safe-mkstemp.c revision 4ded3d18fa391ae5908f9834f1390cf55e8c99d5
45312f52ff3a3d4c137447be4c7556500c2f8bf2Timo Sirainen/* Copyright (c) 2007-2009 Dovecot authors, see the included COPYING file */
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen
08d6658a4e2ec8104cd1307f6baa75fdb07a24f8Mark Washenberger#include "lib.h"
345648b341f228bd7f0b89f8aa3ecb9c470d817eTimo Sirainen#include "str.h"
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen#include "hex-binary.h"
d1414c09cf0d58ac983054e2f4e1a1f329272dcfTimo Sirainen#include "randgen.h"
5a2cb3d097a2d9a9e930af997e7bf3400a8d840dTimo Sirainen#include "hostpid.h"
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen#include "safe-mkstemp.h"
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen#include <unistd.h>
97c339398f1aba6f315b55a9b6ee6b020e33bea4Timo Sirainen#include <fcntl.h>
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen#include <sys/stat.h>
16f46efe0e090fe6975acf012a61a160f4787985Andrey Panin
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainenint safe_mkstemp(string_t *prefix, mode_t mode, uid_t uid, gid_t gid)
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen{
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen size_t prefix_len;
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen struct stat st;
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen unsigned char randbuf[8];
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen mode_t old_umask;
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen int fd;
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen prefix_len = str_len(prefix);
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen for (;;) {
16f46efe0e090fe6975acf012a61a160f4787985Andrey Panin do {
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen random_fill_weak(randbuf, sizeof(randbuf));
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen str_truncate(prefix, prefix_len);
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen str_append(prefix,
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen binary_to_hex(randbuf, sizeof(randbuf)));
d1414c09cf0d58ac983054e2f4e1a1f329272dcfTimo Sirainen } while (lstat(str_c(prefix), &st) == 0);
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen if (errno != ENOENT) {
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen i_error("stat(%s) failed: %m", str_c(prefix));
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen return -1;
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen }
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen old_umask = umask(0666 ^ mode);
25757faf029c369a8318349dafe952e2358df1d8Timo Sirainen fd = open(str_c(prefix), O_RDWR | O_EXCL | O_CREAT, 0666);
7242e1ce7803b83bc82e239ef111b47c1c72dd4bAndrey Panin umask(old_umask);
d1414c09cf0d58ac983054e2f4e1a1f329272dcfTimo Sirainen if (fd != -1)
d1414c09cf0d58ac983054e2f4e1a1f329272dcfTimo Sirainen break;
d1414c09cf0d58ac983054e2f4e1a1f329272dcfTimo Sirainen
d1414c09cf0d58ac983054e2f4e1a1f329272dcfTimo Sirainen if (errno != EEXIST) {
c57776c06ec99ba9b0dafdbf9475ea72ea8ca134Timo Sirainen if (errno != ENOENT && errno != EACCES)
d1414c09cf0d58ac983054e2f4e1a1f329272dcfTimo Sirainen i_error("open(%s) failed: %m", str_c(prefix));
d1414c09cf0d58ac983054e2f4e1a1f329272dcfTimo Sirainen return -1;
d1414c09cf0d58ac983054e2f4e1a1f329272dcfTimo Sirainen }
d1414c09cf0d58ac983054e2f4e1a1f329272dcfTimo Sirainen }
d1414c09cf0d58ac983054e2f4e1a1f329272dcfTimo Sirainen if (uid != (uid_t)-1 || gid != (gid_t)-1) {
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen if (fchown(fd, uid, gid) < 0) {
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen i_error("fchown(%s, %ld, %ld) failed: %m",
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen str_c(prefix),
4051fa1f367553cac34f74c2e332a678390bcee5Timo Sirainen uid == (uid_t)-1 ? -1L : (long)uid,
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen gid == (gid_t)-1 ? -1L : (long)gid);
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen (void)close(fd);
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen (void)unlink(str_c(prefix));
4051fa1f367553cac34f74c2e332a678390bcee5Timo Sirainen return -1;
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen }
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen }
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen return fd;
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen}
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainenint safe_mkstemp_hostpid(string_t *prefix, mode_t mode, uid_t uid, gid_t gid)
648d24583c1574441c4fa0331a90bd4d6e7996c5Timo Sirainen{
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen str_printfa(prefix, "%s.%s.", my_hostname, my_pid);
e70d5895795732b8247ab9abb045b438e954bc46Timo Sirainen return safe_mkstemp(prefix, mode, uid, gid);
1ddec6312bc6882aeb17d4d46d19cbca1723b68bTimo Sirainen}
1ddec6312bc6882aeb17d4d46d19cbca1723b68bTimo Sirainen