2 Unix SMB/CIFS implementation.
4 POSIX NTVFS backend - pvfs_sys wrappers
6 Copyright (C) Andrew Tridgell 2010
7 Copyright (C) Andrew Bartlett 2010
9 This program is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; either version 3 of the License, or
12 (at your option) any later version.
14 This program is distributed in the hope that it will be useful,
15 but WITHOUT ANY WARRANTY; without even the implied warranty of
16 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 GNU General Public License for more details.
19 You should have received a copy of the GNU General Public License
20 along with this program. If not, see <http://www.gnu.org/licenses/>.
24 #include "vfs_posix.h"
25 #include "../lib/util/unix_privs.h"
28 these wrapper functions must only be called when the appropriate ACL
29 has already been checked. The wrappers will override a EACCES result
30 by gaining root privileges if the 'pvfs:perm override' is set on the
31 share (it is enabled by default)
33 Careful use of O_NOFOLLOW and O_DIRECTORY is used to prevent
34 security attacks via symlinks
39 struct pvfs_state *pvfs;
46 return to original directory when context is destroyed
48 static int pvfs_sys_pushdir_destructor(struct pvfs_sys_ctx *ctx)
52 if (ctx->old_wd == NULL) {
56 if (chdir(ctx->old_wd) != 0) {
57 smb_panic("Failed to restore working directory");
59 if (stat(".", &st) != 0) {
60 smb_panic("Failed to stat working directory");
62 if (st.st_ino != ctx->st_orig.st_ino ||
63 st.st_dev != ctx->st_orig.st_dev) {
64 smb_panic("Working directory changed during call");
72 chdir() to the directory part of a pathname, but disallow any
73 component with a symlink
75 Note that we can't use O_NOFOLLOW on the whole path as that only
76 prevents links in the final component of the path
78 static int pvfs_sys_chdir_nosymlink(struct pvfs_sys_ctx *ctx, const char *pathname)
81 size_t base_len = strlen(ctx->pvfs->base_directory);
83 /* don't check for symlinks in the base directory of the share */
84 if (strncmp(ctx->pvfs->base_directory, pathname, base_len) == 0 &&
85 pathname[base_len] == '/') {
86 if (chdir(ctx->pvfs->base_directory) != 0) {
89 pathname += base_len + 1;
92 path = talloc_strdup(ctx, pathname);
96 while ((p = strchr(path, '/'))) {
100 fd = open(path, O_NOFOLLOW | O_DIRECTORY | O_RDONLY);
104 if (chdir(path) != 0) {
108 if (stat(".", &st1) != 0 ||
109 fstat(fd, &st2) != 0) {
114 if (st1.st_ino != st2.st_ino ||
115 st1.st_dev != st2.st_dev) {
116 DEBUG(0,(__location__ ": Inode changed during chdir in '%s' - symlink attack?",
128 become root, and change directory to the directory component of a
129 path. Return a talloc context which when freed will move us back
130 to the original directory, and return us to the original uid
132 change the pathname argument to contain just the base component of
135 return NULL on error, which could include an attempt to subvert
136 security using symlink tricks
138 static struct pvfs_sys_ctx *pvfs_sys_pushdir(struct pvfs_state *pvfs,
139 const char **pathname)
141 struct pvfs_sys_ctx *ctx;
142 char *cwd, *p, *dirname;
145 ctx = talloc_zero(pvfs, struct pvfs_sys_ctx);
150 ctx->privs = root_privileges();
151 if (ctx->privs == NULL) {
156 talloc_steal(ctx, ctx->privs);
159 /* no pathname needed */
163 p = strrchr(*pathname, '/');
165 /* we don't need to change directory */
169 /* we keep the old st around, so we can tell that
170 we have come back to the right directory */
171 if (stat(".", &ctx->st_orig) != 0) {
176 cwd = get_current_dir_name();
181 ctx->old_wd = talloc_strdup(ctx, cwd);
182 if (ctx->old_wd == NULL) {
188 dirname = talloc_strndup(ctx, *pathname, (p - *pathname));
189 if (dirname == NULL) {
194 ret = pvfs_sys_chdir_nosymlink(ctx, *pathname);
200 talloc_set_destructor(ctx, pvfs_sys_pushdir_destructor);
202 /* return the basename as the filename that should be operated on */
203 (*pathname) = talloc_strdup(ctx, p+1);
214 chown a file that we created with a root privileges override
216 static int pvfs_sys_fchown(struct pvfs_state *pvfs, struct pvfs_sys_ctx *ctx, int fd)
218 return fchown(fd, root_privileges_original_uid(ctx->privs), -1);
222 chown a directory that we created with a root privileges override
224 static int pvfs_sys_chown(struct pvfs_state *pvfs, struct pvfs_sys_ctx *ctx, const char *name)
226 /* to avoid symlink hacks, we need to use fchown() on a directory fd */
228 fd = open(name, O_DIRECTORY | O_NOFOLLOW | O_RDONLY);
232 ret = pvfs_sys_fchown(pvfs, ctx, fd);
239 wrap open for system override
241 int pvfs_sys_open(struct pvfs_state *pvfs, const char *filename, int flags, mode_t mode)
244 struct pvfs_sys_ctx *ctx;
245 int saved_errno, orig_errno;
250 fd = open(filename, flags, mode);
252 !(pvfs->flags & PVFS_FLAG_PERM_OVERRIDE) ||
258 ctx = pvfs_sys_pushdir(pvfs, &filename);
264 /* don't allow permission overrides to follow links */
268 if O_CREAT was specified and O_EXCL was not specified
269 then initially do the open without O_CREAT, as in that case
270 we know that we did not create the file, so we don't have
273 if ((flags & O_CREAT) && !(flags & O_EXCL)) {
275 fd = open(filename, flags & ~O_CREAT, mode);
276 /* if this open succeeded, or if it failed
277 with anything other than ENOENT, then we return the
278 open result, with the original errno */
279 if (fd == -1 && errno != ENOENT) {
285 /* the file already existed and we opened it */
291 fd = open(filename, flags | O_EXCL, mode);
292 if (fd == -1 && errno != EEXIST) {
298 /* we created the file, we need to set the
299 right ownership on it */
300 ret = pvfs_sys_fchown(pvfs, ctx, fd);
313 /* the file got created between the two times
314 we tried to open it! Try again */
324 fd = open(filename, flags, mode);
331 /* if we have created a file then fchown it */
332 if (flags & O_CREAT) {
333 ret = pvfs_sys_fchown(pvfs, ctx, fd);
349 wrap unlink for system override
351 int pvfs_sys_unlink(struct pvfs_state *pvfs, const char *filename)
354 struct pvfs_sys_ctx *ctx;
355 int saved_errno, orig_errno;
359 ret = unlink(filename);
361 !(pvfs->flags & PVFS_FLAG_PERM_OVERRIDE) ||
368 ctx = pvfs_sys_pushdir(pvfs, &filename);
374 ret = unlink(filename);
387 static bool contains_symlink(const char *path)
389 int fd = open(path, O_NOFOLLOW | O_RDONLY);
394 return (errno == ELOOP);
398 wrap rename for system override
400 int pvfs_sys_rename(struct pvfs_state *pvfs, const char *name1, const char *name2)
403 struct pvfs_sys_ctx *ctx;
404 int saved_errno, orig_errno;
408 ret = rename(name1, name2);
410 !(pvfs->flags & PVFS_FLAG_PERM_OVERRIDE) ||
417 ctx = pvfs_sys_pushdir(pvfs, &name1);
423 /* we need the destination as an absolute path */
424 if (name2[0] != '/') {
425 name2 = talloc_asprintf(ctx, "%s/%s", ctx->old_wd, name2);
433 /* make sure the destination isn't a symlink beforehand */
434 if (contains_symlink(name2)) {
440 ret = rename(name1, name2);
447 /* make sure the destination isn't a symlink afterwards */
448 if (contains_symlink(name2)) {
449 DEBUG(0,(__location__ ": Possible symlink attack in rename to '%s' - unlinking\n", name2));
463 wrap mkdir for system override
465 int pvfs_sys_mkdir(struct pvfs_state *pvfs, const char *dirname, mode_t mode)
468 struct pvfs_sys_ctx *ctx;
469 int saved_errno, orig_errno;
473 ret = mkdir(dirname, mode);
475 !(pvfs->flags & PVFS_FLAG_PERM_OVERRIDE) ||
481 ctx = pvfs_sys_pushdir(pvfs, &dirname);
487 ret = mkdir(dirname, mode);
494 ret = pvfs_sys_chown(pvfs, ctx, dirname);
508 wrap rmdir for system override
510 int pvfs_sys_rmdir(struct pvfs_state *pvfs, const char *dirname)
513 struct pvfs_sys_ctx *ctx;
514 int saved_errno, orig_errno;
518 ret = rmdir(dirname);
520 !(pvfs->flags & PVFS_FLAG_PERM_OVERRIDE) ||
527 ctx = pvfs_sys_pushdir(pvfs, &dirname);
533 ret = rmdir(dirname);
546 wrap fchmod for system override
548 int pvfs_sys_fchmod(struct pvfs_state *pvfs, int fd, mode_t mode)
551 struct pvfs_sys_ctx *ctx;
552 int saved_errno, orig_errno;
556 ret = fchmod(fd, mode);
558 !(pvfs->flags & PVFS_FLAG_PERM_OVERRIDE) ||
565 ctx = pvfs_sys_pushdir(pvfs, NULL);
571 ret = fchmod(fd, mode);
585 wrap chmod for system override
587 int pvfs_sys_chmod(struct pvfs_state *pvfs, const char *filename, mode_t mode)
590 struct pvfs_sys_ctx *ctx;
591 int saved_errno, orig_errno;
595 ret = chmod(filename, mode);
597 !(pvfs->flags & PVFS_FLAG_PERM_OVERRIDE) ||
604 ctx = pvfs_sys_pushdir(pvfs, &filename);
610 ret = chmod(filename, mode);