1/* $OpenBSD: getgrouplist.c,v 1.30 2022/08/02 17:00:15 deraadt Exp $ */ 2/* 3 * Copyright (c) 2008 Ingo Schwarze <schwarze@usta.de> 4 * Copyright (c) 1991, 1993 5 * The Regents of the University of California. All rights reserved. 6 * 7 * Redistribution and use in source and binary forms, with or without 8 * modification, are permitted provided that the following conditions 9 * are met: 10 * 1. Redistributions of source code must retain the above copyright 11 * notice, this list of conditions and the following disclaimer. 12 * 2. Redistributions in binary form must reproduce the above copyright 13 * notice, this list of conditions and the following disclaimer in the 14 * documentation and/or other materials provided with the distribution. 15 * 3. Neither the name of the University nor the names of its contributors 16 * may be used to endorse or promote products derived from this software 17 * without specific prior written permission. 18 * 19 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 20 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 21 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 22 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 23 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 24 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 25 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 26 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 27 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 28 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 29 * SUCH DAMAGE. 30 */ 31 32/* 33 * get credential 34 */ 35#include <sys/types.h> 36#include <sys/limits.h> 37#include <string.h> 38#include <unistd.h> 39#include <stdio.h> 40#include <stdlib.h> 41#include <grp.h> 42#include <pwd.h> 43#include <errno.h> 44 45#include <rpc/rpc.h> 46#include <rpcsvc/yp.h> 47#include <rpcsvc/ypclnt.h> 48 49#ifdef YP 50#define _PATH_NETID "/etc/netid" 51#define MAXLINELENGTH 1024 52 53static int _parse_netid(char*, uid_t, gid_t*, int*, int); 54static int _read_netid(const char *, uid_t, gid_t*, int*, int); 55 56/* 57 * Parse one string of the form "uid:gid[,gid[,...]]". 58 * If the uid matches, add the groups to the group list. 59 * If the groups fit, return 1, otherwise return -1. 60 * If the uid does not match, return 0. 61 */ 62static int 63_parse_netid(char *netid, uid_t uid, gid_t *groups, int *ngroups, 64 int maxgroups) 65{ 66 const char *errstr = NULL; 67 char *start, *p; 68 uid_t tuid; 69 gid_t gid; 70 int i; 71 72 /* Check the uid. */ 73 p = strchr(netid, ':'); 74 if (!p) 75 return (0); 76 *p++ = '\0'; 77 tuid = (uid_t)strtonum(netid, 0, UID_MAX, &errstr); 78 if (errstr || tuid != uid) 79 return (0); 80 81 /* Loop over the gids. */ 82 while (p && *p) { 83 start = p; 84 p = strchr(start, ','); 85 if (p) 86 *p++ = '\0'; 87 gid = (gid_t)strtonum(start, 0, GID_MAX, &errstr); 88 if (errstr) 89 continue; 90 91 /* Skip this group if it is already in the list. */ 92 for (i = 0; i < *ngroups; i++) 93 if (groups[i] == gid) 94 break; 95 96 /* Try to add this new group to the list. */ 97 if (i == *ngroups) { 98 if (*ngroups >= maxgroups) 99 return (-1); 100 groups[(*ngroups)++] = gid; 101 } 102 } 103 return (1); 104} 105 106/* 107 * Search /etc/netid for a particular uid and process that line. 108 * See _parse_netid for details, including return values. 109 */ 110static int 111_read_netid(const char *key, uid_t uid, gid_t *groups, int *ngroups, 112 int maxgroups) 113{ 114 FILE *fp; 115 char line[MAXLINELENGTH], *p; 116 int found = 0; 117 118 fp = fopen(_PATH_NETID, "re"); 119 if (!fp) 120 return (0); 121 while (!found && fgets(line, sizeof(line), fp)) { 122 p = strchr(line, '\n'); 123 if (p) 124 *p = '\0'; 125 else { /* Skip lines that are too long. */ 126 int ch; 127 while ((ch = getc_unlocked(fp)) != '\n' && ch != EOF) 128 ; 129 continue; 130 } 131 p = strchr(line, ' '); 132 if (!p) 133 continue; 134 *p++ = '\0'; 135 if (strcmp(line, key)) 136 continue; 137 found = _parse_netid(p, uid, groups, ngroups, maxgroups); 138 } 139 (void)fclose(fp); 140 return (found); 141} 142#endif /* YP */ 143 144int 145getgrouplist(const char *uname, gid_t agroup, gid_t *groups, int *grpcnt) 146{ 147 int i, ngroups = 0, ret = 0, maxgroups = *grpcnt, bail; 148 int needyp = 0, foundyp = 0; 149 int *skipyp = &foundyp; 150 extern struct group *_getgrent_yp(int *); 151 struct group *grp; 152 153 /* 154 * install primary group 155 */ 156 if (ngroups >= maxgroups) { 157 *grpcnt = ngroups; 158 return (-1); 159 } 160 groups[ngroups++] = agroup; 161 162 /* 163 * Scan the group file to find additional groups. 164 */ 165 setgrent(); 166 while ((grp = _getgrent_yp(skipyp)) || foundyp) { 167 if (foundyp) { 168 if (foundyp > 0) 169 needyp = 1; 170 else 171 skipyp = NULL; 172 foundyp = 0; 173 continue; 174 } 175 if (grp->gr_gid == agroup) 176 continue; 177 for (bail = 0, i = 0; bail == 0 && i < ngroups; i++) 178 if (groups[i] == grp->gr_gid) 179 bail = 1; 180 if (bail) 181 continue; 182 for (i = 0; grp->gr_mem[i]; i++) { 183 if (!strcmp(grp->gr_mem[i], uname)) { 184 if (ngroups >= maxgroups) { 185 ret = -1; 186 goto out; 187 } 188 groups[ngroups++] = grp->gr_gid; 189 break; 190 } 191 } 192 } 193 194#ifdef YP 195 /* 196 * If we were told that there is a YP marker, look at netid data. 197 */ 198 if (skipyp && needyp) { 199 char buf[MAXLINELENGTH], *ypdata = NULL, *key; 200 static char *__ypdomain; 201 struct passwd pwstore; 202 int ypdatalen; 203 204 /* Construct the netid key to look up. */ 205 if (getpwnam_r(uname, &pwstore, buf, sizeof buf, NULL) || 206 (!__ypdomain && yp_get_default_domain(&__ypdomain))) 207 goto out; 208 i = asprintf(&key, "unix.%u@%s", pwstore.pw_uid, __ypdomain); 209 if (i == -1) 210 goto out; 211 212 /* First scan the static netid file. */ 213 switch (_read_netid(key, pwstore.pw_uid, 214 groups, &ngroups, maxgroups)) { 215 case -1: 216 ret = -1; 217 /* FALLTHROUGH */ 218 case 1: 219 free(key); 220 goto out; 221 default: 222 break; 223 } 224 225 /* Only access YP when there is no static entry. */ 226 if (!yp_match(__ypdomain, "netid.byname", key, 227 (int)strlen(key), &ypdata, &ypdatalen)) 228 if (_parse_netid(ypdata, pwstore.pw_uid, 229 groups, &ngroups, maxgroups) == -1) 230 ret = -1; 231 232 free(key); 233 free(ypdata); 234 } 235#endif /* YP */ 236 237out: 238 endgrent(); 239 *grpcnt = ngroups; 240 return (ret); 241} 242DEF_WEAK(getgrouplist); 243