#!/usr/bin/perl
#------------------------------------------------------------------------------
# Must Be Owner
#
# This broker filter script overrides P4D default behaviour, requiring that
# the user running the specified command to edit/view a spec must be the
# owner of the given spec, or else their command is rejected. For example,
# if you do 'p4 client -o MyWS', you must own the indicated
# workspace. Super users bypass this always.
#
# Enable in the broker config file like this example for various commands:
#
# command: ^branch|client|label|group$
# {
# action = filter;
# checkauth = true;
# execute = /p4/common/site/hms/scripts/broker_must_be_owner.pl;
# }
use strict;
my $User;
my $Cmd;
my $AccessLevel;
my $UpdateTime;
my $ClientSpecName;
my $SpecName;
my $SpecOwner;
while (<STDIN>) {
if (/^user: /) {
$User = $_;
chomp $User;
$User =~ s/^user: //;
}
if (/^command: /) {
$Cmd = $_;
chomp $Cmd;
$Cmd =~ s/^command: //;
}
if (/^workspace: /) {
$ClientSpecName = $_;
$ClientSpecName =~ s/^workspace: //;
chomp $ClientSpecName;
}
# If we see certain flags that take an argument, like '-S <stream>' or
# '-t <template>', ignore them and skip the next argument.
if (/^Arg\d+: -(S|t)/) {
readline;
next;
}
# Ignore all remaining '-' flags, so only the spec name remains.
if (/^Arg\d+: -/) {
next;
}
if (/^Arg\d+: /) {
$SpecName = $_;
$SpecName =~ s/^Arg\d+: //;
chomp $SpecName;
}
}
if ( ! $Cmd ) {
print "action: REJECT\n";
print "message: \"Data Leakage Protection: Internal Error, could not determine Cmd.\"\n";
exit (0);
}
if ( ! $User ) {
print "action: REJECT\n";
print "message: \"Data Leakage Protection: Internal Error, could not determine User.\"\n";
exit (0);
}
$AccessLevel=`$ENV{P4BIN} protects -m -u $User`;
chomp $AccessLevel;
if ($AccessLevel eq "super") {
print "action: PASS\n";
exit (0);
}
if ( ! $SpecName ) {
# Special case for the 'p4 client' command; a default for the client
# spec name (if unspecified) is the current workspace from the
# environment context.
if ($ClientSpecName) {
$SpecName = $ClientSpecName;
} else {
print "action: REJECT\n";
print "message: \"Data Leakage Protection: Internal Error, could not determine SpecName.\"\n";
exit (0);
}
}
# If the spec doesn't yet exist, the user is creating or querying
# a non-existent spec. Allow the command to pass.
$UpdateTime=`$ENV{P4BIN} -ztag -F %Update% $Cmd -o $SpecName`;
chomp $UpdateTime;
if ($UpdateTime eq "") {
print "action: PASS\n";
exit (0);
}
$SpecOwner=`$ENV{P4BIN} -ztag -F %Owner% $Cmd -o $SpecName`;
chomp $SpecOwner;
if ($User eq $SpecOwner) {
print "action: PASS\n";
exit (0);
}
print "action: REJECT\n";
print "message: \"Data Leakage Protection: The command 'p4 $Cmd' requires super access or ownership of the $Cmd spec on this server.\"\n";
exit (0);
| # | Change | User | Description | Committed | |
|---|---|---|---|---|---|
| #1 | 33516 | C. Thomas Tyler |
Consistency pass: fix absolute URLs, p4ms->hms renames, script/doc typos and bugs - Convert absolute workshop.perforce.com URLs to relative paths in dlp/ReadMe.md - Fix case-mismatch link to HMS_Product_Roadmap.md in README.md - Rename reset_p4ms.sh -> reset_hms.sh and p4broker_p4ms_test -> p4broker_hms_test - Fix .sh-suffix bugs: bin/hms calling global_replica_status.sh (should be no ext), and matching SEE ALSO / doc references for sdp_sync and global_replica_status - Add missing scripts (gtu, hrun, irun, global_replica_status) to gen_script_man_pages.sh - Add stub scripts: nj_help.sh, broker_njob.pl, broker_mkproj.pl, broker_jr.pl - Remove dangling absolute symlinks HostCM/p4 and HostCM/p4d (cruft) - Rename test/b -> test/broker_ctl.sh for clarity - Fix real bugs: broker_imply-u.pl broken regex match, gen_dlp_broker_cfg.sh and gen_nj_broker_cfg.sh copy-pasted Version-file existence check, garbled comment in broker_must_be_owner.pl, unclosed quote in tools/gsr.sh usage(), missing 'h' in HMS_SystemComponents.md broker command example (^ms$ -> ^hms$) - Fix broken sed command and incomplete sentence in HMS_Install_Notes.md and SDP_and_HMS_Update_Process.md - Fix broken markdown table in HMS_Product_Roadmap.md - Fix unclosed parenthesis, missing verb, and FKA Swarm mislabel in HMSDeploymentPlanning.adoc - Standardize //streams/main/... naming in HostCM/ReadMe.md - Numerous typo fixes across README.md, HMS_SystemComponents.md, SDP_and_HMS_Update_Process.md, HMS_TightShipManagement.adoc, HMSDeploymentPlanning.adoc, HostCM/ReadMe.md, and various scripts Co-authored-by: Copilot <[email protected]> |