getcap.c revision 1.58 1 1.58 shm /* $NetBSD: getcap.c,v 1.58 2023/09/21 13:46:12 shm Exp $ */
2 1.9 cgd
3 1.1 cgd /*-
4 1.9 cgd * Copyright (c) 1992, 1993
5 1.9 cgd * The Regents of the University of California. All rights reserved.
6 1.1 cgd *
7 1.1 cgd * This code is derived from software contributed to Berkeley by
8 1.1 cgd * Casey Leedom of Lawrence Livermore National Laboratory.
9 1.1 cgd *
10 1.1 cgd * Redistribution and use in source and binary forms, with or without
11 1.1 cgd * modification, are permitted provided that the following conditions
12 1.1 cgd * are met:
13 1.1 cgd * 1. Redistributions of source code must retain the above copyright
14 1.1 cgd * notice, this list of conditions and the following disclaimer.
15 1.1 cgd * 2. Redistributions in binary form must reproduce the above copyright
16 1.1 cgd * notice, this list of conditions and the following disclaimer in the
17 1.1 cgd * documentation and/or other materials provided with the distribution.
18 1.38 agc * 3. Neither the name of the University nor the names of its contributors
19 1.1 cgd * may be used to endorse or promote products derived from this software
20 1.1 cgd * without specific prior written permission.
21 1.1 cgd *
22 1.1 cgd * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
23 1.1 cgd * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24 1.1 cgd * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 1.1 cgd * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
26 1.1 cgd * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27 1.1 cgd * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28 1.1 cgd * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29 1.1 cgd * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30 1.1 cgd * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31 1.1 cgd * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32 1.1 cgd * SUCH DAMAGE.
33 1.1 cgd */
34 1.1 cgd
35 1.39 lukem #if HAVE_NBTOOL_CONFIG_H
36 1.39 lukem #include "nbtool_config.h"
37 1.37 uwe #endif
38 1.37 uwe
39 1.13 christos #include <sys/cdefs.h>
40 1.1 cgd #if defined(LIBC_SCCS) && !defined(lint)
41 1.9 cgd #if 0
42 1.9 cgd static char sccsid[] = "@(#)getcap.c 8.3 (Berkeley) 3/25/94";
43 1.9 cgd #else
44 1.58 shm __RCSID("$NetBSD: getcap.c,v 1.58 2023/09/21 13:46:12 shm Exp $");
45 1.9 cgd #endif
46 1.1 cgd #endif /* LIBC_SCCS and not lint */
47 1.1 cgd
48 1.57 manu #ifndef LIBHACK
49 1.14 jtc #include "namespace.h"
50 1.41 christos #endif
51 1.1 cgd #include <sys/types.h>
52 1.36 tron #include <sys/param.h>
53 1.30 lukem
54 1.30 lukem #include <assert.h>
55 1.51 christos #include <stddef.h>
56 1.1 cgd #include <ctype.h>
57 1.41 christos #ifndef SMALL
58 1.1 cgd #include <db.h>
59 1.41 christos #endif
60 1.1 cgd #include <errno.h>
61 1.1 cgd #include <fcntl.h>
62 1.1 cgd #include <limits.h>
63 1.1 cgd #include <stdio.h>
64 1.1 cgd #include <stdlib.h>
65 1.1 cgd #include <string.h>
66 1.1 cgd #include <unistd.h>
67 1.14 jtc
68 1.57 manu #if defined(__weak_alias) && !defined(LIBHACK)
69 1.32 mycroft __weak_alias(cgetcap,_cgetcap)
70 1.32 mycroft __weak_alias(cgetclose,_cgetclose)
71 1.32 mycroft __weak_alias(cgetent,_cgetent)
72 1.32 mycroft __weak_alias(cgetfirst,_cgetfirst)
73 1.32 mycroft __weak_alias(cgetmatch,_cgetmatch)
74 1.32 mycroft __weak_alias(cgetnext,_cgetnext)
75 1.32 mycroft __weak_alias(cgetnum,_cgetnum)
76 1.32 mycroft __weak_alias(cgetset,_cgetset)
77 1.32 mycroft __weak_alias(cgetstr,_cgetstr)
78 1.32 mycroft __weak_alias(cgetustr,_cgetustr)
79 1.48 christos __weak_alias(csetexpandtc,_csetexpandtc)
80 1.14 jtc #endif
81 1.1 cgd
82 1.1 cgd #define BFRAG 1024
83 1.1 cgd #define BSIZE 1024
84 1.1 cgd #define ESC ('[' & 037) /* ASCII ESC */
85 1.1 cgd #define MAX_RECURSION 32 /* maximum getent recursion */
86 1.1 cgd #define SFRAG 100 /* cgetstr mallocs in SFRAG chunks */
87 1.1 cgd
88 1.1 cgd #define RECOK (char)0
89 1.1 cgd #define TCERR (char)1
90 1.1 cgd #define SHADOW (char)2
91 1.1 cgd
92 1.1 cgd static size_t topreclen; /* toprec length */
93 1.1 cgd static char *toprec; /* Additional record specified by cgetset() */
94 1.1 cgd static int gottoprec; /* Flag indicating retrieval of toprecord */
95 1.48 christos static int expandtc = 1; /* flag to expand tc= or not */
96 1.1 cgd
97 1.41 christos #ifndef SMALL
98 1.40 christos static int cdbget(DB *, char **, const char *);
99 1.41 christos #endif
100 1.40 christos static int getent(char **, size_t *, const char * const *, int,
101 1.40 christos const char *, int, char *);
102 1.40 christos static int nfcmp(char *, char *);
103 1.1 cgd
104 1.1 cgd /*
105 1.1 cgd * Cgetset() allows the addition of a user specified buffer to be added
106 1.1 cgd * to the database array, in effect "pushing" the buffer on top of the
107 1.1 cgd * virtual database. 0 is returned on success, -1 on failure.
108 1.1 cgd */
109 1.1 cgd int
110 1.40 christos cgetset(const char *ent)
111 1.1 cgd {
112 1.27 abs const char *source, *check;
113 1.27 abs char *dest;
114 1.27 abs
115 1.1 cgd if (ent == NULL) {
116 1.47 jnemeth if (toprec != NULL)
117 1.1 cgd free(toprec);
118 1.1 cgd toprec = NULL;
119 1.1 cgd topreclen = 0;
120 1.47 jnemeth return 0;
121 1.1 cgd }
122 1.1 cgd topreclen = strlen(ent);
123 1.47 jnemeth if ((toprec = malloc(topreclen + 1)) == NULL) {
124 1.1 cgd errno = ENOMEM;
125 1.47 jnemeth return -1;
126 1.1 cgd }
127 1.1 cgd gottoprec = 0;
128 1.27 abs
129 1.47 jnemeth source = ent;
130 1.47 jnemeth dest = toprec;
131 1.47 jnemeth while (*source != '\0') { /* Strip whitespace */
132 1.27 abs *dest++ = *source++; /* Do not check first field */
133 1.27 abs while (*source == ':') {
134 1.47 jnemeth check = source + 1;
135 1.29 abs while (*check && (isspace((unsigned char)*check) ||
136 1.29 abs (*check=='\\' && isspace((unsigned char)check[1]))))
137 1.27 abs ++check;
138 1.47 jnemeth if (*check == ':')
139 1.47 jnemeth source = check;
140 1.27 abs else
141 1.27 abs break;
142 1.27 abs
143 1.27 abs }
144 1.27 abs }
145 1.47 jnemeth *dest = 0;
146 1.27 abs
147 1.47 jnemeth return 0;
148 1.1 cgd }
149 1.1 cgd
150 1.1 cgd /*
151 1.1 cgd * Cgetcap searches the capability record buf for the capability cap with
152 1.1 cgd * type `type'. A pointer to the value of cap is returned on success, NULL
153 1.1 cgd * if the requested capability couldn't be found.
154 1.1 cgd *
155 1.1 cgd * Specifying a type of ':' means that nothing should follow cap (:cap:).
156 1.1 cgd * In this case a pointer to the terminating ':' or NUL will be returned if
157 1.1 cgd * cap is found.
158 1.1 cgd *
159 1.1 cgd * If (cap, '@') or (cap, terminator, '@') is found before (cap, terminator)
160 1.1 cgd * return NULL.
161 1.1 cgd */
162 1.1 cgd char *
163 1.52 joerg cgetcap(char *buf, const char *cap, int type)
164 1.1 cgd {
165 1.21 mycroft char *bp;
166 1.21 mycroft const char *cp;
167 1.1 cgd
168 1.30 lukem _DIAGASSERT(buf != NULL);
169 1.30 lukem _DIAGASSERT(cap != NULL);
170 1.30 lukem
171 1.1 cgd bp = buf;
172 1.1 cgd for (;;) {
173 1.1 cgd /*
174 1.1 cgd * Skip past the current capability field - it's either the
175 1.1 cgd * name field if this is the first time through the loop, or
176 1.1 cgd * the remainder of a field whose name failed to match cap.
177 1.1 cgd */
178 1.1 cgd for (;;)
179 1.1 cgd if (*bp == '\0')
180 1.47 jnemeth return NULL;
181 1.47 jnemeth else if (*bp++ == ':')
182 1.47 jnemeth break;
183 1.1 cgd
184 1.1 cgd /*
185 1.1 cgd * Try to match (cap, type) in buf.
186 1.1 cgd */
187 1.1 cgd for (cp = cap; *cp == *bp && *bp != '\0'; cp++, bp++)
188 1.1 cgd continue;
189 1.1 cgd if (*cp != '\0')
190 1.1 cgd continue;
191 1.1 cgd if (*bp == '@')
192 1.47 jnemeth return NULL;
193 1.1 cgd if (type == ':') {
194 1.1 cgd if (*bp != '\0' && *bp != ':')
195 1.1 cgd continue;
196 1.47 jnemeth return bp;
197 1.1 cgd }
198 1.1 cgd if (*bp != type)
199 1.1 cgd continue;
200 1.1 cgd bp++;
201 1.47 jnemeth return *bp == '@' ? NULL : bp;
202 1.1 cgd }
203 1.1 cgd /* NOTREACHED */
204 1.1 cgd }
205 1.1 cgd
206 1.1 cgd /*
207 1.1 cgd * Cgetent extracts the capability record name from the NULL terminated file
208 1.1 cgd * array db_array and returns a pointer to a malloc'd copy of it in buf.
209 1.1 cgd * Buf must be retained through all subsequent calls to cgetcap, cgetnum,
210 1.1 cgd * cgetflag, and cgetstr, but may then be free'd. 0 is returned on success,
211 1.1 cgd * -1 if the requested record couldn't be found, -2 if a system error was
212 1.1 cgd * encountered (couldn't open/read a file, etc.), and -3 if a potential
213 1.1 cgd * reference loop is detected.
214 1.1 cgd */
215 1.45 christos /* coverity[+alloc : arg-*0] */
216 1.1 cgd int
217 1.40 christos cgetent(char **buf, const char * const *db_array, const char *name)
218 1.1 cgd {
219 1.18 thorpej size_t dummy;
220 1.1 cgd
221 1.30 lukem _DIAGASSERT(buf != NULL);
222 1.30 lukem _DIAGASSERT(db_array != NULL);
223 1.30 lukem _DIAGASSERT(name != NULL);
224 1.30 lukem
225 1.47 jnemeth return getent(buf, &dummy, db_array, -1, name, 0, NULL);
226 1.1 cgd }
227 1.1 cgd
228 1.48 christos void
229 1.48 christos csetexpandtc(int etc)
230 1.48 christos {
231 1.48 christos expandtc = etc;
232 1.48 christos }
233 1.48 christos
234 1.1 cgd /*
235 1.1 cgd * Getent implements the functions of cgetent. If fd is non-negative,
236 1.1 cgd * *db_array has already been opened and fd is the open file descriptor. We
237 1.1 cgd * do this to save time and avoid using up file descriptors for tc=
238 1.1 cgd * recursions.
239 1.1 cgd *
240 1.1 cgd * Getent returns the same success/failure codes as cgetent. On success, a
241 1.1 cgd * pointer to a malloc'ed capability record with all tc= capabilities fully
242 1.1 cgd * expanded and its length (not including trailing ASCII NUL) are left in
243 1.1 cgd * *cap and *len.
244 1.1 cgd *
245 1.1 cgd * Basic algorithm:
246 1.1 cgd * + Allocate memory incrementally as needed in chunks of size BFRAG
247 1.1 cgd * for capability buffer.
248 1.1 cgd * + Recurse for each tc=name and interpolate result. Stop when all
249 1.1 cgd * names interpolated, a name can't be found, or depth exceeds
250 1.1 cgd * MAX_RECURSION.
251 1.1 cgd */
252 1.45 christos /* coverity[+alloc : arg-*0] */
253 1.1 cgd static int
254 1.40 christos getent(char **cap, size_t *len, const char * const *db_array, int fd,
255 1.40 christos const char *name, int depth, char *nfield)
256 1.1 cgd {
257 1.41 christos char *record, *newrecord;
258 1.47 jnemeth char *r_end, *rp; /* pacify gcc */
259 1.40 christos const char * const *db_p;
260 1.47 jnemeth int myfd, eof, foundit;
261 1.1 cgd int tc_not_resolved;
262 1.1 cgd
263 1.30 lukem _DIAGASSERT(cap != NULL);
264 1.30 lukem _DIAGASSERT(len != NULL);
265 1.30 lukem _DIAGASSERT(db_array != NULL);
266 1.30 lukem /* fd may be -1 */
267 1.30 lukem _DIAGASSERT(name != NULL);
268 1.30 lukem /* nfield may be NULL */
269 1.30 lukem
270 1.47 jnemeth myfd = 0;
271 1.47 jnemeth rp = NULL;
272 1.47 jnemeth
273 1.1 cgd /*
274 1.1 cgd * Return with ``loop detected'' error if we've recursed more than
275 1.1 cgd * MAX_RECURSION times.
276 1.1 cgd */
277 1.1 cgd if (depth > MAX_RECURSION)
278 1.47 jnemeth return -3;
279 1.1 cgd
280 1.1 cgd /*
281 1.1 cgd * Check if we have a top record from cgetset().
282 1.1 cgd */
283 1.1 cgd if (depth == 0 && toprec != NULL && cgetmatch(toprec, name) == 0) {
284 1.47 jnemeth if ((record = malloc(topreclen + BFRAG)) == NULL) {
285 1.1 cgd errno = ENOMEM;
286 1.47 jnemeth return -2;
287 1.1 cgd }
288 1.11 mrg (void)strcpy(record, toprec); /* XXX: strcpy is safe */
289 1.1 cgd db_p = db_array;
290 1.1 cgd rp = record + topreclen + 1;
291 1.1 cgd r_end = rp + BFRAG;
292 1.1 cgd goto tc_exp;
293 1.1 cgd }
294 1.1 cgd /*
295 1.1 cgd * Allocate first chunk of memory.
296 1.1 cgd */
297 1.1 cgd if ((record = malloc(BFRAG)) == NULL) {
298 1.1 cgd errno = ENOMEM;
299 1.47 jnemeth return -2;
300 1.1 cgd }
301 1.1 cgd r_end = record + BFRAG;
302 1.1 cgd foundit = 0;
303 1.1 cgd /*
304 1.1 cgd * Loop through database array until finding the record.
305 1.1 cgd */
306 1.1 cgd
307 1.1 cgd for (db_p = db_array; *db_p != NULL; db_p++) {
308 1.1 cgd eof = 0;
309 1.1 cgd
310 1.1 cgd /*
311 1.1 cgd * Open database if not already open.
312 1.1 cgd */
313 1.1 cgd
314 1.1 cgd if (fd >= 0) {
315 1.15 kleink (void)lseek(fd, (off_t)0, SEEK_SET);
316 1.1 cgd } else {
317 1.41 christos #ifndef SMALL
318 1.53 christos DB *capdbp;
319 1.53 christos char pbuf[MAXPATHLEN];
320 1.53 christos char *cbuf;
321 1.53 christos int retval;
322 1.53 christos size_t clen;
323 1.53 christos
324 1.1 cgd (void)snprintf(pbuf, sizeof(pbuf), "%s.db", *db_p);
325 1.54 christos if ((capdbp = dbopen(pbuf, O_RDONLY | O_CLOEXEC, 0,
326 1.54 christos DB_HASH, 0)) != NULL) {
327 1.1 cgd free(record);
328 1.1 cgd retval = cdbget(capdbp, &record, name);
329 1.8 cgd if (retval < 0) {
330 1.8 cgd /* no record available */
331 1.8 cgd (void)capdbp->close(capdbp);
332 1.47 jnemeth return retval;
333 1.8 cgd }
334 1.8 cgd /* save the data; close frees it */
335 1.7 cgd clen = strlen(record);
336 1.46 jnemeth if ((cbuf = malloc(clen + 1)) == NULL) {
337 1.46 jnemeth (void)capdbp->close(capdbp);
338 1.46 jnemeth errno = ENOMEM;
339 1.47 jnemeth return -2;
340 1.46 jnemeth }
341 1.23 perry memmove(cbuf, record, clen + 1);
342 1.7 cgd if (capdbp->close(capdbp) < 0) {
343 1.30 lukem int serrno = errno;
344 1.30 lukem
345 1.7 cgd free(cbuf);
346 1.30 lukem errno = serrno;
347 1.47 jnemeth return -2;
348 1.7 cgd }
349 1.7 cgd *len = clen;
350 1.7 cgd *cap = cbuf;
351 1.47 jnemeth return retval;
352 1.41 christos } else
353 1.41 christos #endif
354 1.41 christos {
355 1.54 christos fd = open(*db_p, O_RDONLY | O_CLOEXEC, 0);
356 1.1 cgd if (fd < 0) {
357 1.1 cgd /* No error on unfound file. */
358 1.10 mycroft continue;
359 1.1 cgd }
360 1.1 cgd myfd = 1;
361 1.1 cgd }
362 1.1 cgd }
363 1.1 cgd /*
364 1.1 cgd * Find the requested capability record ...
365 1.1 cgd */
366 1.1 cgd {
367 1.1 cgd char buf[BUFSIZ];
368 1.20 mycroft char *b_end, *bp, *cp;
369 1.20 mycroft int c, slash;
370 1.1 cgd
371 1.1 cgd /*
372 1.1 cgd * Loop invariants:
373 1.1 cgd * There is always room for one more character in record.
374 1.1 cgd * R_end always points just past end of record.
375 1.1 cgd * Rp always points just past last character in record.
376 1.1 cgd * B_end always points just past last character in buf.
377 1.1 cgd * Bp always points at next character in buf.
378 1.20 mycroft * Cp remembers where the last colon was.
379 1.1 cgd */
380 1.1 cgd b_end = buf;
381 1.1 cgd bp = buf;
382 1.47 jnemeth cp = NULL;
383 1.20 mycroft slash = 0;
384 1.1 cgd for (;;) {
385 1.1 cgd /*
386 1.1 cgd * Read in a line implementing (\, newline)
387 1.1 cgd * line continuation.
388 1.1 cgd */
389 1.1 cgd rp = record;
390 1.1 cgd for (;;) {
391 1.1 cgd if (bp >= b_end) {
392 1.51 christos ssize_t n;
393 1.1 cgd
394 1.1 cgd n = read(fd, buf, sizeof(buf));
395 1.1 cgd if (n <= 0) {
396 1.1 cgd if (myfd)
397 1.1 cgd (void)close(fd);
398 1.1 cgd if (n < 0) {
399 1.30 lukem int serrno = errno;
400 1.30 lukem
401 1.1 cgd free(record);
402 1.30 lukem errno = serrno;
403 1.47 jnemeth return -2;
404 1.1 cgd } else {
405 1.1 cgd fd = -1;
406 1.1 cgd eof = 1;
407 1.1 cgd break;
408 1.1 cgd }
409 1.1 cgd }
410 1.1 cgd b_end = buf+n;
411 1.1 cgd bp = buf;
412 1.1 cgd }
413 1.1 cgd
414 1.1 cgd c = *bp++;
415 1.1 cgd if (c == '\n') {
416 1.20 mycroft if (slash) {
417 1.20 mycroft slash = 0;
418 1.1 cgd rp--;
419 1.1 cgd continue;
420 1.1 cgd } else
421 1.1 cgd break;
422 1.1 cgd }
423 1.20 mycroft if (slash) {
424 1.20 mycroft slash = 0;
425 1.20 mycroft cp = 0;
426 1.20 mycroft }
427 1.20 mycroft if (c == ':') {
428 1.20 mycroft /*
429 1.20 mycroft * If the field was `empty' (i.e.
430 1.20 mycroft * contained only white space), back up
431 1.20 mycroft * to the colon (eliminating the
432 1.20 mycroft * field).
433 1.20 mycroft */
434 1.47 jnemeth if (cp != NULL)
435 1.20 mycroft rp = cp;
436 1.20 mycroft else
437 1.20 mycroft cp = rp;
438 1.20 mycroft } else if (c == '\\') {
439 1.20 mycroft slash = 1;
440 1.20 mycroft } else if (c != ' ' && c != '\t') {
441 1.20 mycroft /*
442 1.20 mycroft * Forget where the colon was, as this
443 1.20 mycroft * is not an empty field.
444 1.20 mycroft */
445 1.20 mycroft cp = 0;
446 1.20 mycroft }
447 1.1 cgd *rp++ = c;
448 1.1 cgd
449 1.1 cgd /*
450 1.1 cgd * Enforce loop invariant: if no room
451 1.1 cgd * left in record buffer, try to get
452 1.1 cgd * some more.
453 1.1 cgd */
454 1.1 cgd if (rp >= r_end) {
455 1.51 christos ptrdiff_t pos;
456 1.1 cgd size_t newsize;
457 1.1 cgd
458 1.1 cgd pos = rp - record;
459 1.1 cgd newsize = r_end - record + BFRAG;
460 1.33 itojun newrecord = realloc(record, newsize);
461 1.33 itojun if (newrecord == NULL) {
462 1.33 itojun free(record);
463 1.1 cgd if (myfd)
464 1.1 cgd (void)close(fd);
465 1.30 lukem errno = ENOMEM;
466 1.47 jnemeth return -2;
467 1.1 cgd }
468 1.33 itojun record = newrecord;
469 1.1 cgd r_end = record + newsize;
470 1.1 cgd rp = record + pos;
471 1.1 cgd }
472 1.1 cgd }
473 1.20 mycroft /* Eliminate any white space after the last colon. */
474 1.20 mycroft if (cp)
475 1.20 mycroft rp = cp + 1;
476 1.20 mycroft /* Loop invariant lets us do this. */
477 1.1 cgd *rp++ = '\0';
478 1.1 cgd
479 1.1 cgd /*
480 1.1 cgd * If encountered eof check next file.
481 1.1 cgd */
482 1.1 cgd if (eof)
483 1.1 cgd break;
484 1.1 cgd
485 1.1 cgd /*
486 1.1 cgd * Toss blank lines and comments.
487 1.1 cgd */
488 1.1 cgd if (*record == '\0' || *record == '#')
489 1.1 cgd continue;
490 1.1 cgd
491 1.1 cgd /*
492 1.1 cgd * See if this is the record we want ...
493 1.1 cgd */
494 1.47 jnemeth if (cgetmatch(record, name) == 0)
495 1.1 cgd if (nfield == NULL || !nfcmp(nfield, record)) {
496 1.1 cgd foundit = 1;
497 1.1 cgd break; /* found it! */
498 1.1 cgd }
499 1.1 cgd }
500 1.47 jnemeth }
501 1.1 cgd if (foundit)
502 1.1 cgd break;
503 1.1 cgd }
504 1.1 cgd
505 1.58 shm if (!foundit) {
506 1.58 shm free(record);
507 1.47 jnemeth return -1;
508 1.58 shm }
509 1.1 cgd
510 1.1 cgd /*
511 1.1 cgd * Got the capability record, but now we have to expand all tc=name
512 1.1 cgd * references in it ...
513 1.1 cgd */
514 1.48 christos tc_exp:
515 1.48 christos tc_not_resolved = 0;
516 1.48 christos if (expandtc) {
517 1.16 perry char *newicap, *s;
518 1.17 perry size_t ilen, newilen;
519 1.51 christos int iret;
520 1.51 christos ptrdiff_t diff, tclen;
521 1.1 cgd char *icap, *scan, *tc, *tcstart, *tcend;
522 1.1 cgd
523 1.1 cgd /*
524 1.1 cgd * Loop invariants:
525 1.1 cgd * There is room for one more character in record.
526 1.1 cgd * R_end points just past end of record.
527 1.1 cgd * Rp points just past last character in record.
528 1.1 cgd * Scan points at remainder of record that needs to be
529 1.1 cgd * scanned for tc=name constructs.
530 1.1 cgd */
531 1.1 cgd scan = record;
532 1.1 cgd for (;;) {
533 1.1 cgd if ((tc = cgetcap(scan, "tc", '=')) == NULL)
534 1.1 cgd break;
535 1.1 cgd
536 1.1 cgd /*
537 1.1 cgd * Find end of tc=name and stomp on the trailing `:'
538 1.1 cgd * (if present) so we can use it to call ourselves.
539 1.1 cgd */
540 1.1 cgd s = tc;
541 1.1 cgd for (;;)
542 1.1 cgd if (*s == '\0')
543 1.1 cgd break;
544 1.1 cgd else
545 1.1 cgd if (*s++ == ':') {
546 1.1 cgd *(s - 1) = '\0';
547 1.1 cgd break;
548 1.1 cgd }
549 1.1 cgd tcstart = tc - 3;
550 1.1 cgd tclen = s - tcstart;
551 1.1 cgd tcend = s;
552 1.1 cgd
553 1.1 cgd iret = getent(&icap, &ilen, db_p, fd, tc, depth+1,
554 1.1 cgd NULL);
555 1.1 cgd newicap = icap; /* Put into a register. */
556 1.1 cgd newilen = ilen;
557 1.1 cgd if (iret != 0) {
558 1.1 cgd /* an error */
559 1.1 cgd if (iret < -1) {
560 1.1 cgd if (myfd)
561 1.1 cgd (void)close(fd);
562 1.1 cgd free(record);
563 1.47 jnemeth return iret;
564 1.1 cgd }
565 1.1 cgd if (iret == 1)
566 1.1 cgd tc_not_resolved = 1;
567 1.1 cgd /* couldn't resolve tc */
568 1.1 cgd if (iret == -1) {
569 1.1 cgd *(s - 1) = ':';
570 1.1 cgd scan = s - 1;
571 1.1 cgd tc_not_resolved = 1;
572 1.1 cgd continue;
573 1.1 cgd
574 1.1 cgd }
575 1.1 cgd }
576 1.1 cgd /* not interested in name field of tc'ed record */
577 1.1 cgd s = newicap;
578 1.1 cgd for (;;)
579 1.1 cgd if (*s == '\0')
580 1.1 cgd break;
581 1.47 jnemeth else if (*s++ == ':')
582 1.47 jnemeth break;
583 1.1 cgd newilen -= s - newicap;
584 1.1 cgd newicap = s;
585 1.1 cgd
586 1.1 cgd /* make sure interpolated record is `:'-terminated */
587 1.1 cgd s += newilen;
588 1.47 jnemeth if (*(s - 1) != ':') {
589 1.1 cgd *s = ':'; /* overwrite NUL with : */
590 1.1 cgd newilen++;
591 1.1 cgd }
592 1.1 cgd
593 1.1 cgd /*
594 1.1 cgd * Make sure there's enough room to insert the
595 1.1 cgd * new record.
596 1.1 cgd */
597 1.1 cgd diff = newilen - tclen;
598 1.1 cgd if (diff >= r_end - rp) {
599 1.51 christos ptrdiff_t pos, tcpos, tcposend;
600 1.1 cgd size_t newsize;
601 1.1 cgd
602 1.1 cgd pos = rp - record;
603 1.1 cgd newsize = r_end - record + diff + BFRAG;
604 1.1 cgd tcpos = tcstart - record;
605 1.1 cgd tcposend = tcend - record;
606 1.33 itojun newrecord = realloc(record, newsize);
607 1.33 itojun if (newrecord == NULL) {
608 1.33 itojun free(record);
609 1.1 cgd if (myfd)
610 1.1 cgd (void)close(fd);
611 1.1 cgd free(icap);
612 1.30 lukem errno = ENOMEM;
613 1.47 jnemeth return -2;
614 1.1 cgd }
615 1.33 itojun record = newrecord;
616 1.1 cgd r_end = record + newsize;
617 1.1 cgd rp = record + pos;
618 1.1 cgd tcstart = record + tcpos;
619 1.1 cgd tcend = record + tcposend;
620 1.1 cgd }
621 1.1 cgd
622 1.1 cgd /*
623 1.1 cgd * Insert tc'ed record into our record.
624 1.1 cgd */
625 1.1 cgd s = tcstart + newilen;
626 1.23 perry memmove(s, tcend, (size_t)(rp - tcend));
627 1.23 perry memmove(tcstart, newicap, newilen);
628 1.1 cgd rp += diff;
629 1.1 cgd free(icap);
630 1.1 cgd
631 1.1 cgd /*
632 1.1 cgd * Start scan on `:' so next cgetcap works properly
633 1.1 cgd * (cgetcap always skips first field).
634 1.1 cgd */
635 1.47 jnemeth scan = s - 1;
636 1.1 cgd }
637 1.1 cgd
638 1.1 cgd }
639 1.1 cgd /*
640 1.1 cgd * Close file (if we opened it), give back any extra memory, and
641 1.1 cgd * return capability, length and success.
642 1.1 cgd */
643 1.1 cgd if (myfd)
644 1.1 cgd (void)close(fd);
645 1.1 cgd *len = rp - record - 1; /* don't count NUL */
646 1.33 itojun if (r_end > rp) {
647 1.33 itojun if ((newrecord =
648 1.1 cgd realloc(record, (size_t)(rp - record))) == NULL) {
649 1.33 itojun free(record);
650 1.1 cgd errno = ENOMEM;
651 1.47 jnemeth return -2;
652 1.1 cgd }
653 1.33 itojun record = newrecord;
654 1.33 itojun }
655 1.1 cgd
656 1.1 cgd *cap = record;
657 1.1 cgd if (tc_not_resolved)
658 1.47 jnemeth return 1;
659 1.47 jnemeth return 0;
660 1.1 cgd }
661 1.1 cgd
662 1.41 christos #ifndef SMALL
663 1.1 cgd static int
664 1.40 christos cdbget(DB *capdbp, char **bp, const char *name)
665 1.1 cgd {
666 1.25 christos DBT key;
667 1.24 christos DBT data;
668 1.1 cgd
669 1.30 lukem _DIAGASSERT(capdbp != NULL);
670 1.30 lukem _DIAGASSERT(bp != NULL);
671 1.30 lukem _DIAGASSERT(name != NULL);
672 1.30 lukem
673 1.42 christos key.data = __UNCONST(name);
674 1.1 cgd key.size = strlen(name);
675 1.1 cgd
676 1.1 cgd for (;;) {
677 1.1 cgd /* Get the reference. */
678 1.1 cgd switch(capdbp->get(capdbp, &key, &data, 0)) {
679 1.1 cgd case -1:
680 1.47 jnemeth return -2;
681 1.1 cgd case 1:
682 1.47 jnemeth return -1;
683 1.1 cgd }
684 1.1 cgd
685 1.1 cgd /* If not an index to another record, leave. */
686 1.1 cgd if (((char *)data.data)[0] != SHADOW)
687 1.1 cgd break;
688 1.1 cgd
689 1.1 cgd key.data = (char *)data.data + 1;
690 1.1 cgd key.size = data.size - 1;
691 1.1 cgd }
692 1.1 cgd
693 1.1 cgd *bp = (char *)data.data + 1;
694 1.47 jnemeth return ((char *)(data.data))[0] == TCERR ? 1 : 0;
695 1.1 cgd }
696 1.41 christos #endif
697 1.1 cgd
698 1.1 cgd /*
699 1.1 cgd * Cgetmatch will return 0 if name is one of the names of the capability
700 1.1 cgd * record buf, -1 if not.
701 1.1 cgd */
702 1.1 cgd int
703 1.40 christos cgetmatch(const char *buf, const char *name)
704 1.1 cgd {
705 1.21 mycroft const char *np, *bp;
706 1.1 cgd
707 1.30 lukem _DIAGASSERT(buf != NULL);
708 1.30 lukem _DIAGASSERT(name != NULL);
709 1.30 lukem
710 1.1 cgd /*
711 1.1 cgd * Start search at beginning of record.
712 1.1 cgd */
713 1.1 cgd bp = buf;
714 1.1 cgd for (;;) {
715 1.1 cgd /*
716 1.1 cgd * Try to match a record name.
717 1.1 cgd */
718 1.1 cgd np = name;
719 1.1 cgd for (;;)
720 1.26 christos if (*np == '\0') {
721 1.1 cgd if (*bp == '|' || *bp == ':' || *bp == '\0')
722 1.47 jnemeth return 0;
723 1.1 cgd else
724 1.1 cgd break;
725 1.47 jnemeth } else if (*bp++ != *np++)
726 1.47 jnemeth break;
727 1.1 cgd
728 1.1 cgd /*
729 1.1 cgd * Match failed, skip to next name in record.
730 1.1 cgd */
731 1.34 mrg if (bp > buf)
732 1.34 mrg bp--; /* a '|' or ':' may have stopped the match */
733 1.34 mrg else
734 1.47 jnemeth return -1;
735 1.1 cgd for (;;)
736 1.1 cgd if (*bp == '\0' || *bp == ':')
737 1.47 jnemeth return -1; /* match failed totally */
738 1.47 jnemeth else if (*bp++ == '|')
739 1.47 jnemeth break; /* found next name */
740 1.1 cgd }
741 1.1 cgd }
742 1.1 cgd
743 1.1 cgd int
744 1.40 christos cgetfirst(char **buf, const char * const *db_array)
745 1.1 cgd {
746 1.30 lukem
747 1.30 lukem _DIAGASSERT(buf != NULL);
748 1.30 lukem _DIAGASSERT(db_array != NULL);
749 1.30 lukem
750 1.1 cgd (void)cgetclose();
751 1.47 jnemeth return cgetnext(buf, db_array);
752 1.1 cgd }
753 1.1 cgd
754 1.1 cgd static FILE *pfp;
755 1.1 cgd static int slash;
756 1.40 christos static const char * const *dbp;
757 1.1 cgd
758 1.1 cgd int
759 1.40 christos cgetclose(void)
760 1.1 cgd {
761 1.1 cgd if (pfp != NULL) {
762 1.1 cgd (void)fclose(pfp);
763 1.1 cgd pfp = NULL;
764 1.1 cgd }
765 1.1 cgd dbp = NULL;
766 1.1 cgd gottoprec = 0;
767 1.1 cgd slash = 0;
768 1.47 jnemeth return 0;
769 1.1 cgd }
770 1.1 cgd
771 1.1 cgd /*
772 1.1 cgd * Cgetnext() gets either the first or next entry in the logical database
773 1.1 cgd * specified by db_array. It returns 0 upon completion of the database, 1
774 1.1 cgd * upon returning an entry with more remaining, and -1 if an error occurs.
775 1.1 cgd */
776 1.45 christos /* coverity[+alloc : arg-*0] */
777 1.1 cgd int
778 1.40 christos cgetnext(char **bp, const char * const *db_array)
779 1.1 cgd {
780 1.43 christos size_t len = 0;
781 1.17 perry int status, done;
782 1.1 cgd char *cp, *line, *rp, *np, buf[BSIZE], nbuf[BSIZE];
783 1.18 thorpej size_t dummy;
784 1.1 cgd
785 1.30 lukem _DIAGASSERT(bp != NULL);
786 1.30 lukem _DIAGASSERT(db_array != NULL);
787 1.30 lukem
788 1.1 cgd if (dbp == NULL)
789 1.1 cgd dbp = db_array;
790 1.1 cgd
791 1.50 christos if (pfp == NULL && (pfp = fopen(*dbp, "re")) == NULL) {
792 1.1 cgd (void)cgetclose();
793 1.47 jnemeth return -1;
794 1.1 cgd }
795 1.47 jnemeth for (;;) {
796 1.47 jnemeth if (toprec != NULL && !gottoprec) {
797 1.1 cgd gottoprec = 1;
798 1.1 cgd line = toprec;
799 1.1 cgd } else {
800 1.6 cgd line = fgetln(pfp, &len);
801 1.44 christos if (line == NULL) {
802 1.44 christos if (pfp == NULL)
803 1.44 christos return -1;
804 1.1 cgd if (ferror(pfp)) {
805 1.1 cgd (void)cgetclose();
806 1.47 jnemeth return -1;
807 1.1 cgd } else {
808 1.19 tv (void)fclose(pfp);
809 1.19 tv pfp = NULL;
810 1.1 cgd if (*++dbp == NULL) {
811 1.1 cgd (void)cgetclose();
812 1.47 jnemeth return 0;
813 1.1 cgd } else if ((pfp =
814 1.50 christos fopen(*dbp, "re")) == NULL) {
815 1.1 cgd (void)cgetclose();
816 1.47 jnemeth return -1;
817 1.1 cgd } else
818 1.1 cgd continue;
819 1.1 cgd }
820 1.5 cgd } else
821 1.5 cgd line[len - 1] = '\0';
822 1.5 cgd if (len == 1) {
823 1.1 cgd slash = 0;
824 1.1 cgd continue;
825 1.1 cgd }
826 1.26 christos if (isspace((unsigned char)*line) ||
827 1.1 cgd *line == ':' || *line == '#' || slash) {
828 1.5 cgd if (line[len - 2] == '\\')
829 1.1 cgd slash = 1;
830 1.1 cgd else
831 1.1 cgd slash = 0;
832 1.1 cgd continue;
833 1.1 cgd }
834 1.5 cgd if (line[len - 2] == '\\')
835 1.1 cgd slash = 1;
836 1.1 cgd else
837 1.1 cgd slash = 0;
838 1.1 cgd }
839 1.1 cgd
840 1.1 cgd
841 1.1 cgd /*
842 1.1 cgd * Line points to a name line.
843 1.1 cgd */
844 1.35 groo if (len > sizeof(nbuf))
845 1.35 groo return -1;
846 1.1 cgd done = 0;
847 1.1 cgd np = nbuf;
848 1.1 cgd for (;;) {
849 1.1 cgd for (cp = line; *cp != '\0'; cp++) {
850 1.1 cgd if (*cp == ':') {
851 1.1 cgd *np++ = ':';
852 1.1 cgd done = 1;
853 1.1 cgd break;
854 1.1 cgd }
855 1.1 cgd if (*cp == '\\')
856 1.1 cgd break;
857 1.1 cgd *np++ = *cp;
858 1.1 cgd }
859 1.1 cgd if (done) {
860 1.1 cgd *np = '\0';
861 1.1 cgd break;
862 1.1 cgd } else { /* name field extends beyond the line */
863 1.6 cgd line = fgetln(pfp, &len);
864 1.1 cgd if (line == NULL && pfp) {
865 1.1 cgd if (ferror(pfp)) {
866 1.1 cgd (void)cgetclose();
867 1.47 jnemeth return -1;
868 1.1 cgd }
869 1.19 tv (void)fclose(pfp);
870 1.19 tv pfp = NULL;
871 1.19 tv *np = '\0';
872 1.19 tv break;
873 1.5 cgd } else
874 1.5 cgd line[len - 1] = '\0';
875 1.1 cgd }
876 1.1 cgd }
877 1.35 groo if (len > sizeof(buf))
878 1.35 groo return -1;
879 1.1 cgd rp = buf;
880 1.47 jnemeth for (cp = nbuf; *cp != '\0'; cp++)
881 1.1 cgd if (*cp == '|' || *cp == ':')
882 1.1 cgd break;
883 1.1 cgd else
884 1.1 cgd *rp++ = *cp;
885 1.1 cgd
886 1.1 cgd *rp = '\0';
887 1.1 cgd /*
888 1.1 cgd * XXX
889 1.1 cgd * Last argument of getent here should be nbuf if we want true
890 1.1 cgd * sequential access in the case of duplicates.
891 1.1 cgd * With NULL, getent will return the first entry found
892 1.1 cgd * rather than the duplicate entry record. This is a
893 1.1 cgd * matter of semantics that should be resolved.
894 1.1 cgd */
895 1.1 cgd status = getent(bp, &dummy, db_array, -1, buf, 0, NULL);
896 1.1 cgd if (status == -2 || status == -3)
897 1.1 cgd (void)cgetclose();
898 1.1 cgd
899 1.47 jnemeth return status + 1;
900 1.1 cgd }
901 1.1 cgd /* NOTREACHED */
902 1.1 cgd }
903 1.1 cgd
904 1.1 cgd /*
905 1.1 cgd * Cgetstr retrieves the value of the string capability cap from the
906 1.1 cgd * capability record pointed to by buf. A pointer to a decoded, NUL
907 1.1 cgd * terminated, malloc'd copy of the string is returned in the char *
908 1.1 cgd * pointed to by str. The length of the string not including the trailing
909 1.1 cgd * NUL is returned on success, -1 if the requested string capability
910 1.1 cgd * couldn't be found, -2 if a system error was encountered (storage
911 1.1 cgd * allocation failure).
912 1.1 cgd */
913 1.1 cgd int
914 1.40 christos cgetstr(char *buf, const char *cap, char **str)
915 1.1 cgd {
916 1.16 perry u_int m_room;
917 1.21 mycroft const char *bp;
918 1.21 mycroft char *mp;
919 1.51 christos ptrdiff_t len;
920 1.33 itojun char *mem, *newmem;
921 1.1 cgd
922 1.30 lukem _DIAGASSERT(buf != NULL);
923 1.30 lukem _DIAGASSERT(cap != NULL);
924 1.30 lukem _DIAGASSERT(str != NULL);
925 1.30 lukem
926 1.1 cgd /*
927 1.1 cgd * Find string capability cap
928 1.1 cgd */
929 1.1 cgd bp = cgetcap(buf, cap, '=');
930 1.1 cgd if (bp == NULL)
931 1.47 jnemeth return -1;
932 1.1 cgd
933 1.1 cgd /*
934 1.1 cgd * Conversion / storage allocation loop ... Allocate memory in
935 1.1 cgd * chunks SFRAG in size.
936 1.1 cgd */
937 1.1 cgd if ((mem = malloc(SFRAG)) == NULL) {
938 1.1 cgd errno = ENOMEM;
939 1.47 jnemeth return -2; /* couldn't even allocate the first fragment */
940 1.1 cgd }
941 1.1 cgd m_room = SFRAG;
942 1.1 cgd mp = mem;
943 1.1 cgd
944 1.1 cgd while (*bp != ':' && *bp != '\0') {
945 1.1 cgd /*
946 1.1 cgd * Loop invariants:
947 1.1 cgd * There is always room for one more character in mem.
948 1.1 cgd * Mp always points just past last character in mem.
949 1.1 cgd * Bp always points at next character in buf.
950 1.1 cgd */
951 1.1 cgd if (*bp == '^') {
952 1.1 cgd bp++;
953 1.1 cgd if (*bp == ':' || *bp == '\0')
954 1.1 cgd break; /* drop unfinished escape */
955 1.1 cgd *mp++ = *bp++ & 037;
956 1.1 cgd } else if (*bp == '\\') {
957 1.1 cgd bp++;
958 1.1 cgd if (*bp == ':' || *bp == '\0')
959 1.1 cgd break; /* drop unfinished escape */
960 1.1 cgd if ('0' <= *bp && *bp <= '7') {
961 1.16 perry int n, i;
962 1.1 cgd
963 1.1 cgd n = 0;
964 1.1 cgd i = 3; /* maximum of three octal digits */
965 1.1 cgd do {
966 1.1 cgd n = n * 8 + (*bp++ - '0');
967 1.1 cgd } while (--i && '0' <= *bp && *bp <= '7');
968 1.1 cgd *mp++ = n;
969 1.1 cgd }
970 1.1 cgd else switch (*bp++) {
971 1.1 cgd case 'b': case 'B':
972 1.1 cgd *mp++ = '\b';
973 1.1 cgd break;
974 1.1 cgd case 't': case 'T':
975 1.1 cgd *mp++ = '\t';
976 1.1 cgd break;
977 1.1 cgd case 'n': case 'N':
978 1.1 cgd *mp++ = '\n';
979 1.1 cgd break;
980 1.1 cgd case 'f': case 'F':
981 1.1 cgd *mp++ = '\f';
982 1.1 cgd break;
983 1.1 cgd case 'r': case 'R':
984 1.1 cgd *mp++ = '\r';
985 1.1 cgd break;
986 1.1 cgd case 'e': case 'E':
987 1.1 cgd *mp++ = ESC;
988 1.1 cgd break;
989 1.1 cgd case 'c': case 'C':
990 1.1 cgd *mp++ = ':';
991 1.1 cgd break;
992 1.1 cgd default:
993 1.1 cgd /*
994 1.1 cgd * Catches '\', '^', and
995 1.1 cgd * everything else.
996 1.1 cgd */
997 1.1 cgd *mp++ = *(bp-1);
998 1.1 cgd break;
999 1.1 cgd }
1000 1.1 cgd } else
1001 1.1 cgd *mp++ = *bp++;
1002 1.1 cgd m_room--;
1003 1.1 cgd
1004 1.1 cgd /*
1005 1.1 cgd * Enforce loop invariant: if no room left in current
1006 1.1 cgd * buffer, try to get some more.
1007 1.1 cgd */
1008 1.1 cgd if (m_room == 0) {
1009 1.1 cgd size_t size = mp - mem;
1010 1.1 cgd
1011 1.33 itojun if ((newmem = realloc(mem, size + SFRAG)) == NULL) {
1012 1.33 itojun free(mem);
1013 1.47 jnemeth return -2;
1014 1.33 itojun }
1015 1.33 itojun mem = newmem;
1016 1.1 cgd m_room = SFRAG;
1017 1.1 cgd mp = mem + size;
1018 1.1 cgd }
1019 1.1 cgd }
1020 1.1 cgd *mp++ = '\0'; /* loop invariant let's us do this */
1021 1.1 cgd m_room--;
1022 1.1 cgd len = mp - mem - 1;
1023 1.1 cgd
1024 1.1 cgd /*
1025 1.1 cgd * Give back any extra memory and return value and success.
1026 1.1 cgd */
1027 1.33 itojun if (m_room != 0) {
1028 1.33 itojun if ((newmem = realloc(mem, (size_t)(mp - mem))) == NULL) {
1029 1.33 itojun free(mem);
1030 1.47 jnemeth return -2;
1031 1.33 itojun }
1032 1.33 itojun mem = newmem;
1033 1.33 itojun }
1034 1.1 cgd *str = mem;
1035 1.51 christos _DIAGASSERT(__type_fit(int, len));
1036 1.51 christos return (int)len;
1037 1.1 cgd }
1038 1.1 cgd
1039 1.1 cgd /*
1040 1.1 cgd * Cgetustr retrieves the value of the string capability cap from the
1041 1.1 cgd * capability record pointed to by buf. The difference between cgetustr()
1042 1.1 cgd * and cgetstr() is that cgetustr does not decode escapes but rather treats
1043 1.1 cgd * all characters literally. A pointer to a NUL terminated malloc'd
1044 1.1 cgd * copy of the string is returned in the char pointed to by str. The
1045 1.1 cgd * length of the string not including the trailing NUL is returned on success,
1046 1.1 cgd * -1 if the requested string capability couldn't be found, -2 if a system
1047 1.1 cgd * error was encountered (storage allocation failure).
1048 1.1 cgd */
1049 1.1 cgd int
1050 1.40 christos cgetustr(char *buf, const char *cap, char **str)
1051 1.1 cgd {
1052 1.16 perry u_int m_room;
1053 1.21 mycroft const char *bp;
1054 1.21 mycroft char *mp;
1055 1.51 christos size_t len;
1056 1.33 itojun char *mem, *newmem;
1057 1.1 cgd
1058 1.30 lukem _DIAGASSERT(buf != NULL);
1059 1.30 lukem _DIAGASSERT(cap != NULL);
1060 1.30 lukem _DIAGASSERT(str != NULL);
1061 1.30 lukem
1062 1.1 cgd /*
1063 1.1 cgd * Find string capability cap
1064 1.1 cgd */
1065 1.1 cgd if ((bp = cgetcap(buf, cap, '=')) == NULL)
1066 1.47 jnemeth return -1;
1067 1.1 cgd
1068 1.1 cgd /*
1069 1.1 cgd * Conversion / storage allocation loop ... Allocate memory in
1070 1.1 cgd * chunks SFRAG in size.
1071 1.1 cgd */
1072 1.1 cgd if ((mem = malloc(SFRAG)) == NULL) {
1073 1.1 cgd errno = ENOMEM;
1074 1.47 jnemeth return -2; /* couldn't even allocate the first fragment */
1075 1.1 cgd }
1076 1.1 cgd m_room = SFRAG;
1077 1.1 cgd mp = mem;
1078 1.1 cgd
1079 1.1 cgd while (*bp != ':' && *bp != '\0') {
1080 1.1 cgd /*
1081 1.1 cgd * Loop invariants:
1082 1.1 cgd * There is always room for one more character in mem.
1083 1.1 cgd * Mp always points just past last character in mem.
1084 1.1 cgd * Bp always points at next character in buf.
1085 1.1 cgd */
1086 1.1 cgd *mp++ = *bp++;
1087 1.1 cgd m_room--;
1088 1.1 cgd
1089 1.1 cgd /*
1090 1.1 cgd * Enforce loop invariant: if no room left in current
1091 1.1 cgd * buffer, try to get some more.
1092 1.1 cgd */
1093 1.1 cgd if (m_room == 0) {
1094 1.1 cgd size_t size = mp - mem;
1095 1.1 cgd
1096 1.33 itojun if ((newmem = realloc(mem, size + SFRAG)) == NULL) {
1097 1.33 itojun free(mem);
1098 1.47 jnemeth return -2;
1099 1.33 itojun }
1100 1.33 itojun mem = newmem;
1101 1.1 cgd m_room = SFRAG;
1102 1.1 cgd mp = mem + size;
1103 1.1 cgd }
1104 1.1 cgd }
1105 1.1 cgd *mp++ = '\0'; /* loop invariant let's us do this */
1106 1.1 cgd m_room--;
1107 1.1 cgd len = mp - mem - 1;
1108 1.1 cgd
1109 1.1 cgd /*
1110 1.1 cgd * Give back any extra memory and return value and success.
1111 1.1 cgd */
1112 1.33 itojun if (m_room != 0) {
1113 1.33 itojun if ((newmem = realloc(mem, (size_t)(mp - mem))) == NULL) {
1114 1.33 itojun free(mem);
1115 1.47 jnemeth return -2;
1116 1.33 itojun }
1117 1.33 itojun mem = newmem;
1118 1.33 itojun }
1119 1.1 cgd *str = mem;
1120 1.51 christos _DIAGASSERT(__type_fit(int, len));
1121 1.51 christos return (int)len;
1122 1.1 cgd }
1123 1.1 cgd
1124 1.1 cgd /*
1125 1.1 cgd * Cgetnum retrieves the value of the numeric capability cap from the
1126 1.1 cgd * capability record pointed to by buf. The numeric value is returned in
1127 1.1 cgd * the long pointed to by num. 0 is returned on success, -1 if the requested
1128 1.1 cgd * numeric capability couldn't be found.
1129 1.1 cgd */
1130 1.1 cgd int
1131 1.40 christos cgetnum(char *buf, const char *cap, long *num)
1132 1.1 cgd {
1133 1.16 perry long n;
1134 1.16 perry int base, digit;
1135 1.21 mycroft const char *bp;
1136 1.1 cgd
1137 1.30 lukem _DIAGASSERT(buf != NULL);
1138 1.30 lukem _DIAGASSERT(cap != NULL);
1139 1.30 lukem _DIAGASSERT(num != NULL);
1140 1.30 lukem
1141 1.1 cgd /*
1142 1.1 cgd * Find numeric capability cap
1143 1.1 cgd */
1144 1.1 cgd bp = cgetcap(buf, cap, '#');
1145 1.1 cgd if (bp == NULL)
1146 1.47 jnemeth return -1;
1147 1.1 cgd
1148 1.1 cgd /*
1149 1.1 cgd * Look at value and determine numeric base:
1150 1.1 cgd * 0x... or 0X... hexadecimal,
1151 1.1 cgd * else 0... octal,
1152 1.1 cgd * else decimal.
1153 1.1 cgd */
1154 1.1 cgd if (*bp == '0') {
1155 1.1 cgd bp++;
1156 1.1 cgd if (*bp == 'x' || *bp == 'X') {
1157 1.1 cgd bp++;
1158 1.1 cgd base = 16;
1159 1.1 cgd } else
1160 1.1 cgd base = 8;
1161 1.1 cgd } else
1162 1.1 cgd base = 10;
1163 1.1 cgd
1164 1.1 cgd /*
1165 1.1 cgd * Conversion loop ...
1166 1.1 cgd */
1167 1.1 cgd n = 0;
1168 1.1 cgd for (;;) {
1169 1.1 cgd if ('0' <= *bp && *bp <= '9')
1170 1.1 cgd digit = *bp - '0';
1171 1.1 cgd else if ('a' <= *bp && *bp <= 'f')
1172 1.1 cgd digit = 10 + *bp - 'a';
1173 1.1 cgd else if ('A' <= *bp && *bp <= 'F')
1174 1.1 cgd digit = 10 + *bp - 'A';
1175 1.1 cgd else
1176 1.1 cgd break;
1177 1.1 cgd
1178 1.1 cgd if (digit >= base)
1179 1.1 cgd break;
1180 1.1 cgd
1181 1.1 cgd n = n * base + digit;
1182 1.1 cgd bp++;
1183 1.1 cgd }
1184 1.1 cgd
1185 1.1 cgd /*
1186 1.1 cgd * Return value and success.
1187 1.1 cgd */
1188 1.1 cgd *num = n;
1189 1.47 jnemeth return 0;
1190 1.1 cgd }
1191 1.1 cgd
1192 1.1 cgd
1193 1.1 cgd /*
1194 1.1 cgd * Compare name field of record.
1195 1.1 cgd */
1196 1.1 cgd static int
1197 1.40 christos nfcmp(char *nf, char *rec)
1198 1.1 cgd {
1199 1.1 cgd char *cp, tmp;
1200 1.1 cgd int ret;
1201 1.30 lukem
1202 1.30 lukem _DIAGASSERT(nf != NULL);
1203 1.30 lukem _DIAGASSERT(rec != NULL);
1204 1.30 lukem
1205 1.1 cgd for (cp = rec; *cp != ':'; cp++)
1206 1.47 jnemeth continue;
1207 1.1 cgd
1208 1.1 cgd tmp = *(cp + 1);
1209 1.1 cgd *(cp + 1) = '\0';
1210 1.1 cgd ret = strcmp(nf, rec);
1211 1.1 cgd *(cp + 1) = tmp;
1212 1.1 cgd
1213 1.47 jnemeth return ret;
1214 1.1 cgd }
1215