nuttx/sched/group/group_setuid.c
Abhishek Mishra 370d89a012 sched/group: implement POSIX saved-set-UID/GID semantics
Adds tg_suid and tg_sgid fields to task_group_s to complete the
POSIX three-field identity model (real, effective, saved-set).

Updates group_inherit_identity() to propagate the new fields from
parent to child task group on task creation.

Fixes setuid(), setgid(), seteuid(), and setegid() to implement
correct POSIX privilege transition logic:
- Root (euid==0): may set any value; all three IDs updated by setuid/setgid
- Non-root: may only set effective ID to real or saved value; else EPERM

Signed-off-by: Abhishek Mishra <mishra.abhishek2808@gmail.com>
2026-06-17 17:13:57 +08:00

106 lines
3.3 KiB
C

/****************************************************************************
* sched/group/group_setuid.c
*
* SPDX-License-Identifier: Apache-2.0
*
* Licensed to the Apache Software Foundation (ASF) under one or more
* contributor license agreements. See the NOTICE file distributed with
* this work for additional information regarding copyright ownership. The
* ASF licenses this file to you under the Apache License, Version 2.0 (the
* "License"); you may not use this file except in compliance with the
* License. You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
* WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the
* License for the specific language governing permissions and limitations
* under the License.
*
****************************************************************************/
/****************************************************************************
* Included Files
****************************************************************************/
#include <nuttx/config.h>
#include <sys/types.h>
#include <unistd.h>
#include <assert.h>
#include <errno.h>
#include <sched/sched.h>
/****************************************************************************
* Public Functions
****************************************************************************/
/****************************************************************************
* Name: setuid
*
* Description:
* The setuid() function sets the real user ID, effective user ID, and the
* saved set-user-ID of the calling process to uid, given appropriate
* privileges.
*
* Input Parameters:
* uid - User identity to set the various process's user ID attributes to.
*
* Returned Value:
* Zero if successful and -1 in case of failure, in which case errno is set
* to one of he following values:
*
* EINVAL - The value of the uid argument is invalid and not supported by
* the implementation.
* EPERM - The process does not have appropriate privileges and uid does
* not match the real user ID or the saved set-user-ID.
*
****************************************************************************/
int setuid(uid_t uid)
{
FAR struct tcb_s *rtcb;
FAR struct task_group_s *rgroup;
/* Verify that the UID is in the valid range of 0 through INT16_MAX.
* OpenGroup.org does not specify a UID_MAX or UID_MIN. Instead we use a
* priori knowledge that uid_t is type int16_t.
*/
if ((uint16_t)uid > INT16_MAX)
{
set_errno(EINVAL);
return ERROR;
}
/* Get the currently executing thread's task group. */
rtcb = this_task();
rgroup = rtcb->group;
DEBUGASSERT(rgroup != NULL);
if (rgroup->tg_euid == 0)
{
/* Root: set real, effective, and saved set-user-ID. */
rgroup->tg_uid = uid;
rgroup->tg_euid = uid;
rgroup->tg_suid = uid;
}
else if (uid == rgroup->tg_uid || uid == rgroup->tg_suid)
{
/* Non-root: may only set effective UID to real or saved value. */
rgroup->tg_euid = uid;
}
else
{
set_errno(EPERM);
return ERROR;
}
return OK;
}