1 1.35 christos /* $NetBSD: ruserpass.c,v 1.35 2024/10/04 18:04:06 christos Exp $ */ 2 1.6 tls 3 1.1 cgd /* 4 1.3 cgd * Copyright (c) 1985, 1993, 1994 5 1.3 cgd * The Regents of the University of California. All rights reserved. 6 1.1 cgd * 7 1.1 cgd * Redistribution and use in source and binary forms, with or without 8 1.1 cgd * modification, are permitted provided that the following conditions 9 1.1 cgd * are met: 10 1.1 cgd * 1. Redistributions of source code must retain the above copyright 11 1.1 cgd * notice, this list of conditions and the following disclaimer. 12 1.1 cgd * 2. Redistributions in binary form must reproduce the above copyright 13 1.1 cgd * notice, this list of conditions and the following disclaimer in the 14 1.1 cgd * documentation and/or other materials provided with the distribution. 15 1.29 agc * 3. Neither the name of the University nor the names of its contributors 16 1.1 cgd * may be used to endorse or promote products derived from this software 17 1.1 cgd * without specific prior written permission. 18 1.1 cgd * 19 1.1 cgd * THIS SOFTWARE IS PROVIDED BY THE REGENTS AND CONTRIBUTORS ``AS IS'' AND 20 1.1 cgd * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 21 1.1 cgd * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 22 1.1 cgd * ARE DISCLAIMED. IN NO EVENT SHALL THE REGENTS OR CONTRIBUTORS BE LIABLE 23 1.1 cgd * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 24 1.1 cgd * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 25 1.1 cgd * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 26 1.1 cgd * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 27 1.1 cgd * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 28 1.1 cgd * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 29 1.1 cgd * SUCH DAMAGE. 30 1.1 cgd */ 31 1.1 cgd 32 1.14 lukem #include <sys/cdefs.h> 33 1.1 cgd #ifndef lint 34 1.11 lukem #if 0 35 1.6 tls static char sccsid[] = "@(#)ruserpass.c 8.4 (Berkeley) 4/27/95"; 36 1.11 lukem #else 37 1.35 christos __RCSID("$NetBSD: ruserpass.c,v 1.35 2024/10/04 18:04:06 christos Exp $"); 38 1.11 lukem #endif 39 1.1 cgd #endif /* not lint */ 40 1.1 cgd 41 1.1 cgd #include <sys/types.h> 42 1.3 cgd #include <sys/stat.h> 43 1.3 cgd 44 1.1 cgd #include <ctype.h> 45 1.3 cgd #include <err.h> 46 1.1 cgd #include <errno.h> 47 1.21 lukem #include <netdb.h> 48 1.3 cgd #include <stdio.h> 49 1.3 cgd #include <stdlib.h> 50 1.3 cgd #include <string.h> 51 1.3 cgd #include <unistd.h> 52 1.3 cgd 53 1.1 cgd #include "ftp_var.h" 54 1.1 cgd 55 1.26 lukem static int token(void); 56 1.1 cgd static FILE *cfile; 57 1.1 cgd 58 1.1 cgd #define DEFAULT 1 59 1.1 cgd #define LOGIN 2 60 1.1 cgd #define PASSWD 3 61 1.25 lukem #define ACCOUNT 4 62 1.25 lukem #define MACDEF 5 63 1.1 cgd #define ID 10 64 1.1 cgd #define MACH 11 65 1.1 cgd 66 1.1 cgd static char tokval[100]; 67 1.1 cgd 68 1.1 cgd static struct toktab { 69 1.30 lukem const char *tokstr; 70 1.1 cgd int tval; 71 1.17 lukem } toktab[] = { 72 1.3 cgd { "default", DEFAULT }, 73 1.3 cgd { "login", LOGIN }, 74 1.3 cgd { "password", PASSWD }, 75 1.3 cgd { "passwd", PASSWD }, 76 1.3 cgd { "account", ACCOUNT }, 77 1.3 cgd { "machine", MACH }, 78 1.3 cgd { "macdef", MACDEF }, 79 1.3 cgd { NULL, 0 } 80 1.1 cgd }; 81 1.1 cgd 82 1.35 christos static int 83 1.35 christos match_host_domain(const char *host, const char *domain, const char *tokv) 84 1.35 christos { 85 1.35 christos const char *tmp; 86 1.35 christos 87 1.35 christos if (strcasecmp(host, tokval) == 0) 88 1.35 christos return 1; 89 1.35 christos 90 1.35 christos return (tmp = strchr(host, '.')) != NULL && 91 1.35 christos strcasecmp(tmp, domain) == 0 && 92 1.35 christos strncasecmp(host, tokv, tmp - host) == 0 && 93 1.35 christos tokv[tmp - host] == '\0'; 94 1.35 christos } 95 1.35 christos 96 1.3 cgd int 97 1.30 lukem ruserpass(const char *host, char **aname, char **apass, char **aacct) 98 1.1 cgd { 99 1.28 lukem char *tmp; 100 1.30 lukem const char *mydomain; 101 1.30 lukem char myname[MAXHOSTNAMELEN + 1]; 102 1.1 cgd int t, i, c, usedefault = 0; 103 1.1 cgd struct stat stb; 104 1.1 cgd 105 1.28 lukem if (netrc[0] == '\0') 106 1.8 lukem return (0); 107 1.28 lukem cfile = fopen(netrc, "r"); 108 1.1 cgd if (cfile == NULL) { 109 1.1 cgd if (errno != ENOENT) 110 1.33 lukem warn("Can't read `%s'", netrc); 111 1.3 cgd return (0); 112 1.1 cgd } 113 1.1 cgd if (gethostname(myname, sizeof(myname)) < 0) 114 1.1 cgd myname[0] = '\0'; 115 1.18 mrg myname[sizeof(myname) - 1] = '\0'; 116 1.3 cgd if ((mydomain = strchr(myname, '.')) == NULL) 117 1.1 cgd mydomain = ""; 118 1.27 lukem next: 119 1.32 lukem while ((t = token()) > 0) switch(t) { 120 1.1 cgd 121 1.1 cgd case DEFAULT: 122 1.1 cgd usedefault = 1; 123 1.1 cgd /* FALL THROUGH */ 124 1.1 cgd 125 1.1 cgd case MACH: 126 1.1 cgd if (!usedefault) { 127 1.32 lukem if ((t = token()) == -1) 128 1.32 lukem goto bad; 129 1.32 lukem if (t != ID) 130 1.1 cgd continue; 131 1.1 cgd /* 132 1.1 cgd * Allow match either for user's input host name 133 1.7 lukem * or official hostname. Also allow match of 134 1.1 cgd * incompletely-specified host in local domain. 135 1.1 cgd */ 136 1.35 christos if (match_host_domain(hostname, mydomain, tokval)) 137 1.1 cgd goto match; 138 1.35 christos if (match_host_domain(host, mydomain, tokval)) 139 1.1 cgd goto match; 140 1.1 cgd continue; 141 1.1 cgd } 142 1.1 cgd match: 143 1.32 lukem while ((t = token()) > 0 && 144 1.32 lukem t != MACH && t != DEFAULT) switch(t) { 145 1.1 cgd 146 1.1 cgd case LOGIN: 147 1.32 lukem if ((t = token()) == -1) 148 1.32 lukem goto bad; 149 1.32 lukem if (t) { 150 1.20 lukem if (*aname == NULL) 151 1.31 christos *aname = ftp_strdup(tokval); 152 1.20 lukem else { 153 1.1 cgd if (strcmp(*aname, tokval)) 154 1.1 cgd goto next; 155 1.1 cgd } 156 1.16 christos } 157 1.1 cgd break; 158 1.1 cgd case PASSWD: 159 1.6 tls if ((*aname == NULL || strcmp(*aname, "anonymous")) && 160 1.1 cgd fstat(fileno(cfile), &stb) >= 0 && 161 1.1 cgd (stb.st_mode & 077) != 0) { 162 1.33 lukem warnx("Error: .netrc file is readable by others"); 163 1.33 lukem warnx("Remove password or make file unreadable by others"); 164 1.1 cgd goto bad; 165 1.1 cgd } 166 1.32 lukem if ((t = token()) == -1) 167 1.32 lukem goto bad; 168 1.32 lukem if (t && *apass == NULL) 169 1.31 christos *apass = ftp_strdup(tokval); 170 1.1 cgd break; 171 1.1 cgd case ACCOUNT: 172 1.1 cgd if (fstat(fileno(cfile), &stb) >= 0 173 1.1 cgd && (stb.st_mode & 077) != 0) { 174 1.33 lukem warnx("Error: .netrc file is readable by others"); 175 1.33 lukem warnx("Remove account or make file unreadable by others"); 176 1.1 cgd goto bad; 177 1.1 cgd } 178 1.32 lukem if ((t = token()) == -1) 179 1.32 lukem goto bad; 180 1.32 lukem if (t && *aacct == NULL) 181 1.31 christos *aacct = ftp_strdup(tokval); 182 1.1 cgd break; 183 1.1 cgd case MACDEF: 184 1.1 cgd if (proxy) { 185 1.12 lukem (void)fclose(cfile); 186 1.3 cgd return (0); 187 1.1 cgd } 188 1.17 lukem while ((c = getc(cfile)) != EOF) 189 1.11 lukem if (c != ' ' && c != '\t') 190 1.11 lukem break; 191 1.1 cgd if (c == EOF || c == '\n') { 192 1.17 lukem fputs("Missing macdef name argument.\n", 193 1.17 lukem ttyout); 194 1.1 cgd goto bad; 195 1.1 cgd } 196 1.1 cgd if (macnum == 16) { 197 1.17 lukem fputs( 198 1.17 lukem "Limit of 16 macros have already been defined.\n", 199 1.17 lukem ttyout); 200 1.1 cgd goto bad; 201 1.1 cgd } 202 1.1 cgd tmp = macros[macnum].mac_name; 203 1.1 cgd *tmp++ = c; 204 1.17 lukem for (i = 0; i < 8 && (c = getc(cfile)) != EOF && 205 1.1 cgd !isspace(c); ++i) { 206 1.1 cgd *tmp++ = c; 207 1.1 cgd } 208 1.1 cgd if (c == EOF) { 209 1.17 lukem fputs( 210 1.17 lukem "Macro definition missing null line terminator.\n", 211 1.17 lukem ttyout); 212 1.1 cgd goto bad; 213 1.1 cgd } 214 1.1 cgd *tmp = '\0'; 215 1.1 cgd if (c != '\n') { 216 1.17 lukem while ((c = getc(cfile)) != EOF && c != '\n'); 217 1.1 cgd } 218 1.1 cgd if (c == EOF) { 219 1.17 lukem fputs( 220 1.17 lukem "Macro definition missing null line terminator.\n", 221 1.17 lukem ttyout); 222 1.1 cgd goto bad; 223 1.1 cgd } 224 1.1 cgd if (macnum == 0) { 225 1.1 cgd macros[macnum].mac_start = macbuf; 226 1.1 cgd } 227 1.1 cgd else { 228 1.9 lukem macros[macnum].mac_start = 229 1.9 lukem macros[macnum-1].mac_end + 1; 230 1.1 cgd } 231 1.1 cgd tmp = macros[macnum].mac_start; 232 1.1 cgd while (tmp != macbuf + 4096) { 233 1.17 lukem if ((c = getc(cfile)) == EOF) { 234 1.17 lukem fputs( 235 1.17 lukem "Macro definition missing null line terminator.\n", 236 1.17 lukem ttyout); 237 1.1 cgd goto bad; 238 1.1 cgd } 239 1.1 cgd *tmp = c; 240 1.1 cgd if (*tmp == '\n') { 241 1.32 lukem if (tmp == macros[macnum].mac_start) { 242 1.32 lukem macros[macnum++].mac_end = tmp; 243 1.32 lukem break; 244 1.32 lukem } else if (*(tmp - 1) == '\0') { 245 1.32 lukem macros[macnum++].mac_end = 246 1.32 lukem tmp - 1; 247 1.32 lukem break; 248 1.1 cgd } 249 1.1 cgd *tmp = '\0'; 250 1.1 cgd } 251 1.1 cgd tmp++; 252 1.1 cgd } 253 1.1 cgd if (tmp == macbuf + 4096) { 254 1.34 lukem fputs("4 KiB macro buffer exceeded.\n", 255 1.17 lukem ttyout); 256 1.1 cgd goto bad; 257 1.1 cgd } 258 1.1 cgd break; 259 1.1 cgd default: 260 1.33 lukem warnx("Unknown .netrc keyword `%s'", tokval); 261 1.1 cgd break; 262 1.1 cgd } 263 1.1 cgd goto done; 264 1.1 cgd } 265 1.27 lukem done: 266 1.32 lukem if (t == -1) 267 1.32 lukem goto bad; 268 1.12 lukem (void)fclose(cfile); 269 1.3 cgd return (0); 270 1.27 lukem bad: 271 1.12 lukem (void)fclose(cfile); 272 1.3 cgd return (-1); 273 1.1 cgd } 274 1.1 cgd 275 1.3 cgd static int 276 1.26 lukem token(void) 277 1.1 cgd { 278 1.1 cgd char *cp; 279 1.1 cgd int c; 280 1.1 cgd struct toktab *t; 281 1.1 cgd 282 1.3 cgd if (feof(cfile) || ferror(cfile)) 283 1.1 cgd return (0); 284 1.1 cgd while ((c = getc(cfile)) != EOF && 285 1.1 cgd (c == '\n' || c == '\t' || c == ' ' || c == ',')) 286 1.1 cgd continue; 287 1.1 cgd if (c == EOF) 288 1.1 cgd return (0); 289 1.1 cgd cp = tokval; 290 1.1 cgd if (c == '"') { 291 1.1 cgd while ((c = getc(cfile)) != EOF && c != '"') { 292 1.1 cgd if (c == '\\') 293 1.32 lukem if ((c = getc(cfile)) == EOF) 294 1.32 lukem break; 295 1.1 cgd *cp++ = c; 296 1.32 lukem if (cp == tokval + sizeof(tokval)) { 297 1.32 lukem warnx("Token in .netrc too long"); 298 1.32 lukem return (-1); 299 1.32 lukem } 300 1.1 cgd } 301 1.1 cgd } else { 302 1.1 cgd *cp++ = c; 303 1.1 cgd while ((c = getc(cfile)) != EOF 304 1.1 cgd && c != '\n' && c != '\t' && c != ' ' && c != ',') { 305 1.1 cgd if (c == '\\') 306 1.32 lukem if ((c = getc(cfile)) == EOF) 307 1.32 lukem break; 308 1.1 cgd *cp++ = c; 309 1.32 lukem if (cp == tokval + sizeof(tokval)) { 310 1.32 lukem warnx("Token in .netrc too long"); 311 1.32 lukem return (-1); 312 1.32 lukem } 313 1.1 cgd } 314 1.1 cgd } 315 1.1 cgd *cp = 0; 316 1.1 cgd if (tokval[0] == 0) 317 1.1 cgd return (0); 318 1.1 cgd for (t = toktab; t->tokstr; t++) 319 1.1 cgd if (!strcmp(t->tokstr, tokval)) 320 1.1 cgd return (t->tval); 321 1.1 cgd return (ID); 322 1.1 cgd } 323