From: James Morris <jmorris@namei.org>
To: Linus Torvalds <torvalds@linux-foundation.org>
Cc: linux-kernel@vger.kernel.org, Stephen Smalley <sds@tycho.nsa.gov>,
"David S. Miller" <davem@davemloft.net>
Subject: [PATCH 01/12] NetLabel: cleanup and document CIPSO constants
Date: Thu, 26 Apr 2007 02:03:28 -0400 (EDT) [thread overview]
Message-ID: <Line.LNX.4.64.0704260202340.30059@d.namei> (raw)
In-Reply-To: <Line.LNX.4.64.0704260200450.30059@d.namei>
From: Paul Moore <paul.moore@hp.com>
This patch collects all of the CIPSO constants and puts them in one place; it
also documents each value explaining how the value is derived.
Signed-off-by: Paul Moore <paul.moore@hp.com>
Signed-off-by: James Morris <jmorris@namei.org>
---
net/ipv4/cipso_ipv4.c | 37 +++++++++++++++++++++++++++++--------
1 files changed, 29 insertions(+), 8 deletions(-)
diff --git a/net/ipv4/cipso_ipv4.c b/net/ipv4/cipso_ipv4.c
index 2ce5b69..d466bd5 100644
--- a/net/ipv4/cipso_ipv4.c
+++ b/net/ipv4/cipso_ipv4.c
@@ -92,6 +92,33 @@ int cipso_v4_rbm_optfmt = 0;
int cipso_v4_rbm_strictvalid = 1;
/*
+ * Protocol Constants
+ */
+
+/* Maximum size of the CIPSO IP option, derived from the fact that the maximum
+ * IPv4 header size is 60 bytes and the base IPv4 header is 20 bytes long. */
+#define CIPSO_V4_OPT_LEN_MAX 40
+
+/* Length of the base CIPSO option, this includes the option type (1 byte), the
+ * option length (1 byte), and the DOI (4 bytes). */
+#define CIPSO_V4_HDR_LEN 6
+
+/* Base length of the restrictive category bitmap tag (tag #1). */
+#define CIPSO_V4_TAG_RBM_BLEN 4
+
+/* Base length of the enumerated category tag (tag #2). */
+#define CIPSO_V4_TAG_ENUM_BLEN 4
+
+/* Base length of the ranged categories bitmap tag (tag #5). */
+#define CIPSO_V4_TAG_RNG_BLEN 4
+/* The maximum number of category ranges permitted in the ranged category tag
+ * (tag #5). You may note that the IETF draft states that the maximum number
+ * of category ranges is 7, but if the low end of the last category range is
+ * zero then it is possibile to fit 8 category ranges because the zero should
+ * be omitted. */
+#define CIPSO_V4_TAG_RNG_CAT_MAX 8
+
+/*
* Helper Functions
*/
@@ -1109,15 +1136,12 @@ static int cipso_v4_map_cat_rng_hton(const struct cipso_v4_doi *doi_def,
unsigned char *net_cat,
u32 net_cat_len)
{
- /* The constant '16' is not random, it is the maximum number of
- * high/low category range pairs as permitted by the CIPSO draft based
- * on a maximum IPv4 header length of 60 bytes - the BUG_ON() assertion
- * does a sanity check to make sure we don't overflow the array. */
int iter = -1;
- u16 array[16];
+ u16 array[CIPSO_V4_TAG_RNG_CAT_MAX * 2];
u32 array_cnt = 0;
u32 cat_size = 0;
+ /* make sure we don't overflow the 'array[]' variable */
BUG_ON(net_cat_len > 30);
for (;;) {
@@ -1196,9 +1220,6 @@ static int cipso_v4_map_cat_rng_ntoh(const struct cipso_v4_doi *doi_def,
* Protocol Handling Functions
*/
-#define CIPSO_V4_OPT_LEN_MAX 40
-#define CIPSO_V4_HDR_LEN 6
-
/**
* cipso_v4_gentag_hdr - Generate a CIPSO option header
* @doi_def: the DOI definition
--
1.5.0.6
next prev parent reply other threads:[~2007-04-26 6:03 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-04-26 6:02 [PATCH 0/12] SELinux patches for 2.6.22 James Morris
2007-04-26 6:03 ` James Morris [this message]
2007-04-26 6:04 ` [PATCH 02/12] NetLabel: convert a BUG_ON in the CIPSO code to a runtime check James Morris
2007-04-26 6:05 ` [PATCH 03/12] SELinux: extract the NetLabel SELinux support from the security server James Morris
2007-04-26 6:06 ` [PATCH 04/12] SELinux: rename selinux_netlabel.h to netlabel.h James Morris
2007-04-26 6:07 ` [PATCH 05/12] MAINTAINERS: update selinux entry James Morris
2007-04-26 6:08 ` [PATCH 06/12] SELinux: move security_skb_extlbl_sid() out of the security server James Morris
2007-04-26 6:08 ` [PATCH 07/12] selinux: remove userland security class and permission definitions James Morris
2007-04-26 6:09 ` [PATCH 08/12] selinux: export initial SID contexts via selinuxfs James Morris
2007-04-26 6:10 ` [PATCH 09/12] selinux: explicitly number all selinuxfs inodes James Morris
2007-04-26 6:10 ` [PATCH 10/12] selinux: remove unused enumeration constant from selinuxfs James Morris
2007-04-26 6:11 ` [PATCH 11/12] selinux: change numbering of boolean directory inodes in selinuxfs James Morris
2007-04-26 6:12 ` [PATCH 12/12] selinux: preserve boolean values across policy reloads James Morris
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Line.LNX.4.64.0704260202340.30059@d.namei \
--to=jmorris@namei.org \
--cc=davem@davemloft.net \
--cc=linux-kernel@vger.kernel.org \
--cc=sds@tycho.nsa.gov \
--cc=torvalds@linux-foundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox