X-Git-Url: http://www.chiark.greenend.org.uk/ucgi/~ianmdlvl/git?a=blobdiff_plain;f=extras%2Fvolume_id%2Fvol_id.c;h=6961969c13f63e466638398d537058136cb21108;hb=467546b586e9ae29ac168967f5cdaac696cadcfb;hp=6f99c52728f26b4412dd444f60819f780e7267a7;hpb=f054627f500450a7aadeaf8a9930354fb268718e;p=elogind.git diff --git a/extras/volume_id/vol_id.c b/extras/volume_id/vol_id.c index 6f99c5272..6961969c1 100644 --- a/extras/volume_id/vol_id.c +++ b/extras/volume_id/vol_id.c @@ -27,10 +27,10 @@ #include #include #include +#include #include -#include "../../udev_utils.h" -#include "../../logging.h" +#include "../../udev.h" #include "libvolume_id/volume_id.h" #define BLKGETSIZE64 _IOR(0x12,114,size_t) @@ -111,6 +111,8 @@ int main(int argc, char *argv[]) int i; uint64_t size; const char *node = NULL; + uid_t nobody_uid; + gid_t nobody_gid; int rc = 0; logging_init("vol_id"); @@ -147,12 +149,24 @@ int main(int argc, char *argv[]) size = 0; dbg("BLKGETSIZE64=%llu", size); + /* drop all privileges */ + nobody_uid = lookup_user("nobody"); + nobody_gid = lookup_group("nogroup"); + if (nobody_uid > 0 && nobody_gid > 0) { + if (setgroups(0, NULL) != 0 || + setgid(nobody_gid) != 0 || + setuid(nobody_uid) != 0) { + rc = 3; + goto exit; + } + } + if (volume_id_probe_all(vid, 0, size) == 0) goto print; if (print != PRINT_EXPORT) fprintf(stderr, "%s: unknown volume type\n", node); - rc = 3; + rc = 4; goto exit; print: