Denis Vlasenko | d46d3c2 | 2007-02-06 19:28:50 +0000 | [diff] [blame] | 1 | /* |
| 2 | * getenforce |
| 3 | * |
| 4 | * Based on libselinux 1.33.1 |
| 5 | * Port to BusyBox Hiroshi Shinji <shiroshi@my.email.ne.jp> |
| 6 | * |
Denys Vlasenko | 0ef64bd | 2010-08-16 20:14:46 +0200 | [diff] [blame] | 7 | * Licensed under GPLv2, see file LICENSE in this source tree. |
Denis Vlasenko | d46d3c2 | 2007-02-06 19:28:50 +0000 | [diff] [blame] | 8 | */ |
Denys Vlasenko | a8e52da | 2016-11-23 18:46:40 +0100 | [diff] [blame] | 9 | //config:config GETENFORCE |
Denys Vlasenko | ae178ce | 2017-07-19 14:32:54 +0200 | [diff] [blame] | 10 | //config: bool "getenforce (1.7 kb)" |
Denys Vlasenko | a8e52da | 2016-11-23 18:46:40 +0100 | [diff] [blame] | 11 | //config: default n |
| 12 | //config: depends on SELINUX |
| 13 | //config: help |
Denys Vlasenko | 72089cf | 2017-07-21 09:50:55 +0200 | [diff] [blame] | 14 | //config: Enable support to get the current mode of SELinux. |
Denys Vlasenko | a8e52da | 2016-11-23 18:46:40 +0100 | [diff] [blame] | 15 | |
| 16 | //applet:IF_GETENFORCE(APPLET(getenforce, BB_DIR_USR_SBIN, BB_SUID_DROP)) |
| 17 | |
| 18 | //kbuild:lib-$(CONFIG_GETENFORCE) += getenforce.o |
Denis Vlasenko | d46d3c2 | 2007-02-06 19:28:50 +0000 | [diff] [blame] | 19 | |
Pere Orga | 5bc8c00 | 2011-04-11 03:29:49 +0200 | [diff] [blame] | 20 | //usage:#define getenforce_trivial_usage NOUSAGE_STR |
| 21 | //usage:#define getenforce_full_usage "" |
| 22 | |
Denis Vlasenko | b6adbf1 | 2007-05-26 19:00:18 +0000 | [diff] [blame] | 23 | #include "libbb.h" |
Denis Vlasenko | d46d3c2 | 2007-02-06 19:28:50 +0000 | [diff] [blame] | 24 | |
Denis Vlasenko | 9b49a5e | 2007-10-11 10:05:36 +0000 | [diff] [blame] | 25 | int getenforce_main(int argc, char **argv) MAIN_EXTERNALLY_VISIBLE; |
Denis Vlasenko | a60f84e | 2008-07-05 09:18:54 +0000 | [diff] [blame] | 26 | int getenforce_main(int argc UNUSED_PARAM, char **argv UNUSED_PARAM) |
Denis Vlasenko | d46d3c2 | 2007-02-06 19:28:50 +0000 | [diff] [blame] | 27 | { |
| 28 | int rc; |
| 29 | |
| 30 | rc = is_selinux_enabled(); |
| 31 | if (rc < 0) |
| 32 | bb_error_msg_and_die("is_selinux_enabled() failed"); |
| 33 | |
| 34 | if (rc == 1) { |
| 35 | rc = security_getenforce(); |
| 36 | if (rc < 0) |
| 37 | bb_error_msg_and_die("getenforce() failed"); |
| 38 | |
| 39 | if (rc) |
| 40 | puts("Enforcing"); |
| 41 | else |
| 42 | puts("Permissive"); |
| 43 | } else { |
| 44 | puts("Disabled"); |
| 45 | } |
| 46 | |
| 47 | return 0; |
| 48 | } |