1997-03-31 15:59:14 +00:00
|
|
|
.\" $OpenBSD: issetugid.2,v 1.7 1997/02/18 00:16:09 deraadt Exp $
|
|
|
|
.\"
|
|
|
|
.\" Copyright (c) 1980, 1991, 1993
|
|
|
|
.\" The Regents of the University of California. All rights reserved.
|
|
|
|
.\"
|
|
|
|
.\" Redistribution and use in source and binary forms, with or without
|
|
|
|
.\" modification, are permitted provided that the following conditions
|
|
|
|
.\" are met:
|
|
|
|
.\" 1. Redistributions of source code must retain the above copyright
|
|
|
|
.\" notice, this list of conditions and the following disclaimer.
|
|
|
|
.\" 2. Redistributions in binary form must reproduce the above copyright
|
|
|
|
.\" notice, this list of conditions and the following disclaimer in the
|
|
|
|
.\" documentation and/or other materials provided with the distribution.
|
|
|
|
.\" 4. Neither the name of the University nor the names of its contributors
|
|
|
|
.\" may be used to endorse or promote products derived from this software
|
|
|
|
.\" without specific prior written permission.
|
|
|
|
.\"
|
|
|
|
.\" THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
|
|
|
|
.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
|
|
|
|
.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
|
|
|
|
.\" ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
|
|
|
|
.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
|
|
|
|
.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
|
|
|
|
.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
|
|
|
|
.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
|
|
|
|
.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
|
|
|
|
.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
|
|
|
|
.\" SUCH DAMAGE.
|
|
|
|
.\"
|
1999-08-28 00:22:10 +00:00
|
|
|
.\" $FreeBSD$
|
1997-03-31 16:36:14 +00:00
|
|
|
.\"
|
2000-12-11 15:15:20 +00:00
|
|
|
.Dd August 25, 1996
|
1997-03-31 15:59:14 +00:00
|
|
|
.Dt ISSETUGID 2
|
1997-03-31 16:36:14 +00:00
|
|
|
.Os
|
1997-03-31 15:59:14 +00:00
|
|
|
.Sh NAME
|
|
|
|
.Nm issetugid
|
1997-03-31 16:36:14 +00:00
|
|
|
.Nd is current process tainted by uid or gid changes
|
2000-04-21 09:42:15 +00:00
|
|
|
.Sh LIBRARY
|
|
|
|
.Lb libc
|
1997-03-31 15:59:14 +00:00
|
|
|
.Sh SYNOPSIS
|
2001-10-01 16:09:29 +00:00
|
|
|
.In unistd.h
|
1997-03-31 15:59:14 +00:00
|
|
|
.Ft int
|
|
|
|
.Fn issetugid void
|
|
|
|
.Sh DESCRIPTION
|
|
|
|
The
|
|
|
|
.Fn issetugid
|
2002-12-18 09:22:32 +00:00
|
|
|
system call returns 1 if the process environment or memory address space
|
1999-09-05 07:02:22 +00:00
|
|
|
is considered
|
|
|
|
.Dq tainted ,
|
|
|
|
and returns 0 otherwise.
|
1997-03-31 15:59:14 +00:00
|
|
|
.Pp
|
1997-03-31 16:36:14 +00:00
|
|
|
A process is tainted if it was created as a result of an
|
|
|
|
.Xr execve 2
|
|
|
|
system call which had either of the setuid or setgid bits set (and extra
|
2001-04-15 19:53:47 +00:00
|
|
|
privileges were given as a result) or if it has changed any of its real,
|
1997-03-31 16:36:14 +00:00
|
|
|
effective or saved user or group ID's since it began execution.
|
1997-03-31 15:59:14 +00:00
|
|
|
.Pp
|
1997-03-31 16:36:14 +00:00
|
|
|
This system call exists so that library routines (eg: libc, libtermcap)
|
|
|
|
can reliably determine if it is safe to use information
|
|
|
|
that was obtained from the user, in particular the results from
|
|
|
|
.Xr getenv 3
|
|
|
|
should be viewed with suspicion if it is used to control operation.
|
|
|
|
.Pp
|
1999-09-05 07:02:22 +00:00
|
|
|
A
|
|
|
|
.Dq tainted
|
|
|
|
status is inherited by child processes as a result of the
|
1997-03-31 16:36:14 +00:00
|
|
|
.Xr fork 2
|
|
|
|
system call (or other library code that calls fork, such as
|
1997-04-01 18:45:57 +00:00
|
|
|
.Xr popen 3 ) .
|
1997-03-31 16:36:14 +00:00
|
|
|
.Pp
|
|
|
|
It is assumed that a program that clears all privileges as it prepares
|
1999-09-05 07:02:22 +00:00
|
|
|
to execute another will also reset the environment, hence the
|
|
|
|
.Dq tainted
|
2004-07-02 23:52:20 +00:00
|
|
|
status will not be passed on.
|
|
|
|
This is important for programs such as
|
1997-03-31 16:36:14 +00:00
|
|
|
.Xr su 1
|
|
|
|
which begin setuid but need to be able to create an untainted process.
|
1997-03-31 15:59:14 +00:00
|
|
|
.Sh ERRORS
|
|
|
|
The
|
|
|
|
.Fn issetugid
|
2002-12-18 09:22:32 +00:00
|
|
|
system call is always successful, and no return value is reserved to
|
1997-03-31 15:59:14 +00:00
|
|
|
indicate an error.
|
|
|
|
.Sh SEE ALSO
|
|
|
|
.Xr execve 2 ,
|
1997-03-31 16:36:14 +00:00
|
|
|
.Xr fork 2 ,
|
|
|
|
.Xr setegid 2 ,
|
|
|
|
.Xr seteuid 2 ,
|
1997-09-29 19:11:55 +00:00
|
|
|
.Xr setgid 2 ,
|
1997-03-31 16:36:14 +00:00
|
|
|
.Xr setregid 2 ,
|
1997-04-01 18:50:56 +00:00
|
|
|
.Xr setreuid 2 ,
|
1997-03-31 16:36:14 +00:00
|
|
|
.Xr setuid 2
|
1997-03-31 15:59:14 +00:00
|
|
|
.Sh HISTORY
|
2002-12-18 09:22:32 +00:00
|
|
|
The
|
1997-03-31 16:36:14 +00:00
|
|
|
.Fn issetugid
|
2002-12-18 09:22:32 +00:00
|
|
|
system call first appeared in
|
1997-03-31 16:36:14 +00:00
|
|
|
.Ox 2.0
|
|
|
|
and was also implemented in
|
|
|
|
.Fx 3.0 .
|