Use faccessat, not access, when checking file permissions.
This fixes a bug that has been present in Emacs since its creation.
It was reported by Chris Torek in 1983 even before GNU Emacs existed,
which must set some sort of record. (Torek's bug report was against
a predecessor of GNU Emacs, but GNU Emacs happened to have the
same common flaw.) See Torek's Usenet posting
"setuid/setgid programs & Emacs" Article-I.D.: sri-arpa.858
Posted: Fri Apr 8 14:18:56 1983.
* .bzrignore: Add lib/fcntl.h.
* configure.ac (euidaccess): Remove check; gnulib does this for us now.
(gl_FCNTL_O_FLAGS): Define a dummy version.
* lib/at-func.c, lib/euidaccess.c, lib/faccessat.c, lib/fcntl.in.h:
* lib/getgroups.c, lib/group-member.c, lib/root-uid.h:
* lib/xalloc-oversized.h, m4/euidaccess.m4, m4/faccessat.m4:
* m4/fcntl_h.m4, m4/getgroups.m4, m4/group-member.m4:
New files, from gnulib.
* lib/gnulib.mk, m4/gnulib-comp.m4: Regenerate.
* admin/merge-gnulib (GNULIB_MODULES): Add faccessat.
(GNULIB_TOOL_FLAGS): Avoid at-internal, fchdir, malloc-posix,
openat-die, openat-h, save-cwd. Do not avoid fcntl-h.
Omit gnulib's m4/fcntl-o.m4.
* nt/inc/ms-w32.h (AT_FDCWD, AT_EACCESS): New symbols.
(access): Remove.
(faccessat): New macro.
* src/Makefile.in (LIB_EACCESS): New macro.
(LIBES): Use it.
* src/callproc.c (init_callproc):
* src/charset.c (init_charset):
* src/fileio.c (check_existing, check_executable, check_writable)
(Ffile_readable_p):
* src/lread.c (openp, load_path_check):
* src/process.c (allocate_pty):
* src/xrdb.c (file_p):
Use effective UID when checking permissions, not real UID.
* src/callproc.c (init_callproc):
* src/charset.c (init_charset):
* src/lread.c (load_path_check, init_lread):
Test whether directories are accessible, not merely whether they exist.
* src/conf_post.h (GNULIB_SUPPORT_ONLY_AT_FDCWD): New macro.
* src/fileio.c (check_existing, check_executable, check_writable)
(Ffile_readable_p):
Use symbolic names instead of integers for the flags, as they're
portable now.
(check_writable): New arg AMODE. All uses changed.
Set errno on failure.
(Ffile_readable_p): Use faccessat, not stat + open + close.
(Ffile_writable_p): No need to call check_existing + check_writable.
Just call check_writable and then look at errno. This saves a syscall.
dir should never be nil; replace an unnecessary runtime check
with an eassert. When checking the parent directory of a nonexistent
file, check that the directory is searchable as well as writable, as
we can't create files in unsearchable directories.
(file_directory_p): New function, which uses 'stat' on most platforms
but faccessat with D_OK (for efficiency) if WINDOWSNT.
(Ffile_directory_p, Fset_file_times): Use it.
(file_accessible_directory_p): New function, which uses a single
syscall for efficiency.
(Ffile_accessible_directory_p): Use it.
* src/xrdb.c (file_p): Use file_directory_p.
* src/lisp.h (file_directory_p, file_accessible_directory_p): New decls.
* src/lread.c (openp): When opening a file, use fstat rather than
stat, as that avoids a permissions race. When not opening a file,
use file_directory_p rather than stat.
(dir_warning): First arg is now a usage string, not a format.
Use errno. All uses changed.
* src/nsterm.m (ns_term_init): Remove unnecessary call to file-readable
that merely introduced a race.
* src/process.c, src/sysdep.c, src/term.c: All uses of '#ifdef O_NONBLOCK'
changed to '#if O_NONBLOCK', to accommodate gnulib O_* style,
and similarly for the other O_* flags.
* src/w32.c (sys_faccessat): Rename from sys_access and switch to
faccessat's API. All uses changed.
* src/xrdb.c: Do not include <sys/stat.h>; no longer needed.
(magic_db): Rename from magic_file_p.
(magic_db, search_magic_path): Return an XrmDatabase rather than a
char *, so that we don't have to test for file existence
separately from opening the file for reading. This removes a race
fixes a permission-checking problem, and simplifies the code.
All uses changed.
(file_p): Remove; no longer needed.
Fixes: debbugs:12632
2012-11-14 04:55:41 +00:00
|
|
|
/* Define at-style functions like fstatat, unlinkat, fchownat, etc.
|
2014-01-01 07:43:34 +00:00
|
|
|
Copyright (C) 2006, 2009-2014 Free Software Foundation, Inc.
|
Use faccessat, not access, when checking file permissions.
This fixes a bug that has been present in Emacs since its creation.
It was reported by Chris Torek in 1983 even before GNU Emacs existed,
which must set some sort of record. (Torek's bug report was against
a predecessor of GNU Emacs, but GNU Emacs happened to have the
same common flaw.) See Torek's Usenet posting
"setuid/setgid programs & Emacs" Article-I.D.: sri-arpa.858
Posted: Fri Apr 8 14:18:56 1983.
* .bzrignore: Add lib/fcntl.h.
* configure.ac (euidaccess): Remove check; gnulib does this for us now.
(gl_FCNTL_O_FLAGS): Define a dummy version.
* lib/at-func.c, lib/euidaccess.c, lib/faccessat.c, lib/fcntl.in.h:
* lib/getgroups.c, lib/group-member.c, lib/root-uid.h:
* lib/xalloc-oversized.h, m4/euidaccess.m4, m4/faccessat.m4:
* m4/fcntl_h.m4, m4/getgroups.m4, m4/group-member.m4:
New files, from gnulib.
* lib/gnulib.mk, m4/gnulib-comp.m4: Regenerate.
* admin/merge-gnulib (GNULIB_MODULES): Add faccessat.
(GNULIB_TOOL_FLAGS): Avoid at-internal, fchdir, malloc-posix,
openat-die, openat-h, save-cwd. Do not avoid fcntl-h.
Omit gnulib's m4/fcntl-o.m4.
* nt/inc/ms-w32.h (AT_FDCWD, AT_EACCESS): New symbols.
(access): Remove.
(faccessat): New macro.
* src/Makefile.in (LIB_EACCESS): New macro.
(LIBES): Use it.
* src/callproc.c (init_callproc):
* src/charset.c (init_charset):
* src/fileio.c (check_existing, check_executable, check_writable)
(Ffile_readable_p):
* src/lread.c (openp, load_path_check):
* src/process.c (allocate_pty):
* src/xrdb.c (file_p):
Use effective UID when checking permissions, not real UID.
* src/callproc.c (init_callproc):
* src/charset.c (init_charset):
* src/lread.c (load_path_check, init_lread):
Test whether directories are accessible, not merely whether they exist.
* src/conf_post.h (GNULIB_SUPPORT_ONLY_AT_FDCWD): New macro.
* src/fileio.c (check_existing, check_executable, check_writable)
(Ffile_readable_p):
Use symbolic names instead of integers for the flags, as they're
portable now.
(check_writable): New arg AMODE. All uses changed.
Set errno on failure.
(Ffile_readable_p): Use faccessat, not stat + open + close.
(Ffile_writable_p): No need to call check_existing + check_writable.
Just call check_writable and then look at errno. This saves a syscall.
dir should never be nil; replace an unnecessary runtime check
with an eassert. When checking the parent directory of a nonexistent
file, check that the directory is searchable as well as writable, as
we can't create files in unsearchable directories.
(file_directory_p): New function, which uses 'stat' on most platforms
but faccessat with D_OK (for efficiency) if WINDOWSNT.
(Ffile_directory_p, Fset_file_times): Use it.
(file_accessible_directory_p): New function, which uses a single
syscall for efficiency.
(Ffile_accessible_directory_p): Use it.
* src/xrdb.c (file_p): Use file_directory_p.
* src/lisp.h (file_directory_p, file_accessible_directory_p): New decls.
* src/lread.c (openp): When opening a file, use fstat rather than
stat, as that avoids a permissions race. When not opening a file,
use file_directory_p rather than stat.
(dir_warning): First arg is now a usage string, not a format.
Use errno. All uses changed.
* src/nsterm.m (ns_term_init): Remove unnecessary call to file-readable
that merely introduced a race.
* src/process.c, src/sysdep.c, src/term.c: All uses of '#ifdef O_NONBLOCK'
changed to '#if O_NONBLOCK', to accommodate gnulib O_* style,
and similarly for the other O_* flags.
* src/w32.c (sys_faccessat): Rename from sys_access and switch to
faccessat's API. All uses changed.
* src/xrdb.c: Do not include <sys/stat.h>; no longer needed.
(magic_db): Rename from magic_file_p.
(magic_db, search_magic_path): Return an XrmDatabase rather than a
char *, so that we don't have to test for file existence
separately from opening the file for reading. This removes a race
fixes a permission-checking problem, and simplifies the code.
All uses changed.
(file_p): Remove; no longer needed.
Fixes: debbugs:12632
2012-11-14 04:55:41 +00:00
|
|
|
|
|
|
|
This program is free software: you can redistribute it and/or modify
|
|
|
|
it under the terms of the GNU General Public License as published by
|
|
|
|
the Free Software Foundation; either version 3 of the License, or
|
|
|
|
(at your option) any later version.
|
|
|
|
|
|
|
|
This program is distributed in the hope that it will be useful,
|
|
|
|
but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
GNU General Public License for more details.
|
|
|
|
|
|
|
|
You should have received a copy of the GNU General Public License
|
|
|
|
along with this program. If not, see <http://www.gnu.org/licenses/>. */
|
|
|
|
|
|
|
|
/* written by Jim Meyering */
|
|
|
|
|
|
|
|
#include "dosname.h" /* solely for definition of IS_ABSOLUTE_FILE_NAME */
|
|
|
|
|
|
|
|
#ifdef GNULIB_SUPPORT_ONLY_AT_FDCWD
|
|
|
|
# include <errno.h>
|
|
|
|
# ifndef ENOTSUP
|
|
|
|
# define ENOTSUP EINVAL
|
|
|
|
# endif
|
|
|
|
#else
|
|
|
|
# include "openat.h"
|
|
|
|
# include "openat-priv.h"
|
|
|
|
# include "save-cwd.h"
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#ifdef AT_FUNC_USE_F1_COND
|
|
|
|
# define CALL_FUNC(F) \
|
|
|
|
(flag == AT_FUNC_USE_F1_COND \
|
|
|
|
? AT_FUNC_F1 (F AT_FUNC_POST_FILE_ARGS) \
|
|
|
|
: AT_FUNC_F2 (F AT_FUNC_POST_FILE_ARGS))
|
|
|
|
# define VALIDATE_FLAG(F) \
|
|
|
|
if (flag & ~AT_FUNC_USE_F1_COND) \
|
|
|
|
{ \
|
|
|
|
errno = EINVAL; \
|
|
|
|
return FUNC_FAIL; \
|
|
|
|
}
|
|
|
|
#else
|
|
|
|
# define CALL_FUNC(F) (AT_FUNC_F1 (F AT_FUNC_POST_FILE_ARGS))
|
|
|
|
# define VALIDATE_FLAG(F) /* empty */
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#ifdef AT_FUNC_RESULT
|
|
|
|
# define FUNC_RESULT AT_FUNC_RESULT
|
|
|
|
#else
|
|
|
|
# define FUNC_RESULT int
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#ifdef AT_FUNC_FAIL
|
|
|
|
# define FUNC_FAIL AT_FUNC_FAIL
|
|
|
|
#else
|
|
|
|
# define FUNC_FAIL -1
|
|
|
|
#endif
|
|
|
|
|
|
|
|
/* Call AT_FUNC_F1 to operate on FILE, which is in the directory
|
|
|
|
open on descriptor FD. If AT_FUNC_USE_F1_COND is defined to a value,
|
|
|
|
AT_FUNC_POST_FILE_PARAM_DECLS must include a parameter named flag;
|
|
|
|
call AT_FUNC_F2 if FLAG is 0 or fail if FLAG contains more bits than
|
|
|
|
AT_FUNC_USE_F1_COND. Return int and fail with -1 unless AT_FUNC_RESULT
|
|
|
|
or AT_FUNC_FAIL are defined. If possible, do it without changing the
|
|
|
|
working directory. Otherwise, resort to using save_cwd/fchdir,
|
|
|
|
then AT_FUNC_F?/restore_cwd. If either the save_cwd or the restore_cwd
|
|
|
|
fails, then give a diagnostic and exit nonzero. */
|
|
|
|
FUNC_RESULT
|
|
|
|
AT_FUNC_NAME (int fd, char const *file AT_FUNC_POST_FILE_PARAM_DECLS)
|
|
|
|
{
|
|
|
|
VALIDATE_FLAG (flag);
|
|
|
|
|
|
|
|
if (fd == AT_FDCWD || IS_ABSOLUTE_FILE_NAME (file))
|
|
|
|
return CALL_FUNC (file);
|
|
|
|
|
|
|
|
#ifdef GNULIB_SUPPORT_ONLY_AT_FDCWD
|
|
|
|
errno = ENOTSUP;
|
|
|
|
return FUNC_FAIL;
|
|
|
|
#else
|
|
|
|
{
|
|
|
|
/* Be careful to choose names unlikely to conflict with
|
|
|
|
AT_FUNC_POST_FILE_PARAM_DECLS. */
|
|
|
|
struct saved_cwd saved_cwd;
|
|
|
|
int saved_errno;
|
|
|
|
FUNC_RESULT err;
|
|
|
|
|
|
|
|
{
|
|
|
|
char proc_buf[OPENAT_BUFFER_SIZE];
|
|
|
|
char *proc_file = openat_proc_name (proc_buf, fd, file);
|
|
|
|
if (proc_file)
|
|
|
|
{
|
|
|
|
FUNC_RESULT proc_result = CALL_FUNC (proc_file);
|
|
|
|
int proc_errno = errno;
|
|
|
|
if (proc_file != proc_buf)
|
|
|
|
free (proc_file);
|
|
|
|
/* If the syscall succeeds, or if it fails with an unexpected
|
|
|
|
errno value, then return right away. Otherwise, fall through
|
|
|
|
and resort to using save_cwd/restore_cwd. */
|
|
|
|
if (FUNC_FAIL != proc_result)
|
|
|
|
return proc_result;
|
|
|
|
if (! EXPECTED_ERRNO (proc_errno))
|
|
|
|
{
|
|
|
|
errno = proc_errno;
|
|
|
|
return proc_result;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if (save_cwd (&saved_cwd) != 0)
|
|
|
|
openat_save_fail (errno);
|
|
|
|
if (0 <= fd && fd == saved_cwd.desc)
|
|
|
|
{
|
|
|
|
/* If saving the working directory collides with the user's
|
|
|
|
requested fd, then the user's fd must have been closed to
|
|
|
|
begin with. */
|
|
|
|
free_cwd (&saved_cwd);
|
|
|
|
errno = EBADF;
|
|
|
|
return FUNC_FAIL;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (fchdir (fd) != 0)
|
|
|
|
{
|
|
|
|
saved_errno = errno;
|
|
|
|
free_cwd (&saved_cwd);
|
|
|
|
errno = saved_errno;
|
|
|
|
return FUNC_FAIL;
|
|
|
|
}
|
|
|
|
|
|
|
|
err = CALL_FUNC (file);
|
|
|
|
saved_errno = (err == FUNC_FAIL ? errno : 0);
|
|
|
|
|
|
|
|
if (restore_cwd (&saved_cwd) != 0)
|
|
|
|
openat_restore_fail (errno);
|
|
|
|
|
|
|
|
free_cwd (&saved_cwd);
|
|
|
|
|
|
|
|
if (saved_errno)
|
|
|
|
errno = saved_errno;
|
|
|
|
return err;
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
}
|
|
|
|
#undef CALL_FUNC
|
|
|
|
#undef FUNC_RESULT
|
|
|
|
#undef FUNC_FAIL
|