Move Linux's no_new_privs call into os_calls
This helps keep the application code free of platform-specific cruft. Also remove a needless #include<sys/prctl.h> from sesman/session_list.c.
This commit is contained in:
@@ -53,6 +53,9 @@
|
||||
#include <sys/stat.h>
|
||||
#include <sys/ipc.h>
|
||||
#include <sys/shm.h>
|
||||
#if defined(HAVE_SYS_PRCTL_H)
|
||||
#include <sys/prctl.h>
|
||||
#endif
|
||||
#include <dlfcn.h>
|
||||
#include <arpa/inet.h>
|
||||
#include <netdb.h>
|
||||
@@ -3954,3 +3957,19 @@ g_tcp6_bind_address(int sck, const char *port, const char *address)
|
||||
return -1;
|
||||
#endif
|
||||
}
|
||||
|
||||
/*****************************************************************************/
|
||||
/* returns error, zero is success, non zero is error */
|
||||
/* only works in linux */
|
||||
int
|
||||
g_no_new_privs(void)
|
||||
{
|
||||
#if defined(HAVE_SYS_PRCTL_H) && defined(PR_SET_NO_NEW_PRIVS)
|
||||
/*
|
||||
* PR_SET_NO_NEW_PRIVS requires Linux kernel 3.5 and newer.
|
||||
*/
|
||||
return prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0);
|
||||
#else
|
||||
return 0;
|
||||
#endif
|
||||
}
|
||||
|
||||
@@ -333,6 +333,7 @@ int g_tcp4_socket(void);
|
||||
int g_tcp4_bind_address(int sck, const char *port, const char *address);
|
||||
int g_tcp6_socket(void);
|
||||
int g_tcp6_bind_address(int sck, const char *port, const char *address);
|
||||
int g_no_new_privs(void);
|
||||
|
||||
/* glib-style wrappers */
|
||||
#define g_new(struct_type, n_structs) \
|
||||
|
||||
@@ -33,10 +33,6 @@
|
||||
#include "config_ac.h"
|
||||
#endif
|
||||
|
||||
#ifdef HAVE_SYS_PRCTL_H
|
||||
#include <sys/prctl.h>
|
||||
#endif
|
||||
|
||||
#include <errno.h>
|
||||
|
||||
#include "arch.h"
|
||||
@@ -56,10 +52,6 @@
|
||||
#include "xwait.h"
|
||||
#include "xrdp_sockets.h"
|
||||
|
||||
#ifndef PR_SET_NO_NEW_PRIVS
|
||||
#define PR_SET_NO_NEW_PRIVS 38
|
||||
#endif
|
||||
|
||||
struct session_data
|
||||
{
|
||||
pid_t x_server; ///< PID of X server
|
||||
@@ -347,21 +339,18 @@ prepare_xorg_xserver_params(const struct session_parameters *s,
|
||||
{
|
||||
params->auto_free = 1;
|
||||
|
||||
#ifdef HAVE_SYS_PRCTL_H
|
||||
/*
|
||||
* Make sure Xorg doesn't run setuid root. Root access is not
|
||||
* needed. Xorg can fail when run as root and the user has no
|
||||
* console permissions.
|
||||
* PR_SET_NO_NEW_PRIVS requires Linux kernel 3.5 and newer.
|
||||
*/
|
||||
if (prctl(PR_SET_NO_NEW_PRIVS, 1, 0, 0, 0) < 0)
|
||||
if (g_no_new_privs() != 0)
|
||||
{
|
||||
LOG(LOG_LEVEL_WARNING,
|
||||
"[session start] (display %u): Failed to disable "
|
||||
"setuid on X server: %s",
|
||||
s->display, g_get_strerror());
|
||||
}
|
||||
#endif
|
||||
|
||||
g_snprintf(screen, sizeof(screen), ":%u", s->display);
|
||||
|
||||
|
||||
@@ -33,10 +33,6 @@
|
||||
#include "config_ac.h"
|
||||
#endif
|
||||
|
||||
#ifdef HAVE_SYS_PRCTL_H
|
||||
#include <sys/prctl.h>
|
||||
#endif
|
||||
|
||||
#include "arch.h"
|
||||
#include "session_list.h"
|
||||
#include "trans.h"
|
||||
|
||||
Reference in New Issue
Block a user