t_seteuid.c revision 261363
1100384Speter/* 2100384Speter * Copyright (c) 1999-2001 Proofpoint, Inc. and its suppliers. 3100384Speter * All rights reserved. 4100384Speter * 5100384Speter * By using this file, you agree to the terms and conditions set 6100384Speter * forth in the LICENSE file which can be found at the top level of 7100384Speter * the sendmail distribution. 8100384Speter * 9100384Speter */ 10100384Speter 11100384Speter/* 12100384Speter** This program checks to see if your version of seteuid works. 13100384Speter** Compile it, make it set-user-ID root, and run it as yourself (NOT as 14100384Speter** root). If it won't compile or outputs any MAYDAY messages, don't 15100384Speter** define USESETEUID in conf.h. 16100384Speter** 17100384Speter** NOTE: It is not sufficient to have seteuid in your library. 18100384Speter** You must also have saved uids that function properly. 19100384Speter** 20100384Speter** Compilation is trivial -- just "cc t_seteuid.c". Make it set-user-ID 21100384Speter** root and then execute it as a non-root user. 22100384Speter*/ 23100384Speter 24100384Speter#include <sys/types.h> 25100384Speter#include <unistd.h> 26100384Speter#include <stdio.h> 27118031Sobrien 28118031Sobrien#ifndef lint 29118031Sobrienstatic char id[] = "@(#)$Id: t_seteuid.c,v 8.9 2013/11/22 20:52:01 ca Exp $"; 30104738Speter#endif /* ! lint */ 31104738Speter 32100384Speter#ifdef __hpux 33100384Speter# define seteuid(e) setresuid(-1, e, -1) 34100384Speter#endif /* __hpux */ 35162954Sphk 36100384Speterstatic void 37100384Speterprintuids(str, r, e) 38100384Speter char *str; 39123746Speter uid_t r, e; 40100384Speter{ 41100384Speter printf("%s (should be %d/%d): r/euid=%d/%d\n", str, (int) r, (int) e, 42161343Sjkim (int) getuid(), (int) geteuid()); 43100384Speter} 44100384Speter 45100384Speterint 46151909Spsmain(argc, argv) 47100384Speter int argc; 48100384Speter char **argv; 49100384Speter{ 50100384Speter int fail = 0; 51100384Speter uid_t realuid = getuid(); 52100384Speter 53100384Speter printuids("initial uids", realuid, 0); 54100384Speter 55100384Speter if (geteuid() != 0) 56146950Sps { 57100384Speter printf("SETUP ERROR: re-run set-user-ID root\n"); 58100384Speter exit(1); 59100384Speter } 60100384Speter 61100384Speter if (getuid() == 0) 62100384Speter { 63150883Sjhb printf("SETUP ERROR: must be run by a non-root user\n"); 64113859Sjhb exit(1); 65100384Speter } 66100384Speter 67100384Speter if (seteuid(1) < 0) 68162551Sdavidxu printf("seteuid(1) failure\n"); 69100384Speter printuids("after seteuid(1)", realuid, 1); 70162551Sdavidxu 71100384Speter if (geteuid() != 1) 72127140Sjhb { 73157285Sps fail++; 74157285Sps printf("MAYDAY! Wrong effective uid\n"); 75100384Speter } 76100384Speter 77100384Speter /* do activity here */ 78100384Speter 79100384Speter if (seteuid(0) < 0) 80100384Speter { 81100384Speter fail++; 82100384Speter printf("seteuid(0) failure\n"); 83100384Speter } 84151582Sps printuids("after seteuid(0)", realuid, 0); 85151582Sps 86119333Speter if (geteuid() != 0) 87119333Speter { 88163018Sdavidxu fail++; 89119333Speter printf("MAYDAY! Wrong effective uid\n"); 90100384Speter } 91121719Speter if (getuid() != realuid) 92121719Speter { 93121719Speter fail++; 94121719Speter printf("MAYDAY! Wrong real uid\n"); 95121719Speter } 96100384Speter printf("\n"); 97119333Speter 98100384Speter if (seteuid(2) < 0) 99127140Sjhb { 100127140Sjhb fail++; 101136152Sjhb printf("seteuid(2) failure\n"); 102100384Speter } 103136152Sjhb printuids("after seteuid(2)", realuid, 2); 104136152Sjhb 105136152Sjhb if (geteuid() != 2) 106136152Sjhb { 107136152Sjhb fail++; 108100384Speter printf("MAYDAY! Wrong effective uid\n"); 109100384Speter } 110127140Sjhb 111127140Sjhb /* do activity here */ 112127140Sjhb 113100384Speter if (seteuid(0) < 0) 114100384Speter { 115100384Speter fail++; 116100384Speter printf("seteuid(0) failure\n"); 117100384Speter } 118100384Speter printuids("after seteuid(0)", realuid, 0); 119100384Speter 120100384Speter if (geteuid() != 0) 121100384Speter { 122100384Speter fail++; 123100384Speter printf("MAYDAY! Wrong effective uid\n"); 124100384Speter } 125100384Speter if (getuid() != realuid) 126100384Speter { 127100384Speter fail++; 128100384Speter printf("MAYDAY! Wrong real uid\n"); 129127140Sjhb } 130100384Speter 131100384Speter if (fail) 132100384Speter { 133100384Speter printf("\nThis system cannot use seteuid\n"); 134128597Smarcel exit(1); 135100384Speter } 136100384Speter 137100384Speter printf("\nIt is safe to define USESETEUID on this system\n"); 138156266Sps exit(0); 139156266Sps} 140100384Speter