Blame SOURCES/7.4.238

22c937
To: vim_dev@googlegroups.com
22c937
Subject: Patch 7.4.238
22c937
Fcc: outbox
22c937
From: Bram Moolenaar <Bram@moolenaar.net>
22c937
Mime-Version: 1.0
22c937
Content-Type: text/plain; charset=UTF-8
22c937
Content-Transfer-Encoding: 8bit
22c937
------------
22c937
22c937
Patch 7.4.238
22c937
Problem:    Vim does not support the smack library.
22c937
Solution:   Add smack support (Jose Bollo)
22c937
Files:	    src/config.h.in, src/configure.in, src/fileio.c, src/memfile.c,
22c937
	    src/os_unix.c, src/undo.c, src/auto/configure
22c937
22c937
22c937
*** ../vim-7.4.237/src/config.h.in	2014-02-23 22:52:33.364764715 +0100
22c937
--- src/config.h.in	2014-04-02 13:37:41.095910851 +0200
22c937
***************
22c937
*** 191,196 ****
22c937
--- 191,197 ----
22c937
  #undef HAVE_SIGSETJMP
22c937
  #undef HAVE_SIGSTACK
22c937
  #undef HAVE_SIGVEC
22c937
+ #undef HAVE_SMACK
22c937
  #undef HAVE_STRCASECMP
22c937
  #undef HAVE_STRERROR
22c937
  #undef HAVE_STRFTIME
22c937
*** ../vim-7.4.237/src/configure.in	2014-03-27 18:51:06.604760919 +0100
22c937
--- src/configure.in	2014-04-02 13:49:36.955901004 +0200
22c937
***************
22c937
*** 387,406 ****
22c937
  AC_SUBST(QUOTESED)
22c937
  
22c937
  
22c937
! dnl Link with -lselinux for SELinux stuff; if not found
22c937
! AC_MSG_CHECKING(--disable-selinux argument)
22c937
! AC_ARG_ENABLE(selinux,
22c937
! 	[  --disable-selinux	  Don't check for SELinux support.],
22c937
! 	, enable_selinux="yes")
22c937
! if test "$enable_selinux" = "yes"; then
22c937
    AC_MSG_RESULT(no)
22c937
!   AC_CHECK_LIB(selinux, is_selinux_enabled,
22c937
! 	  [LIBS="$LIBS -lselinux"
22c937
! 	   AC_DEFINE(HAVE_SELINUX)])
22c937
  else
22c937
     AC_MSG_RESULT(yes)
22c937
  fi
22c937
  
22c937
  dnl Check user requested features.
22c937
  
22c937
  AC_MSG_CHECKING(--with-features argument)
22c937
--- 387,427 ----
22c937
  AC_SUBST(QUOTESED)
22c937
  
22c937
  
22c937
! dnl Link with -lsmack for Smack stuff; if not found
22c937
! AC_MSG_CHECKING(--disable-smack argument)
22c937
! AC_ARG_ENABLE(smack,
22c937
! 	[  --disable-smack	  Do not check for Smack support.],
22c937
! 	, enable_smack="yes")
22c937
! if test "$enable_smack" = "yes"; then
22c937
!   AC_CHECK_HEADER([linux/xattr.h], true, enable_smack="no")
22c937
! fi
22c937
! if test "$enable_smack" = "yes"; then
22c937
    AC_MSG_RESULT(no)
22c937
!   AC_CHECK_LIB(attr, llistxattr,
22c937
! 	  [LIBS="$LIBS -lattr"
22c937
! 	   found_smack="yes"
22c937
! 	   AC_DEFINE(HAVE_SMACK)])
22c937
  else
22c937
     AC_MSG_RESULT(yes)
22c937
  fi
22c937
  
22c937
+ dnl When smack was found don't search for SELinux
22c937
+ if test "x$found_smack" = "x"; then
22c937
+   dnl Link with -lselinux for SELinux stuff; if not found
22c937
+   AC_MSG_CHECKING(--disable-selinux argument)
22c937
+   AC_ARG_ENABLE(selinux,
22c937
+ 	  [  --disable-selinux	  Do not check for SELinux support.],
22c937
+ 	  , enable_selinux="yes")
22c937
+   if test "$enable_selinux" = "yes"; then
22c937
+     AC_MSG_RESULT(no)
22c937
+     AC_CHECK_LIB(selinux, is_selinux_enabled,
22c937
+ 	    [LIBS="$LIBS -lselinux"
22c937
+ 	     AC_DEFINE(HAVE_SELINUX)])
22c937
+   else
22c937
+      AC_MSG_RESULT(yes)
22c937
+   fi
22c937
+ fi
22c937
+ 
22c937
  dnl Check user requested features.
22c937
  
22c937
  AC_MSG_CHECKING(--with-features argument)
22c937
*** ../vim-7.4.237/src/fileio.c	2014-03-12 16:51:35.056792541 +0100
22c937
--- src/fileio.c	2014-04-02 13:39:28.983909367 +0200
22c937
***************
22c937
*** 4030,4036 ****
22c937
  						)
22c937
  			    mch_setperm(backup,
22c937
  					  (perm & 0707) | ((perm & 07) << 3));
22c937
! # ifdef HAVE_SELINUX
22c937
  			mch_copy_sec(fname, backup);
22c937
  # endif
22c937
  #endif
22c937
--- 4030,4036 ----
22c937
  						)
22c937
  			    mch_setperm(backup,
22c937
  					  (perm & 0707) | ((perm & 07) << 3));
22c937
! # if defined(HAVE_SELINUX) || defined(HAVE_SMACK)
22c937
  			mch_copy_sec(fname, backup);
22c937
  # endif
22c937
  #endif
22c937
***************
22c937
*** 4069,4075 ****
22c937
  #ifdef HAVE_ACL
22c937
  			mch_set_acl(backup, acl);
22c937
  #endif
22c937
! #ifdef HAVE_SELINUX
22c937
  			mch_copy_sec(fname, backup);
22c937
  #endif
22c937
  			break;
22c937
--- 4069,4075 ----
22c937
  #ifdef HAVE_ACL
22c937
  			mch_set_acl(backup, acl);
22c937
  #endif
22c937
! #if defined(HAVE_SELINUX) || defined(HAVE_SMACK)
22c937
  			mch_copy_sec(fname, backup);
22c937
  #endif
22c937
  			break;
22c937
***************
22c937
*** 4718,4724 ****
22c937
      }
22c937
  #endif
22c937
  
22c937
! #ifdef HAVE_SELINUX
22c937
      /* Probably need to set the security context. */
22c937
      if (!backup_copy)
22c937
  	mch_copy_sec(backup, wfname);
22c937
--- 4718,4724 ----
22c937
      }
22c937
  #endif
22c937
  
22c937
! #if defined(HAVE_SELINUX) || defined(HAVE_SMACK)
22c937
      /* Probably need to set the security context. */
22c937
      if (!backup_copy)
22c937
  	mch_copy_sec(backup, wfname);
22c937
***************
22c937
*** 6707,6713 ****
22c937
      mch_set_acl(to, acl);
22c937
      mch_free_acl(acl);
22c937
  #endif
22c937
! #ifdef HAVE_SELINUX
22c937
      mch_copy_sec(from, to);
22c937
  #endif
22c937
      if (errmsg != NULL)
22c937
--- 6707,6713 ----
22c937
      mch_set_acl(to, acl);
22c937
      mch_free_acl(acl);
22c937
  #endif
22c937
! #if defined(HAVE_SELINUX) || defined(HAVE_SMACK)
22c937
      mch_copy_sec(from, to);
22c937
  #endif
22c937
      if (errmsg != NULL)
22c937
*** ../vim-7.4.237/src/memfile.c	2013-05-23 22:22:22.000000000 +0200
22c937
--- src/memfile.c	2014-04-02 13:37:41.103910851 +0200
22c937
***************
22c937
*** 1358,1364 ****
22c937
  	if (fdflags >= 0 && (fdflags & FD_CLOEXEC) == 0)
22c937
  	    fcntl(mfp->mf_fd, F_SETFD, fdflags | FD_CLOEXEC);
22c937
  #endif
22c937
! #ifdef HAVE_SELINUX
22c937
  	mch_copy_sec(fname, mfp->mf_fname);
22c937
  #endif
22c937
  	mch_hide(mfp->mf_fname);    /* try setting the 'hidden' flag */
22c937
--- 1358,1364 ----
22c937
  	if (fdflags >= 0 && (fdflags & FD_CLOEXEC) == 0)
22c937
  	    fcntl(mfp->mf_fd, F_SETFD, fdflags | FD_CLOEXEC);
22c937
  #endif
22c937
! #if defined(HAVE_SELINUX) || defined(HAVE_SMACK)
22c937
  	mch_copy_sec(fname, mfp->mf_fname);
22c937
  #endif
22c937
  	mch_hide(mfp->mf_fname);    /* try setting the 'hidden' flag */
22c937
*** ../vim-7.4.237/src/os_unix.c	2014-04-01 21:00:45.436733663 +0200
22c937
--- src/os_unix.c	2014-04-02 13:58:55.427893322 +0200
22c937
***************
22c937
*** 46,51 ****
22c937
--- 46,59 ----
22c937
  static int selinux_enabled = -1;
22c937
  #endif
22c937
  
22c937
+ #ifdef HAVE_SMACK
22c937
+ # include <attr/xattr.h>
22c937
+ # include <linux/xattr.h>
22c937
+ # ifndef SMACK_LABEL_LEN
22c937
+ #  define SMACK_LABEL_LEN 1024
22c937
+ # endif
22c937
+ #endif
22c937
+ 
22c937
  /*
22c937
   * Use this prototype for select, some include files have a wrong prototype
22c937
   */
22c937
***************
22c937
*** 2798,2803 ****
22c937
--- 2806,2895 ----
22c937
  }
22c937
  #endif /* HAVE_SELINUX */
22c937
  
22c937
+ #if defined(HAVE_SMACK) && !defined(PROTO)
22c937
+ /*
22c937
+  * Copy security info from "from_file" to "to_file".
22c937
+  */
22c937
+     void
22c937
+ mch_copy_sec(from_file, to_file)
22c937
+     char_u	*from_file;
22c937
+     char_u	*to_file;
22c937
+ {
22c937
+     static const char const *smack_copied_attributes[] =
22c937
+ 	{
22c937
+ 	    XATTR_NAME_SMACK,
22c937
+ 	    XATTR_NAME_SMACKEXEC,
22c937
+ 	    XATTR_NAME_SMACKMMAP
22c937
+ 	};
22c937
+ 
22c937
+     char	buffer[SMACK_LABEL_LEN];
22c937
+     const char	*name;
22c937
+     int		index;
22c937
+     int		ret;
22c937
+     ssize_t	size;
22c937
+ 
22c937
+     if (from_file == NULL)
22c937
+ 	return;
22c937
+ 
22c937
+     for (index = 0 ; index < (int)(sizeof(smack_copied_attributes)
22c937
+ 			      / sizeof(smack_copied_attributes)[0]) ; index++)
22c937
+     {
22c937
+ 	/* get the name of the attribute to copy */
22c937
+ 	name = smack_copied_attributes[index];
22c937
+ 
22c937
+ 	/* get the value of the attribute in buffer */
22c937
+ 	size = getxattr((char*)from_file, name, buffer, sizeof(buffer));
22c937
+ 	if (size >= 0)
22c937
+ 	{
22c937
+ 	    /* copy the attribute value of buffer */
22c937
+ 	    ret = setxattr((char*)to_file, name, buffer, (size_t)size, 0);
22c937
+ 	    if (ret < 0)
22c937
+ 	    {
22c937
+ 		MSG_PUTS(_("Could not set security context "));
22c937
+ 		MSG_PUTS(name);
22c937
+ 		MSG_PUTS(_(" for "));
22c937
+ 		msg_outtrans(to_file);
22c937
+ 		msg_putchar('\n');
22c937
+ 	    }
22c937
+ 	}
22c937
+ 	else
22c937
+ 	{
22c937
+ 	    /* what reason of not having the attribute value? */
22c937
+ 	    switch (errno)
22c937
+ 	    {
22c937
+ 		case ENOTSUP:
22c937
+ 		    /* extended attributes aren't supported or enabled */
22c937
+ 		    /* should a message be echoed? not sure... */
22c937
+ 		    return; /* leave because it isn't usefull to continue */
22c937
+ 
22c937
+ 		case ERANGE:
22c937
+ 		default:
22c937
+ 		    /* no enough size OR unexpected error */
22c937
+ 		    MSG_PUTS(_("Could not get security context "));
22c937
+ 		    MSG_PUTS(name);
22c937
+ 		    MSG_PUTS(_(" for "));
22c937
+ 		    msg_outtrans(from_file);
22c937
+ 		    MSG_PUTS(_(". Removing it!\n"));
22c937
+ 		    /* FALLTHROUGH to remove the attribute */
22c937
+ 
22c937
+ 		case ENODATA:
22c937
+ 		    /* no attribute of this name */
22c937
+ 		    ret = removexattr((char*)to_file, name);
22c937
+ 		    if (ret < 0 && errno != ENODATA)
22c937
+ 		    {
22c937
+ 			MSG_PUTS(_("Could not remove security context "));
22c937
+ 			MSG_PUTS(name);
22c937
+ 			MSG_PUTS(_(" for "));
22c937
+ 			msg_outtrans(to_file);
22c937
+ 			msg_putchar('\n');
22c937
+ 		    }
22c937
+ 		    break;
22c937
+ 	    }
22c937
+ 	}
22c937
+     }
22c937
+ }
22c937
+ #endif /* HAVE_SMACK */
22c937
+ 
22c937
  /*
22c937
   * Return a pointer to the ACL of file "fname" in allocated memory.
22c937
   * Return NULL if the ACL is not available for whatever reason.
22c937
*** ../vim-7.4.237/src/undo.c	2014-03-23 15:12:29.943264337 +0100
22c937
--- src/undo.c	2014-04-02 13:42:15.387907078 +0200
22c937
***************
22c937
*** 1455,1461 ****
22c937
  # endif
22c937
         )
22c937
  	mch_setperm(file_name, (perm & 0707) | ((perm & 07) << 3));
22c937
! # ifdef HAVE_SELINUX
22c937
      if (buf->b_ffname != NULL)
22c937
  	mch_copy_sec(buf->b_ffname, file_name);
22c937
  # endif
22c937
--- 1455,1461 ----
22c937
  # endif
22c937
         )
22c937
  	mch_setperm(file_name, (perm & 0707) | ((perm & 07) << 3));
22c937
! # if defined(HAVE_SELINUX) || defined(HAVE_SMACK)
22c937
      if (buf->b_ffname != NULL)
22c937
  	mch_copy_sec(buf->b_ffname, file_name);
22c937
  # endif
22c937
*** ../vim-7.4.237/src/auto/configure	2014-03-27 18:51:06.612760919 +0100
22c937
--- src/auto/configure	2014-04-02 13:50:11.375900531 +0200
22c937
***************
22c937
*** 782,787 ****
22c937
--- 782,788 ----
22c937
  with_view_name
22c937
  with_global_runtime
22c937
  with_modified_by
22c937
+ enable_smack
22c937
  enable_selinux
22c937
  with_features
22c937
  with_compiledby
22c937
***************
22c937
*** 1453,1459 ****
22c937
    --enable-fail-if-missing    Fail if dependencies on additional features
22c937
       specified on the command line are missing.
22c937
    --disable-darwin        Disable Darwin (Mac OS X) support.
22c937
!   --disable-selinux	  Don't check for SELinux support.
22c937
    --disable-xsmp          Disable XSMP session management
22c937
    --disable-xsmp-interact Disable XSMP interaction
22c937
    --enable-luainterp=OPTS     Include Lua interpreter.  default=no OPTS=no/yes/dynamic
22c937
--- 1454,1461 ----
22c937
    --enable-fail-if-missing    Fail if dependencies on additional features
22c937
       specified on the command line are missing.
22c937
    --disable-darwin        Disable Darwin (Mac OS X) support.
22c937
!   --disable-smack	  Do not check for Smack support.
22c937
!   --disable-selinux	  Do not check for SELinux support.
22c937
    --disable-xsmp          Disable XSMP session management
22c937
    --disable-xsmp-interact Disable XSMP interaction
22c937
    --enable-luainterp=OPTS     Include Lua interpreter.  default=no OPTS=no/yes/dynamic
22c937
***************
22c937
*** 4588,4606 ****
22c937
  
22c937
  
22c937
  
22c937
! { $as_echo "$as_me:${as_lineno-$LINENO}: checking --disable-selinux argument" >&5
22c937
  $as_echo_n "checking --disable-selinux argument... " >&6; }
22c937
! # Check whether --enable-selinux was given.
22c937
  if test "${enable_selinux+set}" = set; then :
22c937
    enableval=$enable_selinux;
22c937
  else
22c937
    enable_selinux="yes"
22c937
  fi
22c937
  
22c937
! if test "$enable_selinux" = "yes"; then
22c937
!   { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
22c937
  $as_echo "no" >&6; }
22c937
!   { $as_echo "$as_me:${as_lineno-$LINENO}: checking for is_selinux_enabled in -lselinux" >&5
22c937
  $as_echo_n "checking for is_selinux_enabled in -lselinux... " >&6; }
22c937
  if ${ac_cv_lib_selinux_is_selinux_enabled+:} false; then :
22c937
    $as_echo_n "(cached) " >&6
22c937
--- 4590,4679 ----
22c937
  
22c937
  
22c937
  
22c937
! { $as_echo "$as_me:${as_lineno-$LINENO}: checking --disable-smack argument" >&5
22c937
! $as_echo_n "checking --disable-smack argument... " >&6; }
22c937
! # Check whether --enable-smack was given.
22c937
! if test "${enable_smack+set}" = set; then :
22c937
!   enableval=$enable_smack;
22c937
! else
22c937
!   enable_smack="yes"
22c937
! fi
22c937
! 
22c937
! if test "$enable_smack" = "yes"; then
22c937
!   ac_fn_c_check_header_mongrel "$LINENO" "linux/xattr.h" "ac_cv_header_linux_xattr_h" "$ac_includes_default"
22c937
! if test "x$ac_cv_header_linux_xattr_h" = xyes; then :
22c937
!   true
22c937
! else
22c937
!   enable_smack="no"
22c937
! fi
22c937
! 
22c937
! 
22c937
! fi
22c937
! if test "$enable_smack" = "yes"; then
22c937
!   { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
22c937
! $as_echo "no" >&6; }
22c937
!   { $as_echo "$as_me:${as_lineno-$LINENO}: checking for llistxattr in -lattr" >&5
22c937
! $as_echo_n "checking for llistxattr in -lattr... " >&6; }
22c937
! if ${ac_cv_lib_attr_llistxattr+:} false; then :
22c937
!   $as_echo_n "(cached) " >&6
22c937
! else
22c937
!   ac_check_lib_save_LIBS=$LIBS
22c937
! LIBS="-lattr  $LIBS"
22c937
! cat confdefs.h - <<_ACEOF >conftest.$ac_ext
22c937
! /* end confdefs.h.  */
22c937
! 
22c937
! /* Override any GCC internal prototype to avoid an error.
22c937
!    Use char because int might match the return type of a GCC
22c937
!    builtin and then its argument prototype would still apply.  */
22c937
! #ifdef __cplusplus
22c937
! extern "C"
22c937
! #endif
22c937
! char llistxattr ();
22c937
! int
22c937
! main ()
22c937
! {
22c937
! return llistxattr ();
22c937
!   ;
22c937
!   return 0;
22c937
! }
22c937
! _ACEOF
22c937
! if ac_fn_c_try_link "$LINENO"; then :
22c937
!   ac_cv_lib_attr_llistxattr=yes
22c937
! else
22c937
!   ac_cv_lib_attr_llistxattr=no
22c937
! fi
22c937
! rm -f core conftest.err conftest.$ac_objext \
22c937
!     conftest$ac_exeext conftest.$ac_ext
22c937
! LIBS=$ac_check_lib_save_LIBS
22c937
! fi
22c937
! { $as_echo "$as_me:${as_lineno-$LINENO}: result: $ac_cv_lib_attr_llistxattr" >&5
22c937
! $as_echo "$ac_cv_lib_attr_llistxattr" >&6; }
22c937
! if test "x$ac_cv_lib_attr_llistxattr" = xyes; then :
22c937
!   LIBS="$LIBS -lattr"
22c937
! 	   found_smack="yes"
22c937
! 	   $as_echo "#define HAVE_SMACK 1" >>confdefs.h
22c937
! 
22c937
! fi
22c937
! 
22c937
! else
22c937
!    { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
22c937
! $as_echo "yes" >&6; }
22c937
! fi
22c937
! 
22c937
! if test "x$found_smack" = "x"; then
22c937
!     { $as_echo "$as_me:${as_lineno-$LINENO}: checking --disable-selinux argument" >&5
22c937
  $as_echo_n "checking --disable-selinux argument... " >&6; }
22c937
!   # Check whether --enable-selinux was given.
22c937
  if test "${enable_selinux+set}" = set; then :
22c937
    enableval=$enable_selinux;
22c937
  else
22c937
    enable_selinux="yes"
22c937
  fi
22c937
  
22c937
!   if test "$enable_selinux" = "yes"; then
22c937
!     { $as_echo "$as_me:${as_lineno-$LINENO}: result: no" >&5
22c937
  $as_echo "no" >&6; }
22c937
!     { $as_echo "$as_me:${as_lineno-$LINENO}: checking for is_selinux_enabled in -lselinux" >&5
22c937
  $as_echo_n "checking for is_selinux_enabled in -lselinux... " >&6; }
22c937
  if ${ac_cv_lib_selinux_is_selinux_enabled+:} false; then :
22c937
    $as_echo_n "(cached) " >&6
22c937
***************
22c937
*** 4638,4650 ****
22c937
  $as_echo "$ac_cv_lib_selinux_is_selinux_enabled" >&6; }
22c937
  if test "x$ac_cv_lib_selinux_is_selinux_enabled" = xyes; then :
22c937
    LIBS="$LIBS -lselinux"
22c937
! 	   $as_echo "#define HAVE_SELINUX 1" >>confdefs.h
22c937
  
22c937
  fi
22c937
  
22c937
! else
22c937
!    { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
22c937
  $as_echo "yes" >&6; }
22c937
  fi
22c937
  
22c937
  
22c937
--- 4711,4724 ----
22c937
  $as_echo "$ac_cv_lib_selinux_is_selinux_enabled" >&6; }
22c937
  if test "x$ac_cv_lib_selinux_is_selinux_enabled" = xyes; then :
22c937
    LIBS="$LIBS -lselinux"
22c937
! 	     $as_echo "#define HAVE_SELINUX 1" >>confdefs.h
22c937
  
22c937
  fi
22c937
  
22c937
!   else
22c937
!      { $as_echo "$as_me:${as_lineno-$LINENO}: result: yes" >&5
22c937
  $as_echo "yes" >&6; }
22c937
+   fi
22c937
  fi
22c937
  
22c937
  
22c937
*** ../vim-7.4.237/src/version.c	2014-04-02 12:12:04.163981514 +0200
22c937
--- src/version.c	2014-04-02 13:38:22.511910282 +0200
22c937
***************
22c937
*** 736,737 ****
22c937
--- 736,739 ----
22c937
  {   /* Add new patch number below this line */
22c937
+ /**/
22c937
+     238,
22c937
  /**/
22c937
22c937
-- 
22c937
hundred-and-one symptoms of being an internet addict:
22c937
25. You believe nothing looks sexier than a man in boxer shorts illuminated
22c937
    only by a 17" inch svga monitor.
22c937
22c937
 /// Bram Moolenaar -- Bram@Moolenaar.net -- http://www.Moolenaar.net   \\\
22c937
///        sponsor Vim, vote for features -- http://www.Vim.org/sponsor/ \\\
22c937
\\\  an exciting new programming language -- http://www.Zimbu.org        ///
22c937
 \\\            help me help AIDS victims -- http://ICCF-Holland.org    ///