Blame selinux_utils.c

Packit Service 3e5a5a
/*
Packit Service 3e5a5a
 * Copyright Red Hat, Inc., 2003,2004.
Packit Service 3e5a5a
 *
Packit Service 3e5a5a
 * Redistribution and use in source and binary forms, with or without
Packit Service 3e5a5a
 * modification, are permitted provided that the following conditions
Packit Service 3e5a5a
 * are met:
Packit Service 3e5a5a
 * 1. Redistributions of source code must retain the above copyright
Packit Service 3e5a5a
 *    notice, and the entire permission notice in its entirety,
Packit Service 3e5a5a
 *    including the disclaimer of warranties.
Packit Service 3e5a5a
 * 2. Redistributions in binary form must reproduce the above copyright
Packit Service 3e5a5a
 *    notice, this list of conditions and the following disclaimer in the
Packit Service 3e5a5a
 *    documentation and/or other materials provided with the distribution.
Packit Service 3e5a5a
 * 3. The name of the author may not be used to endorse or promote
Packit Service 3e5a5a
 *    products derived from this software without specific prior
Packit Service 3e5a5a
 *    written permission.
Packit Service 3e5a5a
 *
Packit Service 3e5a5a
 * ALTERNATIVELY, this product may be distributed under the terms of
Packit Service 3e5a5a
 * the GNU Public License, in which case the provisions of the GPL are
Packit Service 3e5a5a
 * required INSTEAD OF the above restrictions.  (This clause is
Packit Service 3e5a5a
 * necessary due to a potential bad interaction between the GPL and
Packit Service 3e5a5a
 * the restrictions contained in a BSD-style copyright.)
Packit Service 3e5a5a
 *
Packit Service 3e5a5a
 * THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED
Packit Service 3e5a5a
 * WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
Packit Service 3e5a5a
 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
Packit Service 3e5a5a
 * DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT,
Packit Service 3e5a5a
 * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
Packit Service 3e5a5a
 * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
Packit Service 3e5a5a
 * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
Packit Service 3e5a5a
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
Packit Service 3e5a5a
 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
Packit Service 3e5a5a
 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
Packit Service 3e5a5a
 * OF THE POSSIBILITY OF SUCH DAMAGE.
Packit Service 3e5a5a
 */
Packit Service 3e5a5a
Packit Service 3e5a5a
/* Written by Daniel Walsh <dwalsh@redhat.com> */
Packit Service 3e5a5a
Packit Service 3e5a5a
#include "selinux_utils.h"
Packit Service 3e5a5a
#include <selinux/selinux.h>
Packit Service 3e5a5a
#include <stdio.h>
Packit Service 3e5a5a
#include <string.h>
Packit Service 3e5a5a
#include <selinux/avc.h>
Packit Service 3e5a5a
#include <libaudit.h>
Packit Service 3e5a5a
#include <unistd.h>
Packit Service 3e5a5a
#include <limits.h>
Packit Service 3e5a5a
Packit Service 3e5a5a
/* FD to send audit messages to */
Packit Service 3e5a5a
static int audit_fd = -1;
Packit Service 3e5a5a
Packit Service 3e5a5a
/* log_callback stolen from dbus */
Packit Service 3e5a5a
static int
Packit Service 3e5a5a
log_callback (int type, const char *fmt, ...) 
Packit Service 3e5a5a
{
Packit Service 3e5a5a
  va_list ap;
Packit Service 3e5a5a
Packit Service 3e5a5a
  (void)type;
Packit Service 3e5a5a
Packit Service 3e5a5a
  va_start(ap, fmt);
Packit Service 3e5a5a
Packit Service 3e5a5a
  if (audit_fd >= 0)
Packit Service 3e5a5a
  {
Packit Service 3e5a5a
	  char buf[PATH_MAX*2];
Packit Service 3e5a5a
    
Packit Service 3e5a5a
	  vsnprintf(buf, sizeof(buf), fmt, ap);
Packit Service 3e5a5a
	  audit_log_user_avc_message(audit_fd, AUDIT_USER_AVC, buf, NULL, NULL,
Packit Service 3e5a5a
				     NULL, 0);
Packit Service 3e5a5a
	  va_end(ap);
Packit Service 3e5a5a
	  return 0;
Packit Service 3e5a5a
  }
Packit Service 3e5a5a
  
Packit Service 3e5a5a
  vsyslog (LOG_USER | LOG_INFO, fmt, ap);
Packit Service 3e5a5a
  va_end(ap);
Packit Service 3e5a5a
  return 0;
Packit Service 3e5a5a
}
Packit Service 3e5a5a
int selinux_check_root(void) {
Packit Service 3e5a5a
	int status = -1;
Packit Service 3e5a5a
	security_context_t user_context;
Packit Service 3e5a5a
Packit Service 3e5a5a
	if (getuid() != 0) return 0;
Packit Service 3e5a5a
	if (is_selinux_enabled() == 0) return 0;
Packit Service 3e5a5a
	if ((status = getprevcon(&user_context)) < 0) return status;
Packit Service 3e5a5a
Packit Service 3e5a5a
	status = selinux_check_access(user_context, user_context, "passwd", "passwd", NULL);
Packit Service 3e5a5a
Packit Service 3e5a5a
	freecon(user_context);
Packit Service 3e5a5a
Packit Service 3e5a5a
	return status;
Packit Service 3e5a5a
}
Packit Service 3e5a5a
Packit Service 3e5a5a
void selinux_init(int fd) {
Packit Service 3e5a5a
	if (is_selinux_enabled() > 0) {
Packit Service 3e5a5a
		/* initialize audit log */
Packit Service 3e5a5a
Packit Service 3e5a5a
		audit_fd = fd;
Packit Service 3e5a5a
Packit Service 3e5a5a
		/* setup callbacks */
Packit Service 3e5a5a
		selinux_set_callback(SELINUX_CB_LOG, (union selinux_callback) &log_callback);
Packit Service 3e5a5a
	}
Packit Service 3e5a5a
}