From 4e7aab07d5b175345fdf3ea08868dab1e6d90126 Mon Sep 17 00:00:00 2001 From: Ophestra Date: Thu, 13 Nov 2025 01:15:19 +0900 Subject: internal/system: relocate from system These packages are highly specific to hakurei and are difficult to use safely from other pieces of code. Their exported symbols are made available until v0.4.0 where they will be removed for #24. Signed-off-by: Ophestra --- internal/system/acl/libacl-helper.c | 90 +++++++++++++++++++++++++++++++++++++ 1 file changed, 90 insertions(+) create mode 100644 internal/system/acl/libacl-helper.c (limited to 'internal/system/acl/libacl-helper.c') diff --git a/internal/system/acl/libacl-helper.c b/internal/system/acl/libacl-helper.c new file mode 100644 index 00000000..d1df8167 --- /dev/null +++ b/internal/system/acl/libacl-helper.c @@ -0,0 +1,90 @@ +#include "libacl-helper.h" +#include +#include +#include +#include + +int hakurei_acl_update_file_by_uid(const char *path_p, uid_t uid, + acl_perm_t *perms, size_t plen) { + int ret; + bool v; + int i; + acl_t acl; + acl_entry_t entry; + acl_tag_t tag_type; + void *qualifier_p; + acl_permset_t permset; + + ret = -1; /* acl_get_file */ + acl = acl_get_file(path_p, ACL_TYPE_ACCESS); + if (acl == NULL) + goto out; + + /* prune entries by uid */ + for (i = acl_get_entry(acl, ACL_FIRST_ENTRY, &entry); i == 1; + i = acl_get_entry(acl, ACL_NEXT_ENTRY, &entry)) { + ret = -2; /* acl_get_tag_type */ + if (acl_get_tag_type(entry, &tag_type) != 0) + goto out; + if (tag_type != ACL_USER) + continue; + + ret = -3; /* acl_get_qualifier */ + qualifier_p = acl_get_qualifier(entry); + if (qualifier_p == NULL) + goto out; + v = *(uid_t *)qualifier_p == uid; + acl_free(qualifier_p); + + if (!v) + continue; + + ret = -4; /* acl_delete_entry */ + if (acl_delete_entry(acl, entry) != 0) + goto out; + } + + if (plen == 0) + goto set; + + ret = -5; /* acl_create_entry */ + if (acl_create_entry(&acl, &entry) != 0) + goto out; + + ret = -6; /* acl_get_permset */ + if (acl_get_permset(entry, &permset) != 0) + goto out; + + ret = -7; /* acl_add_perm */ + for (i = 0; i < plen; i++) { + if (acl_add_perm(permset, perms[i]) != 0) + goto out; + } + + ret = -8; /* acl_set_tag_type */ + if (acl_set_tag_type(entry, ACL_USER) != 0) + goto out; + + ret = -9; /* acl_set_qualifier */ + if (acl_set_qualifier(entry, (void *)&uid) != 0) + goto out; + +set: + ret = -10; /* acl_calc_mask */ + if (acl_calc_mask(&acl) != 0) + goto out; + + ret = -11; /* acl_valid */ + if (acl_valid(acl) != 0) + goto out; + + ret = -12; /* acl_set_file */ + if (acl_set_file(path_p, ACL_TYPE_ACCESS, acl) == 0) + ret = 0; + +out: + free((void *)path_p); + if (acl != NULL) + acl_free((void *)acl); + return ret; +} -- cgit v1.3.1