• Home
  • Raw
  • Download

Lines Matching full:profile

99  * aa_mangle_name - mangle a profile name to std profile layout form
100 * @name: profile name to mangle (NOT NULL)
608 static void profile_query_cb(struct aa_profile *profile, struct aa_perms *perms, in profile_query_cb() argument
615 if (profile_unconfined(profile)) in profile_query_cb()
617 if (profile->file.dfa && *match_str == AA_CLASS_FILE) { in profile_query_cb()
618 dfa = profile->file.dfa; in profile_query_cb()
619 state = aa_dfa_match_len(dfa, profile->file.start, in profile_query_cb()
626 } else if (profile->policy.dfa) { in profile_query_cb()
627 if (!PROFILE_MEDIATES(profile, *match_str)) in profile_query_cb()
629 dfa = profile->policy.dfa; in profile_query_cb()
630 state = aa_dfa_match_len(dfa, profile->policy.start[0], in profile_query_cb()
635 aa_apply_modes_to_perms(profile, &tmp); in profile_query_cb()
665 struct aa_profile *profile; in query_data() local
700 label_for_each_confined(i, label, profile) { in query_data()
701 if (!profile->data) in query_data()
704 data = rhashtable_lookup_fast(profile->data, &key, in query_data()
705 profile->data->p); in query_data()
754 struct aa_profile *profile; in query_label() local
771 * profile name and dfa string. profile_name_len is greater in query_label()
786 label_for_each_in_ns(i, labels_ns(label), label, profile) { in query_label()
787 profile_query_cb(profile, &perms, match_str, match_len); in query_label()
790 label_for_each(i, label, profile) { in query_label()
791 profile_query_cb(profile, &perms, match_str, match_len); in query_label()
905 #define QUERY_CMD_PROFILE "profile\0"
924 * profile query specific format described in the query_label() function
1026 * profile based file operations
1070 struct aa_profile *profile = labels_profile(label); in seq_profile_name_show() local
1071 seq_printf(seq, "%s\n", profile->base.name); in seq_profile_name_show()
1081 struct aa_profile *profile = labels_profile(label); in seq_profile_mode_show() local
1082 seq_printf(seq, "%s\n", aa_profile_mode_names[profile->mode]); in seq_profile_mode_show()
1092 struct aa_profile *profile = labels_profile(label); in seq_profile_attach_show() local
1093 if (profile->attach) in seq_profile_attach_show()
1094 seq_printf(seq, "%s\n", profile->attach); in seq_profile_attach_show()
1095 else if (profile->xmatch) in seq_profile_attach_show()
1098 seq_printf(seq, "%s\n", profile->base.name); in seq_profile_attach_show()
1108 struct aa_profile *profile = labels_profile(label); in seq_profile_hash_show() local
1111 if (profile->hash) { in seq_profile_hash_show()
1113 seq_printf(seq, "%.2x", profile->hash[i]); in seq_profile_hash_show()
1160 struct aa_profile *profile; in seq_ns_nsstacked_show() local
1167 label_for_each(it, label, profile) in seq_ns_nsstacked_show()
1168 if (profile->ns != labels_ns(label)) { in seq_ns_nsstacked_show()
1499 /** fns to setup dynamic per profile/namespace files **/
1503 * Requires: @profile->ns->lock held
1505 void __aafs_profile_rmdir(struct aa_profile *profile) in __aafs_profile_rmdir() argument
1510 if (!profile) in __aafs_profile_rmdir()
1513 list_for_each_entry(child, &profile->base.profiles, base.list) in __aafs_profile_rmdir()
1518 if (!profile->dents[i]) in __aafs_profile_rmdir()
1521 proxy = d_inode(profile->dents[i])->i_private; in __aafs_profile_rmdir()
1522 aafs_remove(profile->dents[i]); in __aafs_profile_rmdir()
1524 profile->dents[i] = NULL; in __aafs_profile_rmdir()
1550 struct aa_profile *profile, in create_profile_file() argument
1553 struct aa_proxy *proxy = aa_get_proxy(profile->label.proxy); in create_profile_file()
1563 static int profile_depth(struct aa_profile *profile) in profile_depth() argument
1568 for (depth = 0; profile; profile = rcu_access_pointer(profile->parent)) in profile_depth()
1612 struct aa_profile *profile; in rawdata_get_link_base() local
1620 profile = labels_profile(label); in rawdata_get_link_base()
1621 depth = profile_depth(profile); in rawdata_get_link_base()
1622 target = gen_symlink_name(depth, profile->rawdata->name, name); in rawdata_get_link_base()
1667 * Requires: @profile->ns->lock held
1669 int __aafs_profile_mkdir(struct aa_profile *profile, struct dentry *parent) in __aafs_profile_mkdir() argument
1675 AA_BUG(!profile); in __aafs_profile_mkdir()
1676 AA_BUG(!mutex_is_locked(&profiles_ns(profile)->lock)); in __aafs_profile_mkdir()
1680 p = aa_deref_parent(profile); in __aafs_profile_mkdir()
1689 if (!profile->dirname) { in __aafs_profile_mkdir()
1691 len = mangle_name(profile->base.name, NULL); in __aafs_profile_mkdir()
1692 id_len = snprintf(NULL, 0, ".%ld", profile->ns->uniq_id); in __aafs_profile_mkdir()
1694 profile->dirname = kmalloc(len + id_len + 1, GFP_KERNEL); in __aafs_profile_mkdir()
1695 if (!profile->dirname) { in __aafs_profile_mkdir()
1700 mangle_name(profile->base.name, profile->dirname); in __aafs_profile_mkdir()
1701 sprintf(profile->dirname + len, ".%ld", profile->ns->uniq_id++); in __aafs_profile_mkdir()
1704 dent = aafs_create_dir(profile->dirname, parent); in __aafs_profile_mkdir()
1707 prof_dir(profile) = dir = dent; in __aafs_profile_mkdir()
1709 dent = create_profile_file(dir, "name", profile, in __aafs_profile_mkdir()
1713 profile->dents[AAFS_PROF_NAME] = dent; in __aafs_profile_mkdir()
1715 dent = create_profile_file(dir, "mode", profile, in __aafs_profile_mkdir()
1719 profile->dents[AAFS_PROF_MODE] = dent; in __aafs_profile_mkdir()
1721 dent = create_profile_file(dir, "attach", profile, in __aafs_profile_mkdir()
1725 profile->dents[AAFS_PROF_ATTACH] = dent; in __aafs_profile_mkdir()
1727 if (profile->hash) { in __aafs_profile_mkdir()
1728 dent = create_profile_file(dir, "sha1", profile, in __aafs_profile_mkdir()
1732 profile->dents[AAFS_PROF_HASH] = dent; in __aafs_profile_mkdir()
1735 if (profile->rawdata) { in __aafs_profile_mkdir()
1737 profile->label.proxy, NULL, NULL, in __aafs_profile_mkdir()
1741 aa_get_proxy(profile->label.proxy); in __aafs_profile_mkdir()
1742 profile->dents[AAFS_PROF_RAW_HASH] = dent; in __aafs_profile_mkdir()
1745 profile->label.proxy, NULL, NULL, in __aafs_profile_mkdir()
1749 aa_get_proxy(profile->label.proxy); in __aafs_profile_mkdir()
1750 profile->dents[AAFS_PROF_RAW_ABI] = dent; in __aafs_profile_mkdir()
1753 profile->label.proxy, NULL, NULL, in __aafs_profile_mkdir()
1757 aa_get_proxy(profile->label.proxy); in __aafs_profile_mkdir()
1758 profile->dents[AAFS_PROF_RAW_DATA] = dent; in __aafs_profile_mkdir()
1761 list_for_each_entry(child, &profile->base.profiles, base.list) { in __aafs_profile_mkdir()
1762 error = __aafs_profile_mkdir(child, prof_child_dir(profile)); in __aafs_profile_mkdir()
1773 __aafs_profile_rmdir(profile); in __aafs_profile_mkdir()
2098 * __first_profile - find the first profile in a namespace
2102 * Returns: unrefcounted profile or NULL if no profile
2103 * Requires: profile->ns.lock to be held
2120 * __next_profile - step to the next profile in a profile tree
2121 * @profile: current profile in tree (NOT NULL)
2123 * Perform a depth first traversal on the profile tree in a namespace
2125 * Returns: next profile or NULL if done
2126 * Requires: profile->ns.lock to be held
2135 /* is next profile a child */ in __next_profile()
2140 /* is next profile a sibling, parent sibling, gp, sibling, .. */ in __next_profile()
2152 /* is next another profile in the namespace */ in __next_profile()
2161 * next_profile - step to the next profile in where ever it may be
2163 * @profile: current profile (NOT NULL)
2165 * Returns: next profile or NULL if there isn't one
2168 struct aa_profile *profile) in next_profile() argument
2170 struct aa_profile *next = __next_profile(profile); in next_profile()
2175 return __first_profile(root, __next_ns(root, profile->ns)); in next_profile()
2179 * p_start - start a depth first traversal of profile tree
2183 * Returns: first profile under current namespace or NULL if none found
2189 struct aa_profile *profile = NULL; in p_start() local
2194 /* find the first profile */ in p_start()
2196 profile = __first_profile(root, root); in p_start()
2199 for (; profile && l > 0; l--) in p_start()
2200 profile = next_profile(root, profile); in p_start()
2202 return profile; in p_start()
2206 * p_next - read the next profile entry
2208 * @p: profile previously returned
2211 * Returns: next profile after @p or NULL if none
2217 struct aa_profile *profile = p; in p_next() local
2221 return next_profile(ns, profile); in p_next()
2227 * @p: the last profile writen
2233 struct aa_profile *profile = p; in p_stop() local
2236 if (profile) { in p_stop()
2237 for (ns = profile->ns; ns && ns != root; ns = ns->parent) in p_stop()
2245 * seq_show_profile - show a profile entry
2247 * @p: current position (profile) (NOT NULL)
2253 struct aa_profile *profile = (struct aa_profile *)p; in seq_show_profile() local
2256 aa_label_seq_xprint(f, root, &profile->label, in seq_show_profile()
2348 AA_SFS_FILE_BOOLEAN("profile", 1),
2658 /* TODO: add default profile to apparmorfs */ in aa_create_aafs()