mirror of
https://github.com/systemd/systemd.git
synced 2025-03-19 22:50:17 +03:00
smack-setup: enable Smack/CIPSO mapping
CIPSO is the Common IP Security Option, an IETF standard for setting security levels for a process sending packets. In Smack kernels, CIPSO headers are mapped to Smack labels automatically, but can be changed. This patch writes label/category mappings from /etc/smack/cipso/ to /sys/fs/smackfs/cipso2. The mapping format is "%s%4d%4d"["%4d"]... For more information about Smack and CIPSO, see: https://kernel.org/doc/Documentation/security/Smack.txt
This commit is contained in:
parent
a4783bd17a
commit
abbacb1def
@ -40,6 +40,7 @@
|
||||
#include "label.h"
|
||||
|
||||
#define SMACK_CONFIG "/etc/smack/accesses.d/"
|
||||
#define CIPSO_CONFIG "/etc/smack/cipso/"
|
||||
|
||||
static int write_rules(const char* dstpath, const char* srcdir) {
|
||||
_cleanup_fclose_ FILE *dst = NULL;
|
||||
@ -124,9 +125,26 @@ int smack_setup(void) {
|
||||
return 0;
|
||||
case 0:
|
||||
log_info("Successfully loaded Smack policies.");
|
||||
break;
|
||||
default:
|
||||
log_warning("Failed to load Smack access rules: %s, ignoring.",
|
||||
strerror(abs(r)));
|
||||
return 0;
|
||||
}
|
||||
|
||||
r = write_rules("/sys/fs/smackfs/cipso2", CIPSO_CONFIG);
|
||||
switch(r) {
|
||||
case -ENOENT:
|
||||
log_debug("Smack/CIPSO is not enabled in the kernel.");
|
||||
return 0;
|
||||
case ENOENT:
|
||||
log_debug("Smack/CIPSO access rules directory " CIPSO_CONFIG " not found");
|
||||
return 0;
|
||||
case 0:
|
||||
log_info("Successfully loaded Smack/CIPSO policies.");
|
||||
return 0;
|
||||
default:
|
||||
log_warning("Failed to load smack access rules: %s, ignoring.",
|
||||
log_warning("Failed to load Smack/CIPSO access rules: %s, ignoring.",
|
||||
strerror(abs(r)));
|
||||
return 0;
|
||||
}
|
||||
|
Loading…
x
Reference in New Issue
Block a user