openpam_impl.h revision 107937
1/*-
2 * Copyright (c) 2001 Networks Associates Technology, Inc.
3 * All rights reserved.
4 *
5 * This software was developed for the FreeBSD Project by ThinkSec AS and
6 * Network Associates Laboratories, the Security Research Division of
7 * Network Associates, Inc.  under DARPA/SPAWAR contract N66001-01-C-8035
8 * ("CBOSS"), as part of the DARPA CHATS research program.
9 *
10 * Redistribution and use in source and binary forms, with or without
11 * modification, are permitted provided that the following conditions
12 * are met:
13 * 1. Redistributions of source code must retain the above copyright
14 *    notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 *    notice, this list of conditions and the following disclaimer in the
17 *    documentation and/or other materials provided with the distribution.
18 * 3. The name of the author may not be used to endorse or promote
19 *    products derived from this software without specific prior written
20 *    permission.
21 *
22 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
23 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
26 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32 * SUCH DAMAGE.
33 *
34 * $P4: //depot/projects/openpam/lib/openpam_impl.h#17 $
35 */
36
37#ifndef _OPENPAM_IMPL_H_INCLUDED
38#define _OPENPAM_IMPL_H_INCLUDED
39
40#include <security/openpam.h>
41
42extern const char *_pam_func_name[PAM_NUM_PRIMITIVES];
43extern const char *_pam_sm_func_name[PAM_NUM_PRIMITIVES];
44extern const char *_pam_err_name[PAM_NUM_ERRORS];
45
46/*
47 * Control flags
48 */
49#define PAM_REQUIRED		1
50#define PAM_REQUISITE		2
51#define PAM_SUFFICIENT		3
52#define PAM_OPTIONAL		4
53#define PAM_BINDING		5
54#define PAM_NUM_CONTROLFLAGS	6
55
56/*
57 * Chains
58 */
59#define PAM_AUTH		0
60#define PAM_ACCOUNT		1
61#define PAM_SESSION		2
62#define PAM_PASSWORD		3
63#define PAM_NUM_CHAINS		4
64
65typedef struct pam_chain pam_chain_t;
66struct pam_chain {
67	pam_module_t	*module;
68	int		 flag;
69	int		 optc;
70	char	       **optv;
71	pam_chain_t	*next;
72};
73
74typedef struct pam_data pam_data_t;
75struct pam_data {
76	char		*name;
77	void		*data;
78	void		(*cleanup)(pam_handle_t *, void *, int);
79	pam_data_t	*next;
80};
81
82struct pam_handle {
83	char		*service;
84
85	/* chains */
86	pam_chain_t	*chains[PAM_NUM_CHAINS];
87	pam_chain_t	*current;
88	int		 primitive;
89
90	/* items and data */
91	void		*item[PAM_NUM_ITEMS];
92	pam_data_t	*module_data;
93
94	/* environment list */
95	char	       **env;
96	int		 env_count;
97	int		 env_size;
98};
99
100#ifdef NGROUPS_MAX
101#define PAM_SAVED_CRED "pam_saved_cred"
102struct pam_saved_cred {
103	uid_t	 euid;
104	gid_t	 egid;
105	gid_t	 groups[NGROUPS_MAX];
106	int	 ngroups;
107};
108#endif
109
110#define PAM_OTHER	"other"
111
112int		openpam_configure(pam_handle_t *, const char *);
113int		openpam_dispatch(pam_handle_t *, int, int);
114int		openpam_findenv(pam_handle_t *, const char *, size_t);
115int		openpam_add_module(pam_chain_t **, int, int,
116				   const char *, int, const char **);
117void		openpam_clear_chains(pam_chain_t **);
118
119#ifdef OPENPAM_STATIC_MODULES
120pam_module_t   *openpam_static(const char *);
121#endif
122pam_module_t   *openpam_dynamic(const char *);
123
124#ifdef DEBUG
125#define ENTER() openpam_log(PAM_LOG_DEBUG, "entering")
126#define	RETURNV() openpam_log(PAM_LOG_DEBUG, "returning")
127#define RETURNC(c) do { \
128	if ((c) >= 0 && (c) < PAM_NUM_ERRORS)
129		openpam_log(PAM_LOG_DEBUG, "returning %s", _pam_err_name[c]); \
130	else \
131		openpam_log(PAM_LOG_DEBUG, "returning %d!", (c)); \
132	return (c); \
133} while (0)
134#define	RETURNI(n) do { \
135	openpam_log(PAM_LOG_DEBUG, "returning %d", (n)); \
136	return (n); \
137} while (0)
138#define	RETURNP(p) do { \
139	if ((p) == NULL) \
140		openpam_log(PAM_LOG_DEBUG, "returning NULL"); \
141	else \
142		openpam_log(PAM_LOG_DEBUG, "returning %p", (p)); \
143	return (p); \
144} while (0)
145#define	RETURNS(s) do { \
146	if ((s) == NULL) \
147		openpam_log(PAM_LOG_DEBUG, "returning NULL"); \
148	else \
149		openpam_log(PAM_LOG_DEBUG, "returning '%s'", (s)); \
150	return (s); \
151} while (0)
152#else
153#define ENTER()
154#define RETURNV() return
155#define RETURNC(c) return (c)
156#define RETURNI(n) return (i)
157#define RETURNP(p) return (p)
158#define RETURNS(s) return (s)
159#endif
160
161#endif
162