Gunnar Wolf wrote:
> Jeremy Chadwick dijo [Fri, Sep 26, 2008 at 07:37:19PM -0700]:
>
> [...]
>
> case cherokee_logger_writer_file:
> + /* Check against symlink attacks */
> + r = stat (writer->filename.buf, &info);
> + /* Disregard if the stat failed - The file does not exist, so
> everything is fine */
> + if (r == 0 and S_ISLINK(info.st_mode) == 0) {
> + PRINT_MSG ("%s unsafe for opening: Is a symlink\n",
> writer->filename.buf);
> + return ret_error
> + }
> +
> writer->fd = open (writer->filename.buf, O_APPEND | O_WRONLY
> | O_CREAT | O_LARGEFILE, 0
>
Isn't this flawed by a race condition (stat-before-open)? There is a
O_NOFOLLOW (at least on FreeBSD [1] and Linux [2]) flag to open(2) for
this "do not open a symlink" scenario.
BTW, I find the open logs as user flawed (the user can mess with the
logs if allowed to run its own code in the daemon account); IMHO the
route followed by daemontools [3] is the nicer one: the daemon just logs
to stdout and another process writes to disk (or other place).
Best regards,
Rui Lopes
[1] http://www.freebsd.org/cgi/man.cgi?query=open
[2] http://linux.die.net/man/2/open
[3] http://cr.yp.to/daemontools/svscan.html
_______________________________________________
Cherokee mailing list
[email protected]
http://lists.octality.com/listinfo/cherokee