xref: /aosp_15_r20/external/selinux/libselinux/src/setexecfilecon.c (revision 2d543d20722ada2425b5bdab9d0d1d29470e7bba)
1*2d543d20SAndroid Build Coastguard Worker #include <unistd.h>
2*2d543d20SAndroid Build Coastguard Worker #include <fcntl.h>
3*2d543d20SAndroid Build Coastguard Worker #include <string.h>
4*2d543d20SAndroid Build Coastguard Worker #include "selinux_internal.h"
5*2d543d20SAndroid Build Coastguard Worker #include "context_internal.h"
6*2d543d20SAndroid Build Coastguard Worker 
setexecfilecon(const char * filename,const char * fallback_type)7*2d543d20SAndroid Build Coastguard Worker int setexecfilecon(const char *filename, const char *fallback_type)
8*2d543d20SAndroid Build Coastguard Worker {
9*2d543d20SAndroid Build Coastguard Worker 	char * mycon = NULL, *fcon = NULL, *newcon = NULL;
10*2d543d20SAndroid Build Coastguard Worker 	context_t con = NULL;
11*2d543d20SAndroid Build Coastguard Worker 	int rc = 0;
12*2d543d20SAndroid Build Coastguard Worker 
13*2d543d20SAndroid Build Coastguard Worker 	if (is_selinux_enabled() < 1)
14*2d543d20SAndroid Build Coastguard Worker 		return 0;
15*2d543d20SAndroid Build Coastguard Worker 
16*2d543d20SAndroid Build Coastguard Worker 	rc = getcon(&mycon);
17*2d543d20SAndroid Build Coastguard Worker 	if (rc < 0)
18*2d543d20SAndroid Build Coastguard Worker 		goto out;
19*2d543d20SAndroid Build Coastguard Worker 
20*2d543d20SAndroid Build Coastguard Worker 	rc = getfilecon(filename, &fcon);
21*2d543d20SAndroid Build Coastguard Worker 	if (rc < 0)
22*2d543d20SAndroid Build Coastguard Worker 		goto out;
23*2d543d20SAndroid Build Coastguard Worker 
24*2d543d20SAndroid Build Coastguard Worker 	rc = security_compute_create(mycon, fcon, string_to_security_class("process"), &newcon);
25*2d543d20SAndroid Build Coastguard Worker 	if (rc < 0)
26*2d543d20SAndroid Build Coastguard Worker 		goto out;
27*2d543d20SAndroid Build Coastguard Worker 
28*2d543d20SAndroid Build Coastguard Worker 	if (!strcmp(mycon, newcon)) {
29*2d543d20SAndroid Build Coastguard Worker 		/* No default transition, use fallback_type for now. */
30*2d543d20SAndroid Build Coastguard Worker 		rc = -1;
31*2d543d20SAndroid Build Coastguard Worker 		con = context_new(mycon);
32*2d543d20SAndroid Build Coastguard Worker 		if (!con)
33*2d543d20SAndroid Build Coastguard Worker 			goto out;
34*2d543d20SAndroid Build Coastguard Worker 		if (context_type_set(con, fallback_type))
35*2d543d20SAndroid Build Coastguard Worker 			goto out;
36*2d543d20SAndroid Build Coastguard Worker 		freecon(newcon);
37*2d543d20SAndroid Build Coastguard Worker 		newcon = strdup(context_str(con));
38*2d543d20SAndroid Build Coastguard Worker 		if (!newcon)
39*2d543d20SAndroid Build Coastguard Worker 			goto out;
40*2d543d20SAndroid Build Coastguard Worker 	}
41*2d543d20SAndroid Build Coastguard Worker 
42*2d543d20SAndroid Build Coastguard Worker 	rc = setexeccon(newcon);
43*2d543d20SAndroid Build Coastguard Worker       out:
44*2d543d20SAndroid Build Coastguard Worker 
45*2d543d20SAndroid Build Coastguard Worker 	if (rc < 0 && security_getenforce() == 0)
46*2d543d20SAndroid Build Coastguard Worker 		rc = 0;
47*2d543d20SAndroid Build Coastguard Worker 
48*2d543d20SAndroid Build Coastguard Worker 	context_free(con);
49*2d543d20SAndroid Build Coastguard Worker 	freecon(newcon);
50*2d543d20SAndroid Build Coastguard Worker 	freecon(fcon);
51*2d543d20SAndroid Build Coastguard Worker 	freecon(mycon);
52*2d543d20SAndroid Build Coastguard Worker 	return rc < 0 ? rc : 0;
53*2d543d20SAndroid Build Coastguard Worker }
54*2d543d20SAndroid Build Coastguard Worker 
55*2d543d20SAndroid Build Coastguard Worker #ifndef DISABLE_RPM
rpm_execcon(unsigned int verified,const char * filename,char * const argv[],char * const envp[])56*2d543d20SAndroid Build Coastguard Worker int rpm_execcon(unsigned int verified __attribute__ ((unused)),
57*2d543d20SAndroid Build Coastguard Worker 		const char *filename, char *const argv[], char *const envp[])
58*2d543d20SAndroid Build Coastguard Worker {
59*2d543d20SAndroid Build Coastguard Worker 	int rc;
60*2d543d20SAndroid Build Coastguard Worker 
61*2d543d20SAndroid Build Coastguard Worker 	rc = setexecfilecon(filename, "rpm_script_t");
62*2d543d20SAndroid Build Coastguard Worker 	if (rc < 0)
63*2d543d20SAndroid Build Coastguard Worker 		return rc;
64*2d543d20SAndroid Build Coastguard Worker 
65*2d543d20SAndroid Build Coastguard Worker 	return execve(filename, argv, envp);
66*2d543d20SAndroid Build Coastguard Worker }
67*2d543d20SAndroid Build Coastguard Worker #endif
68