| xj | b04a402 | 2021-11-25 15:01:52 +0800 | [diff] [blame] | 1 | /* System keyring containing trusted public keys. | 
|  | 2 | * | 
|  | 3 | * Copyright (C) 2013 Red Hat, Inc. All Rights Reserved. | 
|  | 4 | * Written by David Howells (dhowells@redhat.com) | 
|  | 5 | * | 
|  | 6 | * This program is free software; you can redistribute it and/or | 
|  | 7 | * modify it under the terms of the GNU General Public Licence | 
|  | 8 | * as published by the Free Software Foundation; either version | 
|  | 9 | * 2 of the Licence, or (at your option) any later version. | 
|  | 10 | */ | 
|  | 11 |  | 
|  | 12 | #ifndef _KEYS_SYSTEM_KEYRING_H | 
|  | 13 | #define _KEYS_SYSTEM_KEYRING_H | 
|  | 14 |  | 
|  | 15 | #include <linux/key.h> | 
|  | 16 |  | 
|  | 17 | #ifdef CONFIG_SYSTEM_TRUSTED_KEYRING | 
|  | 18 |  | 
|  | 19 | extern int restrict_link_by_builtin_trusted(struct key *keyring, | 
|  | 20 | const struct key_type *type, | 
|  | 21 | const union key_payload *payload, | 
|  | 22 | struct key *restriction_key); | 
|  | 23 |  | 
|  | 24 | #else | 
|  | 25 | #define restrict_link_by_builtin_trusted restrict_link_reject | 
|  | 26 | #endif | 
|  | 27 |  | 
|  | 28 | #ifdef CONFIG_SECONDARY_TRUSTED_KEYRING | 
|  | 29 | extern int restrict_link_by_builtin_and_secondary_trusted( | 
|  | 30 | struct key *keyring, | 
|  | 31 | const struct key_type *type, | 
|  | 32 | const union key_payload *payload, | 
|  | 33 | struct key *restriction_key); | 
|  | 34 | #else | 
|  | 35 | #define restrict_link_by_builtin_and_secondary_trusted restrict_link_by_builtin_trusted | 
|  | 36 | #endif | 
|  | 37 |  | 
|  | 38 | #ifdef CONFIG_SYSTEM_BLACKLIST_KEYRING | 
|  | 39 | extern int mark_hash_blacklisted(const char *hash); | 
|  | 40 | extern int is_hash_blacklisted(const u8 *hash, size_t hash_len, | 
|  | 41 | const char *type); | 
|  | 42 | #else | 
|  | 43 | static inline int is_hash_blacklisted(const u8 *hash, size_t hash_len, | 
|  | 44 | const char *type) | 
|  | 45 | { | 
|  | 46 | return 0; | 
|  | 47 | } | 
|  | 48 | #endif | 
|  | 49 |  | 
|  | 50 | #ifdef CONFIG_IMA_BLACKLIST_KEYRING | 
|  | 51 | extern struct key *ima_blacklist_keyring; | 
|  | 52 |  | 
|  | 53 | static inline struct key *get_ima_blacklist_keyring(void) | 
|  | 54 | { | 
|  | 55 | return ima_blacklist_keyring; | 
|  | 56 | } | 
|  | 57 | #else | 
|  | 58 | static inline struct key *get_ima_blacklist_keyring(void) | 
|  | 59 | { | 
|  | 60 | return NULL; | 
|  | 61 | } | 
|  | 62 | #endif /* CONFIG_IMA_BLACKLIST_KEYRING */ | 
|  | 63 |  | 
|  | 64 |  | 
|  | 65 | #endif /* _KEYS_SYSTEM_KEYRING_H */ |