Log a little more when credential-switching fails.

svn:r17228
This commit is contained in:
Nick Mathewson 2008-11-09 16:54:54 +00:00
parent dcfbd1e024
commit 13e079f9ec

View File

@ -1052,32 +1052,32 @@ switch_id(const char *user)
/* Properly switch egid,gid,euid,uid here or bail out */ /* Properly switch egid,gid,euid,uid here or bail out */
if (setgroups(1, &pw->pw_gid)) { if (setgroups(1, &pw->pw_gid)) {
log_warn(LD_GENERAL, "Error setting configured groups: %s", log_warn(LD_GENERAL, "Error setting groups to gid %d: %s",
strerror(errno)); (int)pw->pw_gid, strerror(errno));
return -1; return -1;
} }
if (setegid(pw->pw_gid)) { if (setegid(pw->pw_gid)) {
log_warn(LD_GENERAL, "Error setting configured egid: %s", log_warn(LD_GENERAL, "Error setting egid to %d: %s",
strerror(errno)); (int)pw->pw_gid, strerror(errno));
return -1; return -1;
} }
if (setgid(pw->pw_gid)) { if (setgid(pw->pw_gid)) {
log_warn(LD_GENERAL, "Error setting configured gid: %s", log_warn(LD_GENERAL, "Error setting gid to %d: %s",
strerror(errno)); (int)pw->pw_gid, strerror(errno));
return -1; return -1;
} }
if (setuid(pw->pw_uid)) { if (setuid(pw->pw_uid)) {
log_warn(LD_GENERAL, "Error setting configured uid: %s", log_warn(LD_GENERAL, "Error setting configured uid to %s (%d): %s",
strerror(errno)); user, (int)pw->pw_uid, strerror(errno));
return -1; return -1;
} }
if (seteuid(pw->pw_uid)) { if (seteuid(pw->pw_uid)) {
log_warn(LD_GENERAL, "Error setting configured euid: %s", log_warn(LD_GENERAL, "Error setting configured euid to %s (%d): %s",
strerror(errno)); user, (int)pw->pw_uid, strerror(errno));
return -1; return -1;
} }
@ -1103,14 +1103,16 @@ switch_id(const char *user)
/* Try changing GID/EGID */ /* Try changing GID/EGID */
if (pw->pw_gid != old_gid && if (pw->pw_gid != old_gid &&
(setgid(old_gid) != -1 || setegid(old_gid) != -1)) { (setgid(old_gid) != -1 || setegid(old_gid) != -1)) {
log_warn(LD_GENERAL, "Was able to restore group credentials"); log_warn(LD_GENERAL, "Was able to restore group credentials even after "
"switching GID: this means that the setgid code didn't work.");
return -1; return -1;
} }
/* Try changing UID/EUID */ /* Try changing UID/EUID */
if (pw->pw_uid != old_uid && if (pw->pw_uid != old_uid &&
(setuid(old_uid) != -1 || seteuid(old_uid) != -1)) { (setuid(old_uid) != -1 || seteuid(old_uid) != -1)) {
log_warn(LD_GENERAL, "Was able to restore user credentials"); log_warn(LD_GENERAL, "Was able to restore user credentials even after "
"switching UID: this means that the setuid code didn't work.");
return -1; return -1;
} }
} }