1da2e3ebdSchin /***********************************************************************
2da2e3ebdSchin *                                                                      *
3da2e3ebdSchin *               This software is part of the ast package               *
4*b30d1939SAndy Fiddaman *          Copyright (c) 1985-2011 AT&T Intellectual Property          *
5da2e3ebdSchin *                      and is licensed under the                       *
6*b30d1939SAndy Fiddaman *                 Eclipse Public License, Version 1.0                  *
77c2fbfb3SApril Chin *                    by AT&T Intellectual Property                     *
8da2e3ebdSchin *                                                                      *
9da2e3ebdSchin *                A copy of the License is available at                 *
10*b30d1939SAndy Fiddaman *          http://www.eclipse.org/org/documents/epl-v10.html           *
11*b30d1939SAndy Fiddaman *         (with md5 checksum b35adb5213ca9657e911e9befb180842)         *
12da2e3ebdSchin *                                                                      *
13da2e3ebdSchin *              Information and Software Systems Research               *
14da2e3ebdSchin *                            AT&T Research                             *
15da2e3ebdSchin *                           Florham Park NJ                            *
16da2e3ebdSchin *                                                                      *
17da2e3ebdSchin *                 Glenn Fowler <gsf@research.att.com>                  *
18da2e3ebdSchin *                  David Korn <dgk@research.att.com>                   *
19da2e3ebdSchin *                   Phong Vo <kpv@research.att.com>                    *
20da2e3ebdSchin *                                                                      *
21da2e3ebdSchin ***********************************************************************/
22da2e3ebdSchin #pragma prototyped
23da2e3ebdSchin /*
24da2e3ebdSchin  * G. S. Fowler
25da2e3ebdSchin  * D. G. Korn
26da2e3ebdSchin  * AT&T Bell Laboratories
27da2e3ebdSchin  *
28da2e3ebdSchin  * shell library support
29da2e3ebdSchin  */
30da2e3ebdSchin 
31da2e3ebdSchin #include <ast.h>
32da2e3ebdSchin #include <sys/stat.h>
33da2e3ebdSchin 
34da2e3ebdSchin /*
35da2e3ebdSchin  * return pointer to the full path name of the shell
36da2e3ebdSchin  *
37da2e3ebdSchin  * SHELL is read from the environment and must start with /
38da2e3ebdSchin  *
39da2e3ebdSchin  * if set-uid or set-gid then the executable and its containing
40da2e3ebdSchin  * directory must not be owned by the real user/group
41da2e3ebdSchin  *
42da2e3ebdSchin  * root/administrator has its own test
43da2e3ebdSchin  *
44da2e3ebdSchin  * astconf("SH",NiL,NiL) is returned by default
45da2e3ebdSchin  *
46da2e3ebdSchin  * NOTE: csh is rejected because the bsh/csh differentiation is
47da2e3ebdSchin  *       not done for `csh script arg ...'
48da2e3ebdSchin  */
49da2e3ebdSchin 
50da2e3ebdSchin char*
pathshell(void)51da2e3ebdSchin pathshell(void)
52da2e3ebdSchin {
53da2e3ebdSchin 	register char*	sh;
54da2e3ebdSchin 	int		ru;
55da2e3ebdSchin 	int		eu;
56da2e3ebdSchin 	int		rg;
57da2e3ebdSchin 	int		eg;
58da2e3ebdSchin 	struct stat	st;
59da2e3ebdSchin 
60da2e3ebdSchin 	static char*	val;
61da2e3ebdSchin 
62da2e3ebdSchin 	if ((sh = getenv("SHELL")) && *sh == '/' && strmatch(sh, "*/(sh|*[!cC]sh)*([[:digit:]])?(-+([.[:alnum:]]))?(.exe)"))
63da2e3ebdSchin 	{
64da2e3ebdSchin 		if (!(ru = getuid()) || !eaccess("/bin", W_OK))
65da2e3ebdSchin 		{
66da2e3ebdSchin 			if (stat(sh, &st))
67da2e3ebdSchin 				goto defshell;
68da2e3ebdSchin 			if (ru != st.st_uid && !strmatch(sh, "?(/usr)?(/local)/?([ls])bin/?([[:lower:]])sh?(.exe)"))
69da2e3ebdSchin 				goto defshell;
70da2e3ebdSchin 		}
71da2e3ebdSchin 		else
72da2e3ebdSchin 		{
73da2e3ebdSchin 			eu = geteuid();
74da2e3ebdSchin 			rg = getgid();
75da2e3ebdSchin 			eg = getegid();
76da2e3ebdSchin 			if (ru != eu || rg != eg)
77da2e3ebdSchin 			{
78da2e3ebdSchin 				char*	s;
79da2e3ebdSchin 				char	dir[PATH_MAX];
80da2e3ebdSchin 
81da2e3ebdSchin 				s = sh;
82da2e3ebdSchin 				for (;;)
83da2e3ebdSchin 				{
84da2e3ebdSchin 					if (stat(s, &st))
85da2e3ebdSchin 						goto defshell;
86da2e3ebdSchin 					if (ru != eu && st.st_uid == ru)
87da2e3ebdSchin 						goto defshell;
88da2e3ebdSchin 					if (rg != eg && st.st_gid == rg)
89da2e3ebdSchin 						goto defshell;
90da2e3ebdSchin 					if (s != sh)
91da2e3ebdSchin 						break;
92da2e3ebdSchin 					if (strlen(s) >= sizeof(dir))
93da2e3ebdSchin 						goto defshell;
94da2e3ebdSchin 					strcpy(dir, s);
95da2e3ebdSchin 					if (!(s = strrchr(dir, '/')))
96da2e3ebdSchin 						break;
97da2e3ebdSchin 					*s = 0;
98da2e3ebdSchin 					s = dir;
99da2e3ebdSchin 				}
100da2e3ebdSchin 			}
101da2e3ebdSchin 		}
102da2e3ebdSchin 		return sh;
103da2e3ebdSchin 	}
104da2e3ebdSchin  defshell:
105da2e3ebdSchin 	if (!(sh = val))
106da2e3ebdSchin 	{
107da2e3ebdSchin 		if (!*(sh = astconf("SH", NiL, NiL)) || *sh != '/' || eaccess(sh, X_OK) || !(sh = strdup(sh)))
108da2e3ebdSchin 			sh = "/bin/sh";
109da2e3ebdSchin 		val = sh;
110da2e3ebdSchin 	}
111da2e3ebdSchin 	return sh;
112da2e3ebdSchin }
113