1 /* vi: set sw=4 ts=4: */
5 * usually setuid root, -c option only works if getuid() == geteuid()
7 * Copyright 1994 Matthew Dillon (dillon@apollo.west.oic.com)
8 * Vladimir Oleynik <dzo@simtreas.ru> (C) 2002
10 * Licensed under the GPL v2 or later, see the file LICENSE in this tarball.
16 #define CRONTABS "/var/spool/cron/crontabs"
19 #define CRONUPDATE "cron.update"
22 #define PATH_VI "/bin/vi" /* location of vi */
25 static void change_user(const struct passwd *pas)
27 setenv("USER", pas->pw_name, 1);
28 setenv("HOME", pas->pw_dir, 1);
29 setenv("SHELL", DEFAULT_SHELL, 1);
31 /* initgroups, setgid, setuid */
34 if (chdir(pas->pw_dir) < 0) {
35 bb_perror_msg("chdir(%s) by %s failed",
36 pas->pw_dir, pas->pw_name);
41 static void edit_file(const struct passwd *pas, const char *file)
46 if (pid < 0) /* failure */
47 bb_perror_msg_and_die("vfork");
48 if (pid) { /* parent */
53 /* CHILD - change user and run editor */
55 ptr = getenv("VISUAL");
57 ptr = getenv("EDITOR");
62 BB_EXECLP(ptr, ptr, file, NULL);
63 bb_perror_msg_and_die("exec %s", ptr);
66 static int open_as_user(const struct passwd *pas, const char *file)
68 struct fd_pair filedes;
74 if (pid < 0) /* ERROR */
75 bb_perror_msg_and_die("vfork");
76 if (pid) { /* PARENT */
77 int n = safe_read(filedes.rd, &c, 1);
80 if (n > 0) /* child says it can read */
81 return open(file, O_RDONLY);
87 /* initgroups, setgid, setuid */
90 /* We just try to read one byte. If that works, file is readable
91 * under this user. We signal that by sending one byte to parent. */
92 if (safe_read(xopen(file, O_RDONLY), &c, 1) == 1)
93 safe_write(filedes.wr, &c, 1); /* "papa, I can read!" */
97 int crontab_main(int argc, char **argv) MAIN_EXTERNALLY_VISIBLE;
98 int crontab_main(int argc, char **argv)
100 const struct passwd *pas;
101 const char *crontab_dir = CRONTABS;
104 char *user_name; /* -u USER */
109 /* file [opts] Replace crontab from file
110 * - [opts] Replace crontab from stdin
112 * -c dir Crontab directory
113 * -l List crontab for user
114 * -e Edit crontab for user
115 * -r Delete crontab for user
116 * bbox also supports -d == -r, but most other crontab
117 * implementations do not. Deprecated.
125 OPT_ler = OPT_l + OPT_e + OPT_r,
130 opt_complementary = "?1:dr"; /* max one argument; -d implies -r */
131 opt_ler = getopt32(argv, "u:c:lerd", &user_name, &crontab_dir);
134 if (my_uid != geteuid()) { /* run by non-root? */
135 if (opt_ler & (OPT_u|OPT_c))
136 bb_error_msg_and_die("only root can use -c or -u");
137 /* Clear dangerous stuff, set PATH */
138 sanitize_env_for_suid();
141 if (opt_ler & OPT_u) {
142 pas = getpwnam(user_name);
144 bb_error_msg_and_die("user %s is not known", user_name);
145 my_uid = pas->pw_uid;
147 pas = getpwuid(my_uid);
149 bb_perror_msg_and_die("no user record for UID %u",
153 #define user_name DONT_USE_ME_BEYOND_THIS_POINT
154 #define my_uid DONT_USE_ME_BEYOND_THIS_POINT
156 /* From now on, keep only -l, -e, -r bits */
158 if ((opt_ler - 1) & opt_ler) /* more than one bit set? */
161 /* Read replacement file under user's UID/GID/group vector */
162 if (!opt_ler) { /* Replace? */
165 if (NOT_LONE_DASH(argv[0])) {
166 fd = open_as_user(pas, argv[0]);
168 bb_error_msg_and_die("user %s cannot read %s",
169 pas->pw_name, argv[0]);
170 xmove_fd(fd, STDIN_FILENO);
174 /* cd to our crontab directory */
179 /* Handle requested operation */
182 default: /* case OPT_r: Delete */
183 remove(pas->pw_name);
186 case OPT_l: /* List */
188 char *args[2] = { pas->pw_name, NULL };
191 * the rest go play with cron update file */
194 case OPT_e: /* Edit */
195 tmp_fname = xasprintf("%s.%u", crontab_dir, (unsigned)getpid());
196 fd = xopen3(tmp_fname, O_RDWR|O_CREAT|O_TRUNC|O_EXCL, 0600);
197 xmove_fd(fd, STDIN_FILENO);
198 fd = open(pas->pw_name, O_RDONLY);
200 bb_copyfd_eof(fd, STDIN_FILENO);
203 fchown(STDIN_FILENO, pas->pw_uid, pas->pw_gid);
204 edit_file(pas, tmp_fname);
205 xlseek(STDIN_FILENO, 0, SEEK_SET);
208 case 0: /* Replace (no -l, -e, or -r were given) */
209 new_fname = xasprintf("%s.new", pas->pw_name);
210 fd = open(new_fname, O_WRONLY|O_CREAT|O_TRUNC|O_APPEND, 0600);
212 bb_copyfd_eof(STDIN_FILENO, fd);
214 rename(new_fname, pas->pw_name);
216 bb_error_msg("cannot create %s/%s",
217 crontab_dir, new_fname);
226 /* Bump notification file. Handle window where crond picks file up
227 * before we can write our entry out.
229 while ((fd = open(CRONUPDATE, O_WRONLY|O_CREAT|O_APPEND)) >= 0) {
232 fdprintf(fd, "%s\n", pas->pw_name);
233 if (fstat(fd, &st) != 0 || st.st_nlink != 0) {
238 * file was deleted, maybe crond missed our notification */
243 bb_error_msg("cannot append to %s/%s",
244 crontab_dir, CRONUPDATE);