netlabel_cipso_v4.h 4.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171
  1. /*
  2. * NetLabel CIPSO/IPv4 Support
  3. *
  4. * This file defines the CIPSO/IPv4 functions for the NetLabel system. The
  5. * NetLabel system manages static and dynamic label mappings for network
  6. * protocols such as CIPSO and RIPSO.
  7. *
  8. * Author: Paul Moore <paul@paul-moore.com>
  9. *
  10. */
  11. /*
  12. * (c) Copyright Hewlett-Packard Development Company, L.P., 2006
  13. *
  14. * This program is free software; you can redistribute it and/or modify
  15. * it under the terms of the GNU General Public License as published by
  16. * the Free Software Foundation; either version 2 of the License, or
  17. * (at your option) any later version.
  18. *
  19. * This program is distributed in the hope that it will be useful,
  20. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  21. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See
  22. * the GNU General Public License for more details.
  23. *
  24. * You should have received a copy of the GNU General Public License
  25. * along with this program; if not, write to the Free Software
  26. * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
  27. *
  28. */
  29. #ifndef _NETLABEL_CIPSO_V4
  30. #define _NETLABEL_CIPSO_V4
  31. #include <net/netlabel.h>
  32. /*
  33. * The following NetLabel payloads are supported by the CIPSO subsystem.
  34. *
  35. * o ADD:
  36. * Sent by an application to add a new DOI mapping table.
  37. *
  38. * Required attributes:
  39. *
  40. * NLBL_CIPSOV4_A_DOI
  41. * NLBL_CIPSOV4_A_MTYPE
  42. * NLBL_CIPSOV4_A_TAGLST
  43. *
  44. * If using CIPSO_V4_MAP_TRANS the following attributes are required:
  45. *
  46. * NLBL_CIPSOV4_A_MLSLVLLST
  47. * NLBL_CIPSOV4_A_MLSCATLST
  48. *
  49. * If using CIPSO_V4_MAP_PASS or CIPSO_V4_MAP_LOCAL no additional attributes
  50. * are required.
  51. *
  52. * o REMOVE:
  53. * Sent by an application to remove a specific DOI mapping table from the
  54. * CIPSO V4 system.
  55. *
  56. * Required attributes:
  57. *
  58. * NLBL_CIPSOV4_A_DOI
  59. *
  60. * o LIST:
  61. * Sent by an application to list the details of a DOI definition. On
  62. * success the kernel should send a response using the following format.
  63. *
  64. * Required attributes:
  65. *
  66. * NLBL_CIPSOV4_A_DOI
  67. *
  68. * The valid response message format depends on the type of the DOI mapping,
  69. * the defined formats are shown below.
  70. *
  71. * Required attributes:
  72. *
  73. * NLBL_CIPSOV4_A_MTYPE
  74. * NLBL_CIPSOV4_A_TAGLST
  75. *
  76. * If using CIPSO_V4_MAP_TRANS the following attributes are required:
  77. *
  78. * NLBL_CIPSOV4_A_MLSLVLLST
  79. * NLBL_CIPSOV4_A_MLSCATLST
  80. *
  81. * If using CIPSO_V4_MAP_PASS or CIPSO_V4_MAP_LOCAL no additional attributes
  82. * are required.
  83. *
  84. * o LISTALL:
  85. * This message is sent by an application to list the valid DOIs on the
  86. * system. When sent by an application there is no payload and the
  87. * NLM_F_DUMP flag should be set. The kernel should respond with a series of
  88. * the following messages.
  89. *
  90. * Required attributes:
  91. *
  92. * NLBL_CIPSOV4_A_DOI
  93. * NLBL_CIPSOV4_A_MTYPE
  94. *
  95. */
  96. /* NetLabel CIPSOv4 commands */
  97. enum {
  98. NLBL_CIPSOV4_C_UNSPEC,
  99. NLBL_CIPSOV4_C_ADD,
  100. NLBL_CIPSOV4_C_REMOVE,
  101. NLBL_CIPSOV4_C_LIST,
  102. NLBL_CIPSOV4_C_LISTALL,
  103. __NLBL_CIPSOV4_C_MAX,
  104. };
  105. /* NetLabel CIPSOv4 attributes */
  106. enum {
  107. NLBL_CIPSOV4_A_UNSPEC,
  108. NLBL_CIPSOV4_A_DOI,
  109. /* (NLA_U32)
  110. * the DOI value */
  111. NLBL_CIPSOV4_A_MTYPE,
  112. /* (NLA_U32)
  113. * the mapping table type (defined in the cipso_ipv4.h header as
  114. * CIPSO_V4_MAP_*) */
  115. NLBL_CIPSOV4_A_TAG,
  116. /* (NLA_U8)
  117. * a CIPSO tag type, meant to be used within a NLBL_CIPSOV4_A_TAGLST
  118. * attribute */
  119. NLBL_CIPSOV4_A_TAGLST,
  120. /* (NLA_NESTED)
  121. * the CIPSO tag list for the DOI, there must be at least one
  122. * NLBL_CIPSOV4_A_TAG attribute, tags listed first are given higher
  123. * priorirty when sending packets */
  124. NLBL_CIPSOV4_A_MLSLVLLOC,
  125. /* (NLA_U32)
  126. * the local MLS sensitivity level */
  127. NLBL_CIPSOV4_A_MLSLVLREM,
  128. /* (NLA_U32)
  129. * the remote MLS sensitivity level */
  130. NLBL_CIPSOV4_A_MLSLVL,
  131. /* (NLA_NESTED)
  132. * a MLS sensitivity level mapping, must contain only one attribute of
  133. * each of the following types: NLBL_CIPSOV4_A_MLSLVLLOC and
  134. * NLBL_CIPSOV4_A_MLSLVLREM */
  135. NLBL_CIPSOV4_A_MLSLVLLST,
  136. /* (NLA_NESTED)
  137. * the CIPSO level mappings, there must be at least one
  138. * NLBL_CIPSOV4_A_MLSLVL attribute */
  139. NLBL_CIPSOV4_A_MLSCATLOC,
  140. /* (NLA_U32)
  141. * the local MLS category */
  142. NLBL_CIPSOV4_A_MLSCATREM,
  143. /* (NLA_U32)
  144. * the remote MLS category */
  145. NLBL_CIPSOV4_A_MLSCAT,
  146. /* (NLA_NESTED)
  147. * a MLS category mapping, must contain only one attribute of each of
  148. * the following types: NLBL_CIPSOV4_A_MLSCATLOC and
  149. * NLBL_CIPSOV4_A_MLSCATREM */
  150. NLBL_CIPSOV4_A_MLSCATLST,
  151. /* (NLA_NESTED)
  152. * the CIPSO category mappings, there must be at least one
  153. * NLBL_CIPSOV4_A_MLSCAT attribute */
  154. __NLBL_CIPSOV4_A_MAX,
  155. };
  156. #define NLBL_CIPSOV4_A_MAX (__NLBL_CIPSOV4_A_MAX - 1)
  157. /* NetLabel protocol functions */
  158. int netlbl_cipsov4_genl_init(void);
  159. /* Free the memory associated with a CIPSOv4 DOI definition */
  160. void netlbl_cipsov4_doi_free(struct rcu_head *entry);
  161. #endif