Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 1 | /* password.c - password read/update helper functions. |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 2 | * |
| 3 | * Copyright 2012 Ashwini Kumar <ak.ashwini@gmail.com> |
Rob Landley | f033f86 | 2015-05-31 05:11:28 -0500 | [diff] [blame] | 4 | * |
| 5 | * TODO: cleanup |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 6 | */ |
| 7 | |
| 8 | #include "toys.h" |
| 9 | #include <time.h> |
| 10 | |
Rob Landley | 6d15f0d | 2014-06-25 22:54:59 -0500 | [diff] [blame] | 11 | // generate appropriate random salt string for given encryption algorithm. |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 12 | int get_salt(char *salt, char *algo) |
Rob Landley | 2c1cf4a | 2015-01-18 14:06:14 -0600 | [diff] [blame] | 13 | { |
Rob Landley | 6d15f0d | 2014-06-25 22:54:59 -0500 | [diff] [blame] | 14 | struct { |
| 15 | char *type, id, len; |
| 16 | } al[] = {{"des", 0, 2}, {"md5", 1, 8}, {"sha256", 5, 16}, {"sha512", 6, 16}}; |
| 17 | int i; |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 18 | |
Rob Landley | 6d15f0d | 2014-06-25 22:54:59 -0500 | [diff] [blame] | 19 | for (i = 0; i < ARRAY_LEN(al); i++) { |
| 20 | if (!strcmp(algo, al[i].type)) { |
| 21 | int len = al[i].len; |
| 22 | char *s = salt; |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 23 | |
Rob Landley | e0d8009 | 2014-09-26 18:49:44 -0500 | [diff] [blame] | 24 | if (al[i].id) s += sprintf(s, "$%c$", '0'+al[i].id); |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 25 | |
Rob Landley | 6d15f0d | 2014-06-25 22:54:59 -0500 | [diff] [blame] | 26 | // Read appropriate number of random bytes for salt |
Rob Landley | 027a73a | 2016-08-04 10:16:59 -0500 | [diff] [blame] | 27 | i = xopenro("/dev/urandom"); |
Rob Landley | 6d15f0d | 2014-06-25 22:54:59 -0500 | [diff] [blame] | 28 | xreadall(i, libbuf, ((len*6)+7)/8); |
| 29 | close(i); |
Rob Landley | 3403742 | 2013-10-16 20:01:46 -0500 | [diff] [blame] | 30 | |
Rob Landley | 6d15f0d | 2014-06-25 22:54:59 -0500 | [diff] [blame] | 31 | // Grab 6 bit chunks and convert to characters in ./0-9a-zA-Z |
| 32 | for (i=0; i<len; i++) { |
| 33 | int bitpos = i*6, bits = bitpos/8; |
Rob Landley | 3403742 | 2013-10-16 20:01:46 -0500 | [diff] [blame] | 34 | |
Rob Landley | 6d15f0d | 2014-06-25 22:54:59 -0500 | [diff] [blame] | 35 | bits = ((libbuf[i]+(libbuf[i+1]<<8)) >> (bitpos&7)) & 0x3f; |
| 36 | bits += 46; |
| 37 | if (bits > 57) bits += 7; |
| 38 | if (bits > 90) bits += 6; |
Rob Landley | 3403742 | 2013-10-16 20:01:46 -0500 | [diff] [blame] | 39 | |
Rob Landley | 6d15f0d | 2014-06-25 22:54:59 -0500 | [diff] [blame] | 40 | s[i] = bits; |
| 41 | } |
| 42 | salt[len] = 0; |
| 43 | |
| 44 | return s-salt; |
| 45 | } |
Rob Landley | 3403742 | 2013-10-16 20:01:46 -0500 | [diff] [blame] | 46 | } |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 47 | |
Rob Landley | 6d15f0d | 2014-06-25 22:54:59 -0500 | [diff] [blame] | 48 | return -1; |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 49 | } |
| 50 | |
Rob Landley | c0e5ff3 | 2014-06-28 20:02:01 -0500 | [diff] [blame] | 51 | // Prompt with mesg, read password into buf, return 0 for success 1 for fail |
| 52 | int read_password(char *buf, int buflen, char *mesg) |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 53 | { |
Rob Landley | c0e5ff3 | 2014-06-28 20:02:01 -0500 | [diff] [blame] | 54 | struct termios oldtermio; |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 55 | struct sigaction sa, oldsa; |
Rob Landley | c0e5ff3 | 2014-06-28 20:02:01 -0500 | [diff] [blame] | 56 | int i, ret = 1; |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 57 | |
Rob Landley | c0e5ff3 | 2014-06-28 20:02:01 -0500 | [diff] [blame] | 58 | // NOP signal handler to return from the read |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 59 | memset(&sa, 0, sizeof(sa)); |
Rob Landley | c0e5ff3 | 2014-06-28 20:02:01 -0500 | [diff] [blame] | 60 | sa.sa_handler = generic_signal; |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 61 | sigaction(SIGINT, &sa, &oldsa); |
| 62 | |
Rob Landley | c0e5ff3 | 2014-06-28 20:02:01 -0500 | [diff] [blame] | 63 | tcflush(0, TCIFLUSH); |
| 64 | set_terminal(0, 1, &oldtermio); |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 65 | |
Rob Landley | c0e5ff3 | 2014-06-28 20:02:01 -0500 | [diff] [blame] | 66 | xprintf("%s", mesg); |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 67 | |
Rob Landley | c0e5ff3 | 2014-06-28 20:02:01 -0500 | [diff] [blame] | 68 | for (i=0; i < buflen-1; i++) { |
| 69 | if ((ret = read(0, buf+i, 1)) < 0 || (!ret && !i)) { |
| 70 | i = 0; |
| 71 | ret = 1; |
| 72 | |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 73 | break; |
Rob Landley | c0e5ff3 | 2014-06-28 20:02:01 -0500 | [diff] [blame] | 74 | } else if (!ret || buf[i] == '\n' || buf[i] == '\r') { |
| 75 | ret = 0; |
| 76 | |
| 77 | break; |
| 78 | } else if (buf[i] == 8 || buf[i] == 127) i -= i ? 2 : 1; |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 79 | } |
Rob Landley | c0e5ff3 | 2014-06-28 20:02:01 -0500 | [diff] [blame] | 80 | |
| 81 | // Restore terminal/signal state, terminate string |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 82 | sigaction(SIGINT, &oldsa, NULL); |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 83 | tcsetattr(0, TCSANOW, &oldtermio); |
Rob Landley | c0e5ff3 | 2014-06-28 20:02:01 -0500 | [diff] [blame] | 84 | buf[i] = 0; |
| 85 | xputc('\n'); |
| 86 | |
| 87 | return ret; |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 88 | } |
| 89 | |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 90 | static char *get_nextcolon(char *line, int cnt) |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 91 | { |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 92 | while (cnt--) { |
| 93 | if (!(line = strchr(line, ':'))) error_exit("Invalid Entry\n"); |
| 94 | line++; //jump past the colon |
| 95 | } |
| 96 | return line; |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 97 | } |
| 98 | |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 99 | /*update_password is used by multiple utilities to update /etc/passwd, |
Rob Landley | 2c1cf4a | 2015-01-18 14:06:14 -0600 | [diff] [blame] | 100 | * /etc/shadow, /etc/group and /etc/gshadow files, |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 101 | * which are used as user, group databeses |
Rob Landley | 2c1cf4a | 2015-01-18 14:06:14 -0600 | [diff] [blame] | 102 | * entry can be |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 103 | * 1. encrypted password, when updating user password. |
| 104 | * 2. complete entry for user details, when creating new user |
| 105 | * 3. group members comma',' separated list, when adding user to group |
| 106 | * 4. complete entry for group details, when creating new group |
Ashwini Sharma | 656d504 | 2013-12-23 07:23:28 -0600 | [diff] [blame] | 107 | * 5. entry = NULL, delete the named entry user/group |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 108 | */ |
| 109 | int update_password(char *filename, char* username, char* entry) |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 110 | { |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 111 | char *filenamesfx = NULL, *namesfx = NULL, *shadow = NULL, |
| 112 | *sfx = NULL, *line = NULL; |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 113 | FILE *exfp, *newfp; |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 114 | int ret = -1, found = 0; |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 115 | struct flock lock; |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 116 | |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 117 | shadow = strstr(filename, "shadow"); |
Rob Landley | 59d85e2 | 2014-01-16 09:26:50 -0600 | [diff] [blame] | 118 | filenamesfx = xmprintf("%s+", filename); |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 119 | sfx = strchr(filenamesfx, '+'); |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 120 | |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 121 | exfp = fopen(filename, "r+"); |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 122 | if (!exfp) { |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 123 | perror_msg("Couldn't open file %s",filename); |
| 124 | goto free_storage; |
| 125 | } |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 126 | |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 127 | *sfx = '-'; |
Rob Landley | 6e087a3 | 2014-11-11 15:08:25 -0600 | [diff] [blame] | 128 | unlink(filenamesfx); |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 129 | ret = link(filename, filenamesfx); |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 130 | if (ret < 0) error_msg("can't create backup file"); |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 131 | |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 132 | *sfx = '+'; |
| 133 | lock.l_type = F_WRLCK; |
| 134 | lock.l_whence = SEEK_SET; |
| 135 | lock.l_start = 0; |
| 136 | lock.l_len = 0; |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 137 | |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 138 | ret = fcntl(fileno(exfp), F_SETLK, &lock); |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 139 | if (ret < 0) perror_msg("Couldn't lock file %s",filename); |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 140 | |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 141 | lock.l_type = F_UNLCK; //unlocking at a later stage |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 142 | |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 143 | newfp = fopen(filenamesfx, "w+"); |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 144 | if (!newfp) { |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 145 | error_msg("couldn't open file for writing"); |
| 146 | ret = -1; |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 147 | fclose(exfp); |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 148 | goto free_storage; |
| 149 | } |
| 150 | |
| 151 | ret = 0; |
Rob Landley | 59d85e2 | 2014-01-16 09:26:50 -0600 | [diff] [blame] | 152 | namesfx = xmprintf("%s:",username); |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 153 | while ((line = get_line(fileno(exfp))) != NULL) |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 154 | { |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 155 | if (strncmp(line, namesfx, strlen(namesfx))) |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 156 | fprintf(newfp, "%s\n", line); |
Ashwini Sharma | 656d504 | 2013-12-23 07:23:28 -0600 | [diff] [blame] | 157 | else if (entry) { |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 158 | char *current_ptr = NULL; |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 159 | |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 160 | found = 1; |
| 161 | if (!strcmp(toys.which->name, "passwd")) { |
| 162 | fprintf(newfp, "%s%s:",namesfx, entry); |
| 163 | current_ptr = get_nextcolon(line, 2); //past passwd |
| 164 | if (shadow) { |
| 165 | fprintf(newfp, "%u:",(unsigned)(time(NULL))/(24*60*60)); |
| 166 | current_ptr = get_nextcolon(current_ptr, 1); |
| 167 | fprintf(newfp, "%s\n",current_ptr); |
| 168 | } else fprintf(newfp, "%s\n",current_ptr); |
Rob Landley | 2c1cf4a | 2015-01-18 14:06:14 -0600 | [diff] [blame] | 169 | } else if (!strcmp(toys.which->name, "groupadd") || |
Ashwini Sharma | 656d504 | 2013-12-23 07:23:28 -0600 | [diff] [blame] | 170 | !strcmp(toys.which->name, "addgroup") || |
| 171 | !strcmp(toys.which->name, "delgroup") || |
| 172 | !strcmp(toys.which->name, "groupdel")){ |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 173 | current_ptr = get_nextcolon(line, 3); //past gid/admin list |
| 174 | *current_ptr = '\0'; |
| 175 | fprintf(newfp, "%s", line); |
| 176 | fprintf(newfp, "%s\n", entry); |
| 177 | } |
| 178 | } |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 179 | free(line); |
| 180 | } |
| 181 | free(namesfx); |
Ashwini Sharma | 656d504 | 2013-12-23 07:23:28 -0600 | [diff] [blame] | 182 | if (!found && entry) fprintf(newfp, "%s\n", entry); |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 183 | fcntl(fileno(exfp), F_SETLK, &lock); |
| 184 | fclose(exfp); |
| 185 | |
| 186 | errno = 0; |
| 187 | fflush(newfp); |
| 188 | fsync(fileno(newfp)); |
| 189 | fclose(newfp); |
| 190 | rename(filenamesfx, filename); |
Rob Landley | d0f7935 | 2013-10-16 19:30:17 -0500 | [diff] [blame] | 191 | if (errno) { |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 192 | perror_msg("File Writing/Saving failed: "); |
| 193 | unlink(filenamesfx); |
| 194 | ret = -1; |
| 195 | } |
Rob Landley | 2c917f5 | 2012-07-17 08:54:47 -0500 | [diff] [blame] | 196 | |
| 197 | free_storage: |
Rob Landley | 7aa651a | 2012-11-13 17:14:08 -0600 | [diff] [blame] | 198 | free(filenamesfx); |
| 199 | return ret; |
| 200 | } |