2 * Copyright (c) 2003 Networks Associates Technology, Inc.
5 * This software was developed for the FreeBSD Project by
6 * Jacques A. Vidrine, Safeport Network Services, and Network
7 * Associates Laboratories, the Security Research Division of Network
8 * Associates, Inc. under DARPA/SPAWAR contract N66001-01-C-8035
9 * ("CBOSS"), as part of the DARPA CHATS research program.
11 * Redistribution and use in source and binary forms, with or without
12 * modification, are permitted provided that the following conditions
14 * 1. Redistributions of source code must retain the above copyright
15 * notice, this list of conditions and the following disclaimer.
16 * 2. Redistributions in binary form must reproduce the above copyright
17 * notice, this list of conditions and the following disclaimer in the
18 * documentation and/or other materials provided with the distribution.
20 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
21 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
22 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
23 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
24 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
25 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
26 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
27 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
28 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
29 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33 #include <sys/cdefs.h>
34 __FBSDID("$FreeBSD$");
36 #include "namespace.h"
37 #include <sys/param.h>
40 #include <rpcsvc/yp_prot.h>
41 #include <rpcsvc/ypclnt.h>
51 #include <pthread_np.h>
57 #include "un-namespace.h"
58 #include "libc_private.h"
63 GRP_STORAGE_INITIAL = 1 << 10, /* 1 KByte */
64 GRP_STORAGE_MAX = 1 << 20, /* 1 MByte */
67 HESIOD_NAME_MAX = 256,
70 static const ns_src defaultsrc[] = {
71 { NSSRC_COMPAT, NS_SUCCESS },
75 int __gr_match_entry(const char *, size_t, enum nss_lookup_type,
77 int __gr_parse_entry(char *, size_t, struct group *, char *, size_t,
80 static int is_comment_line(const char *, size_t);
86 static struct group *getgr(int (*)(union key, struct group *, char *, size_t,
87 struct group **), union key);
88 static int wrap_getgrnam_r(union key, struct group *, char *, size_t,
90 static int wrap_getgrgid_r(union key, struct group *, char *, size_t,
92 static int wrap_getgrent_r(union key, struct group *, char *, size_t,
99 static void files_endstate(void *);
100 NSS_TLS_HANDLING(files);
101 static int files_setgrent(void *, void *, va_list);
102 static int files_group(void *, void *, va_list);
109 static void dns_endstate(void *);
110 NSS_TLS_HANDLING(dns);
111 static int dns_setgrent(void *, void *, va_list);
112 static int dns_group(void *, void *, va_list);
118 char domain[MAXHOSTNAMELEN];
123 static void nis_endstate(void *);
124 NSS_TLS_HANDLING(nis);
125 static int nis_setgrent(void *, void *, va_list);
126 static int nis_group(void *, void *, va_list);
129 struct compat_state {
139 static void compat_endstate(void *);
140 NSS_TLS_HANDLING(compat);
141 static int compat_setgrent(void *, void *, va_list);
142 static int compat_group(void *, void *, va_list);
145 /* XXX IEEE Std 1003.1, 2003 specifies `void setgrent(void)' */
149 static const ns_dtab dtab[] = {
150 { NSSRC_FILES, files_setgrent, (void *)SETGRENT },
152 { NSSRC_DNS, dns_setgrent, (void *)SETGRENT },
155 { NSSRC_NIS, nis_setgrent, (void *)SETGRENT },
157 { NSSRC_COMPAT, compat_setgrent, (void *)SETGRENT },
160 (void)_nsdispatch(NULL, dtab, NSDB_GROUP, "setgrent", defaultsrc, 0);
166 setgroupent(int stayopen)
168 static const ns_dtab dtab[] = {
169 { NSSRC_FILES, files_setgrent, (void *)SETGRENT },
171 { NSSRC_DNS, dns_setgrent, (void *)SETGRENT },
174 { NSSRC_NIS, nis_setgrent, (void *)SETGRENT },
176 { NSSRC_COMPAT, compat_setgrent, (void *)SETGRENT },
179 (void)_nsdispatch(NULL, dtab, NSDB_GROUP, "setgrent", defaultsrc,
188 static const ns_dtab dtab[] = {
189 { NSSRC_FILES, files_setgrent, (void *)ENDGRENT },
191 { NSSRC_DNS, dns_setgrent, (void *)ENDGRENT },
194 { NSSRC_NIS, nis_setgrent, (void *)ENDGRENT },
196 { NSSRC_COMPAT, compat_setgrent, (void *)ENDGRENT },
199 (void)_nsdispatch(NULL, dtab, NSDB_GROUP, "endgrent", defaultsrc);
204 getgrent_r(struct group *grp, char *buffer, size_t bufsize,
205 struct group **result)
207 static const ns_dtab dtab[] = {
208 { NSSRC_FILES, files_group, (void *)nss_lt_all },
210 { NSSRC_DNS, dns_group, (void *)nss_lt_all },
213 { NSSRC_NIS, nis_group, (void *)nss_lt_all },
215 { NSSRC_COMPAT, compat_group, (void *)nss_lt_all },
222 rv = _nsdispatch(result, dtab, NSDB_GROUP, "getgrent_r", defaultsrc,
223 grp, buffer, bufsize, &ret_errno);
224 if (rv == NS_SUCCESS)
232 getgrnam_r(const char *name, struct group *grp, char *buffer, size_t bufsize,
233 struct group **result)
235 static const ns_dtab dtab[] = {
236 { NSSRC_FILES, files_group, (void *)nss_lt_name },
238 { NSSRC_DNS, dns_group, (void *)nss_lt_name },
241 { NSSRC_NIS, nis_group, (void *)nss_lt_name },
243 { NSSRC_COMPAT, compat_group, (void *)nss_lt_name },
250 rv = _nsdispatch(result, dtab, NSDB_GROUP, "getgrnam_r", defaultsrc,
251 name, grp, buffer, bufsize, &ret_errno);
252 if (rv == NS_SUCCESS)
260 getgrgid_r(gid_t gid, struct group *grp, char *buffer, size_t bufsize,
261 struct group **result)
263 static const ns_dtab dtab[] = {
264 { NSSRC_FILES, files_group, (void *)nss_lt_id },
266 { NSSRC_DNS, dns_group, (void *)nss_lt_id },
269 { NSSRC_NIS, nis_group, (void *)nss_lt_id },
271 { NSSRC_COMPAT, compat_group, (void *)nss_lt_id },
278 rv = _nsdispatch(result, dtab, NSDB_GROUP, "getgrgid_r", defaultsrc,
279 gid, grp, buffer, bufsize, &ret_errno);
280 if (rv == NS_SUCCESS)
287 static struct group grp;
288 static char *grp_storage;
289 static size_t grp_storage_size;
291 static struct group *
292 getgr(int (*fn)(union key, struct group *, char *, size_t, struct group **),
298 if (grp_storage == NULL) {
299 grp_storage = malloc(GRP_STORAGE_INITIAL);
300 if (grp_storage == NULL)
302 grp_storage_size = GRP_STORAGE_INITIAL;
305 rv = fn(key, &grp, grp_storage, grp_storage_size, &res);
306 if (res == NULL && rv == ERANGE) {
308 if ((grp_storage_size << 1) > GRP_STORAGE_MAX) {
313 grp_storage_size <<= 1;
314 grp_storage = malloc(grp_storage_size);
315 if (grp_storage == NULL)
318 } while (res == NULL && rv == ERANGE);
326 wrap_getgrnam_r(union key key, struct group *grp, char *buffer, size_t bufsize,
329 return (getgrnam_r(key.name, grp, buffer, bufsize, res));
334 wrap_getgrgid_r(union key key, struct group *grp, char *buffer, size_t bufsize,
337 return (getgrgid_r(key.gid, grp, buffer, bufsize, res));
342 wrap_getgrent_r(union key key __unused, struct group *grp, char *buffer,
343 size_t bufsize, struct group **res)
345 return (getgrent_r(grp, buffer, bufsize, res));
350 getgrnam(const char *name)
355 return (getgr(wrap_getgrnam_r, key));
365 return (getgr(wrap_getgrgid_r, key));
374 key.gid = 0; /* not used */
375 return (getgr(wrap_getgrent_r, key));
380 is_comment_line(const char *s, size_t n)
387 if (*s == '#' || !isspace((unsigned char)*s))
389 return (*s == '#' || s == eom);
397 files_endstate(void *p)
402 if (((struct files_state *)p)->fp != NULL)
403 fclose(((struct files_state *)p)->fp);
409 files_setgrent(void *retval, void *mdata, va_list ap)
411 struct files_state *st;
414 rv = files_getstate(&st);
417 switch ((enum constants)mdata) {
419 stayopen = va_arg(ap, int);
423 st->fp = fopen(_PATH_GROUP, "r");
426 if (st->fp != NULL) {
439 files_group(void *retval, void *mdata, va_list ap)
441 struct files_state *st;
442 enum nss_lookup_type how;
443 const char *name, *line;
447 size_t bufsize, linesize;
448 int rv, stayopen, *errnop;
452 how = (enum nss_lookup_type)mdata;
455 name = va_arg(ap, const char *);
458 gid = va_arg(ap, gid_t);
463 return (NS_NOTFOUND);
465 grp = va_arg(ap, struct group *);
466 buffer = va_arg(ap, char *);
467 bufsize = va_arg(ap, size_t);
468 errnop = va_arg(ap, int *);
469 *errnop = files_getstate(&st);
472 if (st->fp == NULL &&
473 ((st->fp = fopen(_PATH_GROUP, "r")) == NULL)) {
477 if (how == nss_lt_all)
481 stayopen = st->stayopen;
484 while ((line = fgetln(st->fp, &linesize)) != NULL) {
485 if (line[linesize-1] == '\n')
487 rv = __gr_match_entry(line, linesize, how, name, gid);
488 if (rv != NS_SUCCESS)
490 /* We need room at least for the line, a string NUL
491 * terminator, alignment padding, and one (char *)
492 * pointer for the member list terminator.
494 if (bufsize <= linesize + _ALIGNBYTES + sizeof(char *)) {
499 memcpy(buffer, line, linesize);
500 buffer[linesize] = '\0';
501 rv = __gr_parse_entry(buffer, linesize, grp,
502 &buffer[linesize + 1], bufsize - linesize - 1, errnop);
503 if (rv & NS_TERMINATE)
506 if (!stayopen && st->fp != NULL) {
510 if (rv == NS_SUCCESS && retval != NULL)
511 *(struct group **)retval = grp;
521 dns_endstate(void *p)
529 dns_setgrent(void *retval, void *cb_data, va_list ap)
531 struct dns_state *st;
534 rv = dns_getstate(&st);
543 dns_group(void *retval, void *mdata, va_list ap)
545 char buf[HESIOD_NAME_MAX];
546 struct dns_state *st;
548 const char *name, *label;
551 size_t bufsize, adjsize, linesize;
553 enum nss_lookup_type how;
560 how = (enum nss_lookup_type)mdata;
563 name = va_arg(ap, const char *);
566 gid = va_arg(ap, gid_t);
571 grp = va_arg(ap, struct group *);
572 buffer = va_arg(ap, char *);
573 bufsize = va_arg(ap, size_t);
574 errnop = va_arg(ap, int *);
575 *errnop = dns_getstate(&st);
578 if (hesiod_init(&ctx) != 0) {
590 if (snprintf(buf, sizeof(buf), "%lu",
591 (unsigned long)gid) >= sizeof(buf))
598 if (snprintf(buf, sizeof(buf), "group-%ld",
599 st->counter++) >= sizeof(buf))
604 hes = hesiod_resolve(ctx, label,
605 how == nss_lt_id ? "gid" : "group");
606 if ((how == nss_lt_id && hes == NULL &&
607 (hes = hesiod_resolve(ctx, buf, "group")) == NULL) ||
609 if (how == nss_lt_all)
615 rv = __gr_match_entry(hes[0], strlen(hes[0]), how, name, gid);
616 if (rv != NS_SUCCESS) {
617 hesiod_free_list(ctx, hes);
621 /* We need room at least for the line, a string NUL
622 * terminator, alignment padding, and one (char *)
623 * pointer for the member list terminator.
625 adjsize = bufsize - _ALIGNBYTES - sizeof(char *);
626 linesize = strlcpy(buffer, hes[0], adjsize);
627 if (linesize >= adjsize) {
632 hesiod_free_list(ctx, hes);
634 rv = __gr_parse_entry(buffer, linesize, grp,
635 &buffer[linesize + 1], bufsize - linesize - 1, errnop);
636 } while (how == nss_lt_all && !(rv & NS_TERMINATE));
639 hesiod_free_list(ctx, hes);
642 if (rv == NS_SUCCESS && retval != NULL)
643 *(struct group **)retval = grp;
654 nis_endstate(void *p)
659 free(((struct nis_state *)p)->key);
665 nis_setgrent(void *retval, void *cb_data, va_list ap)
667 struct nis_state *st;
670 rv = nis_getstate(&st);
681 nis_group(void *retval, void *mdata, va_list ap)
684 struct nis_state *st;
687 char *buffer, *key, *result;
690 enum nss_lookup_type how;
691 int *errnop, keylen, resultlen, rv;
695 how = (enum nss_lookup_type)mdata;
698 name = va_arg(ap, const char *);
699 map = "group.byname";
702 gid = va_arg(ap, gid_t);
706 map = "group.byname";
709 grp = va_arg(ap, struct group *);
710 buffer = va_arg(ap, char *);
711 bufsize = va_arg(ap, size_t);
712 errnop = va_arg(ap, int *);
713 *errnop = nis_getstate(&st);
716 if (st->domain[0] == '\0') {
717 if (getdomainname(st->domain, sizeof(st->domain)) != 0) {
727 if (strlcpy(buffer, name, bufsize) >= bufsize)
731 if (snprintf(buffer, bufsize, "%lu",
732 (unsigned long)gid) >= bufsize)
741 if (how == nss_lt_all) {
743 rv = yp_first(st->domain, map, &st->key,
744 &st->keylen, &result, &resultlen);
749 rv = yp_next(st->domain, map, key, keylen,
750 &st->key, &st->keylen, &result,
758 if (rv == YPERR_NOMORE) {
766 rv = yp_match(st->domain, map, buffer, strlen(buffer),
767 &result, &resultlen);
768 if (rv == YPERR_KEY) {
771 } else if (rv != 0) {
777 /* We need room at least for the line, a string NUL
778 * terminator, alignment padding, and one (char *)
779 * pointer for the member list terminator.
781 if (resultlen >= bufsize - _ALIGNBYTES - sizeof(char *))
783 memcpy(buffer, result, resultlen);
784 buffer[resultlen] = '\0';
786 rv = __gr_match_entry(buffer, resultlen, how, name, gid);
787 if (rv == NS_SUCCESS)
788 rv = __gr_parse_entry(buffer, resultlen, grp,
789 &buffer[resultlen+1], bufsize - resultlen - 1,
791 } while (how == nss_lt_all && !(rv & NS_TERMINATE));
793 if (rv == NS_SUCCESS && retval != NULL)
794 *(struct group **)retval = grp;
808 compat_endstate(void *p)
810 struct compat_state *st;
814 st = (struct compat_state *)p;
823 compat_setgrent(void *retval, void *mdata, va_list ap)
825 static const ns_src compatsrc[] = {
827 { NSSRC_NIS, NS_SUCCESS },
833 { NSSRC_DNS, dns_setgrent, NULL },
836 { NSSRC_NIS, nis_setgrent, NULL },
840 struct compat_state *st;
843 #define set_setent(x, y) do { \
846 for (i = 0; i < (sizeof(x)/sizeof(x[0])) - 1; i++) \
847 x[i].mdata = (void *)y; \
850 rv = compat_getstate(&st);
853 switch ((enum constants)mdata) {
855 stayopen = va_arg(ap, int);
859 st->fp = fopen(_PATH_GROUP, "r");
860 set_setent(dtab, mdata);
861 (void)_nsdispatch(NULL, dtab, NSDB_GROUP_COMPAT, "setgrent",
865 if (st->fp != NULL) {
869 set_setent(dtab, mdata);
870 (void)_nsdispatch(NULL, dtab, NSDB_GROUP_COMPAT, "endgrent",
876 st->compat = COMPAT_MODE_OFF;
885 compat_group(void *retval, void *mdata, va_list ap)
887 static const ns_src compatsrc[] = {
889 { NSSRC_NIS, NS_SUCCESS },
895 { NSSRC_NIS, nis_group, NULL },
898 { NSSRC_DNS, dns_group, NULL },
902 struct compat_state *st;
903 enum nss_lookup_type how;
904 const char *name, *line;
909 size_t bufsize, linesize;
910 int rv, stayopen, *errnop;
912 #define set_lookup_type(x, y) do { \
915 for (i = 0; i < (sizeof(x)/sizeof(x[0])) - 1; i++) \
916 x[i].mdata = (void *)y; \
921 how = (enum nss_lookup_type)mdata;
924 name = va_arg(ap, const char *);
927 gid = va_arg(ap, gid_t);
932 return (NS_NOTFOUND);
934 grp = va_arg(ap, struct group *);
935 buffer = va_arg(ap, char *);
936 bufsize = va_arg(ap, size_t);
937 errnop = va_arg(ap, int *);
938 *errnop = compat_getstate(&st);
941 if (st->fp == NULL &&
942 ((st->fp = fopen(_PATH_GROUP, "r")) == NULL)) {
947 if (how == nss_lt_all)
951 stayopen = st->stayopen;
954 switch (st->compat) {
955 case COMPAT_MODE_ALL:
956 set_lookup_type(dtab, how);
959 rv = _nsdispatch(&discard, dtab, NSDB_GROUP_COMPAT,
960 "getgrent_r", compatsrc, grp, buffer, bufsize,
964 rv = _nsdispatch(&discard, dtab, NSDB_GROUP_COMPAT,
965 "getgrgid_r", compatsrc, gid, grp, buffer, bufsize,
969 rv = _nsdispatch(&discard, dtab, NSDB_GROUP_COMPAT,
970 "getgrnam_r", compatsrc, name, grp, buffer,
974 if (rv & NS_TERMINATE)
976 st->compat = COMPAT_MODE_OFF;
978 case COMPAT_MODE_NAME:
979 set_lookup_type(dtab, nss_lt_name);
980 rv = _nsdispatch(&discard, dtab, NSDB_GROUP_COMPAT,
981 "getgrnam_r", compatsrc, st->name, grp, buffer, bufsize,
987 if (strcmp(name, grp->gr_name) != 0)
991 if (gid != grp->gr_gid)
1005 st->compat = COMPAT_MODE_OFF;
1006 if (rv == NS_SUCCESS)
1013 while ((line = fgetln(st->fp, &linesize)) != NULL) {
1014 if (line[linesize-1] == '\n')
1016 if (linesize > 2 && line[0] == '+') {
1017 p = memchr(&line[1], ':', linesize);
1018 if (p == NULL || p == &line[1])
1019 st->compat = COMPAT_MODE_ALL;
1021 st->name = malloc(p - line);
1022 if (st->name == NULL) {
1024 "getgrent memory allocation failure");
1029 memcpy(st->name, &line[1], p - line - 1);
1030 st->name[p - line - 1] = '\0';
1031 st->compat = COMPAT_MODE_NAME;
1035 rv = __gr_match_entry(line, linesize, how, name, gid);
1036 if (rv != NS_SUCCESS)
1038 /* We need room at least for the line, a string NUL
1039 * terminator, alignment padding, and one (char *)
1040 * pointer for the member list terminator.
1042 if (bufsize <= linesize + _ALIGNBYTES + sizeof(char *)) {
1047 memcpy(buffer, line, linesize);
1048 buffer[linesize] = '\0';
1049 rv = __gr_parse_entry(buffer, linesize, grp,
1050 &buffer[linesize + 1], bufsize - linesize - 1, errnop);
1051 if (rv & NS_TERMINATE)
1055 if (!stayopen && st->fp != NULL) {
1059 if (rv == NS_SUCCESS && retval != NULL)
1060 *(struct group **)retval = grp;
1062 #undef set_lookup_type
1067 * common group line matching and parsing
1070 __gr_match_entry(const char *line, size_t linesize, enum nss_lookup_type how,
1071 const char *name, gid_t gid)
1074 const char *p, *eol;
1079 if (linesize == 0 || is_comment_line(line, linesize))
1080 return (NS_NOTFOUND);
1082 case nss_lt_name: needed = 1; break;
1083 case nss_lt_id: needed = 2; break;
1084 default: needed = 2; break;
1086 eol = &line[linesize];
1087 for (p = line, i = 0; i < needed && p < eol; p++)
1091 return (NS_NOTFOUND);
1094 namesize = strlen(name);
1095 if (namesize + 1 == (size_t)(p - line) &&
1096 memcmp(line, name, namesize) == 0)
1097 return (NS_SUCCESS);
1100 n = strtoul(p, &q, 10);
1101 if (q < eol && *q == ':' && gid == (gid_t)n)
1102 return (NS_SUCCESS);
1105 return (NS_SUCCESS);
1109 return (NS_NOTFOUND);
1114 __gr_parse_entry(char *line, size_t linesize, struct group *grp, char *membuf,
1115 size_t membufsize, int *errnop)
1117 char *s_gid, *s_mem, *p, **members;
1121 memset(grp, 0, sizeof(*grp));
1122 members = (char **)_ALIGN(membuf);
1123 membufsize -= (char *)members - membuf;
1124 maxmembers = membufsize / sizeof(*members);
1125 if (maxmembers <= 0 ||
1126 (grp->gr_name = strsep(&line, ":")) == NULL ||
1127 grp->gr_name[0] == '\0' ||
1128 (grp->gr_passwd = strsep(&line, ":")) == NULL ||
1129 (s_gid = strsep(&line, ":")) == NULL ||
1131 return (NS_NOTFOUND);
1133 n = strtoul(s_gid, &s_gid, 10);
1134 if (s_gid[0] != '\0')
1135 return (NS_NOTFOUND);
1136 grp->gr_gid = (gid_t)n;
1137 grp->gr_mem = members;
1138 while (maxmembers > 1 && s_mem != NULL) {
1139 p = strsep(&s_mem, ",");
1140 if (p != NULL && *p != '\0') {
1147 return (NS_SUCCESS);