blob: 1685018111d309ae1d430b5452940b5b3b25d686 [file] [log] [blame]
Eric Andersenaad1a882001-03-16 22:47:14 +00001/* vi: set sw=4 ts=4: */
2/*
3 * Utility routines.
4 *
5 * Copyright (C) tons of folks. Tracking down who wrote what
6 * isn't something I'm going to worry about... If you wrote something
7 * here, please feel free to acknowledge your work.
8 *
9 * This program is free software; you can redistribute it and/or modify
10 * it under the terms of the GNU General Public License as published by
11 * the Free Software Foundation; either version 2 of the License, or
12 * (at your option) any later version.
13 *
14 * This program is distributed in the hope that it will be useful,
15 * but WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
17 * General Public License for more details.
18 *
19 * You should have received a copy of the GNU General Public License
20 * along with this program; if not, write to the Free Software
21 * Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
22 *
23 * Based in part on code from sash, Copyright (c) 1999 by David I. Bell
24 * Permission has been granted to redistribute this code under the GPL.
25 *
26 */
27
Robert Grieblc9aca452002-06-04 20:06:25 +000028#include <unistd.h>
Eric Andersenaad1a882001-03-16 22:47:14 +000029#include <stdio.h>
30#include <stdlib.h>
Eric Andersen08ff8a42001-03-23 17:02:05 +000031#include <string.h>
Eric Andersenaad1a882001-03-16 22:47:14 +000032#include "busybox.h"
33
Eric Andersen2ccfef22001-03-19 19:30:24 +000034#undef APPLET
35#undef APPLET_NOUSAGE
36#undef PROTOTYPES
37#include "applets.h"
38
Eric Andersenaad1a882001-03-16 22:47:14 +000039struct BB_applet *applet_using;
40
Eric Andersen2ccfef22001-03-19 19:30:24 +000041/* The -1 arises because of the {0,NULL,0,-1} entry above. */
42const size_t NUM_APPLETS = (sizeof (applets) / sizeof (struct BB_applet) - 1);
43
Robert Grieblc9aca452002-06-04 20:06:25 +000044
45#ifdef CONFIG_FEATURE_SUID
46
47static void check_suid ( struct BB_applet *app );
48
49#ifdef CONFIG_FEATURE_SUID_CONFIG
50
51#include <sys/stat.h>
52#include <ctype.h>
Eric Andersen887ca792002-07-03 23:19:26 +000053#include "pwd_.h"
54#include "grp_.h"
Robert Grieblc9aca452002-06-04 20:06:25 +000055
Robert Griebl0c789a42002-06-06 17:30:16 +000056static int parse_config_file ( void );
57
58static int config_ok;
Robert Grieblc9aca452002-06-04 20:06:25 +000059
60#define CONFIG_FILE "/etc/busybox.conf"
61
Glenn L McGrathb37367a2002-08-22 13:12:40 +000062/* applets [] is const, so we have to define this "override" structure */
Robert Grieblc9aca452002-06-04 20:06:25 +000063struct BB_suid_config {
64 struct BB_applet *m_applet;
65
66 uid_t m_uid;
67 gid_t m_gid;
68 mode_t m_mode;
Glenn L McGrathb37367a2002-08-22 13:12:40 +000069
Robert Grieblc9aca452002-06-04 20:06:25 +000070 struct BB_suid_config *m_next;
71};
72
73static struct BB_suid_config *suid_config;
74
Glenn L McGrathb37367a2002-08-22 13:12:40 +000075#endif /* CONFIG_FEATURE_SUID_CONFIG */
Robert Grieblc9aca452002-06-04 20:06:25 +000076
Glenn L McGrathb37367a2002-08-22 13:12:40 +000077#endif /* CONFIG_FEATURE_SUID */
Robert Grieblc9aca452002-06-04 20:06:25 +000078
79
80
Eric Andersenaad1a882001-03-16 22:47:14 +000081extern void show_usage(void)
82{
83 const char *format_string;
84 const char *usage_string = usage_messages;
85 int i;
Eric Andersenaad1a882001-03-16 22:47:14 +000086
87 for (i = applet_using - applets; i > 0; ) {
88 if (!*usage_string++) {
89 --i;
90 }
91 }
92 format_string = "%s\n\nUsage: %s %s\n\n";
Eric Andersenc38678d2002-09-16 06:22:25 +000093 if(*usage_string == '\b')
Eric Andersenaad1a882001-03-16 22:47:14 +000094 format_string = "%s\n\nNo help available.\n\n";
95 fprintf(stderr, format_string,
96 full_version, applet_using->name, usage_string);
97 exit(EXIT_FAILURE);
98}
99
100static int applet_name_compare(const void *x, const void *y)
101{
102 const char *name = x;
103 const struct BB_applet *applet = y;
104
105 return strcmp(name, applet->name);
106}
107
Eric Andersen15576262001-06-24 06:09:14 +0000108extern const size_t NUM_APPLETS;
Eric Andersenaad1a882001-03-16 22:47:14 +0000109
110struct BB_applet *find_applet_by_name(const char *name)
111{
112 return bsearch(name, applets, NUM_APPLETS, sizeof(struct BB_applet),
113 applet_name_compare);
114}
115
116void run_applet_by_name(const char *name, int argc, char **argv)
117{
Mark Whitleybd4b6212001-06-15 16:54:25 +0000118 static int recurse_level = 0;
Matt Kraaiab3d8392001-08-27 17:19:38 +0000119 extern int been_there_done_that; /* From busybox.c */
Mark Whitleybd4b6212001-06-15 16:54:25 +0000120
Robert Grieblc9aca452002-06-04 20:06:25 +0000121#ifdef CONFIG_FEATURE_SUID_CONFIG
122 if ( recurse_level == 0 )
Robert Griebl0c789a42002-06-06 17:30:16 +0000123 config_ok = parse_config_file ( );
Robert Grieblc9aca452002-06-04 20:06:25 +0000124#endif
125
Mark Whitleybd4b6212001-06-15 16:54:25 +0000126 recurse_level++;
Eric Andersenaad1a882001-03-16 22:47:14 +0000127 /* Do a binary search to find the applet entry given the name. */
128 if ((applet_using = find_applet_by_name(name)) != NULL) {
129 applet_name = applet_using->name;
Mark Whitleybd4b6212001-06-15 16:54:25 +0000130 if (argv[1] && strcmp(argv[1], "--help") == 0) {
Matt Kraaiab3d8392001-08-27 17:19:38 +0000131 if (strcmp(applet_using->name, "busybox")==0) {
132 if(argv[2])
133 applet_using = find_applet_by_name(argv[2]);
134 else
135 applet_using = NULL;
136 }
137 if(applet_using)
138 show_usage();
139 been_there_done_that=1;
140 busybox_main(0, NULL);
Mark Whitleybd4b6212001-06-15 16:54:25 +0000141 }
Robert Grieblc9aca452002-06-04 20:06:25 +0000142#ifdef CONFIG_FEATURE_SUID
143 check_suid ( applet_using );
144#endif
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000145
Eric Andersenaad1a882001-03-16 22:47:14 +0000146 exit((*(applet_using->main)) (argc, argv));
147 }
Mark Whitleybd4b6212001-06-15 16:54:25 +0000148 /* Just in case they have renamed busybox - Check argv[1] */
149 if (recurse_level == 1) {
150 run_applet_by_name("busybox", argc, argv);
151 }
Matt Kraai861e6242001-08-27 15:08:57 +0000152 recurse_level--;
Eric Andersenaad1a882001-03-16 22:47:14 +0000153}
154
155
Robert Grieblc9aca452002-06-04 20:06:25 +0000156#ifdef CONFIG_FEATURE_SUID
157
158#ifdef CONFIG_FEATURE_SUID_CONFIG
159
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000160/* check if u is member of group g */
Robert Grieblc9aca452002-06-04 20:06:25 +0000161static int ingroup ( uid_t u, gid_t g )
162{
163 struct group *grp = getgrgid ( g );
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000164
Robert Grieblc9aca452002-06-04 20:06:25 +0000165 if ( grp ) {
166 char **mem;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000167
Robert Grieblc9aca452002-06-04 20:06:25 +0000168 for ( mem = grp-> gr_mem; *mem; mem++ ) {
169 struct passwd *pwd = getpwnam ( *mem );
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000170
Robert Grieblc9aca452002-06-04 20:06:25 +0000171 if ( pwd && ( pwd-> pw_uid == u ))
172 return 1;
173 }
174 }
175 return 0;
176}
177
178#endif
179
180
181void check_suid ( struct BB_applet *applet )
182{
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000183 uid_t ruid = getuid ( ); /* real [ug]id */
Robert Grieblc9aca452002-06-04 20:06:25 +0000184 uid_t rgid = getgid ( );
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000185
Robert Grieblc9aca452002-06-04 20:06:25 +0000186#ifdef CONFIG_FEATURE_SUID_CONFIG
Robert Griebl0c789a42002-06-06 17:30:16 +0000187 if ( config_ok ) {
188 struct BB_suid_config *sct;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000189
Robert Griebl0c789a42002-06-06 17:30:16 +0000190 for ( sct = suid_config; sct; sct = sct-> m_next ) {
191 if ( sct-> m_applet == applet )
192 break;
193 }
194 if ( sct ) {
195 mode_t m = sct-> m_mode;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000196
197 if ( sct-> m_uid == ruid ) /* same uid */
Robert Griebl0c789a42002-06-06 17:30:16 +0000198 m >>= 6;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000199 else if (( sct-> m_gid == rgid ) || ingroup ( ruid, sct-> m_gid )) /* same group / in group */
Robert Griebl0c789a42002-06-06 17:30:16 +0000200 m >>= 3;
201
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000202 if (!( m & S_IXOTH )) /* is x bit not set ? */
Robert Griebl0c789a42002-06-06 17:30:16 +0000203 error_msg_and_die ( "You have no permission to run this applet!" );
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000204
205 if (( sct-> m_mode & ( S_ISGID | S_IXGRP )) == ( S_ISGID | S_IXGRP )) { /* *both* have to be set for sgid */
Robert Griebl0c789a42002-06-06 17:30:16 +0000206 if ( setegid ( sct-> m_gid ))
207 error_msg_and_die ( "BusyBox binary has insufficient rights to set proper GID for applet!" );
208 }
209 else
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000210 setgid ( rgid ); /* no sgid -> drop */
211
Robert Griebl0c789a42002-06-06 17:30:16 +0000212 if ( sct-> m_mode & S_ISUID ) {
213 if ( seteuid ( sct-> m_uid ))
214 error_msg_and_die ( "BusyBox binary has insufficient rights to set proper UID for applet!" );
215 }
216 else
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000217 setuid ( ruid ); /* no suid -> drop */
Robert Griebl0c789a42002-06-06 17:30:16 +0000218 }
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000219 else { /* default: drop all priviledges */
Robert Griebl0c789a42002-06-06 17:30:16 +0000220 setgid ( rgid );
221 setuid ( ruid );
222 }
223 return;
Robert Grieblc9aca452002-06-04 20:06:25 +0000224 }
Robert Griebl0c789a42002-06-06 17:30:16 +0000225 else {
Robert Griebl88947dd2002-07-18 23:59:17 +0000226#ifndef CONFIG_FEATURE_SUID_CONFIG_QUIET
Robert Griebl0c789a42002-06-06 17:30:16 +0000227 static int onetime = 0;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000228
Robert Griebl0c789a42002-06-06 17:30:16 +0000229 if ( !onetime ) {
230 onetime = 1;
231 fprintf ( stderr, "Using fallback suid method\n" );
232 }
Robert Griebl88947dd2002-07-18 23:59:17 +0000233#endif
Robert Grieblc9aca452002-06-04 20:06:25 +0000234 }
Robert Griebl0c789a42002-06-06 17:30:16 +0000235#endif
Robert Grieblc9aca452002-06-04 20:06:25 +0000236
237 if ( applet-> need_suid == _BB_SUID_ALWAYS ) {
238 if ( geteuid ( ) != 0 )
239 error_msg_and_die ( "This applet requires root priviledges!" );
240 }
241 else if ( applet-> need_suid == _BB_SUID_NEVER ) {
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000242 setgid ( rgid ); /* drop all priviledges */
Robert Grieblc9aca452002-06-04 20:06:25 +0000243 setuid ( ruid );
244 }
Robert Grieblc9aca452002-06-04 20:06:25 +0000245}
246
247#ifdef CONFIG_FEATURE_SUID_CONFIG
248
Robert Grieblc9aca452002-06-04 20:06:25 +0000249
Robert Griebl0c789a42002-06-06 17:30:16 +0000250#define parse_error(x) { err=x; goto pe_label; }
Robert Grieblc9aca452002-06-04 20:06:25 +0000251
252
Robert Griebl0c789a42002-06-06 17:30:16 +0000253int parse_config_file ( void )
Robert Grieblc9aca452002-06-04 20:06:25 +0000254{
255 struct stat st;
Robert Griebl0c789a42002-06-06 17:30:16 +0000256 char *err = 0;
257 FILE *f = 0;
258 int lc = 0;
Robert Grieblc9aca452002-06-04 20:06:25 +0000259
260 suid_config = 0;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000261
262 /* is there a config file ? */
Robert Grieblc9aca452002-06-04 20:06:25 +0000263 if ( stat ( CONFIG_FILE, &st ) == 0 ) {
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000264 /* is it owned by root with no write perm. for group and others ? */
Robert Grieblc9aca452002-06-04 20:06:25 +0000265 if ( S_ISREG( st. st_mode ) && ( st. st_uid == 0 ) && (!( st. st_mode & ( S_IWGRP | S_IWOTH )))) {
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000266 /* that's ok .. then try to open it */
Robert Griebl0c789a42002-06-06 17:30:16 +0000267 f = fopen ( CONFIG_FILE, "r" );
Robert Grieblc9aca452002-06-04 20:06:25 +0000268
269 if ( f ) {
Robert Griebl0c789a42002-06-06 17:30:16 +0000270 char buffer [256];
Robert Grieblc9aca452002-06-04 20:06:25 +0000271 int section = 0;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000272
Robert Grieblc9aca452002-06-04 20:06:25 +0000273 while ( fgets ( buffer, sizeof( buffer ) - 1, f )) {
274 char c = buffer [0];
275 char *p;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000276
Robert Grieblc9aca452002-06-04 20:06:25 +0000277 lc++;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000278
Robert Grieblc9aca452002-06-04 20:06:25 +0000279 p = strchr ( buffer, '#' );
280 if ( p )
281 *p = 0;
282 p = buffer + xstrlen ( buffer );
283 while (( p > buffer ) && isspace ( *--p ))
284 *p = 0;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000285
Robert Grieblc9aca452002-06-04 20:06:25 +0000286 if ( p == buffer )
287 continue;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000288
Robert Grieblc9aca452002-06-04 20:06:25 +0000289 if ( c == '[' ) {
290 p = strchr ( buffer, ']' );
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000291
292 if ( !p || ( p == ( buffer + 1 ))) /* no matching ] or empty [] */
Robert Griebl0c789a42002-06-06 17:30:16 +0000293 parse_error ( "malformed section header" );
Robert Grieblc9aca452002-06-04 20:06:25 +0000294
295 *p = 0;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000296
Robert Grieblc9aca452002-06-04 20:06:25 +0000297 if ( strcasecmp ( buffer + 1, "SUID" ) == 0 )
298 section = 1;
299 else
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000300 section = -1; /* unknown section - just skip */
Robert Grieblc9aca452002-06-04 20:06:25 +0000301 }
302 else if ( section ) {
303 switch ( section ) {
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000304 case 1: { /* SUID */
Robert Grieblc9aca452002-06-04 20:06:25 +0000305 int l;
306 struct BB_applet *applet;
307
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000308 p = strchr ( buffer, '=' ); /* <key>[::space::]*=[::space::]*<value> */
309
310 if ( !p || ( p == ( buffer + 1 ))) /* no = or key is empty */
Robert Griebl0c789a42002-06-06 17:30:16 +0000311 parse_error ( "malformed keyword" );
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000312
Robert Grieblc9aca452002-06-04 20:06:25 +0000313 l = p - buffer;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000314 while ( isspace ( buffer [--l] )) { } /* skip whitespace */
315
Robert Grieblc9aca452002-06-04 20:06:25 +0000316 buffer [l+1] = 0;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000317
Robert Grieblc9aca452002-06-04 20:06:25 +0000318 if (( applet = find_applet_by_name ( buffer ))) {
319 struct BB_suid_config *sct = xmalloc ( sizeof( struct BB_suid_config ));
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000320
Robert Grieblc9aca452002-06-04 20:06:25 +0000321 sct-> m_applet = applet;
322 sct-> m_next = suid_config;
323 suid_config = sct;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000324
325 while ( isspace ( *++p )) { } /* skip whitespace */
326
Robert Grieblc9aca452002-06-04 20:06:25 +0000327 sct-> m_mode = 0;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000328
Robert Grieblc9aca452002-06-04 20:06:25 +0000329 switch ( *p++ ) {
330 case 'S': sct-> m_mode |= S_ISUID; break;
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000331 case 's': sct-> m_mode |= S_ISUID; /* no break */
Robert Grieblc9aca452002-06-04 20:06:25 +0000332 case 'x': sct-> m_mode |= S_IXUSR; break;
333 case '-': break;
Robert Griebl0c789a42002-06-06 17:30:16 +0000334 default : parse_error ( "invalid user mode" );
Robert Grieblc9aca452002-06-04 20:06:25 +0000335 }
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000336
Robert Grieblc9aca452002-06-04 20:06:25 +0000337 switch ( *p++ ) {
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000338 case 's': sct-> m_mode |= S_ISGID; /* no break */
Robert Grieblc9aca452002-06-04 20:06:25 +0000339 case 'x': sct-> m_mode |= S_IXGRP; break;
340 case 'S': break;
341 case '-': break;
Robert Griebl0c789a42002-06-06 17:30:16 +0000342 default : parse_error ( "invalid group mode" );
Robert Grieblc9aca452002-06-04 20:06:25 +0000343 }
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000344
Robert Grieblc9aca452002-06-04 20:06:25 +0000345 switch ( *p ) {
346 case 't':
347 case 'x': sct-> m_mode |= S_IXOTH; break;
348 case 'T':
349 case '-': break;
Robert Griebl0c789a42002-06-06 17:30:16 +0000350 default : parse_error ( "invalid other mode" );
Robert Grieblc9aca452002-06-04 20:06:25 +0000351 }
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000352
353 while ( isspace ( *++p )) { } /* skip whitespace */
354
Robert Grieblc9aca452002-06-04 20:06:25 +0000355 if ( isdigit ( *p )) {
356 sct-> m_uid = strtol ( p, &p, 10 );
357 if ( *p++ != '.' )
Robert Griebl0c789a42002-06-06 17:30:16 +0000358 parse_error ( "parsing <uid>.<gid>" );
Robert Grieblc9aca452002-06-04 20:06:25 +0000359 }
360 else {
361 struct passwd *pwd;
362 char *p2 = strchr ( p, '.' );
363
364 if ( !p2 )
Robert Griebl0c789a42002-06-06 17:30:16 +0000365 parse_error ( "parsing <uid>.<gid>" );
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000366
Robert Grieblc9aca452002-06-04 20:06:25 +0000367 *p2 = 0;
368 pwd = getpwnam ( p );
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000369
Robert Grieblc9aca452002-06-04 20:06:25 +0000370 if ( !pwd )
Robert Griebl0c789a42002-06-06 17:30:16 +0000371 parse_error ( "invalid user name" );
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000372
Robert Grieblc9aca452002-06-04 20:06:25 +0000373 sct-> m_uid = pwd-> pw_uid;
374 p = p2 + 1;
375 }
376 if ( isdigit ( *p ))
377 sct-> m_gid = strtol ( p, &p, 10 );
378 else {
379 struct group *grp = getgrnam ( p );
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000380
Robert Grieblc9aca452002-06-04 20:06:25 +0000381 if ( !grp )
Robert Griebl0c789a42002-06-06 17:30:16 +0000382 parse_error ( "invalid group name" );
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000383
Robert Grieblc9aca452002-06-04 20:06:25 +0000384 sct-> m_gid = grp-> gr_gid;
385 }
386 }
387 break;
388 }
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000389 default: /* unknown - skip */
Robert Grieblc9aca452002-06-04 20:06:25 +0000390 break;
391 }
392 }
393 else
Robert Griebl0c789a42002-06-06 17:30:16 +0000394 parse_error ( "keyword not within section" );
Robert Grieblc9aca452002-06-04 20:06:25 +0000395 }
396 fclose ( f );
Robert Grieble4f9f3a2002-07-16 21:53:59 +0000397 return 1;
Robert Grieblc9aca452002-06-04 20:06:25 +0000398 }
399 }
400 }
Glenn L McGrathb37367a2002-08-22 13:12:40 +0000401 return 0; /* no config file or not readable (not an error) */
402
Robert Griebl0c789a42002-06-06 17:30:16 +0000403pe_label:
404 fprintf ( stderr, "Parse error in %s, line %d: %s\n", CONFIG_FILE, lc, err );
405
406 if ( f )
407 fclose ( f );
408 return 0;
Robert Grieblc9aca452002-06-04 20:06:25 +0000409}
410
411#endif
412
413#endif
414
Eric Andersenaad1a882001-03-16 22:47:14 +0000415/* END CODE */
416/*
417Local Variables:
418c-file-style: "linux"
419c-basic-offset: 4
420tab-width: 4
421End:
422*/