summaryrefslogtreecommitdiffstats
path: root/security/selinux/include/avc_ss.h
diff options
context:
space:
mode:
authorChad Sellers <csellers@tresys.com>2006-11-06 18:38:16 +0100
committerJames Morris <jmorris@namei.org>2006-11-28 18:04:36 +0100
commit5c45899879e8caadb78f04c9c639f4c2025b9f00 (patch)
treeee47228ccb816e523ac1051cfe41927059bc5ef9 /security/selinux/include/avc_ss.h
parentSELinux: remove current object class and permission validation mechanism (diff)
downloadlinux-5c45899879e8caadb78f04c9c639f4c2025b9f00.tar.xz
linux-5c45899879e8caadb78f04c9c639f4c2025b9f00.zip
SELinux: export object class and permission definitions
Moves the definition of the 3 structs containing object class and permission definitions from avc.c to avc_ss.h so that the security server can access them for validation on policy load. This also adds a new struct type, defined_classes_perms_t, suitable for allowing the security server to access these data structures from the avc. Signed-off-by: Chad Sellers <csellers@tresys.com> Acked-by: Stephen Smalley <sds@tycho.nsa.gov> Signed-off-by: James Morris <jmorris@namei.org>
Diffstat (limited to 'security/selinux/include/avc_ss.h')
-rw-r--r--security/selinux/include/avc_ss.h24
1 files changed, 24 insertions, 0 deletions
diff --git a/security/selinux/include/avc_ss.h b/security/selinux/include/avc_ss.h
index 450a2831e2e3..ff869e8b6f4a 100644
--- a/security/selinux/include/avc_ss.h
+++ b/security/selinux/include/avc_ss.h
@@ -10,5 +10,29 @@
int avc_ss_reset(u32 seqno);
+struct av_perm_to_string
+{
+ u16 tclass;
+ u32 value;
+ const char *name;
+};
+
+struct av_inherit
+{
+ u16 tclass;
+ const char **common_pts;
+ u32 common_base;
+};
+
+struct selinux_class_perm
+{
+ const struct av_perm_to_string *av_perm_to_string;
+ u32 av_pts_len;
+ const char **class_to_string;
+ u32 cts_len;
+ const struct av_inherit *av_inherit;
+ u32 av_inherit_len;
+};
+
#endif /* _SELINUX_AVC_SS_H_ */