aboutsummaryrefslogtreecommitdiffstats
path: root/src/pam.c
blob: 288196e4ee05a84698d7585b4f3e52b54753c2ae (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
/**
 * cerberus – Minimal login program
 * 
 * Copyright © 2013  Mattias Andrée (maandree@member.fsf.org)
 * 
 * This program is free software: you can redistribute it and/or modify
 * it under the terms of the GNU General Public License as published by
 * the Free Software Foundation, either version 3 of the License, or
 * (at your option) any later version.
 * 
 * This program is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
 * GNU General Public License for more details.
 * 
 * You should have received a copy of the GNU General Public License
 * along with this program.  If not, see <http://www.gnu.org/licenses/>.
 */
#include <stdio.h>
#include <unistd.h>
#include <signal.h>
#include <string.h>
#include <security/pam_appl.h>
#include <security/pam_misc.h>

#include "config.h"

#include "pam.h"


#define __failed(RC)  ((RC) != PAM_SUCCESS)


void quit_pam(int sig);

int conv_pam(int num_msg, const struct pam_message** msg, struct pam_response** resp, void* appdata_ptr);


/**
 * Old signal action for SIGHUP
 */
struct sigaction signal_action_hup;

/**
 * Old signal action for SIGTERM
 */
struct sigaction signal_action_term;

/**
 * The process ID of the child process, 0 if none
 */
extern pid_t child_pid;

/**
 * The PAM handle
 */
static pam_handle_t* handle = NULL;

/**
 * The PAM convention
 */
static struct pam_conv conv = { conv_pam, NULL };

/**
 * Whether the user was auto-authenticated
 */
static char auto_authenticated = 1;

/**
 * Function that can be used to read a passphrase from the terminal
 */
static char* (*passphrase_reader)(void) = NULL;


/**
 * Exit if a PAM instruction failed
 * 
 * @param  rc  What the PAM instruction return
 */
static void do_pam(int rc)
{
  if (__failed(rc))
    {
      const char* msg = pam_strerror(handle, rc);
      if (msg)
	fprintf(stderr, "%s\n", msg);
      pam_end(handle, rc);
      sleep(ERROR_SLEEP);
      _exit(1);
    }
}


/**
 * Initialise PAM
 * 
 * @param  remote    The remote computer, {@code NULL} for local login
 * @param  username  The username of the user to log in to
 * @param  reader    Function that can be used to read a passphrase from the terminal
 */
void initialise_pam(char* remote, char* username, char* (*reader)(void))
{
  passphrase_reader = reader;
  
  if (pam_start(remote ? "remote" : "local", username, &conv, &handle) != PAM_SUCCESS)
    {
      fprintf(stderr, "Cannot initialise PAM\n");
      sleep(ERROR_SLEEP);
      _exit(1);
    }
  
  do_pam(pam_set_item(handle, PAM_RHOST, remote ?: "localhost"));
  do_pam(pam_set_item(handle, PAM_TTY, ttyname(STDIN_FILENO) ?: "(none)"));
}


/**
 * Verify that the account may be used
 */
void verify_account_pam(void)
{
  /* FIXME freezes */
  /*
  int rc = pam_acct_mgmt(handle, 0);
  if (rc == PAM_NEW_AUTHTOK_REQD)
    rc = pam_chauthtok(handle, PAM_CHANGE_EXPIRED_AUTHTOK);
  do_pam(rc);
  */
}


/**
 * Open PAM session
 */
void open_session_pam(void)
{
  int rc;
  char** env;
  struct sigaction signal_action;
  
  do_pam(pam_setcred(handle, PAM_ESTABLISH_CRED));
  
  if (__failed(rc = pam_open_session(handle, 0)))
    {
      pam_setcred(handle, PAM_DELETE_CRED);
      do_pam(rc);
    }
  
  if (__failed(rc = pam_setcred(handle, PAM_REINITIALIZE_CRED)))
    {
      pam_close_session(handle, 0);
      do_pam(rc);
    }
  
  memset(&signal_action, 0, sizeof(signal_action));
  signal_action.sa_handler = SIG_IGN;
  sigaction(SIGINT, &signal_action, NULL);
  sigaction(SIGHUP, &signal_action, &signal_action_hup);
  signal_action.sa_handler = quit_pam;
  sigaction(SIGHUP, &signal_action, NULL);
  sigaction(SIGTERM, &signal_action, &signal_action_term);
  
  for (env = pam_getenvlist(handle); env && *env; env++)
    if (putenv(*env))
      {
	pam_setcred(handle, PAM_DELETE_CRED);
	pam_end(handle, pam_close_session(handle, 0));
	sleep(ERROR_SLEEP);
	_exit(1);
      }
}


/**
 * Close PAM session
 */
void close_session_pam(void)
{
  sigaction(SIGHUP, &signal_action_hup, NULL);
  sigaction(SIGTERM, &signal_action_term, NULL);
  
  pam_setcred(handle, PAM_DELETE_CRED);
  pam_end(handle, pam_close_session(handle, 0));
}


/**
 * Signal handler for cleanly exit PAM session
 * 
 * @param  sig  The received signal
 */
void quit_pam(int sig)
{
  if (child_pid)
    kill(-child_pid, sig);
  if (sig == SIGTERM)
    kill(-child_pid, SIGHUP);
  
  pam_setcred(handle, PAM_DELETE_CRED);
  pam_end(handle, pam_close_session(handle, 0));
  
  _exit(sig);
}


/**
 * Perform token authentication
 * 
 * @return  Whether the user got automatically authenticated
 */
char authenticate_pam(void)
{
  int rc;
  
  if (__failed(rc = pam_authenticate(handle, 0)))
    {
      printf("Incorrect passphrase\n");
      pam_end(handle, rc);
      sleep(FAILURE_SLEEP);
      _exit(1);
    }
  
  return auto_authenticated;
}


/**
 * Callback function for converation between PAM this application
 * 
 * @param   num_msg      Number of pointers in the array `msg`
 * @param   msg          Message from PAM
 * @param   resp         Pointer to responses to PAM for by index corresponding messages
 * @param   appdata_ptr  (Not used)
 * @return               `PAM_SUCCESS`, `PAM_CONV_ERR` or `PAM_BUF_ERR`
 */
int conv_pam(int num_msg, const struct pam_message** msg, struct pam_response** resp, void* appdata_ptr)
{
  int i;
  
  (void) appdata_ptr;
  
  *resp = calloc(num_msg, sizeof(struct pam_response));
  
  for (i = 0; i < num_msg; i++)
    {
      ((*resp) + i)->resp = NULL;
      ((*resp) + i)->resp_retcode = 0;
      
      if ((**(msg + i)).msg_style == PAM_PROMPT_ECHO_OFF)
	{
	  (*resp + i)->resp = passphrase_reader();
	  auto_authenticated = 0;
	}
    }
  
  return PAM_SUCCESS;
}