1 1.58 shm /* $NetBSD: getcap.c,v 1.58 2023/09/21 13:46:12 shm Exp $ */ 2 1.9 cgd 3 1.1 cgd /*- 4 1.9 cgd * Copyright (c) 1992, 1993 5 1.9 cgd * The Regents of the University of California. All rights reserved. 6 1.1 cgd * 7 1.1 cgd * This code is derived from software contributed to Berkeley by 8 1.1 cgd * Casey Leedom of Lawrence Livermore National Laboratory. 9 1.1 cgd * 10 1.1 cgd * Redistribution and use in source and binary forms, with or without 11 1.1 cgd * modification, are permitted provided that the following conditions 12 1.1 cgd * are met: 13 1.1 cgd * 1. Redistributions of source code must retain the above copyright 14 1.1 cgd * notice, this list of conditions and the following disclaimer. 15 1.1 cgd * 2. Redistributions in binary form must reproduce the above copyright 16 1.1 cgd * notice, this list of conditions and the following disclaimer in the 17 1.1 cgd * documentation and/or other materials provided with the distribution. 18 1.38 agc * 3. Neither the name of the University nor the names of its contributors 19 1.1 cgd * may be used to endorse or promote products derived from this software 20 1.1 cgd * without specific prior written permission. 21 1.1 cgd * 22 1.1 cgd * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 23 1.1 cgd * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 24 1.1 cgd * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 25 1.1 cgd * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 26 1.1 cgd * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 27 1.1 cgd * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 28 1.1 cgd * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 29 1.1 cgd * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 30 1.1 cgd * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 31 1.1 cgd * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 32 1.1 cgd * SUCH DAMAGE. 33 1.1 cgd */ 34 1.1 cgd 35 1.39 lukem #if HAVE_NBTOOL_CONFIG_H 36 1.39 lukem #include "nbtool_config.h" 37 1.37 uwe #endif 38 1.37 uwe 39 1.13 christos #include <sys/cdefs.h> 40 1.1 cgd #if defined(LIBC_SCCS) && !defined(lint) 41 1.9 cgd #if 0 42 1.9 cgd static char sccsid[] = "@(#)getcap.c 8.3 (Berkeley) 3/25/94"; 43 1.9 cgd #else 44 1.58 shm __RCSID("$NetBSD: getcap.c,v 1.58 2023/09/21 13:46:12 shm Exp $"); 45 1.9 cgd #endif 46 1.1 cgd #endif /* LIBC_SCCS and not lint */ 47 1.1 cgd 48 1.57 manu #ifndef LIBHACK 49 1.14 jtc #include "namespace.h" 50 1.41 christos #endif 51 1.1 cgd #include <sys/types.h> 52 1.36 tron #include <sys/param.h> 53 1.30 lukem 54 1.30 lukem #include <assert.h> 55 1.51 christos #include <stddef.h> 56 1.1 cgd #include <ctype.h> 57 1.41 christos #ifndef SMALL 58 1.1 cgd #include <db.h> 59 1.41 christos #endif 60 1.1 cgd #include <errno.h> 61 1.1 cgd #include <fcntl.h> 62 1.1 cgd #include <limits.h> 63 1.1 cgd #include <stdio.h> 64 1.1 cgd #include <stdlib.h> 65 1.1 cgd #include <string.h> 66 1.1 cgd #include <unistd.h> 67 1.14 jtc 68 1.57 manu #if defined(__weak_alias) && !defined(LIBHACK) 69 1.32 mycroft __weak_alias(cgetcap,_cgetcap) 70 1.32 mycroft __weak_alias(cgetclose,_cgetclose) 71 1.32 mycroft __weak_alias(cgetent,_cgetent) 72 1.32 mycroft __weak_alias(cgetfirst,_cgetfirst) 73 1.32 mycroft __weak_alias(cgetmatch,_cgetmatch) 74 1.32 mycroft __weak_alias(cgetnext,_cgetnext) 75 1.32 mycroft __weak_alias(cgetnum,_cgetnum) 76 1.32 mycroft __weak_alias(cgetset,_cgetset) 77 1.32 mycroft __weak_alias(cgetstr,_cgetstr) 78 1.32 mycroft __weak_alias(cgetustr,_cgetustr) 79 1.48 christos __weak_alias(csetexpandtc,_csetexpandtc) 80 1.14 jtc #endif 81 1.1 cgd 82 1.1 cgd #define BFRAG 1024 83 1.1 cgd #define BSIZE 1024 84 1.1 cgd #define ESC ('[' & 037) /* ASCII ESC */ 85 1.1 cgd #define MAX_RECURSION 32 /* maximum getent recursion */ 86 1.1 cgd #define SFRAG 100 /* cgetstr mallocs in SFRAG chunks */ 87 1.1 cgd 88 1.1 cgd #define RECOK (char)0 89 1.1 cgd #define TCERR (char)1 90 1.1 cgd #define SHADOW (char)2 91 1.1 cgd 92 1.1 cgd static size_t topreclen; /* toprec length */ 93 1.1 cgd static char *toprec; /* Additional record specified by cgetset() */ 94 1.1 cgd static int gottoprec; /* Flag indicating retrieval of toprecord */ 95 1.48 christos static int expandtc = 1; /* flag to expand tc= or not */ 96 1.1 cgd 97 1.41 christos #ifndef SMALL 98 1.40 christos static int cdbget(DB *, char **, const char *); 99 1.41 christos #endif 100 1.40 christos static int getent(char **, size_t *, const char * const *, int, 101 1.40 christos const char *, int, char *); 102 1.40 christos static int nfcmp(char *, char *); 103 1.1 cgd 104 1.1 cgd /* 105 1.1 cgd * Cgetset() allows the addition of a user specified buffer to be added 106 1.1 cgd * to the database array, in effect "pushing" the buffer on top of the 107 1.1 cgd * virtual database. 0 is returned on success, -1 on failure. 108 1.1 cgd */ 109 1.1 cgd int 110 1.40 christos cgetset(const char *ent) 111 1.1 cgd { 112 1.27 abs const char *source, *check; 113 1.27 abs char *dest; 114 1.27 abs 115 1.1 cgd if (ent == NULL) { 116 1.47 jnemeth if (toprec != NULL) 117 1.1 cgd free(toprec); 118 1.1 cgd toprec = NULL; 119 1.1 cgd topreclen = 0; 120 1.47 jnemeth return 0; 121 1.1 cgd } 122 1.1 cgd topreclen = strlen(ent); 123 1.47 jnemeth if ((toprec = malloc(topreclen + 1)) == NULL) { 124 1.1 cgd errno = ENOMEM; 125 1.47 jnemeth return -1; 126 1.1 cgd } 127 1.1 cgd gottoprec = 0; 128 1.27 abs 129 1.47 jnemeth source = ent; 130 1.47 jnemeth dest = toprec; 131 1.47 jnemeth while (*source != '\0') { /* Strip whitespace */ 132 1.27 abs *dest++ = *source++; /* Do not check first field */ 133 1.27 abs while (*source == ':') { 134 1.47 jnemeth check = source + 1; 135 1.29 abs while (*check && (isspace((unsigned char)*check) || 136 1.29 abs (*check=='\\' && isspace((unsigned char)check[1])))) 137 1.27 abs ++check; 138 1.47 jnemeth if (*check == ':') 139 1.47 jnemeth source = check; 140 1.27 abs else 141 1.27 abs break; 142 1.27 abs 143 1.27 abs } 144 1.27 abs } 145 1.47 jnemeth *dest = 0; 146 1.27 abs 147 1.47 jnemeth return 0; 148 1.1 cgd } 149 1.1 cgd 150 1.1 cgd /* 151 1.1 cgd * Cgetcap searches the capability record buf for the capability cap with 152 1.1 cgd * type `type'. A pointer to the value of cap is returned on success, NULL 153 1.1 cgd * if the requested capability couldn't be found. 154 1.1 cgd * 155 1.1 cgd * Specifying a type of ':' means that nothing should follow cap (:cap:). 156 1.1 cgd * In this case a pointer to the terminating ':' or NUL will be returned if 157 1.1 cgd * cap is found. 158 1.1 cgd * 159 1.1 cgd * If (cap, '@') or (cap, terminator, '@') is found before (cap, terminator) 160 1.1 cgd * return NULL. 161 1.1 cgd */ 162 1.1 cgd char * 163 1.52 joerg cgetcap(char *buf, const char *cap, int type) 164 1.1 cgd { 165 1.21 mycroft char *bp; 166 1.21 mycroft const char *cp; 167 1.1 cgd 168 1.30 lukem _DIAGASSERT(buf != NULL); 169 1.30 lukem _DIAGASSERT(cap != NULL); 170 1.30 lukem 171 1.1 cgd bp = buf; 172 1.1 cgd for (;;) { 173 1.1 cgd /* 174 1.1 cgd * Skip past the current capability field - it's either the 175 1.1 cgd * name field if this is the first time through the loop, or 176 1.1 cgd * the remainder of a field whose name failed to match cap. 177 1.1 cgd */ 178 1.1 cgd for (;;) 179 1.1 cgd if (*bp == '\0') 180 1.47 jnemeth return NULL; 181 1.47 jnemeth else if (*bp++ == ':') 182 1.47 jnemeth break; 183 1.1 cgd 184 1.1 cgd /* 185 1.1 cgd * Try to match (cap, type) in buf. 186 1.1 cgd */ 187 1.1 cgd for (cp = cap; *cp == *bp && *bp != '\0'; cp++, bp++) 188 1.1 cgd continue; 189 1.1 cgd if (*cp != '\0') 190 1.1 cgd continue; 191 1.1 cgd if (*bp == '@') 192 1.47 jnemeth return NULL; 193 1.1 cgd if (type == ':') { 194 1.1 cgd if (*bp != '\0' && *bp != ':') 195 1.1 cgd continue; 196 1.47 jnemeth return bp; 197 1.1 cgd } 198 1.1 cgd if (*bp != type) 199 1.1 cgd continue; 200 1.1 cgd bp++; 201 1.47 jnemeth return *bp == '@' ? NULL : bp; 202 1.1 cgd } 203 1.1 cgd /* NOTREACHED */ 204 1.1 cgd } 205 1.1 cgd 206 1.1 cgd /* 207 1.1 cgd * Cgetent extracts the capability record name from the NULL terminated file 208 1.1 cgd * array db_array and returns a pointer to a malloc'd copy of it in buf. 209 1.1 cgd * Buf must be retained through all subsequent calls to cgetcap, cgetnum, 210 1.1 cgd * cgetflag, and cgetstr, but may then be free'd. 0 is returned on success, 211 1.1 cgd * -1 if the requested record couldn't be found, -2 if a system error was 212 1.1 cgd * encountered (couldn't open/read a file, etc.), and -3 if a potential 213 1.1 cgd * reference loop is detected. 214 1.1 cgd */ 215 1.45 christos /* coverity[+alloc : arg-*0] */ 216 1.1 cgd int 217 1.40 christos cgetent(char **buf, const char * const *db_array, const char *name) 218 1.1 cgd { 219 1.18 thorpej size_t dummy; 220 1.1 cgd 221 1.30 lukem _DIAGASSERT(buf != NULL); 222 1.30 lukem _DIAGASSERT(db_array != NULL); 223 1.30 lukem _DIAGASSERT(name != NULL); 224 1.30 lukem 225 1.47 jnemeth return getent(buf, &dummy, db_array, -1, name, 0, NULL); 226 1.1 cgd } 227 1.1 cgd 228 1.48 christos void 229 1.48 christos csetexpandtc(int etc) 230 1.48 christos { 231 1.48 christos expandtc = etc; 232 1.48 christos } 233 1.48 christos 234 1.1 cgd /* 235 1.1 cgd * Getent implements the functions of cgetent. If fd is non-negative, 236 1.1 cgd * *db_array has already been opened and fd is the open file descriptor. We 237 1.1 cgd * do this to save time and avoid using up file descriptors for tc= 238 1.1 cgd * recursions. 239 1.1 cgd * 240 1.1 cgd * Getent returns the same success/failure codes as cgetent. On success, a 241 1.1 cgd * pointer to a malloc'ed capability record with all tc= capabilities fully 242 1.1 cgd * expanded and its length (not including trailing ASCII NUL) are left in 243 1.1 cgd * *cap and *len. 244 1.1 cgd * 245 1.1 cgd * Basic algorithm: 246 1.1 cgd * + Allocate memory incrementally as needed in chunks of size BFRAG 247 1.1 cgd * for capability buffer. 248 1.1 cgd * + Recurse for each tc=name and interpolate result. Stop when all 249 1.1 cgd * names interpolated, a name can't be found, or depth exceeds 250 1.1 cgd * MAX_RECURSION. 251 1.1 cgd */ 252 1.45 christos /* coverity[+alloc : arg-*0] */ 253 1.1 cgd static int 254 1.40 christos getent(char **cap, size_t *len, const char * const *db_array, int fd, 255 1.40 christos const char *name, int depth, char *nfield) 256 1.1 cgd { 257 1.41 christos char *record, *newrecord; 258 1.47 jnemeth char *r_end, *rp; /* pacify gcc */ 259 1.40 christos const char * const *db_p; 260 1.47 jnemeth int myfd, eof, foundit; 261 1.1 cgd int tc_not_resolved; 262 1.1 cgd 263 1.30 lukem _DIAGASSERT(cap != NULL); 264 1.30 lukem _DIAGASSERT(len != NULL); 265 1.30 lukem _DIAGASSERT(db_array != NULL); 266 1.30 lukem /* fd may be -1 */ 267 1.30 lukem _DIAGASSERT(name != NULL); 268 1.30 lukem /* nfield may be NULL */ 269 1.30 lukem 270 1.47 jnemeth myfd = 0; 271 1.47 jnemeth rp = NULL; 272 1.47 jnemeth 273 1.1 cgd /* 274 1.1 cgd * Return with ``loop detected'' error if we've recursed more than 275 1.1 cgd * MAX_RECURSION times. 276 1.1 cgd */ 277 1.1 cgd if (depth > MAX_RECURSION) 278 1.47 jnemeth return -3; 279 1.1 cgd 280 1.1 cgd /* 281 1.1 cgd * Check if we have a top record from cgetset(). 282 1.1 cgd */ 283 1.1 cgd if (depth == 0 && toprec != NULL && cgetmatch(toprec, name) == 0) { 284 1.47 jnemeth if ((record = malloc(topreclen + BFRAG)) == NULL) { 285 1.1 cgd errno = ENOMEM; 286 1.47 jnemeth return -2; 287 1.1 cgd } 288 1.11 mrg (void)strcpy(record, toprec); /* XXX: strcpy is safe */ 289 1.1 cgd db_p = db_array; 290 1.1 cgd rp = record + topreclen + 1; 291 1.1 cgd r_end = rp + BFRAG; 292 1.1 cgd goto tc_exp; 293 1.1 cgd } 294 1.1 cgd /* 295 1.1 cgd * Allocate first chunk of memory. 296 1.1 cgd */ 297 1.1 cgd if ((record = malloc(BFRAG)) == NULL) { 298 1.1 cgd errno = ENOMEM; 299 1.47 jnemeth return -2; 300 1.1 cgd } 301 1.1 cgd r_end = record + BFRAG; 302 1.1 cgd foundit = 0; 303 1.1 cgd /* 304 1.1 cgd * Loop through database array until finding the record. 305 1.1 cgd */ 306 1.1 cgd 307 1.1 cgd for (db_p = db_array; *db_p != NULL; db_p++) { 308 1.1 cgd eof = 0; 309 1.1 cgd 310 1.1 cgd /* 311 1.1 cgd * Open database if not already open. 312 1.1 cgd */ 313 1.1 cgd 314 1.1 cgd if (fd >= 0) { 315 1.15 kleink (void)lseek(fd, (off_t)0, SEEK_SET); 316 1.1 cgd } else { 317 1.41 christos #ifndef SMALL 318 1.53 christos DB *capdbp; 319 1.53 christos char pbuf[MAXPATHLEN]; 320 1.53 christos char *cbuf; 321 1.53 christos int retval; 322 1.53 christos size_t clen; 323 1.53 christos 324 1.1 cgd (void)snprintf(pbuf, sizeof(pbuf), "%s.db", *db_p); 325 1.54 christos if ((capdbp = dbopen(pbuf, O_RDONLY | O_CLOEXEC, 0, 326 1.54 christos DB_HASH, 0)) != NULL) { 327 1.1 cgd free(record); 328 1.1 cgd retval = cdbget(capdbp, &record, name); 329 1.8 cgd if (retval < 0) { 330 1.8 cgd /* no record available */ 331 1.8 cgd (void)capdbp->close(capdbp); 332 1.47 jnemeth return retval; 333 1.8 cgd } 334 1.8 cgd /* save the data; close frees it */ 335 1.7 cgd clen = strlen(record); 336 1.46 jnemeth if ((cbuf = malloc(clen + 1)) == NULL) { 337 1.46 jnemeth (void)capdbp->close(capdbp); 338 1.46 jnemeth errno = ENOMEM; 339 1.47 jnemeth return -2; 340 1.46 jnemeth } 341 1.23 perry memmove(cbuf, record, clen + 1); 342 1.7 cgd if (capdbp->close(capdbp) < 0) { 343 1.30 lukem int serrno = errno; 344 1.30 lukem 345 1.7 cgd free(cbuf); 346 1.30 lukem errno = serrno; 347 1.47 jnemeth return -2; 348 1.7 cgd } 349 1.7 cgd *len = clen; 350 1.7 cgd *cap = cbuf; 351 1.47 jnemeth return retval; 352 1.41 christos } else 353 1.41 christos #endif 354 1.41 christos { 355 1.54 christos fd = open(*db_p, O_RDONLY | O_CLOEXEC, 0); 356 1.1 cgd if (fd < 0) { 357 1.1 cgd /* No error on unfound file. */ 358 1.10 mycroft continue; 359 1.1 cgd } 360 1.1 cgd myfd = 1; 361 1.1 cgd } 362 1.1 cgd } 363 1.1 cgd /* 364 1.1 cgd * Find the requested capability record ... 365 1.1 cgd */ 366 1.1 cgd { 367 1.1 cgd char buf[BUFSIZ]; 368 1.20 mycroft char *b_end, *bp, *cp; 369 1.20 mycroft int c, slash; 370 1.1 cgd 371 1.1 cgd /* 372 1.1 cgd * Loop invariants: 373 1.1 cgd * There is always room for one more character in record. 374 1.1 cgd * R_end always points just past end of record. 375 1.1 cgd * Rp always points just past last character in record. 376 1.1 cgd * B_end always points just past last character in buf. 377 1.1 cgd * Bp always points at next character in buf. 378 1.20 mycroft * Cp remembers where the last colon was. 379 1.1 cgd */ 380 1.1 cgd b_end = buf; 381 1.1 cgd bp = buf; 382 1.47 jnemeth cp = NULL; 383 1.20 mycroft slash = 0; 384 1.1 cgd for (;;) { 385 1.1 cgd /* 386 1.1 cgd * Read in a line implementing (\, newline) 387 1.1 cgd * line continuation. 388 1.1 cgd */ 389 1.1 cgd rp = record; 390 1.1 cgd for (;;) { 391 1.1 cgd if (bp >= b_end) { 392 1.51 christos ssize_t n; 393 1.1 cgd 394 1.1 cgd n = read(fd, buf, sizeof(buf)); 395 1.1 cgd if (n <= 0) { 396 1.1 cgd if (myfd) 397 1.1 cgd (void)close(fd); 398 1.1 cgd if (n < 0) { 399 1.30 lukem int serrno = errno; 400 1.30 lukem 401 1.1 cgd free(record); 402 1.30 lukem errno = serrno; 403 1.47 jnemeth return -2; 404 1.1 cgd } else { 405 1.1 cgd fd = -1; 406 1.1 cgd eof = 1; 407 1.1 cgd break; 408 1.1 cgd } 409 1.1 cgd } 410 1.1 cgd b_end = buf+n; 411 1.1 cgd bp = buf; 412 1.1 cgd } 413 1.1 cgd 414 1.1 cgd c = *bp++; 415 1.1 cgd if (c == '\n') { 416 1.20 mycroft if (slash) { 417 1.20 mycroft slash = 0; 418 1.1 cgd rp--; 419 1.1 cgd continue; 420 1.1 cgd } else 421 1.1 cgd break; 422 1.1 cgd } 423 1.20 mycroft if (slash) { 424 1.20 mycroft slash = 0; 425 1.20 mycroft cp = 0; 426 1.20 mycroft } 427 1.20 mycroft if (c == ':') { 428 1.20 mycroft /* 429 1.20 mycroft * If the field was `empty' (i.e. 430 1.20 mycroft * contained only white space), back up 431 1.20 mycroft * to the colon (eliminating the 432 1.20 mycroft * field). 433 1.20 mycroft */ 434 1.47 jnemeth if (cp != NULL) 435 1.20 mycroft rp = cp; 436 1.20 mycroft else 437 1.20 mycroft cp = rp; 438 1.20 mycroft } else if (c == '\\') { 439 1.20 mycroft slash = 1; 440 1.20 mycroft } else if (c != ' ' && c != '\t') { 441 1.20 mycroft /* 442 1.20 mycroft * Forget where the colon was, as this 443 1.20 mycroft * is not an empty field. 444 1.20 mycroft */ 445 1.20 mycroft cp = 0; 446 1.20 mycroft } 447 1.1 cgd *rp++ = c; 448 1.1 cgd 449 1.1 cgd /* 450 1.1 cgd * Enforce loop invariant: if no room 451 1.1 cgd * left in record buffer, try to get 452 1.1 cgd * some more. 453 1.1 cgd */ 454 1.1 cgd if (rp >= r_end) { 455 1.51 christos ptrdiff_t pos; 456 1.1 cgd size_t newsize; 457 1.1 cgd 458 1.1 cgd pos = rp - record; 459 1.1 cgd newsize = r_end - record + BFRAG; 460 1.33 itojun newrecord = realloc(record, newsize); 461 1.33 itojun if (newrecord == NULL) { 462 1.33 itojun free(record); 463 1.1 cgd if (myfd) 464 1.1 cgd (void)close(fd); 465 1.30 lukem errno = ENOMEM; 466 1.47 jnemeth return -2; 467 1.1 cgd } 468 1.33 itojun record = newrecord; 469 1.1 cgd r_end = record + newsize; 470 1.1 cgd rp = record + pos; 471 1.1 cgd } 472 1.1 cgd } 473 1.20 mycroft /* Eliminate any white space after the last colon. */ 474 1.20 mycroft if (cp) 475 1.20 mycroft rp = cp + 1; 476 1.20 mycroft /* Loop invariant lets us do this. */ 477 1.1 cgd *rp++ = '\0'; 478 1.1 cgd 479 1.1 cgd /* 480 1.1 cgd * If encountered eof check next file. 481 1.1 cgd */ 482 1.1 cgd if (eof) 483 1.1 cgd break; 484 1.1 cgd 485 1.1 cgd /* 486 1.1 cgd * Toss blank lines and comments. 487 1.1 cgd */ 488 1.1 cgd if (*record == '\0' || *record == '#') 489 1.1 cgd continue; 490 1.1 cgd 491 1.1 cgd /* 492 1.1 cgd * See if this is the record we want ... 493 1.1 cgd */ 494 1.47 jnemeth if (cgetmatch(record, name) == 0) 495 1.1 cgd if (nfield == NULL || !nfcmp(nfield, record)) { 496 1.1 cgd foundit = 1; 497 1.1 cgd break; /* found it! */ 498 1.1 cgd } 499 1.1 cgd } 500 1.47 jnemeth } 501 1.1 cgd if (foundit) 502 1.1 cgd break; 503 1.1 cgd } 504 1.1 cgd 505 1.58 shm if (!foundit) { 506 1.58 shm free(record); 507 1.47 jnemeth return -1; 508 1.58 shm } 509 1.1 cgd 510 1.1 cgd /* 511 1.1 cgd * Got the capability record, but now we have to expand all tc=name 512 1.1 cgd * references in it ... 513 1.1 cgd */ 514 1.48 christos tc_exp: 515 1.48 christos tc_not_resolved = 0; 516 1.48 christos if (expandtc) { 517 1.16 perry char *newicap, *s; 518 1.17 perry size_t ilen, newilen; 519 1.51 christos int iret; 520 1.51 christos ptrdiff_t diff, tclen; 521 1.1 cgd char *icap, *scan, *tc, *tcstart, *tcend; 522 1.1 cgd 523 1.1 cgd /* 524 1.1 cgd * Loop invariants: 525 1.1 cgd * There is room for one more character in record. 526 1.1 cgd * R_end points just past end of record. 527 1.1 cgd * Rp points just past last character in record. 528 1.1 cgd * Scan points at remainder of record that needs to be 529 1.1 cgd * scanned for tc=name constructs. 530 1.1 cgd */ 531 1.1 cgd scan = record; 532 1.1 cgd for (;;) { 533 1.1 cgd if ((tc = cgetcap(scan, "tc", '=')) == NULL) 534 1.1 cgd break; 535 1.1 cgd 536 1.1 cgd /* 537 1.1 cgd * Find end of tc=name and stomp on the trailing `:' 538 1.1 cgd * (if present) so we can use it to call ourselves. 539 1.1 cgd */ 540 1.1 cgd s = tc; 541 1.1 cgd for (;;) 542 1.1 cgd if (*s == '\0') 543 1.1 cgd break; 544 1.1 cgd else 545 1.1 cgd if (*s++ == ':') { 546 1.1 cgd *(s - 1) = '\0'; 547 1.1 cgd break; 548 1.1 cgd } 549 1.1 cgd tcstart = tc - 3; 550 1.1 cgd tclen = s - tcstart; 551 1.1 cgd tcend = s; 552 1.1 cgd 553 1.1 cgd iret = getent(&icap, &ilen, db_p, fd, tc, depth+1, 554 1.1 cgd NULL); 555 1.1 cgd newicap = icap; /* Put into a register. */ 556 1.1 cgd newilen = ilen; 557 1.1 cgd if (iret != 0) { 558 1.1 cgd /* an error */ 559 1.1 cgd if (iret < -1) { 560 1.1 cgd if (myfd) 561 1.1 cgd (void)close(fd); 562 1.1 cgd free(record); 563 1.47 jnemeth return iret; 564 1.1 cgd } 565 1.1 cgd if (iret == 1) 566 1.1 cgd tc_not_resolved = 1; 567 1.1 cgd /* couldn't resolve tc */ 568 1.1 cgd if (iret == -1) { 569 1.1 cgd *(s - 1) = ':'; 570 1.1 cgd scan = s - 1; 571 1.1 cgd tc_not_resolved = 1; 572 1.1 cgd continue; 573 1.1 cgd 574 1.1 cgd } 575 1.1 cgd } 576 1.1 cgd /* not interested in name field of tc'ed record */ 577 1.1 cgd s = newicap; 578 1.1 cgd for (;;) 579 1.1 cgd if (*s == '\0') 580 1.1 cgd break; 581 1.47 jnemeth else if (*s++ == ':') 582 1.47 jnemeth break; 583 1.1 cgd newilen -= s - newicap; 584 1.1 cgd newicap = s; 585 1.1 cgd 586 1.1 cgd /* make sure interpolated record is `:'-terminated */ 587 1.1 cgd s += newilen; 588 1.47 jnemeth if (*(s - 1) != ':') { 589 1.1 cgd *s = ':'; /* overwrite NUL with : */ 590 1.1 cgd newilen++; 591 1.1 cgd } 592 1.1 cgd 593 1.1 cgd /* 594 1.1 cgd * Make sure there's enough room to insert the 595 1.1 cgd * new record. 596 1.1 cgd */ 597 1.1 cgd diff = newilen - tclen; 598 1.1 cgd if (diff >= r_end - rp) { 599 1.51 christos ptrdiff_t pos, tcpos, tcposend; 600 1.1 cgd size_t newsize; 601 1.1 cgd 602 1.1 cgd pos = rp - record; 603 1.1 cgd newsize = r_end - record + diff + BFRAG; 604 1.1 cgd tcpos = tcstart - record; 605 1.1 cgd tcposend = tcend - record; 606 1.33 itojun newrecord = realloc(record, newsize); 607 1.33 itojun if (newrecord == NULL) { 608 1.33 itojun free(record); 609 1.1 cgd if (myfd) 610 1.1 cgd (void)close(fd); 611 1.1 cgd free(icap); 612 1.30 lukem errno = ENOMEM; 613 1.47 jnemeth return -2; 614 1.1 cgd } 615 1.33 itojun record = newrecord; 616 1.1 cgd r_end = record + newsize; 617 1.1 cgd rp = record + pos; 618 1.1 cgd tcstart = record + tcpos; 619 1.1 cgd tcend = record + tcposend; 620 1.1 cgd } 621 1.1 cgd 622 1.1 cgd /* 623 1.1 cgd * Insert tc'ed record into our record. 624 1.1 cgd */ 625 1.1 cgd s = tcstart + newilen; 626 1.23 perry memmove(s, tcend, (size_t)(rp - tcend)); 627 1.23 perry memmove(tcstart, newicap, newilen); 628 1.1 cgd rp += diff; 629 1.1 cgd free(icap); 630 1.1 cgd 631 1.1 cgd /* 632 1.1 cgd * Start scan on `:' so next cgetcap works properly 633 1.1 cgd * (cgetcap always skips first field). 634 1.1 cgd */ 635 1.47 jnemeth scan = s - 1; 636 1.1 cgd } 637 1.1 cgd 638 1.1 cgd } 639 1.1 cgd /* 640 1.1 cgd * Close file (if we opened it), give back any extra memory, and 641 1.1 cgd * return capability, length and success. 642 1.1 cgd */ 643 1.1 cgd if (myfd) 644 1.1 cgd (void)close(fd); 645 1.1 cgd *len = rp - record - 1; /* don't count NUL */ 646 1.33 itojun if (r_end > rp) { 647 1.33 itojun if ((newrecord = 648 1.1 cgd realloc(record, (size_t)(rp - record))) == NULL) { 649 1.33 itojun free(record); 650 1.1 cgd errno = ENOMEM; 651 1.47 jnemeth return -2; 652 1.1 cgd } 653 1.33 itojun record = newrecord; 654 1.33 itojun } 655 1.1 cgd 656 1.1 cgd *cap = record; 657 1.1 cgd if (tc_not_resolved) 658 1.47 jnemeth return 1; 659 1.47 jnemeth return 0; 660 1.1 cgd } 661 1.1 cgd 662 1.41 christos #ifndef SMALL 663 1.1 cgd static int 664 1.40 christos cdbget(DB *capdbp, char **bp, const char *name) 665 1.1 cgd { 666 1.25 christos DBT key; 667 1.24 christos DBT data; 668 1.1 cgd 669 1.30 lukem _DIAGASSERT(capdbp != NULL); 670 1.30 lukem _DIAGASSERT(bp != NULL); 671 1.30 lukem _DIAGASSERT(name != NULL); 672 1.30 lukem 673 1.42 christos key.data = __UNCONST(name); 674 1.1 cgd key.size = strlen(name); 675 1.1 cgd 676 1.1 cgd for (;;) { 677 1.1 cgd /* Get the reference. */ 678 1.1 cgd switch(capdbp->get(capdbp, &key, &data, 0)) { 679 1.1 cgd case -1: 680 1.47 jnemeth return -2; 681 1.1 cgd case 1: 682 1.47 jnemeth return -1; 683 1.1 cgd } 684 1.1 cgd 685 1.1 cgd /* If not an index to another record, leave. */ 686 1.1 cgd if (((char *)data.data)[0] != SHADOW) 687 1.1 cgd break; 688 1.1 cgd 689 1.1 cgd key.data = (char *)data.data + 1; 690 1.1 cgd key.size = data.size - 1; 691 1.1 cgd } 692 1.1 cgd 693 1.1 cgd *bp = (char *)data.data + 1; 694 1.47 jnemeth return ((char *)(data.data))[0] == TCERR ? 1 : 0; 695 1.1 cgd } 696 1.41 christos #endif 697 1.1 cgd 698 1.1 cgd /* 699 1.1 cgd * Cgetmatch will return 0 if name is one of the names of the capability 700 1.1 cgd * record buf, -1 if not. 701 1.1 cgd */ 702 1.1 cgd int 703 1.40 christos cgetmatch(const char *buf, const char *name) 704 1.1 cgd { 705 1.21 mycroft const char *np, *bp; 706 1.1 cgd 707 1.30 lukem _DIAGASSERT(buf != NULL); 708 1.30 lukem _DIAGASSERT(name != NULL); 709 1.30 lukem 710 1.1 cgd /* 711 1.1 cgd * Start search at beginning of record. 712 1.1 cgd */ 713 1.1 cgd bp = buf; 714 1.1 cgd for (;;) { 715 1.1 cgd /* 716 1.1 cgd * Try to match a record name. 717 1.1 cgd */ 718 1.1 cgd np = name; 719 1.1 cgd for (;;) 720 1.26 christos if (*np == '\0') { 721 1.1 cgd if (*bp == '|' || *bp == ':' || *bp == '\0') 722 1.47 jnemeth return 0; 723 1.1 cgd else 724 1.1 cgd break; 725 1.47 jnemeth } else if (*bp++ != *np++) 726 1.47 jnemeth break; 727 1.1 cgd 728 1.1 cgd /* 729 1.1 cgd * Match failed, skip to next name in record. 730 1.1 cgd */ 731 1.34 mrg if (bp > buf) 732 1.34 mrg bp--; /* a '|' or ':' may have stopped the match */ 733 1.34 mrg else 734 1.47 jnemeth return -1; 735 1.1 cgd for (;;) 736 1.1 cgd if (*bp == '\0' || *bp == ':') 737 1.47 jnemeth return -1; /* match failed totally */ 738 1.47 jnemeth else if (*bp++ == '|') 739 1.47 jnemeth break; /* found next name */ 740 1.1 cgd } 741 1.1 cgd } 742 1.1 cgd 743 1.1 cgd int 744 1.40 christos cgetfirst(char **buf, const char * const *db_array) 745 1.1 cgd { 746 1.30 lukem 747 1.30 lukem _DIAGASSERT(buf != NULL); 748 1.30 lukem _DIAGASSERT(db_array != NULL); 749 1.30 lukem 750 1.1 cgd (void)cgetclose(); 751 1.47 jnemeth return cgetnext(buf, db_array); 752 1.1 cgd } 753 1.1 cgd 754 1.1 cgd static FILE *pfp; 755 1.1 cgd static int slash; 756 1.40 christos static const char * const *dbp; 757 1.1 cgd 758 1.1 cgd int 759 1.40 christos cgetclose(void) 760 1.1 cgd { 761 1.1 cgd if (pfp != NULL) { 762 1.1 cgd (void)fclose(pfp); 763 1.1 cgd pfp = NULL; 764 1.1 cgd } 765 1.1 cgd dbp = NULL; 766 1.1 cgd gottoprec = 0; 767 1.1 cgd slash = 0; 768 1.47 jnemeth return 0; 769 1.1 cgd } 770 1.1 cgd 771 1.1 cgd /* 772 1.1 cgd * Cgetnext() gets either the first or next entry in the logical database 773 1.1 cgd * specified by db_array. It returns 0 upon completion of the database, 1 774 1.1 cgd * upon returning an entry with more remaining, and -1 if an error occurs. 775 1.1 cgd */ 776 1.45 christos /* coverity[+alloc : arg-*0] */ 777 1.1 cgd int 778 1.40 christos cgetnext(char **bp, const char * const *db_array) 779 1.1 cgd { 780 1.43 christos size_t len = 0; 781 1.17 perry int status, done; 782 1.1 cgd char *cp, *line, *rp, *np, buf[BSIZE], nbuf[BSIZE]; 783 1.18 thorpej size_t dummy; 784 1.1 cgd 785 1.30 lukem _DIAGASSERT(bp != NULL); 786 1.30 lukem _DIAGASSERT(db_array != NULL); 787 1.30 lukem 788 1.1 cgd if (dbp == NULL) 789 1.1 cgd dbp = db_array; 790 1.1 cgd 791 1.50 christos if (pfp == NULL && (pfp = fopen(*dbp, "re")) == NULL) { 792 1.1 cgd (void)cgetclose(); 793 1.47 jnemeth return -1; 794 1.1 cgd } 795 1.47 jnemeth for (;;) { 796 1.47 jnemeth if (toprec != NULL && !gottoprec) { 797 1.1 cgd gottoprec = 1; 798 1.1 cgd line = toprec; 799 1.1 cgd } else { 800 1.6 cgd line = fgetln(pfp, &len); 801 1.44 christos if (line == NULL) { 802 1.44 christos if (pfp == NULL) 803 1.44 christos return -1; 804 1.1 cgd if (ferror(pfp)) { 805 1.1 cgd (void)cgetclose(); 806 1.47 jnemeth return -1; 807 1.1 cgd } else { 808 1.19 tv (void)fclose(pfp); 809 1.19 tv pfp = NULL; 810 1.1 cgd if (*++dbp == NULL) { 811 1.1 cgd (void)cgetclose(); 812 1.47 jnemeth return 0; 813 1.1 cgd } else if ((pfp = 814 1.50 christos fopen(*dbp, "re")) == NULL) { 815 1.1 cgd (void)cgetclose(); 816 1.47 jnemeth return -1; 817 1.1 cgd } else 818 1.1 cgd continue; 819 1.1 cgd } 820 1.5 cgd } else 821 1.5 cgd line[len - 1] = '\0'; 822 1.5 cgd if (len == 1) { 823 1.1 cgd slash = 0; 824 1.1 cgd continue; 825 1.1 cgd } 826 1.26 christos if (isspace((unsigned char)*line) || 827 1.1 cgd *line == ':' || *line == '#' || slash) { 828 1.5 cgd if (line[len - 2] == '\\') 829 1.1 cgd slash = 1; 830 1.1 cgd else 831 1.1 cgd slash = 0; 832 1.1 cgd continue; 833 1.1 cgd } 834 1.5 cgd if (line[len - 2] == '\\') 835 1.1 cgd slash = 1; 836 1.1 cgd else 837 1.1 cgd slash = 0; 838 1.1 cgd } 839 1.1 cgd 840 1.1 cgd 841 1.1 cgd /* 842 1.1 cgd * Line points to a name line. 843 1.1 cgd */ 844 1.35 groo if (len > sizeof(nbuf)) 845 1.35 groo return -1; 846 1.1 cgd done = 0; 847 1.1 cgd np = nbuf; 848 1.1 cgd for (;;) { 849 1.1 cgd for (cp = line; *cp != '\0'; cp++) { 850 1.1 cgd if (*cp == ':') { 851 1.1 cgd *np++ = ':'; 852 1.1 cgd done = 1; 853 1.1 cgd break; 854 1.1 cgd } 855 1.1 cgd if (*cp == '\\') 856 1.1 cgd break; 857 1.1 cgd *np++ = *cp; 858 1.1 cgd } 859 1.1 cgd if (done) { 860 1.1 cgd *np = '\0'; 861 1.1 cgd break; 862 1.1 cgd } else { /* name field extends beyond the line */ 863 1.6 cgd line = fgetln(pfp, &len); 864 1.1 cgd if (line == NULL && pfp) { 865 1.1 cgd if (ferror(pfp)) { 866 1.1 cgd (void)cgetclose(); 867 1.47 jnemeth return -1; 868 1.1 cgd } 869 1.19 tv (void)fclose(pfp); 870 1.19 tv pfp = NULL; 871 1.19 tv *np = '\0'; 872 1.19 tv break; 873 1.5 cgd } else 874 1.5 cgd line[len - 1] = '\0'; 875 1.1 cgd } 876 1.1 cgd } 877 1.35 groo if (len > sizeof(buf)) 878 1.35 groo return -1; 879 1.1 cgd rp = buf; 880 1.47 jnemeth for (cp = nbuf; *cp != '\0'; cp++) 881 1.1 cgd if (*cp == '|' || *cp == ':') 882 1.1 cgd break; 883 1.1 cgd else 884 1.1 cgd *rp++ = *cp; 885 1.1 cgd 886 1.1 cgd *rp = '\0'; 887 1.1 cgd /* 888 1.1 cgd * XXX 889 1.1 cgd * Last argument of getent here should be nbuf if we want true 890 1.1 cgd * sequential access in the case of duplicates. 891 1.1 cgd * With NULL, getent will return the first entry found 892 1.1 cgd * rather than the duplicate entry record. This is a 893 1.1 cgd * matter of semantics that should be resolved. 894 1.1 cgd */ 895 1.1 cgd status = getent(bp, &dummy, db_array, -1, buf, 0, NULL); 896 1.1 cgd if (status == -2 || status == -3) 897 1.1 cgd (void)cgetclose(); 898 1.1 cgd 899 1.47 jnemeth return status + 1; 900 1.1 cgd } 901 1.1 cgd /* NOTREACHED */ 902 1.1 cgd } 903 1.1 cgd 904 1.1 cgd /* 905 1.1 cgd * Cgetstr retrieves the value of the string capability cap from the 906 1.1 cgd * capability record pointed to by buf. A pointer to a decoded, NUL 907 1.1 cgd * terminated, malloc'd copy of the string is returned in the char * 908 1.1 cgd * pointed to by str. The length of the string not including the trailing 909 1.1 cgd * NUL is returned on success, -1 if the requested string capability 910 1.1 cgd * couldn't be found, -2 if a system error was encountered (storage 911 1.1 cgd * allocation failure). 912 1.1 cgd */ 913 1.1 cgd int 914 1.40 christos cgetstr(char *buf, const char *cap, char **str) 915 1.1 cgd { 916 1.16 perry u_int m_room; 917 1.21 mycroft const char *bp; 918 1.21 mycroft char *mp; 919 1.51 christos ptrdiff_t len; 920 1.33 itojun char *mem, *newmem; 921 1.1 cgd 922 1.30 lukem _DIAGASSERT(buf != NULL); 923 1.30 lukem _DIAGASSERT(cap != NULL); 924 1.30 lukem _DIAGASSERT(str != NULL); 925 1.30 lukem 926 1.1 cgd /* 927 1.1 cgd * Find string capability cap 928 1.1 cgd */ 929 1.1 cgd bp = cgetcap(buf, cap, '='); 930 1.1 cgd if (bp == NULL) 931 1.47 jnemeth return -1; 932 1.1 cgd 933 1.1 cgd /* 934 1.1 cgd * Conversion / storage allocation loop ... Allocate memory in 935 1.1 cgd * chunks SFRAG in size. 936 1.1 cgd */ 937 1.1 cgd if ((mem = malloc(SFRAG)) == NULL) { 938 1.1 cgd errno = ENOMEM; 939 1.47 jnemeth return -2; /* couldn't even allocate the first fragment */ 940 1.1 cgd } 941 1.1 cgd m_room = SFRAG; 942 1.1 cgd mp = mem; 943 1.1 cgd 944 1.1 cgd while (*bp != ':' && *bp != '\0') { 945 1.1 cgd /* 946 1.1 cgd * Loop invariants: 947 1.1 cgd * There is always room for one more character in mem. 948 1.1 cgd * Mp always points just past last character in mem. 949 1.1 cgd * Bp always points at next character in buf. 950 1.1 cgd */ 951 1.1 cgd if (*bp == '^') { 952 1.1 cgd bp++; 953 1.1 cgd if (*bp == ':' || *bp == '\0') 954 1.1 cgd break; /* drop unfinished escape */ 955 1.1 cgd *mp++ = *bp++ & 037; 956 1.1 cgd } else if (*bp == '\\') { 957 1.1 cgd bp++; 958 1.1 cgd if (*bp == ':' || *bp == '\0') 959 1.1 cgd break; /* drop unfinished escape */ 960 1.1 cgd if ('0' <= *bp && *bp <= '7') { 961 1.16 perry int n, i; 962 1.1 cgd 963 1.1 cgd n = 0; 964 1.1 cgd i = 3; /* maximum of three octal digits */ 965 1.1 cgd do { 966 1.1 cgd n = n * 8 + (*bp++ - '0'); 967 1.1 cgd } while (--i && '0' <= *bp && *bp <= '7'); 968 1.1 cgd *mp++ = n; 969 1.1 cgd } 970 1.1 cgd else switch (*bp++) { 971 1.1 cgd case 'b': case 'B': 972 1.1 cgd *mp++ = '\b'; 973 1.1 cgd break; 974 1.1 cgd case 't': case 'T': 975 1.1 cgd *mp++ = '\t'; 976 1.1 cgd break; 977 1.1 cgd case 'n': case 'N': 978 1.1 cgd *mp++ = '\n'; 979 1.1 cgd break; 980 1.1 cgd case 'f': case 'F': 981 1.1 cgd *mp++ = '\f'; 982 1.1 cgd break; 983 1.1 cgd case 'r': case 'R': 984 1.1 cgd *mp++ = '\r'; 985 1.1 cgd break; 986 1.1 cgd case 'e': case 'E': 987 1.1 cgd *mp++ = ESC; 988 1.1 cgd break; 989 1.1 cgd case 'c': case 'C': 990 1.1 cgd *mp++ = ':'; 991 1.1 cgd break; 992 1.1 cgd default: 993 1.1 cgd /* 994 1.1 cgd * Catches '\', '^', and 995 1.1 cgd * everything else. 996 1.1 cgd */ 997 1.1 cgd *mp++ = *(bp-1); 998 1.1 cgd break; 999 1.1 cgd } 1000 1.1 cgd } else 1001 1.1 cgd *mp++ = *bp++; 1002 1.1 cgd m_room--; 1003 1.1 cgd 1004 1.1 cgd /* 1005 1.1 cgd * Enforce loop invariant: if no room left in current 1006 1.1 cgd * buffer, try to get some more. 1007 1.1 cgd */ 1008 1.1 cgd if (m_room == 0) { 1009 1.1 cgd size_t size = mp - mem; 1010 1.1 cgd 1011 1.33 itojun if ((newmem = realloc(mem, size + SFRAG)) == NULL) { 1012 1.33 itojun free(mem); 1013 1.47 jnemeth return -2; 1014 1.33 itojun } 1015 1.33 itojun mem = newmem; 1016 1.1 cgd m_room = SFRAG; 1017 1.1 cgd mp = mem + size; 1018 1.1 cgd } 1019 1.1 cgd } 1020 1.1 cgd *mp++ = '\0'; /* loop invariant let's us do this */ 1021 1.1 cgd m_room--; 1022 1.1 cgd len = mp - mem - 1; 1023 1.1 cgd 1024 1.1 cgd /* 1025 1.1 cgd * Give back any extra memory and return value and success. 1026 1.1 cgd */ 1027 1.33 itojun if (m_room != 0) { 1028 1.33 itojun if ((newmem = realloc(mem, (size_t)(mp - mem))) == NULL) { 1029 1.33 itojun free(mem); 1030 1.47 jnemeth return -2; 1031 1.33 itojun } 1032 1.33 itojun mem = newmem; 1033 1.33 itojun } 1034 1.1 cgd *str = mem; 1035 1.51 christos _DIAGASSERT(__type_fit(int, len)); 1036 1.51 christos return (int)len; 1037 1.1 cgd } 1038 1.1 cgd 1039 1.1 cgd /* 1040 1.1 cgd * Cgetustr retrieves the value of the string capability cap from the 1041 1.1 cgd * capability record pointed to by buf. The difference between cgetustr() 1042 1.1 cgd * and cgetstr() is that cgetustr does not decode escapes but rather treats 1043 1.1 cgd * all characters literally. A pointer to a NUL terminated malloc'd 1044 1.1 cgd * copy of the string is returned in the char pointed to by str. The 1045 1.1 cgd * length of the string not including the trailing NUL is returned on success, 1046 1.1 cgd * -1 if the requested string capability couldn't be found, -2 if a system 1047 1.1 cgd * error was encountered (storage allocation failure). 1048 1.1 cgd */ 1049 1.1 cgd int 1050 1.40 christos cgetustr(char *buf, const char *cap, char **str) 1051 1.1 cgd { 1052 1.16 perry u_int m_room; 1053 1.21 mycroft const char *bp; 1054 1.21 mycroft char *mp; 1055 1.51 christos size_t len; 1056 1.33 itojun char *mem, *newmem; 1057 1.1 cgd 1058 1.30 lukem _DIAGASSERT(buf != NULL); 1059 1.30 lukem _DIAGASSERT(cap != NULL); 1060 1.30 lukem _DIAGASSERT(str != NULL); 1061 1.30 lukem 1062 1.1 cgd /* 1063 1.1 cgd * Find string capability cap 1064 1.1 cgd */ 1065 1.1 cgd if ((bp = cgetcap(buf, cap, '=')) == NULL) 1066 1.47 jnemeth return -1; 1067 1.1 cgd 1068 1.1 cgd /* 1069 1.1 cgd * Conversion / storage allocation loop ... Allocate memory in 1070 1.1 cgd * chunks SFRAG in size. 1071 1.1 cgd */ 1072 1.1 cgd if ((mem = malloc(SFRAG)) == NULL) { 1073 1.1 cgd errno = ENOMEM; 1074 1.47 jnemeth return -2; /* couldn't even allocate the first fragment */ 1075 1.1 cgd } 1076 1.1 cgd m_room = SFRAG; 1077 1.1 cgd mp = mem; 1078 1.1 cgd 1079 1.1 cgd while (*bp != ':' && *bp != '\0') { 1080 1.1 cgd /* 1081 1.1 cgd * Loop invariants: 1082 1.1 cgd * There is always room for one more character in mem. 1083 1.1 cgd * Mp always points just past last character in mem. 1084 1.1 cgd * Bp always points at next character in buf. 1085 1.1 cgd */ 1086 1.1 cgd *mp++ = *bp++; 1087 1.1 cgd m_room--; 1088 1.1 cgd 1089 1.1 cgd /* 1090 1.1 cgd * Enforce loop invariant: if no room left in current 1091 1.1 cgd * buffer, try to get some more. 1092 1.1 cgd */ 1093 1.1 cgd if (m_room == 0) { 1094 1.1 cgd size_t size = mp - mem; 1095 1.1 cgd 1096 1.33 itojun if ((newmem = realloc(mem, size + SFRAG)) == NULL) { 1097 1.33 itojun free(mem); 1098 1.47 jnemeth return -2; 1099 1.33 itojun } 1100 1.33 itojun mem = newmem; 1101 1.1 cgd m_room = SFRAG; 1102 1.1 cgd mp = mem + size; 1103 1.1 cgd } 1104 1.1 cgd } 1105 1.1 cgd *mp++ = '\0'; /* loop invariant let's us do this */ 1106 1.1 cgd m_room--; 1107 1.1 cgd len = mp - mem - 1; 1108 1.1 cgd 1109 1.1 cgd /* 1110 1.1 cgd * Give back any extra memory and return value and success. 1111 1.1 cgd */ 1112 1.33 itojun if (m_room != 0) { 1113 1.33 itojun if ((newmem = realloc(mem, (size_t)(mp - mem))) == NULL) { 1114 1.33 itojun free(mem); 1115 1.47 jnemeth return -2; 1116 1.33 itojun } 1117 1.33 itojun mem = newmem; 1118 1.33 itojun } 1119 1.1 cgd *str = mem; 1120 1.51 christos _DIAGASSERT(__type_fit(int, len)); 1121 1.51 christos return (int)len; 1122 1.1 cgd } 1123 1.1 cgd 1124 1.1 cgd /* 1125 1.1 cgd * Cgetnum retrieves the value of the numeric capability cap from the 1126 1.1 cgd * capability record pointed to by buf. The numeric value is returned in 1127 1.1 cgd * the long pointed to by num. 0 is returned on success, -1 if the requested 1128 1.1 cgd * numeric capability couldn't be found. 1129 1.1 cgd */ 1130 1.1 cgd int 1131 1.40 christos cgetnum(char *buf, const char *cap, long *num) 1132 1.1 cgd { 1133 1.16 perry long n; 1134 1.16 perry int base, digit; 1135 1.21 mycroft const char *bp; 1136 1.1 cgd 1137 1.30 lukem _DIAGASSERT(buf != NULL); 1138 1.30 lukem _DIAGASSERT(cap != NULL); 1139 1.30 lukem _DIAGASSERT(num != NULL); 1140 1.30 lukem 1141 1.1 cgd /* 1142 1.1 cgd * Find numeric capability cap 1143 1.1 cgd */ 1144 1.1 cgd bp = cgetcap(buf, cap, '#'); 1145 1.1 cgd if (bp == NULL) 1146 1.47 jnemeth return -1; 1147 1.1 cgd 1148 1.1 cgd /* 1149 1.1 cgd * Look at value and determine numeric base: 1150 1.1 cgd * 0x... or 0X... hexadecimal, 1151 1.1 cgd * else 0... octal, 1152 1.1 cgd * else decimal. 1153 1.1 cgd */ 1154 1.1 cgd if (*bp == '0') { 1155 1.1 cgd bp++; 1156 1.1 cgd if (*bp == 'x' || *bp == 'X') { 1157 1.1 cgd bp++; 1158 1.1 cgd base = 16; 1159 1.1 cgd } else 1160 1.1 cgd base = 8; 1161 1.1 cgd } else 1162 1.1 cgd base = 10; 1163 1.1 cgd 1164 1.1 cgd /* 1165 1.1 cgd * Conversion loop ... 1166 1.1 cgd */ 1167 1.1 cgd n = 0; 1168 1.1 cgd for (;;) { 1169 1.1 cgd if ('0' <= *bp && *bp <= '9') 1170 1.1 cgd digit = *bp - '0'; 1171 1.1 cgd else if ('a' <= *bp && *bp <= 'f') 1172 1.1 cgd digit = 10 + *bp - 'a'; 1173 1.1 cgd else if ('A' <= *bp && *bp <= 'F') 1174 1.1 cgd digit = 10 + *bp - 'A'; 1175 1.1 cgd else 1176 1.1 cgd break; 1177 1.1 cgd 1178 1.1 cgd if (digit >= base) 1179 1.1 cgd break; 1180 1.1 cgd 1181 1.1 cgd n = n * base + digit; 1182 1.1 cgd bp++; 1183 1.1 cgd } 1184 1.1 cgd 1185 1.1 cgd /* 1186 1.1 cgd * Return value and success. 1187 1.1 cgd */ 1188 1.1 cgd *num = n; 1189 1.47 jnemeth return 0; 1190 1.1 cgd } 1191 1.1 cgd 1192 1.1 cgd 1193 1.1 cgd /* 1194 1.1 cgd * Compare name field of record. 1195 1.1 cgd */ 1196 1.1 cgd static int 1197 1.40 christos nfcmp(char *nf, char *rec) 1198 1.1 cgd { 1199 1.1 cgd char *cp, tmp; 1200 1.1 cgd int ret; 1201 1.30 lukem 1202 1.30 lukem _DIAGASSERT(nf != NULL); 1203 1.30 lukem _DIAGASSERT(rec != NULL); 1204 1.30 lukem 1205 1.1 cgd for (cp = rec; *cp != ':'; cp++) 1206 1.47 jnemeth continue; 1207 1.1 cgd 1208 1.1 cgd tmp = *(cp + 1); 1209 1.1 cgd *(cp + 1) = '\0'; 1210 1.1 cgd ret = strcmp(nf, rec); 1211 1.1 cgd *(cp + 1) = tmp; 1212 1.1 cgd 1213 1.47 jnemeth return ret; 1214 1.1 cgd } 1215