1/* Authors: Karl MacMillan <kmacmillan@tresys.com>
2 *          Frank Mayer <mayerf@tresys.com>
3 *
4 * Copyright (C) 2003 - 2005 Tresys Technology, LLC
5 *
6 *  This library is free software; you can redistribute it and/or
7 *  modify it under the terms of the GNU Lesser General Public
8 *  License as published by the Free Software Foundation; either
9 *  version 2.1 of the License, or (at your option) any later version.
10 *
11 *  This library is distributed in the hope that it will be useful,
12 *  but WITHOUT ANY WARRANTY; without even the implied warranty of
13 *  MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
14 *  Lesser General Public License for more details.
15 *
16 *  You should have received a copy of the GNU Lesser General Public
17 *  License along with this library; if not, write to the Free Software
18 *  Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA  02110-1301  USA
19 */
20
21#ifndef _SEPOL_POLICYDB_CONDITIONAL_H_
22#define _SEPOL_POLICYDB_CONDITIONAL_H_
23
24#include <sepol/policydb/flask_types.h>
25#include <sepol/policydb/avtab.h>
26#include <sepol/policydb/symtab.h>
27#include <sepol/policydb/policydb.h>
28
29#ifdef __cplusplus
30extern "C" {
31#endif
32
33#define COND_EXPR_MAXDEPTH 10
34
35/* this is the max unique bools in a conditional expression
36 * for which we precompute all outcomes for the expression.
37 *
38 * NOTE - do _NOT_ use value greater than 5 because
39 * cond_node_t->expr_pre_comp can only hold at most 32 values
40 */
41#define COND_MAX_BOOLS 5
42
43/*
44 * A conditional expression is a list of operators and operands
45 * in reverse polish notation.
46 */
47typedef struct cond_expr {
48#define COND_BOOL	1	/* plain bool */
49#define COND_NOT	2	/* !bool */
50#define COND_OR		3	/* bool || bool */
51#define COND_AND	4	/* bool && bool */
52#define COND_XOR	5	/* bool ^ bool */
53#define COND_EQ		6	/* bool == bool */
54#define COND_NEQ	7	/* bool != bool */
55#define COND_LAST	COND_NEQ
56	uint32_t expr_type;
57	uint32_t bool;
58	struct cond_expr *next;
59} cond_expr_t;
60
61/*
62 * Each cond_node_t contains a list of rules to be enabled/disabled
63 * depending on the current value of the conditional expression. This
64 * struct is for that list.
65 */
66typedef struct cond_av_list {
67	avtab_ptr_t node;
68	struct cond_av_list *next;
69} cond_av_list_t;
70
71/*
72 * A cond node represents a conditional block in a policy. It
73 * contains a conditional expression, the current state of the expression,
74 * two lists of rules to enable/disable depending on the value of the
75 * expression (the true list corresponds to if and the false list corresponds
76 * to else)..
77 */
78typedef struct cond_node {
79	int cur_state;
80	cond_expr_t *expr;
81	/* these true/false lists point into te_avtab when that is used */
82	cond_av_list_t *true_list;
83	cond_av_list_t *false_list;
84	/* and these are used during parsing and for modules */
85	avrule_t *avtrue_list;
86	avrule_t *avfalse_list;
87	/* these fields are not written to binary policy */
88	unsigned int nbools;
89	uint32_t bool_ids[COND_MAX_BOOLS];
90	uint32_t expr_pre_comp;
91	struct cond_node *next;
92	/* a tunable conditional, calculated and used at expansion */
93#define	COND_NODE_FLAGS_TUNABLE	0x01
94	uint32_t flags;
95} cond_node_t;
96
97extern int cond_evaluate_expr(policydb_t * p, cond_expr_t * expr);
98extern cond_expr_t *cond_copy_expr(cond_expr_t * expr);
99
100extern int cond_expr_equal(cond_node_t * a, cond_node_t * b);
101extern int cond_normalize_expr(policydb_t * p, cond_node_t * cn);
102extern void cond_node_destroy(cond_node_t * node);
103extern void cond_expr_destroy(cond_expr_t * expr);
104
105extern cond_node_t *cond_node_find(policydb_t * p,
106				   cond_node_t * needle, cond_node_t * haystack,
107				   int *was_created);
108
109extern cond_node_t *cond_node_create(policydb_t * p, cond_node_t * node);
110
111extern cond_node_t *cond_node_search(policydb_t * p, cond_node_t * list,
112				     cond_node_t * cn);
113
114extern int evaluate_conds(policydb_t * p);
115
116extern avtab_datum_t *cond_av_list_search(avtab_key_t * key,
117					  cond_av_list_t * cond_list);
118
119extern void cond_av_list_destroy(cond_av_list_t * list);
120
121extern void cond_optimize_lists(cond_list_t * cl);
122
123extern int cond_policydb_init(policydb_t * p);
124extern void cond_policydb_destroy(policydb_t * p);
125extern void cond_list_destroy(cond_list_t * list);
126
127extern int cond_init_bool_indexes(policydb_t * p);
128extern int cond_destroy_bool(hashtab_key_t key, hashtab_datum_t datum, void *p);
129
130extern int cond_index_bool(hashtab_key_t key, hashtab_datum_t datum,
131			   void *datap);
132
133extern int cond_read_bool(policydb_t * p, hashtab_t h, struct policy_file *fp);
134
135extern int cond_read_list(policydb_t * p, cond_list_t ** list, void *fp);
136
137extern void cond_compute_av(avtab_t * ctab, avtab_key_t * key,
138			    struct sepol_av_decision *avd);
139
140#ifdef __cplusplus
141}
142#endif
143
144#endif				/* _CONDITIONAL_H_ */
145