Home | History | Annotate | Line # | Download | only in libutil
login_cap.c revision 1.5
      1  1.5  mjl /* $NetBSD: login_cap.c,v 1.5 2000/02/10 20:52:54 mjl Exp $ */
      2  1.1  mjl 
      3  1.1  mjl /*-
      4  1.1  mjl  * Copyright (c) 1995,1997 Berkeley Software Design, Inc. All rights reserved.
      5  1.1  mjl  *
      6  1.1  mjl  * Redistribution and use in source and binary forms, with or without
      7  1.1  mjl  * modification, are permitted provided that the following conditions
      8  1.1  mjl  * are met:
      9  1.1  mjl  * 1. Redistributions of source code must retain the above copyright
     10  1.1  mjl  *    notice, this list of conditions and the following disclaimer.
     11  1.1  mjl  * 2. Redistributions in binary form must reproduce the above copyright
     12  1.1  mjl  *    notice, this list of conditions and the following disclaimer in the
     13  1.1  mjl  *    documentation and/or other materials provided with the distribution.
     14  1.1  mjl  * 3. All advertising materials mentioning features or use of this software
     15  1.1  mjl  *    must display the following acknowledgement:
     16  1.1  mjl  *	This product includes software developed by Berkeley Software Design,
     17  1.1  mjl  *	Inc.
     18  1.1  mjl  * 4. The name of Berkeley Software Design, Inc.  may not be used to endorse
     19  1.1  mjl  *    or promote products derived from this software without specific prior
     20  1.1  mjl  *    written permission.
     21  1.1  mjl  *
     22  1.1  mjl  * THIS SOFTWARE IS PROVIDED BY BERKELEY SOFTWARE DESIGN, INC. ``AS IS'' AND
     23  1.1  mjl  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     24  1.1  mjl  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     25  1.1  mjl  * ARE DISCLAIMED.  IN NO EVENT SHALL BERKELEY SOFTWARE DESIGN, INC. BE LIABLE
     26  1.1  mjl  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     27  1.1  mjl  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     28  1.1  mjl  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     29  1.1  mjl  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     30  1.1  mjl  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     31  1.1  mjl  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     32  1.1  mjl  * SUCH DAMAGE.
     33  1.1  mjl  *
     34  1.1  mjl  *	BSDI login_cap.c,v 2.13 1998/02/07 03:17:05 prb Exp
     35  1.1  mjl  */
     36  1.1  mjl 
     37  1.1  mjl #include <sys/types.h>
     38  1.1  mjl #include <sys/stat.h>
     39  1.1  mjl #include <sys/time.h>
     40  1.1  mjl #include <sys/resource.h>
     41  1.1  mjl 
     42  1.4  mjl #include <ctype.h>
     43  1.1  mjl #include <err.h>
     44  1.1  mjl #include <errno.h>
     45  1.1  mjl #include <fcntl.h>
     46  1.1  mjl #include <limits.h>
     47  1.1  mjl #include <login_cap.h>
     48  1.1  mjl #include <paths.h>
     49  1.1  mjl #include <pwd.h>
     50  1.1  mjl #include <stdio.h>
     51  1.1  mjl #include <stdlib.h>
     52  1.1  mjl #include <string.h>
     53  1.1  mjl #include <syslog.h>
     54  1.1  mjl #include <unistd.h>
     55  1.1  mjl 
     56  1.1  mjl 
     57  1.1  mjl static	char *classfiles[] = { _PATH_LOGIN_CONF, 0 };
     58  1.1  mjl static	void setuserpath __P((login_cap_t *, char *));
     59  1.1  mjl static	u_quad_t multiply __P((u_quad_t, u_quad_t));
     60  1.1  mjl static	u_quad_t strtolimit __P((char *, char **, int));
     61  1.1  mjl static	u_quad_t strtosize __P((char *, char **, int));
     62  1.1  mjl static	int gsetrl __P((login_cap_t *, int, char *, int type));
     63  1.4  mjl static	int setuserenv __P((login_cap_t *));
     64  1.5  mjl static	int isinfinite __P((const char *));
     65  1.1  mjl 
     66  1.1  mjl login_cap_t *
     67  1.1  mjl login_getclass(class)
     68  1.1  mjl 	char *class;
     69  1.1  mjl {
     70  1.1  mjl 	login_cap_t *lc;
     71  1.1  mjl 	int res;
     72  1.1  mjl 
     73  1.1  mjl 	for (res = 0; classfiles[res]; ++res)
     74  1.1  mjl 		if (secure_path(classfiles[res]) < 0)
     75  1.1  mjl 			return (0);
     76  1.1  mjl 
     77  1.1  mjl 	if ((lc = malloc(sizeof(login_cap_t))) == NULL) {
     78  1.1  mjl 		syslog(LOG_ERR, "%s:%d malloc: %m", __FILE__, __LINE__);
     79  1.1  mjl 		return (0);
     80  1.1  mjl 	}
     81  1.1  mjl 
     82  1.1  mjl 	lc->lc_cap = 0;
     83  1.1  mjl 	lc->lc_style = 0;
     84  1.1  mjl 
     85  1.1  mjl 	if (class == NULL || class[0] == '\0')
     86  1.1  mjl 		class = LOGIN_DEFCLASS;
     87  1.1  mjl 
     88  1.1  mjl     	if ((lc->lc_class = strdup(class)) == NULL) {
     89  1.1  mjl 		syslog(LOG_ERR, "%s:%d strdup: %m", __FILE__, __LINE__);
     90  1.1  mjl 		free(lc);
     91  1.1  mjl 		return (0);
     92  1.1  mjl 	}
     93  1.1  mjl 
     94  1.1  mjl 	if ((res = cgetent(&lc->lc_cap, classfiles, lc->lc_class)) != 0 ) {
     95  1.1  mjl 		lc->lc_cap = 0;
     96  1.1  mjl 		switch (res) {
     97  1.1  mjl 		case 1:
     98  1.1  mjl 			syslog(LOG_ERR, "%s: couldn't resolve 'tc'",
     99  1.1  mjl 				lc->lc_class);
    100  1.1  mjl 			break;
    101  1.1  mjl 		case -1:
    102  1.1  mjl 			if ((res = open(classfiles[0], 0)) >= 0)
    103  1.1  mjl 				close(res);
    104  1.1  mjl 			if (strcmp(lc->lc_class, LOGIN_DEFCLASS) == NULL &&
    105  1.1  mjl 			    res < 0)
    106  1.1  mjl 				return (lc);
    107  1.1  mjl 			syslog(LOG_ERR, "%s: unknown class", lc->lc_class);
    108  1.1  mjl 			break;
    109  1.1  mjl 		case -2:
    110  1.1  mjl 			syslog(LOG_ERR, "%s: getting class information: %m",
    111  1.1  mjl 				lc->lc_class);
    112  1.1  mjl 			break;
    113  1.1  mjl 		case -3:
    114  1.1  mjl 			syslog(LOG_ERR, "%s: 'tc' reference loop",
    115  1.1  mjl 				lc->lc_class);
    116  1.1  mjl 			break;
    117  1.1  mjl 		default:
    118  1.1  mjl 			syslog(LOG_ERR, "%s: unexpected cgetent error",
    119  1.1  mjl 				lc->lc_class);
    120  1.1  mjl 			break;
    121  1.1  mjl 		}
    122  1.1  mjl 		free(lc->lc_class);
    123  1.1  mjl 		free(lc);
    124  1.1  mjl 		return (0);
    125  1.1  mjl 	}
    126  1.1  mjl 	return (lc);
    127  1.1  mjl }
    128  1.1  mjl 
    129  1.4  mjl login_cap_t *
    130  1.4  mjl login_getpwclass(pwd)
    131  1.4  mjl 	const struct passwd *pwd;
    132  1.4  mjl {
    133  1.4  mjl 	return login_getclass(pwd ? pwd->pw_class : NULL);
    134  1.4  mjl }
    135  1.4  mjl 
    136  1.1  mjl char *
    137  1.1  mjl login_getcapstr(lc, cap, def, e)
    138  1.1  mjl 	login_cap_t *lc;
    139  1.1  mjl 	char *cap;
    140  1.1  mjl 	char *def;
    141  1.1  mjl 	char *e;
    142  1.1  mjl {
    143  1.1  mjl 	char *res;
    144  1.1  mjl 	int status;
    145  1.1  mjl 
    146  1.1  mjl 	errno = 0;
    147  1.1  mjl 
    148  1.2  mjl 	if (!lc || !lc->lc_cap)
    149  1.1  mjl 		return (def);
    150  1.1  mjl 
    151  1.1  mjl 	switch (status = cgetstr(lc->lc_cap, cap, &res)) {
    152  1.1  mjl 	case -1:
    153  1.1  mjl 		return (def);
    154  1.1  mjl 	case -2:
    155  1.1  mjl 		syslog(LOG_ERR, "%s: getting capability %s: %m",
    156  1.1  mjl 		    lc->lc_class, cap);
    157  1.1  mjl 		return (e);
    158  1.1  mjl 	default:
    159  1.1  mjl 		if (status >= 0)
    160  1.1  mjl 			return (res);
    161  1.1  mjl 		syslog(LOG_ERR, "%s: unexpected error with capability %s",
    162  1.1  mjl 		    lc->lc_class, cap);
    163  1.1  mjl 		return (e);
    164  1.1  mjl 	}
    165  1.1  mjl }
    166  1.1  mjl 
    167  1.1  mjl quad_t
    168  1.1  mjl login_getcaptime(lc, cap, def, e)
    169  1.1  mjl 	login_cap_t *lc;
    170  1.1  mjl 	char *cap;
    171  1.1  mjl 	quad_t def;
    172  1.1  mjl 	quad_t e;
    173  1.1  mjl {
    174  1.1  mjl 	char *ep;
    175  1.1  mjl 	char *res, *sres;
    176  1.1  mjl 	int status;
    177  1.1  mjl 	quad_t q, r;
    178  1.1  mjl 
    179  1.1  mjl 	errno = 0;
    180  1.2  mjl 	if (!lc || !lc->lc_cap)
    181  1.1  mjl 		return (def);
    182  1.1  mjl 
    183  1.1  mjl 	switch (status = cgetstr(lc->lc_cap, cap, &res)) {
    184  1.1  mjl 	case -1:
    185  1.1  mjl 		return (def);
    186  1.1  mjl 	case -2:
    187  1.1  mjl 		syslog(LOG_ERR, "%s: getting capability %s: %m",
    188  1.1  mjl 		    lc->lc_class, cap);
    189  1.1  mjl 		errno = ERANGE;
    190  1.1  mjl 		return (e);
    191  1.1  mjl 	default:
    192  1.1  mjl 		if (status >= 0)
    193  1.1  mjl 			break;
    194  1.1  mjl 		syslog(LOG_ERR, "%s: unexpected error with capability %s",
    195  1.1  mjl 		    lc->lc_class, cap);
    196  1.1  mjl 		errno = ERANGE;
    197  1.1  mjl 		return (e);
    198  1.1  mjl 	}
    199  1.1  mjl 
    200  1.5  mjl 	if (isinfinite(res))
    201  1.1  mjl 		return (RLIM_INFINITY);
    202  1.1  mjl 
    203  1.1  mjl 	errno = 0;
    204  1.1  mjl 
    205  1.1  mjl 	q = 0;
    206  1.1  mjl 	sres = res;
    207  1.1  mjl 	while (*res) {
    208  1.1  mjl 		r = strtoq(res, &ep, 0);
    209  1.1  mjl 		if (!ep || ep == res ||
    210  1.1  mjl 		    ((r == QUAD_MIN || r == QUAD_MAX) && errno == ERANGE)) {
    211  1.1  mjl invalid:
    212  1.1  mjl 			syslog(LOG_ERR, "%s:%s=%s: invalid time",
    213  1.1  mjl 			    lc->lc_class, cap, sres);
    214  1.1  mjl 			errno = ERANGE;
    215  1.1  mjl 			return (e);
    216  1.1  mjl 		}
    217  1.1  mjl 		switch (*ep++) {
    218  1.1  mjl 		case '\0':
    219  1.1  mjl 			--ep;
    220  1.1  mjl 			break;
    221  1.1  mjl 		case 's': case 'S':
    222  1.1  mjl 			break;
    223  1.1  mjl 		case 'm': case 'M':
    224  1.1  mjl 			r *= 60;
    225  1.1  mjl 			break;
    226  1.1  mjl 		case 'h': case 'H':
    227  1.1  mjl 			r *= 60 * 60;
    228  1.1  mjl 			break;
    229  1.1  mjl 		case 'd': case 'D':
    230  1.1  mjl 			r *= 60 * 60 * 24;
    231  1.1  mjl 			break;
    232  1.1  mjl 		case 'w': case 'W':
    233  1.1  mjl 			r *= 60 * 60 * 24 * 7;
    234  1.1  mjl 			break;
    235  1.1  mjl 		case 'y': case 'Y':	/* Pretty absurd */
    236  1.1  mjl 			r *= 60 * 60 * 24 * 365;
    237  1.1  mjl 			break;
    238  1.1  mjl 		default:
    239  1.1  mjl 			goto invalid;
    240  1.1  mjl 		}
    241  1.1  mjl 		res = ep;
    242  1.1  mjl 		q += r;
    243  1.1  mjl 	}
    244  1.1  mjl 	return (q);
    245  1.1  mjl }
    246  1.1  mjl 
    247  1.1  mjl quad_t
    248  1.1  mjl login_getcapnum(lc, cap, def, e)
    249  1.1  mjl 	login_cap_t *lc;
    250  1.1  mjl 	char *cap;
    251  1.1  mjl 	quad_t def;
    252  1.1  mjl 	quad_t e;
    253  1.1  mjl {
    254  1.1  mjl 	char *ep;
    255  1.1  mjl 	char *res;
    256  1.1  mjl 	int status;
    257  1.1  mjl 	quad_t q;
    258  1.1  mjl 
    259  1.1  mjl 	errno = 0;
    260  1.2  mjl 	if (!lc || !lc->lc_cap)
    261  1.1  mjl 		return (def);
    262  1.1  mjl 
    263  1.1  mjl 	switch (status = cgetstr(lc->lc_cap, cap, &res)) {
    264  1.1  mjl 	case -1:
    265  1.1  mjl 		return (def);
    266  1.1  mjl 	case -2:
    267  1.1  mjl 		syslog(LOG_ERR, "%s: getting capability %s: %m",
    268  1.1  mjl 		    lc->lc_class, cap);
    269  1.1  mjl 		errno = ERANGE;
    270  1.1  mjl 		return (e);
    271  1.1  mjl 	default:
    272  1.1  mjl 		if (status >= 0)
    273  1.1  mjl 			break;
    274  1.1  mjl 		syslog(LOG_ERR, "%s: unexpected error with capability %s",
    275  1.1  mjl 		    lc->lc_class, cap);
    276  1.1  mjl 		errno = ERANGE;
    277  1.1  mjl 		return (e);
    278  1.1  mjl 	}
    279  1.1  mjl 
    280  1.5  mjl 	if (isinfinite(res))
    281  1.1  mjl 		return (RLIM_INFINITY);
    282  1.1  mjl 
    283  1.1  mjl 	errno = 0;
    284  1.1  mjl     	q = strtoq(res, &ep, 0);
    285  1.1  mjl 	if (!ep || ep == res || ep[0] ||
    286  1.1  mjl 	    ((q == QUAD_MIN || q == QUAD_MAX) && errno == ERANGE)) {
    287  1.1  mjl 		syslog(LOG_ERR, "%s:%s=%s: invalid number",
    288  1.1  mjl 		    lc->lc_class, cap, res);
    289  1.1  mjl 		errno = ERANGE;
    290  1.1  mjl 		return (e);
    291  1.1  mjl 	}
    292  1.1  mjl 	return (q);
    293  1.1  mjl }
    294  1.1  mjl 
    295  1.1  mjl quad_t
    296  1.1  mjl login_getcapsize(lc, cap, def, e)
    297  1.1  mjl 	login_cap_t *lc;
    298  1.1  mjl 	char *cap;
    299  1.1  mjl 	quad_t def;
    300  1.1  mjl 	quad_t e;
    301  1.1  mjl {
    302  1.1  mjl 	char *ep;
    303  1.1  mjl 	char *res;
    304  1.1  mjl 	int status;
    305  1.1  mjl 	quad_t q;
    306  1.1  mjl 
    307  1.1  mjl 	errno = 0;
    308  1.1  mjl 
    309  1.2  mjl 	if (!lc || !lc->lc_cap)
    310  1.1  mjl 		return (def);
    311  1.1  mjl 
    312  1.1  mjl 	switch (status = cgetstr(lc->lc_cap, cap, &res)) {
    313  1.1  mjl 	case -1:
    314  1.1  mjl 		return (def);
    315  1.1  mjl 	case -2:
    316  1.1  mjl 		syslog(LOG_ERR, "%s: getting capability %s: %m",
    317  1.1  mjl 		    lc->lc_class, cap);
    318  1.1  mjl 		errno = ERANGE;
    319  1.1  mjl 		return (e);
    320  1.1  mjl 	default:
    321  1.1  mjl 		if (status >= 0)
    322  1.1  mjl 			break;
    323  1.1  mjl 		syslog(LOG_ERR, "%s: unexpected error with capability %s",
    324  1.1  mjl 		    lc->lc_class, cap);
    325  1.1  mjl 		errno = ERANGE;
    326  1.1  mjl 		return (e);
    327  1.1  mjl 	}
    328  1.1  mjl 
    329  1.1  mjl 	errno = 0;
    330  1.1  mjl 	q = strtolimit(res, &ep, 0);
    331  1.1  mjl 	if (!ep || ep == res || (ep[0] && ep[1]) ||
    332  1.1  mjl 	    ((q == QUAD_MIN || q == QUAD_MAX) && errno == ERANGE)) {
    333  1.1  mjl 		syslog(LOG_ERR, "%s:%s=%s: invalid size",
    334  1.1  mjl 		    lc->lc_class, cap, res);
    335  1.1  mjl 		errno = ERANGE;
    336  1.1  mjl 		return (e);
    337  1.1  mjl 	}
    338  1.1  mjl 	return (q);
    339  1.1  mjl }
    340  1.1  mjl 
    341  1.1  mjl int
    342  1.1  mjl login_getcapbool(lc, cap, def)
    343  1.1  mjl 	login_cap_t *lc;
    344  1.1  mjl 	char *cap;
    345  1.1  mjl 	u_int def;
    346  1.1  mjl {
    347  1.2  mjl 	if (!lc || !lc->lc_cap)
    348  1.1  mjl 		return (def);
    349  1.1  mjl 
    350  1.1  mjl 	return (cgetcap(lc->lc_cap, cap, ':') != NULL);
    351  1.1  mjl }
    352  1.1  mjl 
    353  1.1  mjl void
    354  1.1  mjl login_close(lc)
    355  1.1  mjl 	login_cap_t *lc;
    356  1.1  mjl {
    357  1.1  mjl 	if (lc) {
    358  1.1  mjl 		if (lc->lc_class)
    359  1.1  mjl 			free(lc->lc_class);
    360  1.1  mjl 		if (lc->lc_cap)
    361  1.1  mjl 			free(lc->lc_cap);
    362  1.1  mjl 		if (lc->lc_style)
    363  1.1  mjl 			free(lc->lc_style);
    364  1.1  mjl 		free(lc);
    365  1.1  mjl 	}
    366  1.1  mjl }
    367  1.1  mjl 
    368  1.1  mjl #define	CTIME	1
    369  1.1  mjl #define	CSIZE	2
    370  1.1  mjl #define	CNUMB	3
    371  1.1  mjl 
    372  1.1  mjl static struct {
    373  1.1  mjl 	int	what;
    374  1.1  mjl 	int	type;
    375  1.1  mjl 	char *	name;
    376  1.1  mjl } r_list[] = {
    377  1.1  mjl 	{ RLIMIT_CPU,		CTIME, "cputime", },
    378  1.1  mjl 	{ RLIMIT_FSIZE,		CSIZE, "filesize", },
    379  1.1  mjl 	{ RLIMIT_DATA,		CSIZE, "datasize", },
    380  1.1  mjl 	{ RLIMIT_STACK,		CSIZE, "stacksize", },
    381  1.1  mjl 	{ RLIMIT_RSS,		CSIZE, "memoryuse", },
    382  1.1  mjl 	{ RLIMIT_MEMLOCK,	CSIZE, "memorylocked", },
    383  1.1  mjl 	{ RLIMIT_NPROC,		CNUMB, "maxproc", },
    384  1.1  mjl 	{ RLIMIT_NOFILE,	CNUMB, "openfiles", },
    385  1.1  mjl 	{ RLIMIT_CORE,		CSIZE, "coredumpsize", },
    386  1.1  mjl 	{ -1, 0, 0 }
    387  1.1  mjl };
    388  1.1  mjl 
    389  1.1  mjl static int
    390  1.1  mjl gsetrl(lc, what, name, type)
    391  1.1  mjl 	login_cap_t *lc;
    392  1.1  mjl 	int what;
    393  1.1  mjl 	char *name;
    394  1.1  mjl 	int type;
    395  1.1  mjl {
    396  1.1  mjl 	struct rlimit rl;
    397  1.1  mjl 	struct rlimit r;
    398  1.1  mjl 	char name_cur[32];
    399  1.1  mjl 	char name_max[32];
    400  1.1  mjl 
    401  1.1  mjl 	sprintf(name_cur, "%s-cur", name);
    402  1.1  mjl 	sprintf(name_max, "%s-max", name);
    403  1.1  mjl 
    404  1.1  mjl 	if (getrlimit(what, &r)) {
    405  1.1  mjl 		syslog(LOG_ERR, "getting resource limit: %m");
    406  1.1  mjl 		return (-1);
    407  1.1  mjl 	}
    408  1.1  mjl 
    409  1.1  mjl #define	RCUR	r.rlim_cur
    410  1.1  mjl #define	RMAX	r.rlim_max
    411  1.1  mjl 
    412  1.1  mjl 	switch (type) {
    413  1.1  mjl 	case CTIME:
    414  1.1  mjl 		RCUR = login_getcaptime(lc, name, RCUR, RCUR);
    415  1.1  mjl 		RMAX = login_getcaptime(lc, name, RMAX, RMAX);
    416  1.1  mjl 		rl.rlim_cur = login_getcaptime(lc, name_cur, RCUR, RCUR);
    417  1.1  mjl 		rl.rlim_max = login_getcaptime(lc, name_max, RMAX, RMAX);
    418  1.1  mjl 		break;
    419  1.1  mjl 	case CSIZE:
    420  1.1  mjl 		RCUR = login_getcapsize(lc, name, RCUR, RCUR);
    421  1.1  mjl 		RMAX = login_getcapsize(lc, name, RMAX, RMAX);
    422  1.1  mjl 		rl.rlim_cur = login_getcapsize(lc, name_cur, RCUR, RCUR);
    423  1.1  mjl 		rl.rlim_max = login_getcapsize(lc, name_max, RMAX, RMAX);
    424  1.1  mjl 		break;
    425  1.1  mjl 	case CNUMB:
    426  1.1  mjl 		RCUR = login_getcapnum(lc, name, RCUR, RCUR);
    427  1.1  mjl 		RMAX = login_getcapnum(lc, name, RMAX, RMAX);
    428  1.1  mjl 		rl.rlim_cur = login_getcapnum(lc, name_cur, RCUR, RCUR);
    429  1.1  mjl 		rl.rlim_max = login_getcapnum(lc, name_max, RMAX, RMAX);
    430  1.1  mjl 		break;
    431  1.1  mjl 	default:
    432  1.1  mjl 		return (-1);
    433  1.1  mjl 	}
    434  1.1  mjl 
    435  1.1  mjl 	if (setrlimit(what, &rl)) {
    436  1.1  mjl 		syslog(LOG_ERR, "%s: setting resource limit %s: %m",
    437  1.1  mjl 		    lc->lc_class, name);
    438  1.1  mjl 		return (-1);
    439  1.1  mjl 	}
    440  1.1  mjl #undef	RCUR
    441  1.1  mjl #undef	RMAX
    442  1.1  mjl 	return (0);
    443  1.1  mjl }
    444  1.1  mjl 
    445  1.4  mjl static int
    446  1.4  mjl setuserenv(lc)
    447  1.4  mjl 	login_cap_t *lc;
    448  1.4  mjl {
    449  1.4  mjl 	char *stop = ", \t";
    450  1.4  mjl 	int i, count;
    451  1.4  mjl 	char *ptr;
    452  1.4  mjl 	char **res;
    453  1.4  mjl 	char *str = login_getcapstr(lc, "setenv", NULL, NULL);
    454  1.4  mjl 
    455  1.4  mjl 	if(str == NULL || *str == '\0')
    456  1.4  mjl 		return 0;
    457  1.4  mjl 
    458  1.4  mjl 	/* count the sub-strings */
    459  1.4  mjl 	for (i = 1, ptr = str; *ptr; i++) {
    460  1.4  mjl 		ptr += strcspn(ptr, stop);
    461  1.4  mjl 		if (*ptr)
    462  1.4  mjl 			ptr++;
    463  1.4  mjl 		}
    464  1.4  mjl 
    465  1.4  mjl 	/* allocate ptr array and string */
    466  1.4  mjl 	count = i;
    467  1.4  mjl 	res = malloc( count * sizeof(char *) + strlen(str) + 1 );
    468  1.4  mjl 
    469  1.4  mjl 	if(!res)
    470  1.4  mjl 		return -1;
    471  1.4  mjl 
    472  1.4  mjl 	ptr = (char *)res + count * sizeof(char *);
    473  1.4  mjl 	strcpy(ptr, str);
    474  1.4  mjl 
    475  1.4  mjl 	/* split string */
    476  1.4  mjl 	for (i = 0; *ptr && i < count; i++) {
    477  1.4  mjl 		res[i] = ptr;
    478  1.4  mjl 		ptr += strcspn(ptr, stop);
    479  1.4  mjl 		if (*ptr)
    480  1.4  mjl 			*ptr++ = '\0';
    481  1.4  mjl 		}
    482  1.4  mjl 
    483  1.4  mjl 	res[i] = NULL;
    484  1.4  mjl 
    485  1.4  mjl 	for (i = 0; i < count && res[i]; i++) {
    486  1.4  mjl 		if (*res[i] != '\0') {
    487  1.4  mjl 			if ((ptr = strchr(res[i], '=')))
    488  1.4  mjl 				*ptr++ = '\0';
    489  1.4  mjl 			else
    490  1.4  mjl 				ptr = "";
    491  1.4  mjl 			setenv(res[i], ptr, 1);
    492  1.4  mjl 		}
    493  1.4  mjl 	}
    494  1.4  mjl 
    495  1.5  mjl 	free(res);
    496  1.4  mjl 	return 0;
    497  1.4  mjl }
    498  1.4  mjl 
    499  1.4  mjl 
    500  1.1  mjl int
    501  1.1  mjl setclasscontext(class, flags)
    502  1.1  mjl 	char *class;
    503  1.1  mjl 	u_int flags;
    504  1.1  mjl {
    505  1.1  mjl 	int ret;
    506  1.1  mjl 	login_cap_t *lc;
    507  1.1  mjl 
    508  1.1  mjl 	flags &= LOGIN_SETRESOURCES | LOGIN_SETPRIORITY | LOGIN_SETUMASK |
    509  1.1  mjl 	    LOGIN_SETPATH;
    510  1.1  mjl 
    511  1.1  mjl 	lc = login_getclass(class);
    512  1.1  mjl 	ret = lc ? setusercontext(lc, NULL, 0, flags) : -1;
    513  1.1  mjl 	login_close(lc);
    514  1.1  mjl 	return (ret);
    515  1.1  mjl }
    516  1.1  mjl 
    517  1.1  mjl int
    518  1.1  mjl setusercontext(lc, pwd, uid, flags)
    519  1.1  mjl 	login_cap_t *lc;
    520  1.1  mjl 	struct passwd *pwd;
    521  1.1  mjl 	uid_t uid;
    522  1.1  mjl 	u_int flags;
    523  1.1  mjl {
    524  1.1  mjl 	login_cap_t *flc;
    525  1.1  mjl 	quad_t p;
    526  1.1  mjl 	int i;
    527  1.1  mjl 
    528  1.1  mjl 	flc = NULL;
    529  1.1  mjl 
    530  1.3  mjl 	if (!lc)
    531  1.3  mjl 		flc = lc = login_getclass(pwd ? pwd->pw_class : NULL);
    532  1.1  mjl 
    533  1.1  mjl 	/*
    534  1.1  mjl 	 * Without the pwd entry being passed we cannot set either
    535  1.1  mjl 	 * the group or the login.  We could complain about it.
    536  1.1  mjl 	 */
    537  1.1  mjl 	if (pwd == NULL)
    538  1.1  mjl 		flags &= ~(LOGIN_SETGROUP|LOGIN_SETLOGIN);
    539  1.1  mjl 
    540  1.1  mjl 	if (flags & LOGIN_SETRESOURCES)
    541  1.1  mjl 		for (i = 0; r_list[i].name; ++i)
    542  1.1  mjl 			if (gsetrl(lc, r_list[i].what, r_list[i].name,
    543  1.1  mjl 			    r_list[i].type))
    544  1.1  mjl 				/* XXX - call syslog()? */;
    545  1.1  mjl 
    546  1.1  mjl 	if (flags & LOGIN_SETPRIORITY) {
    547  1.1  mjl 		p = login_getcapnum(lc, "priority", 0LL, 0LL);
    548  1.1  mjl 
    549  1.1  mjl 		if (setpriority(PRIO_PROCESS, 0, (int)p) < 0)
    550  1.1  mjl 			syslog(LOG_ERR, "%s: setpriority: %m", lc->lc_class);
    551  1.1  mjl 	}
    552  1.1  mjl 
    553  1.1  mjl 	if (flags & LOGIN_SETUMASK) {
    554  1.1  mjl 		p = login_getcapnum(lc, "umask", (quad_t) LOGIN_DEFUMASK,
    555  1.1  mjl 												   (quad_t) LOGIN_DEFUMASK);
    556  1.1  mjl 		umask((mode_t)p);
    557  1.1  mjl 	}
    558  1.1  mjl 
    559  1.1  mjl 	if (flags & LOGIN_SETGROUP) {
    560  1.1  mjl 		if (setgid(pwd->pw_gid) < 0) {
    561  1.1  mjl 			syslog(LOG_ERR, "setgid(%d): %m", pwd->pw_gid);
    562  1.1  mjl 			login_close(flc);
    563  1.1  mjl 			return (-1);
    564  1.1  mjl 		}
    565  1.1  mjl 
    566  1.1  mjl 		if (initgroups(pwd->pw_name, pwd->pw_gid) < 0) {
    567  1.1  mjl 			syslog(LOG_ERR, "initgroups(%s,%d): %m",
    568  1.1  mjl 			    pwd->pw_name, pwd->pw_gid);
    569  1.1  mjl 			login_close(flc);
    570  1.1  mjl 			return (-1);
    571  1.1  mjl 		}
    572  1.1  mjl 	}
    573  1.1  mjl 
    574  1.1  mjl 	if (flags & LOGIN_SETLOGIN)
    575  1.1  mjl 		if (setlogin(pwd->pw_name) < 0) {
    576  1.1  mjl 			syslog(LOG_ERR, "setlogin(%s) failure: %m",
    577  1.1  mjl 			    pwd->pw_name);
    578  1.1  mjl 			login_close(flc);
    579  1.1  mjl 			return (-1);
    580  1.1  mjl 		}
    581  1.1  mjl 
    582  1.1  mjl 	if (flags & LOGIN_SETUSER)
    583  1.1  mjl 		if (setuid(uid) < 0) {
    584  1.1  mjl 			syslog(LOG_ERR, "setuid(%d): %m", uid);
    585  1.1  mjl 			login_close(flc);
    586  1.1  mjl 			return (-1);
    587  1.1  mjl 		}
    588  1.4  mjl 
    589  1.4  mjl 	if (flags & LOGIN_SETENV)
    590  1.4  mjl 		setuserenv(lc);
    591  1.1  mjl 
    592  1.1  mjl 	if (flags & LOGIN_SETPATH)
    593  1.1  mjl 		setuserpath(lc, pwd ? pwd->pw_dir : "");
    594  1.1  mjl 
    595  1.1  mjl 	login_close(flc);
    596  1.1  mjl 	return (0);
    597  1.1  mjl }
    598  1.1  mjl 
    599  1.1  mjl static void
    600  1.1  mjl setuserpath(lc, home)
    601  1.1  mjl 	login_cap_t *lc;
    602  1.1  mjl 	char *home;
    603  1.1  mjl {
    604  1.1  mjl 	size_t hlen, plen;
    605  1.1  mjl 	int cnt = 0;
    606  1.1  mjl 	char *path;
    607  1.1  mjl 	char *p, *q;
    608  1.1  mjl 
    609  1.1  mjl 	hlen = strlen(home);
    610  1.1  mjl 
    611  1.1  mjl 	p = path = login_getcapstr(lc, "path", NULL, NULL);
    612  1.1  mjl 	if (p) {
    613  1.1  mjl 		while (*p)
    614  1.1  mjl 			if (*p++ == '~')
    615  1.1  mjl 				++cnt;
    616  1.1  mjl 		plen = (p - path) + cnt * (hlen + 1) + 1;
    617  1.1  mjl 		p = path;
    618  1.1  mjl 		q = path = malloc(plen);
    619  1.1  mjl 		if (q) {
    620  1.1  mjl 			while (*p) {
    621  1.1  mjl 				p += strspn(p, " \t");
    622  1.1  mjl 				if (*p == '\0')
    623  1.1  mjl 					break;
    624  1.1  mjl 				plen = strcspn(p, " \t");
    625  1.1  mjl 				if (hlen == 0 && *p == '~') {
    626  1.1  mjl 					p += plen;
    627  1.1  mjl 					continue;
    628  1.1  mjl 				}
    629  1.1  mjl 				if (q != path)
    630  1.1  mjl 					*q++ = ':';
    631  1.1  mjl 				if (*p == '~') {
    632  1.1  mjl 					strcpy(q, home);
    633  1.1  mjl 					q += hlen;
    634  1.1  mjl 					++p;
    635  1.1  mjl 					--plen;
    636  1.1  mjl 				}
    637  1.1  mjl 				memcpy(q, p, plen);
    638  1.1  mjl 				p += plen;
    639  1.1  mjl 				q += plen;
    640  1.1  mjl 			}
    641  1.1  mjl 			*q = '\0';
    642  1.1  mjl 		} else
    643  1.1  mjl 			path = _PATH_DEFPATH;
    644  1.1  mjl 	} else
    645  1.1  mjl 		path = _PATH_DEFPATH;
    646  1.1  mjl 	if (setenv("PATH", path, 1))
    647  1.1  mjl 		warn("could not set PATH");
    648  1.1  mjl }
    649  1.1  mjl 
    650  1.1  mjl /*
    651  1.1  mjl  * Convert an expression of the following forms
    652  1.1  mjl  * 	1) A number.
    653  1.1  mjl  *	2) A number followed by a b (mult by 512).
    654  1.1  mjl  *	3) A number followed by a k (mult by 1024).
    655  1.1  mjl  *	5) A number followed by a m (mult by 1024 * 1024).
    656  1.1  mjl  *	6) A number followed by a g (mult by 1024 * 1024 * 1024).
    657  1.1  mjl  *	7) A number followed by a t (mult by 1024 * 1024 * 1024 * 1024).
    658  1.1  mjl  *	8) Two or more numbers (with/without k,b,m,g, or t).
    659  1.1  mjl  *	   seperated by x (also * for backwards compatibility), specifying
    660  1.1  mjl  *	   the product of the indicated values.
    661  1.1  mjl  */
    662  1.1  mjl static
    663  1.1  mjl u_quad_t
    664  1.1  mjl strtosize(str, endptr, radix)
    665  1.1  mjl 	char *str;
    666  1.1  mjl 	char **endptr;
    667  1.1  mjl 	int radix;
    668  1.1  mjl {
    669  1.1  mjl 	u_quad_t num, num2;
    670  1.1  mjl 	char *expr, *expr2;
    671  1.1  mjl 
    672  1.1  mjl 	errno = 0;
    673  1.1  mjl 	num = strtouq(str, &expr, radix);
    674  1.1  mjl 	if (errno || expr == str) {
    675  1.1  mjl 		if (endptr)
    676  1.1  mjl 			*endptr = expr;
    677  1.1  mjl 		return (num);
    678  1.1  mjl 	}
    679  1.1  mjl 
    680  1.1  mjl 	switch(*expr) {
    681  1.1  mjl 	case 'b': case 'B':
    682  1.1  mjl 		num = multiply(num, (u_quad_t)512);
    683  1.1  mjl 		++expr;
    684  1.1  mjl 		break;
    685  1.1  mjl 	case 'k': case 'K':
    686  1.1  mjl 		num = multiply(num, (u_quad_t)1024);
    687  1.1  mjl 		++expr;
    688  1.1  mjl 		break;
    689  1.1  mjl 	case 'm': case 'M':
    690  1.1  mjl 		num = multiply(num, (u_quad_t)1024 * 1024);
    691  1.1  mjl 		++expr;
    692  1.1  mjl 		break;
    693  1.1  mjl 	case 'g': case 'G':
    694  1.1  mjl 		num = multiply(num, (u_quad_t)1024 * 1024 * 1024);
    695  1.1  mjl 		++expr;
    696  1.1  mjl 		break;
    697  1.1  mjl 	case 't': case 'T':
    698  1.1  mjl 		num = multiply(num, (u_quad_t)1024 * 1024);
    699  1.1  mjl 		num = multiply(num, (u_quad_t)1024 * 1024);
    700  1.1  mjl 		++expr;
    701  1.1  mjl 		break;
    702  1.1  mjl 	}
    703  1.1  mjl 
    704  1.1  mjl 	if (errno)
    705  1.1  mjl 		goto erange;
    706  1.1  mjl 
    707  1.1  mjl 	switch(*expr) {
    708  1.1  mjl 	case '*':			/* Backward compatible. */
    709  1.1  mjl 	case 'x':
    710  1.1  mjl 		num2 = strtosize(expr+1, &expr2, radix);
    711  1.1  mjl 		if (errno) {
    712  1.1  mjl 			expr = expr2;
    713  1.1  mjl 			goto erange;
    714  1.1  mjl 		}
    715  1.1  mjl 
    716  1.1  mjl 		if (expr2 == expr + 1) {
    717  1.1  mjl 			if (endptr)
    718  1.1  mjl 				*endptr = expr;
    719  1.1  mjl 			return (num);
    720  1.1  mjl 		}
    721  1.1  mjl 		expr = expr2;
    722  1.1  mjl 		num = multiply(num, num2);
    723  1.1  mjl 		if (errno)
    724  1.1  mjl 			goto erange;
    725  1.1  mjl 		break;
    726  1.1  mjl 	}
    727  1.1  mjl 	if (endptr)
    728  1.1  mjl 		*endptr = expr;
    729  1.1  mjl 	return (num);
    730  1.1  mjl erange:
    731  1.1  mjl 	if (endptr)
    732  1.1  mjl 		*endptr = expr;
    733  1.1  mjl 	errno = ERANGE;
    734  1.1  mjl 	return (UQUAD_MAX);
    735  1.1  mjl }
    736  1.1  mjl 
    737  1.1  mjl static
    738  1.1  mjl u_quad_t
    739  1.1  mjl strtolimit(str, endptr, radix)
    740  1.1  mjl 	char *str;
    741  1.1  mjl 	char **endptr;
    742  1.1  mjl 	int radix;
    743  1.1  mjl {
    744  1.5  mjl 	if (isinfinite(str)) {
    745  1.1  mjl 		if (endptr)
    746  1.1  mjl 			*endptr = str + strlen(str);
    747  1.1  mjl 		return ((u_quad_t)RLIM_INFINITY);
    748  1.1  mjl 	}
    749  1.1  mjl 	return (strtosize(str, endptr, radix));
    750  1.5  mjl }
    751  1.5  mjl 
    752  1.5  mjl static int
    753  1.5  mjl isinfinite(const char *s)
    754  1.5  mjl {
    755  1.5  mjl 	static const char *infs[] = {
    756  1.5  mjl 		"infinity",
    757  1.5  mjl 		"inf",
    758  1.5  mjl 		"unlimited",
    759  1.5  mjl 		"unlimit",
    760  1.5  mjl 		NULL
    761  1.5  mjl 	};
    762  1.5  mjl 	const char **i;
    763  1.5  mjl 
    764  1.5  mjl 	for(i = infs; *i; i++) {
    765  1.5  mjl 		if (!strcasecmp(s, *i))
    766  1.5  mjl 			return 1;
    767  1.5  mjl 	}
    768  1.5  mjl 	return 0;
    769  1.1  mjl }
    770  1.1  mjl 
    771  1.1  mjl static u_quad_t
    772  1.1  mjl multiply(n1, n2)
    773  1.1  mjl 	u_quad_t n1;
    774  1.1  mjl 	u_quad_t n2;
    775  1.1  mjl {
    776  1.1  mjl 	static int bpw = 0;
    777  1.1  mjl 	u_quad_t m;
    778  1.1  mjl 	u_quad_t r;
    779  1.1  mjl 	int b1, b2;
    780  1.1  mjl 
    781  1.1  mjl 	/*
    782  1.1  mjl 	 * Get rid of the simple cases
    783  1.1  mjl 	 */
    784  1.1  mjl 	if (n1 == 0 || n2 == 0)
    785  1.1  mjl 		return (0);
    786  1.1  mjl 	if (n1 == 1)
    787  1.1  mjl 		return (n2);
    788  1.1  mjl 	if (n2 == 1)
    789  1.1  mjl 		return (n1);
    790  1.1  mjl 
    791  1.1  mjl 	/*
    792  1.1  mjl 	 * sizeof() returns number of bytes needed for storage.
    793  1.1  mjl 	 * This may be different from the actual number of useful bits.
    794  1.1  mjl 	 */
    795  1.1  mjl 	if (!bpw) {
    796  1.1  mjl 		bpw = sizeof(u_quad_t) * 8;
    797  1.1  mjl 		while (((u_quad_t)1 << (bpw-1)) == 0)
    798  1.1  mjl 			--bpw;
    799  1.1  mjl 	}
    800  1.1  mjl 
    801  1.1  mjl 	/*
    802  1.1  mjl 	 * First check the magnitude of each number.  If the sum of the
    803  1.1  mjl 	 * magnatude is way to high, reject the number.  (If this test
    804  1.1  mjl 	 * is not done then the first multiply below may overflow.)
    805  1.1  mjl 	 */
    806  1.1  mjl 	for (b1 = bpw; (((u_quad_t)1 << (b1-1)) & n1) == 0; --b1)
    807  1.1  mjl 		;
    808  1.1  mjl 	for (b2 = bpw; (((u_quad_t)1 << (b2-1)) & n2) == 0; --b2)
    809  1.1  mjl 		;
    810  1.1  mjl 	if (b1 + b2 - 2 > bpw) {
    811  1.1  mjl 		errno = ERANGE;
    812  1.1  mjl 		return (UQUAD_MAX);
    813  1.1  mjl 	}
    814  1.1  mjl 
    815  1.1  mjl 	/*
    816  1.1  mjl 	 * Decompose the multiplication to be:
    817  1.1  mjl 	 * h1 = n1 & ~1
    818  1.1  mjl 	 * h2 = n2 & ~1
    819  1.1  mjl 	 * l1 = n1 & 1
    820  1.1  mjl 	 * l2 = n2 & 1
    821  1.1  mjl 	 * (h1 + l1) * (h2 + l2)
    822  1.1  mjl 	 * (h1 * h2) + (h1 * l2) + (l1 * h2) + (l1 * l2)
    823  1.1  mjl 	 *
    824  1.1  mjl 	 * Since h1 && h2 do not have the low bit set, we can then say:
    825  1.1  mjl 	 *
    826  1.1  mjl 	 * (h1>>1 * h2>>1 * 4) + ...
    827  1.1  mjl 	 *
    828  1.1  mjl 	 * So if (h1>>1 * h2>>1) > (1<<(bpw - 2)) then the result will
    829  1.1  mjl 	 * overflow.
    830  1.1  mjl 	 *
    831  1.1  mjl 	 * Finally, if MAX - ((h1 * l2) + (l1 * h2) + (l1 * l2)) < (h1*h2)
    832  1.1  mjl 	 * then adding in residual amout will cause an overflow.
    833  1.1  mjl 	 */
    834  1.1  mjl 
    835  1.1  mjl 	m = (n1 >> 1) * (n2 >> 1);
    836  1.1  mjl 
    837  1.1  mjl 	if (m >= ((u_quad_t)1 << (bpw-2))) {
    838  1.1  mjl 		errno = ERANGE;
    839  1.1  mjl 		return (UQUAD_MAX);
    840  1.1  mjl 	}
    841  1.1  mjl 
    842  1.1  mjl 	m *= 4;
    843  1.1  mjl 
    844  1.1  mjl 	r = (n1 & n2 & 1)
    845  1.1  mjl 	  + (n2 & 1) * (n1 & ~(u_quad_t)1)
    846  1.1  mjl 	  + (n1 & 1) * (n2 & ~(u_quad_t)1);
    847  1.1  mjl 
    848  1.1  mjl 	if ((u_quad_t)(m + r) < m) {
    849  1.1  mjl 		errno = ERANGE;
    850  1.1  mjl 		return (UQUAD_MAX);
    851  1.1  mjl 	}
    852  1.1  mjl 	m += r;
    853  1.1  mjl 
    854  1.1  mjl 	return (m);
    855  1.1  mjl }
    856  1.1  mjl 
    857