Manage selinux context of tftp directory

- Fixes: #1997

Signed-off-by: Jonathon Anderson <janderson@ciq.com>
This commit is contained in:
Jonathon Anderson
2025-10-29 13:09:30 -06:00
parent 9a94d1f2b1
commit be97ef15a0
10 changed files with 179 additions and 35 deletions

View File

@@ -0,0 +1,34 @@
package util
import (
"fmt"
"os/exec"
"strings"
"github.com/opencontainers/selinux/go-selinux"
"github.com/warewulf/warewulf/internal/pkg/wwlog"
)
// RestoreSELinuxContext restores the SELinux context for a path and all its children
// based on the system's SELinux policy, equivalent to running restorecon -R
func RestoreSELinuxContext(rootPath string) error {
if !selinux.GetEnabled() {
wwlog.Debug("SELinux not enabled, skipping context restoration")
return nil
}
wwlog.Info("Restoring SELinux contexts for: %s", rootPath)
cmd := exec.Command("restorecon", "-vR", rootPath)
output, err := cmd.CombinedOutput()
if err != nil {
return fmt.Errorf("restorecon failed: %w: %s", err, string(output))
}
for _, line := range strings.Split(strings.TrimSpace(string(output)), "\n") {
if line != "" {
wwlog.Debug("restorecon output: %s", line)
}
}
return nil
}