3 * routines which are different for -DDEBUG
5 * Copyright (C)1996-1997 Ian Jackson
7 * This is free software; you can redistribute it and/or modify it
8 * under the terms of the GNU General Public License as published by
9 * the Free Software Foundation; either version 2 of the License, or
10 * (at your option) any later version.
12 * This program is distributed in the hope that it will be useful, but
13 * WITHOUT ANY WARRANTY; without even the implied warranty of
14 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
15 * General Public License for more details.
17 * You should have received a copy of the GNU General Public License
18 * along with userv; if not, write to the Free Software
19 * Foundation, 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
29 #include <sys/types.h>
39 static const char *sl_ident= "UNSET";
40 static int sl_option=0, sl_facility=0;
42 void openlog(const char *ident, int option, int facility) {
45 sl_facility= facility;
48 void syslog(int priority, const char *fmt, ...) {
50 fprintf(stderr,"syslog: %s<%d.%d>(%d): ",sl_ident,sl_facility,priority,sl_option);
52 vfprintf(stderr,fmt,al);
59 sl_option= sl_facility= 0;
62 static void fdwantdumprwhead(int *donehead, const char *whichstr, const char *rwstr) {
63 if (*donehead) return;
64 printf("fds %s%s%s:",whichstr,rwstr?" ":"",rwstr?rwstr:"");
68 static void fdwantdumprw(const char *whichstr, int whichval,
69 int rw, const char *rwstr) {
73 for (fd=0; fd<fdarrayused; fd++) {
74 if (!(fdarray[fd].wantstate == whichval && fdarray[fd].wantrw == rw)) continue;
75 fdwantdumprwhead(&donehead,whichstr,rwstr);
78 if (restfdwantstate == whichval && restfdwantrw == rw) {
79 fdwantdumprwhead(&donehead,whichstr,rwstr);
80 printf(" %d-",fdarrayused);
82 if (donehead) printf("\n");
85 static void fdwantdump(const char *whichstr, int whichval, const char *rwunspecstr) {
87 fdwantdumprw(whichstr,whichval,tokv_word_read,"read");
88 fdwantdumprw(whichstr,whichval,tokv_word_write,"write");
89 fdwantdumprw(whichstr,whichval,0,rwunspecstr);
91 fdwantdumprw(whichstr,whichval,0,0);
95 static void truefalsedump(const char *whichstr, int val) {
96 printf("%s: %s\n",whichstr,val?"yes":"no");
99 static void groupsdump(int ngids, const gid_t *gids, const char *const *groups) {
102 for (i=0; i<ngids; i++) printf(" %ld(%s)",(long)gids[i],groups[i]);
105 void debug_dumprequest(pid_t mypid) {
108 printf("server pid: %ld\n"
111 "service user: `%s'\n"
113 "service user shell: `%s'\n"
114 "service user dir: `%s'\n"
116 (long)mypid, (long)request_mbuf.clientpid,
117 service, serviceuser, (long)serviceuser_uid,
118 serviceuser_shell, serviceuser_dir);
119 groupsdump(service_ngids,service_gids,service_groups);
121 "calling user: `%s'\n"
123 "calling user shell: `%s'\n"
125 logname, (long)request_mbuf.callinguid,
127 groupsdump(request_mbuf.ngids,calling_gids,calling_groups);
129 "calling cwd: `%s'\n"
132 for (fd=0; fd<fdarrayused; fd++)
133 if (fdarray[fd].iswrite != -1)
134 printf(" %d%s",fd,fdarray[fd].iswrite ? "w" : "r");
135 printf("\n" "arguments:");
136 for (i=0; i<request_mbuf.nargs; i++) printf(" `%s'",argarray[i]);
137 printf("\n" "variables:");
138 for (i=0; i<request_mbuf.nvars; i++)
139 printf(" `%s'=`%s'",defvararray[i][0],defvararray[i][1]);
141 if (getenv("USERVD_SLEEP")) sleep(atoi(getenv("USERVD_SLEEP")));
144 void debug_dumpexecsettings(void) {
145 printf("configuration parsed\n");
146 if (userrcfile) printf("user-rcfile: `%s'\n",userrcfile);
147 else printf("user-rcfile: <none>\n");
148 fdwantdump("required",tokv_word_requirefd,"ERROR");
149 fdwantdump("allowed",tokv_word_allowfd,"either");
150 fdwantdump("ignored",tokv_word_ignorefd,0);
151 fdwantdump("null",tokv_word_nullfd,"both");
152 fdwantdump("rejected",tokv_word_rejectfd,0);
155 case tokv_word_reject: printf("reject"); break;
156 case tokv_word_execute: printf("`%s'",execpath); break;
157 case tokv_word_executefromdirectory: printf("from directory, `%s'",execpath); break;
158 case tokv_word_executefrompath: printf("from path"); break;
162 truefalsedump("set-environment",setenvironment);
163 truefalsedump("suppress-args",suppressargs);
164 truefalsedump("disconnect-hup",disconnecthup);
165 truefalsedump("set-environment",setenvironment);
168 void debug_dumpparameter(const char *parm, char **values) {
169 printf("config parameter `%s':",parm);
170 while (*values) printf(" `%s'",*values++);
174 static int groupsallin(int na, const gid_t *lista,
175 int nb, const gid_t *listb) {
177 for (i=0; i<na; i++) {
178 for (j=0; j<nb && listb[j] != lista[i]; j++);
184 int setgroups(size_t wantsize, const gid_t *wantlist) {
185 /* This is a bit of a hack really. What we want when we're in debug mode is to
186 * have initgroups() be a no-op iff the groups are already set right (so that
187 * we notice if we're trying to change to the wrong user) but to fail if they're
190 * We can't just call initgroups() because it unconditionally calls
191 * setgroups, which always fails for non-root even if the two group
192 * lists are the same. So here we have a faked-up setgroups which
193 * uses getgroups to see what the group list is and `succeeds' if
194 * the actual group list and the desired one have the same set of
195 * groups, and fails with EPERM if the real setgroups would have
196 * added group(s) or otherwise EINVAL if it would have removed some.
198 * The usual magic with dynamic linking makes the libc initgroups(3) call
199 * pick up our setgroups() rather than the real setgroups(2).
204 realsize= getgroups(0,0); if (realsize == -1) return -1;
205 reallist= malloc(sizeof(gid_t)*realsize); if (!reallist) return -1;
206 if (getgroups(realsize,reallist) != realsize)
207 { e= errno; free(reallist); errno= e; return -1; }
208 if (!groupsallin(wantsize,wantlist,realsize,reallist))
209 { free(reallist); errno= EPERM; return -1; }
210 if (!groupsallin(realsize,reallist,wantsize,wantlist))
211 { free(reallist); errno= EINVAL; return -1; }
212 free(reallist); return 0;
215 pid_t nondebug_fork(void) { return 0; }
216 const char *nondebug_serviceuserdir(const char *ifnondebug) { return SERVICEUSERDIR; }
220 void debug_dumprequest(pid_t mypid) { }
221 void debug_dumpexecsettings(void) { }
222 void debug_dumpparameter(const char *parm, char **values) { }
223 pid_t nondebug_fork(void) { return fork(); }
224 const char *nondebug_serviceuserdir(const char *ifnondebug) { return ifnondebug; }