1*86d7f5d3SJohn Marino /*-
2*86d7f5d3SJohn Marino * Copyright (c) 1999 Robert N. M. Watson
3*86d7f5d3SJohn Marino * All rights reserved.
4*86d7f5d3SJohn Marino *
5*86d7f5d3SJohn Marino * Redistribution and use in source and binary forms, with or without
6*86d7f5d3SJohn Marino * modification, are permitted provided that the following conditions
7*86d7f5d3SJohn Marino * are met:
8*86d7f5d3SJohn Marino * 1. Redistributions of source code must retain the above copyright
9*86d7f5d3SJohn Marino * notice, this list of conditions and the following disclaimer.
10*86d7f5d3SJohn Marino * 2. Redistributions in binary form must reproduce the above copyright
11*86d7f5d3SJohn Marino * notice, this list of conditions and the following disclaimer in the
12*86d7f5d3SJohn Marino * documentation and/or other materials provided with the distribution.
13*86d7f5d3SJohn Marino *
14*86d7f5d3SJohn Marino * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
15*86d7f5d3SJohn Marino * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
16*86d7f5d3SJohn Marino * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
17*86d7f5d3SJohn Marino * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
18*86d7f5d3SJohn Marino * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
19*86d7f5d3SJohn Marino * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
20*86d7f5d3SJohn Marino * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
21*86d7f5d3SJohn Marino * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
22*86d7f5d3SJohn Marino * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
23*86d7f5d3SJohn Marino * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
24*86d7f5d3SJohn Marino * SUCH DAMAGE.
25*86d7f5d3SJohn Marino *
26*86d7f5d3SJohn Marino *$FreeBSD: src/lib/libposix1e/acl_from_text.c,v 1.1 2000/01/15 19:44:24 rwatson Exp $
27*86d7f5d3SJohn Marino *$DragonFly: src/lib/libposix1e/acl_from_text.c,v 1.3 2005/08/04 17:27:09 drhodus Exp $
28*86d7f5d3SJohn Marino */
29*86d7f5d3SJohn Marino /*
30*86d7f5d3SJohn Marino * acl_from_text: convert a text-form ACL from a string to an acl_t
31*86d7f5d3SJohn Marino */
32*86d7f5d3SJohn Marino
33*86d7f5d3SJohn Marino #include <sys/types.h>
34*86d7f5d3SJohn Marino #include <sys/acl.h>
35*86d7f5d3SJohn Marino #include <sys/errno.h>
36*86d7f5d3SJohn Marino #include <stdio.h>
37*86d7f5d3SJohn Marino #include <stdlib.h>
38*86d7f5d3SJohn Marino #include <string.h>
39*86d7f5d3SJohn Marino
40*86d7f5d3SJohn Marino #include "acl_support.h"
41*86d7f5d3SJohn Marino
42*86d7f5d3SJohn Marino enum PARSE_MODE {
43*86d7f5d3SJohn Marino PM_BASE, /* initial, begin line, or after , */
44*86d7f5d3SJohn Marino PM_QUALIFIER, /* in qualifier field */
45*86d7f5d3SJohn Marino PM_PERM, /* in permission field */
46*86d7f5d3SJohn Marino PM_COMMENT, /* in comment */
47*86d7f5d3SJohn Marino };
48*86d7f5d3SJohn Marino
49*86d7f5d3SJohn Marino static char *
string_skip_whitespace(char * string)50*86d7f5d3SJohn Marino string_skip_whitespace(char *string)
51*86d7f5d3SJohn Marino {
52*86d7f5d3SJohn Marino
53*86d7f5d3SJohn Marino while (*string && ((*string == ' ') || (*string == '\t'))) {
54*86d7f5d3SJohn Marino string++;
55*86d7f5d3SJohn Marino }
56*86d7f5d3SJohn Marino return (string);
57*86d7f5d3SJohn Marino }
58*86d7f5d3SJohn Marino
59*86d7f5d3SJohn Marino static void
string_trim_trailing_whitespace(char * string)60*86d7f5d3SJohn Marino string_trim_trailing_whitespace(char *string)
61*86d7f5d3SJohn Marino {
62*86d7f5d3SJohn Marino char *end;
63*86d7f5d3SJohn Marino
64*86d7f5d3SJohn Marino if (*string == '\0')
65*86d7f5d3SJohn Marino return;
66*86d7f5d3SJohn Marino
67*86d7f5d3SJohn Marino end = string + strlen(string) - 1;
68*86d7f5d3SJohn Marino
69*86d7f5d3SJohn Marino while (end != string) {
70*86d7f5d3SJohn Marino if ((*end == ' ') || (*end == '\t')) {
71*86d7f5d3SJohn Marino *end = '\0';
72*86d7f5d3SJohn Marino end--;
73*86d7f5d3SJohn Marino } else {
74*86d7f5d3SJohn Marino return;
75*86d7f5d3SJohn Marino }
76*86d7f5d3SJohn Marino }
77*86d7f5d3SJohn Marino
78*86d7f5d3SJohn Marino return;
79*86d7f5d3SJohn Marino }
80*86d7f5d3SJohn Marino
81*86d7f5d3SJohn Marino acl_tag_t
acl_string_to_tag(char * tag,char * qualifier)82*86d7f5d3SJohn Marino acl_string_to_tag(char *tag, char *qualifier)
83*86d7f5d3SJohn Marino {
84*86d7f5d3SJohn Marino
85*86d7f5d3SJohn Marino if (*qualifier == '\0') {
86*86d7f5d3SJohn Marino if ((!strcmp(tag, "user")) || (!strcmp(tag, "u"))) {
87*86d7f5d3SJohn Marino return (ACL_USER_OBJ);
88*86d7f5d3SJohn Marino } else
89*86d7f5d3SJohn Marino if ((!strcmp(tag, "group")) || (!strcmp(tag, "g"))) {
90*86d7f5d3SJohn Marino return (ACL_GROUP_OBJ);
91*86d7f5d3SJohn Marino } else
92*86d7f5d3SJohn Marino if ((!strcmp(tag, "mask")) || (!strcmp(tag, "m"))) {
93*86d7f5d3SJohn Marino return (ACL_MASK);
94*86d7f5d3SJohn Marino } else
95*86d7f5d3SJohn Marino if ((!strcmp(tag, "other")) || (!strcmp(tag, "o"))) {
96*86d7f5d3SJohn Marino return (ACL_OTHER);
97*86d7f5d3SJohn Marino } else
98*86d7f5d3SJohn Marino return(-1);
99*86d7f5d3SJohn Marino } else {
100*86d7f5d3SJohn Marino if ((!strcmp(tag, "user")) || (!strcmp(tag, "u"))) {
101*86d7f5d3SJohn Marino return(ACL_USER);
102*86d7f5d3SJohn Marino } else
103*86d7f5d3SJohn Marino if ((!strcmp(tag, "group")) || (!strcmp(tag, "g"))) {
104*86d7f5d3SJohn Marino return(ACL_GROUP);
105*86d7f5d3SJohn Marino } else
106*86d7f5d3SJohn Marino return(-1);
107*86d7f5d3SJohn Marino }
108*86d7f5d3SJohn Marino }
109*86d7f5d3SJohn Marino
110*86d7f5d3SJohn Marino /*
111*86d7f5d3SJohn Marino * acl_from_text -- convert a string into an ACL
112*86d7f5d3SJohn Marino * postpone most validity checking until the end and cal acl_valid to do
113*86d7f5d3SJohn Marino * that.
114*86d7f5d3SJohn Marino */
115*86d7f5d3SJohn Marino acl_t
acl_from_text(const char * buf_p)116*86d7f5d3SJohn Marino acl_from_text(const char *buf_p)
117*86d7f5d3SJohn Marino {
118*86d7f5d3SJohn Marino acl_tag_t t;
119*86d7f5d3SJohn Marino acl_perm_t p;
120*86d7f5d3SJohn Marino acl_t acl;
121*86d7f5d3SJohn Marino uid_t id;
122*86d7f5d3SJohn Marino char *mybuf_p, *line, *cur, *notcomment, *comment, *entry;
123*86d7f5d3SJohn Marino char *tag, *qualifier, *permission;
124*86d7f5d3SJohn Marino int error;
125*86d7f5d3SJohn Marino
126*86d7f5d3SJohn Marino /* local copy we can mess up */
127*86d7f5d3SJohn Marino mybuf_p = strdup(buf_p);
128*86d7f5d3SJohn Marino if (!mybuf_p) {
129*86d7f5d3SJohn Marino errno = ENOMEM;
130*86d7f5d3SJohn Marino return(0);
131*86d7f5d3SJohn Marino }
132*86d7f5d3SJohn Marino
133*86d7f5d3SJohn Marino acl = acl_init(3);
134*86d7f5d3SJohn Marino if (!acl) {
135*86d7f5d3SJohn Marino free(mybuf_p);
136*86d7f5d3SJohn Marino errno = ENOMEM;
137*86d7f5d3SJohn Marino return(0);
138*86d7f5d3SJohn Marino }
139*86d7f5d3SJohn Marino
140*86d7f5d3SJohn Marino /* outer loop: delimit at \n boundaries */
141*86d7f5d3SJohn Marino cur = mybuf_p;
142*86d7f5d3SJohn Marino while ((line = strsep(&cur, "\n"))) {
143*86d7f5d3SJohn Marino /* now split the line on the first # to strip out comments */
144*86d7f5d3SJohn Marino comment = line;
145*86d7f5d3SJohn Marino notcomment = strsep(&comment, "#");
146*86d7f5d3SJohn Marino
147*86d7f5d3SJohn Marino /* inner loop: delimit at , boundaries */
148*86d7f5d3SJohn Marino while ((entry = strsep(¬comment, ","))) {
149*86d7f5d3SJohn Marino /* now split into three :-delimited fields */
150*86d7f5d3SJohn Marino tag = strsep(&entry, ":");
151*86d7f5d3SJohn Marino if (!tag) {
152*86d7f5d3SJohn Marino /* printf("no tag\n"); */
153*86d7f5d3SJohn Marino errno = EINVAL;
154*86d7f5d3SJohn Marino goto error_label;
155*86d7f5d3SJohn Marino }
156*86d7f5d3SJohn Marino tag = string_skip_whitespace(tag);
157*86d7f5d3SJohn Marino if ((*tag == '\0') && (!entry)) {
158*86d7f5d3SJohn Marino /*
159*86d7f5d3SJohn Marino * is an entirely comment line, skip to next
160*86d7f5d3SJohn Marino * comma
161*86d7f5d3SJohn Marino */
162*86d7f5d3SJohn Marino continue;
163*86d7f5d3SJohn Marino }
164*86d7f5d3SJohn Marino string_trim_trailing_whitespace(tag);
165*86d7f5d3SJohn Marino
166*86d7f5d3SJohn Marino qualifier = strsep(&entry, ":");
167*86d7f5d3SJohn Marino if (!qualifier) {
168*86d7f5d3SJohn Marino /* printf("no qualifier\n"); */
169*86d7f5d3SJohn Marino errno = EINVAL;
170*86d7f5d3SJohn Marino goto error_label;
171*86d7f5d3SJohn Marino }
172*86d7f5d3SJohn Marino qualifier = string_skip_whitespace(qualifier);
173*86d7f5d3SJohn Marino string_trim_trailing_whitespace(qualifier);
174*86d7f5d3SJohn Marino
175*86d7f5d3SJohn Marino permission = strsep(&entry, ":");
176*86d7f5d3SJohn Marino if ((!permission) || (entry)) {
177*86d7f5d3SJohn Marino /* printf("no permission, or more stuff\n"); */
178*86d7f5d3SJohn Marino errno = EINVAL;
179*86d7f5d3SJohn Marino goto error_label;
180*86d7f5d3SJohn Marino }
181*86d7f5d3SJohn Marino permission = string_skip_whitespace(permission);
182*86d7f5d3SJohn Marino string_trim_trailing_whitespace(permission);
183*86d7f5d3SJohn Marino
184*86d7f5d3SJohn Marino /* printf("[%s/%s/%s]\n", tag, qualifier,
185*86d7f5d3SJohn Marino permission); */
186*86d7f5d3SJohn Marino
187*86d7f5d3SJohn Marino t = acl_string_to_tag(tag, qualifier);
188*86d7f5d3SJohn Marino if (t == -1) {
189*86d7f5d3SJohn Marino errno = EINVAL;
190*86d7f5d3SJohn Marino goto error_label;
191*86d7f5d3SJohn Marino }
192*86d7f5d3SJohn Marino
193*86d7f5d3SJohn Marino error = acl_string_to_perm(permission, &p);
194*86d7f5d3SJohn Marino if (error == -1) {
195*86d7f5d3SJohn Marino errno = EINVAL;
196*86d7f5d3SJohn Marino goto error_label;
197*86d7f5d3SJohn Marino }
198*86d7f5d3SJohn Marino
199*86d7f5d3SJohn Marino switch(t) {
200*86d7f5d3SJohn Marino case ACL_USER_OBJ:
201*86d7f5d3SJohn Marino case ACL_GROUP_OBJ:
202*86d7f5d3SJohn Marino case ACL_MASK:
203*86d7f5d3SJohn Marino case ACL_OTHER:
204*86d7f5d3SJohn Marino if (*qualifier != '\0') {
205*86d7f5d3SJohn Marino errno = EINVAL;
206*86d7f5d3SJohn Marino goto error_label;
207*86d7f5d3SJohn Marino }
208*86d7f5d3SJohn Marino id = 0;
209*86d7f5d3SJohn Marino break;
210*86d7f5d3SJohn Marino
211*86d7f5d3SJohn Marino case ACL_USER:
212*86d7f5d3SJohn Marino case ACL_GROUP:
213*86d7f5d3SJohn Marino error = acl_name_to_id(t, qualifier, &id);
214*86d7f5d3SJohn Marino if (error == -1)
215*86d7f5d3SJohn Marino goto error_label;
216*86d7f5d3SJohn Marino break;
217*86d7f5d3SJohn Marino
218*86d7f5d3SJohn Marino default:
219*86d7f5d3SJohn Marino errno = EINVAL;
220*86d7f5d3SJohn Marino goto error_label;
221*86d7f5d3SJohn Marino }
222*86d7f5d3SJohn Marino
223*86d7f5d3SJohn Marino error = acl_add_entry(acl, t, id, p);
224*86d7f5d3SJohn Marino if (error == -1)
225*86d7f5d3SJohn Marino goto error_label;
226*86d7f5d3SJohn Marino }
227*86d7f5d3SJohn Marino }
228*86d7f5d3SJohn Marino
229*86d7f5d3SJohn Marino #if 0
230*86d7f5d3SJohn Marino /* XXX should we only return ACLs valid according to acl_valid? */
231*86d7f5d3SJohn Marino /* verify validity of the ACL we read in */
232*86d7f5d3SJohn Marino if (acl_valid(acl) == -1) {
233*86d7f5d3SJohn Marino errno = EINVAL;
234*86d7f5d3SJohn Marino goto error_label;
235*86d7f5d3SJohn Marino }
236*86d7f5d3SJohn Marino #endif
237*86d7f5d3SJohn Marino
238*86d7f5d3SJohn Marino return(acl);
239*86d7f5d3SJohn Marino
240*86d7f5d3SJohn Marino error_label:
241*86d7f5d3SJohn Marino acl_free(acl);
242*86d7f5d3SJohn Marino free(mybuf_p);
243*86d7f5d3SJohn Marino return(0);
244*86d7f5d3SJohn Marino }
245*86d7f5d3SJohn Marino
246*86d7f5d3SJohn Marino
247*86d7f5d3SJohn Marino
248