/
niceSOFT
/
shadow
Обзор
Документация
Войти
/
niceSOFT
/
shadow
Код
Задачи
Вики
Пакеты
0
Релизы
0
Аналитика
Безопасность
master
src/grpconv.c
279 строк
7 KB
Alejandro Colomar
lib/, src/: Use eprintf() instead of its pattern
20 июл 2026, 16:43
20 июл 2026, 16:43
8534fc5
Код
Авторство
О чём код?
/* * SPDX-FileCopyrightText: 1996 - 2000, Marek Michałkiewicz * SPDX-FileCopyrightText: 2002 - 2006, Tomasz Kłoczko * SPDX-FileCopyrightText: 2011 , Nicolas François * * SPDX-License-Identifier: BSD-3-Clause */ /* * grpconv - create or update /etc/gshadow with information from * /etc/group. * */ #include "config.h" #ident "$Id$" #include <errno.h> #include <fcntl.h> #include <getopt.h> #include <grp.h> #include <stdio.h> #include <stdlib.h> #include <string.h> #include <strings.h> #include <time.h> #include <unistd.h> #include "attr.h" /*@-exitarg@*/ #include "exitcodes.h" #include "io/fprintf.h" #include "nscd.h" #include "prototypes.h" #include "string/strcmp/streq.h" #ifdef SHADOWGRP #include "groupio.h" #include "sgroupio.h" #include "shadow/gshadow/sgrp.h" #include "shadowlog.h" #include "sssd.h" /* * Structures */ struct option_flags { bool chroot; }; /* * Global variables */ static const char Prog[] = "grpconv"; static bool gr_locked = false; static bool sgr_locked = false; /* local function prototypes */ static void fail_exit (int status, bool process_selinux); static void usage (int status); static void process_flags (int argc, char **argv, struct option_flags *flags); static void fail_exit (int status, bool process_selinux) { if (gr_locked) { if (gr_unlock (process_selinux) == 0) { eprintf(_("%s: failed to unlock %s\n"), Prog, gr_dbname()); SYSLOG(LOG_ERR, "failed to unlock %s", gr_dbname()); /* continue */ } } if (sgr_locked) { if (sgr_unlock (process_selinux) == 0) { eprintf(_("%s: failed to unlock %s\n"), Prog, sgr_dbname()); SYSLOG(LOG_ERR, "failed to unlock %s", sgr_dbname()); /* continue */ } } exit (status); } static void usage (int status) { FILE *usageout = (E_SUCCESS != status) ? stderr : stdout; (void) fprintf (usageout, _("Usage: %s [options]\n" "\n" "Options:\n"), Prog); (void) fputs (_(" -h, --help display this help message and exit\n"), usageout); (void) fputs (_(" -R, --root CHROOT_DIR directory to chroot into\n"), usageout); (void) fputs ("\n", usageout); exit (status); } /* * process_flags - parse the command line options * * It will not return if an error is encountered. */ static void process_flags (int argc, char **argv, struct option_flags *flags) { /* * Parse the command line options. */ int c; static struct option long_options[] = { {"help", no_argument, NULL, 'h'}, {"root", required_argument, NULL, 'R'}, {NULL, 0, NULL, '\0'} }; while ((c = getopt_long (argc, argv, "hR:", long_options, NULL)) != -1) { switch (c) { case 'h': usage (E_SUCCESS); /*@notreached@*/break; case 'R': /* no-op, handled in process_root_flag () */ flags->chroot = true; break; default: usage (E_USAGE); } } if (optind != argc) { usage (E_USAGE); } } int main (int argc, char **argv) { const struct group *gr; struct group grent; const struct sgrp *sg; struct sgrp sgent; struct option_flags flags = {.chroot = false}; bool process_selinux; log_set_progname(Prog); log_set_logfd(stderr); (void) setlocale (LC_ALL, ""); (void) bindtextdomain (PACKAGE, LOCALEDIR); (void) textdomain (PACKAGE); process_root_flag ("-R", argc, argv); OPENLOG (Prog); process_flags (argc, argv, &flags); process_selinux = !flags.chroot; if (gr_lock () == 0) { eprintf(_("%s: cannot lock %s; try again later.\n"), Prog, gr_dbname ()); fail_exit (5, process_selinux); } gr_locked = true; if (gr_open (O_CREAT | O_RDWR) == 0) { eprintf(_("%s: cannot open %s\n"), Prog, gr_dbname()); fail_exit (1, process_selinux); } if (sgr_lock () == 0) { eprintf(_("%s: cannot lock %s; try again later.\n"), Prog, sgr_dbname ()); fail_exit (5, process_selinux); } sgr_locked = true; if (sgr_open (O_CREAT | O_RDWR) == 0) { eprintf(_("%s: cannot open %s\n"), Prog, sgr_dbname()); fail_exit (1, process_selinux); } /* * Remove /etc/gshadow entries for groups not in /etc/group. */ (void) sgr_rewind (); while (NULL != (sg = sgr_next())) { if (gr_locate (sg->sg_namp) != NULL) { continue; } if (sgr_remove (sg->sg_namp) == 0) { /* * This shouldn't happen (the entry exists) but... */ eprintf(_("%s: cannot remove entry '%s' from %s\n"), Prog, sg->sg_namp, sgr_dbname ()); fail_exit (3, process_selinux); } (void) sgr_rewind (); } /* * Update shadow group passwords if non-shadow password is not "x". * Add any missing shadow group entries. */ (void) gr_rewind (); while ((gr = gr_next ()) != NULL) { sg = sgr_locate (gr->gr_name); if (NULL != sg) { /* update existing shadow group entry */ sgent = *sg; if (!streq(gr->gr_passwd, SHADOW_PASSWD_STRING)) sgent.sg_passwd = gr->gr_passwd; } else { static char *empty = NULL; /* add new shadow group entry */ bzero(&sgent, sizeof(sgent)); sgent.sg_namp = gr->gr_name; sgent.sg_passwd = gr->gr_passwd; sgent.sg_adm = ∅ } /* * XXX - sg_mem is redundant, it is currently always a copy * of gr_mem. Very few programs actually use sg_mem, and all * of them are in the shadow suite. Maybe this field could * be used for something else? Any suggestions? */ sgent.sg_mem = gr->gr_mem; if (sgr_update (&sgent) == 0) { eprintf(_("%s: failed to prepare the new %s entry '%s'\n"), Prog, sgr_dbname (), sgent.sg_namp); fail_exit (3, process_selinux); } /* remove password from /etc/group */ grent = *gr; grent.gr_passwd = SHADOW_PASSWD_STRING; /* XXX warning: const */ if (gr_update (&grent) == 0) { eprintf(_("%s: failed to prepare the new %s entry '%s'\n"), Prog, gr_dbname (), grent.gr_name); fail_exit (3, process_selinux); } } if (sgr_close (process_selinux) == 0) { eprintf(_("%s: failure while writing changes to %s\n"), Prog, sgr_dbname ()); SYSLOG(LOG_ERR, "failure while writing changes to %s", sgr_dbname()); fail_exit (3, process_selinux); } if (gr_close (process_selinux) == 0) { eprintf(_("%s: failure while writing changes to %s\n"), Prog, gr_dbname ()); SYSLOG(LOG_ERR, "failure while writing changes to %s", gr_dbname()); fail_exit (3, process_selinux); } if (sgr_unlock (process_selinux) == 0) { eprintf(_("%s: failed to unlock %s\n"), Prog, sgr_dbname()); SYSLOG(LOG_ERR, "failed to unlock %s", sgr_dbname()); /* continue */ } if (gr_unlock (process_selinux) == 0) { eprintf(_("%s: failed to unlock %s\n"), Prog, gr_dbname()); SYSLOG(LOG_ERR, "failed to unlock %s", gr_dbname()); /* continue */ } nscd_flush_cache ("group"); sssd_flush_cache (SSSD_DB_GROUP); return 0; } #else /* !SHADOWGRP */ int main(MAYBE_UNUSED int _1, char **argv) { eprintf("%s: not configured for shadow group support.\n", argv[0]); exit (1); } #endif /* !SHADOWGRP */