summaryrefslogtreecommitdiff
path: root/lib/libutil/pw_util.c
Commit message (Collapse)AuthorAgeFilesLines
* Make vipw error message less crypticPiotr Pawel Stefaniak2020-06-201-5/+8
| | | | | | | | | | | | | | | | | | | | | | | | Unable to find an editor, vipw would give this error: # env EDITOR=fnord vipw vipw: pw_edit(): No such file or directory vigr or crontab do better: # env EDITOR=fnord crontab -e crontab: no crontab for root - using an empty one crontab: fnord: No such file or directory crontab: "fnord" exited with status 1 After this change, vipw behaves more like vigr or crontab: # env EDITOR=fnord vipw vipw: fnord: No such file or directory vipw: "fnord" exited with status 1 Reviewed by: rpokala, emaste MFC after: 1 week Differential Revision: https://reviews.freebsd.org/D25369 Notes: svn path=/head/; revision=362430
* libutil: remove extraneous ": " from error messagesPiotr Pawel Stefaniak2020-06-201-2/+2
| | | | | | | Each of the err() family of functions already takes care of that. Notes: svn path=/head/; revision=362429
* Make pw_scan(3) more compatible with getpwent(3) et. al. when processingIan Lepore2018-07-261-1/+10
| | | | | | | | | | | | | | | | | | | | | | | | | | | | data from /etc/passwd rather than /etc/master.passwd. The libc getpwent(3) and related functions automatically read master.passwd when run by root, or passwd when run by a non-root user. When run by non- root, getpwent() copes with the missing data by setting the corresponding fields in the passwd struct to known values (zeroes for numbers, or a pointer to an empty string for literals). When libutil's pw_scan(3) was used to parse a line without the root-accessible data, it was leaving garbage in the corresponding fields. These changes rename the static pw_init() function used by getpwent() and friends to __pw_initpwd(), and move it into pw_scan.c so that common init code can be shared between libc and libutil. pw_scan(3) now calls __pw_initpwd() before __pw_scan(), just like the getpwent() family does, so that reading an arbitrary passwd file in either format and parsing it with pw_scan(3) returns the same results as getpwent(3) would. This also adds a new pw_initpwd(3) function to libutil, so that code which creates passwd structs from scratch in some manner that doesn't involve pw_scan() can initialize the struct to the values expected by lots of existing code, which doesn't expect to encounter NULL pointers or garbage values in some fields. Notes: svn path=/head/; revision=336746
* Use __SCCSID() for SCCS IDs.John Baldwin2018-05-231-7/+3
| | | | | | | | | - Define NO__SCCSID in CFLAGS to preserve existing behavior of omitting SCCS IDs by default. - While here, fix the $FreeBSD$ in pw_util.c to use __FBSDID. Notes: svn path=/head/; revision=334106
* General further adoption of SPDX licensing ID tags.Pedro F. Giffuni2017-11-201-1/+3
| | | | | | | | | | | | | | | | | Mainly focus on files that use BSD 3-Clause license. The Software Package Data Exchange (SPDX) group provides a specification to make it easier for automated tools to detect and summarize well known opensource licenses. We are gradually adopting the specification, noting that the tags are considered only advisory and do not, in any way, superceed or replace the license texts. Special thanks to Wind River for providing access to "The Duke of Highlander" tool: an older (2014) run over FreeBSD tree was useful as a starting point. Notes: svn path=/head/; revision=326025
* lib: initial use of reallocarray(3).Pedro F. Giffuni2017-04-211-1/+1
| | | | | | | | | | | Make some use of reallocarray, attempting to limit it to cases where the parameters are unsigned and there is some theoretical chance of overflow. MFC afer: 2 weeks Differential Revision: https://reviews.freebsd.org/D9980 Notes: svn path=/head/; revision=317265
* Renumber copyright clause 4Warner Losh2017-02-281-1/+1
| | | | | | | | | | | | Renumber cluase 4 to 3, per what everybody else did when BSD granted them permission to remove clause 3. My insistance on keeping the same numbering for legal reasons is too pedantic, so give up on that point. Submitted by: Jan Schaumann <jschauma@stevens.edu> Pull Request: https://github.com/freebsd/freebsd/pull/96 Notes: svn path=/head/; revision=314436
* Use malloc()ed buffers instead of stack buffers in gr_copy() and pw_copy().Dag-Erling Smørgrav2016-11-281-13/+24
| | | | | | | | | | | | This allows pw(8) to operate on passwd and group files with longer lines than could be accomodated by a stack buffer. It doesn't take more than a few hundred users to exceed 8192 bytes in /etc/group. MFC after: 3 weeks Sponsored by: The University of Oslo Notes: svn path=/head/; revision=309269
* Speed up pw operations that edit /etc/group or /etc/passwdAlan Somers2016-11-181-1/+1
| | | | | | | | | | | | | | | | | r285050 fixed a bug in pw that could lead to /etc/passwd or /etc/group corruption on power loss. However, it fixed it by opening those files with O_SYNC, which is very slow, especially on ZFS. This change replaces O_SYNC with appropriately placed fsync()s instead, which is much faster. Using a ZFS tmpdir, the time to run pw's kyua tests drops from 245s to 35s. Reviewed by: allanjude, bapt, vangyzen, garga Tested on pfSense by: garga MFC after: 4 weeks Sponsored by: Spectra Logic Corp Differential Revision: https://reviews.freebsd.org/D8319 Notes: svn path=/head/; revision=308806
* Remove useless calls to basename().Ed Schouten2016-05-011-2/+1
| | | | | | | | | | | | | | | | | There are a couple of places in the source three where we call basename() on constant strings. This is bad, because the prototype standardized by POSIX allows the implementation to use its argument as a storage buffer. This change eliminates some of these unportable calls to basename() in cases where it was only added for cosmetical reasons, namely to trim argv[0]. There's nothing wrong with setting argv[0] to the full path. Reviewed by: jilles Differential Revision: https://reviews.freebsd.org/D6093 Notes: svn path=/head/; revision=298876
* When passwd or group information is changed (by pw, vipw, chpass, ...)Renato Botelho2015-07-021-1/+1
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | temporary file is created and then a rename() call move it to official file. This operation didn't have any check to make sure data was written to disk and if a power cycle happens system could end up with a 0 length passwd or group database. There is a pfSense bug with more infor about it: https://redmine.pfsense.org/issues/4523 The following changes were made to protect passwd and group operations: * lib/libutil/gr_util.c: - Replace mkstemp() by mkostemp() with O_SYNC flag to create temp file - After rename(), fsync() call on directory for faster result * lib/libutil/pw_util.c - Replace mkstemp() by mkostemp() with O_SYNC flag to create temp file * usr.sbin/pwd_mkdb/pwd_mkdb.c - Added O_SYNC flag on dbopen() calls - After rename(), fsync() call on directory for faster result * lib/libutil/pw_util.3 - pw_lock() returns a file descriptor to master password file on success Differential Revision: https://reviews.freebsd.org/D2978 Approved by: bapt Sponsored by: Netgate Notes: svn path=/head/; revision=285050
* revert r283969,283970 not needed anymore after r283981Baptiste Daroussin2015-06-041-25/+3
| | | | Notes: svn path=/head/; revision=283984
* Add a pw_mkdb2(3) function which does the same thing as pw_mkdb(3) exceptBaptiste Daroussin2015-06-031-3/+25
| | | | | | | | | | | it takes a new argument allowing to specify the endianness of the database to generate Differential Revision: https://reviews.freebsd.org/D2730 Reviewed by: ian Notes: svn path=/head/; revision=283969
* Add O_CLOEXEC to flopenBaptiste Daroussin2012-12-271-1/+1
| | | | | | | Requested by: jilles Notes: svn path=/head/; revision=244744
* Use flopen(3) instead of open(2) + flock(2)Baptiste Daroussin2012-12-271-5/+2
| | | | Notes: svn path=/head/; revision=244735
* backout r242319, racy and not done in the right placeBaptiste Daroussin2012-10-291-9/+0
| | | | | | | Reported by: Garrett Cooper <yanegomi@gmail.com> Notes: svn path=/head/; revision=242324
* make pw_init and gr_init fail if the specified master password or group file isBaptiste Daroussin2012-10-291-0/+9
| | | | | | | | | a directory. MFC after: 1 month Notes: svn path=/head/; revision=242319
* Revert user comparison back to user names as some user can share uids (root/toorBaptiste Daroussin2012-06-191-6/+13
| | | | | | | | | | | | | | for example) get the username information from old_pw structures to still allow renaming of a user. Reported by: Claude Buisson <clbuisson@orange.fr> Approved by: des (mentor) MFC after: 3 weeks Notes: svn path=/head/; revision=237268
* Detect file modification properly by using tv_nsec.Ed Schouten2012-02-101-1/+2
| | | | | | | | | | POSIX 2008 standardizes st_mtim, meaning we can simply use nanosecond precision to detect file modification. MFC after: 2 weeks Notes: svn path=/head/; revision=231383
* Add new pw_make_v7 to make a passwd line (in v7 format) out of a struct passwdBaptiste Daroussin2012-01-051-1/+15
| | | | | | | | | while here, fix missing parentheses of the return statement of pw_make. Approved by: des (mentor) Notes: svn path=/head/; revision=229572
* Modify pw_copy:Baptiste Daroussin2011-12-151-12/+29
| | | | | | | | | | | | | | | | - if pw is NULL and oldpw is not NULL then the oldpw is deleted - if pw->pw_name != oldpw->pw_name but pw->pw_uid == oldpw->pw_uid then it renames the user add new gr_* functions so now gr_util API is similar to pw_util API, this allow to manipulate groups in a safe way. Reviewed by: des Approved by: des MFC after: 1 month Notes: svn path=/head/; revision=228545
* Old patch I had lying around: clean up and use stpcpy(3) instead ofDag-Erling Smørgrav2010-08-161-27/+34
| | | | | | | sprintf(3). Notes: svn path=/head/; revision=211392
* sigset() is the name of function specified by SUSv4.Konstantin Belousov2009-11-261-4/+4
| | | | | | | | | Replace it to avoid conflict. MFC after: 3 weeks Notes: svn path=/head/; revision=199826
* Remove California Regent's clause 3, per letterWarner Losh2007-01-091-4/+0
| | | | Notes: svn path=/head/; revision=165906
* Minor comment fix.Thomas Quinot2006-09-081-1/+1
| | | | Notes: svn path=/head/; revision=162141
* (pw_copy): Handle the case of a malformed line in master.passwdThomas Quinot2006-09-041-2/+11
| | | | | | | | | | | (copy it silently, do not dereference NULL pointer). PR: bin/102848 Reviewed by: security-officer (cperciva) MFC after: 1 week Notes: svn path=/head/; revision=161997
* Don't depend on NULL's expansion being a pointer, cast it before it is passedStefan Farfeleder2004-05-181-3/+4
| | | | | | | | | to variadic functions. Approved by: das (mentor) Notes: svn path=/head/; revision=129392
* ANSIfy, WARNSify, CONSTify. Bit of style(9)-ify.Mark Murray2003-10-181-29/+36
| | | | Notes: svn path=/head/; revision=121193
* Tidy up. Sort headers.Mark Murray2003-06-141-1/+1
| | | | Notes: svn path=/head/; revision=116344
* Brucify.Dag-Erling Smørgrav2003-04-101-4/+8
| | | | Notes: svn path=/head/; revision=113333
* Correctly detect the case where a password entry was changed while we wereDag-Erling Smørgrav2003-04-091-2/+7
| | | | | | | | | preparing to edit it. PR: bin/50563 Notes: svn path=/head/; revision=113305
* Apply the correct fix for bin/50679: don't mess around with process groupsDag-Erling Smørgrav2003-04-091-13/+19
| | | | | | | | | | or the tty, just block selected signals in the parent like system(3) does. Many thanks to bde for his assistance in finding the correct solution. PR: bin/50679 Notes: svn path=/head/; revision=113301
* Band-aid for the "^C kills the editor" problem. I haven't yet found theDag-Erling Smørgrav2003-04-081-10/+6
| | | | | | | | | | | proper way to fix this. The way this works is to prepend "exec " to the editor command to eliminate the "shell in the middle" which prevents us from properly reawakening the editor after a SIGTSTP. PR: bin/50679 Notes: svn path=/head/; revision=113265
* Make pw_edit() use /bin/sh to interpret the EDITOR environmentDavid Schultz2003-03-171-2/+12
| | | | | | | | | | variable. PR: 48748 Reviewed by: mike (mentor) Notes: svn path=/head/; revision=112328
* Don't forget to '\n'-terminate new entries. This unbreaks chpass -a.Dag-Erling Smørgrav2002-10-291-1/+2
| | | | | | | Submitted by: joerg Notes: svn path=/head/; revision=106140
* Be more clear in error messages.Nick Hibma2002-06-231-4/+9
| | | | | | | | | | Distinguish between a held lock and a failed lock op. If rpc.lockd is not running on a diskless client this makes clearer what the problem is. Notes: svn path=/head/; revision=98693
* If no old_pw was passed to pw_copy, compare just the name.Dag-Erling Smørgrav2002-05-081-1/+2
| | | | | | | Sponsored by: DARPA, NAI Labs Notes: svn path=/head/; revision=96220
* Add passwd manipulation code based on parts of vipw and chpass.Dag-Erling Smørgrav2002-05-081-82/+404
| | | | | | | Sponsored by: DARPA, NAI Labs Notes: svn path=/head/; revision=96199
* Make mppath and masterpasswd pointers instead of arrays, and initializeDag-Erling Smørgrav2002-04-171-2/+4
| | | | | | | | | | | | them to point at static strings that contain the default paths. This makes 'vipw -d' work again (I broke it in rev 1.21; apologies for taking so long to fix it.) Spotted by: Olivier Houchard <doginou@cognet.ci0.org> Sponsored by: DARPA, NAI Labs Notes: svn path=/head/; revision=94897
* Remove bogus reference to _use_yp.Dag-Erling Smørgrav2002-04-151-9/+1
| | | | Notes: svn path=/head/; revision=94776
* ANSIfy and constify.Dag-Erling Smørgrav2002-02-051-17/+15
| | | | | | | Sponsored by: DARPA, NAI Labs Notes: svn path=/head/; revision=90233
* Fix the type of the NULL arg to execl()Brian Somers2001-07-091-3/+3
| | | | | | | Idea from: Theo de Raadt <deraadt@openbsd.org> Notes: svn path=/head/; revision=79452
* Don't pass NULL to the %s format.Dima Dorfman2001-04-221-2/+6
| | | | | | | Reviewed by: kris Notes: svn path=/head/; revision=75821
* Don't call warn() without a format string.Kris Kennaway2000-07-121-1/+1
| | | | Notes: svn path=/head/; revision=62988
* $Id$ -> $FreeBSD$Peter Wemm1999-08-281-1/+1
| | | | Notes: svn path=/head/; revision=50479
* Move call to umask(0) back into pw_util(), because the latterPierre Beyssac1999-06-291-1/+4
| | | | | | | function is also used by chpass(1) and passwd(1). Notes: svn path=/head/; revision=48328
* Force umask to 077 (instead of 000) during the edit phase, to getPierre Beyssac1999-06-261-4/+1
| | | | | | | | | | | | | secure permissions in case the user attempts to save something to a file of his own. Move umask stuff out of pw_init() into main() for better visibility of overall umask tweaking logic. PR: misc/11797 Notes: svn path=/head/; revision=48241
* Add -d option to vipw(8) to allow selection of an alternative directorySheldon Hearn1999-06-261-8/+14
| | | | | | | | | | for the password files. PR: 2703 Submitted by: jmg Notes: svn path=/head/; revision=48232
* oops. Fix indentation of the 'for' loop I just added.Matthew Dillon1998-12-131-18/+18
| | | | Notes: svn path=/head/; revision=41711
* Handle the race condition where vipw may lock a password file which hasMatthew Dillon1998-12-131-6/+22
| | | | | | | | just been replaced. After our lock succeeds we check if st_nlink is 0 and if it is we close the descriptor and retry our open/lock sequence. Notes: svn path=/head/; revision=41710