Linux Container Development
 help / color / mirror / Atom feed
From: Matt Helsley <matthltc-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
To: Daniel Lezcano <daniel.lezcano-GANU6spQydw@public.gmane.org>
Cc: Containers <containers-qjLDD68F18O7TbgM5vRIOg@public.gmane.org>
Subject: [PATCH] liblxc: Add username and uid lookup/check.
Date: Wed, 25 Feb 2009 20:21:57 -0800	[thread overview]
Message-ID: <20090226042157.GC11052@us.ibm.com> (raw)

Add the ability to lookup usernames and check uids. Bails out early if the given
uid/name does not exist and avoids using atoi() (which is bad because we can't
tell if it parsed an int or a pumpkin).

Signed-off-by: Matt Helsley <matthltc-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
---
Also gets rid of a bogus "maybe used uninitialized" warning.

 src/lxc/lxc_unshare.c |   32 ++++++++++++++++++++++++++++++--
 1 file changed, 30 insertions(+), 2 deletions(-)

Index: lxc/src/lxc/lxc_unshare.c
===================================================================
--- lxc.orig/src/lxc/lxc_unshare.c
+++ lxc/src/lxc/lxc_unshare.c
@@ -30,6 +30,7 @@
 #include <errno.h>
 #include <sys/types.h>
 #include <sys/wait.h>
+#include <pwd.h>
 
 #include "lxc_namespace.h"
 
@@ -48,12 +49,37 @@ void usage(char *cmd)
 	_exit(1);
 }
 
+static uid_t lookup_user(const char *optarg)
+{
+	char name[sysconf(_SC_LOGIN_NAME_MAX)];
+	uid_t uid = -1;
+
+	if (!optarg || (optarg[0] == '\0'))
+		return uid;
+	if (sscanf(optarg, "%u", &uid) < 1) {
+		struct passwd pwent; /* not a uid -- perhaps a username */
+		struct passwd *pent;
+
+		if (sscanf(optarg, "%s", name) < 1)
+			return uid;
+		if (getpwnam_r(name, &pwent, NULL, 0, &pent) || !pent)
+			return uid;
+		uid = pent->pw_uid;
+	} else {
+		if (getpwuid_r(uid, NULL, NULL, 0, NULL)) {
+			uid = -1;
+			return uid;
+		}
+	}
+	return uid;
+}
+
 int main(int argc, char *argv[])
 {
 	int opt, nbargs = 0, status = 1, hastofork = 0;
 	char **args;
 	long flags = 0;
-	uid_t uid = 0;
+ 	uid_t uid = -1; /* valid only if (flags & CLONE_NEWUSER) */
 	pid_t pid;
 
 	while ((opt = getopt(argc, argv, "fmphiu:n")) != -1) {
@@ -71,8 +97,10 @@ int main(int argc, char *argv[])
 			flags |= CLONE_NEWIPC;
 			break;
 		case 'u':
+			uid = lookup_user(optarg);
+			if (uid == -1)
+				break;
 			flags |= CLONE_NEWUSER;
-			uid = atoi(optarg);
 			break;
 		case 'n':
 			flags |= CLONE_NEWNET;

             reply	other threads:[~2009-02-26  4:21 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-02-26  4:21 Matt Helsley [this message]
     [not found] ` <20090226042157.GC11052-r/Jw6+rmf7HQT0dZR+AlfA@public.gmane.org>
2009-03-08 16:34   ` [PATCH] liblxc: Add username and uid lookup/check Daniel Lezcano

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20090226042157.GC11052@us.ibm.com \
    --to=matthltc-r/jw6+rmf7hqt0dzr+alfa@public.gmane.org \
    --cc=containers-qjLDD68F18O7TbgM5vRIOg@public.gmane.org \
    --cc=daniel.lezcano-GANU6spQydw@public.gmane.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox