Commit Graph
29 Commits
Author SHA1 Message Date
Aaron Andersen 7206f745a2 tmpfiles: fix 'e' type to only adjust existing directories
According to tmpfiles.d(5), the 'e' type adjusts the mode and ownership
of existing paths but should not create them. Previously, mksubsys()
was used which could create directories.

Now we explicitly check if the path is an existing directory before
adjusting its permissions.
2026-01-18 18:59:20 -05:00
Aaron Andersen 25bcde12d4 tmpfiles: add support for numeric uid/gid in config files
Add parse_uid() and parse_gid() helper functions that support both
numeric IDs and name lookups. Update the d/D directory creation
handlers to use these new functions.

This allows config files to specify ownership using numeric UIDs and
GIDs instead of only usernames and group names, matching systemd-tmpfiles
behavior.
2026-01-18 18:59:20 -05:00
Aaron Andersen 7459ede806 tmpfiles: fix L+ to replace non-directory entries
The L+ type should replace existing entries with a symlink. Previously,
rmrf() was always called which is only appropriate for directories.
Now we check if the path is a directory first, and use erase() for
files and symlinks.
2026-01-18 18:59:20 -05:00
Aaron Andersen 6bf35513c3 tmpfiles: add support for config files on command line
Allow specifying one or more configuration files as command line
arguments instead of always processing all files in the standard
tmpfiles.d directories.

This enables targeted operations on specific config files:

    tmpfiles --create /etc/tmpfiles.d/myapp.conf
    tmpfiles --clean /tmp/test.conf /tmp/other.conf

When no config files are specified, the existing behavior of
processing all *.conf files in the standard directories is preserved.

Also refactors file processing into a helper function to reduce
code duplication.
2026-01-18 18:59:20 -05:00
Aaron Andersen 0b8d39329a tmpfiles: add --clean flag for age-based cleanup
Add support for the --clean (-C) flag to remove files and directories
older than the age specified in tmpfiles.d configuration entries.

The age field (6th column) in tmpfiles.d entries can now be used with
'd', 'D', and 'e' type entries to clean up old files.  Supported time
suffixes are: s (seconds), m (minutes), h (hours), d (days), w (weeks).

Example configuration:
    d /tmp/cache 0755 root root 10d

When run with --clean, files in /tmp/cache older than 10 days will be
removed.  The directory itself is preserved.

Uses a conservative cleanup approach matching systemd-tmpfiles:
 - Files: kept if ANY of atime, ctime, mtime is recent
 - Directories: kept if ANY of atime, mtime is recent (ctime excluded
   because cleanup itself updates directory ctime)

A value of "-" or "0" for age disables cleanup for that entry.

Note: x/X exclusion patterns are recognized but not yet implemented.
2026-01-18 18:59:20 -05:00
Aaron Andersen 84098dd8b7 tmpfiles: rename flags for clarity
Rename the command-line flag variables to be more descriptive:

  c_flag -> create_flag
  r_flag -> remove_flag

This improves code readability.
2026-01-18 18:59:20 -05:00
Joachim Wiberg 308f75b209 Silence false positive from Coverity Scan
51static int is_dir_empty(const char *path)
    52{
	 1. var_decl: Declaring variable namelist without initializer.
    53        struct dirent **namelist;
    54        int num;
    55

   CID 898746: (#1 of 1): Uninitialized pointer read (UNINIT)
   2. uninit_use_in_call: Using uninitialized value namelist when calling scandir.
    56        num = scandir(path, &namelist, NULL, NULL);
    57        if (num < 0)
    58                return 0;

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-12-15 22:37:07 +01:00
Joachim Wiberg 8377f0e736 Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-10 14:34:16 +02:00
Joachim Wiberg d652211621 Follow-up to db840bd, use systemf() to simplify tmpfiles evn further
Also, added benefit, we don't get compiler warnings for ignoring the
return value of system(), which we don't care about in this case.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 14:38:27 +02:00
Joachim Wiberg e319a606b8 tmpfiles: minor, fix memory leak
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 11:36:56 +02:00
Joachim Wiberg 58d48b54b3 tmpfiles: add -d,--debug mode
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 03:28:02 +02:00
Joachim Wiberg db840bdc19 Follow-up to 8be7a46, simplify linking of tmpfiles program
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 03:14:04 +02:00
Joachim Wiberg 06daf2e4a5 Relocate helper function, only used by tmpfiles
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-06 03:13:59 +02:00
Joachim Wiberg ffd00f646c Declare unused parameters
When building with global CFLAGS=-Wunused-parameter the output from the
build looks terrible.  This commit explicitly declares unused variables
to prevent triggering -Wunused-parameter

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2025-07-02 14:29:52 +02:00
Aaron Andersen 5993b4bb5d tmpfiles: refactor code into new is_dir_empty function
The existing implementation seemed useful enough to warrant a new
helper function. Care was taken to ensure the revised code no longer
suffers any memory leaks.
2025-06-05 20:53:25 -04:00
Aaron Andersen 2957246092 tmpfiles: implement remove logic for 'D'
> D
> Similar to d, but in addition the contents of the directory will be removed when --remove is used.
2025-06-02 19:27:24 -04:00
Aaron Andersen a5710125f6 tmpfiles: add --create and --remove flags
Allow execution of tmpfiles to specify which mode(s) of operation to run in.
2025-06-02 19:27:24 -04:00
Aaron Andersen ff95ebeb91 tmpfiles: split up create & remove logic
The tmpfiles.d spec contains entry types that should be acted upon in different modes
of operation: create, clean, remove, and purge - split up create & remove logic to
clarify the modes of operation finit supports.
2025-06-02 19:27:24 -04:00
Aaron Andersen 1921b3f2c5 tmpfiles: refactor into separate executable
The tmpfiles.d spec has proven useful in systemd, enough so that some developers
are starting to ship tmpfiles.d configuration files with their software.
By splitting the tmpfiles functionality in finit out into a separate executable
we are providing a useful piece of software that package managers can hook into.
2025-06-02 19:27:24 -04:00
Ming Liu 3e3e9aadf5 tmpfiles.c: prevent nftw follow symbolic links
When dealing with "L+" and "R", the function call 'nftw' should not
follow symbolic links, otherwise, it would also delete the targets
which is wrong.

For instance, if there is already a symbolic link:
```
/path/to/the/link -> /path/to/some/folder
```

if we set the following in a tmpfile conf:

```
L+ /path/to/the/link -    -    -     - /path/to/the/target
```

the result would be /path/to/some/folder also get deleted, which it
should not.

it could be even worse, when the symbolic link already is pointing to:
/path/to/the/target, the whole /path/to/the/target would be deleted on
next system boot.

Signed-off-by: Mathias Thore <mathias.thore@atlascopco.com>
Signed-off-by: Ming Liu <liu.ming50@gmail.com>
2024-08-24 13:29:10 +02:00
Joachim Wiberg b49f55ab3d tmpfiles.d: ignore x/X command, no cleanup at runtime with Finit
Silence log warnings for command x/X (ignore clean for path), because
Finit does not do tmpfiles cleaning at runtime.

x /tmp/podman-run-*
x /tmp/containers-user-*
x /tmp/run-*/libpod
D! /var/lib/containers/storage/tmp 0700 root root
D! /run/podman 0700 root root
D! /var/lib/cni/networks

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-03-13 12:06:39 +01:00
Joachim Wiberg d5d9cd5645 tmpfiles: fix error message and ignore unremovable dirs (EBUSY)
Fix copy-paste of error message from cond-w.c

A read-only root filesystem may have /var/lock, while we want to remove
it and add a symlink to ../run/lock.  Ignore errors from this since we
cannot do anything about it.  It is up to the user to fix their skeleton
or use an overlay.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-07 13:56:31 +01:00
Joachim Wiberg d5a5fffa52 Update copyright years
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2024-01-07 01:50:50 +01:00
Stargirl-chan 42cd8d284b Implement custom basename function (basenm)
There exist two possible basename functions, a xpg compliant one in libgen.h
and a GLIBC exclusive one declared in string.h, that was previously also declared by musl libc.
Both implementations are expecting different parameter types (`const char *` for GLIBC and `char *` for xpg)

With the removal of the basename function from string.h in musl libc, we could only rely on the xpg implementation.

Unfortunately, the xpg implementation of basename does modify the contents of whatever you put in it,
even though that there really is no need for it.

This is an issue in some cases, where we might want to get the basename of a read-only variable, e.g. a `const char *`,
as trying to modify something read-only is undefined behavior.

So in order to keep things consistent for us, we implement our own version of basename called `basenm`,
that does not modify the passed argument.
2023-12-29 10:44:40 +01:00
Joachim Wiberg eaaf8d862e Minor, append _ to PATH constant
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-10-04 18:25:09 +02:00
Joachim Wiberg e75c1792aa tmpfiles.d: propagate possible error from remove() in mksubsys()
Found by Coverity Scan.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-03-04 12:02:52 +01:00
Joachim Wiberg c81b722691 tmpfiles.d: add support for 'l' and 'l+', Finit extensions
Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-28 00:49:55 +01:00
Joachim Wiberg 11da93b759 Add support for Finit specific tmpfiles.d/
The tmpfilesd() glob sorts files according to name, we could name our
.conf as 00finit.conf to prevent ordering issues with, e.g. dnsmasq,
but this is more elegant and allows for multi-level override.

NOTE: bootmisc depends on the pidfile plugins since the latter need
      to set up its iwatches of /run before bootmisc creates /run.
      Depending on if it's a system with /var/run or /run we need to
      drop /var/run before recreating it.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-28 00:49:55 +01:00
Joachim Wiberg a4af9ba248 Add limited tmpfiles.d(5) support
This change adds very basic tmpfiles.d/ support to Finit.  Much of the
basic types are supported, but not all, so for now, please check the
code for details on what is working.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2023-02-28 00:48:25 +01:00