From b44052751e124dcea32a1eae93114dd48beb189f Mon Sep 17 00:00:00 2001 From: Chris Hofstaedtler Date: Tue, 6 Aug 2024 00:09:39 +0200 Subject: [PATCH] Drop Debian-only cppw, cpgr tools Closes: #750752 --- debian/copyright | 5 - debian/cpgr.8 | 1 - debian/cppw.8 | 27 -- debian/passwd.install | 1 - debian/passwd.links | 1 - debian/passwd.manpages | 2 - debian/patches/debian/cppw-Add-tool.patch | 287 ------------------ .../debian/cppw-add-selinux-support.patch | 63 ---- debian/patches/series | 2 - 9 files changed, 389 deletions(-) delete mode 100644 debian/cpgr.8 delete mode 100644 debian/cppw.8 delete mode 100644 debian/patches/debian/cppw-Add-tool.patch delete mode 100644 debian/patches/debian/cppw-add-selinux-support.patch diff --git a/debian/copyright b/debian/copyright index f9340eda..807d01ea 100644 --- a/debian/copyright +++ b/debian/copyright @@ -137,11 +137,6 @@ Copyright: 1999-2001, Ben Collins 2017-2022 Balint Reczey License: BSD-3-clause -Files: debian/patches/cppw-Add-tool.patch -Copyright: 1997, Guy Maor - 1999, Stephen Frost -License: GPL-2+ - Files: debian/passwd.expire.cron Copyright: 1999, Ben Collins License: BSD-3-clause diff --git a/debian/cpgr.8 b/debian/cpgr.8 deleted file mode 100644 index d62ec36f..00000000 --- a/debian/cpgr.8 +++ /dev/null @@ -1 +0,0 @@ -.so man8/cppw.8 diff --git a/debian/cppw.8 b/debian/cppw.8 deleted file mode 100644 index 6a9cc6fc..00000000 --- a/debian/cppw.8 +++ /dev/null @@ -1,27 +0,0 @@ -.TH CPPW 8 "7 Apr 2005" -.SH NAME -cppw, cpgr \- copy with locking the given file to the password or group file -.SH SYNOPSIS -\fBcppw\fR [\fB\-h\fR] [\fB\-s\fR] password_file -.br -\fBcpgr\fR [\fB\-h\fR] [\fB\-s\fR] group_file - -.SH DESCRIPTION -.BR cppw " and " cpgr -will copy, with locking, the given file to -.IR /etc/passwd " and " /etc/group ", respectively." -With the \fB\-s\fR flag, they will copy the shadow versions of those files, -.IR /etc/shadow " and " /etc/gshadow ", respectively." - -With the \fB\-h\fR flag, the commands display a short help message and exit -silently. -.SH "SEE ALSO" -.BR vipw (8), -.BR vigr (8), -.BR group (5), -.BR passwd (5), -.BR shadow (5), -.BR gshadow (5) -.SH AUTHOR -\fBcppw\fR and \fBcpgr\fR were written by Stephen Frost, based on -\fBvipw\fR and \fBvigr\fR written by Guy Maor. diff --git a/debian/passwd.install b/debian/passwd.install index b90a4392..00a0e859 100644 --- a/debian/passwd.install +++ b/debian/passwd.install @@ -8,7 +8,6 @@ usr/bin/gpasswd usr/bin/passwd usr/sbin/chgpasswd usr/sbin/chpasswd -usr/sbin/cppw usr/sbin/groupadd usr/sbin/groupdel usr/sbin/groupmod diff --git a/debian/passwd.links b/debian/passwd.links index 3d7cc843..69aaeb2b 100644 --- a/debian/passwd.links +++ b/debian/passwd.links @@ -1,2 +1 @@ -usr/sbin/cppw usr/sbin/cpgr usr/sbin/vipw usr/sbin/vigr diff --git a/debian/passwd.manpages b/debian/passwd.manpages index 6256ac08..0c09579f 100644 --- a/debian/passwd.manpages +++ b/debian/passwd.manpages @@ -1,5 +1,3 @@ -debian/cpgr.8 -debian/cppw.8 usr/share/man/*/man1/chage.1 usr/share/man/*/man1/chfn.1 usr/share/man/*/man1/chsh.1 diff --git a/debian/patches/debian/cppw-Add-tool.patch b/debian/patches/debian/cppw-Add-tool.patch deleted file mode 100644 index 485e3f07..00000000 --- a/debian/patches/debian/cppw-Add-tool.patch +++ /dev/null @@ -1,287 +0,0 @@ -From: Nicolas FRANCOIS -Date: Sat, 22 Jun 2024 17:39:41 +0200 -Subject: cppw: Add tool - ---- - po/POTFILES.in | 1 + - src/Makefile.am | 2 + - src/cppw.c | 238 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++ - 3 files changed, 241 insertions(+) - create mode 100644 src/cppw.c - -diff --git a/po/POTFILES.in b/po/POTFILES.in -index 6d2c052..1c7ffe3 100644 ---- a/po/POTFILES.in -+++ b/po/POTFILES.in -@@ -85,6 +85,7 @@ src/chfn.c - src/chgpasswd.c - src/chpasswd.c - src/chsh.c -+src/cppw.c - src/expiry.c - src/faillog.c - src/gpasswd.c -diff --git a/src/Makefile.am b/src/Makefile.am -index b6cb09e..c86ba52 100644 ---- a/src/Makefile.am -+++ b/src/Makefile.am -@@ -39,6 +39,7 @@ if WITH_SU - bin_PROGRAMS += su - endif - usbin_PROGRAMS = \ -+ cppw \ - chgpasswd \ - chpasswd \ - groupadd \ -@@ -104,6 +105,7 @@ newuidmap_LDADD = $(LDADD) $(LIBAUDIT) $(LIBSELINUX) $(LIBCAP) $(LIBECONF) -l - newgidmap_LDADD = $(LDADD) $(LIBAUDIT) $(LIBSELINUX) $(LIBCAP) $(LIBECONF) -ldl - chfn_LDADD = $(LDADD) $(LIBPAM) $(LIBAUDIT) $(LIBSELINUX) $(LIBCRYPT_NOPAM) $(LIBSKEY) $(LIBMD) $(LIBECONF) - chgpasswd_LDADD = $(LDADD) $(LIBPAM_SUID) $(LIBAUDIT) $(LIBSELINUX) $(LIBCRYPT) $(LIBECONF) -+cppw_LDADD = $(LDADD) $(LIBAUDIT) $(LIBSELINUX) - chsh_LDADD = $(LDADD) $(LIBPAM) $(LIBAUDIT) $(LIBSELINUX) $(LIBCRYPT_NOPAM) $(LIBSKEY) $(LIBMD) $(LIBECONF) - chpasswd_LDADD = $(LDADD) $(LIBPAM) $(LIBAUDIT) $(LIBSELINUX) $(LIBCRYPT) $(LIBECONF) -ldl - expiry_LDADD = $(LDADD) $(LIBECONF) -diff --git a/src/cppw.c b/src/cppw.c -new file mode 100644 -index 0000000..beb4c36 ---- /dev/null -+++ b/src/cppw.c -@@ -0,0 +1,238 @@ -+/* -+ cppw, cpgr copy with locking given file over the password or group file -+ with -s will copy with locking given file over shadow or gshadow file -+ -+ Copyright (C) 1999 Stephen Frost -+ -+ Based on vipw, vigr by: -+ Copyright (C) 1997 Guy Maor -+ -+ This program is free software; you can redistribute it and/or modify -+ it under the terms of the GNU General Public License as published by -+ the Free Software Foundation; either version 2 of the License, or -+ (at your option) any later version. -+ -+ This program is distributed in the hope that it will be useful, but -+ WITHOUT ANY WARRANTY; without even the implied warranty of -+ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU -+ General Public License for more details. -+ -+ You should have received a copy of the GNU General Public License -+ along with this program; if not, write to the Free Software -+ Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA. -+ -+ */ -+ -+#include -+#include "defines.h" -+ -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include -+#include "exitcodes.h" -+#include "prototypes.h" -+#include "pwio.h" -+#include "shadowio.h" -+#include "groupio.h" -+#include "sgroupio.h" -+ -+ -+const char *Prog; -+ -+const char *filename, *filenewname; -+static bool filelocked = false; -+static int (*unlock) (void); -+ -+/* local function prototypes */ -+static int create_copy (FILE *fp, const char *dest, struct stat *sb); -+static void cppwexit (const char *msg, int syserr, int ret); -+static void cppwcopy (const char *file, -+ const char *in_file, -+ int (*file_lock) (void), -+ int (*file_unlock) (void)); -+ -+static int create_copy (FILE *fp, const char *dest, struct stat *sb) -+{ -+ struct utimbuf ub; -+ FILE *bkfp; -+ int c; -+ mode_t mask; -+ -+ mask = umask (077); -+ bkfp = fopen (dest, "w"); -+ (void) umask (mask); -+ if (NULL == bkfp) { -+ return -1; -+ } -+ -+ rewind (fp); -+ while ((c = getc (fp)) != EOF) { -+ if (putc (c, bkfp) == EOF) { -+ break; -+ } -+ } -+ -+ if ( (c != EOF) -+ || (fflush (bkfp) != 0)) { -+ (void) fclose (bkfp); -+ (void) unlink (dest); -+ return -1; -+ } -+ if ( (fsync (fileno (bkfp)) != 0) -+ || (fclose (bkfp) != 0)) { -+ (void) unlink (dest); -+ return -1; -+ } -+ -+ ub.actime = sb->st_atime; -+ ub.modtime = sb->st_mtime; -+ if ( (utime (dest, &ub) != 0) -+ || (chmod (dest, sb->st_mode) != 0) -+ || (chown (dest, sb->st_uid, sb->st_gid) != 0)) { -+ (void) unlink (dest); -+ return -1; -+ } -+ return 0; -+} -+ -+static void cppwexit (const char *msg, int syserr, int ret) -+{ -+ int err = errno; -+ if (filelocked) { -+ (*unlock) (); -+ } -+ if (NULL != msg) { -+ fprintf (stderr, "%s: %s", Prog, msg); -+ if (0 != syserr) { -+ fprintf (stderr, ": %s", strerror (err)); -+ } -+ (void) fputs ("\n", stderr); -+ } -+ if (NULL != filename) { -+ fprintf (stderr, _("%s: %s is unchanged\n"), Prog, filename); -+ } else { -+ fprintf (stderr, _("%s: no changes\n"), Prog); -+ } -+ -+ exit (ret); -+} -+ -+static void cppwcopy (const char *file, -+ const char *in_file, -+ int (*file_lock) (void), -+ int (*file_unlock) (void)) -+{ -+ struct stat st1; -+ FILE *f; -+ char filenew[1024]; -+ -+ snprintf (filenew, sizeof filenew, "%s.new", file); -+ unlock = file_unlock; -+ filename = file; -+ filenewname = filenew; -+ -+ if (access (file, F_OK) != 0) { -+ cppwexit (file, 1, 1); -+ } -+ if (file_lock () == 0) { -+ cppwexit (_("Couldn't lock file"), 0, 5); -+ } -+ filelocked = true; -+ -+ /* file to copy has same owners, perm */ -+ if (stat (file, &st1) != 0) { -+ cppwexit (file, 1, 1); -+ } -+ f = fopen (in_file, "r"); -+ if (NULL == f) { -+ cppwexit (in_file, 1, 1); -+ } -+ if (create_copy (f, filenew, &st1) != 0) { -+ cppwexit (_("Couldn't make copy"), errno, 1); -+ } -+ -+ /* XXX - here we should check filenew for errors; if there are any, -+ * fail w/ an appropriate error code and let the user manually fix -+ * it. Use pwck or grpck to do the check. - Stephen (Shamelessly -+ * stolen from '--marekm's comment) */ -+ -+ if (rename (filenew, file) != 0) { -+ fprintf (stderr, _("%s: can't copy %s: %s)\n"), -+ Prog, filenew, strerror (errno)); -+ cppwexit (NULL,0,1); -+ } -+ -+ (*file_unlock) (); -+} -+ -+int main (int argc, char **argv) -+{ -+ int flag; -+ bool cpshadow = false; -+ char *in_file; -+ int e = E_USAGE; -+ bool do_cppw = true; -+ -+ (void) setlocale (LC_ALL, ""); -+ (void) bindtextdomain (PACKAGE, LOCALEDIR); -+ (void) textdomain (PACKAGE); -+ -+ Prog = Basename (argv[0]); -+ if (strcmp (Prog, "cpgr") == 0) { -+ do_cppw = false; -+ } -+ -+ while ((flag = getopt (argc, argv, "ghps")) != EOF) { -+ switch (flag) { -+ case 'p': -+ do_cppw = true; -+ break; -+ case 'g': -+ do_cppw = false; -+ break; -+ case 's': -+ cpshadow = true; -+ break; -+ case 'h': -+ e = E_SUCCESS; -+ /*pass through*/ -+ default: -+ (void) fputs (_("Usage:\n\ -+`cppw ' copys over /etc/passwd `cppw -s ' copys over /etc/shadow\n\ -+`cpgr ' copys over /etc/group `cpgr -s ' copys over /etc/gshadow\n\ -+"), (E_SUCCESS != e) ? stderr : stdout); -+ exit (e); -+ } -+ } -+ -+ if (argc != optind + 1) { -+ cppwexit (_("wrong number of arguments, -h for usage"),0,1); -+ } -+ -+ in_file = argv[optind]; -+ -+ if (do_cppw) { -+ if (cpshadow) { -+ cppwcopy (SHADOW_FILE, in_file, spw_lock, spw_unlock); -+ } else { -+ cppwcopy (PASSWD_FILE, in_file, pw_lock, pw_unlock); -+ } -+ } else { -+#ifdef SHADOWGRP -+ if (cpshadow) { -+ cppwcopy (SGROUP_FILE, in_file, sgr_lock, sgr_unlock); -+ } else -+#endif /* SHADOWGRP */ -+ { -+ cppwcopy (GROUP_FILE, in_file, gr_lock, gr_unlock); -+ } -+ } -+ -+ return 0; -+} -+ diff --git a/debian/patches/debian/cppw-add-selinux-support.patch b/debian/patches/debian/cppw-add-selinux-support.patch deleted file mode 100644 index a554373a..00000000 --- a/debian/patches/debian/cppw-add-selinux-support.patch +++ /dev/null @@ -1,63 +0,0 @@ -From: Shadow package maintainers -Date: Sat, 22 Jun 2024 17:39:41 +0200 -Subject: cppw: add selinux support - -Status wrt upstream: cppw is not available upstream. -Needs to be reviewed by an SE-Linux aware person. ---- - src/cppw.c | 28 ++++++++++++++++++++++++++++ - 1 file changed, 28 insertions(+) - -diff --git a/src/cppw.c b/src/cppw.c -index beb4c36..2cbbbc0 100644 ---- a/src/cppw.c -+++ b/src/cppw.c -@@ -34,6 +34,9 @@ - #include - #include - #include -+#ifdef WITH_SELINUX -+#include -+#endif /* WITH_SELINUX */ - #include "exitcodes.h" - #include "prototypes.h" - #include "pwio.h" -@@ -139,6 +142,22 @@ static void cppwcopy (const char *file, - if (access (file, F_OK) != 0) { - cppwexit (file, 1, 1); - } -+#ifdef WITH_SELINUX -+ /* if SE Linux is enabled then set the context of all new files -+ * to be the context of the file we are editing */ -+ if (is_selinux_enabled () > 0) { -+ security_context_t passwd_context=NULL; -+ int ret = 0; -+ if (getfilecon (file, &passwd_context) < 0) { -+ cppwexit (_("Couldn't get file context"), errno, 1); -+ } -+ ret = setfscreatecon (passwd_context); -+ freecon (passwd_context); -+ if (0 != ret) { -+ cppwexit (_("setfscreatecon () failed"), errno, 1); -+ } -+ } -+#endif /* WITH_SELINUX */ - if (file_lock () == 0) { - cppwexit (_("Couldn't lock file"), 0, 5); - } -@@ -167,6 +186,15 @@ static void cppwcopy (const char *file, - cppwexit (NULL,0,1); - } - -+#ifdef WITH_SELINUX -+ /* unset the fscreatecon */ -+ if (is_selinux_enabled () > 0) { -+ if (setfscreatecon (NULL)) { -+ cppwexit (_("setfscreatecon() failed"), errno, 1); -+ } -+ } -+#endif /* WITH_SELINUX */ -+ - (*file_unlock) (); - } - diff --git a/debian/patches/series b/debian/patches/series index 417e25ce..a8e7195b 100644 --- a/debian/patches/series +++ b/debian/patches/series @@ -1,5 +1,3 @@ -debian/cppw-Add-tool.patch -debian/cppw-add-selinux-support.patch debian/Let-pam_unix-handle-login-failure-delays.patch debian/Set-group-and-mode-for-g-shadow-files.patch debian/Keep-using-Debian-adduser-defaults.patch