/*
- Copyright 2015 IoT.bzh
+ Copyright 2015, 2016 IoT.bzh
author: José Bollo <jose.bollo@iot.bzh>
#include <assert.h>
#include <unistd.h>
#include <stdio.h>
+#include <sys/stat.h>
#include "verbose.h"
#include "wgt.h"
#include "secmgr-wrap.h"
#include "utils-dir.h"
+static const char permission_required[] = "required";
+static const char permission_optional[] = "optional";
+static const char feature_required_permissions[] = FWK_PREFIX "required-permissions";
+static const char exec_type_string[] = "application/x-executable";
+
static int check_defined(const void *data, const char *name)
{
if (data)
return 0;
}
-static int check_permissions(const char *name, int required)
+static int set_required_permissions(struct wgt_desc_param *params, int required)
{
- if (permission_exists(name)) {
- if (request_permission(name)) {
- DEBUG("granted permission: %s", name);
- } else if (required) {
- ERROR("ungranted permission required: %s", name);
+ int optional;
+
+ while (params) {
+ /* check the value */
+ if (!strcmp(params->value, permission_required))
+ optional = !required;
+ else if (!strcmp(params->value, permission_optional))
+ optional = 1;
+ else {
+ ERROR("unexpected parameter value: %s found for %s", params->value, params->name);
errno = EPERM;
- return 0;
+ return -1;
+ }
+ /* set the permission */
+ if (request_permission(params->name)) {
+ DEBUG("granted permission: %s", params->name);
+ } else if (optional) {
+ INFO("optional permission ungranted: %s", params->name);
} else {
- INFO("ungranted permission optional: %s", name);
+ ERROR("ungranted permission required: %s", params->name);
+ errno = EPERM;
+ return -1;
}
+ params = params->next;
}
- return 1;
+ return 0;
}
static int check_widget(const struct wgt_desc *desc)
result = check_temporary_constraints(desc);
feature = desc->features;
- while(feature) {
- if (!check_permissions(feature->name, feature->required))
- result = -1;
+ while(result >= 0 && feature) {
+ if (!strcmp(feature->name, feature_required_permissions))
+ result = set_required_permissions(feature->params, feature->required);
feature = feature->next;
}
return result;
rc = snprintf(newdir, sizeof newdir, "%s/%s/%s", root, desc->id, desc->ver);
if (rc >= (int)sizeof newdir) {
- ERROR("path to long in move_widget");
+ ERROR("path too long in move_widget");
errno = EINVAL;
return -1;
}
create_directory(FWK_ICON_DIR, 0755, 1);
rc = snprintf(link, sizeof link, "%s/%s", FWK_ICON_DIR, desc->idaver);
if (rc >= (int)sizeof link) {
- ERROR("link to long in install_icon");
+ ERROR("link too long in install_icon");
errno = EINVAL;
return -1;
}
rc = snprintf(target, sizeof target, "%s/%s", workdir, desc->icons->src);
if (rc >= (int)sizeof target) {
- ERROR("target to long in install_icon");
+ ERROR("target too long in install_icon");
errno = EINVAL;
return -1;
}
return rc;
}
+static int install_exec_flag(const struct wgt_desc *desc)
+{
+ return desc->content_type != NULL && !strcmp(desc->content_type, exec_type_string)
+ ? fchmodat(workdirfd, desc->content_src, 0755, 0) : 0;
+}
+
static int install_security(const struct wgt_desc *desc)
{
char path[PATH_MAX], *head;
if (!ifo)
goto error2;
+ reset_requested_permissions();
desc = wgt_info_desc(ifo);
if (check_widget(desc))
goto error3;
if (install_icon(desc))
goto error3;
+ if (install_exec_flag(desc))
+ goto error3;
+
if (install_security(desc))
goto error3;
-
+
file_reset();
return ifo;