su: do not change to home dir unless -l
Signed-off-by: Pascal Bellard <pascal.bellard@ads-lu.com> Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
This commit is contained in:
parent
588e284f53
commit
70fc8c17e2
@ -1286,6 +1286,7 @@ int sd_listen_fds(void);
|
|||||||
#define SETUP_ENV_CHANGEENV (1 << 0)
|
#define SETUP_ENV_CHANGEENV (1 << 0)
|
||||||
#define SETUP_ENV_CLEARENV (1 << 1)
|
#define SETUP_ENV_CLEARENV (1 << 1)
|
||||||
#define SETUP_ENV_TO_TMP (1 << 2)
|
#define SETUP_ENV_TO_TMP (1 << 2)
|
||||||
|
#define SETUP_ENV_NO_CHDIR (1 << 4)
|
||||||
extern void setup_environment(const char *shell, int flags, const struct passwd *pw) FAST_FUNC;
|
extern void setup_environment(const char *shell, int flags, const struct passwd *pw) FAST_FUNC;
|
||||||
extern int correct_password(const struct passwd *pw) FAST_FUNC;
|
extern int correct_password(const struct passwd *pw) FAST_FUNC;
|
||||||
/* Returns a malloced string */
|
/* Returns a malloced string */
|
||||||
|
@ -37,9 +37,11 @@ void FAST_FUNC setup_environment(const char *shell, int flags, const struct pass
|
|||||||
|
|
||||||
/* Change the current working directory to be the home directory
|
/* Change the current working directory to be the home directory
|
||||||
* of the user */
|
* of the user */
|
||||||
if (chdir(pw->pw_dir)) {
|
if (!(flags & SETUP_ENV_NO_CHDIR)) {
|
||||||
|
if (chdir(pw->pw_dir) != 0) {
|
||||||
|
bb_error_msg("can't change directory to '%s'", pw->pw_dir);
|
||||||
xchdir((flags & SETUP_ENV_TO_TMP) ? "/tmp" : "/");
|
xchdir((flags & SETUP_ENV_TO_TMP) ? "/tmp" : "/");
|
||||||
bb_error_msg("can't chdir to home directory '%s'", pw->pw_dir);
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (flags & SETUP_ENV_CLEARENV) {
|
if (flags & SETUP_ENV_CLEARENV) {
|
||||||
|
@ -355,13 +355,13 @@ void FAST_FUNC xsetuid(uid_t uid)
|
|||||||
void FAST_FUNC xchdir(const char *path)
|
void FAST_FUNC xchdir(const char *path)
|
||||||
{
|
{
|
||||||
if (chdir(path))
|
if (chdir(path))
|
||||||
bb_perror_msg_and_die("chdir(%s)", path);
|
bb_perror_msg_and_die("can't change directory to '%s'", path);
|
||||||
}
|
}
|
||||||
|
|
||||||
void FAST_FUNC xchroot(const char *path)
|
void FAST_FUNC xchroot(const char *path)
|
||||||
{
|
{
|
||||||
if (chroot(path))
|
if (chroot(path))
|
||||||
bb_perror_msg_and_die("can't change root directory to %s", path);
|
bb_perror_msg_and_die("can't change root directory to '%s'", path);
|
||||||
xchdir("/");
|
xchdir("/");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
@ -131,7 +131,8 @@ int su_main(int argc UNUSED_PARAM, char **argv)
|
|||||||
change_identity(pw);
|
change_identity(pw);
|
||||||
setup_environment(opt_shell,
|
setup_environment(opt_shell,
|
||||||
((flags & SU_OPT_l) / SU_OPT_l * SETUP_ENV_CLEARENV)
|
((flags & SU_OPT_l) / SU_OPT_l * SETUP_ENV_CLEARENV)
|
||||||
+ (!(flags & SU_OPT_mp) * SETUP_ENV_CHANGEENV),
|
+ (!(flags & SU_OPT_mp) * SETUP_ENV_CHANGEENV)
|
||||||
|
+ (!(flags & SU_OPT_l) * SETUP_ENV_NO_CHDIR),
|
||||||
pw);
|
pw);
|
||||||
IF_SELINUX(set_current_security_context(NULL);)
|
IF_SELINUX(set_current_security_context(NULL);)
|
||||||
|
|
||||||
|
@ -1414,7 +1414,7 @@ static void send_cgi_and_exit(
|
|||||||
if (script != url) { /* paranoia */
|
if (script != url) { /* paranoia */
|
||||||
*script = '\0';
|
*script = '\0';
|
||||||
if (chdir(url + 1) != 0) {
|
if (chdir(url + 1) != 0) {
|
||||||
bb_perror_msg("chdir(%s)", url + 1);
|
bb_perror_msg("can't change directory to '%s'", url + 1);
|
||||||
goto error_execing_cgi;
|
goto error_execing_cgi;
|
||||||
}
|
}
|
||||||
// not needed: *script = '/';
|
// not needed: *script = '/';
|
||||||
|
Loading…
x
Reference in New Issue
Block a user