Compare commits

..
91 Commits
41 .. 46
Author SHA1 Message Date
Patrick McCarty 8ace503438 Release v46
This release fixes a build issue when not passing -Wl,--copy-dt-needed-entries
to the compiler.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2018-05-25 21:56:43 -07:00
Patrick McCarty 2c87f83adc build: add LIBSYSTEMD_LIBS to link line
For the regular Clear Linux build, the -lsystemd option was not needed at link
time due to -Wl,--copy-dt-needed-entries being used. Without that option
though, the linking of clr_debug_daemon will fail.

Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2018-05-25 21:55:28 -07:00
Patrick McCarty 67b9b3acc8 Update gitignore
Signed-off-by: Patrick McCarty <patrick.mccarty@intel.com>
2018-05-25 21:38:06 -07:00
Arjan van de Ven d108c0af64 add cdn-alt 2018-05-17 13:54:16 +00:00
Auke Kok 98e802b4cc Also install socket unit. 2018-04-24 13:04:33 -07:00
Auke Kok 612801b0c8 Make -daemon socket activated. 2018-04-23 15:15:33 -07:00
Arjan van de Ven 3c2ad26baa have tar follow symlinks 2017-12-23 00:49:24 +00:00
Arjan van de Ven d20d585e5c much shorter timeouts 2017-12-10 14:25:07 +00:00
Icarus Sparry 1f3a0f0be4 Extract tar file as dbginfo
Make /var/cache/debuginfo and its contents owned by dgbinfo. Create
the directories as this user, and switch to run as this user.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-10-31 13:35:29 -07:00
Icarus Sparry d2d67bdb1d Change tmpfiles.d configuration
Use the dbginfo user for the directories.

Signed-off-by: Icarus Sparry <icarus.w.sparry@intel.com>
2017-10-31 09:47:39 -07:00
Auke Kok 60db7bab0f v43 2017-06-06 13:28:11 -07:00
Auke Kok ef6b11498a DefaultDependencies keyword is only valid in [Unit] context. 2017-06-06 13:27:20 -07:00
Auke Kok efeed3e83f v42. 2017-06-01 16:22:00 -07:00
Auke Kok f5542e7fbb Fetch timestamp from debuginfo server.
We trigger redownloads from the server if the timestamp of
downloaded tar files is too new. An easy way around this issue
is to request the timestamp from the server instead of using
the download time. A `touch` of the tar then assures that
the downloaded file has the same timestamp as the server has.
2017-06-01 16:19:15 -07:00
Arjan van de Ven be8a99da53 allow service to start early 2017-05-07 15:42:30 +00:00
Ikey Doherty c9304402e2 Bump v38 to resync configure + tags
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2017-03-09 17:48:59 +00:00
Ikey Doherty 6e202f13f7 Bump v34
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2017-03-09 17:46:10 +00:00
Ikey Doherty 6735f8f6ed nica/files: Ensure we really do break on a read error
Previously nc_copy_file would return true regardless of a source read
error, flagged in analysis. Ensure we bypass the set of ret to true and
return the correct value in all instances.

Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2017-03-09 15:44:09 +00:00
Ikey Doherty 8b3777ab99 server: Remove useless assignment of prefix
This particular assignment is never used, as if this path fails, we go to
the thread end. We then reassign prefix after we split the input string.

Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2017-03-09 15:38:29 +00:00
Ikey Doherty 84350939ef nica/hashmap: Fix signature issue & item dereference
The signature was incorrect for inserting buckets, as we used an int, not
a boolean. Another issue resolved with this change is the potential
dereferencing of a null pointer by not having checked first if item was
NULL when setting the next pointer.

Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2017-03-09 15:35:29 +00:00
Arjan van de Ven 72b1120a40 add --no-same-permissions as well 2017-03-09 14:52:37 +00:00
Auke Kok d3d5fab301 Tag v33 2016-11-01 09:20:19 -07:00
Auke Kok e377433a9d Return on error here too.
Missed a 'return' catching an error.
2016-11-01 09:15:12 -07:00
Auke Kok afa92c77b1 Add reasonable connection timeout limits.
Adds a 30second connection timeout, and a low bandwith timeout
value (at 1kb/sec over 30 seconds) where the attempt will fail.
This provides some feedback to users that network issues are
preventing debug info from being loaded.
2016-11-01 09:15:12 -07:00
Arjan van de Ven a01ce4c329 dumb down due to limited infra 2016-11-01 13:17:49 +00:00
Arjan van de Ven 1eaaac582c use http/2 2016-11-01 12:56:35 +00:00
Arjan van de Ven 935dbee3c7 use CDN urls 2016-11-01 12:53:04 +00:00
Arjan van de Ven 0065ef2670 don't spew the journal 2016-11-01 12:52:17 +00:00
Ikey Doherty b5b4030f7c Release v32
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-18 19:21:20 +01:00
Ikey Doherty de9e0ce5c5 server: Disallow gdb -p attach, drop CAP_SYS_ADMIN
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-18 15:03:28 +01:00
Ikey Doherty 9e400bd149 Use correct types in absence of stdatomic.h
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-18 14:37:07 +01:00
Ikey Doherty f5a65358af Use pthread mutex in the absence of stdatomic C11 atomics
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-18 14:33:26 +01:00
Ikey Doherty c82a007960 Add configure output, and check for stdatomics
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-18 14:18:56 +01:00
Ikey Doherty 02ece110b5 Release v31
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-17 17:29:35 +01:00
Ikey Doherty 3a6bf4a167 Fix print statements when a dir cannot be created
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-17 17:20:31 +01:00
Ikey Doherty fc61591870 Fix distcheck
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-17 17:16:53 +01:00
Ikey Doherty 2f26fc55c7 Stick myself in authors
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-17 17:14:47 +01:00
Ikey Doherty dfff530803 Address unused return issues
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-17 17:13:41 +01:00
Ikey Doherty 9685fcb632 Fix some warnings
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-17 17:07:57 +01:00
Ikey Doherty 14495e064b Make use of autofree to simplify exit conditions
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-17 17:03:54 +01:00
Ikey Doherty 7b64fb601d server: Forcibly inline functions
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-17 16:41:17 +01:00
Ikey Doherty b24d93fe3d server: Atomically manage a maximum connection ceiling
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-17 16:32:01 +01:00
Ikey Doherty 5b7c484b64 Fix up some warnings
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-17 15:17:05 +01:00
Ikey Doherty d23b8e17bd fuse: Greatly simplify allocation and management of strings
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 17:08:00 +01:00
Ikey Doherty b120d1c38f Fix last of the mkdir users
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 16:54:09 +01:00
Ikey Doherty bbc34ad790 Get rid of mkdir calls
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 16:50:27 +01:00
Ikey Doherty caf84d9b5f Use consistent file headers
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 16:43:09 +01:00
Ikey Doherty bc276b4920 Incorporate the nica files component
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 16:42:41 +01:00
Ikey Doherty 78485dc583 Take care of unused variables
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 16:37:52 +01:00
Ikey Doherty ce02c64c0c Drop glib entirely
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 16:34:21 +01:00
Ikey Doherty f272c08d4f Use a hashmap to maintain memory
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 16:30:17 +01:00
Ikey Doherty 3babbe4b7b Incorporate portions of libnica
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 16:18:38 +01:00
Ikey Doherty aad87bbdc1 Use curly braces everywhere
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 15:48:34 +01:00
Ikey Doherty 4505d32c68 Fix last commit
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 15:35:01 +01:00
Ikey Doherty 67a9735acb Swap GMutex for pthread_mutex_t
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 15:33:37 +01:00
Ikey Doherty 1c043d5bd7 Add strict flags
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 15:22:21 +01:00
Ikey Doherty 8c01f4012f Apply clang-format to codebase (switching to spaces for maintainence)
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 15:20:29 +01:00
Ikey Doherty 955c1b7e99 Incorporate clang-format helpers (3.8)
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 15:20:12 +01:00
Ikey Doherty a92e6f386a Add an autogen script
Signed-off-by: Ikey Doherty <michael.i.doherty@intel.com>
2016-05-11 15:17:46 +01:00
Arjan van de Ven 670069d659 version 30 2016-02-01 14:34:27 -05:00
Patrick McCarty be74f893e6 Bump version for release 2015-10-20 10:24:49 -07:00
Patrick McCarty 7a5e4a9acd Do not log for non-fatal curl errors 2015-10-20 10:17:40 -07:00
Patrick McCarty 07a4c3d305 Bump version for release
This release fixes the handling of a server HTTP 304 response, now
treating it as non-fatal.
2015-10-02 12:15:07 -07:00
Patrick McCarty ab0e59628f Treat HTTP 304 codes as non-fatal
We set the If-Modified-Since header field for each GET request, and if
the condition fails, the server will respond with HTTP 304.

The 304 means the cached debuginfo is up-to-date, not requiring a fresh
download. Since this condition is non-fatal, avoid swapping the download
URLs in this case.
2015-10-02 12:15:02 -07:00
Patrick McCarty af4a3f64f0 Update gitignore 2015-10-02 10:36:39 -07:00
Patrick McCarty 8c65e96479 Bump version for release
This release fixes some compiler warnings and the distcheck target, and
addresses a recurrent 404 issue by avoiding a download attempt for
".tar" from the root debuginfo directory.
2015-09-29 12:32:23 -07:00
Patrick McCarty 7ea9a50b19 Avoid attempt to download {lib,src}/debug
The associated cache directories in /var/cache/debuginfo/{lib,src}
already exist, and the tar for / is not created on the server, so avoid
downloading it altogether.
2015-09-29 12:25:13 -07:00
Patrick McCarty e16ab76926 Refresh version in configure.ac
The configure.ac version was falling behind the tagged version...
2015-09-28 14:02:03 -07:00
Patrick McCarty 090cb27a34 Fix distcheck target
Adding two --with-* configure options for the systemd pkgconfig-defined
variables gives opportunity for distcheck to succeed; the variables use
hardcoded paths to /usr/lib/systemd/... without a PREFIX, so the paths
need to be relocated to $dc_install_base, a variable distcheck uses for
the normal variables that begin with PREFIX.
2015-09-28 13:52:24 -07:00
Patrick McCarty cbaf943fca Convert server to use modern Glib Thread API
Using a GStaticMutex and associated functions are deprecated, since
a GMutex can be statically allocated now (as of glib 2.32).
2015-09-25 14:20:22 -07:00
Patrick McCarty 32ae400e7d Update gitignore 2015-09-25 14:19:56 -07:00
Patrick McCarty 82f03f8e22 Fix build warning for implicitly included header 2015-09-25 14:00:33 -07:00
Arjan van de Ven c1f45d9f3c https 2015-07-20 23:02:09 -04:00
Arjan van de Ven bcff8fae39 default to the other server for now 2015-04-24 17:55:53 -04:00
Arjan van de Ven 66bab25bcd implement multi-url setup 2015-03-23 14:45:00 -04:00
Arjan van de Ven 49ac392f01 move logging up 2015-03-23 14:37:26 -04:00
Arjan van de Ven 71f4e789c4 better logging 2015-03-23 14:17:30 -04:00
Arjan van de Ven f776162882 few more checks 2015-03-23 14:15:42 -04:00
Arjan van de Ven a2abd8d2a9 put memory optimizations back 2015-03-23 14:12:31 -04:00
Arjan van de Ven 8844b0b0e1 Revert "Wait with curl init until the first connection comes in"
This reverts commit 6fb3c6f193.
2015-03-05 18:00:06 -05:00
Arjan van de Ven ca63e1be25 Wait with curl init until the first connection comes in
this should save a bunch of memory for the common case
2015-02-16 18:12:45 -05:00
Dimitri John Ledkov 078e9987d5 clr-debug-info: Use well known install paths.
systemd pkgconfig module is already required, which will have system
paths defined as pkg-config variables. This simplifies autofoo, and
installs tmpfile.d into a system location under /usr, rather than
admin location under /etc.
2015-02-02 10:30:49 +00:00
Arjan van de Ven 97431314b5 use the non-staging URL 2015-01-31 13:48:44 -05:00
Arjan van de Ven 07e1f033e1 version 11 2014-12-26 11:28:04 -05:00
Arjan van de Ven 45f22398ca don't "system" unless it's really really needed 2014-12-26 11:26:36 -05:00
Arjan van de Ven b538b457ce one more typo 2014-12-26 10:48:24 -05:00
Arjan van de Ven 09affa9bf5 make systemd not complain 2014-12-26 10:32:42 -05:00
Arjan van de Ven 2a217476f7 move the cache dir to /var/cache
for proper stateless operation
2014-12-26 10:32:05 -05:00
Arjan van de Ven 4d6639148f release 8 2014-12-25 19:29:02 -05:00
Arjan van de Ven 83509e34c7 XFS does nto support DT_DIR 2014-12-26 00:15:36 -05:00
Arjan van de Ven 43d54d03e6 Initial Import from Fenrus Linux 2014-12-25 23:53:41 -05:00
10 changed files with 114 additions and 37 deletions
+1
View File
@@ -8,6 +8,7 @@ clr_debug_prepare
Makefile
Makefile.in
aclocal.m4
ar-lib
autom4te.cache/
compile
config.h
+5 -4
View File
@@ -1,4 +1,4 @@
EXTRA_DIST = COPYING clr_debug_fuse.service clr_debug_daemon.service debuginfo.conf
EXTRA_DIST = COPYING clr_debug_fuse.service clr_debug_daemon.service clr_debug_daemon.socket debuginfo.conf
DISTCHECK_CONFIGURE_FLAGS = \
--with-systemdsystemunitdir=$$dc_install_base/$(systemdsystemunitdir) \
@@ -33,15 +33,16 @@ clr_debug_fuse_SOURCES = src/fuse.c src/client.c
clr_debug_daemon_SOURCES = src/server.c
clr_debug_daemon_CFLAGS = \
-pthread \
$(AM_CFLAGS)
$(AM_CFLAGS) \
$(LIBSYSTEMD_CFLAGS)
clr_debug_prepare_SOURCES = src/prepare.c
clr_debug_fuse_LDADD = ${fuse_LIBS} libnica.la
clr_debug_daemon_LDADD = ${curl_LIBS} libnica.la
clr_debug_daemon_LDADD = ${curl_LIBS} libnica.la ${LIBSYSTEMD_LIBS}
clr_debug_prepare_LDADD = libnica.la
systemdsystemunit_DATA = clr_debug_fuse.service clr_debug_daemon.service
systemdsystemunit_DATA = clr_debug_fuse.service clr_debug_daemon.service clr_debug_daemon.socket
tmpfiles_DATA = debuginfo.conf
+1 -2
View File
@@ -1,11 +1,10 @@
[Unit]
Description=Clear Linux debuginfo daemon
DefaultDependencies=no
[Service]
Type=simple
ExecStart=/usr/bin/clr_debug_daemon
DefaultDependencies=no
Nice=10
[Install]
WantedBy=multi-user.target
+9
View File
@@ -0,0 +1,9 @@
[Unit]
Description=Clear Linux OS debuginfo daemon
[Socket]
ListenStream=/run/clr-debug-info
SocketMode=0600
[Install]
WantedBy=sockets.target
+1 -2
View File
@@ -1,12 +1,11 @@
[Unit]
Description=Clear Linux debuginfo fuse monitor
After=clr_debug_daemon.service
DefaultDependencies=no
[Service]
Type=simple
ExecStart=/usr/bin/clr_debug_fuse
DefaultDependencies=no
Nice=10
[Install]
WantedBy=multi-user.target
+3 -1
View File
@@ -2,15 +2,17 @@
# Process this file with autoconf to produce a configure script.
AC_PREREQ([2.66])
AC_INIT(clr-debug-info, 38, arjan@linux.intel.com)
AC_INIT(clr-debug-info, 46, arjan@linux.intel.com)
AM_INIT_AUTOMAKE([foreign -Wall -W subdir-objects])
AM_SILENT_RULES([yes])
AC_PROG_CC
AM_PROG_AR
AC_LANG(C)
AC_CONFIG_HEADERS([config.h])
PKG_CHECK_MODULES([curl], [libcurl])
PKG_CHECK_MODULES([fuse], [fuse])
PKG_CHECK_MODULES([SYSTEMD], [systemd])
PKG_CHECK_MODULES([LIBSYSTEMD], [libsystemd])
LT_INIT
dir=""
+4 -2
View File
@@ -8,5 +8,7 @@
# See tmpfiles.d(5) for details
# Clear tmp directories separately, to make them easier to override
d /var/cache/debuginfo/lib 755 root root 10d
d /var/cache/debuginfo/src 755 root root 1d
# Unfortunatly tmpfiles doesn't change the ownership for things if they
# are not listed.
d /var/cache/debuginfo/lib 755 dbginfo dbginfo 10d
d /var/cache/debuginfo/src 755 dbginfo dbginfo 1d
+4 -5
View File
@@ -37,8 +37,8 @@
#include <unistd.h>
/* 0.75 seconds timeout */
#define TIMEOUT 750000
#define TIMEOUT2 15000
#define TIMEOUT 75000
#define TIMEOUT2 1500
#define TIMEOUT3 500
char *prefix = "src";
@@ -66,12 +66,11 @@ void try_to_get(const char *path, int pid, time_t timestamp)
}
sun.sun_family = AF_UNIX;
strcpy(sun.sun_path, ":clr-debug-info");
sun.sun_path[0] = 0; /* anonymous unix socket */
strcpy(sun.sun_path, "/run/clr-debug-info");
ret = connect(sockfd,
(struct sockaddr *)&sun,
offsetof(struct sockaddr_un, sun_path) + strlen(":clr-debug-info") + 1);
offsetof(struct sockaddr_un, sun_path) + strlen("/run/clr-debug-info") + 1);
if (ret < 0) {
printf("Cannot connect %s\n", strerror(errno));
close(sockfd);
+1 -1
View File
@@ -137,7 +137,7 @@ static void do_one_file(char *base1, char *base2, char *path, int isdir)
if (!isdir &&
asprintf(&command,
"tar --no-recursion -C %s -Jcf %s %s &",
"tar --no-recursion -h -C %s -Jcf %s %s &",
base1,
fullpath2,
path) >= 0) {
+85 -20
View File
@@ -27,9 +27,11 @@
#define _GNU_SOURCE
#include <errno.h>
#include <grp.h>
#include <linux/capability.h>
#include <malloc.h>
#include <pthread.h>
#include <pwd.h>
#include <signal.h>
#include <stddef.h>
#include <stdio.h>
@@ -47,6 +49,8 @@
#include <curl/curl.h>
#include "systemd/sd-daemon.h"
#include "config.h"
#ifdef HAVE_ATOMIC_SUPPORT
@@ -56,7 +60,7 @@
static pthread_mutex_t dupes_mutex = PTHREAD_MUTEX_INITIALIZER;
char *urls[2] = { "https://cdn.download.clearlinux.org/debuginfo/",
"https://cdn.download.clearlinux.org/debuginfo/" };
"https://cdn-alt.download.clearlinux.org/debuginfo/" };
int urlcounter = 1;
static NcHashmap *hash = NULL;
@@ -162,6 +166,7 @@ static int curl_get_file(const char *url, const char *prefix, time_t timestamp)
{
CURLcode code;
long ret;
long changed;
int fd;
char filename[PATH_MAX];
CURL *curl = NULL;
@@ -203,6 +208,9 @@ static int curl_get_file(const char *url, const char *prefix, time_t timestamp)
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_TIME, 30);
curl_easy_setopt(curl, CURLOPT_LOW_SPEED_LIMIT, 1024);
/* request timestamp of files from server */
curl_easy_setopt(curl, CURLOPT_FILETIME, 1);
if (timestamp) {
curl_easy_setopt(curl, CURLOPT_TIMECONDITION, CURL_TIMECOND_IFMODSINCE);
curl_easy_setopt(curl, CURLOPT_TIMEVALUE, timestamp);
@@ -230,6 +238,17 @@ static int curl_get_file(const char *url, const char *prefix, time_t timestamp)
}
if (ret == 200) {
/* get timestamp, if any */
curl_easy_getinfo(curl, CURLINFO_FILETIME, &changed);
if (changed >= 0) {
struct timespec times[2];
times[0].tv_sec = (time_t)changed;
times[0].tv_nsec = 0;
times[1].tv_sec = (time_t)changed;
times[1].tv_nsec = 0;
futimens(fd, times);
}
autofree(char) *command = NULL;
// printf("Filename is %s\n", filename);
@@ -237,7 +256,8 @@ static int curl_get_file(const char *url, const char *prefix, time_t timestamp)
stat(filename, &statbuf);
if (statbuf.st_size > 0 &&
asprintf(&command,
"tar -C /var/cache/debuginfo/%s --no-same-owner --no-same-permissions -xf %s",
"tar -C /var/cache/debuginfo/%s --no-same-owner "
"--no-same-permissions -xf %s",
prefix,
filename) >= 0) {
if (system(command) != 0) {
@@ -334,7 +354,7 @@ static void *server_thread(void *arg)
}
gettimeofday(&after, NULL);
#if 0
#if 0
if (timedelta(before, after) > 0.6)
printf("Request for %s took %5.2f seconds (%i - %i)\n",
url,
@@ -360,8 +380,19 @@ int main(__nc_unused__ int argc, __nc_unused__ char **argv)
struct sockaddr_un sun;
int ret;
int curl_done = 0;
uid_t dbg_user = 0;
gid_t dbg_group = 0;
struct passwd *passwdentry;
const char *required_paths[] = { "/var/cache/debuginfo/lib", "/var/cache/debuginfo/src" };
umask(0);
passwdentry = getpwnam("dbginfo");
if (passwdentry) {
dbg_user = passwdentry->pw_uid;
dbg_group = passwdentry->pw_gid;
}
endpwent();
if (prctl(PR_SET_DUMPABLE, 0) != 0) {
fprintf(stderr,
"Failed to disable PR_SET_DUMPABLE. Do NOT gdb attach this process: %s\n",
@@ -376,36 +407,70 @@ int main(__nc_unused__ int argc, __nc_unused__ char **argv)
for (size_t i = 0; i < ARRAY_SIZE(required_paths); i++) {
const char *req_path = required_paths[i];
if (nc_file_exists(req_path)) {
continue;
struct stat st = { .st_ino = 0 };
if (lstat(req_path, &st) == 0) {
/* If the file already exists, check ownership
* and delete tree if incorrect. Essentially a
* one-off operation to transition from root owned to
* dbginfo owned */
if (st.st_uid == dbg_user) {
continue;
}
fprintf(stderr, "Removing old debug information %s\n", req_path);
nc_rm_rf(req_path);
}
if (!nc_mkdir_p(req_path, 00755)) {
fprintf(stderr, "Failed to mkdir: %s %s\n", strerror(errno), req_path);
return EXIT_FAILURE;
}
if (chown(req_path, dbg_user, dbg_group) != 0) {
fprintf(stderr, "Failed to chown: %s %s\n", strerror(errno), req_path);
return EXIT_FAILURE;
}
}
signal(SIGPIPE, SIG_IGN);
sockfd = socket(AF_UNIX, SOCK_STREAM, 0);
if (sockfd < 0) {
if (sd_listen_fds(0) == 1) {
/* systemd socket activation */
printf("Received socket from systemd socket activation\n");
sockfd = SD_LISTEN_FDS_START + 0;
} else if (sd_listen_fds(0) > 1) {
printf("Too many file descriptors received.\n");
exit(1);
} else {
sockfd = socket(AF_UNIX, SOCK_STREAM, 0);
if (sockfd < 0) {
return EXIT_FAILURE;
}
sun.sun_family = AF_UNIX;
strcpy(sun.sun_path, "/run/clr-debug-info");
ret = bind(sockfd,
(struct sockaddr *)&sun,
offsetof(struct sockaddr_un, sun_path) + strlen("/run/clr-debug-info") + 1);
if (ret < 0) {
printf("Failed to bind:%s \n", strerror(errno));
return EXIT_FAILURE;
}
if (listen(sockfd, 16) < 0) {
printf("Failed to listen:%s \n", strerror(errno));
return EXIT_FAILURE;
}
}
if (setgid(dbg_group)) {
fprintf(stderr, "Unable to drop privileges setgid %s\n", strerror(errno));
return EXIT_FAILURE;
}
sun.sun_family = AF_UNIX;
strcpy(sun.sun_path, ":clr-debug-info");
sun.sun_path[0] = 0; /* anonymous unix socket */
ret = bind(sockfd,
(struct sockaddr *)&sun,
offsetof(struct sockaddr_un, sun_path) + strlen(":clr-debug-info") + 1);
if (ret < 0) {
printf("Failed to bind:%s \n", strerror(errno));
if (setgroups(1, &dbg_group)) {
fprintf(stderr, "Unable to drop privileges setgroups %s\n", strerror(errno));
return EXIT_FAILURE;
}
if (listen(sockfd, 16) < 0) {
printf("Failed to listen:%s \n", strerror(errno));
if (setuid(dbg_user)) {
fprintf(stderr, "Unable to drop privileges setuid %s\n", strerror(errno));
return EXIT_FAILURE;
}