2018-10-26 08:39:09 -06:00
|
|
|
/*
|
|
|
|
* This is an open source non-commercial project. Dear PVS-Studio, please check it.
|
|
|
|
* PVS-Studio Static Code Analyzer for C, C++ and C#: http://www.viva64.com
|
|
|
|
*/
|
2018-10-21 08:46:05 -06:00
|
|
|
|
2010-11-09 08:55:55 -05:00
|
|
|
#include <config.h>
|
2008-11-09 14:15:36 +00:00
|
|
|
#include <stdlib.h>
|
|
|
|
#include <string.h>
|
2004-10-26 22:10:55 +00:00
|
|
|
#define YYBYACC 1
|
|
|
|
#define YYMAJOR 1
|
|
|
|
#define YYMINOR 9
|
|
|
|
#define YYLEX yylex()
|
|
|
|
#define YYEMPTY -1
|
|
|
|
#define yyclearin (yychar=(YYEMPTY))
|
|
|
|
#define yyerrok (yyerrflag=0)
|
|
|
|
#define YYRECOVERING() (yyerrflag!=0)
|
2012-09-14 16:19:25 -04:00
|
|
|
#define yyparse sudoersparse
|
|
|
|
#define yylex sudoerslex
|
|
|
|
#define yyerror sudoerserror
|
|
|
|
#define yychar sudoerschar
|
|
|
|
#define yyval sudoersval
|
|
|
|
#define yylval sudoerslval
|
|
|
|
#define yydebug sudoersdebug
|
|
|
|
#define yynerrs sudoersnerrs
|
|
|
|
#define yyerrflag sudoerserrflag
|
|
|
|
#define yyss sudoersss
|
|
|
|
#define yysslim sudoerssslim
|
|
|
|
#define yyssp sudoersssp
|
|
|
|
#define yyvs sudoersvs
|
|
|
|
#define yyvsp sudoersvsp
|
|
|
|
#define yystacksize sudoersstacksize
|
|
|
|
#define yylhs sudoerslhs
|
|
|
|
#define yylen sudoerslen
|
|
|
|
#define yydefred sudoersdefred
|
|
|
|
#define yydgoto sudoersdgoto
|
|
|
|
#define yysindex sudoerssindex
|
|
|
|
#define yyrindex sudoersrindex
|
|
|
|
#define yygindex sudoersgindex
|
|
|
|
#define yytable sudoerstable
|
|
|
|
#define yycheck sudoerscheck
|
|
|
|
#define yyname sudoersname
|
|
|
|
#define yyrule sudoersrule
|
|
|
|
#define YYPREFIX "sudoers"
|
2010-05-30 10:31:38 -04:00
|
|
|
#line 2 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
/*
|
2019-04-29 07:21:51 -06:00
|
|
|
* SPDX-License-Identifier: ISC
|
|
|
|
*
|
2020-03-11 11:17:52 -06:00
|
|
|
* Copyright (c) 1996, 1998-2005, 2007-2013, 2014-2020
|
2017-12-03 17:53:40 -07:00
|
|
|
* Todd C. Miller <Todd.Miller@sudo.ws>
|
2004-10-26 22:10:55 +00:00
|
|
|
*
|
|
|
|
* Permission to use, copy, modify, and distribute this software for any
|
|
|
|
* purpose with or without fee is hereby granted, provided that the above
|
|
|
|
* copyright notice and this permission notice appear in all copies.
|
|
|
|
*
|
|
|
|
* THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
|
|
|
|
* WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
|
|
|
|
* MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
|
|
|
|
* ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
|
|
|
* WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
|
|
|
|
* ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
|
|
|
|
* OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
|
|
|
|
*
|
|
|
|
* Sponsored in part by the Defense Advanced Research Projects
|
|
|
|
* Agency (DARPA) and Air Force Research Laboratory, Air Force
|
|
|
|
* Materiel Command, USAF, under agreement number F39502-99-1-0512.
|
|
|
|
*/
|
|
|
|
|
2004-11-19 18:39:14 +00:00
|
|
|
#include <config.h>
|
2004-10-26 22:10:55 +00:00
|
|
|
|
|
|
|
#include <stdio.h>
|
2015-06-19 14:29:27 -06:00
|
|
|
#include <stdlib.h>
|
|
|
|
#include <stddef.h>
|
2020-05-18 07:59:24 -06:00
|
|
|
#include <string.h>
|
2015-07-02 09:08:28 -06:00
|
|
|
#include <unistd.h>
|
2004-10-26 22:10:55 +00:00
|
|
|
#if defined(YYBISON) && defined(HAVE_ALLOCA_H) && !defined(__GNUC__)
|
|
|
|
# include <alloca.h>
|
|
|
|
#endif /* YYBISON && HAVE_ALLOCA_H && !__GNUC__ */
|
2017-02-14 15:56:34 -07:00
|
|
|
#include <errno.h>
|
2004-10-26 22:10:55 +00:00
|
|
|
|
2018-05-14 09:05:02 -06:00
|
|
|
#include "sudoers.h"
|
2018-05-24 21:04:07 -06:00
|
|
|
#include "sudo_digest.h"
|
2011-03-21 12:39:06 -04:00
|
|
|
#include "toke.h"
|
2004-10-26 22:10:55 +00:00
|
|
|
|
2020-08-10 13:59:31 -06:00
|
|
|
#ifdef YYBISON
|
|
|
|
# define YYERROR_VERBOSE
|
|
|
|
#endif
|
|
|
|
|
2016-11-12 19:22:32 -07:00
|
|
|
/* If we last saw a newline the entry is on the preceding line. */
|
2020-08-10 13:59:31 -06:00
|
|
|
#define this_lineno (last_token == '\n' ? sudolineno - 1 : sudolineno)
|
2016-11-12 19:22:32 -07:00
|
|
|
|
2004-10-26 22:10:55 +00:00
|
|
|
/*
|
|
|
|
* Globals
|
|
|
|
*/
|
2012-02-29 15:50:48 -05:00
|
|
|
bool sudoers_warnings = true;
|
2019-11-05 15:18:34 -07:00
|
|
|
bool sudoers_strict = false;
|
2011-12-02 11:27:33 -05:00
|
|
|
bool parse_error = false;
|
2004-10-26 22:10:55 +00:00
|
|
|
int errorlineno = -1;
|
2016-10-31 15:21:18 -06:00
|
|
|
char *errorfile = NULL;
|
2004-10-26 22:10:55 +00:00
|
|
|
|
2018-07-26 15:12:33 -06:00
|
|
|
struct sudoers_parse_tree parsed_policy = {
|
|
|
|
TAILQ_HEAD_INITIALIZER(parsed_policy.userspecs),
|
|
|
|
TAILQ_HEAD_INITIALIZER(parsed_policy.defaults),
|
2019-08-15 14:20:12 -06:00
|
|
|
NULL, /* aliases */
|
|
|
|
NULL, /* lhost */
|
|
|
|
NULL /* shost */
|
2018-07-26 15:12:33 -06:00
|
|
|
};
|
2004-10-26 22:10:55 +00:00
|
|
|
|
|
|
|
/*
|
2020-05-06 09:27:43 -06:00
|
|
|
* Local prototypes
|
2004-10-26 22:10:55 +00:00
|
|
|
*/
|
2017-02-14 15:56:34 -07:00
|
|
|
static void init_options(struct command_options *opts);
|
2015-05-27 10:36:03 -06:00
|
|
|
static bool add_defaults(int, struct member *, struct defaults *);
|
|
|
|
static bool add_userspec(struct member *, struct privilege *);
|
2016-11-09 16:00:12 -07:00
|
|
|
static struct defaults *new_default(char *, char *, short);
|
2010-03-17 19:56:27 -04:00
|
|
|
static struct member *new_member(char *, int);
|
2020-08-10 13:59:31 -06:00
|
|
|
static struct sudo_command *new_command(char *, char *);
|
2018-05-24 21:04:07 -06:00
|
|
|
static struct command_digest *new_digest(int, char *);
|
2020-08-10 13:59:31 -06:00
|
|
|
#line 77 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
#ifndef YYSTYPE_DEFINED
|
|
|
|
#define YYSTYPE_DEFINED
|
|
|
|
typedef union {
|
|
|
|
struct cmndspec *cmndspec;
|
|
|
|
struct defaults *defaults;
|
|
|
|
struct member *member;
|
2007-11-21 20:12:00 +00:00
|
|
|
struct runascontainer *runas;
|
2004-10-26 22:10:55 +00:00
|
|
|
struct privilege *privilege;
|
2018-05-24 21:04:07 -06:00
|
|
|
struct command_digest *digest;
|
2004-10-26 22:10:55 +00:00
|
|
|
struct sudo_command command;
|
2017-02-14 15:56:34 -07:00
|
|
|
struct command_options options;
|
2017-02-14 15:56:34 -07:00
|
|
|
struct cmndtag tag;
|
2004-10-26 22:10:55 +00:00
|
|
|
char *string;
|
|
|
|
int tok;
|
|
|
|
} YYSTYPE;
|
|
|
|
#endif /* YYSTYPE_DEFINED */
|
2020-08-10 13:59:31 -06:00
|
|
|
#line 130 "gram.c"
|
2020-08-07 14:22:24 -06:00
|
|
|
#define END 0
|
2004-10-26 22:10:55 +00:00
|
|
|
#define COMMAND 257
|
|
|
|
#define ALIAS 258
|
|
|
|
#define DEFVAR 259
|
|
|
|
#define NTWKADDR 260
|
|
|
|
#define NETGROUP 261
|
|
|
|
#define USERGROUP 262
|
|
|
|
#define WORD 263
|
2013-04-15 15:12:00 -04:00
|
|
|
#define DIGEST 264
|
2020-05-20 13:10:53 -06:00
|
|
|
#define INCLUDE 265
|
|
|
|
#define INCLUDEDIR 266
|
|
|
|
#define DEFAULTS 267
|
|
|
|
#define DEFAULTS_HOST 268
|
|
|
|
#define DEFAULTS_USER 269
|
|
|
|
#define DEFAULTS_RUNAS 270
|
|
|
|
#define DEFAULTS_CMND 271
|
|
|
|
#define NOPASSWD 272
|
|
|
|
#define PASSWD 273
|
|
|
|
#define NOEXEC 274
|
|
|
|
#define EXEC 275
|
|
|
|
#define SETENV 276
|
|
|
|
#define NOSETENV 277
|
|
|
|
#define LOG_INPUT 278
|
|
|
|
#define NOLOG_INPUT 279
|
|
|
|
#define LOG_OUTPUT 280
|
|
|
|
#define NOLOG_OUTPUT 281
|
|
|
|
#define MAIL 282
|
|
|
|
#define NOMAIL 283
|
|
|
|
#define FOLLOWLNK 284
|
|
|
|
#define NOFOLLOWLNK 285
|
|
|
|
#define ALL 286
|
2020-08-10 13:59:31 -06:00
|
|
|
#define HOSTALIAS 287
|
|
|
|
#define CMNDALIAS 288
|
|
|
|
#define USERALIAS 289
|
|
|
|
#define RUNASALIAS 290
|
|
|
|
#define ERROR 291
|
2020-08-16 06:42:15 -06:00
|
|
|
#define NOMATCH 292
|
2020-09-01 06:26:00 -06:00
|
|
|
#define CHROOT 293
|
|
|
|
#define CWD 294
|
|
|
|
#define TYPE 295
|
|
|
|
#define ROLE 296
|
|
|
|
#define PRIVS 297
|
|
|
|
#define LIMITPRIVS 298
|
|
|
|
#define CMND_TIMEOUT 299
|
|
|
|
#define NOTBEFORE 300
|
|
|
|
#define NOTAFTER 301
|
|
|
|
#define MYSELF 302
|
|
|
|
#define SHA224_TOK 303
|
|
|
|
#define SHA256_TOK 304
|
|
|
|
#define SHA384_TOK 305
|
|
|
|
#define SHA512_TOK 306
|
2004-10-26 22:10:55 +00:00
|
|
|
#define YYERRCODE 256
|
2012-09-14 16:19:25 -04:00
|
|
|
const short sudoerslhs[] =
|
2004-10-26 22:10:55 +00:00
|
|
|
{ -1,
|
2020-09-01 06:26:00 -06:00
|
|
|
0, 0, 37, 37, 38, 38, 38, 38, 38, 38,
|
|
|
|
38, 38, 38, 38, 38, 38, 38, 38, 33, 33,
|
|
|
|
34, 34, 4, 4, 3, 3, 3, 3, 3, 21,
|
2020-08-16 15:19:53 -06:00
|
|
|
21, 21, 20, 11, 11, 9, 9, 9, 9, 9,
|
2020-09-01 06:26:00 -06:00
|
|
|
2, 2, 1, 35, 35, 35, 35, 36, 36, 7,
|
|
|
|
7, 6, 6, 24, 25, 30, 31, 32, 26, 27,
|
|
|
|
28, 29, 18, 18, 19, 19, 19, 19, 19, 23,
|
|
|
|
23, 23, 23, 23, 23, 23, 23, 23, 23, 22,
|
2020-08-16 15:19:53 -06:00
|
|
|
22, 22, 22, 22, 22, 22, 22, 22, 22, 22,
|
2020-09-01 06:26:00 -06:00
|
|
|
22, 22, 22, 22, 5, 5, 5, 41, 41, 44,
|
|
|
|
10, 10, 42, 42, 45, 8, 8, 43, 43, 46,
|
|
|
|
40, 40, 47, 14, 14, 12, 12, 13, 13, 13,
|
|
|
|
13, 13, 17, 17, 15, 15, 16, 16, 16, 39,
|
|
|
|
39,
|
2004-10-26 22:10:55 +00:00
|
|
|
};
|
2012-09-14 16:19:25 -04:00
|
|
|
const short sudoerslen[] =
|
2004-10-26 22:10:55 +00:00
|
|
|
{ 2,
|
2020-08-16 14:59:45 -06:00
|
|
|
0, 1, 1, 2, 1, 2, 1, 1, 3, 3,
|
|
|
|
3, 3, 3, 3, 4, 4, 4, 4, 3, 4,
|
|
|
|
3, 4, 1, 3, 1, 2, 3, 3, 3, 1,
|
2020-08-16 15:19:53 -06:00
|
|
|
3, 4, 3, 1, 2, 1, 1, 1, 1, 1,
|
|
|
|
1, 3, 4, 3, 3, 3, 3, 1, 3, 1,
|
|
|
|
2, 1, 2, 3, 3, 3, 3, 3, 3, 3,
|
2020-09-01 06:26:00 -06:00
|
|
|
3, 3, 0, 3, 0, 1, 3, 2, 1, 0,
|
|
|
|
2, 2, 2, 2, 2, 2, 2, 2, 2, 0,
|
2020-08-16 15:19:53 -06:00
|
|
|
2, 2, 2, 2, 2, 2, 2, 2, 2, 2,
|
2020-09-01 06:26:00 -06:00
|
|
|
2, 2, 2, 2, 1, 1, 1, 1, 3, 3,
|
|
|
|
1, 3, 1, 3, 3, 1, 3, 1, 3, 3,
|
|
|
|
1, 3, 3, 1, 3, 1, 2, 1, 1, 1,
|
|
|
|
1, 1, 1, 3, 1, 2, 1, 1, 1, 1,
|
|
|
|
1,
|
2004-10-26 22:10:55 +00:00
|
|
|
};
|
2012-09-14 16:19:25 -04:00
|
|
|
const short sudoersdefred[] =
|
2004-10-26 22:10:55 +00:00
|
|
|
{ 0,
|
2020-09-01 06:26:00 -06:00
|
|
|
0, 118, 120, 121, 122, 0, 0, 0, 0, 0,
|
|
|
|
0, 0, 119, 0, 0, 0, 0, 0, 5, 0,
|
|
|
|
114, 116, 0, 7, 8, 0, 3, 131, 130, 6,
|
2020-08-16 15:19:53 -06:00
|
|
|
0, 0, 0, 0, 23, 0, 36, 39, 38, 40,
|
2020-09-01 06:26:00 -06:00
|
|
|
37, 0, 34, 0, 101, 0, 0, 97, 96, 95,
|
|
|
|
0, 0, 0, 0, 0, 52, 50, 106, 0, 48,
|
|
|
|
0, 0, 0, 98, 0, 0, 103, 0, 0, 111,
|
|
|
|
0, 0, 108, 117, 0, 0, 30, 0, 4, 0,
|
2020-08-16 15:19:53 -06:00
|
|
|
19, 0, 21, 0, 0, 0, 26, 0, 14, 35,
|
|
|
|
0, 0, 0, 0, 53, 0, 0, 0, 0, 0,
|
|
|
|
0, 0, 51, 0, 0, 11, 0, 0, 12, 0,
|
2020-09-01 06:26:00 -06:00
|
|
|
0, 10, 0, 0, 13, 115, 0, 0, 9, 20,
|
|
|
|
22, 27, 28, 29, 24, 102, 17, 15, 16, 44,
|
|
|
|
45, 46, 47, 107, 18, 49, 0, 99, 0, 104,
|
|
|
|
0, 112, 0, 109, 0, 41, 0, 70, 0, 31,
|
|
|
|
0, 0, 0, 0, 0, 32, 127, 129, 128, 0,
|
|
|
|
123, 125, 0, 0, 64, 42, 0, 0, 0, 0,
|
|
|
|
0, 0, 0, 0, 0, 0, 71, 72, 76, 77,
|
|
|
|
78, 79, 75, 73, 74, 126, 0, 0, 0, 0,
|
|
|
|
0, 0, 0, 0, 0, 0, 0, 81, 82, 83,
|
|
|
|
84, 85, 86, 87, 88, 89, 90, 93, 94, 91,
|
|
|
|
92, 43, 124, 55, 54, 60, 59, 61, 62, 56,
|
|
|
|
57, 58,
|
2004-10-26 22:10:55 +00:00
|
|
|
};
|
2012-09-14 16:19:25 -04:00
|
|
|
const short sudoersdgoto[] =
|
2020-05-20 13:10:53 -06:00
|
|
|
{ 20,
|
2020-08-16 14:59:45 -06:00
|
|
|
146, 147, 35, 36, 56, 57, 58, 59, 43, 76,
|
2020-08-16 15:19:53 -06:00
|
|
|
45, 21, 22, 23, 161, 162, 163, 148, 153, 77,
|
2020-09-01 06:26:00 -06:00
|
|
|
78, 176, 155, 177, 178, 179, 180, 181, 182, 183,
|
|
|
|
184, 185, 24, 25, 60, 61, 26, 27, 30, 69,
|
|
|
|
63, 66, 72, 64, 67, 73, 70,
|
2004-10-26 22:10:55 +00:00
|
|
|
};
|
2012-09-14 16:19:25 -04:00
|
|
|
const short sudoerssindex[] =
|
2020-08-16 14:59:45 -06:00
|
|
|
{ -10,
|
2020-09-01 06:26:00 -06:00
|
|
|
48, 0, 0, 0, 0, -245, -233, -29, 38, 95,
|
|
|
|
95, -32, 0, -205, -197, -195, -191, -144, 0, 0,
|
2020-08-16 14:59:45 -06:00
|
|
|
0, 0, -22, 0, 0, -10, 0, 0, 0, 0,
|
2020-09-01 06:26:00 -06:00
|
|
|
6, 7, 32, -189, 0, 50, 0, 0, 0, 0,
|
|
|
|
0, -138, 0, -31, 0, -30, -30, 0, 0, 0,
|
|
|
|
-220, 15, 22, 27, 43, 0, 0, 0, -25, 0,
|
|
|
|
69, 35, 21, 0, 49, 24, 0, 55, 25, 0,
|
|
|
|
60, 26, 0, 0, 95, 8, 0, 29, 0, 48,
|
|
|
|
0, 48, 0, -157, -156, -155, 0, -29, 0, 0,
|
|
|
|
38, 50, 50, 50, 0, -153, -140, -135, -134, -32,
|
|
|
|
50, -168, 0, 38, -205, 0, -32, -197, 0, 95,
|
|
|
|
-195, 0, 95, -191, 0, 0, 86, 62, 0, 0,
|
2013-04-14 07:00:21 -04:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
2020-09-01 06:26:00 -06:00
|
|
|
0, 0, 0, 0, 0, 0, 88, 0, 96, 0,
|
|
|
|
97, 0, 97, 0, -18, 0, 99, 0, 48, 0,
|
|
|
|
-21, 42, 98, 86, -143, 0, 0, 0, 0, -214,
|
|
|
|
0, 0, 103, -21, 0, 0, 100, 101, 102, 104,
|
|
|
|
105, 106, 107, 108, 109, 59, 0, 0, 0, 0,
|
|
|
|
0, 0, 0, 0, 0, 0, -21, 103, -114, -104,
|
|
|
|
-103, -99, -92, -91, -90, -89, -88, 0, 0, 0,
|
2020-08-16 14:59:45 -06:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
2020-09-01 06:26:00 -06:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
|
|
|
0, 0,};
|
2012-09-14 16:19:25 -04:00
|
|
|
const short sudoersrindex[] =
|
2020-09-01 06:26:00 -06:00
|
|
|
{ 176,
|
2020-08-16 14:59:45 -06:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
2020-09-01 06:26:00 -06:00
|
|
|
0, 0, 0, 0, 0, 177, 0, 0, 0, 0,
|
|
|
|
0, 0, 54, 0, 0, 0, 0, 0, 0, 0,
|
2020-08-07 14:22:24 -06:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
2004-10-26 22:10:55 +00:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
2012-07-26 13:49:21 -04:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
2017-02-14 15:56:34 -07:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
2017-02-18 15:35:48 -07:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
2020-08-16 14:59:45 -06:00
|
|
|
0, 0, 0, 0, 0, 0, 9, 0, 0, 0,
|
2020-08-15 11:38:56 -06:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
2020-09-01 06:26:00 -06:00
|
|
|
0, 0, 0, 0, 0, 0, 33, 0, 41, 0,
|
|
|
|
45, 0, 46, 0, 137, 0, 47, 0, 0, 0,
|
|
|
|
138, 139, 0, 9, 94, 0, 0, 0, 0, 0,
|
|
|
|
0, 0, 140, 0, 0, 0, 0, 0, 0, 0,
|
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
|
|
|
0, 0, 0, 0, 0, 0, 0, 141, 0, 0,
|
2020-08-16 14:59:45 -06:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
2020-09-01 06:26:00 -06:00
|
|
|
0, 0,};
|
2012-09-14 16:19:25 -04:00
|
|
|
const short sudoersgindex[] =
|
2004-10-26 22:10:55 +00:00
|
|
|
{ 0,
|
2020-09-01 06:26:00 -06:00
|
|
|
30, 0, 110, 87, 132, 124, -95, 79, 145, 11,
|
|
|
|
111, 113, 171, -1, 3, 31, 28, 0, 0, 75,
|
2017-02-14 15:56:34 -07:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
2020-09-01 06:26:00 -06:00
|
|
|
0, 0, 0, 0, 92, 0, 0, 169, -4, 0,
|
|
|
|
0, 0, 0, 91, 89, 85, 90,
|
2004-10-26 22:10:55 +00:00
|
|
|
};
|
2020-09-01 06:26:00 -06:00
|
|
|
#define YYTABLESIZE 400
|
2012-09-14 16:19:25 -04:00
|
|
|
const short sudoerstable[] =
|
2020-08-16 14:59:45 -06:00
|
|
|
{ 19,
|
2020-09-01 06:26:00 -06:00
|
|
|
51, 34, 34, 34, 134, 28, 28, 34, 46, 47,
|
|
|
|
42, 160, 91, 75, 18, 29, 29, 31, 100, 44,
|
|
|
|
28, 75, 18, 28, 28, 28, 81, 83, 28, 32,
|
|
|
|
29, 89, 100, 29, 29, 29, 48, 49, 29, 151,
|
|
|
|
105, 63, 100, 157, 113, 110, 33, 28, 158, 28,
|
|
|
|
105, 91, 62, 25, 113, 110, 33, 29, 106, 29,
|
|
|
|
65, 109, 68, 25, 112, 50, 71, 115, 117, 87,
|
|
|
|
42, 159, 96, 119, 85, 120, 86, 121, 105, 97,
|
|
|
|
212, 108, 111, 114, 98, 75, 118, 127, 128, 129,
|
|
|
|
100, 51, 84, 88, 42, 104, 135, 25, 105, 164,
|
|
|
|
99, 51, 113, 110, 33, 122, 123, 124, 141, 107,
|
|
|
|
130, 143, 102, 2, 137, 110, 3, 4, 5, 37,
|
|
|
|
113, 38, 39, 131, 40, 145, 80, 18, 132, 133,
|
|
|
|
92, 91, 93, 94, 52, 53, 54, 55, 165, 100,
|
|
|
|
75, 13, 154, 152, 156, 101, 187, 41, 214, 167,
|
|
|
|
168, 169, 170, 171, 172, 173, 174, 175, 215, 216,
|
|
|
|
189, 190, 191, 217, 192, 193, 194, 195, 196, 197,
|
|
|
|
218, 219, 220, 221, 222, 1, 2, 65, 69, 66,
|
|
|
|
68, 67, 95, 166, 103, 139, 90, 116, 74, 213,
|
|
|
|
186, 188, 150, 136, 79, 138, 140, 125, 144, 0,
|
|
|
|
142, 126, 0, 0, 0, 0, 0, 0, 0, 0,
|
2020-08-10 13:59:31 -06:00
|
|
|
0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
2020-08-16 14:59:45 -06:00
|
|
|
0, 0, 0, 0, 48, 49, 0, 33, 33, 33,
|
2020-08-16 15:19:53 -06:00
|
|
|
0, 0, 0, 33, 0, 37, 157, 38, 39, 2,
|
|
|
|
40, 158, 3, 4, 5, 1, 0, 2, 0, 0,
|
2020-08-16 14:59:45 -06:00
|
|
|
3, 4, 5, 50, 6, 7, 8, 9, 10, 11,
|
2020-09-01 06:26:00 -06:00
|
|
|
12, 80, 82, 41, 159, 63, 63, 13, 0, 0,
|
|
|
|
52, 53, 54, 55, 0, 13, 14, 15, 16, 17,
|
|
|
|
63, 63, 63, 63, 63, 63, 63, 63, 63, 63,
|
|
|
|
63, 63, 63, 63, 63, 37, 0, 38, 39, 0,
|
|
|
|
40, 63, 63, 63, 63, 63, 63, 63, 63, 63,
|
|
|
|
0, 63, 63, 63, 63, 48, 49, 149, 0, 37,
|
|
|
|
0, 38, 39, 41, 40, 48, 49, 0, 0, 0,
|
|
|
|
198, 199, 200, 201, 202, 203, 204, 205, 206, 207,
|
|
|
|
208, 209, 210, 211, 50, 0, 0, 41, 0, 0,
|
|
|
|
80, 80, 2, 0, 50, 3, 4, 5, 0, 0,
|
|
|
|
0, 52, 53, 54, 55, 80, 80, 80, 80, 80,
|
|
|
|
80, 80, 80, 80, 80, 80, 80, 80, 80, 80,
|
|
|
|
13, 0, 0, 0, 0, 0, 0, 0, 0, 0,
|
|
|
|
0, 0, 0, 0, 0, 0, 80, 80, 80, 80,
|
2004-10-26 22:10:55 +00:00
|
|
|
};
|
2012-09-14 16:19:25 -04:00
|
|
|
const short sudoerscheck[] =
|
2020-08-16 14:59:45 -06:00
|
|
|
{ 10,
|
2020-09-01 06:26:00 -06:00
|
|
|
33, 33, 33, 33, 100, 0, 0, 33, 10, 11,
|
|
|
|
33, 33, 44, 44, 33, 10, 10, 263, 44, 9,
|
|
|
|
0, 44, 33, 0, 0, 0, 31, 32, 0, 263,
|
|
|
|
10, 36, 0, 10, 10, 10, 257, 258, 10, 58,
|
|
|
|
0, 33, 10, 258, 0, 0, 0, 0, 263, 0,
|
|
|
|
10, 44, 258, 0, 10, 10, 10, 10, 63, 10,
|
|
|
|
258, 66, 258, 10, 69, 286, 258, 72, 61, 259,
|
|
|
|
33, 286, 58, 78, 43, 80, 45, 82, 58, 58,
|
|
|
|
176, 58, 58, 58, 58, 44, 58, 92, 93, 94,
|
|
|
|
58, 33, 61, 44, 33, 61, 101, 44, 58, 58,
|
|
|
|
58, 33, 58, 58, 58, 263, 263, 263, 110, 61,
|
|
|
|
264, 113, 44, 258, 104, 61, 261, 262, 263, 258,
|
|
|
|
61, 260, 261, 264, 263, 40, 33, 33, 264, 264,
|
|
|
|
44, 44, 46, 47, 303, 304, 305, 306, 41, 44,
|
|
|
|
44, 286, 44, 145, 149, 59, 44, 286, 263, 293,
|
|
|
|
294, 295, 296, 297, 298, 299, 300, 301, 263, 263,
|
|
|
|
61, 61, 61, 263, 61, 61, 61, 61, 61, 61,
|
|
|
|
263, 263, 263, 263, 263, 0, 0, 41, 41, 41,
|
|
|
|
41, 41, 51, 154, 61, 107, 42, 75, 18, 187,
|
|
|
|
160, 164, 118, 102, 26, 105, 108, 88, 114, -1,
|
|
|
|
111, 91, -1, -1, -1, -1, -1, -1, -1, -1,
|
2020-05-20 13:10:53 -06:00
|
|
|
-1, -1, -1, -1, -1, -1, -1, -1, -1, -1,
|
2020-08-16 14:59:45 -06:00
|
|
|
-1, -1, -1, -1, 257, 258, -1, 259, 259, 259,
|
|
|
|
-1, -1, -1, 259, -1, 258, 258, 260, 261, 258,
|
|
|
|
263, 263, 261, 262, 263, 256, -1, 258, -1, -1,
|
|
|
|
261, 262, 263, 286, 265, 266, 267, 268, 269, 270,
|
2020-09-01 06:26:00 -06:00
|
|
|
271, 256, 256, 286, 286, 257, 258, 286, -1, -1,
|
|
|
|
303, 304, 305, 306, -1, 286, 287, 288, 289, 290,
|
2020-08-16 14:59:45 -06:00
|
|
|
272, 273, 274, 275, 276, 277, 278, 279, 280, 281,
|
2020-09-01 06:26:00 -06:00
|
|
|
282, 283, 284, 285, 286, 258, -1, 260, 261, -1,
|
|
|
|
263, 293, 294, 295, 296, 297, 298, 299, 300, 301,
|
|
|
|
-1, 303, 304, 305, 306, 257, 258, 256, -1, 258,
|
|
|
|
-1, 260, 261, 286, 263, 257, 258, -1, -1, -1,
|
|
|
|
272, 273, 274, 275, 276, 277, 278, 279, 280, 281,
|
|
|
|
282, 283, 284, 285, 286, -1, -1, 286, -1, -1,
|
|
|
|
257, 258, 258, -1, 286, 261, 262, 263, -1, -1,
|
|
|
|
-1, 303, 304, 305, 306, 272, 273, 274, 275, 276,
|
|
|
|
277, 278, 279, 280, 281, 282, 283, 284, 285, 286,
|
|
|
|
286, -1, -1, -1, -1, -1, -1, -1, -1, -1,
|
|
|
|
-1, -1, -1, -1, -1, -1, 303, 304, 305, 306,
|
2004-10-26 22:10:55 +00:00
|
|
|
};
|
2020-05-20 13:10:53 -06:00
|
|
|
#define YYFINAL 20
|
2004-10-26 22:10:55 +00:00
|
|
|
#ifndef YYDEBUG
|
|
|
|
#define YYDEBUG 0
|
|
|
|
#endif
|
2020-09-01 06:26:00 -06:00
|
|
|
#define YYMAXTOKEN 306
|
2004-10-26 22:10:55 +00:00
|
|
|
#if YYDEBUG
|
2012-09-14 16:19:25 -04:00
|
|
|
const char * const sudoersname[] =
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-08-10 13:59:31 -06:00
|
|
|
"end-of-file",0,0,0,0,0,0,0,0,0,"'\\n'",0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
|
|
|
|
0,0,"'!'",0,0,0,0,0,0,"'('","')'",0,"'+'","','","'-'",0,0,0,0,0,0,0,0,0,0,0,0,
|
|
|
|
"':'",0,0,"'='",0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
|
2007-08-22 22:39:20 +00:00
|
|
|
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
|
2004-10-26 22:10:55 +00:00
|
|
|
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
|
|
|
|
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
|
|
|
|
0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,
|
2020-08-10 13:59:31 -06:00
|
|
|
0,0,0,"COMMAND","ALIAS","DEFVAR","NTWKADDR","NETGROUP","USERGROUP","WORD",
|
|
|
|
"DIGEST","INCLUDE","INCLUDEDIR","DEFAULTS","DEFAULTS_HOST","DEFAULTS_USER",
|
2020-05-20 13:10:53 -06:00
|
|
|
"DEFAULTS_RUNAS","DEFAULTS_CMND","NOPASSWD","PASSWD","NOEXEC","EXEC","SETENV",
|
|
|
|
"NOSETENV","LOG_INPUT","NOLOG_INPUT","LOG_OUTPUT","NOLOG_OUTPUT","MAIL",
|
2020-08-10 13:59:31 -06:00
|
|
|
"NOMAIL","FOLLOWLNK","NOFOLLOWLNK","ALL","HOSTALIAS","CMNDALIAS","USERALIAS",
|
2020-09-01 06:26:00 -06:00
|
|
|
"RUNASALIAS","ERROR","NOMATCH","CHROOT","CWD","TYPE","ROLE","PRIVS",
|
|
|
|
"LIMITPRIVS","CMND_TIMEOUT","NOTBEFORE","NOTAFTER","MYSELF","SHA224_TOK",
|
|
|
|
"SHA256_TOK","SHA384_TOK","SHA512_TOK",
|
2004-10-26 22:10:55 +00:00
|
|
|
};
|
2012-09-14 16:19:25 -04:00
|
|
|
const char * const sudoersrule[] =
|
2004-10-26 22:10:55 +00:00
|
|
|
{"$accept : file",
|
|
|
|
"file :",
|
|
|
|
"file : line",
|
|
|
|
"line : entry",
|
|
|
|
"line : line entry",
|
2020-08-10 13:59:31 -06:00
|
|
|
"entry : '\\n'",
|
2020-08-16 14:59:45 -06:00
|
|
|
"entry : error eol",
|
2020-08-07 14:22:24 -06:00
|
|
|
"entry : include",
|
|
|
|
"entry : includedir",
|
2020-08-16 14:59:45 -06:00
|
|
|
"entry : userlist privileges eol",
|
|
|
|
"entry : USERALIAS useraliases eol",
|
|
|
|
"entry : HOSTALIAS hostaliases eol",
|
|
|
|
"entry : CMNDALIAS cmndaliases eol",
|
|
|
|
"entry : RUNASALIAS runasaliases eol",
|
|
|
|
"entry : DEFAULTS defaults_list eol",
|
|
|
|
"entry : DEFAULTS_USER userlist defaults_list eol",
|
|
|
|
"entry : DEFAULTS_RUNAS userlist defaults_list eol",
|
|
|
|
"entry : DEFAULTS_HOST hostlist defaults_list eol",
|
|
|
|
"entry : DEFAULTS_CMND cmndlist defaults_list eol",
|
|
|
|
"include : INCLUDE WORD eol",
|
|
|
|
"include : INCLUDE WORD error eol",
|
|
|
|
"includedir : INCLUDEDIR WORD eol",
|
|
|
|
"includedir : INCLUDEDIR WORD error eol",
|
2004-10-26 22:10:55 +00:00
|
|
|
"defaults_list : defaults_entry",
|
|
|
|
"defaults_list : defaults_list ',' defaults_entry",
|
|
|
|
"defaults_entry : DEFVAR",
|
|
|
|
"defaults_entry : '!' DEFVAR",
|
|
|
|
"defaults_entry : DEFVAR '=' WORD",
|
|
|
|
"defaults_entry : DEFVAR '+' WORD",
|
|
|
|
"defaults_entry : DEFVAR '-' WORD",
|
|
|
|
"privileges : privilege",
|
|
|
|
"privileges : privileges ':' privilege",
|
2020-08-16 15:19:53 -06:00
|
|
|
"privileges : privileges ':' error eol",
|
2004-10-26 22:10:55 +00:00
|
|
|
"privilege : hostlist '=' cmndspeclist",
|
|
|
|
"ophost : host",
|
|
|
|
"ophost : '!' host",
|
|
|
|
"host : ALIAS",
|
|
|
|
"host : ALL",
|
|
|
|
"host : NETGROUP",
|
|
|
|
"host : NTWKADDR",
|
|
|
|
"host : WORD",
|
|
|
|
"cmndspeclist : cmndspec",
|
|
|
|
"cmndspeclist : cmndspeclist ',' cmndspec",
|
2017-02-14 15:56:34 -07:00
|
|
|
"cmndspec : runasspec options cmndtag digcmnd",
|
2020-03-11 11:17:52 -06:00
|
|
|
"digestspec : SHA224_TOK ':' DIGEST",
|
|
|
|
"digestspec : SHA256_TOK ':' DIGEST",
|
|
|
|
"digestspec : SHA384_TOK ':' DIGEST",
|
|
|
|
"digestspec : SHA512_TOK ':' DIGEST",
|
|
|
|
"digestlist : digestspec",
|
|
|
|
"digestlist : digestlist ',' digestspec",
|
2013-04-14 07:00:21 -04:00
|
|
|
"digcmnd : opcmnd",
|
2020-03-11 11:17:52 -06:00
|
|
|
"digcmnd : digestlist opcmnd",
|
2004-10-26 22:10:55 +00:00
|
|
|
"opcmnd : cmnd",
|
|
|
|
"opcmnd : '!' cmnd",
|
2020-09-01 06:26:00 -06:00
|
|
|
"chdirspec : CWD '=' WORD",
|
|
|
|
"chrootspec : CHROOT '=' WORD",
|
2017-02-14 15:56:34 -07:00
|
|
|
"timeoutspec : CMND_TIMEOUT '=' WORD",
|
2017-02-18 15:35:48 -07:00
|
|
|
"notbeforespec : NOTBEFORE '=' WORD",
|
|
|
|
"notafterspec : NOTAFTER '=' WORD",
|
2008-02-09 14:30:06 +00:00
|
|
|
"rolespec : ROLE '=' WORD",
|
|
|
|
"typespec : TYPE '=' WORD",
|
2012-07-26 13:49:21 -04:00
|
|
|
"privsspec : PRIVS '=' WORD",
|
|
|
|
"limitprivsspec : LIMITPRIVS '=' WORD",
|
2004-10-26 22:10:55 +00:00
|
|
|
"runasspec :",
|
2007-08-22 22:39:20 +00:00
|
|
|
"runasspec : '(' runaslist ')'",
|
2012-08-02 14:02:54 -04:00
|
|
|
"runaslist :",
|
2007-11-21 20:12:00 +00:00
|
|
|
"runaslist : userlist",
|
|
|
|
"runaslist : userlist ':' grouplist",
|
|
|
|
"runaslist : ':' grouplist",
|
2012-08-02 14:02:54 -04:00
|
|
|
"runaslist : ':'",
|
2017-02-14 15:56:34 -07:00
|
|
|
"options :",
|
2020-09-01 06:26:00 -06:00
|
|
|
"options : options chdirspec",
|
|
|
|
"options : options chrootspec",
|
2017-02-18 15:35:48 -07:00
|
|
|
"options : options notbeforespec",
|
|
|
|
"options : options notafterspec",
|
2017-02-14 15:56:34 -07:00
|
|
|
"options : options timeoutspec",
|
2017-02-14 15:56:34 -07:00
|
|
|
"options : options rolespec",
|
|
|
|
"options : options typespec",
|
|
|
|
"options : options privsspec",
|
|
|
|
"options : options limitprivsspec",
|
2017-02-14 15:56:34 -07:00
|
|
|
"cmndtag :",
|
|
|
|
"cmndtag : cmndtag NOPASSWD",
|
|
|
|
"cmndtag : cmndtag PASSWD",
|
|
|
|
"cmndtag : cmndtag NOEXEC",
|
|
|
|
"cmndtag : cmndtag EXEC",
|
|
|
|
"cmndtag : cmndtag SETENV",
|
|
|
|
"cmndtag : cmndtag NOSETENV",
|
|
|
|
"cmndtag : cmndtag LOG_INPUT",
|
|
|
|
"cmndtag : cmndtag NOLOG_INPUT",
|
|
|
|
"cmndtag : cmndtag LOG_OUTPUT",
|
|
|
|
"cmndtag : cmndtag NOLOG_OUTPUT",
|
2019-02-12 12:02:02 -07:00
|
|
|
"cmndtag : cmndtag FOLLOWLNK",
|
|
|
|
"cmndtag : cmndtag NOFOLLOWLNK",
|
2017-02-14 15:56:34 -07:00
|
|
|
"cmndtag : cmndtag MAIL",
|
|
|
|
"cmndtag : cmndtag NOMAIL",
|
2004-10-26 22:10:55 +00:00
|
|
|
"cmnd : ALL",
|
|
|
|
"cmnd : ALIAS",
|
|
|
|
"cmnd : COMMAND",
|
|
|
|
"hostaliases : hostalias",
|
|
|
|
"hostaliases : hostaliases ':' hostalias",
|
|
|
|
"hostalias : ALIAS '=' hostlist",
|
|
|
|
"hostlist : ophost",
|
|
|
|
"hostlist : hostlist ',' ophost",
|
|
|
|
"cmndaliases : cmndalias",
|
|
|
|
"cmndaliases : cmndaliases ':' cmndalias",
|
|
|
|
"cmndalias : ALIAS '=' cmndlist",
|
2013-04-14 07:00:21 -04:00
|
|
|
"cmndlist : digcmnd",
|
|
|
|
"cmndlist : cmndlist ',' digcmnd",
|
2004-10-26 22:10:55 +00:00
|
|
|
"runasaliases : runasalias",
|
|
|
|
"runasaliases : runasaliases ':' runasalias",
|
2007-11-21 20:12:00 +00:00
|
|
|
"runasalias : ALIAS '=' userlist",
|
2004-10-26 22:10:55 +00:00
|
|
|
"useraliases : useralias",
|
|
|
|
"useraliases : useraliases ':' useralias",
|
|
|
|
"useralias : ALIAS '=' userlist",
|
|
|
|
"userlist : opuser",
|
|
|
|
"userlist : userlist ',' opuser",
|
|
|
|
"opuser : user",
|
|
|
|
"opuser : '!' user",
|
|
|
|
"user : ALIAS",
|
|
|
|
"user : ALL",
|
|
|
|
"user : NETGROUP",
|
|
|
|
"user : USERGROUP",
|
|
|
|
"user : WORD",
|
2007-11-21 20:12:00 +00:00
|
|
|
"grouplist : opgroup",
|
|
|
|
"grouplist : grouplist ',' opgroup",
|
|
|
|
"opgroup : group",
|
|
|
|
"opgroup : '!' group",
|
|
|
|
"group : ALIAS",
|
|
|
|
"group : ALL",
|
|
|
|
"group : WORD",
|
2020-08-16 14:59:45 -06:00
|
|
|
"eol : '\\n'",
|
|
|
|
"eol : END",
|
2004-10-26 22:10:55 +00:00
|
|
|
};
|
|
|
|
#endif
|
|
|
|
#ifdef YYSTACKSIZE
|
|
|
|
#undef YYMAXDEPTH
|
|
|
|
#define YYMAXDEPTH YYSTACKSIZE
|
|
|
|
#else
|
|
|
|
#ifdef YYMAXDEPTH
|
|
|
|
#define YYSTACKSIZE YYMAXDEPTH
|
|
|
|
#else
|
|
|
|
#define YYSTACKSIZE 10000
|
|
|
|
#define YYMAXDEPTH 10000
|
|
|
|
#endif
|
|
|
|
#endif
|
|
|
|
#define YYINITSTACKSIZE 200
|
2007-06-23 23:58:54 +00:00
|
|
|
/* LINTUSED */
|
2004-10-26 22:10:55 +00:00
|
|
|
int yydebug;
|
|
|
|
int yynerrs;
|
|
|
|
int yyerrflag;
|
|
|
|
int yychar;
|
|
|
|
short *yyssp;
|
|
|
|
YYSTYPE *yyvsp;
|
|
|
|
YYSTYPE yyval;
|
|
|
|
YYSTYPE yylval;
|
|
|
|
short *yyss;
|
|
|
|
short *yysslim;
|
|
|
|
YYSTYPE *yyvs;
|
2013-10-30 14:27:50 -06:00
|
|
|
unsigned int yystacksize;
|
2016-09-08 16:38:08 -06:00
|
|
|
int yyparse(void);
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 1018 "gram.y"
|
2013-03-31 09:58:37 -04:00
|
|
|
void
|
|
|
|
sudoerserror(const char *s)
|
|
|
|
{
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(sudoerserror, SUDOERS_DEBUG_PARSER);
|
2013-03-31 09:58:37 -04:00
|
|
|
|
2020-08-16 06:42:15 -06:00
|
|
|
/* The lexer displays more detailed messages for ERROR tokens. */
|
|
|
|
if (last_token == ERROR)
|
2020-08-07 14:20:45 -06:00
|
|
|
debug_return;
|
|
|
|
|
2013-03-31 09:58:37 -04:00
|
|
|
/* Save the line the first error occurred on. */
|
|
|
|
if (errorlineno == -1) {
|
2016-11-12 19:22:32 -07:00
|
|
|
errorlineno = this_lineno;
|
2016-11-11 16:18:27 -07:00
|
|
|
rcstr_delref(errorfile);
|
|
|
|
errorfile = rcstr_addref(sudoers);
|
2013-03-31 09:58:37 -04:00
|
|
|
}
|
|
|
|
if (sudoers_warnings && s != NULL) {
|
|
|
|
LEXTRACE("<*> ");
|
|
|
|
#ifndef TRACELEXER
|
|
|
|
if (trace_print == NULL || trace_print == sudoers_trace_print) {
|
|
|
|
int oldlocale;
|
|
|
|
|
|
|
|
/* Warnings are displayed in the user's locale. */
|
|
|
|
sudoers_setlocale(SUDOERS_LOCALE_USER, &oldlocale);
|
2020-08-07 14:20:45 -06:00
|
|
|
sudo_printf(SUDO_CONV_ERROR_MSG, _("%s:%d: %s\n"), sudoers,
|
|
|
|
this_lineno, _(s));
|
2013-03-31 09:58:37 -04:00
|
|
|
sudoers_setlocale(oldlocale, NULL);
|
2020-08-06 21:16:35 -06:00
|
|
|
|
2020-08-07 14:13:25 -06:00
|
|
|
/* Display the offending line and token if possible. */
|
2020-08-06 21:16:35 -06:00
|
|
|
if (sudolinebuf.len != 0) {
|
2020-08-07 14:13:25 -06:00
|
|
|
char tildes[128];
|
|
|
|
size_t tlen = 0;
|
|
|
|
|
2020-08-06 21:16:35 -06:00
|
|
|
sudo_printf(SUDO_CONV_ERROR_MSG, "%s%s", sudolinebuf.buf,
|
|
|
|
sudolinebuf.buf[sudolinebuf.len - 1] == '\n' ? "" : "\n");
|
2020-08-07 14:13:25 -06:00
|
|
|
if (sudolinebuf.toke_end > sudolinebuf.toke_start) {
|
|
|
|
tlen = sudolinebuf.toke_end - sudolinebuf.toke_start - 1;
|
|
|
|
if (tlen >= sizeof(tildes))
|
|
|
|
tlen = sizeof(tildes) - 1;
|
|
|
|
memset(tildes, '~', tlen);
|
|
|
|
}
|
|
|
|
tildes[tlen] = '\0';
|
|
|
|
sudo_printf(SUDO_CONV_ERROR_MSG, "%*s^%s\n",
|
|
|
|
(int)sudolinebuf.toke_start, "", tildes);
|
2020-08-06 21:16:35 -06:00
|
|
|
}
|
2013-03-31 09:58:37 -04:00
|
|
|
}
|
|
|
|
#endif
|
|
|
|
}
|
|
|
|
parse_error = true;
|
|
|
|
debug_return;
|
|
|
|
}
|
|
|
|
|
2007-08-31 23:14:37 +00:00
|
|
|
static struct defaults *
|
2016-11-09 16:00:12 -07:00
|
|
|
new_default(char *var, char *val, short op)
|
2007-08-31 23:14:37 +00:00
|
|
|
{
|
|
|
|
struct defaults *d;
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(new_default, SUDOERS_DEBUG_PARSER);
|
2007-08-31 23:14:37 +00:00
|
|
|
|
2015-07-14 15:28:01 -06:00
|
|
|
if ((d = calloc(1, sizeof(struct defaults))) == NULL) {
|
|
|
|
sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
|
|
|
|
"unable to allocate memory");
|
|
|
|
debug_return_ptr(NULL);
|
2015-05-27 10:36:03 -06:00
|
|
|
}
|
2007-08-31 23:14:37 +00:00
|
|
|
|
2015-07-14 15:28:01 -06:00
|
|
|
d->var = var;
|
|
|
|
d->val = val;
|
|
|
|
/* d->type = 0; */
|
|
|
|
d->op = op;
|
|
|
|
/* d->binding = NULL */
|
2016-11-12 19:22:32 -07:00
|
|
|
d->lineno = this_lineno;
|
2016-11-11 16:18:27 -07:00
|
|
|
d->file = rcstr_addref(sudoers);
|
2015-07-14 15:28:01 -06:00
|
|
|
HLTQ_INIT(d, entries);
|
|
|
|
|
2011-10-22 14:40:21 -04:00
|
|
|
debug_return_ptr(d);
|
2007-08-31 23:14:37 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
static struct member *
|
2011-01-08 15:15:30 -05:00
|
|
|
new_member(char *name, int type)
|
2007-08-31 23:14:37 +00:00
|
|
|
{
|
|
|
|
struct member *m;
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(new_member, SUDOERS_DEBUG_PARSER);
|
2007-08-31 23:14:37 +00:00
|
|
|
|
2015-07-14 15:28:01 -06:00
|
|
|
if ((m = calloc(1, sizeof(struct member))) == NULL) {
|
|
|
|
sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
|
|
|
|
"unable to allocate memory");
|
|
|
|
debug_return_ptr(NULL);
|
2015-05-27 10:36:03 -06:00
|
|
|
}
|
2007-08-31 23:14:37 +00:00
|
|
|
|
2015-07-14 15:28:01 -06:00
|
|
|
m->name = name;
|
|
|
|
m->type = type;
|
|
|
|
HLTQ_INIT(m, entries);
|
|
|
|
|
2011-10-22 14:40:21 -04:00
|
|
|
debug_return_ptr(m);
|
2007-08-31 23:14:37 +00:00
|
|
|
}
|
2020-08-10 13:59:31 -06:00
|
|
|
|
2020-03-11 11:19:37 -06:00
|
|
|
static struct sudo_command *
|
|
|
|
new_command(char *cmnd, char *args)
|
|
|
|
{
|
|
|
|
struct sudo_command *c;
|
|
|
|
debug_decl(new_command, SUDOERS_DEBUG_PARSER);
|
|
|
|
|
|
|
|
if ((c = calloc(1, sizeof(*c))) == NULL) {
|
|
|
|
sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
|
|
|
|
"unable to allocate memory");
|
|
|
|
debug_return_ptr(NULL);
|
|
|
|
}
|
|
|
|
|
|
|
|
c->cmnd = cmnd;
|
|
|
|
c->args = args;
|
|
|
|
TAILQ_INIT(&c->digests);
|
|
|
|
|
|
|
|
debug_return_ptr(c);
|
|
|
|
}
|
2007-08-31 23:14:37 +00:00
|
|
|
|
2018-05-24 21:04:07 -06:00
|
|
|
static struct command_digest *
|
2017-02-14 15:56:34 -07:00
|
|
|
new_digest(int digest_type, char *digest_str)
|
2013-04-14 07:00:21 -04:00
|
|
|
{
|
2018-05-24 21:04:07 -06:00
|
|
|
struct command_digest *digest;
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(new_digest, SUDOERS_DEBUG_PARSER);
|
2013-04-14 07:00:21 -04:00
|
|
|
|
2018-05-24 21:04:07 -06:00
|
|
|
if ((digest = malloc(sizeof(*digest))) == NULL) {
|
2015-07-14 15:28:01 -06:00
|
|
|
sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
|
|
|
|
"unable to allocate memory");
|
|
|
|
debug_return_ptr(NULL);
|
|
|
|
}
|
|
|
|
|
2020-03-11 11:17:52 -06:00
|
|
|
HLTQ_INIT(digest, entries);
|
2018-05-24 21:04:07 -06:00
|
|
|
digest->digest_type = digest_type;
|
|
|
|
digest->digest_str = digest_str;
|
|
|
|
if (digest->digest_str == NULL) {
|
2015-07-14 15:28:01 -06:00
|
|
|
sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
|
|
|
|
"unable to allocate memory");
|
2018-05-24 21:04:07 -06:00
|
|
|
free(digest);
|
|
|
|
digest = NULL;
|
2015-05-27 10:36:03 -06:00
|
|
|
}
|
2013-04-14 07:00:21 -04:00
|
|
|
|
2018-05-24 21:04:07 -06:00
|
|
|
debug_return_ptr(digest);
|
2013-04-14 07:00:21 -04:00
|
|
|
}
|
|
|
|
|
2004-10-26 22:10:55 +00:00
|
|
|
/*
|
|
|
|
* Add a list of defaults structures to the defaults list.
|
|
|
|
* The binding, if non-NULL, specifies a list of hosts, users, or
|
|
|
|
* runas users the entries apply to (specified by the type).
|
|
|
|
*/
|
2015-05-27 10:36:03 -06:00
|
|
|
static bool
|
2011-01-08 15:15:30 -05:00
|
|
|
add_defaults(int type, struct member *bmem, struct defaults *defs)
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2016-11-01 14:22:32 -06:00
|
|
|
struct defaults *d, *next;
|
2013-10-22 09:08:38 -06:00
|
|
|
struct member_list *binding;
|
2016-11-01 14:22:32 -06:00
|
|
|
bool ret = true;
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(add_defaults, SUDOERS_DEBUG_PARSER);
|
2008-03-05 20:19:50 +00:00
|
|
|
|
2013-10-22 14:58:00 -06:00
|
|
|
if (defs != NULL) {
|
|
|
|
/*
|
|
|
|
* We use a single binding for each entry in defs.
|
|
|
|
*/
|
2015-07-14 15:28:01 -06:00
|
|
|
if ((binding = malloc(sizeof(*binding))) == NULL) {
|
|
|
|
sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
|
|
|
|
"unable to allocate memory");
|
2016-11-01 14:13:47 -06:00
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
2015-05-27 10:36:03 -06:00
|
|
|
debug_return_bool(false);
|
2015-07-14 15:28:01 -06:00
|
|
|
}
|
2013-10-22 14:58:00 -06:00
|
|
|
if (bmem != NULL)
|
|
|
|
HLTQ_TO_TAILQ(binding, bmem, entries);
|
|
|
|
else
|
|
|
|
TAILQ_INIT(binding);
|
2004-10-26 22:10:55 +00:00
|
|
|
|
2013-10-22 14:58:00 -06:00
|
|
|
/*
|
|
|
|
* Set type and binding (who it applies to) for new entries.
|
2016-11-09 16:00:12 -07:00
|
|
|
* Then add to the global defaults list.
|
2013-10-22 14:58:00 -06:00
|
|
|
*/
|
2016-11-01 14:22:32 -06:00
|
|
|
HLTQ_FOREACH_SAFE(d, defs, entries, next) {
|
2016-11-09 16:00:12 -07:00
|
|
|
d->type = type;
|
|
|
|
d->binding = binding;
|
2018-07-26 15:12:33 -06:00
|
|
|
TAILQ_INSERT_TAIL(&parsed_policy.defaults, d, entries);
|
2013-10-22 14:58:00 -06:00
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
2011-10-22 14:40:21 -04:00
|
|
|
|
2016-11-01 14:22:32 -06:00
|
|
|
debug_return_bool(ret);
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Allocate a new struct userspec, populate it, and insert it at the
|
2013-10-22 09:08:38 -06:00
|
|
|
* end of the userspecs list.
|
2004-10-26 22:10:55 +00:00
|
|
|
*/
|
2015-05-27 10:36:03 -06:00
|
|
|
static bool
|
2011-01-08 15:15:30 -05:00
|
|
|
add_userspec(struct member *members, struct privilege *privs)
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
|
|
|
struct userspec *u;
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(add_userspec, SUDOERS_DEBUG_PARSER);
|
2004-10-26 22:10:55 +00:00
|
|
|
|
2015-07-14 15:28:01 -06:00
|
|
|
if ((u = calloc(1, sizeof(*u))) == NULL) {
|
|
|
|
sudo_debug_printf(SUDO_DEBUG_ERROR|SUDO_DEBUG_LINENO,
|
|
|
|
"unable to allocate memory");
|
2015-05-27 10:36:03 -06:00
|
|
|
debug_return_bool(false);
|
2015-07-14 15:28:01 -06:00
|
|
|
}
|
2016-11-12 19:22:32 -07:00
|
|
|
u->lineno = this_lineno;
|
|
|
|
u->file = rcstr_addref(sudoers);
|
2013-10-22 09:08:38 -06:00
|
|
|
HLTQ_TO_TAILQ(&u->users, members, entries);
|
|
|
|
HLTQ_TO_TAILQ(&u->privileges, privs, entries);
|
2018-03-04 07:03:43 -07:00
|
|
|
STAILQ_INIT(&u->comments);
|
2018-07-26 15:12:33 -06:00
|
|
|
TAILQ_INSERT_TAIL(&parsed_policy.userspecs, u, entries);
|
2011-10-22 14:40:21 -04:00
|
|
|
|
2015-05-27 10:36:03 -06:00
|
|
|
debug_return_bool(true);
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
|
2018-02-05 13:33:29 -07:00
|
|
|
/*
|
|
|
|
* Free a member struct and its contents.
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
free_member(struct member *m)
|
|
|
|
{
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(free_member, SUDOERS_DEBUG_PARSER);
|
2018-03-21 12:11:19 -06:00
|
|
|
|
2020-03-11 11:19:37 -06:00
|
|
|
if (m->type == COMMAND || (m->type == ALL && m->name != NULL)) {
|
2020-03-11 11:17:52 -06:00
|
|
|
struct command_digest *digest;
|
|
|
|
struct sudo_command *c = (struct sudo_command *)m->name;
|
|
|
|
free(c->cmnd);
|
|
|
|
free(c->args);
|
|
|
|
while ((digest = TAILQ_FIRST(&c->digests)) != NULL) {
|
|
|
|
TAILQ_REMOVE(&c->digests, digest, entries);
|
|
|
|
free(digest->digest_str);
|
|
|
|
free(digest);
|
|
|
|
}
|
2018-02-05 13:33:29 -07:00
|
|
|
}
|
|
|
|
free(m->name);
|
|
|
|
free(m);
|
2018-03-21 12:11:19 -06:00
|
|
|
|
|
|
|
debug_return;
|
2018-02-05 13:33:29 -07:00
|
|
|
}
|
|
|
|
|
2016-11-01 14:15:07 -06:00
|
|
|
/*
|
|
|
|
* Free a tailq of members but not the struct member_list container itself.
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
free_members(struct member_list *members)
|
|
|
|
{
|
2018-02-05 13:33:29 -07:00
|
|
|
struct member *m;
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(free_members, SUDOERS_DEBUG_PARSER);
|
2016-11-01 14:15:07 -06:00
|
|
|
|
2018-02-05 13:33:29 -07:00
|
|
|
while ((m = TAILQ_FIRST(members)) != NULL) {
|
|
|
|
TAILQ_REMOVE(members, m, entries);
|
|
|
|
free_member(m);
|
2016-11-01 14:15:07 -06:00
|
|
|
}
|
2018-03-21 12:11:19 -06:00
|
|
|
|
|
|
|
debug_return;
|
|
|
|
}
|
|
|
|
|
2018-05-15 16:35:07 -06:00
|
|
|
void
|
|
|
|
free_defaults(struct defaults_list *defs)
|
|
|
|
{
|
|
|
|
struct member_list *prev_binding = NULL;
|
|
|
|
struct defaults *def;
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(free_defaults, SUDOERS_DEBUG_PARSER);
|
2018-05-15 16:35:07 -06:00
|
|
|
|
|
|
|
while ((def = TAILQ_FIRST(defs)) != NULL) {
|
|
|
|
TAILQ_REMOVE(defs, def, entries);
|
|
|
|
free_default(def, &prev_binding);
|
|
|
|
}
|
|
|
|
|
|
|
|
debug_return;
|
|
|
|
}
|
|
|
|
|
2018-03-21 14:55:17 -06:00
|
|
|
void
|
|
|
|
free_default(struct defaults *def, struct member_list **binding)
|
2018-03-21 12:11:19 -06:00
|
|
|
{
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(free_default, SUDOERS_DEBUG_PARSER);
|
2018-03-21 12:11:19 -06:00
|
|
|
|
2018-03-21 14:55:17 -06:00
|
|
|
if (def->binding != *binding) {
|
|
|
|
*binding = def->binding;
|
2018-04-13 10:49:05 -06:00
|
|
|
if (def->binding != NULL) {
|
|
|
|
free_members(def->binding);
|
|
|
|
free(def->binding);
|
|
|
|
}
|
2018-03-21 12:11:19 -06:00
|
|
|
}
|
|
|
|
rcstr_delref(def->file);
|
|
|
|
free(def->var);
|
|
|
|
free(def->val);
|
|
|
|
free(def);
|
|
|
|
|
2018-03-21 14:55:17 -06:00
|
|
|
debug_return;
|
2016-11-01 14:15:07 -06:00
|
|
|
}
|
|
|
|
|
2018-02-05 13:33:29 -07:00
|
|
|
void
|
2018-02-09 18:21:40 -07:00
|
|
|
free_privilege(struct privilege *priv)
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2018-02-09 18:21:40 -07:00
|
|
|
struct member_list *runasuserlist = NULL, *runasgrouplist = NULL;
|
2018-03-21 14:55:17 -06:00
|
|
|
struct member_list *prev_binding = NULL;
|
2018-02-09 18:21:40 -07:00
|
|
|
struct cmndspec *cs;
|
|
|
|
struct defaults *def;
|
2020-09-01 06:26:00 -06:00
|
|
|
char *runcwd = NULL, *runchroot = NULL;
|
2008-02-09 14:30:06 +00:00
|
|
|
#ifdef HAVE_SELINUX
|
2018-02-09 18:21:40 -07:00
|
|
|
char *role = NULL, *type = NULL;
|
2008-02-09 14:30:06 +00:00
|
|
|
#endif /* HAVE_SELINUX */
|
2012-07-26 13:49:21 -04:00
|
|
|
#ifdef HAVE_PRIV_SET
|
2018-02-09 18:21:40 -07:00
|
|
|
char *privs = NULL, *limitprivs = NULL;
|
2012-07-26 13:49:21 -04:00
|
|
|
#endif /* HAVE_PRIV_SET */
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(free_privilege, SUDOERS_DEBUG_PARSER);
|
2007-11-21 20:12:00 +00:00
|
|
|
|
2018-02-09 18:21:40 -07:00
|
|
|
free(priv->ldap_role);
|
|
|
|
free_members(&priv->hostlist);
|
|
|
|
while ((cs = TAILQ_FIRST(&priv->cmndlist)) != NULL) {
|
|
|
|
TAILQ_REMOVE(&priv->cmndlist, cs, entries);
|
2020-09-01 06:26:00 -06:00
|
|
|
/* Only free the first instance of runcwd/runchroot. */
|
|
|
|
if (cs->runcwd != runcwd) {
|
|
|
|
runcwd = cs->runcwd;
|
|
|
|
free(cs->runcwd);
|
|
|
|
}
|
|
|
|
if (cs->runchroot != runchroot) {
|
|
|
|
runcwd = cs->runchroot;
|
|
|
|
free(cs->runchroot);
|
|
|
|
}
|
2008-02-09 14:30:06 +00:00
|
|
|
#ifdef HAVE_SELINUX
|
2018-02-09 18:21:40 -07:00
|
|
|
/* Only free the first instance of a role/type. */
|
|
|
|
if (cs->role != role) {
|
|
|
|
role = cs->role;
|
|
|
|
free(cs->role);
|
|
|
|
}
|
|
|
|
if (cs->type != type) {
|
|
|
|
type = cs->type;
|
|
|
|
free(cs->type);
|
|
|
|
}
|
2008-02-09 14:30:06 +00:00
|
|
|
#endif /* HAVE_SELINUX */
|
2012-07-26 13:49:21 -04:00
|
|
|
#ifdef HAVE_PRIV_SET
|
2018-02-09 18:21:40 -07:00
|
|
|
/* Only free the first instance of privs/limitprivs. */
|
|
|
|
if (cs->privs != privs) {
|
|
|
|
privs = cs->privs;
|
|
|
|
free(cs->privs);
|
|
|
|
}
|
|
|
|
if (cs->limitprivs != limitprivs) {
|
|
|
|
limitprivs = cs->limitprivs;
|
|
|
|
free(cs->limitprivs);
|
|
|
|
}
|
2012-07-26 13:49:21 -04:00
|
|
|
#endif /* HAVE_PRIV_SET */
|
2018-02-09 18:21:40 -07:00
|
|
|
/* Only free the first instance of runas user/group lists. */
|
|
|
|
if (cs->runasuserlist && cs->runasuserlist != runasuserlist) {
|
|
|
|
runasuserlist = cs->runasuserlist;
|
|
|
|
free_members(runasuserlist);
|
|
|
|
free(runasuserlist);
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
2018-02-09 18:21:40 -07:00
|
|
|
if (cs->runasgrouplist && cs->runasgrouplist != runasgrouplist) {
|
|
|
|
runasgrouplist = cs->runasgrouplist;
|
|
|
|
free_members(runasgrouplist);
|
|
|
|
free(runasgrouplist);
|
2018-02-09 18:21:01 -07:00
|
|
|
}
|
2018-02-09 18:21:40 -07:00
|
|
|
free_member(cs->cmnd);
|
|
|
|
free(cs);
|
|
|
|
}
|
|
|
|
while ((def = TAILQ_FIRST(&priv->defaults)) != NULL) {
|
|
|
|
TAILQ_REMOVE(&priv->defaults, def, entries);
|
2018-03-21 14:55:17 -06:00
|
|
|
free_default(def, &prev_binding);
|
2018-02-09 18:21:40 -07:00
|
|
|
}
|
|
|
|
free(priv);
|
2018-03-21 12:11:19 -06:00
|
|
|
|
|
|
|
debug_return;
|
2018-02-09 18:21:40 -07:00
|
|
|
}
|
|
|
|
|
2018-05-15 16:35:07 -06:00
|
|
|
void
|
|
|
|
free_userspecs(struct userspec_list *usl)
|
|
|
|
{
|
|
|
|
struct userspec *us;
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(free_userspecs, SUDOERS_DEBUG_PARSER);
|
2018-05-15 16:35:07 -06:00
|
|
|
|
|
|
|
while ((us = TAILQ_FIRST(usl)) != NULL) {
|
|
|
|
TAILQ_REMOVE(usl, us, entries);
|
|
|
|
free_userspec(us);
|
|
|
|
}
|
|
|
|
|
|
|
|
debug_return;
|
|
|
|
}
|
|
|
|
|
2018-02-09 18:21:40 -07:00
|
|
|
void
|
|
|
|
free_userspec(struct userspec *us)
|
|
|
|
{
|
|
|
|
struct privilege *priv;
|
2018-03-10 20:16:20 -07:00
|
|
|
struct sudoers_comment *comment;
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(free_userspec, SUDOERS_DEBUG_PARSER);
|
2018-02-09 18:21:40 -07:00
|
|
|
|
|
|
|
free_members(&us->users);
|
|
|
|
while ((priv = TAILQ_FIRST(&us->privileges)) != NULL) {
|
|
|
|
TAILQ_REMOVE(&us->privileges, priv, entries);
|
|
|
|
free_privilege(priv);
|
2018-02-05 13:33:29 -07:00
|
|
|
}
|
2018-03-04 07:03:43 -07:00
|
|
|
while ((comment = STAILQ_FIRST(&us->comments)) != NULL) {
|
|
|
|
STAILQ_REMOVE_HEAD(&us->comments, entries);
|
|
|
|
free(comment->str);
|
|
|
|
free(comment);
|
|
|
|
}
|
2018-02-05 13:33:29 -07:00
|
|
|
rcstr_delref(us->file);
|
|
|
|
free(us);
|
2018-03-21 12:11:19 -06:00
|
|
|
|
|
|
|
debug_return;
|
2018-02-05 13:33:29 -07:00
|
|
|
}
|
|
|
|
|
2018-07-26 15:12:33 -06:00
|
|
|
/*
|
|
|
|
* Initialized a sudoers parse tree.
|
|
|
|
*/
|
|
|
|
void
|
2019-08-15 14:20:12 -06:00
|
|
|
init_parse_tree(struct sudoers_parse_tree *parse_tree, const char *lhost,
|
|
|
|
const char *shost)
|
2018-07-26 15:12:33 -06:00
|
|
|
{
|
|
|
|
TAILQ_INIT(&parse_tree->userspecs);
|
|
|
|
TAILQ_INIT(&parse_tree->defaults);
|
|
|
|
parse_tree->aliases = NULL;
|
2019-08-15 14:20:12 -06:00
|
|
|
parse_tree->shost = shost;
|
|
|
|
parse_tree->lhost = lhost;
|
2018-07-26 15:12:33 -06:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Move the contents of parsed_policy to new_tree.
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
reparent_parse_tree(struct sudoers_parse_tree *new_tree)
|
|
|
|
{
|
|
|
|
TAILQ_CONCAT(&new_tree->userspecs, &parsed_policy.userspecs, entries);
|
|
|
|
TAILQ_CONCAT(&new_tree->defaults, &parsed_policy.defaults, entries);
|
|
|
|
new_tree->aliases = parsed_policy.aliases;
|
|
|
|
parsed_policy.aliases = NULL;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Free the contents of a sudoers parse tree and initialize it.
|
|
|
|
*/
|
|
|
|
void
|
|
|
|
free_parse_tree(struct sudoers_parse_tree *parse_tree)
|
|
|
|
{
|
|
|
|
free_userspecs(&parse_tree->userspecs);
|
|
|
|
free_defaults(&parse_tree->defaults);
|
|
|
|
free_aliases(parse_tree->aliases);
|
|
|
|
parse_tree->aliases = NULL;
|
|
|
|
}
|
|
|
|
|
2018-02-05 13:33:29 -07:00
|
|
|
/*
|
|
|
|
* Free up space used by data structures from a previous parser run and sets
|
|
|
|
* the current sudoers file to path.
|
|
|
|
*/
|
|
|
|
bool
|
2019-11-05 15:18:34 -07:00
|
|
|
init_parser(const char *path, bool quiet, bool strict)
|
2018-02-05 13:33:29 -07:00
|
|
|
{
|
|
|
|
bool ret = true;
|
2019-12-22 08:48:16 -07:00
|
|
|
debug_decl(init_parser, SUDOERS_DEBUG_PARSER);
|
2018-02-05 13:33:29 -07:00
|
|
|
|
2018-07-26 15:12:33 -06:00
|
|
|
free_parse_tree(&parsed_policy);
|
2009-04-18 23:25:08 +00:00
|
|
|
init_lexer();
|
|
|
|
|
2016-11-11 16:18:27 -07:00
|
|
|
rcstr_delref(sudoers);
|
2015-05-27 09:51:54 -06:00
|
|
|
if (path != NULL) {
|
2016-11-11 16:18:27 -07:00
|
|
|
if ((sudoers = rcstr_dup(path)) == NULL) {
|
2015-06-19 14:51:17 -06:00
|
|
|
sudo_warnx(U_("%s: %s"), __func__, U_("unable to allocate memory"));
|
2016-09-08 16:38:08 -06:00
|
|
|
ret = false;
|
2015-05-27 09:51:54 -06:00
|
|
|
}
|
|
|
|
} else {
|
|
|
|
sudoers = NULL;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
|
2011-12-02 11:27:33 -05:00
|
|
|
parse_error = false;
|
2004-10-26 22:10:55 +00:00
|
|
|
errorlineno = -1;
|
2016-11-11 16:18:27 -07:00
|
|
|
rcstr_delref(errorfile);
|
2016-10-31 15:21:18 -06:00
|
|
|
errorfile = NULL;
|
2012-02-29 15:50:48 -05:00
|
|
|
sudoers_warnings = !quiet;
|
2019-11-05 15:18:34 -07:00
|
|
|
sudoers_strict = strict;
|
2011-10-22 14:40:21 -04:00
|
|
|
|
2016-09-08 16:38:08 -06:00
|
|
|
debug_return_bool(ret);
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
2017-02-14 15:56:34 -07:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Initialize all options in a cmndspec.
|
|
|
|
*/
|
|
|
|
static void
|
|
|
|
init_options(struct command_options *opts)
|
|
|
|
{
|
2017-02-18 15:35:48 -07:00
|
|
|
opts->notbefore = UNSPEC;
|
|
|
|
opts->notafter = UNSPEC;
|
2017-02-14 15:56:34 -07:00
|
|
|
opts->timeout = UNSPEC;
|
|
|
|
#ifdef HAVE_SELINUX
|
|
|
|
opts->role = NULL;
|
|
|
|
opts->type = NULL;
|
|
|
|
#endif
|
|
|
|
#ifdef HAVE_PRIV_SET
|
|
|
|
opts->privs = NULL;
|
|
|
|
opts->limitprivs = NULL;
|
|
|
|
#endif
|
|
|
|
}
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 1056 "gram.c"
|
2004-10-26 22:10:55 +00:00
|
|
|
/* allocate initial stack or double stack size, up to YYMAXDEPTH */
|
|
|
|
static int yygrowstack(void)
|
|
|
|
{
|
2013-10-30 14:27:50 -06:00
|
|
|
unsigned int newsize;
|
|
|
|
long sslen;
|
2004-10-26 22:10:55 +00:00
|
|
|
short *newss;
|
|
|
|
YYSTYPE *newvs;
|
|
|
|
|
2013-11-04 10:30:12 -07:00
|
|
|
if ((newsize = yystacksize) == 0)
|
|
|
|
newsize = YYINITSTACKSIZE;
|
|
|
|
else if (newsize >= YYMAXDEPTH)
|
2004-10-26 22:10:55 +00:00
|
|
|
return -1;
|
|
|
|
else if ((newsize *= 2) > YYMAXDEPTH)
|
|
|
|
newsize = YYMAXDEPTH;
|
2008-01-13 20:39:54 +00:00
|
|
|
#ifdef SIZE_MAX
|
|
|
|
#define YY_SIZE_MAX SIZE_MAX
|
|
|
|
#else
|
2013-10-30 14:27:50 -06:00
|
|
|
#define YY_SIZE_MAX 0xffffffffU
|
2015-02-03 15:58:09 -07:00
|
|
|
#endif
|
|
|
|
if (YY_SIZE_MAX / newsize < sizeof *newss)
|
2007-11-21 16:05:31 +00:00
|
|
|
goto bail;
|
2015-02-03 15:58:09 -07:00
|
|
|
sslen = yyssp - yyss;
|
2020-08-07 14:13:25 -06:00
|
|
|
newss = yyss ? realloc(yyss, newsize * sizeof *newss) :
|
|
|
|
malloc(newsize * sizeof *newss); /* overflow check above */
|
2004-10-26 22:10:55 +00:00
|
|
|
if (newss == NULL)
|
|
|
|
goto bail;
|
|
|
|
yyss = newss;
|
2013-10-30 14:27:50 -06:00
|
|
|
yyssp = newss + sslen;
|
2020-08-07 14:13:25 -06:00
|
|
|
newvs = yyvs ? realloc(yyvs, newsize * sizeof *newvs) :
|
|
|
|
malloc(newsize * sizeof *newvs); /* overflow check above */
|
2004-10-26 22:10:55 +00:00
|
|
|
if (newvs == NULL)
|
|
|
|
goto bail;
|
|
|
|
yyvs = newvs;
|
2013-10-30 14:27:50 -06:00
|
|
|
yyvsp = newvs + sslen;
|
2004-10-26 22:10:55 +00:00
|
|
|
yystacksize = newsize;
|
|
|
|
yysslim = yyss + newsize - 1;
|
|
|
|
return 0;
|
|
|
|
bail:
|
2020-08-07 14:13:25 -06:00
|
|
|
free(yyss);
|
|
|
|
free(yyvs);
|
2004-10-26 22:10:55 +00:00
|
|
|
yyss = yyssp = NULL;
|
|
|
|
yyvs = yyvsp = NULL;
|
|
|
|
yystacksize = 0;
|
|
|
|
return -1;
|
|
|
|
}
|
|
|
|
|
|
|
|
#define YYABORT goto yyabort
|
|
|
|
#define YYREJECT goto yyabort
|
|
|
|
#define YYACCEPT goto yyaccept
|
|
|
|
#define YYERROR goto yyerrlab
|
|
|
|
int
|
|
|
|
yyparse(void)
|
|
|
|
{
|
|
|
|
int yym, yyn, yystate;
|
|
|
|
#if YYDEBUG
|
|
|
|
const char *yys;
|
|
|
|
|
|
|
|
if ((yys = getenv("YYDEBUG")))
|
|
|
|
{
|
|
|
|
yyn = *yys;
|
|
|
|
if (yyn >= '0' && yyn <= '9')
|
|
|
|
yydebug = yyn - '0';
|
|
|
|
}
|
|
|
|
#endif /* YYDEBUG */
|
|
|
|
|
|
|
|
yynerrs = 0;
|
|
|
|
yyerrflag = 0;
|
|
|
|
yychar = (-1);
|
|
|
|
|
|
|
|
if (yyss == NULL && yygrowstack()) goto yyoverflow;
|
|
|
|
yyssp = yyss;
|
|
|
|
yyvsp = yyvs;
|
|
|
|
*yyssp = yystate = 0;
|
|
|
|
|
|
|
|
yyloop:
|
|
|
|
if ((yyn = yydefred[yystate]) != 0) goto yyreduce;
|
|
|
|
if (yychar < 0)
|
|
|
|
{
|
|
|
|
if ((yychar = yylex()) < 0) yychar = 0;
|
|
|
|
#if YYDEBUG
|
|
|
|
if (yydebug)
|
|
|
|
{
|
|
|
|
yys = 0;
|
|
|
|
if (yychar <= YYMAXTOKEN) yys = yyname[yychar];
|
|
|
|
if (!yys) yys = "illegal-symbol";
|
|
|
|
printf("%sdebug: state %d, reading %d (%s)\n",
|
|
|
|
YYPREFIX, yystate, yychar, yys);
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
}
|
|
|
|
if ((yyn = yysindex[yystate]) && (yyn += yychar) >= 0 &&
|
|
|
|
yyn <= YYTABLESIZE && yycheck[yyn] == yychar)
|
|
|
|
{
|
|
|
|
#if YYDEBUG
|
|
|
|
if (yydebug)
|
|
|
|
printf("%sdebug: state %d, shifting to state %d\n",
|
|
|
|
YYPREFIX, yystate, yytable[yyn]);
|
|
|
|
#endif
|
|
|
|
if (yyssp >= yysslim && yygrowstack())
|
|
|
|
{
|
|
|
|
goto yyoverflow;
|
|
|
|
}
|
|
|
|
*++yyssp = yystate = yytable[yyn];
|
|
|
|
*++yyvsp = yylval;
|
|
|
|
yychar = (-1);
|
|
|
|
if (yyerrflag > 0) --yyerrflag;
|
|
|
|
goto yyloop;
|
|
|
|
}
|
|
|
|
if ((yyn = yyrindex[yystate]) && (yyn += yychar) >= 0 &&
|
|
|
|
yyn <= YYTABLESIZE && yycheck[yyn] == yychar)
|
|
|
|
{
|
|
|
|
yyn = yytable[yyn];
|
|
|
|
goto yyreduce;
|
|
|
|
}
|
|
|
|
if (yyerrflag) goto yyinrecovery;
|
2014-04-09 16:31:13 -06:00
|
|
|
#if defined(__GNUC__)
|
2004-10-26 22:10:55 +00:00
|
|
|
goto yynewerror;
|
|
|
|
#endif
|
|
|
|
yynewerror:
|
|
|
|
yyerror("syntax error");
|
2014-04-09 16:31:13 -06:00
|
|
|
#if defined(__GNUC__)
|
2004-10-26 22:10:55 +00:00
|
|
|
goto yyerrlab;
|
|
|
|
#endif
|
|
|
|
yyerrlab:
|
|
|
|
++yynerrs;
|
|
|
|
yyinrecovery:
|
|
|
|
if (yyerrflag < 3)
|
|
|
|
{
|
|
|
|
yyerrflag = 3;
|
|
|
|
for (;;)
|
|
|
|
{
|
|
|
|
if ((yyn = yysindex[*yyssp]) && (yyn += YYERRCODE) >= 0 &&
|
|
|
|
yyn <= YYTABLESIZE && yycheck[yyn] == YYERRCODE)
|
|
|
|
{
|
|
|
|
#if YYDEBUG
|
|
|
|
if (yydebug)
|
|
|
|
printf("%sdebug: state %d, error recovery shifting\
|
|
|
|
to state %d\n", YYPREFIX, *yyssp, yytable[yyn]);
|
|
|
|
#endif
|
|
|
|
if (yyssp >= yysslim && yygrowstack())
|
|
|
|
{
|
|
|
|
goto yyoverflow;
|
|
|
|
}
|
|
|
|
*++yyssp = yystate = yytable[yyn];
|
|
|
|
*++yyvsp = yylval;
|
|
|
|
goto yyloop;
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
#if YYDEBUG
|
|
|
|
if (yydebug)
|
|
|
|
printf("%sdebug: error recovery discarding state %d\n",
|
|
|
|
YYPREFIX, *yyssp);
|
|
|
|
#endif
|
|
|
|
if (yyssp <= yyss) goto yyabort;
|
|
|
|
--yyssp;
|
|
|
|
--yyvsp;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
else
|
|
|
|
{
|
|
|
|
if (yychar == 0) goto yyabort;
|
|
|
|
#if YYDEBUG
|
|
|
|
if (yydebug)
|
|
|
|
{
|
|
|
|
yys = 0;
|
|
|
|
if (yychar <= YYMAXTOKEN) yys = yyname[yychar];
|
|
|
|
if (!yys) yys = "illegal-symbol";
|
|
|
|
printf("%sdebug: state %d, error recovery discards token %d (%s)\n",
|
|
|
|
YYPREFIX, yystate, yychar, yys);
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
yychar = (-1);
|
|
|
|
goto yyloop;
|
|
|
|
}
|
|
|
|
yyreduce:
|
|
|
|
#if YYDEBUG
|
|
|
|
if (yydebug)
|
|
|
|
printf("%sdebug: state %d, reducing by rule %d (%s)\n",
|
|
|
|
YYPREFIX, yystate, yyn, yyrule[yyn]);
|
|
|
|
#endif
|
|
|
|
yym = yylen[yyn];
|
2008-07-12 12:53:05 +00:00
|
|
|
if (yym)
|
|
|
|
yyval = yyvsp[1-yym];
|
|
|
|
else
|
|
|
|
memset(&yyval, 0, sizeof yyval);
|
2004-10-26 22:10:55 +00:00
|
|
|
switch (yyn)
|
|
|
|
{
|
|
|
|
case 1:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 186 "gram.y"
|
2020-08-16 14:59:45 -06:00
|
|
|
{
|
|
|
|
; /* empty file */
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
break;
|
|
|
|
case 5:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 196 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-08-16 14:59:45 -06:00
|
|
|
; /* blank line */
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 6:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 199 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
|
|
|
yyerrok;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 7:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 202 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-05-20 13:10:53 -06:00
|
|
|
if (!push_include(yyvsp[0].string, false)) {
|
|
|
|
free(yyvsp[0].string);
|
2015-05-27 10:36:03 -06:00
|
|
|
YYERROR;
|
|
|
|
}
|
2020-05-20 13:10:53 -06:00
|
|
|
free(yyvsp[0].string);
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 8:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 209 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-05-20 13:10:53 -06:00
|
|
|
if (!push_include(yyvsp[0].string, true)) {
|
|
|
|
free(yyvsp[0].string);
|
|
|
|
YYERROR;
|
|
|
|
}
|
|
|
|
free(yyvsp[0].string);
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 9:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 216 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-08-16 14:59:45 -06:00
|
|
|
if (!add_userspec(yyvsp[-2].member, yyvsp[-1].privilege)) {
|
2020-05-20 13:10:53 -06:00
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 10:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 222 "gram.y"
|
2020-08-16 14:59:45 -06:00
|
|
|
{
|
|
|
|
;
|
|
|
|
}
|
|
|
|
break;
|
2004-10-26 22:10:55 +00:00
|
|
|
case 11:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 225 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2004-11-15 03:55:22 +00:00
|
|
|
;
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 12:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 228 "gram.y"
|
2020-05-20 13:10:53 -06:00
|
|
|
{
|
|
|
|
;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 13:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 231 "gram.y"
|
2020-05-20 13:10:53 -06:00
|
|
|
{
|
|
|
|
;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 14:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 234 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-08-16 14:59:45 -06:00
|
|
|
if (!add_defaults(DEFAULTS, NULL, yyvsp[-1].defaults))
|
|
|
|
YYERROR;
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-05-20 13:10:53 -06:00
|
|
|
case 15:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 238 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-08-16 14:59:45 -06:00
|
|
|
if (!add_defaults(DEFAULTS_USER, yyvsp[-2].member, yyvsp[-1].defaults))
|
2015-05-27 10:36:03 -06:00
|
|
|
YYERROR;
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-05-20 13:10:53 -06:00
|
|
|
case 16:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 242 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-08-16 14:59:45 -06:00
|
|
|
if (!add_defaults(DEFAULTS_RUNAS, yyvsp[-2].member, yyvsp[-1].defaults))
|
2015-05-27 10:36:03 -06:00
|
|
|
YYERROR;
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-05-20 13:10:53 -06:00
|
|
|
case 17:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 246 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-08-16 14:59:45 -06:00
|
|
|
if (!add_defaults(DEFAULTS_HOST, yyvsp[-2].member, yyvsp[-1].defaults))
|
2015-05-27 10:36:03 -06:00
|
|
|
YYERROR;
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-05-20 13:10:53 -06:00
|
|
|
case 18:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 250 "gram.y"
|
2004-11-19 21:35:12 +00:00
|
|
|
{
|
2020-08-16 14:59:45 -06:00
|
|
|
if (!add_defaults(DEFAULTS_CMND, yyvsp[-2].member, yyvsp[-1].defaults))
|
2015-05-27 10:36:03 -06:00
|
|
|
YYERROR;
|
2004-11-19 21:35:12 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-07 14:22:24 -06:00
|
|
|
case 19:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 256 "gram.y"
|
2020-08-07 14:22:24 -06:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.string = yyvsp[-1].string;
|
2020-08-07 14:22:24 -06:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 20:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 259 "gram.y"
|
2020-08-07 14:22:24 -06:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyerrok;
|
|
|
|
yyval.string = yyvsp[-2].string;
|
2020-08-07 14:22:24 -06:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 21:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 265 "gram.y"
|
2020-08-15 11:29:46 -06:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.string = yyvsp[-1].string;
|
2020-08-15 11:29:46 -06:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 22:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 268 "gram.y"
|
2020-08-07 14:22:24 -06:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyerrok;
|
|
|
|
yyval.string = yyvsp[-2].string;
|
2020-08-07 14:22:24 -06:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 24:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 275 "gram.y"
|
2020-08-15 11:29:46 -06:00
|
|
|
{
|
|
|
|
HLTQ_CONCAT(yyvsp[-2].defaults, yyvsp[0].defaults, entries);
|
|
|
|
yyval.defaults = yyvsp[-2].defaults;
|
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 25:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 281 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2011-12-02 11:27:33 -05:00
|
|
|
yyval.defaults = new_default(yyvsp[0].string, NULL, true);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.defaults == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 26:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 288 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2011-12-02 11:27:33 -05:00
|
|
|
yyval.defaults = new_default(yyvsp[0].string, NULL, false);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.defaults == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 27:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 295 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2011-12-02 11:27:33 -05:00
|
|
|
yyval.defaults = new_default(yyvsp[-2].string, yyvsp[0].string, true);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.defaults == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 28:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 302 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.defaults = new_default(yyvsp[-2].string, yyvsp[0].string, '+');
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.defaults == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 29:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 309 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.defaults = new_default(yyvsp[-2].string, yyvsp[0].string, '-');
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.defaults == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 31:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 319 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2013-10-22 09:08:38 -06:00
|
|
|
HLTQ_CONCAT(yyvsp[-2].privilege, yyvsp[0].privilege, entries);
|
2004-10-26 22:10:55 +00:00
|
|
|
yyval.privilege = yyvsp[-2].privilege;
|
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 32:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 323 "gram.y"
|
2020-08-16 15:19:53 -06:00
|
|
|
{
|
|
|
|
yyerrok;
|
|
|
|
yyval.privilege = yyvsp[-3].privilege;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 33:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 329 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2015-05-27 10:36:03 -06:00
|
|
|
struct privilege *p = calloc(1, sizeof(*p));
|
|
|
|
if (p == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2018-02-09 18:21:01 -07:00
|
|
|
TAILQ_INIT(&p->defaults);
|
2013-10-22 09:08:38 -06:00
|
|
|
HLTQ_TO_TAILQ(&p->hostlist, yyvsp[-2].member, entries);
|
|
|
|
HLTQ_TO_TAILQ(&p->cmndlist, yyvsp[0].cmndspec, entries);
|
|
|
|
HLTQ_INIT(p, entries);
|
2004-10-26 22:10:55 +00:00
|
|
|
yyval.privilege = p;
|
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 34:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 343 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
|
|
|
yyval.member = yyvsp[0].member;
|
2011-12-02 11:27:33 -05:00
|
|
|
yyval.member->negated = false;
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 35:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 347 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
|
|
|
yyval.member = yyvsp[0].member;
|
2011-12-02 11:27:33 -05:00
|
|
|
yyval.member->negated = true;
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 36:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 353 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.member = new_member(yyvsp[0].string, ALIAS);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 37:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 360 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.member = new_member(NULL, ALL);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 38:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 367 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.member = new_member(yyvsp[0].string, NETGROUP);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 39:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 374 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.member = new_member(yyvsp[0].string, NTWKADDR);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 40:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 381 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.member = new_member(yyvsp[0].string, WORD);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 42:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 391 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2013-10-22 09:08:38 -06:00
|
|
|
struct cmndspec *prev;
|
|
|
|
prev = HLTQ_LAST(yyvsp[-2].cmndspec, cmndspec, entries);
|
|
|
|
HLTQ_CONCAT(yyvsp[-2].cmndspec, yyvsp[0].cmndspec, entries);
|
2020-09-01 06:26:00 -06:00
|
|
|
|
|
|
|
/* propagate runcwd and runchroot */
|
|
|
|
if (yyvsp[0].cmndspec->runcwd == NULL)
|
|
|
|
yyvsp[0].cmndspec->runcwd = prev->runcwd;
|
|
|
|
if (yyvsp[0].cmndspec->runchroot == NULL)
|
|
|
|
yyvsp[0].cmndspec->runchroot = prev->runchroot;
|
2008-02-09 14:30:06 +00:00
|
|
|
#ifdef HAVE_SELINUX
|
|
|
|
/* propagate role and type */
|
2017-02-14 15:56:34 -07:00
|
|
|
if (yyvsp[0].cmndspec->role == NULL && yyvsp[0].cmndspec->type == NULL) {
|
2013-10-22 09:08:38 -06:00
|
|
|
yyvsp[0].cmndspec->role = prev->role;
|
|
|
|
yyvsp[0].cmndspec->type = prev->type;
|
2017-02-14 15:56:34 -07:00
|
|
|
}
|
2008-02-09 14:30:06 +00:00
|
|
|
#endif /* HAVE_SELINUX */
|
2012-07-26 13:49:21 -04:00
|
|
|
#ifdef HAVE_PRIV_SET
|
|
|
|
/* propagate privs & limitprivs */
|
2017-02-14 15:56:34 -07:00
|
|
|
if (yyvsp[0].cmndspec->privs == NULL && yyvsp[0].cmndspec->limitprivs == NULL) {
|
2013-10-22 09:08:38 -06:00
|
|
|
yyvsp[0].cmndspec->privs = prev->privs;
|
|
|
|
yyvsp[0].cmndspec->limitprivs = prev->limitprivs;
|
2017-02-14 15:56:34 -07:00
|
|
|
}
|
2012-07-26 13:49:21 -04:00
|
|
|
#endif /* HAVE_PRIV_SET */
|
2017-02-18 15:35:48 -07:00
|
|
|
/* propagate command time restrictions */
|
|
|
|
if (yyvsp[0].cmndspec->notbefore == UNSPEC)
|
|
|
|
yyvsp[0].cmndspec->notbefore = prev->notbefore;
|
|
|
|
if (yyvsp[0].cmndspec->notafter == UNSPEC)
|
|
|
|
yyvsp[0].cmndspec->notafter = prev->notafter;
|
2017-02-14 15:56:34 -07:00
|
|
|
/* propagate command timeout */
|
|
|
|
if (yyvsp[0].cmndspec->timeout == UNSPEC)
|
|
|
|
yyvsp[0].cmndspec->timeout = prev->timeout;
|
2007-09-01 21:39:24 +00:00
|
|
|
/* propagate tags and runas list */
|
|
|
|
if (yyvsp[0].cmndspec->tags.nopasswd == UNSPEC)
|
2013-10-22 09:08:38 -06:00
|
|
|
yyvsp[0].cmndspec->tags.nopasswd = prev->tags.nopasswd;
|
2007-09-01 21:39:24 +00:00
|
|
|
if (yyvsp[0].cmndspec->tags.noexec == UNSPEC)
|
2013-10-22 09:08:38 -06:00
|
|
|
yyvsp[0].cmndspec->tags.noexec = prev->tags.noexec;
|
2007-11-21 16:05:31 +00:00
|
|
|
if (yyvsp[0].cmndspec->tags.setenv == UNSPEC &&
|
2013-10-22 09:08:38 -06:00
|
|
|
prev->tags.setenv != IMPLIED)
|
|
|
|
yyvsp[0].cmndspec->tags.setenv = prev->tags.setenv;
|
2010-05-30 10:31:38 -04:00
|
|
|
if (yyvsp[0].cmndspec->tags.log_input == UNSPEC)
|
2013-10-22 09:08:38 -06:00
|
|
|
yyvsp[0].cmndspec->tags.log_input = prev->tags.log_input;
|
2010-05-30 10:31:38 -04:00
|
|
|
if (yyvsp[0].cmndspec->tags.log_output == UNSPEC)
|
2013-10-22 09:08:38 -06:00
|
|
|
yyvsp[0].cmndspec->tags.log_output = prev->tags.log_output;
|
2015-02-19 10:02:20 -07:00
|
|
|
if (yyvsp[0].cmndspec->tags.send_mail == UNSPEC)
|
|
|
|
yyvsp[0].cmndspec->tags.send_mail = prev->tags.send_mail;
|
2015-08-06 13:20:01 -06:00
|
|
|
if (yyvsp[0].cmndspec->tags.follow == UNSPEC)
|
|
|
|
yyvsp[0].cmndspec->tags.follow = prev->tags.follow;
|
2013-10-22 09:08:38 -06:00
|
|
|
if ((yyvsp[0].cmndspec->runasuserlist == NULL &&
|
|
|
|
yyvsp[0].cmndspec->runasgrouplist == NULL) &&
|
|
|
|
(prev->runasuserlist != NULL ||
|
|
|
|
prev->runasgrouplist != NULL)) {
|
|
|
|
yyvsp[0].cmndspec->runasuserlist = prev->runasuserlist;
|
|
|
|
yyvsp[0].cmndspec->runasgrouplist = prev->runasgrouplist;
|
2007-11-21 20:12:00 +00:00
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
yyval.cmndspec = yyvsp[-2].cmndspec;
|
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 43:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 450 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2015-05-27 10:36:03 -06:00
|
|
|
struct cmndspec *cs = calloc(1, sizeof(*cs));
|
|
|
|
if (cs == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2017-02-14 15:56:34 -07:00
|
|
|
if (yyvsp[-3].runas != NULL) {
|
|
|
|
if (yyvsp[-3].runas->runasusers != NULL) {
|
2013-10-22 09:08:38 -06:00
|
|
|
cs->runasuserlist =
|
2015-05-27 10:36:03 -06:00
|
|
|
malloc(sizeof(*cs->runasuserlist));
|
|
|
|
if (cs->runasuserlist == NULL) {
|
2019-08-30 10:38:07 -06:00
|
|
|
free(cs);
|
2015-05-27 10:36:03 -06:00
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2013-10-22 09:08:38 -06:00
|
|
|
HLTQ_TO_TAILQ(cs->runasuserlist,
|
2017-02-14 15:56:34 -07:00
|
|
|
yyvsp[-3].runas->runasusers, entries);
|
2013-10-22 09:08:38 -06:00
|
|
|
}
|
2017-02-14 15:56:34 -07:00
|
|
|
if (yyvsp[-3].runas->runasgroups != NULL) {
|
2013-10-22 09:08:38 -06:00
|
|
|
cs->runasgrouplist =
|
2015-05-27 10:36:03 -06:00
|
|
|
malloc(sizeof(*cs->runasgrouplist));
|
|
|
|
if (cs->runasgrouplist == NULL) {
|
2019-08-30 10:38:07 -06:00
|
|
|
free(cs);
|
2015-05-27 10:36:03 -06:00
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2013-10-22 09:08:38 -06:00
|
|
|
HLTQ_TO_TAILQ(cs->runasgrouplist,
|
2017-02-14 15:56:34 -07:00
|
|
|
yyvsp[-3].runas->runasgroups, entries);
|
2013-10-22 09:08:38 -06:00
|
|
|
}
|
2017-02-14 15:56:34 -07:00
|
|
|
free(yyvsp[-3].runas);
|
2007-11-21 20:12:00 +00:00
|
|
|
}
|
2008-02-09 14:30:06 +00:00
|
|
|
#ifdef HAVE_SELINUX
|
2017-02-14 15:56:34 -07:00
|
|
|
cs->role = yyvsp[-2].options.role;
|
|
|
|
cs->type = yyvsp[-2].options.type;
|
2012-07-26 13:49:21 -04:00
|
|
|
#endif
|
|
|
|
#ifdef HAVE_PRIV_SET
|
2017-02-14 15:56:34 -07:00
|
|
|
cs->privs = yyvsp[-2].options.privs;
|
|
|
|
cs->limitprivs = yyvsp[-2].options.limitprivs;
|
2008-02-09 14:30:06 +00:00
|
|
|
#endif
|
2017-02-18 15:35:48 -07:00
|
|
|
cs->notbefore = yyvsp[-2].options.notbefore;
|
|
|
|
cs->notafter = yyvsp[-2].options.notafter;
|
2017-02-14 15:56:34 -07:00
|
|
|
cs->timeout = yyvsp[-2].options.timeout;
|
2020-09-01 06:26:00 -06:00
|
|
|
cs->runcwd = yyvsp[-2].options.runcwd;
|
|
|
|
cs->runchroot = yyvsp[-2].options.runchroot;
|
2017-02-14 15:56:34 -07:00
|
|
|
cs->tags = yyvsp[-1].tag;
|
2004-10-26 22:10:55 +00:00
|
|
|
cs->cmnd = yyvsp[0].member;
|
2013-10-22 09:08:38 -06:00
|
|
|
HLTQ_INIT(cs, entries);
|
2007-11-21 16:05:31 +00:00
|
|
|
/* sudo "ALL" implies the SETENV tag */
|
|
|
|
if (cs->cmnd->type == ALL && !cs->cmnd->negated &&
|
|
|
|
cs->tags.setenv == UNSPEC)
|
|
|
|
cs->tags.setenv = IMPLIED;
|
2004-10-26 22:10:55 +00:00
|
|
|
yyval.cmndspec = cs;
|
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 44:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 505 "gram.y"
|
2013-04-14 07:00:21 -04:00
|
|
|
{
|
|
|
|
yyval.digest = new_digest(SUDO_DIGEST_SHA224, yyvsp[0].string);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.digest == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2013-04-14 07:00:21 -04:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 45:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 512 "gram.y"
|
2013-04-14 07:00:21 -04:00
|
|
|
{
|
|
|
|
yyval.digest = new_digest(SUDO_DIGEST_SHA256, yyvsp[0].string);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.digest == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2013-04-14 07:00:21 -04:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 46:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 519 "gram.y"
|
2013-04-14 07:00:21 -04:00
|
|
|
{
|
|
|
|
yyval.digest = new_digest(SUDO_DIGEST_SHA384, yyvsp[0].string);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.digest == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2013-04-14 07:00:21 -04:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 47:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 526 "gram.y"
|
2013-04-14 07:00:21 -04:00
|
|
|
{
|
|
|
|
yyval.digest = new_digest(SUDO_DIGEST_SHA512, yyvsp[0].string);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.digest == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2013-04-14 07:00:21 -04:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 49:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 536 "gram.y"
|
2013-04-14 07:00:21 -04:00
|
|
|
{
|
2020-03-11 11:17:52 -06:00
|
|
|
HLTQ_CONCAT(yyvsp[-2].digest, yyvsp[0].digest, entries);
|
|
|
|
yyval.digest = yyvsp[-2].digest;
|
2013-04-14 07:00:21 -04:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 50:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 542 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
|
|
|
yyval.member = yyvsp[0].member;
|
|
|
|
}
|
|
|
|
break;
|
2020-08-16 15:19:53 -06:00
|
|
|
case 51:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 545 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-03-11 11:17:52 -06:00
|
|
|
struct sudo_command *c =
|
|
|
|
(struct sudo_command *) yyvsp[0].member->name;
|
|
|
|
|
2020-03-11 11:19:37 -06:00
|
|
|
if (yyvsp[0].member->type != COMMAND && yyvsp[0].member->type != ALL) {
|
2020-03-11 11:17:52 -06:00
|
|
|
sudoerserror(N_("a digest requires a path name"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2020-03-11 11:19:37 -06:00
|
|
|
if (c == NULL) {
|
|
|
|
/* lazy-allocate sudo_command for ALL */
|
|
|
|
if ((c = new_command(NULL, NULL)) == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
|
|
|
yyvsp[0].member->name = (char *)c;
|
|
|
|
}
|
2020-03-11 11:17:52 -06:00
|
|
|
HLTQ_TO_TAILQ(&c->digests, yyvsp[-1].digest, entries);
|
2004-10-26 22:10:55 +00:00
|
|
|
yyval.member = yyvsp[0].member;
|
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 52:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 566 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-03-11 11:17:52 -06:00
|
|
|
yyval.member = yyvsp[0].member;
|
2020-08-16 15:19:53 -06:00
|
|
|
yyval.member->negated = false;
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 53:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 570 "gram.y"
|
2008-02-09 14:30:06 +00:00
|
|
|
{
|
2020-08-16 15:19:53 -06:00
|
|
|
yyval.member = yyvsp[0].member;
|
|
|
|
yyval.member->negated = true;
|
2008-02-09 14:30:06 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 54:
|
2020-09-01 06:26:00 -06:00
|
|
|
#line 576 "gram.y"
|
2012-07-26 13:49:21 -04:00
|
|
|
{
|
2020-09-01 14:10:02 -06:00
|
|
|
if (yyvsp[0].string[0] != '/' && yyvsp[0].string[0] != '~') {
|
|
|
|
if (strcmp(yyvsp[0].string, "*") != 0) {
|
|
|
|
sudoerserror(N_("values for \"CWD\" must"
|
|
|
|
" start with a '/', '~', or '*'"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
|
|
|
}
|
2017-02-14 15:56:34 -07:00
|
|
|
yyval.string = yyvsp[0].string;
|
2012-07-26 13:49:21 -04:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 55:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 588 "gram.y"
|
2012-07-26 13:49:21 -04:00
|
|
|
{
|
2020-09-01 14:10:02 -06:00
|
|
|
if (yyvsp[0].string[0] != '/' && yyvsp[0].string[0] != '~') {
|
|
|
|
if (strcmp(yyvsp[0].string, "*") != 0) {
|
|
|
|
sudoerserror(N_("values for \"CHROOT\" must"
|
|
|
|
" start with a '/', '~', or '*'"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
|
|
|
}
|
2017-02-18 15:35:48 -07:00
|
|
|
yyval.string = yyvsp[0].string;
|
2012-07-26 13:49:21 -04:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 56:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 600 "gram.y"
|
2017-02-14 15:56:34 -07:00
|
|
|
{
|
2017-02-18 15:35:48 -07:00
|
|
|
yyval.string = yyvsp[0].string;
|
2017-02-14 15:56:34 -07:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 57:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 605 "gram.y"
|
2017-02-18 15:35:48 -07:00
|
|
|
{
|
2020-03-11 11:17:52 -06:00
|
|
|
yyval.string = yyvsp[0].string;
|
2017-02-18 15:35:48 -07:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 58:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 609 "gram.y"
|
2017-02-18 15:35:48 -07:00
|
|
|
{
|
2020-03-11 11:17:52 -06:00
|
|
|
yyval.string = yyvsp[0].string;
|
2017-02-18 15:35:48 -07:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 59:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 614 "gram.y"
|
2020-03-11 11:17:52 -06:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.string = yyvsp[0].string;
|
2020-03-11 11:17:52 -06:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 60:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 619 "gram.y"
|
2020-03-11 11:17:52 -06:00
|
|
|
{
|
2020-08-16 15:19:53 -06:00
|
|
|
yyval.string = yyvsp[0].string;
|
2020-03-11 11:17:52 -06:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 61:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 624 "gram.y"
|
2020-08-15 11:38:56 -06:00
|
|
|
{
|
2020-09-01 06:26:00 -06:00
|
|
|
yyval.string = yyvsp[0].string;
|
2020-08-15 11:38:56 -06:00
|
|
|
}
|
|
|
|
break;
|
2020-08-16 14:59:45 -06:00
|
|
|
case 62:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 628 "gram.y"
|
2020-08-16 15:19:53 -06:00
|
|
|
{
|
2020-09-01 06:26:00 -06:00
|
|
|
yyval.string = yyvsp[0].string;
|
2020-08-16 15:19:53 -06:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 63:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 633 "gram.y"
|
2020-09-01 06:26:00 -06:00
|
|
|
{
|
|
|
|
yyval.runas = NULL;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 64:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 636 "gram.y"
|
2020-09-01 06:26:00 -06:00
|
|
|
{
|
|
|
|
yyval.runas = yyvsp[-1].runas;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 65:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 641 "gram.y"
|
2015-05-27 10:36:03 -06:00
|
|
|
{
|
|
|
|
yyval.runas = calloc(1, sizeof(struct runascontainer));
|
|
|
|
if (yyval.runas != NULL) {
|
|
|
|
yyval.runas->runasusers = new_member(NULL, MYSELF);
|
|
|
|
/* $$->runasgroups = NULL; */
|
|
|
|
if (yyval.runas->runasusers == NULL) {
|
|
|
|
free(yyval.runas);
|
|
|
|
yyval.runas = NULL;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if (yyval.runas == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 66:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 656 "gram.y"
|
2012-08-02 14:02:54 -04:00
|
|
|
{
|
2015-05-27 10:36:03 -06:00
|
|
|
yyval.runas = calloc(1, sizeof(struct runascontainer));
|
|
|
|
if (yyval.runas == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2012-08-02 14:02:54 -04:00
|
|
|
yyval.runas->runasusers = yyvsp[0].member;
|
|
|
|
/* $$->runasgroups = NULL; */
|
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 67:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 665 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2015-05-27 10:36:03 -06:00
|
|
|
yyval.runas = calloc(1, sizeof(struct runascontainer));
|
|
|
|
if (yyval.runas == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2007-11-21 20:12:00 +00:00
|
|
|
yyval.runas->runasusers = yyvsp[-2].member;
|
|
|
|
yyval.runas->runasgroups = yyvsp[0].member;
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 68:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 674 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2015-05-27 10:36:03 -06:00
|
|
|
yyval.runas = calloc(1, sizeof(struct runascontainer));
|
|
|
|
if (yyval.runas == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2012-03-19 11:24:24 -04:00
|
|
|
/* $$->runasusers = NULL; */
|
2007-11-21 20:12:00 +00:00
|
|
|
yyval.runas->runasgroups = yyvsp[0].member;
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 69:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 683 "gram.y"
|
2015-05-27 10:36:03 -06:00
|
|
|
{
|
|
|
|
yyval.runas = calloc(1, sizeof(struct runascontainer));
|
|
|
|
if (yyval.runas != NULL) {
|
|
|
|
yyval.runas->runasusers = new_member(NULL, MYSELF);
|
|
|
|
/* $$->runasgroups = NULL; */
|
|
|
|
if (yyval.runas->runasusers == NULL) {
|
|
|
|
free(yyval.runas);
|
|
|
|
yyval.runas = NULL;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if (yyval.runas == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2012-08-02 14:02:54 -04:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 70:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 700 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2017-02-14 15:56:34 -07:00
|
|
|
init_options(&yyval.options);
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 71:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 703 "gram.y"
|
2020-09-01 06:26:00 -06:00
|
|
|
{
|
|
|
|
free(yyval.options.runcwd);
|
|
|
|
yyval.options.runcwd = yyvsp[0].string;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 72:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 707 "gram.y"
|
2020-09-01 06:26:00 -06:00
|
|
|
{
|
|
|
|
free(yyval.options.runchroot);
|
|
|
|
yyval.options.runchroot = yyvsp[0].string;
|
|
|
|
}
|
|
|
|
break;
|
|
|
|
case 73:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 711 "gram.y"
|
2017-02-18 15:35:48 -07:00
|
|
|
{
|
|
|
|
yyval.options.notbefore = parse_gentime(yyvsp[0].string);
|
|
|
|
free(yyvsp[0].string);
|
|
|
|
if (yyval.options.notbefore == -1) {
|
|
|
|
sudoerserror(N_("invalid notbefore value"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 74:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 719 "gram.y"
|
2017-02-18 15:35:48 -07:00
|
|
|
{
|
|
|
|
yyval.options.notafter = parse_gentime(yyvsp[0].string);
|
|
|
|
free(yyvsp[0].string);
|
|
|
|
if (yyval.options.notafter == -1) {
|
|
|
|
sudoerserror(N_("invalid notafter value"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 75:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 727 "gram.y"
|
2017-02-14 15:56:34 -07:00
|
|
|
{
|
|
|
|
yyval.options.timeout = parse_timeout(yyvsp[0].string);
|
2017-02-14 15:56:34 -07:00
|
|
|
free(yyvsp[0].string);
|
2017-02-14 15:56:34 -07:00
|
|
|
if (yyval.options.timeout == -1) {
|
2017-02-15 15:13:37 -07:00
|
|
|
if (errno == ERANGE)
|
|
|
|
sudoerserror(N_("timeout value too large"));
|
|
|
|
else
|
|
|
|
sudoerserror(N_("invalid timeout value"));
|
2017-02-14 15:56:34 -07:00
|
|
|
YYERROR;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 76:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 738 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2017-02-14 15:56:34 -07:00
|
|
|
#ifdef HAVE_SELINUX
|
2017-02-14 15:56:34 -07:00
|
|
|
free(yyval.options.role);
|
2017-02-14 15:56:34 -07:00
|
|
|
yyval.options.role = yyvsp[0].string;
|
|
|
|
#endif
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 77:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 744 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2017-02-14 15:56:34 -07:00
|
|
|
#ifdef HAVE_SELINUX
|
2017-02-14 15:56:34 -07:00
|
|
|
free(yyval.options.type);
|
2017-02-14 15:56:34 -07:00
|
|
|
yyval.options.type = yyvsp[0].string;
|
|
|
|
#endif
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 78:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 750 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2017-02-14 15:56:34 -07:00
|
|
|
#ifdef HAVE_PRIV_SET
|
2017-02-14 15:56:34 -07:00
|
|
|
free(yyval.options.privs);
|
2017-02-14 15:56:34 -07:00
|
|
|
yyval.options.privs = yyvsp[0].string;
|
|
|
|
#endif
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 79:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 756 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2017-02-14 15:56:34 -07:00
|
|
|
#ifdef HAVE_PRIV_SET
|
2017-02-14 15:56:34 -07:00
|
|
|
free(yyval.options.limitprivs);
|
2017-02-14 15:56:34 -07:00
|
|
|
yyval.options.limitprivs = yyvsp[0].string;
|
|
|
|
#endif
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 80:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 764 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
TAGS_INIT(yyval.tag);
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 81:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 767 "gram.y"
|
2007-06-23 23:58:54 +00:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.nopasswd = true;
|
2007-06-23 23:58:54 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 82:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 770 "gram.y"
|
2007-06-23 23:58:54 +00:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.nopasswd = false;
|
2007-06-23 23:58:54 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 83:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 773 "gram.y"
|
2009-08-06 00:04:14 +00:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.noexec = true;
|
2009-08-06 00:04:14 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 84:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 776 "gram.y"
|
2009-08-06 00:04:14 +00:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.noexec = false;
|
2009-08-06 00:04:14 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 85:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 779 "gram.y"
|
2010-05-30 10:31:38 -04:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.setenv = true;
|
2010-05-30 10:31:38 -04:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 86:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 782 "gram.y"
|
2010-05-30 10:31:38 -04:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.setenv = false;
|
2010-05-30 10:31:38 -04:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 87:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 785 "gram.y"
|
2015-08-06 13:20:01 -06:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.log_input = true;
|
2015-08-06 13:20:01 -06:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 88:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 788 "gram.y"
|
2015-08-06 13:20:01 -06:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.log_input = false;
|
2015-08-06 13:20:01 -06:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 89:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 791 "gram.y"
|
2017-02-14 15:56:34 -07:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.log_output = true;
|
2017-02-14 15:56:34 -07:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 90:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 794 "gram.y"
|
2017-02-14 15:56:34 -07:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.log_output = false;
|
2017-02-14 15:56:34 -07:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 91:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 797 "gram.y"
|
2017-02-14 15:56:34 -07:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.follow = true;
|
2017-02-14 15:56:34 -07:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 92:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 800 "gram.y"
|
2017-02-14 15:56:34 -07:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.follow = false;
|
2017-02-14 15:56:34 -07:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 93:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 803 "gram.y"
|
2017-02-14 15:56:34 -07:00
|
|
|
{
|
2020-08-15 11:38:56 -06:00
|
|
|
yyval.tag.send_mail = true;
|
2017-02-14 15:56:34 -07:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 94:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 806 "gram.y"
|
2020-08-15 11:38:56 -06:00
|
|
|
{
|
|
|
|
yyval.tag.send_mail = false;
|
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 95:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 811 "gram.y"
|
2015-02-19 10:02:20 -07:00
|
|
|
{
|
|
|
|
yyval.member = new_member(NULL, ALL);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2015-02-19 10:02:20 -07:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 96:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 818 "gram.y"
|
2015-02-19 10:02:20 -07:00
|
|
|
{
|
|
|
|
yyval.member = new_member(yyvsp[0].string, ALIAS);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2015-02-19 10:02:20 -07:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 97:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 825 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2020-03-11 11:19:37 -06:00
|
|
|
struct sudo_command *c;
|
|
|
|
|
|
|
|
if ((c = new_command(yyvsp[0].command.cmnd, yyvsp[0].command.args)) == NULL) {
|
2015-05-27 10:36:03 -06:00
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.member = new_member((char *)c, COMMAND);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
free(c);
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 100:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 845 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2015-05-27 09:48:34 -06:00
|
|
|
const char *s;
|
2018-07-26 15:12:33 -06:00
|
|
|
s = alias_add(&parsed_policy, yyvsp[-2].string, HOSTALIAS,
|
|
|
|
sudoers, this_lineno, yyvsp[0].member);
|
2016-11-12 19:22:32 -07:00
|
|
|
if (s != NULL) {
|
2012-09-17 17:03:17 -04:00
|
|
|
sudoerserror(s);
|
2004-11-15 03:55:22 +00:00
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 102:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 857 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2013-10-22 09:08:38 -06:00
|
|
|
HLTQ_CONCAT(yyvsp[-2].member, yyvsp[0].member, entries);
|
2004-10-26 22:10:55 +00:00
|
|
|
yyval.member = yyvsp[-2].member;
|
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 105:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 867 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2015-05-27 09:48:34 -06:00
|
|
|
const char *s;
|
2018-07-26 15:12:33 -06:00
|
|
|
s = alias_add(&parsed_policy, yyvsp[-2].string, CMNDALIAS,
|
|
|
|
sudoers, this_lineno, yyvsp[0].member);
|
2016-11-12 19:22:32 -07:00
|
|
|
if (s != NULL) {
|
2012-09-17 17:03:17 -04:00
|
|
|
sudoerserror(s);
|
2004-11-15 03:55:22 +00:00
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 107:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 879 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2013-10-22 09:08:38 -06:00
|
|
|
HLTQ_CONCAT(yyvsp[-2].member, yyvsp[0].member, entries);
|
2004-10-26 22:10:55 +00:00
|
|
|
yyval.member = yyvsp[-2].member;
|
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 110:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 889 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2015-05-27 09:48:34 -06:00
|
|
|
const char *s;
|
2018-07-26 15:12:33 -06:00
|
|
|
s = alias_add(&parsed_policy, yyvsp[-2].string, RUNASALIAS,
|
|
|
|
sudoers, this_lineno, yyvsp[0].member);
|
2016-11-12 19:22:32 -07:00
|
|
|
if (s != NULL) {
|
2012-09-17 17:03:17 -04:00
|
|
|
sudoerserror(s);
|
2004-11-15 03:55:22 +00:00
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 113:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 904 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2015-05-27 09:48:34 -06:00
|
|
|
const char *s;
|
2018-07-26 15:12:33 -06:00
|
|
|
s = alias_add(&parsed_policy, yyvsp[-2].string, USERALIAS,
|
|
|
|
sudoers, this_lineno, yyvsp[0].member);
|
2016-11-12 19:22:32 -07:00
|
|
|
if (s != NULL) {
|
2012-09-17 17:03:17 -04:00
|
|
|
sudoerserror(s);
|
2004-11-15 03:55:22 +00:00
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 115:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 916 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2013-10-22 09:08:38 -06:00
|
|
|
HLTQ_CONCAT(yyvsp[-2].member, yyvsp[0].member, entries);
|
2004-10-26 22:10:55 +00:00
|
|
|
yyval.member = yyvsp[-2].member;
|
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 116:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 922 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
|
|
|
yyval.member = yyvsp[0].member;
|
2011-12-02 11:27:33 -05:00
|
|
|
yyval.member->negated = false;
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 117:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 926 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
|
|
|
yyval.member = yyvsp[0].member;
|
2011-12-02 11:27:33 -05:00
|
|
|
yyval.member->negated = true;
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 118:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 932 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.member = new_member(yyvsp[0].string, ALIAS);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 119:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 939 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.member = new_member(NULL, ALL);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 120:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 946 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.member = new_member(yyvsp[0].string, NETGROUP);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 121:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 953 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.member = new_member(yyvsp[0].string, USERGROUP);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 122:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 960 "gram.y"
|
2007-11-21 20:12:00 +00:00
|
|
|
{
|
|
|
|
yyval.member = new_member(yyvsp[0].string, WORD);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2007-11-21 20:12:00 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 124:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 970 "gram.y"
|
2007-11-21 20:12:00 +00:00
|
|
|
{
|
2013-10-22 09:08:38 -06:00
|
|
|
HLTQ_CONCAT(yyvsp[-2].member, yyvsp[0].member, entries);
|
2007-11-21 20:12:00 +00:00
|
|
|
yyval.member = yyvsp[-2].member;
|
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 125:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 976 "gram.y"
|
2007-11-21 20:12:00 +00:00
|
|
|
{
|
|
|
|
yyval.member = yyvsp[0].member;
|
2011-12-02 11:27:33 -05:00
|
|
|
yyval.member->negated = false;
|
2007-11-21 20:12:00 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 126:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 980 "gram.y"
|
2007-11-21 20:12:00 +00:00
|
|
|
{
|
|
|
|
yyval.member = yyvsp[0].member;
|
2011-12-02 11:27:33 -05:00
|
|
|
yyval.member->negated = true;
|
2007-11-21 20:12:00 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 127:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 986 "gram.y"
|
2007-11-21 20:12:00 +00:00
|
|
|
{
|
|
|
|
yyval.member = new_member(yyvsp[0].string, ALIAS);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2007-11-21 20:12:00 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 128:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 993 "gram.y"
|
2007-11-21 20:12:00 +00:00
|
|
|
{
|
|
|
|
yyval.member = new_member(NULL, ALL);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2007-11-21 20:12:00 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 129:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 1000 "gram.y"
|
2004-10-26 22:10:55 +00:00
|
|
|
{
|
2007-08-31 23:14:37 +00:00
|
|
|
yyval.member = new_member(yyvsp[0].string, WORD);
|
2015-05-27 10:36:03 -06:00
|
|
|
if (yyval.member == NULL) {
|
|
|
|
sudoerserror(N_("unable to allocate memory"));
|
|
|
|
YYERROR;
|
|
|
|
}
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 130:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 1009 "gram.y"
|
2020-08-16 14:59:45 -06:00
|
|
|
{
|
|
|
|
;
|
|
|
|
}
|
|
|
|
break;
|
2020-09-01 06:26:00 -06:00
|
|
|
case 131:
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 1012 "gram.y"
|
2020-08-16 14:59:45 -06:00
|
|
|
{
|
|
|
|
; /* EOF */
|
|
|
|
}
|
|
|
|
break;
|
2020-09-01 14:10:02 -06:00
|
|
|
#line 2300 "gram.c"
|
2004-10-26 22:10:55 +00:00
|
|
|
}
|
|
|
|
yyssp -= yym;
|
|
|
|
yystate = *yyssp;
|
|
|
|
yyvsp -= yym;
|
|
|
|
yym = yylhs[yyn];
|
|
|
|
if (yystate == 0 && yym == 0)
|
|
|
|
{
|
|
|
|
#if YYDEBUG
|
|
|
|
if (yydebug)
|
|
|
|
printf("%sdebug: after reduction, shifting from state 0 to\
|
|
|
|
state %d\n", YYPREFIX, YYFINAL);
|
|
|
|
#endif
|
|
|
|
yystate = YYFINAL;
|
|
|
|
*++yyssp = YYFINAL;
|
|
|
|
*++yyvsp = yyval;
|
|
|
|
if (yychar < 0)
|
|
|
|
{
|
|
|
|
if ((yychar = yylex()) < 0) yychar = 0;
|
|
|
|
#if YYDEBUG
|
|
|
|
if (yydebug)
|
|
|
|
{
|
|
|
|
yys = 0;
|
|
|
|
if (yychar <= YYMAXTOKEN) yys = yyname[yychar];
|
|
|
|
if (!yys) yys = "illegal-symbol";
|
|
|
|
printf("%sdebug: state %d, reading %d (%s)\n",
|
|
|
|
YYPREFIX, YYFINAL, yychar, yys);
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
}
|
|
|
|
if (yychar == 0) goto yyaccept;
|
|
|
|
goto yyloop;
|
|
|
|
}
|
|
|
|
if ((yyn = yygindex[yym]) && (yyn += yystate) >= 0 &&
|
|
|
|
yyn <= YYTABLESIZE && yycheck[yyn] == yystate)
|
|
|
|
yystate = yytable[yyn];
|
|
|
|
else
|
|
|
|
yystate = yydgoto[yym];
|
|
|
|
#if YYDEBUG
|
|
|
|
if (yydebug)
|
|
|
|
printf("%sdebug: after reduction, shifting from state %d \
|
|
|
|
to state %d\n", YYPREFIX, *yyssp, yystate);
|
|
|
|
#endif
|
|
|
|
if (yyssp >= yysslim && yygrowstack())
|
|
|
|
{
|
|
|
|
goto yyoverflow;
|
|
|
|
}
|
|
|
|
*++yyssp = yystate;
|
|
|
|
*++yyvsp = yyval;
|
|
|
|
goto yyloop;
|
|
|
|
yyoverflow:
|
|
|
|
yyerror("yacc stack overflow");
|
|
|
|
yyabort:
|
2020-08-07 14:13:25 -06:00
|
|
|
free(yyss);
|
|
|
|
free(yyvs);
|
2004-10-26 22:10:55 +00:00
|
|
|
yyss = yyssp = NULL;
|
|
|
|
yyvs = yyvsp = NULL;
|
|
|
|
yystacksize = 0;
|
|
|
|
return (1);
|
|
|
|
yyaccept:
|
2020-08-07 14:13:25 -06:00
|
|
|
free(yyss);
|
|
|
|
free(yyvs);
|
2004-10-26 22:10:55 +00:00
|
|
|
yyss = yyssp = NULL;
|
|
|
|
yyvs = yyvsp = NULL;
|
|
|
|
yystacksize = 0;
|
|
|
|
return (0);
|
|
|
|
}
|