1 /* SPDX-License-Identifier: LGPL-2.1-or-later */
5 #include "btrfs-util.h"
7 #include "homework-directory.h"
8 #include "homework-quota.h"
10 #include "mount-util.h"
11 #include "path-util.h"
13 #include "tmpfile-util.h"
14 #include "umask-util.h"
16 int home_setup_directory(UserRecord
*h
, bool already_activated
, HomeSetup
*setup
) {
20 setup
->root_fd
= open(user_record_image_path(h
), O_RDONLY
|O_CLOEXEC
|O_DIRECTORY
);
21 if (setup
->root_fd
< 0)
22 return log_error_errno(errno
, "Failed to open home directory: %m");
27 int home_activate_directory(
30 UserRecord
**ret_home
) {
32 _cleanup_(user_record_unrefp
) UserRecord
*new_home
= NULL
, *header_home
= NULL
;
33 _cleanup_(home_setup_done
) HomeSetup setup
= HOME_SETUP_INIT
;
34 const char *hdo
, *hd
, *ipo
, *ip
;
38 assert(IN_SET(user_record_storage(h
), USER_DIRECTORY
, USER_SUBVOLUME
, USER_FSCRYPT
));
41 assert_se(ipo
= user_record_image_path(h
));
42 ip
= strdupa_safe(ipo
); /* copy out, since reconciliation might cause changing of the field */
44 assert_se(hdo
= user_record_home_directory(h
));
45 hd
= strdupa_safe(hdo
);
47 r
= home_setup(h
, false, cache
, &setup
, &header_home
);
51 r
= home_refresh(h
, &setup
, header_home
, cache
, NULL
, &new_home
);
55 setup
.root_fd
= safe_close(setup
.root_fd
);
57 /* Create mount point to mount over if necessary */
58 if (!path_equal(ip
, hd
))
59 (void) mkdir_p(hd
, 0700);
61 /* Create a mount point (even if the directory is already placed correctly), as a way to indicate
62 * this mount point is now "activated". Moreover, we want to set per-user
63 * MS_NOSUID/MS_NOEXEC/MS_NODEV. */
64 r
= mount_nofollow_verbose(LOG_ERR
, ip
, hd
, NULL
, MS_BIND
, NULL
);
68 r
= mount_nofollow_verbose(LOG_ERR
, NULL
, hd
, NULL
, MS_BIND
|MS_REMOUNT
|user_record_mount_flags(h
), NULL
);
70 (void) umount_verbose(LOG_ERR
, hd
, UMOUNT_NOFOLLOW
);
74 log_info("Everything completed.");
76 *ret_home
= TAKE_PTR(new_home
);
80 int home_create_directory_or_subvolume(UserRecord
*h
, UserRecord
**ret_home
) {
81 _cleanup_(rm_rf_subvolume_and_freep
) char *temporary
= NULL
;
82 _cleanup_(user_record_unrefp
) UserRecord
*new_home
= NULL
;
83 _cleanup_close_
int root_fd
= -1;
84 _cleanup_free_
char *d
= NULL
;
89 assert(IN_SET(user_record_storage(h
), USER_DIRECTORY
, USER_SUBVOLUME
));
92 assert_se(ip
= user_record_image_path(h
));
94 r
= tempfn_random(ip
, "homework", &d
);
96 return log_error_errno(r
, "Failed to allocate temporary directory: %m");
98 (void) mkdir_parents(d
, 0755);
100 switch (user_record_storage(h
)) {
104 r
= btrfs_subvol_make(d
);
107 log_info("Subvolume created.");
109 if (h
->disk_size
!= UINT64_MAX
) {
111 /* Enable quota for the subvolume we just created. Note we don't check for
112 * errors here and only log about debug level about this. */
113 r
= btrfs_quota_enable(d
, true);
115 log_debug_errno(r
, "Failed to enable quota on %s, ignoring: %m", d
);
117 r
= btrfs_subvol_auto_qgroup(d
, 0, false);
119 log_debug_errno(r
, "Failed to set up automatic quota group on %s, ignoring: %m", d
);
121 /* Actually configure the quota. We also ignore errors here, but we do log
122 * about them loudly, to keep things discoverable even though we don't
123 * consider lacking quota support in kernel fatal. */
124 (void) home_update_quota_btrfs(h
, d
);
130 return log_error_errno(r
, "Failed to create temporary home directory subvolume %s: %m", d
);
132 log_info("Creating subvolume %s is not supported, as file system does not support subvolumes. Falling back to regular directory.", d
);
137 if (mkdir(d
, 0700) < 0)
138 return log_error_errno(errno
, "Failed to create temporary home directory %s: %m", d
);
140 (void) home_update_quota_classic(h
, d
);
144 assert_not_reached();
147 temporary
= TAKE_PTR(d
); /* Needs to be destroyed now */
149 root_fd
= open(temporary
, O_RDONLY
|O_CLOEXEC
|O_DIRECTORY
|O_NOFOLLOW
);
151 return log_error_errno(errno
, "Failed to open temporary home directory: %m");
153 r
= home_populate(h
, root_fd
);
157 r
= home_sync_and_statfs(root_fd
, NULL
);
161 r
= user_record_clone(h
, USER_RECORD_LOAD_MASK_SECRET
|USER_RECORD_PERMISSIVE
, &new_home
);
163 return log_error_errno(r
, "Failed to clone record: %m");
165 r
= user_record_add_binding(
167 user_record_storage(h
),
180 return log_error_errno(r
, "Failed to add binding to record: %m");
182 if (rename(temporary
, ip
) < 0)
183 return log_error_errno(errno
, "Failed to rename %s to %s: %m", temporary
, ip
);
185 temporary
= mfree(temporary
);
187 log_info("Everything completed.");
189 *ret_home
= TAKE_PTR(new_home
);
193 int home_resize_directory(
195 bool already_activated
,
196 PasswordCache
*cache
,
198 UserRecord
**ret_home
) {
200 _cleanup_(user_record_unrefp
) UserRecord
*embedded_home
= NULL
, *new_home
= NULL
;
206 assert(IN_SET(user_record_storage(h
), USER_DIRECTORY
, USER_SUBVOLUME
, USER_FSCRYPT
));
208 r
= home_setup(h
, already_activated
, cache
, setup
, NULL
);
212 r
= home_load_embedded_identity(h
, setup
->root_fd
, NULL
, USER_RECONCILE_REQUIRE_NEWER_OR_EQUAL
, cache
, &embedded_home
, &new_home
);
216 r
= home_update_quota_auto(h
, NULL
);
217 if (ERRNO_IS_NOT_SUPPORTED(r
))
218 return -ESOCKTNOSUPPORT
; /* make recognizable */
222 r
= home_store_embedded_identity(new_home
, setup
->root_fd
, h
->uid
, embedded_home
);
226 r
= home_extend_embedded_identity(new_home
, h
, setup
);
230 r
= home_sync_and_statfs(setup
->root_fd
, NULL
);
234 r
= home_setup_done(setup
);
238 log_info("Everything completed.");
240 *ret_home
= TAKE_PTR(new_home
);