broker_imply-u.pl #1

  • //
  • p4-hms/
  • dev/
  • p4/
  • common/
  • site/
  • hms/
  • dlp/
  • broker_imply-u.pl
  • View
  • Commits
  • Open Download .zip Download (2 KB)
#!/usr/bin/perl

#------------------------------------------------------------------------------
# This broker filter script is part of Data Leakage Protection (DLP) system.
#
# Imply -u
#
# This broker filter script overrides P4D default behaviour, making it so
# the user running the specified command has the '-u' flag implied, so that
# the user can only see their own specs (clients, labels) in the
# system. For example, a 'p4 clients' command has the '-u <yourself>',
# implied.
#
# Note that for Streams, P4D already has sufficient logic (based on list
# access in the Protections table) to determine which streams to list, so
# no special handling of streams is needed.
#
# Enable in the broker config file like this example:
#
# command: ^branches|clients|groups|labels|remotes|workspaces$
# {
#    action  = filter;
#    checkauth = true;
#    execute = /p4/common/site/hms/scripts/broker_imply-u.pl;
# }

use strict;

my $User;
my $Cmd;
my $Access;
my $Arg;
my @ArgList;
my $ArgCount = 0;
my $ArgListSize = 0;
my $SkipNext = 0;

while (<STDIN>) {
   if (/^user: /) {
      $User = $_;
      chomp $User;
      $User =~ s/^user: //;
   }
   if (/^command: /) {
      $Cmd = $_;
      chomp $Cmd;
      $Cmd =~ s/^command: //;
   }

   # If we see a '-u', ignore it and skip the next line.
   if (/^Arg\d+: -u/) {
      readline;
      next;
   }

   if (/^Arg\d+: /) {
      s/^Arg\d+: //;
      chomp;
      $ArgList[$ArgCount++] = $_;
   }
}

if ( ! $Cmd ) {
   print "action: REJECT\n";
   print "message: \"Data Leakage Protection: Internal Error, could not determine Cmd.\"\n";
   exit (0);
}

if ( ! $User ) {
   print "action: REJECT\n";
   print "message: \"Data Leakage Protection: Internal Error, could not determine User.\"\n";
   exit (0);
}

$Access=`$ENV{P4BIN} protects -m -u $User`;
chomp $Access;

if ($Access eq "super") {
   print "action: PASS\n";
   exit (0);
}

# Indicate a REWRITE action is needed, and then append '-u <current-user>'
# argument.  Note that of the user explicitly specific '-u foo', that
# will be ignored as we'll add '-u me' to the end, and that will win.
print "action: REWRITE\n";
print "command: $Cmd\n";

$ArgListSize = @ArgList;

for (my $i=0; $i < $ArgListSize; $i++) {
   $Arg = $ArgList[$i];

   if ($SkipNext) {
      $SkipNext = 0;
      next;
   }

   if ($Arg =~ /^-u$/) {
      $SkipNext = 1;
      next;
   }

   print "arg: $Arg\n";
}

print "arg: -u\n";
print "arg: $User\n";

exit (0);
# Change User Description Committed
#1 33516 C. Thomas Tyler Consistency pass: fix absolute URLs, p4ms->hms renames, script/doc typos and bugs

- Convert absolute workshop.perforce.com URLs to relative paths in dlp/ReadMe.md
- Fix case-mismatch link to HMS_Product_Roadmap.md in README.md
- Rename reset_p4ms.sh -> reset_hms.sh and p4broker_p4ms_test -> p4broker_hms_test
- Fix .sh-suffix bugs: bin/hms calling global_replica_status.sh (should be no ext),
  and matching SEE ALSO / doc references for sdp_sync and global_replica_status
- Add missing scripts (gtu, hrun, irun, global_replica_status) to gen_script_man_pages.sh
- Add stub scripts: nj_help.sh, broker_njob.pl, broker_mkproj.pl, broker_jr.pl
- Remove dangling absolute symlinks HostCM/p4 and HostCM/p4d (cruft)
- Rename test/b -> test/broker_ctl.sh for clarity
- Fix real bugs: broker_imply-u.pl broken regex match, gen_dlp_broker_cfg.sh and
  gen_nj_broker_cfg.sh copy-pasted Version-file existence check, garbled comment
  in broker_must_be_owner.pl, unclosed quote in tools/gsr.sh usage(), missing 'h'
  in HMS_SystemComponents.md broker command example (^ms$ -> ^hms$)
- Fix broken sed command and incomplete sentence in HMS_Install_Notes.md and
  SDP_and_HMS_Update_Process.md
- Fix broken markdown table in HMS_Product_Roadmap.md
- Fix unclosed parenthesis, missing verb, and FKA Swarm mislabel in
  HMSDeploymentPlanning.adoc
- Standardize //streams/main/... naming in HostCM/ReadMe.md
- Numerous typo fixes across README.md, HMS_SystemComponents.md,
  SDP_and_HMS_Update_Process.md, HMS_TightShipManagement.adoc,
  HMSDeploymentPlanning.adoc, HostCM/ReadMe.md, and various scripts

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>