2 * Copyright 2000, International Business Machines Corporation and others.
5 * This software has been released under the terms of the IBM Public
6 * License. For details, see the LICENSE file in the top-level source
7 * directory or online at http://www.openafs.org/dl/license10.html
11 * Implementation of basic procedures for the AFS user account
16 * --------------------- Required definitions ---------------------
18 #include <afsconfig.h>
19 #include <afs/param.h>
23 #include "uss_procs.h" /*Module interface*/
24 #include "uss_common.h" /*Common defs & operations*/
25 #include "uss_acl.h" /*ACL-related operations*/
26 #include <errno.h> /*Unix error codes*/
27 #include <pwd.h> /*Password info*/
28 #include <sys/stat.h> /*Stat defs*/
29 #include <dirent.h> /*Directory package*/
30 #include <sys/file.h> /*O_EXCL, O_CREAT, etc*/
43 #include <afs/kautils.h> /*MAXKTCREALMLEN*/
48 #undef USS_PROCS_DB_INSTANCE
49 #undef USS_PROCS_DB_BUILDDIR
51 #define uss_procs_MAX_SIZE 2048
59 /*-----------------------------------------------------------------------
60 * EXPORTED uss_procs_BuildDir
63 * Called from the code generated by the uss grammar.
67 *------------------------------------------------------------------------*/
69 afs_int32 uss_procs_BuildDir(a_path, a_mode, a_owner, a_access)
75 { /*uss_procs_BuildDir*/
79 struct uss_subdir *new_dir;
83 * Don't do anything if there's already a problem.
89 printf("Building directory '%s'; owner: '%s', ACL: '%s'\n",
90 a_path, a_owner, a_access);
93 * If we've not been given permission to overwrite things, make sure
94 * the target doesn't exist before doing anything.
96 if (!uss_OverwriteThisOne) {
98 if (!stat(temp, &stbuf)) {
100 printf("\t[Directory exists, NOT overwriting it]\n");
105 sscanf(a_mode, "%o", &m);
106 o = uss_procs_GetOwner(a_owner);
107 #ifdef USS_PROCS_DB_BUILDDIR
108 printf("DEBUGGING: Owner '%s' is uid %d\n", a_owner, o);
109 #endif /* USS_PROCS_DB_BUILDDIR */
112 if (mkdir(a_path, m)) {
114 * Can't make the directory. Complain if the directory doesn't
117 if (errno != EEXIST) {
118 uss_procs_PrintErr(line,
119 "Failed to create directory '%s': %s\n",
120 a_path, sys_errlist[errno]);
122 } /*Directory didn't exist*/
123 } /*Create the directory*/
126 if (uss_OverwriteThisOne)
127 fprintf(stderr, "\t[Dry run: mkdir %s, mode %o]\n",
132 if (chmod(a_path, m)) {
133 uss_procs_PrintErr(line,
134 "Can't chmod() directory '%s' to be '%s' : %s\n",
135 a_path, a_mode, sys_errlist[errno]);
137 } /* chmod the directory */
138 if (chown(a_path, o, -1)) {
139 uss_procs_PrintErr(line,
140 "Can't chown() directory '%s' to be owned by '%s' (uid %d): %s\n",
141 a_path, a_owner, o, sys_errlist[errno]);
147 "\t[Dry run: chown() directory '%s' to be owned by user]\n",
152 * Set the ACL for this new directory so that the uss_AccountCreator
153 * is the only party that has rights. This will be corrected as the
154 * final action performed on the account.
156 sprintf(buf, "%s %s all", a_path, uss_AccountCreator);
160 "Setting ACL: '%s'\n", buf);
161 if (uss_acl_SetAccess(buf, 1, 0))
165 fprintf(stderr, "\t[Dry run: uss_acl_SetAccess(%s) on '%s']\n",
170 * Use our linked list to remember this directory's true ACL setting so
171 * we may set it correctly at the tail end of the account creation.
173 new_dir = (struct uss_subdir *) malloc(sizeof(struct uss_subdir));
174 new_dir->previous = uss_currentDir;
175 new_dir->path = (char *) malloc(strlen(a_path)+1);
176 strcpy(new_dir->path, a_path);
177 new_dir->finalACL = (char *) malloc(strlen(a_access)+1);
178 strcpy(new_dir->finalACL, a_access);
179 uss_currentDir = new_dir;
182 * Return the happy news.
186 } /*uss_procs_BuildDir*/
189 /*-----------------------------------------------------------------------
190 * EXPORTED uss_procs_CpFile
193 * Called from the code generated by the uss grammar.
197 *------------------------------------------------------------------------*/
199 afs_int32 uss_procs_CpFile(a_path, a_mode, a_owner, a_proto)
205 { /*uss_procs_CpFile*/
212 * Don't do anything if something has already gone wrong.
218 printf("Installing '%s'\n", a_path);
221 * If we've not been given permission to overwrite things, make sure
222 * the target doesn't exist before doing anything.
224 if (!uss_OverwriteThisOne) {
225 strcpy(temp, a_path);
226 if (!stat(temp, &stbuf)) {
228 printf("\t[Entry exists, NOT overwriting it]\n");
233 sscanf(a_mode, "%o", &m);
234 o = uss_procs_GetOwner(a_owner);
236 strcpy(temp, a_proto);
238 if (stat(temp, &stbuf)) {
239 uss_procs_PrintErr(line, "Failed to stat '%s': %s\n",
240 a_proto, sys_errlist[errno]);
244 if (stbuf.st_mode & S_IFDIR) {
245 if ((cp = strrchr(a_path, '/')) == NULL) {
246 strcat(a_proto, "/");
247 strcat(a_proto, a_path);
251 * Append the last part (file name).
255 } /*Target is a directory*/
258 if (Copy(a_proto, a_path, m)) {
259 uss_procs_PrintErr(line,
260 "Failed to copy '%s' to '%s'\n",
266 fprintf(stderr, "\t[Dry run: Copying '%s' to '%s', mode %o]\n",
271 if (chown(a_path, o, -1)) {
272 uss_procs_PrintErr(line,
273 "Can't chown() file '%s' to be owned by '%s' (uid %d): %s\n",
274 a_path, a_owner, o, sys_errlist[errno]);
279 fprintf(stderr, "\t[Dry run: chown() file '%s' to be owned by user]\n",
284 * Return the happy news.
288 } /*uss_procs_CpFile*/
291 /*-----------------------------------------------------------------------
292 * EXPORTED uss_procs_EchoToFile
295 * Called from the code generated by the uss grammar.
299 *------------------------------------------------------------------------*/
301 afs_int32 uss_procs_EchoToFile(a_path, a_mode, a_owner, a_content)
307 { /*uss_procs_EchoToFile*/
313 * Don't do anything if something has already gone wrong.
319 printf("Echoing to '%s'\n", a_path);
322 * If we've not been given permission to overwrite things, make sure
323 * the target doesn't exist before doing anything.
325 if (!uss_OverwriteThisOne) {
326 strcpy(temp, a_path);
327 if (!stat(temp, &stbuf)) {
329 printf("\t[Entry exists, NOT overwriting it]\n");
334 sscanf(a_mode, "%o", &m);
335 o = uss_procs_GetOwner(a_owner);
338 if (Echo(a_content, a_path, m)){
339 uss_procs_PrintErr(line,
340 "Failed to echo string '%s' to file '%s'\n",
346 fprintf(stderr, "\t[Dry run: Echoing '%s' into file '%s']\n",
351 if (chown(a_path, o, -1)){
352 uss_procs_PrintErr(line,
353 "Can't chown() file '%s' to be owned by '%s' (uid %d): %s\n",
354 a_path, a_owner, o, sys_errlist[errno]);
360 "\t[Dry run: chown() file '%s' to be owned by user]\n",
365 * Return the happy news.
369 } /*uss_procs_EchoToFile*/
372 /*-----------------------------------------------------------------------
373 * EXPORTED uss_procs_Exec
376 * Called from the code generated by the uss grammar, as well as
381 *------------------------------------------------------------------------*/
383 afs_int32 uss_procs_Exec(a_command)
389 printf("Running '%s'\n", a_command);
392 if (system(a_command)) {
393 uss_procs_PrintErr(line,
394 "Failed to run the '%s' command: %s\n",
395 a_command, sys_errlist[errno]);
400 fprintf(stderr, "\t[Dry run: executing '%s']\n", a_command);
404 * Return the happy news.
411 /*-----------------------------------------------------------------------
412 * EXPORTED uss_procs_SetLink
415 * Called from the code generated by the uss grammar.
419 *------------------------------------------------------------------------*/
421 afs_int32 uss_procs_SetLink(a_path1, a_path2, a_type)
426 { /*uss_procs_SetLink*/
431 printf("Setting link '%s' to '%s'\n", a_path1, a_path2);
434 * If we've not been given permission to overwrite things, make sure
435 * the target doesn't exist before doing anything.
437 if (!uss_OverwriteThisOne) {
438 strcpy(temp, a_path2);
439 if (!stat(temp, &stbuf)) {
441 printf("\t[Entry exists, NOT overwriting it]\n");
451 if (symlink(a_path1, a_path2)) {
452 uss_procs_PrintErr(line,
453 "Failed to make symlink '%s' to '%s': %s\n",
454 a_path1, a_path2, sys_errlist[errno]);
459 fprintf(stderr, "\t[Dry run: Making symlink '%s' to '%s']\n",
468 if (link(a_path1, a_path2)) {
469 uss_procs_PrintErr(line,
470 "Failed to make hard link '%s' to '%s': %s\n",
471 a_path1, a_path2, sys_errlist[errno]);
476 fprintf(stderr, "\t[Dry run: Making hard link '%s' to '%s']\n",
482 * Return the happy news.
486 } /*uss_procs_SetLink*/
489 /*-----------------------------------------------------------------------
490 * EXPORTED uss_procs_GetOwner
493 * Nothing interesting.
497 *------------------------------------------------------------------------*/
499 int uss_procs_GetOwner(a_ownerStr)
502 { /*uss_procs_GetOwner*/
504 struct passwd *pw; /*Ptr to password file entry*/
505 int ownerID; /*Numerical owner*/
507 ownerID = atoi(a_ownerStr);
508 if ((ownerID == 0) && (a_ownerStr[0] != '0')) {
510 * The owner is not in numerical format
512 if ((pw = getpwnam(a_ownerStr)) == NULL) {
513 uss_procs_PrintErr(line,
514 "Owner '%s' is an unknown user\n",
523 } /*uss_procs_GetOwner*/
525 /*-----------------------------------------------------------------------
529 * Copies the "from" file to the "to" file and sets the mode.
532 * a_from : File to copy from.
533 * a_to : File to copy to.
534 * a_mode : New Unix mode to set.
537 * 0 if everything went well,
538 * if there was a problem.
541 * Nothing interesting.
545 *------------------------------------------------------------------------*/
547 static int Copy(a_from, a_to, a_mode)
554 register int fd1, fd2;
559 fd1 = open(a_to, O_EXCL | O_CREAT | O_WRONLY, a_mode);
561 if (errno == EEXIST) {
563 * The file exists. Since we can only be called when overwriting
564 * has been enabled, we back off and open the file normally (not
565 * supplying O_EXCL), then continue normally.
567 fd1 = open(a_to, O_CREAT | O_WRONLY, a_mode);
569 uss_procs_PrintErr(line,
570 "%s: Failed to open '%s' for overwrite: %s.\n",
571 uss_whoami, a_to, sys_errlist[errno]);
575 uss_procs_PrintErr(line, "%s: Failed to open '%s': %s.\n",
576 uss_whoami, a_to, sys_errlist[errno]);
581 if ((fd2 = open(a_from, O_RDONLY, 0)) < 0) {
582 uss_procs_PrintErr(line, "%s: Error reading '%s': %s\n",
583 uss_whoami, a_from, sys_errlist[errno]);
587 while ((cnt = read(fd2, buf, BUFSIZ)) == BUFSIZ)
588 write(fd1, buf, cnt);
590 write(fd1, buf, cnt);
593 uss_procs_PrintErr(line,
594 "Failed to close '%s' %s\n",
595 a_to, sys_errlist[errno]);
599 uss_procs_PrintErr(line, "Warning: Failed to close '%s': %s\n",
600 a_from, sys_errlist[errno]);
605 /*-----------------------------------------------------------------------
609 * Writes a string into a file and sets its mode.
612 * a_s : String to write.
613 * a_f : Filename to write to.
614 * a_mode : New Unix mode to set.
617 * 0 if everything went well,
618 * if there was a problem.
621 * Nothing interesting.
625 *------------------------------------------------------------------------*/
627 static int Echo(a_s, a_f, a_mode)
637 fd = open(a_f, O_EXCL | O_CREAT | O_WRONLY, a_mode);
639 if (errno == EEXIST) {
641 * The file exists. Since we can only be called when
642 * overwriting has been enabled, we back off and open the
643 * file normally (not supplying the O_EXCL), then continue
644 * normally. Notice that we must truncate the file, since
645 * if the original file is longer than the stuff we're about
646 * to put in, all the old data past the current write will
649 fd = open(a_f, O_TRUNC | O_WRONLY, a_mode);
651 uss_procs_PrintErr(line,
652 "%s: Failed to open '%s' for overwrite: %s.\n",
653 uss_whoami, a_f, sys_errlist[errno]);
657 uss_procs_PrintErr(line, "%s: Failed to open '%s': %s. \n",
658 uss_whoami, a_f, sys_errlist[errno]);
662 write(fd, a_s, strlen(a_s));
665 uss_procs_PrintErr(line, "Failed to close '%s': %s\n",
666 a_f, sys_errlist[errno]);
673 /*-----------------------------------------------------------------------
674 * static uss_procs_PickADir
677 * Tries to replace $AUTO by a subdir. Subdirs are given by means
678 * of "G" in the configuration file. Each of the directories is
679 * examined, and the one with the inimum number of entries is
687 * 0 if everything went well,
688 * -1 if there was a problem.
691 * Called with THREE parameters from lex.c!
695 *------------------------------------------------------------------------*/
697 afs_int32 uss_procs_PickADir(path, cp)
701 { /*uss_procs_PickADir*/
703 char cd[300]; /*Current directory for search*/
705 int i, count, MinIndex, mina = 10000;
710 if (uss_NumGroups == 0){
711 fprintf(stderr,"%s: No choice yet given to replace $AUTO\n",
713 fprintf(stderr,"%s: Use the G command before $AUTO in config file\n",
718 if (uss_Auto[0] != '\0')
719 return(0); /* we have already done this for this user */
721 if (*(cp-1) == '/') { /*it's ..../$AUTO*/
722 for (i = 0; &path[i] != cp; i++)
728 fprintf(stderr,"%s: $AUTO must be used to replace the whole path or the whole name of a subdirectory. Found: %s$AUTO\n", uss_whoami, path);
731 cd[0] = '/'; cd[1] = '\0';
735 * We now have the current dir (cd). Search all of the given
736 * subdirs (by G in template), count the number of entries in
737 * each and pick the minimum.
739 for (i=0; i < uss_NumGroups; i++) {
740 sprintf(dirname, "%s/%s", cd, uss_DirPool[i]);
741 if ((dirp = opendir(dirname)) == NULL) {
742 if (errno != ENOTDIR)
744 "%s: Warning: Can't open dir '%s' (errno=%d). Skipped.\n",
745 uss_whoami, dirname, errno);
746 continue; /*Skip and continue anyway*/
749 for (dp = readdir(dirp); dp != NULL; dp = readdir(dirp))
750 if (dp->d_name[0] != '.')
751 count++; /* forget about files starting with .*/
753 printf("debug: Dir '%s' has %d entries\n", dirname, count);
754 #endif /* USS_PROCS_DB */
761 if (mina == 10000) { /* We found nothing */
762 fprintf(stderr,"%s: Warning: No valid choice to replace $AUTO\n",
767 strcpy(uss_Auto, uss_DirPool[MinIndex]);
769 printf("Picking dir w/minimum number of entries: '%s'\n",
774 } /*uss_procs_PickADir*/
776 /*-----------------------------------------------------------------------
777 * EXPORTED uss_procs_AddToDirPool
780 * Called from the code generated by the uss grammar.
784 *------------------------------------------------------------------------*/
786 int uss_procs_AddToDirPool(a_dirToAdd)
789 if (uss_NumGroups > 99) {
792 strcpy(uss_DirPool[uss_NumGroups++], a_dirToAdd);
796 /*-----------------------------------------------------------------------
797 * EXPORTED uss_procs_FindAndOpen
800 * Nothing interesting.
804 *------------------------------------------------------------------------*/
806 FILE *uss_procs_FindAndOpen(a_fileToOpen)
809 { /*uss_procs_FindAndOpen*/
811 #define NUM_TPL_PATHS 3
813 FILE *rv; /*Template file descriptor*/
814 int i; /*Loop counter*/
815 char tmp_str[uss_MAX_SIZE]; /*Tmp string*/
817 TemplatePath[NUM_TPL_PATHS][1024]; /*Template directories*/
818 int cant_read; /*Can't read the file?*/
821 * If a full pathname was given, just take it as is.
823 if (strchr(a_fileToOpen, '/')) {
824 strcpy(tmp_str, a_fileToOpen);
825 rv = fopen(a_fileToOpen, "r");
829 * A relative pathname was given. Try to find the file in each of
830 * the default template directories.
834 sprintf(TemplatePath[0], "%s", ".");
835 sprintf(TemplatePath[1], "/afs/%s/common/uss", uss_Cell);
836 sprintf(TemplatePath[2], "%s", "/etc");
838 for (i = 0; i < NUM_TPL_PATHS; i++) {
839 sprintf(tmp_str, "%s/%s", TemplatePath[i], a_fileToOpen);
840 if ((rv = fopen(tmp_str, "r")) != NULL)
844 * If the file was there but couldn't be opened, we have
847 if (errno != ENOENT) {
851 } /*Look in template directories*/
854 * If we found and opened the file, we're happy. Otherwise,
855 * print out what went wrong.
859 fprintf(stderr, "Using template '%s'\n", tmp_str);
863 * Check to see if we specifically found the file but
868 "%s: Can't open template '%s': %s\n",
869 uss_whoami, tmp_str, sys_errlist[errno]);
872 "%s: Can't find template '%s' in searchlist",
873 uss_whoami, a_fileToOpen);
874 for (i = 0; i < NUM_TPL_PATHS; i++)
875 fprintf(stderr, " '%s'", TemplatePath[i]);
876 fprintf(stderr, "\n");
877 } /*Can't find template*/
879 } /*Relative pathname given*/
882 * Whatever happened, return what we got.
886 } /*uss_procs_FindAndOpen*/
889 /*-----------------------------------------------------------------------
890 * EXPORTED uss_procs_PrintErr
893 * Nothing interesting.
897 *------------------------------------------------------------------------*/
899 void uss_procs_PrintErr(a_lineNum, a_fmt, a_1, a_2, a_3, a_4, a_5)
908 { /*uss_procs_PrintErr*/
911 fprintf(stderr,"%s: Template file, line %d: ", uss_whoami, a_lineNum);
912 fprintf(stderr, a_fmt, a_1, a_2, a_3, a_4, a_5);
914 } /*uss_procs_PrintErr*/