1
0
Fork 0
tuned/tuned/plugins/plugin_selinux.py
Jiri Mencak 5982ad0f0e TuneD plug-in documentation.
AsciiDoc documentation for all the TuneD plug-ins directly in the source
code.  This will allow auto-generation of the TuneD plug-in
documentation.  Documenting new plug-ins and plug-in features needs to
be compulsory now.

Documentation for txqueuelen and mtu options in net plugin provided by
Jan Zerdik.

Signed-off-by: Jiri Mencak <jmencak@users.noreply.github.com>
Signed-off-by: Jan Zerdik <jzerdik@redhat.com>
2022-05-17 11:01:28 +02:00

82 lines
2.2 KiB
Python

import os
from . import base
from .decorators import *
import tuned.logs
from tuned.plugins import exceptions
from tuned.utils.commands import commands
log = tuned.logs.get()
class SelinuxPlugin(base.Plugin):
"""
`selinux`::
Plug-in for tuning SELinux options.
+
SELinux decisions, such as allowing or denying access, are
cached. This cache is known as the Access Vector Cache (AVC). When
using these cached decisions, SELinux policy rules need to be checked
less, which increases performance. The [option]`avc_cache_threshold`
option allows adjusting the maximum number of AVC entries.
+
NOTE: Prior to changing the default value, evaluate the system
performance with care. Increasing the value could potentially
decrease the performance by making AVC slow.
+
.Increase the AVC cache threshold for hosts with containers.
====
----
[selinux]
avc_cache_threshold=8192
----
====
"""
@classmethod
def _get_selinux_path(self):
path = "/sys/fs/selinux"
if not os.path.exists(path):
path = "/selinux"
if not os.path.exists(path):
path = None
return path
def __init__(self, *args, **kwargs):
self._cmd = commands()
self._selinux_path = self._get_selinux_path()
if self._selinux_path is None:
raise exceptions.NotSupportedPluginException("SELinux is not enabled on your system or incompatible version is used.")
self._cache_threshold_path = os.path.join(self._selinux_path, "avc", "cache_threshold")
super(SelinuxPlugin, self).__init__(*args, **kwargs)
@classmethod
def _get_config_options(self):
return {
"avc_cache_threshold" : None,
}
def _instance_init(self, instance):
instance._has_static_tuning = True
instance._has_dynamic_tuning = False
def _instance_cleanup(self, instance):
pass
@command_set("avc_cache_threshold")
def _set_avc_cache_threshold(self, value, sim):
if value is None:
return None
threshold = int(value)
if threshold >= 0:
if not sim:
self._cmd.write_to_file(self._cache_threshold_path, threshold)
return threshold
else:
return None
@command_get("avc_cache_threshold")
def _get_avc_cache_threshold(self):
value = self._cmd.read_file(self._cache_threshold_path)
if len(value) > 0:
return int(value)
return None