Home | History | Annotate | Download | only in policydb
      1 /* Authors: Karl MacMillan <kmacmillan (at) tresys.com>
      2  *          Frank Mayer <mayerf (at) tresys.com>
      3  *
      4  * Copyright (C) 2003 - 2005 Tresys Technology, LLC
      5  *
      6  *  This library is free software; you can redistribute it and/or
      7  *  modify it under the terms of the GNU Lesser General Public
      8  *  License as published by the Free Software Foundation; either
      9  *  version 2.1 of the License, or (at your option) any later version.
     10  *
     11  *  This library is distributed in the hope that it will be useful,
     12  *  but WITHOUT ANY WARRANTY; without even the implied warranty of
     13  *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
     14  *  Lesser General Public License for more details.
     15  *
     16  *  You should have received a copy of the GNU Lesser General Public
     17  *  License along with this library; if not, write to the Free Software
     18  *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
     19  */
     20 
     21 #ifndef _SEPOL_POLICYDB_CONDITIONAL_H_
     22 #define _SEPOL_POLICYDB_CONDITIONAL_H_
     23 
     24 #include <sepol/policydb/flask_types.h>
     25 #include <sepol/policydb/avtab.h>
     26 #include <sepol/policydb/symtab.h>
     27 #include <sepol/policydb/policydb.h>
     28 #include <sys/cdefs.h>
     29 
     30 __BEGIN_DECLS
     31 
     32 #define COND_EXPR_MAXDEPTH 10
     33 
     34 /* this is the max unique bools in a conditional expression
     35  * for which we precompute all outcomes for the expression.
     36  *
     37  * NOTE - do _NOT_ use value greater than 5 because
     38  * cond_node_t->expr_pre_comp can only hold at most 32 values
     39  */
     40 #define COND_MAX_BOOLS 5
     41 
     42 /*
     43  * A conditional expression is a list of operators and operands
     44  * in reverse polish notation.
     45  */
     46 typedef struct cond_expr {
     47 #define COND_BOOL	1	/* plain bool */
     48 #define COND_NOT	2	/* !bool */
     49 #define COND_OR		3	/* bool || bool */
     50 #define COND_AND	4	/* bool && bool */
     51 #define COND_XOR	5	/* bool ^ bool */
     52 #define COND_EQ		6	/* bool == bool */
     53 #define COND_NEQ	7	/* bool != bool */
     54 #define COND_LAST	COND_NEQ
     55 	uint32_t expr_type;
     56 	uint32_t bool;
     57 	struct cond_expr *next;
     58 } cond_expr_t;
     59 
     60 /*
     61  * Each cond_node_t contains a list of rules to be enabled/disabled
     62  * depending on the current value of the conditional expression. This
     63  * struct is for that list.
     64  */
     65 typedef struct cond_av_list {
     66 	avtab_ptr_t node;
     67 	struct cond_av_list *next;
     68 } cond_av_list_t;
     69 
     70 /*
     71  * A cond node represents a conditional block in a policy. It
     72  * contains a conditional expression, the current state of the expression,
     73  * two lists of rules to enable/disable depending on the value of the
     74  * expression (the true list corresponds to if and the false list corresponds
     75  * to else)..
     76  */
     77 typedef struct cond_node {
     78 	int cur_state;
     79 	cond_expr_t *expr;
     80 	/* these true/false lists point into te_avtab when that is used */
     81 	cond_av_list_t *true_list;
     82 	cond_av_list_t *false_list;
     83 	/* and these are used during parsing and for modules */
     84 	avrule_t *avtrue_list;
     85 	avrule_t *avfalse_list;
     86 	/* these fields are not written to binary policy */
     87 	unsigned int nbools;
     88 	uint32_t bool_ids[COND_MAX_BOOLS];
     89 	uint32_t expr_pre_comp;
     90 	struct cond_node *next;
     91 	/* a tunable conditional, calculated and used at expansion */
     92 #define	COND_NODE_FLAGS_TUNABLE	0x01
     93 	uint32_t flags;
     94 } cond_node_t;
     95 
     96 extern int cond_evaluate_expr(policydb_t * p, cond_expr_t * expr);
     97 extern cond_expr_t *cond_copy_expr(cond_expr_t * expr);
     98 
     99 extern int cond_expr_equal(cond_node_t * a, cond_node_t * b);
    100 extern int cond_normalize_expr(policydb_t * p, cond_node_t * cn);
    101 extern void cond_node_destroy(cond_node_t * node);
    102 extern void cond_expr_destroy(cond_expr_t * expr);
    103 
    104 extern cond_node_t *cond_node_find(policydb_t * p,
    105 				   cond_node_t * needle, cond_node_t * haystack,
    106 				   int *was_created);
    107 
    108 extern cond_node_t *cond_node_create(policydb_t * p, cond_node_t * node);
    109 
    110 extern cond_node_t *cond_node_search(policydb_t * p, cond_node_t * list,
    111 				     cond_node_t * cn);
    112 
    113 extern int evaluate_conds(policydb_t * p);
    114 
    115 extern avtab_datum_t *cond_av_list_search(avtab_key_t * key,
    116 					  cond_av_list_t * cond_list);
    117 
    118 extern void cond_av_list_destroy(cond_av_list_t * list);
    119 
    120 extern void cond_optimize_lists(cond_list_t * cl);
    121 
    122 extern int cond_policydb_init(policydb_t * p);
    123 extern void cond_policydb_destroy(policydb_t * p);
    124 extern void cond_list_destroy(cond_list_t * list);
    125 
    126 extern int cond_init_bool_indexes(policydb_t * p);
    127 extern int cond_destroy_bool(hashtab_key_t key, hashtab_datum_t datum, void *p);
    128 
    129 extern int cond_index_bool(hashtab_key_t key, hashtab_datum_t datum,
    130 			   void *datap);
    131 
    132 extern int cond_read_bool(policydb_t * p, hashtab_t h, struct policy_file *fp);
    133 
    134 extern int cond_read_list(policydb_t * p, cond_list_t ** list, void *fp);
    135 
    136 extern void cond_compute_av(avtab_t * ctab, avtab_key_t * key,
    137 			    struct sepol_av_decision *avd);
    138 
    139 __END_DECLS
    140 #endif				/* _CONDITIONAL_H_ */
    141