>From 55845c37c5490e1797ff48fbc74633328e802b2b Mon Sep 17 00:00:00 2001 From: Richard Jones Date: Wed, 12 Aug 2009 16:56:09 +0100 Subject: [PATCH 2/2] Add 'setcon', 'getcon' commands to set and get the SELinux context. --- appliance/packagelist.in | 1 + daemon/Makefile.am | 1 + daemon/configure.ac | 11 ++++++ daemon/selinux.c | 81 ++++++++++++++++++++++++++++++++++++++++++++++ guestfs.pod | 8 ++++ po/POTFILES.in | 1 + src/MAX_PROC_NR | 2 +- src/generator.ml | 18 ++++++++++ 8 files changed, 122 insertions(+), 1 deletions(-) create mode 100644 daemon/selinux.c diff --git a/appliance/packagelist.in b/appliance/packagelist.in index be45fc4..abcd429 100644 --- a/appliance/packagelist.in +++ b/appliance/packagelist.in @@ -15,6 +15,7 @@ MAKEDEV ntfsprogs scrub + libselinux udev util-linux-ng #elif DEBIAN == 1 diff --git a/daemon/Makefile.am b/daemon/Makefile.am index 43cc752..9406944 100644 --- a/daemon/Makefile.am +++ b/daemon/Makefile.am @@ -61,6 +61,7 @@ guestfsd_SOURCES = \ readdir.c \ realpath.c \ scrub.c \ + selinux.c \ sfdisk.c \ sleep.c \ stat.c \ diff --git a/daemon/configure.ac b/daemon/configure.ac index 43e331b..62c28ee 100644 --- a/daemon/configure.ac +++ b/daemon/configure.ac @@ -64,6 +64,17 @@ if test "x$have_augeas" = "xyes"; then AC_DEFINE([HAVE_AUGEAS],[1],[Define to 1 if you have Augeas]) fi +dnl Check for libselinux (optional). +AC_CHECK_HEADERS([selinux/selinux.h]) +AC_CHECK_LIB([selinux],[setexeccon],[ + LIBS="-lselinux $LIBS" + have_libselinux="$ac_cv_header_selinux_selinux_h" + AC_CHECK_FUNCS([setcon getcon]) + ],[have_libselinux=no]) +if test "x$have_libselinux" = "xyes"; then + AC_DEFINE([HAVE_LIBSELINUX],[1],[Define to 1 if you have libselinux]) +fi + dnl Check for XDR library. AC_CHECK_LIB([portablexdr],[xdrmem_create],[],[ AC_SEARCH_LIBS([xdrmem_create],[rpc xdr nsl]) diff --git a/daemon/selinux.c b/daemon/selinux.c new file mode 100644 index 0000000..6e2b347 --- /dev/null +++ b/daemon/selinux.c @@ -0,0 +1,81 @@ +/* libguestfs - the guestfsd daemon + * Copyright (C) 2009 Red Hat Inc. + * + * This program is free software; you can redistribute it and/or modify + * it under the terms of the GNU General Public License as published by + * the Free Software Foundation; either version 2 of the License, or + * (at your option) any later version. + * + * This program is distributed in the hope that it will be useful, + * but WITHOUT ANY WARRANTY; without even the implied warranty of + * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License + * along with this program; if not, write to the Free Software + * Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA. + */ + +#include + +#include +#include +#include + +#ifdef HAVE_SELINUX_SELINUX_H +#include +#endif + +#include "../src/guestfs_protocol.h" +#include "daemon.h" +#include "actions.h" + +#ifdef HAVE_LIBSELINUX + +/* setcon is only valid under the following circumstances: + * - single threaded + * - enforcing=0 + */ +int +do_setcon (char *context) +{ +#ifdef HAVE_SETCON + if (setcon ((char *) context) == -1) { + reply_with_perror ("setcon"); + return -1; + } + + return 0; +#else + reply_with_error ("%s is not available", __func__); + return -1; +#endif +} + +char * +do_getcon (void) +{ +#ifdef HAVE_GETCON + security_context_t context; + char *r; + + if (getcon (&context) == -1) { + reply_with_perror ("getcon"); + return NULL; + } + + r = strdup (context); + freecon (context); + if (r == NULL) { + reply_with_perror ("strdup"); + return NULL; + } + + return r; /* caller frees */ +#else + reply_with_error ("%s is not available", __func__); + return -1; +#endif +} + +#endif /* HAVE_LIBSELINUX */ diff --git a/guestfs.pod b/guestfs.pod index bc16ecb..f657fa1 100644 --- a/guestfs.pod +++ b/guestfs.pod @@ -367,6 +367,14 @@ guest itself: (Older versions of C require you to specify the name of the policy file). +=item 3. + +Optionally, set the security context for the API. The correct +security context to use can only be known by inspecting the +guest. As an example: + + guestfs_setcon (g, "unconfined_u:unconfined_r:unconfined_t:s0"); + =back This will work for running commands and editing existing files. diff --git a/po/POTFILES.in b/po/POTFILES.in index 382cd3a..79a2856 100644 --- a/po/POTFILES.in +++ b/po/POTFILES.in @@ -37,6 +37,7 @@ daemon/proto.c daemon/readdir.c daemon/realpath.c daemon/scrub.c +daemon/selinux.c daemon/sfdisk.c daemon/sleep.c daemon/stat.c diff --git a/src/MAX_PROC_NR b/src/MAX_PROC_NR index dc37bbd..bc3d544 100644 --- a/src/MAX_PROC_NR +++ b/src/MAX_PROC_NR @@ -1 +1 @@ -184 +186 diff --git a/src/generator.ml b/src/generator.ml index b9544ff..3a77202 100755 --- a/src/generator.ml +++ b/src/generator.ml @@ -3427,6 +3427,24 @@ This closes the inotify handle which was previously opened by inotify_init. It removes all watches, throws away any pending events, and deallocates all resources."); + ("setcon", (RErr, [String "context"]), 185, [], + [], + "set SELinux security context", + "\ +This sets the SELinux security context of the daemon +to the string C. + +See the documentation about SELINUX in L."); + + ("getcon", (RString "context", []), 186, [], + [], + "get SELinux security context", + "\ +This gets the SELinux security context of the daemon. + +See the documentation about SELINUX in L, +and C"); + ] let all_functions = non_daemon_functions @ daemon_functions -- 1.6.2.5