mac_inet6.c revision 187014
1/*-
2 * Copyright (c) 2007-2008 Robert N. M. Watson
3 * All rights reserved.
4 *
5 * This software was developed by Robert Watson for the TrustedBSD Project.
6 *
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted provided that the following conditions
9 * are met:
10 * 1. Redistributions of source code must retain the above copyright
11 *    notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 *    notice, this list of conditions and the following disclaimer in the
14 *    documentation and/or other materials provided with the distribution.
15 *
16 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
17 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
20 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26 * SUCH DAMAGE.
27 */
28
29#include <sys/cdefs.h>
30__FBSDID("$FreeBSD: head/sys/security/mac/mac_inet6.c 187014 2009-01-10 09:17:16Z rwatson $");
31
32#include "opt_mac.h"
33
34#include <sys/param.h>
35#include <sys/kernel.h>
36#include <sys/lock.h>
37#include <sys/malloc.h>
38#include <sys/mutex.h>
39#include <sys/sbuf.h>
40#include <sys/systm.h>
41#include <sys/mount.h>
42#include <sys/file.h>
43#include <sys/namei.h>
44#include <sys/protosw.h>
45#include <sys/socket.h>
46#include <sys/socketvar.h>
47#include <sys/sysctl.h>
48
49#include <net/if.h>
50#include <net/if_var.h>
51
52#include <netinet/in.h>
53#include <netinet/ip6.h>
54#include <netinet6/ip6_var.h>
55
56#include <security/mac/mac_framework.h>
57#include <security/mac/mac_internal.h>
58#include <security/mac/mac_policy.h>
59
60static struct label *
61mac_ip6q_label_alloc(int flag)
62{
63	struct label *label;
64	int error;
65
66	label = mac_labelzone_alloc(flag);
67	if (label == NULL)
68		return (NULL);
69
70	MAC_CHECK(ip6q_init_label, label, flag);
71	if (error) {
72		MAC_PERFORM(ip6q_destroy_label, label);
73		mac_labelzone_free(label);
74		return (NULL);
75	}
76	return (label);
77}
78
79int
80mac_ip6q_init(struct ip6q *q6, int flag)
81{
82
83	if (mac_labeled & MPC_OBJECT_IP6Q) {
84		q6->ip6q_label = mac_ip6q_label_alloc(flag);
85		if (q6->ip6q_label == NULL)
86			return (ENOMEM);
87	} else
88		q6->ip6q_label = NULL;
89	return (0);
90}
91
92static void
93mac_ip6q_label_free(struct label *label)
94{
95
96	MAC_PERFORM(ip6q_destroy_label, label);
97	mac_labelzone_free(label);
98}
99
100void
101mac_ip6q_destroy(struct ip6q *q6)
102{
103
104	if (q6->ip6q_label != NULL) {
105		mac_ip6q_label_free(q6->ip6q_label);
106		q6->ip6q_label = NULL;
107	}
108}
109
110void
111mac_ip6q_reassemble(struct ip6q *q6, struct mbuf *m)
112{
113	struct label *label;
114
115	label = mac_mbuf_to_label(m);
116
117	MAC_PERFORM(ip6q_reassemble, q6, q6->ip6q_label, m, label);
118}
119
120void
121mac_ip6q_create(struct mbuf *m, struct ip6q *q6)
122{
123	struct label *label;
124
125	label = mac_mbuf_to_label(m);
126
127	MAC_PERFORM(ip6q_create, m, label, q6, q6->ip6q_label);
128}
129
130int
131mac_ip6q_match(struct mbuf *m, struct ip6q *q6)
132{
133	struct label *label;
134	int result;
135
136	label = mac_mbuf_to_label(m);
137
138	result = 1;
139	MAC_BOOLEAN(ip6q_match, &&, m, label, q6, q6->ip6q_label);
140
141	return (result);
142}
143
144void
145mac_ip6q_update(struct mbuf *m, struct ip6q *q6)
146{
147	struct label *label;
148
149	label = mac_mbuf_to_label(m);
150
151	MAC_PERFORM(ip6q_update, m, label, q6, q6->ip6q_label);
152}
153
154void
155mac_netinet6_nd6_send(struct ifnet *ifp, struct mbuf *m)
156{
157	struct label *mlabel;
158
159	mlabel = mac_mbuf_to_label(m);
160
161	MAC_PERFORM(netinet6_nd6_send, ifp, ifp->if_label, m, mlabel);
162}
163