xref: /freebsd/lib/libsys/setgroups.2 (revision 8269e7673cf033aba67dab8264fe719920c70f87)
1*8269e767SBrooks Davis.\" Copyright (c) 1983, 1991, 1993, 1994
2*8269e767SBrooks Davis.\"	The Regents of the University of California.  All rights reserved.
3*8269e767SBrooks Davis.\"
4*8269e767SBrooks Davis.\" Redistribution and use in source and binary forms, with or without
5*8269e767SBrooks Davis.\" modification, are permitted provided that the following conditions
6*8269e767SBrooks Davis.\" are met:
7*8269e767SBrooks Davis.\" 1. Redistributions of source code must retain the above copyright
8*8269e767SBrooks Davis.\"    notice, this list of conditions and the following disclaimer.
9*8269e767SBrooks Davis.\" 2. Redistributions in binary form must reproduce the above copyright
10*8269e767SBrooks Davis.\"    notice, this list of conditions and the following disclaimer in the
11*8269e767SBrooks Davis.\"    documentation and/or other materials provided with the distribution.
12*8269e767SBrooks Davis.\" 3. Neither the name of the University nor the names of its contributors
13*8269e767SBrooks Davis.\"    may be used to endorse or promote products derived from this software
14*8269e767SBrooks Davis.\"    without specific prior written permission.
15*8269e767SBrooks Davis.\"
16*8269e767SBrooks Davis.\" THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
17*8269e767SBrooks Davis.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
18*8269e767SBrooks Davis.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
19*8269e767SBrooks Davis.\" ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
20*8269e767SBrooks Davis.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
21*8269e767SBrooks Davis.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
22*8269e767SBrooks Davis.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
23*8269e767SBrooks Davis.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
24*8269e767SBrooks Davis.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
25*8269e767SBrooks Davis.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
26*8269e767SBrooks Davis.\" SUCH DAMAGE.
27*8269e767SBrooks Davis.\"
28*8269e767SBrooks Davis.Dd January 19, 2018
29*8269e767SBrooks Davis.Dt SETGROUPS 2
30*8269e767SBrooks Davis.Os
31*8269e767SBrooks Davis.Sh NAME
32*8269e767SBrooks Davis.Nm setgroups
33*8269e767SBrooks Davis.Nd set group access list
34*8269e767SBrooks Davis.Sh LIBRARY
35*8269e767SBrooks Davis.Lb libc
36*8269e767SBrooks Davis.Sh SYNOPSIS
37*8269e767SBrooks Davis.In sys/param.h
38*8269e767SBrooks Davis.In unistd.h
39*8269e767SBrooks Davis.Ft int
40*8269e767SBrooks Davis.Fn setgroups "int ngroups" "const gid_t *gidset"
41*8269e767SBrooks Davis.Sh DESCRIPTION
42*8269e767SBrooks DavisThe
43*8269e767SBrooks Davis.Fn setgroups
44*8269e767SBrooks Davissystem call
45*8269e767SBrooks Davissets the group access list of the current user process
46*8269e767SBrooks Davisaccording to the array
47*8269e767SBrooks Davis.Fa gidset .
48*8269e767SBrooks DavisThe
49*8269e767SBrooks Davis.Fa ngroups
50*8269e767SBrooks Davisargument
51*8269e767SBrooks Davisindicates the number of entries in the array and must be no
52*8269e767SBrooks Davismore than
53*8269e767SBrooks Davis.Dv {NGROUPS_MAX}+1 .
54*8269e767SBrooks Davis.Pp
55*8269e767SBrooks DavisOnly the super-user may set a new group list.
56*8269e767SBrooks Davis.Pp
57*8269e767SBrooks DavisThe first entry of the group array
58*8269e767SBrooks Davis.Pq Va gidset[0]
59*8269e767SBrooks Davisis used as the effective group-ID for the process.
60*8269e767SBrooks DavisThis entry is over-written when a setgid program is run.
61*8269e767SBrooks DavisTo avoid losing access to the privileges of the
62*8269e767SBrooks Davis.Va gidset[0]
63*8269e767SBrooks Davisentry, it should be duplicated later in the group array.
64*8269e767SBrooks DavisBy convention,
65*8269e767SBrooks Davisthis happens because the group value indicated
66*8269e767SBrooks Davisin the password file also appears in
67*8269e767SBrooks Davis.Pa /etc/group .
68*8269e767SBrooks DavisThe group value in the password file is placed in
69*8269e767SBrooks Davis.Va gidset[0]
70*8269e767SBrooks Davisand that value then gets added a second time when the
71*8269e767SBrooks Davis.Pa /etc/group
72*8269e767SBrooks Davisfile is scanned to create the group set.
73*8269e767SBrooks Davis.Sh RETURN VALUES
74*8269e767SBrooks Davis.Rv -std setgroups
75*8269e767SBrooks Davis.Sh ERRORS
76*8269e767SBrooks DavisThe
77*8269e767SBrooks Davis.Fn setgroups
78*8269e767SBrooks Davissystem call will fail if:
79*8269e767SBrooks Davis.Bl -tag -width Er
80*8269e767SBrooks Davis.It Bq Er EPERM
81*8269e767SBrooks DavisThe caller is not the super-user.
82*8269e767SBrooks Davis.It Bq Er EINVAL
83*8269e767SBrooks DavisThe number specified in the
84*8269e767SBrooks Davis.Fa ngroups
85*8269e767SBrooks Davisargument is larger than the
86*8269e767SBrooks Davis.Dv {NGROUPS_MAX}+1
87*8269e767SBrooks Davislimit.
88*8269e767SBrooks Davis.It Bq Er EFAULT
89*8269e767SBrooks DavisThe address specified for
90*8269e767SBrooks Davis.Fa gidset
91*8269e767SBrooks Davisis outside the process
92*8269e767SBrooks Davisaddress space.
93*8269e767SBrooks Davis.El
94*8269e767SBrooks Davis.Sh SEE ALSO
95*8269e767SBrooks Davis.Xr getgroups 2 ,
96*8269e767SBrooks Davis.Xr initgroups 3
97*8269e767SBrooks Davis.Sh HISTORY
98*8269e767SBrooks DavisThe
99*8269e767SBrooks Davis.Fn setgroups
100*8269e767SBrooks Davissystem call appeared in
101*8269e767SBrooks Davis.Bx 4.2 .
102