]> git.cameronkatri.com Git - pw-darwin.git/blobdiff - libutil/pw_util.c
It was possible for an unprivileged user to tie up the password
[pw-darwin.git] / libutil / pw_util.c
index d005d1610696e6cd397fa406b27226cadee8332c..2c082e4286f8b30aa51508806678b8a9f8fad302 100644 (file)
@@ -36,7 +36,7 @@
 static const char sccsid[] = "@(#)pw_util.c    8.3 (Berkeley) 4/2/94";
 #endif
 static const char rcsid[] =
-       "$Id: pw_util.c,v 1.9 1997/10/27 07:53:19 charnier Exp $";
+  "$FreeBSD$";
 #endif /* not lint */
 
 /*
@@ -45,6 +45,7 @@ static const char rcsid[] =
  */
 
 #include <sys/param.h>
+#include <sys/errno.h>
 #include <sys/time.h>
 #include <sys/resource.h>
 #include <sys/stat.h>
@@ -65,10 +66,14 @@ static const char rcsid[] =
 extern char *tempname;
 static pid_t editpid = -1;
 static int lockfd;
+static char _default_editor[] = _PATH_VI;
+char mppath[] = _PATH_PWD;
+char masterpasswd[] = _PATH_MASTERPASSWD;
+
+void            pw_cont(int);
 
 void
-pw_cont(sig)
-       int sig;
+pw_cont(int sig)
 {
 
        if (editpid != -1)
@@ -76,7 +81,7 @@ pw_cont(sig)
 }
 
 void
-pw_init()
+pw_init(void)
 {
        struct rlimit rlim;
 
@@ -106,7 +111,7 @@ pw_init()
 }
 
 int
-pw_lock()
+pw_lock(void)
 {
        /*
         * If the master password file doesn't exist, the system is hosed.
@@ -114,21 +119,40 @@ pw_lock()
         * that users can't get at the encrypted passwords while editing.
         * Open should allow flock'ing the file; see 4.4BSD.    XXX
         */
-       lockfd = open(_PATH_MASTERPASSWD, O_RDONLY, 0);
-       if (lockfd < 0 || fcntl(lockfd, F_SETFD, 1) == -1)
-               err(1, "%s", _PATH_MASTERPASSWD);
-       if (flock(lockfd, LOCK_EX|LOCK_NB))
-               errx(1, "the password db file is busy");
+       for (;;) {
+               struct stat st;
+
+               lockfd = open(masterpasswd, O_RDONLY, 0);
+               if (lockfd < 0 || fcntl(lockfd, F_SETFD, 1) == -1)
+                       err(1, "%s", masterpasswd);
+               if (flock(lockfd, LOCK_EX|LOCK_NB))
+                       errx(1, "the password db file is busy");
+
+               /*
+                * If the password file was replaced while we were trying to
+                * get the lock, our hardlink count will be 0 and we have to
+                * close and retry.
+                */
+               if (fstat(lockfd, &st) < 0)
+                       errx(1, "fstat() failed");
+               if (st.st_nlink != 0)
+                       break;
+               close(lockfd);
+               lockfd = -1;
+       }
        return (lockfd);
 }
 
 int
-pw_tmp()
+pw_tmp(void)
 {
-       static char path[MAXPATHLEN] = _PATH_MASTERPASSWD;
+       static char path[MAXPATHLEN];
        int fd;
        char *p;
 
+       strncpy(path, masterpasswd, MAXPATHLEN - 1);
+       path[MAXPATHLEN] = '\0';
+
        if ((p = strrchr(path, '/')))
                ++p;
        else
@@ -141,8 +165,7 @@ pw_tmp()
 }
 
 int
-pw_mkdb(username)
-char *username;
+pw_mkdb(const char *username)
 {
        int pstat;
        pid_t pid;
@@ -151,11 +174,12 @@ char *username;
        if (!(pid = fork())) {
                if(!username) {
                        warnx("rebuilding the database...");
-                       execl(_PATH_PWD_MKDB, "pwd_mkdb", "-p", tempname, NULL);
+                       execl(_PATH_PWD_MKDB, "pwd_mkdb", "-p", "-d", mppath,
+                           tempname, (char *)NULL);
                } else {
                        warnx("updating the database...");
-                       execl(_PATH_PWD_MKDB, "pwd_mkdb", "-p", "-u", 
-                                       username, tempname, NULL);
+                       execl(_PATH_PWD_MKDB, "pwd_mkdb", "-p", "-d", mppath,
+                           "-u", username, tempname, (char *)NULL);
                }
                pw_error(_PATH_PWD_MKDB, 1, 1);
        }
@@ -167,14 +191,13 @@ char *username;
 }
 
 void
-pw_edit(notsetuid)
-       int notsetuid;
+pw_edit(int notsetuid)
 {
        int pstat;
        char *p, *editor;
 
        if (!(editor = getenv("EDITOR")))
-               editor = _PATH_VI;
+               editor = _default_editor;
        if ((p = strrchr(editor, '/')))
                ++p;
        else
@@ -185,16 +208,18 @@ pw_edit(notsetuid)
                        (void)setgid(getgid());
                        (void)setuid(getuid());
                }
-               execlp(editor, p, tempname, NULL);
-               _exit(1);
+               errno = 0;
+               execlp(editor, p, tempname, (char *)NULL);
+               _exit(errno);
        }
        for (;;) {
                editpid = waitpid(editpid, (int *)&pstat, WUNTRACED);
+               errno = WEXITSTATUS(pstat);
                if (editpid == -1)
                        pw_error(editor, 1, 1);
                else if (WIFSTOPPED(pstat))
                        raise(WSTOPSIG(pstat));
-               else if (WIFEXITED(pstat) && WEXITSTATUS(pstat) == 0)
+               else if (WIFEXITED(pstat) && errno == 0)
                        break;
                else
                        pw_error(editor, 1, 1);
@@ -203,7 +228,7 @@ pw_edit(notsetuid)
 }
 
 void
-pw_prompt()
+pw_prompt(void)
 {
        int c, first;
 
@@ -217,21 +242,23 @@ pw_prompt()
 }
 
 void
-pw_error(name, err, eval)
-       char *name;
-       int err, eval;
+pw_error(const char *name, int error, int eval)
 {
 #ifdef YP
        extern int _use_yp;
 #endif /* YP */
-       if (err)
-               warn(name);
+       if (error) {
+               if (name != NULL)
+                       warn("%s", name);
+               else
+                       warn(NULL);
+       }
 #ifdef YP
        if (_use_yp)
                warnx("NIS information unchanged");
        else
 #endif /* YP */
-       warnx("%s: unchanged", _PATH_MASTERPASSWD);
+       warnx("%s: unchanged", masterpasswd);
        (void)unlink(tempname);
        exit(eval);
 }