tst-pam_access4.c 4.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170
  1. /*
  2. * Redistribution and use in source and binary forms, with or without
  3. * modification, are permitted provided that the following conditions
  4. * are met:
  5. * 1. Redistributions of source code must retain the above copyright
  6. * notice, and the entire permission notice in its entirety,
  7. * including the disclaimer of warranties.
  8. * 2. Redistributions in binary form must reproduce the above copyright
  9. * notice, this list of conditions and the following disclaimer in the
  10. * documentation and/or other materials provided with the distribution.
  11. * 3. The name of the author may not be used to endorse or promote
  12. * products derived from this software without specific prior
  13. * written permission.
  14. *
  15. * ALTERNATIVELY, this product may be distributed under the terms of
  16. * the GNU Public License, in which case the provisions of the GPL are
  17. * required INSTEAD OF the above restrictions. (This clause is
  18. * necessary due to a potential bad interaction between the GPL and
  19. * the restrictions contained in a BSD-style copyright.)
  20. *
  21. * THIS SOFTWARE IS PROVIDED ``AS IS'' AND ANY EXPRESS OR IMPLIED
  22. * WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
  23. * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
  24. * DISCLAIMED. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT,
  25. * INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
  26. * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR
  27. * SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
  28. * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
  29. * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  30. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
  31. * OF THE POSSIBILITY OF SUCH DAMAGE.
  32. */
  33. /*
  34. test case:
  35. Check the following lines in access.conf:
  36. -:ALL EXCEPT tstpamaccess3 :LOCAL
  37. -:ALL:127.0.0.1
  38. pam_authenticate should fail for /dev/tty1, pass for www.example.com,
  39. and fail again for localhost
  40. */
  41. #ifdef HAVE_CONFIG_H
  42. #include <config.h>
  43. #endif
  44. #include <stdio.h>
  45. #include <stdlib.h>
  46. #include <string.h>
  47. #include <security/pam_appl.h>
  48. /* A conversation function which uses an internally-stored value for
  49. the responses. */
  50. static int
  51. fake_conv (int num_msg, const struct pam_message **msgm UNUSED,
  52. struct pam_response **response, void *appdata_ptr UNUSED)
  53. {
  54. struct pam_response *reply;
  55. int count;
  56. /* Sanity test. */
  57. if (num_msg <= 0)
  58. return PAM_CONV_ERR;
  59. /* Allocate memory for the responses. */
  60. reply = calloc (num_msg, sizeof (struct pam_response));
  61. if (reply == NULL)
  62. return PAM_CONV_ERR;
  63. /* Each prompt elicits the same response. */
  64. for (count = 0; count < num_msg; ++count)
  65. {
  66. reply[count].resp_retcode = 0;
  67. reply[count].resp = strdup ("!!");
  68. }
  69. /* Set the pointers in the response structure and return. */
  70. *response = reply;
  71. return PAM_SUCCESS;
  72. }
  73. static struct pam_conv conv = {
  74. fake_conv,
  75. NULL
  76. };
  77. int
  78. main(int argc, char *argv[])
  79. {
  80. pam_handle_t *pamh = NULL;
  81. const char *user="tstpamaccess4";
  82. int retval;
  83. int debug = 0;
  84. if (argc > 1 && strcmp (argv[1], "-d") == 0)
  85. debug = 1;
  86. retval = pam_start("tst-pam_access4", user, &conv, &pamh);
  87. if (retval != PAM_SUCCESS)
  88. {
  89. if (debug)
  90. fprintf (stderr, "pam_access4: pam_start returned %d\n", retval);
  91. return 1;
  92. }
  93. retval = pam_set_item (pamh, PAM_TTY, "/dev/tty1");
  94. if (retval != PAM_SUCCESS)
  95. {
  96. if (debug)
  97. fprintf (stderr,
  98. "pam_access4-1: pam_set_item(PAM_TTY) returned %d\n",
  99. retval);
  100. return 1;
  101. }
  102. retval = pam_authenticate (pamh, 0);
  103. if (retval != PAM_PERM_DENIED)
  104. {
  105. if (debug)
  106. fprintf (stderr, "pam_access4-1: pam_authenticate returned %d\n", retval);
  107. return 1;
  108. }
  109. retval = pam_set_item (pamh, PAM_RHOST, "www.example.com");
  110. if (retval != PAM_SUCCESS)
  111. {
  112. if (debug)
  113. fprintf (stderr,
  114. "pam_access4-2: pam_set_item(PAM_RHOST) returned %d\n",
  115. retval);
  116. return 1;
  117. }
  118. retval = pam_authenticate (pamh, 0);
  119. if (retval != PAM_SUCCESS)
  120. {
  121. if (debug)
  122. fprintf (stderr, "pam_access4-2: pam_authenticate returned %d\n", retval);
  123. return 1;
  124. }
  125. retval = pam_set_item (pamh, PAM_RHOST, "localhost");
  126. if (retval != PAM_SUCCESS)
  127. {
  128. if (debug)
  129. fprintf (stderr,
  130. "pam_access4-3: pam_set_item(PAM_RHOST) returned %d\n",
  131. retval);
  132. return 1;
  133. }
  134. retval = pam_authenticate (pamh, 0);
  135. if (retval != PAM_PERM_DENIED)
  136. {
  137. if (debug)
  138. fprintf (stderr, "pam_access4-3: pam_authenticate returned %d\n", retval);
  139. return 1;
  140. }
  141. retval = pam_end (pamh,retval);
  142. if (retval != PAM_SUCCESS)
  143. {
  144. if (debug)
  145. fprintf (stderr, "pam_access4: pam_end returned %d\n", retval);
  146. return 1;
  147. }
  148. return 0;
  149. }