]>
git.ipfire.org Git - thirdparty/systemd.git/blob - src/basic/user-util.h
1 /* SPDX-License-Identifier: LGPL-2.1+ */
12 #include <sys/types.h>
15 bool uid_is_valid ( uid_t uid
);
17 static inline bool gid_is_valid ( gid_t gid
) {
18 return uid_is_valid (( uid_t
) gid
);
21 int parse_uid ( const char * s
, uid_t
* ret_uid
);
22 int parse_uid_range ( const char * s
, uid_t
* ret_lower
, uid_t
* ret_upper
);
24 static inline int parse_gid ( const char * s
, gid_t
* ret_gid
) {
25 return parse_uid ( s
, ( uid_t
*) ret_gid
);
28 char * getlogname_malloc ( void );
29 char * getusername_malloc ( void );
31 typedef enum UserCredsFlags
{
32 USER_CREDS_PREFER_NSS
= 1 << 0 , /* if set, only synthesize user records if database lacks them. Normally we bypass the userdb entirely for the records we can synthesize */
33 USER_CREDS_ALLOW_MISSING
= 1 << 1 , /* if a numeric UID string is resolved, be OK if there's no record for it */
34 USER_CREDS_CLEAN
= 1 << 2 , /* try to clean up shell and home fields with invalid data */
37 int get_user_creds ( const char ** username
, uid_t
* uid
, gid_t
* gid
, const char ** home
, const char ** shell
, UserCredsFlags flags
);
38 int get_group_creds ( const char ** groupname
, gid_t
* gid
, UserCredsFlags flags
);
40 char * uid_to_name ( uid_t uid
);
41 char * gid_to_name ( gid_t gid
);
43 int in_gid ( gid_t gid
);
44 int in_group ( const char * name
);
46 int merge_gid_lists ( const gid_t
* list1
, size_t size1
, const gid_t
* list2
, size_t size2
, gid_t
** result
);
47 int getgroups_alloc ( gid_t
** gids
);
49 int get_home_dir ( char ** ret
);
50 int get_shell ( char ** _ret
);
52 int reset_uid_gid ( void );
54 int take_etc_passwd_lock ( const char * root
);
56 #define UID_INVALID ((uid_t) -1)
57 #define GID_INVALID ((gid_t) -1)
59 #define UID_NOBODY ((uid_t) 65534U)
60 #define GID_NOBODY ((gid_t) 65534U)
62 #define ETC_PASSWD_LOCK_PATH "/etc/.pwd.lock"
64 static inline bool uid_is_system ( uid_t uid
) {
65 return uid
<= SYSTEM_UID_MAX
;
68 static inline bool gid_is_system ( gid_t gid
) {
69 return gid
<= SYSTEM_GID_MAX
;
72 static inline bool uid_is_dynamic ( uid_t uid
) {
73 return DYNAMIC_UID_MIN
<= uid
&& uid
<= DYNAMIC_UID_MAX
;
76 static inline bool gid_is_dynamic ( gid_t gid
) {
77 return uid_is_dynamic (( uid_t
) gid
);
80 static inline bool uid_is_container ( uid_t uid
) {
81 return CONTAINER_UID_BASE_MIN
<= uid
&& uid
<= CONTAINER_UID_BASE_MAX
;
84 static inline bool gid_is_container ( gid_t gid
) {
85 return uid_is_container (( uid_t
) gid
);
88 /* The following macros add 1 when converting things, since UID 0 is a valid UID, while the pointer
90 #define PTR_TO_UID(p) ((uid_t) (((uintptr_t) (p))-1))
91 #define UID_TO_PTR(u) ((void*) (((uintptr_t) (u))+1))
93 #define PTR_TO_GID(p) ((gid_t) (((uintptr_t) (p))-1))
94 #define GID_TO_PTR(u) ((void*) (((uintptr_t) (u))+1))
96 static inline bool userns_supported ( void ) {
97 return access ( "/proc/self/uid_map" , F_OK
) >= 0 ;
100 typedef enum ValidUserFlags
{
101 VALID_USER_RELAX
= 1 << 0 ,
102 VALID_USER_WARN
= 1 << 1 ,
103 VALID_USER_ALLOW_NUMERIC
= 1 << 2 ,
106 bool valid_user_group_name ( const char * u
, ValidUserFlags flags
);
107 bool valid_gecos ( const char * d
);
108 char * mangle_gecos ( const char * d
);
109 bool valid_home ( const char * p
);
111 static inline bool valid_shell ( const char * p
) {
112 /* We have the same requirements, so just piggy-back on the home check.
114 * Let's ignore /etc/shells because this is only applicable to real and
115 * not system users. It is also incompatible with the idea of empty /etc.
117 return valid_home ( p
);
120 int maybe_setgroups ( size_t size
, const gid_t
* list
);
122 bool synthesize_nobody ( void );
124 int fgetpwent_sane ( FILE * stream
, struct passwd
** pw
);
125 int fgetspent_sane ( FILE * stream
, struct spwd
** sp
);
126 int fgetgrent_sane ( FILE * stream
, struct group
** gr
);
127 int putpwent_sane ( const struct passwd
* pw
, FILE * stream
);
128 int putspent_sane ( const struct spwd
* sp
, FILE * stream
);
129 int putgrent_sane ( const struct group
* gr
, FILE * stream
);
131 int fgetsgent_sane ( FILE * stream
, struct sgrp
** sg
);
132 int putsgent_sane ( const struct sgrp
* sg
, FILE * stream
);
135 bool is_nologin_shell ( const char * shell
);