Compare commits

..

3 commits

Author SHA1 Message Date
Fedora Release Engineering
5bdad15090 dist-git conversion 2010-07-29 04:18:46 +00:00
Bill Nottingham
e9d96a18f4 Fix typo that causes a failure to update the common directory. (releng
#2781)
2009-11-26 01:22:23 +00:00
Jeremy Katz
404096b1c5 Initialize branch FC-6 for netlabel_tools 2006-10-23 16:46:48 +00:00
9 changed files with 173 additions and 302 deletions

5
.gitignore vendored
View file

@ -1,4 +1 @@
netlabel_tools-0.19.tar.gz
/netlabel_tools-0.20.tar.gz
/netlabel_tools-0.21.tar.gz
/netlabel_tools-0.30.0.tar.gz
netlabel_tools-0.17.tar.gz

View file

@ -69,17 +69,17 @@ status() {
# Do not print status if lockfile is missing
if [ ! -f "$VAR_SUBSYS_NETLABEL" ]; then
echo $"Netlabel is stopped."
return 3
return 7
fi
# List rules
/sbin/netlabelctl -p cipsov4 list 2>/dev/null
ret1="$?"
/sbin/netlabelctl -p mgmt protocols 2>/dev/null
/sbin/netlabelctl -p mgmt list 2>/dev/null
ret2="$?"
if [ "$ret1" != "0" -o "$ret2" != "0" ] ; then
return 2
return 1
fi
return 0
}

View file

@ -1,59 +1,9 @@
# This file contains the rules for the Netlabel subsystem, for more information
# please see the netlabelctl(1) man page.
#
# This file contains the rules for the Netlabel subsystem
# Each line contains just the arguments to the netlabel command
####
# NOTE: By default the kernel sends unlabeled traffic and allows unlabled
# traffic into the system, to disable that add the following two lines to
# the beginning of your configuration. However, be warned that you
# should only change these settings if you know what you are doing as you
# could accidently disable networking with a bad configuration.
#
# creates a CIPSO/IPv4 definition using a DOI value of 1
cipsov4 add std doi:1 tags:1 levels:0=0,1=1,2=2 categories:0=0,1=1,2=2
# Remove the default domain mapping
#map del default
# tell the NetLabel system to use this CIPSO/IPv4 defintion by default
mgmt add default protocol:cipsov4,1
# Do not accept incoming unlabeled packets
#unlbl accept off
####
# Unlabeled examples:
#
# Enable unlabeled packets
#unlbl accept on
# Disable unlabeled packets
#unlbl accept off
####
# CIPSOv4 examples:
#
# Create a CIPSOv4 DOI definition using a pass-through mapping with a DOI
# value of 6 and the restricted bitmap tag (CIPSOv4 tag type #1)
#cipsov4 add pass doi:6 tags:1
# Create a CIPSOv4 DOI definition using a standard mapping with a DOI value
# of 8 and the restricted bitmap tag (CIPSOv4 tag type #1). The example
# below maps MLS sensitivity levels and categories 0 through 2 to the same
# values for both CIPSO and the Linux LSM
#cipsov4 add std doi:8 tags:1 levels:0=0,1=1,2=2 categories:0=0,1=1,2=2
####
# LSM mapping examples:
#
# Create a default mapping for all LSM domains using the unlabeled protocol
#map add default protocol:unlbl
# Create a default mapping for all LSM domains using the CIPSOv4 protocol
# with DOI number 6
#map add default protocol:cipsov4,6
# Create a mapping for the "secret_t" LSM domain and the CIPSOv4 protocol
# with DOI number 8
#map add domain:secret_t protocol:cipsov4,8

View file

@ -0,0 +1,65 @@
diff -rup netlabel_tools-0.16-orig/include/linux/netlabel.h netlabel_tools-0.16/include/linux/netlabel.h
--- netlabel_tools-0.16-orig/include/linux/netlabel.h 2006-07-31 17:20:41.000000000 -0400
+++ netlabel_tools-0.16/include/linux/netlabel.h 2006-08-29 14:07:44.000000000 -0400
@@ -39,7 +39,9 @@
/* FIXME: perhaps some or all this lives in a system header file? */
-#define NLMSG_HDRLEN NLMSG_ALIGN(sizeof(struct nlmsghdr))
+#ifndef NLMSG_HDRLEN /* newer netlink.h has these... */
+
+# define NLMSG_HDRLEN NLMSG_ALIGN(sizeof(struct nlmsghdr))
struct nlattr
{
@@ -47,6 +49,13 @@ struct nlattr
unsigned short nla_type;
};
+# define NLA_HDRLEN NLMSG_ALIGN(sizeof(struct nlattr))
+
+# define NETLINK_GENERIC 16
+
+
+#endif
+
enum {
NLA_UNSPEC,
NLA_U8,
@@ -61,10 +70,6 @@ enum {
};
#define NLA_TYPE_MAX (__NLA_TYPE_MAX - 1)
-#define NLA_HDRLEN NLMSG_ALIGN(sizeof(struct nlattr))
-
-#define NETLINK_GENERIC 16
-
struct genlmsghdr {
unsigned char cmd;
unsigned char version;
--- netlabel_tools-0.16-orig/Makefile 2006-06-27 13:06:28.000000000 -0400
+++ netlabel_tools-0.16/Makefile 2006-08-29 16:42:09.000000000 -0400
@@ -43,8 +43,9 @@ INSTALL_SBIN_DIR = $(INSTALL_PREFIX)/sbi
INSTALL_BIN_DIR = $(INSTALL_PREFIX)/bin
INSTALL_MAN_DIR = $(INSTALL_PREFIX)/share/man
-OWNER = root
-GROUP = root
+# Mock doesn't allow this.
+#OWNER = root
+#GROUP = root
#
# targets
@@ -77,9 +78,9 @@ install: $(SUBDIRS)
@echo "INFO: installing files in $(INSTALL_PREFIX)"
@mkdir -p $(INSTALL_SBIN_DIR)
@mkdir -p $(INSTALL_MAN_DIR)/man8
- @install -o $(OWNER) -g $(GROUP) -m 755 netlabelctl/netlabelctl \
+ @install -m 755 netlabelctl/netlabelctl \
$(INSTALL_SBIN_DIR)/netlabelctl
- @install -o $(OWNER) -g $(GROUP) -m 644 docs/man/netlabelctl.8 \
+ @install -m 644 docs/man/netlabelctl.8 \
$(INSTALL_MAN_DIR)/man8
clean:

View file

@ -0,0 +1,26 @@
--- netlabel_tools-0.16-orig/Makefile 2006-06-27 13:06:28.000000000 -0400
+++ netlabel_tools-0.16/Makefile 2006-08-29 16:42:09.000000000 -0400
@@ -43,8 +43,9 @@ INSTALL_SBIN_DIR = $(INSTALL_PREFIX)/sbi
INSTALL_BIN_DIR = $(INSTALL_PREFIX)/bin
INSTALL_MAN_DIR = $(INSTALL_PREFIX)/share/man
-OWNER = root
-GROUP = root
+# Mock doesn't allow this.
+#OWNER = root
+#GROUP = root
#
# targets
@@ -77,9 +78,9 @@ install: $(SUBDIRS)
@echo "INFO: installing files in $(INSTALL_PREFIX)"
@mkdir -p $(INSTALL_SBIN_DIR)
@mkdir -p $(INSTALL_MAN_DIR)/man8
- @install -o $(OWNER) -g $(GROUP) -m 755 netlabelctl/netlabelctl \
+ @install -m 755 netlabelctl/netlabelctl \
$(INSTALL_SBIN_DIR)/netlabelctl
- @install -o $(OWNER) -g $(GROUP) -m 644 docs/man/netlabelctl.8 \
+ @install -m 644 docs/man/netlabelctl.8 \
$(INSTALL_MAN_DIR)/man8
clean:

View file

@ -0,0 +1,29 @@
Index: netlabelctl/cipsov4.c
===================================================================
--- netlabelctl/cipsov4.c (revision 27)
+++ netlabelctl/cipsov4.c (revision 28)
@@ -236,7 +236,7 @@
printf("STANDARD");
break;
case CIPSO_V4_MAP_PASS:
- printf("PASS_THROUGH\n");
+ printf("PASS_THROUGH");
break;
default:
printf("UNKNOWN(%u)", mtype_list[iter]);
Index: netlabelctl/map.c
===================================================================
--- netlabelctl/map.c (revision 27)
+++ netlabelctl/map.c (revision 28)
@@ -224,8 +224,10 @@
printf("UNKNOWN(%u)", domain_p[iter].proto_type);
break;
}
- printf(" ");
+ if (iter + 1 < count)
+ printf(" ");
}
+ printf("\n");
}
list_return:

View file

@ -1,220 +1,62 @@
%define home_base_url http://free.linux.hp.com/~pmoore/projects/linux_cipso
Summary: Tools to manage the Linux NetLabel subsystem
Name: netlabel_tools
Version: 0.30.0
Release: 21%{?dist}
License: GPL-2.0-only
URL: https://github.com/netlabel/netlabel_tools
Source: https://github.com/netlabel/netlabel_tools/releases/download/v%{version}/%{name}-%{version}.tar.gz
Patch0: rhbz1683434.patch
Requires: libnl3
Requires(post): systemd
Requires(preun): systemd
Requires(postun): systemd
BuildRequires: make
BuildRequires: gcc
BuildRequires: kernel-headers
BuildRequires: libnl3-devel
BuildRequires: doxygen
BuildRequires: systemd
Version: 0.17
Release: 5%{?dist}
License: GPL
Group: System Environment/Daemons
URL: %{home_base_url}
Source0: %{home_base_url}/%{name}-%{version}.tar.gz
Source1: netlabel
Source2: netlabel.rules
Patch1: netlabel_tools-0.17-new-hdrs.patch
Patch2: netlabel_tools-27_28.patch
BuildRoot: %{_tmppath}/%{name}-%{version}
BuildRequires: kernel-headers >= 2.6.18
BuildRequires: libnl-devel
%description
NetLabel is a kernel subsystem which implements explicit packet labeling
protocols such as CIPSO for Linux. Packet labeling is used in secure networks
to mark packets with the security attributes of the data they contain. This
package provides the necessary user space tools to query and configure the
kernel subsystem.
protocols such as CIPSO and RIPSO for Linux. Packet labeling is used in
secure networks to mark packets with the security attributes of the data they
contain. This package provides the necessary user space tools to query and
configure the kernel subsystem.
%prep
%autosetup -p 1
%prep
%setup -q -n %{name}-%{version}
# Build fixes.
%patch1 -p1
# Upstream patch.
%patch2 -p0
%build
%configure
make V=1 %{?_smp_mflags}
# Don't use _smp_mflags, it's small and a hand crafted Makefile
make
%install
rm -rf "%{buildroot}"
mkdir -p "%{buildroot}/etc"
mkdir -p "%{buildroot}/%{_sbindir}"
mkdir -p "%{buildroot}/%{_unitdir}"
mkdir -p "%{buildroot}/%{_mandir}"
make V=1 DESTDIR="%{buildroot}" install
rm -rf $RPM_BUILD_ROOT
make INSTALL_PREFIX=${RPM_BUILD_ROOT} \
INSTALL_MAN_DIR=${RPM_BUILD_ROOT}/usr/share/man \
install
mkdir -p $RPM_BUILD_ROOT/etc/rc.d/init.d/
install -m 0755 %{SOURCE1} $RPM_BUILD_ROOT/etc/rc.d/init.d/
install -m 0640 %{SOURCE2} $RPM_BUILD_ROOT/etc/
# NOTE: disable since the tests require messing with the running kernel
#%check
#make V=1 check
%preun
%systemd_preun netlabel.service
%postun
%systemd_postun netlabel.service
%post
%systemd_post netlabel.service
%clean
rm -rf $RPM_BUILD_ROOT
%files
%{!?_licensedir:%global license %%doc}
%license LICENSE
%doc README
%doc CHANGELOG
%doc SUBMITTING_PATCHES
%defattr(-,root,root)
%doc docs/*.txt
%attr(0755,root,root) /sbin/*
%attr(0755,root,root) /etc/rc.d/init.d/netlabel
%config(noreplace) %attr(640,root,root) /etc/netlabel.rules
%attr(0644,root,root) %{_mandir}/man8/*
%attr(0755,root,root) %{_sbindir}/netlabelctl
%attr(0755,root,root) %{_sbindir}/netlabel-config
%attr(0644,root,root) %{_unitdir}/netlabel.service
%attr(0644,root,root) %config(noreplace) /etc/netlabel.rules
%changelog
* Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-21
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
* Fri Jan 17 2025 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-20
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
* Thu Jul 18 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-19
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild
* Thu Jan 25 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-18
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-17
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Thu Jul 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-16
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jan 19 2023 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-15
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild
* Fri Jul 22 2022 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-14
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild
* Thu Jan 20 2022 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-13
- Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild
* Thu Jul 22 2021 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild
* Tue Jan 26 2021 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild
* Tue Jul 28 2020 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild
* Wed Jan 29 2020 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild
* Fri Aug 02 2019 Paul Moore <paul@paul-moore.com> - 0.30.0-8
- Applied upstream patch to improve netlabel-config error reporting (rhbz #1683434)
- Removed the kernel dependency (rhbz #1733605)
* Thu Jul 25 2019 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-7
- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild
* Fri Feb 01 2019 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild
* Fri Jul 13 2018 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-5
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Thu Feb 08 2018 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Thu Aug 03 2017 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
* Wed Jul 26 2017 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Fri Feb 10 2017 Fedora Release Engineering <releng@fedoraproject.org> - 0.30.0-1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
* Thu Dec 08 2016 Paul Moore <pmoore@redhat.com> - 0.30.0-0
-New upstream version
* Thu Feb 04 2016 Fedora Release Engineering <releng@fedoraproject.org> - 0.21-1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
* Fri Jul 10 2015 Paul Moore <pmoore@redhat.com> - 0.21-0
- New upstream version
* Wed Jun 17 2015 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.20-6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
* Sat Mar 21 2015 Peter Robinson <pbrobinson@fedoraproject.org> 0.20-5
- Add patch to support libnl3
- Use %%license
- Cleanup spec
* Sun Aug 17 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.20-4
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
* Sat Jun 07 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.20-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
* Thu Feb 27 2014 Paul Moore <pmoore@redhat.com> - 0.20-2
- Build with CFLAGS="${optflags}"
* Sat Aug 03 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.20-1
- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild
* Mon Jun 3 2013 Paul Moore <pmoore@redhat.com> - 0.20-0
- Version bump to match latest upstream
- Cleanups in the specfile due to changes in the upstream package
* Thu Feb 14 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.19-12
- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild
* Fri Jul 20 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.19-11
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
* Fri Jan 13 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.19-10
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
* Tue Feb 08 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.19-9
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
* Thu Jun 17 2010 Peter Vrabec <pvrabec@redhat.com> - 0.19-8
- fixing return codes (#602291)
* Wed Jun 16 2010 Peter Vrabec <pvrabec@redhat.com> - 0.19-7
- make initscript LSB compliant (#522818)
- show version of netlabelctl and libnetlabel in help (#602577)
* Wed Sep 23 2009 Peter Vrabec <pvrabec@redhat.com> 0.19-6
- make initscript LSB compliant (#522818)
* Wed Sep 23 2009 Peter Vrabec <pvrabec@redhat.com> 0.19-5
- increase rel. number
* Wed Sep 23 2009 Peter Vrabec <pvrabec@redhat.com> 0.19-4
- fix license tag in spec (#524310)
* Sat Jul 25 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.19-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
* Wed Feb 25 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.19-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
* Thu Jan 08 2009 Peter Vrabec <pvrabec@redhat.com> - 0.19-1
- upgrade (#478903)
* Mon Oct 27 2008 Peter Vrabec <pvrabec@redhat.com> - 0.18-1
- upgrade (#439833)
* Mon Aug 11 2008 Tom "spot" Callaway <tcallawa@redhat.com> - 0.17-8
- fix license tag
* Mon Feb 11 2008 Steve Conklin <sconklin@redhat.com> - 0.17-7
- New patch for bz#431766 to resolve conflicts
* Thu Feb 7 2008 Steve Conklin <sconklin@redhat.com> - 0.17-6
- Various fixes to follow upstream
- Resolves bz#431765 The example configuration file is invalid
- Resolves bz#431766 The netlabelctl command fails to run due to newer libnl package
- Resolves bz#431767 The url listed in the netlabel_tools package is wrong
* Mon Oct 16 2006 James Antill <james@and.org> - 0.17-3
- Add upstream patch.
- s/p1/p0/ for upstream patch.

View file

@ -1,38 +0,0 @@
From 578a65904ff6426c01d81826873d27d0af35f355 Mon Sep 17 00:00:00 2001
From: Paul Moore <paul@paul-moore.com>
Date: Sun, 17 Mar 2019 17:13:55 -0400
Subject: [PATCH] netlabel_config: better error reporting on load
Signed-off-by: Paul Moore <paul@paul-moore.com>
---
netlabelctl/netlabel-config | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/netlabelctl/netlabel-config b/netlabelctl/netlabel-config
index 717d795..15c74f7 100755
--- a/netlabelctl/netlabel-config
+++ b/netlabelctl/netlabel-config
@@ -114,15 +114,21 @@ function nlbl_reset() {
# load the NetLabel configuration from the configuration file
function nlbl_load() {
local ret_rc=0
+ local line_num=0
local line
while read line; do
+ line_num=$(($line_num + 1))
# skip comments and blank lines
echo "$line" | egrep '^#|^$' >& /dev/null && continue
# perform the configuration
- netlabelctl $line >& /dev/null
+ output=$(netlabelctl $line 2>&1)
rc=$?
- [[ $rc -ne 0 ]] && ret_rc=1
+ if [[ $rc -ne 0 ]]; then
+ ret_rc=1
+ echo "error: line $line_num \"$line\""
+ echo "$output"
+ fi
done < "$CFG_FILE"
return $ret_rc

View file

@ -1 +1 @@
fc6b07bf01bc3f68f5f05071072e521e netlabel_tools-0.30.0.tar.gz
905ffd48714f48aaa34ecdc3c51d3dcb netlabel_tools-0.17.tar.gz