libselinux: update getseuser

- Bail out if not running on a SELinux enabled system
- Check whether the passed context is valid
- Do not report a get_ordered_context_list_with_level failure on zero
  found contexts

Signed-off-by: Christian Göttsche <cgzones@googlemail.com>
This commit is contained in:
Christian Göttsche 2021-01-07 21:41:54 +01:00 committed by Nicolas Iooss
parent e2dca5df40
commit 156dd0de5c
No known key found for this signature in database
GPG Key ID: C191415F340DAAA0

View File

@ -9,32 +9,51 @@ int main(int argc, char **argv)
{ {
char *seuser = NULL, *level = NULL; char *seuser = NULL, *level = NULL;
char **contextlist; char **contextlist;
int rc, n, i; int rc, n;
if (argc != 3) { if (argc != 3) {
fprintf(stderr, "usage: %s linuxuser fromcon\n", argv[0]); fprintf(stderr, "usage: %s linuxuser fromcon\n", argv[0]);
exit(1); return 1;
}
if (!is_selinux_enabled()) {
fprintf(stderr, "%s may be used only on a SELinux enabled kernel.\n", argv[0]);
return 4;
} }
rc = getseuserbyname(argv[1], &seuser, &level); rc = getseuserbyname(argv[1], &seuser, &level);
if (rc) { if (rc) {
fprintf(stderr, "getseuserbyname failed: %s\n", fprintf(stderr, "getseuserbyname failed: %s\n", strerror(errno));
strerror(errno)); return 2;
exit(2);
} }
printf("seuser: %s, level %s\n", seuser, level); printf("seuser: %s, level %s\n", seuser, level);
n = get_ordered_context_list_with_level(seuser, level, argv[2],
&contextlist); rc = security_check_context(argv[2]);
if (n <= 0) { if (rc) {
fprintf(stderr, fprintf(stderr, "context '%s' is invalid\n", argv[2]);
"get_ordered_context_list_with_level failed: %s\n", free(seuser);
strerror(errno)); free(level);
exit(3); return 5;
} }
n = get_ordered_context_list_with_level(seuser, level, argv[2], &contextlist);
if (n < 0) {
fprintf(stderr, "get_ordered_context_list_with_level failed: %s\n", strerror(errno));
free(seuser);
free(level);
return 3;
}
free(seuser); free(seuser);
free(level); free(level);
for (i = 0; i < n; i++)
if (n == 0)
printf("no valid context found\n");
for (int i = 0; i < n; i++)
printf("Context %d\t%s\n", i, contextlist[i]); printf("Context %d\t%s\n", i, contextlist[i]);
freeconary(contextlist); freeconary(contextlist);
exit(EXIT_SUCCESS);
return EXIT_SUCCESS;
} }