diff --git a/.cvsignore b/.gitignore similarity index 100% rename from .cvsignore rename to .gitignore diff --git a/Makefile b/Makefile deleted file mode 100644 index f67602e..0000000 --- a/Makefile +++ /dev/null @@ -1,21 +0,0 @@ -# Makefile for source rpm: netlabel_tools -# $Id$ -NAME := netlabel_tools -SPECFILE = $(firstword $(wildcard *.spec)) - -define find-makefile-common -for d in common ../common ../../common ; do if [ -f $$d/Makefile.common ] ; then if [ -f $$d/CVS/Root -a -w $$/Makefile.common ] ; then cd $$d ; cvs -Q update ; fi ; echo "$$d/Makefile.common" ; break ; fi ; done -endef - -MAKEFILE_COMMON := $(shell $(find-makefile-common)) - -ifeq ($(MAKEFILE_COMMON),) -# attept a checkout -define checkout-makefile-common -test -f CVS/Root && { cvs -Q -d $$(cat CVS/Root) checkout common && echo "common/Makefile.common" ; } || { echo "ERROR: I can't figure out how to checkout the 'common' module." ; exit -1 ; } >&2 -endef - -MAKEFILE_COMMON := $(shell $(checkout-makefile-common)) -endif - -include $(MAKEFILE_COMMON) diff --git a/netlabel.rules b/netlabel.rules index 34b0880..4c24972 100644 --- a/netlabel.rules +++ b/netlabel.rules @@ -1,9 +1,59 @@ -# This file contains the rules for the Netlabel subsystem +# This file contains the rules for the Netlabel subsystem, for more information +# please see the netlabelctl(1) man page. +# # Each line contains just the arguments to the netlabel command -# creates a CIPSO/IPv4 definition using a DOI value of 1 -cipsov4 add std doi:1 tags:1 levels:0=0,1=1,2=2 categories:0=0,1=1,2=2 +#### +# NOTE: By default the kernel sends unlabeled traffic and allows unlabled +# traffic into the system, to disable that add the following two lines to +# the beginning of your configuration. However, be warned that you +# should only change these settings if you know what you are doing as you +# could accidently disable networking with a bad configuration. +# -# tell the NetLabel system to use this CIPSO/IPv4 defintion by default -mgmt add default protocol:cipsov4,1 +# Remove the default domain mapping +#map del default +# Do not accept incoming unlabeled packets +#unlbl accept off + +#### +# Unlabeled examples: +# + +# Enable unlabeled packets +#unlbl accept on + +# Disable unlabeled packets +#unlbl accept off + + +#### +# CIPSOv4 examples: +# + +# Create a CIPSOv4 DOI definition using a pass-through mapping with a DOI +# value of 6 and the restricted bitmap tag (CIPSOv4 tag type #1) +#cipsov4 add pass doi:6 tags:1 + +# Create a CIPSOv4 DOI definition using a standard mapping with a DOI value +# of 8 and the restricted bitmap tag (CIPSOv4 tag type #1). The example +# below maps MLS sensitivity levels and categories 0 through 2 to the same +# values for both CIPSO and the Linux LSM +#cipsov4 add std doi:8 tags:1 levels:0=0,1=1,2=2 categories:0=0,1=1,2=2 + + +#### +# LSM mapping examples: +# + +# Create a default mapping for all LSM domains using the unlabeled protocol +#map add default protocol:unlbl + +# Create a default mapping for all LSM domains using the CIPSOv4 protocol +# with DOI number 6 +#map add default protocol:cipsov4,6 + +# Create a mapping for the "secret_t" LSM domain and the CIPSOv4 protocol +# with DOI number 8 +#map add domain:secret_t protocol:cipsov4,8 diff --git a/netlabel_tools-0.17-newlibnl.patch b/netlabel_tools-0.17-newlibnl.patch new file mode 100644 index 0000000..88eda66 --- /dev/null +++ b/netlabel_tools-0.17-newlibnl.patch @@ -0,0 +1,218 @@ +diff -up netlabel_tools-0.17/libnetlabel/netlabel_internal.h.libnl netlabel_tools-0.17/libnetlabel/netlabel_internal.h +--- netlabel_tools-0.17/libnetlabel/netlabel_internal.h.libnl 2006-09-28 17:18:05.000000000 -0500 ++++ netlabel_tools-0.17/libnetlabel/netlabel_internal.h 2008-02-11 09:24:06.000000000 -0600 +@@ -8,19 +8,17 @@ + /* + * (c) Copyright Hewlett-Packard Development Company, L.P., 2006 + * +- * This program is free software; you can redistribute it and/or modify +- * it under the terms of the GNU General Public License as published by +- * the Free Software Foundation; either version 2 of the License, or +- * (at your option) any later version. ++ * This program is free software: you can redistribute it and/or modify ++ * it under the terms of version 2 of the GNU General Public License as ++ * published by the Free Software Foundation. + * + * This program is distributed in the hope that it will be useful, +- * but WITHOUT ANY WARRANTY; without even the implied warranty of +- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See +- * the GNU General Public License for more details. ++ * but WITHOUT ANY WARRANTY; without even the implied warranty of ++ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the ++ * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License +- * along with this program; if not, write to the Free Software +- * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA ++ * along with this program. If not, see . + * + */ + +@@ -37,11 +35,13 @@ struct nlbl_handle_s { + /* Specify which version of libnl we are using */ + /* 1.0-pre5 => 1005 */ + /* 1.0-pre6 => 1006 */ +-#define LIBNL_VERSION 1005 ++/* 1.0-pre8 => 1008 */ ++/* 1.1 => 1100 */ ++#define LIBNL_VERSION 1100 + + /* XXX - this whole block will most likely go away once libnl supports Generic + * Netlink */ +-#if 1 /* Generic Netlink types */ ++#if LIBNL_VERSION <= 1006 /* Generic Netlink types */ + + /* Generic Netlink message header */ + struct genlmsghdr { +diff -up netlabel_tools-0.17/libnetlabel/netlabel_msg.c.libnl netlabel_tools-0.17/libnetlabel/netlabel_msg.c +--- netlabel_tools-0.17/libnetlabel/netlabel_msg.c.libnl 2006-09-28 17:18:05.000000000 -0500 ++++ netlabel_tools-0.17/libnetlabel/netlabel_msg.c 2008-02-11 09:22:13.000000000 -0600 +@@ -8,19 +8,17 @@ + /* + * (c) Copyright Hewlett-Packard Development Company, L.P., 2006 + * +- * This program is free software; you can redistribute it and/or modify +- * it under the terms of the GNU General Public License as published by +- * the Free Software Foundation; either version 2 of the License, or +- * (at your option) any later version. ++ * This program is free software: you can redistribute it and/or modify ++ * it under the terms of version 2 of the GNU General Public License as ++ * published by the Free Software Foundation. + * + * This program is distributed in the hope that it will be useful, +- * but WITHOUT ANY WARRANTY; without even the implied warranty of +- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See +- * the GNU General Public License for more details. ++ * but WITHOUT ANY WARRANTY; without even the implied warranty of ++ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the ++ * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License +- * along with this program; if not, write to the Free Software +- * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA ++ * along with this program. If not, see . + * + */ + +@@ -52,7 +50,11 @@ nlbl_msg *nlbl_msg_new(void) + struct genlmsghdr genl_hdr; + + /* create the message with a simple netlink header */ ++#if LIBNL_VERSION >= 1008 ++ msg = nlmsg_alloc(); ++#else + msg = nlmsg_build_no_hdr(); ++#endif + if (msg == NULL) + goto msg_new_failure; + +diff -up netlabel_tools-0.17/libnetlabel/netlabel_comm.c.libnl netlabel_tools-0.17/libnetlabel/netlabel_comm.c +--- netlabel_tools-0.17/libnetlabel/netlabel_comm.c.libnl 2006-09-28 17:18:05.000000000 -0500 ++++ netlabel_tools-0.17/libnetlabel/netlabel_comm.c 2008-02-11 09:24:06.000000000 -0600 +@@ -8,28 +8,33 @@ + /* + * (c) Copyright Hewlett-Packard Development Company, L.P., 2006 + * +- * This program is free software; you can redistribute it and/or modify +- * it under the terms of the GNU General Public License as published by +- * the Free Software Foundation; either version 2 of the License, or +- * (at your option) any later version. ++ * This program is free software: you can redistribute it and/or modify ++ * it under the terms of version 2 of the GNU General Public License as ++ * published by the Free Software Foundation. + * + * This program is distributed in the hope that it will be useful, +- * but WITHOUT ANY WARRANTY; without even the implied warranty of +- * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See +- * the GNU General Public License for more details. ++ * but WITHOUT ANY WARRANTY; without even the implied warranty of ++ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the ++ * GNU General Public License for more details. + * + * You should have received a copy of the GNU General Public License +- * along with this program; if not, write to the Free Software +- * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA ++ * along with this program. If not, see . + * + */ + + #include + #include + #include ++#include + #include ++ ++#ifndef __USE_GNU ++#define __USE_GNU + #include +-#include ++#undef __USE_GNU ++#else ++#include ++#endif + + #include + +@@ -100,7 +105,10 @@ nlbl_handle *nlbl_comm_open(void) + goto open_failure; + + /* set the netlink handle properties */ +-#if LIBNL_VERSION >= 1006 ++#if LIBNL_VERSION >= 1008 ++ nl_socket_set_peer_port(hndl->nl_hndl, 0); ++ nl_set_passcred(hndl->nl_hndl, 1); ++#elif LIBNL_VERSION == 1006 + nl_handle_set_peer_pid(hndl->nl_hndl, 0); + nl_set_passcred(hndl->nl_hndl, 1); + #endif +@@ -177,7 +185,11 @@ int nlbl_comm_recv_raw(nlbl_handle *hndl + * is waiting to be read from the handle */ + timeout.tv_sec = nlcomm_read_timeout; + timeout.tv_usec = 0; ++#if LIBNL_VERSION >= 1008 ++ nl_fd = nl_socket_get_fd(hndl->nl_hndl); ++#else + nl_fd = nl_handle_get_fd(hndl->nl_hndl); ++#endif + FD_ZERO(&read_fds); + FD_SET(nl_fd, &read_fds); + ret_val = select(nl_fd + 1, &read_fds, NULL, NULL, &timeout); +@@ -188,14 +200,12 @@ int nlbl_comm_recv_raw(nlbl_handle *hndl + + /* perform the read operation */ + *data = NULL; +-#if LIBNL_VERSION == 1005 +- ret_val = nl_recv(hndl->nl_hndl, &peer_nladdr, data); ++#if LIBNL_VERSION >= 1006 ++ ret_val = nl_recv(hndl->nl_hndl, &peer_nladdr, data, &creds); + if (ret_val < 0) + return ret_val; +- /* XXX - avoid a compiler warning about unused variables */ +- creds = NULL; +-#elif LIBNL_VERSION >= 1006 +- ret_val = nl_recv(hndl->nl_hndl, &peer_nladdr, data, &creds); ++#else ++ ret_val = nl_recv(hndl->nl_hndl, &peer_nladdr, data); + if (ret_val < 0) + return ret_val; + #endif +@@ -250,7 +260,11 @@ int nlbl_comm_recv(nlbl_handle *hndl, nl + * is waiting to be read from the handle */ + timeout.tv_sec = nlcomm_read_timeout; + timeout.tv_usec = 0; ++#if LIBNL_VERSION >= 1008 ++ nl_fd = nl_socket_get_fd(hndl->nl_hndl); ++#else + nl_fd = nl_handle_get_fd(hndl->nl_hndl); ++#endif + FD_ZERO(&read_fds); + FD_SET(nl_fd, &read_fds); + ret_val = select(nl_fd + 1, &read_fds, NULL, NULL, &timeout); +@@ -260,12 +274,16 @@ int nlbl_comm_recv(nlbl_handle *hndl, nl + return -EAGAIN; + + /* perform the read operation */ +-#if LIBNL_VERSION == 1005 +- ret_val = nl_recv(hndl->nl_hndl, &peer_nladdr, &data); ++#if LIBNL_VERSION >= 1100 ++ ret_val = nl_recv(hndl->nl_hndl, &peer_nladdr, &data, &creds); + if (ret_val < 0) + return ret_val; + #elif LIBNL_VERSION >= 1006 +- ret_val = nl_recv(hndl->nl_hndl, &peer_nladdr, &data, &creds); ++ ret_val = nl_recv(hndl->nl_hndl, &peer_nladdr, data, &creds); ++ if (ret_val < 0) ++ return ret_val; ++#else ++ ret_val = nl_recv(hndl->nl_hndl, &peer_nladdr, data); + if (ret_val < 0) + return ret_val; + #endif +@@ -349,6 +367,6 @@ int nlbl_comm_send(nlbl_handle *hndl, nl + #if LIBNL_VERSION == 1005 + return nl_send_auto_complete(hndl->nl_hndl, nlbl_msg_nlhdr(msg)); + #elif LIBNL_VERSION >= 1006 +- return = nl_send_auto_complete(hndl->nl_hndl, msg); ++ return nl_send_auto_complete(hndl->nl_hndl, msg); + #endif + } diff --git a/netlabel_tools.spec b/netlabel_tools.spec index cad3297..6e70731 100644 --- a/netlabel_tools.spec +++ b/netlabel_tools.spec @@ -1,18 +1,16 @@ - -%define home_base_url http://free.linux.hp.com/~pmoore/projects/linux_cipso - Summary: Tools to manage the Linux NetLabel subsystem Name: netlabel_tools Version: 0.17 -Release: 5%{?dist} +Release: 7%{?dist} License: GPL Group: System Environment/Daemons -URL: %{home_base_url} -Source0: %{home_base_url}/%{name}-%{version}.tar.gz +URL: http://netlabel.sf.net/ +Source0: http://downloads.sourceforge.net/netlabel/%{name}-%{version}.tar.gz Source1: netlabel Source2: netlabel.rules Patch1: netlabel_tools-0.17-new-hdrs.patch Patch2: netlabel_tools-27_28.patch +Patch3: netlabel_tools-0.17-newlibnl.patch BuildRoot: %{_tmppath}/%{name}-%{version} BuildRequires: kernel-headers >= 2.6.18 BuildRequires: libnl-devel @@ -31,6 +29,7 @@ configure the kernel subsystem. %patch1 -p1 # Upstream patch. %patch2 -p0 +%patch3 -p1 -b .libnl %build # Don't use _smp_mflags, it's small and a hand crafted Makefile @@ -57,6 +56,11 @@ rm -rf $RPM_BUILD_ROOT %attr(0644,root,root) %{_mandir}/man8/* %changelog +* Mon Feb 11 2008 Steve Conklin - 0.17-7 +- bz#431765 Updated the .rules file +- bz#431766 added patch to build with new libnl +- bz#431767 fixed URL in spec file + * Mon Oct 16 2006 James Antill - 0.17-3 - Add upstream patch. - s/p1/p0/ for upstream patch.