xref: /aosp_15_r20/external/selinux/libselinux/utils/getdefaultcon.c (revision 2d543d20722ada2425b5bdab9d0d1d29470e7bba)
1 #include <unistd.h>
2 #include <sys/types.h>
3 #include <fcntl.h>
4 #include <stdio.h>
5 #include <stdlib.h>
6 #include <errno.h>
7 #include <string.h>
8 #include <ctype.h>
9 #include <selinux/selinux.h>
10 #include <selinux/get_context_list.h>
11 
usage(const char * name,const char * detail,int rc)12 static __attribute__ ((__noreturn__)) void usage(const char *name, const char *detail, int rc)
13 {
14 	fprintf(stderr, "usage:  %s [-r role] [-l level] [-s service] [-v] user [fromcon]\n", name);
15 	if (detail)
16 		fprintf(stderr, "%s:  %s\n", name, detail);
17 	exit(rc);
18 }
19 
main(int argc,char ** argv)20 int main(int argc, char **argv)
21 {
22 	const char *cur_context, *user;
23 	char *usercon = NULL, *cur_con = NULL;
24 	char *level = NULL, *role=NULL, *seuser=NULL, *dlevel=NULL;
25 	char *service = NULL;
26 	int ret, opt;
27 	int verbose = 0;
28 
29 	while ((opt = getopt(argc, argv, "l:r:s:v")) > 0) {
30 		switch (opt) {
31 		case 'l':
32 			free(level);
33 			level = strdup(optarg);
34 			break;
35 		case 'r':
36 			free(role);
37 			role = strdup(optarg);
38 			break;
39 		case 's':
40 			free(service);
41 			service = strdup(optarg);
42 			break;
43 		case 'v':
44 			verbose = 1;
45 			break;
46 		default:
47 			usage(argv[0], "invalid option", 1);
48 		}
49 	}
50 
51 	if (((argc - optind) < 1) || ((argc - optind) > 2))
52 		usage(argv[0], "invalid number of arguments", 2);
53 
54 	/* If selinux isn't available, bail out. */
55 	if (!is_selinux_enabled()) {
56 		fprintf(stderr,
57 			"%s may be used only on a SELinux kernel.\n", argv[0]);
58 		free(level);
59 		free(role);
60 		free(service);
61 		return 1;
62 	}
63 
64 	user = argv[optind];
65 
66 	/* If a context wasn't passed, use the current context. */
67 	if ((argc - optind) < 2) {
68 		if (getcon(&cur_con) < 0) {
69 			fprintf(stderr, "%s:  couldn't get current context:  %s\n", argv[0], strerror(errno));
70 			free(level);
71 			free(role);
72 			free(service);
73 			return 2;
74 		}
75 		cur_context = cur_con;
76 	} else
77 		cur_context = argv[optind + 1];
78 
79 	if (security_check_context(cur_context)) {
80 		fprintf(stderr, "%s:  invalid from context '%s'\n", argv[0], cur_context);
81 		free(cur_con);
82 		free(level);
83 		free(role);
84 		free(service);
85 		return 3;
86 	}
87 
88 	ret = getseuser(user, service, &seuser, &dlevel);
89 	if (ret) {
90 		fprintf(stderr, "%s:  failed to get seuser:  %s\n", argv[0], strerror(errno));
91 		goto out;
92 	}
93 
94 	if (! level) level=dlevel;
95 	if (role != NULL && role[0])
96 		ret = get_default_context_with_rolelevel(seuser, role, level, cur_context, &usercon);
97 	else
98 		ret = get_default_context_with_level(seuser, level, cur_context, &usercon);
99 	if (ret) {
100 		fprintf(stderr, "%s:  failed to get default context:  %s\n", argv[0], strerror(errno));
101 		goto out;
102 	}
103 
104 	if (verbose) {
105 		printf("%s: %s from %s %s %s %s -> %s\n", argv[0], user, cur_context, seuser, role, level, usercon);
106 	} else {
107 		printf("%s\n", usercon);
108 	}
109 
110 out:
111 	free(role);
112 	free(seuser);
113 	if (level != dlevel) free(level);
114 	free(dlevel);
115 	free(usercon);
116 	free(cur_con);
117 	free(service);
118 
119 	return ret >= 0;
120 }
121