xref: /freebsd/bin/getfacl/getfacl.c (revision c5771451959c82b28d47be9cdf775026d4ae0616)
143960f15SRobert Watson /*-
28051fddeSRobert Watson  * Copyright (c) 1999, 2001, 2002 Robert N M Watson
343960f15SRobert Watson  * All rights reserved.
443960f15SRobert Watson  *
59331ef53SRobert Watson  * This software was developed by Robert Watson for the TrustedBSD Project.
69331ef53SRobert Watson  *
743960f15SRobert Watson  * Redistribution and use in source and binary forms, with or without
843960f15SRobert Watson  * modification, are permitted provided that the following conditions
943960f15SRobert Watson  * are met:
1043960f15SRobert Watson  * 1. Redistributions of source code must retain the above copyright
1143960f15SRobert Watson  *    notice, this list of conditions and the following disclaimer.
1243960f15SRobert Watson  * 2. Redistributions in binary form must reproduce the above copyright
1343960f15SRobert Watson  *    notice, this list of conditions and the following disclaimer in the
1443960f15SRobert Watson  *    documentation and/or other materials provided with the distribution.
1543960f15SRobert Watson  *
1643960f15SRobert Watson  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
1743960f15SRobert Watson  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
1843960f15SRobert Watson  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
1943960f15SRobert Watson  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
2043960f15SRobert Watson  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
2143960f15SRobert Watson  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
2243960f15SRobert Watson  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
2343960f15SRobert Watson  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
2443960f15SRobert Watson  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
2543960f15SRobert Watson  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
2643960f15SRobert Watson  * SUCH DAMAGE.
2743960f15SRobert Watson  */
2843960f15SRobert Watson /*
2943960f15SRobert Watson  * getfacl -- POSIX.1e utility to extract ACLs from files and directories
3043960f15SRobert Watson  * and send the results to stdout
3143960f15SRobert Watson  */
3243960f15SRobert Watson 
335eb43ac2SDavid E. O'Brien 
345eb43ac2SDavid E. O'Brien #include <sys/cdefs.h>
355eb43ac2SDavid E. O'Brien __FBSDID("$FreeBSD$");
365eb43ac2SDavid E. O'Brien 
3743960f15SRobert Watson #include <sys/types.h>
3843960f15SRobert Watson #include <sys/param.h>
3943960f15SRobert Watson #include <sys/acl.h>
4043960f15SRobert Watson #include <sys/stat.h>
415eb43ac2SDavid E. O'Brien 
4243960f15SRobert Watson #include <err.h>
4343960f15SRobert Watson #include <errno.h>
44c5771451SKevin Lo #include <grp.h>
45c5771451SKevin Lo #include <pwd.h>
4643960f15SRobert Watson #include <stdio.h>
477a832d43SChris D. Faulhaber #include <stdlib.h>
4828bf3202SKris Kennaway #include <string.h>
4943960f15SRobert Watson #include <unistd.h>
5043960f15SRobert Watson 
5143960f15SRobert Watson int	more_than_one = 0;
5243960f15SRobert Watson 
5343960f15SRobert Watson static void
5443960f15SRobert Watson usage(void)
5543960f15SRobert Watson {
5643960f15SRobert Watson 
57f9a86e37SRobert Watson 	fprintf(stderr, "getfacl [-dhq] [file ...]\n");
5843960f15SRobert Watson }
5943960f15SRobert Watson 
60c5771451SKevin Lo static char *
61c5771451SKevin Lo getuname(uid_t uid)
62c5771451SKevin Lo {
63c5771451SKevin Lo 	struct passwd *pw;
64c5771451SKevin Lo 	static char uids[10];
65c5771451SKevin Lo 
66c5771451SKevin Lo 	if ((pw = getpwuid(uid)) == NULL) {
67c5771451SKevin Lo 		(void)snprintf(uids, sizeof(uids), "%u", uid);
68c5771451SKevin Lo 		return (uids);
69c5771451SKevin Lo 	} else
70c5771451SKevin Lo 		return (pw->pw_name);
71c5771451SKevin Lo }
72c5771451SKevin Lo 
73c5771451SKevin Lo static char *
74c5771451SKevin Lo getgname(gid_t gid)
75c5771451SKevin Lo {
76c5771451SKevin Lo 	struct group *gr;
77c5771451SKevin Lo 	static char gids[10];
78c5771451SKevin Lo 
79c5771451SKevin Lo 	if ((gr = getgrgid(gid)) == NULL) {
80c5771451SKevin Lo 		(void)snprintf(gids, sizeof(gids), "%u", gid);
81c5771451SKevin Lo 		return (gids);
82c5771451SKevin Lo 	} else
83c5771451SKevin Lo 		return (gr->gr_name);
84c5771451SKevin Lo }
85c5771451SKevin Lo 
867a832d43SChris D. Faulhaber /*
877a832d43SChris D. Faulhaber  * return an ACL corresponding to the permissions
887a832d43SChris D. Faulhaber  * contained in struct stat
897a832d43SChris D. Faulhaber  */
9043960f15SRobert Watson static acl_t
9143960f15SRobert Watson acl_from_stat(struct stat sb)
9243960f15SRobert Watson {
9343960f15SRobert Watson 	acl_t acl;
947a832d43SChris D. Faulhaber 	acl_entry_t entry;
957a832d43SChris D. Faulhaber 	acl_permset_t perms;
9643960f15SRobert Watson 
977a832d43SChris D. Faulhaber 	/* create the ACL */
9843960f15SRobert Watson 	acl = acl_init(3);
9943960f15SRobert Watson 	if (!acl)
1007a832d43SChris D. Faulhaber 		return NULL;
10143960f15SRobert Watson 
1027a832d43SChris D. Faulhaber 	/* First entry: ACL_USER_OBJ */
1037a832d43SChris D. Faulhaber 	if (acl_create_entry(&acl, &entry) == -1)
1047a832d43SChris D. Faulhaber 		return NULL;
1057a832d43SChris D. Faulhaber 	if (acl_set_tag_type(entry, ACL_USER_OBJ) == -1)
1067a832d43SChris D. Faulhaber 		return NULL;
1077a832d43SChris D. Faulhaber 
1087a832d43SChris D. Faulhaber 	if (acl_get_permset(entry, &perms) == -1)
1097a832d43SChris D. Faulhaber 		return NULL;
1107a832d43SChris D. Faulhaber 	if (acl_clear_perms(perms) == -1)
1117a832d43SChris D. Faulhaber 		return NULL;
1127a832d43SChris D. Faulhaber 
1137a832d43SChris D. Faulhaber 	/* calculate user mode */
11443960f15SRobert Watson 	if (sb.st_mode & S_IRUSR)
1157a832d43SChris D. Faulhaber 		if (acl_add_perm(perms, ACL_READ) == -1)
1167a832d43SChris D. Faulhaber 			return NULL;
11743960f15SRobert Watson 	if (sb.st_mode & S_IWUSR)
1187a832d43SChris D. Faulhaber 		if (acl_add_perm(perms, ACL_WRITE) == -1)
1197a832d43SChris D. Faulhaber 			return NULL;
12043960f15SRobert Watson 	if (sb.st_mode & S_IXUSR)
1217a832d43SChris D. Faulhaber 		if (acl_add_perm(perms, ACL_EXECUTE) == -1)
1227a832d43SChris D. Faulhaber 			return NULL;
1237a832d43SChris D. Faulhaber 	if (acl_set_permset(entry, perms) == -1)
1247a832d43SChris D. Faulhaber 		return NULL;
12543960f15SRobert Watson 
1267a832d43SChris D. Faulhaber 	/* Second entry: ACL_GROUP_OBJ */
1277a832d43SChris D. Faulhaber 	if (acl_create_entry(&acl, &entry) == -1)
1287a832d43SChris D. Faulhaber 		return NULL;
1297a832d43SChris D. Faulhaber 	if (acl_set_tag_type(entry, ACL_GROUP_OBJ) == -1)
1307a832d43SChris D. Faulhaber 		return NULL;
1317a832d43SChris D. Faulhaber 
1327a832d43SChris D. Faulhaber 	if (acl_get_permset(entry, &perms) == -1)
1337a832d43SChris D. Faulhaber 		return NULL;
1347a832d43SChris D. Faulhaber 	if (acl_clear_perms(perms) == -1)
1357a832d43SChris D. Faulhaber 		return NULL;
1367a832d43SChris D. Faulhaber 
1377a832d43SChris D. Faulhaber 	/* calculate group mode */
13843960f15SRobert Watson 	if (sb.st_mode & S_IRGRP)
1397a832d43SChris D. Faulhaber 		if (acl_add_perm(perms, ACL_READ) == -1)
1407a832d43SChris D. Faulhaber 			return NULL;
14143960f15SRobert Watson 	if (sb.st_mode & S_IWGRP)
1427a832d43SChris D. Faulhaber 		if (acl_add_perm(perms, ACL_WRITE) == -1)
1437a832d43SChris D. Faulhaber 			return NULL;
14443960f15SRobert Watson 	if (sb.st_mode & S_IXGRP)
1457a832d43SChris D. Faulhaber 		if (acl_add_perm(perms, ACL_EXECUTE) == -1)
1467a832d43SChris D. Faulhaber 			return NULL;
1477a832d43SChris D. Faulhaber 	if (acl_set_permset(entry, perms) == -1)
1487a832d43SChris D. Faulhaber 		return NULL;
14943960f15SRobert Watson 
1507a832d43SChris D. Faulhaber 	/* Third entry: ACL_OTHER */
1517a832d43SChris D. Faulhaber 	if (acl_create_entry(&acl, &entry) == -1)
1527a832d43SChris D. Faulhaber 		return NULL;
1537a832d43SChris D. Faulhaber 	if (acl_set_tag_type(entry, ACL_OTHER) == -1)
1547a832d43SChris D. Faulhaber 		return NULL;
1557a832d43SChris D. Faulhaber 
1567a832d43SChris D. Faulhaber 	if (acl_get_permset(entry, &perms) == -1)
1577a832d43SChris D. Faulhaber 		return NULL;
1587a832d43SChris D. Faulhaber 	if (acl_clear_perms(perms) == -1)
1597a832d43SChris D. Faulhaber 		return NULL;
1607a832d43SChris D. Faulhaber 
1617a832d43SChris D. Faulhaber 	/* calculate other mode */
16243960f15SRobert Watson 	if (sb.st_mode & S_IROTH)
1637a832d43SChris D. Faulhaber 		if (acl_add_perm(perms, ACL_READ) == -1)
1647a832d43SChris D. Faulhaber 			return NULL;
16543960f15SRobert Watson 	if (sb.st_mode & S_IWOTH)
1667a832d43SChris D. Faulhaber 		if (acl_add_perm(perms, ACL_WRITE) == -1)
1677a832d43SChris D. Faulhaber 			return NULL;
16843960f15SRobert Watson 	if (sb.st_mode & S_IXOTH)
1697a832d43SChris D. Faulhaber 		if (acl_add_perm(perms, ACL_EXECUTE) == -1)
1707a832d43SChris D. Faulhaber 			return NULL;
1717a832d43SChris D. Faulhaber 	if (acl_set_permset(entry, perms) == -1)
1727a832d43SChris D. Faulhaber 		return NULL;
17343960f15SRobert Watson 
17443960f15SRobert Watson 	return(acl);
17543960f15SRobert Watson }
17643960f15SRobert Watson 
17743960f15SRobert Watson static int
178f9a86e37SRobert Watson print_acl(char *path, acl_type_t type, int hflag, int qflag)
17943960f15SRobert Watson {
18043960f15SRobert Watson 	struct stat	sb;
18143960f15SRobert Watson 	acl_t	acl;
18243960f15SRobert Watson 	char	*acl_text;
18343960f15SRobert Watson 	int	error;
18443960f15SRobert Watson 
1858051fddeSRobert Watson 	if (hflag)
1868051fddeSRobert Watson 		error = lstat(path, &sb);
1878051fddeSRobert Watson 	else
18843960f15SRobert Watson 		error = stat(path, &sb);
18943960f15SRobert Watson 	if (error == -1) {
1904e65ab95STim J. Robbins 		warn("%s", path);
19143960f15SRobert Watson 		return(-1);
19243960f15SRobert Watson 	}
19343960f15SRobert Watson 
19443960f15SRobert Watson 	if (more_than_one)
19543960f15SRobert Watson 		printf("\n");
19643960f15SRobert Watson 	else
19743960f15SRobert Watson 		more_than_one++;
19843960f15SRobert Watson 
199f9a86e37SRobert Watson 	if (!qflag)
200c5771451SKevin Lo 		printf("# file: %s\n# owner: %s\n# group: %s\n", path,
201c5771451SKevin Lo 		    getuname(sb.st_uid), getgname(sb.st_gid));
20243960f15SRobert Watson 
2038051fddeSRobert Watson 	if (hflag)
2048051fddeSRobert Watson 		acl = acl_get_link_np(path, type);
2058051fddeSRobert Watson 	else
20643960f15SRobert Watson 		acl = acl_get_file(path, type);
20743960f15SRobert Watson 	if (!acl) {
20843960f15SRobert Watson 		if (errno != EOPNOTSUPP) {
20943960f15SRobert Watson 			warn("%s", path);
21043960f15SRobert Watson 			return(-1);
21143960f15SRobert Watson 		}
21243960f15SRobert Watson 		errno = 0;
21343960f15SRobert Watson 		if (type != ACL_TYPE_ACCESS)
21443960f15SRobert Watson 			return(0);
21543960f15SRobert Watson 		acl = acl_from_stat(sb);
21643960f15SRobert Watson 		if (!acl) {
2174e65ab95STim J. Robbins 			warn("acl_from_stat()");
21843960f15SRobert Watson 			return(-1);
21943960f15SRobert Watson 		}
22043960f15SRobert Watson 	}
22143960f15SRobert Watson 
22243960f15SRobert Watson 	acl_text = acl_to_text(acl, 0);
22343960f15SRobert Watson 	if (!acl_text) {
2244e65ab95STim J. Robbins 		warn("%s", path);
22543960f15SRobert Watson 		return(-1);
22643960f15SRobert Watson 	}
22743960f15SRobert Watson 
22843960f15SRobert Watson 	printf("%s", acl_text);
22943960f15SRobert Watson 
230fab912dfSMark Murray 	(void)acl_free(acl);
231fab912dfSMark Murray 	(void)acl_free(acl_text);
23243960f15SRobert Watson 
23343960f15SRobert Watson 	return(0);
23443960f15SRobert Watson }
23543960f15SRobert Watson 
23643960f15SRobert Watson static int
237f9a86e37SRobert Watson print_acl_from_stdin(acl_type_t type, int hflag, int qflag)
23843960f15SRobert Watson {
2394e65ab95STim J. Robbins 	char	*p, pathname[PATH_MAX];
24043960f15SRobert Watson 	int	carried_error = 0;
24143960f15SRobert Watson 
24228bf3202SKris Kennaway 	while (fgets(pathname, (int)sizeof(pathname), stdin)) {
2434e65ab95STim J. Robbins 		if ((p = strchr(pathname, '\n')) != NULL)
2444e65ab95STim J. Robbins 			*p = '\0';
245f9a86e37SRobert Watson 		if (print_acl(pathname, type, hflag, qflag) == -1) {
24643960f15SRobert Watson 			carried_error = -1;
24743960f15SRobert Watson 		}
24843960f15SRobert Watson 	}
24943960f15SRobert Watson 
25043960f15SRobert Watson 	return(carried_error);
25143960f15SRobert Watson }
25243960f15SRobert Watson 
25343960f15SRobert Watson int
25443960f15SRobert Watson main(int argc, char *argv[])
25543960f15SRobert Watson {
25643960f15SRobert Watson 	acl_type_t	type = ACL_TYPE_ACCESS;
25743960f15SRobert Watson 	int	carried_error = 0;
25843960f15SRobert Watson 	int	ch, error, i;
259f9a86e37SRobert Watson 	int	hflag, qflag;
26043960f15SRobert Watson 
2618051fddeSRobert Watson 	hflag = 0;
262f9a86e37SRobert Watson 	qflag = 0;
263f9a86e37SRobert Watson 	while ((ch = getopt(argc, argv, "dhq")) != -1)
26443960f15SRobert Watson 		switch(ch) {
26543960f15SRobert Watson 		case 'd':
26643960f15SRobert Watson 			type = ACL_TYPE_DEFAULT;
26743960f15SRobert Watson 			break;
2688051fddeSRobert Watson 		case 'h':
2698051fddeSRobert Watson 			hflag = 1;
2708051fddeSRobert Watson 			break;
271f9a86e37SRobert Watson 		case 'q':
272f9a86e37SRobert Watson 			qflag = 1;
273f9a86e37SRobert Watson 			break;
27443960f15SRobert Watson 		default:
27543960f15SRobert Watson 			usage();
27643960f15SRobert Watson 			return(-1);
27743960f15SRobert Watson 		}
27843960f15SRobert Watson 	argc -= optind;
27943960f15SRobert Watson 	argv += optind;
28043960f15SRobert Watson 
28143960f15SRobert Watson 	if (argc == 0) {
282f9a86e37SRobert Watson 		error = print_acl_from_stdin(type, hflag, qflag);
2834e65ab95STim J. Robbins 		return(error ? 1 : 0);
28443960f15SRobert Watson 	}
28543960f15SRobert Watson 
28643960f15SRobert Watson 	for (i = 0; i < argc; i++) {
28743960f15SRobert Watson 		if (!strcmp(argv[i], "-")) {
288f9a86e37SRobert Watson 			error = print_acl_from_stdin(type, hflag, qflag);
28943960f15SRobert Watson 			if (error == -1)
29043960f15SRobert Watson 				carried_error = -1;
29143960f15SRobert Watson 		} else {
292f9a86e37SRobert Watson 			error = print_acl(argv[i], type, hflag, qflag);
29343960f15SRobert Watson 			if (error == -1)
29443960f15SRobert Watson 				carried_error = -1;
29543960f15SRobert Watson 		}
29643960f15SRobert Watson 	}
29743960f15SRobert Watson 
2984e65ab95STim J. Robbins 	return(carried_error ? 1 : 0);
29943960f15SRobert Watson }
300