2 * Copyright (c) 1999-2005, 2007-2011
3 * Todd C. Miller <Todd.Miller@courtesan.com>
5 * Permission to use, copy, modify, and distribute this software for any
6 * purpose with or without fee is hereby granted, provided that the above
7 * copyright notice and this permission notice appear in all copies.
9 * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10 * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11 * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12 * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13 * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14 * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15 * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
17 * Sponsored in part by the Defense Advanced Research Projects
18 * Agency (DARPA) and Air Force Research Laboratory, Air Force
19 * Materiel Command, USAF, under agreement number F39502-99-1-0512.
24 #include <sys/types.h>
25 #include <sys/param.h>
34 #endif /* STDC_HEADERS */
37 #endif /* HAVE_STRING_H */
40 #endif /* HAVE_STRINGS_H */
43 #endif /* HAVE_UNISTD_H */
52 * For converting between syslog numbers and strings.
59 #ifdef LOG_NFACILITIES
60 static struct strmap facilities[] = {
62 { "authpriv", LOG_AUTHPRIV },
65 { "daemon", LOG_DAEMON },
67 { "local0", LOG_LOCAL0 },
68 { "local1", LOG_LOCAL1 },
69 { "local2", LOG_LOCAL2 },
70 { "local3", LOG_LOCAL3 },
71 { "local4", LOG_LOCAL4 },
72 { "local5", LOG_LOCAL5 },
73 { "local6", LOG_LOCAL6 },
74 { "local7", LOG_LOCAL7 },
77 #endif /* LOG_NFACILITIES */
79 static struct strmap priorities[] = {
80 { "alert", LOG_ALERT },
82 { "debug", LOG_DEBUG },
83 { "emerg", LOG_EMERG },
86 { "notice", LOG_NOTICE },
87 { "warning", LOG_WARNING },
94 static int store_int(char *, struct sudo_defs_types *, int);
95 static int store_list(char *, struct sudo_defs_types *, int);
96 static int store_mode(char *, struct sudo_defs_types *, int);
97 static int store_str(char *, struct sudo_defs_types *, int);
98 static int store_syslogfac(char *, struct sudo_defs_types *, int);
99 static int store_syslogpri(char *, struct sudo_defs_types *, int);
100 static int store_tuple(char *, struct sudo_defs_types *, int);
101 static int store_uint(char *, struct sudo_defs_types *, int);
102 static int store_float(char *, struct sudo_defs_types *, int);
103 static void list_op(char *, size_t, struct sudo_defs_types *, enum list_ops);
104 static const char *logfac2str(int);
105 static const char *logpri2str(int);
108 * Table describing compile-time and run-time options.
110 #include <def_data.c>
113 * Print version and configure info.
118 struct sudo_defs_types *cur;
119 struct list_member *item;
120 struct def_values *def;
123 for (cur = sudo_defs_table; cur->name; cur++) {
126 switch (cur->type & T_MASK) {
129 sudo_printf(SUDO_CONV_INFO_MSG, "%s\n", desc);
132 if (cur->sd_un.str) {
133 sudo_printf(SUDO_CONV_INFO_MSG, desc, cur->sd_un.str);
134 sudo_printf(SUDO_CONV_INFO_MSG, "\n");
138 if (cur->sd_un.ival) {
139 sudo_printf(SUDO_CONV_INFO_MSG, desc,
140 logfac2str(cur->sd_un.ival));
141 sudo_printf(SUDO_CONV_INFO_MSG, "\n");
145 if (cur->sd_un.ival) {
146 sudo_printf(SUDO_CONV_INFO_MSG, desc,
147 logpri2str(cur->sd_un.ival));
148 sudo_printf(SUDO_CONV_INFO_MSG, "\n");
153 sudo_printf(SUDO_CONV_INFO_MSG, desc, cur->sd_un.ival);
154 sudo_printf(SUDO_CONV_INFO_MSG, "\n");
157 sudo_printf(SUDO_CONV_INFO_MSG, desc, cur->sd_un.fval);
158 sudo_printf(SUDO_CONV_INFO_MSG, "\n");
161 sudo_printf(SUDO_CONV_INFO_MSG, desc, cur->sd_un.mode);
162 sudo_printf(SUDO_CONV_INFO_MSG, "\n");
165 if (cur->sd_un.list) {
166 sudo_printf(SUDO_CONV_INFO_MSG, "%s\n", desc);
167 for (item = cur->sd_un.list; item; item = item->next) {
168 sudo_printf(SUDO_CONV_INFO_MSG,
169 "\t%s\n", item->value);
174 for (def = cur->values; def->sval; def++) {
175 if (cur->sd_un.ival == def->ival) {
176 sudo_printf(SUDO_CONV_INFO_MSG, desc, def->sval);
180 sudo_printf(SUDO_CONV_INFO_MSG, "\n");
188 * List each option along with its description.
193 struct sudo_defs_types *cur;
196 sudo_printf(SUDO_CONV_INFO_MSG,
197 _("Available options in a sudoers ``Defaults'' line:\n\n"));
198 for (cur = sudo_defs_table; cur->name; cur++) {
201 switch (cur->type & T_MASK) {
203 sudo_printf(SUDO_CONV_INFO_MSG,
204 _("%s: %s\n"), cur->name, desc);
207 p = strrchr(desc, ':');
209 while (p > desc && isspace((unsigned char)p[-1]))
211 sudo_printf(SUDO_CONV_INFO_MSG, _("%s: %.*s\n"),
212 cur->name, (int) (p - desc), desc);
214 sudo_printf(SUDO_CONV_INFO_MSG,
215 _("%s: %s\n"), cur->name, desc);
224 * Sets/clears an entry in the defaults structure
225 * If a variable that takes a value is used in a boolean
226 * context with op == 0, disable that variable.
227 * Eg. you may want to turn off logging to a file for some hosts.
228 * This is only meaningful for variables that are *optional*.
231 set_default(char *var, char *val, int op)
233 struct sudo_defs_types *cur;
236 for (cur = sudo_defs_table, num = 0; cur->name; cur++, num++) {
237 if (strcmp(var, cur->name) == 0)
241 warningx(_("unknown defaults entry `%s'"), var);
245 switch (cur->type & T_MASK) {
247 if (!store_syslogfac(val, cur, op)) {
249 warningx(_("value `%s' is invalid for option `%s'"),
252 warningx(_("no value specified for `%s'"), var);
257 if (!store_syslogpri(val, cur, op)) {
259 warningx(_("value `%s' is invalid for option `%s'"),
262 warningx(_("no value specified for `%s'"), var);
268 /* Check for bogus boolean usage or lack of a value. */
269 if (!ISSET(cur->type, T_BOOL) || op != FALSE) {
270 warningx(_("no value specified for `%s'"), var);
274 if (ISSET(cur->type, T_PATH) && val && *val != '/') {
275 warningx(_("values for `%s' must start with a '/'"), var);
278 if (!store_str(val, cur, op)) {
279 warningx(_("value `%s' is invalid for option `%s'"), val, var);
285 /* Check for bogus boolean usage or lack of a value. */
286 if (!ISSET(cur->type, T_BOOL) || op != FALSE) {
287 warningx(_("no value specified for `%s'"), var);
291 if (!store_int(val, cur, op)) {
292 warningx(_("value `%s' is invalid for option `%s'"), val, var);
298 /* Check for bogus boolean usage or lack of a value. */
299 if (!ISSET(cur->type, T_BOOL) || op != FALSE) {
300 warningx(_("no value specified for `%s'"), var);
304 if (!store_uint(val, cur, op)) {
305 warningx(_("value `%s' is invalid for option `%s'"), val, var);
311 /* Check for bogus boolean usage or lack of a value. */
312 if (!ISSET(cur->type, T_BOOL) || op != FALSE) {
313 warningx(_("no value specified for `%s'"), var);
317 if (!store_float(val, cur, op)) {
318 warningx(_("value `%s' is invalid for option `%s'"), val, var);
324 /* Check for bogus boolean usage or lack of a value. */
325 if (!ISSET(cur->type, T_BOOL) || op != FALSE) {
326 warningx(_("no value specified for `%s'"), var);
330 if (!store_mode(val, cur, op)) {
331 warningx(_("value `%s' is invalid for option `%s'"), val, var);
337 warningx(_("option `%s' does not take a value"), var);
340 cur->sd_un.flag = op;
344 /* Check for bogus boolean usage or lack of a value. */
345 if (!ISSET(cur->type, T_BOOL) || op != FALSE) {
346 warningx(_("no value specified for `%s'"), var);
350 if (!store_list(val, cur, op)) {
351 warningx(_("value `%s' is invalid for option `%s'"), val, var);
356 if (!val && !ISSET(cur->type, T_BOOL)) {
357 warningx(_("no value specified for `%s'"), var);
360 if (!store_tuple(val, cur, op)) {
361 warningx(_("value `%s' is invalid for option `%s'"), val, var);
371 * Set default options to compiled-in values.
372 * Any of these may be overridden at runtime by a "Defaults" file.
377 static int firsttime = 1;
378 struct sudo_defs_types *def;
380 /* Clear any old settings. */
382 for (def = sudo_defs_table; def->name; def++) {
383 switch (def->type & T_MASK) {
385 efree(def->sd_un.str);
386 def->sd_un.str = NULL;
389 list_op(NULL, 0, def, freeall);
392 zero_bytes(&def->sd_un, sizeof(def->sd_un));
396 /* First initialize the flags. */
397 #ifdef LONG_OTP_PROMPT
398 def_long_otp_prompt = TRUE;
400 #ifdef IGNORE_DOT_PATH
401 def_ignore_dot = TRUE;
403 #ifdef ALWAYS_SEND_MAIL
404 def_mail_always = TRUE;
406 #ifdef SEND_MAIL_WHEN_NO_USER
407 def_mail_no_user = TRUE;
409 #ifdef SEND_MAIL_WHEN_NO_HOST
410 def_mail_no_host = TRUE;
412 #ifdef SEND_MAIL_WHEN_NOT_OK
413 def_mail_no_perms = TRUE;
415 #ifndef NO_TTY_TICKETS
416 def_tty_tickets = TRUE;
421 #ifndef NO_AUTHENTICATION
422 def_authenticate = TRUE;
425 def_root_sudo = TRUE;
430 #ifdef SHELL_IF_NO_ARGS
431 def_shell_noargs = TRUE;
433 #ifdef SHELL_SETS_HOME
436 #ifndef DONT_LEAK_PATH_INFO
437 def_path_info = TRUE;
446 def_env_editor = TRUE;
448 #ifdef UMASK_OVERRIDE
449 def_umask_override = TRUE;
451 def_iolog_file = estrdup("%{seq}");
452 def_iolog_dir = estrdup(_PATH_SUDO_IO_LOGDIR);
453 def_sudoers_locale = estrdup("C");
454 def_env_reset = ENV_RESET;
455 def_set_logname = TRUE;
456 def_closefrom = STDERR_FILENO + 1;
458 /* Syslog options need special care since they both strings and ints */
459 #if (LOGGING & SLOG_SYSLOG)
460 (void) store_syslogfac(LOGFAC, &sudo_defs_table[I_SYSLOG], TRUE);
461 (void) store_syslogpri(PRI_SUCCESS, &sudo_defs_table[I_SYSLOG_GOODPRI],
463 (void) store_syslogpri(PRI_FAILURE, &sudo_defs_table[I_SYSLOG_BADPRI],
467 /* Password flags also have a string and integer component. */
468 (void) store_tuple("any", &sudo_defs_table[I_LISTPW], TRUE);
469 (void) store_tuple("all", &sudo_defs_table[I_VERIFYPW], TRUE);
471 /* Then initialize the int-like things. */
473 def_umask = SUDO_UMASK;
477 def_loglinelen = MAXLOGFILELEN;
478 def_timestamp_timeout = TIMEOUT;
479 def_passwd_timeout = PASSWORD_TIMEOUT;
480 def_passwd_tries = TRIES_FOR_PASSWORD;
482 def_compress_io = TRUE;
485 /* Now do the strings */
486 def_mailto = estrdup(MAILTO);
487 def_mailsub = estrdup(_(MAILSUBJECT));
488 def_badpass_message = estrdup(_(INCORRECT_PASSWORD));
489 def_timestampdir = estrdup(_PATH_SUDO_TIMEDIR);
490 def_passprompt = estrdup(_(PASSPROMPT));
491 def_runas_default = estrdup(RUNAS_DEFAULT);
492 #ifdef _PATH_SUDO_SENDMAIL
493 def_mailerpath = estrdup(_PATH_SUDO_SENDMAIL);
494 def_mailerflags = estrdup("-t");
496 #if (LOGGING & SLOG_FILE)
497 def_logfile = estrdup(_PATH_SUDO_LOGFILE);
500 def_exempt_group = estrdup(EXEMPTGROUP);
503 def_secure_path = estrdup(SECURE_PATH);
505 def_editor = estrdup(EDITOR);
508 /* Finally do the lists (currently just environment tables). */
515 * Update the defaults based on what was set by sudoers.
516 * Pass in an OR'd list of which default types to update.
519 update_defaults(int what)
521 struct defaults *def;
524 tq_foreach_fwd(&defaults, def) {
527 if (ISSET(what, SETDEF_GENERIC) &&
528 !set_default(def->var, def->val, def->op))
532 if (ISSET(what, SETDEF_USER) &&
533 userlist_matches(sudo_user.pw, &def->binding) == ALLOW &&
534 !set_default(def->var, def->val, def->op))
538 if (ISSET(what, SETDEF_RUNAS) &&
539 runaslist_matches(&def->binding, NULL) == ALLOW &&
540 !set_default(def->var, def->val, def->op))
544 if (ISSET(what, SETDEF_HOST) &&
545 hostlist_matches(&def->binding) == ALLOW &&
546 !set_default(def->var, def->val, def->op))
550 if (ISSET(what, SETDEF_CMND) &&
551 cmndlist_matches(&def->binding) == ALLOW &&
552 !set_default(def->var, def->val, def->op))
561 store_int(char *val, struct sudo_defs_types *def, int op)
569 l = strtol(val, &endp, 10);
572 /* XXX - should check against INT_MAX */
573 def->sd_un.ival = (int)l;
576 return def->callback(val);
581 store_uint(char *val, struct sudo_defs_types *def, int op)
589 l = strtol(val, &endp, 10);
590 if (*endp != '\0' || l < 0)
592 /* XXX - should check against INT_MAX */
593 def->sd_un.ival = (unsigned int)l;
596 return def->callback(val);
601 store_float(char *val, struct sudo_defs_types *def, int op)
607 def->sd_un.fval = 0.0;
609 d = strtod(val, &endp);
612 /* XXX - should check against HUGE_VAL */
616 return def->callback(val);
621 store_tuple(char *val, struct sudo_defs_types *def, int op)
623 struct def_values *v;
626 * Since enums are really just ints we store the value as an ival.
627 * In the future, there may be multiple enums for different tuple
628 * types we want to avoid and special knowledge of the tuple type.
629 * This does assume that the first entry in the tuple enum will
630 * be the equivalent to a boolean "false".
633 def->sd_un.ival = (op == FALSE) ? 0 : 1;
635 for (v = def->values; v->sval != NULL; v++) {
636 if (strcmp(v->sval, val) == 0) {
637 def->sd_un.ival = v->ival;
645 return def->callback(val);
650 store_str(char *val, struct sudo_defs_types *def, int op)
653 efree(def->sd_un.str);
655 def->sd_un.str = NULL;
657 def->sd_un.str = estrdup(val);
659 return def->callback(val);
664 store_list(char *str, struct sudo_defs_types *def, int op)
668 /* Remove all old members. */
669 if (op == FALSE || op == TRUE)
670 list_op(NULL, 0, def, freeall);
672 /* Split str into multiple space-separated words and act on each one. */
676 /* Remove leading blanks, if nothing but blanks we are done. */
677 for (start = end; isblank((unsigned char)*start); start++)
682 /* Find end position and perform operation. */
683 for (end = start; *end && !isblank((unsigned char)*end); end++)
685 list_op(start, end - start, def, op == '-' ? delete : add);
686 } while (*end++ != '\0');
692 store_syslogfac(char *val, struct sudo_defs_types *def, int op)
697 def->sd_un.ival = FALSE;
700 #ifdef LOG_NFACILITIES
703 for (fac = facilities; fac->name && strcmp(val, fac->name); fac++)
705 if (fac->name == NULL)
706 return FALSE; /* not found */
708 def->sd_un.ival = fac->num;
710 def->sd_un.ival = -1;
711 #endif /* LOG_NFACILITIES */
718 #ifdef LOG_NFACILITIES
721 for (fac = facilities; fac->name && fac->num != n; fac++)
726 #endif /* LOG_NFACILITIES */
730 store_syslogpri(char *val, struct sudo_defs_types *def, int op)
734 if (op == FALSE || !val)
737 for (pri = priorities; pri->name && strcmp(val, pri->name); pri++)
739 if (pri->name == NULL)
740 return FALSE; /* not found */
742 def->sd_un.ival = pri->num;
751 for (pri = priorities; pri->name && pri->num != n; pri++)
757 store_mode(char *val, struct sudo_defs_types *def, int op)
763 def->sd_un.mode = (mode_t)0777;
765 l = strtol(val, &endp, 8);
766 if (*endp != '\0' || l < 0 || l > 0777)
768 def->sd_un.mode = (mode_t)l;
771 return def->callback(val);
776 list_op(char *val, size_t len, struct sudo_defs_types *def, enum list_ops op)
778 struct list_member *cur, *prev, *tmp;
781 for (cur = def->sd_un.list; cur; ) {
787 def->sd_un.list = NULL;
791 for (cur = def->sd_un.list, prev = NULL; cur; prev = cur, cur = cur->next) {
792 if ((strncmp(cur->value, val, len) == 0 && cur->value[len] == '\0')) {
795 return; /* already exists */
799 prev->next = cur->next;
801 def->sd_un.list = cur->next;
808 /* Add new node to the head of the list. */
810 cur = emalloc(sizeof(struct list_member));
811 cur->value = emalloc(len + 1);
812 (void) memcpy(cur->value, val, len);
813 cur->value[len] = '\0';
814 cur->next = def->sd_un.list;
815 def->sd_un.list = cur;