wgtpkg-digsig: Add flag to accept/refuse a WGT without signature
[src/app-framework-main.git] / src / wgtpkg-install.c
index cec3b75..27dcb87 100644 (file)
@@ -1,5 +1,5 @@
 /*
- Copyright 2015, 2016, 2017 IoT.bzh
+ Copyright (C) 2015-2018 IoT.bzh
 
  author: José Bollo <jose.bollo@iot.bzh>
 
@@ -168,13 +168,13 @@ static int check_valid_string(const char *value, const char *name)
        if (c == 0) {
                ERROR("empty string forbidden in '%s' (temporary constraints)", name);
                errno = EINVAL;
-               return -1;                      
+               return -1;
        }
        do {
                if (!isalnum(c) && !strchr(".-_", c)) {
                        ERROR("forbidden char %c in '%s' -> '%s' (temporary constraints)", c, name, value);
                        errno = EINVAL;
-                       return -1;                      
+                       return -1;
                }
                c = value[++pos];
        } while(c);
@@ -188,12 +188,13 @@ static int check_temporary_constraints(const struct wgt_desc *desc)
        result  = check_valid_string(desc->id, "id");
        result |= check_valid_string(desc->version, "version");
        result |= check_valid_string(desc->ver, "ver");
-       result |= check_defined(desc->icons, "icon");
        result |= check_defined(desc->content_src, "content");
+       if (desc->icons)
+               result |= check_defined(desc->icons->src, "icon.src");
        if (result)
                return result;
 
-       if (desc->icons->next) {
+       if (desc->icons && desc->icons->next) {
                ERROR("widget has more than one icon defined (temporary constraints)");
                errno = EINVAL;
                result = -1;
@@ -294,6 +295,7 @@ static int check_one_content(const char *src, const char *type)
 {
        int rc;
        struct stat s;
+       int fhtdocs, serr;
 
        if (!src) {
                ERROR("a content src is missing");
@@ -303,6 +305,16 @@ static int check_one_content(const char *src, const char *type)
                /* TODO: when dealing with HTML and languages, the check should
                 * include i18n path search of widgets */
                rc = fstatat(workdirfd, src, &s, AT_NO_AUTOMOUNT|AT_SYMLINK_NOFOLLOW);
+               if (rc < 0) {
+                       serr = errno;
+                       fhtdocs = openat(workdirfd, "htdocs", O_DIRECTORY|O_PATH);
+                       if (fhtdocs >= 0) {
+                               rc = fstatat(fhtdocs, src, &s, AT_NO_AUTOMOUNT|AT_SYMLINK_NOFOLLOW);
+                               serr = errno;
+                               close(fhtdocs);
+                       }
+                       errno = serr;
+               }
                if (rc < 0)
                        ERROR("can't get info on content %s: %m", src);
                else if (!S_ISREG(s.st_mode)) {
@@ -357,6 +369,9 @@ static int install_icon(const struct wgt_desc *desc)
        char target[PATH_MAX];
        int rc;
 
+       if (!desc->icons)
+               return 0;
+
        create_directory(FWK_ICON_DIR, 0755, 1);
        rc = snprintf(link, sizeof link, "%s/%s", FWK_ICON_DIR, desc->idaver);
        if (rc >= (int)sizeof link) {
@@ -384,6 +399,37 @@ static int install_exec_flag(const struct wgt_desc *desc)
        return for_all_content(desc, set_exec_flag);
 }
 
+static int install_file_properties(const struct wgt_desc *desc)
+{
+       int rc, rc2;
+       struct wgt_desc_feature *feat;
+       struct wgt_desc_param *param;
+
+       rc = 0;
+       feat = desc->features;
+       while (feat) {
+               if (!strcmp(feat->name, "urn:AGL:widget:file-properties")) {
+                       param = feat->params;
+                       while (param) {
+                               if (!strcmp(param->value, "executable")) {
+                                       rc2 = fchmodat(workdirfd, param->name, 0755, 0);
+                                       if (rc2 < 0)
+                                               ERROR("can't make executable the file %s: %m", param->name);
+                               } else {
+                                       ERROR("unknown file property %s for %s", param->value, param->name);
+                                       errno = EINVAL;
+                                       rc2 = -1;
+                               }
+                               if (rc2 < 0 && !rc)
+                                       rc = rc2;
+                               param = param->next;
+                       }
+               }
+               feat = feat->next;
+       }
+       return rc;
+}
+
 static int install_security(const struct wgt_desc *desc)
 {
        char path[PATH_MAX], *head;
@@ -411,8 +457,8 @@ static int install_security(const struct wgt_desc *desc)
        }
        len--;
        *head++ = '/';
-       icon = desc->icons->src;
-       lic = (unsigned)strlen(icon);
+       icon = desc->icons ? desc->icons->src : NULL;
+       lic = (unsigned)(icon ? strlen(icon) : 0);
        n = file_count();
        i = 0;
        while(i < n) {
@@ -424,7 +470,7 @@ static int install_security(const struct wgt_desc *desc)
                        goto error2;
                }
                strcpy(head, f->name);
-               if (lf <= lic && !memcmp(f->name, icon, lf) && (!f->name[lf] || f->name[lf] == '/'))
+               if (lf <= lic && icon && !memcmp(f->name, icon, lf) && (!f->name[lf] || f->name[lf] == '/'))
                        rc = secmgr_path_public_read_only(path);
                else
                        rc = secmgr_path_read_only(path);
@@ -471,7 +517,7 @@ struct wgt_info *install_widget(const char *wgtfile, const char *root, int force
        if (zread(wgtfile, 0))
                goto error2;
 
-       if (check_all_signatures())
+       if (check_all_signatures(DEFAULT_ALLOW_NO_SIGNATURE))
                goto error2;
 
        ifo = wgt_info_createat(workdirfd, NULL, 1, 1, 1);
@@ -498,6 +544,9 @@ struct wgt_info *install_widget(const char *wgtfile, const char *root, int force
        if (install_exec_flag(desc))
                goto error4;
 
+       if (install_file_properties(desc))
+               goto error4;
+
        port = get_port();
        if (port < 0)
                goto error4;