SM0 She11
Path:
/
/
usr
/
sbin
Full Path (server): /usr/sbin
Create Fil3
Upl04d Fil3
📄 accessdb
[E]
[D]
[R]
📄 addgnupghome
[E]
[D]
[R]
📄 addpart
[E]
[D]
[R]
📄 adduser
[E]
[D]
[R]
📄 agetty
[E]
[D]
[R]
📄 alternatives
[E]
[D]
[R]
📄 amavisd
[E]
[D]
[R]
📄 anacron
[E]
[D]
[R]
📄 applygnupgdefaults
[E]
[D]
[R]
📄 arp
[E]
[D]
[R]
📄 arpd
[E]
[D]
[R]
📄 arping
[E]
[D]
[R]
📄 atd
[E]
[D]
[R]
📄 atrun
[E]
[D]
[R]
📄 audispd
[E]
[D]
[R]
📄 auditctl
[E]
[D]
[R]
📄 auditd
[E]
[D]
[R]
📄 augenrules
[E]
[D]
[R]
📄 aureport
[E]
[D]
[R]
📄 ausearch
[E]
[D]
[R]
📄 authconfig
[E]
[D]
[R]
📄 authconfig-tui
[E]
[D]
[R]
📄 autrace
[E]
[D]
[R]
📄 avcstat
[E]
[D]
[R]
📄 badblocks
[E]
[D]
[R]
📄 biosdecode
[E]
[D]
[R]
📄 blkdeactivate
[E]
[D]
[R]
📄 blkdiscard
[E]
[D]
[R]
📄 blkid
[E]
[D]
[R]
📄 blockdev
[E]
[D]
[R]
📄 bridge
[E]
[D]
[R]
📄 btrfs
[E]
[D]
[R]
📄 btrfs-convert
[E]
[D]
[R]
📄 btrfs-debug-tree
[E]
[D]
[R]
📄 btrfs-find-root
[E]
[D]
[R]
📄 btrfs-image
[E]
[D]
[R]
📄 btrfs-map-logical
[E]
[D]
[R]
📄 btrfs-select-super
[E]
[D]
[R]
📄 btrfs-zero-log
[E]
[D]
[R]
📄 btrfsck
[E]
[D]
[R]
📄 btrfstune
[E]
[D]
[R]
📄 build-locale-archive
[E]
[D]
[R]
📄 cacertdir_rehash
[E]
[D]
[R]
📄 capsh
[E]
[D]
[R]
📄 cbq
[E]
[D]
[R]
📄 cfdisk
[E]
[D]
[R]
📄 chcpu
[E]
[D]
[R]
📄 chgpasswd
[E]
[D]
[R]
📄 chkconfig
[E]
[D]
[R]
📄 chpasswd
[E]
[D]
[R]
📄 chronyd
[E]
[D]
[R]
📄 chroot
[E]
[D]
[R]
📄 clamd
[E]
[D]
[R]
📄 clamonacc
[E]
[D]
[R]
📄 clock
[E]
[D]
[R]
📄 clockdiff
[E]
[D]
[R]
📄 consoletype
[E]
[D]
[R]
📄 convertquota
[E]
[D]
[R]
📄 cracklib-check
[E]
[D]
[R]
📄 cracklib-format
[E]
[D]
[R]
📄 cracklib-packer
[E]
[D]
[R]
📄 cracklib-unpacker
[E]
[D]
[R]
📄 create-cracklib-dict
[E]
[D]
[R]
📄 crond
[E]
[D]
[R]
📄 csf
[E]
[D]
[R]
📄 ctrlaltdel
[E]
[D]
[R]
📄 ctstat
[E]
[D]
[R]
📄 ddns-confgen
[E]
[D]
[R]
📄 debugfs
[E]
[D]
[R]
📄 delpart
[E]
[D]
[R]
📄 depmod
[E]
[D]
[R]
📄 devlink
[E]
[D]
[R]
📄 dhclient
[E]
[D]
[R]
📄 dhclient-script
[E]
[D]
[R]
📄 dmfilemapd
[E]
[D]
[R]
📄 dmidecode
[E]
[D]
[R]
📄 dmsetup
[E]
[D]
[R]
📄 dmstats
[E]
[D]
[R]
📄 dnssec-checkds
[E]
[D]
[R]
📄 dnssec-coverage
[E]
[D]
[R]
📄 dnssec-dsfromkey
[E]
[D]
[R]
📄 dnssec-importkey
[E]
[D]
[R]
📄 dnssec-keyfromlabel
[E]
[D]
[R]
📄 dnssec-keygen
[E]
[D]
[R]
📄 dnssec-keymgr
[E]
[D]
[R]
📄 dnssec-revoke
[E]
[D]
[R]
📄 dnssec-settime
[E]
[D]
[R]
📄 dnssec-signzone
[E]
[D]
[R]
📄 dnssec-verify
[E]
[D]
[R]
📄 dovecot
[E]
[D]
[R]
📄 dracut
[E]
[D]
[R]
📄 dumpe2fs
[E]
[D]
[R]
📄 e2freefrag
[E]
[D]
[R]
📄 e2fsck
[E]
[D]
[R]
📄 e2image
[E]
[D]
[R]
📄 e2label
[E]
[D]
[R]
📄 e2undo
[E]
[D]
[R]
📄 e4defrag
[E]
[D]
[R]
📄 eapol_test
[E]
[D]
[R]
📄 edquota
[E]
[D]
[R]
📄 ether-wake
[E]
[D]
[R]
📄 ethtool
[E]
[D]
[R]
📄 faillock
[E]
[D]
[R]
📄 fdformat
[E]
[D]
[R]
📄 fdisk
[E]
[D]
[R]
📄 filefrag
[E]
[D]
[R]
📄 findfs
[E]
[D]
[R]
📄 fixfiles
[E]
[D]
[R]
📄 fsck
[E]
[D]
[R]
📄 fsck.btrfs
[E]
[D]
[R]
📄 fsck.cramfs
[E]
[D]
[R]
📄 fsck.ext2
[E]
[D]
[R]
📄 fsck.ext3
[E]
[D]
[R]
📄 fsck.ext4
[E]
[D]
[R]
📄 fsck.minix
[E]
[D]
[R]
📄 fsck.xfs
[E]
[D]
[R]
📄 fsfreeze
[E]
[D]
[R]
📄 fstrim
[E]
[D]
[R]
📄 fuser
[E]
[D]
[R]
📄 genccode
[E]
[D]
[R]
📄 gencmn
[E]
[D]
[R]
📄 genhomedircon
[E]
[D]
[R]
📄 genhostid
[E]
[D]
[R]
📄 genl
[E]
[D]
[R]
📄 genl-ctrl-list
[E]
[D]
[R]
📄 gennorm2
[E]
[D]
[R]
📄 genrandom
[E]
[D]
[R]
📄 gensprep
[E]
[D]
[R]
📄 getcap
[E]
[D]
[R]
📄 getenforce
[E]
[D]
[R]
📄 getpcaps
[E]
[D]
[R]
📄 getsebool
[E]
[D]
[R]
📄 glibc_post_upgrade.x86_64
[E]
[D]
[R]
📄 groupadd
[E]
[D]
[R]
📄 groupdel
[E]
[D]
[R]
📄 groupmems
[E]
[D]
[R]
📄 groupmod
[E]
[D]
[R]
📄 grpck
[E]
[D]
[R]
📄 grpconv
[E]
[D]
[R]
📄 grpunconv
[E]
[D]
[R]
📄 grub2-bios-setup
[E]
[D]
[R]
📄 grub2-get-kernel-settings
[E]
[D]
[R]
📄 grub2-install
[E]
[D]
[R]
📄 grub2-macbless
[E]
[D]
[R]
📄 grub2-mkconfig
[E]
[D]
[R]
📄 grub2-ofpathname
[E]
[D]
[R]
📄 grub2-probe
[E]
[D]
[R]
📄 grub2-reboot
[E]
[D]
[R]
📄 grub2-rpm-sort
[E]
[D]
[R]
📄 grub2-set-default
[E]
[D]
[R]
📄 grub2-setpassword
[E]
[D]
[R]
📄 grub2-sparc64-setup
[E]
[D]
[R]
📄 grubby
[E]
[D]
[R]
📄 gss-server
[E]
[D]
[R]
📄 halt
[E]
[D]
[R]
📄 hardlink
[E]
[D]
[R]
📄 hwclock
[E]
[D]
[R]
📄 iconvconfig
[E]
[D]
[R]
📄 iconvconfig.x86_64
[E]
[D]
[R]
📄 icupkg
[E]
[D]
[R]
📄 ifcfg
[E]
[D]
[R]
📄 ifconfig
[E]
[D]
[R]
📄 ifdown
[E]
[D]
[R]
📄 ifenslave
[E]
[D]
[R]
📄 ifstat
[E]
[D]
[R]
📄 ifup
[E]
[D]
[R]
📄 init
[E]
[D]
[R]
📄 insmod
[E]
[D]
[R]
📄 install-info
[E]
[D]
[R]
📄 installkernel
[E]
[D]
[R]
📄 intel-microcode2ucode
[E]
[D]
[R]
📄 ip
[E]
[D]
[R]
📄 ip6tables
[E]
[D]
[R]
📄 ip6tables-restore
[E]
[D]
[R]
📄 ip6tables-save
[E]
[D]
[R]
📄 ipmaddr
[E]
[D]
[R]
📄 iptables
[E]
[D]
[R]
📄 iptables-restore
[E]
[D]
[R]
📄 iptables-save
[E]
[D]
[R]
📄 iptunnel
[E]
[D]
[R]
📄 irqbalance
[E]
[D]
[R]
📄 isc-hmac-fixup
[E]
[D]
[R]
📄 kexec
[E]
[D]
[R]
📄 killall5
[E]
[D]
[R]
📄 kpartx
[E]
[D]
[R]
📄 lchage
[E]
[D]
[R]
📄 ldattach
[E]
[D]
[R]
📄 ldconfig
[E]
[D]
[R]
📄 lfd
[E]
[D]
[R]
📄 lgroupadd
[E]
[D]
[R]
📄 lgroupdel
[E]
[D]
[R]
📄 lgroupmod
[E]
[D]
[R]
📄 lid
[E]
[D]
[R]
📄 lnewusers
[E]
[D]
[R]
📄 lnstat
[E]
[D]
[R]
📄 load_policy
[E]
[D]
[R]
📄 logrotate
[E]
[D]
[R]
📄 logsave
[E]
[D]
[R]
📄 losetup
[E]
[D]
[R]
📄 lpasswd
[E]
[D]
[R]
📄 lsmod
[E]
[D]
[R]
📄 lsof
[E]
[D]
[R]
📄 luseradd
[E]
[D]
[R]
📄 luserdel
[E]
[D]
[R]
📄 lusermod
[E]
[D]
[R]
📄 lwresd
[E]
[D]
[R]
📄 makedumpfile
[E]
[D]
[R]
📄 matchpathcon
[E]
[D]
[R]
📄 mii-diag
[E]
[D]
[R]
📄 mii-tool
[E]
[D]
[R]
📄 mkdict
[E]
[D]
[R]
📄 mkdumprd
[E]
[D]
[R]
📄 mke2fs
[E]
[D]
[R]
📄 mkfs
[E]
[D]
[R]
📄 mkfs.btrfs
[E]
[D]
[R]
📄 mkfs.cramfs
[E]
[D]
[R]
📄 mkfs.ext2
[E]
[D]
[R]
📄 mkfs.ext3
[E]
[D]
[R]
📄 mkfs.ext4
[E]
[D]
[R]
📄 mkfs.minix
[E]
[D]
[R]
📄 mkfs.xfs
[E]
[D]
[R]
📄 mkhomedir_helper
[E]
[D]
[R]
📄 mklost+found
[E]
[D]
[R]
📄 mkswap
[E]
[D]
[R]
📄 modinfo
[E]
[D]
[R]
📄 modprobe
[E]
[D]
[R]
📄 mysqld
[E]
[D]
[R]
📄 named
[E]
[D]
[R]
📄 named-checkconf
[E]
[D]
[R]
📄 named-checkzone
[E]
[D]
[R]
📄 named-compilezone
[E]
[D]
[R]
📄 named-journalprint
[E]
[D]
[R]
📄 nameif
[E]
[D]
[R]
📄 netreport
[E]
[D]
[R]
📄 new-kernel-pkg
[E]
[D]
[R]
📄 newusers
[E]
[D]
[R]
📄 nl-class-add
[E]
[D]
[R]
📄 nl-class-delete
[E]
[D]
[R]
📄 nl-class-list
[E]
[D]
[R]
📄 nl-classid-lookup
[E]
[D]
[R]
📄 nl-cls-add
[E]
[D]
[R]
📄 nl-cls-delete
[E]
[D]
[R]
📄 nl-cls-list
[E]
[D]
[R]
📄 nl-link-list
[E]
[D]
[R]
📄 nl-pktloc-lookup
[E]
[D]
[R]
📄 nl-qdisc-add
[E]
[D]
[R]
📄 nl-qdisc-delete
[E]
[D]
[R]
📄 nl-qdisc-list
[E]
[D]
[R]
📄 nologin
[E]
[D]
[R]
📄 nsec3hash
[E]
[D]
[R]
📄 nstat
[E]
[D]
[R]
📄 ownership
[E]
[D]
[R]
📄 packer
[E]
[D]
[R]
📄 pam_console_apply
[E]
[D]
[R]
📄 pam_tally2
[E]
[D]
[R]
📄 pam_timestamp_check
[E]
[D]
[R]
📄 paperconfig
[E]
[D]
[R]
📄 parted
[E]
[D]
[R]
📄 partprobe
[E]
[D]
[R]
📄 partx
[E]
[D]
[R]
📄 pflogsumm
[E]
[D]
[R]
📄 pidof
[E]
[D]
[R]
📄 ping6
[E]
[D]
[R]
📄 pivot_root
[E]
[D]
[R]
📄 plipconfig
[E]
[D]
[R]
📄 pluginviewer
[E]
[D]
[R]
📄 portrelease
[E]
[D]
[R]
📄 portreserve
[E]
[D]
[R]
📄 postalias
[E]
[D]
[R]
📄 postcat
[E]
[D]
[R]
📄 postconf
[E]
[D]
[R]
📄 postdrop
[E]
[D]
[R]
📄 postfix
[E]
[D]
[R]
📄 postkick
[E]
[D]
[R]
📄 postlock
[E]
[D]
[R]
📄 postlog
[E]
[D]
[R]
📄 postmap
[E]
[D]
[R]
📄 postmulti
[E]
[D]
[R]
📄 postqueue
[E]
[D]
[R]
📄 postsuper
[E]
[D]
[R]
📄 poweroff
[E]
[D]
[R]
📄 ppp-watch
[E]
[D]
[R]
📄 pure-authd
[E]
[D]
[R]
📄 pure-config.pl
[E]
[D]
[R]
📄 pure-config.py
[E]
[D]
[R]
📄 pure-ftpd
[E]
[D]
[R]
📄 pure-ftpwho
[E]
[D]
[R]
📄 pure-mrtginfo
[E]
[D]
[R]
📄 pure-quotacheck
[E]
[D]
[R]
📄 pure-uploadscript
[E]
[D]
[R]
📄 pwck
[E]
[D]
[R]
📄 pwconv
[E]
[D]
[R]
📄 pwhistory_helper
[E]
[D]
[R]
📄 pwunconv
[E]
[D]
[R]
📄 qshape
[E]
[D]
[R]
📄 quot
[E]
[D]
[R]
📄 quotacheck
[E]
[D]
[R]
📄 quotaoff
[E]
[D]
[R]
📄 quotaon
[E]
[D]
[R]
📄 quotastats
[E]
[D]
[R]
📄 rcmysql
[E]
[D]
[R]
📄 rdisc
[E]
[D]
[R]
📄 rdma
[E]
[D]
[R]
📄 readprofile
[E]
[D]
[R]
📄 reboot
[E]
[D]
[R]
📄 repquota
[E]
[D]
[R]
📄 resize2fs
[E]
[D]
[R]
📄 resizepart
[E]
[D]
[R]
📄 restorecon
[E]
[D]
[R]
📄 rmmod
[E]
[D]
[R]
📄 rndc
[E]
[D]
[R]
📄 rndc-confgen
[E]
[D]
[R]
📄 route
[E]
[D]
[R]
📄 routef
[E]
[D]
[R]
📄 routel
[E]
[D]
[R]
📄 rpc.rquotad
[E]
[D]
[R]
📄 rpcbind
[E]
[D]
[R]
📄 rpcinfo
[E]
[D]
[R]
📄 rsyslogd
[E]
[D]
[R]
📄 rtacct
[E]
[D]
[R]
📄 rtcwake
[E]
[D]
[R]
📄 rtmon
[E]
[D]
[R]
📄 rtpr
[E]
[D]
[R]
📄 rtstat
[E]
[D]
[R]
📄 runlevel
[E]
[D]
[R]
📄 runuser
[E]
[D]
[R]
📄 safe_finger
[E]
[D]
[R]
📄 sasl2-shared-mechlist
[E]
[D]
[R]
📄 saslauthd
[E]
[D]
[R]
📄 sasldblistusers2
[E]
[D]
[R]
📄 saslpasswd2
[E]
[D]
[R]
📄 sefcontext_compile
[E]
[D]
[R]
📄 selabel_digest
[E]
[D]
[R]
📄 selabel_lookup
[E]
[D]
[R]
📄 selabel_lookup_best_match
[E]
[D]
[R]
📄 selabel_partial_match
[E]
[D]
[R]
📄 selinux_restorecon
[E]
[D]
[R]
📄 selinuxconlist
[E]
[D]
[R]
📄 selinuxdefcon
[E]
[D]
[R]
📄 selinuxenabled
[E]
[D]
[R]
📄 selinuxexeccon
[E]
[D]
[R]
📄 semanage
[E]
[D]
[R]
📄 semodule
[E]
[D]
[R]
📄 sendmail
[E]
[D]
[R]
📄 sendmail.postfix
[E]
[D]
[R]
📄 service
[E]
[D]
[R]
📄 sestatus
[E]
[D]
[R]
📄 setcap
[E]
[D]
[R]
📄 setenforce
[E]
[D]
[R]
📄 setfiles
[E]
[D]
[R]
📄 setquota
[E]
[D]
[R]
📄 setsebool
[E]
[D]
[R]
📄 sfdisk
[E]
[D]
[R]
📄 shutdown
[E]
[D]
[R]
📄 sim_server
[E]
[D]
[R]
📄 slattach
[E]
[D]
[R]
📄 sln
[E]
[D]
[R]
📄 smtp-sink
[E]
[D]
[R]
📄 smtp-source
[E]
[D]
[R]
📄 snmpd
[E]
[D]
[R]
📄 snmptrapd
[E]
[D]
[R]
📄 ss
[E]
[D]
[R]
📄 sshd
[E]
[D]
[R]
📄 sshd-keygen
[E]
[D]
[R]
📄 sulogin
[E]
[D]
[R]
📄 sushell
[E]
[D]
[R]
📄 swaplabel
[E]
[D]
[R]
📄 swapoff
[E]
[D]
[R]
📄 swapon
[E]
[D]
[R]
📄 switch_root
[E]
[D]
[R]
📄 sys-unconfig
[E]
[D]
[R]
📄 sysctl
[E]
[D]
[R]
📄 tc
[E]
[D]
[R]
📄 tcpd
[E]
[D]
[R]
📄 tcpdmatch
[E]
[D]
[R]
📄 tcsd
[E]
[D]
[R]
📄 telinit
[E]
[D]
[R]
📄 testsaslauthd
[E]
[D]
[R]
📄 tmpwatch
[E]
[D]
[R]
📄 tracepath
[E]
[D]
[R]
📄 tracepath6
[E]
[D]
[R]
📄 try-from
[E]
[D]
[R]
📄 tsig-keygen
[E]
[D]
[R]
📄 tune2fs
[E]
[D]
[R]
📄 tuned
[E]
[D]
[R]
📄 tuned-adm
[E]
[D]
[R]
📄 udevadm
[E]
[D]
[R]
📄 unix_chkpwd
[E]
[D]
[R]
📄 unix_update
[E]
[D]
[R]
📄 update-alternatives
[E]
[D]
[R]
📄 useradd
[E]
[D]
[R]
📄 userdel
[E]
[D]
[R]
📄 userhelper
[E]
[D]
[R]
📄 usermod
[E]
[D]
[R]
📄 usernetctl
[E]
[D]
[R]
📄 uuserver
[E]
[D]
[R]
📄 vigr
[E]
[D]
[R]
📄 vipw
[E]
[D]
[R]
📄 virt-what
[E]
[D]
[R]
📄 visudo
[E]
[D]
[R]
📄 vmcore-dmesg
[E]
[D]
[R]
📄 vpddecode
[E]
[D]
[R]
📄 weak-modules
[E]
[D]
[R]
📄 wipefs
[E]
[D]
[R]
📄 wpa_cli
[E]
[D]
[R]
📄 wpa_passphrase
[E]
[D]
[R]
📄 wpa_supplicant
[E]
[D]
[R]
📄 xfs_admin
[E]
[D]
[R]
📄 xfs_bmap
[E]
[D]
[R]
📄 xfs_copy
[E]
[D]
[R]
📄 xfs_db
[E]
[D]
[R]
📄 xfs_estimate
[E]
[D]
[R]
📄 xfs_freeze
[E]
[D]
[R]
📄 xfs_fsr
[E]
[D]
[R]
📄 xfs_growfs
[E]
[D]
[R]
📄 xfs_info
[E]
[D]
[R]
📄 xfs_io
[E]
[D]
[R]
📄 xfs_logprint
[E]
[D]
[R]
📄 xfs_mdrestore
[E]
[D]
[R]
📄 xfs_metadump
[E]
[D]
[R]
📄 xfs_mkfile
[E]
[D]
[R]
📄 xfs_ncheck
[E]
[D]
[R]
📄 xfs_quota
[E]
[D]
[R]
📄 xfs_repair
[E]
[D]
[R]
📄 xfs_rtcp
[E]
[D]
[R]
📄 xqmstats
[E]
[D]
[R]
📄 xtables-multi
[E]
[D]
[R]
📄 yum-complete-transaction
[E]
[D]
[R]
📄 yumdb
[E]
[D]
[R]
📄 zdump
[E]
[D]
[R]
📄 zic
[E]
[D]
[R]
📄 zramctl
[E]
[D]
[R]
Editing: fixfiles
#!/bin/bash # fixfiles # # Script to restore labels on a SELinux box # # Copyright (C) 2004-2013 Red Hat, Inc. # Authors: Dan Walsh <dwalsh@redhat.com> # # This program is free software; you can redistribute it and/or modify # it under the terms of the GNU General Public License as published by # the Free Software Foundation; either version 2 of the License, or # (at your option) any later version. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program; if not, write to the Free Software # Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA # # seclabel support was added in 2.6.30. This function will return a positive # number if the current kernel version is greater than 2.6.30, a negative # number if the current is less than 2.6.30 and 0 if they are the same. # function useseclabel { VER=`uname -r` SUP=2.6.30 expr '(' "$VER" : '\([^.]*\)' ')' '-' '(' "$SUP" : '\([^.]*\)' ')' '|' \ '(' "$VER.0" : '[^.]*[.]\([^.]*\)' ')' '-' '(' "$SUP.0" : '[^.]*[.]\([^.]*\)' ')' '|' \ '(' "$VER.0.0" : '[^.]*[.][^.]*[.]\([^.]*\)' ')' '-' '(' "$SUP.0.0" : '[^.]*[.][^.]*[.]\([^.]*\)' ')' } # # Get all mount points that support labeling. Use the 'seclabel' field if it # is available. Else fall back to known fs types which likely support xattrs # and we know were not context mounted. # get_all_labeled_mounts() { FS="`cat /proc/self/mounts | sort | uniq | awk '{print $2}'`" for i in $FS; do if [ `useseclabel` -ge 0 ] then grep " $i " /proc/self/mounts | awk '{print $4}' | egrep --silent '(^|,)seclabel(,|$)' && echo $i else grep " $i " /proc/self/mounts | grep -v "context=" | egrep --silent '(ext[234]| ext4dev | gfs2 | xfs | jfs | btrfs )' && echo $i fi done } get_rw_labeled_mounts() { FS=`get_all_labeled_mounts | sort | uniq` for i in $FS; do grep " $i " /proc/self/mounts | awk '{print $4}' | egrep --silent '(^|,)rw(,|$)' && echo $i done } get_ro_labeled_mounts() { FS=`get_all_labeled_mounts | sort | uniq` for i in $FS; do grep " $i " /proc/self/mounts | awk '{print $4}' | egrep --silent '(^|,)ro(,|$)' && echo $i done } # # Get the default label returned from the kernel for a file with a lable the # kernel does not understand # get_undefined_type() { SELINUXMNT=`grep selinuxfs /proc/self/mountinfo | head -1 | awk '{ print $5 }'` cat ${SELINUXMNT}/initial_contexts/unlabeled | secon -t } # # Get the default label for a file without a label # get_unlabeled_type() { SELINUXMNT=`grep selinuxfs /proc/self/mountinfo | head -1 | awk '{ print $5 }'` cat $SELINUXMNT/initial_contexts/file | secon -t } exclude_dirs_from_relabelling() { exclude_from_relabelling= if [ -e /etc/selinux/fixfiles_exclude_dirs ] then while read i do # skip blank line and comment # skip not absolute path # skip not directory [ -z "${i}" ] && continue [[ "${i}" =~ "^[[:blank:]]*#" ]] && continue [[ ! "${i}" =~ ^/.* ]] && continue [[ ! -d "${i}" ]] && continue exclude_from_relabelling="$exclude_from_relabelling -e $i" logit "skipping the directory $i" done < /etc/selinux/fixfiles_exclude_dirs fi echo "$exclude_from_relabelling" } exclude_dirs() { exclude= for i in /sys /proc /dev /run /mnt /var/tmp /var/lib/BackupPC /home /tmp /dev; do [ -e $i ] && exclude="$exclude -e $i"; done exclude="$exclude `exclude_dirs_from_relabelling`" echo "$exclude" } # # Set global Variables # fullFlag=0 BOOTTIME="" VERBOSE="-p" [ -t 1 ] || VERBOSE="" FORCEFLAG="" DIRS="" RPMILES="" LOGFILE=`tty` if [ $? != 0 ]; then LOGFILE="/dev/null" fi LOGGER=/usr/sbin/logger SETFILES=/sbin/setfiles RESTORECON=/sbin/restorecon FILESYSTEMSRW=`get_rw_labeled_mounts` FILESYSTEMSRO=`get_ro_labeled_mounts` FILESYSTEMS="$FILESYSTEMSRW $FILESYSTEMSRO" SELINUXTYPE="targeted" if [ -e /etc/selinux/config ]; then . /etc/selinux/config FC=/etc/selinux/${SELINUXTYPE}/contexts/files/file_contexts else FC=/etc/security/selinux/file_contexts fi FC_SUB_DIST=${FC}.subs_dist FC_SUB=${FC}.subs FC_HOMEDIRS=${FC}.homedirs FC_LOCAL=${FC}.local # # Log to either syslog or a LOGFILE # logit () { if [ -n $LOGFILE ]; then echo $1 >> $LOGFILE fi } # # Find files newer then the passed in date and fix the label # newer() { DATE=$1 shift for m in `echo $FILESYSTEMSRW`; do find $m -mount -newermt $DATE -print0 2>/dev/null | ${RESTORECON} ${FORCEFLAG} ${VERBOSE} $* -i -0 -f - done; } # # Compare PREVious File Context to currently installed File Context and # run restorecon on all files affected by the differences. # diff_filecontext() { if [ -f ${PREFC} -a -x /usr/bin/diff ]; then TEMPFILE=`mktemp ${FC}.XXXXXXXXXX` test -z "$TEMPFILE" && exit PREFCTEMPFILE=`mktemp ${PREFC}.XXXXXXXXXX` sed -r -e 's,:s0, ,g' $PREFC | sort -u > ${PREFCTEMPFILE} sed -r -e 's,:s0, ,g' $FC | sort -u | \ /usr/bin/diff -b ${PREFCTEMPFILE} - | \ grep '^[<>]'|cut -c3-| grep ^/ | \ egrep -v '(^/home|^/root|^/tmp|^/dev)' |\ sed -r -e 's,[[:blank:]].*,,g' \ -e 's|\(([/[:alnum:]]+)\)\?|{\1,}|g' \ -e 's|([/[:alnum:]])\?|{\1,}|g' \ -e 's|\?.*|*|g' \ -e 's|\{.*|*|g' \ -e 's|\(.*|*|g' \ -e 's|\[.*|*|g' \ -e 's|\.\*.*|*|g' \ -e 's|\.\+.*|*|g' | \ # These two sorts need to be separate commands \ sort -u | \ sort -d | \ while read pattern ; \ do if ! echo "$pattern" | grep -q -f ${TEMPFILE} 2>/dev/null; then \ echo "$pattern"; \ case "$pattern" in *"*") \ echo "$pattern" | sed -e 's,^,^,' -e 's,\*$,,g' >> ${TEMPFILE};; esac; \ fi; \ done | \ ${RESTORECON} ${VERBOSE} -i -f - -R $* `exclude_dirs`; \ rm -f ${TEMPFILE} ${PREFCTEMPFILE} fi } # # Log all Read Only file systems # LogReadOnly() { if [ ! -z "$FILESYSTEMSRO" ]; then logit "Warning: Skipping the following R/O filesystems:" logit "$FILESYSTEMSRO" fi } rpmlist() { rpm -q --qf '[%{FILESTATES} %{FILENAMES}\n]' "$1" | grep '^0 ' | cut -f2- -d ' ' [ ${PIPESTATUS[0]} != 0 ] && echo "$1 not found" >/dev/stderr } # # restore # if called with -n will only check file context # restore () { OPTION=$1 shift if [ ! -z "$PREFC" ]; then diff_filecontext $* exit $? fi if [ ! -z "$BOOTTIME" ]; then newer $BOOTTIME $* exit $? fi [ -x /usr/sbin/genhomedircon ] && /usr/sbin/genhomedircon LogReadOnly # exclude_dirs="`exclude_dirs_from_relabelling $OPTION`" if [ -n "${exclude_dirs}" ] then TEMPFCFILE=`mktemp ${FC}.XXXXXXXXXX` test -z "$TEMPFCFILE" && exit /bin/cp -p ${FC} ${TEMPFCFILE} &>/dev/null || exit tmpdirs=${tempdirs//-e/} for p in ${tmpdirs} do p="${p%/}" p1="${p}(/.*)? -- <<none>>" echo "${p1}" >> $TEMPFCFILE logit "skipping the directory ${p}" done FC=$TEMPFCFILE /bin/cp -p ${FC_SUB_DIST} ${TEMPFCFILE}.subs_dist &>/dev/null || exit /bin/cp -p ${FC_SUB} ${TEMPFCFILE}.subs &>/dev/null || exit /bin/cp -p ${FC_HOMEDIRS} ${TEMPFCFILE}.homedirs &>/dev/null || exit # file_contexts.local does not always exist /bin/cp -p ${FC_LOCAL} ${TEMPFCFILE}.local &>/dev/null fi if [ ! -z "$RPMFILES" ]; then for i in `echo "$RPMFILES" | sed 's/,/ /g'`; do rpmlist $i | ${RESTORECON} $exclude_dirs ${FORCEFLAG} ${VERBOSE} $* -R -i -f - 2>&1 | cat >> $LOGFILE done exit $? fi if [ ! -z "$FILEPATH" ]; then ${RESTORECON} $exclude_dirs ${FORCEFLAG} ${VERBOSE} -R $* "$FILEPATH" 2>&1 | cat >> $LOGFILE return fi if [ -n "${FILESYSTEMSRW}" ]; then echo "${OPTION}ing `echo ${FILESYSTEMSRW}`" ${SETFILES} ${VERBOSE} $exclude_dirs -q ${FORCEFLAG} $* ${FC} ${FILESYSTEMSRW} 2>&1 | cat >> $LOGFILE else echo >&2 "fixfiles: No suitable file systems found" fi if [ ${OPTION} != "Relabel" ]; then return fi echo "Cleaning up labels on /tmp" rm -rf /tmp/gconfd-* /tmp/pulse-* /tmp/orbit-* $TEMPFCFILE ${TEMPFCFILE}.subs_dist ${TEMPFCFILE}.subs ${TEMPFCFILE}.homedirs ${TEMPFCFILE}.local UNDEFINED=`get_undefined_type` || exit $? UNLABELED=`get_unlabeled_type` || exit $? find /tmp \( -context "*:${UNLABELED}*" -o -context "*:${UNDEFINED}*" \) \( -type s -o -type p \) -delete find /tmp \( -context "*:${UNLABELED}*" -o -context "*:${UNDEFINED}*" \) -exec chcon --no-dereference --reference /tmp {} \; find /var/tmp \( -context "*:${UNLABELED}*" -o -context "*:${UNDEFINED}*" \) -exec chcon --no-dereference --reference /var/tmp {} \; find /var/run \( -context "*:${UNLABELED}*" -o -context "*:${UNDEFINED}*" \) -exec chcon --no-dereference --reference /var/run {} \; [ ! -e /var/lib/debug ] || find /var/lib/debug \( -context "*:${UNLABELED}*" -o -context "*:${UNDEFINED}*" \) -exec chcon --no-dereference --reference /lib {} \; exit 0 } fullrelabel() { logit "Cleaning out /tmp" find /tmp/ -mindepth 1 -delete LogReadOnly restore Relabel } relabel() { if [ ! -z "$RPMFILES" ]; then restore Relabel fi if [ $fullFlag == 1 ]; then fullrelabel fi echo -n " Files in the /tmp directory may be labeled incorrectly, this command can remove all files in /tmp. If you choose to remove files from /tmp, a reboot will be required after completion. Do you wish to clean out the /tmp directory [N]? " read answer if [ "$answer" = y -o "$answer" = Y ]; then fullrelabel else restore Relabel fi } process() { # # Make sure they specified one of the three valid commands # case "$1" in restore) restore Relabel;; check) VERBOSE="-v"; restore Check -n;; verify) restore Verify -n -o -;; relabel) relabel;; onboot) > /.autorelabel [ -z "$FORCEFLAG" ] || echo -n "$FORCEFLAG " >> /.autorelabel [ -z "$BOOTTIME" ] || echo -N $BOOTTIME >> /.autorelabel # Force full relabel if / does not have a label on it getfilecon / > /dev/null 2>&1 || echo -F >/.autorelabel echo "System will relabel on next boot" ;; *) usage exit 1 esac } usage() { echo $""" Usage: $0 [-v] [-F] [-N time ] [-l logfile ] { check | restore| [-f] relabel | verify } [[dir/file] ... ] or Usage: $0 [-v] [-F] -R rpmpackage[,rpmpackage...] [-l logfile ] { check | restore | verify } or Usage: $0 [-v] [-F] -C PREVIOUS_FILECONTEXT { check | restore | verify } or Usage: $0 [-F] [-B] onboot """ } if [ $# = 0 ]; then usage exit 1 fi # See how we were called. while getopts "N:BC:FfR:l:v" i; do case "$i" in B) BOOTTIME=`/bin/who -b | awk '{print $3}'` ;; f) fullFlag=1 ;; v) VERBOSE="-v" ;; R) RPMFILES=$OPTARG ;; l) LOGFILE=$OPTARG ;; C) PREFC=$OPTARG ;; F) FORCEFLAG="-F" ;; N) BOOTTIME=$OPTARG ;; *) usage exit 1 esac done # Move out processed options from arguments shift $(( OPTIND - 1 )) # Check for the command command=$1 if [ -z $command ]; then usage fi # Move out command from arguments shift # # check if they specified both DIRS and RPMFILES # if [ ! -z "$RPMFILES" ]; then process $command if [ $# -gt 0 ]; then usage fi else if [ -z "$1" ]; then process $command else while [ -n "$1" ]; do FILEPATH=$1 process $command shift done fi fi exit $?
Save