/snap/snapd/27710/usr/lib/snapd
NameSizeModeActions
apparmor/-0755rm
apparmor.d/-0755rm
apparmor_parser17008320755editdlrm
complete.sh53940644editdlrm
etelpmoc.sh70310644editdlrm
info1180644editdlrm
preseed.json8410644editdlrm
snap-bootstrap138652970755editdlrm
snap-confine2182410755editdlrm
snap-confine.caps1430644editdlrm
snap-confine.v2-only.caps1210644editdlrm
snap-debug-info.sh23720755editdlrm
snap-device-helper675450755editdlrm
snap-discard-ns511130755editdlrm
snap-exec56166960755editdlrm
snap-failure32195290755editdlrm
snap-fde-keymgr53289690755editdlrm
snap-gdbserver-shim10792800755editdlrm
snap-gpio-helper30802650755editdlrm
snap-mgmt222070755editdlrm
snap-mgmt-selinux32690755editdlrm
snap-preseed117719770755editdlrm
snap-recovery-chooser94864090755editdlrm
snap-repair87655130755editdlrm
snap-seccomp30108970755editdlrm
snap-strace-shim342730755editdlrm
snap-update-ns67185840755editdlrm
snapctl84558480755editdlrm
snapd319652570755editdlrm
snapd-apparmor26952410755editdlrm
snapd.core-fixup.sh38260755editdlrm
snapd.run-from-snap730755editdlrm
system-shutdown385850755editdlrm
Edit: /snap/snapd/27710/usr/lib/snapd/snap-mgmt-selinux (3269B)
#!/bin/bash set -e set +x STATIC_SNAP_MOUNT_DIR="/snap" show_help() { exec cat <<'EOF' Usage: snap-mgmt-selinux.sh [OPTIONS] A helper script to manage SELinux contexts used by snapd Arguments: --snap-mount-dir= Provide a path to be used as $STATIC_SNAP_MOUNT_DIR --patch-selinux-mount-context= Add SELinux context to mount units --remove-selinux-mount-context= Remove SELinux context from mount units EOF } SNAP_UNIT_PREFIX="$(systemd-escape -p ${STATIC_SNAP_MOUNT_DIR})" patch_selinux_mount_context() { if ! command -v selinuxenabled > /dev/null; then return fi if ! selinuxenabled; then # The tools are there, but SELinux is not enabled return fi selinux_mount_context="$1" remove="$2" if ! echo "$selinux_mount_context" | grep -qE '[a-zA-Z0-9_]+(:[a-zA-Z0-9_]+){2,3}'; then echo "invalid mount context '$selinux_mount_context'" exit 1 fi context_opt="context=$selinux_mount_context" mounts=$(systemctl list-unit-files --no-legend --full "$SNAP_UNIT_PREFIX-*.mount" | cut -f1 -d ' ' || true) changed_mounts= for unit in $mounts; do # Ensure its really a snap mount unit or systemd unit if ! grep -q 'What=/var/lib/snapd/snaps/' "/etc/systemd/system/$unit" && ! grep -q 'X-Snappy=yes' "/etc/systemd/system/$unit"; then echo "Skipping non-snapd systemd unit $unit" continue fi if [ "$remove" == "" ]; then if grep -q "Options=.*,$context_opt" < "/etc/systemd/system/$unit"; then # already patched continue fi if ! sed -i -e "s#^\\(Options=nodev.*\\)#\\1,$context_opt#" "/etc/systemd/system/$unit"; then echo "Cannot patch $unit" fi changed_mounts="$changed_mounts $unit" elif [ "$remove" == "remove" ]; then if ! grep -q "Options=.*,$context_opt" < "/etc/systemd/system/$unit"; then # Not patched continue fi if ! sed -i -e "s#^\\(Options=nodev.*\\),$context_opt\\(,.*\\)\\?#\\1\\2#" "/etc/systemd/system/$unit"; then echo "Cannot patch $unit" fi changed_mounts="$changed_mounts $unit" fi done if [ -z "$changed_mounts" ]; then # Nothing changed, no need to reload return fi systemctl daemon-reload for unit in $changed_mounts; do if ! systemctl try-restart "$unit" ; then echo "Cannot restart $unit" fi done } while [ -n "$1" ]; do case "$1" in --help) show_help exit ;; --snap-mount-dir=*) STATIC_SNAP_MOUNT_DIR=${1#*=} SNAP_UNIT_PREFIX=$(systemd-escape -p "$STATIC_SNAP_MOUNT_DIR") shift ;; --patch-selinux-mount-context=*) patch_selinux_mount_context "${1#*=}" shift ;; --remove-selinux-mount-context=*) patch_selinux_mount_context "${1#*=}" remove shift ;; *) echo "Unknown command: $1" exit 1 ;; esac done