Module Name:    src
Committed By:   christos
Date:           Fri Feb 16 19:21:49 UTC 2018

Modified Files:
        src/lib/libc/net: getpeereid.c

Log Message:
Enforce that getpeereid only returns success on AF_LOCAL sockets, instead
of returning garbage for other socket types.


To generate a diff of this commit:
cvs rdiff -u -r1.2 -r1.3 src/lib/libc/net/getpeereid.c

Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.

Modified files:

Index: src/lib/libc/net/getpeereid.c
diff -u src/lib/libc/net/getpeereid.c:1.2 src/lib/libc/net/getpeereid.c:1.3
--- src/lib/libc/net/getpeereid.c:1.2	Tue Apr 29 02:53:01 2008
+++ src/lib/libc/net/getpeereid.c	Fri Feb 16 14:21:49 2018
@@ -1,4 +1,4 @@
-/* $NetBSD: getpeereid.c,v 1.2 2008/04/29 06:53:01 martin Exp $ */
+/* $NetBSD: getpeereid.c,v 1.3 2018/02/16 19:21:49 christos Exp $ */
 
 /*-
  * Copyright (c) 2007 The NetBSD Foundation, Inc.
@@ -31,27 +31,38 @@
 
 #include <sys/cdefs.h>
 #if defined(LIBC_SCCS) && !defined(lint)
-__RCSID("$NetBSD: getpeereid.c,v 1.2 2008/04/29 06:53:01 martin Exp $");
+__RCSID("$NetBSD: getpeereid.c,v 1.3 2018/02/16 19:21:49 christos Exp $");
 #endif /* LIBC_SCCS and not lint */
 
 #include <sys/types.h>
-#include <unistd.h>
 #include <sys/un.h>
 #include <sys/socket.h>
+#include <unistd.h>
+#include <errno.h>
 
 
 int
 getpeereid(int s, uid_t *euid, gid_t *egid)
 {
 	struct unpcbid cred;
-	socklen_t len = sizeof(cred);
-	if (getsockopt(s, 0, LOCAL_PEEREID, &cred, &len) < 0) {
+	struct sockaddr_storage ss;
+	socklen_t len;
+
+	len = sizeof(ss);
+	if (getsockname(s, (void *)&ss, &len) == -1)
+		return -1;
+	if (ss.ss_family != AF_LOCAL) {
+		errno = EOPNOTSUPP;
 		return -1;
-	} else {
-		if (euid != NULL)
-			*euid = cred.unp_euid;
-		if (egid != NULL)
-			*egid = cred.unp_egid;
-		return 0;
 	}
+
+	len = sizeof(cred);
+	if (getsockopt(s, 0, LOCAL_PEEREID, &cred, &len) == -1)
+		return -1;
+
+	if (euid != NULL)
+		*euid = cred.unp_euid;
+	if (egid != NULL)
+		*egid = cred.unp_egid;
+	return 0;
 }

Reply via email to