id: don't call getcon unnecessarily
[coreutils.git] / src / id.c
blobda81422873a4ec6be61851d440b5a8973ef88845
1 /* id -- print real and effective UIDs and GIDs
2 Copyright (C) 1989-2012 Free Software Foundation, Inc.
4 This program is free software: you can redistribute it and/or modify
5 it under the terms of the GNU General Public License as published by
6 the Free Software Foundation, either version 3 of the License, or
7 (at your option) any later version.
9 This program is distributed in the hope that it will be useful,
10 but WITHOUT ANY WARRANTY; without even the implied warranty of
11 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 GNU General Public License for more details.
14 You should have received a copy of the GNU General Public License
15 along with this program. If not, see <http://www.gnu.org/licenses/>. */
17 /* Written by Arnold Robbins.
18 Major rewrite by David MacKenzie, djm@gnu.ai.mit.edu. */
20 #include <config.h>
21 #include <stdio.h>
22 #include <sys/types.h>
23 #include <pwd.h>
24 #include <grp.h>
25 #include <getopt.h>
26 #include <selinux/selinux.h>
28 #include "system.h"
29 #include "error.h"
30 #include "mgetgroups.h"
31 #include "quote.h"
32 #include "group-list.h"
34 /* The official name of this program (e.g., no 'g' prefix). */
35 #define PROGRAM_NAME "id"
37 #define AUTHORS \
38 proper_name ("Arnold Robbins"), \
39 proper_name ("David MacKenzie")
41 /* If nonzero, output only the SELinux context. -Z */
42 static int just_context = 0;
44 static void print_user (uid_t uid);
45 static void print_full_info (const char *username);
47 /* If true, output user/group name instead of ID number. -n */
48 static bool use_name = false;
50 /* The real and effective IDs of the user to print. */
51 static uid_t ruid, euid;
52 static gid_t rgid, egid;
54 /* True unless errors have been encountered. */
55 static bool ok = true;
57 /* The SELinux context. Start with a known invalid value so print_full_info
58 knows when 'context' has not been set to a meaningful value. */
59 static security_context_t context = NULL;
61 static struct option const longopts[] =
63 {"context", no_argument, NULL, 'Z'},
64 {"group", no_argument, NULL, 'g'},
65 {"groups", no_argument, NULL, 'G'},
66 {"name", no_argument, NULL, 'n'},
67 {"real", no_argument, NULL, 'r'},
68 {"user", no_argument, NULL, 'u'},
69 {GETOPT_HELP_OPTION_DECL},
70 {GETOPT_VERSION_OPTION_DECL},
71 {NULL, 0, NULL, 0}
74 void
75 usage (int status)
77 if (status != EXIT_SUCCESS)
78 emit_try_help ();
79 else
81 printf (_("Usage: %s [OPTION]... [USERNAME]\n"), program_name);
82 fputs (_("\
83 Print user and group information for the specified USERNAME,\n\
84 or (when USERNAME omitted) for the current user.\n\
85 \n\
86 -a ignore, for compatibility with other versions\n\
87 -Z, --context print only the security context of the current user\n\
88 -g, --group print only the effective group ID\n\
89 -G, --groups print all group IDs\n\
90 -n, --name print a name instead of a number, for -ugG\n\
91 -r, --real print the real ID instead of the effective ID, with -ugG\n\
92 -u, --user print only the effective user ID\n\
93 "), stdout);
94 fputs (HELP_OPTION_DESCRIPTION, stdout);
95 fputs (VERSION_OPTION_DESCRIPTION, stdout);
96 fputs (_("\
97 \n\
98 Without any OPTION, print some useful set of identified information.\n\
99 "), stdout);
100 emit_ancillary_info ();
102 exit (status);
106 main (int argc, char **argv)
108 int optc;
109 int selinux_enabled = (is_selinux_enabled () > 0);
111 /* If true, output the list of all group IDs. -G */
112 bool just_group_list = false;
113 /* If true, output only the group ID(s). -g */
114 bool just_group = false;
115 /* If true, output real UID/GID instead of default effective UID/GID. -r */
116 bool use_real = false;
117 /* If true, output only the user ID(s). -u */
118 bool just_user = false;
120 initialize_main (&argc, &argv);
121 set_program_name (argv[0]);
122 setlocale (LC_ALL, "");
123 bindtextdomain (PACKAGE, LOCALEDIR);
124 textdomain (PACKAGE);
126 atexit (close_stdout);
128 while ((optc = getopt_long (argc, argv, "agnruGZ", longopts, NULL)) != -1)
130 switch (optc)
132 case 'a':
133 /* Ignore -a, for compatibility with SVR4. */
134 break;
136 case 'Z':
137 /* politely decline if we're not on a selinux-enabled kernel. */
138 if (!selinux_enabled)
139 error (EXIT_FAILURE, 0,
140 _("--context (-Z) works only on an SELinux-enabled kernel"));
141 just_context = 1;
142 break;
144 case 'g':
145 just_group = true;
146 break;
147 case 'n':
148 use_name = true;
149 break;
150 case 'r':
151 use_real = true;
152 break;
153 case 'u':
154 just_user = true;
155 break;
156 case 'G':
157 just_group_list = true;
158 break;
159 case_GETOPT_HELP_CHAR;
160 case_GETOPT_VERSION_CHAR (PROGRAM_NAME, AUTHORS);
161 default:
162 usage (EXIT_FAILURE);
166 size_t n_ids = argc - optind;
167 if (1 < n_ids)
169 error (0, 0, _("extra operand %s"), quote (argv[optind + 1]));
170 usage (EXIT_FAILURE);
173 if (n_ids && just_context)
174 error (EXIT_FAILURE, 0,
175 _("cannot print security context when user specified"));
177 if (just_user + just_group + just_group_list + just_context > 1)
178 error (EXIT_FAILURE, 0, _("cannot print \"only\" of more than one choice"));
180 bool default_format = (just_user + just_group + just_group_list == 0);
182 if (default_format && (use_real || use_name))
183 error (EXIT_FAILURE, 0,
184 _("cannot print only names or real IDs in default format"));
186 /* If we are on a selinux-enabled kernel, no user is specified, and
187 either --context is specified or none of (-u,-g,-G) is specified,
188 and we're not in POSIXLY_CORRECT mode, get our context. Otherwise,
189 leave the context variable alone - it has been initialized to an
190 invalid value that will be not displayed in print_full_info(). */
191 if (selinux_enabled
192 && n_ids == 0
193 && (just_context ||
194 (default_format && ! getenv ("POSIXLY_CORRECT"))))
196 /* Report failure only if --context (-Z) was explicitly requested. */
197 if (getcon (&context) && just_context)
198 error (EXIT_FAILURE, 0, _("can't get process context"));
201 if (n_ids == 1)
203 struct passwd *pwd = getpwnam (argv[optind]);
204 if (pwd == NULL)
205 error (EXIT_FAILURE, 0, _("%s: no such user"), argv[optind]);
206 ruid = euid = pwd->pw_uid;
207 rgid = egid = pwd->pw_gid;
209 else
211 /* POSIX says identification functions (getuid, getgid, and
212 others) cannot fail, but they can fail under GNU/Hurd and a
213 few other systems. Test for failure by checking errno. */
214 uid_t NO_UID = -1;
215 gid_t NO_GID = -1;
217 if (just_user ? !use_real
218 : !just_group && !just_group_list && !just_context)
220 errno = 0;
221 euid = geteuid ();
222 if (euid == NO_UID && errno)
223 error (EXIT_FAILURE, errno, _("cannot get effective UID"));
226 if (just_user ? use_real
227 : !just_group && (just_group_list || !just_context))
229 errno = 0;
230 ruid = getuid ();
231 if (ruid == NO_UID && errno)
232 error (EXIT_FAILURE, errno, _("cannot get real UID"));
235 if (!just_user && (just_group || just_group_list || !just_context))
237 errno = 0;
238 egid = getegid ();
239 if (egid == NO_GID && errno)
240 error (EXIT_FAILURE, errno, _("cannot get effective GID"));
242 errno = 0;
243 rgid = getgid ();
244 if (rgid == NO_GID && errno)
245 error (EXIT_FAILURE, errno, _("cannot get real GID"));
249 if (just_user)
251 print_user (use_real ? ruid : euid);
253 else if (just_group)
255 if (!print_group (use_real ? rgid : egid, use_name))
256 ok = false;
258 else if (just_group_list)
260 if (!print_group_list (argv[optind], ruid, rgid, egid, use_name))
261 ok = false;
263 else if (just_context)
265 fputs (context, stdout);
267 else
269 print_full_info (argv[optind]);
271 putchar ('\n');
273 exit (ok ? EXIT_SUCCESS : EXIT_FAILURE);
276 /* Print the name or value of user ID UID. */
278 static void
279 print_user (uid_t uid)
281 struct passwd *pwd = NULL;
283 if (use_name)
285 pwd = getpwuid (uid);
286 if (pwd == NULL)
288 error (0, 0, _("cannot find name for user ID %lu"),
289 (unsigned long int) uid);
290 ok = false;
294 if (pwd == NULL)
295 printf ("%lu", (unsigned long int) uid);
296 else
297 printf ("%s", pwd->pw_name);
300 /* Print all of the info about the user's user and group IDs. */
302 static void
303 print_full_info (const char *username)
305 struct passwd *pwd;
306 struct group *grp;
308 printf (_("uid=%lu"), (unsigned long int) ruid);
309 pwd = getpwuid (ruid);
310 if (pwd)
311 printf ("(%s)", pwd->pw_name);
313 printf (_(" gid=%lu"), (unsigned long int) rgid);
314 grp = getgrgid (rgid);
315 if (grp)
316 printf ("(%s)", grp->gr_name);
318 if (euid != ruid)
320 printf (_(" euid=%lu"), (unsigned long int) euid);
321 pwd = getpwuid (euid);
322 if (pwd)
323 printf ("(%s)", pwd->pw_name);
326 if (egid != rgid)
328 printf (_(" egid=%lu"), (unsigned long int) egid);
329 grp = getgrgid (egid);
330 if (grp)
331 printf ("(%s)", grp->gr_name);
335 gid_t *groups;
336 int i;
338 int n_groups = xgetgroups (username, (pwd ? pwd->pw_gid : -1),
339 &groups);
340 if (n_groups < 0)
342 if (username)
344 error (0, errno, _("failed to get groups for user %s"),
345 quote (username));
347 else
349 error (0, errno, _("failed to get groups for the current process"));
351 ok = false;
352 return;
355 if (n_groups > 0)
356 fputs (_(" groups="), stdout);
357 for (i = 0; i < n_groups; i++)
359 if (i > 0)
360 putchar (',');
361 printf ("%lu", (unsigned long int) groups[i]);
362 grp = getgrgid (groups[i]);
363 if (grp)
364 printf ("(%s)", grp->gr_name);
366 free (groups);
369 /* POSIX mandates the precise output format, and that it not include
370 any context=... part, so skip that if POSIXLY_CORRECT is set. */
371 if (context)
372 printf (_(" context=%s"), context);