Blame libarchive/archive_acl.c

Packit 08bd4c
/*-
Packit 08bd4c
 * Copyright (c) 2003-2010 Tim Kientzle
Packit 08bd4c
 * Copyright (c) 2016 Martin Matuska
Packit 08bd4c
 * All rights reserved.
Packit 08bd4c
 *
Packit 08bd4c
 * Redistribution and use in source and binary forms, with or without
Packit 08bd4c
 * modification, are permitted provided that the following conditions
Packit 08bd4c
 * are met:
Packit 08bd4c
 * 1. Redistributions of source code must retain the above copyright
Packit 08bd4c
 *    notice, this list of conditions and the following disclaimer.
Packit 08bd4c
 * 2. Redistributions in binary form must reproduce the above copyright
Packit 08bd4c
 *    notice, this list of conditions and the following disclaimer in the
Packit 08bd4c
 *    documentation and/or other materials provided with the distribution.
Packit 08bd4c
 *
Packit 08bd4c
 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR(S) ``AS IS'' AND ANY EXPRESS OR
Packit 08bd4c
 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
Packit 08bd4c
 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
Packit 08bd4c
 * IN NO EVENT SHALL THE AUTHOR(S) BE LIABLE FOR ANY DIRECT, INDIRECT,
Packit 08bd4c
 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
Packit 08bd4c
 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
Packit 08bd4c
 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
Packit 08bd4c
 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
Packit 08bd4c
 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
Packit 08bd4c
 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
Packit 08bd4c
 */
Packit 08bd4c
Packit 08bd4c
#include "archive_platform.h"
Packit 08bd4c
__FBSDID("$FreeBSD$");
Packit 08bd4c
Packit 08bd4c
#ifdef HAVE_ERRNO_H
Packit 08bd4c
#include <errno.h>
Packit 08bd4c
#endif
Packit 08bd4c
#ifdef HAVE_LIMITS_H
Packit 08bd4c
#include <limits.h>
Packit 08bd4c
#endif
Packit 08bd4c
#ifdef HAVE_WCHAR_H
Packit 08bd4c
#include <wchar.h>
Packit 08bd4c
#endif
Packit 08bd4c
Packit 08bd4c
#include "archive_acl_private.h"
Packit 08bd4c
#include "archive_entry.h"
Packit 08bd4c
#include "archive_private.h"
Packit 08bd4c
Packit 08bd4c
#undef max
Packit 08bd4c
#define	max(a, b)	((a)>(b)?(a):(b))
Packit 08bd4c
Packit 08bd4c
#ifndef HAVE_WMEMCMP
Packit 08bd4c
/* Good enough for simple equality testing, but not for sorting. */
Packit 08bd4c
#define wmemcmp(a,b,i)  memcmp((a), (b), (i) * sizeof(wchar_t))
Packit 08bd4c
#endif
Packit 08bd4c
Packit 08bd4c
static int	acl_special(struct archive_acl *acl,
Packit 08bd4c
		    int type, int permset, int tag);
Packit 08bd4c
static struct archive_acl_entry *acl_new_entry(struct archive_acl *acl,
Packit 08bd4c
		    int type, int permset, int tag, int id);
Packit 08bd4c
static int	archive_acl_add_entry_len_l(struct archive_acl *acl,
Packit 08bd4c
		    int type, int permset, int tag, int id, const char *name,
Packit 08bd4c
		    size_t len, struct archive_string_conv *sc);
Packit 08bd4c
static int	archive_acl_text_want_type(struct archive_acl *acl, int flags);
Packit 08bd4c
static ssize_t	archive_acl_text_len(struct archive_acl *acl, int want_type,
Packit 08bd4c
		    int flags, int wide, struct archive *a,
Packit 08bd4c
		    struct archive_string_conv *sc);
Packit 08bd4c
static int	isint_w(const wchar_t *start, const wchar_t *end, int *result);
Packit 08bd4c
static int	ismode_w(const wchar_t *start, const wchar_t *end, int *result);
Packit 08bd4c
static int	is_nfs4_flags_w(const wchar_t *start, const wchar_t *end,
Packit 08bd4c
		    int *result);
Packit 08bd4c
static int	is_nfs4_perms_w(const wchar_t *start, const wchar_t *end,
Packit 08bd4c
		    int *result);
Packit 08bd4c
static void	next_field_w(const wchar_t **wp, const wchar_t **start,
Packit 08bd4c
		    const wchar_t **end, wchar_t *sep);
Packit 08bd4c
static void	append_entry_w(wchar_t **wp, const wchar_t *prefix, int type,
Packit 08bd4c
		    int tag, int flags, const wchar_t *wname, int perm, int id);
Packit 08bd4c
static void	append_id_w(wchar_t **wp, int id);
Packit 08bd4c
static int	isint(const char *start, const char *end, int *result);
Packit 08bd4c
static int	ismode(const char *start, const char *end, int *result);
Packit 08bd4c
static int	is_nfs4_flags(const char *start, const char *end,
Packit 08bd4c
		    int *result);
Packit 08bd4c
static int	is_nfs4_perms(const char *start, const char *end,
Packit 08bd4c
		    int *result);
Packit 08bd4c
static void	next_field(const char **p, const char **start,
Packit 08bd4c
		    const char **end, char *sep);
Packit 08bd4c
static void	append_entry(char **p, const char *prefix, int type,
Packit 08bd4c
		    int tag, int flags, const char *name, int perm, int id);
Packit 08bd4c
static void	append_id(char **p, int id);
Packit 08bd4c
Packit 08bd4c
static const struct {
Packit 08bd4c
	const int perm;
Packit 08bd4c
	const char c;
Packit 08bd4c
	const wchar_t wc;
Packit 08bd4c
} nfsv4_acl_perm_map[] = {
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_READ_DATA | ARCHIVE_ENTRY_ACL_LIST_DIRECTORY, 'r',
Packit 08bd4c
	    L'r' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_WRITE_DATA | ARCHIVE_ENTRY_ACL_ADD_FILE, 'w',
Packit 08bd4c
	    L'w' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_EXECUTE, 'x', L'x' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_APPEND_DATA | ARCHIVE_ENTRY_ACL_ADD_SUBDIRECTORY,
Packit 08bd4c
	    'p', L'p' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_DELETE, 'd', L'd' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_DELETE_CHILD, 'D', L'D' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_READ_ATTRIBUTES, 'a', L'a' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_WRITE_ATTRIBUTES, 'A', L'A' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_READ_NAMED_ATTRS, 'R', L'R' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_WRITE_NAMED_ATTRS, 'W', L'W' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_READ_ACL, 'c', L'c' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_WRITE_ACL, 'C', L'C' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_WRITE_OWNER, 'o', L'o' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_SYNCHRONIZE, 's', L's' }
Packit 08bd4c
};
Packit 08bd4c
Packit 08bd4c
static const int nfsv4_acl_perm_map_size = (int)(sizeof(nfsv4_acl_perm_map) /
Packit 08bd4c
    sizeof(nfsv4_acl_perm_map[0]));
Packit 08bd4c
Packit 08bd4c
static const struct {
Packit 08bd4c
	const int perm;
Packit 08bd4c
	const char c;
Packit 08bd4c
	const wchar_t wc;
Packit 08bd4c
} nfsv4_acl_flag_map[] = {
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_ENTRY_FILE_INHERIT, 'f', L'f' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_ENTRY_DIRECTORY_INHERIT, 'd', L'd' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_ENTRY_INHERIT_ONLY, 'i', L'i' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_ENTRY_NO_PROPAGATE_INHERIT, 'n', L'n' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_ENTRY_SUCCESSFUL_ACCESS, 'S', L'S' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_ENTRY_FAILED_ACCESS, 'F', L'F' },
Packit 08bd4c
	{ ARCHIVE_ENTRY_ACL_ENTRY_INHERITED, 'I', L'I' }
Packit 08bd4c
};
Packit 08bd4c
Packit 08bd4c
static const int nfsv4_acl_flag_map_size = (int)(sizeof(nfsv4_acl_flag_map) /
Packit 08bd4c
    sizeof(nfsv4_acl_flag_map[0]));
Packit 08bd4c
Packit 08bd4c
void
Packit 08bd4c
archive_acl_clear(struct archive_acl *acl)
Packit 08bd4c
{
Packit 08bd4c
	struct archive_acl_entry *ap;
Packit 08bd4c
Packit 08bd4c
	while (acl->acl_head != NULL) {
Packit 08bd4c
		ap = acl->acl_head->next;
Packit 08bd4c
		archive_mstring_clean(&acl->acl_head->name);
Packit 08bd4c
		free(acl->acl_head);
Packit 08bd4c
		acl->acl_head = ap;
Packit 08bd4c
	}
Packit 08bd4c
	if (acl->acl_text_w != NULL) {
Packit 08bd4c
		free(acl->acl_text_w);
Packit 08bd4c
		acl->acl_text_w = NULL;
Packit 08bd4c
	}
Packit 08bd4c
	if (acl->acl_text != NULL) {
Packit 08bd4c
		free(acl->acl_text);
Packit 08bd4c
		acl->acl_text = NULL;
Packit 08bd4c
	}
Packit 08bd4c
	acl->acl_p = NULL;
Packit 08bd4c
	acl->acl_types = 0;
Packit 08bd4c
	acl->acl_state = 0; /* Not counting. */
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
void
Packit 08bd4c
archive_acl_copy(struct archive_acl *dest, struct archive_acl *src)
Packit 08bd4c
{
Packit 08bd4c
	struct archive_acl_entry *ap, *ap2;
Packit 08bd4c
Packit 08bd4c
	archive_acl_clear(dest);
Packit 08bd4c
Packit 08bd4c
	dest->mode = src->mode;
Packit 08bd4c
	ap = src->acl_head;
Packit 08bd4c
	while (ap != NULL) {
Packit 08bd4c
		ap2 = acl_new_entry(dest,
Packit 08bd4c
		    ap->type, ap->permset, ap->tag, ap->id);
Packit 08bd4c
		if (ap2 != NULL)
Packit 08bd4c
			archive_mstring_copy(&ap2->name, &ap->name);
Packit 08bd4c
		ap = ap->next;
Packit 08bd4c
	}
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
int
Packit 08bd4c
archive_acl_add_entry(struct archive_acl *acl,
Packit 08bd4c
    int type, int permset, int tag, int id, const char *name)
Packit 08bd4c
{
Packit 08bd4c
	struct archive_acl_entry *ap;
Packit 08bd4c
Packit 08bd4c
	if (acl_special(acl, type, permset, tag) == 0)
Packit 08bd4c
		return ARCHIVE_OK;
Packit 08bd4c
	ap = acl_new_entry(acl, type, permset, tag, id);
Packit 08bd4c
	if (ap == NULL) {
Packit 08bd4c
		/* XXX Error XXX */
Packit 08bd4c
		return ARCHIVE_FAILED;
Packit 08bd4c
	}
Packit 08bd4c
	if (name != NULL  &&  *name != '\0')
Packit 08bd4c
		archive_mstring_copy_mbs(&ap->name, name);
Packit 08bd4c
	else
Packit 08bd4c
		archive_mstring_clean(&ap->name);
Packit 08bd4c
	return ARCHIVE_OK;
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
int
Packit 08bd4c
archive_acl_add_entry_w_len(struct archive_acl *acl,
Packit 08bd4c
    int type, int permset, int tag, int id, const wchar_t *name, size_t len)
Packit 08bd4c
{
Packit 08bd4c
	struct archive_acl_entry *ap;
Packit 08bd4c
Packit 08bd4c
	if (acl_special(acl, type, permset, tag) == 0)
Packit 08bd4c
		return ARCHIVE_OK;
Packit 08bd4c
	ap = acl_new_entry(acl, type, permset, tag, id);
Packit 08bd4c
	if (ap == NULL) {
Packit 08bd4c
		/* XXX Error XXX */
Packit 08bd4c
		return ARCHIVE_FAILED;
Packit 08bd4c
	}
Packit 08bd4c
	if (name != NULL  &&  *name != L'\0' && len > 0)
Packit 08bd4c
		archive_mstring_copy_wcs_len(&ap->name, name, len);
Packit 08bd4c
	else
Packit 08bd4c
		archive_mstring_clean(&ap->name);
Packit 08bd4c
	return ARCHIVE_OK;
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
static int
Packit 08bd4c
archive_acl_add_entry_len_l(struct archive_acl *acl,
Packit 08bd4c
    int type, int permset, int tag, int id, const char *name, size_t len,
Packit 08bd4c
    struct archive_string_conv *sc)
Packit 08bd4c
{
Packit 08bd4c
	struct archive_acl_entry *ap;
Packit 08bd4c
	int r;
Packit 08bd4c
Packit 08bd4c
	if (acl_special(acl, type, permset, tag) == 0)
Packit 08bd4c
		return ARCHIVE_OK;
Packit 08bd4c
	ap = acl_new_entry(acl, type, permset, tag, id);
Packit 08bd4c
	if (ap == NULL) {
Packit 08bd4c
		/* XXX Error XXX */
Packit 08bd4c
		return ARCHIVE_FAILED;
Packit 08bd4c
	}
Packit 08bd4c
	if (name != NULL  &&  *name != '\0' && len > 0) {
Packit 08bd4c
		r = archive_mstring_copy_mbs_len_l(&ap->name, name, len, sc);
Packit 08bd4c
	} else {
Packit 08bd4c
		r = 0;
Packit 08bd4c
		archive_mstring_clean(&ap->name);
Packit 08bd4c
	}
Packit 08bd4c
	if (r == 0)
Packit 08bd4c
		return (ARCHIVE_OK);
Packit 08bd4c
	else if (errno == ENOMEM)
Packit 08bd4c
		return (ARCHIVE_FATAL);
Packit 08bd4c
	else
Packit 08bd4c
		return (ARCHIVE_WARN);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * If this ACL entry is part of the standard POSIX permissions set,
Packit 08bd4c
 * store the permissions in the stat structure and return zero.
Packit 08bd4c
 */
Packit 08bd4c
static int
Packit 08bd4c
acl_special(struct archive_acl *acl, int type, int permset, int tag)
Packit 08bd4c
{
Packit 08bd4c
	if (type == ARCHIVE_ENTRY_ACL_TYPE_ACCESS
Packit 08bd4c
	    && ((permset & ~007) == 0)) {
Packit 08bd4c
		switch (tag) {
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_USER_OBJ:
Packit 08bd4c
			acl->mode &= ~0700;
Packit 08bd4c
			acl->mode |= (permset & 7) << 6;
Packit 08bd4c
			return (0);
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_GROUP_OBJ:
Packit 08bd4c
			acl->mode &= ~0070;
Packit 08bd4c
			acl->mode |= (permset & 7) << 3;
Packit 08bd4c
			return (0);
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_OTHER:
Packit 08bd4c
			acl->mode &= ~0007;
Packit 08bd4c
			acl->mode |= permset & 7;
Packit 08bd4c
			return (0);
Packit 08bd4c
		}
Packit 08bd4c
	}
Packit 08bd4c
	return (1);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Allocate and populate a new ACL entry with everything but the
Packit 08bd4c
 * name.
Packit 08bd4c
 */
Packit 08bd4c
static struct archive_acl_entry *
Packit 08bd4c
acl_new_entry(struct archive_acl *acl,
Packit 08bd4c
    int type, int permset, int tag, int id)
Packit 08bd4c
{
Packit 08bd4c
	struct archive_acl_entry *ap, *aq;
Packit 08bd4c
Packit 08bd4c
	/* Type argument must be a valid NFS4 or POSIX.1e type.
Packit 08bd4c
	 * The type must agree with anything already set and
Packit 08bd4c
	 * the permset must be compatible. */
Packit 08bd4c
	if (type & ARCHIVE_ENTRY_ACL_TYPE_NFS4) {
Packit 08bd4c
		if (acl->acl_types & ~ARCHIVE_ENTRY_ACL_TYPE_NFS4) {
Packit 08bd4c
			return (NULL);
Packit 08bd4c
		}
Packit 08bd4c
		if (permset &
Packit 08bd4c
		    ~(ARCHIVE_ENTRY_ACL_PERMS_NFS4
Packit 08bd4c
			| ARCHIVE_ENTRY_ACL_INHERITANCE_NFS4)) {
Packit 08bd4c
			return (NULL);
Packit 08bd4c
		}
Packit 08bd4c
	} else	if (type & ARCHIVE_ENTRY_ACL_TYPE_POSIX1E) {
Packit 08bd4c
		if (acl->acl_types & ~ARCHIVE_ENTRY_ACL_TYPE_POSIX1E) {
Packit 08bd4c
			return (NULL);
Packit 08bd4c
		}
Packit 08bd4c
		if (permset & ~ARCHIVE_ENTRY_ACL_PERMS_POSIX1E) {
Packit 08bd4c
			return (NULL);
Packit 08bd4c
		}
Packit 08bd4c
	} else {
Packit 08bd4c
		return (NULL);
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	/* Verify the tag is valid and compatible with NFS4 or POSIX.1e. */
Packit 08bd4c
	switch (tag) {
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_USER:
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_USER_OBJ:
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_GROUP:
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_GROUP_OBJ:
Packit 08bd4c
		/* Tags valid in both NFS4 and POSIX.1e */
Packit 08bd4c
		break;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_MASK:
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_OTHER:
Packit 08bd4c
		/* Tags valid only in POSIX.1e. */
Packit 08bd4c
		if (type & ~ARCHIVE_ENTRY_ACL_TYPE_POSIX1E) {
Packit 08bd4c
			return (NULL);
Packit 08bd4c
		}
Packit 08bd4c
		break;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_EVERYONE:
Packit 08bd4c
		/* Tags valid only in NFS4. */
Packit 08bd4c
		if (type & ~ARCHIVE_ENTRY_ACL_TYPE_NFS4) {
Packit 08bd4c
			return (NULL);
Packit 08bd4c
		}
Packit 08bd4c
		break;
Packit 08bd4c
	default:
Packit 08bd4c
		/* No other values are valid. */
Packit 08bd4c
		return (NULL);
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	if (acl->acl_text_w != NULL) {
Packit 08bd4c
		free(acl->acl_text_w);
Packit 08bd4c
		acl->acl_text_w = NULL;
Packit 08bd4c
	}
Packit 08bd4c
	if (acl->acl_text != NULL) {
Packit 08bd4c
		free(acl->acl_text);
Packit 08bd4c
		acl->acl_text = NULL;
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	/*
Packit 08bd4c
	 * If there's a matching entry already in the list, overwrite it.
Packit 08bd4c
	 * NFSv4 entries may be repeated and are not overwritten.
Packit 08bd4c
	 *
Packit 08bd4c
	 * TODO: compare names of no id is provided (needs more rework)
Packit 08bd4c
	 */
Packit 08bd4c
	ap = acl->acl_head;
Packit 08bd4c
	aq = NULL;
Packit 08bd4c
	while (ap != NULL) {
Packit 08bd4c
		if (((type & ARCHIVE_ENTRY_ACL_TYPE_NFS4) == 0) &&
Packit 08bd4c
		    ap->type == type && ap->tag == tag && ap->id == id) {
Packit 08bd4c
			if (id != -1 || (tag != ARCHIVE_ENTRY_ACL_USER &&
Packit 08bd4c
			    tag != ARCHIVE_ENTRY_ACL_GROUP)) {
Packit 08bd4c
				ap->permset = permset;
Packit 08bd4c
				return (ap);
Packit 08bd4c
			}
Packit 08bd4c
		}
Packit 08bd4c
		aq = ap;
Packit 08bd4c
		ap = ap->next;
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	/* Add a new entry to the end of the list. */
Packit 08bd4c
	ap = (struct archive_acl_entry *)calloc(1, sizeof(*ap));
Packit 08bd4c
	if (ap == NULL)
Packit 08bd4c
		return (NULL);
Packit 08bd4c
	if (aq == NULL)
Packit 08bd4c
		acl->acl_head = ap;
Packit 08bd4c
	else
Packit 08bd4c
		aq->next = ap;
Packit 08bd4c
	ap->type = type;
Packit 08bd4c
	ap->tag = tag;
Packit 08bd4c
	ap->id = id;
Packit 08bd4c
	ap->permset = permset;
Packit 08bd4c
	acl->acl_types |= type;
Packit 08bd4c
	return (ap);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Return a count of entries matching "want_type".
Packit 08bd4c
 */
Packit 08bd4c
int
Packit 08bd4c
archive_acl_count(struct archive_acl *acl, int want_type)
Packit 08bd4c
{
Packit 08bd4c
	int count;
Packit 08bd4c
	struct archive_acl_entry *ap;
Packit 08bd4c
Packit 08bd4c
	count = 0;
Packit 08bd4c
	ap = acl->acl_head;
Packit 08bd4c
	while (ap != NULL) {
Packit 08bd4c
		if ((ap->type & want_type) != 0)
Packit 08bd4c
			count++;
Packit 08bd4c
		ap = ap->next;
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	if (count > 0 && ((want_type & ARCHIVE_ENTRY_ACL_TYPE_ACCESS) != 0))
Packit 08bd4c
		count += 3;
Packit 08bd4c
	return (count);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Return a bitmask of stored ACL types in an ACL list
Packit 08bd4c
 */
Packit 08bd4c
int
Packit 08bd4c
archive_acl_types(struct archive_acl *acl)
Packit 08bd4c
{
Packit 08bd4c
	return (acl->acl_types);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Prepare for reading entries from the ACL data.  Returns a count
Packit 08bd4c
 * of entries matching "want_type", or zero if there are no
Packit 08bd4c
 * non-extended ACL entries of that type.
Packit 08bd4c
 */
Packit 08bd4c
int
Packit 08bd4c
archive_acl_reset(struct archive_acl *acl, int want_type)
Packit 08bd4c
{
Packit 08bd4c
	int count, cutoff;
Packit 08bd4c
Packit 08bd4c
	count = archive_acl_count(acl, want_type);
Packit 08bd4c
Packit 08bd4c
	/*
Packit 08bd4c
	 * If the only entries are the three standard ones,
Packit 08bd4c
	 * then don't return any ACL data.  (In this case,
Packit 08bd4c
	 * client can just use chmod(2) to set permissions.)
Packit 08bd4c
	 */
Packit 08bd4c
	if ((want_type & ARCHIVE_ENTRY_ACL_TYPE_ACCESS) != 0)
Packit 08bd4c
		cutoff = 3;
Packit 08bd4c
	else
Packit 08bd4c
		cutoff = 0;
Packit 08bd4c
Packit 08bd4c
	if (count > cutoff)
Packit 08bd4c
		acl->acl_state = ARCHIVE_ENTRY_ACL_USER_OBJ;
Packit 08bd4c
	else
Packit 08bd4c
		acl->acl_state = 0;
Packit 08bd4c
	acl->acl_p = acl->acl_head;
Packit 08bd4c
	return (count);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Return the next ACL entry in the list.  Fake entries for the
Packit 08bd4c
 * standard permissions and include them in the returned list.
Packit 08bd4c
 */
Packit 08bd4c
int
Packit 08bd4c
archive_acl_next(struct archive *a, struct archive_acl *acl, int want_type,
Packit 08bd4c
    int *type, int *permset, int *tag, int *id, const char **name)
Packit 08bd4c
{
Packit 08bd4c
	*name = NULL;
Packit 08bd4c
	*id = -1;
Packit 08bd4c
Packit 08bd4c
	/*
Packit 08bd4c
	 * The acl_state is either zero (no entries available), -1
Packit 08bd4c
	 * (reading from list), or an entry type (retrieve that type
Packit 08bd4c
	 * from ae_stat.aest_mode).
Packit 08bd4c
	 */
Packit 08bd4c
	if (acl->acl_state == 0)
Packit 08bd4c
		return (ARCHIVE_WARN);
Packit 08bd4c
Packit 08bd4c
	/* The first three access entries are special. */
Packit 08bd4c
	if ((want_type & ARCHIVE_ENTRY_ACL_TYPE_ACCESS) != 0) {
Packit 08bd4c
		switch (acl->acl_state) {
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_USER_OBJ:
Packit 08bd4c
			*permset = (acl->mode >> 6) & 7;
Packit 08bd4c
			*type = ARCHIVE_ENTRY_ACL_TYPE_ACCESS;
Packit 08bd4c
			*tag = ARCHIVE_ENTRY_ACL_USER_OBJ;
Packit 08bd4c
			acl->acl_state = ARCHIVE_ENTRY_ACL_GROUP_OBJ;
Packit 08bd4c
			return (ARCHIVE_OK);
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_GROUP_OBJ:
Packit 08bd4c
			*permset = (acl->mode >> 3) & 7;
Packit 08bd4c
			*type = ARCHIVE_ENTRY_ACL_TYPE_ACCESS;
Packit 08bd4c
			*tag = ARCHIVE_ENTRY_ACL_GROUP_OBJ;
Packit 08bd4c
			acl->acl_state = ARCHIVE_ENTRY_ACL_OTHER;
Packit 08bd4c
			return (ARCHIVE_OK);
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_OTHER:
Packit 08bd4c
			*permset = acl->mode & 7;
Packit 08bd4c
			*type = ARCHIVE_ENTRY_ACL_TYPE_ACCESS;
Packit 08bd4c
			*tag = ARCHIVE_ENTRY_ACL_OTHER;
Packit 08bd4c
			acl->acl_state = -1;
Packit 08bd4c
			acl->acl_p = acl->acl_head;
Packit 08bd4c
			return (ARCHIVE_OK);
Packit 08bd4c
		default:
Packit 08bd4c
			break;
Packit 08bd4c
		}
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	while (acl->acl_p != NULL && (acl->acl_p->type & want_type) == 0)
Packit 08bd4c
		acl->acl_p = acl->acl_p->next;
Packit 08bd4c
	if (acl->acl_p == NULL) {
Packit 08bd4c
		acl->acl_state = 0;
Packit 08bd4c
		*type = 0;
Packit 08bd4c
		*permset = 0;
Packit 08bd4c
		*tag = 0;
Packit 08bd4c
		*id = -1;
Packit 08bd4c
		*name = NULL;
Packit 08bd4c
		return (ARCHIVE_EOF); /* End of ACL entries. */
Packit 08bd4c
	}
Packit 08bd4c
	*type = acl->acl_p->type;
Packit 08bd4c
	*permset = acl->acl_p->permset;
Packit 08bd4c
	*tag = acl->acl_p->tag;
Packit 08bd4c
	*id = acl->acl_p->id;
Packit 08bd4c
	if (archive_mstring_get_mbs(a, &acl->acl_p->name, name) != 0) {
Packit 08bd4c
		if (errno == ENOMEM)
Packit 08bd4c
			return (ARCHIVE_FATAL);
Packit 08bd4c
		*name = NULL;
Packit 08bd4c
	}
Packit 08bd4c
	acl->acl_p = acl->acl_p->next;
Packit 08bd4c
	return (ARCHIVE_OK);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Determine what type of ACL do we want
Packit 08bd4c
 */
Packit 08bd4c
static int
Packit 08bd4c
archive_acl_text_want_type(struct archive_acl *acl, int flags)
Packit 08bd4c
{
Packit 08bd4c
	int want_type;
Packit 08bd4c
Packit 08bd4c
	/* Check if ACL is NFSv4 */
Packit 08bd4c
	if ((acl->acl_types & ARCHIVE_ENTRY_ACL_TYPE_NFS4) != 0) {
Packit 08bd4c
		/* NFSv4 should never mix with POSIX.1e */
Packit 08bd4c
		if ((acl->acl_types & ARCHIVE_ENTRY_ACL_TYPE_POSIX1E) != 0)
Packit 08bd4c
			return (0);
Packit 08bd4c
		else
Packit 08bd4c
			return (ARCHIVE_ENTRY_ACL_TYPE_NFS4);
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	/* Now deal with POSIX.1e ACLs */
Packit 08bd4c
Packit 08bd4c
	want_type = 0;
Packit 08bd4c
	if ((flags & ARCHIVE_ENTRY_ACL_TYPE_ACCESS) != 0)
Packit 08bd4c
		want_type |= ARCHIVE_ENTRY_ACL_TYPE_ACCESS;
Packit 08bd4c
	if ((flags & ARCHIVE_ENTRY_ACL_TYPE_DEFAULT) != 0)
Packit 08bd4c
		want_type |= ARCHIVE_ENTRY_ACL_TYPE_DEFAULT;
Packit 08bd4c
Packit 08bd4c
	/* By default we want both access and default ACLs */
Packit 08bd4c
	if (want_type == 0)
Packit 08bd4c
		return (ARCHIVE_ENTRY_ACL_TYPE_POSIX1E);
Packit 08bd4c
Packit 08bd4c
	return (want_type);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Calculate ACL text string length
Packit 08bd4c
 */
Packit 08bd4c
static ssize_t
Packit 08bd4c
archive_acl_text_len(struct archive_acl *acl, int want_type, int flags,
Packit 08bd4c
    int wide, struct archive *a, struct archive_string_conv *sc) {
Packit 08bd4c
	struct archive_acl_entry *ap;
Packit 08bd4c
	const char *name;
Packit 08bd4c
	const wchar_t *wname;
Packit 08bd4c
	int count, idlen, tmp, r;
Packit 08bd4c
	ssize_t length;
Packit 08bd4c
	size_t len;
Packit 08bd4c
Packit 08bd4c
	count = 0;
Packit 08bd4c
	length = 0;
Packit 08bd4c
	for (ap = acl->acl_head; ap != NULL; ap = ap->next) {
Packit 08bd4c
		if ((ap->type & want_type) == 0)
Packit 08bd4c
			continue;
Packit 08bd4c
		/*
Packit 08bd4c
		 * Filemode-mapping ACL entries are stored exclusively in
Packit 08bd4c
		 * ap->mode so they should not be in the list
Packit 08bd4c
		 */
Packit 08bd4c
		if ((ap->type == ARCHIVE_ENTRY_ACL_TYPE_ACCESS)
Packit 08bd4c
		    && (ap->tag == ARCHIVE_ENTRY_ACL_USER_OBJ
Packit 08bd4c
		    || ap->tag == ARCHIVE_ENTRY_ACL_GROUP_OBJ
Packit 08bd4c
		    || ap->tag == ARCHIVE_ENTRY_ACL_OTHER))
Packit 08bd4c
			continue;
Packit 08bd4c
		count++;
Packit 08bd4c
		if ((want_type & ARCHIVE_ENTRY_ACL_TYPE_DEFAULT) != 0
Packit 08bd4c
		    && (ap->type & ARCHIVE_ENTRY_ACL_TYPE_DEFAULT) != 0)
Packit 08bd4c
			length += 8; /* "default:" */
Packit 08bd4c
		switch (ap->tag) {
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_USER_OBJ:
Packit 08bd4c
			if (want_type == ARCHIVE_ENTRY_ACL_TYPE_NFS4) {
Packit 08bd4c
				length += 6; /* "owner@" */
Packit 08bd4c
				break;
Packit 08bd4c
			}
Packit 08bd4c
			/* FALLTHROUGH */
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_USER:
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_MASK:
Packit 08bd4c
			length += 4; /* "user", "mask" */
Packit 08bd4c
			break;
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_GROUP_OBJ:
Packit 08bd4c
			if (want_type == ARCHIVE_ENTRY_ACL_TYPE_NFS4) {
Packit 08bd4c
				length += 6; /* "group@" */
Packit 08bd4c
				break;
Packit 08bd4c
			}
Packit 08bd4c
			/* FALLTHROUGH */
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_GROUP:
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_OTHER:
Packit 08bd4c
			length += 5; /* "group", "other" */
Packit 08bd4c
			break;
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_EVERYONE:
Packit 08bd4c
			length += 9; /* "everyone@" */
Packit 08bd4c
			break;
Packit 08bd4c
		}
Packit 08bd4c
		length += 1; /* colon after tag */
Packit 08bd4c
		if (ap->tag == ARCHIVE_ENTRY_ACL_USER ||
Packit 08bd4c
		    ap->tag == ARCHIVE_ENTRY_ACL_GROUP) {
Packit 08bd4c
			if (wide) {
Packit 08bd4c
				r = archive_mstring_get_wcs(a, &ap->name,
Packit 08bd4c
				    &wname);
Packit 08bd4c
				if (r == 0 && wname != NULL)
Packit 08bd4c
					length += wcslen(wname);
Packit 08bd4c
				else if (r < 0 && errno == ENOMEM)
Packit 08bd4c
					return (0);
Packit 08bd4c
				else
Packit 08bd4c
					length += sizeof(uid_t) * 3 + 1;
Packit 08bd4c
			} else {
Packit 08bd4c
				r = archive_mstring_get_mbs_l(&ap->name, &name,
Packit 08bd4c
				    &len, sc);
Packit 08bd4c
				if (r != 0)
Packit 08bd4c
					return (0);
Packit 08bd4c
				if (len > 0 && name != NULL)
Packit 08bd4c
					length += len;
Packit 08bd4c
				else
Packit 08bd4c
					length += sizeof(uid_t) * 3 + 1;
Packit 08bd4c
			}
Packit 08bd4c
			length += 1; /* colon after user or group name */
Packit 08bd4c
		} else if (want_type != ARCHIVE_ENTRY_ACL_TYPE_NFS4)
Packit 08bd4c
			length += 1; /* 2nd colon empty user,group or other */
Packit 08bd4c
Packit 08bd4c
		if (((flags & ARCHIVE_ENTRY_ACL_STYLE_SOLARIS) != 0)
Packit 08bd4c
		    && ((want_type & ARCHIVE_ENTRY_ACL_TYPE_POSIX1E) != 0)
Packit 08bd4c
		    && (ap->tag == ARCHIVE_ENTRY_ACL_OTHER
Packit 08bd4c
		    || ap->tag == ARCHIVE_ENTRY_ACL_MASK)) {
Packit 08bd4c
			/* Solaris has no colon after other: and mask: */
Packit 08bd4c
			length = length - 1;
Packit 08bd4c
		}
Packit 08bd4c
Packit 08bd4c
		if (want_type == ARCHIVE_ENTRY_ACL_TYPE_NFS4) {
Packit 08bd4c
			/* rwxpdDaARWcCos:fdinSFI:deny */
Packit 08bd4c
			length += 27;
Packit 08bd4c
			if ((ap->type & ARCHIVE_ENTRY_ACL_TYPE_DENY) == 0)
Packit 08bd4c
				length += 1; /* allow, alarm, audit */
Packit 08bd4c
		} else
Packit 08bd4c
			length += 3; /* rwx */
Packit 08bd4c
Packit 08bd4c
		if ((ap->tag == ARCHIVE_ENTRY_ACL_USER ||
Packit 08bd4c
		    ap->tag == ARCHIVE_ENTRY_ACL_GROUP) &&
Packit 08bd4c
		    (flags & ARCHIVE_ENTRY_ACL_STYLE_EXTRA_ID) != 0) {
Packit 08bd4c
			length += 1; /* colon */
Packit 08bd4c
			/* ID digit count */
Packit 08bd4c
			idlen = 1;
Packit 08bd4c
			tmp = ap->id;
Packit 08bd4c
			while (tmp > 9) {
Packit 08bd4c
				tmp = tmp / 10;
Packit 08bd4c
				idlen++;
Packit 08bd4c
			}
Packit 08bd4c
			length += idlen;
Packit 08bd4c
		}
Packit 08bd4c
		length ++; /* entry separator */
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	/* Add filemode-mapping access entries to the length */
Packit 08bd4c
	if ((want_type & ARCHIVE_ENTRY_ACL_TYPE_ACCESS) != 0) {
Packit 08bd4c
		if ((flags & ARCHIVE_ENTRY_ACL_STYLE_SOLARIS) != 0) {
Packit 08bd4c
			/* "user::rwx\ngroup::rwx\nother:rwx\n" */
Packit 08bd4c
			length += 31;
Packit 08bd4c
		} else {
Packit 08bd4c
			/* "user::rwx\ngroup::rwx\nother::rwx\n" */
Packit 08bd4c
			length += 32;
Packit 08bd4c
		}
Packit 08bd4c
	} else if (count == 0)
Packit 08bd4c
		return (0);
Packit 08bd4c
Packit 08bd4c
	/* The terminating character is included in count */
Packit 08bd4c
	return (length);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Generate a wide text version of the ACL. The flags parameter controls
Packit 08bd4c
 * the type and style of the generated ACL.
Packit 08bd4c
 */
Packit 08bd4c
wchar_t *
Packit 08bd4c
archive_acl_to_text_w(struct archive_acl *acl, ssize_t *text_len, int flags,
Packit 08bd4c
    struct archive *a)
Packit 08bd4c
{
Packit 08bd4c
	int count;
Packit 08bd4c
	ssize_t length;
Packit 08bd4c
	size_t len;
Packit 08bd4c
	const wchar_t *wname;
Packit 08bd4c
	const wchar_t *prefix;
Packit 08bd4c
	wchar_t separator;
Packit 08bd4c
	struct archive_acl_entry *ap;
Packit 08bd4c
	int id, r, want_type;
Packit 08bd4c
	wchar_t *wp, *ws;
Packit 08bd4c
Packit 08bd4c
	want_type = archive_acl_text_want_type(acl, flags);
Packit 08bd4c
Packit 08bd4c
	/* Both NFSv4 and POSIX.1 types found */
Packit 08bd4c
	if (want_type == 0)
Packit 08bd4c
		return (NULL);
Packit 08bd4c
Packit 08bd4c
	if (want_type == ARCHIVE_ENTRY_ACL_TYPE_POSIX1E)
Packit 08bd4c
		flags |= ARCHIVE_ENTRY_ACL_STYLE_MARK_DEFAULT;
Packit 08bd4c
Packit 08bd4c
	length = archive_acl_text_len(acl, want_type, flags, 1, a, NULL);
Packit 08bd4c
Packit 08bd4c
	if (length == 0)
Packit 08bd4c
		return (NULL);
Packit 08bd4c
Packit 08bd4c
	if (flags & ARCHIVE_ENTRY_ACL_STYLE_SEPARATOR_COMMA)
Packit 08bd4c
		separator = L',';
Packit 08bd4c
	else
Packit 08bd4c
		separator = L'\n';
Packit 08bd4c
Packit 08bd4c
	/* Now, allocate the string and actually populate it. */
Packit 08bd4c
	wp = ws = (wchar_t *)malloc(length * sizeof(wchar_t));
Packit 08bd4c
	if (wp == NULL) {
Packit 08bd4c
		if (errno == ENOMEM)
Packit 08bd4c
			__archive_errx(1, "No memory");
Packit 08bd4c
		return (NULL);
Packit 08bd4c
	}
Packit 08bd4c
	count = 0;
Packit 08bd4c
Packit 08bd4c
	if ((want_type & ARCHIVE_ENTRY_ACL_TYPE_ACCESS) != 0) {
Packit 08bd4c
		append_entry_w(&wp, NULL, ARCHIVE_ENTRY_ACL_TYPE_ACCESS,
Packit 08bd4c
		    ARCHIVE_ENTRY_ACL_USER_OBJ, flags, NULL,
Packit 08bd4c
		    acl->mode & 0700, -1);
Packit 08bd4c
		*wp++ = separator;
Packit 08bd4c
		append_entry_w(&wp, NULL, ARCHIVE_ENTRY_ACL_TYPE_ACCESS,
Packit 08bd4c
		    ARCHIVE_ENTRY_ACL_GROUP_OBJ, flags, NULL,
Packit 08bd4c
		    acl->mode & 0070, -1);
Packit 08bd4c
		*wp++ = separator;
Packit 08bd4c
		append_entry_w(&wp, NULL, ARCHIVE_ENTRY_ACL_TYPE_ACCESS,
Packit 08bd4c
		    ARCHIVE_ENTRY_ACL_OTHER, flags, NULL,
Packit 08bd4c
		    acl->mode & 0007, -1);
Packit 08bd4c
		count += 3;
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	for (ap = acl->acl_head; ap != NULL; ap = ap->next) {
Packit 08bd4c
		if ((ap->type & want_type) == 0)
Packit 08bd4c
			continue;
Packit 08bd4c
		/*
Packit 08bd4c
		 * Filemode-mapping ACL entries are stored exclusively in
Packit 08bd4c
		 * ap->mode so they should not be in the list
Packit 08bd4c
		 */
Packit 08bd4c
		if ((ap->type == ARCHIVE_ENTRY_ACL_TYPE_ACCESS)
Packit 08bd4c
		    && (ap->tag == ARCHIVE_ENTRY_ACL_USER_OBJ
Packit 08bd4c
		    || ap->tag == ARCHIVE_ENTRY_ACL_GROUP_OBJ
Packit 08bd4c
		    || ap->tag == ARCHIVE_ENTRY_ACL_OTHER))
Packit 08bd4c
			continue;
Packit 08bd4c
		if (ap->type == ARCHIVE_ENTRY_ACL_TYPE_DEFAULT &&
Packit 08bd4c
		    (flags & ARCHIVE_ENTRY_ACL_STYLE_MARK_DEFAULT) != 0)
Packit 08bd4c
			prefix = L"default:";
Packit 08bd4c
		else
Packit 08bd4c
			prefix = NULL;
Packit 08bd4c
		r = archive_mstring_get_wcs(a, &ap->name, &wname);
Packit 08bd4c
		if (r == 0) {
Packit 08bd4c
			if (count > 0)
Packit 08bd4c
				*wp++ = separator;
Packit 08bd4c
			if (flags & ARCHIVE_ENTRY_ACL_STYLE_EXTRA_ID)
Packit 08bd4c
				id = ap->id;
Packit 08bd4c
			else
Packit 08bd4c
				id = -1;
Packit 08bd4c
			append_entry_w(&wp, prefix, ap->type, ap->tag, flags,
Packit 08bd4c
			    wname, ap->permset, id);
Packit 08bd4c
			count++;
Packit Service 108033
		} else if (r < 0 && errno == ENOMEM)
Packit 08bd4c
			return (NULL);
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	/* Add terminating character */
Packit 08bd4c
	*wp++ = L'\0';
Packit 08bd4c
Packit 08bd4c
	len = wcslen(ws);
Packit 08bd4c
Packit 08bd4c
	if ((ssize_t)len > (length - 1))
Packit 08bd4c
		__archive_errx(1, "Buffer overrun");
Packit 08bd4c
Packit 08bd4c
	if (text_len != NULL)
Packit 08bd4c
		*text_len = len;
Packit 08bd4c
Packit 08bd4c
	return (ws);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
static void
Packit 08bd4c
append_id_w(wchar_t **wp, int id)
Packit 08bd4c
{
Packit 08bd4c
	if (id < 0)
Packit 08bd4c
		id = 0;
Packit 08bd4c
	if (id > 9)
Packit 08bd4c
		append_id_w(wp, id / 10);
Packit 08bd4c
	*(*wp)++ = L"0123456789"[id % 10];
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
static void
Packit 08bd4c
append_entry_w(wchar_t **wp, const wchar_t *prefix, int type,
Packit 08bd4c
    int tag, int flags, const wchar_t *wname, int perm, int id)
Packit 08bd4c
{
Packit 08bd4c
	int i;
Packit 08bd4c
Packit 08bd4c
	if (prefix != NULL) {
Packit 08bd4c
		wcscpy(*wp, prefix);
Packit 08bd4c
		*wp += wcslen(*wp);
Packit 08bd4c
	}
Packit 08bd4c
	switch (tag) {
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_USER_OBJ:
Packit 08bd4c
		wname = NULL;
Packit 08bd4c
		id = -1;
Packit 08bd4c
		if ((type & ARCHIVE_ENTRY_ACL_TYPE_NFS4) != 0) {
Packit 08bd4c
			wcscpy(*wp, L"owner@");
Packit 08bd4c
			break;
Packit 08bd4c
		}
Packit 08bd4c
		/* FALLTHROUGH */
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_USER:
Packit 08bd4c
		wcscpy(*wp, L"user");
Packit 08bd4c
		break;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_GROUP_OBJ:
Packit 08bd4c
		wname = NULL;
Packit 08bd4c
		id = -1;
Packit 08bd4c
		if ((type & ARCHIVE_ENTRY_ACL_TYPE_NFS4) != 0) {
Packit 08bd4c
			wcscpy(*wp, L"group@");
Packit 08bd4c
			break;
Packit 08bd4c
		}
Packit 08bd4c
		/* FALLTHROUGH */
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_GROUP:
Packit 08bd4c
		wcscpy(*wp, L"group");
Packit 08bd4c
		break;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_MASK:
Packit 08bd4c
		wcscpy(*wp, L"mask");
Packit 08bd4c
		wname = NULL;
Packit 08bd4c
		id = -1;
Packit 08bd4c
		break;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_OTHER:
Packit 08bd4c
		wcscpy(*wp, L"other");
Packit 08bd4c
		wname = NULL;
Packit 08bd4c
		id = -1;
Packit 08bd4c
		break;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_EVERYONE:
Packit 08bd4c
		wcscpy(*wp, L"everyone@");
Packit 08bd4c
		wname = NULL;
Packit 08bd4c
		id = -1;
Packit 08bd4c
		break;
Packit 08bd4c
	}
Packit 08bd4c
	*wp += wcslen(*wp);
Packit 08bd4c
	*(*wp)++ = L':';
Packit 08bd4c
	if (((type & ARCHIVE_ENTRY_ACL_TYPE_POSIX1E) != 0) ||
Packit 08bd4c
	    tag == ARCHIVE_ENTRY_ACL_USER ||
Packit 08bd4c
	    tag == ARCHIVE_ENTRY_ACL_GROUP) {
Packit 08bd4c
		if (wname != NULL) {
Packit 08bd4c
			wcscpy(*wp, wname);
Packit 08bd4c
			*wp += wcslen(*wp);
Packit 08bd4c
		} else if (tag == ARCHIVE_ENTRY_ACL_USER
Packit 08bd4c
		    || tag == ARCHIVE_ENTRY_ACL_GROUP) {
Packit 08bd4c
			append_id_w(wp, id);
Packit 08bd4c
			if ((type & ARCHIVE_ENTRY_ACL_TYPE_NFS4) == 0)
Packit 08bd4c
				id = -1;
Packit 08bd4c
		}
Packit 08bd4c
		/* Solaris style has no second colon after other and mask */
Packit 08bd4c
		if (((flags & ARCHIVE_ENTRY_ACL_STYLE_SOLARIS) == 0)
Packit 08bd4c
		    || (tag != ARCHIVE_ENTRY_ACL_OTHER
Packit 08bd4c
		    && tag != ARCHIVE_ENTRY_ACL_MASK))
Packit 08bd4c
			*(*wp)++ = L':';
Packit 08bd4c
	}
Packit 08bd4c
	if ((type & ARCHIVE_ENTRY_ACL_TYPE_POSIX1E) != 0) {
Packit 08bd4c
		/* POSIX.1e ACL perms */
Packit 08bd4c
		*(*wp)++ = (perm & 0444) ? L'r' : L'-';
Packit 08bd4c
		*(*wp)++ = (perm & 0222) ? L'w' : L'-';
Packit 08bd4c
		*(*wp)++ = (perm & 0111) ? L'x' : L'-';
Packit 08bd4c
	} else {
Packit 08bd4c
		/* NFSv4 ACL perms */
Packit 08bd4c
		for (i = 0; i < nfsv4_acl_perm_map_size; i++) {
Packit 08bd4c
			if (perm & nfsv4_acl_perm_map[i].perm)
Packit 08bd4c
				*(*wp)++ = nfsv4_acl_perm_map[i].wc;
Packit 08bd4c
			else if ((flags & ARCHIVE_ENTRY_ACL_STYLE_COMPACT) == 0)
Packit 08bd4c
				*(*wp)++ = L'-';
Packit 08bd4c
		}
Packit 08bd4c
		*(*wp)++ = L':';
Packit 08bd4c
		for (i = 0; i < nfsv4_acl_flag_map_size; i++) {
Packit 08bd4c
			if (perm & nfsv4_acl_flag_map[i].perm)
Packit 08bd4c
				*(*wp)++ = nfsv4_acl_flag_map[i].wc;
Packit 08bd4c
			else if ((flags & ARCHIVE_ENTRY_ACL_STYLE_COMPACT) == 0)
Packit 08bd4c
				*(*wp)++ = L'-';
Packit 08bd4c
		}
Packit 08bd4c
		*(*wp)++ = L':';
Packit 08bd4c
		switch (type) {
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_TYPE_ALLOW:
Packit 08bd4c
			wcscpy(*wp, L"allow");
Packit 08bd4c
			break;
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_TYPE_DENY:
Packit 08bd4c
			wcscpy(*wp, L"deny");
Packit 08bd4c
			break;
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_TYPE_AUDIT:
Packit 08bd4c
			wcscpy(*wp, L"audit");
Packit 08bd4c
			break;
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_TYPE_ALARM:
Packit 08bd4c
			wcscpy(*wp, L"alarm");
Packit 08bd4c
			break;
Packit 08bd4c
		default:
Packit 08bd4c
			break;
Packit 08bd4c
		}
Packit 08bd4c
		*wp += wcslen(*wp);
Packit 08bd4c
	}
Packit 08bd4c
	if (id != -1) {
Packit 08bd4c
		*(*wp)++ = L':';
Packit 08bd4c
		append_id_w(wp, id);
Packit 08bd4c
	}
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Generate a text version of the ACL. The flags parameter controls
Packit 08bd4c
 * the type and style of the generated ACL.
Packit 08bd4c
 */
Packit 08bd4c
char *
Packit 08bd4c
archive_acl_to_text_l(struct archive_acl *acl, ssize_t *text_len, int flags,
Packit 08bd4c
    struct archive_string_conv *sc)
Packit 08bd4c
{
Packit 08bd4c
	int count;
Packit 08bd4c
	ssize_t length;
Packit 08bd4c
	size_t len;
Packit 08bd4c
	const char *name;
Packit 08bd4c
	const char *prefix;
Packit 08bd4c
	char separator;
Packit 08bd4c
	struct archive_acl_entry *ap;
Packit 08bd4c
	int id, r, want_type;
Packit 08bd4c
	char *p, *s;
Packit 08bd4c
Packit 08bd4c
	want_type = archive_acl_text_want_type(acl, flags);
Packit 08bd4c
Packit 08bd4c
	/* Both NFSv4 and POSIX.1 types found */
Packit 08bd4c
	if (want_type == 0)
Packit 08bd4c
		return (NULL);
Packit 08bd4c
Packit 08bd4c
	if (want_type == ARCHIVE_ENTRY_ACL_TYPE_POSIX1E)
Packit 08bd4c
		flags |= ARCHIVE_ENTRY_ACL_STYLE_MARK_DEFAULT;
Packit 08bd4c
Packit 08bd4c
	length = archive_acl_text_len(acl, want_type, flags, 0, NULL, sc);
Packit 08bd4c
Packit 08bd4c
	if (length == 0)
Packit 08bd4c
		return (NULL);
Packit 08bd4c
Packit 08bd4c
	if (flags & ARCHIVE_ENTRY_ACL_STYLE_SEPARATOR_COMMA)
Packit 08bd4c
		separator = ',';
Packit 08bd4c
	else
Packit 08bd4c
		separator = '\n';
Packit 08bd4c
Packit 08bd4c
	/* Now, allocate the string and actually populate it. */
Packit 08bd4c
	p = s = (char *)malloc(length * sizeof(char));
Packit 08bd4c
	if (p == NULL) {
Packit 08bd4c
		if (errno == ENOMEM)
Packit 08bd4c
			__archive_errx(1, "No memory");
Packit 08bd4c
		return (NULL);
Packit 08bd4c
	}
Packit 08bd4c
	count = 0;
Packit 08bd4c
Packit 08bd4c
	if ((want_type & ARCHIVE_ENTRY_ACL_TYPE_ACCESS) != 0) {
Packit 08bd4c
		append_entry(&p, NULL, ARCHIVE_ENTRY_ACL_TYPE_ACCESS,
Packit 08bd4c
		    ARCHIVE_ENTRY_ACL_USER_OBJ, flags, NULL,
Packit 08bd4c
		    acl->mode & 0700, -1);
Packit 08bd4c
		*p++ = separator;
Packit 08bd4c
		append_entry(&p, NULL, ARCHIVE_ENTRY_ACL_TYPE_ACCESS,
Packit 08bd4c
		    ARCHIVE_ENTRY_ACL_GROUP_OBJ, flags, NULL,
Packit 08bd4c
		    acl->mode & 0070, -1);
Packit 08bd4c
		*p++ = separator;
Packit 08bd4c
		append_entry(&p, NULL, ARCHIVE_ENTRY_ACL_TYPE_ACCESS,
Packit 08bd4c
		    ARCHIVE_ENTRY_ACL_OTHER, flags, NULL,
Packit 08bd4c
		    acl->mode & 0007, -1);
Packit 08bd4c
		count += 3;
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	for (ap = acl->acl_head; ap != NULL; ap = ap->next) {
Packit 08bd4c
		if ((ap->type & want_type) == 0)
Packit 08bd4c
			continue;
Packit 08bd4c
		/*
Packit 08bd4c
		 * Filemode-mapping ACL entries are stored exclusively in
Packit 08bd4c
		 * ap->mode so they should not be in the list
Packit 08bd4c
		 */
Packit 08bd4c
		if ((ap->type == ARCHIVE_ENTRY_ACL_TYPE_ACCESS)
Packit 08bd4c
		    && (ap->tag == ARCHIVE_ENTRY_ACL_USER_OBJ
Packit 08bd4c
		    || ap->tag == ARCHIVE_ENTRY_ACL_GROUP_OBJ
Packit 08bd4c
		    || ap->tag == ARCHIVE_ENTRY_ACL_OTHER))
Packit 08bd4c
			continue;
Packit 08bd4c
		if (ap->type == ARCHIVE_ENTRY_ACL_TYPE_DEFAULT &&
Packit 08bd4c
		    (flags & ARCHIVE_ENTRY_ACL_STYLE_MARK_DEFAULT) != 0)
Packit 08bd4c
			prefix = "default:";
Packit 08bd4c
		else
Packit 08bd4c
			prefix = NULL;
Packit 08bd4c
		r = archive_mstring_get_mbs_l(
Packit 08bd4c
		    &ap->name, &name, &len, sc);
Packit Service 108033
		if (r != 0)
Packit 08bd4c
			return (NULL);
Packit 08bd4c
		if (count > 0)
Packit 08bd4c
			*p++ = separator;
Packit 08bd4c
		if (name == NULL ||
Packit 08bd4c
		    (flags & ARCHIVE_ENTRY_ACL_STYLE_EXTRA_ID)) {
Packit 08bd4c
			id = ap->id;
Packit 08bd4c
		} else {
Packit 08bd4c
			id = -1;
Packit 08bd4c
		}
Packit 08bd4c
		append_entry(&p, prefix, ap->type, ap->tag, flags, name,
Packit 08bd4c
		    ap->permset, id);
Packit 08bd4c
		count++;
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	/* Add terminating character */
Packit 08bd4c
	*p++ = '\0';
Packit 08bd4c
Packit 08bd4c
	len = strlen(s);
Packit 08bd4c
Packit 08bd4c
	if ((ssize_t)len > (length - 1))
Packit 08bd4c
		__archive_errx(1, "Buffer overrun");
Packit 08bd4c
Packit 08bd4c
	if (text_len != NULL)
Packit 08bd4c
		*text_len = len;
Packit 08bd4c
Packit 08bd4c
	return (s);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
static void
Packit 08bd4c
append_id(char **p, int id)
Packit 08bd4c
{
Packit 08bd4c
	if (id < 0)
Packit 08bd4c
		id = 0;
Packit 08bd4c
	if (id > 9)
Packit 08bd4c
		append_id(p, id / 10);
Packit 08bd4c
	*(*p)++ = "0123456789"[id % 10];
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
static void
Packit 08bd4c
append_entry(char **p, const char *prefix, int type,
Packit 08bd4c
    int tag, int flags, const char *name, int perm, int id)
Packit 08bd4c
{
Packit 08bd4c
	int i;
Packit 08bd4c
Packit 08bd4c
	if (prefix != NULL) {
Packit 08bd4c
		strcpy(*p, prefix);
Packit 08bd4c
		*p += strlen(*p);
Packit 08bd4c
	}
Packit 08bd4c
	switch (tag) {
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_USER_OBJ:
Packit 08bd4c
		name = NULL;
Packit 08bd4c
		id = -1;
Packit 08bd4c
		if ((type & ARCHIVE_ENTRY_ACL_TYPE_NFS4) != 0) {
Packit 08bd4c
			strcpy(*p, "owner@");
Packit 08bd4c
			break;
Packit 08bd4c
		}
Packit 08bd4c
		/* FALLTHROUGH */
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_USER:
Packit 08bd4c
		strcpy(*p, "user");
Packit 08bd4c
		break;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_GROUP_OBJ:
Packit 08bd4c
		name = NULL;
Packit 08bd4c
		id = -1;
Packit 08bd4c
		if ((type & ARCHIVE_ENTRY_ACL_TYPE_NFS4) != 0) {
Packit 08bd4c
			strcpy(*p, "group@");
Packit 08bd4c
			break;
Packit 08bd4c
		}
Packit 08bd4c
		/* FALLTHROUGH */
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_GROUP:
Packit 08bd4c
		strcpy(*p, "group");
Packit 08bd4c
		break;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_MASK:
Packit 08bd4c
		strcpy(*p, "mask");
Packit 08bd4c
		name = NULL;
Packit 08bd4c
		id = -1;
Packit 08bd4c
		break;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_OTHER:
Packit 08bd4c
		strcpy(*p, "other");
Packit 08bd4c
		name = NULL;
Packit 08bd4c
		id = -1;
Packit 08bd4c
		break;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_EVERYONE:
Packit 08bd4c
		strcpy(*p, "everyone@");
Packit 08bd4c
		name = NULL;
Packit 08bd4c
		id = -1;
Packit 08bd4c
		break;
Packit 08bd4c
	}
Packit 08bd4c
	*p += strlen(*p);
Packit 08bd4c
	*(*p)++ = ':';
Packit 08bd4c
	if (((type & ARCHIVE_ENTRY_ACL_TYPE_POSIX1E) != 0) ||
Packit 08bd4c
	    tag == ARCHIVE_ENTRY_ACL_USER ||
Packit 08bd4c
	    tag == ARCHIVE_ENTRY_ACL_GROUP) {
Packit 08bd4c
		if (name != NULL) {
Packit 08bd4c
			strcpy(*p, name);
Packit 08bd4c
			*p += strlen(*p);
Packit 08bd4c
		} else if (tag == ARCHIVE_ENTRY_ACL_USER
Packit 08bd4c
		    || tag == ARCHIVE_ENTRY_ACL_GROUP) {
Packit 08bd4c
			append_id(p, id);
Packit 08bd4c
			if ((type & ARCHIVE_ENTRY_ACL_TYPE_NFS4) == 0)
Packit 08bd4c
				id = -1;
Packit 08bd4c
		}
Packit 08bd4c
		/* Solaris style has no second colon after other and mask */
Packit 08bd4c
		if (((flags & ARCHIVE_ENTRY_ACL_STYLE_SOLARIS) == 0)
Packit 08bd4c
		    || (tag != ARCHIVE_ENTRY_ACL_OTHER
Packit 08bd4c
		    && tag != ARCHIVE_ENTRY_ACL_MASK))
Packit 08bd4c
			*(*p)++ = ':';
Packit 08bd4c
	}
Packit 08bd4c
	if ((type & ARCHIVE_ENTRY_ACL_TYPE_POSIX1E) != 0) {
Packit 08bd4c
		/* POSIX.1e ACL perms */
Packit 08bd4c
		*(*p)++ = (perm & 0444) ? 'r' : '-';
Packit 08bd4c
		*(*p)++ = (perm & 0222) ? 'w' : '-';
Packit 08bd4c
		*(*p)++ = (perm & 0111) ? 'x' : '-';
Packit 08bd4c
	} else {
Packit 08bd4c
		/* NFSv4 ACL perms */
Packit 08bd4c
		for (i = 0; i < nfsv4_acl_perm_map_size; i++) {
Packit 08bd4c
			if (perm & nfsv4_acl_perm_map[i].perm)
Packit 08bd4c
				*(*p)++ = nfsv4_acl_perm_map[i].c;
Packit 08bd4c
			else if ((flags & ARCHIVE_ENTRY_ACL_STYLE_COMPACT) == 0)
Packit 08bd4c
				*(*p)++ = '-';
Packit 08bd4c
		}
Packit 08bd4c
		*(*p)++ = ':';
Packit 08bd4c
		for (i = 0; i < nfsv4_acl_flag_map_size; i++) {
Packit 08bd4c
			if (perm & nfsv4_acl_flag_map[i].perm)
Packit 08bd4c
				*(*p)++ = nfsv4_acl_flag_map[i].c;
Packit 08bd4c
			else if ((flags & ARCHIVE_ENTRY_ACL_STYLE_COMPACT) == 0)
Packit 08bd4c
				*(*p)++ = '-';
Packit 08bd4c
		}
Packit 08bd4c
		*(*p)++ = ':';
Packit 08bd4c
		switch (type) {
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_TYPE_ALLOW:
Packit 08bd4c
			strcpy(*p, "allow");
Packit 08bd4c
			break;
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_TYPE_DENY:
Packit 08bd4c
			strcpy(*p, "deny");
Packit 08bd4c
			break;
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_TYPE_AUDIT:
Packit 08bd4c
			strcpy(*p, "audit");
Packit 08bd4c
			break;
Packit 08bd4c
		case ARCHIVE_ENTRY_ACL_TYPE_ALARM:
Packit 08bd4c
			strcpy(*p, "alarm");
Packit 08bd4c
			break;
Packit 08bd4c
		}
Packit 08bd4c
		*p += strlen(*p);
Packit 08bd4c
	}
Packit 08bd4c
	if (id != -1) {
Packit 08bd4c
		*(*p)++ = ':';
Packit 08bd4c
		append_id(p, id);
Packit 08bd4c
	}
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Parse a wide ACL text string.
Packit 08bd4c
 *
Packit 08bd4c
 * The want_type argument may be one of the following:
Packit 08bd4c
 * ARCHIVE_ENTRY_ACL_TYPE_ACCESS - text is a POSIX.1e ACL of type ACCESS
Packit 08bd4c
 * ARCHIVE_ENTRY_ACL_TYPE_DEFAULT - text is a POSIX.1e ACL of type DEFAULT
Packit 08bd4c
 * ARCHIVE_ENTRY_ACL_TYPE_NFS4 - text is as a NFSv4 ACL
Packit 08bd4c
 *
Packit 08bd4c
 * POSIX.1e ACL entries prefixed with "default:" are treated as
Packit 08bd4c
 * ARCHIVE_ENTRY_ACL_TYPE_DEFAULT unless type is ARCHIVE_ENTRY_ACL_TYPE_NFS4
Packit 08bd4c
 */
Packit 08bd4c
int
Packit 08bd4c
archive_acl_from_text_w(struct archive_acl *acl, const wchar_t *text,
Packit 08bd4c
    int want_type)
Packit 08bd4c
{
Packit 08bd4c
	struct {
Packit 08bd4c
		const wchar_t *start;
Packit 08bd4c
		const wchar_t *end;
Packit 08bd4c
	} field[6], name;
Packit 08bd4c
Packit 08bd4c
	const wchar_t *s, *st;
Packit 08bd4c
Packit 08bd4c
	int numfields, fields, n, r, sol, ret;
Packit 08bd4c
	int type, types, tag, permset, id;
Packit 08bd4c
	size_t len;
Packit 08bd4c
	wchar_t sep;
Packit 08bd4c
Packit 08bd4c
	ret = ARCHIVE_OK;
Packit 08bd4c
	types = 0;
Packit 08bd4c
Packit 08bd4c
	switch (want_type) {
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_TYPE_POSIX1E:
Packit 08bd4c
		want_type = ARCHIVE_ENTRY_ACL_TYPE_ACCESS;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_TYPE_ACCESS:
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_TYPE_DEFAULT:
Packit 08bd4c
		numfields = 5;
Packit 08bd4c
		break;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_TYPE_NFS4:
Packit 08bd4c
		numfields = 6;
Packit 08bd4c
		break;
Packit 08bd4c
	default:
Packit 08bd4c
		return (ARCHIVE_FATAL);
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	while (text != NULL && *text != L'\0') {
Packit 08bd4c
		/*
Packit 08bd4c
		 * Parse the fields out of the next entry,
Packit 08bd4c
		 * advance 'text' to start of next entry.
Packit 08bd4c
		 */
Packit 08bd4c
		fields = 0;
Packit 08bd4c
		do {
Packit 08bd4c
			const wchar_t *start, *end;
Packit 08bd4c
			next_field_w(&text, &start, &end, &sep;;
Packit 08bd4c
			if (fields < numfields) {
Packit 08bd4c
				field[fields].start = start;
Packit 08bd4c
				field[fields].end = end;
Packit 08bd4c
			}
Packit 08bd4c
			++fields;
Packit 08bd4c
		} while (sep == L':');
Packit 08bd4c
Packit 08bd4c
		/* Set remaining fields to blank. */
Packit 08bd4c
		for (n = fields; n < numfields; ++n)
Packit 08bd4c
			field[n].start = field[n].end = NULL;
Packit 08bd4c
Packit 08bd4c
		if (field[0].start != NULL && *(field[0].start) == L'#') {
Packit 08bd4c
			/* Comment, skip entry */
Packit 08bd4c
			continue;
Packit 08bd4c
		}
Packit 08bd4c
Packit 08bd4c
		n = 0;
Packit 08bd4c
		sol = 0;
Packit 08bd4c
		id = -1;
Packit 08bd4c
		permset = 0;
Packit 08bd4c
		name.start = name.end = NULL;
Packit 08bd4c
Packit 08bd4c
		if (want_type != ARCHIVE_ENTRY_ACL_TYPE_NFS4) {
Packit 08bd4c
			/* POSIX.1e ACLs */
Packit 08bd4c
			/*
Packit 08bd4c
			 * Default keyword "default:user::rwx"
Packit 08bd4c
			 * if found, we have one more field
Packit 08bd4c
			 *
Packit 08bd4c
			 * We also support old Solaris extension:
Packit 08bd4c
			 * "defaultuser::rwx" is the default ACL corresponding
Packit 08bd4c
			 * to "user::rwx", etc. valid only for first field
Packit 08bd4c
			 */
Packit 08bd4c
			s = field[0].start;
Packit 08bd4c
			len = field[0].end - field[0].start;
Packit 08bd4c
			if (*s == L'd' && (len == 1 || (len >= 7
Packit 08bd4c
			    && wmemcmp((s + 1), L"efault", 6) == 0))) {
Packit 08bd4c
				type = ARCHIVE_ENTRY_ACL_TYPE_DEFAULT;
Packit 08bd4c
				if (len > 7)
Packit 08bd4c
					field[0].start += 7;
Packit 08bd4c
				else
Packit 08bd4c
					n = 1;
Packit 08bd4c
			} else
Packit 08bd4c
				type = want_type;
Packit 08bd4c
Packit 08bd4c
			/* Check for a numeric ID in field n+1 or n+3. */
Packit 08bd4c
			isint_w(field[n + 1].start, field[n + 1].end, &id;;
Packit 08bd4c
			/* Field n+3 is optional. */
Packit 08bd4c
			if (id == -1 && fields > n+3)
Packit 08bd4c
				isint_w(field[n + 3].start, field[n + 3].end,
Packit 08bd4c
				    &id;;
Packit 08bd4c
Packit 08bd4c
			tag = 0;
Packit 08bd4c
			s = field[n].start;
Packit 08bd4c
			st = field[n].start + 1;
Packit 08bd4c
			len = field[n].end - field[n].start;
Packit 08bd4c
Packit 08bd4c
			switch (*s) {
Packit 08bd4c
			case L'u':
Packit 08bd4c
				if (len == 1 || (len == 4
Packit 08bd4c
				    && wmemcmp(st, L"ser", 3) == 0))
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_USER_OBJ;
Packit 08bd4c
				break;
Packit 08bd4c
			case L'g':
Packit 08bd4c
				if (len == 1 || (len == 5
Packit 08bd4c
				    && wmemcmp(st, L"roup", 4) == 0))
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_GROUP_OBJ;
Packit 08bd4c
				break;
Packit 08bd4c
			case L'o':
Packit 08bd4c
				if (len == 1 || (len == 5
Packit 08bd4c
				    && wmemcmp(st, L"ther", 4) == 0))
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_OTHER;
Packit 08bd4c
				break;
Packit 08bd4c
			case L'm':
Packit 08bd4c
				if (len == 1 || (len == 4
Packit 08bd4c
				    && wmemcmp(st, L"ask", 3) == 0))
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_MASK;
Packit 08bd4c
				break;
Packit 08bd4c
			default:
Packit 08bd4c
					break;
Packit 08bd4c
			}
Packit 08bd4c
Packit 08bd4c
			switch (tag) {
Packit 08bd4c
			case ARCHIVE_ENTRY_ACL_OTHER:
Packit 08bd4c
			case ARCHIVE_ENTRY_ACL_MASK:
Packit 08bd4c
				if (fields == (n + 2)
Packit 08bd4c
				    && field[n + 1].start < field[n + 1].end
Packit 08bd4c
				    && ismode_w(field[n + 1].start,
Packit 08bd4c
				    field[n + 1].end, &permset)) {
Packit 08bd4c
					/* This is Solaris-style "other:rwx" */
Packit 08bd4c
					sol = 1;
Packit 08bd4c
				} else if (fields == (n + 3) &&
Packit 08bd4c
				    field[n + 1].start < field[n + 1].end) {
Packit 08bd4c
					/* Invalid mask or other field */
Packit 08bd4c
					ret = ARCHIVE_WARN;
Packit 08bd4c
					continue;
Packit 08bd4c
				}
Packit 08bd4c
				break;
Packit 08bd4c
			case ARCHIVE_ENTRY_ACL_USER_OBJ:
Packit 08bd4c
			case ARCHIVE_ENTRY_ACL_GROUP_OBJ:
Packit 08bd4c
				if (id != -1 ||
Packit 08bd4c
				    field[n + 1].start < field[n + 1].end) {
Packit 08bd4c
					name = field[n + 1];
Packit 08bd4c
					if (tag == ARCHIVE_ENTRY_ACL_USER_OBJ)
Packit 08bd4c
						tag = ARCHIVE_ENTRY_ACL_USER;
Packit 08bd4c
					else
Packit 08bd4c
						tag = ARCHIVE_ENTRY_ACL_GROUP;
Packit 08bd4c
				}
Packit 08bd4c
				break;
Packit 08bd4c
			default:
Packit 08bd4c
				/* Invalid tag, skip entry */
Packit 08bd4c
				ret = ARCHIVE_WARN;
Packit 08bd4c
				continue;
Packit 08bd4c
			}
Packit 08bd4c
Packit 08bd4c
			/*
Packit 08bd4c
			 * Without "default:" we expect mode in field 2
Packit 08bd4c
			 * Exception: Solaris other and mask fields
Packit 08bd4c
			 */
Packit 08bd4c
			if (permset == 0 && !ismode_w(field[n + 2 - sol].start,
Packit 08bd4c
			    field[n + 2 - sol].end, &permset)) {
Packit 08bd4c
				/* Invalid mode, skip entry */
Packit 08bd4c
				ret = ARCHIVE_WARN;
Packit 08bd4c
				continue;
Packit 08bd4c
			}
Packit 08bd4c
		} else {
Packit 08bd4c
			/* NFS4 ACLs */
Packit 08bd4c
			s = field[0].start;
Packit 08bd4c
			len = field[0].end - field[0].start;
Packit 08bd4c
			tag = 0;
Packit 08bd4c
Packit 08bd4c
			switch (len) {
Packit 08bd4c
			case 4:
Packit 08bd4c
				if (wmemcmp(s, L"user", 4) == 0)
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_USER;
Packit 08bd4c
				break;
Packit 08bd4c
			case 5:
Packit 08bd4c
				if (wmemcmp(s, L"group", 5) == 0)
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_GROUP;
Packit 08bd4c
				break;
Packit 08bd4c
			case 6:
Packit 08bd4c
				if (wmemcmp(s, L"owner@", 6) == 0)
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_USER_OBJ;
Packit 08bd4c
				else if (wmemcmp(s, L"group@", len) == 0)
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_GROUP_OBJ;
Packit 08bd4c
				break;
Packit 08bd4c
			case 9:
Packit 08bd4c
				if (wmemcmp(s, L"everyone@", 9) == 0)
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_EVERYONE;
Packit 08bd4c
			default:
Packit 08bd4c
				break;
Packit 08bd4c
			}
Packit 08bd4c
Packit 08bd4c
			if (tag == 0) {
Packit 08bd4c
				/* Invalid tag, skip entry */
Packit 08bd4c
				ret = ARCHIVE_WARN;
Packit 08bd4c
				continue;
Packit 08bd4c
			} else if (tag == ARCHIVE_ENTRY_ACL_USER ||
Packit 08bd4c
			    tag == ARCHIVE_ENTRY_ACL_GROUP) {
Packit 08bd4c
				n = 1;
Packit 08bd4c
				name = field[1];
Packit 08bd4c
				isint_w(name.start, name.end, &id;;
Packit 08bd4c
			} else
Packit 08bd4c
				n = 0;
Packit 08bd4c
Packit 08bd4c
			if (!is_nfs4_perms_w(field[1 + n].start,
Packit 08bd4c
			    field[1 + n].end, &permset)) {
Packit 08bd4c
				/* Invalid NFSv4 perms, skip entry */
Packit 08bd4c
				ret = ARCHIVE_WARN;
Packit 08bd4c
				continue;
Packit 08bd4c
			}
Packit 08bd4c
			if (!is_nfs4_flags_w(field[2 + n].start,
Packit 08bd4c
			    field[2 + n].end, &permset)) {
Packit 08bd4c
				/* Invalid NFSv4 flags, skip entry */
Packit 08bd4c
				ret = ARCHIVE_WARN;
Packit 08bd4c
				continue;
Packit 08bd4c
			}
Packit 08bd4c
			s = field[3 + n].start;
Packit 08bd4c
			len = field[3 + n].end - field[3 + n].start;
Packit 08bd4c
			type = 0;
Packit 08bd4c
			if (len == 4) {
Packit 08bd4c
				if (wmemcmp(s, L"deny", 4) == 0)
Packit 08bd4c
					type = ARCHIVE_ENTRY_ACL_TYPE_DENY;
Packit 08bd4c
			} else if (len == 5) {
Packit 08bd4c
				if (wmemcmp(s, L"allow", 5) == 0)
Packit 08bd4c
					type = ARCHIVE_ENTRY_ACL_TYPE_ALLOW;
Packit 08bd4c
				else if (wmemcmp(s, L"audit", 5) == 0)
Packit 08bd4c
					type = ARCHIVE_ENTRY_ACL_TYPE_AUDIT;
Packit 08bd4c
				else if (wmemcmp(s, L"alarm", 5) == 0)
Packit 08bd4c
					type = ARCHIVE_ENTRY_ACL_TYPE_ALARM;
Packit 08bd4c
			}
Packit 08bd4c
			if (type == 0) {
Packit 08bd4c
				/* Invalid entry type, skip entry */
Packit 08bd4c
				ret = ARCHIVE_WARN;
Packit 08bd4c
				continue;
Packit 08bd4c
			}
Packit 08bd4c
			isint_w(field[4 + n].start, field[4 + n].end, &id;;
Packit 08bd4c
		}
Packit 08bd4c
Packit 08bd4c
		/* Add entry to the internal list. */
Packit 08bd4c
		r = archive_acl_add_entry_w_len(acl, type, permset,
Packit 08bd4c
		    tag, id, name.start, name.end - name.start);
Packit 08bd4c
		if (r < ARCHIVE_WARN)
Packit 08bd4c
			return (r);
Packit 08bd4c
		if (r != ARCHIVE_OK)
Packit 08bd4c
			ret = ARCHIVE_WARN;
Packit 08bd4c
		types |= type;
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	/* Reset ACL */
Packit 08bd4c
	archive_acl_reset(acl, types);
Packit 08bd4c
Packit 08bd4c
	return (ret);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Parse a string to a positive decimal integer.  Returns true if
Packit 08bd4c
 * the string is non-empty and consists only of decimal digits,
Packit 08bd4c
 * false otherwise.
Packit 08bd4c
 */
Packit 08bd4c
static int
Packit 08bd4c
isint_w(const wchar_t *start, const wchar_t *end, int *result)
Packit 08bd4c
{
Packit 08bd4c
	int n = 0;
Packit 08bd4c
	if (start >= end)
Packit 08bd4c
		return (0);
Packit 08bd4c
	while (start < end) {
Packit 08bd4c
		if (*start < '0' || *start > '9')
Packit 08bd4c
			return (0);
Packit 08bd4c
		if (n > (INT_MAX / 10) ||
Packit 08bd4c
		    (n == INT_MAX / 10 && (*start - '0') > INT_MAX % 10)) {
Packit 08bd4c
			n = INT_MAX;
Packit 08bd4c
		} else {
Packit 08bd4c
			n *= 10;
Packit 08bd4c
			n += *start - '0';
Packit 08bd4c
		}
Packit 08bd4c
		start++;
Packit 08bd4c
	}
Packit 08bd4c
	*result = n;
Packit 08bd4c
	return (1);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Parse a string as a mode field.  Returns true if
Packit 08bd4c
 * the string is non-empty and consists only of mode characters,
Packit 08bd4c
 * false otherwise.
Packit 08bd4c
 */
Packit 08bd4c
static int
Packit 08bd4c
ismode_w(const wchar_t *start, const wchar_t *end, int *permset)
Packit 08bd4c
{
Packit 08bd4c
	const wchar_t *p;
Packit 08bd4c
Packit 08bd4c
	if (start >= end)
Packit 08bd4c
		return (0);
Packit 08bd4c
	p = start;
Packit 08bd4c
	*permset = 0;
Packit 08bd4c
	while (p < end) {
Packit 08bd4c
		switch (*p++) {
Packit 08bd4c
		case L'r': case L'R':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_READ;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'w': case L'W':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_WRITE;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'x': case L'X':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_EXECUTE;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'-':
Packit 08bd4c
			break;
Packit 08bd4c
		default:
Packit 08bd4c
			return (0);
Packit 08bd4c
		}
Packit 08bd4c
	}
Packit 08bd4c
	return (1);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Parse a string as a NFS4 ACL permission field.
Packit 08bd4c
 * Returns true if the string is non-empty and consists only of NFS4 ACL
Packit 08bd4c
 * permission characters, false otherwise
Packit 08bd4c
 */
Packit 08bd4c
static int
Packit 08bd4c
is_nfs4_perms_w(const wchar_t *start, const wchar_t *end, int *permset)
Packit 08bd4c
{
Packit 08bd4c
	const wchar_t *p = start;
Packit 08bd4c
Packit 08bd4c
	while (p < end) {
Packit 08bd4c
		switch (*p++) {
Packit 08bd4c
		case L'r':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_READ_DATA;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'w':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_WRITE_DATA;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'x':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_EXECUTE;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'p':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_APPEND_DATA;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'D':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_DELETE_CHILD;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'd':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_DELETE;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'a':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_READ_ATTRIBUTES;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'A':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_WRITE_ATTRIBUTES;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'R':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_READ_NAMED_ATTRS;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'W':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_WRITE_NAMED_ATTRS;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'c':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_READ_ACL;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'C':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_WRITE_ACL;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'o':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_WRITE_OWNER;
Packit 08bd4c
			break;
Packit 08bd4c
		case L's':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_SYNCHRONIZE;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'-':
Packit 08bd4c
			break;
Packit 08bd4c
		default:
Packit 08bd4c
			return(0);
Packit 08bd4c
		}
Packit 08bd4c
	}
Packit 08bd4c
	return (1);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Parse a string as a NFS4 ACL flags field.
Packit 08bd4c
 * Returns true if the string is non-empty and consists only of NFS4 ACL
Packit 08bd4c
 * flag characters, false otherwise
Packit 08bd4c
 */
Packit 08bd4c
static int
Packit 08bd4c
is_nfs4_flags_w(const wchar_t *start, const wchar_t *end, int *permset)
Packit 08bd4c
{
Packit 08bd4c
	const wchar_t *p = start;
Packit 08bd4c
Packit 08bd4c
	while (p < end) {
Packit 08bd4c
		switch(*p++) {
Packit 08bd4c
		case L'f':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_ENTRY_FILE_INHERIT;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'd':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_ENTRY_DIRECTORY_INHERIT;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'i':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_ENTRY_INHERIT_ONLY;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'n':
Packit 08bd4c
			*permset |=
Packit 08bd4c
			    ARCHIVE_ENTRY_ACL_ENTRY_NO_PROPAGATE_INHERIT;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'S':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_ENTRY_SUCCESSFUL_ACCESS;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'F':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_ENTRY_FAILED_ACCESS;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'I':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_ENTRY_INHERITED;
Packit 08bd4c
			break;
Packit 08bd4c
		case L'-':
Packit 08bd4c
			break;
Packit 08bd4c
		default:
Packit 08bd4c
			return (0);
Packit 08bd4c
		}
Packit 08bd4c
	}
Packit 08bd4c
	return (1);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Match "[:whitespace:]*(.*)[:whitespace:]*[:,\n]".  *wp is updated
Packit 08bd4c
 * to point to just after the separator.  *start points to the first
Packit 08bd4c
 * character of the matched text and *end just after the last
Packit 08bd4c
 * character of the matched identifier.  In particular *end - *start
Packit 08bd4c
 * is the length of the field body, not including leading or trailing
Packit 08bd4c
 * whitespace.
Packit 08bd4c
 */
Packit 08bd4c
static void
Packit 08bd4c
next_field_w(const wchar_t **wp, const wchar_t **start,
Packit 08bd4c
    const wchar_t **end, wchar_t *sep)
Packit 08bd4c
{
Packit 08bd4c
	/* Skip leading whitespace to find start of field. */
Packit 08bd4c
	while (**wp == L' ' || **wp == L'\t' || **wp == L'\n') {
Packit 08bd4c
		(*wp)++;
Packit 08bd4c
	}
Packit 08bd4c
	*start = *wp;
Packit 08bd4c
Packit 08bd4c
	/* Scan for the separator. */
Packit 08bd4c
	while (**wp != L'\0' && **wp != L',' && **wp != L':' &&
Packit 08bd4c
	    **wp != L'\n') {
Packit 08bd4c
		(*wp)++;
Packit 08bd4c
	}
Packit 08bd4c
	*sep = **wp;
Packit 08bd4c
Packit 08bd4c
	/* Trim trailing whitespace to locate end of field. */
Packit 08bd4c
	*end = *wp - 1;
Packit 08bd4c
	while (**end == L' ' || **end == L'\t' || **end == L'\n') {
Packit 08bd4c
		(*end)--;
Packit 08bd4c
	}
Packit 08bd4c
	(*end)++;
Packit 08bd4c
Packit 08bd4c
	/* Adjust scanner location. */
Packit 08bd4c
	if (**wp != L'\0')
Packit 08bd4c
		(*wp)++;
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Parse an ACL text string.
Packit 08bd4c
 *
Packit 08bd4c
 * The want_type argument may be one of the following:
Packit 08bd4c
 * ARCHIVE_ENTRY_ACL_TYPE_ACCESS - text is a POSIX.1e ACL of type ACCESS
Packit 08bd4c
 * ARCHIVE_ENTRY_ACL_TYPE_DEFAULT - text is a POSIX.1e ACL of type DEFAULT
Packit 08bd4c
 * ARCHIVE_ENTRY_ACL_TYPE_NFS4 - text is as a NFSv4 ACL
Packit 08bd4c
 *
Packit 08bd4c
 * POSIX.1e ACL entries prefixed with "default:" are treated as
Packit 08bd4c
 * ARCHIVE_ENTRY_ACL_TYPE_DEFAULT unless type is ARCHIVE_ENTRY_ACL_TYPE_NFS4
Packit 08bd4c
 */
Packit 08bd4c
int
Packit 08bd4c
archive_acl_from_text_l(struct archive_acl *acl, const char *text,
Packit 08bd4c
    int want_type, struct archive_string_conv *sc)
Packit 08bd4c
{
Packit 08bd4c
	struct {
Packit 08bd4c
		const char *start;
Packit 08bd4c
		const char *end;
Packit 08bd4c
	} field[6], name;
Packit 08bd4c
Packit 08bd4c
	const char *s, *st;
Packit 08bd4c
	int numfields, fields, n, r, sol, ret;
Packit 08bd4c
	int type, types, tag, permset, id;
Packit 08bd4c
	size_t len;
Packit 08bd4c
	char sep;
Packit 08bd4c
Packit 08bd4c
	switch (want_type) {
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_TYPE_POSIX1E:
Packit 08bd4c
		want_type = ARCHIVE_ENTRY_ACL_TYPE_ACCESS;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_TYPE_ACCESS:
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_TYPE_DEFAULT:
Packit 08bd4c
		numfields = 5;
Packit 08bd4c
		break;
Packit 08bd4c
	case ARCHIVE_ENTRY_ACL_TYPE_NFS4:
Packit 08bd4c
		numfields = 6;
Packit 08bd4c
		break;
Packit 08bd4c
	default:
Packit 08bd4c
		return (ARCHIVE_FATAL);
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	ret = ARCHIVE_OK;
Packit 08bd4c
	types = 0;
Packit 08bd4c
Packit 08bd4c
	while (text != NULL  &&  *text != '\0') {
Packit 08bd4c
		/*
Packit 08bd4c
		 * Parse the fields out of the next entry,
Packit 08bd4c
		 * advance 'text' to start of next entry.
Packit 08bd4c
		 */
Packit 08bd4c
		fields = 0;
Packit 08bd4c
		do {
Packit 08bd4c
			const char *start, *end;
Packit 08bd4c
			next_field(&text, &start, &end, &sep;;
Packit 08bd4c
			if (fields < numfields) {
Packit 08bd4c
				field[fields].start = start;
Packit 08bd4c
				field[fields].end = end;
Packit 08bd4c
			}
Packit 08bd4c
			++fields;
Packit 08bd4c
		} while (sep == ':');
Packit 08bd4c
Packit 08bd4c
		/* Set remaining fields to blank. */
Packit 08bd4c
		for (n = fields; n < numfields; ++n)
Packit 08bd4c
			field[n].start = field[n].end = NULL;
Packit 08bd4c
Packit 08bd4c
		if (field[0].start != NULL && *(field[0].start) == '#') {
Packit 08bd4c
			/* Comment, skip entry */
Packit 08bd4c
			continue;
Packit 08bd4c
		}
Packit 08bd4c
Packit 08bd4c
		n = 0;
Packit 08bd4c
		sol = 0;
Packit 08bd4c
		id = -1;
Packit 08bd4c
		permset = 0;
Packit 08bd4c
		name.start = name.end = NULL;
Packit 08bd4c
Packit 08bd4c
		if (want_type != ARCHIVE_ENTRY_ACL_TYPE_NFS4) {
Packit 08bd4c
			/* POSIX.1e ACLs */
Packit 08bd4c
			/*
Packit 08bd4c
			 * Default keyword "default:user::rwx"
Packit 08bd4c
			 * if found, we have one more field
Packit 08bd4c
			 *
Packit 08bd4c
			 * We also support old Solaris extension:
Packit 08bd4c
			 * "defaultuser::rwx" is the default ACL corresponding
Packit 08bd4c
			 * to "user::rwx", etc. valid only for first field
Packit 08bd4c
			 */
Packit 08bd4c
			s = field[0].start;
Packit 08bd4c
			len = field[0].end - field[0].start;
Packit 08bd4c
			if (*s == 'd' && (len == 1 || (len >= 7
Packit 08bd4c
			    && memcmp((s + 1), "efault", 6) == 0))) {
Packit 08bd4c
				type = ARCHIVE_ENTRY_ACL_TYPE_DEFAULT;
Packit 08bd4c
				if (len > 7)
Packit 08bd4c
					field[0].start += 7;
Packit 08bd4c
				else
Packit 08bd4c
					n = 1;
Packit 08bd4c
			} else
Packit 08bd4c
				type = want_type;
Packit 08bd4c
Packit 08bd4c
			/* Check for a numeric ID in field n+1 or n+3. */
Packit 08bd4c
			isint(field[n + 1].start, field[n + 1].end, &id;;
Packit 08bd4c
			/* Field n+3 is optional. */
Packit 08bd4c
			if (id == -1 && fields > (n + 3))
Packit 08bd4c
				isint(field[n + 3].start, field[n + 3].end,
Packit 08bd4c
				    &id;;
Packit 08bd4c
Packit 08bd4c
			tag = 0;
Packit 08bd4c
			s = field[n].start;
Packit 08bd4c
			st = field[n].start + 1;
Packit 08bd4c
			len = field[n].end - field[n].start;
Packit 08bd4c
Packit 08bd4c
			switch (*s) {
Packit 08bd4c
			case 'u':
Packit 08bd4c
				if (len == 1 || (len == 4
Packit 08bd4c
				    && memcmp(st, "ser", 3) == 0))
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_USER_OBJ;
Packit 08bd4c
				break;
Packit 08bd4c
			case 'g':
Packit 08bd4c
				if (len == 1 || (len == 5
Packit 08bd4c
				    && memcmp(st, "roup", 4) == 0))
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_GROUP_OBJ;
Packit 08bd4c
				break;
Packit 08bd4c
			case 'o':
Packit 08bd4c
				if (len == 1 || (len == 5
Packit 08bd4c
				    && memcmp(st, "ther", 4) == 0))
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_OTHER;
Packit 08bd4c
				break;
Packit 08bd4c
			case 'm':
Packit 08bd4c
				if (len == 1 || (len == 4
Packit 08bd4c
				    && memcmp(st, "ask", 3) == 0))
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_MASK;
Packit 08bd4c
				break;
Packit 08bd4c
			default:
Packit 08bd4c
					break;
Packit 08bd4c
			}
Packit 08bd4c
Packit 08bd4c
			switch (tag) {
Packit 08bd4c
			case ARCHIVE_ENTRY_ACL_OTHER:
Packit 08bd4c
			case ARCHIVE_ENTRY_ACL_MASK:
Packit 08bd4c
				if (fields == (n + 2)
Packit 08bd4c
				    && field[n + 1].start < field[n + 1].end
Packit 08bd4c
				    && ismode(field[n + 1].start,
Packit 08bd4c
				    field[n + 1].end, &permset)) {
Packit 08bd4c
					/* This is Solaris-style "other:rwx" */
Packit 08bd4c
					sol = 1;
Packit 08bd4c
				} else if (fields == (n + 3) &&
Packit 08bd4c
				    field[n + 1].start < field[n + 1].end) {
Packit 08bd4c
					/* Invalid mask or other field */
Packit 08bd4c
					ret = ARCHIVE_WARN;
Packit 08bd4c
					continue;
Packit 08bd4c
				}
Packit 08bd4c
				break;
Packit 08bd4c
			case ARCHIVE_ENTRY_ACL_USER_OBJ:
Packit 08bd4c
			case ARCHIVE_ENTRY_ACL_GROUP_OBJ:
Packit 08bd4c
				if (id != -1 ||
Packit 08bd4c
				    field[n + 1].start < field[n + 1].end) {
Packit 08bd4c
					name = field[n + 1];
Packit 08bd4c
					if (tag == ARCHIVE_ENTRY_ACL_USER_OBJ)
Packit 08bd4c
						tag = ARCHIVE_ENTRY_ACL_USER;
Packit 08bd4c
					else
Packit 08bd4c
						tag = ARCHIVE_ENTRY_ACL_GROUP;
Packit 08bd4c
				}
Packit 08bd4c
				break;
Packit 08bd4c
			default:
Packit 08bd4c
				/* Invalid tag, skip entry */
Packit 08bd4c
				ret = ARCHIVE_WARN;
Packit 08bd4c
				continue;
Packit 08bd4c
			}
Packit 08bd4c
Packit 08bd4c
			/*
Packit 08bd4c
			 * Without "default:" we expect mode in field 3
Packit 08bd4c
			 * Exception: Solaris other and mask fields
Packit 08bd4c
			 */
Packit 08bd4c
			if (permset == 0 && !ismode(field[n + 2 - sol].start,
Packit 08bd4c
			    field[n + 2 - sol].end, &permset)) {
Packit 08bd4c
				/* Invalid mode, skip entry */
Packit 08bd4c
				ret = ARCHIVE_WARN;
Packit 08bd4c
				continue;
Packit 08bd4c
			}
Packit 08bd4c
		} else {
Packit 08bd4c
			/* NFS4 ACLs */
Packit 08bd4c
			s = field[0].start;
Packit 08bd4c
			len = field[0].end - field[0].start;
Packit 08bd4c
			tag = 0;
Packit 08bd4c
Packit 08bd4c
			switch (len) {
Packit 08bd4c
			case 4:
Packit 08bd4c
				if (memcmp(s, "user", 4) == 0)
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_USER;
Packit 08bd4c
				break;
Packit 08bd4c
			case 5:
Packit 08bd4c
				if (memcmp(s, "group", 5) == 0)
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_GROUP;
Packit 08bd4c
				break;
Packit 08bd4c
			case 6:
Packit 08bd4c
				if (memcmp(s, "owner@", 6) == 0)
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_USER_OBJ;
Packit 08bd4c
				else if (memcmp(s, "group@", 6) == 0)
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_GROUP_OBJ;
Packit 08bd4c
				break;
Packit 08bd4c
			case 9:
Packit 08bd4c
				if (memcmp(s, "everyone@", 9) == 0)
Packit 08bd4c
					tag = ARCHIVE_ENTRY_ACL_EVERYONE;
Packit 08bd4c
				break;
Packit 08bd4c
			default:
Packit 08bd4c
				break;
Packit 08bd4c
			}
Packit 08bd4c
Packit 08bd4c
			if (tag == 0) {
Packit 08bd4c
				/* Invalid tag, skip entry */
Packit 08bd4c
				ret = ARCHIVE_WARN;
Packit 08bd4c
				continue;
Packit 08bd4c
			} else if (tag == ARCHIVE_ENTRY_ACL_USER ||
Packit 08bd4c
			    tag == ARCHIVE_ENTRY_ACL_GROUP) {
Packit 08bd4c
				n = 1;
Packit 08bd4c
				name = field[1];
Packit 08bd4c
				isint(name.start, name.end, &id;;
Packit 08bd4c
			} else
Packit 08bd4c
				n = 0;
Packit 08bd4c
Packit 08bd4c
			if (!is_nfs4_perms(field[1 + n].start,
Packit 08bd4c
			    field[1 + n].end, &permset)) {
Packit 08bd4c
				/* Invalid NFSv4 perms, skip entry */
Packit 08bd4c
				ret = ARCHIVE_WARN;
Packit 08bd4c
				continue;
Packit 08bd4c
			}
Packit 08bd4c
			if (!is_nfs4_flags(field[2 + n].start,
Packit 08bd4c
			    field[2 + n].end, &permset)) {
Packit 08bd4c
				/* Invalid NFSv4 flags, skip entry */
Packit 08bd4c
				ret = ARCHIVE_WARN;
Packit 08bd4c
				continue;
Packit 08bd4c
			}
Packit 08bd4c
			s = field[3 + n].start;
Packit 08bd4c
			len = field[3 + n].end - field[3 + n].start;
Packit 08bd4c
			type = 0;
Packit 08bd4c
			if (len == 4) {
Packit 08bd4c
				if (memcmp(s, "deny", 4) == 0)
Packit 08bd4c
					type = ARCHIVE_ENTRY_ACL_TYPE_DENY;
Packit 08bd4c
			} else if (len == 5) {
Packit 08bd4c
				if (memcmp(s, "allow", 5) == 0)
Packit 08bd4c
					type = ARCHIVE_ENTRY_ACL_TYPE_ALLOW;
Packit 08bd4c
				else if (memcmp(s, "audit", 5) == 0)
Packit 08bd4c
					type = ARCHIVE_ENTRY_ACL_TYPE_AUDIT;
Packit 08bd4c
				else if (memcmp(s, "alarm", 5) == 0)
Packit 08bd4c
					type = ARCHIVE_ENTRY_ACL_TYPE_ALARM;
Packit 08bd4c
			}
Packit 08bd4c
			if (type == 0) {
Packit 08bd4c
				/* Invalid entry type, skip entry */
Packit 08bd4c
				ret = ARCHIVE_WARN;
Packit 08bd4c
				continue;
Packit 08bd4c
			}
Packit 08bd4c
			isint(field[4 + n].start, field[4 + n].end,
Packit 08bd4c
			    &id;;
Packit 08bd4c
		}
Packit 08bd4c
Packit 08bd4c
		/* Add entry to the internal list. */
Packit 08bd4c
		r = archive_acl_add_entry_len_l(acl, type, permset,
Packit 08bd4c
		    tag, id, name.start, name.end - name.start, sc);
Packit 08bd4c
		if (r < ARCHIVE_WARN)
Packit 08bd4c
			return (r);
Packit 08bd4c
		if (r != ARCHIVE_OK)
Packit 08bd4c
			ret = ARCHIVE_WARN;
Packit 08bd4c
		types |= type;
Packit 08bd4c
	}
Packit 08bd4c
Packit 08bd4c
	/* Reset ACL */
Packit 08bd4c
	archive_acl_reset(acl, types);
Packit 08bd4c
Packit 08bd4c
	return (ret);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Parse a string to a positive decimal integer.  Returns true if
Packit 08bd4c
 * the string is non-empty and consists only of decimal digits,
Packit 08bd4c
 * false otherwise.
Packit 08bd4c
 */
Packit 08bd4c
static int
Packit 08bd4c
isint(const char *start, const char *end, int *result)
Packit 08bd4c
{
Packit 08bd4c
	int n = 0;
Packit 08bd4c
	if (start >= end)
Packit 08bd4c
		return (0);
Packit 08bd4c
	while (start < end) {
Packit 08bd4c
		if (*start < '0' || *start > '9')
Packit 08bd4c
			return (0);
Packit 08bd4c
		if (n > (INT_MAX / 10) ||
Packit 08bd4c
		    (n == INT_MAX / 10 && (*start - '0') > INT_MAX % 10)) {
Packit 08bd4c
			n = INT_MAX;
Packit 08bd4c
		} else {
Packit 08bd4c
			n *= 10;
Packit 08bd4c
			n += *start - '0';
Packit 08bd4c
		}
Packit 08bd4c
		start++;
Packit 08bd4c
	}
Packit 08bd4c
	*result = n;
Packit 08bd4c
	return (1);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Parse a string as a mode field.  Returns true if
Packit 08bd4c
 * the string is non-empty and consists only of mode characters,
Packit 08bd4c
 * false otherwise.
Packit 08bd4c
 */
Packit 08bd4c
static int
Packit 08bd4c
ismode(const char *start, const char *end, int *permset)
Packit 08bd4c
{
Packit 08bd4c
	const char *p;
Packit 08bd4c
Packit 08bd4c
	if (start >= end)
Packit 08bd4c
		return (0);
Packit 08bd4c
	p = start;
Packit 08bd4c
	*permset = 0;
Packit 08bd4c
	while (p < end) {
Packit 08bd4c
		switch (*p++) {
Packit 08bd4c
		case 'r': case 'R':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_READ;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'w': case 'W':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_WRITE;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'x': case 'X':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_EXECUTE;
Packit 08bd4c
			break;
Packit 08bd4c
		case '-':
Packit 08bd4c
			break;
Packit 08bd4c
		default:
Packit 08bd4c
			return (0);
Packit 08bd4c
		}
Packit 08bd4c
	}
Packit 08bd4c
	return (1);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Parse a string as a NFS4 ACL permission field.
Packit 08bd4c
 * Returns true if the string is non-empty and consists only of NFS4 ACL
Packit 08bd4c
 * permission characters, false otherwise
Packit 08bd4c
 */
Packit 08bd4c
static int
Packit 08bd4c
is_nfs4_perms(const char *start, const char *end, int *permset)
Packit 08bd4c
{
Packit 08bd4c
	const char *p = start;
Packit 08bd4c
Packit 08bd4c
	while (p < end) {
Packit 08bd4c
		switch (*p++) {
Packit 08bd4c
		case 'r':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_READ_DATA;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'w':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_WRITE_DATA;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'x':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_EXECUTE;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'p':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_APPEND_DATA;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'D':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_DELETE_CHILD;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'd':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_DELETE;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'a':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_READ_ATTRIBUTES;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'A':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_WRITE_ATTRIBUTES;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'R':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_READ_NAMED_ATTRS;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'W':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_WRITE_NAMED_ATTRS;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'c':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_READ_ACL;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'C':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_WRITE_ACL;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'o':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_WRITE_OWNER;
Packit 08bd4c
			break;
Packit 08bd4c
		case 's':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_SYNCHRONIZE;
Packit 08bd4c
			break;
Packit 08bd4c
		case '-':
Packit 08bd4c
			break;
Packit 08bd4c
		default:
Packit 08bd4c
			return(0);
Packit 08bd4c
		}
Packit 08bd4c
	}
Packit 08bd4c
	return (1);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Parse a string as a NFS4 ACL flags field.
Packit 08bd4c
 * Returns true if the string is non-empty and consists only of NFS4 ACL
Packit 08bd4c
 * flag characters, false otherwise
Packit 08bd4c
 */
Packit 08bd4c
static int
Packit 08bd4c
is_nfs4_flags(const char *start, const char *end, int *permset)
Packit 08bd4c
{
Packit 08bd4c
	const char *p = start;
Packit 08bd4c
Packit 08bd4c
	while (p < end) {
Packit 08bd4c
		switch(*p++) {
Packit 08bd4c
		case 'f':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_ENTRY_FILE_INHERIT;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'd':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_ENTRY_DIRECTORY_INHERIT;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'i':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_ENTRY_INHERIT_ONLY;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'n':
Packit 08bd4c
			*permset |=
Packit 08bd4c
			    ARCHIVE_ENTRY_ACL_ENTRY_NO_PROPAGATE_INHERIT;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'S':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_ENTRY_SUCCESSFUL_ACCESS;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'F':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_ENTRY_FAILED_ACCESS;
Packit 08bd4c
			break;
Packit 08bd4c
		case 'I':
Packit 08bd4c
			*permset |= ARCHIVE_ENTRY_ACL_ENTRY_INHERITED;
Packit 08bd4c
			break;
Packit 08bd4c
		case '-':
Packit 08bd4c
			break;
Packit 08bd4c
		default:
Packit 08bd4c
			return (0);
Packit 08bd4c
		}
Packit 08bd4c
	}
Packit 08bd4c
	return (1);
Packit 08bd4c
}
Packit 08bd4c
Packit 08bd4c
/*
Packit 08bd4c
 * Match "[:whitespace:]*(.*)[:whitespace:]*[:,\n]".  *wp is updated
Packit 08bd4c
 * to point to just after the separator.  *start points to the first
Packit 08bd4c
 * character of the matched text and *end just after the last
Packit 08bd4c
 * character of the matched identifier.  In particular *end - *start
Packit 08bd4c
 * is the length of the field body, not including leading or trailing
Packit 08bd4c
 * whitespace.
Packit 08bd4c
 */
Packit 08bd4c
static void
Packit 08bd4c
next_field(const char **p, const char **start,
Packit 08bd4c
    const char **end, char *sep)
Packit 08bd4c
{
Packit 08bd4c
	/* Skip leading whitespace to find start of field. */
Packit 08bd4c
	while (**p == ' ' || **p == '\t' || **p == '\n') {
Packit 08bd4c
		(*p)++;
Packit 08bd4c
	}
Packit 08bd4c
	*start = *p;
Packit 08bd4c
Packit 08bd4c
	/* Scan for the separator. */
Packit 08bd4c
	while (**p != '\0' && **p != ',' && **p != ':' && **p != '\n') {
Packit 08bd4c
		(*p)++;
Packit 08bd4c
	}
Packit 08bd4c
	*sep = **p;
Packit 08bd4c
Packit 08bd4c
	/* Trim trailing whitespace to locate end of field. */
Packit 08bd4c
	*end = *p - 1;
Packit 08bd4c
	while (**end == ' ' || **end == '\t' || **end == '\n') {
Packit 08bd4c
		(*end)--;
Packit 08bd4c
	}
Packit 08bd4c
	(*end)++;
Packit 08bd4c
Packit 08bd4c
	/* Adjust scanner location. */
Packit 08bd4c
	if (**p != '\0')
Packit 08bd4c
		(*p)++;
Packit 08bd4c
}