1*b0d29bc4SBrooks Davis // Copyright 2010 The Kyua Authors.
2*b0d29bc4SBrooks Davis // All rights reserved.
3*b0d29bc4SBrooks Davis //
4*b0d29bc4SBrooks Davis // Redistribution and use in source and binary forms, with or without
5*b0d29bc4SBrooks Davis // modification, are permitted provided that the following conditions are
6*b0d29bc4SBrooks Davis // met:
7*b0d29bc4SBrooks Davis //
8*b0d29bc4SBrooks Davis // * Redistributions of source code must retain the above copyright
9*b0d29bc4SBrooks Davis // notice, this list of conditions and the following disclaimer.
10*b0d29bc4SBrooks Davis // * Redistributions in binary form must reproduce the above copyright
11*b0d29bc4SBrooks Davis // notice, this list of conditions and the following disclaimer in the
12*b0d29bc4SBrooks Davis // documentation and/or other materials provided with the distribution.
13*b0d29bc4SBrooks Davis // * Neither the name of Google Inc. nor the names of its contributors
14*b0d29bc4SBrooks Davis // may be used to endorse or promote products derived from this software
15*b0d29bc4SBrooks Davis // without specific prior written permission.
16*b0d29bc4SBrooks Davis //
17*b0d29bc4SBrooks Davis // THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
18*b0d29bc4SBrooks Davis // "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
19*b0d29bc4SBrooks Davis // LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
20*b0d29bc4SBrooks Davis // A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
21*b0d29bc4SBrooks Davis // OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
22*b0d29bc4SBrooks Davis // SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
23*b0d29bc4SBrooks Davis // LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
24*b0d29bc4SBrooks Davis // DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
25*b0d29bc4SBrooks Davis // THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
26*b0d29bc4SBrooks Davis // (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
27*b0d29bc4SBrooks Davis // OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
28*b0d29bc4SBrooks Davis
29*b0d29bc4SBrooks Davis #include "utils/passwd.hpp"
30*b0d29bc4SBrooks Davis
31*b0d29bc4SBrooks Davis extern "C" {
32*b0d29bc4SBrooks Davis #include <sys/types.h>
33*b0d29bc4SBrooks Davis
34*b0d29bc4SBrooks Davis #include <pwd.h>
35*b0d29bc4SBrooks Davis #include <unistd.h>
36*b0d29bc4SBrooks Davis }
37*b0d29bc4SBrooks Davis
38*b0d29bc4SBrooks Davis #include <stdexcept>
39*b0d29bc4SBrooks Davis
40*b0d29bc4SBrooks Davis #include "utils/format/macros.hpp"
41*b0d29bc4SBrooks Davis #include "utils/logging/macros.hpp"
42*b0d29bc4SBrooks Davis #include "utils/optional.ipp"
43*b0d29bc4SBrooks Davis #include "utils/sanity.hpp"
44*b0d29bc4SBrooks Davis
45*b0d29bc4SBrooks Davis namespace passwd_ns = utils::passwd;
46*b0d29bc4SBrooks Davis
47*b0d29bc4SBrooks Davis
48*b0d29bc4SBrooks Davis namespace {
49*b0d29bc4SBrooks Davis
50*b0d29bc4SBrooks Davis
51*b0d29bc4SBrooks Davis /// If defined, replaces the value returned by current_user().
52*b0d29bc4SBrooks Davis static utils::optional< passwd_ns::user > fake_current_user;
53*b0d29bc4SBrooks Davis
54*b0d29bc4SBrooks Davis
55*b0d29bc4SBrooks Davis /// If not empty, defines the current set of mock users.
56*b0d29bc4SBrooks Davis static std::vector< passwd_ns::user > mock_users;
57*b0d29bc4SBrooks Davis
58*b0d29bc4SBrooks Davis
59*b0d29bc4SBrooks Davis /// Formats a user for logging purposes.
60*b0d29bc4SBrooks Davis ///
61*b0d29bc4SBrooks Davis /// \param user The user to format.
62*b0d29bc4SBrooks Davis ///
63*b0d29bc4SBrooks Davis /// \return The user as a string.
64*b0d29bc4SBrooks Davis static std::string
format_user(const passwd_ns::user & user)65*b0d29bc4SBrooks Davis format_user(const passwd_ns::user& user)
66*b0d29bc4SBrooks Davis {
67*b0d29bc4SBrooks Davis return F("name=%s, uid=%s, gid=%s") % user.name % user.uid % user.gid;
68*b0d29bc4SBrooks Davis }
69*b0d29bc4SBrooks Davis
70*b0d29bc4SBrooks Davis
71*b0d29bc4SBrooks Davis } // anonymous namespace
72*b0d29bc4SBrooks Davis
73*b0d29bc4SBrooks Davis
74*b0d29bc4SBrooks Davis /// Constructs a new user.
75*b0d29bc4SBrooks Davis ///
76*b0d29bc4SBrooks Davis /// \param name_ The name of the user.
77*b0d29bc4SBrooks Davis /// \param uid_ The user identifier.
78*b0d29bc4SBrooks Davis /// \param gid_ The login group identifier.
user(const std::string & name_,const unsigned int uid_,const unsigned int gid_)79*b0d29bc4SBrooks Davis passwd_ns::user::user(const std::string& name_, const unsigned int uid_,
80*b0d29bc4SBrooks Davis const unsigned int gid_) :
81*b0d29bc4SBrooks Davis name(name_),
82*b0d29bc4SBrooks Davis uid(uid_),
83*b0d29bc4SBrooks Davis gid(gid_)
84*b0d29bc4SBrooks Davis {
85*b0d29bc4SBrooks Davis }
86*b0d29bc4SBrooks Davis
87*b0d29bc4SBrooks Davis
88*b0d29bc4SBrooks Davis /// Checks if the user has superpowers or not.
89*b0d29bc4SBrooks Davis ///
90*b0d29bc4SBrooks Davis /// \return True if the user is root, false otherwise.
91*b0d29bc4SBrooks Davis bool
is_root(void) const92*b0d29bc4SBrooks Davis passwd_ns::user::is_root(void) const
93*b0d29bc4SBrooks Davis {
94*b0d29bc4SBrooks Davis return uid == 0;
95*b0d29bc4SBrooks Davis }
96*b0d29bc4SBrooks Davis
97*b0d29bc4SBrooks Davis
98*b0d29bc4SBrooks Davis /// Gets the current user.
99*b0d29bc4SBrooks Davis ///
100*b0d29bc4SBrooks Davis /// \return The current user.
101*b0d29bc4SBrooks Davis passwd_ns::user
current_user(void)102*b0d29bc4SBrooks Davis passwd_ns::current_user(void)
103*b0d29bc4SBrooks Davis {
104*b0d29bc4SBrooks Davis if (fake_current_user) {
105*b0d29bc4SBrooks Davis const user u = fake_current_user.get();
106*b0d29bc4SBrooks Davis LD(F("Current user is fake: %s") % format_user(u));
107*b0d29bc4SBrooks Davis return u;
108*b0d29bc4SBrooks Davis } else {
109*b0d29bc4SBrooks Davis const user u = find_user_by_uid(::getuid());
110*b0d29bc4SBrooks Davis LD(F("Current user is: %s") % format_user(u));
111*b0d29bc4SBrooks Davis return u;
112*b0d29bc4SBrooks Davis }
113*b0d29bc4SBrooks Davis }
114*b0d29bc4SBrooks Davis
115*b0d29bc4SBrooks Davis
116*b0d29bc4SBrooks Davis /// Gets information about a user by its name.
117*b0d29bc4SBrooks Davis ///
118*b0d29bc4SBrooks Davis /// \param name The name of the user to query.
119*b0d29bc4SBrooks Davis ///
120*b0d29bc4SBrooks Davis /// \return The information about the user.
121*b0d29bc4SBrooks Davis ///
122*b0d29bc4SBrooks Davis /// \throw std::runtime_error If the user does not exist.
123*b0d29bc4SBrooks Davis passwd_ns::user
find_user_by_name(const std::string & name)124*b0d29bc4SBrooks Davis passwd_ns::find_user_by_name(const std::string& name)
125*b0d29bc4SBrooks Davis {
126*b0d29bc4SBrooks Davis if (mock_users.empty()) {
127*b0d29bc4SBrooks Davis const struct ::passwd* pw = ::getpwnam(name.c_str());
128*b0d29bc4SBrooks Davis if (pw == NULL)
129*b0d29bc4SBrooks Davis throw std::runtime_error(F("Failed to get information about the "
130*b0d29bc4SBrooks Davis "user '%s'") % name);
131*b0d29bc4SBrooks Davis INV(pw->pw_name == name);
132*b0d29bc4SBrooks Davis return user(pw->pw_name, pw->pw_uid, pw->pw_gid);
133*b0d29bc4SBrooks Davis } else {
134*b0d29bc4SBrooks Davis for (std::vector< user >::const_iterator iter = mock_users.begin();
135*b0d29bc4SBrooks Davis iter != mock_users.end(); iter++) {
136*b0d29bc4SBrooks Davis if ((*iter).name == name)
137*b0d29bc4SBrooks Davis return *iter;
138*b0d29bc4SBrooks Davis }
139*b0d29bc4SBrooks Davis throw std::runtime_error(F("Failed to get information about the "
140*b0d29bc4SBrooks Davis "user '%s'") % name);
141*b0d29bc4SBrooks Davis }
142*b0d29bc4SBrooks Davis }
143*b0d29bc4SBrooks Davis
144*b0d29bc4SBrooks Davis
145*b0d29bc4SBrooks Davis /// Gets information about a user by its identifier.
146*b0d29bc4SBrooks Davis ///
147*b0d29bc4SBrooks Davis /// \param uid The identifier of the user to query.
148*b0d29bc4SBrooks Davis ///
149*b0d29bc4SBrooks Davis /// \return The information about the user.
150*b0d29bc4SBrooks Davis ///
151*b0d29bc4SBrooks Davis /// \throw std::runtime_error If the user does not exist.
152*b0d29bc4SBrooks Davis passwd_ns::user
find_user_by_uid(const unsigned int uid)153*b0d29bc4SBrooks Davis passwd_ns::find_user_by_uid(const unsigned int uid)
154*b0d29bc4SBrooks Davis {
155*b0d29bc4SBrooks Davis if (mock_users.empty()) {
156*b0d29bc4SBrooks Davis const struct ::passwd* pw = ::getpwuid(uid);
157*b0d29bc4SBrooks Davis if (pw == NULL)
158*b0d29bc4SBrooks Davis throw std::runtime_error(F("Failed to get information about the "
159*b0d29bc4SBrooks Davis "user with UID %s") % uid);
160*b0d29bc4SBrooks Davis INV(pw->pw_uid == uid);
161*b0d29bc4SBrooks Davis return user(pw->pw_name, pw->pw_uid, pw->pw_gid);
162*b0d29bc4SBrooks Davis } else {
163*b0d29bc4SBrooks Davis for (std::vector< user >::const_iterator iter = mock_users.begin();
164*b0d29bc4SBrooks Davis iter != mock_users.end(); iter++) {
165*b0d29bc4SBrooks Davis if ((*iter).uid == uid)
166*b0d29bc4SBrooks Davis return *iter;
167*b0d29bc4SBrooks Davis }
168*b0d29bc4SBrooks Davis throw std::runtime_error(F("Failed to get information about the "
169*b0d29bc4SBrooks Davis "user with UID %s") % uid);
170*b0d29bc4SBrooks Davis }
171*b0d29bc4SBrooks Davis }
172*b0d29bc4SBrooks Davis
173*b0d29bc4SBrooks Davis
174*b0d29bc4SBrooks Davis /// Overrides the current user for testing purposes.
175*b0d29bc4SBrooks Davis ///
176*b0d29bc4SBrooks Davis /// This DOES NOT change the current privileges!
177*b0d29bc4SBrooks Davis ///
178*b0d29bc4SBrooks Davis /// \param new_current_user The new current user.
179*b0d29bc4SBrooks Davis void
set_current_user_for_testing(const user & new_current_user)180*b0d29bc4SBrooks Davis passwd_ns::set_current_user_for_testing(const user& new_current_user)
181*b0d29bc4SBrooks Davis {
182*b0d29bc4SBrooks Davis fake_current_user = new_current_user;
183*b0d29bc4SBrooks Davis }
184*b0d29bc4SBrooks Davis
185*b0d29bc4SBrooks Davis
186*b0d29bc4SBrooks Davis /// Overrides the current set of users for testing purposes.
187*b0d29bc4SBrooks Davis ///
188*b0d29bc4SBrooks Davis /// \param users The new users set. Cannot be empty.
189*b0d29bc4SBrooks Davis void
set_mock_users_for_testing(const std::vector<user> & users)190*b0d29bc4SBrooks Davis passwd_ns::set_mock_users_for_testing(const std::vector< user >& users)
191*b0d29bc4SBrooks Davis {
192*b0d29bc4SBrooks Davis PRE(!users.empty());
193*b0d29bc4SBrooks Davis mock_users = users;
194*b0d29bc4SBrooks Davis }
195