[PATCH 15/16 net-next v2] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency

Paul Moore paul at paul-moore.com
Wed Sep 30 01:37:37 UTC 2026


On Mon, Sep 28, 2026 at 3:32 PM Fernando Fernandez Mancera
<fmancera at suse.de> wrote:
>
> Currently, the Commercial IP Security Option (CIPSO) is unconditionally
> tied to CONFIG_NETLABEL. Because CIPSO is inherently an IPv4 protocol
> feature, this creates a transitive dependency where subsystems relying
> on NetLabel (such as Smack) are forced to depend on CONFIG_IPV4, even if
> the user only wants to utilize IPv6/CALIPSO.
>
> This patch introduces a new CONFIG_CIPSO boolean that is automatically
> enabled only when both NETLABEL and IPV4 are selected. It abstracts the
> CIPSO-specific Makefile targets, sysctls, and kernel APIs behind this
> new config.
>
> By safely stubbing out the CIPSO netlabel_kapi functions to return
> -ENOSYS when disabled, this allows NetLabel and Smack to be successfully
> built and used on IPv6-only kernels.
>
> Signed-off-by: Fernando Fernandez Mancera <fmancera at suse.de>
> ---
>  include/net/cipso_ipv4.h         | 18 +++++++++++-------
>  net/Kconfig                      |  3 ---
>  net/ipv4/Makefile                |  2 +-
>  net/ipv4/sysctl_net_ipv4.c       |  4 ++--
>  net/netlabel/Kconfig             |  4 ++++
>  net/netlabel/Makefile            |  2 +-
>  net/netlabel/netlabel_cipso_v4.h |  7 +++++++
>  net/netlabel/netlabel_kapi.c     |  3 +++
>  security/smack/Kconfig           |  1 -
>  9 files changed, 29 insertions(+), 15 deletions(-)

Acked-by: Paul Moore <paul at paul-moore.com>

-- 
paul-moore.com



More information about the Linux-security-module-archive mailing list