File: do-avc-work

package info (click to toggle)
pcp 7.1.0-1
  • links: PTS
  • area: main
  • in suites: forky, sid
  • size: 252,748 kB
  • sloc: ansic: 1,483,656; sh: 182,366; xml: 160,462; cpp: 83,813; python: 24,980; perl: 18,327; yacc: 6,877; lex: 2,864; makefile: 2,738; awk: 165; fortran: 60; java: 52
file content (36 lines) | stat: -rwxr-xr-x 573 bytes parent folder | download | duplicates (4)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
#!/bin/sh
#
# take type=AVC lines from a .out.bad file and do the necessary
# SELinux magic ...
#
#

tmp=/var/tmp/$$
trap "rm -f $tmp.*; exit 0" 0 1 2 3 15

if [ $# != 1 ]
then
    echo "Usage: avc-do-work seq"
    exit
fi

seq=$1

if [ ! -f $seq.out.bad ]
then
    echo "Error: no $seq.out.bad file"
    exit
fi

grep '^type=AVC' $seq.out.bad \
| sed \
    -e "s/msg=audit([^)]*):/msg=audit(qa\/$seq)/" \
    -e 's/pid=[0-9][0-9]*/pid=1/' \
    -e 's/name=\"[^"]*"/name="???"/' \
| sort \
| uniq >$tmp.avc

sed -e 's/^/# /' <$tmp.avc

cat $tmp.avc | audit2allow -m pcpqa