summaryrefslogtreecommitdiffstats
path: root/security/apparmor/include/file.h
diff options
context:
space:
mode:
authorJohn Johansen <john.johansen@canonical.com>2017-05-21 17:15:28 -0700
committerJohn Johansen <john.johansen@canonical.com>2017-06-08 11:29:33 -0700
commitaf7caa8f8dd1b45e38a3653a69ed4d708286bc83 (patch)
treef2bf5db48baf996acf450c7aa5155c2aa98cd74b /security/apparmor/include/file.h
parent651e54953b5d4ad103f0efa54fc6b380807fca3a (diff)
downloadlinux-af7caa8f8dd1b45e38a3653a69ed4d708286bc83.tar.gz
linux-af7caa8f8dd1b45e38a3653a69ed4d708286bc83.tar.bz2
linux-af7caa8f8dd1b45e38a3653a69ed4d708286bc83.zip
apparmor: move file context into file.h
Signed-off-by: John Johansen <john.johansen@canonical.com>
Diffstat (limited to 'security/apparmor/include/file.h')
-rw-r--r--security/apparmor/include/file.h32
1 files changed, 32 insertions, 0 deletions
diff --git a/security/apparmor/include/file.h b/security/apparmor/include/file.h
index 38f821bf49b6..eba39cb25f02 100644
--- a/security/apparmor/include/file.h
+++ b/security/apparmor/include/file.h
@@ -47,6 +47,38 @@ struct path;
AA_MAY_CHMOD | AA_MAY_CHOWN | AA_MAY_LOCK | \
AA_EXEC_MMAP | AA_MAY_LINK)
+/* struct aa_file_ctx - the AppArmor context the file was opened in
+ * @perms: the permission the file was opened with
+ *
+ * The file_ctx could currently be directly stored in file->f_security
+ * as the profile reference is now stored in the f_cred. However the
+ * ctx struct will expand in the future so we keep the struct.
+ */
+struct aa_file_ctx {
+ u16 allow;
+};
+
+/**
+ * aa_alloc_file_context - allocate file_ctx
+ * @gfp: gfp flags for allocation
+ *
+ * Returns: file_ctx or NULL on failure
+ */
+static inline struct aa_file_ctx *aa_alloc_file_context(gfp_t gfp)
+{
+ return kzalloc(sizeof(struct aa_file_ctx), gfp);
+}
+
+/**
+ * aa_free_file_context - free a file_ctx
+ * @ctx: file_ctx to free (MAYBE_NULL)
+ */
+static inline void aa_free_file_context(struct aa_file_ctx *ctx)
+{
+ if (ctx)
+ kzfree(ctx);
+}
+
/*
* The xindex is broken into 3 parts
* - index - an index into either the exec name table or the variable table