summaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authorChristian Breunig <christian@breunig.cc>2025-12-17 21:36:47 +0100
committerGitHub <noreply@github.com>2025-12-17 21:36:47 +0100
commit5a22bd6e6ba87c6666b8cacecb1e8c071b81f2cd (patch)
tree6e044b10e3fa1648de2b6e8c6a3838da8e4dfa0d /src
parent3d5ebd5956c4e4333e66097d6d339c2329c21295 (diff)
parent197809bf77d841fe57bdcbaeeb3b078145aab140 (diff)
downloadvyos-1x-5a22bd6e6ba87c6666b8cacecb1e8c071b81f2cd.tar.gz
vyos-1x-5a22bd6e6ba87c6666b8cacecb1e8c071b81f2cd.zip
Merge pull request #4892 from c-po/getpwall
login: T8086: replace getpwall() based user enumeration to avoid NSS/TACACS timeouts
Diffstat (limited to 'src')
-rwxr-xr-xsrc/conf_mode/system_login.py7
-rwxr-xr-xsrc/op_mode/show_users.py8
-rw-r--r--src/tests/test_utils.py45
-rw-r--r--src/tests/test_utils_auth.py75
4 files changed, 83 insertions, 52 deletions
diff --git a/src/conf_mode/system_login.py b/src/conf_mode/system_login.py
index 2692f427f..3cff7a806 100755
--- a/src/conf_mode/system_login.py
+++ b/src/conf_mode/system_login.py
@@ -21,8 +21,6 @@ import json
from copy import deepcopy
from passlib.hosts import linux_context
from psutil import users
-from pwd import getpwall
-from pwd import getpwuid
from sys import exit
from time import sleep
@@ -38,6 +36,7 @@ from vyos.template import is_ipv4
from vyos.utils.auth import EPasswdStrength
from vyos.utils.auth import evaluate_strength
from vyos.utils.auth import get_current_user
+from vyos.utils.auth import get_local_passwd_entries
from vyos.utils.auth import get_local_users
from vyos.utils.auth import get_user_home_dir
from vyos.utils.auth import MIN_USER_UID
@@ -136,7 +135,7 @@ def verify(login):
raise ConfigError(f'Attempting to delete current user: {tmp}')
if 'user' in login:
- system_users = getpwall()
+ system_users = get_local_passwd_entries()
for user, user_config in login['user'].items():
# Linux system users range up until UID 1000, we can not create a
# VyOS CLI user which already exists as system user
@@ -432,7 +431,7 @@ def apply(login):
# retrieve current owner of home directory and adjust on demand
dir_owner = None
try:
- dir_owner = getpwuid(os.stat(home_dir).st_uid).pw_name
+ dir_owner = get_local_passwd_entries(os.stat(home_dir).st_uid).pw_name
except:
pass
diff --git a/src/op_mode/show_users.py b/src/op_mode/show_users.py
index bccfaf991..086c8b1e2 100755
--- a/src/op_mode/show_users.py
+++ b/src/op_mode/show_users.py
@@ -13,15 +13,15 @@
#
# You should have received a copy of the GNU General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
+
import argparse
-import pwd
import struct
import sys
from time import ctime
from tabulate import tabulate
from vyos.config import Config
-
+from vyos.utils.auth import get_local_passwd_entries
class UserInfo:
def __init__(self, uid, name, user_type, is_locked, login_time, tty, host):
@@ -79,7 +79,9 @@ def list_users():
vyos_users = cfg.list_effective_nodes('system login user')
users = []
with open('/var/log/lastlog', 'rb') as lastlog_file:
- for (name, _, uid, _, _, _, _) in pwd.getpwall():
+ for entry in get_local_passwd_entries():
+ name = entry.pw_name
+ uid = entry.pw_uid
lastlog_info = decode_lastlog(lastlog_file, uid)
if lastlog_info is None:
continue
diff --git a/src/tests/test_utils.py b/src/tests/test_utils.py
index 12fda84d0..9cf6f7a1e 100644
--- a/src/tests/test_utils.py
+++ b/src/tests/test_utils.py
@@ -12,12 +12,8 @@
# You should have received a copy of the GNU General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
-import pwd
from unittest import TestCase
-from vyos.utils import auth
-
-
class TestVyOSUtils(TestCase):
def test_key_mangling(self):
from vyos.utils.dict import mangle_dict_keys
@@ -41,44 +37,3 @@ class TestVyOSUtils(TestCase):
self.assertEqual(list_strip(lst, rsb, right=True), ['a', 'b', 'c'])
self.assertEqual(list_strip(lst, non), [])
self.assertEqual(list_strip(sub, lst), [])
-
-class TestVyOSUtilsAuth(TestCase):
-
- def test_get_local_users_returns_existing_usernames(self):
- # Returned users exist, skip list is excluded, and UIDs are in range
-
- all_users = set(s_user.pw_name for s_user in pwd.getpwall())
- local_users = auth.get_local_users()
-
- # All returned users must really exist
- for user in local_users:
- self.assertIn(user, all_users)
-
- # Nobody in the skip list
- for skipped in auth.SYSTEM_USER_SKIP_LIST:
- self.assertNotIn(skipped, local_users)
-
- # All are within UID range
- for s_user in pwd.getpwall():
- if s_user.pw_name in local_users:
- self.assertGreaterEqual(s_user.pw_uid, auth.MIN_USER_UID)
- self.assertLessEqual(s_user.pw_uid, auth.MAX_USER_UID)
-
- def test_get_user_home_dir_for_real_user(self):
- # User's homedir is a non-empty string for a valid user
-
- local_users = auth.get_local_users()
- if local_users:
- for user in local_users:
- home_dir = auth.get_user_home_dir(user)
- self.assertIsInstance(home_dir, str)
- self.assertTrue(bool(home_dir)) # Should not be empty
- else:
- self.skipTest("No suitable non-system users found on this system")
-
- def test_get_user_home_dir_invalid_user(self):
- # Raises KeyError for nonexistent username
-
- user = "__this_user_does_not_exist__" # Test using unlikely username
- with self.assertRaises(KeyError):
- auth.get_user_home_dir(user)
diff --git a/src/tests/test_utils_auth.py b/src/tests/test_utils_auth.py
new file mode 100644
index 000000000..f3b52ab29
--- /dev/null
+++ b/src/tests/test_utils_auth.py
@@ -0,0 +1,75 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This program is free software; you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 2 or later as
+# published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program. If not, see <http://www.gnu.org/licenses/>.
+
+import pwd
+import unittest
+
+from vyos.utils import auth
+
+class TestVyOSUtilsAuth(unittest.TestCase):
+ def test_uid_root(self):
+ self.assertEqual(auth.get_local_passwd_entries(0).pw_name, 'root')
+ self.assertEqual(auth.get_local_passwd_entries(0).pw_uid, 0)
+
+ def test_uid_daemon(self):
+ uid = None
+ for user in auth.get_local_passwd_entries():
+ if user.pw_name == 'daemon':
+ uid = user.pw_uid
+ break
+
+ self.assertEqual(auth.get_local_passwd_entries(uid).pw_name, 'daemon')
+ self.assertEqual(auth.get_local_passwd_entries(uid).pw_uid, uid)
+
+ def test_uid_not_found(self):
+ self.assertEqual(auth.get_local_passwd_entries(5465487635), None)
+
+ def test_get_local_users_returns_existing_usernames(self):
+ # Returned users exist, skip list is excluded, and UIDs are in range
+
+ all_users = set(s_user.pw_name for s_user in pwd.getpwall())
+ local_users = auth.get_local_users()
+
+ # All returned users must really exist
+ for user in local_users:
+ self.assertIn(user, all_users)
+
+ # Nobody in the skip list
+ for skipped in auth.SYSTEM_USER_SKIP_LIST:
+ self.assertNotIn(skipped, local_users)
+
+ # All are within UID range
+ for s_user in pwd.getpwall():
+ if s_user.pw_name in local_users:
+ self.assertGreaterEqual(s_user.pw_uid, auth.MIN_USER_UID)
+ self.assertLessEqual(s_user.pw_uid, auth.MAX_USER_UID)
+
+ def test_get_user_home_dir_for_real_user(self):
+ # User's homedir is a non-empty string for a valid user
+
+ local_users = auth.get_local_users()
+ if local_users:
+ for user in local_users:
+ home_dir = auth.get_user_home_dir(user)
+ self.assertIsInstance(home_dir, str)
+ self.assertTrue(bool(home_dir)) # Should not be empty
+ else:
+ self.skipTest("No suitable non-system users found on this system")
+
+ def test_get_user_home_dir_invalid_user(self):
+ # Raises KeyError for nonexistent username
+
+ user = "__this_user_does_not_exist__" # Test using unlikely username
+ with self.assertRaises(KeyError):
+ auth.get_user_home_dir(user)