123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504 |
- /* update-game-score.c --- Update a score file
- Copyright (C) 2002-2015 Free Software Foundation, Inc.
- Author: Colin Walters <walters@debian.org>
- This file is part of GNU Emacs.
- GNU Emacs is free software: you can redistribute it and/or modify
- it under the terms of the GNU General Public License as published by
- the Free Software Foundation, either version 3 of the License, or
- (at your option) any later version.
- GNU Emacs is distributed in the hope that it will be useful,
- but WITHOUT ANY WARRANTY; without even the implied warranty of
- MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
- GNU General Public License for more details.
- You should have received a copy of the GNU General Public License
- along with GNU Emacs. If not, see <http://www.gnu.org/licenses/>. */
- /* This program allows a game to securely and atomically update a
- score file. It should be installed setuid, owned by an appropriate
- user like `games'.
- Alternatively, it can be compiled without HAVE_SHARED_GAME_DIR
- defined, and in that case it will store scores in the user's home
- directory (it should NOT be setuid).
- Created 2002/03/22.
- */
- #include <config.h>
- #include <unistd.h>
- #include <errno.h>
- #include <inttypes.h>
- #include <limits.h>
- #include <stdbool.h>
- #include <string.h>
- #include <stdlib.h>
- #include <stdio.h>
- #include <time.h>
- #include <pwd.h>
- #include <ctype.h>
- #include <fcntl.h>
- #include <sys/stat.h>
- #include <getopt.h>
- #ifdef WINDOWSNT
- #include "ntlib.h"
- #endif
- #ifndef min
- # define min(a,b) ((a) < (b) ? (a) : (b))
- #endif
- #define MAX_ATTEMPTS 5
- #define MAX_DATA_LEN 1024
- static _Noreturn void
- usage (int err)
- {
- fprintf (stdout, "Usage: update-game-score [-m MAX] [-r] [-d DIR] game/scorefile SCORE DATA\n");
- fprintf (stdout, " update-game-score -h\n");
- fprintf (stdout, " -h\t\tDisplay this help.\n");
- fprintf (stdout, " -m MAX\t\tLimit the maximum number of scores to MAX.\n");
- fprintf (stdout, " -r\t\tSort the scores in increasing order.\n");
- fprintf (stdout, " -d DIR\t\tStore scores in DIR (only if not setuid).\n");
- exit (err);
- }
- static int lock_file (const char *filename, void **state);
- static int unlock_file (const char *filename, void *state);
- struct score_entry
- {
- char *score;
- char *user_data;
- };
- #define MAX_SCORES min (PTRDIFF_MAX, SIZE_MAX / sizeof (struct score_entry))
- static int read_scores (const char *filename, struct score_entry **scores,
- ptrdiff_t *count, ptrdiff_t *alloc);
- static int push_score (struct score_entry **scores, ptrdiff_t *count,
- ptrdiff_t *size, struct score_entry const *newscore);
- static void sort_scores (struct score_entry *scores, ptrdiff_t count,
- bool reverse);
- static int write_scores (const char *filename,
- const struct score_entry *scores, ptrdiff_t count);
- static _Noreturn void
- lose (const char *msg)
- {
- fprintf (stderr, "%s\n", msg);
- exit (EXIT_FAILURE);
- }
- static _Noreturn void
- lose_syserr (const char *msg)
- {
- fprintf (stderr, "%s: %s\n", msg,
- errno ? strerror (errno) : "Invalid data in score file");
- exit (EXIT_FAILURE);
- }
- static char *
- get_user_id (void)
- {
- struct passwd *buf = getpwuid (getuid ());
- if (!buf || strchr (buf->pw_name, ' ') || strchr (buf->pw_name, '\n'))
- {
- intmax_t uid = getuid ();
- char *name = malloc (sizeof uid * CHAR_BIT / 3 + 4);
- if (name)
- sprintf (name, "%"PRIdMAX, uid);
- return name;
- }
- return buf->pw_name;
- }
- static const char *
- get_prefix (bool running_suid, const char *user_prefix)
- {
- if (!running_suid && user_prefix == NULL)
- lose ("Not using a shared game directory, and no prefix given.");
- if (running_suid)
- {
- #ifdef HAVE_SHARED_GAME_DIR
- return HAVE_SHARED_GAME_DIR;
- #else
- lose ("This program was compiled without HAVE_SHARED_GAME_DIR,\n and should not be suid.");
- #endif
- }
- return user_prefix;
- }
- static char *
- normalize_integer (char *num)
- {
- bool neg;
- char *p;
- while (*num != '\n' && isspace (*num))
- num++;
- neg = *num == '-';
- num += neg || *num == '-';
- if (*num == '0')
- {
- while (*++num == '0')
- continue;
- neg &= !!*num;
- num -= !*num;
- }
- for (p = num; '0' <= *p && *p <= '9'; p++)
- continue;
- if (*p || p == num)
- {
- errno = 0;
- return 0;
- }
- if (neg)
- *--num = '-';
- return num;
- }
- int
- main (int argc, char **argv)
- {
- int c;
- bool running_suid;
- void *lockstate;
- char *scorefile;
- char *end, *nl, *user, *data;
- const char *prefix, *user_prefix = NULL;
- struct score_entry *scores;
- struct score_entry newscore;
- bool reverse = false;
- ptrdiff_t scorecount, scorealloc;
- ptrdiff_t max_scores = MAX_SCORES;
- srand (time (0));
- while ((c = getopt (argc, argv, "hrm:d:")) != -1)
- switch (c)
- {
- case 'h':
- usage (EXIT_SUCCESS);
- break;
- case 'd':
- user_prefix = optarg;
- break;
- case 'r':
- reverse = 1;
- break;
- case 'm':
- {
- intmax_t m = strtoimax (optarg, &end, 10);
- if (optarg == end || *end || m < 0)
- usage (EXIT_FAILURE);
- max_scores = min (m, MAX_SCORES);
- }
- break;
- default:
- usage (EXIT_FAILURE);
- }
- if (argc - optind != 3)
- usage (EXIT_FAILURE);
- running_suid = (getuid () != geteuid ());
- prefix = get_prefix (running_suid, user_prefix);
- scorefile = malloc (strlen (prefix) + strlen (argv[optind]) + 2);
- if (!scorefile)
- lose_syserr ("Couldn't allocate score file");
- char *z = stpcpy (scorefile, prefix);
- *z++ = '/';
- strcpy (z, argv[optind]);
- newscore.score = normalize_integer (argv[optind + 1]);
- if (! newscore.score)
- {
- fprintf (stderr, "%s: Invalid score\n", argv[optind + 1]);
- return EXIT_FAILURE;
- }
- user = get_user_id ();
- if (! user)
- lose_syserr ("Couldn't determine user id");
- data = argv[optind + 2];
- if (strlen (data) > MAX_DATA_LEN)
- data[MAX_DATA_LEN] = '\0';
- nl = strchr (data, '\n');
- if (nl)
- *nl = '\0';
- newscore.user_data = malloc (strlen (user) + 1 + strlen (data) + 1);
- if (! newscore.user_data
- || sprintf (newscore.user_data, "%s %s", user, data) < 0)
- lose_syserr ("Memory exhausted");
- if (lock_file (scorefile, &lockstate) < 0)
- lose_syserr ("Failed to lock scores file");
- if (read_scores (scorefile, &scores, &scorecount, &scorealloc) < 0)
- {
- unlock_file (scorefile, lockstate);
- lose_syserr ("Failed to read scores file");
- }
- if (push_score (&scores, &scorecount, &scorealloc, &newscore) < 0)
- {
- unlock_file (scorefile, lockstate);
- lose_syserr ("Failed to add score");
- }
- sort_scores (scores, scorecount, reverse);
- /* Limit the number of scores. If we're using reverse sorting, then
- also increment the beginning of the array, to skip over the
- *smallest* scores. Otherwise, just decrementing the number of
- scores suffices, since the smallest is at the end. */
- if (scorecount > max_scores)
- {
- if (reverse)
- scores += scorecount - max_scores;
- scorecount = max_scores;
- }
- if (write_scores (scorefile, scores, scorecount) < 0)
- {
- unlock_file (scorefile, lockstate);
- lose_syserr ("Failed to write scores file");
- }
- if (unlock_file (scorefile, lockstate) < 0)
- lose_syserr ("Failed to unlock scores file");
- exit (EXIT_SUCCESS);
- }
- static char *
- read_score (char *p, struct score_entry *score)
- {
- score->score = p;
- p = strchr (p, ' ');
- if (!p)
- return p;
- *p++ = 0;
- score->user_data = p;
- p = strchr (p, '\n');
- if (!p)
- return p;
- *p++ = 0;
- return p;
- }
- static int
- read_scores (const char *filename, struct score_entry **scores,
- ptrdiff_t *count, ptrdiff_t *alloc)
- {
- char *p, *filedata;
- ptrdiff_t filesize, nread;
- struct stat st;
- FILE *f = fopen (filename, "r");
- if (!f)
- return -1;
- if (fstat (fileno (f), &st) != 0)
- return -1;
- if (! (0 <= st.st_size && st.st_size < min (PTRDIFF_MAX, SIZE_MAX)))
- {
- errno = EOVERFLOW;
- return -1;
- }
- filesize = st.st_size;
- filedata = malloc (filesize + 1);
- if (! filedata)
- return -1;
- nread = fread (filedata, 1, filesize + 1, f);
- if (filesize < nread)
- {
- errno = 0;
- return -1;
- }
- if (nread < filesize)
- filesize = nread;
- if (ferror (f) || fclose (f) != 0)
- return -1;
- filedata[filesize] = 0;
- if (strlen (filedata) != filesize)
- {
- errno = 0;
- return -1;
- }
- *scores = 0;
- *count = *alloc = 0;
- for (p = filedata; p < filedata + filesize; )
- {
- struct score_entry entry;
- p = read_score (p, &entry);
- if (!p)
- {
- errno = 0;
- return -1;
- }
- if (push_score (scores, count, alloc, &entry) < 0)
- return -1;
- }
- return 0;
- }
- static int
- score_compare (const void *a, const void *b)
- {
- const struct score_entry *sa = (const struct score_entry *) a;
- const struct score_entry *sb = (const struct score_entry *) b;
- char *sca = sa->score;
- char *scb = sb->score;
- size_t lena, lenb;
- bool nega = *sca == '-';
- bool negb = *scb == '-';
- int diff = nega - negb;
- if (diff)
- return diff;
- if (nega)
- {
- char *tmp = sca;
- sca = scb + 1;
- scb = tmp + 1;
- }
- lena = strlen (sca);
- lenb = strlen (scb);
- if (lena != lenb)
- return lenb < lena ? -1 : 1;
- return strcmp (scb, sca);
- }
- static int
- score_compare_reverse (const void *a, const void *b)
- {
- return score_compare (b, a);
- }
- int
- push_score (struct score_entry **scores, ptrdiff_t *count, ptrdiff_t *size,
- struct score_entry const *newscore)
- {
- struct score_entry *newscores = *scores;
- if (*count == *size)
- {
- ptrdiff_t newsize = *size;
- if (newsize <= 0)
- newsize = 1;
- else if (newsize <= MAX_SCORES / 2)
- newsize *= 2;
- else if (newsize < MAX_SCORES)
- newsize = MAX_SCORES;
- else
- {
- errno = ENOMEM;
- return -1;
- }
- newscores = realloc (newscores, sizeof *newscores * newsize);
- if (!newscores)
- return -1;
- *scores = newscores;
- *size = newsize;
- }
- newscores[*count] = *newscore;
- (*count) += 1;
- return 0;
- }
- static void
- sort_scores (struct score_entry *scores, ptrdiff_t count, bool reverse)
- {
- qsort (scores, count, sizeof *scores,
- reverse ? score_compare_reverse : score_compare);
- }
- static int
- write_scores (const char *filename, const struct score_entry *scores,
- ptrdiff_t count)
- {
- int fd;
- FILE *f;
- ptrdiff_t i;
- char *tempfile = malloc (strlen (filename) + strlen (".tempXXXXXX") + 1);
- if (!tempfile)
- return -1;
- strcpy (stpcpy (tempfile, filename), ".tempXXXXXX");
- fd = mkostemp (tempfile, 0);
- if (fd < 0)
- return -1;
- #ifndef DOS_NT
- if (fchmod (fd, 0644) != 0)
- return -1;
- #endif
- f = fdopen (fd, "w");
- if (! f)
- return -1;
- for (i = 0; i < count; i++)
- if (fprintf (f, "%s %s\n", scores[i].score, scores[i].user_data) < 0)
- return -1;
- if (fclose (f) != 0)
- return -1;
- if (rename (tempfile, filename) != 0)
- return -1;
- return 0;
- }
- static int
- lock_file (const char *filename, void **state)
- {
- int fd;
- struct stat buf;
- int attempts = 0;
- const char *lockext = ".lockfile";
- char *lockpath = malloc (strlen (filename) + strlen (lockext) + 60);
- if (!lockpath)
- return -1;
- strcpy (stpcpy (lockpath, filename), lockext);
- *state = lockpath;
- while ((fd = open (lockpath, O_CREAT | O_EXCL, 0600)) < 0)
- {
- if (errno != EEXIST)
- return -1;
- attempts++;
- /* Break the lock if it is over an hour old, or if we've tried
- more than MAX_ATTEMPTS times. We won't corrupt the file, but
- we might lose some scores. */
- if (MAX_ATTEMPTS < attempts
- || (stat (lockpath, &buf) == 0 && 60 * 60 < time (0) - buf.st_ctime))
- {
- if (unlink (lockpath) != 0 && errno != ENOENT)
- return -1;
- attempts = 0;
- }
- sleep ((rand () & 1) + 1);
- }
- close (fd);
- return 0;
- }
- static int
- unlock_file (const char *filename, void *state)
- {
- char *lockpath = (char *) state;
- int saved_errno = errno;
- int ret = unlink (lockpath);
- int unlink_errno = errno;
- free (lockpath);
- errno = ret < 0 ? unlink_errno : saved_errno;
- return ret;
- }
- /* update-game-score.c ends here */
|