Eric Andersen | 27f64e1 | 2002-06-23 04:24:25 +0000 | [diff] [blame] | 1 | /* vi: set sw=4 ts=4: */ |
| 2 | /* |
| 3 | * Copyright 1989 - 1991, Julianne Frances Haugh <jockgrrl@austin.rr.com> |
| 4 | * All rights reserved. |
| 5 | * |
| 6 | * Redistribution and use in source and binary forms, with or without |
| 7 | * modification, are permitted provided that the following conditions |
| 8 | * are met: |
| 9 | * 1. Redistributions of source code must retain the above copyright |
| 10 | * notice, this list of conditions and the following disclaimer. |
| 11 | * 2. Redistributions in binary form must reproduce the above copyright |
| 12 | * notice, this list of conditions and the following disclaimer in the |
| 13 | * documentation and/or other materials provided with the distribution. |
| 14 | * 3. Neither the name of Julianne F. Haugh nor the names of its contributors |
| 15 | * may be used to endorse or promote products derived from this software |
| 16 | * without specific prior written permission. |
| 17 | * |
| 18 | * THIS SOFTWARE IS PROVIDED BY JULIE HAUGH AND CONTRIBUTORS ``AS IS'' AND |
| 19 | * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE |
| 20 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE |
| 21 | * ARE DISCLAIMED. IN NO EVENT SHALL JULIE HAUGH OR CONTRIBUTORS BE LIABLE |
| 22 | * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL |
| 23 | * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS |
| 24 | * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) |
| 25 | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT |
| 26 | * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY |
| 27 | * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF |
| 28 | * SUCH DAMAGE. |
| 29 | */ |
| 30 | |
Eric Andersen | 27f64e1 | 2002-06-23 04:24:25 +0000 | [diff] [blame] | 31 | #include "libbb.h" |
| 32 | |
Eric Andersen | 27f64e1 | 2002-06-23 04:24:25 +0000 | [diff] [blame] | 33 | /* Ask the user for a password. |
maxwen | 27116ba | 2015-08-14 21:41:28 +0200 | [diff] [blame] | 34 | * Return 1 without asking if PW has an empty password. |
| 35 | * Return -1 on EOF, error while reading input, or timeout. |
Denis Vlasenko | 65e14b4 | 2007-06-08 15:27:06 +0000 | [diff] [blame] | 36 | * Return 1 if the user gives the correct password for entry PW, |
maxwen | 27116ba | 2015-08-14 21:41:28 +0200 | [diff] [blame] | 37 | * 0 if not. |
Denis Vlasenko | 65e14b4 | 2007-06-08 15:27:06 +0000 | [diff] [blame] | 38 | * |
maxwen | 27116ba | 2015-08-14 21:41:28 +0200 | [diff] [blame] | 39 | * NULL pw means "just fake it for login with bad username" |
| 40 | */ |
| 41 | int FAST_FUNC ask_and_check_password_extended(const struct passwd *pw, |
| 42 | int timeout, const char *prompt) |
Eric Andersen | 27f64e1 | 2002-06-23 04:24:25 +0000 | [diff] [blame] | 43 | { |
Denis Vlasenko | 5df955f | 2007-03-13 13:01:14 +0000 | [diff] [blame] | 44 | char *unencrypted, *encrypted; |
| 45 | const char *correct; |
Denis Vlasenko | fdddab0 | 2008-06-12 16:56:52 +0000 | [diff] [blame] | 46 | int r; |
Denis Vlasenko | 85532fc | 2007-06-16 14:16:30 +0000 | [diff] [blame] | 47 | /* fake salt. crypt() can choke otherwise. */ |
Bernhard Reutner-Fischer | 8672660 | 2007-06-15 08:30:33 +0000 | [diff] [blame] | 48 | correct = "aa"; |
Denis Vlasenko | ca525b4 | 2007-06-13 12:27:17 +0000 | [diff] [blame] | 49 | if (!pw) { |
Bernhard Reutner-Fischer | 8672660 | 2007-06-15 08:30:33 +0000 | [diff] [blame] | 50 | /* "aa" will never match */ |
Denis Vlasenko | ca525b4 | 2007-06-13 12:27:17 +0000 | [diff] [blame] | 51 | goto fake_it; |
| 52 | } |
Denis Vlasenko | 5df955f | 2007-03-13 13:01:14 +0000 | [diff] [blame] | 53 | correct = pw->pw_passwd; |
| 54 | #if ENABLE_FEATURE_SHADOWPASSWDS |
Tanguy Pruvot | 823694d | 2012-11-18 13:20:29 +0100 | [diff] [blame] | 55 | /* Using _r function to avoid pulling in static buffers */ |
Denis Vlasenko | e190c16 | 2007-07-03 06:15:42 +0000 | [diff] [blame] | 56 | if ((correct[0] == 'x' || correct[0] == '*') && !correct[1]) { |
Tanguy Pruvot | 823694d | 2012-11-18 13:20:29 +0100 | [diff] [blame] | 57 | struct spwd spw; |
| 58 | char buffer[256]; |
Denis Vlasenko | 15ca51e | 2007-10-29 19:25:45 +0000 | [diff] [blame] | 59 | /* getspnam_r may return 0 yet set result to NULL. |
| 60 | * At least glibc 2.4 does this. Be extra paranoid here. */ |
| 61 | struct spwd *result = NULL; |
Denis Vlasenko | 21765fa | 2008-06-13 20:44:05 +0000 | [diff] [blame] | 62 | r = getspnam_r(pw->pw_name, &spw, buffer, sizeof(buffer), &result); |
Denis Vlasenko | 15ca51e | 2007-10-29 19:25:45 +0000 | [diff] [blame] | 63 | correct = (r || !result) ? "aa" : result->sp_pwdp; |
Denis Vlasenko | 5df955f | 2007-03-13 13:01:14 +0000 | [diff] [blame] | 64 | } |
| 65 | #endif |
Eric Andersen | 27f64e1 | 2002-06-23 04:24:25 +0000 | [diff] [blame] | 66 | |
Denis Vlasenko | 54e19da | 2007-07-03 10:28:46 +0000 | [diff] [blame] | 67 | if (!correct[0]) /* empty password field? */ |
Eric Andersen | 27f64e1 | 2002-06-23 04:24:25 +0000 | [diff] [blame] | 68 | return 1; |
| 69 | |
Denis Vlasenko | 65e14b4 | 2007-06-08 15:27:06 +0000 | [diff] [blame] | 70 | fake_it: |
maxwen | 27116ba | 2015-08-14 21:41:28 +0200 | [diff] [blame] | 71 | unencrypted = bb_ask(STDIN_FILENO, timeout, prompt); |
Denis Vlasenko | a36a676 | 2006-09-23 13:11:49 +0000 | [diff] [blame] | 72 | if (!unencrypted) { |
maxwen | 27116ba | 2015-08-14 21:41:28 +0200 | [diff] [blame] | 73 | /* EOF (such as ^D) or error (such as ^C) or timeout */ |
| 74 | return -1; |
Eric Andersen | 27f64e1 | 2002-06-23 04:24:25 +0000 | [diff] [blame] | 75 | } |
Denis Vlasenko | 4ea83bf | 2008-06-12 16:55:59 +0000 | [diff] [blame] | 76 | encrypted = pw_encrypt(unencrypted, correct, 1); |
Denis Vlasenko | fdddab0 | 2008-06-12 16:56:52 +0000 | [diff] [blame] | 77 | r = (strcmp(encrypted, correct) == 0); |
| 78 | free(encrypted); |
maxwen | 27116ba | 2015-08-14 21:41:28 +0200 | [diff] [blame] | 79 | nuke_str(unencrypted); |
Denis Vlasenko | fdddab0 | 2008-06-12 16:56:52 +0000 | [diff] [blame] | 80 | return r; |
Eric Andersen | 27f64e1 | 2002-06-23 04:24:25 +0000 | [diff] [blame] | 81 | } |
maxwen | 27116ba | 2015-08-14 21:41:28 +0200 | [diff] [blame] | 82 | |
| 83 | int FAST_FUNC ask_and_check_password(const struct passwd *pw) |
| 84 | { |
| 85 | return ask_and_check_password_extended(pw, 0, "Password: "); |
| 86 | } |