]> git.ipfire.org Git - thirdparty/systemd.git/blob - src/core/smack-setup.c
Add open_memstream_unlocked() wrapper
[thirdparty/systemd.git] / src / core / smack-setup.c
1 /* SPDX-License-Identifier: LGPL-2.1+ */
2 /***
3 Copyright © 2013 Intel Corporation
4 Authors:
5 Nathaniel Chen <nathaniel.chen@intel.com>
6 ***/
7
8 #include <dirent.h>
9 #include <errno.h>
10 #include <fcntl.h>
11 #include <stdio.h>
12 #include <stdlib.h>
13 #include <string.h>
14 #include <unistd.h>
15
16 #include "alloc-util.h"
17 #include "dirent-util.h"
18 #include "fd-util.h"
19 #include "fileio.h"
20 #include "log.h"
21 #include "macro.h"
22 #include "smack-setup.h"
23 #include "string-util.h"
24 #include "util.h"
25
26 #if ENABLE_SMACK
27
28 static int fdopen_unlocked_at(int dfd, const char *dir, const char *name, int *status, FILE **ret_file) {
29 int fd, r;
30 FILE *f;
31
32 fd = openat(dfd, name, O_RDONLY|O_CLOEXEC);
33 if (fd < 0) {
34 if (*status == 0)
35 *status = -errno;
36
37 return log_warning_errno(errno, "Failed to open \"%s/%s\": %m", dir, name);
38 }
39
40 r = fdopen_unlocked(fd, "r", &f);
41 if (r < 0) {
42 if (*status == 0)
43 *status = r;
44
45 safe_close(fd);
46 return log_error_errno(r, "Failed to open \"%s/%s\": %m", dir, name);
47 }
48
49 *ret_file = f;
50 return 0;
51 }
52
53 static int write_access2_rules(const char *srcdir) {
54 _cleanup_close_ int load2_fd = -1, change_fd = -1;
55 _cleanup_closedir_ DIR *dir = NULL;
56 struct dirent *entry;
57 int dfd = -1, r = 0;
58
59 load2_fd = open("/sys/fs/smackfs/load2", O_RDWR|O_CLOEXEC|O_NONBLOCK|O_NOCTTY);
60 if (load2_fd < 0) {
61 if (errno != ENOENT)
62 log_warning_errno(errno, "Failed to open '/sys/fs/smackfs/load2': %m");
63 return -errno; /* negative error */
64 }
65
66 change_fd = open("/sys/fs/smackfs/change-rule", O_RDWR|O_CLOEXEC|O_NONBLOCK|O_NOCTTY);
67 if (change_fd < 0) {
68 if (errno != ENOENT)
69 log_warning_errno(errno, "Failed to open '/sys/fs/smackfs/change-rule': %m");
70 return -errno; /* negative error */
71 }
72
73 /* write rules to load2 or change-rule from every file in the directory */
74 dir = opendir(srcdir);
75 if (!dir) {
76 if (errno != ENOENT)
77 log_warning_errno(errno, "Failed to opendir '%s': %m", srcdir);
78 return errno; /* positive on purpose */
79 }
80
81 dfd = dirfd(dir);
82 assert(dfd >= 0);
83
84 FOREACH_DIRENT(entry, dir, return 0) {
85 _cleanup_fclose_ FILE *policy = NULL;
86
87 if (!dirent_is_file(entry))
88 continue;
89
90 if (fdopen_unlocked_at(dfd, srcdir, entry->d_name, &r, &policy) < 0)
91 continue;
92
93 /* load2 write rules in the kernel require a line buffered stream */
94 for (;;) {
95 _cleanup_free_ char *buf = NULL, *sbj = NULL, *obj = NULL, *acc1 = NULL, *acc2 = NULL;
96 int q;
97
98 q = read_line(policy, NAME_MAX, &buf);
99 if (q < 0)
100 return log_error_errno(q, "Failed to read line from '%s': %m", entry->d_name);
101 if (q == 0)
102 break;
103
104 if (isempty(buf) || strchr(COMMENTS, buf[0]))
105 continue;
106
107 /* if 3 args -> load rule : subject object access1 */
108 /* if 4 args -> change rule : subject object access1 access2 */
109 if (sscanf(buf, "%ms %ms %ms %ms", &sbj, &obj, &acc1, &acc2) < 3) {
110 log_error_errno(errno, "Failed to parse rule '%s' in '%s', ignoring.", buf, entry->d_name);
111 continue;
112 }
113
114 if (write(isempty(acc2) ? load2_fd : change_fd, buf, strlen(buf)) < 0) {
115 if (r == 0)
116 r = -errno;
117 log_error_errno(errno, "Failed to write '%s' to '%s' in '%s': %m",
118 buf, isempty(acc2) ? "/sys/fs/smackfs/load2" : "/sys/fs/smackfs/change-rule", entry->d_name);
119 }
120 }
121 }
122
123 return r;
124 }
125
126 static int write_cipso2_rules(const char *srcdir) {
127 _cleanup_close_ int cipso2_fd = -1;
128 _cleanup_closedir_ DIR *dir = NULL;
129 struct dirent *entry;
130 int dfd = -1, r = 0;
131
132 cipso2_fd = open("/sys/fs/smackfs/cipso2", O_RDWR|O_CLOEXEC|O_NONBLOCK|O_NOCTTY);
133 if (cipso2_fd < 0) {
134 if (errno != ENOENT)
135 log_warning_errno(errno, "Failed to open '/sys/fs/smackfs/cipso2': %m");
136 return -errno; /* negative error */
137 }
138
139 /* write rules to cipso2 from every file in the directory */
140 dir = opendir(srcdir);
141 if (!dir) {
142 if (errno != ENOENT)
143 log_warning_errno(errno, "Failed to opendir '%s': %m", srcdir);
144 return errno; /* positive on purpose */
145 }
146
147 dfd = dirfd(dir);
148 assert(dfd >= 0);
149
150 FOREACH_DIRENT(entry, dir, return 0) {
151 _cleanup_fclose_ FILE *policy = NULL;
152
153 if (!dirent_is_file(entry))
154 continue;
155
156 if (fdopen_unlocked_at(dfd, srcdir, entry->d_name, &r, &policy) < 0)
157 continue;
158
159 /* cipso2 write rules in the kernel require a line buffered stream */
160 for (;;) {
161 _cleanup_free_ char *buf = NULL;
162 int q;
163
164 q = read_line(policy, NAME_MAX, &buf);
165 if (q < 0)
166 return log_error_errno(q, "Failed to read line from '%s': %m", entry->d_name);
167 if (q == 0)
168 break;
169
170 if (isempty(buf) || strchr(COMMENTS, buf[0]))
171 continue;
172
173 if (write(cipso2_fd, buf, strlen(buf)) < 0) {
174 if (r == 0)
175 r = -errno;
176 log_error_errno(errno, "Failed to write '%s' to '/sys/fs/smackfs/cipso2' in '%s': %m",
177 buf, entry->d_name);
178 break;
179 }
180 }
181 }
182
183 return r;
184 }
185
186 static int write_netlabel_rules(const char *srcdir) {
187 _cleanup_fclose_ FILE *dst = NULL;
188 _cleanup_closedir_ DIR *dir = NULL;
189 struct dirent *entry;
190 int dfd = -1, r = 0;
191
192 dst = fopen("/sys/fs/smackfs/netlabel", "we");
193 if (!dst) {
194 if (errno != ENOENT)
195 log_warning_errno(errno, "Failed to open /sys/fs/smackfs/netlabel: %m");
196 return -errno; /* negative error */
197 }
198
199 /* write rules to dst from every file in the directory */
200 dir = opendir(srcdir);
201 if (!dir) {
202 if (errno != ENOENT)
203 log_warning_errno(errno, "Failed to opendir %s: %m", srcdir);
204 return errno; /* positive on purpose */
205 }
206
207 dfd = dirfd(dir);
208 assert(dfd >= 0);
209
210 FOREACH_DIRENT(entry, dir, return 0) {
211 _cleanup_fclose_ FILE *policy = NULL;
212
213 if (fdopen_unlocked_at(dfd, srcdir, entry->d_name, &r, &policy) < 0)
214 continue;
215
216 /* load2 write rules in the kernel require a line buffered stream */
217 for (;;) {
218 _cleanup_free_ char *buf = NULL;
219 int q;
220
221 q = read_line(policy, NAME_MAX, &buf);
222 if (q < 0)
223 return log_error_errno(q, "Failed to read line from %s: %m", entry->d_name);
224 if (q == 0)
225 break;
226
227 if (!fputs(buf, dst)) {
228 if (r == 0)
229 r = -EINVAL;
230 log_error_errno(errno, "Failed to write line to /sys/fs/smackfs/netlabel: %m");
231 break;
232 }
233 q = fflush_and_check(dst);
234 if (q < 0) {
235 if (r == 0)
236 r = q;
237 log_error_errno(q, "Failed to flush writes to /sys/fs/smackfs/netlabel: %m");
238 break;
239 }
240 }
241 }
242
243 return r;
244 }
245
246 static int write_onlycap_list(void) {
247 _cleanup_close_ int onlycap_fd = -1;
248 _cleanup_free_ char *list = NULL;
249 _cleanup_fclose_ FILE *f = NULL;
250 size_t len = 0, allocated = 0;
251 int r;
252
253 f = fopen("/etc/smack/onlycap", "re");
254 if (!f) {
255 if (errno != ENOENT)
256 log_warning_errno(errno, "Failed to read '/etc/smack/onlycap': %m");
257
258 return errno == ENOENT ? ENOENT : -errno;
259 }
260
261 for (;;) {
262 _cleanup_free_ char *buf = NULL;
263 size_t l;
264
265 r = read_line(f, LONG_LINE_MAX, &buf);
266 if (r < 0)
267 return log_error_errno(r, "Failed to read line from /etc/smack/onlycap: %m");
268 if (r == 0)
269 break;
270
271 if (isempty(buf) || strchr(COMMENTS, *buf))
272 continue;
273
274 l = strlen(buf);
275 if (!GREEDY_REALLOC(list, allocated, len + l + 1))
276 return log_oom();
277
278 stpcpy(list + len, buf)[0] = ' ';
279 len += l + 1;
280 }
281
282 if (len == 0)
283 return 0;
284
285 list[len - 1] = 0;
286
287 onlycap_fd = open("/sys/fs/smackfs/onlycap", O_WRONLY|O_CLOEXEC|O_NONBLOCK|O_NOCTTY);
288 if (onlycap_fd < 0) {
289 if (errno != ENOENT)
290 log_warning_errno(errno, "Failed to open '/sys/fs/smackfs/onlycap': %m");
291 return -errno; /* negative error */
292 }
293
294 r = write(onlycap_fd, list, len);
295 if (r < 0)
296 return log_error_errno(errno, "Failed to write onlycap list(%s) to '/sys/fs/smackfs/onlycap': %m", list);
297
298 return 0;
299 }
300
301 #endif
302
303 int mac_smack_setup(bool *loaded_policy) {
304
305 #if ENABLE_SMACK
306
307 int r;
308
309 assert(loaded_policy);
310
311 r = write_access2_rules("/etc/smack/accesses.d/");
312 switch(r) {
313 case -ENOENT:
314 log_debug("Smack is not enabled in the kernel.");
315 return 0;
316 case ENOENT:
317 log_debug("Smack access rules directory '/etc/smack/accesses.d/' not found");
318 return 0;
319 case 0:
320 log_info("Successfully loaded Smack policies.");
321 break;
322 default:
323 log_warning_errno(r, "Failed to load Smack access rules, ignoring: %m");
324 return 0;
325 }
326
327 #ifdef SMACK_RUN_LABEL
328 r = write_string_file("/proc/self/attr/current", SMACK_RUN_LABEL, WRITE_STRING_FILE_DISABLE_BUFFER);
329 if (r < 0)
330 log_warning_errno(r, "Failed to set SMACK label \"" SMACK_RUN_LABEL "\" on self: %m");
331 r = write_string_file("/sys/fs/smackfs/ambient", SMACK_RUN_LABEL, WRITE_STRING_FILE_DISABLE_BUFFER);
332 if (r < 0)
333 log_warning_errno(r, "Failed to set SMACK ambient label \"" SMACK_RUN_LABEL "\": %m");
334 r = write_string_file("/sys/fs/smackfs/netlabel",
335 "0.0.0.0/0 " SMACK_RUN_LABEL, WRITE_STRING_FILE_DISABLE_BUFFER);
336 if (r < 0)
337 log_warning_errno(r, "Failed to set SMACK netlabel rule \"0.0.0.0/0 " SMACK_RUN_LABEL "\": %m");
338 r = write_string_file("/sys/fs/smackfs/netlabel", "127.0.0.1 -CIPSO", WRITE_STRING_FILE_DISABLE_BUFFER);
339 if (r < 0)
340 log_warning_errno(r, "Failed to set SMACK netlabel rule \"127.0.0.1 -CIPSO\": %m");
341 #endif
342
343 r = write_cipso2_rules("/etc/smack/cipso.d/");
344 switch(r) {
345 case -ENOENT:
346 log_debug("Smack/CIPSO is not enabled in the kernel.");
347 return 0;
348 case ENOENT:
349 log_debug("Smack/CIPSO access rules directory '/etc/smack/cipso.d/' not found");
350 break;
351 case 0:
352 log_info("Successfully loaded Smack/CIPSO policies.");
353 break;
354 default:
355 log_warning_errno(r, "Failed to load Smack/CIPSO access rules, ignoring: %m");
356 break;
357 }
358
359 r = write_netlabel_rules("/etc/smack/netlabel.d/");
360 switch(r) {
361 case -ENOENT:
362 log_debug("Smack/CIPSO is not enabled in the kernel.");
363 return 0;
364 case ENOENT:
365 log_debug("Smack network host rules directory '/etc/smack/netlabel.d/' not found");
366 break;
367 case 0:
368 log_info("Successfully loaded Smack network host rules.");
369 break;
370 default:
371 log_warning_errno(r, "Failed to load Smack network host rules: %m, ignoring.");
372 break;
373 }
374
375 r = write_onlycap_list();
376 switch(r) {
377 case -ENOENT:
378 log_debug("Smack is not enabled in the kernel.");
379 break;
380 case ENOENT:
381 log_debug("Smack onlycap list file '/etc/smack/onlycap' not found");
382 break;
383 case 0:
384 log_info("Successfully wrote Smack onlycap list.");
385 break;
386 default:
387 log_emergency_errno(r, "Failed to write Smack onlycap list: %m");
388 return r;
389 }
390
391 *loaded_policy = true;
392
393 #endif
394
395 return 0;
396 }