17c478bd9Sstevel@tonic-gate /*
27c478bd9Sstevel@tonic-gate * CDDL HEADER START
37c478bd9Sstevel@tonic-gate *
47c478bd9Sstevel@tonic-gate * The contents of this file are subject to the terms of the
5f48205beScasper * Common Development and Distribution License (the "License").
6f48205beScasper * You may not use this file except in compliance with the License.
77c478bd9Sstevel@tonic-gate *
87c478bd9Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
97c478bd9Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing.
107c478bd9Sstevel@tonic-gate * See the License for the specific language governing permissions
117c478bd9Sstevel@tonic-gate * and limitations under the License.
127c478bd9Sstevel@tonic-gate *
137c478bd9Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each
147c478bd9Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
157c478bd9Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the
167c478bd9Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying
177c478bd9Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner]
187c478bd9Sstevel@tonic-gate *
197c478bd9Sstevel@tonic-gate * CDDL HEADER END
207c478bd9Sstevel@tonic-gate */
21*7257d1b4Sraf
227c478bd9Sstevel@tonic-gate /*
23*7257d1b4Sraf * Copyright 2008 Sun Microsystems, Inc. All rights reserved.
247c478bd9Sstevel@tonic-gate * Use is subject to license terms.
257c478bd9Sstevel@tonic-gate */
267c478bd9Sstevel@tonic-gate
277c478bd9Sstevel@tonic-gate /* Copyright (c) 1988 AT&T */
287c478bd9Sstevel@tonic-gate /* All Rights Reserved */
297c478bd9Sstevel@tonic-gate
30*7257d1b4Sraf #pragma ident "%Z%%M% %I% %E% SMI"
317c478bd9Sstevel@tonic-gate
32*7257d1b4Sraf #pragma weak _initgroups = initgroups
337c478bd9Sstevel@tonic-gate
34*7257d1b4Sraf #include "lint.h"
357c478bd9Sstevel@tonic-gate #include <stdlib.h>
367c478bd9Sstevel@tonic-gate #include <errno.h>
377c478bd9Sstevel@tonic-gate #include <grp.h>
387c478bd9Sstevel@tonic-gate #include <sys/types.h>
39f48205beScasper #include <sys/param.h>
407c478bd9Sstevel@tonic-gate #include <unistd.h>
417c478bd9Sstevel@tonic-gate
427c478bd9Sstevel@tonic-gate /* Private interface to the groups code in getgrnam.c */
437c478bd9Sstevel@tonic-gate extern int _getgroupsbymember(const char *, gid_t[], int, int);
447c478bd9Sstevel@tonic-gate
457c478bd9Sstevel@tonic-gate int
initgroups(const char * uname,gid_t agroup)467c478bd9Sstevel@tonic-gate initgroups(const char *uname, gid_t agroup)
477c478bd9Sstevel@tonic-gate {
487c478bd9Sstevel@tonic-gate gid_t *groups;
497c478bd9Sstevel@tonic-gate long ngroups_max;
507c478bd9Sstevel@tonic-gate int ngroups;
517c478bd9Sstevel@tonic-gate int errsave, retsave;
527c478bd9Sstevel@tonic-gate
537c478bd9Sstevel@tonic-gate if ((ngroups_max = sysconf(_SC_NGROUPS_MAX)) < 0) {
547c478bd9Sstevel@tonic-gate /* ==== Hope sysconf() set errno to something sensible */
557c478bd9Sstevel@tonic-gate return (-1);
567c478bd9Sstevel@tonic-gate }
577c478bd9Sstevel@tonic-gate /*
587c478bd9Sstevel@tonic-gate * ngroups_max is the maximum number of supplemental groups per
597c478bd9Sstevel@tonic-gate * process. if no supplemental groups are allowed, we're done.
607c478bd9Sstevel@tonic-gate */
617c478bd9Sstevel@tonic-gate if (ngroups_max == 0)
627c478bd9Sstevel@tonic-gate return (0);
637c478bd9Sstevel@tonic-gate
647c478bd9Sstevel@tonic-gate if ((groups = (gid_t *)calloc(ngroups_max, sizeof (gid_t))) == 0) {
657c478bd9Sstevel@tonic-gate errno = ENOMEM;
667c478bd9Sstevel@tonic-gate return (-1);
677c478bd9Sstevel@tonic-gate }
687c478bd9Sstevel@tonic-gate groups[0] = agroup;
697c478bd9Sstevel@tonic-gate
707c478bd9Sstevel@tonic-gate ngroups = _getgroupsbymember(uname, groups, (int)ngroups_max,
71f48205beScasper (agroup <= MAXUID) ? 1 : 0);
727c478bd9Sstevel@tonic-gate if (ngroups < 0) {
737c478bd9Sstevel@tonic-gate /* XXX -- man page does not define a value for errno in */
747c478bd9Sstevel@tonic-gate /* this case. Should be looked into sometime. */
757c478bd9Sstevel@tonic-gate free(groups);
767c478bd9Sstevel@tonic-gate return (-1);
777c478bd9Sstevel@tonic-gate }
787c478bd9Sstevel@tonic-gate
797c478bd9Sstevel@tonic-gate retsave = setgroups(ngroups, groups);
807c478bd9Sstevel@tonic-gate errsave = errno;
817c478bd9Sstevel@tonic-gate
827c478bd9Sstevel@tonic-gate free(groups);
837c478bd9Sstevel@tonic-gate
847c478bd9Sstevel@tonic-gate errno = errsave;
857c478bd9Sstevel@tonic-gate return (retsave);
867c478bd9Sstevel@tonic-gate }
87