1 /* wrap getfilecon, lgetfilecon, and fgetfilecon
2 Copyright (C) 2009-2017 Free Software Foundation, Inc.
4 This program is free software; you can redistribute it and/or modify
5 it under the terms of the GNU General Public License as published by
6 the Free Software Foundation; either version 3, or (at your option)
9 This program is distributed in the hope that it will be useful,
10 but WITHOUT ANY WARRANTY; without even the implied warranty of
11 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 GNU General Public License for more details.
14 You should have received a copy of the GNU General Public License
15 along with this program; if not, see <http://www.gnu.org/licenses/>. */
17 /* written by Jim Meyering */
21 #include <selinux/selinux.h>
23 #include <sys/types.h>
27 /* FIXME: remove this once there is an errno-gnu module
28 that guarantees the definition of ENODATA. */
30 # define ENODATA ENOTSUP
36 int getfilecon (char const *file
, security_context_t
*con
);
37 int lgetfilecon (char const *file
, security_context_t
*con
);
38 int fgetfilecon (int fd
, security_context_t
*con
);
40 /* getfilecon, lgetfilecon, and fgetfilecon can all misbehave, be it
41 via an old version of libselinux where these would return 0 and set the
42 result context to NULL, or via a modern kernel+lib operating on a file
43 from a disk whose attributes were set by a kernel from around 2006.
44 In that latter case, the functions return a length of 10 for the
45 "unlabeled" context. Map both failures to a return value of -1, and
46 set errno to ENOTSUP in the first case, and ENODATA in the latter. */
49 map_to_failure (int ret
, security_context_t
*con
)
57 if (ret
== 10 && strcmp (*con
, "unlabeled") == 0)
69 rpl_getfilecon (char const *file
, security_context_t
*con
)
71 int ret
= getfilecon (file
, con
);
72 return map_to_failure (ret
, con
);
76 rpl_lgetfilecon (char const *file
, security_context_t
*con
)
78 int ret
= lgetfilecon (file
, con
);
79 return map_to_failure (ret
, con
);
83 rpl_fgetfilecon (int fd
, security_context_t
*con
)
85 int ret
= fgetfilecon (fd
, con
);
86 return map_to_failure (ret
, con
);