version 1.1.1.2, 2012/05/29 12:26:49
|
version 1.1.1.5, 2013/10/14 07:56:35
|
Line 1
|
Line 1
|
/* |
/* |
* Copyright (c) 1996, 1998-2005, 2007-2012 | * Copyright (c) 1996, 1998-2005, 2007-2013 |
* Todd C. Miller <Todd.Miller@courtesan.com> |
* Todd C. Miller <Todd.Miller@courtesan.com> |
* |
* |
* Permission to use, copy, modify, and distribute this software for any |
* Permission to use, copy, modify, and distribute this software for any |
Line 25
|
Line 25
|
|
|
#include <config.h> |
#include <config.h> |
|
|
#include <sys/param.h> |
|
#include <sys/types.h> |
#include <sys/types.h> |
#include <sys/stat.h> |
#include <sys/stat.h> |
#include <sys/socket.h> |
#include <sys/socket.h> |
Line 59
|
Line 58
|
#include <errno.h> |
#include <errno.h> |
#include <netinet/in.h> |
#include <netinet/in.h> |
#include <arpa/inet.h> |
#include <arpa/inet.h> |
#include <netdb.h> |
|
#ifdef HAVE_SETLOCALE |
|
# include <locale.h> |
|
#endif |
|
|
|
#include "tsgetgrpw.h" |
#include "tsgetgrpw.h" |
#include "sudoers.h" |
#include "sudoers.h" |
#include "interfaces.h" |
#include "interfaces.h" |
#include "parse.h" |
#include "parse.h" |
#include "sudo_conf.h" |
#include "sudo_conf.h" |
|
#include "secure_path.h" |
#include <gram.h> |
#include <gram.h> |
|
|
/* |
/* |
Line 80 void print_defaults(void);
|
Line 76 void print_defaults(void);
|
void print_privilege(struct privilege *); |
void print_privilege(struct privilege *); |
void print_userspecs(void); |
void print_userspecs(void); |
void usage(void) __attribute__((__noreturn__)); |
void usage(void) __attribute__((__noreturn__)); |
void cleanup(int); |
|
static void set_runaspw(const char *); |
static void set_runaspw(const char *); |
static void set_runasgr(const char *); |
static void set_runasgr(const char *); |
static int cb_runas_default(const char *); |
static int cb_runas_default(const char *); |
static int testsudoers_printf(int msg_type, const char *fmt, ...); |
|
static int testsudoers_print(const char *msg); |
static int testsudoers_print(const char *msg); |
|
|
extern void setgrfile(const char *); |
extern void setgrfile(const char *); |
Line 105 extern int (*trace_print)(const char *msg);
|
Line 99 extern int (*trace_print)(const char *msg);
|
/* |
/* |
* Globals |
* Globals |
*/ |
*/ |
struct interface *interfaces; |
|
struct sudo_user sudo_user; |
struct sudo_user sudo_user; |
struct passwd *list_pw; |
struct passwd *list_pw; |
static char *runas_group, *runas_user; |
static char *runas_group, *runas_user; |
extern int errorlineno; |
extern int errorlineno; |
extern bool parse_error; |
extern bool parse_error; |
extern char *errorfile; |
extern char *errorfile; |
sudo_printf_t sudo_printf = testsudoers_printf; |
|
sudo_conv_t sudo_conv; /* NULL in non-plugin */ |
|
|
|
/* For getopt(3) */ |
/* For getopt(3) */ |
extern char *optarg; |
extern char *optarg; |
Line 123 extern int optind;
|
Line 114 extern int optind;
|
extern char *malloc_options; |
extern char *malloc_options; |
#endif |
#endif |
#ifdef YYDEBUG |
#ifdef YYDEBUG |
extern int yydebug; | extern int sudoersdebug; |
#endif |
#endif |
|
|
|
__dso_public int main(int argc, char *argv[]); |
|
|
int |
int |
main(int argc, char *argv[]) |
main(int argc, char *argv[]) |
{ |
{ |
Line 133 main(int argc, char *argv[])
|
Line 126 main(int argc, char *argv[])
|
struct privilege *priv; |
struct privilege *priv; |
struct userspec *us; |
struct userspec *us; |
char *p, *grfile, *pwfile; |
char *p, *grfile, *pwfile; |
char hbuf[MAXHOSTNAMELEN + 1]; | char hbuf[HOST_NAME_MAX + 1]; |
int match, host_match, runas_match, cmnd_match; |
int match, host_match, runas_match, cmnd_match; |
int ch, dflag, exitcode = 0; |
int ch, dflag, exitcode = 0; |
debug_decl(main, SUDO_DEBUG_MAIN) |
debug_decl(main, SUDO_DEBUG_MAIN) |
Line 142 main(int argc, char *argv[])
|
Line 135 main(int argc, char *argv[])
|
malloc_options = "AFGJPR"; |
malloc_options = "AFGJPR"; |
#endif |
#endif |
#ifdef YYDEBUG |
#ifdef YYDEBUG |
yydebug = 1; | sudoersdebug = 1; |
#endif |
#endif |
|
|
#if !defined(HAVE_GETPROGNAME) && !defined(HAVE___PROGNAME) |
#if !defined(HAVE_GETPROGNAME) && !defined(HAVE___PROGNAME) |
setprogname(argc > 0 ? argv[0] : "testsudoers"); |
setprogname(argc > 0 ? argv[0] : "testsudoers"); |
#endif |
#endif |
|
|
#ifdef HAVE_SETLOCALE | sudoers_setlocale(SUDOERS_LOCALE_USER, NULL); |
setlocale(LC_ALL, ""); | |
#endif | |
bindtextdomain("sudoers", LOCALEDIR); /* XXX - should have own domain */ |
bindtextdomain("sudoers", LOCALEDIR); /* XXX - should have own domain */ |
textdomain("sudoers"); |
textdomain("sudoers"); |
|
|
/* Read sudo.conf. */ |
/* Read sudo.conf. */ |
sudo_conf_read(); | sudo_conf_read(NULL); |
|
|
dflag = 0; |
dflag = 0; |
grfile = pwfile = NULL; |
grfile = pwfile = NULL; |
while ((ch = getopt(argc, argv, "dg:G:h:p:tu:")) != -1) { | while ((ch = getopt(argc, argv, "dg:G:h:P:p:tu:U:")) != -1) { |
switch (ch) { |
switch (ch) { |
case 'd': |
case 'd': |
dflag = 1; |
dflag = 1; |
Line 169 main(int argc, char *argv[])
|
Line 160 main(int argc, char *argv[])
|
user_host = optarg; |
user_host = optarg; |
break; |
break; |
case 'G': |
case 'G': |
grfile = optarg; | sudoers_gid = (gid_t)atoi(optarg); |
break; |
break; |
case 'g': |
case 'g': |
runas_group = optarg; |
runas_group = optarg; |
Line 177 main(int argc, char *argv[])
|
Line 168 main(int argc, char *argv[])
|
case 'p': |
case 'p': |
pwfile = optarg; |
pwfile = optarg; |
break; |
break; |
|
case 'P': |
|
grfile = optarg; |
|
break; |
case 't': |
case 't': |
trace_print = testsudoers_print; |
trace_print = testsudoers_print; |
break; |
break; |
|
case 'U': |
|
sudoers_uid = (uid_t)atoi(optarg); |
|
break; |
case 'u': |
case 'u': |
runas_user = optarg; |
runas_user = optarg; |
break; |
break; |
Line 215 main(int argc, char *argv[])
|
Line 212 main(int argc, char *argv[])
|
argc -= 2; |
argc -= 2; |
} |
} |
if ((sudo_user.pw = sudo_getpwnam(user_name)) == NULL) |
if ((sudo_user.pw = sudo_getpwnam(user_name)) == NULL) |
errorx(1, _("unknown user: %s"), user_name); | fatalx(_("unknown user: %s"), user_name); |
|
|
if (user_host == NULL) { |
if (user_host == NULL) { |
if (gethostname(hbuf, sizeof(hbuf)) != 0) |
if (gethostname(hbuf, sizeof(hbuf)) != 0) |
error(1, "gethostname"); | fatal("gethostname"); |
hbuf[sizeof(hbuf) - 1] = '\0'; |
hbuf[sizeof(hbuf) - 1] = '\0'; |
user_host = hbuf; |
user_host = hbuf; |
} |
} |
Line 230 main(int argc, char *argv[])
|
Line 227 main(int argc, char *argv[])
|
} else { |
} else { |
user_shost = user_host; |
user_shost = user_host; |
} |
} |
|
user_runhost = user_host; |
|
user_srunhost = user_shost; |
|
|
/* Fill in user_args from argv. */ |
/* Fill in user_args from argv. */ |
if (argc > 0) { |
if (argc > 0) { |
Line 243 main(int argc, char *argv[])
|
Line 242 main(int argc, char *argv[])
|
for (to = user_args, from = argv; *from; from++) { |
for (to = user_args, from = argv; *from; from++) { |
n = strlcpy(to, *from, size - (to - user_args)); |
n = strlcpy(to, *from, size - (to - user_args)); |
if (n >= size - (to - user_args)) |
if (n >= size - (to - user_args)) |
errorx(1, _("internal error, init_vars() overflow")); | fatalx(_("internal error, %s overflow"), "init_vars()"); |
to += n; |
to += n; |
*to++ = ' '; |
*to++ = ' '; |
} |
} |
Line 261 main(int argc, char *argv[])
|
Line 260 main(int argc, char *argv[])
|
set_interfaces(p); |
set_interfaces(p); |
|
|
/* Allocate space for data structures in the parser. */ |
/* Allocate space for data structures in the parser. */ |
init_parser("sudoers", 0); | init_parser("sudoers", false); |
|
|
if (yyparse() != 0 || parse_error) { | if (sudoersparse() != 0 || parse_error) { |
parse_error = true; |
parse_error = true; |
if (errorlineno != -1) |
if (errorlineno != -1) |
(void) printf("Parse error in %s near line %d", |
(void) printf("Parse error in %s near line %d", |
Line 317 main(int argc, char *argv[])
|
Line 316 main(int argc, char *argv[])
|
puts("\thost matched"); |
puts("\thost matched"); |
tq_foreach_rev(&priv->cmndlist, cs) { |
tq_foreach_rev(&priv->cmndlist, cs) { |
runas_match = runaslist_matches(&cs->runasuserlist, |
runas_match = runaslist_matches(&cs->runasuserlist, |
&cs->runasgrouplist); | &cs->runasgrouplist, NULL, NULL); |
if (runas_match == ALLOW) { |
if (runas_match == ALLOW) { |
puts("\trunas matched"); |
puts("\trunas matched"); |
cmnd_match = cmnd_matches(cs->cmnd); |
cmnd_match = cmnd_matches(cs->cmnd); |
Line 353 set_runaspw(const char *user)
|
Line 352 set_runaspw(const char *user)
|
debug_decl(main, SUDO_DEBUG_UTIL) |
debug_decl(main, SUDO_DEBUG_UTIL) |
|
|
if (runas_pw != NULL) |
if (runas_pw != NULL) |
pw_delref(runas_pw); | sudo_pw_delref(runas_pw); |
if (*user == '#') { |
if (*user == '#') { |
if ((runas_pw = sudo_getpwuid(atoi(user + 1))) == NULL) |
if ((runas_pw = sudo_getpwuid(atoi(user + 1))) == NULL) |
runas_pw = sudo_fakepwnam(user, runas_gr ? runas_gr->gr_gid : 0); |
runas_pw = sudo_fakepwnam(user, runas_gr ? runas_gr->gr_gid : 0); |
} else { |
} else { |
if ((runas_pw = sudo_getpwnam(user)) == NULL) |
if ((runas_pw = sudo_getpwnam(user)) == NULL) |
errorx(1, _("unknown user: %s"), user); | fatalx(_("unknown user: %s"), user); |
} |
} |
|
|
debug_return; |
debug_return; |
Line 371 set_runasgr(const char *group)
|
Line 370 set_runasgr(const char *group)
|
debug_decl(main, SUDO_DEBUG_UTIL) |
debug_decl(main, SUDO_DEBUG_UTIL) |
|
|
if (runas_gr != NULL) |
if (runas_gr != NULL) |
gr_delref(runas_gr); | sudo_gr_delref(runas_gr); |
if (*group == '#') { |
if (*group == '#') { |
if ((runas_gr = sudo_getgrgid(atoi(group + 1))) == NULL) |
if ((runas_gr = sudo_getgrgid(atoi(group + 1))) == NULL) |
runas_gr = sudo_fakegrnam(group); |
runas_gr = sudo_fakegrnam(group); |
} else { |
} else { |
if ((runas_gr = sudo_getgrnam(group)) == NULL) |
if ((runas_gr = sudo_getgrnam(group)) == NULL) |
errorx(1, _("unknown group: %s"), group); | fatalx(_("unknown group: %s"), group); |
} |
} |
|
|
debug_return; |
debug_return; |
Line 407 sudo_endspent(void)
|
Line 406 sudo_endspent(void)
|
return; |
return; |
} |
} |
|
|
void |
|
set_fqdn(void) |
|
{ |
|
return; |
|
} |
|
|
|
FILE * |
FILE * |
open_sudoers(const char *path, bool doedit, bool *keepopen) | open_sudoers(const char *sudoers, bool doedit, bool *keepopen) |
{ |
{ |
|
struct stat sb; |
|
FILE *fp = NULL; |
|
char *sudoers_base; |
debug_decl(open_sudoers, SUDO_DEBUG_UTIL) |
debug_decl(open_sudoers, SUDO_DEBUG_UTIL) |
|
|
debug_return_ptr(fopen(path, "r")); | sudoers_base = strrchr(sudoers, '/'); |
| if (sudoers_base != NULL) |
| sudoers_base++; |
| |
| switch (sudo_secure_file(sudoers, sudoers_uid, sudoers_gid, &sb)) { |
| case SUDO_PATH_SECURE: |
| fp = fopen(sudoers, "r"); |
| break; |
| case SUDO_PATH_MISSING: |
| warning("unable to stat %s", sudoers_base); |
| break; |
| case SUDO_PATH_BAD_TYPE: |
| warningx("%s is not a regular file", sudoers_base); |
| break; |
| case SUDO_PATH_WRONG_OWNER: |
| warningx("%s should be owned by uid %u", |
| sudoers_base, (unsigned int) sudoers_uid); |
| break; |
| case SUDO_PATH_WORLD_WRITABLE: |
| warningx("%s is world writable", sudoers_base); |
| break; |
| case SUDO_PATH_GROUP_WRITABLE: |
| warningx("%s should be owned by gid %u", |
| sudoers_base, (unsigned int) sudoers_gid); |
| break; |
| default: |
| /* NOTREACHED */ |
| break; |
| } |
| |
| debug_return_ptr(fp); |
} |
} |
|
|
void |
void |
Line 439 restore_perms(void)
|
Line 465 restore_perms(void)
|
} |
} |
|
|
void |
void |
cleanup(int gotsignal) |
|
{ |
|
if (!gotsignal) { |
|
sudo_endpwent(); |
|
sudo_endgrent(); |
|
} |
|
} |
|
|
|
void |
|
print_member(struct member *m) |
print_member(struct member *m) |
{ |
{ |
struct sudo_command *c; |
struct sudo_command *c; |
Line 563 print_privilege(struct privilege *priv)
|
Line 580 print_privilege(struct privilege *priv)
|
print_member(m); |
print_member(m); |
} |
} |
fputs(" = ", stdout); |
fputs(" = ", stdout); |
tags.nopasswd = tags.noexec = UNSPEC; | tags.nopasswd = UNSPEC; |
| tags.noexec = UNSPEC; |
tq_foreach_fwd(&p->cmndlist, cs) { |
tq_foreach_fwd(&p->cmndlist, cs) { |
if (cs != tq_first(&p->cmndlist)) |
if (cs != tq_first(&p->cmndlist)) |
fputs(", ", stdout); |
fputs(", ", stdout); |
Line 596 print_privilege(struct privilege *priv)
|
Line 614 print_privilege(struct privilege *priv)
|
if (cs->type) |
if (cs->type) |
printf("TYPE=%s ", cs->type); |
printf("TYPE=%s ", cs->type); |
#endif /* HAVE_SELINUX */ |
#endif /* HAVE_SELINUX */ |
|
#ifdef HAVE_PRIV_SET |
|
if (cs->privs) |
|
printf("PRIVS=%s ", cs->privs); |
|
if (cs->limitprivs) |
|
printf("LIMITPRIVS=%s ", cs->limitprivs); |
|
#endif /* HAVE_PRIV_SET */ |
if (cs->tags.nopasswd != UNSPEC && cs->tags.nopasswd != tags.nopasswd) |
if (cs->tags.nopasswd != UNSPEC && cs->tags.nopasswd != tags.nopasswd) |
printf("%sPASSWD: ", cs->tags.nopasswd ? "NO" : ""); |
printf("%sPASSWD: ", cs->tags.nopasswd ? "NO" : ""); |
if (cs->tags.noexec != UNSPEC && cs->tags.noexec != tags.noexec) |
if (cs->tags.noexec != UNSPEC && cs->tags.noexec != tags.noexec) |
Line 627 print_userspecs(void)
|
Line 651 print_userspecs(void)
|
debug_return; |
debug_return; |
} |
} |
|
|
static int |
|
testsudoers_printf(int msg_type, const char *fmt, ...) |
|
{ |
|
va_list ap; |
|
FILE *fp; |
|
debug_decl(testsudoers_printf, SUDO_DEBUG_UTIL) |
|
|
|
switch (msg_type) { |
|
case SUDO_CONV_INFO_MSG: |
|
fp = stdout; |
|
break; |
|
case SUDO_CONV_ERROR_MSG: |
|
fp = stderr; |
|
break; |
|
default: |
|
errno = EINVAL; |
|
debug_return_int(-1); |
|
} |
|
|
|
va_start(ap, fmt); |
|
vfprintf(fp, fmt, ap); |
|
va_end(ap); |
|
|
|
debug_return_int(0); |
|
} |
|
|
|
void |
void |
dump_sudoers(void) |
dump_sudoers(void) |
{ |
{ |
Line 677 static int testsudoers_print(const char *msg)
|
Line 675 static int testsudoers_print(const char *msg)
|
void |
void |
usage(void) |
usage(void) |
{ |
{ |
(void) fprintf(stderr, "usage: %s [-dt] [-G grfile] [-g group] [-h host] [-p pwfile] [-u user] <user> <command> [args]\n", getprogname()); | (void) fprintf(stderr, "usage: %s [-dt] [-G sudoers_gid] [-g group] [-h host] [-p grfile] [-p pwfile] [-U sudoers_uid] [-u user] <user> <command> [args]\n", getprogname()); |
exit(1); |
exit(1); |
} |
} |