diff --git a/.gitignore b/.gitignore index e69de29..773f963 100644 --- a/.gitignore +++ b/.gitignore @@ -0,0 +1,4 @@ +netlabel_tools-0.19.tar.gz +/netlabel_tools-0.20.tar.gz +/netlabel_tools-0.21.tar.gz +/netlabel_tools-0.30.0.tar.gz diff --git a/netlabel b/netlabel new file mode 100755 index 0000000..668c2aa --- /dev/null +++ b/netlabel @@ -0,0 +1,119 @@ +#!/bin/sh +# +# netlabel Start CIPSO labeled networking +# +# chkconfig: - 09 91 +# description: Starts and stops CIPSO labeled networking +# +# config: /etc/netlabel.rules +# +# Return values according to LSB for all commands but status: +# 0 - success +# 1 - generic or unspecified error +# 2 - invalid or excess argument(s) +# 3 - unimplemented feature (e.g. "reload") +# 4 - insufficient privilege +# 5 - program is not installed +# 6 - program is not configured +# 7 - program is not running + +PATH=/sbin:/bin:/usr/bin:/usr/sbin +VAR_SUBSYS_NETLABEL=/var/lock/subsys/netlabel +RULES=/etc/netlabel.rules + +# Source function library. +. /etc/init.d/functions + +# Check that we are root ... so non-root users stop here +test `id -u` = 0 || exit 4 +test -x /sbin/netlabelctl || exit 5 +test -f $RULES || exit 6 + +start() { + ret_val="0" + + # Loop through rules + while read LINE + do + # Skip comments and blank lines + if echo $LINE | egrep '^#|^$' >/dev/null ; then + continue + fi + /sbin/netlabelctl $LINE >/dev/null 2>&1 + ret="$?" + if [ "$ret" != "0" ] ; then + ret_val="$ret" + fi + done < $RULES + touch $VAR_SUBSYS_NETLABEL + return $ret_val +} + +stop() { + rm -f $VAR_SUBSYS_NETLABEL + + # Delete rules + list=`/sbin/netlabelctl cipsov4 list 2>/dev/null` + ret="$?" + if [ x"$list" != "x" ] ; then + for line in "$list" + do + /sbin/netlabelctl cipsov4 del "doi:$line" 2>/dev/null + ret="$?" + done + fi + return $ret +} + +status() { + # Do not print status if lockfile is missing + if [ ! -f "$VAR_SUBSYS_NETLABEL" ]; then + echo $"Netlabel is stopped." + return 3 + fi + + # List rules + /sbin/netlabelctl -p cipsov4 list 2>/dev/null + ret1="$?" + /sbin/netlabelctl -p mgmt protocols 2>/dev/null + ret2="$?" + + if [ "$ret1" != "0" -o "$ret2" != "0" ] ; then + return 2 + fi + return 0 +} + +restart() { + stop + start +} + +case "$1" in + start) + stop + start + RETVAL="$?" + ;; + stop) + stop + RETVAL="$?" + ;; + restart) + restart + RETVAL="$?" + ;; + condrestart) + [ -e "$VAR_SUBSYS_NETLABEL" ] && restart + ;; + status) + status + RETVAL="$?" + ;; + *) + echo $"Usage: $0 {start|stop|restart|condrestart|status}" + exit 3 + ;; +esac + +exit $RETVAL diff --git a/netlabel.rules b/netlabel.rules new file mode 100644 index 0000000..4c24972 --- /dev/null +++ b/netlabel.rules @@ -0,0 +1,59 @@ +# This file contains the rules for the Netlabel subsystem, for more information +# please see the netlabelctl(1) man page. +# +# Each line contains just the arguments to the netlabel command + +#### +# NOTE: By default the kernel sends unlabeled traffic and allows unlabled +# traffic into the system, to disable that add the following two lines to +# the beginning of your configuration. However, be warned that you +# should only change these settings if you know what you are doing as you +# could accidently disable networking with a bad configuration. +# + +# Remove the default domain mapping +#map del default + +# Do not accept incoming unlabeled packets +#unlbl accept off + +#### +# Unlabeled examples: +# + +# Enable unlabeled packets +#unlbl accept on + +# Disable unlabeled packets +#unlbl accept off + + +#### +# CIPSOv4 examples: +# + +# Create a CIPSOv4 DOI definition using a pass-through mapping with a DOI +# value of 6 and the restricted bitmap tag (CIPSOv4 tag type #1) +#cipsov4 add pass doi:6 tags:1 + +# Create a CIPSOv4 DOI definition using a standard mapping with a DOI value +# of 8 and the restricted bitmap tag (CIPSOv4 tag type #1). The example +# below maps MLS sensitivity levels and categories 0 through 2 to the same +# values for both CIPSO and the Linux LSM +#cipsov4 add std doi:8 tags:1 levels:0=0,1=1,2=2 categories:0=0,1=1,2=2 + + +#### +# LSM mapping examples: +# + +# Create a default mapping for all LSM domains using the unlabeled protocol +#map add default protocol:unlbl + +# Create a default mapping for all LSM domains using the CIPSOv4 protocol +# with DOI number 6 +#map add default protocol:cipsov4,6 + +# Create a mapping for the "secret_t" LSM domain and the CIPSOv4 protocol +# with DOI number 8 +#map add domain:secret_t protocol:cipsov4,8 diff --git a/netlabel_tools.spec b/netlabel_tools.spec new file mode 100644 index 0000000..2159299 --- /dev/null +++ b/netlabel_tools.spec @@ -0,0 +1,225 @@ +Summary: Tools to manage the Linux NetLabel subsystem +Name: netlabel_tools +Version: 0.30.0 +Release: 10%{?dist} +License: GPLv2 +URL: https://github.com/netlabel/netlabel_tools +Source: https://github.com/netlabel/netlabel_tools/releases/download/v%{version}/%{name}-%{version}.tar.gz +Patch0: rhbz1683434.patch + +Requires: libnl3 +Requires(post): systemd +Requires(preun): systemd +Requires(postun): systemd +BuildRequires: gcc +BuildRequires: kernel-headers +BuildRequires: libnl3-devel +BuildRequires: doxygen +BuildRequires: systemd + +%description +NetLabel is a kernel subsystem which implements explicit packet labeling +protocols such as CIPSO for Linux. Packet labeling is used in secure networks +to mark packets with the security attributes of the data they contain. This +package provides the necessary user space tools to query and configure the +kernel subsystem. + +%prep +%setup -q +%patch0 -p1 + +%build +%configure +make V=1 %{?_smp_mflags} + +%install +rm -rf "%{buildroot}" +mkdir -p "%{buildroot}/etc" +mkdir -p "%{buildroot}/%{_sbindir}" +mkdir -p "%{buildroot}/%{_unitdir}" +mkdir -p "%{buildroot}/%{_mandir}" +make V=1 DESTDIR="%{buildroot}" install + +# NOTE: disable since the tests require messing with the running kernel +#%check +#make V=1 check + +%preun +%systemd_preun netlabel.service + +%postun +%systemd_postun netlabel.service + +%post +%systemd_post netlabel.service + +%files +%{!?_licensedir:%global license %%doc} +%license LICENSE +%doc README +%doc CHANGELOG +%doc SUBMITTING_PATCHES +%attr(0644,root,root) %{_mandir}/man8/* +%attr(0755,root,root) %{_sbindir}/netlabelctl +%attr(0755,root,root) %{_sbindir}/netlabel-config +%attr(0644,root,root) %{_unitdir}/netlabel.service +%attr(0644,root,root) %config(noreplace) /etc/netlabel.rules + +%changelog +* Tue Jul 28 2020 Fedora Release Engineering - 0.30.0-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild + +* Wed Jan 29 2020 Fedora Release Engineering - 0.30.0-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild + +* Fri Aug 02 2019 Paul Moore - 0.30.0-8 +- Applied upstream patch to improve netlabel-config error reporting (rhbz #1683434) +- Removed the kernel dependency (rhbz #1733605) + +* Thu Jul 25 2019 Fedora Release Engineering - 0.30.0-7 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild + +* Fri Feb 01 2019 Fedora Release Engineering - 0.30.0-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild + +* Fri Jul 13 2018 Fedora Release Engineering - 0.30.0-5 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild + +* Thu Feb 08 2018 Fedora Release Engineering - 0.30.0-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild + +* Thu Aug 03 2017 Fedora Release Engineering - 0.30.0-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild + +* Wed Jul 26 2017 Fedora Release Engineering - 0.30.0-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild + +* Fri Feb 10 2017 Fedora Release Engineering - 0.30.0-1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild + +* Thu Dec 08 2016 Paul Moore - 0.30.0-0 +-New upstream version + +* Thu Feb 04 2016 Fedora Release Engineering - 0.21-1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild + +* Fri Jul 10 2015 Paul Moore - 0.21-0 +- New upstream version + +* Wed Jun 17 2015 Fedora Release Engineering - 0.20-6 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild + +* Sat Mar 21 2015 Peter Robinson 0.20-5 +- Add patch to support libnl3 +- Use %%license +- Cleanup spec + +* Sun Aug 17 2014 Fedora Release Engineering - 0.20-4 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild + +* Sat Jun 07 2014 Fedora Release Engineering - 0.20-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild + +* Thu Feb 27 2014 Paul Moore - 0.20-2 +- Build with CFLAGS="${optflags}" + +* Sat Aug 03 2013 Fedora Release Engineering - 0.20-1 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild + +* Mon Jun 3 2013 Paul Moore - 0.20-0 +- Version bump to match latest upstream +- Cleanups in the specfile due to changes in the upstream package + +* Thu Feb 14 2013 Fedora Release Engineering - 0.19-12 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild + +* Fri Jul 20 2012 Fedora Release Engineering - 0.19-11 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild + +* Fri Jan 13 2012 Fedora Release Engineering - 0.19-10 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild + +* Tue Feb 08 2011 Fedora Release Engineering - 0.19-9 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild + +* Thu Jun 17 2010 Peter Vrabec - 0.19-8 +- fixing return codes (#602291) + +* Wed Jun 16 2010 Peter Vrabec - 0.19-7 +- make initscript LSB compliant (#522818) +- show version of netlabelctl and libnetlabel in help (#602577) + +* Wed Sep 23 2009 Peter Vrabec 0.19-6 +- make initscript LSB compliant (#522818) + +* Wed Sep 23 2009 Peter Vrabec 0.19-5 +- increase rel. number + +* Wed Sep 23 2009 Peter Vrabec 0.19-4 +- fix license tag in spec (#524310) + +* Sat Jul 25 2009 Fedora Release Engineering - 0.19-3 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild + +* Wed Feb 25 2009 Fedora Release Engineering - 0.19-2 +- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild + +* Thu Jan 08 2009 Peter Vrabec - 0.19-1 +- upgrade (#478903) + +* Mon Oct 27 2008 Peter Vrabec - 0.18-1 +- upgrade (#439833) + +* Mon Aug 11 2008 Tom "spot" Callaway - 0.17-8 +- fix license tag + +* Mon Feb 11 2008 Steve Conklin - 0.17-7 +- New patch for bz#431766 to resolve conflicts + +* Thu Feb 7 2008 Steve Conklin - 0.17-6 +- Various fixes to follow upstream +- Resolves bz#431765 The example configuration file is invalid +- Resolves bz#431766 The netlabelctl command fails to run due to newer libnl package +- Resolves bz#431767 The url listed in the netlabel_tools package is wrong + +* Mon Oct 16 2006 James Antill - 0.17-3 +- Add upstream patch. +- s/p1/p0/ for upstream patch. + +* Sat Oct 14 2006 Steve Grubb - 0.17-3 +- Add init scripts and default rules + +* Sun Oct 1 2006 James Antill - 0.17-2 +- Upgrade to latest upstream. + +* Tue Aug 29 2006 James Antill - 0.16-5 +- Fix install calls for mock. + +* Tue Aug 29 2006 James Antill - 0.16-4 +- Fix more reviewing problems, building on newer kernel-headers. +- Add URL tag. + +* Fri Aug 18 2006 James Antill - 0.16-3 +- Fix minor review problems. +- Added BuildRequires for kernel headers (netlink). + +* Fri Aug 18 2006 James Antill - 0.16-2 +- Use root as owner. +- Contribute to fedora extras. + +* Thu Aug 3 2006 Paul Moore 0.16-1 +- Bumped version number. + +* Thu Jul 6 2006 Paul Moore 0.15-1 +- Bumped version number. + +* Mon Jun 26 2006 Paul Moore 0.14-1 +- Bumped version number. +- Changes related to including the version number in the path name. +- Changed the netlabelctl perms from 0750 to 0755. +- Removed the patch. (included in the base with edits) +- Updated the description. + +* Fri Jun 23 2006 Steve Grubb 0.13-1 +- Initial build. + diff --git a/rhbz1683434.patch b/rhbz1683434.patch new file mode 100644 index 0000000..d8aeae1 --- /dev/null +++ b/rhbz1683434.patch @@ -0,0 +1,38 @@ +From 578a65904ff6426c01d81826873d27d0af35f355 Mon Sep 17 00:00:00 2001 +From: Paul Moore +Date: Sun, 17 Mar 2019 17:13:55 -0400 +Subject: [PATCH] netlabel_config: better error reporting on load + +Signed-off-by: Paul Moore +--- + netlabelctl/netlabel-config | 10 ++++++++-- + 1 file changed, 8 insertions(+), 2 deletions(-) + +diff --git a/netlabelctl/netlabel-config b/netlabelctl/netlabel-config +index 717d795..15c74f7 100755 +--- a/netlabelctl/netlabel-config ++++ b/netlabelctl/netlabel-config +@@ -114,15 +114,21 @@ function nlbl_reset() { + # load the NetLabel configuration from the configuration file + function nlbl_load() { + local ret_rc=0 ++ local line_num=0 + local line + while read line; do ++ line_num=$(($line_num + 1)) + # skip comments and blank lines + echo "$line" | egrep '^#|^$' >& /dev/null && continue + + # perform the configuration +- netlabelctl $line >& /dev/null ++ output=$(netlabelctl $line 2>&1) + rc=$? +- [[ $rc -ne 0 ]] && ret_rc=1 ++ if [[ $rc -ne 0 ]]; then ++ ret_rc=1 ++ echo "error: line $line_num \"$line\"" ++ echo "$output" ++ fi + done < "$CFG_FILE" + + return $ret_rc diff --git a/sources b/sources new file mode 100644 index 0000000..3b7bc4b --- /dev/null +++ b/sources @@ -0,0 +1 @@ +fc6b07bf01bc3f68f5f05071072e521e netlabel_tools-0.30.0.tar.gz