I occasionally run into a situation where I need a root-owned script to change the ownership or permissions of a file or directory located in a directory that is accessible by an unprivileged user. This requires some tricky work to do safely, since the user could create a symlink where I expect there to be a directory, pointing at some sensitive file or directory. This can be worked around in some situations by checking for symlinks first if the script runs during early boot where TOCTOU isn't an issue, or passing --no-dereference, but that doesn't help if I have to dig into a directory that itself may be a symlink. For instance, if I want to do:
chown user:user -- /home/user/path/to/dir
There is no way to do this safely in-place. I can't use setpriv to drop
privileges since chown requires root. I can't check if /home/user/path,
/home/user/path/to, and /home/user/path/to/dir are symlinks first
because that leaves a TOCTOU vulnerability. --no-dereference doesn't
work because chown will dig through the 'path' and 'to' dirs which may
be symlinks to something important. There are ugly ways around this
like copying 'dir' somewhere else, fixing ownership, then deleting the
original and moving the fixed version back, but that's obviously
non-ideal.
Would it be possible to add a `--no-canonicalize` feature to `chown`
and `chmod` (and possibly other utilities where it might make sense)
that throws an error if any portion of the path being acted on does not
exist or goes through a symlink?
--
Aaron
pgpxnpB9zf73j.pgp
Description: OpenPGP digital signature
