1 /* 2 * Copyright (C) 2008 IBM Corporation 3 * Author: Mimi Zohar <[email protected]> 4 * 5 * This program is free software; you can redistribute it and/or modify 6 * it under the terms of the GNU General Public License as published by 7 * the Free Software Foundation, version 2 of the License. 8 */ 9 10 #ifndef _LINUX_IMA_H 11 #define _LINUX_IMA_H 12 13 #include <linux/fs.h> 14 #include <linux/security.h> 15 #include <linux/kexec.h> 16 struct linux_binprm; 17 18 #ifdef CONFIG_IMA 19 extern int ima_bprm_check(struct linux_binprm *bprm); 20 extern int ima_file_check(struct file *file, int mask); 21 extern void ima_post_create_tmpfile(struct inode *inode); 22 extern void ima_file_free(struct file *file); 23 extern int ima_file_mmap(struct file *file, unsigned long prot); 24 extern int ima_load_data(enum kernel_load_data_id id); 25 extern int ima_read_file(struct file *file, enum kernel_read_file_id id); 26 extern int ima_post_read_file(struct file *file, void *buf, loff_t size, 27 enum kernel_read_file_id id); 28 extern void ima_post_path_mknod(struct dentry *dentry); 29 30 #ifdef CONFIG_IMA_KEXEC 31 extern void ima_add_kexec_buffer(struct kimage *image); 32 #endif 33 34 #if defined(CONFIG_X86) && defined(CONFIG_EFI) 35 extern bool arch_ima_get_secureboot(void); 36 extern const char * const *arch_get_ima_policy(void); 37 #else 38 static inline bool arch_ima_get_secureboot(void) 39 { 40 return false; 41 } 42 43 static inline const char * const *arch_get_ima_policy(void) 44 { 45 return NULL; 46 } 47 #endif 48 49 #else 50 static inline int ima_bprm_check(struct linux_binprm *bprm) 51 { 52 return 0; 53 } 54 55 static inline int ima_file_check(struct file *file, int mask) 56 { 57 return 0; 58 } 59 60 static inline void ima_post_create_tmpfile(struct inode *inode) 61 { 62 } 63 64 static inline void ima_file_free(struct file *file) 65 { 66 return; 67 } 68 69 static inline int ima_file_mmap(struct file *file, unsigned long prot) 70 { 71 return 0; 72 } 73 74 static inline int ima_load_data(enum kernel_load_data_id id) 75 { 76 return 0; 77 } 78 79 static inline int ima_read_file(struct file *file, enum kernel_read_file_id id) 80 { 81 return 0; 82 } 83 84 static inline int ima_post_read_file(struct file *file, void *buf, loff_t size, 85 enum kernel_read_file_id id) 86 { 87 return 0; 88 } 89 90 static inline void ima_post_path_mknod(struct dentry *dentry) 91 { 92 return; 93 } 94 95 #endif /* CONFIG_IMA */ 96 97 #ifndef CONFIG_IMA_KEXEC 98 struct kimage; 99 100 static inline void ima_add_kexec_buffer(struct kimage *image) 101 {} 102 #endif 103 104 #ifdef CONFIG_IMA_APPRAISE 105 extern bool is_ima_appraise_enabled(void); 106 extern void ima_inode_post_setattr(struct dentry *dentry); 107 extern int ima_inode_setxattr(struct dentry *dentry, const char *xattr_name, 108 const void *xattr_value, size_t xattr_value_len); 109 extern int ima_inode_removexattr(struct dentry *dentry, const char *xattr_name); 110 #else 111 static inline bool is_ima_appraise_enabled(void) 112 { 113 return 0; 114 } 115 116 static inline void ima_inode_post_setattr(struct dentry *dentry) 117 { 118 return; 119 } 120 121 static inline int ima_inode_setxattr(struct dentry *dentry, 122 const char *xattr_name, 123 const void *xattr_value, 124 size_t xattr_value_len) 125 { 126 return 0; 127 } 128 129 static inline int ima_inode_removexattr(struct dentry *dentry, 130 const char *xattr_name) 131 { 132 return 0; 133 } 134 #endif /* CONFIG_IMA_APPRAISE */ 135 #endif /* _LINUX_IMA_H */ 136