scsi: esp: check buffer length before reading scsi command
[qemu.git] / os-posix.c
1 /*
2 * os-posix.c
3 *
4 * Copyright (c) 2003-2008 Fabrice Bellard
5 * Copyright (c) 2010 Red Hat, Inc.
6 *
7 * Permission is hereby granted, free of charge, to any person obtaining a copy
8 * of this software and associated documentation files (the "Software"), to deal
9 * in the Software without restriction, including without limitation the rights
10 * to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
11 * copies of the Software, and to permit persons to whom the Software is
12 * furnished to do so, subject to the following conditions:
13 *
14 * The above copyright notice and this permission notice shall be included in
15 * all copies or substantial portions of the Software.
16 *
17 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
18 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
19 * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
20 * THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
21 * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
22 * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
23 * THE SOFTWARE.
24 */
25
26 #include "qemu/osdep.h"
27 #include <sys/wait.h>
28 /*needed for MAP_POPULATE before including qemu-options.h */
29 #include <pwd.h>
30 #include <grp.h>
31 #include <libgen.h>
32
33 /* Needed early for CONFIG_BSD etc. */
34 #include "sysemu/sysemu.h"
35 #include "net/slirp.h"
36 #include "qemu-options.h"
37 #include "qemu/rcu.h"
38 #include "qemu/error-report.h"
39 #include "qemu/log.h"
40 #include "qemu/cutils.h"
41
42 #ifdef CONFIG_LINUX
43 #include <sys/prctl.h>
44 #endif
45
46 static struct passwd *user_pwd;
47 static const char *chroot_dir;
48 static int daemonize;
49 static int daemon_pipe;
50
51 void os_setup_early_signal_handling(void)
52 {
53 struct sigaction act;
54 sigfillset(&act.sa_mask);
55 act.sa_flags = 0;
56 act.sa_handler = SIG_IGN;
57 sigaction(SIGPIPE, &act, NULL);
58 }
59
60 static void termsig_handler(int signal, siginfo_t *info, void *c)
61 {
62 qemu_system_killed(info->si_signo, info->si_pid);
63 }
64
65 void os_setup_signal_handling(void)
66 {
67 struct sigaction act;
68
69 memset(&act, 0, sizeof(act));
70 act.sa_sigaction = termsig_handler;
71 act.sa_flags = SA_SIGINFO;
72 sigaction(SIGINT, &act, NULL);
73 sigaction(SIGHUP, &act, NULL);
74 sigaction(SIGTERM, &act, NULL);
75 }
76
77 /* Find a likely location for support files using the location of the binary.
78 For installed binaries this will be "$bindir/../share/qemu". When
79 running from the build tree this will be "$bindir/../pc-bios". */
80 #define SHARE_SUFFIX "/share/qemu"
81 #define BUILD_SUFFIX "/pc-bios"
82 char *os_find_datadir(void)
83 {
84 char *dir, *exec_dir;
85 char *res;
86 size_t max_len;
87
88 exec_dir = qemu_get_exec_dir();
89 if (exec_dir == NULL) {
90 return NULL;
91 }
92 dir = dirname(exec_dir);
93
94 max_len = strlen(dir) +
95 MAX(strlen(SHARE_SUFFIX), strlen(BUILD_SUFFIX)) + 1;
96 res = g_malloc0(max_len);
97 snprintf(res, max_len, "%s%s", dir, SHARE_SUFFIX);
98 if (access(res, R_OK)) {
99 snprintf(res, max_len, "%s%s", dir, BUILD_SUFFIX);
100 if (access(res, R_OK)) {
101 g_free(res);
102 res = NULL;
103 }
104 }
105
106 g_free(exec_dir);
107 return res;
108 }
109 #undef SHARE_SUFFIX
110 #undef BUILD_SUFFIX
111
112 void os_set_proc_name(const char *s)
113 {
114 #if defined(PR_SET_NAME)
115 char name[16];
116 if (!s)
117 return;
118 pstrcpy(name, sizeof(name), s);
119 /* Could rewrite argv[0] too, but that's a bit more complicated.
120 This simple way is enough for `top'. */
121 if (prctl(PR_SET_NAME, name)) {
122 perror("unable to change process name");
123 exit(1);
124 }
125 #else
126 fprintf(stderr, "Change of process name not supported by your OS\n");
127 exit(1);
128 #endif
129 }
130
131 /*
132 * Parse OS specific command line options.
133 * return 0 if option handled, -1 otherwise
134 */
135 void os_parse_cmd_args(int index, const char *optarg)
136 {
137 switch (index) {
138 #ifdef CONFIG_SLIRP
139 case QEMU_OPTION_smb:
140 error_report("The -smb option is deprecated. "
141 "Please use '-netdev user,smb=...' instead.");
142 if (net_slirp_smb(optarg) < 0)
143 exit(1);
144 break;
145 #endif
146 case QEMU_OPTION_runas:
147 user_pwd = getpwnam(optarg);
148 if (!user_pwd) {
149 fprintf(stderr, "User \"%s\" doesn't exist\n", optarg);
150 exit(1);
151 }
152 break;
153 case QEMU_OPTION_chroot:
154 chroot_dir = optarg;
155 break;
156 case QEMU_OPTION_daemonize:
157 daemonize = 1;
158 break;
159 #if defined(CONFIG_LINUX)
160 case QEMU_OPTION_enablefips:
161 fips_set_state(true);
162 break;
163 #endif
164 }
165 }
166
167 static void change_process_uid(void)
168 {
169 if (user_pwd) {
170 if (setgid(user_pwd->pw_gid) < 0) {
171 fprintf(stderr, "Failed to setgid(%d)\n", user_pwd->pw_gid);
172 exit(1);
173 }
174 if (initgroups(user_pwd->pw_name, user_pwd->pw_gid) < 0) {
175 fprintf(stderr, "Failed to initgroups(\"%s\", %d)\n",
176 user_pwd->pw_name, user_pwd->pw_gid);
177 exit(1);
178 }
179 if (setuid(user_pwd->pw_uid) < 0) {
180 fprintf(stderr, "Failed to setuid(%d)\n", user_pwd->pw_uid);
181 exit(1);
182 }
183 if (setuid(0) != -1) {
184 fprintf(stderr, "Dropping privileges failed\n");
185 exit(1);
186 }
187 }
188 }
189
190 static void change_root(void)
191 {
192 if (chroot_dir) {
193 if (chroot(chroot_dir) < 0) {
194 fprintf(stderr, "chroot failed\n");
195 exit(1);
196 }
197 if (chdir("/")) {
198 perror("not able to chdir to /");
199 exit(1);
200 }
201 }
202
203 }
204
205 void os_daemonize(void)
206 {
207 if (daemonize) {
208 pid_t pid;
209 int fds[2];
210
211 if (pipe(fds) == -1) {
212 exit(1);
213 }
214
215 pid = fork();
216 if (pid > 0) {
217 uint8_t status;
218 ssize_t len;
219
220 close(fds[1]);
221
222 do {
223 len = read(fds[0], &status, 1);
224 } while (len < 0 && errno == EINTR);
225
226 /* only exit successfully if our child actually wrote
227 * a one-byte zero to our pipe, upon successful init */
228 exit(len == 1 && status == 0 ? 0 : 1);
229
230 } else if (pid < 0) {
231 exit(1);
232 }
233
234 close(fds[0]);
235 daemon_pipe = fds[1];
236 qemu_set_cloexec(daemon_pipe);
237
238 setsid();
239
240 pid = fork();
241 if (pid > 0) {
242 exit(0);
243 } else if (pid < 0) {
244 exit(1);
245 }
246 umask(027);
247
248 signal(SIGTSTP, SIG_IGN);
249 signal(SIGTTOU, SIG_IGN);
250 signal(SIGTTIN, SIG_IGN);
251 rcu_after_fork();
252 }
253 }
254
255 void os_setup_post(void)
256 {
257 int fd = 0;
258
259 if (daemonize) {
260 if (chdir("/")) {
261 perror("not able to chdir to /");
262 exit(1);
263 }
264 TFR(fd = qemu_open("/dev/null", O_RDWR));
265 if (fd == -1) {
266 exit(1);
267 }
268 }
269
270 change_root();
271 change_process_uid();
272
273 if (daemonize) {
274 uint8_t status = 0;
275 ssize_t len;
276
277 dup2(fd, 0);
278 dup2(fd, 1);
279 /* In case -D is given do not redirect stderr to /dev/null */
280 if (!qemu_logfile) {
281 dup2(fd, 2);
282 }
283
284 close(fd);
285
286 do {
287 len = write(daemon_pipe, &status, 1);
288 } while (len < 0 && errno == EINTR);
289 if (len != 1) {
290 exit(1);
291 }
292 }
293 }
294
295 void os_set_line_buffering(void)
296 {
297 setvbuf(stdout, NULL, _IOLBF, 0);
298 }
299
300 int qemu_create_pidfile(const char *filename)
301 {
302 char buffer[128];
303 int len;
304 int fd;
305
306 fd = qemu_open(filename, O_RDWR | O_CREAT, 0600);
307 if (fd == -1) {
308 return -1;
309 }
310 if (lockf(fd, F_TLOCK, 0) == -1) {
311 close(fd);
312 return -1;
313 }
314 len = snprintf(buffer, sizeof(buffer), FMT_pid "\n", getpid());
315 if (write(fd, buffer, len) != len) {
316 close(fd);
317 return -1;
318 }
319
320 /* keep pidfile open & locked forever */
321 return 0;
322 }
323
324 bool is_daemonized(void)
325 {
326 return daemonize;
327 }
328
329 int os_mlock(void)
330 {
331 int ret = 0;
332
333 ret = mlockall(MCL_CURRENT | MCL_FUTURE);
334 if (ret < 0) {
335 perror("mlockall");
336 }
337
338 return ret;
339 }