hjl / source-git / glibc

Forked from source-git/glibc 3 years ago
Clone

Blame nis/nss_nis/nis-initgroups.c

Packit 6c4009
/* Copyright (C) 1998-2018 Free Software Foundation, Inc.
Packit 6c4009
   This file is part of the GNU C Library.
Packit 6c4009
   Contributed by Thorsten Kukuk <kukuk@suse.de>, 1998.
Packit 6c4009
Packit 6c4009
   The GNU C Library is free software; you can redistribute it and/or
Packit 6c4009
   modify it under the terms of the GNU Lesser General Public
Packit 6c4009
   License as published by the Free Software Foundation; either
Packit 6c4009
   version 2.1 of the License, or (at your option) any later version.
Packit 6c4009
Packit 6c4009
   The GNU C Library is distributed in the hope that it will be useful,
Packit 6c4009
   but WITHOUT ANY WARRANTY; without even the implied warranty of
Packit 6c4009
   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
Packit 6c4009
   Lesser General Public License for more details.
Packit 6c4009
Packit 6c4009
   You should have received a copy of the GNU Lesser General Public
Packit 6c4009
   License along with the GNU C Library; if not, see
Packit 6c4009
   <http://www.gnu.org/licenses/>.  */
Packit 6c4009
Packit 6c4009
#include <ctype.h>
Packit 6c4009
#include <errno.h>
Packit 6c4009
#include <grp.h>
Packit 6c4009
#include <nss.h>
Packit 6c4009
#include <pwd.h>
Packit 6c4009
#include <string.h>
Packit 6c4009
#include <unistd.h>
Packit 6c4009
#include <rpcsvc/yp.h>
Packit 6c4009
#include <rpcsvc/ypclnt.h>
Packit 6c4009
#include <sys/param.h>
Packit 6c4009
#include <scratch_buffer.h>
Packit 6c4009
Packit 6c4009
#include "nss-nis.h"
Packit 6c4009
#include <libnsl.h>
Packit 6c4009
Packit 6c4009
/* Get the declaration of the parser function.  */
Packit 6c4009
#define ENTNAME grent
Packit 6c4009
#define STRUCTURE group
Packit 6c4009
#define EXTERN_PARSER
Packit 6c4009
#include <nss/nss_files/files-parse.c>
Packit 6c4009
Packit 6c4009
Packit 6c4009
static enum nss_status
Packit 6c4009
internal_setgrent (char *domainname, intern_t *intern)
Packit 6c4009
{
Packit 6c4009
  struct ypall_callback ypcb;
Packit 6c4009
  enum nss_status status;
Packit 6c4009
Packit 6c4009
  ypcb.foreach = _nis_saveit;
Packit 6c4009
  ypcb.data = (char *) intern;
Packit 6c4009
  status = yperr2nss (yp_all (domainname, "group.byname", &ypcb));
Packit 6c4009
Packit 6c4009
  /* Mark the last buffer as full.  */
Packit 6c4009
  if (intern->next != NULL)
Packit 6c4009
    intern->next->size = intern->offset;
Packit 6c4009
Packit 6c4009
  intern->next = intern->start;
Packit 6c4009
  intern->offset = 0;
Packit 6c4009
Packit 6c4009
  return status;
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
Packit 6c4009
static enum nss_status
Packit 6c4009
internal_getgrent_r (struct group *grp, char *buffer, size_t buflen,
Packit 6c4009
		     int *errnop, intern_t *intern)
Packit 6c4009
{
Packit 6c4009
  if (intern->start == NULL)
Packit 6c4009
    return NSS_STATUS_NOTFOUND;
Packit 6c4009
Packit 6c4009
  /* Get the next entry until we found a correct one. */
Packit 6c4009
  int parse_res;
Packit 6c4009
  do
Packit 6c4009
    {
Packit 6c4009
      struct response_t *bucket = intern->next;
Packit 6c4009
Packit 6c4009
      if (__glibc_unlikely (intern->offset >= bucket->size))
Packit 6c4009
	{
Packit 6c4009
	  if (bucket->next == NULL)
Packit 6c4009
	    return NSS_STATUS_NOTFOUND;
Packit 6c4009
Packit 6c4009
	  /* We look at all the content in the current bucket.  Go on
Packit 6c4009
	     to the next.  */
Packit 6c4009
	  bucket = intern->next = bucket->next;
Packit 6c4009
	  intern->offset = 0;
Packit 6c4009
	}
Packit 6c4009
Packit 6c4009
      char *p;
Packit 6c4009
      for (p = &bucket->mem[intern->offset]; isspace (*p); ++p)
Packit 6c4009
        ++intern->offset;
Packit 6c4009
Packit 6c4009
      size_t len = strlen (p) + 1;
Packit 6c4009
      if (__glibc_unlikely (len > buflen))
Packit 6c4009
	{
Packit 6c4009
	  *errnop = ERANGE;
Packit 6c4009
	  return NSS_STATUS_TRYAGAIN;
Packit 6c4009
	}
Packit 6c4009
Packit 6c4009
      /* We unfortunately have to copy the data in the user-provided
Packit 6c4009
	 buffer because that buffer might be around for a very long
Packit 6c4009
	 time and the servent structure must remain valid.  If we would
Packit 6c4009
	 rely on the BUCKET memory the next 'setservent' or 'endservent'
Packit 6c4009
	 call would destroy it.
Packit 6c4009
Packit 6c4009
	 The important thing is that it is a single NUL-terminated
Packit 6c4009
	 string.  This is what the parsing routine expects.  */
Packit 6c4009
      p = memcpy (buffer, &bucket->mem[intern->offset], len);
Packit 6c4009
Packit 6c4009
      parse_res = _nss_files_parse_grent (p, grp, (void *) buffer, buflen,
Packit 6c4009
					  errnop);
Packit 6c4009
      if (__glibc_unlikely (parse_res == -1))
Packit 6c4009
        return NSS_STATUS_TRYAGAIN;
Packit 6c4009
Packit 6c4009
      intern->offset += len;
Packit 6c4009
    }
Packit 6c4009
  while (!parse_res);
Packit 6c4009
Packit 6c4009
  return NSS_STATUS_SUCCESS;
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
Packit 6c4009
static int
Packit 6c4009
get_uid (const char *user, uid_t *uidp)
Packit 6c4009
{
Packit 6c4009
  struct scratch_buffer tmpbuf;
Packit 6c4009
  scratch_buffer_init (&tmpbuf);
Packit 6c4009
Packit 6c4009
  while (1)
Packit 6c4009
    {
Packit 6c4009
      struct passwd result;
Packit 6c4009
      struct passwd *resp;
Packit 6c4009
Packit 6c4009
      int r = getpwnam_r (user, &result, tmpbuf.data, tmpbuf.length, &resp);
Packit 6c4009
      if (r == 0 && resp != NULL)
Packit 6c4009
	{
Packit 6c4009
	  *uidp = resp->pw_uid;
Packit 6c4009
	  scratch_buffer_free (&tmpbuf);
Packit 6c4009
	  return 0;
Packit 6c4009
	}
Packit 6c4009
Packit 6c4009
      if (r != ERANGE)
Packit 6c4009
	break;
Packit 6c4009
Packit 6c4009
      if (!scratch_buffer_grow (&tmpbuf))
Packit 6c4009
	return 1;
Packit 6c4009
    }
Packit 6c4009
Packit 6c4009
  scratch_buffer_free (&tmpbuf);
Packit 6c4009
  return 1;
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
Packit 6c4009
static enum nss_status
Packit 6c4009
initgroups_netid (uid_t uid, gid_t group, long int *start, long int *size,
Packit 6c4009
		  gid_t **groupsp, long int limit, int *errnop,
Packit 6c4009
		  const char *domainname)
Packit 6c4009
{
Packit 6c4009
  /* Limit domainname length to the maximum size of an RPC packet.  */
Packit 6c4009
  if (strlen (domainname) > UDPMSGSIZE)
Packit 6c4009
    {
Packit 6c4009
      *errnop = ERANGE;
Packit 6c4009
      return NSS_STATUS_UNAVAIL;
Packit 6c4009
    }
Packit 6c4009
Packit 6c4009
  /* Prepare the key.  The form is "unix.UID@DOMAIN" with the UID and
Packit 6c4009
     DOMAIN field filled in appropriately.  */
Packit 6c4009
  char key[sizeof ("unix.@") + sizeof (uid_t) * 3 + strlen (domainname)];
Packit 6c4009
  ssize_t keylen = snprintf (key, sizeof (key), "unix.%lu@%s",
Packit 6c4009
			     (unsigned long int) uid, domainname);
Packit 6c4009
Packit 6c4009
  char *result;
Packit 6c4009
  int reslen;
Packit 6c4009
  int yperr = yp_match (domainname, "netid.byname", key, keylen, &result,
Packit 6c4009
			&reslen);
Packit 6c4009
  if (__glibc_unlikely (yperr != YPERR_SUCCESS))
Packit 6c4009
    return yperr2nss (yperr);
Packit 6c4009
Packit 6c4009
  /* Parse the result: following the colon is a comma separated list of
Packit 6c4009
     group IDs.  */
Packit 6c4009
  char *cp = strchr (result, ':');
Packit 6c4009
  if (cp == NULL)
Packit 6c4009
    {
Packit 6c4009
    errout:
Packit 6c4009
      free (result);
Packit 6c4009
      return NSS_STATUS_NOTFOUND;
Packit 6c4009
    }
Packit 6c4009
  /* Skip the colon.  */
Packit 6c4009
  ++cp;
Packit 6c4009
Packit 6c4009
  gid_t *groups = *groupsp;
Packit 6c4009
  while (*cp != '\0')
Packit 6c4009
    {
Packit 6c4009
      char *endp;
Packit 6c4009
      unsigned long int gid = strtoul (cp, &endp, 0);
Packit 6c4009
      if (cp == endp)
Packit 6c4009
	goto errout;
Packit 6c4009
      if (*endp == ',')
Packit 6c4009
	++endp;
Packit 6c4009
      else if (*endp != '\0')
Packit 6c4009
	goto errout;
Packit 6c4009
      cp = endp;
Packit 6c4009
Packit 6c4009
      if (gid == group)
Packit 6c4009
	/* We do not need this group again.  */
Packit 6c4009
	continue;
Packit 6c4009
Packit 6c4009
      /* Insert this group.  */
Packit 6c4009
      if (*start == *size)
Packit 6c4009
	{
Packit 6c4009
	  /* Need a bigger buffer.  */
Packit 6c4009
	  long int newsize;
Packit 6c4009
Packit 6c4009
	  if (limit > 0 && *size == limit)
Packit 6c4009
	    /* We reached the maximum.  */
Packit 6c4009
	    break;
Packit 6c4009
Packit 6c4009
	  if (limit <= 0)
Packit 6c4009
	    newsize = 2 * *size;
Packit 6c4009
	  else
Packit 6c4009
	    newsize = MIN (limit, 2 * *size);
Packit 6c4009
Packit 6c4009
	  gid_t *newgroups = realloc (groups, newsize * sizeof (*groups));
Packit 6c4009
	  if (newgroups == NULL)
Packit 6c4009
	    goto errout;
Packit 6c4009
	  *groupsp = groups = newgroups;
Packit 6c4009
	  *size = newsize;
Packit 6c4009
	}
Packit 6c4009
Packit 6c4009
      groups[*start] = gid;
Packit 6c4009
      *start += 1;
Packit 6c4009
    }
Packit 6c4009
Packit 6c4009
  free (result);
Packit 6c4009
Packit 6c4009
  return NSS_STATUS_SUCCESS;
Packit 6c4009
}
Packit 6c4009
Packit 6c4009
Packit 6c4009
enum nss_status
Packit 6c4009
_nss_nis_initgroups_dyn (const char *user, gid_t group, long int *start,
Packit 6c4009
			 long int *size, gid_t **groupsp, long int limit,
Packit 6c4009
			 int *errnop)
Packit 6c4009
{
Packit 6c4009
  /* We always need the domain name.  */
Packit 6c4009
  char *domainname;
Packit 6c4009
  if (yp_get_default_domain (&domainname))
Packit 6c4009
    return NSS_STATUS_UNAVAIL;
Packit 6c4009
Packit 6c4009
  /* Check whether we are supposed to use the netid.byname map.  */
Packit 6c4009
  if (_nsl_default_nss () & NSS_FLAG_NETID_AUTHORITATIVE)
Packit 6c4009
    {
Packit 6c4009
      /* We need the user ID.  */
Packit 6c4009
      uid_t uid;
Packit 6c4009
Packit 6c4009
      if (get_uid (user, &uid) == 0
Packit 6c4009
	  && initgroups_netid (uid, group, start, size, groupsp, limit,
Packit 6c4009
			       errnop, domainname) == NSS_STATUS_SUCCESS)
Packit 6c4009
	return NSS_STATUS_SUCCESS;
Packit 6c4009
    }
Packit 6c4009
Packit 6c4009
  struct group grpbuf, *g;
Packit 6c4009
  enum nss_status status;
Packit 6c4009
  intern_t intern = { NULL, NULL, 0 };
Packit 6c4009
  gid_t *groups = *groupsp;
Packit 6c4009
Packit 6c4009
  status = internal_setgrent (domainname, &intern;;
Packit 6c4009
  if (status != NSS_STATUS_SUCCESS)
Packit 6c4009
    return status;
Packit 6c4009
Packit 6c4009
  struct scratch_buffer tmpbuf;
Packit 6c4009
  scratch_buffer_init (&tmpbuf);
Packit 6c4009
Packit 6c4009
  while (1)
Packit 6c4009
    {
Packit 6c4009
      while ((status =
Packit 6c4009
	      internal_getgrent_r (&grpbuf, tmpbuf.data, tmpbuf.length, errnop,
Packit 6c4009
				   &intern)) == NSS_STATUS_TRYAGAIN
Packit 6c4009
             && *errnop == ERANGE)
Packit 6c4009
	if (!scratch_buffer_grow (&tmpbuf))
Packit 6c4009
	  {
Packit 6c4009
	    status = NSS_STATUS_TRYAGAIN;
Packit 6c4009
	    goto done;
Packit 6c4009
	  }
Packit 6c4009
Packit 6c4009
      if (status != NSS_STATUS_SUCCESS)
Packit 6c4009
	{
Packit 6c4009
	  if (status == NSS_STATUS_NOTFOUND)
Packit 6c4009
	    status = NSS_STATUS_SUCCESS;
Packit 6c4009
	  goto done;
Packit 6c4009
	}
Packit 6c4009
Packit 6c4009
      g = &grpbuf;
Packit 6c4009
      if (g->gr_gid != group)
Packit 6c4009
        {
Packit 6c4009
          char **m;
Packit 6c4009
Packit 6c4009
          for (m = g->gr_mem; *m != NULL; ++m)
Packit 6c4009
            if (strcmp (*m, user) == 0)
Packit 6c4009
              {
Packit 6c4009
                /* Matches user.  Insert this group.  */
Packit 6c4009
                if (*start == *size)
Packit 6c4009
                  {
Packit 6c4009
                    /* Need a bigger buffer.  */
Packit 6c4009
		    gid_t *newgroups;
Packit 6c4009
		    long int newsize;
Packit 6c4009
Packit 6c4009
		    if (limit > 0 && *size == limit)
Packit 6c4009
		      /* We reached the maximum.  */
Packit 6c4009
		      goto done;
Packit 6c4009
Packit 6c4009
		    if (limit <= 0)
Packit 6c4009
		      newsize = 2 * *size;
Packit 6c4009
		    else
Packit 6c4009
		      newsize = MIN (limit, 2 * *size);
Packit 6c4009
Packit 6c4009
		    newgroups = realloc (groups, newsize * sizeof (*groups));
Packit 6c4009
		    if (newgroups == NULL)
Packit 6c4009
		      {
Packit 6c4009
			status = NSS_STATUS_TRYAGAIN;
Packit 6c4009
			*errnop = errno;
Packit 6c4009
			goto done;
Packit 6c4009
		      }
Packit 6c4009
		    *groupsp = groups = newgroups;
Packit 6c4009
                    *size = newsize;
Packit 6c4009
                  }
Packit 6c4009
Packit 6c4009
                groups[*start] = g->gr_gid;
Packit 6c4009
		*start += 1;
Packit 6c4009
Packit 6c4009
                break;
Packit 6c4009
              }
Packit 6c4009
        }
Packit 6c4009
    }
Packit 6c4009
Packit 6c4009
done:
Packit 6c4009
  while (intern.start != NULL)
Packit 6c4009
    {
Packit 6c4009
      intern.next = intern.start;
Packit 6c4009
      intern.start = intern.start->next;
Packit 6c4009
      free (intern.next);
Packit 6c4009
    }
Packit 6c4009
  scratch_buffer_free (&tmpbuf);
Packit 6c4009
Packit 6c4009
  return status;
Packit 6c4009
}