9b45c60 This patch adds a polmatch avperm to arbitrate flow/state's access to

Authored and Committed by Chris PeBenito 17 years ago
    This patch adds a polmatch avperm to arbitrate flow/state's access to
    a xfrm policy. It also defines MLS policy for association { sendto,
    recvfrom, polmatch }.
    
    NOTE: When an inbound packet is not using an IPSec SA, a check is performed
    between the socket label and the unlabeled sid (SYSTEM_HIGH MLS label). For
    MLS purposes however, the target of the check should be the MLS label taken
    from the node sid (or secmark in the new secmark world). This would present
    a severe performance overhead (to make a new sid based on the unlabeled sid
    with the MLS taken from the node sid or secmark and then using this sid as
    the target). Pending reconciliation of the netlabel, ipsec and iptables contexts,
    I have chosen to currently make an exception for unlabeled_t SAs if TE policy
    allowed it. A similar problem exists for the outbound case and it has been similarly
    handled in the policy below (by making an exception for unlabeled_t).
    
    I am submitting the below limited patch pending a comprehensive patch from
    Joy Latten at IBM (latten@austin.ibm.com).
    
    I am not sure if I needed to manually do a "make tolib" in the flask subdir
    and submit the results as well. Please let me know if I needed to.
    
    Signed-off-by: Venkat Yekkirala <vyekkirala@TrustedCS.com>
    
    
        
file modified
+1 -0
file modified
+13 -2