Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 21 Dec 2023 13:43:38 GMT
From:      Olivier Certner <olce@FreeBSD.org>
To:        src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-branches@FreeBSD.org
Subject:   git: 3fab2d96cdd7 - stable/13 - New realgroupmember()
Message-ID:  <202312211343.3BLDhc5O079218@gitrepo.freebsd.org>

next in thread | raw e-mail | index | archive | help
The branch stable/13 has been updated by olce:

URL: https://cgit.FreeBSD.org/src/commit/?id=3fab2d96cdd7f4ce78391ab67f719bd2936bec60

commit 3fab2d96cdd7f4ce78391ab67f719bd2936bec60
Author:     Olivier Certner <olce.freebsd@certner.fr>
AuthorDate: 2023-08-17 23:54:45 +0000
Commit:     Olivier Certner <olce@FreeBSD.org>
CommitDate: 2023-12-21 13:37:52 +0000

    New realgroupmember()
    
    Like groupmember(), but taking into account the real group instead of
    the effective group.  Leverages the new supplementary_group_member()
    function.
    
    Reviewed by:            mhorne
    Sponsored by:           Kumacom SAS
    Differential Revision:  https://reviews.freebsd.org/D40641
    
    (cherry picked from commit 2a2bfa6ad92e9c82dcc55733ad2fd58fd2ea7559)
    
    Approved by:    markj (mentor)
---
 sys/kern/kern_prot.c | 13 +++++++++++++
 sys/sys/ucred.h      |  1 +
 2 files changed, 14 insertions(+)

diff --git a/sys/kern/kern_prot.c b/sys/kern/kern_prot.c
index 682754dd7687..e6c11d2ea74b 100644
--- a/sys/kern/kern_prot.c
+++ b/sys/kern/kern_prot.c
@@ -1314,6 +1314,19 @@ groupmember(gid_t gid, struct ucred *cred)
 	return (supplementary_group_member(gid, cred));
 }
 
+/*
+ * Check if gid is a member of the real group set (i.e., real and supplementary
+ * groups).
+ */
+int
+realgroupmember(gid_t gid, struct ucred *cred)
+{
+	if (gid == cred->cr_rgid)
+		return (1);
+
+	return (supplementary_group_member(gid, cred));
+}
+
 /*
  * Test the active securelevel against a given level.  securelevel_gt()
  * implements (securelevel > level).  securelevel_ge() implements
diff --git a/sys/sys/ucred.h b/sys/sys/ucred.h
index b17dccada4d8..837c33757317 100644
--- a/sys/sys/ucred.h
+++ b/sys/sys/ucred.h
@@ -159,6 +159,7 @@ void	cru2x(struct ucred *cr, struct xucred *xcr);
 void	cru2xt(struct thread *td, struct xucred *xcr);
 void	crsetgroups(struct ucred *cr, int n, gid_t *groups);
 int	groupmember(gid_t gid, struct ucred *cred);
+int	realgroupmember(gid_t gid, struct ucred *cred);
 #endif /* _KERNEL */
 
 #endif /* !_SYS_UCRED_H_ */



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202312211343.3BLDhc5O079218>