From nobody Thu Feb 15 14:23:41 2024 X-Original-To: dev-commits-src-branches@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4TbHNt05Ntz541Z8; Thu, 15 Feb 2024 14:23:42 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4TbHNs67S5z4DH5; Thu, 15 Feb 2024 14:23:41 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1708007021; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=DKE40jHPk4lyUIv05Mi9XyczVp31GYRlul11r3+WMuM=; b=PWxIdkdW9gfP7fqcdEyC8gQxItdep8R+VUJKsMW+girCp8tofYu4ebwVPDjV5mIitUA1cZ RHOyDm+JSs+8heoqxNyv7+dQft6811n4ssRCo9P3C+esgCNZ+jwMGxANs0VPwWahLFRzB8 NkF5qAMBh58xRo0M9FJsYlA5pdQDFk/02gxCCy12yZiu8yum2YTqovT/gTf+rSxFzStIX+ a2Tv4Q6yh5yQWvORqBvgowDyBARYQ5nIoUGek57ZLdzdHfPXE/cjnCI5yz497RBFlG3Pw+ Xnk5tW5uWOO/yKhKmiH6gMZaGsNjwxs+TgGYpXQ3u5po+JXD+CBzDWw7OXVj0g== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1708007021; a=rsa-sha256; cv=none; b=XN2+yJAB2mU7mLJ/b+CQcGk3vpWthoa+F3KTYw5M46Rr1pVpOwCLMj63WwQUXHlM48Zlzy To+7mdf2O2Ya7ssnzUvJI/wliNaAd5xzN2/7NUjiwOBigRA49xNldb1pQB53zoL9UzaD9P ZWG/R7cr5CbvouchtHQOiRksQ0Nqp/v7EiLPVLyN1NlWgOSAarWteXoHeTnCplXVd1d42G o+ypBdQ1siT+VuiLZC4D6b6r2fofmj4R/4+Ga7XS0AwuUJgMKEx0X3sx+RHQ1Cn5XMCjWA ROftld1dcER1ARQjRXmeeoT8MEbyVk08UFOmCkLge8hqOa2BsOCSMg6ApBVFrA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1708007021; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=DKE40jHPk4lyUIv05Mi9XyczVp31GYRlul11r3+WMuM=; b=nvEcnt+xWUFCTKPjjjTk5JKwYEoJ8HP4X6ZgOG82jlp7hiWcQjau1WqC2fF5GXMtX6yCaK qCXvLUMVZE2gKxOnbRsZBsVmk3i5MCUF9QWJEAOU0y/74DfVC7IhIDE0zxeKKk2xMYdPHW KExycDtCWSCj06aBqovcPAxXTbAEMlUnq4TJe/AiHSLaUSeA88zDv/yEw2VC8Be+NbDjZF tb7/hgSyya/cZsMx4GUASyXXQ1SkCIWy7HFXAqcytopuyneCBqO0R+om8OwW0HGwx6eZOy aZGB3fuUO0vSQYtKF6cBuU6u2QDbpLooWu0Ig5OGhWISJG+yprY39IfQLQDPLg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4TbHNs5CldzlVk; Thu, 15 Feb 2024 14:23:41 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 41FENfCY047583; Thu, 15 Feb 2024 14:23:41 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 41FENfH2047580; Thu, 15 Feb 2024 14:23:41 GMT (envelope-from git) Date: Thu, 15 Feb 2024 14:23:41 GMT Message-Id: <202402151423.41FENfH2047580@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org From: Mark Johnston Subject: git: efec2f0d4e17 - stable/14 - md5: Enter capability mode earlier List-Id: Commits to the stable branches of the FreeBSD src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-branches List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-branches@freebsd.org X-BeenThere: dev-commits-src-branches@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/stable/14 X-Git-Reftype: branch X-Git-Commit: efec2f0d4e1739c94cb2581e6ff25a41fc9e38c2 Auto-Submitted: auto-generated The branch stable/14 has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=efec2f0d4e1739c94cb2581e6ff25a41fc9e38c2 commit efec2f0d4e1739c94cb2581e6ff25a41fc9e38c2 Author: Ricardo Branco AuthorDate: 2024-01-03 18:00:47 +0000 Commit: Mark Johnston CommitDate: 2024-02-15 14:16:07 +0000 md5: Enter capability mode earlier Reviewed by: markj MFC after: 1 month Pull Request: https://github.com/freebsd/freebsd-src/pull/988 (cherry picked from commit 9b20849bc5f1b500f2de7aeca77f0e6556069bbb) --- sbin/md5/Makefile | 9 ++++++--- sbin/md5/md5.c | 57 +++++++++++++++++++++++++++++++------------------------ 2 files changed, 38 insertions(+), 28 deletions(-) diff --git a/sbin/md5/Makefile b/sbin/md5/Makefile index 359c4b96f9fd..e4e6335ae875 100644 --- a/sbin/md5/Makefile +++ b/sbin/md5/Makefile @@ -59,16 +59,19 @@ MLINKS= md5.1 md5sum.1 \ LIBADD= md -.ifndef(BOOTSTRAPPING) +.include + +.if ${MK_CASPER} != "no" && !defined(RESCUE) && !defined(BOOTSTRAPPING) # Avoid depending on capsicum during bootstrap. caph_limit_stdout() is not # available when building for Linux/MacOS or older FreeBSD hosts. # We need to bootstrap md5 when building on Linux since the md5sum command there # produces different output. CFLAGS+=-DHAVE_CAPSICUM +CFLAGS+=-DWITH_CASPER +LIBADD+= casper +LIBADD+= cap_fileargs .endif -.include - HAS_TESTS= SUBDIR.${MK_TESTS}+= tests diff --git a/sbin/md5/md5.c b/sbin/md5/md5.c index 15fd7ebec5d4..eb9a2ffae1cc 100644 --- a/sbin/md5/md5.c +++ b/sbin/md5/md5.c @@ -47,6 +47,8 @@ #ifdef HAVE_CAPSICUM #include #include +#include +#include #endif /* @@ -311,6 +313,7 @@ gnu_check(const char *checksumsfile) const char *digestname; size_t digestnamelen; size_t hashstrlen; + struct stat st; if (strcmp(checksumsfile, "-") == 0) inp = stdin; @@ -358,6 +361,15 @@ gnu_check(const char *checksumsfile) rec = malloc(sizeof(*rec)); if (rec == NULL) errx(1, "malloc failed"); + + if (*filename == '*' || + *filename == ' ' || + *filename == 'U' || + *filename == '^') { + if (lstat(filename, &st) != 0) + filename++; + } + rec->chksum = strdup(hashstr); rec->filename = strdup(filename); if (rec->chksum == NULL || rec->filename == NULL) @@ -385,6 +397,7 @@ main(int argc, char *argv[]) { #ifdef HAVE_CAPSICUM cap_rights_t rights; + fileargs_t *fa = NULL; #endif const struct option *longopts; const char *shortopts; @@ -585,24 +598,25 @@ main(int argc, char *argv[]) rec = head; } +#ifdef HAVE_CAPSICUM + fa = fileargs_init(argc, argv, O_RDONLY, 0, + cap_rights_init(&rights, CAP_READ, CAP_FSTAT, CAP_FCNTL), FA_OPEN | FA_LSTAT); + if (fa == NULL) + err(1, "Unable to initialize casper"); + if (caph_enter_casper() < 0) + err(1, "Unable to enter capability mode"); +#endif + if (*argv) { do { - struct stat st; const char *filename = *argv; const char *filemode = "rb"; - if (*filename == '*' || - *filename == ' ' || - *filename == 'U' || - *filename == '^') { - if (lstat(filename, &st) != 0) { - input_mode = (int)*filename; - filename++; - } - } - if (input_mode == input_text) - filemode = "r"; +#ifdef HAVE_CAPSICUM + if ((f = fileargs_fopen(fa, filename, filemode)) == NULL) { +#else if ((f = fopen(filename, filemode)) == NULL) { +#endif if (errno != ENOENT || !(cflag && ignoreMissing)) { warn("%s", filename); failed = true; @@ -611,20 +625,10 @@ main(int argc, char *argv[]) rec = rec->next; continue; } - /* - * XXX Enter capability mode on the last argv file. - * When a casper file service or other approach is - * available, switch to that and enter capability mode - * earlier. - */ - if (*(argv + 1) == NULL) { #ifdef HAVE_CAPSICUM - cap_rights_init(&rights, CAP_READ, CAP_FSTAT); - if (caph_rights_limit(fileno(f), &rights) < 0 || - caph_enter() < 0) - err(1, "capsicum"); + if (caph_rights_limit(fileno(f), &rights) < 0) + err(1, "capsicum"); #endif - } if (cflag && mode != mode_bsd) { checkAgainst = rec->chksum; rec = rec->next; @@ -635,7 +639,7 @@ main(int argc, char *argv[]) } while (*++argv); } else if (!cflag && string == NULL && !skip) { #ifdef HAVE_CAPSICUM - if (caph_limit_stdin() < 0 || caph_enter() < 0) + if (caph_limit_stdin() < 0) err(1, "capsicum"); #endif if (mode == mode_bsd) @@ -659,6 +663,9 @@ main(int argc, char *argv[]) if (checksFailed != 0 || (strict && malformed > 0)) return (1); } +#ifdef HAVE_CAPSICUM + fileargs_free(fa); +#endif if (failed) return (1); if (checksFailed > 0)