1 /*- 2 * Copyright (C) 1996 3 * David L. Nugent. All rights reserved. 4 * 5 * Redistribution and use in source and binary forms, with or without 6 * modification, are permitted provided that the following conditions 7 * are met: 8 * 1. Redistributions of source code must retain the above copyright 9 * notice, this list of conditions and the following disclaimer. 10 * 2. Redistributions in binary form must reproduce the above copyright 11 * notice, this list of conditions and the following disclaimer in the 12 * documentation and/or other materials provided with the distribution. 13 * 14 * THIS SOFTWARE IS PROVIDED BY DAVID L. NUGENT AND CONTRIBUTORS ``AS IS'' AND 15 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 16 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 17 * ARE DISCLAIMED. IN NO EVENT SHALL DAVID L. NUGENT OR CONTRIBUTORS BE LIABLE 18 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 19 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 20 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 21 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 22 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 23 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 24 * SUCH DAMAGE. 25 */ 26 27 #ifndef lint 28 static const char rcsid[] = 29 "$FreeBSD$"; 30 #endif /* not lint */ 31 32 #include <err.h> 33 #include <fcntl.h> 34 #include <locale.h> 35 #include <paths.h> 36 #include <stdbool.h> 37 #include <sys/wait.h> 38 #include "pw.h" 39 40 #if !defined(_PATH_YP) 41 #define _PATH_YP "/var/yp/" 42 #endif 43 const char *Modes[] = { 44 "add", "del", "mod", "show", "next", 45 NULL}; 46 const char *Which[] = {"user", "group", NULL}; 47 static const char *Combo1[] = { 48 "useradd", "userdel", "usermod", "usershow", "usernext", 49 "lock", "unlock", 50 "groupadd", "groupdel", "groupmod", "groupshow", "groupnext", 51 NULL}; 52 static const char *Combo2[] = { 53 "adduser", "deluser", "moduser", "showuser", "nextuser", 54 "lock", "unlock", 55 "addgroup", "delgroup", "modgroup", "showgroup", "nextgroup", 56 NULL}; 57 58 struct pwf PWF = 59 { 60 PWF_REGULAR, 61 setpwent, 62 endpwent, 63 getpwent, 64 getpwuid, 65 getpwnam, 66 setgrent, 67 endgrent, 68 getgrent, 69 getgrgid, 70 getgrnam, 71 72 }; 73 struct pwf VPWF = 74 { 75 PWF_ALT, 76 vsetpwent, 77 vendpwent, 78 vgetpwent, 79 vgetpwuid, 80 vgetpwnam, 81 vsetgrent, 82 vendgrent, 83 vgetgrent, 84 vgetgrgid, 85 vgetgrnam, 86 }; 87 88 struct pwconf conf; 89 90 static struct cargs arglist; 91 92 static int getindex(const char *words[], const char *word); 93 static void cmdhelp(int mode, int which); 94 95 96 int 97 main(int argc, char *argv[]) 98 { 99 int ch; 100 int mode = -1; 101 int which = -1; 102 long id = -1; 103 char *config = NULL; 104 struct stat st; 105 const char *errstr; 106 char arg, *name; 107 bool relocated, nis; 108 109 static const char *opts[W_NUM][M_NUM] = 110 { 111 { /* user */ 112 "R:V:C:qn:u:c:d:e:p:g:G:mM:k:s:oL:i:w:h:H:Db:NPy:Y", 113 "R:V:C:qn:u:rY", 114 "R:V:C:qn:u:c:d:e:p:g:G:mM:l:k:s:w:L:h:H:FNPY", 115 "R:V:C:qn:u:FPa7", 116 "R:V:C:q", 117 "R:V:C:q", 118 "R:V:C:q" 119 }, 120 { /* grp */ 121 "R:V:C:qn:g:h:H:M:opNPY", 122 "R:V:C:qn:g:Y", 123 "R:V:C:qn:d:g:l:h:H:FM:m:NPY", 124 "R:V:C:qn:g:FPa", 125 "R:V:C:q" 126 } 127 }; 128 129 static int (*funcs[W_NUM]) (int _mode, char *_name, long _id, 130 struct cargs * _args) = 131 { /* Request handlers */ 132 pw_user, 133 pw_group 134 }; 135 136 name = NULL; 137 relocated = nis = false; 138 memset(&conf, 0, sizeof(conf)); 139 strlcpy(conf.etcpath, _PATH_PWD, sizeof(conf.etcpath)); 140 conf.fd = -1; 141 142 LIST_INIT(&arglist); 143 144 (void)setlocale(LC_ALL, ""); 145 146 /* 147 * Break off the first couple of words to determine what exactly 148 * we're being asked to do 149 */ 150 while (argc > 1) { 151 int tmp; 152 153 if (*argv[1] == '-') { 154 /* 155 * Special case, allow pw -V<dir> <operation> [args] for scripts etc. 156 */ 157 arg = argv[1][1]; 158 if (arg == 'V' || arg == 'R') { 159 if (relocated) 160 errx(EXIT_FAILURE, "Both '-R' and '-V' " 161 "specified, only one accepted"); 162 relocated = true; 163 optarg = &argv[1][2]; 164 if (*optarg == '\0') { 165 if (stat(argv[2], &st) != 0) 166 errx(EX_OSFILE, \ 167 "no such directory `%s'", 168 argv[2]); 169 if (!S_ISDIR(st.st_mode)) 170 errx(EX_OSFILE, "`%s' not a " 171 "directory", argv[2]); 172 optarg = argv[2]; 173 ++argv; 174 --argc; 175 } 176 memcpy(&PWF, &VPWF, sizeof PWF); 177 if (arg == 'R') { 178 strlcpy(conf.rootdir, optarg, 179 sizeof(conf.rootdir)); 180 PWF._altdir = PWF_ROOTDIR; 181 } 182 snprintf(conf.etcpath, sizeof(conf.etcpath), 183 "%s%s", optarg, arg == 'R' ? "/etc" : ""); 184 } else 185 break; 186 } 187 else if (mode == -1 && (tmp = getindex(Modes, argv[1])) != -1) 188 mode = tmp; 189 else if (which == -1 && (tmp = getindex(Which, argv[1])) != -1) 190 which = tmp; 191 else if ((mode == -1 && which == -1) && 192 ((tmp = getindex(Combo1, argv[1])) != -1 || 193 (tmp = getindex(Combo2, argv[1])) != -1)) { 194 which = tmp / M_NUM; 195 mode = tmp % M_NUM; 196 } else if (strcmp(argv[1], "help") == 0 && argv[2] == NULL) 197 cmdhelp(mode, which); 198 else if (which != -1 && mode != -1) { 199 if (strspn(argv[1], "0123456789") == strlen(argv[1])) { 200 id = strtonum(argv[1], 0, LONG_MAX, &errstr); 201 if (errstr != NULL) 202 errx(EX_USAGE, "Bad id '%s': %s", 203 argv[1], errstr); 204 } else 205 name = argv[1]; 206 } else 207 errx(EX_USAGE, "unknown keyword `%s'", argv[1]); 208 ++argv; 209 --argc; 210 } 211 212 /* 213 * Bail out unless the user is specific! 214 */ 215 if (mode == -1 || which == -1) 216 cmdhelp(mode, which); 217 218 /* 219 * We know which mode we're in and what we're about to do, so now 220 * let's dispatch the remaining command line args in a genric way. 221 */ 222 optarg = NULL; 223 224 while ((ch = getopt(argc, argv, opts[which][mode])) != -1) { 225 switch (ch) { 226 case '?': 227 errx(EX_USAGE, "unknown switch"); 228 break; 229 case '7': 230 conf.v7 = true; 231 break; 232 case 'C': 233 conf.config = optarg; 234 config = conf.config; 235 break; 236 case 'N': 237 conf.dryrun = true; 238 break; 239 case 'l': 240 if (strlen(optarg) >= MAXLOGNAME) 241 errx(EX_USAGE, "new name too long: %s", optarg); 242 conf.newname = optarg; 243 break; 244 case 'P': 245 conf.pretty = true; 246 break; 247 case 'Y': 248 nis = true; 249 break; 250 case 'g': 251 if (which == 0) { /* for user* */ 252 addarg(&arglist, 'g', optarg); 253 break; 254 } 255 if (strspn(optarg, "0123456789") != strlen(optarg)) 256 errx(EX_USAGE, "-g expects a number"); 257 id = strtonum(optarg, 0, LONG_MAX, &errstr); 258 if (errstr != NULL) 259 errx(EX_USAGE, "Bad id '%s': %s", optarg, 260 errstr); 261 break; 262 case 'u': 263 if (strspn(optarg, "0123456789,") != strlen(optarg)) 264 errx(EX_USAGE, "-u expects a number"); 265 if (strchr(optarg, ',') != NULL) { 266 addarg(&arglist, 'u', optarg); 267 break; 268 } 269 id = strtonum(optarg, 0, LONG_MAX, &errstr); 270 if (errstr != NULL) 271 errx(EX_USAGE, "Bad id '%s': %s", optarg, 272 errstr); 273 break; 274 case 'n': 275 if (strspn(optarg, "0123456789") != strlen(optarg)) { 276 name = optarg; 277 break; 278 } 279 id = strtonum(optarg, 0, LONG_MAX, &errstr); 280 if (errstr != NULL) 281 errx(EX_USAGE, "Bad id '%s': %s", optarg, 282 errstr); 283 break; 284 case 'H': 285 if (conf.fd != -1) 286 errx(EX_USAGE, "'-h' and '-H' are mutually " 287 "exclusive options"); 288 conf.precrypted = true; 289 if (strspn(optarg, "0123456789") != strlen(optarg)) 290 errx(EX_USAGE, "'-H' expects a file descriptor"); 291 292 conf.fd = strtonum(optarg, 0, INT_MAX, &errstr); 293 if (errstr != NULL) 294 errx(EX_USAGE, "Bad file descriptor '%s': %s", 295 optarg, errstr); 296 break; 297 case 'h': 298 if (conf.fd != -1) 299 errx(EX_USAGE, "'-h' and '-H' are mutually " 300 "exclusive options"); 301 302 if (strcmp(optarg, "-") == 0) 303 conf.fd = '-'; 304 else if (strspn(optarg, "0123456789") == strlen(optarg)) { 305 conf.fd = strtonum(optarg, 0, INT_MAX, &errstr); 306 if (errstr != NULL) 307 errx(EX_USAGE, "'-h' expects a " 308 "file descriptor or '-'"); 309 } else 310 errx(EX_USAGE, "'-h' expects a file " 311 "descriptor or '-'"); 312 break; 313 case 'o': 314 conf.checkduplicate = true; 315 break; 316 default: 317 addarg(&arglist, ch, optarg); 318 break; 319 } 320 optarg = NULL; 321 } 322 323 if (name != NULL && strlen(name) >= MAXLOGNAME) 324 errx(EX_USAGE, "name too long: %s", name); 325 326 /* 327 * Must be root to attempt an update 328 */ 329 if (geteuid() != 0 && mode != M_PRINT && mode != M_NEXT && !conf.dryrun) 330 errx(EX_NOPERM, "you must be root to run this program"); 331 332 /* 333 * We should immediately look for the -q 'quiet' switch so that we 334 * don't bother with extraneous errors 335 */ 336 if (getarg(&arglist, 'q') != NULL) 337 freopen(_PATH_DEVNULL, "w", stderr); 338 339 /* 340 * Set our base working path if not overridden 341 */ 342 343 if (config == NULL) { /* Only override config location if -C not specified */ 344 asprintf(&config, "%s/pw.conf", conf.etcpath); 345 if (config == NULL) 346 errx(EX_OSERR, "out of memory"); 347 } 348 349 /* 350 * Now, let's do the common initialisation 351 */ 352 conf.userconf = read_userconfig(config); 353 354 ch = funcs[which] (mode, name, id, &arglist); 355 356 /* 357 * If everything went ok, and we've been asked to update 358 * the NIS maps, then do it now 359 */ 360 if (ch == EXIT_SUCCESS && nis) { 361 pid_t pid; 362 363 fflush(NULL); 364 if (chdir(_PATH_YP) == -1) 365 warn("chdir(" _PATH_YP ")"); 366 else if ((pid = fork()) == -1) 367 warn("fork()"); 368 else if (pid == 0) { 369 /* Is make anywhere else? */ 370 execlp("/usr/bin/make", "make", (char *)NULL); 371 _exit(1); 372 } else { 373 int i; 374 waitpid(pid, &i, 0); 375 if ((i = WEXITSTATUS(i)) != 0) 376 errx(ch, "make exited with status %d", i); 377 else 378 pw_log(conf.userconf, mode, which, "NIS maps updated"); 379 } 380 } 381 return ch; 382 } 383 384 385 static int 386 getindex(const char *words[], const char *word) 387 { 388 int i = 0; 389 390 while (words[i]) { 391 if (strcmp(words[i], word) == 0) 392 return i; 393 i++; 394 } 395 return -1; 396 } 397 398 399 /* 400 * This is probably an overkill for a cmdline help system, but it reflects 401 * the complexity of the command line. 402 */ 403 404 static void 405 cmdhelp(int mode, int which) 406 { 407 if (which == -1) 408 fprintf(stderr, "usage:\n pw [user|group|lock|unlock] [add|del|mod|show|next] [help|switches/values]\n"); 409 else if (mode == -1) 410 fprintf(stderr, "usage:\n pw %s [add|del|mod|show|next] [help|switches/values]\n", Which[which]); 411 else { 412 413 /* 414 * We need to give mode specific help 415 */ 416 static const char *help[W_NUM][M_NUM] = 417 { 418 { 419 "usage: pw useradd [name] [switches]\n" 420 "\t-V etcdir alternate /etc location\n" 421 "\t-R rootir alternate root directory\n" 422 "\t-C config configuration file\n" 423 "\t-q quiet operation\n" 424 " Adding users:\n" 425 "\t-n name login name\n" 426 "\t-u uid user id\n" 427 "\t-c comment user name/comment\n" 428 "\t-d directory home directory\n" 429 "\t-e date account expiry date\n" 430 "\t-p date password expiry date\n" 431 "\t-g grp initial group\n" 432 "\t-G grp1,grp2 additional groups\n" 433 "\t-m [ -k dir ] create and set up home\n" 434 "\t-M mode home directory permissions\n" 435 "\t-s shell name of login shell\n" 436 "\t-o duplicate uid ok\n" 437 "\t-L class user class\n" 438 "\t-h fd read password on fd\n" 439 "\t-H fd read encrypted password on fd\n" 440 "\t-Y update NIS maps\n" 441 "\t-N no update\n" 442 " Setting defaults:\n" 443 "\t-V etcdir alternate /etc location\n" 444 "\t-R rootir alternate root directory\n" 445 "\t-D set user defaults\n" 446 "\t-b dir default home root dir\n" 447 "\t-e period default expiry period\n" 448 "\t-p period default password change period\n" 449 "\t-g group default group\n" 450 "\t-G grp1,grp2 additional groups\n" 451 "\t-L class default user class\n" 452 "\t-k dir default home skeleton\n" 453 "\t-M mode home directory permissions\n" 454 "\t-u min,max set min,max uids\n" 455 "\t-i min,max set min,max gids\n" 456 "\t-w method set default password method\n" 457 "\t-s shell default shell\n" 458 "\t-y path set NIS passwd file path\n", 459 "usage: pw userdel [uid|name] [switches]\n" 460 "\t-V etcdir alternate /etc location\n" 461 "\t-R rootir alternate root directory\n" 462 "\t-n name login name\n" 463 "\t-u uid user id\n" 464 "\t-Y update NIS maps\n" 465 "\t-r remove home & contents\n", 466 "usage: pw usermod [uid|name] [switches]\n" 467 "\t-V etcdir alternate /etc location\n" 468 "\t-R rootir alternate root directory\n" 469 "\t-C config configuration file\n" 470 "\t-q quiet operation\n" 471 "\t-F force add if no user\n" 472 "\t-n name login name\n" 473 "\t-u uid user id\n" 474 "\t-c comment user name/comment\n" 475 "\t-d directory home directory\n" 476 "\t-e date account expiry date\n" 477 "\t-p date password expiry date\n" 478 "\t-g grp initial group\n" 479 "\t-G grp1,grp2 additional groups\n" 480 "\t-l name new login name\n" 481 "\t-L class user class\n" 482 "\t-m [ -k dir ] create and set up home\n" 483 "\t-M mode home directory permissions\n" 484 "\t-s shell name of login shell\n" 485 "\t-w method set new password using method\n" 486 "\t-h fd read password on fd\n" 487 "\t-H fd read encrypted password on fd\n" 488 "\t-Y update NIS maps\n" 489 "\t-N no update\n", 490 "usage: pw usershow [uid|name] [switches]\n" 491 "\t-V etcdir alternate /etc location\n" 492 "\t-R rootir alternate root directory\n" 493 "\t-n name login name\n" 494 "\t-u uid user id\n" 495 "\t-F force print\n" 496 "\t-P prettier format\n" 497 "\t-a print all users\n" 498 "\t-7 print in v7 format\n", 499 "usage: pw usernext [switches]\n" 500 "\t-V etcdir alternate /etc location\n" 501 "\t-R rootir alternate root directory\n" 502 "\t-C config configuration file\n" 503 "\t-q quiet operation\n", 504 "usage pw: lock [switches]\n" 505 "\t-V etcdir alternate /etc locations\n" 506 "\t-C config configuration file\n" 507 "\t-q quiet operation\n", 508 "usage pw: unlock [switches]\n" 509 "\t-V etcdir alternate /etc locations\n" 510 "\t-C config configuration file\n" 511 "\t-q quiet operation\n" 512 }, 513 { 514 "usage: pw groupadd [group|gid] [switches]\n" 515 "\t-V etcdir alternate /etc location\n" 516 "\t-R rootir alternate root directory\n" 517 "\t-C config configuration file\n" 518 "\t-q quiet operation\n" 519 "\t-n group group name\n" 520 "\t-g gid group id\n" 521 "\t-M usr1,usr2 add users as group members\n" 522 "\t-o duplicate gid ok\n" 523 "\t-Y update NIS maps\n" 524 "\t-N no update\n", 525 "usage: pw groupdel [group|gid] [switches]\n" 526 "\t-V etcdir alternate /etc location\n" 527 "\t-R rootir alternate root directory\n" 528 "\t-n name group name\n" 529 "\t-g gid group id\n" 530 "\t-Y update NIS maps\n", 531 "usage: pw groupmod [group|gid] [switches]\n" 532 "\t-V etcdir alternate /etc location\n" 533 "\t-R rootir alternate root directory\n" 534 "\t-C config configuration file\n" 535 "\t-q quiet operation\n" 536 "\t-F force add if not exists\n" 537 "\t-n name group name\n" 538 "\t-g gid group id\n" 539 "\t-M usr1,usr2 replaces users as group members\n" 540 "\t-m usr1,usr2 add users as group members\n" 541 "\t-d usr1,usr2 delete users as group members\n" 542 "\t-l name new group name\n" 543 "\t-Y update NIS maps\n" 544 "\t-N no update\n", 545 "usage: pw groupshow [group|gid] [switches]\n" 546 "\t-V etcdir alternate /etc location\n" 547 "\t-R rootir alternate root directory\n" 548 "\t-n name group name\n" 549 "\t-g gid group id\n" 550 "\t-F force print\n" 551 "\t-P prettier format\n" 552 "\t-a print all accounting groups\n", 553 "usage: pw groupnext [switches]\n" 554 "\t-V etcdir alternate /etc location\n" 555 "\t-R rootir alternate root directory\n" 556 "\t-C config configuration file\n" 557 "\t-q quiet operation\n" 558 } 559 }; 560 561 fprintf(stderr, "%s", help[which][mode]); 562 } 563 exit(EXIT_FAILURE); 564 } 565 566 struct carg * 567 getarg(struct cargs * _args, int ch) 568 { 569 struct carg *c = LIST_FIRST(_args); 570 571 while (c != NULL && c->ch != ch) 572 c = LIST_NEXT(c, list); 573 return c; 574 } 575 576 struct carg * 577 addarg(struct cargs * _args, int ch, char *argstr) 578 { 579 struct carg *ca = malloc(sizeof(struct carg)); 580 581 if (ca == NULL) 582 errx(EX_OSERR, "out of memory"); 583 ca->ch = ch; 584 ca->val = argstr; 585 LIST_INSERT_HEAD(_args, ca, list); 586 return ca; 587 } 588