summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorLennart Poettering <lennart@poettering.net>2014-03-19 16:23:32 +0100
committerLennart Poettering <lennart@poettering.net>2014-03-19 16:25:11 +0100
commit2b85f4e19cee6a8533208f9fd618a7da6d32ad51 (patch)
tree531e0ce8b7a9a201bdb24634ac64e7f30325b699
parentd0ce77344bfb71e50da7296cd0d4f2529a109044 (diff)
core: Beef up PrivateDevices=
Also mount /dev/kdbus, /dev/mqueue and /dev/hugepages into the /dev for namespaced services.
-rw-r--r--src/core/namespace.c128
-rw-r--r--src/shared/dev-setup.c2
2 files changed, 94 insertions, 36 deletions
diff --git a/src/core/namespace.c b/src/core/namespace.c
index 3694368ab2..4cbb0a1565 100644
--- a/src/core/namespace.c
+++ b/src/core/namespace.c
@@ -142,9 +142,8 @@ static int mount_dev(BindMount *m) {
"/dev/urandom\0"
"/dev/tty\0";
- struct stat devnodes_stat[6] = {};
- const char *d;
- unsigned n = 0;
+ char temporary_mount[] = "/tmp/namespace-dev-XXXXXX";
+ const char *d, *dev = NULL, *devpts = NULL, *devshm = NULL, *devkdbus = NULL, *devhugepages = NULL, *devmqueue = NULL;
_cleanup_umask_ mode_t u;
int r;
@@ -152,56 +151,115 @@ static int mount_dev(BindMount *m) {
u = umask(0000);
- /* First: record device mode_t and dev_t */
+ if (!mkdtemp(temporary_mount))
+ return -errno;
+
+ dev = strappenda(temporary_mount, "/dev");
+ mkdir(dev, 0755);
+ if (mount("tmpfs", dev, "tmpfs", MS_NOSUID|MS_STRICTATIME, "mode=755") < 0) {
+ r = -errno;
+ goto fail;
+ }
+
+ devpts = strappenda(temporary_mount, "/dev/pts");
+ mkdir(devpts, 0755);
+ if (mount("/dev/pts", devpts, NULL, MS_BIND, NULL) < 0) {
+ r = -errno;
+ goto fail;
+ }
+
+ devshm = strappenda(temporary_mount, "/dev/shm");
+ mkdir(devshm, 01777);
+ r = mount("/dev/shm", devshm, NULL, MS_BIND, NULL);
+ if (r < 0) {
+ r = -errno;
+ goto fail;
+ }
+
+ devmqueue = strappenda(temporary_mount, "/dev/mqueue");
+ mkdir(devmqueue, 0755);
+ mount("/dev/mqueue", devmqueue, NULL, MS_BIND, NULL);
+
+ devkdbus = strappenda(temporary_mount, "/dev/kdbus");
+ mkdir(devkdbus, 0755);
+ mount("/dev/kdbus", devkdbus, NULL, MS_BIND, NULL);
+
+ devhugepages = strappenda(temporary_mount, "/dev/hugepages");
+ mkdir(devhugepages, 0755);
+ mount("/dev/hugepages", devhugepages, NULL, MS_BIND, NULL);
+
NULSTR_FOREACH(d, devnodes) {
- r = stat(d, &devnodes_stat[n]);
+ _cleanup_free_ char *dn = NULL;
+ struct stat st;
+
+ r = stat(d, &st);
if (r < 0) {
- if (errno != ENOENT)
- return -errno;
- } else {
- if (!S_ISBLK(devnodes_stat[n].st_mode) &&
- !S_ISCHR(devnodes_stat[n].st_mode))
- return -EINVAL;
+
+ if (errno == ENOENT)
+ continue;
+
+ r = -errno;
+ goto fail;
+ }
+
+ if (!S_ISBLK(st.st_mode) &&
+ !S_ISCHR(st.st_mode)) {
+ r = -EINVAL;
+ goto fail;
+ }
+
+ if (st.st_rdev == 0)
+ continue;
+
+ dn = strappend(temporary_mount, d);
+ if (!dn) {
+ r = -ENOMEM;
+ goto fail;
}
- n++;
+ r = mknod(dn, st.st_mode, st.st_rdev);
+ if (r < 0) {
+ r = -errno;
+ goto fail;
+ }
}
- assert(n == ELEMENTSOF(devnodes_stat));
+ dev_setup(temporary_mount);
- r = mount("tmpfs", "/dev", "tmpfs", MS_NOSUID|MS_STRICTATIME, "mode=755");
- if (r < 0)
- return m->ignore ? 0 : -errno;
+ if (mount(dev, "/dev/", NULL, MS_MOVE, NULL) < 0) {
+ r = -errno;
+ goto fail;
+ }
+ rmdir(dev);
+ rmdir(temporary_mount);
- mkdir_p("/dev/pts", 0755);
+ return 0;
- r = mount("devpts", "/dev/pts", "devpts", MS_NOSUID|MS_NOEXEC, "newinstance,ptmxmode=0666,mode=620,gid=" STRINGIFY(TTY_GID));
- if (r < 0)
- return m->ignore ? 0 : -errno;
+fail:
+ if (devpts)
+ umount(devpts);
- mkdir_p("/dev/shm", 0755);
+ if (devshm)
+ umount(devshm);
- r = mount("tmpfs", "/dev/shm", "tmpfs", MS_NOSUID|MS_NODEV|MS_STRICTATIME, "mode=1777");
- if (r < 0)
- return m->ignore ? 0 : -errno;
+ if (devkdbus)
+ umount(devkdbus);
- /* Second: actually create it */
- n = 0;
- NULSTR_FOREACH(d, devnodes) {
- if (devnodes_stat[n].st_rdev == 0)
- continue;
+ if (devhugepages)
+ umount(devhugepages);
- r = mknod(d, devnodes_stat[n].st_mode, devnodes_stat[n].st_rdev);
- if (r < 0)
- return m->ignore ? 0 : -errno;
+ if (devmqueue)
+ umount(devmqueue);
- n++;
+ if (dev) {
+ umount(dev);
+ rmdir(dev);
}
- dev_setup(NULL);
+ rmdir(temporary_mount);
- return 0;
+ return r;
}
static int apply_mount(
diff --git a/src/shared/dev-setup.c b/src/shared/dev-setup.c
index e025e17bbe..1a565d5470 100644
--- a/src/shared/dev-setup.c
+++ b/src/shared/dev-setup.c
@@ -64,7 +64,7 @@ int dev_setup(const char *prefix) {
if (j[0] == '-') {
j++;
- if (access(j, F_OK))
+ if (access(j, F_OK) < 0)
continue;
}