1*0Sstevel@tonic-gate /* 2*0Sstevel@tonic-gate * Copyright (c) 2001 Kevin Steves. All rights reserved. 3*0Sstevel@tonic-gate * 4*0Sstevel@tonic-gate * Redistribution and use in source and binary forms, with or without 5*0Sstevel@tonic-gate * modification, are permitted provided that the following conditions 6*0Sstevel@tonic-gate * are met: 7*0Sstevel@tonic-gate * 1. Redistributions of source code must retain the above copyright 8*0Sstevel@tonic-gate * notice, this list of conditions and the following disclaimer. 9*0Sstevel@tonic-gate * 2. Redistributions in binary form must reproduce the above copyright 10*0Sstevel@tonic-gate * notice, this list of conditions and the following disclaimer in the 11*0Sstevel@tonic-gate * documentation and/or other materials provided with the distribution. 12*0Sstevel@tonic-gate * 13*0Sstevel@tonic-gate * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR 14*0Sstevel@tonic-gate * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES 15*0Sstevel@tonic-gate * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. 16*0Sstevel@tonic-gate * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, 17*0Sstevel@tonic-gate * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 18*0Sstevel@tonic-gate * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, 19*0Sstevel@tonic-gate * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY 20*0Sstevel@tonic-gate * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT 21*0Sstevel@tonic-gate * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF 22*0Sstevel@tonic-gate * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. 23*0Sstevel@tonic-gate */ 24*0Sstevel@tonic-gate 25*0Sstevel@tonic-gate #include "includes.h" 26*0Sstevel@tonic-gate RCSID("$OpenBSD: groupaccess.c,v 1.5 2002/03/04 17:27:39 stevesk Exp $"); 27*0Sstevel@tonic-gate 28*0Sstevel@tonic-gate #pragma ident "%Z%%M% %I% %E% SMI" 29*0Sstevel@tonic-gate 30*0Sstevel@tonic-gate #include "groupaccess.h" 31*0Sstevel@tonic-gate #include "xmalloc.h" 32*0Sstevel@tonic-gate #include "match.h" 33*0Sstevel@tonic-gate #include "log.h" 34*0Sstevel@tonic-gate 35*0Sstevel@tonic-gate static int ngroups; 36*0Sstevel@tonic-gate static char *groups_byname[NGROUPS_MAX + 1]; /* +1 for base/primary group */ 37*0Sstevel@tonic-gate 38*0Sstevel@tonic-gate /* 39*0Sstevel@tonic-gate * Initialize group access list for user with primary (base) and 40*0Sstevel@tonic-gate * supplementary groups. Return the number of groups in the list. 41*0Sstevel@tonic-gate */ 42*0Sstevel@tonic-gate int 43*0Sstevel@tonic-gate ga_init(const char *user, gid_t base) 44*0Sstevel@tonic-gate { 45*0Sstevel@tonic-gate gid_t groups_bygid[NGROUPS_MAX + 1]; 46*0Sstevel@tonic-gate int i, j; 47*0Sstevel@tonic-gate struct group *gr; 48*0Sstevel@tonic-gate 49*0Sstevel@tonic-gate if (ngroups > 0) 50*0Sstevel@tonic-gate ga_free(); 51*0Sstevel@tonic-gate 52*0Sstevel@tonic-gate ngroups = sizeof(groups_bygid) / sizeof(gid_t); 53*0Sstevel@tonic-gate if (getgrouplist(user, base, groups_bygid, &ngroups) == -1) 54*0Sstevel@tonic-gate log("getgrouplist: groups list too small"); 55*0Sstevel@tonic-gate for (i = 0, j = 0; i < ngroups; i++) 56*0Sstevel@tonic-gate if ((gr = getgrgid(groups_bygid[i])) != NULL) 57*0Sstevel@tonic-gate groups_byname[j++] = xstrdup(gr->gr_name); 58*0Sstevel@tonic-gate return (ngroups = j); 59*0Sstevel@tonic-gate } 60*0Sstevel@tonic-gate 61*0Sstevel@tonic-gate /* 62*0Sstevel@tonic-gate * Return 1 if one of user's groups is contained in groups. 63*0Sstevel@tonic-gate * Return 0 otherwise. Use match_pattern() for string comparison. 64*0Sstevel@tonic-gate */ 65*0Sstevel@tonic-gate int 66*0Sstevel@tonic-gate ga_match(char * const *groups, int n) 67*0Sstevel@tonic-gate { 68*0Sstevel@tonic-gate int i, j; 69*0Sstevel@tonic-gate 70*0Sstevel@tonic-gate for (i = 0; i < ngroups; i++) 71*0Sstevel@tonic-gate for (j = 0; j < n; j++) 72*0Sstevel@tonic-gate if (match_pattern(groups_byname[i], groups[j])) 73*0Sstevel@tonic-gate return 1; 74*0Sstevel@tonic-gate return 0; 75*0Sstevel@tonic-gate } 76*0Sstevel@tonic-gate 77*0Sstevel@tonic-gate /* 78*0Sstevel@tonic-gate * Free memory allocated for group access list. 79*0Sstevel@tonic-gate */ 80*0Sstevel@tonic-gate void 81*0Sstevel@tonic-gate ga_free(void) 82*0Sstevel@tonic-gate { 83*0Sstevel@tonic-gate int i; 84*0Sstevel@tonic-gate 85*0Sstevel@tonic-gate if (ngroups > 0) { 86*0Sstevel@tonic-gate for (i = 0; i < ngroups; i++) 87*0Sstevel@tonic-gate xfree(groups_byname[i]); 88*0Sstevel@tonic-gate ngroups = 0; 89*0Sstevel@tonic-gate } 90*0Sstevel@tonic-gate } 91