1*0d9d0fd8Schristos /* $NetBSD: openpam_get_feature.c,v 1.4 2023/06/30 21:46:20 christos Exp $ */
2201780c4Schristos
376e8c542Schristos /*-
44cb4af11Schristos * Copyright (c) 2012-2017 Dag-Erling Smørgrav
576e8c542Schristos * All rights reserved.
676e8c542Schristos *
776e8c542Schristos * Redistribution and use in source and binary forms, with or without
876e8c542Schristos * modification, are permitted provided that the following conditions
976e8c542Schristos * are met:
1076e8c542Schristos * 1. Redistributions of source code must retain the above copyright
1176e8c542Schristos * notice, this list of conditions and the following disclaimer.
1276e8c542Schristos * 2. Redistributions in binary form must reproduce the above copyright
1376e8c542Schristos * notice, this list of conditions and the following disclaimer in the
1476e8c542Schristos * documentation and/or other materials provided with the distribution.
1576e8c542Schristos * 3. The name of the author may not be used to endorse or promote
1676e8c542Schristos * products derived from this software without specific prior written
1776e8c542Schristos * permission.
1876e8c542Schristos *
1976e8c542Schristos * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
2076e8c542Schristos * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
2176e8c542Schristos * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
2276e8c542Schristos * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
2376e8c542Schristos * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
2476e8c542Schristos * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
2576e8c542Schristos * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
2676e8c542Schristos * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
2776e8c542Schristos * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
2876e8c542Schristos * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
2976e8c542Schristos * SUCH DAMAGE.
3076e8c542Schristos */
3176e8c542Schristos
3276e8c542Schristos #ifdef HAVE_CONFIG_H
3376e8c542Schristos # include "config.h"
3476e8c542Schristos #endif
3576e8c542Schristos
36201780c4Schristos #include <sys/cdefs.h>
37*0d9d0fd8Schristos __RCSID("$NetBSD: openpam_get_feature.c,v 1.4 2023/06/30 21:46:20 christos Exp $");
38201780c4Schristos
3976e8c542Schristos #include <security/pam_appl.h>
4076e8c542Schristos #include <security/openpam.h>
4176e8c542Schristos
4276e8c542Schristos #include "openpam_impl.h"
4376e8c542Schristos
4476e8c542Schristos /*
4576e8c542Schristos * OpenPAM extension
4676e8c542Schristos *
4776e8c542Schristos * Query the state of an optional feature.
4876e8c542Schristos */
4976e8c542Schristos
5076e8c542Schristos int
openpam_get_feature(int feature,int * onoff)5176e8c542Schristos openpam_get_feature(int feature, int *onoff)
5276e8c542Schristos {
5376e8c542Schristos
5476e8c542Schristos ENTERF(feature);
5576e8c542Schristos if (feature < 0 || feature >= OPENPAM_NUM_FEATURES)
564cb4af11Schristos RETURNC(PAM_BAD_FEATURE);
5776e8c542Schristos *onoff = openpam_features[feature].onoff;
5876e8c542Schristos RETURNC(PAM_SUCCESS);
5976e8c542Schristos }
6076e8c542Schristos
6176e8c542Schristos /*
6276e8c542Schristos * Error codes:
6376e8c542Schristos *
644cb4af11Schristos * PAM_BAD_FEATURE
6576e8c542Schristos */
6676e8c542Schristos
6776e8c542Schristos /**
6876e8c542Schristos * EXPERIMENTAL
6976e8c542Schristos *
7076e8c542Schristos * The =openpam_get_feature function stores the current state of the
7176e8c542Schristos * specified feature in the variable pointed to by its =onoff argument.
7276e8c542Schristos *
7376e8c542Schristos * The following features are recognized:
7476e8c542Schristos *
7576e8c542Schristos * =OPENPAM_RESTRICT_SERVICE_NAME:
7676e8c542Schristos * Disallow path separators in service names.
7776e8c542Schristos * This feature is enabled by default.
7876e8c542Schristos * Disabling it allows the application to specify the path to
7976e8c542Schristos * the desired policy file directly.
8076e8c542Schristos *
8176e8c542Schristos * =OPENPAM_VERIFY_POLICY_FILE:
8276e8c542Schristos * Verify the ownership and permissions of the policy file
8376e8c542Schristos * and the path leading up to it.
8476e8c542Schristos * This feature is enabled by default.
8576e8c542Schristos *
8676e8c542Schristos * =OPENPAM_RESTRICT_MODULE_NAME:
8776e8c542Schristos * Disallow path separators in module names.
8876e8c542Schristos * This feature is disabled by default.
8976e8c542Schristos * Enabling it prevents the use of modules in non-standard
9076e8c542Schristos * locations.
9176e8c542Schristos *
9276e8c542Schristos * =OPENPAM_VERIFY_MODULE_FILE:
9376e8c542Schristos * Verify the ownership and permissions of each loadable
9476e8c542Schristos * module and the path leading up to it.
9576e8c542Schristos * This feature is enabled by default.
9676e8c542Schristos *
9776e8c542Schristos *
9876e8c542Schristos * >openpam_set_feature
9976e8c542Schristos *
10076e8c542Schristos * AUTHOR DES
10176e8c542Schristos */
102