1 /****************************************************************************
2 * Copyright 2019-2020,2021 Thomas E. Dickey *
3 * Copyright 1998-2011,2012 Free Software Foundation, Inc. *
5 * Permission is hereby granted, free of charge, to any person obtaining a *
6 * copy of this software and associated documentation files (the *
7 * "Software"), to deal in the Software without restriction, including *
8 * without limitation the rights to use, copy, modify, merge, publish, *
9 * distribute, distribute with modifications, sublicense, and/or sell *
10 * copies of the Software, and to permit persons to whom the Software is *
11 * furnished to do so, subject to the following conditions: *
13 * The above copyright notice and this permission notice shall be included *
14 * in all copies or substantial portions of the Software. *
16 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS *
17 * OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF *
18 * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. *
19 * IN NO EVENT SHALL THE ABOVE COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, *
20 * DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR *
21 * OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR *
22 * THE USE OR OTHER DEALINGS IN THE SOFTWARE. *
24 * Except as contained in this notice, the name(s) of the above copyright *
25 * holders shall not be used in advertising or otherwise to promote the *
26 * sale, use or other dealings in this Software without prior written *
28 ****************************************************************************/
30 /****************************************************************************
31 * Author: Thomas E. Dickey *
32 ****************************************************************************/
34 #include <curses.priv.h>
38 #ifndef USE_ROOT_ACCESS
40 #include <sys/fsuid.h>
48 MODULE_ID("$Id: access.c,v 1.29 2021/06/26 23:50:02 tom Exp $")
50 #define LOWERCASE(c) ((isalpha(UChar(c)) && isupper(UChar(c))) ? tolower(UChar(c)) : (c))
53 # define ACCESS(FN, MODE) access((FN), (MODE)&(R_OK|W_OK))
55 # define ACCESS access
58 NCURSES_EXPORT(char *)
59 _nc_rootname(char *path)
61 char *result = _nc_basename(path);
62 #if !MIXEDCASE_FILENAMES || defined(PROG_EXT)
66 temp = strdup(result);
68 #if !MIXEDCASE_FILENAMES
69 for (s = result; *s != '\0'; ++s) {
70 *s = (char) LOWERCASE(*s);
74 if ((s = strrchr(result, '.')) != 0) {
75 if (!strcmp(s, PROG_EXT))
84 * Check if a string appears to be an absolute pathname.
87 _nc_is_abs_path(const char *path)
89 #if defined(__EMX__) || defined(__DJGPP__)
90 #define is_pathname(s) ((((s) != 0) && ((s)[0] == '/')) \
91 || (((s)[0] != 0) && ((s)[1] == ':')))
93 #define is_pathname(s) ((s) != 0 && (s)[0] == '/')
95 return is_pathname(path);
99 * Return index of the basename
101 NCURSES_EXPORT(unsigned)
102 _nc_pathlast(const char *path)
104 const char *test = strrchr(path, '/');
107 test = strrchr(path, '\\');
113 return (unsigned) (test - path);
116 NCURSES_EXPORT(char *)
117 _nc_basename(char *path)
119 return path + _nc_pathlast(path);
123 _nc_access(const char *path, int mode)
129 } else if (ACCESS(path, mode) < 0) {
130 if ((mode & W_OK) != 0
132 && strlen(path) < PATH_MAX) {
136 _nc_STRCPY(head, path, sizeof(head));
137 leaf = _nc_basename(head);
142 _nc_STRCPY(head, ".", sizeof(head));
144 result = ACCESS(head, R_OK | W_OK | X_OK);
155 _nc_is_dir_path(const char *path)
160 if (stat(path, &sb) == 0
161 && S_ISDIR(sb.st_mode)) {
168 _nc_is_file_path(const char *path)
173 if (stat(path, &sb) == 0
174 && S_ISREG(sb.st_mode)) {
181 #define is_elevated() issetugid()
182 #elif HAVE_GETEUID && HAVE_GETEGID
183 #define is_elevated() \
184 (getuid() != geteuid() \
185 || getgid() != getegid())
187 #define is_elevated() FALSE
191 #define lower_privileges() \
192 int save_err = errno; \
193 setfsuid(getuid()); \
194 setfsgid(getgid()); \
196 #define resume_elevation() \
198 setfsuid(geteuid()); \
199 setfsgid(getegid()); \
202 #define lower_privileges() /* nothing */
203 #define resume_elevation() /* nothing */
206 #ifndef USE_ROOT_ENVIRON
208 * Returns true if we allow application to use environment variables that are
209 * used for searching lists of directories, etc.
218 } else if ((getuid() != ROOT_UID) && (geteuid() != ROOT_UID)) {
223 #endif /* USE_ROOT_ENVIRON */
225 #ifndef USE_ROOT_ACCESS
227 * Limit privileges if possible; otherwise disallow access for updating files.
229 NCURSES_EXPORT(FILE *)
230 _nc_safe_fopen(const char *path, const char *mode)
235 result = fopen(path, mode);
238 if (!is_elevated() || *mode == 'r') {
239 result = fopen(path, mode);
246 _nc_safe_open3(const char *path, int flags, mode_t mode)
251 result = open(path, flags, mode);
254 if (!is_elevated() || (flags & O_RDONLY)) {
255 result = open(path, flags, mode);
260 #endif /* USE_ROOT_ENVIRON */