Lines Matching +full:srp +full:- +full:capable

1 // SPDX-License-Identifier: GPL-2.0-only
3 * Copyright (C) 2007 Casey Schaufler <casey@schaufler-ca.com>
6 * Casey Schaufler <casey@schaufler-ca.com>
38 SMK_CIPSO = 4, /* load label -> CIPSO mapping */
43 SMK_ONLYCAP = 9, /* the only "capable" label */
53 SMK_CIPSO2 = 17, /* load long label -> CIPSO mapping */
54 SMK_REVOKE_SUBJ = 18, /* set rules with subject label to '-' */
101 * debugging and application bring-up purposes only.
164 #define SMK_OACCESSLEN (sizeof(SMK_OACCESS) - 1)
165 #define SMK_ACCESSLEN (sizeof(SMK_ACCESS) - 1)
178 catsetp[(cat - 1) / 8] |= 0x80 >> ((cat - 1) % 8); in smack_catset_bit()
182 * smk_netlabel_audit_set - fill a netlbl_audit struct
187 nap->loginuid = audit_get_loginuid(current); in smk_netlabel_audit_set()
188 nap->sessionid = audit_get_sessionid(current); in smk_netlabel_audit_set()
189 nap->prop.smack.skp = smk_of_current(); in smk_netlabel_audit_set()
199 * smk_set_access - add a rule to the rule list or replace an old rule
200 * @srp: the rule to add or replace
209 * Returns 0 if nothing goes wrong or -ENOMEM if it fails
212 static int smk_set_access(struct smack_parsed_rule *srp, in smk_set_access() argument
227 if (sp->smk_object == srp->smk_object && in smk_set_access()
228 sp->smk_subject == srp->smk_subject) { in smk_set_access()
230 sp->smk_access |= srp->smk_access1; in smk_set_access()
231 sp->smk_access &= ~srp->smk_access2; in smk_set_access()
239 rc = -ENOMEM; in smk_set_access()
243 sp->smk_subject = srp->smk_subject; in smk_set_access()
244 sp->smk_object = srp->smk_object; in smk_set_access()
245 sp->smk_access = srp->smk_access1 & ~srp->smk_access2; in smk_set_access()
247 list_add_rcu(&sp->list, rule_list); in smk_set_access()
256 * smk_perm_from_str - parse smack accesses from a text string
268 case '-': in smk_perm_from_str()
304 * smk_fill_rule - Fill Smack rule from strings
310 * @import: if non-zero, import labels
324 rule->smk_subject = smk_import_entry(subject, len); in smk_fill_rule()
325 if (IS_ERR(rule->smk_subject)) in smk_fill_rule()
326 return PTR_ERR(rule->smk_subject); in smk_fill_rule()
328 rule->smk_object = smk_import_entry(object, len); in smk_fill_rule()
329 if (IS_ERR(rule->smk_object)) in smk_fill_rule()
330 return PTR_ERR(rule->smk_object); in smk_fill_rule()
338 return -ENOENT; in smk_fill_rule()
339 rule->smk_subject = skp; in smk_fill_rule()
347 return -ENOENT; in smk_fill_rule()
348 rule->smk_object = skp; in smk_fill_rule()
351 rule->smk_access1 = smk_perm_from_str(access1); in smk_fill_rule()
353 rule->smk_access2 = smk_perm_from_str(access2); in smk_fill_rule()
355 rule->smk_access2 = ~rule->smk_access1; in smk_fill_rule()
361 * smk_parse_rule - parse Smack rule from load string
364 * @import: if non-zero, import labels
366 * Returns 0 on success, -1 on errors.
380 * smk_parse_long_rule - parse Smack rule from rule string
383 * @import: if non-zero, import labels
386 * Returns number of processed bytes on success, -ERRNO on failure.
397 * Parsing the rule in-place, filling all white-spaces with '\0' in smk_parse_long_rule()
405 return -EINVAL; in smk_parse_long_rule()
426 * smk_write_rules_list - write() for any /smack rule file
430 * @ppos: where to start - must be 0
433 * @format: /smack/load or /smack/load2 or /smack/change-rule format.
461 return -EINVAL; in smk_write_rules_list()
468 return -EINVAL; in smk_write_rules_list()
471 count = PAGE_SIZE - 1; in smk_write_rules_list()
485 while (count > 0 && (data[count - 1] != '\n')) in smk_write_rules_list()
486 --count; in smk_write_rules_list()
488 rc = -EINVAL; in smk_write_rules_list()
506 rc = -EINVAL; in smk_write_rules_list()
513 rc = smk_set_access(&rule, &rule.smk_subject->smk_rules, in smk_write_rules_list()
514 &rule.smk_subject->smk_rules_lock); in smk_write_rules_list()
542 if (i-- == 0) in smk_seq_start()
565 static void smk_rule_show(struct seq_file *s, struct smack_rule *srp, int max) in smk_rule_show() argument
574 if (strlen(srp->smk_subject->smk_known) >= max || in smk_rule_show()
575 strlen(srp->smk_object->smk_known) >= max) in smk_rule_show()
578 if (srp->smk_access == 0) in smk_rule_show()
581 smack_str_from_perm(acc, srp->smk_access); in smk_rule_show()
583 srp->smk_subject->smk_known, in smk_rule_show()
584 srp->smk_object->smk_known, in smk_rule_show()
605 struct smack_rule *srp; in load_seq_show() local
609 list_for_each_entry_rcu(srp, &skp->smk_rules, list) in load_seq_show()
610 smk_rule_show(s, srp, SMK_LABELLEN); in load_seq_show()
623 * smk_open_load - open() for /smack/load
635 * smk_write_load - write() for /smack/load
639 * @ppos: where to start - must be 0
651 return -EPERM; in smk_write_load()
666 * smk_cipso_doi - initialize the CIPSO domain
682 doip->map.std = NULL; in smk_cipso_doi()
683 doip->doi = smk_cipso_doi_value; in smk_cipso_doi()
684 doip->type = CIPSO_V4_MAP_PASS; in smk_cipso_doi()
685 doip->tags[0] = CIPSO_V4_TAG_RBITMAP; in smk_cipso_doi()
687 doip->tags[rc] = CIPSO_V4_TAG_INVALID; in smk_cipso_doi()
696 rc = netlbl_cfg_cipsov4_map_add(doip->doi, NULL, NULL, NULL, &nai); in smk_cipso_doi()
700 netlbl_cfg_cipsov4_del(doip->doi, &nai); in smk_cipso_doi()
706 * smk_unlbl_ambient - initialize the unlabeled domain
725 rc = netlbl_cfg_unlbl_map_add(smack_net_ambient->smk_known, PF_INET, in smk_unlbl_ambient()
755 struct netlbl_lsm_catmap *cmp = skp->smk_netlabel.attr.mls.cat; in cipso_seq_show()
767 if (strlen(skp->smk_known) >= SMK_LABELLEN) in cipso_seq_show()
770 seq_printf(s, "%s %3d", skp->smk_known, skp->smk_netlabel.attr.mls.lvl); in cipso_seq_show()
791 * smk_open_cipso - open() for /smack/cipso
804 * smk_set_cipso - do the work for write() for cipso and cipso2
824 ssize_t rc = -EINVAL; in smk_set_cipso()
836 return -EPERM; in smk_set_cipso()
838 return -EINVAL; in smk_set_cipso()
841 return -EINVAL; in smk_set_cipso()
843 return -EINVAL; in smk_set_cipso()
865 rule += strlen(skp->smk_known) + 1; in smk_set_cipso()
868 rc = -EOVERFLOW; in smk_set_cipso()
878 rc = -EOVERFLOW; in smk_set_cipso()
895 rc = -EOVERFLOW; in smk_set_cipso()
907 old_cat = skp->smk_netlabel.attr.mls.cat; in smk_set_cipso()
908 rcu_assign_pointer(skp->smk_netlabel.attr.mls.cat, ncats.attr.mls.cat); in smk_set_cipso()
910 skp->smk_netlabel.flags |= NETLBL_SECATTR_MLS_CAT; in smk_set_cipso()
912 skp->smk_netlabel.flags &= ~(u32)NETLBL_SECATTR_MLS_CAT; in smk_set_cipso()
913 skp->smk_netlabel.attr.mls.lvl = ncats.attr.mls.lvl; in smk_set_cipso()
930 * smk_write_cipso - write() for /smack/cipso
966 struct netlbl_lsm_catmap *cmp = skp->smk_netlabel.attr.mls.cat; in cipso2_seq_show()
970 seq_printf(s, "%s %3d", skp->smk_known, skp->smk_netlabel.attr.mls.lvl); in cipso2_seq_show()
991 * smk_open_cipso2 - open() for /smack/cipso2
1004 * smk_write_cipso2 - write() for /smack/cipso2
1051 if (skp->smk_label != NULL) in net4addr_seq_show()
1052 kp = skp->smk_label->smk_known; in net4addr_seq_show()
1053 seq_printf(s, "%pI4/%d %s\n", &skp->smk_host.s_addr, in net4addr_seq_show()
1054 skp->smk_masks, kp); in net4addr_seq_show()
1067 * smk_open_net4addr - open() for /smack/netlabel
1094 list_add_rcu(&new->list, &smk_net4addr_list); in smk_net4addr_insert()
1102 if (new->smk_masks > m->smk_masks) { in smk_net4addr_insert()
1103 list_add_rcu(&new->list, &smk_net4addr_list); in smk_net4addr_insert()
1108 if (list_is_last(&m->list, &smk_net4addr_list)) { in smk_net4addr_insert()
1109 list_add_rcu(&new->list, &m->list); in smk_net4addr_insert()
1112 m_next = list_entry_rcu(m->list.next, in smk_net4addr_insert()
1114 if (new->smk_masks > m_next->smk_masks) { in smk_net4addr_insert()
1115 list_add_rcu(&new->list, &m->list); in smk_net4addr_insert()
1123 * smk_write_net4addr - write() for /smack/netlabel
1159 return -EPERM; in smk_write_net4addr()
1161 return -EINVAL; in smk_write_net4addr()
1162 if (count < SMK_NETLBLADDRMIN || count > PAGE_SIZE - 1) in smk_write_net4addr()
1163 return -EINVAL; in smk_write_net4addr()
1171 rc = -ENOMEM; in smk_write_net4addr()
1181 rc = -EINVAL; in smk_write_net4addr()
1187 rc = -EINVAL; in smk_write_net4addr()
1192 * If smack begins with '-', it is an option, don't import it in smk_write_net4addr()
1194 if (smack[0] != '-') { in smk_write_net4addr()
1202 * Only the -CIPSO option is supported for IPv4 in smk_write_net4addr()
1205 rc = -EINVAL; in smk_write_net4addr()
1210 for (m = masks, temp_mask = 0; m > 0; m--) { in smk_write_net4addr()
1227 if (snp->smk_host.s_addr == nsa && snp->smk_masks == masks) { in smk_write_net4addr()
1237 rc = -ENOMEM; in smk_write_net4addr()
1240 snp->smk_host.s_addr = newname.sin_addr.s_addr; in smk_write_net4addr()
1241 snp->smk_mask.s_addr = mask.s_addr; in smk_write_net4addr()
1242 snp->smk_label = skp; in smk_write_net4addr()
1243 snp->smk_masks = masks; in smk_write_net4addr()
1251 if (snp->smk_label != NULL) in smk_write_net4addr()
1253 &snp->smk_host, &snp->smk_mask, in smk_write_net4addr()
1257 snp->smk_label = skp; in smk_write_net4addr()
1267 &snp->smk_host, &snp->smk_mask, PF_INET, in smk_write_net4addr()
1268 snp->smk_label->smk_secid, &audit_info); in smk_write_net4addr()
1315 if (skp->smk_label != NULL) in net6addr_seq_show()
1316 seq_printf(s, "%pI6/%d %s\n", &skp->smk_host, skp->smk_masks, in net6addr_seq_show()
1317 skp->smk_label->smk_known); in net6addr_seq_show()
1330 * smk_open_net6addr - open() for /smack/netlabel
1357 list_add_rcu(&new->list, &smk_net6addr_list); in smk_net6addr_insert()
1364 if (new->smk_masks > m->smk_masks) { in smk_net6addr_insert()
1365 list_add_rcu(&new->list, &smk_net6addr_list); in smk_net6addr_insert()
1370 if (list_is_last(&m->list, &smk_net6addr_list)) { in smk_net6addr_insert()
1371 list_add_rcu(&new->list, &m->list); in smk_net6addr_insert()
1374 m_next = list_entry_rcu(m->list.next, in smk_net6addr_insert()
1376 if (new->smk_masks > m_next->smk_masks) { in smk_net6addr_insert()
1377 list_add_rcu(&new->list, &m->list); in smk_net6addr_insert()
1385 * smk_write_net6addr - write() for /smack/netlabel
1418 return -EPERM; in smk_write_net6addr()
1420 return -EINVAL; in smk_write_net6addr()
1421 if (count < SMK_NETLBLADDRMIN || count > PAGE_SIZE - 1) in smk_write_net6addr()
1422 return -EINVAL; in smk_write_net6addr()
1430 rc = -ENOMEM; in smk_write_net6addr()
1444 rc = -EINVAL; in smk_write_net6addr()
1449 rc = -EINVAL; in smk_write_net6addr()
1454 rc = -EINVAL; in smk_write_net6addr()
1461 * If smack begins with '-', it is an option, don't import it in smk_write_net6addr()
1463 if (smack[0] != '-') { in smk_write_net6addr()
1471 * Only -DELETE is supported for IPv6 in smk_write_net6addr()
1474 rc = -EINVAL; in smk_write_net6addr()
1482 m -= 16; in smk_write_net6addr()
1484 fullmask.s6_addr16[i] = (1 << m) - 1; in smk_write_net6addr()
1500 if (mask != snp->smk_masks) in smk_write_net6addr()
1504 snp->smk_host.s6_addr16[i]) { in smk_write_net6addr()
1515 rc = -ENOMEM; in smk_write_net6addr()
1517 snp->smk_host = newname; in smk_write_net6addr()
1518 snp->smk_mask = fullmask; in smk_write_net6addr()
1519 snp->smk_masks = mask; in smk_write_net6addr()
1520 snp->smk_label = skp; in smk_write_net6addr()
1524 snp->smk_label = skp; in smk_write_net6addr()
1550 * smk_read_doi - read() for /smack/doi
1574 * smk_write_doi - write() for /smack/doi
1589 return -EPERM; in smk_write_doi()
1592 return -EINVAL; in smk_write_doi()
1595 return -EFAULT; in smk_write_doi()
1600 return -EINVAL; in smk_write_doi()
1616 * smk_read_direct - read() for /smack/direct
1640 * smk_write_direct - write() for /smack/direct
1656 return -EPERM; in smk_write_direct()
1659 return -EINVAL; in smk_write_direct()
1662 return -EFAULT; in smk_write_direct()
1667 return -EINVAL; in smk_write_direct()
1677 if (skp->smk_netlabel.attr.mls.lvl == in smk_write_direct()
1679 skp->smk_netlabel.attr.mls.lvl = i; in smk_write_direct()
1694 * smk_read_mapped - read() for /smack/mapped
1718 * smk_write_mapped - write() for /smack/mapped
1734 return -EPERM; in smk_write_mapped()
1737 return -EINVAL; in smk_write_mapped()
1740 return -EFAULT; in smk_write_mapped()
1745 return -EINVAL; in smk_write_mapped()
1755 if (skp->smk_netlabel.attr.mls.lvl == in smk_write_mapped()
1757 skp->smk_netlabel.attr.mls.lvl = i; in smk_write_mapped()
1772 * smk_read_ambient - read() for /smack/ambient
1794 asize = strlen(smack_net_ambient->smk_known) + 1; in smk_read_ambient()
1798 smack_net_ambient->smk_known, in smk_read_ambient()
1801 rc = -EINVAL; in smk_read_ambient()
1809 * smk_write_ambient - write() for /smack/ambient
1826 return -EPERM; in smk_write_ambient()
1830 return -EINVAL; in smk_write_ambient()
1844 oldambient = smack_net_ambient->smk_known; in smk_write_ambient()
1880 seq_puts(s, sklep->smk_label->smk_known); in onlycap_seq_show()
1899 * smk_list_swap_rcu - swap public list with a private one in RCU-safe way
1916 first = public->next; in smk_list_swap_rcu()
1917 last = public->prev; in smk_list_swap_rcu()
1919 /* Publish private list in place of public in RCU-safe way */ in smk_list_swap_rcu()
1920 private->prev->next = public; in smk_list_swap_rcu()
1921 private->next->prev = public; in smk_list_swap_rcu()
1922 rcu_assign_pointer(public->next, private->next); in smk_list_swap_rcu()
1923 public->prev = private->prev; in smk_list_swap_rcu()
1929 private->next = first; in smk_list_swap_rcu()
1930 private->prev = last; in smk_list_swap_rcu()
1931 first->prev = private; in smk_list_swap_rcu()
1932 last->next = private; in smk_list_swap_rcu()
1937 * smk_parse_label_list - parse list of Smack labels, separated by spaces
1960 return -ENOMEM; in smk_parse_label_list()
1962 sklep->smk_label = skp; in smk_parse_label_list()
1963 list_add(&sklep->list, list); in smk_parse_label_list()
1970 * smk_destroy_label_list - destroy a list of smack_known_list_elem
1985 * smk_write_onlycap - write() for smackfs/onlycap
2001 return -EPERM; in smk_write_onlycap()
2004 return -EINVAL; in smk_write_onlycap()
2017 * Importing will also reject a label beginning with '-', in smk_write_onlycap()
2018 * so "-usecapabilities" will also work. in smk_write_onlycap()
2023 if (!rc || (rc == -EINVAL && list_empty(&list_tmp))) { in smk_write_onlycap()
2045 * smk_read_unconfined - read() for smackfs/unconfined
2057 ssize_t rc = -EINVAL; in smk_read_unconfined()
2064 smack = smack_unconfined->smk_known; in smk_read_unconfined()
2075 * smk_write_unconfined - write() for smackfs/unconfined
2091 return -EPERM; in smk_write_unconfined()
2094 return -EINVAL; in smk_write_unconfined()
2104 * Importing will also reject a label beginning with '-', in smk_write_unconfined()
2105 * so "-confine" will also work. in smk_write_unconfined()
2110 if (PTR_ERR(skp) == -EINVAL) in smk_write_unconfined()
2133 * smk_read_logging - read() for /smack/logging
2156 * smk_write_logging - write() for /smack/logging
2171 return -EPERM; in smk_write_logging()
2174 return -EINVAL; in smk_write_logging()
2177 return -EFAULT; in smk_write_logging()
2182 return -EINVAL; in smk_write_logging()
2184 return -EINVAL; in smk_write_logging()
2199 * Seq_file read operations for /smack/load-self
2206 return smk_seq_start(s, pos, &tsp->smk_rules); in load_self_seq_start()
2213 return smk_seq_next(s, v, pos, &tsp->smk_rules); in load_self_seq_next()
2219 struct smack_rule *srp = in load_self_seq_show() local
2222 smk_rule_show(s, srp, SMK_LABELLEN); in load_self_seq_show()
2236 * smk_open_load_self - open() for /smack/load-self2
2248 * smk_write_load_self - write() for /smack/load-self
2252 * @ppos: where to start - must be 0
2260 return smk_write_rules_list(file, buf, count, ppos, &tsp->smk_rules, in smk_write_load_self()
2261 &tsp->smk_rules_lock, SMK_FIXED24_FMT); in smk_write_load_self()
2273 * smk_user_access - handle access check transaction
2277 * @ppos: where to start - must be 0
2278 * @format: /smack/load or /smack/load2 or /smack/change-rule format.
2293 return -EINVAL; in smk_user_access()
2297 * simple_transaction_get() returns null-terminated data in smk_user_access()
2305 else if (res != -ENOENT) in smk_user_access()
2322 * smk_write_access - handle access check transaction
2326 * @ppos: where to start - must be 0
2349 struct smack_rule *srp; in load2_seq_show() local
2353 list_for_each_entry_rcu(srp, &skp->smk_rules, list) in load2_seq_show()
2354 smk_rule_show(s, srp, SMK_LONGLABEL); in load2_seq_show()
2367 * smk_open_load2 - open() for /smack/load2
2379 * smk_write_load2 - write() for /smack/load2
2383 * @ppos: where to start - must be 0
2393 return -EPERM; in smk_write_load2()
2408 * Seq_file read operations for /smack/load-self2
2415 return smk_seq_start(s, pos, &tsp->smk_rules); in load_self2_seq_start()
2422 return smk_seq_next(s, v, pos, &tsp->smk_rules); in load_self2_seq_next()
2428 struct smack_rule *srp = in load_self2_seq_show() local
2431 smk_rule_show(s, srp, SMK_LONGLABEL); in load_self2_seq_show()
2444 * smk_open_load_self2 - open() for /smack/load-self2
2456 * smk_write_load_self2 - write() for /smack/load-self2
2460 * @ppos: where to start - must be 0
2468 return smk_write_rules_list(file, buf, count, ppos, &tsp->smk_rules, in smk_write_load_self2()
2469 &tsp->smk_rules_lock, SMK_LONG_FMT); in smk_write_load_self2()
2481 * smk_write_access2 - handle access check transaction
2485 * @ppos: where to start - must be 0
2501 * smk_write_revoke_subj - write() for /smack/revoke-subject
2505 * @ppos: where to start - must be 0
2519 return -EINVAL; in smk_write_revoke_subj()
2522 return -EPERM; in smk_write_revoke_subj()
2525 return -EINVAL; in smk_write_revoke_subj()
2541 rule_list = &skp->smk_rules; in smk_write_revoke_subj()
2542 rule_lock = &skp->smk_rules_lock; in smk_write_revoke_subj()
2547 sp->smk_access = 0; in smk_write_revoke_subj()
2567 * smk_init_sysfs - initialize /sys/fs/smackfs
2576 * smk_write_change_rule - write() for /smack/change-rule
2580 * @ppos: where to start - must be 0
2589 return -EPERM; in smk_write_change_rule()
2603 * smk_read_syslog - read() for smackfs/syslog
2615 ssize_t rc = -EINVAL; in smk_read_syslog()
2626 asize = strlen(skp->smk_known) + 1; in smk_read_syslog()
2629 rc = simple_read_from_buffer(buf, cn, ppos, skp->smk_known, in smk_read_syslog()
2636 * smk_write_syslog - write() for smackfs/syslog
2652 return -EPERM; in smk_write_syslog()
2656 return -EINVAL; in smk_write_syslog()
2679 * Seq_file read operations for /smack/relabel-self
2686 return smk_seq_start(s, pos, &tsp->smk_relabel); in relabel_self_seq_start()
2693 return smk_seq_next(s, v, pos, &tsp->smk_relabel); in relabel_self_seq_next()
2702 seq_puts(s, sklep->smk_label->smk_known); in relabel_self_seq_show()
2716 * smk_open_relabel_self - open() for /smack/relabel-self
2718 * @file: "relabel-self" file pointer
2720 * Connect our relabel_self_seq_* operations with /smack/relabel-self
2729 * smk_write_relabel_self - write() for /smack/relabel-self
2733 * @ppos: where to start - must be 0
2747 return -EPERM; in smk_write_relabel_self()
2754 return -EINVAL; in smk_write_relabel_self()
2756 return -EINVAL; in smk_write_relabel_self()
2765 if (!rc || (rc == -EINVAL && list_empty(&list_tmp))) { in smk_write_relabel_self()
2771 rc = -ENOMEM; in smk_write_relabel_self()
2775 smk_destroy_label_list(&tsp->smk_relabel); in smk_write_relabel_self()
2776 list_splice(&list_tmp, &tsp->smk_relabel); in smk_write_relabel_self()
2794 * smk_read_ptrace - read() for /smack/ptrace
2817 * smk_write_ptrace - write() for /smack/ptrace
2821 * @ppos: where to start - must be 0
2830 return -EPERM; in smk_write_ptrace()
2833 return -EINVAL; in smk_write_ptrace()
2836 return -EFAULT; in smk_write_ptrace()
2841 return -EINVAL; in smk_write_ptrace()
2843 return -EINVAL; in smk_write_ptrace()
2856 * smk_fill_super - fill the smackfs superblock
2888 "load-self", &smk_load_self_ops, S_IRUGO|S_IWUGO}, in smk_fill_super()
2896 "load-self2", &smk_load_self2_ops, S_IRUGO|S_IWUGO}, in smk_fill_super()
2902 "revoke-subject", &smk_revoke_subj_ops, in smk_fill_super()
2905 "change-rule", &smk_change_rule_ops, S_IRUGO|S_IWUSR}, in smk_fill_super()
2919 "relabel-self", &smk_relabel_self_ops, in smk_fill_super()
2936 * smk_get_tree - get the smackfs superblock
2953 * smk_init_fs_context - Initialise a filesystem context for smackfs
2958 fc->ops = &smk_context_ops; in smk_init_fs_context()
2971 * init_smk_fs - get the smackfs superblock