xref: /freebsd/contrib/openpam/lib/libpam/openpam_dispatch.c (revision f7e6344d4a3b7072f8b8a1dec8f483a5a3ca50eb)
1*f7e6344dSDag-Erling Smørgrav /*-
2*f7e6344dSDag-Erling Smørgrav  * Copyright (c) 2002-2003 Networks Associates Technology, Inc.
3*f7e6344dSDag-Erling Smørgrav  * Copyright (c) 2004-2011 Dag-Erling Smørgrav
4*f7e6344dSDag-Erling Smørgrav  * All rights reserved.
5*f7e6344dSDag-Erling Smørgrav  *
6*f7e6344dSDag-Erling Smørgrav  * This software was developed for the FreeBSD Project by ThinkSec AS and
7*f7e6344dSDag-Erling Smørgrav  * Network Associates Laboratories, the Security Research Division of
8*f7e6344dSDag-Erling Smørgrav  * Network Associates, Inc.  under DARPA/SPAWAR contract N66001-01-C-8035
9*f7e6344dSDag-Erling Smørgrav  * ("CBOSS"), as part of the DARPA CHATS research program.
10*f7e6344dSDag-Erling Smørgrav  *
11*f7e6344dSDag-Erling Smørgrav  * Redistribution and use in source and binary forms, with or without
12*f7e6344dSDag-Erling Smørgrav  * modification, are permitted provided that the following conditions
13*f7e6344dSDag-Erling Smørgrav  * are met:
14*f7e6344dSDag-Erling Smørgrav  * 1. Redistributions of source code must retain the above copyright
15*f7e6344dSDag-Erling Smørgrav  *    notice, this list of conditions and the following disclaimer.
16*f7e6344dSDag-Erling Smørgrav  * 2. Redistributions in binary form must reproduce the above copyright
17*f7e6344dSDag-Erling Smørgrav  *    notice, this list of conditions and the following disclaimer in the
18*f7e6344dSDag-Erling Smørgrav  *    documentation and/or other materials provided with the distribution.
19*f7e6344dSDag-Erling Smørgrav  * 3. The name of the author may not be used to endorse or promote
20*f7e6344dSDag-Erling Smørgrav  *    products derived from this software without specific prior written
21*f7e6344dSDag-Erling Smørgrav  *    permission.
22*f7e6344dSDag-Erling Smørgrav  *
23*f7e6344dSDag-Erling Smørgrav  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
24*f7e6344dSDag-Erling Smørgrav  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25*f7e6344dSDag-Erling Smørgrav  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26*f7e6344dSDag-Erling Smørgrav  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
27*f7e6344dSDag-Erling Smørgrav  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28*f7e6344dSDag-Erling Smørgrav  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29*f7e6344dSDag-Erling Smørgrav  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30*f7e6344dSDag-Erling Smørgrav  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31*f7e6344dSDag-Erling Smørgrav  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32*f7e6344dSDag-Erling Smørgrav  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33*f7e6344dSDag-Erling Smørgrav  * SUCH DAMAGE.
34*f7e6344dSDag-Erling Smørgrav  *
35*f7e6344dSDag-Erling Smørgrav  * $Id: openpam_dispatch.c 501 2011-12-07 01:28:05Z des $
36*f7e6344dSDag-Erling Smørgrav  */
37*f7e6344dSDag-Erling Smørgrav 
38*f7e6344dSDag-Erling Smørgrav #ifdef HAVE_CONFIG_H
39*f7e6344dSDag-Erling Smørgrav # include "config.h"
40*f7e6344dSDag-Erling Smørgrav #endif
41*f7e6344dSDag-Erling Smørgrav 
42*f7e6344dSDag-Erling Smørgrav #include <sys/param.h>
43*f7e6344dSDag-Erling Smørgrav 
44*f7e6344dSDag-Erling Smørgrav #include <security/pam_appl.h>
45*f7e6344dSDag-Erling Smørgrav 
46*f7e6344dSDag-Erling Smørgrav #include "openpam_impl.h"
47*f7e6344dSDag-Erling Smørgrav 
48*f7e6344dSDag-Erling Smørgrav #if !defined(OPENPAM_RELAX_CHECKS)
49*f7e6344dSDag-Erling Smørgrav static void openpam_check_error_code(int, int);
50*f7e6344dSDag-Erling Smørgrav #else
51*f7e6344dSDag-Erling Smørgrav #define openpam_check_error_code(a, b)
52*f7e6344dSDag-Erling Smørgrav #endif /* !defined(OPENPAM_RELAX_CHECKS) */
53*f7e6344dSDag-Erling Smørgrav 
54*f7e6344dSDag-Erling Smørgrav /*
55*f7e6344dSDag-Erling Smørgrav  * OpenPAM internal
56*f7e6344dSDag-Erling Smørgrav  *
57*f7e6344dSDag-Erling Smørgrav  * Execute a module chain
58*f7e6344dSDag-Erling Smørgrav  */
59*f7e6344dSDag-Erling Smørgrav 
60*f7e6344dSDag-Erling Smørgrav int
61*f7e6344dSDag-Erling Smørgrav openpam_dispatch(pam_handle_t *pamh,
62*f7e6344dSDag-Erling Smørgrav 	int primitive,
63*f7e6344dSDag-Erling Smørgrav 	int flags)
64*f7e6344dSDag-Erling Smørgrav {
65*f7e6344dSDag-Erling Smørgrav 	pam_chain_t *chain;
66*f7e6344dSDag-Erling Smørgrav 	int err, fail, r;
67*f7e6344dSDag-Erling Smørgrav 	int debug;
68*f7e6344dSDag-Erling Smørgrav 
69*f7e6344dSDag-Erling Smørgrav 	ENTER();
70*f7e6344dSDag-Erling Smørgrav 	if (pamh == NULL)
71*f7e6344dSDag-Erling Smørgrav 		RETURNC(PAM_SYSTEM_ERR);
72*f7e6344dSDag-Erling Smørgrav 
73*f7e6344dSDag-Erling Smørgrav 	/* prevent recursion */
74*f7e6344dSDag-Erling Smørgrav 	if (pamh->current != NULL) {
75*f7e6344dSDag-Erling Smørgrav 		openpam_log(PAM_LOG_ERROR,
76*f7e6344dSDag-Erling Smørgrav 		    "%s() called while %s::%s() is in progress",
77*f7e6344dSDag-Erling Smørgrav 		    pam_func_name[primitive],
78*f7e6344dSDag-Erling Smørgrav 		    pamh->current->module->path,
79*f7e6344dSDag-Erling Smørgrav 		    pam_sm_func_name[pamh->primitive]);
80*f7e6344dSDag-Erling Smørgrav 		RETURNC(PAM_ABORT);
81*f7e6344dSDag-Erling Smørgrav 	}
82*f7e6344dSDag-Erling Smørgrav 
83*f7e6344dSDag-Erling Smørgrav 	/* pick a chain */
84*f7e6344dSDag-Erling Smørgrav 	switch (primitive) {
85*f7e6344dSDag-Erling Smørgrav 	case PAM_SM_AUTHENTICATE:
86*f7e6344dSDag-Erling Smørgrav 	case PAM_SM_SETCRED:
87*f7e6344dSDag-Erling Smørgrav 		chain = pamh->chains[PAM_AUTH];
88*f7e6344dSDag-Erling Smørgrav 		break;
89*f7e6344dSDag-Erling Smørgrav 	case PAM_SM_ACCT_MGMT:
90*f7e6344dSDag-Erling Smørgrav 		chain = pamh->chains[PAM_ACCOUNT];
91*f7e6344dSDag-Erling Smørgrav 		break;
92*f7e6344dSDag-Erling Smørgrav 	case PAM_SM_OPEN_SESSION:
93*f7e6344dSDag-Erling Smørgrav 	case PAM_SM_CLOSE_SESSION:
94*f7e6344dSDag-Erling Smørgrav 		chain = pamh->chains[PAM_SESSION];
95*f7e6344dSDag-Erling Smørgrav 		break;
96*f7e6344dSDag-Erling Smørgrav 	case PAM_SM_CHAUTHTOK:
97*f7e6344dSDag-Erling Smørgrav 		chain = pamh->chains[PAM_PASSWORD];
98*f7e6344dSDag-Erling Smørgrav 		break;
99*f7e6344dSDag-Erling Smørgrav 	default:
100*f7e6344dSDag-Erling Smørgrav 		RETURNC(PAM_SYSTEM_ERR);
101*f7e6344dSDag-Erling Smørgrav 	}
102*f7e6344dSDag-Erling Smørgrav 
103*f7e6344dSDag-Erling Smørgrav 	/* execute */
104*f7e6344dSDag-Erling Smørgrav 	for (err = fail = 0; chain != NULL; chain = chain->next) {
105*f7e6344dSDag-Erling Smørgrav 		if (chain->module->func[primitive] == NULL) {
106*f7e6344dSDag-Erling Smørgrav 			openpam_log(PAM_LOG_ERROR, "%s: no %s()",
107*f7e6344dSDag-Erling Smørgrav 			    chain->module->path, pam_sm_func_name[primitive]);
108*f7e6344dSDag-Erling Smørgrav 			r = PAM_SYSTEM_ERR;
109*f7e6344dSDag-Erling Smørgrav 		} else {
110*f7e6344dSDag-Erling Smørgrav 			pamh->primitive = primitive;
111*f7e6344dSDag-Erling Smørgrav 			pamh->current = chain;
112*f7e6344dSDag-Erling Smørgrav 			debug = (openpam_get_option(pamh, "debug") != NULL);
113*f7e6344dSDag-Erling Smørgrav 			if (debug)
114*f7e6344dSDag-Erling Smørgrav 				++openpam_debug;
115*f7e6344dSDag-Erling Smørgrav 			openpam_log(PAM_LOG_DEBUG, "calling %s() in %s",
116*f7e6344dSDag-Erling Smørgrav 			    pam_sm_func_name[primitive], chain->module->path);
117*f7e6344dSDag-Erling Smørgrav 			r = (chain->module->func[primitive])(pamh, flags,
118*f7e6344dSDag-Erling Smørgrav 			    chain->optc, (const char **)chain->optv);
119*f7e6344dSDag-Erling Smørgrav 			pamh->current = NULL;
120*f7e6344dSDag-Erling Smørgrav 			openpam_log(PAM_LOG_DEBUG, "%s: %s(): %s",
121*f7e6344dSDag-Erling Smørgrav 			    chain->module->path, pam_sm_func_name[primitive],
122*f7e6344dSDag-Erling Smørgrav 			    pam_strerror(pamh, r));
123*f7e6344dSDag-Erling Smørgrav 			if (debug)
124*f7e6344dSDag-Erling Smørgrav 				--openpam_debug;
125*f7e6344dSDag-Erling Smørgrav 		}
126*f7e6344dSDag-Erling Smørgrav 
127*f7e6344dSDag-Erling Smørgrav 		if (r == PAM_IGNORE)
128*f7e6344dSDag-Erling Smørgrav 			continue;
129*f7e6344dSDag-Erling Smørgrav 		if (r == PAM_SUCCESS) {
130*f7e6344dSDag-Erling Smørgrav 			/*
131*f7e6344dSDag-Erling Smørgrav 			 * For pam_setcred() and pam_chauthtok() with the
132*f7e6344dSDag-Erling Smørgrav 			 * PAM_PRELIM_CHECK flag, treat "sufficient" as
133*f7e6344dSDag-Erling Smørgrav 			 * "optional".
134*f7e6344dSDag-Erling Smørgrav 			 */
135*f7e6344dSDag-Erling Smørgrav 			if ((chain->flag == PAM_SUFFICIENT ||
136*f7e6344dSDag-Erling Smørgrav 			    chain->flag == PAM_BINDING) && !fail &&
137*f7e6344dSDag-Erling Smørgrav 			    primitive != PAM_SM_SETCRED &&
138*f7e6344dSDag-Erling Smørgrav 			    !(primitive == PAM_SM_CHAUTHTOK &&
139*f7e6344dSDag-Erling Smørgrav 				(flags & PAM_PRELIM_CHECK)))
140*f7e6344dSDag-Erling Smørgrav 				break;
141*f7e6344dSDag-Erling Smørgrav 			continue;
142*f7e6344dSDag-Erling Smørgrav 		}
143*f7e6344dSDag-Erling Smørgrav 
144*f7e6344dSDag-Erling Smørgrav 		openpam_check_error_code(primitive, r);
145*f7e6344dSDag-Erling Smørgrav 
146*f7e6344dSDag-Erling Smørgrav 		/*
147*f7e6344dSDag-Erling Smørgrav 		 * Record the return code from the first module to
148*f7e6344dSDag-Erling Smørgrav 		 * fail.  If a required module fails, record the
149*f7e6344dSDag-Erling Smørgrav 		 * return code from the first required module to fail.
150*f7e6344dSDag-Erling Smørgrav 		 */
151*f7e6344dSDag-Erling Smørgrav 		if (err == 0)
152*f7e6344dSDag-Erling Smørgrav 			err = r;
153*f7e6344dSDag-Erling Smørgrav 		if ((chain->flag == PAM_REQUIRED ||
154*f7e6344dSDag-Erling Smørgrav 		    chain->flag == PAM_BINDING) && !fail) {
155*f7e6344dSDag-Erling Smørgrav 			openpam_log(PAM_LOG_DEBUG, "required module failed");
156*f7e6344dSDag-Erling Smørgrav 			fail = 1;
157*f7e6344dSDag-Erling Smørgrav 			err = r;
158*f7e6344dSDag-Erling Smørgrav 		}
159*f7e6344dSDag-Erling Smørgrav 
160*f7e6344dSDag-Erling Smørgrav 		/*
161*f7e6344dSDag-Erling Smørgrav 		 * If a requisite module fails, terminate the chain
162*f7e6344dSDag-Erling Smørgrav 		 * immediately.
163*f7e6344dSDag-Erling Smørgrav 		 */
164*f7e6344dSDag-Erling Smørgrav 		if (chain->flag == PAM_REQUISITE) {
165*f7e6344dSDag-Erling Smørgrav 			openpam_log(PAM_LOG_DEBUG, "requisite module failed");
166*f7e6344dSDag-Erling Smørgrav 			fail = 1;
167*f7e6344dSDag-Erling Smørgrav 			break;
168*f7e6344dSDag-Erling Smørgrav 		}
169*f7e6344dSDag-Erling Smørgrav 	}
170*f7e6344dSDag-Erling Smørgrav 
171*f7e6344dSDag-Erling Smørgrav 	if (!fail && err != PAM_NEW_AUTHTOK_REQD)
172*f7e6344dSDag-Erling Smørgrav 		err = PAM_SUCCESS;
173*f7e6344dSDag-Erling Smørgrav 	RETURNC(err);
174*f7e6344dSDag-Erling Smørgrav }
175*f7e6344dSDag-Erling Smørgrav 
176*f7e6344dSDag-Erling Smørgrav #if !defined(OPENPAM_RELAX_CHECKS)
177*f7e6344dSDag-Erling Smørgrav static void
178*f7e6344dSDag-Erling Smørgrav openpam_check_error_code(int primitive, int r)
179*f7e6344dSDag-Erling Smørgrav {
180*f7e6344dSDag-Erling Smørgrav 	/* common error codes */
181*f7e6344dSDag-Erling Smørgrav 	if (r == PAM_SUCCESS ||
182*f7e6344dSDag-Erling Smørgrav 	    r == PAM_SERVICE_ERR ||
183*f7e6344dSDag-Erling Smørgrav 	    r == PAM_BUF_ERR ||
184*f7e6344dSDag-Erling Smørgrav 	    r == PAM_CONV_ERR ||
185*f7e6344dSDag-Erling Smørgrav 	    r == PAM_PERM_DENIED ||
186*f7e6344dSDag-Erling Smørgrav 	    r == PAM_ABORT)
187*f7e6344dSDag-Erling Smørgrav 		return;
188*f7e6344dSDag-Erling Smørgrav 
189*f7e6344dSDag-Erling Smørgrav 	/* specific error codes */
190*f7e6344dSDag-Erling Smørgrav 	switch (primitive) {
191*f7e6344dSDag-Erling Smørgrav 	case PAM_SM_AUTHENTICATE:
192*f7e6344dSDag-Erling Smørgrav 		if (r == PAM_AUTH_ERR ||
193*f7e6344dSDag-Erling Smørgrav 		    r == PAM_CRED_INSUFFICIENT ||
194*f7e6344dSDag-Erling Smørgrav 		    r == PAM_AUTHINFO_UNAVAIL ||
195*f7e6344dSDag-Erling Smørgrav 		    r == PAM_USER_UNKNOWN ||
196*f7e6344dSDag-Erling Smørgrav 		    r == PAM_MAXTRIES)
197*f7e6344dSDag-Erling Smørgrav 			return;
198*f7e6344dSDag-Erling Smørgrav 		break;
199*f7e6344dSDag-Erling Smørgrav 	case PAM_SM_SETCRED:
200*f7e6344dSDag-Erling Smørgrav 		if (r == PAM_CRED_UNAVAIL ||
201*f7e6344dSDag-Erling Smørgrav 		    r == PAM_CRED_EXPIRED ||
202*f7e6344dSDag-Erling Smørgrav 		    r == PAM_USER_UNKNOWN ||
203*f7e6344dSDag-Erling Smørgrav 		    r == PAM_CRED_ERR)
204*f7e6344dSDag-Erling Smørgrav 			return;
205*f7e6344dSDag-Erling Smørgrav 		break;
206*f7e6344dSDag-Erling Smørgrav 	case PAM_SM_ACCT_MGMT:
207*f7e6344dSDag-Erling Smørgrav 		if (r == PAM_USER_UNKNOWN ||
208*f7e6344dSDag-Erling Smørgrav 		    r == PAM_AUTH_ERR ||
209*f7e6344dSDag-Erling Smørgrav 		    r == PAM_NEW_AUTHTOK_REQD ||
210*f7e6344dSDag-Erling Smørgrav 		    r == PAM_ACCT_EXPIRED)
211*f7e6344dSDag-Erling Smørgrav 			return;
212*f7e6344dSDag-Erling Smørgrav 		break;
213*f7e6344dSDag-Erling Smørgrav 	case PAM_SM_OPEN_SESSION:
214*f7e6344dSDag-Erling Smørgrav 	case PAM_SM_CLOSE_SESSION:
215*f7e6344dSDag-Erling Smørgrav 		if (r == PAM_SESSION_ERR)
216*f7e6344dSDag-Erling Smørgrav 			return;
217*f7e6344dSDag-Erling Smørgrav 		break;
218*f7e6344dSDag-Erling Smørgrav 	case PAM_SM_CHAUTHTOK:
219*f7e6344dSDag-Erling Smørgrav 		if (r == PAM_PERM_DENIED ||
220*f7e6344dSDag-Erling Smørgrav 		    r == PAM_AUTHTOK_ERR ||
221*f7e6344dSDag-Erling Smørgrav 		    r == PAM_AUTHTOK_RECOVERY_ERR ||
222*f7e6344dSDag-Erling Smørgrav 		    r == PAM_AUTHTOK_LOCK_BUSY ||
223*f7e6344dSDag-Erling Smørgrav 		    r == PAM_AUTHTOK_DISABLE_AGING ||
224*f7e6344dSDag-Erling Smørgrav 		    r == PAM_TRY_AGAIN)
225*f7e6344dSDag-Erling Smørgrav 			return;
226*f7e6344dSDag-Erling Smørgrav 		break;
227*f7e6344dSDag-Erling Smørgrav 	}
228*f7e6344dSDag-Erling Smørgrav 
229*f7e6344dSDag-Erling Smørgrav 	openpam_log(PAM_LOG_ERROR, "%s(): unexpected return value %d",
230*f7e6344dSDag-Erling Smørgrav 	    pam_sm_func_name[primitive], r);
231*f7e6344dSDag-Erling Smørgrav }
232*f7e6344dSDag-Erling Smørgrav #endif /* !defined(OPENPAM_RELAX_CHECKS) */
233*f7e6344dSDag-Erling Smørgrav 
234*f7e6344dSDag-Erling Smørgrav /*
235*f7e6344dSDag-Erling Smørgrav  * NODOC
236*f7e6344dSDag-Erling Smørgrav  *
237*f7e6344dSDag-Erling Smørgrav  * Error codes:
238*f7e6344dSDag-Erling Smørgrav  */
239