Re: Odd situation - SETUID fail
Posted in 2009
Topics: Stored Procedures & SPL, Server Administration, Security, Permissions & Auditing, Versions, Editions & End-of-Life
Hi Jonathan,
Thanks a lot for your answer and questions.
My answers are below , if miss some information , please tell me.
1) I'm not using ACL.
Is enable by default at the mount in /etc/fstab and just to sure this is not the reason I remove all "acl" options and restart my computer. The same effect occur.
2) About /opt mount:
The /opt is part of / (root) :
| root@note-cim:/# ls -ld /opt
| drwxr-xr-x 6 root root 4096 2009-03-18 09:48 /opt
| root@note-cim:/# mount
| /dev/sda1 on / type ext2 (rw,noatime,relatime,acl,user_xattr)
| /proc on /proc type proc (rw)
| sysfs on /sys type sysfs (rw)
| debugfs on /sys/kernel/debug type debugfs (rw)
| udev on /dev type tmpfs (rw)
| devpts on /dev/pts type devpts (rw,mode=0620,gid=5)
| /dev/sda3 on /var type ext2 (rw,noatime,relatime,acl,user_xattr)
| /dev/sdb2 on /dados type ext2
| (rw,nosuid,nodev,noatime,relatime,acl,user_xattr)
| /tmp on /tmp type tmpfs (rw,size=400M)
| /dev/sdc2 on /media/SD type vfat
| rw,noexec,nosuid,nodev,noatime,relatime,gid=100,umask=0002,utf8=true)
| fusectl on /sys/fs/fuse/connections type fusectl (rw)
| gvfs-fuse-daemon on /home/cmartins/.gvfs type fuse.gvfs-fuse-daemon
| (rw,nosuid,nodev,user=cmartins)
3) Informix group
| root@note-cim:/# grep informix /etc/group
| dialout:x:16:cmartins,informix
| video:x:33:cmartins,informix
| informix:!:1000:
|
| root@note-cim:/# grep informix /etc/passwd
| informix:x:1001:1000:DBSA Informix:/home/informix:/bin/bash
4) About /INFORMIXTMP creation. Looking the / (root) mount:
| root@note-cim:~# ls -la / |head -n3
| total 104
| drwxr-xr-x 23 root root 4096 2009-04-05 11:40 .
| drwxr-xr-x 23 root root 4096 2009-04-05 11:40 ..
I don't create /INFORMIXTMP manually , I just remove it with "rm -rf /INFORMIXTMP" . They are created just when I execute the "oninit" with "root" or "root + myexec" .
Here is the permission of /INFORMIXTMP when execute "oninit" with "root" and "myexec":
| root@note-cim:/# id
| uid=0(root) gid=0(root) groups=0(root)
|
| root@note-cim:/# rm -rf /INFORMIXTMP
| removed `/INFORMIXTMP/.infxdirs'
| removed `/INFORMIXTMP/.idsmoon.alarm'
| removed directory: `/INFORMIXTMP'
|
| root@note-cim:/# echo $INFORMIXSERVER
| idsmoon
|
| root@note-cim:/# chown :root /ifmxdados/*
| root@note-cim:/# oninit -iy
| root@note-cim:/# onstat -
|
| IBM Informix Dynamic Server Version 11.50.UC3DE -- On-Line -- Up 00:00:42 -- 144144 Kbytes
|
| root@note-cim:/# ls -la /INFORMIXTMP
| total 12
| drwxrwxr-t 2 informix informix 4096 2009-04-05 12:30 .
| drwxr-xr-x 24 root root 4096 2009-04-05 12:30 ..
| -rw-rw-r-- 1 root root 22 2009-04-05 12:30 .infxdirs
| srwxrwx--- 1 root root 0 2009-04-05 12:30 VP.idsmoon.010100s
|
| root@note-cim:/# onmode -ky
|
| root@note-cim:/# chown :informix /ifmxdados/*
|
| root@note-cim:/# rm -rf /INFORMIXTMP
| removed `/INFORMIXTMP/.infxdirs'
| removed `/INFORMIXTMP/.idsmoon.alarm'
| removed directory: `/INFORMIXTMP'
|
| root@note-cim:/# myexec 1001 1000 "oninit -iy"
| argc = 4
| arg 0 = myexec
| arg 1 = 1001
| arg 2 = 1000
| arg 3 = oninit -iy
|
| Setting Effective UID = 1001 GID = 1000
| Effective / Real UID/GID defined:
| uid=0 gid=1000 euid=0 egid=1000
|
| Executing oninit -iy
|
| root@note-cim:/# ls -la /INFORMIXTMP/
| total 12
| drwxrwxr-t 2 informix informix 4096 2009-04-05 12:37 .
| drwxr-xr-x 24 root root 4096 2009-04-05 12:37 ..
| -rw-rw-r-- 1 root informix 22 2009-04-05 12:37 .infxdirs
| srwxrwx--- 1 root informix 0 2009-04-05 12:37 VP.idsmoon.010100s
|
5) Now, about the setfsuid , I don't know if the test I executed is the expected for you, I replace the setregid to setfsuid and setfsgid , this is part of the C code (myexec2.c):
| 5 int main(int argc, char *argv[] ) {
| 6 if ( argc != 4 ) {
| 7 printf("\\nInvalid Parameters!\\nsyntax: [uid] [gid] [command]\\n\\n");
| 8 exit(1) ;
| 9 }
| 10 int i,old_uid, old_gid;
| 11 old_uid=0;
| 12 old_gid=0;
| 13 printf("argc = %i\\n", argc );
| 14 for (i = 0 ; i <= argc-1 ; i++) printf("\\targ %i = %s\\n", i, argv[i]);
| 15
| 16 printf( "\\nSetting FS UID = %s GID = %s\\n", argv[1], argv[2]);
| 17 old_uid=setfsuid(atoi(argv[1])); // define FS user
| 18 old_gid=setfsgid(atoi(argv[2])); // define FS group
| 19 printf("Old FS UID/GID : ");
| 20 printf("uid=%i \\t gid=%i\\n\\n", old_uid, old_gid);
| 21 old_uid=setfsuid(atoi(argv[1])); // define FS user
| 22 old_gid=setfsgid(atoi(argv[2])); // define FS group
| 23 printf("NEW FS UID/GID : ");
| 24 printf("uid=%i \\t gid=%i\\n\\n", old_uid, old_gid);
| 25
| 26 printf("Executing %s\\n", argv[3] );
| 27 system(argv[3]);
| 28 }
|
There is the execution with "root" user, for me I don't see any effect :
| root@note-cim:/# rm -rf /INFORMIXTMP/
| removed `/INFORMIXTMP/.infxdirs'
| removed `/INFORMIXTMP/.idsmoon.alarm'
| removed directory: `/INFORMIXTMP'
|
| root@note-cim:/# myexec2 1001 1000 "oninit -ivy"
| argc = 4
| arg 0 = myexec2
| arg 1 = 1001
| arg 2 = 1000
| arg 3 = oninit -ivy
|
| Setting FS UID = 1001 GID = 1000
| Old FS UID/GID : uid=0 gid=0
|
| NEW FS UID/GID : uid=1001 gid=1000
|
| Executing oninit -ivy
| Checking group membership to determine server run mode...succeeded
| Reading configuration file '/opt/IBM/ids1150uc3de/etc/onconfig.idsmoon'...succeeded
| Creating /INFORMIXTMP/.infxdirs...succeeded
| Creating infos file "/opt/IBM/ids1150uc3de/etc/.infos.idsmoon"...succeeded
| Linking conf file "/opt/IBM/ids1150uc3de/etc/.conf.idsmoon"...succeeded
| Checking config parameters...succeeded
| Writing to infos file...succeeded
| Allocating and attaching to shared memory...succeeded
| Creating resident pool 10570 kbytes...succeeded
| Allocating 100016 kbytes for buffer pool of 2K page size...succeeded
| Initializing rhead structure...succeeded
| Initialization of Encryption...succeeded
| Initializing ASF...succeeded
| Initializing Dictionary Cache and SPL Routine Cache...succeeded
| Bringing up ADM VP...succeeded
| Creating VP classes...succeeded
| Onlining 0 additional cpu vps...succeeded
| Onlining 2 IO vps...succeeded
| Forking main_loop thread...succeeded
| Initializing DR structures...succeeded
| Forking 1 'soctcp' listener threads...succeeded
| Starting tracing...succeeded
| Initializing 8 flushers...succeeded
| FAILED
|
| WARNING: server initialization failed, or possibly timed out (if -w was used).
| Check the message log, online.log, for errors.
|
| root@note-cim:/# onstat -m
| shared memory not initialized for INFORMIXSERVER 'idsmoon'
|@@NL
On Apr 5, 2:26 pm, cesar_inacio_mart...@yahoo.com.br wrote:
> Hi Jonathan,
> Thanks a lot for your answer and questions.
>
> My answers are below , if miss some information , please tell me.
>
> 1) I'm not using ACL.
> Is enable by default at the mount in /etc/fstab and just to sure this is not the reason I remove all "acl" options and restart my computer. The same effect occur.
>
> 2) About /opt mount:
> The /opt is part of / (root) :
> | root@note-cim:/# ls -ld /opt
> | drwxr-xr-x 6 root root 4096 2009-03-18 09:48 /opt
>
> | root@note-cim:/# mount
> | /dev/sda1 on / type ext2 (rw,noatime,relatime,acl,user_xattr)
> | /proc on /proc type proc (rw)
> | sysfs on /sys type sysfs (rw)
> | debugfs on /sys/kernel/debug type debugfs (rw)
> | udev on /dev type tmpfs (rw)
> | devpts on /dev/pts type devpts (rw,mode=0620,gid=5)
> | /dev/sda3 on /var type ext2 (rw,noatime,relatime,acl,user_xattr)
> | /dev/sdb2 on /dados type ext2
> | (rw,nosuid,nodev,noatime,relatime,acl,user_xattr)
> | /tmp on /tmp type tmpfs (rw,size=400M)
> | /dev/sdc2 on /media/SD type vfat
> | rw,noexec,nosuid,nodev,noatime,relatime,gid=100,umask=0002,utf8=true)
> | fusectl on /sys/fs/fuse/connections type fusectl (rw)
> | gvfs-fuse-daemon on /home/cmartins/.gvfs type fuse.gvfs-fuse-daemon
> | (rw,nosuid,nodev,user=cmartins)
>
>
> 3) Informix group
> | root@note-cim:/# grep informix /etc/group
> | dialout:x:16:cmartins,informix
> | video:x:33:cmartins,informix
> | informix:!:1000:
> |
> | root@note-cim:/# grep informix /etc/passwd
> | informix:x:1001:1000:DBSA Informix:/home/informix:/bin/bash
>
>
> 4) About /INFORMIXTMP creation. Looking the / (root) mount:
> | root@note-cim:~# ls -la / |head -n3
> | total 104
> | drwxr-xr-x 23 root root 4096 2009-04-05 11:40 .
> | drwxr-xr-x 23 root root 4096 2009-04-05 11:40 ..
>
> I don't create /INFORMIXTMP manually , I just remove it with "rm -rf /INFORMIXTMP" . They are created just when I execute the "oninit" with "root" or "root + myexec" .
> Here is the permission of /INFORMIXTMP when execute "oninit" with "root" and "myexec":
> | root@note-cim:/# id
> | uid=0(root) gid=0(root) groups=0(root)
> |
> | root@note-cim:/# rm -rf /INFORMIXTMP
> | removed `/INFORMIXTMP/.infxdirs'
> | removed `/INFORMIXTMP/.idsmoon.alarm'
> | removed directory: `/INFORMIXTMP'
> |
> | root@note-cim:/# echo $INFORMIXSERVER
> | idsmoon
> |
> | root@note-cim:/# chown :root /ifmxdados/*
> | root@note-cim:/# oninit -iy
> | root@note-cim:/# onstat -
> |
> | IBM Informix Dynamic Server Version 11.50.UC3DE -- On-Line -- Up 00:00:42 -- 144144 Kbytes
> |
> | root@note-cim:/# ls -la /INFORMIXTMP
> | total 12
> | drwxrwxr-t 2 informix informix 4096 2009-04-05 12:30 .
> | drwxr-xr-x 24 root root 4096 2009-04-05 12:30 ..
> | -rw-rw-r-- 1 root root 22 2009-04-05 12:30 .infxdirs
> | srwxrwx--- 1 root root 0 2009-04-05 12:30 VP.idsmoon.010100s
> |
> | root@note-cim:/# onmode -ky
> |
> | root@note-cim:/# chown :informix /ifmxdados/*
> |
> | root@note-cim:/# rm -rf /INFORMIXTMP
> | removed `/INFORMIXTMP/.infxdirs'
> | removed `/INFORMIXTMP/.idsmoon.alarm'
> | removed directory: `/INFORMIXTMP'
> |
> | root@note-cim:/# myexec 1001 1000 "oninit -iy"
> | argc = 4
> | arg 0 = myexec
> | arg 1 = 1001
> | arg 2 = 1000
> | arg 3 = oninit -iy
> |
> | Setting Effective UID = 1001 GID = 1000
> | Effective / Real UID/GID defined:
> | uid=0 gid=1000 euid=0 egid=1000
> |
> | Executing oninit -iy
> |
> | root@note-cim:/# ls -la /INFORMIXTMP/
> | total 12
> | drwxrwxr-t 2 informix informix 4096 2009-04-05 12:37 .
> | drwxr-xr-x 24 root root 4096 2009-04-05 12:37 ..
> | -rw-rw-r-- 1 root informix 22 2009-04-05 12:37 .infxdirs
> | srwxrwx--- 1 root informix 0 2009-04-05 12:37 VP.idsmoon.010100s
> |
>
> 5) Now, about the setfsuid , I don't know if the test I executed is the expected for you, I replace the setregid to setfsuid and setfsgid , this is part of the C code (myexec2.c):
> | 5 int main(int argc, char *argv[] ) {
> | 6 if ( argc != 4 ) {
> | 7 printf("\\nInvalid Parameters!\\nsyntax: [uid] [gid] [command]\\n\\n");
> | 8 exit(1) ;
> | 9 }
> | 10 int i,old_uid, old_gid;
> | 11 old_uid=0;
> | 12 old_gid=0;
> | 13 printf("argc = %i\\n", argc );
> | 14 for (i = 0 ; i <= argc-1 ; i++) printf("\\targ %i = %s\\n", i, argv[i]);
> | 15
> | 16 printf( "\\nSetting FS UID = %s GID = %s\\n", argv[1], argv[2]);
> | 17 old_uid=setfsuid(atoi(argv[1])); // define FS user
> | 18 old_gid=setfsgid(atoi(argv[2])); // define FS group
> | 19 printf("Old FS UID/GID : ");
> | 20 printf("uid=%i \\t gid=%i\\n\\n", old_uid, old_gid);
> | 21 old_uid=setfsuid(atoi(argv[1])); // define FS user
> | 22 old_gid=setfsgid(atoi(argv[2])); // define FS group
> | 23 printf("NEW FS UID/GID : ");
> | 24 printf("uid=%i \\t gid=%i\\n\\n", old_uid, old_gid);
> | 25
> | 26 printf("Executing %s\\n", argv[3] );
> | 27 system(argv[3]);
> | 28 }
> |
>
> There is the execution with "root" user, for me I don't see any effect :
>
> | root@note-cim:/# rm -rf /INFORMIXTMP/
> | removed `/INFORMIXTMP/.infxdirs'
> | removed `/INFORMIXTMP/.idsmoon.alarm'
> | removed directory: `/INFORMIXTMP'
> |
> | root@note-cim:/# myexec2 1001 1000 "oninit -ivy"
> | argc = 4
> | arg 0 = myexec2
> | arg 1 = 1001
> | arg 2 = 1000
> | arg 3 = oninit -ivy
> |
> | Setting FS UID = 1001 GID = 1000
> | Old FS UID/GID : uid=0 gid=0
> |
> | NEW FS UID/GID : uid=1001 gid=1000
> |
> | Executing oninit -ivy
> | Checking group membership to determine server run mode...succeeded
> | Reading configuration file '/opt/IBM/ids1150uc3de/etc/onconfig.idsmoon'...succeeded
> | Creating /INFORMIXTMP/.infxdirs...succeeded
> | Creating infos file "/opt/IBM/ids1150uc3de/etc/.infos.idsmoon"...succeeded
> | Linking conf file "/opt/IBM/ids1150uc3de/etc/.conf.idsmoon"...succeeded
> | Checking config parameters...succeeded
> | Writing to infos file...succeeded
> | Allocating and attaching to shared memory...succeeded
> | Creating resident pool 10570 kbytes...succeeded
> | Allocating 100016 kbytes for buffer pool of 2K page size...succeeded
> | Initializing rhead structure...succeeded
> | Initialization of Encryption...succeeded
> | Initializing ASF...succeeded
> | Initializing Dictionary Cache and SPL Routine Cache...succeeded
> | Bringing up ADM VP...succeeded
> | Creating VP classes...succeeded
> | Onlining 0 additional cpu vps...succeeded
> | Onlining 2 IO vps...succeeded
> | Forking main_loop thread...succeeded
> | Initializing DR structures...succeeded
> | Forking 1 'soctcp' l