source: trunk/server/common/oursrc/nss_nonlocal/nonlocal-shadow.c @ 2297

Last change on this file since 2297 was 1825, checked in by andersk, 15 years ago
Update nss_nonlocal to 2.0 - Fix errno saving and restoring. - Document nss-nonlocal-users and nss-local-users groups in README. - Allow local whitelisting of nonlocal user and group memberships, using the magic local ‘nss-nonlocal-users’ user and group.
File size: 4.2 KB
Line 
1/*
2 * nonlocal-shadow.c
3 * shadow database for nss_nonlocal proxy.
4 *
5 * Copyright © 2007–2010 Anders Kaseorg <andersk@mit.edu>
6 *
7 * This file is part of nss_nonlocal.
8 *
9 * nss_nonlocal is free software; you can redistribute it and/or
10 * modify it under the terms of the GNU Lesser General Public License
11 * as published by the Free Software Foundation; either version 2.1 of
12 * the License, or (at your option) any later version.
13 *
14 * nss_nonlocal is distributed in the hope that it will be useful, but
15 * WITHOUT ANY WARRANTY; without even the implied warranty of
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
17 * Lesser General Public License for more details.
18 *
19 * You should have received a copy of the GNU Lesser General Public
20 * License along with nss_nonlocal; if not, write to the Free Software
21 * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
22 * 02110-1301  USA
23 */
24
25#define _GNU_SOURCE
26#include <sys/types.h>
27#include <unistd.h>
28#include <stdlib.h>
29#include <stdint.h>
30#include <string.h>
31#include <dlfcn.h>
32#include <stdio.h>
33#include <syslog.h>
34#include <errno.h>
35#include <shadow.h>
36#include <nss.h>
37
38#include "nsswitch-internal.h"
39#include "nonlocal.h"
40
41
42static service_user *__nss_shadow_nonlocal_database;
43
44static int
45internal_function
46__nss_shadow_nonlocal_lookup(service_user **ni, const char *fct_name,
47                            void **fctp)
48{
49    if (__nss_shadow_nonlocal_database == NULL
50        && __nss_database_lookup("shadow_nonlocal", NULL, NULL,
51                                 &__nss_shadow_nonlocal_database) < 0)
52        return -1;
53
54    *ni = __nss_shadow_nonlocal_database;
55
56    *fctp = __nss_lookup_function(*ni, fct_name);
57    return 0;
58}
59
60
61static service_user *spent_startp, *spent_nip;
62static void *spent_fct_start;
63static union {
64    enum nss_status (*l)(struct spwd *pwd, char *buffer, size_t buflen,
65                         int *errnop);
66    void *ptr;
67} spent_fct;
68static const char *spent_fct_name = "getspent_r";
69
70enum nss_status
71_nss_nonlocal_setspent(int stayopen)
72{
73    enum nss_status status;
74    const struct walk_nss w = {
75        .lookup = &__nss_shadow_nonlocal_lookup, .fct_name = "setspent",
76        .status = &status
77    };
78    const __typeof__(&_nss_nonlocal_setspent) self = NULL;
79#define args (stayopen)
80#include "walk_nss.h"
81#undef args
82    if (status != NSS_STATUS_SUCCESS)
83        return status;
84
85    if (spent_fct_start == NULL)
86        __nss_shadow_nonlocal_lookup(&spent_startp, spent_fct_name,
87                                     &spent_fct_start);
88    spent_nip = spent_startp;
89    spent_fct.ptr = spent_fct_start;
90    return NSS_STATUS_SUCCESS;
91}
92
93enum nss_status
94_nss_nonlocal_endspent(void)
95{
96    enum nss_status status;
97    const struct walk_nss w = {
98        .lookup = &__nss_shadow_nonlocal_lookup, .fct_name = "endspent",
99        .status = &status
100    };
101    const __typeof__(&_nss_nonlocal_endspent) self = NULL;
102
103    spent_nip = NULL;
104
105#define args ()
106#include "walk_nss.h"
107#undef args
108    return status;
109}
110
111enum nss_status
112_nss_nonlocal_getspent_r(struct spwd *pwd, char *buffer, size_t buflen,
113                         int *errnop)
114{
115    enum nss_status status;
116    if (spent_nip == NULL) {
117        status = _nss_nonlocal_setspent(0);
118        if (status != NSS_STATUS_SUCCESS)
119            return status;
120    }
121    do {
122        if (spent_fct.ptr == NULL)
123            status = NSS_STATUS_UNAVAIL;
124        else
125            status = DL_CALL_FCT(spent_fct.l, (pwd, buffer, buflen, errnop));   
126        if (status == NSS_STATUS_TRYAGAIN && *errnop == ERANGE)
127            return status;
128
129        if (status == NSS_STATUS_SUCCESS)
130            return NSS_STATUS_SUCCESS;
131    } while (__nss_next(&spent_nip, spent_fct_name, &spent_fct.ptr, status, 0) == 0);
132
133    spent_nip = NULL;
134    return NSS_STATUS_NOTFOUND;
135}
136
137
138enum nss_status
139_nss_nonlocal_getspnam_r(const char *name, struct spwd *pwd,
140                         char *buffer, size_t buflen, int *errnop)
141{
142    enum nss_status status;
143    const struct walk_nss w = {
144        .lookup = __nss_shadow_nonlocal_lookup, .fct_name = "getspnam_r",
145        .status = &status, .errnop = errnop
146    };
147    const __typeof__(&_nss_nonlocal_getspnam_r) self = NULL;
148#define args (name, pwd, buffer, buflen, errnop)
149#include "walk_nss.h"
150#undef args
151    if (status != NSS_STATUS_SUCCESS)
152        return status;
153
154    if (strcmp(name, pwd->sp_namp) != 0) {
155        syslog(LOG_ERR, "nss_nonlocal: discarding shadow %s from lookup for shadow %s\n", pwd->sp_namp, name);
156        return NSS_STATUS_NOTFOUND;
157    }
158
159    return NSS_STATUS_SUCCESS;
160}
Note: See TracBrowser for help on using the repository browser.