setuid.patch revision 919
90N/A#
90N/A# Copyright 2007 Sun Microsystems, Inc. All rights reserved.
919N/A# Use is subject to license terms.
90N/A#
90N/A# Permission is hereby granted, free of charge, to any person obtaining a
919N/A# copy of this software and associated documentation files (the "Software"),
919N/A# to deal in the Software without restriction, including without limitation
919N/A# the rights to use, copy, modify, merge, publish, distribute, sublicense,
919N/A# and/or sell copies of the Software, and to permit persons to whom the
919N/A# Software is furnished to do so, subject to the following conditions:
90N/A#
919N/A# The above copyright notice and this permission notice (including the next
919N/A# paragraph) shall be included in all copies or substantial portions of the
919N/A# Software.
90N/A#
919N/A# THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
919N/A# IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
919N/A# FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL
919N/A# THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
919N/A# LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
919N/A# FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER
919N/A# DEALINGS IN THE SOFTWARE.
90N/A#
90N/A#
90N/A
90N/AAdditional security checks for setuid programs that X.Org upstream doesn't
90N/Ahave yet.
90N/A
90N/A--- src/RdFToI.c 2006-10-11 15:31:40.000000000 -0700
90N/A+++ src/RdFToI.c 2006-10-03 16:34:35.553330000 -0700
90N/A@@ -154,7 +154,15 @@
90N/A goto err;
90N/A if ( 0 == pid )
90N/A {
90N/A- execlp(cmd, cmd, arg1, (char *)NULL);
90N/A+/* #ifdef SUNSOFT */
90N/A+ closefrom(3);
90N/A+ if (issetugid()) {
90N/A+ char commandpath[32] = "/usr/bin/";
90N/A+ strlcat(commandpath, cmd, sizeof(commandpath));
90N/A+ execl(commandpath, cmd, arg1, NULL);
90N/A+ } else
90N/A+/* #endif */
90N/A+ execlp(cmd, cmd, arg1, NULL);
90N/A perror(cmd);
90N/A goto err;
90N/A }
90N/A