safe-mkstemp.c revision 45312f52ff3a3d4c137447be4c7556500c2f8bf2
45312f52ff3a3d4c137447be4c7556500c2f8bf2Timo Sirainen/* Copyright (c) 2007-2009 Dovecot authors, see the included COPYING file */
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen#include "lib.h"
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen#include "str.h"
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen#include "hex-binary.h"
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen#include "randgen.h"
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen#include "hostpid.h"
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen#include "safe-mkstemp.h"
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen#include <unistd.h>
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen#include <fcntl.h>
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen#include <sys/stat.h>
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainenint safe_mkstemp(string_t *prefix, mode_t mode, uid_t uid, gid_t gid)
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen{
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen size_t prefix_len;
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen struct stat st;
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen unsigned char randbuf[8];
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen int fd;
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen prefix_len = str_len(prefix);
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen for (;;) {
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen do {
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen random_fill_weak(randbuf, sizeof(randbuf));
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen str_truncate(prefix, prefix_len);
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen str_append(prefix,
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen binary_to_hex(randbuf, sizeof(randbuf)));
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen } while (lstat(str_c(prefix), &st) == 0);
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen if (errno != ENOENT) {
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen i_error("stat(%s) failed: %m", str_c(prefix));
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen return -1;
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen }
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen fd = open(str_c(prefix), O_RDWR | O_EXCL | O_CREAT, mode);
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen if (fd != -1)
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen break;
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen if (errno != EEXIST) {
ba153863e55d75a7c2f28c9c010a905b8887b62bTimo Sirainen if (errno != ENOENT && errno != EACCES)
b3a069922c8150a1cb14ec7683444f60dee98b55Timo Sirainen i_error("open(%s) failed: %m", str_c(prefix));
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen return -1;
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen }
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen }
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen if (uid != (uid_t)-1 || gid != (gid_t)-1) {
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen if (fchown(fd, uid, gid) < 0) {
7b9f0c6aba07358e5520dc60c058126a4cae4056Timo Sirainen i_error("fchown(%s, %ld, %ld) failed: %m",
7b9f0c6aba07358e5520dc60c058126a4cae4056Timo Sirainen str_c(prefix),
7b9f0c6aba07358e5520dc60c058126a4cae4056Timo Sirainen uid == (uid_t)-1 ? -1L : (long)uid,
7b9f0c6aba07358e5520dc60c058126a4cae4056Timo Sirainen gid == (gid_t)-1 ? -1L : (long)gid);
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen (void)close(fd);
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen (void)unlink(str_c(prefix));
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen return -1;
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen }
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen }
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen return fd;
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen}
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainenint safe_mkstemp_hostpid(string_t *prefix, mode_t mode, uid_t uid, gid_t gid)
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen{
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen str_printfa(prefix, "%s.%s.", my_hostname, my_pid);
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen return safe_mkstemp(prefix, mode, uid, gid);
128ab2c52a29068be87e12ab5aebbb8fdc933adfTimo Sirainen}