chiark / gitweb /
selinux: do not label files in runtime dir
[elogind.git] / libudev / libudev-util-private.c
1 /*
2  * libudev - interface to udev device information
3  *
4  * Copyright (C) 2003-2009 Kay Sievers <kay.sievers@vrfy.org>
5  *
6  * This library is free software; you can redistribute it and/or
7  * modify it under the terms of the GNU Lesser General Public
8  * License as published by the Free Software Foundation; either
9  * version 2.1 of the License, or (at your option) any later version.
10  */
11
12 #include <stdlib.h>
13 #include <stdio.h>
14 #include <stddef.h>
15 #include <unistd.h>
16 #include <string.h>
17 #include <fcntl.h>
18 #include <errno.h>
19 #include <ctype.h>
20 #include <pwd.h>
21 #include <grp.h>
22 #include <sys/wait.h>
23 #include <sys/param.h>
24
25 #include "libudev.h"
26 #include "libudev-private.h"
27
28 static int create_path(struct udev *udev, const char *path, bool selinux)
29 {
30         char p[UTIL_PATH_SIZE];
31         char *pos;
32         struct stat stats;
33         int err;
34
35         util_strscpy(p, sizeof(p), path);
36         pos = strrchr(p, '/');
37         if (pos == NULL)
38                 return 0;
39         while (pos != p && pos[-1] == '/')
40                 pos--;
41         if (pos == p)
42                 return 0;
43         pos[0] = '\0';
44
45         dbg(udev, "stat '%s'\n", p);
46         if (stat(p, &stats) == 0) {
47                 if ((stats.st_mode & S_IFMT) == S_IFDIR)
48                         return 0;
49                 else
50                         return -ENOTDIR;
51         }
52
53         err = util_create_path(udev, p);
54         if (err != 0)
55                 return err;
56
57         dbg(udev, "mkdir '%s'\n", p);
58         if (selinux)
59                 udev_selinux_setfscreatecon(udev, p, S_IFDIR|0755);
60         err = mkdir(p, 0755);
61         if (err != 0) {
62                 err = -errno;
63                 if (err == -EEXIST && stat(p, &stats) == 0) {
64                         if ((stats.st_mode & S_IFMT) == S_IFDIR)
65                                 err = 0;
66                         else
67                                 err = -ENOTDIR;
68                 }
69         }
70         if (selinux)
71                 udev_selinux_resetfscreatecon(udev);
72         return err;
73 }
74
75 int util_create_path(struct udev *udev, const char *path)
76 {
77         return create_path(udev, path, false);
78 }
79
80 int util_create_path_selinux(struct udev *udev, const char *path)
81 {
82         return create_path(udev, path, true);
83 }
84
85 int util_delete_path(struct udev *udev, const char *path)
86 {
87         char p[UTIL_PATH_SIZE];
88         char *pos;
89         int err = 0;
90
91         if (path[0] == '/')
92                 while(path[1] == '/')
93                         path++;
94         util_strscpy(p, sizeof(p), path);
95         pos = strrchr(p, '/');
96         if (pos == p || pos == NULL)
97                 return 0;
98
99         for (;;) {
100                 *pos = '\0';
101                 pos = strrchr(p, '/');
102
103                 /* don't remove the last one */
104                 if ((pos == p) || (pos == NULL))
105                         break;
106
107                 err = rmdir(p);
108                 if (err < 0) {
109                         if (errno == ENOENT)
110                                 err = 0;
111                         break;
112                 }
113         }
114         return err;
115 }
116
117 /* Reset permissions on the device node, before unlinking it to make sure,
118  * that permissions of possible hard links will be removed too.
119  */
120 int util_unlink_secure(struct udev *udev, const char *filename)
121 {
122         int err;
123
124         chown(filename, 0, 0);
125         chmod(filename, 0000);
126         err = unlink(filename);
127         if (errno == ENOENT)
128                 err = 0;
129         if (err)
130                 err(udev, "unlink(%s) failed: %m\n", filename);
131         return err;
132 }
133
134 uid_t util_lookup_user(struct udev *udev, const char *user)
135 {
136         char *endptr;
137         int buflen = sysconf(_SC_GETPW_R_SIZE_MAX);
138         char buf[buflen];
139         struct passwd pwbuf;
140         struct passwd *pw;
141         uid_t uid;
142
143         if (strcmp(user, "root") == 0)
144                 return 0;
145         uid = strtoul(user, &endptr, 10);
146         if (endptr[0] == '\0')
147                 return uid;
148
149         errno = getpwnam_r(user, &pwbuf, buf, buflen, &pw);
150         if (pw != NULL)
151                 return pw->pw_uid;
152         if (errno == 0 || errno == ENOENT || errno == ESRCH)
153                 err(udev, "specified user '%s' unknown\n", user);
154         else
155                 err(udev, "error resolving user '%s': %m\n", user);
156         return 0;
157 }
158
159 gid_t util_lookup_group(struct udev *udev, const char *group)
160 {
161         char *endptr;
162         int buflen = sysconf(_SC_GETGR_R_SIZE_MAX);
163         char *buf;
164         struct group grbuf;
165         struct group *gr;
166         gid_t gid = 0;
167
168         if (strcmp(group, "root") == 0)
169                 return 0;
170         gid = strtoul(group, &endptr, 10);
171         if (endptr[0] == '\0')
172                 return gid;
173         buf = NULL;
174         gid = 0;
175         for (;;) {
176                 char *newbuf;
177
178                 newbuf = realloc(buf, buflen);
179                 if (!newbuf)
180                         break;
181                 buf = newbuf;
182                 errno = getgrnam_r(group, &grbuf, buf, buflen, &gr);
183                 if (gr != NULL) {
184                         gid = gr->gr_gid;
185                 } else if (errno == ERANGE) {
186                         buflen *= 2;
187                         continue;
188                 } else if (errno == 0 || errno == ENOENT || errno == ESRCH) {
189                         err(udev, "specified group '%s' unknown\n", group);
190                 } else {
191                         err(udev, "error resolving group '%s': %m\n", group);
192                 }
193                 break;
194         }
195         free(buf);
196         return gid;
197 }
198
199 /* handle "[<SUBSYSTEM>/<KERNEL>]<attribute>" format */
200 int util_resolve_subsys_kernel(struct udev *udev, const char *string,
201                                char *result, size_t maxsize, int read_value)
202 {
203         char temp[UTIL_PATH_SIZE];
204         char *subsys;
205         char *sysname;
206         struct udev_device *dev;
207         char *attr;
208
209         if (string[0] != '[')
210                 return -1;
211
212         util_strscpy(temp, sizeof(temp), string);
213
214         subsys = &temp[1];
215
216         sysname = strchr(subsys, '/');
217         if (sysname == NULL)
218                 return -1;
219         sysname[0] = '\0';
220         sysname = &sysname[1];
221
222         attr = strchr(sysname, ']');
223         if (attr == NULL)
224                 return -1;
225         attr[0] = '\0';
226         attr = &attr[1];
227         if (attr[0] == '/')
228                 attr = &attr[1];
229         if (attr[0] == '\0')
230                 attr = NULL;
231
232         if (read_value && attr == NULL)
233                 return -1;
234
235         dev = udev_device_new_from_subsystem_sysname(udev, subsys, sysname);
236         if (dev == NULL)
237                 return -1;
238
239         if (read_value) {
240                 const char *val;
241
242                 val = udev_device_get_sysattr_value(dev, attr);
243                 if (val != NULL)
244                         util_strscpy(result, maxsize, val);
245                 else
246                         result[0] = '\0';
247                 info(udev, "value '[%s/%s]%s' is '%s'\n", subsys, sysname, attr, result);
248         } else {
249                 size_t l;
250                 char *s;
251
252                 s = result;
253                 l = util_strpcpyl(&s, maxsize, udev_device_get_syspath(dev), NULL);
254                 if (attr != NULL)
255                         util_strpcpyl(&s, l, "/", attr, NULL);
256                 info(udev, "path '[%s/%s]%s' is '%s'\n", subsys, sysname, attr, result);
257         }
258         udev_device_unref(dev);
259         return 0;
260 }
261
262 int util_run_program(struct udev *udev, const char *command, char **envp,
263                      char *result, size_t ressize, size_t *reslen,
264                      const sigset_t *sigmask, bool reset_prio)
265 {
266         int status;
267         int outpipe[2] = {-1, -1};
268         int errpipe[2] = {-1, -1};
269         pid_t pid;
270         char arg[UTIL_PATH_SIZE];
271         char program[UTIL_PATH_SIZE];
272         char *argv[((sizeof(arg) + 1) / 2) + 1];
273         int devnull;
274         int i;
275         int err = 0;
276
277         info(udev, "'%s' started\n", command);
278
279         /* build argv from command */
280         util_strscpy(arg, sizeof(arg), command);
281         i = 0;
282         if (strchr(arg, ' ') != NULL) {
283                 char *pos = arg;
284
285                 while (pos != NULL && pos[0] != '\0') {
286                         if (pos[0] == '\'') {
287                                 /* do not separate quotes */
288                                 pos++;
289                                 argv[i] = strsep(&pos, "\'");
290                                 if (pos != NULL)
291                                         while (pos[0] == ' ')
292                                                 pos++;
293                         } else {
294                                 argv[i] = strsep(&pos, " ");
295                                 if (pos != NULL)
296                                         while (pos[0] == ' ')
297                                                 pos++;
298                         }
299                         dbg(udev, "arg[%i] '%s'\n", i, argv[i]);
300                         i++;
301                 }
302                 argv[i] = NULL;
303         } else {
304                 argv[0] = arg;
305                 argv[1] = NULL;
306         }
307
308         /* prepare pipes from child to parent */
309         if (result != NULL || udev_get_log_priority(udev) >= LOG_INFO) {
310                 if (pipe(outpipe) != 0) {
311                         err(udev, "pipe failed: %m\n");
312                         return -1;
313                 }
314         }
315         if (udev_get_log_priority(udev) >= LOG_INFO) {
316                 if (pipe(errpipe) != 0) {
317                         err(udev, "pipe failed: %m\n");
318                         return -1;
319                 }
320         }
321
322         /* allow programs in /lib/udev/ to be called without the path */
323         if (argv[0][0] != '/') {
324                 util_strscpyl(program, sizeof(program), LIBEXECDIR "/", argv[0], NULL);
325                 argv[0] = program;
326         }
327
328         pid = fork();
329         switch(pid) {
330         case 0:
331                 /* child closes parent ends of pipes */
332                 if (outpipe[READ_END] > 0)
333                         close(outpipe[READ_END]);
334                 if (errpipe[READ_END] > 0)
335                         close(errpipe[READ_END]);
336
337                 /* discard child output or connect to pipe */
338                 devnull = open("/dev/null", O_RDWR);
339                 if (devnull > 0) {
340                         dup2(devnull, STDIN_FILENO);
341                         if (outpipe[WRITE_END] < 0)
342                                 dup2(devnull, STDOUT_FILENO);
343                         if (errpipe[WRITE_END] < 0)
344                                 dup2(devnull, STDERR_FILENO);
345                         close(devnull);
346                 } else
347                         err(udev, "open /dev/null failed: %m\n");
348                 if (outpipe[WRITE_END] > 0) {
349                         dup2(outpipe[WRITE_END], STDOUT_FILENO);
350                         close(outpipe[WRITE_END]);
351                 }
352                 if (errpipe[WRITE_END] > 0) {
353                         dup2(errpipe[WRITE_END], STDERR_FILENO);
354                         close(errpipe[WRITE_END]);
355                 }
356
357                 if (sigmask)
358                         sigprocmask(SIG_SETMASK, sigmask, NULL);
359                 if (reset_prio)
360                         setpriority(PRIO_PROCESS, 0, 0);
361
362                 execve(argv[0], argv, envp);
363                 if (errno == ENOENT || errno == ENOTDIR) {
364                         /* may be on a filesystem which is not mounted right now */
365                         info(udev, "program '%s' not found\n", argv[0]);
366                 } else {
367                         /* other problems */
368                         err(udev, "exec of program '%s' failed\n", argv[0]);
369                 }
370                 _exit(1);
371         case -1:
372                 err(udev, "fork of '%s' failed: %m\n", argv[0]);
373                 return -1;
374         default:
375                 /* read from child if requested */
376                 if (outpipe[READ_END] > 0 || errpipe[READ_END] > 0) {
377                         ssize_t count;
378                         size_t respos = 0;
379
380                         /* parent closes child ends of pipes */
381                         if (outpipe[WRITE_END] > 0)
382                                 close(outpipe[WRITE_END]);
383                         if (errpipe[WRITE_END] > 0)
384                                 close(errpipe[WRITE_END]);
385
386                         /* read child output */
387                         while (outpipe[READ_END] > 0 || errpipe[READ_END] > 0) {
388                                 int fdcount;
389                                 fd_set readfds;
390
391                                 FD_ZERO(&readfds);
392                                 if (outpipe[READ_END] > 0)
393                                         FD_SET(outpipe[READ_END], &readfds);
394                                 if (errpipe[READ_END] > 0)
395                                         FD_SET(errpipe[READ_END], &readfds);
396                                 fdcount = select(MAX(outpipe[READ_END], errpipe[READ_END])+1, &readfds, NULL, NULL, NULL);
397                                 if (fdcount < 0) {
398                                         if (errno == EINTR)
399                                                 continue;
400                                         err = -1;
401                                         break;
402                                 }
403
404                                 /* get stdout */
405                                 if (outpipe[READ_END] > 0 && FD_ISSET(outpipe[READ_END], &readfds)) {
406                                         char inbuf[1024];
407                                         char *pos;
408                                         char *line;
409
410                                         count = read(outpipe[READ_END], inbuf, sizeof(inbuf)-1);
411                                         if (count <= 0) {
412                                                 close(outpipe[READ_END]);
413                                                 outpipe[READ_END] = -1;
414                                                 if (count < 0) {
415                                                         err(udev, "stdin read failed: %m\n");
416                                                         err = -1;
417                                                 }
418                                                 continue;
419                                         }
420                                         inbuf[count] = '\0';
421
422                                         /* store result for rule processing */
423                                         if (result) {
424                                                 if (respos + count < ressize) {
425                                                         memcpy(&result[respos], inbuf, count);
426                                                         respos += count;
427                                                 } else {
428                                                         err(udev, "ressize %ld too short\n", (long)ressize);
429                                                         err = -1;
430                                                 }
431                                         }
432                                         pos = inbuf;
433                                         while ((line = strsep(&pos, "\n")))
434                                                 if (pos || line[0] != '\0')
435                                                         info(udev, "'%s' (stdout) '%s'\n", argv[0], line);
436                                 }
437
438                                 /* get stderr */
439                                 if (errpipe[READ_END] > 0 && FD_ISSET(errpipe[READ_END], &readfds)) {
440                                         char errbuf[1024];
441                                         char *pos;
442                                         char *line;
443
444                                         count = read(errpipe[READ_END], errbuf, sizeof(errbuf)-1);
445                                         if (count <= 0) {
446                                                 close(errpipe[READ_END]);
447                                                 errpipe[READ_END] = -1;
448                                                 if (count < 0)
449                                                         err(udev, "stderr read failed: %m\n");
450                                                 continue;
451                                         }
452                                         errbuf[count] = '\0';
453                                         pos = errbuf;
454                                         while ((line = strsep(&pos, "\n")))
455                                                 if (pos || line[0] != '\0')
456                                                         info(udev, "'%s' (stderr) '%s'\n", argv[0], line);
457                                 }
458                         }
459                         if (outpipe[READ_END] > 0)
460                                 close(outpipe[READ_END]);
461                         if (errpipe[READ_END] > 0)
462                                 close(errpipe[READ_END]);
463
464                         /* return the child's stdout string */
465                         if (result) {
466                                 result[respos] = '\0';
467                                 dbg(udev, "result='%s'\n", result);
468                                 if (reslen)
469                                         *reslen = respos;
470                         }
471                 }
472                 waitpid(pid, &status, 0);
473                 if (WIFEXITED(status)) {
474                         info(udev, "'%s' returned with exitcode %i\n", command, WEXITSTATUS(status));
475                         if (WEXITSTATUS(status) != 0)
476                                 err = -1;
477                 } else {
478                         err(udev, "'%s' unexpected exit with status 0x%04x\n", command, status);
479                         err = -1;
480                 }
481         }
482         return err;
483 }