Re: [PATCH 15/16 net-next v2] netlabel: cipso: introduce CONFIG_CIPSO to decouple IPv4 dependency

From: Paul Moore

Date: Tue Sep 29 2026 - 21:38:01 EST


On Mon, Sep 28, 2026 at 3:32 PM Fernando Fernandez Mancera
<fmancera@xxxxxxx> wrote:
>
> Currently, the Commercial IP Security Option (CIPSO) is unconditionally
> tied to CONFIG_NETLABEL. Because CIPSO is inherently an IPv4 protocol
> feature, this creates a transitive dependency where subsystems relying
> on NetLabel (such as Smack) are forced to depend on CONFIG_IPV4, even if
> the user only wants to utilize IPv6/CALIPSO.
>
> This patch introduces a new CONFIG_CIPSO boolean that is automatically
> enabled only when both NETLABEL and IPV4 are selected. It abstracts the
> CIPSO-specific Makefile targets, sysctls, and kernel APIs behind this
> new config.
>
> By safely stubbing out the CIPSO netlabel_kapi functions to return
> -ENOSYS when disabled, this allows NetLabel and Smack to be successfully
> built and used on IPv6-only kernels.
>
> Signed-off-by: Fernando Fernandez Mancera <fmancera@xxxxxxx>
> ---
> include/net/cipso_ipv4.h | 18 +++++++++++-------
> net/Kconfig | 3 ---
> net/ipv4/Makefile | 2 +-
> net/ipv4/sysctl_net_ipv4.c | 4 ++--
> net/netlabel/Kconfig | 4 ++++
> net/netlabel/Makefile | 2 +-
> net/netlabel/netlabel_cipso_v4.h | 7 +++++++
> net/netlabel/netlabel_kapi.c | 3 +++
> security/smack/Kconfig | 1 -
> 9 files changed, 29 insertions(+), 15 deletions(-)

Acked-by: Paul Moore <paul@xxxxxxxxxxxxxx>

--
paul-moore.com