chiark
/
gitweb
/
~ianmdlvl
/
elogind.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
core: expose consumed CPU time per unit
[elogind.git]
/
src
/
core
/
smack-setup.c
diff --git
a/src/core/smack-setup.c
b/src/core/smack-setup.c
index d67a84a583308362b80fe469e098b729c215206b..ff2a02004d78307919a1cfc7092384cfd8e6b7f6 100644
(file)
--- a/
src/core/smack-setup.c
+++ b/
src/core/smack-setup.c
@@
-24,23
+24,18
@@
#include <stdio.h>
#include <errno.h>
#include <string.h>
#include <stdio.h>
#include <errno.h>
#include <string.h>
-#include <unistd.h>
#include <stdlib.h>
#include <stdlib.h>
-#include <sys/vfs.h>
#include <fcntl.h>
#include <fcntl.h>
-#include <sys/types.h>
#include <dirent.h>
#include <dirent.h>
-#include <sys/mount.h>
-#include <stdint.h>
#include "macro.h"
#include "smack-setup.h"
#include "util.h"
#include "macro.h"
#include "smack-setup.h"
#include "util.h"
+#include "fileio.h"
#include "log.h"
#include "log.h"
-#include "label.h"
#define SMACK_CONFIG "/etc/smack/accesses.d/"
#define SMACK_CONFIG "/etc/smack/accesses.d/"
-#define CIPSO_CONFIG "/etc/smack/cipso/"
+#define CIPSO_CONFIG "/etc/smack/cipso
.d
/"
#ifdef HAVE_SMACK
#ifdef HAVE_SMACK
@@
-55,7
+50,7
@@
static int write_rules(const char* dstpath, const char* srcdir) {
dst = fopen(dstpath, "we");
if (!dst) {
if (errno != ENOENT)
dst = fopen(dstpath, "we");
if (!dst) {
if (errno != ENOENT)
- log_warning
(
"Failed to open %s: %m", dstpath);
+ log_warning
_errno(errno,
"Failed to open %s: %m", dstpath);
return -errno; /* negative error */
}
return -errno; /* negative error */
}
@@
-63,7
+58,7
@@
static int write_rules(const char* dstpath, const char* srcdir) {
dir = opendir(srcdir);
if (!dir) {
if (errno != ENOENT)
dir = opendir(srcdir);
if (!dir) {
if (errno != ENOENT)
- log_warning
(
"Failed to opendir %s: %m", srcdir);
+ log_warning
_errno(errno,
"Failed to opendir %s: %m", srcdir);
return errno; /* positive on purpose */
}
return errno; /* positive on purpose */
}
@@
-78,7
+73,7
@@
static int write_rules(const char* dstpath, const char* srcdir) {
if (fd < 0) {
if (r == 0)
r = -errno;
if (fd < 0) {
if (r == 0)
r = -errno;
- log_warning
(
"Failed to open %s: %m", entry->d_name);
+ log_warning
_errno(errno,
"Failed to open %s: %m", entry->d_name);
continue;
}
continue;
}
@@
-86,14
+81,14
@@
static int write_rules(const char* dstpath, const char* srcdir) {
if (!policy) {
if (r == 0)
r = -errno;
if (!policy) {
if (r == 0)
r = -errno;
-
close_nointr_nofail
(fd);
- log_error
(
"Failed to open %s: %m", entry->d_name);
+
safe_close
(fd);
+ log_error
_errno(errno,
"Failed to open %s: %m", entry->d_name);
continue;
}
/* load2 write rules in the kernel require a line buffered stream */
FOREACH_LINE(buf, policy,
continue;
}
/* load2 write rules in the kernel require a line buffered stream */
FOREACH_LINE(buf, policy,
- log_error
(
"Failed to read line from %s: %m",
+ log_error
_errno(errno,
"Failed to read line from %s: %m",
entry->d_name)) {
if (!fputs(buf, dst)) {
if (r == 0)
entry->d_name)) {
if (!fputs(buf, dst)) {
if (r == 0)
@@
-104,7
+99,7
@@
static int write_rules(const char* dstpath, const char* srcdir) {
if (fflush(dst)) {
if (r == 0)
r = -errno;
if (fflush(dst)) {
if (r == 0)
r = -errno;
- log_error
(
"Failed to flush writes to %s: %m", dstpath);
+ log_error
_errno(errno,
"Failed to flush writes to %s: %m", dstpath);
break;
}
}
break;
}
}
@@
-115,12
+110,14
@@
static int write_rules(const char* dstpath, const char* srcdir) {
#endif
#endif
-int
smack_setup(void
) {
+int
mac_smack_setup(bool *loaded_policy
) {
#ifdef HAVE_SMACK
int r;
#ifdef HAVE_SMACK
int r;
+ assert(loaded_policy);
+
r = write_rules("/sys/fs/smackfs/load2", SMACK_CONFIG);
switch(r) {
case -ENOENT:
r = write_rules("/sys/fs/smackfs/load2", SMACK_CONFIG);
switch(r) {
case -ENOENT:
@@
-138,6
+135,13
@@
int smack_setup(void) {
return 0;
}
return 0;
}
+#ifdef SMACK_RUN_LABEL
+ r = write_string_file("/proc/self/attr/current", SMACK_RUN_LABEL);
+ if (r)
+ log_warning("Failed to set SMACK label \"%s\" on self: %s",
+ SMACK_RUN_LABEL, strerror(-r));
+#endif
+
r = write_rules("/sys/fs/smackfs/cipso2", CIPSO_CONFIG);
switch(r) {
case -ENOENT:
r = write_rules("/sys/fs/smackfs/cipso2", CIPSO_CONFIG);
switch(r) {
case -ENOENT:
@@
-148,13
+152,15
@@
int smack_setup(void) {
return 0;
case 0:
log_info("Successfully loaded Smack/CIPSO policies.");
return 0;
case 0:
log_info("Successfully loaded Smack/CIPSO policies.");
-
return 0
;
+
break
;
default:
log_warning("Failed to load Smack/CIPSO access rules: %s, ignoring.",
strerror(abs(r)));
return 0;
}
default:
log_warning("Failed to load Smack/CIPSO access rules: %s, ignoring.",
strerror(abs(r)));
return 0;
}
+ *loaded_policy = true;
+
#endif
return 0;
#endif
return 0;