static char * get_tablepath (char *name, dir_binding *bptr) { enum clnt_stat result; nis_result res; struct ns_request req; memset (&res, '\0', sizeof (res)); req.ns_name = name; req.ns_object.ns_object_len = 0; req.ns_object.ns_object_val = NULL; result = clnt_call (bptr->clnt, NIS_LOOKUP, (xdrproc_t) _xdr_ns_request, (caddr_t) &req, (xdrproc_t) _xdr_nis_result, (caddr_t) &res, RPCTIMEOUT); const char *cptr; if (result == RPC_SUCCESS && NIS_RES_STATUS (&res) == NIS_SUCCESS && __type_of (NIS_RES_OBJECT (&res)) == NIS_TABLE_OBJ) cptr = NIS_RES_OBJECT (&res)->TA_data.ta_path; else cptr = ""; char *str = strdup (cptr); if (result == RPC_SUCCESS) xdr_free ((xdrproc_t) _xdr_nis_result, (char *) &res); return str; }
nis_result * nis_checkpoint (const_nis_name dirname) { nis_result *res; res = calloc (1, sizeof (nis_result)); if (res == NULL) return NULL; if (dirname != NULL) { nis_result *res2; u_int i; res2 = nis_lookup (dirname, EXPAND_NAME); if (NIS_RES_STATUS (res2) != NIS_SUCCESS) { free (res); return res2; } /* Check if obj is really a diryectory object */ if (__type_of (NIS_RES_OBJECT (res2)) != NIS_DIRECTORY_OBJ) { nis_freeresult (res2); NIS_RES_STATUS (res) = NIS_INVALIDOBJ; return res; } for (i = 0; i < NIS_RES_OBJECT (res2)->DI_data.do_servers.do_servers_len; ++i) { cp_result cpres; memset (&cpres, '\0', sizeof (cp_result)); if (__do_niscall2 (&NIS_RES_OBJECT(res2)->DI_data.do_servers.do_servers_val[i], 1, NIS_CHECKPOINT, (xdrproc_t) _xdr_nis_name, (caddr_t) &dirname, (xdrproc_t) _xdr_cp_result, (caddr_t) &cpres, 0, NULL) != NIS_SUCCESS) NIS_RES_STATUS (res) = NIS_RPCERROR; else { NIS_RES_STATUS (res) = cpres.cp_status; res->zticks += cpres.cp_zticks; res->dticks += cpres.cp_dticks; } } nis_freeresult (res2); } else NIS_RES_STATUS (res) = NIS_NOSUCHNAME; return res; }
static int _nss_nisplus_parse_etherent (nis_result *result, struct etherent *ether, char *buffer, size_t buflen, int *errnop) { char *p = buffer; size_t room_left = buflen; if (result == NULL) return 0; if ((result->status != NIS_SUCCESS && result->status != NIS_S_SUCCESS) || NIS_RES_NUMOBJ (result) != 1 || __type_of (NIS_RES_OBJECT (result)) != NIS_ENTRY_OBJ || strcmp (NIS_RES_OBJECT (result)->EN_data.en_type, "ethers_tbl") != 0 || NIS_RES_OBJECT (result)->EN_data.en_cols.en_cols_len < 2) return 0; /* Generate the ether entry format and use the normal parser */ if (NISENTRYLEN (0, 0, result) + 1 > room_left) { *errnop = ERANGE; return -1; } char *cp = __stpncpy (p, NISENTRYVAL (0, 0, result), NISENTRYLEN (0, 0, result)); *cp = '\0'; room_left -= NISENTRYLEN (0, 0, result) + 1; ether->e_name = p; struct ether_addr *ea = ether_aton (NISENTRYVAL (0, 1, result)); if (ea == NULL) { *errnop = EINVAL; return -2; } ether->e_addr = *ea; return 1; }
int lookup_mount(const char *root, const char *name, int name_len, void *context) { struct lookup_context *ctxt = (struct lookup_context *) context; char tablename[strlen(name) + strlen(ctxt->mapname) + strlen(ctxt->domainname) + 20]; nis_result *result; int rv; debug(MODPREFIX "looking up %s", name); sprintf(tablename, "[key=%s],%s.org_dir.%s", name, ctxt->mapname, ctxt->domainname); result = nis_list(tablename, FOLLOW_PATH | FOLLOW_LINKS, NULL, NULL); if (result->status != NIS_SUCCESS && result->status != NIS_S_SUCCESS) { /* Try to get the "*" entry if there is one - note that we *don't* modify "name" so & -> the name we used, not "*" */ sprintf(tablename, "[key=*],%s.org_dir.%s", ctxt->mapname, ctxt->domainname); result = nis_list(tablename, FOLLOW_PATH | FOLLOW_LINKS, NULL, NULL); } if (result->status != NIS_SUCCESS && result->status != NIS_S_SUCCESS) { crit(MODPREFIX "lookup for %s failed: %s", name, nis_sperrno(result->status)); return 1; } debug(MODPREFIX "%s -> %s", name, NIS_RES_OBJECT(result)->EN_data.en_cols.en_cols_val[1].ec_value. ec_value_val); rv = ctxt->parse->parse_mount(root, name, name_len, NIS_RES_OBJECT(result)->EN_data.en_cols. en_cols_val[1].ec_value.ec_value_val, ctxt->parse->context); return rv; }
nis_error nis_removemember (const_nis_name member, const_nis_name group) { if (group != NULL && group[0] != '\0') { size_t grouplen = strlen (group); char buf[grouplen + 14 + NIS_MAXNAMELEN]; char leafbuf[grouplen + 2]; char domainbuf[grouplen + 2]; nis_name *newmem; nis_result *res, *res2; nis_error status; char *cp, *cp2; unsigned long int i, j, k; cp = stpcpy (buf, nis_leaf_of_r (group, leafbuf, sizeof (leafbuf) - 1)); cp = stpcpy (cp, ".groups_dir"); cp2 = nis_domain_of_r (group, domainbuf, sizeof (domainbuf) - 1); if (cp2 != NULL && cp2[0] != '\0') { cp = stpcpy (cp, "."); stpcpy (cp, cp2); } res = nis_lookup (buf, FOLLOW_LINKS|EXPAND_NAME); if (res == NULL || NIS_RES_STATUS (res) != NIS_SUCCESS) { if (res) { status = NIS_RES_STATUS (res); nis_freeresult (res); } else return NIS_NOMEMORY; return status; } if ((res->objects.objects_len != 1) || (__type_of (NIS_RES_OBJECT (res)) != NIS_GROUP_OBJ)) { nis_freeresult (res); return NIS_INVALIDOBJ; } newmem = calloc (NIS_RES_OBJECT(res)->GR_data.gr_members.gr_members_len, sizeof (char *)); if (newmem == NULL) return NIS_NOMEMORY; k = NIS_RES_OBJECT (res)[0].GR_data.gr_members.gr_members_len; j = 0; for (i = 0; i < NIS_RES_OBJECT(res)->GR_data.gr_members.gr_members_len; ++i) { if (strcmp (NIS_RES_OBJECT(res)->GR_data.gr_members.gr_members_val[i], member) != 0) { newmem[j] = NIS_RES_OBJECT(res)->GR_data.gr_members.gr_members_val[i]; ++j; } else { free (NIS_RES_OBJECT(res)->GR_data.gr_members.gr_members_val[i]); --k; } } free (NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val); newmem = realloc (newmem, k * sizeof (char*)); if (newmem == NULL) return NIS_NOMEMORY; NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val = newmem; NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_len = k; cp = stpcpy (buf, NIS_RES_OBJECT (res)->zo_name); *cp++ = '.'; strncpy (cp, NIS_RES_OBJECT (res)->zo_domain, NIS_MAXNAMELEN); res2 = nis_modify (buf, NIS_RES_OBJECT (res)); status = NIS_RES_STATUS (res2); nis_freeresult (res); nis_freeresult (res2); return status; } else return NIS_FAIL; }
nis_result * nis_list (const_nis_name name, unsigned int flags, int (*callback) (const_nis_name name, const nis_object *object, const void *userdata), const void *userdata) { nis_result *res = malloc (sizeof (nis_result)); ib_request *ibreq; int status; enum clnt_stat clnt_status; int count_links = 0; /* We will only follow NIS_MAXLINKS links! */ int done = 0; nis_name *names; nis_name namebuf[2] = {NULL, NULL}; int name_nr = 0; nis_cb *cb = NULL; char *tableptr; char *tablepath = NULL; int first_try = 0; /* Do we try the old binding at first ? */ nis_result *allres = NULL; if (res == NULL) return NULL; if (name == NULL) { status = NIS_BADNAME; err_out: nis_freeresult (allres); memset (res, '\0', sizeof (nis_result)); NIS_RES_STATUS (res) = status; return res; } ibreq = __create_ib_request (name, flags); if (ibreq == NULL) { status = NIS_BADNAME; goto err_out; } if ((flags & EXPAND_NAME) && ibreq->ibr_name[strlen (ibreq->ibr_name) - 1] != '.') { names = nis_getnames (ibreq->ibr_name); free (ibreq->ibr_name); ibreq->ibr_name = NULL; if (names == NULL) { nis_free_request (ibreq); status = NIS_BADNAME; goto err_out; } ibreq->ibr_name = strdup (names[name_nr]); if (ibreq->ibr_name == NULL) { nis_freenames (names); nis_free_request (ibreq); status = NIS_NOMEMORY; goto err_out; } } else { names = namebuf; names[name_nr] = ibreq->ibr_name; } cb = NULL; while (!done) { dir_binding bptr; directory_obj *dir = NULL; memset (res, '\0', sizeof (nis_result)); status = __nisfind_server (ibreq->ibr_name, ibreq->ibr_srch.ibr_srch_val != NULL, &dir, &bptr, flags & ~MASTER_ONLY); if (status != NIS_SUCCESS) { NIS_RES_STATUS (res) = status; goto fail3; } while (__nisbind_connect (&bptr) != NIS_SUCCESS) if (__nisbind_next (&bptr) != NIS_SUCCESS) { NIS_RES_STATUS (res) = NIS_NAMEUNREACHABLE; goto fail; } if (callback != NULL) { assert (cb == NULL); cb = __nis_create_callback (callback, userdata, flags); ibreq->ibr_cbhost.ibr_cbhost_len = 1; ibreq->ibr_cbhost.ibr_cbhost_val = cb->serv; } again: clnt_status = clnt_call (bptr.clnt, NIS_IBLIST, (xdrproc_t) _xdr_ib_request, (caddr_t) ibreq, (xdrproc_t) _xdr_nis_result, (caddr_t) res, RPCTIMEOUT); if (clnt_status != RPC_SUCCESS) NIS_RES_STATUS (res) = NIS_RPCERROR; else switch (NIS_RES_STATUS (res)) { /* start switch */ case NIS_PARTIAL: case NIS_SUCCESS: case NIS_S_SUCCESS: if (__type_of (NIS_RES_OBJECT (res)) == NIS_LINK_OBJ && (flags & FOLLOW_LINKS)) /* We are following links. */ { free (ibreq->ibr_name); ibreq->ibr_name = NULL; /* If we hit the link limit, bail. */ if (count_links > NIS_MAXLINKS) { NIS_RES_STATUS (res) = NIS_LINKNAMEERROR; ++done; break; } ++count_links; ibreq->ibr_name = strdup (NIS_RES_OBJECT (res)->LI_data.li_name); if (ibreq->ibr_name == NULL) { NIS_RES_STATUS (res) = NIS_NOMEMORY; fail: __nisbind_destroy (&bptr); nis_free_directory (dir); fail3: free (tablepath); if (cb) { __nis_destroy_callback (cb); ibreq->ibr_cbhost.ibr_cbhost_len = 0; ibreq->ibr_cbhost.ibr_cbhost_val = NULL; } if (names != namebuf) nis_freenames (names); nis_free_request (ibreq); nis_freeresult (allres); return res; } if (NIS_RES_OBJECT (res)->LI_data.li_attrs.li_attrs_len) if (ibreq->ibr_srch.ibr_srch_len == 0) { ibreq->ibr_srch.ibr_srch_len = NIS_RES_OBJECT (res)->LI_data.li_attrs.li_attrs_len; ibreq->ibr_srch.ibr_srch_val = NIS_RES_OBJECT (res)->LI_data.li_attrs.li_attrs_val; } /* The following is a non-obvious optimization. A nis_freeresult call would call xdr_free as the following code. But it also would unnecessarily free the result structure. We avoid this here along with the necessary tests. */ xdr_free ((xdrproc_t) _xdr_nis_result, (char *)res); memset (res, '\0', sizeof (*res)); first_try = 1; /* Try at first the old binding */ goto again; } else if ((flags & FOLLOW_PATH) && NIS_RES_STATUS (res) == NIS_PARTIAL) { enum nis_error err = __follow_path (&tablepath, &tableptr, ibreq, &bptr); if (err != NIS_SUCCESS) { if (err == NIS_NOMEMORY) NIS_RES_STATUS (res) = err; ++done; } else { /* The following is a non-obvious optimization. A nis_freeresult call would call xdr_free as the following code. But it also would unnecessarily free the result structure. We avoid this here along with the necessary tests. */ xdr_free ((xdrproc_t) _xdr_nis_result, (char *) res); memset (res, '\0', sizeof (*res)); first_try = 1; goto again; } } else if ((flags & (FOLLOW_PATH | ALL_RESULTS)) == (FOLLOW_PATH | ALL_RESULTS)) { if (allres == NULL) { allres = res; res = malloc (sizeof (nis_result)); if (res == NULL) { res = allres; allres = NULL; NIS_RES_STATUS (res) = NIS_NOMEMORY; goto fail; } NIS_RES_STATUS (res) = NIS_RES_STATUS (allres); } else { nis_object *objects_val = realloc (NIS_RES_OBJECT (allres), (NIS_RES_NUMOBJ (allres) + NIS_RES_NUMOBJ (res)) * sizeof (nis_object)); if (objects_val == NULL) { NIS_RES_STATUS (res) = NIS_NOMEMORY; goto fail; } NIS_RES_OBJECT (allres) = objects_val; memcpy (NIS_RES_OBJECT (allres) + NIS_RES_NUMOBJ (allres), NIS_RES_OBJECT (res), NIS_RES_NUMOBJ (res) * sizeof (nis_object)); NIS_RES_NUMOBJ (allres) += NIS_RES_NUMOBJ (res); NIS_RES_NUMOBJ (res) = 0; free (NIS_RES_OBJECT (res)); NIS_RES_OBJECT (res) = NULL; NIS_RES_STATUS (allres) = NIS_RES_STATUS (res); xdr_free ((xdrproc_t) _xdr_nis_result, (char *) res); } enum nis_error err = __follow_path (&tablepath, &tableptr, ibreq, &bptr); if (err != NIS_SUCCESS) { /* Prepare for the nis_freeresult call. */ memset (res, '\0', sizeof (*res)); if (err == NIS_NOMEMORY) NIS_RES_STATUS (allres) = err; ++done; } } else ++done; break; case NIS_CBRESULTS: if (cb != NULL) { __nis_do_callback (&bptr, &res->cookie, cb); NIS_RES_STATUS (res) = cb->result; if (!(flags & ALL_RESULTS)) ++done; else { enum nis_error err = __follow_path (&tablepath, &tableptr, ibreq, &bptr); if (err != NIS_SUCCESS) { if (err == NIS_NOMEMORY) NIS_RES_STATUS (res) = err; ++done; } } } break; case NIS_SYSTEMERROR: case NIS_NOSUCHNAME: case NIS_NOT_ME: /* If we had first tried the old binding, do nothing, but get a new binding */ if (!first_try) { if (__nisbind_next (&bptr) != NIS_SUCCESS) { ++done; break; /* No more servers to search */ } while (__nisbind_connect (&bptr) != NIS_SUCCESS) { if (__nisbind_next (&bptr) != NIS_SUCCESS) { ++done; break; /* No more servers to search */ } } goto again; } break; default: if (!first_try) { /* Try the next domainname if we don't follow a link. */ free (ibreq->ibr_name); ibreq->ibr_name = NULL; if (count_links) { NIS_RES_STATUS (res) = NIS_LINKNAMEERROR; ++done; break; } ++name_nr; if (names[name_nr] == NULL) { ++done; break; } ibreq->ibr_name = strdup (names[name_nr]); if (ibreq->ibr_name == NULL) { NIS_RES_STATUS (res) = NIS_NOMEMORY; goto fail; } first_try = 1; /* Try old binding at first */ goto again; } break; } first_try = 0; if (cb) { __nis_destroy_callback (cb); ibreq->ibr_cbhost.ibr_cbhost_len = 0; ibreq->ibr_cbhost.ibr_cbhost_val = NULL; cb = NULL; } __nisbind_destroy (&bptr); nis_free_directory (dir); } free (tablepath); if (names != namebuf) nis_freenames (names); nis_free_request (ibreq); if (allres) { nis_freeresult (res); return allres; } return res; }
void nis_print_group_entry (const_nis_name group) { if (group != NULL && group[0] != '\0') { size_t grouplen = strlen (group); char buf[grouplen + 50]; char leafbuf[grouplen + 3]; char domainbuf[grouplen + 3]; nis_result *res; char *cp, *cp2; u_int i; cp = stpcpy (buf, nis_leaf_of_r (group, leafbuf, sizeof (leafbuf) - 1)); cp = stpcpy (cp, ".groups_dir"); cp2 = nis_domain_of_r (group, domainbuf, sizeof (domainbuf) - 1); if (cp2 != NULL && cp2[0] != '\0') { *cp++ = '.'; stpcpy (cp, cp2); } res = nis_lookup (buf, FOLLOW_LINKS | EXPAND_NAME); if (res == NULL) return; if (NIS_RES_STATUS (res) != NIS_SUCCESS || NIS_RES_NUMOBJ (res) != 1 || __type_of (NIS_RES_OBJECT (res)) != NIS_GROUP_OBJ) { nis_freeresult (res); return; } char *mem_exp[NIS_RES_NUMOBJ (res)]; char *mem_imp[NIS_RES_NUMOBJ (res)]; char *mem_rec[NIS_RES_NUMOBJ (res)]; char *nomem_exp[NIS_RES_NUMOBJ (res)]; char *nomem_imp[NIS_RES_NUMOBJ (res)]; char *nomem_rec[NIS_RES_NUMOBJ (res)]; unsigned long mem_exp_cnt = 0, mem_imp_cnt = 0, mem_rec_cnt = 0; unsigned long nomem_exp_cnt = 0, nomem_imp_cnt = 0, nomem_rec_cnt = 0; for (i = 0; i < NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_len; ++i) { char *grmem = NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val[i]; int neg = grmem[0] == '-'; switch (grmem[neg]) { case '*': if (neg) { nomem_imp[nomem_imp_cnt] = grmem; ++nomem_imp_cnt; } else { mem_imp[mem_imp_cnt] = grmem; ++mem_imp_cnt; } break; case '@': if (neg) { nomem_rec[nomem_rec_cnt] = grmem; ++nomem_rec_cnt; } else { mem_rec[mem_rec_cnt] = grmem; ++mem_rec_cnt; } break; default: if (neg) { nomem_exp[nomem_exp_cnt] = grmem; ++nomem_exp_cnt; } else { mem_exp[mem_exp_cnt] = grmem; ++mem_exp_cnt; } break; } } { char buf[strlen (NIS_RES_OBJECT (res)->zo_domain) + 10]; printf (_("Group entry for \"%s.%s\" group:\n"), NIS_RES_OBJECT (res)->zo_name, nis_domain_of_r (NIS_RES_OBJECT (res)->zo_domain, buf, strlen (NIS_RES_OBJECT (res)->zo_domain) + 10)); } if (mem_exp_cnt) { fputs (_(" Explicit members:\n"), stdout); for (i = 0; i < mem_exp_cnt; ++i) printf ("\t%s\n", mem_exp[i]); } else fputs (_(" No explicit members\n"), stdout); if (mem_imp_cnt) { fputs (_(" Implicit members:\n"), stdout); for (i = 0; i < mem_imp_cnt; ++i) printf ("\t%s\n", &mem_imp[i][2]); } else fputs (_(" No implicit members\n"), stdout); if (mem_rec_cnt) { fputs (_(" Recursive members:\n"), stdout); for (i = 0; i < mem_rec_cnt; ++i) printf ("\t%s\n", &mem_rec[i][1]); } else fputs (_(" No recursive members\n"), stdout); if (nomem_exp_cnt) { fputs (_(" Explicit nonmembers:\n"), stdout); for (i = 0; i < nomem_exp_cnt; ++i) printf ("\t%s\n", &nomem_exp[i][1]); } else fputs (_(" No explicit nonmembers\n"), stdout); if (nomem_imp_cnt) { fputs (_(" Implicit nonmembers:\n"), stdout); for (i = 0; i < nomem_imp_cnt; ++i) printf ("\t%s\n", &nomem_imp[i][3]); } else fputs (_(" No implicit nonmembers\n"), stdout); if (nomem_rec_cnt) { fputs (_(" Recursive nonmembers:\n"), stdout); for (i = 0; i < nomem_rec_cnt; ++i) printf ("\t%s=n", &nomem_rec[i][2]); } else fputs (_(" No recursive nonmembers\n"), stdout); nis_freeresult (res); } }
nis_error nis_addmember (const_nis_name member, const_nis_name group) { if (group != NULL && group[0] != '\0') { size_t grouplen = strlen (group); char buf[grouplen + 14 + NIS_MAXNAMELEN]; char domainbuf[grouplen + 2]; nis_result *res, *res2; nis_error status; char *cp, *cp2; cp = rawmemchr (nis_leaf_of_r (group, buf, sizeof (buf) - 1), '\0'); cp = stpcpy (cp, ".groups_dir"); cp2 = nis_domain_of_r (group, domainbuf, sizeof (domainbuf) - 1); if (cp2 != NULL && cp2[0] != '\0') { *cp++ = '.'; stpcpy (cp, cp2); } res = nis_lookup (buf, FOLLOW_LINKS | EXPAND_NAME); if (NIS_RES_STATUS (res) != NIS_SUCCESS) { status = NIS_RES_STATUS (res); nis_freeresult (res); return status; } if (NIS_RES_NUMOBJ (res) != 1 || __type_of (NIS_RES_OBJECT (res)) != NIS_GROUP_OBJ) { nis_freeresult (res); return NIS_INVALIDOBJ; } u_int gr_members_len = NIS_RES_OBJECT(res)->GR_data.gr_members.gr_members_len; nis_name *new_gr_members_val = realloc (NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val, (gr_members_len + 1) * sizeof (nis_name)); if (new_gr_members_val == NULL) goto nomem_out; NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val = new_gr_members_val; new_gr_members_val[gr_members_len] = strdup (member); if (new_gr_members_val[gr_members_len] == NULL) { nomem_out: nis_freeresult (res); return NIS_NOMEMORY; } ++NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_len; /* Check the buffer bounds are not exceeded. */ assert (strlen (NIS_RES_OBJECT(res)->zo_name) + 1 < grouplen + 14); cp = stpcpy (buf, NIS_RES_OBJECT(res)->zo_name); *cp++ = '.'; strncpy (cp, NIS_RES_OBJECT (res)->zo_domain, NIS_MAXNAMELEN); res2 = nis_modify (buf, NIS_RES_OBJECT (res)); status = NIS_RES_STATUS (res2); nis_freeresult (res); nis_freeresult (res2); return status; } else return NIS_FAIL; }
enum nss_status _nss_nisplus_initgroups_dyn (const char *user, gid_t group, long int *start, long int *size, gid_t **groupsp, long int limit, int *errnop) { if (grp_tablename_val == NULL) { enum nss_status status = _nss_grp_create_tablename (errnop); if (status != NSS_STATUS_SUCCESS) return status; } nis_result *result; char buf[strlen (user) + 12 + grp_tablename_len]; snprintf (buf, sizeof (buf), "[members=%s],%s", user, grp_tablename_val); result = nis_list (buf, FOLLOW_LINKS | FOLLOW_PATH | ALL_RESULTS, NULL, NULL); if (result == NULL) { *errnop = ENOMEM; return NSS_STATUS_TRYAGAIN; } if (__builtin_expect (niserr2nss (result->status) != NSS_STATUS_SUCCESS, 0)) { enum nss_status status = niserr2nss (result->status); nis_freeresult (result); return status; } if (NIS_RES_NUMOBJ (result) == 0) { errout: nis_freeresult (result); return NSS_STATUS_NOTFOUND; } gid_t *groups = *groupsp; nis_object *obj = NIS_RES_OBJECT (result); for (unsigned int cnt = 0; cnt < NIS_RES_NUMOBJ (result); ++cnt, ++obj) { if (__type_of (obj) != NIS_ENTRY_OBJ || strcmp (obj->EN_data.en_type, "group_tbl") != 0 || obj->EN_data.en_cols.en_cols_len < 4) continue; char *numstr = NISOBJVAL (2, obj); size_t len = NISOBJLEN (2, obj); if (len == 0 || numstr[0] == '\0') continue; gid_t gid; char *endp; if (__builtin_expect (numstr[len - 1] != '\0', 0)) { char numstrbuf[len + 1]; memcpy (numstrbuf, numstr, len); numstrbuf[len] = '\0'; gid = strtoul (numstrbuf, &endp, 10); if (*endp) continue; } else { gid = strtoul (numstr, &endp, 10); if (*endp) continue; } if (gid == group) continue; /* Insert this group. */ if (*start == *size) { /* Need a bigger buffer. */ long int newsize; if (limit > 0 && *size == limit) /* We reached the maximum. */ break; if (limit <= 0) newsize = 2 * *size; else newsize = MIN (limit, 2 * *size); gid_t *newgroups = realloc (groups, newsize * sizeof (*groups)); if (newgroups == NULL) goto errout; *groupsp = groups = newgroups; *size = newsize; } groups[*start] = gid; *start += 1; } nis_freeresult (result); return NSS_STATUS_SUCCESS; }
nis_error nis_addmember (const_nis_name member, const_nis_name group) { if (group != NULL && group[0] != '\0') { size_t grouplen = strlen (group); char buf[grouplen + 14 + NIS_MAXNAMELEN]; char leafbuf[grouplen + 2]; char domainbuf[grouplen + 2]; nis_result *res, *res2; nis_error status; char *cp, *cp2; cp = stpcpy (buf, nis_leaf_of_r (group, leafbuf, sizeof (leafbuf) - 1)); cp = stpcpy (cp, ".groups_dir"); cp2 = nis_domain_of_r (group, domainbuf, sizeof (domainbuf) - 1); if (cp2 != NULL && cp2[0] != '\0') { *cp++ = '.'; stpcpy (cp, cp2); } res = nis_lookup (buf, FOLLOW_LINKS|EXPAND_NAME); if (NIS_RES_STATUS (res) != NIS_SUCCESS) { status = NIS_RES_STATUS (res); nis_freeresult (res); return status; } if ((NIS_RES_NUMOBJ (res) != 1) || (__type_of (NIS_RES_OBJECT (res)) != NIS_GROUP_OBJ)) { nis_freeresult (res); return NIS_INVALIDOBJ; } NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val = realloc (NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val, (NIS_RES_OBJECT(res)->GR_data.gr_members.gr_members_len + 1) * sizeof (char *)); if (NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val == NULL) goto nomem_out; NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val[NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_len] = strdup (member); if (NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val[NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_len] == NULL) { free (NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val); nomem_out: nis_freeresult (res); return NIS_NOMEMORY; } ++NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_len; cp = stpcpy (buf, NIS_RES_OBJECT(res)->zo_name); *cp++ = '.'; strncpy (cp, NIS_RES_OBJECT (res)->zo_domain, NIS_MAXNAMELEN); res2 = nis_modify (buf, NIS_RES_OBJECT (res)); status = NIS_RES_STATUS (res2); nis_freeresult (res); nis_freeresult (res2); return status; } else return NIS_FAIL; }
/* internal_nis_ismember () return codes: -1 principal is in -group 0 principal isn't in any group 1 pirncipal is in group */ static int internal_ismember (const_nis_name principal, const_nis_name group) { size_t grouplen = strlen (group); char buf[grouplen + 50]; char leafbuf[grouplen + 2]; char domainbuf[grouplen + 2]; nis_result *res; char *cp, *cp2; u_int i; cp = stpcpy (buf, nis_leaf_of_r (group, leafbuf, sizeof (leafbuf) - 1)); cp = stpcpy (cp, ".groups_dir"); cp2 = nis_domain_of_r (group, domainbuf, sizeof (domainbuf) - 1); if (cp2 != NULL && cp2[0] != '\0') { *cp++ = '.'; strcpy (cp, cp2); } res = nis_lookup (buf, EXPAND_NAME|FOLLOW_LINKS); if (res == NULL || NIS_RES_STATUS (res) != NIS_SUCCESS) { nis_freeresult (res); return 0; } if ((NIS_RES_NUMOBJ (res) != 1) || (__type_of (NIS_RES_OBJECT (res)) != NIS_GROUP_OBJ)) { nis_freeresult (res); return 0; } /* We search twice in the list, at first, if we have the name with a "-", then if without. "-member" has priority */ for (i = 0; i < NIS_RES_OBJECT(res)->GR_data.gr_members.gr_members_len; ++i) { cp = NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val[i]; if (cp[0] == '-') { if (strcmp (&cp[1], principal) == 0) { nis_freeresult (res); return -1; } if (cp[1] == '@') switch (internal_ismember (principal, &cp[2])) { case -1: nis_freeresult (res); return -1; case 1: nis_freeresult (res); return 1; default: break; } else if (cp[1] == '*') { char buf1[strlen (principal) + 2]; char buf2[strlen (cp) + 2]; if (strcmp (nis_domain_of_r (principal, buf1, sizeof buf1), nis_domain_of_r (cp, buf2, sizeof buf2)) == 0) { nis_freeresult (res); return -1; } } } } for (i = 0; i < NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_len; ++i) { cp = NIS_RES_OBJECT (res)->GR_data.gr_members.gr_members_val[i]; if (cp[0] != '-') { if (strcmp (cp, principal) == 0) { nis_freeresult (res); return 1; } if (cp[0] == '@') switch (internal_ismember (principal, &cp[1])) { case -1: nis_freeresult (res); return -1; case 1: nis_freeresult (res); return 1; default: break; } else if (cp[0] == '*') { char buf1[strlen (principal) + 2]; char buf2[strlen (cp) + 2]; if (strcmp (nis_domain_of_r (principal, buf1, sizeof buf1), nis_domain_of_r (cp, buf2, sizeof buf2)) == 0) { nis_freeresult (res); return 1; } } } } nis_freeresult (res); return 0; }
nis_result * nis_lookup (const_nis_name name, const unsigned int flags) { nis_result *res = calloc (1, sizeof (nis_result)); struct ns_request req; nis_name *names; nis_error status; int link_first_try = 0; int count_links = 0; /* We will follow only 16 links in the deep */ int done = 0; int name_nr = 0; nis_name namebuf[2] = {NULL, NULL}; if (res == NULL) return NULL; if ((flags & EXPAND_NAME) && (name[strlen (name) - 1] != '.')) { names = nis_getnames (name); if (names == NULL) { NIS_RES_STATUS (res) = NIS_NAMEUNREACHABLE; return res; } } else { names = namebuf; names[0] = (nis_name)name; } req.ns_name = names[0]; while (!done) { dir_binding bptr; directory_obj *dir = NULL; req.ns_object.ns_object_len = 0; req.ns_object.ns_object_val = NULL; status = __nisfind_server (req.ns_name, &dir); if (status != NIS_SUCCESS) { NIS_RES_STATUS (res) = status; return res; } status = __nisbind_create (&bptr, dir->do_servers.do_servers_val, dir->do_servers.do_servers_len, flags); if (status != NIS_SUCCESS) { NIS_RES_STATUS (res) = status; nis_free_directory (dir); return res; } while (__nisbind_connect (&bptr) != NIS_SUCCESS) { if (__nisbind_next (&bptr) != NIS_SUCCESS) { __nisbind_destroy (&bptr); nis_free_directory (dir); NIS_RES_STATUS (res) = NIS_NAMEUNREACHABLE; return res; } } do { static struct timeval RPCTIMEOUT = {10, 0}; enum clnt_stat result; again: result = clnt_call (bptr.clnt, NIS_LOOKUP, (xdrproc_t) _xdr_ns_request, (caddr_t) &req, (xdrproc_t) _xdr_nis_result, (caddr_t) res, RPCTIMEOUT); if (result != RPC_SUCCESS) status = NIS_RPCERROR; else { status = NIS_SUCCESS; if (NIS_RES_STATUS (res) == NIS_SUCCESS) { if (__type_of(NIS_RES_OBJECT (res)) == NIS_LINK_OBJ && flags & FOLLOW_LINKS) /* We are following links */ { if (count_links) free (req.ns_name); /* if we hit the link limit, bail */ if (count_links > NIS_MAXLINKS) { NIS_RES_STATUS (res) = NIS_LINKNAMEERROR; break; } ++count_links; req.ns_name = strdup (NIS_RES_OBJECT (res)->LI_data.li_name); if (req.ns_name == NULL) return NULL; nis_freeresult (res); res = calloc (1, sizeof (nis_result)); if (res == NULL) { __nisbind_destroy (&bptr); return NULL; } link_first_try = 1; /* Try at first the old binding */ goto again; } } else if ((NIS_RES_STATUS (res) == NIS_SYSTEMERROR) || (NIS_RES_STATUS (res) == NIS_NOSUCHNAME) || (NIS_RES_STATUS (res) == NIS_NOT_ME)) { if (link_first_try) { __nisbind_destroy (&bptr); nis_free_directory (dir); if (__nisfind_server (req.ns_name, &dir) != NIS_SUCCESS) return res; if (__nisbind_create (&bptr, dir->do_servers.do_servers_val, dir->do_servers.do_servers_len, flags) != NIS_SUCCESS) { nis_free_directory (dir); return res; } } else if (__nisbind_next (&bptr) != NIS_SUCCESS) break; /* No more servers to search */ while (__nisbind_connect (&bptr) != NIS_SUCCESS) { if (__nisbind_next (&bptr) != NIS_SUCCESS) { __nisbind_destroy (&bptr); nis_free_directory (dir); return res; } } goto again; } break; } link_first_try = 0; /* Set it back */ } while ((flags & HARD_LOOKUP) && status == NIS_RPCERROR); __nisbind_destroy (&bptr); nis_free_directory (dir); if (status != NIS_SUCCESS) { NIS_RES_STATUS (res) = status; return res; } switch (NIS_RES_STATUS (res)) { case NIS_PARTIAL: case NIS_SUCCESS: case NIS_S_SUCCESS: case NIS_LINKNAMEERROR: /* We follow to max links */ case NIS_UNAVAIL: /* NIS+ is not installed, or all servers are down */ ++done; break; default: /* Try the next domainname if we don't follow a link */ if (count_links) { free (req.ns_name); NIS_RES_STATUS (res) = NIS_LINKNAMEERROR; ++done; break; } ++name_nr; if (names[name_nr] == NULL) { ++done; break; } req.ns_name = names[name_nr]; break; } } if (names != namebuf) nis_freenames (names); return res; }