2 * Unix SMB/CIFS implementation.
3 * SMB parameters and setup
4 * Copyright (C) Andrew Tridgell 1992-1998
5 * Modified by Jeremy Allison 1995.
6 * Modified by Gerald (Jerry) Carter 2000-2001,2003
7 * Modified by Andrew Bartlett 2002.
9 * This program is free software; you can redistribute it and/or modify it under
10 * the terms of the GNU General Public License as published by the Free
11 * Software Foundation; either version 2 of the License, or (at your option)
14 * This program is distributed in the hope that it will be useful, but WITHOUT
15 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
16 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
19 * You should have received a copy of the GNU General Public License along with
20 * this program; if not, write to the Free Software Foundation, Inc., 675
21 * Mass Ave, Cambridge, MA 02139, USA.
27 #define DBGC_CLASS DBGC_PASSDB
30 smb_passwd is analogous to sam_passwd used everywhere
31 else. However, smb_passwd is limited to the information
32 stored by an smbpasswd entry
37 uint32 smb_userid; /* this is actually the unix uid_t */
38 const char *smb_name; /* username string */
40 const unsigned char *smb_passwd; /* Null if no password */
41 const unsigned char *smb_nt_passwd; /* Null if no password */
43 uint16 acct_ctrl; /* account info (ACB_xxxx bit-mask) */
44 time_t pass_last_set_time; /* password last set time */
47 struct smbpasswd_privates
49 /* used for maintain locks on the smbpasswd file */
50 int pw_file_lock_depth;
52 /* Global File pointer */
55 /* formerly static variables */
56 struct smb_passwd pw_buf;
58 unsigned char smbpwd[16];
59 unsigned char smbntpwd[16];
61 /* retrive-once info */
62 const char *smbpasswd_file;
65 enum pwf_access_type { PWF_READ, PWF_UPDATE, PWF_CREATE };
67 /***************************************************************
68 Lock an fd. Abandon after waitsecs seconds.
69 ****************************************************************/
71 static BOOL pw_file_lock(int fd, int type, int secs, int *plock_depth)
77 if(*plock_depth == 0) {
78 if (!do_file_lock(fd, secs, type)) {
79 DEBUG(10,("pw_file_lock: locking file failed, error = %s.\n",
90 /***************************************************************
91 Unlock an fd. Abandon after waitsecs seconds.
92 ****************************************************************/
94 static BOOL pw_file_unlock(int fd, int *plock_depth)
98 if (fd == 0 || *plock_depth == 0) {
102 if(*plock_depth == 1) {
103 ret = do_file_lock(fd, 5, F_UNLCK);
106 if (*plock_depth > 0) {
111 DEBUG(10,("pw_file_unlock: unlocking file failed, error = %s.\n",
117 /**************************************************************
118 Intialize a smb_passwd struct
119 *************************************************************/
121 static void pdb_init_smb(struct smb_passwd *user)
127 user->pass_last_set_time = (time_t)0;
130 /***************************************************************
131 Internal fn to enumerate the smbpasswd list. Returns a void pointer
132 to ensure no modification outside this module. Checks for atomic
133 rename of smbpasswd file on update or create once the lock has
134 been granted to prevent race conditions. JRA.
135 ****************************************************************/
137 static FILE *startsmbfilepwent(const char *pfile, enum pwf_access_type type, int *lock_depth)
140 const char *open_mode = NULL;
142 int lock_type = F_RDLCK;
145 DEBUG(0, ("startsmbfilepwent: No SMB password file set\n"));
160 * Ensure atomic file creation.
165 for(i = 0; i < 5; i++) {
166 if((fd = sys_open(pfile, O_CREAT|O_TRUNC|O_EXCL|O_RDWR, 0600))!=-1) {
169 sys_usleep(200); /* Spin, spin... */
172 DEBUG(0,("startsmbfilepwent_internal: too many race conditions \
173 creating file %s\n", pfile));
183 for(race_loop = 0; race_loop < 5; race_loop++) {
184 DEBUG(10, ("startsmbfilepwent_internal: opening file %s\n", pfile));
186 if((fp = sys_fopen(pfile, open_mode)) == NULL) {
189 * If smbpasswd file doesn't exist, then create new one. This helps to avoid
190 * confusing error msg when adding user account first time.
192 if (errno == ENOENT) {
193 if ((fp = sys_fopen(pfile, "a+")) != NULL) {
194 DEBUG(0, ("startsmbfilepwent_internal: file %s did not \
195 exist. File successfully created.\n", pfile));
197 DEBUG(0, ("startsmbfilepwent_internal: file %s did not \
198 exist. Couldn't create new one. Error was: %s",
199 pfile, strerror(errno)));
203 DEBUG(0, ("startsmbfilepwent_internal: unable to open file %s. \
204 Error was: %s\n", pfile, strerror(errno)));
209 if (!pw_file_lock(fileno(fp), lock_type, 5, lock_depth)) {
210 DEBUG(0, ("startsmbfilepwent_internal: unable to lock file %s. \
211 Error was %s\n", pfile, strerror(errno) ));
217 * Only check for replacement races on update or create.
218 * For read we don't mind if the data is one record out of date.
221 if(type == PWF_READ) {
224 SMB_STRUCT_STAT sbuf1, sbuf2;
227 * Avoid the potential race condition between the open and the lock
228 * by doing a stat on the filename and an fstat on the fd. If the
229 * two inodes differ then someone did a rename between the open and
230 * the lock. Back off and try the open again. Only do this 5 times to
231 * prevent infinate loops. JRA.
234 if (sys_stat(pfile,&sbuf1) != 0) {
235 DEBUG(0, ("startsmbfilepwent_internal: unable to stat file %s. \
236 Error was %s\n", pfile, strerror(errno)));
237 pw_file_unlock(fileno(fp), lock_depth);
242 if (sys_fstat(fileno(fp),&sbuf2) != 0) {
243 DEBUG(0, ("startsmbfilepwent_internal: unable to fstat file %s. \
244 Error was %s\n", pfile, strerror(errno)));
245 pw_file_unlock(fileno(fp), lock_depth);
250 if( sbuf1.st_ino == sbuf2.st_ino) {
256 * Race occurred - back off and try again...
259 pw_file_unlock(fileno(fp), lock_depth);
265 DEBUG(0, ("startsmbfilepwent_internal: too many race conditions opening file %s\n", pfile));
269 /* Set a buffer to do more efficient reads */
270 setvbuf(fp, (char *)NULL, _IOFBF, 1024);
272 /* Make sure it is only rw by the owner */
274 if(fchmod(fileno(fp), S_IRUSR|S_IWUSR) == -1) {
276 if(chmod(pfile, S_IRUSR|S_IWUSR) == -1) {
278 DEBUG(0, ("startsmbfilepwent_internal: failed to set 0600 permissions on password file %s. \
279 Error was %s\n.", pfile, strerror(errno) ));
280 pw_file_unlock(fileno(fp), lock_depth);
285 /* We have a lock on the file. */
289 /***************************************************************
290 End enumeration of the smbpasswd list.
291 ****************************************************************/
293 static void endsmbfilepwent(FILE *fp, int *lock_depth)
299 pw_file_unlock(fileno(fp), lock_depth);
301 DEBUG(7, ("endsmbfilepwent_internal: closed password file.\n"));
304 /*************************************************************************
305 Routine to return the next entry in the smbpasswd list.
306 *************************************************************************/
308 static struct smb_passwd *getsmbfilepwent(struct smbpasswd_privates *smbpasswd_state, FILE *fp)
310 /* Static buffers we will return. */
311 struct smb_passwd *pw_buf = &smbpasswd_state->pw_buf;
312 char *user_name = smbpasswd_state->user_name;
313 unsigned char *smbpwd = smbpasswd_state->smbpwd;
314 unsigned char *smbntpwd = smbpasswd_state->smbntpwd;
323 DEBUG(0,("getsmbfilepwent: Bad password file pointer.\n"));
327 pdb_init_smb(pw_buf);
328 pw_buf->acct_ctrl = ACB_NORMAL;
331 * Scan the file, a line at a time and check if the name matches.
334 while (status && !feof(fp)) {
337 status = fgets(linebuf, 256, fp);
338 if (status == NULL && ferror(fp)) {
343 * Check if the string is terminated with a newline - if not
344 * then we must keep reading and discard until we get one.
346 if ((linebuf_len = strlen(linebuf)) == 0) {
350 if (linebuf[linebuf_len - 1] != '\n') {
352 while (!ferror(fp) && !feof(fp)) {
359 linebuf[linebuf_len - 1] = '\0';
362 #ifdef DEBUG_PASSWORD
363 DEBUG(100, ("getsmbfilepwent: got line |%s|\n", linebuf));
365 if ((linebuf[0] == 0) && feof(fp)) {
366 DEBUG(4, ("getsmbfilepwent: end of file reached\n"));
371 * The line we have should be of the form :-
373 * username:uid:32hex bytes:[Account type]:LCT-12345678....other flags presently
378 * username:uid:32hex bytes:32hex bytes:[Account type]:LCT-12345678....ignored....
380 * if Windows NT compatible passwords are also present.
381 * [Account type] is an ascii encoding of the type of account.
382 * LCT-(8 hex digits) is the time_t value of the last change time.
385 if (linebuf[0] == '#' || linebuf[0] == '\0') {
386 DEBUG(6, ("getsmbfilepwent: skipping comment or blank line\n"));
389 p = (unsigned char *) strchr_m(linebuf, ':');
391 DEBUG(0, ("getsmbfilepwent: malformed password entry (no :)\n"));
396 * As 256 is shorter than a pstring we don't need to check
397 * length here - if this ever changes....
399 SMB_ASSERT(sizeof(pstring) > sizeof(linebuf));
401 strncpy(user_name, linebuf, PTR_DIFF(p, linebuf));
402 user_name[PTR_DIFF(p, linebuf)] = '\0';
406 p++; /* Go past ':' */
409 DEBUG(0, ("getsmbfilepwent: user name %s has a negative uid.\n", user_name));
414 DEBUG(0, ("getsmbfilepwent: malformed password entry for user %s (uid not number)\n",
419 uidval = atoi((char *) p);
421 while (*p && isdigit(*p)) {
426 DEBUG(0, ("getsmbfilepwent: malformed password entry for user %s (no : after uid)\n",
431 pw_buf->smb_name = user_name;
432 pw_buf->smb_userid = uidval;
435 * Now get the password value - this should be 32 hex digits
436 * which are the ascii representations of a 16 byte string.
437 * Get two at a time and put them into the password.
443 if (linebuf_len < (PTR_DIFF(p, linebuf) + 33)) {
444 DEBUG(0, ("getsmbfilepwent: malformed password entry for user %s (passwd too short)\n",
450 DEBUG(0, ("getsmbfilepwent: malformed password entry for user %s (no terminating :)\n",
455 if (strnequal((char *) p, "NO PASSWORD", 11)) {
456 pw_buf->smb_passwd = NULL;
457 pw_buf->acct_ctrl |= ACB_PWNOTREQ;
459 if (*p == '*' || *p == 'X') {
460 /* NULL LM password */
461 pw_buf->smb_passwd = NULL;
462 DEBUG(10, ("getsmbfilepwent: LM password for user %s invalidated\n", user_name));
463 } else if (pdb_gethexpwd((char *)p, smbpwd)) {
464 pw_buf->smb_passwd = smbpwd;
466 pw_buf->smb_passwd = NULL;
467 DEBUG(0, ("getsmbfilepwent: Malformed Lanman password entry for user %s \
468 (non hex chars)\n", user_name));
473 * Now check if the NT compatible password is
476 pw_buf->smb_nt_passwd = NULL;
477 p += 33; /* Move to the first character of the line after the lanman password. */
478 if ((linebuf_len >= (PTR_DIFF(p, linebuf) + 33)) && (p[32] == ':')) {
479 if (*p != '*' && *p != 'X') {
480 if(pdb_gethexpwd((char *)p,smbntpwd)) {
481 pw_buf->smb_nt_passwd = smbntpwd;
484 p += 33; /* Move to the first character of the line after the NT password. */
487 DEBUG(5,("getsmbfilepwent: returning passwd entry for user %s, uid %ld\n",
491 unsigned char *end_p = (unsigned char *)strchr_m((char *)p, ']');
492 pw_buf->acct_ctrl = pdb_decode_acct_ctrl((char*)p);
494 /* Must have some account type set. */
495 if(pw_buf->acct_ctrl == 0) {
496 pw_buf->acct_ctrl = ACB_NORMAL;
499 /* Now try and get the last change time. */
505 if(*p && (StrnCaseCmp((char *)p, "LCT-", 4)==0)) {
508 for(i = 0; i < 8; i++) {
509 if(p[i] == '\0' || !isxdigit(p[i])) {
515 * p points at 8 characters of hex digits -
516 * read into a time_t as the seconds since
517 * 1970 that the password was last changed.
519 pw_buf->pass_last_set_time = (time_t)strtol((char *)p, NULL, 16);
524 /* 'Old' style file. Fake up based on user name. */
526 * Currently trust accounts are kept in the same
527 * password file as 'normal accounts'. If this changes
528 * we will have to fix this code. JRA.
530 if(pw_buf->smb_name[strlen(pw_buf->smb_name) - 1] == '$') {
531 pw_buf->acct_ctrl &= ~ACB_NORMAL;
532 pw_buf->acct_ctrl |= ACB_WSTRUST;
539 DEBUG(5,("getsmbfilepwent: end of file reached.\n"));
543 /************************************************************************
544 Create a new smbpasswd entry - malloced space returned.
545 *************************************************************************/
547 static char *format_new_smbpasswd_entry(const struct smb_passwd *newpwd)
549 int new_entry_length;
553 new_entry_length = strlen(newpwd->smb_name) + 1 + 15 + 1 + 32 + 1 + 32 + 1 +
554 NEW_PW_FORMAT_SPACE_PADDED_LEN + 1 + 13 + 2;
556 if((new_entry = (char *)SMB_MALLOC( new_entry_length )) == NULL) {
557 DEBUG(0, ("format_new_smbpasswd_entry: Malloc failed adding entry for user %s.\n",
562 slprintf(new_entry, new_entry_length - 1, "%s:%u:", newpwd->smb_name, (unsigned)newpwd->smb_userid);
564 p = new_entry+strlen(new_entry);
565 pdb_sethexpwd(p, newpwd->smb_passwd, newpwd->acct_ctrl);
570 pdb_sethexpwd(p, newpwd->smb_nt_passwd, newpwd->acct_ctrl);
575 /* Add the account encoding and the last change time. */
576 slprintf((char *)p, new_entry_length - 1 - (p - new_entry), "%s:LCT-%08X:\n",
577 pdb_encode_acct_ctrl(newpwd->acct_ctrl, NEW_PW_FORMAT_SPACE_PADDED_LEN),
578 (uint32)newpwd->pass_last_set_time);
583 /************************************************************************
584 Routine to add an entry to the smbpasswd file.
585 *************************************************************************/
587 static NTSTATUS add_smbfilepwd_entry(struct smbpasswd_privates *smbpasswd_state,
588 struct smb_passwd *newpwd)
590 const char *pfile = smbpasswd_state->smbpasswd_file;
591 struct smb_passwd *pwd = NULL;
595 size_t new_entry_length;
599 /* Open the smbpassword file - for update. */
600 fp = startsmbfilepwent(pfile, PWF_UPDATE, &smbpasswd_state->pw_file_lock_depth);
602 if (fp == NULL && errno == ENOENT) {
603 /* Try again - create. */
604 fp = startsmbfilepwent(pfile, PWF_CREATE, &smbpasswd_state->pw_file_lock_depth);
608 DEBUG(0, ("add_smbfilepwd_entry: unable to open file.\n"));
609 return map_nt_error_from_unix(errno);
613 * Scan the file, a line at a time and check if the name matches.
616 while ((pwd = getsmbfilepwent(smbpasswd_state, fp)) != NULL) {
617 if (strequal(newpwd->smb_name, pwd->smb_name)) {
618 DEBUG(0, ("add_smbfilepwd_entry: entry with name %s already exists\n", pwd->smb_name));
619 endsmbfilepwent(fp, &smbpasswd_state->pw_file_lock_depth);
620 return NT_STATUS_USER_EXISTS;
624 /* Ok - entry doesn't exist. We can add it */
626 /* Create a new smb passwd entry and set it to the given password. */
628 * The add user write needs to be atomic - so get the fd from
629 * the fp and do a raw write() call.
633 if((offpos = sys_lseek(fd, 0, SEEK_END)) == -1) {
634 NTSTATUS result = map_nt_error_from_unix(errno);
635 DEBUG(0, ("add_smbfilepwd_entry(sys_lseek): Failed to add entry for user %s to file %s. \
636 Error was %s\n", newpwd->smb_name, pfile, strerror(errno)));
637 endsmbfilepwent(fp, &smbpasswd_state->pw_file_lock_depth);
641 if((new_entry = format_new_smbpasswd_entry(newpwd)) == NULL) {
642 DEBUG(0, ("add_smbfilepwd_entry(malloc): Failed to add entry for user %s to file %s. \
643 Error was %s\n", newpwd->smb_name, pfile, strerror(errno)));
644 endsmbfilepwent(fp, &smbpasswd_state->pw_file_lock_depth);
645 return NT_STATUS_NO_MEMORY;
648 new_entry_length = strlen(new_entry);
650 #ifdef DEBUG_PASSWORD
651 DEBUG(100, ("add_smbfilepwd_entry(%d): new_entry_len %d made line |%s|",
652 fd, (int)new_entry_length, new_entry));
655 if ((wr_len = write(fd, new_entry, new_entry_length)) != new_entry_length) {
656 NTSTATUS result = map_nt_error_from_unix(errno);
657 DEBUG(0, ("add_smbfilepwd_entry(write): %d Failed to add entry for user %s to file %s. \
658 Error was %s\n", wr_len, newpwd->smb_name, pfile, strerror(errno)));
660 /* Remove the entry we just wrote. */
661 if(sys_ftruncate(fd, offpos) == -1) {
662 DEBUG(0, ("add_smbfilepwd_entry: ERROR failed to ftruncate file %s. \
663 Error was %s. Password file may be corrupt ! Please examine by hand !\n",
664 newpwd->smb_name, strerror(errno)));
667 endsmbfilepwent(fp, &smbpasswd_state->pw_file_lock_depth);
673 endsmbfilepwent(fp, &smbpasswd_state->pw_file_lock_depth);
677 /************************************************************************
678 Routine to search the smbpasswd file for an entry matching the username.
679 and then modify its password entry. We can't use the startsmbpwent()/
680 getsmbpwent()/endsmbpwent() interfaces here as we depend on looking
681 in the actual file to decide how much room we have to write data.
682 override = False, normal
683 override = True, override XXXXXXXX'd out password or NO PASS
684 ************************************************************************/
686 static BOOL mod_smbfilepwd_entry(struct smbpasswd_privates *smbpasswd_state, const struct smb_passwd* pwd)
688 /* Static buffers we will return. */
697 unsigned char *p = NULL;
698 size_t linebuf_len = 0;
701 const char *pfile = smbpasswd_state->smbpasswd_file;
702 BOOL found_entry = False;
703 BOOL got_pass_last_set_time = False;
705 SMB_OFF_T pwd_seekpos = 0;
712 DEBUG(0, ("No SMB password file set\n"));
715 DEBUG(10, ("mod_smbfilepwd_entry: opening file %s\n", pfile));
717 fp = sys_fopen(pfile, "r+");
720 DEBUG(0, ("mod_smbfilepwd_entry: unable to open file %s\n", pfile));
723 /* Set a buffer to do more efficient reads */
724 setvbuf(fp, readbuf, _IOFBF, sizeof(readbuf));
728 if (!pw_file_lock(lockfd, F_WRLCK, 5, &smbpasswd_state->pw_file_lock_depth)) {
729 DEBUG(0, ("mod_smbfilepwd_entry: unable to lock file %s\n", pfile));
734 /* Make sure it is only rw by the owner */
737 /* We have a write lock on the file. */
739 * Scan the file, a line at a time and check if the name matches.
742 while (status && !feof(fp)) {
743 pwd_seekpos = sys_ftell(fp);
747 status = fgets(linebuf, sizeof(linebuf), fp);
748 if (status == NULL && ferror(fp)) {
749 pw_file_unlock(lockfd, &smbpasswd_state->pw_file_lock_depth);
755 * Check if the string is terminated with a newline - if not
756 * then we must keep reading and discard until we get one.
758 linebuf_len = strlen(linebuf);
759 if (linebuf[linebuf_len - 1] != '\n') {
761 while (!ferror(fp) && !feof(fp)) {
768 linebuf[linebuf_len - 1] = '\0';
771 #ifdef DEBUG_PASSWORD
772 DEBUG(100, ("mod_smbfilepwd_entry: got line |%s|\n", linebuf));
775 if ((linebuf[0] == 0) && feof(fp)) {
776 DEBUG(4, ("mod_smbfilepwd_entry: end of file reached\n"));
781 * The line we have should be of the form :-
783 * username:uid:[32hex bytes]:....other flags presently
788 * username:uid:[32hex bytes]:[32hex bytes]:[attributes]:LCT-XXXXXXXX:...ignored.
790 * if Windows NT compatible passwords are also present.
793 if (linebuf[0] == '#' || linebuf[0] == '\0') {
794 DEBUG(6, ("mod_smbfilepwd_entry: skipping comment or blank line\n"));
798 p = (unsigned char *) strchr_m(linebuf, ':');
801 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry (no :)\n"));
806 * As 256 is shorter than a pstring we don't need to check
807 * length here - if this ever changes....
810 SMB_ASSERT(sizeof(user_name) > sizeof(linebuf));
812 strncpy(user_name, linebuf, PTR_DIFF(p, linebuf));
813 user_name[PTR_DIFF(p, linebuf)] = '\0';
814 if (strequal(user_name, pwd->smb_name)) {
821 pw_file_unlock(lockfd, &smbpasswd_state->pw_file_lock_depth);
824 DEBUG(2, ("Cannot update entry for user %s, as they don't exist in the smbpasswd file!\n",
829 DEBUG(6, ("mod_smbfilepwd_entry: entry exists for user %s\n", pwd->smb_name));
831 /* User name matches - get uid and password */
832 p++; /* Go past ':' */
835 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (uid not number)\n",
837 pw_file_unlock(lockfd, &smbpasswd_state->pw_file_lock_depth);
842 while (*p && isdigit(*p)) {
846 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (no : after uid)\n",
848 pw_file_unlock(lockfd, &smbpasswd_state->pw_file_lock_depth);
854 * Now get the password value - this should be 32 hex digits
855 * which are the ascii representations of a 16 byte string.
856 * Get two at a time and put them into the password.
860 /* Record exact password position */
861 pwd_seekpos += PTR_DIFF(p, linebuf);
863 if (linebuf_len < (PTR_DIFF(p, linebuf) + 33)) {
864 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (passwd too short)\n",
866 pw_file_unlock(lockfd,&smbpasswd_state->pw_file_lock_depth);
872 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (no terminating :)\n",
874 pw_file_unlock(lockfd,&smbpasswd_state->pw_file_lock_depth);
879 /* Now check if the NT compatible password is available. */
880 p += 33; /* Move to the first character of the line after the lanman password. */
881 if (linebuf_len < (PTR_DIFF(p, linebuf) + 33)) {
882 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (passwd too short)\n",
884 pw_file_unlock(lockfd,&smbpasswd_state->pw_file_lock_depth);
890 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (no terminating :)\n",
892 pw_file_unlock(lockfd,&smbpasswd_state->pw_file_lock_depth);
898 * Now check if the account info and the password last
899 * change time is available.
901 p += 33; /* Move to the first character of the line after the NT password. */
905 encode_bits[i++] = *p++;
906 while((linebuf_len > PTR_DIFF(p, linebuf)) && (*p != ']')) {
907 encode_bits[i++] = *p++;
910 encode_bits[i++] = ']';
911 encode_bits[i++] = '\0';
913 if(i == NEW_PW_FORMAT_SPACE_PADDED_LEN) {
915 * We are using a new format, space padded
916 * acct ctrl field. Encode the given acct ctrl
919 fstrcpy(encode_bits, pdb_encode_acct_ctrl(pwd->acct_ctrl, NEW_PW_FORMAT_SPACE_PADDED_LEN));
921 DEBUG(0,("mod_smbfilepwd_entry: Using old smbpasswd format for user %s. \
922 This is no longer supported.!\n", pwd->smb_name));
923 DEBUG(0,("mod_smbfilepwd_entry: No changes made, failing.!\n"));
924 pw_file_unlock(lockfd, &smbpasswd_state->pw_file_lock_depth);
929 /* Go past the ']' */
930 if(linebuf_len > PTR_DIFF(p, linebuf)) {
934 if((linebuf_len > PTR_DIFF(p, linebuf)) && (*p == ':')) {
937 /* We should be pointing at the LCT entry. */
938 if((linebuf_len > (PTR_DIFF(p, linebuf) + 13)) && (StrnCaseCmp((char *)p, "LCT-", 4) == 0)) {
940 for(i = 0; i < 8; i++) {
941 if(p[i] == '\0' || !isxdigit(p[i])) {
947 * p points at 8 characters of hex digits -
948 * read into a time_t as the seconds since
949 * 1970 that the password was last changed.
951 got_pass_last_set_time = True;
953 } /* *p && StrnCaseCmp() */
957 /* Entry is correctly formed. */
959 /* Create the 32 byte representation of the new p16 */
960 pdb_sethexpwd(ascii_p16, pwd->smb_passwd, pwd->acct_ctrl);
962 /* Add on the NT md4 hash */
965 pdb_sethexpwd(ascii_p16+33, pwd->smb_nt_passwd, pwd->acct_ctrl);
967 ascii_p16[66] = '\0'; /* null-terminate the string so that strlen works */
969 /* Add on the account info bits and the time of last password change. */
970 if(got_pass_last_set_time) {
971 slprintf(&ascii_p16[strlen(ascii_p16)],
972 sizeof(ascii_p16)-(strlen(ascii_p16)+1),
974 encode_bits, (uint32)pwd->pass_last_set_time );
975 wr_len = strlen(ascii_p16);
978 #ifdef DEBUG_PASSWORD
979 DEBUG(100,("mod_smbfilepwd_entry: "));
980 dump_data(100, ascii_p16, wr_len);
983 if(wr_len > sizeof(linebuf)) {
984 DEBUG(0, ("mod_smbfilepwd_entry: line to write (%d) is too long.\n", wr_len+1));
985 pw_file_unlock(lockfd,&smbpasswd_state->pw_file_lock_depth);
991 * Do an atomic write into the file at the position defined by
995 /* The mod user write needs to be atomic - so get the fd from
996 the fp and do a raw write() call.
1001 if (sys_lseek(fd, pwd_seekpos - 1, SEEK_SET) != pwd_seekpos - 1) {
1002 DEBUG(0, ("mod_smbfilepwd_entry: seek fail on file %s.\n", pfile));
1003 pw_file_unlock(lockfd,&smbpasswd_state->pw_file_lock_depth);
1008 /* Sanity check - ensure the areas we are writing are framed by ':' */
1009 if (read(fd, linebuf, wr_len+1) != wr_len+1) {
1010 DEBUG(0, ("mod_smbfilepwd_entry: read fail on file %s.\n", pfile));
1011 pw_file_unlock(lockfd,&smbpasswd_state->pw_file_lock_depth);
1016 if ((linebuf[0] != ':') || (linebuf[wr_len] != ':')) {
1017 DEBUG(0, ("mod_smbfilepwd_entry: check on passwd file %s failed.\n", pfile));
1018 pw_file_unlock(lockfd,&smbpasswd_state->pw_file_lock_depth);
1023 if (sys_lseek(fd, pwd_seekpos, SEEK_SET) != pwd_seekpos) {
1024 DEBUG(0, ("mod_smbfilepwd_entry: seek fail on file %s.\n", pfile));
1025 pw_file_unlock(lockfd,&smbpasswd_state->pw_file_lock_depth);
1030 if (write(fd, ascii_p16, wr_len) != wr_len) {
1031 DEBUG(0, ("mod_smbfilepwd_entry: write failed in passwd file %s\n", pfile));
1032 pw_file_unlock(lockfd,&smbpasswd_state->pw_file_lock_depth);
1037 pw_file_unlock(lockfd,&smbpasswd_state->pw_file_lock_depth);
1042 /************************************************************************
1043 Routine to delete an entry in the smbpasswd file by name.
1044 *************************************************************************/
1046 static BOOL del_smbfilepwd_entry(struct smbpasswd_privates *smbpasswd_state, const char *name)
1048 const char *pfile = smbpasswd_state->smbpasswd_file;
1050 struct smb_passwd *pwd = NULL;
1052 FILE *fp_write = NULL;
1053 int pfile2_lockdepth = 0;
1055 slprintf(pfile2, sizeof(pfile2)-1, "%s.%u", pfile, (unsigned)sys_getpid() );
1058 * Open the smbpassword file - for update. It needs to be update
1059 * as we need any other processes to wait until we have replaced
1063 if((fp = startsmbfilepwent(pfile, PWF_UPDATE, &smbpasswd_state->pw_file_lock_depth)) == NULL) {
1064 DEBUG(0, ("del_smbfilepwd_entry: unable to open file %s.\n", pfile));
1069 * Create the replacement password file.
1071 if((fp_write = startsmbfilepwent(pfile2, PWF_CREATE, &pfile2_lockdepth)) == NULL) {
1072 DEBUG(0, ("del_smbfilepwd_entry: unable to open file %s.\n", pfile));
1073 endsmbfilepwent(fp, &smbpasswd_state->pw_file_lock_depth);
1078 * Scan the file, a line at a time and check if the name matches.
1081 while ((pwd = getsmbfilepwent(smbpasswd_state, fp)) != NULL) {
1083 size_t new_entry_length;
1085 if (strequal(name, pwd->smb_name)) {
1086 DEBUG(10, ("add_smbfilepwd_entry: found entry with name %s - deleting it.\n", name));
1091 * We need to copy the entry out into the second file.
1094 if((new_entry = format_new_smbpasswd_entry(pwd)) == NULL) {
1095 DEBUG(0, ("del_smbfilepwd_entry(malloc): Failed to copy entry for user %s to file %s. \
1096 Error was %s\n", pwd->smb_name, pfile2, strerror(errno)));
1098 endsmbfilepwent(fp, &smbpasswd_state->pw_file_lock_depth);
1099 endsmbfilepwent(fp_write, &pfile2_lockdepth);
1103 new_entry_length = strlen(new_entry);
1105 if(fwrite(new_entry, 1, new_entry_length, fp_write) != new_entry_length) {
1106 DEBUG(0, ("del_smbfilepwd_entry(write): Failed to copy entry for user %s to file %s. \
1107 Error was %s\n", pwd->smb_name, pfile2, strerror(errno)));
1109 endsmbfilepwent(fp, &smbpasswd_state->pw_file_lock_depth);
1110 endsmbfilepwent(fp_write, &pfile2_lockdepth);
1119 * Ensure pfile2 is flushed before rename.
1122 if(fflush(fp_write) != 0) {
1123 DEBUG(0, ("del_smbfilepwd_entry: Failed to flush file %s. Error was %s\n", pfile2, strerror(errno)));
1124 endsmbfilepwent(fp, &smbpasswd_state->pw_file_lock_depth);
1125 endsmbfilepwent(fp_write,&pfile2_lockdepth);
1130 * Do an atomic rename - then release the locks.
1133 if(rename(pfile2,pfile) != 0) {
1137 endsmbfilepwent(fp, &smbpasswd_state->pw_file_lock_depth);
1138 endsmbfilepwent(fp_write,&pfile2_lockdepth);
1142 /*********************************************************************
1143 Create a smb_passwd struct from a struct samu.
1144 We will not allocate any new memory. The smb_passwd struct
1145 should only stay around as long as the struct samu does.
1146 ********************************************************************/
1148 static BOOL build_smb_pass (struct smb_passwd *smb_pw, const struct samu *sampass)
1152 if (sampass == NULL)
1154 ZERO_STRUCTP(smb_pw);
1156 if (!IS_SAM_DEFAULT(sampass, PDB_USERSID)) {
1157 rid = pdb_get_user_rid(sampass);
1159 /* If the user specified a RID, make sure its able to be both stored and retreived */
1160 if (rid == DOMAIN_USER_RID_GUEST) {
1161 struct passwd *passwd = getpwnam_alloc(NULL, lp_guestaccount());
1163 DEBUG(0, ("Could not find guest account via getpwnam()! (%s)\n", lp_guestaccount()));
1166 smb_pw->smb_userid=passwd->pw_uid;
1167 TALLOC_FREE(passwd);
1168 } else if (algorithmic_pdb_rid_is_user(rid)) {
1169 smb_pw->smb_userid=algorithmic_pdb_user_rid_to_uid(rid);
1171 DEBUG(0,("build_sam_pass: Failing attempt to store user with non-uid based user RID. \n"));
1176 smb_pw->smb_name=(const char*)pdb_get_username(sampass);
1178 smb_pw->smb_passwd=pdb_get_lanman_passwd(sampass);
1179 smb_pw->smb_nt_passwd=pdb_get_nt_passwd(sampass);
1181 smb_pw->acct_ctrl=pdb_get_acct_ctrl(sampass);
1182 smb_pw->pass_last_set_time=pdb_get_pass_last_set_time(sampass);
1187 /*********************************************************************
1188 Create a struct samu from a smb_passwd struct
1189 ********************************************************************/
1191 static BOOL build_sam_account(struct smbpasswd_privates *smbpasswd_state,
1192 struct samu *sam_pass, const struct smb_passwd *pw_buf)
1194 struct passwd *pwfile;
1195 fstring unix_username;
1198 DEBUG(5,("build_sam_account: struct samu is NULL\n"));
1202 /* verify the user account exists */
1204 fstrcpy( unix_username, pw_buf->smb_name );
1205 strlower_m( unix_username );
1207 if ( !(pwfile = getpwnam_alloc(NULL, unix_username )) ) {
1208 DEBUG(0,("build_sam_account: smbpasswd database is corrupt! username %s with uid "
1209 "%u is not in unix passwd database!\n", pw_buf->smb_name, pw_buf->smb_userid));
1213 if ( !NT_STATUS_IS_OK( samu_set_unix(sam_pass, pwfile )) )
1216 TALLOC_FREE(pwfile);
1218 /* set remaining fields */
1220 pdb_set_nt_passwd (sam_pass, pw_buf->smb_nt_passwd, PDB_SET);
1221 pdb_set_lanman_passwd (sam_pass, pw_buf->smb_passwd, PDB_SET);
1222 pdb_set_acct_ctrl (sam_pass, pw_buf->acct_ctrl, PDB_SET);
1223 pdb_set_pass_last_set_time (sam_pass, pw_buf->pass_last_set_time, PDB_SET);
1224 pdb_set_pass_can_change_time (sam_pass, pw_buf->pass_last_set_time, PDB_SET);
1229 /*****************************************************************
1230 Functions to be implemented by the new passdb API
1231 ****************************************************************/
1233 static NTSTATUS smbpasswd_setsampwent (struct pdb_methods *my_methods, BOOL update, uint32 acb_mask)
1235 struct smbpasswd_privates *smbpasswd_state = (struct smbpasswd_privates*)my_methods->private_data;
1237 smbpasswd_state->pw_file = startsmbfilepwent(smbpasswd_state->smbpasswd_file,
1238 update ? PWF_UPDATE : PWF_READ,
1239 &(smbpasswd_state->pw_file_lock_depth));
1241 /* did we fail? Should we try to create it? */
1242 if (!smbpasswd_state->pw_file && update && errno == ENOENT) {
1244 /* slprintf(msg_str,msg_str_len-1,
1245 "smbpasswd file did not exist - attempting to create it.\n"); */
1246 DEBUG(0,("smbpasswd file did not exist - attempting to create it.\n"));
1247 fp = sys_fopen(smbpasswd_state->smbpasswd_file, "w");
1249 fprintf(fp, "# Samba SMB password file\n");
1253 smbpasswd_state->pw_file = startsmbfilepwent(smbpasswd_state->smbpasswd_file,
1254 update ? PWF_UPDATE : PWF_READ,
1255 &(smbpasswd_state->pw_file_lock_depth));
1258 if (smbpasswd_state->pw_file != NULL)
1259 return NT_STATUS_OK;
1261 return NT_STATUS_UNSUCCESSFUL;
1264 static void smbpasswd_endsampwent (struct pdb_methods *my_methods)
1266 struct smbpasswd_privates *smbpasswd_state = (struct smbpasswd_privates*)my_methods->private_data;
1267 endsmbfilepwent(smbpasswd_state->pw_file, &(smbpasswd_state->pw_file_lock_depth));
1270 /*****************************************************************
1271 ****************************************************************/
1273 static NTSTATUS smbpasswd_getsampwent(struct pdb_methods *my_methods, struct samu *user)
1275 NTSTATUS nt_status = NT_STATUS_UNSUCCESSFUL;
1276 struct smbpasswd_privates *smbpasswd_state = (struct smbpasswd_privates*)my_methods->private_data;
1277 struct smb_passwd *pw_buf=NULL;
1280 DEBUG(5,("pdb_getsampwent\n"));
1283 DEBUG(5,("pdb_getsampwent (smbpasswd): user is NULL\n"));
1288 /* do we have an entry? */
1289 pw_buf = getsmbfilepwent(smbpasswd_state, smbpasswd_state->pw_file);
1293 /* build the struct samu entry from the smb_passwd struct.
1294 We loop in case the user in the pdb does not exist in
1295 the local system password file */
1296 if (build_sam_account(smbpasswd_state, user, pw_buf))
1300 DEBUG(5,("getsampwent (smbpasswd): done\n"));
1303 return NT_STATUS_OK;
1306 /****************************************************************
1307 Search smbpasswd file by iterating over the entries. Do not
1308 call getpwnam() for unix account information until we have found
1310 ***************************************************************/
1312 static NTSTATUS smbpasswd_getsampwnam(struct pdb_methods *my_methods,
1313 struct samu *sam_acct, const char *username)
1315 NTSTATUS nt_status = NT_STATUS_UNSUCCESSFUL;
1316 struct smbpasswd_privates *smbpasswd_state = (struct smbpasswd_privates*)my_methods->private_data;
1317 struct smb_passwd *smb_pw;
1320 DEBUG(10, ("getsampwnam (smbpasswd): search by name: %s\n", username));
1322 /* startsmbfilepwent() is used here as we don't want to lookup
1323 the UNIX account in the local system password file until
1325 fp = startsmbfilepwent(smbpasswd_state->smbpasswd_file, PWF_READ, &(smbpasswd_state->pw_file_lock_depth));
1328 DEBUG(0, ("Unable to open passdb database.\n"));
1332 while ( ((smb_pw=getsmbfilepwent(smbpasswd_state, fp)) != NULL)&& (!strequal(smb_pw->smb_name, username)) )
1333 /* do nothing....another loop */ ;
1335 endsmbfilepwent(fp, &(smbpasswd_state->pw_file_lock_depth));
1338 /* did we locate the username in smbpasswd */
1342 DEBUG(10, ("getsampwnam (smbpasswd): found by name: %s\n", smb_pw->smb_name));
1345 DEBUG(10,("getsampwnam (smbpasswd): struct samu is NULL\n"));
1349 /* now build the struct samu */
1350 if (!build_sam_account(smbpasswd_state, sam_acct, smb_pw))
1354 return NT_STATUS_OK;
1357 static NTSTATUS smbpasswd_getsampwsid(struct pdb_methods *my_methods, struct samu *sam_acct, const DOM_SID *sid)
1359 NTSTATUS nt_status = NT_STATUS_UNSUCCESSFUL;
1360 struct smbpasswd_privates *smbpasswd_state = (struct smbpasswd_privates*)my_methods->private_data;
1361 struct smb_passwd *smb_pw;
1366 DEBUG(10, ("smbpasswd_getsampwrid: search by sid: %s\n", sid_to_string(sid_str, sid)));
1368 if (!sid_peek_check_rid(get_global_sam_sid(), sid, &rid))
1369 return NT_STATUS_UNSUCCESSFUL;
1371 /* More special case 'guest account' hacks... */
1372 if (rid == DOMAIN_USER_RID_GUEST) {
1373 const char *guest_account = lp_guestaccount();
1374 if (!(guest_account && *guest_account)) {
1375 DEBUG(1, ("Guest account not specfied!\n"));
1378 return smbpasswd_getsampwnam(my_methods, sam_acct, guest_account);
1381 /* Open the sam password file - not for update. */
1382 fp = startsmbfilepwent(smbpasswd_state->smbpasswd_file, PWF_READ, &(smbpasswd_state->pw_file_lock_depth));
1385 DEBUG(0, ("Unable to open passdb database.\n"));
1389 while ( ((smb_pw=getsmbfilepwent(smbpasswd_state, fp)) != NULL) && (algorithmic_pdb_uid_to_user_rid(smb_pw->smb_userid) != rid) )
1392 endsmbfilepwent(fp, &(smbpasswd_state->pw_file_lock_depth));
1395 /* did we locate the username in smbpasswd */
1399 DEBUG(10, ("getsampwrid (smbpasswd): found by name: %s\n", smb_pw->smb_name));
1402 DEBUG(10,("getsampwrid: (smbpasswd) struct samu is NULL\n"));
1406 /* now build the struct samu */
1407 if (!build_sam_account (smbpasswd_state, sam_acct, smb_pw))
1410 /* build_sam_account might change the SID on us, if the name was for the guest account */
1411 if (NT_STATUS_IS_OK(nt_status) && !sid_equal(pdb_get_user_sid(sam_acct), sid)) {
1412 fstring sid_string1, sid_string2;
1413 DEBUG(1, ("looking for user with sid %s instead returned %s for account %s!?!\n",
1414 sid_to_string(sid_string1, sid), sid_to_string(sid_string2, pdb_get_user_sid(sam_acct)), pdb_get_username(sam_acct)));
1415 return NT_STATUS_NO_SUCH_USER;
1419 return NT_STATUS_OK;
1422 static NTSTATUS smbpasswd_add_sam_account(struct pdb_methods *my_methods, struct samu *sampass)
1424 struct smbpasswd_privates *smbpasswd_state = (struct smbpasswd_privates*)my_methods->private_data;
1425 struct smb_passwd smb_pw;
1427 /* convert the struct samu */
1428 if (!build_smb_pass(&smb_pw, sampass)) {
1429 return NT_STATUS_UNSUCCESSFUL;
1433 return add_smbfilepwd_entry(smbpasswd_state, &smb_pw);
1436 static NTSTATUS smbpasswd_update_sam_account(struct pdb_methods *my_methods, struct samu *sampass)
1438 struct smbpasswd_privates *smbpasswd_state = (struct smbpasswd_privates*)my_methods->private_data;
1439 struct smb_passwd smb_pw;
1441 /* convert the struct samu */
1442 if (!build_smb_pass(&smb_pw, sampass)) {
1443 DEBUG(0, ("smbpasswd_update_sam_account: build_smb_pass failed!\n"));
1444 return NT_STATUS_UNSUCCESSFUL;
1447 /* update the entry */
1448 if(!mod_smbfilepwd_entry(smbpasswd_state, &smb_pw)) {
1449 DEBUG(0, ("smbpasswd_update_sam_account: mod_smbfilepwd_entry failed!\n"));
1450 return NT_STATUS_UNSUCCESSFUL;
1453 return NT_STATUS_OK;
1456 static NTSTATUS smbpasswd_delete_sam_account (struct pdb_methods *my_methods, struct samu *sampass)
1458 struct smbpasswd_privates *smbpasswd_state = (struct smbpasswd_privates*)my_methods->private_data;
1460 const char *username = pdb_get_username(sampass);
1462 if (del_smbfilepwd_entry(smbpasswd_state, username))
1463 return NT_STATUS_OK;
1465 return NT_STATUS_UNSUCCESSFUL;
1468 static NTSTATUS smbpasswd_rename_sam_account (struct pdb_methods *my_methods,
1469 struct samu *old_acct,
1470 const char *newname)
1472 pstring rename_script;
1473 struct samu *new_acct = NULL;
1474 BOOL interim_account = False;
1475 NTSTATUS ret = NT_STATUS_UNSUCCESSFUL;
1477 if (!*(lp_renameuser_script()))
1480 if ( !(new_acct = samu_new( NULL )) ) {
1481 return NT_STATUS_NO_MEMORY;
1484 if ( !pdb_copy_sam_account( new_acct, old_acct )
1485 || !pdb_set_username(new_acct, newname, PDB_CHANGED))
1490 ret = smbpasswd_add_sam_account(my_methods, new_acct);
1491 if (!NT_STATUS_IS_OK(ret))
1494 interim_account = True;
1496 /* rename the posix user */
1497 pstrcpy(rename_script, lp_renameuser_script());
1499 if (*rename_script) {
1502 string_sub2(rename_script, "%unew", newname, sizeof(pstring),
1504 string_sub2(rename_script, "%uold", pdb_get_username(old_acct),
1505 sizeof(pstring), True, False, True);
1507 rename_ret = smbrun(rename_script, NULL);
1509 DEBUG(rename_ret ? 0 : 3,("Running the command `%s' gave %d\n", rename_script, rename_ret));
1517 smbpasswd_delete_sam_account(my_methods, old_acct);
1518 interim_account = False;
1522 if (interim_account)
1523 smbpasswd_delete_sam_account(my_methods, new_acct);
1526 TALLOC_FREE(new_acct);
1531 static BOOL smbpasswd_rid_algorithm(struct pdb_methods *methods)
1536 static void free_private_data(void **vp)
1538 struct smbpasswd_privates **privates = (struct smbpasswd_privates**)vp;
1540 endsmbfilepwent((*privates)->pw_file, &((*privates)->pw_file_lock_depth));
1543 /* No need to free any further, as it is talloc()ed */
1546 static NTSTATUS pdb_init_smbpasswd( struct pdb_methods **pdb_method, const char *location )
1549 struct smbpasswd_privates *privates;
1551 if ( !NT_STATUS_IS_OK(nt_status = make_pdb_method( pdb_method )) ) {
1555 (*pdb_method)->name = "smbpasswd";
1557 (*pdb_method)->setsampwent = smbpasswd_setsampwent;
1558 (*pdb_method)->endsampwent = smbpasswd_endsampwent;
1559 (*pdb_method)->getsampwent = smbpasswd_getsampwent;
1560 (*pdb_method)->getsampwnam = smbpasswd_getsampwnam;
1561 (*pdb_method)->getsampwsid = smbpasswd_getsampwsid;
1562 (*pdb_method)->add_sam_account = smbpasswd_add_sam_account;
1563 (*pdb_method)->update_sam_account = smbpasswd_update_sam_account;
1564 (*pdb_method)->delete_sam_account = smbpasswd_delete_sam_account;
1565 (*pdb_method)->rename_sam_account = smbpasswd_rename_sam_account;
1567 (*pdb_method)->rid_algorithm = smbpasswd_rid_algorithm;
1569 /* Setup private data and free function */
1571 if ( !(privates = TALLOC_ZERO_P( *pdb_method, struct smbpasswd_privates )) ) {
1572 DEBUG(0, ("talloc() failed for smbpasswd private_data!\n"));
1573 return NT_STATUS_NO_MEMORY;
1576 /* Store some config details */
1579 privates->smbpasswd_file = talloc_strdup(*pdb_method, location);
1581 privates->smbpasswd_file = talloc_strdup(*pdb_method, lp_smb_passwd_file());
1584 if (!privates->smbpasswd_file) {
1585 DEBUG(0, ("talloc_strdp() failed for storing smbpasswd location!\n"));
1586 return NT_STATUS_NO_MEMORY;
1589 (*pdb_method)->private_data = privates;
1591 (*pdb_method)->free_private_data = free_private_data;
1593 return NT_STATUS_OK;
1596 NTSTATUS pdb_smbpasswd_init(void)
1598 return smb_register_passdb(PASSDB_INTERFACE_VERSION, "smbpasswd", pdb_init_smbpasswd);