Path: blob/master/security/apparmor/include/policy_compat.h
26442 views
/* SPDX-License-Identifier: GPL-2.0-only */1/*2* AppArmor security module3*4* Code to provide backwards compatibility with older policy versions,5* by converting/mapping older policy formats into the newer internal6* formats.7*8* Copyright 2022 Canonical Ltd.9*/1011#ifndef __POLICY_COMPAT_H12#define __POLICY_COMPAT_H1314#include "policy.h"1516#define K_ABI_MASK 0x3ff17#define FORCE_COMPLAIN_FLAG 0x80018#define VERSION_LT(X, Y) (((X) & K_ABI_MASK) < ((Y) & K_ABI_MASK))19#define VERSION_LE(X, Y) (((X) & K_ABI_MASK) <= ((Y) & K_ABI_MASK))20#define VERSION_GT(X, Y) (((X) & K_ABI_MASK) > ((Y) & K_ABI_MASK))2122#define v5 5 /* base version */23#define v6 6 /* per entry policydb mediation check */24#define v7 725#define v8 8 /* full network masking */26#define v9 9 /* xbits are used as permission bits in policydb */2728int aa_compat_map_xmatch(struct aa_policydb *policy);29int aa_compat_map_policy(struct aa_policydb *policy, u32 version);30int aa_compat_map_file(struct aa_policydb *policy);3132#endif /* __POLICY_COMPAT_H */333435