*/
#define _GNU_SOURCE
+#define _LGPL_SOURCE
#include <errno.h>
#include <limits.h>
#include <stdio.h>
#include <common/utils.h>
#include <common/compat/mman.h>
#include <common/compat/clone.h>
+#include <common/compat/getenv.h>
#include "runas.h"
mode_t mode;
};
+struct run_as_unlink_data {
+ const char *path;
+};
+
+struct run_as_recursive_rmdir_data {
+ const char *path;
+};
+
+struct run_as_ret {
+ int ret;
+ int _errno;
+};
+
+#ifdef VALGRIND
+static
+int use_clone(void)
+{
+ return 0;
+}
+#else
+static
+int use_clone(void)
+{
+ return !lttng_secure_getenv("LTTNG_DEBUG_NOCLONE");
+}
+#endif
+
+LTTNG_HIDDEN
+int _utils_mkdir_recursive_unsafe(const char *path, mode_t mode);
+
/*
* Create recursively directory using the FULL path.
*/
path = data->path;
mode = data->mode;
- return utils_mkdir_recursive(path, mode);
+ /* Safe to call as we have transitioned to the requested uid/gid. */
+ return _utils_mkdir_recursive_unsafe(path, mode);
}
static
int _mkdir(void *_data)
{
- int ret;
struct run_as_mkdir_data *data = _data;
- ret = mkdir(data->path, data->mode);
- if (ret < 0) {
- ret = -errno;
- }
-
- return ret;
+ return mkdir(data->path, data->mode);
}
static
int _open(void *_data)
{
struct run_as_open_data *data = _data;
+
return open(data->path, data->flags, data->mode);
}
+static
+int _unlink(void *_data)
+{
+ struct run_as_unlink_data *data = _data;
+
+ return unlink(data->path);
+}
+
+static
+int _recursive_rmdir(void *_data)
+{
+ struct run_as_recursive_rmdir_data *data = _data;
+
+ return utils_recursive_rmdir(data->path);
+}
+
static
int child_run_as(void *_data)
{
int ret;
struct run_as_data *data = _data;
ssize_t writelen;
- size_t writeleft, index;
- union {
- int i;
- char c[sizeof(int)];
- } sendret;
+ struct run_as_ret sendret;
/*
* Child: it is safe to drop egid and euid while sharing the
ret = setegid(data->gid);
if (ret < 0) {
PERROR("setegid");
- sendret.i = -1;
goto write_return;
}
}
ret = seteuid(data->uid);
if (ret < 0) {
PERROR("seteuid");
- sendret.i = -1;
goto write_return;
}
}
* Also set umask to 0 for mkdir executable bit.
*/
umask(0);
- sendret.i = (*data->cmd)(data->data);
+ ret = (*data->cmd)(data->data);
write_return:
+ sendret.ret = ret;
+ sendret._errno = errno;
/* send back return value */
- writeleft = sizeof(sendret);
- index = 0;
- do {
- do {
- writelen = write(data->retval_pipe, &sendret.c[index],
- writeleft);
- } while (writelen < 0 && errno == EINTR);
- if (writelen < 0) {
- PERROR("write");
- return EXIT_FAILURE;
- }
- writeleft -= writelen;
- index += writelen;
- } while (writeleft > 0);
- return EXIT_SUCCESS;
+ writelen = lttng_write(data->retval_pipe, &sendret, sizeof(sendret));
+ if (writelen < sizeof(sendret)) {
+ PERROR("lttng_write error");
+ return EXIT_FAILURE;
+ } else {
+ return EXIT_SUCCESS;
+ }
}
static
{
struct run_as_data run_as_data;
int ret = 0;
+ ssize_t readlen;
int status;
pid_t pid;
int retval_pipe[2];
- ssize_t readlen, readleft, index;
void *child_stack;
- union {
- int i;
- char c[sizeof(int)];
- } retval;
+ struct run_as_ret recvret;
/*
* If we are non-root, we can only deal with our own uid.
*/
if (geteuid() != 0) {
if (uid != geteuid()) {
+ recvret.ret = -1;
+ recvret._errno = EPERM;
ERR("Client (%d)/Server (%d) UID mismatch (and sessiond is not root)",
uid, geteuid());
- return -EPERM;
+ goto end;
}
}
ret = pipe(retval_pipe);
if (ret < 0) {
+ recvret.ret = -1;
+ recvret._errno = errno;
PERROR("pipe");
- retval.i = ret;
goto end;
}
run_as_data.data = data;
MAP_PRIVATE | MAP_GROWSDOWN | MAP_ANONYMOUS | LTTNG_MAP_STACK,
-1, 0);
if (child_stack == MAP_FAILED) {
+ recvret.ret = -1;
+ recvret._errno = ENOMEM;
PERROR("mmap");
- retval.i = -ENOMEM;
goto close_pipe;
}
/*
pid = lttng_clone_files(child_run_as, child_stack + (RUNAS_CHILD_STACK_SIZE / 2),
&run_as_data);
if (pid < 0) {
+ recvret.ret = -1;
+ recvret._errno = errno;
PERROR("clone");
- retval.i = pid;
goto unmap_stack;
}
/* receive return value */
- readleft = sizeof(retval);
- index = 0;
- do {
- readlen = read(retval_pipe[0], &retval.c[index], readleft);
- if (readlen < 0) {
- PERROR("read");
- ret = -1;
- break;
- }
- readleft -= readlen;
- index += readlen;
- } while (readleft > 0);
+ readlen = lttng_read(retval_pipe[0], &recvret, sizeof(recvret));
+ if (readlen < sizeof(recvret)) {
+ recvret.ret = -1;
+ recvret._errno = errno;
+ }
/*
* Parent: wait for child to return, in which case the
*/
pid = waitpid(pid, &status, 0);
if (pid < 0 || !WIFEXITED(status) || WEXITSTATUS(status) != 0) {
+ recvret.ret = -1;
+ recvret._errno = errno;
PERROR("wait");
- retval.i = -1;
}
unmap_stack:
ret = munmap(child_stack, RUNAS_CHILD_STACK_SIZE);
if (ret < 0) {
+ recvret.ret = -1;
+ recvret._errno = errno;
PERROR("munmap");
- retval.i = ret;
}
close_pipe:
ret = close(retval_pipe[0]);
if (ret) {
+ recvret.ret = -1;
+ recvret._errno = errno;
PERROR("close");
}
ret = close(retval_pipe[1]);
if (ret) {
+ recvret.ret = -1;
+ recvret._errno = errno;
PERROR("close");
}
end:
- return retval.i;
+ errno = recvret._errno;
+ return recvret.ret;
}
/*
static
int run_as_noclone(int (*cmd)(void *data), void *data, uid_t uid, gid_t gid)
{
- int ret;
+ int ret, saved_errno;
mode_t old_mask;
old_mask = umask(0);
ret = cmd(data);
+ saved_errno = errno;
umask(old_mask);
+ errno = saved_errno;
return ret;
}
static
int run_as(int (*cmd)(void *data), void *data, uid_t uid, gid_t gid)
{
- if (!getenv("LTTNG_DEBUG_NOCLONE")) {
+ if (use_clone()) {
int ret;
DBG("Using run_as_clone");
data.mode = mode;
return run_as(_open, &data, uid, gid);
}
+
+LTTNG_HIDDEN
+int run_as_unlink(const char *path, uid_t uid, gid_t gid)
+{
+ struct run_as_unlink_data data;
+
+ DBG3("unlink() %s with for uid %d and gid %d",
+ path, uid, gid);
+ data.path = path;
+ return run_as(_unlink, &data, uid, gid);
+}
+
+LTTNG_HIDDEN
+int run_as_recursive_rmdir(const char *path, uid_t uid, gid_t gid)
+{
+ struct run_as_recursive_rmdir_data data;
+
+ DBG3("recursive_rmdir() %s with for uid %d and gid %d",
+ path, uid, gid);
+ data.path = path;
+ return run_as(_recursive_rmdir, &data, uid, gid);
+}