1*10b5fe87SSascha Wildner /*-
2*10b5fe87SSascha Wildner * Copyright (c) 2002-2003 Networks Associates Technology, Inc.
3*10b5fe87SSascha Wildner * Copyright (c) 2004-2011 Dag-Erling Smørgrav
4*10b5fe87SSascha Wildner * All rights reserved.
5*10b5fe87SSascha Wildner *
6*10b5fe87SSascha Wildner * This software was developed for the FreeBSD Project by ThinkSec AS and
7*10b5fe87SSascha Wildner * Network Associates Laboratories, the Security Research Division of
8*10b5fe87SSascha Wildner * Network Associates, Inc. under DARPA/SPAWAR contract N66001-01-C-8035
9*10b5fe87SSascha Wildner * ("CBOSS"), as part of the DARPA CHATS research program.
10*10b5fe87SSascha Wildner *
11*10b5fe87SSascha Wildner * Redistribution and use in source and binary forms, with or without
12*10b5fe87SSascha Wildner * modification, are permitted provided that the following conditions
13*10b5fe87SSascha Wildner * are met:
14*10b5fe87SSascha Wildner * 1. Redistributions of source code must retain the above copyright
15*10b5fe87SSascha Wildner * notice, this list of conditions and the following disclaimer.
16*10b5fe87SSascha Wildner * 2. Redistributions in binary form must reproduce the above copyright
17*10b5fe87SSascha Wildner * notice, this list of conditions and the following disclaimer in the
18*10b5fe87SSascha Wildner * documentation and/or other materials provided with the distribution.
19*10b5fe87SSascha Wildner * 3. The name of the author may not be used to endorse or promote
20*10b5fe87SSascha Wildner * products derived from this software without specific prior written
21*10b5fe87SSascha Wildner * permission.
22*10b5fe87SSascha Wildner *
23*10b5fe87SSascha Wildner * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
24*10b5fe87SSascha Wildner * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25*10b5fe87SSascha Wildner * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26*10b5fe87SSascha Wildner * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
27*10b5fe87SSascha Wildner * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28*10b5fe87SSascha Wildner * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29*10b5fe87SSascha Wildner * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30*10b5fe87SSascha Wildner * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31*10b5fe87SSascha Wildner * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32*10b5fe87SSascha Wildner * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33*10b5fe87SSascha Wildner * SUCH DAMAGE.
34*10b5fe87SSascha Wildner *
35*10b5fe87SSascha Wildner * $OpenPAM: openpam_set_option.c 938 2017-04-30 21:34:42Z des $
36*10b5fe87SSascha Wildner */
37*10b5fe87SSascha Wildner
38*10b5fe87SSascha Wildner #ifdef HAVE_CONFIG_H
39*10b5fe87SSascha Wildner # include "config.h"
40*10b5fe87SSascha Wildner #endif
41*10b5fe87SSascha Wildner
42*10b5fe87SSascha Wildner #include <sys/param.h>
43*10b5fe87SSascha Wildner
44*10b5fe87SSascha Wildner #include <stdio.h>
45*10b5fe87SSascha Wildner #include <stdlib.h>
46*10b5fe87SSascha Wildner #include <string.h>
47*10b5fe87SSascha Wildner
48*10b5fe87SSascha Wildner #include <security/pam_appl.h>
49*10b5fe87SSascha Wildner
50*10b5fe87SSascha Wildner #include "openpam_impl.h"
51*10b5fe87SSascha Wildner #include "openpam_asprintf.h"
52*10b5fe87SSascha Wildner
53*10b5fe87SSascha Wildner /*
54*10b5fe87SSascha Wildner * OpenPAM extension
55*10b5fe87SSascha Wildner *
56*10b5fe87SSascha Wildner * Sets the value of a module option
57*10b5fe87SSascha Wildner */
58*10b5fe87SSascha Wildner
59*10b5fe87SSascha Wildner int
openpam_set_option(pam_handle_t * pamh,const char * option,const char * value)60*10b5fe87SSascha Wildner openpam_set_option(pam_handle_t *pamh,
61*10b5fe87SSascha Wildner const char *option,
62*10b5fe87SSascha Wildner const char *value)
63*10b5fe87SSascha Wildner {
64*10b5fe87SSascha Wildner pam_chain_t *cur;
65*10b5fe87SSascha Wildner char *opt, **optv;
66*10b5fe87SSascha Wildner size_t len;
67*10b5fe87SSascha Wildner int i;
68*10b5fe87SSascha Wildner
69*10b5fe87SSascha Wildner ENTERS(option);
70*10b5fe87SSascha Wildner if (pamh == NULL || pamh->current == NULL || option == NULL)
71*10b5fe87SSascha Wildner RETURNC(PAM_SYSTEM_ERR);
72*10b5fe87SSascha Wildner cur = pamh->current;
73*10b5fe87SSascha Wildner for (len = 0; option[len] != '\0'; ++len)
74*10b5fe87SSascha Wildner if (option[len] == '=')
75*10b5fe87SSascha Wildner break;
76*10b5fe87SSascha Wildner for (i = 0; i < cur->optc; ++i) {
77*10b5fe87SSascha Wildner if (strncmp(cur->optv[i], option, len) == 0 &&
78*10b5fe87SSascha Wildner (cur->optv[i][len] == '\0' || cur->optv[i][len] == '='))
79*10b5fe87SSascha Wildner break;
80*10b5fe87SSascha Wildner }
81*10b5fe87SSascha Wildner if (value == NULL) {
82*10b5fe87SSascha Wildner /* remove */
83*10b5fe87SSascha Wildner if (i == cur->optc)
84*10b5fe87SSascha Wildner RETURNC(PAM_SUCCESS);
85*10b5fe87SSascha Wildner for (free(cur->optv[i]); i < cur->optc; ++i)
86*10b5fe87SSascha Wildner cur->optv[i] = cur->optv[i + 1];
87*10b5fe87SSascha Wildner cur->optv[i] = NULL;
88*10b5fe87SSascha Wildner RETURNC(PAM_SUCCESS);
89*10b5fe87SSascha Wildner }
90*10b5fe87SSascha Wildner if (asprintf(&opt, "%.*s=%s", (int)len, option, value) < 0)
91*10b5fe87SSascha Wildner RETURNC(PAM_BUF_ERR);
92*10b5fe87SSascha Wildner if (i == cur->optc) {
93*10b5fe87SSascha Wildner /* add */
94*10b5fe87SSascha Wildner optv = realloc(cur->optv, sizeof(char *) * (cur->optc + 2));
95*10b5fe87SSascha Wildner if (optv == NULL) {
96*10b5fe87SSascha Wildner FREE(opt);
97*10b5fe87SSascha Wildner RETURNC(PAM_BUF_ERR);
98*10b5fe87SSascha Wildner }
99*10b5fe87SSascha Wildner optv[i] = opt;
100*10b5fe87SSascha Wildner optv[i + 1] = NULL;
101*10b5fe87SSascha Wildner cur->optv = optv;
102*10b5fe87SSascha Wildner ++cur->optc;
103*10b5fe87SSascha Wildner } else {
104*10b5fe87SSascha Wildner /* replace */
105*10b5fe87SSascha Wildner FREE(cur->optv[i]);
106*10b5fe87SSascha Wildner cur->optv[i] = opt;
107*10b5fe87SSascha Wildner }
108*10b5fe87SSascha Wildner RETURNC(PAM_SUCCESS);
109*10b5fe87SSascha Wildner }
110*10b5fe87SSascha Wildner
111*10b5fe87SSascha Wildner /*
112*10b5fe87SSascha Wildner * Error codes:
113*10b5fe87SSascha Wildner *
114*10b5fe87SSascha Wildner * PAM_SYSTEM_ERR
115*10b5fe87SSascha Wildner * PAM_BUF_ERR
116*10b5fe87SSascha Wildner */
117*10b5fe87SSascha Wildner
118*10b5fe87SSascha Wildner /**
119*10b5fe87SSascha Wildner * The =openpam_set_option function sets the specified option in the
120*10b5fe87SSascha Wildner * context of the currently executing service module.
121*10b5fe87SSascha Wildner *
122*10b5fe87SSascha Wildner * >openpam_get_option
123*10b5fe87SSascha Wildner */
124