2007-10-07 11:44:02 +00:00
|
|
|
/*
|
2021-12-05 09:35:27 -06:00
|
|
|
* SPDX-FileCopyrightText: 1991 - 1994, Julianne Frances Haugh
|
|
|
|
* SPDX-FileCopyrightText: 1996 - 2000, Marek Michałkiewicz
|
|
|
|
* SPDX-FileCopyrightText: 2002 - 2006, Tomasz Kłoczko
|
|
|
|
* SPDX-FileCopyrightText: 2007 - 2008, Nicolas François
|
2007-10-07 11:44:02 +00:00
|
|
|
*
|
2021-12-05 09:35:27 -06:00
|
|
|
* SPDX-License-Identifier: BSD-3-Clause
|
2007-10-07 11:44:02 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
#include <config.h>
|
|
|
|
|
2007-11-10 23:46:11 +00:00
|
|
|
#ident "$Id$"
|
2007-10-07 11:47:01 +00:00
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
#include "prototypes.h"
|
|
|
|
#include "defines.h"
|
2023-02-01 13:50:48 +01:00
|
|
|
#include <stddef.h>
|
2007-10-07 11:44:02 +00:00
|
|
|
#include <stdio.h>
|
2007-10-07 11:45:40 +00:00
|
|
|
#include <stdlib.h>
|
2007-10-07 11:44:02 +00:00
|
|
|
#include <ctype.h>
|
2008-09-13 18:03:50 +00:00
|
|
|
#include <errno.h>
|
2019-09-20 10:27:31 +02:00
|
|
|
#ifdef USE_ECONF
|
|
|
|
#include <libeconf.h>
|
|
|
|
#endif
|
2023-02-04 22:41:18 +01:00
|
|
|
|
|
|
|
#include "alloc.h"
|
2007-10-07 11:44:02 +00:00
|
|
|
#include "getdef.h"
|
2021-11-28 17:37:53 -06:00
|
|
|
#include "shadowlog_internal.h"
|
2023-02-04 22:41:18 +01:00
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
/*
|
|
|
|
* A configuration item definition.
|
|
|
|
*/
|
|
|
|
struct itemdef {
|
2009-04-23 11:46:46 +00:00
|
|
|
/*@null@*/const char *name; /* name of the item */
|
|
|
|
/*@null@*/char *value; /* value given, or NULL if no value */
|
2007-10-07 11:44:02 +00:00
|
|
|
};
|
|
|
|
|
2015-02-27 12:39:44 +00:00
|
|
|
#define PAMDEFS \
|
|
|
|
{"CHFN_AUTH", NULL}, \
|
|
|
|
{"CHSH_AUTH", NULL}, \
|
|
|
|
{"CRACKLIB_DICTPATH", NULL}, \
|
|
|
|
{"ENV_HZ", NULL}, \
|
|
|
|
{"ENVIRON_FILE", NULL}, \
|
|
|
|
{"ENV_TZ", NULL}, \
|
|
|
|
{"FAILLOG_ENAB", NULL}, \
|
|
|
|
{"FTMP_FILE", NULL}, \
|
2021-05-06 17:23:33 +02:00
|
|
|
{"HMAC_CRYPTO_ALGO", NULL}, \
|
2015-02-27 12:39:44 +00:00
|
|
|
{"ISSUE_FILE", NULL}, \
|
|
|
|
{"LASTLOG_ENAB", NULL}, \
|
|
|
|
{"LOGIN_STRING", NULL}, \
|
|
|
|
{"MAIL_CHECK_ENAB", NULL}, \
|
|
|
|
{"MOTD_FILE", NULL}, \
|
|
|
|
{"NOLOGINS_FILE", NULL}, \
|
|
|
|
{"OBSCURE_CHECKS_ENAB", NULL}, \
|
|
|
|
{"PASS_ALWAYS_WARN", NULL}, \
|
|
|
|
{"PASS_CHANGE_TRIES", NULL}, \
|
|
|
|
{"PASS_MAX_LEN", NULL}, \
|
|
|
|
{"PASS_MIN_LEN", NULL}, \
|
|
|
|
{"PORTTIME_CHECKS_ENAB", NULL}, \
|
|
|
|
{"QUOTAS_ENAB", NULL}, \
|
|
|
|
{"SU_WHEEL_ONLY", NULL}, \
|
|
|
|
{"ULIMIT", NULL},
|
|
|
|
|
2020-10-08 12:17:30 +02:00
|
|
|
/*
|
|
|
|
* Items used in other tools (util-linux, etc.)
|
|
|
|
*/
|
|
|
|
#define FOREIGNDEFS \
|
|
|
|
{"ALWAYS_SET_PATH", NULL}, \
|
|
|
|
{"ENV_ROOTPATH", NULL}, \
|
|
|
|
{"LOGIN_KEEP_USERNAME", NULL}, \
|
|
|
|
{"LOGIN_PLAIN_PROMPT", NULL}, \
|
|
|
|
{"MOTD_FIRSTONLY", NULL}, \
|
|
|
|
|
2015-02-27 12:39:44 +00:00
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
#define NUMDEFS (sizeof(def_table)/sizeof(def_table[0]))
|
|
|
|
static struct itemdef def_table[] = {
|
2007-10-07 11:46:07 +00:00
|
|
|
{"CHFN_RESTRICT", NULL},
|
2007-10-07 11:46:52 +00:00
|
|
|
{"CONSOLE_GROUPS", NULL},
|
|
|
|
{"CONSOLE", NULL},
|
|
|
|
{"CREATE_HOME", NULL},
|
2007-10-07 11:46:07 +00:00
|
|
|
{"DEFAULT_HOME", NULL},
|
2007-11-20 09:33:52 +00:00
|
|
|
{"ENCRYPT_METHOD", NULL},
|
2007-10-07 11:46:52 +00:00
|
|
|
{"ENV_PATH", NULL},
|
|
|
|
{"ENV_SUPATH", NULL},
|
|
|
|
{"ERASECHAR", NULL},
|
2007-10-07 11:46:07 +00:00
|
|
|
{"FAIL_DELAY", NULL},
|
2007-10-07 11:46:52 +00:00
|
|
|
{"FAKE_SHELL", NULL},
|
|
|
|
{"GID_MAX", NULL},
|
|
|
|
{"GID_MIN", NULL},
|
2020-01-11 22:19:37 +01:00
|
|
|
{"HOME_MODE", NULL},
|
2007-10-07 11:46:52 +00:00
|
|
|
{"HUSHLOGIN_FILE", NULL},
|
|
|
|
{"KILLCHAR", NULL},
|
2018-11-28 14:57:16 +01:00
|
|
|
{"LASTLOG_UID_MAX", NULL},
|
2007-10-07 11:46:52 +00:00
|
|
|
{"LOGIN_RETRIES", NULL},
|
|
|
|
{"LOGIN_TIMEOUT", NULL},
|
|
|
|
{"LOG_OK_LOGINS", NULL},
|
|
|
|
{"LOG_UNKFAIL_ENAB", NULL},
|
|
|
|
{"MAIL_DIR", NULL},
|
2007-10-07 11:47:11 +00:00
|
|
|
{"MAIL_FILE", NULL},
|
2007-11-23 00:07:59 +00:00
|
|
|
{"MAX_MEMBERS_PER_GROUP", NULL},
|
2007-11-20 09:33:52 +00:00
|
|
|
{"MD5_CRYPT_ENAB", NULL},
|
2020-05-08 10:42:52 -04:00
|
|
|
{"NONEXISTENT", NULL},
|
2007-10-07 11:46:07 +00:00
|
|
|
{"PASS_MAX_DAYS", NULL},
|
|
|
|
{"PASS_MIN_DAYS", NULL},
|
|
|
|
{"PASS_WARN_AGE", NULL},
|
2008-05-19 20:58:59 +00:00
|
|
|
#ifdef USE_SHA_CRYPT
|
2007-11-20 09:33:52 +00:00
|
|
|
{"SHA_CRYPT_MAX_ROUNDS", NULL},
|
|
|
|
{"SHA_CRYPT_MIN_ROUNDS", NULL},
|
2019-09-16 20:54:56 +02:00
|
|
|
#endif
|
|
|
|
#ifdef USE_BCRYPT
|
|
|
|
{"BCRYPT_MAX_ROUNDS", NULL},
|
|
|
|
{"BCRYPT_MIN_ROUNDS", NULL},
|
2020-12-27 21:09:25 +01:00
|
|
|
#endif
|
|
|
|
#ifdef USE_YESCRYPT
|
|
|
|
{"YESCRYPT_COST_FACTOR", NULL},
|
2008-05-19 20:58:59 +00:00
|
|
|
#endif
|
2013-01-22 01:14:35 -08:00
|
|
|
{"SUB_GID_COUNT", NULL},
|
|
|
|
{"SUB_GID_MAX", NULL},
|
|
|
|
{"SUB_GID_MIN", NULL},
|
|
|
|
{"SUB_UID_COUNT", NULL},
|
|
|
|
{"SUB_UID_MAX", NULL},
|
|
|
|
{"SUB_UID_MIN", NULL},
|
2007-10-07 11:46:52 +00:00
|
|
|
{"SULOG_FILE", NULL},
|
|
|
|
{"SU_NAME", NULL},
|
2008-02-25 21:06:30 +00:00
|
|
|
{"SYS_GID_MAX", NULL},
|
|
|
|
{"SYS_GID_MIN", NULL},
|
|
|
|
{"SYS_UID_MAX", NULL},
|
|
|
|
{"SYS_UID_MIN", NULL},
|
2007-10-07 11:46:52 +00:00
|
|
|
{"TTYGROUP", NULL},
|
|
|
|
{"TTYPERM", NULL},
|
|
|
|
{"TTYTYPE_FILE", NULL},
|
|
|
|
{"UID_MAX", NULL},
|
|
|
|
{"UID_MIN", NULL},
|
|
|
|
{"UMASK", NULL},
|
2007-10-07 11:46:07 +00:00
|
|
|
{"USERDEL_CMD", NULL},
|
2007-10-07 11:46:52 +00:00
|
|
|
{"USERGROUPS_ENAB", NULL},
|
|
|
|
#ifndef USE_PAM
|
2015-02-27 12:39:44 +00:00
|
|
|
PAMDEFS
|
2007-10-07 11:44:14 +00:00
|
|
|
#endif
|
2007-10-07 11:46:07 +00:00
|
|
|
{"SYSLOG_SG_ENAB", NULL},
|
|
|
|
{"SYSLOG_SU_ENAB", NULL},
|
2010-01-30 Paweł Hajdan, Jr. <phajdan.jr@gentoo.org>
* NEWS: Add support for TCB.
* lib/tcbfuncs.h, lib/tcbfuncs.c, lib/Makefile.am: New library to
support TCB.
* lib/prototypes, libmisc/copydir.c (remove_tree): Add boolean
parameter remove_root.
* configure.in: Add conditional WITH_TCB.
* src/userdel.c, src/usermod.c: Add support for TCB. Update call to
remove_tree().
* src/pwconv.c, src/pwunconv.c: Should not be used with TCB enabled.
* src/vipw.c: Add support for TCB. Update call to remove_tree().
* src/useradd.c: Add support for TCB. Open the shadow file outside
of open_files().
* src/chage.c: Add support for TCB.
* src/Makefile.am: Install passwd sgid shadow when TCB is enabled.
* lib/getdefs.c, man/vipw.8.xml, man/login.defs.5.xml,
man/login.defs/TCB_AUTH_GROUP.xml, man/login.defs/USE_TCB.xml,
man/login.defs/TCB_SYMLINKS.xml, man/generate_mans.mak,
man/generate_mans.deps, man/Makefile.am: New configuration
parameters: TCB_AUTH_GROUP, TCB_SYMLINKS, USE_TCB.
* lib/shadowio.c, lib/commonio.c: Add support for TCB.
2010-03-04 18:11:13 +00:00
|
|
|
#ifdef WITH_TCB
|
|
|
|
{"TCB_AUTH_GROUP", NULL},
|
|
|
|
{"TCB_SYMLINKS", NULL},
|
|
|
|
{"USE_TCB", NULL},
|
2007-10-07 11:44:02 +00:00
|
|
|
#endif
|
2015-02-27 14:18:56 +00:00
|
|
|
{"FORCE_SHADOW", NULL},
|
2021-01-07 12:15:25 +01:00
|
|
|
{"GRANT_AUX_GROUP_SUBIDS", NULL},
|
2021-03-29 05:16:03 +02:00
|
|
|
{"PREVENT_NO_AUTH", NULL},
|
2007-10-07 11:46:16 +00:00
|
|
|
{NULL, NULL}
|
2007-10-07 11:44:02 +00:00
|
|
|
};
|
|
|
|
|
2015-02-27 12:39:44 +00:00
|
|
|
#define NUMKNOWNDEFS (sizeof(knowndef_table)/sizeof(knowndef_table[0]))
|
|
|
|
static struct itemdef knowndef_table[] = {
|
|
|
|
#ifdef USE_PAM
|
|
|
|
PAMDEFS
|
|
|
|
#endif
|
2020-10-08 12:17:30 +02:00
|
|
|
FOREIGNDEFS
|
2017-01-26 16:48:48 +01:00
|
|
|
{NULL, NULL}
|
2015-02-27 12:39:44 +00:00
|
|
|
};
|
|
|
|
|
2019-09-20 10:27:31 +02:00
|
|
|
#ifdef USE_ECONF
|
|
|
|
#ifdef VENDORDIR
|
|
|
|
static const char* vendordir = VENDORDIR;
|
|
|
|
#else
|
|
|
|
static const char* vendordir = NULL;
|
|
|
|
#endif
|
|
|
|
static const char* sysconfdir = "/etc";
|
|
|
|
#else
|
2007-10-07 11:44:02 +00:00
|
|
|
#ifndef LOGINDEFS
|
|
|
|
#define LOGINDEFS "/etc/login.defs"
|
|
|
|
#endif
|
|
|
|
|
2016-05-15 15:49:39 +02:00
|
|
|
static const char* def_fname = LOGINDEFS; /* login config defs file */
|
2019-09-20 10:27:31 +02:00
|
|
|
#endif
|
2008-05-25 21:43:05 +00:00
|
|
|
static bool def_loaded = false; /* are defs already loaded? */
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/* local function prototypes */
|
2009-04-23 11:46:46 +00:00
|
|
|
static /*@observer@*/ /*@null@*/struct itemdef *def_find (const char *);
|
2007-10-07 11:46:07 +00:00
|
|
|
static void def_load (void);
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
* getdef_str - get string value from table of definitions.
|
|
|
|
*
|
|
|
|
* Return point to static data for specified item, or NULL if item is not
|
|
|
|
* defined. First time invoked, will load definitions from the file.
|
|
|
|
*/
|
|
|
|
|
2009-04-23 11:46:46 +00:00
|
|
|
/*@observer@*/ /*@null@*/const char *getdef_str (const char *item)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
struct itemdef *d;
|
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
if (!def_loaded) {
|
2007-10-07 11:46:07 +00:00
|
|
|
def_load ();
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
d = def_find (item);
|
2023-02-01 13:50:48 +01:00
|
|
|
return (NULL == d) ? NULL : d->value;
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
* getdef_bool - get boolean value from table of definitions.
|
|
|
|
*
|
|
|
|
* Return TRUE if specified item is defined as "yes", else FALSE.
|
|
|
|
*/
|
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
bool getdef_bool (const char *item)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
struct itemdef *d;
|
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
if (!def_loaded) {
|
2007-10-07 11:46:07 +00:00
|
|
|
def_load ();
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
d = def_find (item);
|
|
|
|
if ((NULL == d) || (NULL == d->value)) {
|
|
|
|
return false;
|
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
return (strcasecmp (d->value, "yes") == 0);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
* getdef_num - get numerical value from table of definitions
|
|
|
|
*
|
|
|
|
* Returns numeric value of specified item, else the "dflt" value if
|
|
|
|
* the item is not defined. Octal (leading "0") and hex (leading "0x")
|
|
|
|
* values are handled.
|
|
|
|
*/
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
int getdef_num (const char *item, int dflt)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
struct itemdef *d;
|
2009-04-10 22:35:26 +00:00
|
|
|
long val;
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
if (!def_loaded) {
|
2007-10-07 11:46:07 +00:00
|
|
|
def_load ();
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
d = def_find (item);
|
|
|
|
if ((NULL == d) || (NULL == d->value)) {
|
2007-10-07 11:44:02 +00:00
|
|
|
return dflt;
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2009-04-10 22:35:26 +00:00
|
|
|
if ( (getlong (d->value, &val) == 0)
|
|
|
|
|| (val > INT_MAX)
|
|
|
|
|| (val < INT_MIN)) {
|
2021-05-08 17:42:14 -05:00
|
|
|
fprintf (shadow_logfd,
|
2009-04-10 22:35:26 +00:00
|
|
|
_("configuration error - cannot parse %s value: '%s'"),
|
|
|
|
item, d->value);
|
|
|
|
return dflt;
|
|
|
|
}
|
|
|
|
|
2023-02-01 13:50:48 +01:00
|
|
|
return val;
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2007-10-07 11:44:59 +00:00
|
|
|
/*
|
|
|
|
* getdef_unum - get unsigned numerical value from table of definitions
|
|
|
|
*
|
|
|
|
* Returns numeric value of specified item, else the "dflt" value if
|
|
|
|
* the item is not defined. Octal (leading "0") and hex (leading "0x")
|
|
|
|
* values are handled.
|
|
|
|
*/
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
unsigned int getdef_unum (const char *item, unsigned int dflt)
|
2007-10-07 11:44:59 +00:00
|
|
|
{
|
|
|
|
struct itemdef *d;
|
2009-04-10 22:35:26 +00:00
|
|
|
long val;
|
2007-10-07 11:44:59 +00:00
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
if (!def_loaded) {
|
2007-10-07 11:46:07 +00:00
|
|
|
def_load ();
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:59 +00:00
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
d = def_find (item);
|
|
|
|
if ((NULL == d) || (NULL == d->value)) {
|
2007-10-07 11:44:59 +00:00
|
|
|
return dflt;
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:59 +00:00
|
|
|
|
2009-04-10 22:35:26 +00:00
|
|
|
if ( (getlong (d->value, &val) == 0)
|
|
|
|
|| (val < 0)
|
|
|
|
|| (val > INT_MAX)) {
|
2021-05-08 17:42:14 -05:00
|
|
|
fprintf (shadow_logfd,
|
2009-04-10 22:35:26 +00:00
|
|
|
_("configuration error - cannot parse %s value: '%s'"),
|
|
|
|
item, d->value);
|
|
|
|
return dflt;
|
|
|
|
}
|
|
|
|
|
2023-02-01 13:50:48 +01:00
|
|
|
return val;
|
2007-10-07 11:44:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
/*
|
|
|
|
* getdef_long - get long integer value from table of definitions
|
|
|
|
*
|
|
|
|
* Returns numeric value of specified item, else the "dflt" value if
|
|
|
|
* the item is not defined. Octal (leading "0") and hex (leading "0x")
|
|
|
|
* values are handled.
|
|
|
|
*/
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
long getdef_long (const char *item, long dflt)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
struct itemdef *d;
|
2009-04-10 22:35:26 +00:00
|
|
|
long val;
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
if (!def_loaded) {
|
2007-10-07 11:46:07 +00:00
|
|
|
def_load ();
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
d = def_find (item);
|
|
|
|
if ((NULL == d) || (NULL == d->value)) {
|
2007-10-07 11:44:02 +00:00
|
|
|
return dflt;
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2009-04-10 22:35:26 +00:00
|
|
|
if (getlong (d->value, &val) == 0) {
|
2021-05-08 17:42:14 -05:00
|
|
|
fprintf (shadow_logfd,
|
2009-04-10 22:35:26 +00:00
|
|
|
_("configuration error - cannot parse %s value: '%s'"),
|
|
|
|
item, d->value);
|
|
|
|
return dflt;
|
|
|
|
}
|
|
|
|
|
|
|
|
return val;
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2008-06-13 21:35:22 +00:00
|
|
|
/*
|
|
|
|
* getdef_ulong - get unsigned long numerical value from table of definitions
|
|
|
|
*
|
|
|
|
* Returns numeric value of specified item, else the "dflt" value if
|
|
|
|
* the item is not defined. Octal (leading "0") and hex (leading "0x")
|
|
|
|
* values are handled.
|
|
|
|
*/
|
|
|
|
|
2008-06-14 21:09:33 +00:00
|
|
|
unsigned long getdef_ulong (const char *item, unsigned long dflt)
|
2008-06-13 21:35:22 +00:00
|
|
|
{
|
|
|
|
struct itemdef *d;
|
2009-04-23 11:46:46 +00:00
|
|
|
unsigned long val;
|
2008-06-13 21:35:22 +00:00
|
|
|
|
|
|
|
if (!def_loaded) {
|
|
|
|
def_load ();
|
|
|
|
}
|
|
|
|
|
|
|
|
d = def_find (item);
|
|
|
|
if ((NULL == d) || (NULL == d->value)) {
|
|
|
|
return dflt;
|
|
|
|
}
|
|
|
|
|
2009-04-23 11:46:46 +00:00
|
|
|
if (getulong (d->value, &val) == 0) {
|
2021-05-08 17:42:14 -05:00
|
|
|
fprintf (shadow_logfd,
|
2009-04-10 22:35:26 +00:00
|
|
|
_("configuration error - cannot parse %s value: '%s'"),
|
|
|
|
item, d->value);
|
|
|
|
return dflt;
|
|
|
|
}
|
|
|
|
|
|
|
|
return val;
|
2008-06-13 21:35:22 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* putdef_str - override the value read from /etc/login.defs
|
|
|
|
* (also used when loading the initial defaults)
|
|
|
|
*/
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
int putdef_str (const char *name, const char *value)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
struct itemdef *d;
|
|
|
|
char *cp;
|
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
if (!def_loaded) {
|
2007-10-07 11:46:07 +00:00
|
|
|
def_load ();
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Locate the slot to save the value. If this parameter
|
|
|
|
* is unknown then "def_find" will print an err message.
|
|
|
|
*/
|
2008-05-25 21:43:05 +00:00
|
|
|
d = def_find (name);
|
|
|
|
if (NULL == d) {
|
2007-10-07 11:44:02 +00:00
|
|
|
return -1;
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Save off the value.
|
|
|
|
*/
|
2008-05-25 21:43:05 +00:00
|
|
|
cp = strdup (value);
|
|
|
|
if (NULL == cp) {
|
2009-04-23 11:46:46 +00:00
|
|
|
(void) fputs (_("Could not allocate space for config info.\n"),
|
2021-05-08 17:42:14 -05:00
|
|
|
shadow_logfd);
|
2007-10-07 11:46:07 +00:00
|
|
|
SYSLOG ((LOG_ERR, "could not allocate space for config info"));
|
2007-10-07 11:44:02 +00:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2022-09-28 22:03:52 +02:00
|
|
|
free (d->value);
|
2007-10-07 11:44:02 +00:00
|
|
|
d->value = cp;
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
/*
|
|
|
|
* def_find - locate named item in table
|
|
|
|
*
|
2007-10-07 11:46:16 +00:00
|
|
|
* Search through a table of configurable items to locate the
|
2007-10-07 11:44:02 +00:00
|
|
|
* specified configuration option.
|
|
|
|
*/
|
|
|
|
|
2009-04-23 11:46:46 +00:00
|
|
|
static /*@observer@*/ /*@null@*/struct itemdef *def_find (const char *name)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:16 +00:00
|
|
|
struct itemdef *ptr;
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
2007-10-07 11:46:16 +00:00
|
|
|
* Search into the table.
|
2007-10-07 11:44:02 +00:00
|
|
|
*/
|
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
for (ptr = def_table; NULL != ptr->name; ptr++) {
|
|
|
|
if (strcmp (ptr->name, name) == 0) {
|
2007-10-07 11:46:16 +00:00
|
|
|
return ptr;
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:46:25 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Item was never found.
|
|
|
|
*/
|
|
|
|
|
2015-02-27 12:39:44 +00:00
|
|
|
for (ptr = knowndef_table; NULL != ptr->name; ptr++) {
|
|
|
|
if (strcmp (ptr->name, name) == 0) {
|
|
|
|
goto out;
|
|
|
|
}
|
|
|
|
}
|
2021-05-08 17:42:14 -05:00
|
|
|
fprintf (shadow_logfd,
|
2009-04-10 22:35:26 +00:00
|
|
|
_("configuration error - unknown item '%s' (notify administrator)\n"),
|
|
|
|
name);
|
2007-10-07 11:46:07 +00:00
|
|
|
SYSLOG ((LOG_CRIT, "unknown configuration item `%s'", name));
|
2015-02-27 12:39:44 +00:00
|
|
|
|
|
|
|
out:
|
2023-02-01 13:50:48 +01:00
|
|
|
return NULL;
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2016-05-15 15:49:39 +02:00
|
|
|
/*
|
|
|
|
* setdef_config_file - set the default configuration file path
|
|
|
|
*
|
|
|
|
* must be called prior to any def* calls.
|
|
|
|
*/
|
|
|
|
|
|
|
|
void setdef_config_file (const char* file)
|
|
|
|
{
|
2019-09-20 10:27:31 +02:00
|
|
|
#ifdef USE_ECONF
|
|
|
|
size_t len;
|
|
|
|
char* cp;
|
|
|
|
|
|
|
|
len = strlen(file) + strlen(sysconfdir) + 2;
|
2023-02-04 22:41:18 +01:00
|
|
|
cp = MALLOCARRAY(len, char);
|
2019-09-20 10:27:31 +02:00
|
|
|
if (cp == NULL)
|
|
|
|
exit (13);
|
|
|
|
snprintf(cp, len, "%s/%s", file, sysconfdir);
|
|
|
|
sysconfdir = cp;
|
|
|
|
#ifdef VENDORDIR
|
|
|
|
len = strlen(file) + strlen(vendordir) + 2;
|
2023-02-04 22:41:18 +01:00
|
|
|
cp = MALLOCARRAY(len, char);
|
2019-09-20 10:27:31 +02:00
|
|
|
if (cp == NULL)
|
|
|
|
exit (13);
|
|
|
|
snprintf(cp, len, "%s/%s", file, vendordir);
|
|
|
|
vendordir = cp;
|
|
|
|
#endif
|
|
|
|
#else
|
2016-05-15 15:49:39 +02:00
|
|
|
def_fname = file;
|
2019-09-20 10:27:31 +02:00
|
|
|
#endif
|
2016-05-15 15:49:39 +02:00
|
|
|
}
|
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
/*
|
|
|
|
* def_load - load configuration table
|
|
|
|
*
|
|
|
|
* Loads the user-configured options from the default configuration file
|
|
|
|
*/
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
static void def_load (void)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2019-09-20 10:27:31 +02:00
|
|
|
#ifdef USE_ECONF
|
|
|
|
econf_file *defs_file = NULL;
|
|
|
|
econf_err error;
|
|
|
|
char **keys;
|
|
|
|
size_t key_number;
|
|
|
|
#else
|
2007-10-07 11:44:02 +00:00
|
|
|
int i;
|
|
|
|
FILE *fp;
|
|
|
|
char buf[1024], *name, *value, *s;
|
2019-09-20 10:27:31 +02:00
|
|
|
#endif
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2015-02-27 11:23:58 +00:00
|
|
|
/*
|
|
|
|
* Set the initialized flag.
|
|
|
|
* (do it early to prevent recursion in putdef_str())
|
|
|
|
*/
|
|
|
|
def_loaded = true;
|
|
|
|
|
2019-09-20 10:27:31 +02:00
|
|
|
#ifdef USE_ECONF
|
|
|
|
|
|
|
|
error = econf_readDirs (&defs_file, vendordir, sysconfdir, "login", "defs", " \t", "#");
|
|
|
|
if (error) {
|
|
|
|
if (error == ECONF_NOFILE)
|
|
|
|
return;
|
|
|
|
|
|
|
|
SYSLOG ((LOG_CRIT, "cannot open login definitions [%s]",
|
|
|
|
econf_errString(error)));
|
|
|
|
exit (EXIT_FAILURE);
|
|
|
|
}
|
|
|
|
|
|
|
|
if ((error = econf_getKeys(defs_file, NULL, &key_number, &keys))) {
|
|
|
|
SYSLOG ((LOG_CRIT, "cannot read login definitions [%s]",
|
|
|
|
econf_errString(error)));
|
|
|
|
exit (EXIT_FAILURE);
|
|
|
|
}
|
|
|
|
|
|
|
|
for (size_t i = 0; i < key_number; i++) {
|
|
|
|
char *value;
|
|
|
|
|
|
|
|
econf_getStringValue(defs_file, NULL, keys[i], &value);
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Store the value in def_table.
|
|
|
|
*
|
|
|
|
* Ignore failures to load the login.defs file.
|
|
|
|
* The error was already reported to the user and to
|
|
|
|
* syslog. The tools will just use their default values.
|
|
|
|
*/
|
|
|
|
(void)putdef_str (keys[i], value);
|
|
|
|
}
|
|
|
|
|
|
|
|
econf_free (keys);
|
|
|
|
econf_free (defs_file);
|
|
|
|
#else
|
2007-10-07 11:44:02 +00:00
|
|
|
/*
|
|
|
|
* Open the configuration definitions file.
|
|
|
|
*/
|
2008-05-25 21:43:05 +00:00
|
|
|
fp = fopen (def_fname, "r");
|
|
|
|
if (NULL == fp) {
|
2015-02-27 11:23:58 +00:00
|
|
|
if (errno == ENOENT)
|
|
|
|
return;
|
|
|
|
|
2008-09-13 18:03:50 +00:00
|
|
|
int err = errno;
|
|
|
|
SYSLOG ((LOG_CRIT, "cannot open login definitions %s [%s]",
|
|
|
|
def_fname, strerror (err)));
|
2009-04-23 11:46:46 +00:00
|
|
|
exit (EXIT_FAILURE);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Go through all of the lines in the file.
|
|
|
|
*/
|
2023-02-01 13:50:48 +01:00
|
|
|
while (fgets (buf, sizeof (buf), fp) != NULL) {
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Trim trailing whitespace.
|
|
|
|
*/
|
2023-02-01 13:50:48 +01:00
|
|
|
for (i = (ptrdiff_t) strlen (buf) - 1; i >= 0; --i) {
|
2008-05-25 21:43:05 +00:00
|
|
|
if (!isspace (buf[i])) {
|
2007-10-07 11:44:02 +00:00
|
|
|
break;
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2008-06-13 21:35:22 +00:00
|
|
|
i++;
|
|
|
|
buf[i] = '\0';
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Break the line into two fields.
|
|
|
|
*/
|
2007-10-07 11:46:07 +00:00
|
|
|
name = buf + strspn (buf, " \t"); /* first nonwhite */
|
2007-10-07 11:44:02 +00:00
|
|
|
if (*name == '\0' || *name == '#')
|
2007-10-07 11:46:07 +00:00
|
|
|
continue; /* comment or empty */
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
s = name + strcspn (name, " \t"); /* end of field */
|
2007-10-07 11:44:02 +00:00
|
|
|
if (*s == '\0')
|
2007-10-07 11:46:07 +00:00
|
|
|
continue; /* only 1 field?? */
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
*s++ = '\0';
|
2007-10-07 11:46:07 +00:00
|
|
|
value = s + strspn (s, " \"\t"); /* next nonwhite */
|
|
|
|
*(value + strcspn (value, "\"")) = '\0';
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Store the value in def_table.
|
2009-04-23 11:46:46 +00:00
|
|
|
*
|
|
|
|
* Ignore failures to load the login.defs file.
|
|
|
|
* The error was already reported to the user and to
|
|
|
|
* syslog. The tools will just use their default values.
|
2007-10-07 11:44:02 +00:00
|
|
|
*/
|
2009-04-23 11:46:46 +00:00
|
|
|
(void)putdef_str (name, value);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2007-10-07 11:45:40 +00:00
|
|
|
|
2008-05-25 21:43:05 +00:00
|
|
|
if (ferror (fp) != 0) {
|
2008-09-13 18:03:50 +00:00
|
|
|
int err = errno;
|
|
|
|
SYSLOG ((LOG_CRIT, "cannot read login definitions %s [%s]",
|
|
|
|
def_fname, strerror (err)));
|
2009-04-23 11:46:46 +00:00
|
|
|
exit (EXIT_FAILURE);
|
2007-10-07 11:45:40 +00:00
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
(void) fclose (fp);
|
2019-09-20 10:27:31 +02:00
|
|
|
#endif
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
#ifdef CKDEFS
|
2007-10-07 11:46:07 +00:00
|
|
|
int main (int argc, char **argv)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
int i;
|
|
|
|
char *cp;
|
|
|
|
struct itemdef *d;
|
|
|
|
|
|
|
|
def_load ();
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
for (i = 0; i < NUMDEFS; ++i) {
|
2008-05-25 21:43:05 +00:00
|
|
|
d = def_find (def_table[i].name);
|
|
|
|
if (NULL == d) {
|
2007-10-07 11:46:07 +00:00
|
|
|
printf ("error - lookup '%s' failed\n",
|
2008-05-25 21:43:05 +00:00
|
|
|
def_table[i].name);
|
|
|
|
} else {
|
2007-10-07 11:46:07 +00:00
|
|
|
printf ("%4d %-24s %s\n", i + 1, d->name, d->value);
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2007-10-07 11:46:07 +00:00
|
|
|
for (i = 1; i < argc; i++) {
|
2008-05-25 21:43:05 +00:00
|
|
|
cp = getdef_str (argv[1]);
|
|
|
|
if (NULL != cp) {
|
2007-10-07 11:44:02 +00:00
|
|
|
printf ("%s `%s'\n", argv[1], cp);
|
2008-05-25 21:43:05 +00:00
|
|
|
} else {
|
2007-10-07 11:45:23 +00:00
|
|
|
printf ("%s not found\n", argv[1]);
|
2008-05-25 21:43:05 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2009-04-23 11:46:46 +00:00
|
|
|
exit (EXIT_SUCCESS);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
#endif
|