2 * Unix SMB/CIFS implementation.
3 * SMB parameters and setup
4 * Copyright (C) Andrew Tridgell 1992-1998
5 * Modified by Jeremy Allison 1995.
6 * Modified by Gerald (Jerry) Carter 2000-2001,2003
7 * Modified by Andrew Bartlett 2002.
9 * This program is free software; you can redistribute it and/or modify it under
10 * the terms of the GNU General Public License as published by the Free
11 * Software Foundation; either version 2 of the License, or (at your option)
14 * This program is distributed in the hope that it will be useful, but WITHOUT
15 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
16 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
19 * You should have received a copy of the GNU General Public License along with
20 * this program; if not, write to the Free Software Foundation, Inc., 675
21 * Mass Ave, Cambridge, MA 02139, USA.
27 #define DBGC_CLASS DBGC_PASSDB
30 smb_passwd is analogous to sam_passwd used everywhere
31 else. However, smb_passwd is limited to the information
32 stored by an smbpasswd entry
37 uint32 smb_userid
; /* this is actually the unix uid_t */
38 const char *smb_name
; /* username string */
40 const unsigned char *smb_passwd
; /* Null if no password */
41 const unsigned char *smb_nt_passwd
; /* Null if no password */
43 uint16 acct_ctrl
; /* account info (ACB_xxxx bit-mask) */
44 time_t pass_last_set_time
; /* password last set time */
47 struct smbpasswd_privates
49 /* used for maintain locks on the smbpasswd file */
50 int pw_file_lock_depth
;
52 /* Global File pointer */
55 /* formerly static variables */
56 struct smb_passwd pw_buf
;
58 unsigned char smbpwd
[16];
59 unsigned char smbntpwd
[16];
61 /* retrive-once info */
62 const char *smbpasswd_file
;
65 enum pwf_access_type
{ PWF_READ
, PWF_UPDATE
, PWF_CREATE
};
67 static SIG_ATOMIC_T gotalarm
;
69 /***************************************************************
70 Signal function to tell us we timed out.
71 ****************************************************************/
73 static void gotalarm_sig(void)
78 /***************************************************************
79 Lock or unlock a fd for a known lock type. Abandon after waitsecs
81 ****************************************************************/
83 static BOOL
do_file_lock(int fd
, int waitsecs
, int type
)
85 SMB_STRUCT_FLOCK lock
;
87 void (*oldsig_handler
)(int);
90 oldsig_handler
= CatchSignal(SIGALRM
, SIGNAL_CAST gotalarm_sig
);
93 lock
.l_whence
= SEEK_SET
;
99 /* Note we must *NOT* use sys_fcntl here ! JRA */
100 ret
= fcntl(fd
, SMB_F_SETLKW
, &lock
);
102 CatchSignal(SIGALRM
, SIGNAL_CAST oldsig_handler
);
105 DEBUG(0, ("do_file_lock: failed to %s file.\n",
106 type
== F_UNLCK
? "unlock" : "lock"));
113 /***************************************************************
114 Lock an fd. Abandon after waitsecs seconds.
115 ****************************************************************/
117 static BOOL
pw_file_lock(int fd
, int type
, int secs
, int *plock_depth
)
123 if(*plock_depth
== 0) {
124 if (!do_file_lock(fd
, secs
, type
)) {
125 DEBUG(10,("pw_file_lock: locking file failed, error = %s.\n",
136 /***************************************************************
137 Unlock an fd. Abandon after waitsecs seconds.
138 ****************************************************************/
140 static BOOL
pw_file_unlock(int fd
, int *plock_depth
)
144 if (fd
== 0 || *plock_depth
== 0) {
148 if(*plock_depth
== 1) {
149 ret
= do_file_lock(fd
, 5, F_UNLCK
);
152 if (*plock_depth
> 0) {
157 DEBUG(10,("pw_file_unlock: unlocking file failed, error = %s.\n",
163 /**************************************************************
164 Intialize a smb_passwd struct
165 *************************************************************/
167 static void pdb_init_smb(struct smb_passwd
*user
)
173 user
->pass_last_set_time
= (time_t)0;
176 /***************************************************************
177 Internal fn to enumerate the smbpasswd list. Returns a void pointer
178 to ensure no modification outside this module. Checks for atomic
179 rename of smbpasswd file on update or create once the lock has
180 been granted to prevent race conditions. JRA.
181 ****************************************************************/
183 static FILE *startsmbfilepwent(const char *pfile
, enum pwf_access_type type
, int *lock_depth
)
186 const char *open_mode
= NULL
;
188 int lock_type
= F_RDLCK
;
191 DEBUG(0, ("startsmbfilepwent: No SMB password file set\n"));
206 * Ensure atomic file creation.
211 for(i
= 0; i
< 5; i
++) {
212 if((fd
= sys_open(pfile
, O_CREAT
|O_TRUNC
|O_EXCL
|O_RDWR
, 0600))!=-1) {
215 sys_usleep(200); /* Spin, spin... */
218 DEBUG(0,("startsmbfilepwent_internal: too many race conditions \
219 creating file %s\n", pfile
));
229 for(race_loop
= 0; race_loop
< 5; race_loop
++) {
230 DEBUG(10, ("startsmbfilepwent_internal: opening file %s\n", pfile
));
232 if((fp
= sys_fopen(pfile
, open_mode
)) == NULL
) {
235 * If smbpasswd file doesn't exist, then create new one. This helps to avoid
236 * confusing error msg when adding user account first time.
238 if (errno
== ENOENT
) {
239 if ((fp
= sys_fopen(pfile
, "a+")) != NULL
) {
240 DEBUG(0, ("startsmbfilepwent_internal: file %s did not \
241 exist. File successfully created.\n", pfile
));
243 DEBUG(0, ("startsmbfilepwent_internal: file %s did not \
244 exist. Couldn't create new one. Error was: %s",
245 pfile
, strerror(errno
)));
249 DEBUG(0, ("startsmbfilepwent_internal: unable to open file %s. \
250 Error was: %s\n", pfile
, strerror(errno
)));
255 if (!pw_file_lock(fileno(fp
), lock_type
, 5, lock_depth
)) {
256 DEBUG(0, ("startsmbfilepwent_internal: unable to lock file %s. \
257 Error was %s\n", pfile
, strerror(errno
) ));
263 * Only check for replacement races on update or create.
264 * For read we don't mind if the data is one record out of date.
267 if(type
== PWF_READ
) {
270 SMB_STRUCT_STAT sbuf1
, sbuf2
;
273 * Avoid the potential race condition between the open and the lock
274 * by doing a stat on the filename and an fstat on the fd. If the
275 * two inodes differ then someone did a rename between the open and
276 * the lock. Back off and try the open again. Only do this 5 times to
277 * prevent infinate loops. JRA.
280 if (sys_stat(pfile
,&sbuf1
) != 0) {
281 DEBUG(0, ("startsmbfilepwent_internal: unable to stat file %s. \
282 Error was %s\n", pfile
, strerror(errno
)));
283 pw_file_unlock(fileno(fp
), lock_depth
);
288 if (sys_fstat(fileno(fp
),&sbuf2
) != 0) {
289 DEBUG(0, ("startsmbfilepwent_internal: unable to fstat file %s. \
290 Error was %s\n", pfile
, strerror(errno
)));
291 pw_file_unlock(fileno(fp
), lock_depth
);
296 if( sbuf1
.st_ino
== sbuf2
.st_ino
) {
302 * Race occurred - back off and try again...
305 pw_file_unlock(fileno(fp
), lock_depth
);
311 DEBUG(0, ("startsmbfilepwent_internal: too many race conditions opening file %s\n", pfile
));
315 /* Set a buffer to do more efficient reads */
316 setvbuf(fp
, (char *)NULL
, _IOFBF
, 1024);
318 /* Make sure it is only rw by the owner */
320 if(fchmod(fileno(fp
), S_IRUSR
|S_IWUSR
) == -1) {
322 if(chmod(pfile
, S_IRUSR
|S_IWUSR
) == -1) {
324 DEBUG(0, ("startsmbfilepwent_internal: failed to set 0600 permissions on password file %s. \
325 Error was %s\n.", pfile
, strerror(errno
) ));
326 pw_file_unlock(fileno(fp
), lock_depth
);
331 /* We have a lock on the file. */
335 /***************************************************************
336 End enumeration of the smbpasswd list.
337 ****************************************************************/
339 static void endsmbfilepwent(FILE *fp
, int *lock_depth
)
345 pw_file_unlock(fileno(fp
), lock_depth
);
347 DEBUG(7, ("endsmbfilepwent_internal: closed password file.\n"));
350 /*************************************************************************
351 Routine to return the next entry in the smbpasswd list.
352 *************************************************************************/
354 static struct smb_passwd
*getsmbfilepwent(struct smbpasswd_privates
*smbpasswd_state
, FILE *fp
)
356 /* Static buffers we will return. */
357 struct smb_passwd
*pw_buf
= &smbpasswd_state
->pw_buf
;
358 char *user_name
= smbpasswd_state
->user_name
;
359 unsigned char *smbpwd
= smbpasswd_state
->smbpwd
;
360 unsigned char *smbntpwd
= smbpasswd_state
->smbntpwd
;
369 DEBUG(0,("getsmbfilepwent: Bad password file pointer.\n"));
373 pdb_init_smb(pw_buf
);
374 pw_buf
->acct_ctrl
= ACB_NORMAL
;
377 * Scan the file, a line at a time and check if the name matches.
380 while (status
&& !feof(fp
)) {
383 status
= fgets(linebuf
, 256, fp
);
384 if (status
== NULL
&& ferror(fp
)) {
389 * Check if the string is terminated with a newline - if not
390 * then we must keep reading and discard until we get one.
392 if ((linebuf_len
= strlen(linebuf
)) == 0) {
396 if (linebuf
[linebuf_len
- 1] != '\n') {
398 while (!ferror(fp
) && !feof(fp
)) {
405 linebuf
[linebuf_len
- 1] = '\0';
408 #ifdef DEBUG_PASSWORD
409 DEBUG(100, ("getsmbfilepwent: got line |%s|\n", linebuf
));
411 if ((linebuf
[0] == 0) && feof(fp
)) {
412 DEBUG(4, ("getsmbfilepwent: end of file reached\n"));
417 * The line we have should be of the form :-
419 * username:uid:32hex bytes:[Account type]:LCT-12345678....other flags presently
424 * username:uid:32hex bytes:32hex bytes:[Account type]:LCT-12345678....ignored....
426 * if Windows NT compatible passwords are also present.
427 * [Account type] is an ascii encoding of the type of account.
428 * LCT-(8 hex digits) is the time_t value of the last change time.
431 if (linebuf
[0] == '#' || linebuf
[0] == '\0') {
432 DEBUG(6, ("getsmbfilepwent: skipping comment or blank line\n"));
435 p
= (unsigned char *) strchr_m(linebuf
, ':');
437 DEBUG(0, ("getsmbfilepwent: malformed password entry (no :)\n"));
442 * As 256 is shorter than a pstring we don't need to check
443 * length here - if this ever changes....
445 SMB_ASSERT(sizeof(pstring
) > sizeof(linebuf
));
447 strncpy(user_name
, linebuf
, PTR_DIFF(p
, linebuf
));
448 user_name
[PTR_DIFF(p
, linebuf
)] = '\0';
452 p
++; /* Go past ':' */
455 DEBUG(0, ("getsmbfilepwent: user name %s has a negative uid.\n", user_name
));
460 DEBUG(0, ("getsmbfilepwent: malformed password entry for user %s (uid not number)\n",
465 uidval
= atoi((char *) p
);
467 while (*p
&& isdigit(*p
)) {
472 DEBUG(0, ("getsmbfilepwent: malformed password entry for user %s (no : after uid)\n",
477 pw_buf
->smb_name
= user_name
;
478 pw_buf
->smb_userid
= uidval
;
481 * Now get the password value - this should be 32 hex digits
482 * which are the ascii representations of a 16 byte string.
483 * Get two at a time and put them into the password.
489 if (linebuf_len
< (PTR_DIFF(p
, linebuf
) + 33)) {
490 DEBUG(0, ("getsmbfilepwent: malformed password entry for user %s (passwd too short)\n",
496 DEBUG(0, ("getsmbfilepwent: malformed password entry for user %s (no terminating :)\n",
501 if (strnequal((char *) p
, "NO PASSWORD", 11)) {
502 pw_buf
->smb_passwd
= NULL
;
503 pw_buf
->acct_ctrl
|= ACB_PWNOTREQ
;
505 if (*p
== '*' || *p
== 'X') {
506 /* NULL LM password */
507 pw_buf
->smb_passwd
= NULL
;
508 DEBUG(10, ("getsmbfilepwent: LM password for user %s invalidated\n", user_name
));
509 } else if (pdb_gethexpwd((char *)p
, smbpwd
)) {
510 pw_buf
->smb_passwd
= smbpwd
;
512 pw_buf
->smb_passwd
= NULL
;
513 DEBUG(0, ("getsmbfilepwent: Malformed Lanman password entry for user %s \
514 (non hex chars)\n", user_name
));
519 * Now check if the NT compatible password is
522 pw_buf
->smb_nt_passwd
= NULL
;
523 p
+= 33; /* Move to the first character of the line after the lanman password. */
524 if ((linebuf_len
>= (PTR_DIFF(p
, linebuf
) + 33)) && (p
[32] == ':')) {
525 if (*p
!= '*' && *p
!= 'X') {
526 if(pdb_gethexpwd((char *)p
,smbntpwd
)) {
527 pw_buf
->smb_nt_passwd
= smbntpwd
;
530 p
+= 33; /* Move to the first character of the line after the NT password. */
533 DEBUG(5,("getsmbfilepwent: returning passwd entry for user %s, uid %ld\n",
537 unsigned char *end_p
= (unsigned char *)strchr_m((char *)p
, ']');
538 pw_buf
->acct_ctrl
= pdb_decode_acct_ctrl((char*)p
);
540 /* Must have some account type set. */
541 if(pw_buf
->acct_ctrl
== 0) {
542 pw_buf
->acct_ctrl
= ACB_NORMAL
;
545 /* Now try and get the last change time. */
551 if(*p
&& (StrnCaseCmp((char *)p
, "LCT-", 4)==0)) {
554 for(i
= 0; i
< 8; i
++) {
555 if(p
[i
] == '\0' || !isxdigit(p
[i
])) {
561 * p points at 8 characters of hex digits -
562 * read into a time_t as the seconds since
563 * 1970 that the password was last changed.
565 pw_buf
->pass_last_set_time
= (time_t)strtol((char *)p
, NULL
, 16);
570 /* 'Old' style file. Fake up based on user name. */
572 * Currently trust accounts are kept in the same
573 * password file as 'normal accounts'. If this changes
574 * we will have to fix this code. JRA.
576 if(pw_buf
->smb_name
[strlen(pw_buf
->smb_name
) - 1] == '$') {
577 pw_buf
->acct_ctrl
&= ~ACB_NORMAL
;
578 pw_buf
->acct_ctrl
|= ACB_WSTRUST
;
585 DEBUG(5,("getsmbfilepwent: end of file reached.\n"));
589 /************************************************************************
590 Create a new smbpasswd entry - malloced space returned.
591 *************************************************************************/
593 static char *format_new_smbpasswd_entry(const struct smb_passwd
*newpwd
)
595 int new_entry_length
;
599 new_entry_length
= strlen(newpwd
->smb_name
) + 1 + 15 + 1 + 32 + 1 + 32 + 1 +
600 NEW_PW_FORMAT_SPACE_PADDED_LEN
+ 1 + 13 + 2;
602 if((new_entry
= (char *)SMB_MALLOC( new_entry_length
)) == NULL
) {
603 DEBUG(0, ("format_new_smbpasswd_entry: Malloc failed adding entry for user %s.\n",
608 slprintf(new_entry
, new_entry_length
- 1, "%s:%u:", newpwd
->smb_name
, (unsigned)newpwd
->smb_userid
);
610 p
= new_entry
+strlen(new_entry
);
611 pdb_sethexpwd(p
, newpwd
->smb_passwd
, newpwd
->acct_ctrl
);
616 pdb_sethexpwd(p
, newpwd
->smb_nt_passwd
, newpwd
->acct_ctrl
);
621 /* Add the account encoding and the last change time. */
622 slprintf((char *)p
, new_entry_length
- 1 - (p
- new_entry
), "%s:LCT-%08X:\n",
623 pdb_encode_acct_ctrl(newpwd
->acct_ctrl
, NEW_PW_FORMAT_SPACE_PADDED_LEN
),
624 (uint32
)newpwd
->pass_last_set_time
);
629 /************************************************************************
630 Routine to add an entry to the smbpasswd file.
631 *************************************************************************/
633 static NTSTATUS
add_smbfilepwd_entry(struct smbpasswd_privates
*smbpasswd_state
,
634 struct smb_passwd
*newpwd
)
636 const char *pfile
= smbpasswd_state
->smbpasswd_file
;
637 struct smb_passwd
*pwd
= NULL
;
641 size_t new_entry_length
;
645 /* Open the smbpassword file - for update. */
646 fp
= startsmbfilepwent(pfile
, PWF_UPDATE
, &smbpasswd_state
->pw_file_lock_depth
);
648 if (fp
== NULL
&& errno
== ENOENT
) {
649 /* Try again - create. */
650 fp
= startsmbfilepwent(pfile
, PWF_CREATE
, &smbpasswd_state
->pw_file_lock_depth
);
654 DEBUG(0, ("add_smbfilepwd_entry: unable to open file.\n"));
655 return map_nt_error_from_unix(errno
);
659 * Scan the file, a line at a time and check if the name matches.
662 while ((pwd
= getsmbfilepwent(smbpasswd_state
, fp
)) != NULL
) {
663 if (strequal(newpwd
->smb_name
, pwd
->smb_name
)) {
664 DEBUG(0, ("add_smbfilepwd_entry: entry with name %s already exists\n", pwd
->smb_name
));
665 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
666 return NT_STATUS_USER_EXISTS
;
670 /* Ok - entry doesn't exist. We can add it */
672 /* Create a new smb passwd entry and set it to the given password. */
674 * The add user write needs to be atomic - so get the fd from
675 * the fp and do a raw write() call.
679 if((offpos
= sys_lseek(fd
, 0, SEEK_END
)) == -1) {
680 NTSTATUS result
= map_nt_error_from_unix(errno
);
681 DEBUG(0, ("add_smbfilepwd_entry(sys_lseek): Failed to add entry for user %s to file %s. \
682 Error was %s\n", newpwd
->smb_name
, pfile
, strerror(errno
)));
683 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
687 if((new_entry
= format_new_smbpasswd_entry(newpwd
)) == NULL
) {
688 DEBUG(0, ("add_smbfilepwd_entry(malloc): Failed to add entry for user %s to file %s. \
689 Error was %s\n", newpwd
->smb_name
, pfile
, strerror(errno
)));
690 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
691 return NT_STATUS_NO_MEMORY
;
694 new_entry_length
= strlen(new_entry
);
696 #ifdef DEBUG_PASSWORD
697 DEBUG(100, ("add_smbfilepwd_entry(%d): new_entry_len %d made line |%s|",
698 fd
, (int)new_entry_length
, new_entry
));
701 if ((wr_len
= write(fd
, new_entry
, new_entry_length
)) != new_entry_length
) {
702 NTSTATUS result
= map_nt_error_from_unix(errno
);
703 DEBUG(0, ("add_smbfilepwd_entry(write): %d Failed to add entry for user %s to file %s. \
704 Error was %s\n", wr_len
, newpwd
->smb_name
, pfile
, strerror(errno
)));
706 /* Remove the entry we just wrote. */
707 if(sys_ftruncate(fd
, offpos
) == -1) {
708 DEBUG(0, ("add_smbfilepwd_entry: ERROR failed to ftruncate file %s. \
709 Error was %s. Password file may be corrupt ! Please examine by hand !\n",
710 newpwd
->smb_name
, strerror(errno
)));
713 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
719 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
723 /************************************************************************
724 Routine to search the smbpasswd file for an entry matching the username.
725 and then modify its password entry. We can't use the startsmbpwent()/
726 getsmbpwent()/endsmbpwent() interfaces here as we depend on looking
727 in the actual file to decide how much room we have to write data.
728 override = False, normal
729 override = True, override XXXXXXXX'd out password or NO PASS
730 ************************************************************************/
732 static BOOL
mod_smbfilepwd_entry(struct smbpasswd_privates
*smbpasswd_state
, const struct smb_passwd
* pwd
)
734 /* Static buffers we will return. */
743 unsigned char *p
= NULL
;
744 size_t linebuf_len
= 0;
747 const char *pfile
= smbpasswd_state
->smbpasswd_file
;
748 BOOL found_entry
= False
;
749 BOOL got_pass_last_set_time
= False
;
751 SMB_OFF_T pwd_seekpos
= 0;
758 DEBUG(0, ("No SMB password file set\n"));
761 DEBUG(10, ("mod_smbfilepwd_entry: opening file %s\n", pfile
));
763 fp
= sys_fopen(pfile
, "r+");
766 DEBUG(0, ("mod_smbfilepwd_entry: unable to open file %s\n", pfile
));
769 /* Set a buffer to do more efficient reads */
770 setvbuf(fp
, readbuf
, _IOFBF
, sizeof(readbuf
));
774 if (!pw_file_lock(lockfd
, F_WRLCK
, 5, &smbpasswd_state
->pw_file_lock_depth
)) {
775 DEBUG(0, ("mod_smbfilepwd_entry: unable to lock file %s\n", pfile
));
780 /* Make sure it is only rw by the owner */
783 /* We have a write lock on the file. */
785 * Scan the file, a line at a time and check if the name matches.
788 while (status
&& !feof(fp
)) {
789 pwd_seekpos
= sys_ftell(fp
);
793 status
= fgets(linebuf
, sizeof(linebuf
), fp
);
794 if (status
== NULL
&& ferror(fp
)) {
795 pw_file_unlock(lockfd
, &smbpasswd_state
->pw_file_lock_depth
);
801 * Check if the string is terminated with a newline - if not
802 * then we must keep reading and discard until we get one.
804 linebuf_len
= strlen(linebuf
);
805 if (linebuf
[linebuf_len
- 1] != '\n') {
807 while (!ferror(fp
) && !feof(fp
)) {
814 linebuf
[linebuf_len
- 1] = '\0';
817 #ifdef DEBUG_PASSWORD
818 DEBUG(100, ("mod_smbfilepwd_entry: got line |%s|\n", linebuf
));
821 if ((linebuf
[0] == 0) && feof(fp
)) {
822 DEBUG(4, ("mod_smbfilepwd_entry: end of file reached\n"));
827 * The line we have should be of the form :-
829 * username:uid:[32hex bytes]:....other flags presently
834 * username:uid:[32hex bytes]:[32hex bytes]:[attributes]:LCT-XXXXXXXX:...ignored.
836 * if Windows NT compatible passwords are also present.
839 if (linebuf
[0] == '#' || linebuf
[0] == '\0') {
840 DEBUG(6, ("mod_smbfilepwd_entry: skipping comment or blank line\n"));
844 p
= (unsigned char *) strchr_m(linebuf
, ':');
847 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry (no :)\n"));
852 * As 256 is shorter than a pstring we don't need to check
853 * length here - if this ever changes....
856 SMB_ASSERT(sizeof(user_name
) > sizeof(linebuf
));
858 strncpy(user_name
, linebuf
, PTR_DIFF(p
, linebuf
));
859 user_name
[PTR_DIFF(p
, linebuf
)] = '\0';
860 if (strequal(user_name
, pwd
->smb_name
)) {
867 pw_file_unlock(lockfd
, &smbpasswd_state
->pw_file_lock_depth
);
870 DEBUG(2, ("Cannot update entry for user %s, as they don't exist in the smbpasswd file!\n",
875 DEBUG(6, ("mod_smbfilepwd_entry: entry exists for user %s\n", pwd
->smb_name
));
877 /* User name matches - get uid and password */
878 p
++; /* Go past ':' */
881 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (uid not number)\n",
883 pw_file_unlock(lockfd
, &smbpasswd_state
->pw_file_lock_depth
);
888 while (*p
&& isdigit(*p
)) {
892 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (no : after uid)\n",
894 pw_file_unlock(lockfd
, &smbpasswd_state
->pw_file_lock_depth
);
900 * Now get the password value - this should be 32 hex digits
901 * which are the ascii representations of a 16 byte string.
902 * Get two at a time and put them into the password.
906 /* Record exact password position */
907 pwd_seekpos
+= PTR_DIFF(p
, linebuf
);
909 if (linebuf_len
< (PTR_DIFF(p
, linebuf
) + 33)) {
910 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (passwd too short)\n",
912 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
918 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (no terminating :)\n",
920 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
925 /* Now check if the NT compatible password is available. */
926 p
+= 33; /* Move to the first character of the line after the lanman password. */
927 if (linebuf_len
< (PTR_DIFF(p
, linebuf
) + 33)) {
928 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (passwd too short)\n",
930 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
936 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (no terminating :)\n",
938 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
944 * Now check if the account info and the password last
945 * change time is available.
947 p
+= 33; /* Move to the first character of the line after the NT password. */
951 encode_bits
[i
++] = *p
++;
952 while((linebuf_len
> PTR_DIFF(p
, linebuf
)) && (*p
!= ']')) {
953 encode_bits
[i
++] = *p
++;
956 encode_bits
[i
++] = ']';
957 encode_bits
[i
++] = '\0';
959 if(i
== NEW_PW_FORMAT_SPACE_PADDED_LEN
) {
961 * We are using a new format, space padded
962 * acct ctrl field. Encode the given acct ctrl
965 fstrcpy(encode_bits
, pdb_encode_acct_ctrl(pwd
->acct_ctrl
, NEW_PW_FORMAT_SPACE_PADDED_LEN
));
967 DEBUG(0,("mod_smbfilepwd_entry: Using old smbpasswd format for user %s. \
968 This is no longer supported.!\n", pwd
->smb_name
));
969 DEBUG(0,("mod_smbfilepwd_entry: No changes made, failing.!\n"));
970 pw_file_unlock(lockfd
, &smbpasswd_state
->pw_file_lock_depth
);
975 /* Go past the ']' */
976 if(linebuf_len
> PTR_DIFF(p
, linebuf
)) {
980 if((linebuf_len
> PTR_DIFF(p
, linebuf
)) && (*p
== ':')) {
983 /* We should be pointing at the LCT entry. */
984 if((linebuf_len
> (PTR_DIFF(p
, linebuf
) + 13)) && (StrnCaseCmp((char *)p
, "LCT-", 4) == 0)) {
986 for(i
= 0; i
< 8; i
++) {
987 if(p
[i
] == '\0' || !isxdigit(p
[i
])) {
993 * p points at 8 characters of hex digits -
994 * read into a time_t as the seconds since
995 * 1970 that the password was last changed.
997 got_pass_last_set_time
= True
;
999 } /* *p && StrnCaseCmp() */
1003 /* Entry is correctly formed. */
1005 /* Create the 32 byte representation of the new p16 */
1006 pdb_sethexpwd(ascii_p16
, pwd
->smb_passwd
, pwd
->acct_ctrl
);
1008 /* Add on the NT md4 hash */
1009 ascii_p16
[32] = ':';
1011 pdb_sethexpwd(ascii_p16
+33, pwd
->smb_nt_passwd
, pwd
->acct_ctrl
);
1012 ascii_p16
[65] = ':';
1013 ascii_p16
[66] = '\0'; /* null-terminate the string so that strlen works */
1015 /* Add on the account info bits and the time of last password change. */
1016 if(got_pass_last_set_time
) {
1017 slprintf(&ascii_p16
[strlen(ascii_p16
)],
1018 sizeof(ascii_p16
)-(strlen(ascii_p16
)+1),
1020 encode_bits
, (uint32
)pwd
->pass_last_set_time
);
1021 wr_len
= strlen(ascii_p16
);
1024 #ifdef DEBUG_PASSWORD
1025 DEBUG(100,("mod_smbfilepwd_entry: "));
1026 dump_data(100, ascii_p16
, wr_len
);
1029 if(wr_len
> sizeof(linebuf
)) {
1030 DEBUG(0, ("mod_smbfilepwd_entry: line to write (%d) is too long.\n", wr_len
+1));
1031 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1037 * Do an atomic write into the file at the position defined by
1041 /* The mod user write needs to be atomic - so get the fd from
1042 the fp and do a raw write() call.
1047 if (sys_lseek(fd
, pwd_seekpos
- 1, SEEK_SET
) != pwd_seekpos
- 1) {
1048 DEBUG(0, ("mod_smbfilepwd_entry: seek fail on file %s.\n", pfile
));
1049 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1054 /* Sanity check - ensure the areas we are writing are framed by ':' */
1055 if (read(fd
, linebuf
, wr_len
+1) != wr_len
+1) {
1056 DEBUG(0, ("mod_smbfilepwd_entry: read fail on file %s.\n", pfile
));
1057 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1062 if ((linebuf
[0] != ':') || (linebuf
[wr_len
] != ':')) {
1063 DEBUG(0, ("mod_smbfilepwd_entry: check on passwd file %s failed.\n", pfile
));
1064 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1069 if (sys_lseek(fd
, pwd_seekpos
, SEEK_SET
) != pwd_seekpos
) {
1070 DEBUG(0, ("mod_smbfilepwd_entry: seek fail on file %s.\n", pfile
));
1071 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1076 if (write(fd
, ascii_p16
, wr_len
) != wr_len
) {
1077 DEBUG(0, ("mod_smbfilepwd_entry: write failed in passwd file %s\n", pfile
));
1078 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1083 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1088 /************************************************************************
1089 Routine to delete an entry in the smbpasswd file by name.
1090 *************************************************************************/
1092 static BOOL
del_smbfilepwd_entry(struct smbpasswd_privates
*smbpasswd_state
, const char *name
)
1094 const char *pfile
= smbpasswd_state
->smbpasswd_file
;
1096 struct smb_passwd
*pwd
= NULL
;
1098 FILE *fp_write
= NULL
;
1099 int pfile2_lockdepth
= 0;
1101 slprintf(pfile2
, sizeof(pfile2
)-1, "%s.%u", pfile
, (unsigned)sys_getpid() );
1104 * Open the smbpassword file - for update. It needs to be update
1105 * as we need any other processes to wait until we have replaced
1109 if((fp
= startsmbfilepwent(pfile
, PWF_UPDATE
, &smbpasswd_state
->pw_file_lock_depth
)) == NULL
) {
1110 DEBUG(0, ("del_smbfilepwd_entry: unable to open file %s.\n", pfile
));
1115 * Create the replacement password file.
1117 if((fp_write
= startsmbfilepwent(pfile2
, PWF_CREATE
, &pfile2_lockdepth
)) == NULL
) {
1118 DEBUG(0, ("del_smbfilepwd_entry: unable to open file %s.\n", pfile
));
1119 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
1124 * Scan the file, a line at a time and check if the name matches.
1127 while ((pwd
= getsmbfilepwent(smbpasswd_state
, fp
)) != NULL
) {
1129 size_t new_entry_length
;
1131 if (strequal(name
, pwd
->smb_name
)) {
1132 DEBUG(10, ("add_smbfilepwd_entry: found entry with name %s - deleting it.\n", name
));
1137 * We need to copy the entry out into the second file.
1140 if((new_entry
= format_new_smbpasswd_entry(pwd
)) == NULL
) {
1141 DEBUG(0, ("del_smbfilepwd_entry(malloc): Failed to copy entry for user %s to file %s. \
1142 Error was %s\n", pwd
->smb_name
, pfile2
, strerror(errno
)));
1144 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
1145 endsmbfilepwent(fp_write
, &pfile2_lockdepth
);
1149 new_entry_length
= strlen(new_entry
);
1151 if(fwrite(new_entry
, 1, new_entry_length
, fp_write
) != new_entry_length
) {
1152 DEBUG(0, ("del_smbfilepwd_entry(write): Failed to copy entry for user %s to file %s. \
1153 Error was %s\n", pwd
->smb_name
, pfile2
, strerror(errno
)));
1155 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
1156 endsmbfilepwent(fp_write
, &pfile2_lockdepth
);
1165 * Ensure pfile2 is flushed before rename.
1168 if(fflush(fp_write
) != 0) {
1169 DEBUG(0, ("del_smbfilepwd_entry: Failed to flush file %s. Error was %s\n", pfile2
, strerror(errno
)));
1170 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
1171 endsmbfilepwent(fp_write
,&pfile2_lockdepth
);
1176 * Do an atomic rename - then release the locks.
1179 if(rename(pfile2
,pfile
) != 0) {
1183 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
1184 endsmbfilepwent(fp_write
,&pfile2_lockdepth
);
1188 /*********************************************************************
1189 Create a smb_passwd struct from a struct samu.
1190 We will not allocate any new memory. The smb_passwd struct
1191 should only stay around as long as the struct samu does.
1192 ********************************************************************/
1194 static BOOL
build_smb_pass (struct smb_passwd
*smb_pw
, const struct samu
*sampass
)
1198 if (sampass
== NULL
)
1200 ZERO_STRUCTP(smb_pw
);
1202 if (!IS_SAM_DEFAULT(sampass
, PDB_USERSID
)) {
1203 rid
= pdb_get_user_rid(sampass
);
1205 /* If the user specified a RID, make sure its able to be both stored and retreived */
1206 if (rid
== DOMAIN_USER_RID_GUEST
) {
1207 struct passwd
*passwd
= getpwnam_alloc(NULL
, lp_guestaccount());
1209 DEBUG(0, ("Could not find guest account via getpwnam()! (%s)\n", lp_guestaccount()));
1212 smb_pw
->smb_userid
=passwd
->pw_uid
;
1213 TALLOC_FREE(passwd
);
1214 } else if (algorithmic_pdb_rid_is_user(rid
)) {
1215 smb_pw
->smb_userid
=algorithmic_pdb_user_rid_to_uid(rid
);
1217 DEBUG(0,("build_sam_pass: Failing attempt to store user with non-uid based user RID. \n"));
1222 smb_pw
->smb_name
=(const char*)pdb_get_username(sampass
);
1224 smb_pw
->smb_passwd
=pdb_get_lanman_passwd(sampass
);
1225 smb_pw
->smb_nt_passwd
=pdb_get_nt_passwd(sampass
);
1227 smb_pw
->acct_ctrl
=pdb_get_acct_ctrl(sampass
);
1228 smb_pw
->pass_last_set_time
=pdb_get_pass_last_set_time(sampass
);
1233 /*********************************************************************
1234 Create a struct samu from a smb_passwd struct
1235 ********************************************************************/
1237 static BOOL
build_sam_account(struct smbpasswd_privates
*smbpasswd_state
,
1238 struct samu
*sam_pass
, const struct smb_passwd
*pw_buf
)
1240 struct passwd
*pwfile
;
1241 fstring unix_username
;
1244 DEBUG(5,("build_sam_account: struct samu is NULL\n"));
1248 /* verify the user account exists */
1250 fstrcpy( unix_username
, pw_buf
->smb_name
);
1251 strlower_m( unix_username
);
1253 if ( !(pwfile
= getpwnam_alloc(NULL
, unix_username
)) ) {
1254 DEBUG(0,("build_sam_account: smbpasswd database is corrupt! username %s with uid "
1255 "%u is not in unix passwd database!\n", pw_buf
->smb_name
, pw_buf
->smb_userid
));
1259 if ( !NT_STATUS_IS_OK( samu_set_unix(sam_pass
, pwfile
)) )
1262 TALLOC_FREE(pwfile
);
1264 /* set remaining fields */
1266 pdb_set_nt_passwd (sam_pass
, pw_buf
->smb_nt_passwd
, PDB_SET
);
1267 pdb_set_lanman_passwd (sam_pass
, pw_buf
->smb_passwd
, PDB_SET
);
1268 pdb_set_acct_ctrl (sam_pass
, pw_buf
->acct_ctrl
, PDB_SET
);
1269 pdb_set_pass_last_set_time (sam_pass
, pw_buf
->pass_last_set_time
, PDB_SET
);
1270 pdb_set_pass_can_change_time (sam_pass
, pw_buf
->pass_last_set_time
, PDB_SET
);
1275 /*****************************************************************
1276 Functions to be implemented by the new passdb API
1277 ****************************************************************/
1279 static NTSTATUS
smbpasswd_setsampwent (struct pdb_methods
*my_methods
, BOOL update
, uint32 acb_mask
)
1281 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1283 smbpasswd_state
->pw_file
= startsmbfilepwent(smbpasswd_state
->smbpasswd_file
,
1284 update
? PWF_UPDATE
: PWF_READ
,
1285 &(smbpasswd_state
->pw_file_lock_depth
));
1287 /* did we fail? Should we try to create it? */
1288 if (!smbpasswd_state
->pw_file
&& update
&& errno
== ENOENT
) {
1290 /* slprintf(msg_str,msg_str_len-1,
1291 "smbpasswd file did not exist - attempting to create it.\n"); */
1292 DEBUG(0,("smbpasswd file did not exist - attempting to create it.\n"));
1293 fp
= sys_fopen(smbpasswd_state
->smbpasswd_file
, "w");
1295 fprintf(fp
, "# Samba SMB password file\n");
1299 smbpasswd_state
->pw_file
= startsmbfilepwent(smbpasswd_state
->smbpasswd_file
,
1300 update
? PWF_UPDATE
: PWF_READ
,
1301 &(smbpasswd_state
->pw_file_lock_depth
));
1304 if (smbpasswd_state
->pw_file
!= NULL
)
1305 return NT_STATUS_OK
;
1307 return NT_STATUS_UNSUCCESSFUL
;
1310 static void smbpasswd_endsampwent (struct pdb_methods
*my_methods
)
1312 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1313 endsmbfilepwent(smbpasswd_state
->pw_file
, &(smbpasswd_state
->pw_file_lock_depth
));
1316 /*****************************************************************
1317 ****************************************************************/
1319 static NTSTATUS
smbpasswd_getsampwent(struct pdb_methods
*my_methods
, struct samu
*user
)
1321 NTSTATUS nt_status
= NT_STATUS_UNSUCCESSFUL
;
1322 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1323 struct smb_passwd
*pw_buf
=NULL
;
1326 DEBUG(5,("pdb_getsampwent\n"));
1329 DEBUG(5,("pdb_getsampwent (smbpasswd): user is NULL\n"));
1334 /* do we have an entry? */
1335 pw_buf
= getsmbfilepwent(smbpasswd_state
, smbpasswd_state
->pw_file
);
1339 /* build the struct samu entry from the smb_passwd struct.
1340 We loop in case the user in the pdb does not exist in
1341 the local system password file */
1342 if (build_sam_account(smbpasswd_state
, user
, pw_buf
))
1346 DEBUG(5,("getsampwent (smbpasswd): done\n"));
1349 return NT_STATUS_OK
;
1352 /****************************************************************
1353 Search smbpasswd file by iterating over the entries. Do not
1354 call getpwnam() for unix account information until we have found
1356 ***************************************************************/
1358 static NTSTATUS
smbpasswd_getsampwnam(struct pdb_methods
*my_methods
,
1359 struct samu
*sam_acct
, const char *username
)
1361 NTSTATUS nt_status
= NT_STATUS_UNSUCCESSFUL
;
1362 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1363 struct smb_passwd
*smb_pw
;
1366 DEBUG(10, ("getsampwnam (smbpasswd): search by name: %s\n", username
));
1368 /* startsmbfilepwent() is used here as we don't want to lookup
1369 the UNIX account in the local system password file until
1371 fp
= startsmbfilepwent(smbpasswd_state
->smbpasswd_file
, PWF_READ
, &(smbpasswd_state
->pw_file_lock_depth
));
1374 DEBUG(0, ("Unable to open passdb database.\n"));
1378 while ( ((smb_pw
=getsmbfilepwent(smbpasswd_state
, fp
)) != NULL
)&& (!strequal(smb_pw
->smb_name
, username
)) )
1379 /* do nothing....another loop */ ;
1381 endsmbfilepwent(fp
, &(smbpasswd_state
->pw_file_lock_depth
));
1384 /* did we locate the username in smbpasswd */
1388 DEBUG(10, ("getsampwnam (smbpasswd): found by name: %s\n", smb_pw
->smb_name
));
1391 DEBUG(10,("getsampwnam (smbpasswd): struct samu is NULL\n"));
1395 /* now build the struct samu */
1396 if (!build_sam_account(smbpasswd_state
, sam_acct
, smb_pw
))
1400 return NT_STATUS_OK
;
1403 static NTSTATUS
smbpasswd_getsampwsid(struct pdb_methods
*my_methods
, struct samu
*sam_acct
, const DOM_SID
*sid
)
1405 NTSTATUS nt_status
= NT_STATUS_UNSUCCESSFUL
;
1406 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1407 struct smb_passwd
*smb_pw
;
1412 DEBUG(10, ("smbpasswd_getsampwrid: search by sid: %s\n", sid_to_string(sid_str
, sid
)));
1414 if (!sid_peek_check_rid(get_global_sam_sid(), sid
, &rid
))
1415 return NT_STATUS_UNSUCCESSFUL
;
1417 /* More special case 'guest account' hacks... */
1418 if (rid
== DOMAIN_USER_RID_GUEST
) {
1419 const char *guest_account
= lp_guestaccount();
1420 if (!(guest_account
&& *guest_account
)) {
1421 DEBUG(1, ("Guest account not specfied!\n"));
1424 return smbpasswd_getsampwnam(my_methods
, sam_acct
, guest_account
);
1427 /* Open the sam password file - not for update. */
1428 fp
= startsmbfilepwent(smbpasswd_state
->smbpasswd_file
, PWF_READ
, &(smbpasswd_state
->pw_file_lock_depth
));
1431 DEBUG(0, ("Unable to open passdb database.\n"));
1435 while ( ((smb_pw
=getsmbfilepwent(smbpasswd_state
, fp
)) != NULL
) && (algorithmic_pdb_uid_to_user_rid(smb_pw
->smb_userid
) != rid
) )
1438 endsmbfilepwent(fp
, &(smbpasswd_state
->pw_file_lock_depth
));
1441 /* did we locate the username in smbpasswd */
1445 DEBUG(10, ("getsampwrid (smbpasswd): found by name: %s\n", smb_pw
->smb_name
));
1448 DEBUG(10,("getsampwrid: (smbpasswd) struct samu is NULL\n"));
1452 /* now build the struct samu */
1453 if (!build_sam_account (smbpasswd_state
, sam_acct
, smb_pw
))
1456 /* build_sam_account might change the SID on us, if the name was for the guest account */
1457 if (NT_STATUS_IS_OK(nt_status
) && !sid_equal(pdb_get_user_sid(sam_acct
), sid
)) {
1458 fstring sid_string1
, sid_string2
;
1459 DEBUG(1, ("looking for user with sid %s instead returned %s for account %s!?!\n",
1460 sid_to_string(sid_string1
, sid
), sid_to_string(sid_string2
, pdb_get_user_sid(sam_acct
)), pdb_get_username(sam_acct
)));
1461 return NT_STATUS_NO_SUCH_USER
;
1465 return NT_STATUS_OK
;
1468 static NTSTATUS
smbpasswd_add_sam_account(struct pdb_methods
*my_methods
, struct samu
*sampass
)
1470 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1471 struct smb_passwd smb_pw
;
1473 /* convert the struct samu */
1474 if (!build_smb_pass(&smb_pw
, sampass
)) {
1475 return NT_STATUS_UNSUCCESSFUL
;
1479 return add_smbfilepwd_entry(smbpasswd_state
, &smb_pw
);
1482 static NTSTATUS
smbpasswd_update_sam_account(struct pdb_methods
*my_methods
, struct samu
*sampass
)
1484 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1485 struct smb_passwd smb_pw
;
1487 /* convert the struct samu */
1488 if (!build_smb_pass(&smb_pw
, sampass
)) {
1489 DEBUG(0, ("smbpasswd_update_sam_account: build_smb_pass failed!\n"));
1490 return NT_STATUS_UNSUCCESSFUL
;
1493 /* update the entry */
1494 if(!mod_smbfilepwd_entry(smbpasswd_state
, &smb_pw
)) {
1495 DEBUG(0, ("smbpasswd_update_sam_account: mod_smbfilepwd_entry failed!\n"));
1496 return NT_STATUS_UNSUCCESSFUL
;
1499 return NT_STATUS_OK
;
1502 static NTSTATUS
smbpasswd_delete_sam_account (struct pdb_methods
*my_methods
, struct samu
*sampass
)
1504 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1506 const char *username
= pdb_get_username(sampass
);
1508 if (del_smbfilepwd_entry(smbpasswd_state
, username
))
1509 return NT_STATUS_OK
;
1511 return NT_STATUS_UNSUCCESSFUL
;
1514 static NTSTATUS
smbpasswd_rename_sam_account (struct pdb_methods
*my_methods
,
1515 struct samu
*old_acct
,
1516 const char *newname
)
1518 pstring rename_script
;
1519 struct samu
*new_acct
= NULL
;
1520 BOOL interim_account
= False
;
1521 NTSTATUS ret
= NT_STATUS_UNSUCCESSFUL
;
1523 if (!*(lp_renameuser_script()))
1526 if ( !(new_acct
= samu_new( NULL
)) ) {
1527 return NT_STATUS_NO_MEMORY
;
1530 if ( !pdb_copy_sam_account( new_acct
, old_acct
)
1531 || !pdb_set_username(new_acct
, newname
, PDB_CHANGED
))
1536 ret
= smbpasswd_add_sam_account(my_methods
, new_acct
);
1537 if (!NT_STATUS_IS_OK(ret
))
1540 interim_account
= True
;
1542 /* rename the posix user */
1543 pstrcpy(rename_script
, lp_renameuser_script());
1545 if (*rename_script
) {
1548 string_sub2(rename_script
, "%unew", newname
, sizeof(pstring
),
1550 string_sub2(rename_script
, "%uold", pdb_get_username(old_acct
),
1551 sizeof(pstring
), True
, False
, True
);
1553 rename_ret
= smbrun(rename_script
, NULL
);
1555 DEBUG(rename_ret
? 0 : 3,("Running the command `%s' gave %d\n", rename_script
, rename_ret
));
1563 smbpasswd_delete_sam_account(my_methods
, old_acct
);
1564 interim_account
= False
;
1568 if (interim_account
)
1569 smbpasswd_delete_sam_account(my_methods
, new_acct
);
1572 TALLOC_FREE(new_acct
);
1577 static BOOL
smbpasswd_rid_algorithm(struct pdb_methods
*methods
)
1582 static void free_private_data(void **vp
)
1584 struct smbpasswd_privates
**privates
= (struct smbpasswd_privates
**)vp
;
1586 endsmbfilepwent((*privates
)->pw_file
, &((*privates
)->pw_file_lock_depth
));
1589 /* No need to free any further, as it is talloc()ed */
1592 static NTSTATUS
pdb_init_smbpasswd( struct pdb_methods
**pdb_method
, const char *location
)
1595 struct smbpasswd_privates
*privates
;
1597 if ( !NT_STATUS_IS_OK(nt_status
= make_pdb_method( pdb_method
)) ) {
1601 (*pdb_method
)->name
= "smbpasswd";
1603 (*pdb_method
)->setsampwent
= smbpasswd_setsampwent
;
1604 (*pdb_method
)->endsampwent
= smbpasswd_endsampwent
;
1605 (*pdb_method
)->getsampwent
= smbpasswd_getsampwent
;
1606 (*pdb_method
)->getsampwnam
= smbpasswd_getsampwnam
;
1607 (*pdb_method
)->getsampwsid
= smbpasswd_getsampwsid
;
1608 (*pdb_method
)->add_sam_account
= smbpasswd_add_sam_account
;
1609 (*pdb_method
)->update_sam_account
= smbpasswd_update_sam_account
;
1610 (*pdb_method
)->delete_sam_account
= smbpasswd_delete_sam_account
;
1611 (*pdb_method
)->rename_sam_account
= smbpasswd_rename_sam_account
;
1613 (*pdb_method
)->rid_algorithm
= smbpasswd_rid_algorithm
;
1615 /* Setup private data and free function */
1617 if ( !(privates
= TALLOC_ZERO_P( *pdb_method
, struct smbpasswd_privates
)) ) {
1618 DEBUG(0, ("talloc() failed for smbpasswd private_data!\n"));
1619 return NT_STATUS_NO_MEMORY
;
1622 /* Store some config details */
1625 privates
->smbpasswd_file
= talloc_strdup(*pdb_method
, location
);
1627 privates
->smbpasswd_file
= talloc_strdup(*pdb_method
, lp_smb_passwd_file());
1630 if (!privates
->smbpasswd_file
) {
1631 DEBUG(0, ("talloc_strdp() failed for storing smbpasswd location!\n"));
1632 return NT_STATUS_NO_MEMORY
;
1635 (*pdb_method
)->private_data
= privates
;
1637 (*pdb_method
)->free_private_data
= free_private_data
;
1639 return NT_STATUS_OK
;
1642 NTSTATUS
pdb_smbpasswd_init(void)
1644 return smb_register_passdb(PASSDB_INTERFACE_VERSION
, "smbpasswd", pdb_init_smbpasswd
);