-
Notifications
You must be signed in to change notification settings - Fork 0
/
main.c
86 lines (83 loc) · 2.11 KB
/
main.c
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
#define _GNU_SOURCE
#include <errno.h>
#include <limits.h>
#include <stdio.h>
#include <sched.h>
#include <stdlib.h>
#include <string.h>
#include <unistd.h>
#include <sys/capability.h>
#include <sys/types.h>
#include <sys/mount.h>
#include <sys/stat.h>
int is_file(char path[]) {
struct stat statbuf;
if (stat(path, &statbuf) == -1) {
perror("stat");
}
return !S_ISDIR(statbuf.st_mode);
}
int hide_package(const char* atom) {
FILE *fp;
char path[PATH_MAX+1];
/* str + max filename * 2 + \0, overkill */
char cmd[12+255+255+1] = "equery files ";
strcat(cmd, atom);
fp = popen(cmd, "r");
if (fp == NULL) {
fprintf(stderr, "failed querying files for %s\n", atom);
return -1;
}
memset(path, 0, sizeof(path));
while (fgets(path, sizeof(path), fp) != NULL) {
/* \n breaks stat() */
path[strcspn(path, "\n")] = 0;
if (is_file(path)) {
if (mount("/dev/null", path, "none", MS_BIND, "bind") == -1) {
perror("mount");
}
}
}
pclose(fp);
return 0;
}
int main(int argc, char* argv[], char *envp[]) {
cap_t cap;
cap_flag_value_t cf;
char **arg;
char *shell;
char *child_argv[] = { NULL };
/* needed for unshare(CLONE_NEWNS) */
cap = cap_get_proc();
cap_get_flag(cap, CAP_SYS_ADMIN, CAP_EFFECTIVE, &cf);
if (cf == CAP_CLEAR) {
fprintf(stderr, "CAP_SYS_ADMIN is cleared\n\
Please set it before executing this binary using:\n\
# setcap cap_sys_admin+eip build/ehide\n");
exit(EXIT_FAILURE);
}
if (argc < 2) {
fprintf(stdout, "desc: hide installed Portage \
package files using mount namespaces\n\
page: https://github.com/alfredfo/ehide\n\
usage: ehide <atom 1> <atom 2> <atom 3> ...\n");
exit(EXIT_FAILURE);
}
if (unshare(CLONE_NEWNS) == -1) {
perror("unshare");
exit(EXIT_FAILURE);
}
for (arg = ++argv; *arg; ++arg) {
if (hide_package(*arg) == -1) {
fprintf(stderr, "failed hiding package: %s\n", *arg);
continue;
}
printf("package hidden: %s\n", *arg);
}
shell = getenv("SHELL");
if (execve(shell, child_argv, envp) == -1) {
perror("Could not execute $SHELL");
exit(EXIT_FAILURE);
}
return 0;
}