annotate src/lib/safe-mkstemp.c @ 9490:fd84592e817b HEAD

dovecot-example.conf: Updated dict comments.
author Timo Sirainen <tss@iki.fi>
date Mon, 23 Nov 2009 13:08:47 -0500
parents 644b956f5f5a
children 00cd9aacd03c
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
8590
b9faf4db2a9f Updated copyright notices to include year 2009.
Timo Sirainen <tss@iki.fi>
parents: 8032
diff changeset
1 /* Copyright (c) 2007-2009 Dovecot authors, see the included COPYING file */
5542
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
2
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
3 #include "lib.h"
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
4 #include "str.h"
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
5 #include "hex-binary.h"
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
6 #include "randgen.h"
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
7 #include "hostpid.h"
9168
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
8 #include "eacces-error.h"
5542
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
9 #include "safe-mkstemp.h"
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
10
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
11 #include <unistd.h>
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
12 #include <fcntl.h>
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
13 #include <sys/stat.h>
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
14
9168
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
15 static int
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
16 safe_mkstemp_full(string_t *prefix, mode_t mode, uid_t uid, gid_t gid,
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
17 const char *gid_origin)
5542
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
18 {
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
19 size_t prefix_len;
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
20 struct stat st;
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
21 unsigned char randbuf[8];
9001
5302ce189a70 safe_mkstemp()'s mode parameter didn't override umask as it was supposed to.
Timo Sirainen <tss@iki.fi>
parents: 8590
diff changeset
22 mode_t old_umask;
5542
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
23 int fd;
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
24
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
25 prefix_len = str_len(prefix);
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
26 for (;;) {
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
27 do {
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
28 random_fill_weak(randbuf, sizeof(randbuf));
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
29 str_truncate(prefix, prefix_len);
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
30 str_append(prefix,
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
31 binary_to_hex(randbuf, sizeof(randbuf)));
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
32 } while (lstat(str_c(prefix), &st) == 0);
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
33
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
34 if (errno != ENOENT) {
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
35 i_error("stat(%s) failed: %m", str_c(prefix));
9206
644b956f5f5a safe_mkstemp*(): Truncate prefix to original length if creation failed.
Timo Sirainen <tss@iki.fi>
parents: 9168
diff changeset
36 str_truncate(prefix, prefix_len);
5542
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
37 return -1;
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
38 }
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
39
9001
5302ce189a70 safe_mkstemp()'s mode parameter didn't override umask as it was supposed to.
Timo Sirainen <tss@iki.fi>
parents: 8590
diff changeset
40 old_umask = umask(0666 ^ mode);
5302ce189a70 safe_mkstemp()'s mode parameter didn't override umask as it was supposed to.
Timo Sirainen <tss@iki.fi>
parents: 8590
diff changeset
41 fd = open(str_c(prefix), O_RDWR | O_EXCL | O_CREAT, 0666);
5302ce189a70 safe_mkstemp()'s mode parameter didn't override umask as it was supposed to.
Timo Sirainen <tss@iki.fi>
parents: 8590
diff changeset
42 umask(old_umask);
5542
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
43 if (fd != -1)
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
44 break;
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
45
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
46 if (errno != EEXIST) {
7343
034e18a91a6b Ignore EACCES errors silently.
Timo Sirainen <tss@iki.fi>
parents: 7086
diff changeset
47 if (errno != ENOENT && errno != EACCES)
6775
b6135e6a5ff2 Don't log an ENOENT error.
Timo Sirainen <tss@iki.fi>
parents: 6430
diff changeset
48 i_error("open(%s) failed: %m", str_c(prefix));
9206
644b956f5f5a safe_mkstemp*(): Truncate prefix to original length if creation failed.
Timo Sirainen <tss@iki.fi>
parents: 9168
diff changeset
49 str_truncate(prefix, prefix_len);
5542
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
50 return -1;
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
51 }
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
52 }
9168
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
53 if (uid == (uid_t)-1 && gid == (gid_t)-1)
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
54 return fd;
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
55
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
56 if (fchown(fd, uid, gid) < 0) {
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
57 if (errno == EPERM) {
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
58 i_error("%s", eperm_error_get_chgrp("fchown",
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
59 str_c(prefix), gid, gid_origin));
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
60 } else {
8032
fa2bd47fc59c safe_mkstemp(): If fchown() fails, log the used uid/gid.
Timo Sirainen <tss@iki.fi>
parents: 7343
diff changeset
61 i_error("fchown(%s, %ld, %ld) failed: %m",
fa2bd47fc59c safe_mkstemp(): If fchown() fails, log the used uid/gid.
Timo Sirainen <tss@iki.fi>
parents: 7343
diff changeset
62 str_c(prefix),
fa2bd47fc59c safe_mkstemp(): If fchown() fails, log the used uid/gid.
Timo Sirainen <tss@iki.fi>
parents: 7343
diff changeset
63 uid == (uid_t)-1 ? -1L : (long)uid,
fa2bd47fc59c safe_mkstemp(): If fchown() fails, log the used uid/gid.
Timo Sirainen <tss@iki.fi>
parents: 7343
diff changeset
64 gid == (gid_t)-1 ? -1L : (long)gid);
5542
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
65 }
9168
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
66 (void)close(fd);
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
67 (void)unlink(str_c(prefix));
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
68 return -1;
5542
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
69 }
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
70 return fd;
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
71 }
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
72
9168
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
73 int safe_mkstemp(string_t *prefix, mode_t mode, uid_t uid, gid_t gid)
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
74 {
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
75 return safe_mkstemp_full(prefix, mode, uid, gid, NULL);
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
76 }
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
77
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
78 int safe_mkstemp_group(string_t *prefix, mode_t mode,
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
79 gid_t gid, const char *gid_origin)
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
80 {
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
81 return safe_mkstemp_full(prefix, mode, (uid_t)-1, gid, gid_origin);
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
82 }
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
83
5542
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
84 int safe_mkstemp_hostpid(string_t *prefix, mode_t mode, uid_t uid, gid_t gid)
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
85 {
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
86 str_printfa(prefix, "%s.%s.", my_hostname, my_pid);
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
87 return safe_mkstemp(prefix, mode, uid, gid);
8669dc1e4036 Added safe_mkstemp().
Timo Sirainen <tss@iki.fi>
parents:
diff changeset
88 }
9168
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
89
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
90 int safe_mkstemp_hostpid_group(string_t *prefix, mode_t mode,
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
91 gid_t gid, const char *gid_origin)
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
92 {
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
93 str_printfa(prefix, "%s.%s.", my_hostname, my_pid);
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
94 return safe_mkstemp_group(prefix, mode, gid, gid_origin);
2bbf175bb6d3 Whenever file's group changing fails, show the group origin in the error message.
Timo Sirainen <tss@iki.fi>
parents: 9001
diff changeset
95 }