2 * Copyright (c) 2000 Andre Lucas. All rights reserved.
3 * Portions copyright (c) 1998 Todd C. Miller
4 * Portions copyright (c) 1996 Jason Downs
5 * Portions copyright (c) 1996 Theo de Raadt
7 * Redistribution and use in source and binary forms, with or without
8 * modification, are permitted provided that the following conditions
10 * 1. Redistributions of source code must retain the above copyright
11 * notice, this list of conditions and the following disclaimer.
12 * 2. Redistributions in binary form must reproduce the above copyright
13 * notice, this list of conditions and the following disclaimer in the
14 * documentation and/or other materials provided with the distribution.
15 * 3. All advertising materials mentioning features or use of this software
16 * must display the following acknowledgement:
17 * This product includes software developed by Markus Friedl.
18 * 4. The name of the author may not be used to endorse or promote products
19 * derived from this software without specific prior written permission.
21 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
22 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
23 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
24 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
25 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
26 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
27 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
28 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
29 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
30 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
34 ** loginrec.c: platform-independent login recording and lastlog retrieval
38 The new login code explained
39 ============================
41 This code attempts to provide a common interface to login recording
42 (utmp and friends) and last login time retrieval.
44 Its primary means of achieving this is to use 'struct logininfo', a
45 union of all the useful fields in the various different types of
46 system login record structures one finds on UNIX variants.
48 We depend on autoconf to define which recording methods are to be
49 used, and which fields are contained in the relevant data structures
50 on the local system. Many C preprocessor symbols affect which code
53 The code is designed to make it easy to modify a particular
54 recording method, without affecting other methods nor requiring so
55 many nested conditional compilation blocks as were commonplace in
58 For login recording, we try to use the local system's libraries as
59 these are clearly most likely to work correctly. For utmp systems
60 this usually means login() and logout() or setutent() etc., probably
61 in libutil, along with logwtmp() etc. On these systems, we fall back
62 to writing the files directly if we have to, though this method
63 requires very thorough testing so we do not corrupt local auditing
64 information. These files and their access methods are very system
67 For utmpx systems, the corresponding library functions are
68 setutxent() etc. To the author's knowledge, all utmpx systems have
69 these library functions and so no direct write is attempted. If such
70 a system exists and needs support, direct analogues of the [uw]tmp
73 Retrieving the time of last login ('lastlog') is in some ways even
74 more problemmatic than login recording. Some systems provide a
75 simple table of all users which we seek based on uid and retrieve a
76 relatively standard structure. Others record the same information in
77 a directory with a separate file, and others don't record the
78 information separately at all. For systems in the latter category,
79 we look backwards in the wtmp or wtmpx file for the last login entry
80 for our user. Naturally this is slower and on busy systems could
81 incur a significant performance penalty.
86 In OpenSSH all login recording and retrieval is performed in
87 login.c. Here you'll find working examples. Also, in the logintest.c
88 program there are more examples.
90 Internal handler calling method
91 -------------------------------
93 When a call is made to login_login() or login_logout(), both
94 routines set a struct logininfo flag defining which action (log in,
95 or log out) is to be taken. They both then call login_write(), which
96 calls whichever of the many structure-specific handlers autoconf
97 selects for the local system.
99 The handlers themselves handle system data structure specifics. Both
100 struct utmp and struct utmpx have utility functions (see
101 construct_utmp*()) to try to make it simpler to add extra systems
102 that introduce new features to either structure.
104 While it may seem terribly wasteful to replicate so much similar
105 code for each method, experience has shown that maintaining code to
106 write both struct utmp and utmpx in one function, whilst maintaining
107 support for all systems whether they have library support or not, is
108 a difficult and time-consuming task.
110 Lastlog support proceeds similarly. Functions login_get_lastlog()
111 (and its OpenSSH-tuned friend login_get_lastlog_time()) call
112 getlast_entry(), which tries one of three methods to find the last
113 login time. It uses local system lastlog support if it can,
114 otherwise it tries wtmp or wtmpx before giving up and returning 0,
120 In many cases it's possible to tweak autoconf to select the correct
121 methods for a particular platform, either by improving the detection
122 code (best), or by presetting DISABLE_<method> or CONF_<method>_FILE
123 symbols for the platform.
125 Use logintest to check which symbols are defined before modifying
126 configure.ac and loginrec.c. (You have to build logintest yourself
127 with 'make logintest' as it's not built by default.)
129 Otherwise, patches to the specific method(s) are very helpful!
135 ** homegrown ttyslot()
142 ** Linux (Redhat 6.2, Debian)
144 ** HP-UX 10.20 (gcc only)
146 ** NeXT - M68k/HPPA/Sparc (4.2/3.3)
148 ** Testing required: Please send reports!
153 ** Platforms with known problems:
154 ** Some variants of Slackware Linux
158 #include "includes.h"
162 #include "loginrec.h"
164 #include "atomicio.h"
172 #ifdef HAVE_LIBUTIL_H
173 # include <libutil.h>
177 ** prototypes for helper functions in this file
181 void set_utmp_time(struct logininfo *li, struct utmp *ut);
182 void construct_utmp(struct logininfo *li, struct utmp *ut);
186 void set_utmpx_time(struct logininfo *li, struct utmpx *ut);
187 void construct_utmpx(struct logininfo *li, struct utmpx *ut);
190 int utmp_write_entry(struct logininfo *li);
191 int utmpx_write_entry(struct logininfo *li);
192 int wtmp_write_entry(struct logininfo *li);
193 int wtmpx_write_entry(struct logininfo *li);
194 int lastlog_write_entry(struct logininfo *li);
195 int syslogin_write_entry(struct logininfo *li);
197 int getlast_entry(struct logininfo *li);
198 int lastlog_get_entry(struct logininfo *li);
199 int wtmp_get_entry(struct logininfo *li);
200 int wtmpx_get_entry(struct logininfo *li);
202 /* pick the shortest string */
203 #define MIN_SIZEOF(s1,s2) ( sizeof(s1) < sizeof(s2) ? sizeof(s1) : sizeof(s2) )
206 ** platform-independent login functions
209 /* login_login(struct logininfo *) -Record a login
211 * Call with a pointer to a struct logininfo initialised with
212 * login_init_entry() or login_alloc_entry()
216 * 0 on failure (will use OpenSSH's logging facilities for diagnostics)
219 login_login (struct logininfo *li)
221 li->type = LTYPE_LOGIN;
222 return login_write(li);
226 /* login_logout(struct logininfo *) - Record a logout
228 * Call as with login_login()
232 * 0 on failure (will use OpenSSH's logging facilities for diagnostics)
235 login_logout(struct logininfo *li)
237 li->type = LTYPE_LOGOUT;
238 return login_write(li);
241 /* login_get_lastlog_time(int) - Retrieve the last login time
243 * Retrieve the last login time for the given uid. Will try to use the
244 * system lastlog facilities if they are available, but will fall back
245 * to looking in wtmp/wtmpx if necessary
248 * 0 on failure, or if user has never logged in
249 * Time in seconds from the epoch if successful
251 * Useful preprocessor symbols:
252 * DISABLE_LASTLOG: If set, *never* even try to retrieve lastlog
254 * USE_LASTLOG: If set, indicates the presence of system lastlog
255 * facilities. If this and DISABLE_LASTLOG are not set,
256 * try to retrieve lastlog information from wtmp/wtmpx.
259 login_get_lastlog_time(const int uid)
263 if (login_get_lastlog(&li, uid))
269 /* login_get_lastlog(struct logininfo *, int) - Retrieve a lastlog entry
271 * Retrieve a logininfo structure populated (only partially) with
272 * information from the system lastlog data, or from wtmp/wtmpx if no
273 * system lastlog information exists.
275 * Note this routine must be given a pre-allocated logininfo.
278 * >0: A pointer to your struct logininfo if successful
279 * 0 on failure (will use OpenSSH's logging facilities for diagnostics)
283 login_get_lastlog(struct logininfo *li, const int uid)
287 memset(li, '\0', sizeof(*li));
291 * If we don't have a 'real' lastlog, we need the username to
292 * reliably search wtmp(x) for the last login (see
297 fatal("login_get_lastlog: Cannot find account for uid %i", uid);
299 /* No MIN_SIZEOF here - we absolutely *must not* truncate the
301 strlcpy(li->username, pw->pw_name, sizeof(li->username));
303 if (getlast_entry(li))
310 /* login_alloc_entry(int, char*, char*, char*) - Allocate and initialise
311 * a logininfo structure
313 * This function creates a new struct logininfo, a data structure
314 * meant to carry the information required to portably record login info.
316 * Returns a pointer to a newly created struct logininfo. If memory
317 * allocation fails, the program halts.
320 logininfo *login_alloc_entry(int pid, const char *username,
321 const char *hostname, const char *line)
323 struct logininfo *newli;
325 newli = (struct logininfo *) xmalloc (sizeof(*newli));
326 (void)login_init_entry(newli, pid, username, hostname, line);
331 /* login_free_entry(struct logininfo *) - free struct memory */
333 login_free_entry(struct logininfo *li)
339 /* login_init_entry(struct logininfo *, int, char*, char*, char*)
340 * - initialise a struct logininfo
342 * Populates a new struct logininfo, a data structure meant to carry
343 * the information required to portably record login info.
348 login_init_entry(struct logininfo *li, int pid, const char *username,
349 const char *hostname, const char *line)
353 memset(li, 0, sizeof(*li));
357 /* set the line information */
359 line_fullname(li->line, line, sizeof(li->line));
362 strlcpy(li->username, username, sizeof(li->username));
363 pw = getpwnam(li->username);
365 fatal("login_init_entry: Cannot find user \"%s\"", li->username);
366 li->uid = pw->pw_uid;
370 strlcpy(li->hostname, hostname, sizeof(li->hostname));
375 /* login_set_current_time(struct logininfo *) - set the current time
377 * Set the current time in a logininfo structure. This function is
378 * meant to eliminate the need to deal with system dependencies for
382 login_set_current_time(struct logininfo *li)
386 gettimeofday(&tv, NULL);
388 li->tv_sec = tv.tv_sec;
389 li->tv_usec = tv.tv_usec;
392 /* copy a sockaddr_* into our logininfo */
394 login_set_addr(struct logininfo *li, const struct sockaddr *sa,
395 const unsigned int sa_size)
397 unsigned int bufsize = sa_size;
399 /* make sure we don't overrun our union */
400 if (sizeof(li->hostaddr) < sa_size)
401 bufsize = sizeof(li->hostaddr);
403 memcpy((void *)&(li->hostaddr.sa), (const void *)sa, bufsize);
408 ** login_write: Call low-level recording functions based on autoconf
412 login_write (struct logininfo *li)
415 if ((int)geteuid() != 0) {
416 log("Attempt to write login records by non-root user (aborting)");
421 /* set the timestamp */
422 login_set_current_time(li);
424 syslogin_write_entry(li);
427 if (li->type == LTYPE_LOGIN) {
428 lastlog_write_entry(li);
432 utmp_write_entry(li);
435 wtmp_write_entry(li);
438 utmpx_write_entry(li);
441 wtmpx_write_entry(li);
446 #ifdef LOGIN_NEEDS_UTMPX
448 login_utmp_only(struct logininfo *li)
450 li->type = LTYPE_LOGIN;
451 login_set_current_time(li);
453 utmp_write_entry(li);
456 wtmp_write_entry(li);
459 utmpx_write_entry(li);
462 wtmpx_write_entry(li);
469 ** getlast_entry: Call low-level functions to retrieve the last login
473 /* take the uid in li and return the last login time */
475 getlast_entry(struct logininfo *li)
478 return(lastlog_get_entry(li));
479 #else /* !USE_LASTLOG */
481 #ifdef DISABLE_LASTLOG
482 /* On some systems we shouldn't even try to obtain last login
485 # else /* DISABLE_LASTLOG */
486 /* Try to retrieve the last login time from wtmp */
487 # if defined(USE_WTMP) && (defined(HAVE_TIME_IN_UTMP) || defined(HAVE_TV_IN_UTMP))
488 /* retrieve last login time from utmp */
489 return (wtmp_get_entry(li));
490 # else /* defined(USE_WTMP) && (defined(HAVE_TIME_IN_UTMP) || defined(HAVE_TV_IN_UTMP)) */
491 /* If wtmp isn't available, try wtmpx */
492 # if defined(USE_WTMPX) && (defined(HAVE_TIME_IN_UTMPX) || defined(HAVE_TV_IN_UTMPX))
493 /* retrieve last login time from utmpx */
494 return (wtmpx_get_entry(li));
496 /* Give up: No means of retrieving last login time */
498 # endif /* USE_WTMPX && (HAVE_TIME_IN_UTMPX || HAVE_TV_IN_UTMPX) */
499 # endif /* USE_WTMP && (HAVE_TIME_IN_UTMP || HAVE_TV_IN_UTMP) */
500 # endif /* DISABLE_LASTLOG */
501 #endif /* USE_LASTLOG */
507 * 'line' string utility functions
509 * These functions process the 'line' string into one of three forms:
511 * 1. The full filename (including '/dev')
512 * 2. The stripped name (excluding '/dev')
513 * 3. The abbreviated name (e.g. /dev/ttyp00 -> yp00
514 * /dev/pts/1 -> ts/1 )
516 * Form 3 is used on some systems to identify a .tmp.? entry when
517 * attempting to remove it. Typically both addition and removal is
518 * performed by one application - say, sshd - so as long as the choice
519 * uniquely identifies a terminal it's ok.
523 /* line_fullname(): add the leading '/dev/' if it doesn't exist make
524 * sure dst has enough space, if not just copy src (ugh) */
526 line_fullname(char *dst, const char *src, int dstsize)
528 memset(dst, '\0', dstsize);
529 if ((strncmp(src, "/dev/", 5) == 0) || (dstsize < (strlen(src) + 5))) {
530 strlcpy(dst, src, dstsize);
532 strlcpy(dst, "/dev/", dstsize);
533 strlcat(dst, src, dstsize);
538 /* line_stripname(): strip the leading '/dev' if it exists, return dst */
540 line_stripname(char *dst, const char *src, int dstsize)
542 memset(dst, '\0', dstsize);
543 if (strncmp(src, "/dev/", 5) == 0)
544 strlcpy(dst, src + 5, dstsize);
546 strlcpy(dst, src, dstsize);
550 /* line_abbrevname(): Return the abbreviated (usually four-character)
551 * form of the line (Just use the last <dstsize> characters of the
554 * NOTE: use strncpy because we do NOT necessarily want zero
557 line_abbrevname(char *dst, const char *src, int dstsize)
561 memset(dst, '\0', dstsize);
563 /* Always skip prefix if present */
564 if (strncmp(src, "/dev/", 5) == 0)
570 if (((int)len - dstsize) > 0)
571 src += ((int)len - dstsize);
573 /* note: _don't_ change this to strlcpy */
574 strncpy(dst, src, (size_t)dstsize);
581 ** utmp utility functions
583 ** These functions manipulate struct utmp, taking system differences
587 #if defined(USE_UTMP) || defined (USE_WTMP) || defined (USE_LOGIN)
589 /* build the utmp structure */
591 set_utmp_time(struct logininfo *li, struct utmp *ut)
593 # ifdef HAVE_TV_IN_UTMP
594 ut->ut_tv.tv_sec = li->tv_sec;
595 ut->ut_tv.tv_usec = li->tv_usec;
597 # ifdef HAVE_TIME_IN_UTMP
598 ut->ut_time = li->tv_sec;
604 construct_utmp(struct logininfo *li,
607 memset(ut, '\0', sizeof(*ut));
609 /* First fill out fields used for both logins and logouts */
611 # ifdef HAVE_ID_IN_UTMP
612 line_abbrevname(ut->ut_id, li->line, sizeof(ut->ut_id));
615 # ifdef HAVE_TYPE_IN_UTMP
616 /* This is done here to keep utmp constants out of struct logininfo */
619 ut->ut_type = USER_PROCESS;
625 ut->ut_type = DEAD_PROCESS;
627 cray_retain_utmp(ut, li->pid);
632 set_utmp_time(li, ut);
634 line_stripname(ut->ut_line, li->line, sizeof(ut->ut_line));
636 # ifdef HAVE_PID_IN_UTMP
637 ut->ut_pid = li->pid;
640 /* If we're logging out, leave all other fields blank */
641 if (li->type == LTYPE_LOGOUT)
645 * These fields are only used when logging in, and are blank
649 /* Use strncpy because we don't necessarily want null termination */
650 strncpy(ut->ut_name, li->username, MIN_SIZEOF(ut->ut_name, li->username));
651 # ifdef HAVE_HOST_IN_UTMP
652 strncpy(ut->ut_host, li->hostname, MIN_SIZEOF(ut->ut_host, li->hostname));
654 # ifdef HAVE_ADDR_IN_UTMP
655 /* this is just a 32-bit IP address */
656 if (li->hostaddr.sa.sa_family == AF_INET)
657 ut->ut_addr = li->hostaddr.sa_in.sin_addr.s_addr;
660 #endif /* USE_UTMP || USE_WTMP || USE_LOGIN */
663 ** utmpx utility functions
665 ** These functions manipulate struct utmpx, accounting for system
669 #if defined(USE_UTMPX) || defined (USE_WTMPX)
670 /* build the utmpx structure */
672 set_utmpx_time(struct logininfo *li, struct utmpx *utx)
674 # ifdef HAVE_TV_IN_UTMPX
675 utx->ut_tv.tv_sec = li->tv_sec;
676 utx->ut_tv.tv_usec = li->tv_usec;
677 # else /* HAVE_TV_IN_UTMPX */
678 # ifdef HAVE_TIME_IN_UTMPX
679 utx->ut_time = li->tv_sec;
680 # endif /* HAVE_TIME_IN_UTMPX */
681 # endif /* HAVE_TV_IN_UTMPX */
685 construct_utmpx(struct logininfo *li, struct utmpx *utx)
687 memset(utx, '\0', sizeof(*utx));
688 # ifdef HAVE_ID_IN_UTMPX
689 line_abbrevname(utx->ut_id, li->line, sizeof(utx->ut_id));
692 /* this is done here to keep utmp constants out of loginrec.h */
695 utx->ut_type = USER_PROCESS;
698 utx->ut_type = DEAD_PROCESS;
701 line_stripname(utx->ut_line, li->line, sizeof(utx->ut_line));
702 set_utmpx_time(li, utx);
703 utx->ut_pid = li->pid;
705 if (li->type == LTYPE_LOGOUT)
709 * These fields are only used when logging in, and are blank
713 /* strncpy(): Don't necessarily want null termination */
714 strncpy(utx->ut_name, li->username, MIN_SIZEOF(utx->ut_name, li->username));
715 # ifdef HAVE_HOST_IN_UTMPX
716 strncpy(utx->ut_host, li->hostname, MIN_SIZEOF(utx->ut_host, li->hostname));
718 # ifdef HAVE_ADDR_IN_UTMPX
719 /* this is just a 32-bit IP address */
720 if (li->hostaddr.sa.sa_family == AF_INET)
721 utx->ut_addr = li->hostaddr.sa_in.sin_addr.s_addr;
723 # ifdef HAVE_SYSLEN_IN_UTMPX
724 /* ut_syslen is the length of the utx_host string */
725 utx->ut_syslen = MIN(strlen(li->hostname), sizeof(utx->ut_host));
728 #endif /* USE_UTMPX || USE_WTMPX */
731 ** Low-level utmp functions
734 /* FIXME: (ATL) utmp_write_direct needs testing */
737 /* if we can, use pututline() etc. */
738 # if !defined(DISABLE_PUTUTLINE) && defined(HAVE_SETUTENT) && \
739 defined(HAVE_PUTUTLINE)
740 # define UTMP_USE_LIBRARY
744 /* write a utmp entry with the system's help (pututline() and pals) */
745 # ifdef UTMP_USE_LIBRARY
747 utmp_write_library(struct logininfo *li, struct utmp *ut)
752 # ifdef HAVE_ENDUTENT
757 # else /* UTMP_USE_LIBRARY */
759 /* write a utmp entry direct to the file */
760 /* This is a slightly modification of code in OpenBSD's login.c */
762 utmp_write_direct(struct logininfo *li, struct utmp *ut)
768 /* FIXME: (ATL) ttyslot() needs local implementation */
770 #if defined(HAVE_GETTTYENT)
771 register struct ttyent *ty;
776 while ((struct ttyent *)0 != (ty = getttyent())) {
778 if (!strncmp(ty->ty_name, ut->ut_line, sizeof(ut->ut_line)))
783 if((struct ttyent *)0 == ty) {
784 log("utmp_write_entry: tty not found");
789 tty = ttyslot(); /* seems only to work for /dev/ttyp? style names */
791 #endif /* HAVE_GETTTYENT */
793 if (tty > 0 && (fd = open(UTMP_FILE, O_RDWR|O_CREAT, 0644)) >= 0) {
794 (void)lseek(fd, (off_t)(tty * sizeof(struct utmp)), SEEK_SET);
796 * Prevent luser from zero'ing out ut_host.
797 * If the new ut_line is empty but the old one is not
798 * and ut_line and ut_name match, preserve the old ut_line.
800 if (atomicio(read, fd, &old_ut, sizeof(old_ut)) == sizeof(old_ut) &&
801 (ut->ut_host[0] == '\0') && (old_ut.ut_host[0] != '\0') &&
802 (strncmp(old_ut.ut_line, ut->ut_line, sizeof(ut->ut_line)) == 0) &&
803 (strncmp(old_ut.ut_name, ut->ut_name, sizeof(ut->ut_name)) == 0)) {
804 (void)memcpy(ut->ut_host, old_ut.ut_host, sizeof(ut->ut_host));
807 (void)lseek(fd, (off_t)(tty * sizeof(struct utmp)), SEEK_SET);
808 if (atomicio(write, fd, ut, sizeof(*ut)) != sizeof(*ut))
809 log("utmp_write_direct: error writing %s: %s",
810 UTMP_FILE, strerror(errno));
818 # endif /* UTMP_USE_LIBRARY */
821 utmp_perform_login(struct logininfo *li)
825 construct_utmp(li, &ut);
826 # ifdef UTMP_USE_LIBRARY
827 if (!utmp_write_library(li, &ut)) {
828 log("utmp_perform_login: utmp_write_library() failed");
832 if (!utmp_write_direct(li, &ut)) {
833 log("utmp_perform_login: utmp_write_direct() failed");
842 utmp_perform_logout(struct logininfo *li)
846 construct_utmp(li, &ut);
847 # ifdef UTMP_USE_LIBRARY
848 if (!utmp_write_library(li, &ut)) {
849 log("utmp_perform_logout: utmp_write_library() failed");
853 if (!utmp_write_direct(li, &ut)) {
854 log("utmp_perform_logout: utmp_write_direct() failed");
863 utmp_write_entry(struct logininfo *li)
867 return utmp_perform_login(li);
870 return utmp_perform_logout(li);
873 log("utmp_write_entry: invalid type field");
877 #endif /* USE_UTMP */
881 ** Low-level utmpx functions
884 /* not much point if we don't want utmpx entries */
887 /* if we have the wherewithall, use pututxline etc. */
888 # if !defined(DISABLE_PUTUTXLINE) && defined(HAVE_SETUTXENT) && \
889 defined(HAVE_PUTUTXLINE)
890 # define UTMPX_USE_LIBRARY
894 /* write a utmpx entry with the system's help (pututxline() and pals) */
895 # ifdef UTMPX_USE_LIBRARY
897 utmpx_write_library(struct logininfo *li, struct utmpx *utx)
902 # ifdef HAVE_ENDUTXENT
908 # else /* UTMPX_USE_LIBRARY */
910 /* write a utmp entry direct to the file */
912 utmpx_write_direct(struct logininfo *li, struct utmpx *utx)
914 log("utmpx_write_direct: not implemented!");
917 # endif /* UTMPX_USE_LIBRARY */
920 utmpx_perform_login(struct logininfo *li)
924 construct_utmpx(li, &utx);
925 # ifdef UTMPX_USE_LIBRARY
926 if (!utmpx_write_library(li, &utx)) {
927 log("utmpx_perform_login: utmp_write_library() failed");
931 if (!utmpx_write_direct(li, &ut)) {
932 log("utmpx_perform_login: utmp_write_direct() failed");
941 utmpx_perform_logout(struct logininfo *li)
945 memset(&utx, '\0', sizeof(utx));
946 set_utmpx_time(li, &utx);
947 line_stripname(utx.ut_line, li->line, sizeof(utx.ut_line));
948 # ifdef HAVE_ID_IN_UTMPX
949 line_abbrevname(utx.ut_id, li->line, sizeof(utx.ut_id));
951 # ifdef HAVE_TYPE_IN_UTMPX
952 utx.ut_type = DEAD_PROCESS;
955 # ifdef UTMPX_USE_LIBRARY
956 utmpx_write_library(li, &utx);
958 utmpx_write_direct(li, &utx);
964 utmpx_write_entry(struct logininfo *li)
968 return utmpx_perform_login(li);
970 return utmpx_perform_logout(li);
972 log("utmpx_write_entry: invalid type field");
976 #endif /* USE_UTMPX */
980 ** Low-level wtmp functions
985 /* write a wtmp entry direct to the end of the file */
986 /* This is a slight modification of code in OpenBSD's logwtmp.c */
988 wtmp_write(struct logininfo *li, struct utmp *ut)
993 if ((fd = open(WTMP_FILE, O_WRONLY|O_APPEND, 0)) < 0) {
994 log("wtmp_write: problem writing %s: %s",
995 WTMP_FILE, strerror(errno));
998 if (fstat(fd, &buf) == 0)
999 if (atomicio(write, fd, ut, sizeof(*ut)) != sizeof(*ut)) {
1000 ftruncate(fd, buf.st_size);
1001 log("wtmp_write: problem writing %s: %s",
1002 WTMP_FILE, strerror(errno));
1010 wtmp_perform_login(struct logininfo *li)
1014 construct_utmp(li, &ut);
1015 return wtmp_write(li, &ut);
1020 wtmp_perform_logout(struct logininfo *li)
1024 construct_utmp(li, &ut);
1025 return wtmp_write(li, &ut);
1030 wtmp_write_entry(struct logininfo *li)
1034 return wtmp_perform_login(li);
1036 return wtmp_perform_logout(li);
1038 log("wtmp_write_entry: invalid type field");
1044 /* Notes on fetching login data from wtmp/wtmpx
1046 * Logouts are usually recorded with (amongst other things) a blank
1047 * username on a given tty line. However, some systems (HP-UX is one)
1048 * leave all fields set, but change the ut_type field to DEAD_PROCESS.
1050 * Since we're only looking for logins here, we know that the username
1051 * must be set correctly. On systems that leave it in, we check for
1052 * ut_type==USER_PROCESS (indicating a login.)
1054 * Portability: Some systems may set something other than USER_PROCESS
1055 * to indicate a login process. I don't know of any as I write. Also,
1056 * it's possible that some systems may both leave the username in
1057 * place and not have ut_type.
1060 /* return true if this wtmp entry indicates a login */
1062 wtmp_islogin(struct logininfo *li, struct utmp *ut)
1064 if (strncmp(li->username, ut->ut_name,
1065 MIN_SIZEOF(li->username, ut->ut_name)) == 0) {
1066 # ifdef HAVE_TYPE_IN_UTMP
1067 if (ut->ut_type & USER_PROCESS)
1077 wtmp_get_entry(struct logininfo *li)
1083 /* Clear the time entries in our logininfo */
1084 li->tv_sec = li->tv_usec = 0;
1086 if ((fd = open(WTMP_FILE, O_RDONLY)) < 0) {
1087 log("wtmp_get_entry: problem opening %s: %s",
1088 WTMP_FILE, strerror(errno));
1091 if (fstat(fd, &st) != 0) {
1092 log("wtmp_get_entry: couldn't stat %s: %s",
1093 WTMP_FILE, strerror(errno));
1098 /* Seek to the start of the last struct utmp */
1099 if (lseek(fd, -(off_t)sizeof(struct utmp), SEEK_END) == -1) {
1100 /* Looks like we've got a fresh wtmp file */
1106 if (atomicio(read, fd, &ut, sizeof(ut)) != sizeof(ut)) {
1107 log("wtmp_get_entry: read of %s failed: %s",
1108 WTMP_FILE, strerror(errno));
1112 if ( wtmp_islogin(li, &ut) ) {
1114 /* We've already checked for a time in struct
1115 * utmp, in login_getlast(). */
1116 # ifdef HAVE_TIME_IN_UTMP
1117 li->tv_sec = ut.ut_time;
1119 # if HAVE_TV_IN_UTMP
1120 li->tv_sec = ut.ut_tv.tv_sec;
1123 line_fullname(li->line, ut.ut_line,
1124 MIN_SIZEOF(li->line, ut.ut_line));
1125 # ifdef HAVE_HOST_IN_UTMP
1126 strlcpy(li->hostname, ut.ut_host,
1127 MIN_SIZEOF(li->hostname, ut.ut_host));
1131 /* Seek back 2 x struct utmp */
1132 if (lseek(fd, -(off_t)(2 * sizeof(struct utmp)), SEEK_CUR) == -1) {
1133 /* We've found the start of the file, so quit */
1139 /* We found an entry. Tidy up and return */
1143 # endif /* USE_WTMP */
1147 ** Low-level wtmpx functions
1151 /* write a wtmpx entry direct to the end of the file */
1152 /* This is a slight modification of code in OpenBSD's logwtmp.c */
1154 wtmpx_write(struct logininfo *li, struct utmpx *utx)
1159 if ((fd = open(WTMPX_FILE, O_WRONLY|O_APPEND, 0)) < 0) {
1160 log("wtmpx_write: problem opening %s: %s",
1161 WTMPX_FILE, strerror(errno));
1165 if (fstat(fd, &buf) == 0)
1166 if (atomicio(write, fd, utx, sizeof(*utx)) != sizeof(*utx)) {
1167 ftruncate(fd, buf.st_size);
1168 log("wtmpx_write: problem writing %s: %s",
1169 WTMPX_FILE, strerror(errno));
1179 wtmpx_perform_login(struct logininfo *li)
1183 construct_utmpx(li, &utx);
1184 return wtmpx_write(li, &utx);
1189 wtmpx_perform_logout(struct logininfo *li)
1193 construct_utmpx(li, &utx);
1194 return wtmpx_write(li, &utx);
1199 wtmpx_write_entry(struct logininfo *li)
1203 return wtmpx_perform_login(li);
1205 return wtmpx_perform_logout(li);
1207 log("wtmpx_write_entry: invalid type field");
1212 /* Please see the notes above wtmp_islogin() for information about the
1213 next two functions */
1215 /* Return true if this wtmpx entry indicates a login */
1217 wtmpx_islogin(struct logininfo *li, struct utmpx *utx)
1219 if ( strncmp(li->username, utx->ut_name,
1220 MIN_SIZEOF(li->username, utx->ut_name)) == 0 ) {
1221 # ifdef HAVE_TYPE_IN_UTMPX
1222 if (utx->ut_type == USER_PROCESS)
1233 wtmpx_get_entry(struct logininfo *li)
1239 /* Clear the time entries */
1240 li->tv_sec = li->tv_usec = 0;
1242 if ((fd = open(WTMPX_FILE, O_RDONLY)) < 0) {
1243 log("wtmpx_get_entry: problem opening %s: %s",
1244 WTMPX_FILE, strerror(errno));
1247 if (fstat(fd, &st) != 0) {
1248 log("wtmpx_get_entry: couldn't stat %s: %s",
1249 WTMP_FILE, strerror(errno));
1254 /* Seek to the start of the last struct utmpx */
1255 if (lseek(fd, -(off_t)sizeof(struct utmpx), SEEK_END) == -1 ) {
1256 /* probably a newly rotated wtmpx file */
1262 if (atomicio(read, fd, &utx, sizeof(utx)) != sizeof(utx)) {
1263 log("wtmpx_get_entry: read of %s failed: %s",
1264 WTMPX_FILE, strerror(errno));
1268 /* Logouts are recorded as a blank username on a particular line.
1269 * So, we just need to find the username in struct utmpx */
1270 if ( wtmpx_islogin(li, &utx) ) {
1271 # ifdef HAVE_TV_IN_UTMPX
1272 li->tv_sec = utx.ut_tv.tv_sec;
1274 # ifdef HAVE_TIME_IN_UTMPX
1275 li->tv_sec = utx.ut_time;
1278 line_fullname(li->line, utx.ut_line, sizeof(li->line));
1279 # ifdef HAVE_HOST_IN_UTMPX
1280 strlcpy(li->hostname, utx.ut_host,
1281 MIN_SIZEOF(li->hostname, utx.ut_host));
1285 if (lseek(fd, -(off_t)(2 * sizeof(struct utmpx)), SEEK_CUR) == -1) {
1294 #endif /* USE_WTMPX */
1297 ** Low-level libutil login() functions
1302 syslogin_perform_login(struct logininfo *li)
1306 if (! (ut = (struct utmp *)malloc(sizeof(*ut)))) {
1307 log("syslogin_perform_login: couldn't malloc()");
1310 construct_utmp(li, ut);
1317 syslogin_perform_logout(struct logininfo *li)
1322 (void)line_stripname(line, li->line, sizeof(line));
1324 if (!logout(line)) {
1325 log("syslogin_perform_logout: logout() returned an error");
1326 # ifdef HAVE_LOGWTMP
1328 logwtmp(line, "", "");
1331 /* FIXME: (ATL - if the need arises) What to do if we have
1332 * login, but no logout? what if logout but no logwtmp? All
1333 * routines are in libutil so they should all be there,
1340 syslogin_write_entry(struct logininfo *li)
1344 return syslogin_perform_login(li);
1346 return syslogin_perform_logout(li);
1348 log("syslogin_write_entry: Invalid type field");
1352 #endif /* USE_LOGIN */
1354 /* end of file log-syslogin.c */
1357 ** Low-level lastlog functions
1366 lastlog_construct(struct logininfo *li, struct lastlog *last)
1368 /* clear the structure */
1369 memset(last, '\0', sizeof(*last));
1371 (void)line_stripname(last->ll_line, li->line, sizeof(last->ll_line));
1372 strlcpy(last->ll_host, li->hostname,
1373 MIN_SIZEOF(last->ll_host, li->hostname));
1374 last->ll_time = li->tv_sec;
1378 lastlog_filetype(char *filename)
1382 if (stat(LASTLOG_FILE, &st) != 0) {
1383 log("lastlog_perform_login: Couldn't stat %s: %s", LASTLOG_FILE,
1387 if (S_ISDIR(st.st_mode))
1389 else if (S_ISREG(st.st_mode))
1396 /* open the file (using filemode) and seek to the login entry */
1398 lastlog_openseek(struct logininfo *li, int *fd, int filemode)
1402 char lastlog_file[1024];
1404 type = lastlog_filetype(LASTLOG_FILE);
1407 strlcpy(lastlog_file, LASTLOG_FILE, sizeof(lastlog_file));
1410 snprintf(lastlog_file, sizeof(lastlog_file), "%s/%s",
1411 LASTLOG_FILE, li->username);
1414 log("lastlog_openseek: %.100s is not a file or directory!",
1419 *fd = open(lastlog_file, filemode);
1421 debug("lastlog_openseek: Couldn't open %s: %s",
1422 lastlog_file, strerror(errno));
1426 if (type == LL_FILE) {
1427 /* find this uid's offset in the lastlog file */
1428 offset = (off_t) ((long)li->uid * sizeof(struct lastlog));
1430 if ( lseek(*fd, offset, SEEK_SET) != offset ) {
1431 log("lastlog_openseek: %s->lseek(): %s",
1432 lastlog_file, strerror(errno));
1441 lastlog_perform_login(struct logininfo *li)
1443 struct lastlog last;
1446 /* create our struct lastlog */
1447 lastlog_construct(li, &last);
1449 if (!lastlog_openseek(li, &fd, O_RDWR|O_CREAT))
1452 /* write the entry */
1453 if (atomicio(write, fd, &last, sizeof(last)) != sizeof(last)) {
1455 log("lastlog_write_filemode: Error writing to %s: %s",
1456 LASTLOG_FILE, strerror(errno));
1465 lastlog_write_entry(struct logininfo *li)
1469 return lastlog_perform_login(li);
1471 log("lastlog_write_entry: Invalid type field");
1477 lastlog_populate_entry(struct logininfo *li, struct lastlog *last)
1479 line_fullname(li->line, last->ll_line, sizeof(li->line));
1480 strlcpy(li->hostname, last->ll_host,
1481 MIN_SIZEOF(li->hostname, last->ll_host));
1482 li->tv_sec = last->ll_time;
1486 lastlog_get_entry(struct logininfo *li)
1488 struct lastlog last;
1491 if (!lastlog_openseek(li, &fd, O_RDONLY))
1494 if (atomicio(read, fd, &last, sizeof(last)) != sizeof(last)) {
1496 log("lastlog_get_entry: Error reading from %s: %s",
1497 LASTLOG_FILE, strerror(errno));
1503 lastlog_populate_entry(li, &last);
1507 #endif /* USE_LASTLOG */