Home | History | Annotate | Line # | Download | only in ftp
      1  1.35  christos /*	$NetBSD: ruserpass.c,v 1.35 2024/10/04 18:04:06 christos Exp $	*/
      2   1.6       tls 
      3   1.1       cgd /*
      4   1.3       cgd  * Copyright (c) 1985, 1993, 1994
      5   1.3       cgd  *	The Regents of the University of California.  All rights reserved.
      6   1.1       cgd  *
      7   1.1       cgd  * Redistribution and use in source and binary forms, with or without
      8   1.1       cgd  * modification, are permitted provided that the following conditions
      9   1.1       cgd  * are met:
     10   1.1       cgd  * 1. Redistributions of source code must retain the above copyright
     11   1.1       cgd  *    notice, this list of conditions and the following disclaimer.
     12   1.1       cgd  * 2. Redistributions in binary form must reproduce the above copyright
     13   1.1       cgd  *    notice, this list of conditions and the following disclaimer in the
     14   1.1       cgd  *    documentation and/or other materials provided with the distribution.
     15  1.29       agc  * 3. Neither the name of the University nor the names of its contributors
     16   1.1       cgd  *    may be used to endorse or promote products derived from this software
     17   1.1       cgd  *    without specific prior written permission.
     18   1.1       cgd  *
     19   1.1       cgd  * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND
     20   1.1       cgd  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     21   1.1       cgd  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     22   1.1       cgd  * ARE DISCLAIMED.  IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE
     23   1.1       cgd  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     24   1.1       cgd  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     25   1.1       cgd  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     26   1.1       cgd  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     27   1.1       cgd  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     28   1.1       cgd  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     29   1.1       cgd  * SUCH DAMAGE.
     30   1.1       cgd  */
     31   1.1       cgd 
     32  1.14     lukem #include <sys/cdefs.h>
     33   1.1       cgd #ifndef lint
     34  1.11     lukem #if 0
     35   1.6       tls static char sccsid[] = "@(#)ruserpass.c	8.4 (Berkeley) 4/27/95";
     36  1.11     lukem #else
     37  1.35  christos __RCSID("$NetBSD: ruserpass.c,v 1.35 2024/10/04 18:04:06 christos Exp $");
     38  1.11     lukem #endif
     39   1.1       cgd #endif /* not lint */
     40   1.1       cgd 
     41   1.1       cgd #include <sys/types.h>
     42   1.3       cgd #include <sys/stat.h>
     43   1.3       cgd 
     44   1.1       cgd #include <ctype.h>
     45   1.3       cgd #include <err.h>
     46   1.1       cgd #include <errno.h>
     47  1.21     lukem #include <netdb.h>
     48   1.3       cgd #include <stdio.h>
     49   1.3       cgd #include <stdlib.h>
     50   1.3       cgd #include <string.h>
     51   1.3       cgd #include <unistd.h>
     52   1.3       cgd 
     53   1.1       cgd #include "ftp_var.h"
     54   1.1       cgd 
     55  1.26     lukem static	int token(void);
     56   1.1       cgd static	FILE *cfile;
     57   1.1       cgd 
     58   1.1       cgd #define	DEFAULT	1
     59   1.1       cgd #define	LOGIN	2
     60   1.1       cgd #define	PASSWD	3
     61  1.25     lukem #define	ACCOUNT	4
     62  1.25     lukem #define	MACDEF	5
     63   1.1       cgd #define	ID	10
     64   1.1       cgd #define	MACH	11
     65   1.1       cgd 
     66   1.1       cgd static char tokval[100];
     67   1.1       cgd 
     68   1.1       cgd static struct toktab {
     69  1.30     lukem 	const char *tokstr;
     70   1.1       cgd 	int tval;
     71  1.17     lukem } toktab[] = {
     72   1.3       cgd 	{ "default",	DEFAULT },
     73   1.3       cgd 	{ "login",	LOGIN },
     74   1.3       cgd 	{ "password",	PASSWD },
     75   1.3       cgd 	{ "passwd",	PASSWD },
     76   1.3       cgd 	{ "account",	ACCOUNT },
     77   1.3       cgd 	{ "machine",	MACH },
     78   1.3       cgd 	{ "macdef",	MACDEF },
     79   1.3       cgd 	{ NULL,		0 }
     80   1.1       cgd };
     81   1.1       cgd 
     82  1.35  christos static int
     83  1.35  christos match_host_domain(const char *host, const char *domain, const char *tokv)
     84  1.35  christos {
     85  1.35  christos 	const char *tmp;
     86  1.35  christos 
     87  1.35  christos 	if (strcasecmp(host, tokval) == 0)
     88  1.35  christos 		return 1;
     89  1.35  christos 
     90  1.35  christos 	return (tmp = strchr(host, '.')) != NULL &&
     91  1.35  christos 	    strcasecmp(tmp, domain) == 0 &&
     92  1.35  christos 	    strncasecmp(host, tokv, tmp - host) == 0 &&
     93  1.35  christos 	    tokv[tmp - host] == '\0';
     94  1.35  christos }
     95  1.35  christos 
     96   1.3       cgd int
     97  1.30     lukem ruserpass(const char *host, char **aname, char **apass, char **aacct)
     98   1.1       cgd {
     99  1.28     lukem 	char *tmp;
    100  1.30     lukem 	const char *mydomain;
    101  1.30     lukem 	char myname[MAXHOSTNAMELEN + 1];
    102   1.1       cgd 	int t, i, c, usedefault = 0;
    103   1.1       cgd 	struct stat stb;
    104   1.1       cgd 
    105  1.28     lukem 	if (netrc[0] == '\0')
    106   1.8     lukem 		return (0);
    107  1.28     lukem 	cfile = fopen(netrc, "r");
    108   1.1       cgd 	if (cfile == NULL) {
    109   1.1       cgd 		if (errno != ENOENT)
    110  1.33     lukem 			warn("Can't read `%s'", netrc);
    111   1.3       cgd 		return (0);
    112   1.1       cgd 	}
    113   1.1       cgd 	if (gethostname(myname, sizeof(myname)) < 0)
    114   1.1       cgd 		myname[0] = '\0';
    115  1.18       mrg 	myname[sizeof(myname) - 1] = '\0';
    116   1.3       cgd 	if ((mydomain = strchr(myname, '.')) == NULL)
    117   1.1       cgd 		mydomain = "";
    118  1.27     lukem  next:
    119  1.32     lukem 	while ((t = token()) > 0) switch(t) {
    120   1.1       cgd 
    121   1.1       cgd 	case DEFAULT:
    122   1.1       cgd 		usedefault = 1;
    123   1.1       cgd 		/* FALL THROUGH */
    124   1.1       cgd 
    125   1.1       cgd 	case MACH:
    126   1.1       cgd 		if (!usedefault) {
    127  1.32     lukem 			if ((t = token()) == -1)
    128  1.32     lukem 				goto bad;
    129  1.32     lukem 			if (t != ID)
    130   1.1       cgd 				continue;
    131   1.1       cgd 			/*
    132   1.1       cgd 			 * Allow match either for user's input host name
    133   1.7     lukem 			 * or official hostname.  Also allow match of
    134   1.1       cgd 			 * incompletely-specified host in local domain.
    135   1.1       cgd 			 */
    136  1.35  christos 			if (match_host_domain(hostname, mydomain, tokval))
    137   1.1       cgd 				goto match;
    138  1.35  christos 			if (match_host_domain(host, mydomain, tokval))
    139   1.1       cgd 				goto match;
    140   1.1       cgd 			continue;
    141   1.1       cgd 		}
    142   1.1       cgd 	match:
    143  1.32     lukem 		while ((t = token()) > 0 &&
    144  1.32     lukem 		    t != MACH && t != DEFAULT) switch(t) {
    145   1.1       cgd 
    146   1.1       cgd 		case LOGIN:
    147  1.32     lukem 			if ((t = token()) == -1)
    148  1.32     lukem 				goto bad;
    149  1.32     lukem 			if (t) {
    150  1.20     lukem 				if (*aname == NULL)
    151  1.31  christos 					*aname = ftp_strdup(tokval);
    152  1.20     lukem 				else {
    153   1.1       cgd 					if (strcmp(*aname, tokval))
    154   1.1       cgd 						goto next;
    155   1.1       cgd 				}
    156  1.16  christos 			}
    157   1.1       cgd 			break;
    158   1.1       cgd 		case PASSWD:
    159   1.6       tls 			if ((*aname == NULL || strcmp(*aname, "anonymous")) &&
    160   1.1       cgd 			    fstat(fileno(cfile), &stb) >= 0 &&
    161   1.1       cgd 			    (stb.st_mode & 077) != 0) {
    162  1.33     lukem 	warnx("Error: .netrc file is readable by others");
    163  1.33     lukem 	warnx("Remove password or make file unreadable by others");
    164   1.1       cgd 				goto bad;
    165   1.1       cgd 			}
    166  1.32     lukem 			if ((t = token()) == -1)
    167  1.32     lukem 				goto bad;
    168  1.32     lukem 			if (t && *apass == NULL)
    169  1.31  christos 				*apass = ftp_strdup(tokval);
    170   1.1       cgd 			break;
    171   1.1       cgd 		case ACCOUNT:
    172   1.1       cgd 			if (fstat(fileno(cfile), &stb) >= 0
    173   1.1       cgd 			    && (stb.st_mode & 077) != 0) {
    174  1.33     lukem 	warnx("Error: .netrc file is readable by others");
    175  1.33     lukem 	warnx("Remove account or make file unreadable by others");
    176   1.1       cgd 				goto bad;
    177   1.1       cgd 			}
    178  1.32     lukem 			if ((t = token()) == -1)
    179  1.32     lukem 				goto bad;
    180  1.32     lukem 			if (t && *aacct == NULL)
    181  1.31  christos 				*aacct = ftp_strdup(tokval);
    182   1.1       cgd 			break;
    183   1.1       cgd 		case MACDEF:
    184   1.1       cgd 			if (proxy) {
    185  1.12     lukem 				(void)fclose(cfile);
    186   1.3       cgd 				return (0);
    187   1.1       cgd 			}
    188  1.17     lukem 			while ((c = getc(cfile)) != EOF)
    189  1.11     lukem 				if (c != ' ' && c != '\t')
    190  1.11     lukem 					break;
    191   1.1       cgd 			if (c == EOF || c == '\n') {
    192  1.17     lukem 				fputs("Missing macdef name argument.\n",
    193  1.17     lukem 				    ttyout);
    194   1.1       cgd 				goto bad;
    195   1.1       cgd 			}
    196   1.1       cgd 			if (macnum == 16) {
    197  1.17     lukem 				fputs(
    198  1.17     lukem 			    "Limit of 16 macros have already been defined.\n",
    199  1.17     lukem 				    ttyout);
    200   1.1       cgd 				goto bad;
    201   1.1       cgd 			}
    202   1.1       cgd 			tmp = macros[macnum].mac_name;
    203   1.1       cgd 			*tmp++ = c;
    204  1.17     lukem 			for (i = 0; i < 8 && (c = getc(cfile)) != EOF &&
    205   1.1       cgd 			    !isspace(c); ++i) {
    206   1.1       cgd 				*tmp++ = c;
    207   1.1       cgd 			}
    208   1.1       cgd 			if (c == EOF) {
    209  1.17     lukem 				fputs(
    210  1.17     lukem 			    "Macro definition missing null line terminator.\n",
    211  1.17     lukem 				    ttyout);
    212   1.1       cgd 				goto bad;
    213   1.1       cgd 			}
    214   1.1       cgd 			*tmp = '\0';
    215   1.1       cgd 			if (c != '\n') {
    216  1.17     lukem 				while ((c = getc(cfile)) != EOF && c != '\n');
    217   1.1       cgd 			}
    218   1.1       cgd 			if (c == EOF) {
    219  1.17     lukem 				fputs(
    220  1.17     lukem 			    "Macro definition missing null line terminator.\n",
    221  1.17     lukem 				    ttyout);
    222   1.1       cgd 				goto bad;
    223   1.1       cgd 			}
    224   1.1       cgd 			if (macnum == 0) {
    225   1.1       cgd 				macros[macnum].mac_start = macbuf;
    226   1.1       cgd 			}
    227   1.1       cgd 			else {
    228   1.9     lukem 				macros[macnum].mac_start =
    229   1.9     lukem 				    macros[macnum-1].mac_end + 1;
    230   1.1       cgd 			}
    231   1.1       cgd 			tmp = macros[macnum].mac_start;
    232   1.1       cgd 			while (tmp != macbuf + 4096) {
    233  1.17     lukem 				if ((c = getc(cfile)) == EOF) {
    234  1.17     lukem 					fputs(
    235  1.17     lukem 			    "Macro definition missing null line terminator.\n",
    236  1.17     lukem 					    ttyout);
    237   1.1       cgd 					goto bad;
    238   1.1       cgd 				}
    239   1.1       cgd 				*tmp = c;
    240   1.1       cgd 				if (*tmp == '\n') {
    241  1.32     lukem 					if (tmp == macros[macnum].mac_start) {
    242  1.32     lukem 						macros[macnum++].mac_end = tmp;
    243  1.32     lukem 						break;
    244  1.32     lukem 					} else if (*(tmp - 1) == '\0') {
    245  1.32     lukem 						macros[macnum++].mac_end =
    246  1.32     lukem 						    tmp - 1;
    247  1.32     lukem 						break;
    248   1.1       cgd 					}
    249   1.1       cgd 					*tmp = '\0';
    250   1.1       cgd 				}
    251   1.1       cgd 				tmp++;
    252   1.1       cgd 			}
    253   1.1       cgd 			if (tmp == macbuf + 4096) {
    254  1.34     lukem 				fputs("4 KiB macro buffer exceeded.\n",
    255  1.17     lukem 				    ttyout);
    256   1.1       cgd 				goto bad;
    257   1.1       cgd 			}
    258   1.1       cgd 			break;
    259   1.1       cgd 		default:
    260  1.33     lukem 			warnx("Unknown .netrc keyword `%s'", tokval);
    261   1.1       cgd 			break;
    262   1.1       cgd 		}
    263   1.1       cgd 		goto done;
    264   1.1       cgd 	}
    265  1.27     lukem  done:
    266  1.32     lukem 	if (t == -1)
    267  1.32     lukem 		goto bad;
    268  1.12     lukem 	(void)fclose(cfile);
    269   1.3       cgd 	return (0);
    270  1.27     lukem  bad:
    271  1.12     lukem 	(void)fclose(cfile);
    272   1.3       cgd 	return (-1);
    273   1.1       cgd }
    274   1.1       cgd 
    275   1.3       cgd static int
    276  1.26     lukem token(void)
    277   1.1       cgd {
    278   1.1       cgd 	char *cp;
    279   1.1       cgd 	int c;
    280   1.1       cgd 	struct toktab *t;
    281   1.1       cgd 
    282   1.3       cgd 	if (feof(cfile) || ferror(cfile))
    283   1.1       cgd 		return (0);
    284   1.1       cgd 	while ((c = getc(cfile)) != EOF &&
    285   1.1       cgd 	    (c == '\n' || c == '\t' || c == ' ' || c == ','))
    286   1.1       cgd 		continue;
    287   1.1       cgd 	if (c == EOF)
    288   1.1       cgd 		return (0);
    289   1.1       cgd 	cp = tokval;
    290   1.1       cgd 	if (c == '"') {
    291   1.1       cgd 		while ((c = getc(cfile)) != EOF && c != '"') {
    292   1.1       cgd 			if (c == '\\')
    293  1.32     lukem 				if ((c = getc(cfile)) == EOF)
    294  1.32     lukem 					break;
    295   1.1       cgd 			*cp++ = c;
    296  1.32     lukem 			if (cp == tokval + sizeof(tokval)) {
    297  1.32     lukem 				warnx("Token in .netrc too long");
    298  1.32     lukem 				return (-1);
    299  1.32     lukem 			}
    300   1.1       cgd 		}
    301   1.1       cgd 	} else {
    302   1.1       cgd 		*cp++ = c;
    303   1.1       cgd 		while ((c = getc(cfile)) != EOF
    304   1.1       cgd 		    && c != '\n' && c != '\t' && c != ' ' && c != ',') {
    305   1.1       cgd 			if (c == '\\')
    306  1.32     lukem 				if ((c = getc(cfile)) == EOF)
    307  1.32     lukem 					break;
    308   1.1       cgd 			*cp++ = c;
    309  1.32     lukem 			if (cp == tokval + sizeof(tokval)) {
    310  1.32     lukem 				warnx("Token in .netrc too long");
    311  1.32     lukem 				return (-1);
    312  1.32     lukem 			}
    313   1.1       cgd 		}
    314   1.1       cgd 	}
    315   1.1       cgd 	*cp = 0;
    316   1.1       cgd 	if (tokval[0] == 0)
    317   1.1       cgd 		return (0);
    318   1.1       cgd 	for (t = toktab; t->tokstr; t++)
    319   1.1       cgd 		if (!strcmp(t->tokstr, tokval))
    320   1.1       cgd 			return (t->tval);
    321   1.1       cgd 	return (ID);
    322   1.1       cgd }
    323