2 Copyright (C) Andrew Tridgell 2009
4 This program is free software; you can redistribute it and/or modify
5 it under the terms of the GNU General Public License as published by
6 the Free Software Foundation; either version 3 of the License, or
7 (at your option) any later version.
9 This program is distributed in the hope that it will be useful,
10 but WITHOUT ANY WARRANTY; without even the implied warranty of
11 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 GNU General Public License for more details.
14 You should have received a copy of the GNU General Public License
15 along with this program. If not, see <http://www.gnu.org/licenses/>.
20 #define UID_WRAPPER_NOT_REPLACE
21 #include "../replace/replace.h"
23 #include "system/passwd.h"
25 #else /* _SAMBA_BUILD_ */
27 #error uid_wrapper_only_supported_in_samba_yet
36 we keep the virtualised euid/egid/groups information here
46 static void uwrap_init(void)
48 if (uwrap.initialised) return;
49 uwrap.initialised = true;
50 if (getenv("UID_WRAPPER")) {
52 /* put us in one group */
53 uwrap.euid = geteuid();
54 uwrap.egid = getegid();
55 uwrap.groups = talloc_array(NULL, gid_t, 1);
61 _PUBLIC_ int uwrap_enabled(void)
64 return uwrap.enabled?1:0;
67 _PUBLIC_ int uwrap_seteuid(uid_t euid)
73 /* assume for now that the ruid stays as root */
78 _PUBLIC_ int uwrap_setreuid(uid_t ruid, uid_t euid)
82 return setreuid(ruid, euid);
84 /* assume for now that the ruid stays as root */
89 _PUBLIC_ int uwrap_setresuid(uid_t ruid, uid_t euid, uid_t suid)
93 return setresuid(ruid, euid, suid);
95 /* assume for now that the ruid stays as root */
100 _PUBLIC_ uid_t uwrap_geteuid(void)
103 if (!uwrap.enabled) {
109 _PUBLIC_ int uwrap_setegid(gid_t egid)
112 if (!uwrap.enabled) {
113 return setegid(egid);
115 /* assume for now that the ruid stays as root */
120 _PUBLIC_ int uwrap_setregid(gid_t rgid, gid_t egid)
123 if (!uwrap.enabled) {
124 return setregid(rgid, egid);
126 /* assume for now that the ruid stays as root */
131 _PUBLIC_ uid_t uwrap_getegid(void)
134 if (!uwrap.enabled) {
140 _PUBLIC_ int uwrap_setgroups(size_t size, const gid_t *list)
143 if (!uwrap.enabled) {
144 return setgroups(size, list);
147 talloc_free(uwrap.groups);
151 uwrap.groups = talloc_array(NULL, gid_t, size);
152 if (uwrap.groups == NULL) {
156 memcpy(uwrap.groups, list, size*sizeof(gid_t));
161 _PUBLIC_ int uwrap_getgroups(int size, gid_t *list)
166 if (!uwrap.enabled) {
167 return getgroups(size, list);
170 ngroups = talloc_array_length(uwrap.groups);
172 if (size > ngroups) {
178 if (size < ngroups) {
182 memcpy(list, uwrap.groups, size*sizeof(gid_t));
186 _PUBLIC_ uid_t uwrap_getuid(void)
189 if (!uwrap.enabled) {
192 /* we don't simulate ruid changing */
196 _PUBLIC_ gid_t uwrap_getgid(void)
199 if (!uwrap.enabled) {
202 /* we don't simulate rgid changing */