On Mon, Sep 28, 2026 at 3:32 PM Fernando Fernandez Mancera
[off-list ref] wrote:
Currently, the Commercial IP Security Option (CIPSO) is unconditionally
tied to CONFIG_NETLABEL. Because CIPSO is inherently an IPv4 protocol
feature, this creates a transitive dependency where subsystems relying
on NetLabel (such as Smack) are forced to depend on CONFIG_IPV4, even if
the user only wants to utilize IPv6/CALIPSO.
This patch introduces a new CONFIG_CIPSO boolean that is automatically
enabled only when both NETLABEL and IPV4 are selected. It abstracts the
CIPSO-specific Makefile targets, sysctls, and kernel APIs behind this
new config.
By safely stubbing out the CIPSO netlabel_kapi functions to return
-ENOSYS when disabled, this allows NetLabel and Smack to be successfully
built and used on IPv6-only kernels.
Signed-off-by: Fernando Fernandez Mancera <redacted>
---
include/net/cipso_ipv4.h | 18 +++++++++++-------
net/Kconfig | 3 ---
net/ipv4/Makefile | 2 +-
net/ipv4/sysctl_net_ipv4.c | 4 ++--
net/netlabel/Kconfig | 4 ++++
net/netlabel/Makefile | 2 +-
net/netlabel/netlabel_cipso_v4.h | 7 +++++++
net/netlabel/netlabel_kapi.c | 3 +++
security/smack/Kconfig | 1 -
9 files changed, 29 insertions(+), 15 deletions(-)
Acked-by: Paul Moore <paul@paul-moore.com>
--
paul-moore.com