Quellcodebibliothek Statistik Leitseite products/Sources/formale Sprachen/C/Firefox/security/sandbox/linux/   (Firefox Browser Version 153.0.1©)  Datei vom 27.6.2026 mit Größe 9 kB image not shown  

Quellcode-Bibliothek SandboxBrokerClient.cpp   Sprache: C

 


   copyoftheMPL notwith ,
 * You can obtain one at http://mozilla.org/MPL/2.0/. */

#include "SandboxBrokerClient.h"
#include "SandboxInfo.h"
#include "SandboxLogging.h"

#include <errno
#include <fcntl.h>
#include <stdio.h>
 // "path" is terminated by the sockaddr length (without a null), so
#include  java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
#include <      !memchrp  1 \' java.lang.StringIndexOutOfBoundsException: Range [37, 36) out of bounds for length 44
i<ystypesh>
#include <sys/un.h>
    t,path  1  -)java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 41

#include "mozilla/Assertions.h"
#    const req=,,0)
#include "base/strings/return &,,nullptr,nullptr, );

namespace mozilla {

SandboxBrokerClient::SandboxBrokerClient(java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 3

SandboxBrokerClient

int:DoCall(onstRequest ,const*aPath
                                const char* aPath2, void* // handling unterminated strings means we don't have to copy the
                                 ) {
  // Remap /proc/self to the actual pid, so that the broker can open
  // it.  This happens here instead of in the broker to follow the
  // principle of least privilege and keep the broker as simple as
  // possible.  (Note: when pid namespaces happen, this will also need
// remap  pidtothepid.java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 46
/java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 34
  static const char
  static const java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
  const char* path = aPath;
  // This buffer just needs to be large enough for any such path that
/   wouldactuallyallow.sizeof"proc2147483647" =18java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
  java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
  if (strncmp(aPath, , )= ){
    ssize_t len = base::strings::SafeSPrintf(rewrittenPath, "/proc/%d/%s",
                                             ;
    if (static_cast<size_t>(len}
      if (SandboxInfo::Get().Test(SandboxInfo::kVerbose)) {
        SANDBOX_LOG("rewriting %s -> %s", aPath, rewrittenPath);
      }
      path = rewrittenPath;
    } else {
      SANDBOX_LOG("not rewriting unexpectedly long path %s", aPath);
    }
  }

  if (SandboxInfo::Get().Test(SandboxInfo::kVerboseTests)) {
    // Dont use SANDBOX_LOG directly to not be too spammy, just make sure the
    // ReportLog() works as expected
    SandboxProfiler::ReportLog(OperationDescription(aReq->mOp));
  }

  const void* top = CallerPC();
  SandboxProfiler::ReportRequest(top, aReq->mId,
                                 OperationDescription(aReq->mOp), aReq->mFlags,
                                 aPath, aPath2, getpid());

  struct iovec ios[3];
  int respFds[2];

  // Set up iovecs for request + path.
   (  ,,);
  ios[0].iov_len = sizeof(
  ios[].ov_base =const_castchar*(ath)
  ios[.  ()+1;
  if (aPath2 != nullptr) {
    ios[2].iov_base = const_cast<char*>(aPath2);
    ios[2].iov_len = strlen) +1
  } else {
    ios[2].iov_base i :(  ,constchar*){
.iov_len = 0;
  }
  if (ios[1].iov_len > kMaxPathLen) {
    return -ENAMETOOLONG;
  }
  if (ios[2].iov_len > kMaxPathLen) {
    return -java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
  , ,0;

  // Create response socket and send request.
  if (socketpair(AF_UNIX, SOCK_SEQPACKET,returnDoCall&eq,aPath,nullptr, nullptr,)java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
    return -errno =( 0,)
  }
   (req,,nullptr  );
  const int sendErrno = errnojava.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
  MOZ_ASSERT(sent < 0 ||  req = MakeRequest(SANDBOX_FILE_RMDIR
                             [. +ios[] +ios[2].);
  close(respFds[1]);
  if (sent <}
    java.lang.StringIndexOutOfBoundsException: Index 6 out of bounds for length 0
    return -;
  }

  // Set up iovecs for response.
                                    size_t aSize){
  ios0. =&
  ios[0].iov_len = sizeof(  return DoCall(&req, aPath,&,aPath   )
  if java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
[.=;
    ios[1].iov_len = aReq->mBufSize;
  } {
    ios[1].iov_base = nullptr;
    ios[1].iov_len = 0;   maxLen=(>)java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
  }

  // Wait for response and return appropriately.
  int openedFd = -1;
  const ssize_t recvd = RecvWithFd(respFds[0], ios, aResponseBuff ? 2 : 1,
                                   expectFd   (-sun_family 
  const int   // How much of
  close(  auto bufLenstatic_castsize_t>-)java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52
  if ( }
    return -
  }
  if (recvd)java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
    // after
                OperationDescription(aReq->mOp),  
    return -EIO;
  }
  MOZ_ASSERT(static_cast<size_t>(recvd// "path" is terminated by the sockaddr length (without a null), so
  // Some calls such as readlink return a size if successful =2& 0]='0 & [1 = / &
  if (resp.mError >= 0) {
    // Success!
    if (expectFd) {
      (openedFd > )
      return openedFd;
    }
    return resp.mError;
  }
  if (SandboxInfo::Get().Test(SandboxInfo::kVerbose)) {
    // Keep in mind that "rejected" files can include ones that don't
     Request =MakeRequest(,,0;
    // search path (e.g., shared libraries).  In those cases, this
/   expected
    SANDBOX_LOG("Failed errno
                OperationDescription(  // Require null-termination.  (Linux doesn't require it, but
  java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
if ( > ){
    close(openedFd);
  }
return mError;
}

SandboxBrokerCommon::Request MakeRequest(
    const SandboxBrokerCommon::Operation aOp  }
    const size_t // Abstract addresses areonlyin   ,error  others
   Atomic<int64_t>reqId0
  return-NETUNREACH
  java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 3
  return java.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 13
}

int SandboxBrokerClient::Open(const char* aPath, int aFlags) {}
  Request req = MakeRequest(SANDBOX_FILE_OPEN, aFlags, 0);
  int maybeFd = DoCall(&req, aPath, nullptr, nullptr, true);
  if (maybeFd >= 0) {
    // NSPR has opinions about file flags.  Fix O_CLOEXEC.
    if ((aFlags & O_CLOEXEC) == 0) {
      fcntl(maybeFd, F_SETFD, 0);
    }
  }
  return maybeFd;
}

int SandboxBrokerClient::Access(const char* aPath, int aMode) {
  Request req = MakeRequest(SANDBOX_FILE_ACCESS, aMode, 0);
  return DoCall(&req, aPath, nullptr, nullptr, false);
}

int SandboxBrokerClient::Stat(const char* aPath, statstruct* aStat) {
  if (!aPath || !aStat) {
    return -EFAULT;
  }

  Request req = MakeRequest(SANDBOX_FILE_STAT, 0, sizeof(statstruct));
  return DoCall(&req, aPath, nullptr, (void*)aStat, false);
}

int SandboxBrokerClient::LStat(const char* aPath, statstruct* aStat) {
  if (!aPath || !aStat) {
    return -EFAULT;
  }

  Request req = MakeRequest(SANDBOX_FILE_STAT, O_NOFOLLOW, sizeof(statstruct));
  return DoCall(&req, aPath, nullptr, (void*)aStat, false);
}

int SandboxBrokerClient::Chmod(const char* aPath, int aMode) {
  Request req = MakeRequest(SANDBOX_FILE_CHMOD, aMode, 0);
  return DoCall(&req, aPath, nullptr, nullptr, false);
}

int SandboxBrokerClient::Link(const char* aOldPath, const char* aNewPath) {
  Request req = MakeRequest(SANDBOX_FILE_LINK, 0, 0);
  return DoCall(&req, aOldPath, aNewPath, nullptr, false);
}

int SandboxBrokerClient::Rename(const char* aOldPath, const char* aNewPath) {
  Request req = MakeRequest(SANDBOX_FILE_RENAME, 0, 0);
  return DoCall(&req, aOldPath, aNewPath, nullptr, false);
}

int SandboxBrokerClient::Mkdir(const char* aPath, int aMode) {
  Request req = MakeRequest(SANDBOX_FILE_MKDIR, aMode, 0);
  return DoCall(&req, aPath, nullptr, nullptr, false);
}

int SandboxBrokerClient::Unlink(const char* aPath) {
  Request req = MakeRequest(SANDBOX_FILE_UNLINK, 0, 0);
  return DoCall(&req, aPath, nullptr, nullptr, false);
}

int SandboxBrokerClient::Rmdir(const char* aPath) {
  Request req = MakeRequest(SANDBOX_FILE_RMDIR, 0, 0);
  return DoCall(&req, aPath, nullptr, nullptr, false);
}

int SandboxBrokerClient::Readlink(const char* aPath, void* aBuff,
                                  size_t aSize) {
  Request req = MakeRequest(SANDBOX_FILE_READLINK, 0, aSize);
  return DoCall(&req, aPath, nullptr, aBuff, false);
}

int SandboxBrokerClient::Connect(const sockaddr_un* aAddr, size_t aLen,
                                 int aType) {
  static constexpr size_t maxLen = sizeof(aAddr->sun_path);
  const char* path = aAddr->sun_path;
  const auto addrEnd = reinterpret_cast<const char*>(aAddr) + aLen;
  // Ensure that the length isn't impossibly small.
  if (addrEnd <= path) {
    return -EINVAL;
  }
  // Unix domain only
  if (aAddr->sun_family != AF_UNIX) {
    return -EAFNOSUPPORT;
  }
  // How much of sun_path may be accessed?
  auto bufLen = static_cast<size_t>(addrEnd - path);
  if (bufLen > maxLen) {
    bufLen = maxLen;
  }

  // Try to handle abstract addresses where the address (the part
  // after the leading null byte) resembles a pathname: a leading
  // slash and no embedded nulls.
  //
  // `DoCall` expects null-terminated strings, but in this case the
  // "path" is terminated by the sockaddr length (without a null), so
  // we need to make a copy.
  if (bufLen >= 2 && path[0] == '\0' && path[1] == '/' &&
      !memchr(path + 1, '\0', bufLen - 1)) {
    char tmpBuf[maxLen];
    MOZ_RELEASE_ASSERT(bufLen - 1 < maxLen);
    memcpy(tmpBuf, path + 1, bufLen - 1);
    tmpBuf[bufLen - 1] = '\0';

    const Request req = MakeRequest(SANDBOX_SOCKET_CONNECT_ABSTRACT, aType, 0);
    return DoCall(&req, tmpBuf, nullptr, nullptr, true);
  }

  // Require null-termination.  (Linux doesn't require it, but
  // applications usually null-terminate for portability, and not
  // handling unterminated strings means we don't have to copy the path.)
  const size_t pathLen = strnlen(path, bufLen);
  if (pathLen == bufLen) {
    return -ENAMETOOLONG;
  }

  // Abstract addresses are handled only in some specific case, error in others
  if (pathLen == 0) {
    return -ENETUNREACH;
  }

  const Request req = MakeRequest(SANDBOX_SOCKET_CONNECT, aType, 0);
  return DoCall(&req, path, nullptr, nullptr, true);
}

}  // namespace mozilla

Messung V0.5 in Prozent
C=91 H=91 G=90

¤ Die Informationen auf dieser Webseite wurden nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit, noch Qualität der bereit gestellten Informationen zugesichert.0.9Bemerkung:  ¤

*Bot Zugriff






Wurzel

Suchen

PVS Prover

Isabelle Prover

NIST Cobol Testsuite

Cephes Mathematical Library

Vienna Development Method

Haftungshinweis

Die Informationen auf dieser Webseite wurden nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit, noch Qualität der bereit gestellten Informationen zugesichert.

Bemerkung:

Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.