evm: add evm_inode_setattr to prevent updating an invalid security.evm
[pandora-kernel.git] / include / linux / evm.h
1 /*
2  * evm.h
3  *
4  * Copyright (c) 2009 IBM Corporation
5  * Author: Mimi Zohar <zohar@us.ibm.com>
6  */
7
8 #ifndef _LINUX_EVM_H
9 #define _LINUX_EVM_H
10
11 #include <linux/integrity.h>
12 #include <linux/xattr.h>
13
14 struct integrity_iint_cache;
15
16 #ifdef CONFIG_EVM
17 extern enum integrity_status evm_verifyxattr(struct dentry *dentry,
18                                              const char *xattr_name,
19                                              void *xattr_value,
20                                              size_t xattr_value_len,
21                                              struct integrity_iint_cache *iint);
22 extern int evm_inode_setattr(struct dentry *dentry, struct iattr *attr);
23 extern void evm_inode_post_setattr(struct dentry *dentry, int ia_valid);
24 extern int evm_inode_setxattr(struct dentry *dentry, const char *name,
25                               const void *value, size_t size);
26 extern void evm_inode_post_setxattr(struct dentry *dentry,
27                                     const char *xattr_name,
28                                     const void *xattr_value,
29                                     size_t xattr_value_len);
30 extern int evm_inode_removexattr(struct dentry *dentry, const char *xattr_name);
31 extern void evm_inode_post_removexattr(struct dentry *dentry,
32                                        const char *xattr_name);
33 extern int evm_inode_init_security(struct inode *inode,
34                                    const struct xattr *xattr_array,
35                                    struct xattr *evm);
36 #else
37 #ifdef CONFIG_INTEGRITY
38 static inline enum integrity_status evm_verifyxattr(struct dentry *dentry,
39                                                     const char *xattr_name,
40                                                     void *xattr_value,
41                                                     size_t xattr_value_len,
42                                         struct integrity_iint_cache *iint)
43 {
44         return INTEGRITY_UNKNOWN;
45 }
46 #endif
47
48 static int evm_inode_setattr(struct dentry *dentry, struct iattr *attr)
49 {
50         return 0;
51 }
52
53 static inline void evm_inode_post_setattr(struct dentry *dentry, int ia_valid)
54 {
55         return;
56 }
57
58 static inline int evm_inode_setxattr(struct dentry *dentry, const char *name,
59                                      const void *value, size_t size)
60 {
61         return 0;
62 }
63
64 static inline void evm_inode_post_setxattr(struct dentry *dentry,
65                                            const char *xattr_name,
66                                            const void *xattr_value,
67                                            size_t xattr_value_len)
68 {
69         return;
70 }
71
72 static inline int evm_inode_removexattr(struct dentry *dentry,
73                                         const char *xattr_name)
74 {
75         return 0;
76 }
77
78 static inline void evm_inode_post_removexattr(struct dentry *dentry,
79                                               const char *xattr_name)
80 {
81         return;
82 }
83
84 static inline int evm_inode_init_security(struct inode *inode,
85                                           const struct xattr *xattr_array,
86                                           struct xattr *evm)
87 {
88         return -EOPNOTSUPP;
89 }
90
91 #endif /* CONFIG_EVM_H */
92 #endif /* LINUX_EVM_H */