Blame sysdeps/freebsd/suid_open.c

Packit d37888
/* Copyright (C) 1998 Joshua Sled
Packit d37888
   This file is part of LibGTop 1.0.
Packit d37888
Packit d37888
   Contributed by Joshua Sled <jsled@xcf.berkeley.edu>, July 1998.
Packit d37888
Packit d37888
   LibGTop is free software; you can redistribute it and/or modify it
Packit d37888
   under the terms of the GNU General Public License as published by
Packit d37888
   the Free Software Foundation; either version 2 of the License,
Packit d37888
   or (at your option) any later version.
Packit d37888
Packit d37888
   LibGTop is distributed in the hope that it will be useful, but WITHOUT
Packit d37888
   ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
Packit d37888
   FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
Packit d37888
   for more details.
Packit d37888
Packit d37888
   You should have received a copy of the GNU General Public License
Packit d37888
   along with LibGTop; see the file COPYING. If not, write to the
Packit d37888
   Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,
Packit d37888
   Boston, MA 02110-1301, USA.
Packit d37888
*/
Packit d37888
Packit d37888
#include <config.h>
Packit d37888
#include <glibtop.h>
Packit d37888
#include <glibtop/error.h>
Packit d37888
#include <glibtop/cpu.h>
Packit d37888
#include <glibtop/open.h>
Packit d37888
#include <glibtop/init_hooks.h>
Packit d37888
#include <glibtop/machine.h>
Packit d37888
Packit d37888
Packit d37888
/* !!! THIS FUNCTION RUNS SUID ROOT - CHANGE WITH CAUTION !!! */
Packit d37888
Packit d37888
void
Packit d37888
glibtop_init_p (glibtop *server, const unsigned long features,
Packit d37888
		const unsigned flags)
Packit d37888
{
Packit d37888
	const _glibtop_init_func_t *init_fkt;
Packit d37888
Packit d37888
	if (server == NULL)
Packit d37888
		glibtop_error_r (NULL, "glibtop_init_p (server == NULL)");
Packit d37888
Packit d37888
	/* Do the initialization, but only if not already initialized. */
Packit d37888
Packit d37888
	if ((server->flags & _GLIBTOP_INIT_STATE_SYSDEPS) == 0) {
Packit d37888
		glibtop_open_p (server, "glibtop", features, flags);
Packit d37888
Packit d37888
		for (init_fkt = _glibtop_init_hook_p; *init_fkt; init_fkt++)
Packit d37888
			(*init_fkt) (server);
Packit d37888
Packit d37888
		server->flags |= _GLIBTOP_INIT_STATE_SYSDEPS;
Packit d37888
	}
Packit d37888
}
Packit d37888
Packit d37888
void
Packit d37888
glibtop_open_p (glibtop *server, const char *program_name,
Packit d37888
		const unsigned long features,
Packit d37888
		const unsigned flags)
Packit d37888
{
Packit d37888
	char errbuf[_POSIX2_LINE_MAX];
Packit d37888
	glibtop_debug ("glibtop_open_p ()");
Packit d37888
Packit d37888
	/* !!! WE ARE ROOT HERE - CHANGE WITH CAUTION !!! */
Packit d37888
	server->machine->uid = getuid ();
Packit d37888
	server->machine->euid = geteuid ();
Packit d37888
	server->machine->gid = getgid ();
Packit d37888
	server->machine->egid = getegid ();
Packit d37888
	/* Setup machine-specific data */
Packit d37888
	server->machine->kd = kvm_openfiles (NULL, NULL, NULL, O_RDONLY, errbuf);
Packit d37888
Packit d37888
	if (server->machine->kd == NULL)
Packit d37888
		glibtop_error_io_r (server, "kvm_open");
Packit d37888
Packit d37888
	/* Drop priviledges. */
Packit d37888
Packit d37888
	glibtop_debug ("uid=%d euid=%d gid=%d egid=%d", getuid(), geteuid(), getgid(), getegid());
Packit d37888
Packit d37888
	if (setreuid (server->machine->euid, server->machine->uid))
Packit d37888
		_exit (1);
Packit d37888
Packit d37888
	if (setregid (server->machine->egid, server->machine->gid))
Packit d37888
		_exit (1);
Packit d37888
Packit d37888
	glibtop_debug ("uid=%d euid=%d gid=%d egid=%d", getuid(), geteuid(), getgid(), getegid());
Packit d37888
Packit d37888
	/* !!! END OF SUID ROOT PART !!! */
Packit d37888
Packit d37888
	/* Our effective uid is now those of the user invoking the server,
Packit d37888
	 * so we do no longer have any priviledges. */
Packit d37888
Packit d37888
	/* NOTE: On FreeBSD, we do not need to be suid root, we just need to
Packit d37888
	 * be sgid kmem.
Packit d37888
	 *
Packit d37888
	 * The server will only use setegid() to get back it's priviledges,
Packit d37888
	 * so it will fail if it is suid root and not sgid kmem. */
Packit d37888
}