* [PATCH] policycoreutils: Using vendor defined directories for configuration files
@ 2026-07-21 7:35 Johannes Segitz
2026-07-21 13:54 ` Stephen Smalley
0 siblings, 1 reply; 2+ messages in thread
From: Johannes Segitz @ 2026-07-21 7:35 UTC (permalink / raw)
To: selinux
[-- Attachment #1: Type: text/plain, Size: 4284 bytes --]
Besides user/admin defined configuration files. Useful for systems
that have config files in /usr/etc
Signed-off-by: Stefan Schubert <schubi@suse.de>
---
policycoreutils/sestatus/Makefile | 8 +++
policycoreutils/sestatus/sestatus.c | 78 +++++++++++++++++++++++-
policycoreutils/sestatus/sestatus.conf.5 | 2 +-
3 files changed, 84 insertions(+), 4 deletions(-)
diff --git a/policycoreutils/sestatus/Makefile b/policycoreutils/sestatus/Makefile
index 3dbb792b..935fd6dc 100644
--- a/policycoreutils/sestatus/Makefile
+++ b/policycoreutils/sestatus/Makefile
@@ -5,6 +5,7 @@ BINDIR ?= $(PREFIX)/bin
SBINDIR ?= $(PREFIX)/sbin
MANDIR = $(PREFIX)/share/man
ETCDIR ?= /etc
+LIBECONFH ?= $(shell test -f /usr/include/libeconf.h && echo y)
CFLAGS ?= -Werror -Wall -W
override CFLAGS += -D_FILE_OFFSET_BITS=64
@@ -13,6 +14,13 @@ override LDLIBS += -lselinux
all: sestatus
sestatus: sestatus.o
+ifdef VENDORDIR
+ifneq ($(LIBECONFH), y)
+ (echo "VENDORDIR defined but libeconf not available."; exit 1)
+endif
+override CFLAGS += -DVENDORDIR='"${VENDORDIR}"'
+override LDLIBS += -leconf
+endif
install: all
[ -d $(DESTDIR)$(MANDIR)/man8 ] || mkdir -p $(DESTDIR)$(MANDIR)/man8
diff --git a/policycoreutils/sestatus/sestatus.c b/policycoreutils/sestatus/sestatus.c
index 6c95828e..a0b9b0f1 100644
--- a/policycoreutils/sestatus/sestatus.c
+++ b/policycoreutils/sestatus/sestatus.c
@@ -21,11 +21,16 @@
#define PROC_BASE "/proc"
#define MAX_CHECK 50
-#define CONF "/etc/sestatus.conf"
+#define CONFDIR "/etc"
+#define CONFNAME "sestatus"
+#define CONFPOST "conf"
+#define CONF CONFDIR "/" CONFNAME "." CONFPOST
/* conf file sections */
-#define PROCS "[process]"
-#define FILES "[files]"
+#define SECTIONPROCS "process"
+#define SECTIONFILES "files"
+#define PROCS "[" SECTIONPROCS "]"
+#define FILES "[" SECTIONFILES "]"
/* buffer size for cmp_cmdline */
#define BUFSIZE 255
@@ -92,9 +97,76 @@ static int pidof(const char *command)
return ret;
}
+#ifdef VENDORDIR
+#include <libeconf.h>
+
+static void load_checks_with_vendor_settings(char *pc[], int *npc, char *fc[], int *nfc)
+{
+ econf_file *key_file = NULL;
+ econf_err error;
+ char **keys;
+ size_t key_number;
+
+ error = econf_readDirs (&key_file,
+ VENDORDIR,
+ CONFDIR,
+ CONFNAME,
+ CONFPOST,
+ "", "#");
+ if (error != ECONF_SUCCESS) {
+ printf("\nCannot read settings %s.%s: %s\n",
+ CONFNAME,
+ CONFPOST,
+ econf_errString( error ));
+ return;
+ }
+
+ error = econf_getKeys(key_file, SECTIONPROCS, &key_number, &keys);
+ if (error != ECONF_SUCCESS) {
+ printf("\nCannot read group %s: %s\n",
+ SECTIONPROCS,
+ econf_errString( error ));
+ } else {
+ for (size_t i = 0; i < key_number; i++) {
+ if (*npc >= MAX_CHECK)
+ break;
+ pc[*npc] = strdup(keys[i]);
+ if (!pc[*npc])
+ break;
+ (*npc)++;
+ }
+ econf_free (keys);
+ }
+
+ error = econf_getKeys(key_file, SECTIONFILES, &key_number, &keys);
+ if (error != ECONF_SUCCESS) {
+ printf("\nCannot read group %s: %s\n",
+ SECTIONFILES,
+ econf_errString( error ));
+ } else {
+ for (size_t i = 0; i < key_number; i++) {
+ if (*nfc >= MAX_CHECK)
+ break;
+ fc[*nfc] = strdup(keys[i]);
+ if (!fc[*nfc])
+ break;
+ (*nfc)++;
+ }
+ econf_free (keys);
+ }
+
+ econf_free (key_file);
+ return;
+}
+#endif
+
static void load_checks(char *pc[], int *npc, char *fc[], int *nfc)
{
+#ifdef VENDORDIR
+ load_checks_with_vendor_settings(pc, npc, fc, nfc);
+ return;
+#endif
FILE *fp = fopen(CONF, "r");
char buf[255], *bufp;
int buf_len, section = -1;
diff --git a/policycoreutils/sestatus/sestatus.conf.5 b/policycoreutils/sestatus/sestatus.conf.5
index acfedf6f..01f8051d 100644
--- a/policycoreutils/sestatus/sestatus.conf.5
+++ b/policycoreutils/sestatus/sestatus.conf.5
@@ -8,7 +8,7 @@ The \fIsestatus.conf\fR file is used by the \fBsestatus\fR(8) command with the \
.sp
The fully qualified path name of the configuration file is:
.RS
-\fI/etc/sestatus.conf\fR
+\fI/etc/sestatus.conf\fR or \fI<vendordir>/sestatus.conf\fR if it is not available
.RE
.RE
.sp
--
2.55.0
[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 870 bytes --]
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] policycoreutils: Using vendor defined directories for configuration files
2026-07-21 7:35 [PATCH] policycoreutils: Using vendor defined directories for configuration files Johannes Segitz
@ 2026-07-21 13:54 ` Stephen Smalley
0 siblings, 0 replies; 2+ messages in thread
From: Stephen Smalley @ 2026-07-21 13:54 UTC (permalink / raw)
To: Johannes Segitz; +Cc: selinux
On Tue, Jul 21, 2026 at 3:41 AM Johannes Segitz <jsegitz@suse.de> wrote:
>
> Besides user/admin defined configuration files. Useful for systems
> that have config files in /usr/etc
>
> Signed-off-by: Stefan Schubert <schubi@suse.de>
This doesn't apply on selinux/main.
> ---
> policycoreutils/sestatus/Makefile | 8 +++
> policycoreutils/sestatus/sestatus.c | 78 +++++++++++++++++++++++-
> policycoreutils/sestatus/sestatus.conf.5 | 2 +-
> 3 files changed, 84 insertions(+), 4 deletions(-)
>
> diff --git a/policycoreutils/sestatus/Makefile b/policycoreutils/sestatus/Makefile
> index 3dbb792b..935fd6dc 100644
> --- a/policycoreutils/sestatus/Makefile
> +++ b/policycoreutils/sestatus/Makefile
> @@ -5,6 +5,7 @@ BINDIR ?= $(PREFIX)/bin
> SBINDIR ?= $(PREFIX)/sbin
> MANDIR = $(PREFIX)/share/man
> ETCDIR ?= /etc
> +LIBECONFH ?= $(shell test -f /usr/include/libeconf.h && echo y)
>
> CFLAGS ?= -Werror -Wall -W
> override CFLAGS += -D_FILE_OFFSET_BITS=64
> @@ -13,6 +14,13 @@ override LDLIBS += -lselinux
> all: sestatus
>
> sestatus: sestatus.o
> +ifdef VENDORDIR
> +ifneq ($(LIBECONFH), y)
> + (echo "VENDORDIR defined but libeconf not available."; exit 1)
> +endif
> +override CFLAGS += -DVENDORDIR='"${VENDORDIR}"'
> +override LDLIBS += -leconf
> +endif
>
> install: all
> [ -d $(DESTDIR)$(MANDIR)/man8 ] || mkdir -p $(DESTDIR)$(MANDIR)/man8
> diff --git a/policycoreutils/sestatus/sestatus.c b/policycoreutils/sestatus/sestatus.c
> index 6c95828e..a0b9b0f1 100644
> --- a/policycoreutils/sestatus/sestatus.c
> +++ b/policycoreutils/sestatus/sestatus.c
> @@ -21,11 +21,16 @@
>
> #define PROC_BASE "/proc"
> #define MAX_CHECK 50
> -#define CONF "/etc/sestatus.conf"
> +#define CONFDIR "/etc"
> +#define CONFNAME "sestatus"
> +#define CONFPOST "conf"
> +#define CONF CONFDIR "/" CONFNAME "." CONFPOST
>
> /* conf file sections */
> -#define PROCS "[process]"
> -#define FILES "[files]"
> +#define SECTIONPROCS "process"
> +#define SECTIONFILES "files"
> +#define PROCS "[" SECTIONPROCS "]"
> +#define FILES "[" SECTIONFILES "]"
>
> /* buffer size for cmp_cmdline */
> #define BUFSIZE 255
> @@ -92,9 +97,76 @@ static int pidof(const char *command)
> return ret;
> }
>
> +#ifdef VENDORDIR
> +#include <libeconf.h>
> +
> +static void load_checks_with_vendor_settings(char *pc[], int *npc, char *fc[], int *nfc)
> +{
> + econf_file *key_file = NULL;
> + econf_err error;
> + char **keys;
> + size_t key_number;
> +
> + error = econf_readDirs (&key_file,
> + VENDORDIR,
> + CONFDIR,
> + CONFNAME,
> + CONFPOST,
> + "", "#");
> + if (error != ECONF_SUCCESS) {
> + printf("\nCannot read settings %s.%s: %s\n",
> + CONFNAME,
> + CONFPOST,
> + econf_errString( error ));
> + return;
> + }
> +
> + error = econf_getKeys(key_file, SECTIONPROCS, &key_number, &keys);
> + if (error != ECONF_SUCCESS) {
> + printf("\nCannot read group %s: %s\n",
> + SECTIONPROCS,
> + econf_errString( error ));
> + } else {
> + for (size_t i = 0; i < key_number; i++) {
> + if (*npc >= MAX_CHECK)
> + break;
> + pc[*npc] = strdup(keys[i]);
> + if (!pc[*npc])
> + break;
> + (*npc)++;
> + }
> + econf_free (keys);
> + }
> +
> + error = econf_getKeys(key_file, SECTIONFILES, &key_number, &keys);
> + if (error != ECONF_SUCCESS) {
> + printf("\nCannot read group %s: %s\n",
> + SECTIONFILES,
> + econf_errString( error ));
> + } else {
> + for (size_t i = 0; i < key_number; i++) {
> + if (*nfc >= MAX_CHECK)
> + break;
> + fc[*nfc] = strdup(keys[i]);
> + if (!fc[*nfc])
> + break;
> + (*nfc)++;
> + }
> + econf_free (keys);
> + }
> +
> + econf_free (key_file);
> + return;
> +}
> +#endif
> +
> static void load_checks(char *pc[], int *npc, char *fc[], int *nfc)
> {
>
> +#ifdef VENDORDIR
> + load_checks_with_vendor_settings(pc, npc, fc, nfc);
> + return;
> +#endif
> FILE *fp = fopen(CONF, "r");
> char buf[255], *bufp;
> int buf_len, section = -1;
> diff --git a/policycoreutils/sestatus/sestatus.conf.5 b/policycoreutils/sestatus/sestatus.conf.5
> index acfedf6f..01f8051d 100644
> --- a/policycoreutils/sestatus/sestatus.conf.5
> +++ b/policycoreutils/sestatus/sestatus.conf.5
> @@ -8,7 +8,7 @@ The \fIsestatus.conf\fR file is used by the \fBsestatus\fR(8) command with the \
> .sp
> The fully qualified path name of the configuration file is:
> .RS
> -\fI/etc/sestatus.conf\fR
> +\fI/etc/sestatus.conf\fR or \fI<vendordir>/sestatus.conf\fR if it is not available
> .RE
> .RE
> .sp
> --
> 2.55.0
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-07-21 13:55 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-21 7:35 [PATCH] policycoreutils: Using vendor defined directories for configuration files Johannes Segitz
2026-07-21 13:54 ` Stephen Smalley
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.