]> git.cameronkatri.com Git - pw-darwin.git/blobdiff - pw/pwupd.c
Do not expose password if it is empty and PWF_STANDARD format is requested
[pw-darwin.git] / pw / pwupd.c
index baaf102b1c4d8ea540e06790caf0431440e6b79a..84226a90b300b73df246057583e899f485edb68f 100644 (file)
@@ -43,6 +43,7 @@ static const char rcsid[] =
 #include "pwupd.h"
 
 #define HAVE_PWDB_C    1
+#define        HAVE_PWDB_U     1
 
 static char pathpwd[] = _PATH_PWD;
 static char * pwpath = pathpwd;
@@ -110,7 +111,8 @@ fmtpwentry(char *buf, struct passwd * pwd, int type)
        int             l;
        char           *pw;
 
-       pw = (pwd->pw_passwd == NULL || !*pwd->pw_passwd) ? "" : (type == PWF_MASTER) ? pwd->pw_passwd : "*";
+       pw = (type == PWF_MASTER) ?
+           ((pwd->pw_passwd == NULL) ? "" : pwd->pw_passwd) : "*";
 
        if (type == PWF_PASSWD)
                l = sprintf(buf, "%s:*:%ld:%ld:%s:%s:%s\n",
@@ -150,9 +152,12 @@ pw_update(struct passwd * pwd, char const * user, int mode)
 #else
        {                               /* No -C */
 #endif
-               char            pfx[32];
+               char            pfx[PWBUFSZ];
                char            pwbuf[PWBUFSZ];
-               int             l = sprintf(pfx, "%s:", user);
+               int             l = snprintf(pfx, PWBUFSZ, "%s:", user);
+#ifdef HAVE_PWDB_U
+               int             isrename = pwd!=NULL && strcmp(user, pwd->pw_name);
+#endif
 
                /*
                 * Update the passwd file first
@@ -162,6 +167,8 @@ pw_update(struct passwd * pwd, char const * user, int mode)
                else
                        fmtpwentry(pwbuf, pwd, PWF_PASSWD);
 
+               if (l < 0)
+                       l = 0;
                rc = fileupdate(getpwpath(_PASSWD), 0644, pwbuf, pfx, l, mode);
                if (rc == 0) {
 
@@ -170,12 +177,16 @@ pw_update(struct passwd * pwd, char const * user, int mode)
                         */
                        if (pwd != NULL)
                                fmtpwentry(pwbuf, pwd, PWF_MASTER);
-                       rc = fileupdate(getpwpath(_MASTERPASSWD), 0644, pwbuf, pfx, l, mode);
-                       if (rc != 0) {
-                               if (mode == UPD_DELETE)
+                       rc = fileupdate(getpwpath(_MASTERPASSWD), 0600, pwbuf, pfx, l, mode);
+                       if (rc == 0) {
+#ifdef HAVE_PWDB_U
+                               if (mode == UPD_DELETE || isrename)
+#endif
                                        rc = pwdb(NULL);
+#ifdef HAVE_PWDB_U
                                else
                                        rc = pwdb("-u", user, NULL);
+#endif
                        }
                }
        }