]> sourceware.org Git - newlib-cygwin.git/blobdiff - winsup/utils/mkpasswd.c
Cygwin: add 3.2.1 release file and add fixes up to this point
[newlib-cygwin.git] / winsup / utils / mkpasswd.c
index 47d344038f59c42a472a0043330bb290574fbda6..3bbdb1c71033da91808900ba01a9cf2e8db7a3a5 100644 (file)
@@ -1,56 +1,70 @@
 /* mkpasswd.c:
 
-   Copyright 1997, 1998, 1999, 2000 Cygnus Solutions.
-
    This file is part of Cygwin.
 
    This software is a copyrighted work licensed under the terms of the
    Cygwin license.  Please consult the file "CYGWIN_LICENSE" for
    details. */
 
+#define _WIN32_WINNT 0x0a00
+#include <errno.h>
 #include <ctype.h>
 #include <stdlib.h>
 #include <wchar.h>
+#include <wctype.h>
+#include <locale.h>
 #include <stdio.h>
-#include <windows.h>
-#include <sys/cygwin.h>
+#include <unistd.h>
+#include <inttypes.h>
 #include <getopt.h>
-#include <lmaccess.h>
-#include <lmapibuf.h>
+#include <io.h>
+#include <pwd.h>
+#include <sys/fcntl.h>
+#include <sys/cygwin.h>
+#include <cygwin/version.h>
+#include <windows.h>
+#include <lm.h>
+#include <iptypes.h>
+#include <wininet.h>
+#include <ntsecapi.h>
+#include <dsgetdc.h>
+#include <ntdef.h>
+
+#define print_win_error(x) _print_win_error(x, __LINE__)
 
 SID_IDENTIFIER_AUTHORITY sid_world_auth = {SECURITY_WORLD_SID_AUTHORITY};
 SID_IDENTIFIER_AUTHORITY sid_nt_auth = {SECURITY_NT_AUTHORITY};
 
-NET_API_STATUS WINAPI (*netapibufferfree)(PVOID);
-NET_API_STATUS WINAPI (*netuserenum)(LPWSTR,DWORD,DWORD,PBYTE*,DWORD,PDWORD,PDWORD,PDWORD);
-NET_API_STATUS WINAPI (*netlocalgroupenum)(LPWSTR,DWORD,PBYTE*,DWORD,PDWORD,PDWORD,PDWORD);
-NET_API_STATUS WINAPI (*netgetdcname)(LPWSTR,LPWSTR,PBYTE*);
-
 #ifndef min
 #define min(a,b) (((a)<(b))?(a):(b))
 #endif
 
-BOOL
-load_netapi ()
+typedef struct
 {
-  HANDLE h = LoadLibrary ("netapi32.dll");
-
-  if (!h)
-    return FALSE;
-
-  if (!(netapibufferfree = GetProcAddress (h, "NetApiBufferFree")))
-    return FALSE;
-  if (!(netuserenum = GetProcAddress (h, "NetUserEnum")))
-    return FALSE;
-  if (!(netlocalgroupenum = GetProcAddress (h, "NetLocalGroupEnum")))
-    return FALSE;
-  if (!(netgetdcname = GetProcAddress (h, "NetGetDCName")))
-    return FALSE;
+  char *str;
+  BOOL domain;
+  BOOL with_dom;
+} domlist_t;
 
-  return TRUE;
+static void
+_print_win_error(DWORD code, int line)
+{
+  char buf[4096];
+
+  if (FormatMessage (FORMAT_MESSAGE_FROM_SYSTEM
+      | FORMAT_MESSAGE_IGNORE_INSERTS,
+      NULL,
+      code,
+      MAKELANGID (LANG_NEUTRAL, SUBLANG_DEFAULT),
+      (LPTSTR) buf, sizeof (buf), NULL))
+    fprintf (stderr, "mkpasswd (%d): [%" PRIu32 "] %s",
+            line, (unsigned int) code, buf);
+  else
+    fprintf (stderr, "mkpasswd (%d): error %" PRIu32,
+            line, (unsigned int) code);
 }
 
-char *
+static char *
 put_sid (PSID sid)
 {
   static char s[512];
@@ -62,247 +76,281 @@ put_sid (PSID sid)
   strcat (s, t);
   for (i = 0; i < *GetSidSubAuthorityCount (sid); ++i)
     {
-      sprintf(t, "-%lu", *GetSidSubAuthority (sid, i));
+      sprintf(t, "-%" PRIu32, (unsigned int) *GetSidSubAuthority (sid, i));
       strcat (s, t);
     }
   return s;
 }
 
-void
-psx_dir (char *in, char *out)
+static void
+uni2ansi (LPWSTR wcs, char *mbs, int size)
 {
-  if (isalpha (in[0]) && in[1] == ':')
-    {
-      sprintf (out, "/cygdrive/%c", in[0]);
-      in += 2;
-      out += strlen (out);
-    }
+  if (wcs)
+    wcstombs (mbs, wcs, size);
+  else
+    *mbs = '\0';
+}
 
-  while (*in)
-    {
-      if (*in == '\\')
-       *out = '/';
-      else
-       *out = *in;
-      in++;
-      out++;
-    }
+typedef struct {
+  PSID psid;
+  int buffer[10];
+} sidbuf;
 
-  *out = '\0';
-}
+static sidbuf curr_user;
+static sidbuf curr_pgrp;
+static BOOL got_curr_user = FALSE;
 
-void
-uni2ansi (LPWSTR wcs, char *mbs)
+static void
+fetch_current_user_sid ()
 {
-  if (wcs)
-    wcstombs (mbs, wcs, (wcslen (wcs) + 1) * sizeof (WCHAR));
-
-  else
-    *mbs = '\0';
+  DWORD len;
+  HANDLE ptok;
+
+  if (!OpenProcessToken (GetCurrentProcess (), TOKEN_QUERY, &ptok)
+      || !GetTokenInformation (ptok, TokenUser, &curr_user, sizeof curr_user,
+                              &len)
+      || !GetTokenInformation (ptok, TokenPrimaryGroup, &curr_pgrp,
+                              sizeof curr_pgrp, &len)
+      || !CloseHandle (ptok))
+    {
+      print_win_error (GetLastError ());
+      return;
+    }
 }
 
-int
-enum_users (LPWSTR servername, int print_sids, int print_cygpath,
-           const char * passed_home_path)
+static void
+enum_unix_users (domlist_t *mach, const char *sep, DWORD id_offset,
+                char *unix_user_list)
 {
-  USER_INFO_3 *buffer;
-  DWORD entriesread = 0;
-  DWORD totalentries = 0;
-  DWORD resume_handle = 0;
-  DWORD rc;
-  char ansi_srvname[256];
+  WCHAR machine[INTERNET_MAX_HOST_NAME_LENGTH + 1];
+  SID_IDENTIFIER_AUTHORITY auth = { { 0, 0, 0, 0, 0, 22 } };
+  char *ustr, *user_list;
+  WCHAR user[UNLEN + sizeof ("Unix User\\") + 1];
+  WCHAR dom[MAX_DOMAIN_NAME_LEN + 1];
+  DWORD ulen, dlen, sidlen;
+  PSID psid;
+  PSID numeric_psid;
+  char psid_buffer[SECURITY_MAX_SID_SIZE];
+  SID_NAME_USE acc_type;
+
+  int ret = mbstowcs (machine, mach->str, INTERNET_MAX_HOST_NAME_LENGTH + 1);
+  if (ret < 1 || ret >= INTERNET_MAX_HOST_NAME_LENGTH + 1)
+    {
+      fprintf (stderr, "%s: Invalid machine name '%s'.  Skipping...\n",
+              program_invocation_short_name, mach->str);
+      return;
+    }
 
-  if (servername)
-    uni2ansi (servername, ansi_srvname);
+  if (!AllocateAndInitializeSid (&auth, 2, 1, 0, 0, 0, 0, 0, 0, 0,
+                                &numeric_psid))
+    return;
 
-  do
+  if (!(user_list = strdup (unix_user_list)))
     {
-      DWORD i;
+      FreeSid (numeric_psid);
+      return;
+    }
 
-      rc = netuserenum (servername, 3, FILTER_NORMAL_ACCOUNT,
-                       (LPBYTE *) & buffer, 1024,
-                       &entriesread, &totalentries, &resume_handle);
-      switch (rc)
+  for (ustr = strtok (user_list, ","); ustr; ustr = strtok (NULL, ","))
+    {
+      if (!isdigit ((unsigned char) ustr[0]) && ustr[0] != '-')
        {
-       case ERROR_ACCESS_DENIED:
-         fprintf (stderr, "Access denied\n");
-         exit (1);
-
-       case ERROR_MORE_DATA:
-       case ERROR_SUCCESS:
-         break;
-
-       default:
-         fprintf (stderr, "NetUserEnum() failed with %ld\n", rc);
-         exit (1);
+         PWCHAR p = wcpcpy (user, L"Unix User\\");
+         ret = mbstowcs (p, ustr, UNLEN + 1);
+         if (ret < 1 || ret >= UNLEN + 1)
+           {
+             fprintf (stderr, "%s: Invalid user name '%s'.  Skipping...\n",
+                      program_invocation_short_name, ustr);
+             continue;
+           }
+         psid = (PSID) psid_buffer;
+         sidlen = SECURITY_MAX_SID_SIZE;
+         dlen = MAX_DOMAIN_NAME_LEN + 1;
+         if (LookupAccountNameW (machine, user, psid, &sidlen,
+                                 dom, &dlen, &acc_type))
+           printf ("%s%s%ls:*:%" PRIu32 ":99999:,%s::\n",
+                   "Unix_User",
+                   sep,
+                   user + 10,
+                   (unsigned int) (id_offset +
+                   *GetSidSubAuthority (psid,
+                                        *GetSidSubAuthorityCount(psid) - 1)),
+                   put_sid (psid));
        }
-
-      for (i = 0; i < entriesread; i++)
+      else
        {
-         char username[100];
-         char fullname[100];
-         char homedir_psx[MAX_PATH];
-         char homedir_w32[MAX_PATH];
-         char domain_name[100];
-         DWORD domname_len = 100;
-         char psid_buffer[1024];
-         PSID psid = (PSID) psid_buffer;
-         DWORD sid_length = 1024;
-         SID_NAME_USE acc_type;
-
-         int uid = buffer[i].usri3_user_id;
-         int gid = buffer[i].usri3_primary_group_id;
-         uni2ansi (buffer[i].usri3_name, username);
-         uni2ansi (buffer[i].usri3_full_name, fullname);
-         homedir_w32[0] = homedir_psx[0] = '\0';
-         uni2ansi (buffer[i].usri3_home_dir, homedir_w32);
-         if (print_cygpath)
-           cygwin_conv_to_posix_path (homedir_w32, homedir_psx);
+         DWORD start, stop;
+         char *p = ustr;
+         if (*p == '-')
+           start = 0;
          else
-           psx_dir (homedir_w32, homedir_psx);
-
-         if (homedir_psx[0] == '\0')
+           start = strtol (p, &p, 10);
+         if (!*p)
+           stop = start;
+         else if (*p++ != '-' || !isdigit ((unsigned char) *p)
+                  || (stop = strtol (p, &p, 10)) < start || *p)
            {
-             strcat (homedir_psx, passed_home_path);
-             strcat (homedir_psx, username);
+             fprintf (stderr, "%s: Malformed unix user list entry '%s'.  "
+                              "Skipping...\n",
+                              program_invocation_short_name, ustr);
+             continue;
            }
-
-         if (print_sids)
+         for (; start <= stop; ++ start)
            {
-             if (!LookupAccountName (servername ? ansi_srvname : NULL,
-                                     username,
-                                     psid, &sid_length,
-                                     domain_name, &domname_len,
-                                     &acc_type))
-               {
-                 fprintf (stderr,
-                          "LookupAccountName(%s,%s) failed with error %ld\n",
-                          servername ? ansi_srvname : "NULL",
-                          username,
-                          GetLastError ());
-                 continue;
-               }
-             else if (acc_type == SidTypeDomain)
-               {
-                 char domname[356];
-
-                 strcpy (domname, domain_name);
-                 strcat (domname, "\\");
-                 strcat (domname, username);
-                 sid_length = 1024;
-                 domname_len = 100;
-                 if (!LookupAccountName (servername ? ansi_srvname : NULL,
-                                         domname,
-                                         psid, &sid_length,
-                                         domain_name, &domname_len,
-                                         &acc_type))
-                   {
-                     fprintf (stderr,
-                              "LookupAccountName(%s,%s) failed with error %ld\n",
-                              servername ? ansi_srvname : "NULL",
-                              domname,
-                              GetLastError ());
-                     continue;
-                   }
-               }
+             psid = numeric_psid;
+             *GetSidSubAuthority (psid, *GetSidSubAuthorityCount(psid) - 1)
+             = start;
+             ulen = GNLEN + 1;
+             dlen = MAX_DOMAIN_NAME_LEN + 1;
+             if (LookupAccountSidW (machine, psid, user, &ulen,
+                                    dom, &dlen, &acc_type)
+                 && !iswdigit (user[0]))
+               printf ("%s%s%ls:*:%" PRIu32 ":99999:,%s::\n",
+                       "Unix_User",
+                       sep,
+                       user,
+                       (unsigned int) (id_offset + start),
+                       put_sid (psid));
            }
-         printf ("%s::%d:%d:%s%s%s:%s:/bin/sh\n", username, uid, gid,
-                 fullname,
-                 print_sids ? "," : "",
-                 print_sids ? put_sid (psid) : "",
-                 homedir_psx);
        }
-
-      netapibufferfree (buffer);
-
     }
-  while (rc == ERROR_MORE_DATA);
 
-  if (servername)
-    netapibufferfree (servername);
-
-  return 0;
+  free (user_list);
+  FreeSid (numeric_psid);
 }
 
-int
-enum_local_groups (int print_sids)
+static int
+enum_users (domlist_t *mach, const char *sep, const char *passed_home_path,
+           DWORD id_offset, char *disp_username, int print_current)
 {
-  LOCALGROUP_INFO_0 *buffer;
+  WCHAR machine[INTERNET_MAX_HOST_NAME_LENGTH + 1];
+  USER_INFO_3 *buffer;
   DWORD entriesread = 0;
   DWORD totalentries = 0;
   DWORD resume_handle = 0;
-  DWORD rc ;
+  DWORD rc;
+  WCHAR uni_name[UNLEN + 1];
+
+  int ret = mbstowcs (machine, mach->str, INTERNET_MAX_HOST_NAME_LENGTH + 1);
+  if (ret < 1 || ret >= INTERNET_MAX_HOST_NAME_LENGTH + 1)
+    {
+      fprintf (stderr, "%s: Invalid machine name '%s'.  Skipping...\n",
+              program_invocation_short_name, mach->str);
+      return 1;
+    }
 
   do
     {
       DWORD i;
 
-      rc = netlocalgroupenum (NULL, 0, (LPBYTE *) & buffer, 1024,
-                             &entriesread, &totalentries, &resume_handle);
+      if (disp_username != NULL)
+       {
+         mbstowcs (uni_name, disp_username, UNLEN + 1);
+         rc = NetUserGetInfo (machine, (LPWSTR) &uni_name, 3,
+                              (void *) &buffer);
+         entriesread = 1;
+         /* Avoid annoying error messages just because the user hasn't been
+            found. */
+         if (rc == NERR_UserNotFound)
+           return 0;
+       }
+      else
+       rc = NetUserEnum (machine, 3, FILTER_NORMAL_ACCOUNT,
+                         (void *) &buffer, MAX_PREFERRED_LENGTH,
+                         &entriesread, &totalentries, &resume_handle);
       switch (rc)
        {
        case ERROR_ACCESS_DENIED:
-         fprintf (stderr, "Access denied\n");
-         exit (1);
+         print_win_error(rc);
+         return 1;
 
        case ERROR_MORE_DATA:
        case ERROR_SUCCESS:
          break;
 
        default:
-         fprintf (stderr, "NetLocalGroupEnum() failed with %ld\n", rc);
-         exit (1);
+         print_win_error(rc);
+         return 1;
        }
 
       for (i = 0; i < entriesread; i++)
        {
-         char localgroup_name[100];
-         char domain_name[100];
-         DWORD domname_len = 100;
-         char psid_buffer[1024];
+         char homedir_psx[PATH_MAX];
+         WCHAR domain_name[MAX_DOMAIN_NAME_LEN + 1];
+         DWORD domname_len = MAX_DOMAIN_NAME_LEN + 1;
+         char psid_buffer[SECURITY_MAX_SID_SIZE];
          PSID psid = (PSID) psid_buffer;
-         DWORD sid_length = 1024;
-         DWORD gid;
+         DWORD sid_length = SECURITY_MAX_SID_SIZE;
          SID_NAME_USE acc_type;
-         uni2ansi (buffer[i].lgrpi0_name, localgroup_name);
 
-         if (!LookupAccountName (NULL, localgroup_name, psid,
-                                 &sid_length, domain_name, &domname_len,
-                                 &acc_type))
+         int uid = buffer[i].usri3_user_id;
+         int gid = buffer[i].usri3_primary_group_id;
+         homedir_psx[0] = '\0';
+         if (passed_home_path[0] == '\0')
+           {
+             if (buffer[i].usri3_home_dir[0] != L'\0')
+               cygwin_conv_path (CCP_WIN_W_TO_POSIX | CCP_ABSOLUTE,
+                                 buffer[i].usri3_home_dir, homedir_psx,
+                                 PATH_MAX);
+             else
+               uni2ansi (buffer[i].usri3_name,
+                         stpcpy (homedir_psx, "/home/"), PATH_MAX - 6);
+           }
+         else
+           uni2ansi (buffer[i].usri3_name,
+                     stpcpy (homedir_psx, passed_home_path),
+                     PATH_MAX - strlen (passed_home_path));
+
+         if (!LookupAccountNameW (machine, buffer[i].usri3_name,
+                                  psid, &sid_length, domain_name,
+                                  &domname_len, &acc_type))
            {
-             fprintf (stderr, "LookupAccountName(%s) failed with %ld\n",
-                      localgroup_name, GetLastError ());
+             print_win_error(GetLastError ());
+             fprintf(stderr, " (%ls)\n", buffer[i].usri3_name);
              continue;
            }
          else if (acc_type == SidTypeDomain)
            {
-             char domname[356];
-
-             strcpy (domname, domain_name);
-             strcat (domname, "\\");
-             strcat (domname, localgroup_name);
-             sid_length = 1024;
-             domname_len = 100;
-             if (!LookupAccountName (NULL, domname,
-                                     psid, &sid_length,
-                                     domain_name, &domname_len,
-                                     &acc_type))
+             WCHAR domname[MAX_DOMAIN_NAME_LEN + UNLEN + 2];
+             PWCHAR p;
+
+             p = wcpcpy (domname, machine);
+             p = wcpcpy (p, L"\\");
+             p = wcpncpy (p, buffer[i].usri3_name, UNLEN);
+             *p = L'\0';
+             sid_length = SECURITY_MAX_SID_SIZE;
+             domname_len = sizeof (domname);
+             if (!LookupAccountNameW (machine, domname, psid,
+                                      &sid_length, domain_name,
+                                      &domname_len, &acc_type))
                {
-                 fprintf (stderr,
-                          "LookupAccountName(%s) failed with error %ld\n",
-                          localgroup_name, GetLastError ());
+                 print_win_error(GetLastError ());
+                 fprintf(stderr, " (%ls)\n", domname);
                  continue;
                }
            }
-
-         gid = *GetSidSubAuthority (psid, *GetSidSubAuthorityCount(psid) - 1);
-
-         printf ("%s:*:%ld:%ld:%s%s::\n", localgroup_name, gid, gid,
-                 print_sids ? "," : "",
-                 print_sids ? put_sid (psid) : "");
+         if (!print_current)
+           /* fall through */;
+         else if (EqualSid (curr_user.psid, psid))
+           got_curr_user = TRUE;
+
+         printf ("%ls%s%ls:*:%" PRIu32 ":%" PRIu32
+                 ":%ls%sU-%ls\\%ls,%s:%s:/bin/bash\n",
+                 mach->with_dom ? domain_name : L"",
+                 mach->with_dom ? sep : "",
+                 buffer[i].usri3_name,
+                 (unsigned int) (id_offset + uid),
+                 (unsigned int) (id_offset + gid),
+                 buffer[i].usri3_full_name ?: L"",
+                 buffer[i].usri3_full_name
+                 && buffer[i].usri3_full_name[0] ? "," : "",
+                 domain_name,
+                 buffer[i].usri3_name,
+                 put_sid (psid),
+                 homedir_psx);
        }
 
-      netapibufferfree (buffer);
+      NetApiBufferFree (buffer);
 
     }
   while (rc == ERROR_MORE_DATA);
@@ -310,227 +358,362 @@ enum_local_groups (int print_sids)
   return 0;
 }
 
-int
-usage ()
+static int __attribute__ ((__noreturn__))
+usage (FILE * stream)
 {
-  fprintf (stderr, "Usage: mkpasswd [OPTION]... [domain]\n\n");
-  fprintf (stderr, "This program prints a /etc/passwd file to stdout\n\n");
-  fprintf (stderr, "Options:\n");
-  fprintf (stderr, "   -l,--local              print local user accounts\n");
-  fprintf (stderr, "   -d,--domain             print domain accounts (from current domain\n");
-  fprintf (stderr, "                           if no domain specified)\n");
-  fprintf (stderr, "   -g,--local-groups       print local group information too\n");
-  fprintf (stderr, "                           if no domain specified\n");
-  fprintf (stderr, "   -m,--no-mount           don't use mount points for home dir\n");
-  fprintf (stderr, "   -s,--no-sids            don't print SIDs in GCOS field\n");
-  fprintf (stderr, "                           (this affects ntsec)\n");
-  fprintf (stderr, "   -p,--path-to-home path  if user account has no home dir, use\n");
-  fprintf (stderr, "                           path instead of /home/\n");
-  fprintf (stderr, "   -?,--help               displays this message\n\n");
-  fprintf (stderr, "One of `-l', `-d' or `-g' must be given on NT/W2K.\n");
-  return 1;
+  fprintf (stream,
+"Usage: %s [OPTIONS]...\n"
+"\n"
+"Write /etc/passwd-like output to stdout\n"
+"\n"
+"Don't use this command to generate a local /etc/passwd file, unless you\n"
+"really need one.  See the Cygwin User's Guide for more information.\n"
+"\n"
+"Options:\n"
+"\n"
+"   -l,--local [machine]    Print local user accounts of \"machine\",\n"
+"                           from local machine if no machine specified.\n"
+"                           Automatically adding machine prefix for local\n"
+"                           machine depends on settings in /etc/nsswitch.conf.\n"
+"   -L,--Local machine      Ditto, but generate username with machine prefix.\n"
+"   -d,--domain [domain]    Print domain accounts,\n"
+"                           from current domain if no domain specified.\n"
+"   -c,--current            Print current user.\n"
+"   -S,--separator char     For -L use character char as domain\\user\n"
+"                           separator in username instead of the default '%s'.\n"
+"   -o,--id-offset offset   Change the default offset (0x10000) added to uids\n"
+"                           of foreign local machine accounts.  Use with -l/-L.\n"
+"   -u,--username username  Only return information for the specified user.\n"
+"                           One of -l, -d must be specified, too\n"
+"   -b,--no-builtin         Don't print BUILTIN users.\n"
+"   -p,--path-to-home path  Use specified path instead of user account home dir\n"
+"                           or /home prefix.\n"
+"   -U,--unix userlist      Print UNIX users when using -l on a UNIX Samba\n"
+"                           server.  Userlist is a comma-separated list of\n"
+"                           usernames or uid ranges (root,-25,50-100).\n"
+"                           Enumerating large ranges can take a long time!\n"
+"   -h,--help               Displays this message.\n"
+"   -V,--version            Version information and exit.\n"
+"\n"
+"Default is to print local accounts on stand-alone machines, domain accounts\n"
+"on domain controllers and domain member machines.\n"
+"\n", program_invocation_short_name,
+      (const char *) cygwin_internal (CW_GETNSSSEP));
+  exit (stream == stdout ? 0 : 1);
 }
 
-struct option longopts[] = {
-  {"local", no_argument, NULL, 'l'},
-  {"domain", no_argument, NULL, 'd'},
+static struct option longopts[] = {
+  {"no-builtin", no_argument, NULL, 'b'},
+  {"current", no_argument, NULL, 'c'},
+  {"Current", no_argument, NULL, 'C'},
+  {"domain", optional_argument, NULL, 'd'},
+  {"Domain", optional_argument, NULL, 'D'},
   {"local-groups", no_argument, NULL, 'g'},
+  {"help", no_argument, NULL, 'h'},
+  {"local", optional_argument, NULL, 'l'},
+  {"Local", optional_argument, NULL, 'L'},
   {"no-mount", no_argument, NULL, 'm'},
+  {"id-offset", required_argument, NULL, 'o'},
+  {"path-to-home", required_argument, NULL, 'p'},
   {"no-sids", no_argument, NULL, 's'},
-  {"path-to-home",required_argument, NULL, 'p'},
-  {"help", no_argument, NULL, 'h'},
+  {"separator", required_argument, NULL, 'S'},
+  {"username", required_argument, NULL, 'u'},
+  {"unix", required_argument, NULL, 'U'},
+  {"version", no_argument, NULL, 'V'},
   {0, no_argument, NULL, 0}
 };
 
-char opts[] = "ldgsmhp:";
+static char opts[] = "bcCd::D::ghl::L::mo:sS:p:u:U:V";
+
+static void
+print_version ()
+{
+  printf ("mkpasswd (cygwin) %d.%d.%d\n"
+         "Passwd File Generator\n"
+         "Copyright (C) 1997 - %s Cygwin Authors\n"
+         "This is free software; see the source for copying conditions.  There is NO\n"
+         "warranty; not even for MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.\n",
+         CYGWIN_VERSION_DLL_MAJOR / 1000,
+         CYGWIN_VERSION_DLL_MAJOR % 1000,
+         CYGWIN_VERSION_DLL_MINOR,
+         strrchr (__DATE__, ' ') + 1);
+}
 
 int
 main (int argc, char **argv)
 {
-  LPWSTR servername = NULL;
-  DWORD rc = ERROR_SUCCESS;
-  WCHAR domain_name[200];
-  int print_local = 0;
-  int print_domain = 0;
-  int print_local_groups = 0;
-  int domain_name_specified = 0;
-  int print_sids = 1;
-  int print_cygpath = 1;
-  int i;
-
-  char name[256], dom[256], passed_home_path[MAX_PATH];
-  DWORD len, len2;
-  PSID sid;
-  SID_NAME_USE use;
+  int print_domlist = 0;
+  domlist_t domlist[32];
+  char cname[1024];
+  char *opt, *p, *ep;
+  int print_current = 0;
+  int print_builtin = 1;
+  char *print_unix = NULL;
+  const char *nss_sep = (const char *) cygwin_internal (CW_GETNSSSEP);
+  const char *sep_char = nss_sep;
+  DWORD id_offset = 0x10000, off;
+  int c, i;
+  char *disp_username = NULL;
+  char passed_home_path[PATH_MAX];
+  int optional_args = 0;
+  uintptr_t nss_src = cygwin_internal (CW_GETNSS_PWD_SRC);
 
   passed_home_path[0] = '\0';
+  if (!isatty (1))
+    setmode (1, O_BINARY);
 
-  if (GetVersion () < 0x80000000)
-    if (argc == 1)
-      return usage ();
-    else
+  /* Use locale from environment.  If not set or set to "C", use UTF-8. */
+  setlocale (LC_CTYPE, "");
+  if (!strcmp (setlocale (LC_CTYPE, NULL), "C"))
+    setlocale (LC_CTYPE, "en_US.UTF-8");
+  fetch_current_user_sid ();
+
+  if (argc == 1)
+    {
+      int enums = ENUM_PRIMARY | ENUM_LOCAL | ENUM_BUILTIN;
+      uintptr_t ticket = cygwin_internal (CW_SETENT, FALSE, enums, NULL);
+      if (ticket)
+       {
+         struct passwd *pwd;
+
+         while ((pwd = (struct passwd *) cygwin_internal (CW_GETENT, FALSE,
+                                                          ticket)))
+           printf ("%s:%s:%u:%u:%s:%s:%s\n", pwd->pw_name, pwd->pw_passwd,
+                   pwd->pw_uid, pwd->pw_gid, pwd->pw_gecos, pwd->pw_dir,
+                   pwd->pw_shell);
+         cygwin_internal (CW_ENDENT, FALSE, ticket);
+       }
+      return 0;
+    }
+
+  unsetenv ("POSIXLY_CORRECT"); /* To get optional arg processing right. */
+  while ((c = getopt_long (argc, argv, opts, longopts, NULL)) != EOF)
+    switch (c)
       {
-       while ((i = getopt_long (argc, argv, opts, longopts, NULL)) != EOF)
-         switch (i)
+      case 'd':
+      case 'D':
+      case 'l':
+      case 'L':
+       if (print_domlist >= 32)
+         {
+           fprintf (stderr, "%s: Can not enumerate from more than 32 "
+                            "domains and machines.\n",
+                            program_invocation_short_name);
+           return 1;
+         }
+       domlist[print_domlist].domain = (c == 'd' || c == 'D');
+       opt = optarg ?:
+             argv[optind] && argv[optind][0] != '-' ? argv[optind] : NULL;
+       if (argv[optind] && opt == argv[optind])
+         ++optional_args;
+       for (i = 0; i < print_domlist; ++i)
+         if (domlist[i].domain == domlist[print_domlist].domain
+             && ((!domlist[i].str && !opt)
+                 || (domlist[i].str && opt
+                     && (off = strlen (domlist[i].str))
+                     && !strncmp (domlist[i].str, opt, off)
+                     && (!opt[off] || opt[off] == ','))))
            {
-           case 'l':
-             print_local = 1;
-             break;
-           case 'd':
-             print_domain = 1;
-             break;
-           case 'g':
-             print_local_groups = 1;
-             break;
-           case 's':
-             print_sids = 0;
+             fprintf (stderr, "%s: Duplicate %s '%s'.  Skipping...\n",
+                      program_invocation_short_name,
+                      domlist[i].domain ? "domain" : "machine",
+                      domlist[i].str);
              break;
-           case 'm':
-             print_cygpath = 0;
-             break;
-            case 'p':
-              if (optarg[0] != '/')
-               {
-                  fprintf (stderr, "%s: `%s' is not a fully qualified path.\n",
-                           argv[0], optarg);
-                  return 1;
-                }
-              strcpy (passed_home_path, optarg);
-              if (optarg[strlen (optarg)-1] != '/')
-                strcat (passed_home_path, "/");
-              break;
-           case 'h':
-             return usage ();
-           default:
-             fprintf (stderr, "Try `%s --help' for more information.\n", argv[0]);
-             return 1;
            }
-       if (!print_local && !print_domain && !print_local_groups)
+       domlist[print_domlist].str = opt;
+       if (opt && (p = strchr (opt, ',')))
          {
-           fprintf (stderr, "%s: Specify one of `-l', `-d' or `-g'\n", argv[0]);
-           return 1;
+           if (p == opt)
+             {
+               fprintf (stderr, "%s: Malformed domain string '%s'.  "
+                        "Skipping...\n", program_invocation_short_name, opt);
+               break;
+             }
+           *p = '\0';
          }
-       if (optind < argc)
+       if (c == 'l' || c == 'L')
          {
-           if (!print_domain)
+           DWORD csize = sizeof cname;
+
+           domlist[print_domlist].with_dom = (c == 'L');
+           if (!opt)
+             {
+               /* If the system uses /etc/passwd exclusively as account DB,
+                  create local group names the old fashioned way. */
+               if (nss_src == NSS_SRC_FILES)
+                 {
+                   GetComputerNameExA (ComputerNameNetBIOS, cname, &csize);
+                   domlist[print_domlist].str = cname;
+                 }
+             }
+           else if (nss_src != NSS_SRC_FILES)
              {
-               fprintf (stderr, "%s: A domain name is only accepted "
-                                "when `-d' is given.\n", argv[0]);
-               return 1;
+               /* If the system uses Windows account DBs, check if machine
+                  name is local machine.  If so, remove the domain name to
+                  enforce system naming convention. */
+               if (GetComputerNameExA (strchr (opt, '.')
+                                       ? ComputerNameDnsFullyQualified
+                                       : ComputerNameNetBIOS,
+                                       cname, &csize)
+                   && strcasecmp (opt, cname) == 0)
+                 domlist[print_domlist].str = NULL;
              }
-           mbstowcs (domain_name, argv[optind], (strlen (argv[optind]) + 1));
-           domain_name_specified = 1;
          }
+       ++print_domlist;
+       break;
+      case 'S':
+       sep_char = optarg;
+       if (strlen (sep_char) > 1)
+         {
+           fprintf (stderr, "%s: Only one ASCII character allowed as "
+                            "domain\\user separator character.\n",
+                            program_invocation_short_name);
+           return 1;
+         }
+       if (*sep_char == ':')
+         {
+           fprintf (stderr, "%s: Colon not allowed as domain\\user separator "
+                            "character.\n", program_invocation_short_name);
+           return 1;
+         }
+       break;
+      case 'U':
+       print_unix = optarg;
+       break;
+      case 'c':
+      case 'C':
+       print_current = 1;
+       break;
+      case 'o':
+       id_offset = strtoul (optarg, &ep, 10);
+       break;
+      case 'b':
+       print_builtin = 0;
+       break;
+      case 'p':
+       if (optarg[0] != '/')
+       {
+         fprintf (stderr, "%s: '%s' is not a fully qualified path.\n",
+                  program_invocation_short_name, optarg);
+         return 1;
+       }
+       strcpy (passed_home_path, optarg);
+       if (optarg[strlen (optarg)-1] != '/')
+         strcat (passed_home_path, "/");
+       break;
+      case 'u':
+       disp_username = optarg;
+       break;
+      case 'h':
+       usage (stdout);
+      case 'V':
+       print_version ();
+       return 0;
+      case 'g':                /* deprecated */
+      case 's':                /* deprecated */
+      case 'm':                /* deprecated */
+       break;
+      default:
+       fprintf (stderr, "Try `%s --help' for more information.\n",
+                program_invocation_short_name);
+       return 1;
       }
 
-  if (passed_home_path[0] == '\0')
-      strcpy (passed_home_path, "/home/");
-
-  /* This takes Windows 9x/ME into account. */
-  if (GetVersion () >= 0x80000000)
+  optind += optional_args;
+  if (argv[optind])
     {
-      /* Same behaviour as in cygwin/uinfo.cc (internal_getlogin). */
-      if (!GetUserName (name, (len = 256, &len)))
-       strcpy (name, "unknown");
-
-      printf ("%s::%ld:%ld::%s%s:/bin/sh\n", name,
-                                            DOMAIN_USER_RID_ADMIN,
-                                            DOMAIN_ALIAS_RID_ADMINS,
-                                            passed_home_path,
-                                            name);
-
-      return 0;
+      fprintf (stderr,
+              "mkpasswd: non-option command line argument `%s' is not allowed.\n"
+              "Try `mkpasswd --help' for more information.\n", argv[optind]);
+      exit (1);
     }
 
-  if (!load_netapi ())
+  struct passwd *ppwd = NULL;
+  const char *ppwd_sid = NULL;
+  if (print_current)
     {
-      fprintf (stderr, "Failed loading symbols from netapi32.dll "
-                      "with error %lu\n", GetLastError ());
-      return 1;
+      ppwd = (struct passwd *) cygwin_internal (CW_GETPWSID, TRUE,
+                                               curr_user.psid);
+      if (ppwd)
+       ppwd_sid = strrchr (ppwd->pw_gecos, ',');
     }
 
-  /*
-   * Get `Everyone' group
-  */
-  if (AllocateAndInitializeSid (&sid_world_auth, 1, SECURITY_WORLD_RID,
-                               0, 0, 0, 0, 0, 0, 0, &sid))
+  int enums = ENUM_NONE;
+  WCHAR tdoms[print_domlist * 258];
+  PWCHAR t = tdoms;
+  if (!disp_username && print_builtin && print_domlist)
+    enums |= ENUM_BUILTIN;
+  for (i = 0; i < print_domlist; ++i)
     {
-      if (LookupAccountSid (NULL, sid,
-                           name, (len = 256, &len),
-                           dom, (len2 = 256, &len),
-                           &use))
-       printf ("%s:*:%d:%d:%s%s::\n", name,
-                                        SECURITY_WORLD_RID,
-                                        SECURITY_WORLD_RID,
-                                        print_sids ? "," : "",
-                                        print_sids ? put_sid (sid) : "");
-      FreeSid (sid);
+      if (domlist[i].domain)
+        {
+          if (domlist[i].str)
+            {
+              enums |= ENUM_TDOMS;
+              t += mbstowcs (t, domlist[i].str, 257);
+              *t++ = L'\0';
+            }
+          else
+            enums |= ENUM_PRIMARY;
+        }
+      else if (!domlist[i].str)
+        enums |= ENUM_LOCAL;
     }
-
-  /*
-   * Get `system' group
-  */
-  if (AllocateAndInitializeSid (&sid_nt_auth, 1, SECURITY_LOCAL_SYSTEM_RID,
-                               0, 0, 0, 0, 0, 0, 0, &sid))
+  if (t > tdoms)
+    *t++ = L'\0';
+  if (enums)
     {
-      if (LookupAccountSid (NULL, sid,
-                           name, (len = 256, &len),
-                           dom, (len2 = 256, &len),
-                           &use))
-       printf ("%s:*:%d:%d:%s%s::\n", name,
-                                        SECURITY_LOCAL_SYSTEM_RID,
-                                        SECURITY_LOCAL_SYSTEM_RID,
-                                        print_sids ? "," : "",
-                                        print_sids ? put_sid (sid) : "");
-      FreeSid (sid);
+      uintptr_t ticket = cygwin_internal (CW_SETENT, FALSE, enums,
+                                          t > tdoms ? tdoms : NULL);
+      if (ticket)
+        {
+          struct passwd *pwd;
+
+          while ((pwd = (struct passwd *)
+                        cygwin_internal (CW_GETENT, FALSE, ticket)))
+            {
+             p = NULL;
+              if (disp_username
+                  && strcasecmp (disp_username, pwd->pw_name) != 0
+                  && (!(p = strchr (pwd->pw_name, nss_sep[0]))
+                      || strcasecmp (disp_username, p + 1) != 0))
+                continue;
+             printf ("%s:%s:%u:%u:%s:%s%s:%s\n", pwd->pw_name, pwd->pw_passwd,
+                     pwd->pw_uid, pwd->pw_gid, pwd->pw_gecos,
+                     passed_home_path[0] ? passed_home_path : "",
+                     passed_home_path[0] ? (p ? p + 1 : pwd->pw_name)
+                                         : pwd->pw_dir,
+                     pwd->pw_shell);
+             const char *pwd_sid = strrchr (pwd->pw_gecos, ',');
+              if (ppwd && ppwd_sid && pwd_sid && !strcmp (pwd_sid, ppwd_sid))
+                got_curr_user = TRUE;
+            }
+          cygwin_internal (CW_ENDENT, FALSE, ticket);
+        }
     }
 
-  /*
-   * Get `administrators' group
-  */
-  if (!print_local_groups
-      && AllocateAndInitializeSid (&sid_nt_auth, 2,
-                                  SECURITY_BUILTIN_DOMAIN_RID,
-                                  DOMAIN_ALIAS_RID_ADMINS,
-                                  0, 0, 0, 0, 0, 0, &sid))
+  if (print_current && !got_curr_user)
     {
-      if (LookupAccountSid (NULL, sid,
-                           name, (len = 256, &len),
-                           dom, (len2 = 256, &len),
-                           &use))
-       printf ("%s:*:%ld:%ld:%s%s::\n", name,
-                                        DOMAIN_ALIAS_RID_ADMINS,
-                                        DOMAIN_ALIAS_RID_ADMINS,
-                                        print_sids ? "," : "",
-                                        print_sids ? put_sid (sid) : "");
-      FreeSid (sid);
+      p = strchr (ppwd->pw_name, nss_sep[0]);
+      printf ("%s:%s:%u:%u:%s:%s%s:%s\n", ppwd->pw_name, ppwd->pw_passwd,
+             ppwd->pw_uid, ppwd->pw_gid, ppwd->pw_gecos,
+             passed_home_path[0] ? passed_home_path : "",
+             passed_home_path[0] ? (p ? p + 1 : ppwd->pw_name) : ppwd->pw_dir,
+             ppwd->pw_shell);
     }
 
-  if (print_local_groups)
-    enum_local_groups (print_sids);
-
-  if (print_domain)
+  off = 0xfd000000;
+  for (i = 0; i < print_domlist; ++i)
     {
-      if (domain_name_specified)
-       rc = netgetdcname (NULL, domain_name, (LPBYTE *) & servername);
-
-      else
-       rc = netgetdcname (NULL, NULL, (LPBYTE *) & servername);
-
-      if (rc != ERROR_SUCCESS)
-       {
-         fprintf (stderr, "Cannot get DC, code = %ld\n", rc);
-         exit (1);
-       }
-
-      enum_users (servername, print_sids, print_cygpath, passed_home_path);
+      if (domlist[i].domain || !domlist[i].str)
+       continue;
+      enum_users (domlist + i, sep_char, passed_home_path,
+                 (nss_src == NSS_SRC_FILES) ? 0x30000 : off,
+                 disp_username, print_current);
+      if (!domlist[i].domain && domlist[i].str && print_unix)
+       enum_unix_users (domlist + i, sep_char, 0xff000000, print_unix);
+      off += id_offset;
     }
 
-  if (print_local)
-    enum_users (NULL, print_sids, print_cygpath, passed_home_path);
-
-  if (servername)
-    netapibufferfree (servername);
-
   return 0;
 }
This page took 0.04554 seconds and 5 git commands to generate.