]> git.ipfire.org Git - thirdparty/glibc.git/blame - shadow/shadow.h
elf: Refuse to dlopen PIE objects [BZ #24323]
[thirdparty/glibc.git] / shadow / shadow.h
CommitLineData
04277e02 1/* Copyright (C) 1996-2019 Free Software Foundation, Inc.
2c6fe0bd 2 This file is part of the GNU C Library.
267ca16a 3
2c6fe0bd 4 The GNU C Library is free software; you can redistribute it and/or
41bdb6e2
AJ
5 modify it under the terms of the GNU Lesser General Public
6 License as published by the Free Software Foundation; either
7 version 2.1 of the License, or (at your option) any later version.
267ca16a 8
2c6fe0bd
UD
9 The GNU C Library is distributed in the hope that it will be useful,
10 but WITHOUT ANY WARRANTY; without even the implied warranty of
11 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
41bdb6e2 12 Lesser General Public License for more details.
267ca16a 13
41bdb6e2 14 You should have received a copy of the GNU Lesser General Public
59ba27a6
PE
15 License along with the GNU C Library; if not, see
16 <http://www.gnu.org/licenses/>. */
267ca16a 17
841785ba
ZW
18/* Declaration of types and functions for "shadow" storage of hashed
19 passphrases. The shadow database is like the user database, but is
20 only accessible with special privileges, so that malicious users
21 cannot retrieve everyone else's hashed passphrase to brute-force at
22 their convenience. */
267ca16a
UD
23
24#ifndef _SHADOW_H
267ca16a 25#define _SHADOW_H 1
5107cf1d 26
267ca16a
UD
27#include <features.h>
28
2c6fe0bd
UD
29#include <paths.h>
30
0f110f41
TBB
31#define __need_size_t
32#include <stddef.h>
33
199fc19d
ZW
34#include <bits/types/FILE.h>
35
2c6fe0bd
UD
36/* Paths to the user database files. */
37#define SHADOW _PATH_SHADOW
267ca16a
UD
38
39
40__BEGIN_DECLS
41
841785ba 42/* A record in the shadow database. */
267ca16a 43struct spwd
19361cb7
UD
44 {
45 char *sp_namp; /* Login name. */
841785ba 46 char *sp_pwdp; /* Hashed passphrase. */
19361cb7
UD
47 long int sp_lstchg; /* Date of last change. */
48 long int sp_min; /* Minimum number of days between changes. */
49 long int sp_max; /* Maximum number of days between changes. */
50 long int sp_warn; /* Number of days to warn user to change
267ca16a 51 the password. */
19361cb7 52 long int sp_inact; /* Number of days the account may be
267ca16a 53 inactive. */
19361cb7 54 long int sp_expire; /* Number of days since 1970-01-01 until
dcf0671d 55 account expires. */
19361cb7
UD
56 unsigned long int sp_flag; /* Reserved. */
57 };
267ca16a
UD
58
59
2c008571 60/* Open database for reading.
267ca16a 61
2c008571
UD
62 This function is not part of POSIX and therefore no official
63 cancellation point. But due to similarity with an POSIX interface
64 or due to the implementation it is a cancellation point and
65 therefore not marked with __THROW. */
66extern void setspent (void);
267ca16a 67
2c008571 68/* Close database.
267ca16a 69
2c008571
UD
70 This function is not part of POSIX and therefore no official
71 cancellation point. But due to similarity with an POSIX interface
72 or due to the implementation it is a cancellation point and
73 therefore not marked with __THROW. */
74extern void endspent (void);
267ca16a 75
2c008571 76/* Get next entry from database, perhaps after opening the file.
267ca16a 77
2c008571
UD
78 This function is not part of POSIX and therefore no official
79 cancellation point. But due to similarity with an POSIX interface
80 or due to the implementation it is a cancellation point and
81 therefore not marked with __THROW. */
82extern struct spwd *getspent (void);
267ca16a 83
2c008571
UD
84/* Get shadow entry matching NAME.
85
86 This function is not part of POSIX and therefore no official
87 cancellation point. But due to similarity with an POSIX interface
88 or due to the implementation it is a cancellation point and
89 therefore not marked with __THROW. */
a784e502 90extern struct spwd *getspnam (const char *__name);
2c008571
UD
91
92/* Read shadow entry from STRING.
93
94 This function is not part of POSIX and therefore no official
95 cancellation point. But due to similarity with an POSIX interface
96 or due to the implementation it is a cancellation point and
97 therefore not marked with __THROW. */
a784e502 98extern struct spwd *sgetspent (const char *__string);
2c008571
UD
99
100/* Read next shadow entry from STREAM.
101
102 This function is not part of POSIX and therefore no official
103 cancellation point. But due to similarity with an POSIX interface
104 or due to the implementation it is a cancellation point and
105 therefore not marked with __THROW. */
106extern struct spwd *fgetspent (FILE *__stream);
107
841785ba 108/* Write line containing shadow entry to stream.
2c008571
UD
109
110 This function is not part of POSIX and therefore no official
111 cancellation point. But due to similarity with an POSIX interface
112 or due to the implementation it is a cancellation point and
113 therefore not marked with __THROW. */
a784e502 114extern int putspent (const struct spwd *__p, FILE *__stream);
267ca16a
UD
115
116
19361cb7 117#ifdef __USE_MISC
2c008571
UD
118/* Reentrant versions of some of the functions above.
119
120 These functions are not part of POSIX and therefore no official
121 cancellation point. But due to similarity with an POSIX interface
122 or due to the implementation they are cancellation points and
123 therefore not marked with __THROW. */
c1422e5b 124extern int getspent_r (struct spwd *__result_buf, char *__buffer,
2c008571 125 size_t __buflen, struct spwd **__result);
ba1ffaa1 126
a784e502 127extern int getspnam_r (const char *__name, struct spwd *__result_buf,
c1422e5b 128 char *__buffer, size_t __buflen,
2c008571 129 struct spwd **__result);
ba1ffaa1 130
a784e502 131extern int sgetspent_r (const char *__string, struct spwd *__result_buf,
c1422e5b 132 char *__buffer, size_t __buflen,
2c008571 133 struct spwd **__result);
ba1ffaa1 134
c1422e5b
UD
135extern int fgetspent_r (FILE *__stream, struct spwd *__result_buf,
136 char *__buffer, size_t __buflen,
2c008571 137 struct spwd **__result);
19361cb7 138#endif /* misc */
dcf0671d 139
2c008571
UD
140
141/* The simple locking functionality provided here is not suitable for
142 multi-threaded applications. */
143
841785ba 144/* Request exclusive access to /etc/passwd and /etc/shadow. */
c1422e5b 145extern int lckpwdf (void) __THROW;
dcf0671d 146
841785ba 147/* Release exclusive access to /etc/passwd and /etc/shadow. */
c1422e5b 148extern int ulckpwdf (void) __THROW;
dcf0671d 149
267ca16a
UD
150__END_DECLS
151
152#endif /* shadow.h */