// $Id: capchroot.c,v 1.1.4.2 2003/11/28 23:08:43 ensc Exp $ // Copyright (C) 2003 Enrico Scholz // based on capchroot.cc by Jacques Gelinas // // This program is free software; you can redistribute it and/or modify // it under the terms of the GNU General Public License as published by // the Free Software Foundation; either version 2, or (at your option) // any later version. // // This program is distributed in the hope that it will be useful, // but WITHOUT ANY WARRANTY; without even the implied warranty of // MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the // GNU General Public License for more details. // // You should have received a copy of the GNU General Public License // along with this program; if not, write to the Free Software // Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. /* This chroot command does very little. Once the chroot system call is executed, it (option) remove the CAP_SYS_CHROOT capability. Then it executes its argument */ #ifdef HAVE_CONFIG_H # include #endif #include "compat.h" #include #include #include #include #include #include #include #include #include "linuxcaps.h" #include "vserver.h" int main (int argc, char *argv[]) { if (argc < 3){ fprintf (stderr,"capchroot version %s\n",VERSION); fprintf (stderr ,"capchroot --nochroot directory [ --suid user ] command argument\n" "\n" "--nochroot remove the CAP_SYS_CHROOT capability\n" " after the chroot system call.\n" "--suid switch to a different user (in the vserver context)\n" " before executing the command.\n"); }else{ const char *uid = NULL; bool nochroot = false; int dir; for (dir=1; dirpw_gid); setuid(p->pw_uid); } if (cmd >= argc){ fprintf (stderr,"capchroot: No command to execute, do nothing\n"); }else{ execvp (argv[cmd],argv+cmd); fprintf (stderr,"Can't execute %s (%s)\n",argv[cmd] ,strerror(errno)); } } } return -1; }