/
usr
/
sbin
/
/usr/sbin
mkdir
upload
Name
Size
Mode
Actions
a2disconf
16276
0755
edit
dl
rm
a2dismod
16276
0755
edit
dl
rm
a2dissite
16276
0755
edit
dl
rm
a2enconf
16276
0755
edit
dl
rm
a2enmod
16276
0755
edit
dl
rm
a2ensite
16276
0755
edit
dl
rm
a2query
9870
0755
edit
dl
rm
aa-remove-unknown
3068
0755
edit
dl
rm
aa-status
64120
0755
edit
dl
rm
aa-teardown
137
0755
edit
dl
rm
accessdb
14904
0755
edit
dl
rm
add-shell
1051
0755
edit
dl
rm
addgnupghome
3075
0755
edit
dl
rm
addgroup
38247
0755
edit
dl
rm
adduser
38247
0755
edit
dl
rm
agetty
56896
0755
edit
dl
rm
apache2
758736
0755
edit
dl
rm
apache2ctl
7229
0755
edit
dl
rm
apachectl
7229
0755
edit
dl
rm
apparmor_parser
1548064
0755
edit
dl
rm
apparmor_status
64120
0755
edit
dl
rm
applygnupgdefaults
2217
0755
edit
dl
rm
arp
63088
0755
edit
dl
rm
arpd
26960
0755
edit
dl
rm
arptables
224296
0755
edit
dl
rm
arptables-nft
224296
0755
edit
dl
rm
arptables-nft-restore
224296
0755
edit
dl
rm
arptables-nft-save
224296
0755
edit
dl
rm
arptables-restore
224296
0755
edit
dl
rm
arptables-save
224296
0755
edit
dl
rm
badblocks
35144
0755
edit
dl
rm
bcache-super-show
14648
0755
edit
dl
rm
biosdecode
23760
0755
edit
dl
rm
blkdeactivate
16351
0755
edit
dl
rm
blkdiscard
22912
0755
edit
dl
rm
blkid
51624
0755
edit
dl
rm
blkzone
35200
0755
edit
dl
rm
blockdev
31104
0755
edit
dl
rm
bridge
94712
0755
edit
dl
rm
cache_check
1389608
0755
edit
dl
rm
cache_dump
1389608
0755
edit
dl
rm
cache_metadata_size
1389608
0755
edit
dl
rm
cache_repair
1389608
0755
edit
dl
rm
cache_restore
1389608
0755
edit
dl
rm
cache_writeback
1389608
0755
edit
dl
rm
capsh
31032
0755
edit
dl
rm
cfdisk
97008
0755
edit
dl
rm
cgdisk
154096
0755
edit
dl
rm
chcpu
31104
0755
edit
dl
rm
check_forensic
952
0755
edit
dl
rm
chgpasswd
59528
0755
edit
dl
rm
chmem
35200
0755
edit
dl
rm
chpasswd
55464
0755
edit
dl
rm
chroot
39432
0755
edit
dl
rm
cpgr
49448
0755
edit
dl
rm
cppw
49448
0755
edit
dl
rm
cron
51792
0755
edit
dl
rm
cryptdisks_start
1544
0755
edit
dl
rm
cryptdisks_stop
844
0755
edit
dl
rm
cryptsetup
173616
0755
edit
dl
rm
cryptsetup-reencrypt
92544
0755
edit
dl
rm
cryptsetup-ssh
24096
0755
edit
dl
rm
ctrlaltdel
14720
0755
edit
dl
rm
dbconfig-generate-include
12656
0755
edit
dl
rm
dbconfig-load-include
5704
0755
edit
dl
rm
dcb
82448
0755
edit
dl
rm
debugfs
235320
0755
edit
dl
rm
delgroup
16495
0755
edit
dl
rm
deluser
16495
0755
edit
dl
rm
depmod
170352
0755
edit
dl
rm
devlink
146288
0755
edit
dl
rm
dhclient
453280
0755
edit
dl
rm
dhclient-script
16304
0755
edit
dl
rm
dmeventd
51592
0755
edit
dl
rm
dmidecode
125936
0755
edit
dl
rm
dmsetup
175128
0755
edit
dl
rm
dmstats
175128
0755
edit
dl
rm
dosfsck
84360
0755
edit
dl
rm
dosfslabel
39304
0755
edit
dl
rm
dpkg-preconfigure
3663
0755
edit
dl
rm
dpkg-reconfigure
4485
0755
edit
dl
rm
dumpe2fs
31040
0755
edit
dl
rm
e2freefrag
14648
0755
edit
dl
rm
e2fsck
360280
0755
edit
dl
rm
e2image
43328
0755
edit
dl
rm
e2label
105016
0755
edit
dl
rm
e2mmpstatus
31040
0755
edit
dl
rm
e2scrub
7296
0755
edit
dl
rm
e2scrub_all
5395
0755
edit
dl
rm
e2undo
22840
0755
edit
dl
rm
e4crypt
31104
0755
edit
dl
rm
e4defrag
31032
0755
edit
dl
rm
ebtables
224296
0755
edit
dl
rm
ebtables-nft
224296
0755
edit
dl
rm
ebtables-nft-restore
224296
0755
edit
dl
rm
ebtables-nft-save
224296
0755
edit
dl
rm
ebtables-restore
224296
0755
edit
dl
rm
ebtables-save
224296
0755
edit
dl
rm
era_check
1389608
0755
edit
dl
rm
era_dump
1389608
0755
edit
dl
rm
era_invalidate
1389608
0755
edit
dl
rm
era_restore
1389608
0755
edit
dl
rm
escapesrc
22992
0755
edit
dl
rm
ethtool
564712
0755
edit
dl
rm
faillock
14488
0755
edit
dl
rm
fatlabel
39304
0755
edit
dl
rm
fdisk
113072
0755
edit
dl
rm
filefrag
18760
0755
edit
dl
rm
findfs
14720
0755
edit
dl
rm
fixparts
59880
0755
edit
dl
rm
fsadm
24519
0755
edit
dl
rm
fsck
43440
0755
edit
dl
rm
fsck.btrfs
1185
0755
edit
dl
rm
fsck.cramfs
31168
0755
edit
dl
rm
fsck.ext2
360280
0755
edit
dl
rm
fsck.ext3
360280
0755
edit
dl
rm
fsck.ext4
360280
0755
edit
dl
rm
fsck.fat
84360
0755
edit
dl
rm
fsck.minix
55712
0755
edit
dl
rm
fsck.msdos
84360
0755
edit
dl
rm
fsck.vfat
84360
0755
edit
dl
rm
fsck.xfs
1940
0755
edit
dl
rm
fsfreeze
14720
0755
edit
dl
rm
fstab-decode
18744
0755
edit
dl
rm
fstrim
43392
0755
edit
dl
rm
gdisk
178672
0755
edit
dl
rm
genccode
15088
0755
edit
dl
rm
gencmn
15088
0755
edit
dl
rm
genl
92608
0755
edit
dl
rm
gennorm2
64408
0755
edit
dl
rm
gensprep
27448
0755
edit
dl
rm
getcap
14648
0755
edit
dl
rm
getpcaps
14648
0755
edit
dl
rm
getty
56896
0755
edit
dl
rm
groupadd
68520
0755
edit
dl
rm
groupdel
64232
0755
edit
dl
rm
groupmems
55488
0755
edit
dl
rm
groupmod
68424
0755
edit
dl
rm
grpck
59528
0755
edit
dl
rm
grpconv
51208
0755
edit
dl
rm
grpunconv
51208
0755
edit
dl
rm
grub-bios-setup
964016
0755
edit
dl
rm
grub-install
1204128
0755
edit
dl
rm
grub-macbless
951408
0755
edit
dl
rm
grub-mkconfig
8805
0755
edit
dl
rm
grub-mkdevicemap
220880
0755
edit
dl
rm
grub-probe
963952
0755
edit
dl
rm
grub-reboot
4841
0755
edit
dl
rm
grub-set-default
3556
0755
edit
dl
rm
halt
1119856
0755
edit
dl
rm
hdparm
142776
0755
edit
dl
rm
httxt2dbm
14648
0755
edit
dl
rm
hwclock
51712
0755
edit
dl
rm
iconvconfig
31128
0755
edit
dl
rm
icupkg
23656
0755
edit
dl
rm
ifconfig
79024
0755
edit
dl
rm
init
1849992
0755
edit
dl
rm
insmod
170352
0755
edit
dl
rm
installkernel
2659
0755
edit
dl
rm
integritysetup
55368
0755
edit
dl
rm
invoke-rc.d
16507
0755
edit
dl
rm
ip
718896
0755
edit
dl
rm
ip6tables
224296
0755
edit
dl
rm
ip6tables-apply
7057
0755
edit
dl
rm
ip6tables-legacy
99272
0755
edit
dl
rm
ip6tables-legacy-restore
99272
0755
edit
dl
rm
ip6tables-legacy-save
99272
0755
edit
dl
rm
ip6tables-nft
224296
0755
edit
dl
rm
ip6tables-nft-restore
224296
0755
edit
dl
rm
ip6tables-nft-save
224296
0755
edit
dl
rm
ip6tables-restore
224296
0755
edit
dl
rm
ip6tables-restore-translate
224296
0755
edit
dl
rm
ip6tables-save
224296
0755
edit
dl
rm
ip6tables-translate
224296
0755
edit
dl
rm
ipmaddr
18744
0755
edit
dl
rm
iptables
224296
0755
edit
dl
rm
iptables-apply
7057
0755
edit
dl
rm
iptables-legacy
99272
0755
edit
dl
rm
iptables-legacy-restore
99272
0755
edit
dl
rm
iptables-legacy-save
99272
0755
edit
dl
rm
iptables-nft
224296
0755
edit
dl
rm
iptables-nft-restore
224296
0755
edit
dl
rm
iptables-nft-save
224296
0755
edit
dl
rm
iptables-restore
224296
0755
edit
dl
rm
iptables-restore-translate
224296
0755
edit
dl
rm
iptables-save
224296
0755
edit
dl
rm
iptables-translate
224296
0755
edit
dl
rm
iptunnel
18744
0755
edit
dl
rm
irqbalance
68464
0755
edit
dl
rm
irqbalance-ui
35208
0755
edit
dl
rm
iscsi-iname
14648
0755
edit
dl
rm
iscsiadm
408024
0755
edit
dl
rm
iscsid
305720
0755
edit
dl
rm
iscsistart
285248
0755
edit
dl
rm
iscsi_discovery
5293
0755
edit
dl
rm
isosize
14720
0755
edit
dl
rm
iucode-tool
59736
0755
edit
dl
rm
iucode_tool
59736
0755
edit
dl
rm
kbdrate
18600
0755
edit
dl
rm
killall5
31112
0755
edit
dl
rm
kpartx
47272
0755
edit
dl
rm
ldattach
27008
0755
edit
dl
rm
ldconfig
387
0755
edit
dl
rm
ldconfig.real
1213960
0755
edit
dl
rm
locale-gen
4398
0755
edit
dl
rm
logrotate
104696
0755
edit
dl
rm
logsave
14496
0755
edit
dl
rm
losetup
72208
0755
edit
dl
rm
lsmod
170352
0755
edit
dl
rm
luksformat
3401
0755
edit
dl
rm
lvchange
3027544
0755
edit
dl
rm
lvconvert
3027544
0755
edit
dl
rm
lvcreate
3027544
0755
edit
dl
rm
lvdisplay
3027544
0755
edit
dl
rm
lvextend
3027544
0755
edit
dl
rm
lvm
3027544
0755
edit
dl
rm
lvmconfig
3027544
0755
edit
dl
rm
lvmdiskscan
3027544
0755
edit
dl
rm
lvmdump
10312
0755
edit
dl
rm
lvmpolld
241864
0755
edit
dl
rm
lvmsadc
3027544
0755
edit
dl
rm
lvmsar
3027544
0755
edit
dl
rm
lvreduce
3027544
0755
edit
dl
rm
lvremove
3027544
0755
edit
dl
rm
lvrename
3027544
0755
edit
dl
rm
lvresize
3027544
0755
edit
dl
rm
lvs
3027544
0755
edit
dl
rm
lvscan
3027544
0755
edit
dl
rm
make-bcache
22912
0755
edit
dl
rm
make-ssl-cert
6812
0755
edit
dl
rm
mdadm
615744
0755
edit
dl
rm
mdmon
264640
0755
edit
dl
rm
mii-tool
27376
0755
edit
dl
rm
mkdosfs
52048
0755
edit
dl
rm
mke2fs
133752
0755
edit
dl
rm
mkfs
14720
0755
edit
dl
rm
mkfs.bfs
22912
0755
edit
dl
rm
mkfs.btrfs
482560
0755
edit
dl
rm
mkfs.cramfs
35144
0755
edit
dl
rm
mkfs.ext2
133752
0755
edit
dl
rm
mkfs.ext3
133752
0755
edit
dl
rm
mkfs.ext4
133752
0755
edit
dl
rm
mkfs.fat
52048
0755
edit
dl
rm
mkfs.minix
43408
0755
edit
dl
rm
mkfs.msdos
52048
0755
edit
dl
rm
mkfs.ntfs
72072
0755
edit
dl
rm
mkfs.vfat
52048
0755
edit
dl
rm
mkfs.xfs
391960
0755
edit
dl
rm
mkhomedir_helper
22704
0755
edit
dl
rm
mkinitramfs
12453
0755
edit
dl
rm
mklost+found
14648
0755
edit
dl
rm
mkntfs
72072
0755
edit
dl
rm
mkswap
47496
0755
edit
dl
rm
ModemManager
2194240
0755
edit
dl
rm
modinfo
170352
0755
edit
dl
rm
modprobe
170352
0755
edit
dl
rm
mount.fuse
18736
0755
edit
dl
rm
mount.fuse3
18736
0755
edit
dl
rm
mount.lowntfs-3g
117736
0755
edit
dl
rm
mount.ntfs
162824
0755
edit
dl
rm
mount.ntfs-3g
162824
0755
edit
dl
rm
mpathpersist
31800
0755
edit
dl
rm
multipath
34968
0755
edit
dl
rm
multipathd
137480
0755
edit
dl
rm
mysqld
55604728
0755
edit
dl
rm
nameif
14824
0755
edit
dl
rm
needrestart
39658
0755
edit
dl
rm
netplan
798
0755
edit
dl
rm
netwatch
337664
0755
edit
dl
rm
newusers
76520
0755
edit
dl
rm
nfnl_osf
18736
0755
edit
dl
rm
nft
26856
0755
edit
dl
rm
nginx
1240552
0755
edit
dl
rm
nologin
14640
0755
edit
dl
rm
ntfsclone
51592
0755
edit
dl
rm
ntfscp
35200
0755
edit
dl
rm
ntfslabel
22912
0755
edit
dl
rm
ntfsresize
63888
0755
edit
dl
rm
ntfsundelete
51592
0755
edit
dl
rm
on_ac_power
3788
0755
edit
dl
rm
overlayroot-chroot
2510
0755
edit
dl
rm
ownership
14792
0755
edit
dl
rm
pam-auth-update
20992
0755
edit
dl
rm
pam_extrausers_chkpwd
22680
2755
edit
dl
rm
pam_extrausers_update
30872
0755
edit
dl
rm
pam_getenv
2890
0755
edit
dl
rm
pam_timestamp_check
14488
0755
edit
dl
rm
paperconfig
4170
0755
edit
dl
rm
parted
88472
0755
edit
dl
rm
partprobe
14720
0755
edit
dl
rm
pdata_tools
1389608
0755
edit
dl
rm
php-fpm8.1
5553448
0755
edit
dl
rm
php-fpm8.3
5780304
0755
edit
dl
rm
php-fpm8.5
10280440
0755
edit
dl
rm
phpdismod
7278
0755
edit
dl
rm
phpenmod
7278
0755
edit
dl
rm
phpquery
6389
0755
edit
dl
rm
pivot_root
14720
0755
edit
dl
rm
plipconfig
14648
0755
edit
dl
rm
plymouthd
154168
0755
edit
dl
rm
postalias
22832
0755
edit
dl
rm
postcat
22904
0755
edit
dl
rm
postconf
188208
0755
edit
dl
rm
postdrop
22960
2555
edit
dl
rm
postfix
18816
0755
edit
dl
rm
postfix-add-filter
4954
0755
edit
dl
rm
postfix-add-policy
3860
0755
edit
dl
rm
postfix-collate
2942
0755
edit
dl
rm
postkick
14640
0755
edit
dl
rm
postlock
14640
0755
edit
dl
rm
postlog
14800
0755
edit
dl
rm
postmap
22832
0755
edit
dl
rm
postmulti
31424
0755
edit
dl
rm
postqueue
22912
2555
edit
dl
rm
postsuper
31328
0755
edit
dl
rm
posttls-finger
43400
0755
edit
dl
rm
poweroff
1119856
0755
edit
dl
rm
pvchange
3027544
0755
edit
dl
rm
pvck
3027544
0755
edit
dl
rm
pvcreate
3027544
0755
edit
dl
rm
pvdisplay
3027544
0755
edit
dl
rm
pvmove
3027544
0755
edit
dl
rm
pvremove
3027544
0755
edit
dl
rm
pvresize
3027544
0755
edit
dl
rm
pvs
3027544
0755
edit
dl
rm
pvscan
3027544
0755
edit
dl
rm
pwck
51336
0755
edit
dl
rm
pwconv
47112
0755
edit
dl
rm
pwunconv
43016
0755
edit
dl
rm
qmqp-sink
18736
0755
edit
dl
rm
qmqp-source
22848
0755
edit
dl
rm
qshape
12849
0755
edit
dl
rm
rarp
33104
0755
edit
dl
rm
readprofile
22944
0755
edit
dl
rm
reboot
1119856
0755
edit
dl
rm
remove-shell
1099
0755
edit
dl
rm
resize2fs
67896
0755
edit
dl
rm
rmail
18736
0755
edit
dl
rm
rmmod
170352
0755
edit
dl
rm
rmt
59976
0755
edit
dl
rm
rmt-tar
59976
0755
edit
dl
rm
route
65808
0755
edit
dl
rm
rsyslogd
785600
0755
edit
dl
rm
rtacct
28992
0755
edit
dl
rm
rtcwake
35200
0755
edit
dl
rm
rtmon
92560
0755
edit
dl
rm
runlevel
1119856
0755
edit
dl
rm
runuser
55680
0755
edit
dl
rm
sendmail
31184
0755
edit
dl
rm
service
9097
0755
edit
dl
rm
setcap
14648
0755
edit
dl
rm
setvesablank
14568
0755
edit
dl
rm
setvtrgb
14632
0755
edit
dl
rm
sfdisk
104832
0755
edit
dl
rm
sgdisk
166384
0755
edit
dl
rm
shadowconfig
885
0755
edit
dl
rm
shutdown
1119856
0755
edit
dl
rm
slattach
36944
0755
edit
dl
rm
smtp-sink
36112
0755
edit
dl
rm
smtp-source
31048
0755
edit
dl
rm
split-logfile
2415
0755
edit
dl
rm
sshd
921288
0755
edit
dl
rm
start-stop-daemon
48488
0755
edit
dl
rm
statnetd
35032
0755
edit
dl
rm
sudo_logsrvd
204904
0755
edit
dl
rm
sudo_sendlog
109912
0755
edit
dl
rm
sulogin
43392
0755
edit
dl
rm
swaplabel
18816
0755
edit
dl
rm
swapoff
22912
0755
edit
dl
rm
swapon
43392
0755
edit
dl
rm
switch_root
22912
0755
edit
dl
rm
sysctl
30960
0755
edit
dl
rm
tarcat
936
0755
edit
dl
rm
tc
628816
0755
edit
dl
rm
tcpblast
35456
0755
edit
dl
rm
telinit
1119856
0755
edit
dl
rm
thermald
567912
0755
edit
dl
rm
thin_check
1389608
0755
edit
dl
rm
thin_delta
1389608
0755
edit
dl
rm
thin_dump
1389608
0755
edit
dl
rm
thin_ls
1389608
0755
edit
dl
rm
thin_metadata_size
1389608
0755
edit
dl
rm
thin_repair
1389608
0755
edit
dl
rm
thin_restore
1389608
0755
edit
dl
rm
thin_rmap
1389608
0755
edit
dl
rm
thin_trim
1389608
0755
edit
dl
rm
tipc
92608
0755
edit
dl
rm
trafshow
130592
0755
edit
dl
rm
tune2fs
105016
0755
edit
dl
rm
tzconfig
106
0755
edit
dl
rm
udpblast
35456
0755
edit
dl
rm
ufw
4938
0755
edit
dl
rm
umount.udisks2
14640
0755
edit
dl
rm
unix_chkpwd
26776
2755
edit
dl
rm
unix_update
30872
0755
edit
dl
rm
update-ca-certificates
5418
0755
edit
dl
rm
update-grub
64
0755
edit
dl
rm
update-grub-gfxpayload
301
0755
edit
dl
rm
update-grub2
64
0755
edit
dl
rm
update-gsfontmap
470
0755
edit
dl
rm
update-info-dir
1700
0755
edit
dl
rm
update-initramfs
6906
0755
edit
dl
rm
update-locale
3063
0755
edit
dl
rm
update-mime
9613
0755
edit
dl
rm
update-passwd
35392
0755
edit
dl
rm
update-pciids
1753
0755
edit
dl
rm
update-rc.d
17324
0755
edit
dl
rm
update-secureboot-policy
7605
0755
edit
dl
rm
update-shells
3806
0755
edit
dl
rm
upgrade-from-grub-legacy
1596
0755
edit
dl
rm
usbmuxd
88680
0755
edit
dl
rm
usb_modeswitch
61096
0755
edit
dl
rm
usb_modeswitch_dispatcher
27418
0755
edit
dl
rm
useradd
130720
0755
edit
dl
rm
userdel
88936
0755
edit
dl
rm
usermod
126424
0755
edit
dl
rm
uuidd
31592
0755
edit
dl
rm
validlocale
1773
0755
edit
dl
rm
vcstime
14488
0755
edit
dl
rm
vdpa
31296
0755
edit
dl
rm
veritysetup
44808
0755
edit
dl
rm
vgcfgbackup
3027544
0755
edit
dl
rm
vgcfgrestore
3027544
0755
edit
dl
rm
vgchange
3027544
0755
edit
dl
rm
vgck
3027544
0755
edit
dl
rm
vgconvert
3027544
0755
edit
dl
rm
vgcreate
3027544
0755
edit
dl
rm
vgdisplay
3027544
0755
edit
dl
rm
vgexport
3027544
0755
edit
dl
rm
vgextend
3027544
0755
edit
dl
rm
vgimport
3027544
0755
edit
dl
rm
vgimportclone
3027544
0755
edit
dl
rm
vgmerge
3027544
0755
edit
dl
rm
vgmknodes
3027544
0755
edit
dl
rm
vgreduce
3027544
0755
edit
dl
rm
vgremove
3027544
0755
edit
dl
rm
vgrename
3027544
0755
edit
dl
rm
vgs
3027544
0755
edit
dl
rm
vgscan
3027544
0755
edit
dl
rm
vgsplit
3027544
0755
edit
dl
rm
vigr
57888
0755
edit
dl
rm
vipw
57888
0755
edit
dl
rm
visudo
225064
0755
edit
dl
rm
vpddecode
14928
0755
edit
dl
rm
wipefs
39296
0755
edit
dl
rm
xfs_admin
1407
0755
edit
dl
rm
xfs_bmap
695
0755
edit
dl
rm
xfs_copy
84464
0755
edit
dl
rm
xfs_db
668096
0755
edit
dl
rm
xfs_estimate
14504
0755
edit
dl
rm
xfs_freeze
800
0755
edit
dl
rm
xfs_fsr
43192
0755
edit
dl
rm
xfs_growfs
39200
0755
edit
dl
rm
xfs_info
1294
0755
edit
dl
rm
xfs_io
204344
0755
edit
dl
rm
xfs_logprint
80208
0755
edit
dl
rm
xfs_mdrestore
26800
0755
edit
dl
rm
xfs_metadump
782
0755
edit
dl
rm
xfs_mkfile
1040
0755
edit
dl
rm
xfs_ncheck
685
0755
edit
dl
rm
xfs_quota
92328
0755
edit
dl
rm
xfs_repair
613768
0755
edit
dl
rm
xfs_rtcp
18584
0755
edit
dl
rm
xfs_scrub
108816
0755
edit
dl
rm
xfs_scrub_all
6006
0755
edit
dl
rm
xfs_spaceman
43320
0755
edit
dl
rm
xtables-legacy-multi
99272
0755
edit
dl
rm
xtables-monitor
224296
0755
edit
dl
rm
xtables-nft-multi
224296
0755
edit
dl
rm
zerofree
14488
0755
edit
dl
rm
zic
63816
0755
edit
dl
rm
zramctl
55824
0755
edit
dl
rm
Edit:
/usr/sbin/pam-auth-update
(20992B)
#!/usr/bin/perl -w # pam-auth-update: update /etc/pam.d/common-* from /usr/share/pam-configs # # Update the /etc/pam.d/common-* files based on the per-package profiles # provided in /usr/share/pam-configs/ taking into consideration user's # preferences (as determined via debconf prompting). # # Written by Steve Langasek <steve.langasek@canonical.com> # # Copyright (C) 2008 Canonical Ltd. # # This program is free software; you can redistribute it and/or modify # it under the terms of version 3 of the GNU General Public License as # published by the Free Software Foundation. # # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the # GNU General Public License for more details. # # You should have received a copy of the GNU General Public License # along with this program; if not, write to the Free Software # Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, # USA. use strict; use Debconf::Client::ConfModule ':all'; use IPC::Open2 'open2'; version('2.0'); my $capb=capb('backup escape'); my $inputdir = '/usr/share/pam-configs'; my $template = 'libpam-runtime/profiles'; my $errtemplate = 'libpam-runtime/conflicts'; my $overridetemplate = 'libpam-runtime/override'; my $blanktemplate = 'libpam-runtime/no_profiles_chosen'; my $titletemplate = 'libpam-runtime/title'; my $confdir = '/etc/pam.d'; my $savedir = '/var/lib/pam'; my (%profiles, @sorted, @enabled, @conflicts, @new, %removals, %to_enable); my $force = 0; my $package = 0; my $priority = 'high'; my %md5sums = ( 'auth' => ['8d4fe17e66ba25de16a117035d1396aa'], 'account' => ['3c0c362eaf3421848b679d63fd48c3fa'], 'password' => [ '4d5c92d595a46b69cd61f18feb4c0574', '50fce2113dfda83ac8bdd5a6e706caec', '4bd7610f2e85f8ddaef79c7db7cb49eb', '9ba753d0824276b44bcadfee1f87b6bc', ], 'session' => [ 'f297c731a467822cbd86e1283263e8a3', '240fb92986c885b327cdb21dd641da8c', '4a25673e8b36f1805219027d3be02cd2', 'd38511a6ce8324742c151eed9fb57ba1', ], 'session-noninteractive' => [ 'ad2b78ce1498dd637ef36469430b6ac6', 'a20e8df3469bfe25c13a3b39161b30f0', ], ); my @invalid_modules = ('pam_tally'); opendir(DIR, $inputdir) || die "could not open config directory: $!"; while (my $profile = readdir(DIR)) { next if ($profile eq '.' || $profile eq '..' || $profile =~ m/~$/ || $profile =~ m/^#.+#$/); %{$profiles{$profile}} = parse_pam_profile($inputdir . '/' . $profile); if (defined $profiles{$profile}{'disabled'} and $profiles{$profile}{'disabled'}) { delete $profiles{$profile}; } } closedir DIR; # use a '--force' arg to specify that /etc/pam.d should be overwritten; # used only on upgrades where the postinst has already determined that the # checksums match. Module packages other than libpam-runtime itself must # NEVER use this option! Document with big skullses and crossboneses! It # needs to be exposed for libpam-runtime because that's the package that # decides whether we have a pristine config to be converted, and knows # whether the version being upgraded from is one for which the conversion # should be done. while ($#ARGV >= 0) { my $opt = shift; if ($opt eq '--force') { $force = 1; } elsif ($opt eq '--package') { $package = 1; } elsif ($opt eq '--root') { my $rootdir = shift @ARGV; $savedir = "${rootdir}$savedir"; $confdir = "${rootdir}$confdir"; $inputdir = "${rootdir}$inputdir"; } elsif ($opt eq '--remove') { while ($#ARGV >= 0) { last if ($ARGV[0] =~ /^--/); $removals{shift @ARGV} = 1; } # --remove implies --package $package = 1 if (keys(%removals)); } elsif ($opt eq '--enable') { while ($#ARGV >= 0) { last if ($ARGV[0] =~ /^--/); $to_enable{shift @ARGV} = 1; } # --enable implies --package $package = 1 if (keys(%to_enable)); } } $priority = 'medium' if ($package); x_loadtemplatefile('/var/lib/dpkg/info/libpam-runtime.templates','libpam-runtime'); # always sort by priority, so we have consistency and don't have to # shuffle later @sorted = sort { $profiles{$b}->{'Priority'} <=> $profiles{$a}->{'Priority'} || $b cmp $a } keys(%profiles); # If we're being called for package removal, filter out those options here @sorted = grep { !$removals{$_} } @sorted; subst($template, 'profile_names', join(', ',@sorted)); subst($template, 'profiles', join(', ', map { $profiles{$_}->{'Name'} } @sorted)); my $diff = diff_profiles($confdir,$savedir); if ($diff) { @enabled = grep { !$removals{$_} } @{$diff->{'mods'}}; } else { @enabled = split(/, /,get($template)); } # find out what we've seen, so we can ignore those defaults my %seen; if (-e $savedir . '/seen') { open(SEEN,$savedir . '/seen') or die("open(${savedir}/seen) failed: $!"); while (<SEEN>) { chomp; $seen{$_} = 1; } close(SEEN); } # filter out any options that are no longer available for any reason @enabled = grep { $profiles{$_} } @enabled; # an empty module set is an error, so in that case grab all the defaults if (!@enabled) { %seen = (); $priority = 'high' unless ($force); } # add configs to enable push(@enabled, grep { $to_enable{$_} } @sorted); # add any previously-unseen configs push(@enabled, grep { $profiles{$_}->{'Default'} eq 'yes' && !$seen{$_} } @sorted); @enabled = sort { $profiles{$b}->{'Priority'} <=> $profiles{$a}->{'Priority'} || $b cmp $a } @enabled; my $prev = ''; @enabled = grep { $_ ne $prev && (($prev) = $_) } @enabled; # Do we have any new options to show? If not, we shouldn't reprompt the # user, at any priority level, unless explicitly called. @new = grep { !$seen{$_} } @sorted; settitle($titletemplate); # if diff_profiles() fails, and we weren't passed a 'force' argument # (because this isn't an upgrade from an old version, or the checksum # didn't match, or we're being called by some other module package), prompt # the user whether to override. If the user declines (the default), we # never again manage this config unless manually called with '--force'. if (!$diff && !$force) { input('high',$overridetemplate); go(); $force = 1 if (get($overridetemplate) eq 'true'); } if (!$diff && !$force) { print STDERR <<EOF; pam-auth-update: Local modifications to /etc/pam.d/common-*, not updating. pam-auth-update: Run pam-auth-update --force to override. EOF exit; } umask(0022); do { @conflicts = (); if (@new || !$package) { fset($template,'seen','false'); } set($template,join(', ', @enabled)); input($priority,$template); go(); @enabled = split(/, /, get($template)); # in case of conflicts, automatically unset the lower priority # item of each pair foreach my $elem (@enabled) { for (my $i=$#enabled; $i >= 0; $i--) { my $conflict = $enabled[$i]; if ($profiles{$elem}->{'Conflicts'}->{$conflict}) { splice(@enabled,$i,1); my $desc = $profiles{$elem}->{'Name'} . ', ' . $profiles{$conflict}->{'Name'}; push(@conflicts,$desc); } } } if (@conflicts) { subst($errtemplate, 'conflicts', join("\\n", @conflicts)); input('high',$errtemplate); } set($template, join(', ', @enabled)); if (!@enabled) { input('high',$blanktemplate); # we can only end up here by user error, but give them another # shot at selecting a correct config anyway. fset($template,'seen','false'); } } while (@conflicts || !@enabled); # the decision has been made about what configs to use, so even if # something fails after this, we shouldn't go munging the default # options again. Save the list of known configs to /var/lib/pam. open(SEEN,"> $savedir/seen") or die("open(${savedir}/seen) failed: $!"); for my $i (@sorted) { print SEEN "$i\n"; } close(SEEN) or die("close(${savedir}/seen) failed: $!"); # @enabled now contains our list of profiles to use for piecing together # a config # we have: # - templates into which we insert the specialness # - magic comments denoting the beginning and end of our managed block; # looking at only the functional config lines would potentially let us # handle more cases, at the expense of much greater complexity, so # pass on this at least for the first round # - a representation of the autogenerated config stored in /var/lib/pam, # that we can diff against in order to account for changed options or # manually dropped modules # - a hash describing the local modifications the user has made to the # config; these are always preserved unless manually overridden with # the --force option write_profiles(\%profiles, \@enabled, $confdir, $savedir, $diff, $force); # take a single line from a stock config, and merge it with the # information about local admin edits sub merge_one_line { my ($line,$diff,$count) = @_; my (@opts,$modline); my ($adds,$removes); $line =~ /^((\[[^]]+\]|\w+)\s+\S+)\s*(.*)/; @opts = split(/\s+/,$3); $modline = $1; $modline =~ s/end/$count/g; if ($diff) { my $mod = $modline; $mod =~ s/(\[[^0-9]*)[0-9]+(.*\])/$1$2/g; $adds = \%{$diff->{'add'}{$mod}}; $removes = \%{$diff->{'remove'}{$mod}}; } else { $adds = $removes = undef; } for (my $i = 0; $i <= $#opts; $i++) { if ($adds->{$opts[$i]}) { delete $adds->{$opts[$i]}; } if ($removes->{$opts[$i]}) { splice(@opts,$i,1); $i--; } } return $modline . " " . join(' ',@opts,sort keys(%{$adds})) . "\n"; } # return the lines for a given config name, type, and position in the stack sub lines_for_module_and_type { my ($profiles, $mod, $type, $modpos) = @_; if ($modpos == 0 && $profiles->{$mod}{$type . '-Initial'}) { return $profiles->{$mod}{$type . '-Initial'}; } return $profiles->{$mod}{$type}; } # create a single PAM config from the indicated template and selections, # writing to a new file sub create_from_template { my($template,$dest,$profiles,$enabled,$diff,$type) = @_; my $state = 0; my $uctype = ucfirst($type); $type =~ s/-noninteractive//; open(INPUT,$template) || return 0; open(OUTPUT,">$dest") || return 0; while (<INPUT>) { if ($state == 1) { if (/^# here's the fallback if no module succeeds/) { print OUTPUT; $state++; } next; } if ($state == 3) { if (/^# end of pam-auth-update config/) { print OUTPUT; $state++; } next; } print OUTPUT; my ($pattern,$val); if ($state == 0) { $pattern = '^# here are the per-package modules \(the "Primary" block\)'; $val = 'Primary'; } elsif ($state == 2) { $pattern = '^# and here are more per-package modules \(the "Additional" block\)'; $val = 'Additional'; } else { next; } if (/$pattern/) { my $i = 0; my $count = 0; # first we need to get a count of lines that we're # going to output, so we can fix up the jumps correctly for my $mod (@{$enabled}) { my $output; next if (!$profiles->{$mod}{$uctype . '-Type'}); next if $profiles->{$mod}{$uctype . '-Type'} ne $val; $output = lines_for_module_and_type($profiles, $mod, $uctype, $i++); # bypasses a perl warning about @_, sigh my @tmparr = split("\n+",$output); $count += @tmparr; } # in case anything tries to jump in the 'additional' # block, let's try not to jump off the stack... $count-- if ($val eq 'Additional'); # no primary block, so output a stock pam_permit line # to keep the stack intact if ($val eq 'Primary' && $count == 0) { print OUTPUT "$type\t[default=1]\t\t\tpam_permit.so\n"; } $i = 0; for my $mod (@{$enabled}) { my $output; my @output; next if (!$profiles->{$mod}{$uctype . '-Type'}); next if $profiles->{$mod}{$uctype . '-Type'} ne $val; $output = lines_for_module_and_type($profiles, $mod, $uctype, $i++); for my $line (split("\n",$output)) { $line = merge_one_line($line,$diff, $count); print OUTPUT "$type\t$line"; $count--; } } $state++; } } close(INPUT); close(OUTPUT) or die("close($dest) failed: $!"); if ($state < 4) { unlink($dest); return 0; } return 1; } # take a template file, strip out everything between the markers, and # return the md5sum of the remaining contents. Used for testing for # local modifications of the boilerplate. sub get_template_md5sum { my($template) = @_; my $state = 0; open(INPUT,$template) || return ''; my($md5sum_fd,$output_fd); my $pid = open2($md5sum_fd, $output_fd, 'md5sum'); return '' if (!$pid); while (<INPUT>) { if ($state == 1) { if (/^# here's the fallback if no module succeeds/) { print $output_fd $_; $state++; } next; } if ($state == 3) { if (/^# end of pam-auth-update config/) { print $output_fd $_; $state++; } next; } print $output_fd $_; my ($pattern,$val); if ($state == 0) { $pattern = '^# here are the per-package modules \(the "Primary" block\)'; } elsif ($state == 2) { $pattern = '^# and here are more per-package modules \(the "Additional" block\)'; } else { next; } if (/$pattern/) { $state++; } } close(INPUT); close($output_fd); my $md5sum = <$md5sum_fd>; close($md5sum_fd); waitpid $pid, 0; $md5sum = (split(/\s+/,$md5sum))[0]; return $md5sum; } # merge a set of module declarations into a set of new config files, # using the information returned from diff_profiles(). sub write_profiles { my($profiles,$enabled,$confdir,$savedir,$diff,$force) = @_; if (! -d $savedir) { mkdir($savedir); } # because we can't atomically replace both /var/lib/pam/$foo and # /etc/pam.d/common-$foo at the same time, take steps to make this # somewhat robust for my $type ('auth','account','password','session', 'session-noninteractive') { my $target = $confdir . '/common-' . $type; my $template = $target; my $dest = $template . '.pam-new'; my $diff = $diff; if ($diff) { $diff = \%{$diff->{$type}}; } # Detect if the template is unmodified, and if so, use # the version from /usr/share. Depends on knowing the # md5sums of the originals. my $md5sum = get_template_md5sum($template); for my $i (@{$md5sums{$type}}) { if ($md5sum eq $i) { $template = '/usr/share/pam/common-' . $type; last; } } # first, write out the new config if (!create_from_template($template,$dest,$profiles,$enabled, $diff,$type)) { if (!$force) { return 0; } $template = '/usr/share/pam/common-' . $type; if (!create_from_template($template,$dest,$profiles, $enabled,$diff,$type)) { return 0; } } # then write out the saved config if (!open(OUTPUT, "> $savedir/$type.new")) { unlink($dest); return 0; } my $i = 0; my $uctype = ucfirst($type); for my $mod (@{$enabled}) { my $output; next if (!$profiles->{$mod}{$uctype . '-Type'}); next if ($profiles->{$mod}{$uctype . '-Type'} eq 'Additional'); $output = lines_for_module_and_type($profiles, $mod, $uctype, $i++); if ($output) { print OUTPUT "Module: $mod\n"; print OUTPUT $output . "\n"; } } # no primary block, so output a stock pam_permit line if ($i == 0) { print OUTPUT "Module: null\n"; print OUTPUT "[default=1]\t\t\tpam_permit.so\n"; } $i = 0; for my $mod (@{$enabled}) { my $output; next if (!$profiles->{$mod}{$uctype . '-Type'}); next if ($profiles->{$mod}{$uctype . '-Type'} eq 'Primary'); $output = lines_for_module_and_type($profiles, $mod, $uctype, $i++); if ($output) { print OUTPUT "Module: $mod\n"; print OUTPUT $output . "\n"; } } close(OUTPUT) or die("close($dest) failed: $!"); # then do the renames, back-to-back # we have to use system because File::Copy is in # perl-modules, not perl-base if (-e $target && $force) { system('cp','-f',$target,$target . '.pam-old') == 0 or die("cp -f ${target} ${target}.pam.old failed"); } rename($dest,$target) or die("rename($dest, $target) failed: $!"); rename("$savedir/${type}.new","$savedir/$type") or die("rename(${savedir}/${type}.new, ${savedir}/${type}) failed: $!"); } # at the end of a successful write, reset the 'seen' flag and the # value of the debconf override question. fset($overridetemplate,'seen','false'); set($overridetemplate,'false'); } # reconcile the current config in /etc/pam.d with the saved ones in # /var/lib/pam; returns a hash of profile names and the corresponding # options that should be added/removed relative to the stock config. # returns false if any of the markers are missing that permit a merge, # or on any other failure. sub diff_profiles { my ($sourcedir,$savedir) = @_; my (%diff); @{$diff{'mods'}} = (); # Load the saved config from /var/lib/pam, then iterate through all # lines in the current config that are in the managed block. # If anything fails here, just return immediately since we then # have nothing to merge; instead, the caller will decide later # whether to force an overwrite. for my $type ('auth','account','password','session', 'session-noninteractive') { my (@saved,$modname); open(SAVED,$savedir . '/' . $type) || return 0; while (<SAVED>) { if (/^Module: (.*)/) { $modname = $1; next; } chomp; # trim out the destination of any jumps; this saves # us from having to re-parse everything just to fix # up the jump lengths, when changes to these will # already show up as inconsistencies elsewhere s/(\[[^0-9]*)[0-9]+(.*\])/$1$2/g; s/(\[.*)end(.*\])/$1$2/g; my (@temp) = ($modname,$_); push(@saved,\@temp); } close(SAVED); my $state = 0; my (@prev_opts,$curmod); my $realtype = $type; $realtype =~ s/-noninteractive//; open(CURRENT,$sourcedir . '/common-' . $type) || return 0; while (<CURRENT>) { if ($state == 0) { $state = 1 if (/^# here are the per-package modules \(the "Primary" block\)/); next; } if ($state == 1) { s/^$realtype\s+//; if (/^# here's the fallback if no module succeeds/) { $state = 2; next; } } if ($state == 2) { $state = 3 if (/^# and here are more per-package modules \(the "Additional" block\)/); next; } if ($state == 3) { last if (/^# end of pam-auth-update config/); s/^$realtype\s+//; } my $found = 0; my $curopts; while (!$found && $#saved >= 0) { my $line; ($modname,$line) = @{$saved[0]}; shift(@saved); $line =~ /^((\[[^]]+\]|\w+)\s+\S+)\s*(.*)/; @prev_opts = split(/\s+/,$3); $curmod = $1; # FIXME: the key isn't derived from the config # name, so collisions are possible if more # than one config references the same module $_ =~ s/(\[[^0-9]*)[0-9]+(.*\])/$1$2/g; # check if this is a match for the current line if ($_ =~ /^\Q$curmod\E\s*(.*)$/) { $found = 1; $curopts = $1; push(@{$diff{'mods'}},$modname); } } # there's a line in the live config that doesn't # correspond to anything from the saved config. # treat this as a failure; it's very error-prone # to decide what to do with an added line that # didn't come from a package. return 0 if (!$found); for my $opt (split(/\s+/,$curopts)) { my $found = 0; for (my $i = 0; $i <= $#prev_opts; $i++) { if ($prev_opts[$i] eq $opt) { $found = 1; splice(@prev_opts,$i,1); } } $diff{$type}{'add'}{$curmod}{$opt} = 1 if (!$found); } for my $opt (@prev_opts) { $diff{$type}{'remove'}{$curmod}{$opt} = 1; } } close(CURRENT); # we couldn't parse the config, so the merge fails return 0 if ($state < 3); } return \%diff; } # simple function to parse a provided config file, in pseudo-RFC822 # format, sub parse_pam_profile { my ($profile) = $_[0]; my $fieldname; my %profile; open(PROFILE, $profile) || die "could not read profile $profile: $!"; while (<PROFILE>) { if (/^(\S+):\s+(.*)\s*$/) { $fieldname = $1; # compatibility with the first implementation round; # "Auth-Final" is now just called "Auth" $fieldname =~ s/-Final$//; if ($fieldname eq 'Conflicts') { foreach my $elem (split(/, /, $2)) { $profile{'Conflicts'}->{$elem} = 1; } } else { $profile{$fieldname} = $2; } } else { chomp; s/^\s+//; s/\s+$//; $profile{$fieldname} .= "\n$_" if ($_); if (grep { $profile{$fieldname} =~ /$_/} @invalid_modules) { $profile{'disabled'} = 1; } $profile{$fieldname} =~ s/^[\n\s]+//; } } close(PROFILE); if (!defined($profile{'Session-Interactive-Only'})) { $profile{'Session-noninteractive-Type'} = $profile{'Session-Type'}; $profile{'Session-noninteractive'} = $profile{'Session'}; $profile{'Session-noninteractive-Initial'} = $profile{'Session-Initial'}; } return %profile; }
Save
cmd:
run