]> granicus.if.org Git - strace/commitdiff
netlink: decode NETLINK_SELINUX protocol
authorJingPiao Chen <chenjingpiao@gmail.com>
Fri, 14 Jul 2017 05:16:36 +0000 (13:16 +0800)
committerDmitry V. Levin <ldv@altlinux.org>
Sun, 16 Jul 2017 18:26:10 +0000 (18:26 +0000)
* netlink_selinux.c: New file.
* Makefile.am (strace_SOURCES): Add it.
* defs.h (decode_netlink_selinux): New prototype.
* netlink.c (netlink_decoders): Add NETLINK_SELINUX.

Makefile.am
defs.h
netlink.c
netlink_selinux.c [new file with mode: 0644]

index 2517c0d467f97bcbb0f1179c8e0049c82ca2a32e..03f262452e27f925fe9c13a29c2c5924d717afcc 100644 (file)
@@ -183,6 +183,7 @@ strace_SOURCES =    \
        net.c           \
        netlink.c       \
        netlink.h       \
+       netlink_selinux.c \
        netlink_sock_diag.c \
        nlattr.c        \
        nlattr.h        \
diff --git a/defs.h b/defs.h
index 5b378a946316975de01bc99986a4f1dcc75d040f..bc9a3e01130a6b1703080a60c2e5586c2bb311f0 100644 (file)
--- a/defs.h
+++ b/defs.h
@@ -709,6 +709,7 @@ typedef bool (*netlink_decoder_t)(struct tcb *, const struct nlmsghdr *,
 extern bool                                                            \
 decode_netlink_ ## name(struct tcb *, const struct nlmsghdr *,         \
                        kernel_ulong_t addr, kernel_ulong_t len)
+DECL_NETLINK(selinux);
 DECL_NETLINK(sock_diag);
 
 extern int tv_nz(const struct timeval *);
index 0ae9a46b7f109763974c38f141760d34fab11f29..e054ae30e2a3e32fce26324ce81a4f4535d530d3 100644 (file)
--- a/netlink.c
+++ b/netlink.c
@@ -327,6 +327,7 @@ decode_nlmsgerr(struct tcb *const tcp,
 }
 
 static const netlink_decoder_t netlink_decoders[] = {
+       [NETLINK_SELINUX] = decode_netlink_selinux,
        [NETLINK_SOCK_DIAG] = decode_netlink_sock_diag
 };
 
diff --git a/netlink_selinux.c b/netlink_selinux.c
new file mode 100644 (file)
index 0000000..43885ff
--- /dev/null
@@ -0,0 +1,69 @@
+/*
+ * Copyright (c) 2017 JingPiao Chen <chenjingpiao@gmail.com>
+ * Copyright (c) 2017 The strace developers.
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ *    notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ *    notice, this list of conditions and the following disclaimer in the
+ *    documentation and/or other materials provided with the distribution.
+ * 3. The name of the author may not be used to endorse or promote products
+ *    derived from this software without specific prior written permission.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
+ * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
+ * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
+ * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
+ * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
+ * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
+ * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
+ * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
+ * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#include "defs.h"
+#include "netlink.h"
+#include "print_fields.h"
+
+#include <linux/selinux_netlink.h>
+
+bool
+decode_netlink_selinux(struct tcb *const tcp,
+                      const struct nlmsghdr *const nlmsghdr,
+                      const kernel_ulong_t addr,
+                      const kernel_ulong_t len)
+{
+       switch (nlmsghdr->nlmsg_type) {
+       case SELNL_MSG_SETENFORCE: {
+               struct selnl_msg_setenforce msg;
+
+               if (len < sizeof(msg))
+                       printstr_ex(tcp, addr, len, QUOTE_FORCE_HEX);
+               else if (!umove_or_printaddr(tcp, addr, &msg)) {
+                       PRINT_FIELD_D("{", msg, val);
+                       tprints("}");
+               }
+               break;
+       }
+       case SELNL_MSG_POLICYLOAD: {
+               struct selnl_msg_policyload msg;
+
+               if (len < sizeof(msg))
+                       printstr_ex(tcp, addr, len, QUOTE_FORCE_HEX);
+               else if (!umove_or_printaddr(tcp, addr, &msg)) {
+                       PRINT_FIELD_U("{", msg, seqno);
+                       tprints("}");
+               }
+               break;
+       }
+       default:
+               return false;
+       }
+
+       return true;
+}