Re: [PATCH] policycoreutils: Using vendor defined directories for configuration files

Stephen Smalley <[email protected]> Wed, 29 Jul 2026 16:20:35 -0400
Newsgroups org.kernel.vger.selinux
Message-ID <CAEjxPJ5+v8=WxxhstnQ+DZLcCUpzz-MgWPjKj8mY2RUrO_VSuA@mail.gmail.com>
On Wed, Jul 29, 2026 at 10:06 AM Stephen Smalley
<[email protected]> wrote:
>
> On Tue, Jul 28, 2026 at 5:27 AM Johannes Segitz <[email protected]> wrote:
> >
> > Besides user/admin defined configuration files. Useful for systems
> > that have config files in /usr/etc
> >
> > Signed-off-by: Stefan Schubert <[email protected]>
>
> Will reformat on merge.
>
> Acked-by: Stephen Smalley <[email protected]>

Merged.

>
> > ---
> >  policycoreutils/sestatus/Makefile        |  8 +++
> >  policycoreutils/sestatus/sestatus.c      | 78 +++++++++++++++++++++++-
> >  policycoreutils/sestatus/sestatus.conf.5 |  2 +-
> >  3 files changed, 84 insertions(+), 4 deletions(-)
> >
> > diff --git a/policycoreutils/sestatus/Makefile b/policycoreutils/sestatus/Makefile
> > index 70f46956..6f8db774 100644
> > --- a/policycoreutils/sestatus/Makefile
> > +++ b/policycoreutils/sestatus/Makefile
> > @@ -5,6 +5,7 @@ BINDIR ?= $(PREFIX)/bin
> >  SBINDIR ?= $(PREFIX)/sbin
> >  MANDIR = $(PREFIX)/share/man
> >  ETCDIR ?= /etc
> > +LIBECONFH ?= $(shell test -f /usr/include/libeconf.h && echo y)
> >
> >  CFLAGS ?= -Werror -Wall -W
> >  override CFLAGS += -I../../libselinux/include -D_FILE_OFFSET_BITS=64
> > @@ -14,6 +15,13 @@ override LDLIBS += $(LIBSELINUX_LDLIBS)
> >  all: sestatus
> >
> >  sestatus: sestatus.o
> > +ifdef VENDORDIR
> > +ifneq ($(LIBECONFH), y)
> > +       (echo "VENDORDIR defined but libeconf not available."; exit 1)
> > +endif
> > +override CFLAGS += -DVENDORDIR='"${VENDORDIR}"'
> > +override LDLIBS += -leconf
> > +endif
> >
> >  install: all
> >         [ -d $(DESTDIR)$(MANDIR)/man8 ] || mkdir -p $(DESTDIR)$(MANDIR)/man8
> > diff --git a/policycoreutils/sestatus/sestatus.c b/policycoreutils/sestatus/sestatus.c
> > index a719f0b3..528a81ae 100644
> > --- a/policycoreutils/sestatus/sestatus.c
> > +++ b/policycoreutils/sestatus/sestatus.c
> > @@ -21,11 +21,16 @@
> >
> >  #define PROC_BASE "/proc"
> >  #define MAX_CHECK 50
> > -#define CONF "/etc/sestatus.conf"
> > +#define CONFDIR "/etc"
> > +#define CONFNAME "sestatus"
> > +#define CONFPOST "conf"
> > +#define CONF CONFDIR "/" CONFNAME "." CONFPOST
> >
> >  /* conf file sections */
> > -#define PROCS "[process]"
> > -#define FILES "[files]"
> > +#define SECTIONPROCS "process"
> > +#define SECTIONFILES "files"
> > +#define PROCS "[" SECTIONPROCS "]"
> > +#define FILES "[" SECTIONFILES "]"
> >
> >  /* buffer size for cmp_cmdline */
> >  #define BUFSIZE 255
> > @@ -91,8 +96,75 @@ static int pidof(const char *command)
> >         return ret;
> >  }
> >
> > +#ifdef VENDORDIR
> > +#include <libeconf.h>
> > +
> > +static void load_checks_with_vendor_settings(char *pc[], int *npc, char *fc[], int *nfc)
> > +{
> > +       econf_file *key_file = NULL;
> > +       econf_err error;
> > +       char **keys;
> > +       size_t key_number;
> > +
> > +       error = econf_readDirs (&key_file,
> > +                               VENDORDIR,
> > +                               CONFDIR,
> > +                               CONFNAME,
> > +                               CONFPOST,
> > +                               "", "#");
> > +       if (error != ECONF_SUCCESS) {
> > +               printf("\nCannot read settings %s.%s: %s\n",
> > +                      CONFNAME,
> > +                      CONFPOST,
> > +                      econf_errString( error ));
> > +               return;
> > +       }
> > +
> > +       error = econf_getKeys(key_file, SECTIONPROCS, &key_number, &keys);
> > +       if (error != ECONF_SUCCESS) {
> > +               printf("\nCannot read group %s: %s\n",
> > +                      SECTIONPROCS,
> > +                      econf_errString( error ));
> > +       } else {
> > +               for (size_t i = 0; i < key_number; i++) {
> > +                       if (*npc >= MAX_CHECK)
> > +                               break;
> > +                       pc[*npc] = strdup(keys[i]);
> > +                       if (!pc[*npc])
> > +                               break;
> > +                       (*npc)++;
> > +               }
> > +               econf_free (keys);
> > +       }
> > +
> > +       error = econf_getKeys(key_file, SECTIONFILES, &key_number, &keys);
> > +       if (error != ECONF_SUCCESS) {
> > +               printf("\nCannot read group %s: %s\n",
> > +                      SECTIONFILES,
> > +                      econf_errString( error ));
> > +       } else {
> > +               for (size_t i = 0; i < key_number; i++) {
> > +                       if (*nfc >= MAX_CHECK)
> > +                               break;
> > +                       fc[*nfc] = strdup(keys[i]);
> > +                       if (!fc[*nfc])
> > +                               break;
> > +                       (*nfc)++;
> > +               }
> > +               econf_free (keys);
> > +       }
> > +
> > +       econf_free (key_file);
> > +       return;
> > +}
> > +#endif
> > +
> >  static void load_checks(char *pc[], int *npc, char *fc[], int *nfc)
> >  {
> > +#ifdef VENDORDIR
> > +       load_checks_with_vendor_settings(pc, npc, fc, nfc);
> > +       return;
> > +#endif
> >         FILE *fp = fopen(CONF, "r");
> >         char buf[255], *bufp;
> >         int buf_len, section = -1;
> > diff --git a/policycoreutils/sestatus/sestatus.conf.5 b/policycoreutils/sestatus/sestatus.conf.5
> > index acfedf6f..01f8051d 100644
> > --- a/policycoreutils/sestatus/sestatus.conf.5
> > +++ b/policycoreutils/sestatus/sestatus.conf.5
> > @@ -8,7 +8,7 @@ The \fIsestatus.conf\fR file is used by the \fBsestatus\fR(8) command with the \
> >  .sp
> >  The fully qualified path name of the configuration file is:
> >  .RS
> > -\fI/etc/sestatus.conf\fR
> > +\fI/etc/sestatus.conf\fR or \fI<vendordir>/sestatus.conf\fR if it is not available
> >  .RE
> >  .RE
> >  .sp
> > --
> > 2.55.0
> >
> >