1 /* $OpenBSD: getgrouplist.c,v 1.31 2024/11/04 21:49:26 jca Exp $ */
2 /*
3 * Copyright (c) 2008 Ingo Schwarze <schwarze@usta.de>
4 * Copyright (c) 1991, 1993
5 * The Regents of the University of California. All rights reserved.
6 *
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted provided that the following conditions
9 * are met:
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
15 * 3. Neither the name of the University nor the names of its contributors
16 * may be used to endorse or promote products derived from this software
17 * without specific prior written permission.
18 *
19 * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
20 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
21 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
22 * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
23 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
24 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
25 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
26 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
27 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
28 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29 * SUCH DAMAGE.
30 */
31
32 /*
33 * get credential
34 */
35 #include <sys/types.h>
36 #include <sys/limits.h>
37 #include <string.h>
38 #include <unistd.h>
39 #include <stdio.h>
40 #include <stdlib.h>
41 #include <grp.h>
42 #include <pwd.h>
43 #include <errno.h>
44
45 #include <rpc/rpc.h>
46 #include <rpcsvc/yp.h>
47 #include <rpcsvc/ypclnt.h>
48
49 #ifdef YP
50 #define _PATH_NETID "/etc/netid"
51 #define MAXLINELENGTH 1024
52
53 static int _parse_netid(char*, uid_t, gid_t*, int*, int);
54 static int _read_netid(const char *, uid_t, gid_t*, int*, int);
55
56 /*
57 * Parse one string of the form "uid:gid[,gid[,...]]".
58 * If the uid matches, add the groups to the group list and return 1.
59 * If the uid does not match, return 0.
60 */
61 static int
_parse_netid(char * netid,uid_t uid,gid_t * groups,int * ngroups,int maxgroups)62 _parse_netid(char *netid, uid_t uid, gid_t *groups, int *ngroups,
63 int maxgroups)
64 {
65 const char *errstr = NULL;
66 char *start, *p;
67 uid_t tuid;
68 gid_t gid;
69 int i;
70
71 /* Check the uid. */
72 p = strchr(netid, ':');
73 if (!p)
74 return (0);
75 *p++ = '\0';
76 tuid = (uid_t)strtonum(netid, 0, UID_MAX, &errstr);
77 if (errstr || tuid != uid)
78 return (0);
79
80 /* Loop over the gids. */
81 while (p && *p) {
82 start = p;
83 p = strchr(start, ',');
84 if (p)
85 *p++ = '\0';
86 gid = (gid_t)strtonum(start, 0, GID_MAX, &errstr);
87 if (errstr)
88 continue;
89
90 /* Skip this group if it is already in the list. */
91 for (i = 0; i < maxgroups && i < *ngroups; i++)
92 if (groups[i] == gid)
93 break;
94
95 /* Try to add this new group to the list. */
96 if (i == *ngroups) {
97 if (*ngroups >= maxgroups)
98 (*ngroups)++;
99 else
100 groups[(*ngroups)++] = gid;
101 }
102 }
103 return (1);
104 }
105
106 /*
107 * Search /etc/netid for a particular uid and process that line.
108 * See _parse_netid for details, including return values.
109 */
110 static int
_read_netid(const char * key,uid_t uid,gid_t * groups,int * ngroups,int maxgroups)111 _read_netid(const char *key, uid_t uid, gid_t *groups, int *ngroups,
112 int maxgroups)
113 {
114 FILE *fp;
115 char line[MAXLINELENGTH], *p;
116 int found = 0;
117
118 fp = fopen(_PATH_NETID, "re");
119 if (!fp)
120 return (0);
121 while (!found && fgets(line, sizeof(line), fp)) {
122 p = strchr(line, '\n');
123 if (p)
124 *p = '\0';
125 else { /* Skip lines that are too long. */
126 int ch;
127 while ((ch = getc_unlocked(fp)) != '\n' && ch != EOF)
128 ;
129 continue;
130 }
131 p = strchr(line, ' ');
132 if (!p)
133 continue;
134 *p++ = '\0';
135 if (strcmp(line, key))
136 continue;
137 found = _parse_netid(p, uid, groups, ngroups, maxgroups);
138 }
139 (void)fclose(fp);
140 return (found);
141 }
142 #endif /* YP */
143
144 int
getgrouplist(const char * uname,gid_t agroup,gid_t * groups,int * grpcnt)145 getgrouplist(const char *uname, gid_t agroup, gid_t *groups, int *grpcnt)
146 {
147 int i, ngroups = 0, maxgroups = *grpcnt, bail;
148 int needyp = 0, foundyp = 0;
149 int *skipyp = &foundyp;
150 extern struct group *_getgrent_yp(int *);
151 struct group *grp;
152
153 /*
154 * install primary group
155 */
156 if (ngroups >= maxgroups)
157 ngroups++;
158 else
159 groups[ngroups++] = agroup;
160
161 /*
162 * Scan the group file to find additional groups.
163 */
164 setgrent();
165 while ((grp = _getgrent_yp(skipyp)) || foundyp) {
166 if (foundyp) {
167 if (foundyp > 0)
168 needyp = 1;
169 else
170 skipyp = NULL;
171 foundyp = 0;
172 continue;
173 }
174 if (grp->gr_gid == agroup)
175 continue;
176 for (bail = 0, i = 0; bail == 0 && i < maxgroups &&
177 i < ngroups; i++) {
178 if (groups[i] == grp->gr_gid)
179 bail = 1;
180 }
181 if (bail)
182 continue;
183 for (i = 0; grp->gr_mem[i]; i++) {
184 if (!strcmp(grp->gr_mem[i], uname)) {
185 if (ngroups >= maxgroups)
186 ngroups++;
187 else
188 groups[ngroups++] = grp->gr_gid;
189 break;
190 }
191 }
192 }
193
194 #ifdef YP
195 /*
196 * If we were told that there is a YP marker, look at netid data.
197 */
198 if (skipyp && needyp) {
199 char buf[MAXLINELENGTH], *ypdata = NULL, *key;
200 static char *__ypdomain;
201 struct passwd pwstore;
202 int ypdatalen;
203
204 /* Construct the netid key to look up. */
205 if (getpwnam_r(uname, &pwstore, buf, sizeof buf, NULL) ||
206 (!__ypdomain && yp_get_default_domain(&__ypdomain)))
207 goto out;
208 i = asprintf(&key, "unix.%u@%s", pwstore.pw_uid, __ypdomain);
209 if (i == -1)
210 goto out;
211
212 /* First scan the static netid file. */
213 if (_read_netid(key, pwstore.pw_uid, groups, &ngroups,
214 maxgroups)) {
215 free(key);
216 goto out;
217 }
218
219 /* Only access YP when there is no static entry. */
220 if (!yp_match(__ypdomain, "netid.byname", key,
221 (int)strlen(key), &ypdata, &ypdatalen))
222 _parse_netid(ypdata, pwstore.pw_uid, groups, &ngroups,
223 maxgroups);
224
225 free(key);
226 free(ypdata);
227 }
228 #endif /* YP */
229
230 out:
231 endgrent();
232 *grpcnt = ngroups;
233 return (ngroups > maxgroups ? -1 : 0);
234 }
235 DEF_WEAK(getgrouplist);
236