svn commit: r343117 - head/usr.bin/cmp

Mark Johnston markj at FreeBSD.org
Thu Jan 17 17:36:19 UTC 2019


Author: markj
Date: Thu Jan 17 17:36:18 2019
New Revision: 343117
URL: https://svnweb.freebsd.org/changeset/base/343117

Log:
  Fix handling of rights on stdio streams.
  
  - Limit rights on stdio before opening input files.  Otherwise, open()
    may return one of the standard descriptors and we end up limiting
    rights such that we cannot read from one of the input files.
  - Use caph_limit_stdio(), which suppresses EBADF, to ensure that
    we don't emit an error if one of the stdio streams is closed.
  - Don't bother further limiting rights on stdin when stdin isn't going
    to be used.  Doing so correctly requires checking for a number of
    edge cases, and it doesn't provide any significant benefit.
  
  PR:		234885
  Reviewed by:	oshogbo
  MFC after:	3 days
  Sponsored by:	The FreeBSD Foundation
  Differential Revision:	https://reviews.freebsd.org/D18860

Modified:
  head/usr.bin/cmp/cmp.c

Modified: head/usr.bin/cmp/cmp.c
==============================================================================
--- head/usr.bin/cmp/cmp.c	Thu Jan 17 16:50:50 2019	(r343116)
+++ head/usr.bin/cmp/cmp.c	Thu Jan 17 17:36:18 2019	(r343117)
@@ -116,14 +116,16 @@ main(int argc, char *argv[])
 	if (argc < 2 || argc > 4)
 		usage();
 
+	if (caph_limit_stdio() == -1)
+		err(ERR_EXIT, "failed to limit stdio");
+
 	/* Backward compatibility -- handle "-" meaning stdin. */
 	special = 0;
 	if (strcmp(file1 = argv[0], "-") == 0) {
 		special = 1;
-		fd1 = 0;
+		fd1 = STDIN_FILENO;
 		file1 = "stdin";
-	}
-	else if ((fd1 = open(file1, oflag, 0)) < 0 && errno != EMLINK) {
+	} else if ((fd1 = open(file1, oflag, 0)) < 0 && errno != EMLINK) {
 		if (!sflag)
 			err(ERR_EXIT, "%s", file1);
 		else
@@ -134,10 +136,9 @@ main(int argc, char *argv[])
 			errx(ERR_EXIT,
 				"standard input may only be specified once");
 		special = 1;
-		fd2 = 0;
+		fd2 = STDIN_FILENO;
 		file2 = "stdin";
-	}
-	else if ((fd2 = open(file2, oflag, 0)) < 0 && errno != EMLINK) {
+	} else if ((fd2 = open(file2, oflag, 0)) < 0 && errno != EMLINK) {
 		if (!sflag)
 			err(ERR_EXIT, "%s", file2);
 		else
@@ -174,16 +175,6 @@ main(int argc, char *argv[])
 		err(ERR_EXIT, "unable to limit fcntls for %s", file1);
 	if (caph_fcntls_limit(fd2, fcntls) < 0)
 		err(ERR_EXIT, "unable to limit fcntls for %s", file2);
-
-	if (!special) {
-		cap_rights_init(&rights);
-		if (caph_rights_limit(STDIN_FILENO, &rights) < 0) {
-			err(ERR_EXIT, "unable to limit stdio");
-		}
-	}
-
-	if (caph_limit_stdout() == -1 || caph_limit_stderr() == -1)
-		err(ERR_EXIT, "unable to limit stdio");
 
 	caph_cache_catpages();
 


More information about the svn-src-all mailing list