core-agent-linux/qubes-rpc/qfile-unpacker.c

64 lines
1.5 KiB
C
Raw Normal View History

2011-03-15 16:43:43 +01:00
#define _GNU_SOURCE
#include <grp.h>
#include <unistd.h>
#include <stdio.h>
#include <stdlib.h>
#include <pwd.h>
#include <sys/stat.h>
#include <string.h>
#include <unistd.h>
#include <sys/fsuid.h>
#include <gui-fatal.h>
#include <errno.h>
#include <libqubes-rpc-filecopy.h>
#define INCOMING_DIR_ROOT "/home/user/QubesIncoming"
2013-12-28 12:49:30 +01:00
int prepare_creds_return_uid(const char *username)
2011-03-15 16:43:43 +01:00
{
const struct passwd *pwd;
2011-03-15 16:43:43 +01:00
pwd = getpwnam(username);
if (!pwd) {
perror("getpwnam");
exit(1);
}
setenv("HOME", pwd->pw_dir, 1);
setenv("USER", username, 1);
2013-12-28 12:50:18 +01:00
if (setgid(pwd->pw_gid) < 0)
gui_fatal("Error setting group permissions");
if (initgroups(username, pwd->pw_gid) < 0)
gui_fatal("Error initializing groups");
if (setfsuid(pwd->pw_uid) < 0)
gui_fatal("Error setting filesystem level permissions");
2011-03-15 16:43:43 +01:00
return pwd->pw_uid;
}
void notify_progress(int p1, int p2)
{
}
2011-03-15 16:43:43 +01:00
int main(int argc, char ** argv)
{
char *incoming_dir;
int uid;
2013-12-28 12:49:30 +01:00
const char *remote_domain;
2011-03-15 16:43:43 +01:00
uid = prepare_creds_return_uid("user");
remote_domain = getenv("QREXEC_REMOTE_DOMAIN");
if (!remote_domain) {
gui_fatal("Cannot get remote domain name");
exit(1);
}
2011-03-15 16:43:43 +01:00
mkdir(INCOMING_DIR_ROOT, 0700);
2013-12-28 12:50:18 +01:00
if (asprintf(&incoming_dir, "%s/%s", INCOMING_DIR_ROOT, remote_domain) < 0)
gui_fatal("Error allocating memory");
2011-03-15 16:43:43 +01:00
mkdir(incoming_dir, 0700);
if (chdir(incoming_dir))
gui_fatal("Error chdir to %s", incoming_dir);
if (chroot(incoming_dir)) //impossible
gui_fatal("Error chroot to %s", incoming_dir);
2013-12-28 12:50:18 +01:00
if (setuid(uid) < 0)
gui_fatal("Error changing permissions to '%s'", "user");
return do_unpack();
2011-03-15 16:43:43 +01:00
}