| /linux/security/apparmor/ |
| H A D | policy_compat.c | 100 static void compute_fperms_allow(struct aa_perms *perms, const struct aa_dfa *dfa, in compute_fperms_allow() argument 103 perms->allow |= AA_MAY_GETATTR; in compute_fperms_allow() 107 perms->allow |= AA_MAY_CHANGE_PROFILE; in compute_fperms_allow() 109 perms->allow |= AA_MAY_ONEXEC; in compute_fperms_allow() 115 struct aa_perms perms = { }; in compute_fperms_user() local 117 perms.allow = map_old_perms(dfa_user_allow(dfa, state)); in compute_fperms_user() 118 perms.audit = map_old_perms(dfa_user_audit(dfa, state)); in compute_fperms_user() 119 perms.quiet = map_old_perms(dfa_user_quiet(dfa, state)); in compute_fperms_user() 120 perms.xindex = dfa_user_xindex(dfa, state); in compute_fperms_user() 122 compute_fperms_allow(&perms, dfa, state); in compute_fperms_user() [all …]
|
| H A D | lib.c | 365 struct aa_perms *perms) in aa_apply_modes_to_perms() argument 368 perms->kill = ~perms->allow; in aa_apply_modes_to_perms() 370 perms->complain |= ~(perms->allow | perms->deny); in aa_apply_modes_to_perms() 372 perms->prompt |= ~(perms->allow | perms->deny); in aa_apply_modes_to_perms() 376 perms->audit = ALL_PERMS_MASK; in aa_apply_modes_to_perms() 379 perms->quiet = 0; in aa_apply_modes_to_perms() 382 perms->audit = 0; in aa_apply_modes_to_perms() 385 perms->quiet |= ~perms->allow; in aa_apply_modes_to_perms() 388 perms->quiet |= perms->complain | perms->allow; in aa_apply_modes_to_perms() 396 int type, u32 request, struct aa_perms *perms) in aa_profile_match_label() argument [all …]
|
| H A D | file.c | 96 struct aa_profile *profile, const struct aa_perms *perms, in aa_audit_file() argument 101 u32 quiet = perms->quiet; in aa_audit_file() 102 u32 complain = perms->complain; in aa_audit_file() 108 ad.tags = perms->tag; in aa_audit_file() 118 complain |= ~(perms->allow | perms->deny); in aa_audit_file() 120 u32 mask = perms->audit; in aa_audit_file() 133 ad.request = ad.request & ~perms->allow; in aa_audit_file() 136 if (ad.request & perms->kill) in aa_audit_file() 140 quiet |= complain | perms->allow; in aa_audit_file() 152 ad.denied = ad.request & ~perms->allow; in aa_audit_file() [all …]
|
| H A D | domain.c | 133 struct aa_perms *perms) in label_compound_match() argument 151 *perms = allperms; in label_compound_match() 163 *perms = *(aa_lookup_condperms(current_fsuid(), rules->file, state, in label_compound_match() 165 aa_apply_modes_to_perms(profile, perms); in label_compound_match() 166 if ((perms->allow & request) != request) in label_compound_match() 172 *perms = nullperms; in label_compound_match() 195 struct aa_perms *perms) in label_components_match() argument 221 aa_perms_accum(perms, &tmp); in label_components_match() 231 aa_perms_accum(perms, &tmp); in label_components_match() 234 if ((perms->allow & request) != request) in label_components_match() [all …]
|
| H A D | capability.c | 130 struct aa_perms perms = { }; in profile_capable() local 136 perms = *aa_lookup_perms(rules->policy, state); in profile_capable() 137 aa_apply_modes_to_perms(profile, &perms); in profile_capable() 140 if (perms.complain & request) in profile_capable() 145 return aa_check_perms(profile, &perms, request, ad, in profile_capable() 206 struct aa_perms perms = { }; in aa_profile_capget() local 210 perms = *aa_lookup_perms(rules->policy, tmp); in aa_profile_capget() 211 aa_apply_modes_to_perms(profile, &perms); in aa_profile_capget() 212 caps.val |= ((u64)(perms.allow)) << (i * 5); in aa_profile_capget() 213 caps.val |= ((u64)(perms.complain)) << (i * 5); in aa_profile_capget()
|
| H A D | mount.c | 162 void *data, bool binary, struct aa_perms *perms) in do_match_mnt() argument 168 AA_BUG(!policy->perms); in do_match_mnt() 169 AA_BUG(!perms); in do_match_mnt() 191 *perms = *aa_lookup_perms(policy, state); in do_match_mnt() 192 if (perms->allow & AA_MAY_MOUNT) in do_match_mnt() 196 if (data && !binary && (perms->allow & AA_MNT_CONT_MATCH)) { in do_match_mnt() 204 *perms = *aa_lookup_perms(policy, state); in do_match_mnt() 205 if (perms->allow & AA_MAY_MOUNT) in do_match_mnt() 245 struct aa_perms perms = { }; in match_mnt_path_str() local 276 mntpnt, devname, type, flags, data, binary, &perms); in match_mnt_path_str() [all …]
|
| H A D | net.c | 172 struct aa_perms perms; in aa_do_perms() local 180 perms = *p; in aa_do_perms() 181 aa_apply_modes_to_perms(profile, &perms); in aa_do_perms() 182 return aa_check_perms(profile, &perms, request, ad, in aa_do_perms() 375 struct aa_perms perms = { }; in aa_secmark_perm() local 391 perms.deny = ALL_PERMS_MASK; in aa_secmark_perm() 393 perms.allow = ALL_PERMS_MASK; in aa_secmark_perm() 396 perms.audit = ALL_PERMS_MASK; in aa_secmark_perm() 400 aa_apply_modes_to_perms(profile, &perms); in aa_secmark_perm() 402 return aa_check_perms(profile, &perms, request, ad, audit_net_cb); in aa_secmark_perm()
|
| H A D | task.c | 260 struct aa_perms perms = { }; in profile_ptrace_perm() local 265 &perms); in profile_ptrace_perm() 266 aa_apply_modes_to_perms(profile, &perms); in profile_ptrace_perm() 267 return aa_check_perms(profile, &perms, request, ad, audit_ptrace_cb); in profile_ptrace_perm() 378 struct aa_perms perms = { }; in aa_profile_ns_perm() local 392 perms = *aa_lookup_perms(rules->policy, state); in aa_profile_ns_perm() 393 aa_apply_modes_to_perms(profile, &perms); in aa_profile_ns_perm() 394 error = aa_check_perms(profile, &perms, request, ad, in aa_profile_ns_perm()
|
| H A D | ipc.c | 84 struct aa_perms perms; in profile_signal_perm() local 97 aa_label_match(profile, rules, peer, state, false, request, &perms); in profile_signal_perm() 98 aa_apply_modes_to_perms(profile, &perms); in profile_signal_perm() 99 return aa_check_perms(profile, &perms, request, ad, audit_signal_cb); in profile_signal_perm()
|
| H A D | policy_unpack.c | 924 static ssize_t unpack_perms_table(struct aa_ext *e, struct aa_perms **perms) in unpack_perms_table() argument 929 AA_BUG(!perms); in unpack_perms_table() 942 *perms = kzalloc_objs(struct aa_perms, size); in unpack_perms_table() 943 if (!*perms) { in unpack_perms_table() 948 if (!unpack_perm(e, version, &(*perms)[i])) in unpack_perms_table() 956 *perms = NULL; in unpack_perms_table() 961 kfree(*perms); in unpack_perms_table() 986 size = unpack_perms_table(e, &pdb->perms); in unpack_pdb() 989 pdb->perms = NULL; in unpack_pdb() 995 if (pdb->perms) { in unpack_pdb() [all …]
|
| H A D | audit.c | 143 int aa_select_audit_type(u32 denied, const struct aa_perms *perms) in aa_select_audit_type() argument 147 else if (denied & perms->kill) in aa_select_audit_type() 149 else if (denied == (denied & perms->complain)) in aa_select_audit_type()
|
| H A D | label.c | 1333 struct aa_perms *perms) in label_compound_match() argument 1349 *perms = allperms; in label_compound_match() 1361 *perms = *aa_lookup_perms(rules->policy, state); in label_compound_match() 1365 *perms = nullperms; in label_compound_match() 1389 struct aa_perms *perms) in label_components_match() argument 1411 aa_perms_accum(perms, &tmp); in label_components_match() 1419 aa_perms_accum(perms, &tmp); in label_components_match() 1422 if ((perms->allow & request) != request) in label_components_match() 1428 *perms = nullperms; in label_components_match() 1446 u32 request, struct aa_perms *perms) in aa_label_match() argument [all …]
|
| /linux/security/apparmor/include/ |
| H A D | file.h | 75 struct aa_profile *profile, const struct aa_perms *perms, 85 struct aa_perms *perms); 90 struct aa_perms *perms); 115 u32 perms = 0; in aa_map_file_to_perms() local 118 perms |= MAY_WRITE; in aa_map_file_to_perms() 120 perms |= MAY_READ; in aa_map_file_to_perms() 122 if ((flags & O_APPEND) && (perms & MAY_WRITE)) in aa_map_file_to_perms() 123 perms = (perms & ~MAY_WRITE) | MAY_APPEND; in aa_map_file_to_perms() 126 perms |= MAY_WRITE; in aa_map_file_to_perms() 128 perms |= AA_MAY_CREATE; in aa_map_file_to_perms() [all …]
|
| H A D | perms.h | 210 struct aa_perms *perms); 215 int type, u32 request, struct aa_perms *perms); 216 int aa_check_perms(struct aa_profile *profile, const struct aa_perms *perms,
|
| /linux/drivers/s390/crypto/ |
| H A D | zcrypt_api.c | 123 struct ap_perms perms; member 168 for (i = 0; i < sizeof(zcdndev->perms.ioctlm) / sizeof(long); i++) in ioctlmask_show() 169 n += sysfs_emit_at(buf, n, "%016lx", zcdndev->perms.ioctlm[i]); in ioctlmask_show() 184 rc = ap_parse_mask_str(buf, zcdndev->perms.ioctlm, in ioctlmask_store() 205 for (i = 0; i < sizeof(zcdndev->perms.apm) / sizeof(long); i++) in apmask_show() 206 n += sysfs_emit_at(buf, n, "%016lx", zcdndev->perms.apm[i]); in apmask_show() 221 rc = ap_parse_mask_str(buf, zcdndev->perms.apm, in apmask_store() 242 for (i = 0; i < sizeof(zcdndev->perms.aqm) / sizeof(long); i++) in aqmask_show() 243 n += sysfs_emit_at(buf, n, "%016lx", zcdndev->perms.aqm[i]); in aqmask_show() 258 rc = ap_parse_mask_str(buf, zcdndev->perms.aqm, in aqmask_store() [all …]
|
| /linux/drivers/soc/qcom/ |
| H A D | rmtfs_mem.c | 34 u64 perms; member 174 struct qcom_scm_vmperm perms[NUM_MAX_VMIDS + 1]; in qcom_rmtfs_mem_probe() local 264 perms[0].vmid = QCOM_SCM_VMID_HLOS; in qcom_rmtfs_mem_probe() 265 perms[0].perm = QCOM_SCM_PERM_RW; in qcom_rmtfs_mem_probe() 268 perms[i + 1].vmid = vmid[i]; in qcom_rmtfs_mem_probe() 269 perms[i + 1].perm = QCOM_SCM_PERM_RW; in qcom_rmtfs_mem_probe() 272 rmtfs_mem->perms = BIT(QCOM_SCM_VMID_HLOS); in qcom_rmtfs_mem_probe() 274 &rmtfs_mem->perms, perms, num_vmids + 1); in qcom_rmtfs_mem_probe() 298 if (rmtfs_mem->perms) { in qcom_rmtfs_mem_remove() 303 &rmtfs_mem->perms, &perm, 1); in qcom_rmtfs_mem_remove()
|
| /linux/fs/orangefs/ |
| H A D | orangefs-utils.c | 106 if (attrs->perms & ORANGEFS_O_EXECUTE) in orangefs_inode_perms() 108 if (attrs->perms & ORANGEFS_O_WRITE) in orangefs_inode_perms() 110 if (attrs->perms & ORANGEFS_O_READ) in orangefs_inode_perms() 113 if (attrs->perms & ORANGEFS_G_EXECUTE) in orangefs_inode_perms() 115 if (attrs->perms & ORANGEFS_G_WRITE) in orangefs_inode_perms() 117 if (attrs->perms & ORANGEFS_G_READ) in orangefs_inode_perms() 120 if (attrs->perms & ORANGEFS_U_EXECUTE) in orangefs_inode_perms() 122 if (attrs->perms & ORANGEFS_U_WRITE) in orangefs_inode_perms() 124 if (attrs->perms & ORANGEFS_U_READ) in orangefs_inode_perms() 127 if (attrs->perms & ORANGEFS_G_SGID) in orangefs_inode_perms() [all …]
|
| /linux/include/linux/ |
| H A D | sysfs.h | 812 #define VERIFY_OCTAL_PERMISSIONS(perms) \ argument 813 (BUILD_BUG_ON_ZERO((perms) < 0) + \ 814 BUILD_BUG_ON_ZERO((perms) > 0777) + \ 816 BUILD_BUG_ON_ZERO((((perms) >> 6) & 4) < (((perms) >> 3) & 4)) + \ 817 BUILD_BUG_ON_ZERO((((perms) >> 3) & 4) < ((perms) & 4)) + \ 819 BUILD_BUG_ON_ZERO((((perms) >> 6) & 2) < (((perms) >> 3) & 2)) + \ 821 BUILD_BUG_ON_ZERO((perms) & 2) + \ 822 (perms))
|
| /linux/security/selinux/include/ |
| H A D | security.h | 253 #define security_xperm_set(perms, x) ((perms)[(x) >> 5] |= 1 << ((x)&0x1f)) argument 254 #define security_xperm_test(perms, x) (1 & ((perms)[(x) >> 5] >> ((x)&0x1f))) 342 char ***perms, u32 *nperms); 252 security_xperm_set(perms,x) global() argument
|
| /linux/tools/testing/selftests/mm/ |
| H A D | mlock2.h | 24 char perms[5]; in seek_to_smaps_entry() local 36 &start, &end, perms, &offset, dev, &inode, path) < 6) in seek_to_smaps_entry()
|
| /linux/security/selinux/ss/ |
| H A D | avtab.c | 101 /* extended perms may not be unique */ in avtab_insert() 317 __le32 buf32[ARRAY_SIZE(xperms.perms.p)]; in avtab_read_item() 477 sizeof(u32) * ARRAY_SIZE(xperms.perms.p)); in avtab_read() 482 for (i = 0; i < ARRAY_SIZE(xperms.perms.p); i++) in avtab_read() 483 xperms.perms.p[i] = le32_to_cpu(buf32[i]); in avtab_read() 558 __le32 buf32[ARRAY_SIZE(cur->datum.u.xperms->perms.p)]; in avtab_write() 578 for (i = 0; i < ARRAY_SIZE(cur->datum.u.xperms->perms.p); i++) 579 buf32[i] = cpu_to_le32(cur->datum.u.xperms->perms.p[i]); in avtab_cache_init() 581 ARRAY_SIZE(cur->datum.u.xperms->perms.p), fp); in avtab_cache_init()
|
| H A D | services.c | 140 while (p_in->perms[k]) { in selinux_set_mapping() 142 if (!*p_in->perms[k]) { in selinux_set_mapping() 146 p_out->perms[k] = string_to_av_perm(pol, p_out->value, in selinux_set_mapping() 147 p_in->perms[k]); in selinux_set_mapping() 148 if (!p_out->perms[k]) { in selinux_set_mapping() 150 p_in->perms[k], p_in->name); in selinux_set_mapping() 210 if (avd->allowed & mapping->perms[i]) in map_decision() 212 if (allow_unknown && !mapping->perms[i]) in map_decision() 218 if (avd->auditallow & mapping->perms[i]) in map_decision() 223 if (avd->auditdeny & mapping->perms[i]) in map_decision() [all …]
|
| /linux/security/selinux/ |
| H A D | avc.c | 655 const char *const *perms; in avc_audit_pre_callback() local 665 perms = secclass_map[sad->tclass-1].perms; in avc_audit_pre_callback() 671 if ((perm & av) && perms[i]) { in avc_audit_pre_callback() 672 audit_log_format(ab, " %s", perms[i]); in avc_audit_pre_callback() 813 * @perms : Permission mask bits 829 static int avc_update_node(u32 event, u32 perms, u8 driver, u8 base_perm, in avc_update_node() argument 886 node->ae.avd.allowed |= perms; in avc_update_node() 892 node->ae.avd.allowed &= ~perms; in avc_update_node() 895 node->ae.avd.auditallow |= perms; in avc_update_node() [all...] |
| /linux/tools/testing/selftests/mqueue/ |
| H A D | mq_open_tests.c | 203 int perms = DEFFILEMODE; in test_queue() local 205 if ((queue = mq_open(queue_path, flags, perms, attr)) == -1) in test_queue() 225 int perms = DEFFILEMODE; in test_queue_fail() local 227 if ((queue = mq_open(queue_path, flags, perms, attr)) == -1) in test_queue_fail()
|
| /linux/drivers/tee/qcomtee/ |
| H A D | mem_obj.c | 155 u64 *mem_size, u32 *perms) in qcomtee_mem_object_map() argument 165 *perms = QCOM_SCM_PERM_RW; in qcomtee_mem_object_map()
|