/usr/bin
NameSizeModeActions
2to31060755editdlrm
2to3-3.61060755editdlrm
ab743680755editdlrm
aclocal364780755editdlrm
aclocal-1.16364780755editdlrm
acyclic127120755editdlrm
addr2line342240755editdlrm
alias290755editdlrm
animate121280755editdlrm
apropos553360755editdlrm
ar634480755editdlrm
arch382320755editdlrm
aria_chk56372320755editdlrm
aria_dump_log54318640755editdlrm
aria_ftdump54444320755editdlrm
aria_pack54708640755editdlrm
aria_read_log55913840755editdlrm
arpaname121040755editdlrm
as9112640755editdlrm
aspell1633280755editdlrm
at587040755editdlrm
atq587040755editdlrm
atrm587040755editdlrm
aulast210720755editdlrm
aulastlog127360755editdlrm
ausyscall125680755editdlrm
authselect421120755editdlrm
autoconf147680755editdlrm
autoheader85340755editdlrm
autom4te321810755editdlrm
automake2579490755editdlrm
automake-1.162579490755editdlrm
autopoint265720755editdlrm
autoreconf210660755editdlrm
autoscan171240755editdlrm
autoupdate338720755editdlrm
auvirt335120755editdlrm
awk6858480755editdlrm
b2sum590720755editdlrm
base32424640755editdlrm
base64424800755editdlrm
basename383120755editdlrm
bash11546800755editdlrm
bashbug73480755editdlrm
bashbug-6473480755editdlrm
batch1370755editdlrm
bc972560755editdlrm
bcomps211120755editdlrm
bdftopcf464880755editdlrm
bg260755editdlrm
bind9-config34160755editdlrm
bison4482240755editdlrm
bluemoon1000480755editdlrm
bluetoothctl2941200755editdlrm
bond2team232890755editdlrm
bootctl462320755editdlrm
brotli7569440755editdlrm
btattach916880755editdlrm
btmon9667360755editdlrm
bunzip2377440755editdlrm
busctl791200755editdlrm
bwrap712960755editdlrm
bzcat377440755editdlrm
bzcmp21280755editdlrm
bzdiff21280755editdlrm
bzegrep16770755editdlrm
bzfgrep16770755editdlrm
bzgrep16770755editdlrm
bzip2377440755editdlrm
bzip2recover168320755editdlrm
bzless12590755editdlrm
bzmore12590755editdlrm
c++12666160755editdlrm
c++filt295840755editdlrm
c892240755editdlrm
c992150755editdlrm
ca-legacy16440755editdlrm
cairo-sphinx713840755editdlrm
cal675600755editdlrm
captoinfo873600755editdlrm
cat383600755editdlrm
catchsegv32830755editdlrm
catman424480755editdlrm
cc12665760755editdlrm
ccomps253120755editdlrm
cd260755editdlrm
centrino-decode115360755editdlrm
certutil2039280755editdlrm
chacl167680755editdlrm
chage795440755editdlrm
chardetect4000755editdlrm
chattr168000755editdlrm
chcon720240755editdlrm
checkmodule4372560755editdlrm
checkpolicy5003680755editdlrm
chfn336880711editdlrm
chgrp678640755editdlrm
chmem465600755editdlrm
chmod636880755editdlrm
chown719760755editdlrm
chronyc1306640755editdlrm
chrt380800755editdlrm
chsh253120711editdlrm
chvt128320755editdlrm
cifsiostat423440755editdlrm
ciptool2158160755editdlrm
circo125520755editdlrm
cksum382880755editdlrm
clear128400755editdlrm
cloud-id4020755editdlrm
cloud-init4060755editdlrm
cloud-init-per21080755editdlrm
cluster5307680755editdlrm
cmp1062480755editdlrm
cmsutil1254000755editdlrm
col297040755editdlrm
colcrt168720755editdlrm
colrm254800755editdlrm
column506560755editdlrm
comm425600755editdlrm
command310755editdlrm
compare121360755editdlrm
compile_et13420755editdlrm
composite121200755editdlrm
config_data71380755editdlrm
conjure121200755editdlrm
convert121200755editdlrm
coredumpctl459920755editdlrm
corelist149950755editdlrm
cp1515280755editdlrm
cpan83700755editdlrm
cpan-mirrors42880755editdlrm
cpapi134969120755editdlrm
cpapi234969120755editdlrm
cpapi334969120755editdlrm
cpio1636400755editdlrm
cpp12665520755editdlrm
cpupower685120755editdlrm
crb26440744editdlrm
crc3210430755editdlrm
crlutil1381840755editdlrm
cronnext510000755editdlrm
crontab631524755editdlrm
csplit549680755editdlrm
csslint-0.6251520755editdlrm
curl2356000755editdlrm
cut507040755editdlrm
cvtsudoers2910320755editdlrm
cxpm298080755editdlrm
date1084960755editdlrm
dbilogstrip13800755editdlrm
dbiprof62060755editdlrm
dbus-binding-tool1130800755editdlrm
dbus-cleanup-sockets167840755editdlrm
dbus-daemon2454480755editdlrm
dbus-monitor292640755editdlrm
dbus-run-session162640755editdlrm
dbus-send292240755editdlrm
dbus-test-tool251920755editdlrm
dbus-update-activation-environment168080755editdlrm
dbus-uuidgen126720755editdlrm
dbxtool252400755editdlrm
db_archive127520755editdlrm
db_checkpoint168720755editdlrm
db_deadlock168720755editdlrm
db_dump169040755editdlrm
db_dump185712240755editdlrm
db_hotbackup209840755editdlrm
db_load292960755editdlrm
db_log_verify169120755editdlrm
db_printlog342000755editdlrm
db_recover169040755editdlrm
db_replicate168880755editdlrm
db_stat168720755editdlrm
db_tuner251440755editdlrm
db_upgrade127520755editdlrm
db_verify168560755editdlrm
dc542960755editdlrm
dd798400755editdlrm
deallocvt128400755editdlrm
debuginfo-install37020755editdlrm
debuginfod-find168640755editdlrm
delv434800755editdlrm
df932720755editdlrm
diff2744400755editdlrm
diff31316880755editdlrm
diffimg125680755editdlrm
dig1660640755editdlrm
dijkstra171120755editdlrm
dir1432480755editdlrm
dircolors507440755editdlrm
dirmngr5938080755editdlrm
dirmngr-client1230000755editdlrm
dirname341600755editdlrm
display121280755editdlrm
dltest121520755editdlrm
dmesg797440755editdlrm
dnf21040755editdlrm
dnf-321040755editdlrm
dnsdomainname216640755editdlrm
dnstap-read209200755editdlrm
domainname216640755editdlrm
dot125520755editdlrm
dot2gxl422880755editdlrm
dotty20850755editdlrm
doveadm9735040755editdlrm
doveconf3978480755editdlrm
dovecot-sysreport64310755editdlrm
dpkg3237600755editdlrm
dpkg-deb1694720755editdlrm
dpkg-divert1615360755editdlrm
dpkg-maintscript-helper211620755editdlrm
dpkg-query1698240755editdlrm
dpkg-realpath41490755editdlrm
dpkg-split1355680755editdlrm
dpkg-statoverride680080755editdlrm
dpkg-trigger897680755editdlrm
dracut691820755editdlrm
dtrace178080755editdlrm
du1095680755editdlrm
dumpkeys1739520755editdlrm
dumpsexp168320755editdlrm
dwp22334400755editdlrm
dwz1716640755editdlrm
ea-php7463827840755editdlrm
ea-php74-pear3830755editdlrm
ea-php74-pecl2990755editdlrm
ea-php8281471280755editdlrm
ea-php82-pear3830755editdlrm
ea-php82-pecl2990755editdlrm
ea-php8381757760755editdlrm
ea-php83-pear3830755editdlrm
ea-php83-pecl2990755editdlrm
ea-wappspector1000755editdlrm
easy_install-32460755editdlrm
easy_install-3.62460755editdlrm
echo382480755editdlrm
edgepaint4308880755editdlrm
egrep280755editdlrm
eject591680755editdlrm
elfedit340800755editdlrm
enc2xs419580755editdlrm
encguess29800755editdlrm
env423520755editdlrm
envml41970755editdlrm
envsubst501680755editdlrm
eps2eps6390755editdlrm
eqn2377280755editdlrm
event_rpcgen.py555590755editdlrm
evmctl640400755editdlrm
ex11805600755editdlrm
expand425920755editdlrm
expr507520755editdlrm
factor880320755editdlrm
fallocate296560755editdlrm
false341200755editdlrm
fc260755editdlrm
fc-cache1320755editdlrm
fc-cache-64208400755editdlrm
fc-cat167440755editdlrm
fc-conflist125440755editdlrm
fc-list125440755editdlrm
fc-match166480755editdlrm
fc-pattern125520755editdlrm
fc-query125360755editdlrm
fc-scan125520755editdlrm
fc-validate166480755editdlrm
fdp125520755editdlrm
fg260755editdlrm
fgconsole128480755editdlrm
fgrep280755editdlrm
filan969920755editdlrm
file252800755editdlrm
fincore338320755editdlrm
find2286320755editdlrm
find-repos-of-install37020755editdlrm
findmnt723040755editdlrm
fips-finish-install13230755editdlrm
fips-mode-setup40070755editdlrm
firewall-cmd1429550755editdlrm
firewall-offline-cmd1236240755editdlrm
flex4387280755editdlrm
flex++4387280755editdlrm
flock339920755editdlrm
fmt465840755editdlrm
fold424160755editdlrm
fonttosfnt421680755editdlrm
free212880755editdlrm
freetype-config44160755editdlrm
fribidi216480755editdlrm
ftp1036320755editdlrm
funzip375040755editdlrm
fwupdmgr1620800755editdlrm
fwupdtool2118480755editdlrm
g++12666160755editdlrm
g132170640755editdlrm
galera_new_cluster12680755editdlrm
galera_recovery33660755editdlrm
gapplication209360755editdlrm
garb-systemd13450755editdlrm
garbd17353040755editdlrm
gatttool3801760755editdlrm
gawk6858480755editdlrm
gc170400755editdlrm
gcc12665760755editdlrm
gcc-ar375360755editdlrm
gcc-nm375360755editdlrm
gcc-ranlib375360755editdlrm
gcov13774080755editdlrm
gcov-dump5846640755editdlrm
gcov-tool6223600755editdlrm
gdbmtool1142480755editdlrm
gdbm_dump215600755editdlrm
gdbm_load259200755editdlrm
gdbus498880755editdlrm
gdk-pixbuf-query-loaders-64163120755editdlrm
gdk-pixbuf-thumbnailer209440755editdlrm
gdlib-config28610755editdlrm
gencat254320755editdlrm
genl-ctrl-list123280755editdlrm
geqn2377280755editdlrm
GET162170755editdlrm
getconf332400755editdlrm
getent339200755editdlrm
getfacl293840755editdlrm
getkeycodes128400755editdlrm
getopt210240755editdlrm
getopts310755editdlrm
gettext501440755editdlrm
gettext.sh46290755editdlrm
gettextize437180755editdlrm
ghostscript126480755editdlrm
gio872640755editdlrm
gio-querymodules-64166960755editdlrm
git276658160755editdlrm
git-receive-pack276658160755editdlrm
git-shell165537680755editdlrm
git-upload-archive276658160755editdlrm
git-upload-pack276658160755editdlrm
glib-compile-schemas500240755editdlrm
gmake2409680755editdlrm
gml2gv422160755editdlrm
gneqn9080755editdlrm
gnroff33120755editdlrm
gpasswd841444755editdlrm
gpg10903440755editdlrm
gpg-agent4293600755editdlrm
gpg-connect-agent1692720755editdlrm
gpg-error349760755editdlrm
gpg-error-config23180755editdlrm
gpg-wks-server2116720755editdlrm
gpg-zip35250755editdlrm
gpg210903440755editdlrm
gpgconf1803280755editdlrm
gpgme-json877360755editdlrm
gpgparsemail294320755editdlrm
gpgrt-config23180755editdlrm
gpgsm5268080755editdlrm
gpgsplit891120755editdlrm
gpgv4623440755editdlrm
gpgv24623440755editdlrm
gpic3008960755editdlrm
gpio-event-mon153200755editdlrm
gpio-hammer153200755editdlrm
gprof1058320755editdlrm
gr2fonttest306720755editdlrm
graphml2gv211440755editdlrm
grep1982800755editdlrm
groff1279200755editdlrm
grops1957280755editdlrm
grotty1453040755editdlrm
groups382880755editdlrm
growpart298950755editdlrm
grub2-editenv4588480755editdlrm
grub2-file9508320755editdlrm
grub2-fstest12104560755editdlrm
grub2-glue-efi2861200755editdlrm
grub2-kbdcomp16680755editdlrm
grub2-menulst2cfg2689600755editdlrm
grub2-mkfont3196160755editdlrm
grub2-mkimage4417600755editdlrm
grub2-mklayout2964320755editdlrm
grub2-mknetdir4974880755editdlrm
grub2-mkpasswd-pbkdf22988880755editdlrm
grub2-mkrelpath2859680755editdlrm
grub2-mkrescue11702080755editdlrm
grub2-mkstandalone6085600755editdlrm
grub2-render-label9595760755editdlrm
grub2-script-check3235840755editdlrm
grub2-syslinux2cfg8822880755editdlrm
gs126480755editdlrm
gsettings292960755editdlrm
gsnd2770755editdlrm
gsoelim435760755editdlrm
gss-client251520755editdlrm
gtar4597680755editdlrm
gtbl1583200755editdlrm
gtk-query-immodules-2.0-64166800755editdlrm
gtk-update-icon-cache338240755editdlrm
gtroff8243440755editdlrm
gunzip23450755editdlrm
gv2gml252880755editdlrm
gv2gxl422880755editdlrm
gvcolor480240755editdlrm
gvgen253920755editdlrm
gvmap5389440755editdlrm
gvmap.sh21900755editdlrm
gvpack4716400755editdlrm
gvpr80160755editdlrm
gxl2dot422880755editdlrm
gxl2gv422880755editdlrm
gzexe63750755editdlrm
gzip969440755editdlrm
h2ph293820755editdlrm
h2xs608660755editdlrm
hash280755editdlrm
hciattach2073280755editdlrm
hciconfig2009840755editdlrm
hcidump4932400755editdlrm
hcitool2169840755editdlrm
HEAD162170755editdlrm
head466000755editdlrm
hex2hcd167760755editdlrm
hexdump588880755editdlrm
hmac256172720755editdlrm
host1457120755editdlrm
hostid341360755editdlrm
hostname216640755editdlrm
hostnamectl213280755editdlrm
htdbm324800755editdlrm
htdigest222320755editdlrm
html2text4060755editdlrm
htpasswd323040755editdlrm
httxt2dbm216080755editdlrm
hunspell1481680755editdlrm
i386212560755editdlrm
iceauth428720755editdlrm
iconv629040755editdlrm
id465280755editdlrm
identify121280755editdlrm
idiag-socket-details123760755editdlrm
idn403520755editdlrm
ifnames41280755editdlrm
iio_event_monitor235280755editdlrm
iio_generic_buffer276240755editdlrm
import121200755editdlrm
imunify-agent-proxy137819220755editdlrm
imunify-antivirus10240755editdlrm
imunify-fgw-dump81830000755editdlrm
imunify-service10200755editdlrm
imunify360-agent10240755editdlrm
imunify360-command-wrapper122100755editdlrm
info2558880755editdlrm
infocmp625120755editdlrm
infotocap873600755editdlrm
innochecksum47652960755editdlrm
install1598880755editdlrm
install-tools41580755editdlrm
instmodsh41940755editdlrm
intel-speed-select952560755editdlrm
ionice296800755editdlrm
iostat590720755editdlrm
ipcalc471840755editdlrm
ipcmk298400755editdlrm
ipcrm296880755editdlrm
ipcs546800755editdlrm
isc-config.sh34160755editdlrm
isosize254800755editdlrm
ispell9880755editdlrm
isql374560755editdlrm
iusql293440755editdlrm
jcat-tool419120755editdlrm
jobs280755editdlrm
join549840755editdlrm
journalctl788400755editdlrm
jq290960755editdlrm
jsondiff10330755editdlrm
jsondiff-310330755editdlrm
jsondiff-3.610330755editdlrm
jsonpatch36760755editdlrm
jsonpatch-336760755editdlrm
jsonpatch-3.636760755editdlrm
jsonpointer13560755editdlrm
jsonpointer-313560755editdlrm
jsonpointer-3.613560755editdlrm
jsonschema-34090755editdlrm
json_pp42860755editdlrm
json_reformat169520755editdlrm
json_verify125680755editdlrm
json_xs70020755editdlrm
kbdinfo169600755editdlrm
kbdrate168400755editdlrm
kbd_mode128560755editdlrm
kbxutil1816080755editdlrm
kdumpctl337220755editdlrm
kernel-install45110755editdlrm
keyctl377040755editdlrm
kill381760755editdlrm
killall304800755editdlrm
kmod1637840755editdlrm
krb5-config71440755editdlrm
kvm_stat623070755editdlrm
l2ping1676880755editdlrm
l2test1844960755editdlrm
last504160755editdlrm
lastb504160755editdlrm
lastlog211200755editdlrm
lchfn208400755editdlrm
lchsh167440755editdlrm
ld17890800755editdlrm
ld.bfd17890800755editdlrm
ld.gold24676560755editdlrm
ld.so11040640755editdlrm
ldd54410755editdlrm
lefty3118320755editdlrm
less1779280755editdlrm
lessecho126960755editdlrm
lesskey225200755editdlrm
lesspipe.sh31430755editdlrm
lex4387280755editdlrm
lexgrog959520755editdlrm
libgcrypt-config39310755editdlrm
libnetcfg157750755editdlrm
libpng-config23820755editdlrm
libpng16-config23820755editdlrm
libtool3677240755editdlrm
libtoolize1291970755editdlrm
libwmf-fontmap133400755editdlrm
link341360755editdlrm
linux-boot-prober59930755editdlrm
linux32212560755editdlrm
linux64212560755editdlrm
ln721920755editdlrm
lneato15470755editdlrm
loadkeys2155840755editdlrm
loadunimap297280755editdlrm
locale577920755editdlrm
localectl295520755editdlrm
localedef3148480755editdlrm
logger511840755editdlrm
login419440755editdlrm
loginctl586560755editdlrm
logname341440755editdlrm
logresolve219680755editdlrm
look168560755editdlrm
ls1432480755editdlrm
lsattr122160755editdlrm
lsblk923040755editdlrm
lscpu836560755editdlrm
lsgpio154240755editdlrm
lsiio235280755editdlrm
lsinitrd88860755editdlrm
lsipc755120755editdlrm
lslocks384320755editdlrm
lslogins671920755editdlrm
lsmem464240755editdlrm
lsns504720755editdlrm
lsof1796080755editdlrm
lsphp9370755editdlrm
lsscsi880720755editdlrm
lua209440755editdlrm
luac1564400755editdlrm
lwp-download102920755editdlrm
lwp-dump27110755editdlrm
lwp-mirror24130755editdlrm
lwp-request162170755editdlrm
m41900160755editdlrm
Mail4187040755editdlrm
mail4187040755editdlrm
mailx4187040755editdlrm
make2409680755editdlrm
make-dummy-cert6100755editdlrm
makedb254320755editdlrm
man1152240755editdlrm
mandb1377440755editdlrm
manpath342240755editdlrm
mapscrn254400755editdlrm
mariadb55014880755editdlrm
mariadb-access1119610755editdlrm
mariadb-admin50426560755editdlrm
mariadb-binlog53285040755editdlrm
mariadb-check50355760755editdlrm
mariadb-config124880755editdlrm
mariadb-conv47561040755editdlrm
mariadb-convert-table-format42200755editdlrm
mariadb-dump51282240755editdlrm
mariadb-dumpslow82420755editdlrm
mariadb-embedded249113200755editdlrm
mariadb-find-rows32900755editdlrm
mariadb-fix-extensions12500755editdlrm
mariadb-hotcopy353590755editdlrm
mariadb-import50304480755editdlrm
mariadb-install-db226920755editdlrm
mariadb-plugin47349120755editdlrm
mariadb-secure-installation137990755editdlrm
mariadb-service-convert25060755editdlrm
mariadb-setpermission179770755editdlrm
mariadb-show50247360755editdlrm
mariadb-slap50442800755editdlrm
mariadb-tzinfo-to-sql47343360755editdlrm
mariadb-upgrade51858560755editdlrm
mariadb-waitpid47216160755editdlrm
mariadbd-multi274250755editdlrm
mariadbd-safe312140755editdlrm
mariadbd-safe-helper46917920755editdlrm
mariadb_config124880755editdlrm
mcookie340640755editdlrm
mcpp92320755editdlrm
md5sum466400755editdlrm
mdig496800755editdlrm
memstrack857920755editdlrm
mesg167520755editdlrm
miniterm-3.6.py338870755editdlrm
miniterm-3.py338870755editdlrm
mkdir846800755editdlrm
mkfifo680560755editdlrm
mkfontdir650755editdlrm
mkfontscale425920755editdlrm
mkinitrd65850755editdlrm
mknod721600755editdlrm
mktemp467600755editdlrm
mm2gv927040755editdlrm
mmdblookup171440755editdlrm
modulecmd3939800755editdlrm
modulemd-validator255600755editdlrm
modutil1816880755editdlrm
mogrify121200755editdlrm
mokutil511840755editdlrm
montage121200755editdlrm
more460160755editdlrm
mount503280755editdlrm
mountpoint168800755editdlrm
mpicalc208720755editdlrm
mpris-proxy1013680755editdlrm
mpstat547920755editdlrm
msgattrib261920755editdlrm
msgcat261680755editdlrm
msgcmp267440755editdlrm
msgcomm261680755editdlrm
msgconv220720755editdlrm
msgen220640755editdlrm
msgexec220720755editdlrm
msgfilter353600755editdlrm
msgfmt924640755editdlrm
msggrep446480755editdlrm
msginit694800755editdlrm
msgmerge732000755editdlrm
msgunfmt366640755editdlrm
msguniq261760755editdlrm
msql2mysql14460755editdlrm
mv1474080755editdlrm
myisamchk51451360755editdlrm
myisamlog50024160755editdlrm
myisampack50416000755editdlrm
myisam_ftdump50203120755editdlrm
mysql55014880755editdlrm
mysqlaccess1119610755editdlrm
mysqladmin50426560755editdlrm
mysqlbinlog53285040755editdlrm
mysqlcheck50355760755editdlrm
mysqldump51282240755editdlrm
mysqld_multi274250755editdlrm
mysqld_safe312140755editdlrm
mysqld_safe_helper46917920755editdlrm
mysqlimport50304480755editdlrm
mysqlshow50247360755editdlrm
mysqlslap50442800755editdlrm
mysql_config46230755editdlrm
mysql_embedded249113200755editdlrm
mysql_find_rows32900755editdlrm
mysql_fix_extensions12500755editdlrm
mysql_install_db226920755editdlrm
mysql_plugin47349120755editdlrm
mysql_tzinfo_to_sql47343360755editdlrm
mysql_upgrade51858560755editdlrm
mysql_waitpid47216160755editdlrm
mytop737570755editdlrm
my_print_defaults47262880755editdlrm
nail4187040755editdlrm
named-rrchecker203520755editdlrm
namei338960755editdlrm
nano2538880755editdlrm
nc505760755editdlrm
ncurses6-config60150755editdlrm
ncursesw6-config60180755editdlrm
ndptool250400755editdlrm
neato125520755editdlrm
needs-restarting37020755editdlrm
neqn9080755editdlrm
netcat505760755editdlrm
netstat1624880755editdlrm
newgidmap489600755editdlrm
newgrp434800755editdlrm
newuidmap489200755editdlrm
nf-ct-add168560755editdlrm
nf-ct-events126720755editdlrm
nf-ct-list168880755editdlrm
nf-exp-add172720755editdlrm
nf-exp-delete170560755editdlrm
nf-exp-list168880755editdlrm
nf-log126480755editdlrm
nf-monitor126560755editdlrm
nf-queue167440755editdlrm
ngettext501440755editdlrm
nice382240755editdlrm
nisdomainname216640755editdlrm
nl466480755editdlrm
nl-addr-add126320755editdlrm
nl-addr-delete171680755editdlrm
nl-addr-list172800755editdlrm
nl-class-add171280755editdlrm
nl-class-delete129280755editdlrm
nl-class-list128960755editdlrm
nl-classid-lookup127680755editdlrm
nl-cls-add171680755editdlrm
nl-cls-delete171760755editdlrm
nl-cls-list130400755editdlrm
nl-fib-lookup128000755editdlrm
nl-link-enslave121520755editdlrm
nl-link-ifindex2name121520755editdlrm
nl-link-list125280755editdlrm
nl-link-name2ifindex121440755editdlrm
nl-link-release121440755editdlrm
nl-link-set130720755editdlrm
nl-link-stats128880755editdlrm
nl-list-caches125680755editdlrm
nl-list-sockets121520755editdlrm
nl-monitor128160755editdlrm
nl-neigh-add129280755editdlrm
nl-neigh-delete129680755editdlrm
nl-neigh-list124800755editdlrm
nl-neightbl-list122960755editdlrm
nl-pktloc-lookup128640755editdlrm
nl-qdisc-add129520755editdlrm
nl-qdisc-delete129280755editdlrm
nl-qdisc-list171440755editdlrm
nl-route-add167840755editdlrm
nl-route-delete172880755editdlrm
nl-route-get126480755editdlrm
nl-route-list168320755editdlrm
nl-rule-list123360755editdlrm
nl-tctree-list129600755editdlrm
nl-util-addr121360755editdlrm
nm515840755editdlrm
nm-online213360755editdlrm
nmcli10332160755editdlrm
nmtui8029360755editdlrm
nmtui-connect8029360755editdlrm
nmtui-edit8029360755editdlrm
nmtui-hostname8029360755editdlrm
nohup383120755editdlrm
nop128000755editdlrm
nproc383040755editdlrm
nroff33120755editdlrm
nsenter340960755editdlrm
nslookup1497680755editdlrm
nss-policy-check166960755editdlrm
nsupdate748080755editdlrm
numfmt672160755editdlrm
objcopy2458320755editdlrm
objdump4298320755editdlrm
od755760755editdlrm
odbcinst295760755editdlrm
odbc_config121280755editdlrm
open214720755editdlrm
openssl7638480755editdlrm
openvt214720755editdlrm
os-prober59150755editdlrm
osage125520755editdlrm
p11-kit380400755editdlrm
package-cleanup37020755editdlrm
page_owner_sort116160755editdlrm
pango-list121600755editdlrm
pango-view588160755editdlrm
paperconf133840755editdlrm
passwd335604755editdlrm
paste382800755editdlrm
patch2114160755editdlrm
patchwork125520755editdlrm
pathchk382240755editdlrm
pathfix.py67900755editdlrm
pcre2-config19500755editdlrm
pdf2dsc6980755editdlrm
pdf2ps9090755editdlrm
pdnsutil54421120755editdlrm
pdns_control4979360755editdlrm
peekfd169040755editdlrm
perl127280755editdlrm
perl5.26.3127280755editdlrm
perlbug454580755editdlrm
perldoc1180755editdlrm
perlivp108130755editdlrm
perlml67680755editdlrm
perlthanks454580755editdlrm
perror49280080755editdlrm
pflags26360755editdlrm
pftp1036320755editdlrm
pgrep295360755editdlrm
php9370755editdlrm
pic3008960755editdlrm
piconv82710755editdlrm
pidof170960755editdlrm
pidstat672960755editdlrm
pigz1283920755editdlrm
pinentry24040755editdlrm
pinentry-curses797600755editdlrm
ping677120755editdlrm
pinky424560755editdlrm
pip-32090755editdlrm
pip-3.62090755editdlrm
pip32090755editdlrm
pip3.62090755editdlrm
pk12util1137840755editdlrm
pkaction167760755editdlrm
pkcheck250160755editdlrm
pkexec290880755editdlrm
pkg-config410000755editdlrm
pkgconf410000755editdlrm
pkill295360755editdlrm
pkla-admin-identities263360755editdlrm
pkla-check-authorization345920755editdlrm
pkttyagent208720755editdlrm
pl2pm45330755editdlrm
pldd171520755editdlrm
pmap335680755editdlrm
png-fix-itxt121360755editdlrm
pngfix541200755editdlrm
pod2html41340755editdlrm
pod2man150340755editdlrm
pod2text108030755editdlrm
pod2usage39480755editdlrm
podchecker36580755editdlrm
podselect25270755editdlrm
POST162170755editdlrm
post-grohtml2444560755editdlrm
powernow-k8-decode111360755editdlrm
pr841200755editdlrm
pre-grohtml1336880755editdlrm
precat56560755editdlrm
preconv590320755editdlrm
preunzip56560755editdlrm
prezip56560755editdlrm
prezip-bin122640755editdlrm
printenv341200755editdlrm
printf548480755editdlrm
prlimit384400755editdlrm
prl_backup75440755editdlrm
procan845840755editdlrm
protoc168880755editdlrm
protoc-c2506640755editdlrm
protoc-gen-c2506640755editdlrm
prove135620755editdlrm
prtstat210000755editdlrm
prune171280755editdlrm
ps1379840755editdlrm
ps2ascii6310755editdlrm
ps2epsi27520755editdlrm
ps2pdf2720755editdlrm
ps2pdf122150755editdlrm
ps2pdf132150755editdlrm
ps2pdf142150755editdlrm
ps2pdfwr10970755editdlrm
ps2ps6470755editdlrm
ps2ps26690755editdlrm
psfaddtable211520755editdlrm
psfgettable211520755editdlrm
psfstriptable211520755editdlrm
psfxtable211520755editdlrm
pslog127840755editdlrm
pstree343360755editdlrm
pstree.x11343360755editdlrm
ptar34560755editdlrm
ptardiff25350755editdlrm
ptargrep42990755editdlrm
ptx798640755editdlrm
pure-pw397680755editdlrm
pure-pwconvert109760755editdlrm
pure-statsdecode109760755editdlrm
pv753280755editdlrm
pwd383200755editdlrm
pwdx129840755editdlrm
pwmake125600755editdlrm
pwscore125600755editdlrm
pybabel3880755editdlrm
pydoc-3890755editdlrm
pydoc3890755editdlrm
pydoc3.6890755editdlrm
pydoc3.12790755editdlrm
pyjwt3840755editdlrm
python-html2text4060755editdlrm
python3118720755editdlrm
python3-config2040755editdlrm
python3-html2text4060755editdlrm
python3.6118720755editdlrm
python3.6-config2040755editdlrm
python3.6m118720755editdlrm
python3.6m-config2040755editdlrm
python3.6m-x86_64-config36260755editdlrm
python3.1277520755editdlrm
pyvenv-34460755editdlrm
pyvenv-3.64460755editdlrm
qemu-ga10044080755editdlrm
quota936884755editdlrm
quotasync764800755editdlrm
ranlib634560755editdlrm
raw168960755editdlrm
rctest2157440755editdlrm
read280755editdlrm
readelf6395280755editdlrm
readlink469840755editdlrm
realpath511440755editdlrm
recode-sr-latin184240755editdlrm
rename168960755editdlrm
renew-dummy-cert7250755editdlrm
renice168560755editdlrm
replace47040880755editdlrm
repo-graph37020755editdlrm
repoclosure37020755editdlrm
repodiff37020755editdlrm
repomanage37020755editdlrm
repoquery37020755editdlrm
reposync37020755editdlrm
repotrack37020755editdlrm
rescan-scsi-bus.sh391610755editdlrm
reset253520755editdlrm
resizecons212720755editdlrm
resolvectl2004480755editdlrm
resolveip47215600755editdlrm
resolve_stack_dump47257280755editdlrm
rev127600755editdlrm
rfcomm1766640755editdlrm
rm720640755editdlrm
rmdir465520755editdlrm
rnano2538880755editdlrm
rpcbind630240755editdlrm
rpcinfo334240755editdlrm
rpm213520755editdlrm
rpm2archive209520755editdlrm
rpm2cpio121280755editdlrm
rpmdb173680755editdlrm
rpmkeys172720755editdlrm
rpmquery213520755editdlrm
rpmverify213520755editdlrm
rsync5348880755editdlrm
rsyslog-recover-qi.pl60980755editdlrm
run-parts19830755editdlrm
run-with-aspell850755editdlrm
runcon382720755editdlrm
rvi11805600755editdlrm
rview11805600755editdlrm
rvim30678560755editdlrm
sadf3426000755editdlrm
sar1390240755editdlrm
sccmap211120755editdlrm
scl377520755editdlrm
scl_enabled2580755editdlrm
scl_source18630755editdlrm
scp1053120755editdlrm
script376800755editdlrm
scriptreplay296960755editdlrm
scsi-rescan391610755editdlrm
scsi_logging_level85850755editdlrm
scsi_mandat36020755editdlrm
scsi_readcap13270755editdlrm
scsi_ready11210755editdlrm
scsi_satl38570755editdlrm
scsi_start12850755editdlrm
scsi_stop14740755editdlrm
scsi_temperature9360755editdlrm
sdiff1078560755editdlrm
sdptool2813600755editdlrm
secon260720755editdlrm
secret-tool216800755editdlrm
sed1180400755editdlrm
sedismod2802320755editdlrm
sedispol2032480755editdlrm
semodule_expand125760755editdlrm
semodule_link125760755editdlrm
semodule_package170800755editdlrm
semodule_unpackage125920755editdlrm
seq547280755editdlrm
sessreg178000755editdlrm
setarch212560755editdlrm
setfacl460640755editdlrm
setfont462720755editdlrm
setkeycodes128640755editdlrm
setleds170000755editdlrm
setmetamode128640755editdlrm
setpriv462400755editdlrm
setsid167680755editdlrm
setterm462080755editdlrm
setup-nsssysinit15390755editdlrm
setup-nsssysinit.sh15390755editdlrm
setvtrgb170400755editdlrm
sfdp125520755editdlrm
sftp1635840755editdlrm
sg434800755editdlrm
sginfo766480755editdlrm
sgm_dd333440755editdlrm
sgp_dd378480755editdlrm
sg_bg_ctl164640755editdlrm
sg_compare_and_write214080755editdlrm
sg_copy_results213200755editdlrm
sg_dd456640755editdlrm
sg_decode_sense208320755editdlrm
sg_emc_trespass125600755editdlrm
sg_format341840755editdlrm
sg_get_config341280755editdlrm
sg_get_lba_status209680755editdlrm
sg_ident165680755editdlrm
sg_inq1207440755editdlrm
sg_logs1536320755editdlrm
sg_luns254640755editdlrm
sg_map168080755editdlrm
sg_map26254800755editdlrm
sg_modes449440755editdlrm
sg_opcodes293760755editdlrm
sg_persist349600755editdlrm
sg_prevent123680755editdlrm
sg_raw249840755editdlrm
sg_rbuf213520755editdlrm
sg_rdac162640755editdlrm
sg_read250160755editdlrm
sg_readcap213760755editdlrm
sg_read_attr356400755editdlrm
sg_read_block_limits124160755editdlrm
sg_read_buffer214800755editdlrm
sg_read_long166640755editdlrm
sg_reassign166240755editdlrm
sg_referrals166320755editdlrm
sg_rep_zones211680755editdlrm
sg_requests167040755editdlrm
sg_reset171440755editdlrm
sg_reset_wp165680755editdlrm
sg_rmsn123680755editdlrm
sg_rtpg165680755editdlrm
sg_safte207600755editdlrm
sg_sanitize251840755editdlrm
sg_sat_identify171280755editdlrm
sg_sat_phy_event210880755editdlrm
sg_sat_read_gplog166960755editdlrm
sg_sat_set_features166640755editdlrm
sg_scan169120755editdlrm
sg_seek172720755editdlrm
sg_senddiag258880755editdlrm
sg_ses1210880755editdlrm
sg_ses_microcode302000755editdlrm
sg_start214480755editdlrm
sg_stpg208000755editdlrm
sg_stream_ctl207600755editdlrm
sg_sync166240755editdlrm
sg_test_rwbuf212480755editdlrm
sg_timestamp212560755editdlrm
sg_turs171600755editdlrm
sg_unmap249120755editdlrm
sg_verify209600755editdlrm
sg_vpd1113760755editdlrm
sg_write_buffer217680755editdlrm
sg_write_long167360755editdlrm
sg_write_same250800755editdlrm
sg_write_verify212960755editdlrm
sg_write_x550560755editdlrm
sg_wr_mode207920755editdlrm
sg_xcopy415760755editdlrm
sg_zone166960755editdlrm
sh11546800755editdlrm
sha1hmac334400755editdlrm
sha1sum466480755editdlrm
sha224hmac334400755editdlrm
sha224sum466720755editdlrm
sha256hmac334400755editdlrm
sha256sum466720755editdlrm
sha384hmac334400755editdlrm
sha384sum466800755editdlrm
sha512hmac334400755editdlrm
sha512sum466880755editdlrm
shasum98920755editdlrm
showconsolefont212320755editdlrm
showkey169760755editdlrm
showrgb133680755editdlrm
shred633360755editdlrm
shuf594880755editdlrm
sieve-dump358720755editdlrm
sieve-filter455520755editdlrm
sieve-test413920755editdlrm
sievec361280755editdlrm
signver1175440755editdlrm
sim_client166640755editdlrm
size340480755editdlrm
skill294880755editdlrm
slabinfo370160755editdlrm
slabtop213440755editdlrm
sleep382960755editdlrm
slencheck125840755editdlrm
sm3hmac334400755editdlrm
snice294880755editdlrm
socat4162480755editdlrm
soelim435760755editdlrm
sort1264320755editdlrm
sotruss42810755editdlrm
spell1220755editdlrm
splain191500755editdlrm
split594400755editdlrm
sprof293600755editdlrm
sqlite313465120755editdlrm
ssh7757760755editdlrm
ssh-add3544480755editdlrm
ssh-agent3333840755editdlrm
ssh-copy-id106940755editdlrm
ssh-keygen4374320755editdlrm
ssh-keyscan4429920755editdlrm
ssltap1336400755editdlrm
sss_ssh_authorizedkeys294720755editdlrm
sss_ssh_knownhostsproxy294720755editdlrm
stat882320755editdlrm
stdbuf506880755editdlrm
strace20298320755editdlrm
strace-log-merge18210755editdlrm
stream121120755editdlrm
strings383280755editdlrm
strip2458560755editdlrm
stty794720755editdlrm
stunnel2305040755editdlrm
su501684750editdlrm
sudo1910004111editdlrm
sudoedit1910004111editdlrm
sudoreplay1220560111editdlrm
sum466240755editdlrm
sw-engine210956320755editdlrm
sxpm295040755editdlrm
sync382560755editdlrm
systemctl2236960755editdlrm
systemd-analyze16348640755editdlrm
systemd-ask-password123120755editdlrm
systemd-cat164160755editdlrm
systemd-cgls168320755editdlrm
systemd-cgtop336720755editdlrm
systemd-delta250320755editdlrm
systemd-detect-virt121680755editdlrm
systemd-escape163920755editdlrm
systemd-firstboot378720755editdlrm
systemd-hwdb296000755editdlrm
systemd-inhibit164160755editdlrm
systemd-machine-id-setup253440755editdlrm
systemd-mount538960755editdlrm
systemd-notify164160755editdlrm
systemd-path164000755editdlrm
systemd-resolve2004480755editdlrm
systemd-run501200755editdlrm
systemd-socket-activate253680755editdlrm
systemd-stdio-bridge164080755editdlrm
systemd-sysusers543200755editdlrm
systemd-tmpfiles750560755editdlrm
systemd-tty-ask-password-agent336080755editdlrm
systemd-umount538960755editdlrm
tabs169520755editdlrm
tac424880755editdlrm
tail759120755editdlrm
tapestat423120755editdlrm
tar4597680755editdlrm
taskset381520755editdlrm
tbl1583200755editdlrm
tclsh92560755editdlrm
tclsh8.692560755editdlrm
tcptraceroute15850755editdlrm
teamd1643680755editdlrm
teamdctl310960755editdlrm
teamnl209600755editdlrm
tee424720755editdlrm
test548480755editdlrm
tic873600755editdlrm
timedatectl378480755editdlrm
timeout428640755editdlrm
tload171600755editdlrm
tmon405760755editdlrm
tmpwatch363200755editdlrm
toe168480755editdlrm
top1246160755editdlrm
touch961920755editdlrm
tput253920755editdlrm
tr508160755editdlrm
tracepath209280755editdlrm
traceroute726720755editdlrm
traceroute6726720755editdlrm
tred169840755editdlrm
troff8243440755editdlrm
true341280755editdlrm
truncate423520755editdlrm
trust2248240755editdlrm
tset253520755editdlrm
tsort424880755editdlrm
tty341120755editdlrm
turbostat1339360755editdlrm
twopi125520755editdlrm
type280755editdlrm
tzselect153700755editdlrm
uapi34969120755editdlrm
ucs2any250000755editdlrm
udevadm4347520755editdlrm
udisksctl621920755editdlrm
ul210800755editdlrm
ulimit300755editdlrm
umask290755editdlrm
umount335360755editdlrm
unalias310755editdlrm
uname382240755editdlrm
uname26212560755editdlrm
unexpand466880755editdlrm
unflatten170240755editdlrm
unicode_start26130755editdlrm
unicode_stop3630755editdlrm
uniq508320755editdlrm
unlink341440755editdlrm
unpigz1283920755editdlrm
unshare255280755editdlrm
unversioned-python1570755editdlrm
unxz840560755editdlrm
unzip2067280755editdlrm
unzipsfx1039120755editdlrm
update-ca-trust12680755editdlrm
update-crypto-policies870755editdlrm
update-gtk-immodules3130755editdlrm
update-mime-database585920755editdlrm
uptime128880755editdlrm
users382960755editdlrm
usleep121440755editdlrm
utmpdump293520755editdlrm
uuclient162560755editdlrm
uuidgen167680755editdlrm
uuidparse380240755editdlrm
vdir1432560755editdlrm
vi11805600755editdlrm
view11805600755editdlrm
vim30678560755editdlrm
vimdiff30678560755editdlrm
vimdot10820755editdlrm
vimtutor21210755editdlrm
vlock213280755editdlrm
vmstat376720755editdlrm
w212480755editdlrm
wait280755editdlrm
wall338400755editdlrm
watch298880755editdlrm
watchgnupg168320755editdlrm
wc508320755editdlrm
wdctl378640755editdlrm
wget5339440755editdlrm
whatis553360755editdlrm
whereis299760755editdlrm
which300880755editdlrm
whiptail338800755editdlrm
who548800755editdlrm
whoami341360755editdlrm
wmf2eps175600755editdlrm
wmf2fig175600755editdlrm
wmf2gd175520755editdlrm
wmf2svg175760755editdlrm
wmf2x175360755editdlrm
word-list-compress122800755editdlrm
write211120755editdlrm
wsrep_sst_backup24470755editdlrm
wsrep_sst_common701410644editdlrm
wsrep_sst_mariabackup542650755editdlrm
wsrep_sst_mysqldump82960755editdlrm
wsrep_sst_rsync314730755editdlrm
wsrep_sst_rsync_wan314730755editdlrm
x86_64212560755editdlrm
x86_64-redhat-linux-c++12666160755editdlrm
x86_64-redhat-linux-g++12666160755editdlrm
x86_64-redhat-linux-gcc12665760755editdlrm
x86_64-redhat-linux-gcc-812665760755editdlrm
x86_64-redhat-linux-gnu-pkg-config4240755editdlrm
x86_energy_perf_policy327200755editdlrm
xargs758880755editdlrm
xb-tool293920755editdlrm
xgamma174880755editdlrm
xgettext2906960755editdlrm
xhost175280755editdlrm
xinput651360755editdlrm
xkill175120755editdlrm
xml2-config17460755editdlrm
xmlcatalog208720755editdlrm
xmllint751360755editdlrm
xmlwf378560755editdlrm
xmodmap409360755editdlrm
xorg-x11-fonts-update-dirs13220744editdlrm
xrandr670320755editdlrm
xrdb348000755editdlrm
xrefresh183680755editdlrm
xset380880755editdlrm
xsetpointer133680755editdlrm
xsetroot219520755editdlrm
xslt-config24180755editdlrm
xsltproc291520755editdlrm
xstdcmap181040755editdlrm
xsubpp50800755editdlrm
xxd210320755editdlrm
xz840560755editdlrm
xzcat840560755editdlrm
xzcmp66320755editdlrm
xzdec168800755editdlrm
xzdiff66320755editdlrm
xzegrep59020755editdlrm
xzfgrep59020755editdlrm
xzgrep59020755editdlrm
xzless18020755editdlrm
xzmore21610755editdlrm
yat2m341440755editdlrm
yes341680755editdlrm
ypdomainname216640755editdlrm
yum21040755editdlrm
yum-builddep37020755editdlrm
yum-config-manager37020755editdlrm
yum-debug-dump37020755editdlrm
yum-debug-restore37020755editdlrm
yum-groups-manager37020755editdlrm
yumdownloader37020755editdlrm
zcat19830755editdlrm
zcmp16770755editdlrm
zdiff58790755editdlrm
zegrep290755editdlrm
zfgrep290755editdlrm
zforce20800755editdlrm
zgrep75820755editdlrm
zip2344960755editdlrm
zipcloak1053760755editdlrm
zipdetails505760755editdlrm
zipgrep29530755editdlrm
zipinfo2067280755editdlrm
zipnote1001040755editdlrm
zipsplit1001040755editdlrm
zless22050755editdlrm
zmore18410755editdlrm
znew45520755editdlrm
zone2json14526480755editdlrm
zone2sql14737760755editdlrm
zsoelim435760755editdlrm
[548880755editdlrm
Edit: /usr/bin/mariadb-access (111961B)
#!/usr/bin/perl # Copyright (c) 2000, 2017, Oracle and/or its affiliates. All rights reserved. # # This program is free software; you can redistribute it and/or # modify it under the terms of the GNU Library General Public # License as published by the Free Software Foundation; version 2 # of the License. # # This program is distributed in the hope that it will be useful, # but WITHOUT ANY WARRANTY; without even the implied warranty of # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU # Library General Public License for more details. # # You should have received a copy of the GNU Library General Public # License along with this library; if not, write to the Free # Software Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, # MA 02110-1335 USA # **************************** package MySQLaccess; #use strict; use File::Temp qw(tempfile tmpnam); use Fcntl; BEGIN { # **************************** # static information... $VERSION = "2.10, 13 Sep 2019"; $0 =~ m%/([^/]+)$%o; $script = $1; $script = 'MySQLAccess' unless $script; $script_conf = "$script.conf"; $script_log = $ENV{'HOME'}."/$script.log"; # **************************** # information on MariaDB $MYSQL = '/usr/bin/mariadb'; # path to mariadb executable $SERVER = '3.21'; $MYSQL_OPT = ' --batch --unbuffered'; $ACCESS_DB = 'mysql'; # name of DB with grant-tables $ACCESS_H = 'host'; # $ACCESS_U = 'user'; # $ACCESS_D = 'db'; # # Add/Edit privileges $ACCESS_H_TMP = 'host_tmp'; $ACCESS_U_TMP = 'user_tmp'; $ACCESS_D_TMP = 'db_tmp'; $ACCESS_H_BCK = 'host_backup'; $ACCESS_U_BCK = 'user_backup'; $ACCESS_D_BCK = 'db_backup'; $DIFF = '/usr/bin/diff'; $MYSQLDUMP = '/usr/bin/mariadb-dump'; #path to mariadb-dump executable $MYSQLADMIN= 'http://foobar.com/MySQLadmin'; #URL of CGI for manipulating #the temporary grant-tables } END { unlink $MYSQL_CNF if defined $MYSQL_CNF and not $DEBUG; } $INFO = <<"_INFO"; -------------------------------------------------------------------------- mysqlaccess (Version $VERSION) ~~~~~~~~~~~ Copyright (C) 1997,1998 Yves.Carlier\@rug.ac.be University of Ghent (RUG), Belgium Administratieve Informatieverwerking (AIV) report the access-privileges for a USER from a HOST to a DB Many thanks go to and for their suggestions, debugging and patches. use `$script -?' to get more information on available options. From version 2.0x, $script can also be used through a WEB-browser if it is ran as a CGI-script. (See the release-notes) -------------------------------------------------------------------------- _INFO $OPTIONS = <<_OPTIONS; Usage: $script [host [user [db]]] OPTIONS -?, --help display this helpscreen and exit -v, --version print information on the program `$script' -u, --user=# username for logging in to the db -p, --password=# validate password for user -h, --host=# name or IP-number of the host -d, --db=# name of the database -U, --superuser=# connect as superuser -P, --spassword=# password for superuser -H, --rhost=# remote MariaDB-server to connect to --old_server connect to old MariaDB-server (before v3.21) which does not yet know how to handle full where clauses. -b, --brief single-line tabular report -t, --table report in table-format --relnotes print release-notes --plan print suggestions/ideas for future releases --howto some examples of how to run `$script' --debug=N enter debuglevel N (0..3) --copy reload temporary grant-tables from original ones --preview show differences in privileges after making changes in (temporary) grant-tables --commit copy grant-rules from temporary tables to grant-tables (!don't forget to do an mysqladmin reload) --rollback undo the last changes to the grant-tables. Note: At least the user and the db must be given (even with wildcards) If no host is given, `localhost' is assumed Wilcards (*,?,%,_) are allowed for host, user and db, but be sure to escape them from your shell!! (ie type \\* or '*') _OPTIONS $RELEASE = <<'_RELEASE'; Release Notes: ------------- 0.1-beta1: internal - first trial. 0.1-beta2: (1997-02-27) - complete rewrite of the granting-rules, based on the documentation found in de FAQ. - IP-number and name for a host are equiv. 0.1-beta3: (1997-03-10) - more information - 'localhost' and the name/ip of the local machine are now equiv. 0.1-beta4: (1997-03-11) - inform the user if he has not enough priv. to read the mysql db 1.0-beta1: (1997-03-12) suggestions by Monty: - connect as superuser with superpassword. - mysqlaccess could also notice if all tables are empty. This means that all user have full access! - It would be nice if one could optionally start mysqlaccess without any options just the arguments 'user db' or 'host user db', where host is 'localhost' if one uses only two arguments. 1.0-beta2: (1997-03-14) - bugfix: translation to reg.expr of \_ and \%. - bugfix: error in matching regular expression and string given by user which resulted in 'test_123' being matched with 'test' 1.0-beta3: (1997-03-14) - bugfix: the user-field should not be treated as a sql-regexpr, but as a plain string. - bugfix: the host-table should not be used if the host isn't empty in db or if the host isn't emty in user (Monty) 1.0-beta4: (1997-03-14) - bugfix: in an expression "$i = $j or $k", the '=' binds tighter than the or which results in problems... (by Monty) - running mysqlaccess with "perl -w" gives less warnings... ;-) 1.0-beta5: (1997-04-04) - bugfix: The table sorting was only being applied to the "user" table; all the tables need to be sorted. Rewrote the sort algorithm, and the table walk algorithm (no temp file anymore), and various other cleanups. I believe the access calculation is 100% correct. (by Paul D. Smith ) - Allow the debug level to be set on the cmd line with --debug=N. (by Paul D. Smith ) - More -w cleanups; should be totally -w-clean. (by Paul D. Smith ) 1.1-beta1: (1997-04-xx) 1.1-beta2: (1997-04-11) - new options: --all_users : report access-rights for all possible users --all_dbs : report access-rights for all possible dbs --all_hosts : report access-rights for all possible hosts --brief : as brief as possible, don't mention notes,warnings and rules --password : validate password for user - layout: long messages are wrapped on the report. - functionality: more descriptive notes and warnings wildcards (*,?) are allowed in the user,host and db options setting xxxx=* is equiv to using option --all_xxxx note: make sure you escape your wildcards, so they don't get interpreted by the shell. use \* or '*' - bugfix: Fieldnames which should be skipped on the output can now have a first capital letter. - bugfix: any option with a '.' (eg ip-number) was interpreted as a wildcard-expression. - bugfix: When no entry was found in the db-table, the default accessrights are N, instead of the faulty Y in a previous version. 1.1-beta-3 : (1997-04-xx) 1.1-beta-4 : (1997-04-xx) 1.1-beta-5 : (1997-04-xx) 1.1 : (1997-04-28) - new options: --rhost : name of mysql-server to connect to --plan : print suggestions/ideas for future releases --relnotes : display release-notes --howto : display examples on how to use mysqlaccess --brief : single-line tabular output - functionality/bugfix: * removed options --all_users,--all_dbs,--all_hosts, which were redundant with the wildcard-expressions for the corresponding options. They made the processing of the commandline too painful and confusing ;-) (suggested by psmith) * redefined the option --brief, which now gives a single-line tabular output * Now we check if the right version of the mysql-client is used, since we might use an option not yet implemented in an older version (--unbuffered, since 3.0.18) Also the error-messages the mysql-client reports are better interpreted ;-) * Wildcards can now be given following the SQL-expression (%,_) and the Regular-expression (*,?) syntax. - speed: we now open a bidirectional pipe to the mysql-client, and keep it open throughout the whole run. Queries are written to, and the answers read from the pipe. (suggested by monty) - bugfixes: * the Rules were not properly reset over iterations * when in different tables the field-names were not identical, eg. Select_priv and select_priv, they were considered as definitions of 2 different access-rights. * the IP-number of a host with a name containing wildcards should not be searched for in Name2IP and IP2Name. * various other small things, pointed out by and 1.2 : (1997-05-13) - bugfix: * Fixed bug in acl with anonymous user: Now if one gets accepted by the user table as a empty user name, the user name is set to '' when checking against the 'db' and 'host' tables. (Bug fixed in MySQL3.20.19) 1.2-1 : (1997-xx-xx) - bugfix: * hashes should be initialized with () instead of {} * "my" variable $name masks earlier declaration in same scope, using perl 5.004 1.2-2 : (1997-06-10) 2.0p1-3 : (1997-10-xx) - new * packages * log-file for debug-output : /tmp/mysqlaccess.log * default values are read from a configuration file $script.conf first this file is looked for in the current directory; if not found it is looked for in /etc Note that when default-values are given, these can't get overridden by empty (blanc) values! * CGI-BIN version with HTML and forms interface. Simply place the script in an ScriptAliased directory, make the configuration file available in the that directory or in /etc, and point your browser to the right URL. * copy the grant-rules to temporary tables, where you are safe to play with them. * preview changes in privileges after changing grant-rules, before taking them into production * copy the new grant-rules from the temporary tables back to the grant-tables. * Undo all changes made in the grant-tables (1-level undo). -new options: * --table : as opposite of the --brief option. * --copy : (re)load temporary grant-tables from original ones. * --preview : preview changes in privileges after changing some or more entries in the grant-tables. * --commit : copy grant-rules from temporary tables to grant-tables (!don't forget to do an mysqladmin reload) * --rollback: undo the last changes to the grant-tables. - bugfix: * if the table db is empty, mysqlaccess freezed (by X Zhu ) 2.0 : (1997-10-09) - fixed some "-w" warnings. - complain when certain programs and paths can't be found. 2.01 : (1997-12-12) - bugfix: * rules for db-table where not calculated and reported correctly. 2.02 : (1998-01-xx) - bugfix: * Privileges of the user-table were not AND-ed properly with the other privileges. (reported by monty) - new option: * --old_server: mysqlaccess will now use a full where clause when retrieving information from the MySQL-server. If you are connecting to an old server (before v3.21) then use the option --old_server. 2.03 : (1998-02-27) - bugfix: * in Host::MatchTemplate: incorrect match if host-field was left empty. 2.04-alpha1 : (2000-02-11) Closes vulnerability due to former implementation requiring passwords to be passed on the command line. - functionality Option values for --password -p -spassword -P may now be omitted from command line, in which case the values will be prompted for. (fix supplied by Steve Harvey ) 2.05: (2000-02-17) Monty Moved the log file from /tmp to ~ 2.06: Don't print '+++USING FULL WHERE CLAUSE+++' _RELEASE $TODO = <<_TODO; Plans: ----- -a full where clause is use now. How can we handle older servers? -add some more functionality for DNS. -select the warnings more carefuly. >> I think that the warnings should either be enhanced to _really_ >> understand and report real problems accurately, or restricted to >> only printing things that it knows with 100% certainty. > Why do I have both '%' and 'any_other_host' in there? Isn't that >> the same thing? I think it's because I have an actual host '%' in >> one of my tables. Probably the script should catch that and not >> duplicate output. _TODO # From the FAQ: the Grant-algorithm # ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ # The host table is mainly to maintain a list of "secure" servers. # At TCX hosts contain a list of all machines on local network. These are granted # all privileges. # Technically the user grant is calculated by: # # 1.First sort all entries by host by putting host without wildcards first, # after this host with wildcards and entries with host = ". # Under each host sort user by the same criterias. # 2.Get grant for user from the "db" table. # 3.If hostname is "empty" for the found entry, AND the privileges with # the privileges for the host in "host" table. # (Remove all which is not "Y" in both) # 4.OR (add) the privileges for the user from the "user" table. # (add all privileges which is "Y" in "user") # # When matching, use the first found match. # # ----------------------------------------------------------------------------------- $HOWTO = <<_HOWTO; Examples of how to call $script: ~~~~~~~~ 1)Calling $script with 2 arguments: \$ $script root mysql ->report rights of user root logged on at the local host in db mysql Access-rights for USER 'root', from HOST 'localhost', to DB 'mysql' +-----------------+---+ +-----------------+---+ | select_priv | Y | | drop_priv | Y | | insert_priv | Y | | reload_priv | Y | | update_priv | Y | | shutdown_priv | Y | | delete_priv | Y | | process_priv | Y | | create_priv | Y | | file_priv | Y | +-----------------+---+ +-----------------+---+ BEWARE: Everybody can access your DB as user 'root' : WITHOUT supplying a password. Be very careful about it!! The following rules are used: db : 'No matching rule' host : 'Not processed: host-field is not empty in db-table.' user : 'localhost','root','','Y','Y','Y','Y','Y','Y','Y','Y','Y','Y' 2)Calling $script with 3 arguments: \$ $script foo.bar nobody Foo ->report rights of user root logged in at machine foobar to db Foo Access-rights for USER 'nobody', from HOST 'foo.bar', to DB 'Foo' +-----------------+---+ +-----------------+---+ | select_priv | Y | | drop_priv | N | | insert_priv | Y | | reload_priv | N | | update_priv | Y | | shutdown_priv | N | | delete_priv | Y | | process_priv | N | | create_priv | N | | file_priv | N | +-----------------+---+ +-----------------+---+ BEWARE: Everybody can access your DB as user 'nobody' : WITHOUT supplying a password. Be very careful about it!! The following rules are used: db : 'foo.bar','Foo','nobody','Y','Y','Y','N','N','N' host : 'Not processed: host-field is not empty in db-table.' user : 'foo.bar','nobody','','N','N','N','Y','N','N','N','N','N','N' 3)Using wildcards: \$ $script \\* nobody Foo --brief ->report access-rights of user nobody from all machines to db Foo, and use a matrix-report. Sel Ins Upd Del Crea Drop Reld Shut Proc File Host,User,DB ---- ---- ---- ---- ---- ---- ---- ---- ---- ---- -------------------- Y Y Y Y N N N N N N localhost,nobody,Foo N N N N N N N N N N %,nobody,Foo N N N N N N N N N N any_other_host,nobody,Foo _HOWTO # +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ # # START OF THE PROGRAM # # +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ # use Getopt::Long; use Sys::Hostname; use IPC::Open3; # **************************** # debugging flag # can be set to 0,1,2,3 # a higher value gives more info # ! this can also be set on the command-line $DEBUG = 0; # ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++>8 # Normally nothing should be changed beneeth this line # **************************** # no caching on STDOUT $|=1; $MYSQL_CNF = tmpnam(); %MYSQL_CNF = (client => { }, mysql => { }, mysqldump => { }, ); $NEW_USER = 'ANY_NEW_USER'; $NEW_DB = 'ANY_NEW_DB' ; # %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% # # mysqlaccess: # # ~~~~~~~~~~~ # # Lets get to it, # # and start the program by processing the parameters # # %%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%% # ($CMD,$CGI) = GetMode(); # **************************** # the copyright message should # always be printed (once) MySQLaccess::Report::Print_Header(); # ***************************** # Read configuration-file MySQLaccess::Debug::Print(1, "Reading configuration file..."); if (-f "/etc/$script_conf") { print "Configuration file '$script_conf' is found in '/etc/'\n"; require "/etc/$script_conf"; } elsif (-f "/usr/$script_conf") { print "Configuration file '$script_conf' is found in '/usr/'\n"; require "/usr/$script_conf"; } elsif (-f "./$script_conf") { print "\nERROR! Configuration file '$script_conf' is found in the current "; print "directory.\nThe permissible locations for this file are either "; print "/etc/ or /usr/\n"; print "Please move it to one of these locations and retry.\n\n"; exit 0; } # **************************** # Read in all parameters if ($MySQLaccess::CMD) { #command-line version # ---------------------------- # Get options from commandline $Getopt::Long::ignorecase=0; #case sensitive options if ( grep(/\-\?/,@ARGV) ) { MySQLaccess::Report::Print_Usage(); exit 0; } GetOptions("help" => \$Param{'help'} ,"host|h=s" => \$Param{'host'} ,"user|u=s" => \$Param{'user'} ,"password|p:s" => \$Param{'password'} ,"db|d=s" => \$Param{'db'} ,"superuser|U=s" => \$Param{'superuser'} ,"spassword|P:s" => \$Param{'spassword'} ,"rhost|H=s" => \$Param{'rhost'} ,"old_server" => \$Param{'old_server'} ,"debug=i" => \$Param{'DEBUG'} ,"brief|b" => \$Param{'brief'} ,"table|t" => \$Param{'table'} ,"relnotes" => \$Param{'relnotes'} ,"plan" => \$Param{'plan'} ,"howto" => \$Param{'howto'} ,"version|v" => \$Param{'version'} ,"preview" => \$Param{'preview'} ,"copy" => \$Param{'copy'} ,"commit" => \$Param{'commit'} ,'rollback' => \$Param{'rollback'} ); # ----------------------------- # set DEBUG $DEBUG = $Param{'DEBUG'} if ($Param{'DEBUG'}>=$DEBUG); # ----------------------------- # check for things which aren't # declared as options: # 2 arguments: (user,db) -> ('localhost','user','db') if ($#ARGV == 1) { MySQLaccess::Debug::Print(2,"$script called with 2 arguments:"); $Param{'host'} = $Param{'host'} || 'localhost'; $Param{'user'} = $ARGV[0] || $Param{'user'}; $Param{'db'} = $ARGV[1] || $Param{'db'}; } # 3 arguments: (host,user,db) if ($#ARGV == 2) { MySQLaccess::Debug::Print(2,"$script called with 3 arguments:"); $Param{'host'} = $ARGV[0] || $Param{'host'}; $Param{'user'} = $ARGV[1] || $Param{'user'}; $Param{'db'} = $ARGV[2] || $Param{'db'}; } # ------------------------------------- # prompt for user password if requested if ( defined($Param{'password'}) && length($Param{'password'}) == 0 ) { $Param{'password'} = PromptPass( "Password for MySQL user $Param{'user'}: "); } } if ($MySQLaccess::CGI) { #CGI-version require CGI; $Q = new CGI; $Param{'help'} = $Q->param('help') ; $Param{'host'} = $Q->param('host') || $Q->param('h') || $Param{'host'}; $Param{'user'} = $Q->param('user') || $Q->param('u') || $Param{'user'}; $Param{'db'} = $Q->param('db') || $Q->param('d') || $Param{'db'}; $Param{'password'} = $Q->param('password') || $Q->param('p') || $Param{'password'}; $Param{'superuser'} = $Q->param('superuser') || $Q->param('U') || $Param{'superuser'}; $Param{'spassword'} = $Q->param('spassword') || $Q->param('P') || $Param{'spassword'}; $Param{'rhost'} = $Q->param('rhost') || $Q->param('H') || $Param{'rhost'}; $Param{'old_server'}= $Q->param('old_server')|| $Param{'old_server'}; $Param{'debug'} = $Q->param('debug') || $Param{'debug'}; $Param{'brief'} = $Q->param('brief') || $Param{'brief'}; $Param{'table'} = $Q->param('table') || $Param{'table'}; $Param{'relnotes'} = $Q->param('relnotes'); $Param{'plan'} = $Q->param('plan'); $Param{'howto'} = $Q->param('howto'); $Param{'version'} = $Q->param('version') ? $Q->param('version') : $Q->param('v'); $Param{'edit'} = $Q->param('edit'); $Param{'preview'} = $Q->param('preview'); $Param{'copy'} = $Q->param('copy'); $Param{'commit'} = $Q->param('commit'); $Param{'rollback'} = $Q->param('rollback'); # ----------------------------- # set DEBUG $DEBUG = $Q->param('debug') if ($Q->param('debug')>=$DEBUG); } # ---------------------- # brief and table-format # exclude each-other # table-format is preferred if (defined($Param{'table'})) { undef($Param{'brief'}); } if (defined($Param{'preview'}) or defined($Param{'copy'}) or defined($Param{'commit'}) or defined($Param{'rollback'}) ) { $Param{'edit'}='on'; } # ---------------------- # if no host is given # assume we mean 'localhost' if (!defined($Param{'host'})) { $Param{'host'}='localhost'; } # ---------------------- # perform some checks # -> eliminate 'broken pipe' error push(@MySQLaccess::Grant::Error,'not_found_mysql') if !(-x $MYSQL); push(@MySQLaccess::Grant::Error,'not_found_diff') if !(-x $DIFF); push(@MySQLaccess::Grant::Error,'not_found_mysqldump') if !(-x $MYSQLDUMP); if (@MySQLaccess::Grant::Error) { MySQLaccess::Report::Print_Error_Messages() ; exit 0; } #----------------------- # get info/help if necc. $print_usage=1; if ( defined($Param{'version'}) ) { MySQLaccess::Report::Print_Version(); $print_usage=0; MySQLaccess::Report::Print_Footer(); MySQLaccess::DB::CloseConnection(); exit 0; # exit 0; } if ( defined($Param{'relnotes'}) ) { MySQLaccess::Report::Print_Relnotes(); $print_usage=0; MySQLaccess::Report::Print_Footer(); MySQLaccess::DB::CloseConnection(); exit 0; # exit 0; } if ( defined($Param{'plan'}) ) { MySQLaccess::Report::Print_Plans(); $print_usage=0; MySQLaccess::Report::Print_Footer(); MySQLaccess::DB::CloseConnection(); exit 0; # exit 0; } if ( defined($Param{'howto'}) ) { MySQLaccess::Report::Print_HowTo(); $print_usage=0; MySQLaccess::Report::Print_Footer(); MySQLaccess::DB::CloseConnection(); exit 0; # exit 0; } # ----------------------------- # generate a help-screen in CMD-mode # or a blanc form in CGI-mode if ( defined($Param{'help'}) or !defined($Param{'user'}) or !defined($Param{'host'}) or !defined($Param{'db'}) ) { push(@MySQLaccess::Grant::Error,'user_required') unless defined($Param{'user'}); push(@MySQLaccess::Grant::Error,'db_required') unless defined($Param{'db'}); push(@MySQLaccess::Grant::Error,'host_required') unless defined($Param{'host'}); MySQLaccess::Report::Print_Usage() if $print_usage; exit 0; } # ---------------------------- # get hostname and local-ip # for localhost $localhost = MySQLaccess::Host::LocalHost(); $local_ip = MySQLaccess::Host::Name2IP($localhost); $MySQLaccess::Host::localhost = MySQLaccess::Host::LocalHost(); $MySQLaccess::Host::local_ip = MySQLaccess::Host::Name2IP($localhost); MySQLaccess::Debug::Print(3, "localhost name=$localhost, ip=$local_ip"); #----------------------------------- # version of MySQL-server to connect # to determine use of full where clause $MySQLaccess::Host::SERVER = $Param{'old_server'} ? '3.20' : $SERVER; #--------------------------------- # create the config file for mysql and mysqldump # to avoid passing authentication info on the command line # MergeConfigFiles(); die "Unsafe config file found: $unsafeConfig\n" if $unsafeConfig; if (defined($Param{'superuser'})) { $MYSQL_CNF{'mysql'}{'user'} = $Param{'superuser'}; $MYSQL_CNF{'mysqldump'}{'user'} = $Param{'superuser'}; } if (defined($Param{'spassword'})) { if ( $CMD && length($Param{'spassword'}) == 0 ) { $Param{'spassword'} = PromptPass("Password for MySQL superuser $Param{'superuser'}: "); } if ( length($Param{'spassword'}) > 0 ) { $MYSQL_CNF{'mysql'}{'password'} = $Param{'spassword'}; $MYSQL_CNF{'mysqldump'}{'password'} = $Param{'spassword'}; } } WriteTempConfigFile(); #--------------------------------- # Inform user if he has not enough # privileges to read the access-db if ( $nerror=MySQLaccess::DB::OpenConnection() ) { MySQLaccess::Report::Print_Error_Access($nerror); exit 0; } # ----------------------- # Read MySQL ACL-files if ($nerror=MySQLaccess::Grant::ReadTables()) { MySQLaccess::Report::Print_Error_Access($nerror); exit 0; }; if ($Param{'edit'} and $nerror=MySQLaccess::Grant::ReadTables('tmp')) { MySQLaccess::Report::Print_Error_Access($nerror); exit 0; } #--------------------------------- # reload temporay grant-tables # with data from original ones if ( defined($Param{'copy'}) ) { $nerror=MySQLaccess::DB::LoadTmpTables(); if ($nerror) { MySQLaccess::Report::Print_Error_Access($nerror); exit 0; } my $msg = "The grant-rules are copied from the grant-tables to\n" . "the temporary tables."; MySQLaccess::Report::Print_Message([$msg]); # MySQLaccess::Report::Print_Footer(); # MySQLaccess::DB::CloseConnection(); # exit 0; } #--------------------------------- # preview result of changes in the # grant-tables if ( defined($Param{'preview'}) ) { $aref=MySQLaccess::Grant::Diff_Privileges(); MySQLaccess::Report::Print_Diff_ACL($aref); # MySQLaccess::Report::Print_Footer(); # MySQLaccess::DB::CloseConnection(); # exit 0; } #--------------------------------- # reload grant-tables # with data from temporary tables if ( defined($Param{'commit'}) ) { if ($nerror = MySQLaccess::DB::CommitGrantTables()) { MySQLaccess::Report::Print_Error_Access($nerror); exit 0; } my $msg = "The grant-rules have been copied from the temporary tables\n" . "to the grant-tables."; my $msg1= "Don't forget to do an 'mysqladmin reload' before these\n" . "changes take effect."; my $msg2= "A backup-version of your original grant-rules are saved in the\n" . "backup-tables, so you can always perform a 1-level rollback."; MySQLaccess::Report::Print_Message([$msg,$msg1,$msg2]); # MySQLaccess::Report::Print_Footer(); # MySQLaccess::DB::CloseConnection(); # exit 0; } #--------------------------------- # restore previous grant-rules # with data from backup tables if ( defined($Param{'rollback'}) ) { if ($nerror = MySQLaccess::DB::RollbackGrantTables()) { MySQLaccess::Report::Print_Error_Access($nerror); exit 0; } my $msg = "The old grant-rules have been copied back from the backup tables\n" . "to the grant-tables."; my $msg1= "Don't forget to do an 'mysqladmin reload' before these\n" . "changes take effect."; MySQLaccess::Report::Print_Message([$msg,$msg1]); # MySQLaccess::Report::Print_Footer(); # MySQLaccess::DB::CloseConnection(); # exit 0; } #---------------------------------- # show edit-taskbar if ( defined($Param{'edit'})) { if ($MySQLaccess::CGI ) { MySQLaccess::Report::Print_Edit(); $print_usage=0; MySQLaccess::Report::Print_Footer(); MySQLaccess::DB::CloseConnection(); exit 0; } else { MySQLaccess::Report::Print_Edit(); $print_usage=0; MySQLaccess::Report::Print_Footer(); MySQLaccess::DB::CloseConnection(); exit 0; } } # ----------------------------- # Build list of users,dbs,hosts # to process... @all_dbs = @{MySQLaccess::DB::Get_All_dbs($Param{'db'})}; @all_users = @{MySQLaccess::DB::Get_All_users($Param{'user'})}; @all_hosts = @{MySQLaccess::DB::Get_All_hosts($Param{'host'})}; #if EDIT-mode #@all_dbs_tmp = @{MySQLaccess::DB::Get_All_dbs($Param{'db'},'tmp')}; #@all_users_tmp = @{MySQLaccess::DB::Get_All_users($Param{'user'},'tmp')}; #@all_hosts_tmp = @{MySQLaccess::DB::Get_All_hosts($Param{'host'},'tmp')}; # ----------------------------- # Report access-rights for each # tuple (host,user,db) #$headers=0; my %Access = (); foreach $host (@all_hosts) { foreach $user (@all_users) { foreach $db (@all_dbs) { MySQLaccess::Grant::Initialize(); %Access = MySQLaccess::Grant::Get_Access_Rights($host,$user,$db); MySQLaccess::Report::Print_Access_rights($host,$user,$db,\%Access); } } } # ----------------------------- # End script MySQLaccess::Report::Print_Footer(); MySQLaccess::DB::CloseConnection(); exit 0; ############################################################# # FUNCTIONS # ############### sub GetMode { my $cmd=0; my $cgi=0; if (defined($ENV{'HTTP_HOST'})) { $cmd=0; $cgi=1; } else { $cmd=1; $cgi=0; } return ($cmd,$cgi); } # ================================ # sub PromptPass # prompt tty for a password # ================================ sub PromptPass { my ($prompt) = @_; my $password; $ENV{PATH} = "/bin:/usr/bin"; $ENV{IFS} = " \t\n"; $ENV{SHELL} = "/bin/sh"; system "stty -echo"; print $prompt; chomp($password = ); print "\n"; system "stty echo"; $password; } # ================================= # sub CheckUnsafeFile # tell if a config file containing a password is unsafe # ================================= sub CheckUnsafeFile { my ($fname) = @_; my ($dev, $ino, $mode, $nlink, $uid, $gid, $rdev, $size, $atime, $mtime, $ctime, $blksize, $blocks) = stat($fname); if ( $uid != $< ) { # unsafe if owned by other than current user return 1; } if ( $mode & 066 ) { # unsafe if accessible by other return 1; } $fname =~ s#/[^/]+$##; if ( (length $fname) > 0 ) { return CheckUnsafeDir($fname); } return 0; } # ================================= # sub CheckUnsafeDir # tell if a directory is unsafe # ================================= sub CheckUnsafeDir { my ($fname) = @_; my ($dev, $ino, $mode, $nlink, $uid, $gid, $rdev, $size, $atime, $mtime, $ctime, $blksize, $blocks) = stat($fname); # not owned by me or root if ( ($uid != $<) && ($uid != 0) ) { return 1; } if ( $mode & 022 ) { # unsafe if writable by other return 1 unless $mode & 01000; # but sticky bit ok } $fname =~ s#/[^/]+$##; if ( (length $fname) > 0 ) { return CheckUnsafeDir($fname); } return 0; } # ================================= # sub MergeConfigFile # merge data from .cnf file # ================================= sub MergeConfigFile { my ($fname) = @_; my ($group, $item, $value); if ( open CNF, $fname ) { while () { s/^\s+//; next if /^[#;]/; if ( /\[\s*(\w+)\s*]/ ) { $group = $1; $group =~ tr/A-Z/a-z/; if ( !exists $MYSQL_CNF{$group} ) { undef $group; } } elsif ( defined $group ) { ($item, $value) = /((?:\w|-)+)\s*=\s*(\S+)/; # don't unquote backslashes as we just write it back out if ( defined $item ) { if ( $item =~ /^password$/ ) { if ( CheckUnsafeFile($fname) ) { $unsafeConfig = $fname; } } if ( $group eq 'client' || $group eq "client-server") { $MYSQL_CNF{'mysql'}{$item} = $value; $MYSQL_CNF{'mysqldump'}{$item} = $value; } else { $MYSQL_CNF{$group}{$item} = $value; } } } } close(CNF); } } # ================================= # sub MergeConfigFiles # merge options from config files # NOTE: really should do two separate merges for each # client to exactly duplicate order of resulting argument lists # ================================= sub MergeConfigFiles { my ($name,$pass,$uid,$gid,$quota,$comment,$gcos,$dir,$shell) = getpwuid $<; MergeConfigFile("/usr/my.cnf"); MergeConfigFile("/etc/my.cnf"); MergeConfigFile("$dir/.my.cnf"); } # ================================= # sub WriteTempConfigFile # write # ================================= sub WriteTempConfigFile { sysopen CNFFILE, $MYSQL_CNF, O_RDWR|O_CREAT|O_EXCL, 0700 or die "sysopen $MYSQL_CNF: $!"; # groups may be in any order, generic groups such as [client] assumed # here to be empty foreach $group (keys %MYSQL_CNF) { print CNFFILE "[$group]\n"; foreach $item (keys %{$MYSQL_CNF{$group}}) { if ( defined $MYSQL_CNF{$group}{$item} ) { print CNFFILE "$item=$MYSQL_CNF{$group}{$item}\n"; } else { print CNFFILE "$item\n"; } } print CNFFILE "\n"; } close(CNFFILE); } ###################################################################### package MySQLaccess::DB; ########### BEGIN { $DEBUG = 2; $DEBUG = $MySQLaccess::DEBUG unless ($DEBUG); # Error-messages from the MySQL client %ACCESS_ERR= ('Access_denied' => 'Access denied' ,'Dbaccess_denied' => 'Access to database denied' ,'Unrecognized_option' => 'unrecognized option' ,'Unknown_table' => "Can't find file:" ,'unknown_error' => '^ERROR:' ); } # ###################################### # Connecting to the MYSQL DB # ====================================== # sub OpenConnection # Open an connection to the mysql-db # questions to MYSQL_Q # answers from MYSQL_A # ====================================== sub OpenConnection { my $pid; MySQLaccess::Debug::Print(2,"OpenConnection:"); # check path to mysql-client executable if (! -f $MySQLaccess::MYSQL) { if ($MySQLaccess::CMD) { die "Could not find MySQL-client '$MySQLaccess::MYSQL'"; } if ($MySQLaccess::CGI) { print "
\n\n"; print "ERROR: Could not find MySQL-client '$MySQLaccess::MYSQL'"; print "
\n\n"; exit 0; } } # path to mysql executable my $connect = "$MySQLaccess::MYSQL --defaults-file=$MySQLaccess::MYSQL_CNF"; $connect .= " $MySQLaccess::MYSQL_OPT"; # superuser, spassword transmitted via defaults-file if (defined($MySQLaccess::Param{'rhost'})) { $connect .= " --host=$MySQLaccess::Param{'rhost'}"; } # other options?? # grant-database $connect .= " $MySQLaccess::ACCESS_DB"; # open connection (not using /bin/sh -c) MySQLaccess::Debug::Print(2,"Connecting to: $connect"); $pid=IPC::Open3::open3(\*MYSQL_Q,\*MYSQL_A,"",split /\s+/,$connect); MySQLaccess::Debug::Print(2,"PID of open pipe: $pid"); # check connection print MYSQL_Q "select 'ok';\n"; $answer = ; #answer from mysql MySQLaccess::Debug::Print(2,"Answer: $answer\n"); foreach $nerror (sort(keys(%ACCESS_ERR))) { MySQLaccess::Debug::Print(3,"check answer for error $ACCESS_ERR{$nerror}"); if (grep(/$ACCESS_ERR{$nerror}/i,$answer)) { MySQLaccess::Debug::Print(2,"Answer contain error [$nerror]"); return $nerror; } } if (0) { # check server-version print MYSQL_Q "select 'ok';\n"; $answer = ; #answer from mysql MySQLaccess::Debug::Print(2,"Answer: $answer\n"); foreach $nerror (sort(keys(%ACCESS_ERR))) { MySQLaccess::Debug::Print(3,"check answer for error $ACCESS_ERR{$nerror}"); if (grep(/$ACCESS_ERR{$nerror}/i,$answer)) { MySQLaccess::Debug::Print(2,"Answer contain error [$nerror]"); return $nerror; } } } my $skip=; return 0; } # ====================================== # sub CloseConnection # Close the connection to the mysql-db # ====================================== sub CloseConnection { close MYSQL_Q; close MYSQL_A; } # =========================================================== # sub CreateTable($table) # Create temporary/backup table # =========================================================== sub CreateTable { my $pid; my ($table,$force) = @_; my %tables = ( $MySQLaccess::ACCESS_U_TMP => $MySQLaccess::ACCESS_U, $MySQLaccess::ACCESS_H_TMP => $MySQLaccess::ACCESS_H, $MySQLaccess::ACCESS_D_TMP => $MySQLaccess::ACCESS_D, $MySQLaccess::ACCESS_U_BCK => $MySQLaccess::ACCESS_U, $MySQLaccess::ACCESS_H_BCK => $MySQLaccess::ACCESS_H, $MySQLaccess::ACCESS_D_BCK => $MySQLaccess::ACCESS_D, $MySQLaccess::ACCESS_U => $MySQLaccess::ACCESS_U_BCK, $MySQLaccess::ACCESS_H => $MySQLaccess::ACCESS_H_BCK, $MySQLaccess::ACCESS_D => $MySQLaccess::ACCESS_D_BCK, ); my $tbl; my $query=""; my $delim; my $skip; my $create; my @known_tables=(); # print STDERR "CreateTable($table)\n"; MySQLaccess::Debug::Print(1,"CreateTable($table):"); ## error-handling return 'Unknown_table' unless defined($tables{$table}); ## build list of known/existing tables; ## if 'force' existing table is dropped first if (defined($force) and $force) { @known_tables = Show_Tables(); if (grep(/^$table$/,@known_tables)) { $query = "DROP TABLE $table;"; } } ## path to mysqldump executable my $connect = $MySQLaccess::MYSQLDUMP; $connect .= " --defaults-file=$MySQLaccess::MYSQL_CNF --no-data"; # superuser, spassword transmitted via defaults-file if (defined($MySQLaccess::Param{'rhost'})) { $connect .= " --host=$MySQLaccess::Param{'rhost'}"; } $connect .= " $MySQLaccess::ACCESS_DB"; $connect .= " $tables{$table}"; ## get creation-data for original table $create = ''; my $mysqldump = $connect; $mysqldump =~ s/ \$TABLE / $tbl /; # open connection (not using /bin/sh -c) MySQLaccess::Debug::Print(2,"Connecting to: $connect"); $pid=IPC::Open3::open3(\*DONTCARE,\*CREATE,"",split /\s+/,$mysqldump); MySQLaccess::Debug::Print(2,"PID of open pipe: $pid"); #open(CREATE,"$mysqldump"); @create = ; $create = "@create"; foreach $nerror (sort(keys(%ACCESS_ERR))) { MySQLaccess::Debug::Print(3,"check answer for error $ACCESS_ERR{$nerror}"); if (grep(/$ACCESS_ERR{$nerror}/i,$create)) { MySQLaccess::Debug::Print(2,"Answer contain error [$nerror]"); return $nerror; } } close(CREATE); close(DONTCARE); ## manipulate result for creation-data for temporary table $create =~ s/CREATE TABLE $tables{$table} \(/CREATE TABLE $table \(/; ## recreate temporary table $query .= "$create\n"; $query .= "select 'ok';"; ## execute query print MYSQL_Q "$query\n"; # print STDERR $query; $answer = ; #answer from mysql # print STDERR "A>",$answer; MySQLaccess::Debug::Print(2,"Answer: $answer\n"); foreach $nerror (sort(keys(%ACCESS_ERR))) { # print STDERR "->$nerror?"; MySQLaccess::Debug::Print(3,"check answer for error $ACCESS_ERR{$nerror}"); if (grep(/$ACCESS_ERR{$nerror}/i,$answer)) { # print STDERR "Yes!"; MySQLaccess::Debug::Print(2,"Answer contain error [$nerror]"); return $nerror; } } $delim = ; # read header if ($delim ne "ok\n") { while (($line=) ne "ok\n") { MySQLaccess::Debug::Print(3," A> $line"); } $skip = ; # skip result 'ok' } # print STDERR "CreateTable done\n"; return 0; } # =========================================================== # sub CopyTable() # Copy the structure and the data of a table to another table # =========================================================== sub CopyTable { my ($from,$to,$force) = @_; my @known_tables = Show_Tables(); my $query = ""; my $nerror= 0; my $skip; # print STDERR "CopyTable($from,$to)\n"; MySQLaccess::Debug::Print(1,"MySQLaccess::DB::CopyTable($from,$to)"); ## error-handling if (!grep(/^$from$/,@known_tables)) { return 'Unknown_table'; } ## copy structure ## if forced if (defined($force) and $force) { return $nerror if ($nerror=CreateTable($to,$force)); # print STDERR "Structure copied\n"; } ## copy data $query .= "DELETE FROM $to;"; $query .= "INSERT INTO $to SELECT * FROM $from;"; $query .= "SELECT 'ok';\n"; MySQLaccess::Debug::Print(2,"Query: $query"); ## execute query print MYSQL_Q "$query\n"; # print STDERR $query; ## check for errors... my $answer = ; #answer from mysql # print STDERR $answer; MySQLaccess::Debug::Print(2,"Answer: $answer\n"); foreach $nerror (sort(keys(%ACCESS_ERR))) { MySQLaccess::Debug::Print(3,"check answer for error $ACCESS_ERR{$nerror}"); if (grep(/$ACCESS_ERR{$nerror}/i,$answer)) { MySQLaccess::Debug::Print(2,"Answer contain error [$nerror]"); return $nerror; } } my $delim = ; # read header # print STDERR $delim; if ($delim ne "ok\n") { while (($line=) ne "ok\n") { MySQLaccess::Debug::Print(3," A> $line"); } $skip = ; # skip result 'ok' } return 0; } # =========================================================== # sub LoadTmpTables() # (Re)load temporary tables with entries of ACL-tables # =========================================================== sub LoadTmpTables { my %tables = ( $MySQLaccess::ACCESS_U => $MySQLaccess::ACCESS_U_TMP, $MySQLaccess::ACCESS_H => $MySQLaccess::ACCESS_H_TMP, $MySQLaccess::ACCESS_D => $MySQLaccess::ACCESS_D_TMP, ); my $tbl; my $nerror; # print STDERR "LoadTmpTables:\n"; MySQLaccess::Debug::Print(1,"LoadTmpTables():"); foreach $tbl (keys(%tables)) { # print STDERR "$tbl -> $tables{$tbl}\n"; MySQLaccess::Debug::Print(2,"Loading table $tbl -> $tables{$tbl}."); return $nerror if ($nerror=CopyTable($tbl,$tables{$tbl},'force')); } return 0; } # =========================================================== # sub BackupGrantTables() # Make a backup of the original grant-tables # =========================================================== sub BackupGrantTables { my %tables = ( $MySQLaccess::ACCESS_U => $MySQLaccess::ACCESS_U_BCK, $MySQLaccess::ACCESS_H => $MySQLaccess::ACCESS_H_BCK, $MySQLaccess::ACCESS_D => $MySQLaccess::ACCESS_D_BCK, ); my $tbl; my $nerror; # print STDERR "BackupGrantTables:\n"; MySQLaccess::Debug::Print(1,"BackupGrantTables():"); foreach $tbl (keys(%tables)) { # print STDERR "$tbl -> $tables{$tbl}\n"; MySQLaccess::Debug::Print(2,"Backup table $tbl -> $tables{$tbl}."); return $nerror if ($nerror=CopyTable($tbl,$tables{$tbl},'force')); } return 0; } # =========================================================== # sub RollbackGrantTables() # Rollback the backup of the grant-tables # =========================================================== sub RollbackGrantTables { my %tables = ( $MySQLaccess::ACCESS_U_BCK => $MySQLaccess::ACCESS_U, $MySQLaccess::ACCESS_H_BCK => $MySQLaccess::ACCESS_H, $MySQLaccess::ACCESS_D_BCK => $MySQLaccess::ACCESS_D, ); my $tbl; my $nerror; # print STDERR "RollbackGrantTables:\n"; MySQLaccess::Debug::Print(1,"RollbackGrantTables():"); foreach $tbl (keys(%tables)) { # print STDERR "$tbl -> $tables{$tbl}\n"; MySQLaccess::Debug::Print(2,"Rollback table $tbl -> $tables{$tbl}."); return $nerror if ($nerror=CopyTable($tbl,$tables{$tbl},'force')); } return 0; } # =========================================================== # sub CommitGrantTables() # Copy grant-rules from temporary tables to the ACL-tables # =========================================================== sub CommitGrantTables { my %tables = ( $MySQLaccess::ACCESS_U => $MySQLaccess::ACCESS_U_TMP, $MySQLaccess::ACCESS_H => $MySQLaccess::ACCESS_H_TMP, $MySQLaccess::ACCESS_D => $MySQLaccess::ACCESS_D_TMP, ); my $tbl; my $query; my $delim; my $skip; my $create; print STDERR "CommitGrantTables()\n"; MySQLaccess::Debug::Print(1,"CommitGrantTables():"); ## Make backup of original grant-tables MySQLaccess::Debug::Print(2,"Making backup of original grant-tables..."); BackupGrantTables(); ## Copy data from temporay tables to grant-tables foreach $tbl (keys(%tables)) { print STDERR "$tbl -> $tables{$tbl}\n"; MySQLaccess::Debug::Print(2,"Loading data $tables{$tbl} -> $tbl."); return $nerror if ($nerror=CopyTable($tables{$tbl},$tbl)); } return 0; } # =========================================================== # sub Show_Fields($table): # return (a reference to) a hash which holds the names # of all relevant grant-fields, with their index in the record, # and (a reference to) an array which holds the fieldnames. # =========================================================== sub Show_Fields { my ($table) = @_; my %skip = ('host' => [0,1] ,'user' => [0,1,2] ,'db' => [0,1,2] ); my %Struct = (); my @Struct = (); my $query = "show fields from $table;select 'ok';\n"; my $i=0; my $line; #print STDERR $query; MySQLaccess::Debug::Print(1,"Show_Fields($table):"); MySQLaccess::Debug::Print(2,"SQL: $query"); print MYSQL_Q "$query"; my $skip = ; #skip header while (($line=) ne "ok\n") { #print STDERR ">",$line; chop($line); MySQLaccess::Debug::Print(2," $table>: $line"); my ($field,$type,$null,$key,$default,$extra) = split(' ',$line); $field = ucfirst($field); MySQLaccess::Debug::Print(3, " added column[$i]: $field ($Struct{$field})"); } else { MySQLaccess::Debug::Print(3," ==> skipped column[$i], value=[$field]"); } $i++; } $skip=; # Get ok row (found already ok header) MySQLaccess::Debug::Print(2, "Array:"); foreach $field (@Struct) { MySQLaccess::Debug::Print(2,"+ $field"); } MySQLaccess::Debug::Print(2,"Hash:"); foreach $field (keys(%Struct)) { MySQLaccess::Debug::Print(2,"+ $field -> $Struct{$field}"); } return (\%Struct,\@Struct); } # =========================================================== # sub Show_Tables(): # return (a reference to) an array which holds all # known tables. # =========================================================== sub Show_Tables { my @Tables = (); my $query = "show tables;select 'ok';\n"; my $i=0; my $line; MySQLaccess::Debug::Print(1,"Show_Tables():"); MySQLaccess::Debug::Print(2,"SQL: $query"); print MYSQL_Q "$query"; my $skip = ; #skip header while (($line=) ne "ok\n") { chop($line); push(@Tables,$line); #array MySQLaccess::Debug::Print(3," ==> added table: $line"); } $skip=; # Get ok row (found already ok header) MySQLaccess::Debug::Print(2, "Array:"); foreach $tbl (@Tables) { MySQLaccess::Debug::Print(2,"+ $tbl"); } return @Tables; } # ====================================== # sub Validate_Password($passwd,$host,$user,$encpw) # Validate the given password # for user '$user' # connecting from host '$host' # ====================================== sub Validate_Password { my ($password,$host,$user,$encpw) = @_; my $valid=0; MySQLaccess::Debug::Print(1,"Validate_Password($password,$host,$user,$encpw)"); my $sql = "select host,user,password from user having " ."host='$host' and user='$user' and password='$encpw' " ."and password=PASSWORD('$password');\n"; $sql .= "select 'ok';\n"; MySQLaccess::Debug::Print(2,"SQL = $sql"); print MYSQL_Q "$sql"; # if password is valid, at least 1 row returns before we read 'ok' while ( ($line=) ne "ok\n") { MySQLaccess::Debug::Print(2," A> $line"); $valid = defined($line); } my $skip = ; # read 'ok' return $valid; } # ========================================================== # sub Sort_fields: (rewritten by psmith) # Build the query for an ordered list of entries # ========================================================== sub Sort_fields { my ($start, $end, $sofar, $this, @rest) = (@_); my @where = ("((FIELD not like '\\%') AND (FIELD <> ''))", "((FIELD like '%\\%%') OR (FIELD like '%\\_%'))", "(FIELD = '')"); my $res = ''; $this or return ("$start $sofar $end"); $sofar .= ' AND ' if $sofar; foreach $w (@where) { my $f = $w; $f =~ s/FIELD/$this/g; $res .= Sort_fields($start, $end, "$sofar$f", @rest); } return ($res); } # =========================================================== # sub Sort_table: (rewritten by psmith) # return all entries in the given table, # in an ordered fashion # =========================================================== sub Sort_table { my ($tbl, @order) = @_; my @res=(); # as long as there's no full where clause (Distrib 3.20)... # use having :-( # NOTE: this clause WILL NOT work on 3.21, because of the # order of 'ORDER BY' and 'HAVING' my $start = "SELECT *,UCASE(host) as ucase_host FROM $tbl "; $start .= 'ORDER BY ' . join(',', @order) ." HAVING "; my $end = ";\n"; # server version 3.21 has a full where clause :-) if ($MySQLaccess::Host::SERVER >= '3.21') { # print "+++USING FULL WHERE CLAUSE+++\n"; $start = "SELECT *,UCASE(host) as ucase_host FROM $tbl WHERE "; $end = ' ORDER BY ' . join(',', @order) . ";\n"; } MySQLaccess::Debug::Print(1,"Sort_table():"); MySQLaccess::Debug::Print(2,"Sorting table $tbl by `@order'"); my $tmp; foreach $tmp (@order) { $tmp="UCASE(host)" if ($tmp eq "ucase_host"); } my $query = Sort_fields($start, $end, '', @order); $query .= "select 'ok';\n"; MySQLaccess::Debug::Print(2,"Query: $query"); print MYSQL_Q "$query\n"; my $delim = ; # read header MySQLaccess::Debug::Print(3," A> $delim"); if ($delim ne "ok\n") { if ($delim =~ /^ERROR/) { push(@MySQLaccess::Grant::Error,'use_old_server'); MySQLaccess::Report::Print_Error_Messages() ; exit 1; } while (($line=) ne "ok\n") { MySQLaccess::Debug::Print(3," A> $line"); push(@res,$line); } } my $skip = ; # skip result 'ok' # remove columnheaders from output @res = grep(!/^\Q$delim\E$/, @res); # remove trailing \n from each returned record chomp(@res); # each record has 1 field to much : ucase_host @res = grep { /(.*)\t.*$/; $_ = $1; } @res; MySQLaccess::Debug::Print(2,"Result of sorted table $tbl:"); foreach $line (@res) { MySQLaccess::Debug::Print(2," >>$line"); } return @res; } # =========================================================== # sub Get_All_db(template): # return all db the grant-tables are working on, # which conform to the template # =========================================================== sub Get_All_dbs { my ($template,$tmp) = @_; my @db=(); my $aref; # working with temporary tables or production tables if (defined($tmp) and $tmp) { $aref = \@MySQLaccess::Grant::sorted_db_tmp_table ; } else { $aref = \@MySQLaccess::Grant::sorted_db_table; } MySQLaccess::Debug::Print(1," template=[$template]"); # get all db for which access-rights can be calculated, # which conform to the template. # !! these db's don't have to exist yet, so it's not # enough to look which db already exist on the system $reg_expr = $template; if ($template =~ /[\*\?]/) { $reg_expr =~ tr/*?/%_/; #$reg_expr = MySQLaccess::Wildcards::Wild2Reg($template); } $reg_expr = MySQLaccess::Wildcards::SQL2Reg("$reg_expr"); if ( ! ($template =~ /[\*\?%_]/) ) { push(@db,$template); return \@db; } MySQLaccess::Debug::Print(2,"#Reading db-table..."); foreach $record (@{$aref}) { #MySQLaccess::Grant::sorted_db_table) { my @record=split(/\t/,$record); my $db = $record[1]; MySQLaccess::Debug::Print(2,"> $db "); if ( (!grep(/$db/i,@db)) and ($db =~/$reg_expr/i) ) { push(@db,$db); MySQLaccess::Debug::Print(2,"added"); } else { MySQLaccess::Debug::Print(2,"skipped"); } } # if no rule is found for a certain db in the db-table, # the rights of the user are used, so we should inform # the user for if (!grep(/^%$/,@db)) { push(@db,"$MySQLaccess::NEW_DB"); } return \@db; } # =========================================================== # sub Get_All_users(template): # return all users the grant-tables are working on, # which conform to the template # =========================================================== sub Get_All_users { ($template,$tmp) = @_; # nog verder uitwerken!!! my @user=(); my $aref; # working with temporary tables or production tables if (defined($tmp) and $tmp) { $aref = \@MySQLaccess::Grant::sorted_user_tmp_table ; } else { $aref = \@MySQLaccess::Grant::sorted_user_table; } MySQLaccess::Debug::Print(1,"Debug Get_All_users:"); # get all db for which access-rights can be calculated. # !! these db's don't have to exist yet, so it's not # enough to look which db already exist on the system $reg_expr = $template; if ($template =~ /[\*\?]/) { $reg_expr =~ tr/*?/%_/; #$reg_expr = MySQLaccess::Wildcards::Wild2Reg($template); } $reg_expr = MySQLaccess::Wildcards::SQL2Reg("$reg_expr"); if ( ! ($template =~ /[\*\?%_]/) ) { push(@user,$template); return \@user; } MySQLaccess::Debug::Print(2,"#Reading user-table..."); foreach $record (@{$aref}) { #MySQLaccess::Grant::sorted_user_table) { my @record=split(/\t/,$record); my $user = $record[1]; MySQLaccess::Debug::Print(2,"> $user "); if ( (!grep(/$user/,@user)) and ($user=~/$reg_expr/)) { push(@user,$user); MySQLaccess::Debug::Print(2, "added"); } else { MySQLaccess::Debug::Print(2, "skipped"); } } # Any user means also: # - the 'empty' user, ie without supplying a username # - any user still to be defined/created #push(@user,''); #without_suplying_a_username push(@user,"$MySQLaccess::NEW_USER"); #push(@Warnings,'minimum_priv'); return \@user; } # =========================================================== # sub Get_All_hosts(template): # return all hosts the grant-tables are working on, # which conform to the template # =========================================================== sub Get_All_hosts { my ($template,$tmp) = @_; my @host=(); my $aref; my $aref1; # working with temporary tables or production tables if (defined($tmp) and $tmp) { $aref = \@MySQLaccess::Grant::sorted_host_tmp_table ; $aref1= \@MySQLaccess::Grant::sorted_db_tmp_table ; } else { $aref = \@MySQLaccess::Grant::sorted_host_table; $aref1= \@MySQLaccess::Grant::sorted_db_table ; } MySQLaccess::Debug::Print(1, "Debug Get_All_hosts:"); # get all db for which access-rights can be calculated. # !! these db's don't have to exist yet, so it's not # enough to look which db already exist on the system $reg_expr = $template; if ($template =~ /[\*\?]/) { $reg_expr =~ tr/*?/%_/; #$reg_expr = MySQLaccess::Wildcards::Wild2Reg($template); } $reg_expr = MySQLaccess::Wildcards::SQL2Reg("$reg_expr"); if ( ! ($template =~ /[\*\?%_]/) ) { push(@host,$template); return \@host; } MySQLaccess::Debug::Print(1, "#Reading db-table..."); foreach $record (@{$aref1}) { #MySQLaccess::Grant::sorted_db_table) { my @record=split(/\t/,$record); my $host = $record[0]; MySQLaccess::Debug::Print(2, "> $host "); if (! grep(/$host/i,@host)) { push(@host,$host); MySQLaccess::Debug::Print(2, "added"); } else { MySQLaccess::Debug::Print(2, "skipped"); } } MySQLaccess::Debug::Print(1, "#Reading host-table..."); foreach $record (@{$aref}) { my @record=split(/\t/,$record); my $host = $record[0]; MySQLaccess::Debug::Print(2, "> $host "); if ( (!grep(/$host/,@host)) and ($host=~/$reg_expr/)) { push(@host,$host); MySQLaccess::Debug::Print(2, "added"); } else { MySQLaccess::Debug::Print(2, "skipped"); } } # DOUBT: #print "#Reading user-table...\n" if ($DEBUG>1); #foreach $record (@MySQLaccess::Grant::sorted_user_table) { # my @record=split(/\t/,$record); # my $host = $record[0]; # print "> $host " if ($DEBUG>2); # if ( (!grep(/$host/,@host)) and ($host=~/$reg_expr/)) { # push(@host,$host); # print "added\n" if ($DEBUG>2); # } # else { # print "skipped\n" if ($DEBUG>2); # } #} # Any host also means: # - any host still to be defined/created #push(@host,"any_other_host"); @host = sort(@host); return \@host; } ########################################################################## package MySQLaccess::Grant; ############## BEGIN { $DEBUG = 0; $DEBUG = $MySQLaccess::DEBUG unless ($DEBUG); } # =========================================================== # sub Diff_Privileges() # Calculate diff between temporary and original grant-tables # =========================================================== sub Diff_Privileges { my @before=(); my @after =(); my @diffs =(); # ----------------------------- # Build list of users,dbs,hosts # to process... my @all_dbs = @{MySQLaccess::DB::Get_All_dbs('*')}; my @all_users = @{MySQLaccess::DB::Get_All_users('*')}; my @all_hosts = @{MySQLaccess::DB::Get_All_hosts('*')}; #if EDIT-mode my @all_dbs_tmp = @{MySQLaccess::DB::Get_All_dbs('*','tmp')}; my @all_users_tmp = @{MySQLaccess::DB::Get_All_users('*','tmp')}; my @all_hosts_tmp = @{MySQLaccess::DB::Get_All_hosts('*','tmp')}; my %Access; # ------------------------------------ # Build list of priv. for grant-tables foreach $host (@all_hosts) { foreach $user (@all_users) { foreach $db (@all_dbs) { MySQLaccess::Grant::Initialize(); %Access = MySQLaccess::Grant::Get_Access_Rights($host,$user,$db); push(@before,MySQLaccess::Report::Raw_Report($host,$user,$db,\%Access)); } } } # ---------------------------------- # Build list of priv. for tmp-tables foreach $host (@all_hosts_tmp) { foreach $user (@all_users_tmp) { foreach $db (@all_dbs_tmp) { MySQLaccess::Grant::Initialize('tmp'); %Access = MySQLaccess::Grant::Get_Access_Rights($host,$user,$db,'tmp'); push(@after,MySQLaccess::Report::Raw_Report($host,$user,$db,\%Access)); } } } # ---------------------------------- # Write results to temp-file to make # DIFF @before = sort(@before); @after = sort(@after); ($hb, $before) = tempfile("$MySQLaccess::script.XXXXXX") or push(@MySQLaccess::Report::Errors,"Can't create temporary file: $!"); ($ha, $after) = tempfile("$MySQLaccess::script.XXXXXX") or push(@MySQLaccess::Report::Errors,"Can't create temporary file: $!"); print $hb join("\n",@before); print $ha join("\n",@after); close $hb; close $ha; # ---------------------------------- # compute difference my $cmd="$MySQLaccess::DIFF $before $after |"; open(DIFF,"$cmd"); @diffs = ; @diffs = grep(/[<>]/,@diffs); chomp(@diffs); close(DIFF); # ---------------------------------- # cleanup temp. files unlink($before); unlink($after); return \@diffs; } # =========================================================== # sub Initialize() # # =========================================================== sub Initialize { %MySQLaccess::Grant::Access = %{Default_Access_Rights()}; @MySQLaccess::Grant::Errors = (); @MySQLaccess::Grant::Warnings = (); @MySQLaccess::Grant::Notes = (); # ----- # rules $MySQLaccess::Grant::Rules{'user'} = 'no_rule_found'; $MySQLaccess::Grant::Rules{'db'} = 'no_rule_found'; $MySQLaccess::Grant::Rules{'host'} = 'no_equiv_host'; $MySQLaccess::Grant::full_access = 1; $MySQLaccess::Grant::process_host_table = 0; return 1; } # =========================================================== # sub ReadTables() # # =========================================================== sub ReadTables { my ($tmp) = @_; my ($HOST,$DB,$USER); my @tables; # build list of available tables @tables = MySQLaccess::DB::Show_Tables(); # reading production grant-tables or temporary tables? $tmp = (defined($tmp) and $tmp) ? 1 : 0; if ($tmp) { #reading temporary tables $HOST=$MySQLaccess::ACCESS_H_TMP; $DB =$MySQLaccess::ACCESS_D_TMP; $USER=$MySQLaccess::ACCESS_U_TMP; # ---------------------------- # do tables exist? if (!grep(/$HOST/,@tables)) { MySQLaccess::DB::CreateTable($HOST); } if (!grep(/$USER/,@tables)) { MySQLaccess::DB::CreateTable($USER); } if (!grep(/$DB/,@tables)) { MySQLaccess::DB::CreateTable($DB); } MySQLaccess::Debug::Print(1,"Finding fields in tmp-ACL files:"); # ----------------------------- # Get record-layout my ($h1,$h2) = MySQLaccess::DB::Show_Fields($HOST); my ($d1,$d2) = MySQLaccess::DB::Show_Fields($DB); my ($u1,$u2) = MySQLaccess::DB::Show_Fields($USER); %MySQLaccess::Grant::H_tmp = %{$h1}; @MySQLaccess::Grant::H_tmp = @{$h2}; %MySQLaccess::Grant::D_tmp = %{$d1}; @MySQLaccess::Grant::D_tmp = @{$d2}; %MySQLaccess::Grant::U_tmp = %{$u1}; @MySQLaccess::Grant::U_tmp = @{$u2}; # @MySQLaccess::Grant::Privileges_tmp=@{Make_Privlist()}; # MySQLaccess::Debug::Print(1, "Reading sorted temp-tables:"); @MySQLaccess::Grant::sorted_db_tmp_table = MySQLaccess::DB::Sort_table($DB, 'ucase_host', 'user', 'db'); @MySQLaccess::Grant::sorted_host_tmp_table= MySQLaccess::DB::Sort_table($HOST, 'ucase_host', 'db'); @MySQLaccess::Grant::sorted_user_tmp_table= defined($MySQLaccess::Param{'password'}) ? MySQLaccess::DB::Sort_table($USER, 'ucase_host', 'user', 'password'): MySQLaccess::DB::Sort_table($USER, 'ucase_host', 'user'); } else { #reading production grant-tables $HOST=$MySQLaccess::ACCESS_H; $DB =$MySQLaccess::ACCESS_D; $USER=$MySQLaccess::ACCESS_U; MySQLaccess::Debug::Print(1,"Finding fields in ACL files:"); # ----------------------------- # Get record-layout my ($h1,$h2) = MySQLaccess::DB::Show_Fields($HOST); my ($d1,$d2) = MySQLaccess::DB::Show_Fields($DB); my ($u1,$u2) = MySQLaccess::DB::Show_Fields($USER); %MySQLaccess::Grant::H = %{$h1}; @MySQLaccess::Grant::H = @{$h2}; %MySQLaccess::Grant::D = %{$d1}; @MySQLaccess::Grant::D = @{$d2}; %MySQLaccess::Grant::U = %{$u1}; @MySQLaccess::Grant::U = @{$u2}; @MySQLaccess::Grant::Privileges=@{Make_Privlist()}; MySQLaccess::Debug::Print(1, "Reading sorted tables:"); @MySQLaccess::Grant::sorted_db_table = MySQLaccess::DB::Sort_table($DB, 'ucase_host', 'user', 'db'); @MySQLaccess::Grant::sorted_host_table= MySQLaccess::DB::Sort_table($HOST, 'ucase_host', 'db'); @MySQLaccess::Grant::sorted_user_table= defined($MySQLaccess::Param{'password'}) ? MySQLaccess::DB::Sort_table($USER, 'ucase_host', 'user', 'password'): MySQLaccess::DB::Sort_table($USER, 'ucase_host', 'user'); } return 0; } # =========================================================== # sub Get_Access_Rights(host,user,db) # report the access_rights for the tuple ($host,$user,$db). # =========================================================== sub Get_Access_Rights { local ($host,$user,$db,$tmp) = @_; my $aref_user; my $aref_host; my $aref_db; # working with temporary tables or production tables if (defined($tmp) and $tmp) { $aref_user = \@MySQLaccess::Grant::sorted_user_tmp_table; $aref_host = \@MySQLaccess::Grant::sorted_host_tmp_table; $aref_db = \@MySQLaccess::Grant::sorted_db_tmp_table; } else { $aref_user = \@MySQLaccess::Grant::sorted_user_table; $aref_host = \@MySQLaccess::Grant::sorted_host_table; $aref_db = \@MySQLaccess::Grant::sorted_db_table; } my ($refrecord,$refgrant); my ($_host_,$_user_,$encpw_); my %_Access_; MySQLaccess::Debug::Print(1, "for ($host,$user,$db):"); # ****************************************************************************** # Create default access-rights # default access-rights are no access at all!! # ****************************************************************************** # get hostname for IP-address # get IP-address for hostname local $host_name = MySQLaccess::Host::IP2Name($host); local $host_ip = MySQLaccess::Host::Name2IP($host); MySQLaccess::Debug::Print(3,"host=$host, hostname=$host_name, host-ip =$host_ip"); MySQLaccess::Debug::Print(3,"user=$user"); MySQLaccess::Debug::Print(3,"db =$db"); # *********************************************************************** # retrieve information on USER # check all records in mysql::user for matches with the tuple (host,user) # *********************************************************************** # 4.OR (add) the privileges for the user from the "user" table. # (add all privileges which is "Y" in "user") ($refrecord,$refgrant) = Get_grant_from_user($host,$user,$aref_user); ($_host_,$_user_,$encpw_) = @{$refrecord}; %_access_ = %{$refgrant}; foreach $field (keys(%U)) { ##only priv. set in user-table $MySQLaccess::Grant::Access{$field} = ($MySQLaccess::Grant::Access{$field} or $_access_{$field}); } if ($_user_ eq $MySQLaccess::NEW_USER) { push(@Warnings,'minimum_priv'); } if ($_user_ ne $user) { $user=$_user_; push(@Warnings,'anonymous_access'); } # ******************************************************* # Validate password if this has been asked to do # ******************************************************* if (defined($password)) { $valid = Validate_Password($password,$_host_,$_user_,$_encpw_,$aref_user); if (!$valid) { push(@Errors,'invalid_password'); } else { push(@Notes,'valid_password'); } } # ****************************************************************************** # retrieve information on DB # check all records in mysql::db for matches with the triple (host,db,user) # first match is used. # ****************************************************************************** # 2.Get grant for user from the "db" table. ($refrecord,$refgrant)=Get_grant_from_db($host,$db,$user,$aref_db); #set process_host_table ($_host_,$_user_,$encpw_) = @{$refrecord}; %_access_ = %{$refgrant}; foreach $field (keys(%D)) { ##only priv. set in db-table $MySQLaccess::Grant::Access{$field} = ($MySQLaccess::Grant::Access{$field} or $_access_{$field}); } # *********************************************************************** # retrieve information on HOST # check all records in mysql::host for matches with the tuple (host,db) # # ' The host table is mainly to maintain a list of "secure" servers. ' # *********************************************************************** # 3.If hostname is "empty" for the found entry, AND the privileges with # the privileges for the host in "host" table. # (Remove all which is not "Y" in both) if ($MySQLaccess::Grant::process_host_table) { ($refrecord,$refgrant)=Get_grant_from_host($host,$db,$aref_host); ($_host_,$_user_,$encpw_) = @{$refrecord}; %_access_ = %{$refgrant}; foreach $field (keys(%H)) { ##only priv. set in host-table $MySQLaccess::Grant::Access{$field} = ($MySQLaccess::Grant::Access{$field} and $_access_{$field}); } } MySQLaccess::Debug::Print(1,"done for ($host,$user,$db)"); return %MySQLaccess::Grant::Access; } # #################################### # FINDING THE RIGHT GRANT-RULE # ========================================================== # sub Get_grant_from_user: # ========================================================== sub Get_grant_from_user { my ($host,$user,$aref) = @_; MySQLaccess::Debug::Print(1, ""); MySQLaccess::Debug::Print(1, "(host=$host,user=$user)"); my %Access_user = %{Default_Access_Rights()}; my $rule_found=0; my @record = (); my $record; foreach $record (@{$aref}) { $MySQLaccess::Grant::full_access=0; MySQLaccess::Debug::Print(3, "Record= $record"); @record=split(/\t/,$record); # check host and db # with possible wildcards in field # replace mysql-wildcards by reg-wildcards my $host_tpl = MySQLaccess::Wildcards::SQL2Reg($record[0]); my $user_tpl = $record[1]; #user field isn't pattern-matched!! my $passwd = $record[2]; MySQLaccess::Debug::Print(3, "=>host_tpl : read=$record[0] -> converted=$host_tpl"); MySQLaccess::Debug::Print(3, "=>user_tpl : read=$record[1] -> $user_tpl"); MySQLaccess::Debug::Print(3, "=>password : read=$record[2] -> $passwd"); if ( MySQLaccess::Host::MatchTemplate($host,$host_tpl) and MySQLaccess::Wildcards::MatchTemplate($user_tpl,$user) ) { MySQLaccess::Debug::Print(2, "FOUND!!"); if ($passwd eq '') { push(@Warnings,'insecure_user'); } else { push(@Notes,'password_required'); } foreach $field (keys(%U)) { $Access_user{$field} = $MySQLaccess::Report::Answer{$record[$U{$field}]}; } #print "\n" if $DEBUG; $MySQLaccess::Grant::Rules{'user'} = $record; $rule_found=1; last; } } # ------------------------------- # setting privileges to user-priv MySQLaccess::Debug::Print(2, "Rights after parsing user-table..:"); if (! $rule_found ) { @record=(); MySQLaccess::Debug::Print(2, "NO record found in the user-table!!"); } else { MySQLaccess::Debug::Print(2, "Selected record=@record"); MySQLaccess::Debug::Print(2, "<=?=> $record"); } MySQLaccess::Debug::Print(1, "returning @record"); return (\@record,\%Access_user); #matching record in user-table } # ========================================================== # sub Get_grant_from_db: # ========================================================== sub Get_grant_from_db { my ($host,$db,$user,$aref) = @_; MySQLaccess::Debug::Print(1, "(host=$host,user=$user,db=$db)"); my %Access_db = %{Default_Access_Rights()}; my $rule_found=0; foreach $record (@{$aref}) { $full_access=0; MySQLaccess::Debug::Print(2, "Read db: $record"); @record=split(/\t/,$record); # check host and db # with possible wildcards in field # replace mysql-wildcards by reg-wildcards my $host_tpl = MySQLaccess::Wildcards::SQL2Reg($record[0]); my $db_tpl = MySQLaccess::Wildcards::SQL2Reg($record[1]); my $user_tpl = $record[2]; #user field isn't pattern matched!! MySQLaccess::Debug::Print(3, "=>host_tpl : read=$record[0] -> converted=$host_tpl"); MySQLaccess::Debug::Print(3, "=>db_tpl : read=$record[1] -> $db_tpl"); MySQLaccess::Debug::Print(3, "=>user_tpl : read=$record[2] -> $user_tpl"); if ( ( MySQLaccess::Host::Is_localhost($host_tpl) or MySQLaccess::Wildcards::MatchTemplate($host_tpl,$host_name) or MySQLaccess::Wildcards::MatchTemplate($host_tpl,$host_ip) ) and ( MySQLaccess::Wildcards::MatchTemplate($db_tpl,$db) ) and ( MySQLaccess::Wildcards::MatchTemplate($user_tpl,$user) ) ) { $MySQLaccess::Grant::process_host_table = ($record[0] eq ''); if ($user_tpl eq '') { push(@Warnings,'public_database'); } foreach $field (keys(%D)) { $Access_db{$field} = $MySQLaccess::Report::Answer{$record[$D{$field}]}; } $rule_found=1; $MySQLaccess::Grant::Rules{'db'} = $record; last; } } # ------------------------------- # setting privileges to db-priv MySQLaccess::Debug::Print(2, "Rights after parsing db-table..:"); if (! $rule_found ) { MySQLaccess::Debug::Print(2, "NO rule found in db-table => no access granted!!"); } return (\@record,\%Access_db); } # ========================================================== # sub Get_grant_from_host: # ========================================================== sub Get_grant_from_host { my ($host,$db,$aref) = @_; MySQLaccess::Debug::Print(1, "Get_grant_from_host()"); my %Access_host = %{Default_Access_Rights()}; # the host-table doesn't have to be processed if the host-field # in the db-table isn't empty if (!$MySQLaccess::Grant::process_host_table) { MySQLaccess::Debug::Print(2, ">> Host-table doesn't have to be processed!!"); $MySQLaccess::Grant::Rules{'host'} = 'no_equiv_host'; return ([],\%Access_host); } my $rule_found=0; my @record = (); foreach $record (@{$aref}) { $full_access=0; MySQLaccess::Debug::Print(2, "host: $record"); @record=split(/\t/,$record); # check host and db # with possible wildcards in field # replace mysql-wildcards by reg-wildcards my $host_tpl = MySQLaccess::Wildcards::SQL2Reg($record[0]); my $db_tpl = MySQLaccess::Wildcards::SQL2Reg($record[1]); MySQLaccess::Debug::Print(3, "=>host_tpl : $record[0] -> $host_tpl"); MySQLaccess::Debug::Print(3, "=>db_tpl : $record[1] -> $db_tpl"); if ( ( MySQLaccess::Host::Is_localhost($host_tpl) or MySQLaccess::Wildcards::MatchTemplate($host_tpl,$host_name) or MySQLaccess::Wildcards::MatchTemplate($host_tpl,$host_ip) ) and ( MySQLaccess::Wildcards::MatchTemplate($db_tpl,$db) ) ) { $MySQLaccess::Grant::Rules{'host'} = $record; $rule_found=1; foreach $field (keys(%H)) { $Access_host{$field} = $MySQLaccess::Report::Answer{$record[$H{$field}]}; } last; } } # ------------------------------- # setting privileges to host-priv MySQLaccess::Debug::Print(2, "Rights after parsing host-table..:"); if (! $rule_found ) { @record=(); MySQLaccess::Debug::Print(2, "NO restrictions found in the host-table!!"); } # -------------------------------- # debugging access-rights in db return (\@record,\%Access_host); #matching record in host-table } # =========================================================== # sub Default_Access_Rights(): # return (a reference to) a hash which holds all default # priviliges currently defined in the grant-tables. # =========================================================== sub Default_Access_Rights { my %right = (); MySQLaccess::Debug::Print(2, "Debug Default_Access_Rights():"); # add entry for all fields in the HOST-table foreach $field (keys(%MySQLaccess::Grant::H)) { $right{$field}='0' unless (defined($right{$field})); } # add entry for all fields in the DB-table foreach $field (keys(%MySQLaccess::Grant::D)) { $right{$field}='0' unless (defined($right{$field})); } # add entry for all fields in the USER-table foreach $field (keys(%MySQLaccess::Grant::U)) { $right{$field}='0' unless (defined($right{$field})); } # -------------- # debugging info foreach $field (keys(%right)) { MySQLaccess::Debug::Print(3, sprintf("> %15s : %1s",$field,$right{$field})); } return \%right; } # ====================================== # sub Make_Privlist # Make an ordered list of the privileges # that should be reported # ====================================== sub Make_Privlist { # layout: #'select_priv', 'create_priv', #'insert_priv', 'drop_priv', #'update_priv', 'reload_priv', #'delete_priv', 'process_priv', #'file_priv', 'shutdown_priv'); my $right; my @privlist=(); foreach $right (@U) { if (! grep(/$right/,@privlist)) { push(@privlist,$right); } }; foreach $right (@D) { if (! grep(/$right/,@privlist)) { push(@privlist,$right); } }; foreach $right (@H) { if (! grep(/$right/,@privlist)) { push(@privlist,$right); } }; # print "Privileges:\n"; # foreach $field (@privlist) { print " > $field\n"; } return \@privlist; } ######################################################################## package MySQLaccess::Report; use Exporter (); @EXPORT = qw(&Print_Header()); BEGIN { $FORM = $ENV{'SCRIPT_NAME'}; $DEBUG = 0; $DEBUG = $MySQLaccess::DEBUG unless ($DEBUG); # translation-table for poss. answers %Answer = ('Y' => 1 , 'N' => 0 , 1 => 'Y', 0 => 'N' ,'?' => '?', '' => '?' ); $headers = 0; $separator = 0; # **************************** # Notes and warnings %MESSAGES = ( 'insecure_user' => "Everybody can access your DB as user `\$user' from host `\$host'\n" ."WITHOUT supplying a password.\n" ."Be very careful about it!!" ,'password_required' => "A password is required for user `\$user' :-(" ,'invalid_password' => "The password '\$password' for user `\$user' is invalid :-P" , 'valid_password' => "You supplied the right password for user `\$user' :-)" ,'public_database' => "Any user with the appropriate permissions has access to your DB!\n" ."Check your users!" ,'full_access' => "All grant-tables are empty, which gives full access to ALL users !!" ,'no_rule_found' => "No matching rule" ,'no_equiv_host' => "Not processed: host-field is not empty in db-table." ,'least_priv' => "If the final priveliges of the user are more then you gave the user,\n" ."check the priveliges in the db-table `\$db'." ,'minimum_priv' => "The privileges for any new user are AT LEAST\n" ."the ones shown in the table above,\n" ."since these are the privileges of the db `\$db'.\n" ,'not_found_mysql' => "The MySQL client program <$MySQLaccess::MYSQL> could not be found.\n" ."+ Check your path, or\n" ."+ edit the source of this script to point \$MYSQL to the mysql client.\n" ,'not_found_mysqldump' => "The MySQL dump program <$MySQLaccess::MYSQLDUMP> could not be found.\n" ."+ Check your path, or\n" ."+ edit the source of this script to point \$MYSQLDUMP to the mysqldump program.\n" ,'not_found_diff' => "The diff program <$MySQLaccess::DIFF> could not be found.\n" ."+ Check your path, or\n" ."+ edit the source of this script to point \$DIFF to the diff program.\n" ,'Unrecognized_option' => "Sorry,\n" ."You are using an old version of the mysql-program,\n" ."which does not yet implement a neccessary option.\n" ."\n" ."You need at least Version 6.2 of the mysql-client,\n" ."which was build in MySQL v3.0.18, to use this version\n" ."of `$MySQLaccess::script'." ,'Access_denied' => "Sorry,\n" ."An error occurred when trying to connect to the database\n" ."with the grant-tables:\n" ."* Maybe YOU do not have READ-access to this database?\n" ."* If you used the -U option, you may have supplied an invalid username?\n" ." for the superuser?\n" ."* If you used the -U option, it may be possible you have to supply\n" ." a superuser-password to, with the -P option?\n" ."* If you used the -P option, you may have supplied an invalid password?\n" ,'Dbaccess_denied' => "Sorry,\n" ."An error occurred when trying to connect to the database\n" ."with the grant-tables. (dbaccess denied)\n" ,'Unknown_tmp_table' => "Sorry,\n" ."An error occurred when trying to work with the temporary tables in the database\n" ."with the grant-tables. (One of the temporary tables does not exist)\n" ,'Unknown_table' => "Sorry,\n" ."An error occurred when trying to work with some tables in the database\n" ."with the grant-tables. (table does not exist)\n" ,'use_old_server' => "Sorry,\n" ."An error occurred when executing an SQL statement.\n" ."You might consider altering the use of the parameter `--old_server' when \n" ."calling `$MySQLaccess::script'." ,'unknown_error' => "Sorry,\n" ."An error occurred when trying to connect to the database\n" ."with the grant-tables. (unknown error)\n" ,'anonymous_access' => "Accessing the db as an anonymous user.\n" ."Your username has no relevance\n" ,'user_required' => "You have to supply a userid." ,'db_required' => "You have to supply the name of a database." ,'host_required' => "You have to supply the name of a host." ); } # ===================================== # sub Print_Header: # print header info # ===================================== sub Print_Header { if ($MySQLaccess::CMD) { #command-line mode print "$MySQLaccess::script Version $MySQLaccess::VERSION\n" ."By RUG-AIV, by Yves Carlier (Yves.Carlier\@rug.ac.be)\n" ."Changes by Steve Harvey (sgh\@vex.net)\n" ."This software comes with ABSOLUTELY NO WARRANTY.\n"; } if ($MySQLaccess::CGI) { #CGI-BIN mode print "content-type: text/html\n\n" . "\n" ."\n" ."MySQLaccess\n" ."\n" ."\n" ."

$MySQLaccess::script Version $MySQLaccess::VERSION

\n" ."
\n
\n" ."By RUG-AIV, by Yves Carlier (Yves.Carlier\@rug.ac.be)
\n" ."Changes by Steve Harvey (sgh\@vex.net)
\n" ."This software comes with ABSOLUTELY NO WARRANTY.
\n" ."
\n
\n" ."
\n"; Print_Taskbar(); print "
\n"; } return 1; } # ===================================== # sub Print_Footer: # print footer info # ===================================== sub Print_Footer { if ($MySQLaccess::CMD) { #command-line mode print "\n" ."BUGs can be reported at https://jira.mariadb.org\n"; } if ($MySQLaccess::CGI) { #CGI-BIN mode if ($MySQLaccess::Param{'brief'}) { print "\n"; #close table in brief-output } print "
\n" ."
\n" ."BUGs can be reported at MariaDB JIRA
\n" # ."Don't forget to mention the version $VERSION!
\n" ."
\n" ."\n" ."\n"; } return 1; } # ===================================== # sub Print_Taskbar: # print taskbar on STDOUT # ===================================== sub Print_Taskbar { print "
\n" ."[Release Notes] \n" ."[Version] \n" ."[Future Plans] \n" ."[Examples] \n" ."[New check] \n" ."[Change/edit ACL] \n" ."
\n"; return 1; } # ===================================== # sub Print_Form: # print CGI-form # ===================================== sub Print_Form { print <
MySQL server User information Reports
Host
(Host on which MySQL-server resides.)
Superuser
(User which has read-access to grant-tables.)
Password
(of Superuser.)
User
(Userid used to connect to MySQL-database.)
Password
(Password user has to give to get access to MySQL-database.)
Database
(Name of MySQL-database user tries to connect to.
Wildcards (*,?,%,_) are allowed.)
Host
(Host from where the user is trying to connect to MySQL-database.
Wildcards (*,?,%,_) are allowed.)

EOForm return 1; } # ===================================== # sub Print_Usage: # print some information on STDOUT # ===================================== sub Print_Usage { Print_Error_Messages(); if ($MySQLaccess::CMD) { #command-line mode Print_Options(); } if ($MySQLaccess::CGI) { #CGI-BIN mode Print_Form(); } return 1; } # ====================================== # sub Print_Version: # ====================================== sub Print_Version { if ($MySQLaccess::CMD) { print $MySQLaccess::INFO; } if ($MySQLaccess::CGI) { print "
\n"; 
       print $MySQLaccess::INFO;
       print "
\n"; } return 1; } # ====================================== # sub Print_Relnotes: # ====================================== sub Print_Relnotes { if ($MySQLaccess::CMD) { print $MySQLaccess::RELEASE; } if ($MySQLaccess::CGI) { print "
\n";
       print $MySQLaccess::RELEASE;
       print "
\n"; } return 1; } # ====================================== # sub Print_Plans: # ====================================== sub Print_Plans { if ($MySQLaccess::CMD) { print $MySQLaccess::TODO; } if ($MySQLaccess::CGI) { print "
\n";
       print $MySQLaccess::TODO;
       print "
\n"; } return 1; } # ====================================== # sub Print_HowTo: # ====================================== sub Print_HowTo { if ($MySQLaccess::CMD) { print $MySQLaccess::HOWTO; } if ($MySQLaccess::CGI) { print "
\n"; 
       print $MySQLaccess::HOWTO;
       print "
\n"; } return 1; } # ====================================== # sub Print_Options: # ====================================== sub Print_Options { if ($MySQLaccess::CGI) { print "
\n"; }
    print $MySQLaccess::OPTIONS;
    if ($MySQLaccess::CGI) { print "
\n"; } return 1; } # ====================================== # sub Print_Error_Access: # ====================================== sub Print_Error_Access { my ($error) = @_; print "\n"; if ($MySQLaccess::CGI) { print "\n
\n"; }
    print $MESSAGES{$error};
    if ($MySQLaccess::CGI) { print "
\n
\n"; } print "\n"; return 1; } # ====================================== # sub Print_Error_Messages: # ====================================== sub Print_Error_Messages { # my ($error) = @_; print "\n"; if ($MySQLaccess::CGI) { print "\n
\n"; } foreach $error (@MySQLaccess::Grant::Error) { print $MESSAGES{$error}; print $MySQLaccess::CGI ? "
\n" : "\n"; } if ($MySQLaccess::CGI) { print "
\n
\n"; } print "\n"; return 1; } # ====================================== # sub Print_Message: # ====================================== sub Print_Message { my ($aref) = @_; my @messages = @{$aref}; print "\n"; if ($MySQLaccess::CGI) { print "\n
\n"; } foreach $msg (@messages) { print $msg; print $MySQLaccess::CGI ? "
\n" : "\n"; } if ($MySQLaccess::CGI) { print "
\n
\n"; } print "\n"; return 1; } # ====================================== # sub Print_Edit: # ====================================== sub Print_Edit { print "\n"; if (!$MySQLaccess::CGI) { print "Note: Editing the temporary tables is NOT supported in CMD-line mode!\n"; return 0; } print "
\n" ."
\n" ."\n" ."\n" ." \n" ." \n" ."\n" ."\n" ." \n" ."\n" ."\n" ." \n" ."\n" ."\n" ." \n" ."\n" ."\n" ." \n" ."\n" ."\n" ." \n" ."\n" ."
Copy grant-rules to temporary tables
Edit temporary tables with external application:
" ." $MySQLaccess::MYSQLADMIN
Preview changes made in temporary tables
Make changes permanent
Restore previous grand-rules
You need write,delete and drop-privileges to perform the above actions
\n" ."
\n" ."
\n"; return 1; } # ====================================== # sub Print_Access_rights: # print the access-rights on STDOUT # ====================================== sub Print_Access_rights { my ($host,$user,$db,$refhash) = @_; if (defined($MySQLaccess::Param{'brief'})) { # if ($MySQLaccess::CGI) { print "
\n"; }
       Matrix_Report($host,$user,$db,$refhash);  
#       if ($MySQLaccess::CGI) { print "
\n"; } } else { Tabular_Report($host,$user,$db,$refhash); $MySQLaccess::Report::separator = $MySQLaccess::CGI ? "
" : "-"x80; } return 1; } # ====================================== # sub Print_Diff_ACL: # print the diff. in the grants before and after # ====================================== sub Print_Diff_ACL { my ($aref) = @_; my @diffs = @{$aref}; my %block = ( '<' => 'Before', '>' => 'After', ); my %color = ( '<' => 'Green', '>' => 'Red', ); my $curblock = ''; # ----------------------------- # create column-headers foreach $field (@MySQLaccess::Grant::Privileges) { push(@headers,substr($field,0,4)); } if ($MySQLaccess::CMD) { print "\n"; print "Differences in access-rights BEFORE and AFTER changes in grant-tables\n"; # print "---------------------------------------------------------------------\n"; my $line1=""; my $line2=""; $line1 .= sprintf("| %-30s|",'Host,User,DB'); $line2 .= sprintf("+-%-30s+",'-' x 30); foreach $header (@headers) { $line1 .= sprintf("%-4s|",$header); $line2 .= sprintf("%s+",'----'); } print "$line2\n"; print "$line1\n"; print "$line2\n"; $format = "format STDOUT = \n" . "^<<<<<<<<<<<<<<<<<<<<<<<<<<<<<< " . " @|||" x 10 ."\n" . '$host_user_db,@priv' . "\n" . ".\n"; #print $format; eval $format; } if ($MySQLaccess::CGI) { print "\n"; print "\n"; print ""; print "\n"; print "\n"; $line1 .= sprintf("",'Host, User, DB'); foreach $header (@headers) { $line1 .= sprintf("",$header); } print "$line1\n"; } foreach $line (@diffs) { $type = substr($line,0,1); $line = substr($line,1); ($host,$user,$db,@priv) = split(/,/,$line); if ($MySQLaccess::CMD) { if ($type ne $curblock) { $curblock = $type; print $block{$curblock},":\n"; } #print "$line\n"; write; } if ($MySQLaccess::CGI) { if ($type ne $curblock) { $curblock = $type; print "\n"; } $line1=""; foreach $field (@priv) { $line1 .= sprintf("",$field); } print "$line1\n"; } } print "\n"; if ($MySQLaccess::CMD) { print "---------------------------------------------------------------------\n"; } if ($MySQLaccess::CGI) { print "
"; print "Differences in access-rights BEFORE " ."and '}>AFTER changes to grant-tables\n"; print "
%-20s%-4s
$block{$curblock}
$host, $user, $db%-4s

"; } return 1; } # ====================================== # sub Tabular_Report # Tabular report, # suitable for 1 triple (host,db,user) # ====================================== sub Tabular_Report { my ($host,$user,$db,$a) = @_; my $column=2; # ----------------------------- # separator if ($MySQLaccess::Report::separator) { print "$MySQLaccess::Report::separator\n"; } # ----------------------------- # print table of access-rights my $rows = int(@MySQLaccess::Grant::Privileges/2); #round up my @table=(); $j=0; for $i (0 .. $rows-1) { $table[$j]=$MySQLaccess::Grant::Privileges[$i]; $j = $j+2; } $j=1; for $i ($rows .. $#MySQLaccess::Grant::Privileges) { $table[$j]=$MySQLaccess::Grant::Privileges[$i]; $j = $j+2; } if ($MySQLaccess::CMD) { print "\n"; print "Access-rights\n"; print "for USER '$user', from HOST '$host', to DB '$db'\n"; } if ($MySQLaccess::CGI) { print "\n"; print "\n"; } if ($MySQLaccess::CGI) { print ""; print "\n"; print "\n"; } if ($MySQLaccess::CMD) { print "\t+-----------------+---+\t+-----------------+---+"; } foreach $field (@table) { if ($MySQLaccess::CMD) { if ($column==2) { print "\n\t"; $column=1;} else { print "\t"; $column=2;} printf "| %-15s | %s |",$field,$Answer{$a->{$field}}; } if ($MySQLaccess::CGI) { if ($column==2) { print "\n\n"; $column=1;} else { print ""; $column=2;} printf " \n",$field,$Answer{$a->{$field}}; } } print "\n"; if ($MySQLaccess::CMD) { print "\t+-----------------+---+\t+-----------------+---+\n"; } if ($MySQLaccess::CGI) { print "\n
"; print "Access-rights\n"; print "for USER '$user', from HOST '$host', to DB '$db'\n"; print "
%-15s%s

"; } # --------------- # print notes: foreach $note (@MySQLaccess::Grant::Notes) { my $message = $MESSAGES{$note}; $message =~ s/\$user/$user/g; $message =~ s/\$db/$db/g; $message =~ s/\$host/$host/g; $message =~ s/\$password/$password/g; $PREFIX='NOTE'; if ($MySQLaccess::CMD) { my @lines = split(/\n/,$message); foreach $line (@lines) { print "$PREFIX:\t $line\n"; $PREFIX=' '; } } if ($MySQLaccess::CGI) { print "$PREFIX: $message
\n"; } } # --------------- # print warnings: foreach $warning (@MySQLaccess::Grant::Warnings) { my $message = $MESSAGES{$warning}; $message =~ s/\$user/$user/g; $message =~ s/\$db/$db/g; $message =~ s/\$host/$host/g; $message =~ s/\$password/$password/g; $PREFIX='BEWARE'; if ($MySQLaccess::CMD) { my @lines = split(/\n/,$message); foreach $line (@lines) { print "$PREFIX:\t $line\n"; $PREFIX=' '; } } if ($MySQLaccess::CGI) { print "$PREFIX: $message
\n"; } } # --------------- # print errors: foreach $error (@MySQLaccess::Grant::Errors) { my $message = $MESSAGES{$error}; $message =~ s/\$user/$user/g; $message =~ s/\$db/$db/g; $message =~ s/\$host/$host/g; $message =~ s/\$password/$password/g; $PREFIX='ERROR'; if ($MySQLaccess::CMD) { my @lines = split(/\n/,$message); foreach $line (@lines) { print "$PREFIX:\t $line\n"; $PREFIX=' '; } } if ($MySQLaccess::CGI) { print "$PREFIX: $message
\n"; } } # --------------- # inform if there are no rules ==> full access for everyone. if ($MySQLaccess::Grant::full_access) { print "$MESSAGES{'full_access'}\n"; } # --------------- # print the rules used print "\n"; if ($MySQLaccess::CMD) { print "The following rules are used:\n"; foreach $field (sort(keys(%MySQLaccess::Grant::Rules))) { my $rule = (defined($MESSAGES{$MySQLaccess::Grant::Rules{$field}}) ? $MESSAGES{$MySQLaccess::Grant::Rules{$field}} : $MySQLaccess::Grant::Rules{$field}); $rule =~ s/\t/','/g; printf " %-5s : '%s'\n",$field,$rule; } } if ($MySQLaccess::CGI) { print "
\n"; print "\n"; print "\n"; foreach $field (sort(keys(%MySQLaccess::Grant::Rules))) { my $rule = (defined($MESSAGES{$MySQLaccess::Grant::Rules{$field}}) ? $MESSAGES{$MySQLaccess::Grant::Rules{$field}} : $MySQLaccess::Grant::Rules{$field}); $rule =~ s/\t/','/g; printf "\n",$field,$rule; } print "
The following rules are used:
%-5s'%s'
\n"; } return 1; } # ====================================== # sub Matrix_Report: # single-line output foreach triple, # no notes,warnings,... # ====================================== sub Matrix_Report { my ($host,$user,$db,$a) = @_; my @headers = (); if (! $headers) { # ----------------------------- # create column-headers foreach $field (@MySQLaccess::Grant::Privileges) { push(@headers,substr($field,0,4)); } # ----------------------------- # print column-headers print "\n"; if ($MySQLaccess::CMD) { my $line1=""; my $line2=""; foreach $header (@headers) { $line1 .= sprintf("%-4s ",$header); $line2 .= sprintf("%s ",'----'); } $line1 .= sprintf("| %-20s",'Host,User,DB'); $line2 .= sprintf("+ %-20s",'-' x 20); print "$line1\n"; print "$line2\n"; } if ($MySQLaccess::CGI) { print "\n"; my $line1=""; foreach $header (@headers) { $line1 .= sprintf("",$header); } $line1 .= sprintf("",'Host, User, DB'); print "$line1\n"; } # ---------------------------- # column-headers should only be # printed once. $MySQLaccess::Report::headers=1; } # ------------------------ # print access-information if ($MySQLaccess::CMD) { foreach $field (@MySQLaccess::Grant::Privileges) { printf " %-2s ",$Answer{$a->{$field}}; } printf "| %-20s",join(',',$host,$user,$db); print "\n"; } if ($MySQLaccess::CGI) { print ""; foreach $field (@MySQLaccess::Grant::Privileges) { printf "",$Answer{$a->{$field}}; } printf "",join(', ',$host,$user,$db); print "\n"; } return 1; } # ====================================== # sub Raw_Report: # single-line output foreach triple, # no notes,warnings,... # ====================================== sub Raw_Report { my ($host,$user,$db,$a) = @_; my @headers = (); my $string = ""; # ------------------------ # print access-information $string = "$host,$user,$db,"; foreach $field (@MySQLaccess::Grant::Privileges) { $string .= $Answer{$a->{$field}} . ","; } return $string; } ####################################################################### package MySQLaccess::Wildcards; BEGIN { $DEBUG = 0; $DEBUG = $MySQLaccess::DEBUG unless ($DEBUG); } # ############################################ # SQL, WILDCARDS and REGULAR EXPRESSIONS # ============================================ # translage SQL-expressions to Reg-expressions # ============================================ sub SQL2Reg { my ($expr) = @_; my $expr_o = $expr; $expr =~ s/\./\\./g; $expr =~ s/\\%/\002/g; $expr =~ s/%/.*/g; $expr =~ s/\002/%/g; $expr =~ s/\\_/\002/g; $expr =~ s/_/.+/g; $expr =~ s/\002/_/g; MySQLaccess::Debug::Print(2,"$expr_o --> $expr"); return $expr; } # translage WILDcards to Reg-expressions # ============================================ sub Wild2Reg { my ($expr) = @_; my $expr_o = $expr; $expr =~ s/\./\\./g; $expr =~ s/\\\*/\002/g; $expr =~ s/\*/.*/g; $expr =~ s/\002/*/g; $expr =~ s/\\\?/\002/g; $expr =~ s/\?/.+/g; $expr =~ s/\002/?/g; MySQLaccess::Debug::Print(2,"$expr_o --> $expr"); return $expr; } # ============================================= # match a given string with a template # ============================================= sub MatchTemplate { my ($tpl,$string) = @_; my $match=0; if ($string=~ /^$tpl$/ or $tpl eq '') { $match=1; } else { $match=0;} MySQLaccess::Debug::Print(2,"($tpl,$string) --> $match"); return $match; } ####################################################################### package MySQLaccess::Host; BEGIN { $localhost = undef; $DEBUG = 2; $DEBUG = $MySQLaccess::DEBUG unless ($DEBUG); } # ====================================== # sub IP2Name # return the Name with the corr. IP-nmbr # (no aliases yet!!) # ====================================== sub IP2Name { my ($ip) = @_; my $ip_o = $ip; if ($ip !~ /([0-9]+)\.([0-9]+)\.([0-9]+)\.([0-9]+)/o) { MySQLaccess::Debug::Print(3,"'$ip' is not an ip-number, returning IP=$ip"); return $ip; } MySQLaccess::Debug::Print(4,"IP=$ip split up => $1.$2.$3.$4"); $ip = pack "C4",$1,$2,$3,$4; MySQLaccess::Debug::Print(4,"IP packed -> >>$ip<<\n"); my ($name,$aliases,$addrtype,$length,@addrs) = gethostbyaddr($ip, AF_INET); MySQLaccess::Debug::Print(3,"IP=$ip_o => hostname=$name"); MySQLaccess::Debug::Print(4,"aliases=$aliases"); MySQLaccess::Debug::Print(4,"addrtype=$addrtype - length=$length"); return ($name || $ip); #return ($name || undef); } # ====================================== # sub Name2IP # return the IP-number of the host # ====================================== sub Name2IP { my ($name) = @_; if ($name =~ /[%_]/) { MySQLaccess::Debug::Print(3,"'$name' contains SQL-wildcards, returning name=$name"); return $name; } my ($_name,$aliases,$addrtype,$length,@addrs) = gethostbyname($name); my ($a,$b,$c,$d) = unpack('C4',$addrs[0]); my $ip = "$a.$b.$c.$d"; MySQLaccess::Debug::Print(3,"hostname=$name => IP=$ip"); MySQLaccess::Debug::Print(4,"aliases=$aliases"); MySQLaccess::Debug::Print(4,"addrtype=$addrtype - length=$length"); #if ($ip ne "") { return "$ip"; } #else { return undef; } return ($ip || $name); } # ======================================== # sub LocalHost # some special action has to be taken for # the localhost # ======================================== sub LocalHost { if (!defined($MySQLaccess::Host::localhost)) { $MySQLaccess::Host::localhost = Sys::Hostname::hostname(); MySQLaccess::Debug::Print(3,"Setting package variable \$localhost=$MySQLaccess::Host::localhost"); } my $host = $localhost; MySQLaccess::Debug::Print(3,"localhost = $host"); return $host; } # ======================================== # check if the given hostname (or ip) # corresponds with the localhost # ======================================== sub Is_localhost { my ($host_tpl) = @_; my $isit = 0; if (($MySQLaccess::host_name eq $localhost) or ($MySQLaccess::host_ip eq $local_ip)) { MySQLaccess::Debug::Print(2,"Checking for localhost"); MySQLaccess::Debug::Print(3,"because ($MySQLaccess::host_name EQ $localhost) AND ($MySQLaccess::host_ip EQ $local_ip)"); $isit = ( 'localhost' =~ /$host_tpl/ ) ? 1 : 0; MySQLaccess::Debug::Print(3," 'localhost' =?= $host_tpl -> $isit"); return $isit; } else { MySQLaccess::Debug::Print(4,"Not checking for localhost"); MySQLaccess::Debug::Print(4,"because ($MySQLaccess::host_name != $localhost) AND ($MySQLaccess::host_ip != $local_ip)"); return 0; } } # ========================================= # check if host (IP or name) can be matched # on the template. # ========================================= sub MatchTemplate { my ($host,$tpl) = @_; my $match = 0; MySQLaccess::Debug::Print(1, "($host) =?= ($tpl)"); my $host_name = IP2Name($host); my $host_ip = Name2IP($host); MySQLaccess::Debug::Print(2, "name=$host_name ; ip=$host_ip"); $match = (MySQLaccess::Wildcards::MatchTemplate($tpl,$host_name) or MySQLaccess::Wildcards::MatchTemplate($tpl,$host_ip)); MySQLaccess::Debug::Print(2, "($host_name,$host_ip) =?= ($tpl): $ncount"); return $match; } ######################################################################## package MySQLaccess::Debug; BEGIN { my $dbg_file = "$MySQLaccess::script_log"; open(DEBUG,"> $dbg_file") or warn "Could not open outputfile $dbg_file for debugging-info\n"; select DEBUG; $| = 1; select STDOUT; } # ========================================= # Print debugging information on STDERR # ========================================= sub Print { my ($level,$mesg) = @_; my ($pack,$file,$line,$subname,$hasargs,$wantarray) = caller(1); my ($PACK) = split('::',$subname); my $DEBUG = ${$PACK."::DEBUG"} ? ${$PACK."::DEBUG"} : $MySQLaccess::DEBUG ; my ($sec,$min,$hour) = localtime(); print DEBUG "[$hour:$min:$sec $subname] $mesg\n" if ($DEBUG>=$level); }
%-4s%-20s
%-2s%-20s