chiark
/
gitweb
/
~ianmdlvl
/
elogind.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
main: add configuration option to alter capability bounding set for PID 1
[elogind.git]
/
src
/
core
/
mount-setup.c
diff --git
a/src/core/mount-setup.c
b/src/core/mount-setup.c
index 30046a51bd2ad1fbac117f4236788fe88e704ff6..56ce2ae71a01a72634020e2cfeeebafff69af573 100644
(file)
--- a/
src/core/mount-setup.c
+++ b/
src/core/mount-setup.c
@@
-30,6
+30,7
@@
#include <ftw.h>
#include "mount-setup.h"
#include <ftw.h>
#include "mount-setup.h"
+#include "dev-setup.h"
#include "log.h"
#include "macro.h"
#include "util.h"
#include "log.h"
#include "macro.h"
#include "util.h"
@@
-37,6
+38,7
@@
#include "set.h"
#include "strv.h"
#include "mkdir.h"
#include "set.h"
#include "strv.h"
#include "mkdir.h"
+#include "path-util.h"
#ifndef TTY_GID
#define TTY_GID 5
#ifndef TTY_GID
#define TTY_GID 5
@@
-71,11
+73,22
@@
static const MountPoint mount_table[] = {
/* These are API file systems that might be mounted by other software,
* we just list them here so that we know that we should ignore them */
/* These are API file systems that might be mounted by other software,
* we just list them here so that we know that we should ignore them */
-static const char * const ignore_paths[] = {
- "/sys/fs/selinux",
- "/selinux",
- "/proc/bus/usb"
-};
+static const char ignore_paths[] =
+ /* SELinux file systems */
+ "/sys/fs/selinux\0"
+ "/selinux\0"
+ /* Legacy cgroup mount points */
+ "/dev/cgroup\0"
+ "/cgroup\0"
+ /* Legacy kernel file system */
+ "/proc/bus/usb\0"
+ /* Container bind mounts */
+ "/proc/sys\0"
+ "/dev/console\0"
+ "/proc/kmsg\0"
+ "/etc/localtime\0"
+ "/etc/timezone\0"
+ "/etc/machine-id\0";
bool mount_point_is_api(const char *path) {
unsigned i;
bool mount_point_is_api(const char *path) {
unsigned i;
@@
-91,10
+104,10
@@
bool mount_point_is_api(const char *path) {
}
bool mount_point_ignore(const char *path) {
}
bool mount_point_ignore(const char *path) {
-
unsigned
i;
+
const char *
i;
-
for (i = 0; i < ELEMENTSOF(ignore_paths); i++
)
- if (path_equal(path, i
gnore_paths[i]
))
+
NULSTR_FOREACH(i, ignore_paths
)
+ if (path_equal(path, i))
return true;
return false;
return true;
return false;
@@
-130,7
+143,7
@@
static int mount_one(const MountPoint *p, bool relabel) {
p->type,
p->flags,
p->options) < 0) {
p->type,
p->flags,
p->options) < 0) {
- log_
error(
"Failed to mount %s: %s", p->where, strerror(errno));
+ log_
full(p->fatal ? LOG_ERR : LOG_DEBUG,
"Failed to mount %s: %s", p->where, strerror(errno));
return p->fatal ? -errno : 0;
}
return p->fatal ? -errno : 0;
}
@@
-323,24
+336,6
@@
finish:
return r;
}
return r;
}
-static int symlink_and_label(const char *old_path, const char *new_path) {
- int r;
-
- assert(old_path);
- assert(new_path);
-
- r = label_context_set(new_path, S_IFLNK);
- if (r < 0)
- return r;
-
- if (symlink(old_path, new_path) < 0)
- r = -errno;
-
- label_context_clear();
-
- return r;
-}
-
static int nftw_cb(
const char *fpath,
const struct stat *sb,
static int nftw_cb(
const char *fpath,
const struct stat *sb,
@@
-365,20
+360,13
@@
static int nftw_cb(
int mount_setup(bool loaded_policy) {
int mount_setup(bool loaded_policy) {
- static const char symlinks[] =
- "/proc/kcore\0" "/dev/core\0"
- "/proc/self/fd\0" "/dev/fd\0"
- "/proc/self/fd/0\0" "/dev/stdin\0"
- "/proc/self/fd/1\0" "/dev/stdout\0"
- "/proc/self/fd/2\0" "/dev/stderr\0";
-
static const char relabel[] =
"/run/initramfs/root-fsck\0"
"/run/initramfs/shutdown\0";
int r;
unsigned i;
static const char relabel[] =
"/run/initramfs/root-fsck\0"
"/run/initramfs/shutdown\0";
int r;
unsigned i;
- const char *j
, *k
;
+ const char *j;
for (i = 0; i < ELEMENTSOF(mount_table); i ++) {
r = mount_one(mount_table + i, true);
for (i = 0; i < ELEMENTSOF(mount_table); i ++) {
r = mount_one(mount_table + i, true);
@@
-413,8
+401,7
@@
int mount_setup(bool loaded_policy) {
/* Create a few default symlinks, which are normally created
* by udevd, but some scripts might need them before we start
* udevd. */
/* Create a few default symlinks, which are normally created
* by udevd, but some scripts might need them before we start
* udevd. */
- NULSTR_FOREACH_PAIR(j, k, symlinks)
- symlink_and_label(j, k);
+ dev_setup();
/* Create a few directories we always want around */
label_mkdir("/run/systemd", 0755);
/* Create a few directories we always want around */
label_mkdir("/run/systemd", 0755);