openpam_impl.h revision 114536
1/*-
2 * Copyright (c) 2001 Networks Associates Technology, Inc.
3 * All rights reserved.
4 *
5 * This software was developed for the FreeBSD Project by ThinkSec AS and
6 * Network Associates Laboratories, the Security Research Division of
7 * Network Associates, Inc.  under DARPA/SPAWAR contract N66001-01-C-8035
8 * ("CBOSS"), as part of the DARPA CHATS research program.
9 *
10 * Redistribution and use in source and binary forms, with or without
11 * modification, are permitted provided that the following conditions
12 * are met:
13 * 1. Redistributions of source code must retain the above copyright
14 *    notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 *    notice, this list of conditions and the following disclaimer in the
17 *    documentation and/or other materials provided with the distribution.
18 * 3. The name of the author may not be used to endorse or promote
19 *    products derived from this software without specific prior written
20 *    permission.
21 *
22 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
23 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
24 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
25 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
26 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
27 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
28 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
29 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
30 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
31 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
32 * SUCH DAMAGE.
33 *
34 * $P4: //depot/projects/openpam/lib/openpam_impl.h#21 $
35 */
36
37#ifndef _OPENPAM_IMPL_H_INCLUDED
38#define _OPENPAM_IMPL_H_INCLUDED
39
40#include <security/openpam.h>
41
42extern const char *_pam_func_name[PAM_NUM_PRIMITIVES];
43extern const char *_pam_sm_func_name[PAM_NUM_PRIMITIVES];
44extern const char *_pam_err_name[PAM_NUM_ERRORS];
45extern const char *_pam_item_name[PAM_NUM_ITEMS];
46
47extern int _openpam_debug;
48
49/*
50 * Control flags
51 */
52#define PAM_REQUIRED		1
53#define PAM_REQUISITE		2
54#define PAM_SUFFICIENT		3
55#define PAM_OPTIONAL		4
56#define PAM_BINDING		5
57#define PAM_NUM_CONTROLFLAGS	6
58
59/*
60 * Chains
61 */
62#define PAM_AUTH		0
63#define PAM_ACCOUNT		1
64#define PAM_SESSION		2
65#define PAM_PASSWORD		3
66#define PAM_NUM_CHAINS		4
67
68typedef struct pam_chain pam_chain_t;
69struct pam_chain {
70	pam_module_t	*module;
71	int		 flag;
72	int		 optc;
73	char	       **optv;
74	pam_chain_t	*next;
75};
76
77typedef struct pam_data pam_data_t;
78struct pam_data {
79	char		*name;
80	void		*data;
81	void		(*cleanup)(pam_handle_t *, void *, int);
82	pam_data_t	*next;
83};
84
85struct pam_handle {
86	char		*service;
87
88	/* chains */
89	pam_chain_t	*chains[PAM_NUM_CHAINS];
90	pam_chain_t	*current;
91	int		 primitive;
92
93	/* items and data */
94	void		*item[PAM_NUM_ITEMS];
95	pam_data_t	*module_data;
96
97	/* environment list */
98	char	       **env;
99	int		 env_count;
100	int		 env_size;
101};
102
103#ifdef NGROUPS_MAX
104#define PAM_SAVED_CRED "pam_saved_cred"
105struct pam_saved_cred {
106	uid_t	 euid;
107	gid_t	 egid;
108	gid_t	 groups[NGROUPS_MAX];
109	int	 ngroups;
110};
111#endif
112
113#define PAM_OTHER	"other"
114
115int		openpam_configure(pam_handle_t *, const char *);
116int		openpam_dispatch(pam_handle_t *, int, int);
117int		openpam_findenv(pam_handle_t *, const char *, size_t);
118int		openpam_add_module(pam_chain_t **, int, int,
119				   const char *, int, const char **);
120void		openpam_clear_chains(pam_chain_t **);
121
122#ifdef OPENPAM_STATIC_MODULES
123pam_module_t   *openpam_static(const char *);
124#endif
125pam_module_t   *openpam_dynamic(const char *);
126
127#ifdef DEBUG
128#define ENTER() openpam_log(PAM_LOG_DEBUG, "entering")
129#define ENTERI(i) do { \
130	if ((i) > 0 && (i) < PAM_NUM_ITEMS) \
131		openpam_log(PAM_LOG_DEBUG, "entering: %s", _pam_item_name[i]); \
132	else \
133		openpam_log(PAM_LOG_DEBUG, "entering: %d", (i)); \
134} while (0);
135#define ENTERN(n) do { \
136	openpam_log(PAM_LOG_DEBUG, "entering: %d", (n)); \
137} while (0);
138#define ENTERS(s) do { \
139	if ((s) == NULL) \
140		openpam_log(PAM_LOG_DEBUG, "entering: NULL"); \
141	else \
142		openpam_log(PAM_LOG_DEBUG, "entering: '%s'", (s)); \
143} while (0);
144#define	RETURNV() openpam_log(PAM_LOG_DEBUG, "returning")
145#define RETURNC(c) do { \
146	if ((c) >= 0 && (c) < PAM_NUM_ERRORS) \
147		openpam_log(PAM_LOG_DEBUG, "returning %s", _pam_err_name[c]); \
148	else \
149		openpam_log(PAM_LOG_DEBUG, "returning %d!", (c)); \
150	return (c); \
151} while (0)
152#define	RETURNN(n) do { \
153	openpam_log(PAM_LOG_DEBUG, "returning %d", (n)); \
154	return (n); \
155} while (0)
156#define	RETURNP(p) do { \
157	if ((p) == NULL) \
158		openpam_log(PAM_LOG_DEBUG, "returning NULL"); \
159	else \
160		openpam_log(PAM_LOG_DEBUG, "returning %p", (p)); \
161	return (p); \
162} while (0)
163#define	RETURNS(s) do { \
164	if ((s) == NULL) \
165		openpam_log(PAM_LOG_DEBUG, "returning NULL"); \
166	else \
167		openpam_log(PAM_LOG_DEBUG, "returning '%s'", (s)); \
168	return (s); \
169} while (0)
170#else
171#define ENTER()
172#define ENTERI(i)
173#define ENTERN(n)
174#define ENTERS(s)
175#define RETURNV() return
176#define RETURNC(c) return (c)
177#define RETURNN(n) return (n)
178#define RETURNP(p) return (p)
179#define RETURNS(s) return (s)
180#endif
181
182#endif
183