1*2d543d20SAndroid Build Coastguard Worker #include <unistd.h>
2*2d543d20SAndroid Build Coastguard Worker #include <sys/types.h>
3*2d543d20SAndroid Build Coastguard Worker #include <fcntl.h>
4*2d543d20SAndroid Build Coastguard Worker #include <stdlib.h>
5*2d543d20SAndroid Build Coastguard Worker #include <stdio.h>
6*2d543d20SAndroid Build Coastguard Worker #include <errno.h>
7*2d543d20SAndroid Build Coastguard Worker #include <string.h>
8*2d543d20SAndroid Build Coastguard Worker #include <limits.h>
9*2d543d20SAndroid Build Coastguard Worker #include "selinux_internal.h"
10*2d543d20SAndroid Build Coastguard Worker #include "policy.h"
11*2d543d20SAndroid Build Coastguard Worker #include "mapping.h"
12*2d543d20SAndroid Build Coastguard Worker
security_validatetrans_raw(const char * scon,const char * tcon,security_class_t tclass,const char * newcon)13*2d543d20SAndroid Build Coastguard Worker int security_validatetrans_raw(const char *scon,
14*2d543d20SAndroid Build Coastguard Worker const char *tcon,
15*2d543d20SAndroid Build Coastguard Worker security_class_t tclass,
16*2d543d20SAndroid Build Coastguard Worker const char *newcon)
17*2d543d20SAndroid Build Coastguard Worker {
18*2d543d20SAndroid Build Coastguard Worker char path[PATH_MAX];
19*2d543d20SAndroid Build Coastguard Worker char *buf = NULL;
20*2d543d20SAndroid Build Coastguard Worker int size, bufsz;
21*2d543d20SAndroid Build Coastguard Worker int fd, ret = -1;
22*2d543d20SAndroid Build Coastguard Worker errno = ENOENT;
23*2d543d20SAndroid Build Coastguard Worker
24*2d543d20SAndroid Build Coastguard Worker if (!selinux_mnt) {
25*2d543d20SAndroid Build Coastguard Worker return -1;
26*2d543d20SAndroid Build Coastguard Worker }
27*2d543d20SAndroid Build Coastguard Worker
28*2d543d20SAndroid Build Coastguard Worker snprintf(path, sizeof path, "%s/validatetrans", selinux_mnt);
29*2d543d20SAndroid Build Coastguard Worker fd = open(path, O_WRONLY | O_CLOEXEC);
30*2d543d20SAndroid Build Coastguard Worker if (fd < 0) {
31*2d543d20SAndroid Build Coastguard Worker return -1;
32*2d543d20SAndroid Build Coastguard Worker }
33*2d543d20SAndroid Build Coastguard Worker
34*2d543d20SAndroid Build Coastguard Worker errno = EINVAL;
35*2d543d20SAndroid Build Coastguard Worker size = selinux_page_size;
36*2d543d20SAndroid Build Coastguard Worker buf = malloc(size);
37*2d543d20SAndroid Build Coastguard Worker if (!buf) {
38*2d543d20SAndroid Build Coastguard Worker goto out;
39*2d543d20SAndroid Build Coastguard Worker }
40*2d543d20SAndroid Build Coastguard Worker
41*2d543d20SAndroid Build Coastguard Worker bufsz = snprintf(buf, size, "%s %s %hu %s", scon, tcon, unmap_class(tclass), newcon);
42*2d543d20SAndroid Build Coastguard Worker if (bufsz >= size || bufsz < 0) {
43*2d543d20SAndroid Build Coastguard Worker // It got truncated or there was an encoding error
44*2d543d20SAndroid Build Coastguard Worker goto out;
45*2d543d20SAndroid Build Coastguard Worker }
46*2d543d20SAndroid Build Coastguard Worker
47*2d543d20SAndroid Build Coastguard Worker // clear errno for write()
48*2d543d20SAndroid Build Coastguard Worker errno = 0;
49*2d543d20SAndroid Build Coastguard Worker ret = write(fd, buf, strlen(buf));
50*2d543d20SAndroid Build Coastguard Worker if (ret > 0) {
51*2d543d20SAndroid Build Coastguard Worker // The kernel returns the bytes written on success, not 0 as noted in the commit message
52*2d543d20SAndroid Build Coastguard Worker ret = 0;
53*2d543d20SAndroid Build Coastguard Worker }
54*2d543d20SAndroid Build Coastguard Worker out:
55*2d543d20SAndroid Build Coastguard Worker free(buf);
56*2d543d20SAndroid Build Coastguard Worker close(fd);
57*2d543d20SAndroid Build Coastguard Worker return ret;
58*2d543d20SAndroid Build Coastguard Worker }
59*2d543d20SAndroid Build Coastguard Worker
60*2d543d20SAndroid Build Coastguard Worker
security_validatetrans(const char * scon,const char * tcon,security_class_t tclass,const char * newcon)61*2d543d20SAndroid Build Coastguard Worker int security_validatetrans(const char *scon,
62*2d543d20SAndroid Build Coastguard Worker const char *tcon,
63*2d543d20SAndroid Build Coastguard Worker security_class_t tclass,
64*2d543d20SAndroid Build Coastguard Worker const char *newcon)
65*2d543d20SAndroid Build Coastguard Worker {
66*2d543d20SAndroid Build Coastguard Worker int ret = -1;
67*2d543d20SAndroid Build Coastguard Worker char *rscon = NULL;
68*2d543d20SAndroid Build Coastguard Worker char *rtcon = NULL;
69*2d543d20SAndroid Build Coastguard Worker char *rnewcon = NULL;
70*2d543d20SAndroid Build Coastguard Worker
71*2d543d20SAndroid Build Coastguard Worker if (selinux_trans_to_raw_context(scon, &rscon)) {
72*2d543d20SAndroid Build Coastguard Worker goto out;
73*2d543d20SAndroid Build Coastguard Worker }
74*2d543d20SAndroid Build Coastguard Worker
75*2d543d20SAndroid Build Coastguard Worker if (selinux_trans_to_raw_context(tcon, &rtcon)) {
76*2d543d20SAndroid Build Coastguard Worker goto out;
77*2d543d20SAndroid Build Coastguard Worker }
78*2d543d20SAndroid Build Coastguard Worker
79*2d543d20SAndroid Build Coastguard Worker if (selinux_trans_to_raw_context(newcon, &rnewcon)) {
80*2d543d20SAndroid Build Coastguard Worker goto out;
81*2d543d20SAndroid Build Coastguard Worker }
82*2d543d20SAndroid Build Coastguard Worker
83*2d543d20SAndroid Build Coastguard Worker ret = security_validatetrans_raw(rscon, rtcon, tclass, rnewcon);
84*2d543d20SAndroid Build Coastguard Worker
85*2d543d20SAndroid Build Coastguard Worker out:
86*2d543d20SAndroid Build Coastguard Worker freecon(rnewcon);
87*2d543d20SAndroid Build Coastguard Worker freecon(rtcon);
88*2d543d20SAndroid Build Coastguard Worker freecon(rscon);
89*2d543d20SAndroid Build Coastguard Worker
90*2d543d20SAndroid Build Coastguard Worker return ret;
91*2d543d20SAndroid Build Coastguard Worker }
92*2d543d20SAndroid Build Coastguard Worker
93