1 /*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
4 This file is part of systemd.
6 Copyright 2010 Lennart Poettering
8 systemd is free software; you can redistribute it and/or modify it
9 under the terms of the GNU Lesser General Public License as published by
10 the Free Software Foundation; either version 2.1 of the License, or
11 (at your option) any later version.
13 systemd is distributed in the hope that it will be useful, but
14 WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
16 Lesser General Public License for more details.
18 You should have received a copy of the GNU Lesser General Public License
19 along with systemd; If not, see <http://www.gnu.org/licenses/>.
23 #include <sys/mount.h>
28 #include <sys/types.h>
30 #include <sys/syscall.h>
36 #include "path-util.h"
37 #include "namespace.h"
40 typedef enum PathMode {
41 /* This is ordered by priority! */
55 static int append_paths(Path **p, char **strv, PathMode mode) {
58 STRV_FOREACH(i, strv) {
60 if (!path_is_absolute(*i))
71 static int path_compare(const void *a, const void *b) {
72 const Path *p = a, *q = b;
74 if (path_equal(p->path, q->path)) {
76 /* If the paths are equal, check the mode */
77 if (p->mode < q->mode)
80 if (p->mode > q->mode)
86 /* If the paths are not equal, then order prefixes first */
87 if (path_startswith(p->path, q->path))
90 if (path_startswith(q->path, p->path))
96 static void drop_duplicates(Path *p, unsigned *n, bool *need_inaccessible) {
97 Path *f, *t, *previous;
101 assert(need_inaccessible);
103 for (f = p, t = p, previous = NULL; f < p+*n; f++) {
105 /* The first one wins */
106 if (previous && path_equal(f->path, previous->path))
112 if (t->mode == INACCESSIBLE)
113 *need_inaccessible = true;
123 static int apply_mount(
126 const char *var_tmp_dir,
127 const char *inaccessible_dir) {
137 what = inaccessible_dir;
149 case PRIVATE_VAR_TMP:
154 assert_not_reached("Unknown mode");
159 r = mount(what, p->path, NULL, MS_BIND|MS_REC, NULL);
161 log_debug("Successfully mounted %s to %s", what, p->path);
166 static int make_read_only(Path *p) {
171 if (p->mode != INACCESSIBLE && p->mode != READONLY)
174 r = mount(NULL, p->path, NULL, MS_BIND|MS_REMOUNT|MS_RDONLY|MS_REC, NULL);
186 unsigned long flags) {
189 tmp_dir[] = "/tmp/systemd-private-XXXXXX",
190 var_tmp_dir[] = "/var/tmp/systemd-private-XXXXXX",
191 inaccessible_dir[] = "/tmp/systemd-inaccessible-XXXXXX";
195 bool need_inaccessible = false;
196 bool remove_tmp = false, remove_var_tmp = false, remove_inaccessible = false;
203 strv_length(writable) +
204 strv_length(readable) +
205 strv_length(inaccessible) +
206 (private_tmp ? 2 : 0);
208 p = paths = alloca(sizeof(Path) * n);
209 if ((r = append_paths(&p, writable, READWRITE)) < 0 ||
210 (r = append_paths(&p, readable, READONLY)) < 0 ||
211 (r = append_paths(&p, inaccessible, INACCESSIBLE)) < 0)
216 p->mode = PRIVATE_TMP;
219 p->path = "/var/tmp";
220 p->mode = PRIVATE_VAR_TMP;
224 assert(paths + n == p);
226 qsort(paths, n, sizeof(Path), path_compare);
227 drop_duplicates(paths, &n, &need_inaccessible);
229 if (need_inaccessible) {
234 d = mkdtemp(inaccessible_dir);
242 remove_inaccessible = true;
250 d = mkdtemp(tmp_dir);
261 d = mkdtemp(var_tmp_dir);
269 remove_var_tmp = true;
271 if (chmod(tmp_dir, 0777 + S_ISVTX) < 0) {
276 if (chmod(var_tmp_dir, 0777 + S_ISVTX) < 0) {
282 if (unshare(CLONE_NEWNS) < 0) {
287 /* Remount / as SLAVE so that nothing now mounted in the namespace
288 shows up in the parent */
289 if (mount(NULL, "/", NULL, MS_SLAVE|MS_REC, NULL) < 0) {
294 for (p = paths; p < paths + n; p++) {
295 r = apply_mount(p, tmp_dir, var_tmp_dir, inaccessible_dir);
300 for (p = paths; p < paths + n; p++) {
301 r = make_read_only(p);
306 /* Remount / as the desired mode */
307 if (mount(NULL, "/", NULL, flags|MS_REC, NULL) < 0) {
315 for (p = paths; p < paths + n; p++)
317 umount2(p->path, MNT_DETACH);
320 if (remove_inaccessible)
321 rmdir(inaccessible_dir);