2008-04-27 00:40:09 +00:00
|
|
|
/*
|
|
|
|
* Copyright (c) 1996 - 2000, Marek Michałkiewicz
|
|
|
|
* Copyright (c) 2002 - 2006, Tomasz Kłoczko
|
|
|
|
* All rights reserved.
|
|
|
|
*
|
|
|
|
* Redistribution and use in source and binary forms, with or without
|
|
|
|
* modification, are permitted provided that the following conditions
|
|
|
|
* are met:
|
|
|
|
* 1. Redistributions of source code must retain the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer.
|
|
|
|
* 2. Redistributions in binary form must reproduce the above copyright
|
|
|
|
* notice, this list of conditions and the following disclaimer in the
|
|
|
|
* documentation and/or other materials provided with the distribution.
|
|
|
|
* 3. The name of the copyright holders or contributors may not be used to
|
|
|
|
* endorse or promote products derived from this software without
|
|
|
|
* specific prior written permission.
|
|
|
|
*
|
|
|
|
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
|
|
|
* ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
|
|
|
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
|
|
|
|
* PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
|
|
|
|
* HOLDERS OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
|
|
|
|
* SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
|
|
|
|
* LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
|
|
|
|
* DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
|
|
|
|
* THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
|
|
|
|
* (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
|
|
|
|
* OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
|
|
|
*/
|
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
/*
|
|
|
|
* grpconv - create or update /etc/gshadow with information from
|
|
|
|
* /etc/group.
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
|
|
|
#include <config.h>
|
2007-11-10 23:46:11 +00:00
|
|
|
#ident "$Id$"
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
#include <errno.h>
|
2007-10-07 11:47:01 +00:00
|
|
|
#include <fcntl.h>
|
|
|
|
#include <grp.h>
|
|
|
|
#include <stdio.h>
|
2007-10-07 11:44:02 +00:00
|
|
|
#include <stdlib.h>
|
|
|
|
#include <string.h>
|
|
|
|
#include <time.h>
|
|
|
|
#include <unistd.h>
|
2007-10-07 11:47:22 +00:00
|
|
|
#include "nscd.h"
|
2007-10-07 11:44:02 +00:00
|
|
|
#include "prototypes.h"
|
|
|
|
#ifdef SHADOWGRP
|
|
|
|
#include "groupio.h"
|
|
|
|
#include "sgroupio.h"
|
2007-10-07 11:47:01 +00:00
|
|
|
/*
|
|
|
|
* Global variables
|
|
|
|
*/
|
2008-06-10 19:18:34 +00:00
|
|
|
static bool group_locked = false;
|
|
|
|
static bool gshadow_locked = false;
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
/* local function prototypes */
|
2007-10-07 11:44:59 +00:00
|
|
|
static void fail_exit (int);
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2007-10-07 11:44:59 +00:00
|
|
|
static void fail_exit (int status)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2008-06-10 19:18:34 +00:00
|
|
|
if (group_locked) {
|
2007-10-07 11:44:59 +00:00
|
|
|
gr_unlock ();
|
2008-06-10 19:18:34 +00:00
|
|
|
}
|
|
|
|
if (gshadow_locked) {
|
2007-10-07 11:44:59 +00:00
|
|
|
sgr_unlock ();
|
2008-06-10 19:18:34 +00:00
|
|
|
}
|
2007-10-07 11:44:59 +00:00
|
|
|
exit (status);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2007-10-07 11:44:59 +00:00
|
|
|
int main (int argc, char **argv)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
const struct group *gr;
|
|
|
|
struct group grent;
|
|
|
|
const struct sgrp *sg;
|
|
|
|
struct sgrp sgent;
|
|
|
|
char *Prog = argv[0];
|
|
|
|
|
2008-06-10 19:18:34 +00:00
|
|
|
(void) setlocale (LC_ALL, "");
|
|
|
|
(void) bindtextdomain (PACKAGE, LOCALEDIR);
|
|
|
|
(void) textdomain (PACKAGE);
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2008-06-10 19:18:34 +00:00
|
|
|
if (gr_lock () == 0) {
|
2007-10-07 11:44:59 +00:00
|
|
|
fprintf (stderr, _("%s: can't lock group file\n"), Prog);
|
|
|
|
fail_exit (5);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2008-06-10 19:18:34 +00:00
|
|
|
group_locked = true;
|
|
|
|
if (gr_open (O_RDWR) == 0) {
|
2007-10-07 11:44:59 +00:00
|
|
|
fprintf (stderr, _("%s: can't open group file\n"), Prog);
|
|
|
|
fail_exit (1);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2008-06-10 19:18:34 +00:00
|
|
|
if (sgr_lock () == 0) {
|
2007-10-07 11:46:07 +00:00
|
|
|
fprintf (stderr, _("%s: can't lock shadow group file\n"), Prog);
|
2007-10-07 11:44:59 +00:00
|
|
|
fail_exit (5);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2008-06-10 19:18:34 +00:00
|
|
|
gshadow_locked = true;
|
|
|
|
if (sgr_open (O_CREAT | O_RDWR) == 0) {
|
2007-10-07 11:46:07 +00:00
|
|
|
fprintf (stderr, _("%s: can't open shadow group file\n"), Prog);
|
2007-10-07 11:44:59 +00:00
|
|
|
fail_exit (1);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Remove /etc/gshadow entries for groups not in /etc/group.
|
|
|
|
*/
|
2007-10-07 11:44:59 +00:00
|
|
|
sgr_rewind ();
|
2008-06-10 19:18:34 +00:00
|
|
|
while ((sg = sgr_next ()) != NULL) {
|
|
|
|
if (gr_locate (sg->sg_name) != NULL) {
|
2007-10-07 11:44:02 +00:00
|
|
|
continue;
|
2008-06-10 19:18:34 +00:00
|
|
|
}
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2008-06-10 19:18:34 +00:00
|
|
|
if (sgr_remove (sg->sg_name) == 0) {
|
2007-10-07 11:44:02 +00:00
|
|
|
/*
|
|
|
|
* This shouldn't happen (the entry exists) but...
|
|
|
|
*/
|
2007-10-07 11:44:59 +00:00
|
|
|
fprintf (stderr,
|
|
|
|
_("%s: can't remove shadow group %s\n"),
|
|
|
|
Prog, sg->sg_name);
|
|
|
|
fail_exit (3);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Update shadow group passwords if non-shadow password is not "x".
|
|
|
|
* Add any missing shadow group entries.
|
|
|
|
*/
|
2007-10-07 11:44:59 +00:00
|
|
|
gr_rewind ();
|
2008-06-10 19:18:34 +00:00
|
|
|
while ((gr = gr_next ()) != NULL) {
|
2007-10-07 11:44:59 +00:00
|
|
|
sg = sgr_locate (gr->gr_name);
|
2008-06-10 19:18:34 +00:00
|
|
|
if (NULL != sg) {
|
2007-10-07 11:44:02 +00:00
|
|
|
/* update existing shadow group entry */
|
|
|
|
sgent = *sg;
|
2007-10-07 11:46:07 +00:00
|
|
|
if (strcmp (gr->gr_passwd, SHADOW_PASSWD_STRING) != 0)
|
2007-10-07 11:44:02 +00:00
|
|
|
sgent.sg_passwd = gr->gr_passwd;
|
|
|
|
} else {
|
|
|
|
static char *empty = 0;
|
|
|
|
|
|
|
|
/* add new shadow group entry */
|
2007-10-07 11:44:59 +00:00
|
|
|
memset (&sgent, 0, sizeof sgent);
|
2007-10-07 11:44:02 +00:00
|
|
|
sgent.sg_name = gr->gr_name;
|
|
|
|
sgent.sg_passwd = gr->gr_passwd;
|
|
|
|
sgent.sg_adm = ∅
|
|
|
|
}
|
|
|
|
/*
|
|
|
|
* XXX - sg_mem is redundant, it is currently always a copy
|
2007-10-07 11:44:59 +00:00
|
|
|
* of gr_mem. Very few programs actually use sg_mem, and all
|
|
|
|
* of them are in the shadow suite. Maybe this field could
|
|
|
|
* be used for something else? Any suggestions?
|
2007-10-07 11:44:02 +00:00
|
|
|
*/
|
|
|
|
sgent.sg_mem = gr->gr_mem;
|
|
|
|
|
2008-06-10 19:18:34 +00:00
|
|
|
if (sgr_update (&sgent) == 0) {
|
2007-10-07 11:44:59 +00:00
|
|
|
fprintf (stderr,
|
|
|
|
_
|
|
|
|
("%s: can't update shadow entry for %s\n"),
|
|
|
|
Prog, sgent.sg_name);
|
|
|
|
fail_exit (3);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
/* remove password from /etc/group */
|
|
|
|
grent = *gr;
|
2007-10-07 11:44:59 +00:00
|
|
|
grent.gr_passwd = SHADOW_PASSWD_STRING; /* XXX warning: const */
|
2008-06-10 19:18:34 +00:00
|
|
|
if (gr_update (&grent) == 0) {
|
2007-10-07 11:44:59 +00:00
|
|
|
fprintf (stderr,
|
|
|
|
_
|
|
|
|
("%s: can't update entry for group %s\n"),
|
|
|
|
Prog, grent.gr_name);
|
|
|
|
fail_exit (3);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2008-06-10 19:18:34 +00:00
|
|
|
if (sgr_close () == 0) {
|
2007-10-07 11:44:59 +00:00
|
|
|
fprintf (stderr, _("%s: can't update shadow group file\n"),
|
|
|
|
Prog);
|
|
|
|
fail_exit (3);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2008-06-10 19:18:34 +00:00
|
|
|
if (gr_close () == 0) {
|
2007-10-07 11:44:59 +00:00
|
|
|
fprintf (stderr, _("%s: can't update group file\n"), Prog);
|
|
|
|
fail_exit (3);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2007-10-07 11:44:59 +00:00
|
|
|
sgr_unlock ();
|
|
|
|
gr_unlock ();
|
2007-10-07 11:46:52 +00:00
|
|
|
|
|
|
|
nscd_flush_cache ("group");
|
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
return 0;
|
|
|
|
}
|
2007-10-07 11:44:59 +00:00
|
|
|
#else /* !SHADOWGRP */
|
|
|
|
int main (int argc, char **argv)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:44:59 +00:00
|
|
|
fprintf (stderr,
|
2007-10-07 11:46:07 +00:00
|
|
|
"%s: not configured for shadow group support.\n", argv[0]);
|
2007-10-07 11:44:59 +00:00
|
|
|
exit (1);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2007-10-07 11:44:59 +00:00
|
|
|
#endif /* !SHADOWGRP */
|
2008-04-27 00:40:09 +00:00
|
|
|
|