mirror of
git://anongit.mindrot.org/openssh.git
synced 2025-02-19 23:36:54 +00:00
- markus@cvs.openbsd.org 2000/06/18 18:50:11 [auth2.c compat.c compat.h sshconnect2.c] make userauth+pubkey interop with ssh.com-2.2.0 - markus@cvs.openbsd.org 2000/06/18 20:56:17 [dsa.c] mem leak + be more paranoid in dsa_verify. - markus@cvs.openbsd.org 2000/06/18 21:29:50 [key.c] cleanup fingerprinting, less hardcoded sizes - markus@cvs.openbsd.org 2000/06/19 19:39:45 [atomicio.c auth-options.c auth-passwd.c auth-rh-rsa.c auth-rhosts.c] [auth-rsa.c auth-skey.c authfd.c authfd.h authfile.c bufaux.c bufaux.h] [buffer.c buffer.h canohost.c channels.c channels.h cipher.c cipher.h] [clientloop.c compat.c compat.h compress.c compress.h crc32.c crc32.h] [deattack.c dispatch.c dsa.c fingerprint.c fingerprint.h getput.h hmac.c] [kex.c log-client.c log-server.c login.c match.c mpaux.c mpaux.h nchan.c] [nchan.h packet.c packet.h pty.c pty.h readconf.c readconf.h readpass.c] [rsa.c rsa.h scp.c servconf.c servconf.h ssh-add.c ssh-keygen.c ssh.c] [ssh.h tildexpand.c ttymodes.c ttymodes.h uidswap.c xmalloc.c xmalloc.h] OpenBSD tag - markus@cvs.openbsd.org 2000/06/21 10:46:10 sshconnect2.c missing free; nuke old comment
89 lines
2.4 KiB
C
89 lines
2.4 KiB
C
/*
|
|
* Author: Tatu Ylonen <ylo@cs.hut.fi>
|
|
* Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
|
|
* All rights reserved
|
|
* Created: Sat Sep 9 01:56:14 1995 ylo
|
|
* Code for uid-swapping.
|
|
*/
|
|
|
|
#include "includes.h"
|
|
RCSID("$OpenBSD: uidswap.c,v 1.7 2000/06/20 01:39:45 markus Exp $");
|
|
|
|
#include "ssh.h"
|
|
#include "uidswap.h"
|
|
|
|
/*
|
|
* Note: all these functions must work in all of the following cases:
|
|
* 1. euid=0, ruid=0
|
|
* 2. euid=0, ruid!=0
|
|
* 3. euid!=0, ruid!=0
|
|
* Additionally, they must work regardless of whether the system has
|
|
* POSIX saved uids or not.
|
|
*/
|
|
|
|
#ifdef _POSIX_SAVED_IDS
|
|
/* Lets assume that posix saved ids also work with seteuid, even though that
|
|
is not part of the posix specification. */
|
|
#define SAVED_IDS_WORK_WITH_SETEUID
|
|
|
|
/* Saved effective uid. */
|
|
static uid_t saved_euid = 0;
|
|
|
|
#endif /* _POSIX_SAVED_IDS */
|
|
|
|
/*
|
|
* Temporarily changes to the given uid. If the effective user
|
|
* id is not root, this does nothing. This call cannot be nested.
|
|
*/
|
|
void
|
|
temporarily_use_uid(uid_t uid)
|
|
{
|
|
#ifdef SAVED_IDS_WORK_WITH_SETEUID
|
|
/* Save the current euid. */
|
|
saved_euid = geteuid();
|
|
|
|
/* Set the effective uid to the given (unprivileged) uid. */
|
|
if (seteuid(uid) == -1)
|
|
debug("seteuid %d: %.100s", (int) uid, strerror(errno));
|
|
#else /* SAVED_IDS_WORK_WITH_SETUID */
|
|
/* Propagate the privileged uid to all of our uids. */
|
|
if (setuid(geteuid()) < 0)
|
|
debug("setuid %d: %.100s", (int) geteuid(), strerror(errno));
|
|
|
|
/* Set the effective uid to the given (unprivileged) uid. */
|
|
if (seteuid(uid) == -1)
|
|
debug("seteuid %d: %.100s", (int) uid, strerror(errno));
|
|
#endif /* SAVED_IDS_WORK_WITH_SETEUID */
|
|
}
|
|
|
|
/*
|
|
* Restores to the original uid.
|
|
*/
|
|
void
|
|
restore_uid()
|
|
{
|
|
#ifdef SAVED_IDS_WORK_WITH_SETEUID
|
|
/* Set the effective uid back to the saved uid. */
|
|
if (seteuid(saved_euid) < 0)
|
|
debug("seteuid %d: %.100s", (int) saved_euid, strerror(errno));
|
|
#else /* SAVED_IDS_WORK_WITH_SETEUID */
|
|
/*
|
|
* We are unable to restore the real uid to its unprivileged value.
|
|
* Propagate the real uid (usually more privileged) to effective uid
|
|
* as well.
|
|
*/
|
|
setuid(getuid());
|
|
#endif /* SAVED_IDS_WORK_WITH_SETEUID */
|
|
}
|
|
|
|
/*
|
|
* Permanently sets all uids to the given uid. This cannot be
|
|
* called while temporarily_use_uid is effective.
|
|
*/
|
|
void
|
|
permanently_set_uid(uid_t uid)
|
|
{
|
|
if (setuid(uid) < 0)
|
|
debug("setuid %d: %.100s", (int) uid, strerror(errno));
|
|
}
|