Micah Morton | aeca4e2 | 2019-01-16 07:46:06 -0800 | [diff] [blame] | 1 | /* SPDX-License-Identifier: GPL-2.0 */ |
| 2 | /* |
| 3 | * SafeSetID Linux Security Module |
| 4 | * |
| 5 | * Author: Micah Morton <mortonm@chromium.org> |
| 6 | * |
| 7 | * Copyright (C) 2018 The Chromium OS Authors. |
| 8 | * |
| 9 | * This program is free software; you can redistribute it and/or modify |
| 10 | * it under the terms of the GNU General Public License version 2, as |
| 11 | * published by the Free Software Foundation. |
| 12 | * |
| 13 | */ |
| 14 | #ifndef _SAFESETID_H |
| 15 | #define _SAFESETID_H |
| 16 | |
| 17 | #include <linux/types.h> |
Jann Horn | 1cd02a2 | 2019-04-10 09:55:34 -0700 | [diff] [blame] | 18 | #include <linux/uidgid.h> |
| 19 | #include <linux/hashtable.h> |
Micah Morton | aeca4e2 | 2019-01-16 07:46:06 -0800 | [diff] [blame] | 20 | |
| 21 | /* Flag indicating whether initialization completed */ |
| 22 | extern int safesetid_initialized; |
| 23 | |
Jann Horn | 1cd02a2 | 2019-04-10 09:55:34 -0700 | [diff] [blame] | 24 | enum sid_policy_type { |
| 25 | SIDPOL_DEFAULT, /* source ID is unaffected by policy */ |
| 26 | SIDPOL_CONSTRAINED, /* source ID is affected by policy */ |
| 27 | SIDPOL_ALLOWED /* target ID explicitly allowed */ |
| 28 | }; |
| 29 | |
| 30 | /* |
| 31 | * Hash table entry to store safesetid policy signifying that 'src_uid' |
Jann Horn | 03638e6 | 2019-04-10 09:56:05 -0700 | [diff] [blame] | 32 | * can setuid to 'dst_uid'. |
Jann Horn | 1cd02a2 | 2019-04-10 09:55:34 -0700 | [diff] [blame] | 33 | */ |
Jann Horn | 03638e6 | 2019-04-10 09:56:05 -0700 | [diff] [blame] | 34 | struct setuid_rule { |
Jann Horn | 1cd02a2 | 2019-04-10 09:55:34 -0700 | [diff] [blame] | 35 | struct hlist_node next; |
Jann Horn | 1cd02a2 | 2019-04-10 09:55:34 -0700 | [diff] [blame] | 36 | kuid_t src_uid; |
| 37 | kuid_t dst_uid; |
| 38 | }; |
| 39 | |
Jann Horn | 03638e6 | 2019-04-10 09:56:05 -0700 | [diff] [blame] | 40 | #define SETID_HASH_BITS 8 /* 256 buckets in hash table */ |
Micah Morton | aeca4e2 | 2019-01-16 07:46:06 -0800 | [diff] [blame] | 41 | |
Jann Horn | 03638e6 | 2019-04-10 09:56:05 -0700 | [diff] [blame] | 42 | struct setuid_ruleset { |
| 43 | DECLARE_HASHTABLE(rules, SETID_HASH_BITS); |
Jann Horn | fbd9acb | 2019-04-11 13:11:54 -0700 | [diff] [blame] | 44 | char *policy_str; |
Jann Horn | 03638e6 | 2019-04-10 09:56:05 -0700 | [diff] [blame] | 45 | struct rcu_head rcu; |
| 46 | }; |
| 47 | |
| 48 | enum sid_policy_type _setuid_policy_lookup(struct setuid_ruleset *policy, |
| 49 | kuid_t src, kuid_t dst); |
| 50 | |
| 51 | extern struct setuid_ruleset __rcu *safesetid_setuid_rules; |
Micah Morton | aeca4e2 | 2019-01-16 07:46:06 -0800 | [diff] [blame] | 52 | |
| 53 | #endif /* _SAFESETID_H */ |