Mercurial > geeqie
annotate src/secure_save.c @ 773:4acde7a0bb01
do not change original FileData on copy
author | nadvornik |
---|---|
date | Sat, 31 May 2008 19:46:26 +0000 |
parents | 9873d695a9c1 |
children | 4fe8f9656107 |
rev | line source |
---|---|
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
1 /* |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
2 * Geeqie |
475 | 3 * Copyright (C) 2008 The Geeqie Team |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
4 * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
5 * based on the code developped for ELinks by Laurent Monin |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
6 * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
7 * This software is released under the GNU General Public License (GNU GPL). |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
8 * Please read the included file COPYING for more information. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
9 * This software comes with no warranty of any kind, use at your own risk! |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
10 */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
11 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
12 #include <glib/gstdio.h> |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
13 #include <errno.h> |
311
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
14 #include <utime.h> |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
15 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
16 #include "main.h" |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
17 #include "secure_save.h" |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
18 |
507 | 19 |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
20 /* ABOUT SECURE SAVE */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
21 /* This code was borrowed from the ELinks project (http://elinks.cz) |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
22 * It was originally written by me (Laurent Monin aka Zas) and heavily |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
23 * modified and improved by all ELinks contributors. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
24 * This code was released under the GPLv2 licence. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
25 * It was modified to be included in geeqie on 2008/04/05 */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
26 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
27 /* If ssi->secure_save is TRUE: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
28 * ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
29 * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
30 * A call to secure_open("/home/me/.confdir/filename", mask) will open a file |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
31 * named "filename.tmp_XXXXXX" in /home/me/.confdir/ and return a pointer to a |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
32 * structure SecureSaveInfo on success or NULL on error. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
33 * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
34 * filename.tmp_XXXXXX can't conflict with any file since it's created using |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
35 * mkstemp(). XXXXXX is a random string. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
36 * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
37 * Subsequent write operations are done using returned SecureSaveInfo FILE * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
38 * field named fp. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
39 * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
40 * If an error is encountered, SecureSaveInfo int field named err is set |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
41 * (automatically if using secure_fp*() functions or by programmer) |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
42 * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
43 * When secure_close() is called, "filename.tmp_XXXXXX" is flushed and closed, |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
44 * and if SecureSaveInfo err field has a value of zero, "filename.tmp_XXXXXX" |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
45 * is renamed to "filename". If this succeeded, then secure_close() returns 0. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
46 * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
47 * WARNING: since rename() is used, any symlink called "filename" may be |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
48 * replaced by a regular file. If destination file isn't a regular file, |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
49 * then secsave is disabled for that file. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
50 * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
51 * If ssi->secure_save is FALSE: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
52 * ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
53 * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
54 * No temporary file is created, "filename" is truncated, all operations are |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
55 * done on it, no rename nor flush occur, symlinks are preserved. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
56 * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
57 * In both cases: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
58 * ~~~~~~~~~~~~~ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
59 * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
60 * Access rights are affected by secure_open() mask parameter. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
61 */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
62 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
63 /* FIXME: locking system on files about to be rewritten ? */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
64 /* FIXME: Low risk race conditions about ssi->file_name. */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
65 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
66 SecureSaveErrno secsave_errno = SS_ERR_NONE; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
67 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
68 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
69 /** Open a file for writing in a secure way. @returns a pointer to a |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
70 * structure secure_save_info on success, or NULL on failure. */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
71 static SecureSaveInfo * |
309 | 72 secure_open_umask(const gchar *file_name) |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
73 { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
74 struct stat st; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
75 SecureSaveInfo *ssi; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
76 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
77 secsave_errno = SS_ERR_NONE; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
78 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
79 ssi = g_new0(SecureSaveInfo, 1); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
80 if (!ssi) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
81 secsave_errno = SS_ERR_OUT_OF_MEM; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
82 goto end; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
83 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
84 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
85 ssi->secure_save = TRUE; |
311
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
86 ssi->preserve_perms = TRUE; |
313
a955b7fd626b
Secure save now unlinks temporary file on error by default.
zas_
parents:
311
diff
changeset
|
87 ssi->unlink_on_error = TRUE; |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
88 |
310
4b25b3b30f35
Revert part of the previous patch, let the caller take care
zas_
parents:
309
diff
changeset
|
89 ssi->file_name = g_strdup(file_name); |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
90 if (!ssi->file_name) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
91 secsave_errno = SS_ERR_OUT_OF_MEM; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
92 goto free_f; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
93 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
94 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
95 /* Check properties of final file. */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
96 #ifndef NO_UNIX_SOFTLINKS |
699
9873d695a9c1
Do not use glib posix wrappers since they were introduced in 2.6
zas_
parents:
698
diff
changeset
|
97 if (lstat(ssi->file_name, &st)) { |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
98 #else |
699
9873d695a9c1
Do not use glib posix wrappers since they were introduced in 2.6
zas_
parents:
698
diff
changeset
|
99 if (stat(ssi->file_name, &st)) { |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
100 #endif |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
101 /* We ignore error caused by file inexistence. */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
102 if (errno != ENOENT) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
103 /* lstat() error. */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
104 ssi->err = errno; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
105 secsave_errno = SS_ERR_STAT; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
106 goto free_file_name; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
107 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
108 } else { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
109 if (!S_ISREG(st.st_mode)) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
110 /* Not a regular file, secure_save is disabled. */ |
313
a955b7fd626b
Secure save now unlinks temporary file on error by default.
zas_
parents:
311
diff
changeset
|
111 ssi->secure_save = FALSE; |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
112 } else { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
113 #ifdef HAVE_ACCESS |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
114 /* XXX: access() do not work with setuid programs. */ |
698
2700db14aaa6
Use access() instead of g_access() which is only available in 2.8.
zas_
parents:
671
diff
changeset
|
115 if (access(ssi->file_name, R_OK | W_OK) < 0) { |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
116 ssi->err = errno; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
117 secsave_errno = SS_ERR_ACCESS; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
118 goto free_file_name; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
119 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
120 #else |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
121 FILE *f1; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
122 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
123 /* We still have a race condition here between |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
124 * [l]stat() and fopen() */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
125 |
699
9873d695a9c1
Do not use glib posix wrappers since they were introduced in 2.6
zas_
parents:
698
diff
changeset
|
126 f1 = fopen(ssi->file_name, "rb+"); |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
127 if (f1) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
128 fclose(f1); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
129 } else { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
130 ssi->err = errno; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
131 secsave_errno = SS_ERR_OPEN_READ; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
132 goto free_file_name; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
133 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
134 #endif |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
135 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
136 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
137 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
138 if (ssi->secure_save) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
139 /* We use a random name for temporary file, mkstemp() opens |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
140 * the file and return a file descriptor named fd, which is |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
141 * then converted to FILE * using fdopen(). |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
142 */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
143 gint fd; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
144 gchar *randname = g_strconcat(ssi->file_name, ".tmp_XXXXXX", NULL); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
145 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
146 if (!randname) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
147 secsave_errno = SS_ERR_OUT_OF_MEM; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
148 goto free_file_name; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
149 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
150 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
151 /* No need to use safe_mkstemp() here. --Zas */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
152 fd = g_mkstemp(randname); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
153 if (fd == -1) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
154 secsave_errno = SS_ERR_MKSTEMP; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
155 g_free(randname); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
156 goto free_file_name; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
157 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
158 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
159 ssi->fp = fdopen(fd, "wb"); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
160 if (!ssi->fp) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
161 secsave_errno = SS_ERR_OPEN_WRITE; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
162 ssi->err = errno; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
163 g_free(randname); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
164 goto free_file_name; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
165 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
166 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
167 ssi->tmp_file_name = randname; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
168 } else { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
169 /* No need to create a temporary file here. */ |
699
9873d695a9c1
Do not use glib posix wrappers since they were introduced in 2.6
zas_
parents:
698
diff
changeset
|
170 ssi->fp = fopen(ssi->file_name, "wb"); |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
171 if (!ssi->fp) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
172 secsave_errno = SS_ERR_OPEN_WRITE; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
173 ssi->err = errno; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
174 goto free_file_name; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
175 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
176 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
177 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
178 return ssi; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
179 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
180 free_file_name: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
181 g_free(ssi->file_name); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
182 ssi->file_name = NULL; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
183 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
184 free_f: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
185 g_free(ssi); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
186 ssi = NULL; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
187 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
188 end: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
189 return NULL; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
190 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
191 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
192 SecureSaveInfo * |
309 | 193 secure_open(const gchar *file_name) |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
194 { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
195 SecureSaveInfo *ssi; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
196 mode_t saved_mask; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
197 #ifdef CONFIG_OS_WIN32 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
198 /* There is neither S_IRWXG nor S_IRWXO under crossmingw32-gcc */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
199 const mode_t mask = 0177; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
200 #else |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
201 const mode_t mask = S_IXUSR | S_IRWXG | S_IRWXO; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
202 #endif |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
203 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
204 saved_mask = umask(mask); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
205 ssi = secure_open_umask(file_name); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
206 umask(saved_mask); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
207 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
208 return ssi; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
209 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
210 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
211 /** Close a file opened with secure_open(). Rreturns 0 on success, |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
212 * errno or -1 on failure. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
213 */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
214 gint |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
215 secure_close(SecureSaveInfo *ssi) |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
216 { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
217 gint ret = -1; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
218 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
219 if (!ssi) return ret; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
220 if (!ssi->fp) goto free; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
221 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
222 if (ssi->err) { /* Keep previous errno. */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
223 ret = ssi->err; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
224 fclose(ssi->fp); /* Close file */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
225 goto free; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
226 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
227 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
228 /* Ensure data is effectively written to disk, we first flush libc buffers |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
229 * using fflush(), then fsync() to flush kernel buffers, and finally call |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
230 * fclose() (which call fflush() again, but the first one is needed since |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
231 * it doesn't make much sense to flush kernel buffers and then libc buffers, |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
232 * while closing file releases file descriptor we need to call fsync(). */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
233 #if defined(HAVE_FFLUSH) || defined(HAVE_FSYNC) |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
234 if (ssi->secure_save) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
235 int fail = 0; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
236 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
237 #ifdef HAVE_FFLUSH |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
238 fail = (fflush(ssi->fp) == EOF); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
239 #endif |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
240 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
241 #ifdef HAVE_FSYNC |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
242 if (!fail) fail = fsync(fileno(ssi->fp)); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
243 #endif |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
244 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
245 if (fail) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
246 ret = errno; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
247 secsave_errno = SS_ERR_OTHER; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
248 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
249 fclose(ssi->fp); /* Close file, ignore errors. */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
250 goto free; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
251 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
252 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
253 #endif |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
254 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
255 /* Close file. */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
256 if (fclose(ssi->fp) == EOF) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
257 ret = errno; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
258 secsave_errno = SS_ERR_OTHER; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
259 goto free; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
260 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
261 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
262 if (ssi->secure_save && ssi->file_name && ssi->tmp_file_name) { |
311
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
263 struct stat st; |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
264 |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
265 /* FIXME: Race condition on ssi->file_name. The file |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
266 * named ssi->file_name may have changed since |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
267 * secure_open() call (where we stat() file and |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
268 * more..). */ |
311
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
269 #ifndef NO_UNIX_SOFTLINKS |
699
9873d695a9c1
Do not use glib posix wrappers since they were introduced in 2.6
zas_
parents:
698
diff
changeset
|
270 if (lstat(ssi->file_name, &st) == 0) |
442 | 271 #else |
699
9873d695a9c1
Do not use glib posix wrappers since they were introduced in 2.6
zas_
parents:
698
diff
changeset
|
272 if (stat(ssi->file_name, &st) == 0) |
311
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
273 #endif |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
274 { |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
275 /* set the dest file attributes to that of source (ignoring errors) */ |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
276 if (ssi->preserve_perms) |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
277 { |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
278 chown(ssi->tmp_file_name, st.st_uid, st.st_gid); |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
279 chmod(ssi->tmp_file_name, st.st_mode); |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
280 } |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
281 |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
282 if (ssi->preserve_mtime) |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
283 { |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
284 struct utimbuf tb; |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
285 |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
286 tb.actime = st.st_atime; |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
287 tb.modtime = st.st_mtime; |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
288 utime(ssi->tmp_file_name, &tb); |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
289 } |
8a6650589829
Preserve permissions of the destination file when using secure save.
zas_
parents:
310
diff
changeset
|
290 } |
506
fc9c8a3e1a8b
Handle the newline in DEBUG_N() macro instead of adding one
zas_
parents:
495
diff
changeset
|
291 DEBUG_3("rename %s -> %s", ssi->tmp_file_name, ssi->file_name); |
699
9873d695a9c1
Do not use glib posix wrappers since they were introduced in 2.6
zas_
parents:
698
diff
changeset
|
292 if (rename(ssi->tmp_file_name, ssi->file_name) == -1) { |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
293 ret = errno; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
294 secsave_errno = SS_ERR_RENAME; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
295 goto free; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
296 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
297 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
298 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
299 ret = 0; /* Success. */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
300 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
301 free: |
313
a955b7fd626b
Secure save now unlinks temporary file on error by default.
zas_
parents:
311
diff
changeset
|
302 if (ssi->tmp_file_name) |
a955b7fd626b
Secure save now unlinks temporary file on error by default.
zas_
parents:
311
diff
changeset
|
303 { |
a955b7fd626b
Secure save now unlinks temporary file on error by default.
zas_
parents:
311
diff
changeset
|
304 if (ret && ssi->unlink_on_error) unlink(ssi->tmp_file_name); |
a955b7fd626b
Secure save now unlinks temporary file on error by default.
zas_
parents:
311
diff
changeset
|
305 g_free(ssi->tmp_file_name); |
a955b7fd626b
Secure save now unlinks temporary file on error by default.
zas_
parents:
311
diff
changeset
|
306 } |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
307 if (ssi->file_name) g_free(ssi->file_name); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
308 if (ssi) g_free(ssi); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
309 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
310 return ret; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
311 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
312 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
313 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
314 /** fputs() wrapper, set ssi->err to errno on error. If ssi->err is set when |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
315 * called, it immediatly returns EOF. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
316 */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
317 gint |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
318 secure_fputs(SecureSaveInfo *ssi, const gchar *s) |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
319 { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
320 gint ret; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
321 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
322 if (!ssi || !ssi->fp || ssi->err) return EOF; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
323 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
324 ret = fputs(s, ssi->fp); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
325 if (ret == EOF) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
326 secsave_errno = SS_ERR_OTHER; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
327 ssi->err = errno; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
328 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
329 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
330 return ret; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
331 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
332 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
333 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
334 /** fputc() wrapper, set ssi->err to errno on error. If ssi->err is set when |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
335 * called, it immediatly returns EOF. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
336 */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
337 gint |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
338 secure_fputc(SecureSaveInfo *ssi, gint c) |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
339 { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
340 gint ret; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
341 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
342 if (!ssi || !ssi->fp || ssi->err) return EOF; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
343 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
344 ret = fputc(c, ssi->fp); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
345 if (ret == EOF) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
346 ssi->err = errno; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
347 secsave_errno = SS_ERR_OTHER; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
348 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
349 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
350 return ret; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
351 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
352 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
353 /** fprintf() wrapper, set ssi->err to errno on error and return a negative |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
354 * value. If ssi->err is set when called, it immediatly returns -1. |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
355 */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
356 gint |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
357 secure_fprintf(SecureSaveInfo *ssi, const gchar *format, ...) |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
358 { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
359 va_list ap; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
360 gint ret; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
361 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
362 if (!ssi || !ssi->fp || ssi->err) return -1; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
363 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
364 va_start(ap, format); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
365 ret = vfprintf(ssi->fp, format, ap); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
366 if (ret < 0) ssi->err = errno; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
367 va_end(ap); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
368 |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
369 return ret; |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
370 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
371 |
536 | 372 /** fwrite() wrapper, set ssi->err to errno on error and return a value less than |
373 * the number of elements to write. If ssi->err is set when called, it immediatly returns 0. | |
374 */ | |
375 size_t | |
376 secure_fwrite(const void *ptr, size_t size, size_t nmemb, SecureSaveInfo *ssi) | |
377 { | |
378 size_t ret; | |
379 | |
380 if (!ssi || !ssi->fp || ssi->err) return 0; | |
381 | |
382 ret = fwrite(ptr, size, nmemb, ssi->fp); | |
383 if (ret < nmemb) | |
384 { | |
385 ssi->err = errno; | |
386 secsave_errno = SS_ERR_OTHER; | |
387 } | |
388 | |
389 return ret; | |
390 } | |
391 | |
307
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
392 gchar * |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
393 secsave_strerror(SecureSaveErrno secsave_error) |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
394 { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
395 switch (secsave_error) { |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
396 case SS_ERR_OPEN_READ: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
397 return _("Cannot read the file"); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
398 case SS_ERR_STAT: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
399 return _("Cannot get file status"); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
400 case SS_ERR_ACCESS: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
401 return _("Cannot access the file"); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
402 case SS_ERR_MKSTEMP: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
403 return _("Cannot create temp file"); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
404 case SS_ERR_RENAME: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
405 return _("Cannot rename the file"); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
406 case SS_ERR_DISABLED: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
407 return _("File saving disabled by option"); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
408 case SS_ERR_OUT_OF_MEM: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
409 return _("Out of memory"); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
410 case SS_ERR_OPEN_WRITE: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
411 return _("Cannot write the file"); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
412 case SS_ERR_NONE: /* Impossible. */ |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
413 case SS_ERR_OTHER: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
414 default: |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
415 return _("Secure file saving error"); |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
416 } |
667e49f52168
Move secure save code to its own files: secure_save.{c,h}.
zas_
parents:
diff
changeset
|
417 } |