blob: 37477652b66a80d77c3c8c44ddf40ad030aec04e [file] [log] [blame]
Denis Vlasenkod46d3c22007-02-06 19:28:50 +00001/*
2 * getenforce
3 *
4 * Based on libselinux 1.33.1
5 * Port to BusyBox Hiroshi Shinji <shiroshi@my.email.ne.jp>
6 *
Denys Vlasenko0ef64bd2010-08-16 20:14:46 +02007 * Licensed under GPLv2, see file LICENSE in this source tree.
Denis Vlasenkod46d3c22007-02-06 19:28:50 +00008 */
Denys Vlasenkoa8e52da2016-11-23 18:46:40 +01009//config:config GETENFORCE
10//config: bool "getenforce"
11//config: default n
12//config: depends on SELINUX
13//config: help
14//config: Enable support to get the current mode of SELinux.
15
16//applet:IF_GETENFORCE(APPLET(getenforce, BB_DIR_USR_SBIN, BB_SUID_DROP))
17
18//kbuild:lib-$(CONFIG_GETENFORCE) += getenforce.o
Denis Vlasenkod46d3c22007-02-06 19:28:50 +000019
Pere Orga5bc8c002011-04-11 03:29:49 +020020//usage:#define getenforce_trivial_usage NOUSAGE_STR
21//usage:#define getenforce_full_usage ""
22
Denis Vlasenkob6adbf12007-05-26 19:00:18 +000023#include "libbb.h"
Denis Vlasenkod46d3c22007-02-06 19:28:50 +000024
Denis Vlasenko9b49a5e2007-10-11 10:05:36 +000025int getenforce_main(int argc, char **argv) MAIN_EXTERNALLY_VISIBLE;
Denis Vlasenkoa60f84e2008-07-05 09:18:54 +000026int getenforce_main(int argc UNUSED_PARAM, char **argv UNUSED_PARAM)
Denis Vlasenkod46d3c22007-02-06 19:28:50 +000027{
28 int rc;
29
30 rc = is_selinux_enabled();
31 if (rc < 0)
32 bb_error_msg_and_die("is_selinux_enabled() failed");
33
34 if (rc == 1) {
35 rc = security_getenforce();
36 if (rc < 0)
37 bb_error_msg_and_die("getenforce() failed");
38
39 if (rc)
40 puts("Enforcing");
41 else
42 puts("Permissive");
43 } else {
44 puts("Disabled");
45 }
46
47 return 0;
48}