diff options
author | deraadt@openbsd.org <deraadt@openbsd.org> | 2015-10-09 01:37:08 +0000 |
---|---|---|
committer | Damien Miller <djm@mindrot.org> | 2015-10-14 03:22:08 +1100 |
commit | 2539dce2a049a8f6bb0d44cac51f07ad48e691d3 (patch) | |
tree | 4bfeaba2e6740193ed669006ffb6cebb88d8f279 /sandbox-pledge.c | |
parent | 9846a2f4067383bb76b4e31a9d2303e0a9c13a73 (diff) |
upstream commit
Change all tame callers to namechange to pledge(2).
Upstream-ID: 17e654fc27ceaf523c60f4ffd9ec7ae4e7efc7f2
Diffstat (limited to 'sandbox-pledge.c')
-rw-r--r-- | sandbox-pledge.c | 77 |
1 files changed, 77 insertions, 0 deletions
diff --git a/sandbox-pledge.c b/sandbox-pledge.c new file mode 100644 index 000000000..1d3e247d7 --- /dev/null +++ b/sandbox-pledge.c | |||
@@ -0,0 +1,77 @@ | |||
1 | /* $OpenBSD: sandbox-pledge.c,v 1.1 2015/10/09 01:37:08 deraadt Exp $ */ | ||
2 | /* | ||
3 | * Copyright (c) 2015 Theo de Raadt <deraadt@openbsd.org> | ||
4 | * | ||
5 | * Permission to use, copy, modify, and distribute this software for any | ||
6 | * purpose with or without fee is hereby granted, provided that the above | ||
7 | * copyright notice and this permission notice appear in all copies. | ||
8 | * | ||
9 | * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES | ||
10 | * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF | ||
11 | * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR | ||
12 | * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES | ||
13 | * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN | ||
14 | * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF | ||
15 | * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. | ||
16 | */ | ||
17 | |||
18 | #include "includes.h" | ||
19 | |||
20 | #ifdef SANDBOX_TAME | ||
21 | |||
22 | #include <sys/types.h> | ||
23 | #include <sys/ioctl.h> | ||
24 | #include <sys/syscall.h> | ||
25 | #include <sys/socket.h> | ||
26 | #include <sys/wait.h> | ||
27 | |||
28 | #include <errno.h> | ||
29 | #include <limits.h> | ||
30 | #include <stdarg.h> | ||
31 | #include <stdio.h> | ||
32 | #include <stdlib.h> | ||
33 | #include <unistd.h> | ||
34 | #include <pwd.h> | ||
35 | |||
36 | #include "log.h" | ||
37 | #include "ssh-sandbox.h" | ||
38 | #include "xmalloc.h" | ||
39 | |||
40 | struct ssh_sandbox { | ||
41 | pid_t child_pid; | ||
42 | }; | ||
43 | |||
44 | struct ssh_sandbox * | ||
45 | ssh_sandbox_init(struct monitor *m) | ||
46 | { | ||
47 | struct ssh_sandbox *box; | ||
48 | |||
49 | debug3("%s: preparing pledge sandbox", __func__); | ||
50 | box = xcalloc(1, sizeof(*box)); | ||
51 | box->child_pid = 0; | ||
52 | |||
53 | return box; | ||
54 | } | ||
55 | |||
56 | void | ||
57 | ssh_sandbox_child(struct ssh_sandbox *box) | ||
58 | { | ||
59 | if (pledge("stdio", NULL) == -1) | ||
60 | fatal("%s: pledge()", __func__); | ||
61 | } | ||
62 | |||
63 | void | ||
64 | ssh_sandbox_parent_finish(struct ssh_sandbox *box) | ||
65 | { | ||
66 | free(box); | ||
67 | debug3("%s: finished", __func__); | ||
68 | } | ||
69 | |||
70 | void | ||
71 | ssh_sandbox_parent_preauth(struct ssh_sandbox *box, pid_t child_pid) | ||
72 | { | ||
73 | box->child_pid = child_pid; | ||
74 | /* Nothing to do here */ | ||
75 | } | ||
76 | |||
77 | #endif /* SANDBOX_TAME */ | ||