The login applet should always be setuid root
[oweals/busybox.git] / coreutils / id.c
index e91ac758570e7b3e4ef9ef042611507bb65d068e..db8afc58575a3493e7199786aee7878715627957 100644 (file)
  *
  */
 
+/* BB_AUDIT SUSv3 _NOT_ compliant -- option -G is not currently supported. */
+
 #include "busybox.h"
 #include <stdio.h>
 #include <unistd.h>
 #include <getopt.h>
 #include <string.h>
 #include <sys/types.h>
+#ifdef CONFIG_SELINUX
+#include <proc_secure.h>
+#include <flask_util.h>
+#endif
+
+#define JUST_USER         1
+#define JUST_GROUP        2
+#define PRINT_REAL        4
+#define NAME_NOT_NUMBER   8
 
 extern int id_main(int argc, char **argv)
 {
-       int no_user = 0, no_group = 0, print_real = 0;
-       int name_not_number = 0;
-       char user[9], group[9];
-       long gid;
+       char user[32], group[32];
        long pwnam, grnam;
-       int opt;
-       
-       gid = 0;
+       int uid, gid;
+       int flags;
+#ifdef CONFIG_SELINUX
+       int is_flask_enabled_flag = is_flask_enabled();
+#endif
 
-       while ((opt = getopt(argc, argv, "ugrn")) > 0) {
-               switch (opt) {
-                       case 'u':
-                               no_group++;
-                               break;
-                       case 'g':
-                               no_user++;
-                               break;
-                       case 'r':
-                               print_real++;
-                               break;
-                       case 'n':
-                               name_not_number++;
-                               break;
-                       default:
-                               usage(id_usage);
-               }
-       }
+       flags = bb_getopt_ulflags(argc, argv, "ugrn");
 
-       if (no_user && no_group) usage(id_usage);
+       if (((flags & (JUST_USER | JUST_GROUP)) == (JUST_USER | JUST_GROUP))
+               || (argc > optind + 1)
+       ) {
+               bb_show_usage();
+       }
 
        if (argv[optind] == NULL) {
-               if (print_real) {
-                       my_getpwuid(user, getuid());
-                       my_getgrgid(group, getgid());
+               if (flags & PRINT_REAL) {
+                       uid = getuid();
+                       gid = getgid();
                } else {
-                       my_getpwuid(user, geteuid());
-                       my_getgrgid(group, getegid());
+                       uid = geteuid();
+                       gid = getegid();
                }
+               my_getpwuid(user, uid, sizeof(user));
        } else {
-               strncpy(user, argv[optind], 8);
-               user[8] = '\0';
+               safe_strncpy(user, argv[optind], sizeof(user));
            gid = my_getpwnamegid(user);
-               my_getgrgid(group, gid);
        }
+       my_getgrgid(group, gid, sizeof(group));
 
        pwnam=my_getpwnam(user);
        grnam=my_getgrnam(group);
-       if (gid == -1 || pwnam==-1 || grnam==-1) {
-               error_msg_and_die("%s: No such user\n", user);
-       }
 
-       if (no_group) {
-               if(name_not_number && user)
-                       printf("%s\n",user);
-               else
-                       printf("%ld\n", pwnam);
-       } else if (no_user) {
-               if(name_not_number && group)
-                       printf("%s\n", group);
-               else
+       if (flags & (JUST_GROUP | JUST_USER)) {
+               char *s = group;
+               if (flags & JUST_USER) {
+                       s = user;
+                       grnam = pwnam;
+               }
+               if (flags & NAME_NOT_NUMBER) {
+                       puts(s);
+               } else {
                        printf("%ld\n", grnam);
+               }
        } else {
+#ifdef CONFIG_SELINUX
+               printf("uid=%ld(%s) gid=%ld(%s)", pwnam, user, grnam, group);
+               if(is_flask_enabled_flag)
+               {
+                       security_id_t mysid = getsecsid();
+                       char context[80];
+                       int len = sizeof(context);
+                       context[0] = '\0';
+                       if(security_sid_to_context(mysid, context, &len))
+                               strcpy(context, "unknown");
+                       printf(" context=%s\n", context);
+               }
+               else
+                       printf("\n");
+#else
                printf("uid=%ld(%s) gid=%ld(%s)\n", pwnam, user, grnam, group);
-       }
-       return(0);
-}
+#endif
 
+       }
 
-/* END CODE */
+       bb_fflush_stdout_and_exit(0);
+}