Re: [PATCH] policycoreutils: Using vendor defined directories for configuration files
Stephen Smalley <[email protected]> Wed, 29 Jul 2026 16:20:35 -0400
| Newsgroups | org.kernel.vger.selinux |
|---|---|
| Message-ID | <CAEjxPJ5+v8=WxxhstnQ+DZLcCUpzz-MgWPjKj8mY2RUrO_VSuA@mail.gmail.com> |
On Wed, Jul 29, 2026 at 10:06 AM Stephen Smalley <[email protected]> wrote: > > On Tue, Jul 28, 2026 at 5:27 AM Johannes Segitz <[email protected]> wrote: > > > > Besides user/admin defined configuration files. Useful for systems > > that have config files in /usr/etc > > > > Signed-off-by: Stefan Schubert <[email protected]> > > Will reformat on merge. > > Acked-by: Stephen Smalley <[email protected]> Merged. > > > --- > > policycoreutils/sestatus/Makefile | 8 +++ > > policycoreutils/sestatus/sestatus.c | 78 +++++++++++++++++++++++- > > policycoreutils/sestatus/sestatus.conf.5 | 2 +- > > 3 files changed, 84 insertions(+), 4 deletions(-) > > > > diff --git a/policycoreutils/sestatus/Makefile b/policycoreutils/sestatus/Makefile > > index 70f46956..6f8db774 100644 > > --- a/policycoreutils/sestatus/Makefile > > +++ b/policycoreutils/sestatus/Makefile > > @@ -5,6 +5,7 @@ BINDIR ?= $(PREFIX)/bin > > SBINDIR ?= $(PREFIX)/sbin > > MANDIR = $(PREFIX)/share/man > > ETCDIR ?= /etc > > +LIBECONFH ?= $(shell test -f /usr/include/libeconf.h && echo y) > > > > CFLAGS ?= -Werror -Wall -W > > override CFLAGS += -I../../libselinux/include -D_FILE_OFFSET_BITS=64 > > @@ -14,6 +15,13 @@ override LDLIBS += $(LIBSELINUX_LDLIBS) > > all: sestatus > > > > sestatus: sestatus.o > > +ifdef VENDORDIR > > +ifneq ($(LIBECONFH), y) > > + (echo "VENDORDIR defined but libeconf not available."; exit 1) > > +endif > > +override CFLAGS += -DVENDORDIR='"${VENDORDIR}"' > > +override LDLIBS += -leconf > > +endif > > > > install: all > > [ -d $(DESTDIR)$(MANDIR)/man8 ] || mkdir -p $(DESTDIR)$(MANDIR)/man8 > > diff --git a/policycoreutils/sestatus/sestatus.c b/policycoreutils/sestatus/sestatus.c > > index a719f0b3..528a81ae 100644 > > --- a/policycoreutils/sestatus/sestatus.c > > +++ b/policycoreutils/sestatus/sestatus.c > > @@ -21,11 +21,16 @@ > > > > #define PROC_BASE "/proc" > > #define MAX_CHECK 50 > > -#define CONF "/etc/sestatus.conf" > > +#define CONFDIR "/etc" > > +#define CONFNAME "sestatus" > > +#define CONFPOST "conf" > > +#define CONF CONFDIR "/" CONFNAME "." CONFPOST > > > > /* conf file sections */ > > -#define PROCS "[process]" > > -#define FILES "[files]" > > +#define SECTIONPROCS "process" > > +#define SECTIONFILES "files" > > +#define PROCS "[" SECTIONPROCS "]" > > +#define FILES "[" SECTIONFILES "]" > > > > /* buffer size for cmp_cmdline */ > > #define BUFSIZE 255 > > @@ -91,8 +96,75 @@ static int pidof(const char *command) > > return ret; > > } > > > > +#ifdef VENDORDIR > > +#include <libeconf.h> > > + > > +static void load_checks_with_vendor_settings(char *pc[], int *npc, char *fc[], int *nfc) > > +{ > > + econf_file *key_file = NULL; > > + econf_err error; > > + char **keys; > > + size_t key_number; > > + > > + error = econf_readDirs (&key_file, > > + VENDORDIR, > > + CONFDIR, > > + CONFNAME, > > + CONFPOST, > > + "", "#"); > > + if (error != ECONF_SUCCESS) { > > + printf("\nCannot read settings %s.%s: %s\n", > > + CONFNAME, > > + CONFPOST, > > + econf_errString( error )); > > + return; > > + } > > + > > + error = econf_getKeys(key_file, SECTIONPROCS, &key_number, &keys); > > + if (error != ECONF_SUCCESS) { > > + printf("\nCannot read group %s: %s\n", > > + SECTIONPROCS, > > + econf_errString( error )); > > + } else { > > + for (size_t i = 0; i < key_number; i++) { > > + if (*npc >= MAX_CHECK) > > + break; > > + pc[*npc] = strdup(keys[i]); > > + if (!pc[*npc]) > > + break; > > + (*npc)++; > > + } > > + econf_free (keys); > > + } > > + > > + error = econf_getKeys(key_file, SECTIONFILES, &key_number, &keys); > > + if (error != ECONF_SUCCESS) { > > + printf("\nCannot read group %s: %s\n", > > + SECTIONFILES, > > + econf_errString( error )); > > + } else { > > + for (size_t i = 0; i < key_number; i++) { > > + if (*nfc >= MAX_CHECK) > > + break; > > + fc[*nfc] = strdup(keys[i]); > > + if (!fc[*nfc]) > > + break; > > + (*nfc)++; > > + } > > + econf_free (keys); > > + } > > + > > + econf_free (key_file); > > + return; > > +} > > +#endif > > + > > static void load_checks(char *pc[], int *npc, char *fc[], int *nfc) > > { > > +#ifdef VENDORDIR > > + load_checks_with_vendor_settings(pc, npc, fc, nfc); > > + return; > > +#endif > > FILE *fp = fopen(CONF, "r"); > > char buf[255], *bufp; > > int buf_len, section = -1; > > diff --git a/policycoreutils/sestatus/sestatus.conf.5 b/policycoreutils/sestatus/sestatus.conf.5 > > index acfedf6f..01f8051d 100644 > > --- a/policycoreutils/sestatus/sestatus.conf.5 > > +++ b/policycoreutils/sestatus/sestatus.conf.5 > > @@ -8,7 +8,7 @@ The \fIsestatus.conf\fR file is used by the \fBsestatus\fR(8) command with the \ > > .sp > > The fully qualified path name of the configuration file is: > > .RS > > -\fI/etc/sestatus.conf\fR > > +\fI/etc/sestatus.conf\fR or \fI<vendordir>/sestatus.conf\fR if it is not available > > .RE > > .RE > > .sp > > -- > > 2.55.0 > > > >