Add file access tests using effective UID/GID (20.08) #422
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What:
The new functions gvm_file_exists, gvm_file_is_executable and
gvm_file_is_readable are added as an alternative to g_file_test that
tests the file access according to the effective user and group ID
instead of the real one.
Why:
The change is required for gvmd to work properly with the file flags
to set the UID and GID
How:
I tested the functions with a small test program like this:
The cases I checked were:
test.txt
not existingbut setting the setuid and setgid flags of the executable so it is run as a user with
access to the file.
Checklist: