]> git.pld-linux.org Git - packages/ntp.git/blame - ntp-4.2.6p1-droproot.patch
ntpd requires libgcc_s.so.1
[packages/ntp.git] / ntp-4.2.6p1-droproot.patch
CommitLineData
eb371d2a
ER
1--- ntp-4.2.8/html/ntpdate.html~ 2014-12-19 13:56:51.000000000 +0200
2+++ ntp-4.2.8/html/ntpdate.html 2015-01-02 10:27:05.538902307 +0200
3@@ -27,7 +27,7 @@
4 page and/or the <a href="sntp.html"><tt>sntp</tt> - Simple Network Time
5 Protocol (SNTP) Client</a> page. After a suitable period of mourning, the <tt>ntpdate</tt> program will be retired from this distribution.</p>
6 <h4>Synopsis</h4>
7-<tt>ntpdate [ -46bBdqsuv ] [ -a <i>key</i> ] [ -e <i>authdelay</i> ] [ -k <i>keyfile</i> ] [ -o <i>version</i> ] [ -p <i>samples</i> ] [ -t <i>timeout</i> ] <i>server</i> [ ... ]</tt>
8+<tt>ntpdate [ -46bBdqsuv ] [ -a <i>key</i> ] [ -e <i>authdelay</i> ] [ -k <i>keyfile</i> ] [ -o <i>version</i> ] [ -p <i>samples</i> ] [ -t <i>timeout</i> ] [ -U <i>user_name</i> ] <i>server</i> [ ... ]</tt>
9 <h4>Description</h4>
10 <p><tt>ntpdate</tt> sets the local date and time by polling the Network Time Protocol (NTP) server(s) given as the <i>server</i> arguments to determine the correct time. It must be run as root on the local host. A number of samples are obtained from each of the servers specified and a subset of the NTP clock filter and selection algorithms are applied to select the best of these. Note that the accuracy and reliability of <tt>ntpdate</tt> depends on the number of servers, the number of polls each time it is run and the interval between runs.</p>
11 <p><tt>ntpdate</tt> can be run manually as necessary to set the host clock, or it can be run from the host startup script to set the clock at boot time. This is useful in some cases to set the clock initially before starting the NTP daemon <tt>ntpd</tt>. It is also possible to run <tt>ntpdate</tt> from a <tt>cron</tt> script. However, it is important to note that <tt>ntpdate</tt> with contrived <tt>cron</tt> scripts is no substitute for the NTP daemon, which uses sophisticated algorithms to maximize accuracy and reliability while minimizing resource use. Finally, since <tt>ntpdate</tt> does not discipline the host clock frequency as does <tt>ntpd</tt>, the accuracy using <tt>ntpdate</tt> is limited.</p>
12@@ -68,6 +68,11 @@
13 <dd>Direct <tt>ntpdate</tt> to use an unprivileged port for outgoing packets. This is most useful when behind a firewall that blocks incoming traffic to privileged ports, and you want to synchronize with hosts beyond the firewall. Note that the <tt>-d</tt> option always uses unprivileged ports.
14 <dt><tt>-<i>v</i></tt></dt>
15 <dd>Be verbose. This option will cause <tt>ntpdate</tt>'s version identification string to be logged.</dd>
a8809dbd 16+
eb371d2a
ER
17+ <dt><tt>-U <i>user_name</i></tt></dt>
18+ <dd>ntpdate process drops root privileges and changes user ID to
19+ <i>user_name</i> and group ID to the primary group of
20+ <i>server_user</i>.
21 </dl>
22 <h4>Diagnostics</h4>
23 <tt>ntpdate</tt>'s exit status is zero if it finds a server and updates the clock, and nonzero otherwise.
a8809dbd
ER
24diff -up ntp-4.2.6p1/ntpdate/ntpdate.c.droproot ntp-4.2.6p1/ntpdate/ntpdate.c
25--- ntp-4.2.6p1/ntpdate/ntpdate.c.droproot 2009-12-09 08:36:35.000000000 +0100
26+++ ntp-4.2.6p1/ntpdate/ntpdate.c 2010-03-03 15:33:06.000000000 +0100
27@@ -48,6 +48,12 @@
6fca7355
ER
28
29 #include <arpa/inet.h>
30
31+/* Linux capabilities */
32+#include <sys/capability.h>
33+#include <sys/prctl.h>
34+#include <pwd.h>
35+#include <grp.h>
36+
37 #ifdef SYS_VXWORKS
38 # include "ioLib.h"
39 # include "sockLib.h"
a8809dbd 40@@ -152,6 +158,11 @@ int simple_query = 0;
6fca7355
ER
41 int unpriv_port = 0;
42
43 /*
44+ * Use capabilities to drop privileges and switch uids
45+ */
46+char *server_user;
47+
48+/*
49 * Program name.
50 */
51 char *progname;
a8809dbd
ER
52@@ -293,6 +304,88 @@ void clear_globals()
53 static ni_namelist *getnetinfoservers (void);
6fca7355
ER
54 #endif
55
56+/* This patch is adapted (copied) from Chris Wings drop root patch
57+ * for xntpd.
58+ */
59+void drop_root(uid_t server_uid, gid_t server_gid)
60+{
61+ cap_t caps;
62+
63+ if (prctl(PR_SET_KEEPCAPS, 1)) {
64+ if (syslogit) {
65+ msyslog(LOG_ERR, "prctl(PR_SET_KEEPCAPS, 1) failed");
66+ }
67+ else {
68+ fprintf(stderr, "prctl(PR_SET_KEEPCAPS, 1) failed.\n");
69+ }
70+ exit(1);
71+ }
72+
73+ if ( setgroups(0, NULL) == -1 ) {
74+ if (syslogit) {
75+ msyslog(LOG_ERR, "setgroups failed.");
76+ }
77+ else {
78+ fprintf(stderr, "setgroups failed.\n");
79+ }
80+ exit(1);
81+ }
82+
83+ if ( setegid(server_gid) == -1 || seteuid(server_uid) == -1 ) {
84+ if (syslogit) {
85+ msyslog(LOG_ERR, "setegid/seteuid to uid=%d/gid=%d failed.", server_uid,
86+ server_gid);
87+ }
88+ else {
89+ fprintf(stderr, "setegid/seteuid to uid=%d/gid=%d failed.\n", server_uid,
90+ server_gid);
91+ }
92+ exit(1);
93+ }
94+
95+ caps = cap_from_text("cap_sys_time=epi");
96+ if (caps == NULL) {
97+ if (syslogit) {
98+ msyslog(LOG_ERR, "cap_from_text failed.");
99+ }
100+ else {
101+ fprintf(stderr, "cap_from_text failed.\n");
102+ }
103+ exit(1);
104+ }
105+
106+ if (cap_set_proc(caps) == -1) {
107+ if (syslogit) {
108+ msyslog(LOG_ERR, "cap_set_proc failed.");
109+ }
110+ else {
111+ fprintf(stderr, "cap_set_proc failed.\n");
112+ }
113+ exit(1);
114+ }
115+
116+ /* Try to free the memory from cap_from_text */
117+ cap_free( caps );
118+
119+ if ( setregid(server_gid, server_gid) == -1 ||
120+ setreuid(server_uid, server_uid) == -1 ) {
121+ if (syslogit) {
122+ msyslog(LOG_ERR, "setregid/setreuid to uid=%d/gid=%d failed.",
123+ server_uid, server_gid);
124+ }
125+ else {
126+ fprintf(stderr, "setregid/setreuid to uid=%d/gid=%d failed.\n",
127+ server_uid, server_gid);
128+ }
129+ exit(1);
130+ }
131+
132+ if (syslogit) {
133+ msyslog(LOG_DEBUG, "running as uid(%d)/gid(%d) euid(%d)/egid(%d).",
134+ getuid(), getgid(), geteuid(), getegid());
135+ }
136+}
137+
138 /*
139 * Main program. Initialize us and loop waiting for I/O and/or
140 * timer expiries.
a8809dbd
ER
141@@ -340,6 +433,8 @@ ntpdatemain (
142
143 init_lib(); /* sets up ipv4_works, ipv6_works */
6fca7355 144
6fca7355 145+ server_user = NULL;
a8809dbd
ER
146+
147 /* Check to see if we have IPv6. Otherwise default to IPv4 */
148 if (!ipv6_works)
6fca7355 149 ai_fam_templ = AF_INET;
a8809dbd 150@@ -351,7 +446,7 @@ ntpdatemain (
6fca7355
ER
151 /*
152 * Decode argument list
153 */
154- while ((c = ntp_getopt(argc, argv, "46a:bBde:k:o:p:qst:uv")) != EOF)
155+ while ((c = ntp_getopt(argc, argv, "46a:bBde:k:o:p:qst:uvU:")) != EOF)
156 switch (c)
157 {
158 case '4':
a8809dbd 159@@ -429,6 +524,14 @@ ntpdatemain (
6fca7355
ER
160 case 'u':
161 unpriv_port = 1;
162 break;
163+ case 'U':
164+ if (ntp_optarg) {
165+ server_user = strdup(ntp_optarg);
166+ }
167+ else {
168+ ++errflg;
169+ }
170+ break;
171 case '?':
172 ++errflg;
173 break;
a8809dbd 174@@ -438,7 +541,7 @@ ntpdatemain (
6fca7355
ER
175
176 if (errflg) {
177 (void) fprintf(stderr,
178- "usage: %s [-46bBdqsuv] [-a key#] [-e delay] [-k file] [-p samples] [-o version#] [-t timeo] server ...\n",
179+ "usage: %s [-46bBdqsuv] [-a key#] [-e delay] [-k file] [-p samples] [-o version#] [-t timeo] [-U username] server ...\n",
180 progname);
181 exit(2);
182 }
a8809dbd 183@@ -544,6 +647,24 @@ ntpdatemain (
6fca7355
ER
184 initializing = 0;
185 was_alarmed = 0;
186
187+ if (server_user) {
188+ struct passwd *pwd = NULL;
189+
190+ /* Lookup server_user uid/gid before chroot/chdir */
191+ pwd = getpwnam( server_user );
192+ if ( pwd == NULL ) {
193+ if (syslogit) {
194+ msyslog(LOG_ERR, "Failed to lookup user '%s'.", server_user);
195+ }
196+ else {
197+ fprintf(stderr, "Failed to lookup user '%s'.\n", server_user);
198+ }
199+ exit(1);
200+ }
201+ drop_root(pwd->pw_uid, pwd->pw_gid);
202+ }
203+
204+
205 while (complete_servers < sys_numservers) {
206 #ifdef HAVE_POLL_H
207 struct pollfd* rdfdes;
This page took 0.083139 seconds and 4 git commands to generate.