ports/ftp/proftpd/files/patch-8-src-fsio.c
Mathieu Arnold 0438143249 Remove OSVERSION checks that do not make sense any more.
For example (${OSVERSION} >= 900000 && ${OSVERSION} < 900021) is always true,
as is (${OSVERSION} > 900002 || ${OSVERSION} < 900000 && ${OSVERSION} > 800107).

Regarding patches, when an EXTRA_PATCHES is no longer needed, I remove it, when
it is always needed, I renamed it, in one case, I merged two patches.

Differential Revision:	https://reviews.freebsd.org/D2209
2015-04-03 11:26:48 +00:00

44 lines
908 B
C

--- src/fsio.c.orig 2010-04-12 21:00:00.000000000 +0200
+++ src/fsio.c 2011-12-29 21:51:33.844925577 +0100
@@ -50,6 +50,10 @@
# include <acl/libacl.h>
#endif
+#if defined(__FreeBSD__)
+#include <dlfcn.h>
+#endif
+
typedef struct fsopendir fsopendir_t;
struct fsopendir {
@@ -284,7 +288,30 @@
#endif
}
+#if defined(__FreeBSD__)
+static int
+enter_freebsd_restricted_mode()
+{
+ typedef void frmode_t();
+ frmode_t *frmode;
+
+ frmode = (frmode_t *)dlfunc(
+ RTLD_NEXT, "__FreeBSD_libc_enter_restricted_mode");
+ if (frmode == NULL) {
+ pr_log_pri(PR_LOG_ERR,
+ "error: FreeBSD with vulnerable chroot (FreeBSD-SA-11:07.chroot)");
+ return 1;
+ }
+ frmode();
+ return 0;
+}
+#endif
+
static int sys_chroot(pr_fs_t *fs, const char *path) {
+#if defined(__FreeBSD__)
+ if (enter_freebsd_restricted_mode() != 0)
+ return -1;
+#endif
if (chroot(path) < 0)
return -1;