/usr/sbin
NameSizeModeActions
aa-remove-unknown30680755editdlrm
aa-status88390755editdlrm
aa-teardown1390755editdlrm
accessdb147280755editdlrm
add-shell8600755editdlrm
addgnupghome30750755editdlrm
addgroup377850755editdlrm
adduser377850755editdlrm
agetty690000755editdlrm
apparmor_parser15263680755editdlrm
apparmor_status88390755editdlrm
applygnupgdefaults22170755editdlrm
arpd801440755editdlrm
arptables2204880755editdlrm
arptables-nft2204880755editdlrm
arptables-nft-restore2204880755editdlrm
arptables-nft-save2204880755editdlrm
arptables-restore2204880755editdlrm
arptables-save2204880755editdlrm
atd307280755editdlrm
badblocks351440755editdlrm
bcache-super-show144880755editdlrm
biosdecode278560755editdlrm
blkdeactivate148370755editdlrm
blkdiscard350480755editdlrm
blkid1210960755editdlrm
blkzone719120755editdlrm
blockdev678160755editdlrm
bridge1047600755editdlrm
cache_check13522880755editdlrm
cache_dump13522880755editdlrm
cache_metadata_size13522880755editdlrm
cache_repair13522880755editdlrm
cache_restore13522880755editdlrm
cache_writeback13522880755editdlrm
capsh310320755editdlrm
cfdisk1050480755editdlrm
cgdisk2114320755editdlrm
chcpu473360755editdlrm
chgpasswd677920755editdlrm
chmem637200755editdlrm
chpasswd596000755editdlrm
chroot433520755editdlrm
cpgr617840755editdlrm
cppw617840755editdlrm
cron559440755editdlrm
cryptdisks_start15440755editdlrm
cryptdisks_stop8440755editdlrm
cryptsetup1387920755editdlrm
cryptsetup-reencrypt1078480755editdlrm
ctrlaltdel391440755editdlrm
debugfs2312240755editdlrm
delgroup164950755editdlrm
deluser164950755editdlrm
depmod1744240755editdlrm
devlink1540800755editdlrm
dhclient5212000755editdlrm
dhclient-script163040755editdlrm
dmeventd514400755editdlrm
dmidecode1218560755editdlrm
dmsetup1751280755editdlrm
dmstats1751280755editdlrm
dosfsck594720755editdlrm
dosfslabel553760755editdlrm
dpkg-preconfigure36630755editdlrm
dpkg-reconfigure44480755editdlrm
dumpe2fs311120755editdlrm
e2freefrag188160755editdlrm
e2fsck3350640755editdlrm
e2image434000755editdlrm
e2label1091120755editdlrm
e2mmpstatus311120755editdlrm
e2scrub72960755editdlrm
e2scrub_all53950755editdlrm
e2undo229120755editdlrm
e4crypt311040755editdlrm
e4defrag351280755editdlrm
ebtables2204880755editdlrm
ebtables-nft2204880755editdlrm
ebtables-nft-restore2204880755editdlrm
ebtables-nft-save2204880755editdlrm
ebtables-restore2204880755editdlrm
ebtables-save2204880755editdlrm
era_check13522880755editdlrm
era_dump13522880755editdlrm
era_invalidate13522880755editdlrm
era_restore13522880755editdlrm
ethtool3840480755editdlrm
faillock144880755editdlrm
fatlabel553760755editdlrm
fdformat350480755editdlrm
fdisk1538800755editdlrm
filefrag187680755editdlrm
findfs145680755editdlrm
fixparts762640755editdlrm
fsadm241080755editdlrm
fsck555760755editdlrm
fsck.btrfs11850755editdlrm
fsck.cramfs391760755editdlrm
fsck.ext23350640755editdlrm
fsck.ext33350640755editdlrm
fsck.ext43350640755editdlrm
fsck.fat594720755editdlrm
fsck.minix1251840755editdlrm
fsck.msdos594720755editdlrm
fsck.vfat594720755editdlrm
fsck.xfs19680755editdlrm
fsfreeze145680755editdlrm
fstab-decode146480755editdlrm
fstrim719120755editdlrm
gdisk2155280755editdlrm
genl842640755editdlrm
getcap146480755editdlrm
getpcaps146480755editdlrm
getty690000755editdlrm
groupadd931360755editdlrm
groupdel888480755editdlrm
groupmems637360755editdlrm
groupmod971360755editdlrm
grpck636720755editdlrm
grpconv594480755editdlrm
grpunconv594480755editdlrm
grub-bios-setup9311680755editdlrm
grub-install11629920755editdlrm
grub-macbless9185600755editdlrm
grub-mkconfig87500755editdlrm
grub-mkdevicemap2208800755editdlrm
grub-probe9270080755editdlrm
grub-reboot48430755editdlrm
grub-set-default35580755editdlrm
halt9965840755editdlrm
hdparm1437040755editdlrm
hwclock1048080755editdlrm
iconvconfig311280755editdlrm
init16202240755editdlrm
insmod1744240755editdlrm
installkernel26380755editdlrm
integritysetup616720755editdlrm
invoke-rc.d170420755editdlrm
ip6119600755editdlrm
ip6tables992960755editdlrm
ip6tables-apply70570755editdlrm
ip6tables-legacy992960755editdlrm
ip6tables-legacy-restore992960755editdlrm
ip6tables-legacy-save992960755editdlrm
ip6tables-nft2204880755editdlrm
ip6tables-nft-restore2204880755editdlrm
ip6tables-nft-save2204880755editdlrm
ip6tables-restore992960755editdlrm
ip6tables-restore-translate2204880755editdlrm
ip6tables-save992960755editdlrm
ip6tables-translate2204880755editdlrm
iptables992960755editdlrm
iptables-apply70570755editdlrm
iptables-legacy992960755editdlrm
iptables-legacy-restore992960755editdlrm
iptables-legacy-save992960755editdlrm
iptables-nft2204880755editdlrm
iptables-nft-restore2204880755editdlrm
iptables-nft-save2204880755editdlrm
iptables-restore992960755editdlrm
iptables-restore-translate2204880755editdlrm
iptables-save992960755editdlrm
iptables-translate2204880755editdlrm
irqbalance644320755editdlrm
irqbalance-ui352000755editdlrm
iscsi-iname185840755editdlrm
iscsiadm4035600755editdlrm
iscsid4201520755editdlrm
iscsistart3750800755editdlrm
iscsi_discovery52850755editdlrm
isosize309520755editdlrm
kbdrate143280755editdlrm
killall5270160755editdlrm
kpartx472720755editdlrm
ldattach350480755editdlrm
ldconfig3870755editdlrm
ldconfig.real10537680755editdlrm
locale-gen43990755editdlrm
logrotate840560755editdlrm
logsave144960755editdlrm
losetup1129920755editdlrm
lsmod1744240755editdlrm
luksformat34010755editdlrm
lvchange28628720755editdlrm
lvconvert28628720755editdlrm
lvcreate28628720755editdlrm
lvdisplay28628720755editdlrm
lvextend28628720755editdlrm
lvm28628720755editdlrm
lvmconfig28628720755editdlrm
lvmdiskscan28628720755editdlrm
lvmdump103120755editdlrm
lvmpolld2376240755editdlrm
lvmsadc28628720755editdlrm
lvmsar28628720755editdlrm
lvreduce28628720755editdlrm
lvremove28628720755editdlrm
lvrename28628720755editdlrm
lvresize28628720755editdlrm
lvs28628720755editdlrm
lvscan28628720755editdlrm
make-bcache227600755editdlrm
mdadm6038000755editdlrm
mdmon3333040755editdlrm
mkdosfs353280755editdlrm
mke2fs1378480755editdlrm
mkfs145680755editdlrm
mkfs.bfs350480755editdlrm
mkfs.btrfs4623680755editdlrm
mkfs.cramfs431680755editdlrm
mkfs.ext21378480755editdlrm
mkfs.ext31378480755editdlrm
mkfs.ext41378480755editdlrm
mkfs.fat353280755editdlrm
mkfs.minix1087840755editdlrm
mkfs.msdos353280755editdlrm
mkfs.ntfs883360755editdlrm
mkfs.vfat353280755editdlrm
mkfs.xfs3750320755editdlrm
mkhomedir_helper227040755editdlrm
mkinitramfs117920755editdlrm
mklost+found146480755editdlrm
mkntfs883360755editdlrm
mkswap1087840755editdlrm
modinfo1744240755editdlrm
modprobe1744240755editdlrm
mount.fuse144880755editdlrm
mount.lowntfs-3g1217120755editdlrm
mount.ntfs1627040755editdlrm
mount.ntfs-3g1627040755editdlrm
mount.vmhgfs475920755editdlrm
mpathpersist318000755editdlrm
multipath349680755editdlrm
multipathd1292240755editdlrm
mysqld674968480755editdlrm
netplan7980755editdlrm
newusers1011680755editdlrm
nfnl_osf187360755editdlrm
nginx11951520755editdlrm
nologin146400755editdlrm
ntfsclone596720755editdlrm
ntfscp432720755editdlrm
ntfslabel350800755editdlrm
ntfsresize801520755editdlrm
ntfsundelete555600755editdlrm
on_ac_power22280755editdlrm
overlayroot-chroot25100755editdlrm
ownership147920755editdlrm
pam-auth-update203350755editdlrm
pam_extrausers_chkpwd431682755editdlrm
pam_extrausers_update431680755editdlrm
pam_getenv28900755editdlrm
pam_tally145040755editdlrm
pam_tally2186000755editdlrm
pam_timestamp_check144880755editdlrm
parted883200755editdlrm
partprobe145680755editdlrm
pdata_tools13522880755editdlrm
php-fpm7.447673200755editdlrm
phpdismod72780755editdlrm
phpenmod72780755editdlrm
phpquery63890755editdlrm
pivot_root145680755editdlrm
plymouthd1499200755editdlrm
popcon-largest-unused5430755editdlrm
popularity-contest53530755editdlrm
poweroff9965840755editdlrm
pvchange28628720755editdlrm
pvck28628720755editdlrm
pvcreate28628720755editdlrm
pvdisplay28628720755editdlrm
pvmove28628720755editdlrm
pvremove28628720755editdlrm
pvresize28628720755editdlrm
pvs28628720755editdlrm
pvscan28628720755editdlrm
pwck595680755editdlrm
pwconv553440755editdlrm
pwunconv553520755editdlrm
raw145680755editdlrm
readprofile227920755editdlrm
reboot9965840755editdlrm
remove-shell9040755editdlrm
resize2fs679680755editdlrm
rmmod1744240755editdlrm
rmt599520755editdlrm
rmt-tar599520755editdlrm
rsyslogd7272480755editdlrm
rtacct494480755editdlrm
rtcwake473360755editdlrm
rtmon801200755editdlrm
runlevel9965840755editdlrm
runuser678160755editdlrm
service92620755editdlrm
setcap146480755editdlrm
setvesablank144080755editdlrm
setvtrgb144720755editdlrm
sfdisk1415440755editdlrm
sgdisk1950480755editdlrm
shadowconfig8850755editdlrm
shutdown9965840755editdlrm
sshd8845200755editdlrm
start-stop-daemon484560755editdlrm
sulogin514320755editdlrm
swaplabel186640755editdlrm
swapoff227600755editdlrm
swapon514320755editdlrm
switch_root145680755editdlrm
sysctl309600755editdlrm
tarcat9360755editdlrm
tc5421600755editdlrm
tcpdump10442320755editdlrm
telinit9965840755editdlrm
thin_check13522880755editdlrm
thin_delta13522880755editdlrm
thin_dump13522880755editdlrm
thin_ls13522880755editdlrm
thin_metadata_size13522880755editdlrm
thin_repair13522880755editdlrm
thin_restore13522880755editdlrm
thin_rmap13522880755editdlrm
thin_trim13522880755editdlrm
tipc1292640755editdlrm
tune2fs1091120755editdlrm
tzconfig1060755editdlrm
ufw49360755editdlrm
unix_chkpwd431602755editdlrm
unix_update431600755editdlrm
update-ca-certificates54180755editdlrm
update-grub640755editdlrm
update-grub-gfxpayload3010755editdlrm
update-grub2640755editdlrm
update-info-dir17000755editdlrm
update-initramfs74190755editdlrm
update-locale30630755editdlrm
update-mime94020755editdlrm
update-passwd353920755editdlrm
update-pciids17490755editdlrm
update-rc.d171610755editdlrm
update-secureboot-policy76050755editdlrm
upgrade-from-grub-legacy15240755editdlrm
useradd1471600755editdlrm
userdel1012640755editdlrm
usermod1428400755editdlrm
uuidd433200755editdlrm
validlocale17730755editdlrm
vcstime143280755editdlrm
veritysetup530640755editdlrm
vgcfgbackup28628720755editdlrm
vgcfgrestore28628720755editdlrm
vgchange28628720755editdlrm
vgck28628720755editdlrm
vgconvert28628720755editdlrm
vgcreate28628720755editdlrm
vgdisplay28628720755editdlrm
vgexport28628720755editdlrm
vgextend28628720755editdlrm
vgimport28628720755editdlrm
vgimportclone28628720755editdlrm
vgmerge28628720755editdlrm
vgmknodes28628720755editdlrm
vgreduce28628720755editdlrm
vgremove28628720755editdlrm
vgrename28628720755editdlrm
vgs28628720755editdlrm
vgscan28628720755editdlrm
vgsplit28628720755editdlrm
vigr702000755editdlrm
vipw702000755editdlrm
visudo2234320755editdlrm
vpddecode190240755editdlrm
wipefs473360755editdlrm
xfs_admin14150755editdlrm
xfs_bmap6950755editdlrm
xfs_copy924480755editdlrm
xfs_db6349760755editdlrm
xfs_estimate143440755editdlrm
xfs_freeze8000755editdlrm
xfs_fsr430320755editdlrm
xfs_growfs349600755editdlrm
xfs_info12940755editdlrm
xfs_io1918320755editdlrm
xfs_logprint759280755editdlrm
xfs_mdrestore307360755editdlrm
xfs_metadump7820755editdlrm
xfs_mkfile10400755editdlrm
xfs_ncheck6850755editdlrm
xfs_quota880720755editdlrm
xfs_repair5766640755editdlrm
xfs_rtcp184240755editdlrm
xfs_scrub1045600755editdlrm
xfs_scrub_all60050755editdlrm
xfs_spaceman431600755editdlrm
xtables-legacy-multi992960755editdlrm
xtables-monitor2204880755editdlrm
xtables-nft-multi2204880755editdlrm
zerofree102320755editdlrm
zic637840755editdlrm
zramctl1170880755editdlrm
Edit: /usr/sbin/pam-auth-update (20335B)
#!/usr/bin/perl -w # pam-auth-update: update /etc/pam.d/common-* from /usr/share/pam-configs # # Update the /etc/pam.d/common-* files based on the per-package profiles # provided in /usr/share/pam-configs/ taking into consideration user's # preferences (as determined via debconf prompting). # # Written by Steve Langasek # # Copyright (C) 2008 Canonical Ltd. # # This program is free software; you can redistribute it and/or modify # it under the terms of version 3 of the GNU General Public License as # published by the Free Software Foundation. # # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program; if not, write to the Free Software # Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, # USA. use strict; use Debconf::Client::ConfModule ':all'; use IPC::Open2 'open2'; version('2.0'); my $capb=capb('backup escape'); my $inputdir = '/usr/share/pam-configs'; my $template = 'libpam-runtime/profiles'; my $errtemplate = 'libpam-runtime/conflicts'; my $overridetemplate = 'libpam-runtime/override'; my $blanktemplate = 'libpam-runtime/no_profiles_chosen'; my $titletemplate = 'libpam-runtime/title'; my $confdir = '/etc/pam.d'; my $savedir = '/var/lib/pam'; my (%profiles, @sorted, @enabled, @conflicts, @new, %removals, %to_enable); my $force = 0; my $package = 0; my $priority = 'high'; my %md5sums = ( 'auth' => ['8d4fe17e66ba25de16a117035d1396aa'], 'account' => ['3c0c362eaf3421848b679d63fd48c3fa'], 'password' => [ '50fce2113dfda83ac8bdd5a6e706caec', '4bd7610f2e85f8ddaef79c7db7cb49eb', '9ba753d0824276b44bcadfee1f87b6bc', ], 'session' => [ '240fb92986c885b327cdb21dd641da8c', '4a25673e8b36f1805219027d3be02cd2', '73144a2f4e609a922a51e301cd66a57e', ], 'session-noninteractive' => [ 'ad2b78ce1498dd637ef36469430b6ac6', 'a20e8df3469bfe25c13a3b39161b30f0', ], ); opendir(DIR, $inputdir) || die "could not open config directory: $!"; while (my $profile = readdir(DIR)) { next if ($profile eq '.' || $profile eq '..' || $profile =~ m/~$/ || $profile =~ m/^#.+#$/); %{$profiles{$profile}} = parse_pam_profile($inputdir . '/' . $profile); } closedir DIR; # use a '--force' arg to specify that /etc/pam.d should be overwritten; # used only on upgrades where the postinst has already determined that the # checksums match. Module packages other than libpam-runtime itself must # NEVER use this option! Document with big skullses and crossboneses! It # needs to be exposed for libpam-runtime because that's the package that # decides whether we have a pristine config to be converted, and knows # whether the version being upgraded from is one for which the conversion # should be done. while ($#ARGV >= 0) { my $opt = shift; if ($opt eq '--force') { $force = 1; } elsif ($opt eq '--package') { $package = 1; } elsif ($opt eq '--remove') { while ($#ARGV >= 0) { last if ($ARGV[0] =~ /^--/); $removals{shift @ARGV} = 1; } # --remove implies --package $package = 1 if (keys(%removals)); } elsif ($opt eq '--enable') { while ($#ARGV >= 0) { last if ($ARGV[0] =~ /^--/); $to_enable{shift @ARGV} = 1; } # --enable implies --package $package = 1 if (keys(%to_enable)); } } $priority = 'medium' if ($package); x_loadtemplatefile('/var/lib/dpkg/info/libpam-runtime.templates','libpam-runtime'); # always sort by priority, so we have consistency and don't have to # shuffle later @sorted = sort { $profiles{$b}->{'Priority'} <=> $profiles{$a}->{'Priority'} || $b cmp $a } keys(%profiles); # If we're being called for package removal, filter out those options here @sorted = grep { !$removals{$_} } @sorted; subst($template, 'profile_names', join(', ',@sorted)); subst($template, 'profiles', join(', ', map { $profiles{$_}->{'Name'} } @sorted)); my $diff = diff_profiles($confdir,$savedir); if ($diff) { @enabled = grep { !$removals{$_} } @{$diff->{'mods'}}; } else { @enabled = split(/, /,get($template)); } # find out what we've seen, so we can ignore those defaults my %seen; if (-e $savedir . '/seen') { open(SEEN,$savedir . '/seen') or die("open(${savedir}/seen) failed: $!"); while () { chomp; $seen{$_} = 1; } close(SEEN); } # filter out any options that are no longer available for any reason @enabled = grep { $profiles{$_} } @enabled; # an empty module set is an error, so in that case grab all the defaults if (!@enabled) { %seen = (); $priority = 'high' unless ($force); } # add configs to enable push(@enabled, grep { $to_enable{$_} } @sorted); # add any previously-unseen configs push(@enabled, grep { $profiles{$_}->{'Default'} eq 'yes' && !$seen{$_} } @sorted); @enabled = sort { $profiles{$b}->{'Priority'} <=> $profiles{$a}->{'Priority'} || $b cmp $a } @enabled; my $prev = ''; @enabled = grep { $_ ne $prev && (($prev) = $_) } @enabled; # Do we have any new options to show? If not, we shouldn't reprompt the # user, at any priority level, unless explicitly called. @new = grep { !$seen{$_} } @sorted; settitle($titletemplate); # if diff_profiles() fails, and we weren't passed a 'force' argument # (because this isn't an upgrade from an old version, or the checksum # didn't match, or we're being called by some other module package), prompt # the user whether to override. If the user declines (the default), we # never again manage this config unless manually called with '--force'. if (!$diff && !$force) { input('high',$overridetemplate); go(); $force = 1 if (get($overridetemplate) eq 'true'); } if (!$diff && !$force) { print STDERR <= 0; $i--) { my $conflict = $enabled[$i]; if ($profiles{$elem}->{'Conflicts'}->{$conflict}) { splice(@enabled,$i,1); my $desc = $profiles{$elem}->{'Name'} . ', ' . $profiles{$conflict}->{'Name'}; push(@conflicts,$desc); } } } if (@conflicts) { subst($errtemplate, 'conflicts', join("\\n", @conflicts)); input('high',$errtemplate); } set($template, join(', ', @enabled)); if (!@enabled) { input('high',$blanktemplate); # we can only end up here by user error, but give them another # shot at selecting a correct config anyway. fset($template,'seen','false'); } } while (@conflicts || !@enabled); # the decision has been made about what configs to use, so even if # something fails after this, we shouldn't go munging the default # options again. Save the list of known configs to /var/lib/pam. open(SEEN,"> $savedir/seen") or die("open(${savedir}/seen) failed: $!"); for my $i (@sorted) { print SEEN "$i\n"; } close(SEEN) or die("close(${savedir}/seen) failed: $!"); # @enabled now contains our list of profiles to use for piecing together # a config # we have: # - templates into which we insert the specialness # - magic comments denoting the beginning and end of our managed block; # looking at only the functional config lines would potentially let us # handle more cases, at the expense of much greater complexity, so # pass on this at least for the first round # - a representation of the autogenerated config stored in /var/lib/pam, # that we can diff against in order to account for changed options or # manually dropped modules # - a hash describing the local modifications the user has made to the # config; these are always preserved unless manually overridden with # the --force option write_profiles(\%profiles, \@enabled, $confdir, $savedir, $diff, $force); # take a single line from a stock config, and merge it with the # information about local admin edits sub merge_one_line { my ($line,$diff,$count) = @_; my (@opts,$modline); my ($adds,$removes); $line =~ /^((\[[^]]+\]|\w+)\s+\S+)\s*(.*)/; @opts = split(/\s+/,$3); $modline = $1; $modline =~ s/end/$count/g; if ($diff) { my $mod = $modline; $mod =~ s/(\[[^0-9]*)[0-9]+(.*\])/$1$2/g; $adds = \%{$diff->{'add'}{$mod}}; $removes = \%{$diff->{'remove'}{$mod}}; } else { $adds = $removes = undef; } for (my $i = 0; $i <= $#opts; $i++) { if ($adds->{$opts[$i]}) { delete $adds->{$opts[$i]}; } if ($removes->{$opts[$i]}) { splice(@opts,$i,1); $i--; } } return $modline . " " . join(' ',@opts,sort keys(%{$adds})) . "\n"; } # return the lines for a given config name, type, and position in the stack sub lines_for_module_and_type { my ($profiles, $mod, $type, $modpos) = @_; if ($modpos == 0 && $profiles->{$mod}{$type . '-Initial'}) { return $profiles->{$mod}{$type . '-Initial'}; } return $profiles->{$mod}{$type}; } # create a single PAM config from the indicated template and selections, # writing to a new file sub create_from_template { my($template,$dest,$profiles,$enabled,$diff,$type) = @_; my $state = 0; my $uctype = ucfirst($type); $type =~ s/-noninteractive//; open(INPUT,$template) || return 0; open(OUTPUT,">$dest") || return 0; while () { if ($state == 1) { if (/^# here's the fallback if no module succeeds/) { print OUTPUT; $state++; } next; } if ($state == 3) { if (/^# end of pam-auth-update config/) { print OUTPUT; $state++; } next; } print OUTPUT; my ($pattern,$val); if ($state == 0) { $pattern = '^# here are the per-package modules \(the "Primary" block\)'; $val = 'Primary'; } elsif ($state == 2) { $pattern = '^# and here are more per-package modules \(the "Additional" block\)'; $val = 'Additional'; } else { next; } if (/$pattern/) { my $i = 0; my $count = 0; # first we need to get a count of lines that we're # going to output, so we can fix up the jumps correctly for my $mod (@{$enabled}) { my $output; next if (!$profiles->{$mod}{$uctype . '-Type'}); next if $profiles->{$mod}{$uctype . '-Type'} ne $val; $output = lines_for_module_and_type($profiles, $mod, $uctype, $i++); # bypasses a perl warning about @_, sigh my @tmparr = split("\n+",$output); $count += @tmparr; } # in case anything tries to jump in the 'additional' # block, let's try not to jump off the stack... $count-- if ($val eq 'Additional'); # no primary block, so output a stock pam_permit line # to keep the stack intact if ($val eq 'Primary' && $count == 0) { print OUTPUT "$type\t[default=1]\t\t\tpam_permit.so\n"; } $i = 0; for my $mod (@{$enabled}) { my $output; my @output; next if (!$profiles->{$mod}{$uctype . '-Type'}); next if $profiles->{$mod}{$uctype . '-Type'} ne $val; $output = lines_for_module_and_type($profiles, $mod, $uctype, $i++); for my $line (split("\n",$output)) { $line = merge_one_line($line,$diff, $count); print OUTPUT "$type\t$line"; $count--; } } $state++; } } close(INPUT); close(OUTPUT) or die("close($dest) failed: $!"); if ($state < 4) { unlink($dest); return 0; } return 1; } # take a template file, strip out everything between the markers, and # return the md5sum of the remaining contents. Used for testing for # local modifications of the boilerplate. sub get_template_md5sum { my($template) = @_; my $state = 0; open(INPUT,$template) || return ''; my($md5sum_fd,$output_fd); my $pid = open2($md5sum_fd, $output_fd, 'md5sum'); return '' if (!$pid); while () { if ($state == 1) { if (/^# here's the fallback if no module succeeds/) { print $output_fd $_; $state++; } next; } if ($state == 3) { if (/^# end of pam-auth-update config/) { print $output_fd $_; $state++; } next; } print $output_fd $_; my ($pattern,$val); if ($state == 0) { $pattern = '^# here are the per-package modules \(the "Primary" block\)'; } elsif ($state == 2) { $pattern = '^# and here are more per-package modules \(the "Additional" block\)'; } else { next; } if (/$pattern/) { $state++; } } close(INPUT); close($output_fd); my $md5sum = <$md5sum_fd>; close($md5sum_fd); waitpid $pid, 0; $md5sum = (split(/\s+/,$md5sum))[0]; return $md5sum; } # merge a set of module declarations into a set of new config files, # using the information returned from diff_profiles(). sub write_profiles { my($profiles,$enabled,$confdir,$savedir,$diff,$force) = @_; if (! -d $savedir) { mkdir($savedir); } # because we can't atomically replace both /var/lib/pam/$foo and # /etc/pam.d/common-$foo at the same time, take steps to make this # somewhat robust for my $type ('auth','account','password','session', 'session-noninteractive') { my $target = $confdir . '/common-' . $type; my $template = $target; my $dest = $template . '.pam-new'; my $diff = $diff; if ($diff) { $diff = \%{$diff->{$type}}; } # Detect if the template is unmodified, and if so, use # the version from /usr/share. Depends on knowing the # md5sums of the originals. my $md5sum = get_template_md5sum($template); for my $i (@{$md5sums{$type}}) { if ($md5sum eq $i) { $template = '/usr/share/pam/common-' . $type; last; } } # first, write out the new config if (!create_from_template($template,$dest,$profiles,$enabled, $diff,$type)) { if (!$force) { return 0; } $template = '/usr/share/pam/common-' . $type; if (!create_from_template($template,$dest,$profiles, $enabled,$diff,$type)) { return 0; } } # then write out the saved config if (!open(OUTPUT, "> $savedir/$type.new")) { unlink($dest); return 0; } my $i = 0; my $uctype = ucfirst($type); for my $mod (@{$enabled}) { my $output; next if (!$profiles->{$mod}{$uctype . '-Type'}); next if ($profiles->{$mod}{$uctype . '-Type'} eq 'Additional'); $output = lines_for_module_and_type($profiles, $mod, $uctype, $i++); if ($output) { print OUTPUT "Module: $mod\n"; print OUTPUT $output . "\n"; } } # no primary block, so output a stock pam_permit line if ($i == 0) { print OUTPUT "Module: null\n"; print OUTPUT "[default=1]\t\t\tpam_permit.so\n"; } $i = 0; for my $mod (@{$enabled}) { my $output; next if (!$profiles->{$mod}{$uctype . '-Type'}); next if ($profiles->{$mod}{$uctype . '-Type'} eq 'Primary'); $output = lines_for_module_and_type($profiles, $mod, $uctype, $i++); if ($output) { print OUTPUT "Module: $mod\n"; print OUTPUT $output . "\n"; } } close(OUTPUT) or die("close($dest) failed: $!"); # then do the renames, back-to-back # we have to use system because File::Copy is in # perl-modules, not perl-base if (-e $target && $force) { system('cp','-f',$target,$target . '.pam-old') == 0 or die("cp -f ${target} ${target}.pam.old failed"); } rename($dest,$target) or die("rename($dest, $target) failed: $!"); rename("$savedir/${type}.new","$savedir/$type") or die("rename(${savedir}/${type}.new, ${savedir}/${type}) failed: $!"); } # at the end of a successful write, reset the 'seen' flag and the # value of the debconf override question. fset($overridetemplate,'seen','false'); set($overridetemplate,'false'); } # reconcile the current config in /etc/pam.d with the saved ones in # /var/lib/pam; returns a hash of profile names and the corresponding # options that should be added/removed relative to the stock config. # returns false if any of the markers are missing that permit a merge, # or on any other failure. sub diff_profiles { my ($sourcedir,$savedir) = @_; my (%diff); @{$diff{'mods'}} = (); # Load the saved config from /var/lib/pam, then iterate through all # lines in the current config that are in the managed block. # If anything fails here, just return immediately since we then # have nothing to merge; instead, the caller will decide later # whether to force an overwrite. for my $type ('auth','account','password','session', 'session-noninteractive') { my (@saved,$modname); open(SAVED,$savedir . '/' . $type) || return 0; while () { if (/^Module: (.*)/) { $modname = $1; next; } chomp; # trim out the destination of any jumps; this saves # us from having to re-parse everything just to fix # up the jump lengths, when changes to these will # already show up as inconsistencies elsewhere s/(\[[^0-9]*)[0-9]+(.*\])/$1$2/g; s/(\[.*)end(.*\])/$1$2/g; my (@temp) = ($modname,$_); push(@saved,\@temp); } close(SAVED); my $state = 0; my (@prev_opts,$curmod); my $realtype = $type; $realtype =~ s/-noninteractive//; open(CURRENT,$sourcedir . '/common-' . $type) || return 0; while () { if ($state == 0) { $state = 1 if (/^# here are the per-package modules \(the "Primary" block\)/); next; } if ($state == 1) { s/^$realtype\s+//; if (/^# here's the fallback if no module succeeds/) { $state = 2; next; } } if ($state == 2) { $state = 3 if (/^# and here are more per-package modules \(the "Additional" block\)/); next; } if ($state == 3) { last if (/^# end of pam-auth-update config/); s/^$realtype\s+//; } my $found = 0; my $curopts; while (!$found && $#saved >= 0) { my $line; ($modname,$line) = @{$saved[0]}; shift(@saved); $line =~ /^((\[[^]]+\]|\w+)\s+\S+)\s*(.*)/; @prev_opts = split(/\s+/,$3); $curmod = $1; # FIXME: the key isn't derived from the config # name, so collisions are possible if more # than one config references the same module $_ =~ s/(\[[^0-9]*)[0-9]+(.*\])/$1$2/g; # check if this is a match for the current line if ($_ =~ /^\Q$curmod\E\s*(.*)$/) { $found = 1; $curopts = $1; push(@{$diff{'mods'}},$modname); } } # there's a line in the live config that doesn't # correspond to anything from the saved config. # treat this as a failure; it's very error-prone # to decide what to do with an added line that # didn't come from a package. return 0 if (!$found); for my $opt (split(/\s+/,$curopts)) { my $found = 0; for (my $i = 0; $i <= $#prev_opts; $i++) { if ($prev_opts[$i] eq $opt) { $found = 1; splice(@prev_opts,$i,1); } } $diff{$type}{'add'}{$curmod}{$opt} = 1 if (!$found); } for my $opt (@prev_opts) { $diff{$type}{'remove'}{$curmod}{$opt} = 1; } } close(CURRENT); # we couldn't parse the config, so the merge fails return 0 if ($state < 3); } return \%diff; } # simple function to parse a provided config file, in pseudo-RFC822 # format, sub parse_pam_profile { my ($profile) = $_[0]; my $fieldname; my %profile; open(PROFILE, $profile) || die "could not read profile $profile: $!"; while () { if (/^(\S+):\s+(.*)\s*$/) { $fieldname = $1; # compatibility with the first implementation round; # "Auth-Final" is now just called "Auth" $fieldname =~ s/-Final$//; if ($fieldname eq 'Conflicts') { foreach my $elem (split(/, /, $2)) { $profile{'Conflicts'}->{$elem} = 1; } } else { $profile{$fieldname} = $2; } } else { chomp; s/^\s+//; s/\s+$//; $profile{$fieldname} .= "\n$_" if ($_); $profile{$fieldname} =~ s/^[\n\s]+//; } } close(PROFILE); if (!defined($profile{'Session-Interactive-Only'})) { $profile{'Session-noninteractive-Type'} = $profile{'Session-Type'}; $profile{'Session-noninteractive'} = $profile{'Session'}; $profile{'Session-noninteractive-Initial'} = $profile{'Session-Initial'}; } return %profile; }