Linux and UNIX Man Pages

Linux & Unix Commands - Search Man Pages

set_matchpathcon_printf(3) [debian man page]

set_matchpathcon_flags(3)				     SELinux API documentation					 set_matchpathcon_flags(3)

NAME
set_matchpathcon_flags, set_matchpathcon_invalidcon, set_matchpathcon_printf - set flags controlling the operation of matchpathcon or matchpathcon_index and configure the behaviour of validity checking and error displaying. SYNOPSIS
#include <selinux/selinux.h> void set_matchpathcon_flags(unsigned int flags); void set_matchpathcon_invalidcon(int (*f)(const char *path, unsigned lineno, char * context)); void set_matchpathcon_printf(void (*f)(const char *fmt, ...)); DESCRIPTION
set_matchpathcon_flags sets the flags controlling the operation of matchpathcon_init and subsequently matchpathcon_index or matchpathcon. If the MATCHPATHCON_BASEONLY flag is set, then only the base file contexts configuration file will be processed, not any dynamically gener- ated entries or local customizations. set_matchpathcon_invalidcon sets the function used by matchpathcon_init when checking the validity of a context in the file contexts con- figuration. If not set, then this defaults to a test based on security_check_context(3), which checks validity against the active policy on a SELinux system. This can be set to instead perform checking based on a binary policy file, e.g. using sepol_check_context(3), as is done by setfiles -c. The function is also responsible for reporting any such error, and may include the path and lineno in such error mes- sages. set_matchpathcon_printf sets the function used by matchpathcon_init when displaying errors about the file contexts configuration. If not set, then this defaults to fprintf(stderr, fmt, ...). This can be set to redirect error reporting to a different destination. RETURN VALUE
Returns zero on success or -1 otherwise. SEE ALSO
selinux(8), matchpathcon(3), matchpathcon_index(3), set_matchpathcon_invalidcon(3), set_matchpathcon_printf(3), freecon(3), setfilecon(3), setfscreatecon(3) sds@tycho.nsa.gov 21 November 2009 set_matchpathcon_flags(3)

Check Out this Related Man Page

matchpathcon(3) 					     SELinux API documentation						   matchpathcon(3)

NAME
matchpathcon, matchpathcon_index - get the default SELinux security context for the specified path from the file contexts configuration SYNOPSIS
#include <selinux/selinux.h> int matchpathcon_init(const char *path); int matchpathcon_init_prefix(const char *path, const char *subset); int matchpathcon_fini(void); int matchpathcon(const char *path, mode_t mode, security_context_t *con); int matchpathcon_index(const char *name, mode_t mode, security_context_t *con); DESCRIPTION
matchpathcon_init() loads the file contexts configuration specified by path into memory for use by subsequent matchpathcon() calls. If path is NULL, then the active file contexts configuration is loaded by default, i.e. the path returned by selinux_file_context_path(3). Unless the MATCHPATHCON_BASEONLY flag has been set via set_matchpathcon_flags(3), files with the same path prefix but a .homedirs and .local suffix are also looked up and loaded if present. These files provide dynamically generated entries for user home directories and for local customizations. matchpathcon_init_prefix() is the same as matchpathcon_init() but only loads entries with regular expressions that have stems prefixed by prefix. matchpathcon_fini() frees the memory allocated by a prior call to matchpathcon_init.() This function can be used to free and reset the internal state between multiple matchpathcon_init() calls, or to free memory when finished using matchpathcon(). matchpathcon() matches the specified pathname and mode against the file contexts configuration and sets the security context con to refer to the resulting context. The caller must free the returned security context con using freecon(3) when finished using it. mode can be 0 to disable mode matching, but should be provided whenever possible, as it may affect the matching. Only the file format bits (i.e. the file type) of the mode are used. If matchpathcon_init() has not already been called, then this function will call it upon its first invocation with a NULL path, defaulting to the active file contexts configuration. matchpathcon_index() is the same as matchpathcon() but returns a specification index that can later be used in a matchpathcon_file- spec_add(3) call. RETURN VALUE
Returns zero on success or -1 otherwise. SEE ALSO
selinux(8), set_matchpathcon_flags(3), set_matchpathcon_invalidcon(3), set_matchpathcon_printf(3), matchpathcon_filespec_add(3), matchpathcon_checkmatches(3), freecon(3), setfilecon(3), setfscreatecon(3) sds@tycho.nsa.gov 21 November 2009 matchpathcon(3)
Man Page