1/* $KAME: safefile.c,v 1.5 2001/03/05 19:54:06 thorpej Exp $ */ 2 3/* 4 * Copyright (C) 2000 WIDE Project. 5 * All rights reserved. 6 * 7 * Redistribution and use in source and binary forms, with or without 8 * modification, are permitted provided that the following conditions 9 * are met: 10 * 1. Redistributions of source code must retain the above copyright 11 * notice, this list of conditions and the following disclaimer. 12 * 2. Redistributions in binary form must reproduce the above copyright 13 * notice, this list of conditions and the following disclaimer in the 14 * documentation and/or other materials provided with the distribution. 15 * 3. Neither the name of the project nor the names of its contributors 16 * may be used to endorse or promote products derived from this software 17 * without specific prior written permission. 18 * 19 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND 20 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 21 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 22 * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE 23 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 24 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 25 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 26 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 27 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 28 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 29 * SUCH DAMAGE. 30 */ 31 32#include <sys/types.h> 33#include <sys/stat.h> 34#include <sys/socket.h> 35#include <netinet/in.h> 36#include <unistd.h> 37 38#include "plog.h" 39#include "debug.h" 40#include "misc.h" 41#include "safefile.h" 42 43int 44safefile(path, secret) 45 const char *path; 46 int secret; 47{ 48 struct stat s; 49 uid_t me; 50 51 /* no setuid */ 52 if (getuid() != geteuid()) { 53 plog(LLV_ERROR, LOCATION, NULL, 54 "setuid'ed execution not allowed\n"); 55 return -1; 56 } 57 58 if (stat(path, &s) != 0) 59 return -1; 60 61 /* the file must be owned by the running uid */ 62 me = getuid(); 63 if (s.st_uid != me) { 64 plog(LLV_ERROR, LOCATION, NULL, 65 "%s has invalid owner uid\n", path); 66 return -1; 67 } 68 69 switch (s.st_mode & S_IFMT) { 70 case S_IFREG: 71 break; 72 default: 73 plog(LLV_ERROR, LOCATION, NULL, 74 "%s is an invalid file type 0x%x\n", path, 75 (s.st_mode & S_IFMT)); 76 return -1; 77 } 78 79 /* secret file should not be read by others */ 80 if (secret) { 81 if ((s.st_mode & S_IRWXG) != 0 || (s.st_mode & S_IRWXO) != 0) { 82 plog(LLV_ERROR, LOCATION, NULL, 83 "%s has weak file permission\n", path); 84 return -1; 85 } 86 } 87 88 return 0; 89} 90