1 /* Copyright 1988,1990,1993,1994 by Paul Vixie
4 * Distribute freely, except: don't remove my name from the source or
5 * documentation (don't take credit for my work), mark your changes (don't
6 * get me blamed for your possible bugs), don't alter or remove this
7 * notice. May be sold if buildable source is provided to buyer. No
8 * warrantee of any kind, express or implied, is included with this
9 * software; use at your own risk, responsibility for damages (if any) to
10 * anyone resulting from the use of this software rests entirely with the
13 * Send bug reports, bug fixes, enhancements, requests, flames, etc., and
14 * I'll try to keep a version up to date. I can be reached as follows:
15 * Paul Vixie <paul@vix.com> uunet!decwrl!vixie!paul
17 * From Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp
18 * $FreeBSD: src/usr.sbin/cron/crontab/crontab.c,v 1.12.2.4 2001/06/16 03:18:37 peter Exp $
21 /* crontab - install and manage per-user crontab files
22 * vix 02may87 [RCS has the rest of the log]
23 * vix 26jan87 [original]
35 # include <sys/time.h>
45 #define NHEADER_LINES 2
48 enum opt_t { opt_unknown, opt_list, opt_delete, opt_edit, opt_replace };
51 static char *Options[] = { "???", "list", "delete", "edit", "replace" };
56 static char User[MAX_UNAME], RealUser[MAX_UNAME];
57 static char Filename[MAX_FNAME];
58 static FILE *NewCrontab;
59 static int CheckErrorCount;
60 static enum opt_t Option;
61 static struct passwd *pw;
62 static void list_cmd(void),
67 parse_args(int c, char *v[]);
68 static int replace_cmd(void);
74 fprintf(stderr, "crontab: usage error: %s\n", msg);
75 fprintf(stderr, "%s\n%s\n",
76 "usage: crontab [-u user] file",
77 " crontab [-u user] { -e | -l | -r }");
83 main(int argc, char **argv)
88 ProgramName = argv[0];
91 setlocale(LC_ALL, "");
97 parse_args(argc, argv); /* sets many globals, opens a file */
100 if (!allowed(User)) {
101 warnx("you (%s) are not allowed to use this program", User);
102 log_it(RealUser, Pid, "AUTH", "crontab command not allowed");
105 exitstatus = OK_EXIT;
107 case opt_list: list_cmd();
109 case opt_delete: delete_cmd();
111 case opt_edit: edit_cmd();
113 case opt_replace: if (replace_cmd() < 0)
114 exitstatus = ERROR_EXIT;
125 parse_args(int argc, char **argv)
129 if (!(pw = getpwuid(getuid())))
130 errx(ERROR_EXIT, "your UID isn't in the passwd file, bailing out");
131 strncpy(User, pw->pw_name, (sizeof User)-1);
132 User[(sizeof User)-1] = '\0';
133 strcpy(RealUser, User);
135 Option = opt_unknown;
136 while ((argch = getopt(argc, argv, "u:lerx:")) != -1) {
139 if (!set_debug_flags(optarg))
140 usage("bad debug option");
143 if (getuid() != ROOT_UID)
144 errx(ERROR_EXIT, "must be privileged to use -u");
145 if (!(pw = getpwnam(optarg)))
146 errx(ERROR_EXIT, "user `%s' unknown", optarg);
147 strncpy(User, pw->pw_name, (sizeof User)-1);
148 User[(sizeof User)-1] = '\0';
151 if (Option != opt_unknown)
152 usage("only one operation permitted");
156 if (Option != opt_unknown)
157 usage("only one operation permitted");
161 if (Option != opt_unknown)
162 usage("only one operation permitted");
166 usage("unrecognized option");
172 if (Option != opt_unknown) {
173 if (argv[optind] != NULL) {
174 usage("no arguments permitted after this option");
177 if (argv[optind] != NULL) {
178 Option = opt_replace;
179 strncpy (Filename, argv[optind], (sizeof Filename)-1);
180 Filename[(sizeof Filename)-1] = '\0';
183 usage("file name must be specified for replace");
187 if (Option == opt_replace) {
188 /* we have to open the file here because we're going to
189 * chdir(2) into /var/cron before we get around to
192 if (!strcmp(Filename, "-")) {
195 /* relinquish the setuid status of the binary during
196 * the open, lest nonroot users read files they should
197 * not be able to read. we can't use access() here
198 * since there's a race condition. thanks go out to
199 * Arnt Gulbrandsen <agulbra@pvv.unit.no> for spotting
203 if (swap_uids() < OK)
204 err(ERROR_EXIT, "swapping uids");
205 if (!(NewCrontab = fopen(Filename, "r")))
206 err(ERROR_EXIT, "%s", Filename);
207 if (swap_uids() < OK)
208 err(ERROR_EXIT, "swapping uids back");
212 Debug(DMISC, ("user=%s, file=%s, option=%s\n",
213 User, Filename, Options[(int)Option]))
224 log_it(RealUser, Pid, "LIST", User);
225 sprintf(n, CRON_TAB(User));
226 if (!(f = fopen(n, "r"))) {
228 errx(ERROR_EXIT, "no crontab for %s", User);
230 err(ERROR_EXIT, "%s", n);
233 /* file is open. copy to stdout, close.
237 /* ignore the top few comments since we probably put them there.
239 for (x = 0; x < NHEADER_LINES; x++) {
247 while (EOF != (ch = get_char(f)))
254 while (EOF != (ch = get_char(f)))
266 if (isatty(STDIN_FILENO)) {
267 fprintf(stderr, "remove crontab for %s? ", User);
268 first = ch = getchar();
269 while (ch != '\n' && ch != EOF)
271 if (first != 'y' && first != 'Y')
275 log_it(RealUser, Pid, "DELETE", User);
276 sprintf(n, CRON_TAB(User));
279 errx(ERROR_EXIT, "no crontab for %s", User);
281 err(ERROR_EXIT, "%s", n);
288 check_error(char *msg)
291 fprintf(stderr, "\"%s\":%d: %s\n", Filename, LineNumber-1, msg);
298 char n[MAX_FNAME], q[MAX_TEMPSTR], *editor;
301 struct stat statbuf, fsbuf;
307 log_it(RealUser, Pid, "BEGIN EDIT", User);
308 sprintf(n, CRON_TAB(User));
309 if (!(f = fopen(n, "r"))) {
311 err(ERROR_EXIT, "%s", n);
312 warnx("no crontab for %s - using an empty one", User);
313 if (!(f = fopen(_PATH_DEVNULL, "r")))
314 err(ERROR_EXIT, _PATH_DEVNULL);
318 sprintf(Filename, "/tmp/crontab.XXXXXXXXXX");
319 if ((t = mkstemp(Filename)) == -1) {
320 warn("%s", Filename);
326 if (fchown(t, getuid(), getgid()) < 0) {
328 if (chown(Filename, getuid(), getgid()) < 0) {
333 if (!(NewCrontab = fdopen(t, "r+"))) {
340 /* ignore the top few comments since we probably put them there.
342 for (x = 0; x < NHEADER_LINES; x++) {
347 putc(ch, NewCrontab);
350 while (EOF != (ch = get_char(f)))
357 /* copy the rest of the crontab (if any) to the temp file.
360 while (EOF != (ch = get_char(f)))
361 putc(ch, NewCrontab);
363 if (fflush(NewCrontab))
364 err(ERROR_EXIT, "%s", Filename);
365 if (fstat(t, &fsbuf) < 0) {
366 warn("unable to fstat temp file");
370 if (stat(Filename, &statbuf) < 0) {
372 fatal: unlink(Filename);
375 if (statbuf.st_dev != fsbuf.st_dev || statbuf.st_ino != fsbuf.st_ino)
376 errx(ERROR_EXIT, "temp file must be edited in place");
377 mtime = statbuf.st_mtime;
379 if ((!(editor = getenv("VISUAL")))
380 && (!(editor = getenv("EDITOR")))
385 /* we still have the file open. editors will generally rewrite the
386 * original file rather than renaming/unlinking it and starting a
387 * new one; even backup files are supposed to be made by copying
388 * rather than by renaming. if some editor does not support this,
389 * then don't use it. the security problems are more severe if we
390 * close and reopen the file around the edit.
393 switch (pid = fork()) {
399 if (setuid(getuid()) < 0)
400 err(ERROR_EXIT, "setuid(getuid())");
401 if (chdir("/tmp") < 0)
402 err(ERROR_EXIT, "chdir(/tmp)");
403 if (strlen(editor) + strlen(Filename) + 2 >= MAX_TEMPSTR)
404 errx(ERROR_EXIT, "editor or filename too long");
405 execlp(editor, editor, Filename, NULL);
406 err(ERROR_EXIT, "%s", editor);
416 f[0] = signal(SIGHUP, SIG_IGN);
417 f[1] = signal(SIGINT, SIG_IGN);
418 f[2] = signal(SIGTERM, SIG_IGN);
419 xpid = wait(&waiter);
420 signal(SIGHUP, f[0]);
421 signal(SIGINT, f[1]);
422 signal(SIGTERM, f[2]);
425 warnx("wrong PID (%d != %d) from \"%s\"", xpid, pid, editor);
428 if (WIFEXITED(waiter) && WEXITSTATUS(waiter)) {
429 warnx("\"%s\" exited with status %d", editor, WEXITSTATUS(waiter));
432 if (WIFSIGNALED(waiter)) {
433 warnx("\"%s\" killed; signal %d (%score dumped)",
434 editor, WTERMSIG(waiter), WCOREDUMP(waiter) ?"" :"no ");
437 if (stat(Filename, &statbuf) < 0) {
441 if (statbuf.st_dev != fsbuf.st_dev || statbuf.st_ino != fsbuf.st_ino)
442 errx(ERROR_EXIT, "temp file must be edited in place");
443 if (mtime == statbuf.st_mtime) {
444 warnx("no changes made to crontab");
447 warnx("installing new crontab");
448 switch (replace_cmd()) {
453 printf("Do you want to retry the same edit? ");
456 fgets(q, sizeof q, stdin);
457 switch (islower(q[0]) ? q[0] : tolower(q[0])) {
463 fprintf(stderr, "Enter Y or N\n");
469 warnx("edits left in %s", Filename);
472 warnx("panic: bad switch() in replace_cmd()");
478 log_it(RealUser, Pid, "END EDIT", User);
482 /* returns 0 on success
484 * -2 on install error
489 char n[MAX_FNAME], envstr[MAX_ENVSTR], tn[MAX_FNAME];
493 time_t now = time(NULL);
494 char **envp = env_init();
497 warnx("cannot allocate memory");
501 sprintf(n, "tmp.%d", Pid);
502 sprintf(tn, CRON_TAB(n));
503 if (!(tmp = fopen(tn, "w+"))) {
508 /* write a signature at the top of the file.
510 * VERY IMPORTANT: make sure NHEADER_LINES agrees with this code.
512 fprintf(tmp, "# DO NOT EDIT THIS FILE - edit the master and reinstall.\n");
513 fprintf(tmp, "# (%s installed on %-24.24s)\n", Filename, ctime(&now));
515 /* copy the crontab to the tmp
519 while (EOF != (ch = get_char(NewCrontab)))
521 ftruncate(fileno(tmp), ftell(tmp));
522 fflush(tmp); rewind(tmp);
525 warnx("error while writing new crontab to %s", tn);
526 fclose(tmp); unlink(tn);
530 /* check the syntax of the file being installed.
533 /* BUG: was reporting errors after the EOF if there were any errors
534 * in the file proper -- kludged it by stopping after first error.
537 Set_LineNum(1 - NHEADER_LINES)
538 CheckErrorCount = 0; eof = FALSE;
539 while (!CheckErrorCount && !eof) {
540 switch (load_env(envstr, tmp)) {
545 e = load_entry(tmp, check_error, pw, envp);
554 if (CheckErrorCount != 0) {
555 warnx("errors in crontab file, can't install");
556 fclose(tmp); unlink(tn);
561 if (fchown(fileno(tmp), ROOT_UID, -1) < OK)
563 if (chown(tn, ROOT_UID, -1) < OK)
567 fclose(tmp); unlink(tn);
572 if (fchmod(fileno(tmp), 0600) < OK)
574 if (chmod(tn, 0600) < OK)
578 fclose(tmp); unlink(tn);
582 if (fclose(tmp) == EOF) {
588 sprintf(n, CRON_TAB(User));
590 warn("error renaming %s to %s", tn, n);
594 log_it(RealUser, Pid, "REPLACE", User);
606 struct timeval tvs[2];
609 gettimeofday(&tvs[0], &tz);
611 if (utimes(SPOOL_DIR, tvs) < OK) {
612 warn("can't update mtime on spooldir %s", SPOOL_DIR);
616 if (utime(SPOOL_DIR, NULL) < OK) {
617 warn("can't update mtime on spooldir %s", SPOOL_DIR);
620 #endif /*USE_UTIMES*/