mac_stub.c revision 112717
1/*-
2 * Copyright (c) 1999, 2000, 2001, 2002 Robert N. M. Watson
3 * Copyright (c) 2001, 2002 Networks Associates Technology, Inc.
4 * All rights reserved.
5 *
6 * This software was developed by Robert Watson for the TrustedBSD Project.
7 *
8 * This software was developed for the FreeBSD Project in part by Network
9 * Associates Laboratories, the Security Research Division of Network
10 * Associates, Inc. under DARPA/SPAWAR contract N66001-01-C-8035 ("CBOSS"),
11 * as part of the DARPA CHATS research program.
12 *
13 * Redistribution and use in source and binary forms, with or without
14 * modification, are permitted provided that the following conditions
15 * are met:
16 * 1. Redistributions of source code must retain the above copyright
17 *    notice, this list of conditions and the following disclaimer.
18 * 2. Redistributions in binary form must reproduce the above copyright
19 *    notice, this list of conditions and the following disclaimer in the
20 *    documentation and/or other materials provided with the distribution.
21 *
22 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
23 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
26 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32 * SUCH DAMAGE.
33 *
34 * $FreeBSD: head/sys/security/mac_stub/mac_stub.c 112717 2003-03-27 19:26:39Z rwatson $
35 */
36
37/*
38 * Developed by the TrustedBSD Project.
39 * Generic mandatory access module that does nothing.
40 */
41
42#include <sys/types.h>
43#include <sys/param.h>
44#include <sys/acl.h>
45#include <sys/conf.h>
46#include <sys/extattr.h>
47#include <sys/kernel.h>
48#include <sys/mac.h>
49#include <sys/mount.h>
50#include <sys/proc.h>
51#include <sys/systm.h>
52#include <sys/sysproto.h>
53#include <sys/sysent.h>
54#include <sys/vnode.h>
55#include <sys/file.h>
56#include <sys/socket.h>
57#include <sys/socketvar.h>
58#include <sys/pipe.h>
59#include <sys/sysctl.h>
60
61#include <fs/devfs/devfs.h>
62
63#include <net/bpfdesc.h>
64#include <net/if.h>
65#include <net/if_types.h>
66#include <net/if_var.h>
67
68#include <netinet/in.h>
69#include <netinet/ip_var.h>
70
71#include <vm/vm.h>
72
73#include <sys/mac_policy.h>
74
75SYSCTL_DECL(_security_mac);
76
77SYSCTL_NODE(_security_mac, OID_AUTO, none, CTLFLAG_RW, 0,
78    "TrustedBSD mac_none policy controls");
79
80static int	mac_none_enabled = 1;
81SYSCTL_INT(_security_mac_none, OID_AUTO, enabled, CTLFLAG_RW,
82    &mac_none_enabled, 0, "Enforce none policy");
83
84/*
85 * Policy module operations.
86 */
87static void
88mac_none_destroy(struct mac_policy_conf *conf)
89{
90
91}
92
93static void
94mac_none_init(struct mac_policy_conf *conf)
95{
96
97}
98
99static int
100mac_none_syscall(struct thread *td, int call, void *arg)
101{
102
103	return (0);
104}
105
106/*
107 * Label operations.
108 */
109static void
110mac_none_init_label(struct label *label)
111{
112
113}
114
115static int
116mac_none_init_label_waitcheck(struct label *label, int flag)
117{
118
119	return (0);
120}
121
122static void
123mac_none_destroy_label(struct label *label)
124{
125
126}
127
128static int
129mac_none_externalize_label(struct label *label, char *element_name,
130    char *element_data, size_t size, size_t *len, int *claimed)
131{
132
133	return (0);
134}
135
136static int
137mac_none_internalize_label(struct label *label, char *element_name,
138    char *element_data, int *claimed)
139{
140
141	return (0);
142}
143
144/*
145 * Labeling event operations: file system objects, and things that look
146 * a lot like file system objects.
147 */
148static void
149mac_none_associate_vnode_devfs(struct mount *mp, struct label *fslabel,
150    struct devfs_dirent *de, struct label *delabel, struct vnode *vp,
151    struct label *vlabel)
152{
153
154}
155
156static int
157mac_none_associate_vnode_extattr(struct mount *mp, struct label *fslabel,
158    struct vnode *vp, struct label *vlabel)
159{
160
161	return (0);
162}
163
164static void
165mac_none_associate_vnode_singlelabel(struct mount *mp,
166    struct label *fslabel, struct vnode *vp, struct label *vlabel)
167{
168
169}
170
171static void
172mac_none_create_devfs_device(struct mount *mp, dev_t dev,
173    struct devfs_dirent *devfs_dirent, struct label *label)
174{
175
176}
177
178static void
179mac_none_create_devfs_directory(struct mount *mp, char *dirname,
180    int dirnamelen, struct devfs_dirent *devfs_dirent, struct label *label)
181{
182
183}
184
185static void
186mac_none_create_devfs_symlink(struct ucred *cred, struct mount *mp,
187    struct devfs_dirent *dd, struct label *ddlabel, struct devfs_dirent *de,
188    struct label *delabel)
189{
190
191}
192
193static int
194mac_none_create_vnode_extattr(struct ucred *cred, struct mount *mp,
195    struct label *fslabel, struct vnode *dvp, struct label *dlabel,
196    struct vnode *vp, struct label *vlabel, struct componentname *cnp)
197{
198
199	return (0);
200}
201
202static void
203mac_none_create_mount(struct ucred *cred, struct mount *mp,
204    struct label *mntlabel, struct label *fslabel)
205{
206
207}
208
209static void
210mac_none_create_root_mount(struct ucred *cred, struct mount *mp,
211    struct label *mntlabel, struct label *fslabel)
212{
213
214}
215
216static void
217mac_none_relabel_vnode(struct ucred *cred, struct vnode *vp,
218    struct label *vnodelabel, struct label *label)
219{
220
221}
222
223static int
224mac_none_setlabel_vnode_extattr(struct ucred *cred, struct vnode *vp,
225    struct label *vlabel, struct label *intlabel)
226{
227
228	return (0);
229}
230
231static void
232mac_none_update_devfsdirent(struct mount *mp,
233    struct devfs_dirent *devfs_dirent, struct label *direntlabel,
234    struct vnode *vp, struct label *vnodelabel)
235{
236
237}
238
239/*
240 * Labeling event operations: IPC object.
241 */
242static void
243mac_none_create_mbuf_from_socket(struct socket *so, struct label *socketlabel,
244    struct mbuf *m, struct label *mbuflabel)
245{
246
247}
248
249static void
250mac_none_create_socket(struct ucred *cred, struct socket *socket,
251    struct label *socketlabel)
252{
253
254}
255
256static void
257mac_none_create_pipe(struct ucred *cred, struct pipe *pipe,
258    struct label *pipelabel)
259{
260
261}
262
263static void
264mac_none_create_socket_from_socket(struct socket *oldsocket,
265    struct label *oldsocketlabel, struct socket *newsocket,
266    struct label *newsocketlabel)
267{
268
269}
270
271static void
272mac_none_relabel_socket(struct ucred *cred, struct socket *socket,
273    struct label *socketlabel, struct label *newlabel)
274{
275
276}
277
278static void
279mac_none_relabel_pipe(struct ucred *cred, struct pipe *pipe,
280    struct label *pipelabel, struct label *newlabel)
281{
282
283}
284
285static void
286mac_none_set_socket_peer_from_mbuf(struct mbuf *mbuf, struct label *mbuflabel,
287    struct socket *socket, struct label *socketpeerlabel)
288{
289
290}
291
292static void
293mac_none_set_socket_peer_from_socket(struct socket *oldsocket,
294    struct label *oldsocketlabel, struct socket *newsocket,
295    struct label *newsocketpeerlabel)
296{
297
298}
299
300/*
301 * Labeling event operations: network objects.
302 */
303static void
304mac_none_create_bpfdesc(struct ucred *cred, struct bpf_d *bpf_d,
305    struct label *bpflabel)
306{
307
308}
309
310static void
311mac_none_create_datagram_from_ipq(struct ipq *ipq, struct label *ipqlabel,
312    struct mbuf *datagram, struct label *datagramlabel)
313{
314
315}
316
317static void
318mac_none_create_fragment(struct mbuf *datagram, struct label *datagramlabel,
319    struct mbuf *fragment, struct label *fragmentlabel)
320{
321
322}
323
324static void
325mac_none_create_ifnet(struct ifnet *ifnet, struct label *ifnetlabel)
326{
327
328}
329
330static void
331mac_none_create_ipq(struct mbuf *fragment, struct label *fragmentlabel,
332    struct ipq *ipq, struct label *ipqlabel)
333{
334
335}
336
337static void
338mac_none_create_mbuf_from_mbuf(struct mbuf *oldmbuf,
339    struct label *oldmbuflabel, struct mbuf *newmbuf,
340    struct label *newmbuflabel)
341{
342
343}
344
345static void
346mac_none_create_mbuf_linklayer(struct ifnet *ifnet, struct label *ifnetlabel,
347    struct mbuf *mbuf, struct label *mbuflabel)
348{
349
350}
351
352static void
353mac_none_create_mbuf_from_bpfdesc(struct bpf_d *bpf_d, struct label *bpflabel,
354    struct mbuf *mbuf, struct label *mbuflabel)
355{
356
357}
358
359static void
360mac_none_create_mbuf_from_ifnet(struct ifnet *ifnet, struct label *ifnetlabel,
361    struct mbuf *m, struct label *mbuflabel)
362{
363
364}
365
366static void
367mac_none_create_mbuf_multicast_encap(struct mbuf *oldmbuf,
368    struct label *oldmbuflabel, struct ifnet *ifnet, struct label *ifnetlabel,
369    struct mbuf *newmbuf, struct label *newmbuflabel)
370{
371
372}
373
374static void
375mac_none_create_mbuf_netlayer(struct mbuf *oldmbuf,
376    struct label *oldmbuflabel, struct mbuf *newmbuf, struct label *newmbuflabel)
377{
378
379}
380
381static int
382mac_none_fragment_match(struct mbuf *fragment, struct label *fragmentlabel,
383    struct ipq *ipq, struct label *ipqlabel)
384{
385
386	return (1);
387}
388
389static void
390mac_none_relabel_ifnet(struct ucred *cred, struct ifnet *ifnet,
391    struct label *ifnetlabel, struct label *newlabel)
392{
393
394}
395
396static void
397mac_none_update_ipq(struct mbuf *fragment, struct label *fragmentlabel,
398    struct ipq *ipq, struct label *ipqlabel)
399{
400
401}
402
403/*
404 * Labeling event operations: processes.
405 */
406static void
407mac_none_create_cred(struct ucred *cred_parent, struct ucred *cred_child)
408{
409
410}
411
412static void
413mac_none_execve_transition(struct ucred *old, struct ucred *new,
414    struct vnode *vp, struct label *vnodelabel,
415    struct label *interpvnodelabel, struct image_params *imgp,
416    struct label *execlabel)
417{
418
419}
420
421static int
422mac_none_execve_will_transition(struct ucred *old, struct vnode *vp,
423    struct label *vnodelabel, struct label *interpvnodelabel,
424    struct image_params *imgp, struct label *execlabel)
425{
426
427	return (0);
428}
429
430static void
431mac_none_create_proc0(struct ucred *cred)
432{
433
434}
435
436static void
437mac_none_create_proc1(struct ucred *cred)
438{
439
440}
441
442static void
443mac_none_relabel_cred(struct ucred *cred, struct label *newlabel)
444{
445
446}
447
448static void
449mac_none_thread_userret(struct thread *td)
450{
451
452}
453
454/*
455 * Access control checks.
456 */
457static int
458mac_none_check_bpfdesc_receive(struct bpf_d *bpf_d, struct label *bpflabel,
459    struct ifnet *ifnet, struct label *ifnet_label)
460{
461
462        return (0);
463}
464
465static int
466mac_none_check_cred_relabel(struct ucred *cred, struct label *newlabel)
467{
468
469	return (0);
470}
471
472static int
473mac_none_check_cred_visible(struct ucred *u1, struct ucred *u2)
474{
475
476	return (0);
477}
478
479static int
480mac_none_check_ifnet_relabel(struct ucred *cred, struct ifnet *ifnet,
481    struct label *ifnetlabel, struct label *newlabel)
482{
483
484	return (0);
485}
486
487static int
488mac_none_check_ifnet_transmit(struct ifnet *ifnet, struct label *ifnetlabel,
489    struct mbuf *m, struct label *mbuflabel)
490{
491
492	return (0);
493}
494
495static int
496mac_none_check_kenv_dump(struct ucred *cred)
497{
498
499	return (0);
500}
501
502static int
503mac_none_check_kenv_get(struct ucred *cred, char *name)
504{
505
506	return (0);
507}
508
509static int
510mac_none_check_kenv_set(struct ucred *cred, char *name, char *value)
511{
512
513	return (0);
514}
515
516static int
517mac_none_check_kenv_unset(struct ucred *cred, char *name)
518{
519
520	return (0);
521}
522
523static int
524mac_none_check_kld_load(struct ucred *cred, struct vnode *vp,
525    struct label *vlabel)
526{
527
528	return (0);
529}
530
531static int
532mac_none_check_kld_stat(struct ucred *cred)
533{
534
535	return (0);
536}
537
538static int
539mac_none_check_kld_unload(struct ucred *cred)
540{
541
542	return (0);
543}
544
545static int
546mac_none_check_mount_stat(struct ucred *cred, struct mount *mp,
547    struct label *mntlabel)
548{
549
550	return (0);
551}
552
553static int
554mac_none_check_pipe_ioctl(struct ucred *cred, struct pipe *pipe,
555    struct label *pipelabel, unsigned long cmd, void /* caddr_t */ *data)
556{
557
558	return (0);
559}
560
561static int
562mac_none_check_pipe_poll(struct ucred *cred, struct pipe *pipe,
563    struct label *pipelabel)
564{
565
566	return (0);
567}
568
569static int
570mac_none_check_pipe_read(struct ucred *cred, struct pipe *pipe,
571    struct label *pipelabel)
572{
573
574	return (0);
575}
576
577static int
578mac_none_check_pipe_relabel(struct ucred *cred, struct pipe *pipe,
579    struct label *pipelabel, struct label *newlabel)
580{
581
582	return (0);
583}
584
585static int
586mac_none_check_pipe_stat(struct ucred *cred, struct pipe *pipe,
587    struct label *pipelabel)
588{
589
590	return (0);
591}
592
593static int
594mac_none_check_pipe_write(struct ucred *cred, struct pipe *pipe,
595    struct label *pipelabel)
596{
597
598	return (0);
599}
600
601static int
602mac_none_check_proc_debug(struct ucred *cred, struct proc *proc)
603{
604
605	return (0);
606}
607
608static int
609mac_none_check_proc_sched(struct ucred *cred, struct proc *proc)
610{
611
612	return (0);
613}
614
615static int
616mac_none_check_proc_signal(struct ucred *cred, struct proc *proc, int signum)
617{
618
619	return (0);
620}
621
622static int
623mac_none_check_socket_bind(struct ucred *cred, struct socket *socket,
624    struct label *socketlabel, struct sockaddr *sockaddr)
625{
626
627	return (0);
628}
629
630static int
631mac_none_check_socket_connect(struct ucred *cred, struct socket *socket,
632    struct label *socketlabel, struct sockaddr *sockaddr)
633{
634
635	return (0);
636}
637
638static int
639mac_none_check_socket_deliver(struct socket *so, struct label *socketlabel,
640    struct mbuf *m, struct label *mbuflabel)
641{
642
643	return (0);
644}
645
646static int
647mac_none_check_socket_listen(struct ucred *cred, struct socket *so,
648    struct label *socketlabel)
649{
650
651	return (0);
652}
653
654static int
655mac_none_check_socket_relabel(struct ucred *cred, struct socket *socket,
656    struct label *socketlabel, struct label *newlabel)
657{
658
659	return (0);
660}
661
662static int
663mac_none_check_socket_visible(struct ucred *cred, struct socket *socket,
664   struct label *socketlabel)
665{
666
667	return (0);
668}
669
670static int
671mac_none_check_sysarch_ioperm(struct ucred *cred)
672{
673
674	return (0);
675}
676
677static int
678mac_none_check_system_acct(struct ucred *cred, struct vnode *vp,
679    struct label *vlabel)
680{
681
682	return (0);
683}
684
685static int
686mac_none_check_system_reboot(struct ucred *cred, int how)
687{
688
689	return (0);
690}
691
692static int
693mac_none_check_system_settime(struct ucred *cred)
694{
695
696	return (0);
697}
698
699static int
700mac_none_check_system_swapon(struct ucred *cred, struct vnode *vp,
701    struct label *label)
702{
703
704	return (0);
705}
706
707static int
708mac_none_check_system_swapoff(struct ucred *cred, struct vnode *vp,
709    struct label *label)
710{
711
712	return (0);
713}
714
715static int
716mac_none_check_system_sysctl(struct ucred *cred, int *name, u_int namelen,
717    void *old, size_t *oldlenp, int inkernel, void *new, size_t newlen)
718{
719
720	return (0);
721}
722
723static int
724mac_none_check_vnode_access(struct ucred *cred, struct vnode *vp,
725    struct label *label, int acc_mode)
726{
727
728	return (0);
729}
730
731static int
732mac_none_check_vnode_chdir(struct ucred *cred, struct vnode *dvp,
733    struct label *dlabel)
734{
735
736	return (0);
737}
738
739static int
740mac_none_check_vnode_chroot(struct ucred *cred, struct vnode *dvp,
741    struct label *dlabel)
742{
743
744	return (0);
745}
746
747static int
748mac_none_check_vnode_create(struct ucred *cred, struct vnode *dvp,
749    struct label *dlabel, struct componentname *cnp, struct vattr *vap)
750{
751
752	return (0);
753}
754
755static int
756mac_none_check_vnode_delete(struct ucred *cred, struct vnode *dvp,
757    struct label *dlabel, struct vnode *vp, struct label *label,
758    struct componentname *cnp)
759{
760
761	return (0);
762}
763
764static int
765mac_none_check_vnode_deleteacl(struct ucred *cred, struct vnode *vp,
766    struct label *label, acl_type_t type)
767{
768
769	return (0);
770}
771
772static int
773mac_none_check_vnode_exec(struct ucred *cred, struct vnode *vp,
774    struct label *label, struct image_params *imgp,
775    struct label *execlabel)
776{
777
778	return (0);
779}
780
781static int
782mac_none_check_vnode_getacl(struct ucred *cred, struct vnode *vp,
783    struct label *label, acl_type_t type)
784{
785
786	return (0);
787}
788
789static int
790mac_none_check_vnode_getextattr(struct ucred *cred, struct vnode *vp,
791    struct label *label, int attrnamespace, const char *name, struct uio *uio)
792{
793
794	return (0);
795}
796
797static int
798mac_none_check_vnode_link(struct ucred *cred, struct vnode *dvp,
799    struct label *dlabel, struct vnode *vp, struct label *label,
800    struct componentname *cnp)
801{
802
803	return (0);
804}
805
806static int
807mac_none_check_vnode_lookup(struct ucred *cred, struct vnode *dvp,
808    struct label *dlabel, struct componentname *cnp)
809{
810
811	return (0);
812}
813
814static int
815mac_none_check_vnode_mmap(struct ucred *cred, struct vnode *vp,
816    struct label *label, int prot)
817{
818
819	return (0);
820}
821
822static int
823mac_none_check_vnode_mprotect(struct ucred *cred, struct vnode *vp,
824    struct label *label, int prot)
825{
826
827	return (0);
828}
829
830static int
831mac_none_check_vnode_open(struct ucred *cred, struct vnode *vp,
832    struct label *filelabel, int acc_mode)
833{
834
835	return (0);
836}
837
838static int
839mac_none_check_vnode_poll(struct ucred *active_cred, struct ucred *file_cred,
840    struct vnode *vp, struct label *label)
841{
842
843	return (0);
844}
845
846static int
847mac_none_check_vnode_read(struct ucred *active_cred, struct ucred *file_cred,
848    struct vnode *vp, struct label *label)
849{
850
851	return (0);
852}
853
854static int
855mac_none_check_vnode_readdir(struct ucred *cred, struct vnode *vp,
856    struct label *dlabel)
857{
858
859	return (0);
860}
861
862static int
863mac_none_check_vnode_readlink(struct ucred *cred, struct vnode *vp,
864    struct label *vnodelabel)
865{
866
867	return (0);
868}
869
870static int
871mac_none_check_vnode_relabel(struct ucred *cred, struct vnode *vp,
872    struct label *vnodelabel, struct label *newlabel)
873{
874
875	return (0);
876}
877
878static int
879mac_none_check_vnode_rename_from(struct ucred *cred, struct vnode *dvp,
880    struct label *dlabel, struct vnode *vp, struct label *label,
881    struct componentname *cnp)
882{
883
884	return (0);
885}
886
887static int
888mac_none_check_vnode_rename_to(struct ucred *cred, struct vnode *dvp,
889    struct label *dlabel, struct vnode *vp, struct label *label, int samedir,
890    struct componentname *cnp)
891{
892
893	return (0);
894}
895
896static int
897mac_none_check_vnode_revoke(struct ucred *cred, struct vnode *vp,
898    struct label *label)
899{
900
901	return (0);
902}
903
904static int
905mac_none_check_vnode_setacl(struct ucred *cred, struct vnode *vp,
906    struct label *label, acl_type_t type, struct acl *acl)
907{
908
909	return (0);
910}
911
912static int
913mac_none_check_vnode_setextattr(struct ucred *cred, struct vnode *vp,
914    struct label *label, int attrnamespace, const char *name, struct uio *uio)
915{
916
917	return (0);
918}
919
920static int
921mac_none_check_vnode_setflags(struct ucred *cred, struct vnode *vp,
922    struct label *label, u_long flags)
923{
924
925	return (0);
926}
927
928static int
929mac_none_check_vnode_setmode(struct ucred *cred, struct vnode *vp,
930    struct label *label, mode_t mode)
931{
932
933	return (0);
934}
935
936static int
937mac_none_check_vnode_setowner(struct ucred *cred, struct vnode *vp,
938    struct label *label, uid_t uid, gid_t gid)
939{
940
941	return (0);
942}
943
944static int
945mac_none_check_vnode_setutimes(struct ucred *cred, struct vnode *vp,
946    struct label *label, struct timespec atime, struct timespec mtime)
947{
948
949	return (0);
950}
951
952static int
953mac_none_check_vnode_stat(struct ucred *active_cred, struct ucred *file_cred,
954    struct vnode *vp, struct label *label)
955{
956
957	return (0);
958}
959
960static int
961mac_none_check_vnode_write(struct ucred *active_cred,
962    struct ucred *file_cred, struct vnode *vp, struct label *label)
963{
964
965	return (0);
966}
967
968static struct mac_policy_ops mac_none_ops =
969{
970	.mpo_destroy = mac_none_destroy,
971	.mpo_init = mac_none_init,
972	.mpo_syscall = mac_none_syscall,
973	.mpo_init_bpfdesc_label = mac_none_init_label,
974	.mpo_init_cred_label = mac_none_init_label,
975	.mpo_init_devfsdirent_label = mac_none_init_label,
976	.mpo_init_ifnet_label = mac_none_init_label,
977	.mpo_init_ipq_label = mac_none_init_label_waitcheck,
978	.mpo_init_mbuf_label = mac_none_init_label_waitcheck,
979	.mpo_init_mount_label = mac_none_init_label,
980	.mpo_init_mount_fs_label = mac_none_init_label,
981	.mpo_init_pipe_label = mac_none_init_label,
982	.mpo_init_socket_label = mac_none_init_label_waitcheck,
983	.mpo_init_socket_peer_label = mac_none_init_label_waitcheck,
984	.mpo_init_vnode_label = mac_none_init_label,
985	.mpo_destroy_bpfdesc_label = mac_none_destroy_label,
986	.mpo_destroy_cred_label = mac_none_destroy_label,
987	.mpo_destroy_devfsdirent_label = mac_none_destroy_label,
988	.mpo_destroy_ifnet_label = mac_none_destroy_label,
989	.mpo_destroy_ipq_label = mac_none_destroy_label,
990	.mpo_destroy_mbuf_label = mac_none_destroy_label,
991	.mpo_destroy_mount_label = mac_none_destroy_label,
992	.mpo_destroy_mount_fs_label = mac_none_destroy_label,
993	.mpo_destroy_pipe_label = mac_none_destroy_label,
994	.mpo_destroy_socket_label = mac_none_destroy_label,
995	.mpo_destroy_socket_peer_label = mac_none_destroy_label,
996	.mpo_destroy_vnode_label = mac_none_destroy_label,
997	.mpo_externalize_cred_label = mac_none_externalize_label,
998	.mpo_externalize_ifnet_label = mac_none_externalize_label,
999	.mpo_externalize_pipe_label = mac_none_externalize_label,
1000	.mpo_externalize_socket_label = mac_none_externalize_label,
1001	.mpo_externalize_socket_peer_label = mac_none_externalize_label,
1002	.mpo_externalize_vnode_label = mac_none_externalize_label,
1003	.mpo_internalize_cred_label = mac_none_internalize_label,
1004	.mpo_internalize_ifnet_label = mac_none_internalize_label,
1005	.mpo_internalize_pipe_label = mac_none_internalize_label,
1006	.mpo_internalize_socket_label = mac_none_internalize_label,
1007	.mpo_internalize_vnode_label = mac_none_internalize_label,
1008	.mpo_associate_vnode_devfs = mac_none_associate_vnode_devfs,
1009	.mpo_associate_vnode_extattr = mac_none_associate_vnode_extattr,
1010	.mpo_associate_vnode_singlelabel = mac_none_associate_vnode_singlelabel,
1011	.mpo_create_devfs_device = mac_none_create_devfs_device,
1012	.mpo_create_devfs_directory = mac_none_create_devfs_directory,
1013	.mpo_create_devfs_symlink = mac_none_create_devfs_symlink,
1014	.mpo_create_vnode_extattr = mac_none_create_vnode_extattr,
1015	.mpo_create_mount = mac_none_create_mount,
1016	.mpo_create_root_mount = mac_none_create_root_mount,
1017	.mpo_relabel_vnode = mac_none_relabel_vnode,
1018	.mpo_setlabel_vnode_extattr = mac_none_setlabel_vnode_extattr,
1019	.mpo_update_devfsdirent = mac_none_update_devfsdirent,
1020	.mpo_create_mbuf_from_socket = mac_none_create_mbuf_from_socket,
1021	.mpo_create_pipe = mac_none_create_pipe,
1022	.mpo_create_socket = mac_none_create_socket,
1023	.mpo_create_socket_from_socket = mac_none_create_socket_from_socket,
1024	.mpo_relabel_pipe = mac_none_relabel_pipe,
1025	.mpo_relabel_socket = mac_none_relabel_socket,
1026	.mpo_set_socket_peer_from_mbuf = mac_none_set_socket_peer_from_mbuf,
1027	.mpo_set_socket_peer_from_socket = mac_none_set_socket_peer_from_socket,
1028	.mpo_create_bpfdesc = mac_none_create_bpfdesc,
1029	.mpo_create_ifnet = mac_none_create_ifnet,
1030	.mpo_create_ipq = mac_none_create_ipq,
1031	.mpo_create_datagram_from_ipq = mac_none_create_datagram_from_ipq,
1032	.mpo_create_fragment = mac_none_create_fragment,
1033	.mpo_create_ipq = mac_none_create_ipq,
1034	.mpo_create_mbuf_from_mbuf = mac_none_create_mbuf_from_mbuf,
1035	.mpo_create_mbuf_linklayer = mac_none_create_mbuf_linklayer,
1036	.mpo_create_mbuf_from_bpfdesc = mac_none_create_mbuf_from_bpfdesc,
1037	.mpo_create_mbuf_from_ifnet = mac_none_create_mbuf_from_ifnet,
1038	.mpo_create_mbuf_multicast_encap = mac_none_create_mbuf_multicast_encap,
1039	.mpo_create_mbuf_netlayer = mac_none_create_mbuf_netlayer,
1040	.mpo_fragment_match = mac_none_fragment_match,
1041	.mpo_relabel_ifnet = mac_none_relabel_ifnet,
1042	.mpo_update_ipq = mac_none_update_ipq,
1043	.mpo_create_cred = mac_none_create_cred,
1044	.mpo_execve_transition = mac_none_execve_transition,
1045	.mpo_execve_will_transition = mac_none_execve_will_transition,
1046	.mpo_create_proc0 = mac_none_create_proc0,
1047	.mpo_create_proc1 = mac_none_create_proc1,
1048	.mpo_relabel_cred = mac_none_relabel_cred,
1049	.mpo_thread_userret = mac_none_thread_userret,
1050	.mpo_check_bpfdesc_receive = mac_none_check_bpfdesc_receive,
1051	.mpo_check_cred_relabel = mac_none_check_cred_relabel,
1052	.mpo_check_cred_visible = mac_none_check_cred_visible,
1053	.mpo_check_ifnet_relabel = mac_none_check_ifnet_relabel,
1054	.mpo_check_ifnet_transmit = mac_none_check_ifnet_transmit,
1055	.mpo_check_kenv_dump = mac_none_check_kenv_dump,
1056	.mpo_check_kenv_get = mac_none_check_kenv_get,
1057	.mpo_check_kenv_set = mac_none_check_kenv_set,
1058	.mpo_check_kenv_unset = mac_none_check_kenv_unset,
1059	.mpo_check_kld_load = mac_none_check_kld_load,
1060	.mpo_check_kld_stat = mac_none_check_kld_stat,
1061	.mpo_check_kld_unload = mac_none_check_kld_unload,
1062	.mpo_check_mount_stat = mac_none_check_mount_stat,
1063	.mpo_check_pipe_ioctl = mac_none_check_pipe_ioctl,
1064	.mpo_check_pipe_poll = mac_none_check_pipe_poll,
1065	.mpo_check_pipe_read = mac_none_check_pipe_read,
1066	.mpo_check_pipe_relabel = mac_none_check_pipe_relabel,
1067	.mpo_check_pipe_stat = mac_none_check_pipe_stat,
1068	.mpo_check_pipe_write = mac_none_check_pipe_write,
1069	.mpo_check_proc_debug = mac_none_check_proc_debug,
1070	.mpo_check_proc_sched = mac_none_check_proc_sched,
1071	.mpo_check_proc_signal = mac_none_check_proc_signal,
1072	.mpo_check_socket_bind = mac_none_check_socket_bind,
1073	.mpo_check_socket_connect = mac_none_check_socket_connect,
1074	.mpo_check_socket_deliver = mac_none_check_socket_deliver,
1075	.mpo_check_socket_listen = mac_none_check_socket_listen,
1076	.mpo_check_socket_relabel = mac_none_check_socket_relabel,
1077	.mpo_check_socket_visible = mac_none_check_socket_visible,
1078	.mpo_check_sysarch_ioperm = mac_none_check_sysarch_ioperm,
1079	.mpo_check_system_acct = mac_none_check_system_acct,
1080	.mpo_check_system_reboot = mac_none_check_system_reboot,
1081	.mpo_check_system_settime = mac_none_check_system_settime,
1082	.mpo_check_system_swapon = mac_none_check_system_swapon,
1083	.mpo_check_system_swapoff = mac_none_check_system_swapoff,
1084	.mpo_check_system_sysctl = mac_none_check_system_sysctl,
1085	.mpo_check_vnode_access = mac_none_check_vnode_access,
1086	.mpo_check_vnode_chdir = mac_none_check_vnode_chdir,
1087	.mpo_check_vnode_chroot = mac_none_check_vnode_chroot,
1088	.mpo_check_vnode_create = mac_none_check_vnode_create,
1089	.mpo_check_vnode_delete = mac_none_check_vnode_delete,
1090	.mpo_check_vnode_deleteacl = mac_none_check_vnode_deleteacl,
1091	.mpo_check_vnode_exec = mac_none_check_vnode_exec,
1092	.mpo_check_vnode_getacl = mac_none_check_vnode_getacl,
1093	.mpo_check_vnode_getextattr = mac_none_check_vnode_getextattr,
1094	.mpo_check_vnode_link = mac_none_check_vnode_link,
1095	.mpo_check_vnode_lookup = mac_none_check_vnode_lookup,
1096	.mpo_check_vnode_mmap = mac_none_check_vnode_mmap,
1097	.mpo_check_vnode_mprotect = mac_none_check_vnode_mprotect,
1098	.mpo_check_vnode_open = mac_none_check_vnode_open,
1099	.mpo_check_vnode_poll = mac_none_check_vnode_poll,
1100	.mpo_check_vnode_read = mac_none_check_vnode_read,
1101	.mpo_check_vnode_readdir = mac_none_check_vnode_readdir,
1102	.mpo_check_vnode_readlink = mac_none_check_vnode_readlink,
1103	.mpo_check_vnode_relabel = mac_none_check_vnode_relabel,
1104	.mpo_check_vnode_rename_from = mac_none_check_vnode_rename_from,
1105	.mpo_check_vnode_rename_to = mac_none_check_vnode_rename_to,
1106	.mpo_check_vnode_revoke = mac_none_check_vnode_revoke,
1107	.mpo_check_vnode_setacl = mac_none_check_vnode_setacl,
1108	.mpo_check_vnode_setextattr = mac_none_check_vnode_setextattr,
1109	.mpo_check_vnode_setflags = mac_none_check_vnode_setflags,
1110	.mpo_check_vnode_setmode = mac_none_check_vnode_setmode,
1111	.mpo_check_vnode_setowner = mac_none_check_vnode_setowner,
1112	.mpo_check_vnode_setutimes = mac_none_check_vnode_setutimes,
1113	.mpo_check_vnode_stat = mac_none_check_vnode_stat,
1114	.mpo_check_vnode_write = mac_none_check_vnode_write,
1115};
1116
1117MAC_POLICY_SET(&mac_none_ops, mac_none, "TrustedBSD MAC/None",
1118    MPC_LOADTIME_FLAG_UNLOADOK, NULL);
1119