Conversation
When the exec of a hook script fails, the child reopens syslog and logs "Can't execute <script>: %m". reopen_log() can change errno, so the message may show the error from reopening the log instead of the one from the exec. On OmniOS this reported "Bad file number" where the exec had actually failed with EFAULT. Save errno before reopen_log() and restore it before logging. Signed-off-by: Adam Zegarek <keragez@gmail.com>
Since 6a4944f, with strict-script-checks (the default), run_program() executes hook scripts through the descriptor it checked, using fexecve() or /dev/fd/N. On illumos neither works for #! scripts, so ip-up, ip-down, auth-up and the other hooks never run; the child exits with status 99 and logs "Can't execute ...". Tested on OmniOS r151058: - fexecve(fd, ...) fails with EFAULT - execve("/dev/fd/N", ...) fails with EACCES (not a regular file) - execve("/proc/self/fd/N", ...) hangs the child On SOL2, exec the script by path as 2.5.3 did, but only if stat() of the path still gives the same device and inode as fstat() of the checked descriptor. This leaves a small window between the stat() and the execve() instead of none, which pppd.8 now mentions. Linux is unchanged. Fixes: 6a4944f ("pppd: relax and simplify permission check") Signed-off-by: Adam Zegarek <keragez@gmail.com>
With "pppd: Exec hook scripts by path on Solaris/illumos" the hooks run on OmniOS, so drop the XFAIL for hooks that fail to exec there. Such a failure is now a plain FAIL on every platform; the pppd log line with the exit status is still included in the message. Signed-off-by: Adam Zegarek <keragez@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #639.
On illumos, hook scripts (
ip-up,ip-down,auth-up, ...) don't run in 2.5.4: none of the fd-based exec methods work for#!scripts there (fexecve()→EFAULT,/dev/fd/N→EACCES,/proc/self/fd/Nhangs). OnSOL2, this restores exec by path as in 2.5.3, but only ifstat()of the path still matchesfstat()of the checked descriptor. That leaves a small check-to-exec window on Solaris/illumos, documented inpppd.8. Linux is unchanged.Also fixes the
"Can't execute"message reporting a wrongerrno, which made this hard to diagnose.Testing: OmniOS
script-runpasses with this PR, with all five hooks running and labelled correctly. On master it reportsXFAIL(hooks exit 99).