xref: /openbsd-src/lib/libc/gen/getgrouplist.c (revision a28daedfc357b214be5c701aa8ba8adb29a7f1c2)
1 /*	$OpenBSD: getgrouplist.c,v 1.16 2009/03/27 12:31:31 schwarze Exp $ */
2 /*
3  * Copyright (c) 2008 Ingo Schwarze <schwarze@usta.de>
4  * Copyright (c) 1991, 1993
5  *	The Regents of the University of California.  All rights reserved.
6  *
7  * Redistribution and use in source and binary forms, with or without
8  * modification, are permitted provided that the following conditions
9  * are met:
10  * 1. Redistributions of source code must retain the above copyright
11  *    notice, this list of conditions and the following disclaimer.
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in the
14  *    documentation and/or other materials provided with the distribution.
15  * 3. Neither the name of the University nor the names of its contributors
16  *    may be used to endorse or promote products derived from this software
17  *    without specific prior written permission.
18  *
19  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
20  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
21  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
22  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
23  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
24  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
25  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
26  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
27  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
28  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29  * SUCH DAMAGE.
30  */
31 
32 /*
33  * get credential
34  */
35 #include <sys/types.h>
36 #include <sys/limits.h>
37 #include <string.h>
38 #include <unistd.h>
39 #include <stdio.h>
40 #include <stdlib.h>
41 #include <grp.h>
42 #include <pwd.h>
43 
44 #include <rpc/rpc.h>
45 #include <rpcsvc/yp.h>
46 #include <rpcsvc/ypclnt.h>
47 
48 #ifdef YP
49 #define _PATH_NETID	"/etc/netid"
50 #define MAXLINELENGTH	1024
51 
52 static int _parse_netid(char*, uid_t, gid_t*, int*, int);
53 static int _read_netid(const char *, uid_t, gid_t*, int*, int);
54 
55 /*
56  * Parse one string of the form "uid:gid[,gid[,...]]".
57  * If the uid matches, add the groups to the group list.
58  * If the groups fit, return 1, otherwise return -1.
59  * If the uid does not match, return 0.
60  */
61 static int
62 _parse_netid(char *netid, uid_t uid, gid_t *groups, int *ngroups,
63 	     int maxgroups)
64 {
65 	const char *errstr = NULL;
66 	char *start, *p;
67 	uid_t tuid;
68 	gid_t gid;
69 	int i;
70 
71 	/* Check the uid. */
72 	p = strchr(netid, ':');
73 	if (!p)
74 		return (0);
75 	*p++ = '\0';
76 	tuid = (uid_t)strtonum(netid, 0, UID_MAX, &errstr);
77 	if (errstr || tuid != uid)
78 		return (0);
79 
80         /* Loop over the gids. */
81 	while (p && *p) {
82 		start = p;
83 		p = strchr(start, ',');
84 		if (p)
85 			*p++ = '\0';
86 		gid = (gid_t)strtonum(start, 0, GID_MAX, &errstr);
87 		if (errstr)
88 			continue;
89 
90 		/* Skip this group if it is already in the list. */
91 		for (i = 0; i < *ngroups; i++)
92 			if (groups[i] == gid)
93 				break;
94 
95 		/* Try to add this new group to the list. */
96 		if (i == *ngroups) {
97 			if (*ngroups >= maxgroups)
98 				return (-1);
99 			groups[(*ngroups)++] = gid;
100 		}
101 	}
102 	return (1);
103 }
104 
105 /*
106  * Search /etc/netid for a particular uid and process that line.
107  * See _parse_netid for details, including return values.
108  */
109 static int
110 _read_netid(const char *key, uid_t uid, gid_t *groups, int *ngroups,
111 	    int maxgroups)
112 {
113 	FILE *fp;
114 	char line[MAXLINELENGTH], *p;
115 	int found = 0;
116 
117 	fp = fopen(_PATH_NETID, "r");
118 	if (!fp)
119 		return (0);
120 	while (!found && fgets(line, sizeof(line), fp)) {
121 		p = strchr(line, '\n');
122 		if (p)
123 			*p = '\0';
124 		else { /* Skip lines that are too long. */
125 			int ch;
126 			while ((ch = getc(fp)) != '\n' && ch != EOF)
127 				;
128 			continue;
129 		}
130 		p = strchr(line, ' ');
131 		if (!p)
132 			continue;
133 		*p++ = '\0';
134 		if (strcmp(line, key))
135 			continue;
136 		found = _parse_netid(p, uid, groups, ngroups, maxgroups);
137 	}
138 	(void)fclose(fp);
139 	return (found);
140 }
141 #endif /* YP */
142 
143 int
144 getgrouplist(const char *uname, gid_t agroup, gid_t *groups, int *grpcnt)
145 {
146 	int i, ngroups = 0, ret = 0, maxgroups = *grpcnt, bail;
147 	int needyp = 0, foundyp = 0;
148 	extern struct group *_getgrent_yp(int *);
149 	struct group *grp;
150 
151 	/*
152 	 * install primary group
153 	 */
154 	if (ngroups >= maxgroups) {
155 		*grpcnt = ngroups;
156 		return (-1);
157 	}
158 	groups[ngroups++] = agroup;
159 
160 	/*
161 	 * Scan the group file to find additional groups.
162 	 */
163 	setgrent();
164 	while ((grp = _getgrent_yp(&foundyp)) || foundyp) {
165 		if (foundyp) {
166 			needyp = 1;
167 			foundyp = 0;
168 			continue;
169 		}
170 		if (grp->gr_gid == agroup)
171 			continue;
172 		for (bail = 0, i = 0; bail == 0 && i < ngroups; i++)
173 			if (groups[i] == grp->gr_gid)
174 				bail = 1;
175 		if (bail)
176 			continue;
177 		for (i = 0; grp->gr_mem[i]; i++) {
178 			if (!strcmp(grp->gr_mem[i], uname)) {
179 				if (ngroups >= maxgroups) {
180 					ret = -1;
181 					goto out;
182 				}
183 				groups[ngroups++] = grp->gr_gid;
184 				break;
185 			}
186 		}
187 	}
188 
189 #ifdef YP
190 	/*
191 	 * If we were told that there is a YP marker, look at netid data.
192 	 */
193 	if (needyp) {
194 		char buf[MAXLINELENGTH], *ypdata = NULL, *key;
195 		static char *__ypdomain;
196 		struct passwd pwstore;
197 		int ypdatalen;
198 
199 		/* Construct the netid key to look up. */
200 		if (getpwnam_r(uname, &pwstore, buf, sizeof buf, NULL) ||
201 		    !__ypdomain && yp_get_default_domain(&__ypdomain))
202 			goto out;
203 		asprintf(&key, "unix.%u@%s", pwstore.pw_uid, __ypdomain);
204 		if (key == NULL)
205 			goto out;
206 
207 		/* First scan the static netid file. */
208 		if (ret = _read_netid(key, pwstore.pw_uid,
209 				      groups, &ngroups, maxgroups))
210 			goto out;
211 
212 		/* Only access YP when there is no static entry. */
213 		if (!yp_bind(__ypdomain) &&
214 		    !yp_match(__ypdomain, "netid.byname", key,
215 			     (int)strlen(key), &ypdata, &ypdatalen))
216 			ret = _parse_netid(ypdata, pwstore.pw_uid,
217 			    		   groups, &ngroups, maxgroups);
218 
219 		free(key);
220 		free(ypdata);
221 	}
222 #endif /* YP */
223 
224 out:
225 	endgrent();
226 	*grpcnt = ngroups;
227 	return (ret);
228 }
229