forked from podman-container-tools/buildah
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathselinux.go
More file actions
36 lines (32 loc) · 1.11 KB
/
Copy pathselinux.go
File metadata and controls
36 lines (32 loc) · 1.11 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
package buildah
import (
"errors"
"fmt"
"os"
"runtime"
"github.com/opencontainers/runtime-tools/generate"
selinux "github.com/opencontainers/selinux/go-selinux"
)
func setupSelinux(g *generate.Generator, processLabel, mountLabel string) {
if runtime.GOOS == "linux" && processLabel != "" && selinux.GetEnabled() {
g.SetProcessSelinuxLabel(processLabel)
g.SetLinuxMountLabel(mountLabel)
}
}
func runLabelStdioPipes(stdioPipe [][]int, processLabel, mountLabel string) error {
if runtime.GOOS != "linux" || !selinux.GetEnabled() || processLabel == "" || mountLabel == "" {
// Not on Linux, or SELinux is disabled, or empty labels.
return nil
}
pipeContext, err := selinux.ComputeCreateContext(processLabel, mountLabel, "fifo_file")
if err != nil {
return fmt.Errorf("computing file creation context for pipes: %w", err)
}
for i := range stdioPipe {
pipeFdName := fmt.Sprintf("/proc/self/fd/%d", stdioPipe[i][0])
if err := selinux.SetFileLabel(pipeFdName, pipeContext); err != nil && !errors.Is(err, os.ErrNotExist) {
return fmt.Errorf("setting file label on %q: %w", pipeFdName, err)
}
}
return nil
}