mirror of
https://github.com/systemd/systemd.git
synced 2026-08-05 07:30:30 +00:00
resolved: apply label to /run/systemd/resolve/resolv.conf
Under an SELinux system, we want the file that is created to have a proper context, different from the default for files in /run. This is so that the policy can give access to almost everyone to this file.
This commit is contained in:
@@ -34,6 +34,7 @@
|
||||
#include "socket-util.h"
|
||||
#include "af-list.h"
|
||||
#include "utf8.h"
|
||||
#include "fileio-label.h"
|
||||
|
||||
#include "resolved-dns-domain.h"
|
||||
#include "resolved-conf.h"
|
||||
@@ -821,7 +822,7 @@ int manager_write_resolv_conf(Manager *m) {
|
||||
}
|
||||
}
|
||||
|
||||
r = fopen_temporary(path, &f, &temp_path);
|
||||
r = fopen_temporary_label(path, path, &f, &temp_path);
|
||||
if (r < 0)
|
||||
return r;
|
||||
|
||||
|
||||
@@ -38,14 +38,20 @@ int main(int argc, char *argv[]) {
|
||||
log_parse_environment();
|
||||
log_open();
|
||||
|
||||
umask(0022);
|
||||
|
||||
if (argc != 1) {
|
||||
log_error("This program takes no arguments.");
|
||||
r = -EINVAL;
|
||||
goto finish;
|
||||
}
|
||||
|
||||
umask(0022);
|
||||
|
||||
r = label_init(NULL);
|
||||
if (r < 0) {
|
||||
log_error("SELinux setup failed: %s", strerror(-r));
|
||||
goto finish;
|
||||
}
|
||||
|
||||
r = get_user_creds(&user, &uid, &gid, NULL, NULL);
|
||||
if (r < 0) {
|
||||
log_error("Cannot resolve user name %s: %s", user, strerror(-r));
|
||||
|
||||
Reference in New Issue
Block a user