From: Matt Helsley <matthltc-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
To: Daniel Lezcano <daniel.lezcano-GANU6spQydw@public.gmane.org>
Cc: Containers <containers-qjLDD68F18O7TbgM5vRIOg@public.gmane.org>
Subject: [PATCH] liblxc: Add username and uid lookup/check.
Date: Wed, 25 Feb 2009 20:21:57 -0800 [thread overview]
Message-ID: <20090226042157.GC11052@us.ibm.com> (raw)
Add the ability to lookup usernames and check uids. Bails out early if the given
uid/name does not exist and avoids using atoi() (which is bad because we can't
tell if it parsed an int or a pumpkin).
Signed-off-by: Matt Helsley <matthltc-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
---
Also gets rid of a bogus "maybe used uninitialized" warning.
src/lxc/lxc_unshare.c | 32 ++++++++++++++++++++++++++++++--
1 file changed, 30 insertions(+), 2 deletions(-)
Index: lxc/src/lxc/lxc_unshare.c
===================================================================
--- lxc.orig/src/lxc/lxc_unshare.c
+++ lxc/src/lxc/lxc_unshare.c
@@ -30,6 +30,7 @@
#include <errno.h>
#include <sys/types.h>
#include <sys/wait.h>
+#include <pwd.h>
#include "lxc_namespace.h"
@@ -48,12 +49,37 @@ void usage(char *cmd)
_exit(1);
}
+static uid_t lookup_user(const char *optarg)
+{
+ char name[sysconf(_SC_LOGIN_NAME_MAX)];
+ uid_t uid = -1;
+
+ if (!optarg || (optarg[0] == '\0'))
+ return uid;
+ if (sscanf(optarg, "%u", &uid) < 1) {
+ struct passwd pwent; /* not a uid -- perhaps a username */
+ struct passwd *pent;
+
+ if (sscanf(optarg, "%s", name) < 1)
+ return uid;
+ if (getpwnam_r(name, &pwent, NULL, 0, &pent) || !pent)
+ return uid;
+ uid = pent->pw_uid;
+ } else {
+ if (getpwuid_r(uid, NULL, NULL, 0, NULL)) {
+ uid = -1;
+ return uid;
+ }
+ }
+ return uid;
+}
+
int main(int argc, char *argv[])
{
int opt, nbargs = 0, status = 1, hastofork = 0;
char **args;
long flags = 0;
- uid_t uid = 0;
+ uid_t uid = -1; /* valid only if (flags & CLONE_NEWUSER) */
pid_t pid;
while ((opt = getopt(argc, argv, "fmphiu:n")) != -1) {
@@ -71,8 +97,10 @@ int main(int argc, char *argv[])
flags |= CLONE_NEWIPC;
break;
case 'u':
+ uid = lookup_user(optarg);
+ if (uid == -1)
+ break;
flags |= CLONE_NEWUSER;
- uid = atoi(optarg);
break;
case 'n':
flags |= CLONE_NEWNET;
next reply other threads:[~2009-02-26 4:21 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-02-26 4:21 Matt Helsley [this message]
[not found] ` <20090226042157.GC11052-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-03-08 16:34 ` [PATCH] liblxc: Add username and uid lookup/check Daniel Lezcano
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20090226042157.GC11052@us.ibm.com \
--to=matthltc-r/jw6+rmf7hqt0dzr+alfa@public.gmane.org \
--cc=containers-qjLDD68F18O7TbgM5vRIOg@public.gmane.org \
--cc=daniel.lezcano-GANU6spQydw@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox