blob: 2acb50e96f35b8d6df1360321803529dd06e5bf3 [file] [log] [blame]
Denis Vlasenko1203c9b2007-03-11 22:16:02 +00001/*
2 * libbb/selinux_common.c
3 * -- common SELinux utility functions
Denis Vlasenkoc86e0522007-03-20 11:30:28 +00004 *
Denis Vlasenko1203c9b2007-03-11 22:16:02 +00005 * Copyright 2007 KaiGai Kohei <kaigai@kaigai.gr.jp>
Denis Vlasenkodb12d1d2008-12-07 00:52:58 +00006 *
7 * Licensed under GPLv2, see file LICENSE in this tarball for details.
Denis Vlasenko1203c9b2007-03-11 22:16:02 +00008 */
Denis Vlasenkob6adbf12007-05-26 19:00:18 +00009#include "libbb.h"
Denis Vlasenko1203c9b2007-03-11 22:16:02 +000010#include <selinux/context.h>
11
Denis Vlasenkodefc1ea2008-06-27 02:52:20 +000012context_t FAST_FUNC set_security_context_component(security_context_t cur_context,
Denis Vlasenko1203c9b2007-03-11 22:16:02 +000013 char *user, char *role, char *type, char *range)
14{
15 context_t con = context_new(cur_context);
16 if (!con)
17 return NULL;
18
19 if (user && context_user_set(con, user))
20 goto error;
21 if (type && context_type_set(con, type))
22 goto error;
23 if (range && context_range_set(con, range))
24 goto error;
25 if (role && context_role_set(con, role))
26 goto error;
27 return con;
28
29error:
30 context_free(con);
31 return NULL;
32}
Denis Vlasenko39c651e2007-03-12 18:22:55 +000033
Denis Vlasenkodefc1ea2008-06-27 02:52:20 +000034void FAST_FUNC setfscreatecon_or_die(security_context_t scontext)
Denis Vlasenko39c651e2007-03-12 18:22:55 +000035{
36 if (setfscreatecon(scontext) < 0) {
37 /* Can be NULL. All known printf implementations
38 * display "(null)", "<null>" etc */
Denys Vlasenko6331cf02009-11-13 09:08:27 +010039 bb_perror_msg_and_die("can't set default "
Denis Vlasenko39c651e2007-03-12 18:22:55 +000040 "file creation context to %s", scontext);
41 }
42}
Denis Vlasenko2edbc2a2007-10-20 02:00:49 +000043
Denis Vlasenkodefc1ea2008-06-27 02:52:20 +000044void FAST_FUNC selinux_preserve_fcontext(int fdesc)
Denis Vlasenko2edbc2a2007-10-20 02:00:49 +000045{
46 security_context_t context;
47
48 if (fgetfilecon(fdesc, &context) < 0) {
49 if (errno == ENODATA || errno == ENOTSUP)
50 return;
51 bb_perror_msg_and_die("fgetfilecon failed");
52 }
53 setfscreatecon_or_die(context);
54 freecon(context);
55}