| 978 | } |
| 979 | |
| 980 | static int |
| 981 | mls_ifnet_check_relabel(struct ucred *cred, struct ifnet *ifp, |
| 982 | struct label *ifplabel, struct label *newlabel) |
| 983 | { |
| 984 | struct mac_mls *subj, *new; |
| 985 | int error; |
| 986 | |
| 987 | subj = SLOT(cred->cr_label); |
| 988 | new = SLOT(newlabel); |
| 989 | |
| 990 | /* |
| 991 | * If there is an MLS label update for the interface, it may be an |
| 992 | * update of effective, range, or both. |
| 993 | */ |
| 994 | error = mls_atmostflags(new, MAC_MLS_FLAGS_BOTH); |
| 995 | if (error) |
| 996 | return (error); |
| 997 | |
| 998 | /* |
| 999 | * Relabeling network interfaces requires MLS privilege. |
| 1000 | */ |
| 1001 | return (mls_subject_privileged(subj)); |
| 1002 | } |
| 1003 | |
| 1004 | static int |
| 1005 | mls_ifnet_check_transmit(struct ifnet *ifp, struct label *ifplabel, |
nothing calls this directly
no test coverage detected