From: Fernando Fernandez Mancera <fmancera@suse.de>
To: netdev@vger.kernel.org
Cc: horms@kernel.org, kuba@kernel.org, pabeni@redhat.com,
edumazet@kernel.org, davem@davemloft.net,
Fernando Fernandez Mancera <fmancera@suse.de>,
Paul Moore <paul@paul-moore.com>,
Eric Dumazet <edumazet@google.com>,
Casey Schaufler <casey@schaufler-ca.com>,
James Morris <jmorris@namei.org>,
"Serge E. Hallyn" <serge@hallyn.com>,
Eric Biggers <ebiggers@kernel.org>,
Neal Cardwell <ncardwell@google.com>,
Willem de Bruijn <willemb@google.com>,
Kuniyuki Iwashima <kuniyu@google.com>,
Florian Westphal <fw@strlen.de>,
Chia-Yu Chang <chia-yu.chang@nokia-bell-labs.com>,
Wyatt Feng <bronzed_45_vested@icloud.com>,
Joel Granados <joel.granados@kernel.org>,
Ido Schimmel <idosch@nvidia.com>,
Yung Chih Su <yuuchihsu@gmail.com>,
linux-security-module@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: [PATCH 15/16 net-next v2] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency
Date: Mon, 28 Sep 2026 21:30:11 +0200 [thread overview]
Message-ID: <20260928193046.6698-16-fmancera@suse.de> (raw)
In-Reply-To: <20260928193046.6698-1-fmancera@suse.de>
Currently, the Commercial IP Security Option (CIPSO) is unconditionally
tied to CONFIG_NETLABEL. Because CIPSO is inherently an IPv4 protocol
feature, this creates a transitive dependency where subsystems relying
on NetLabel (such as Smack) are forced to depend on CONFIG_IPV4, even if
the user only wants to utilize IPv6/CALIPSO.
This patch introduces a new CONFIG_CIPSO boolean that is automatically
enabled only when both NETLABEL and IPV4 are selected. It abstracts the
CIPSO-specific Makefile targets, sysctls, and kernel APIs behind this
new config.
By safely stubbing out the CIPSO netlabel_kapi functions to return
-ENOSYS when disabled, this allows NetLabel and Smack to be successfully
built and used on IPv6-only kernels.
Signed-off-by: Fernando Fernandez Mancera <fmancera@suse.de>
---
include/net/cipso_ipv4.h | 18 +++++++++++-------
net/Kconfig | 3 ---
net/ipv4/Makefile | 2 +-
net/ipv4/sysctl_net_ipv4.c | 4 ++--
net/netlabel/Kconfig | 4 ++++
net/netlabel/Makefile | 2 +-
net/netlabel/netlabel_cipso_v4.h | 7 +++++++
net/netlabel/netlabel_kapi.c | 3 +++
security/smack/Kconfig | 1 -
9 files changed, 29 insertions(+), 15 deletions(-)
diff --git a/include/net/cipso_ipv4.h b/include/net/cipso_ipv4.h
index d6780d7903f4..6f50a0a6951b 100644
--- a/include/net/cipso_ipv4.h
+++ b/include/net/cipso_ipv4.h
@@ -100,7 +100,7 @@ struct cipso_v4_std_map_tbl {
* Sysctl Variables
*/
-#ifdef CONFIG_NETLABEL
+#ifdef CONFIG_CIPSO
extern int cipso_v4_cache_enabled;
extern int cipso_v4_cache_bucketsize;
extern int cipso_v4_rbm_optfmt;
@@ -111,7 +111,7 @@ extern int cipso_v4_rbm_strictvalid;
* DOI List Functions
*/
-#ifdef CONFIG_NETLABEL
+#ifdef CONFIG_CIPSO
int cipso_v4_doi_add(struct cipso_v4_doi *doi_def,
struct netlbl_audit *audit_info);
void cipso_v4_doi_free(struct cipso_v4_doi *doi_def);
@@ -144,19 +144,23 @@ static inline struct cipso_v4_doi *cipso_v4_doi_getdef(u32 doi)
return NULL;
}
+static inline void cipso_v4_doi_putdef(struct cipso_v4_doi *doi_def)
+{
+}
+
static inline int cipso_v4_doi_walk(u32 *skip_cnt,
int (*callback) (struct cipso_v4_doi *doi_def, void *arg),
void *cb_arg)
{
return 0;
}
-#endif /* CONFIG_NETLABEL */
+#endif /* CONFIG_CIPSO */
/*
* Label Mapping Cache Functions
*/
-#ifdef CONFIG_NETLABEL
+#ifdef CONFIG_CIPSO
void cipso_v4_cache_invalidate(void);
int cipso_v4_cache_add(const unsigned char *cipso_ptr,
const struct netlbl_lsm_secattr *secattr);
@@ -171,13 +175,13 @@ static inline int cipso_v4_cache_add(const unsigned char *cipso_ptr,
{
return 0;
}
-#endif /* CONFIG_NETLABEL */
+#endif /* CONFIG_CIPSO */
/*
* Protocol Handling Functions
*/
-#ifdef CONFIG_NETLABEL
+#ifdef CONFIG_CIPSO
void cipso_v4_error(struct sk_buff *skb, int error, u32 gateway);
int cipso_v4_getattr(const unsigned char *cipso,
struct netlbl_lsm_secattr *secattr);
@@ -303,6 +307,6 @@ static inline int cipso_v4_validate(const struct sk_buff *skb,
return err_offset;
}
-#endif /* CONFIG_NETLABEL */
+#endif /* CONFIG_CIPSO */
#endif /* _CIPSO_IPV4_H */
diff --git a/net/Kconfig b/net/Kconfig
index ca86f20540dd..2ef4ea6ce056 100644
--- a/net/Kconfig
+++ b/net/Kconfig
@@ -136,10 +136,7 @@ if INET
source "net/ipv4/Kconfig"
source "net/ipv6/Kconfig"
source "net/mptcp/Kconfig"
-
-if IPV4
source "net/netlabel/Kconfig"
-endif # if IPV4
endif # if INET
diff --git a/net/ipv4/Makefile b/net/ipv4/Makefile
index 83c25f52eb58..871187937add 100644
--- a/net/ipv4/Makefile
+++ b/net/ipv4/Makefile
@@ -62,7 +62,7 @@ obj-$(CONFIG_TCP_CONG_YEAH) += tcp_yeah.o
obj-$(CONFIG_TCP_CONG_ILLINOIS) += tcp_illinois.o
obj-$(CONFIG_NET_SOCK_MSG) += tcp_bpf.o
obj-$(CONFIG_BPF_SYSCALL) += udp_bpf.o
-obj-$(CONFIG_NETLABEL) += cipso_ipv4.o
+obj-$(CONFIG_CIPSO) += cipso_ipv4.o
obj-$(CONFIG_XFRM) += xfrm4_policy.o xfrm4_state.o xfrm4_input.o \
xfrm4_output.o xfrm4_protocol.o
diff --git a/net/ipv4/sysctl_net_ipv4.c b/net/ipv4/sysctl_net_ipv4.c
index 6096e9e4d82d..89b0caf5a9f5 100644
--- a/net/ipv4/sysctl_net_ipv4.c
+++ b/net/ipv4/sysctl_net_ipv4.c
@@ -573,7 +573,7 @@ static struct ctl_table ipv4_table[] = {
.mode = 0644,
.proc_handler = proc_dointvec
},
-#ifdef CONFIG_NETLABEL
+#ifdef CONFIG_CIPSO
{
.procname = "cipso_cache_enable",
.data = &cipso_v4_cache_enabled,
@@ -602,7 +602,7 @@ static struct ctl_table ipv4_table[] = {
.mode = 0644,
.proc_handler = proc_dointvec,
},
-#endif /* CONFIG_NETLABEL */
+#endif /* CONFIG_CIPSO */
{
.procname = "tcp_available_ulp",
.maxlen = TCP_ULP_BUF_MAX,
diff --git a/net/netlabel/Kconfig b/net/netlabel/Kconfig
index 4383ac29693e..bcc27196d5bd 100644
--- a/net/netlabel/Kconfig
+++ b/net/netlabel/Kconfig
@@ -17,3 +17,7 @@ config NETLABEL
* https://github.com/netlabel/netlabel_tools
If you are unsure, say N.
+
+config CIPSO
+ def_bool y
+ depends on NETLABEL && IPV4
diff --git a/net/netlabel/Makefile b/net/netlabel/Makefile
index 5a46381a64e7..8afc1bf00424 100644
--- a/net/netlabel/Makefile
+++ b/net/netlabel/Makefile
@@ -12,5 +12,5 @@ obj-y += netlabel_mgmt.o
# protocol modules
obj-y += netlabel_unlabeled.o
-obj-y += netlabel_cipso_v4.o
+obj-$(CONFIG_CIPSO) += netlabel_cipso_v4.o
obj-$(subst m,y,$(CONFIG_IPV6)) += netlabel_calipso.o
diff --git a/net/netlabel/netlabel_cipso_v4.h b/net/netlabel/netlabel_cipso_v4.h
index 9518ab56ec98..fb718f86bcbd 100644
--- a/net/netlabel/netlabel_cipso_v4.h
+++ b/net/netlabel/netlabel_cipso_v4.h
@@ -147,6 +147,13 @@ enum {
#define NLBL_CIPSOV4_A_MAX (__NLBL_CIPSOV4_A_MAX - 1)
/* NetLabel protocol functions */
+#if IS_ENABLED(CONFIG_CIPSO)
int netlbl_cipsov4_genl_init(void);
+#else
+static inline int netlbl_cipsov4_genl_init(void)
+{
+ return 0;
+}
+#endif
#endif
diff --git a/net/netlabel/netlabel_kapi.c b/net/netlabel/netlabel_kapi.c
index 3583fa63dd01..c088f599b53d 100644
--- a/net/netlabel/netlabel_kapi.c
+++ b/net/netlabel/netlabel_kapi.c
@@ -332,6 +332,9 @@ int netlbl_cfg_cipsov4_map_add(u32 doi,
struct netlbl_domaddr_map *addrmap = NULL;
struct netlbl_domaddr4_map *addrinfo = NULL;
+ if (!IS_ENABLED(CONFIG_CIPSO))
+ return -ENOSYS;
+
doi_def = cipso_v4_doi_getdef(doi);
if (doi_def == NULL)
return -ENOENT;
diff --git a/security/smack/Kconfig b/security/smack/Kconfig
index b4e6d0168bd1..5a8dfad469c3 100644
--- a/security/smack/Kconfig
+++ b/security/smack/Kconfig
@@ -3,7 +3,6 @@ config SECURITY_SMACK
bool "Simplified Mandatory Access Control Kernel Support"
depends on NET
depends on INET
- depends on IPV4
depends on SECURITY
select NETLABEL
select SECURITY_NETWORK
--
2.55.0
next prev parent reply other threads:[~2026-09-28 19:32 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20260928193046.6698-1-fmancera@suse.de>
2026-09-28 19:29 ` [PATCH 01/16 net-next v2] ipv4: introduce CONFIG_IPV4 to decouple the IPv4 stack Fernando Fernandez Mancera
2026-09-28 19:29 ` [PATCH 02/16 net-next v2] net: core: add IPv4 fallback stubs and guards for CONFIG_IPV4=n Fernando Fernandez Mancera
2026-09-28 19:29 ` [PATCH 03/16 net-next v2] net: inet: relocate ip_generic_getfrag and guard IPv4 socket logic Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 04/16 net-next v2] tcp: move protocol agnostic TCP functions out of tcp_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 05/16 net-next v2] ipv4: raw: split IPv4 specific logic into raw_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 06/16 net-next v2] ipv4: udp: split IPv4 specific logic into udp_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 07/16 net-next v2] ipv4: icmp: split IPv4 specific logic into icmp_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 08/16 net-next v2] ipv4: ping: split IPv4 specific logic into ping_ipv4.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 09/16 net-next v2] ipv4: fib: split common nexthop logic to fib_core.c Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 10/16 net-next v2] tunnels: guard IPv4 tunnel functions with CONFIG_IPV4 Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 11/16 net-next v2] ipv4: disable IPv4-only sysctls when CONFIG_IPV4=n Fernando Fernandez Mancera
2026-09-29 7:14 ` Joel Granados
2026-09-29 8:20 ` Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 12/16 net-next v2] netfilter: ipv4: guard ip_route_me_harder() with CONFIG_IPV4 Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 13/16 net-next v2] net: bridge: guard ARP/RARP proxy and suppression " Fernando Fernandez Mancera
2026-09-28 19:30 ` [PATCH 14/16 net-next v2] wifi: mac80211: replace CONFIG_INET with CONFIG_IPV4 guards Fernando Fernandez Mancera
2026-09-28 19:30 ` Fernando Fernandez Mancera [this message]
2026-09-28 19:30 ` [PATCH 16/16 net-next v2] ipv4: make CONFIG_IPV4 boolean Fernando Fernandez Mancera
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928193046.6698-16-fmancera@suse.de \
--to=fmancera@suse.de \
--cc=bronzed_45_vested@icloud.com \
--cc=casey@schaufler-ca.com \
--cc=chia-yu.chang@nokia-bell-labs.com \
--cc=davem@davemloft.net \
--cc=ebiggers@kernel.org \
--cc=edumazet@google.com \
--cc=edumazet@kernel.org \
--cc=fw@strlen.de \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=jmorris@namei.org \
--cc=joel.granados@kernel.org \
--cc=kuba@kernel.org \
--cc=kuniyu@google.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-security-module@vger.kernel.org \
--cc=ncardwell@google.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=paul@paul-moore.com \
--cc=serge@hallyn.com \
--cc=willemb@google.com \
--cc=yuuchihsu@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®