2003-11-27 09:17:14 +08:00
|
|
|
/* user.c - set user id, group id and group access list */
|
1999-09-09 03:06:24 +08:00
|
|
|
/* $OpenLDAP$ */
|
2003-11-27 09:17:14 +08:00
|
|
|
/* This work is part of OpenLDAP Software <http://www.openldap.org/>.
|
1999-04-03 11:19:07 +08:00
|
|
|
*
|
2017-01-04 04:36:47 +08:00
|
|
|
* Copyright 1998-2017 The OpenLDAP Foundation.
|
2003-11-27 09:17:14 +08:00
|
|
|
* Portions Copyright 1999 PM Lashley.
|
1999-04-03 11:19:07 +08:00
|
|
|
* All rights reserved.
|
|
|
|
*
|
2003-11-27 09:17:14 +08:00
|
|
|
* Redistribution and use in source and binary forms, with or without
|
|
|
|
* modification, are permitted only as authorized by the OpenLDAP
|
|
|
|
* Public License.
|
|
|
|
*
|
|
|
|
* A copy of this license is available in the file LICENSE in the
|
|
|
|
* top-level directory of the distribution or, alternatively, at
|
|
|
|
* <http://www.OpenLDAP.org/license.html>.
|
|
|
|
*/
|
1999-04-03 11:19:07 +08:00
|
|
|
|
|
|
|
#include "portable.h"
|
|
|
|
|
1999-04-21 08:40:20 +08:00
|
|
|
#if defined(HAVE_SETUID) && defined(HAVE_SETGID)
|
1999-04-03 11:19:07 +08:00
|
|
|
|
|
|
|
#include <stdio.h>
|
1999-06-03 08:37:44 +08:00
|
|
|
|
|
|
|
#include <ac/stdlib.h>
|
1999-04-21 08:40:20 +08:00
|
|
|
|
|
|
|
#ifdef HAVE_PWD_H
|
1999-04-03 11:19:07 +08:00
|
|
|
#include <pwd.h>
|
1999-04-21 08:40:20 +08:00
|
|
|
#endif
|
|
|
|
#ifdef HAVE_GRP_H
|
1999-04-03 11:19:07 +08:00
|
|
|
#include <grp.h>
|
1999-04-21 08:40:20 +08:00
|
|
|
#endif
|
1999-04-03 11:19:07 +08:00
|
|
|
|
|
|
|
#include <ac/ctype.h>
|
|
|
|
#include <ac/unistd.h>
|
|
|
|
|
|
|
|
#include "slap.h"
|
2005-11-24 09:10:05 +08:00
|
|
|
#include "lutil.h"
|
1999-04-03 11:19:07 +08:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Set real and effective user id and group id, and group access list
|
1999-07-18 09:04:49 +08:00
|
|
|
* The user and group arguments are freed.
|
1999-04-03 11:19:07 +08:00
|
|
|
*/
|
|
|
|
|
|
|
|
void
|
2002-01-30 03:01:15 +08:00
|
|
|
slap_init_user( char *user, char *group )
|
1999-04-03 11:19:07 +08:00
|
|
|
{
|
2001-11-18 00:18:07 +08:00
|
|
|
uid_t uid = 0;
|
|
|
|
gid_t gid = 0;
|
2001-01-18 00:35:53 +08:00
|
|
|
int got_uid = 0, got_gid = 0;
|
1999-04-03 11:19:07 +08:00
|
|
|
|
|
|
|
if ( user ) {
|
|
|
|
struct passwd *pwd;
|
2005-11-24 09:10:05 +08:00
|
|
|
if ( isdigit( (unsigned char) *user ) ) {
|
|
|
|
unsigned u;
|
|
|
|
|
1999-07-18 09:04:49 +08:00
|
|
|
got_uid = 1;
|
2005-11-24 09:10:05 +08:00
|
|
|
if ( lutil_atou( &u, user ) != 0 ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "Unble to parse user %s\n",
|
|
|
|
user, 0, 0 );
|
|
|
|
|
|
|
|
exit( EXIT_FAILURE );
|
|
|
|
}
|
|
|
|
uid = (uid_t)u;
|
1999-04-03 11:19:07 +08:00
|
|
|
#ifdef HAVE_GETPWUID
|
|
|
|
pwd = getpwuid( uid );
|
|
|
|
goto did_getpw;
|
1999-07-18 09:04:49 +08:00
|
|
|
#else
|
|
|
|
free( user );
|
|
|
|
user = NULL;
|
1999-04-03 11:19:07 +08:00
|
|
|
#endif
|
|
|
|
} else {
|
|
|
|
pwd = getpwnam( user );
|
|
|
|
did_getpw:
|
|
|
|
if ( pwd == NULL ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "No passwd entry for user %s\n",
|
|
|
|
user, 0, 0 );
|
2001-01-16 03:17:29 +08:00
|
|
|
|
1999-08-04 02:14:24 +08:00
|
|
|
exit( EXIT_FAILURE );
|
1999-04-03 11:19:07 +08:00
|
|
|
}
|
1999-07-18 09:04:49 +08:00
|
|
|
if ( got_uid ) {
|
1999-04-03 11:19:07 +08:00
|
|
|
free( user );
|
|
|
|
user = (pwd != NULL ? ch_strdup( pwd->pw_name ) : NULL);
|
|
|
|
} else {
|
1999-07-18 09:04:49 +08:00
|
|
|
got_uid = 1;
|
1999-04-03 11:19:07 +08:00
|
|
|
uid = pwd->pw_uid;
|
|
|
|
}
|
1999-07-18 09:04:49 +08:00
|
|
|
got_gid = 1;
|
1999-04-03 11:19:07 +08:00
|
|
|
gid = pwd->pw_gid;
|
|
|
|
#ifdef HAVE_ENDPWENT
|
|
|
|
endpwent();
|
|
|
|
#endif
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if ( group ) {
|
|
|
|
struct group *grp;
|
|
|
|
if ( isdigit( (unsigned char) *group )) {
|
2005-11-24 09:10:05 +08:00
|
|
|
unsigned g;
|
|
|
|
|
|
|
|
if ( lutil_atou( &g, group ) != 0 ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "Unble to parse group %s\n",
|
|
|
|
group, 0, 0 );
|
|
|
|
|
|
|
|
exit( EXIT_FAILURE );
|
|
|
|
}
|
|
|
|
gid = (uid_t)g;
|
1999-04-03 11:19:07 +08:00
|
|
|
#ifdef HAVE_GETGRGID
|
|
|
|
grp = getgrgid( gid );
|
|
|
|
goto did_group;
|
|
|
|
#endif
|
|
|
|
} else {
|
|
|
|
grp = getgrnam( group );
|
|
|
|
if ( grp != NULL )
|
|
|
|
gid = grp->gr_gid;
|
|
|
|
did_group:
|
|
|
|
if ( grp == NULL ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "No group entry for group %s\n",
|
|
|
|
group, 0, 0 );
|
2001-01-16 03:17:29 +08:00
|
|
|
|
1999-08-04 02:14:24 +08:00
|
|
|
exit( EXIT_FAILURE );
|
1999-04-03 11:19:07 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
free( group );
|
1999-07-18 09:04:49 +08:00
|
|
|
got_gid = 1;
|
1999-04-03 11:19:07 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
if ( user ) {
|
|
|
|
if ( getuid() == 0 && initgroups( user, gid ) != 0 ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY,
|
|
|
|
"Could not set the group access (gid) list\n", 0, 0, 0 );
|
2001-01-16 03:17:29 +08:00
|
|
|
|
1999-08-04 02:14:24 +08:00
|
|
|
exit( EXIT_FAILURE );
|
1999-04-03 11:19:07 +08:00
|
|
|
}
|
|
|
|
free( user );
|
|
|
|
}
|
|
|
|
|
|
|
|
#ifdef HAVE_ENDGRENT
|
|
|
|
endgrent();
|
|
|
|
#endif
|
|
|
|
|
1999-07-18 09:04:49 +08:00
|
|
|
if ( got_gid ) {
|
1999-04-03 11:19:07 +08:00
|
|
|
if ( setgid( gid ) != 0 ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "Could not set real group id to %d\n",
|
1999-09-02 16:11:54 +08:00
|
|
|
(int) gid, 0, 0 );
|
2001-01-16 03:17:29 +08:00
|
|
|
|
1999-08-04 02:14:24 +08:00
|
|
|
exit( EXIT_FAILURE );
|
1999-04-03 11:19:07 +08:00
|
|
|
}
|
1999-04-21 08:40:20 +08:00
|
|
|
#ifdef HAVE_SETEGID
|
1999-04-03 11:19:07 +08:00
|
|
|
if ( setegid( gid ) != 0 ) {
|
|
|
|
Debug( LDAP_DEBUG_ANY, "Could not set effective group id to %d\n",
|
1999-09-02 16:11:54 +08:00
|
|
|
(int) gid, 0, 0 );
|
2001-01-16 03:17:29 +08:00
|
|
|
|
1999-08-04 02:14:24 +08:00
|
|
|
exit( EXIT_FAILURE );
|
1999-04-03 11:19:07 +08:00
|
|
|
}
|
1999-04-21 08:40:20 +08:00
|
|
|
#endif
|
1999-04-03 11:19:07 +08:00
|
|
|
}
|
|
|
|
|
1999-07-18 09:04:49 +08:00
|
|
|
if ( got_uid ) {
|
1999-04-03 11:19:07 +08:00
|
|
|
if ( setuid( uid ) != 0 ) {
|
1999-07-13 16:24:26 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "Could not set real user id to %d\n",
|
1999-09-02 16:11:54 +08:00
|
|
|
(int) uid, 0, 0 );
|
2001-01-16 03:17:29 +08:00
|
|
|
|
1999-08-04 02:14:24 +08:00
|
|
|
exit( EXIT_FAILURE );
|
1999-04-03 11:19:07 +08:00
|
|
|
}
|
1999-04-21 08:40:20 +08:00
|
|
|
#ifdef HAVE_SETEUID
|
1999-04-03 11:19:07 +08:00
|
|
|
if ( seteuid( uid ) != 0 ) {
|
1999-07-13 16:24:26 +08:00
|
|
|
Debug( LDAP_DEBUG_ANY, "Could not set effective user id to %d\n",
|
1999-09-02 16:11:54 +08:00
|
|
|
(int) uid, 0, 0 );
|
2001-01-16 03:17:29 +08:00
|
|
|
|
1999-08-04 02:14:24 +08:00
|
|
|
exit( EXIT_FAILURE );
|
1999-04-03 11:19:07 +08:00
|
|
|
}
|
1999-04-21 08:40:20 +08:00
|
|
|
#endif
|
1999-04-03 11:19:07 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
#endif /* HAVE_PWD_H && HAVE_GRP_H */
|