From 2ca174000e9be4878321c08920e7abfc76b89d88 Mon Sep 17 00:00:00 2001 From: TitanSnow Date: Mon, 22 May 2017 14:52:58 +0800 Subject: add setuid feature to os.uid --- core/src/xmake/os/uid.c | 92 ++++++++++++++++++++++++++++++++++++++++++++++++- xmake/core/base/os.lua | 10 ++---- 2 files changed, 93 insertions(+), 9 deletions(-) diff --git a/core/src/xmake/os/uid.c b/core/src/xmake/os/uid.c index d19bbd88e..0c67a3edf 100644 --- a/core/src/xmake/os/uid.c +++ b/core/src/xmake/os/uid.c @@ -35,6 +35,7 @@ #include "prefix.h" #ifndef TB_CONFIG_OS_WINDOWS # include +# include /* ////////////////////////////////////////////////////////////////////////////////////// * implementation @@ -46,11 +47,100 @@ tb_int_t xm_os_uid(lua_State* lua) // check tb_assert_and_check_return_val(lua, 0); + tb_int_t uidset = -1, euidset = -1; + + tb_int_t argc = lua_gettop(lua); + + if (argc == 1) + { + if (lua_istable(lua, 1)) + { + // os.uid({["uid"] = uid, ["euid"] = euid}) + lua_getfield(lua, 1, "uid"); + lua_getfield(lua, 1, "euid"); + if (!lua_isnil(lua, -1)) + { + if (!lua_isnumber(lua, -1)) + { + lua_pushfstring(lua, "invalid field type(%s) in `euid` for os.uid", luaL_typename(lua, -1)); + lua_error(lua); + return 0; + } + euidset = (tb_int_t)lua_tonumber(lua, -1); + } + lua_pop(lua, 1); + if (!lua_isnil(lua, -1)) + { + if (!lua_isnumber(lua, -1)) + { + lua_pushfstring(lua, "invalid field type(%s) in `uid` for os.uid", luaL_typename(lua, -1)); + lua_error(lua); + return 0; + } + uidset = (tb_int_t)lua_tonumber(lua, -1); + } + lua_pop(lua, 1); + } else if (lua_isnumber(lua, 1)) + { + // os.uid(euid) + euidset = (tb_int_t)lua_tonumber(lua, 1); + } else + { + lua_pushfstring(lua, "invalid argument type(%s) for os.uid", luaL_typename(lua, 1)); + lua_error(lua); + return 0; + } + } else if (argc == 2) + { + // os.uid(uid, euid) + if (!lua_isnil(lua, 1)) + { + if (!lua_isnumber(lua, 1)) + { + lua_pushfstring(lua, "invalid argument type(%s) for os.uid", luaL_typename(lua, 1)); + lua_error(lua); + return 0; + } + uidset = (tb_int_t)lua_tonumber(lua, 1); + } + if (!lua_isnil(lua, 2)) + { + if (!lua_isnumber(lua, 2)) + { + lua_pushfstring(lua, "invalid argument type(%s) for os.uid", luaL_typename(lua, 2)); + lua_error(lua); + return 0; + } + euidset = (tb_int_t)lua_tonumber(lua, 2); + } + } else if (argc != 0) + { + lua_pushstring(lua, "invalid argument count for os.uid"); + lua_error(lua); + return 0; + } + + // store return value + lua_newtable(lua); + + // set uid & euid + if (uidset != -1) + { + lua_pushstring(lua, "setuid_errno"); + lua_pushinteger(lua, setuid(uidset) != 0 ? errno : 0); + lua_settable(lua, -3); + } + if (euidset != -1) + { + lua_pushstring(lua, "seteuid_errno"); + lua_pushinteger(lua, seteuid(euidset) != 0 ? errno : 0); + lua_settable(lua, -3); + } + // get uid & euid uid_t uid = getuid(), euid = geteuid(); // push - lua_newtable(lua); lua_pushstring(lua, "uid"); lua_pushinteger(lua, uid); lua_settable(lua, -3); diff --git a/xmake/core/base/os.lua b/xmake/core/base/os.lua index 02d96ad7e..0bae655b7 100644 --- a/xmake/core/base/os.lua +++ b/xmake/core/base/os.lua @@ -627,17 +627,11 @@ function os.nuldev() end -- get uid -function os.uid() - - -- get it from cache first - if os._UID then - return os._UID - end - +function os.uid(...) -- get uid os._UID = {} if os._uid then - os._UID = os._uid() or {} + os._UID = os._uid(...) or {} end -- ok? -- cgit v1.3.1 From d4aab4ff42e4032f848e0c6f048aaa61cb7db18b Mon Sep 17 00:00:00 2001 From: TitanSnow Date: Mon, 22 May 2017 15:22:16 +0800 Subject: add os.gid() --- core/src/xmake/machine.c | 2 + core/src/xmake/makefile | 1 + core/src/xmake/os/gid.c | 155 +++++++++++++++++++++++++++++++++++++++++++++++ xmake/core/base/os.lua | 13 ++++ 4 files changed, 171 insertions(+) create mode 100644 core/src/xmake/os/gid.c diff --git a/core/src/xmake/machine.c b/core/src/xmake/machine.c index 753ff579d..a1ae497ec 100644 --- a/core/src/xmake/machine.c +++ b/core/src/xmake/machine.c @@ -83,6 +83,7 @@ tb_int_t xm_os_getwinsize(lua_State* lua); tb_int_t xm_os_versioninfo(lua_State* lua); #ifndef TB_CONFIG_OS_WINDOWS tb_int_t xm_os_uid(lua_State* lua); +tb_int_t xm_os_gid(lua_State* lua); #endif // the path functions @@ -146,6 +147,7 @@ static luaL_Reg const g_os_functions[] = , { "versioninfo", xm_os_versioninfo} #ifndef TB_CONFIG_OS_WINDOWS , { "uid", xm_os_uid } +, { "gid", xm_os_gid } #endif , { tb_null, tb_null } }; diff --git a/core/src/xmake/makefile b/core/src/xmake/makefile index b1b29ed83..f2be6405d 100644 --- a/core/src/xmake/makefile +++ b/core/src/xmake/makefile @@ -38,6 +38,7 @@ xmake_C_FILES += \ os/getwinsize \ os/versioninfo \ os/uid \ + os/gid \ path/relative \ path/absolute \ path/translate \ diff --git a/core/src/xmake/os/gid.c b/core/src/xmake/os/gid.c new file mode 100644 index 000000000..03a8c0e13 --- /dev/null +++ b/core/src/xmake/os/gid.c @@ -0,0 +1,155 @@ +/*!The Make-like Build Utility based on Lua + * + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + * + * Copyright (C) 2015 - 2017, TBOOX Open Source Group. + * + * @author TitanSnow + * @file gid.c + * + */ + +/* ////////////////////////////////////////////////////////////////////////////////////// + * trace + */ +#define TB_TRACE_MODULE_NAME "gid" +#define TB_TRACE_MODULE_DEBUG (0) + +/* ////////////////////////////////////////////////////////////////////////////////////// + * includes + */ +#include "prefix.h" +#ifndef TB_CONFIG_OS_WINDOWS +# include +# include + +/* ////////////////////////////////////////////////////////////////////////////////////// + * implementation + */ + +// get gid & egid +tb_int_t xm_os_gid(lua_State* lua) +{ + // check + tb_assert_and_check_return_val(lua, 0); + + tb_int_t gidset = -1, egidset = -1; + + tb_int_t argc = lua_gettop(lua); + + if (argc == 1) + { + if (lua_istable(lua, 1)) + { + // os.gid({["gid"] = gid, ["egid"] = egid}) + lua_getfield(lua, 1, "gid"); + lua_getfield(lua, 1, "egid"); + if (!lua_isnil(lua, -1)) + { + if (!lua_isnumber(lua, -1)) + { + lua_pushfstring(lua, "invalid field type(%s) in `egid` for os.gid", luaL_typename(lua, -1)); + lua_error(lua); + return 0; + } + egidset = (tb_int_t)lua_tonumber(lua, -1); + } + lua_pop(lua, 1); + if (!lua_isnil(lua, -1)) + { + if (!lua_isnumber(lua, -1)) + { + lua_pushfstring(lua, "invalid field type(%s) in `gid` for os.gid", luaL_typename(lua, -1)); + lua_error(lua); + return 0; + } + gidset = (tb_int_t)lua_tonumber(lua, -1); + } + lua_pop(lua, 1); + } else if (lua_isnumber(lua, 1)) + { + // os.gid(egid) + egidset = (tb_int_t)lua_tonumber(lua, 1); + } else + { + lua_pushfstring(lua, "invalid argument type(%s) for os.gid", luaL_typename(lua, 1)); + lua_error(lua); + return 0; + } + } else if (argc == 2) + { + // os.gid(gid, egid) + if (!lua_isnil(lua, 1)) + { + if (!lua_isnumber(lua, 1)) + { + lua_pushfstring(lua, "invalid argument type(%s) for os.gid", luaL_typename(lua, 1)); + lua_error(lua); + return 0; + } + gidset = (tb_int_t)lua_tonumber(lua, 1); + } + if (!lua_isnil(lua, 2)) + { + if (!lua_isnumber(lua, 2)) + { + lua_pushfstring(lua, "invalid argument type(%s) for os.gid", luaL_typename(lua, 2)); + lua_error(lua); + return 0; + } + egidset = (tb_int_t)lua_tonumber(lua, 2); + } + } else if (argc != 0) + { + lua_pushstring(lua, "invalid argument count for os.gid"); + lua_error(lua); + return 0; + } + + // store return value + lua_newtable(lua); + + // set gid & egid + if (gidset != -1) + { + lua_pushstring(lua, "setgid_errno"); + lua_pushinteger(lua, setgid(gidset) != 0 ? errno : 0); + lua_settable(lua, -3); + } + if (egidset != -1) + { + lua_pushstring(lua, "setegid_errno"); + lua_pushinteger(lua, setegid(egidset) != 0 ? errno : 0); + lua_settable(lua, -3); + } + + // get gid & egid + gid_t gid = getgid(), egid = getegid(); + + // push + lua_pushstring(lua, "gid"); + lua_pushinteger(lua, gid); + lua_settable(lua, -3); + lua_pushstring(lua, "egid"); + lua_pushinteger(lua, egid); + lua_settable(lua, -3); + + // ok + return 1; +} + +#endif diff --git a/xmake/core/base/os.lua b/xmake/core/base/os.lua index 0bae655b7..a56c199dd 100644 --- a/xmake/core/base/os.lua +++ b/xmake/core/base/os.lua @@ -34,6 +34,7 @@ local string = require("base/string") -- save original interfaces os._uid = os._uid or os.uid +os._gid = os._gid or os.gid os._mkdir = os._mkdir or os.mkdir os._rmdir = os._rmdir or os.rmdir os._tmpdir = os._tmpdir or os.tmpdir @@ -638,6 +639,18 @@ function os.uid(...) return os._UID end +-- get gid +function os.gid(...) + -- get gid + os._GID = {} + if os._gid then + os._GID = os._gid(...) or {} + end + + -- ok? + return os._GID +end + -- check run command as root function os.isroot() -- cgit v1.3.1 From b8e4fb467d8de881749e3bc77493728a642ff145 Mon Sep 17 00:00:00 2001 From: TitanSnow Date: Mon, 22 May 2017 18:33:04 +0800 Subject: add os.getown --- core/src/xmake/machine.c | 2 ++ core/src/xmake/makefile | 1 + core/src/xmake/os/getown.c | 71 ++++++++++++++++++++++++++++++++++++++++++++++ 3 files changed, 74 insertions(+) create mode 100644 core/src/xmake/os/getown.c diff --git a/core/src/xmake/machine.c b/core/src/xmake/machine.c index a1ae497ec..ccfd91254 100644 --- a/core/src/xmake/machine.c +++ b/core/src/xmake/machine.c @@ -84,6 +84,7 @@ tb_int_t xm_os_versioninfo(lua_State* lua); #ifndef TB_CONFIG_OS_WINDOWS tb_int_t xm_os_uid(lua_State* lua); tb_int_t xm_os_gid(lua_State* lua); +tb_int_t xm_os_getown(lua_State* lua); #endif // the path functions @@ -148,6 +149,7 @@ static luaL_Reg const g_os_functions[] = #ifndef TB_CONFIG_OS_WINDOWS , { "uid", xm_os_uid } , { "gid", xm_os_gid } +, { "getown", xm_os_getown } #endif , { tb_null, tb_null } }; diff --git a/core/src/xmake/makefile b/core/src/xmake/makefile index f2be6405d..c7b1ffc29 100644 --- a/core/src/xmake/makefile +++ b/core/src/xmake/makefile @@ -39,6 +39,7 @@ xmake_C_FILES += \ os/versioninfo \ os/uid \ os/gid \ + os/getown \ path/relative \ path/absolute \ path/translate \ diff --git a/core/src/xmake/os/getown.c b/core/src/xmake/os/getown.c new file mode 100644 index 000000000..aa4e2de66 --- /dev/null +++ b/core/src/xmake/os/getown.c @@ -0,0 +1,71 @@ +/*!The Make-like Build Utility based on Lua + * + * Licensed to the Apache Software Foundation (ASF) under one + * or more contributor license agreements. See the NOTICE file + * distributed with this work for additional information + * regarding copyright ownership. The ASF licenses this file + * to you under the Apache License, Version 2.0 (the + * "License"); you may not use this file except in compliance + * with the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + * + * Copyright (C) 2015 - 2017, TBOOX Open Source Group. + * + * @author TitanSnow + * @file getown.c + * + */ + +/* ////////////////////////////////////////////////////////////////////////////////////// + * trace + */ +#define TB_TRACE_MODULE_NAME "getown" +#define TB_TRACE_MODULE_DEBUG (0) + +/* ////////////////////////////////////////////////////////////////////////////////////// + * includes + */ +#include "prefix.h" +#ifndef TB_CONFIG_OS_WINDOWS +# include +# include + +/* ////////////////////////////////////////////////////////////////////////////////////// + * implementation + */ +// get owner by a given path +tb_int_t xm_os_getown(lua_State* lua) +{ + // check + tb_assert_and_check_return_val(lua, 0); + + // get the pathname + tb_char_t const* pathname = luaL_checkstring(lua, 1); + tb_check_return_val(pathname, 0); + + // get stat + struct stat sts; + if(stat(pathname, &sts) != 0) + return 0; + + // push + lua_newtable(lua); + lua_pushstring(lua, "uid"); + lua_pushinteger(lua, sts.st_uid); + lua_settable(lua, -3); + lua_pushstring(lua, "gid"); + lua_pushinteger(lua, sts.st_gid); + lua_settable(lua, -3); + + // ok + return 1; +} + +#endif -- cgit v1.3.1 From bd775f017f77043aac5b6290c9899f7daf23e172 Mon Sep 17 00:00:00 2001 From: TitanSnow Date: Mon, 22 May 2017 19:37:24 +0800 Subject: add module privilege to manage root privilege --- xmake/core/base/os.lua | 6 +- xmake/core/base/privilege.lua | 92 ++++++++++++++++++++++ xmake/core/main.lua | 9 ++- .../sandbox/modules/import/core/base/privilege.lua | 26 ++++++ 4 files changed, 125 insertions(+), 8 deletions(-) create mode 100644 xmake/core/base/privilege.lua create mode 100644 xmake/core/sandbox/modules/import/core/base/privilege.lua diff --git a/xmake/core/base/os.lua b/xmake/core/base/os.lua index a56c199dd..ea6d3a9b0 100644 --- a/xmake/core/base/os.lua +++ b/xmake/core/base/os.lua @@ -653,11 +653,7 @@ end -- check run command as root function os.isroot() - - -- get it from cache - if os._ISROOT ~= nil then - return os._ISROOT - end + os._ISROOT = nil -- check it if os.uid().euid == 0 then diff --git a/xmake/core/base/privilege.lua b/xmake/core/base/privilege.lua new file mode 100644 index 000000000..5c66ba5f1 --- /dev/null +++ b/xmake/core/base/privilege.lua @@ -0,0 +1,92 @@ +--!The Make-like Build Utility based on Lua +-- +-- Licensed to the Apache Software Foundation (ASF) under one +-- or more contributor license agreements. See the NOTICE file +-- distributed with this work for additional information +-- regarding copyright ownership. The ASF licenses this file +-- to you under the Apache License, Version 2.0 (the +-- "License"); you may not use this file except in compliance +-- with the License. You may obtain a copy of the License at +-- +-- http://www.apache.org/licenses/LICENSE-2.0 +-- +-- Unless required by applicable law or agreed to in writing, software +-- distributed under the License is distributed on an "AS IS" BASIS, +-- WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +-- See the License for the specific language governing permissions and +-- limitations under the License. +-- +-- Copyright (C) 2015 - 2017, TBOOX Open Source Group. +-- +-- @author TitanSnow +-- @file privilege.lua +-- + +-- define module +local privilege = privilege or {} + +-- load modules +local os = require("base/os") + +-- store privilege +function privilege.store() + -- check if root + if not os.isroot() then + return false + end + + -- find projectdir's owner + local projectdir = xmake._PROJECT_DIR + assert(projectdir) + local owner = os.getown(projectdir) + if not owner then + -- fallback to current dir + owner = os.getown(".") + if not owner then + return false + end + end + + -- set gid + if os.gid(owner.gid).setegid_errno ~= 0 then + return false + end + + -- set uid + if os.uid(owner.uid).seteuid_errno ~= 0 then + return false + end + + -- set flag + privilege._HAS_PRIVILEGE = true + + -- ok + return true +end + +-- check if has stored privilege +function privilege.has() + return privilege._HAS_PRIVILEGE or false +end + +function privilege.get() + -- has? + if privilege._HAS_PRIVILEGE ~= true then + return false + end + + -- set uid + if os.uid(0).seteuid_errno ~= 0 then + return false + end + + -- set gid + if os.gid(0).setegid_errno ~= 0 then + return false + end + + return true +end + +-- return module +return privilege diff --git a/xmake/core/main.lua b/xmake/core/main.lua index b4ca6afab..cda338294 100644 --- a/xmake/core/main.lua +++ b/xmake/core/main.lua @@ -32,6 +32,7 @@ local utils = require("base/utils") local option = require("base/option") local profiler = require("base/profiler") local deprecated = require("base/deprecated") +local privilege = require("base/privilege") local task = require("project/task") local history = require("project/history") @@ -143,12 +144,14 @@ function main.done() -- check run command as root if not option.get("root") then if os.isroot() then - utils.error([[Running xmake as root is extremely dangerous and no longer supported. + if not privilege.store() or os.isroot() then + utils.error([[Running xmake as root is extremely dangerous and no longer supported. As xmake does not drop privileges on installation you would be giving all build scripts full access to your system. Or you can add `--root` option to allow run as root temporarily. - ]]) - return -1 + ]]) + return -1 + end end end diff --git a/xmake/core/sandbox/modules/import/core/base/privilege.lua b/xmake/core/sandbox/modules/import/core/base/privilege.lua new file mode 100644 index 000000000..8f94cdb79 --- /dev/null +++ b/xmake/core/sandbox/modules/import/core/base/privilege.lua @@ -0,0 +1,26 @@ +--!The Make-like Build Utility based on Lua +-- +-- Licensed to the Apache Software Foundation (ASF) under one +-- or more contributor license agreements. See the NOTICE file +-- distributed with this work for additional information +-- regarding copyright ownership. The ASF licenses this file +-- to you under the Apache License, Version 2.0 (the +-- "License"); you may not use this file except in compliance +-- with the License. You may obtain a copy of the License at +-- +-- http://www.apache.org/licenses/LICENSE-2.0 +-- +-- Unless required by applicable law or agreed to in writing, software +-- distributed under the License is distributed on an "AS IS" BASIS, +-- WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +-- See the License for the specific language governing permissions and +-- limitations under the License. +-- +-- Copyright (C) 2015 - 2017, TBOOX Open Source Group. +-- +-- @author TitanSnow +-- @file privilege.lua +-- + +-- return module +return require("base/privilege") -- cgit v1.3.1 From 5e36555036052217345596a1bab1e859ffaa8db0 Mon Sep 17 00:00:00 2001 From: TitanSnow Date: Mon, 22 May 2017 20:02:51 +0800 Subject: get privilege while installing --- xmake/actions/install/main.lua | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/xmake/actions/install/main.lua b/xmake/actions/install/main.lua index 3ca155789..f9bca9419 100644 --- a/xmake/actions/install/main.lua +++ b/xmake/actions/install/main.lua @@ -26,6 +26,7 @@ import("core.base.option") import("core.project.task") import("core.platform.platform") +import("core.base.privilege") import("install") -- main @@ -57,6 +58,28 @@ function main() -- failed or not permission? request administrator permission and install it again function (errors) + -- try get privilege + if privilege.get() then + local ok = try + { + function () + -- install target + install.install(targetname or ifelse(option.get("all"), "__all", "__def")) + + -- trace + cprint("${bright}install ok!${clear}${ok_hand}") + + -- ok + return true + end + } + + -- release privilege + privilege.store() + + if ok then return end + end + -- show tips cprint("${bright red}error: ${default red}installation failed, may permission denied!") -- cgit v1.3.1 From 7b2bd5ca66ae8ed9f890d32f86fee9501d84968a Mon Sep 17 00:00:00 2001 From: TitanSnow Date: Mon, 22 May 2017 20:15:24 +0800 Subject: use privilege while uninstalling --- xmake/actions/uninstall/main.lua | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+) diff --git a/xmake/actions/uninstall/main.lua b/xmake/actions/uninstall/main.lua index a7cfec3db..2b25a058d 100644 --- a/xmake/actions/uninstall/main.lua +++ b/xmake/actions/uninstall/main.lua @@ -26,6 +26,7 @@ import("core.base.option") import("core.project.task") import("core.platform.platform") +import("core.base.privilege") import("uninstall") -- main @@ -57,6 +58,28 @@ function main() -- failed or not permission? request administrator permission and uninstall it again function (errors) + -- try get privilege + if privilege.get() then + local ok = try + { + function () + -- uninstall target + uninstall.uninstall(targetname) + + -- trace + cprint("${bright}uninstall ok!${clear}${ok_hand}") + + -- ok + return true + end + } + + -- release privilege + privilege.store() + + if ok then return end + end + -- show tips cprint("${bright red}error: ${default red}failed to uninstall, may permission denied!") -- cgit v1.3.1 From ce5c4be20bb79418ec63b705952e3ef383b130eb Mon Sep 17 00:00:00 2001 From: TitanSnow Date: Tue, 23 May 2017 07:45:22 +0800 Subject: use setreuid --- core/src/xmake/os/gid.c | 39 +++++++++++++++------------------------ core/src/xmake/os/uid.c | 39 +++++++++++++++------------------------ 2 files changed, 30 insertions(+), 48 deletions(-) diff --git a/core/src/xmake/os/gid.c b/core/src/xmake/os/gid.c index 03a8c0e13..e3506514d 100644 --- a/core/src/xmake/os/gid.c +++ b/core/src/xmake/os/gid.c @@ -41,13 +41,13 @@ * implementation */ -// get gid & egid +// get & set gid tb_int_t xm_os_gid(lua_State* lua) { // check tb_assert_and_check_return_val(lua, 0); - tb_int_t gidset = -1, egidset = -1; + tb_int_t rgidset = -1, egidset = -1; tb_int_t argc = lua_gettop(lua); @@ -55,8 +55,8 @@ tb_int_t xm_os_gid(lua_State* lua) { if (lua_istable(lua, 1)) { - // os.gid({["gid"] = gid, ["egid"] = egid}) - lua_getfield(lua, 1, "gid"); + // os.gid({["rgid"] = rgid, ["egid"] = egid}) + lua_getfield(lua, 1, "rgid"); lua_getfield(lua, 1, "egid"); if (!lua_isnil(lua, -1)) { @@ -73,17 +73,17 @@ tb_int_t xm_os_gid(lua_State* lua) { if (!lua_isnumber(lua, -1)) { - lua_pushfstring(lua, "invalid field type(%s) in `gid` for os.gid", luaL_typename(lua, -1)); + lua_pushfstring(lua, "invalid field type(%s) in `rgid` for os.gid", luaL_typename(lua, -1)); lua_error(lua); return 0; } - gidset = (tb_int_t)lua_tonumber(lua, -1); + rgidset = (tb_int_t)lua_tonumber(lua, -1); } lua_pop(lua, 1); } else if (lua_isnumber(lua, 1)) { - // os.gid(egid) - egidset = (tb_int_t)lua_tonumber(lua, 1); + // os.gid(gid) + rgidset = egidset = (tb_int_t)lua_tonumber(lua, 1); } else { lua_pushfstring(lua, "invalid argument type(%s) for os.gid", luaL_typename(lua, 1)); @@ -92,7 +92,7 @@ tb_int_t xm_os_gid(lua_State* lua) } } else if (argc == 2) { - // os.gid(gid, egid) + // os.gid(rgid, egid) if (!lua_isnil(lua, 1)) { if (!lua_isnumber(lua, 1)) @@ -101,7 +101,7 @@ tb_int_t xm_os_gid(lua_State* lua) lua_error(lua); return 0; } - gidset = (tb_int_t)lua_tonumber(lua, 1); + rgidset = (tb_int_t)lua_tonumber(lua, 1); } if (!lua_isnil(lua, 2)) { @@ -123,25 +123,16 @@ tb_int_t xm_os_gid(lua_State* lua) // store return value lua_newtable(lua); - // set gid & egid - if (gidset != -1) - { - lua_pushstring(lua, "setgid_errno"); - lua_pushinteger(lua, setgid(gidset) != 0 ? errno : 0); - lua_settable(lua, -3); - } - if (egidset != -1) - { - lua_pushstring(lua, "setegid_errno"); - lua_pushinteger(lua, setegid(egidset) != 0 ? errno : 0); - lua_settable(lua, -3); - } + // set rgid & egid + lua_pushstring(lua, "errno"); + lua_pushinteger(lua, setregid(rgidset, egidset) != 0 ? errno : 0); + lua_settable(lua, -3); // get gid & egid gid_t gid = getgid(), egid = getegid(); // push - lua_pushstring(lua, "gid"); + lua_pushstring(lua, "rgid"); lua_pushinteger(lua, gid); lua_settable(lua, -3); lua_pushstring(lua, "egid"); diff --git a/core/src/xmake/os/uid.c b/core/src/xmake/os/uid.c index 0c67a3edf..2c173b868 100644 --- a/core/src/xmake/os/uid.c +++ b/core/src/xmake/os/uid.c @@ -41,13 +41,13 @@ * implementation */ -// get uid & euid +// get & set uid tb_int_t xm_os_uid(lua_State* lua) { // check tb_assert_and_check_return_val(lua, 0); - tb_int_t uidset = -1, euidset = -1; + tb_int_t ruidset = -1, euidset = -1; tb_int_t argc = lua_gettop(lua); @@ -55,8 +55,8 @@ tb_int_t xm_os_uid(lua_State* lua) { if (lua_istable(lua, 1)) { - // os.uid({["uid"] = uid, ["euid"] = euid}) - lua_getfield(lua, 1, "uid"); + // os.uid({["ruid"] = ruid, ["euid"] = euid}) + lua_getfield(lua, 1, "ruid"); lua_getfield(lua, 1, "euid"); if (!lua_isnil(lua, -1)) { @@ -73,17 +73,17 @@ tb_int_t xm_os_uid(lua_State* lua) { if (!lua_isnumber(lua, -1)) { - lua_pushfstring(lua, "invalid field type(%s) in `uid` for os.uid", luaL_typename(lua, -1)); + lua_pushfstring(lua, "invalid field type(%s) in `ruid` for os.uid", luaL_typename(lua, -1)); lua_error(lua); return 0; } - uidset = (tb_int_t)lua_tonumber(lua, -1); + ruidset = (tb_int_t)lua_tonumber(lua, -1); } lua_pop(lua, 1); } else if (lua_isnumber(lua, 1)) { - // os.uid(euid) - euidset = (tb_int_t)lua_tonumber(lua, 1); + // os.uid(uid) + ruidset = euidset = (tb_int_t)lua_tonumber(lua, 1); } else { lua_pushfstring(lua, "invalid argument type(%s) for os.uid", luaL_typename(lua, 1)); @@ -92,7 +92,7 @@ tb_int_t xm_os_uid(lua_State* lua) } } else if (argc == 2) { - // os.uid(uid, euid) + // os.uid(ruid, euid) if (!lua_isnil(lua, 1)) { if (!lua_isnumber(lua, 1)) @@ -101,7 +101,7 @@ tb_int_t xm_os_uid(lua_State* lua) lua_error(lua); return 0; } - uidset = (tb_int_t)lua_tonumber(lua, 1); + ruidset = (tb_int_t)lua_tonumber(lua, 1); } if (!lua_isnil(lua, 2)) { @@ -123,25 +123,16 @@ tb_int_t xm_os_uid(lua_State* lua) // store return value lua_newtable(lua); - // set uid & euid - if (uidset != -1) - { - lua_pushstring(lua, "setuid_errno"); - lua_pushinteger(lua, setuid(uidset) != 0 ? errno : 0); - lua_settable(lua, -3); - } - if (euidset != -1) - { - lua_pushstring(lua, "seteuid_errno"); - lua_pushinteger(lua, seteuid(euidset) != 0 ? errno : 0); - lua_settable(lua, -3); - } + // set ruid & euid + lua_pushstring(lua, "errno"); + lua_pushinteger(lua, setreuid(ruidset, euidset) != 0 ? errno : 0); + lua_settable(lua, -3); // get uid & euid uid_t uid = getuid(), euid = geteuid(); // push - lua_pushstring(lua, "uid"); + lua_pushstring(lua, "ruid"); lua_pushinteger(lua, uid); lua_settable(lua, -3); lua_pushstring(lua, "euid"); -- cgit v1.3.1 From c78a2867af7dca124aecbd56ecf6e0490b2a78c9 Mon Sep 17 00:00:00 2001 From: TitanSnow Date: Tue, 23 May 2017 07:57:13 +0800 Subject: do not set if no param --- core/src/xmake/os/gid.c | 11 +++++++---- core/src/xmake/os/uid.c | 11 +++++++---- 2 files changed, 14 insertions(+), 8 deletions(-) diff --git a/core/src/xmake/os/gid.c b/core/src/xmake/os/gid.c index e3506514d..7d949ebc6 100644 --- a/core/src/xmake/os/gid.c +++ b/core/src/xmake/os/gid.c @@ -123,10 +123,13 @@ tb_int_t xm_os_gid(lua_State* lua) // store return value lua_newtable(lua); - // set rgid & egid - lua_pushstring(lua, "errno"); - lua_pushinteger(lua, setregid(rgidset, egidset) != 0 ? errno : 0); - lua_settable(lua, -3); + if (rgidset != -1 || egidset != -1) + { + // set rgid & egid + lua_pushstring(lua, "errno"); + lua_pushinteger(lua, setregid(rgidset, egidset) != 0 ? errno : 0); + lua_settable(lua, -3); + } // get gid & egid gid_t gid = getgid(), egid = getegid(); diff --git a/core/src/xmake/os/uid.c b/core/src/xmake/os/uid.c index 2c173b868..4bcc9d122 100644 --- a/core/src/xmake/os/uid.c +++ b/core/src/xmake/os/uid.c @@ -123,10 +123,13 @@ tb_int_t xm_os_uid(lua_State* lua) // store return value lua_newtable(lua); - // set ruid & euid - lua_pushstring(lua, "errno"); - lua_pushinteger(lua, setreuid(ruidset, euidset) != 0 ? errno : 0); - lua_settable(lua, -3); + if (ruidset != -1 || euidset != -1) + { + // set ruid & euid + lua_pushstring(lua, "errno"); + lua_pushinteger(lua, setreuid(ruidset, euidset) != 0 ? errno : 0); + lua_settable(lua, -3); + } // get uid & euid uid_t uid = getuid(), euid = geteuid(); -- cgit v1.3.1 From 2cb7a91bf266680266de51636ce6620cbecc9362 Mon Sep 17 00:00:00 2001 From: TitanSnow Date: Tue, 23 May 2017 07:59:21 +0800 Subject: fix privilege --- xmake/core/base/privilege.lua | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/xmake/core/base/privilege.lua b/xmake/core/base/privilege.lua index 5c66ba5f1..275a7e7b5 100644 --- a/xmake/core/base/privilege.lua +++ b/xmake/core/base/privilege.lua @@ -48,12 +48,12 @@ function privilege.store() end -- set gid - if os.gid(owner.gid).setegid_errno ~= 0 then + if os.gid(owner.gid).errno ~= 0 then return false end -- set uid - if os.uid(owner.uid).seteuid_errno ~= 0 then + if os.uid({["ruid"] = owner.uid}).errno ~= 0 or os.uid({["euid"] = owner.uid}).errno ~= 0 then return false end @@ -76,12 +76,12 @@ function privilege.get() end -- set uid - if os.uid(0).seteuid_errno ~= 0 then + if os.uid({["euid"] = 0}).errno ~= 0 or os.uid({["ruid"] = 0}).errno ~= 0 then return false end -- set gid - if os.gid(0).setegid_errno ~= 0 then + if os.gid(0).errno ~= 0 then return false end -- cgit v1.3.1