getpwent.c revision 1.56 1 1.56 lukem /* $NetBSD: getpwent.c,v 1.56 2003/11/26 00:48:59 lukem Exp $ */
2 1.12 cgd
3 1.1 cgd /*
4 1.12 cgd * Copyright (c) 1988, 1993
5 1.12 cgd * The Regents of the University of California. All rights reserved.
6 1.54 agc *
7 1.54 agc * Redistribution and use in source and binary forms, with or without
8 1.54 agc * modification, are permitted provided that the following conditions
9 1.54 agc * are met:
10 1.54 agc * 1. Redistributions of source code must retain the above copyright
11 1.54 agc * notice, this list of conditions and the following disclaimer.
12 1.54 agc * 2. Redistributions in binary form must reproduce the above copyright
13 1.54 agc * notice, this list of conditions and the following disclaimer in the
14 1.54 agc * documentation and/or other materials provided with the distribution.
15 1.54 agc * 3. Neither the name of the University nor the names of its contributors
16 1.54 agc * may be used to endorse or promote products derived from this software
17 1.54 agc * without specific prior written permission.
18 1.54 agc *
19 1.54 agc * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
20 1.54 agc * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
21 1.54 agc * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
22 1.54 agc * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
23 1.54 agc * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
24 1.54 agc * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
25 1.54 agc * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
26 1.54 agc * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
27 1.54 agc * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
28 1.54 agc * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
29 1.54 agc * SUCH DAMAGE.
30 1.54 agc */
31 1.54 agc
32 1.54 agc /*
33 1.14 phil * Portions Copyright (c) 1994, 1995, Jason Downs. All rights reserved.
34 1.1 cgd *
35 1.1 cgd * Redistribution and use in source and binary forms, with or without
36 1.1 cgd * modification, are permitted provided that the following conditions
37 1.1 cgd * are met:
38 1.1 cgd * 1. Redistributions of source code must retain the above copyright
39 1.1 cgd * notice, this list of conditions and the following disclaimer.
40 1.1 cgd * 2. Redistributions in binary form must reproduce the above copyright
41 1.1 cgd * notice, this list of conditions and the following disclaimer in the
42 1.1 cgd * documentation and/or other materials provided with the distribution.
43 1.1 cgd *
44 1.55 agc * THIS SOFTWARE IS PROVIDED BY THE AUTHOR(S) ``AS IS'' AND ANY EXPRESS
45 1.55 agc * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
46 1.55 agc * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
47 1.55 agc * DISCLAIMED. IN NO EVENT SHALL THE AUTHOR(S) BE LIABLE FOR ANY DIRECT,
48 1.55 agc * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
49 1.55 agc * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
50 1.55 agc * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
51 1.55 agc * CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
52 1.1 cgd * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
53 1.1 cgd * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
54 1.1 cgd * SUCH DAMAGE.
55 1.1 cgd */
56 1.1 cgd
57 1.22 christos #include <sys/cdefs.h>
58 1.1 cgd #if defined(LIBC_SCCS) && !defined(lint)
59 1.12 cgd #if 0
60 1.24 perry static char sccsid[] = "@(#)getpwent.c 8.2 (Berkeley) 4/27/95";
61 1.12 cgd #else
62 1.56 lukem __RCSID("$NetBSD: getpwent.c,v 1.56 2003/11/26 00:48:59 lukem Exp $");
63 1.12 cgd #endif
64 1.1 cgd #endif /* LIBC_SCCS and not lint */
65 1.1 cgd
66 1.23 jtc #include "namespace.h"
67 1.1 cgd #include <sys/param.h>
68 1.45 lukem
69 1.45 lukem #include <assert.h>
70 1.1 cgd #include <db.h>
71 1.1 cgd #include <errno.h>
72 1.45 lukem #include <fcntl.h>
73 1.1 cgd #include <limits.h>
74 1.14 phil #include <netgroup.h>
75 1.32 lukem #include <nsswitch.h>
76 1.45 lukem #include <pwd.h>
77 1.51 wiz #include <stdarg.h>
78 1.56 lukem #include <stdio.h>
79 1.45 lukem #include <stdlib.h>
80 1.45 lukem #include <string.h>
81 1.45 lukem #include <syslog.h>
82 1.45 lukem #include <unistd.h>
83 1.45 lukem #include <utmp.h>
84 1.45 lukem
85 1.32 lukem #ifdef HESIOD
86 1.32 lukem #include <hesiod.h>
87 1.32 lukem #endif
88 1.4 deraadt #ifdef YP
89 1.14 phil #include <machine/param.h>
90 1.4 deraadt #include <rpc/rpc.h>
91 1.4 deraadt #include <rpcsvc/yp_prot.h>
92 1.4 deraadt #include <rpcsvc/ypclnt.h>
93 1.23 jtc #endif
94 1.23 jtc
95 1.27 thorpej #include "pw_private.h"
96 1.27 thorpej
97 1.40 lukem #if defined(YP) || defined(HESIOD)
98 1.40 lukem #define _PASSWD_COMPAT
99 1.40 lukem #endif
100 1.40 lukem
101 1.23 jtc #ifdef __weak_alias
102 1.46 mycroft __weak_alias(endpwent,_endpwent)
103 1.46 mycroft __weak_alias(getpwent,_getpwent)
104 1.46 mycroft __weak_alias(getpwnam,_getpwnam)
105 1.46 mycroft __weak_alias(getpwuid,_getpwuid)
106 1.46 mycroft __weak_alias(setpassent,_setpassent)
107 1.46 mycroft __weak_alias(setpwent,_setpwent)
108 1.4 deraadt #endif
109 1.1 cgd
110 1.24 perry
111 1.24 perry /*
112 1.24 perry * The lookup techniques and data extraction code here must be kept
113 1.24 perry * in sync with that in `pwd_mkdb'.
114 1.24 perry */
115 1.24 perry
116 1.1 cgd static struct passwd _pw_passwd; /* password structure */
117 1.1 cgd static DB *_pw_db; /* password database */
118 1.42 lukem static int _pw_keynum; /* key counter. no more records if -1 */
119 1.1 cgd static int _pw_stayopen; /* keep fd's open */
120 1.14 phil static int _pw_flags; /* password flags */
121 1.32 lukem
122 1.14 phil static int __hashpw __P((DBT *));
123 1.14 phil static int __initdb __P((void));
124 1.14 phil
125 1.14 phil const char __yp_token[] = "__YP!"; /* Let pwd_mkdb pull this in. */
126 1.36 lukem static const ns_src compatsrc[] = {
127 1.36 lukem { NSSRC_COMPAT, NS_SUCCESS },
128 1.36 lukem { 0 }
129 1.36 lukem };
130 1.1 cgd
131 1.4 deraadt #ifdef YP
132 1.32 lukem static char *__ypcurrent, *__ypdomain;
133 1.32 lukem static int __ypcurrentlen;
134 1.42 lukem static int _pw_ypdone; /* non-zero if no more yp records */
135 1.32 lukem #endif
136 1.32 lukem
137 1.32 lukem #ifdef HESIOD
138 1.42 lukem static int _pw_hesnum; /* hes counter. no more records if -1 */
139 1.32 lukem #endif
140 1.32 lukem
141 1.40 lukem #ifdef _PASSWD_COMPAT
142 1.32 lukem enum _pwmode { PWMODE_NONE, PWMODE_FULL, PWMODE_USER, PWMODE_NETGRP };
143 1.32 lukem static enum _pwmode __pwmode;
144 1.14 phil
145 1.26 lukem enum _ypmap { YPMAP_NONE, YPMAP_ADJUNCT, YPMAP_MASTER };
146 1.26 lukem
147 1.32 lukem static struct passwd *__pwproto = (struct passwd *)NULL;
148 1.32 lukem static int __pwproto_flags;
149 1.32 lukem static char line[1024];
150 1.32 lukem static long prbuf[1024 / sizeof(long)];
151 1.32 lukem static DB *__pwexclude = (DB *)NULL;
152 1.32 lukem
153 1.32 lukem static int __pwexclude_add __P((const char *));
154 1.32 lukem static int __pwexclude_is __P((const char *));
155 1.32 lukem static void __pwproto_set __P((void));
156 1.32 lukem static int __ypmaptype __P((void));
157 1.32 lukem static int __pwparse __P((struct passwd *, char *));
158 1.14 phil
159 1.26 lukem /* macros for deciding which YP maps to use. */
160 1.26 lukem #define PASSWD_BYNAME (__ypmaptype() == YPMAP_MASTER \
161 1.26 lukem ? "master.passwd.byname" : "passwd.byname")
162 1.26 lukem #define PASSWD_BYUID (__ypmaptype() == YPMAP_MASTER \
163 1.26 lukem ? "master.passwd.byuid" : "passwd.byuid")
164 1.26 lukem
165 1.32 lukem /*
166 1.32 lukem * add a name to the compat mode exclude list
167 1.32 lukem */
168 1.14 phil static int
169 1.32 lukem __pwexclude_add(name)
170 1.26 lukem const char *name;
171 1.14 phil {
172 1.30 christos DBT key;
173 1.30 christos DBT data;
174 1.14 phil
175 1.45 lukem _DIAGASSERT(name != NULL);
176 1.45 lukem
177 1.14 phil /* initialize the exclusion table if needed. */
178 1.32 lukem if(__pwexclude == (DB *)NULL) {
179 1.32 lukem __pwexclude = dbopen(NULL, O_RDWR, 600, DB_HASH, NULL);
180 1.32 lukem if(__pwexclude == (DB *)NULL)
181 1.32 lukem return 1;
182 1.14 phil }
183 1.14 phil
184 1.14 phil /* set up the key */
185 1.30 christos key.size = strlen(name);
186 1.30 christos /* LINTED key does not get modified */
187 1.14 phil key.data = (char *)name;
188 1.14 phil
189 1.14 phil /* data is nothing. */
190 1.14 phil data.data = NULL;
191 1.14 phil data.size = 0;
192 1.14 phil
193 1.14 phil /* store it */
194 1.32 lukem if((__pwexclude->put)(__pwexclude, &key, &data, 0) == -1)
195 1.32 lukem return 1;
196 1.14 phil
197 1.32 lukem return 0;
198 1.14 phil }
199 1.14 phil
200 1.32 lukem /*
201 1.32 lukem * test if a name is on the compat mode exclude list
202 1.32 lukem */
203 1.14 phil static int
204 1.32 lukem __pwexclude_is(name)
205 1.26 lukem const char *name;
206 1.14 phil {
207 1.31 christos DBT key;
208 1.30 christos DBT data;
209 1.14 phil
210 1.45 lukem _DIAGASSERT(name != NULL);
211 1.45 lukem
212 1.32 lukem if(__pwexclude == (DB *)NULL)
213 1.32 lukem return 0; /* nothing excluded */
214 1.14 phil
215 1.14 phil /* set up the key */
216 1.30 christos key.size = strlen(name);
217 1.30 christos /* LINTED key does not get modified */
218 1.14 phil key.data = (char *)name;
219 1.14 phil
220 1.32 lukem if((__pwexclude->get)(__pwexclude, &key, &data, 0) == 0)
221 1.32 lukem return 1; /* excluded */
222 1.14 phil
223 1.32 lukem return 0;
224 1.14 phil }
225 1.14 phil
226 1.32 lukem /*
227 1.32 lukem * setup the compat mode prototype template
228 1.32 lukem */
229 1.14 phil static void
230 1.32 lukem __pwproto_set()
231 1.14 phil {
232 1.17 lukem char *ptr;
233 1.17 lukem struct passwd *pw = &_pw_passwd;
234 1.14 phil
235 1.14 phil /* make this the new prototype */
236 1.30 christos ptr = (char *)(void *)prbuf;
237 1.14 phil
238 1.14 phil /* first allocate the struct. */
239 1.37 christos __pwproto = (struct passwd *)(void *)ptr;
240 1.14 phil ptr += sizeof(struct passwd);
241 1.14 phil
242 1.14 phil /* name */
243 1.14 phil if(pw->pw_name && (pw->pw_name)[0]) {
244 1.37 christos ptr = (char *)ALIGN((u_long)ptr);
245 1.29 perry memmove(ptr, pw->pw_name, strlen(pw->pw_name) + 1);
246 1.32 lukem __pwproto->pw_name = ptr;
247 1.14 phil ptr += (strlen(pw->pw_name) + 1);
248 1.14 phil } else
249 1.32 lukem __pwproto->pw_name = (char *)NULL;
250 1.14 phil
251 1.14 phil /* password */
252 1.14 phil if(pw->pw_passwd && (pw->pw_passwd)[0]) {
253 1.37 christos ptr = (char *)ALIGN((u_long)ptr);
254 1.29 perry memmove(ptr, pw->pw_passwd, strlen(pw->pw_passwd) + 1);
255 1.32 lukem __pwproto->pw_passwd = ptr;
256 1.14 phil ptr += (strlen(pw->pw_passwd) + 1);
257 1.14 phil } else
258 1.32 lukem __pwproto->pw_passwd = (char *)NULL;
259 1.14 phil
260 1.14 phil /* uid */
261 1.32 lukem __pwproto->pw_uid = pw->pw_uid;
262 1.14 phil
263 1.14 phil /* gid */
264 1.32 lukem __pwproto->pw_gid = pw->pw_gid;
265 1.14 phil
266 1.14 phil /* change (ignored anyway) */
267 1.32 lukem __pwproto->pw_change = pw->pw_change;
268 1.14 phil
269 1.14 phil /* class (ignored anyway) */
270 1.32 lukem __pwproto->pw_class = "";
271 1.14 phil
272 1.14 phil /* gecos */
273 1.14 phil if(pw->pw_gecos && (pw->pw_gecos)[0]) {
274 1.37 christos ptr = (char *)ALIGN((u_long)ptr);
275 1.29 perry memmove(ptr, pw->pw_gecos, strlen(pw->pw_gecos) + 1);
276 1.32 lukem __pwproto->pw_gecos = ptr;
277 1.14 phil ptr += (strlen(pw->pw_gecos) + 1);
278 1.14 phil } else
279 1.32 lukem __pwproto->pw_gecos = (char *)NULL;
280 1.14 phil
281 1.14 phil /* dir */
282 1.14 phil if(pw->pw_dir && (pw->pw_dir)[0]) {
283 1.37 christos ptr = (char *)ALIGN((u_long)ptr);
284 1.29 perry memmove(ptr, pw->pw_dir, strlen(pw->pw_dir) + 1);
285 1.32 lukem __pwproto->pw_dir = ptr;
286 1.14 phil ptr += (strlen(pw->pw_dir) + 1);
287 1.14 phil } else
288 1.32 lukem __pwproto->pw_dir = (char *)NULL;
289 1.14 phil
290 1.14 phil /* shell */
291 1.14 phil if(pw->pw_shell && (pw->pw_shell)[0]) {
292 1.37 christos ptr = (char *)ALIGN((u_long)ptr);
293 1.29 perry memmove(ptr, pw->pw_shell, strlen(pw->pw_shell) + 1);
294 1.32 lukem __pwproto->pw_shell = ptr;
295 1.14 phil ptr += (strlen(pw->pw_shell) + 1);
296 1.14 phil } else
297 1.32 lukem __pwproto->pw_shell = (char *)NULL;
298 1.14 phil
299 1.14 phil /* expire (ignored anyway) */
300 1.32 lukem __pwproto->pw_expire = pw->pw_expire;
301 1.14 phil
302 1.14 phil /* flags */
303 1.32 lukem __pwproto_flags = _pw_flags;
304 1.14 phil }
305 1.4 deraadt
306 1.5 deraadt static int
307 1.26 lukem __ypmaptype()
308 1.26 lukem {
309 1.26 lukem static int maptype = -1;
310 1.56 lukem #ifdef YP
311 1.26 lukem int order, r;
312 1.56 lukem #endif
313 1.26 lukem
314 1.26 lukem if (maptype != -1)
315 1.26 lukem return (maptype);
316 1.26 lukem
317 1.26 lukem maptype = YPMAP_NONE;
318 1.26 lukem if (geteuid() != 0)
319 1.26 lukem return (maptype);
320 1.26 lukem
321 1.56 lukem #ifdef YP
322 1.26 lukem if (!__ypdomain) {
323 1.26 lukem if( _yp_check(&__ypdomain) == 0)
324 1.26 lukem return (maptype);
325 1.26 lukem }
326 1.26 lukem
327 1.26 lukem r = yp_order(__ypdomain, "master.passwd.byname", &order);
328 1.26 lukem if (r == 0) {
329 1.26 lukem maptype = YPMAP_MASTER;
330 1.26 lukem return (maptype);
331 1.26 lukem }
332 1.26 lukem
333 1.26 lukem /*
334 1.26 lukem * NIS+ in YP compat mode doesn't support
335 1.26 lukem * YPPROC_ORDER -- no point in continuing.
336 1.26 lukem */
337 1.26 lukem if (r == YPERR_YPERR)
338 1.26 lukem return (maptype);
339 1.26 lukem
340 1.26 lukem /* master.passwd doesn't exist -- try passwd.adjunct */
341 1.26 lukem if (r == YPERR_MAP) {
342 1.26 lukem r = yp_order(__ypdomain, "passwd.adjunct.byname", &order);
343 1.26 lukem if (r == 0)
344 1.26 lukem maptype = YPMAP_ADJUNCT;
345 1.26 lukem return (maptype);
346 1.26 lukem }
347 1.56 lukem #endif /* YP */
348 1.26 lukem return (maptype);
349 1.26 lukem }
350 1.26 lukem
351 1.32 lukem /*
352 1.42 lukem * parse a passwd file line (from NIS or HESIOD).
353 1.42 lukem * assumed to be `old-style' if maptype != YPMAP_MASTER.
354 1.32 lukem */
355 1.26 lukem static int
356 1.32 lukem __pwparse(pw, s)
357 1.26 lukem struct passwd *pw;
358 1.26 lukem char *s;
359 1.4 deraadt {
360 1.56 lukem #ifdef YP
361 1.26 lukem static char adjunctpw[YPMAXRECORD + 2];
362 1.56 lukem #endif
363 1.26 lukem int flags, maptype;
364 1.4 deraadt
365 1.45 lukem _DIAGASSERT(pw != NULL);
366 1.45 lukem _DIAGASSERT(s != NULL);
367 1.45 lukem
368 1.26 lukem maptype = __ypmaptype();
369 1.26 lukem flags = _PASSWORD_NOWARN;
370 1.26 lukem if (maptype != YPMAP_MASTER)
371 1.26 lukem flags |= _PASSWORD_OLDFMT;
372 1.27 thorpej if (! __pw_scan(s, pw, &flags))
373 1.13 mycroft return 1;
374 1.14 phil
375 1.14 phil /* now let the prototype override, if set. */
376 1.32 lukem if(__pwproto != (struct passwd *)NULL) {
377 1.32 lukem #ifdef PW_OVERRIDE_PASSWD
378 1.32 lukem if(__pwproto->pw_passwd != (char *)NULL)
379 1.32 lukem pw->pw_passwd = __pwproto->pw_passwd;
380 1.14 phil #endif
381 1.32 lukem if(!(__pwproto_flags & _PASSWORD_NOUID))
382 1.32 lukem pw->pw_uid = __pwproto->pw_uid;
383 1.32 lukem if(!(__pwproto_flags & _PASSWORD_NOGID))
384 1.32 lukem pw->pw_gid = __pwproto->pw_gid;
385 1.32 lukem if(__pwproto->pw_gecos != (char *)NULL)
386 1.32 lukem pw->pw_gecos = __pwproto->pw_gecos;
387 1.32 lukem if(__pwproto->pw_dir != (char *)NULL)
388 1.32 lukem pw->pw_dir = __pwproto->pw_dir;
389 1.32 lukem if(__pwproto->pw_shell != (char *)NULL)
390 1.32 lukem pw->pw_shell = __pwproto->pw_shell;
391 1.14 phil }
392 1.56 lukem #ifdef YP
393 1.26 lukem if ((maptype == YPMAP_ADJUNCT) &&
394 1.26 lukem (strstr(pw->pw_passwd, "##") != NULL)) {
395 1.26 lukem char *data, *bp;
396 1.26 lukem int datalen;
397 1.26 lukem
398 1.26 lukem if (yp_match(__ypdomain, "passwd.adjunct.byname", pw->pw_name,
399 1.30 christos (int)strlen(pw->pw_name), &data, &datalen) == 0) {
400 1.50 groo strlcpy(adjunctpw, data, MIN((size_t)datalen,
401 1.50 groo sizeof(adjunctpw)));
402 1.26 lukem
403 1.26 lukem /* skip name to get password */
404 1.26 lukem if ((bp = strsep(&data, ":")) != NULL &&
405 1.26 lukem (bp = strsep(&data, ":")) != NULL)
406 1.26 lukem pw->pw_passwd = bp;
407 1.26 lukem }
408 1.26 lukem }
409 1.56 lukem #endif /* YP */
410 1.4 deraadt return 0;
411 1.4 deraadt }
412 1.40 lukem #endif /* _PASSWD_COMPAT */
413 1.32 lukem
414 1.32 lukem /*
415 1.32 lukem * local files implementation of getpw*()
416 1.32 lukem * varargs: type, [ uid (type == _PW_KEYBYUID) | name (type == _PW_KEYBYNAME) ]
417 1.32 lukem */
418 1.32 lukem static int _local_getpw __P((void *, void *, va_list));
419 1.4 deraadt
420 1.37 christos /*ARGSUSED*/
421 1.32 lukem static int
422 1.32 lukem _local_getpw(rv, cb_data, ap)
423 1.32 lukem void *rv;
424 1.32 lukem void *cb_data;
425 1.32 lukem va_list ap;
426 1.1 cgd {
427 1.32 lukem DBT key;
428 1.37 christos char bf[/*CONSTCOND*/ MAX(MAXLOGNAME, sizeof(_pw_keynum)) + 1];
429 1.32 lukem uid_t uid;
430 1.49 mycroft size_t len;
431 1.49 mycroft int search, rval;
432 1.32 lukem const char *name;
433 1.1 cgd
434 1.1 cgd if (!_pw_db && !__initdb())
435 1.32 lukem return NS_UNAVAIL;
436 1.32 lukem
437 1.32 lukem search = va_arg(ap, int);
438 1.32 lukem bf[0] = search;
439 1.32 lukem switch (search) {
440 1.32 lukem case _PW_KEYBYNUM:
441 1.42 lukem if (_pw_keynum == -1)
442 1.42 lukem return NS_NOTFOUND; /* no more local records */
443 1.32 lukem ++_pw_keynum;
444 1.37 christos memmove(bf + 1, &_pw_keynum, sizeof(_pw_keynum));
445 1.32 lukem key.size = sizeof(_pw_keynum) + 1;
446 1.32 lukem break;
447 1.32 lukem case _PW_KEYBYNAME:
448 1.32 lukem name = va_arg(ap, const char *);
449 1.32 lukem len = strlen(name);
450 1.49 mycroft if (len > MAXLOGNAME)
451 1.49 mycroft return NS_NOTFOUND;
452 1.49 mycroft memmove(bf + 1, name, len);
453 1.32 lukem key.size = len + 1;
454 1.32 lukem break;
455 1.32 lukem case _PW_KEYBYUID:
456 1.32 lukem uid = va_arg(ap, uid_t);
457 1.49 mycroft memmove(bf + 1, &uid, sizeof(uid));
458 1.32 lukem key.size = sizeof(uid) + 1;
459 1.32 lukem break;
460 1.32 lukem default:
461 1.32 lukem abort();
462 1.32 lukem }
463 1.32 lukem
464 1.32 lukem key.data = (u_char *)bf;
465 1.32 lukem rval = __hashpw(&key);
466 1.42 lukem if (rval == NS_NOTFOUND && search == _PW_KEYBYNUM)
467 1.42 lukem _pw_keynum = -1; /* flag `no more local records' */
468 1.32 lukem
469 1.32 lukem if (!_pw_stayopen && (search != _PW_KEYBYNUM)) {
470 1.32 lukem (void)(_pw_db->close)(_pw_db);
471 1.32 lukem _pw_db = (DB *)NULL;
472 1.32 lukem }
473 1.32 lukem return (rval);
474 1.32 lukem }
475 1.32 lukem
476 1.32 lukem #ifdef HESIOD
477 1.32 lukem /*
478 1.32 lukem * hesiod implementation of getpw*()
479 1.32 lukem * varargs: type, [ uid (type == _PW_KEYBYUID) | name (type == _PW_KEYBYNAME) ]
480 1.32 lukem */
481 1.32 lukem static int _dns_getpw __P((void *, void *, va_list));
482 1.32 lukem
483 1.37 christos /*ARGSUSED*/
484 1.32 lukem static int
485 1.32 lukem _dns_getpw(rv, cb_data, ap)
486 1.32 lukem void *rv;
487 1.32 lukem void *cb_data;
488 1.32 lukem va_list ap;
489 1.32 lukem {
490 1.32 lukem const char *name;
491 1.32 lukem uid_t uid;
492 1.32 lukem int search;
493 1.39 lukem
494 1.42 lukem const char *map;
495 1.32 lukem char **hp;
496 1.39 lukem void *context;
497 1.39 lukem int r;
498 1.32 lukem
499 1.32 lukem search = va_arg(ap, int);
500 1.43 lukem nextdnsbynum:
501 1.32 lukem switch (search) {
502 1.32 lukem case _PW_KEYBYNUM:
503 1.42 lukem if (_pw_hesnum == -1)
504 1.42 lukem return NS_NOTFOUND; /* no more hesiod records */
505 1.32 lukem snprintf(line, sizeof(line) - 1, "passwd-%u", _pw_hesnum);
506 1.32 lukem _pw_hesnum++;
507 1.38 mycroft map = "passwd";
508 1.32 lukem break;
509 1.32 lukem case _PW_KEYBYNAME:
510 1.32 lukem name = va_arg(ap, const char *);
511 1.53 itojun strlcpy(line, name, sizeof(line));
512 1.38 mycroft map = "passwd";
513 1.32 lukem break;
514 1.32 lukem case _PW_KEYBYUID:
515 1.32 lukem uid = va_arg(ap, uid_t);
516 1.33 lukem snprintf(line, sizeof(line), "%u", (unsigned int)uid);
517 1.40 lukem map = "uid"; /* XXX this is `passwd' on ultrix */
518 1.32 lukem break;
519 1.32 lukem default:
520 1.32 lukem abort();
521 1.32 lukem }
522 1.32 lukem
523 1.39 lukem r = NS_UNAVAIL;
524 1.39 lukem if (hesiod_init(&context) == -1)
525 1.39 lukem return (r);
526 1.39 lukem
527 1.39 lukem hp = hesiod_resolve(context, line, map);
528 1.32 lukem if (hp == NULL) {
529 1.39 lukem if (errno == ENOENT) {
530 1.42 lukem /* flag `no more hesiod records' */
531 1.42 lukem if (search == _PW_KEYBYNUM)
532 1.42 lukem _pw_hesnum = -1;
533 1.42 lukem r = NS_NOTFOUND;
534 1.32 lukem }
535 1.39 lukem goto cleanup_dns_getpw;
536 1.32 lukem }
537 1.32 lukem
538 1.53 itojun strlcpy(line, hp[0], sizeof(line)); /* only check first elem */
539 1.39 lukem hesiod_free_list(context, hp);
540 1.43 lukem if (__pwparse(&_pw_passwd, line)) {
541 1.43 lukem if (search == _PW_KEYBYNUM)
542 1.43 lukem goto nextdnsbynum; /* skip dogdy entries */
543 1.39 lukem r = NS_UNAVAIL;
544 1.43 lukem } else
545 1.39 lukem r = NS_SUCCESS;
546 1.39 lukem cleanup_dns_getpw:
547 1.39 lukem hesiod_end(context);
548 1.39 lukem return (r);
549 1.32 lukem }
550 1.32 lukem #endif
551 1.1 cgd
552 1.4 deraadt #ifdef YP
553 1.32 lukem /*
554 1.32 lukem * nis implementation of getpw*()
555 1.32 lukem * varargs: type, [ uid (type == _PW_KEYBYUID) | name (type == _PW_KEYBYNAME) ]
556 1.32 lukem */
557 1.32 lukem static int _nis_getpw __P((void *, void *, va_list));
558 1.14 phil
559 1.37 christos /*ARGSUSED*/
560 1.32 lukem static int
561 1.32 lukem _nis_getpw(rv, cb_data, ap)
562 1.32 lukem void *rv;
563 1.32 lukem void *cb_data;
564 1.32 lukem va_list ap;
565 1.32 lukem {
566 1.32 lukem const char *name;
567 1.32 lukem uid_t uid;
568 1.32 lukem int search;
569 1.32 lukem char *key, *data;
570 1.42 lukem const char *map;
571 1.42 lukem int keylen, datalen, r, rval;
572 1.32 lukem
573 1.32 lukem if(__ypdomain == NULL) {
574 1.32 lukem if(_yp_check(&__ypdomain) == 0)
575 1.32 lukem return NS_UNAVAIL;
576 1.32 lukem }
577 1.32 lukem
578 1.42 lukem map = PASSWD_BYNAME;
579 1.32 lukem search = va_arg(ap, int);
580 1.32 lukem switch (search) {
581 1.32 lukem case _PW_KEYBYNUM:
582 1.32 lukem break;
583 1.32 lukem case _PW_KEYBYNAME:
584 1.32 lukem name = va_arg(ap, const char *);
585 1.53 itojun strlcpy(line, name, sizeof(line));
586 1.32 lukem break;
587 1.32 lukem case _PW_KEYBYUID:
588 1.32 lukem uid = va_arg(ap, uid_t);
589 1.33 lukem snprintf(line, sizeof(line), "%u", (unsigned int)uid);
590 1.32 lukem map = PASSWD_BYUID;
591 1.32 lukem break;
592 1.32 lukem default:
593 1.32 lukem abort();
594 1.32 lukem }
595 1.42 lukem rval = NS_UNAVAIL;
596 1.32 lukem if (search != _PW_KEYBYNUM) {
597 1.32 lukem data = NULL;
598 1.32 lukem r = yp_match(__ypdomain, map, line, (int)strlen(line),
599 1.32 lukem &data, &datalen);
600 1.42 lukem if (r == YPERR_KEY)
601 1.42 lukem rval = NS_NOTFOUND;
602 1.32 lukem if (r != 0) {
603 1.32 lukem if (data)
604 1.32 lukem free(data);
605 1.42 lukem return (rval);
606 1.4 deraadt }
607 1.32 lukem data[datalen] = '\0'; /* clear trailing \n */
608 1.53 itojun strlcpy(line, data, sizeof(line));
609 1.32 lukem free(data);
610 1.32 lukem if (__pwparse(&_pw_passwd, line))
611 1.32 lukem return NS_UNAVAIL;
612 1.32 lukem return NS_SUCCESS;
613 1.32 lukem }
614 1.32 lukem
615 1.42 lukem if (_pw_ypdone)
616 1.42 lukem return NS_NOTFOUND;
617 1.32 lukem for (;;) {
618 1.32 lukem data = key = NULL;
619 1.32 lukem if (__ypcurrent) {
620 1.32 lukem r = yp_next(__ypdomain, map,
621 1.14 phil __ypcurrent, __ypcurrentlen,
622 1.14 phil &key, &keylen, &data, &datalen);
623 1.32 lukem free(__ypcurrent);
624 1.32 lukem switch (r) {
625 1.32 lukem case 0:
626 1.32 lukem __ypcurrent = key;
627 1.32 lukem __ypcurrentlen = keylen;
628 1.32 lukem break;
629 1.32 lukem case YPERR_NOMORE:
630 1.32 lukem __ypcurrent = NULL;
631 1.42 lukem /* flag `no more yp records' */
632 1.42 lukem _pw_ypdone = 1;
633 1.42 lukem rval = NS_NOTFOUND;
634 1.17 lukem }
635 1.32 lukem } else {
636 1.42 lukem r = yp_first(__ypdomain, map, &__ypcurrent,
637 1.42 lukem &__ypcurrentlen, &data, &datalen);
638 1.32 lukem }
639 1.32 lukem if (r != 0) {
640 1.32 lukem if (key)
641 1.32 lukem free(key);
642 1.32 lukem if (data)
643 1.32 lukem free(data);
644 1.42 lukem return (rval);
645 1.32 lukem }
646 1.32 lukem data[datalen] = '\0'; /* clear trailing \n */
647 1.53 itojun strlcpy(line, data, sizeof(line));
648 1.53 itojun free(data);
649 1.32 lukem if (! __pwparse(&_pw_passwd, line))
650 1.32 lukem return NS_SUCCESS;
651 1.32 lukem }
652 1.32 lukem /* NOTREACHED */
653 1.32 lukem } /* _nis_getpw */
654 1.32 lukem #endif
655 1.32 lukem
656 1.40 lukem #ifdef _PASSWD_COMPAT
657 1.32 lukem /*
658 1.32 lukem * See if the compat token is in the database. Only works if pwd_mkdb knows
659 1.32 lukem * about the token.
660 1.32 lukem */
661 1.32 lukem static int __has_compatpw __P((void));
662 1.32 lukem
663 1.32 lukem static int
664 1.32 lukem __has_compatpw()
665 1.32 lukem {
666 1.32 lukem DBT key, data;
667 1.32 lukem DBT pkey, pdata;
668 1.35 lukem char bf[MAXLOGNAME];
669 1.32 lukem
670 1.37 christos /*LINTED*/
671 1.32 lukem key.data = (u_char *)__yp_token;
672 1.32 lukem key.size = strlen(__yp_token);
673 1.32 lukem
674 1.32 lukem /* Pre-token database support. */
675 1.32 lukem bf[0] = _PW_KEYBYNAME;
676 1.35 lukem bf[1] = '+';
677 1.32 lukem pkey.data = (u_char *)bf;
678 1.35 lukem pkey.size = 2;
679 1.32 lukem
680 1.32 lukem if ((_pw_db->get)(_pw_db, &key, &data, 0)
681 1.32 lukem && (_pw_db->get)(_pw_db, &pkey, &pdata, 0))
682 1.32 lukem return 0; /* No compat token */
683 1.32 lukem return 1;
684 1.32 lukem }
685 1.32 lukem
686 1.32 lukem /*
687 1.32 lukem * log an error if "files" or "compat" is specified in passwd_compat database
688 1.32 lukem */
689 1.32 lukem static int _bad_getpw __P((void *, void *, va_list));
690 1.32 lukem
691 1.37 christos /*ARGSUSED*/
692 1.32 lukem static int
693 1.32 lukem _bad_getpw(rv, cb_data, ap)
694 1.32 lukem void *rv;
695 1.32 lukem void *cb_data;
696 1.32 lukem va_list ap;
697 1.32 lukem {
698 1.32 lukem static int warned;
699 1.45 lukem
700 1.45 lukem _DIAGASSERT(cb_data != NULL);
701 1.45 lukem
702 1.32 lukem if (!warned) {
703 1.32 lukem syslog(LOG_ERR,
704 1.32 lukem "nsswitch.conf passwd_compat database can't use '%s'",
705 1.32 lukem (char *)cb_data);
706 1.32 lukem }
707 1.32 lukem warned = 1;
708 1.32 lukem return NS_UNAVAIL;
709 1.32 lukem }
710 1.32 lukem
711 1.32 lukem /*
712 1.32 lukem * when a name lookup in compat mode is required (e.g., '+name', or a name in
713 1.32 lukem * '+@netgroup'), look it up in the 'passwd_compat' nsswitch database.
714 1.32 lukem * only Hesiod and NIS is supported - it doesn't make sense to lookup
715 1.32 lukem * compat names from 'files' or 'compat'.
716 1.32 lukem */
717 1.32 lukem static int __getpwcompat __P((int, uid_t, const char *));
718 1.32 lukem
719 1.32 lukem static int
720 1.32 lukem __getpwcompat(type, uid, name)
721 1.32 lukem int type;
722 1.32 lukem uid_t uid;
723 1.32 lukem const char *name;
724 1.32 lukem {
725 1.36 lukem static const ns_dtab dtab[] = {
726 1.35 lukem NS_FILES_CB(_bad_getpw, "files")
727 1.35 lukem NS_DNS_CB(_dns_getpw, NULL)
728 1.35 lukem NS_NIS_CB(_nis_getpw, NULL)
729 1.35 lukem NS_COMPAT_CB(_bad_getpw, "compat")
730 1.35 lukem { 0 }
731 1.32 lukem };
732 1.36 lukem static const ns_src defaultnis[] = {
733 1.36 lukem { NSSRC_NIS, NS_SUCCESS },
734 1.36 lukem { 0 }
735 1.36 lukem };
736 1.32 lukem
737 1.32 lukem switch (type) {
738 1.32 lukem case _PW_KEYBYNUM:
739 1.35 lukem return nsdispatch(NULL, dtab, NSDB_PASSWD_COMPAT, "getpwcompat",
740 1.36 lukem defaultnis, type);
741 1.32 lukem case _PW_KEYBYNAME:
742 1.45 lukem _DIAGASSERT(name != NULL);
743 1.35 lukem return nsdispatch(NULL, dtab, NSDB_PASSWD_COMPAT, "getpwcompat",
744 1.36 lukem defaultnis, type, name);
745 1.32 lukem case _PW_KEYBYUID:
746 1.35 lukem return nsdispatch(NULL, dtab, NSDB_PASSWD_COMPAT, "getpwcompat",
747 1.36 lukem defaultnis, type, uid);
748 1.32 lukem default:
749 1.32 lukem abort();
750 1.37 christos /*NOTREACHED*/
751 1.32 lukem }
752 1.32 lukem }
753 1.40 lukem #endif /* _PASSWD_COMPAT */
754 1.32 lukem
755 1.32 lukem /*
756 1.32 lukem * compat implementation of getpwent()
757 1.32 lukem * varargs (ignored):
758 1.32 lukem * type, [ uid (type == _PW_KEYBYUID) | name (type == _PW_KEYBYNAME) ]
759 1.32 lukem */
760 1.32 lukem static int _compat_getpwent __P((void *, void *, va_list));
761 1.32 lukem
762 1.37 christos /*ARGSUSED*/
763 1.32 lukem static int
764 1.32 lukem _compat_getpwent(rv, cb_data, ap)
765 1.32 lukem void *rv;
766 1.32 lukem void *cb_data;
767 1.32 lukem va_list ap;
768 1.32 lukem {
769 1.32 lukem DBT key;
770 1.44 ross int rval;
771 1.32 lukem char bf[sizeof(_pw_keynum) + 1];
772 1.40 lukem #ifdef _PASSWD_COMPAT
773 1.32 lukem static char *name = NULL;
774 1.32 lukem const char *user, *host, *dom;
775 1.44 ross int has_compatpw;
776 1.40 lukem #endif
777 1.32 lukem
778 1.32 lukem if (!_pw_db && !__initdb())
779 1.32 lukem return NS_UNAVAIL;
780 1.32 lukem
781 1.40 lukem #ifdef _PASSWD_COMPAT
782 1.32 lukem has_compatpw = __has_compatpw();
783 1.32 lukem
784 1.32 lukem again:
785 1.32 lukem if (has_compatpw && (__pwmode != PWMODE_NONE)) {
786 1.32 lukem int r;
787 1.32 lukem
788 1.32 lukem switch (__pwmode) {
789 1.32 lukem case PWMODE_FULL:
790 1.32 lukem r = __getpwcompat(_PW_KEYBYNUM, 0, NULL);
791 1.32 lukem if (r == NS_SUCCESS)
792 1.32 lukem return r;
793 1.32 lukem __pwmode = PWMODE_NONE;
794 1.14 phil break;
795 1.32 lukem
796 1.32 lukem case PWMODE_NETGRP:
797 1.32 lukem r = getnetgrent(&host, &user, &dom);
798 1.32 lukem if (r == 0) { /* end of group */
799 1.14 phil endnetgrent();
800 1.32 lukem __pwmode = PWMODE_NONE;
801 1.32 lukem break;
802 1.14 phil }
803 1.32 lukem if (!user || !*user)
804 1.32 lukem break;
805 1.32 lukem r = __getpwcompat(_PW_KEYBYNAME, 0, user);
806 1.32 lukem if (r == NS_SUCCESS)
807 1.32 lukem return r;
808 1.14 phil break;
809 1.32 lukem
810 1.32 lukem case PWMODE_USER:
811 1.32 lukem if (name == NULL) {
812 1.32 lukem __pwmode = PWMODE_NONE;
813 1.32 lukem break;
814 1.4 deraadt }
815 1.32 lukem r = __getpwcompat(_PW_KEYBYNAME, 0, name);
816 1.32 lukem free(name);
817 1.32 lukem name = NULL;
818 1.32 lukem if (r == NS_SUCCESS)
819 1.32 lukem return r;
820 1.14 phil break;
821 1.32 lukem
822 1.32 lukem case PWMODE_NONE:
823 1.32 lukem abort();
824 1.4 deraadt }
825 1.32 lukem goto again;
826 1.4 deraadt }
827 1.40 lukem #endif
828 1.4 deraadt
829 1.42 lukem if (_pw_keynum == -1)
830 1.42 lukem return NS_NOTFOUND; /* no more local records */
831 1.1 cgd ++_pw_keynum;
832 1.1 cgd bf[0] = _PW_KEYBYNUM;
833 1.37 christos memmove(bf + 1, &_pw_keynum, sizeof(_pw_keynum));
834 1.32 lukem key.data = (u_char *)bf;
835 1.32 lukem key.size = sizeof(_pw_keynum) + 1;
836 1.42 lukem rval = __hashpw(&key);
837 1.42 lukem if (rval == NS_NOTFOUND)
838 1.42 lukem _pw_keynum = -1; /* flag `no more local records' */
839 1.42 lukem else if (rval == NS_SUCCESS) {
840 1.40 lukem #ifdef _PASSWD_COMPAT
841 1.14 phil /* if we don't have YP at all, don't bother. */
842 1.32 lukem if (has_compatpw) {
843 1.14 phil if(_pw_passwd.pw_name[0] == '+') {
844 1.14 phil /* set the mode */
845 1.14 phil switch(_pw_passwd.pw_name[1]) {
846 1.14 phil case '\0':
847 1.32 lukem __pwmode = PWMODE_FULL;
848 1.14 phil break;
849 1.14 phil case '@':
850 1.32 lukem __pwmode = PWMODE_NETGRP;
851 1.14 phil setnetgrent(_pw_passwd.pw_name + 2);
852 1.14 phil break;
853 1.14 phil default:
854 1.32 lukem __pwmode = PWMODE_USER;
855 1.14 phil name = strdup(_pw_passwd.pw_name + 1);
856 1.14 phil break;
857 1.14 phil }
858 1.14 phil
859 1.14 phil /* save the prototype */
860 1.32 lukem __pwproto_set();
861 1.14 phil goto again;
862 1.14 phil } else if(_pw_passwd.pw_name[0] == '-') {
863 1.14 phil /* an attempted exclusion */
864 1.14 phil switch(_pw_passwd.pw_name[1]) {
865 1.14 phil case '\0':
866 1.14 phil break;
867 1.14 phil case '@':
868 1.14 phil setnetgrent(_pw_passwd.pw_name + 2);
869 1.14 phil while(getnetgrent(&host, &user, &dom)) {
870 1.14 phil if(user && *user)
871 1.32 lukem __pwexclude_add(user);
872 1.14 phil }
873 1.14 phil endnetgrent();
874 1.14 phil break;
875 1.14 phil default:
876 1.32 lukem __pwexclude_add(_pw_passwd.pw_name + 1);
877 1.14 phil break;
878 1.14 phil }
879 1.14 phil goto again;
880 1.14 phil }
881 1.4 deraadt }
882 1.40 lukem #endif
883 1.4 deraadt }
884 1.42 lukem return (rval);
885 1.1 cgd }
886 1.1 cgd
887 1.14 phil /*
888 1.32 lukem * compat implementation of getpwnam() and getpwuid()
889 1.32 lukem * varargs: type, [ uid (type == _PW_KEYBYUID) | name (type == _PW_KEYBYNAME) ]
890 1.14 phil */
891 1.32 lukem static int _compat_getpw __P((void *, void *, va_list));
892 1.32 lukem
893 1.14 phil static int
894 1.32 lukem _compat_getpw(rv, cb_data, ap)
895 1.32 lukem void *rv;
896 1.32 lukem void *cb_data;
897 1.32 lukem va_list ap;
898 1.14 phil {
899 1.40 lukem #ifdef _PASSWD_COMPAT
900 1.32 lukem DBT key;
901 1.42 lukem int search, rval, r, s, keynum;
902 1.32 lukem uid_t uid;
903 1.42 lukem char bf[sizeof(keynum) + 1];
904 1.34 lukem const char *name, *host, *user, *dom;
905 1.40 lukem #endif
906 1.34 lukem
907 1.34 lukem if (!_pw_db && !__initdb())
908 1.34 lukem return NS_UNAVAIL;
909 1.34 lukem
910 1.34 lukem /*
911 1.34 lukem * If there isn't a compat token in the database, use files.
912 1.34 lukem */
913 1.40 lukem #ifdef _PASSWD_COMPAT
914 1.34 lukem if (! __has_compatpw())
915 1.40 lukem #endif
916 1.34 lukem return (_local_getpw(rv, cb_data, ap));
917 1.32 lukem
918 1.40 lukem #ifdef _PASSWD_COMPAT
919 1.32 lukem search = va_arg(ap, int);
920 1.32 lukem uid = 0;
921 1.32 lukem name = NULL;
922 1.32 lukem rval = NS_NOTFOUND;
923 1.32 lukem switch (search) {
924 1.32 lukem case _PW_KEYBYNAME:
925 1.32 lukem name = va_arg(ap, const char *);
926 1.32 lukem break;
927 1.32 lukem case _PW_KEYBYUID:
928 1.32 lukem uid = va_arg(ap, uid_t);
929 1.32 lukem break;
930 1.32 lukem default:
931 1.32 lukem abort();
932 1.32 lukem }
933 1.14 phil
934 1.42 lukem for (s = -1, keynum = 1 ; ; keynum++) {
935 1.34 lukem bf[0] = _PW_KEYBYNUM;
936 1.42 lukem memmove(bf + 1, &keynum, sizeof(keynum));
937 1.34 lukem key.data = (u_char *)bf;
938 1.42 lukem key.size = sizeof(keynum) + 1;
939 1.34 lukem if(__hashpw(&key) != NS_SUCCESS)
940 1.34 lukem break;
941 1.34 lukem switch(_pw_passwd.pw_name[0]) {
942 1.34 lukem case '+':
943 1.34 lukem /* save the prototype */
944 1.34 lukem __pwproto_set();
945 1.34 lukem
946 1.34 lukem switch(_pw_passwd.pw_name[1]) {
947 1.34 lukem case '\0':
948 1.34 lukem r = __getpwcompat(search, uid, name);
949 1.34 lukem if (r != NS_SUCCESS)
950 1.34 lukem continue;
951 1.10 deraadt break;
952 1.34 lukem case '@':
953 1.14 phil pwnam_netgrp:
954 1.42 lukem #if 0 /* XXX: is this a hangover from pre-nsswitch? */
955 1.34 lukem if(__ypcurrent) {
956 1.34 lukem free(__ypcurrent);
957 1.34 lukem __ypcurrent = NULL;
958 1.34 lukem }
959 1.42 lukem #endif
960 1.34 lukem if (s == -1) /* first time */
961 1.34 lukem setnetgrent(_pw_passwd.pw_name + 2);
962 1.34 lukem s = getnetgrent(&host, &user, &dom);
963 1.34 lukem if (s == 0) { /* end of group */
964 1.34 lukem endnetgrent();
965 1.34 lukem s = -1;
966 1.34 lukem continue;
967 1.34 lukem }
968 1.34 lukem if (!user || !*user)
969 1.34 lukem goto pwnam_netgrp;
970 1.32 lukem
971 1.34 lukem r = __getpwcompat(_PW_KEYBYNAME, 0, user);
972 1.32 lukem
973 1.34 lukem if (r == NS_UNAVAIL)
974 1.34 lukem return r;
975 1.34 lukem if (r == NS_NOTFOUND) {
976 1.34 lukem /*
977 1.34 lukem * just because this user is bad
978 1.34 lukem * it doesn't mean they all are.
979 1.34 lukem */
980 1.34 lukem goto pwnam_netgrp;
981 1.4 deraadt }
982 1.34 lukem break;
983 1.34 lukem default:
984 1.34 lukem user = _pw_passwd.pw_name + 1;
985 1.34 lukem r = __getpwcompat(_PW_KEYBYNAME, 0, user);
986 1.34 lukem
987 1.34 lukem if (r == NS_UNAVAIL)
988 1.34 lukem return r;
989 1.34 lukem if (r == NS_NOTFOUND)
990 1.10 deraadt continue;
991 1.14 phil break;
992 1.34 lukem }
993 1.34 lukem if(__pwexclude_is(_pw_passwd.pw_name)) {
994 1.34 lukem if(s == 1) /* inside netgroup */
995 1.34 lukem goto pwnam_netgrp;
996 1.34 lukem continue;
997 1.34 lukem }
998 1.34 lukem break;
999 1.34 lukem case '-':
1000 1.34 lukem /* attempted exclusion */
1001 1.34 lukem switch(_pw_passwd.pw_name[1]) {
1002 1.34 lukem case '\0':
1003 1.34 lukem break;
1004 1.34 lukem case '@':
1005 1.34 lukem setnetgrent(_pw_passwd.pw_name + 2);
1006 1.34 lukem while(getnetgrent(&host, &user, &dom)) {
1007 1.34 lukem if(user && *user)
1008 1.34 lukem __pwexclude_add(user);
1009 1.14 phil }
1010 1.34 lukem endnetgrent();
1011 1.14 phil break;
1012 1.34 lukem default:
1013 1.34 lukem __pwexclude_add(_pw_passwd.pw_name + 1);
1014 1.32 lukem break;
1015 1.4 deraadt }
1016 1.34 lukem break;
1017 1.34 lukem }
1018 1.34 lukem if ((search == _PW_KEYBYNAME &&
1019 1.34 lukem strcmp(_pw_passwd.pw_name, name) == 0)
1020 1.34 lukem || (search == _PW_KEYBYUID && _pw_passwd.pw_uid == uid)) {
1021 1.34 lukem rval = NS_SUCCESS;
1022 1.34 lukem break;
1023 1.4 deraadt }
1024 1.34 lukem if(s == 1) /* inside netgroup */
1025 1.34 lukem goto pwnam_netgrp;
1026 1.34 lukem continue;
1027 1.4 deraadt }
1028 1.34 lukem __pwproto = (struct passwd *)NULL;
1029 1.1 cgd
1030 1.1 cgd if (!_pw_stayopen) {
1031 1.1 cgd (void)(_pw_db->close)(_pw_db);
1032 1.1 cgd _pw_db = (DB *)NULL;
1033 1.1 cgd }
1034 1.32 lukem if(__pwexclude != (DB *)NULL) {
1035 1.32 lukem (void)(__pwexclude->close)(__pwexclude);
1036 1.32 lukem __pwexclude = (DB *)NULL;
1037 1.32 lukem }
1038 1.32 lukem return rval;
1039 1.40 lukem #endif /* _PASSWD_COMPAT */
1040 1.1 cgd }
1041 1.1 cgd
1042 1.1 cgd struct passwd *
1043 1.32 lukem getpwent()
1044 1.1 cgd {
1045 1.32 lukem int r;
1046 1.36 lukem static const ns_dtab dtab[] = {
1047 1.35 lukem NS_FILES_CB(_local_getpw, NULL)
1048 1.35 lukem NS_DNS_CB(_dns_getpw, NULL)
1049 1.35 lukem NS_NIS_CB(_nis_getpw, NULL)
1050 1.35 lukem NS_COMPAT_CB(_compat_getpwent, NULL)
1051 1.35 lukem { 0 }
1052 1.32 lukem };
1053 1.32 lukem
1054 1.36 lukem r = nsdispatch(NULL, dtab, NSDB_PASSWD, "getpwent", compatsrc,
1055 1.35 lukem _PW_KEYBYNUM);
1056 1.42 lukem if (r != NS_SUCCESS)
1057 1.32 lukem return (struct passwd *)NULL;
1058 1.32 lukem return &_pw_passwd;
1059 1.32 lukem }
1060 1.10 deraadt
1061 1.32 lukem struct passwd *
1062 1.32 lukem getpwnam(name)
1063 1.32 lukem const char *name;
1064 1.32 lukem {
1065 1.32 lukem int r;
1066 1.36 lukem static const ns_dtab dtab[] = {
1067 1.35 lukem NS_FILES_CB(_local_getpw, NULL)
1068 1.35 lukem NS_DNS_CB(_dns_getpw, NULL)
1069 1.35 lukem NS_NIS_CB(_nis_getpw, NULL)
1070 1.35 lukem NS_COMPAT_CB(_compat_getpw, NULL)
1071 1.35 lukem { 0 }
1072 1.32 lukem };
1073 1.4 deraadt
1074 1.32 lukem if (name == NULL || name[0] == '\0')
1075 1.32 lukem return (struct passwd *)NULL;
1076 1.4 deraadt
1077 1.36 lukem r = nsdispatch(NULL, dtab, NSDB_PASSWD, "getpwnam", compatsrc,
1078 1.35 lukem _PW_KEYBYNAME, name);
1079 1.32 lukem return (r == NS_SUCCESS ? &_pw_passwd : (struct passwd *)NULL);
1080 1.32 lukem }
1081 1.14 phil
1082 1.32 lukem struct passwd *
1083 1.32 lukem getpwuid(uid)
1084 1.32 lukem uid_t uid;
1085 1.32 lukem {
1086 1.32 lukem int r;
1087 1.36 lukem static const ns_dtab dtab[] = {
1088 1.35 lukem NS_FILES_CB(_local_getpw, NULL)
1089 1.35 lukem NS_DNS_CB(_dns_getpw, NULL)
1090 1.35 lukem NS_NIS_CB(_nis_getpw, NULL)
1091 1.35 lukem NS_COMPAT_CB(_compat_getpw, NULL)
1092 1.35 lukem { 0 }
1093 1.32 lukem };
1094 1.1 cgd
1095 1.36 lukem r = nsdispatch(NULL, dtab, NSDB_PASSWD, "getpwuid", compatsrc,
1096 1.35 lukem _PW_KEYBYUID, uid);
1097 1.32 lukem return (r == NS_SUCCESS ? &_pw_passwd : (struct passwd *)NULL);
1098 1.1 cgd }
1099 1.1 cgd
1100 1.1 cgd int
1101 1.1 cgd setpassent(stayopen)
1102 1.1 cgd int stayopen;
1103 1.1 cgd {
1104 1.1 cgd _pw_keynum = 0;
1105 1.1 cgd _pw_stayopen = stayopen;
1106 1.9 jtc #ifdef YP
1107 1.32 lukem __pwmode = PWMODE_NONE;
1108 1.9 jtc if(__ypcurrent)
1109 1.9 jtc free(__ypcurrent);
1110 1.9 jtc __ypcurrent = NULL;
1111 1.42 lukem _pw_ypdone = 0;
1112 1.32 lukem #endif
1113 1.32 lukem #ifdef HESIOD
1114 1.32 lukem _pw_hesnum = 0;
1115 1.32 lukem #endif
1116 1.40 lukem #ifdef _PASSWD_COMPAT
1117 1.32 lukem if(__pwexclude != (DB *)NULL) {
1118 1.32 lukem (void)(__pwexclude->close)(__pwexclude);
1119 1.32 lukem __pwexclude = (DB *)NULL;
1120 1.14 phil }
1121 1.32 lukem __pwproto = (struct passwd *)NULL;
1122 1.9 jtc #endif
1123 1.32 lukem return 1;
1124 1.1 cgd }
1125 1.1 cgd
1126 1.8 jtc void
1127 1.1 cgd setpwent()
1128 1.1 cgd {
1129 1.9 jtc (void) setpassent(0);
1130 1.1 cgd }
1131 1.1 cgd
1132 1.1 cgd void
1133 1.1 cgd endpwent()
1134 1.1 cgd {
1135 1.1 cgd _pw_keynum = 0;
1136 1.1 cgd if (_pw_db) {
1137 1.1 cgd (void)(_pw_db->close)(_pw_db);
1138 1.1 cgd _pw_db = (DB *)NULL;
1139 1.1 cgd }
1140 1.40 lukem #ifdef _PASSWD_COMPAT
1141 1.32 lukem __pwmode = PWMODE_NONE;
1142 1.32 lukem #endif
1143 1.4 deraadt #ifdef YP
1144 1.4 deraadt if(__ypcurrent)
1145 1.4 deraadt free(__ypcurrent);
1146 1.4 deraadt __ypcurrent = NULL;
1147 1.42 lukem _pw_ypdone = 0;
1148 1.32 lukem #endif
1149 1.32 lukem #ifdef HESIOD
1150 1.32 lukem _pw_hesnum = 0;
1151 1.32 lukem #endif
1152 1.40 lukem #ifdef _PASSWD_COMPAT
1153 1.32 lukem if(__pwexclude != (DB *)NULL) {
1154 1.32 lukem (void)(__pwexclude->close)(__pwexclude);
1155 1.32 lukem __pwexclude = (DB *)NULL;
1156 1.14 phil }
1157 1.32 lukem __pwproto = (struct passwd *)NULL;
1158 1.4 deraadt #endif
1159 1.1 cgd }
1160 1.1 cgd
1161 1.4 deraadt static int
1162 1.1 cgd __initdb()
1163 1.1 cgd {
1164 1.1 cgd static int warned;
1165 1.1 cgd char *p;
1166 1.1 cgd
1167 1.40 lukem #ifdef _PASSWD_COMPAT
1168 1.32 lukem __pwmode = PWMODE_NONE;
1169 1.14 phil #endif
1170 1.25 mrg if (geteuid() == 0) {
1171 1.25 mrg _pw_db = dbopen((p = _PATH_SMP_DB), O_RDONLY, 0, DB_HASH, NULL);
1172 1.25 mrg if (_pw_db)
1173 1.25 mrg return(1);
1174 1.25 mrg }
1175 1.25 mrg _pw_db = dbopen((p = _PATH_MP_DB), O_RDONLY, 0, DB_HASH, NULL);
1176 1.1 cgd if (_pw_db)
1177 1.32 lukem return 1;
1178 1.1 cgd if (!warned)
1179 1.1 cgd syslog(LOG_ERR, "%s: %m", p);
1180 1.11 deraadt warned = 1;
1181 1.32 lukem return 0;
1182 1.1 cgd }
1183 1.1 cgd
1184 1.4 deraadt static int
1185 1.1 cgd __hashpw(key)
1186 1.1 cgd DBT *key;
1187 1.1 cgd {
1188 1.47 simonb char *p, *t, *oldbuf;
1189 1.1 cgd static u_int max;
1190 1.30 christos static char *buf;
1191 1.1 cgd DBT data;
1192 1.45 lukem
1193 1.45 lukem _DIAGASSERT(key != NULL);
1194 1.1 cgd
1195 1.32 lukem switch ((_pw_db->get)(_pw_db, key, &data, 0)) {
1196 1.32 lukem case 0:
1197 1.32 lukem break; /* found */
1198 1.32 lukem case 1:
1199 1.32 lukem return NS_NOTFOUND;
1200 1.32 lukem case -1:
1201 1.32 lukem return NS_UNAVAIL; /* error in db routines */
1202 1.32 lukem default:
1203 1.32 lukem abort();
1204 1.32 lukem }
1205 1.32 lukem
1206 1.1 cgd p = (char *)data.data;
1207 1.47 simonb if (data.size > max) {
1208 1.47 simonb max = roundup(data.size, 1024);
1209 1.47 simonb oldbuf = buf;
1210 1.47 simonb if ((buf = realloc(buf, max)) == NULL) {
1211 1.47 simonb if (oldbuf != NULL)
1212 1.47 simonb free(oldbuf);
1213 1.48 enami max = 0;
1214 1.47 simonb return NS_UNAVAIL;
1215 1.47 simonb }
1216 1.47 simonb }
1217 1.1 cgd
1218 1.24 perry /* THIS CODE MUST MATCH THAT IN pwd_mkdb. */
1219 1.30 christos t = buf;
1220 1.14 phil #define EXPAND(e) e = t; while ((*t++ = *p++));
1221 1.24 perry #define SCALAR(v) memmove(&(v), p, sizeof v); p += sizeof v
1222 1.1 cgd EXPAND(_pw_passwd.pw_name);
1223 1.1 cgd EXPAND(_pw_passwd.pw_passwd);
1224 1.24 perry SCALAR(_pw_passwd.pw_uid);
1225 1.24 perry SCALAR(_pw_passwd.pw_gid);
1226 1.24 perry SCALAR(_pw_passwd.pw_change);
1227 1.1 cgd EXPAND(_pw_passwd.pw_class);
1228 1.1 cgd EXPAND(_pw_passwd.pw_gecos);
1229 1.1 cgd EXPAND(_pw_passwd.pw_dir);
1230 1.1 cgd EXPAND(_pw_passwd.pw_shell);
1231 1.24 perry SCALAR(_pw_passwd.pw_expire);
1232 1.14 phil
1233 1.14 phil /* See if there's any data left. If so, read in flags. */
1234 1.52 thorpej if (data.size > (size_t) (p - (char *)data.data)) {
1235 1.24 perry SCALAR(_pw_flags);
1236 1.14 phil } else
1237 1.14 phil _pw_flags = _PASSWORD_NOUID|_PASSWORD_NOGID; /* default */
1238 1.14 phil
1239 1.32 lukem return NS_SUCCESS;
1240 1.1 cgd }
1241