]> git.ipfire.org Git - thirdparty/systemd.git/blame - src/shared/base-filesystem.c
Merge pull request #11239 from poettering/news-v240-final
[thirdparty/systemd.git] / src / shared / base-filesystem.c
CommitLineData
53e1b683 1/* SPDX-License-Identifier: LGPL-2.1+ */
3577de7a
KS
2
3#include <errno.h>
a8fbdf54
TA
4#include <fcntl.h>
5#include <stdbool.h>
3577de7a 6#include <stdlib.h>
07630cea 7#include <sys/stat.h>
a8fbdf54 8#include <syslog.h>
3577de7a
KS
9#include <unistd.h>
10
b5efdb8a 11#include "alloc-util.h"
affb60b1
LP
12#include "base-filesystem.h"
13#include "fd-util.h"
3577de7a
KS
14#include "log.h"
15#include "macro.h"
07630cea 16#include "string-util.h"
affb60b1 17#include "umask-util.h"
ee104e11 18#include "user-util.h"
3577de7a 19#include "util.h"
3577de7a
KS
20
21typedef struct BaseFilesystem {
22 const char *dir;
23 mode_t mode;
24 const char *target;
3fd165e5 25 const char *exists;
6404ecc8 26 bool ignore_failure;
3577de7a
KS
27} BaseFilesystem;
28
29static const BaseFilesystem table[] = {
30d7c9c4
HH
30 { "bin", 0, "usr/bin\0", NULL },
31 { "lib", 0, "usr/lib\0", NULL },
6404ecc8 32 { "root", 0755, NULL, NULL, true },
30d7c9c4 33 { "sbin", 0, "usr/sbin\0", NULL },
03cfe0d5
LP
34 { "usr", 0755, NULL, NULL },
35 { "var", 0755, NULL, NULL },
36 { "etc", 0755, NULL, NULL },
10404d52
DH
37 { "proc", 0755, NULL, NULL, true },
38 { "sys", 0755, NULL, NULL, true },
39 { "dev", 0755, NULL, NULL, true },
e1ae9755 40#if defined(__i386__) || defined(__x86_64__)
30d7c9c4
HH
41 { "lib64", 0, "usr/lib/x86_64-linux-gnu\0"
42 "usr/lib64\0", "ld-linux-x86-64.so.2" },
e1ae9755 43#endif
3577de7a
KS
44};
45
03cfe0d5 46int base_filesystem_create(const char *root, uid_t uid, gid_t gid) {
3577de7a 47 _cleanup_close_ int fd = -1;
a7f7d1bd 48 int r = 0;
da6053d0 49 size_t i;
3577de7a
KS
50
51 fd = open(root, O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC|O_NOFOLLOW);
4a62c710
MS
52 if (fd < 0)
53 return log_error_errno(errno, "Failed to open root file system: %m");
3577de7a
KS
54
55 for (i = 0; i < ELEMENTSOF(table); i ++) {
6f4f8056
HH
56 if (faccessat(fd, table[i].dir, F_OK, AT_SYMLINK_NOFOLLOW) >= 0)
57 continue;
58
3577de7a 59 if (table[i].target) {
6dc2852c 60 const char *target = NULL, *s;
e1ae9755
KS
61
62 /* check if one of the targets exists */
63 NULSTR_FOREACH(s, table[i].target) {
64 if (faccessat(fd, s, F_OK, AT_SYMLINK_NOFOLLOW) < 0)
65 continue;
66
3fd165e5
KS
67 /* check if a specific file exists at the target path */
68 if (table[i].exists) {
69 _cleanup_free_ char *p = NULL;
70
605405c6 71 p = strjoin(s, "/", table[i].exists);
3fd165e5
KS
72 if (!p)
73 return log_oom();
74
75 if (faccessat(fd, p, F_OK, AT_SYMLINK_NOFOLLOW) < 0)
76 continue;
77 }
78
e1ae9755
KS
79 target = s;
80 break;
81 }
82
83 if (!target)
3577de7a
KS
84 continue;
85
e1ae9755 86 r = symlinkat(target, fd, table[i].dir);
4a62c710
MS
87 if (r < 0 && errno != EEXIST)
88 return log_error_errno(errno, "Failed to create symlink at %s/%s: %m", root, table[i].dir);
03cfe0d5 89
289cb4d5 90 if (uid_is_valid(uid) || gid_is_valid(gid)) {
03cfe0d5
LP
91 if (fchownat(fd, table[i].dir, uid, gid, AT_SYMLINK_NOFOLLOW) < 0)
92 return log_error_errno(errno, "Failed to chown symlink at %s/%s: %m", root, table[i].dir);
93 }
94
3577de7a
KS
95 continue;
96 }
97
98 RUN_WITH_UMASK(0000)
99 r = mkdirat(fd, table[i].dir, table[i].mode);
6404ecc8
LP
100 if (r < 0 && errno != EEXIST) {
101 log_full_errno(table[i].ignore_failure ? LOG_DEBUG : LOG_ERR, errno,
102 "Failed to create directory at %s/%s: %m", root, table[i].dir);
103
104 if (!table[i].ignore_failure)
105 return -errno;
d1d59eeb
DH
106
107 continue;
6404ecc8 108 }
03cfe0d5
LP
109
110 if (uid != UID_INVALID || gid != UID_INVALID) {
111 if (fchownat(fd, table[i].dir, uid, gid, AT_SYMLINK_NOFOLLOW) < 0)
112 return log_error_errno(errno, "Failed to chown directory at %s/%s: %m", root, table[i].dir);
113 }
3577de7a
KS
114 }
115
116 return 0;
117}