* lib/tcbfuncs.h: Added type shadowtcb_status.

* lib/tcbfuncs.h, lib/tcbfuncs.c: Return a shadowtcb_status
	instead of an int.
	* lib/tcbfuncs.c: Do not return in OUT_OF_MEMORY.
This commit is contained in:
nekral-guest 2010-03-17 23:59:55 +00:00
parent fe71812b1d
commit 8acf9cd11d
3 changed files with 84 additions and 56 deletions

View File

@ -1,3 +1,10 @@
2010-03-17 Nicolas François <nicolas.francois@centraliens.net>
* lib/tcbfuncs.h: Added type shadowtcb_status.
* lib/tcbfuncs.h, lib/tcbfuncs.c: Return a shadowtcb_status
instead of an int.
* lib/tcbfuncs.c: Do not return in OUT_OF_MEMORY.
2010-03-17 Nicolas François <nicolas.francois@centraliens.net> 2010-03-17 Nicolas François <nicolas.francois@centraliens.net>
* lib/commonio.c: Avoid implicit conversion of pointers to * lib/commonio.c: Avoid implicit conversion of pointers to

View File

@ -34,28 +34,29 @@
#include "defines.h" #include "defines.h"
#include "getdef.h" #include "getdef.h"
#include "tcbfuncs.h"
#define SHADOWTCB_HASH_BY 1000 #define SHADOWTCB_HASH_BY 1000
#define SHADOWTCB_LOCK_SUFFIX ".lock" #define SHADOWTCB_LOCK_SUFFIX ".lock"
static char *stored_tcb_user = NULL; static char *stored_tcb_user = NULL;
int shadowtcb_drop_priv() shadowtcb_status shadowtcb_drop_priv()
{ {
if (!getdef_bool("USE_TCB")) if (!getdef_bool("USE_TCB"))
return 1; return SHADOWTCB_SUCCESS;
if (stored_tcb_user) if (stored_tcb_user)
return !tcb_drop_priv(stored_tcb_user); return (tcb_drop_priv(stored_tcb_user) == 0) ? SHADOWTCB_SUCCESS : SHADOWTCB_FAILURE;
return 0; return SHADOWTCB_FAILURE;
} }
int shadowtcb_gain_priv() shadowtcb_status shadowtcb_gain_priv()
{ {
if (!getdef_bool("USE_TCB")) if (!getdef_bool("USE_TCB"))
return 1; return SHADOWTCB_SUCCESS;
return !tcb_gain_priv(); return (tcb_gain_priv() == 0) ? SHADOWTCB_SUCCESS : SHADOWTCB_FAILURE;
} }
/* In case something goes wrong, we return immediately, not polluting the /* In case something goes wrong, we return immediately, not polluting the
@ -65,7 +66,6 @@ int shadowtcb_gain_priv()
#define OUT_OF_MEMORY do { \ #define OUT_OF_MEMORY do { \
fprintf(stderr, _("%s: out of memory\n"), Prog); \ fprintf(stderr, _("%s: out of memory\n"), Prog); \
fflush(stderr); \ fflush(stderr); \
return 0; \
} while(0) } while(0)
/* Returns user's tcb directory path relative to TCB_DIR. */ /* Returns user's tcb directory path relative to TCB_DIR. */
@ -85,6 +85,7 @@ static char *shadowtcb_path_rel(const char *name, uid_t uid)
} }
if (!ret) { if (!ret) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return NULL;
} }
return ret; return ret;
} }
@ -99,6 +100,7 @@ static char *shadowtcb_path_rel_existing(const char *name)
asprintf(&path, TCB_DIR "/%s", name); asprintf(&path, TCB_DIR "/%s", name);
if (!path) { if (!path) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return NULL;
} }
if (lstat(path, &st)) { if (lstat(path, &st)) {
fprintf(stderr, _("%s: Cannot stat %s: %s\n"), Prog, path, strerror(errno)); fprintf(stderr, _("%s: Cannot stat %s: %s\n"), Prog, path, strerror(errno));
@ -110,6 +112,7 @@ static char *shadowtcb_path_rel_existing(const char *name)
rval = strdup(name); rval = strdup(name);
if (!rval) { if (!rval) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return NULL;
} }
return rval; return rval;
} }
@ -133,6 +136,7 @@ static char *shadowtcb_path_rel_existing(const char *name)
rval = strdup(link); rval = strdup(link);
if (!rval) { if (!rval) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return NULL;
} }
return rval; return rval;
} }
@ -147,6 +151,7 @@ static char *shadowtcb_path(const char *name, uid_t uid)
free(rel); free(rel);
if (!ret) { if (!ret) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return NULL;
} }
return ret; return ret;
} }
@ -161,17 +166,18 @@ static char *shadowtcb_path_existing(const char *name)
free(rel); free(rel);
if (!ret) { if (!ret) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return NULL;
} }
return ret; return ret;
} }
static int mkdir_leading(const char *name, uid_t uid) static shadowtcb_status mkdir_leading(const char *name, uid_t uid)
{ {
char *ind, *dir, *ptr, *path = shadowtcb_path_rel(name, uid); char *ind, *dir, *ptr, *path = shadowtcb_path_rel(name, uid);
struct stat st; struct stat st;
if (!path) if (!path)
return 0; return SHADOWTCB_FAILURE;
ptr = path; ptr = path;
if (stat(TCB_DIR, &st)) { if (stat(TCB_DIR, &st)) {
fprintf(stderr, _("%s: Cannot stat %s: %s\n"), Prog, TCB_DIR, strerror(errno)); fprintf(stderr, _("%s: Cannot stat %s: %s\n"), Prog, TCB_DIR, strerror(errno));
@ -182,6 +188,7 @@ static int mkdir_leading(const char *name, uid_t uid)
asprintf(&dir, TCB_DIR "/%s", path); asprintf(&dir, TCB_DIR "/%s", path);
if (!dir) { if (!dir) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return SHADOWTCB_FAILURE;
} }
if (mkdir(dir, 0700) && errno != EEXIST) { if (mkdir(dir, 0700) && errno != EEXIST) {
fprintf(stderr, _("%s: Cannot create directory %s: %s\n"), Prog, dir, strerror(errno)); fprintf(stderr, _("%s: Cannot create directory %s: %s\n"), Prog, dir, strerror(errno));
@ -200,15 +207,15 @@ static int mkdir_leading(const char *name, uid_t uid)
ptr = ind + 1; ptr = ind + 1;
} }
free(path); free(path);
return 1; return SHADOWTCB_SUCCESS;
out_free_dir: out_free_dir:
free(dir); free(dir);
out_free_path: out_free_path:
free(path); free(path);
return 0; return SHADOWTCB_FAILURE;
} }
static int unlink_suffs(const char *user) static shadowtcb_status unlink_suffs(const char *user)
{ {
static char *suffs[] = { "+", "-", SHADOWTCB_LOCK_SUFFIX }; static char *suffs[] = { "+", "-", SHADOWTCB_LOCK_SUFFIX };
char *tmp; char *tmp;
@ -218,33 +225,35 @@ static int unlink_suffs(const char *user)
asprintf(&tmp, TCB_FMT "%s", user, suffs[i]); asprintf(&tmp, TCB_FMT "%s", user, suffs[i]);
if (!tmp) { if (!tmp) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return SHADOWTCB_FAILURE;
} }
if (unlink(tmp) && errno != ENOENT) { if (unlink(tmp) && errno != ENOENT) {
fprintf(stderr, _("%s: unlink: %s: %s\n"), Prog, tmp, strerror(errno)); fprintf(stderr, _("%s: unlink: %s: %s\n"), Prog, tmp, strerror(errno));
free(tmp); free(tmp);
return 0; return SHADOWTCB_FAILURE;
} }
free(tmp); free(tmp);
} }
return 1; return SHADOWTCB_SUCCESS;
} }
/* path should be a relative existing tcb directory */ /* path should be a relative existing tcb directory */
static int rmdir_leading(char *path) static shadowtcb_status rmdir_leading(char *path)
{ {
char *ind, *dir; char *ind, *dir;
int ret = 1; shadowtcb_status ret = SHADOWTCB_SUCCESS;
while ((ind = strrchr(path, '/'))) { while ((ind = strrchr(path, '/'))) {
*ind = 0; *ind = 0;
asprintf(&dir, TCB_DIR "/%s", path); asprintf(&dir, TCB_DIR "/%s", path);
if (!dir) { if (!dir) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return SHADOWTCB_FAILURE;
} }
if (rmdir(dir)) { if (rmdir(dir)) {
if (errno != ENOTEMPTY) { if (errno != ENOTEMPTY) {
fprintf(stderr, _("%s: Cannot removedirectory %s: %s\n"), Prog, dir, strerror(errno)); fprintf(stderr, _("%s: Cannot removedirectory %s: %s\n"), Prog, dir, strerror(errno));
ret = 0; ret = SHADOWTCB_FAILURE;
} }
free(dir); free(dir);
break; break;
@ -254,14 +263,14 @@ static int rmdir_leading(char *path)
return ret; return ret;
} }
static int move_dir(const char *user_newname, uid_t user_newid) static shadowtcb_status move_dir(const char *user_newname, uid_t user_newid)
{ {
char *olddir = NULL, *newdir = NULL; char *olddir = NULL, *newdir = NULL;
char *real_old_dir = NULL, *real_new_dir = NULL; char *real_old_dir = NULL, *real_new_dir = NULL;
char *real_old_dir_rel = NULL, *real_new_dir_rel = NULL; char *real_old_dir_rel = NULL, *real_new_dir_rel = NULL;
uid_t old_uid, the_newid; uid_t old_uid, the_newid;
struct stat oldmode; struct stat oldmode;
int ret = 0; shadowtcb_status ret = SHADOWTCB_FAILURE;
asprintf(&olddir, TCB_DIR "/%s", stored_tcb_user); asprintf(&olddir, TCB_DIR "/%s", stored_tcb_user);
if (!olddir) if (!olddir)
@ -277,18 +286,18 @@ static int move_dir(const char *user_newname, uid_t user_newid)
if (!(real_new_dir = shadowtcb_path(user_newname, the_newid))) if (!(real_new_dir = shadowtcb_path(user_newname, the_newid)))
goto out_free; goto out_free;
if (!strcmp(real_old_dir, real_new_dir)) { if (!strcmp(real_old_dir, real_new_dir)) {
ret = 1; ret = SHADOWTCB_SUCCESS;
goto out_free; goto out_free;
} }
if (!(real_old_dir_rel = shadowtcb_path_rel_existing(stored_tcb_user))) if (!(real_old_dir_rel = shadowtcb_path_rel_existing(stored_tcb_user)))
goto out_free; goto out_free;
if (!mkdir_leading(user_newname, the_newid)) if (mkdir_leading(user_newname, the_newid) == SHADOWTCB_FAILURE)
goto out_free; goto out_free;
if (rename(real_old_dir, real_new_dir)) { if (rename(real_old_dir, real_new_dir)) {
fprintf(stderr, _("%s: Cannot rename %s to %s: %s\n"), Prog, real_old_dir, real_new_dir, strerror(errno)); fprintf(stderr, _("%s: Cannot rename %s to %s: %s\n"), Prog, real_old_dir, real_new_dir, strerror(errno));
goto out_free; goto out_free;
} }
if (!rmdir_leading(real_old_dir_rel)) if (rmdir_leading(real_old_dir_rel) == SHADOWTCB_FAILURE)
goto out_free; goto out_free;
if (unlink(olddir) && errno != ENOENT) { if (unlink(olddir) && errno != ENOENT) {
fprintf(stderr, _("%s: Cannot remove %s: %s\n"), Prog, olddir, strerror(errno)); fprintf(stderr, _("%s: Cannot remove %s: %s\n"), Prog, olddir, strerror(errno));
@ -303,11 +312,10 @@ static int move_dir(const char *user_newname, uid_t user_newid)
fprintf(stderr, _("%s: Cannot create symbolic link %s: %s\n"), Prog, real_new_dir_rel, strerror(errno)); fprintf(stderr, _("%s: Cannot create symbolic link %s: %s\n"), Prog, real_new_dir_rel, strerror(errno));
goto out_free; goto out_free;
} }
ret = 1; ret = SHADOWTCB_SUCCESS;
goto out_free; goto out_free;
out_free_nomem: out_free_nomem:
fprintf(stderr, _("%s: out of memory\n"), Prog); \ OUT_OF_MEMORY;
fflush(stderr);
out_free: out_free:
free(olddir); free(olddir);
free(newdir); free(newdir);
@ -318,13 +326,13 @@ out_free:
return ret; return ret;
} }
int shadowtcb_set_user(const char* name) shadowtcb_status shadowtcb_set_user(const char* name)
{ {
char *buf; char *buf;
int retval; shadowtcb_status retval;
if (!getdef_bool("USE_TCB")) if (!getdef_bool("USE_TCB"))
return 1; return SHADOWTCB_SUCCESS;
if (stored_tcb_user) if (stored_tcb_user)
free(stored_tcb_user); free(stored_tcb_user);
@ -336,53 +344,56 @@ int shadowtcb_set_user(const char* name)
asprintf(&buf, TCB_FMT, name); asprintf(&buf, TCB_FMT, name);
if (!buf) { if (!buf) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return SHADOWTCB_FAILURE;
} }
retval = spw_setdbname(buf); retval = (spw_setdbname(buf) != 0) ? SHADOWTCB_SUCCESS : SHADOWTCB_FAILURE;
free(buf); free(buf);
return retval; return retval;
} }
/* tcb directory must be empty before shadowtcb_remove is called. */ /* tcb directory must be empty before shadowtcb_remove is called. */
int shadowtcb_remove(const char *name) shadowtcb_status shadowtcb_remove(const char *name)
{ {
int ret = 1; shadowtcb_status ret = SHADOWTCB_SUCCESS;
char *path = shadowtcb_path_existing(name); char *path = shadowtcb_path_existing(name);
char *rel = shadowtcb_path_rel_existing(name); char *rel = shadowtcb_path_rel_existing(name);
if (!path || !rel || rmdir(path)) if (!path || !rel || rmdir(path))
return 0; return SHADOWTCB_FAILURE;
if (!rmdir_leading(rel)) if (rmdir_leading(rel) == SHADOWTCB_FAILURE)
return 0; return SHADOWTCB_FAILURE;
free(path); free(path);
free(rel); free(rel);
asprintf(&path, TCB_DIR "/%s", name); asprintf(&path, TCB_DIR "/%s", name);
if (!path) { if (!path) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return SHADOWTCB_FAILURE;
} }
if (unlink(path) && errno != ENOENT) if (unlink(path) && errno != ENOENT)
ret = 0; ret = SHADOWTCB_FAILURE;
free(path); free(path);
return ret; return ret;
} }
int shadowtcb_move(const char *user_newname, uid_t user_newid) shadowtcb_status shadowtcb_move(const char *user_newname, uid_t user_newid)
{ {
struct stat dirmode, filemode; struct stat dirmode, filemode;
char *tcbdir, *shadow; char *tcbdir, *shadow;
int ret = 0; shadowtcb_status ret = SHADOWTCB_FAILURE;
if (!getdef_bool("USE_TCB")) if (!getdef_bool("USE_TCB"))
return 1; return SHADOWTCB_SUCCESS;
if (!user_newname) if (!user_newname)
user_newname = stored_tcb_user; user_newname = stored_tcb_user;
if (!move_dir(user_newname, user_newid)) if (move_dir(user_newname, user_newid) == SHADOWTCB_FAILURE)
return 0; return SHADOWTCB_FAILURE;
if (user_newid == -1) if (user_newid == -1)
return 1; return SHADOWTCB_SUCCESS;
asprintf(&tcbdir, TCB_DIR "/%s", user_newname); asprintf(&tcbdir, TCB_DIR "/%s", user_newname);
asprintf(&shadow, TCB_FMT, user_newname); asprintf(&shadow, TCB_FMT, user_newname);
if (!tcbdir || !shadow) { if (!tcbdir || !shadow) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return SHADOWTCB_FAILURE;
} }
if (stat(tcbdir, &dirmode)) { if (stat(tcbdir, &dirmode)) {
fprintf(stderr, _("%s: Cannot stat %s: %s\n"), Prog, tcbdir, strerror(errno)); fprintf(stderr, _("%s: Cannot stat %s: %s\n"), Prog, tcbdir, strerror(errno));
@ -423,32 +434,33 @@ int shadowtcb_move(const char *user_newname, uid_t user_newid)
goto out_free; goto out_free;
} }
} }
if (!unlink_suffs(user_newname)) if (unlink_suffs(user_newname) == SHADOWTCB_FAILURE)
goto out_free; goto out_free;
if (chown(tcbdir, user_newid, dirmode.st_gid)) { if (chown(tcbdir, user_newid, dirmode.st_gid)) {
fprintf(stderr, _("%s: Cannot change owner of %s: %s\n"), Prog, tcbdir, strerror(errno)); fprintf(stderr, _("%s: Cannot change owner of %s: %s\n"), Prog, tcbdir, strerror(errno));
goto out_free; goto out_free;
} }
ret = 1; ret = SHADOWTCB_SUCCESS;
out_free: out_free:
free(tcbdir); free(tcbdir);
free(shadow); free(shadow);
return ret; return ret;
} }
int shadowtcb_create(const char *name, uid_t uid) shadowtcb_status shadowtcb_create(const char *name, uid_t uid)
{ {
char *dir, *shadow; char *dir, *shadow;
struct stat tcbdir_stat; struct stat tcbdir_stat;
gid_t shadowgid, authgid; gid_t shadowgid, authgid;
struct group *gr; struct group *gr;
int fd, ret = 0; int fd;
shadowtcb_status ret = SHADOWTCB_FAILURE;
if (!getdef_bool("USE_TCB")) if (!getdef_bool("USE_TCB"))
return 1; return SHADOWTCB_SUCCESS;
if (stat(TCB_DIR, &tcbdir_stat)) { if (stat(TCB_DIR, &tcbdir_stat)) {
fprintf(stderr, _("%s: Cannot stat %s: %s\n"), Prog, tcbdir, strerror(errno)); fprintf(stderr, _("%s: Cannot stat %s: %s\n"), Prog, tcbdir, strerror(errno));
return 0; return SHADOWTCB_FAILURE;
} }
shadowgid = tcbdir_stat.st_gid; shadowgid = tcbdir_stat.st_gid;
if (getdef_bool("TCB_AUTH_GROUP") && if (getdef_bool("TCB_AUTH_GROUP") &&
@ -462,6 +474,7 @@ int shadowtcb_create(const char *name, uid_t uid)
asprintf(&shadow, TCB_FMT, name); asprintf(&shadow, TCB_FMT, name);
if (!dir || !shadow) { if (!dir || !shadow) {
OUT_OF_MEMORY; OUT_OF_MEMORY;
return SHADOWTCB_FAILURE;
} }
if (mkdir(dir, 0700)) { if (mkdir(dir, 0700)) {
fprintf(stderr, _("%s: mkdir: %s: %s\n"), Prog, dir, strerror(errno)); fprintf(stderr, _("%s: mkdir: %s: %s\n"), Prog, dir, strerror(errno));
@ -490,11 +503,13 @@ int shadowtcb_create(const char *name, uid_t uid)
fprintf(stderr, _("%s: Cannot change mode of %s: %s\n"), Prog, dir, strerror(errno)); fprintf(stderr, _("%s: Cannot change mode of %s: %s\n"), Prog, dir, strerror(errno));
goto out_free; goto out_free;
} }
if (!shadowtcb_set_user(name) || !shadowtcb_move(NULL, uid)) if ( (shadowtcb_set_user(name) == SHADOWTCB_FAILURE)
|| (shadowtcb_move(NULL, uid) == SHADOWTCB_FAILURE))
goto out_free; goto out_free;
ret = 1; ret = SHADOWTCB_SUCCESS;
out_free: out_free:
free(dir); free(dir);
free(shadow); free(shadow);
return ret; return ret;
} }

View File

@ -3,11 +3,17 @@
#include <sys/types.h> #include <sys/types.h>
extern int shadowtcb_drop_priv(); typedef enum {
extern int shadowtcb_gain_priv(); SHADOWTCB_FAILURE = 0,
extern int shadowtcb_set_user(const char *name); SHADOWTCB_SUCCESS = 1
extern int shadowtcb_remove(const char *name); } shadowtcb_status;
extern int shadowtcb_move(const char *user_newname, uid_t user_newid);
extern int shadowtcb_create(const char *name, uid_t uid); extern shadowtcb_status shadowtcb_drop_priv();
extern shadowtcb_status shadowtcb_gain_priv();
extern shadowtcb_status shadowtcb_set_user(const char *name);
extern shadowtcb_status shadowtcb_remove(const char *name);
extern shadowtcb_status shadowtcb_move(/*@null@*/const char *user_newname,
uid_t user_newid);
extern shadowtcb_status shadowtcb_create(const char *name, uid_t uid);
#endif #endif