audit.c 8.99 KB
Newer Older
1 2 3
/* audit.c - Alpine Package Keeper (APK)
 *
 * Copyright (C) 2005-2008 Natanael Copa <n@tanael.org>
4
 * Copyright (C) 2008-2011 Timo Teräs <timo.teras@iki.fi>
5 6
 * All rights reserved.
 *
Timo Teräs's avatar
Timo Teräs committed
7
 * This program is free software; you can redistribute it and/or modify it
8 9 10 11 12 13
 * under the terms of the GNU General Public License version 2 as published
 * by the Free Software Foundation. See http://www.gnu.org/ for details.
 */

#include <errno.h>
#include <stdio.h>
14
#include <fcntl.h>
15 16
#include <unistd.h>
#include <dirent.h>
17
#include <fnmatch.h>
18
#include <limits.h>
19 20 21
#include <sys/stat.h>
#include "apk_applet.h"
#include "apk_database.h"
22 23
#include "apk_print.h"

24 25 26 27
/* Use (unused) highest bit of mode_t as seen flag of our internal
 * database file entries */
#define S_SEENFLAG	0x80000000

28 29 30 31
enum {
	MODE_BACKUP = 0,
	MODE_SYSTEM
};
32 33

struct audit_ctx {
34 35 36 37 38 39
	unsigned mode : 1;
	unsigned recursive : 1;
	unsigned check_permissions : 1;
	unsigned packages_only : 1;
};

40
static int option_parse_applet(void *ctx, struct apk_db_options *dbopts, int optch, const char *optarg)
41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60
{
	struct audit_ctx *actx = (struct audit_ctx *) ctx;

	switch (optch) {
	case 0x10000:
		actx->mode = MODE_BACKUP;
		break;
	case 0x10001:
		actx->mode = MODE_SYSTEM;
		break;
	case 0x10002:
		actx->check_permissions = 1;
		break;
	case 0x10003:
		actx->packages_only = 1;
		break;
	case 'r':
		actx->recursive = 1;
		break;
	default:
61
		return -ENOTSUP;
62 63 64 65
	}
	return 0;
}

66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81
static const struct apk_option options_applet[] = {
	{ 0x10000, "backup", "List all modified configuration files (in "
			     "protected_paths.d) that need to be backed up" },
	{ 0x10001, "system", "Verify checksums of all installed non-configuration files " },
	{ 0x10002, "check-permissions", "Check file and directory uid/gid/mode too" },
	{ 'r', "recursive",  "List individually all entries in new directories" },
	{ 0x10003, "packages", "List only the changed packages (or names only with -q)" },
};

static const struct apk_option_group optgroup_applet = {
	.name = "Audit",
	.options = options_applet,
	.num_options = ARRAY_SIZE(options_applet),
	.parse = option_parse_applet,
};

82 83 84
struct audit_tree_ctx {
	struct audit_ctx *actx;
	struct apk_database *db;
85
	struct apk_db_dir *dir;
86 87
	size_t pathlen;
	char path[PATH_MAX];
88 89
};

90 91 92
static int audit_file(struct audit_ctx *actx,
		      struct apk_database *db,
		      struct apk_db_file *dbf,
93
		      int dirfd, const char *name)
Timo Teräs's avatar
Timo Teräs committed
94 95
{
	struct apk_file_info fi;
Timo Teräs's avatar
Timo Teräs committed
96
	int rv = 0;
Timo Teräs's avatar
Timo Teräs committed
97

98 99 100
	if (dbf == NULL)
		return 'A';

101
	dbf->audited = 1;
102

Timo Teräs's avatar
Timo Teräs committed
103 104 105 106 107
	if (apk_fileinfo_get(dirfd, name,
				APK_FI_NOFOLLOW |
				APK_FI_XATTR_CSUM(dbf->acl->xattr_csum.type ?: APK_CHECKSUM_DEFAULT) |
				APK_FI_CSUM(dbf->csum.type),
				&fi) != 0)
108
		return -EPERM;
Timo Teräs's avatar
Timo Teräs committed
109 110

	if (dbf->csum.type != APK_CHECKSUM_NONE &&
111
	    apk_checksum_compare(&fi.csum, &dbf->csum) != 0)
Timo Teräs's avatar
Timo Teräs committed
112
		rv = 'U';
113
	else if (!S_ISLNK(fi.mode) && !dbf->diri->pkg->ipkg->broken_xattr &&
114
	         apk_checksum_compare(&fi.xattr_csum, &dbf->acl->xattr_csum) != 0)
115
		rv = 'x';
Timo Teräs's avatar
Timo Teräs committed
116 117 118
	else if (S_ISLNK(fi.mode) && dbf->csum.type == APK_CHECKSUM_NONE)
		rv = 'U';
	else if (actx->check_permissions) {
119
		if ((fi.mode & 07777) != (dbf->acl->mode & 07777))
Timo Teräs's avatar
Timo Teräs committed
120 121 122
			rv = 'M';
		else if (fi.uid != dbf->acl->uid || fi.gid != dbf->acl->gid)
			rv = 'M';
123
	}
Timo Teräs's avatar
Timo Teräs committed
124
	apk_fileinfo_free(&fi);
Timo Teräs's avatar
Timo Teräs committed
125

Timo Teräs's avatar
Timo Teräs committed
126
	return rv;
127 128 129 130 131 132 133
}

static int audit_directory(struct audit_ctx *actx,
			   struct apk_database *db,
			   struct apk_db_dir *dbd,
			   struct apk_file_info *fi)
{
134 135
	if (dbd != NULL) dbd->mode |= S_SEENFLAG;

136 137
	if (dbd == NULL || dbd->refs == 1)
		return actx->recursive ? 'd' : 'D';
138 139

	if (actx->check_permissions &&
140
	    ((dbd->mode & ~S_SEENFLAG) || dbd->uid || dbd->gid)) {
141 142 143 144 145
		if ((fi->mode & 07777) != (dbd->mode & 07777))
			return 'm';
		if (fi->uid != dbd->uid || fi->gid != dbd->gid)
			return 'm';
	}
146

147
	return 0;
Timo Teräs's avatar
Timo Teräs committed
148 149
}

150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168
static void report_audit(struct audit_ctx *actx,
			 char reason, apk_blob_t bfull, struct apk_package *pkg)
{
	if (!reason)
		return;

	if (actx->packages_only) {
		if (pkg == NULL || pkg->state_int != 0)
			return;
		pkg->state_int = 1;
		if (apk_verbosity < 1)
			printf("%s\n", pkg->name->name);
		else
			printf(PKG_VER_FMT "\n", PKG_VER_PRINTF(pkg));
	} else if (apk_verbosity < 1) {
		printf(BLOB_FMT "\n", BLOB_PRINTF(bfull));
	} else
		printf("%c " BLOB_FMT "\n", reason, BLOB_PRINTF(bfull));
}
169

170
static int audit_directory_tree_item(void *ctx, int dirfd, const char *name)
171
{
172
	struct audit_tree_ctx *atctx = (struct audit_tree_ctx *) ctx;
173 174 175
	apk_blob_t bdir = APK_BLOB_PTR_LEN(atctx->path, atctx->pathlen);
	apk_blob_t bent = APK_BLOB_STR(name);
	apk_blob_t bfull;
176 177
	struct audit_ctx *actx = atctx->actx;
	struct apk_database *db = atctx->db;
178
	struct apk_db_dir *dir = atctx->dir, *child = NULL;
179
	struct apk_file_info fi;
180
	int reason = 0;
Timo Teräs's avatar
Timo Teräs committed
181

182 183
	if (bdir.len + bent.len + 1 >= sizeof(atctx->path)) return 0;
	if (apk_fileinfo_get(dirfd, name, APK_FI_NOFOLLOW, &fi) < 0) return 0;
184

185 186 187
	memcpy(&atctx->path[atctx->pathlen], bent.ptr, bent.len);
	atctx->pathlen += bent.len;
	bfull = APK_BLOB_PTR_LEN(atctx->path, atctx->pathlen);
188

189 190
	if (S_ISDIR(fi.mode)) {
		int recurse = TRUE;
191

192 193 194 195
		if (actx->mode == MODE_BACKUP) {
			child = apk_db_dir_get(db, bfull);
			if (!child->has_protected_children)
				recurse = FALSE;
196
			if (child->protect_mode == APK_PROTECT_NONE)
197
				goto recurse_check;
198
		} else {
199 200
			child = apk_db_dir_query(db, bfull);
			if (child == NULL)
201 202
				goto done;
			child = apk_db_dir_ref(child);
203
		}
Timo Teräs's avatar
Timo Teräs committed
204

205 206 207
		reason = audit_directory(actx, db, child, &fi);
		if (reason < 0)
			goto done;
Timo Teräs's avatar
Timo Teräs committed
208

209 210 211 212
recurse_check:
		atctx->path[atctx->pathlen++] = '/';
		bfull.len++;
		report_audit(actx, reason, bfull, NULL);
213
		if (reason != 'D' && recurse) {
214
			atctx->dir = child;
215 216 217
			reason = apk_dir_foreach_file(
				openat(dirfd, name, O_RDONLY|O_CLOEXEC),
				audit_directory_tree_item, atctx);
218
			atctx->dir = dir;
219 220 221 222 223
		}
		bfull.len--;
		atctx->pathlen--;
	} else {
		struct apk_db_file *dbf;
224
		struct apk_protected_path *ppath;
225
		int protect_mode = dir->protect_mode;
226 227

		/* inherit file's protection mask */
228
		foreach_array_item(ppath, dir->protected_paths) {
229 230 231 232
			char *slash = strchr(ppath->relative_pattern, '/');
			if (slash == NULL) {
				if (fnmatch(ppath->relative_pattern, name, FNM_PATHNAME) != 0)
					continue;
233
				protect_mode = ppath->protect_mode;
234 235
			}
		}
236 237

		if (actx->mode == MODE_BACKUP) {
238 239
			switch (protect_mode) {
			case APK_PROTECT_NONE:
240
				goto done;
241 242 243 244 245 246 247 248 249 250
			case APK_PROTECT_CHANGED:
				break;
			case APK_PROTECT_SYMLINKS_ONLY:
				if (!S_ISLNK(fi.mode))
					goto done;
				break;
			case APK_PROTECT_ALL:
				reason = 'A';
				break;
			}
251
		}
Timo Teräs's avatar
Timo Teräs committed
252

253
		dbf = apk_db_file_query(db, bdir, bent);
254 255
		if (reason == 0)
			reason = audit_file(actx, db, dbf, dirfd, name);
256 257
		if (reason < 0)
			goto done;
258 259
		if (actx->mode == MODE_SYSTEM &&
		    (reason == 'A' || protect_mode != APK_PROTECT_NONE))
260
			goto done;
261 262 263 264
		if (actx->mode == MODE_BACKUP &&
		    reason == 'A' &&
		    apk_blob_ends_with(bent, APK_BLOB_STR(".apk-new")))
			goto done;
265 266 267 268
		report_audit(actx, reason, bfull, dbf ? dbf->diri->pkg : NULL);
	}

done:
269 270 271
	if (child)
		apk_db_dir_unref(db, child, FALSE);

272
	atctx->pathlen -= bent.len;
273
	return 0;
Timo Teräs's avatar
Timo Teräs committed
274 275
}

276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300
static int audit_directory_tree(struct audit_tree_ctx *atctx, int dirfd)
{
	apk_blob_t path;
	int r;

	path = APK_BLOB_PTR_LEN(atctx->path, atctx->pathlen);
	if (path.len && path.ptr[path.len-1] == '/')
		path.len--;

	atctx->dir = apk_db_dir_get(atctx->db, path);
	atctx->dir->mode |= S_SEENFLAG;
	r = apk_dir_foreach_file(dirfd, audit_directory_tree_item, atctx);
	apk_db_dir_unref(atctx->db, atctx->dir, FALSE);

	return r;
}

static int audit_missing_files(apk_hash_item item, void *pctx)
{
	struct audit_ctx *actx = pctx;
	struct apk_db_file *file = item;
	struct apk_db_dir *dir;
	char path[PATH_MAX];
	int len;

301
	if (file->audited) return 0;
302 303 304 305 306 307 308 309 310 311

	dir = file->diri->dir;
	if (dir->mode & S_SEENFLAG) {
		len = snprintf(path, sizeof(path), DIR_FILE_FMT, DIR_FILE_PRINTF(dir, file));
		report_audit(actx, 'X', APK_BLOB_PTR_LEN(path, len), file->diri->pkg);
	}

	return 0;
}

312
static int audit_main(void *ctx, struct apk_database *db, struct apk_string_array *args)
Timo Teräs's avatar
Timo Teräs committed
313
{
314
	struct audit_tree_ctx atctx;
315
	struct audit_ctx *actx = (struct audit_ctx *) ctx;
316 317
	char **parg, *arg;
	int r = 0;
318 319

	atctx.db = db;
320
	atctx.actx = actx;
321 322 323
	atctx.pathlen = 0;
	atctx.path[0] = 0;

324
	if (args->num == 0) {
325 326 327 328 329 330 331 332 333 334 335 336 337
		r |= audit_directory_tree(&atctx, dup(db->root_fd));
	} else {
		foreach_array_item(parg, args) {
			arg = *parg;
			if (arg[0] != '/') {
				apk_warning("%s: relative path skipped.\n", arg);
				continue;
			}
			arg++;
			atctx.pathlen = strlen(arg);
			memcpy(atctx.path, arg, atctx.pathlen);
			if (atctx.path[atctx.pathlen-1] != '/')
				atctx.path[atctx.pathlen++] = '/';
338

339
			r |= audit_directory_tree(&atctx, openat(db->root_fd, arg, O_RDONLY|O_CLOEXEC));
Timo Teräs's avatar
Timo Teräs committed
340 341
		}
	}
342 343 344
	if (actx->mode == MODE_SYSTEM)
		apk_hash_foreach(&db->installed.files, audit_missing_files, ctx);

345
	return r;
346 347 348 349
}

static struct apk_applet apk_audit = {
	.name = "audit",
350
	.help = "Audit the directories for changes",
351
	.arguments = "[directory to audit]...",
352
	.open_flags = APK_OPENF_READ|APK_OPENF_NO_SCRIPTS|APK_OPENF_NO_REPOS,
353
	.context_size = sizeof(struct audit_ctx),
354
	.optgroups = { &optgroup_global, &optgroup_applet },
355 356 357 358 359
	.main = audit_main,
};

APK_DEFINE_APPLET(apk_audit);