2008-04-27 00:40:09 +00:00
|
|
|
/*
|
2021-12-05 09:35:27 -06:00
|
|
|
* SPDX-FileCopyrightText: 1990 - 1994, Julianne Frances Haugh
|
|
|
|
* SPDX-FileCopyrightText: 1996 - 2000, Marek Michałkiewicz
|
|
|
|
* SPDX-FileCopyrightText: 2001 , Michał Moskal
|
|
|
|
* SPDX-FileCopyrightText: 2003 - 2005, Tomasz Kłoczko
|
|
|
|
* SPDX-FileCopyrightText: 2007 - 2009, Nicolas François
|
2008-04-27 00:40:09 +00:00
|
|
|
*
|
2021-12-05 09:35:27 -06:00
|
|
|
* SPDX-License-Identifier: BSD-3-Clause
|
2008-04-27 00:40:09 +00:00
|
|
|
*/
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
#include <config.h>
|
|
|
|
|
2007-11-10 23:46:11 +00:00
|
|
|
#ident "$Id$"
|
2007-10-07 11:47:01 +00:00
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
#include "prototypes.h"
|
|
|
|
#include "defines.h"
|
|
|
|
#include <pwd.h>
|
|
|
|
#include <stdio.h>
|
|
|
|
#include "commonio.h"
|
|
|
|
#include "pwio.h"
|
|
|
|
|
* libmisc/xgetXXbyYY.c, libmisc/myname.c, libmisc/getgr_nam_gid.c,
libmisc/salt.c, libmisc/list.c, libmisc/cleanup.c, src/login.c,
lib/getdef.h, lib/groupio.c, lib/getlong.c, lib/gshadow_.h,
lib/sgroupio.c, lib/shadowio.c, lib/pwio.c, lib/commonio.h,
lib/fputsx.c, lib/prototypes.h: Added splint annotations.
* lib/groupio.c: Avoid implicit conversion of pointers to
booleans.
* lib/groupio.c: Free allocated buffers in case of failure.
2009-04-23 09:57:03 +00:00
|
|
|
static /*@null@*/ /*@only@*/void *passwd_dup (const void *ent)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
const struct passwd *pw = ent;
|
2007-10-07 11:46:07 +00:00
|
|
|
|
|
|
|
return __pw_dup (pw);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
* libmisc/utmp.c, libmisc/age.c, libmisc/shell.c, lib/groupio.c,
lib/groupio.h, lib/sgroupio.c, lib/sgroupio.h, lib/shadowio.c,
lib/pwio.c, lib/commonio.c, lib/shadowio.h, lib/pwio.h,
lib/commonio.h, lib/prototypes.h: Added splint annotations.
2009-04-22 21:21:14 +00:00
|
|
|
static void passwd_free (/*@out@*/ /*@only@*/void *ent)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
struct passwd *pw = ent;
|
|
|
|
|
2009-04-21 22:14:10 +00:00
|
|
|
pw_free (pw);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
static const char *passwd_getname (const void *ent)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
const struct passwd *pw = ent;
|
2007-10-07 11:46:07 +00:00
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
return pw->pw_name;
|
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
static void *passwd_parse (const char *line)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
return (void *) sgetpwent (line);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
static int passwd_put (const void *ent, FILE * file)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
const struct passwd *pw = ent;
|
2007-10-07 11:46:07 +00:00
|
|
|
|
2011-02-16 20:32:16 +00:00
|
|
|
if ( (NULL == pw)
|
|
|
|
|| (valid_field (pw->pw_name, ":\n") == -1)
|
|
|
|
|| (valid_field (pw->pw_passwd, ":\n") == -1)
|
|
|
|
|| (pw->pw_uid == (uid_t)-1)
|
|
|
|
|| (pw->pw_gid == (gid_t)-1)
|
|
|
|
|| (valid_field (pw->pw_gecos, ":\n") == -1)
|
|
|
|
|| (valid_field (pw->pw_dir, ":\n") == -1)
|
2022-10-07 12:36:59 +02:00
|
|
|
|| (valid_field (pw->pw_shell, ":\n") == -1)
|
|
|
|
|| (strlen (pw->pw_name) + strlen (pw->pw_passwd) +
|
|
|
|
strlen (pw->pw_gecos) + strlen (pw->pw_dir) +
|
|
|
|
strlen (pw->pw_shell) + 100 > PASSWD_ENTRY_MAX_LENGTH)) {
|
2011-02-16 20:32:16 +00:00
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
return (putpwent (pw, file) == -1) ? -1 : 0;
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
static struct commonio_ops passwd_ops = {
|
|
|
|
passwd_dup,
|
|
|
|
passwd_free,
|
|
|
|
passwd_getname,
|
|
|
|
passwd_parse,
|
|
|
|
passwd_put,
|
|
|
|
fgets,
|
2007-11-23 00:07:59 +00:00
|
|
|
fputs,
|
|
|
|
NULL, /* open_hook */
|
|
|
|
NULL /* close_hook */
|
2007-10-07 11:44:02 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
static struct commonio_db passwd_db = {
|
2007-10-07 11:46:07 +00:00
|
|
|
PASSWD_FILE, /* filename */
|
|
|
|
&passwd_ops, /* ops */
|
|
|
|
NULL, /* fp */
|
2007-11-19 20:25:36 +00:00
|
|
|
#ifdef WITH_SELINUX
|
|
|
|
NULL, /* scontext */
|
|
|
|
#endif
|
2015-02-27 16:26:57 +00:00
|
|
|
0644, /* st_mode */
|
|
|
|
0, /* st_uid */
|
|
|
|
0, /* st_gid */
|
2007-10-07 11:46:07 +00:00
|
|
|
NULL, /* head */
|
|
|
|
NULL, /* tail */
|
|
|
|
NULL, /* cursor */
|
2008-05-26 08:49:44 +00:00
|
|
|
false, /* changed */
|
|
|
|
false, /* isopen */
|
|
|
|
false, /* locked */
|
2019-05-02 14:33:06 +02:00
|
|
|
false, /* readonly */
|
|
|
|
false /* setname */
|
2007-10-07 11:44:02 +00:00
|
|
|
};
|
|
|
|
|
* lib/groupio.c, lib/groupio.h, lib/pwio.c, lib/pwio.h,
lib/sgroupio.c, lib/sgroupio.h, lib/shadowio.c, lib/shadowio.h:
Added *_dbname() functions to retrieve the name of the databases.
* lib/groupio.c, lib/groupio.h, lib/pwio.c, lib/pwio.h,
lib/sgroupio.c, lib/sgroupio.h, lib/shadowio.c, lib/shadowio.h:
*_name() functions renamed *setname().
* src/grpck.c, src/pwck.c: Likewise.
* lib/groupio.h, lib/pwio.h, lib/sgroupio.h, lib/shadowio.h: Added
the name of the arguments to the prototypes.
* src/chage, src/chfn.c, src/chgpasswd.c, src/chpasswd.c,
src/chsh.c, src/gpasswd.c, src/groupadd.c, src/groupdel.c,
src/groupmod.c, src/grpck.c, src/grpconv.c, src/grpunconv.c,
src/newusers.c, src/passwd.c, src/pwck.c, src/pwconv.c,
src/pwunconv.c, src/useradd.c, src/userdel.c, src/usermod.c:
Harmonize the erro & syslog messages in case of failure of the
*_lock(), *_open(), *_close(), *_unlock(), *_remove() functions.
* src/chgpasswd.c, src/chpasswd.c, src/usermod.c: Avoid
capitalized messages.
* src/chpasswd.c, src/useradd.c, src/usermod.c: Harmonize messages
in case of inexistent entries.
* src/usermod.c: Harmonize messages in case of already existing
entries.
* src/newusers.c, src/useradd.c: Simplify PAM error handling.
* src/useradd.c: Report failures to unlock files (stderr, syslog,
and audit). But do not fail (continue).
* src/useradd.c (open_files): Do not report to syslog & audit
failures to lock or open the databases. This might be harmless,
and the logs were not already informed that a change was
requested.
* src/usermod.c: It's not the account which is unlocked, but its
password.
2008-08-06 15:57:31 +00:00
|
|
|
int pw_setdbname (const char *filename)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
return commonio_setname (&passwd_db, filename);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
* libmisc/utmp.c, libmisc/age.c, libmisc/shell.c, lib/groupio.c,
lib/groupio.h, lib/sgroupio.c, lib/sgroupio.h, lib/shadowio.c,
lib/pwio.c, lib/commonio.c, lib/shadowio.h, lib/pwio.h,
lib/commonio.h, lib/prototypes.h: Added splint annotations.
2009-04-22 21:21:14 +00:00
|
|
|
/*@observer@*/const char *pw_dbname (void)
|
* lib/groupio.c, lib/groupio.h, lib/pwio.c, lib/pwio.h,
lib/sgroupio.c, lib/sgroupio.h, lib/shadowio.c, lib/shadowio.h:
Added *_dbname() functions to retrieve the name of the databases.
* lib/groupio.c, lib/groupio.h, lib/pwio.c, lib/pwio.h,
lib/sgroupio.c, lib/sgroupio.h, lib/shadowio.c, lib/shadowio.h:
*_name() functions renamed *setname().
* src/grpck.c, src/pwck.c: Likewise.
* lib/groupio.h, lib/pwio.h, lib/sgroupio.h, lib/shadowio.h: Added
the name of the arguments to the prototypes.
* src/chage, src/chfn.c, src/chgpasswd.c, src/chpasswd.c,
src/chsh.c, src/gpasswd.c, src/groupadd.c, src/groupdel.c,
src/groupmod.c, src/grpck.c, src/grpconv.c, src/grpunconv.c,
src/newusers.c, src/passwd.c, src/pwck.c, src/pwconv.c,
src/pwunconv.c, src/useradd.c, src/userdel.c, src/usermod.c:
Harmonize the erro & syslog messages in case of failure of the
*_lock(), *_open(), *_close(), *_unlock(), *_remove() functions.
* src/chgpasswd.c, src/chpasswd.c, src/usermod.c: Avoid
capitalized messages.
* src/chpasswd.c, src/useradd.c, src/usermod.c: Harmonize messages
in case of inexistent entries.
* src/usermod.c: Harmonize messages in case of already existing
entries.
* src/newusers.c, src/useradd.c: Simplify PAM error handling.
* src/useradd.c: Report failures to unlock files (stderr, syslog,
and audit). But do not fail (continue).
* src/useradd.c (open_files): Do not report to syslog & audit
failures to lock or open the databases. This might be harmless,
and the logs were not already informed that a change was
requested.
* src/usermod.c: It's not the account which is unlocked, but its
password.
2008-08-06 15:57:31 +00:00
|
|
|
{
|
|
|
|
return passwd_db.filename;
|
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
int pw_lock (void)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
return commonio_lock (&passwd_db);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
int pw_open (int mode)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
return commonio_open (&passwd_db, mode);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2009-04-23 21:19:02 +00:00
|
|
|
/*@observer@*/ /*@null@*/const struct passwd *pw_locate (const char *name)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
return commonio_locate (&passwd_db, name);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2009-04-23 21:19:02 +00:00
|
|
|
/*@observer@*/ /*@null@*/const struct passwd *pw_locate_uid (uid_t uid)
|
2008-02-03 16:50:14 +00:00
|
|
|
{
|
|
|
|
const struct passwd *pwd;
|
|
|
|
|
|
|
|
pw_rewind ();
|
|
|
|
while ( ((pwd = pw_next ()) != NULL)
|
|
|
|
&& (pwd->pw_uid != uid)) {
|
|
|
|
}
|
|
|
|
|
|
|
|
return pwd;
|
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
int pw_update (const struct passwd *pw)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
return commonio_update (&passwd_db, (const void *) pw);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
int pw_remove (const char *name)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
return commonio_remove (&passwd_db, name);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
int pw_rewind (void)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
return commonio_rewind (&passwd_db);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2009-04-23 21:19:02 +00:00
|
|
|
/*@observer@*/ /*@null@*/const struct passwd *pw_next (void)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
return commonio_next (&passwd_db);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
int pw_close (void)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
return commonio_close (&passwd_db);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
int pw_unlock (void)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
return commonio_unlock (&passwd_db);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
* libmisc/utmp.c, libmisc/age.c, libmisc/shell.c, lib/groupio.c,
lib/groupio.h, lib/sgroupio.c, lib/sgroupio.h, lib/shadowio.c,
lib/pwio.c, lib/commonio.c, lib/shadowio.h, lib/pwio.h,
lib/commonio.h, lib/prototypes.h: Added splint annotations.
2009-04-22 21:21:14 +00:00
|
|
|
/*@null@*/struct commonio_entry *__pw_get_head (void)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
return passwd_db.head;
|
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
void __pw_del_entry (const struct commonio_entry *ent)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
commonio_del_entry (&passwd_db, ent);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2007-10-07 11:44:51 +00:00
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
struct commonio_db *__pw_get_db (void)
|
2007-10-07 11:44:51 +00:00
|
|
|
{
|
|
|
|
return &passwd_db;
|
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
static int pw_cmp (const void *p1, const void *p2)
|
2007-10-07 11:44:51 +00:00
|
|
|
{
|
|
|
|
uid_t u1, u2;
|
|
|
|
|
2007-10-07 11:46:07 +00:00
|
|
|
if ((*(struct commonio_entry **) p1)->eptr == NULL)
|
2007-10-07 11:44:51 +00:00
|
|
|
return 1;
|
2007-10-07 11:46:07 +00:00
|
|
|
if ((*(struct commonio_entry **) p2)->eptr == NULL)
|
2007-10-07 11:44:51 +00:00
|
|
|
return -1;
|
2007-10-07 11:46:07 +00:00
|
|
|
|
|
|
|
u1 = ((struct passwd *) (*(struct commonio_entry **) p1)->eptr)->pw_uid;
|
|
|
|
u2 = ((struct passwd *) (*(struct commonio_entry **) p2)->eptr)->pw_uid;
|
2007-10-07 11:44:51 +00:00
|
|
|
|
|
|
|
if (u1 < u2)
|
|
|
|
return -1;
|
|
|
|
else if (u1 > u2)
|
|
|
|
return 1;
|
|
|
|
else
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2007-10-07 11:46:25 +00:00
|
|
|
/* Sort entries by UID */
|
2007-10-07 11:46:07 +00:00
|
|
|
int pw_sort ()
|
2007-10-07 11:44:51 +00:00
|
|
|
{
|
2007-10-07 11:46:07 +00:00
|
|
|
return commonio_sort (&passwd_db, pw_cmp);
|
2007-10-07 11:44:51 +00:00
|
|
|
}
|