HomeFreeBSD

setusercontext(): Apply personal settings only on matching effective UID

Description

setusercontext(): Apply personal settings only on matching effective UID

Commit 35305a8dc114 (r211393) added a check on whether 'uid' was equal
to getuid() before calling setlogincontext(). Doing so still allows
a setuid program to apply resource limits and priorities specified in
a user-controlled configuration file ('~/.login_conf') where
a non-setuid program could not. Plug the hole by checking instead that
the process' effective UID is the target one (which is likely what was
meant in the initial commit).

PR: 271750
Reviewed by: kib, des
MFC after: 2 weeks
Sponsored by: Kumacom SAS
Differential Revision: https://reviews.freebsd.org/D40351

Details

Provenance
olceAuthored on May 30 2023, 4:35 PM
emasteCommitted on Oct 10 2023, 1:47 AM
Reviewer
kib
Differential Revision
D40351: setusercontext(): Apply user login context only on process' euid being set
Parents
rG6e92fc930943: vkbd: correct ref count on cloned cdevs
Branches
Unknown
Tags
Unknown