|
root / base / usr / src / cmd / cron / permit.c
permit.c C 121 lines 2.6 KB
  1
  2
  3
  4
  5
  6
  7
  8
  9
 10
 11
 12
 13
 14
 15
 16
 17
 18
 19
 20
 21
 22
 23
 24
 25
 26
 27
 28
 29
 30
 31
 32
 33
 34
 35
 36
 37
 38
 39
 40
 41
 42
 43
 44
 45
 46
 47
 48
 49
 50
 51
 52
 53
 54
 55
 56
 57
 58
 59
 60
 61
 62
 63
 64
 65
 66
 67
 68
 69
 70
 71
 72
 73
 74
 75
 76
 77
 78
 79
 80
 81
 82
 83
 84
 85
 86
 87
 88
 89
 90
 91
 92
 93
 94
 95
 96
 97
 98
 99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
/*
 * CDDL HEADER START
 *
 * The contents of this file are subject to the terms of the
 * Common Development and Distribution License (the "License").
 * You may not use this file except in compliance with the License.
 *
 * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
 * or http://www.opensolaris.org/os/licensing.
 * See the License for the specific language governing permissions
 * and limitations under the License.
 *
 * When distributing Covered Code, include this CDDL HEADER in each
 * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
 * If applicable, add the following below this CDDL HEADER, with the
 * fields enclosed by brackets "[]" replaced with your own identifying
 * information: Portions Copyright [yyyy] [name of copyright owner]
 *
 * CDDL HEADER END
 */
/*	Copyright (c) 1984, 1986, 1987, 1988, 1989 AT&T	*/
/*	  All Rights Reserved  */

/*
 * Copyright 2009 Sun Microsystems, Inc.  All rights reserved.
 * Use is subject to license terms.
 */

#include <sys/types.h>
#include <sys/stat.h>
#include <stdio.h>
#include <string.h>
#include <ctype.h>
#include <pwd.h>
#include <auth_attr.h>
#include <auth_list.h>

#include "cron.h"

struct stat globstat;
#define	exists(file)	(stat(file, &globstat) == 0)
#define	ROOT	"root"

int per_errno;	/* status info from getuser */
static int within(char *, char *);


char *
getuser(uid_t uid)
{
	struct passwd *nptr;

	if ((nptr = getpwuid(uid)) == NULL) {
		per_errno = 1;
		return (NULL);
	}
	if ((strcmp(nptr->pw_shell, SHELL) != 0) &&
	    (strcmp(nptr->pw_shell, "") != 0)) {
		per_errno = 2;
		/*
		 * return NULL if you want crontab and at to abort
		 * when the users login shell is not /usr/bin/sh otherwise
		 * return pw_name
		 */
		return (nptr->pw_name);
	}
	return (nptr->pw_name);
}

int
allowed(char *user, char *allow, char *deny)
{
	if (exists(allow)) {
		if (within(user, allow)) {
			return (1);
		} else {
			return (0);
		}
	} else if (exists(deny)) {
		if (within(user, deny)) {
			return (0);
		} else {
			return (1);
		}
	} else if (chkauthattr(CRONUSER_AUTH, user)) {
		return (1);
	} else {
		return (0);
	}
}

static int
within(char *username, char *filename)
{
	char line[UNAMESIZE];
	FILE *cap;
	int i;

	if ((cap = fopen(filename, "r")) == NULL)
		return (0);
	while (fgets(line, UNAMESIZE, cap) != NULL) {
		for (i = 0; line[i] != '\0'; i++) {
			if (isspace(line[i])) {
				line[i] = '\0';
				break; }
		}
		if (strcmp(line, username) == 0) {
			fclose(cap);
			return (1);
		}
	}
	fclose(cap);
	return (0);
}

int
cron_admin(const char *name)
{
	return (chkauthattr(CRONADMIN_AUTH, name));
}