enum {
SYSUPGRADE_PATH,
+ SYSUPGRADE_PREFIX,
__SYSUPGRADE_MAX
};
static const struct blobmsg_policy sysupgrade_policy[__SYSUPGRADE_MAX] = {
[SYSUPGRADE_PATH] = { .name = "path", .type = BLOBMSG_TYPE_STRING },
+ [SYSUPGRADE_PREFIX] = { .name = "prefix", .type = BLOBMSG_TYPE_STRING },
};
static void
-procd_spawn_upgraded(char *path)
+procd_exec_upgraded(const char *prefix, char *path)
{
char *wdt_fd = watchdog_fd();
- char *argv[] = { "/tmp/upgraded", NULL, NULL};
+ char *argv[] = { "/sbin/upgraded", NULL, NULL};
+
+ if (chroot(prefix)) {
+ fprintf(stderr, "Failed to chroot for upgraded exec.\n");
+ return;
+ }
argv[1] = path;
DEBUG(2, "Exec to upgraded now\n");
if (wdt_fd) {
- watchdog_no_cloexec();
+ watchdog_set_cloexec(false);
setenv("WDTFD", wdt_fd, 1);
}
execvp(argv[0], argv);
+
+ /* Cleanup on failure */
+ fprintf(stderr, "Failed to exec upgraded.\n");
+ unsetenv("WDTFD");
+ watchdog_set_cloexec(true);
+ chroot(".");
}
static int sysupgrade(struct ubus_context *ctx, struct ubus_object *obj,
return UBUS_STATUS_INVALID_ARGUMENT;
blobmsg_parse(sysupgrade_policy, __SYSUPGRADE_MAX, tb, blob_data(msg), blob_len(msg));
- if (!tb[SYSUPGRADE_PATH])
+ if (!tb[SYSUPGRADE_PATH] || !tb[SYSUPGRADE_PREFIX])
return UBUS_STATUS_INVALID_ARGUMENT;
- procd_spawn_upgraded(blobmsg_get_string(tb[SYSUPGRADE_PATH]));
- fprintf(stderr, "Yikees, something went wrong. no /sbin/upgraded ?\n");
+ procd_exec_upgraded(blobmsg_get_string(tb[SYSUPGRADE_PREFIX]),
+ blobmsg_get_string(tb[SYSUPGRADE_PATH]));
return 0;
}
PROJECT(upgraded C)
ADD_DEFINITIONS(-Os -ggdb -Wall -Werror --std=gnu99 -Wmissing-declarations)
-set(CMAKE_EXE_LINKER_FLAGS "-static -fPIC")
-set(CMAKE_FIND_LIBRARY_SUFFIXES .a)
-set(CMAKE_EXE_LINK_DYNAMIC_C_FLAGS)
-set(CMAKE_EXE_LINK_DYNAMIC_CXX_FLAGS)
-set(CMAKE_SHARED_LIBRARY_C_FLAGS)
-set(CMAKE_SHARED_LIBRARY_CXX_FLAGS)
-set(CMAKE_SHARED_LIBRARY_LINK_C_FLAGS)
-set(CMAKE_SHARED_LIBRARY_LINK_CXX_FLAGS)
ADD_EXECUTABLE(upgraded upgraded.c ../watchdog.c)
-TARGET_LINK_LIBRARIES(upgraded ubox rt -lc -lgcc_pic)
+TARGET_LINK_LIBRARIES(upgraded ubox)
INSTALL(TARGETS upgraded
RUNTIME DESTINATION sbin
)
#include <sys/reboot.h>
+#include <fcntl.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include "../watchdog.h"
+#ifndef O_PATH
+#define O_PATH 010000000
+#endif
+
static struct uloop_process upgrade_proc;
unsigned int debug = 2;
uloop_end();
}
-static void sysupgarde(char *folder)
+static void sysupgrade(char *folder)
{
char *args[] = { "/sbin/sysupgrade", "nand", NULL, NULL };
exit(-1);
}
if (upgrade_proc.pid <= 0) {
- fprintf(stderr, "Failed to start sysupgarde\n");
+ fprintf(stderr, "Failed to start sysupgrade\n");
uloop_end();
}
}
fprintf(stderr, "this tool needs to run as pid 1\n");
return -1;
}
- if (chdir("/tmp") == -1) {
- fprintf(stderr, "failed to chdir to /tmp: %s\n", strerror(errno));
+
+ int fd = open("/", O_DIRECTORY|O_PATH);
+ if (fd < 0) {
+ fprintf(stderr, "unable to open prefix directory: %s\n", strerror(errno));
return -1;
}
+
+ chroot(".");
+
+ if (fchdir(fd) == -1) {
+ fprintf(stderr, "failed to chdir to prefix directory: %s\n", strerror(errno));
+ return -1;
+ }
+ close(fd);
+
if (argc != 2) {
fprintf(stderr, "sysupgrade stage 2 failed, no folder specified\n");
return -1;
uloop_init();
watchdog_init(0);
- sysupgarde(argv[1]);
+ sysupgrade(argv[1]);
uloop_run();
reboot(RB_AUTOBOOT);
}
-void watchdog_no_cloexec(void)
+void watchdog_set_cloexec(bool val)
{
if (wdt_fd < 0)
return;
- fcntl(wdt_fd, F_SETFD, fcntl(wdt_fd, F_GETFD) & ~FD_CLOEXEC);
+ int flags = fcntl(wdt_fd, F_GETFD);
+ if (val)
+ flags |= FD_CLOEXEC;
+ else
+ flags &= ~FD_CLOEXEC;
+ fcntl(wdt_fd, F_SETFD, flags);
}
int watchdog_frequency(int frequency);
void watchdog_set_stopped(bool val);
bool watchdog_get_stopped(void);
-void watchdog_no_cloexec(void);
+void watchdog_set_cloexec(bool val);
void watchdog_ping(void);
#else
static inline void watchdog_init(int preinit)
return true;
}
-static inline void watchdog_no_cloexec(void)
+static inline void watchdog_set_cloexec(bool val)
{
}