From nobody Tue Feb 10 12:40:04 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (lists.gnu.org [208.118.235.17]) by mx.zohomail.com with SMTPS id 1505499265445147.3629926467553; Fri, 15 Sep 2017 11:14:25 -0700 (PDT) Received: from localhost ([::1]:54510 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dsv8A-0004wB-O3 for importer@patchew.org; Fri, 15 Sep 2017 14:14:22 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:39152) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1dsv49-0000lX-Nc for qemu-devel@nongnu.org; Fri, 15 Sep 2017 14:10:14 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1dsv47-0006t2-R9 for qemu-devel@nongnu.org; Fri, 15 Sep 2017 14:10:13 -0400 Received: from smtp02.citrix.com ([66.165.176.63]:59995) by eggs.gnu.org with esmtps (TLS1.0:RSA_ARCFOUR_SHA1:16) (Exim 4.71) (envelope-from ) id 1dsv47-0006gP-LL for qemu-devel@nongnu.org; Fri, 15 Sep 2017 14:10:11 -0400 X-IronPort-AV: E=Sophos;i="5.42,398,1500940800"; d="scan'208";a="448014541" From: Ian Jackson To: Date: Fri, 15 Sep 2017 19:09:59 +0100 Message-ID: <1505498999-17427-7-git-send-email-ian.jackson@eu.citrix.com> X-Mailer: git-send-email 2.1.4 In-Reply-To: <1505498999-17427-1-git-send-email-ian.jackson@eu.citrix.com> References: <1505498999-17427-1-git-send-email-ian.jackson@eu.citrix.com> MIME-Version: 1.0 X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 66.165.176.63 Subject: [Qemu-devel] [PATCH RFC 6/6] os-posix: Provide new -runasid option X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Juergen Gross , Stefano Stabellini , Ian Jackson , xen-devel@nongnu.org Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail: RSF_0 Z_629925259 SPT_0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" This allows the caller to specify a uid and gid to use, even if there is no corresponding password entry. This will be useful in certain Xen configurations. Signed-off-by: Ian Jackson --- os-posix.c | 30 ++++++++++++++++++++++++++---- qemu-options.hx | 12 ++++++++++++ 2 files changed, 38 insertions(+), 4 deletions(-) diff --git a/os-posix.c b/os-posix.c index 92e9d85..b88995e 100644 --- a/os-posix.c +++ b/os-posix.c @@ -43,6 +43,8 @@ #endif =20 static struct passwd *user_pwd; +static uid_t user_uid =3D (uid_t)-1; +static gid_t user_gid =3D (gid_t)-1; static const char *chroot_dir; static int daemonize; static int daemon_pipe; @@ -134,6 +136,8 @@ void os_set_proc_name(const char *s) */ void os_parse_cmd_args(int index, const char *optarg) { + unsigned long lv; + char *ep; switch (index) { #ifdef CONFIG_SLIRP case QEMU_OPTION_smb: @@ -150,6 +154,22 @@ void os_parse_cmd_args(int index, const char *optarg) exit(1); } break; + case QEMU_OPTION_runasid: + errno =3D 0; + lv =3D strtoul(optarg, &ep, 0); + if (errno || *ep !=3D '.' || (user_uid =3D lv) !=3D lv + || (user_uid =3D=3D (uid_t)-1)) { + fprintf(stderr, "Could not obtain uid from \"%s\"", optarg); + exit(1); + } + errno =3D 0; + lv =3D strtoul(ep+1, &ep, 0); + if (errno || *ep || (user_gid =3D lv) !=3D lv + || (user_gid =3D=3D (gid_t)-1)) { + fprintf(stderr ,"Could not obtain gid from \"%s\"", optarg); + exit(1); + } + break; case QEMU_OPTION_chroot: chroot_dir =3D optarg; break; @@ -166,17 +186,19 @@ void os_parse_cmd_args(int index, const char *optarg) =20 static void change_process_uid(void) { - if (user_pwd) { - if (setgid(user_pwd->pw_gid) < 0) { + if (user_pwd || user_uid !=3D (uid_t)-1) { + if (setgid(user_pwd ? user_pwd->pw_gid : user_gid) < 0) { fprintf(stderr, "Failed to setgid(%d)\n", user_pwd->pw_gid); exit(1); } - if (initgroups(user_pwd->pw_name, user_pwd->pw_gid) < 0) { + if ((user_pwd + ? initgroups(user_pwd->pw_name, user_pwd->pw_gid) + : setgroups(1, &user_gid)) < 0) { fprintf(stderr, "Failed to initgroups(\"%s\", %d)\n", user_pwd->pw_name, user_pwd->pw_gid); exit(1); } - if (setuid(user_pwd->pw_uid) < 0) { + if (setuid(user_pwd ? user_pwd->pw_uid : user_gid) < 0) { fprintf(stderr, "Failed to setuid(%d)\n", user_pwd->pw_uid); exit(1); } diff --git a/qemu-options.hx b/qemu-options.hx index 9f6e2ad..34a5329 100644 --- a/qemu-options.hx +++ b/qemu-options.hx @@ -3968,6 +3968,18 @@ Immediately before starting guest execution, drop ro= ot privileges, switching to the specified user. ETEXI =20 +#ifndef _WIN32 +DEF("runasid", HAS_ARG, QEMU_OPTION_runasid, \ + "-runasid uid.gid change to numeric uid and gid just before starti= ng the VM\n", + QEMU_ARCH_ALL) +#endif +STEXI +@item -runasid @var{uid}.@var{gid} +@findex -runasid +Immediately before starting guest execution, drop root privileges, switchi= ng +to the specified uid and gid. +ETEXI + DEF("prom-env", HAS_ARG, QEMU_OPTION_prom_env, "-prom-env variable=3Dvalue\n" " set OpenBIOS nvram variables\n", --=20 2.1.4