1*8269e767SBrooks Davis.\" Copyright (c) 1983, 1991, 1993, 1994 2*8269e767SBrooks Davis.\" The Regents of the University of California. All rights reserved. 3*8269e767SBrooks Davis.\" 4*8269e767SBrooks Davis.\" Redistribution and use in source and binary forms, with or without 5*8269e767SBrooks Davis.\" modification, are permitted provided that the following conditions 6*8269e767SBrooks Davis.\" are met: 7*8269e767SBrooks Davis.\" 1. Redistributions of source code must retain the above copyright 8*8269e767SBrooks Davis.\" notice, this list of conditions and the following disclaimer. 9*8269e767SBrooks Davis.\" 2. Redistributions in binary form must reproduce the above copyright 10*8269e767SBrooks Davis.\" notice, this list of conditions and the following disclaimer in the 11*8269e767SBrooks Davis.\" documentation and/or other materials provided with the distribution. 12*8269e767SBrooks Davis.\" 3. Neither the name of the University nor the names of its contributors 13*8269e767SBrooks Davis.\" may be used to endorse or promote products derived from this software 14*8269e767SBrooks Davis.\" without specific prior written permission. 15*8269e767SBrooks Davis.\" 16*8269e767SBrooks Davis.\" THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 17*8269e767SBrooks Davis.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 18*8269e767SBrooks Davis.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 19*8269e767SBrooks Davis.\" ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 20*8269e767SBrooks Davis.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 21*8269e767SBrooks Davis.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 22*8269e767SBrooks Davis.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 23*8269e767SBrooks Davis.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 24*8269e767SBrooks Davis.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 25*8269e767SBrooks Davis.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 26*8269e767SBrooks Davis.\" SUCH DAMAGE. 27*8269e767SBrooks Davis.\" 28*8269e767SBrooks Davis.Dd January 19, 2018 29*8269e767SBrooks Davis.Dt SETGROUPS 2 30*8269e767SBrooks Davis.Os 31*8269e767SBrooks Davis.Sh NAME 32*8269e767SBrooks Davis.Nm setgroups 33*8269e767SBrooks Davis.Nd set group access list 34*8269e767SBrooks Davis.Sh LIBRARY 35*8269e767SBrooks Davis.Lb libc 36*8269e767SBrooks Davis.Sh SYNOPSIS 37*8269e767SBrooks Davis.In sys/param.h 38*8269e767SBrooks Davis.In unistd.h 39*8269e767SBrooks Davis.Ft int 40*8269e767SBrooks Davis.Fn setgroups "int ngroups" "const gid_t *gidset" 41*8269e767SBrooks Davis.Sh DESCRIPTION 42*8269e767SBrooks DavisThe 43*8269e767SBrooks Davis.Fn setgroups 44*8269e767SBrooks Davissystem call 45*8269e767SBrooks Davissets the group access list of the current user process 46*8269e767SBrooks Davisaccording to the array 47*8269e767SBrooks Davis.Fa gidset . 48*8269e767SBrooks DavisThe 49*8269e767SBrooks Davis.Fa ngroups 50*8269e767SBrooks Davisargument 51*8269e767SBrooks Davisindicates the number of entries in the array and must be no 52*8269e767SBrooks Davismore than 53*8269e767SBrooks Davis.Dv {NGROUPS_MAX}+1 . 54*8269e767SBrooks Davis.Pp 55*8269e767SBrooks DavisOnly the super-user may set a new group list. 56*8269e767SBrooks Davis.Pp 57*8269e767SBrooks DavisThe first entry of the group array 58*8269e767SBrooks Davis.Pq Va gidset[0] 59*8269e767SBrooks Davisis used as the effective group-ID for the process. 60*8269e767SBrooks DavisThis entry is over-written when a setgid program is run. 61*8269e767SBrooks DavisTo avoid losing access to the privileges of the 62*8269e767SBrooks Davis.Va gidset[0] 63*8269e767SBrooks Davisentry, it should be duplicated later in the group array. 64*8269e767SBrooks DavisBy convention, 65*8269e767SBrooks Davisthis happens because the group value indicated 66*8269e767SBrooks Davisin the password file also appears in 67*8269e767SBrooks Davis.Pa /etc/group . 68*8269e767SBrooks DavisThe group value in the password file is placed in 69*8269e767SBrooks Davis.Va gidset[0] 70*8269e767SBrooks Davisand that value then gets added a second time when the 71*8269e767SBrooks Davis.Pa /etc/group 72*8269e767SBrooks Davisfile is scanned to create the group set. 73*8269e767SBrooks Davis.Sh RETURN VALUES 74*8269e767SBrooks Davis.Rv -std setgroups 75*8269e767SBrooks Davis.Sh ERRORS 76*8269e767SBrooks DavisThe 77*8269e767SBrooks Davis.Fn setgroups 78*8269e767SBrooks Davissystem call will fail if: 79*8269e767SBrooks Davis.Bl -tag -width Er 80*8269e767SBrooks Davis.It Bq Er EPERM 81*8269e767SBrooks DavisThe caller is not the super-user. 82*8269e767SBrooks Davis.It Bq Er EINVAL 83*8269e767SBrooks DavisThe number specified in the 84*8269e767SBrooks Davis.Fa ngroups 85*8269e767SBrooks Davisargument is larger than the 86*8269e767SBrooks Davis.Dv {NGROUPS_MAX}+1 87*8269e767SBrooks Davislimit. 88*8269e767SBrooks Davis.It Bq Er EFAULT 89*8269e767SBrooks DavisThe address specified for 90*8269e767SBrooks Davis.Fa gidset 91*8269e767SBrooks Davisis outside the process 92*8269e767SBrooks Davisaddress space. 93*8269e767SBrooks Davis.El 94*8269e767SBrooks Davis.Sh SEE ALSO 95*8269e767SBrooks Davis.Xr getgroups 2 , 96*8269e767SBrooks Davis.Xr initgroups 3 97*8269e767SBrooks Davis.Sh HISTORY 98*8269e767SBrooks DavisThe 99*8269e767SBrooks Davis.Fn setgroups 100*8269e767SBrooks Davissystem call appeared in 101*8269e767SBrooks Davis.Bx 4.2 . 102