From 8943501993322c59a6eb5be456b0d716aafff21e Mon Sep 17 00:00:00 2001 From: Lennart Poettering Date: Wed, 27 May 2015 09:23:27 -0400 Subject: nspawn: finish user namespace support Signed-off-by: Anthony G. Basile --- src/shared/dev-setup.c | 29 ++++++++++++++++++++--------- src/shared/dev-setup.h | 4 +++- src/udev/udevd.c | 2 +- 3 files changed, 24 insertions(+), 11 deletions(-) (limited to 'src') diff --git a/src/shared/dev-setup.c b/src/shared/dev-setup.c index c9eb0a5efc..60687a62dd 100644 --- a/src/shared/dev-setup.c +++ b/src/shared/dev-setup.c @@ -24,15 +24,14 @@ #include #include -#include "dev-setup.h" #include "log.h" #include "macro.h" #include "util.h" #include "label.h" +#include "path-util.h" +#include "dev-setup.h" -int dev_setup(const char *prefix) { - const char *j, *k; - +int dev_setup(const char *prefix, uid_t uid, gid_t gid) { static const char symlinks[] = "-/proc/kcore\0" "/dev/core\0" "/proc/self/fd\0" "/dev/fd\0" @@ -40,7 +39,13 @@ int dev_setup(const char *prefix) { "/proc/self/fd/1\0" "/dev/stdout\0" "/proc/self/fd/2\0" "/dev/stderr\0"; + const char *j, *k; + int r; + NULSTR_FOREACH_PAIR(j, k, symlinks) { + _cleanup_free_ char *link_name = NULL; + const char *n; + if (j[0] == '-') { j++; @@ -49,15 +54,21 @@ int dev_setup(const char *prefix) { } if (prefix) { - _cleanup_free_ char *link_name = NULL; - - link_name = strjoin(prefix, "/", k, NULL); + link_name = prefix_root(prefix, k); if (!link_name) return -ENOMEM; - symlink_label(j, link_name); + n = link_name; } else - symlink_label(j, k); + n = k; + + r = symlink_label(j, n); + if (r < 0) + log_debug_errno(r, "Failed to symlink %s to %s: %m", j, n); + + if (uid != UID_INVALID || gid != GID_INVALID) + if (lchown(n, uid, gid) < 0) + log_debug_errno(errno, "Failed to chown %s: %m", n); } return 0; diff --git a/src/shared/dev-setup.h b/src/shared/dev-setup.h index 0adea22a99..e85d89e5bc 100644 --- a/src/shared/dev-setup.h +++ b/src/shared/dev-setup.h @@ -19,4 +19,6 @@ #pragma once -int dev_setup(const char *pathprefix); +#include + +int dev_setup(const char *prefix, uid_t uid, gid_t gid); diff --git a/src/udev/udevd.c b/src/udev/udevd.c index 578178008a..6cfb2bcfcd 100644 --- a/src/udev/udevd.c +++ b/src/udev/udevd.c @@ -1183,7 +1183,7 @@ int main(int argc, char *argv[]) { goto exit; } - dev_setup(NULL); + dev_setup(NULL, UID_INVALID, GID_INVALID); /* before opening new files, make sure std{in,out,err} fds are in a sane state */ if (arg_daemonize) { -- cgit v1.2.3-54-g00ecf