[PATCH] Declare set*id with warn_unused_result
Mike Frysinger
vapier@gentoo.org
Tue Jul 24 16:07:00 GMT 2012
On Tuesday 24 July 2012 07:58:28 Florian Weimer wrote:
> On Linux (except very current versions without funky security modules),
> set*uid can fail with EAGAIN when RLIMIT_NPROC would be exceeded.
> Missing return value checks are known to result in privilege escalation
> vulnerabilities. It is a common coding error to call setuid before
> setgid, so that the setgid fails, and checking for the setgid result
> should prevent this mistake from going unnoticed. Therefore, I think it
> makes sense to add the attribute to both groups of functions.
SGTM
-mike
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: This is a digitally signed message part.
URL: <http://sourceware.org/pipermail/libc-alpha/attachments/20120724/391c5abc/attachment.sig>
More information about the Libc-alpha
mailing list