Home | History | Annotate | Line # | Download | only in pam_ftpusers
pam_ftpusers.c revision 1.5.42.1
      1  1.5.42.1      yamt /*	$NetBSD: pam_ftpusers.c,v 1.5.42.1 2012/04/17 00:05:30 yamt Exp $	*/
      2       1.2  christos 
      3       1.1  christos /*-
      4       1.1  christos  * Copyright (c) 2001 Networks Associates Technology, Inc.
      5       1.1  christos  * All rights reserved.
      6       1.1  christos  *
      7       1.1  christos  * This software was developed for the FreeBSD Project by ThinkSec AS and
      8       1.1  christos  * NAI Labs, the Security Research Division of Network Associates, Inc.
      9       1.1  christos  * under DARPA/SPAWAR contract N66001-01-C-8035 ("CBOSS"), as part of the
     10       1.1  christos  * DARPA CHATS research program.
     11       1.1  christos  *
     12       1.1  christos  * Redistribution and use in source and binary forms, with or without
     13       1.1  christos  * modification, are permitted provided that the following conditions
     14       1.1  christos  * are met:
     15       1.1  christos  * 1. Redistributions of source code must retain the above copyright
     16       1.1  christos  *    notice, this list of conditions and the following disclaimer.
     17       1.1  christos  * 2. Redistributions in binary form must reproduce the above copyright
     18       1.1  christos  *    notice, this list of conditions and the following disclaimer in the
     19       1.1  christos  *    documentation and/or other materials provided with the distribution.
     20       1.1  christos  * 3. The name of the author may not be used to endorse or promote
     21       1.1  christos  *    products derived from this software without specific prior written
     22       1.1  christos  *    permission.
     23       1.1  christos  *
     24       1.1  christos  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
     25       1.1  christos  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     26       1.1  christos  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     27       1.1  christos  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
     28       1.1  christos  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     29       1.1  christos  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     30       1.1  christos  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     31       1.1  christos  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     32       1.1  christos  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     33       1.1  christos  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     34       1.1  christos  * SUCH DAMAGE.
     35       1.1  christos  */
     36       1.1  christos 
     37       1.1  christos #include <sys/cdefs.h>
     38       1.2  christos #ifdef __FreeBSD__
     39       1.1  christos __FBSDID("$FreeBSD: src/lib/libpam/modules/pam_ftpusers/pam_ftpusers.c,v 1.1 2002/05/08 00:30:10 des Exp $");
     40       1.2  christos #else
     41  1.5.42.1      yamt __RCSID("$NetBSD: pam_ftpusers.c,v 1.5.42.1 2012/04/17 00:05:30 yamt Exp $");
     42       1.2  christos #endif
     43       1.1  christos 
     44       1.1  christos #include <ctype.h>
     45       1.1  christos #include <grp.h>
     46       1.1  christos #include <paths.h>
     47       1.1  christos #include <pwd.h>
     48       1.1  christos #include <stdio.h>
     49  1.5.42.1      yamt #include <errno.h>
     50       1.1  christos #include <stdlib.h>
     51       1.1  christos #include <string.h>
     52       1.1  christos 
     53       1.1  christos #define PAM_SM_ACCOUNT
     54       1.1  christos 
     55       1.1  christos #include <security/pam_appl.h>
     56       1.1  christos #include <security/pam_modules.h>
     57       1.1  christos #include <security/pam_mod_misc.h>
     58       1.1  christos #include <security/openpam.h>
     59       1.1  christos 
     60       1.1  christos PAM_EXTERN int
     61       1.1  christos pam_sm_acct_mgmt(pam_handle_t *pamh, int flags __unused,
     62       1.1  christos     int argc __unused, const char *argv[] __unused)
     63       1.1  christos {
     64       1.3   thorpej 	struct passwd *pwd, pwres;
     65       1.5  christos 	struct group *grp, grres;
     66       1.1  christos 	const char *user;
     67       1.1  christos 	int pam_err, found, allow;
     68       1.1  christos 	char *line, *name, **mem;
     69       1.1  christos 	size_t len, ulen;
     70       1.1  christos 	FILE *f;
     71       1.5  christos 	char pwbuf[1024], grbuf[1024];
     72       1.1  christos 
     73       1.1  christos 	pam_err = pam_get_user(pamh, &user, NULL);
     74       1.1  christos 	if (pam_err != PAM_SUCCESS)
     75       1.1  christos 		return (pam_err);
     76       1.3   thorpej 	if (user == NULL ||
     77       1.4  christos 	    getpwnam_r(user, &pwres, pwbuf, sizeof(pwbuf), &pwd) != 0 ||
     78       1.4  christos 	    pwd == NULL)
     79       1.1  christos 		return (PAM_SERVICE_ERR);
     80       1.1  christos 
     81       1.1  christos 	found = 0;
     82       1.1  christos 	ulen = strlen(user);
     83       1.1  christos 	if ((f = fopen(_PATH_FTPUSERS, "r")) == NULL) {
     84  1.5.42.1      yamt 		PAM_LOG("%s: %s", _PATH_FTPUSERS, strerror(errno));
     85       1.1  christos 		goto done;
     86       1.1  christos 	}
     87       1.1  christos 	while (!found && (line = fgetln(f, &len)) != NULL) {
     88       1.1  christos 		if (*line == '#')
     89       1.1  christos 			continue;
     90       1.2  christos 		while (len > 0 && isspace((unsigned char)line[len - 1]))
     91       1.1  christos 			--len;
     92       1.1  christos 		if (len == 0)
     93       1.1  christos 			continue;
     94       1.1  christos 		/* simple case first */
     95       1.1  christos 		if (*line != '@') {
     96       1.1  christos 			if (len == ulen && strncmp(user, line, len) == 0)
     97       1.1  christos 				found = 1;
     98       1.1  christos 			continue;
     99       1.1  christos 		}
    100       1.1  christos 		/* member of specified group? */
    101       1.1  christos 		asprintf(&name, "%.*s", (int)len - 1, line + 1);
    102       1.1  christos 		if (name == NULL) {
    103       1.1  christos 			fclose(f);
    104       1.1  christos 			return (PAM_BUF_ERR);
    105       1.1  christos 		}
    106       1.5  christos 		(void)getgrnam_r(name, &grres, grbuf, sizeof(grbuf), &grp);
    107       1.1  christos 		free(name);
    108       1.1  christos 		if (grp == NULL)
    109       1.1  christos 			continue;
    110       1.1  christos 		for (mem = grp->gr_mem; mem && *mem && !found; ++mem)
    111       1.1  christos 			if (strcmp(user, *mem) == 0)
    112       1.1  christos 				found = 1;
    113       1.1  christos 	}
    114       1.1  christos  done:
    115       1.1  christos 	allow = (openpam_get_option(pamh, "disallow") == NULL);
    116       1.1  christos 	if (found)
    117       1.1  christos 		pam_err = allow ? PAM_SUCCESS : PAM_AUTH_ERR;
    118       1.1  christos 	else
    119       1.1  christos 		pam_err = allow ? PAM_AUTH_ERR : PAM_SUCCESS;
    120       1.1  christos 	if (f != NULL)
    121       1.1  christos 		fclose(f);
    122       1.1  christos 	return (pam_err);
    123       1.1  christos }
    124       1.1  christos 
    125       1.1  christos PAM_MODULE_ENTRY("pam_ftpusers");
    126