script.c 9.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406
  1. /*
  2. * dpkg - main program for package management
  3. * script.c - maintainer script routines
  4. *
  5. * Copyright © 1995 Ian Jackson <ian@chiark.greenend.org.uk>
  6. * Copyright © 2007-2013 Guillem Jover <guillem@debian.org>
  7. *
  8. * This is free software; you can redistribute it and/or modify
  9. * it under the terms of the GNU General Public License as published by
  10. * the Free Software Foundation; either version 2 of the License, or
  11. * (at your option) any later version.
  12. *
  13. * This is distributed in the hope that it will be useful,
  14. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  15. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  16. * GNU General Public License for more details.
  17. *
  18. * You should have received a copy of the GNU General Public License
  19. * along with this program. If not, see <https://www.gnu.org/licenses/>.
  20. */
  21. #include <config.h>
  22. #include <compat.h>
  23. #include <sys/types.h>
  24. #include <sys/stat.h>
  25. #include <assert.h>
  26. #include <errno.h>
  27. #include <string.h>
  28. #include <unistd.h>
  29. #include <stdlib.h>
  30. #ifdef WITH_SELINUX
  31. #include <selinux/selinux.h>
  32. #include <selinux/flask.h>
  33. #include <selinux/context.h>
  34. #endif
  35. #include <dpkg/i18n.h>
  36. #include <dpkg/dpkg.h>
  37. #include <dpkg/dpkg-db.h>
  38. #include <dpkg/pkg.h>
  39. #include <dpkg/subproc.h>
  40. #include <dpkg/command.h>
  41. #include <dpkg/triglib.h>
  42. #include "filesdb.h"
  43. #include "infodb.h"
  44. #include "main.h"
  45. void
  46. post_postinst_tasks(struct pkginfo *pkg, enum pkgstatus new_status)
  47. {
  48. if (new_status < stat_triggersawaited)
  49. pkg_set_status(pkg, new_status);
  50. else if (pkg->trigaw.head)
  51. pkg_set_status(pkg, stat_triggersawaited);
  52. else if (pkg->trigpend_head)
  53. pkg_set_status(pkg, stat_triggerspending);
  54. else
  55. pkg_set_status(pkg, stat_installed);
  56. modstatdb_note(pkg);
  57. debug(dbg_triggersdetail, "post_postinst_tasks - trig_incorporate");
  58. trig_incorporate(modstatdb_get_status());
  59. }
  60. static void
  61. post_script_tasks(void)
  62. {
  63. debug(dbg_triggersdetail, "post_script_tasks - ensure_diversions");
  64. ensure_diversions();
  65. debug(dbg_triggersdetail, "post_script_tasks - trig_incorporate");
  66. trig_incorporate(modstatdb_get_status());
  67. }
  68. static void
  69. cu_post_script_tasks(int argc, void **argv)
  70. {
  71. post_script_tasks();
  72. }
  73. static void
  74. setexecute(const char *path, struct stat *stab)
  75. {
  76. if ((stab->st_mode & 0555) == 0555)
  77. return;
  78. if (!chmod(path, 0755))
  79. return;
  80. ohshite(_("unable to set execute permissions on `%.250s'"), path);
  81. }
  82. /**
  83. * Returns the path to the script inside the chroot.
  84. */
  85. static const char *
  86. maintscript_pre_exec(struct command *cmd)
  87. {
  88. const char *admindir = dpkg_db_get_dir();
  89. size_t instdirl = strlen(instdir);
  90. if (*instdir) {
  91. if (strncmp(admindir, instdir, instdirl) != 0)
  92. ohshit(_("admindir must be inside instdir for dpkg to work properly"));
  93. if (setenv("DPKG_ADMINDIR", admindir + instdirl, 1) < 0)
  94. ohshite(_("unable to setenv for subprocesses"));
  95. if (chroot(instdir))
  96. ohshite(_("failed to chroot to `%.250s'"), instdir);
  97. }
  98. /* Switch to a known good directory to give the maintainer script
  99. * a saner environment, also needed after the chroot(). */
  100. if (chdir("/"))
  101. ohshite(_("failed to chdir to `%.255s'"), "/");
  102. if (debug_has_flag(dbg_scripts)) {
  103. struct varbuf args = VARBUF_INIT;
  104. const char **argv = cmd->argv;
  105. while (*++argv) {
  106. varbuf_add_char(&args, ' ');
  107. varbuf_add_str(&args, *argv);
  108. }
  109. varbuf_end_str(&args);
  110. debug(dbg_scripts, "fork/exec %s (%s )", cmd->filename,
  111. args.buf);
  112. varbuf_destroy(&args);
  113. }
  114. if (!instdirl)
  115. return cmd->filename;
  116. assert(strlen(cmd->filename) >= instdirl);
  117. return cmd->filename + instdirl;
  118. }
  119. /**
  120. * Set a new security execution context for the maintainer script.
  121. *
  122. * Try to create a new execution context based on the current one and the
  123. * specific maintainer script filename. If it's the same as the current
  124. * one, use the given fallback.
  125. */
  126. static int
  127. maintscript_set_exec_context(struct command *cmd, const char *fallback)
  128. {
  129. int rc = 0;
  130. #ifdef WITH_SELINUX
  131. security_context_t curcon = NULL, newcon = NULL, filecon = NULL;
  132. context_t tmpcon = NULL;
  133. if (is_selinux_enabled() < 1)
  134. return 0;
  135. rc = getcon(&curcon);
  136. if (rc < 0)
  137. goto out;
  138. rc = getfilecon(cmd->filename, &filecon);
  139. if (rc < 0)
  140. goto out;
  141. rc = security_compute_create(curcon, filecon, SECCLASS_PROCESS, &newcon);
  142. if (rc < 0)
  143. goto out;
  144. if (strcmp(curcon, newcon) == 0) {
  145. /* No default transition, use fallback for now. */
  146. rc = -1;
  147. tmpcon = context_new(curcon);
  148. if (tmpcon == NULL)
  149. goto out;
  150. if (context_type_set(tmpcon, fallback))
  151. goto out;
  152. freecon(newcon);
  153. newcon = strdup(context_str(tmpcon));
  154. if (newcon == NULL)
  155. goto out;
  156. }
  157. rc = setexeccon(newcon);
  158. out:
  159. if (rc < 0 && security_getenforce() == 0)
  160. rc = 0;
  161. context_free(tmpcon);
  162. freecon(newcon);
  163. freecon(curcon);
  164. freecon(filecon);
  165. #endif
  166. return rc < 0 ? rc : 0;
  167. }
  168. static int
  169. maintscript_exec(struct pkginfo *pkg, struct pkgbin *pkgbin,
  170. struct command *cmd, struct stat *stab, int warn)
  171. {
  172. pid_t pid;
  173. int rc;
  174. setexecute(cmd->filename, stab);
  175. push_cleanup(cu_post_script_tasks, ehflag_bombout, NULL, 0, 0);
  176. pid = subproc_fork();
  177. if (pid == 0) {
  178. char *pkg_count;
  179. m_asprintf(&pkg_count, "%d", pkgset_installed_instances(pkg->set));
  180. if (setenv("DPKG_MAINTSCRIPT_PACKAGE", pkg->set->name, 1) ||
  181. setenv("DPKG_MAINTSCRIPT_PACKAGE_REFCOUNT", pkg_count, 1) ||
  182. setenv("DPKG_MAINTSCRIPT_ARCH", pkgbin->arch->name, 1) ||
  183. setenv("DPKG_MAINTSCRIPT_NAME", cmd->argv[0], 1) ||
  184. setenv("DPKG_RUNNING_VERSION", PACKAGE_VERSION, 1))
  185. ohshite(_("unable to setenv for maintainer script"));
  186. cmd->filename = cmd->argv[0] = maintscript_pre_exec(cmd);
  187. if (maintscript_set_exec_context(cmd, "dpkg_script_t") < 0)
  188. ohshite(_("cannot set security execution context for "
  189. "maintainer script"));
  190. command_exec(cmd);
  191. }
  192. subproc_signals_setup(cmd->name); /* This does a push_cleanup(). */
  193. rc = subproc_wait_check(pid, cmd->name, warn);
  194. pop_cleanup(ehflag_normaltidy);
  195. pop_cleanup(ehflag_normaltidy);
  196. return rc;
  197. }
  198. static int
  199. vmaintscript_installed(struct pkginfo *pkg, const char *scriptname,
  200. const char *desc, va_list args)
  201. {
  202. struct command cmd;
  203. const char *scriptpath;
  204. struct stat stab;
  205. char buf[100];
  206. scriptpath = pkg_infodb_get_file(pkg, &pkg->installed, scriptname);
  207. sprintf(buf, _("installed %s script"), desc);
  208. command_init(&cmd, scriptpath, buf);
  209. command_add_arg(&cmd, scriptname);
  210. command_add_argv(&cmd, args);
  211. if (stat(scriptpath, &stab)) {
  212. command_destroy(&cmd);
  213. if (errno == ENOENT) {
  214. debug(dbg_scripts,
  215. "vmaintscript_installed nonexistent %s",
  216. scriptname);
  217. return 0;
  218. }
  219. ohshite(_("unable to stat %s `%.250s'"), buf, scriptpath);
  220. }
  221. maintscript_exec(pkg, &pkg->installed, &cmd, &stab, 0);
  222. command_destroy(&cmd);
  223. return 1;
  224. }
  225. /*
  226. * All ...'s in maintscript_* are const char *'s.
  227. */
  228. int
  229. maintscript_installed(struct pkginfo *pkg, const char *scriptname,
  230. const char *desc, ...)
  231. {
  232. va_list args;
  233. int rc;
  234. va_start(args, desc);
  235. rc = vmaintscript_installed(pkg, scriptname, desc, args);
  236. va_end(args);
  237. if (rc)
  238. post_script_tasks();
  239. return rc;
  240. }
  241. int
  242. maintscript_postinst(struct pkginfo *pkg, ...)
  243. {
  244. va_list args;
  245. int rc;
  246. va_start(args, pkg);
  247. rc = vmaintscript_installed(pkg, POSTINSTFILE, "post-installation", args);
  248. va_end(args);
  249. if (rc)
  250. ensure_diversions();
  251. return rc;
  252. }
  253. int
  254. maintscript_new(struct pkginfo *pkg, const char *scriptname,
  255. const char *desc, const char *cidir, char *cidirrest, ...)
  256. {
  257. struct command cmd;
  258. struct stat stab;
  259. va_list args;
  260. char buf[100];
  261. strcpy(cidirrest, scriptname);
  262. sprintf(buf, _("new %s script"), desc);
  263. va_start(args, cidirrest);
  264. command_init(&cmd, cidir, buf);
  265. command_add_arg(&cmd, scriptname);
  266. command_add_argv(&cmd, args);
  267. va_end(args);
  268. if (stat(cidir, &stab)) {
  269. command_destroy(&cmd);
  270. if (errno == ENOENT) {
  271. debug(dbg_scripts,
  272. "maintscript_new nonexistent %s '%s'",
  273. scriptname, cidir);
  274. return 0;
  275. }
  276. ohshite(_("unable to stat %s `%.250s'"), buf, cidir);
  277. }
  278. maintscript_exec(pkg, &pkg->available, &cmd, &stab, 0);
  279. command_destroy(&cmd);
  280. post_script_tasks();
  281. return 1;
  282. }
  283. int
  284. maintscript_fallback(struct pkginfo *pkg,
  285. const char *scriptname, const char *desc,
  286. const char *cidir, char *cidirrest,
  287. const char *ifok, const char *iffallback)
  288. {
  289. struct command cmd;
  290. const char *oldscriptpath;
  291. struct stat stab;
  292. char buf[100];
  293. oldscriptpath = pkg_infodb_get_file(pkg, &pkg->installed, scriptname);
  294. sprintf(buf, _("old %s script"), desc);
  295. command_init(&cmd, oldscriptpath, buf);
  296. command_add_args(&cmd, scriptname, ifok,
  297. versiondescribe(&pkg->available.version, vdew_nonambig),
  298. NULL);
  299. if (stat(oldscriptpath, &stab)) {
  300. if (errno == ENOENT) {
  301. debug(dbg_scripts,
  302. "maintscript_fallback nonexistent %s '%s'",
  303. scriptname, oldscriptpath);
  304. command_destroy(&cmd);
  305. return 0;
  306. }
  307. warning(_("unable to stat %s '%.250s': %s"),
  308. cmd.name, oldscriptpath, strerror(errno));
  309. } else {
  310. if (!maintscript_exec(pkg, &pkg->installed, &cmd, &stab, PROCWARN)) {
  311. command_destroy(&cmd);
  312. post_script_tasks();
  313. return 1;
  314. }
  315. }
  316. notice(_("trying script from the new package instead ..."));
  317. strcpy(cidirrest, scriptname);
  318. sprintf(buf, _("new %s script"), desc);
  319. command_destroy(&cmd);
  320. command_init(&cmd, cidir, buf);
  321. command_add_args(&cmd, scriptname, iffallback,
  322. versiondescribe(&pkg->installed.version, vdew_nonambig),
  323. NULL);
  324. if (stat(cidir, &stab)) {
  325. command_destroy(&cmd);
  326. if (errno == ENOENT)
  327. ohshit(_("there is no script in the new version of the package - giving up"));
  328. else
  329. ohshite(_("unable to stat %s `%.250s'"), buf, cidir);
  330. }
  331. maintscript_exec(pkg, &pkg->available, &cmd, &stab, 0);
  332. notice(_("... it looks like that went OK"));
  333. command_destroy(&cmd);
  334. post_script_tasks();
  335. return 1;
  336. }