#include <mach/mach.h>
#include <mach/mach_error.h>
#include <servers/bootstrap.h>
#include <unistd.h>
#include <stdio.h>
#include <stdlib.h>
#include <stdbool.h>
#include <membership.h>
#include <pthread.h>
#include <errno.h>
#include <sys/types.h>
#include <sys/stat.h>
#include <sys/param.h>
#include <uuid/uuid.h>
#include <string.h>
#include <libkern/OSByteOrder.h>
#include <TargetConditionals.h>
#include <xpc/xpc.h>
#include <xpc/private.h>
#include "dirhelper.h"
#include "dirhelper_priv.h"
#define BUCKETLEN 2
#define MUTEX_LOCK(x) if(__is_threaded) pthread_mutex_lock(x)
#define MUTEX_UNLOCK(x) if(__is_threaded) pthread_mutex_unlock(x)
#define ENCODEBITS 5
#define ENCODEDSIZE ((8 * UUID_UID_SIZE + ENCODEBITS - 1) / ENCODEBITS)
#define MASK(x) ((1 << (x)) - 1)
#define UUID_UID_SIZE (sizeof(uuid_t) + sizeof(uid_t))
extern int __is_threaded;
static const mode_t modes[] = {
0755,
0700,
0700,
};
static const char *subdirs[] = {
DIRHELPER_TOP_STR,
DIRHELPER_TEMP_STR,
DIRHELPER_CACHE_STR,
};
static pthread_once_t userdir_control = PTHREAD_ONCE_INIT;
static char *userdir = NULL;
static const char encode[] = "0123456789_bcdfghjklmnpqrstvwxyz";
static void
encode_uuid_uid(const uuid_t uuid, uid_t uid, char *str)
{
unsigned char buf[UUID_UID_SIZE + 1];
unsigned char *bp = buf;
int i;
unsigned int n;
memcpy(bp, uuid, sizeof(uuid_t));
uid = OSSwapHostToBigInt32(uid);
memcpy(bp + sizeof(uuid_t), &uid, sizeof(uid_t));
bp[UUID_UID_SIZE] = 0; for(i = 0; i < ENCODEDSIZE; i++) {
switch(i % 8) {
case 0:
n = *bp++;
*str++ = encode[n >> 3];
break;
case 1:
n = ((n & MASK(3)) << 8) | *bp++;
*str++ = encode[n >> 6];
break;
case 2:
n &= MASK(6);
*str++ = encode[n >> 1];
break;
case 3:
n = ((n & MASK(1)) << 8) | *bp++;
*str++ = encode[n >> 4];
break;
case 4:
n = ((n & MASK(4)) << 8) | *bp++;
*str++ = encode[n >> 7];
break;
case 5:
n &= MASK(7);
*str++ = encode[n >> 2];
break;
case 6:
n = ((n & MASK(2)) << 8) | *bp++;
*str++ = encode[n >> 5];
break;
case 7:
*str++ = encode[n & MASK(5)];
break;
}
}
*str = 0;
}
char *
__user_local_dirname(uid_t uid, dirhelper_which_t which, char *path, size_t pathlen)
{
#if TARGET_OS_EMBEDDED
char *tmpdir;
#else
uuid_t uuid;
char str[ENCODEDSIZE + 1];
#endif
int res;
if(which < 0 || which > DIRHELPER_USER_LOCAL_LAST) {
errno = EINVAL;
return NULL;
}
#if TARGET_OS_EMBEDDED
if(which == DIRHELPER_USER_LOCAL_TEMP) {
tmpdir = getenv("TMPDIR");
if(!tmpdir) {
errno = EINVAL;
return NULL;
}
res = snprintf(path, pathlen, "%s", tmpdir);
} else {
errno = EINVAL;
return NULL;
}
#else
res = mbr_uid_to_uuid(uid, uuid);
if(res != 0) {
errno = res;
return NULL;
}
encode_uuid_uid(uuid, uid, str);
res = snprintf(path, pathlen,
"%s%.*s/%s/%s",
VAR_FOLDERS_PATH, BUCKETLEN, str, str + BUCKETLEN, subdirs[which]);
#endif
if(res >= pathlen) {
errno = EINVAL;
return NULL;
}
return path;
}
char *
__user_local_mkdir_p(char *path)
{
char *next;
int res;
next = path + strlen(VAR_FOLDERS_PATH);
while ((next = strchr(next, '/')) != NULL) {
*next = 0; res = mkdir(path, 0755);
if (res != 0 && errno != EEXIST)
return NULL;
*next++ = '/'; }
return path;
}
static void userdir_allocate(void)
{
userdir = calloc(PATH_MAX, sizeof(char));
}
__private_extern__ void
_dirhelper_fork_child(void)
{
if(userdir) *userdir = 0;
}
__private_extern__ char *
_dirhelper(dirhelper_which_t which, char *path, size_t pathlen)
{
static pthread_mutex_t lock = PTHREAD_MUTEX_INITIALIZER;
struct stat sb;
if(which < 0 || which > DIRHELPER_USER_LOCAL_LAST) {
errno = EINVAL;
return NULL;
}
if (pthread_once(&userdir_control, userdir_allocate)
|| !userdir) {
errno = ENOMEM;
return NULL;
}
if(!*userdir) {
MUTEX_LOCK(&lock);
if (!*userdir) {
if(__user_local_dirname(geteuid(), DIRHELPER_USER_LOCAL, userdir, PATH_MAX) == NULL) {
MUTEX_UNLOCK(&lock);
return NULL;
}
userdir[strlen(userdir) - (sizeof(DIRHELPER_TOP_STR) - 1)] = 0;
if(stat(userdir, &sb) < 0) {
mach_port_t mp;
if(errno != ENOENT) {
*userdir = 0;
MUTEX_UNLOCK(&lock);
return NULL;
}
if (geteuid() == 0) {
if (__user_local_mkdir_p(userdir) == NULL) {
*userdir = 0;
MUTEX_UNLOCK(&lock);
return NULL;
}
} else {
if(bootstrap_look_up(bootstrap_port, DIRHELPER_BOOTSTRAP_NAME, &mp) != KERN_SUCCESS) {
errno = EPERM;
server_error:
mach_port_deallocate(mach_task_self(), mp);
MUTEX_UNLOCK(&lock);
return NULL;
}
if(__dirhelper_create_user_local(mp) != KERN_SUCCESS) {
errno = EPERM;
goto server_error;
}
if(stat(userdir, &sb) < 0) {
goto server_error;
}
mach_port_deallocate(mach_task_self(), mp);
}
}
}
MUTEX_UNLOCK(&lock);
}
if(pathlen < strlen(userdir) + strlen(subdirs[which]) + 1) {
errno = EINVAL;
return NULL;
}
strcpy(path, userdir);
strcat(path, subdirs[which]);
#if !TARGET_OS_EMBEDDED
if (!_xpc_runtime_is_app_sandboxed())
#endif
if(mkdir(path, modes[which]) != 0 && errno != EEXIST)
return NULL;
#if !TARGET_OS_EMBEDDED
if (_xpc_runtime_is_app_sandboxed()) {
if(stat(path, &sb) < 0) {
errno = EPERM;
return NULL;
}
char *container_id = getenv(XPC_ENV_SANDBOX_CONTAINER_ID);
if(!container_id) {
errno = EINVAL;
return NULL;
}
if (pathlen < strlen(path) + strlen(container_id) + 2) {
errno = EINVAL;
return NULL;
}
strcat(path, container_id);
strcat(path, "/");
if(mkdir(path, modes[which]) != 0 && errno != EEXIST)
return NULL;
}
#endif
return path;
}