2003-01-12 19:38:51 +08:00
|
|
|
/* sec_acl.cc: Sun compatible ACL functions.
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2010-01-12 18:14:59 +08:00
|
|
|
Copyright 2000, 2001, 2002, 2003, 2004, 2005, 2006, 2007, 2008,
|
2012-03-29 23:01:18 +08:00
|
|
|
2009, 2010, 2011, 2012 Red Hat, Inc.
|
2001-04-20 21:02:32 +08:00
|
|
|
|
|
|
|
Written by Corinna Vinschen <corinna@vinschen.de>
|
|
|
|
|
|
|
|
This file is part of Cygwin.
|
|
|
|
|
|
|
|
This software is a copyrighted work licensed under the terms of the
|
|
|
|
Cygwin license. Please consult the file "CYGWIN_LICENSE" for
|
|
|
|
details. */
|
|
|
|
|
|
|
|
#include "winsup.h"
|
|
|
|
#include <stdlib.h>
|
|
|
|
#include <sys/acl.h>
|
|
|
|
#include <ctype.h>
|
|
|
|
#include "cygerrno.h"
|
2001-07-27 03:22:24 +08:00
|
|
|
#include "security.h"
|
2001-04-20 21:02:32 +08:00
|
|
|
#include "path.h"
|
* devices.cc: New file.
* devices.gperf: New file.
* devices.shilka: New file.
* cygwin-gperf: New file.
* cygwin-shilka: New file.
* fhandler_fifo.cc: New file.
* fhandler_nodevice.cc : New file. Reorganize headers so that path.h precedes
fhandler.h throughout. Remove device argument and unit arguments from fhandler
constructors throughout. Remove pc arguments to fhandler functions and use
internal pc element instead, throughout. Use dev element in pc throughout.
Use major/minor elements rather than units and device numbers previously in
fhandler class. Use correct methods for fhandler file names rather than
directly accessing file name variables, throughout.
* Makefile.in (DLL_OFILES): Add devices.o, fhandler_fifo.o
* dcrt0.cc (dll_crt0_1): Call device::init.
* devices.h: Renumber devices based on more Linux-like major/minor numbers.
Add more devices. Declare standard device storage.
(device): Declare struct.
* dir.cc (opendir): Use new 'build_fh_name' to construct a fhandler_* type.
* dtable.cc (dtable::get_debugger_info): Ditto.
(cygwin_attach_handle_to_fd): Ditto.
(dtable::release): Remove special FH_SOCKET case in favor of generic
"need_fixup_before" test.
(dtable::init_std_file_from_handle): Use either build_fh_dev or build_fh_name
to build standard fhandler.
(dtable::build_fh_name): Renamed from dtable::build_fhandler_from_name. Move
out of dtable class. Don't accept a path_conv argument. Just build it here
and pass it to:
(build_fh_pc): Renamed from dtable::build_fhandler. Move out of dtable class.
Use intrinsic device type in path_conv to create new fhandler.
(build_fh_dev): Renamed from dtable::build_fhandler. Move out of dtable class.
Simplify arguments to just take new 'device' type and a name. Just return
pointer to fhandler rather than trying to insert into dtable.
(dtable::dup_worker): Accommodate above build_fh name changes.
(dtable::find_fifo): New (currently broken) function.
(handle_to_fn): Use strechr for efficiency.
* dtable.h: Reflect above build_fh name changes and argument differences.
(fhandler_base *&operator []): Return self rather than copy of self.
* fhandler.cc (fhandler_base::operator =): Use pc element to set normalized
path.
(fhandler_base::set_name): Ditto.
(fhandler_base::raw_read): Use method to access name.
(fhandler_base::write): Correctly use get_output_handle rather than get_handle.
(handler_base::device_access_denied): New function.
(fhandler_base::open): Eliminate pc argument and use pc element of
fhandler_base throughout.
(fhandler_base::fstat): Detect if device is based in filesystem and use
fstat_fs to calculate stat, if so.
(fhandler_base::fhandler_base): Eliminate handling of file names and, instead,
just free appropriate component from pc.
(fhandler_base::opendir): Remove path_conv parameter.
* fhandler.h: Remove all device flags.
(fhandler_base::pc): New element.
(fhandler_base::set_name): Change argument to path_conv.
(fhandler_base::error): New function.
(fhandler_base::exists): New function.
(fhandler_base::pc_binmode): New function.
(fhandler_base::dev): New function.
(fhandler_base::open_fs): New function.
(fhandler_base::fstat_fs): New function.
(fhandler_base::fstat_by_name): New function.
(fhandler_base::fstat_by_handle): New function.
(fhandler_base::isfifo): New function.
(fhandler_base::is_slow): New function.
(fhandler_base::is_auto_device): New function.
(fhandler_base::is_fs_special): New function.
(fhandler_base::device_access_denied): New function.
(fhandler_base::operator DWORD&): New operator.
(fhandler_base::get_name): Return normalized path from pc.
(fhandler_base::get_win32_name): Return windows path from pc.
(fhandler_base::isdevice): Renamed from is_device.
(fhandler_base::get_native_name): Return device format.
(fhandler_fifo): New class.
(fhandler_nodevice): New class.
(select_stuff::device_specific): Remove array.
(select_stuff::device_specific_pipe): New class element.
(select_stuff::device_specific_socket): New class element.
(select_stuff::device_specific_serial): New class element.
(select_stuff::select_stuff): Initialize new elements.
* fhandler_disk_file.cc (fhandler_base::fstat_by_handle): Move to base class
from fhandler_disk_file.
(fhandler_base::fstat_by_name): Ditto.
(fhandler_base::fstat_by_name): Ditto.
(fhandler_disk_file::open): Move most functionality into
fhandler_base::open_fs.
(fhandler_base::open_fs): New function.
(fhandler_disk_file::close): Move most functionality into
fhandler_base::close_fs.
(fhandler_base::close_fs): New function.
* fhandler_mem.cc (fhandler_dev_mem::open): Use device name in debugging
output.
* fhandler_socket.cc (fhandler_socket::set_connect_secret): Copy standard
urandom device into appropriate place.
(fhandler_socket::accept): Reflect change in fdsock return value.
* fhandler_tty.cc: See "throughouts" above.
* net.cc: Accommodate fdsock change throughout.
(fdsock): Return success or failure, accept fd argument and device argument.
* path.cc (symlink_info::major): New element.
(symlink_info::minor): New element.
(symlink_info::parse_device): Declare new function.
(fs_info::update): Accommodate changes in path_conv class.
(path_conv::fillin): Ditto.
(path_conv::return_and_clear_normalized_path): Eliminate.
(path_conv::set_normalized_path): New function.
(path_conv::path_conv): Set info in dev element. Use path_conv methods Check
for FH_FS rather than FH_BAD to indicate when to fill in filesystem stuff.
where appropriate rather than direct access. Use set_normalized_path to set
normalized path.
(windows_device_names): Eliminate.
(get_dev): Ditto.
(get_raw_device_number): Ditto.
(get_device_number): Ditto.
(win32_device_name): Call new device name parser to do most of the heavy
lifting.
(mount_info::conv_to_win32_path): Fill in dev field as appropriate.
(symlink_worker): Handle new device files.
(symlink_info::check): Ditto.
(symlink_info::parse_device): Define new function.
* path.h (executable_states): Move here from fhandler.h.
(fs_info): Rename variables to *_storage and create methods for accessing same.
(path_conv): Add dev element, remove devn and unit and adjust inline methods to
accommodate.
(set_normalized_path): Declare new function.
* pinfo.cc (_pinfo::commune_recv): Add broken support for handling fifos.
(_pinfo::commune_send): Ditto.
* pipe.cc (fhandler_pipe::close): check for existence of handle before closing
it.
(handler_pipe::create): Rename from make_pipe. Change arguments to accept
fhandler_pipe array. Accommodate fifos.
(pipe): Rework to deal with fhandler_pipe::create changes.
(_pipe): Ditto.
* select.cc: Use individual device_specific types throughout rather than
indexing with obsolete device number.
(set_bits): Use is_socket call rather than checking device number.
* shared_info.h (CURR_MOUNT_MAGIC): Update.
(conv_to_win32_path): Reflect addition of device argument.
* syscalls.cc (mknod_worker): New function.
(open): Use build_fh_name to build fhandler.
(chown_worker): Detect if this is an 'auto' device rather than an on-filesystem
device and handle appropriately.
(chmod_device): New function.
(chmod): Detect if this is an 'auto' device rather than an on-filesystem device
and handle appropriately. Use chmod_device to set mode of in-filesystem
devices.
(stat_worker): Eliminate path_conv argument. Call build_fh_name to construct
fhandler. Use fh->error() rather than pc->error to detect errors in fhandler
construction.
(access_worker): New function pulled from access. Accommodate in-filesystem
devices.
(access): Use access_worker.
(fpathconf): Detect if this is an 'auto' device rather than an on-filesystem
device and handle appropriately.
(mknod_worker): New function.
(mknod32): New function.
(chroot): Free normalized path -- assuming it was actually cmalloced.
* tty.cc (create_tty_master): Tweak for new device class.
(tty::common_init): Ditto.
* winsup.h (stat_worker): Remove.
(symlink_worker): Declare.
* exceptions.cc (set_process_mask): Just call sig_dispatch_pending and don't
worry about pending_signals since sig_dispatch_pending should always do the
right thing now.
(sig_handle): Reorganize SIGCONT handling to more closely conform to SUSv3.
* pinfo.h: Move __SIG enum to sigproc.h.
(PICOM_FIFO): New enum element.
(_pinfo): Remove 'thread2signal' stuff throughout class.
(_pinfo::commune_send): Make varargs.
(_pinfo::sigtodo): Eliminate.
(_pinfo::thread2signal): Ditto.
* signal.cc (kill_worker): Eliminate call to setthread2signal.
* sigproc.cc (local_sigtodo): Eliminate.
(getlocal_sigtodo): Ditto.
(sigelem): New class.
(pending_signals): New class.
(sigqueue): New variable, start of sigqueue linked list.
(sigcatch_nonmain): Eliminate.
(sigcatch_main): Eliminate.
(sigcatch_nosync): Eliminate.
(sigcomplete_nonmain): Eliminate.
(pending_signals): Eliminate.
(sig_clear): Call signal thread to clear pending signals, unless already in
signal thread.
(sigpending): Call signal thread to get pending signals.
(sig_dispatch_pending): Eliminate use of pending_signals and just check
sigqueue.
(sigproc_terminate): Eliminate all of the obsolete semaphore stuff. Close
signal pipe handle.
(sig_send): Eliminate all of the obsolete semaphore stuff and use pipe to send
signals.
(getevent): Eliminate.
(pending_signals::add): New function.
(pending_signals::del): New function.
(pending_signals::next): New function.
(wait_sig): Eliminate all of the obsolete semaphore stuff. Use pipe to
communicate and maintain a linked list of signals.
* sigproc.h: Move __SIG defines here. Add __SIGPENDING.
(sig_dispatch_pending): Remove "C" specifier.
(sig_handle): Accept a mask argument.
* thread.cc: Remove signal handling considerations throughout.
2003-09-25 08:37:18 +08:00
|
|
|
#include "fhandler.h"
|
2001-04-20 21:02:32 +08:00
|
|
|
#include "dtable.h"
|
|
|
|
#include "cygheap.h"
|
2011-04-28 17:30:36 +08:00
|
|
|
#include "ntdll.h"
|
2002-12-10 Pierre Humblet <pierre.humblet@ieee.org>
* pwdgrp.h (pwdgrp_check::pwdgrp_state): Replace by
pwdgrp_check::isinitializing ().
(pwdgrp_check::isinitializing): Create.
* passwd.cc (grab_int): Change type to unsigned, use strtoul and
set the pointer content to 0 if the field is invalid.
(parse_pwd): Move validity test after getting pw_gid.
(read_etc_passwd): Replace "passwd_state <= " by
passwd_state::isinitializing ().
(internal_getpwuid): Ditto.
(internal_getpwnam): Ditto.
(getpwent): Ditto.
(getpass): Ditto.
* grp.cc (parse_grp): Use strtoul for gr_gid and verify the validity.
(read_etc_group): Replace "group_state <= " by
group_state::isinitializing ().
(internal_getgrgid): Ditto.
(getgrent32): Ditto.
(internal_getgrent): Ditto.
2002-12-10 Pierre Humblet <pierre.humblet@ieee.org>
* security.h: Move declarations of internal_getgrent,
internal_getpwsid and internal_getgrsid to pwdgrp.h.
* pwdgrp.h: Declare internal_getpwsid, internal_getpwnam,
internal_getpwuid, internal_getgrsid, internal_getgrgid,
internal_getgrnam, internal_getgrent and internal_getgroups.
Delete "emulated" from enum pwdgrp_state.
(pwdgrp_check::isuninitialized): Create.
(pwdgrp_check::pwdgrp_state): Change state to initializing
rather than to uninitialized.
(pwdgrp_read::gets): Remove trailing CRs.
* passwd.cc (grab_string): Don't look for NLs.
(grab_int): Ditto.
(parse_pwd): Don't look for CRs. Return 0 if entry is too short.
(search_for): Delete.
(read_etc_passwd): Simplify tests to actually read the file.
Set state to loaded before making internal_getpwXX calls.
Replace search_for calls by equivalent internal_pwgetXX calls.
(internal_getpwsid): Use passwd_state.isuninitialized to decide
to call read_etc_passwd.
(internal_getpwuid): Create.
(internal_getpwnam): Create.
(getpwuid32): Simply call internal_getpwuid.
(getpwuid_r32): Call internal_getpwuid.
(getpwnam): Simply call internal_getpwnam.
(getpwnam_r): Call internal_getpwnam.
* grp.cc (parse_grp): Don't look for CRs. Adjust blank space.
(add_grp_line): Adjust blank space.
(class group_lock): Ditto.
(read_etc_group): Simplify tests to actually read the file.
Set state to loaded before making internal_getgrXX calls.
Replace getgrXX calls by equivalent internal calls.
(internal_getgrsid): Use group_state.isuninitialized to decide
to call read_etc_group.
(internal_getgrgid): Create.
(internal_getgrnam): Create.
(getgroups32): Simply call internal_getgrgid.
(getgrnam32): Simply call internal_getgrnam.
(internal_getgrent): Call group_state.isuninitialized.
(internal_getgroups): Create from the former getgroups32, using
two of the four arguments. Set gid to myself->gid and username
to cygheap->user.name ().
(getgroups32): Simply call internal_getgroup.
(getgroups): Call internal_getgroup instead of getgroups32.
(setgroups32): Call internal versions of get{pw,gr}XX.
* sec_helper.cc: Include pwdgrp.h.
(is_grp_member): Call internal versions of get{pw,gr}XX.
* security.cc: Include pwdgrp.h.
(alloc_sd): Call internal versions of get{pw,gr}XX.
* syscalls.cc: Include pwdgrp.h.
(seteuid32): Call internal versions of get{pw,gr}XX.
(setegid32): Ditto.
* uinfo.cc: Include pwdgrp.h.
(internal_getlogin): Call internal versions of get{pw,gr}XX.
(cygheap_user::ontherange): Ditto.
* sec_acl.cc: Include pwdgrp.h.
(setacl): Call internal versions of get{pw,gr}XX.
(acl_access): Ditto and simplify logic.
(aclfromtext): Ditto.
2002-12-10 20:43:49 +08:00
|
|
|
#include "pwdgrp.h"
|
2010-09-10 22:53:44 +08:00
|
|
|
#include "tls_pbuf.h"
|
2001-04-20 21:02:32 +08:00
|
|
|
|
|
|
|
static int
|
2003-02-06 00:15:22 +08:00
|
|
|
searchace (__aclent32_t *aclp, int nentries, int type, __uid32_t id = ILLEGAL_UID)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
int i;
|
|
|
|
|
|
|
|
for (i = 0; i < nentries; ++i)
|
2003-02-06 00:15:22 +08:00
|
|
|
if ((aclp[i].a_type == type && (id == ILLEGAL_UID || aclp[i].a_id == id))
|
2001-04-20 21:02:32 +08:00
|
|
|
|| !aclp[i].a_type)
|
|
|
|
return i;
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2004-04-15 00:36:26 +08:00
|
|
|
int
|
2007-07-20 22:29:43 +08:00
|
|
|
setacl (HANDLE handle, path_conv &pc, int nentries, __aclent32_t *aclbufp,
|
2007-01-07 20:44:10 +08:00
|
|
|
bool &writable)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2003-11-26 21:23:27 +08:00
|
|
|
security_descriptor sd_ret;
|
2010-09-10 22:53:44 +08:00
|
|
|
tmp_pathbuf tp;
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2010-09-10 17:32:13 +08:00
|
|
|
if (get_file_sd (handle, pc, sd_ret, false))
|
2007-07-20 22:29:43 +08:00
|
|
|
return -1;
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2011-04-28 17:53:11 +08:00
|
|
|
NTSTATUS status;
|
|
|
|
BOOLEAN dummy;
|
2001-04-20 21:02:32 +08:00
|
|
|
|
|
|
|
/* Get owner SID. */
|
2003-02-06 00:15:22 +08:00
|
|
|
PSID owner_sid;
|
2011-04-28 17:53:11 +08:00
|
|
|
status = RtlGetOwnerSecurityDescriptor (sd_ret, &owner_sid, &dummy);
|
|
|
|
if (!NT_SUCCESS (status))
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2011-04-28 17:53:11 +08:00
|
|
|
__seterrno_from_nt_status (status);
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
}
|
2001-04-25 17:43:25 +08:00
|
|
|
cygsid owner (owner_sid);
|
2001-04-20 21:02:32 +08:00
|
|
|
|
|
|
|
/* Get group SID. */
|
2003-02-06 00:15:22 +08:00
|
|
|
PSID group_sid;
|
2011-04-28 17:53:11 +08:00
|
|
|
status = RtlGetGroupSecurityDescriptor (sd_ret, &group_sid, &dummy);
|
|
|
|
if (!NT_SUCCESS (status))
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2011-04-28 17:53:11 +08:00
|
|
|
__seterrno_from_nt_status (status);
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
}
|
2001-04-25 17:43:25 +08:00
|
|
|
cygsid group (group_sid);
|
2001-04-20 21:02:32 +08:00
|
|
|
|
|
|
|
/* Initialize local security descriptor. */
|
|
|
|
SECURITY_DESCRIPTOR sd;
|
2011-04-28 17:30:36 +08:00
|
|
|
RtlCreateSecurityDescriptor (&sd, SECURITY_DESCRIPTOR_REVISION);
|
2011-04-28 23:54:47 +08:00
|
|
|
status = RtlSetOwnerSecurityDescriptor (&sd, owner, FALSE);
|
|
|
|
if (!NT_SUCCESS (status))
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2011-04-28 23:54:47 +08:00
|
|
|
__seterrno_from_nt_status (status);
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
}
|
2011-04-28 23:54:47 +08:00
|
|
|
status = RtlSetGroupSecurityDescriptor (&sd, group, FALSE);
|
|
|
|
if (!NT_SUCCESS (status))
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2011-04-28 23:54:47 +08:00
|
|
|
__seterrno_from_nt_status (status);
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
/* Fill access control list. */
|
2010-09-10 22:53:44 +08:00
|
|
|
PACL acl = (PACL) tp.w_get ();
|
2001-04-20 21:02:32 +08:00
|
|
|
size_t acl_len = sizeof (ACL);
|
|
|
|
int ace_off = 0;
|
|
|
|
|
2001-04-25 17:43:25 +08:00
|
|
|
cygsid sid;
|
2001-04-20 21:02:32 +08:00
|
|
|
struct passwd *pw;
|
Change internal gid datatype from __gid16_t to __gid32_t
throughout.
* cygwin.din: Export new symbols chown32, fchown32, getegid32,
getgid32, getgrgid32, getgrnam32, getgroups32, initgroups32, lchown32,
setgid32, setegid32, getgrent32.
* grp.cc (grp32togrp16): New static function.
(getgrgid32): New function.
(getgrnam32): Ditto.
(getgrent32): Ditto.
(getgroups32): Change name of internal function from getgroups.
(getgroups32): New function.
(initgroups32): Ditto.
* syscalls.cc (chown32): Ditto.
(lchown32): Ditto.
(fchown32): Ditto.
(setegid32): Ditto.
(setgid32): Ditto.
* uinfo.cc (getgid32): Ditto.
(getegid32): Ditto.
* include/cygwin/grp.h: Remove declaration of getgrgid() and getgrnam().
Declare getgrgid32() and getgrnam32() instead. Declare getgid32().
2002-05-28 22:10:55 +08:00
|
|
|
struct __group32 *gr;
|
2001-04-20 21:02:32 +08:00
|
|
|
int pos;
|
|
|
|
|
2011-04-28 17:30:36 +08:00
|
|
|
RtlCreateAcl (acl, ACL_MAXIMUM_SIZE, ACL_REVISION);
|
2007-01-07 20:44:10 +08:00
|
|
|
|
|
|
|
writable = false;
|
|
|
|
|
2001-04-20 21:02:32 +08:00
|
|
|
for (int i = 0; i < nentries; ++i)
|
|
|
|
{
|
2003-02-06 00:15:22 +08:00
|
|
|
DWORD allow;
|
|
|
|
/* Owner has more standard rights set. */
|
|
|
|
if ((aclbufp[i].a_type & ~ACL_DEFAULT) == USER_OBJ)
|
2008-10-14 00:01:50 +08:00
|
|
|
allow = STANDARD_RIGHTS_ALL
|
|
|
|
| (pc.fs_is_samba ()
|
|
|
|
? 0 : (FILE_READ_ATTRIBUTES | FILE_WRITE_ATTRIBUTES));
|
2003-02-06 00:15:22 +08:00
|
|
|
else
|
2008-10-14 00:01:50 +08:00
|
|
|
allow = STANDARD_RIGHTS_READ
|
|
|
|
| (pc.fs_is_samba () ? 0 : FILE_READ_ATTRIBUTES);
|
2001-04-20 21:02:32 +08:00
|
|
|
if (aclbufp[i].a_perm & S_IROTH)
|
|
|
|
allow |= FILE_GENERIC_READ;
|
|
|
|
if (aclbufp[i].a_perm & S_IWOTH)
|
2007-01-07 20:44:10 +08:00
|
|
|
{
|
2008-10-14 00:01:50 +08:00
|
|
|
allow |= FILE_GENERIC_WRITE;
|
2007-01-07 20:44:10 +08:00
|
|
|
writable = true;
|
|
|
|
}
|
2001-04-20 21:02:32 +08:00
|
|
|
if (aclbufp[i].a_perm & S_IXOTH)
|
2008-10-14 00:01:50 +08:00
|
|
|
allow |= FILE_GENERIC_EXECUTE & ~FILE_READ_ATTRIBUTES;
|
2001-07-16 06:40:07 +08:00
|
|
|
if ((aclbufp[i].a_perm & (S_IWOTH | S_IXOTH)) == (S_IWOTH | S_IXOTH))
|
2001-09-08 05:32:07 +08:00
|
|
|
allow |= FILE_DELETE_CHILD;
|
2001-04-20 21:02:32 +08:00
|
|
|
/* Set inherit property. */
|
|
|
|
DWORD inheritance = (aclbufp[i].a_type & ACL_DEFAULT)
|
2009-10-31 03:58:53 +08:00
|
|
|
? (CONTAINER_INHERIT_ACE | OBJECT_INHERIT_ACE
|
|
|
|
| INHERIT_ONLY_ACE)
|
2002-07-02 16:11:15 +08:00
|
|
|
: NO_INHERITANCE;
|
2001-04-20 21:02:32 +08:00
|
|
|
/*
|
|
|
|
* If a specific acl contains a corresponding default entry with
|
|
|
|
* identical permissions, only one Windows ACE with proper
|
|
|
|
* inheritance bits is created.
|
|
|
|
*/
|
|
|
|
if (!(aclbufp[i].a_type & ACL_DEFAULT)
|
2003-01-12 19:38:51 +08:00
|
|
|
&& aclbufp[i].a_type & (USER|GROUP|OTHER_OBJ)
|
2003-01-26 14:42:40 +08:00
|
|
|
&& (pos = searchace (aclbufp + i + 1, nentries - i - 1,
|
2001-04-20 21:02:32 +08:00
|
|
|
aclbufp[i].a_type | ACL_DEFAULT,
|
|
|
|
(aclbufp[i].a_type & (USER|GROUP))
|
2003-02-06 00:15:22 +08:00
|
|
|
? aclbufp[i].a_id : ILLEGAL_UID)) >= 0
|
2004-04-11 04:18:11 +08:00
|
|
|
&& aclbufp[i].a_perm == aclbufp[i + 1 + pos].a_perm)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2009-10-31 03:58:53 +08:00
|
|
|
inheritance = CONTAINER_INHERIT_ACE | OBJECT_INHERIT_ACE;
|
2003-01-26 14:42:40 +08:00
|
|
|
/* This invalidates the corresponding default entry. */
|
2004-04-11 04:18:11 +08:00
|
|
|
aclbufp[i + 1 + pos].a_type = USER|GROUP|ACL_DEFAULT;
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
|
|
|
switch (aclbufp[i].a_type)
|
|
|
|
{
|
|
|
|
case USER_OBJ:
|
|
|
|
if (!add_access_allowed_ace (acl, ace_off++, allow,
|
2001-04-25 17:43:25 +08:00
|
|
|
owner, acl_len, inheritance))
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
break;
|
2003-01-12 19:38:51 +08:00
|
|
|
case DEF_USER_OBJ:
|
|
|
|
if (!add_access_allowed_ace (acl, ace_off++, allow,
|
|
|
|
well_known_creator_owner_sid, acl_len, inheritance))
|
|
|
|
return -1;
|
|
|
|
break;
|
2001-04-20 21:02:32 +08:00
|
|
|
case USER:
|
|
|
|
case DEF_USER:
|
2002-12-10 Pierre Humblet <pierre.humblet@ieee.org>
* pwdgrp.h (pwdgrp_check::pwdgrp_state): Replace by
pwdgrp_check::isinitializing ().
(pwdgrp_check::isinitializing): Create.
* passwd.cc (grab_int): Change type to unsigned, use strtoul and
set the pointer content to 0 if the field is invalid.
(parse_pwd): Move validity test after getting pw_gid.
(read_etc_passwd): Replace "passwd_state <= " by
passwd_state::isinitializing ().
(internal_getpwuid): Ditto.
(internal_getpwnam): Ditto.
(getpwent): Ditto.
(getpass): Ditto.
* grp.cc (parse_grp): Use strtoul for gr_gid and verify the validity.
(read_etc_group): Replace "group_state <= " by
group_state::isinitializing ().
(internal_getgrgid): Ditto.
(getgrent32): Ditto.
(internal_getgrent): Ditto.
2002-12-10 Pierre Humblet <pierre.humblet@ieee.org>
* security.h: Move declarations of internal_getgrent,
internal_getpwsid and internal_getgrsid to pwdgrp.h.
* pwdgrp.h: Declare internal_getpwsid, internal_getpwnam,
internal_getpwuid, internal_getgrsid, internal_getgrgid,
internal_getgrnam, internal_getgrent and internal_getgroups.
Delete "emulated" from enum pwdgrp_state.
(pwdgrp_check::isuninitialized): Create.
(pwdgrp_check::pwdgrp_state): Change state to initializing
rather than to uninitialized.
(pwdgrp_read::gets): Remove trailing CRs.
* passwd.cc (grab_string): Don't look for NLs.
(grab_int): Ditto.
(parse_pwd): Don't look for CRs. Return 0 if entry is too short.
(search_for): Delete.
(read_etc_passwd): Simplify tests to actually read the file.
Set state to loaded before making internal_getpwXX calls.
Replace search_for calls by equivalent internal_pwgetXX calls.
(internal_getpwsid): Use passwd_state.isuninitialized to decide
to call read_etc_passwd.
(internal_getpwuid): Create.
(internal_getpwnam): Create.
(getpwuid32): Simply call internal_getpwuid.
(getpwuid_r32): Call internal_getpwuid.
(getpwnam): Simply call internal_getpwnam.
(getpwnam_r): Call internal_getpwnam.
* grp.cc (parse_grp): Don't look for CRs. Adjust blank space.
(add_grp_line): Adjust blank space.
(class group_lock): Ditto.
(read_etc_group): Simplify tests to actually read the file.
Set state to loaded before making internal_getgrXX calls.
Replace getgrXX calls by equivalent internal calls.
(internal_getgrsid): Use group_state.isuninitialized to decide
to call read_etc_group.
(internal_getgrgid): Create.
(internal_getgrnam): Create.
(getgroups32): Simply call internal_getgrgid.
(getgrnam32): Simply call internal_getgrnam.
(internal_getgrent): Call group_state.isuninitialized.
(internal_getgroups): Create from the former getgroups32, using
two of the four arguments. Set gid to myself->gid and username
to cygheap->user.name ().
(getgroups32): Simply call internal_getgroup.
(getgroups): Call internal_getgroup instead of getgroups32.
(setgroups32): Call internal versions of get{pw,gr}XX.
* sec_helper.cc: Include pwdgrp.h.
(is_grp_member): Call internal versions of get{pw,gr}XX.
* security.cc: Include pwdgrp.h.
(alloc_sd): Call internal versions of get{pw,gr}XX.
* syscalls.cc: Include pwdgrp.h.
(seteuid32): Call internal versions of get{pw,gr}XX.
(setegid32): Ditto.
* uinfo.cc: Include pwdgrp.h.
(internal_getlogin): Call internal versions of get{pw,gr}XX.
(cygheap_user::ontherange): Ditto.
* sec_acl.cc: Include pwdgrp.h.
(setacl): Call internal versions of get{pw,gr}XX.
(acl_access): Ditto and simplify logic.
(aclfromtext): Ditto.
2002-12-10 20:43:49 +08:00
|
|
|
if (!(pw = internal_getpwuid (aclbufp[i].a_id))
|
2008-05-22 20:43:18 +08:00
|
|
|
|| !sid.getfrompw (pw))
|
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
if (!add_access_allowed_ace (acl, ace_off++, allow,
|
|
|
|
sid, acl_len, inheritance))
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
break;
|
|
|
|
case GROUP_OBJ:
|
|
|
|
if (!add_access_allowed_ace (acl, ace_off++, allow,
|
2003-02-06 00:15:22 +08:00
|
|
|
group, acl_len, inheritance))
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
break;
|
2003-01-12 19:38:51 +08:00
|
|
|
case DEF_GROUP_OBJ:
|
|
|
|
if (!add_access_allowed_ace (acl, ace_off++, allow,
|
|
|
|
well_known_creator_group_sid, acl_len, inheritance))
|
|
|
|
return -1;
|
|
|
|
break;
|
2001-04-20 21:02:32 +08:00
|
|
|
case GROUP:
|
|
|
|
case DEF_GROUP:
|
2002-12-10 Pierre Humblet <pierre.humblet@ieee.org>
* pwdgrp.h (pwdgrp_check::pwdgrp_state): Replace by
pwdgrp_check::isinitializing ().
(pwdgrp_check::isinitializing): Create.
* passwd.cc (grab_int): Change type to unsigned, use strtoul and
set the pointer content to 0 if the field is invalid.
(parse_pwd): Move validity test after getting pw_gid.
(read_etc_passwd): Replace "passwd_state <= " by
passwd_state::isinitializing ().
(internal_getpwuid): Ditto.
(internal_getpwnam): Ditto.
(getpwent): Ditto.
(getpass): Ditto.
* grp.cc (parse_grp): Use strtoul for gr_gid and verify the validity.
(read_etc_group): Replace "group_state <= " by
group_state::isinitializing ().
(internal_getgrgid): Ditto.
(getgrent32): Ditto.
(internal_getgrent): Ditto.
2002-12-10 Pierre Humblet <pierre.humblet@ieee.org>
* security.h: Move declarations of internal_getgrent,
internal_getpwsid and internal_getgrsid to pwdgrp.h.
* pwdgrp.h: Declare internal_getpwsid, internal_getpwnam,
internal_getpwuid, internal_getgrsid, internal_getgrgid,
internal_getgrnam, internal_getgrent and internal_getgroups.
Delete "emulated" from enum pwdgrp_state.
(pwdgrp_check::isuninitialized): Create.
(pwdgrp_check::pwdgrp_state): Change state to initializing
rather than to uninitialized.
(pwdgrp_read::gets): Remove trailing CRs.
* passwd.cc (grab_string): Don't look for NLs.
(grab_int): Ditto.
(parse_pwd): Don't look for CRs. Return 0 if entry is too short.
(search_for): Delete.
(read_etc_passwd): Simplify tests to actually read the file.
Set state to loaded before making internal_getpwXX calls.
Replace search_for calls by equivalent internal_pwgetXX calls.
(internal_getpwsid): Use passwd_state.isuninitialized to decide
to call read_etc_passwd.
(internal_getpwuid): Create.
(internal_getpwnam): Create.
(getpwuid32): Simply call internal_getpwuid.
(getpwuid_r32): Call internal_getpwuid.
(getpwnam): Simply call internal_getpwnam.
(getpwnam_r): Call internal_getpwnam.
* grp.cc (parse_grp): Don't look for CRs. Adjust blank space.
(add_grp_line): Adjust blank space.
(class group_lock): Ditto.
(read_etc_group): Simplify tests to actually read the file.
Set state to loaded before making internal_getgrXX calls.
Replace getgrXX calls by equivalent internal calls.
(internal_getgrsid): Use group_state.isuninitialized to decide
to call read_etc_group.
(internal_getgrgid): Create.
(internal_getgrnam): Create.
(getgroups32): Simply call internal_getgrgid.
(getgrnam32): Simply call internal_getgrnam.
(internal_getgrent): Call group_state.isuninitialized.
(internal_getgroups): Create from the former getgroups32, using
two of the four arguments. Set gid to myself->gid and username
to cygheap->user.name ().
(getgroups32): Simply call internal_getgroup.
(getgroups): Call internal_getgroup instead of getgroups32.
(setgroups32): Call internal versions of get{pw,gr}XX.
* sec_helper.cc: Include pwdgrp.h.
(is_grp_member): Call internal versions of get{pw,gr}XX.
* security.cc: Include pwdgrp.h.
(alloc_sd): Call internal versions of get{pw,gr}XX.
* syscalls.cc: Include pwdgrp.h.
(seteuid32): Call internal versions of get{pw,gr}XX.
(setegid32): Ditto.
* uinfo.cc: Include pwdgrp.h.
(internal_getlogin): Call internal versions of get{pw,gr}XX.
(cygheap_user::ontherange): Ditto.
* sec_acl.cc: Include pwdgrp.h.
(setacl): Call internal versions of get{pw,gr}XX.
(acl_access): Ditto and simplify logic.
(aclfromtext): Ditto.
2002-12-10 20:43:49 +08:00
|
|
|
if (!(gr = internal_getgrgid (aclbufp[i].a_id))
|
2008-05-22 20:43:18 +08:00
|
|
|
|| !sid.getfromgr (gr))
|
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
if (!add_access_allowed_ace (acl, ace_off++, allow,
|
|
|
|
sid, acl_len, inheritance))
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
break;
|
|
|
|
case OTHER_OBJ:
|
|
|
|
case DEF_OTHER_OBJ:
|
|
|
|
if (!add_access_allowed_ace (acl, ace_off++, allow,
|
* fork.cc (fork): Eliminate superfluous call to getuid().
* security.h: New define `NO_SID'. Remove declarations of functions
moved to methods into class cygsid.
(class cygsid): Declare new methods `getfromstr', `get_sid',
`getfrompw', `getfromgr', `get_rid', `get_uid', `get_gid', `string'
and new constructors and operators =, == and !=.
Declare new global cygsids `well_known_XXX_sid' substituting the
corresponding `get_XXX_sid' functions. Remove declarations of
these functions.
* sec_helper.cc (well_known_admin_sid): New global variable.
(well_known_system_sid): Ditto
(well_known_creator_owner_sid): Ditto
(well_known_world_sid): Ditto
(cygsid::string): New method, substituting `convert_sid_to_string_sid'.
(cygsid::get_sid): New method, substituting `get_sid'.
(cygsid::getfromstr): New method, substituting
`convert_string_sid_to_sid'.
(cygsid::getfrompw): New method, substituting `get_pw_sid'.
(cygsid::getfromgr): New method, substituting `get_gr_sid'.
(cygsid::get_id): New method, substituting `get_id_from_sid'.
(get_admin_sid): Eliminated.
(get_system_sid): Ditto.
(get_creator_owner_sid): Ditto.
(get_world_sid): Ditto.
* grp.cc: Use new cygsid methods and well known sids throughout.
* registry.cc: Ditto.
* sec_acl.cc: Ditto.
* security.cc: Ditto.
* shared.cc: Ditto.
* syscalls.cc (seteuid): Ditto. Eliminate redundant conditional.
* uinfo.cc (internal_getlogin): Ditto.
* spawn.cc (spawn_guts) Revert previous patch.
2001-05-16 03:23:31 +08:00
|
|
|
well_known_world_sid,
|
|
|
|
acl_len, inheritance))
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
/* Set AclSize to computed value. */
|
|
|
|
acl->AclSize = acl_len;
|
|
|
|
debug_printf ("ACL-Size: %d", acl_len);
|
|
|
|
/* Create DACL for local security descriptor. */
|
2011-04-28 23:54:47 +08:00
|
|
|
status = RtlSetDaclSecurityDescriptor (&sd, TRUE, acl, FALSE);
|
|
|
|
if (!NT_SUCCESS (status))
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2011-04-28 23:54:47 +08:00
|
|
|
__seterrno_from_nt_status (status);
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
}
|
2003-11-26 21:23:27 +08:00
|
|
|
/* Make self relative security descriptor in sd_ret. */
|
|
|
|
DWORD sd_size = 0;
|
2011-04-29 18:38:12 +08:00
|
|
|
RtlAbsoluteToSelfRelativeSD (&sd, sd_ret, &sd_size);
|
2001-04-20 21:02:32 +08:00
|
|
|
if (sd_size <= 0)
|
|
|
|
{
|
|
|
|
__seterrno ();
|
|
|
|
return -1;
|
|
|
|
}
|
2004-01-20 17:13:20 +08:00
|
|
|
if (!sd_ret.realloc (sd_size))
|
|
|
|
{
|
|
|
|
set_errno (ENOMEM);
|
|
|
|
return -1;
|
|
|
|
}
|
2011-04-29 18:38:12 +08:00
|
|
|
status = RtlAbsoluteToSelfRelativeSD (&sd, sd_ret, &sd_size);
|
|
|
|
if (!NT_SUCCESS (status))
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2011-04-29 18:38:12 +08:00
|
|
|
__seterrno_from_nt_status (status);
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
}
|
2003-11-26 21:23:27 +08:00
|
|
|
debug_printf ("Created SD-Size: %d", sd_ret.size ());
|
2009-04-09 17:19:03 +08:00
|
|
|
return set_file_sd (handle, pc, sd_ret, false);
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
|
|
|
|
2002-11-25 02:58:47 +08:00
|
|
|
/* Temporary access denied bits */
|
|
|
|
#define DENY_R 040000
|
|
|
|
#define DENY_W 020000
|
|
|
|
#define DENY_X 010000
|
|
|
|
|
2001-04-20 21:02:32 +08:00
|
|
|
static void
|
2003-02-06 00:15:22 +08:00
|
|
|
getace (__aclent32_t &acl, int type, int id, DWORD win_ace_mask,
|
2003-01-26 14:42:40 +08:00
|
|
|
DWORD win_ace_type)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
acl.a_type = type;
|
|
|
|
acl.a_id = id;
|
|
|
|
|
2003-11-26 18:52:21 +08:00
|
|
|
if ((win_ace_mask & FILE_READ_BITS) && !(acl.a_perm & (S_IROTH | DENY_R)))
|
2008-09-11 12:34:24 +08:00
|
|
|
{
|
|
|
|
if (win_ace_type == ACCESS_ALLOWED_ACE_TYPE)
|
|
|
|
acl.a_perm |= S_IROTH;
|
|
|
|
else if (win_ace_type == ACCESS_DENIED_ACE_TYPE)
|
|
|
|
acl.a_perm |= DENY_R;
|
|
|
|
}
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2003-11-26 18:52:21 +08:00
|
|
|
if ((win_ace_mask & FILE_WRITE_BITS) && !(acl.a_perm & (S_IWOTH | DENY_W)))
|
2008-09-11 12:34:24 +08:00
|
|
|
{
|
|
|
|
if (win_ace_type == ACCESS_ALLOWED_ACE_TYPE)
|
|
|
|
acl.a_perm |= S_IWOTH;
|
|
|
|
else if (win_ace_type == ACCESS_DENIED_ACE_TYPE)
|
|
|
|
acl.a_perm |= DENY_W;
|
|
|
|
}
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2003-11-26 18:52:21 +08:00
|
|
|
if ((win_ace_mask & FILE_EXEC_BITS) && !(acl.a_perm & (S_IXOTH | DENY_X)))
|
2008-09-11 12:34:24 +08:00
|
|
|
{
|
|
|
|
if (win_ace_type == ACCESS_ALLOWED_ACE_TYPE)
|
|
|
|
acl.a_perm |= S_IXOTH;
|
|
|
|
else if (win_ace_type == ACCESS_DENIED_ACE_TYPE)
|
|
|
|
acl.a_perm |= DENY_X;
|
|
|
|
}
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
|
|
|
|
2004-04-15 00:36:26 +08:00
|
|
|
int
|
2007-07-20 22:29:43 +08:00
|
|
|
getacl (HANDLE handle, path_conv &pc, int nentries, __aclent32_t *aclbufp)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2003-11-26 21:23:27 +08:00
|
|
|
security_descriptor sd;
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2010-09-10 17:32:13 +08:00
|
|
|
if (get_file_sd (handle, pc, sd, false))
|
2007-07-20 22:29:43 +08:00
|
|
|
return -1;
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2003-02-06 00:15:22 +08:00
|
|
|
cygpsid owner_sid;
|
|
|
|
cygpsid group_sid;
|
2011-04-28 17:53:11 +08:00
|
|
|
NTSTATUS status;
|
|
|
|
BOOLEAN dummy;
|
2002-05-29 23:04:29 +08:00
|
|
|
__uid32_t uid;
|
Change internal gid datatype from __gid16_t to __gid32_t
throughout.
* cygwin.din: Export new symbols chown32, fchown32, getegid32,
getgid32, getgrgid32, getgrnam32, getgroups32, initgroups32, lchown32,
setgid32, setegid32, getgrent32.
* grp.cc (grp32togrp16): New static function.
(getgrgid32): New function.
(getgrnam32): Ditto.
(getgrent32): Ditto.
(getgroups32): Change name of internal function from getgroups.
(getgroups32): New function.
(initgroups32): Ditto.
* syscalls.cc (chown32): Ditto.
(lchown32): Ditto.
(fchown32): Ditto.
(setegid32): Ditto.
(setgid32): Ditto.
* uinfo.cc (getgid32): Ditto.
(getegid32): Ditto.
* include/cygwin/grp.h: Remove declaration of getgrgid() and getgrnam().
Declare getgrgid32() and getgrnam32() instead. Declare getgid32().
2002-05-28 22:10:55 +08:00
|
|
|
__gid32_t gid;
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2011-04-28 17:53:11 +08:00
|
|
|
status = RtlGetOwnerSecurityDescriptor (sd, (PSID *) &owner_sid, &dummy);
|
|
|
|
if (!NT_SUCCESS (status))
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2011-04-28 17:53:11 +08:00
|
|
|
__seterrno_from_nt_status (status);
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
}
|
2003-02-06 00:15:22 +08:00
|
|
|
uid = owner_sid.get_uid ();
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2011-04-28 17:53:11 +08:00
|
|
|
status = RtlGetGroupSecurityDescriptor (sd, (PSID *) &group_sid, &dummy);
|
|
|
|
if (!NT_SUCCESS (status))
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2011-04-28 17:53:11 +08:00
|
|
|
__seterrno_from_nt_status (status);
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
}
|
2003-02-06 00:15:22 +08:00
|
|
|
gid = group_sid.get_gid ();
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2003-02-06 00:15:22 +08:00
|
|
|
__aclent32_t lacl[MAX_ACL_ENTRIES];
|
|
|
|
memset (&lacl, 0, MAX_ACL_ENTRIES * sizeof (__aclent32_t));
|
2001-04-20 21:02:32 +08:00
|
|
|
lacl[0].a_type = USER_OBJ;
|
|
|
|
lacl[0].a_id = uid;
|
|
|
|
lacl[1].a_type = GROUP_OBJ;
|
|
|
|
lacl[1].a_id = gid;
|
|
|
|
lacl[2].a_type = OTHER_OBJ;
|
2002-11-25 02:58:47 +08:00
|
|
|
lacl[2].a_id = ILLEGAL_GID;
|
|
|
|
lacl[3].a_type = CLASS_OBJ;
|
|
|
|
lacl[3].a_id = ILLEGAL_GID;
|
|
|
|
lacl[3].a_perm = S_IROTH | S_IWOTH | S_IXOTH;
|
2001-04-20 21:02:32 +08:00
|
|
|
|
|
|
|
PACL acl;
|
2011-04-28 17:53:11 +08:00
|
|
|
BOOLEAN acl_exists;
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2011-04-28 17:53:11 +08:00
|
|
|
status = RtlGetDaclSecurityDescriptor (sd, &acl_exists, &acl, &dummy);
|
|
|
|
if (!NT_SUCCESS (status))
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2011-04-28 17:53:11 +08:00
|
|
|
__seterrno_from_nt_status (status);
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2002-11-25 02:58:47 +08:00
|
|
|
int pos, i, types_def = 0;
|
2001-04-20 21:02:32 +08:00
|
|
|
|
|
|
|
if (!acl_exists || !acl)
|
2002-11-25 02:58:47 +08:00
|
|
|
for (pos = 0; pos < 3; ++pos) /* Don't change CLASS_OBJ entry */
|
|
|
|
lacl[pos].a_perm = S_IROTH | S_IWOTH | S_IXOTH;
|
|
|
|
else
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2002-11-25 02:58:47 +08:00
|
|
|
for (i = 0; i < acl->AceCount; ++i)
|
|
|
|
{
|
|
|
|
ACCESS_ALLOWED_ACE *ace;
|
2002-12-12 11:09:38 +08:00
|
|
|
|
2011-04-28 17:30:36 +08:00
|
|
|
if (!NT_SUCCESS (RtlGetAce (acl, i, (PVOID *) &ace)))
|
2002-11-25 02:58:47 +08:00
|
|
|
continue;
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2003-02-06 00:15:22 +08:00
|
|
|
cygpsid ace_sid ((PSID) &ace->SidStart);
|
2002-11-25 02:58:47 +08:00
|
|
|
int id;
|
|
|
|
int type = 0;
|
2001-04-20 21:02:32 +08:00
|
|
|
|
2002-11-25 02:58:47 +08:00
|
|
|
if (ace_sid == well_known_world_sid)
|
|
|
|
{
|
|
|
|
type = OTHER_OBJ;
|
|
|
|
id = ILLEGAL_GID;
|
|
|
|
}
|
|
|
|
else if (ace_sid == group_sid)
|
|
|
|
{
|
|
|
|
type = GROUP_OBJ;
|
|
|
|
id = gid;
|
|
|
|
}
|
|
|
|
else if (ace_sid == owner_sid)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2002-11-25 02:58:47 +08:00
|
|
|
type = USER_OBJ;
|
|
|
|
id = uid;
|
|
|
|
}
|
2003-01-12 19:38:51 +08:00
|
|
|
else if (ace_sid == well_known_creator_group_sid)
|
|
|
|
{
|
|
|
|
type = GROUP_OBJ | ACL_DEFAULT;
|
2010-12-15 22:11:03 +08:00
|
|
|
types_def |= type;
|
2003-01-12 19:38:51 +08:00
|
|
|
id = ILLEGAL_GID;
|
|
|
|
}
|
|
|
|
else if (ace_sid == well_known_creator_owner_sid)
|
|
|
|
{
|
|
|
|
type = USER_OBJ | ACL_DEFAULT;
|
2010-12-15 22:11:03 +08:00
|
|
|
types_def |= type;
|
2003-01-12 19:38:51 +08:00
|
|
|
id = ILLEGAL_GID;
|
|
|
|
}
|
2002-11-25 02:58:47 +08:00
|
|
|
else
|
2003-12-08 06:37:12 +08:00
|
|
|
id = ace_sid.get_id (true, &type);
|
2003-02-06 00:15:22 +08:00
|
|
|
|
2002-11-25 02:58:47 +08:00
|
|
|
if (!type)
|
|
|
|
continue;
|
2009-10-31 03:58:53 +08:00
|
|
|
if (!(ace->Header.AceFlags & INHERIT_ONLY_ACE || type & ACL_DEFAULT))
|
2002-11-25 02:58:47 +08:00
|
|
|
{
|
|
|
|
if ((pos = searchace (lacl, MAX_ACL_ENTRIES, type, id)) >= 0)
|
|
|
|
getace (lacl[pos], type, id, ace->Mask, ace->Header.AceType);
|
|
|
|
}
|
2009-10-31 03:58:53 +08:00
|
|
|
if ((ace->Header.AceFlags
|
|
|
|
& (CONTAINER_INHERIT_ACE | OBJECT_INHERIT_ACE))
|
2007-07-20 22:29:43 +08:00
|
|
|
&& pc.isdir ())
|
2002-11-25 02:58:47 +08:00
|
|
|
{
|
2003-01-12 19:38:51 +08:00
|
|
|
if (type == USER_OBJ)
|
|
|
|
type = USER;
|
|
|
|
else if (type == GROUP_OBJ)
|
|
|
|
type = GROUP;
|
2002-11-25 02:58:47 +08:00
|
|
|
type |= ACL_DEFAULT;
|
|
|
|
types_def |= type;
|
|
|
|
if ((pos = searchace (lacl, MAX_ACL_ENTRIES, type, id)) >= 0)
|
|
|
|
getace (lacl[pos], type, id, ace->Mask, ace->Header.AceType);
|
|
|
|
}
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
2010-12-15 22:11:03 +08:00
|
|
|
if (types_def && (pos = searchace (lacl, MAX_ACL_ENTRIES, 0)) >= 0)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2010-12-15 22:11:03 +08:00
|
|
|
/* Ensure that the default acl contains at
|
|
|
|
least DEF_(USER|GROUP|OTHER)_OBJ entries. */
|
|
|
|
if (!(types_def & USER_OBJ))
|
|
|
|
{
|
|
|
|
lacl[pos].a_type = DEF_USER_OBJ;
|
|
|
|
lacl[pos].a_id = uid;
|
|
|
|
lacl[pos].a_perm = lacl[0].a_perm;
|
|
|
|
pos++;
|
|
|
|
}
|
|
|
|
if (!(types_def & GROUP_OBJ) && pos < MAX_ACL_ENTRIES)
|
|
|
|
{
|
|
|
|
lacl[pos].a_type = DEF_GROUP_OBJ;
|
|
|
|
lacl[pos].a_id = gid;
|
|
|
|
lacl[pos].a_perm = lacl[1].a_perm;
|
|
|
|
pos++;
|
|
|
|
}
|
|
|
|
if (!(types_def & OTHER_OBJ) && pos < MAX_ACL_ENTRIES)
|
|
|
|
{
|
|
|
|
lacl[pos].a_type = DEF_OTHER_OBJ;
|
|
|
|
lacl[pos].a_id = ILLEGAL_GID;
|
|
|
|
lacl[pos].a_perm = lacl[2].a_perm;
|
|
|
|
pos++;
|
|
|
|
}
|
|
|
|
/* Include DEF_CLASS_OBJ if any named default ace exists. */
|
|
|
|
if ((types_def & (USER|GROUP)) && pos < MAX_ACL_ENTRIES)
|
|
|
|
{
|
|
|
|
lacl[pos].a_type = DEF_CLASS_OBJ;
|
|
|
|
lacl[pos].a_id = ILLEGAL_GID;
|
|
|
|
lacl[pos].a_perm = S_IROTH | S_IWOTH | S_IXOTH;
|
|
|
|
}
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
|
|
|
}
|
|
|
|
if ((pos = searchace (lacl, MAX_ACL_ENTRIES, 0)) < 0)
|
|
|
|
pos = MAX_ACL_ENTRIES;
|
2002-11-25 02:58:47 +08:00
|
|
|
if (aclbufp) {
|
2003-02-06 00:15:22 +08:00
|
|
|
if (owner_sid == group_sid)
|
2002-11-25 02:58:47 +08:00
|
|
|
lacl[0].a_perm = lacl[1].a_perm;
|
|
|
|
if (pos > nentries)
|
2002-11-25 19:23:21 +08:00
|
|
|
{
|
2003-01-26 14:42:40 +08:00
|
|
|
set_errno (ENOSPC);
|
2002-11-25 19:23:21 +08:00
|
|
|
return -1;
|
|
|
|
}
|
2003-02-06 00:15:22 +08:00
|
|
|
memcpy (aclbufp, lacl, pos * sizeof (__aclent32_t));
|
2002-11-25 02:58:47 +08:00
|
|
|
for (i = 0; i < pos; ++i)
|
|
|
|
aclbufp[i].a_perm &= ~(DENY_R | DENY_W | DENY_X);
|
2003-02-06 00:15:22 +08:00
|
|
|
aclsort32 (pos, 0, aclbufp);
|
2002-11-25 02:58:47 +08:00
|
|
|
}
|
2011-12-04 05:43:27 +08:00
|
|
|
syscall_printf ("%R = getacl(%S)", pos, pc.get_nt_native_path ());
|
2001-04-20 21:02:32 +08:00
|
|
|
return pos;
|
|
|
|
}
|
|
|
|
|
2010-09-13 03:43:55 +08:00
|
|
|
extern "C" int
|
|
|
|
acl32 (const char *path, int cmd, int nentries, __aclent32_t *aclbufp)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2004-04-15 00:36:26 +08:00
|
|
|
int res = -1;
|
2010-09-13 03:43:55 +08:00
|
|
|
|
|
|
|
fhandler_base *fh = build_fh_name (path, PC_SYM_FOLLOW | PC_KEEP_HANDLE,
|
2010-06-15 20:05:15 +08:00
|
|
|
stat_suffixes);
|
2012-03-29 23:01:18 +08:00
|
|
|
if (!fh || !fh->exists ())
|
|
|
|
set_errno (ENOENT);
|
|
|
|
else if (fh->error ())
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2004-04-15 00:36:26 +08:00
|
|
|
debug_printf ("got %d error from build_fh_name", fh->error ());
|
|
|
|
set_errno (fh->error ());
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
2004-04-15 00:36:26 +08:00
|
|
|
else
|
|
|
|
res = fh->facl (cmd, nentries, aclbufp);
|
2004-04-15 05:11:45 +08:00
|
|
|
|
|
|
|
delete fh;
|
2011-12-04 05:43:27 +08:00
|
|
|
syscall_printf ("%R = acl(%s)", res, path);
|
2004-04-15 00:36:26 +08:00
|
|
|
return res;
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
lacl32 (const char *path, int cmd, int nentries, __aclent32_t *aclbufp)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2010-09-13 03:43:55 +08:00
|
|
|
/* This call was an accident. Make it absolutely clear. */
|
|
|
|
set_errno (ENOSYS);
|
|
|
|
return -1;
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
facl32 (int fd, int cmd, int nentries, __aclent32_t *aclbufp)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2001-10-16 07:39:33 +08:00
|
|
|
cygheap_fdget cfd (fd);
|
|
|
|
if (cfd < 0)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
syscall_printf ("-1 = facl (%d)", fd);
|
|
|
|
return -1;
|
|
|
|
}
|
2004-04-15 00:36:26 +08:00
|
|
|
int res = cfd->facl (cmd, nentries, aclbufp);
|
2011-12-04 05:43:27 +08:00
|
|
|
syscall_printf ("%R = facl(%s) )", res, cfd->get_name ());
|
2004-04-15 00:36:26 +08:00
|
|
|
return res;
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
aclcheck32 (__aclent32_t *aclbufp, int nentries, int *which)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2003-12-08 06:37:12 +08:00
|
|
|
bool has_user_obj = false;
|
|
|
|
bool has_group_obj = false;
|
|
|
|
bool has_other_obj = false;
|
|
|
|
bool has_class_obj = false;
|
|
|
|
bool has_ug_objs = false;
|
|
|
|
bool has_def_user_obj = false;
|
|
|
|
bool has_def_group_obj = false;
|
|
|
|
bool has_def_other_obj = false;
|
|
|
|
bool has_def_class_obj = false;
|
|
|
|
bool has_def_ug_objs = false;
|
2001-04-20 21:02:32 +08:00
|
|
|
int pos2;
|
|
|
|
|
|
|
|
for (int pos = 0; pos < nentries; ++pos)
|
|
|
|
switch (aclbufp[pos].a_type)
|
|
|
|
{
|
|
|
|
case USER_OBJ:
|
|
|
|
if (has_user_obj)
|
|
|
|
{
|
|
|
|
if (which)
|
|
|
|
*which = pos;
|
|
|
|
return USER_ERROR;
|
|
|
|
}
|
2003-12-08 06:37:12 +08:00
|
|
|
has_user_obj = true;
|
2001-04-20 21:02:32 +08:00
|
|
|
break;
|
|
|
|
case GROUP_OBJ:
|
|
|
|
if (has_group_obj)
|
|
|
|
{
|
|
|
|
if (which)
|
|
|
|
*which = pos;
|
|
|
|
return GRP_ERROR;
|
|
|
|
}
|
2003-12-08 06:37:12 +08:00
|
|
|
has_group_obj = true;
|
2001-04-20 21:02:32 +08:00
|
|
|
break;
|
|
|
|
case OTHER_OBJ:
|
|
|
|
if (has_other_obj)
|
|
|
|
{
|
|
|
|
if (which)
|
|
|
|
*which = pos;
|
|
|
|
return OTHER_ERROR;
|
|
|
|
}
|
2003-12-08 06:37:12 +08:00
|
|
|
has_other_obj = true;
|
2001-04-20 21:02:32 +08:00
|
|
|
break;
|
|
|
|
case CLASS_OBJ:
|
|
|
|
if (has_class_obj)
|
|
|
|
{
|
|
|
|
if (which)
|
|
|
|
*which = pos;
|
|
|
|
return CLASS_ERROR;
|
|
|
|
}
|
2003-12-08 06:37:12 +08:00
|
|
|
has_class_obj = true;
|
2001-04-20 21:02:32 +08:00
|
|
|
break;
|
|
|
|
case USER:
|
|
|
|
case GROUP:
|
|
|
|
if ((pos2 = searchace (aclbufp + pos + 1, nentries - pos - 1,
|
|
|
|
aclbufp[pos].a_type, aclbufp[pos].a_id)) >= 0)
|
|
|
|
{
|
|
|
|
if (which)
|
|
|
|
*which = pos2;
|
|
|
|
return DUPLICATE_ERROR;
|
|
|
|
}
|
2003-12-08 06:37:12 +08:00
|
|
|
has_ug_objs = true;
|
2001-04-20 21:02:32 +08:00
|
|
|
break;
|
|
|
|
case DEF_USER_OBJ:
|
|
|
|
if (has_def_user_obj)
|
|
|
|
{
|
|
|
|
if (which)
|
|
|
|
*which = pos;
|
|
|
|
return USER_ERROR;
|
|
|
|
}
|
2003-12-08 06:37:12 +08:00
|
|
|
has_def_user_obj = true;
|
2001-04-20 21:02:32 +08:00
|
|
|
break;
|
|
|
|
case DEF_GROUP_OBJ:
|
|
|
|
if (has_def_group_obj)
|
|
|
|
{
|
|
|
|
if (which)
|
|
|
|
*which = pos;
|
|
|
|
return GRP_ERROR;
|
|
|
|
}
|
2003-12-08 06:37:12 +08:00
|
|
|
has_def_group_obj = true;
|
2001-04-20 21:02:32 +08:00
|
|
|
break;
|
|
|
|
case DEF_OTHER_OBJ:
|
|
|
|
if (has_def_other_obj)
|
|
|
|
{
|
|
|
|
if (which)
|
|
|
|
*which = pos;
|
|
|
|
return OTHER_ERROR;
|
|
|
|
}
|
2003-12-08 06:37:12 +08:00
|
|
|
has_def_other_obj = true;
|
2001-04-20 21:02:32 +08:00
|
|
|
break;
|
|
|
|
case DEF_CLASS_OBJ:
|
|
|
|
if (has_def_class_obj)
|
|
|
|
{
|
|
|
|
if (which)
|
|
|
|
*which = pos;
|
|
|
|
return CLASS_ERROR;
|
|
|
|
}
|
2003-12-08 06:37:12 +08:00
|
|
|
has_def_class_obj = true;
|
2001-04-20 21:02:32 +08:00
|
|
|
break;
|
|
|
|
case DEF_USER:
|
|
|
|
case DEF_GROUP:
|
|
|
|
if ((pos2 = searchace (aclbufp + pos + 1, nentries - pos - 1,
|
|
|
|
aclbufp[pos].a_type, aclbufp[pos].a_id)) >= 0)
|
|
|
|
{
|
|
|
|
if (which)
|
|
|
|
*which = pos2;
|
|
|
|
return DUPLICATE_ERROR;
|
|
|
|
}
|
2003-12-08 06:37:12 +08:00
|
|
|
has_def_ug_objs = true;
|
2001-04-20 21:02:32 +08:00
|
|
|
break;
|
|
|
|
default:
|
|
|
|
return ENTRY_ERROR;
|
|
|
|
}
|
|
|
|
if (!has_user_obj
|
|
|
|
|| !has_group_obj
|
|
|
|
|| !has_other_obj
|
|
|
|
#if 0
|
|
|
|
/* These checks are not ok yet since CLASS_OBJ isn't fully implemented. */
|
|
|
|
|| (has_ug_objs && !has_class_obj)
|
|
|
|
|| (has_def_ug_objs && !has_def_class_obj)
|
|
|
|
#endif
|
|
|
|
)
|
|
|
|
{
|
|
|
|
if (which)
|
|
|
|
*which = -1;
|
|
|
|
return MISS_ERROR;
|
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
static int
|
|
|
|
acecmp (const void *a1, const void *a2)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2003-02-06 00:15:22 +08:00
|
|
|
#define ace(i) ((const __aclent32_t *) a##i)
|
2002-09-22 11:38:57 +08:00
|
|
|
int ret = ace (1)->a_type - ace (2)->a_type;
|
2001-04-20 21:02:32 +08:00
|
|
|
if (!ret)
|
2002-09-22 11:38:57 +08:00
|
|
|
ret = ace (1)->a_id - ace (2)->a_id;
|
2001-04-20 21:02:32 +08:00
|
|
|
return ret;
|
|
|
|
#undef ace
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
aclsort32 (int nentries, int, __aclent32_t *aclbufp)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2003-02-06 00:15:22 +08:00
|
|
|
if (aclcheck32 (aclbufp, nentries, NULL))
|
2001-04-20 21:02:32 +08:00
|
|
|
return -1;
|
|
|
|
if (!aclbufp || nentries < 1)
|
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return -1;
|
|
|
|
}
|
2003-02-06 00:15:22 +08:00
|
|
|
qsort ((void *) aclbufp, nentries, sizeof (__aclent32_t), acecmp);
|
2001-04-20 21:02:32 +08:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
acltomode32 (__aclent32_t *aclbufp, int nentries, mode_t *modep)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
int pos;
|
|
|
|
|
|
|
|
if (!aclbufp || nentries < 1 || !modep)
|
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
*modep = 0;
|
2002-11-25 02:58:47 +08:00
|
|
|
if ((pos = searchace (aclbufp, nentries, USER_OBJ)) < 0
|
|
|
|
|| !aclbufp[pos].a_type)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return -1;
|
|
|
|
}
|
2002-11-25 02:58:47 +08:00
|
|
|
*modep |= (aclbufp[pos].a_perm & S_IRWXO) << 6;
|
|
|
|
if ((pos = searchace (aclbufp, nentries, GROUP_OBJ)) < 0
|
|
|
|
|| !aclbufp[pos].a_type)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return -1;
|
|
|
|
}
|
2002-11-25 02:58:47 +08:00
|
|
|
*modep |= (aclbufp[pos].a_perm & S_IRWXO) << 3;
|
|
|
|
int cpos;
|
|
|
|
if ((cpos = searchace (aclbufp, nentries, CLASS_OBJ)) >= 0
|
|
|
|
&& aclbufp[cpos].a_type == CLASS_OBJ)
|
|
|
|
*modep |= ((aclbufp[pos].a_perm & S_IRWXO) & aclbufp[cpos].a_perm) << 3;
|
|
|
|
if ((pos = searchace (aclbufp, nentries, OTHER_OBJ)) < 0
|
|
|
|
|| !aclbufp[pos].a_type)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return -1;
|
|
|
|
}
|
2002-11-25 02:58:47 +08:00
|
|
|
*modep |= aclbufp[pos].a_perm & S_IRWXO;
|
2001-04-20 21:02:32 +08:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
aclfrommode32 (__aclent32_t *aclbufp, int nentries, mode_t *modep)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
int pos;
|
|
|
|
|
|
|
|
if (!aclbufp || nentries < 1 || !modep)
|
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return -1;
|
|
|
|
}
|
2002-11-25 02:58:47 +08:00
|
|
|
if ((pos = searchace (aclbufp, nentries, USER_OBJ)) < 0
|
|
|
|
|| !aclbufp[pos].a_type)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return -1;
|
|
|
|
}
|
2002-11-25 02:58:47 +08:00
|
|
|
aclbufp[pos].a_perm = (*modep & S_IRWXU) >> 6;
|
|
|
|
if ((pos = searchace (aclbufp, nentries, GROUP_OBJ)) < 0
|
|
|
|
|| !aclbufp[pos].a_type)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return -1;
|
|
|
|
}
|
2002-11-25 02:58:47 +08:00
|
|
|
aclbufp[pos].a_perm = (*modep & S_IRWXG) >> 3;
|
|
|
|
if ((pos = searchace (aclbufp, nentries, CLASS_OBJ)) >= 0
|
|
|
|
&& aclbufp[pos].a_type == CLASS_OBJ)
|
|
|
|
aclbufp[pos].a_perm = (*modep & S_IRWXG) >> 3;
|
|
|
|
if ((pos = searchace (aclbufp, nentries, OTHER_OBJ)) < 0
|
|
|
|
|| !aclbufp[pos].a_type)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return -1;
|
|
|
|
}
|
2002-11-25 02:58:47 +08:00
|
|
|
aclbufp[pos].a_perm = (*modep & S_IRWXO);
|
2001-04-20 21:02:32 +08:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
acltopbits32 (__aclent32_t *aclbufp, int nentries, mode_t *pbitsp)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2003-02-06 00:15:22 +08:00
|
|
|
return acltomode32 (aclbufp, nentries, pbitsp);
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
aclfrompbits32 (__aclent32_t *aclbufp, int nentries, mode_t *pbitsp)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
2003-02-06 00:15:22 +08:00
|
|
|
return aclfrommode32 (aclbufp, nentries, pbitsp);
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
static char *
|
|
|
|
permtostr (mode_t perm)
|
|
|
|
{
|
|
|
|
static char pbuf[4];
|
|
|
|
|
2002-11-25 02:58:47 +08:00
|
|
|
pbuf[0] = (perm & S_IROTH) ? 'r' : '-';
|
|
|
|
pbuf[1] = (perm & S_IWOTH) ? 'w' : '-';
|
|
|
|
pbuf[2] = (perm & S_IXOTH) ? 'x' : '-';
|
2001-04-20 21:02:32 +08:00
|
|
|
pbuf[3] = '\0';
|
|
|
|
return pbuf;
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" char *
|
2003-02-06 00:15:22 +08:00
|
|
|
acltotext32 (__aclent32_t *aclbufp, int aclcnt)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
if (!aclbufp || aclcnt < 1 || aclcnt > MAX_ACL_ENTRIES
|
2003-02-06 00:15:22 +08:00
|
|
|
|| aclcheck32 (aclbufp, aclcnt, NULL))
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
char buf[32000];
|
|
|
|
buf[0] = '\0';
|
2003-12-08 06:37:12 +08:00
|
|
|
bool first = true;
|
2001-04-20 21:02:32 +08:00
|
|
|
|
|
|
|
for (int pos = 0; pos < aclcnt; ++pos)
|
|
|
|
{
|
|
|
|
if (!first)
|
|
|
|
strcat (buf, ",");
|
2003-12-08 06:37:12 +08:00
|
|
|
first = false;
|
2001-04-20 21:02:32 +08:00
|
|
|
if (aclbufp[pos].a_type & ACL_DEFAULT)
|
|
|
|
strcat (buf, "default");
|
2006-07-18 22:11:38 +08:00
|
|
|
switch (aclbufp[pos].a_type & ~ACL_DEFAULT)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
case USER_OBJ:
|
|
|
|
__small_sprintf (buf + strlen (buf), "user::%s",
|
|
|
|
permtostr (aclbufp[pos].a_perm));
|
|
|
|
break;
|
|
|
|
case USER:
|
|
|
|
__small_sprintf (buf + strlen (buf), "user:%d:%s",
|
|
|
|
aclbufp[pos].a_id, permtostr (aclbufp[pos].a_perm));
|
|
|
|
break;
|
|
|
|
case GROUP_OBJ:
|
|
|
|
__small_sprintf (buf + strlen (buf), "group::%s",
|
|
|
|
permtostr (aclbufp[pos].a_perm));
|
|
|
|
break;
|
|
|
|
case GROUP:
|
|
|
|
__small_sprintf (buf + strlen (buf), "group:%d:%s",
|
|
|
|
aclbufp[pos].a_id, permtostr (aclbufp[pos].a_perm));
|
|
|
|
break;
|
|
|
|
case CLASS_OBJ:
|
|
|
|
__small_sprintf (buf + strlen (buf), "mask::%s",
|
|
|
|
permtostr (aclbufp[pos].a_perm));
|
|
|
|
break;
|
|
|
|
case OTHER_OBJ:
|
|
|
|
__small_sprintf (buf + strlen (buf), "other::%s",
|
|
|
|
permtostr (aclbufp[pos].a_perm));
|
|
|
|
break;
|
|
|
|
default:
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return strdup (buf);
|
|
|
|
}
|
|
|
|
|
|
|
|
static mode_t
|
|
|
|
permfromstr (char *perm)
|
|
|
|
{
|
|
|
|
mode_t mode = 0;
|
|
|
|
|
|
|
|
if (strlen (perm) != 3)
|
|
|
|
return 01000;
|
|
|
|
if (perm[0] == 'r')
|
2002-11-25 02:58:47 +08:00
|
|
|
mode |= S_IROTH;
|
2001-04-20 21:02:32 +08:00
|
|
|
else if (perm[0] != '-')
|
|
|
|
return 01000;
|
|
|
|
if (perm[1] == 'w')
|
2002-11-25 02:58:47 +08:00
|
|
|
mode |= S_IWOTH;
|
2001-04-20 21:02:32 +08:00
|
|
|
else if (perm[1] != '-')
|
|
|
|
return 01000;
|
|
|
|
if (perm[2] == 'x')
|
2002-11-25 02:58:47 +08:00
|
|
|
mode |= S_IXOTH;
|
2001-04-20 21:02:32 +08:00
|
|
|
else if (perm[2] != '-')
|
|
|
|
return 01000;
|
|
|
|
return mode;
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" __aclent32_t *
|
2003-02-06 00:15:22 +08:00
|
|
|
aclfromtext32 (char *acltextp, int *)
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
if (!acltextp)
|
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
char buf[strlen (acltextp) + 1];
|
2003-02-06 00:15:22 +08:00
|
|
|
__aclent32_t lacl[MAX_ACL_ENTRIES];
|
2001-04-20 21:02:32 +08:00
|
|
|
memset (lacl, 0, sizeof lacl);
|
|
|
|
int pos = 0;
|
|
|
|
strcpy (buf, acltextp);
|
|
|
|
char *lasts;
|
|
|
|
for (char *c = strtok_r (buf, ",", &lasts);
|
|
|
|
c;
|
|
|
|
c = strtok_r (NULL, ",", &lasts))
|
|
|
|
{
|
|
|
|
if (!strncmp (c, "default", 7))
|
|
|
|
{
|
|
|
|
lacl[pos].a_type |= ACL_DEFAULT;
|
|
|
|
c += 7;
|
|
|
|
}
|
|
|
|
if (!strncmp (c, "user:", 5))
|
|
|
|
{
|
|
|
|
if (c[5] == ':')
|
|
|
|
lacl[pos].a_type |= USER_OBJ;
|
|
|
|
else
|
|
|
|
{
|
|
|
|
lacl[pos].a_type |= USER;
|
|
|
|
c += 5;
|
|
|
|
if (isalpha (*c))
|
|
|
|
{
|
2002-12-10 Pierre Humblet <pierre.humblet@ieee.org>
* pwdgrp.h (pwdgrp_check::pwdgrp_state): Replace by
pwdgrp_check::isinitializing ().
(pwdgrp_check::isinitializing): Create.
* passwd.cc (grab_int): Change type to unsigned, use strtoul and
set the pointer content to 0 if the field is invalid.
(parse_pwd): Move validity test after getting pw_gid.
(read_etc_passwd): Replace "passwd_state <= " by
passwd_state::isinitializing ().
(internal_getpwuid): Ditto.
(internal_getpwnam): Ditto.
(getpwent): Ditto.
(getpass): Ditto.
* grp.cc (parse_grp): Use strtoul for gr_gid and verify the validity.
(read_etc_group): Replace "group_state <= " by
group_state::isinitializing ().
(internal_getgrgid): Ditto.
(getgrent32): Ditto.
(internal_getgrent): Ditto.
2002-12-10 Pierre Humblet <pierre.humblet@ieee.org>
* security.h: Move declarations of internal_getgrent,
internal_getpwsid and internal_getgrsid to pwdgrp.h.
* pwdgrp.h: Declare internal_getpwsid, internal_getpwnam,
internal_getpwuid, internal_getgrsid, internal_getgrgid,
internal_getgrnam, internal_getgrent and internal_getgroups.
Delete "emulated" from enum pwdgrp_state.
(pwdgrp_check::isuninitialized): Create.
(pwdgrp_check::pwdgrp_state): Change state to initializing
rather than to uninitialized.
(pwdgrp_read::gets): Remove trailing CRs.
* passwd.cc (grab_string): Don't look for NLs.
(grab_int): Ditto.
(parse_pwd): Don't look for CRs. Return 0 if entry is too short.
(search_for): Delete.
(read_etc_passwd): Simplify tests to actually read the file.
Set state to loaded before making internal_getpwXX calls.
Replace search_for calls by equivalent internal_pwgetXX calls.
(internal_getpwsid): Use passwd_state.isuninitialized to decide
to call read_etc_passwd.
(internal_getpwuid): Create.
(internal_getpwnam): Create.
(getpwuid32): Simply call internal_getpwuid.
(getpwuid_r32): Call internal_getpwuid.
(getpwnam): Simply call internal_getpwnam.
(getpwnam_r): Call internal_getpwnam.
* grp.cc (parse_grp): Don't look for CRs. Adjust blank space.
(add_grp_line): Adjust blank space.
(class group_lock): Ditto.
(read_etc_group): Simplify tests to actually read the file.
Set state to loaded before making internal_getgrXX calls.
Replace getgrXX calls by equivalent internal calls.
(internal_getgrsid): Use group_state.isuninitialized to decide
to call read_etc_group.
(internal_getgrgid): Create.
(internal_getgrnam): Create.
(getgroups32): Simply call internal_getgrgid.
(getgrnam32): Simply call internal_getgrnam.
(internal_getgrent): Call group_state.isuninitialized.
(internal_getgroups): Create from the former getgroups32, using
two of the four arguments. Set gid to myself->gid and username
to cygheap->user.name ().
(getgroups32): Simply call internal_getgroup.
(getgroups): Call internal_getgroup instead of getgroups32.
(setgroups32): Call internal versions of get{pw,gr}XX.
* sec_helper.cc: Include pwdgrp.h.
(is_grp_member): Call internal versions of get{pw,gr}XX.
* security.cc: Include pwdgrp.h.
(alloc_sd): Call internal versions of get{pw,gr}XX.
* syscalls.cc: Include pwdgrp.h.
(seteuid32): Call internal versions of get{pw,gr}XX.
(setegid32): Ditto.
* uinfo.cc: Include pwdgrp.h.
(internal_getlogin): Call internal versions of get{pw,gr}XX.
(cygheap_user::ontherange): Ditto.
* sec_acl.cc: Include pwdgrp.h.
(setacl): Call internal versions of get{pw,gr}XX.
(acl_access): Ditto and simplify logic.
(aclfromtext): Ditto.
2002-12-10 20:43:49 +08:00
|
|
|
struct passwd *pw = internal_getpwnam (c);
|
2001-04-20 21:02:32 +08:00
|
|
|
if (!pw)
|
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
lacl[pos].a_id = pw->pw_uid;
|
2003-02-06 00:15:22 +08:00
|
|
|
c = strechr (c, ':');
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
|
|
|
else if (isdigit (*c))
|
|
|
|
lacl[pos].a_id = strtol (c, &c, 10);
|
2003-02-06 00:15:22 +08:00
|
|
|
if (*c != ':')
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
else if (!strncmp (c, "group:", 6))
|
|
|
|
{
|
|
|
|
if (c[5] == ':')
|
|
|
|
lacl[pos].a_type |= GROUP_OBJ;
|
|
|
|
else
|
|
|
|
{
|
|
|
|
lacl[pos].a_type |= GROUP;
|
|
|
|
c += 5;
|
|
|
|
if (isalpha (*c))
|
|
|
|
{
|
2002-12-10 Pierre Humblet <pierre.humblet@ieee.org>
* pwdgrp.h (pwdgrp_check::pwdgrp_state): Replace by
pwdgrp_check::isinitializing ().
(pwdgrp_check::isinitializing): Create.
* passwd.cc (grab_int): Change type to unsigned, use strtoul and
set the pointer content to 0 if the field is invalid.
(parse_pwd): Move validity test after getting pw_gid.
(read_etc_passwd): Replace "passwd_state <= " by
passwd_state::isinitializing ().
(internal_getpwuid): Ditto.
(internal_getpwnam): Ditto.
(getpwent): Ditto.
(getpass): Ditto.
* grp.cc (parse_grp): Use strtoul for gr_gid and verify the validity.
(read_etc_group): Replace "group_state <= " by
group_state::isinitializing ().
(internal_getgrgid): Ditto.
(getgrent32): Ditto.
(internal_getgrent): Ditto.
2002-12-10 Pierre Humblet <pierre.humblet@ieee.org>
* security.h: Move declarations of internal_getgrent,
internal_getpwsid and internal_getgrsid to pwdgrp.h.
* pwdgrp.h: Declare internal_getpwsid, internal_getpwnam,
internal_getpwuid, internal_getgrsid, internal_getgrgid,
internal_getgrnam, internal_getgrent and internal_getgroups.
Delete "emulated" from enum pwdgrp_state.
(pwdgrp_check::isuninitialized): Create.
(pwdgrp_check::pwdgrp_state): Change state to initializing
rather than to uninitialized.
(pwdgrp_read::gets): Remove trailing CRs.
* passwd.cc (grab_string): Don't look for NLs.
(grab_int): Ditto.
(parse_pwd): Don't look for CRs. Return 0 if entry is too short.
(search_for): Delete.
(read_etc_passwd): Simplify tests to actually read the file.
Set state to loaded before making internal_getpwXX calls.
Replace search_for calls by equivalent internal_pwgetXX calls.
(internal_getpwsid): Use passwd_state.isuninitialized to decide
to call read_etc_passwd.
(internal_getpwuid): Create.
(internal_getpwnam): Create.
(getpwuid32): Simply call internal_getpwuid.
(getpwuid_r32): Call internal_getpwuid.
(getpwnam): Simply call internal_getpwnam.
(getpwnam_r): Call internal_getpwnam.
* grp.cc (parse_grp): Don't look for CRs. Adjust blank space.
(add_grp_line): Adjust blank space.
(class group_lock): Ditto.
(read_etc_group): Simplify tests to actually read the file.
Set state to loaded before making internal_getgrXX calls.
Replace getgrXX calls by equivalent internal calls.
(internal_getgrsid): Use group_state.isuninitialized to decide
to call read_etc_group.
(internal_getgrgid): Create.
(internal_getgrnam): Create.
(getgroups32): Simply call internal_getgrgid.
(getgrnam32): Simply call internal_getgrnam.
(internal_getgrent): Call group_state.isuninitialized.
(internal_getgroups): Create from the former getgroups32, using
two of the four arguments. Set gid to myself->gid and username
to cygheap->user.name ().
(getgroups32): Simply call internal_getgroup.
(getgroups): Call internal_getgroup instead of getgroups32.
(setgroups32): Call internal versions of get{pw,gr}XX.
* sec_helper.cc: Include pwdgrp.h.
(is_grp_member): Call internal versions of get{pw,gr}XX.
* security.cc: Include pwdgrp.h.
(alloc_sd): Call internal versions of get{pw,gr}XX.
* syscalls.cc: Include pwdgrp.h.
(seteuid32): Call internal versions of get{pw,gr}XX.
(setegid32): Ditto.
* uinfo.cc: Include pwdgrp.h.
(internal_getlogin): Call internal versions of get{pw,gr}XX.
(cygheap_user::ontherange): Ditto.
* sec_acl.cc: Include pwdgrp.h.
(setacl): Call internal versions of get{pw,gr}XX.
(acl_access): Ditto and simplify logic.
(aclfromtext): Ditto.
2002-12-10 20:43:49 +08:00
|
|
|
struct __group32 *gr = internal_getgrnam (c);
|
2001-04-20 21:02:32 +08:00
|
|
|
if (!gr)
|
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
lacl[pos].a_id = gr->gr_gid;
|
2003-02-06 00:15:22 +08:00
|
|
|
c = strechr (c, ':');
|
2001-04-20 21:02:32 +08:00
|
|
|
}
|
|
|
|
else if (isdigit (*c))
|
|
|
|
lacl[pos].a_id = strtol (c, &c, 10);
|
2003-02-06 00:15:22 +08:00
|
|
|
if (*c != ':')
|
2001-04-20 21:02:32 +08:00
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
else if (!strncmp (c, "mask:", 5))
|
|
|
|
{
|
|
|
|
if (c[5] == ':')
|
|
|
|
lacl[pos].a_type |= CLASS_OBJ;
|
|
|
|
else
|
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
else if (!strncmp (c, "other:", 6))
|
|
|
|
{
|
|
|
|
if (c[5] == ':')
|
|
|
|
lacl[pos].a_type |= OTHER_OBJ;
|
|
|
|
else
|
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if ((lacl[pos].a_perm = permfromstr (c)) == 01000)
|
|
|
|
{
|
|
|
|
set_errno (EINVAL);
|
|
|
|
return NULL;
|
|
|
|
}
|
|
|
|
++pos;
|
|
|
|
}
|
2003-02-06 00:15:22 +08:00
|
|
|
__aclent32_t *aclp = (__aclent32_t *) malloc (pos * sizeof (__aclent32_t));
|
2001-04-20 21:02:32 +08:00
|
|
|
if (aclp)
|
2003-02-06 00:15:22 +08:00
|
|
|
memcpy (aclp, lacl, pos * sizeof (__aclent32_t));
|
2001-04-20 21:02:32 +08:00
|
|
|
return aclp;
|
|
|
|
}
|
|
|
|
|
2003-02-06 00:15:22 +08:00
|
|
|
/* __aclent16_t and __aclent32_t have same size and same member offsets */
|
|
|
|
static __aclent32_t *
|
|
|
|
acl16to32 (__aclent16_t *aclbufp, int nentries)
|
|
|
|
{
|
|
|
|
__aclent32_t *aclbufp32 = (__aclent32_t *) aclbufp;
|
|
|
|
if (aclbufp32)
|
|
|
|
for (int i = 0; i < nentries; i++)
|
|
|
|
aclbufp32[i].a_id &= USHRT_MAX;
|
|
|
|
return aclbufp32;
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
acl (const char *path, int cmd, int nentries, __aclent16_t *aclbufp)
|
|
|
|
{
|
|
|
|
return acl32 (path, cmd, nentries, acl16to32 (aclbufp, nentries));
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
facl (int fd, int cmd, int nentries, __aclent16_t *aclbufp)
|
|
|
|
{
|
|
|
|
return facl32 (fd, cmd, nentries, acl16to32 (aclbufp, nentries));
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
lacl (const char *path, int cmd, int nentries, __aclent16_t *aclbufp)
|
|
|
|
{
|
2010-09-13 03:43:55 +08:00
|
|
|
/* This call was an accident. Make it absolutely clear. */
|
|
|
|
set_errno (ENOSYS);
|
|
|
|
return -1;
|
2003-02-06 00:15:22 +08:00
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
aclcheck (__aclent16_t *aclbufp, int nentries, int *which)
|
|
|
|
{
|
|
|
|
return aclcheck32 (acl16to32 (aclbufp, nentries), nentries, which);
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
aclsort (int nentries, int i, __aclent16_t *aclbufp)
|
|
|
|
{
|
|
|
|
return aclsort32 (nentries, i, acl16to32 (aclbufp, nentries));
|
|
|
|
}
|
|
|
|
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
acltomode (__aclent16_t *aclbufp, int nentries, mode_t *modep)
|
|
|
|
{
|
|
|
|
return acltomode32 (acl16to32 (aclbufp, nentries), nentries, modep);
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
aclfrommode (__aclent16_t *aclbufp, int nentries, mode_t *modep)
|
|
|
|
{
|
|
|
|
return aclfrommode32 ((__aclent32_t *)aclbufp, nentries, modep);
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
acltopbits (__aclent16_t *aclbufp, int nentries, mode_t *pbitsp)
|
|
|
|
{
|
|
|
|
return acltopbits32 (acl16to32 (aclbufp, nentries), nentries, pbitsp);
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" int
|
2003-02-06 00:15:22 +08:00
|
|
|
aclfrompbits (__aclent16_t *aclbufp, int nentries, mode_t *pbitsp)
|
|
|
|
{
|
|
|
|
return aclfrompbits32 ((__aclent32_t *)aclbufp, nentries, pbitsp);
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" char *
|
2003-02-06 00:15:22 +08:00
|
|
|
acltotext (__aclent16_t *aclbufp, int aclcnt)
|
|
|
|
{
|
|
|
|
return acltotext32 (acl16to32 (aclbufp, aclcnt), aclcnt);
|
|
|
|
}
|
|
|
|
|
2003-03-10 04:10:25 +08:00
|
|
|
extern "C" __aclent16_t *
|
2003-02-06 00:15:22 +08:00
|
|
|
aclfromtext (char *acltextp, int * aclcnt)
|
|
|
|
{
|
|
|
|
return (__aclent16_t *) aclfromtext32 (acltextp, aclcnt);
|
|
|
|
}
|