Thread (1 message) 1 message, 1 author, 2014-02-21

Re: [PATCH] ss: Add support for retrieving SELinux contexts

From: Richard Haines <hidden>
Date: 2014-02-21 12:27:43
Also in: selinux

I've updated the patch with your suggestions and rebuild using the latest git
repository. Will send V2 patch today.

Thanks
Richard



----- Original Message -----
From: Ben Hutchings <ben-/+tVBieCtBitmTQ+vhA3Yw@public.gmane.org>
To: Richard Haines <redacted>
Cc: netdev-u79uwXL29TY76Z2rM5mHXA@public.gmane.org; selinux-+05T5uksL2qpZYMLLGbcSA@public.gmane.org
Sent: Sunday, 16 February 2014, 13:18
Subject: Re: [PATCH] ss: Add support for retrieving SELinux contexts

On Fri, 2014-02-14 at 15:20 +0000, Richard Haines wrote:
quoted
 The process SELinux contexts can be added to the output using the -Z
 option. Using the -z option will show the process and socket contexts (see
 the man page for details).
 For netlink sockets: if valid process show process context, if pid = 0
 show kernel initial context, if unknown show "not available".

 Signed-off-by: Richard Haines [off-list ref]
 ---
  configure     |  16 +++
  man/man8/ss.8 |  34 ++++++
  misc/Makefile |  12 ++
  misc/ss.c     | 375 
++++++++++++++++++++++++++++++++++++++++++++++++++--------
quoted
  4 files changed, 387 insertions(+), 50 deletions(-)

 diff --git a/configure b/configure
 index da01c19..854837e 100755
 --- a/configure
 +++ b/configure
 @@ -231,6 +231,19 @@ EOF
      rm -f $TMPDIR/ipsettest.c $TMPDIR/ipsettest
  }
  
 +check_selinux()
 +# SELinux is a compile time option in the ss utility
 +{
 +    SELINUX_LIB=$(${PKG_CONFIG} --silence-errors libselinux --libs)
 +    if [ -n "$SELINUX_LIB" ]
This should be just:
    if pkg-config libselinux --exists
quoted
 +    then
 +    echo "HAVE_SELINUX:=y" >>Config
 +    echo "yes"
 +    else
 +    echo "no"
 +    fi
 +}
[...]
quoted
 --- a/misc/Makefile
 +++ b/misc/Makefile
 @@ -8,6 +8,18 @@ include ../Config
  all: $(TARGETS)
  
  ss: $(SSOBJ)
 +ifeq ($(HAVE_SELINUX),y)
 +    $(CC) $(CFLAGS) $(LDFLAGS) -o $@ $(SSOBJ) $(LDLIBS) -lselinux
This should use the output of 'pkg-config libselinux --libs'.
quoted
 +else
 +    $(CC) $(CFLAGS) $(LDFLAGS) -o $@ $(SSOBJ) $(LDLIBS)
 +endif
 +
 +ss.o: ss.c
 +ifeq ($(HAVE_SELINUX),y)
 +    $(CC) $(CFLAGS) -DHAVE_SELINUX -c $+
This should use the output of 'pkg-config libselinux --cflags'.
quoted
 +else
 +    $(CC) $(CFLAGS) -c $+
 +endif
[...]

Ben.

-- 
Ben Hutchings
Any sufficiently advanced bug is indistinguishable from a feature.
_______________________________________________
Selinux mailing list
Selinux-+05T5uksL2qpZYMLLGbcSA@public.gmane.org
To unsubscribe, send email to Selinux-leave-+05T5uksL2pAGbPMOrvdOA@public.gmane.org
To get help, send an email containing "help" to Selinux-request-+05T5uksL2pUKDJzkOSz4g@public.gmane.orgov.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help