Lines Matching refs:e
63 const char *name, const char *info, struct aa_ext *e, in audit_iface() argument
68 if (e) in audit_iface()
69 ad.iface.pos = e->pos - e->start; in audit_iface()
162 VISIBLE_IF_KUNIT bool aa_inbounds(struct aa_ext *e, size_t size) in aa_inbounds() argument
164 return (size <= e->end - e->pos); in aa_inbounds()
175 VISIBLE_IF_KUNIT size_t aa_unpack_u16_chunk(struct aa_ext *e, char **chunk) in aa_unpack_u16_chunk() argument
178 void *pos = e->pos; in aa_unpack_u16_chunk()
180 if (!aa_inbounds(e, sizeof(u16))) in aa_unpack_u16_chunk()
182 size = le16_to_cpu(get_unaligned((__le16 *) e->pos)); in aa_unpack_u16_chunk()
183 e->pos += sizeof(__le16); in aa_unpack_u16_chunk()
184 if (!aa_inbounds(e, size)) in aa_unpack_u16_chunk()
186 *chunk = e->pos; in aa_unpack_u16_chunk()
187 e->pos += size; in aa_unpack_u16_chunk()
191 e->pos = pos; in aa_unpack_u16_chunk()
197 VISIBLE_IF_KUNIT bool aa_unpack_X(struct aa_ext *e, enum aa_code code) in aa_unpack_X() argument
199 if (!aa_inbounds(e, 1)) in aa_unpack_X()
201 if (*(u8 *) e->pos != code) in aa_unpack_X()
203 e->pos++; in aa_unpack_X()
224 VISIBLE_IF_KUNIT bool aa_unpack_nameX(struct aa_ext *e, enum aa_code code, const char *name) in aa_unpack_nameX() argument
229 void *pos = e->pos; in aa_unpack_nameX()
234 if (aa_unpack_X(e, AA_NAME)) { in aa_unpack_nameX()
236 size_t size = aa_unpack_u16_chunk(e, &tag); in aa_unpack_nameX()
246 if (aa_unpack_X(e, code)) in aa_unpack_nameX()
250 e->pos = pos; in aa_unpack_nameX()
255 static bool unpack_u8(struct aa_ext *e, u8 *data, const char *name) in unpack_u8() argument
257 void *pos = e->pos; in unpack_u8()
259 if (aa_unpack_nameX(e, AA_U8, name)) { in unpack_u8()
260 if (!aa_inbounds(e, sizeof(u8))) in unpack_u8()
263 *data = *((u8 *)e->pos); in unpack_u8()
264 e->pos += sizeof(u8); in unpack_u8()
269 e->pos = pos; in unpack_u8()
273 VISIBLE_IF_KUNIT bool aa_unpack_u32(struct aa_ext *e, u32 *data, const char *name) in aa_unpack_u32() argument
275 void *pos = e->pos; in aa_unpack_u32()
277 if (aa_unpack_nameX(e, AA_U32, name)) { in aa_unpack_u32()
278 if (!aa_inbounds(e, sizeof(u32))) in aa_unpack_u32()
281 *data = le32_to_cpu(get_unaligned((__le32 *) e->pos)); in aa_unpack_u32()
282 e->pos += sizeof(u32); in aa_unpack_u32()
287 e->pos = pos; in aa_unpack_u32()
292 VISIBLE_IF_KUNIT bool aa_unpack_u64(struct aa_ext *e, u64 *data, const char *name) in aa_unpack_u64() argument
294 void *pos = e->pos; in aa_unpack_u64()
296 if (aa_unpack_nameX(e, AA_U64, name)) { in aa_unpack_u64()
297 if (!aa_inbounds(e, sizeof(u64))) in aa_unpack_u64()
300 *data = le64_to_cpu(get_unaligned((__le64 *) e->pos)); in aa_unpack_u64()
301 e->pos += sizeof(u64); in aa_unpack_u64()
306 e->pos = pos; in aa_unpack_u64()
311 static bool aa_unpack_cap_low(struct aa_ext *e, kernel_cap_t *data, const char *name) in aa_unpack_cap_low() argument
315 if (!aa_unpack_u32(e, &val, name)) in aa_unpack_cap_low()
321 static bool aa_unpack_cap_high(struct aa_ext *e, kernel_cap_t *data, const char *name) in aa_unpack_cap_high() argument
325 if (!aa_unpack_u32(e, &val, name)) in aa_unpack_cap_high()
331 VISIBLE_IF_KUNIT bool aa_unpack_array(struct aa_ext *e, const char *name, u16 *size) in aa_unpack_array() argument
333 void *pos = e->pos; in aa_unpack_array()
335 if (aa_unpack_nameX(e, AA_ARRAY, name)) { in aa_unpack_array()
336 if (!aa_inbounds(e, sizeof(u16))) in aa_unpack_array()
338 *size = le16_to_cpu(get_unaligned((__le16 *) e->pos)); in aa_unpack_array()
339 e->pos += sizeof(u16); in aa_unpack_array()
344 e->pos = pos; in aa_unpack_array()
349 VISIBLE_IF_KUNIT size_t aa_unpack_blob(struct aa_ext *e, char **blob, const char *name) in aa_unpack_blob() argument
351 void *pos = e->pos; in aa_unpack_blob()
353 if (aa_unpack_nameX(e, AA_BLOB, name)) { in aa_unpack_blob()
355 if (!aa_inbounds(e, sizeof(u32))) in aa_unpack_blob()
357 size = le32_to_cpu(get_unaligned((__le32 *) e->pos)); in aa_unpack_blob()
358 e->pos += sizeof(u32); in aa_unpack_blob()
359 if (aa_inbounds(e, (size_t) size)) { in aa_unpack_blob()
360 *blob = e->pos; in aa_unpack_blob()
361 e->pos += size; in aa_unpack_blob()
367 e->pos = pos; in aa_unpack_blob()
372 VISIBLE_IF_KUNIT int aa_unpack_str(struct aa_ext *e, const char **string, const char *name) in aa_unpack_str() argument
376 void *pos = e->pos; in aa_unpack_str()
378 if (aa_unpack_nameX(e, AA_STRING, name)) { in aa_unpack_str()
379 size = aa_unpack_u16_chunk(e, &src_str); in aa_unpack_str()
391 e->pos = pos; in aa_unpack_str()
396 VISIBLE_IF_KUNIT int aa_unpack_strdup(struct aa_ext *e, char **string, const char *name) in aa_unpack_strdup() argument
399 void *pos = e->pos; in aa_unpack_strdup()
400 int res = aa_unpack_str(e, &tmp, name); in aa_unpack_strdup()
408 e->pos = pos; in aa_unpack_strdup()
424 static struct aa_dfa *unpack_dfa(struct aa_ext *e, int flags) in unpack_dfa() argument
430 size = aa_unpack_blob(e, &blob, "aadfa"); in unpack_dfa()
437 size_t sz = blob - (char *) e->start - in unpack_dfa()
438 ((e->pos - e->start) & 7); in unpack_dfa()
459 static bool unpack_trans_table(struct aa_ext *e, struct aa_str_table *strs) in unpack_trans_table() argument
461 void *saved_pos = e->pos; in unpack_trans_table()
465 if (aa_unpack_nameX(e, AA_STRUCT, "xtable")) { in unpack_trans_table()
469 if (!aa_unpack_array(e, NULL, &size)) in unpack_trans_table()
485 int c, j, pos, size2 = aa_unpack_strdup(e, &str, NULL); in unpack_trans_table()
521 if (!aa_unpack_nameX(e, AA_ARRAYEND, NULL)) in unpack_trans_table()
523 if (!aa_unpack_nameX(e, AA_STRUCTEND, NULL)) in unpack_trans_table()
530 e->pos = saved_pos; in unpack_trans_table()
534 static bool unpack_xattrs(struct aa_ext *e, struct aa_profile *profile) in unpack_xattrs() argument
536 void *pos = e->pos; in unpack_xattrs()
538 if (aa_unpack_nameX(e, AA_STRUCT, "xattrs")) { in unpack_xattrs()
542 if (!aa_unpack_array(e, NULL, &size)) in unpack_xattrs()
549 if (!aa_unpack_strdup(e, &profile->attach.xattrs[i], NULL)) in unpack_xattrs()
552 if (!aa_unpack_nameX(e, AA_ARRAYEND, NULL)) in unpack_xattrs()
554 if (!aa_unpack_nameX(e, AA_STRUCTEND, NULL)) in unpack_xattrs()
561 e->pos = pos; in unpack_xattrs()
565 static bool unpack_secmark(struct aa_ext *e, struct aa_ruleset *rules) in unpack_secmark() argument
567 void *pos = e->pos; in unpack_secmark()
571 if (aa_unpack_nameX(e, AA_STRUCT, "secmark")) { in unpack_secmark()
572 if (!aa_unpack_array(e, NULL, &size)) in unpack_secmark()
583 if (!unpack_u8(e, &rules->secmark[i].audit, NULL)) in unpack_secmark()
585 if (!unpack_u8(e, &rules->secmark[i].deny, NULL)) in unpack_secmark()
587 if (!aa_unpack_strdup(e, &rules->secmark[i].label, NULL)) in unpack_secmark()
590 if (!aa_unpack_nameX(e, AA_ARRAYEND, NULL)) in unpack_secmark()
592 if (!aa_unpack_nameX(e, AA_STRUCTEND, NULL)) in unpack_secmark()
607 e->pos = pos; in unpack_secmark()
611 static bool unpack_rlimits(struct aa_ext *e, struct aa_ruleset *rules) in unpack_rlimits() argument
613 void *pos = e->pos; in unpack_rlimits()
616 if (aa_unpack_nameX(e, AA_STRUCT, "rlimits")) { in unpack_rlimits()
620 if (!aa_unpack_u32(e, &tmp, NULL)) in unpack_rlimits()
624 if (!aa_unpack_array(e, NULL, &size) || in unpack_rlimits()
630 if (!aa_unpack_u64(e, &tmp2, NULL)) in unpack_rlimits()
634 if (!aa_unpack_nameX(e, AA_ARRAYEND, NULL)) in unpack_rlimits()
636 if (!aa_unpack_nameX(e, AA_STRUCTEND, NULL)) in unpack_rlimits()
642 e->pos = pos; in unpack_rlimits()
646 static bool unpack_perm(struct aa_ext *e, u32 version, struct aa_perms *perm) in unpack_perm() argument
651 return aa_unpack_u32(e, &perm->allow, NULL) && in unpack_perm()
652 aa_unpack_u32(e, &perm->allow, NULL) && in unpack_perm()
653 aa_unpack_u32(e, &perm->deny, NULL) && in unpack_perm()
654 aa_unpack_u32(e, &perm->subtree, NULL) && in unpack_perm()
655 aa_unpack_u32(e, &perm->cond, NULL) && in unpack_perm()
656 aa_unpack_u32(e, &perm->kill, NULL) && in unpack_perm()
657 aa_unpack_u32(e, &perm->complain, NULL) && in unpack_perm()
658 aa_unpack_u32(e, &perm->prompt, NULL) && in unpack_perm()
659 aa_unpack_u32(e, &perm->audit, NULL) && in unpack_perm()
660 aa_unpack_u32(e, &perm->quiet, NULL) && in unpack_perm()
661 aa_unpack_u32(e, &perm->hide, NULL) && in unpack_perm()
662 aa_unpack_u32(e, &perm->xindex, NULL) && in unpack_perm()
663 aa_unpack_u32(e, &perm->tag, NULL) && in unpack_perm()
664 aa_unpack_u32(e, &perm->label, NULL); in unpack_perm()
667 static ssize_t unpack_perms_table(struct aa_ext *e, struct aa_perms **perms) in unpack_perms_table() argument
669 void *pos = e->pos; in unpack_perms_table()
677 if (aa_unpack_nameX(e, AA_STRUCT, "perms")) { in unpack_perms_table()
681 if (!aa_unpack_u32(e, &version, "version")) in unpack_perms_table()
683 if (!aa_unpack_array(e, NULL, &size)) in unpack_perms_table()
689 if (!unpack_perm(e, version, &(*perms)[i])) in unpack_perms_table()
692 if (!aa_unpack_nameX(e, AA_ARRAYEND, NULL)) in unpack_perms_table()
694 if (!aa_unpack_nameX(e, AA_STRUCTEND, NULL)) in unpack_perms_table()
704 e->pos = pos; in unpack_perms_table()
708 static int unpack_pdb(struct aa_ext *e, struct aa_policydb *policy, in unpack_pdb() argument
712 void *pos = e->pos; in unpack_pdb()
716 size = unpack_perms_table(e, &policy->perms); in unpack_pdb()
734 policy->dfa = unpack_dfa(e, flags); in unpack_pdb()
754 if (!aa_unpack_u32(e, &policy->start[0], "start")) in unpack_pdb()
757 if (!aa_unpack_u32(e, &policy->start[AA_CLASS_FILE], "dfa_start")) { in unpack_pdb()
765 if (!unpack_trans_table(e, &policy->trans) && required_trans) { in unpack_pdb()
776 e->pos = pos; in unpack_pdb()
802 static struct aa_profile *unpack_profile(struct aa_ext *e, char **ns_name) in unpack_profile() argument
819 if (!aa_unpack_nameX(e, AA_STRUCT, "profile")) in unpack_profile()
821 if (!aa_unpack_str(e, &name, NULL)) in unpack_profile()
850 (void) aa_unpack_str(e, &profile->rename, "rename"); in unpack_profile()
853 (void) aa_unpack_str(e, &profile->attach.xmatch_str, "attach"); in unpack_profile()
856 error = unpack_pdb(e, &profile->attach.xmatch, false, false, &info); in unpack_profile()
864 if (!aa_unpack_u32(e, &tmp, NULL)) { in unpack_profile()
880 (void) aa_unpack_strdup(e, &disconnected, "disconnected"); in unpack_profile()
884 if (!aa_unpack_nameX(e, AA_STRUCT, "flags")) { in unpack_profile()
889 if (!aa_unpack_u32(e, &tmp, NULL)) in unpack_profile()
897 if (!aa_unpack_u32(e, &tmp, NULL)) in unpack_profile()
899 if (tmp == PACKED_MODE_COMPLAIN || (e->version & FORCE_COMPLAIN_FLAG)) { in unpack_profile()
913 if (!aa_unpack_u32(e, &tmp, NULL)) in unpack_profile()
918 if (!aa_unpack_nameX(e, AA_STRUCTEND, NULL)) in unpack_profile()
922 if (aa_unpack_u32(e, &profile->path_flags, "path_flags")) in unpack_profile()
930 if (!aa_unpack_cap_low(e, &rules->caps.allow, NULL)) in unpack_profile()
932 if (!aa_unpack_cap_low(e, &rules->caps.audit, NULL)) in unpack_profile()
934 if (!aa_unpack_cap_low(e, &rules->caps.quiet, NULL)) in unpack_profile()
936 if (!aa_unpack_cap_low(e, &tmpcap, NULL)) in unpack_profile()
940 if (aa_unpack_nameX(e, AA_STRUCT, "caps64")) { in unpack_profile()
942 if (!aa_unpack_cap_high(e, &rules->caps.allow, NULL)) in unpack_profile()
944 if (!aa_unpack_cap_high(e, &rules->caps.audit, NULL)) in unpack_profile()
946 if (!aa_unpack_cap_high(e, &rules->caps.quiet, NULL)) in unpack_profile()
948 if (!aa_unpack_cap_high(e, &tmpcap, NULL)) in unpack_profile()
950 if (!aa_unpack_nameX(e, AA_STRUCTEND, NULL)) in unpack_profile()
955 if (aa_unpack_nameX(e, AA_STRUCT, "capsx")) { in unpack_profile()
957 if (!aa_unpack_cap_low(e, &rules->caps.extended, NULL)) in unpack_profile()
959 if (!aa_unpack_cap_high(e, &rules->caps.extended, NULL)) in unpack_profile()
961 if (!aa_unpack_nameX(e, AA_STRUCTEND, NULL)) in unpack_profile()
965 if (!unpack_xattrs(e, profile)) { in unpack_profile()
970 if (!unpack_rlimits(e, rules)) { in unpack_profile()
975 if (!unpack_secmark(e, rules)) { in unpack_profile()
980 if (aa_unpack_nameX(e, AA_STRUCT, "policydb")) { in unpack_profile()
983 error = unpack_pdb(e, &rules->policy, true, false, in unpack_profile()
994 if (!aa_unpack_nameX(e, AA_STRUCTEND, NULL)) in unpack_profile()
998 e->version); in unpack_profile()
1013 error = unpack_pdb(e, &rules->file, false, true, &info); in unpack_profile()
1045 if (aa_unpack_nameX(e, AA_STRUCT, "data")) { in unpack_profile()
1064 while (aa_unpack_strdup(e, &key, NULL)) { in unpack_profile()
1073 data->size = aa_unpack_blob(e, &data->data, NULL); in unpack_profile()
1092 if (!aa_unpack_nameX(e, AA_STRUCTEND, NULL)) { in unpack_profile()
1098 if (!aa_unpack_nameX(e, AA_STRUCTEND, NULL)) { in unpack_profile()
1117 audit_iface(profile, NULL, name, info, e, error); in unpack_profile()
1131 static int verify_header(struct aa_ext *e, int required, const char **ns) in verify_header() argument
1138 if (!aa_unpack_u32(e, &e->version, "version")) { in verify_header()
1141 e, error); in verify_header()
1150 if (VERSION_LT(e->version, v5) || VERSION_GT(e->version, v9)) { in verify_header()
1152 e, error); in verify_header()
1157 if (aa_unpack_str(e, &name, "namespace")) { in verify_header()
1160 e, error); in verify_header()
1164 audit_iface(NULL, NULL, NULL, "invalid ns change", e, in verify_header()
1413 struct aa_ext e = { in aa_unpack() local
1420 while (e.pos < e.end) { in aa_unpack()
1422 error = verify_header(&e, e.pos == e.start, ns); in aa_unpack()
1426 start = e.pos; in aa_unpack()
1427 profile = unpack_profile(&e, &ns_name); in aa_unpack()
1438 error = aa_calc_profile_hash(profile, e.version, start, in aa_unpack()
1439 e.pos - start); in aa_unpack()
1454 udata->abi = e.version & K_ABI_MASK; in aa_unpack()