1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
|
/*-*- Mode: C; c-basic-offset: 8; indent-tabs-mode: nil -*-*/
/***
This file is part of systemd.
Copyright 2014 Lennart Poettering
systemd is free software; you can redistribute it and/or modify it
under the terms of the GNU Lesser General Public License as published by
the Free Software Foundation; either version 2.1 of the License, or
(at your option) any later version.
systemd is distributed in the hope that it will be useful, but
WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
Lesser General Public License for more details.
You should have received a copy of the GNU Lesser General Public License
along with systemd; If not, see <http://www.gnu.org/licenses/>.
***/
#include "util.h"
#include "label.h"
static int apply_timestamp(const char *path, struct timespec *ts) {
struct timespec twice[2];
struct stat st;
assert(path);
assert(ts);
if (stat(path, &st) >= 0) {
/* Is the timestamp file already newer than the OS? If so, there's nothing to do. */
if (st.st_mtim.tv_sec > ts->tv_sec ||
(st.st_mtim.tv_sec == ts->tv_sec && st.st_mtim.tv_nsec >= ts->tv_nsec))
return 0;
/* It is older? Then let's update it */
twice[0] = *ts;
twice[1] = *ts;
if (utimensat(AT_FDCWD, path, twice, AT_SYMLINK_NOFOLLOW) < 0) {
if (errno == EROFS) {
log_debug("Can't update timestamp file %s, file system is read-only.", path);
return 0;
}
log_error("Failed to update timestamp on %s: %m", path);
return -errno;
}
} else if (errno == ENOENT) {
_cleanup_close_ int fd = -1;
int r;
/* The timestamp file doesn't exist yet? Then let's create it. */
r = label_context_set(path, S_IFREG);
if (r < 0) {
log_error("Failed to set SELinux context for %s: %s",
path, strerror(-r));
return r;
}
fd = open(path, O_CREAT|O_EXCL|O_WRONLY|O_TRUNC|O_CLOEXEC|O_NOCTTY|O_NOFOLLOW, 0644);
label_context_clear();
if (fd < 0) {
if (errno == EROFS) {
log_debug("Can't create timestamp file %s, file system is read-only.", path);
return 0;
}
log_error("Failed to create timestamp file %s: %m", path);
return -errno;
}
twice[0] = *ts;
twice[1] = *ts;
if (futimens(fd, twice) < 0) {
log_error("Failed to update timestamp on %s: %m", path);
return -errno;
}
} else {
log_error("Failed to stat() timestamp file %s: %m", path);
return -errno;
}
return 0;
}
int main(int argc, char *argv[]) {
struct stat st;
int r, q = 0;
log_set_target(LOG_TARGET_AUTO);
log_parse_environment();
log_open();
if (stat("/usr", &st) < 0) {
log_error("Failed to stat /usr: %m");
return EXIT_FAILURE;
}
r = label_init(NULL);
if (r < 0) {
log_error("SELinux setup failed: %s", strerror(-r));
goto finish;
}
r = apply_timestamp("/etc/.updated", &st.st_mtim);
q = apply_timestamp("/var/.updated", &st.st_mtim);
finish:
return r < 0 || q < 0 ? EXIT_FAILURE : EXIT_SUCCESS;
}
|