xref: /aosp_15_r20/external/selinux/libselinux/src/compute_member.c (revision 2d543d20722ada2425b5bdab9d0d1d29470e7bba)
1*2d543d20SAndroid Build Coastguard Worker #include <unistd.h>
2*2d543d20SAndroid Build Coastguard Worker #include <sys/types.h>
3*2d543d20SAndroid Build Coastguard Worker #include <fcntl.h>
4*2d543d20SAndroid Build Coastguard Worker #include <stdlib.h>
5*2d543d20SAndroid Build Coastguard Worker #include <stdio.h>
6*2d543d20SAndroid Build Coastguard Worker #include <errno.h>
7*2d543d20SAndroid Build Coastguard Worker #include <string.h>
8*2d543d20SAndroid Build Coastguard Worker #include <limits.h>
9*2d543d20SAndroid Build Coastguard Worker #include "selinux_internal.h"
10*2d543d20SAndroid Build Coastguard Worker #include "policy.h"
11*2d543d20SAndroid Build Coastguard Worker #include "mapping.h"
12*2d543d20SAndroid Build Coastguard Worker 
security_compute_member_raw(const char * scon,const char * tcon,security_class_t tclass,char ** newcon)13*2d543d20SAndroid Build Coastguard Worker int security_compute_member_raw(const char * scon,
14*2d543d20SAndroid Build Coastguard Worker 				const char * tcon,
15*2d543d20SAndroid Build Coastguard Worker 				security_class_t tclass,
16*2d543d20SAndroid Build Coastguard Worker 				char ** newcon)
17*2d543d20SAndroid Build Coastguard Worker {
18*2d543d20SAndroid Build Coastguard Worker 	char path[PATH_MAX];
19*2d543d20SAndroid Build Coastguard Worker 	char *buf;
20*2d543d20SAndroid Build Coastguard Worker 	size_t size;
21*2d543d20SAndroid Build Coastguard Worker 	int fd, ret;
22*2d543d20SAndroid Build Coastguard Worker 
23*2d543d20SAndroid Build Coastguard Worker 	if (!selinux_mnt) {
24*2d543d20SAndroid Build Coastguard Worker 		errno = ENOENT;
25*2d543d20SAndroid Build Coastguard Worker 		return -1;
26*2d543d20SAndroid Build Coastguard Worker 	}
27*2d543d20SAndroid Build Coastguard Worker 
28*2d543d20SAndroid Build Coastguard Worker 	snprintf(path, sizeof path, "%s/member", selinux_mnt);
29*2d543d20SAndroid Build Coastguard Worker 	fd = open(path, O_RDWR | O_CLOEXEC);
30*2d543d20SAndroid Build Coastguard Worker 	if (fd < 0)
31*2d543d20SAndroid Build Coastguard Worker 		return -1;
32*2d543d20SAndroid Build Coastguard Worker 
33*2d543d20SAndroid Build Coastguard Worker 	size = selinux_page_size;
34*2d543d20SAndroid Build Coastguard Worker 	buf = malloc(size);
35*2d543d20SAndroid Build Coastguard Worker 	if (!buf) {
36*2d543d20SAndroid Build Coastguard Worker 		ret = -1;
37*2d543d20SAndroid Build Coastguard Worker 		goto out;
38*2d543d20SAndroid Build Coastguard Worker 	}
39*2d543d20SAndroid Build Coastguard Worker 
40*2d543d20SAndroid Build Coastguard Worker 	ret = snprintf(buf, size, "%s %s %hu", scon, tcon, unmap_class(tclass));
41*2d543d20SAndroid Build Coastguard Worker 	if (ret < 0 || (size_t)ret >= size) {
42*2d543d20SAndroid Build Coastguard Worker 		errno = EOVERFLOW;
43*2d543d20SAndroid Build Coastguard Worker 		ret = -1;
44*2d543d20SAndroid Build Coastguard Worker 		goto out2;
45*2d543d20SAndroid Build Coastguard Worker 	}
46*2d543d20SAndroid Build Coastguard Worker 
47*2d543d20SAndroid Build Coastguard Worker 	ret = write(fd, buf, strlen(buf));
48*2d543d20SAndroid Build Coastguard Worker 	if (ret < 0)
49*2d543d20SAndroid Build Coastguard Worker 		goto out2;
50*2d543d20SAndroid Build Coastguard Worker 
51*2d543d20SAndroid Build Coastguard Worker 	memset(buf, 0, size);
52*2d543d20SAndroid Build Coastguard Worker 	ret = read(fd, buf, size - 1);
53*2d543d20SAndroid Build Coastguard Worker 	if (ret < 0)
54*2d543d20SAndroid Build Coastguard Worker 		goto out2;
55*2d543d20SAndroid Build Coastguard Worker 
56*2d543d20SAndroid Build Coastguard Worker 	*newcon = strdup(buf);
57*2d543d20SAndroid Build Coastguard Worker 	if (!(*newcon)) {
58*2d543d20SAndroid Build Coastguard Worker 		ret = -1;
59*2d543d20SAndroid Build Coastguard Worker 		goto out2;
60*2d543d20SAndroid Build Coastguard Worker 	}
61*2d543d20SAndroid Build Coastguard Worker 	ret = 0;
62*2d543d20SAndroid Build Coastguard Worker       out2:
63*2d543d20SAndroid Build Coastguard Worker 	free(buf);
64*2d543d20SAndroid Build Coastguard Worker       out:
65*2d543d20SAndroid Build Coastguard Worker 	close(fd);
66*2d543d20SAndroid Build Coastguard Worker 	return ret;
67*2d543d20SAndroid Build Coastguard Worker }
68*2d543d20SAndroid Build Coastguard Worker 
69*2d543d20SAndroid Build Coastguard Worker 
security_compute_member(const char * scon,const char * tcon,security_class_t tclass,char ** newcon)70*2d543d20SAndroid Build Coastguard Worker int security_compute_member(const char * scon,
71*2d543d20SAndroid Build Coastguard Worker 			    const char * tcon,
72*2d543d20SAndroid Build Coastguard Worker 			    security_class_t tclass,
73*2d543d20SAndroid Build Coastguard Worker 			    char ** newcon)
74*2d543d20SAndroid Build Coastguard Worker {
75*2d543d20SAndroid Build Coastguard Worker 	int ret;
76*2d543d20SAndroid Build Coastguard Worker 	char * rscon;
77*2d543d20SAndroid Build Coastguard Worker 	char * rtcon;
78*2d543d20SAndroid Build Coastguard Worker 	char * rnewcon;
79*2d543d20SAndroid Build Coastguard Worker 
80*2d543d20SAndroid Build Coastguard Worker 	if (selinux_trans_to_raw_context(scon, &rscon))
81*2d543d20SAndroid Build Coastguard Worker 		return -1;
82*2d543d20SAndroid Build Coastguard Worker 	if (selinux_trans_to_raw_context(tcon, &rtcon)) {
83*2d543d20SAndroid Build Coastguard Worker 		freecon(rscon);
84*2d543d20SAndroid Build Coastguard Worker 		return -1;
85*2d543d20SAndroid Build Coastguard Worker 	}
86*2d543d20SAndroid Build Coastguard Worker 
87*2d543d20SAndroid Build Coastguard Worker 	ret = security_compute_member_raw(rscon, rtcon, tclass, &rnewcon);
88*2d543d20SAndroid Build Coastguard Worker 
89*2d543d20SAndroid Build Coastguard Worker 	freecon(rscon);
90*2d543d20SAndroid Build Coastguard Worker 	freecon(rtcon);
91*2d543d20SAndroid Build Coastguard Worker 	if (!ret) {
92*2d543d20SAndroid Build Coastguard Worker 		if (selinux_raw_to_trans_context(rnewcon, newcon)) {
93*2d543d20SAndroid Build Coastguard Worker 			*newcon = NULL;
94*2d543d20SAndroid Build Coastguard Worker 			ret = -1;
95*2d543d20SAndroid Build Coastguard Worker 		}
96*2d543d20SAndroid Build Coastguard Worker 		freecon(rnewcon);
97*2d543d20SAndroid Build Coastguard Worker 	}
98*2d543d20SAndroid Build Coastguard Worker 
99*2d543d20SAndroid Build Coastguard Worker 	return ret;
100*2d543d20SAndroid Build Coastguard Worker }
101