MCPcopy Create free account
hub / github.com/DeusData/codebase-memory-mcp / private_log_directory_path_copy

Function private_log_directory_path_copy

src/daemon/ipc.c:1346–1380  ·  view source on GitHub ↗

Source from the content-addressed store, hash-verified

1344}
1345
1346static char *private_log_directory_path_copy(const char *directory_path) {
1347#ifdef __APPLE__
1348 /* Darwin exposes the trusted top-level aliases /tmp -> /private/tmp and
1349 * /var -> /private/var. Resolve only those root-owned aliases before the
1350 * component-wise O_NOFOLLOW walk. Canonicalizing the complete caller path
1351 * would follow an attacker-controlled cache/log symlink and is forbidden. */
1352 static const char *const aliases[] = {"/tmp", "/var"};
1353 for (size_t index = 0; index < sizeof(aliases) / sizeof(aliases[0]); index++) {
1354 const char *alias = aliases[index];
1355 size_t alias_length = strlen(alias);
1356 if (strncmp(directory_path, alias, alias_length) != 0 ||
1357 (directory_path[alias_length] != '\0' && directory_path[alias_length] != '/')) {
1358 continue;
1359 }
1360 struct stat alias_status;
1361 if (lstat(alias, &alias_status) != 0 || !S_ISLNK(alias_status.st_mode)) {
1362 break;
1363 }
1364 struct stat root_status;
1365 char resolved[CBM_DAEMON_IPC_PATH_CAP];
1366 if (alias_status.st_uid != 0 || lstat("/", &root_status) != 0 ||
1367 !S_ISDIR(root_status.st_mode) || root_status.st_uid != 0 ||
1368 (root_status.st_mode & 0022) != 0 || !realpath(alias, resolved)) {
1369 return NULL;
1370 }
1371 struct stat resolved_status;
1372 if (lstat(resolved, &resolved_status) != 0 || !S_ISDIR(resolved_status.st_mode) ||
1373 resolved_status.st_uid != 0) {
1374 return NULL;
1375 }
1376 return string_format("%s%s", resolved, directory_path + alias_length);
1377 }
1378#endif
1379 return string_copy(directory_path);
1380}
1381
1382static bool posix_directory_owner_trusted(uid_t owner) {
1383 return owner == (uid_t)0 || owner == geteuid();

Callers 1

Calls 2

string_formatFunction · 0.85
string_copyFunction · 0.85

Tested by

no test coverage detected