[PATCH 15/16 net-next v2] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency
Paul Moore
paul at paul-moore.com
Wed Sep 30 01:37:37 UTC 2026
On Mon, Sep 28, 2026 at 3:32 PM Fernando Fernandez Mancera
<fmancera at suse.de> wrote:
>
> Currently, the Commercial IP Security Option (CIPSO) is unconditionally
> tied to CONFIG_NETLABEL. Because CIPSO is inherently an IPv4 protocol
> feature, this creates a transitive dependency where subsystems relying
> on NetLabel (such as Smack) are forced to depend on CONFIG_IPV4, even if
> the user only wants to utilize IPv6/CALIPSO.
>
> This patch introduces a new CONFIG_CIPSO boolean that is automatically
> enabled only when both NETLABEL and IPV4 are selected. It abstracts the
> CIPSO-specific Makefile targets, sysctls, and kernel APIs behind this
> new config.
>
> By safely stubbing out the CIPSO netlabel_kapi functions to return
> -ENOSYS when disabled, this allows NetLabel and Smack to be successfully
> built and used on IPv6-only kernels.
>
> Signed-off-by: Fernando Fernandez Mancera <fmancera at suse.de>
> ---
> include/net/cipso_ipv4.h | 18 +++++++++++-------
> net/Kconfig | 3 ---
> net/ipv4/Makefile | 2 +-
> net/ipv4/sysctl_net_ipv4.c | 4 ++--
> net/netlabel/Kconfig | 4 ++++
> net/netlabel/Makefile | 2 +-
> net/netlabel/netlabel_cipso_v4.h | 7 +++++++
> net/netlabel/netlabel_kapi.c | 3 +++
> security/smack/Kconfig | 1 -
> 9 files changed, 29 insertions(+), 15 deletions(-)
Acked-by: Paul Moore <paul at paul-moore.com>
--
paul-moore.com
More information about the Linux-security-module-archive
mailing list