File: drop_privs.c

package info (click to toggle)
mimedefang 2.64-6
  • links: PTS
  • area: main
  • in suites: lenny
  • size: 1,888 kB
  • ctags: 624
  • sloc: ansic: 8,338; perl: 6,380; sh: 1,555; tcl: 693; makefile: 71; php: 19
file content (58 lines) | stat: -rw-r--r-- 1,553 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
/***********************************************************************
*
* drop_privs.c
*
* Defines the "drop_privs" function which switches to specified user name.
*
* Copyright (C) 2002-2003 by Roaring Penguin Software Inc.
* http://www.roaringpenguin.com
*
* This program may be distributed under the terms of the GNU General
* Public License, Version 2, or (at your option) any later version.
*
***********************************************************************/

static char const RCSID[] =
"$Id$";

#include "config.h"
#include <sys/types.h>
#include <unistd.h>
#include <syslog.h>
#include <grp.h>

/**********************************************************************
* %FUNCTION: drop_privs
* %ARGUMENTS:
*  user -- name of user to become
*  uid, gid -- uid and gid to use
* %RETURNS:
*  0 on success; -1 on failure.
* %DESCRIPTION:
*  Switches uid to uid of "user"; also enters that user's group and calls
*  initgroups.
***********************************************************************/
int
drop_privs(char const *user, uid_t uid, gid_t gid)
{
    /* Call initgroups */
#ifdef HAVE_INITGROUPS
    if (initgroups((char *) user, gid) < 0) {
	syslog(LOG_ERR, "drop_privs: initgroups for '%s' failed: %m", user);
	return -1;
    }
#endif

    /* Call setgid */
    if (setgid(gid) < 0) {
	syslog(LOG_ERR, "drop_privs: setgid for '%s' failed: %m", user);
	return -1;
    }

    /* Finally, call setuid */
    if (setuid(uid) < 0) {
	syslog(LOG_ERR, "drop_privs: setuid for '%s' failed: %m", user);
	return -1;
    }
    return 0;
}