#include #include #include #include #include #include #include "selinux_internal.h" #include "policy.h" #include #include int security_reject_unknown(void) { int fd, ret, reject_unknown = 0; char path[PATH_MAX]; char buf[20]; if (!selinux_mnt) { errno = ENOENT; return -1; } snprintf(path, sizeof(path), "%s/reject_unknown", selinux_mnt); fd = open(path, O_RDONLY | O_CLOEXEC); if (fd < 0) return -1; memset(buf, 0, sizeof(buf)); ret = read(fd, buf, sizeof(buf) - 1); close(fd); if (ret < 0) return -1; if (sscanf(buf, "%d", &reject_unknown) != 1) return -1; return reject_unknown; } hidden_def(security_reject_unknown);