568 		}
2569 		task_unlock(current);
2570 		if (IS_ENABLED(CONFIG_POSIX_TIMERS))
2571 			update_rlimit_cpu(current, rlimit(RLIMIT_CPU));
2572 	}
2573 }
2574 
2575 /*
2576  * Clean up the process immediately after the installation of new credentials
2577  * due to exec
2578  */
2579 static void selinux_bprm_committed_creds(const struct linux_binprm *bprm)
2580 {
2581 	const struct cred_security_struct *crsec = selinux_cred(current_cred());
2582 	u32 osid, sid;
2583 	int rc;
2584 
2585 	osid = crsec->osid;
2586 	sid = crsec->sid;
2587 
2588 	if (sid == osid)
2589 		return;
2590 
2591 	/* Check whether the new SID can inherit signal state from the old SID.
2592 	 * If not, clear itimers to avoid subsequent signal generation and
2593 	 * flush and unblock signals.
2594 	 *
2595 	 * This must occur _after_ the task SID has been updated so that any
2596 	 * kill done after the flush will be checked against the new SID.
2597 	 */
2598 	rc = avc_has_perm(osid, sid, SECCLASS_PROCESS, PROCESS__SIGINH, NULL);
2599 	if (rc) {
2600 		clear_itimer();
2601 
2602 		spin_lock_irq(&unrcu_pointer(current->sighand)->siglock);
2603 		if (!fatal_signal_pending(current)) {
2604 			flush_sigqueue(&current->pending);
2605 			flush_sigqueue(&current->signal->shared_pending);
2606 			flush_signal_handlers(current, 1);
2607 			sigemptyset(&current->blocked);
2608 			recalc_sigpending();
2609 		}
2610 		spin_unlock_irq(&unrcu_pointer(current->sighand)->siglock);
2611 	}
2612 
2613 	/* Wake up the parent if it is waiting so that it can recheck
2614 	 * wait permission to the new task SID. */
2615 	read_lock(&tasklist_lock);
2616 	__wake_up_parent(current, unrcu_pointer(current->real_parent));
2617 	read_unlock(&tasklist_lock);
2618 }
2619 
2620 /* superblock security operations */
2621 
2622 static int selinux_sb_alloc_security(struct super_block *sb)
2623 {
2624 	struct superblock_security_struct *sbsec = selinux_superblock(sb);
2625 
2626 	mutex_init(&sbsec->lock);
2627 	INIT_LIST_HEAD(&sbsec->isec_head);
2628 	spin_lock_init(&sbsec->isec_lock);
2629 	sbsec->sid = SECINITSID_UNLABELED;
2630 	sbsec->def_sid = SECINITSID_FILE;
2631 	sbsec->mntpoint_sid = SECINITSID_UNLABELED;
2632 	sbsec->creator_sid = SECINITSID_UNLABELED;
2633 
2634 	return 0;
2635 }
2636 
2637 static inline int opt_len(const char *s)
2638 {
2639 	bool open_quote = false;
2640 	int len;
2641 	char c;
2642 
2643 	for (len = 0; (c = s[len]) != '\0'; len++) {
2644 		if (c == '"')
2645 			open_quote = !open_quote;
2646 		if (c == ',' && !open_quote)
2647 			break;
2648 	}
2649 	return len;
2650 }
2651 
2652 static int selinux_sb_eat_lsm_opts(char *options, void **mnt_opts)
2653 {
2654 	char *from = options;
2655 	char *to = options;
2656 	bool first = true;
2657 	int rc;
2658 
2659 	while (1) {
2660 		int len = opt_len(from);
2661 		int token;
2662 		char *arg = NULL;
2663 
2664 		token = match_opt_prefix(from, len, &arg);
2665 
2666 		if (token != Opt_error) {
2667 			char *p, *q;
2668 
2669 			/* strip quotes */
2670 			if (arg) {
2671 				for (p = q = arg; p < from + len; p++) {
2672 					char c = *p;
2673 					if (c != '"')
2674 						*q++ = c;
2675 				}
2676 				arg = kmemdup_nul(arg, q - arg, GFP_KERNEL);
2677 				if (!arg) {
2678 					rc = -ENOMEM;
2679 					goto free_opt;
2680 				}
2681 			}
2682 			rc = selinux_add_opt(token, arg, mnt_opts);
2683 			kfree(arg);
2684 			arg = NULL;
2685 			if (unlikely(rc)) {
2686 				goto free_opt;
2687 			}
2688 		} else {
2689 			if (!first) {	// copy with preceding comma
2690 				from--;
2691 				len++;
2692 			}
2693 			if (to != from)
2694 				memmove(to, from, len);
2695 			to += len;
2696 			first = false;
2697 		}
2698 		if (!from[len])
2699 			break;
2700 		from += len + 1;
2701 	}
2702 	*to = '\0';
2703 	return 0;
2704 
2705 free_opt:
2706 	if (*mnt_opts) {
2707 		selinux_free_mnt_opts(*mnt_opts);
2708 		*mnt_opts = NULL;
2709 	}
2710 	return rc;
2711 }
2712 
2713 static int selinux_sb_mnt_opts_compat(struct super_block *sb, void *mnt_opts)
2714 {
2715 	struct selinux_mnt_opts *opts = mnt_opts;
2716 	struct superblock_security_struct *sbsec = selinux_superblock(sb);
2717 
2718 	/*
2719 	 * Superblock not initialized (i.e. no options) - reject if any
2720 	 * options specified, otherwise accept.
2721 	 */
2722 	if (!(sbsec->flags & SE_SBINITIALIZED))
2723 		return opts ? 1 : 0;
2724 
2725 	/*
2726 	 * Superblock initialized and no options specified - reject if
2727 	 * superblock has any options set, otherwise accept.
2728 	 */
2729 	if (!opts)
2730 		return (sbsec->flags & SE_MNTMASK) ? 1 : 0;
2731 
2732 	if (opts->fscontext_sid) {
2733 		if (bad_option(sbsec, FSCONTEXT_MNT, sbsec->sid,
2734 			       opts->fscontext_sid))
2735 			return 1;
2736 	}
2737 	if (opts->context_sid) {
2738 		if (bad_option(sbsec, CONTEXT_MNT, sbsec->mntpoint_sid,
2739 			       opts->context_sid))
2740 			return 1;
2741 	}
2742 	if (opts->rootcontext_sid) {
2743 		struct inode_security_struct *root_isec;
2744 
2745 		root_isec = backing_inode_security(sb->s_root);
2746 		if (bad_option(sbsec, ROOTCONTEXT_MNT, root_isec->sid,
2747 			       opts->rootcontext_sid))
2748 			return 1;
2749 	}
2750 	if (opts->defcontext_sid) {
2751 		if (bad_option(sbsec, DEFCONTEXT_MNT, sbsec->def_sid,
2752 			       opts->defcontext_sid))
2753 			return 1;
2754 	}
2755 	return 0;
2756 }
2757 
2758 static int selinux_sb_remount(struct super_block *sb, void *mnt_opts)
2759 {
2760 	struct selinux_mnt_opts *opts = mnt_opts;
2761 	struct superblock_security_struct *sbsec = selinux_superblock(sb);
2762 
2763 	if (!(sbsec->flags & SE_SBINITIALIZED))
2764 		return 0;
2765 
2766 	if (!opts)
2767 		return 0;
2768 
2769 	if (opts->fscontext_sid) {
2770 		if (bad_option(sbsec, FSCONTEXT_MNT, sbsec->sid,
2771 			       opts->fscontext_sid))
2772 			goto out_bad_option;
2773 	}
2774 	if (opts->context_sid) {
2775 		if (bad_option(sbsec, CONTEXT_MNT, sbsec->mntpoint_sid,
2776 			       opts->context_sid))
2777 			goto out_bad_option;
2778 	}
2779 	if (opts->rootcontext_sid) {
2780 		struct inode_security_struct *root_isec;
2781 		root_isec = backing_inode_security(sb->s_root);
2782 		if (bad_option(sbsec, ROOTCONTEXT_MNT, root_isec->sid,
2783 			       opts->rootcontext_sid))
2784 			goto out_bad_option;
2785 	}
2786 	if (opts->defcontext_sid) {
2787 		if (bad_option(sbsec, DEFCONTEXT_MNT, sbsec->def_sid,
2788 			       opts->defcontext_sid))
2789 			goto out_bad_option;
2790 	}
2791 	return 0;
2792 
2793 out_bad_option:
2794 	pr_warn("SELinux: unable to change security options "
2795 	       "during remount (dev %s, type=%s)\n", sb->s_id,
2796 	       sb->s_type->name);
2797 	return -EINVAL;
2798 }
2799 
2800 static int selinux_sb_kern_mount(const struct super_block *sb)
2801 {
2802 	const struct cred *cred = current_cred();
2803 	struct common_audit_data ad;
2804 
2805 	ad.type = LSM_AUDIT_DATA_DENTRY;
2806 	ad.u.dentry = sb->s_root;
2807 	return superblock_has_perm(cred, sb, FILESYSTEM__MOUNT, &ad);
2808 }
2809 
2810 static int selinux_sb_statfs(struct dentry *dentry)
2811 {
2812 	const struct cred *cred = current_cred();
2813 	struct common_audit_data ad;
2814 
2815 	ad.type = LSM_AUDIT_DATA_DENTRY;
2816 	ad.u.dentry = dentry->d_sb->s_root;
2817 	return superblock_has_perm(cred, dentry->d_sb, FILESYSTEM__GETATTR, &ad);
2818 }
2819 
2820 static int selinux_mount(const char *dev_name,
2821 			 const struct path *path,
2822 			 const char *type,
2823 			 unsigned long flags,
2824 			 void *data)
2825 {
2826 	const struct cred *cred = current_cred();
2827 
2828 	if (flags & MS_REMOUNT)
2829 		return superblock_has_perm(cred, path->dentry->d_sb,
2830 					   FILESYSTEM__REMOUNT, NULL);
2831 	else
2832 		return path_has_perm(cred, path, FILE__MOUNTON);
2833 }
2834 
2835 static int selinux_move_mount(const struct path *from_path,
2836 			      const struct path *to_path)
2837 {
2838 	const struct cred *cred = current_cred();
2839 
2840 	return path_has_perm(cred, to_path, FILE__MOUNTON);
2841 }
2842 
2843 static int selinux_umount(struct vfsmount *mnt, int flags)
2844 {
2845 	const struct cred *cred = current_cred();
2846 
2847 	return superblock_has_perm(cred, mnt->mnt_sb,
2848 				   FILESYSTEM__UNMOUNT, NULL);
2849 }
2850 
2851 static int selinux_fs_context_submount(struct fs_context *fc,
2852 				   struct super_block *reference)
2853 {
2854 	const struct superblock_security_struct *sbsec = selinux_superblock(reference);
2855 	struct selinux_mnt_opts *opts;
2856 
2857 	/*
2858 	 * Ensure that fc->security remains NULL when no options are set
2859 	 * as expected by selinux_set_mnt_opts().
2860 	 */
2861 	if (!(sbsec->flags & (FSCONTEXT_MNT|CONTEXT_MNT|DEFCONTEXT_MNT)))
2862 		return 0;
2863 
2864 	opts = kzalloc_obj(*opts);
2865 	if (!opts)
2866 		return -ENOMEM;
2867 
2868 	if (sbsec->flags & FSCONTEXT_MNT)
2869 		opts->fscontext_sid = sbsec->sid;
2870 	if (sbsec->flags & CONTEXT_MNT)
2871 		opts->context_sid = sbsec->mntpoint_sid;
2872 	if (sbsec->flags & DEFCONTEXT_MNT)
2873 		opts->defcontext_sid = sbsec->def_sid;
2874 	fc->security = opts;
2875 	return 0;
2876 }
2877 
2878 static int selinux_fs_context_dup(struct fs_context *fc,
2879 				  struct fs_context *src_fc)
2880 {
2881 	const struct selinux_mnt_opts *src = src_fc->security;
2882 
2883 	if (!src)
2884 		return 0;
2885 
2886 	fc->security = kmemdup(src, sizeof(*src), GFP_KERNEL);
2887 	return fc->security ? 0 : -ENOMEM;
2888 }
2889 
2890 static const struct fs_parameter_spec selinux_fs_parameters[] = {
2891 	fsparam_string(CONTEXT_STR,	Opt_context),
2892 	fsparam_string(DEFCONTEXT_STR,	Opt_defcontext),
2893 	fsparam_string(FSCONTEXT_STR,	Opt_fscontext),
2894 	fsparam_string(ROOTCONTEXT_STR,	Opt_rootcontext),
2895 	fsparam_flag  (SECLABEL_STR,	Opt_seclabel),
2896 	{}
2897 };
2898 
2899 static int selinux_fs_context_parse_param(struct fs_context *fc,
2900 					  struct fs_parameter *param)
2901 {
2902 	struct fs_parse_result result;
2903 	int opt;
2904 
2905 	opt = fs_parse(fc, selinux_fs_parameters, param, &result);
2906 	if (opt < 0)
2907 		return opt;
2908 
2909 	return selinux_add_opt(opt, param->string, &fc->security);
2910 }
2911 
2912 /* inode security operations */
2913 
2914 static int selinux_inode_alloc_security(struct inode *inode)
2915 {
2916 	struct inode_security_struct *isec = selinux_inode(inode);
2917 	u32 sid = current_sid();
2918 
2919 	spin_lock_init(&isec->lock);
2920 	INIT_LIST_HEAD(&isec->list);
2921 	isec->inode = inode;
2922 	isec->sid = SECINITSID_UNLABELED;
2923 	isec->sclass = SECCLASS_FILE;
2924 	isec->task_sid = sid;
2925 	isec->initialized = LABEL_INVALID;
2926 
2927 	return 0;
2928 }
2929 
2930 static void selinux_inode_free_security(struct inode *inode)
2931 {
2932 	inode_free_security(inode);
2933 }
2934 
2935 static int selinux_dentry_init_security(struct dentry *dentry, int mode,
2936 					const struct qstr *name,
2937 					const char **xattr_name,
2938 					struct lsm_context *cp)
2939 {
2940 	u32 newsid;
2941 	int rc;
2942 
2943 	rc = selinux_determine_inode_label(selinux_cred(current_cred()),
2944 					   d_inode(dentry->d_parent), name,
2945 					   inode_mode_to_security_class(mode),
2946 					   &newsid);
2947 	if (rc)
2948 		return rc;
2949 
2950 	if (xattr_name)
2951 		*xattr_name = XATTR_NAME_SELINUX;
2952 
2953 	cp->id = LSM_ID_SELINUX;
2954 	return security_sid_to_context(newsid, &cp->context, &cp->len);
2955 }
2956 
2957 static int selinux_dentry_create_files_as(struct dentry *dentry, int mode,
2958 					  const struct qstr *name,
2959 					  const struct cred *old,
2960 					  struct cred *new)
2961 {
2962 	u32 newsid;
2963 	int rc;
2964 	struct cred_security_struct *crsec;
2965 
2966 	rc = selinux_determine_inode_label(selinux_cred(old),
2967 					   d_inode(dentry->d_parent), name,
2968 					   inode_mode_to_security_class(mode),
2969 					   &newsid);
2970 	if (rc)
2971 		return rc;
2972 
2973 	crsec = selinux_cred(new);
2974 	crsec->create_sid = newsid;
2975 	return 0;
2976 }
2977 
2978 static int selinux_inode_init_security(struct inode *inode, struct inode *dir,
2979 				       const struct qstr *qstr,
2980 				       struct xattr *xattrs, int *xattr_count)
2981 {
2982 	const struct cred_security_struct *crsec = selinux_cred(current_cred());
2983 	struct superblock_security_struct *sbsec;
2984 	struct xattr *xattr;
2985 	u32 newsid, clen;
2986 	u16 newsclass;
2987 	int rc;
2988 	char *context;
2989 
2990 	sbsec = selinux_superblock(dir->i_sb);
2991 
2992 	if (!selinux_initialized() ||
2993 	    !(sbsec->flags & SBLABEL_MNT))
2994 		return -EOPNOTSUPP;
2995 
2996 	newsid = crsec->create_sid;
2997 	newsclass = inode_mode_to_security_class(inode->i_mode);
2998 	rc = selinux_determine_inode_label(crsec, dir, qstr, newsclass, &newsid);
2999 	if (rc)
3000 		return rc;
3001 
3002 	/* Possibly defer initialization to selinux_complete_init. */
3003 	if (sbsec->flags & SE_SBINITIALIZED) {
3004 		struct inode_security_struct *isec = selinux_inode(inode);
3005 		isec->sclass = newsclass;
3006 		isec->sid = newsid;
3007 		isec->initialized = LABEL_INITIALIZED;
3008 	}
3009 
3010 	xattr = lsm_get_xattr_slot(xattrs, xattr_count);
3011 	if (xattr) {
3012 		rc = security_sid_to_context_force(newsid,
3013 						   &context, &clen);
3014 		if (rc)
3015 			return rc;
3016 		xattr->value = context;
3017 		xattr->value_len = clen;
3018 		xattr->name = XATTR_SELINUX_SUFFIX;
3019 	}
3020 
3021 	return 0;
3022 }
3023 
3024 static int selinux_inode_init_security_anon(struct inode *inode,
3025 					    const struct qstr *name,
3026 					    const struct inode *context_inode)
3027 {
3028 	u32 sid = current_sid();
3029 	struct common_audit_data ad;
3030 	struct inode_security_struct *isec;
3031 	int rc;
3032 	bool is_memfd = false;
3033 
3034 	if (unlikely(!selinux_initialized()))
3035 		return 0;
3036 
3037 	if (name != NULL && name->name != NULL &&
3038 	    !strcmp(name->name, MEMFD_ANON_NAME)) {
3039 		if (!selinux_policycap_memfd_class())
3040 			return 0;
3041 		is_memfd = true;
3042 	}
3043 
3044 	isec = selinux_inode(inode);
3045 
3046 	/*
3047 	 * We only get here once per ephemeral inode.  The inode has
3048 	 * been initialized via inode_alloc_security but is otherwise
3049 	 * untouched.
3050 	 */
3051 
3052 	if (context_inode) {
3053 		struct inode_security_struct *context_isec =
3054 			selinux_inode(context_inode);
3055 		if (context_isec->initialized != LABEL_INITIALIZED) {
3056 			pr_err("SELinux:  context_inode is not initialized\n");
3057 			return -EACCES;
3058 		}
3059 
3060 		isec->sclass = context_isec->sclass;
3061 		isec->sid = context_isec->sid;
3062 	} else {
3063 		if (is_memfd)
3064 			isec->sclass = SECCLASS_MEMFD_FILE;
3065 		else
3066 			isec->sclass = SECCLASS_ANON_INODE;
3067 		rc = security_transition_sid(
3068 			sid, sid,
3069 			isec->sclass, name, &isec->sid);
3070 		if (rc)
3071 			return rc;
3072 	}
3073 
3074 	isec->initialized = LABEL_INITIALIZED;
3075 	/*
3076 	 * Now that we've initialized security, check whether we're
3077 	 * allowed to actually create this type of anonymous inode.
3078 	 */
3079 
3080 	ad.type = LSM_AUDIT_DATA_ANONINODE;
3081 	ad.u.anonclass = name ? (const char *)name->name : "?";
3082 
3083 	return avc_has_perm(sid,
3084 			    isec->sid,
3085 			    isec->sclass,
3086 			    FILE__CREATE,
3087 			    &ad);
3088 }
3089 
3090 static int selinux_inode_create(struct inode *dir, struct dentry *dentry, umode_t mode)
3091 {
3092 	return may_create(dir, dentry, SECCLASS_FILE);
3093 }
3094 
3095 static int selinux_inode_link(struct dentry *old_dentry, struct inode *dir, struct dentry *new_dentry)
3096 {
3097 	return may_link(dir, old_dentry, MAY_LINK);
3098 }
3099 
3100 static int selinux_inode_unlink(struct inode *dir, struct dentry *dentry)
3101 {
3102 	return may_link(dir, dentry, MAY_UNLINK);
3103 }
3104 
3105 static int selinux_inode_symlink(struct inode *dir, struct dentry *dentry, const char *name)
3106 {
3107 	return may_create(dir, dentry, SECCLASS_LNK_FILE);
3108 }
3109 
3110 static int selinux_inode_mkdir(struct inode *dir, struct dentry *dentry, umode_t mask)
3111 {
3112 	return may_create(dir, dentry, SECCLASS_DIR);
3113 }
3114 
3115 static int selinux_inode_rmdir(struct inode *dir, struct dentry *dentry)
3116 {
3117 	return may_link(dir, dentry, MAY_RMDIR);
3118 }
3119 
3120 static int selinux_inode_mknod(struct inode *dir, struct dentry *dentry, umode_t mode, dev_t dev)
3121 {
3122 	return may_create(dir, dentry, inode_mode_to_security_class(mode));
3123 }
3124 
3125 static int selinux_inode_rename(struct inode *old_inode, struct dentry *old_dentry,
3126 				struct inode *new_inode, struct dentry *new_dentry)
3127 {
3128 	return may_rename(old_inode, old_dentry, new_inode, new_dentry);
3129 }
3130 
3131 static int selinux_inode_readlink(struct dentry *dentry)
3132 {
3133 	const struct cred *cred = current_cred();
3134 
3135 	return dentry_has_perm(cred, dentry, FILE__READ);
3136 }
3137 
3138 static int selinux_inode_follow_link(struct dentry *dentry, struct inode *inode,
3139 				     bool rcu)
3140 {
3141 	struct common_audit_data ad;
3142 	struct inode_security_struct *isec;
3143 	u32 sid = current_sid();
3144 
3145 	ad.type = LSM_AUDIT_DATA_DENTRY;
3146 	ad.u.dentry = dentry;
3147 	isec = inode_security_rcu(inode, rcu);
3148 	if (IS_ERR(isec))
3149 		return PTR_ERR(isec);
3150 
3151 	return avc_has_perm(sid, isec->sid, isec->sclass, FILE__READ, &ad);
3152 }
3153 
3154 static noinline int audit_inode_permission(struct inode *inode,
3155 					   u32 perms, u32 audited, u32 denied,
3156 					   int result)
3157 {
3158 	struct common_audit_data ad;
3159 	struct inode_security_struct *isec = selinux_inode(inode);
3160 
3161 	ad.type = LSM_AUDIT_DATA_INODE;
3162 	ad.u.inode = inode;
3163 
3164 	return slow_avc_audit(current_sid(), isec->sid, isec->sclass, perms,
3165 			    audited, denied, result, &ad);
3166 }
3167 
3168 /**
3169  * task_avdcache_reset - Reset the task's AVD cache
3170  * @tsec: the task's security state
3171  *
3172  * Clear the task's AVD cache in @tsec and reset it to the current policy's
3173  * and task's info.
3174  */
3175 static inline void task_avdcache_reset(struct task_security_struct *tsec)
3176 {
3177 	memset(&tsec->avdcache.dir, 0, sizeof(tsec->avdcache.dir));
3178 	tsec->avdcache.sid = current_sid();
3179 	tsec->avdcache.seqno = avc_policy_seqno();
3180 	tsec->avdcache.dir_spot = TSEC_AVDC_DIR_SIZE - 1;
3181 }
3182 
3183 /**
3184  * task_avdcache_search - Search the task's AVD cache
3185  * @tsec: the task's security state
3186  * @isec: the inode to search for in the cache
3187  * @avdc: matching avd cache entry returned to the caller
3188  *
3189  * Search @tsec for a AVD cache entry that matches @isec and return it to the
3190  * caller via @avdc.  Returns 0 if a match is found, negative values otherwise.
3191  */
3192 static inline int task_avdcache_search(struct task_security_struct *tsec,
3193 				       struct inode_security_struct *isec,
3194 				       struct avdc_entry **avdc)
3195 {
3196 	int orig, iter;
3197 
3198 	/* focused on path walk optimization, only cache directories */
3199 	if (isec->sclass != SECCLASS_DIR)
3200 		return -ENOENT;
3201 
3202 	if (unlikely(current_sid() != tsec->avdcache.sid ||
3203 		     tsec->avdcache.seqno != avc_policy_seqno())) {
3204 		task_avdcache_reset(tsec);
3205 		return -ENOENT;
3206 	}
3207 
3208 	orig = iter = tsec->avdcache.dir_spot;
3209 	do {
3210 		if (tsec->avdcache.dir[iter].isid == isec->sid) {
3211 			/* cache hit */
3212 			tsec->avdcache.dir_spot = iter;
3213 			*avdc = &tsec->avdcache.dir[iter];
3214 			return 0;
3215 		}
3216 		iter = (iter - 1) & (TSEC_AVDC_DIR_SIZE - 1);
3217 	} while (iter != orig);
3218 
3219 	return -ENOENT;
3220 }
3221 
3222 /**
3223  * task_avdcache_update - Update the task's AVD cache
3224  * @tsec: the task's security state
3225  * @isec: the inode associated with the cache entry
3226  * @avd: the AVD to cache
3227  *
3228  * Update the AVD cache in @tsec with the @avd info associated
3229  * with @isec.
3230  */
3231 static inline void task_avdcache_update(struct task_security_struct *tsec,
3232 					struct inode_security_struct *isec,
3233 					struct av_decision *avd)
3234 {
3235 	int spot;
3236 
3237 	/* focused on path walk optimization, only cache directories */
3238 	if (isec->sclass != SECCLASS_DIR)
3239 		return;
3240 
3241 	/* update cache */
3242 	spot = (tsec->avdcache.dir_spot + 1) & (TSEC_AVDC_DIR_SIZE - 1);
3243 	tsec->avdcache.dir_spot = spot;
3244 	tsec->avdcache.dir[spot].isid = isec->sid;
3245 	tsec->avdcache.dir[spot].avd = *avd;
3246 	tsec->avdcache.permissive_neveraudit =
3247 		(avd->flags == (AVD_FLAGS_PERMISSIVE|AVD_FLAGS_NEVERAUDIT));
3248 }
3249 
3250 /**
3251  * selinux_inode_permission - Check if the current task can access an inode
3252  * @inode: the inode that is being accessed
3253  * @requested: the accesses being requested
3254  *
3255  * Check if the current task is allowed to access @inode according to
3256  * @requested.  Returns 0 if allowed, negative values otherwise.
3257  */
3258 static int selinux_inode_permission(struct inode *inode, int requested)
3259 {
3260 	int mask;
3261 	u32 perms;
3262 	u32 sid = current_sid();
3263 	struct task_security_struct *tsec;
3264 	struct inode_security_struct *isec;
3265 	struct avdc_entry *avdc;
3266 	struct av_decision avd, *avdp = &avd;
3267 	int rc, rc2;
3268 	u32 audited, denied;
3269 
3270 	mask = requested & (MAY_READ|MAY_WRITE|MAY_EXEC|MAY_APPEND);
3271 
3272 	/* No permission to check.  Existence test. */
3273 	if (!mask)
3274 		return 0;
3275 
3276 	tsec = selinux_task(current);
3277 	if (task_avdcache_permnoaudit(tsec, sid))
3278 		return 0;
3279 
3280 	isec = inode_security_rcu(inode, requested & MAY_NOT_BLOCK);
3281 	if (IS_ERR(isec))
3282 		return PTR_ERR(isec);
3283 	perms = file_mask_to_av(inode->i_mode, mask);
3284 
3285 	rc = task_avdcache_search(tsec, isec, &avdc);
3286 	if (likely(!rc)) {
3287 		/* Cache hit. */
3288 		avdp = &avdc->avd;
3289 		denied = perms & ~avdp->allowed;
3290 		if (unlikely(denied) && enforcing_enabled() &&
3291 			!(avdp->flags & AVD_FLAGS_PERMISSIVE))
3292 			rc = -EACCES;
3293 	} else {
3294 		/* Cache miss. */
3295 		rc = avc_has_perm_noaudit(sid, isec->sid, isec->sclass,
3296 					  perms, 0, avdp);
3297 		task_avdcache_update(tsec, isec, avdp);
3298 	}
3299 
3300 	audited = avc_audit_required(perms, avdp, rc,
3301 				     (requested & MAY_ACCESS) ?
3302 				     FILE__AUDIT_ACCESS : 0, &denied);
3303 	if (likely(!audited))
3304 		return rc;
3305 
3306 	rc2 = audit_inode_permission(inode, perms, audited, denied, rc);
3307 	if (rc2)
3308 		return rc2;
3309 
3310 	return rc;
3311 }
3312 
3313 static int selinux_inode_setattr(struct mnt_idmap *idmap, struct dentry *dentry,
3314 				 struct iattr *iattr)
3315 {
3316 	const struct cred *cred = current_cred();
3317 	struct inode *inode = d_backing_inode(dentry);
3318 	unsigned int ia_valid = iattr->ia_valid;
3319 	u32 av = FILE__WRITE;
3320 
3321 	/* ATTR_FORCE is just used for ATTR_KILL_S[UG]ID. */
3322 	if (ia_valid & ATTR_FORCE) {
3323 		ia_valid &= ~(ATTR_KILL_SUID | ATTR_KILL_SGID | ATTR_MODE |
3324 			      ATTR_FORCE);
3325 		if (!ia_valid)
3326 			return 0;
3327 	}
3328 
3329 	if (ia_valid & (ATTR_MODE | ATTR_UID | ATTR_GID |
3330 			ATTR_ATIME_SET | ATTR_MTIME_SET | ATTR_TIMES_SET))
3331 		return dentry_has_perm(cred, dentry, FILE__SETATTR);
3332 
3333 	if (selinux_policycap_openperm() &&
3334 	    inode->i_sb->s_magic != SOCKFS_MAGIC &&
3335 	    (ia_valid & ATTR_SIZE) &&
3336 	    !(ia_valid & ATTR_FILE))
3337 		av |= FILE__OPEN;
3338 
3339 	return dentry_has_perm(cred, dentry, av);
3340 }
3341 
3342 static int selinux_inode_getattr(const struct path *path)
3343 {
3344 	struct task_security_struct *tsec;
3345 
3346 	tsec = selinux_task(current);
3347 
3348 	if (task_avdcache_permnoaudit(tsec, current_sid()))
3349 		return 0;
3350 
3351 	return path_has_perm(current_cred(), path, FILE__GETATTR);
3352 }
3353 
3354 static bool has_cap_mac_admin(bool audit)
3355 {
3356 	const struct cred *cred = current_cred();
3357 	unsigned int opts = audit ? CAP_OPT_NONE : CAP_OPT_NOAUDIT;
3358 
3359 	if (cap_capable(cred, &init_user_ns, CAP_MAC_ADMIN, opts))
3360 		return false;
3361 	if (cred_has_capability(cred, CAP_MAC_ADMIN, opts, true))
3362 		return false;
3363 	return true;
3364 }
3365 
3366 /**
3367  * selinux_inode_xattr_skipcap - Skip the xattr capability checks?
3368  * @name: name of the xattr
3369  *
3370  * Returns 1 to indicate that SELinux "owns" the access control rights to xattrs
3371  * named @name; the LSM layer should avoid enforcing any traditional
3372  * capability based access controls on this xattr.  Returns 0 to indicate that
3373  * SELinux does not "own" the access control rights to xattrs named @name and is
3374  * deferring to the LSM layer for further access controls, including capability
3375  * based controls.
3376  */
3377 static int selinux_inode_xattr_skipcap(const char *name)
3378 {
3379 	/* require capability check if not a selinux xattr */
3380 	return !strcmp(name, XATTR_NAME_SELINUX);
3381 }
3382 
3383 static int selinux_inode_setxattr(struct mnt_idmap *idmap,
3384 				  struct dentry *dentry, const char *name,
3385 				  const void *value, size_t size, int flags)
3386 {
3387 	struct inode *inode = d_backing_inode(dentry);
3388 	struct inode_security_struct *isec;
3389 	struct superblock_security_struct *sbsec;
3390 	struct common_audit_data ad;
3391 	u32 newsid, sid = current_sid();
3392 	int rc = 0;
3393 
3394 	/* if not a selinux xattr, only check the ordinary setattr perm */
3395 	if (strcmp(name, XATTR_NAME_SELINUX))
3396 		return dentry_has_perm(current_cred(), dentry, FILE__SETATTR);
3397 
3398 	if (!selinux_initialized())
3399 		return (inode_owner_or_capable(idmap, inode) ? 0 : -EPERM);
3400 
3401 	sbsec = selinux_superblock(inode->i_sb);
3402 	if (!(sbsec->flags & SBLABEL_MNT))
3403 		return -EOPNOTSUPP;
3404 
3405 	if (!inode_owner_or_capable(idmap, inode))
3406 		return -EPERM;
3407 
3408 	ad.type = LSM_AUDIT_DATA_DENTRY;
3409 	ad.u.dentry = dentry;
3410 
3411 	isec = backing_inode_security(dentry);
3412 	rc = avc_has_perm(sid, isec->sid, isec->sclass,
3413 			  FILE__RELABELFROM, &ad);
3414 	if (rc)
3415 		return rc;
3416 
3417 	rc = security_context_to_sid(value, size, &newsid,
3418 				     GFP_KERNEL);
3419 	if (rc == -EINVAL) {
3420 		if (!has_cap_mac_admin(true)) {
3421 			struct audit_buffer *ab;
3422 			size_t audit_size;
3423 
3424 			/* We strip a nul only if it is at the end, otherwise the
3425 			 * context contains a nul and we should audit that */
3426 			if (value) {
3427 				const char *str = value;
3428 
3429 				if (str[size - 1] == '\0')
3430 					audit_size = size - 1;
3431 				else
3432 					audit_size = size;
3433 			} else {
3434 				audit_size = 0;
3435 			}
3436 			ab = audit_log_start(audit_context(),
3437 					     GFP_ATOMIC, AUDIT_SELINUX_ERR);
3438 			if (!ab)
3439 				return rc;
3440 			audit_log_format(ab, "op=setxattr invalid_context=");
3441 			audit_log_n_untrustedstring(ab, value, audit_size);
3442 			audit_log_end(ab);
3443 
3444 			return rc;
3445 		}
3446 		rc = security_context_to_sid_force(value,
3447 						   size, &newsid);
3448 	}
3449 	if (rc)
3450 		return rc;
3451 
3452 	rc = avc_has_perm(sid, newsid, isec->sclass,
3453 			  FILE__RELABELTO, &ad);
3454 	if (rc)
3455 		return rc;
3456 
3457 	rc = security_validate_transition(isec->sid, newsid,
3458 					  sid, isec->sclass);
3459 	if (rc)
3460 		return rc;
3461 
3462 	return avc_has_perm(newsid,
3463 			    sbsec->sid,
3464 			    SECCLASS_FILESYSTEM,
3465 			    FILESYSTEM__ASSOCIATE,
3466 			    &ad);
3467 }
3468 
3469 static int selinux_inode_set_acl(struct mnt_idmap *idmap,
3470 				 struct dentry *dentry, const char *acl_name,
3471 				 struct posix_acl *kacl)
3472 {
3473 	return dentry_has_perm(current_cred(), dentry, FILE__SETATTR);
3474 }
3475 
3476 static int selinux_inode_get_acl(struct mnt_idmap *idmap,
3477 				 struct dentry *dentry, const char *acl_name)
3478 {
3479 	return dentry_has_perm(current_cred(), dentry, FILE__GETATTR);
3480 }
3481 
3482 static int selinux_inode_remove_acl(struct mnt_idmap *idmap,
3483 				    struct dentry *dentry, const char *acl_name)
3484 {
3485 	return dentry_has_perm(current_cred(), dentry, FILE__SETATTR);
3486 }
3487 
3488 static void selinux_inode_post_setxattr(struct dentry *dentry, const char *name,
3489 					const void *value, size_t size,
3490 					int flags)
3491 {
3492 	struct inode *inode = d_backing_inode(dentry);
3493 	struct inode_security_struct *isec;
3494 	u32 newsid;
3495 	int rc;
3496 
3497 	if (strcmp(name, XATTR_NAME_SELINUX)) {
3498 		/* Not an attribute we recognize, so nothing to do. */
3499 		return;
3500 	}
3501 
3502 	if (!selinux_initialized()) {
3503 		/* If we haven't even been initialized, then we can't validate
3504 		 * against a policy, so leave the label as invalid. It may
3505 		 * resolve to a valid label on the next revalidation try if
3506 		 * we've since initialized.
3507 		 */
3508 		return;
3509 	}
3510 
3511 	rc = security_context_to_sid_force(value, size,
3512 					   &newsid);
3513 	if (rc) {
3514 		pr_err("SELinux:  unable to map context to SID"
3515 		       "for (%s, %llu), rc=%d\n",
3516 		       inode->i_sb->s_id, inode->i_ino, -rc);
3517 		return;
3518 	}
3519 
3520 	isec = backing_inode_security(dentry);
3521 	spin_lock(&isec->lock);
3522 	isec->sclass = inode_mode_to_security_class(inode->i_mode);
3523 	isec->sid = newsid;
3524 	isec->initialized = LABEL_INITIALIZED;
3525 	spin_unlock(&isec->lock);
3526 }
3527 
3528 static int selinux_inode_getxattr(struct dentry *dentry, const char *name)
3529 {
3530 	const struct cred *cred = current_cred();
3531 
3532 	return dentry_has_perm(cred, dentry, FILE__GETATTR);
3533 }
3534 
3535 static int selinux_inode_listxattr(struct dentry *dentry)
3536 {
3537 	const struct cred *cred = current_cred();
3538 
3539 	return dentry_has_perm(cred, dentry, FILE__GETATTR);
3540 }
3541 
3542 static int selinux_inode_removexattr(struct mnt_idmap *idmap,
3543 				     struct dentry *dentry, const char *name)
3544 {
3545 	/* if not a selinux xattr, only check the ordinary setattr perm */
3546 	if (strcmp(name, XATTR_NAME_SELINUX))
3547 		return dentry_has_perm(current_cred(), dentry, FILE__SETATTR);
3548 
3549 	if (!selinux_initialized())
3550 		return 0;
3551 
3552 	/* No one is allowed to remove a SELinux security label.
3553 	   You can change the label, but all data must be labeled. */
3554 	return -EACCES;
3555 }
3556 
3557 static int selinux_inode_file_setattr(struct dentry *dentry,
3558 				      struct file_kattr *fa)
3559 {
3560 	return dentry_has_perm(current_cred(), dentry, FILE__SETATTR);
3561 }
3562 
3563 static int selinux_inode_file_getattr(struct dentry *dentry,
3564 				      struct file_kattr *fa)
3565 {
3566 	return dentry_has_perm(current_cred(), dentry, FILE__GETATTR);
3567 }
3568 
3569 static int selinux_path_notify(const struct path *path, u64 mask,
3570 						unsigned int obj_type)
3571 {
3572 	int ret;
3573 	u32 perm;
3574 
3575 	struct common_audit_data ad;
3576 
3577 	ad.type = LSM_AUDIT_DATA_PATH;
3578 	ad.u.path = *path;
3579 
3580 	/*
3581 	 * Set permission needed based on the type of mark being set.
3582 	 * Performs an additional check for sb watches.
3583 	 */
3584 	switch (obj_type) {
3585 	case FSNOTIFY_OBJ_TYPE_VFSMOUNT:
3586 		perm = FILE__WATCH_MOUNT;
3587 		break;
3588 	case FSNOTIFY_OBJ_TYPE_SB:
3589 		perm = FILE__WATCH_SB;
3590 		ret = superblock_has_perm(current_cred(), path->dentry->d_sb,
3591 						FILESYSTEM__WATCH, &ad);
3592 		if (ret)
3593 			return ret;
3594 		break;
3595 	case FSNOTIFY_OBJ_TYPE_INODE:
3596 		perm = FILE__WATCH;
3597 		break;
3598 	case FSNOTIFY_OBJ_TYPE_MNTNS:
3599 		perm = FILE__WATCH_MOUNTNS;
3600 		break;
3601 	default:
3602 		return -EINVAL;
3603 	}
3604 
3605 	/* blocking watches require the file:watch_with_perm permission */
3606 	if (mask & (ALL_FSNOTIFY_PERM_EVENTS))
3607 		perm |= FILE__WATCH_WITH_PERM;
3608 
3609 	/* watches on read-like events need the file:watch_reads permission */
3610 	if (mask & (FS_ACCESS | FS_ACCESS_PERM | FS_PRE_ACCESS |
3611 		    FS_CLOSE_NOWRITE))
3612 		perm |= FILE__WATCH_READS;
3613 
3614 	return path_has_perm(current_cred(), path, perm);
3615 }
3616 
3617 /*
3618  * Copy the inode security context value to the user.
3619  *
3620  * Permission check is handled by selinux_inode_getxattr hook.
3621  */
3622 static int selinux_inode_getsecurity(struct mnt_idmap *idmap,
3623 				     struct inode *inode, const char *name,
3624 				     void **buffer, bool alloc)
3625 {
3626 	u32 size;
3627 	int error;
3628 	char *context = NULL;
3629 	struct inode_security_struct *isec;
3630 
3631 	/*
3632 	 * If we're not initialized yet, then we can't validate contexts, so
3633 	 * just let vfs_getxattr fall back to using the on-disk xattr.
3634 	 */
3635 	if (!selinux_initialized() ||
3636 	    strcmp(name, XATTR_SELINUX_SUFFIX))
3637 		return -EOPNOTSUPP;
3638 
3639 	/*
3640 	 * If the caller has CAP_MAC_ADMIN, then get the raw context
3641 	 * value even if it is not defined by current policy; otherwise,
3642 	 * use the in-core value under current policy.
3643 	 * Use the non-auditing forms of the permission checks since
3644 	 * getxattr may be called by unprivileged processes commonly
3645 	 * and lack of permission just means that we fall back to the
3646 	 * in-core context value, not a denial.
3647 	 */
3648 	isec = inode_security(inode);
3649 	if (has_cap_mac_admin(false))
3650 		error = security_sid_to_context_force(isec->sid, &context,
3651 						      &size);
3652 	else
3653 		error = security_sid_to_context(isec->sid,
3654 						&context, &size);
3655 	if (error)
3656 		return error;
3657 	error = size;
3658 	if (alloc) {
3659 		*buffer = context;
3660 		goto out_nofree;
3661 	}
3662 	kfree(context);
3663 out_nofree:
3664 	return error;
3665 }
3666 
3667 static int selinux_inode_setsecurity(struct inode *inode, const char *name,
3668 				     const void *value, size_t size, int flags)
3669 {
3670 	struct inode_security_struct *isec = inode_security_novalidate(inode);
3671 	struct superblock_security_struct *sbsec;
3672 	u32 newsid;
3673 	int rc;
3674 
3675 	if (strcmp(name, XATTR_SELINUX_SUFFIX))
3676 		return -EOPNOTSUPP;
3677 
3678 	sbsec = selinux_superblock(inode->i_sb);
3679 	if (!(sbsec->flags & SBLABEL_MNT))
3680 		return -EOPNOTSUPP;
3681 
3682 	if (!value || !size)
3683 		return -EACCES;
3684 
3685 	rc = security_context_to_sid(value, size, &newsid,
3686 				     GFP_KERNEL);
3687 	if (rc)
3688 		return rc;
3689 
3690 	spin_lock(&isec->lock);
3691 	isec->sclass = inode_mode_to_security_class(inode->i_mode);
3692 	isec->sid = newsid;
3693 	isec->initialized = LABEL_INITIALIZED;
3694 	spin_unlock(&isec->lock);
3695 	return 0;
3696 }
3697 
3698 static int selinux_inode_listsecurity(struct inode *inode, char **buffer,
3699 				ssize_t *remaining_size)
3700 {
3701 	if (!selinux_initialized())
3702 		return 0;
3703 	return xattr_list_one(buffer, remaining_size, XATTR_NAME_SELINUX);
3704 }
3705 
3706 static void selinux_inode_getlsmprop(struct inode *inode, struct lsm_prop *prop)
3707 {
3708 	struct inode_security_struct *isec = inode_security_novalidate(inode);
3709 
3710 	prop->selinux.secid = isec->sid;
3711 }
3712 
3713 static int selinux_inode_copy_up(struct dentry *src, struct cred **new)
3714 {
3715 	struct lsm_prop prop;
3716 	struct cred_security_struct *crsec;
3717 	struct cred *new_creds = *new;
3718 
3719 	if (new_creds == NULL) {
3720 		new_creds = prepare_creds();
3721 		if (!new_creds)
3722 			return -ENOMEM;
3723 	}
3724 
3725 	crsec = selinux_cred(new_creds);
3726 	/* Get label from overlay inode and set it in create_sid */
3727 	selinux_inode_getlsmprop(d_inode(src), &prop);
3728 	crsec->create_sid = prop.selinux.secid;
3729 	*new = new_creds;
3730 	return 0;
3731 }
3732 
3733 static int selinux_inode_copy_up_xattr(struct dentry *dentry, const char *name)
3734 {
3735 	/* The copy_up hook above sets the initial context on an inode, but we
3736 	 * don't then want to overwrite it by blindly copying all the lower
3737 	 * xattrs up.  Instead, filter out SELinux-related xattrs following
3738 	 * policy load.
3739 	 */
3740 	if (selinux_initialized() && !strcmp(name, XATTR_NAME_SELINUX))
3741 		return -ECANCELED; /* Discard */
3742 	/*
3743 	 * Any other attribute apart from SELINUX is not claimed, supported
3744 	 * by selinux.
3745 	 */
3746 	return -EOPNOTSUPP;
3747 }
3748 
3749 /* kernfs node operations */
3750 
3751 static int selinux_kernfs_init_security(struct kernfs_node *kn_dir,
3752 					struct kernfs_node *kn)
3753 {
3754 	const struct cred_security_struct *crsec = selinux_cred(current_cred());
3755 	u32 parent_sid, newsid, clen;
3756 	int rc;
3757 	char *context;
3758 
3759 	rc = kernfs_xattr_get(kn_dir, XATTR_NAME_SELINUX, NULL, 0);
3760 	if (rc == -ENODATA)
3761 		return 0;
3762 	else if (rc < 0)
3763 		return rc;
3764 
3765 	clen = (u32)rc;
3766 	context = kmalloc(clen, GFP_KERNEL);
3767 	if (!context)
3768 		return -ENOMEM;
3769 
3770 	rc = kernfs_xattr_get(kn_dir, XATTR_NAME_SELINUX, context, clen);
3771 	if (rc < 0) {
3772 		kfree(context);
3773 		return rc;
3774 	}
3775 
3776 	rc = security_context_to_sid(context, clen, &parent_sid,
3777 				     GFP_KERNEL);
3778 	kfree(context);
3779 	if (rc)
3780 		return rc;
3781 
3782 	if (crsec->create_sid) {
3783 		newsid = crsec->create_sid;
3784 	} else {
3785 		u16 secclass = inode_mode_to_security_class(kn->mode);
3786 		const char *kn_name;
3787 		struct qstr q;
3788 
3789 		/* kn is fresh, can't be renamed, name goes not away */
3790 		kn_name = rcu_dereference_check(kn->name, true);
3791 		q.name = kn_name;
3792 		q.hash_len = hashlen_string(kn_dir, kn_name);
3793 
3794 		rc = security_transition_sid(crsec->sid,
3795 					     parent_sid, secclass, &q,
3796 					     &newsid);
3797 		if (rc)
3798 			return rc;
3799 	}
3800 
3801 	rc = security_sid_to_context_force(newsid,
3802 					   &context, &clen);
3803 	if (rc)
3804 		return rc;
3805 
3806 	rc = kernfs_xattr_set(kn, XATTR_NAME_SELINUX, context, clen,
3807 			      XATTR_CREATE);
3808 	kfree(context);
3809 	return rc;
3810 }
3811 
3812 
3813 /* file security operations */
3814 
3815 static int selinux_revalidate_file_permission(struct file *file, int mask)
3816 {
3817 	const struct cred *cred = current_cred();
3818 	struct inode *inode = file_inode(file);
3819 
3820 	/* file_mask_to_av won't add FILE__WRITE if MAY_APPEND is set */
3821 	if ((file->f_flags & O_APPEND) && (mask & MAY_WRITE))
3822 		mask |= MAY_APPEND;
3823 
3824 	return file_has_perm(cred, file,
3825 			     file_mask_to_av(inode->i_mode, mask));
3826 }
3827 
3828 static int selinux_file_permission(struct file *file, int mask)
3829 {
3830 	struct inode *inode = file_inode(file);
3831 	struct file_security_struct *fsec = selinux_file(file);
3832 	struct inode_security_struct *isec;
3833 	u32 sid = current_sid();
3834 
3835 	if (!mask)
3836 		/* No permission to check.  Existence test. */
3837 		return 0;
3838 
3839 	isec = inode_security(inode);
3840 	if (sid == fsec->sid && fsec->isid == isec->sid &&
3841 	    fsec->pseqno == avc_policy_seqno())
3842 		/* No change since file_open check. */
3843 		return 0;
3844 
3845 	return selinux_revalidate_file_permission(file, mask);
3846 }
3847 
3848 static int selinux_file_alloc_security(struct file *file)
3849 {
3850 	struct file_security_struct *fsec = selinux_file(file);
3851 	u32 sid = current_sid();
3852 
3853 	fsec->sid = sid;
3854 	fsec->fown_sid = sid;
3855 
3856 	return 0;
3857 }
3858 
3859 static inline u32 selinux_file_user_sid(const struct file *file)
3860 {
3861 	if (unlikely(file->f_mode & FMODE_BACKING))
3862 		return selinux_backing_file(file)->uf_sid;
3863 	return selinux_file(file)->sid;
3864 }
3865 
3866 static int selinux_backing_file_alloc(struct file *backing_file,
3867 				      const struct file *user_file)
3868 {
3869 	struct backing_file_security_struct *bfsec;
3870 	const struct backing_file_security_struct *ubfsec;
3871 	struct backing_file_security_layer *layer;
3872 	u32 i;
3873 
3874 	bfsec = selinux_backing_file(backing_file);
3875 	bfsec->uf_sid = selinux_file_user_sid(user_file);
3876 	if (!(user_file->f_mode & FMODE_BACKING))
3877 		return 0;
3878 
3879 	ubfsec = selinux_backing_file(user_file);
3880 	/* a wrapped count would make kmalloc_array() return ZERO_SIZE_PTR */
3881 	if (unlikely(ubfsec->layer_count == U32_MAX))
3882 		return -EOVERFLOW;
3883 
3884 	/*
3885 	 * The final VMA only retains the lowest backing file, so record the
3886 	 * whole chain here rather than in the mmap hook, where concurrent
3887 	 * mappings would have to be serialized.  Size it dynamically: erofs
3888 	 * inode sharing adds a backing file without bumping s_stack_depth.
3889 	 */
3890 	bfsec->layers = kmalloc_array(ubfsec->layer_count + 1,
3891 				      sizeof(*bfsec->layers), GFP_KERNEL);
3892 	if (!bfsec->layers)
3893 		return -ENOMEM;
3894 
3895 	for (i = 0; i < ubfsec->layer_count; i++) {
3896 		layer = &bfsec->layers[i];
3897 		*layer = ubfsec->layers[i];
3898 		path_get(&layer->path);
3899 	}
3900 
3901 	/* f_path, not file_user_path(): this layer, not the top-level file */
3902 	layer = &bfsec->layers[i];
3903 	layer->path = user_file->f_path;
3904 	layer->mounter_sid = cred_sid(user_file->f_cred);
3905 	layer->fd_sid = selinux_file(user_file)->sid;
3906 	path_get(&layer->path);
3907 	bfsec->layer_count = ubfsec->layer_count + 1;
3908 
3909 	return 0;
3910 }
3911 
3912 static void selinux_backing_file_free(struct file *backing_file)
3913 {
3914 	struct backing_file_security_struct *bfsec;
3915 
3916 	/* security_backing_file_free() may be called twice after an error */
3917 	if (!backing_file_security(backing_file))
3918 		return;
3919 
3920 	bfsec = selinux_backing_file(backing_file);
3921 	while (bfsec->layer_count)
3922 		path_put(&bfsec->layers[--bfsec->layer_count].path);
3923 	kfree(bfsec->layers);
3924 	bfsec->layers = NULL;
3925 }
3926 
3927 /*
3928  * Check whether a task has the ioctl permission and cmd
3929  * operation to an inode.
3930  */
3931 static int ioctl_has_perm(const struct cred *cred, struct file *file,
3932 		u32 requested, u16 cmd)
3933 {
3934 	struct common_audit_data ad;
3935 	struct file_security_struct *fsec = selinux_file(file);
3936 	struct inode *inode = file_inode(file);
3937 	struct inode_security_struct *isec;
3938 	struct lsm_ioctlop_audit ioctl;
3939 	u32 ssid = cred_sid(cred);
3940 	int rc;
3941 	u8 driver = cmd >> 8;
3942 	u8 xperm = cmd & 0xff;
3943 
3944 	ad.type = LSM_AUDIT_DATA_IOCTL_OP;
3945 	ad.u.op = &ioctl;
3946 	ad.u.op->cmd = cmd;
3947 	ad.u.op->path = file->f_path;
3948 
3949 	if (ssid != fsec->sid) {
3950 		rc = avc_has_perm(ssid, fsec->sid,
3951 				SECCLASS_FD,
3952 				FD__USE,
3953 				&ad);
3954 		if (rc)
3955 			goto out;
3956 	}
3957 
3958 	if (unlikely(IS_PRIVATE(inode)))
3959 		return 0;
3960 
3961 	isec = inode_security(inode);
3962 	rc = avc_has_extended_perms(ssid, isec->sid, isec->sclass, requested,
3963 				    driver, AVC_EXT_IOCTL, xperm, &ad);
3964 out:
3965 	return rc;
3966 }
3967 
3968 static int selinux_file_ioctl(struct file *file, unsigned int cmd,
3969 			      unsigned long arg)
3970 {
3971 	const struct cred *cred = current_cred();
3972 	int error = 0;
3973 
3974 	switch (cmd) {
3975 	case FIONREAD:
3976 	case FIBMAP:
3977 	case FIGETBSZ:
3978 	case FS_IOC_GETFLAGS:
3979 	case FS_IOC_GETVERSION:
3980 		error = file_has_perm(cred, file, FILE__GETATTR);
3981 		break;
3982 
3983 	case FS_IOC_SETFLAGS:
3984 	case FS_IOC_SETVERSION:
3985 		error = file_has_perm(cred, file, FILE__SETATTR);
3986 		break;
3987 
3988 	/* sys_ioctl() checks */
3989 	case FIONBIO:
3990 	case FIOASYNC:
3991 		error = file_has_perm(cred, file, 0);
3992 		break;
3993 
3994 	case KDSKBENT:
3995 	case KDSKBSENT:
3996 		error = cred_has_capability(cred, CAP_SYS_TTY_CONFIG,
3997 					    CAP_OPT_NONE, true);
3998 		break;
3999 
4000 	case FIOCLEX:
4001 	case FIONCLEX:
4002 		if (!selinux_policycap_ioctl_skip_cloexec())
4003 			error = ioctl_has_perm(cred, file, FILE__IOCTL, (u16) cmd);
4004 		break;
4005 
4006 	/* default case assumes that the command will go
4007 	 * to the file's ioctl() function.
4008 	 */
4009 	default:
4010 		error = ioctl_has_perm(cred, file, FILE__IOCTL, (u16) cmd);
4011 	}
4012 	return error;
4013 }
4014 
4015 static int selinux_file_ioctl_compat(struct file *file, unsigned int cmd,
4016 			      unsigned long arg)
4017 {
4018 	/*
4019 	 * If we are in a 64-bit kernel running 32-bit userspace, we need to
4020 	 * make sure we don't compare 32-bit flags to 64-bit flags.
4021 	 */
4022 	switch (cmd) {
4023 	case FS_IOC32_GETFLAGS:
4024 		cmd = FS_IOC_GETFLAGS;
4025 		break;
4026 	case FS_IOC32_SETFLAGS:
4027 		cmd = FS_IOC_SETFLAGS;
4028 		break;
4029 	case FS_IOC32_GETVERSION:
4030 		cmd = FS_IOC_GETVERSION;
4031 		break;
4032 	case FS_IOC32_SETVERSION:
4033 		cmd = FS_IOC_SETVERSION;
4034 		break;
4035 	default:
4036 		break;
4037 	}
4038 
4039 	return selinux_file_ioctl(file, cmd, arg);
4040 }
4041 
4042 static int default_noexec __ro_after_init;
4043 
4044 static u32 file_map_prot_to_av(unsigned long prot, bool shared)
4045 {
4046 	u32 av = FILE__READ;
4047 
4048 	if (shared && (prot & PROT_WRITE))
4049 		av |= FILE__WRITE;
4050 	if (prot & PROT_EXEC)
4051 		av |= FILE__EXECUTE;
4052 
4053 	return av;
4054 }
4055 
4056 static int backing_mounters_has_perm(const struct file *file, u32 av)
4057 {
4058 	const struct backing_file_security_struct *bfsec;
4059 	const struct backing_file_security_layer *layer;
4060 	struct common_audit_data ad;
4061 	struct inode *inode;
4062 	u32 i;
4063 	int rc;
4064 
4065 	if (WARN_ON_ONCE(!(file->f_mode & FMODE_BACKING)))
4066 		return -EIO;
4067 
4068 	bfsec = selinux_backing_file(file);
4069 	for (i = 0; i < bfsec->layer_count; i++) {
4070 		layer = &bfsec->layers[i];
4071 		inode = d_inode(layer->path.dentry);
4072 
4073 		ad.type = LSM_AUDIT_DATA_PATH;
4074 		ad.u.path = layer->path;
4075 
4076 		if (layer->mounter_sid != layer->fd_sid) {
4077 			rc = avc_has_perm(layer->mounter_sid, layer->fd_sid,
4078 					  SECCLASS_FD, FD__USE, &ad);
4079 			if (rc)
4080 				return rc;
4081 		}
4082 
4083 		rc = inode_sid_has_perm(layer->mounter_sid, inode, av, &ad);
4084 		if (rc)
4085 			return rc;
4086 	}
4087 
4088 	return 0;
4089 }
4090 
4091 static int __file_map_prot_check(const struct file *file, unsigned long prot,
4092 				 bool shared, bool mounter_check,
4093 				 bool bf_user_file)
4094 {
4095 	struct inode *inode = NULL;
4096 	bool prot_exec = prot & PROT_EXEC;
4097 	bool prot_write = prot & PROT_WRITE;
4098 
4099 	if (file) {
4100 		if (bf_user_file)
4101 			inode = d_inode(backing_file_user_path(file)->dentry);
4102 		else
4103 			inode = file_inode(file);
4104 	}
4105 
4106 	if (!mounter_check && default_noexec && prot_exec &&
4107 	    (!file || IS_PRIVATE(inode) || (!shared && prot_write))) {
4108 		int rc;
4109 		u32 sid = current_sid();
4110 
4111 		/*
4112 		 * We are making executable an anonymous mapping or a private
4113 		 * file mapping that will also be writable.
4114 		 */
4115 		rc = avc_has_perm(sid, sid, SECCLASS_PROCESS, PROCESS__EXECMEM,
4116 				  NULL);
4117 		if (rc)
4118 			return rc;
4119 	}
4120 
4121 	if (file) {
4122 		const struct cred *cred = mounter_check ?
4123 				file->f_cred : current_cred();
4124 
4125 		return __file_has_perm(cred, file,
4126 				       file_map_prot_to_av(prot, shared),
4127 				       bf_user_file);
4128 	}
4129 
4130 	return 0;
4131 }
4132 
4133 static inline int file_map_prot_check(const struct file *file,
4134 				      unsigned long prot, bool shared,
4135 				      bool mounter_check)
4136 {
4137 	return __file_map_prot_check(file, prot, shared, mounter_check, false);
4138 }
4139 
4140 static int selinux_mmap_addr(unsigned long addr)
4141 {
4142 	int rc = 0;
4143 
4144 	if (addr < CONFIG_LSM_MMAP_MIN_ADDR) {
4145 		u32 sid = current_sid();
4146 		rc = avc_has_perm(sid, sid, SECCLASS_MEMPROTECT,
4147 				  MEMPROTECT__MMAP_ZERO, NULL);
4148 	}
4149 
4150 	return rc;
4151 }
4152 
4153 static int selinux_mmap_file_common(struct file *file, unsigned long prot,
4154 				    bool shared, bool mounter_check)
4155 {
4156 	if (file) {
4157 		int rc;
4158 		struct common_audit_data ad;
4159 		const struct cred *cred = mounter_check ?
4160 				file->f_cred : current_cred();
4161 
4162 		ad.type = LSM_AUDIT_DATA_FILE;
4163 		ad.u.file = file;
4164 		rc = inode_has_perm(cred, file_inode(file), FILE__MAP, &ad);
4165 		if (rc)
4166 			return rc;
4167 	}
4168 
4169 	return file_map_prot_check(file, prot, shared, mounter_check);
4170 }
4171 
4172 static int selinux_mmap_file(struct file *file,
4173 			     unsigned long reqprot __always_unused,
4174 			     unsigned long prot, unsigned long flags)
4175 {
4176 	return selinux_mmap_file_common(file, prot,
4177 					(flags & MAP_TYPE) == MAP_SHARED,
4178 					false);
4179 }
4180 
4181 /**
4182  * selinux_mmap_backing_file - Check mmap permissions on a backing file
4183  * @vma: memory region
4184  * @backing_file: stacked filesystem backing file
4185  * @user_file: user visible file
4186  *
4187  * This is called after selinux_mmap_file() on stacked filesystems, and it
4188  * is this function's responsibility to verify access to @backing_file and
4189  * setup the SELinux state for possible later use in the mprotect() code path.
4190  *
4191  * By the time this function is called, mmap() access to @user_file has already
4192  * been authorized and @vma->vm_file has been set to point to @backing_file.
4193  *
4194  * Return zero on success, negative values otherwise.
4195  */
4196 static int selinux_mmap_backing_file(struct vm_area_struct *vma,
4197 				     struct file *backing_file,
4198 				     struct file *user_file __always_unused)
4199 {
4200 	unsigned long prot = 0;
4201 
4202 	/* translate vma->vm_flags perms into PROT perms */
4203 	if (vma->vm_flags & VM_READ)
4204 		prot |= PROT_READ;
4205 	if (vma->vm_flags & VM_WRITE)
4206 		prot |= PROT_WRITE;
4207 	if (vma->vm_flags & VM_EXEC)
4208 		prot |= PROT_EXEC;
4209 
4210 	return selinux_mmap_file_common(backing_file, prot,
4211 					vma->vm_flags & VM_SHARED,
4212 					true);
4213 }
4214 
4215 static int selinux_file_mprotect(struct vm_area_struct *vma,
4216 				 unsigned long reqprot __always_unused,
4217 				 unsigned long prot)
4218 {
4219 	int rc;
4220 	const struct cred *cred = current_cred();
4221 	u32 sid = cred_sid(cred);
4222 	u32 av;
4223 	const struct file *file = vma->vm_file;
4224 	bool backing_file;
4225 	bool shared = vma->vm_flags & VM_SHARED;
4226 
4227 	/* check if we need to trigger the "backing files are awful" mode */
4228 	backing_file = file && (file->f_mode & FMODE_BACKING);
4229 
4230 	if (default_noexec &&
4231 	    (prot & PROT_EXEC) && !(vma->vm_flags & VM_EXEC)) {
4232 		/*
4233 		 * We don't use the vma_is_initial_heap() helper as it has
4234 		 * a history of problems and is currently broken on systems
4235 		 * where there is no heap, e.g. brk == start_brk.  Before
4236 		 * replacing the conditional below with vma_is_initial_heap(),
4237 		 * or something similar, please ensure that the logic is the
4238 		 * same as what we have below or you have tested every possible
4239 		 * corner case you can think to test.
4240 		 */
4241 		if (vma->vm_start >= vma->vm_mm->start_brk &&
4242 		    vma->vm_end <= vma->vm_mm->brk) {
4243 			rc = avc_has_perm(sid, sid, SECCLASS_PROCESS,
4244 					  PROCESS__EXECHEAP, NULL);
4245 			if (rc)
4246 				return rc;
4247 		} else if (!file && (vma_is_initial_stack(vma) ||
4248 			    vma_is_stack_for_current(vma))) {
4249 			rc = avc_has_perm(sid, sid, SECCLASS_PROCESS,
4250 					  PROCESS__EXECSTACK, NULL);
4251 			if (rc)
4252 				return rc;
4253 		} else if (file && vma->anon_vma) {
4254 			/*
4255 			 * We are making executable a file mapping that has
4256 			 * had some COW done. Since pages might have been
4257 			 * written, check ability to execute the possibly
4258 			 * modified content.  This typically should only
4259 			 * occur for text relocations.
4260 			 */
4261 			rc = __file_has_perm(cred, file, FILE__EXECMOD,
4262 					     backing_file);
4263 			if (rc)
4264 				return rc;
4265 			if (backing_file) {
4266 				rc = backing_mounters_has_perm(file,
4267 							       FILE__EXECMOD);
4268 				if (rc)
4269 					return rc;
4270 				rc = file_has_perm(file->f_cred, file,
4271 						   FILE__EXECMOD);
4272 				if (rc)
4273 					return rc;
4274 			}
4275 		}
4276 	}
4277 
4278 	rc = __file_map_prot_check(file, prot, shared, false, backing_file);
4279 	if (rc)
4280 		return rc;
4281 	if (backing_file) {
4282 		av = file_map_prot_to_av(prot, shared);
4283 		rc = backing_mounters_has_perm(file, av);
4284 		if (rc)
4285 			return rc;
4286 		rc = file_map_prot_check(file, prot, shared, true);
4287 		if (rc)
4288 			return rc;
4289 	}
4290 
4291 	return 0;
4292 }
4293 
4294 static int selinux_file_lock(struct file *file, unsigned int cmd)
4295 {
4296 	const struct cred *cred = current_cred();
4297 
4298 	return file_has_perm(cred, file, FILE__LOCK);
4299 }
4300 
4301 static int selinux_file_fcntl(struct file *file, unsigned int cmd,
4302 			      unsigned long arg)
4303 {
4304 	const struct cred *cred = current_cred();
4305 	int err = 0;
4306 
4307 	switch (cmd) {
4308 	case F_SETFL:
4309 		if ((file->f_flags & O_APPEND) && !(arg & O_APPEND)) {
4310 			err = file_has_perm(cred, file, FILE__WRITE);
4311 			break;
4312 		}
4313 		fallthrough;
4314 	case F_SETOWN:
4315 	case F_SETSIG:
4316 	case F_GETFL:
4317 	case F_GETOWN:
4318 	case F_GETSIG:
4319 	case F_GETOWNER_UIDS:
4320 		/* Just check FD__USE permission */
4321 		err = file_has_perm(cred, file, 0);
4322 		break;
4323 	case F_GETLK:
4324 	case F_SETLK:
4325 	case F_SETLKW:
4326 	case F_OFD_GETLK:
4327 	case F_OFD_SETLK:
4328 	case F_OFD_SETLKW:
4329 #if BITS_PER_LONG == 32
4330 	case F_GETLK64:
4331 	case F_SETLK64:
4332 	case F_SETLKW64:
4333 #endif
4334 		err = file_has_perm(cred, file, FILE__LOCK);
4335 		break;
4336 	}
4337 
4338 	return err;
4339 }
4340 
4341 static void selinux_file_set_fowner(struct file *file)
4342 {
4343 	struct file_security_struct *fsec;
4344 
4345 	fsec = selinux_file(file);
4346 	fsec->fown_sid = current_sid();
4347 }
4348 
4349 static int selinux_file_send_sigiotask(struct task_struct *tsk,
4350 				       struct fown_struct *fown, int signum)
4351 {
4352 	struct file *file;
4353 	u32 sid = task_sid_obj(tsk);
4354 	u32 perm;
4355 	struct file_security_struct *fsec;
4356 
4357 	/* struct fown_struct is never outside the context of a struct file */
4358 	file = fown->file;
4359 
4360 	fsec = selinux_file(file);
4361 
4362 	if (!signum)
4363 		perm = signal_to_av(SIGIO); /* as per send_sigio_to_task */
4364 	else
4365 		perm = signal_to_av(signum);
4366 
4367 	return avc_has_perm(fsec->fown_sid, sid,
4368 			    SECCLASS_PROCESS, perm, NULL);
4369 }
4370 
4371 static int selinux_file_receive(struct file *file)
4372 {
4373 	const struct cred *cred = current_cred();
4374 
4375 	return file_has_perm(cred, file, file_to_av(file));
4376 }
4377 
4378 static int selinux_file_open(struct file *file)
4379 {
4380 	struct file_security_struct *fsec;
4381 	struct inode_security_struct *isec;
4382 
4383 	fsec = selinux_file(file);
4384 	isec = inode_security(file_inode(file));
4385 	/*
4386 	 * Save inode label and policy sequence number
4387 	 * at open-time so that selinux_file_permission
4388 	 * can determine whether revalidation is necessary.
4389 	 * Task label is already saved in the file security
4390 	 * struct as its SID.
4391 	 */
4392 	fsec->isid = isec->sid;
4393 	fsec->pseqno = avc_policy_seqno();
4394 	/*
4395 	 * Since the inode label or policy seqno may have changed
4396 	 * between the selinux_inode_permission check and the saving
4397 	 * of state above, recheck that access is still permitted.
4398 	 * Otherwise, access might never be revalidated against the
4399 	 * new inode label or new policy.
4400 	 * This check is not redundant - do not remove.
4401 	 */
4402 	return file_path_has_perm(file->f_cred, file, open_file_to_av(file));
4403 }
4404 
4405 /* task security operations */
4406 
4407 static int selinux_task_alloc(struct task_struct *task,
4408 			      u64 clone_flags)
4409 {
4410 	u32 sid = current_sid();
4411 	struct task_security_struct *old_tsec = selinux_task(current);
4412 	struct task_security_struct *new_tsec = selinux_task(task);
4413 
4414 	*new_tsec = *old_tsec;
4415 	return avc_has_perm(sid, sid, SECCLASS_PROCESS, PROCESS__FORK, NULL);
4416 }
4417 
4418 /*
4419  * prepare a new set of credentials for modification
4420  */
4421 static int selinux_cred_prepare(struct cred *new, const struct cred *old,
4422 				gfp_t gfp)
4423 {
4424 	const struct cred_security_struct *old_crsec = selinux_cred(old);
4425 	struct cred_security_struct *crsec = selinux_cred(new);
4426 
4427 	*crsec = *old_crsec;
4428 	return 0;
4429 }
4430 
4431 /*
4432  * transfer the SELinux data to a blank set of creds
4433  */
4434 static void selinux_cred_transfer(struct cred *new, const struct cred *old)
4435 {
4436 	const struct cred_security_struct *old_crsec = selinux_cred(old);
4437 	struct cred_security_struct *crsec = selinux_cred(new);
4438 
4439 	*crsec = *old_crsec;
4440 }
4441 
4442 static void selinux_cred_getsecid(const struct cred *c, u32 *secid)
4443 {
4444 	*secid = cred_sid(c);
4445 }
4446 
4447 static void selinux_cred_getlsmprop(const struct cred *c, struct lsm_prop *prop)
4448 {
4449 	prop->selinux.secid = cred_sid(c);
4450 }
4451 
4452 /*
4453  * set the security data for a kernel service
4454  * - all the creation contexts are set to unlabelled
4455  */
4456 static int selinux_kernel_act_as(struct cred *new, u32 secid)
4457 {
4458 	struct cred_security_struct *crsec = selinux_cred(new);
4459 	u32 sid = current_sid();
4460 	int ret;
4461 
4462 	ret = avc_has_perm(sid, secid,
4463 			   SECCLASS_KERNEL_SERVICE,
4464 			   KERNEL_SERVICE__USE_AS_OVERRIDE,
4465 			   NULL);
4466 	if (ret == 0) {
4467 		crsec->sid = secid;
4468 		crsec->create_sid = 0;
4469 		crsec->keycreate_sid = 0;
4470 		crsec->sockcreate_sid = 0;
4471 	}
4472 	return ret;
4473 }
4474 
4475 /*
4476  * set the file creation context in a security record to the same as the
4477  * objective context of the specified inode
4478  */
4479 static int selinux_kernel_create_files_as(struct cred *new, struct inode *inode)
4480 {
4481 	struct inode_security_struct *isec = inode_security(inode);
4482 	struct cred_security_struct *crsec = selinux_cred(new);
4483 	u32 sid = current_sid();
4484 	int ret;
4485 
4486 	ret = avc_has_perm(sid, isec->sid,
4487 			   SECCLASS_KERNEL_SERVICE,
4488 			   KERNEL_SERVICE__CREATE_FILES_AS,
4489 			   NULL);
4490 
4491 	if (ret == 0)
4492 		crsec->create_sid = isec->sid;
4493 	return ret;
4494 }
4495 
4496 static int selinux_kernel_module_request(char *kmod_name)
4497 {
4498 	struct common_audit_data ad;
4499 
4500 	ad.type = LSM_AUDIT_DATA_KMOD;
4501 	ad.u.kmod_name = kmod_name;
4502 
4503 	return avc_has_perm(current_sid(), SECINITSID_KERNEL, SECCLASS_SYSTEM,
4504 			    SYSTEM__MODULE_REQUEST, &ad);
4505 }
4506 
4507 static int selinux_kernel_load_from_file(struct file *file, u32 requested)
4508 {
4509 	struct common_audit_data ad;
4510 	struct inode_security_struct *isec;
4511 	struct file_security_struct *fsec;
4512 	u32 sid = current_sid();
4513 	int rc;
4514 
4515 	if (file == NULL)
4516 		return avc_has_perm(sid, sid, SECCLASS_SYSTEM, requested, NULL);
4517 
4518 	ad.type = LSM_AUDIT_DATA_FILE;
4519 	ad.u.file = file;
4520 
4521 	fsec = selinux_file(file);
4522 	if (sid != fsec->sid) {
4523 		rc = avc_has_perm(sid, fsec->sid, SECCLASS_FD, FD__USE, &ad);
4524 		if (rc)
4525 			return rc;
4526 	}
4527 
4528 	isec = inode_security(file_inode(file));
4529 	return avc_has_perm(sid, isec->sid, SECCLASS_SYSTEM, requested, &ad);
4530 }
4531 
4532 static int selinux_kernel_read_file(struct file *file,
4533 				    enum kernel_read_file_id id,
4534 				    bool contents)
4535 {
4536 	int rc = 0;
4537 
4538 	BUILD_BUG_ON_MSG(READING_MAX_ID > 8,
4539 			 "New kernel_read_file_id introduced; update SELinux!");
4540 
4541 	switch (id) {
4542 	case READING_FIRMWARE:
4543 		rc = selinux_kernel_load_from_file(file, SYSTEM__FIRMWARE_LOAD);
4544 		break;
4545 	case READING_MODULE:
4546 	case READING_MODULE_COMPRESSED:
4547 		rc = selinux_kernel_load_from_file(file, SYSTEM__MODULE_LOAD);
4548 		break;
4549 	case READING_KEXEC_IMAGE:
4550 		rc = selinux_kernel_load_from_file(file,
4551 						   SYSTEM__KEXEC_IMAGE_LOAD);
4552 		break;
4553 	case READING_KEXEC_INITRAMFS:
4554 		rc = selinux_kernel_load_from_file(file,
4555 						SYSTEM__KEXEC_INITRAMFS_LOAD);
4556 		break;
4557 	case READING_POLICY:
4558 		rc = selinux_kernel_load_from_file(file, SYSTEM__POLICY_LOAD);
4559 		break;
4560 	case READING_X509_CERTIFICATE:
4561 		rc = selinux_kernel_load_from_file(file,
4562 						SYSTEM__X509_CERTIFICATE_LOAD);
4563 		break;
4564 	default:
4565 		break;
4566 	}
4567 
4568 	return rc;
4569 }
4570 
4571 static int selinux_kernel_load_data(enum kernel_load_data_id id, bool contents)
4572 {
4573 	int rc = 0;
4574 
4575 	BUILD_BUG_ON_MSG(LOADING_MAX_ID > 8,
4576 			 "New kernel_load_data_id introduced; update SELinux!");
4577 
4578 	switch (id) {
4579 	case LOADING_FIRMWARE:
4580 		rc = selinux_kernel_load_from_file(NULL, SYSTEM__FIRMWARE_LOAD);
4581 		break;
4582 	case LOADING_MODULE:
4583 		rc = selinux_kernel_load_from_file(NULL, SYSTEM__MODULE_LOAD);
4584 		break;
4585 	case LOADING_KEXEC_IMAGE:
4586 		rc = selinux_kernel_load_from_file(NULL,
4587 						   SYSTEM__KEXEC_IMAGE_LOAD);
4588 		break;
4589 	case LOADING_KEXEC_INITRAMFS:
4590 		rc = selinux_kernel_load_from_file(NULL,
4591 						SYSTEM__KEXEC_INITRAMFS_LOAD);
4592 		break;
4593 	case LOADING_POLICY:
4594 		rc = selinux_kernel_load_from_file(NULL,
4595 						   SYSTEM__POLICY_LOAD);
4596 		break;
4597 	case LOADING_X509_CERTIFICATE:
4598 		rc = selinux_kernel_load_from_file(NULL,
4599 						SYSTEM__X509_CERTIFICATE_LOAD);
4600 		break;
4601 	default:
4602 		break;
4603 	}
4604 
4605 	return rc;
4606 }
4607 
4608 static int selinux_task_setpgid(struct task_struct *p, pid_t pgid)
4609 {
4610 	return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS,
4611 			    PROCESS__SETPGID, NULL);
4612 }
4613 
4614 static int selinux_task_getpgid(struct task_struct *p)
4615 {
4616 	return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS,
4617 			    PROCESS__GETPGID, NULL);
4618 }
4619 
4620 static int selinux_task_getsid(struct task_struct *p)
4621 {
4622 	return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS,
4623 			    PROCESS__GETSESSION, NULL);
4624 }
4625 
4626 static void selinux_current_getlsmprop_subj(struct lsm_prop *prop)
4627 {
4628 	prop->selinux.secid = current_sid();
4629 }
4630 
4631 static void selinux_task_getlsmprop_obj(struct task_struct *p,
4632 					struct lsm_prop *prop)
4633 {
4634 	prop->selinux.secid = task_sid_obj(p);
4635 }
4636 
4637 static int selinux_task_setnice(struct task_struct *p, int nice)
4638 {
4639 	return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS,
4640 			    PROCESS__SETSCHED, NULL);
4641 }
4642 
4643 static int selinux_task_setioprio(struct task_struct *p, int ioprio)
4644 {
4645 	return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS,
4646 			    PROCESS__SETSCHED, NULL);
4647 }
4648 
4649 static int selinux_task_getioprio(struct task_struct *p)
4650 {
4651 	return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS,
4652 			    PROCESS__GETSCHED, NULL);
4653 }
4654 
4655 static int selinux_task_prlimit(const struct cred *cred, const struct cred *tcred,
4656 				unsigned int flags)
4657 {
4658 	u32 av = 0;
4659 
4660 	if (!flags)
4661 		return 0;
4662 	if (flags & LSM_PRLIMIT_WRITE)
4663 		av |= PROCESS__SETRLIMIT;
4664 	if (flags & LSM_PRLIMIT_READ)
4665 		av |= PROCESS__GETRLIMIT;
4666 	return avc_has_perm(cred_sid(cred), cred_sid(tcred),
4667 			    SECCLASS_PROCESS, av, NULL);
4668 }
4669 
4670 static int selinux_task_setrlimit(struct task_struct *p, unsigned int resource,
4671 		struct rlimit *new_rlim)
4672 {
4673 	struct rlimit *old_rlim = p->signal->rlim + resource;
4674 
4675 	/* Control the ability to change the hard limit (whether
4676 	   lowering or raising it), so that the hard limit can
4677 	   later be used as a safe reset point for the soft limit
4678 	   upon context transitions.  See selinux_bprm_committing_creds. */
4679 	if (old_rlim->rlim_max != new_rlim->rlim_max)
4680 		return avc_has_perm(current_sid(), task_sid_obj(p),
4681 				    SECCLASS_PROCESS, PROCESS__SETRLIMIT, NULL);
4682 
4683 	return 0;
4684 }
4685 
4686 static int selinux_task_setscheduler(struct task_struct *p)
4687 {
4688 	return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS,
4689 			    PROCESS__SETSCHED, NULL);
4690 }
4691 
4692 static int selinux_task_getscheduler(struct task_struct *p)
4693 {
4694 	return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS,
4695 			    PROCESS__GETSCHED, NULL);
4696 }
4697 
4698 static int selinux_task_movememory(struct task_struct *p)
4699 {
4700 	return avc_has_perm(current_sid(), task_sid_obj(p), SECCLASS_PROCESS,
4701 			    PROCESS__SETSCHED, NULL);
4702 }
4703 
4704 static int selinux_task_kill(struct task_struct *p, struct kernel_siginfo *info,
4705 				int sig, const struct cred *cred)
4706 {
4707 	u32 secid;
4708 	u32 perm;
4709 
4710 	if (!sig)
4711 		perm = PROCESS__SIGNULL; /* null signal; existence test */
4712 	else
4713 		perm = signal_to_av(sig);
4714 	if (!cred)
4715 		secid = current_sid();
4716 	else
4717 		secid = cred_sid(cred);
4718 	return avc_has_perm(secid, task_sid_obj(p), SECCLASS_PROCESS, perm, NULL);
4719 }
4720 
4721 static void selinux_task_to_inode(struct task_struct *p,
4722 				  struct inode *inode)
4723 {
4724 	struct inode_security_struct *isec = selinux_inode(inode);
4725 	u32 sid = task_sid_obj(p);
4726 
4727 	spin_lock(&isec->lock);
4728 	isec->sclass = inode_mode_to_security_class(inode->i_mode);
4729 	isec->sid = sid;
4730 	isec->initialized = LABEL_INITIALIZED;
4731 	spin_unlock(&isec->lock);
4732 }
4733 
4734 static int selinux_userns_create(const struct cred *cred)
4735 {
4736 	u32 sid = current_sid();
4737 
4738 	return avc_has_perm(sid, sid, SECCLASS_USER_NAMESPACE,
4739 			USER_NAMESPACE__CREATE, NULL);
4740 }
4741 
4742 /* Returns error only if unable to parse addresses */
4743 static int selinux_parse_skb_ipv4(struct sk_buff *skb,
4744 			struct common_audit_data *ad, u8 *proto)
4745 {
4746 	int offset, ihlen, ret = -EINVAL;
4747 	struct iphdr _iph, *ih;
4748 
4749 	offset = skb_network_offset(skb);
4750 	ih = skb_header_pointer(skb, offset, sizeof(_iph), &_iph);
4751 	if (ih == NULL)
4752 		goto out;
4753 
4754 	ihlen = ih->ihl * 4;
4755 	if (ihlen < sizeof(_iph))
4756 		goto out;
4757 
4758 	ad->u.net->v4info.saddr = ih->saddr;
4759 	ad->u.net->v4info.daddr = ih->daddr;
4760 	ret = 0;
4761 
4762 	if (proto)
4763 		*proto = ih->protocol;
4764 
4765 	switch (ih->protocol) {
4766 	case IPPROTO_TCP: {
4767 		struct tcphdr _tcph, *th;
4768 
4769 		if (ntohs(ih->frag_off) & IP_OFFSET)
4770 			break;
4771 
4772 		offset += ihlen;
4773 		th = skb_header_pointer(skb, offset, sizeof(_tcph), &_tcph);
4774 		if (th == NULL)
4775 			break;
4776 
4777 		ad->u.net->sport = th->source;
4778 		ad->u.net->dport = th->dest;
4779 		break;
4780 	}
4781 
4782 	case IPPROTO_UDP: {
4783 		struct udphdr _udph, *uh;
4784 
4785 		if (ntohs(ih->frag_off) & IP_OFFSET)
4786 			break;
4787 
4788 		offset += ihlen;
4789 		uh = skb_header_pointer(skb, offset, sizeof(_udph), &_udph);
4790 		if (uh == NULL)
4791 			break;
4792 
4793 		ad->u.net->sport = uh->source;
4794 		ad->u.net->dport = uh->dest;
4795 		break;
4796 	}
4797 
4798 #if IS_ENABLED(CONFIG_IP_SCTP)
4799 	case IPPROTO_SCTP: {
4800 		struct sctphdr _sctph, *sh;
4801 
4802 		if (ntohs(ih->frag_off) & IP_OFFSET)
4803 			break;
4804 
4805 		offset += ihlen;
4806 		sh = skb_header_pointer(skb, offset, sizeof(_sctph), &_sctph);
4807 		if (sh == NULL)
4808 			break;
4809 
4810 		ad->u.net->sport = sh->source;
4811 		ad->u.net->dport = sh->dest;
4812 		break;
4813 	}
4814 #endif
4815 	default:
4816 		break;
4817 	}
4818 out:
4819 	return ret;
4820 }
4821 
4822 #if IS_ENABLED(CONFIG_IPV6)
4823 
4824 /* Returns error only if unable to parse addresses */
4825 static int selinux_parse_skb_ipv6(struct sk_buff *skb,
4826 			struct common_audit_data *ad, u8 *proto)
4827 {
4828 	u8 nexthdr;
4829 	int ret = -EINVAL, offset;
4830 	struct ipv6hdr _ipv6h, *ip6;
4831 	__be16 frag_off;
4832 
4833 	offset = skb_network_offset(skb);
4834 	ip6 = skb_header_pointer(skb, offset, sizeof(_ipv6h), &_ipv6h);
4835 	if (ip6 == NULL)
4836 		goto out;
4837 
4838 	ad->u.net->v6info.saddr = ip6->saddr;
4839 	ad->u.net->v6info.daddr = ip6->daddr;
4840 	ret = 0;
4841 
4842 	nexthdr = ip6->nexthdr;
4843 	offset += sizeof(_ipv6h);
4844 	offset = ipv6_skip_exthdr(skb, offset, &nexthdr, &frag_off);
4845 	if (offset < 0)
4846 		goto out;
4847 
4848 	if (proto)
4849 		*proto = nexthdr;
4850 
4851 	switch (nexthdr) {
4852 	case IPPROTO_TCP: {
4853 		struct tcphdr _tcph, *th;
4854 
4855 		th = skb_header_pointer(skb, offset, sizeof(_tcph), &_tcph);
4856 		if (th == NULL)
4857 			break;
4858 
4859 		ad->u.net->sport = th->source;
4860 		ad->u.net->dport = th->dest;
4861 		break;
4862 	}
4863 
4864 	case IPPROTO_UDP: {
4865 		struct udphdr _udph, *uh;
4866 
4867 		uh = skb_header_pointer(skb, offset, sizeof(_udph), &_udph);
4868 		if (uh == NULL)
4869 			break;
4870 
4871 		ad->u.net->sport = uh->source;
4872 		ad->u.net->dport = uh->dest;
4873 		break;
4874 	}
4875 
4876 #if IS_ENABLED(CONFIG_IP_SCTP)
4877 	case IPPROTO_SCTP: {
4878 		struct sctphdr _sctph, *sh;
4879 
4880 		sh = skb_header_pointer(skb, offset, sizeof(_sctph), &_sctph);
4881 		if (sh == NULL)
4882 			break;
4883 
4884 		ad->u.net->sport = sh->source;
4885 		ad->u.net->dport = sh->dest;
4886 		break;
4887 	}
4888 #endif
4889 	/* includes fragments */
4890 	default:
4891 		break;
4892 	}
4893 out:
4894 	return ret;
4895 }
4896 
4897 #endif /* IPV6 */
4898 
4899 static int selinux_parse_skb(struct sk_buff *skb, struct common_audit_data *ad,
4900 			     char **_addrp, int src, u8 *proto)
4901 {
4902 	char *addrp;
4903 	int ret;
4904 
4905 	switch (ad->u.net->family) {
4906 	case PF_INET:
4907 		ret = selinux_parse_skb_ipv4(skb, ad, proto);
4908 		if (ret)
4909 			goto parse_error;
4910 		addrp = (char *)(src ? &ad->u.net->v4info.saddr :
4911 				       &ad->u.net->v4info.daddr);
4912 		goto okay;
4913 
4914 #if IS_ENABLED(CONFIG_IPV6)
4915 	case PF_INET6:
4916 		ret = selinux_parse_skb_ipv6(skb, ad, proto);
4917 		if (ret)
4918 			goto parse_error;
4919 		addrp = (char *)(src ? &ad->u.net->v6info.saddr :
4920 				       &ad->u.net->v6info.daddr);
4921 		goto okay;
4922 #endif	/* IPV6 */
4923 	default:
4924 		addrp = NULL;
4925 		goto okay;
4926 	}
4927 
4928 parse_error:
4929 	pr_warn(
4930 	       "SELinux: failure in selinux_parse_skb(),"
4931 	       " unable to parse packet\n");
4932 	return ret;
4933 
4934 okay:
4935 	if (_addrp)
4936 		*_addrp = addrp;
4937 	return 0;
4938 }
4939 
4940 /**
4941  * selinux_skb_peerlbl_sid - Determine the peer label of a packet
4942  * @skb: the packet
4943  * @family: protocol family
4944  * @sid: the packet's peer label SID
4945  *
4946  * Description:
4947  * Check the various different forms of network peer labeling and determine
4948  * the peer label/SID for the packet; most of the magic actually occurs in
4949  * the security server function security_net_peersid_cmp().  The function
4950  * returns zero if the value in @sid is valid (although it may be SECSID_NULL)
4951  * or -EACCES if @sid is invalid due to inconsistencies with the different
4952  * peer labels.
4953  *
4954  */
4955 static int selinux_skb_peerlbl_sid(struct sk_buff *skb, u16 family, u32 *sid)
4956 {
4957 	int err;
4958 	u32 xfrm_sid;
4959 	u32 nlbl_sid;
4960 	u32 nlbl_type;
4961 
4962 	err = selinux_xfrm_skb_sid(skb, &xfrm_sid);
4963 	if (unlikely(err))
4964 		return -EACCES;
4965 	err = selinux_netlbl_skbuff_getsid(skb, family, &nlbl_type, &nlbl_sid);
4966 	if (unlikely(err))
4967 		return -EACCES;
4968 
4969 	err = security_net_peersid_resolve(nlbl_sid,
4970 					   nlbl_type, xfrm_sid, sid);
4971 	if (unlikely(err)) {
4972 		pr_warn(
4973 		       "SELinux: failure in selinux_skb_peerlbl_sid(),"
4974 		       " unable to determine packet's peer label\n");
4975 		return -EACCES;
4976 	}
4977 
4978 	return 0;
4979 }
4980 
4981 /**
4982  * selinux_conn_sid - Determine the child socket label for a connection
4983  * @sk_sid: the parent socket's SID
4984  * @skb_sid: the packet's SID
4985  * @conn_sid: the resulting connection SID
4986  *
4987  * If @skb_sid is valid then the user:role:type information from @sk_sid is
4988  * combined with the MLS information from @skb_sid in order to create
4989  * @conn_sid.  If @skb_sid is not valid then @conn_sid is simply a copy
4990  * of @sk_sid.  Returns zero on success, negative values on failure.
4991  *
4992  */
4993 static int selinux_conn_sid(u32 sk_sid, u32 skb_sid, u32 *conn_sid)
4994 {
4995 	int err = 0;
4996 
4997 	if (skb_sid != SECSID_NULL)
4998 		err = security_sid_mls_copy(sk_sid, skb_sid,
4999 					    conn_sid);
5000 	else
5001 		*conn_sid = sk_sid;
5002 
5003 	return err;
5004 }
5005 
5006 /* socket security operations */
5007 
5008 static int socket_sockcreate_sid(const struct cred_security_struct *crsec,
5009 				 u16 secclass, u32 *socksid)
5010 {
5011 	if (crsec->sockcreate_sid > SECSID_NULL) {
5012 		*socksid = crsec->sockcreate_sid;
5013 		return 0;
5014 	}
5015 
5016 	return security_transition_sid(crsec->sid, crsec->sid,
5017 				       secclass, NULL, socksid);
5018 }
5019 
5020 static bool sock_skip_has_perm(u32 sid)
5021 {
5022 	if (sid == SECINITSID_KERNEL)
5023 		return true;
5024 
5025 	/*
5026 	 * Before POLICYDB_CAP_USERSPACE_INITIAL_CONTEXT, sockets that
5027 	 * inherited the kernel context from early boot used to be skipped
5028 	 * here, so preserve that behavior unless the capability is set.
5029 	 *
5030 	 * By setting the capability the policy signals that it is ready
5031 	 * for this quirk to be fixed. Note that sockets created by a kernel
5032 	 * thread or a usermode helper executed without a transition will
5033 	 * still be skipped in this check regardless of the policycap
5034 	 * setting.
5035 	 */
5036 	if (!selinux_policycap_userspace_initial_context() &&
5037 	    sid == SECINITSID_INIT)
5038 		return true;
5039 	return false;
5040 }
5041 
5042 
5043 static int sock_has_perm(struct sock *sk, u32 perms)
5044 {
5045 	struct sk_security_struct *sksec = selinux_sock(sk);
5046 	struct common_audit_data ad;
5047 	struct lsm_network_audit net;
5048 
5049 	if (sock_skip_has_perm(sksec->sid))
5050 		return 0;
5051 
5052 	ad_net_init_from_sk(&ad, &net, sk);
5053 
5054 	return avc_has_perm(current_sid(), sksec->sid, sksec->sclass, perms,
5055 			    &ad);
5056 }
5057 
5058 static int selinux_socket_create(int family, int type,
5059 				 int protocol, int kern)
5060 {
5061 	const struct cred_security_struct *crsec = selinux_cred(current_cred());
5062 	u32 newsid;
5063 	u16 secclass;
5064 	int rc;
5065 
5066 	if (kern)
5067 		return 0;
5068 
5069 	secclass = socket_type_to_security_class(family, type, protocol);
5070 	rc = socket_sockcreate_sid(crsec, secclass, &newsid);
5071 	if (rc)
5072 		return rc;
5073 
5074 	return avc_has_perm(crsec->sid, newsid, secclass, SOCKET__CREATE, NULL);
5075 }
5076 
5077 static int selinux_socket_post_create(struct socket *sock, int family,
5078 				      int type, int protocol, int kern)
5079 {
5080 	const struct cred_security_struct *crsec = selinux_cred(current_cred());
5081 	struct inode_security_struct *isec = inode_security_novalidate(SOCK_INODE(sock));
5082 	struct sk_security_struct *sksec;
5083 	u16 sclass = socket_type_to_security_class(family, type, protocol);
5084 	u32 sid = SECINITSID_KERNEL;
5085 	int err = 0;
5086 
5087 	if (!kern) {
5088 		err = socket_sockcreate_sid(crsec, sclass, &sid);
5089 		if (err)
5090 			return err;
5091 	}
5092 
5093 	isec->sclass = sclass;
5094 	isec->sid = sid;
5095 	isec->initialized = LABEL_INITIALIZED;
5096 
5097 	if (sock->sk) {
5098 		sksec = selinux_sock(sock->sk);
5099 		sksec->sclass = sclass;
5100 		sksec->sid = sid;
5101 		/* Allows detection of the first association on this socket */
5102 		if (sksec->sclass == SECCLASS_SCTP_SOCKET)
5103 			sksec->sctp_assoc_state = SCTP_ASSOC_UNSET;
5104 
5105 		err = selinux_netlbl_socket_post_create(sock->sk, family);
5106 	}
5107 
5108 	return err;
5109 }
5110 
5111 static int selinux_socket_socketpair(struct socket *socka,
5112 				     struct socket *sockb)
5113 {
5114 	struct sk_security_struct *sksec_a = selinux_sock(socka->sk);
5115 	struct sk_security_struct *sksec_b = selinux_sock(sockb->sk);
5116 
5117 	sksec_a->peer_sid = sksec_b->sid;
5118 	sksec_b->peer_sid = sksec_a->sid;
5119 
5120 	return 0;
5121 }
5122 
5123 /* Range of port numbers used to automatically bind.
5124    Need to determine whether we should perform a name_bind
5125    permission check between the socket and the port number. */
5126 
5127 static int __selinux_socket_bind(struct sock *sk, struct sockaddr *address, int addrlen)
5128 {
5129 	struct sk_security_struct *sksec = selinux_sock(sk);
5130 	u16 family;
5131 	int err;
5132 
5133 	err = sock_has_perm(sk, SOCKET__BIND);
5134 	if (err)
5135 		goto out;
5136 
5137 	/* If PF_INET or PF_INET6, check name_bind permission for the port. */
5138 	family = sk->sk_family;
5139 	if (family == PF_INET || family == PF_INET6) {
5140 		char *addrp;
5141 		struct common_audit_data ad;
5142 		struct lsm_network_audit net = {0,};
5143 		struct sockaddr_in *addr4 = NULL;
5144 		struct sockaddr_in6 *addr6 = NULL;
5145 		u16 family_sa;
5146 		unsigned short snum;
5147 		u32 sid, node_perm;
5148 
5149 		/*
5150 		 * sctp_bindx(3) calls via selinux_sctp_bind_connect()
5151 		 * that validates multiple binding addresses. Because of this
5152 		 * need to check address->sa_family as it is possible to have
5153 		 * sk->sk_family = PF_INET6 with addr->sa_family = AF_INET.
5154 		 */
5155 		if (addrlen < offsetofend(struct sockaddr, sa_family))
5156 			return -EINVAL;
5157 		family_sa = address->sa_family;
5158 		switch (family_sa) {
5159 		case AF_UNSPEC:
5160 		case AF_INET:
5161 			if (addrlen < sizeof(struct sockaddr_in))
5162 				return -EINVAL;
5163 			addr4 = (struct sockaddr_in *)address;
5164 			if (family_sa == AF_UNSPEC) {
5165 				if (family == PF_INET6) {
5166 					/* Length check from inet6_bind_sk() */
5167 					if (addrlen < SIN6_LEN_RFC2133)
5168 						return -EINVAL;
5169 					/* Family check from __inet6_bind() */
5170 					goto err_af;
5171 				}
5172 				/* see __inet_bind(), we only want to allow
5173 				 * AF_UNSPEC if the address is INADDR_ANY
5174 				 */
5175 				if (addr4->sin_addr.s_addr != htonl(INADDR_ANY))
5176 					goto err_af;
5177 				family_sa = AF_INET;
5178 			}
5179 			snum = ntohs(addr4->sin_port);
5180 			addrp = (char *)&addr4->sin_addr.s_addr;
5181 			break;
5182 		case AF_INET6:
5183 			if (addrlen < SIN6_LEN_RFC2133)
5184 				return -EINVAL;
5185 			addr6 = (struct sockaddr_in6 *)address;
5186 			snum = ntohs(addr6->sin6_port);
5187 			addrp = (char *)&addr6->sin6_addr.s6_addr;
5188 			break;
5189 		default:
5190 			goto err_af;
5191 		}
5192 
5193 		ad.type = LSM_AUDIT_DATA_NET;
5194 		ad.u.net = &net;
5195 		ad.u.net->sport = htons(snum);
5196 		ad.u.net->family = family_sa;
5197 
5198 		if (snum) {
5199 			int low, high;
5200 
5201 			inet_get_local_port_range(sock_net(sk), &low, &high);
5202 
5203 			if (inet_port_requires_bind_service(sock_net(sk), snum) ||
5204 			    snum < low || snum > high) {
5205 				err = sel_netport_sid(sk->sk_protocol,
5206 						      snum, &sid);
5207 				if (err)
5208 					goto out;
5209 				err = avc_has_perm(sksec->sid, sid,
5210 						   sksec->sclass,
5211 						   SOCKET__NAME_BIND, &ad);
5212 				if (err)
5213 					goto out;
5214 			}
5215 		}
5216 
5217 		switch (sksec->sclass) {
5218 		case SECCLASS_TCP_SOCKET:
5219 			node_perm = TCP_SOCKET__NODE_BIND;
5220 			break;
5221 
5222 		case SECCLASS_UDP_SOCKET:
5223 			node_perm = UDP_SOCKET__NODE_BIND;
5224 			break;
5225 
5226 		case SECCLASS_SCTP_SOCKET:
5227 			node_perm = SCTP_SOCKET__NODE_BIND;
5228 			break;
5229 
5230 		default:
5231 			node_perm = RAWIP_SOCKET__NODE_BIND;
5232 			break;
5233 		}
5234 
5235 		err = sel_netnode_sid(addrp, family_sa, &sid);
5236 		if (err)
5237 			goto out;
5238 
5239 		if (family_sa == AF_INET)
5240 			ad.u.net->v4info.saddr = addr4->sin_addr.s_addr;
5241 		else
5242 			ad.u.net->v6info.saddr = addr6->sin6_addr;
5243 
5244 		err = avc_has_perm(sksec->sid, sid,
5245 				   sksec->sclass, node_perm, &ad);
5246 		if (err)
5247 			goto out;
5248 	}
5249 out:
5250 	return err;
5251 err_af:
5252 	/* Note that SCTP services expect -EINVAL, others -EAFNOSUPPORT. */
5253 	if (sk->sk_protocol == IPPROTO_SCTP)
5254 		return -EINVAL;
5255 	return -EAFNOSUPPORT;
5256 }
5257 
5258 static int selinux_socket_bind(struct socket *sock, struct sockaddr *address, int addrlen)
5259 {
5260 	return __selinux_socket_bind(sock->sk, address, addrlen);
5261 }
5262 
5263 /* This supports connect(2) and SCTP connect services such as sctp_connectx(3)
5264  * and sctp_sendmsg(3) as described in Documentation/security/SCTP.rst
5265  */
5266 static int selinux_socket_connect_helper(struct sock *sk,
5267 					 struct sockaddr *address, int addrlen)
5268 {
5269 	struct sk_security_struct *sksec = selinux_sock(sk);
5270 	int err;
5271 
5272 	err = sock_has_perm(sk, SOCKET__CONNECT);
5273 	if (err)
5274 		return err;
5275 	if (addrlen < offsetofend(struct sockaddr, sa_family))
5276 		return -EINVAL;
5277 
5278 	/* connect(AF_UNSPEC) has special handling, as it is a documented
5279 	 * way to disconnect the socket
5280 	 */
5281 	if (address->sa_family == AF_UNSPEC)
5282 		return 0;
5283 
5284 	/*
5285 	 * If a TCP or SCTP socket, check name_connect permission
5286 	 * for the port.
5287 	 */
5288 	if (sksec->sclass == SECCLASS_TCP_SOCKET ||
5289 	    sksec->sclass == SECCLASS_SCTP_SOCKET) {
5290 		struct common_audit_data ad;
5291 		struct lsm_network_audit net = {0,};
5292 		struct sockaddr_in *addr4 = NULL;
5293 		struct sockaddr_in6 *addr6 = NULL;
5294 		unsigned short snum;
5295 		u32 sid, perm;
5296 
5297 		/* sctp_connectx(3) calls via selinux_sctp_bind_connect()
5298 		 * that validates multiple connect addresses. Because of this
5299 		 * need to check address->sa_family as it is possible to have
5300 		 * sk->sk_family = PF_INET6 with addr->sa_family = AF_INET.
5301 		 */
5302 		switch (address->sa_family) {
5303 		case AF_INET:
5304 			addr4 = (struct sockaddr_in *)address;
5305 			if (addrlen < sizeof(struct sockaddr_in))
5306 				return -EINVAL;
5307 			snum = ntohs(addr4->sin_port);
5308 			break;
5309 		case AF_INET6:
5310 			addr6 = (struct sockaddr_in6 *)address;
5311 			if (addrlen < SIN6_LEN_RFC2133)
5312 				return -EINVAL;
5313 			snum = ntohs(addr6->sin6_port);
5314 			break;
5315 		default:
5316 			/* Note that SCTP services expect -EINVAL, whereas
5317 			 * others expect -EAFNOSUPPORT.
5318 			 */
5319 			if (sksec->sclass == SECCLASS_SCTP_SOCKET)
5320 				return -EINVAL;
5321 			else
5322 				return -EAFNOSUPPORT;
5323 		}
5324 
5325 		err = sel_netport_sid(sk->sk_protocol, snum, &sid);
5326 		if (err)
5327 			return err;
5328 
5329 		switch (sksec->sclass) {
5330 		case SECCLASS_TCP_SOCKET:
5331 			perm = TCP_SOCKET__NAME_CONNECT;
5332 			break;
5333 		case SECCLASS_SCTP_SOCKET:
5334 			perm = SCTP_SOCKET__NAME_CONNECT;
5335 			break;
5336 		}
5337 
5338 		ad.type = LSM_AUDIT_DATA_NET;
5339 		ad.u.net = &net;
5340 		ad.u.net->dport = htons(snum);
5341 		ad.u.net->family = address->sa_family;
5342 		err = avc_has_perm(sksec->sid, sid, sksec->sclass, perm, &ad);
5343 		if (err)
5344 			return err;
5345 	}
5346 
5347 	return 0;
5348 }
5349 
5350 /* Supports connect(2), see comments in selinux_socket_connect_helper() */
5351 static int selinux_socket_connect(struct socket *sock,
5352 				  struct sockaddr *address, int addrlen)
5353 {
5354 	int err;
5355 	struct sock *sk = sock->sk;
5356 
5357 	err = selinux_socket_connect_helper(sk, address, addrlen);
5358 	if (err)
5359 		return err;
5360 
5361 	return selinux_netlbl_socket_connect(sk, address);
5362 }
5363 
5364 static int selinux_socket_listen(struct socket *sock, int backlog)
5365 {
5366 	return sock_has_perm(sock->sk, SOCKET__LISTEN);
5367 }
5368 
5369 static int selinux_socket_accept(struct socket *sock, struct socket *newsock)
5370 {
5371 	int err;
5372 	struct inode_security_struct *isec;
5373 	struct inode_security_struct *newisec;
5374 	u16 sclass;
5375 	u32 sid;
5376 
5377 	err = sock_has_perm(sock->sk, SOCKET__ACCEPT);
5378 	if (err)
5379 		return err;
5380 
5381 	isec = inode_security_novalidate(SOCK_INODE(sock));
5382 	spin_lock(&isec->lock);
5383 	sclass = isec->sclass;
5384 	sid = isec->sid;
5385 	spin_unlock(&isec->lock);
5386 
5387 	newisec = inode_security_novalidate(SOCK_INODE(newsock));
5388 	newisec->sclass = sclass;
5389 	newisec->sid = sid;
5390 	newisec->initialized = LABEL_INITIALIZED;
5391 
5392 	return 0;
5393 }
5394 
5395 static int selinux_socket_sendmsg(struct socket *sock, struct msghdr *msg,
5396 				  int size)
5397 {
5398 	int rc;
5399 	struct sockaddr *const addr = msg->msg_name;
5400 	const int addrlen = msg->msg_namelen;
5401 
5402 	rc = sock_has_perm(sock->sk, SOCKET__WRITE);
5403 	if (rc)
5404 		return rc;
5405 
5406 	if (addr && (msg->msg_flags & MSG_FASTOPEN) &&
5407 	    (sk_is_tcp(sock->sk) ||
5408 	     (sk_is_inet(sock->sk) && sock->sk->sk_type == SOCK_STREAM &&
5409 	      sock->sk->sk_protocol == IPPROTO_MPTCP))) {
5410 		rc = selinux_socket_connect(sock, addr, addrlen);
5411 		if (rc)
5412 			return rc;
5413 	}
5414 
5415 	return 0;
5416 }
5417 
5418 static int selinux_socket_recvmsg(struct socket *sock, struct msghdr *msg,
5419 				  int size, int flags)
5420 {
5421 	return sock_has_perm(sock->sk, SOCKET__READ);
5422 }
5423 
5424 static int selinux_socket_getsockname(struct socket *sock)
5425 {
5426 	return sock_has_perm(sock->sk, SOCKET__GETATTR);
5427 }
5428 
5429 static int selinux_socket_getpeername(struct socket *sock)
5430 {
5431 	return sock_has_perm(sock->sk, SOCKET__GETATTR);
5432 }
5433 
5434 static int selinux_socket_setsockopt(struct socket *sock, int level, int optname)
5435 {
5436 	int err;
5437 
5438 	err = sock_has_perm(sock->sk, SOCKET__SETOPT);
5439 	if (err)
5440 		return err;
5441 
5442 	return selinux_netlbl_socket_setsockopt(sock, level, optname);
5443 }
5444 
5445 static int selinux_socket_getsockopt(struct socket *sock, int level,
5446 				     int optname)
5447 {
5448 	return sock_has_perm(sock->sk, SOCKET__GETOPT);
5449 }
5450 
5451 static int selinux_socket_shutdown(struct socket *sock, int how)
5452 {
5453 	return sock_has_perm(sock->sk, SOCKET__SHUTDOWN);
5454 }
5455 
5456 static int selinux_socket_unix_stream_connect(struct sock *sock,
5457 					      struct sock *other,
5458 					      struct sock *newsk)
5459 {
5460 	struct sk_security_struct *sksec_sock = selinux_sock(sock);
5461 	struct sk_security_struct *sksec_other = selinux_sock(other);
5462 	struct sk_security_struct *sksec_new = selinux_sock(newsk);
5463 	struct common_audit_data ad;
5464 	struct lsm_network_audit net;
5465 	int err;
5466 
5467 	ad_net_init_from_sk(&ad, &net, other);
5468 
5469 	err = avc_has_perm(sksec_sock->sid, sksec_other->sid,
5470 			   sksec_other->sclass,
5471 			   UNIX_STREAM_SOCKET__CONNECTTO, &ad);
5472 	if (err)
5473 		return err;
5474 
5475 	/* server child socket */
5476 	sksec_new->peer_sid = sksec_sock->sid;
5477 	err = security_sid_mls_copy(sksec_other->sid,
5478 				    sksec_sock->sid, &sksec_new->sid);
5479 	if (err)
5480 		return err;
5481 
5482 	/* connecting socket */
5483 	sksec_sock->peer_sid = sksec_new->sid;
5484 
5485 	return 0;
5486 }
5487 
5488 static int selinux_socket_unix_may_send(struct socket *sock,
5489 					struct socket *other)
5490 {
5491 	struct sk_security_struct *ssec = selinux_sock(sock->sk);
5492 	struct sk_security_struct *osec = selinux_sock(other->sk);
5493 	struct common_audit_data ad;
5494 	struct lsm_network_audit net;
5495 
5496 	ad_net_init_from_sk(&ad, &net, other->sk);
5497 
5498 	return avc_has_perm(ssec->sid, osec->sid, osec->sclass, SOCKET__SENDTO,
5499 			    &ad);
5500 }
5501 
5502 static int selinux_inet_sys_rcv_skb(struct net *ns, int ifindex,
5503 				    char *addrp, u16 family, u32 peer_sid,
5504 				    struct common_audit_data *ad)
5505 {
5506 	int err;
5507 	u32 if_sid;
5508 	u32 node_sid;
5509 
5510 	err = sel_netif_sid(ns, ifindex, &if_sid);
5511 	if (err)
5512 		return err;
5513 	err = avc_has_perm(peer_sid, if_sid,
5514 			   SECCLASS_NETIF, NETIF__INGRESS, ad);
5515 	if (err)
5516 		return err;
5517 
5518 	err = sel_netnode_sid(addrp, family, &node_sid);
5519 	if (err)
5520 		return err;
5521 	return avc_has_perm(peer_sid, node_sid,
5522 			    SECCLASS_NODE, NODE__RECVFROM, ad);
5523 }
5524 
5525 static int selinux_sock_rcv_skb_compat(struct sock *sk, struct sk_buff *skb,
5526 				       u16 family)
5527 {
5528 	int err = 0;
5529 	struct sk_security_struct *sksec = selinux_sock(sk);
5530 	u32 sk_sid = sksec->sid;
5531 	struct common_audit_data ad;
5532 	struct lsm_network_audit net;
5533 	char *addrp;
5534 
5535 	ad_net_init_from_iif(&ad, &net, skb->skb_iif, family);
5536 	err = selinux_parse_skb(skb, &ad, &addrp, 1, NULL);
5537 	if (err)
5538 		return err;
5539 
5540 	if (selinux_secmark_enabled()) {
5541 		err = avc_has_perm(sk_sid, skb->secmark, SECCLASS_PACKET,
5542 				   PACKET__RECV, &ad);
5543 		if (err)
5544 			return err;
5545 	}
5546 
5547 	err = selinux_netlbl_sock_rcv_skb(sksec, skb, family, &ad);
5548 	if (err)
5549 		return err;
5550 	err = selinux_xfrm_sock_rcv_skb(sksec->sid, skb, &ad);
5551 
5552 	return err;
5553 }
5554 
5555 static int selinux_socket_sock_rcv_skb(struct sock *sk, struct sk_buff *skb)
5556 {
5557 	int err, peerlbl_active, secmark_active;
5558 	struct sk_security_struct *sksec = selinux_sock(sk);
5559 	u16 family = sk->sk_family;
5560 	u32 sk_sid = sksec->sid;
5561 	struct common_audit_data ad;
5562 	struct lsm_network_audit net;
5563 	char *addrp;
5564 
5565 	if (family != PF_INET && family != PF_INET6)
5566 		return 0;
5567 
5568 	/* Handle mapped IPv4 packets arriving via IPv6 sockets */
5569 	if (family == PF_INET6 && skb->protocol == htons(ETH_P_IP))
5570 		family = PF_INET;
5571 
5572 	/* If any sort of compatibility mode is enabled then handoff processing
5573 	 * to the selinux_sock_rcv_skb_compat() function to deal with the
5574 	 * special handling.  We do this in an attempt to keep this function
5575 	 * as fast and as clean as possible. */
5576 	if (!selinux_policycap_netpeer())
5577 		return selinux_sock_rcv_skb_compat(sk, skb, family);
5578 
5579 	secmark_active = selinux_secmark_enabled();
5580 	peerlbl_active = selinux_peerlbl_enabled();
5581 	if (!secmark_active && !peerlbl_active)
5582 		return 0;
5583 
5584 	ad_net_init_from_iif(&ad, &net, skb->skb_iif, family);
5585 	err = selinux_parse_skb(skb, &ad, &addrp, 1, NULL);
5586 	if (err)
5587 		return err;
5588 
5589 	if (peerlbl_active) {
5590 		u32 peer_sid;
5591 
5592 		err = selinux_skb_peerlbl_sid(skb, family, &peer_sid);
5593 		if (err)
5594 			return err;
5595 		err = selinux_inet_sys_rcv_skb(sock_net(sk), skb->skb_iif,
5596 					       addrp, family, peer_sid, &ad);
5597 		if (err) {
5598 			selinux_netlbl_err(skb, family, err, 0);
5599 			return err;
5600 		}
5601 		err = avc_has_perm(sk_sid, peer_sid, SECCLASS_PEER,
5602 				   PEER__RECV, &ad);
5603 		if (err) {
5604 			selinux_netlbl_err(skb, family, err, 0);
5605 			return err;
5606 		}
5607 	}
5608 
5609 	if (secmark_active) {
5610 		err = avc_has_perm(sk_sid, skb->secmark, SECCLASS_PACKET,
5611 				   PACKET__RECV, &ad);
5612 		if (err)
5613 			return err;
5614 	}
5615 
5616 	return err;
5617 }
5618 
5619 static int selinux_socket_getpeersec_stream(struct socket *sock,
5620 					    sockptr_t optval, sockptr_t optlen,
5621 					    unsigned int len)
5622 {
5623 	int err = 0;
5624 	char *scontext = NULL;
5625 	u32 scontext_len;
5626 	struct sk_security_struct *sksec = selinux_sock(sock->sk);
5627 	u32 peer_sid = SECSID_NULL;
5628 
5629 	if (sksec->sclass == SECCLASS_UNIX_STREAM_SOCKET ||
5630 	    sksec->sclass == SECCLASS_TCP_SOCKET ||
5631 	    sksec->sclass == SECCLASS_SCTP_SOCKET)
5632 		peer_sid = sksec->peer_sid;
5633 	if (peer_sid == SECSID_NULL)
5634 		return -ENOPROTOOPT;
5635 
5636 	err = security_sid_to_context(peer_sid, &scontext,
5637 				      &scontext_len);
5638 	if (err)
5639 		return err;
5640 	if (scontext_len > len) {
5641 		err = -ERANGE;
5642 		goto out_len;
5643 	}
5644 
5645 	if (copy_to_sockptr(optval, scontext, scontext_len))
5646 		err = -EFAULT;
5647 out_len:
5648 	if (copy_to_sockptr(optlen, &scontext_len, sizeof(scontext_len)))
5649 		err = -EFAULT;
5650 	kfree(scontext);
5651 	return err;
5652 }
5653 
5654 static int selinux_socket_getpeersec_dgram(struct socket *sock,
5655 					   struct sk_buff *skb, u32 *secid)
5656 {
5657 	u32 peer_secid = SECSID_NULL;
5658 	u16 family;
5659 
5660 	if (skb && skb->protocol == htons(ETH_P_IP))
5661 		family = PF_INET;
5662 	else if (skb && skb->protocol == htons(ETH_P_IPV6))
5663 		family = PF_INET6;
5664 	else if (sock)
5665 		family = sock->sk->sk_family;
5666 	else {
5667 		*secid = SECSID_NULL;
5668 		return -EINVAL;
5669 	}
5670 
5671 	if (sock && family == PF_UNIX) {
5672 		struct inode_security_struct *isec;
5673 		isec = inode_security_novalidate(SOCK_INODE(sock));
5674 		peer_secid = isec->sid;
5675 	} else if (skb)
5676 		selinux_skb_peerlbl_sid(skb, family, &peer_secid);
5677 
5678 	*secid = peer_secid;
5679 	if (peer_secid == SECSID_NULL)
5680 		return -ENOPROTOOPT;
5681 	return 0;
5682 }
5683 
5684 static int selinux_sk_alloc_security(struct sock *sk, int family, gfp_t priority)
5685 {
5686 	struct sk_security_struct *sksec = selinux_sock(sk);
5687 
5688 	sksec->peer_sid = SECINITSID_UNLABELED;
5689 	sksec->sid = SECINITSID_UNLABELED;
5690 	sksec->sclass = SECCLASS_SOCKET;
5691 	selinux_netlbl_sk_security_reset(sksec);
5692 
5693 	return 0;
5694 }
5695 
5696 static void selinux_sk_free_security(struct sock *sk)
5697 {
5698 	struct sk_security_struct *sksec = selinux_sock(sk);
5699 
5700 	selinux_netlbl_sk_security_free(sksec);
5701 }
5702 
5703 static void selinux_sk_clone_security(const struct sock *sk, struct sock *newsk)
5704 {
5705 	struct sk_security_struct *sksec = selinux_sock(sk);
5706 	struct sk_security_struct *newsksec = selinux_sock(newsk);
5707 
5708 	newsksec->sid = sksec->sid;
5709 	newsksec->peer_sid = sksec->peer_sid;
5710 	newsksec->sclass = sksec->sclass;
5711 
5712 	selinux_netlbl_sk_security_reset(newsksec);
5713 }
5714 
5715 static void selinux_sk_getsecid(const struct sock *sk, u32 *secid)
5716 {
5717 	if (!sk)
5718 		*secid = SECINITSID_ANY_SOCKET;
5719 	else {
5720 		const struct sk_security_struct *sksec = selinux_sock(sk);
5721 
5722 		*secid = sksec->sid;
5723 	}
5724 }
5725 
5726 static void selinux_sock_graft(struct sock *sk, struct socket *parent)
5727 {
5728 	struct inode_security_struct *isec =
5729 		inode_security_novalidate(SOCK_INODE(parent));
5730 	struct sk_security_struct *sksec = selinux_sock(sk);
5731 
5732 	if (sk->sk_family == PF_INET || sk->sk_family == PF_INET6 ||
5733 	    sk->sk_family == PF_UNIX)
5734 		isec->sid = sksec->sid;
5735 	sksec->sclass = isec->sclass;
5736 }
5737 
5738 /*
5739  * Determines peer_secid for the asoc and updates socket's peer label
5740  * if it's the first association on the socket.
5741  */
5742 static int selinux_sctp_process_new_assoc(struct sctp_association *asoc,
5743 					  struct sk_buff *skb)
5744 {
5745 	struct sock *sk = asoc->base.sk;
5746 	u16 family = sk->sk_family;
5747 	struct sk_security_struct *sksec = selinux_sock(sk);
5748 	struct common_audit_data ad;
5749 	struct lsm_network_audit net;
5750 	int err;
5751 
5752 	/* handle mapped IPv4 packets arriving via IPv6 sockets */
5753 	if (family == PF_INET6 && skb->protocol == htons(ETH_P_IP))
5754 		family = PF_INET;
5755 
5756 	if (selinux_peerlbl_enabled()) {
5757 		asoc->peer_secid = SECSID_NULL;
5758 
5759 		/* This will return peer_sid = SECSID_NULL if there are
5760 		 * no peer labels, see security_net_peersid_resolve().
5761 		 */
5762 		err = selinux_skb_peerlbl_sid(skb, family, &asoc->peer_secid);
5763 		if (err)
5764 			return err;
5765 
5766 		if (asoc->peer_secid == SECSID_NULL)
5767 			asoc->peer_secid = SECINITSID_UNLABELED;
5768 	} else {
5769 		asoc->peer_secid = SECINITSID_UNLABELED;
5770 	}
5771 
5772 	if (sksec->sctp_assoc_state == SCTP_ASSOC_UNSET) {
5773 		sksec->sctp_assoc_state = SCTP_ASSOC_SET;
5774 
5775 		/* Here as first association on socket. As the peer SID
5776 		 * was allowed by peer recv (and the netif/node checks),
5777 		 * then it is approved by policy and used as the primary
5778 		 * peer SID for getpeercon(3).
5779 		 */
5780 		sksec->peer_sid = asoc->peer_secid;
5781 	} else if (sksec->peer_sid != asoc->peer_secid) {
5782 		/* Other association peer SIDs are checked to enforce
5783 		 * consistency among the peer SIDs.
5784 		 */
5785 		ad_net_init_from_sk(&ad, &net, asoc->base.sk);
5786 		err = avc_has_perm(sksec->peer_sid, asoc->peer_secid,
5787 				   sksec->sclass, SCTP_SOCKET__ASSOCIATION,
5788 				   &ad);
5789 		if (err)
5790 			return err;
5791 	}
5792 	return 0;
5793 }
5794 
5795 /* Called whenever SCTP receives an INIT or COOKIE ECHO chunk. This
5796  * happens on an incoming connect(2), sctp_connectx(3) or
5797  * sctp_sendmsg(3) (with no association already present).
5798  */
5799 static int selinux_sctp_assoc_request(struct sctp_association *asoc,
5800 				      struct sk_buff *skb)
5801 {
5802 	struct sk_security_struct *sksec = selinux_sock(asoc->base.sk);
5803 	u32 conn_sid;
5804 	int err;
5805 
5806 	if (!selinux_policycap_extsockclass())
5807 		return 0;
5808 
5809 	err = selinux_sctp_process_new_assoc(asoc, skb);
5810 	if (err)
5811 		return err;
5812 
5813 	/* Compute the MLS component for the connection and store
5814 	 * the information in asoc. This will be used by SCTP TCP type
5815 	 * sockets and peeled off connections as they cause a new
5816 	 * socket to be generated. selinux_sctp_sk_clone() will then
5817 	 * plug this into the new socket.
5818 	 */
5819 	err = selinux_conn_sid(sksec->sid, asoc->peer_secid, &conn_sid);
5820 	if (err)
5821 		return err;
5822 
5823 	asoc->secid = conn_sid;
5824 
5825 	/* Set any NetLabel labels including CIPSO/CALIPSO options. */
5826 	return selinux_netlbl_sctp_assoc_request(asoc, skb);
5827 }
5828 
5829 /* Called when SCTP receives a COOKIE ACK chunk as the final
5830  * response to an association request (initited by us).
5831  */
5832 static int selinux_sctp_assoc_established(struct sctp_association *asoc,
5833 					  struct sk_buff *skb)
5834 {
5835 	struct sk_security_struct *sksec = selinux_sock(asoc->base.sk);
5836 
5837 	if (!selinux_policycap_extsockclass())
5838 		return 0;
5839 
5840 	/* Inherit secid from the parent socket - this will be picked up
5841 	 * by selinux_sctp_sk_clone() if the association gets peeled off
5842 	 * into a new socket.
5843 	 */
5844 	asoc->secid = sksec->sid;
5845 
5846 	return selinux_sctp_process_new_assoc(asoc, skb);
5847 }
5848 
5849 /* Check if sctp IPv4/IPv6 addresses are valid for binding or connecting
5850  * based on their @optname.
5851  */
5852 static int selinux_sctp_bind_connect(struct sock *sk, int optname,
5853 				     struct sockaddr *address,
5854 				     int addrlen)
5855 {
5856 	int len, err = 0, walk_size = 0;
5857 	void *addr_buf;
5858 	struct sockaddr *addr;
5859 
5860 	if (!selinux_policycap_extsockclass())
5861 		return 0;
5862 
5863 	/* Process one or more addresses that may be IPv4 or IPv6 */
5864 	addr_buf = address;
5865 
5866 	while (walk_size < addrlen) {
5867 		if (walk_size + sizeof(sa_family_t) > addrlen)
5868 			return -EINVAL;
5869 
5870 		addr = addr_buf;
5871 		switch (addr->sa_family) {
5872 		case AF_UNSPEC:
5873 		case AF_INET:
5874 			len = sizeof(struct sockaddr_in);
5875 			break;
5876 		case AF_INET6:
5877 			len = sizeof(struct sockaddr_in6);
5878 			break;
5879 		default:
5880 			return -EINVAL;
5881 		}
5882 
5883 		if (walk_size + len > addrlen)
5884 			return -EINVAL;
5885 
5886 		err = -EINVAL;
5887 		switch (optname) {
5888 		/* Bind checks */
5889 		case SCTP_PRIMARY_ADDR:
5890 		case SCTP_SET_PEER_PRIMARY_ADDR:
5891 		case SCTP_SOCKOPT_BINDX_ADD:
5892 			err = __selinux_socket_bind(sk, addr, len);
5893 			break;
5894 		/* Connect checks */
5895 		case SCTP_SOCKOPT_CONNECTX:
5896 		case SCTP_PARAM_SET_PRIMARY:
5897 		case SCTP_PARAM_ADD_IP:
5898 		case SCTP_SENDMSG_CONNECT:
5899 			err = selinux_socket_connect_helper(sk, addr, len);
5900 			if (err)
5901 				return err;
5902 
5903 			/* As selinux_sctp_bind_connect() is called by the
5904 			 * SCTP protocol layer, the socket is already locked,
5905 			 * therefore selinux_netlbl_socket_connect_locked()
5906 			 * is called here. The situations handled are:
5907 			 * sctp_connectx(3), sctp_sendmsg(3), sendmsg(2),
5908 			 * whenever a new IP address is added or when a new
5909 			 * primary address is selected.
5910 			 * Note that an SCTP connect(2) call happens before
5911 			 * the SCTP protocol layer and is handled via
5912 			 * selinux_socket_connect().
5913 			 */
5914 			err = selinux_netlbl_socket_connect_locked(sk, addr);
5915 			break;
5916 		}
5917 
5918 		if (err)
5919 			return err;
5920 
5921 		addr_buf += len;
5922 		walk_size += len;
5923 	}
5924 
5925 	return 0;
5926 }
5927 
5928 /* Called whenever a new socket is created by accept(2) or sctp_peeloff(3). */
5929 static void selinux_sctp_sk_clone(struct sctp_association *asoc, struct sock *sk,
5930 				  struct sock *newsk)
5931 {
5932 	struct sk_security_struct *sksec = selinux_sock(sk);
5933 	struct sk_security_struct *newsksec = selinux_sock(newsk);
5934 
5935 	/* If policy does not support SECCLASS_SCTP_SOCKET then call
5936 	 * the non-sctp clone version.
5937 	 */
5938 	if (!selinux_policycap_extsockclass())
5939 		return selinux_sk_clone_security(sk, newsk);
5940 
5941 	newsksec->sid = asoc->secid;
5942 	newsksec->peer_sid = asoc->peer_secid;
5943 	newsksec->sclass = sksec->sclass;
5944 	selinux_netlbl_sctp_sk_clone(sk, newsk);
5945 }
5946 
5947 static int selinux_mptcp_add_subflow(struct sock *sk, struct sock *ssk)
5948 {
5949 	struct sk_security_struct *ssksec = selinux_sock(ssk);
5950 	struct sk_security_struct *sksec = selinux_sock(sk);
5951 
5952 	ssksec->sclass = sksec->sclass;
5953 	ssksec->sid = sksec->sid;
5954 
5955 	/* replace the existing subflow label deleting the existing one
5956 	 * and re-recreating a new label using the updated context
5957 	 */
5958 	selinux_netlbl_sk_security_free(ssksec);
5959 	return selinux_netlbl_socket_post_create(ssk, ssk->sk_family);
5960 }
5961 
5962 static int selinux_inet_conn_request(const struct sock *sk, struct sk_buff *skb,
5963 				     struct request_sock *req)
5964 {
5965 	struct sk_security_struct *sksec = selinux_sock(sk);
5966 	int err;
5967 	u16 family = req->rsk_ops->family;
5968 	u32 connsid;
5969 	u32 peersid;
5970 
5971 	err = selinux_skb_peerlbl_sid(skb, family, &peersid);
5972 	if (err)
5973 		return err;
5974 	err = selinux_conn_sid(sksec->sid, peersid, &connsid);
5975 	if (err)
5976 		return err;
5977 	req->secid = connsid;
5978 	req->peer_secid = peersid;
5979 
5980 	return selinux_netlbl_inet_conn_request(req, family);
5981 }
5982 
5983 static void selinux_inet_csk_clone(struct sock *newsk,
5984 				   const struct request_sock *req)
5985 {
5986 	struct sk_security_struct *newsksec = selinux_sock(newsk);
5987 
5988 	newsksec->sid = req->secid;
5989 	newsksec->peer_sid = req->peer_secid;
5990 	/* NOTE: Ideally, we should also get the isec->sid for the
5991 	   new socket in sync, but we don't have the isec available yet.
5992 	   So we will wait until sock_graft to do it, by which
5993 	   time it will have been created and available. */
5994 
5995 	/* We don't need to take any sort of lock here as we are the only
5996 	 * thread with access to newsksec */
5997 	selinux_netlbl_inet_csk_clone(newsk, req->rsk_ops->family);
5998 }
5999 
6000 static void selinux_inet_conn_established(struct sock *sk, struct sk_buff *skb)
6001 {
6002 	u16 family = sk->sk_family;
6003 	struct sk_security_struct *sksec = selinux_sock(sk);
6004 
6005 	/* handle mapped IPv4 packets arriving via IPv6 sockets */
6006 	if (family == PF_INET6 && skb->protocol == htons(ETH_P_IP))
6007 		family = PF_INET;
6008 
6009 	selinux_skb_peerlbl_sid(skb, family, &sksec->peer_sid);
6010 }
6011 
6012 static int selinux_secmark_relabel_packet(u32 sid)
6013 {
6014 	return avc_has_perm(current_sid(), sid, SECCLASS_PACKET, PACKET__RELABELTO,
6015 			    NULL);
6016 }
6017 
6018 static void selinux_secmark_refcount_inc(void)
6019 {
6020 	atomic_inc(&selinux_secmark_refcount);
6021 }
6022 
6023 static void selinux_secmark_refcount_dec(void)
6024 {
6025 	atomic_dec(&selinux_secmark_refcount);
6026 }
6027 
6028 static void selinux_req_classify_flow(const struct request_sock *req,
6029 				      struct flowi_common *flic)
6030 {
6031 	flic->flowic_secid = req->secid;
6032 }
6033 
6034 static int selinux_tun_dev_alloc_security(void *security)
6035 {
6036 	struct tun_security_struct *tunsec = selinux_tun_dev(security);
6037 
6038 	tunsec->sid = current_sid();
6039 	return 0;
6040 }
6041 
6042 static int selinux_tun_dev_create(void)
6043 {
6044 	u32 sid = current_sid();
6045 
6046 	/* we aren't taking into account the "sockcreate" SID since the socket
6047 	 * that is being created here is not a socket in the traditional sense,
6048 	 * instead it is a private sock, accessible only to the kernel, and
6049 	 * representing a wide range of network traffic spanning multiple
6050 	 * connections unlike traditional sockets - check the TUN driver to
6051 	 * get a better understanding of why this socket is special */
6052 
6053 	return avc_has_perm(sid, sid, SECCLASS_TUN_SOCKET, TUN_SOCKET__CREATE,
6054 			    NULL);
6055 }
6056 
6057 static int selinux_tun_dev_attach_queue(void *security)
6058 {
6059 	struct tun_security_struct *tunsec = selinux_tun_dev(security);
6060 
6061 	return avc_has_perm(current_sid(), tunsec->sid, SECCLASS_TUN_SOCKET,
6062 			    TUN_SOCKET__ATTACH_QUEUE, NULL);
6063 }
6064 
6065 static int selinux_tun_dev_attach(struct sock *sk, void *security)
6066 {
6067 	struct tun_security_struct *tunsec = selinux_tun_dev(security);
6068 	struct sk_security_struct *sksec = selinux_sock(sk);
6069 
6070 	/* we don't currently perform any NetLabel based labeling here and it
6071 	 * isn't clear that we would want to do so anyway; while we could apply
6072 	 * labeling without the support of the TUN user the resulting labeled
6073 	 * traffic from the other end of the connection would almost certainly
6074 	 * cause confusion to the TUN user that had no idea network labeling
6075 	 * protocols were being used */
6076 
6077 	sksec->sid = tunsec->sid;
6078 	sksec->sclass = SECCLASS_TUN_SOCKET;
6079 
6080 	return 0;
6081 }
6082 
6083 static int selinux_tun_dev_open(void *security)
6084 {
6085 	struct tun_security_struct *tunsec = selinux_tun_dev(security);
6086 	u32 sid = current_sid();
6087 	int err;
6088 
6089 	err = avc_has_perm(sid, tunsec->sid, SECCLASS_TUN_SOCKET,
6090 			   TUN_SOCKET__RELABELFROM, NULL);
6091 	if (err)
6092 		return err;
6093 	err = avc_has_perm(sid, sid, SECCLASS_TUN_SOCKET,
6094 			   TUN_SOCKET__RELABELTO, NULL);
6095 	if (err)
6096 		return err;
6097 	tunsec->sid = sid;
6098 
6099 	return 0;
6100 }
6101 
6102 #ifdef CONFIG_NETFILTER
6103 
6104 static unsigned int selinux_ip_forward(void *priv, struct sk_buff *skb,
6105 				       const struct nf_hook_state *state)
6106 {
6107 	int ifindex;
6108 	u16 family;
6109 	char *addrp;
6110 	u32 peer_sid;
6111 	struct common_audit_data ad;
6112 	struct lsm_network_audit net;
6113 	int secmark_active, peerlbl_active;
6114 
6115 	if (!selinux_policycap_netpeer())
6116 		return NF_ACCEPT;
6117 
6118 	secmark_active = selinux_secmark_enabled();
6119 	peerlbl_active = selinux_peerlbl_enabled();
6120 	if (!secmark_active && !peerlbl_active)
6121 		return NF_ACCEPT;
6122 
6123 	family = state->pf;
6124 	if (selinux_skb_peerlbl_sid(skb, family, &peer_sid) != 0)
6125 		return NF_DROP;
6126 
6127 	ifindex = state->in->ifindex;
6128 	ad_net_init_from_iif(&ad, &net, ifindex, family);
6129 	if (selinux_parse_skb(skb, &ad, &addrp, 1, NULL) != 0)
6130 		return NF_DROP;
6131 
6132 	if (peerlbl_active) {
6133 		int err;
6134 
6135 		err = selinux_inet_sys_rcv_skb(state->net, ifindex,
6136 					       addrp, family, peer_sid, &ad);
6137 		if (err) {
6138 			selinux_netlbl_err(skb, family, err, 1);
6139 			return NF_DROP;
6140 		}
6141 	}
6142 
6143 	if (secmark_active)
6144 		if (avc_has_perm(peer_sid, skb->secmark,
6145 				 SECCLASS_PACKET, PACKET__FORWARD_IN, &ad))
6146 			return NF_DROP;
6147 
6148 	if (netlbl_enabled())
6149 		/* we do this in the FORWARD path and not the POST_ROUTING
6150 		 * path because we want to make sure we apply the necessary
6151 		 * labeling before IPsec is applied so we can leverage AH
6152 		 * protection */
6153 		if (selinux_netlbl_skbuff_setsid(skb, family, peer_sid) != 0)
6154 			return NF_DROP;
6155 
6156 	return NF_ACCEPT;
6157 }
6158 
6159 static unsigned int selinux_ip_output(void *priv, struct sk_buff *skb,
6160 				      const struct nf_hook_state *state)
6161 {
6162 	struct sock *sk;
6163 	u32 sid;
6164 
6165 	if (!netlbl_enabled())
6166 		return NF_ACCEPT;
6167 
6168 	/* we do this in the LOCAL_OUT path and not the POST_ROUTING path
6169 	 * because we want to make sure we apply the necessary labeling
6170 	 * before IPsec is applied so we can leverage AH protection */
6171 	sk = skb_to_full_sk(skb);
6172 	if (sk) {
6173 		struct sk_security_struct *sksec;
6174 
6175 		if (sk_listener(sk))
6176 			/* if the socket is the listening state then this
6177 			 * packet is a SYN-ACK packet which means it needs to
6178 			 * be labeled based on the connection/request_sock and
6179 			 * not the parent socket.  unfortunately, we can't
6180 			 * lookup the request_sock yet as it isn't queued on
6181 			 * the parent socket until after the SYN-ACK is sent.
6182 			 * the "solution" is to simply pass the packet as-is
6183 			 * as any IP option based labeling should be copied
6184 			 * from the initial connection request (in the IP
6185 			 * layer).  it is far from ideal, but until we get a
6186 			 * security label in the packet itself this is the
6187 			 * best we can do. */
6188 			return NF_ACCEPT;
6189 
6190 		/* standard practice, label using the parent socket */
6191 		sksec = selinux_sock(sk);
6192 		sid = sksec->sid;
6193 	} else
6194 		sid = SECINITSID_KERNEL;
6195 	if (selinux_netlbl_skbuff_setsid(skb, state->pf, sid) != 0)
6196 		return NF_DROP;
6197 
6198 	return NF_ACCEPT;
6199 }
6200 
6201 
6202 static unsigned int selinux_ip_postroute_compat(struct sk_buff *skb,
6203 					const struct nf_hook_state *state)
6204 {
6205 	struct sock *sk;
6206 	struct sk_security_struct *sksec;
6207 	struct common_audit_data ad;
6208 	struct lsm_network_audit net;
6209 	u8 proto = 0;
6210 
6211 	sk = skb_to_full_sk(skb);
6212 	if (sk == NULL)
6213 		return NF_ACCEPT;
6214 	sksec = selinux_sock(sk);
6215 
6216 	ad_net_init_from_iif(&ad, &net, state->out->ifindex, state->pf);
6217 	if (selinux_parse_skb(skb, &ad, NULL, 0, &proto))
6218 		return NF_DROP;
6219 
6220 	if (selinux_secmark_enabled())
6221 		if (avc_has_perm(sksec->sid, skb->secmark,
6222 				 SECCLASS_PACKET, PACKET__SEND, &ad))
6223 			return NF_DROP_ERR(-ECONNREFUSED);
6224 
6225 	if (selinux_xfrm_postroute_last(sksec->sid, skb, &ad, proto))
6226 		return NF_DROP_ERR(-ECONNREFUSED);
6227 
6228 	return NF_ACCEPT;
6229 }
6230 
6231 static unsigned int selinux_ip_postroute(void *priv,
6232 					 struct sk_buff *skb,
6233 					 const struct nf_hook_state *state)
6234 {
6235 	u16 family;
6236 	u32 secmark_perm;
6237 	u32 peer_sid;
6238 	int ifindex;
6239 	struct sock *sk;
6240 	struct common_audit_data ad;
6241 	struct lsm_network_audit net;
6242 	char *addrp;
6243 	int secmark_active, peerlbl_active;
6244 
6245 	/* If any sort of compatibility mode is enabled then handoff processing
6246 	 * to the selinux_ip_postroute_compat() function to deal with the
6247 	 * special handling.  We do this in an attempt to keep this function
6248 	 * as fast and as clean as possible. */
6249 	if (!selinux_policycap_netpeer())
6250 		return selinux_ip_postroute_compat(skb, state);
6251 
6252 	secmark_active = selinux_secmark_enabled();
6253 	peerlbl_active = selinux_peerlbl_enabled();
6254 	if (!secmark_active && !peerlbl_active)
6255 		return NF_ACCEPT;
6256 
6257 	sk = skb_to_full_sk(skb);
6258 
6259 #ifdef CONFIG_XFRM
6260 	/* If skb->dst->xfrm is non-NULL then the packet is undergoing an IPsec
6261 	 * packet transformation so allow the packet to pass without any checks
6262 	 * since we'll have another chance to perform access control checks
6263 	 * when the packet is on it's final way out.
6264 	 * NOTE: there appear to be some IPv6 multicast cases where skb->dst
6265 	 *       is NULL, in this case go ahead and apply access control.
6266 	 * NOTE: if this is a local socket (skb->sk != NULL) that is in the
6267 	 *       TCP listening state we cannot wait until the XFRM processing
6268 	 *       is done as we will miss out on the SA label if we do;
6269 	 *       unfortunately, this means more work, but it is only once per
6270 	 *       connection. */
6271 	if (skb_dst(skb) != NULL && skb_dst(skb)->xfrm != NULL &&
6272 	    !(sk && sk_listener(sk)))
6273 		return NF_ACCEPT;
6274 #endif
6275 
6276 	family = state->pf;
6277 	if (sk == NULL) {
6278 		/* Without an associated socket the packet is either coming
6279 		 * from the kernel or it is being forwarded; check the packet
6280 		 * to determine which and if the packet is being forwarded
6281 		 * query the packet directly to determine the security label. */
6282 		if (skb->skb_iif) {
6283 			secmark_perm = PACKET__FORWARD_OUT;
6284 			if (selinux_skb_peerlbl_sid(skb, family, &peer_sid))
6285 				return NF_DROP;
6286 		} else {
6287 			secmark_perm = PACKET__SEND;
6288 			peer_sid = SECINITSID_KERNEL;
6289 		}
6290 	} else if (sk_listener(sk)) {
6291 		/* Locally generated packet but the associated socket is in the
6292 		 * listening state which means this is a SYN-ACK packet.  In
6293 		 * this particular case the correct security label is assigned
6294 		 * to the connection/request_sock but unfortunately we can't
6295 		 * query the request_sock as it isn't queued on the parent
6296 		 * socket until after the SYN-ACK packet is sent; the only
6297 		 * viable choice is to regenerate the label like we do in
6298 		 * selinux_inet_conn_request().  See also selinux_ip_output()
6299 		 * for similar problems. */
6300 		u32 skb_sid;
6301 		struct sk_security_struct *sksec;
6302 
6303 		sksec = selinux_sock(sk);
6304 		if (selinux_skb_peerlbl_sid(skb, family, &skb_sid))
6305 			return NF_DROP;
6306 		/* At this point, if the returned skb peerlbl is SECSID_NULL
6307 		 * and the packet has been through at least one XFRM
6308 		 * transformation then we must be dealing with the "final"
6309 		 * form of labeled IPsec packet; since we've already applied
6310 		 * all of our access controls on this packet we can safely
6311 		 * pass the packet. */
6312 		if (skb_sid == SECSID_NULL) {
6313 			switch (family) {
6314 			case PF_INET:
6315 				if (IPCB(skb)->flags & IPSKB_XFRM_TRANSFORMED)
6316 					return NF_ACCEPT;
6317 				break;
6318 			case PF_INET6:
6319 				if (IP6CB(skb)->flags & IP6SKB_XFRM_TRANSFORMED)
6320 					return NF_ACCEPT;
6321 				break;
6322 			default:
6323 				return NF_DROP_ERR(-ECONNREFUSED);
6324 			}
6325 		}
6326 		if (selinux_conn_sid(sksec->sid, skb_sid, &peer_sid))
6327 			return NF_DROP;
6328 		secmark_perm = PACKET__SEND;
6329 	} else {
6330 		/* Locally generated packet, fetch the security label from the
6331 		 * associated socket. */
6332 		struct sk_security_struct *sksec = selinux_sock(sk);
6333 		peer_sid = sksec->sid;
6334 		secmark_perm = PACKET__SEND;
6335 	}
6336 
6337 	ifindex = state->out->ifindex;
6338 	ad_net_init_from_iif(&ad, &net, ifindex, family);
6339 	if (selinux_parse_skb(skb, &ad, &addrp, 0, NULL))
6340 		return NF_DROP;
6341 
6342 	if (secmark_active)
6343 		if (avc_has_perm(peer_sid, skb->secmark,
6344 				 SECCLASS_PACKET, secmark_perm, &ad))
6345 			return NF_DROP_ERR(-ECONNREFUSED);
6346 
6347 	if (peerlbl_active) {
6348 		u32 if_sid;
6349 		u32 node_sid;
6350 
6351 		if (sel_netif_sid(state->net, ifindex, &if_sid))
6352 			return NF_DROP;
6353 		if (avc_has_perm(peer_sid, if_sid,
6354 				 SECCLASS_NETIF, NETIF__EGRESS, &ad))
6355 			return NF_DROP_ERR(-ECONNREFUSED);
6356 
6357 		if (sel_netnode_sid(addrp, family, &node_sid))
6358 			return NF_DROP;
6359 		if (avc_has_perm(peer_sid, node_sid,
6360 				 SECCLASS_NODE, NODE__SENDTO, &ad))
6361 			return NF_DROP_ERR(-ECONNREFUSED);
6362 	}
6363 
6364 	return NF_ACCEPT;
6365 }
6366 #endif	/* CONFIG_NETFILTER */
6367 
6368 static int nlmsg_sock_has_extended_perms(struct sock *sk, u32 perms, u16 nlmsg_type)
6369 {
6370 	struct sk_security_struct *sksec = selinux_sock(sk);
6371 	struct common_audit_data ad;
6372 	u8 driver;
6373 	u8 xperm;
6374 
6375 	if (sock_skip_has_perm(sksec->sid))
6376 		return 0;
6377 
6378 	ad.type = LSM_AUDIT_DATA_NLMSGTYPE;
6379 	ad.u.nlmsg_type = nlmsg_type;
6380 
6381 	driver = nlmsg_type >> 8;
6382 	xperm = nlmsg_type & 0xff;
6383 
6384 	return avc_has_extended_perms(current_sid(), sksec->sid, sksec->sclass,
6385 				      perms, driver, AVC_EXT_NLMSG, xperm, &ad);
6386 }
6387 
6388 static int selinux_netlink_send(struct sock *sk, struct sk_buff *skb)
6389 {
6390 	int rc = 0;
6391 	unsigned int msg_len;
6392 	unsigned int data_len = skb->len;
6393 	unsigned char *data = skb->data;
6394 	struct nlmsghdr *nlh;
6395 	struct sk_security_struct *sksec = selinux_sock(sk);
6396 	u16 sclass = sksec->sclass;
6397 	u32 perm;
6398 
6399 	while (data_len >= nlmsg_total_size(0)) {
6400 		nlh = (struct nlmsghdr *)data;
6401 
6402 		/* NOTE: the nlmsg_len field isn't reliably set by some netlink
6403 		 *       users which means we can't reject skb's with bogus
6404 		 *       length fields; our solution is to follow what
6405 		 *       netlink_rcv_skb() does and simply skip processing at
6406 		 *       messages with length fields that are clearly junk
6407 		 */
6408 		if (nlh->nlmsg_len < NLMSG_HDRLEN || nlh->nlmsg_len > data_len)
6409 			return 0;
6410 
6411 		rc = selinux_nlmsg_lookup(sclass, nlh->nlmsg_type, &perm);
6412 		if (rc == 0) {
6413 			if (selinux_policycap_netlink_xperm()) {
6414 				rc = nlmsg_sock_has_extended_perms(
6415 					sk, perm, nlh->nlmsg_type);
6416 			} else {
6417 				rc = sock_has_perm(sk, perm);
6418 			}
6419 			if (rc)
6420 				return rc;
6421 		} else if (rc == -EINVAL) {
6422 			/* -EINVAL is a missing msg/perm mapping */
6423 			if (sclass == SECCLASS_NETLINK_TCPDIAG_SOCKET &&
6424 			    nlh->nlmsg_type == DCCPDIAG_GETSOCK)
6425 				pr_warn_once("SELinux: DCCP has been removed, pid=%d comm=%s\n",
6426 					     task_pid_nr(current), current->comm);
6427 			else
6428 				pr_warn_ratelimited("SELinux: unrecognized netlink"
6429 					" message: protocol=%hu nlmsg_type=%hu sclass=%s"
6430 					" pid=%d comm=%s\n",
6431 					sk->sk_protocol, nlh->nlmsg_type,
6432 					secclass_map[sclass - 1].name,
6433 					task_pid_nr(current), current->comm);
6434 			if (enforcing_enabled() &&
6435 			    !security_get_allow_unknown())
6436 				return rc;
6437 			rc = 0;
6438 		} else if (rc == -ENOENT) {
6439 			/* -ENOENT is a missing socket/class mapping, ignore */
6440 			rc = 0;
6441 		} else {
6442 			return rc;
6443 		}
6444 
6445 		/* move to the next message after applying netlink padding */
6446 		msg_len = NLMSG_ALIGN(nlh->nlmsg_len);
6447 		if (msg_len >= data_len)
6448 			return 0;
6449 		data_len -= msg_len;
6450 		data += msg_len;
6451 	}
6452 
6453 	return rc;
6454 }
6455 
6456 static void ipc_init_security(struct ipc_security_struct *isec, u16 sclass)
6457 {
6458 	isec->sclass = sclass;
6459 	isec->sid = current_sid();
6460 }
6461 
6462 static int ipc_has_perm(struct kern_ipc_perm *ipc_perms,
6463 			u32 perms)
6464 {
6465 	struct ipc_security_struct *isec;
6466 	struct common_audit_data ad;
6467 	u32 sid = current_sid();
6468 
6469 	isec = selinux_ipc(ipc_perms);
6470 
6471 	ad.type = LSM_AUDIT_DATA_IPC;
6472 	ad.u.ipc_id = ipc_perms->key;
6473 
6474 	return avc_has_perm(sid, isec->sid, isec->sclass, perms, &ad);
6475 }
6476 
6477 static int selinux_msg_msg_alloc_security(struct msg_msg *msg)
6478 {
6479 	struct msg_security_struct *msec;
6480 
6481 	msec = selinux_msg_msg(msg);
6482 	msec->sid = SECINITSID_UNLABELED;
6483 
6484 	return 0;
6485 }
6486 
6487 /* message queue security operations */
6488 static int selinux_msg_queue_alloc_security(struct kern_ipc_perm *msq)
6489 {
6490 	struct ipc_security_struct *isec;
6491 	struct common_audit_data ad;
6492 	u32 sid = current_sid();
6493 
6494 	isec = selinux_ipc(msq);
6495 	ipc_init_security(isec, SECCLASS_MSGQ);
6496 
6497 	ad.type = LSM_AUDIT_DATA_IPC;
6498 	ad.u.ipc_id = msq->key;
6499 
6500 	return avc_has_perm(sid, isec->sid, SECCLASS_MSGQ,
6501 			    MSGQ__CREATE, &ad);
6502 }
6503 
6504 static int selinux_msg_queue_associate(struct kern_ipc_perm *msq, int msqflg)
6505 {
6506 	struct ipc_security_struct *isec;
6507 	struct common_audit_data ad;
6508 	u32 sid = current_sid();
6509 
6510 	isec = selinux_ipc(msq);
6511 
6512 	ad.type = LSM_AUDIT_DATA_IPC;
6513 	ad.u.ipc_id = msq->key;
6514 
6515 	return avc_has_perm(sid, isec->sid, SECCLASS_MSGQ,
6516 			    MSGQ__ASSOCIATE, &ad);
6517 }
6518 
6519 static int selinux_msg_queue_msgctl(struct kern_ipc_perm *msq, int cmd)
6520 {
6521 	u32 perms;
6522 
6523 	switch (cmd) {
6524 	case IPC_INFO:
6525 	case MSG_INFO:
6526 		/* No specific object, just general system-wide information. */
6527 		return avc_has_perm(current_sid(), SECINITSID_KERNEL,
6528 				    SECCLASS_SYSTEM, SYSTEM__IPC_INFO, NULL);
6529 	case IPC_STAT:
6530 	case MSG_STAT:
6531 	case MSG_STAT_ANY:
6532 		perms = MSGQ__GETATTR | MSGQ__ASSOCIATE;
6533 		break;
6534 	case IPC_SET:
6535 		perms = MSGQ__SETATTR;
6536 		break;
6537 	case IPC_RMID:
6538 		perms = MSGQ__DESTROY;
6539 		break;
6540 	default:
6541 		return 0;
6542 	}
6543 
6544 	return ipc_has_perm(msq, perms);
6545 }
6546 
6547 static int selinux_msg_queue_msgsnd(struct kern_ipc_perm *msq, struct msg_msg *msg, int msqflg)
6548 {
6549 	struct ipc_security_struct *isec;
6550 	struct msg_security_struct *msec;
6551 	struct common_audit_data ad;
6552 	u32 sid = current_sid();
6553 	int rc;
6554 
6555 	isec = selinux_ipc(msq);
6556 	msec = selinux_msg_msg(msg);
6557 
6558 	/*
6559 	 * First time through, need to assign label to the message
6560 	 */
6561 	if (msec->sid == SECINITSID_UNLABELED) {
6562 		/*
6563 		 * Compute new sid based on current process and
6564 		 * message queue this message will be stored in
6565 		 */
6566 		rc = security_transition_sid(sid, isec->sid,
6567 					     SECCLASS_MSG, NULL, &msec->sid);
6568 		if (rc)
6569 			return rc;
6570 	}
6571 
6572 	ad.type = LSM_AUDIT_DATA_IPC;
6573 	ad.u.ipc_id = msq->key;
6574 
6575 	/* Can this process write to the queue? */
6576 	rc = avc_has_perm(sid, isec->sid, SECCLASS_MSGQ,
6577 			  MSGQ__WRITE, &ad);
6578 	if (!rc)
6579 		/* Can this process send the message */
6580 		rc = avc_has_perm(sid, msec->sid, SECCLASS_MSG,
6581 				  MSG__SEND, &ad);
6582 	if (!rc)
6583 		/* Can the message be put in the queue? */
6584 		rc = avc_has_perm(msec->sid, isec->sid, SECCLASS_MSGQ,
6585 				  MSGQ__ENQUEUE, &ad);
6586 
6587 	return rc;
6588 }
6589 
6590 static int selinux_msg_queue_msgrcv(struct kern_ipc_perm *msq, struct msg_msg *msg,
6591 				    struct task_struct *target,
6592 				    long type, int mode)
6593 {
6594 	struct ipc_security_struct *isec;
6595 	struct msg_security_struct *msec;
6596 	struct common_audit_data ad;
6597 	u32 sid = task_sid_obj(target);
6598 	int rc;
6599 
6600 	isec = selinux_ipc(msq);
6601 	msec = selinux_msg_msg(msg);
6602 
6603 	ad.type = LSM_AUDIT_DATA_IPC;
6604 	ad.u.ipc_id = msq->key;
6605 
6606 	rc = avc_has_perm(sid, isec->sid,
6607 			  SECCLASS_MSGQ, MSGQ__READ, &ad);
6608 	if (!rc)
6609 		rc = avc_has_perm(sid, msec->sid,
6610 				  SECCLASS_MSG, MSG__RECEIVE, &ad);
6611 	return rc;
6612 }
6613 
6614 /* Shared Memory security operations */
6615 static int selinux_shm_alloc_security(struct kern_ipc_perm *shp)
6616 {
6617 	struct ipc_security_struct *isec;
6618 	struct common_audit_data ad;
6619 	u32 sid = current_sid();
6620 
6621 	isec = selinux_ipc(shp);
6622 	ipc_init_security(isec, SECCLASS_SHM);
6623 
6624 	ad.type = LSM_AUDIT_DATA_IPC;
6625 	ad.u.ipc_id = shp->key;
6626 
6627 	return avc_has_perm(sid, isec->sid, SECCLASS_SHM,
6628 			    SHM__CREATE, &ad);
6629 }
6630 
6631 static int selinux_shm_associate(struct kern_ipc_perm *shp, int shmflg)
6632 {
6633 	struct ipc_security_struct *isec;
6634 	struct common_audit_data ad;
6635 	u32 sid = current_sid();
6636 
6637 	isec = selinux_ipc(shp);
6638 
6639 	ad.type = LSM_AUDIT_DATA_IPC;
6640 	ad.u.ipc_id = shp->key;
6641 
6642 	return avc_has_perm(sid, isec->sid, SECCLASS_SHM,
6643 			    SHM__ASSOCIATE, &ad);
6644 }
6645 
6646 /* Note, at this point, shp is locked down */
6647 static int selinux_shm_shmctl(struct kern_ipc_perm *shp, int cmd)
6648 {
6649 	u32 perms;
6650 
6651 	switch (cmd) {
6652 	case IPC_INFO:
6653 	case SHM_INFO:
6654 		/* No specific object, just general system-wide information. */
6655 		return avc_has_perm(current_sid(), SECINITSID_KERNEL,
6656 				    SECCLASS_SYSTEM, SYSTEM__IPC_INFO, NULL);
6657 	case IPC_STAT:
6658 	case SHM_STAT:
6659 	case SHM_STAT_ANY:
6660 		perms = SHM__GETATTR | SHM__ASSOCIATE;
6661 		break;
6662 	case IPC_SET:
6663 		perms = SHM__SETATTR;
6664 		break;
6665 	case SHM_LOCK:
6666 	case SHM_UNLOCK:
6667 		perms = SHM__LOCK;
6668 		break;
6669 	case IPC_RMID:
6670 		perms = SHM__DESTROY;
6671 		break;
6672 	default:
6673 		return 0;
6674 	}
6675 
6676 	return ipc_has_perm(shp, perms);
6677 }
6678 
6679 static int selinux_shm_shmat(struct kern_ipc_perm *shp,
6680 			     char __user *shmaddr, int shmflg)
6681 {
6682 	u32 perms;
6683 
6684 	if (shmflg & SHM_RDONLY)
6685 		perms = SHM__READ;
6686 	else
6687 		perms = SHM__READ | SHM__WRITE;
6688 
6689 	return ipc_has_perm(shp, perms);
6690 }
6691 
6692 /* Semaphore security operations */
6693 static int selinux_sem_alloc_security(struct kern_ipc_perm *sma)
6694 {
6695 	struct ipc_security_struct *isec;
6696 	struct common_audit_data ad;
6697 	u32 sid = current_sid();
6698 
6699 	isec = selinux_ipc(sma);
6700 	ipc_init_security(isec, SECCLASS_SEM);
6701 
6702 	ad.type = LSM_AUDIT_DATA_IPC;
6703 	ad.u.ipc_id = sma->key;
6704 
6705 	return avc_has_perm(sid, isec->sid, SECCLASS_SEM,
6706 			    SEM__CREATE, &ad);
6707 }
6708 
6709 static int selinux_sem_associate(struct kern_ipc_perm *sma, int semflg)
6710 {
6711 	struct ipc_security_struct *isec;
6712 	struct common_audit_data ad;
6713 	u32 sid = current_sid();
6714 
6715 	isec = selinux_ipc(sma);
6716 
6717 	ad.type = LSM_AUDIT_DATA_IPC;
6718 	ad.u.ipc_id = sma->key;
6719 
6720 	return avc_has_perm(sid, isec->sid, SECCLASS_SEM,
6721 			    SEM__ASSOCIATE, &ad);
6722 }
6723 
6724 /* Note, at this point, sma is locked down */
6725 static int selinux_sem_semctl(struct kern_ipc_perm *sma, int cmd)
6726 {
6727 	int err;
6728 	u32 perms;
6729 
6730 	switch (cmd) {
6731 	case IPC_INFO:
6732 	case SEM_INFO:
6733 		/* No specific object, just general system-wide information. */
6734 		return avc_has_perm(current_sid(), SECINITSID_KERNEL,
6735 				    SECCLASS_SYSTEM, SYSTEM__IPC_INFO, NULL);
6736 	case GETPID:
6737 	case GETNCNT:
6738 	case GETZCNT:
6739 		perms = SEM__GETATTR;
6740 		break;
6741 	case GETVAL:
6742 	case GETALL:
6743 		perms = SEM__READ;
6744 		break;
6745 	case SETVAL:
6746 	case SETALL:
6747 		perms = SEM__WRITE;
6748 		break;
6749 	case IPC_RMID:
6750 		perms = SEM__DESTROY;
6751 		break;
6752 	case IPC_SET:
6753 		perms = SEM__SETATTR;
6754 		break;
6755 	case IPC_STAT:
6756 	case SEM_STAT:
6757 	case SEM_STAT_ANY:
6758 		perms = SEM__GETATTR | SEM__ASSOCIATE;
6759 		break;
6760 	default:
6761 		return 0;
6762 	}
6763 
6764 	err = ipc_has_perm(sma, perms);
6765 	return err;
6766 }
6767 
6768 static int selinux_sem_semop(struct kern_ipc_perm *sma,
6769 			     struct sembuf *sops, unsigned nsops, int alter)
6770 {
6771 	u32 perms;
6772 
6773 	if (alter)
6774 		perms = SEM__READ | SEM__WRITE;
6775 	else
6776 		perms = SEM__READ;
6777 
6778 	return ipc_has_perm(sma, perms);
6779 }
6780 
6781 static int selinux_ipc_permission(struct kern_ipc_perm *ipcp, short flag)
6782 {
6783 	u32 av = 0;
6784 
6785 	av = 0;
6786 	if (flag & S_IRUGO)
6787 		av |= IPC__UNIX_READ;
6788 	if (flag & S_IWUGO)
6789 		av |= IPC__UNIX_WRITE;
6790 
6791 	if (av == 0)
6792 		return 0;
6793 
6794 	return ipc_has_perm(ipcp, av);
6795 }
6796 
6797 static void selinux_ipc_getlsmprop(struct kern_ipc_perm *ipcp,
6798 				   struct lsm_prop *prop)
6799 {
6800 	struct ipc_security_struct *isec = selinux_ipc(ipcp);
6801 	prop->selinux.secid = isec->sid;
6802 }
6803 
6804 static void selinux_d_instantiate(struct dentry *dentry, struct inode *inode)
6805 {
6806 	if (inode)
6807 		inode_doinit_with_dentry(inode, dentry);
6808 }
6809 
6810 static int selinux_lsm_getattr(unsigned int attr, struct task_struct *p,
6811 			       char **value)
6812 {
6813 	const struct cred_security_struct *crsec;
6814 	int error;
6815 	u32 sid;
6816 	u32 len;
6817 
6818 	rcu_read_lock();
6819 	crsec = selinux_cred(__task_cred(p));
6820 	if (p != current) {
6821 		error = avc_has_perm(current_sid(), crsec->sid,
6822 				     SECCLASS_PROCESS, PROCESS__GETATTR, NULL);
6823 		if (error)
6824 			goto err_unlock;
6825 	}
6826 	switch (attr) {
6827 	case LSM_ATTR_CURRENT:
6828 		sid = crsec->sid;
6829 		break;
6830 	case LSM_ATTR_PREV:
6831 		sid = crsec->osid;
6832 		break;
6833 	case LSM_ATTR_EXEC:
6834 		sid = crsec->exec_sid;
6835 		break;
6836 	case LSM_ATTR_FSCREATE:
6837 		sid = crsec->create_sid;
6838 		break;
6839 	case LSM_ATTR_KEYCREATE:
6840 		sid = crsec->keycreate_sid;
6841 		break;
6842 	case LSM_ATTR_SOCKCREATE:
6843 		sid = crsec->sockcreate_sid;
6844 		break;
6845 	default:
6846 		error = -EOPNOTSUPP;
6847 		goto err_unlock;
6848 	}
6849 	rcu_read_unlock();
6850 
6851 	if (sid == SECSID_NULL) {
6852 		*value = NULL;
6853 		return 0;
6854 	}
6855 
6856 	error = security_sid_to_context(sid, value, &len);
6857 	if (error)
6858 		return error;
6859 	return len;
6860 
6861 err_unlock:
6862 	rcu_read_unlock();
6863 	return error;
6864 }
6865 
6866 static int selinux_lsm_setattr(u64 attr, void *value, size_t size)
6867 {
6868 	struct cred_security_struct *crsec;
6869 	struct cred *new;
6870 	u32 mysid = current_sid(), sid = 0, ptsid;
6871 	int error;
6872 	char *str = value;
6873 
6874 	/*
6875 	 * Basic control over ability to set these attributes at all.
6876 	 */
6877 	switch (attr) {
6878 	case LSM_ATTR_EXEC:
6879 		error = avc_has_perm(mysid, mysid, SECCLASS_PROCESS,
6880 				     PROCESS__SETEXEC, NULL);
6881 		break;
6882 	case LSM_ATTR_FSCREATE:
6883 		error = avc_has_perm(mysid, mysid, SECCLASS_PROCESS,
6884 				     PROCESS__SETFSCREATE, NULL);
6885 		break;
6886 	case LSM_ATTR_KEYCREATE:
6887 		error = avc_has_perm(mysid, mysid, SECCLASS_PROCESS,
6888 				     PROCESS__SETKEYCREATE, NULL);
6889 		break;
6890 	case LSM_ATTR_SOCKCREATE:
6891 		error = avc_has_perm(mysid, mysid, SECCLASS_PROCESS,
6892 				     PROCESS__SETSOCKCREATE, NULL);
6893 		break;
6894 	case LSM_ATTR_CURRENT:
6895 		error = avc_has_perm(mysid, mysid, SECCLASS_PROCESS,
6896 				     PROCESS__SETCURRENT, NULL);
6897 		break;
6898 	default:
6899 		error = -EOPNOTSUPP;
6900 		break;
6901 	}
6902 	if (error)
6903 		return error;
6904 
6905 	/* Obtain a SID for the context, if one was specified. */
6906 	if (size && str[0] && str[0] != '\n') {
6907 		if (str[size-1] == '\n') {
6908 			str[size-1] = 0;
6909 			size--;
6910 		}
6911 		error = security_context_to_sid(value, size,
6912 						&sid, GFP_KERNEL);
6913 		if (error == -EINVAL && attr == LSM_ATTR_FSCREATE) {
6914 			if (!has_cap_mac_admin(true)) {
6915 				struct audit_buffer *ab;
6916 				size_t audit_size;
6917 
6918 				/* We strip a nul only if it is at the end,
6919 				 * otherwise the context contains a nul and
6920 				 * we should audit that */
6921 				if (str[size - 1] == '\0')
6922 					audit_size = size - 1;
6923 				else
6924 					audit_size = size;
6925 				ab = audit_log_start(audit_context(),
6926 						     GFP_ATOMIC,
6927 						     AUDIT_SELINUX_ERR);
6928 				if (!ab)
6929 					return error;
6930 				audit_log_format(ab, "op=fscreate invalid_context=");
6931 				audit_log_n_untrustedstring(ab, value,
6932 							    audit_size);
6933 				audit_log_end(ab);
6934 
6935 				return error;
6936 			}
6937 			error = security_context_to_sid_force(value, size,
6938 							&sid);
6939 		}
6940 		if (error)
6941 			return error;
6942 	}
6943 
6944 	new = prepare_creds();
6945 	if (!new)
6946 		return -ENOMEM;
6947 
6948 	/* Permission checking based on the specified context is
6949 	   performed during the actual operation (execve,
6950 	   open/mkdir/...), when we know the full context of the
6951 	   operation.  See selinux_bprm_creds_for_exec for the execve
6952 	   checks and may_create for the file creation checks. The
6953 	   operation will then fail if the context is not permitted. */
6954 	crsec = selinux_cred(new);
6955 	if (attr == LSM_ATTR_EXEC) {
6956 		crsec->exec_sid = sid;
6957 	} else if (attr == LSM_ATTR_FSCREATE) {
6958 		crsec->create_sid = sid;
6959 	} else if (attr == LSM_ATTR_KEYCREATE) {
6960 		if (sid) {
6961 			error = avc_has_perm(mysid, sid,
6962 					     SECCLASS_KEY, KEY__CREATE, NULL);
6963 			if (error)
6964 				goto abort_change;
6965 		}
6966 		crsec->keycreate_sid = sid;
6967 	} else if (attr == LSM_ATTR_SOCKCREATE) {
6968 		crsec->sockcreate_sid = sid;
6969 	} else if (attr == LSM_ATTR_CURRENT) {
6970 		error = -EINVAL;
6971 		if (sid == 0)
6972 			goto abort_change;
6973 
6974 		if (!current_is_single_threaded()) {
6975 			error = security_bounded_transition(crsec->sid, sid);
6976 			if (error)
6977 				goto abort_change;
6978 		}
6979 
6980 		/* Check permissions for the transition. */
6981 		error = avc_has_perm(crsec->sid, sid, SECCLASS_PROCESS,
6982 				     PROCESS__DYNTRANSITION, NULL);
6983 		if (error)
6984 			goto abort_change;
6985 
6986 		/* Check for ptracing, and update the task SID if ok.
6987 		   Otherwise, leave SID unchanged and fail. */
6988 		ptsid = ptrace_parent_sid();
6989 		if (ptsid != 0) {
6990 			error = avc_has_perm(ptsid, sid, SECCLASS_PROCESS,
6991 					     PROCESS__PTRACE, NULL);
6992 			if (error)
6993 				goto abort_change;
6994 		}
6995 
6996 		crsec->sid = sid;
6997 	} else {
6998 		error = -EINVAL;
6999 		goto abort_change;
7000 	}
7001 
7002 	commit_creds(new);
7003 	return size;
7004 
7005 abort_change:
7006 	abort_creds(new);
7007 	return error;
7008 }
7009 
7010 /**
7011  * selinux_getselfattr - Get SELinux current task attributes
7012  * @attr: the requested attribute
7013  * @ctx: buffer to receive the result
7014  * @size: buffer size (input), buffer size used (output)
7015  * @flags: unused
7016  *
7017  * Fill the passed user space @ctx with the details of the requested
7018  * attribute.
7019  *
7020  * Returns the number of attributes on success, an error code otherwise.
7021  * There will only ever be one attribute.
7022  */
7023 static int selinux_getselfattr(unsigned int attr, struct lsm_ctx __user *ctx,
7024 			       u32 *size, u32 flags)
7025 {
7026 	int rc;
7027 	char *val = NULL;
7028 	int val_len;
7029 
7030 	val_len = selinux_lsm_getattr(attr, current, &val);
7031 	if (val_len < 0)
7032 		return val_len;
7033 	rc = lsm_fill_user_ctx(ctx, size, val, val_len, LSM_ID_SELINUX, 0);
7034 	kfree(val);
7035 	return (!rc ? 1 : rc);
7036 }
7037 
7038 static int selinux_setselfattr(unsigned int attr, struct lsm_ctx *ctx,
7039 			       u32 size, u32 flags)
7040 {
7041 	int rc;
7042 
7043 	rc = selinux_lsm_setattr(attr, ctx->ctx, ctx->ctx_len);
7044 	if (rc > 0)
7045 		return 0;
7046 	return rc;
7047 }
7048 
7049 static int selinux_getprocattr(struct task_struct *p,
7050 			       const char *name, char **value)
7051 {
7052 	unsigned int attr = lsm_name_to_attr(name);
7053 	int rc;
7054 
7055 	if (attr) {
7056 		rc = selinux_lsm_getattr(attr, p, value);
7057 		if (rc != -EOPNOTSUPP)
7058 			return rc;
7059 	}
7060 
7061 	return -EINVAL;
7062 }
7063 
7064 static int selinux_setprocattr(const char *name, void *value, size_t size)
7065 {
7066 	int attr = lsm_name_to_attr(name);
7067 
7068 	if (attr)
7069 		return selinux_lsm_setattr(attr, value, size);
7070 	return -EINVAL;
7071 }
7072 
7073 static int selinux_ismaclabel(const char *name)
7074 {
7075 	return (strcmp(name, XATTR_SELINUX_SUFFIX) == 0);
7076 }
7077 
7078 static int selinux_secid_to_secctx(u32 secid, struct lsm_context *cp)
7079 {
7080 	u32 seclen;
7081 	int ret;
7082 
7083 	if (cp) {
7084 		cp->id = LSM_ID_SELINUX;
7085 		ret = security_sid_to_context(secid, &cp->context, &cp->len);
7086 		if (ret < 0)
7087 			return ret;
7088 		return cp->len;
7089 	}
7090 	ret = security_sid_to_context(secid, NULL, &seclen);
7091 	if (ret < 0)
7092 		return ret;
7093 	return seclen;
7094 }
7095 
7096 static int selinux_lsmprop_to_secctx(struct lsm_prop *prop,
7097 				     struct lsm_context *cp)
7098 {
7099 	return selinux_secid_to_secctx(prop->selinux.secid, cp);
7100 }
7101 
7102 static int selinux_secctx_to_secid(const char *secdata, u32 seclen, u32 *secid)
7103 {
7104 	return security_context_to_sid(secdata, seclen,
7105 				       secid, GFP_KERNEL);
7106 }
7107 
7108 static void selinux_release_secctx(struct lsm_context *cp)
7109 {
7110 	if (cp->id == LSM_ID_SELINUX) {
7111 		kfree(cp->context);
7112 		cp->context = NULL;
7113 		cp->id = LSM_ID_UNDEF;
7114 	}
7115 }
7116 
7117 static void selinux_inode_invalidate_secctx(struct inode *inode)
7118 {
7119 	struct inode_security_struct *isec = selinux_inode(inode);
7120 
7121 	spin_lock(&isec->lock);
7122 	isec->initialized = LABEL_INVALID;
7123 	spin_unlock(&isec->lock);
7124 }
7125 
7126 /*
7127  *	called with inode->i_mutex locked
7128  */
7129 static int selinux_inode_notifysecctx(struct inode *inode, void *ctx, u32 ctxlen)
7130 {
7131 	int rc = selinux_inode_setsecurity(inode, XATTR_SELINUX_SUFFIX,
7132 					   ctx, ctxlen, 0);
7133 	/* Do not return error when suppressing label (SBLABEL_MNT not set). */
7134 	return rc == -EOPNOTSUPP ? 0 : rc;
7135 }
7136 
7137 /*
7138  *	called with inode->i_mutex locked
7139  */
7140 static int selinux_inode_setsecctx(struct dentry *dentry, void *ctx, u32 ctxlen)
7141 {
7142 	return __vfs_setxattr_locked(&nop_mnt_idmap, dentry, XATTR_NAME_SELINUX,
7143 				     ctx, ctxlen, 0, NULL);
7144 }
7145 
7146 static int selinux_inode_getsecctx(struct inode *inode, struct lsm_context *cp)
7147 {
7148 	int len;
7149 	len = selinux_inode_getsecurity(&nop_mnt_idmap, inode,
7150 					XATTR_SELINUX_SUFFIX,
7151 					(void **)&cp->context, true);
7152 	if (len < 0)
7153 		return len;
7154 	cp->len = len;
7155 	cp->id = LSM_ID_SELINUX;
7156 	return 0;
7157 }
7158 #ifdef CONFIG_KEYS
7159 
7160 static int selinux_key_alloc(struct key *k, const struct cred *cred,
7161 			     unsigned long flags)
7162 {
7163 	const struct cred_security_struct *crsec;
7164 	struct key_security_struct *ksec = selinux_key(k);
7165 
7166 	crsec = selinux_cred(cred);
7167 	if (crsec->keycreate_sid)
7168 		ksec->sid = crsec->keycreate_sid;
7169 	else
7170 		ksec->sid = crsec->sid;
7171 
7172 	return 0;
7173 }
7174 
7175 static int selinux_key_permission(key_ref_t key_ref,
7176 				  const struct cred *cred,
7177 				  enum key_need_perm need_perm)
7178 {
7179 	struct key *key;
7180 	struct key_security_struct *ksec;
7181 	u32 perm, sid;
7182 
7183 	switch (need_perm) {
7184 	case KEY_NEED_VIEW:
7185 		perm = KEY__VIEW;
7186 		break;
7187 	case KEY_NEED_READ:
7188 		perm = KEY__READ;
7189 		break;
7190 	case KEY_NEED_WRITE:
7191 		perm = KEY__WRITE;
7192 		break;
7193 	case KEY_NEED_SEARCH:
7194 		perm = KEY__SEARCH;
7195 		break;
7196 	case KEY_NEED_LINK:
7197 		perm = KEY__LINK;
7198 		break;
7199 	case KEY_NEED_SETATTR:
7200 		perm = KEY__SETATTR;
7201 		break;
7202 	case KEY_NEED_UNLINK:
7203 	case KEY_SYSADMIN_OVERRIDE:
7204 	case KEY_AUTHTOKEN_OVERRIDE:
7205 	case KEY_DEFER_PERM_CHECK:
7206 		return 0;
7207 	default:
7208 		WARN_ON(1);
7209 		return -EPERM;
7210 
7211 	}
7212 
7213 	sid = cred_sid(cred);
7214 	key = key_ref_to_ptr(key_ref);
7215 	ksec = selinux_key(key);
7216 
7217 	return avc_has_perm(sid, ksec->sid, SECCLASS_KEY, perm, NULL);
7218 }
7219 
7220 static int selinux_key_getsecurity(struct key *key, char **_buffer)
7221 {
7222 	struct key_security_struct *ksec = selinux_key(key);
7223 	char *context = NULL;
7224 	unsigned len;
7225 	int rc;
7226 
7227 	rc = security_sid_to_context(ksec->sid,
7228 				     &context, &len);
7229 	if (!rc)
7230 		rc = len;
7231 	*_buffer = context;
7232 	return rc;
7233 }
7234 
7235 #ifdef CONFIG_KEY_NOTIFICATIONS
7236 static int selinux_watch_key(struct key *key)
7237 {
7238 	struct key_security_struct *ksec = selinux_key(key);
7239 	u32 sid = current_sid();
7240 
7241 	return avc_has_perm(sid, ksec->sid, SECCLASS_KEY, KEY__VIEW, NULL);
7242 }
7243 #endif
7244 #endif
7245 
7246 #ifdef CONFIG_SECURITY_INFINIBAND
7247 static int selinux_ib_pkey_access(void *ib_sec, u64 subnet_prefix, u16 pkey_val)
7248 {
7249 	struct common_audit_data ad;
7250 	int err;
7251 	u32 sid = 0;
7252 	struct ib_security_struct *sec = ib_sec;
7253 	struct lsm_ibpkey_audit ibpkey;
7254 
7255 	err = sel_ib_pkey_sid(subnet_prefix, pkey_val, &sid);
7256 	if (err)
7257 		return err;
7258 
7259 	ad.type = LSM_AUDIT_DATA_IBPKEY;
7260 	ibpkey.subnet_prefix = subnet_prefix;
7261 	ibpkey.pkey = pkey_val;
7262 	ad.u.ibpkey = &ibpkey;
7263 	return avc_has_perm(sec->sid, sid,
7264 			    SECCLASS_INFINIBAND_PKEY,
7265 			    INFINIBAND_PKEY__ACCESS, &ad);
7266 }
7267 
7268 static int selinux_ib_endport_manage_subnet(void *ib_sec, const char *dev_name,
7269 					    u8 port_num)
7270 {
7271 	struct common_audit_data ad;
7272 	int err;
7273 	u32 sid = 0;
7274 	struct ib_security_struct *sec = ib_sec;
7275 	struct lsm_ibendport_audit ibendport;
7276 
7277 	err = security_ib_endport_sid(dev_name, port_num,
7278 				      &sid);
7279 
7280 	if (err)
7281 		return err;
7282 
7283 	ad.type = LSM_AUDIT_DATA_IBENDPORT;
7284 	ibendport.dev_name = dev_name;
7285 	ibendport.port = port_num;
7286 	ad.u.ibendport = &ibendport;
7287 	return avc_has_perm(sec->sid, sid,
7288 			    SECCLASS_INFINIBAND_ENDPORT,
7289 			    INFINIBAND_ENDPORT__MANAGE_SUBNET, &ad);
7290 }
7291 
7292 static int selinux_ib_alloc_security(void *ib_sec)
7293 {
7294 	struct ib_security_struct *sec = selinux_ib(ib_sec);
7295 
7296 	sec->sid = current_sid();
7297 	return 0;
7298 }
7299 #endif
7300 
7301 #ifdef CONFIG_BPF_SYSCALL
7302 static int selinux_bpf(int cmd, union bpf_attr *attr,
7303 		       unsigned int size, bool kernel)
7304 {
7305 	u32 sid = current_sid();
7306 	int ret;
7307 
7308 	if (selinux_policycap_bpf_token_perms())
7309 		return 0;
7310 
7311 	switch (cmd) {
7312 	case BPF_MAP_CREATE:
7313 		ret = avc_has_perm(sid, sid, SECCLASS_BPF, BPF__MAP_CREATE,
7314 				   NULL);
7315 		break;
7316 	case BPF_PROG_LOAD:
7317 		ret = avc_has_perm(sid, sid, SECCLASS_BPF, BPF__PROG_LOAD,
7318 				   NULL);
7319 		break;
7320 	default:
7321 		ret = 0;
7322 		break;
7323 	}
7324 
7325 	return ret;
7326 }
7327 
7328 static u32 bpf_map_fmode_to_av(fmode_t fmode)
7329 {
7330 	u32 av = 0;
7331 
7332 	if (fmode & FMODE_READ)
7333 		av |= BPF__MAP_READ;
7334 	if (fmode & FMODE_WRITE)
7335 		av |= BPF__MAP_WRITE;
7336 	return av;
7337 }
7338 
7339 /* This function will check the file pass through unix socket or binder to see
7340  * if it is a bpf related object. And apply corresponding checks on the bpf
7341  * object based on the type. The bpf maps and programs, not like other files and
7342  * socket, are using a shared anonymous inode inside the kernel as their inode.
7343  * So checking that inode cannot identify if the process have privilege to
7344  * access the bpf object and that's why we have to add this additional check in
7345  * selinux_file_receive and selinux_binder_transfer_files.
7346  */
7347 static int bpf_fd_pass(const struct file *file, u32 sid)
7348 {
7349 	struct bpf_security_struct *bpfsec;
7350 	struct bpf_prog *prog;
7351 	struct bpf_map *map;
7352 	int ret;
7353 
7354 	if (file->f_op == &bpf_map_fops) {
7355 		map = file->private_data;
7356 		bpfsec = selinux_bpf_map_security(map);
7357 		ret = avc_has_perm(sid, bpfsec->sid, SECCLASS_BPF,
7358 				   bpf_map_fmode_to_av(file->f_mode), NULL);
7359 		if (ret)
7360 			return ret;
7361 	} else if (file->f_op == &bpf_prog_fops) {
7362 		prog = file->private_data;
7363 		bpfsec = selinux_bpf_prog_security(prog);
7364 		ret = avc_has_perm(sid, bpfsec->sid, SECCLASS_BPF,
7365 				   BPF__PROG_RUN, NULL);
7366 		if (ret)
7367 			return ret;
7368 	}
7369 	return 0;
7370 }
7371 
7372 static int selinux_bpf_map(struct bpf_map *map, fmode_t fmode)
7373 {
7374 	u32 sid = current_sid();
7375 	struct bpf_security_struct *bpfsec;
7376 
7377 	bpfsec = selinux_bpf_map_security(map);
7378 	return avc_has_perm(sid, bpfsec->sid, SECCLASS_BPF,
7379 			    bpf_map_fmode_to_av(fmode), NULL);
7380 }
7381 
7382 static int selinux_bpf_prog(struct bpf_prog *prog)
7383 {
7384 	u32 sid = current_sid();
7385 	struct bpf_security_struct *bpfsec;
7386 
7387 	bpfsec = selinux_bpf_prog_security(prog);
7388 	return avc_has_perm(sid, bpfsec->sid, SECCLASS_BPF,
7389 			    BPF__PROG_RUN, NULL);
7390 }
7391 
7392 static int selinux_bpf_map_create(struct bpf_map *map, union bpf_attr *attr,
7393 				  struct bpf_token *token, bool kernel)
7394 {
7395 	struct bpf_security_struct *bpfsec;
7396 	u32 ssid;
7397 
7398 	bpfsec = selinux_bpf_map_security(map);
7399 	bpfsec->sid = current_sid();
7400 
7401 	if (!token)
7402 		ssid = bpfsec->sid;
7403 	else
7404 		ssid = selinux_bpf_token_security(token)->grantor_sid;
7405 
7406 	return avc_has_perm(ssid, bpfsec->sid, SECCLASS_BPF, BPF__MAP_CREATE,
7407 			    NULL);
7408 }
7409 
7410 static int selinux_bpf_prog_load(struct bpf_prog *prog, union bpf_attr *attr,
7411 				 struct bpf_token *token, bool kernel)
7412 {
7413 	struct bpf_security_struct *bpfsec;
7414 	u32 ssid;
7415 
7416 	bpfsec = selinux_bpf_prog_security(prog);
7417 	bpfsec->sid = current_sid();
7418 
7419 	if (!token)
7420 		ssid = bpfsec->sid;
7421 	else
7422 		ssid = selinux_bpf_token_security(token)->grantor_sid;
7423 
7424 	return avc_has_perm(ssid, bpfsec->sid, SECCLASS_BPF, BPF__PROG_LOAD,
7425 			    NULL);
7426 }
7427 
7428 #define bpf_token_cmd(T, C) \
7429 	((T)->allowed_cmds & (1ULL << (C)))
7430 
7431 static int selinux_bpf_token_create(struct bpf_token *token,
7432 				    union bpf_attr *attr,
7433 				    const struct path *path)
7434 {
7435 	struct bpf_security_struct *bpfsec;
7436 	struct superblock_security_struct *sbsec;
7437 	int err;
7438 
7439 	sbsec = selinux_superblock(path->dentry->d_sb);
7440 
7441 	bpfsec = selinux_bpf_token_security(token);
7442 	bpfsec->sid = current_sid();
7443 	bpfsec->grantor_sid = sbsec->creator_sid;
7444 
7445 	bpfsec->perms = 0;
7446 	/**
7447 	 * 'token->allowed_cmds' is a bit mask of allowed commands
7448 	 * Convert the BPF command enum to a bitmask representing its position
7449 	 * in the allowed_cmds bitmap.
7450 	 */
7451 	if (bpf_token_cmd(token, BPF_MAP_CREATE)) {
7452 		err = avc_has_perm(bpfsec->sid, bpfsec->grantor_sid,
7453 				   SECCLASS_BPF, BPF__MAP_CREATE_AS, NULL);
7454 		if (err)
7455 			return err;
7456 		bpfsec->perms |= BPF__MAP_CREATE;
7457 	}
7458 	if (bpf_token_cmd(token, BPF_PROG_LOAD)) {
7459 		err = avc_has_perm(bpfsec->sid, bpfsec->grantor_sid,
7460 				   SECCLASS_BPF, BPF__PROG_LOAD_AS, NULL);
7461 		if (err)
7462 			return err;
7463 		bpfsec->perms |= BPF__PROG_LOAD;
7464 	}
7465 
7466 	return 0;
7467 }
7468 
7469 static int selinux_bpf_token_cmd(const struct bpf_token *token,
7470 				 enum bpf_cmd cmd)
7471 {
7472 	struct bpf_security_struct *bpfsec;
7473 
7474 	bpfsec = token->security;
7475 	switch (cmd) {
7476 	case BPF_MAP_CREATE:
7477 		if (!(bpfsec->perms & BPF__MAP_CREATE))
7478 			return -EACCES;
7479 		break;
7480 	case BPF_PROG_LOAD:
7481 		if (!(bpfsec->perms & BPF__PROG_LOAD))
7482 			return -EACCES;
7483 		break;
7484 	default:
7485 		break;
7486 	}
7487 
7488 	return 0;
7489 }
7490 
7491 static int selinux_bpf_token_capable(const struct bpf_token *token, int cap)
7492 {
7493 	u16 sclass;
7494 	struct bpf_security_struct *bpfsec = token->security;
7495 	bool initns = (token->userns == &init_user_ns);
7496 	u32 av = CAP_TO_MASK(cap);
7497 
7498 	switch (CAP_TO_INDEX(cap)) {
7499 	case 0:
7500 		sclass = initns ? SECCLASS_CAPABILITY : SECCLASS_CAP_USERNS;
7501 		break;
7502 	case 1:
7503 		sclass = initns ? SECCLASS_CAPABILITY2 : SECCLASS_CAP2_USERNS;
7504 		break;
7505 	default:
7506 		pr_err("SELinux:  out of range capability %d\n", cap);
7507 		return -EINVAL;
7508 	}
7509 
7510 	return avc_has_perm(current_sid(), bpfsec->grantor_sid, sclass, av,
7511 			    NULL);
7512 }
7513 #endif
7514 
7515 #ifdef CONFIG_PERF_EVENTS
7516 static int selinux_perf_event_open(int type)
7517 {
7518 	u32 requested, sid = current_sid();
7519 
7520 	if (type == PERF_SECURITY_OPEN)
7521 		requested = PERF_EVENT__OPEN;
7522 	else if (type == PERF_SECURITY_CPU)
7523 		requested = PERF_EVENT__CPU;
7524 	else if (type == PERF_SECURITY_KERNEL)
7525 		requested = PERF_EVENT__KERNEL;
7526 	else if (type == PERF_SECURITY_TRACEPOINT)
7527 		requested = PERF_EVENT__TRACEPOINT;
7528 	else
7529 		return -EINVAL;
7530 
7531 	return avc_has_perm(sid, sid, SECCLASS_PERF_EVENT,
7532 			    requested, NULL);
7533 }
7534 
7535 static int selinux_perf_event_alloc(struct perf_event *event)
7536 {
7537 	struct perf_event_security_struct *perfsec;
7538 
7539 	perfsec = selinux_perf_event(event->security);
7540 	perfsec->sid = current_sid();
7541 
7542 	return 0;
7543 }
7544 
7545 static int selinux_perf_event_read(struct perf_event *event)
7546 {
7547 	struct perf_event_security_struct *perfsec = event->security;
7548 	u32 sid = current_sid();
7549 
7550 	return avc_has_perm(sid, perfsec->sid,
7551 			    SECCLASS_PERF_EVENT, PERF_EVENT__READ, NULL);
7552 }
7553 
7554 static int selinux_perf_event_write(struct perf_event *event)
7555 {
7556 	struct perf_event_security_struct *perfsec = event->security;
7557 	u32 sid = current_sid();
7558 
7559 	return avc_has_perm(sid, perfsec->sid,
7560 			    SECCLASS_PERF_EVENT, PERF_EVENT__WRITE, NULL);
7561 }
7562 #endif
7563 
7564 #ifdef CONFIG_IO_URING
7565 /**
7566  * selinux_uring_override_creds - check the requested cred override
7567  * @new: the target creds
7568  *
7569  * Check to see if the current task is allowed to override it's credentials
7570  * to service an io_uring operation.
7571  */
7572 static int selinux_uring_override_creds(const struct cred *new)
7573 {
7574 	return avc_has_perm(current_sid(), cred_sid(new),
7575 			    SECCLASS_IO_URING, IO_URING__OVERRIDE_CREDS, NULL);
7576 }
7577 
7578 /**
7579  * selinux_uring_sqpoll - check if a io_uring polling thread can be created
7580  *
7581  * Check to see if the current task is allowed to create a new io_uring
7582  * kernel polling thread.
7583  */
7584 static int selinux_uring_sqpoll(void)
7585 {
7586 	u32 sid = current_sid();
7587 
7588 	return avc_has_perm(sid, sid,
7589 			    SECCLASS_IO_URING, IO_URING__SQPOLL, NULL);
7590 }
7591 
7592 /**
7593  * selinux_uring_cmd - check if IORING_OP_URING_CMD is allowed
7594  * @ioucmd: the io_uring command structure
7595  *
7596  * Check to see if the current domain is allowed to execute an
7597  * IORING_OP_URING_CMD against the device/file specified in @ioucmd.
7598  *
7599  */
7600 static int selinux_uring_cmd(struct io_uring_cmd *ioucmd)
7601 {
7602 	struct file *file = ioucmd->file;
7603 	struct inode *inode = file_inode(file);
7604 	struct inode_security_struct *isec = selinux_inode(inode);
7605 	struct common_audit_data ad;
7606 
7607 	ad.type = LSM_AUDIT_DATA_FILE;
7608 	ad.u.file = file;
7609 
7610 	return avc_has_perm(current_sid(), isec->sid,
7611 			    SECCLASS_IO_URING, IO_URING__CMD, &ad);
7612 }
7613 
7614 /**
7615  * selinux_uring_allowed - check if io_uring_setup() can be called
7616  *
7617  * Check to see if the current task is allowed to call io_uring_setup().
7618  */
7619 static int selinux_uring_allowed(void)
7620 {
7621 	u32 sid = current_sid();
7622 
7623 	return avc_has_perm(sid, sid, SECCLASS_IO_URING, IO_URING__ALLOWED,
7624 			    NULL);
7625 }
7626 #endif /* CONFIG_IO_URING */
7627 
7628 static const struct lsm_id selinux_lsmid = {
7629 	.name = "selinux",
7630 	.id = LSM_ID_SELINUX,
7631 };
7632 
7633 struct lsm_blob_sizes selinux_blob_sizes __ro_after_init = {
7634 	.lbs_cred = sizeof(struct cred_security_struct),
7635 	.lbs_task = sizeof(struct task_security_struct),
7636 	.lbs_file = sizeof(struct file_security_struct),
7637 	.lbs_backing_file = sizeof(struct backing_file_security_struct),
7638 	.lbs_inode = sizeof(struct inode_security_struct),
7639 	.lbs_ipc = sizeof(struct ipc_security_struct),
7640 	.lbs_key = sizeof(struct key_security_struct),
7641 	.lbs_msg_msg = sizeof(struct msg_security_struct),
7642 #ifdef CONFIG_PERF_EVENTS
7643 	.lbs_perf_event = sizeof(struct perf_event_security_struct),
7644 #endif
7645 	.lbs_sock = sizeof(struct sk_security_struct),
7646 	.lbs_superblock = sizeof(struct superblock_security_struct),
7647 	.lbs_xattr_count = SELINUX_INODE_INIT_XATTRS,
7648 	.lbs_tun_dev = sizeof(struct tun_security_struct),
7649 	.lbs_ib = sizeof(struct ib_security_struct),
7650 	.lbs_bpf_map = sizeof(struct bpf_security_struct),
7651 	.lbs_bpf_prog = sizeof(struct bpf_security_struct),
7652 	.lbs_bpf_token = sizeof(struct bpf_security_struct),
7653 };
7654 
7655 /*
7656  * IMPORTANT NOTE: When adding new hooks, please be careful to keep this order:
7657  * 1. any hooks that don't belong to (2.) or (3.) below,
7658  * 2. hooks that both access structures allocated by other hooks, and allocate
7659  *    structures that can be later accessed by other hooks (mostly "cloning"
7660  *    hooks),
7661  * 3. hooks that only allocate structures that can be later accessed by other
7662  *    hooks ("allocating" hooks).
7663  *
7664  * Please follow block comment delimiters in the list to keep this order.
7665  */
7666 static struct security_hook_list selinux_hooks[] __ro_after_init = {
7667 	LSM_HOOK_INIT(binder_set_context_mgr, selinux_binder_set_context_mgr),
7668 	LSM_HOOK_INIT(binder_transaction, selinux_binder_transaction),
7669 	LSM_HOOK_INIT(binder_transfer_binder, selinux_binder_transfer_binder),
7670 	LSM_HOOK_INIT(binder_transfer_file, selinux_binder_transfer_file),
7671 
7672 	LSM_HOOK_INIT(ptrace_access_check, selinux_ptrace_access_check),
7673 	LSM_HOOK_INIT(ptrace_traceme, selinux_ptrace_traceme),
7674 	LSM_HOOK_INIT(capget, selinux_capget),
7675 	LSM_HOOK_INIT(capset, selinux_capset),
7676 	LSM_HOOK_INIT(capable, selinux_capable),
7677 	LSM_HOOK_INIT(quotactl, selinux_quotactl),
7678 	LSM_HOOK_INIT(quota_on, selinux_quota_on),
7679 	LSM_HOOK_INIT(syslog, selinux_syslog),
7680 	LSM_HOOK_INIT(vm_enough_memory, selinux_vm_enough_memory),
7681 
7682 	LSM_HOOK_INIT(netlink_send, selinux_netlink_send),
7683 
7684 	LSM_HOOK_INIT(bprm_creds_for_exec, selinux_bprm_creds_for_exec),
7685 	LSM_HOOK_INIT(bprm_committing_creds, selinux_bprm_committing_creds),
7686 	LSM_HOOK_INIT(bprm_committed_creds, selinux_bprm_committed_creds),
7687 
7688 	LSM_HOOK_INIT(sb_free_mnt_opts, selinux_free_mnt_opts),
7689 	LSM_HOOK_INIT(sb_mnt_opts_compat, selinux_sb_mnt_opts_compat),
7690 	LSM_HOOK_INIT(sb_remount, selinux_sb_remount),
7691 	LSM_HOOK_INIT(sb_kern_mount, selinux_sb_kern_mount),
7692 	LSM_HOOK_INIT(sb_show_options, selinux_sb_show_options),
7693 	LSM_HOOK_INIT(sb_statfs, selinux_sb_statfs),
7694 	LSM_HOOK_INIT(sb_mount, selinux_mount),
7695 	LSM_HOOK_INIT(sb_umount, selinux_umount),
7696 	LSM_HOOK_INIT(sb_set_mnt_opts, selinux_set_mnt_opts),
7697 	LSM_HOOK_INIT(sb_clone_mnt_opts, selinux_sb_clone_mnt_opts),
7698 
7699 	LSM_HOOK_INIT(move_mount, selinux_move_mount),
7700 
7701 	LSM_HOOK_INIT(dentry_init_security, selinux_dentry_init_security),
7702 	LSM_HOOK_INIT(dentry_create_files_as, selinux_dentry_create_files_as),
7703 
7704 	LSM_HOOK_INIT(inode_free_security, selinux_inode_free_security),
7705 	LSM_HOOK_INIT(inode_init_security, selinux_inode_init_security),
7706 	LSM_HOOK_INIT(inode_init_security_anon, selinux_inode_init_security_anon),
7707 	LSM_HOOK_INIT(inode_create, selinux_inode_create),
7708 	LSM_HOOK_INIT(inode_link, selinux_inode_link),
7709 	LSM_HOOK_INIT(inode_unlink, selinux_inode_unlink),
7710 	LSM_HOOK_INIT(inode_symlink, selinux_inode_symlink),
7711 	LSM_HOOK_INIT(inode_mkdir, selinux_inode_mkdir),
7712 	LSM_HOOK_INIT(inode_rmdir, selinux_inode_rmdir),
7713 	LSM_HOOK_INIT(inode_mknod, selinux_inode_mknod),
7714 	LSM_HOOK_INIT(inode_rename, selinux_inode_rename),
7715 	LSM_HOOK_INIT(inode_readlink, selinux_inode_readlink),
7716 	LSM_HOOK_INIT(inode_follow_link, selinux_inode_follow_link),
7717 	LSM_HOOK_INIT(inode_permission, selinux_inode_permission),
7718 	LSM_HOOK_INIT(inode_setattr, selinux_inode_setattr),
7719 	LSM_HOOK_INIT(inode_getattr, selinux_inode_getattr),
7720 	LSM_HOOK_INIT(inode_xattr_skipcap, selinux_inode_xattr_skipcap),
7721 	LSM_HOOK_INIT(inode_setxattr, selinux_inode_setxattr),
7722 	LSM_HOOK_INIT(inode_post_setxattr, selinux_inode_post_setxattr),
7723 	LSM_HOOK_INIT(inode_getxattr, selinux_inode_getxattr),
7724 	LSM_HOOK_INIT(inode_listxattr, selinux_inode_listxattr),
7725 	LSM_HOOK_INIT(inode_removexattr, selinux_inode_removexattr),
7726 	LSM_HOOK_INIT(inode_file_getattr, selinux_inode_file_getattr),
7727 	LSM_HOOK_INIT(inode_file_setattr, selinux_inode_file_setattr),
7728 	LSM_HOOK_INIT(inode_set_acl, selinux_inode_set_acl),
7729 	LSM_HOOK_INIT(inode_get_acl, selinux_inode_get_acl),
7730 	LSM_HOOK_INIT(inode_remove_acl, selinux_inode_remove_acl),
7731 	LSM_HOOK_INIT(inode_getsecurity, selinux_inode_getsecurity),
7732 	LSM_HOOK_INIT(inode_setsecurity, selinux_inode_setsecurity),
7733 	LSM_HOOK_INIT(inode_listsecurity, selinux_inode_listsecurity),
7734 	LSM_HOOK_INIT(inode_getlsmprop, selinux_inode_getlsmprop),
7735 	LSM_HOOK_INIT(inode_copy_up, selinux_inode_copy_up),
7736 	LSM_HOOK_INIT(inode_copy_up_xattr, selinux_inode_copy_up_xattr),
7737 	LSM_HOOK_INIT(path_notify, selinux_path_notify),
7738 
7739 	LSM_HOOK_INIT(kernfs_init_security, selinux_kernfs_init_security),
7740 
7741 	LSM_HOOK_INIT(file_permission, selinux_file_permission),
7742 	LSM_HOOK_INIT(file_alloc_security, selinux_file_alloc_security),
7743 	LSM_HOOK_INIT(backing_file_alloc, selinux_backing_file_alloc),
7744 	LSM_HOOK_INIT(backing_file_free, selinux_backing_file_free),
7745 	LSM_HOOK_INIT(file_ioctl, selinux_file_ioctl),
7746 	LSM_HOOK_INIT(file_ioctl_compat, selinux_file_ioctl_compat),
7747 	LSM_HOOK_INIT(mmap_file, selinux_mmap_file),
7748 	LSM_HOOK_INIT(mmap_backing_file, selinux_mmap_backing_file),
7749 	LSM_HOOK_INIT(mmap_addr, selinux_mmap_addr),
7750 	LSM_HOOK_INIT(file_mprotect, selinux_file_mprotect),
7751 	LSM_HOOK_INIT(file_lock, selinux_file_lock),
7752 	LSM_HOOK_INIT(file_fcntl, selinux_file_fcntl),
7753 	LSM_HOOK_INIT(file_set_fowner, selinux_file_set_fowner),
7754 	LSM_HOOK_INIT(file_send_sigiotask, selinux_file_send_sigiotask),
7755 	LSM_HOOK_INIT(file_receive, selinux_file_receive),
7756 
7757 	LSM_HOOK_INIT(file_open, selinux_file_open),
7758 
7759 	LSM_HOOK_INIT(task_alloc, selinux_task_alloc),
7760 	LSM_HOOK_INIT(cred_prepare, selinux_cred_prepare),
7761 	LSM_HOOK_INIT(cred_transfer, selinux_cred_transfer),
7762 	LSM_HOOK_INIT(cred_getsecid, selinux_cred_getsecid),
7763 	LSM_HOOK_INIT(cred_getlsmprop, selinux_cred_getlsmprop),
7764 	LSM_HOOK_INIT(kernel_act_as, selinux_kernel_act_as),
7765 	LSM_HOOK_INIT(kernel_create_files_as, selinux_kernel_create_files_as),
7766 	LSM_HOOK_INIT(kernel_module_request, selinux_kernel_module_request),
7767 	LSM_HOOK_INIT(kernel_load_data, selinux_kernel_load_data),
7768 	LSM_HOOK_INIT(kernel_read_file, selinux_kernel_read_file),
7769 	LSM_HOOK_INIT(task_setpgid, selinux_task_setpgid),
7770 	LSM_HOOK_INIT(task_getpgid, selinux_task_getpgid),
7771 	LSM_HOOK_INIT(task_getsid, selinux_task_getsid),
7772 	LSM_HOOK_INIT(current_getlsmprop_subj, selinux_current_getlsmprop_subj),
7773 	LSM_HOOK_INIT(task_getlsmprop_obj, selinux_task_getlsmprop_obj),
7774 	LSM_HOOK_INIT(task_setnice, selinux_task_setnice),
7775 	LSM_HOOK_INIT(task_setioprio, selinux_task_setioprio),
7776 	LSM_HOOK_INIT(task_getioprio, selinux_task_getioprio),
7777 	LSM_HOOK_INIT(task_prlimit, selinux_task_prlimit),
7778 	LSM_HOOK_INIT(task_setrlimit, selinux_task_setrlimit),
7779 	LSM_HOOK_INIT(task_setscheduler, selinux_task_setscheduler),
7780 	LSM_HOOK_INIT(task_getscheduler, selinux_task_getscheduler),
7781 	LSM_HOOK_INIT(task_movememory, selinux_task_movememory),
7782 	LSM_HOOK_INIT(task_kill, selinux_task_kill),
7783 	LSM_HOOK_INIT(task_to_inode, selinux_task_to_inode),
7784 	LSM_HOOK_INIT(userns_create, selinux_userns_create),
7785 
7786 	LSM_HOOK_INIT(ipc_permission, selinux_ipc_permission),
7787 	LSM_HOOK_INIT(ipc_getlsmprop, selinux_ipc_getlsmprop),
7788 
7789 	LSM_HOOK_INIT(msg_queue_associate, selinux_msg_queue_associate),
7790 	LSM_HOOK_INIT(msg_queue_msgctl, selinux_msg_queue_msgctl),
7791 	LSM_HOOK_INIT(msg_queue_msgsnd, selinux_msg_queue_msgsnd),
7792 	LSM_HOOK_INIT(msg_queue_msgrcv, selinux_msg_queue_msgrcv),
7793 
7794 	LSM_HOOK_INIT(shm_associate, selinux_shm_associate),
7795 	LSM_HOOK_INIT(shm_shmctl, selinux_shm_shmctl),
7796 	LSM_HOOK_INIT(shm_shmat, selinux_shm_shmat),
7797 
7798 	LSM_HOOK_INIT(sem_associate, selinux_sem_associate),
7799 	LSM_HOOK_INIT(sem_semctl, selinux_sem_semctl),
7800 	LSM_HOOK_INIT(sem_semop, selinux_sem_semop),
7801 
7802 	LSM_HOOK_INIT(d_instantiate, selinux_d_instantiate),
7803 
7804 	LSM_HOOK_INIT(getselfattr, selinux_getselfattr),
7805 	LSM_HOOK_INIT(setselfattr, selinux_setselfattr),
7806 	LSM_HOOK_INIT(getprocattr, selinux_getprocattr),
7807 	LSM_HOOK_INIT(setprocattr, selinux_setprocattr),
7808 
7809 	LSM_HOOK_INIT(ismaclabel, selinux_ismaclabel),
7810 	LSM_HOOK_INIT(secctx_to_secid, selinux_secctx_to_secid),
7811 	LSM_HOOK_INIT(release_secctx, selinux_release_secctx),
7812 	LSM_HOOK_INIT(inode_invalidate_secctx, selinux_inode_invalidate_secctx),
7813 	LSM_HOOK_INIT(inode_notifysecctx, selinux_inode_notifysecctx),
7814 	LSM_HOOK_INIT(inode_setsecctx, selinux_inode_setsecctx),
7815 
7816 	LSM_HOOK_INIT(unix_stream_connect, selinux_socket_unix_stream_connect),
7817 	LSM_HOOK_INIT(unix_may_send, selinux_socket_unix_may_send),
7818 
7819 	LSM_HOOK_INIT(socket_create, selinux_socket_create),
7820 	LSM_HOOK_INIT(socket_post_create, selinux_socket_post_create),
7821 	LSM_HOOK_INIT(socket_socketpair, selinux_socket_socketpair),
7822 	LSM_HOOK_INIT(socket_bind, selinux_socket_bind),
7823 	LSM_HOOK_INIT(socket_connect, selinux_socket_connect),
7824 	LSM_HOOK_INIT(socket_listen, selinux_socket_listen),
7825 	LSM_HOOK_INIT(socket_accept, selinux_socket_accept),
7826 	LSM_HOOK_INIT(socket_sendmsg, selinux_socket_sendmsg),
7827 	LSM_HOOK_INIT(socket_recvmsg, selinux_socket_recvmsg),
7828 	LSM_HOOK_INIT(socket_getsockname, selinux_socket_getsockname),
7829 	LSM_HOOK_INIT(socket_getpeername, selinux_socket_getpeername),
7830 	LSM_HOOK_INIT(socket_getsockopt, selinux_socket_getsockopt),
7831 	LSM_HOOK_INIT(socket_setsockopt, selinux_socket_setsockopt),
7832 	LSM_HOOK_INIT(socket_shutdown, selinux_socket_shutdown),
7833 	LSM_HOOK_INIT(socket_sock_rcv_skb, selinux_socket_sock_rcv_skb),
7834 	LSM_HOOK_INIT(socket_getpeersec_stream,
7835 			selinux_socket_getpeersec_stream),
7836 	LSM_HOOK_INIT(socket_getpeersec_dgram, selinux_socket_getpeersec_dgram),
7837 	LSM_HOOK_INIT(sk_free_security, selinux_sk_free_security),
7838 	LSM_HOOK_INIT(sk_clone_security, selinux_sk_clone_security),
7839 	LSM_HOOK_INIT(sk_getsecid, selinux_sk_getsecid),
7840 	LSM_HOOK_INIT(sock_graft, selinux_sock_graft),
7841 	LSM_HOOK_INIT(sctp_assoc_request, selinux_sctp_assoc_request),
7842 	LSM_HOOK_INIT(sctp_sk_clone, selinux_sctp_sk_clone),
7843 	LSM_HOOK_INIT(sctp_bind_connect, selinux_sctp_bind_connect),
7844 	LSM_HOOK_INIT(sctp_assoc_established, selinux_sctp_assoc_established),
7845 	LSM_HOOK_INIT(mptcp_add_subflow, selinux_mptcp_add_subflow),
7846 	LSM_HOOK_INIT(inet_conn_request, selinux_inet_conn_request),
7847 	LSM_HOOK_INIT(inet_csk_clone, selinux_inet_csk_clone),
7848 	LSM_HOOK_INIT(inet_conn_established, selinux_inet_conn_established),
7849 	LSM_HOOK_INIT(secmark_relabel_packet, selinux_secmark_relabel_packet),
7850 	LSM_HOOK_INIT(secmark_refcount_inc, selinux_secmark_refcount_inc),
7851 	LSM_HOOK_INIT(secmark_refcount_dec, selinux_secmark_refcount_dec),
7852 	LSM_HOOK_INIT(req_classify_flow, selinux_req_classify_flow),
7853 	LSM_HOOK_INIT(tun_dev_create, selinux_tun_dev_create),
7854 	LSM_HOOK_INIT(tun_dev_attach_queue, selinux_tun_dev_attach_queue),
7855 	LSM_HOOK_INIT(tun_dev_attach, selinux_tun_dev_attach),
7856 	LSM_HOOK_INIT(tun_dev_open, selinux_tun_dev_open),
7857 #ifdef CONFIG_SECURITY_INFINIBAND
7858 	LSM_HOOK_INIT(ib_pkey_access, selinux_ib_pkey_access),
7859 	LSM_HOOK_INIT(ib_endport_manage_subnet,
7860 		      selinux_ib_endport_manage_subnet),
7861 #endif
7862 #ifdef CONFIG_SECURITY_NETWORK_XFRM
7863 	LSM_HOOK_INIT(xfrm_policy_free_security, selinux_xfrm_policy_free),
7864 	LSM_HOOK_INIT(xfrm_policy_delete_security, selinux_xfrm_policy_delete),
7865 	LSM_HOOK_INIT(xfrm_state_free_security, selinux_xfrm_state_free),
7866 	LSM_HOOK_INIT(xfrm_state_delete_security, selinux_xfrm_state_delete),
7867 	LSM_HOOK_INIT(xfrm_policy_lookup, selinux_xfrm_policy_lookup),
7868 	LSM_HOOK_INIT(xfrm_state_pol_flow_match,
7869 			selinux_xfrm_state_pol_flow_match),
7870 	LSM_HOOK_INIT(xfrm_decode_session, selinux_xfrm_decode_session),
7871 #endif
7872 
7873 #ifdef CONFIG_KEYS
7874 	LSM_HOOK_INIT(key_permission, selinux_key_permission),
7875 	LSM_HOOK_INIT(key_getsecurity, selinux_key_getsecurity),
7876 #ifdef CONFIG_KEY_NOTIFICATIONS
7877 	LSM_HOOK_INIT(watch_key, selinux_watch_key),
7878 #endif
7879 #endif
7880 
7881 #ifdef CONFIG_AUDIT
7882 	LSM_HOOK_INIT(audit_rule_known, selinux_audit_rule_known),
7883 	LSM_HOOK_INIT(audit_rule_match, selinux_audit_rule_match),
7884 	LSM_HOOK_INIT(audit_rule_free, selinux_audit_rule_free),
7885 #endif
7886 
7887 #ifdef CONFIG_BPF_SYSCALL
7888 	LSM_HOOK_INIT(bpf, selinux_bpf),
7889 	LSM_HOOK_INIT(bpf_map, selinux_bpf_map),
7890 	LSM_HOOK_INIT(bpf_prog, selinux_bpf_prog),
7891 #endif
7892 
7893 #ifdef CONFIG_PERF_EVENTS
7894 	LSM_HOOK_INIT(perf_event_open, selinux_perf_event_open),
7895 	LSM_HOOK_INIT(perf_event_read, selinux_perf_event_read),
7896 	LSM_HOOK_INIT(perf_event_write, selinux_perf_event_write),
7897 #endif
7898 
7899 #ifdef CONFIG_IO_URING
7900 	LSM_HOOK_INIT(uring_override_creds, selinux_uring_override_creds),
7901 	LSM_HOOK_INIT(uring_sqpoll, selinux_uring_sqpoll),
7902 	LSM_HOOK_INIT(uring_cmd, selinux_uring_cmd),
7903 	LSM_HOOK_INIT(uring_allowed, selinux_uring_allowed),
7904 #endif
7905 
7906 	/*
7907 	 * PUT "CLONING" (ACCESSING + ALLOCATING) HOOKS HERE
7908 	 */
7909 	LSM_HOOK_INIT(fs_context_submount, selinux_fs_context_submount),
7910 	LSM_HOOK_INIT(fs_context_dup, selinux_fs_context_dup),
7911 	LSM_HOOK_INIT(fs_context_parse_param, selinux_fs_context_parse_param),
7912 	LSM_HOOK_INIT(sb_eat_lsm_opts, selinux_sb_eat_lsm_opts),
7913 #ifdef CONFIG_SECURITY_NETWORK_XFRM
7914 	LSM_HOOK_INIT(xfrm_policy_clone_security, selinux_xfrm_policy_clone),
7915 #endif
7916 
7917 	/*
7918 	 * PUT "ALLOCATING" HOOKS HERE
7919 	 */
7920 	LSM_HOOK_INIT(msg_msg_alloc_security, selinux_msg_msg_alloc_security),
7921 	LSM_HOOK_INIT(msg_queue_alloc_security,
7922 		      selinux_msg_queue_alloc_security),
7923 	LSM_HOOK_INIT(shm_alloc_security, selinux_shm_alloc_security),
7924 	LSM_HOOK_INIT(sb_alloc_security, selinux_sb_alloc_security),
7925 	LSM_HOOK_INIT(inode_alloc_security, selinux_inode_alloc_security),
7926 	LSM_HOOK_INIT(sem_alloc_security, selinux_sem_alloc_security),
7927 	LSM_HOOK_INIT(secid_to_secctx, selinux_secid_to_secctx),
7928 	LSM_HOOK_INIT(lsmprop_to_secctx, selinux_lsmprop_to_secctx),
7929 	LSM_HOOK_INIT(inode_getsecctx, selinux_inode_getsecctx),
7930 	LSM_HOOK_INIT(sk_alloc_security, selinux_sk_alloc_security),
7931 	LSM_HOOK_INIT(tun_dev_alloc_security, selinux_tun_dev_alloc_security),
7932 #ifdef CONFIG_SECURITY_INFINIBAND
7933 	LSM_HOOK_INIT(ib_alloc_security, selinux_ib_alloc_security),
7934 #endif
7935 #ifdef CONFIG_SECURITY_NETWORK_XFRM
7936 	LSM_HOOK_INIT(xfrm_policy_alloc_security, selinux_xfrm_policy_alloc),
7937 	LSM_HOOK_INIT(xfrm_state_alloc, selinux_xfrm_state_alloc),
7938 	LSM_HOOK_INIT(xfrm_state_alloc_acquire,
7939 		      selinux_xfrm_state_alloc_acquire),
7940 #endif
7941 #ifdef CONFIG_KEYS
7942 	LSM_HOOK_INIT(key_alloc, selinux_key_alloc),
7943 #endif
7944 #ifdef CONFIG_AUDIT
7945 	LSM_HOOK_INIT(audit_rule_init, selinux_audit_rule_init),
7946 #endif
7947 #ifdef CONFIG_BPF_SYSCALL
7948 	LSM_HOOK_INIT(bpf_map_create, selinux_bpf_map_create),
7949 	LSM_HOOK_INIT(bpf_prog_load, selinux_bpf_prog_load),
7950 	LSM_HOOK_INIT(bpf_token_create, selinux_bpf_token_create),
7951 	LSM_HOOK_INIT(bpf_token_cmd, selinux_bpf_token_cmd),
7952 	LSM_HOOK_INIT(bpf_token_capable, selinux_bpf_token_capable),
7953 #endif
7954 #ifdef CONFIG_PERF_EVENTS
7955 	LSM_HOOK_INIT(perf_event_alloc, selinux_perf_event_alloc),
7956 #endif
7957 };
7958 
7959 static __init int selinux_init(void)
7960 {
7961 	vma_flags_t data_default_flags = VMA_DATA_DEFAULT_FLAGS;
7962 
7963 	pr_info("SELinux:  Initializing.\n");
7964 
7965 	memset(&selinux_state, 0, sizeof(selinux_state));
7966 	enforcing_set(selinux_enforcing_boot);
7967 	selinux_avc_init();
7968 	mutex_init(&selinux_state.status_lock);
7969 	mutex_init(&selinux_state.policy_mutex);
7970 
7971 	/* Set the security state for the initial task. */
7972 	cred_init_security();
7973 
7974 	/* Inform the audit system that secctx is used */
7975 	audit_cfg_lsm(&selinux_lsmid,
7976 		      AUDIT_CFG_LSM_SECCTX_SUBJECT |
7977 		      AUDIT_CFG_LSM_SECCTX_OBJECT);
7978 
7979 	default_noexec = !vma_flags_test(&data_default_flags, VMA_EXEC_BIT);
7980 	if (!default_noexec)
7981 		pr_notice("SELinux:  virtual memory is executable by default\n");
7982 
7983 	avc_init();
7984 
7985 	avtab_cache_init();
7986 
7987 	ebitmap_cache_init();
7988 
7989 	hashtab_cache_init();
7990 
7991 	selinux_ima_config_len_init();
7992 
7993 	security_add_hooks(selinux_hooks, ARRAY_SIZE(selinux_hooks),
7994 			   &selinux_lsmid);
7995 
7996 	if (avc_add_callback(selinux_netcache_avc_callback, AVC_CALLBACK_RESET))
7997 		panic("SELinux: Unable to register AVC netcache callback\n");
7998 
7999 	if (avc_add_callback(selinux_lsm_notifier_avc_callback, AVC_CALLBACK_RESET))
8000 		panic("SELinux: Unable to register AVC LSM notifier callback\n");
8001 
8002 	if (avc_add_callback(selinux_audit_rule_avc_callback,
8003 			     AVC_CALLBACK_RESET))
8004 		panic("SELinux: Unable to register AVC audit callback\n");
8005 
8006 	if (selinux_enforcing_boot)
8007 		pr_debug("SELinux:  Starting in enforcing mode\n");
8008 	else
8009 		pr_debug("SELinux:  Starting in permissive mode\n");
8010 
8011 	fs_validate_description("selinux", selinux_fs_parameters);
8012 
8013 	return 0;
8014 }
8015 
8016 static void delayed_superblock_init(struct super_block *sb, void *unused)
8017 {
8018 	selinux_set_mnt_opts(sb, NULL, 0, NULL);
8019 }
8020 
8021 void selinux_complete_init(void)
8022 {
8023 	pr_debug("SELinux:  Completing initialization.\n");
8024 
8025 	/* Set up any superblocks initialized prior to the policy load. */
8026 	pr_debug("SELinux:  Setting up existing superblocks.\n");
8027 	iterate_supers(delayed_superblock_init, NULL);
8028 }
8029 
8030 /* SELinux requires early initialization in order to label
8031    all processes and objects when they are created. */
8032 DEFINE_LSM(selinux) = {
8033 	.id = &selinux_lsmid,
8034 	.flags = LSM_FLAG_LEGACY_MAJOR | LSM_FLAG_EXCLUSIVE,
8035 	.enabled = &selinux_enabled_boot,
8036 	.blobs = &selinux_blob_sizes,
8037 	.init = selinux_init,
8038 	.initcall_device = selinux_initcall,
8039 };
8040 
8041 #if defined(CONFIG_NETFILTER)
8042 static const struct nf_hook_ops selinux_nf_ops[] = {
8043 	{
8044 		.hook =		selinux_ip_postroute,
8045 		.pf =		NFPROTO_IPV4,
8046 		.hooknum =	NF_INET_POST_ROUTING,
8047 		.priority =	NF_IP_PRI_SELINUX_LAST,
8048 	},
8049 	{
8050 		.hook =		selinux_ip_forward,
8051 		.pf =		NFPROTO_IPV4,
8052 		.hooknum =	NF_INET_FORWARD,
8053 		.priority =	NF_IP_PRI_SELINUX_FIRST,
8054 	},
8055 	{
8056 		.hook =		selinux_ip_output,
8057 		.pf =		NFPROTO_IPV4,
8058 		.hooknum =	NF_INET_LOCAL_OUT,
8059 		.priority =	NF_IP_PRI_SELINUX_FIRST,
8060 	},
8061 #if IS_ENABLED(CONFIG_IPV6)
8062 	{
8063 		.hook =		selinux_ip_postroute,
8064 		.pf =		NFPROTO_IPV6,
8065 		.hooknum =	NF_INET_POST_ROUTING,
8066 		.priority =	NF_IP6_PRI_SELINUX_LAST,
8067 	},
8068 	{
8069 		.hook =		selinux_ip_forward,
8070 		.pf =		NFPROTO_IPV6,
8071 		.hooknum =	NF_INET_FORWARD,
8072 		.priority =	NF_IP6_PRI_SELINUX_FIRST,
8073 	},
8074 	{
8075 		.hook =		selinux_ip_output,
8076 		.pf =		NFPROTO_IPV6,
8077 		.hooknum =	NF_INET_LOCAL_OUT,
8078 		.priority =	NF_IP6_PRI_SELINUX_FIRST,
8079 	},
8080 #endif	/* IPV6 */
8081 };
8082 
8083 static int __net_init selinux_nf_register(struct net *net)
8084 {
8085 	return nf_register_net_hooks(net, selinux_nf_ops,
8086 				     ARRAY_SIZE(selinux_nf_ops));
8087 }
8088 
8089 static void __net_exit selinux_nf_unregister(struct net *net)
8090 {
8091 	nf_unregister_net_hooks(net, selinux_nf_ops,
8092 				ARRAY_SIZE(selinux_nf_ops));
8093 }
8094 
8095 static struct pernet_operations selinux_net_ops = {
8096 	.init = selinux_nf_register,
8097 	.exit = selinux_nf_unregister,
8098 };
8099 
8100 int __init selinux_nf_ip_init(void)
8101 {
8102 	int err;
8103 
8104 	if (!selinux_enabled_boot)
8105 		return 0;
8106 
8107 	pr_debug("SELinux:  Registering netfilter hooks\n");
8108 
8109 	err = register_pernet_subsys(&selinux_net_ops);
8110 	if (err)
8111 		panic("SELinux: register_pernet_subsys: error %d\n", err);
8112 
8113 	return 0;
8114 }
8115 #endif /* CONFIG_NETFILTER */
8116