| Directory: | cvmfs/ |
|---|---|
| File: | cvmfs/uid_map.h |
| Date: | 2025-10-19 02:35:28 |
| Exec | Total | Coverage | |
|---|---|---|---|
| Lines: | 62 | 63 | 98.4% |
| Branches: | 60 | 85 | 70.6% |
| Line | Branch | Exec | Source |
|---|---|---|---|
| 1 | /** | ||
| 2 | * This file is part of the CernVM File System. | ||
| 3 | */ | ||
| 4 | |||
| 5 | #ifndef CVMFS_UID_MAP_H_ | ||
| 6 | #define CVMFS_UID_MAP_H_ | ||
| 7 | |||
| 8 | #include <sys/types.h> | ||
| 9 | |||
| 10 | #include <cerrno> | ||
| 11 | #include <map> | ||
| 12 | #include <string> | ||
| 13 | #include <vector> | ||
| 14 | |||
| 15 | #include "sanitizer.h" | ||
| 16 | #include "util/logging.h" | ||
| 17 | #include "util/string.h" | ||
| 18 | |||
| 19 | /** | ||
| 20 | * This reads a mapping file of (roughly) the following format: | ||
| 21 | * +-------------------------------------------------------------+ | ||
| 22 | * | user_id.map | | ||
| 23 | * | ~~~~~~~~~~~ | | ||
| 24 | * | | | ||
| 25 | * | # map UIDs 137 and 138 to 1000 (I am a comment by the way) | | ||
| 26 | * | 137 1000 | | ||
| 27 | * | 138 1000 | | ||
| 28 | * | | | ||
| 29 | * | # swap two UIDs | | ||
| 30 | * | 101 5 | | ||
| 31 | * | 5 101 | | ||
| 32 | * | | | ||
| 33 | * | # map everything else to root (wildcard) | | ||
| 34 | * | * 0 | | ||
| 35 | * +-------------------------------------------------------------+ | ||
| 36 | * | ||
| 37 | * These files are intended for the definition of UID and GID mappings both on | ||
| 38 | * the client and the server side of CernVM-FS. | ||
| 39 | * | ||
| 40 | * The class takes care of managing these mappings and can be initialised via | ||
| 41 | * a file read from disk or programmatically through the class's public API. | ||
| 42 | * When reading from a file, simple consistency checks are performed to ensure | ||
| 43 | * proper functionality. | ||
| 44 | */ | ||
| 45 | template<typename T> | ||
| 46 | class IntegerMap { | ||
| 47 | public: | ||
| 48 | typedef T key_type; | ||
| 49 | typedef T value_type; | ||
| 50 | typedef typename std::map<key_type, value_type> map_type; | ||
| 51 | |||
| 52 | public: | ||
| 53 | 8169 | IntegerMap() | |
| 54 | 8169 | : valid_(true), has_default_value_(false), default_value_(T(0)) { } | |
| 55 | |||
| 56 | /** | ||
| 57 | * Define a mapping from k to v | ||
| 58 | * @param k map the given value to v | ||
| 59 | * @param v the value given in k is mapped to this | ||
| 60 | **/ | ||
| 61 | 492 | void Set(const T k, const T v) { map_[k] = v; } | |
| 62 | |||
| 63 | /** | ||
| 64 | * Sets a default (or fallback) value to be used if no other mapping rule fits | ||
| 65 | * Note: A previously defined default value is overwritten. | ||
| 66 | * @param v the value to be used as a fallback in Map() | ||
| 67 | */ | ||
| 68 | 205 | void SetDefault(const T v) { | |
| 69 | 205 | has_default_value_ = true; | |
| 70 | 205 | default_value_ = v; | |
| 71 | 205 | } | |
| 72 | |||
| 73 | /** | ||
| 74 | * Reads mapping rules from a provided file path. The file format is discussed | ||
| 75 | * in the class description above. | ||
| 76 | * Note: If a read failure occurs the IntegerMap<> is declared invalid and | ||
| 77 | * must not be used anymore. | ||
| 78 | * | ||
| 79 | * @param path the file path to be read | ||
| 80 | * @return true if the file was successfully read | ||
| 81 | */ | ||
| 82 | 207 | bool Read(const std::string &path) { | |
| 83 | 207 | valid_ = ReadFromFile(path); | |
| 84 | 207 | return IsValid(); | |
| 85 | } | ||
| 86 | |||
| 87 | /** | ||
| 88 | * Checks if a mapping rule for a given value is available | ||
| 89 | * @param k the value to be checked | ||
| 90 | * @return true if a mapping rule for k exists | ||
| 91 | */ | ||
| 92 | 328 | bool Contains(const T k) const { | |
| 93 |
1/2✗ Branch 1 not taken.
✓ Branch 2 taken 328 times.
|
328 | assert(IsValid()); |
| 94 |
1/2✓ Branch 2 taken 328 times.
✗ Branch 3 not taken.
|
328 | return map_.find(k) != map_.end(); |
| 95 | } | ||
| 96 | |||
| 97 | /** | ||
| 98 | * Applies the mapping rules inside this IntegerMap<> to the given value. | ||
| 99 | * @param k the value to be mapped | ||
| 100 | * @return the result of the mapping rule application (might be the default) | ||
| 101 | */ | ||
| 102 | 451 | T Map(const T k) const { | |
| 103 |
1/2✗ Branch 1 not taken.
✓ Branch 2 taken 451 times.
|
451 | assert(IsValid()); |
| 104 |
1/2✓ Branch 1 taken 451 times.
✗ Branch 2 not taken.
|
451 | const typename map_type::const_iterator i = map_.find(k); |
| 105 |
2/2✓ Branch 2 taken 246 times.
✓ Branch 3 taken 205 times.
|
451 | if (i != map_.end()) { |
| 106 | 246 | return i->second; | |
| 107 | } | ||
| 108 | |||
| 109 |
2/2✓ Branch 1 taken 164 times.
✓ Branch 2 taken 41 times.
|
205 | return (HasDefault()) ? default_value_ : k; |
| 110 | } | ||
| 111 | |||
| 112 |
4/4✓ Branch 1 taken 6803 times.
✓ Branch 2 taken 41 times.
✓ Branch 3 taken 41 times.
✓ Branch 4 taken 6762 times.
|
6844 | bool HasEffect() const { return (map_.size() != 0) || has_default_value_; } |
| 113 | |||
| 114 | 164 | bool IsEmpty() const { return map_.size() == 0; } | |
| 115 | 1273 | bool IsValid() const { return valid_; } | |
| 116 | 369 | bool HasDefault() const { return has_default_value_; } | |
| 117 | 164 | size_t RuleCount() const { return map_.size(); } | |
| 118 | |||
| 119 | 82 | T GetDefault() const { | |
| 120 |
1/2✗ Branch 0 not taken.
✓ Branch 1 taken 82 times.
|
82 | assert(has_default_value_); |
| 121 | 82 | return default_value_; | |
| 122 | } | ||
| 123 | ✗ | const map_type &GetRuleMap() const { return map_; } | |
| 124 | |||
| 125 | protected: | ||
| 126 | 207 | bool ReadFromFile(const std::string &path) { | |
| 127 |
1/2✓ Branch 2 taken 207 times.
✗ Branch 3 not taken.
|
207 | FILE *fmap = fopen(path.c_str(), "r"); |
| 128 |
2/2✓ Branch 0 taken 43 times.
✓ Branch 1 taken 164 times.
|
207 | if (!fmap) { |
| 129 |
1/2✓ Branch 1 taken 43 times.
✗ Branch 2 not taken.
|
43 | LogCvmfs(kLogUtility, kLogDebug, "failed to open %s (errno: %d)", |
| 130 | 43 | path.c_str(), errno); | |
| 131 | 43 | return false; | |
| 132 | } | ||
| 133 | |||
| 134 |
1/2✓ Branch 1 taken 164 times.
✗ Branch 2 not taken.
|
164 | const sanitizer::IntegerSanitizer int_sanitizer; |
| 135 | |||
| 136 | 164 | std::string line; | |
| 137 | 164 | unsigned int line_number = 0; | |
| 138 |
6/7✓ Branch 1 taken 164 times.
✓ Branch 2 taken 41 times.
✓ Branch 3 taken 123 times.
✓ Branch 5 taken 615 times.
✗ Branch 6 not taken.
✓ Branch 7 taken 574 times.
✓ Branch 8 taken 41 times.
|
943 | while (GetLineFile(fmap, &line)) { |
| 139 | 574 | ++line_number; | |
| 140 |
1/2✓ Branch 1 taken 574 times.
✗ Branch 2 not taken.
|
574 | line = Trim(line); |
| 141 |
7/8✓ Branch 1 taken 533 times.
✓ Branch 2 taken 41 times.
✓ Branch 4 taken 533 times.
✗ Branch 5 not taken.
✓ Branch 6 taken 205 times.
✓ Branch 7 taken 328 times.
✓ Branch 8 taken 246 times.
✓ Branch 9 taken 328 times.
|
574 | if (line.empty() || line[0] == '#') { |
| 142 | 287 | continue; | |
| 143 | } | ||
| 144 | |||
| 145 |
1/2✓ Branch 1 taken 328 times.
✗ Branch 2 not taken.
|
328 | std::vector<std::string> components = SplitString(line, ' '); |
| 146 |
1/2✓ Branch 1 taken 328 times.
✗ Branch 2 not taken.
|
328 | FilterEmptyStrings(&components); |
| 147 |
3/4✓ Branch 3 taken 287 times.
✗ Branch 4 not taken.
✓ Branch 5 taken 246 times.
✓ Branch 6 taken 41 times.
|
615 | if (components.size() != 2 || !int_sanitizer.IsValid(components[1]) |
| 148 |
10/14✓ Branch 0 taken 287 times.
✓ Branch 1 taken 41 times.
✓ Branch 4 taken 246 times.
✗ Branch 5 not taken.
✓ Branch 6 taken 205 times.
✓ Branch 7 taken 41 times.
✗ Branch 8 not taken.
✗ Branch 9 not taken.
✓ Branch 10 taken 205 times.
✗ Branch 11 not taken.
✓ Branch 12 taken 41 times.
✓ Branch 13 taken 164 times.
✓ Branch 14 taken 123 times.
✓ Branch 15 taken 205 times.
|
615 | || (components[0] != "*" && !int_sanitizer.IsValid(components[0]))) { |
| 149 |
1/2✓ Branch 1 taken 123 times.
✗ Branch 2 not taken.
|
123 | fclose(fmap); |
| 150 |
1/2✓ Branch 2 taken 123 times.
✗ Branch 3 not taken.
|
123 | LogCvmfs(kLogUtility, kLogDebug, "failed to read line %d in %s", |
| 151 | line_number, path.c_str()); | ||
| 152 | 123 | return false; | |
| 153 | } | ||
| 154 | |||
| 155 |
1/2✓ Branch 2 taken 205 times.
✗ Branch 3 not taken.
|
205 | value_type to = String2Uint64(components[1]); |
| 156 |
2/2✓ Branch 2 taken 41 times.
✓ Branch 3 taken 164 times.
|
205 | if (components[0] == "*") { |
| 157 | 41 | SetDefault(to); | |
| 158 | 41 | continue; | |
| 159 | } | ||
| 160 | |||
| 161 |
1/2✓ Branch 2 taken 164 times.
✗ Branch 3 not taken.
|
164 | key_type from = String2Uint64(components[0]); |
| 162 |
1/2✓ Branch 1 taken 164 times.
✗ Branch 2 not taken.
|
164 | Set(from, to); |
| 163 | } | ||
| 164 | |||
| 165 |
1/2✓ Branch 1 taken 41 times.
✗ Branch 2 not taken.
|
41 | fclose(fmap); |
| 166 | 41 | return true; | |
| 167 | 164 | } | |
| 168 | |||
| 169 | 328 | void FilterEmptyStrings(std::vector<std::string> *vec) const { | |
| 170 | 328 | std::vector<std::string>::iterator i = vec->begin(); | |
| 171 |
2/2✓ Branch 2 taken 738 times.
✓ Branch 3 taken 328 times.
|
1066 | for (; i != vec->end();) { |
| 172 |
3/4✓ Branch 2 taken 123 times.
✓ Branch 3 taken 615 times.
✓ Branch 6 taken 123 times.
✗ Branch 7 not taken.
|
738 | i = (i->empty()) ? vec->erase(i) : i + 1; |
| 173 | } | ||
| 174 | 328 | } | |
| 175 | |||
| 176 | private: | ||
| 177 | bool valid_; | ||
| 178 | map_type map_; | ||
| 179 | |||
| 180 | bool has_default_value_; | ||
| 181 | T default_value_; | ||
| 182 | }; | ||
| 183 | |||
| 184 | typedef IntegerMap<uid_t> UidMap; | ||
| 185 | typedef IntegerMap<gid_t> GidMap; | ||
| 186 | |||
| 187 | #endif // CVMFS_UID_MAP_H_ | ||
| 188 |