… | |
… | |
51 | #if (defined(HAVE_SETEUID) || defined(HAVE_SETREUID)) && !defined(__CYGWIN32__) |
51 | #if (defined(HAVE_SETEUID) || defined(HAVE_SETREUID)) && !defined(__CYGWIN32__) |
52 | static uid_t saved_euid; |
52 | static uid_t saved_euid; |
53 | static gid_t saved_egid; |
53 | static gid_t saved_egid; |
54 | #endif |
54 | #endif |
55 | |
55 | |
|
|
56 | bool |
|
|
57 | rxvt_tainted () |
|
|
58 | { |
|
|
59 | #if (defined(HAVE_SETEUID) || defined(HAVE_SETREUID)) && !defined(__CYGWIN32__) |
|
|
60 | return getuid () != saved_euid || getgid () != saved_egid; |
|
|
61 | #else |
|
|
62 | return false; |
|
|
63 | #endif |
|
|
64 | } |
|
|
65 | |
56 | vector<rxvt_term *> rxvt_term::termlist; |
66 | vector<rxvt_term *> rxvt_term::termlist; |
57 | |
67 | |
58 | static char curlocale[128], savelocale[128]; |
68 | static char curlocale[128], savelocale[128]; |
59 | |
69 | |
60 | bool |
70 | bool |
… | |
… | |
66 | strncpy (curlocale, locale, 128); |
76 | strncpy (curlocale, locale, 128); |
67 | setlocale (LC_CTYPE, curlocale); |
77 | setlocale (LC_CTYPE, curlocale); |
68 | return true; |
78 | return true; |
69 | } |
79 | } |
70 | |
80 | |
71 | bool |
81 | void |
72 | rxvt_push_locale (const char *locale) |
82 | rxvt_push_locale (const char *locale) |
73 | { |
83 | { |
74 | strcpy (savelocale, curlocale); |
84 | strcpy (savelocale, curlocale); |
75 | rxvt_set_locale (locale); |
85 | rxvt_set_locale (locale); |
76 | } |
86 | } |
… | |
… | |
278 | // TODO: free pixcolours, colours should become part of rxvt_display |
288 | // TODO: free pixcolours, colours should become part of rxvt_display |
279 | |
289 | |
280 | delete pix_colors_focused; |
290 | delete pix_colors_focused; |
281 | #if OFF_FOCUS_FADING |
291 | #if OFF_FOCUS_FADING |
282 | delete pix_colors_unfocused; |
292 | delete pix_colors_unfocused; |
283 | #endif |
|
|
284 | #if USE_XGETDEFAULT |
|
|
285 | XrmDestroyDatabase (xrmdatabase); |
|
|
286 | #endif |
293 | #endif |
287 | |
294 | |
288 | displays.put (display); |
295 | displays.put (display); |
289 | |
296 | |
290 | scr_release (); |
297 | scr_release (); |
… | |
… | |
502 | |
509 | |
503 | if ((rs[Rs_perl_ext_1] && *rs[Rs_perl_ext_1]) |
510 | if ((rs[Rs_perl_ext_1] && *rs[Rs_perl_ext_1]) |
504 | || (rs[Rs_perl_ext_2] && *rs[Rs_perl_ext_2]) |
511 | || (rs[Rs_perl_ext_2] && *rs[Rs_perl_ext_2]) |
505 | || (rs[Rs_perl_eval] && *rs[Rs_perl_eval])) |
512 | || (rs[Rs_perl_eval] && *rs[Rs_perl_eval])) |
506 | { |
513 | { |
507 | bool tainted = false; |
|
|
508 | |
|
|
509 | #if (defined(HAVE_SETEUID) || defined(HAVE_SETREUID)) && !defined(__CYGWIN32__) |
514 | #if (defined(HAVE_SETEUID) || defined(HAVE_SETREUID)) && !defined(__CYGWIN32__) |
510 | // ignore some perl-related arguments if some bozo installed us set[ug]id |
515 | // ignore some perl-related arguments if some bozo installed us set[ug]id |
511 | if (getuid () != saved_euid || getgid () != saved_egid) |
516 | if (rxvt_tainted ()) |
512 | { |
517 | { |
513 | tainted = true; |
|
|
514 | |
|
|
515 | if ((rs[Rs_perl_lib] && *rs[Rs_perl_lib]) |
518 | if ((rs[Rs_perl_lib] && *rs[Rs_perl_lib]) |
516 | || (rs[Rs_perl_eval] && *rs[Rs_perl_eval])) |
519 | || (rs[Rs_perl_eval] && *rs[Rs_perl_eval])) |
517 | { |
520 | { |
518 | rxvt_warn ("running with elevated privileges: ignoring perl-lib and perl-eval.\n"); |
521 | rxvt_warn ("running with elevated privileges: ignoring perl-lib and perl-eval.\n"); |
519 | rs[Rs_perl_lib] = 0; |
522 | rs[Rs_perl_lib] = 0; |
520 | rs[Rs_perl_eval] = "our $tainted = 1"; |
523 | rs[Rs_perl_eval] = 0; |
521 | } |
524 | } |
522 | } |
525 | } |
523 | #endif |
526 | #endif |
524 | rxvt_perl.init (tainted); |
527 | rxvt_perl.init (); |
525 | HOOK_INVOKE ((this, HOOK_INIT, DT_END)); |
528 | HOOK_INVOKE ((this, HOOK_INIT, DT_END)); |
526 | } |
529 | } |
527 | #endif |
530 | #endif |
528 | |
531 | |
529 | create_windows (argc, argv); |
532 | create_windows (argc, argv); |
… | |
… | |
639 | |
642 | |
640 | old_xerror_handler = XSetErrorHandler ((XErrorHandler) rxvt_xerror_handler); |
643 | old_xerror_handler = XSetErrorHandler ((XErrorHandler) rxvt_xerror_handler); |
641 | // TODO: handle this with exceptions and tolerate the memory loss |
644 | // TODO: handle this with exceptions and tolerate the memory loss |
642 | XSetIOErrorHandler (rxvt_xioerror_handler); |
645 | XSetIOErrorHandler (rxvt_xioerror_handler); |
643 | |
646 | |
644 | #ifdef USE_XGETDEFAULT |
|
|
645 | XrmInitialize (); |
647 | XrmInitialize (); |
646 | #endif |
|
|
647 | } |
648 | } |
648 | |
649 | |
649 | /* ------------------------------------------------------------------------- * |
650 | /* ------------------------------------------------------------------------- * |
650 | * MEMORY ALLOCATION WRAPPERS * |
651 | * MEMORY ALLOCATION WRAPPERS * |
651 | * ------------------------------------------------------------------------- */ |
652 | * ------------------------------------------------------------------------- */ |