1 /*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
4 This file is part of systemd.
6 Copyright 2010 Lennart Poettering
8 systemd is free software; you can redistribute it and/or modify it
9 under the terms of the GNU General Public License as published by
10 the Free Software Foundation; either version 2 of the License, or
11 (at your option) any later version.
13 systemd is distributed in the hope that it will be useful, but
14 WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 General Public License for more details.
18 You should have received a copy of the GNU General Public License
19 along with systemd; If not, see <http://www.gnu.org/licenses/>.
29 #include <selinux/selinux.h>
32 #include "selinux-setup.h"
37 int selinux_setup(char *const argv[]) {
42 /* Already initialized? */
43 if (path_is_mount_point("/sys/fs/selinux") > 0 ||
44 path_is_mount_point("/selinux") > 0)
47 /* Before we load the policy we create a flag file to ensure
48 * that after the reexec we iterate through /run and /dev to
50 touch("/dev/.systemd-relabel-run-dev");
52 n = now(CLOCK_MONOTONIC);
53 if (selinux_init_load_policy(&enforce) == 0) {
54 char buf[FORMAT_TIMESPAN_MAX];
56 n = now(CLOCK_MONOTONIC) - n;
57 log_info("Successfully loaded SELinux policy in %s, reexecuting.",
58 format_timespan(buf, sizeof(buf), n));
60 /* FIXME: Ideally we'd just call setcon() here instead
61 * of having to reexecute ourselves here. */
63 execv(SYSTEMD_BINARY_PATH, argv);
64 log_error("Failed to reexecute: %m");
68 log_full(enforce > 0 ? LOG_ERR : LOG_WARNING, "Failed to load SELinux policy.");
70 unlink("/dev/.systemd-relabel-run-dev");