#include <assert.h>
#include <errno.h>
#include <fcntl.h>
#include <priv.h>
#include <signal.h>
#include <stdlib.h>
#include <stdio.h>
#include <strings.h>
#include <syslog.h>
#include <zone.h>
#include <sys/dld.h>
#include <sys/dld_ioc.h>
#include <sys/param.h>
#include <sys/stat.h>
#include <unistd.h>
#include <libdladm_impl.h>
#include <libdlmgmt.h>
#include "dlmgmt_impl.h"
const char *progname;
boolean_t debug;
static int pfds[2];
static int dlmgmt_door_fd = -1;
dladm_handle_t dld_handle = NULL;
static void dlmgmtd_exit(int);
static int dlmgmt_init();
static void dlmgmt_fini();
static int dlmgmt_set_privileges();
static int
dlmgmt_set_doorfd(boolean_t start)
{
dld_ioc_door_t did;
int err = 0;
assert(dld_handle != NULL);
did.did_start_door = start;
if (ioctl(dladm_dld_fd(dld_handle), DLDIOC_DOORSERVER, &did) == -1)
err = errno;
return (err);
}
static int
dlmgmt_door_init(void)
{
int err = 0;
if ((dlmgmt_door_fd = door_create(dlmgmt_handler, NULL,
DOOR_REFUSE_DESC | DOOR_NO_CANCEL)) == -1) {
err = errno;
dlmgmt_log(LOG_ERR, "door_create() failed: %s",
strerror(err));
return (err);
}
return (err);
}
static void
dlmgmt_door_fini(void)
{
if (dlmgmt_door_fd == -1)
return;
if (door_revoke(dlmgmt_door_fd) == -1) {
dlmgmt_log(LOG_WARNING, "door_revoke(%s) failed: %s",
DLMGMT_DOOR, strerror(errno));
}
(void) dlmgmt_set_doorfd(B_FALSE);
dlmgmt_door_fd = -1;
}
static int
dlmgmt_door_attach(zoneid_t zoneid, char *rootdir)
{
int fd;
int err = 0;
char doorpath[MAXPATHLEN];
(void) snprintf(doorpath, sizeof (doorpath), "%s%s", rootdir,
DLMGMT_DOOR);
if ((fd = open(doorpath, O_CREAT|O_RDONLY, 0644)) == -1) {
err = errno;
dlmgmt_log(LOG_ERR, "open(%s) failed: %s", doorpath,
strerror(err));
return (err);
}
(void) close(fd);
if (chown(doorpath, UID_DLADM, GID_NETADM) == -1)
return (errno);
(void) fdetach(doorpath);
if (fattach(dlmgmt_door_fd, doorpath) != 0) {
err = errno;
dlmgmt_log(LOG_ERR, "fattach(%s) failed: %s", doorpath,
strerror(err));
} else if (zoneid == GLOBAL_ZONEID) {
if ((err = dlmgmt_set_doorfd(B_TRUE)) != 0) {
dlmgmt_log(LOG_ERR, "cannot set kernel doorfd: %s",
strerror(err));
}
}
return (err);
}
int
dlmgmt_zone_init(zoneid_t zoneid)
{
char rootdir[MAXPATHLEN], tmpfsdir[MAXPATHLEN];
int err;
struct stat statbuf;
if (zoneid == GLOBAL_ZONEID) {
rootdir[0] = '\0';
} else if (zone_getattr(zoneid, ZONE_ATTR_ROOT, rootdir,
sizeof (rootdir)) < 0) {
return (errno);
}
(void) snprintf(tmpfsdir, sizeof (tmpfsdir), "%s%s", rootdir,
DLMGMT_TMPFS_DIR);
if (stat(tmpfsdir, &statbuf) < 0) {
if (mkdir(tmpfsdir, (mode_t)0755) < 0)
return (errno);
} else if ((statbuf.st_mode & S_IFMT) != S_IFDIR) {
return (ENOTDIR);
}
if ((chmod(tmpfsdir, 0755) < 0) ||
(chown(tmpfsdir, UID_DLADM, GID_NETADM) < 0)) {
return (EPERM);
}
if ((err = dlmgmt_db_init(zoneid, rootdir)) != 0)
return (err);
return (dlmgmt_door_attach(zoneid, rootdir));
}
static int
dlmgmt_allzones_init(void)
{
int i;
zoneid_t *zids = NULL;
uint_t nzids, nzids_saved;
if (zone_list(NULL, &nzids) != 0)
return (errno);
again:
nzids *= 2;
if ((zids = malloc(nzids * sizeof (zoneid_t))) == NULL)
return (errno);
nzids_saved = nzids;
if (zone_list(zids, &nzids) != 0) {
free(zids);
return (errno);
}
if (nzids > nzids_saved) {
free(zids);
goto again;
}
for (i = 0; i < nzids; i++) {
int res;
zone_status_t status;
if (zone_getattr(zids[i], ZONE_ATTR_STATUS, &status,
sizeof (status)) < 0) {
continue;
}
switch (status) {
case ZONE_IS_SHUTTING_DOWN:
case ZONE_IS_EMPTY:
case ZONE_IS_DOWN:
case ZONE_IS_DYING:
case ZONE_IS_DEAD:
case ZONE_IS_INITIALIZED:
case ZONE_IS_UNINITIALIZED:
continue;
default:
break;
}
if ((res = dlmgmt_zone_init(zids[i])) != 0) {
(void) fprintf(stderr, "zone (%ld) init error %s",
zids[i], strerror(res));
dlmgmt_log(LOG_ERR, "zone (%d) init error %s",
zids[i], strerror(res));
}
}
free(zids);
return (0);
}
static int
dlmgmt_init(void)
{
int err;
char *fmri, *c;
char filename[MAXPATHLEN];
if (dladm_open(&dld_handle) != DLADM_STATUS_OK) {
dlmgmt_log(LOG_ERR, "dladm_open() failed");
return (EPERM);
}
if (signal(SIGTERM, dlmgmtd_exit) == SIG_ERR ||
signal(SIGINT, dlmgmtd_exit) == SIG_ERR) {
err = errno;
dlmgmt_log(LOG_ERR, "signal() for SIGTERM/INT failed: %s",
strerror(err));
return (err);
}
if (debug) {
(void) snprintf(cachefile, MAXPATHLEN, "%s/%s%s",
DLMGMT_TMPFS_DIR, progname, ".debug.cache");
} else {
if ((fmri = getenv("SMF_FMRI")) == NULL) {
dlmgmt_log(LOG_ERR, "dlmgmtd is an smf(7) managed "
"service and should not be run from the command "
"line.");
return (EINVAL);
}
if ((c = strchr(fmri, '/')) != NULL)
c++;
else
c = fmri;
(void) snprintf(filename, MAXPATHLEN, "%s.cache", c);
c = filename;
while ((c = strchr(c, '/')) != NULL)
*c = '-';
(void) snprintf(cachefile, MAXPATHLEN, "%s/%s",
DLMGMT_TMPFS_DIR, filename);
}
dlmgmt_linktable_init();
if ((err = dlmgmt_door_init()) != 0)
goto done;
if ((err = dlmgmt_allzones_init()) != 0)
dlmgmt_door_fini();
done:
if (err != 0)
dlmgmt_linktable_fini();
return (err);
}
static void
dlmgmt_fini(void)
{
dlmgmt_door_fini();
dlmgmt_linktable_fini();
if (dld_handle != NULL) {
dladm_close(dld_handle);
dld_handle = NULL;
}
}
static void
dlmgmt_inform_parent_exit(int rv)
{
if (debug)
return;
if (write(pfds[1], &rv, sizeof (int)) != sizeof (int)) {
dlmgmt_log(LOG_WARNING,
"dlmgmt_inform_parent_exit() failed: %s", strerror(errno));
(void) close(pfds[1]);
exit(EXIT_FAILURE);
}
(void) close(pfds[1]);
}
static void
dlmgmtd_exit(int signo)
{
(void) close(pfds[1]);
dlmgmt_fini();
exit(EXIT_FAILURE);
}
static void
usage(void)
{
(void) fprintf(stderr, "Usage: %s [-d]\n", progname);
exit(EXIT_FAILURE);
}
int
dlmgmt_drop_privileges(void)
{
priv_set_t *pset;
priv_ptype_t ptype;
zoneid_t zoneid = getzoneid();
int err = 0;
if ((pset = priv_allocset()) == NULL)
return (errno);
priv_basicset(pset);
(void) priv_delset(pset, PRIV_PROC_EXEC);
(void) priv_delset(pset, PRIV_PROC_INFO);
(void) priv_delset(pset, PRIV_PROC_SESSION);
(void) priv_delset(pset, PRIV_FILE_LINK_ANY);
if (zoneid == GLOBAL_ZONEID) {
ptype = PRIV_EFFECTIVE;
if (priv_addset(pset, PRIV_SYS_CONFIG) == -1 ||
priv_addset(pset, PRIV_SYS_DL_CONFIG) == -1)
err = errno;
} else {
(void) priv_delset(pset, PRIV_PROC_FORK);
ptype = PRIV_PERMITTED;
}
if (err == 0 && setppriv(PRIV_SET, ptype, pset) == -1)
err = errno;
priv_freeset(pset);
return (err);
}
int
dlmgmt_elevate_privileges(void)
{
priv_set_t *privset;
int err = 0;
if ((privset = priv_str_to_set("zone", ",", NULL)) == NULL)
return (errno);
if (setppriv(PRIV_SET, PRIV_EFFECTIVE, privset) == -1)
err = errno;
priv_freeset(privset);
return (err);
}
static int
dlmgmt_set_privileges(void)
{
int err;
(void) setgroups(0, NULL);
if (setegid(GID_NETADM) == -1 || seteuid(UID_DLADM) == -1)
err = errno;
else
err = dlmgmt_drop_privileges();
return (err);
}
static int
closefunc(void *arg, int fd)
{
if (fd != pfds[1])
(void) close(fd);
return (0);
}
static boolean_t
dlmgmt_daemonize(void)
{
pid_t pid;
int rv;
if (pipe(pfds) < 0) {
(void) fprintf(stderr, "%s: pipe() failed: %s\n",
progname, strerror(errno));
exit(EXIT_FAILURE);
}
if ((pid = fork()) == -1) {
(void) fprintf(stderr, "%s: fork() failed: %s\n",
progname, strerror(errno));
exit(EXIT_FAILURE);
} else if (pid > 0) {
(void) close(pfds[1]);
if (read(pfds[0], &rv, sizeof (int)) != sizeof (int)) {
(void) kill(pid, SIGKILL);
rv = EXIT_FAILURE;
}
(void) close(pfds[0]);
exit(rv);
}
(void) close(pfds[0]);
(void) setsid();
(void) fdwalk(closefunc, NULL);
(void) chdir("/");
openlog(progname, LOG_PID, LOG_DAEMON);
return (B_TRUE);
}
int
main(int argc, char *argv[])
{
int opt, err;
progname = strrchr(argv[0], '/');
if (progname != NULL)
progname++;
else
progname = argv[0];
while ((opt = getopt(argc, argv, "d")) != EOF) {
switch (opt) {
case 'd':
debug = B_TRUE;
break;
default:
usage();
}
}
if (!debug && !dlmgmt_daemonize())
return (EXIT_FAILURE);
if ((err = dlmgmt_init()) != 0) {
dlmgmt_log(LOG_ERR, "unable to initialize daemon: %s",
strerror(err));
goto child_out;
} else if ((err = dlmgmt_set_privileges()) != 0) {
dlmgmt_log(LOG_ERR, "unable to set daemon privileges: %s",
strerror(err));
dlmgmt_fini();
goto child_out;
}
dlmgmt_inform_parent_exit(EXIT_SUCCESS);
for (;;)
(void) pause();
child_out:
dlmgmt_inform_parent_exit(EXIT_FAILURE);
return (EXIT_FAILURE);
}