Blame view

fs/binfmt_script.c 4.38 KB
09c434b8a   Thomas Gleixner   treewide: Add SPD...
1
  // SPDX-License-Identifier: GPL-2.0-only
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
2
3
4
  /*
   *  linux/fs/binfmt_script.c
   *
96de0e252   Jan Engelhardt   Convert files to ...
5
   *  Copyright (C) 1996  Martin von Löwis
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
6
7
8
9
10
11
   *  original #!-checking implemented by tytso.
   */
  
  #include <linux/module.h>
  #include <linux/string.h>
  #include <linux/stat.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
12
13
14
  #include <linux/binfmts.h>
  #include <linux/init.h>
  #include <linux/file.h>
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
15
16
  #include <linux/err.h>
  #include <linux/fs.h>
b5372fe5d   Kees Cook   exec: load_script...
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
  static inline bool spacetab(char c) { return c == ' ' || c == '\t'; }
  static inline char *next_non_spacetab(char *first, const char *last)
  {
  	for (; first <= last; first++)
  		if (!spacetab(*first))
  			return first;
  	return NULL;
  }
  static inline char *next_terminator(char *first, const char *last)
  {
  	for (; first <= last; first++)
  		if (spacetab(*first) || !*first)
  			return first;
  	return NULL;
  }
71613c3b8   Al Viro   get rid of pt_reg...
32
  static int load_script(struct linux_binprm *bprm)
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
33
  {
d7627467b   David Howells   Make do_execve() ...
34
  	const char *i_arg, *i_name;
b5372fe5d   Kees Cook   exec: load_script...
35
  	char *cp, *buf_end;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
36
  	struct file *file;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
37
  	int retval;
b5372fe5d   Kees Cook   exec: load_script...
38
  	/* Not ours to exec if we don't start with "#!". */
d74026986   Kees Cook   exec: use -ELOOP ...
39
  	if ((bprm->buf[0] != '#') || (bprm->buf[1] != '!'))
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
40
  		return -ENOEXEC;
51f39a1f0   David Drysdale   syscalls: impleme...
41
42
43
44
45
46
47
48
49
  
  	/*
  	 * If the script filename will be inaccessible after exec, typically
  	 * because it is a "/dev/fd/<fd>/.." path against an O_CLOEXEC fd, give
  	 * up now (on the assumption that the interpreter will want to load
  	 * this file).
  	 */
  	if (bprm->interp_flags & BINPRM_FLAGS_PATH_INACCESSIBLE)
  		return -ENOENT;
b5372fe5d   Kees Cook   exec: load_script...
50
  	/* Release since we are not mapping a binary into memory. */
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
51
52
53
  	allow_write_access(bprm->file);
  	fput(bprm->file);
  	bprm->file = NULL;
b5372fe5d   Kees Cook   exec: load_script...
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
  	/*
  	 * This section handles parsing the #! line into separate
  	 * interpreter path and argument strings. We must be careful
  	 * because bprm->buf is not yet guaranteed to be NUL-terminated
  	 * (though the buffer will have trailing NUL padding when the
  	 * file size was smaller than the buffer size).
  	 *
  	 * We do not want to exec a truncated interpreter path, so either
  	 * we find a newline (which indicates nothing is truncated), or
  	 * we find a space/tab/NUL after the interpreter path (which
  	 * itself may be preceded by spaces/tabs). Truncating the
  	 * arguments is fine: the interpreter can re-read the script to
  	 * parse them on its own.
  	 */
  	buf_end = bprm->buf + sizeof(bprm->buf) - 1;
  	cp = strnchr(bprm->buf, sizeof(bprm->buf), '
  ');
  	if (!cp) {
  		cp = next_non_spacetab(bprm->buf + 2, buf_end);
  		if (!cp)
  			return -ENOEXEC; /* Entire buf is spaces/tabs */
  		/*
  		 * If there is no later space/tab/NUL we must assume the
  		 * interpreter path is truncated.
  		 */
  		if (!next_terminator(cp, buf_end))
  			return -ENOEXEC;
  		cp = buf_end;
  	}
  	/* NUL-terminate the buffer and any trailing spaces/tabs. */
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
84
85
86
87
88
89
90
91
92
  	*cp = '\0';
  	while (cp > bprm->buf) {
  		cp--;
  		if ((*cp == ' ') || (*cp == '\t'))
  			*cp = '\0';
  		else
  			break;
  	}
  	for (cp = bprm->buf+2; (*cp == ' ') || (*cp == '\t'); cp++);
c2315c187   Oleg Nesterov   exec: load_script...
93
  	if (*cp == '\0')
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
94
95
96
97
98
99
100
101
102
  		return -ENOEXEC; /* No interpreter name found */
  	i_name = cp;
  	i_arg = NULL;
  	for ( ; *cp && (*cp != ' ') && (*cp != '\t'); cp++)
  		/* nothing */ ;
  	while ((*cp == ' ') || (*cp == '\t'))
  		*cp++ = '\0';
  	if (*cp)
  		i_arg = cp;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
103
104
105
106
107
108
109
110
111
112
  	/*
  	 * OK, we've parsed out the interpreter name and
  	 * (optional) argument.
  	 * Splice in (1) the interpreter's name for argv[0]
  	 *           (2) (optional) argument to interpreter
  	 *           (3) filename of shell script (replace argv[0])
  	 *
  	 * This is done in reverse order, because of how the
  	 * user environment and arguments are stored.
  	 */
b6a2fea39   Ollie Wild   mm: variable leng...
113
114
115
  	retval = remove_arg_zero(bprm);
  	if (retval)
  		return retval;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
116
  	retval = copy_strings_kernel(1, &bprm->interp, bprm);
c2315c187   Oleg Nesterov   exec: load_script...
117
118
  	if (retval < 0)
  		return retval;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
119
120
121
  	bprm->argc++;
  	if (i_arg) {
  		retval = copy_strings_kernel(1, &i_arg, bprm);
c2315c187   Oleg Nesterov   exec: load_script...
122
123
  		if (retval < 0)
  			return retval;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
124
125
126
  		bprm->argc++;
  	}
  	retval = copy_strings_kernel(1, &i_name, bprm);
c2315c187   Oleg Nesterov   exec: load_script...
127
128
  	if (retval)
  		return retval;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
129
  	bprm->argc++;
c2315c187   Oleg Nesterov   exec: load_script...
130
  	retval = bprm_change_interp(i_name, bprm);
b66c59840   Kees Cook   exec: do not leav...
131
132
  	if (retval < 0)
  		return retval;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
133
134
135
136
  
  	/*
  	 * OK, now restart the process with the interpreter's dentry.
  	 */
c2315c187   Oleg Nesterov   exec: load_script...
137
  	file = open_exec(i_name);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
138
139
140
141
142
143
144
  	if (IS_ERR(file))
  		return PTR_ERR(file);
  
  	bprm->file = file;
  	retval = prepare_binprm(bprm);
  	if (retval < 0)
  		return retval;
3c456bfc4   Al Viro   get rid of pt_reg...
145
  	return search_binary_handler(bprm);
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
146
147
148
149
150
151
152
153
154
  }
  
  static struct linux_binfmt script_format = {
  	.module		= THIS_MODULE,
  	.load_binary	= load_script,
  };
  
  static int __init init_script_binfmt(void)
  {
8fc3dc5a3   Al Viro   __register_binfmt...
155
156
  	register_binfmt(&script_format);
  	return 0;
1da177e4c   Linus Torvalds   Linux-2.6.12-rc2
157
158
159
160
161
162
163
164
165
166
  }
  
  static void __exit exit_script_binfmt(void)
  {
  	unregister_binfmt(&script_format);
  }
  
  core_initcall(init_script_binfmt);
  module_exit(exit_script_binfmt);
  MODULE_LICENSE("GPL");