commit: ffc185bb4929de36ad3f8766b114cd11be8f0a62 Author: Mart Raudsepp <leio <AT> gentoo <DOT> org> AuthorDate: Fri Nov 11 10:34:48 2016 +0000 Commit: Michał Górny <mgorny <AT> gentoo <DOT> org> CommitDate: Tue Sep 26 20:14:36 2017 +0000 URL: https://gitweb.gentoo.org/proj/sandbox.git/commit/?id=ffc185bb
libsandbox: do not abort with a long name to opendir Add a pre-check for opendir that catches too long name arguments given to opendir, as it would get messed up and abort before it even gets to the open*() syscall (which would handle it correctly), due to opendir going through before_syscall/check_syscall, even though it isn't a true syscall and it getting cut to SB_PATH_MAX inbetween and getting confused somewhere. Test case added by Michał Górny <mgorny <AT> gentoo.org>. Bug: https://bugs.gentoo.org/553092 Signed-off-by: Mart Raudsepp <leio <AT> gentoo.org> libsandbox/wrapper-funcs/opendir.c | 2 ++ libsandbox/wrapper-funcs/opendir_pre_check.c | 26 ++++++++++++++++++++++++++ libsandbox/wrappers.h | 1 + tests/opendir-1.sh | 7 +++++++ tests/opendir.at | 1 + 5 files changed, 37 insertions(+) diff --git a/libsandbox/wrapper-funcs/opendir.c b/libsandbox/wrapper-funcs/opendir.c index 7670775..70c2692 100644 --- a/libsandbox/wrapper-funcs/opendir.c +++ b/libsandbox/wrapper-funcs/opendir.c @@ -10,4 +10,6 @@ #define WRAPPER_SAFE() SB_SAFE(name) #define WRAPPER_RET_TYPE DIR * #define WRAPPER_RET_DEFAULT NULL +#define WRAPPER_PRE_CHECKS() sb_opendir_pre_check(STRING_NAME, name) + #include "__wrapper_simple.c" diff --git a/libsandbox/wrapper-funcs/opendir_pre_check.c b/libsandbox/wrapper-funcs/opendir_pre_check.c new file mode 100644 index 0000000..60c869f --- /dev/null +++ b/libsandbox/wrapper-funcs/opendir_pre_check.c @@ -0,0 +1,26 @@ +/* + * opendir() pre-check. + * + * Copyright 1999-2016 Gentoo Foundation + * Licensed under the GPL-2 + */ + +bool sb_opendir_pre_check(const char *func, const char *name) +{ + /* If length of name is larger than PATH_MAX, we would mess it up + * before it reaches the open syscall, which would cleanly error out + * via sandbox as well (actually with much smaller lengths than even + * PATH_MAX). + * So error out early in this case, in order to avoid an abort in + * check_syscall later on, which gets ran for opendir, despite it not + * being a syscall. + */ + if (strnlen(name, PATH_MAX) == PATH_MAX) { + errno = ENAMETOOLONG; + sb_debug_dyn("EARLY FAIL: %s(%s): %s\n", + func, name, strerror(errno)); + return false; + } + + return true; +} diff --git a/libsandbox/wrappers.h b/libsandbox/wrappers.h index 0aa58bb..bf5bf64 100644 --- a/libsandbox/wrappers.h +++ b/libsandbox/wrappers.h @@ -27,6 +27,7 @@ attribute_hidden bool sb_fopen64_pre_check (const char *func, const char *pathn attribute_hidden bool sb_mkdirat_pre_check (const char *func, const char *pathname, int dirfd); attribute_hidden bool sb_openat_pre_check (const char *func, const char *pathname, int dirfd, int flags); attribute_hidden bool sb_openat64_pre_check (const char *func, const char *pathname, int dirfd, int flags); +attribute_hidden bool sb_opendir_pre_check (const char *func, const char *name); attribute_hidden bool sb_unlinkat_pre_check (const char *func, const char *pathname, int dirfd); attribute_hidden bool sb_common_at_pre_check(const char *func, const char **pathname, int dirfd, char *dirfd_path, size_t dirfd_path_len); diff --git a/tests/opendir-1.sh b/tests/opendir-1.sh new file mode 100755 index 0000000..a66f234 --- /dev/null +++ b/tests/opendir-1.sh @@ -0,0 +1,7 @@ +#!/bin/sh +# check that very long paths to opendir() do not cause segv +path= +for (( i = 0; i < 1000; i++ )); do + path+=/verylong +done +exec opendir-0 0,ENAMETOOLONG "${path}" diff --git a/tests/opendir.at b/tests/opendir.at new file mode 100644 index 0000000..081d7d2 --- /dev/null +++ b/tests/opendir.at @@ -0,0 +1 @@ +SB_CHECK(1)
