cgdconfig.c revision 1.9 1 /* $NetBSD: cgdconfig.c,v 1.9 2003/09/23 17:24:46 cb Exp $ */
2
3 /*-
4 * Copyright (c) 2002, 2003 The NetBSD Foundation, Inc.
5 * All rights reserved.
6 *
7 * This code is derived from software contributed to The NetBSD Foundation
8 * by Roland C. Dowdeswell.
9 *
10 * Redistribution and use in source and binary forms, with or without
11 * modification, are permitted provided that the following conditions
12 * are met:
13 * 1. Redistributions of source code must retain the above copyright
14 * notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 * notice, this list of conditions and the following disclaimer in the
17 * documentation and/or other materials provided with the distribution.
18 * 3. All advertising materials mentioning features or use of this software
19 * must display the following acknowledgement:
20 * This product includes software developed by the NetBSD
21 * Foundation, Inc. and its contributors.
22 * 4. Neither the name of The NetBSD Foundation nor the names of its
23 * contributors may be used to endorse or promote products derived
24 * from this software without specific prior written permission.
25 *
26 * THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS
27 * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED
28 * TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
29 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS
30 * BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
31 * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
32 * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
33 * INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
34 * CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
35 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
36 * POSSIBILITY OF SUCH DAMAGE.
37 */
38
39 #include <sys/cdefs.h>
40 #ifndef lint
41 __COPYRIGHT(
42 "@(#) Copyright (c) 2002, 2003\
43 The NetBSD Foundation, Inc. All rights reserved.");
44 __RCSID("$NetBSD: cgdconfig.c,v 1.9 2003/09/23 17:24:46 cb Exp $");
45 #endif
46
47 #include <err.h>
48 #include <errno.h>
49 #include <fcntl.h>
50 #include <libgen.h>
51 #include <stdio.h>
52 #include <stdlib.h>
53 #include <string.h>
54 #include <unistd.h>
55 #include <util.h>
56
57 #include <sys/ioctl.h>
58 #include <sys/disklabel.h>
59 #include <sys/param.h>
60
61 #include <dev/cgdvar.h>
62
63 #include <ufs/ffs/fs.h>
64
65 #include "params.h"
66 #include "pkcs5_pbkdf2.h"
67 #include "utils.h"
68
69 #define CGDCONFIG_DIR "/etc/cgd"
70 #define CGDCONFIG_CFILE CGDCONFIG_DIR "/cgd.conf"
71
72 #define ACTION_CONFIGURE 0x1 /* configure, with paramsfile */
73 #define ACTION_UNCONFIGURE 0x2 /* unconfigure */
74 #define ACTION_GENERATE 0x3 /* generate a paramsfile */
75 #define ACTION_GENERATE_CONVERT 0x4 /* generate a ``dup'' paramsfile */
76 #define ACTION_CONFIGALL 0x5 /* configure all from config file */
77 #define ACTION_UNCONFIGALL 0x6 /* unconfigure all from config file */
78 #define ACTION_CONFIGSTDIN 0x7 /* configure, key from stdin */
79
80 /* if nflag is set, do not configure/unconfigure the cgd's */
81
82 int nflag = 0;
83
84 static int configure(int, char **, struct params *, int);
85 static int configure_stdin(struct params *, int argc, char **);
86 static int generate(struct params *, int, char **, const char *);
87 static int generate_convert(struct params *, int, char **, const char *);
88 static int unconfigure(int, char **, struct params *, int);
89 static int do_all(const char *, int, char **,
90 int (*)(int, char **, struct params *, int));
91
92 #define CONFIG_FLAGS_FROMALL 1 /* called from configure_all() */
93 #define CONFIG_FLAGS_FROMMAIN 2 /* called from main() */
94
95 static int configure_params(int, const char *, const char *,
96 struct params *);
97 static bits_t *getkey(const char *, struct keygen *, int);
98 static bits_t *getkey_storedkey(const char *, struct keygen *, int);
99 static bits_t *getkey_randomkey(const char *, struct keygen *, int);
100 static bits_t *getkey_pkcs5_pbkdf2(const char *, struct keygen *, int);
101 static int opendisk_werror(const char *, char *, int);
102 static int unconfigure_fd(int);
103 static int verify(struct params *, int);
104 static int verify_disklabel(int);
105 static int verify_ffs(int);
106 static int verify_reenter(struct params *);
107
108 static void usage(void);
109
110 /* Verbose Framework */
111 int verbose = 0;
112
113 #define VERBOSE(x,y) if (verbose >= x) y
114 #define VPRINTF(x,y) if (verbose >= x) printf y
115
116 static void
117 usage(void)
118 {
119
120 fprintf(stderr, "usage: %s [-nv] [-V vmeth] cgd dev [paramsfile]\n",
121 getprogname());
122 fprintf(stderr, " %s -C [-nv] [-f configfile]\n", getprogname());
123 fprintf(stderr, " %s -U [-nv] [-f configfile]\n", getprogname());
124 fprintf(stderr, " %s -G [-nv] [-i ivmeth] [-k kgmeth] "
125 "[-o outfile] paramsfile\n", getprogname());
126 fprintf(stderr, " %s -g [-nv] [-i ivmeth] [-k kgmeth] "
127 "[-o outfile] alg [keylen]\n", getprogname());
128 fprintf(stderr, " %s -s [-nv] [-i ivmeth] cgd dev alg "
129 "[keylen]\n", getprogname());
130 fprintf(stderr, " %s -u [-nv] cgd\n", getprogname());
131 exit(1);
132 }
133
134 int
135 main(int argc, char **argv)
136 {
137 struct params *p;
138 struct params *tp;
139 struct keygen *kg;
140 int action = ACTION_CONFIGURE;
141 int actions = 0;
142 int ch;
143 char cfile[FILENAME_MAX] = "";
144 char outfile[FILENAME_MAX] = "";
145
146 setprogname(*argv);
147 p = params_new();
148 kg = NULL;
149
150 while ((ch = getopt(argc, argv, "CGUV:b:f:gi:k:no:usv")) != -1)
151 switch (ch) {
152 case 'C':
153 action = ACTION_CONFIGALL;
154 actions++;
155 break;
156 case 'G':
157 action = ACTION_GENERATE_CONVERT;
158 actions++;
159 break;
160 case 'U':
161 action = ACTION_UNCONFIGALL;
162 actions++;
163 break;
164 case 'V':
165 tp = params_verify_method(string_fromcharstar(optarg));
166 if (!tp)
167 usage();
168 p = params_combine(p, tp);
169 break;
170 case 'b':
171 tp = params_bsize(atoi(optarg));
172 if (!tp)
173 usage();
174 p = params_combine(p, tp);
175 break;
176 case 'f':
177 strlcpy(cfile, optarg, sizeof(cfile));
178 break;
179 case 'g':
180 action = ACTION_GENERATE;
181 actions++;
182 break;
183 case 'i':
184 tp = params_ivmeth(string_fromcharstar(optarg));
185 p = params_combine(p, tp);
186 break;
187 case 'k':
188 kg = keygen_method(string_fromcharstar(optarg));
189 if (!kg)
190 usage();
191 keygen_addlist(&p->keygen, kg);
192 break;
193 case 'n':
194 nflag = 1;
195 break;
196 case 'o':
197 strlcpy(outfile, optarg, sizeof(outfile));
198 break;
199 case 's':
200 action = ACTION_CONFIGSTDIN;
201 actions++;
202 break;
203
204 case 'u':
205 action = ACTION_UNCONFIGURE;
206 actions++;
207 break;
208 case 'v':
209 verbose++;
210 break;
211 default:
212 usage();
213 /* NOTREACHED */
214 }
215
216 argc -= optind;
217 argv += optind;
218
219 /* validate the consistency of the arguments */
220
221 if (actions > 1)
222 usage();
223
224 switch (action) {
225 case ACTION_CONFIGURE:
226 return configure(argc, argv, p, CONFIG_FLAGS_FROMMAIN);
227 case ACTION_UNCONFIGURE:
228 return unconfigure(argc, argv, NULL, CONFIG_FLAGS_FROMMAIN);
229 case ACTION_GENERATE:
230 return generate(p, argc, argv, outfile);
231 case ACTION_GENERATE_CONVERT:
232 return generate_convert(p, argc, argv, outfile);
233 case ACTION_CONFIGALL:
234 return do_all(cfile, argc, argv, configure);
235 case ACTION_UNCONFIGALL:
236 return do_all(cfile, argc, argv, unconfigure);
237 case ACTION_CONFIGSTDIN:
238 return configure_stdin(p, argc, argv);
239 default:
240 errx(EXIT_FAILURE, "undefined action");
241 }
242 /* NOTREACHED */
243 }
244
245 static bits_t *
246 getkey(const char *dev, struct keygen *kg, int len)
247 {
248 bits_t *ret = NULL;
249 bits_t *tmp;
250
251 VPRINTF(3, ("getkey(\"%s\", %p, %d) called\n", dev, kg, len));
252 for (; kg; kg=kg->next) {
253 switch (kg->kg_method) {
254 case KEYGEN_STOREDKEY:
255 tmp = getkey_storedkey(dev, kg, len);
256 break;
257 case KEYGEN_RANDOMKEY:
258 tmp = getkey_randomkey(dev, kg, len);
259 break;
260 case KEYGEN_PKCS5_PBKDF2:
261 tmp = getkey_pkcs5_pbkdf2(dev, kg, len);
262 break;
263 default:
264 warnx("unrecognised keygen method %d in getkey()",
265 kg->kg_method);
266 if (ret)
267 bits_free(ret);
268 return NULL;
269 }
270
271 if (ret)
272 ret = bits_xor_d(tmp, ret);
273 else
274 ret = tmp;
275 }
276
277 return ret;
278 }
279
280 /*ARGSUSED*/
281 static bits_t *
282 getkey_storedkey(const char *target, struct keygen *kg, int keylen)
283 {
284
285 return bits_dup(kg->kg_key);
286 }
287
288 /*ARGSUSED*/
289 static bits_t *
290 getkey_randomkey(const char *target, struct keygen *kg, int keylen)
291 {
292
293 return bits_getrandombits(keylen);
294 }
295
296 /*ARGSUSED*/
297 static bits_t *
298 getkey_pkcs5_pbkdf2(const char *target, struct keygen *kg, int keylen)
299 {
300 bits_t *ret;
301 char *passp;
302 char buf[1024];
303 u_int8_t *tmp;
304
305 snprintf(buf, sizeof(buf), "%s's passphrase:", target);
306 passp = getpass(buf);
307 if (pkcs5_pbkdf2(&tmp, BITS2BYTES(keylen), passp, strlen(passp),
308 bits_getbuf(kg->kg_salt), BITS2BYTES(bits_len(kg->kg_salt)),
309 kg->kg_iterations)) {
310 warnx("failed to generate PKCS#5 PBKDF2 key");
311 return NULL;
312 }
313
314 ret = bits_new(tmp, keylen);
315 kg->kg_key = bits_dup(ret);
316 free(tmp);
317 return ret;
318 }
319
320 /*ARGSUSED*/
321 static int
322 unconfigure(int argc, char **argv, struct params *inparams, int flags)
323 {
324 int fd;
325 int ret;
326 char buf[MAXPATHLEN] = "";
327
328 /* only complain about additional arguments, if called from main() */
329 if (flags == CONFIG_FLAGS_FROMMAIN && argc != 1)
330 usage();
331
332 /* if called from do_all(), then ensure that 2 or 3 args exist */
333 if (flags == CONFIG_FLAGS_FROMALL && (argc < 2 || argc > 3))
334 return -1;
335
336 fd = opendisk(*argv, O_RDWR, buf, sizeof(buf), 1);
337 if (fd == -1) {
338 warn("can't open cgd \"%s\", \"%s\"", *argv, buf);
339
340 /* this isn't fatal with nflag != 0 */
341 if (!nflag)
342 return errno;
343 }
344
345 VPRINTF(1, ("%s (%s): clearing\n", *argv, buf));
346
347 if (nflag)
348 return 0;
349
350 ret = unconfigure_fd(fd);
351 close(fd);
352 return ret;
353 }
354
355 static int
356 unconfigure_fd(int fd)
357 {
358 struct cgd_ioctl ci;
359 int ret;
360
361 ret = ioctl(fd, CGDIOCCLR, &ci);
362 if (ret == -1) {
363 perror("ioctl");
364 return -1;
365 }
366
367 return 0;
368 }
369
370 /*ARGSUSED*/
371 static int
372 configure(int argc, char **argv, struct params *inparams, int flags)
373 {
374 struct params *p;
375 int fd;
376 int ret;
377 char pfile[FILENAME_MAX];
378 char cgdname[PATH_MAX];
379
380 switch (argc) {
381 case 2:
382 strlcpy(pfile, CGDCONFIG_DIR, FILENAME_MAX);
383 strlcat(pfile, "/", FILENAME_MAX);
384 strlcat(pfile, basename(argv[1]), FILENAME_MAX);
385 break;
386 case 3:
387 strlcpy(pfile, argv[2], FILENAME_MAX);
388 break;
389 default:
390 /* print usage and exit, only if called from main() */
391 if (flags == CONFIG_FLAGS_FROMMAIN) {
392 warnx("wrong number of args");
393 usage();
394 }
395 return -1;
396 /* NOTREACHED */
397 }
398
399 p = params_cget(pfile);
400 if (!p)
401 return -1;
402
403 /*
404 * over-ride with command line specifications and fill in default
405 * values.
406 */
407
408 p = params_combine(p, inparams);
409 ret = params_filldefaults(p);
410 if (ret) {
411 params_free(p);
412 return ret;
413 }
414
415 if (!params_verify(p)) {
416 warnx("params invalid");
417 return -1;
418 }
419
420 /*
421 * loop over configuring the disk and checking to see if it
422 * verifies properly. We open and close the disk device each
423 * time, because if the user passes us the block device we
424 * need to flush the buffer cache.
425 */
426
427 for (;;) {
428 fd = opendisk_werror(argv[0], cgdname, sizeof(cgdname));
429 if (fd == -1)
430 return -1;
431
432 if (p->key)
433 bits_free(p->key);
434
435 p->key = getkey(argv[1], p->keygen, p->keylen);
436 if (!p->key)
437 goto bail_err;
438
439 ret = configure_params(fd, cgdname, argv[1], p);
440 if (ret)
441 goto bail_err;
442
443 ret = verify(p, fd);
444 if (ret == -1)
445 goto bail_err;
446 if (!ret)
447 break;
448
449 fprintf(stderr, "verification failed, please reenter "
450 "passphrase\n");
451
452 unconfigure_fd(fd);
453 close(fd);
454 }
455
456 params_free(p);
457 close(fd);
458 return 0;
459 bail_err:
460 params_free(p);
461 close(fd);
462 return -1;
463 }
464
465 static int
466 configure_stdin(struct params *p, int argc, char **argv)
467 {
468 int fd;
469 int ret;
470 char cgdname[PATH_MAX];
471
472 if (argc < 3 || argc > 4)
473 usage();
474
475 p->algorithm = string_fromcharstar(argv[2]);
476 if (argc > 3)
477 p->keylen = atoi(argv[3]);
478
479 ret = params_filldefaults(p);
480 if (ret)
481 return ret;
482
483 fd = opendisk_werror(argv[0], cgdname, sizeof(cgdname));
484 if (fd == -1)
485 return -1;
486
487 p->key = bits_fget(stdin, p->keylen);
488 if (!p->key) {
489 warnx("failed to read key from stdin");
490 return -1;
491 }
492
493 return configure_params(fd, cgdname, argv[1], p);
494 }
495
496 static int
497 opendisk_werror(const char *cgd, char *buf, int buflen)
498 {
499 int fd;
500
501 VPRINTF(3, ("opendisk_werror(%s, %s, %d) called.\n", cgd, buf, buflen));
502
503 /* sanity */
504 if (!cgd || !buf)
505 return -1;
506
507 if (nflag) {
508 strlcpy(buf, cgd, buflen);
509 return 0;
510 }
511
512 fd = opendisk(cgd, O_RDWR, buf, buflen, 0);
513 if (fd == -1)
514 warnx("can't open cgd \"%s\", \"%s\"", cgd, buf);
515
516 return fd;
517 }
518
519 static int
520 configure_params(int fd, const char *cgd, const char *dev, struct params *p)
521 {
522 struct cgd_ioctl ci;
523 int ret;
524
525 /* sanity */
526 if (!cgd || !dev)
527 return -1;
528
529 memset(&ci, 0x0, sizeof(ci));
530 ci.ci_disk = (char *)dev;
531 ci.ci_alg = (char *)string_tocharstar(p->algorithm);
532 ci.ci_ivmethod = (char *)string_tocharstar(p->ivmeth);
533 ci.ci_key = (char *)bits_getbuf(p->key);
534 ci.ci_keylen = p->keylen;
535 ci.ci_blocksize = p->bsize;
536
537 VPRINTF(1, (" with alg %s keylen %d blocksize %d ivmethod %s\n",
538 string_tocharstar(p->algorithm), p->keylen, p->bsize,
539 string_tocharstar(p->ivmeth)));
540 VPRINTF(2, ("key: "));
541 VERBOSE(2, bits_fprint(stdout, p->key));
542 VPRINTF(2, ("\n"));
543
544 if (nflag)
545 return 0;
546
547 ret = ioctl(fd, CGDIOCSET, &ci);
548 if (ret == -1) {
549 perror("ioctl");
550 return errno;
551 }
552
553 return 0;
554 }
555
556 /*
557 * verify returns 0 for success, -1 for unrecoverable error, or 1 for retry.
558 */
559
560 #define SCANSIZE 8192
561
562 static int
563 verify(struct params *p, int fd)
564 {
565
566 switch (p->verify_method) {
567 case VERIFY_NONE:
568 return 0;
569 case VERIFY_DISKLABEL:
570 return verify_disklabel(fd);
571 case VERIFY_FFS:
572 return verify_ffs(fd);
573 case VERIFY_REENTER:
574 return verify_reenter(p);
575 default:
576 warnx("unimplemented verification method");
577 return -1;
578 }
579 }
580
581 static int
582 verify_disklabel(int fd)
583 {
584 struct disklabel l;
585 int ret;
586 char buf[SCANSIZE];
587
588 /*
589 * we simply scan the first few blocks for a disklabel, ignoring
590 * any MBR/filecore sorts of logic. MSDOS and RiscOS can't read
591 * a cgd, anyway, so it is unlikely that there will be non-native
592 * partition information.
593 */
594
595 ret = pread(fd, buf, 8192, 0);
596 if (ret == -1) {
597 warn("can't read disklabel area");
598 return -1;
599 }
600
601 /* now scan for the disklabel */
602
603 return disklabel_scan(&l, buf, sizeof(buf));
604 }
605
606 static off_t sblock_try[] = SBLOCKSEARCH;
607
608 static int
609 verify_ffs(int fd)
610 {
611 struct fs *fs;
612 int ret, i;
613 char buf[SBLOCKSIZE];
614
615 for (i = 0; sblock_try[i] != -1; i++) {
616 ret = pread(fd, buf, sizeof(buf), sblock_try[i]);
617 if (ret == -1) {
618 warn("pread");
619 return 0;
620 }
621 fs = (struct fs *)buf;
622 switch (fs->fs_magic) {
623 case FS_UFS1_MAGIC:
624 case FS_UFS2_MAGIC:
625 case FS_UFS1_MAGIC_SWAPPED:
626 case FS_UFS2_MAGIC_SWAPPED:
627 return 0;
628 default:
629 continue;
630 }
631 }
632 return 1;
633 }
634
635 static int
636 verify_reenter(struct params *p)
637 {
638 struct keygen *kg;
639 bits_t *orig_key, *key;
640 int ret;
641
642 ret = 0;
643 for (kg = p->keygen; kg && !ret; kg = kg->next) {
644 if (kg->kg_method != KEYGEN_PKCS5_PBKDF2)
645 continue;
646
647 orig_key = kg->kg_key;
648 kg->kg_key = NULL;
649
650 key = getkey_pkcs5_pbkdf2("re-enter device", kg,
651 bits_len(orig_key));
652 ret = !bits_match(key, orig_key);
653
654 bits_free(key);
655 bits_free(kg->kg_key);
656 kg->kg_key = orig_key;
657 }
658
659 return ret;
660 }
661
662 static int
663 generate(struct params *p, int argc, char **argv, const char *outfile)
664 {
665 int ret;
666
667 if (argc < 1 || argc > 2)
668 usage();
669
670 p->algorithm = string_fromcharstar(argv[0]);
671 if (argc > 1)
672 p->keylen = atoi(argv[1]);
673
674 ret = params_filldefaults(p);
675 if (ret)
676 return ret;
677
678 if (!p->keygen) {
679 p->keygen = keygen_generate(KEYGEN_PKCS5_PBKDF2);
680 if (!p->keygen)
681 return -1;
682 }
683
684 if (keygen_filldefaults(p->keygen, p->keylen)) {
685 warnx("Failed to generate defaults for keygen");
686 return -1;
687 }
688
689 if (!params_verify(p)) {
690 warnx("invalid parameters generated");
691 return -1;
692 }
693
694 return params_cput(p, outfile);
695 }
696
697 static int
698 generate_convert(struct params *p, int argc, char **argv, const char *outfile)
699 {
700 struct params *oldp;
701 struct keygen *kg;
702
703 if (argc != 1)
704 usage();
705
706 oldp = params_cget(*argv);
707 if (!oldp)
708 return -1;
709
710 /* for sanity, we ensure that none of the keygens are randomkey */
711 for (kg=p->keygen; kg; kg=kg->next)
712 if (kg->kg_method == KEYGEN_RANDOMKEY)
713 goto bail;
714 for (kg=oldp->keygen; kg; kg=kg->next)
715 if (kg->kg_method == KEYGEN_RANDOMKEY)
716 goto bail;
717
718 if (!params_verify(oldp)) {
719 warnx("invalid old parameters file \"%s\"", *argv);
720 return -1;
721 }
722
723 oldp->key = getkey("old file", oldp->keygen, oldp->keylen);
724
725 /* we copy across the non-keygen info, here. */
726
727 string_free(p->algorithm);
728 string_free(p->ivmeth);
729
730 p->algorithm = string_dup(oldp->algorithm);
731 p->ivmeth = string_dup(oldp->ivmeth);
732 p->keylen = oldp->keylen;
733 p->bsize = oldp->bsize;
734 if (p->verify_method == VERIFY_UNKNOWN)
735 p->verify_method = oldp->verify_method;
736
737 params_free(oldp);
738
739 if (!p->keygen) {
740 p->keygen = keygen_generate(KEYGEN_PKCS5_PBKDF2);
741 if (!p->keygen)
742 return -1;
743 }
744 params_filldefaults(p);
745 keygen_filldefaults(p->keygen, p->keylen);
746 p->key = getkey("new file", p->keygen, p->keylen);
747
748 kg = keygen_generate(KEYGEN_STOREDKEY);
749 kg->kg_key = bits_xor(p->key, oldp->key);
750 keygen_addlist(&p->keygen, kg);
751
752 if (!params_verify(p)) {
753 warnx("can't generate new parameters file");
754 return -1;
755 }
756
757 return params_cput(p, outfile);
758 bail:
759 params_free(oldp);
760 return -1;
761 }
762
763 static int
764 do_all(const char *cfile, int argc, char **argv,
765 int (*conf)(int, char **, struct params *, int))
766 {
767 FILE *f;
768 size_t len;
769 size_t lineno;
770 int my_argc;
771 int ret;
772 const char *fn;
773 char *line;
774 char **my_argv;
775
776 if (argc > 0)
777 usage();
778
779 if (!cfile[0])
780 fn = CGDCONFIG_CFILE;
781 else
782 fn = cfile;
783
784 f = fopen(fn, "r");
785 if (!f) {
786 warn("could not open config file \"%s\"", fn);
787 return -1;
788 }
789
790 ret = chdir(CGDCONFIG_DIR);
791 if (ret == -1)
792 warn("could not chdir to %s", CGDCONFIG_DIR);
793
794 ret = 0;
795 lineno = 0;
796 for (;;) {
797 line = fparseln(f, &len, &lineno, "\\\\#", FPARSELN_UNESCALL);
798 if (!line)
799 break;
800 if (!*line)
801 continue;
802
803 my_argv = words(line, &my_argc);
804 ret = conf(my_argc, my_argv, NULL, CONFIG_FLAGS_FROMALL);
805 if (ret) {
806 warnx("action failed on \"%s\" line %lu", fn,
807 (u_long)lineno);
808 break;
809 }
810 words_free(my_argv, my_argc);
811 }
812 return ret;
813 }
814