2 * SPDX-License-Identifier: LGPL-2.1-only
4 * Copyright (C) 2017 Mathieu Desnoyers <mathieu.desnoyers@efficios.com>
11 #include <sys/types.h>
12 #include <urcu/system.h>
13 #include "common/logging.h"
14 #include "common/macros.h"
15 #include "common/getenv.h"
17 enum lttng_env_secure
{
24 enum lttng_env_secure secure
;
29 int lttng_ust_getenv_is_init
= 0;
31 static struct lttng_env lttng_env
[] = {
33 * LTTNG_UST_DEBUG is used directly by snprintf, because it
34 * needs to be already set for ERR() used in
35 * lttng_ust_getenv_init().
37 { "LTTNG_UST_DEBUG", LTTNG_ENV_NOT_SECURE
, NULL
, },
39 /* Env. var. which can be used in setuid/setgid executables. */
40 { "LTTNG_UST_WITHOUT_BADDR_STATEDUMP", LTTNG_ENV_NOT_SECURE
, NULL
, },
41 { "LTTNG_UST_REGISTER_TIMEOUT", LTTNG_ENV_NOT_SECURE
, NULL
, },
43 /* Env. var. which are not fetched in setuid/setgid executables. */
44 { "LTTNG_UST_CLOCK_PLUGIN", LTTNG_ENV_SECURE
, NULL
, },
45 { "LTTNG_UST_GETCPU_PLUGIN", LTTNG_ENV_SECURE
, NULL
, },
46 { "LTTNG_UST_ALLOW_BLOCKING", LTTNG_ENV_SECURE
, NULL
, },
47 { "HOME", LTTNG_ENV_SECURE
, NULL
, },
48 { "LTTNG_HOME", LTTNG_ENV_SECURE
, NULL
, },
52 int lttng_is_setuid_setgid(void)
54 return geteuid() != getuid() || getegid() != getgid();
58 * Wrapper over getenv that will only return the values of whitelisted
59 * environment variables when the current process is setuid and/or setgid.
61 char *lttng_ust_getenv(const char *name
)
67 if (!CMM_LOAD_SHARED(lttng_ust_getenv_is_init
))
70 for (i
= 0; i
< LTTNG_ARRAY_SIZE(lttng_env
); i
++) {
73 if (strcmp(e
->key
, name
) == 0) {
84 void lttng_ust_getenv_init(void)
88 if (CMM_LOAD_SHARED(lttng_ust_getenv_is_init
))
91 for (i
= 0; i
< LTTNG_ARRAY_SIZE(lttng_env
); i
++) {
92 struct lttng_env
*e
= <tng_env
[i
];
94 if (e
->secure
== LTTNG_ENV_SECURE
&& lttng_is_setuid_setgid()) {
95 ERR("Getting environment variable '%s' from setuid/setgid binary refused for security reasons.",
99 e
->value
= getenv(e
->key
);
101 CMM_STORE_SHARED(lttng_ust_getenv_is_init
, 1);
This page took 0.035505 seconds and 4 git commands to generate.