New upstream version 4.17.3

This commit is contained in:
Chris Hofstaedtler
2025-02-24 22:57:12 +01:00
parent 65261e28f4
commit a475f464e0
543 changed files with 6960 additions and 4050 deletions
+1 -1
View File
@@ -99,7 +99,7 @@ else
LIBCRYPT_NOPAM = $(LIBCRYPT)
endif
chage_LDADD = $(LDADD) $(LIBPAM_SUID) $(LIBAUDIT) $(LIBSELINUX) $(LIBECONF) -ldl
chage_LDADD = $(LDADD) $(LIBAUDIT) $(LIBSELINUX) $(LIBECONF) -ldl
newuidmap_LDADD = $(LDADD) $(LIBAUDIT) $(LIBSELINUX) $(LIBCAP) $(LIBECONF) -ldl
newgidmap_LDADD = $(LDADD) $(LIBAUDIT) $(LIBSELINUX) $(LIBCAP) $(LIBECONF) -ldl
chfn_LDADD = $(LDADD) $(LIBPAM) $(LIBAUDIT) $(LIBSELINUX) $(LIBCRYPT_NOPAM) $(LIBSKEY) $(LIBMD) $(LIBECONF)
+24 -25
View File
@@ -150,10 +150,8 @@ chage_OBJECTS = chage.$(OBJEXT)
am__DEPENDENCIES_1 =
am__DEPENDENCIES_2 = $(am__DEPENDENCIES_1) \
$(top_builddir)/lib/libshadow.la $(am__DEPENDENCIES_1)
@ACCT_TOOLS_SETUID_TRUE@am__DEPENDENCIES_3 = $(am__DEPENDENCIES_1)
chage_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_3) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1)
chage_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1)
AM_V_lt = $(am__v_lt_@AM_V@)
am__v_lt_ = $(am__v_lt_@AM_DEFAULT_V@)
am__v_lt_0 = --silent
@@ -161,11 +159,11 @@ am__v_lt_1 =
check_subid_range_SOURCES = check_subid_range.c
check_subid_range_OBJECTS = \
check_subid_range-check_subid_range.$(OBJEXT)
@USE_PAM_FALSE@am__DEPENDENCIES_4 = $(am__DEPENDENCIES_1)
@ENABLE_SUBIDS_TRUE@am__DEPENDENCIES_5 = $(am__DEPENDENCIES_1) \
@USE_PAM_FALSE@am__DEPENDENCIES_3 = $(am__DEPENDENCIES_1)
@ENABLE_SUBIDS_TRUE@am__DEPENDENCIES_4 = $(am__DEPENDENCIES_1) \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_1) \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_1) \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_4) \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_3) \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_1) \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_1) \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_1) \
@@ -173,16 +171,17 @@ check_subid_range_OBJECTS = \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_1)
@ENABLE_SUBIDS_TRUE@check_subid_range_DEPENDENCIES = \
@ENABLE_SUBIDS_TRUE@ $(top_builddir)/lib/libshadow.la \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_5)
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_4)
chfn_SOURCES = chfn.c
chfn_OBJECTS = chfn.$(OBJEXT)
chfn_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_4) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_3) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1)
chgpasswd_SOURCES = chgpasswd.c
chgpasswd_OBJECTS = chgpasswd.$(OBJEXT)
chgpasswd_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_3) \
@ACCT_TOOLS_SETUID_TRUE@am__DEPENDENCIES_5 = $(am__DEPENDENCIES_1)
chgpasswd_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_5) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1)
chpasswd_SOURCES = chpasswd.c
@@ -194,7 +193,7 @@ chsh_SOURCES = chsh.c
chsh_OBJECTS = chsh.$(OBJEXT)
chsh_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_4) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_3) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1)
expiry_SOURCES = expiry.c
expiry_OBJECTS = expiry.$(OBJEXT)
@@ -210,20 +209,20 @@ free_subid_range_OBJECTS = \
@ENABLE_SUBIDS_TRUE@free_subid_range_DEPENDENCIES = \
@ENABLE_SUBIDS_TRUE@ $(top_builddir)/lib/libshadow.la \
@ENABLE_SUBIDS_TRUE@ $(top_builddir)/libsubid/libsubid.la \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_5)
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_4)
get_subid_owners_SOURCES = get_subid_owners.c
get_subid_owners_OBJECTS = \
get_subid_owners-get_subid_owners.$(OBJEXT)
@ENABLE_SUBIDS_TRUE@get_subid_owners_DEPENDENCIES = \
@ENABLE_SUBIDS_TRUE@ $(top_builddir)/lib/libshadow.la \
@ENABLE_SUBIDS_TRUE@ $(top_builddir)/libsubid/libsubid.la \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_5)
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_4)
getsubids_SOURCES = getsubids.c
getsubids_OBJECTS = getsubids-getsubids.$(OBJEXT)
@ENABLE_SUBIDS_TRUE@getsubids_DEPENDENCIES = \
@ENABLE_SUBIDS_TRUE@ $(top_builddir)/lib/libshadow.la \
@ENABLE_SUBIDS_TRUE@ $(top_builddir)/libsubid/libsubid.la \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_5)
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_4)
gpasswd_SOURCES = gpasswd.c
gpasswd_OBJECTS = gpasswd.$(OBJEXT)
gpasswd_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
@@ -231,12 +230,12 @@ gpasswd_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1)
groupadd_SOURCES = groupadd.c
groupadd_OBJECTS = groupadd.$(OBJEXT)
groupadd_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_3) \
groupadd_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_5) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1)
groupdel_SOURCES = groupdel.c
groupdel_OBJECTS = groupdel.$(OBJEXT)
groupdel_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_3) \
groupdel_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_5) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1)
groupmems_SOURCES = groupmems.c
@@ -246,7 +245,7 @@ groupmems_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1)
groupmod_SOURCES = groupmod.c
groupmod_OBJECTS = groupmod.$(OBJEXT)
groupmod_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_3) \
groupmod_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_5) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1)
grpck_SOURCES = grpck.c
@@ -268,7 +267,7 @@ lastlog_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
am_login_OBJECTS = login.$(OBJEXT) login_nopam.$(OBJEXT)
login_OBJECTS = $(am_login_OBJECTS)
login_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_4) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_3) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1)
logoutd_SOURCES = logoutd.c
@@ -281,7 +280,7 @@ new_subid_range_OBJECTS = new_subid_range-new_subid_range.$(OBJEXT)
@ENABLE_SUBIDS_TRUE@new_subid_range_DEPENDENCIES = \
@ENABLE_SUBIDS_TRUE@ $(top_builddir)/lib/libshadow.la \
@ENABLE_SUBIDS_TRUE@ $(top_builddir)/libsubid/libsubid.la \
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_5)
@ENABLE_SUBIDS_TRUE@ $(am__DEPENDENCIES_4)
newgidmap_SOURCES = newgidmap.c
newgidmap_OBJECTS = newgidmap.$(OBJEXT)
newgidmap_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
@@ -306,7 +305,7 @@ passwd_SOURCES = passwd.c
passwd_OBJECTS = passwd.$(OBJEXT)
passwd_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_4) $(am__DEPENDENCIES_1)
$(am__DEPENDENCIES_3) $(am__DEPENDENCIES_1)
pwck_SOURCES = pwck.c
pwck_OBJECTS = pwck.$(OBJEXT)
pwck_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
@@ -322,7 +321,7 @@ pwunconv_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
am_su_OBJECTS = su.$(OBJEXT) suauth.$(OBJEXT)
su_OBJECTS = $(am_su_OBJECTS)
su_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_4) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_3) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1)
sulogin_SOURCES = sulogin.c
@@ -331,18 +330,18 @@ sulogin_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1)
useradd_SOURCES = useradd.c
useradd_OBJECTS = useradd.$(OBJEXT)
useradd_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_3) \
useradd_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_5) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1)
userdel_SOURCES = userdel.c
userdel_OBJECTS = userdel.$(OBJEXT)
userdel_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_3) \
userdel_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_5) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1)
usermod_SOURCES = usermod.c
usermod_OBJECTS = usermod.$(OBJEXT)
usermod_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_3) \
usermod_DEPENDENCIES = $(am__DEPENDENCIES_2) $(am__DEPENDENCIES_5) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1) \
$(am__DEPENDENCIES_1) $(am__DEPENDENCIES_1)
@@ -651,7 +650,7 @@ LDADD = $(INTLLIBS) \
@ACCT_TOOLS_SETUID_TRUE@LIBPAM_SUID = $(LIBPAM)
@USE_PAM_FALSE@LIBCRYPT_NOPAM = $(LIBCRYPT)
@USE_PAM_TRUE@LIBCRYPT_NOPAM =
chage_LDADD = $(LDADD) $(LIBPAM_SUID) $(LIBAUDIT) $(LIBSELINUX) $(LIBECONF) -ldl
chage_LDADD = $(LDADD) $(LIBAUDIT) $(LIBSELINUX) $(LIBECONF) -ldl
newuidmap_LDADD = $(LDADD) $(LIBAUDIT) $(LIBSELINUX) $(LIBCAP) $(LIBECONF) -ldl
newgidmap_LDADD = $(LDADD) $(LIBAUDIT) $(LIBSELINUX) $(LIBCAP) $(LIBECONF) -ldl
chfn_LDADD = $(LDADD) $(LIBPAM) $(LIBAUDIT) $(LIBSELINUX) $(LIBCRYPT_NOPAM) $(LIBSKEY) $(LIBMD) $(LIBECONF)
-51
View File
@@ -19,11 +19,6 @@
#include <stdlib.h>
#include <sys/types.h>
#include <time.h>
#ifdef ACCT_TOOLS_SETUID
#ifdef USE_PAM
#include "pam_defs.h"
#endif /* USE_PAM */
#endif /* ACCT_TOOLS_SETUID */
#include <pwd.h>
#include "atoi/a2i/a2s.h"
@@ -474,23 +469,10 @@ static void check_flags (int argc, int opt_index)
* (we will later make sure that the user is only listing her aging
* information)
*
* With PAM support, the setuid bit can be set on chage to allow
* non-root users to groups.
* Without PAM support, only users who can write in the group databases
* can add groups.
*
* It will not return if the user is not allowed.
*/
static void check_perms (void)
{
#ifdef ACCT_TOOLS_SETUID
#ifdef USE_PAM
pam_handle_t *pamh = NULL;
struct passwd *pampw;
int retval;
#endif /* USE_PAM */
#endif /* ACCT_TOOLS_SETUID */
/*
* An unprivileged user can ask for their own aging information, but
* only root can change it, or list another user's aging
@@ -501,39 +483,6 @@ static void check_perms (void)
fprintf (stderr, _("%s: Permission denied.\n"), Prog);
fail_exit (E_NOPERM);
}
#ifdef ACCT_TOOLS_SETUID
#ifdef USE_PAM
pampw = getpwuid (getuid ()); /* local, no need for xgetpwuid */
if (NULL == pampw) {
fprintf (stderr,
_("%s: Cannot determine your user name.\n"),
Prog);
exit (E_NOPERM);
}
retval = pam_start (Prog, pampw->pw_name, &conv, &pamh);
if (PAM_SUCCESS == retval) {
retval = pam_authenticate (pamh, 0);
}
if (PAM_SUCCESS == retval) {
retval = pam_acct_mgmt (pamh, 0);
}
if (PAM_SUCCESS != retval) {
fprintf (stderr, _("%s: PAM: %s\n"),
Prog, pam_strerror (pamh, retval));
SYSLOG((LOG_ERR, "%s", pam_strerror (pamh, retval)));
if (NULL != pamh) {
(void) pam_end (pamh, retval);
}
fail_exit (E_NOPERM);
}
(void) pam_end (pamh, retval);
#endif /* USE_PAM */
#endif /* ACCT_TOOLS_SETUID */
}
/*
+16 -15
View File
@@ -14,6 +14,7 @@
#include <fcntl.h>
#include <getopt.h>
#include <pwd.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
@@ -425,8 +426,8 @@ int main (int argc, char **argv)
const struct group *gr;
struct group newgr;
int errors = 0;
int line = 0;
bool errors = false;
intmax_t line = 0;
log_set_progname(Prog);
log_set_logfd(stderr);
@@ -463,9 +464,9 @@ int main (int argc, char **argv)
while (fgets (buf, (int) sizeof buf, stdin) != NULL) {
line++;
if (stpsep(buf, "\n") == NULL) {
fprintf (stderr, _("%s: line %d: line too long\n"),
fprintf (stderr, _("%s: line %jd: line too long\n"),
Prog, line);
errors++;
errors = true;
continue;
}
@@ -482,9 +483,9 @@ int main (int argc, char **argv)
cp = stpsep(name, ":");
if (cp == NULL) {
fprintf (stderr,
_("%s: line %d: missing new password\n"),
_("%s: line %jd: missing new password\n"),
Prog, line);
errors++;
errors = true;
continue;
}
newpwd = cp;
@@ -533,9 +534,9 @@ int main (int argc, char **argv)
gr = gr_locate (name);
if (NULL == gr) {
fprintf (stderr,
_("%s: line %d: group '%s' does not exist\n"), Prog,
_("%s: line %jd: group '%s' does not exist\n"), Prog,
line, name);
errors++;
errors = true;
continue;
}
#ifdef SHADOWGRP
@@ -556,7 +557,7 @@ int main (int argc, char **argv)
* group, but there are no entries in
* gshadow, create one.
*/
newsg.sg_name = name;
newsg.sg_namp = name;
/* newsg.sg_passwd = NULL; will be set later */
newsg.sg_adm = &empty;
newsg.sg_mem = dup_list (gr->gr_mem);
@@ -593,9 +594,9 @@ int main (int argc, char **argv)
if (NULL != sg) {
if (sgr_update (&newsg) == 0) {
fprintf (stderr,
_("%s: line %d: failed to prepare the new %s entry '%s'\n"),
Prog, line, sgr_dbname (), newsg.sg_name);
errors++;
_("%s: line %jd: failed to prepare the new %s entry '%s'\n"),
Prog, line, sgr_dbname (), newsg.sg_namp);
errors = true;
continue;
}
}
@@ -605,9 +606,9 @@ int main (int argc, char **argv)
{
if (gr_update (&newgr) == 0) {
fprintf (stderr,
_("%s: line %d: failed to prepare the new %s entry '%s'\n"),
_("%s: line %jd: failed to prepare the new %s entry '%s'\n"),
Prog, line, gr_dbname (), newgr.gr_name);
errors++;
errors = true;
continue;
}
}
@@ -620,7 +621,7 @@ int main (int argc, char **argv)
* changes to be written out all at once, and then unlocked
* afterwards.
*/
if (0 != errors) {
if (errors) {
fprintf (stderr,
_("%s: error detected, changes ignored\n"), Prog);
fail_exit (1);
+16 -15
View File
@@ -14,6 +14,7 @@
#include <fcntl.h>
#include <getopt.h>
#include <pwd.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
@@ -452,8 +453,8 @@ int main (int argc, char **argv)
bool use_pam = true;
#endif /* USE_PAM */
int errors = 0;
int line = 0;
bool errors = false;
intmax_t line = 0;
log_set_progname(Prog);
log_set_logfd(stderr);
@@ -514,9 +515,9 @@ int main (int argc, char **argv)
}
fprintf (stderr,
_("%s: line %d: line too long\n"),
_("%s: line %jd: line too long\n"),
Prog, line);
errors++;
errors = true;
continue;
}
}
@@ -534,9 +535,9 @@ int main (int argc, char **argv)
cp = stpsep(name, ":");
if (cp == NULL) {
fprintf (stderr,
_("%s: line %d: missing new password\n"),
_("%s: line %jd: missing new password\n"),
Prog, line);
errors++;
errors = true;
continue;
}
newpwd = cp;
@@ -545,9 +546,9 @@ int main (int argc, char **argv)
if (use_pam) {
if (do_pam_passwd_non_interactive (Prog, name, newpwd) != 0) {
fprintf (stderr,
_("%s: (line %d, user %s) password not changed\n"),
_("%s: (line %jd, user %s) password not changed\n"),
Prog, line, name);
errors++;
errors = true;
}
} else
#endif /* USE_PAM */
@@ -574,9 +575,9 @@ int main (int argc, char **argv)
pw = pw_locate (name);
if (NULL == pw) {
fprintf (stderr,
_("%s: line %d: user '%s' does not exist\n"), Prog,
_("%s: line %jd: user '%s' does not exist\n"), Prog,
line, name);
errors++;
errors = true;
continue;
}
if (is_shadow_pwd) {
@@ -640,9 +641,9 @@ int main (int argc, char **argv)
if (NULL != sp) {
if (spw_update (&newsp) == 0) {
fprintf (stderr,
_("%s: line %d: failed to prepare the new %s entry '%s'\n"),
_("%s: line %jd: failed to prepare the new %s entry '%s'\n"),
Prog, line, spw_dbname (), newsp.sp_namp);
errors++;
errors = true;
continue;
}
}
@@ -650,9 +651,9 @@ int main (int argc, char **argv)
|| !streq(pw->pw_passwd, SHADOW_PASSWD_STRING)) {
if (pw_update (&newpw) == 0) {
fprintf (stderr,
_("%s: line %d: failed to prepare the new %s entry '%s'\n"),
_("%s: line %jd: failed to prepare the new %s entry '%s'\n"),
Prog, line, pw_dbname (), newpw.pw_name);
errors++;
errors = true;
continue;
}
}
@@ -669,7 +670,7 @@ int main (int argc, char **argv)
* With PAM, it is not possible to delay the update of the
* password database.
*/
if (0 != errors) {
if (errors) {
#ifdef USE_PAM
if (!use_pam)
#endif /* USE_PAM */
+12 -7
View File
@@ -555,9 +555,11 @@ int main (int argc, char **argv)
fprintf (stderr, _("%s: Invalid entry: %s\n"), Prog, loginsh);
fail_exit (1);
}
if (loginsh[0] != '/'
|| is_restricted_shell (loginsh)
|| (access (loginsh, X_OK) != 0)) {
if (!streq(loginsh, "")
&& (loginsh[0] != '/'
|| is_restricted_shell (loginsh)
|| (access (loginsh, X_OK) != 0)))
{
if (amroot) {
fprintf (stderr, _("%s: Warning: %s is an invalid shell\n"), Prog, loginsh);
} else {
@@ -567,10 +569,13 @@ int main (int argc, char **argv)
}
/* Even for root, warn if an invalid shell is specified. */
if (access (loginsh, F_OK) != 0) {
fprintf (stderr, _("%s: Warning: %s does not exist\n"), Prog, loginsh);
} else if (access (loginsh, X_OK) != 0) {
fprintf (stderr, _("%s: Warning: %s is not executable\n"), Prog, loginsh);
if (!streq(loginsh, "")) {
/* But not if an empty string is given, documented as meaning the default shell */
if (access (loginsh, F_OK) != 0) {
fprintf (stderr, _("%s: Warning: %s does not exist\n"), Prog, loginsh);
} else if (access (loginsh, X_OK) != 0) {
fprintf (stderr, _("%s: Warning: %s is not executable\n"), Prog, loginsh);
}
}
update_shell (user, loginsh);
+5 -5
View File
@@ -708,7 +708,7 @@ static void update_group (struct group *gr)
if (is_shadowgrp && (sgr_update (sg) == 0)) {
fprintf (stderr,
_("%s: failed to prepare the new %s entry '%s'\n"),
Prog, sgr_dbname (), sg->sg_name);
Prog, sgr_dbname (), sg->sg_namp);
exit (1);
}
#endif /* SHADOWGRP */
@@ -774,13 +774,13 @@ static void get_group (struct group *gr)
tmpsg = sgr_locate (group);
if (NULL != tmpsg) {
*sg = *tmpsg;
sg->sg_name = xstrdup (tmpsg->sg_name);
sg->sg_namp = xstrdup (tmpsg->sg_namp);
sg->sg_passwd = xstrdup (tmpsg->sg_passwd);
sg->sg_mem = dup_list (tmpsg->sg_mem);
sg->sg_adm = dup_list (tmpsg->sg_adm);
} else {
sg->sg_name = xstrdup (group);
sg->sg_namp = xstrdup (group);
sg->sg_passwd = gr->gr_passwd;
gr->gr_passwd = SHADOW_PASSWD_STRING; /* XXX warning: const */
@@ -818,7 +818,7 @@ static void change_passwd (struct group *gr)
#endif
{
char *cp;
static char pass[BUFSIZ];
static char pass[PASS_MAX + 1];
int retries;
const char *salt;
@@ -864,13 +864,13 @@ static void change_passwd (struct group *gr)
salt = crypt_make_salt (NULL, NULL);
cp = pw_encrypt (pass, salt);
MEMZERO(pass);
if (NULL == cp) {
fprintf (stderr,
_("%s: failed to crypt password with salt '%s': %s\n"),
Prog, salt, strerror (errno));
exit (1);
}
MEMZERO(pass);
#ifdef SHADOWGRP
if (is_shadowgrp) {
gr->gr_passwd = SHADOW_PASSWD_STRING;
+2 -2
View File
@@ -149,7 +149,7 @@ static void new_grent (struct group *grent)
static void new_sgent (struct sgrp *sgent)
{
memzero (sgent, sizeof *sgent);
sgent->sg_name = group_name;
sgent->sg_namp = group_name;
if (pflg) {
sgent->sg_passwd = group_passwd;
} else {
@@ -231,7 +231,7 @@ grp_update(void)
if (is_shadow_grp && (sgr_update (&sgrp) == 0)) {
fprintf (stderr,
_("%s: failed to prepare the new %s entry '%s'\n"),
Prog, sgr_dbname (), sgrp.sg_name);
Prog, sgr_dbname (), sgrp.sg_namp);
exit (E_GRP_UPDATE);
}
#endif /* SHADOWGRP */
+6 -6
View File
@@ -128,7 +128,7 @@ static void add_user (const char *user,
if (NULL == sg) {
/* Create a shadow group based on this group */
static struct sgrp sgrent;
sgrent.sg_name = xstrdup (newgrp->gr_name);
sgrent.sg_namp = xstrdup (newgrp->gr_name);
sgrent.sg_mem = dup_list (newgrp->gr_mem);
sgrent.sg_adm = XMALLOC(1, char *);
sgrent.sg_adm[0] = NULL;
@@ -154,7 +154,7 @@ static void add_user (const char *user,
if (sgr_update (newsg) == 0) {
fprintf (stderr,
_("%s: failed to prepare the new %s entry '%s'\n"),
Prog, sgr_dbname (), newsg->sg_name);
Prog, sgr_dbname (), newsg->sg_namp);
fail_exit (13);
}
}
@@ -203,7 +203,7 @@ static void remove_user (const char *user,
if (NULL == sg) {
/* Create a shadow group based on this group */
static struct sgrp sgrent;
sgrent.sg_name = xstrdup (newgrp->gr_name);
sgrent.sg_namp = xstrdup (newgrp->gr_name);
sgrent.sg_mem = dup_list (newgrp->gr_mem);
sgrent.sg_adm = XMALLOC(1, char *);
sgrent.sg_adm[0] = NULL;
@@ -230,7 +230,7 @@ static void remove_user (const char *user,
if (sgr_update (newsg) == 0) {
fprintf (stderr,
_("%s: failed to prepare the new %s entry '%s'\n"),
Prog, sgr_dbname (), newsg->sg_name);
Prog, sgr_dbname (), newsg->sg_namp);
fail_exit (13);
}
}
@@ -269,7 +269,7 @@ static void purge_members (const struct group *grp)
if (NULL == sg) {
/* Create a shadow group based on this group */
static struct sgrp sgrent;
sgrent.sg_name = xstrdup (newgrp->gr_name);
sgrent.sg_namp = xstrdup (newgrp->gr_name);
sgrent.sg_mem = XMALLOC(1, char *);
sgrent.sg_mem[0] = NULL;
sgrent.sg_adm = XMALLOC(1, char *);
@@ -299,7 +299,7 @@ static void purge_members (const struct group *grp)
if (sgr_update (newsg) == 0) {
fprintf (stderr,
_("%s: failed to prepare the new %s entry '%s'\n"),
Prog, sgr_dbname (), newsg->sg_name);
Prog, sgr_dbname (), newsg->sg_namp);
fail_exit (13);
}
}
+3 -3
View File
@@ -178,7 +178,7 @@ static void new_grent (struct group *grent)
static void new_sgent (struct sgrp *sgent)
{
if (nflg) {
sgent->sg_name = xstrdup (group_newname);
sgent->sg_namp = xstrdup (group_newname);
}
/* Always update the shadowed password if there is a shadow entry
@@ -238,7 +238,7 @@ grp_update(void)
* gshadow entry when a new password is requested.
*/
bzero(&sgrp, sizeof sgrp);
sgrp.sg_name = xstrdup (grp.gr_name);
sgrp.sg_namp = xstrdup (grp.gr_name);
sgrp.sg_passwd = xstrdup (grp.gr_passwd);
sgrp.sg_adm = &empty;
sgrp.sg_mem = dup_list (grp.gr_mem);
@@ -318,7 +318,7 @@ grp_update(void)
if (sgr_update (&sgrp) == 0) {
fprintf (stderr,
_("%s: failed to prepare the new %s entry '%s'\n"),
Prog, sgr_dbname (), sgrp.sg_name);
Prog, sgr_dbname (), sgrp.sg_namp);
exit (E_GRP_UPDATE);
}
if (nflg && (sgr_remove (group_name) == 0)) {
+27 -27
View File
@@ -74,15 +74,15 @@ static int check_members (const char *groupname,
const char *fmt_info,
const char *fmt_prompt,
const char *fmt_syslog,
int *errors);
static void check_grp_file (int *errors, bool *changed);
bool *errors);
static void check_grp_file (bool *errors, bool *changed);
#ifdef SHADOWGRP
static void compare_members_lists (const char *groupname,
char **members,
char **other_members,
const char *file,
const char *other_file);
static void check_sgr_file (int *errors, bool *changed);
static void check_sgr_file (bool *errors, bool *changed);
#endif
/*
@@ -360,7 +360,7 @@ static void close_files (bool changed)
/*
* check_members - check that every members of a group exist
*
* If an error is detected, *errors is incremented.
* If an error is detected, *errors is set to true.
*
* The user will be prompted for the removal of the non-existent
* user.
@@ -381,7 +381,7 @@ static int check_members (const char *groupname,
const char *fmt_info,
const char *fmt_prompt,
const char *fmt_syslog,
int *errors)
bool *errors)
{
int i;
int members_changed = 0;
@@ -398,7 +398,7 @@ static int check_members (const char *groupname,
* Can't find this user. Remove them
* from the list.
*/
*errors += 1;
*errors = true;
printf (fmt_info, groupname, members[i]);
printf (fmt_prompt, members[i]);
@@ -454,7 +454,7 @@ static void compare_members_lists (const char *groupname,
/*
* check_grp_file - check the content of the group file
*/
static void check_grp_file (int *errors, bool *changed)
static void check_grp_file (bool *errors, bool *changed)
{
struct commonio_entry *gre, *tgre;
struct group *grp;
@@ -487,7 +487,7 @@ static void check_grp_file (int *errors, bool *changed)
*/
(void) puts (_("invalid group file entry"));
printf (_("delete line '%s'? "), gre->line);
*errors += 1;
*errors = true;
/*
* prompt the user to delete the entry or not
@@ -547,7 +547,7 @@ static void check_grp_file (int *errors, bool *changed)
*/
(void) puts (_("duplicate group entry"));
printf (_("delete line '%s'? "), gre->line);
*errors += 1;
*errors = true;
/*
* prompt the user to delete the entry or not
@@ -561,7 +561,7 @@ static void check_grp_file (int *errors, bool *changed)
* Check for invalid group names. --marekm
*/
if (!is_valid_group_name (grp->gr_name)) {
*errors += 1;
*errors = true;
printf (_("invalid group name '%s'\n"), grp->gr_name);
}
@@ -570,7 +570,7 @@ static void check_grp_file (int *errors, bool *changed)
*/
if (grp->gr_gid == (gid_t)-1) {
printf (_("invalid group ID '%lu'\n"), (long unsigned int)grp->gr_gid);
*errors += 1;
*errors = true;
}
/*
@@ -607,13 +607,13 @@ static void check_grp_file (int *errors, bool *changed)
sgr_file);
printf (_("add group '%s' in %s? "),
grp->gr_name, sgr_file);
*errors += 1;
*errors = true;
if (yes_or_no (read_only)) {
struct sgrp sg;
struct group gr;
static char *empty = NULL;
sg.sg_name = grp->gr_name;
sg.sg_namp = grp->gr_name;
sg.sg_passwd = grp->gr_passwd;
sg.sg_adm = &empty;
sg.sg_mem = grp->gr_mem;
@@ -625,7 +625,7 @@ static void check_grp_file (int *errors, bool *changed)
if (sgr_update (&sg) == 0) {
fprintf (stderr,
_("%s: failed to prepare the new %s entry '%s'\n"),
Prog, sgr_dbname (), sg.sg_name);
Prog, sgr_dbname (), sg.sg_namp);
fail_exit (E_CANT_UPDATE);
}
/* remove password from /etc/group */
@@ -653,7 +653,7 @@ static void check_grp_file (int *errors, bool *changed)
if (!streq(grp->gr_passwd, SHADOW_PASSWD_STRING)) {
printf (_("group %s has an entry in %s, but its password field in %s is not set to 'x'\n"),
grp->gr_name, sgr_file, grp_file);
*errors += 1;
*errors = true;
}
}
}
@@ -666,7 +666,7 @@ static void check_grp_file (int *errors, bool *changed)
/*
* check_sgr_file - check the content of the shadowed group file (gshadow)
*/
static void check_sgr_file (int *errors, bool *changed)
static void check_sgr_file (bool *errors, bool *changed)
{
const struct group *grp;
struct commonio_entry *sge, *tsge;
@@ -690,7 +690,7 @@ static void check_sgr_file (int *errors, bool *changed)
*/
(void) puts (_("invalid shadow group file entry"));
printf (_("delete line '%s'? "), sge->line);
*errors += 1;
*errors = true;
/*
* prompt the user to delete the entry or not
@@ -740,7 +740,7 @@ static void check_sgr_file (int *errors, bool *changed)
continue;
}
if (!streq(sgr->sg_name, ent->sg_name)) {
if (!streq(sgr->sg_namp, ent->sg_namp)) {
continue;
}
@@ -750,7 +750,7 @@ static void check_sgr_file (int *errors, bool *changed)
*/
(void) puts (_("duplicate shadow group entry"));
printf (_("delete line '%s'? "), sge->line);
*errors += 1;
*errors = true;
/*
* prompt the user to delete the entry or not
@@ -763,12 +763,12 @@ static void check_sgr_file (int *errors, bool *changed)
/*
* Make sure this entry exists in the /etc/group file.
*/
grp = gr_locate (sgr->sg_name);
grp = gr_locate (sgr->sg_namp);
if (grp == NULL) {
printf (_("no matching group file entry in %s\n"),
grp_file);
printf (_("delete line '%s'? "), sge->line);
*errors += 1;
*errors = true;
if (yes_or_no (read_only)) {
goto delete_sg;
}
@@ -777,7 +777,7 @@ static void check_sgr_file (int *errors, bool *changed)
* Verify that the all members defined in /etc/gshadow are also
* present in /etc/group.
*/
compare_members_lists (sgr->sg_name,
compare_members_lists (sgr->sg_namp,
sgr->sg_mem, grp->gr_mem,
sgr_file, grp_file);
}
@@ -785,7 +785,7 @@ static void check_sgr_file (int *errors, bool *changed)
/*
* Make sure each administrator exists
*/
if (check_members (sgr->sg_name, sgr->sg_adm,
if (check_members (sgr->sg_namp, sgr->sg_adm,
_("shadow group %s: no administrative user %s\n"),
_("delete administrative member '%s'? "),
"delete admin '%s' from shadow group '%s'",
@@ -798,7 +798,7 @@ static void check_sgr_file (int *errors, bool *changed)
/*
* Make sure each member exists
*/
if (check_members (sgr->sg_name, sgr->sg_mem,
if (check_members (sgr->sg_namp, sgr->sg_mem,
_("shadow group %s: no user %s\n"),
_("delete member '%s'? "),
"delete member '%s' from shadow group '%s'",
@@ -816,7 +816,7 @@ static void check_sgr_file (int *errors, bool *changed)
*/
int main (int argc, char **argv)
{
int errors = 0;
bool errors = false;
bool changed = false;
log_set_progname(Prog);
@@ -863,7 +863,7 @@ int main (int argc, char **argv)
/*
* Tell the user what we did and exit.
*/
if (0 != errors) {
if (errors) {
if (changed) {
printf (_("%s: the files have been updated\n"), Prog);
} else {
@@ -871,6 +871,6 @@ int main (int argc, char **argv)
}
}
return ((0 != errors) ? E_BAD_ENTRY : E_OKAY);
return (errors ? E_BAD_ENTRY : E_OKAY);
}
+5 -5
View File
@@ -172,17 +172,17 @@ int main (int argc, char **argv)
*/
(void) sgr_rewind ();
while ((sg = sgr_next ()) != NULL) {
if (gr_locate (sg->sg_name) != NULL) {
if (gr_locate (sg->sg_namp) != NULL) {
continue;
}
if (sgr_remove (sg->sg_name) == 0) {
if (sgr_remove (sg->sg_namp) == 0) {
/*
* This shouldn't happen (the entry exists) but...
*/
fprintf (stderr,
_("%s: cannot remove entry '%s' from %s\n"),
Prog, sg->sg_name, sgr_dbname ());
Prog, sg->sg_namp, sgr_dbname ());
fail_exit (3);
}
(void) sgr_rewind ();
@@ -205,7 +205,7 @@ int main (int argc, char **argv)
/* add new shadow group entry */
bzero(&sgent, sizeof sgent);
sgent.sg_name = gr->gr_name;
sgent.sg_namp = gr->gr_name;
sgent.sg_passwd = gr->gr_passwd;
sgent.sg_adm = &empty;
}
@@ -220,7 +220,7 @@ int main (int argc, char **argv)
if (sgr_update (&sgent) == 0) {
fprintf (stderr,
_("%s: failed to prepare the new %s entry '%s'\n"),
Prog, sgr_dbname (), sgent.sg_name);
Prog, sgr_dbname (), sgent.sg_namp);
fail_exit (3);
}
/* remove password from /etc/group */
+6 -8
View File
@@ -21,6 +21,7 @@
#include <pwd.h>
#include <signal.h>
#include <stdio.h>
#include <stdlib.h>
#include <sys/stat.h>
#include <sys/ioctl.h>
#include <assert.h>
@@ -77,7 +78,6 @@ static const char Prog[] = "login";
static const char *hostname = "";
static /*@null@*/ /*@only@*/char *username = NULL;
static int reason = PW_LOGIN;
#ifndef USE_PAM
#ifdef ENABLE_LASTLOG
@@ -289,7 +289,6 @@ static void process_flags (int argc, char *const *argv)
case 'h':
hflg = true;
hostname = optarg;
reason = PW_TELNET;
break;
case 'p':
pflg = true;
@@ -536,9 +535,6 @@ int main (int argc, char **argv)
if (fflg) {
preauth_flag = true;
}
if (hflg) {
reason = PW_RLOGIN;
}
OPENLOG (Prog);
@@ -903,7 +899,7 @@ int main (int argc, char **argv)
goto auth_ok;
}
if (pw_auth (user_passwd, username, reason, NULL) == 0) {
if (pw_auth(user_passwd, username) == 0) {
goto auth_ok;
}
@@ -964,7 +960,7 @@ int main (int argc, char **argv)
* all). --marekm
*/
if (streq(user_passwd, "")) {
pw_auth ("!", username, reason, NULL);
pw_auth("!", username);
}
/*
@@ -1180,7 +1176,9 @@ int main (int argc, char **argv)
* this
*/
#ifndef USE_PAM
motd (); /* print the message of the day */
if (motd() == -1)
exit(EXIT_FAILURE);
if ( getdef_bool ("FAILLOG_ENAB")
&& (0 != faillog.fail_cnt)) {
failprint (&faillog);
+30 -33
View File
@@ -47,6 +47,7 @@
#include <pwd.h>
#endif
#include <stddef.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
@@ -58,8 +59,9 @@
#include "prototypes.h"
#include "sizeof.h"
#include "string/strchr/strrspn.h"
#include "string/strcmp/strcaseeq.h"
#include "string/strcmp/streq.h"
#include "string/strspn/stprspn.h"
#include "string/strtok/stpsep.h"
@@ -94,7 +96,7 @@ login_access(const char *user, const char *from)
*/
fp = fopen (TABLE, "r");
if (NULL != fp) {
int lineno = 0; /* for diagnostics */
intmax_t lineno = 0; /* for diagnostics */
while ( !match
&& (fgets (line, sizeof (line), fp) == line))
{
@@ -103,14 +105,14 @@ login_access(const char *user, const char *from)
lineno++;
if (stpsep(line, "\n") == NULL) {
SYSLOG ((LOG_ERR,
"%s: line %d: missing newline or line too long",
"%s: line %jd: missing newline or line too long",
TABLE, lineno));
continue;
}
if (line[0] == '#') {
continue; /* comment line */
}
stpcpy(strrspn(line, " \t"), "");
stpcpy(stprspn(line, " \t"), "");
if (streq(line, "")) { /* skip blank lines */
continue;
}
@@ -120,13 +122,13 @@ login_access(const char *user, const char *from)
froms = strsep(&p, ":");
if (froms == NULL || p != NULL) {
SYSLOG ((LOG_ERR,
"%s: line %d: bad field count",
"%s: line %jd: bad field count",
TABLE, lineno));
continue;
}
if (perm[0] != '+' && perm[0] != '-') {
SYSLOG ((LOG_ERR,
"%s: line %d: bad first field",
"%s: line %jd: bad first field",
TABLE, lineno));
continue;
}
@@ -145,37 +147,32 @@ login_access(const char *user, const char *from)
static bool
list_match(char *list, const char *item, bool (*match_fn)(char *, const char*))
{
static const char sep[] = ", \t";
char *tok;
bool match = false;
bool inclusion = true;
bool matched = false;
bool result = false;
/*
* Process tokens one at a time. We have exhausted all possible matches
* when we reach an "EXCEPT" token or the end of the list. If we do find
* a match, look for an "EXCEPT" list and recurse to determine whether
* the match is affected by any exceptions.
* a match, look for an "EXCEPT" list and determine whether the match is
* affected by any exceptions.
*/
while (NULL != (tok = strsep(&list, sep))) {
if (strcasecmp (tok, "EXCEPT") == 0) { /* EXCEPT: give up */
break;
}
match = (*match_fn) (tok, item);
if (match) {
break;
while (NULL != (tok = strsep(&list, ", \t"))) {
if (strcaseeq(tok, "EXCEPT")) { /* EXCEPT: invert */
if (!matched) { /* stop processing: not part of list */
break;
}
inclusion = !inclusion;
matched = false;
} else if ((*match_fn)(tok, item)) {
result = inclusion;
matched = true;
}
}
/* Process exceptions to matches. */
if (match) {
while ( (NULL != (tok = strsep(&list, sep)))
&& (strcasecmp (tok, "EXCEPT") != 0))
/* VOID */ ;
if (tok == NULL || !list_match(list, item, match_fn)) {
return (match);
}
}
return false;
return result;
}
/* myhostname - figure out local machine name */
@@ -236,7 +233,7 @@ static bool user_match (char *tok, const char *string)
} else if ((group = getgrnam (tok)) != NULL) { /* try group membership */
int i;
for (i = 0; NULL != group->gr_mem[i]; i++) {
if (strcasecmp (string, group->gr_mem[i]) == 0) {
if (strcaseeq(string, group->gr_mem[i])) {
return true;
}
}
@@ -313,10 +310,10 @@ static bool from_match (char *tok, const char *string)
str_len = strlen (string);
tok_len = strlen (tok);
if ( (str_len > tok_len)
&& (strcasecmp (tok, string + str_len - tok_len) == 0)) {
&& strcaseeq(tok, string + str_len - tok_len)) {
return true;
}
} else if (strcasecmp (tok, "LOCAL") == 0) { /* local: no dots */
} else if (strcaseeq(tok, "LOCAL")) { /* LOCAL: no dots */
if (strchr (string, '.') == NULL) {
return true;
}
@@ -335,9 +332,9 @@ static bool string_match (const char *tok, const char *string)
* If the token has the magic value "ALL" the match always succeeds.
* Otherwise, return true if the token fully matches the string.
*/
if (strcasecmp (tok, "ALL") == 0) { /* all: always matches */
if (strcaseeq(tok, "ALL")) { /* ALL: always matches */
return true;
} else if (strcasecmp (tok, string) == 0) { /* try exact match */
} else if (strcaseeq(tok, string)) { /* try exact match */
return true;
}
return false;
+31 -60
View File
@@ -1,11 +1,10 @@
/*
* SPDX-FileCopyrightText: 1990 - 1994, Julianne Frances Haugh
* SPDX-FileCopyrightText: 1996 - 2000, Marek Michałkiewicz
* SPDX-FileCopyrightText: 2001 - 2006, Tomasz Kłoczko
* SPDX-FileCopyrightText: 2007 - 2008, Nicolas François
*
* SPDX-License-Identifier: BSD-3-Clause
*/
// SPDX-FileCopyrightText: 1990-1994, Julianne Frances Haugh
// SPDX-FileCopyrightText: 1996-2000, Marek Michałkiewicz
// SPDX-FileCopyrightText: 2001-2006, Tomasz Kłoczko
// SPDX-FileCopyrightText: 2007-2008, Nicolas François
// SPDX-FileCopyrightText: 2024, Alejandro Colomar <alx@kernel.org>
// SPDX-License-Identifier: BSD-3-Clause
#include <config.h>
@@ -15,7 +14,7 @@
#include <grp.h>
#include <pwd.h>
#include <stdio.h>
#include <assert.h>
#include <sys/types.h>
#include "agetpass.h"
#include "alloc/x/xmalloc.h"
@@ -25,11 +24,16 @@
#include "exitcodes.h"
#include "getdef.h"
#include "prototypes.h"
#include "search/l/lfind.h"
#include "search/l/lsearch.h"
#include "shadow/grp/agetgroups.h"
#include "shadowlog.h"
#include "string/sprintf/snprintf.h"
#include "string/strcmp/streq.h"
#include "string/strdup/xstrdup.h"
#include <assert.h>
/*
* Global variables
@@ -38,10 +42,8 @@ static const char *Prog;
extern char **newenvp;
#ifdef HAVE_SETGROUPS
static int ngroups;
static /*@null@*/ /*@only@*/GETGROUPS_T *grouplist;
#endif
static size_t ngroups;
static /*@null@*/ /*@only@*/gid_t *gids;
static bool is_newgrp;
@@ -372,7 +374,6 @@ static void syslog_sg (const char *name, const char *group)
int main (int argc, char **argv)
{
bool initflag = false;
int i;
bool is_member = false;
bool cflag = false;
int err = 0;
@@ -551,40 +552,27 @@ int main (int argc, char **argv)
}
}
#ifdef HAVE_SETGROUPS
/*
* get the current user's groupset. The new group will be added to
* the concurrent groupset if there is room, otherwise you get a
* nasty message but at least your real and effective group ids are
* set.
*/
/* don't use getgroups(0, 0) - it doesn't work on some systems */
i = 16;
for (;;) {
grouplist = XMALLOC(i, GETGROUPS_T);
ngroups = getgroups (i, grouplist);
if (i > ngroups && !(ngroups == -1 && errno == EINVAL)) {
break;
}
/* not enough room, so try allocating a larger buffer */
free (grouplist);
i *= 2;
}
if (ngroups < 0) {
perror ("getgroups");
gids = agetgroups(&ngroups);
if (gids == NULL) {
perror("agetgroups");
#ifdef WITH_AUDIT
if (group) {
SNPRINTF(audit_buf, "changing new-group=%s", group);
audit_logger (AUDIT_CHGRP_ID, Prog,
audit_buf, NULL, getuid (), 0);
audit_logger(AUDIT_CHGRP_ID, Prog,
audit_buf, NULL, getuid(), 0);
} else {
audit_logger (AUDIT_CHGRP_ID, Prog,
"changing", NULL, getuid (), 0);
audit_logger(AUDIT_CHGRP_ID, Prog,
"changing", NULL, getuid(), 0);
}
#endif
exit (EXIT_FAILURE);
exit(EXIT_FAILURE);
}
#endif /* HAVE_SETGROUPS */
/*
* now we put her in the new group. The password file entry for her
@@ -632,18 +620,12 @@ int main (int argc, char **argv)
goto failure;
}
#ifdef HAVE_SETGROUPS
/* when using pam_group, she will not be listed in the groups
* database. However getgroups() will return the group. So
* if she is listed there already it is ok to grant membership.
*/
for (i = 0; i < ngroups; i++) {
if (grp->gr_gid == grouplist[i]) {
is_member = true;
break;
}
}
#endif /* HAVE_SETGROUPS */
is_member = (LFIND(&grp->gr_gid, gids, ngroups) != NULL);
/*
* For split groups (due to limitations of NIS), check all
* groups of the same GID like the requested group for
@@ -688,29 +670,18 @@ int main (int argc, char **argv)
gid = grp->gr_gid;
#ifdef HAVE_SETGROUPS
/*
* I am going to try to add her new group id to her concurrent group
* set. If the group id is already present I'll just skip this part.
* If the group doesn't fit, I'll complain loudly and skip this
* part.
*/
for (i = 0; i < ngroups; i++) {
if (gid == grouplist[i]) {
break;
}
}
if (i == ngroups) {
if (ngroups >= sysconf (_SC_NGROUPS_MAX)) {
(void) fputs (_("too many groups\n"), stderr);
} else {
grouplist[ngroups++] = gid;
if (setgroups (ngroups, grouplist) != 0) {
perror ("setgroups");
}
}
}
#endif
gids = XREALLOC(gids, ngroups + 1, gid_t);
LSEARCH(&gid, gids, &ngroups);
if (setgroups(ngroups, gids) == -1)
perror("setgroups");
/*
* Close all files before changing the user/group IDs.
+21 -20
View File
@@ -28,6 +28,8 @@
#include <getopt.h>
#include <ctype.h>
#include <errno.h>
#include <stddef.h>
#include <stdint.h>
#include <string.h>
#include "alloc/reallocf.h"
@@ -321,7 +323,7 @@ static int add_group (const char *name, const char *gid, gid_t *ngid, uid_t uid)
if (is_shadow_grp) {
struct sgrp sgrent;
char *admins[1];
sgrent.sg_name = grent.gr_name;
sgrent.sg_namp = grent.gr_name;
sgrent.sg_passwd = "*"; /* XXX warning: const */
grent.gr_passwd = "x"; /* XXX warning: const */
admins[0] = NULL;
@@ -1062,14 +1064,14 @@ int main (int argc, char **argv)
char *cp;
const struct passwd *pw;
struct passwd newpw;
int line = 0;
intmax_t line = 0;
uid_t uid;
gid_t gid;
#ifdef USE_PAM
int *lines = NULL;
intmax_t *lines = NULL;
char **usernames = NULL;
char **passwords = NULL;
unsigned int nusers = 0;
size_t nusers = 0;
#endif /* USE_PAM */
log_set_progname(Prog);
@@ -1112,7 +1114,7 @@ int main (int argc, char **argv)
while (fgets (buf, sizeof buf, stdin) != NULL) {
line++;
if (stpsep(buf, "\n") == NULL && feof(stdin) == 0) {
fprintf (stderr, _("%s: line %d: line too long\n"),
fprintf (stderr, _("%s: line %jd: line too long\n"),
Prog, line);
fail_exit (EXIT_FAILURE);
}
@@ -1128,7 +1130,7 @@ int main (int argc, char **argv)
break;
}
if (nfields != 6) {
fprintf (stderr, _("%s: line %d: invalid line\n"),
fprintf (stderr, _("%s: line %jd: invalid line\n"),
Prog, line);
fail_exit (EXIT_FAILURE);
}
@@ -1147,7 +1149,7 @@ int main (int argc, char **argv)
if (NULL == pw && get_user_id(fields[2], &uid) != 0) {
fprintf (stderr,
_("%s: line %d: can't create user\n"),
_("%s: line %jd: can't create user\n"),
Prog, line);
fail_exit (EXIT_FAILURE);
}
@@ -1167,7 +1169,7 @@ int main (int argc, char **argv)
if ( (NULL == pw)
&& (add_group (fields[0], fields[3], &gid, uid) != 0)) {
fprintf (stderr,
_("%s: line %d: can't create group\n"),
_("%s: line %jd: can't create group\n"),
Prog, line);
fail_exit (EXIT_FAILURE);
}
@@ -1182,7 +1184,7 @@ int main (int argc, char **argv)
if ( (NULL == pw)
&& (add_user (fields[0], uid, gid) != 0)) {
fprintf (stderr,
_("%s: line %d: can't create user\n"),
_("%s: line %jd: can't create user\n"),
Prog, line);
fail_exit (EXIT_FAILURE);
}
@@ -1194,7 +1196,7 @@ int main (int argc, char **argv)
pw = pw_locate (fields[0]);
if (NULL == pw) {
fprintf (stderr,
_("%s: line %d: user '%s' does not exist in %s\n"),
_("%s: line %jd: user '%s' does not exist in %s\n"),
Prog, line, fields[0], pw_dbname ());
fail_exit (EXIT_FAILURE);
}
@@ -1203,12 +1205,12 @@ int main (int argc, char **argv)
#ifdef USE_PAM
/* keep the list of user/password for later update by PAM */
nusers++;
lines = REALLOCF(lines, nusers, int);
lines = REALLOCF(lines, nusers, intmax_t);
usernames = REALLOCF(usernames, nusers, char *);
passwords = REALLOCF(passwords, nusers, char *);
if (lines == NULL || usernames == NULL || passwords == NULL) {
fprintf (stderr,
_("%s: line %d: %s\n"),
_("%s: line %jd: %s\n"),
Prog, line, strerror(errno));
fail_exit (EXIT_FAILURE);
}
@@ -1218,7 +1220,7 @@ int main (int argc, char **argv)
#endif /* USE_PAM */
if (add_passwd (&newpw, fields[1]) != 0) {
fprintf (stderr,
_("%s: line %d: can't update password\n"),
_("%s: line %jd: can't update password\n"),
Prog, line);
fail_exit (EXIT_FAILURE);
}
@@ -1241,13 +1243,13 @@ int main (int argc, char **argv)
0777 & ~getdef_num ("UMASK", GETDEF_DEFAULT_UMASK));
if (newpw.pw_dir[0] != '/') {
fprintf(stderr,
_("%s: line %d: homedir must be an absolute path\n"),
_("%s: line %jd: homedir must be an absolute path\n"),
Prog, line);
fail_exit (EXIT_FAILURE);
}
if (mkdir (newpw.pw_dir, mode) != 0) {
fprintf (stderr,
_("%s: line %d: mkdir %s failed: %s\n"),
_("%s: line %jd: mkdir %s failed: %s\n"),
Prog, line, newpw.pw_dir,
strerror (errno));
if (errno != EEXIST) {
@@ -1257,7 +1259,7 @@ int main (int argc, char **argv)
if (chown(newpw.pw_dir, newpw.pw_uid, newpw.pw_gid) != 0)
{
fprintf (stderr,
_("%s: line %d: chown %s failed: %s\n"),
_("%s: line %jd: chown %s failed: %s\n"),
Prog, line, newpw.pw_dir,
strerror (errno));
fail_exit (EXIT_FAILURE);
@@ -1269,7 +1271,7 @@ int main (int argc, char **argv)
*/
if (pw_update (&newpw) == 0) {
fprintf (stderr,
_("%s: line %d: can't update entry\n"),
_("%s: line %jd: can't update entry\n"),
Prog, line);
fail_exit (EXIT_FAILURE);
}
@@ -1333,12 +1335,11 @@ int main (int argc, char **argv)
sssd_flush_cache (SSSD_DB_PASSWD | SSSD_DB_GROUP);
#ifdef USE_PAM
unsigned int i;
/* Now update the passwords using PAM */
for (i = 0; i < nusers; i++) {
for (size_t i = 0; i < nusers; i++) {
if (do_pam_passwd_non_interactive ("newusers", usernames[i], passwords[i]) != 0) {
fprintf (stderr,
_("%s: (line %d, user %s) password not changed\n"),
_("%s: (line %jd, user %s) password not changed\n"),
Prog, lines[i], usernames[i]);
exit (EXIT_FAILURE);
}
+24 -24
View File
@@ -73,8 +73,8 @@ NORETURN static void usage (int status);
static void process_flags (int argc, char **argv);
static void open_files (void);
static void close_files (bool changed);
static void check_pw_file (int *errors, bool *changed);
static void check_spw_file (int *errors, bool *changed);
static void check_pw_file (bool *errors, bool *changed);
static void check_spw_file (bool *errors, bool *changed);
extern int allow_bad_names;
@@ -367,7 +367,7 @@ static void close_files (bool changed)
/*
* check_pw_file - check the content of the passwd file
*/
static void check_pw_file (int *errors, bool *changed)
static void check_pw_file (bool *errors, bool *changed)
{
struct commonio_entry *pfe, *tpfe;
struct passwd *pwd;
@@ -399,7 +399,7 @@ static void check_pw_file (int *errors, bool *changed)
*/
puts (_("invalid password file entry"));
printf (_("delete line '%s'? "), pfe->line);
*errors += 1;
*errors = true;
/*
* prompt the user to delete the entry or not
@@ -460,7 +460,7 @@ static void check_pw_file (int *errors, bool *changed)
*/
puts (_("duplicate password entry"));
printf (_("delete line '%s'? "), pfe->line);
*errors += 1;
*errors = true;
/*
* prompt the user to delete the entry or not
@@ -482,7 +482,7 @@ static void check_pw_file (int *errors, bool *changed)
printf(_("invalid user name '%s'\n"),
pwd->pw_name);
}
*errors += 1;
*errors = true;
}
/*
@@ -490,7 +490,7 @@ static void check_pw_file (int *errors, bool *changed)
*/
if (pwd->pw_uid == (uid_t)-1) {
printf (_("invalid user ID '%lu'\n"), (long unsigned int)pwd->pw_uid);
*errors += 1;
*errors = true;
}
/*
@@ -505,7 +505,7 @@ static void check_pw_file (int *errors, bool *changed)
printf (_("user '%s': no group %lu\n"),
pwd->pw_name, (unsigned long) pwd->pw_gid);
*errors += 1;
*errors = true;
}
/*
@@ -524,7 +524,7 @@ static void check_pw_file (int *errors, bool *changed)
if (NULL == nonexistent || !streq(pwd->pw_dir, nonexistent)) {
printf (_("user '%s': directory '%s' does not exist\n"),
pwd->pw_name, pwd->pw_dir);
*errors += 1;
*errors = true;
}
}
}
@@ -541,7 +541,7 @@ static void check_pw_file (int *errors, bool *changed)
*/
printf (_("user '%s': program '%s' does not exist\n"),
pwd->pw_name, pwd->pw_shell);
*errors += 1;
*errors = true;
}
/*
@@ -556,10 +556,10 @@ static void check_pw_file (int *errors, bool *changed)
pwd->pw_name);
printf (_("create tcb directory for %s?"),
pwd->pw_name);
*errors += 1;
*errors = true;
if (yes_or_no (read_only)) {
if (shadowtcb_create (pwd->pw_name, pwd->pw_uid) == SHADOWTCB_FAILURE) {
*errors += 1;
*errors = true;
printf (_("failed to create tcb directory for %s\n"), pwd->pw_name);
continue;
}
@@ -568,7 +568,7 @@ static void check_pw_file (int *errors, bool *changed)
}
}
if (spw_lock () == 0) {
*errors += 1;
*errors = true;
fprintf (stderr,
_("%s: cannot lock %s.\n"),
Prog, spw_dbname ());
@@ -579,7 +579,7 @@ static void check_pw_file (int *errors, bool *changed)
fprintf (stderr,
_("%s: cannot open %s\n"),
Prog, spw_dbname ());
*errors += 1;
*errors = true;
if (spw_unlock () == 0) {
fprintf (stderr,
_("%s: failed to unlock %s\n"),
@@ -601,7 +601,7 @@ static void check_pw_file (int *errors, bool *changed)
spw_dbname ());
printf (_("add user '%s' in %s? "),
pwd->pw_name, spw_dbname ());
*errors += 1;
*errors = true;
if (yes_or_no (read_only)) {
struct spwd sp;
struct passwd pw;
@@ -650,7 +650,7 @@ static void check_pw_file (int *errors, bool *changed)
&& !streq(pwd->pw_passwd, SHADOW_PASSWD_STRING)) {
printf (_("user %s has an entry in %s, but its password field in %s is not set to 'x'\n"),
pwd->pw_name, spw_dbname (), pw_dbname ());
*errors += 1;
*errors = true;
}
}
}
@@ -687,7 +687,7 @@ static void check_pw_file (int *errors, bool *changed)
/*
* check_spw_file - check the content of the shadowed password file (shadow)
*/
static void check_spw_file (int *errors, bool *changed)
static void check_spw_file (bool *errors, bool *changed)
{
struct commonio_entry *spe, *tspe;
struct spwd *spw;
@@ -724,7 +724,7 @@ static void check_spw_file (int *errors, bool *changed)
*/
puts (_("invalid shadow password file entry"));
printf (_("delete line '%s'? "), spe->line);
*errors += 1;
*errors = true;
/*
* prompt the user to delete the entry or not
@@ -785,7 +785,7 @@ static void check_spw_file (int *errors, bool *changed)
*/
puts (_("duplicate shadow password entry"));
printf (_("delete line '%s'? "), spe->line);
*errors += 1;
*errors = true;
/*
* prompt the user to delete the entry or not
@@ -807,7 +807,7 @@ static void check_spw_file (int *errors, bool *changed)
printf (_("no matching password file entry in %s\n"),
pw_dbname ());
printf (_("delete line '%s'? "), spe->line);
*errors += 1;
*errors = true;
/*
* prompt the user to delete the entry or not
@@ -826,7 +826,7 @@ static void check_spw_file (int *errors, bool *changed)
&& (spw->sp_lstchg > t / DAY)) {
printf (_("user %s: last password change in the future\n"),
spw->sp_namp);
*errors += 1;
*errors = true;
}
}
}
@@ -837,7 +837,7 @@ static void check_spw_file (int *errors, bool *changed)
*/
int main (int argc, char **argv)
{
int errors = 0;
bool errors = false;
bool changed = false;
log_set_progname(Prog);
@@ -890,13 +890,13 @@ int main (int argc, char **argv)
/*
* Tell the user what we did and exit.
*/
if (0 != errors) {
if (errors) {
printf (changed ?
_("%s: the files have been updated\n") :
_("%s: no changes\n"), Prog);
}
closelog ();
return ((0 != errors) ? E_BADENTRY : E_OKAY);
return (errors ? E_BADENTRY : E_OKAY);
}
+1 -1
View File
@@ -590,7 +590,7 @@ static void check_perms_nopam (const struct passwd *pw)
* The first character of an administrator defined method is an '@'
* character.
*/
if (pw_auth (password, name, PW_SU, NULL) != 0) {
if (pw_auth(password, name) != 0) {
SYSLOG (((pw->pw_uid != 0)? LOG_NOTICE : LOG_WARN,
"Authentication failed for %s", name));
fprintf(stderr, _("%s: Authentication failure\n"), Prog);
+12 -11
View File
@@ -12,15 +12,16 @@
#include <errno.h>
#include <grp.h>
#include <pwd.h>
#include <stdint.h>
#include <stdio.h>
#include <string.h>
#include <sys/types.h>
#include "defines.h"
#include "prototypes.h"
#include "string/strchr/stpspn.h"
#include "string/strchr/strrspn.h"
#include "string/strcmp/streq.h"
#include "string/strspn/stpspn.h"
#include "string/strspn/stprspn.h"
#include "string/strtok/stpsep.h"
@@ -42,7 +43,7 @@ static int applies (const char *, char *);
static int isgrp (const char *, const char *);
static int lines = 0;
static intmax_t lines = 0;
int
@@ -78,12 +79,12 @@ check_su_auth(const char *actual_id, const char *wanted_id, bool su_to_root)
if (stpsep(temp, "\n") == NULL) {
SYSLOG ((LOG_ERR,
"%s, line %d: line too long or missing newline",
"%s, line %jd: line too long or missing newline",
SUAUTHFILE, lines));
continue;
}
stpcpy(strrspn(temp, " \t"), "");
stpcpy(stprspn(temp, " \t"), "");
p = stpspn(temp, " \t");
if (*p == '#' || streq(p, ""))
@@ -94,7 +95,7 @@ check_su_auth(const char *actual_id, const char *wanted_id, bool su_to_root)
action = strsep(&p, ":");
if (action == NULL || p != NULL) {
SYSLOG ((LOG_ERR,
"%s, line %d. Bad number of fields.\n",
"%s, line %jd. Bad number of fields.\n",
SUAUTHFILE, lines));
continue;
}
@@ -128,7 +129,7 @@ check_su_auth(const char *actual_id, const char *wanted_id, bool su_to_root)
return OWNPWORD;
} else {
SYSLOG ((LOG_ERR,
"%s, line %d: unrecognized action!\n",
"%s, line %jd: unrecognized action!\n",
SUAUTHFILE, lines));
}
}
@@ -148,7 +149,7 @@ applies(const char *single, char *list)
if (streq(tok, "ALL")) {
if (state != 0) {
SYSLOG ((LOG_ERR,
"%s, line %d: ALL in bad place\n",
"%s, line %jd: ALL in bad place\n",
SUAUTHFILE, lines));
return 0;
}
@@ -156,7 +157,7 @@ applies(const char *single, char *list)
} else if (streq(tok, "EXCEPT")) {
if (state != 1) {
SYSLOG ((LOG_ERR,
"%s, line %d: EXCEPT in bas place\n",
"%s, line %jd: EXCEPT in bas place\n",
SUAUTHFILE, lines));
return 0;
}
@@ -164,7 +165,7 @@ applies(const char *single, char *list)
} else if (streq(tok, "GROUP")) {
if ((state != 0) && (state != 2)) {
SYSLOG ((LOG_ERR,
"%s, line %d: GROUP in bad place\n",
"%s, line %jd: GROUP in bad place\n",
SUAUTHFILE, lines));
return 0;
}
@@ -177,7 +178,7 @@ applies(const char *single, char *list)
break;
case 1: /* An all */
SYSLOG ((LOG_ERR,
"%s, line %d: expect another token after ALL\n",
"%s, line %jd: expect another token after ALL\n",
SUAUTHFILE, lines));
return 0;
case 2: /* All except */
+15 -13
View File
@@ -67,6 +67,7 @@
#include "string/memset/memzero.h"
#include "string/sprintf/snprintf.h"
#include "string/sprintf/xasprintf.h"
#include "string/strcmp/strcaseeq.h"
#include "string/strcmp/streq.h"
#include "string/strdup/xstrdup.h"
#include "string/strtok/stpsep.h"
@@ -201,6 +202,7 @@ static bool home_added = false;
#define E_SUB_UID_UPDATE 16 /* can't update the subordinate uid file */
#define E_SUB_GID_UPDATE 18 /* can't update the subordinate gid file */
#endif /* ENABLE_SUBIDS */
#define E_BAD_NAME 19 /* Bad login name */
#define DGROUP "GROUP"
#define DGROUPS "GROUPS"
@@ -758,7 +760,7 @@ err_free_new:
static int get_groups (char *list)
{
struct group *grp;
int errors = 0;
bool errors = false;
int ngroups = 0;
/*
@@ -808,7 +810,7 @@ static int get_groups (char *list)
fprintf (stderr,
_("%s: group '%s' does not exist\n"),
Prog, g);
errors++;
errors = true;
}
/*
@@ -842,7 +844,7 @@ static int get_groups (char *list)
/*
* Any errors in finding group names are fatal
*/
if (0 != errors) {
if (errors) {
return -1;
}
@@ -1098,11 +1100,11 @@ static void grp_update (void)
* user_groups. All these groups should be checked
* for existence with gr_locate already.
*/
if (gr_locate (sgrp->sg_name) == NULL) {
if (gr_locate (sgrp->sg_namp) == NULL) {
continue;
}
if (!is_on_list (user_groups, sgrp->sg_name)) {
if (!is_on_list (user_groups, sgrp->sg_namp)) {
continue;
}
@@ -1133,7 +1135,7 @@ static void grp_update (void)
if (sgr_update (nsgrp) == 0) {
fprintf (stderr,
_("%s: failed to prepare the new %s entry '%s'\n"),
Prog, sgr_dbname (), nsgrp->sg_name);
Prog, sgr_dbname (), nsgrp->sg_namp);
SYSLOG ((LOG_ERR, "failed to prepare the new %s entry '%s'", sgr_dbname (), user_name));
#ifdef WITH_AUDIT
audit_logger (AUDIT_ADD_USER, Prog,
@@ -1151,7 +1153,7 @@ static void grp_update (void)
#endif
SYSLOG ((LOG_INFO,
"add '%s' to shadow group '%s'",
user_name, nsgrp->sg_name));
user_name, nsgrp->sg_namp));
}
#endif /* SHADOWGRP */
}
@@ -1549,7 +1551,7 @@ static void process_flags (int argc, char **argv)
user_name, AUDIT_NO_ID,
SHADOW_AUDIT_FAILURE);
#endif
exit (E_BAD_ARG);
exit (E_BAD_NAME);
}
if (!dflg) {
char *uh;
@@ -1913,7 +1915,7 @@ static void new_grent (struct group *grent)
static void new_sgent (struct sgrp *sgent)
{
memzero (sgent, sizeof *sgent);
sgent->sg_name = (char *) user_name;
sgent->sg_namp = (char *) user_name;
sgent->sg_passwd = "!"; /* XXX warning: const */
sgent->sg_adm = &empty_list;
sgent->sg_mem = &empty_list;
@@ -1965,7 +1967,7 @@ static void grp_add (void)
if (is_shadow_grp && (sgr_update (&sgrp) == 0)) {
fprintf (stderr,
_("%s: failed to prepare the new %s entry '%s'\n"),
Prog, sgr_dbname (), sgrp.sg_name);
Prog, sgr_dbname (), sgrp.sg_namp);
#ifdef WITH_AUDIT
audit_logger (AUDIT_ADD_GROUP, Prog,
"adding group",
@@ -2259,9 +2261,9 @@ static void create_home (void)
*/
for (cp = strtok(bhome, "/"); cp != NULL; cp = strtok(NULL, "/")) {
/* Avoid turning a relative path into an absolute path. */
if (bhome[0] == '/' || strlen(path) != 0) {
if (bhome[0] == '/' || !streq(path, ""))
strcat(path, "/");
}
strcat(path, cp);
if (access(path, F_OK) == 0) {
continue;
@@ -2360,7 +2362,7 @@ static void create_mail (void)
const char *spool;
struct group *gr;
if (strcasecmp(create_mail_spool, "yes") != 0)
if (!strcaseeq(create_mail_spool, "yes"))
return;
spool = getdef_str("MAIL_DIR");
+22 -17
View File
@@ -119,7 +119,7 @@ static void user_cancel (const char *);
static bool path_prefix (const char *, const char *);
#endif /* EXTRA_CHECK_HOME_DIR */
static int is_owner (uid_t, const char *);
static int remove_mailbox (void);
static bool remove_mailbox (void);
#ifdef WITH_TCB
static int remove_tcbdir (const char *user_name, uid_t user_id);
#endif /* WITH_TCB */
@@ -264,7 +264,7 @@ static void update_groups (void)
if (sgr_update (nsgrp) == 0) {
fprintf (stderr,
_("%s: failed to prepare the new %s entry '%s'\n"),
Prog, sgr_dbname (), nsgrp->sg_name);
Prog, sgr_dbname (), nsgrp->sg_namp);
exit (E_GRP_UPDATE);
}
#ifdef WITH_AUDIT
@@ -273,7 +273,7 @@ static void update_groups (void)
user_name, user_id, SHADOW_AUDIT_SUCCESS);
#endif /* WITH_AUDIT */
SYSLOG ((LOG_INFO, "delete '%s' from shadow group '%s'\n",
user_name, nsgrp->sg_name));
user_name, nsgrp->sg_namp));
}
#endif /* SHADOWGRP */
}
@@ -789,9 +789,10 @@ static int is_owner (uid_t uid, const char *path)
return (st.st_uid == uid) ? 1 : 0;
}
static int remove_mailbox (void)
static bool remove_mailbox (void)
{
int i, errors = 0;
int i;
bool errors = false;
char *mailfile;
const char *maildir;
@@ -844,7 +845,7 @@ static int remove_mailbox (void)
"deleting mail file",
user_name, user_id, SHADOW_AUDIT_FAILURE);
#endif /* WITH_AUDIT */
errors = 1;
errors = true;
/* continue */
}
#ifdef WITH_AUDIT
@@ -887,7 +888,7 @@ static int remove_mailbox (void)
"deleting mail file",
user_name, user_id, SHADOW_AUDIT_FAILURE);
#endif /* WITH_AUDIT */
errors = 1;
errors = true;
/* continue */
}
#ifdef WITH_AUDIT
@@ -951,7 +952,7 @@ static int remove_tcbdir (const char *user_name, uid_t user_id)
*/
int main (int argc, char **argv)
{
int errors = 0; /* Error in the removal of the home directory */
bool errors = false; /* Error in the removal of the home directory */
#ifdef ACCT_TOOLS_SETUID
#ifdef USE_PAM
@@ -1152,7 +1153,9 @@ int main (int argc, char **argv)
update_groups ();
if (rflg) {
errors += remove_mailbox ();
if (remove_mailbox ()) {
errors = true;
}
}
if (rflg) {
int home_owned = is_owner (user_id, user_home);
@@ -1166,7 +1169,7 @@ int main (int argc, char **argv)
_("%s: %s not owned by %s, not removing\n"),
Prog, user_home, user_name);
rflg = 0;
errors++;
errors = true;
/* continue */
}
}
@@ -1192,7 +1195,7 @@ int main (int argc, char **argv)
_("%s: not removing directory %s (would remove home of user %s)\n"),
Prog, user_home, pwd->pw_name);
rflg = false;
errors++;
errors = true;
/* continue */
break;
}
@@ -1205,7 +1208,7 @@ int main (int argc, char **argv)
#ifdef WITH_BTRFS
int is_subvolume = btrfs_is_subvolume (user_home);
if (is_subvolume < 0) {
errors++;
errors = true;
/* continue */
}
else if (is_subvolume > 0) {
@@ -1213,7 +1216,7 @@ int main (int argc, char **argv)
fprintf (stderr,
_("%s: error removing subvolume %s\n"),
Prog, user_home);
errors++;
errors = true;
/* continue */
}
}
@@ -1223,7 +1226,7 @@ int main (int argc, char **argv)
fprintf (stderr,
_("%s: error removing directory %s\n"),
Prog, user_home);
errors++;
errors = true;
/* continue */
}
#ifdef WITH_AUDIT
@@ -1236,7 +1239,7 @@ int main (int argc, char **argv)
#endif /* WITH_AUDIT */
}
#ifdef WITH_AUDIT
if (0 != errors) {
if (errors) {
audit_logger (AUDIT_DEL_USER, Prog,
"deleting home directory",
user_name, AUDIT_NO_ID,
@@ -1273,13 +1276,15 @@ int main (int argc, char **argv)
}
#ifdef WITH_TCB
errors += remove_tcbdir (user_name, user_id);
if (remove_tcbdir (user_name, user_id)) {
errors = true;
}
#endif /* WITH_TCB */
nscd_flush_cache ("passwd");
nscd_flush_cache ("group");
sssd_flush_cache (SSSD_DB_PASSWD | SSSD_DB_GROUP);
return ((0 != errors) ? E_HOMEDIR : E_SUCCESS);
return (errors ? E_HOMEDIR : E_SUCCESS);
}
+10 -10
View File
@@ -219,7 +219,7 @@ extern int allow_bad_names;
static int get_groups (char *list)
{
struct group *grp;
int errors = 0;
bool errors = false;
int ngroups = 0;
/*
@@ -257,7 +257,7 @@ static int get_groups (char *list)
if (NULL == grp) {
fprintf (stderr, _("%s: group '%s' does not exist\n"),
Prog, g);
errors++;
errors = true;
}
/*
@@ -288,7 +288,7 @@ static int get_groups (char *list)
/*
* Any errors in finding group names are fatal
*/
if (0 != errors) {
if (errors) {
return -1;
}
@@ -850,7 +850,7 @@ update_gshadow(const struct sgrp *sgrp)
* concurrent groups.
*/
is_member = Gflg && ( (was_member && aflg)
|| is_on_list (user_groups, sgrp->sg_name));
|| is_on_list (user_groups, sgrp->sg_namp));
if (!was_member && !was_admin && !is_member)
return;
@@ -885,7 +885,7 @@ update_gshadow(const struct sgrp *sgrp)
#endif
SYSLOG ((LOG_INFO,
"change admin '%s' to '%s' in shadow group '%s'",
user_name, user_newname, nsgrp->sg_name));
user_name, user_newname, nsgrp->sg_namp));
}
if (was_member) {
@@ -908,7 +908,7 @@ update_gshadow(const struct sgrp *sgrp)
SYSLOG ((LOG_INFO,
"change '%s' to '%s' in shadow group '%s'",
user_name, user_newname,
nsgrp->sg_name));
nsgrp->sg_namp));
}
} else {
/* User was a member but is no more a
@@ -923,7 +923,7 @@ update_gshadow(const struct sgrp *sgrp)
#endif
SYSLOG ((LOG_INFO,
"delete '%s' from shadow group '%s'",
user_name, nsgrp->sg_name));
user_name, nsgrp->sg_namp));
}
} else if (is_member) {
/* User was not a member but is now a member this
@@ -937,7 +937,7 @@ update_gshadow(const struct sgrp *sgrp)
user_newname, AUDIT_NO_ID, 1);
#endif
SYSLOG ((LOG_INFO, "add '%s' to shadow group '%s'",
user_newname, nsgrp->sg_name));
user_newname, nsgrp->sg_namp));
}
if (!changed)
goto free_nsgrp;
@@ -948,9 +948,9 @@ update_gshadow(const struct sgrp *sgrp)
if (sgr_update (nsgrp) == 0) {
fprintf (stderr,
_("%s: failed to prepare the new %s entry '%s'\n"),
Prog, sgr_dbname (), nsgrp->sg_name);
Prog, sgr_dbname (), nsgrp->sg_namp);
SYSLOG ((LOG_WARN, "failed to prepare the new %s entry '%s'",
sgr_dbname (), nsgrp->sg_name));
sgr_dbname (), nsgrp->sg_namp));
fail_exit (E_GRP_UPDATE);
}
+7 -1
View File
@@ -372,8 +372,14 @@ vipwedit (const char *file, int (*file_lock) (void), int (*file_unlock) (void))
}
}
if (orig_pgrp != -1)
if (orig_pgrp != -1) {
/* Restore terminal pgrp after editing. */
if (tcsetpgrp(STDIN_FILENO, orig_pgrp) == -1) {
fprintf(stderr, "%s: %s: %s", Prog,
"tcsetpgrp", strerror(errno));
}
sigprocmask(SIG_SETMASK, &omask, NULL);
}
if (-1 == pid) {
vipwexit (editor, 1, 1);