2007-10-07 11:44:02 +00:00
|
|
|
/*
|
|
|
|
* grpconv - create or update /etc/gshadow with information from
|
|
|
|
* /etc/group.
|
|
|
|
*
|
|
|
|
* Copyright (C) 1996, Marek Michalkiewicz
|
|
|
|
* <marekm@i17linuxb.ists.pwr.wroc.pl>
|
2007-10-07 11:44:59 +00:00
|
|
|
* This program may be freely used and distributed. If you improve
|
|
|
|
* it, please send me your changes. Thanks!
|
2007-10-07 11:44:02 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
#include <config.h>
|
|
|
|
|
|
|
|
#include <stdio.h>
|
|
|
|
#include <errno.h>
|
|
|
|
#include <stdlib.h>
|
|
|
|
#include <string.h>
|
|
|
|
#include <fcntl.h>
|
|
|
|
#include <time.h>
|
|
|
|
#include <unistd.h>
|
|
|
|
|
|
|
|
#include <grp.h>
|
|
|
|
#include "prototypes.h"
|
|
|
|
|
|
|
|
#ifdef SHADOWGRP
|
|
|
|
|
|
|
|
#include "groupio.h"
|
|
|
|
#include "sgroupio.h"
|
|
|
|
|
|
|
|
#include "rcsid.h"
|
2007-10-07 11:46:52 +00:00
|
|
|
RCSID (PKG_VER "$Id: grpconv.c,v 1.17 2005/08/09 15:27:51 kloczek Exp $")
|
2007-10-07 11:44:02 +00:00
|
|
|
|
|
|
|
static int group_locked = 0;
|
|
|
|
static int gshadow_locked = 0;
|
|
|
|
|
|
|
|
/* local function prototypes */
|
2007-10-07 11:44:59 +00:00
|
|
|
static void fail_exit (int);
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2007-10-07 11:44:59 +00:00
|
|
|
static void fail_exit (int status)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
if (group_locked)
|
2007-10-07 11:44:59 +00:00
|
|
|
gr_unlock ();
|
2007-10-07 11:44:02 +00:00
|
|
|
if (gshadow_locked)
|
2007-10-07 11:44:59 +00:00
|
|
|
sgr_unlock ();
|
|
|
|
exit (status);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2007-10-07 11:44:59 +00:00
|
|
|
int main (int argc, char **argv)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
|
|
|
const struct group *gr;
|
|
|
|
struct group grent;
|
|
|
|
const struct sgrp *sg;
|
|
|
|
struct sgrp sgent;
|
|
|
|
char *Prog = argv[0];
|
|
|
|
|
2007-10-07 11:44:59 +00:00
|
|
|
setlocale (LC_ALL, "");
|
|
|
|
bindtextdomain (PACKAGE, LOCALEDIR);
|
|
|
|
textdomain (PACKAGE);
|
2007-10-07 11:44:02 +00:00
|
|
|
|
2007-10-07 11:44:59 +00:00
|
|
|
if (!gr_lock ()) {
|
|
|
|
fprintf (stderr, _("%s: can't lock group file\n"), Prog);
|
|
|
|
fail_exit (5);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
group_locked++;
|
2007-10-07 11:44:59 +00:00
|
|
|
if (!gr_open (O_RDWR)) {
|
|
|
|
fprintf (stderr, _("%s: can't open group file\n"), Prog);
|
|
|
|
fail_exit (1);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
2007-10-07 11:44:59 +00:00
|
|
|
if (!sgr_lock ()) {
|
2007-10-07 11:46:07 +00:00
|
|
|
fprintf (stderr, _("%s: can't lock shadow group file\n"), Prog);
|
2007-10-07 11:44:59 +00:00
|
|
|
fail_exit (5);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
gshadow_locked++;
|
2007-10-07 11:44:59 +00:00
|
|
|
if (!sgr_open (O_CREAT | O_RDWR)) {
|
2007-10-07 11:46:07 +00:00
|
|
|
fprintf (stderr, _("%s: can't open shadow group file\n"), Prog);
|
2007-10-07 11:44:59 +00:00
|
|
|
fail_exit (1);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Remove /etc/gshadow entries for groups not in /etc/group.
|
|
|
|
*/
|
2007-10-07 11:44:59 +00:00
|
|
|
sgr_rewind ();
|
|
|
|
while ((sg = sgr_next ())) {
|
|
|
|
if (gr_locate (sg->sg_name))
|
2007-10-07 11:44:02 +00:00
|
|
|
continue;
|
|
|
|
|
2007-10-07 11:44:59 +00:00
|
|
|
if (!sgr_remove (sg->sg_name)) {
|
2007-10-07 11:44:02 +00:00
|
|
|
/*
|
|
|
|
* This shouldn't happen (the entry exists) but...
|
|
|
|
*/
|
2007-10-07 11:44:59 +00:00
|
|
|
fprintf (stderr,
|
|
|
|
_("%s: can't remove shadow group %s\n"),
|
|
|
|
Prog, sg->sg_name);
|
|
|
|
fail_exit (3);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Update shadow group passwords if non-shadow password is not "x".
|
|
|
|
* Add any missing shadow group entries.
|
|
|
|
*/
|
2007-10-07 11:44:59 +00:00
|
|
|
gr_rewind ();
|
|
|
|
while ((gr = gr_next ())) {
|
|
|
|
sg = sgr_locate (gr->gr_name);
|
2007-10-07 11:44:02 +00:00
|
|
|
if (sg) {
|
|
|
|
/* update existing shadow group entry */
|
|
|
|
sgent = *sg;
|
2007-10-07 11:46:07 +00:00
|
|
|
if (strcmp (gr->gr_passwd, SHADOW_PASSWD_STRING) != 0)
|
2007-10-07 11:44:02 +00:00
|
|
|
sgent.sg_passwd = gr->gr_passwd;
|
|
|
|
} else {
|
|
|
|
static char *empty = 0;
|
|
|
|
|
|
|
|
/* add new shadow group entry */
|
2007-10-07 11:44:59 +00:00
|
|
|
memset (&sgent, 0, sizeof sgent);
|
2007-10-07 11:44:02 +00:00
|
|
|
sgent.sg_name = gr->gr_name;
|
|
|
|
sgent.sg_passwd = gr->gr_passwd;
|
|
|
|
sgent.sg_adm = ∅
|
|
|
|
}
|
|
|
|
/*
|
|
|
|
* XXX - sg_mem is redundant, it is currently always a copy
|
2007-10-07 11:44:59 +00:00
|
|
|
* of gr_mem. Very few programs actually use sg_mem, and all
|
|
|
|
* of them are in the shadow suite. Maybe this field could
|
|
|
|
* be used for something else? Any suggestions?
|
2007-10-07 11:44:02 +00:00
|
|
|
*/
|
|
|
|
sgent.sg_mem = gr->gr_mem;
|
|
|
|
|
2007-10-07 11:44:59 +00:00
|
|
|
if (!sgr_update (&sgent)) {
|
|
|
|
fprintf (stderr,
|
|
|
|
_
|
|
|
|
("%s: can't update shadow entry for %s\n"),
|
|
|
|
Prog, sgent.sg_name);
|
|
|
|
fail_exit (3);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
/* remove password from /etc/group */
|
|
|
|
grent = *gr;
|
2007-10-07 11:44:59 +00:00
|
|
|
grent.gr_passwd = SHADOW_PASSWD_STRING; /* XXX warning: const */
|
|
|
|
if (!gr_update (&grent)) {
|
|
|
|
fprintf (stderr,
|
|
|
|
_
|
|
|
|
("%s: can't update entry for group %s\n"),
|
|
|
|
Prog, grent.gr_name);
|
|
|
|
fail_exit (3);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2007-10-07 11:44:59 +00:00
|
|
|
if (!sgr_close ()) {
|
|
|
|
fprintf (stderr, _("%s: can't update shadow group file\n"),
|
|
|
|
Prog);
|
|
|
|
fail_exit (3);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2007-10-07 11:44:59 +00:00
|
|
|
if (!gr_close ()) {
|
|
|
|
fprintf (stderr, _("%s: can't update group file\n"), Prog);
|
|
|
|
fail_exit (3);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2007-10-07 11:44:59 +00:00
|
|
|
sgr_unlock ();
|
|
|
|
gr_unlock ();
|
2007-10-07 11:46:52 +00:00
|
|
|
|
|
|
|
nscd_flush_cache ("group");
|
|
|
|
|
2007-10-07 11:44:02 +00:00
|
|
|
return 0;
|
|
|
|
}
|
2007-10-07 11:44:59 +00:00
|
|
|
#else /* !SHADOWGRP */
|
|
|
|
int main (int argc, char **argv)
|
2007-10-07 11:44:02 +00:00
|
|
|
{
|
2007-10-07 11:44:59 +00:00
|
|
|
fprintf (stderr,
|
2007-10-07 11:46:07 +00:00
|
|
|
"%s: not configured for shadow group support.\n", argv[0]);
|
2007-10-07 11:44:59 +00:00
|
|
|
exit (1);
|
2007-10-07 11:44:02 +00:00
|
|
|
}
|
2007-10-07 11:44:59 +00:00
|
|
|
#endif /* !SHADOWGRP */
|