2020-11-09 05:23:58 +01:00
|
|
|
/* SPDX-License-Identifier: LGPL-2.1-or-later */
|
2013-03-07 20:06:58 +01:00
|
|
|
/***
|
2018-06-12 17:15:23 +02:00
|
|
|
Copyright © 2013 Intel Corporation
|
2013-03-07 20:06:58 +01:00
|
|
|
Authors:
|
|
|
|
Nathaniel Chen <nathaniel.chen@intel.com>
|
|
|
|
***/
|
|
|
|
|
|
|
|
#include <errno.h>
|
|
|
|
#include <fcntl.h>
|
2015-10-24 22:58:24 +02:00
|
|
|
#include <stdio.h>
|
|
|
|
#include <stdlib.h>
|
2019-03-27 11:32:41 +01:00
|
|
|
#include <unistd.h>
|
2013-03-07 20:06:58 +01:00
|
|
|
|
2015-10-27 03:01:06 +01:00
|
|
|
#include "alloc-util.h"
|
2015-10-26 20:07:55 +01:00
|
|
|
#include "dirent-util.h"
|
2015-10-25 13:14:12 +01:00
|
|
|
#include "fd-util.h"
|
2013-09-26 00:49:42 +02:00
|
|
|
#include "fileio.h"
|
2013-03-07 20:06:58 +01:00
|
|
|
#include "log.h"
|
2015-10-24 22:58:24 +02:00
|
|
|
#include "macro.h"
|
2015-10-25 13:14:12 +01:00
|
|
|
#include "smack-setup.h"
|
2015-10-24 22:58:24 +02:00
|
|
|
#include "string-util.h"
|
|
|
|
#include "util.h"
|
2013-03-07 20:06:58 +01:00
|
|
|
|
2017-10-03 12:22:40 +02:00
|
|
|
#if ENABLE_SMACK
|
2013-05-16 10:40:03 +02:00
|
|
|
|
2019-04-04 11:27:21 +02:00
|
|
|
static int fdopen_unlocked_at(int dfd, const char *dir, const char *name, int *status, FILE **ret_file) {
|
|
|
|
int fd, r;
|
|
|
|
FILE *f;
|
|
|
|
|
|
|
|
fd = openat(dfd, name, O_RDONLY|O_CLOEXEC);
|
|
|
|
if (fd < 0) {
|
|
|
|
if (*status == 0)
|
|
|
|
*status = -errno;
|
|
|
|
|
|
|
|
return log_warning_errno(errno, "Failed to open \"%s/%s\": %m", dir, name);
|
|
|
|
}
|
|
|
|
|
|
|
|
r = fdopen_unlocked(fd, "r", &f);
|
|
|
|
if (r < 0) {
|
|
|
|
if (*status == 0)
|
|
|
|
*status = r;
|
|
|
|
|
|
|
|
safe_close(fd);
|
|
|
|
return log_error_errno(r, "Failed to open \"%s/%s\": %m", dir, name);
|
|
|
|
}
|
|
|
|
|
|
|
|
*ret_file = f;
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
static int write_access2_rules(const char *srcdir) {
|
2015-06-10 04:33:00 +02:00
|
|
|
_cleanup_close_ int load2_fd = -1, change_fd = -1;
|
2013-03-07 20:06:58 +01:00
|
|
|
_cleanup_closedir_ DIR *dir = NULL;
|
|
|
|
struct dirent *entry;
|
2019-04-04 11:27:21 +02:00
|
|
|
int dfd = -1, r = 0;
|
2013-03-07 20:06:58 +01:00
|
|
|
|
2015-06-10 04:33:00 +02:00
|
|
|
load2_fd = open("/sys/fs/smackfs/load2", O_RDWR|O_CLOEXEC|O_NONBLOCK|O_NOCTTY);
|
|
|
|
if (load2_fd < 0) {
|
|
|
|
if (errno != ENOENT)
|
|
|
|
log_warning_errno(errno, "Failed to open '/sys/fs/smackfs/load2': %m");
|
|
|
|
return -errno; /* negative error */
|
|
|
|
}
|
|
|
|
|
|
|
|
change_fd = open("/sys/fs/smackfs/change-rule", O_RDWR|O_CLOEXEC|O_NONBLOCK|O_NOCTTY);
|
|
|
|
if (change_fd < 0) {
|
2013-03-14 04:23:06 +01:00
|
|
|
if (errno != ENOENT)
|
2015-06-10 04:33:00 +02:00
|
|
|
log_warning_errno(errno, "Failed to open '/sys/fs/smackfs/change-rule': %m");
|
2013-03-14 04:23:06 +01:00
|
|
|
return -errno; /* negative error */
|
2013-03-07 20:06:58 +01:00
|
|
|
}
|
|
|
|
|
2015-06-10 04:33:00 +02:00
|
|
|
/* write rules to load2 or change-rule from every file in the directory */
|
2013-03-14 04:23:06 +01:00
|
|
|
dir = opendir(srcdir);
|
2013-03-07 20:06:58 +01:00
|
|
|
if (!dir) {
|
2013-03-14 04:23:06 +01:00
|
|
|
if (errno != ENOENT)
|
2015-06-10 04:33:00 +02:00
|
|
|
log_warning_errno(errno, "Failed to opendir '%s': %m", srcdir);
|
2013-03-14 04:23:06 +01:00
|
|
|
return errno; /* positive on purpose */
|
2013-03-07 20:06:58 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
dfd = dirfd(dir);
|
2013-03-11 23:03:13 +01:00
|
|
|
assert(dfd >= 0);
|
2013-03-07 20:06:58 +01:00
|
|
|
|
|
|
|
FOREACH_DIRENT(entry, dir, return 0) {
|
|
|
|
_cleanup_fclose_ FILE *policy = NULL;
|
|
|
|
|
2019-09-29 13:43:00 +02:00
|
|
|
dirent_ensure_type(dir, entry);
|
2015-06-10 04:33:00 +02:00
|
|
|
if (!dirent_is_file(entry))
|
|
|
|
continue;
|
|
|
|
|
2019-04-04 11:27:21 +02:00
|
|
|
if (fdopen_unlocked_at(dfd, srcdir, entry->d_name, &r, &policy) < 0)
|
2013-03-07 20:06:58 +01:00
|
|
|
continue;
|
|
|
|
|
|
|
|
/* load2 write rules in the kernel require a line buffered stream */
|
2018-10-18 16:14:12 +02:00
|
|
|
for (;;) {
|
|
|
|
_cleanup_free_ char *buf = NULL, *sbj = NULL, *obj = NULL, *acc1 = NULL, *acc2 = NULL;
|
|
|
|
int q;
|
2015-06-10 04:33:00 +02:00
|
|
|
|
2018-10-18 16:14:12 +02:00
|
|
|
q = read_line(policy, NAME_MAX, &buf);
|
|
|
|
if (q < 0)
|
|
|
|
return log_error_errno(q, "Failed to read line from '%s': %m", entry->d_name);
|
|
|
|
if (q == 0)
|
|
|
|
break;
|
2015-06-10 04:33:00 +02:00
|
|
|
|
2018-10-18 16:14:12 +02:00
|
|
|
if (isempty(buf) || strchr(COMMENTS, buf[0]))
|
2015-06-10 04:33:00 +02:00
|
|
|
continue;
|
|
|
|
|
|
|
|
/* if 3 args -> load rule : subject object access1 */
|
|
|
|
/* if 4 args -> change rule : subject object access1 access2 */
|
|
|
|
if (sscanf(buf, "%ms %ms %ms %ms", &sbj, &obj, &acc1, &acc2) < 3) {
|
|
|
|
log_error_errno(errno, "Failed to parse rule '%s' in '%s', ignoring.", buf, entry->d_name);
|
|
|
|
continue;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (write(isempty(acc2) ? load2_fd : change_fd, buf, strlen(buf)) < 0) {
|
2013-03-14 04:23:06 +01:00
|
|
|
if (r == 0)
|
2015-06-10 04:33:00 +02:00
|
|
|
r = -errno;
|
2018-10-19 18:40:42 +02:00
|
|
|
log_error_errno(errno, "Failed to write '%s' to '%s' in '%s': %m",
|
2015-06-10 04:33:00 +02:00
|
|
|
buf, isempty(acc2) ? "/sys/fs/smackfs/load2" : "/sys/fs/smackfs/change-rule", entry->d_name);
|
2013-03-14 04:23:06 +01:00
|
|
|
}
|
2015-06-10 04:33:00 +02:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return r;
|
|
|
|
}
|
|
|
|
|
2019-04-04 11:27:21 +02:00
|
|
|
static int write_cipso2_rules(const char *srcdir) {
|
2015-06-10 04:33:00 +02:00
|
|
|
_cleanup_close_ int cipso2_fd = -1;
|
|
|
|
_cleanup_closedir_ DIR *dir = NULL;
|
|
|
|
struct dirent *entry;
|
2019-04-04 11:27:21 +02:00
|
|
|
int dfd = -1, r = 0;
|
2015-06-10 04:33:00 +02:00
|
|
|
|
|
|
|
cipso2_fd = open("/sys/fs/smackfs/cipso2", O_RDWR|O_CLOEXEC|O_NONBLOCK|O_NOCTTY);
|
|
|
|
if (cipso2_fd < 0) {
|
|
|
|
if (errno != ENOENT)
|
|
|
|
log_warning_errno(errno, "Failed to open '/sys/fs/smackfs/cipso2': %m");
|
|
|
|
return -errno; /* negative error */
|
|
|
|
}
|
|
|
|
|
|
|
|
/* write rules to cipso2 from every file in the directory */
|
|
|
|
dir = opendir(srcdir);
|
|
|
|
if (!dir) {
|
|
|
|
if (errno != ENOENT)
|
|
|
|
log_warning_errno(errno, "Failed to opendir '%s': %m", srcdir);
|
|
|
|
return errno; /* positive on purpose */
|
|
|
|
}
|
|
|
|
|
|
|
|
dfd = dirfd(dir);
|
|
|
|
assert(dfd >= 0);
|
|
|
|
|
|
|
|
FOREACH_DIRENT(entry, dir, return 0) {
|
|
|
|
_cleanup_fclose_ FILE *policy = NULL;
|
|
|
|
|
2019-09-29 13:43:00 +02:00
|
|
|
dirent_ensure_type(dir, entry);
|
2015-06-10 04:33:00 +02:00
|
|
|
if (!dirent_is_file(entry))
|
|
|
|
continue;
|
|
|
|
|
2019-04-04 11:27:21 +02:00
|
|
|
if (fdopen_unlocked_at(dfd, srcdir, entry->d_name, &r, &policy) < 0)
|
2015-06-10 04:33:00 +02:00
|
|
|
continue;
|
|
|
|
|
|
|
|
/* cipso2 write rules in the kernel require a line buffered stream */
|
2018-10-18 16:14:12 +02:00
|
|
|
for (;;) {
|
|
|
|
_cleanup_free_ char *buf = NULL;
|
|
|
|
int q;
|
|
|
|
|
|
|
|
q = read_line(policy, NAME_MAX, &buf);
|
|
|
|
if (q < 0)
|
|
|
|
return log_error_errno(q, "Failed to read line from '%s': %m", entry->d_name);
|
|
|
|
if (q == 0)
|
|
|
|
break;
|
2015-06-10 04:33:00 +02:00
|
|
|
|
2018-10-18 16:14:12 +02:00
|
|
|
if (isempty(buf) || strchr(COMMENTS, buf[0]))
|
2015-06-10 04:33:00 +02:00
|
|
|
continue;
|
|
|
|
|
|
|
|
if (write(cipso2_fd, buf, strlen(buf)) < 0) {
|
2013-03-14 04:23:06 +01:00
|
|
|
if (r == 0)
|
|
|
|
r = -errno;
|
2018-10-19 18:40:42 +02:00
|
|
|
log_error_errno(errno, "Failed to write '%s' to '/sys/fs/smackfs/cipso2' in '%s': %m",
|
2015-06-10 04:33:00 +02:00
|
|
|
buf, entry->d_name);
|
2013-03-14 04:23:06 +01:00
|
|
|
break;
|
|
|
|
}
|
2013-03-07 20:06:58 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2015-06-10 04:33:00 +02:00
|
|
|
return r;
|
2013-03-14 04:23:06 +01:00
|
|
|
}
|
|
|
|
|
2019-04-04 11:27:21 +02:00
|
|
|
static int write_netlabel_rules(const char *srcdir) {
|
2013-11-08 18:42:26 +01:00
|
|
|
_cleanup_fclose_ FILE *dst = NULL;
|
|
|
|
_cleanup_closedir_ DIR *dir = NULL;
|
|
|
|
struct dirent *entry;
|
2019-04-04 11:27:21 +02:00
|
|
|
int dfd = -1, r = 0;
|
2013-11-08 18:42:26 +01:00
|
|
|
|
|
|
|
dst = fopen("/sys/fs/smackfs/netlabel", "we");
|
|
|
|
if (!dst) {
|
|
|
|
if (errno != ENOENT)
|
|
|
|
log_warning_errno(errno, "Failed to open /sys/fs/smackfs/netlabel: %m");
|
|
|
|
return -errno; /* negative error */
|
|
|
|
}
|
|
|
|
|
|
|
|
/* write rules to dst from every file in the directory */
|
|
|
|
dir = opendir(srcdir);
|
|
|
|
if (!dir) {
|
|
|
|
if (errno != ENOENT)
|
|
|
|
log_warning_errno(errno, "Failed to opendir %s: %m", srcdir);
|
|
|
|
return errno; /* positive on purpose */
|
|
|
|
}
|
|
|
|
|
|
|
|
dfd = dirfd(dir);
|
|
|
|
assert(dfd >= 0);
|
|
|
|
|
|
|
|
FOREACH_DIRENT(entry, dir, return 0) {
|
|
|
|
_cleanup_fclose_ FILE *policy = NULL;
|
|
|
|
|
2019-04-04 11:27:21 +02:00
|
|
|
if (fdopen_unlocked_at(dfd, srcdir, entry->d_name, &r, &policy) < 0)
|
2013-11-08 18:42:26 +01:00
|
|
|
continue;
|
2017-12-11 19:50:30 +01:00
|
|
|
|
2013-11-08 18:42:26 +01:00
|
|
|
/* load2 write rules in the kernel require a line buffered stream */
|
2018-10-18 16:14:12 +02:00
|
|
|
for (;;) {
|
|
|
|
_cleanup_free_ char *buf = NULL;
|
2017-12-11 19:50:30 +01:00
|
|
|
int q;
|
|
|
|
|
2018-10-18 16:14:12 +02:00
|
|
|
q = read_line(policy, NAME_MAX, &buf);
|
|
|
|
if (q < 0)
|
|
|
|
return log_error_errno(q, "Failed to read line from %s: %m", entry->d_name);
|
|
|
|
if (q == 0)
|
|
|
|
break;
|
|
|
|
|
2017-12-11 19:50:30 +01:00
|
|
|
if (!fputs(buf, dst)) {
|
2013-11-08 18:42:26 +01:00
|
|
|
if (r == 0)
|
|
|
|
r = -EINVAL;
|
2018-10-19 18:40:42 +02:00
|
|
|
log_error_errno(errno, "Failed to write line to /sys/fs/smackfs/netlabel: %m");
|
2013-11-08 18:42:26 +01:00
|
|
|
break;
|
|
|
|
}
|
2017-12-11 19:50:30 +01:00
|
|
|
q = fflush_and_check(dst);
|
|
|
|
if (q < 0) {
|
2013-11-08 18:42:26 +01:00
|
|
|
if (r == 0)
|
2017-12-11 19:50:30 +01:00
|
|
|
r = q;
|
|
|
|
log_error_errno(q, "Failed to flush writes to /sys/fs/smackfs/netlabel: %m");
|
2013-11-08 18:42:26 +01:00
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2016-02-25 00:27:56 +01:00
|
|
|
return r;
|
2013-11-08 18:42:26 +01:00
|
|
|
}
|
|
|
|
|
2017-06-26 21:00:03 +02:00
|
|
|
static int write_onlycap_list(void) {
|
|
|
|
_cleanup_close_ int onlycap_fd = -1;
|
|
|
|
_cleanup_free_ char *list = NULL;
|
|
|
|
_cleanup_fclose_ FILE *f = NULL;
|
|
|
|
size_t len = 0, allocated = 0;
|
|
|
|
int r;
|
|
|
|
|
|
|
|
f = fopen("/etc/smack/onlycap", "re");
|
|
|
|
if (!f) {
|
|
|
|
if (errno != ENOENT)
|
2018-10-18 16:14:25 +02:00
|
|
|
log_warning_errno(errno, "Failed to read '/etc/smack/onlycap': %m");
|
|
|
|
|
2017-06-26 21:00:03 +02:00
|
|
|
return errno == ENOENT ? ENOENT : -errno;
|
|
|
|
}
|
|
|
|
|
2018-10-18 16:14:12 +02:00
|
|
|
for (;;) {
|
|
|
|
_cleanup_free_ char *buf = NULL;
|
2017-06-26 21:00:03 +02:00
|
|
|
size_t l;
|
|
|
|
|
2018-10-18 16:14:12 +02:00
|
|
|
r = read_line(f, LONG_LINE_MAX, &buf);
|
|
|
|
if (r < 0)
|
|
|
|
return log_error_errno(r, "Failed to read line from /etc/smack/onlycap: %m");
|
|
|
|
if (r == 0)
|
|
|
|
break;
|
|
|
|
|
|
|
|
if (isempty(buf) || strchr(COMMENTS, *buf))
|
2017-06-26 21:00:03 +02:00
|
|
|
continue;
|
|
|
|
|
|
|
|
l = strlen(buf);
|
|
|
|
if (!GREEDY_REALLOC(list, allocated, len + l + 1))
|
|
|
|
return log_oom();
|
|
|
|
|
|
|
|
stpcpy(list + len, buf)[0] = ' ';
|
|
|
|
len += l + 1;
|
|
|
|
}
|
|
|
|
|
2018-10-18 16:14:25 +02:00
|
|
|
if (len == 0)
|
2017-06-26 21:00:03 +02:00
|
|
|
return 0;
|
|
|
|
|
|
|
|
list[len - 1] = 0;
|
|
|
|
|
|
|
|
onlycap_fd = open("/sys/fs/smackfs/onlycap", O_WRONLY|O_CLOEXEC|O_NONBLOCK|O_NOCTTY);
|
|
|
|
if (onlycap_fd < 0) {
|
|
|
|
if (errno != ENOENT)
|
2018-10-18 16:14:25 +02:00
|
|
|
log_warning_errno(errno, "Failed to open '/sys/fs/smackfs/onlycap': %m");
|
2017-06-26 21:00:03 +02:00
|
|
|
return -errno; /* negative error */
|
|
|
|
}
|
|
|
|
|
|
|
|
r = write(onlycap_fd, list, len);
|
|
|
|
if (r < 0)
|
2018-10-18 16:14:25 +02:00
|
|
|
return log_error_errno(errno, "Failed to write onlycap list(%s) to '/sys/fs/smackfs/onlycap': %m", list);
|
2017-06-26 21:00:03 +02:00
|
|
|
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2013-05-16 10:40:03 +02:00
|
|
|
#endif
|
2013-03-07 20:06:58 +01:00
|
|
|
|
2014-10-24 14:15:25 +02:00
|
|
|
int mac_smack_setup(bool *loaded_policy) {
|
2013-05-16 10:40:03 +02:00
|
|
|
|
2017-10-03 12:22:40 +02:00
|
|
|
#if ENABLE_SMACK
|
2013-05-16 10:40:03 +02:00
|
|
|
|
2013-03-14 04:23:06 +01:00
|
|
|
int r;
|
|
|
|
|
2013-12-19 15:15:54 +01:00
|
|
|
assert(loaded_policy);
|
|
|
|
|
2015-06-10 04:33:00 +02:00
|
|
|
r = write_access2_rules("/etc/smack/accesses.d/");
|
2013-03-14 04:23:06 +01:00
|
|
|
switch(r) {
|
|
|
|
case -ENOENT:
|
|
|
|
log_debug("Smack is not enabled in the kernel.");
|
|
|
|
return 0;
|
|
|
|
case ENOENT:
|
2015-06-10 04:33:00 +02:00
|
|
|
log_debug("Smack access rules directory '/etc/smack/accesses.d/' not found");
|
2013-03-14 04:23:06 +01:00
|
|
|
return 0;
|
|
|
|
case 0:
|
|
|
|
log_info("Successfully loaded Smack policies.");
|
2013-03-13 00:16:44 +01:00
|
|
|
break;
|
|
|
|
default:
|
2015-09-30 22:16:17 +02:00
|
|
|
log_warning_errno(r, "Failed to load Smack access rules, ignoring: %m");
|
2013-03-13 00:16:44 +01:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2013-09-26 00:49:42 +02:00
|
|
|
#ifdef SMACK_RUN_LABEL
|
2018-11-06 13:00:07 +01:00
|
|
|
r = write_string_file("/proc/self/attr/current", SMACK_RUN_LABEL, WRITE_STRING_FILE_DISABLE_BUFFER);
|
2013-11-08 18:42:26 +01:00
|
|
|
if (r < 0)
|
|
|
|
log_warning_errno(r, "Failed to set SMACK label \"" SMACK_RUN_LABEL "\" on self: %m");
|
2018-11-06 13:00:07 +01:00
|
|
|
r = write_string_file("/sys/fs/smackfs/ambient", SMACK_RUN_LABEL, WRITE_STRING_FILE_DISABLE_BUFFER);
|
2013-11-08 18:42:26 +01:00
|
|
|
if (r < 0)
|
|
|
|
log_warning_errno(r, "Failed to set SMACK ambient label \"" SMACK_RUN_LABEL "\": %m");
|
|
|
|
r = write_string_file("/sys/fs/smackfs/netlabel",
|
2018-11-06 13:00:07 +01:00
|
|
|
"0.0.0.0/0 " SMACK_RUN_LABEL, WRITE_STRING_FILE_DISABLE_BUFFER);
|
2013-11-08 18:42:26 +01:00
|
|
|
if (r < 0)
|
|
|
|
log_warning_errno(r, "Failed to set SMACK netlabel rule \"0.0.0.0/0 " SMACK_RUN_LABEL "\": %m");
|
2018-11-06 13:00:07 +01:00
|
|
|
r = write_string_file("/sys/fs/smackfs/netlabel", "127.0.0.1 -CIPSO", WRITE_STRING_FILE_DISABLE_BUFFER);
|
2013-11-08 18:42:26 +01:00
|
|
|
if (r < 0)
|
|
|
|
log_warning_errno(r, "Failed to set SMACK netlabel rule \"127.0.0.1 -CIPSO\": %m");
|
2013-09-26 00:49:42 +02:00
|
|
|
#endif
|
|
|
|
|
2015-06-10 04:33:00 +02:00
|
|
|
r = write_cipso2_rules("/etc/smack/cipso.d/");
|
2013-03-13 00:16:44 +01:00
|
|
|
switch(r) {
|
|
|
|
case -ENOENT:
|
|
|
|
log_debug("Smack/CIPSO is not enabled in the kernel.");
|
|
|
|
return 0;
|
|
|
|
case ENOENT:
|
2015-06-10 04:33:00 +02:00
|
|
|
log_debug("Smack/CIPSO access rules directory '/etc/smack/cipso.d/' not found");
|
2013-11-08 18:42:26 +01:00
|
|
|
break;
|
2013-03-13 00:16:44 +01:00
|
|
|
case 0:
|
|
|
|
log_info("Successfully loaded Smack/CIPSO policies.");
|
2014-09-12 15:49:48 +02:00
|
|
|
break;
|
2013-03-14 04:23:06 +01:00
|
|
|
default:
|
2015-09-30 22:16:17 +02:00
|
|
|
log_warning_errno(r, "Failed to load Smack/CIPSO access rules, ignoring: %m");
|
2013-11-08 18:42:26 +01:00
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
|
|
|
r = write_netlabel_rules("/etc/smack/netlabel.d/");
|
|
|
|
switch(r) {
|
|
|
|
case -ENOENT:
|
|
|
|
log_debug("Smack/CIPSO is not enabled in the kernel.");
|
2013-03-14 04:23:06 +01:00
|
|
|
return 0;
|
2013-11-08 18:42:26 +01:00
|
|
|
case ENOENT:
|
|
|
|
log_debug("Smack network host rules directory '/etc/smack/netlabel.d/' not found");
|
|
|
|
break;
|
|
|
|
case 0:
|
|
|
|
log_info("Successfully loaded Smack network host rules.");
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
log_warning_errno(r, "Failed to load Smack network host rules: %m, ignoring.");
|
|
|
|
break;
|
2013-03-14 04:23:06 +01:00
|
|
|
}
|
2013-05-16 10:40:03 +02:00
|
|
|
|
2017-06-26 21:00:03 +02:00
|
|
|
r = write_onlycap_list();
|
|
|
|
switch(r) {
|
|
|
|
case -ENOENT:
|
|
|
|
log_debug("Smack is not enabled in the kernel.");
|
|
|
|
break;
|
|
|
|
case ENOENT:
|
|
|
|
log_debug("Smack onlycap list file '/etc/smack/onlycap' not found");
|
|
|
|
break;
|
|
|
|
case 0:
|
|
|
|
log_info("Successfully wrote Smack onlycap list.");
|
|
|
|
break;
|
|
|
|
default:
|
2020-11-26 01:27:21 +01:00
|
|
|
return log_emergency_errno(r, "Failed to write Smack onlycap list: %m");
|
2017-06-26 21:00:03 +02:00
|
|
|
}
|
|
|
|
|
2013-12-19 15:15:54 +01:00
|
|
|
*loaded_policy = true;
|
|
|
|
|
2013-05-16 10:40:03 +02:00
|
|
|
#endif
|
|
|
|
|
|
|
|
return 0;
|
2013-03-07 20:06:58 +01:00
|
|
|
}
|