mirror of
https://github.com/RsyncProject/rsync.git
synced 2026-09-15 06:41:28 -04:00
Give vfs_open_owner_walk an explicit is_operator argument so its module-root confinement (abspath_excluded_by_module) reads the policy from the caller instead of the vfs.operator_path_resolve global -- the last owner-walk function still reading it. secure_basis_open gains an is_operator parameter threaded to it; its gate (owner-walk vs strict resolve) now branches on that param too. Faithful conversion (no behaviour change): every direct caller passes the value the global held at that site -- config/log/motd/early-input/files-from/ batch/connection/exclude/authenticate/params, change_dir's daemon dest-chdir, and vfs_secure_mkstemp's --temp-dir all pass 0; secure_basis_open passes VFS_OPERATOR_PATH only for the operator cases (a --partial-dir basis, fnamecmp_type == FNAMECMP_PARTIAL_DIR; and one_inplace partial-dir staging). This preserves the existing --temp-dir behaviour (unconfined) by deliberate choice; hardening that is a separate decision. The receiver partial-dir-basis and one_inplace operator_path_resolve blocks are removed (receiver.c is now free of the global). Set-sites: 7 -> 5 (backup make_backup, generator 1071/2085/2130, util1 handle_partial_dir). The operator-path-partial-dir-daemon test caught a real regression mid-change (secure_basis_open's gate still read the global after its set/clear block was removed, dropping the confinement); fixed by gating on is_operator. Full suite 190/50.
50 lines
1.5 KiB
C
50 lines
1.5 KiB
C
/*
|
|
* Support the max connections option.
|
|
*
|
|
* Copyright (C) 1998 Andrew Tridgell
|
|
* Copyright (C) 2006-2020 Wayne Davison
|
|
*
|
|
* This program is free software; you can redistribute it and/or modify
|
|
* it under the terms of the GNU General Public License as published by
|
|
* the Free Software Foundation; either version 3 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* This program is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU General Public License along
|
|
* with this program; if not, visit the http://fsf.org website.
|
|
*/
|
|
|
|
#include "rsync.h"
|
|
|
|
/* A simple routine to do connection counting. This returns 1 on success
|
|
* and 0 on failure, with errno also being set if the open() failed (errno
|
|
* will be 0 if the lock request failed). */
|
|
int claim_connection(char *fname, int max_connections)
|
|
{
|
|
int fd, i;
|
|
|
|
if (max_connections == 0)
|
|
return 1;
|
|
|
|
/* 'lock file = PATH': refuse symlinks not owned by uid 0 or our euid so
|
|
* a planted parent can't redirect the root daemon's O_CREAT open. */
|
|
if ((fd = vfs_open_owner_walk(fname, O_RDWR|O_CREAT, 0600, 0)) < 0)
|
|
return 0;
|
|
|
|
/* Find a free spot. */
|
|
for (i = 0; i < max_connections; i++) {
|
|
if (lock_range(fd, i*4, 4))
|
|
return 1;
|
|
}
|
|
|
|
close(fd);
|
|
|
|
/* A lock failure needs to return an errno of 0. */
|
|
errno = 0;
|
|
return 0;
|
|
}
|