]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/core/smack-setup.c
Merge pull request #20020 from anitazha/oomd_with_mem
[thirdparty/systemd.git] / src / core / smack-setup.c
1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
2 /***
3 Copyright © 2013 Intel Corporation
4 Authors:
5 Nathaniel Chen <nathaniel.chen@intel.com>
6 ***/
7
8 #include <errno.h>
9 #include <fcntl.h>
10 #include <stdio.h>
11 #include <stdlib.h>
12 #include <unistd.h>
13
14 #include "alloc-util.h"
15 #include "dirent-util.h"
16 #include "fd-util.h"
17 #include "fileio.h"
18 #include "log.h"
19 #include "macro.h"
20 #include "smack-setup.h"
21 #include "string-util.h"
22 #include "util.h"
23
24 #if ENABLE_SMACK
25
26 static int fdopen_unlocked_at(int dfd, const char *dir, const char *name, int *status, FILE **ret_file) {
27 int fd, r;
28 FILE *f;
29
30 fd = openat(dfd, name, O_RDONLY|O_CLOEXEC);
31 if (fd < 0) {
32 if (*status == 0)
33 *status = -errno;
34
35 return log_warning_errno(errno, "Failed to open \"%s/%s\": %m", dir, name);
36 }
37
38 r = fdopen_unlocked(fd, "r", &f);
39 if (r < 0) {
40 if (*status == 0)
41 *status = r;
42
43 safe_close(fd);
44 return log_error_errno(r, "Failed to open \"%s/%s\": %m", dir, name);
45 }
46
47 *ret_file = f;
48 return 0;
49 }
50
51 static int write_access2_rules(const char *srcdir) {
52 _cleanup_close_ int load2_fd = -1, change_fd = -1;
53 _cleanup_closedir_ DIR *dir = NULL;
54 struct dirent *entry;
55 int dfd = -1, r = 0;
56
57 load2_fd = open("/sys/fs/smackfs/load2", O_RDWR|O_CLOEXEC|O_NONBLOCK|O_NOCTTY);
58 if (load2_fd < 0) {
59 if (errno != ENOENT)
60 log_warning_errno(errno, "Failed to open '/sys/fs/smackfs/load2': %m");
61 return -errno; /* negative error */
62 }
63
64 change_fd = open("/sys/fs/smackfs/change-rule", O_RDWR|O_CLOEXEC|O_NONBLOCK|O_NOCTTY);
65 if (change_fd < 0) {
66 if (errno != ENOENT)
67 log_warning_errno(errno, "Failed to open '/sys/fs/smackfs/change-rule': %m");
68 return -errno; /* negative error */
69 }
70
71 /* write rules to load2 or change-rule from every file in the directory */
72 dir = opendir(srcdir);
73 if (!dir) {
74 if (errno != ENOENT)
75 log_warning_errno(errno, "Failed to opendir '%s': %m", srcdir);
76 return errno; /* positive on purpose */
77 }
78
79 dfd = dirfd(dir);
80 assert(dfd >= 0);
81
82 FOREACH_DIRENT(entry, dir, return 0) {
83 _cleanup_fclose_ FILE *policy = NULL;
84
85 if (!dirent_is_file(entry))
86 continue;
87
88 if (fdopen_unlocked_at(dfd, srcdir, entry->d_name, &r, &policy) < 0)
89 continue;
90
91 /* load2 write rules in the kernel require a line buffered stream */
92 for (;;) {
93 _cleanup_free_ char *buf = NULL, *sbj = NULL, *obj = NULL, *acc1 = NULL, *acc2 = NULL;
94 int q;
95
96 q = read_line(policy, NAME_MAX, &buf);
97 if (q < 0)
98 return log_error_errno(q, "Failed to read line from '%s': %m", entry->d_name);
99 if (q == 0)
100 break;
101
102 if (isempty(buf) || strchr(COMMENTS, buf[0]))
103 continue;
104
105 /* if 3 args -> load rule : subject object access1 */
106 /* if 4 args -> change rule : subject object access1 access2 */
107 if (sscanf(buf, "%ms %ms %ms %ms", &sbj, &obj, &acc1, &acc2) < 3) {
108 log_error_errno(errno, "Failed to parse rule '%s' in '%s', ignoring.", buf, entry->d_name);
109 continue;
110 }
111
112 if (write(isempty(acc2) ? load2_fd : change_fd, buf, strlen(buf)) < 0) {
113 if (r == 0)
114 r = -errno;
115 log_error_errno(errno, "Failed to write '%s' to '%s' in '%s': %m",
116 buf, isempty(acc2) ? "/sys/fs/smackfs/load2" : "/sys/fs/smackfs/change-rule", entry->d_name);
117 }
118 }
119 }
120
121 return r;
122 }
123
124 static int write_cipso2_rules(const char *srcdir) {
125 _cleanup_close_ int cipso2_fd = -1;
126 _cleanup_closedir_ DIR *dir = NULL;
127 struct dirent *entry;
128 int dfd = -1, r = 0;
129
130 cipso2_fd = open("/sys/fs/smackfs/cipso2", O_RDWR|O_CLOEXEC|O_NONBLOCK|O_NOCTTY);
131 if (cipso2_fd < 0) {
132 if (errno != ENOENT)
133 log_warning_errno(errno, "Failed to open '/sys/fs/smackfs/cipso2': %m");
134 return -errno; /* negative error */
135 }
136
137 /* write rules to cipso2 from every file in the directory */
138 dir = opendir(srcdir);
139 if (!dir) {
140 if (errno != ENOENT)
141 log_warning_errno(errno, "Failed to opendir '%s': %m", srcdir);
142 return errno; /* positive on purpose */
143 }
144
145 dfd = dirfd(dir);
146 assert(dfd >= 0);
147
148 FOREACH_DIRENT(entry, dir, return 0) {
149 _cleanup_fclose_ FILE *policy = NULL;
150
151 if (!dirent_is_file(entry))
152 continue;
153
154 if (fdopen_unlocked_at(dfd, srcdir, entry->d_name, &r, &policy) < 0)
155 continue;
156
157 /* cipso2 write rules in the kernel require a line buffered stream */
158 for (;;) {
159 _cleanup_free_ char *buf = NULL;
160 int q;
161
162 q = read_line(policy, NAME_MAX, &buf);
163 if (q < 0)
164 return log_error_errno(q, "Failed to read line from '%s': %m", entry->d_name);
165 if (q == 0)
166 break;
167
168 if (isempty(buf) || strchr(COMMENTS, buf[0]))
169 continue;
170
171 if (write(cipso2_fd, buf, strlen(buf)) < 0) {
172 if (r == 0)
173 r = -errno;
174 log_error_errno(errno, "Failed to write '%s' to '/sys/fs/smackfs/cipso2' in '%s': %m",
175 buf, entry->d_name);
176 break;
177 }
178 }
179 }
180
181 return r;
182 }
183
184 static int write_netlabel_rules(const char *srcdir) {
185 _cleanup_fclose_ FILE *dst = NULL;
186 _cleanup_closedir_ DIR *dir = NULL;
187 struct dirent *entry;
188 int dfd = -1, r = 0;
189
190 dst = fopen("/sys/fs/smackfs/netlabel", "we");
191 if (!dst) {
192 if (errno != ENOENT)
193 log_warning_errno(errno, "Failed to open /sys/fs/smackfs/netlabel: %m");
194 return -errno; /* negative error */
195 }
196
197 /* write rules to dst from every file in the directory */
198 dir = opendir(srcdir);
199 if (!dir) {
200 if (errno != ENOENT)
201 log_warning_errno(errno, "Failed to opendir %s: %m", srcdir);
202 return errno; /* positive on purpose */
203 }
204
205 dfd = dirfd(dir);
206 assert(dfd >= 0);
207
208 FOREACH_DIRENT(entry, dir, return 0) {
209 _cleanup_fclose_ FILE *policy = NULL;
210
211 if (fdopen_unlocked_at(dfd, srcdir, entry->d_name, &r, &policy) < 0)
212 continue;
213
214 /* load2 write rules in the kernel require a line buffered stream */
215 for (;;) {
216 _cleanup_free_ char *buf = NULL;
217 int q;
218
219 q = read_line(policy, NAME_MAX, &buf);
220 if (q < 0)
221 return log_error_errno(q, "Failed to read line from %s: %m", entry->d_name);
222 if (q == 0)
223 break;
224
225 if (!fputs(buf, dst)) {
226 if (r == 0)
227 r = -EINVAL;
228 log_error_errno(errno, "Failed to write line to /sys/fs/smackfs/netlabel: %m");
229 break;
230 }
231 q = fflush_and_check(dst);
232 if (q < 0) {
233 if (r == 0)
234 r = q;
235 log_error_errno(q, "Failed to flush writes to /sys/fs/smackfs/netlabel: %m");
236 break;
237 }
238 }
239 }
240
241 return r;
242 }
243
244 static int write_onlycap_list(void) {
245 _cleanup_close_ int onlycap_fd = -1;
246 _cleanup_free_ char *list = NULL;
247 _cleanup_fclose_ FILE *f = NULL;
248 size_t len = 0;
249 int r;
250
251 f = fopen("/etc/smack/onlycap", "re");
252 if (!f) {
253 if (errno != ENOENT)
254 log_warning_errno(errno, "Failed to read '/etc/smack/onlycap': %m");
255
256 return errno == ENOENT ? ENOENT : -errno;
257 }
258
259 for (;;) {
260 _cleanup_free_ char *buf = NULL;
261 size_t l;
262
263 r = read_line(f, LONG_LINE_MAX, &buf);
264 if (r < 0)
265 return log_error_errno(r, "Failed to read line from /etc/smack/onlycap: %m");
266 if (r == 0)
267 break;
268
269 if (isempty(buf) || strchr(COMMENTS, *buf))
270 continue;
271
272 l = strlen(buf);
273 if (!GREEDY_REALLOC(list, len + l + 1))
274 return log_oom();
275
276 stpcpy(list + len, buf)[0] = ' ';
277 len += l + 1;
278 }
279
280 if (len == 0)
281 return 0;
282
283 list[len - 1] = 0;
284
285 onlycap_fd = open("/sys/fs/smackfs/onlycap", O_WRONLY|O_CLOEXEC|O_NONBLOCK|O_NOCTTY);
286 if (onlycap_fd < 0) {
287 if (errno != ENOENT)
288 log_warning_errno(errno, "Failed to open '/sys/fs/smackfs/onlycap': %m");
289 return -errno; /* negative error */
290 }
291
292 r = write(onlycap_fd, list, len);
293 if (r < 0)
294 return log_error_errno(errno, "Failed to write onlycap list(%s) to '/sys/fs/smackfs/onlycap': %m", list);
295
296 return 0;
297 }
298
299 #endif
300
301 int mac_smack_setup(bool *loaded_policy) {
302
303 #if ENABLE_SMACK
304
305 int r;
306
307 assert(loaded_policy);
308
309 r = write_access2_rules("/etc/smack/accesses.d/");
310 switch(r) {
311 case -ENOENT:
312 log_debug("Smack is not enabled in the kernel.");
313 return 0;
314 case ENOENT:
315 log_debug("Smack access rules directory '/etc/smack/accesses.d/' not found");
316 return 0;
317 case 0:
318 log_info("Successfully loaded Smack policies.");
319 break;
320 default:
321 log_warning_errno(r, "Failed to load Smack access rules, ignoring: %m");
322 return 0;
323 }
324
325 #ifdef SMACK_RUN_LABEL
326 r = write_string_file("/proc/self/attr/current", SMACK_RUN_LABEL, WRITE_STRING_FILE_DISABLE_BUFFER);
327 if (r < 0)
328 log_warning_errno(r, "Failed to set SMACK label \"" SMACK_RUN_LABEL "\" on self: %m");
329 r = write_string_file("/sys/fs/smackfs/ambient", SMACK_RUN_LABEL, WRITE_STRING_FILE_DISABLE_BUFFER);
330 if (r < 0)
331 log_warning_errno(r, "Failed to set SMACK ambient label \"" SMACK_RUN_LABEL "\": %m");
332 r = write_string_file("/sys/fs/smackfs/netlabel",
333 "0.0.0.0/0 " SMACK_RUN_LABEL, WRITE_STRING_FILE_DISABLE_BUFFER);
334 if (r < 0)
335 log_warning_errno(r, "Failed to set SMACK netlabel rule \"0.0.0.0/0 " SMACK_RUN_LABEL "\": %m");
336 r = write_string_file("/sys/fs/smackfs/netlabel", "127.0.0.1 -CIPSO", WRITE_STRING_FILE_DISABLE_BUFFER);
337 if (r < 0)
338 log_warning_errno(r, "Failed to set SMACK netlabel rule \"127.0.0.1 -CIPSO\": %m");
339 #endif
340
341 r = write_cipso2_rules("/etc/smack/cipso.d/");
342 switch(r) {
343 case -ENOENT:
344 log_debug("Smack/CIPSO is not enabled in the kernel.");
345 return 0;
346 case ENOENT:
347 log_debug("Smack/CIPSO access rules directory '/etc/smack/cipso.d/' not found");
348 break;
349 case 0:
350 log_info("Successfully loaded Smack/CIPSO policies.");
351 break;
352 default:
353 log_warning_errno(r, "Failed to load Smack/CIPSO access rules, ignoring: %m");
354 break;
355 }
356
357 r = write_netlabel_rules("/etc/smack/netlabel.d/");
358 switch(r) {
359 case -ENOENT:
360 log_debug("Smack/CIPSO is not enabled in the kernel.");
361 return 0;
362 case ENOENT:
363 log_debug("Smack network host rules directory '/etc/smack/netlabel.d/' not found");
364 break;
365 case 0:
366 log_info("Successfully loaded Smack network host rules.");
367 break;
368 default:
369 log_warning_errno(r, "Failed to load Smack network host rules: %m, ignoring.");
370 break;
371 }
372
373 r = write_onlycap_list();
374 switch(r) {
375 case -ENOENT:
376 log_debug("Smack is not enabled in the kernel.");
377 break;
378 case ENOENT:
379 log_debug("Smack onlycap list file '/etc/smack/onlycap' not found");
380 break;
381 case 0:
382 log_info("Successfully wrote Smack onlycap list.");
383 break;
384 default:
385 return log_emergency_errno(r, "Failed to write Smack onlycap list: %m");
386 }
387
388 *loaded_policy = true;
389
390 #endif
391
392 return 0;
393 }