openpam_impl.h revision 114536
1/*- 2 * Copyright (c) 2001 Networks Associates Technology, Inc. 3 * All rights reserved. 4 * 5 * This software was developed for the FreeBSD Project by ThinkSec AS and 6 * Network Associates Laboratories, the Security Research Division of 7 * Network Associates, Inc. under DARPA/SPAWAR contract N66001-01-C-8035 8 * ("CBOSS"), as part of the DARPA CHATS research program. 9 * 10 * Redistribution and use in source and binary forms, with or without 11 * modification, are permitted provided that the following conditions 12 * are met: 13 * 1. Redistributions of source code must retain the above copyright 14 * notice, this list of conditions and the following disclaimer. 15 * 2. Redistributions in binary form must reproduce the above copyright 16 * notice, this list of conditions and the following disclaimer in the 17 * documentation and/or other materials provided with the distribution. 18 * 3. The name of the author may not be used to endorse or promote 19 * products derived from this software without specific prior written 20 * permission. 21 * 22 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND 23 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 24 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 25 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 26 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 27 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 28 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 29 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 31 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 32 * SUCH DAMAGE. 33 * 34 * $P4: //depot/projects/openpam/lib/openpam_impl.h#21 $ 35 */ 36 37#ifndef _OPENPAM_IMPL_H_INCLUDED 38#define _OPENPAM_IMPL_H_INCLUDED 39 40#include <security/openpam.h> 41 42extern const char *_pam_func_name[PAM_NUM_PRIMITIVES]; 43extern const char *_pam_sm_func_name[PAM_NUM_PRIMITIVES]; 44extern const char *_pam_err_name[PAM_NUM_ERRORS]; 45extern const char *_pam_item_name[PAM_NUM_ITEMS]; 46 47extern int _openpam_debug; 48 49/* 50 * Control flags 51 */ 52#define PAM_REQUIRED 1 53#define PAM_REQUISITE 2 54#define PAM_SUFFICIENT 3 55#define PAM_OPTIONAL 4 56#define PAM_BINDING 5 57#define PAM_NUM_CONTROLFLAGS 6 58 59/* 60 * Chains 61 */ 62#define PAM_AUTH 0 63#define PAM_ACCOUNT 1 64#define PAM_SESSION 2 65#define PAM_PASSWORD 3 66#define PAM_NUM_CHAINS 4 67 68typedef struct pam_chain pam_chain_t; 69struct pam_chain { 70 pam_module_t *module; 71 int flag; 72 int optc; 73 char **optv; 74 pam_chain_t *next; 75}; 76 77typedef struct pam_data pam_data_t; 78struct pam_data { 79 char *name; 80 void *data; 81 void (*cleanup)(pam_handle_t *, void *, int); 82 pam_data_t *next; 83}; 84 85struct pam_handle { 86 char *service; 87 88 /* chains */ 89 pam_chain_t *chains[PAM_NUM_CHAINS]; 90 pam_chain_t *current; 91 int primitive; 92 93 /* items and data */ 94 void *item[PAM_NUM_ITEMS]; 95 pam_data_t *module_data; 96 97 /* environment list */ 98 char **env; 99 int env_count; 100 int env_size; 101}; 102 103#ifdef NGROUPS_MAX 104#define PAM_SAVED_CRED "pam_saved_cred" 105struct pam_saved_cred { 106 uid_t euid; 107 gid_t egid; 108 gid_t groups[NGROUPS_MAX]; 109 int ngroups; 110}; 111#endif 112 113#define PAM_OTHER "other" 114 115int openpam_configure(pam_handle_t *, const char *); 116int openpam_dispatch(pam_handle_t *, int, int); 117int openpam_findenv(pam_handle_t *, const char *, size_t); 118int openpam_add_module(pam_chain_t **, int, int, 119 const char *, int, const char **); 120void openpam_clear_chains(pam_chain_t **); 121 122#ifdef OPENPAM_STATIC_MODULES 123pam_module_t *openpam_static(const char *); 124#endif 125pam_module_t *openpam_dynamic(const char *); 126 127#ifdef DEBUG 128#define ENTER() openpam_log(PAM_LOG_DEBUG, "entering") 129#define ENTERI(i) do { \ 130 if ((i) > 0 && (i) < PAM_NUM_ITEMS) \ 131 openpam_log(PAM_LOG_DEBUG, "entering: %s", _pam_item_name[i]); \ 132 else \ 133 openpam_log(PAM_LOG_DEBUG, "entering: %d", (i)); \ 134} while (0); 135#define ENTERN(n) do { \ 136 openpam_log(PAM_LOG_DEBUG, "entering: %d", (n)); \ 137} while (0); 138#define ENTERS(s) do { \ 139 if ((s) == NULL) \ 140 openpam_log(PAM_LOG_DEBUG, "entering: NULL"); \ 141 else \ 142 openpam_log(PAM_LOG_DEBUG, "entering: '%s'", (s)); \ 143} while (0); 144#define RETURNV() openpam_log(PAM_LOG_DEBUG, "returning") 145#define RETURNC(c) do { \ 146 if ((c) >= 0 && (c) < PAM_NUM_ERRORS) \ 147 openpam_log(PAM_LOG_DEBUG, "returning %s", _pam_err_name[c]); \ 148 else \ 149 openpam_log(PAM_LOG_DEBUG, "returning %d!", (c)); \ 150 return (c); \ 151} while (0) 152#define RETURNN(n) do { \ 153 openpam_log(PAM_LOG_DEBUG, "returning %d", (n)); \ 154 return (n); \ 155} while (0) 156#define RETURNP(p) do { \ 157 if ((p) == NULL) \ 158 openpam_log(PAM_LOG_DEBUG, "returning NULL"); \ 159 else \ 160 openpam_log(PAM_LOG_DEBUG, "returning %p", (p)); \ 161 return (p); \ 162} while (0) 163#define RETURNS(s) do { \ 164 if ((s) == NULL) \ 165 openpam_log(PAM_LOG_DEBUG, "returning NULL"); \ 166 else \ 167 openpam_log(PAM_LOG_DEBUG, "returning '%s'", (s)); \ 168 return (s); \ 169} while (0) 170#else 171#define ENTER() 172#define ENTERI(i) 173#define ENTERN(n) 174#define ENTERS(s) 175#define RETURNV() return 176#define RETURNC(c) return (c) 177#define RETURNN(n) return (n) 178#define RETURNP(p) return (p) 179#define RETURNS(s) return (s) 180#endif 181 182#endif 183