From patchwork Sun Oct 1 18:01:26 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vit Mojzis X-Patchwork-Id: 9979801 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id E9187602A0 for ; Sun, 1 Oct 2017 18:03:31 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id D9DD328AD1 for ; Sun, 1 Oct 2017 18:03:31 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id CD92828AE0; Sun, 1 Oct 2017 18:03:31 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-4.2 required=2.0 tests=BAYES_00, RCVD_IN_DNSWL_MED autolearn=ham version=3.3.1 Received: from uhil19pa12.eemsg.mail.mil (uhil19pa12.eemsg.mail.mil [214.24.21.85]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 680B928AD1 for ; Sun, 1 Oct 2017 18:03:30 +0000 (UTC) Received: from emsm-gh1-uea11.ncsc.mil ([214.29.60.3]) by uhil19pa12.eemsg.mail.mil with ESMTP; 01 Oct 2017 18:03:29 +0000 Received: from unknown (HELO tarius.tycho.ncsc.mil) ([144.51.242.1]) by emsm-gh1-uea11.NCSC.MIL with ESMTP; 01 Oct 2017 18:03:28 +0000 Received: from prometheus.infosec.tycho.ncsc.mil (prometheus [192.168.25.40]) by tarius.tycho.ncsc.mil (8.14.4/8.14.4) with ESMTP id v91I3NnA026694; Sun, 1 Oct 2017 14:03:23 -0400 Received: from tarius.tycho.ncsc.mil (tarius.infosec.tycho.ncsc.mil [144.51.242.1]) by prometheus.infosec.tycho.ncsc.mil (8.15.2/8.15.2) with ESMTP id v91I25GV049913 for ; Sun, 1 Oct 2017 14:02:05 -0400 Received: from goalie.tycho.ncsc.mil (goalie [144.51.242.250]) by tarius.tycho.ncsc.mil (8.14.4/8.14.4) with ESMTP id v91I24bZ026471 for ; Sun, 1 Oct 2017 14:02:04 -0400 X-IronPort-Anti-Spam-Filtered: true X-IronPort-Anti-Spam-Result: =?us-ascii?q?A1BOBADCLNFZ/yMWGNZcHAEBBAEBCgEBg?= =?us-ascii?q?zIoA0QgF1cnjwyObZo0ChMQhRgChDNXAQIBAQEBAQJrhUEGJ2JRV4h3gVIDDac?= =?us-ascii?q?1OosvAQshBYMtggKBUYZjgWGHJiAFoTKHXox6DYtMhz2VVIE5V4EOUyUVhhiBU?= =?us-ascii?q?HQBiU4BAQE?= X-IPAS-Result: =?us-ascii?q?A1BOBADCLNFZ/yMWGNZcHAEBBAEBCgEBgzIoA0QgF1cnjwy?= =?us-ascii?q?ObZo0ChMQhRgChDNXAQIBAQEBAQJrhUEGJ2JRV4h3gVIDDac1OosvAQshBYMtg?= =?us-ascii?q?gKBUYZjgWGHJiAFoTKHXox6DYtMhz2VVIE5V4EOUyUVhhiBUHQBiU4BAQE?= X-IronPort-AV: E=Sophos;i="5.42,465,1500955200"; d="scan'208";a="68929" Received: from emsm-gh1-uea10.ncsc.mil ([214.29.60.34]) by goalie.tycho.ncsc.mil with ESMTP; 01 Oct 2017 14:02:02 -0400 Received: from ukel19pa05.eemsg.mail.mil ([214.24.22.35]) by EMSM-GH1-UEA10.NCSC.MIL with ESMTP; 01 Oct 2017 18:02:01 +0000 X-EEMSG-check-005: 0 X-EEMSG-check-006: 000-001;dbbaa461-b801-46ec-ac51-b1769440cdf4 Authentication-Results: ukel19pa06.eemsg.mail.mil; dkim=neutral (message not signed) header.i=none X-EEMSG-check-008: 273130357|UKEL19PA06_EEMSG_MP3.csd.disa.mil X-EEMSG-check-001: false X-EEMSG-SBRS: 3.5 X-EEMSG-ORIG-IP: 209.132.183.28 X-EEMSG-check-002: true X-IronPort-Anti-Spam-Filtered: true X-IronPort-Anti-Spam-Result: A0BeAAA5KtFZhxy3hNFcGwEBAQMBAQEJAQEBgzIoAWZuJ44YdI5tmCKCEgojhRgChDM/GAECAQEBAQEBARMBAQEKCwkIKC+FGQMDJ2JRV4h3gVIQpyo6iy8BCyEFgy2CAoFRhmOBYYcmIAWhModejHoNi0yHPZVUgTkfgUZTJRWFc4F1PjYBiU4BAQE X-IPAS-Result: A0BeAAA5KtFZhxy3hNFcGwEBAQMBAQEJAQEBgzIoAWZuJ44YdI5tmCKCEgojhRgChDM/GAECAQEBAQEBARMBAQEKCwkIKC+FGQMDJ2JRV4h3gVIQpyo6iy8BCyEFgy2CAoFRhmOBYYcmIAWhModejHoNi0yHPZVUgTkfgUZTJRWFc4F1PjYBiU4BAQE Received: from mx1.redhat.com ([209.132.183.28]) by ukel19pa06.eemsg.mail.mil with ESMTP; 01 Oct 2017 18:01:59 +0000 Received: from smtp.corp.redhat.com (int-mx04.intmail.prod.int.phx2.redhat.com [10.5.11.14]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id DEED781DF1 for ; Sun, 1 Oct 2017 18:01:58 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mx1.redhat.com DEED781DF1 Received: from Thinkpad_450.redhat.com (ovpn-204-59.brq.redhat.com [10.40.204.59]) by smtp.corp.redhat.com (Postfix) with ESMTP id 2608417AF2 for ; Sun, 1 Oct 2017 18:01:57 +0000 (UTC) X-EEMSG-check-009: 444-444 From: Vit Mojzis To: selinux@tycho.nsa.gov Date: Sun, 1 Oct 2017 20:01:26 +0200 Message-Id: <20171001180127.3673-2-vmojzis@redhat.com> In-Reply-To: <20171001180127.3673-1-vmojzis@redhat.com> References: <1506536279.27095.13.camel@tycho.nsa.gov> <20171001180127.3673-1-vmojzis@redhat.com> X-Scanned-By: MIMEDefang 2.79 on 10.5.11.14 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.5.110.25]); Sun, 01 Oct 2017 18:01:59 +0000 (UTC) Subject: [PATCH 2/3] libsemanage: Add support for listing fcontext.homedirs file X-BeenThere: selinux@tycho.nsa.gov X-Mailman-Version: 2.1.21 Precedence: list List-Id: "Security-Enhanced Linux \(SELinux\) mailing list" List-Post: List-Help: Errors-To: selinux-bounces@tycho.nsa.gov Sender: "Selinux" X-Virus-Scanned: ClamAV using ClamSMTP Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=1409813 --- libsemanage/include/semanage/fcontexts_policy.h | 4 ++++ libsemanage/src/direct_api.c | 6 ++++++ libsemanage/src/fcontexts_policy.c | 8 ++++++++ libsemanage/src/handle.h | 19 +++++++++++++------ 4 files changed, 31 insertions(+), 6 deletions(-) diff --git a/libsemanage/include/semanage/fcontexts_policy.h b/libsemanage/include/semanage/fcontexts_policy.h index a50db2b..199a1e1 100644 --- a/libsemanage/include/semanage/fcontexts_policy.h +++ b/libsemanage/include/semanage/fcontexts_policy.h @@ -26,4 +26,8 @@ extern int semanage_fcontext_list(semanage_handle_t * handle, semanage_fcontext_t *** records, unsigned int *count); +extern int semanage_fcontext_list_homedirs(semanage_handle_t * handle, + semanage_fcontext_t *** records, + unsigned int *count); + #endif diff --git a/libsemanage/src/direct_api.c b/libsemanage/src/direct_api.c index 971a08f..334267d 100644 --- a/libsemanage/src/direct_api.c +++ b/libsemanage/src/direct_api.c @@ -210,6 +210,12 @@ int semanage_direct_connect(semanage_handle_t * sh) semanage_fcontext_dbase_local(sh)) < 0) goto err; + if (fcontext_file_dbase_init(sh, + semanage_path(SEMANAGE_ACTIVE, SEMANAGE_STORE_FC_HOMEDIRS), + semanage_path(SEMANAGE_TMP, SEMANAGE_STORE_FC_HOMEDIRS), + semanage_fcontext_dbase_homedirs(sh)) < 0) + goto err; + if (seuser_file_dbase_init(sh, semanage_path(SEMANAGE_ACTIVE, SEMANAGE_SEUSERS_LOCAL), diff --git a/libsemanage/src/fcontexts_policy.c b/libsemanage/src/fcontexts_policy.c index 0b063b1..98490ab 100644 --- a/libsemanage/src/fcontexts_policy.c +++ b/libsemanage/src/fcontexts_policy.c @@ -51,3 +51,11 @@ int semanage_fcontext_list(semanage_handle_t * handle, dbase_config_t *dconfig = semanage_fcontext_dbase_policy(handle); return dbase_list(handle, dconfig, records, count); } + +int semanage_fcontext_list_homedirs(semanage_handle_t * handle, + semanage_fcontext_t *** records, unsigned int *count) +{ + + dbase_config_t *dconfig = semanage_fcontext_dbase_homedirs(handle); + return dbase_list(handle, dconfig, records, count); +} diff --git a/libsemanage/src/handle.h b/libsemanage/src/handle.h index 889871d..1780ac8 100644 --- a/libsemanage/src/handle.h +++ b/libsemanage/src/handle.h @@ -79,7 +79,7 @@ struct semanage_handle { struct semanage_policy_table *funcs; /* Object databases */ -#define DBASE_COUNT 23 +#define DBASE_COUNT 24 /* Local modifications */ #define DBASE_LOCAL_USERS_BASE 0 @@ -102,13 +102,14 @@ struct semanage_handle { #define DBASE_POLICY_INTERFACES 15 #define DBASE_POLICY_BOOLEANS 16 #define DBASE_POLICY_FCONTEXTS 17 -#define DBASE_POLICY_SEUSERS 18 -#define DBASE_POLICY_NODES 19 -#define DBASE_POLICY_IBPKEYS 20 -#define DBASE_POLICY_IBENDPORTS 21 +#define DBASE_POLICY_FCONTEXTS_H 18 +#define DBASE_POLICY_SEUSERS 19 +#define DBASE_POLICY_NODES 20 +#define DBASE_POLICY_IBPKEYS 21 +#define DBASE_POLICY_IBENDPORTS 22 /* Active kernel policy */ -#define DBASE_ACTIVE_BOOLEANS 22 +#define DBASE_ACTIVE_BOOLEANS 23 dbase_config_t dbase[DBASE_COUNT]; }; @@ -236,6 +237,12 @@ static inline } static inline + dbase_config_t * semanage_fcontext_dbase_homedirs(semanage_handle_t * handle) +{ + return &handle->dbase[DBASE_POLICY_FCONTEXTS_H]; +} + +static inline dbase_config_t * semanage_seuser_dbase_policy(semanage_handle_t * handle) { return &handle->dbase[DBASE_POLICY_SEUSERS];