lsm_audit.h 2.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109
  1. /*
  2. * Common LSM logging functions
  3. * Heavily borrowed from selinux/avc.h
  4. *
  5. * Author : Etienne BASSET <etienne.basset@ensta.org>
  6. *
  7. * All credits to : Stephen Smalley, <sds@epoch.ncsc.mil>
  8. * All BUGS to : Etienne BASSET <etienne.basset@ensta.org>
  9. */
  10. #ifndef _LSM_COMMON_LOGGING_
  11. #define _LSM_COMMON_LOGGING_
  12. #include <linux/stddef.h>
  13. #include <linux/errno.h>
  14. #include <linux/kernel.h>
  15. #include <linux/kdev_t.h>
  16. #include <linux/spinlock.h>
  17. #include <linux/init.h>
  18. #include <linux/audit.h>
  19. #include <linux/in6.h>
  20. #include <linux/path.h>
  21. #include <linux/key.h>
  22. #include <linux/skbuff.h>
  23. struct lsm_network_audit {
  24. int netif;
  25. struct sock *sk;
  26. u16 family;
  27. __be16 dport;
  28. __be16 sport;
  29. union {
  30. struct {
  31. __be32 daddr;
  32. __be32 saddr;
  33. } v4;
  34. struct {
  35. struct in6_addr daddr;
  36. struct in6_addr saddr;
  37. } v6;
  38. } fam;
  39. };
  40. struct lsm_ioctlop_audit {
  41. struct path path;
  42. u16 cmd;
  43. };
  44. /* Auxiliary data to use in generating the audit record. */
  45. struct common_audit_data {
  46. char type;
  47. #define LSM_AUDIT_DATA_PATH 1
  48. #define LSM_AUDIT_DATA_NET 2
  49. #define LSM_AUDIT_DATA_CAP 3
  50. #define LSM_AUDIT_DATA_IPC 4
  51. #define LSM_AUDIT_DATA_TASK 5
  52. #define LSM_AUDIT_DATA_KEY 6
  53. #define LSM_AUDIT_DATA_NONE 7
  54. #define LSM_AUDIT_DATA_KMOD 8
  55. #define LSM_AUDIT_DATA_INODE 9
  56. #define LSM_AUDIT_DATA_DENTRY 10
  57. #define LSM_AUDIT_DATA_IOCTL_OP 11
  58. #define LSM_AUDIT_DATA_FILE 12
  59. union {
  60. struct path path;
  61. struct dentry *dentry;
  62. struct inode *inode;
  63. struct lsm_network_audit *net;
  64. int cap;
  65. int ipc_id;
  66. struct task_struct *tsk;
  67. #ifdef CONFIG_KEYS
  68. struct {
  69. key_serial_t key;
  70. char *key_desc;
  71. } key_struct;
  72. #endif
  73. char *kmod_name;
  74. struct lsm_ioctlop_audit *op;
  75. struct file *file;
  76. } u;
  77. /* this union contains LSM specific data */
  78. union {
  79. #ifdef CONFIG_SECURITY_SMACK
  80. struct smack_audit_data *smack_audit_data;
  81. #endif
  82. #ifdef CONFIG_SECURITY_SELINUX
  83. struct selinux_audit_data *selinux_audit_data;
  84. #endif
  85. #ifdef CONFIG_SECURITY_APPARMOR
  86. struct apparmor_audit_data *apparmor_audit_data;
  87. #endif
  88. }; /* per LSM data pointer union */
  89. };
  90. #define v4info fam.v4
  91. #define v6info fam.v6
  92. int ipv4_skb_to_auditdata(struct sk_buff *skb,
  93. struct common_audit_data *ad, u8 *proto);
  94. int ipv6_skb_to_auditdata(struct sk_buff *skb,
  95. struct common_audit_data *ad, u8 *proto);
  96. void common_lsm_audit(struct common_audit_data *a,
  97. void (*pre_audit)(struct audit_buffer *, void *),
  98. void (*post_audit)(struct audit_buffer *, void *));
  99. #endif