]> git.ipfire.org Git - thirdparty/glibc.git/blob - nis/nss_nis/nis-initgroups.c
Move non-deprecated RPC-related functions from sunrpc to inet
[thirdparty/glibc.git] / nis / nss_nis / nis-initgroups.c
1 /* Copyright (C) 1998-2020 Free Software Foundation, Inc.
2 This file is part of the GNU C Library.
3 Contributed by Thorsten Kukuk <kukuk@suse.de>, 1998.
4
5 The GNU C Library is free software; you can redistribute it and/or
6 modify it under the terms of the GNU Lesser General Public
7 License as published by the Free Software Foundation; either
8 version 2.1 of the License, or (at your option) any later version.
9
10 The GNU C Library is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
13 Lesser General Public License for more details.
14
15 You should have received a copy of the GNU Lesser General Public
16 License along with the GNU C Library; if not, see
17 <https://www.gnu.org/licenses/>. */
18
19 #include <ctype.h>
20 #include <errno.h>
21 #include <grp.h>
22 #include <nss.h>
23 #include <pwd.h>
24 #include <string.h>
25 #include <unistd.h>
26 #include <rpcsvc/yp.h>
27 #include <rpcsvc/ypclnt.h>
28 #include <sys/param.h>
29 #include <scratch_buffer.h>
30
31 #include "nss-nis.h"
32 #include <libnsl.h>
33
34 /* Get the declaration of the parser function. */
35 #define ENTNAME grent
36 #define STRUCTURE group
37 #define EXTERN_PARSER
38 #include <nss/nss_files/files-parse.c>
39
40
41 static enum nss_status
42 internal_setgrent (char *domainname, intern_t *intern)
43 {
44 struct ypall_callback ypcb;
45 enum nss_status status;
46
47 ypcb.foreach = _nis_saveit;
48 ypcb.data = (char *) intern;
49 status = yperr2nss (yp_all (domainname, "group.byname", &ypcb));
50
51 /* Mark the last buffer as full. */
52 if (intern->next != NULL)
53 intern->next->size = intern->offset;
54
55 intern->next = intern->start;
56 intern->offset = 0;
57
58 return status;
59 }
60
61
62 static enum nss_status
63 internal_getgrent_r (struct group *grp, char *buffer, size_t buflen,
64 int *errnop, intern_t *intern)
65 {
66 if (intern->start == NULL)
67 return NSS_STATUS_NOTFOUND;
68
69 /* Get the next entry until we found a correct one. */
70 int parse_res;
71 do
72 {
73 struct response_t *bucket = intern->next;
74
75 if (__glibc_unlikely (intern->offset >= bucket->size))
76 {
77 if (bucket->next == NULL)
78 return NSS_STATUS_NOTFOUND;
79
80 /* We look at all the content in the current bucket. Go on
81 to the next. */
82 bucket = intern->next = bucket->next;
83 intern->offset = 0;
84 }
85
86 char *p;
87 for (p = &bucket->mem[intern->offset]; isspace (*p); ++p)
88 ++intern->offset;
89
90 size_t len = strlen (p) + 1;
91 if (__glibc_unlikely (len > buflen))
92 {
93 *errnop = ERANGE;
94 return NSS_STATUS_TRYAGAIN;
95 }
96
97 /* We unfortunately have to copy the data in the user-provided
98 buffer because that buffer might be around for a very long
99 time and the servent structure must remain valid. If we would
100 rely on the BUCKET memory the next 'setservent' or 'endservent'
101 call would destroy it.
102
103 The important thing is that it is a single NUL-terminated
104 string. This is what the parsing routine expects. */
105 p = memcpy (buffer, &bucket->mem[intern->offset], len);
106
107 parse_res = _nss_files_parse_grent (p, grp, (void *) buffer, buflen,
108 errnop);
109 if (__glibc_unlikely (parse_res == -1))
110 return NSS_STATUS_TRYAGAIN;
111
112 intern->offset += len;
113 }
114 while (!parse_res);
115
116 return NSS_STATUS_SUCCESS;
117 }
118
119
120 static int
121 get_uid (const char *user, uid_t *uidp)
122 {
123 struct scratch_buffer tmpbuf;
124 scratch_buffer_init (&tmpbuf);
125
126 while (1)
127 {
128 struct passwd result;
129 struct passwd *resp;
130
131 int r = getpwnam_r (user, &result, tmpbuf.data, tmpbuf.length, &resp);
132 if (r == 0 && resp != NULL)
133 {
134 *uidp = resp->pw_uid;
135 scratch_buffer_free (&tmpbuf);
136 return 0;
137 }
138
139 if (r != ERANGE)
140 break;
141
142 if (!scratch_buffer_grow (&tmpbuf))
143 return 1;
144 }
145
146 scratch_buffer_free (&tmpbuf);
147 return 1;
148 }
149
150
151 static enum nss_status
152 initgroups_netid (uid_t uid, gid_t group, long int *start, long int *size,
153 gid_t **groupsp, long int limit, int *errnop,
154 const char *domainname)
155 {
156 /* Limit domainname length to the maximum size of an RPC packet. */
157 if (strlen (domainname) > UDPMSGSIZE)
158 {
159 *errnop = ERANGE;
160 return NSS_STATUS_UNAVAIL;
161 }
162
163 /* Prepare the key. The form is "unix.UID@DOMAIN" with the UID and
164 DOMAIN field filled in appropriately. */
165 char key[sizeof ("unix.@") + sizeof (uid_t) * 3 + strlen (domainname)];
166 ssize_t keylen = snprintf (key, sizeof (key), "unix.%lu@%s",
167 (unsigned long int) uid, domainname);
168
169 char *result;
170 int reslen;
171 int yperr = yp_match (domainname, "netid.byname", key, keylen, &result,
172 &reslen);
173 if (__glibc_unlikely (yperr != YPERR_SUCCESS))
174 return yperr2nss (yperr);
175
176 /* Parse the result: following the colon is a comma separated list of
177 group IDs. */
178 char *cp = strchr (result, ':');
179 if (cp == NULL)
180 {
181 errout:
182 free (result);
183 return NSS_STATUS_NOTFOUND;
184 }
185 /* Skip the colon. */
186 ++cp;
187
188 gid_t *groups = *groupsp;
189 while (*cp != '\0')
190 {
191 char *endp;
192 unsigned long int gid = strtoul (cp, &endp, 0);
193 if (cp == endp)
194 goto errout;
195 if (*endp == ',')
196 ++endp;
197 else if (*endp != '\0')
198 goto errout;
199 cp = endp;
200
201 if (gid == group)
202 /* We do not need this group again. */
203 continue;
204
205 /* Insert this group. */
206 if (*start == *size)
207 {
208 /* Need a bigger buffer. */
209 long int newsize;
210
211 if (limit > 0 && *size == limit)
212 /* We reached the maximum. */
213 break;
214
215 if (limit <= 0)
216 newsize = 2 * *size;
217 else
218 newsize = MIN (limit, 2 * *size);
219
220 gid_t *newgroups = realloc (groups, newsize * sizeof (*groups));
221 if (newgroups == NULL)
222 goto errout;
223 *groupsp = groups = newgroups;
224 *size = newsize;
225 }
226
227 groups[*start] = gid;
228 *start += 1;
229 }
230
231 free (result);
232
233 return NSS_STATUS_SUCCESS;
234 }
235
236
237 enum nss_status
238 _nss_nis_initgroups_dyn (const char *user, gid_t group, long int *start,
239 long int *size, gid_t **groupsp, long int limit,
240 int *errnop)
241 {
242 /* We always need the domain name. */
243 char *domainname;
244 if (yp_get_default_domain (&domainname))
245 return NSS_STATUS_UNAVAIL;
246
247 /* Check whether we are supposed to use the netid.byname map. */
248 if (_nsl_default_nss () & NSS_FLAG_NETID_AUTHORITATIVE)
249 {
250 /* We need the user ID. */
251 uid_t uid;
252
253 if (get_uid (user, &uid) == 0
254 && initgroups_netid (uid, group, start, size, groupsp, limit,
255 errnop, domainname) == NSS_STATUS_SUCCESS)
256 return NSS_STATUS_SUCCESS;
257 }
258
259 struct group grpbuf, *g;
260 enum nss_status status;
261 intern_t intern = { NULL, NULL, 0 };
262 gid_t *groups = *groupsp;
263
264 status = internal_setgrent (domainname, &intern);
265 if (status != NSS_STATUS_SUCCESS)
266 return status;
267
268 struct scratch_buffer tmpbuf;
269 scratch_buffer_init (&tmpbuf);
270
271 while (1)
272 {
273 while ((status =
274 internal_getgrent_r (&grpbuf, tmpbuf.data, tmpbuf.length, errnop,
275 &intern)) == NSS_STATUS_TRYAGAIN
276 && *errnop == ERANGE)
277 if (!scratch_buffer_grow (&tmpbuf))
278 {
279 status = NSS_STATUS_TRYAGAIN;
280 goto done;
281 }
282
283 if (status != NSS_STATUS_SUCCESS)
284 {
285 if (status == NSS_STATUS_NOTFOUND)
286 status = NSS_STATUS_SUCCESS;
287 goto done;
288 }
289
290 g = &grpbuf;
291 if (g->gr_gid != group)
292 {
293 char **m;
294
295 for (m = g->gr_mem; *m != NULL; ++m)
296 if (strcmp (*m, user) == 0)
297 {
298 /* Matches user. Insert this group. */
299 if (*start == *size)
300 {
301 /* Need a bigger buffer. */
302 gid_t *newgroups;
303 long int newsize;
304
305 if (limit > 0 && *size == limit)
306 /* We reached the maximum. */
307 goto done;
308
309 if (limit <= 0)
310 newsize = 2 * *size;
311 else
312 newsize = MIN (limit, 2 * *size);
313
314 newgroups = realloc (groups, newsize * sizeof (*groups));
315 if (newgroups == NULL)
316 {
317 status = NSS_STATUS_TRYAGAIN;
318 *errnop = errno;
319 goto done;
320 }
321 *groupsp = groups = newgroups;
322 *size = newsize;
323 }
324
325 groups[*start] = g->gr_gid;
326 *start += 1;
327
328 break;
329 }
330 }
331 }
332
333 done:
334 while (intern.start != NULL)
335 {
336 intern.next = intern.start;
337 intern.start = intern.start->next;
338 free (intern.next);
339 }
340 scratch_buffer_free (&tmpbuf);
341
342 return status;
343 }