1*d62bc4baSyz147064 /* 2*d62bc4baSyz147064 * CDDL HEADER START 3*d62bc4baSyz147064 * 4*d62bc4baSyz147064 * The contents of this file are subject to the terms of the 5*d62bc4baSyz147064 * Common Development and Distribution License (the "License"). 6*d62bc4baSyz147064 * You may not use this file except in compliance with the License. 7*d62bc4baSyz147064 * 8*d62bc4baSyz147064 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 9*d62bc4baSyz147064 * or http://www.opensolaris.org/os/licensing. 10*d62bc4baSyz147064 * See the License for the specific language governing permissions 11*d62bc4baSyz147064 * and limitations under the License. 12*d62bc4baSyz147064 * 13*d62bc4baSyz147064 * When distributing Covered Code, include this CDDL HEADER in each 14*d62bc4baSyz147064 * file and include the License file at usr/src/OPENSOLARIS.LICENSE. 15*d62bc4baSyz147064 * If applicable, add the following below this CDDL HEADER, with the 16*d62bc4baSyz147064 * fields enclosed by brackets "[]" replaced with your own identifying 17*d62bc4baSyz147064 * information: Portions Copyright [yyyy] [name of copyright owner] 18*d62bc4baSyz147064 * 19*d62bc4baSyz147064 * CDDL HEADER END 20*d62bc4baSyz147064 */ 21*d62bc4baSyz147064 22*d62bc4baSyz147064 /* 23*d62bc4baSyz147064 * Copyright 2008 Sun Microsystems, Inc. All rights reserved. 24*d62bc4baSyz147064 * Use is subject to license terms. 25*d62bc4baSyz147064 */ 26*d62bc4baSyz147064 27*d62bc4baSyz147064 #pragma ident "%Z%%M% %I% %E% SMI" 28*d62bc4baSyz147064 29*d62bc4baSyz147064 /* 30*d62bc4baSyz147064 * The dlmgmtd daemon is started by the datalink-management SMF service. 31*d62bc4baSyz147064 * This daemon is used to manage <link name, linkid> mapping and the 32*d62bc4baSyz147064 * persistent datalink configuration. 33*d62bc4baSyz147064 * 34*d62bc4baSyz147064 * Today, the <link name, linkid> mapping and the persistent configuration 35*d62bc4baSyz147064 * of datalinks is kept in /etc/dladm/datalink.conf, and the daemon keeps 36*d62bc4baSyz147064 * a copy of the datalinks in the memory (see dlmgmt_id_avl and 37*d62bc4baSyz147064 * dlmgmt_name_avl). The active <link name, linkid> mapping is kept in 38*d62bc4baSyz147064 * /etc/svc/volatile cache file, so that the mapping can be recovered when 39*d62bc4baSyz147064 * dlmgmtd exits for some reason (e.g., when dlmgmtd is accidentally killed). 40*d62bc4baSyz147064 */ 41*d62bc4baSyz147064 42*d62bc4baSyz147064 #include <assert.h> 43*d62bc4baSyz147064 #include <errno.h> 44*d62bc4baSyz147064 #include <fcntl.h> 45*d62bc4baSyz147064 #include <priv.h> 46*d62bc4baSyz147064 #include <signal.h> 47*d62bc4baSyz147064 #include <stdlib.h> 48*d62bc4baSyz147064 #include <stdio.h> 49*d62bc4baSyz147064 #include <stropts.h> 50*d62bc4baSyz147064 #include <strings.h> 51*d62bc4baSyz147064 #include <syslog.h> 52*d62bc4baSyz147064 #include <sys/dld.h> 53*d62bc4baSyz147064 #include <unistd.h> 54*d62bc4baSyz147064 #include <libdlmgmt.h> 55*d62bc4baSyz147064 #include "dlmgmt_impl.h" 56*d62bc4baSyz147064 57*d62bc4baSyz147064 const char *progname; 58*d62bc4baSyz147064 boolean_t debug; 59*d62bc4baSyz147064 static int pfds[2]; 60*d62bc4baSyz147064 static char dlmgmt_door_file[] = DLMGMT_DOOR; 61*d62bc4baSyz147064 static int dlmgmt_door_fd = -1; 62*d62bc4baSyz147064 63*d62bc4baSyz147064 static int 64*d62bc4baSyz147064 dlmgmt_set_doorfd(boolean_t start) 65*d62bc4baSyz147064 { 66*d62bc4baSyz147064 dld_ioc_door_t did; 67*d62bc4baSyz147064 struct strioctl iocb; 68*d62bc4baSyz147064 int fd; 69*d62bc4baSyz147064 int err = 0; 70*d62bc4baSyz147064 71*d62bc4baSyz147064 if ((fd = open(DLD_CONTROL_DEV, O_RDWR)) < 0) 72*d62bc4baSyz147064 return (EINVAL); 73*d62bc4baSyz147064 74*d62bc4baSyz147064 did.did_start_door = start; 75*d62bc4baSyz147064 76*d62bc4baSyz147064 iocb.ic_cmd = DLDIOC_DOORSERVER; 77*d62bc4baSyz147064 iocb.ic_timout = 0; 78*d62bc4baSyz147064 iocb.ic_len = sizeof (did); 79*d62bc4baSyz147064 iocb.ic_dp = (char *)&did; 80*d62bc4baSyz147064 81*d62bc4baSyz147064 if (ioctl(fd, I_STR, &iocb) == -1) 82*d62bc4baSyz147064 err = errno; 83*d62bc4baSyz147064 84*d62bc4baSyz147064 (void) close(fd); 85*d62bc4baSyz147064 return (err); 86*d62bc4baSyz147064 } 87*d62bc4baSyz147064 88*d62bc4baSyz147064 static int 89*d62bc4baSyz147064 dlmgmt_door_init() 90*d62bc4baSyz147064 { 91*d62bc4baSyz147064 int err; 92*d62bc4baSyz147064 93*d62bc4baSyz147064 if ((dlmgmt_door_fd = door_create(dlmgmt_handler, NULL, 94*d62bc4baSyz147064 DOOR_REFUSE_DESC | DOOR_NO_CANCEL)) == -1) { 95*d62bc4baSyz147064 err = errno; 96*d62bc4baSyz147064 dlmgmt_log(LOG_WARNING, "door_create() failed: %s", 97*d62bc4baSyz147064 strerror(err)); 98*d62bc4baSyz147064 return (err); 99*d62bc4baSyz147064 } 100*d62bc4baSyz147064 if (fattach(dlmgmt_door_fd, DLMGMT_DOOR) != 0) { 101*d62bc4baSyz147064 err = errno; 102*d62bc4baSyz147064 dlmgmt_log(LOG_WARNING, "fattach(%s) failed: %s", 103*d62bc4baSyz147064 DLMGMT_DOOR, strerror(err)); 104*d62bc4baSyz147064 goto fail; 105*d62bc4baSyz147064 } 106*d62bc4baSyz147064 if ((err = dlmgmt_set_doorfd(B_TRUE)) != 0) { 107*d62bc4baSyz147064 dlmgmt_log(LOG_WARNING, "cannot set kernel doorfd: %s", 108*d62bc4baSyz147064 strerror(err)); 109*d62bc4baSyz147064 goto fail; 110*d62bc4baSyz147064 } 111*d62bc4baSyz147064 112*d62bc4baSyz147064 return (0); 113*d62bc4baSyz147064 fail: 114*d62bc4baSyz147064 if (dlmgmt_door_fd != -1) { 115*d62bc4baSyz147064 (void) door_revoke(dlmgmt_door_fd); 116*d62bc4baSyz147064 dlmgmt_door_fd = -1; 117*d62bc4baSyz147064 } 118*d62bc4baSyz147064 (void) fdetach(DLMGMT_DOOR); 119*d62bc4baSyz147064 return (err); 120*d62bc4baSyz147064 } 121*d62bc4baSyz147064 122*d62bc4baSyz147064 static void 123*d62bc4baSyz147064 dlmgmt_door_fini() 124*d62bc4baSyz147064 { 125*d62bc4baSyz147064 (void) dlmgmt_set_doorfd(B_FALSE); 126*d62bc4baSyz147064 if ((dlmgmt_door_fd != -1) && (door_revoke(dlmgmt_door_fd) == -1)) { 127*d62bc4baSyz147064 dlmgmt_log(LOG_WARNING, "door_revoke(%s) failed: %s", 128*d62bc4baSyz147064 dlmgmt_door_file, strerror(errno)); 129*d62bc4baSyz147064 } 130*d62bc4baSyz147064 (void) fdetach(DLMGMT_DOOR); 131*d62bc4baSyz147064 } 132*d62bc4baSyz147064 133*d62bc4baSyz147064 static int 134*d62bc4baSyz147064 dlmgmt_init() 135*d62bc4baSyz147064 { 136*d62bc4baSyz147064 int err; 137*d62bc4baSyz147064 138*d62bc4baSyz147064 if ((err = dlmgmt_linktable_init()) != 0) 139*d62bc4baSyz147064 return (err); 140*d62bc4baSyz147064 141*d62bc4baSyz147064 if ((err = dlmgmt_db_init()) != 0 || (err = dlmgmt_door_init()) != 0) 142*d62bc4baSyz147064 dlmgmt_linktable_fini(); 143*d62bc4baSyz147064 144*d62bc4baSyz147064 return (err); 145*d62bc4baSyz147064 } 146*d62bc4baSyz147064 147*d62bc4baSyz147064 static void 148*d62bc4baSyz147064 dlmgmt_fini() 149*d62bc4baSyz147064 { 150*d62bc4baSyz147064 dlmgmt_door_fini(); 151*d62bc4baSyz147064 dlmgmt_linktable_fini(); 152*d62bc4baSyz147064 } 153*d62bc4baSyz147064 154*d62bc4baSyz147064 /* 155*d62bc4baSyz147064 * This is called by the child process to inform the parent process to 156*d62bc4baSyz147064 * exit with the given return value. 157*d62bc4baSyz147064 */ 158*d62bc4baSyz147064 static void 159*d62bc4baSyz147064 dlmgmt_inform_parent_exit(int rv) 160*d62bc4baSyz147064 { 161*d62bc4baSyz147064 if (debug) 162*d62bc4baSyz147064 return; 163*d62bc4baSyz147064 164*d62bc4baSyz147064 if (write(pfds[1], &rv, sizeof (int)) != sizeof (int)) { 165*d62bc4baSyz147064 dlmgmt_log(LOG_WARNING, 166*d62bc4baSyz147064 "dlmgmt_inform_parent_exit() failed: %s", strerror(errno)); 167*d62bc4baSyz147064 (void) close(pfds[1]); 168*d62bc4baSyz147064 exit(EXIT_FAILURE); 169*d62bc4baSyz147064 } 170*d62bc4baSyz147064 (void) close(pfds[1]); 171*d62bc4baSyz147064 } 172*d62bc4baSyz147064 173*d62bc4baSyz147064 /*ARGSUSED*/ 174*d62bc4baSyz147064 static void 175*d62bc4baSyz147064 dlmgmtd_exit(int signo) 176*d62bc4baSyz147064 { 177*d62bc4baSyz147064 (void) close(pfds[1]); 178*d62bc4baSyz147064 dlmgmt_fini(); 179*d62bc4baSyz147064 exit(EXIT_FAILURE); 180*d62bc4baSyz147064 } 181*d62bc4baSyz147064 182*d62bc4baSyz147064 static void 183*d62bc4baSyz147064 usage(void) 184*d62bc4baSyz147064 { 185*d62bc4baSyz147064 (void) fprintf(stderr, "Usage: %s [-d]\n", progname); 186*d62bc4baSyz147064 exit(EXIT_FAILURE); 187*d62bc4baSyz147064 } 188*d62bc4baSyz147064 189*d62bc4baSyz147064 static int 190*d62bc4baSyz147064 dlmgmt_setup_privs() 191*d62bc4baSyz147064 { 192*d62bc4baSyz147064 priv_set_t *priv_set = NULL; 193*d62bc4baSyz147064 char *p; 194*d62bc4baSyz147064 195*d62bc4baSyz147064 priv_set = priv_allocset(); 196*d62bc4baSyz147064 if (priv_set == NULL || getppriv(PRIV_PERMITTED, priv_set) == -1) { 197*d62bc4baSyz147064 dlmgmt_log(LOG_WARNING, "failed to get the permitted set of " 198*d62bc4baSyz147064 "privileges %s", strerror(errno)); 199*d62bc4baSyz147064 return (-1); 200*d62bc4baSyz147064 } 201*d62bc4baSyz147064 202*d62bc4baSyz147064 p = priv_set_to_str(priv_set, ',', 0); 203*d62bc4baSyz147064 dlmgmt_log(LOG_DEBUG, "start with privs %s", p != NULL ? p : "Unknown"); 204*d62bc4baSyz147064 free(p); 205*d62bc4baSyz147064 206*d62bc4baSyz147064 priv_emptyset(priv_set); 207*d62bc4baSyz147064 (void) priv_addset(priv_set, "file_dac_write"); 208*d62bc4baSyz147064 (void) priv_addset(priv_set, "file_chown_self"); 209*d62bc4baSyz147064 (void) priv_addset(priv_set, "sys_mount"); 210*d62bc4baSyz147064 (void) priv_addset(priv_set, "sys_net_config"); 211*d62bc4baSyz147064 212*d62bc4baSyz147064 if (setppriv(PRIV_SET, PRIV_INHERITABLE, priv_set) == -1) { 213*d62bc4baSyz147064 dlmgmt_log(LOG_WARNING, "failed to set the inheritable set of " 214*d62bc4baSyz147064 "privileges %s", strerror(errno)); 215*d62bc4baSyz147064 priv_freeset(priv_set); 216*d62bc4baSyz147064 return (-1); 217*d62bc4baSyz147064 } 218*d62bc4baSyz147064 219*d62bc4baSyz147064 if (setppriv(PRIV_SET, PRIV_PERMITTED, priv_set) == -1) { 220*d62bc4baSyz147064 dlmgmt_log(LOG_WARNING, "failed to set the permitted set of " 221*d62bc4baSyz147064 "privileges %s", strerror(errno)); 222*d62bc4baSyz147064 priv_freeset(priv_set); 223*d62bc4baSyz147064 return (-1); 224*d62bc4baSyz147064 } 225*d62bc4baSyz147064 226*d62bc4baSyz147064 if (setppriv(PRIV_SET, PRIV_EFFECTIVE, priv_set) == -1) { 227*d62bc4baSyz147064 dlmgmt_log(LOG_WARNING, "failed to set the effective set of " 228*d62bc4baSyz147064 "privileges %s", strerror(errno)); 229*d62bc4baSyz147064 priv_freeset(priv_set); 230*d62bc4baSyz147064 return (-1); 231*d62bc4baSyz147064 } 232*d62bc4baSyz147064 233*d62bc4baSyz147064 priv_freeset(priv_set); 234*d62bc4baSyz147064 return (0); 235*d62bc4baSyz147064 } 236*d62bc4baSyz147064 237*d62bc4baSyz147064 /* 238*d62bc4baSyz147064 * Keep the pfds fd open, close other fds. 239*d62bc4baSyz147064 */ 240*d62bc4baSyz147064 /*ARGSUSED*/ 241*d62bc4baSyz147064 static int 242*d62bc4baSyz147064 closefunc(void *arg, int fd) 243*d62bc4baSyz147064 { 244*d62bc4baSyz147064 if (fd != pfds[1]) 245*d62bc4baSyz147064 (void) close(fd); 246*d62bc4baSyz147064 return (0); 247*d62bc4baSyz147064 } 248*d62bc4baSyz147064 249*d62bc4baSyz147064 static boolean_t 250*d62bc4baSyz147064 dlmgmt_daemonize(void) 251*d62bc4baSyz147064 { 252*d62bc4baSyz147064 pid_t pid; 253*d62bc4baSyz147064 int rv; 254*d62bc4baSyz147064 255*d62bc4baSyz147064 if (pipe(pfds) < 0) { 256*d62bc4baSyz147064 (void) fprintf(stderr, "%s: pipe() failed: %s\n", 257*d62bc4baSyz147064 progname, strerror(errno)); 258*d62bc4baSyz147064 exit(EXIT_FAILURE); 259*d62bc4baSyz147064 } 260*d62bc4baSyz147064 261*d62bc4baSyz147064 if ((pid = fork()) == -1) { 262*d62bc4baSyz147064 (void) fprintf(stderr, "%s: fork() failed: %s\n", 263*d62bc4baSyz147064 progname, strerror(errno)); 264*d62bc4baSyz147064 exit(EXIT_FAILURE); 265*d62bc4baSyz147064 } else if (pid > 0) { /* Parent */ 266*d62bc4baSyz147064 (void) close(pfds[1]); 267*d62bc4baSyz147064 268*d62bc4baSyz147064 /* 269*d62bc4baSyz147064 * Read the child process's return value from the pfds. 270*d62bc4baSyz147064 * If the child process exits unexpected, read() returns -1. 271*d62bc4baSyz147064 */ 272*d62bc4baSyz147064 if (read(pfds[0], &rv, sizeof (int)) != sizeof (int)) { 273*d62bc4baSyz147064 (void) kill(pid, SIGKILL); 274*d62bc4baSyz147064 rv = EXIT_FAILURE; 275*d62bc4baSyz147064 } 276*d62bc4baSyz147064 277*d62bc4baSyz147064 (void) close(pfds[0]); 278*d62bc4baSyz147064 exit(rv); 279*d62bc4baSyz147064 } 280*d62bc4baSyz147064 281*d62bc4baSyz147064 /* Child */ 282*d62bc4baSyz147064 (void) close(pfds[0]); 283*d62bc4baSyz147064 (void) setsid(); 284*d62bc4baSyz147064 285*d62bc4baSyz147064 /* 286*d62bc4baSyz147064 * Close all files except pfds[1]. 287*d62bc4baSyz147064 */ 288*d62bc4baSyz147064 (void) fdwalk(closefunc, NULL); 289*d62bc4baSyz147064 (void) chdir("/"); 290*d62bc4baSyz147064 openlog(progname, LOG_PID, LOG_DAEMON); 291*d62bc4baSyz147064 return (B_TRUE); 292*d62bc4baSyz147064 } 293*d62bc4baSyz147064 294*d62bc4baSyz147064 int 295*d62bc4baSyz147064 main(int argc, char *argv[]) 296*d62bc4baSyz147064 { 297*d62bc4baSyz147064 int opt; 298*d62bc4baSyz147064 299*d62bc4baSyz147064 progname = strrchr(argv[0], '/'); 300*d62bc4baSyz147064 if (progname != NULL) 301*d62bc4baSyz147064 progname++; 302*d62bc4baSyz147064 else 303*d62bc4baSyz147064 progname = argv[0]; 304*d62bc4baSyz147064 305*d62bc4baSyz147064 /* 306*d62bc4baSyz147064 * Process options. 307*d62bc4baSyz147064 */ 308*d62bc4baSyz147064 while ((opt = getopt(argc, argv, "d")) != EOF) { 309*d62bc4baSyz147064 switch (opt) { 310*d62bc4baSyz147064 case 'd': 311*d62bc4baSyz147064 debug = B_TRUE; 312*d62bc4baSyz147064 break; 313*d62bc4baSyz147064 default: 314*d62bc4baSyz147064 usage(); 315*d62bc4baSyz147064 } 316*d62bc4baSyz147064 } 317*d62bc4baSyz147064 318*d62bc4baSyz147064 if (!debug && !dlmgmt_daemonize()) 319*d62bc4baSyz147064 return (EXIT_FAILURE); 320*d62bc4baSyz147064 321*d62bc4baSyz147064 if (signal(SIGTERM, dlmgmtd_exit) == SIG_ERR) { 322*d62bc4baSyz147064 dlmgmt_log(LOG_WARNING, "signal() for SIGTERM failed: %s", 323*d62bc4baSyz147064 strerror(errno)); 324*d62bc4baSyz147064 goto child_out; 325*d62bc4baSyz147064 } 326*d62bc4baSyz147064 327*d62bc4baSyz147064 if (dlmgmt_init() != 0) 328*d62bc4baSyz147064 goto child_out; 329*d62bc4baSyz147064 330*d62bc4baSyz147064 if (dlmgmt_setup_privs() != 0) 331*d62bc4baSyz147064 goto child_out; 332*d62bc4baSyz147064 333*d62bc4baSyz147064 /* 334*d62bc4baSyz147064 * Inform the parent process that it can successfully exit. 335*d62bc4baSyz147064 */ 336*d62bc4baSyz147064 dlmgmt_inform_parent_exit(EXIT_SUCCESS); 337*d62bc4baSyz147064 338*d62bc4baSyz147064 for (;;) 339*d62bc4baSyz147064 (void) pause(); 340*d62bc4baSyz147064 341*d62bc4baSyz147064 child_out: 342*d62bc4baSyz147064 /* return from main() forcibly exits an MT process */ 343*d62bc4baSyz147064 dlmgmt_inform_parent_exit(EXIT_FAILURE); 344*d62bc4baSyz147064 return (EXIT_FAILURE); 345*d62bc4baSyz147064 } 346