The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: James Morris <jmorris@namei.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: linux-kernel@vger.kernel.org, Stephen Smalley <sds@tycho.nsa.gov>,
	"David S. Miller" <davem@davemloft.net>
Subject: [PATCH 01/12] NetLabel: cleanup and document CIPSO constants
Date: Thu, 26 Apr 2007 02:03:28 -0400 (EDT)	[thread overview]
Message-ID: <Line.LNX.4.64.0704260202340.30059@d.namei> (raw)
In-Reply-To: <Line.LNX.4.64.0704260200450.30059@d.namei>

From: Paul Moore <paul.moore@hp.com>

This patch collects all of the CIPSO constants and puts them in one place; it
also documents each value explaining how the value is derived.

Signed-off-by: Paul Moore <paul.moore@hp.com>
Signed-off-by: James Morris <jmorris@namei.org>
---
 net/ipv4/cipso_ipv4.c |   37 +++++++++++++++++++++++++++++--------
 1 files changed, 29 insertions(+), 8 deletions(-)

diff --git a/net/ipv4/cipso_ipv4.c b/net/ipv4/cipso_ipv4.c
index 2ce5b69..d466bd5 100644
--- a/net/ipv4/cipso_ipv4.c
+++ b/net/ipv4/cipso_ipv4.c
@@ -92,6 +92,33 @@ int cipso_v4_rbm_optfmt = 0;
 int cipso_v4_rbm_strictvalid = 1;
 
 /*
+ * Protocol Constants
+ */
+
+/* Maximum size of the CIPSO IP option, derived from the fact that the maximum
+ * IPv4 header size is 60 bytes and the base IPv4 header is 20 bytes long. */
+#define CIPSO_V4_OPT_LEN_MAX          40
+
+/* Length of the base CIPSO option, this includes the option type (1 byte), the
+ * option length (1 byte), and the DOI (4 bytes). */
+#define CIPSO_V4_HDR_LEN              6
+
+/* Base length of the restrictive category bitmap tag (tag #1). */
+#define CIPSO_V4_TAG_RBM_BLEN         4
+
+/* Base length of the enumerated category tag (tag #2). */
+#define CIPSO_V4_TAG_ENUM_BLEN        4
+
+/* Base length of the ranged categories bitmap tag (tag #5). */
+#define CIPSO_V4_TAG_RNG_BLEN         4
+/* The maximum number of category ranges permitted in the ranged category tag
+ * (tag #5).  You may note that the IETF draft states that the maximum number
+ * of category ranges is 7, but if the low end of the last category range is
+ * zero then it is possibile to fit 8 category ranges because the zero should
+ * be omitted. */
+#define CIPSO_V4_TAG_RNG_CAT_MAX      8
+
+/*
  * Helper Functions
  */
 
@@ -1109,15 +1136,12 @@ static int cipso_v4_map_cat_rng_hton(const struct cipso_v4_doi *doi_def,
 				     unsigned char *net_cat,
 				     u32 net_cat_len)
 {
-	/* The constant '16' is not random, it is the maximum number of
-	 * high/low category range pairs as permitted by the CIPSO draft based
-	 * on a maximum IPv4 header length of 60 bytes - the BUG_ON() assertion
-	 * does a sanity check to make sure we don't overflow the array. */
 	int iter = -1;
-	u16 array[16];
+	u16 array[CIPSO_V4_TAG_RNG_CAT_MAX * 2];
 	u32 array_cnt = 0;
 	u32 cat_size = 0;
 
+	/* make sure we don't overflow the 'array[]' variable */
 	BUG_ON(net_cat_len > 30);
 
 	for (;;) {
@@ -1196,9 +1220,6 @@ static int cipso_v4_map_cat_rng_ntoh(const struct cipso_v4_doi *doi_def,
  * Protocol Handling Functions
  */
 
-#define CIPSO_V4_OPT_LEN_MAX          40
-#define CIPSO_V4_HDR_LEN              6
-
 /**
  * cipso_v4_gentag_hdr - Generate a CIPSO option header
  * @doi_def: the DOI definition
-- 
1.5.0.6


  reply	other threads:[~2007-04-26  6:03 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-04-26  6:02 [PATCH 0/12] SELinux patches for 2.6.22 James Morris
2007-04-26  6:03 ` James Morris [this message]
2007-04-26  6:04 ` [PATCH 02/12] NetLabel: convert a BUG_ON in the CIPSO code to a runtime check James Morris
2007-04-26  6:05 ` [PATCH 03/12] SELinux: extract the NetLabel SELinux support from the security server James Morris
2007-04-26  6:06 ` [PATCH 04/12] SELinux: rename selinux_netlabel.h to netlabel.h James Morris
2007-04-26  6:07 ` [PATCH 05/12] MAINTAINERS: update selinux entry James Morris
2007-04-26  6:08 ` [PATCH 06/12] SELinux: move security_skb_extlbl_sid() out of the security server James Morris
2007-04-26  6:08 ` [PATCH 07/12] selinux: remove userland security class and permission definitions James Morris
2007-04-26  6:09 ` [PATCH 08/12] selinux: export initial SID contexts via selinuxfs James Morris
2007-04-26  6:10 ` [PATCH 09/12] selinux: explicitly number all selinuxfs inodes James Morris
2007-04-26  6:10 ` [PATCH 10/12] selinux: remove unused enumeration constant from selinuxfs James Morris
2007-04-26  6:11 ` [PATCH 11/12] selinux: change numbering of boolean directory inodes in selinuxfs James Morris
2007-04-26  6:12 ` [PATCH 12/12] selinux: preserve boolean values across policy reloads James Morris

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Line.LNX.4.64.0704260202340.30059@d.namei \
    --to=jmorris@namei.org \
    --cc=davem@davemloft.net \
    --cc=linux-kernel@vger.kernel.org \
    --cc=sds@tycho.nsa.gov \
    --cc=torvalds@linux-foundation.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox