#include <syslog.h>
#include <errno.h>
#include <fcntl.h>
+#include <time.h>
-#include "includes.h"
+#include "openbsd.h"
#include "doas.h"
static void __dead
permit(uid_t uid, gid_t *groups, int ngroups, const struct rule **lastr,
uid_t target, const char *cmd, const char **cmdargs)
{
- int i;
+ size_t i;
*lastr = NULL;
for (i = 0; i < nrules; i++) {
return rv;
}
+void
+authfail(int opt)
+{
+
+#ifdef DOAS_INSULTS
+ if (opt)
+ printf("%s\n", getinsult());
+#endif
+
+ errx(1, "Authentication failed");
+}
+
int
main(int argc, char **argv)
{
const char *cwd;
char **envp;
+ if (argc <= 0 || argv == NULL || argv[0] == NULL) {
+ fprintf(stderr, "doas: executed without argv\n");
+ exit(1);
+ }
+
setprogname("doas");
closefrom(STDERR_FILENO + 1);
errc(1, EPERM, NULL);
}
-#if defined(USE_SHADOW)
if (!(rule->options & NOPASS)) {
if (nflag)
- errx(1, "Authorization required");
+ errx(1, "Authentication required");
- shadowauth(mypw->pw_name, rule->options & PERSIST);
+ int ret = shadowauth(mypw->pw_name, rule->options & PERSIST);
+ if (ret == 5)
+ authfail(rule->options & INSULT);
}
-#elif !defined(USE_PAM)
- /* no authentication provider, only allow NOPASS rules */
- (void) nflag;
- if (!(rule->options & NOPASS))
- errx(1, "Authorization required");
-#endif
if ((p = getenv("PATH")) != NULL)
formerpath = strdup(p);
if (targpw == NULL)
errx(1, "no passwd entry for target");
-#if defined(USE_PAM)
- pamauth(targpw->pw_name, mypw->pw_name, !nflag, rule->options & NOPASS,
- rule->options & PERSIST);
-#endif
-
#ifdef HAVE_LOGIN_CAP_H
if (setusercontext(NULL, targpw, target, LOGIN_SETGROUP |
+ LOGIN_SETPATH |
LOGIN_SETPRIORITY | LOGIN_SETRESOURCES | LOGIN_SETUMASK |
LOGIN_SETUSER) != 0)
errx(1, "failed to set user context for target");
err(1, "initgroups");
if (setresuid(target, target, target) != 0)
err(1, "setresuid");
+ if (setenv("PATH", safepath, 1) == -1)
+ err(1, "failed to set PATH '%s'", safepath);
#endif
if (getcwd(cwdpath, sizeof(cwdpath)) == NULL)