core: respect SELinuxContext= for socket creation

On socket creation respect the SELinuxContext= setting of the associated
service, such that the initial created socket has the same label as the
future process accepting the connection (since w.r.t SELinux sockets
normally have the same label as the owning process).

Triggered by #24702
This commit is contained in:
Christian Göttsche
2022-09-23 19:00:22 +02:00
committed by Yu Watanabe
parent 3b51a183af
commit 599b384924

View File

@@ -1421,6 +1421,7 @@ static int socket_determine_selinux_label(Socket *s, char **ret) {
Unit *service;
ExecCommand *c;
const char *exec_context;
_cleanup_free_ char *path = NULL;
r = socket_load_service_unit(s, -1, &service);
@@ -1429,6 +1430,18 @@ static int socket_determine_selinux_label(Socket *s, char **ret) {
if (r < 0)
return r;
exec_context = SERVICE(service)->exec_context.selinux_context;
if (exec_context) {
char *con;
con = strdup(exec_context);
if (!con)
return -ENOMEM;
*ret = TAKE_PTR(con);
return 0;
}
c = SERVICE(service)->exec_command[SERVICE_EXEC_START];
if (!c)
goto no_label;