2 * Unix SMB/CIFS implementation.
3 * SMB parameters and setup
4 * Copyright (C) Andrew Tridgell 1992-1998
5 * Modified by Jeremy Allison 1995.
6 * Modified by Gerald (Jerry) Carter 2000-2001,2003
7 * Modified by Andrew Bartlett 2002.
9 * This program is free software; you can redistribute it and/or modify it under
10 * the terms of the GNU General Public License as published by the Free
11 * Software Foundation; either version 3 of the License, or (at your option)
14 * This program is distributed in the hope that it will be useful, but WITHOUT
15 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
16 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
19 * You should have received a copy of the GNU General Public License along with
20 * this program; if not, see <http://www.gnu.org/licenses/>.
26 #define DBGC_CLASS DBGC_PASSDB
29 smb_passwd is analogous to sam_passwd used everywhere
30 else. However, smb_passwd is limited to the information
31 stored by an smbpasswd entry
36 uint32 smb_userid
; /* this is actually the unix uid_t */
37 const char *smb_name
; /* username string */
39 const unsigned char *smb_passwd
; /* Null if no password */
40 const unsigned char *smb_nt_passwd
; /* Null if no password */
42 uint16 acct_ctrl
; /* account info (ACB_xxxx bit-mask) */
43 time_t pass_last_set_time
; /* password last set time */
46 struct smbpasswd_privates
48 /* used for maintain locks on the smbpasswd file */
49 int pw_file_lock_depth
;
51 /* Global File pointer */
54 /* formerly static variables */
55 struct smb_passwd pw_buf
;
57 unsigned char smbpwd
[16];
58 unsigned char smbntpwd
[16];
60 /* retrive-once info */
61 const char *smbpasswd_file
;
64 enum pwf_access_type
{ PWF_READ
, PWF_UPDATE
, PWF_CREATE
};
66 static SIG_ATOMIC_T gotalarm
;
68 /***************************************************************
69 Signal function to tell us we timed out.
70 ****************************************************************/
72 static void gotalarm_sig(void)
77 /***************************************************************
78 Lock or unlock a fd for a known lock type. Abandon after waitsecs
80 ****************************************************************/
82 static bool do_file_lock(int fd
, int waitsecs
, int type
)
84 SMB_STRUCT_FLOCK lock
;
86 void (*oldsig_handler
)(int);
89 oldsig_handler
= CatchSignal(SIGALRM
, SIGNAL_CAST gotalarm_sig
);
92 lock
.l_whence
= SEEK_SET
;
98 /* Note we must *NOT* use sys_fcntl here ! JRA */
99 ret
= fcntl(fd
, SMB_F_SETLKW
, &lock
);
101 CatchSignal(SIGALRM
, SIGNAL_CAST oldsig_handler
);
104 DEBUG(0, ("do_file_lock: failed to %s file.\n",
105 type
== F_UNLCK
? "unlock" : "lock"));
112 /***************************************************************
113 Lock an fd. Abandon after waitsecs seconds.
114 ****************************************************************/
116 static bool pw_file_lock(int fd
, int type
, int secs
, int *plock_depth
)
122 if(*plock_depth
== 0) {
123 if (!do_file_lock(fd
, secs
, type
)) {
124 DEBUG(10,("pw_file_lock: locking file failed, error = %s.\n",
135 /***************************************************************
136 Unlock an fd. Abandon after waitsecs seconds.
137 ****************************************************************/
139 static bool pw_file_unlock(int fd
, int *plock_depth
)
143 if (fd
== 0 || *plock_depth
== 0) {
147 if(*plock_depth
== 1) {
148 ret
= do_file_lock(fd
, 5, F_UNLCK
);
151 if (*plock_depth
> 0) {
156 DEBUG(10,("pw_file_unlock: unlocking file failed, error = %s.\n",
162 /**************************************************************
163 Intialize a smb_passwd struct
164 *************************************************************/
166 static void pdb_init_smb(struct smb_passwd
*user
)
172 user
->pass_last_set_time
= (time_t)0;
175 /***************************************************************
176 Internal fn to enumerate the smbpasswd list. Returns a void pointer
177 to ensure no modification outside this module. Checks for atomic
178 rename of smbpasswd file on update or create once the lock has
179 been granted to prevent race conditions. JRA.
180 ****************************************************************/
182 static FILE *startsmbfilepwent(const char *pfile
, enum pwf_access_type type
, int *lock_depth
)
185 const char *open_mode
= NULL
;
187 int lock_type
= F_RDLCK
;
190 DEBUG(0, ("startsmbfilepwent: No SMB password file set\n"));
205 * Ensure atomic file creation.
210 for(i
= 0; i
< 5; i
++) {
211 if((fd
= sys_open(pfile
, O_CREAT
|O_TRUNC
|O_EXCL
|O_RDWR
, 0600))!=-1) {
214 sys_usleep(200); /* Spin, spin... */
217 DEBUG(0,("startsmbfilepwent_internal: too many race conditions \
218 creating file %s\n", pfile
));
228 for(race_loop
= 0; race_loop
< 5; race_loop
++) {
229 DEBUG(10, ("startsmbfilepwent_internal: opening file %s\n", pfile
));
231 if((fp
= sys_fopen(pfile
, open_mode
)) == NULL
) {
234 * If smbpasswd file doesn't exist, then create new one. This helps to avoid
235 * confusing error msg when adding user account first time.
237 if (errno
== ENOENT
) {
238 if ((fp
= sys_fopen(pfile
, "a+")) != NULL
) {
239 DEBUG(0, ("startsmbfilepwent_internal: file %s did not \
240 exist. File successfully created.\n", pfile
));
242 DEBUG(0, ("startsmbfilepwent_internal: file %s did not \
243 exist. Couldn't create new one. Error was: %s",
244 pfile
, strerror(errno
)));
248 DEBUG(0, ("startsmbfilepwent_internal: unable to open file %s. \
249 Error was: %s\n", pfile
, strerror(errno
)));
254 if (!pw_file_lock(fileno(fp
), lock_type
, 5, lock_depth
)) {
255 DEBUG(0, ("startsmbfilepwent_internal: unable to lock file %s. \
256 Error was %s\n", pfile
, strerror(errno
) ));
262 * Only check for replacement races on update or create.
263 * For read we don't mind if the data is one record out of date.
266 if(type
== PWF_READ
) {
269 SMB_STRUCT_STAT sbuf1
, sbuf2
;
272 * Avoid the potential race condition between the open and the lock
273 * by doing a stat on the filename and an fstat on the fd. If the
274 * two inodes differ then someone did a rename between the open and
275 * the lock. Back off and try the open again. Only do this 5 times to
276 * prevent infinate loops. JRA.
279 if (sys_stat(pfile
,&sbuf1
) != 0) {
280 DEBUG(0, ("startsmbfilepwent_internal: unable to stat file %s. \
281 Error was %s\n", pfile
, strerror(errno
)));
282 pw_file_unlock(fileno(fp
), lock_depth
);
287 if (sys_fstat(fileno(fp
),&sbuf2
) != 0) {
288 DEBUG(0, ("startsmbfilepwent_internal: unable to fstat file %s. \
289 Error was %s\n", pfile
, strerror(errno
)));
290 pw_file_unlock(fileno(fp
), lock_depth
);
295 if( sbuf1
.st_ino
== sbuf2
.st_ino
) {
301 * Race occurred - back off and try again...
304 pw_file_unlock(fileno(fp
), lock_depth
);
310 DEBUG(0, ("startsmbfilepwent_internal: too many race conditions opening file %s\n", pfile
));
314 /* Set a buffer to do more efficient reads */
315 setvbuf(fp
, (char *)NULL
, _IOFBF
, 1024);
317 /* Make sure it is only rw by the owner */
319 if(fchmod(fileno(fp
), S_IRUSR
|S_IWUSR
) == -1) {
321 if(chmod(pfile
, S_IRUSR
|S_IWUSR
) == -1) {
323 DEBUG(0, ("startsmbfilepwent_internal: failed to set 0600 permissions on password file %s. \
324 Error was %s\n.", pfile
, strerror(errno
) ));
325 pw_file_unlock(fileno(fp
), lock_depth
);
330 /* We have a lock on the file. */
334 /***************************************************************
335 End enumeration of the smbpasswd list.
336 ****************************************************************/
338 static void endsmbfilepwent(FILE *fp
, int *lock_depth
)
344 pw_file_unlock(fileno(fp
), lock_depth
);
346 DEBUG(7, ("endsmbfilepwent_internal: closed password file.\n"));
349 /*************************************************************************
350 Routine to return the next entry in the smbpasswd list.
351 *************************************************************************/
353 static struct smb_passwd
*getsmbfilepwent(struct smbpasswd_privates
*smbpasswd_state
, FILE *fp
)
355 /* Static buffers we will return. */
356 struct smb_passwd
*pw_buf
= &smbpasswd_state
->pw_buf
;
357 char *user_name
= smbpasswd_state
->user_name
;
358 unsigned char *smbpwd
= smbpasswd_state
->smbpwd
;
359 unsigned char *smbntpwd
= smbpasswd_state
->smbntpwd
;
368 DEBUG(0,("getsmbfilepwent: Bad password file pointer.\n"));
372 pdb_init_smb(pw_buf
);
373 pw_buf
->acct_ctrl
= ACB_NORMAL
;
376 * Scan the file, a line at a time and check if the name matches.
379 while (status
&& !feof(fp
)) {
382 status
= fgets(linebuf
, 256, fp
);
383 if (status
== NULL
&& ferror(fp
)) {
388 * Check if the string is terminated with a newline - if not
389 * then we must keep reading and discard until we get one.
391 if ((linebuf_len
= strlen(linebuf
)) == 0) {
395 if (linebuf
[linebuf_len
- 1] != '\n') {
397 while (!ferror(fp
) && !feof(fp
)) {
404 linebuf
[linebuf_len
- 1] = '\0';
407 #ifdef DEBUG_PASSWORD
408 DEBUG(100, ("getsmbfilepwent: got line |%s|\n", linebuf
));
410 if ((linebuf
[0] == 0) && feof(fp
)) {
411 DEBUG(4, ("getsmbfilepwent: end of file reached\n"));
416 * The line we have should be of the form :-
418 * username:uid:32hex bytes:[Account type]:LCT-12345678....other flags presently
423 * username:uid:32hex bytes:32hex bytes:[Account type]:LCT-12345678....ignored....
425 * if Windows NT compatible passwords are also present.
426 * [Account type] is an ascii encoding of the type of account.
427 * LCT-(8 hex digits) is the time_t value of the last change time.
430 if (linebuf
[0] == '#' || linebuf
[0] == '\0') {
431 DEBUG(6, ("getsmbfilepwent: skipping comment or blank line\n"));
434 p
= (unsigned char *) strchr_m(linebuf
, ':');
436 DEBUG(0, ("getsmbfilepwent: malformed password entry (no :)\n"));
440 strncpy(user_name
, linebuf
, PTR_DIFF(p
, linebuf
));
441 user_name
[PTR_DIFF(p
, linebuf
)] = '\0';
445 p
++; /* Go past ':' */
448 DEBUG(0, ("getsmbfilepwent: user name %s has a negative uid.\n", user_name
));
453 DEBUG(0, ("getsmbfilepwent: malformed password entry for user %s (uid not number)\n",
458 uidval
= atoi((char *) p
);
460 while (*p
&& isdigit(*p
)) {
465 DEBUG(0, ("getsmbfilepwent: malformed password entry for user %s (no : after uid)\n",
470 pw_buf
->smb_name
= user_name
;
471 pw_buf
->smb_userid
= uidval
;
474 * Now get the password value - this should be 32 hex digits
475 * which are the ascii representations of a 16 byte string.
476 * Get two at a time and put them into the password.
482 if (linebuf_len
< (PTR_DIFF(p
, linebuf
) + 33)) {
483 DEBUG(0, ("getsmbfilepwent: malformed password entry for user %s (passwd too short)\n",
489 DEBUG(0, ("getsmbfilepwent: malformed password entry for user %s (no terminating :)\n",
494 if (strnequal((char *) p
, "NO PASSWORD", 11)) {
495 pw_buf
->smb_passwd
= NULL
;
496 pw_buf
->acct_ctrl
|= ACB_PWNOTREQ
;
498 if (*p
== '*' || *p
== 'X') {
499 /* NULL LM password */
500 pw_buf
->smb_passwd
= NULL
;
501 DEBUG(10, ("getsmbfilepwent: LM password for user %s invalidated\n", user_name
));
502 } else if (pdb_gethexpwd((char *)p
, smbpwd
)) {
503 pw_buf
->smb_passwd
= smbpwd
;
505 pw_buf
->smb_passwd
= NULL
;
506 DEBUG(0, ("getsmbfilepwent: Malformed Lanman password entry for user %s \
507 (non hex chars)\n", user_name
));
512 * Now check if the NT compatible password is
515 pw_buf
->smb_nt_passwd
= NULL
;
516 p
+= 33; /* Move to the first character of the line after the lanman password. */
517 if ((linebuf_len
>= (PTR_DIFF(p
, linebuf
) + 33)) && (p
[32] == ':')) {
518 if (*p
!= '*' && *p
!= 'X') {
519 if(pdb_gethexpwd((char *)p
,smbntpwd
)) {
520 pw_buf
->smb_nt_passwd
= smbntpwd
;
523 p
+= 33; /* Move to the first character of the line after the NT password. */
526 DEBUG(5,("getsmbfilepwent: returning passwd entry for user %s, uid %ld\n",
530 unsigned char *end_p
= (unsigned char *)strchr_m((char *)p
, ']');
531 pw_buf
->acct_ctrl
= pdb_decode_acct_ctrl((char*)p
);
533 /* Must have some account type set. */
534 if(pw_buf
->acct_ctrl
== 0) {
535 pw_buf
->acct_ctrl
= ACB_NORMAL
;
538 /* Now try and get the last change time. */
544 if(*p
&& (StrnCaseCmp((char *)p
, "LCT-", 4)==0)) {
547 for(i
= 0; i
< 8; i
++) {
548 if(p
[i
] == '\0' || !isxdigit(p
[i
])) {
554 * p points at 8 characters of hex digits -
555 * read into a time_t as the seconds since
556 * 1970 that the password was last changed.
558 pw_buf
->pass_last_set_time
= (time_t)strtol((char *)p
, NULL
, 16);
563 /* 'Old' style file. Fake up based on user name. */
565 * Currently trust accounts are kept in the same
566 * password file as 'normal accounts'. If this changes
567 * we will have to fix this code. JRA.
569 if(pw_buf
->smb_name
[strlen(pw_buf
->smb_name
) - 1] == '$') {
570 pw_buf
->acct_ctrl
&= ~ACB_NORMAL
;
571 pw_buf
->acct_ctrl
|= ACB_WSTRUST
;
578 DEBUG(5,("getsmbfilepwent: end of file reached.\n"));
582 /************************************************************************
583 Create a new smbpasswd entry - malloced space returned.
584 *************************************************************************/
586 static char *format_new_smbpasswd_entry(const struct smb_passwd
*newpwd
)
588 int new_entry_length
;
592 new_entry_length
= strlen(newpwd
->smb_name
) + 1 + 15 + 1 + 32 + 1 + 32 + 1 +
593 NEW_PW_FORMAT_SPACE_PADDED_LEN
+ 1 + 13 + 2;
595 if((new_entry
= (char *)SMB_MALLOC( new_entry_length
)) == NULL
) {
596 DEBUG(0, ("format_new_smbpasswd_entry: Malloc failed adding entry for user %s.\n",
601 slprintf(new_entry
, new_entry_length
- 1, "%s:%u:", newpwd
->smb_name
, (unsigned)newpwd
->smb_userid
);
603 p
= new_entry
+strlen(new_entry
);
604 pdb_sethexpwd(p
, newpwd
->smb_passwd
, newpwd
->acct_ctrl
);
609 pdb_sethexpwd(p
, newpwd
->smb_nt_passwd
, newpwd
->acct_ctrl
);
614 /* Add the account encoding and the last change time. */
615 slprintf((char *)p
, new_entry_length
- 1 - (p
- new_entry
), "%s:LCT-%08X:\n",
616 pdb_encode_acct_ctrl(newpwd
->acct_ctrl
, NEW_PW_FORMAT_SPACE_PADDED_LEN
),
617 (uint32
)newpwd
->pass_last_set_time
);
622 /************************************************************************
623 Routine to add an entry to the smbpasswd file.
624 *************************************************************************/
626 static NTSTATUS
add_smbfilepwd_entry(struct smbpasswd_privates
*smbpasswd_state
,
627 struct smb_passwd
*newpwd
)
629 const char *pfile
= smbpasswd_state
->smbpasswd_file
;
630 struct smb_passwd
*pwd
= NULL
;
634 size_t new_entry_length
;
638 /* Open the smbpassword file - for update. */
639 fp
= startsmbfilepwent(pfile
, PWF_UPDATE
, &smbpasswd_state
->pw_file_lock_depth
);
641 if (fp
== NULL
&& errno
== ENOENT
) {
642 /* Try again - create. */
643 fp
= startsmbfilepwent(pfile
, PWF_CREATE
, &smbpasswd_state
->pw_file_lock_depth
);
647 DEBUG(0, ("add_smbfilepwd_entry: unable to open file.\n"));
648 return map_nt_error_from_unix(errno
);
652 * Scan the file, a line at a time and check if the name matches.
655 while ((pwd
= getsmbfilepwent(smbpasswd_state
, fp
)) != NULL
) {
656 if (strequal(newpwd
->smb_name
, pwd
->smb_name
)) {
657 DEBUG(0, ("add_smbfilepwd_entry: entry with name %s already exists\n", pwd
->smb_name
));
658 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
659 return NT_STATUS_USER_EXISTS
;
663 /* Ok - entry doesn't exist. We can add it */
665 /* Create a new smb passwd entry and set it to the given password. */
667 * The add user write needs to be atomic - so get the fd from
668 * the fp and do a raw write() call.
672 if((offpos
= sys_lseek(fd
, 0, SEEK_END
)) == -1) {
673 NTSTATUS result
= map_nt_error_from_unix(errno
);
674 DEBUG(0, ("add_smbfilepwd_entry(sys_lseek): Failed to add entry for user %s to file %s. \
675 Error was %s\n", newpwd
->smb_name
, pfile
, strerror(errno
)));
676 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
680 if((new_entry
= format_new_smbpasswd_entry(newpwd
)) == NULL
) {
681 DEBUG(0, ("add_smbfilepwd_entry(malloc): Failed to add entry for user %s to file %s. \
682 Error was %s\n", newpwd
->smb_name
, pfile
, strerror(errno
)));
683 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
684 return NT_STATUS_NO_MEMORY
;
687 new_entry_length
= strlen(new_entry
);
689 #ifdef DEBUG_PASSWORD
690 DEBUG(100, ("add_smbfilepwd_entry(%d): new_entry_len %d made line |%s|",
691 fd
, (int)new_entry_length
, new_entry
));
694 if ((wr_len
= write(fd
, new_entry
, new_entry_length
)) != new_entry_length
) {
695 NTSTATUS result
= map_nt_error_from_unix(errno
);
696 DEBUG(0, ("add_smbfilepwd_entry(write): %d Failed to add entry for user %s to file %s. \
697 Error was %s\n", wr_len
, newpwd
->smb_name
, pfile
, strerror(errno
)));
699 /* Remove the entry we just wrote. */
700 if(sys_ftruncate(fd
, offpos
) == -1) {
701 DEBUG(0, ("add_smbfilepwd_entry: ERROR failed to ftruncate file %s. \
702 Error was %s. Password file may be corrupt ! Please examine by hand !\n",
703 newpwd
->smb_name
, strerror(errno
)));
706 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
712 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
716 /************************************************************************
717 Routine to search the smbpasswd file for an entry matching the username.
718 and then modify its password entry. We can't use the startsmbpwent()/
719 getsmbpwent()/endsmbpwent() interfaces here as we depend on looking
720 in the actual file to decide how much room we have to write data.
721 override = False, normal
722 override = True, override XXXXXXXX'd out password or NO PASS
723 ************************************************************************/
725 static bool mod_smbfilepwd_entry(struct smbpasswd_privates
*smbpasswd_state
, const struct smb_passwd
* pwd
)
727 /* Static buffers we will return. */
736 unsigned char *p
= NULL
;
737 size_t linebuf_len
= 0;
740 const char *pfile
= smbpasswd_state
->smbpasswd_file
;
741 bool found_entry
= False
;
742 bool got_pass_last_set_time
= False
;
744 SMB_OFF_T pwd_seekpos
= 0;
751 DEBUG(0, ("No SMB password file set\n"));
754 DEBUG(10, ("mod_smbfilepwd_entry: opening file %s\n", pfile
));
756 fp
= sys_fopen(pfile
, "r+");
759 DEBUG(0, ("mod_smbfilepwd_entry: unable to open file %s\n", pfile
));
762 /* Set a buffer to do more efficient reads */
763 setvbuf(fp
, readbuf
, _IOFBF
, sizeof(readbuf
));
767 if (!pw_file_lock(lockfd
, F_WRLCK
, 5, &smbpasswd_state
->pw_file_lock_depth
)) {
768 DEBUG(0, ("mod_smbfilepwd_entry: unable to lock file %s\n", pfile
));
773 /* Make sure it is only rw by the owner */
776 /* We have a write lock on the file. */
778 * Scan the file, a line at a time and check if the name matches.
781 while (status
&& !feof(fp
)) {
782 pwd_seekpos
= sys_ftell(fp
);
786 status
= fgets(linebuf
, sizeof(linebuf
), fp
);
787 if (status
== NULL
&& ferror(fp
)) {
788 pw_file_unlock(lockfd
, &smbpasswd_state
->pw_file_lock_depth
);
794 * Check if the string is terminated with a newline - if not
795 * then we must keep reading and discard until we get one.
797 linebuf_len
= strlen(linebuf
);
798 if (linebuf
[linebuf_len
- 1] != '\n') {
800 while (!ferror(fp
) && !feof(fp
)) {
807 linebuf
[linebuf_len
- 1] = '\0';
810 #ifdef DEBUG_PASSWORD
811 DEBUG(100, ("mod_smbfilepwd_entry: got line |%s|\n", linebuf
));
814 if ((linebuf
[0] == 0) && feof(fp
)) {
815 DEBUG(4, ("mod_smbfilepwd_entry: end of file reached\n"));
820 * The line we have should be of the form :-
822 * username:uid:[32hex bytes]:....other flags presently
827 * username:uid:[32hex bytes]:[32hex bytes]:[attributes]:LCT-XXXXXXXX:...ignored.
829 * if Windows NT compatible passwords are also present.
832 if (linebuf
[0] == '#' || linebuf
[0] == '\0') {
833 DEBUG(6, ("mod_smbfilepwd_entry: skipping comment or blank line\n"));
837 p
= (unsigned char *) strchr_m(linebuf
, ':');
840 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry (no :)\n"));
844 strncpy(user_name
, linebuf
, PTR_DIFF(p
, linebuf
));
845 user_name
[PTR_DIFF(p
, linebuf
)] = '\0';
846 if (strequal(user_name
, pwd
->smb_name
)) {
853 pw_file_unlock(lockfd
, &smbpasswd_state
->pw_file_lock_depth
);
856 DEBUG(2, ("Cannot update entry for user %s, as they don't exist in the smbpasswd file!\n",
861 DEBUG(6, ("mod_smbfilepwd_entry: entry exists for user %s\n", pwd
->smb_name
));
863 /* User name matches - get uid and password */
864 p
++; /* Go past ':' */
867 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (uid not number)\n",
869 pw_file_unlock(lockfd
, &smbpasswd_state
->pw_file_lock_depth
);
874 while (*p
&& isdigit(*p
)) {
878 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (no : after uid)\n",
880 pw_file_unlock(lockfd
, &smbpasswd_state
->pw_file_lock_depth
);
886 * Now get the password value - this should be 32 hex digits
887 * which are the ascii representations of a 16 byte string.
888 * Get two at a time and put them into the password.
892 /* Record exact password position */
893 pwd_seekpos
+= PTR_DIFF(p
, linebuf
);
895 if (linebuf_len
< (PTR_DIFF(p
, linebuf
) + 33)) {
896 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (passwd too short)\n",
898 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
904 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (no terminating :)\n",
906 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
911 /* Now check if the NT compatible password is available. */
912 p
+= 33; /* Move to the first character of the line after the lanman password. */
913 if (linebuf_len
< (PTR_DIFF(p
, linebuf
) + 33)) {
914 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (passwd too short)\n",
916 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
922 DEBUG(0, ("mod_smbfilepwd_entry: malformed password entry for user %s (no terminating :)\n",
924 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
930 * Now check if the account info and the password last
931 * change time is available.
933 p
+= 33; /* Move to the first character of the line after the NT password. */
937 encode_bits
[i
++] = *p
++;
938 while((linebuf_len
> PTR_DIFF(p
, linebuf
)) && (*p
!= ']')) {
939 encode_bits
[i
++] = *p
++;
942 encode_bits
[i
++] = ']';
943 encode_bits
[i
++] = '\0';
945 if(i
== NEW_PW_FORMAT_SPACE_PADDED_LEN
) {
947 * We are using a new format, space padded
948 * acct ctrl field. Encode the given acct ctrl
951 fstrcpy(encode_bits
, pdb_encode_acct_ctrl(pwd
->acct_ctrl
, NEW_PW_FORMAT_SPACE_PADDED_LEN
));
953 DEBUG(0,("mod_smbfilepwd_entry: Using old smbpasswd format for user %s. \
954 This is no longer supported.!\n", pwd
->smb_name
));
955 DEBUG(0,("mod_smbfilepwd_entry: No changes made, failing.!\n"));
956 pw_file_unlock(lockfd
, &smbpasswd_state
->pw_file_lock_depth
);
961 /* Go past the ']' */
962 if(linebuf_len
> PTR_DIFF(p
, linebuf
)) {
966 if((linebuf_len
> PTR_DIFF(p
, linebuf
)) && (*p
== ':')) {
969 /* We should be pointing at the LCT entry. */
970 if((linebuf_len
> (PTR_DIFF(p
, linebuf
) + 13)) && (StrnCaseCmp((char *)p
, "LCT-", 4) == 0)) {
972 for(i
= 0; i
< 8; i
++) {
973 if(p
[i
] == '\0' || !isxdigit(p
[i
])) {
979 * p points at 8 characters of hex digits -
980 * read into a time_t as the seconds since
981 * 1970 that the password was last changed.
983 got_pass_last_set_time
= True
;
985 } /* *p && StrnCaseCmp() */
989 /* Entry is correctly formed. */
991 /* Create the 32 byte representation of the new p16 */
992 pdb_sethexpwd(ascii_p16
, pwd
->smb_passwd
, pwd
->acct_ctrl
);
994 /* Add on the NT md4 hash */
997 pdb_sethexpwd(ascii_p16
+33, pwd
->smb_nt_passwd
, pwd
->acct_ctrl
);
999 ascii_p16
[66] = '\0'; /* null-terminate the string so that strlen works */
1001 /* Add on the account info bits and the time of last password change. */
1002 if(got_pass_last_set_time
) {
1003 slprintf(&ascii_p16
[strlen(ascii_p16
)],
1004 sizeof(ascii_p16
)-(strlen(ascii_p16
)+1),
1006 encode_bits
, (uint32
)pwd
->pass_last_set_time
);
1007 wr_len
= strlen(ascii_p16
);
1010 #ifdef DEBUG_PASSWORD
1011 DEBUG(100,("mod_smbfilepwd_entry: "));
1012 dump_data(100, (uint8
*)ascii_p16
, wr_len
);
1015 if(wr_len
> sizeof(linebuf
)) {
1016 DEBUG(0, ("mod_smbfilepwd_entry: line to write (%d) is too long.\n", wr_len
+1));
1017 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1023 * Do an atomic write into the file at the position defined by
1027 /* The mod user write needs to be atomic - so get the fd from
1028 the fp and do a raw write() call.
1033 if (sys_lseek(fd
, pwd_seekpos
- 1, SEEK_SET
) != pwd_seekpos
- 1) {
1034 DEBUG(0, ("mod_smbfilepwd_entry: seek fail on file %s.\n", pfile
));
1035 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1040 /* Sanity check - ensure the areas we are writing are framed by ':' */
1041 if (read(fd
, linebuf
, wr_len
+1) != wr_len
+1) {
1042 DEBUG(0, ("mod_smbfilepwd_entry: read fail on file %s.\n", pfile
));
1043 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1048 if ((linebuf
[0] != ':') || (linebuf
[wr_len
] != ':')) {
1049 DEBUG(0, ("mod_smbfilepwd_entry: check on passwd file %s failed.\n", pfile
));
1050 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1055 if (sys_lseek(fd
, pwd_seekpos
, SEEK_SET
) != pwd_seekpos
) {
1056 DEBUG(0, ("mod_smbfilepwd_entry: seek fail on file %s.\n", pfile
));
1057 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1062 if (write(fd
, ascii_p16
, wr_len
) != wr_len
) {
1063 DEBUG(0, ("mod_smbfilepwd_entry: write failed in passwd file %s\n", pfile
));
1064 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1069 pw_file_unlock(lockfd
,&smbpasswd_state
->pw_file_lock_depth
);
1074 /************************************************************************
1075 Routine to delete an entry in the smbpasswd file by name.
1076 *************************************************************************/
1078 static bool del_smbfilepwd_entry(struct smbpasswd_privates
*smbpasswd_state
, const char *name
)
1080 const char *pfile
= smbpasswd_state
->smbpasswd_file
;
1081 char *pfile2
= NULL
;
1082 struct smb_passwd
*pwd
= NULL
;
1084 FILE *fp_write
= NULL
;
1085 int pfile2_lockdepth
= 0;
1087 pfile2
= talloc_asprintf(talloc_tos(),
1089 pfile
, (unsigned)sys_getpid());
1095 * Open the smbpassword file - for update. It needs to be update
1096 * as we need any other processes to wait until we have replaced
1100 if((fp
= startsmbfilepwent(pfile
, PWF_UPDATE
, &smbpasswd_state
->pw_file_lock_depth
)) == NULL
) {
1101 DEBUG(0, ("del_smbfilepwd_entry: unable to open file %s.\n", pfile
));
1106 * Create the replacement password file.
1108 if((fp_write
= startsmbfilepwent(pfile2
, PWF_CREATE
, &pfile2_lockdepth
)) == NULL
) {
1109 DEBUG(0, ("del_smbfilepwd_entry: unable to open file %s.\n", pfile
));
1110 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
1115 * Scan the file, a line at a time and check if the name matches.
1118 while ((pwd
= getsmbfilepwent(smbpasswd_state
, fp
)) != NULL
) {
1120 size_t new_entry_length
;
1122 if (strequal(name
, pwd
->smb_name
)) {
1123 DEBUG(10, ("del_smbfilepwd_entry: found entry with "
1124 "name %s - deleting it.\n", name
));
1129 * We need to copy the entry out into the second file.
1132 if((new_entry
= format_new_smbpasswd_entry(pwd
)) == NULL
) {
1133 DEBUG(0, ("del_smbfilepwd_entry(malloc): Failed to copy entry for user %s to file %s. \
1134 Error was %s\n", pwd
->smb_name
, pfile2
, strerror(errno
)));
1136 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
1137 endsmbfilepwent(fp_write
, &pfile2_lockdepth
);
1141 new_entry_length
= strlen(new_entry
);
1143 if(fwrite(new_entry
, 1, new_entry_length
, fp_write
) != new_entry_length
) {
1144 DEBUG(0, ("del_smbfilepwd_entry(write): Failed to copy entry for user %s to file %s. \
1145 Error was %s\n", pwd
->smb_name
, pfile2
, strerror(errno
)));
1147 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
1148 endsmbfilepwent(fp_write
, &pfile2_lockdepth
);
1157 * Ensure pfile2 is flushed before rename.
1160 if(fflush(fp_write
) != 0) {
1161 DEBUG(0, ("del_smbfilepwd_entry: Failed to flush file %s. Error was %s\n", pfile2
, strerror(errno
)));
1162 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
1163 endsmbfilepwent(fp_write
,&pfile2_lockdepth
);
1168 * Do an atomic rename - then release the locks.
1171 if(rename(pfile2
,pfile
) != 0) {
1175 endsmbfilepwent(fp
, &smbpasswd_state
->pw_file_lock_depth
);
1176 endsmbfilepwent(fp_write
,&pfile2_lockdepth
);
1180 /*********************************************************************
1181 Create a smb_passwd struct from a struct samu.
1182 We will not allocate any new memory. The smb_passwd struct
1183 should only stay around as long as the struct samu does.
1184 ********************************************************************/
1186 static bool build_smb_pass (struct smb_passwd
*smb_pw
, const struct samu
*sampass
)
1190 if (sampass
== NULL
)
1192 ZERO_STRUCTP(smb_pw
);
1194 if (!IS_SAM_DEFAULT(sampass
, PDB_USERSID
)) {
1195 rid
= pdb_get_user_rid(sampass
);
1197 /* If the user specified a RID, make sure its able to be both stored and retreived */
1198 if (rid
== DOMAIN_USER_RID_GUEST
) {
1199 struct passwd
*passwd
= getpwnam_alloc(NULL
, lp_guestaccount());
1201 DEBUG(0, ("Could not find guest account via getpwnam()! (%s)\n", lp_guestaccount()));
1204 smb_pw
->smb_userid
=passwd
->pw_uid
;
1205 TALLOC_FREE(passwd
);
1206 } else if (algorithmic_pdb_rid_is_user(rid
)) {
1207 smb_pw
->smb_userid
=algorithmic_pdb_user_rid_to_uid(rid
);
1209 DEBUG(0,("build_sam_pass: Failing attempt to store user with non-uid based user RID. \n"));
1214 smb_pw
->smb_name
=(const char*)pdb_get_username(sampass
);
1216 smb_pw
->smb_passwd
=pdb_get_lanman_passwd(sampass
);
1217 smb_pw
->smb_nt_passwd
=pdb_get_nt_passwd(sampass
);
1219 smb_pw
->acct_ctrl
=pdb_get_acct_ctrl(sampass
);
1220 smb_pw
->pass_last_set_time
=pdb_get_pass_last_set_time(sampass
);
1225 /*********************************************************************
1226 Create a struct samu from a smb_passwd struct
1227 ********************************************************************/
1229 static bool build_sam_account(struct smbpasswd_privates
*smbpasswd_state
,
1230 struct samu
*sam_pass
, const struct smb_passwd
*pw_buf
)
1232 struct passwd
*pwfile
;
1235 DEBUG(5,("build_sam_account: struct samu is NULL\n"));
1239 /* verify the user account exists */
1241 if ( !(pwfile
= Get_Pwnam_alloc(NULL
, pw_buf
->smb_name
)) ) {
1242 DEBUG(0,("build_sam_account: smbpasswd database is corrupt! username %s with uid "
1243 "%u is not in unix passwd database!\n", pw_buf
->smb_name
, pw_buf
->smb_userid
));
1247 if ( !NT_STATUS_IS_OK( samu_set_unix(sam_pass
, pwfile
)) )
1250 TALLOC_FREE(pwfile
);
1252 /* set remaining fields */
1254 pdb_set_nt_passwd (sam_pass
, pw_buf
->smb_nt_passwd
, PDB_SET
);
1255 pdb_set_lanman_passwd (sam_pass
, pw_buf
->smb_passwd
, PDB_SET
);
1256 pdb_set_acct_ctrl (sam_pass
, pw_buf
->acct_ctrl
, PDB_SET
);
1257 pdb_set_pass_last_set_time (sam_pass
, pw_buf
->pass_last_set_time
, PDB_SET
);
1258 pdb_set_pass_can_change_time (sam_pass
, pw_buf
->pass_last_set_time
, PDB_SET
);
1263 /*****************************************************************
1264 Functions to be implemented by the new passdb API
1265 ****************************************************************/
1267 /****************************************************************
1268 Search smbpasswd file by iterating over the entries. Do not
1269 call getpwnam() for unix account information until we have found
1271 ***************************************************************/
1273 static NTSTATUS
smbpasswd_getsampwnam(struct pdb_methods
*my_methods
,
1274 struct samu
*sam_acct
, const char *username
)
1276 NTSTATUS nt_status
= NT_STATUS_UNSUCCESSFUL
;
1277 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1278 struct smb_passwd
*smb_pw
;
1281 DEBUG(10, ("getsampwnam (smbpasswd): search by name: %s\n", username
));
1283 /* startsmbfilepwent() is used here as we don't want to lookup
1284 the UNIX account in the local system password file until
1286 fp
= startsmbfilepwent(smbpasswd_state
->smbpasswd_file
, PWF_READ
, &(smbpasswd_state
->pw_file_lock_depth
));
1289 DEBUG(0, ("Unable to open passdb database.\n"));
1293 while ( ((smb_pw
=getsmbfilepwent(smbpasswd_state
, fp
)) != NULL
)&& (!strequal(smb_pw
->smb_name
, username
)) )
1294 /* do nothing....another loop */ ;
1296 endsmbfilepwent(fp
, &(smbpasswd_state
->pw_file_lock_depth
));
1299 /* did we locate the username in smbpasswd */
1303 DEBUG(10, ("getsampwnam (smbpasswd): found by name: %s\n", smb_pw
->smb_name
));
1306 DEBUG(10,("getsampwnam (smbpasswd): struct samu is NULL\n"));
1310 /* now build the struct samu */
1311 if (!build_sam_account(smbpasswd_state
, sam_acct
, smb_pw
))
1315 return NT_STATUS_OK
;
1318 static NTSTATUS
smbpasswd_getsampwsid(struct pdb_methods
*my_methods
, struct samu
*sam_acct
, const DOM_SID
*sid
)
1320 NTSTATUS nt_status
= NT_STATUS_UNSUCCESSFUL
;
1321 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1322 struct smb_passwd
*smb_pw
;
1326 DEBUG(10, ("smbpasswd_getsampwrid: search by sid: %s\n",
1327 sid_string_dbg(sid
)));
1329 if (!sid_peek_check_rid(get_global_sam_sid(), sid
, &rid
))
1330 return NT_STATUS_UNSUCCESSFUL
;
1332 /* More special case 'guest account' hacks... */
1333 if (rid
== DOMAIN_USER_RID_GUEST
) {
1334 const char *guest_account
= lp_guestaccount();
1335 if (!(guest_account
&& *guest_account
)) {
1336 DEBUG(1, ("Guest account not specfied!\n"));
1339 return smbpasswd_getsampwnam(my_methods
, sam_acct
, guest_account
);
1342 /* Open the sam password file - not for update. */
1343 fp
= startsmbfilepwent(smbpasswd_state
->smbpasswd_file
, PWF_READ
, &(smbpasswd_state
->pw_file_lock_depth
));
1346 DEBUG(0, ("Unable to open passdb database.\n"));
1350 while ( ((smb_pw
=getsmbfilepwent(smbpasswd_state
, fp
)) != NULL
) && (algorithmic_pdb_uid_to_user_rid(smb_pw
->smb_userid
) != rid
) )
1353 endsmbfilepwent(fp
, &(smbpasswd_state
->pw_file_lock_depth
));
1356 /* did we locate the username in smbpasswd */
1360 DEBUG(10, ("getsampwrid (smbpasswd): found by name: %s\n", smb_pw
->smb_name
));
1363 DEBUG(10,("getsampwrid: (smbpasswd) struct samu is NULL\n"));
1367 /* now build the struct samu */
1368 if (!build_sam_account (smbpasswd_state
, sam_acct
, smb_pw
))
1371 /* build_sam_account might change the SID on us, if the name was for the guest account */
1372 if (NT_STATUS_IS_OK(nt_status
) && !sid_equal(pdb_get_user_sid(sam_acct
), sid
)) {
1373 DEBUG(1, ("looking for user with sid %s instead returned %s "
1374 "for account %s!?!\n", sid_string_dbg(sid
),
1375 sid_string_dbg(pdb_get_user_sid(sam_acct
)),
1376 pdb_get_username(sam_acct
)));
1377 return NT_STATUS_NO_SUCH_USER
;
1381 return NT_STATUS_OK
;
1384 static NTSTATUS
smbpasswd_add_sam_account(struct pdb_methods
*my_methods
, struct samu
*sampass
)
1386 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1387 struct smb_passwd smb_pw
;
1389 /* convert the struct samu */
1390 if (!build_smb_pass(&smb_pw
, sampass
)) {
1391 return NT_STATUS_UNSUCCESSFUL
;
1395 return add_smbfilepwd_entry(smbpasswd_state
, &smb_pw
);
1398 static NTSTATUS
smbpasswd_update_sam_account(struct pdb_methods
*my_methods
, struct samu
*sampass
)
1400 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1401 struct smb_passwd smb_pw
;
1403 /* convert the struct samu */
1404 if (!build_smb_pass(&smb_pw
, sampass
)) {
1405 DEBUG(0, ("smbpasswd_update_sam_account: build_smb_pass failed!\n"));
1406 return NT_STATUS_UNSUCCESSFUL
;
1409 /* update the entry */
1410 if(!mod_smbfilepwd_entry(smbpasswd_state
, &smb_pw
)) {
1411 DEBUG(0, ("smbpasswd_update_sam_account: mod_smbfilepwd_entry failed!\n"));
1412 return NT_STATUS_UNSUCCESSFUL
;
1415 return NT_STATUS_OK
;
1418 static NTSTATUS
smbpasswd_delete_sam_account (struct pdb_methods
*my_methods
, struct samu
*sampass
)
1420 struct smbpasswd_privates
*smbpasswd_state
= (struct smbpasswd_privates
*)my_methods
->private_data
;
1422 const char *username
= pdb_get_username(sampass
);
1424 if (del_smbfilepwd_entry(smbpasswd_state
, username
))
1425 return NT_STATUS_OK
;
1427 return NT_STATUS_UNSUCCESSFUL
;
1430 static NTSTATUS
smbpasswd_rename_sam_account (struct pdb_methods
*my_methods
,
1431 struct samu
*old_acct
,
1432 const char *newname
)
1434 char *rename_script
= NULL
;
1435 struct samu
*new_acct
= NULL
;
1436 bool interim_account
= False
;
1437 TALLOC_CTX
*ctx
= talloc_tos();
1438 NTSTATUS ret
= NT_STATUS_UNSUCCESSFUL
;
1440 if (!*(lp_renameuser_script()))
1443 if ( !(new_acct
= samu_new( NULL
)) ) {
1444 return NT_STATUS_NO_MEMORY
;
1447 if ( !pdb_copy_sam_account( new_acct
, old_acct
)
1448 || !pdb_set_username(new_acct
, newname
, PDB_CHANGED
))
1453 ret
= smbpasswd_add_sam_account(my_methods
, new_acct
);
1454 if (!NT_STATUS_IS_OK(ret
))
1457 interim_account
= True
;
1459 /* rename the posix user */
1460 rename_script
= talloc_strdup(ctx
,
1461 lp_renameuser_script());
1462 if (!rename_script
) {
1463 ret
= NT_STATUS_NO_MEMORY
;
1467 if (*rename_script
) {
1470 rename_script
= talloc_string_sub2(ctx
,
1477 if (!rename_script
) {
1478 ret
= NT_STATUS_NO_MEMORY
;
1481 rename_script
= talloc_string_sub2(ctx
,
1484 pdb_get_username(old_acct
),
1488 if (!rename_script
) {
1489 ret
= NT_STATUS_NO_MEMORY
;
1493 rename_ret
= smbrun(rename_script
, NULL
);
1495 DEBUG(rename_ret
? 0 : 3,("Running the command `%s' gave %d\n", rename_script
, rename_ret
));
1497 if (rename_ret
== 0) {
1498 smb_nscd_flush_user_cache();
1507 smbpasswd_delete_sam_account(my_methods
, old_acct
);
1508 interim_account
= False
;
1512 if (interim_account
)
1513 smbpasswd_delete_sam_account(my_methods
, new_acct
);
1516 TALLOC_FREE(new_acct
);
1521 static bool smbpasswd_rid_algorithm(struct pdb_methods
*methods
)
1526 static void free_private_data(void **vp
)
1528 struct smbpasswd_privates
**privates
= (struct smbpasswd_privates
**)vp
;
1530 endsmbfilepwent((*privates
)->pw_file
, &((*privates
)->pw_file_lock_depth
));
1533 /* No need to free any further, as it is talloc()ed */
1536 struct smbpasswd_search_state
{
1537 uint32_t acct_flags
;
1539 struct samr_displayentry
*entries
;
1540 uint32_t num_entries
;
1545 static void smbpasswd_search_end(struct pdb_search
*search
)
1547 struct smbpasswd_search_state
*state
= talloc_get_type_abort(
1548 search
->private_data
, struct smbpasswd_search_state
);
1552 static bool smbpasswd_search_next_entry(struct pdb_search
*search
,
1553 struct samr_displayentry
*entry
)
1555 struct smbpasswd_search_state
*state
= talloc_get_type_abort(
1556 search
->private_data
, struct smbpasswd_search_state
);
1558 if (state
->current
== state
->num_entries
) {
1562 *entry
= state
->entries
[state
->current
++];
1567 static bool smbpasswd_search_users(struct pdb_methods
*methods
,
1568 struct pdb_search
*search
,
1569 uint32_t acct_flags
)
1571 struct smbpasswd_privates
*smbpasswd_state
=
1572 (struct smbpasswd_privates
*)methods
->private_data
;
1574 struct smbpasswd_search_state
*search_state
;
1575 struct smb_passwd
*pwd
;
1578 search_state
= TALLOC_ZERO_P(search
->mem_ctx
,
1579 struct smbpasswd_search_state
);
1580 if (search_state
== NULL
) {
1581 DEBUG(0, ("talloc failed\n"));
1584 search_state
->acct_flags
= acct_flags
;
1586 fp
= startsmbfilepwent(smbpasswd_state
->smbpasswd_file
, PWF_READ
,
1587 &smbpasswd_state
->pw_file_lock_depth
);
1590 DEBUG(10, ("Unable to open smbpasswd file.\n"));
1591 TALLOC_FREE(search_state
);
1595 while ((pwd
= getsmbfilepwent(smbpasswd_state
, fp
)) != NULL
) {
1596 struct samr_displayentry entry
;
1599 if ((acct_flags
!= 0)
1600 && ((acct_flags
& pwd
->acct_ctrl
) == 0)) {
1604 user
= samu_new(talloc_tos());
1606 DEBUG(0, ("samu_new failed\n"));
1610 if (!build_sam_account(smbpasswd_state
, user
, pwd
)) {
1611 /* Already got debug msgs... */
1617 entry
.acct_flags
= pdb_get_acct_ctrl(user
);
1618 sid_peek_rid(pdb_get_user_sid(user
), &entry
.rid
);
1619 entry
.account_name
= talloc_strdup(
1620 search_state
, pdb_get_username(user
));
1621 entry
.fullname
= talloc_strdup(
1622 search_state
, pdb_get_fullname(user
));
1623 entry
.description
= talloc_strdup(
1624 search_state
, pdb_get_acct_desc(user
));
1628 if ((entry
.account_name
== NULL
) || (entry
.fullname
== NULL
)
1629 || (entry
.description
== NULL
)) {
1630 DEBUG(0, ("talloc_strdup failed\n"));
1634 ADD_TO_LARGE_ARRAY(search_state
, struct samr_displayentry
,
1635 entry
, &search_state
->entries
,
1636 &search_state
->num_entries
,
1637 &search_state
->array_size
);
1640 endsmbfilepwent(fp
, &(smbpasswd_state
->pw_file_lock_depth
));
1642 search
->private_data
= search_state
;
1643 search
->next_entry
= smbpasswd_search_next_entry
;
1644 search
->search_end
= smbpasswd_search_end
;
1649 static NTSTATUS
pdb_init_smbpasswd( struct pdb_methods
**pdb_method
, const char *location
)
1652 struct smbpasswd_privates
*privates
;
1654 if ( !NT_STATUS_IS_OK(nt_status
= make_pdb_method( pdb_method
)) ) {
1658 (*pdb_method
)->name
= "smbpasswd";
1660 (*pdb_method
)->getsampwnam
= smbpasswd_getsampwnam
;
1661 (*pdb_method
)->getsampwsid
= smbpasswd_getsampwsid
;
1662 (*pdb_method
)->add_sam_account
= smbpasswd_add_sam_account
;
1663 (*pdb_method
)->update_sam_account
= smbpasswd_update_sam_account
;
1664 (*pdb_method
)->delete_sam_account
= smbpasswd_delete_sam_account
;
1665 (*pdb_method
)->rename_sam_account
= smbpasswd_rename_sam_account
;
1666 (*pdb_method
)->search_users
= smbpasswd_search_users
;
1668 (*pdb_method
)->rid_algorithm
= smbpasswd_rid_algorithm
;
1670 /* Setup private data and free function */
1672 if ( !(privates
= TALLOC_ZERO_P( *pdb_method
, struct smbpasswd_privates
)) ) {
1673 DEBUG(0, ("talloc() failed for smbpasswd private_data!\n"));
1674 return NT_STATUS_NO_MEMORY
;
1677 /* Store some config details */
1680 privates
->smbpasswd_file
= talloc_strdup(*pdb_method
, location
);
1682 privates
->smbpasswd_file
= talloc_strdup(*pdb_method
, lp_smb_passwd_file());
1685 if (!privates
->smbpasswd_file
) {
1686 DEBUG(0, ("talloc_strdp() failed for storing smbpasswd location!\n"));
1687 return NT_STATUS_NO_MEMORY
;
1690 (*pdb_method
)->private_data
= privates
;
1692 (*pdb_method
)->free_private_data
= free_private_data
;
1694 return NT_STATUS_OK
;
1697 NTSTATUS
pdb_smbpasswd_init(void)
1699 return smb_register_passdb(PASSDB_INTERFACE_VERSION
, "smbpasswd", pdb_init_smbpasswd
);