chiark / gitweb /
[PATCH] PATCH selinux for udev
[elogind.git] / udev-remove.c
index 0f14a3d685f7745e3afa8c05ea2443c8e640138a..7ad7c2402a8e05f77d23a1451ab9b891372a8116 100644 (file)
 #include <errno.h>
 
 #include "udev.h"
+#include "udev_lib.h"
 #include "udev_version.h"
+#include "logging.h"
 #include "namedev.h"
 #include "udevdb.h"
-#include "libsysfs/libsysfs.h"
 
-
-/*
- * Look up the sysfs path in the database to see if we have named this device
- * something different from the kernel name.  If we have, us it.  If not, use
- * the default kernel name for lack of anything else to know to do.
- */
-static char *get_name(char *path, int major, int minor)
+static int delete_path(char *path)
 {
-       static char name[100];
-       struct udevice *dev;
-       char *temp;
+       char *pos;
+       int retval;
 
-       dev = udevdb_get_dev(path);
-       if (dev != NULL) {
-               strcpy(name, dev->name);
-               goto exit;
+       pos = strrchr(path, '/');
+       while (1) {
+               *pos = '\0';
+               pos = strrchr(path, '/');
+
+               /* don't remove the last one */
+               if ((pos == path) || (pos == NULL))
+                       break;
+
+               /* remove if empty */
+               retval = rmdir(path);
+               if (errno == ENOENT)
+                       retval = 0;
+               if (retval) {
+                       if (errno == ENOTEMPTY)
+                               return 0;
+                       dbg("rmdir(%s) failed with error '%s'",
+                           path, strerror(errno));
+                       break;
+               }
+               dbg("removed '%s'", path);
        }
-
-       dbg("'%s' not found in database, falling back on default name", path);
-       temp = strrchr(path, '/');
-       if (temp == NULL)
-               return NULL;
-       strncpy(name, &temp[1], sizeof(name));
-
-exit:
-       dbg("name is '%s'", name);
-       return &name[0];
+       return 0;
 }
 
-/*
- * We also want to clean up any symlinks that were created in create_node()
- */
-static int delete_node(char *name)
+/** Remove all permissions on the device node, before
+  * unlinking it. This fixes a security issue.
+  * If the user created a hard-link to the device node,
+  * he can't use it any longer, because he lost permission
+  * to do so.
+  */
+static int secure_unlink(const char *filename)
 {
-       char filename[255];
        int retval;
 
-       strncpy(filename, udev_root, sizeof(filename));
-       strncat(filename, name, sizeof(filename));
-
-       dbg("unlinking '%s'", filename);
+       retval = chown(filename, 0, 0);
+       if (retval) {
+               dbg("chown(%s, 0, 0) failed with error '%s'",
+                   filename, strerror(errno));
+               /* We continue nevertheless.
+                * I think it's very unlikely for chown
+                * to fail here, if the file exists.
+                */
+       }
+       retval = chmod(filename, 0000);
+       if (retval) {
+               dbg("chmod(%s, 0000) failed with error '%s'",
+                   filename, strerror(errno));
+               /* We continue nevertheless. */
+       }
        retval = unlink(filename);
+       if (errno == ENOENT)
+               retval = 0;
        if (retval) {
                dbg("unlink(%s) failed with error '%s'",
                        filename, strerror(errno));
+       }
+       return retval;
+}
+
+static int delete_node(struct udevice *dev)
+{
+       char filename[NAME_SIZE];
+       char linkname[NAME_SIZE];
+       char partitionname[NAME_SIZE];
+       int retval;
+       int i;
+       char *pos;
+       int len;
+
+       strfieldcpy(filename, udev_root);
+       strfieldcat(filename, dev->name);
+
+       info("removing device node '%s'", filename);
+       retval = secure_unlink(filename);
+       if (retval)
                return retval;
+
+       /* remove partition nodes */
+       if (dev->partitions > 0) {
+               info("removing partitions '%s[1-%i]'", filename, dev->partitions);
+               for (i = 1; i <= dev->partitions; i++) {
+                       strfieldcpy(partitionname, filename);
+                       strintcat(partitionname, i);
+                       secure_unlink(partitionname);
+               }
        }
 
        /* remove subdirectories */
-       if (strchr(name, '/')) {
-               char *pos;
-
-               pos = strrchr(filename, '/');
-               while (1) {
-                       *pos = 0x00;
-                       pos = strrchr(filename, '/');
-
-                       /* don't remove the last one */
-                       if ((pos == filename) || (pos == NULL))
-                               break;
-
-                       /* remove if empty */
-                       retval = rmdir(filename);
-                       if (retval) {
-                               if (errno == ENOTEMPTY)
-                                       return 0;
-                               dbg("rmdir(%s) failed with error '%s'",
-                                   filename, strerror(errno));
-                               break;
-                       }
-                       dbg("removed '%s'", filename);
+       if (strchr(dev->name, '/'))
+               delete_path(filename);
+
+       foreach_strpart(dev->symlink, " ", pos, len) {
+               strfieldcpymax(linkname, pos, len+1);
+               strfieldcpy(filename, udev_root);
+               strfieldcat(filename, linkname);
+
+               dbg("unlinking symlink '%s'", filename);
+               retval = unlink(filename);
+               if (errno == ENOENT)
+                       retval = 0;
+               if (retval) {
+                       dbg("unlink(%s) failed with error '%s'",
+                               filename, strerror(errno));
+                       return retval;
+               }
+               if (strchr(dev->symlink, '/')) {
+                       delete_path(filename);
                }
        }
+
        return retval;
 }
 
-int udev_remove_device(char *device, char *subsystem)
+/*
+ * Look up the sysfs path in the database to see if we have named this device
+ * something different from the kernel name.  If we have, us it.  If not, use
+ * the default kernel name for lack of anything else to know to do.
+ */
+int udev_remove_device(const char *path, const char *subsystem)
 {
-       char *name;
-       int retval = 0;
-
-       name = get_name(device, 0, 0);
-       if (name == NULL) {
-               dbg ("get_name failed");
-               retval = -ENODEV;
-               goto exit;
+       struct udevice dev;
+       char *temp;
+       int retval;
+
+       memset(&dev, 0x00, sizeof(dev));
+
+       retval = udevdb_get_dev(path, &dev);
+       if (retval != 0) {
+               dbg("'%s' not found in database, falling back on default name", path);
+               temp = strrchr(path, '/');
+               if (temp == NULL)
+                       return -ENODEV;
+               strfieldcpy(dev.name, &temp[1]);
        }
+       dbg("name='%s'", dev.name);
 
-       udevdb_delete_dev(device);
+       dev.type = get_device_type(path, subsystem);
+       dev_d_send(&dev, subsystem, path);
+       udevdb_delete_dev(path);
 
-       return delete_node(name);
+       if (dev.type == 'b' || dev.type == 'c')
+               retval = delete_node(&dev);
+       else if (dev.type == 'n')
+               retval = 0;
 
-exit:
        return retval;
 }