diff options
| author | Christian Breunig <christian@breunig.cc> | 2025-12-17 21:36:47 +0100 |
|---|---|---|
| committer | GitHub <noreply@github.com> | 2025-12-17 21:36:47 +0100 |
| commit | 5a22bd6e6ba87c6666b8cacecb1e8c071b81f2cd (patch) | |
| tree | 6e044b10e3fa1648de2b6e8c6a3838da8e4dfa0d /src | |
| parent | 3d5ebd5956c4e4333e66097d6d339c2329c21295 (diff) | |
| parent | 197809bf77d841fe57bdcbaeeb3b078145aab140 (diff) | |
| download | vyos-1x-5a22bd6e6ba87c6666b8cacecb1e8c071b81f2cd.tar.gz vyos-1x-5a22bd6e6ba87c6666b8cacecb1e8c071b81f2cd.zip | |
Merge pull request #4892 from c-po/getpwall
login: T8086: replace getpwall() based user enumeration to avoid NSS/TACACS timeouts
Diffstat (limited to 'src')
| -rwxr-xr-x | src/conf_mode/system_login.py | 7 | ||||
| -rwxr-xr-x | src/op_mode/show_users.py | 8 | ||||
| -rw-r--r-- | src/tests/test_utils.py | 45 | ||||
| -rw-r--r-- | src/tests/test_utils_auth.py | 75 |
4 files changed, 83 insertions, 52 deletions
diff --git a/src/conf_mode/system_login.py b/src/conf_mode/system_login.py index 2692f427f..3cff7a806 100755 --- a/src/conf_mode/system_login.py +++ b/src/conf_mode/system_login.py @@ -21,8 +21,6 @@ import json from copy import deepcopy from passlib.hosts import linux_context from psutil import users -from pwd import getpwall -from pwd import getpwuid from sys import exit from time import sleep @@ -38,6 +36,7 @@ from vyos.template import is_ipv4 from vyos.utils.auth import EPasswdStrength from vyos.utils.auth import evaluate_strength from vyos.utils.auth import get_current_user +from vyos.utils.auth import get_local_passwd_entries from vyos.utils.auth import get_local_users from vyos.utils.auth import get_user_home_dir from vyos.utils.auth import MIN_USER_UID @@ -136,7 +135,7 @@ def verify(login): raise ConfigError(f'Attempting to delete current user: {tmp}') if 'user' in login: - system_users = getpwall() + system_users = get_local_passwd_entries() for user, user_config in login['user'].items(): # Linux system users range up until UID 1000, we can not create a # VyOS CLI user which already exists as system user @@ -432,7 +431,7 @@ def apply(login): # retrieve current owner of home directory and adjust on demand dir_owner = None try: - dir_owner = getpwuid(os.stat(home_dir).st_uid).pw_name + dir_owner = get_local_passwd_entries(os.stat(home_dir).st_uid).pw_name except: pass diff --git a/src/op_mode/show_users.py b/src/op_mode/show_users.py index bccfaf991..086c8b1e2 100755 --- a/src/op_mode/show_users.py +++ b/src/op_mode/show_users.py @@ -13,15 +13,15 @@ # # You should have received a copy of the GNU General Public License # along with this program. If not, see <http://www.gnu.org/licenses/>. + import argparse -import pwd import struct import sys from time import ctime from tabulate import tabulate from vyos.config import Config - +from vyos.utils.auth import get_local_passwd_entries class UserInfo: def __init__(self, uid, name, user_type, is_locked, login_time, tty, host): @@ -79,7 +79,9 @@ def list_users(): vyos_users = cfg.list_effective_nodes('system login user') users = [] with open('/var/log/lastlog', 'rb') as lastlog_file: - for (name, _, uid, _, _, _, _) in pwd.getpwall(): + for entry in get_local_passwd_entries(): + name = entry.pw_name + uid = entry.pw_uid lastlog_info = decode_lastlog(lastlog_file, uid) if lastlog_info is None: continue diff --git a/src/tests/test_utils.py b/src/tests/test_utils.py index 12fda84d0..9cf6f7a1e 100644 --- a/src/tests/test_utils.py +++ b/src/tests/test_utils.py @@ -12,12 +12,8 @@ # You should have received a copy of the GNU General Public License # along with this program. If not, see <http://www.gnu.org/licenses/>. -import pwd from unittest import TestCase -from vyos.utils import auth - - class TestVyOSUtils(TestCase): def test_key_mangling(self): from vyos.utils.dict import mangle_dict_keys @@ -41,44 +37,3 @@ class TestVyOSUtils(TestCase): self.assertEqual(list_strip(lst, rsb, right=True), ['a', 'b', 'c']) self.assertEqual(list_strip(lst, non), []) self.assertEqual(list_strip(sub, lst), []) - -class TestVyOSUtilsAuth(TestCase): - - def test_get_local_users_returns_existing_usernames(self): - # Returned users exist, skip list is excluded, and UIDs are in range - - all_users = set(s_user.pw_name for s_user in pwd.getpwall()) - local_users = auth.get_local_users() - - # All returned users must really exist - for user in local_users: - self.assertIn(user, all_users) - - # Nobody in the skip list - for skipped in auth.SYSTEM_USER_SKIP_LIST: - self.assertNotIn(skipped, local_users) - - # All are within UID range - for s_user in pwd.getpwall(): - if s_user.pw_name in local_users: - self.assertGreaterEqual(s_user.pw_uid, auth.MIN_USER_UID) - self.assertLessEqual(s_user.pw_uid, auth.MAX_USER_UID) - - def test_get_user_home_dir_for_real_user(self): - # User's homedir is a non-empty string for a valid user - - local_users = auth.get_local_users() - if local_users: - for user in local_users: - home_dir = auth.get_user_home_dir(user) - self.assertIsInstance(home_dir, str) - self.assertTrue(bool(home_dir)) # Should not be empty - else: - self.skipTest("No suitable non-system users found on this system") - - def test_get_user_home_dir_invalid_user(self): - # Raises KeyError for nonexistent username - - user = "__this_user_does_not_exist__" # Test using unlikely username - with self.assertRaises(KeyError): - auth.get_user_home_dir(user) diff --git a/src/tests/test_utils_auth.py b/src/tests/test_utils_auth.py new file mode 100644 index 000000000..f3b52ab29 --- /dev/null +++ b/src/tests/test_utils_auth.py @@ -0,0 +1,75 @@ +# Copyright VyOS maintainers and contributors <maintainers@vyos.io> +# +# This program is free software; you can redistribute it and/or modify +# it under the terms of the GNU General Public License version 2 or later as +# published by the Free Software Foundation. +# +# This program is distributed in the hope that it will be useful, +# but WITHOUT ANY WARRANTY; without even the implied warranty of +# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the +# GNU General Public License for more details. +# +# You should have received a copy of the GNU General Public License +# along with this program. If not, see <http://www.gnu.org/licenses/>. + +import pwd +import unittest + +from vyos.utils import auth + +class TestVyOSUtilsAuth(unittest.TestCase): + def test_uid_root(self): + self.assertEqual(auth.get_local_passwd_entries(0).pw_name, 'root') + self.assertEqual(auth.get_local_passwd_entries(0).pw_uid, 0) + + def test_uid_daemon(self): + uid = None + for user in auth.get_local_passwd_entries(): + if user.pw_name == 'daemon': + uid = user.pw_uid + break + + self.assertEqual(auth.get_local_passwd_entries(uid).pw_name, 'daemon') + self.assertEqual(auth.get_local_passwd_entries(uid).pw_uid, uid) + + def test_uid_not_found(self): + self.assertEqual(auth.get_local_passwd_entries(5465487635), None) + + def test_get_local_users_returns_existing_usernames(self): + # Returned users exist, skip list is excluded, and UIDs are in range + + all_users = set(s_user.pw_name for s_user in pwd.getpwall()) + local_users = auth.get_local_users() + + # All returned users must really exist + for user in local_users: + self.assertIn(user, all_users) + + # Nobody in the skip list + for skipped in auth.SYSTEM_USER_SKIP_LIST: + self.assertNotIn(skipped, local_users) + + # All are within UID range + for s_user in pwd.getpwall(): + if s_user.pw_name in local_users: + self.assertGreaterEqual(s_user.pw_uid, auth.MIN_USER_UID) + self.assertLessEqual(s_user.pw_uid, auth.MAX_USER_UID) + + def test_get_user_home_dir_for_real_user(self): + # User's homedir is a non-empty string for a valid user + + local_users = auth.get_local_users() + if local_users: + for user in local_users: + home_dir = auth.get_user_home_dir(user) + self.assertIsInstance(home_dir, str) + self.assertTrue(bool(home_dir)) # Should not be empty + else: + self.skipTest("No suitable non-system users found on this system") + + def test_get_user_home_dir_invalid_user(self): + # Raises KeyError for nonexistent username + + user = "__this_user_does_not_exist__" # Test using unlikely username + with self.assertRaises(KeyError): + auth.get_user_home_dir(user) |
