golden hour
/opt/osquery/share/osquery/lenses
⬆️ Go Up
Upload
File/Folder
Size
Actions
COPYING
25.91 KB
Del
OK
access.aug
3.58 KB
Del
OK
activemq_conf.aug
1.47 KB
Del
OK
activemq_xml.aug
864 B
Del
OK
afs_cellalias.aug
1.56 KB
Del
OK
aliases.aug
2.18 KB
Del
OK
anaconda.aug
775 B
Del
OK
anacron.aug
2.49 KB
Del
OK
approx.aug
1.26 KB
Del
OK
apt_update_manager.aug
1.11 KB
Del
OK
aptcacherngsecurity.aug
726 B
Del
OK
aptconf.aug
3.9 KB
Del
OK
aptpreferences.aug
1.79 KB
Del
OK
aptsources.aug
1.98 KB
Del
OK
authorized_keys.aug
1.84 KB
Del
OK
automaster.aug
3.31 KB
Del
OK
automounter.aug
4.05 KB
Del
OK
avahi.aug
1.38 KB
Del
OK
backuppchosts.aug
1014 B
Del
OK
bbhosts.aug
4.24 KB
Del
OK
bootconf.aug
3.65 KB
Del
OK
build.aug
16.65 KB
Del
OK
cachefilesd.aug
2 KB
Del
OK
carbon.aug
1.54 KB
Del
OK
ceph.aug
719 B
Del
OK
cgconfig.aug
3.37 KB
Del
OK
cgrules.aug
2.38 KB
Del
OK
channels.aug
3.84 KB
Del
OK
chrony.aug
12.87 KB
Del
OK
clamav.aug
1.53 KB
Del
OK
cobblermodules.aug
398 B
Del
OK
cobblersettings.aug
2.24 KB
Del
OK
collectd.aug
869 B
Del
OK
cpanel.aug
824 B
Del
OK
cron.aug
4.05 KB
Del
OK
cron_user.aug
1.26 KB
Del
OK
crypttab.aug
3.01 KB
Del
OK
csv.aug
1.18 KB
Del
OK
cups.aug
459 B
Del
OK
cyrus_imapd.aug
1.51 KB
Del
OK
darkice.aug
773 B
Del
OK
debctrl.aug
3.61 KB
Del
OK
desktop.aug
1.39 KB
Del
OK
devfsrules.aug
619 B
Del
OK
device_map.aug
620 B
Del
OK
dhclient.aug
6.69 KB
Del
OK
dhcpd.aug
20.88 KB
Del
OK
dns_zone.aug
2.89 KB
Del
OK
dnsmasq.aug
2.16 KB
Del
OK
dovecot.aug
3.98 KB
Del
OK
dpkg.aug
2.78 KB
Del
OK
dput.aug
2.16 KB
Del
OK
erlang.aug
4.33 KB
Del
OK
ethers.aug
663 B
Del
OK
exports.aug
2.37 KB
Del
OK
fai_diskconfig.aug
9.28 KB
Del
OK
fonts.aug
819 B
Del
OK
fstab.aug
1.23 KB
Del
OK
fuse.aug
871 B
Del
OK
gdm.aug
1.8 KB
Del
OK
getcap.aug
1.57 KB
Del
OK
group.aug
1.66 KB
Del
OK
grub.aug
11.04 KB
Del
OK
grubenv.aug
508 B
Del
OK
gshadow.aug
2.19 KB
Del
OK
gtkbookmarks.aug
855 B
Del
OK
host_conf.aug
1.9 KB
Del
OK
hostname.aug
435 B
Del
OK
hosts.aug
485 B
Del
OK
hosts_access.aug
4.32 KB
Del
OK
htpasswd.aug
1.02 KB
Del
OK
httpd.aug
7.35 KB
Del
OK
inetd.aug
6.22 KB
Del
OK
inifile.aug
15.49 KB
Del
OK
inittab.aug
780 B
Del
OK
inputrc.aug
1.62 KB
Del
OK
interfaces.aug
4.62 KB
Del
OK
iproute2.aug
323 B
Del
OK
iptables.aug
2.64 KB
Del
OK
iscsid.aug
684 B
Del
OK
jaas.aug
1.57 KB
Del
OK
jettyrealm.aug
1.52 KB
Del
OK
jmxaccess.aug
1.35 KB
Del
OK
jmxpassword.aug
1.34 KB
Del
OK
json.aug
2.15 KB
Del
OK
kdump.aug
2.91 KB
Del
OK
keepalived.aug
10.7 KB
Del
OK
known_hosts.aug
1.93 KB
Del
OK
koji.aug
898 B
Del
OK
krb5.aug
6.16 KB
Del
OK
ldif.aug
7.65 KB
Del
OK
ldso.aug
1.06 KB
Del
OK
lightdm.aug
1.75 KB
Del
OK
limits.aug
2.02 KB
Del
OK
login_defs.aug
615 B
Del
OK
logrotate.aug
4.22 KB
Del
OK
logwatch.aug
1.44 KB
Del
OK
lokkit.aug
2.16 KB
Del
OK
lvm.aug
2.03 KB
Del
OK
mailscanner.aug
1.66 KB
Del
OK
mailscanner_rules.aug
2.84 KB
Del
OK
masterpasswd.aug
4.36 KB
Del
OK
mcollective.aug
1.09 KB
Del
OK
mdadm_conf.aug
10.05 KB
Del
OK
memcached.aug
1.24 KB
Del
OK
mke2fs.aug
4.67 KB
Del
OK
modprobe.aug
3.34 KB
Del
OK
modules.aug
741 B
Del
OK
modules_conf.aug
1.04 KB
Del
OK
mongodbserver.aug
1.17 KB
Del
OK
monit.aug
2.13 KB
Del
OK
multipath.aug
4.21 KB
Del
OK
mysql.aug
1.95 KB
Del
OK
nagioscfg.aug
2.09 KB
Del
OK
nagiosobjects.aug
1.57 KB
Del
OK
netmasks.aug
1.69 KB
Del
OK
networkmanager.aug
2 KB
Del
OK
networks.aug
1.09 KB
Del
OK
nginx.aug
3.65 KB
Del
OK
nrpe.aug
1.75 KB
Del
OK
nslcd.aug
9.87 KB
Del
OK
nsswitch.aug
2.33 KB
Del
OK
ntp.aug
5.29 KB
Del
OK
ntpd.aug
4.75 KB
Del
OK
odbc.aug
1.42 KB
Del
OK
opendkim.aug
3.08 KB
Del
OK
openshift_config.aug
2.46 KB
Del
OK
openshift_http.aug
1.03 KB
Del
OK
openshift_quickstarts.aug
1.02 KB
Del
OK
openvpn.aug
22.28 KB
Del
OK
oz.aug
1.35 KB
Del
OK
pagekite.aug
2.6 KB
Del
OK
pam.aug
2.58 KB
Del
OK
pamconf.aug
1.23 KB
Del
OK
passwd.aug
3.52 KB
Del
OK
pbuilder.aug
638 B
Del
OK
pg_hba.aug
2.97 KB
Del
OK
pgbouncer.aug
1.43 KB
Del
OK
php.aug
2.34 KB
Del
OK
phpvars.aug
3.85 KB
Del
OK
postfix_access.aug
771 B
Del
OK
postfix_main.aug
1.52 KB
Del
OK
postfix_master.aug
1.9 KB
Del
OK
postfix_passwordmap.aug
1.28 KB
Del
OK
postfix_sasl_smtpd.aug
697 B
Del
OK
postfix_transport.aug
1.48 KB
Del
OK
postfix_virtual.aug
1.32 KB
Del
OK
postgresql.aug
2.1 KB
Del
OK
properties.aug
2.3 KB
Del
OK
protocols.aug
1.05 KB
Del
OK
puppet.aug
1.52 KB
Del
OK
puppet_auth.aug
1.95 KB
Del
OK
puppetfile.aug
2.27 KB
Del
OK
puppetfileserver.aug
3.12 KB
Del
OK
pylonspaste.aug
2.3 KB
Del
OK
pythonpaste.aug
1.99 KB
Del
OK
qpid.aug
670 B
Del
OK
quote.aug
6.71 KB
Del
OK
rabbitmq.aug
4.69 KB
Del
OK
radicale.aug
1.48 KB
Del
OK
rancid.aug
927 B
Del
OK
redis.aug
4.96 KB
Del
OK
reprepro_uploaders.aug
5.47 KB
Del
OK
resolv.aug
3.87 KB
Del
OK
rhsm.aug
1.1 KB
Del
OK
rmt.aug
788 B
Del
OK
rsyncd.aug
1.97 KB
Del
OK
rsyslog.aug
3.17 KB
Del
OK
rtadvd.aug
854 B
Del
OK
rx.aug
4.06 KB
Del
OK
samba.aug
1.71 KB
Del
OK
schroot.aug
1.79 KB
Del
OK
securetty.aug
450 B
Del
OK
semanage.aug
859 B
Del
OK
sep.aug
1.28 KB
Del
OK
services.aug
2.82 KB
Del
OK
shadow.aug
2.35 KB
Del
OK
shells.aug
745 B
Del
OK
shellvars.aug
11.97 KB
Del
OK
shellvars_list.aug
1.74 KB
Del
OK
simplelines.aug
1.13 KB
Del
OK
simplevars.aug
1.34 KB
Del
OK
sip_conf.aug
1.61 KB
Del
OK
slapd.aug
5.2 KB
Del
OK
smbusers.aug
781 B
Del
OK
solaris_system.aug
3.15 KB
Del
OK
soma.aug
1.14 KB
Del
OK
spacevars.aug
1.42 KB
Del
OK
splunk.aug
1.64 KB
Del
OK
squid.aug
15.95 KB
Del
OK
ssh.aug
3.91 KB
Del
OK
sshd.aug
4.01 KB
Del
OK
sssd.aug
861 B
Del
OK
star.aug
941 B
Del
OK
strongswan.aug
1.63 KB
Del
OK
stunnel.aug
2.21 KB
Del
OK
subversion.aug
2.75 KB
Del
OK
sudoers.aug
20.03 KB
Del
OK
sysconfig.aug
2.49 KB
Del
OK
sysconfig_route.aug
2.55 KB
Del
OK
sysctl.aug
923 B
Del
OK
syslog.aug
7.33 KB
Del
OK
systemd.aug
5.88 KB
Del
OK
termcap.aug
1.03 KB
Del
OK
thttpd.aug
1.31 KB
Del
OK
tmpfiles.aug
3.03 KB
Del
OK
toml.aug
4.06 KB
Del
OK
trapperkeeper.aug
4.01 KB
Del
OK
tuned.aug
387 B
Del
OK
up2date.aug
2.21 KB
Del
OK
updatedb.aug
1.13 KB
Del
OK
util.aug
4.85 KB
Del
OK
vfstab.aug
1.71 KB
Del
OK
vmware_config.aug
702 B
Del
OK
vsftpd.aug
2.72 KB
Del
OK
webmin.aug
1.23 KB
Del
OK
wine.aug
1.92 KB
Del
OK
xendconfsxp.aug
1.07 KB
Del
OK
xinetd.aug
4.02 KB
Del
OK
xml.aug
6.33 KB
Del
OK
xorg.aug
10.43 KB
Del
OK
xymon.aug
2.26 KB
Del
OK
xymon_alerting.aug
6.11 KB
Del
OK
yaml.aug
1.54 KB
Del
OK
yum.aug
2.19 KB
Del
OK
Edit: sudoers.aug
(* Module: Sudoers Parses /etc/sudoers Author: Raphael Pinson <raphink@gmail.com> About: Reference This lens tries to keep as close as possible to `man sudoers` where possible. For example, recursive definitions such as > Cmnd_Spec_List ::= Cmnd_Spec | > Cmnd_Spec ',' Cmnd_Spec_List are replaced by > let cmnd_spec_list = cmnd_spec . ( sep_com . cmnd_spec )* since Augeas cannot deal with recursive definitions. The definitions from `man sudoers` are put as commentaries for reference throughout the file. More information can be found in the manual. About: License This file is licensed under the LGPL v2+, like the rest of Augeas. About: Lens Usage Sample usage of this lens in augtool * Set first Defaults to apply to the "LOCALNET" network alias > set /files/etc/sudoers/Defaults[1]/type "@LOCALNET" * List all user specifications applying explicitly to the "admin" Unix group > match /files/etc/sudoers/spec/user "%admin" * Remove the full 3rd user specification > rm /files/etc/sudoers/spec[3] About: Configuration files This lens applies to /etc/sudoers. See <filter>. *) module Sudoers = autoload xfm (************************************************************************ * Group: USEFUL PRIMITIVES *************************************************************************) (* Group: Generic primitives *) (* Variable: eol *) let eol = Util.eol (* Variable: indent *) let indent = Util.indent (* Group: Separators *) (* Variable: sep_spc *) let sep_spc = Sep.space (* Variable: sep_cont *) let sep_cont = Sep.cl_or_space (* Variable: sep_cont_opt *) let sep_cont_opt = Sep.cl_or_opt_space (* Variable: sep_cont_opt_build *) let sep_cont_opt_build (sep:string) = del (Rx.cl_or_opt_space . sep . Rx.cl_or_opt_space) (" " . sep . " ") (* Variable: sep_com *) let sep_com = sep_cont_opt_build "," (* Variable: sep_eq *) let sep_eq = sep_cont_opt_build "=" (* Variable: sep_col *) let sep_col = sep_cont_opt_build ":" (* Variable: sep_dquote *) let sep_dquote = Util.del_str "\"" (* Group: Negation expressions *) (************************************************************************ * View: del_negate * Delete an even number of '!' signs *************************************************************************) let del_negate = del /(!!)*/ "" (************************************************************************ * View: negate_node * Negation of boolean values for <defaults>. Accept one optional '!' * and produce a 'negate' node if there is one. *************************************************************************) let negate_node = [ del "!" "!" . label "negate" ] (************************************************************************ * View: negate_or_value * A <del_negate>, followed by either a negated key, or a key/value pair *************************************************************************) let negate_or_value (key:lens) (value:lens) = [ del_negate . (negate_node . key | key . value) ] (* Group: Stores *) (* Variable: sto_to_com_cmnd sto_to_com_cmnd does not begin or end with a space *) let sto_to_com_cmnd = del_negate . negate_node? . ( let alias = Rx.word - /(NO)?(PASSWD|EXEC|SETENV)/ in let non_alias = /[\/a-z]([^,:#()\n\\]|\\\\[=:,\\])*[^,=:#() \t\n\\]|[^,=:#() \t\n\\]/ in store (alias | non_alias)) (* Variable: sto_to_com There could be a \ in the middle of a command *) let sto_to_com = store /([^,=:#() \t\n\\][^,=:#()\n]*[^,=:#() \t\n\\])|[^,=:#() \t\n\\]/ (* Variable: sto_to_com_host *) let sto_to_com_host = store /[^,=:#() \t\n\\]+/ (* Variable: sto_to_com_user Escaped spaces and NIS domains and allowed*) let sto_to_com_user = let nis_re = /([A-Z]([-A-Z0-9]|(\\\\[ \t]))*+\\\\\\\\)/ in let user_re = /[%+@a-z]([-A-Za-z0-9._+]|(\\\\[ \t]))*/ in let alias_re = /[A-Z_]+/ in store ((nis_re? . user_re) | alias_re) (* Variable: to_com_chars *) let to_com_chars = /[^",=#() \t\n\\]+/ (* " relax emacs *) (* Variable: to_com_dquot *) let to_com_dquot = /"[^",=#()\n\\]+"/ (* " relax emacs *) (* Variable: sto_to_com_dquot *) let sto_to_com_dquot = store (to_com_chars|to_com_dquot) (* Variable: sto_to_com_col *) let sto_to_com_col = store to_com_chars (* Variable: sto_to_eq *) let sto_to_eq = store /[^,=:#() \t\n\\]+/ (* Variable: sto_to_spc *) let sto_to_spc = store /[^", \t\n\\]+|"[^", \t\n\\]+"/ (* Variable: sto_to_spc_no_dquote *) let sto_to_spc_no_dquote = store /[^",# \t\n\\]+/ (* " relax emacs *) (* Variable: sto_integer *) let sto_integer = store /[0-9]+/ (* Group: Comments and empty lines *) (* View: comment Map comments in "#comment" nodes *) let comment = let sto_to_eol = store (/([^ \t\n].*[^ \t\n]|[^ \t\n])/ - /include(dir)?.*/) in [ label "#comment" . del /[ \t]*#[ \t]*/ "# " . sto_to_eol . eol ] (* View: comment_eol Requires a space before the # *) let comment_eol = Util.comment_generic /[ \t]+#[ \t]*/ " # " (* View: comment_or_eol A <comment_eol> or <eol> *) let comment_or_eol = comment_eol | (del /([ \t]+#\n|[ \t]*\n)/ "\n") (* View: empty Map empty lines *) let empty = [ del /[ \t]*#?[ \t]*\n/ "\n" ] (* View: includedir *) let includedir = [ key /#include(dir)?/ . Sep.space . store Rx.fspath . eol ] (************************************************************************ * Group: ALIASES *************************************************************************) (************************************************************************ * View: alias_field * Generic alias field to gather all Alias definitions * * Definition: * > User_Alias ::= NAME '=' User_List * > Runas_Alias ::= NAME '=' Runas_List * > Host_Alias ::= NAME '=' Host_List * > Cmnd_Alias ::= NAME '=' Cmnd_List * * Parameters: * kw:string - the label string * sto:lens - the store lens *************************************************************************) let alias_field (kw:string) (sto:lens) = [ label kw . sto ] (* View: alias_list List of <alias_fields>, separated by commas *) let alias_list (kw:string) (sto:lens) = Build.opt_list (alias_field kw sto) sep_com (************************************************************************ * View: alias_name * Name of an <alias_entry_single> * * Definition: * > NAME ::= [A-Z]([A-Z][0-9]_)* *************************************************************************) let alias_name = [ label "name" . store /[A-Z][A-Z0-9_]*/ ] (************************************************************************ * View: alias_entry_single * Single <alias_entry>, named using <alias_name> and listing <alias_list> * * Definition: * > Alias_Type NAME = item1, item2, ... * * Parameters: * field:string - the field name, passed to <alias_list> * sto:lens - the store lens, passed to <alias_list> *************************************************************************) let alias_entry_single (field:string) (sto:lens) = [ label "alias" . alias_name . sep_eq . alias_list field sto ] (************************************************************************ * View: alias_entry * Alias entry, a list of comma-separated <alias_entry_single> fields * * Definition: * > Alias_Type NAME = item1, item2, item3 : NAME = item4, item5 * * Parameters: * kw:string - the alias keyword string * field:string - the field name, passed to <alias_entry_single> * sto:lens - the store lens, passed to <alias_entry_single> *************************************************************************) let alias_entry (kw:string) (field:string) (sto:lens) = [ indent . key kw . sep_cont . alias_entry_single field sto . ( sep_col . alias_entry_single field sto )* . comment_or_eol ] (* TODO: go further in user definitions *) (* View: user_alias User_Alias, see <alias_field> *) let user_alias = alias_entry "User_Alias" "user" sto_to_com (* View: runas_alias Run_Alias, see <alias_field> *) let runas_alias = alias_entry "Runas_Alias" "runas_user" sto_to_com (* View: host_alias Host_Alias, see <alias_field> *) let host_alias = alias_entry "Host_Alias" "host" sto_to_com (* View: cmnd_alias Cmnd_Alias, see <alias_field> *) let cmnd_alias = alias_entry "Cmnd_Alias" "command" sto_to_com_cmnd (************************************************************************ * View: alias * Every kind of Alias entry, * see <user_alias>, <runas_alias>, <host_alias> and <cmnd_alias> * * Definition: * > Alias ::= 'User_Alias' User_Alias (':' User_Alias)* | * > 'Runas_Alias' Runas_Alias (':' Runas_Alias)* | * > 'Host_Alias' Host_Alias (':' Host_Alias)* | * > 'Cmnd_Alias' Cmnd_Alias (':' Cmnd_Alias)* *************************************************************************) let alias = user_alias | runas_alias | host_alias | cmnd_alias (************************************************************************ * Group: DEFAULTS *************************************************************************) (************************************************************************ * View: default_type * Type definition for <defaults> * * Definition: * > Default_Type ::= 'Defaults' | * > 'Defaults' '@' Host_List | * > 'Defaults' ':' User_List | * > 'Defaults' '!' Cmnd_List | * > 'Defaults' '>' Runas_List *************************************************************************) let default_type = let value = store /[@:!>][^ \t\n\\]+/ in [ label "type" . value ] (************************************************************************ * View: parameter_flag * A flag parameter for <defaults> * * Flags are implicitly boolean and can be turned off via the '!' operator. * Some integer, string and list parameters may also be used in a boolean * context to disable them. *************************************************************************) let parameter_flag_kw = "always_set_home" | "authenticate" | "env_editor" | "env_reset" | "fqdn" | "ignore_dot" | "ignore_local_sudoers" | "insults" | "log_host" | "log_year" | "long_otp_prompt" | "mail_always" | "mail_badpass" | "mail_no_host" | "mail_no_perms" | "mail_no_user" | "noexec" | "path_info" | "passprompt_override" | "preserve_groups" | "requiretty" | "root_sudo" | "rootpw" | "runaspw" | "set_home" | "set_logname" | "setenv" | "shell_noargs" | "stay_setuid" | "targetpw" | "tty_tickets" | "visiblepw" | "closefrom_override" | "closefrom_override" | "compress_io" | "fast_glob" | "log_input" | "log_output" | "pwfeedback" | "umask_override" | "use_pty" | "match_group_by_gid" | "always_query_group_plugin" let parameter_flag = [ del_negate . negate_node? . key parameter_flag_kw ] (************************************************************************ * View: parameter_integer * An integer parameter for <defaults> *************************************************************************) let parameter_integer_nobool_kw = "passwd_tries" let parameter_integer_nobool = [ key parameter_integer_nobool_kw . sep_eq . del /"?/ "" . sto_integer . del /"?/ "" ] let parameter_integer_bool_kw = "loglinelen" | "passwd_timeout" | "timestamp_timeout" | "umask" let parameter_integer_bool = negate_or_value (key parameter_integer_bool_kw) (sep_eq . del /"?/ "" . sto_integer . del /"?/ "") let parameter_integer = parameter_integer_nobool | parameter_integer_bool (************************************************************************ * View: parameter_string * A string parameter for <defaults> * * An odd number of '!' operators negate the value of the item; * an even number just cancel each other out. *************************************************************************) let parameter_string_nobool_kw = "badpass_message" | "editor" | "mailsub" | "noexec_file" | "passprompt" | "runas_default" | "syslog_badpri" | "syslog_goodpri" | "timestampdir" | "timestampowner" | "secure_path" let parameter_string_nobool = [ key parameter_string_nobool_kw . sep_eq . sto_to_com_dquot ] let parameter_string_bool_kw = "exempt_group" | "lecture" | "lecture_file" | "listpw" | "logfile" | "mailerflags" | "mailerpath" | "mailto" | "mailfrom" | "syslog" | "verifypw" let parameter_string_bool = negate_or_value (key parameter_string_bool_kw) (sep_eq . sto_to_com_dquot) let parameter_string = parameter_string_nobool | parameter_string_bool (************************************************************************ * View: parameter_lists * A single list parameter for <defaults> * * All lists can be used in a boolean context * The argument may be a double-quoted, space-separated list or a single * value without double-quotes. * The list can be replaced, added to, deleted from, or disabled * by using the =, +=, -=, and ! operators respectively. * An odd number of '!' operators negate the value of the item; * an even number just cancel each other out. *************************************************************************) let parameter_lists_kw = "env_check" | "env_delete" | "env_keep" let parameter_lists_value = [ label "var" . sto_to_spc_no_dquote ] let parameter_lists_value_dquote = [ label "var" . del /"?/ "" . sto_to_spc_no_dquote . del /"?/ "" ] let parameter_lists_values = parameter_lists_value_dquote | ( sep_dquote . parameter_lists_value . ( sep_cont . parameter_lists_value )+ . sep_dquote ) let parameter_lists_sep = sep_cont_opt . ( [ del "+" "+" . label "append" ] | [ del "-" "-" . label "remove" ] )? . del "=" "=" . sep_cont_opt let parameter_lists = negate_or_value (key parameter_lists_kw) (parameter_lists_sep . parameter_lists_values) (************************************************************************ * View: parameter * A single parameter for <defaults> * * Definition: * > Parameter ::= Parameter '=' Value | * > Parameter '+=' Value | * > Parameter '-=' Value | * > '!'* Parameter * * Parameters may be flags, integer values, strings, or lists. * *************************************************************************) let parameter = parameter_flag | parameter_integer | parameter_string | parameter_lists (************************************************************************ * View: parameter_list * A list of comma-separated <parameters> for <defaults> * * Definition: * > Parameter_List ::= Parameter | * > Parameter ',' Parameter_List *************************************************************************) let parameter_list = parameter . ( sep_com . parameter )* (************************************************************************ * View: defaults * A Defaults entry * * Definition: * > Default_Entry ::= Default_Type Parameter_List *************************************************************************) let defaults = [ indent . key "Defaults" . default_type? . sep_cont . parameter_list . comment_or_eol ] (************************************************************************ * Group: USER SPECIFICATION *************************************************************************) (************************************************************************ * View: runas_spec * A runas specification for <spec>, using <alias_list> for listing * users and/or groups used to run a command * * Definition: * > Runas_Spec ::= '(' Runas_List ')' | * > '(:' Runas_List ')' | * > '(' Runas_List ':' Runas_List ')' *************************************************************************) let runas_spec_user = alias_list "runas_user" sto_to_com let runas_spec_group = Util.del_str ":" . indent . alias_list "runas_group" sto_to_com let runas_spec_usergroup = runas_spec_user . indent . runas_spec_group let runas_spec = Util.del_str "(" . (runas_spec_user | runas_spec_group | runas_spec_usergroup ) . Util.del_str ")" . sep_cont_opt (************************************************************************ * View: tag_spec * Tag specification for <spec> * * Definition: * > Tag_Spec ::= ('NOPASSWD:' | 'PASSWD:' | 'NOEXEC:' | 'EXEC:' | * > 'SETENV:' | 'NOSETENV:') *************************************************************************) let tag_spec = [ label "tag" . store /(NO)?(PASSWD|EXEC|SETENV)/ . sep_col ] (************************************************************************ * View: cmnd_spec * Command specification for <spec>, * with optional <runas_spec> and any amount of <tag_specs> * * Definition: * > Cmnd_Spec ::= Runas_Spec? Tag_Spec* Cmnd *************************************************************************) let cmnd_spec = [ label "command" . runas_spec? . tag_spec* . sto_to_com_cmnd ] (************************************************************************ * View: cmnd_spec_list * A list of comma-separated <cmnd_specs> * * Definition: * > Cmnd_Spec_List ::= Cmnd_Spec | * > Cmnd_Spec ',' Cmnd_Spec_List *************************************************************************) let cmnd_spec_list = Build.opt_list cmnd_spec sep_com (************************************************************************ * View: spec_list * Group of hosts with <cmnd_spec_list> *************************************************************************) let spec_list = [ label "host_group" . alias_list "host" sto_to_com_host . sep_eq . cmnd_spec_list ] (************************************************************************ * View: spec * A user specification, listing colon-separated <spec_lists> * * Definition: * > User_Spec ::= User_List Host_List '=' Cmnd_Spec_List \ * > (':' Host_List '=' Cmnd_Spec_List)* *************************************************************************) let spec = [ label "spec" . indent . alias_list "user" sto_to_com_user . sep_cont . Build.opt_list spec_list sep_col . comment_or_eol ] (************************************************************************ * Group: LENS & FILTER *************************************************************************) (* View: lns The sudoers lens, any amount of * <empty> lines * <comments> * <includedirs> * <aliases> * <defaults> * <specs> *) let lns = ( empty | comment | includedir | alias | defaults | spec )* (* View: filter *) let filter = (incl "/etc/sudoers") . (incl "/usr/local/etc/sudoers") . (incl "/etc/sudoers.d/*") . (incl "/usr/local/etc/sudoers.d/*") . (incl "/opt/csw/etc/sudoers") . (incl "/etc/opt/csw/sudoers") . Util.stdexcl let xfm = transform lns filter
Save