summaryrefslogtreecommitdiffstats
path: root/contrib/sendmail/test/t_setgid.c
blob: dfe180587a402e0d9b43fc49bc5ca767972bee2f (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
/*
 * Copyright (c) 2001 Sendmail, Inc. and its suppliers.
 *	All rights reserved.
 *
 * By using this file, you agree to the terms and conditions set
 * forth in the LICENSE file which can be found at the top level of
 * the sendmail distribution.
 *
 */

/*
**  This program checks to see if your version of setgid works.
**  Compile it, make it set-group-ID guest, and run it as yourself (NOT as
**  root and not as member of the group guest).
**
**  Compilation is trivial -- just "cc t_setgid.c".  Make it set-group-ID,
**  guest and then execute it as a non-root user.
*/

#include <sys/types.h>
#include <unistd.h>
#include <stdio.h>

#ifndef lint
static char id[] = "@(#)$Id: t_setgid.c,v 1.6 2001/09/23 03:35:41 ca Exp $";
#endif /* ! lint */

static void
printgids(str, r, e)
	char *str;
	gid_t r, e;
{
	printf("%s (should be %d/%d): r/egid=%d/%d\n", str, (int) r, (int) e,
	       (int) getgid(), (int) getegid());
}

int
main(argc, argv)
	int argc;
	char **argv;
{
	int fail = 0;
	int res;
	gid_t realgid = getgid();
	gid_t effgid = getegid();

	printgids("initial gids", realgid, effgid);

	if (effgid == realgid)
	{
		printf("SETUP ERROR: re-run set-group-ID guest\n");
		exit(1);
	}

#if SM_CONF_SETREGID
	res = setregid(effgid, effgid);
#else /* SM_CONF_SETREGID */
	res = setgid(effgid);
#endif /* SM_CONF_SETREGID */

	printf("setgid(%d)=%d %s\n", (int) effgid, res,
		res < 0 ? "failure" : "ok");
#if SM_CONF_SETREGID
	printgids("after setregid()", effgid, effgid);
#else /* SM_CONF_SETREGID */
	printgids("after setgid()", effgid, effgid);
#endif /* SM_CONF_SETREGID */

	if (getegid() != effgid)
	{
		fail++;
		printf("MAYDAY!  Wrong effective gid\n");
	}

	if (getgid() != effgid)
	{
		fail++;
		printf("MAYDAY!  Wrong real gid\n");
	}

	/* do activity here */
	if (setgid(0) == 0)
	{
		fail++;
		printf("MAYDAY!  setgid(0) succeeded (should have failed)\n");
	}
	else
	{
		printf("setgid(0) failed (this is correct)\n");
	}
	printgids("after setgid(0)", effgid, effgid);

	if (getegid() != effgid)
	{
		fail++;
		printf("MAYDAY!  Wrong effective gid\n");
	}
	if (getgid() != effgid)
	{
		fail++;
		printf("MAYDAY!  Wrong real gid\n");
	}
	printf("\n");

	if (fail > 0)
	{
		printf("\nThis system cannot use %s to set the real gid to the effective gid\nand clear the saved gid.\n",
#if SM_CONF_SETREGID
			"setregid"
#else /* SM_CONF_SETREGID */
			"setgid"
#endif /* SM_CONF_SETREGID */
			);
		exit(1);
	}

	printf("\nIt is possible to use setgid on this system\n");
	exit(0);
}
OpenPOWER on IntegriCloud