|
| 1 | +/* Black Belt Ethical Auditor - alternate no-save launcher. */ |
| 2 | +#define _POSIX_C_SOURCE 200809L |
| 3 | +#include <stdio.h> |
| 4 | +#include <stdlib.h> |
| 5 | +#include <string.h> |
| 6 | +#include <unistd.h> |
| 7 | +#include <limits.h> |
| 8 | + |
| 9 | +static int copy_argument(char **dst, int *outc, int max, const char *arg) { |
| 10 | + if (*outc >= max) return 0; |
| 11 | + dst[(*outc)++] = (char *)arg; |
| 12 | + return 1; |
| 13 | +} |
| 14 | + |
| 15 | +int main(int argc, char **argv) { |
| 16 | + char executable[PATH_MAX]; |
| 17 | + ssize_t n = readlink("/proc/self/exe", executable, sizeof(executable) - 1); |
| 18 | + if (n < 0 || (size_t)n >= sizeof(executable) - 1) { |
| 19 | + perror("blackbelt-2: cannot locate executable"); |
| 20 | + return 127; |
| 21 | + } |
| 22 | + executable[n] = '\0'; |
| 23 | + char *slash = strrchr(executable, '/'); |
| 24 | + if (!slash) { |
| 25 | + fprintf(stderr, "blackbelt-2: invalid executable path\n"); |
| 26 | + return 127; |
| 27 | + } |
| 28 | + *slash = '\0'; |
| 29 | + char blackbelt_c[PATH_MAX]; |
| 30 | + if (snprintf(blackbelt_c, sizeof(blackbelt_c), "%s/blackbelt-c", executable) >= (int)sizeof(blackbelt_c)) { |
| 31 | + fprintf(stderr, "blackbelt-2: executable path is too long\n"); |
| 32 | + return 127; |
| 33 | + } |
| 34 | + |
| 35 | + setenv("BBEA_NO_SAVE", "1", 1); |
| 36 | + |
| 37 | + /* This alternate binary is deliberately no-save: reject --save FILE rather |
| 38 | + than allowing the underlying standard binary to write a response file. */ |
| 39 | + char *child_argv[argc + 2]; |
| 40 | + int child_argc = 0; |
| 41 | + copy_argument(child_argv, &child_argc, argc + 1, blackbelt_c); |
| 42 | + for (int i = 1; i < argc; ++i) { |
| 43 | + if (!strcmp(argv[i], "--save")) { |
| 44 | + if (i + 1 < argc) ++i; |
| 45 | + fprintf(stderr, "blackbelt-2: --save is disabled; output will not be saved\n"); |
| 46 | + continue; |
| 47 | + } |
| 48 | + if (!copy_argument(child_argv, &child_argc, argc + 1, argv[i])) return 2; |
| 49 | + } |
| 50 | + child_argv[child_argc] = NULL; |
| 51 | + |
| 52 | + execv(blackbelt_c, child_argv); |
| 53 | + perror("blackbelt-2: exec blackbelt-c"); |
| 54 | + return 127; |
| 55 | +} |
0 commit comments