|
1 | | -//go:build aix || darwin || dragonfly || freebsd || linux || netbsd || solaris |
2 | | -// +build aix darwin dragonfly freebsd linux netbsd solaris |
| 1 | +//go:build aix || darwin || dragonfly || freebsd || linux || netbsd || openbsd || solaris |
| 2 | +// +build aix darwin dragonfly freebsd linux netbsd openbsd solaris |
3 | 3 |
|
4 | 4 | package main |
5 | 5 |
|
6 | 6 | import ( |
7 | | - "errors" |
8 | 7 | "fmt" |
9 | | - "math" |
10 | | - osuser "os/user" |
| 8 | + "os/user" |
11 | 9 | "strconv" |
12 | 10 | "strings" |
13 | | - "syscall" |
| 11 | + |
| 12 | + "golang.org/x/sys/unix" |
14 | 13 | ) |
15 | 14 |
|
16 | | -func chuser(user string) error { |
17 | | - group := "" |
18 | | - if i := strings.IndexByte(user, ':'); i >= 0 { |
19 | | - user, group = user[:i], user[i+1:] |
20 | | - } |
| 15 | +func chuser(input string) error { |
| 16 | + givenUser, givenGroup, _ := strings.Cut(input, ":") |
21 | 17 |
|
22 | | - u := (*osuser.User)(nil) |
23 | | - g := (*osuser.Group)(nil) |
| 18 | + var ( |
| 19 | + err error |
| 20 | + usr *user.User |
| 21 | + grp *user.Group |
| 22 | + uid, gid int |
| 23 | + ) |
24 | 24 |
|
25 | | - if user != "" { |
26 | | - if _, err := strconv.ParseUint(user, 10, 32); err == nil { |
27 | | - u, err = osuser.LookupId(user) |
28 | | - if err != nil { |
29 | | - return fmt.Errorf("failed to lookup user by id %q: %v", user, err) |
30 | | - } |
31 | | - } else { |
32 | | - u, err = osuser.Lookup(user) |
33 | | - if err != nil { |
34 | | - return fmt.Errorf("failed to lookup user by name %q: %v", user, err) |
35 | | - } |
| 25 | + if usr, err = user.Lookup(givenUser); err != nil { |
| 26 | + if usr, err = user.LookupId(givenUser); err != nil { |
| 27 | + return err |
36 | 28 | } |
37 | 29 | } |
38 | | - if group != "" { |
39 | | - if _, err := strconv.ParseUint(group, 10, 32); err == nil { |
40 | | - g, err = osuser.LookupGroupId(group) |
41 | | - if err != nil { |
42 | | - return fmt.Errorf("failed to lookup group by id %q: %v", user, err) |
43 | | - } |
44 | | - } else { |
45 | | - g, err = osuser.LookupGroup(group) |
46 | | - if err != nil { |
47 | | - return fmt.Errorf("failed to lookup group by name %q: %v", user, err) |
48 | | - } |
49 | | - } |
| 30 | + if uid, err = strconv.Atoi(usr.Uid); err != nil { |
| 31 | + return err |
50 | 32 | } |
51 | 33 |
|
52 | | - if g != nil { |
53 | | - gid, _ := strconv.ParseUint(g.Gid, 10, 32) |
54 | | - var err error |
55 | | - if gid < math.MaxInt { |
56 | | - if err := syscall.Setgroups([]int{int(gid)}); err != nil { |
57 | | - return fmt.Errorf("failed to setgroups %d: %v", gid, err) |
| 34 | + if givenGroup != "" { |
| 35 | + if grp, err = user.LookupGroup(givenGroup); err != nil { |
| 36 | + if grp, err = user.LookupGroupId(givenGroup); err != nil { |
| 37 | + return err |
58 | 38 | } |
59 | | - err = syscall.Setgid(int(gid)) |
60 | | - } else { |
61 | | - err = errors.New("gid too big") |
62 | 39 | } |
63 | 40 |
|
64 | | - if err != nil { |
65 | | - return fmt.Errorf("failed to setgid %d: %v", gid, err) |
66 | | - } |
67 | | - } else if u != nil { |
68 | | - gid, _ := strconv.ParseUint(u.Gid, 10, 32) |
69 | | - if err := syscall.Setgroups([]int{int(uint32(gid))}); err != nil { |
70 | | - return fmt.Errorf("failed to setgroups %d: %v", gid, err) |
71 | | - } |
72 | | - err := syscall.Setgid(int(uint32(gid))) |
73 | | - if err != nil { |
74 | | - return fmt.Errorf("failed to setgid %d: %v", gid, err) |
75 | | - } |
| 41 | + gid, _ = strconv.Atoi(grp.Gid) |
| 42 | + } else { |
| 43 | + gid, _ = strconv.Atoi(usr.Gid) |
76 | 44 | } |
77 | 45 |
|
78 | | - if u != nil { |
79 | | - uid, _ := strconv.ParseUint(u.Uid, 10, 32) |
80 | | - var err error |
81 | | - if uid < math.MaxInt { |
82 | | - err = syscall.Setuid(int(uid)) |
83 | | - } else { |
84 | | - err = errors.New("uid too big") |
85 | | - } |
86 | | - |
87 | | - if err != nil { |
88 | | - return fmt.Errorf("failed to setuid %d: %v", uid, err) |
89 | | - } |
| 46 | + if err := unix.Setgroups([]int{gid}); err != nil { |
| 47 | + return fmt.Errorf("setgroups: %d: %v", gid, err) |
| 48 | + } |
| 49 | + if err := unix.Setresgid(gid, gid, gid); err != nil { |
| 50 | + return fmt.Errorf("setresgid: %d: %v", gid, err) |
| 51 | + } |
| 52 | + if err := unix.Setresuid(uid, uid, uid); err != nil { |
| 53 | + return fmt.Errorf("setresuid: %d: %v", uid, err) |
90 | 54 | } |
91 | 55 |
|
92 | 56 | return nil |
|
0 commit comments