aboutsummaryrefslogtreecommitdiffhomepage
path: root/cmd/fsu/main.go
diff options
context:
space:
mode:
Diffstat (limited to 'cmd/fsu/main.go')
-rw-r--r--cmd/fsu/main.go23
1 files changed, 5 insertions, 18 deletions
diff --git a/cmd/fsu/main.go b/cmd/fsu/main.go
index fd3ba1e2..33ecbf43 100644
--- a/cmd/fsu/main.go
+++ b/cmd/fsu/main.go
@@ -13,7 +13,6 @@ import (
)
const (
- compPoison = "INVALIDINVALIDINVALIDINVALIDINVALID"
fsuConfFile = "/etc/fsurc"
envShim = "FORTIFY_SHIM"
envAID = "FORTIFY_APP_ID"
@@ -22,10 +21,6 @@ const (
PR_SET_NO_NEW_PRIVS = 0x26
)
-var (
- Fmain = compPoison
-)
-
func main() {
log.SetFlags(0)
log.SetPrefix("fsu: ")
@@ -40,20 +35,16 @@ func main() {
log.Fatal("this program must not be started by root")
}
- var fmain string
- if p, ok := checkPath(Fmain); !ok {
- log.Fatal("invalid fortify path, this copy of fsu is not compiled correctly")
- } else {
- fmain = p
- }
-
+ var toolPath string
pexe := path.Join("/proc", strconv.Itoa(os.Getppid()), "exe")
if p, err := os.Readlink(pexe); err != nil {
log.Fatalf("cannot read parent executable path: %v", err)
} else if strings.HasSuffix(p, " (deleted)") {
log.Fatal("fortify executable has been deleted")
- } else if p != fmain {
+ } else if p != mustCheckPath(fmain) && p != mustCheckPath(fpkg) {
log.Fatal("this program must be started by fortify")
+ } else {
+ toolPath = p
}
// uid = 1000000 +
@@ -147,13 +138,9 @@ func main() {
if _, _, errno := syscall.AllThreadsSyscall(syscall.SYS_PRCTL, PR_SET_NO_NEW_PRIVS, 1, 0); errno != 0 {
log.Fatalf("cannot set no_new_privs flag: %s", errno.Error())
}
- if err := syscall.Exec(fmain, []string{"fortify", "shim"}, []string{envShim + "=" + shimSetupFd}); err != nil {
+ if err := syscall.Exec(toolPath, []string{"fortify", "shim"}, []string{envShim + "=" + shimSetupFd}); err != nil {
log.Fatalf("cannot start shim: %v", err)
}
panic("unreachable")
}
-
-func checkPath(p string) (string, bool) {
- return p, p != compPoison && p != "" && path.IsAbs(p)
-}