From: Yelninei <[email protected]>
By convention the first uid/gid is the euid/egid. Ensure that the
first uid/gid in the array passed to auth_makeauth is the egid/egid to
not unexpectedly overwrite it.
---
hurd/seteuids.c | 17 +++++++++++++----
sysdeps/mach/hurd/setgroups.c | 17 +++++++++++++----
2 files changed, 26 insertions(+), 8 deletions(-)
diff --git a/hurd/seteuids.c b/hurd/seteuids.c
index 3be772ae8b..8c4f5f2c20 100644
--- a/hurd/seteuids.c
+++ b/hurd/seteuids.c
@@ -15,6 +15,7 @@
License along with the GNU C Library; if not, see
<https://www.gnu.org/licenses/>. */
+#include <unistd.h>
#include <hurd.h>
#include <hurd/id.h>
@@ -24,12 +25,20 @@ seteuids (size_t n, const uid_t *uids)
{
error_t err;
auth_t newauth;
- size_t i;
- gid_t new[n];
+ size_t i, start;
+ uid_t euid;
+ uid_t new[n + 1];
+ start = 0;
+ euid = geteuid ();
+ if (euid != (uid_t) -1 && (n == 0 || (n > 0 && euid != uids[0])))
+ {
+ new[0] = euid;
+ start = 1;
+ }
/* Fault before taking locks. */
for (i = 0; i < n; ++i)
- new[i] = uids[i];
+ new[i + start] = uids[i];
retry:
HURD_CRITICAL_BEGIN;
@@ -40,7 +49,7 @@ retry:
/* Get a new auth port using those IDs. */
err = __USEPORT (AUTH,
__auth_makeauth (port, NULL, MACH_MSG_TYPE_COPY_SEND, 0,
- new, n,
+ new, n + start,
_hurd_id.aux.uids, _hurd_id.aux.nuids,
_hurd_id.gen.gids, _hurd_id.gen.ngids,
_hurd_id.aux.gids, _hurd_id.aux.ngids,
diff --git a/sysdeps/mach/hurd/setgroups.c b/sysdeps/mach/hurd/setgroups.c
index 5d71d89011..ddfed7cac5 100644
--- a/sysdeps/mach/hurd/setgroups.c
+++ b/sysdeps/mach/hurd/setgroups.c
@@ -17,6 +17,7 @@
#include <errno.h>
#include <sys/types.h>
+#include <unistd.h>
#include <grp.h>
#include <hurd.h>
#include <hurd/id.h>
@@ -27,12 +28,20 @@ setgroups (size_t n, const gid_t *groups)
{
error_t err;
auth_t newauth;
- size_t i;
- gid_t new[n];
+ size_t i, start;
+ gid_t egid;
+ gid_t new[n + 1];
+ start = 0;
+ egid = getegid ();
+ if (egid != (gid_t) -1 && (n == 0 || (n > 0 && egid != groups[0])))
+ {
+ new[0] = egid;
+ start = 1;
+ }
/* Fault before taking locks. */
for (i = 0; i < n; ++i)
- new[i] = groups[i];
+ new[i + start] = groups[i];
retry:
HURD_CRITICAL_BEGIN;
@@ -45,7 +54,7 @@ retry:
__auth_makeauth (port, NULL, MACH_MSG_TYPE_COPY_SEND, 0,
_hurd_id.gen.uids, _hurd_id.gen.nuids,
_hurd_id.aux.uids, _hurd_id.aux.nuids,
- new, n,
+ new, n + start,
_hurd_id.aux.gids, _hurd_id.aux.ngids,
&newauth));
}
--
2.53.0