uci: reject invalid section and option names
[project/rpcd.git] / uci.c
1 /*
2 * rpcd - UBUS RPC server
3 *
4 * Copyright (C) 2013-2014 Jo-Philipp Wich <jow@openwrt.org>
5 *
6 * Permission to use, copy, modify, and/or distribute this software for any
7 * purpose with or without fee is hereby granted, provided that the above
8 * copyright notice and this permission notice appear in all copies.
9 *
10 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
11 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
12 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
13 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
14 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
15 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
16 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17 */
18
19 #include <libgen.h>
20 #include <glob.h>
21
22 #include <libubox/blobmsg.h>
23 #include <libubox/blobmsg_json.h>
24
25 #include <rpcd/uci.h>
26 #include <rpcd/exec.h>
27 #include <rpcd/session.h>
28
29 static struct blob_buf buf;
30 static struct uci_context *cursor;
31 static struct uloop_timeout apply_timer;
32 static struct ubus_context *apply_ctx;
33
34 char apply_sid[RPC_SID_LEN + 1];
35
36 enum {
37 RPC_G_CONFIG,
38 RPC_G_SECTION,
39 RPC_G_OPTION,
40 RPC_G_TYPE,
41 RPC_G_MATCH,
42 RPC_G_SESSION,
43 __RPC_G_MAX,
44 };
45
46 static const struct blobmsg_policy rpc_uci_get_policy[__RPC_G_MAX] = {
47 [RPC_G_CONFIG] = { .name = "config", .type = BLOBMSG_TYPE_STRING },
48 [RPC_G_SECTION] = { .name = "section", .type = BLOBMSG_TYPE_STRING },
49 [RPC_G_OPTION] = { .name = "option", .type = BLOBMSG_TYPE_STRING },
50 [RPC_G_TYPE] = { .name = "type", .type = BLOBMSG_TYPE_STRING },
51 [RPC_G_MATCH] = { .name = "match", .type = BLOBMSG_TYPE_TABLE },
52 [RPC_G_SESSION] = { .name = "ubus_rpc_session",
53 .type = BLOBMSG_TYPE_STRING },
54 };
55
56 enum {
57 RPC_A_CONFIG,
58 RPC_A_TYPE,
59 RPC_A_NAME,
60 RPC_A_VALUES,
61 RPC_A_SESSION,
62 __RPC_A_MAX,
63 };
64
65 static const struct blobmsg_policy rpc_uci_add_policy[__RPC_A_MAX] = {
66 [RPC_A_CONFIG] = { .name = "config", .type = BLOBMSG_TYPE_STRING },
67 [RPC_A_TYPE] = { .name = "type", .type = BLOBMSG_TYPE_STRING },
68 [RPC_A_NAME] = { .name = "name", .type = BLOBMSG_TYPE_STRING },
69 [RPC_A_VALUES] = { .name = "values", .type = BLOBMSG_TYPE_TABLE },
70 [RPC_A_SESSION] = { .name = "ubus_rpc_session",
71 .type = BLOBMSG_TYPE_STRING },
72 };
73
74 enum {
75 RPC_S_CONFIG,
76 RPC_S_SECTION,
77 RPC_S_TYPE,
78 RPC_S_MATCH,
79 RPC_S_VALUES,
80 RPC_S_SESSION,
81 __RPC_S_MAX,
82 };
83
84 static const struct blobmsg_policy rpc_uci_set_policy[__RPC_S_MAX] = {
85 [RPC_S_CONFIG] = { .name = "config", .type = BLOBMSG_TYPE_STRING },
86 [RPC_S_SECTION] = { .name = "section", .type = BLOBMSG_TYPE_STRING },
87 [RPC_S_TYPE] = { .name = "type", .type = BLOBMSG_TYPE_STRING },
88 [RPC_S_MATCH] = { .name = "match", .type = BLOBMSG_TYPE_TABLE },
89 [RPC_S_VALUES] = { .name = "values", .type = BLOBMSG_TYPE_TABLE },
90 [RPC_S_SESSION] = { .name = "ubus_rpc_session",
91 .type = BLOBMSG_TYPE_STRING },
92 };
93
94 enum {
95 RPC_D_CONFIG,
96 RPC_D_SECTION,
97 RPC_D_TYPE,
98 RPC_D_MATCH,
99 RPC_D_OPTION,
100 RPC_D_OPTIONS,
101 RPC_D_SESSION,
102 __RPC_D_MAX,
103 };
104
105 static const struct blobmsg_policy rpc_uci_delete_policy[__RPC_D_MAX] = {
106 [RPC_D_CONFIG] = { .name = "config", .type = BLOBMSG_TYPE_STRING },
107 [RPC_D_SECTION] = { .name = "section", .type = BLOBMSG_TYPE_STRING },
108 [RPC_D_TYPE] = { .name = "type", .type = BLOBMSG_TYPE_STRING },
109 [RPC_D_MATCH] = { .name = "match", .type = BLOBMSG_TYPE_TABLE },
110 [RPC_D_OPTION] = { .name = "option", .type = BLOBMSG_TYPE_STRING },
111 [RPC_D_OPTIONS] = { .name = "options", .type = BLOBMSG_TYPE_ARRAY },
112 [RPC_D_SESSION] = { .name = "ubus_rpc_session",
113 .type = BLOBMSG_TYPE_STRING },
114 };
115
116 enum {
117 RPC_R_CONFIG,
118 RPC_R_SECTION,
119 RPC_R_OPTION,
120 RPC_R_NAME,
121 RPC_R_SESSION,
122 __RPC_R_MAX,
123 };
124
125 static const struct blobmsg_policy rpc_uci_rename_policy[__RPC_R_MAX] = {
126 [RPC_R_CONFIG] = { .name = "config", .type = BLOBMSG_TYPE_STRING },
127 [RPC_R_SECTION] = { .name = "section", .type = BLOBMSG_TYPE_STRING },
128 [RPC_R_OPTION] = { .name = "option", .type = BLOBMSG_TYPE_STRING },
129 [RPC_R_NAME] = { .name = "name", .type = BLOBMSG_TYPE_STRING },
130 [RPC_R_SESSION] = { .name = "ubus_rpc_session",
131 .type = BLOBMSG_TYPE_STRING },
132 };
133
134 enum {
135 RPC_O_CONFIG,
136 RPC_O_SECTIONS,
137 RPC_O_SESSION,
138 __RPC_O_MAX,
139 };
140
141 static const struct blobmsg_policy rpc_uci_order_policy[__RPC_O_MAX] = {
142 [RPC_O_CONFIG] = { .name = "config", .type = BLOBMSG_TYPE_STRING },
143 [RPC_O_SECTIONS] = { .name = "sections", .type = BLOBMSG_TYPE_ARRAY },
144 [RPC_O_SESSION] = { .name = "ubus_rpc_session",
145 .type = BLOBMSG_TYPE_STRING },
146 };
147
148 enum {
149 RPC_C_CONFIG,
150 RPC_C_SESSION,
151 __RPC_C_MAX,
152 };
153
154 static const struct blobmsg_policy rpc_uci_config_policy[__RPC_C_MAX] = {
155 [RPC_C_CONFIG] = { .name = "config", .type = BLOBMSG_TYPE_STRING },
156 [RPC_C_SESSION] = { .name = "ubus_rpc_session",
157 .type = BLOBMSG_TYPE_STRING },
158 };
159
160 enum {
161 RPC_T_ROLLBACK,
162 RPC_T_TIMEOUT,
163 RPC_T_SESSION,
164 __RPC_T_MAX,
165 };
166
167 static const struct blobmsg_policy rpc_uci_apply_policy[__RPC_T_MAX] = {
168 [RPC_T_ROLLBACK] = { .name = "rollback", .type = BLOBMSG_TYPE_BOOL },
169 [RPC_T_TIMEOUT] = { .name = "timeout", .type = BLOBMSG_TYPE_INT32 },
170 [RPC_T_SESSION] = { .name = "ubus_rpc_session",
171 .type = BLOBMSG_TYPE_STRING },
172 };
173
174 enum {
175 RPC_B_SESSION,
176 __RPC_B_MAX,
177 };
178
179 static const struct blobmsg_policy rpc_uci_rollback_policy[__RPC_B_MAX] = {
180 [RPC_B_SESSION] = { .name = "ubus_rpc_session",
181 .type = BLOBMSG_TYPE_STRING },
182 };
183
184 /*
185 * Validate a uci name
186 */
187 static bool
188 rpc_uci_verify_str(const char *name, bool extended, bool type)
189 {
190 const char *c;
191 char *e;
192
193 if (!name || !*name)
194 return false;
195
196 if (extended && *name != '@')
197 extended = false;
198
199 for (c = name + extended; *c; c++)
200 if (!isalnum(*c) && *c != '_' && ((!type && !extended) || *c != '-'))
201 break;
202
203 if (extended) {
204 if (*c != '[')
205 return false;
206
207 strtol(++c, &e, 10);
208
209 return (e > c && *e == ']' && *(e+1) == 0);
210 }
211
212 return (*c == 0);
213 }
214
215 /*
216 * Check that string is a valid, shell compatible uci name
217 */
218 static bool rpc_uci_verify_name(const char *name) {
219 return rpc_uci_verify_str(name, false, false);
220 }
221
222 /*
223 * Check that string is a valid section type name
224 */
225 static bool rpc_uci_verify_type(const char *type) {
226 return rpc_uci_verify_str(type, false, true);
227 }
228
229 /*
230 * Check that the string is a valid section id, optionally in extended
231 * lookup notation
232 */
233 static bool rpc_uci_verify_section(const char *section) {
234 return rpc_uci_verify_str(section, true, false);
235 }
236
237
238 /*
239 * Turn uci error state into ubus return code
240 */
241 static int
242 rpc_uci_status(void)
243 {
244 switch (cursor->err)
245 {
246 case UCI_OK:
247 return UBUS_STATUS_OK;
248
249 case UCI_ERR_INVAL:
250 return UBUS_STATUS_INVALID_ARGUMENT;
251
252 case UCI_ERR_NOTFOUND:
253 return UBUS_STATUS_NOT_FOUND;
254
255 default:
256 return UBUS_STATUS_UNKNOWN_ERROR;
257 }
258 }
259
260 /*
261 * Clear all save directories from the uci cursor and append the given path
262 * as new save directory.
263 */
264 static void
265 rpc_uci_replace_savedir(const char *path)
266 {
267 struct uci_element *e, *tmp;
268
269 uci_foreach_element_safe(&cursor->delta_path, tmp, e) {
270 if (e->name)
271 free(e->name);
272
273 free(e);
274 }
275
276 cursor->delta_path.prev = &cursor->delta_path;
277 cursor->delta_path.next = &cursor->delta_path;
278
279 if (path)
280 uci_set_savedir(cursor, path);
281 }
282
283 /*
284 * Setup per-session delta save directory. If the passed "sid" blob attribute
285 * pointer is NULL then the precedure was not invoked through the ubus-rpc so
286 * we do not perform session isolation and use the default save directory.
287 */
288 static void
289 rpc_uci_set_savedir(struct blob_attr *sid)
290 {
291 char path[PATH_MAX];
292
293 if (!sid)
294 {
295 rpc_uci_replace_savedir("/tmp/.uci");
296 return;
297 }
298
299 snprintf(path, sizeof(path) - 1,
300 RPC_UCI_SAVEDIR_PREFIX "%s", blobmsg_get_string(sid));
301
302 rpc_uci_replace_savedir(path);
303 }
304
305 /*
306 * Test read access to given config. If the passed "sid" blob attribute pointer
307 * is NULL then the precedure was not invoked through the ubus-rpc so we do not
308 * perform access control and always assume true.
309 */
310 static bool
311 rpc_uci_read_access(struct blob_attr *sid, struct blob_attr *config)
312 {
313 rpc_uci_set_savedir(sid);
314
315 if (!sid)
316 return true;
317
318 return rpc_session_access(blobmsg_data(sid), "uci",
319 blobmsg_data(config), "read");
320 }
321
322 /*
323 * Test write access to given config. If the passed "sid" blob attribute pointer
324 * is NULL then the precedure was not invoked through the ubus-rpc so we do not
325 * perform access control and always assume true.
326 */
327 static bool
328 rpc_uci_write_access(struct blob_attr *sid, struct blob_attr *config)
329 {
330 rpc_uci_set_savedir(sid);
331
332 if (!sid)
333 return true;
334
335 return rpc_session_access(blobmsg_data(sid), "uci",
336 blobmsg_data(config), "write");
337 }
338
339 /*
340 * Format applicable blob value as string and place a pointer to the string
341 * buffer in "p". Uses a static string buffer.
342 */
343 static bool
344 rpc_uci_format_blob(struct blob_attr *v, const char **p)
345 {
346 static char buf[21];
347
348 *p = NULL;
349
350 switch (blobmsg_type(v))
351 {
352 case BLOBMSG_TYPE_STRING:
353 *p = blobmsg_data(v);
354 break;
355
356 case BLOBMSG_TYPE_INT64:
357 snprintf(buf, sizeof(buf), "%"PRIu64, blobmsg_get_u64(v));
358 *p = buf;
359 break;
360
361 case BLOBMSG_TYPE_INT32:
362 snprintf(buf, sizeof(buf), "%u", blobmsg_get_u32(v));
363 *p = buf;
364 break;
365
366 case BLOBMSG_TYPE_INT16:
367 snprintf(buf, sizeof(buf), "%u", blobmsg_get_u16(v));
368 *p = buf;
369 break;
370
371 case BLOBMSG_TYPE_INT8:
372 snprintf(buf, sizeof(buf), "%u", !!blobmsg_get_u8(v));
373 *p = buf;
374 break;
375
376 default:
377 break;
378 }
379
380 return !!*p;
381 }
382
383 /*
384 * Lookup the given uci_ptr and enable extended lookup format if the .section
385 * value of the uci_ptr looks like extended syntax. Uses an internal copy
386 * of the given uci_ptr to perform the lookup as failing extended section
387 * lookup operations in libuci will zero our the uci_ptr struct.
388 * Copies the internal uci_ptr back to given the uci_ptr on success.
389 */
390 static int
391 rpc_uci_lookup(struct uci_ptr *ptr)
392 {
393 int rv;
394 struct uci_ptr lookup = *ptr;
395
396 if (!lookup.s && lookup.section && *lookup.section == '@')
397 lookup.flags |= UCI_LOOKUP_EXTENDED;
398
399 rv = uci_lookup_ptr(cursor, &lookup, NULL, true);
400
401 if (!rv)
402 *ptr = lookup;
403
404 return rv;
405 }
406
407 /*
408 * Checks whether the given uci_option object matches the given string value.
409 * 1) If the uci_option is of type list, check whether any of the list elements
410 * equals to the given string
411 * 2) If the uci_option is of type string, parse it into space separated tokens
412 * and check if any of the tokens equals to the given string.
413 * Returns true if a list element or token matched the given string.
414 */
415 static bool
416 rpc_uci_match_option(struct uci_option *o, const char *cmp)
417 {
418 struct uci_element *e;
419 char *s, *p;
420
421 if (o->type == UCI_TYPE_LIST)
422 {
423 uci_foreach_element(&o->v.list, e)
424 if (e->name && !strcmp(e->name, cmp))
425 return true;
426
427 return false;
428 }
429
430 if (!o->v.string)
431 return false;
432
433 s = strdup(o->v.string);
434
435 if (!s)
436 return false;
437
438 for (p = strtok(s, " \t"); p; p = strtok(NULL, " \t"))
439 {
440 if (!strcmp(p, cmp))
441 {
442 free(s);
443 return true;
444 }
445 }
446
447 free(s);
448 return false;
449 }
450
451 /*
452 * Checks whether the given uci_section matches the type and value blob attrs.
453 * 1) Returns false if "type" is given and the section type does not match
454 * the value specified in the "type" string blob attribute, else continue.
455 * 2) Tests whether any key in the "matches" table blob attribute exists in
456 * the given uci_section and whether each value is contained in the
457 * corresponding uci option value (see rpc_uci_match_option()).
458 * 3) A missing or empty "matches" table blob attribute is always considered
459 * to be a match.
460 * Returns true if "type" matches or is NULL and "matches" matches or is NULL.
461 */
462 static bool
463 rpc_uci_match_section(struct uci_section *s,
464 struct blob_attr *type, struct blob_attr *matches)
465 {
466 struct uci_element *e;
467 struct blob_attr *cur;
468 const char *cmp;
469 bool match = false;
470 bool empty = true;
471 int rem;
472
473 if (type && strcmp(s->type, blobmsg_data(type)))
474 return false;
475
476 if (!matches)
477 return true;
478
479 blobmsg_for_each_attr(cur, matches, rem)
480 {
481 if (!rpc_uci_format_blob(cur, &cmp))
482 continue;
483
484 uci_foreach_element(&s->options, e)
485 {
486 if (strcmp(e->name, blobmsg_name(cur)))
487 continue;
488
489 if (!rpc_uci_match_option(uci_to_option(e), cmp))
490 return false;
491
492 match = true;
493 }
494
495 empty = false;
496 }
497
498 return (empty || match);
499 }
500
501 /*
502 * Dump the given uci_option value into the global blobmsg buffer and use
503 * given "name" as key.
504 * 1) If the uci_option is of type list, put a table into the blob buffer and
505 * add each list item as string to it.
506 * 2) If the uci_option is of type string, put its value directly into the blob
507 * buffer.
508 */
509 static void
510 rpc_uci_dump_option(struct uci_option *o, const char *name)
511 {
512 void *c;
513 struct uci_element *e;
514
515 switch (o->type)
516 {
517 case UCI_TYPE_STRING:
518 blobmsg_add_string(&buf, name, o->v.string);
519 break;
520
521 case UCI_TYPE_LIST:
522 c = blobmsg_open_array(&buf, name);
523
524 uci_foreach_element(&o->v.list, e)
525 blobmsg_add_string(&buf, NULL, e->name);
526
527 blobmsg_close_array(&buf, c);
528 break;
529
530 default:
531 break;
532 }
533 }
534
535 /*
536 * Dump the given uci_section object into the global blobmsg buffer and use
537 * given "name" as key.
538 * Puts a table into the blob buffer and puts each section option member value
539 * as value into the table using the option name as key.
540 * Adds three special keys ".anonymous", ".type" and ".name" which specify the
541 * corresponding section properties.
542 */
543 static void
544 rpc_uci_dump_section(struct uci_section *s, const char *name, int index)
545 {
546 void *c;
547 struct uci_option *o;
548 struct uci_element *e;
549
550 c = blobmsg_open_table(&buf, name);
551
552 blobmsg_add_u8(&buf, ".anonymous", s->anonymous);
553 blobmsg_add_string(&buf, ".type", s->type);
554 blobmsg_add_string(&buf, ".name", s->e.name);
555
556 if (index >= 0)
557 blobmsg_add_u32(&buf, ".index", index);
558
559 uci_foreach_element(&s->options, e)
560 {
561 o = uci_to_option(e);
562 rpc_uci_dump_option(o, o->e.name);
563 }
564
565 blobmsg_close_table(&buf, c);
566 }
567
568 /*
569 * Dump the given uci_package object into the global blobmsg buffer and use
570 * given "name" as key.
571 * Puts a table into the blob buffer and puts each package section member as
572 * value into the table using the section name as key.
573 * Only dumps sections matching the given "type" and "matches", see explaination
574 * of rpc_uci_match_section() for details.
575 */
576 static void
577 rpc_uci_dump_package(struct uci_package *p, const char *name,
578 struct blob_attr *type, struct blob_attr *matches)
579 {
580 void *c;
581 struct uci_element *e;
582 int i = -1;
583
584 c = blobmsg_open_table(&buf, name);
585
586 uci_foreach_element(&p->sections, e)
587 {
588 i++;
589
590 if (!rpc_uci_match_section(uci_to_section(e), type, matches))
591 continue;
592
593 rpc_uci_dump_section(uci_to_section(e), e->name, i);
594 }
595
596 blobmsg_close_table(&buf, c);
597 }
598
599
600 static int
601 rpc_uci_getcommon(struct ubus_context *ctx, struct ubus_request_data *req,
602 struct blob_attr *msg, bool use_state)
603 {
604 struct blob_attr *tb[__RPC_G_MAX];
605 struct uci_package *p = NULL;
606 struct uci_ptr ptr = { 0 };
607
608 blobmsg_parse(rpc_uci_get_policy, __RPC_G_MAX, tb,
609 blob_data(msg), blob_len(msg));
610
611 if (!tb[RPC_G_CONFIG])
612 return UBUS_STATUS_INVALID_ARGUMENT;
613
614 if (!rpc_uci_read_access(tb[RPC_G_SESSION], tb[RPC_G_CONFIG]))
615 return UBUS_STATUS_PERMISSION_DENIED;
616
617 ptr.package = blobmsg_data(tb[RPC_G_CONFIG]);
618
619 if (use_state)
620 uci_set_savedir(cursor, "/var/state");
621
622 if (uci_load(cursor, ptr.package, &p))
623 return rpc_uci_status();
624
625 if (tb[RPC_G_SECTION])
626 {
627 ptr.section = blobmsg_data(tb[RPC_G_SECTION]);
628
629 if (tb[RPC_G_OPTION])
630 ptr.option = blobmsg_data(tb[RPC_G_OPTION]);
631 }
632
633 if (rpc_uci_lookup(&ptr) || !(ptr.flags & UCI_LOOKUP_COMPLETE))
634 goto out;
635
636 blob_buf_init(&buf, 0);
637
638 switch (ptr.last->type)
639 {
640 case UCI_TYPE_PACKAGE:
641 rpc_uci_dump_package(ptr.p, "values", tb[RPC_G_TYPE], tb[RPC_G_MATCH]);
642 break;
643
644 case UCI_TYPE_SECTION:
645 rpc_uci_dump_section(ptr.s, "values", -1);
646 break;
647
648 case UCI_TYPE_OPTION:
649 rpc_uci_dump_option(ptr.o, "value");
650 break;
651
652 default:
653 break;
654 }
655
656 ubus_send_reply(ctx, req, buf.head);
657
658 out:
659 uci_unload(cursor, p);
660
661 return rpc_uci_status();
662 }
663
664 static int
665 rpc_uci_get(struct ubus_context *ctx, struct ubus_object *obj,
666 struct ubus_request_data *req, const char *method,
667 struct blob_attr *msg)
668 {
669 return rpc_uci_getcommon(ctx, req, msg, false);
670 }
671
672 static int
673 rpc_uci_state(struct ubus_context *ctx, struct ubus_object *obj,
674 struct ubus_request_data *req, const char *method,
675 struct blob_attr *msg)
676 {
677 return rpc_uci_getcommon(ctx, req, msg, true);
678 }
679
680 static int
681 rpc_uci_add(struct ubus_context *ctx, struct ubus_object *obj,
682 struct ubus_request_data *req, const char *method,
683 struct blob_attr *msg)
684 {
685 struct blob_attr *tb[__RPC_A_MAX];
686 struct blob_attr *cur, *elem;
687 struct uci_package *p = NULL;
688 struct uci_section *s;
689 struct uci_ptr ptr = { 0 };
690 int rem, rem2;
691
692 blobmsg_parse(rpc_uci_add_policy, __RPC_A_MAX, tb,
693 blob_data(msg), blob_len(msg));
694
695 if (!tb[RPC_A_CONFIG] || !tb[RPC_A_TYPE])
696 return UBUS_STATUS_INVALID_ARGUMENT;
697
698 if (!rpc_uci_write_access(tb[RPC_A_SESSION], tb[RPC_A_CONFIG]))
699 return UBUS_STATUS_PERMISSION_DENIED;
700
701 if (!rpc_uci_verify_type(blobmsg_data(tb[RPC_A_TYPE])))
702 return UBUS_STATUS_INVALID_ARGUMENT;
703
704 if (tb[RPC_A_NAME] &&
705 !rpc_uci_verify_name(blobmsg_data(tb[RPC_A_NAME])))
706 return UBUS_STATUS_INVALID_ARGUMENT;
707
708 ptr.package = blobmsg_data(tb[RPC_A_CONFIG]);
709
710 if (uci_load(cursor, ptr.package, &p))
711 return rpc_uci_status();
712
713 /* add named section */
714 if (tb[RPC_A_NAME])
715 {
716 ptr.section = blobmsg_data(tb[RPC_A_NAME]);
717 ptr.value = blobmsg_data(tb[RPC_A_TYPE]);
718 ptr.option = NULL;
719
720 if (rpc_uci_lookup(&ptr) || uci_set(cursor, &ptr))
721 goto out;
722 }
723
724 /* add anon section */
725 else
726 {
727 if (uci_add_section(cursor, p, blobmsg_data(tb[RPC_A_TYPE]), &s) || !s)
728 goto out;
729
730 ptr.section = s->e.name;
731 }
732
733 if (tb[RPC_A_VALUES])
734 {
735 blobmsg_for_each_attr(cur, tb[RPC_A_VALUES], rem)
736 {
737 ptr.o = NULL;
738 ptr.option = blobmsg_name(cur);
739
740 if (!rpc_uci_verify_name(ptr.option))
741 continue;
742
743 if (rpc_uci_lookup(&ptr) || !ptr.s)
744 continue;
745
746 switch (blobmsg_type(cur))
747 {
748 case BLOBMSG_TYPE_ARRAY:
749 blobmsg_for_each_attr(elem, cur, rem2)
750 if (rpc_uci_format_blob(elem, &ptr.value))
751 uci_add_list(cursor, &ptr);
752 break;
753
754 default:
755 if (rpc_uci_format_blob(cur, &ptr.value))
756 uci_set(cursor, &ptr);
757 break;
758 }
759 }
760 }
761
762 uci_save(cursor, p);
763
764 blob_buf_init(&buf, 0);
765 blobmsg_add_string(&buf, "section", ptr.section);
766 ubus_send_reply(ctx, req, buf.head);
767
768 out:
769 uci_unload(cursor, p);
770
771 return rpc_uci_status();
772 }
773
774 /*
775 * Turn value from a blob attribute into uci set operation
776 * 1) if the blob is of type array, delete existing option (if any) and
777 * emit uci add_list operations for each element
778 * 2) if the blob is not an array but an option of type list exists,
779 * delete existing list and emit uci set operation for the blob value
780 * 3) in all other cases only emit a set operation if there is no existing
781 * option of if the existing options value differs from the blob value
782 */
783 static void
784 rpc_uci_merge_set(struct blob_attr *opt, struct uci_ptr *ptr)
785 {
786 struct blob_attr *cur;
787 int rem;
788
789 ptr->o = NULL;
790 ptr->option = blobmsg_name(opt);
791 ptr->value = NULL;
792
793 if (!rpc_uci_verify_name(ptr->option))
794 return;
795
796 if (rpc_uci_lookup(ptr) || !ptr->s)
797 return;
798
799 if (blobmsg_type(opt) == BLOBMSG_TYPE_ARRAY)
800 {
801 if (ptr->o)
802 uci_delete(cursor, ptr);
803
804 blobmsg_for_each_attr(cur, opt, rem)
805 if (rpc_uci_format_blob(cur, &ptr->value))
806 uci_add_list(cursor, ptr);
807 }
808 else if (ptr->o && ptr->o->type == UCI_TYPE_LIST)
809 {
810 uci_delete(cursor, ptr);
811
812 if (rpc_uci_format_blob(opt, &ptr->value))
813 uci_set(cursor, ptr);
814 }
815 else if (rpc_uci_format_blob(opt, &ptr->value))
816 {
817 if (!ptr->o || !ptr->o->v.string || strcmp(ptr->o->v.string, ptr->value))
818 uci_set(cursor, ptr);
819 }
820 }
821
822 static int
823 rpc_uci_set(struct ubus_context *ctx, struct ubus_object *obj,
824 struct ubus_request_data *req, const char *method,
825 struct blob_attr *msg)
826 {
827 struct blob_attr *tb[__RPC_S_MAX];
828 struct blob_attr *cur;
829 struct uci_package *p = NULL;
830 struct uci_element *e;
831 struct uci_ptr ptr = { 0 };
832 int rem;
833
834 blobmsg_parse(rpc_uci_set_policy, __RPC_S_MAX, tb,
835 blob_data(msg), blob_len(msg));
836
837 if (!tb[RPC_S_CONFIG] || !tb[RPC_S_VALUES] ||
838 (!tb[RPC_S_SECTION] && !tb[RPC_S_TYPE] && !tb[RPC_S_MATCH]))
839 return UBUS_STATUS_INVALID_ARGUMENT;
840
841 if (!rpc_uci_write_access(tb[RPC_S_SESSION], tb[RPC_S_CONFIG]))
842 return UBUS_STATUS_PERMISSION_DENIED;
843
844 if (tb[RPC_S_SECTION] &&
845 !rpc_uci_verify_section(blobmsg_data(tb[RPC_S_SECTION])))
846 return UBUS_STATUS_INVALID_ARGUMENT;
847
848 ptr.package = blobmsg_data(tb[RPC_S_CONFIG]);
849
850 if (uci_load(cursor, ptr.package, &p))
851 return rpc_uci_status();
852
853 if (tb[RPC_S_SECTION])
854 {
855 ptr.section = blobmsg_data(tb[RPC_S_SECTION]);
856 blobmsg_for_each_attr(cur, tb[RPC_S_VALUES], rem)
857 rpc_uci_merge_set(cur, &ptr);
858 }
859 else
860 {
861 uci_foreach_element(&p->sections, e)
862 {
863 if (!rpc_uci_match_section(uci_to_section(e),
864 tb[RPC_S_TYPE], tb[RPC_S_MATCH]))
865 continue;
866
867 ptr.s = NULL;
868 ptr.section = e->name;
869
870 blobmsg_for_each_attr(cur, tb[RPC_S_VALUES], rem)
871 rpc_uci_merge_set(cur, &ptr);
872 }
873 }
874
875 uci_save(cursor, p);
876 uci_unload(cursor, p);
877
878 return rpc_uci_status();
879 }
880
881 /*
882 * Delete option or section from uci specified by given blob attribute pointer
883 * 1) if the blob is of type array, delete any option named after each element
884 * 2) if the blob is of type string, delete the option named after its value
885 * 3) if the blob is NULL, delete entire section
886 */
887 static void
888 rpc_uci_merge_delete(struct blob_attr *opt, struct uci_ptr *ptr)
889 {
890 struct blob_attr *cur;
891 int rem;
892
893 if (rpc_uci_lookup(ptr) || !ptr->s)
894 return;
895
896 if (!opt)
897 {
898 ptr->o = NULL;
899 ptr->option = NULL;
900
901 uci_delete(cursor, ptr);
902 }
903 else if (blobmsg_type(opt) == BLOBMSG_TYPE_ARRAY)
904 {
905 blobmsg_for_each_attr(cur, opt, rem)
906 {
907 if (blobmsg_type(cur) != BLOBMSG_TYPE_STRING)
908 continue;
909
910 ptr->o = NULL;
911 ptr->option = blobmsg_data(cur);
912
913 if (rpc_uci_lookup(ptr) || !ptr->o)
914 continue;
915
916 uci_delete(cursor, ptr);
917 }
918 }
919 else if (blobmsg_type(opt) == BLOBMSG_TYPE_STRING)
920 {
921 ptr->o = NULL;
922 ptr->option = blobmsg_data(opt);
923
924 if (rpc_uci_lookup(ptr) || !ptr->o)
925 return;
926
927 uci_delete(cursor, ptr);
928 }
929 }
930
931 static int
932 rpc_uci_delete(struct ubus_context *ctx, struct ubus_object *obj,
933 struct ubus_request_data *req, const char *method,
934 struct blob_attr *msg)
935 {
936 struct blob_attr *tb[__RPC_D_MAX];
937 struct uci_package *p = NULL;
938 struct uci_element *e, *tmp;
939 struct uci_ptr ptr = { 0 };
940
941 blobmsg_parse(rpc_uci_delete_policy, __RPC_D_MAX, tb,
942 blob_data(msg), blob_len(msg));
943
944 if (!tb[RPC_D_CONFIG] ||
945 (!tb[RPC_D_SECTION] && !tb[RPC_D_TYPE] && !tb[RPC_D_MATCH]))
946 return UBUS_STATUS_INVALID_ARGUMENT;
947
948 if (!rpc_uci_write_access(tb[RPC_D_SESSION], tb[RPC_D_CONFIG]))
949 return UBUS_STATUS_PERMISSION_DENIED;
950
951 ptr.package = blobmsg_data(tb[RPC_D_CONFIG]);
952
953 if (uci_load(cursor, ptr.package, &p))
954 return rpc_uci_status();
955
956 if (tb[RPC_D_SECTION])
957 {
958 ptr.section = blobmsg_data(tb[RPC_D_SECTION]);
959
960 if (tb[RPC_D_OPTIONS])
961 rpc_uci_merge_delete(tb[RPC_D_OPTIONS], &ptr);
962 else
963 rpc_uci_merge_delete(tb[RPC_D_OPTION], &ptr);
964 }
965 else
966 {
967 uci_foreach_element_safe(&p->sections, tmp, e)
968 {
969 if (!rpc_uci_match_section(uci_to_section(e),
970 tb[RPC_D_TYPE], tb[RPC_D_MATCH]))
971 continue;
972
973 ptr.s = NULL;
974 ptr.section = e->name;
975
976 if (tb[RPC_D_OPTIONS])
977 rpc_uci_merge_delete(tb[RPC_D_OPTIONS], &ptr);
978 else
979 rpc_uci_merge_delete(tb[RPC_D_OPTION], &ptr);
980 }
981 }
982
983 uci_save(cursor, p);
984 uci_unload(cursor, p);
985
986 return rpc_uci_status();
987 }
988
989 static int
990 rpc_uci_rename(struct ubus_context *ctx, struct ubus_object *obj,
991 struct ubus_request_data *req, const char *method,
992 struct blob_attr *msg)
993 {
994 struct blob_attr *tb[__RPC_R_MAX];
995 struct uci_package *p = NULL;
996 struct uci_ptr ptr = { 0 };
997
998 blobmsg_parse(rpc_uci_rename_policy, __RPC_R_MAX, tb,
999 blob_data(msg), blob_len(msg));
1000
1001 if (!tb[RPC_R_CONFIG] || !tb[RPC_R_SECTION] || !tb[RPC_R_NAME])
1002 return UBUS_STATUS_INVALID_ARGUMENT;
1003
1004 if (!rpc_uci_write_access(tb[RPC_R_SESSION], tb[RPC_R_CONFIG]))
1005 return UBUS_STATUS_PERMISSION_DENIED;
1006
1007 ptr.package = blobmsg_data(tb[RPC_R_CONFIG]);
1008 ptr.section = blobmsg_data(tb[RPC_R_SECTION]);
1009 ptr.value = blobmsg_data(tb[RPC_R_NAME]);
1010
1011 if (!rpc_uci_verify_name(ptr.value))
1012 return UBUS_STATUS_INVALID_ARGUMENT;
1013
1014 if (tb[RPC_R_OPTION])
1015 ptr.option = blobmsg_data(tb[RPC_R_OPTION]);
1016
1017 if (uci_load(cursor, ptr.package, &p))
1018 return rpc_uci_status();
1019
1020 if (uci_lookup_ptr(cursor, &ptr, NULL, true))
1021 goto out;
1022
1023 if ((ptr.option && !ptr.o) || !ptr.s)
1024 {
1025 cursor->err = UCI_ERR_NOTFOUND;
1026 goto out;
1027 }
1028
1029 if (uci_rename(cursor, &ptr))
1030 goto out;
1031
1032 uci_save(cursor, p);
1033
1034 out:
1035 uci_unload(cursor, p);
1036
1037 return rpc_uci_status();
1038 }
1039
1040 static int
1041 rpc_uci_order(struct ubus_context *ctx, struct ubus_object *obj,
1042 struct ubus_request_data *req, const char *method,
1043 struct blob_attr *msg)
1044 {
1045 struct blob_attr *tb[__RPC_O_MAX];
1046 struct blob_attr *cur;
1047 struct uci_package *p = NULL;
1048 struct uci_ptr ptr = { 0 };
1049 int rem, i = 0;
1050
1051 blobmsg_parse(rpc_uci_order_policy, __RPC_O_MAX, tb,
1052 blob_data(msg), blob_len(msg));
1053
1054 if (!tb[RPC_O_CONFIG] || !tb[RPC_O_SECTIONS])
1055 return UBUS_STATUS_INVALID_ARGUMENT;
1056
1057 if (!rpc_uci_write_access(tb[RPC_O_SESSION], tb[RPC_O_CONFIG]))
1058 return UBUS_STATUS_PERMISSION_DENIED;
1059
1060 ptr.package = blobmsg_data(tb[RPC_O_CONFIG]);
1061
1062 if (uci_load(cursor, ptr.package, &p))
1063 return rpc_uci_status();
1064
1065 blobmsg_for_each_attr(cur, tb[RPC_O_SECTIONS], rem)
1066 {
1067 if (blobmsg_type(cur) != BLOBMSG_TYPE_STRING)
1068 continue;
1069
1070 ptr.s = NULL;
1071 ptr.section = blobmsg_data(cur);
1072
1073 if (uci_lookup_ptr(cursor, &ptr, NULL, true) || !ptr.s)
1074 continue;
1075
1076 uci_reorder_section(cursor, ptr.s, i++);
1077 }
1078
1079 uci_save(cursor, p);
1080 uci_unload(cursor, p);
1081
1082 return rpc_uci_status();
1083 }
1084
1085 static void
1086 rpc_uci_dump_change(struct uci_delta *d)
1087 {
1088 void *c;
1089 const char *types[] = {
1090 [UCI_CMD_REORDER] = "order",
1091 [UCI_CMD_REMOVE] = "remove",
1092 [UCI_CMD_RENAME] = "rename",
1093 [UCI_CMD_ADD] = "add",
1094 [UCI_CMD_LIST_ADD] = "list-add",
1095 [UCI_CMD_LIST_DEL] = "list-del",
1096 [UCI_CMD_CHANGE] = "set",
1097 };
1098
1099 if (!d->section)
1100 return;
1101
1102 c = blobmsg_open_array(&buf, NULL);
1103
1104 blobmsg_add_string(&buf, NULL, types[d->cmd]);
1105 blobmsg_add_string(&buf, NULL, d->section);
1106
1107 if (d->e.name)
1108 blobmsg_add_string(&buf, NULL, d->e.name);
1109
1110 if (d->value)
1111 {
1112 if (d->cmd == UCI_CMD_REORDER)
1113 blobmsg_add_u32(&buf, NULL, strtoul(d->value, NULL, 10));
1114 else
1115 blobmsg_add_string(&buf, NULL, d->value);
1116 }
1117
1118 blobmsg_close_array(&buf, c);
1119 }
1120
1121 static int
1122 rpc_uci_changes(struct ubus_context *ctx, struct ubus_object *obj,
1123 struct ubus_request_data *req, const char *method,
1124 struct blob_attr *msg)
1125 {
1126 struct blob_attr *tb[__RPC_C_MAX];
1127 struct uci_package *p = NULL;
1128 struct uci_element *e;
1129 char **configs;
1130 void *c, *d;
1131 int i;
1132
1133 blobmsg_parse(rpc_uci_config_policy, __RPC_C_MAX, tb,
1134 blob_data(msg), blob_len(msg));
1135
1136 if (tb[RPC_C_CONFIG])
1137 {
1138 if (!rpc_uci_read_access(tb[RPC_C_SESSION], tb[RPC_C_CONFIG]))
1139 return UBUS_STATUS_PERMISSION_DENIED;
1140
1141 if (uci_load(cursor, blobmsg_data(tb[RPC_C_CONFIG]), &p))
1142 return rpc_uci_status();
1143
1144 blob_buf_init(&buf, 0);
1145 c = blobmsg_open_array(&buf, "changes");
1146
1147 uci_foreach_element(&p->saved_delta, e)
1148 rpc_uci_dump_change(uci_to_delta(e));
1149
1150 blobmsg_close_array(&buf, c);
1151
1152 uci_unload(cursor, p);
1153
1154 ubus_send_reply(ctx, req, buf.head);
1155
1156 return rpc_uci_status();
1157 }
1158
1159 rpc_uci_set_savedir(tb[RPC_C_SESSION]);
1160
1161 if (uci_list_configs(cursor, &configs))
1162 return rpc_uci_status();
1163
1164 blob_buf_init(&buf, 0);
1165
1166 c = blobmsg_open_table(&buf, "changes");
1167
1168 for (i = 0; configs[i]; i++)
1169 {
1170 if (tb[RPC_C_SESSION] &&
1171 !rpc_session_access(blobmsg_data(tb[RPC_C_SESSION]), "uci",
1172 configs[i], "read"))
1173 continue;
1174
1175 if (uci_load(cursor, configs[i], &p))
1176 continue;
1177
1178 if (!uci_list_empty(&p->saved_delta))
1179 {
1180 d = blobmsg_open_array(&buf, configs[i]);
1181
1182 uci_foreach_element(&p->saved_delta, e)
1183 rpc_uci_dump_change(uci_to_delta(e));
1184
1185 blobmsg_close_array(&buf, d);
1186 }
1187
1188 uci_unload(cursor, p);
1189 }
1190
1191 blobmsg_close_table(&buf, c);
1192
1193 ubus_send_reply(ctx, req, buf.head);
1194
1195 return 0;
1196 }
1197
1198 static void
1199 rpc_uci_trigger_event(struct ubus_context *ctx, const char *config)
1200 {
1201 char *pkg = strdup(config);
1202 static struct blob_buf b;
1203 uint32_t id;
1204
1205 if (!ubus_lookup_id(ctx, "service", &id)) {
1206 void *c;
1207
1208 blob_buf_init(&b, 0);
1209 blobmsg_add_string(&b, "type", "config.change");
1210 c = blobmsg_open_table(&b, "data");
1211 blobmsg_add_string(&b, "package", pkg);
1212 blobmsg_close_table(&b, c);
1213 ubus_invoke(ctx, id, "event", b.head, NULL, 0, 1000);
1214 }
1215 free(pkg);
1216 }
1217
1218 static int
1219 rpc_uci_revert_commit(struct ubus_context *ctx, struct blob_attr *msg, bool commit)
1220 {
1221 struct blob_attr *tb[__RPC_C_MAX];
1222 struct uci_package *p = NULL;
1223 struct uci_ptr ptr = { 0 };
1224
1225 if (apply_sid[0])
1226 return UBUS_STATUS_PERMISSION_DENIED;
1227
1228 blobmsg_parse(rpc_uci_config_policy, __RPC_C_MAX, tb,
1229 blob_data(msg), blob_len(msg));
1230
1231 if (!tb[RPC_C_CONFIG])
1232 return UBUS_STATUS_INVALID_ARGUMENT;
1233
1234 if (!rpc_uci_write_access(tb[RPC_C_SESSION], tb[RPC_C_CONFIG]))
1235 return UBUS_STATUS_PERMISSION_DENIED;
1236
1237 ptr.package = blobmsg_data(tb[RPC_C_CONFIG]);
1238
1239 if (commit)
1240 {
1241 if (!uci_load(cursor, ptr.package, &p))
1242 {
1243 uci_commit(cursor, &p, false);
1244 uci_unload(cursor, p);
1245 rpc_uci_trigger_event(ctx, blobmsg_get_string(tb[RPC_C_CONFIG]));
1246 }
1247 }
1248 else
1249 {
1250 if (!uci_lookup_ptr(cursor, &ptr, NULL, true) && ptr.p)
1251 {
1252 uci_revert(cursor, &ptr);
1253 uci_unload(cursor, ptr.p);
1254 }
1255 }
1256
1257 return rpc_uci_status();
1258 }
1259
1260 static int
1261 rpc_uci_revert(struct ubus_context *ctx, struct ubus_object *obj,
1262 struct ubus_request_data *req, const char *method,
1263 struct blob_attr *msg)
1264 {
1265 return rpc_uci_revert_commit(ctx, msg, false);
1266 }
1267
1268 static int
1269 rpc_uci_commit(struct ubus_context *ctx, struct ubus_object *obj,
1270 struct ubus_request_data *req, const char *method,
1271 struct blob_attr *msg)
1272 {
1273 return rpc_uci_revert_commit(ctx, msg, true);
1274 }
1275
1276 static int
1277 rpc_uci_configs(struct ubus_context *ctx, struct ubus_object *obj,
1278 struct ubus_request_data *req, const char *method,
1279 struct blob_attr *msg)
1280 {
1281 char **configs;
1282 void *c;
1283 int i;
1284
1285 if (uci_list_configs(cursor, &configs))
1286 goto out;
1287
1288 blob_buf_init(&buf, 0);
1289
1290 c = blobmsg_open_array(&buf, "configs");
1291
1292 for (i = 0; configs[i]; i++)
1293 blobmsg_add_string(&buf, NULL, configs[i]);
1294
1295 blobmsg_close_array(&buf, c);
1296
1297 ubus_send_reply(ctx, req, buf.head);
1298
1299 out:
1300 return rpc_uci_status();
1301 }
1302
1303
1304 /*
1305 * Remove given delta save directory (if any).
1306 */
1307 static void
1308 rpc_uci_purge_dir(const char *path)
1309 {
1310 DIR *d;
1311 struct stat s;
1312 struct dirent *e;
1313 char file[PATH_MAX];
1314
1315 if (stat(path, &s) || !S_ISDIR(s.st_mode))
1316 return;
1317
1318 if ((d = opendir(path)) != NULL)
1319 {
1320 while ((e = readdir(d)) != NULL)
1321 {
1322 snprintf(file, sizeof(file) - 1, "%s/%s", path, e->d_name);
1323
1324 if (stat(file, &s) || !S_ISREG(s.st_mode))
1325 continue;
1326
1327 unlink(file);
1328 }
1329
1330 closedir(d);
1331
1332 rmdir(path);
1333 }
1334 }
1335
1336 static int
1337 rpc_uci_apply_config(struct ubus_context *ctx, char *config)
1338 {
1339 struct uci_package *p = NULL;
1340
1341 if (!uci_load(cursor, config, &p)) {
1342 uci_commit(cursor, &p, false);
1343 uci_unload(cursor, p);
1344 }
1345 rpc_uci_trigger_event(ctx, config);
1346
1347 return 0;
1348 }
1349
1350 static void
1351 rpc_uci_copy_file(const char *src, const char *target, const char *file)
1352 {
1353 char tmp[256];
1354 FILE *in, *out;
1355
1356 snprintf(tmp, sizeof(tmp), "%s%s", src, file);
1357 in = fopen(tmp, "rb");
1358 snprintf(tmp, sizeof(tmp), "%s%s", target, file);
1359 out = fopen(tmp, "wb+");
1360 if (in && out)
1361 while (!feof(in)) {
1362 int len = fread(tmp, 1, sizeof(tmp), in);
1363
1364 if(len > 0)
1365 fwrite(tmp, 1, len, out);
1366 }
1367 if(in)
1368 fclose(in);
1369 if(out)
1370 fclose(out);
1371 }
1372
1373 static int
1374 rpc_uci_apply_access(const char *sid, glob_t *gl)
1375 {
1376 struct stat s;
1377 int i, c = 0;
1378
1379 if (gl->gl_pathc < 3)
1380 return UBUS_STATUS_NO_DATA;
1381
1382 for (i = 0; i < gl->gl_pathc; i++) {
1383 char *config = basename(gl->gl_pathv[i]);
1384
1385 if (*config == '.')
1386 continue;
1387 if (stat(gl->gl_pathv[i], &s) || !s.st_size)
1388 continue;
1389 if (!rpc_session_access(sid, "uci", config, "write"))
1390 return UBUS_STATUS_PERMISSION_DENIED;
1391 c++;
1392 }
1393
1394 if (!c)
1395 return UBUS_STATUS_NO_DATA;
1396
1397 return 0;
1398 }
1399
1400 static void
1401 rpc_uci_do_rollback(struct ubus_context *ctx, glob_t *gl)
1402 {
1403 int i, deny;
1404 char tmp[PATH_MAX];
1405
1406 /* Test apply permission to see if the initiator session still exists.
1407 * If it does, restore the delta files as well, else just restore the
1408 * main configuration files. */
1409 deny = apply_sid[0]
1410 ? rpc_uci_apply_access(apply_sid, gl) : UBUS_STATUS_NOT_FOUND;
1411
1412 if (!deny) {
1413 snprintf(tmp, sizeof(tmp), RPC_UCI_SAVEDIR_PREFIX "%s/", apply_sid);
1414 mkdir(tmp, 0700);
1415 }
1416
1417 /* avoid merging unrelated uci changes when restoring old configs */
1418 rpc_uci_replace_savedir("/dev/null");
1419
1420 for (i = 0; i < gl->gl_pathc; i++) {
1421 char *config = basename(gl->gl_pathv[i]);
1422
1423 if (*config == '.')
1424 continue;
1425
1426 rpc_uci_copy_file(RPC_SNAPSHOT_FILES, RPC_UCI_DIR, config);
1427 rpc_uci_apply_config(ctx, config);
1428
1429 if (deny)
1430 continue;
1431
1432 rpc_uci_copy_file(RPC_SNAPSHOT_DELTA, tmp, config);
1433 }
1434
1435 rpc_uci_purge_dir(RPC_SNAPSHOT_FILES);
1436 rpc_uci_purge_dir(RPC_SNAPSHOT_DELTA);
1437
1438 uloop_timeout_cancel(&apply_timer);
1439 memset(apply_sid, 0, sizeof(apply_sid));
1440 apply_ctx = NULL;
1441 }
1442
1443 static void
1444 rpc_uci_apply_timeout(struct uloop_timeout *t)
1445 {
1446 glob_t gl;
1447 char tmp[PATH_MAX];
1448
1449 snprintf(tmp, sizeof(tmp), "%s/*", RPC_SNAPSHOT_FILES);
1450 if (glob(tmp, GLOB_PERIOD, NULL, &gl) < 0)
1451 return;
1452
1453 rpc_uci_do_rollback(apply_ctx, &gl);
1454
1455 globfree(&gl);
1456 }
1457
1458 static int
1459 rpc_uci_apply(struct ubus_context *ctx, struct ubus_object *obj,
1460 struct ubus_request_data *req, const char *method,
1461 struct blob_attr *msg)
1462 {
1463 struct blob_attr *tb[__RPC_T_MAX];
1464 int timeout = RPC_APPLY_TIMEOUT;
1465 char tmp[PATH_MAX];
1466 bool rollback = false;
1467 int ret, i;
1468 char *sid;
1469 glob_t gl;
1470
1471 blobmsg_parse(rpc_uci_apply_policy, __RPC_T_MAX, tb,
1472 blob_data(msg), blob_len(msg));
1473
1474 if (tb[RPC_T_ROLLBACK])
1475 rollback = blobmsg_get_bool(tb[RPC_T_ROLLBACK]);
1476
1477 if (apply_sid[0] && rollback)
1478 return UBUS_STATUS_PERMISSION_DENIED;
1479
1480 if (!tb[RPC_T_SESSION])
1481 return UBUS_STATUS_INVALID_ARGUMENT;
1482
1483 sid = blobmsg_data(tb[RPC_T_SESSION]);
1484
1485 if (tb[RPC_T_TIMEOUT])
1486 timeout = blobmsg_get_u32(tb[RPC_T_TIMEOUT]);
1487
1488 rpc_uci_purge_dir(RPC_SNAPSHOT_FILES);
1489 rpc_uci_purge_dir(RPC_SNAPSHOT_DELTA);
1490
1491 if (!apply_sid[0]) {
1492 rpc_uci_set_savedir(tb[RPC_T_SESSION]);
1493
1494 mkdir(RPC_SNAPSHOT_FILES, 0700);
1495 mkdir(RPC_SNAPSHOT_DELTA, 0700);
1496
1497 snprintf(tmp, sizeof(tmp), RPC_UCI_SAVEDIR_PREFIX "%s/*", sid);
1498 if (glob(tmp, GLOB_PERIOD, NULL, &gl) < 0)
1499 return UBUS_STATUS_NOT_FOUND;
1500
1501 snprintf(tmp, sizeof(tmp), RPC_UCI_SAVEDIR_PREFIX "%s/", sid);
1502
1503 ret = rpc_uci_apply_access(sid, &gl);
1504 if (ret) {
1505 globfree(&gl);
1506 return ret;
1507 }
1508
1509 /* copy SID early because rpc_uci_apply_config() will clobber buf */
1510 if (rollback)
1511 strncpy(apply_sid, sid, RPC_SID_LEN);
1512
1513 for (i = 0; i < gl.gl_pathc; i++) {
1514 char *config = basename(gl.gl_pathv[i]);
1515 struct stat s;
1516
1517 if (*config == '.')
1518 continue;
1519
1520 if (stat(gl.gl_pathv[i], &s) || !s.st_size)
1521 continue;
1522
1523 rpc_uci_copy_file(RPC_UCI_DIR, RPC_SNAPSHOT_FILES, config);
1524 rpc_uci_copy_file(tmp, RPC_SNAPSHOT_DELTA, config);
1525 rpc_uci_apply_config(ctx, config);
1526 }
1527
1528 globfree(&gl);
1529
1530 if (rollback) {
1531 apply_timer.cb = rpc_uci_apply_timeout;
1532 uloop_timeout_set(&apply_timer, timeout * 1000);
1533 apply_ctx = ctx;
1534 }
1535 }
1536
1537 return 0;
1538 }
1539
1540 static int
1541 rpc_uci_confirm(struct ubus_context *ctx, struct ubus_object *obj,
1542 struct ubus_request_data *req, const char *method,
1543 struct blob_attr *msg)
1544 {
1545 struct blob_attr *tb[__RPC_B_MAX];
1546 char *sid;
1547
1548 blobmsg_parse(rpc_uci_rollback_policy, __RPC_B_MAX, tb,
1549 blob_data(msg), blob_len(msg));
1550
1551 if (!tb[RPC_B_SESSION])
1552 return UBUS_STATUS_INVALID_ARGUMENT;
1553
1554 sid = blobmsg_data(tb[RPC_B_SESSION]);
1555
1556 if (!apply_sid[0])
1557 return UBUS_STATUS_NO_DATA;
1558
1559 if (strcmp(apply_sid, sid))
1560 return UBUS_STATUS_PERMISSION_DENIED;
1561
1562 rpc_uci_purge_dir(RPC_SNAPSHOT_FILES);
1563 rpc_uci_purge_dir(RPC_SNAPSHOT_DELTA);
1564
1565 uloop_timeout_cancel(&apply_timer);
1566 memset(apply_sid, 0, sizeof(apply_sid));
1567 apply_ctx = NULL;
1568
1569 return 0;
1570 }
1571
1572 static int
1573 rpc_uci_rollback(struct ubus_context *ctx, struct ubus_object *obj,
1574 struct ubus_request_data *req, const char *method,
1575 struct blob_attr *msg)
1576 {
1577 struct blob_attr *tb[__RPC_B_MAX];
1578 char tmp[PATH_MAX];
1579 glob_t gl;
1580 char *sid;
1581
1582 blobmsg_parse(rpc_uci_rollback_policy, __RPC_B_MAX, tb,
1583 blob_data(msg), blob_len(msg));
1584
1585 if (!apply_sid[0])
1586 return UBUS_STATUS_NO_DATA;
1587
1588 if (!tb[RPC_B_SESSION])
1589 return UBUS_STATUS_INVALID_ARGUMENT;
1590
1591 sid = blobmsg_data(tb[RPC_B_SESSION]);
1592
1593 if (strcmp(apply_sid, sid))
1594 return UBUS_STATUS_PERMISSION_DENIED;
1595
1596 snprintf(tmp, sizeof(tmp), "%s/*", RPC_SNAPSHOT_FILES);
1597 if (glob(tmp, GLOB_PERIOD, NULL, &gl) < 0)
1598 return UBUS_STATUS_NOT_FOUND;
1599
1600 rpc_uci_do_rollback(ctx, &gl);
1601
1602 globfree(&gl);
1603
1604 return 0;
1605 }
1606
1607 static int
1608 rpc_uci_reload(struct ubus_context *ctx, struct ubus_object *obj,
1609 struct ubus_request_data *req, const char *method,
1610 struct blob_attr *msg)
1611 {
1612 char * const cmd[2] = { "/sbin/reload_config", NULL };
1613
1614 if (!fork()) {
1615 /* wait for the RPC call to complete */
1616 sleep(2);
1617 return execv(cmd[0], cmd);
1618 }
1619
1620 return 0;
1621 }
1622
1623 /*
1624 * Session destroy callback to purge associated delta directory.
1625 */
1626 static void
1627 rpc_uci_purge_savedir_cb(struct rpc_session *ses, void *priv)
1628 {
1629 char path[PATH_MAX];
1630
1631 snprintf(path, sizeof(path) - 1, RPC_UCI_SAVEDIR_PREFIX "%s", ses->id);
1632 rpc_uci_purge_dir(path);
1633 }
1634
1635 /*
1636 * Removes all delta directories which match the RPC_UCI_SAVEDIR_PREFIX.
1637 * This is used to clean up garbage when starting rpcd.
1638 */
1639 void rpc_uci_purge_savedirs(void)
1640 {
1641 int i;
1642 glob_t gl;
1643
1644 if (!glob(RPC_UCI_SAVEDIR_PREFIX "*", 0, NULL, &gl))
1645 {
1646 for (i = 0; i < gl.gl_pathc; i++)
1647 rpc_uci_purge_dir(gl.gl_pathv[i]);
1648
1649 globfree(&gl);
1650 }
1651 }
1652
1653 int rpc_uci_api_init(struct ubus_context *ctx)
1654 {
1655 static const struct ubus_method uci_methods[] = {
1656 { .name = "configs", .handler = rpc_uci_configs },
1657 UBUS_METHOD("get", rpc_uci_get, rpc_uci_get_policy),
1658 UBUS_METHOD("state", rpc_uci_state, rpc_uci_get_policy),
1659 UBUS_METHOD("add", rpc_uci_add, rpc_uci_add_policy),
1660 UBUS_METHOD("set", rpc_uci_set, rpc_uci_set_policy),
1661 UBUS_METHOD("delete", rpc_uci_delete, rpc_uci_delete_policy),
1662 UBUS_METHOD("rename", rpc_uci_rename, rpc_uci_rename_policy),
1663 UBUS_METHOD("order", rpc_uci_order, rpc_uci_order_policy),
1664 UBUS_METHOD("changes", rpc_uci_changes, rpc_uci_config_policy),
1665 UBUS_METHOD("revert", rpc_uci_revert, rpc_uci_config_policy),
1666 UBUS_METHOD("commit", rpc_uci_commit, rpc_uci_config_policy),
1667 UBUS_METHOD("apply", rpc_uci_apply, rpc_uci_apply_policy),
1668 UBUS_METHOD("confirm", rpc_uci_confirm, rpc_uci_rollback_policy),
1669 UBUS_METHOD("rollback", rpc_uci_rollback, rpc_uci_rollback_policy),
1670 UBUS_METHOD_NOARG("reload_config", rpc_uci_reload),
1671 };
1672
1673 static struct ubus_object_type uci_type =
1674 UBUS_OBJECT_TYPE("luci-rpc-uci", uci_methods);
1675
1676 static struct ubus_object obj = {
1677 .name = "uci",
1678 .type = &uci_type,
1679 .methods = uci_methods,
1680 .n_methods = ARRAY_SIZE(uci_methods),
1681 };
1682
1683 static struct rpc_session_cb cb = {
1684 .cb = rpc_uci_purge_savedir_cb
1685 };
1686
1687 cursor = uci_alloc_context();
1688
1689 if (!cursor)
1690 return UBUS_STATUS_UNKNOWN_ERROR;
1691
1692 rpc_session_destroy_cb(&cb);
1693
1694 return ubus_add_object(ctx, &obj);
1695 }