su: do not change to home dir unless -l

Signed-off-by: Pascal Bellard <pascal.bellard@ads-lu.com>
Signed-off-by: Denys Vlasenko <vda.linux@googlemail.com>
This commit is contained in:
Pascal Bellard 2012-06-12 13:21:02 +02:00 committed by Denys Vlasenko
parent 588e284f53
commit 70fc8c17e2
5 changed files with 11 additions and 7 deletions

View File

@ -1286,6 +1286,7 @@ int sd_listen_fds(void);
#define SETUP_ENV_CHANGEENV (1 << 0) #define SETUP_ENV_CHANGEENV (1 << 0)
#define SETUP_ENV_CLEARENV (1 << 1) #define SETUP_ENV_CLEARENV (1 << 1)
#define SETUP_ENV_TO_TMP (1 << 2) #define SETUP_ENV_TO_TMP (1 << 2)
#define SETUP_ENV_NO_CHDIR (1 << 4)
extern void setup_environment(const char *shell, int flags, const struct passwd *pw) FAST_FUNC; extern void setup_environment(const char *shell, int flags, const struct passwd *pw) FAST_FUNC;
extern int correct_password(const struct passwd *pw) FAST_FUNC; extern int correct_password(const struct passwd *pw) FAST_FUNC;
/* Returns a malloced string */ /* Returns a malloced string */

View File

@ -37,9 +37,11 @@ void FAST_FUNC setup_environment(const char *shell, int flags, const struct pass
/* Change the current working directory to be the home directory /* Change the current working directory to be the home directory
* of the user */ * of the user */
if (chdir(pw->pw_dir)) { if (!(flags & SETUP_ENV_NO_CHDIR)) {
if (chdir(pw->pw_dir) != 0) {
bb_error_msg("can't change directory to '%s'", pw->pw_dir);
xchdir((flags & SETUP_ENV_TO_TMP) ? "/tmp" : "/"); xchdir((flags & SETUP_ENV_TO_TMP) ? "/tmp" : "/");
bb_error_msg("can't chdir to home directory '%s'", pw->pw_dir); }
} }
if (flags & SETUP_ENV_CLEARENV) { if (flags & SETUP_ENV_CLEARENV) {

View File

@ -355,13 +355,13 @@ void FAST_FUNC xsetuid(uid_t uid)
void FAST_FUNC xchdir(const char *path) void FAST_FUNC xchdir(const char *path)
{ {
if (chdir(path)) if (chdir(path))
bb_perror_msg_and_die("chdir(%s)", path); bb_perror_msg_and_die("can't change directory to '%s'", path);
} }
void FAST_FUNC xchroot(const char *path) void FAST_FUNC xchroot(const char *path)
{ {
if (chroot(path)) if (chroot(path))
bb_perror_msg_and_die("can't change root directory to %s", path); bb_perror_msg_and_die("can't change root directory to '%s'", path);
xchdir("/"); xchdir("/");
} }

View File

@ -131,7 +131,8 @@ int su_main(int argc UNUSED_PARAM, char **argv)
change_identity(pw); change_identity(pw);
setup_environment(opt_shell, setup_environment(opt_shell,
((flags & SU_OPT_l) / SU_OPT_l * SETUP_ENV_CLEARENV) ((flags & SU_OPT_l) / SU_OPT_l * SETUP_ENV_CLEARENV)
+ (!(flags & SU_OPT_mp) * SETUP_ENV_CHANGEENV), + (!(flags & SU_OPT_mp) * SETUP_ENV_CHANGEENV)
+ (!(flags & SU_OPT_l) * SETUP_ENV_NO_CHDIR),
pw); pw);
IF_SELINUX(set_current_security_context(NULL);) IF_SELINUX(set_current_security_context(NULL);)

View File

@ -1414,7 +1414,7 @@ static void send_cgi_and_exit(
if (script != url) { /* paranoia */ if (script != url) { /* paranoia */
*script = '\0'; *script = '\0';
if (chdir(url + 1) != 0) { if (chdir(url + 1) != 0) {
bb_perror_msg("chdir(%s)", url + 1); bb_perror_msg("can't change directory to '%s'", url + 1);
goto error_execing_cgi; goto error_execing_cgi;
} }
// not needed: *script = '/'; // not needed: *script = '/';