2007-10-07 11:44:02 +00:00
|
|
|
/*
|
2021-12-05 09:35:27 -06:00
|
|
|
* SPDX-FileCopyrightText: 1992 - 1993, Julianne Frances Haugh
|
|
|
|
* SPDX-FileCopyrightText: 1996 - 2000, Marek Michałkiewicz
|
|
|
|
* SPDX-FileCopyrightText: 2003 - 2005, Tomasz Kłoczko
|
|
|
|
* SPDX-FileCopyrightText: 2010 - , Nicolas François
|
2007-10-07 11:44:02 +00:00
|
|
|
*
|
2021-12-05 09:35:27 -06:00
|
|
|
* SPDX-License-Identifier: BSD-3-Clause
|
2007-10-07 11:44:02 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
#include <config.h>
|
|
|
|
|
2007-11-10 23:46:11 +00:00
|
|
|
#ident "$Id$"
|
2007-10-07 11:47:01 +00:00
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
#include <sys/types.h>
|
|
|
|
#include <sys/stat.h>
|
|
|
|
#include "prototypes.h"
|
|
|
|
#include "defines.h"
|
|
|
|
#include <fcntl.h>
|
|
|
|
#include <stdio.h>
|
|
|
|
/*
|
|
|
|
* chown_tree - change ownership of files in a directory tree
|
|
|
|
*
|
|
|
|
* chown_dir() walks a directory tree and changes the ownership
|
|
|
|
* of all files owned by the provided user ID.
|
2010-04-04 20:55:46 +00:00
|
|
|
*
|
|
|
|
* Only files owned (resp. group-owned) by old_uid (resp. by old_gid)
|
|
|
|
* will have their ownership (resp. group-ownership) modified, unless
|
|
|
|
* old_uid (resp. old_gid) is set to -1.
|
|
|
|
*
|
|
|
|
* new_uid and new_gid can be set to -1 to indicate that no owner or
|
|
|
|
* group-owner shall be changed.
|
2007-10-07 11:44:02 +00:00
|
|
|
*/
|
2010-04-04 20:55:46 +00:00
|
|
|
int chown_tree (const char *root,
|
|
|
|
uid_t old_uid,
|
|
|
|
uid_t new_uid,
|
|
|
|
gid_t old_gid,
|
|
|
|
gid_t new_gid)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2010-04-04 20:55:46 +00:00
|
|
|
char *new_name;
|
|
|
|
size_t new_name_len;
|
2007-10-07 11:45:23 +00:00
|
|
|
int rc = 0;
|
2021-12-30 14:13:36 +01:00
|
|
|
struct dirent *ent;
|
2007-10-07 11:45:23 +00:00
|
|
|
struct stat sb;
|
|
|
|
DIR *dir;
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2010-04-04 20:55:46 +00:00
|
|
|
new_name = malloc (1024);
|
|
|
|
if (NULL == new_name) {
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
new_name_len = 1024;
|
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
/*
|
|
|
|
* Make certain the directory exists. This routine is called
|
2010-04-04 20:55:46 +00:00
|
|
|
* directly by the invoker, or recursively.
|
2007-10-07 11:44:02 +00:00
|
|
|
*/
|
|
|
|
|
2010-03-18 18:52:53 +00:00
|
|
|
if (access (root, F_OK) != 0) {
|
* libmisc/limits.c: Avoid implicit conversion of integer to
boolean.
* libmisc/basename.c: Avoid implicit conversion of pointer to
boolean.
* libmisc/basename.c, lib/prototypes.h (Basename): Return a
constant string.
* libmisc/basename.c, libmisc/obscure.c, lib/prototypes.h,
libmisc/xmalloc.c, libmisc/getdate.h, libmisc/system.c,
libmisc/getgr_nam_gid.c, libmisc/failure.c, libmisc/valid.c: Add
splint annotations.
* libmisc/chowndir.c: Avoid memory leak.
* libmisc/chowndir.c: Do not check *printf/*puts return value.
* libmisc/chowntty.c: Avoid implicit conversion between integer
types.
* libmisc/obscure.c: Return a bool when possible instead of int.
* libmisc/shell.c: Do not check *printf/*puts return value.
* libmisc/shell.c: Do not check execle return value.
* libmisc/setupenv.c: Avoid implicit conversion between integer
types.
* libmisc/xmalloc.c: size should not be zero to avoid returning
NULL pointers.
* libmisc/hushed.c: Do not check *printf/*puts return value.
* libmisc/system.c: Avoid implicit conversion of integer to
boolean. safe_system last argument is a boolean.
* libmisc/system.c: Check return value of dup2.
* libmisc/system.c: Do not check *printf/*puts return value.
* libmisc/system.c: Do not check execve return value.
* libmisc/salt.c: Do not check *printf/*puts return value.
* libmisc/loginprompt.c: Do not check gethostname return value.
* libmisc/find_new_gid.c, libmisc/find_new_uid.c: Do not check
gr_rewind/pw_rewind return value.
* libmisc/ttytype.c: Limit the number of parsed characters in the
sscanf format.
* libmisc/ttytype.c: Test if a type was really read.
* libmisc/sub.c: Do not check *printf/*puts return value.
* libmisc/sub.c: Avoid implicit conversion of integer to boolean.
* src/userdel.c: Fix typo in comment.
* src/userdel.c: Avoid implicit conversion of boolean to integer.
* src/userdel.c: safe_system last argument is a boolean.
* src/newusers.c: Avoid implicit conversion of boolean to integer.
* src/newusers.c: Avoid implicit conversion of integer to boolean.
* src/usermod.c: Add brackets.
* src/usermod.c: Avoid implicit conversion of characters or
integers to booleans.
* src/vipw.c: Avoid implicit conversion of integer to boolean.
* src/su.c: Avoid implicit conversion of integer to boolean.
* src/su.c: Add brackets.
* src/useradd.c: Avoid implicit conversion of characters or
integers to booleans.
2010-08-22 19:13:53 +00:00
|
|
|
free (new_name);
|
2007-10-07 11:44:02 +00:00
|
|
|
return -1;
|
2010-03-18 18:52:53 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Open the directory and read each entry. Every entry is tested
|
|
|
|
* to see if it is a directory, and if so this routine is called
|
2010-04-04 20:55:46 +00:00
|
|
|
* recursively. If not, it is checked to see if an ownership
|
|
|
|
* shall be changed.
|
2007-10-07 11:44:02 +00:00
|
|
|
*/
|
|
|
|
|
2010-03-18 18:52:53 +00:00
|
|
|
dir = opendir (root);
|
|
|
|
if (NULL == dir) {
|
* libmisc/limits.c: Avoid implicit conversion of integer to
boolean.
* libmisc/basename.c: Avoid implicit conversion of pointer to
boolean.
* libmisc/basename.c, lib/prototypes.h (Basename): Return a
constant string.
* libmisc/basename.c, libmisc/obscure.c, lib/prototypes.h,
libmisc/xmalloc.c, libmisc/getdate.h, libmisc/system.c,
libmisc/getgr_nam_gid.c, libmisc/failure.c, libmisc/valid.c: Add
splint annotations.
* libmisc/chowndir.c: Avoid memory leak.
* libmisc/chowndir.c: Do not check *printf/*puts return value.
* libmisc/chowntty.c: Avoid implicit conversion between integer
types.
* libmisc/obscure.c: Return a bool when possible instead of int.
* libmisc/shell.c: Do not check *printf/*puts return value.
* libmisc/shell.c: Do not check execle return value.
* libmisc/setupenv.c: Avoid implicit conversion between integer
types.
* libmisc/xmalloc.c: size should not be zero to avoid returning
NULL pointers.
* libmisc/hushed.c: Do not check *printf/*puts return value.
* libmisc/system.c: Avoid implicit conversion of integer to
boolean. safe_system last argument is a boolean.
* libmisc/system.c: Check return value of dup2.
* libmisc/system.c: Do not check *printf/*puts return value.
* libmisc/system.c: Do not check execve return value.
* libmisc/salt.c: Do not check *printf/*puts return value.
* libmisc/loginprompt.c: Do not check gethostname return value.
* libmisc/find_new_gid.c, libmisc/find_new_uid.c: Do not check
gr_rewind/pw_rewind return value.
* libmisc/ttytype.c: Limit the number of parsed characters in the
sscanf format.
* libmisc/ttytype.c: Test if a type was really read.
* libmisc/sub.c: Do not check *printf/*puts return value.
* libmisc/sub.c: Avoid implicit conversion of integer to boolean.
* src/userdel.c: Fix typo in comment.
* src/userdel.c: Avoid implicit conversion of boolean to integer.
* src/userdel.c: safe_system last argument is a boolean.
* src/newusers.c: Avoid implicit conversion of boolean to integer.
* src/newusers.c: Avoid implicit conversion of integer to boolean.
* src/usermod.c: Add brackets.
* src/usermod.c: Avoid implicit conversion of characters or
integers to booleans.
* src/vipw.c: Avoid implicit conversion of integer to boolean.
* src/su.c: Avoid implicit conversion of integer to boolean.
* src/su.c: Add brackets.
* src/useradd.c: Avoid implicit conversion of characters or
integers to booleans.
2010-08-22 19:13:53 +00:00
|
|
|
free (new_name);
|
2007-10-07 11:44:02 +00:00
|
|
|
return -1;
|
2010-03-18 18:52:53 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
while ((ent = readdir (dir))) {
|
2010-09-05 15:34:42 +00:00
|
|
|
size_t ent_name_len;
|
2010-04-04 20:55:46 +00:00
|
|
|
uid_t tmpuid = (uid_t) -1;
|
|
|
|
gid_t tmpgid = (gid_t) -1;
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Skip the "." and ".." entries
|
|
|
|
*/
|
|
|
|
|
2010-03-18 18:52:53 +00:00
|
|
|
if ( (strcmp (ent->d_name, ".") == 0)
|
|
|
|
|| (strcmp (ent->d_name, "..") == 0)) {
|
2007-10-07 11:44:02 +00:00
|
|
|
continue;
|
2010-03-18 18:52:53 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Make the filename for both the source and the
|
|
|
|
* destination files.
|
|
|
|
*/
|
|
|
|
|
2010-09-05 15:34:42 +00:00
|
|
|
ent_name_len = strlen (root) + strlen (ent->d_name) + 2;
|
|
|
|
if (ent_name_len > new_name_len) {
|
2011-08-14 14:00:14 +00:00
|
|
|
/*@only@*/char *tmp = realloc (new_name, ent_name_len);
|
2010-09-05 15:34:42 +00:00
|
|
|
if (NULL == tmp) {
|
2010-04-04 20:55:46 +00:00
|
|
|
rc = -1;
|
|
|
|
break;
|
|
|
|
}
|
2010-09-05 15:34:42 +00:00
|
|
|
new_name = tmp;
|
|
|
|
new_name_len = ent_name_len;
|
2010-03-18 18:52:53 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
* libmisc/limits.c: Avoid implicit conversion of integer to
boolean.
* libmisc/basename.c: Avoid implicit conversion of pointer to
boolean.
* libmisc/basename.c, lib/prototypes.h (Basename): Return a
constant string.
* libmisc/basename.c, libmisc/obscure.c, lib/prototypes.h,
libmisc/xmalloc.c, libmisc/getdate.h, libmisc/system.c,
libmisc/getgr_nam_gid.c, libmisc/failure.c, libmisc/valid.c: Add
splint annotations.
* libmisc/chowndir.c: Avoid memory leak.
* libmisc/chowndir.c: Do not check *printf/*puts return value.
* libmisc/chowntty.c: Avoid implicit conversion between integer
types.
* libmisc/obscure.c: Return a bool when possible instead of int.
* libmisc/shell.c: Do not check *printf/*puts return value.
* libmisc/shell.c: Do not check execle return value.
* libmisc/setupenv.c: Avoid implicit conversion between integer
types.
* libmisc/xmalloc.c: size should not be zero to avoid returning
NULL pointers.
* libmisc/hushed.c: Do not check *printf/*puts return value.
* libmisc/system.c: Avoid implicit conversion of integer to
boolean. safe_system last argument is a boolean.
* libmisc/system.c: Check return value of dup2.
* libmisc/system.c: Do not check *printf/*puts return value.
* libmisc/system.c: Do not check execve return value.
* libmisc/salt.c: Do not check *printf/*puts return value.
* libmisc/loginprompt.c: Do not check gethostname return value.
* libmisc/find_new_gid.c, libmisc/find_new_uid.c: Do not check
gr_rewind/pw_rewind return value.
* libmisc/ttytype.c: Limit the number of parsed characters in the
sscanf format.
* libmisc/ttytype.c: Test if a type was really read.
* libmisc/sub.c: Do not check *printf/*puts return value.
* libmisc/sub.c: Avoid implicit conversion of integer to boolean.
* src/userdel.c: Fix typo in comment.
* src/userdel.c: Avoid implicit conversion of boolean to integer.
* src/userdel.c: safe_system last argument is a boolean.
* src/newusers.c: Avoid implicit conversion of boolean to integer.
* src/newusers.c: Avoid implicit conversion of integer to boolean.
* src/usermod.c: Add brackets.
* src/usermod.c: Avoid implicit conversion of characters or
integers to booleans.
* src/vipw.c: Avoid implicit conversion of integer to boolean.
* src/su.c: Avoid implicit conversion of integer to boolean.
* src/su.c: Add brackets.
* src/useradd.c: Avoid implicit conversion of characters or
integers to booleans.
2010-08-22 19:13:53 +00:00
|
|
|
(void) snprintf (new_name, new_name_len, "%s/%s", root, ent->d_name);
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2007-10-07 11:44:14 +00:00
|
|
|
/* Don't follow symbolic links! */
|
2010-03-18 18:52:53 +00:00
|
|
|
if (LSTAT (new_name, &sb) == -1) {
|
2007-10-07 11:44:02 +00:00
|
|
|
continue;
|
2010-03-18 18:52:53 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2007-10-07 11:45:23 +00:00
|
|
|
if (S_ISDIR (sb.st_mode) && !S_ISLNK (sb.st_mode)) {
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Do the entire subdirectory.
|
|
|
|
*/
|
|
|
|
|
2008-05-25 21:23:28 +00:00
|
|
|
rc = chown_tree (new_name, old_uid, new_uid,
|
|
|
|
old_gid, new_gid);
|
|
|
|
if (0 != rc) {
|
2007-10-07 11:44:02 +00:00
|
|
|
break;
|
2008-05-25 21:23:28 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2007-10-07 11:44:14 +00:00
|
|
|
#ifndef HAVE_LCHOWN
|
|
|
|
/* don't use chown (follows symbolic links!) */
|
2010-03-18 18:52:53 +00:00
|
|
|
if (S_ISLNK (sb.st_mode)) {
|
2007-10-07 11:44:14 +00:00
|
|
|
continue;
|
2010-03-18 18:52:53 +00:00
|
|
|
}
|
2007-10-07 11:44:14 +00:00
|
|
|
#endif
|
2010-04-04 20:55:46 +00:00
|
|
|
/*
|
|
|
|
* By default, the IDs are not changed (-1).
|
|
|
|
*
|
|
|
|
* If the file is not owned by the user, the owner is not
|
|
|
|
* changed.
|
|
|
|
*
|
|
|
|
* If the file is not group-owned by the group, the
|
|
|
|
* group-owner is not changed.
|
|
|
|
*/
|
|
|
|
if (((uid_t) -1 == old_uid) || (sb.st_uid == old_uid)) {
|
|
|
|
tmpuid = new_uid;
|
|
|
|
}
|
|
|
|
if (((gid_t) -1 == old_gid) || (sb.st_gid == old_gid)) {
|
|
|
|
tmpgid = new_gid;
|
|
|
|
}
|
|
|
|
if (((uid_t) -1 != tmpuid) || ((gid_t) -1 != tmpgid)) {
|
|
|
|
rc = LCHOWN (new_name, tmpuid, tmpgid);
|
|
|
|
if (0 != rc) {
|
|
|
|
break;
|
|
|
|
}
|
2010-03-18 18:52:53 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2010-04-04 20:55:46 +00:00
|
|
|
|
|
|
|
free (new_name);
|
2008-05-25 21:23:28 +00:00
|
|
|
(void) closedir (dir);
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Now do the root of the tree
|
|
|
|
*/
|
|
|
|
|
2010-04-04 20:55:46 +00:00
|
|
|
if ((0 == rc) && (stat (root, &sb) == 0)) {
|
|
|
|
uid_t tmpuid = (uid_t) -1;
|
|
|
|
gid_t tmpgid = (gid_t) -1;
|
|
|
|
if (((uid_t) -1 == old_uid) || (sb.st_uid == old_uid)) {
|
|
|
|
tmpuid = new_uid;
|
|
|
|
}
|
|
|
|
if (((gid_t) -1 == old_gid) || (sb.st_gid == old_gid)) {
|
|
|
|
tmpgid = new_gid;
|
2008-05-25 21:23:28 +00:00
|
|
|
}
|
2010-04-04 20:55:46 +00:00
|
|
|
if (((uid_t) -1 != tmpuid) || ((gid_t) -1 != tmpgid)) {
|
|
|
|
rc = LCHOWN (root, tmpuid, tmpgid);
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
rc = -1;
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2010-04-04 20:55:46 +00:00
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
return rc;
|
|
|
|
}
|
2008-05-25 21:23:28 +00:00
|
|
|
|