1 Star 0 Fork 0

zhuchance/kubernetes

加入 Gitee
与超过 1200万 开发者一起发现、参与优秀开源项目,私有仓库也完全免费 :)
免费加入
文件
.github
Godeps
api
build
cluster
cmd
docs
examples
federation
hack
logo
pkg
api
apimachinery/tests
apis
auth
bootstrap/api
capabilities
client
cloudprovider
controller
credentialprovider
features
fieldpath
generated
hyperkube
kubeapiserver
kubectl
kubelet
kubemark
master
printers
probe
proxy
quota
registry
routes
security
securitycontext
serviceaccount
ssh
util
async
bandwidth
config
configz
dbus
ebtables
env
file
filesystem
flock
goroutinemap
hash
initsystem
interrupt
io
ipconfig
iptables
ipvs
keymutex
labels
limitwriter
maps
metrics
mount
net
netsh
node
oom
parsers
pointer
procfs
reflector/prometheus
removeall
resourcecontainer
rlimit
selinux
BUILD
doc.go
selinux.go
selinux_linux.go
selinux_unsupported.go
slice
strings
sysctl
system
tail
taints
template
term
threading
tolerations
version
workqueue/prometheus
BUILD
verify-util-pkg.sh
version
volume
watch
BUILD
OWNERS
plugin
staging
test
third_party
translations
vendor
.bazelrc
.generated_files
.gitattributes
.gitignore
.kazelcfg.json
BUILD.bazel
CHANGELOG-1.8.md
CONTRIBUTING.md
LICENSE
Makefile
Makefile.generated_files
OWNERS
OWNERS_ALIASES
README.md
SUPPORT.md
Vagrantfile
WORKSPACE
code-of-conduct.md
labels.yaml
克隆/下载
selinux_linux.go 1.54 KB
一键复制 编辑 原始数据 按行查看 历史
// +build linux
/*
Copyright 2014 The Kubernetes Authors.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
*/
package selinux
import (
selinux "github.com/opencontainers/selinux/go-selinux"
)
// SELinuxEnabled returns whether SELinux is enabled on the system. SELinux
// has a tri-state:
//
// 1. disabled: SELinux Kernel modules not loaded, SELinux policy is not
// checked during Kernel MAC checks
// 2. enforcing: Enabled; SELinux policy violations are denied and logged
// in the audit log
// 3. permissive: Enabled, but SELinux policy violations are permitted and
// logged in the audit log
//
// SELinuxEnabled returns true if SELinux is enforcing or permissive, and
// false if it is disabled.
func SELinuxEnabled() bool {
return selinux.GetEnabled()
}
// realSELinuxRunner is the real implementation of SELinuxRunner interface for
// Linux.
type realSELinuxRunner struct{}
var _ SELinuxRunner = &realSELinuxRunner{}
func (_ *realSELinuxRunner) Getfilecon(path string) (string, error) {
if !SELinuxEnabled() {
return "", nil
}
return selinux.FileLabel(path)
}
Loading...
马建仓 AI 助手
尝试更多
代码解读
代码找茬
代码优化
Go
1
https://gitee.com/meoom/kubernetes.git
git@gitee.com:meoom/kubernetes.git
meoom
kubernetes
kubernetes
v1.8.5

搜索帮助