RPM Package Manager, CVS Repository
http://rpm5.org/cvs/
____________________________________________________________________________
Server: rpm5.org Name: Jeff Johnson
Root: /v/rpm/cvs Email: [EMAIL PROTECTED]
Module: rpm Date: 06-Oct-2008 21:05:33
Branch: HEAD Handle: 2008100619053101
Modified files:
rpm CHANGES
rpm/lib fsm.c librpm.vers rpminstall.c rpmts.c rpmts.h
transaction.c
rpm/python rpmts-py.c
rpm/rpmio iosm.c iosm.h
Log:
- jbj: selinux: resurrect lsetfilecon using libselinux API.
Summary:
Revision Changes Path
1.2586 +1 -0 rpm/CHANGES
2.175 +24 -18 rpm/lib/fsm.c
1.53 +0 -2 rpm/lib/librpm.vers
1.215 +0 -10 rpm/lib/rpminstall.c
2.155 +4 -18 rpm/lib/rpmts.c
2.107 +0 -18 rpm/lib/rpmts.h
1.386 +15 -0 rpm/lib/transaction.c
1.95 +0 -10 rpm/python/rpmts-py.c
1.27 +26 -22 rpm/rpmio/iosm.c
1.15 +0 -1 rpm/rpmio/iosm.h
____________________________________________________________________________
patch -p0 <<'@@ .'
Index: rpm/CHANGES
============================================================================
$ cvs diff -u -r1.2585 -r1.2586 CHANGES
--- rpm/CHANGES 4 Oct 2008 19:35:32 -0000 1.2585
+++ rpm/CHANGES 6 Oct 2008 19:05:31 -0000 1.2586
@@ -1,5 +1,6 @@
5.1.0 -> 5.2a0:
+ - jbj: selinux: resurrect lsetfilecon using libselinux API.
- jbj: use macro, not /bin/bash, in scriptlet_requires.
- jbj: don't run empty transactions, avoiding obscure error msg.
- jbj: permit a negative index as alias for the last problem added to
set.
@@ .
patch -p0 <<'@@ .'
Index: rpm/lib/fsm.c
============================================================================
$ cvs diff -u -r2.174 -r2.175 fsm.c
--- rpm/lib/fsm.c 17 Sep 2008 20:09:16 -0000 2.174
+++ rpm/lib/fsm.c 6 Oct 2008 19:05:32 -0000 2.175
@@ -136,7 +136,6 @@
FSMI_t iter = p;
if (iter) {
iter->fi = rpmfiUnlink(iter->fi, "mapIterator");
- iter->sx = rpmsxFree(iter->sx);
/[EMAIL PROTECTED]@*/ /* XXX rpmswExit() */
iter->ts = rpmtsFree(iter->ts);
/[EMAIL PROTECTED]@*/
@@ -683,10 +682,7 @@
/[EMAIL PROTECTED]@*/ /* LCL: avoid void * _ts/_fi annotations for
now. */
fsm->iter = mapInitIterator(fi, reverse);
fsm->iter->ts = rpmtsLink(ts, "mapIterator");
- fsm->nofcontexts = (ts != NULL && rpmtsSELinuxEnabled(ts) == 1 &&
- !(rpmtsFlags(ts) & RPMTRANS_FLAG_NOCONTEXTS));
- /* XXX Set file contexts on non-packaged dirs iff selinux enabled. */
- fsm->iter->sx = (!fsm->nofcontexts ? rpmtsREContext(ts) : NULL);
+ fsm->nofcontexts = (rpmtsFlags(ts) & RPMTRANS_FLAG_NOCONTEXTS);
/[EMAIL PROTECTED]@*/
fsm->nofdigests =
(ts != NULL && !(rpmtsFlags(ts) & RPMTRANS_FLAG_NOFDIGESTS))
@@ -751,7 +747,6 @@
&fsm->op_digest);
fsm->lmtab = _free(fsm->lmtab);
- fsm->iter->sx = rpmsxFree(fsm->iter->sx);
fsm->iter->ts = rpmtsFree(fsm->iter->ts);
fsm->iter = mapFreeIterator(fsm->iter);
if (fsm->cfd != NULL) {
@@ -764,28 +759,33 @@
return rc;
}
+/*
+ * Set file security context (if not disabled).
+ * @param fsm file state machine data
+ * @return 0 always
+ */
static int fsmMapFContext(IOSM_t fsm)
/[EMAIL PROTECTED] fsm @*/
{
- rpmfi fi = fsmGetFi(fsm);
-
- /*
- * Find file security context (if not disabled).
- */
fsm->fcontext = NULL;
if (!fsm->nofcontexts) {
+ struct stat * st = &fsm->sb;
security_context_t scon = NULL;
+ int xx = matchpathcon(fsm->path, st->st_mode, &scon);
/[EMAIL PROTECTED]@*/
- if (matchpathcon(fsm->path, fsm->sb.st_mode, &scon) == 0 && scon !=
NULL)
+ if (!xx && scon != NULL)
fsm->fcontext = scon;
+#ifdef DYING /* XXX SELinux file contexts not set from package
content. */
else {
+ rpmfi fi = fsmGetFi(fsm);
int i = fsm->ix;
/* Get file security context from package. */
if (fi && i >= 0 && i < (int)fi->fc)
fsm->fcontext = (fi->fcontexts ? fi->fcontexts[i] : NULL);
}
+#endif
/[EMAIL PROTECTED]@*/
}
return 0;
@@ -1489,23 +1489,29 @@
st->st_mode = S_IFDIR | (fi->dperms & 07777);
rc = fsmNext(fsm, IOSM_MKDIR);
if (!rc) {
+ security_context_t scon = NULL;
/* XXX FIXME? only new dir will have context set. */
/* Get file security context from patterns. */
- if (fsm->iter->sx != NULL) {
- fsm->fcontext = rpmsxFContext(fsm->iter->sx,
- fsm->path, st->st_mode);
+ if (!fsm->nofcontexts
+ && !matchpathcon(fsm->path, st->st_mode, &scon)
+ && scon != NULL)
+ {
+ fsm->fcontext = scon;
rc = fsmNext(fsm, IOSM_LSETFCON);
- }
+ } else
+ fsm->fcontext = NULL;
if (fsm->fcontext == NULL)
rpmlog(RPMLOG_DEBUG,
D_("%s directory created with perms %04o, no
context.\n"),
fsm->path, (unsigned)(st->st_mode & 07777));
- else
+ else {
rpmlog(RPMLOG_DEBUG,
D_("%s directory created with perms %04o, context
%s.\n"),
fsm->path, (unsigned)(st->st_mode & 07777),
fsm->fcontext);
- fsm->fcontext = NULL;
+ fsm->fcontext = NULL;
+ scon = _free(scon);
+ }
}
*te = '/';
}
@@ .
patch -p0 <<'@@ .'
Index: rpm/lib/librpm.vers
============================================================================
$ cvs diff -u -r1.52 -r1.53 librpm.vers
--- rpm/lib/librpm.vers 23 Sep 2008 19:01:08 -0000 1.52
+++ rpm/lib/librpm.vers 6 Oct 2008 19:05:32 -0000 1.53
@@ -364,7 +364,6 @@
rpmtsPRCO;
rpmtsProblems;
rpmtsRebuildDB;
- rpmtsREContext;
rpmtsRelocateElement;
rpmtsRootDir;
rpmtsRun;
@@ -379,7 +378,6 @@
rpmtsSetGoal;
rpmtsSetKeyring;
rpmtsSetNotifyCallback;
- rpmtsSetREContext;
rpmtsSetRelocateElement;
rpmtsSetRootDir;
rpmtsSetScriptFd;
@@ .
patch -p0 <<'@@ .'
Index: rpm/lib/rpminstall.c
============================================================================
$ cvs diff -u -r1.214 -r1.215 rpminstall.c
--- rpm/lib/rpminstall.c 4 Oct 2008 18:12:35 -0000 1.214
+++ rpm/lib/rpminstall.c 6 Oct 2008 19:05:32 -0000 1.215
@@ -512,16 +512,6 @@
if (rpmExpandNumeric("%{?_repackage_all_erasures}"))
ia->transFlags |= RPMTRANS_FLAG_REPACKAGE;
- /* Initialize security context patterns (if not already done). */
- if (rpmtsSELinuxEnabled(ts) && !(ia->transFlags &
RPMTRANS_FLAG_NOCONTEXTS))
- {
- const char *fn = rpmGetPath("%{?_install_file_context_path}", NULL);
-/[EMAIL PROTECTED]@*/
- if (fn != NULL && *fn != '\0')
- xx = matchpathcon_init(fn);
-/[EMAIL PROTECTED]@*/
- fn = _free(fn);
- }
(void) rpmtsSetFlags(ts, ia->transFlags);
(void) rpmtsSetDFlags(ts, ia->depFlags);
@@ .
patch -p0 <<'@@ .'
Index: rpm/lib/rpmts.c
============================================================================
$ cvs diff -u -r2.154 -r2.155 rpmts.c
--- rpm/lib/rpmts.c 2 Aug 2008 00:38:05 -0000 2.154
+++ rpm/lib/rpmts.c 6 Oct 2008 19:05:32 -0000 2.155
@@ -910,7 +910,10 @@
int rpmtsSELinuxEnabled(rpmts ts)
{
- return (ts != NULL ? (ts->selinuxEnabled > 0) : 0);
+ int selinuxEnabled = 0;
+ if (ts)
+ selinuxEnabled = (ts->selinuxEnabled > 0);
+ return selinuxEnabled;
}
int rpmtsChrootDone(rpmts ts)
@@ -930,23 +933,6 @@
return ochrootDone;
}
-rpmsx rpmtsREContext(rpmts ts)
-{
- return ( (ts && ts->sx ? rpmsxLink(ts->sx, __func__) : NULL) );
-}
-
-int rpmtsSetREContext(rpmts ts, rpmsx sx)
-{
- int rc = -1;
- if (ts != NULL) {
- ts->sx = rpmsxFree(ts->sx);
- ts->sx = rpmsxLink(sx, __func__);
- if (ts->sx != NULL)
- rc = 0;
- }
- return rc;
-}
-
rpmuint32_t rpmtsGetTid(rpmts ts)
{
rpmuint32_t tid = 0; /* XXX -1 is time(2) error return. */
@@ .
patch -p0 <<'@@ .'
Index: rpm/lib/rpmts.h
============================================================================
$ cvs diff -u -r2.106 -r2.107 rpmts.h
--- rpm/lib/rpmts.h 2 Aug 2008 17:56:47 -0000 2.106
+++ rpm/lib/rpmts.h 6 Oct 2008 19:05:32 -0000 2.107
@@ -765,24 +765,6 @@
/[EMAIL PROTECTED] ts @*/;
/** \ingroup rpmts
- * Get file security context patterns.
- * @param ts transaction set
- * @return file security context patterns
- */
-/[EMAIL PROTECTED]@*/
-rpmsx rpmtsREContext(const rpmts ts)
- /[EMAIL PROTECTED] ts @*/;
-
-/** \ingroup rpmts
- * Get file security context patterns.
- * @param ts transaction set
- * @param sx security context patterns
- * @return 0 on success
- */
-int rpmtsSetREContext(rpmts ts, rpmsx sx)
- /[EMAIL PROTECTED] ts, sx @*/;
-
-/** \ingroup rpmts
* Get transaction id, i.e. transaction time stamp.
* @param ts transaction set
* @return transaction id
@@ .
patch -p0 <<'@@ .'
Index: rpm/lib/transaction.c
============================================================================
$ cvs diff -u -r1.385 -r1.386 transaction.c
--- rpm/lib/transaction.c 23 Sep 2008 17:50:07 -0000 1.385
+++ rpm/lib/transaction.c 6 Oct 2008 19:05:32 -0000 1.386
@@ -1187,6 +1187,18 @@
if (rpmtsFlags(ts) & RPMTRANS_FLAG_JUSTDB)
(void) rpmtsSetFlags(ts, (rpmtsFlags(ts) | _noTransScripts |
_noTransTriggers));
+ /* if SELinux isn't enabled or init fails, don't bother... */
+ if (!rpmtsSELinuxEnabled(ts))
+ (void) rpmtsSetFlags(ts, (rpmtsFlags(ts) | RPMTRANS_FLAG_NOCONTEXTS));
+
+ if (!(rpmtsFlags(ts) & RPMTRANS_FLAG_NOCONTEXTS)) {
+ const char * fn = rpmGetPath("%{?_install_file_context_path}", NULL);
+ int xx = matchpathcon_init(fn);
+ if (xx == -1)
+ (void) rpmtsSetFlags(ts, (rpmtsFlags(ts) |
RPMTRANS_FLAG_NOCONTEXTS));
+ fn = _free(fn);
+ }
+
ts->probs = rpmpsFree(ts->probs);
ts->probs = rpmpsCreate();
@@ -1948,6 +1960,9 @@
pi = rpmtsiFree(pi);
}
+ if (!(rpmtsFlags(ts) & RPMTRANS_FLAG_NOCONTEXTS))
+ matchpathcon_fini();
+
lock = rpmtsFreeLock(lock);
/[EMAIL PROTECTED]@*/ /* FIX: ts->flList may be NULL */
@@ .
patch -p0 <<'@@ .'
Index: rpm/python/rpmts-py.c
============================================================================
$ cvs diff -u -r1.94 -r1.95 rpmts-py.c
--- rpm/python/rpmts-py.c 2 Oct 2008 14:45:22 -0000 1.94
+++ rpm/python/rpmts-py.c 6 Oct 2008 19:05:32 -0000 1.95
@@ -1260,16 +1260,6 @@
(void) rpmtsSetNotifyCallback(s->ts, rpmtsCallback, (void *) &cbInfo);
}
- /* Initialize security context patterns (if not already done). */
- if (rpmtsSELinuxEnabled(s->ts)
- && !(rpmtsFlags(s->ts) & RPMTRANS_FLAG_NOCONTEXTS))
- {
- const char *fn = rpmGetPath("%{?_install_file_context_path}", NULL);
- if (fn != NULL && *fn != '\0')
- rc = matchpathcon_init(fn);
- fn = _free(fn);
- }
-
if (_rpmts_debug)
fprintf(stderr, "*** rpmts_Run(%p) ts %p ignore %x\n", s, s->ts,
s->ignoreSet);
@@ .
patch -p0 <<'@@ .'
Index: rpm/rpmio/iosm.c
============================================================================
$ cvs diff -u -r1.26 -r1.27 iosm.c
--- rpm/rpmio/iosm.c 17 Sep 2008 20:09:17 -0000 1.26
+++ rpm/rpmio/iosm.c 6 Oct 2008 19:05:32 -0000 1.27
@@ -725,14 +725,7 @@
/[EMAIL PROTECTED]@*/
#if defined(_USE_RPMTS)
iosm->iter->ts = rpmtsLink(ts, "mapIterator");
- iosm->nofcontexts = (ts != NULL && rpmtsSELinuxEnabled(ts) == 1 &&
- !(rpmtsFlags(ts) & RPMTRANS_FLAG_NOCONTEXTS));
-#if defined(_USE_RPMSX)
- /* XXX Set file contexts on non-packaged dirs iff selinux enabled. */
- iosm->iter->sx = (!iosm->nofcontexts ? rpmtsREContext(ts) : NULL);
-#else
- iosm->iter->sx = NULL;
-#endif
+ iosm->nofcontexts = (rpmtsFlags(ts) & RPMTRANS_FLAG_NOCONTEXTS);
iosm->nofdigests =
(ts != NULL && !(rpmtsFlags(ts) & RPMTRANS_FLAG_NOFDIGESTS))
? 0 : 1;
@@ -744,7 +737,6 @@
/[EMAIL PROTECTED] -temptrans @*/
iosm->iter->ts = (void *)_ts;
/[EMAIL PROTECTED] =temptrans @*/
- iosm->iter->sx = NULL;
iosm->nofcontexts = 1;
iosm->nofdigests = 1;
iosm->commit = 1;
@@ -808,14 +800,10 @@
iosm->lmtab = _free(iosm->lmtab);
#if defined(_USE_RPMTS)
-#if defined(_USE_RPMSX)
- iosm->iter->sx = rpmsxFree(sx);
-#endif
(void) rpmswAdd(rpmtsOp(iosmGetTs(iosm), RPMTS_OP_DIGEST),
&iosm->op_digest);
iosm->iter->ts = rpmtsFree(iter->ts);
#else
- iosm->iter->sx = NULL;
iosm->iter->ts = NULL;
#endif
iosm->iter = mapFreeIterator(iosm->iter);
@@ -827,28 +815,36 @@
return rc;
}
+/*
+ * Set file security context (if not disabled).
+ * @param iosm file state machine data
+ * @return 0 always
+ */
static int iosmMapFContext(IOSM_t iosm)
/[EMAIL PROTECTED] iosm @*/
{
- rpmfi fi = iosmGetFi(iosm);
-
/*
* Find file security context (if not disabled).
*/
iosm->fcontext = NULL;
if (!iosm->nofcontexts) {
+ struct stat * st = &iosm->sb;
security_context_t scon = NULL;
+ int xx = matchpathcon(iosm->path, st->st_mode, &scon);
/[EMAIL PROTECTED]@*/
- if (matchpathcon(iosm->path, iosm->sb.st_mode, &scon) == 0 && scon !=
NULL)
+ if (!xx && scon != NULL)
iosm->fcontext = scon;
+#ifdef DYING /* XXX SELinux file contexts not set from package
content. */
else {
+ rpmfi fi = iosmGetFi(iosm);
int i = iosm->ix;
/* Get file security context from package. */
if (fi && i >= 0 && i < (int)fi->fc)
iosm->fcontext = (fi->fcontexts ? fi->fcontexts[i] : NULL);
}
+#endif
/[EMAIL PROTECTED]@*/
}
return 0;
@@ -1553,24 +1549,32 @@
rc = iosmNext(iosm, IOSM_MKDIR);
if (!rc) {
#if defined(_USE_RPMSX)
+ security_context_t scon = NULL;
/* XXX FIXME? only new dir will have context set. */
/* Get file security context from patterns. */
- if (iosm->iter->sx != NULL) {
- iosm->fcontext = rpmsxFContext(iosm->iter->sx,
- iosm->path, st->st_mode);
+ if (!fsm->nofcontexts
+ && !matchpathcon(iosm->path, st->st_mode, &scon)
+ && scon != NULL)
+ {
+ iosm->fcontext = scon;
rc = iosmNext(iosm, IOSM_LSETFCON);
- }
+ } else
#endif
+ iosm->fcontext = NULL;
if (iosm->fcontext == NULL)
rpmlog(RPMLOG_DEBUG,
D_("%s directory created with perms %04o, no
context.\n"),
iosm->path, (unsigned)(st->st_mode & 07777));
- else
+ else {
rpmlog(RPMLOG_DEBUG,
D_("%s directory created with perms %04o, context
%s.\n"),
iosm->path, (unsigned)(st->st_mode & 07777),
iosm->fcontext);
- iosm->fcontext = NULL;
+#if defined(_USE_RPMSX)
+ iosm->fcontext = NULL;
+ scon = _free(scon);
+#endif
+ }
}
*te = '/';
}
@@ .
patch -p0 <<'@@ .'
Index: rpm/rpmio/iosm.h
============================================================================
$ cvs diff -u -r1.14 -r1.15 iosm.h
--- rpm/rpmio/iosm.h 31 Jul 2008 02:40:10 -0000 1.14
+++ rpm/rpmio/iosm.h 6 Oct 2008 19:05:32 -0000 1.15
@@ -189,7 +189,6 @@
struct iosmIterator_s {
void * ts; /*!< transaction set. */
void * fi; /*!< transaction element file info. */
- void * sx; /*!< SELinux file context container. */
int reverse; /*!< reversed traversal? */
int isave; /*!< last returned iterator index. */
int i; /*!< iterator index. */
@@ .
______________________________________________________________________
RPM Package Manager http://rpm5.org
CVS Sources Repository [email protected]