diff options
| author | Robert Watson <rwatson@FreeBSD.org> | 2008-10-28 21:53:10 +0000 |
|---|---|---|
| committer | Robert Watson <rwatson@FreeBSD.org> | 2008-10-28 21:53:10 +0000 |
| commit | 564f8f0fee165503b0b366ccdcc2bd933080a39b (patch) | |
| tree | 3d638b6a037aae8cb74c10686fe2d118831f9f38 /sys/security/mac/mac_process.c | |
| parent | 5031ddc46c06f199dbe08e976cbdce257192e13c (diff) | |
Notes
Diffstat (limited to 'sys/security/mac/mac_process.c')
| -rw-r--r-- | sys/security/mac/mac_process.c | 141 |
1 files changed, 0 insertions, 141 deletions
diff --git a/sys/security/mac/mac_process.c b/sys/security/mac/mac_process.c index bb29aaabb8e6f..dba4769d438bf 100644 --- a/sys/security/mac/mac_process.c +++ b/sys/security/mac/mac_process.c @@ -84,26 +84,6 @@ SYSCTL_INT(_security_mac, OID_AUTO, mmap_revocation_via_cow, CTLFLAG_RW, static void mac_proc_vm_revoke_recurse(struct thread *td, struct ucred *cred, struct vm_map *map); -struct label * -mac_cred_label_alloc(void) -{ - struct label *label; - - label = mac_labelzone_alloc(M_WAITOK); - MAC_PERFORM(cred_init_label, label); - return (label); -} - -void -mac_cred_init(struct ucred *cred) -{ - - if (mac_labeled & MPC_OBJECT_CRED) - cred->cr_label = mac_cred_label_alloc(); - else - cred->cr_label = NULL; -} - static struct label * mac_proc_label_alloc(void) { @@ -124,24 +104,6 @@ mac_proc_init(struct proc *p) p->p_label = NULL; } -void -mac_cred_label_free(struct label *label) -{ - - MAC_PERFORM(cred_destroy_label, label); - mac_labelzone_free(label); -} - -void -mac_cred_destroy(struct ucred *cred) -{ - - if (cred->cr_label != NULL) { - mac_cred_label_free(cred->cr_label); - cred->cr_label = NULL; - } -} - static void mac_proc_label_free(struct label *label) { @@ -160,65 +122,6 @@ mac_proc_destroy(struct proc *p) } } -/* - * When a thread becomes an NFS server daemon, its credential may need to be - * updated to reflect this so that policies can recognize when file system - * operations originate from the network. - * - * At some point, it would be desirable if the credential used for each NFS - * RPC could be set based on the RPC context (i.e., source system, etc) to - * provide more fine-grained access control. - */ -void -mac_cred_associate_nfsd(struct ucred *cred) -{ - - MAC_PERFORM(cred_associate_nfsd, cred); -} - -/* - * Initialize MAC label for the first kernel process, from which other kernel - * processes and threads are spawned. - */ -void -mac_cred_create_swapper(struct ucred *cred) -{ - - MAC_PERFORM(cred_create_swapper, cred); -} - -/* - * Initialize MAC label for the first userland process, from which other - * userland processes and threads are spawned. - */ -void -mac_cred_create_init(struct ucred *cred) -{ - - MAC_PERFORM(cred_create_init, cred); -} - -int -mac_cred_externalize_label(struct label *label, char *elements, - char *outbuf, size_t outbuflen) -{ - int error; - - MAC_EXTERNALIZE(cred, label, elements, outbuf, outbuflen); - - return (error); -} - -int -mac_cred_internalize_label(struct label *label, char *string) -{ - int error; - - MAC_INTERNALIZE(cred, label, string); - - return (error); -} - void mac_thread_userret(struct thread *td) { @@ -226,18 +129,6 @@ mac_thread_userret(struct thread *td) MAC_PERFORM(thread_userret, td); } -/* - * When a new process is created, its label must be initialized. Generally, - * this involves inheritence from the parent process, modulo possible deltas. - * This function allows that processing to take place. - */ -void -mac_cred_copy(struct ucred *src, struct ucred *dest) -{ - - MAC_PERFORM(cred_copy_label, src->cr_label, dest->cr_label); -} - int mac_execve_enter(struct image_params *imgp, struct mac *mac_p) { @@ -484,38 +375,6 @@ mac_proc_vm_revoke_recurse(struct thread *td, struct ucred *cred, vm_map_unlock_read(map); } -/* - * When the subject's label changes, it may require revocation of privilege - * to mapped objects. This can't be done on-the-fly later with a unified - * buffer cache. - */ -void -mac_cred_relabel(struct ucred *cred, struct label *newlabel) -{ - - MAC_PERFORM(cred_relabel, cred, newlabel); -} - -int -mac_cred_check_relabel(struct ucred *cred, struct label *newlabel) -{ - int error; - - MAC_CHECK(cred_check_relabel, cred, newlabel); - - return (error); -} - -int -mac_cred_check_visible(struct ucred *cr1, struct ucred *cr2) -{ - int error; - - MAC_CHECK(cred_check_visible, cr1, cr2); - - return (error); -} - int mac_proc_check_debug(struct ucred *cred, struct proc *p) { |
