1 /* vi: set sw=4 ts=4: */
5 * usually setuid root, -c option only works if getuid() == geteuid()
7 * Copyright 1994 Matthew Dillon (dillon@apollo.west.oic.com)
8 * Vladimir Oleynik <dzo@simtreas.ru> (C) 2002
10 * Licensed under the GPL v2 or later, see the file LICENSE in this tarball.
16 #define CRONTABS "/var/spool/cron/crontabs"
19 #define CRONUPDATE "cron.update"
22 #define PATH_VI "/bin/vi" /* location of vi */
25 static void change_user(const struct passwd *pas)
27 setenv("USER", pas->pw_name, 1);
28 setenv("HOME", pas->pw_dir, 1);
29 setenv("SHELL", DEFAULT_SHELL, 1);
31 /* initgroups, setgid, setuid */
34 if (chdir(pas->pw_dir) < 0) {
35 bb_perror_msg("chdir(%s) by %s failed",
36 pas->pw_dir, pas->pw_name);
41 static void edit_file(const struct passwd *pas, const char *file)
46 if (pid < 0) /* failure */
47 bb_perror_msg_and_die("vfork");
48 if (pid) { /* parent */
53 /* CHILD - change user and run editor */
55 ptr = getenv("VISUAL");
57 ptr = getenv("EDITOR");
62 BB_EXECLP(ptr, ptr, file, NULL);
63 bb_perror_msg_and_die("exec %s", ptr);
66 static int open_as_user(const struct passwd *pas, const char *file)
72 if (pid < 0) /* ERROR */
73 bb_perror_msg_and_die("vfork");
74 if (pid) { /* PARENT */
75 if (wait4pid(pid) == 0) {
76 /* exitcode 0: child says it can read */
77 return open(file, O_RDONLY);
83 /* initgroups, setgid, setuid */
85 /* We just try to read one byte. If it works, file is readable
86 * under this user. We signal that by exiting with 0. */
87 _exit(safe_read(xopen(file, O_RDONLY), &c, 1) < 0);
90 int crontab_main(int argc, char **argv) MAIN_EXTERNALLY_VISIBLE;
91 int crontab_main(int argc ATTRIBUTE_UNUSED, char **argv)
93 const struct passwd *pas;
94 const char *crontab_dir = CRONTABS;
97 char *user_name; /* -u USER */
101 /* file [opts] Replace crontab from file
102 * - [opts] Replace crontab from stdin
104 * -c dir Crontab directory
105 * -l List crontab for user
106 * -e Edit crontab for user
107 * -r Delete crontab for user
108 * bbox also supports -d == -r, but most other crontab
109 * implementations do not. Deprecated.
117 OPT_ler = OPT_l + OPT_e + OPT_r,
120 opt_complementary = "?1:dr"; /* max one argument; -d implies -r */
121 opt_ler = getopt32(argv, "u:c:lerd", &user_name, &crontab_dir);
124 if (sanitize_env_if_suid()) { /* Clears dangerous stuff, sets PATH */
125 /* run by non-root? */
126 if (opt_ler & (OPT_u|OPT_c))
127 bb_error_msg_and_die("only root can use -c or -u");
130 if (opt_ler & OPT_u) {
131 pas = getpwnam(user_name);
133 bb_error_msg_and_die("user %s is not known", user_name);
135 uid_t my_uid = getuid();
136 pas = getpwuid(my_uid);
138 bb_perror_msg_and_die("no user record for UID %u",
142 #define user_name DONT_USE_ME_BEYOND_THIS_POINT
144 /* From now on, keep only -l, -e, -r bits */
146 if ((opt_ler - 1) & opt_ler) /* more than one bit set? */
149 /* Read replacement file under user's UID/GID/group vector */
150 if (!opt_ler) { /* Replace? */
153 if (NOT_LONE_DASH(argv[0])) {
154 fd = open_as_user(pas, argv[0]);
156 bb_error_msg_and_die("user %s cannot read %s",
157 pas->pw_name, argv[0]);
158 xmove_fd(fd, STDIN_FILENO);
162 /* cd to our crontab directory */
167 /* Handle requested operation */
170 default: /* case OPT_r: Delete */
171 unlink(pas->pw_name);
174 case OPT_l: /* List */
176 char *args[2] = { pas->pw_name, NULL };
179 * the rest go play with cron update file */
182 case OPT_e: /* Edit */
183 tmp_fname = xasprintf("%s.%u", crontab_dir, (unsigned)getpid());
184 fd = xopen3(tmp_fname, O_RDWR|O_CREAT|O_TRUNC|O_EXCL, 0600);
185 xmove_fd(fd, STDIN_FILENO);
186 fd = open(pas->pw_name, O_RDONLY);
188 bb_copyfd_eof(fd, STDIN_FILENO);
191 fchown(STDIN_FILENO, pas->pw_uid, pas->pw_gid);
192 edit_file(pas, tmp_fname);
193 xlseek(STDIN_FILENO, 0, SEEK_SET);
196 case 0: /* Replace (no -l, -e, or -r were given) */
197 new_fname = xasprintf("%s.new", pas->pw_name);
198 fd = open(new_fname, O_WRONLY|O_CREAT|O_TRUNC|O_APPEND, 0600);
200 bb_copyfd_eof(STDIN_FILENO, fd);
202 xrename(new_fname, pas->pw_name);
204 bb_error_msg("cannot create %s/%s",
205 crontab_dir, new_fname);
214 /* Bump notification file. Handle window where crond picks file up
215 * before we can write our entry out.
217 while ((fd = open(CRONUPDATE, O_WRONLY|O_CREAT|O_APPEND, 0600)) >= 0) {
220 fdprintf(fd, "%s\n", pas->pw_name);
221 if (fstat(fd, &st) != 0 || st.st_nlink != 0) {
226 * file was deleted, maybe crond missed our notification */
231 bb_error_msg("cannot append to %s/%s",
232 crontab_dir, CRONUPDATE);