popen.c revision 1.30
1/*	$OpenBSD: popen.c,v 1.30 2020/12/27 15:11:04 florian Exp $	*/
2/*	$NetBSD: popen.c,v 1.5 1995/04/11 02:45:00 cgd Exp $	*/
3
4/*
5 * Copyright (c) 1988, 1993, 1994
6 *	The Regents of the University of California.  All rights reserved.
7 *
8 * This code is derived from software written by Ken Arnold and
9 * published in UNIX Review, Vol. 6, No. 8.
10 *
11 * Redistribution and use in source and binary forms, with or without
12 * modification, are permitted provided that the following conditions
13 * are met:
14 * 1. Redistributions of source code must retain the above copyright
15 *    notice, this list of conditions and the following disclaimer.
16 * 2. Redistributions in binary form must reproduce the above copyright
17 *    notice, this list of conditions and the following disclaimer in the
18 *    documentation and/or other materials provided with the distribution.
19 * 3. Neither the name of the University nor the names of its contributors
20 *    may be used to endorse or promote products derived from this software
21 *    without specific prior written permission.
22 *
23 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
24 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26 * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
27 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33 * SUCH DAMAGE.
34 *
35 */
36
37#include <sys/types.h>
38#include <sys/wait.h>
39
40#include <errno.h>
41#include <glob.h>
42#include <limits.h>
43#include <signal.h>
44#include <stdio.h>
45#include <stdlib.h>
46#include <string.h>
47#include <syslog.h>
48#include <unistd.h>
49
50#include <netinet/in.h>
51
52#include "monitor.h"
53#include "extern.h"
54
55/*
56 * Special version of popen which avoids call to shell.  This ensures no one
57 * may create a pipe to a hidden program as a side effect of a list or dir
58 * command.
59 */
60
61FILE *
62ftpd_ls(const char *path, pid_t *pidptr)
63{
64	char *cp;
65	FILE *iop;
66	int argc = 0, pdes[2];
67	pid_t pid;
68	char **pop, *argv[_POSIX_ARG_MAX];
69
70	if (pipe(pdes) == -1)
71		return (NULL);
72
73	/* break up string into pieces */
74	argv[argc++] = "/bin/ls";
75	argv[argc++] = "-lgA";
76	argv[argc++] = "--";
77
78	/* glob that path */
79	if (path != NULL) {
80		glob_t gl;
81
82		memset(&gl, 0, sizeof(gl));
83		if (glob(path,
84		    GLOB_BRACE|GLOB_NOCHECK|GLOB_QUOTE|GLOB_TILDE|GLOB_LIMIT,
85		    NULL, &gl)) {
86			fatal ("Glob error.");
87		} else if (gl.gl_pathc > 0) {
88			for (pop = gl.gl_pathv; *pop && argc < _POSIX_ARG_MAX-1;
89			    pop++) {
90				argv[argc++] = strdup(*pop);
91				if (argv[argc - 1] == NULL)
92					fatal ("Out of memory.");
93			}
94		}
95		globfree(&gl);
96	}
97	argv[argc] = NULL;
98
99	iop = NULL;
100
101	switch (pid = fork()) {
102	case -1:			/* error */
103		(void)close(pdes[0]);
104		(void)close(pdes[1]);
105		goto pfree;
106		/* NOTREACHED */
107	case 0:				/* child */
108		if (pdes[1] != STDOUT_FILENO) {
109			dup2(pdes[1], STDOUT_FILENO);
110			(void)close(pdes[1]);
111		}
112		dup2(STDOUT_FILENO, STDERR_FILENO); /* stderr too! */
113		(void)close(pdes[0]);
114		closelog();
115
116		extern int ls_main(int, char **);
117
118		/* reset getopt for ls_main */
119		optreset = optind = 1;
120		exit(ls_main(argc, argv));
121	}
122	/* parent; assume fdopen can't fail...  */
123	iop = fdopen(pdes[0], "r");
124	(void)close(pdes[1]);
125	*pidptr = pid;
126
127 pfree:
128	for (argc = 3; argv[argc] != NULL; argc++)
129		free(argv[argc]);
130
131	return (iop);
132}
133
134int
135ftpd_pclose(FILE *iop, pid_t pid)
136{
137	int status;
138	pid_t rv;
139	sigset_t sigset, osigset;
140
141	(void)fclose(iop);
142	sigemptyset(&sigset);
143	sigaddset(&sigset, SIGINT);
144	sigaddset(&sigset, SIGQUIT);
145	sigaddset(&sigset, SIGHUP);
146	sigprocmask(SIG_BLOCK, &sigset, &osigset);
147	while ((rv = waitpid(pid, &status, 0)) == -1 && errno == EINTR)
148		continue;
149	sigprocmask(SIG_SETMASK, &osigset, NULL);
150	if (rv == -1)
151		return (-1);
152	if (WIFEXITED(status))
153		return (WEXITSTATUS(status));
154	return (1);
155}
156