Mercurial > crates > nonstick
annotate src/libpam/handle.rs @ 159:634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
author | Paul Fisher <paul@pfish.zone> |
---|---|
date | Sat, 12 Jul 2025 18:16:18 -0400 |
parents | 0099f2f79f86 |
children | a75a66cb4181 |
rev | line source |
---|---|
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
1 use super::conversation::{OwnedConversation, PamConv}; |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
2 use crate::_doc::{guide, linklist, man7, stdlinks}; |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
3 use crate::constants::{ErrorCode, Result}; |
130
80c07e5ab22f
Transfer over (almost) completely to using libpam-sys.
Paul Fisher <paul@pfish.zone>
parents:
118
diff
changeset
|
4 use crate::conv::Exchange; |
98
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
5 use crate::environ::EnvironMapMut; |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
6 use crate::handle::PamShared; |
146
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
7 use crate::items::{Items, ItemsMut}; |
98
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
8 use crate::libpam::environ::{LibPamEnviron, LibPamEnvironMut}; |
146
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
9 use crate::libpam::items::{LibPamItems, LibPamItemsMut}; |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
10 use crate::libpam::{items, memory}; |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
11 use crate::logging::{Level, Location, Logger}; |
146
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
12 use crate::{Conversation, EnvironMap, Flags, ModuleClient, Transaction}; |
148
4b3a5095f68c
Move libpam-sys helpers into their own library.
Paul Fisher <paul@pfish.zone>
parents:
147
diff
changeset
|
13 use libpam_sys_consts::constants; |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
14 use num_enum::{IntoPrimitive, TryFromPrimitive}; |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
15 use std::any::TypeId; |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
16 use std::cell::Cell; |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
17 use std::ffi::{c_char, c_int, c_void, CString, OsStr, OsString}; |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
18 use std::mem::ManuallyDrop; |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
19 use std::os::unix::ffi::OsStrExt; |
130
80c07e5ab22f
Transfer over (almost) completely to using libpam-sys.
Paul Fisher <paul@pfish.zone>
parents:
118
diff
changeset
|
20 use std::ptr::NonNull; |
157
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
21 use std::{fmt, ptr}; |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
22 |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
23 /// An owned PAM handle. |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
24 pub struct LibPamTransaction<C: Conversation> { |
101 | 25 /// The handle itself. |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
26 handle: ManuallyDrop<LibPamHandle>, |
101 | 27 /// The last return value from the handle. |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
28 last_return: Cell<Result<()>>, |
101 | 29 /// If set, the Conversation that this PAM handle owns. |
102
94eb11cb1798
Improve documentation for pam_start.
Paul Fisher <paul@pfish.zone>
parents:
101
diff
changeset
|
30 /// |
94eb11cb1798
Improve documentation for pam_start.
Paul Fisher <paul@pfish.zone>
parents:
101
diff
changeset
|
31 /// We have to hold on to this because the PAM specification doesn't |
94eb11cb1798
Improve documentation for pam_start.
Paul Fisher <paul@pfish.zone>
parents:
101
diff
changeset
|
32 /// actually say what the PAM library should do with a passed-in |
94eb11cb1798
Improve documentation for pam_start.
Paul Fisher <paul@pfish.zone>
parents:
101
diff
changeset
|
33 /// conversation. Linux-PAM copies the contents of the `pam_conv` struct |
94eb11cb1798
Improve documentation for pam_start.
Paul Fisher <paul@pfish.zone>
parents:
101
diff
changeset
|
34 /// that you pass in to `pam_start`, but OpenPAM uses the pointer itself, |
94eb11cb1798
Improve documentation for pam_start.
Paul Fisher <paul@pfish.zone>
parents:
101
diff
changeset
|
35 /// so you have to keep it in one place. |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
36 conversation: Box<OwnedConversation<C>>, |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
37 } |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
38 |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
39 #[derive(Debug, PartialEq)] |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
40 pub struct TransactionBuilder { |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
41 service_name: OsString, |
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
42 username: Option<OsString>, |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
43 } |
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
44 |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
45 impl TransactionBuilder { |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
46 /// Creates a builder to start a PAM transaction for the given service. |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
47 /// |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
48 /// The service name is what controls the steps and checks PAM goes through |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
49 /// when authenticating a user. This corresponds to the configuration file |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
50 /// usually at <code>/etc/pam.d/<var>service_name</var></code>. |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
51 /// |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
52 /// # References |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
53 #[doc = linklist!(pam_start: adg, _std)] |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
54 /// |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
55 #[doc = stdlinks!(3 pam_start)] |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
56 #[doc = guide!(adg: "adg-interface-by-app-expected.html#adg-pam_start")] |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
57 pub fn new_with_service(service_name: impl AsRef<OsStr>) -> Self { |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
58 Self { |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
59 service_name: service_name.as_ref().into(), |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
60 username: None, |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
61 } |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
62 } |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
63 |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
64 /// Updates the service name. |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
65 pub fn service_name(mut self, service_name: impl AsRef<OsStr>) -> Self { |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
66 self.service_name = service_name.as_ref().into(); |
98
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
67 self |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
68 } |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
69 |
102
94eb11cb1798
Improve documentation for pam_start.
Paul Fisher <paul@pfish.zone>
parents:
101
diff
changeset
|
70 /// Sets the username. Setting this will avoid the need for an extra |
94eb11cb1798
Improve documentation for pam_start.
Paul Fisher <paul@pfish.zone>
parents:
101
diff
changeset
|
71 /// round trip through the conversation and may otherwise improve |
94eb11cb1798
Improve documentation for pam_start.
Paul Fisher <paul@pfish.zone>
parents:
101
diff
changeset
|
72 /// the login experience. |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
73 pub fn username(mut self, username: impl AsRef<OsStr>) -> Self { |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
74 self.username = Some(username.as_ref().into()); |
98
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
75 self |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
76 } |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
77 |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
78 /// Builds the PAM handle and starts the transaction. |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
79 pub fn build(self, conv: impl Conversation) -> Result<LibPamTransaction<impl Conversation>> { |
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
80 LibPamTransaction::start(self.service_name, self.username, conv) |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
81 } |
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
82 } |
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
83 |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
84 impl<C: Conversation> LibPamTransaction<C> { |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
85 fn start(service_name: OsString, username: Option<OsString>, conversation: C) -> Result<Self> { |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
86 let conv = Box::new(OwnedConversation::new(conversation)); |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
87 let service_cstr = CString::new(service_name.as_bytes()).expect("null is forbidden"); |
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
88 let username_cstr = memory::option_cstr_os(username.as_deref()); |
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
89 let username_cstr = memory::prompt_ptr(username_cstr.as_deref()); |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
90 |
130
80c07e5ab22f
Transfer over (almost) completely to using libpam-sys.
Paul Fisher <paul@pfish.zone>
parents:
118
diff
changeset
|
91 let mut handle: *mut libpam_sys::pam_handle = ptr::null_mut(); |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
92 // SAFETY: We've set everything up properly to call `pam_start`. |
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
93 // The returned value will be a valid pointer provided the result is OK. |
101 | 94 let result = unsafe { |
130
80c07e5ab22f
Transfer over (almost) completely to using libpam-sys.
Paul Fisher <paul@pfish.zone>
parents:
118
diff
changeset
|
95 libpam_sys::pam_start( |
101 | 96 service_cstr.as_ptr(), |
97 username_cstr, | |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
98 (conv.as_ref() as *const OwnedConversation<C>) |
130
80c07e5ab22f
Transfer over (almost) completely to using libpam-sys.
Paul Fisher <paul@pfish.zone>
parents:
118
diff
changeset
|
99 .cast_mut() |
80c07e5ab22f
Transfer over (almost) completely to using libpam-sys.
Paul Fisher <paul@pfish.zone>
parents:
118
diff
changeset
|
100 .cast(), |
101 | 101 &mut handle, |
102 ) | |
103 }; | |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
104 ErrorCode::result_from(result)?; |
130
80c07e5ab22f
Transfer over (almost) completely to using libpam-sys.
Paul Fisher <paul@pfish.zone>
parents:
118
diff
changeset
|
105 let handle = NonNull::new(handle).ok_or(ErrorCode::BufferError)?; |
98
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
106 Ok(Self { |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
107 handle: ManuallyDrop::new(LibPamHandle(handle)), |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
108 last_return: Cell::new(Ok(())), |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
109 conversation: conv, |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
110 }) |
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
111 } |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
112 |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
113 #[cfg_attr( |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
114 pam_impl = "LinuxPam", |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
115 doc = "Ends the PAM transaction \"quietly\" (on Linux-PAM only)." |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
116 )] |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
117 #[cfg_attr( |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
118 not(pam_impl = "LinuxPam"), |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
119 doc = "Exactly equivalent to `drop(self)` (except on Linux-PAM)." |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
120 )] |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
121 /// |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
122 /// On Linux-PAM, this is equivalent to passing the `PAM_DATA_SILENT` flag |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
123 /// to [`pam_end` on Linux-PAM][man7], which signals that data cleanup |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
124 /// should "not treat the call too seriously" \[sic]. |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
125 /// |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
126 /// On other platforms, this is no different than letting the transaction |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
127 /// end on its own. |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
128 /// |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
129 #[doc = man7!(3 pam_end)] |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
130 pub fn end_silent(self) { |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
131 #[cfg(pam_impl = "LinuxPam")] |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
132 { |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
133 let mut me = ManuallyDrop::new(self); |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
134 me.end_internal(libpam_sys::PAM_DATA_SILENT); |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
135 } |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
136 // If it's not LinuxPam, we just drop normally. |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
137 } |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
138 |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
139 /// Internal "end" function, which binary-ORs the status with `or_with`. |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
140 fn end_internal(&mut self, or_with: i32) { |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
141 let result = ErrorCode::result_to_c(self.last_return.get()) | or_with; |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
142 unsafe { libpam_sys::pam_end(self.handle.raw_mut(), result) }; |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
143 } |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
144 } |
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
145 |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
146 macro_rules! wrap { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
147 (fn $name:ident { $pam_func:ident }) => { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
148 fn $name(&mut self, flags: Flags) -> Result<()> { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
149 ErrorCode::result_from(unsafe { libpam_sys::$pam_func(self.0.as_mut(), flags.bits()) }) |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
150 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
151 }; |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
152 } |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
153 |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
154 impl Transaction for LibPamHandle { |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
155 wrap!(fn authenticate { pam_authenticate }); |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
156 wrap!(fn account_management { pam_acct_mgmt }); |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
157 wrap!(fn change_authtok { pam_chauthtok }); |
97
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
158 } |
efe2f5f8b5b2
Implement "stateless" application-side PAM calls.
Paul Fisher <paul@pfish.zone>
parents:
96
diff
changeset
|
159 |
147
4d7333337569
Implement Transaction for LibPamTransaction.
Paul Fisher <paul@pfish.zone>
parents:
146
diff
changeset
|
160 // TODO: pam_setcred - app |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
161 // pam_open_session - app |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
162 // pam_close_session - app |
147
4d7333337569
Implement Transaction for LibPamTransaction.
Paul Fisher <paul@pfish.zone>
parents:
146
diff
changeset
|
163 // pam_set/get_data - module |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
164 |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
165 impl<C: Conversation> Drop for LibPamTransaction<C> { |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
166 /// Closes the PAM session on an owned PAM handle. |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
167 /// |
103
dfcd96a74ac4
write a truly prodigious amount of documentation
Paul Fisher <paul@pfish.zone>
parents:
102
diff
changeset
|
168 /// This internally calls `pam_end` with the appropriate error code. |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
169 /// |
103
dfcd96a74ac4
write a truly prodigious amount of documentation
Paul Fisher <paul@pfish.zone>
parents:
102
diff
changeset
|
170 /// # References |
116
a12706e42c9d
Logging, macros, and building:
Paul Fisher <paul@pfish.zone>
parents:
105
diff
changeset
|
171 #[doc = linklist!(pam_end: adg, _std)] |
103
dfcd96a74ac4
write a truly prodigious amount of documentation
Paul Fisher <paul@pfish.zone>
parents:
102
diff
changeset
|
172 /// |
116
a12706e42c9d
Logging, macros, and building:
Paul Fisher <paul@pfish.zone>
parents:
105
diff
changeset
|
173 #[doc = guide!(adg: "adg-interface-by-app-expected.html#adg-pam_end")] |
a12706e42c9d
Logging, macros, and building:
Paul Fisher <paul@pfish.zone>
parents:
105
diff
changeset
|
174 #[doc = stdlinks!(3 pam_end)] |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
175 fn drop(&mut self) { |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
176 self.end_internal(0) |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
177 } |
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
178 } |
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
179 |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
180 macro_rules! delegate { |
98
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
181 // First have the kind that save the result after delegation. |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
182 (fn $meth:ident(&self $(, $param:ident: $typ:ty)*) -> Result<$ret:ty>) => { |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
183 fn $meth(&self $(, $param: $typ)*) -> Result<$ret> { |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
184 let result = self.handle.$meth($($param),*); |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
185 self.last_return.set(split(&result)); |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
186 result |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
187 } |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
188 }; |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
189 (fn $meth:ident(&mut self $(, $param:ident: $typ:ty)*) -> Result<$ret:ty>) => { |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
190 fn $meth(&mut self $(, $param: $typ)*) -> Result<$ret> { |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
191 let result = self.handle.$meth($($param),*); |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
192 self.last_return.set(split(&result)); |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
193 result |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
194 } |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
195 }; |
98
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
196 // Then have the kind that are just raw delegates |
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
197 (fn $meth:ident(&self $(, $param:ident: $typ:ty)*) -> $ret:ty) => { |
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
198 fn $meth(&self $(, $param: $typ)*) -> $ret { |
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
199 self.handle.$meth($($param),*) |
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
200 } |
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
201 }; |
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
202 (fn $meth:ident(&mut self $(, $param:ident: $typ:ty)*) -> $ret:ty) => { |
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
203 fn $meth(&mut self $(, $param: $typ)*) -> $ret { |
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
204 self.handle.$meth($($param),*) |
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
205 } |
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
206 }; |
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
207 // Then have item getters / setters |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
208 (get = $get:ident$(, set = $set:ident)?) => { |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
209 delegate!(fn $get(&self) -> Result<Option<OsString>>); |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
210 $(delegate!(set = $set);)? |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
211 }; |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
212 (set = $set:ident) => { |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
213 delegate!(fn $set(&mut self, value: Option<&OsStr>) -> Result<()>); |
80
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
214 }; |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
215 } |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
216 |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
217 fn split<T>(result: &Result<T>) -> Result<()> { |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
218 result.as_ref().map(drop).map_err(|&e| e) |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
219 } |
5aa1a010f1e8
Start using PAM headers; improve owned/borrowed distinction.
Paul Fisher <paul@pfish.zone>
parents:
78
diff
changeset
|
220 |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
221 impl<C: Conversation> Logger for LibPamTransaction<C> { |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
222 delegate!(fn log(&self, level: Level, location: Location<'_>, entry: fmt::Arguments) -> ()); |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
223 } |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
224 |
147
4d7333337569
Implement Transaction for LibPamTransaction.
Paul Fisher <paul@pfish.zone>
parents:
146
diff
changeset
|
225 impl<C: Conversation> Transaction for LibPamTransaction<C> { |
4d7333337569
Implement Transaction for LibPamTransaction.
Paul Fisher <paul@pfish.zone>
parents:
146
diff
changeset
|
226 delegate!(fn authenticate(&mut self, flags: Flags) -> Result<()>); |
4d7333337569
Implement Transaction for LibPamTransaction.
Paul Fisher <paul@pfish.zone>
parents:
146
diff
changeset
|
227 delegate!(fn account_management(&mut self, flags: Flags) -> Result<()>); |
4d7333337569
Implement Transaction for LibPamTransaction.
Paul Fisher <paul@pfish.zone>
parents:
146
diff
changeset
|
228 delegate!(fn change_authtok(&mut self, flags: Flags) -> Result<()>); |
4d7333337569
Implement Transaction for LibPamTransaction.
Paul Fisher <paul@pfish.zone>
parents:
146
diff
changeset
|
229 } |
4d7333337569
Implement Transaction for LibPamTransaction.
Paul Fisher <paul@pfish.zone>
parents:
146
diff
changeset
|
230 |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
231 impl<C: Conversation> PamShared for LibPamTransaction<C> { |
98
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
232 delegate!(fn environ(&self) -> impl EnvironMap); |
b87100c5eed4
Start on environment variables, and make pointers nicer.
Paul Fisher <paul@pfish.zone>
parents:
97
diff
changeset
|
233 delegate!(fn environ_mut(&mut self) -> impl EnvironMapMut); |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
234 delegate!(fn username(&mut self, prompt: Option<&OsStr>) -> Result<OsString>); |
146
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
235 delegate!(fn items(&self) -> impl Items); |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
236 delegate!(fn items_mut(&mut self) -> impl ItemsMut); |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
237 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
238 |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
239 /// An owned variation of a basic PAM handle. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
240 /// |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
241 /// This is the most basic version of a wrapped PAM handle. It's mostly used |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
242 /// as the inside of the [`LibPamTransaction`], but can also be used to "adopt" |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
243 /// a PAM handle created by another library. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
244 /// |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
245 /// If [`Self::end`] is not called, this will always call `pam_end` reporting |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
246 /// successful completion. |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
247 #[repr(transparent)] |
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
248 pub struct LibPamHandle(NonNull<libpam_sys::pam_handle>); |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
249 |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
250 impl LibPamHandle { |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
251 /// Takes ownership of the pointer to the given PAM handle. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
252 /// |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
253 /// **Do not use this just to get a reference to a PAM handle.** |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
254 /// |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
255 /// # Safety |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
256 /// |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
257 /// - The pointer must point to a valid PAM handle. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
258 /// - The conversation associated with the handle must remain valid |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
259 /// for as long as the handle is open. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
260 pub unsafe fn from_ptr(handle: NonNull<libpam_sys::pam_handle>) -> Self { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
261 Self(handle) |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
262 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
263 |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
264 /// Ends the transaction, reporting `error_code` to cleanup callbacks. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
265 /// |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
266 /// # References |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
267 #[doc = linklist!(pam_end: adg, _std)] |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
268 /// |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
269 #[doc = guide!(adg: "adg-interface-by-app-expected.html#adg-pam_end")] |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
270 #[doc = stdlinks!(3 pam_end)] |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
271 pub fn end(self, result: Result<()>) { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
272 let mut me = ManuallyDrop::new(self); |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
273 unsafe { libpam_sys::pam_end(me.raw_mut(), ErrorCode::result_to_c(result)) }; |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
274 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
275 |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
276 #[cfg_attr( |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
277 not(pam_impl = "LinuxPam"), |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
278 doc = "Exactly equivalent to [`Self::end`], except on Linux-PAM." |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
279 )] |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
280 #[cfg_attr( |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
281 pam_impl = "LinuxPam", |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
282 doc = "Ends the transaction \"quietly\", reporting `error_code` to cleanup callbacks." |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
283 )] |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
284 /// |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
285 /// On Linux-PAM only, this sets the |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
286 /// [`PAM_DATA_SILENT`](libpam_sys::PAM_DATA_SILENT) flag on the flags |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
287 /// passed to the cleanup callbacks. This conventionally means that this |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
288 /// `pam_end` call is occurring on a forked process, and that a session |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
289 /// may still be open on the parent process, and modules "should not treat |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
290 /// the call too seriously". |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
291 /// |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
292 /// # References |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
293 #[doc = linklist!(pam_end: adg, _std)] |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
294 /// |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
295 #[doc = guide!(adg: "adg-interface-by-app-expected.html#adg-pam_end")] |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
296 #[doc = stdlinks!(3 pam_end)] |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
297 pub fn end_silent(self, result: Result<()>) { |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
298 let mut me = ManuallyDrop::new(self); |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
299 let result = ErrorCode::result_to_c(result); |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
300 #[cfg(pam_impl = "LinuxPam")] |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
301 let result = result | libpam_sys::PAM_DATA_SILENT; |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
302 unsafe { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
303 libpam_sys::pam_end(me.raw_mut(), result); |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
304 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
305 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
306 |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
307 /// Consumes this and gives you back the raw PAM handle. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
308 pub fn into_inner(self) -> NonNull<libpam_sys::pam_handle> { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
309 let me = ManuallyDrop::new(self); |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
310 me.0 |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
311 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
312 |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
313 /// Gets a reference to the inner PAM handle. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
314 pub fn raw_ref(&self) -> &libpam_sys::pam_handle { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
315 unsafe { self.0.as_ref() } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
316 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
317 /// Gets a mutable reference to the inner PAM handle. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
318 pub fn raw_mut(&mut self) -> &mut libpam_sys::pam_handle { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
319 unsafe { self.0.as_mut() } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
320 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
321 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
322 |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
323 impl Drop for LibPamHandle { |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
324 fn drop(&mut self) { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
325 unsafe { libpam_sys::pam_end(self.0.as_mut(), 0) }; |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
326 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
327 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
328 |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
329 impl Logger for LibPamHandle { |
157
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
330 fn log(&self, level: Level, loc: Location<'_>, entry: fmt::Arguments) { |
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
331 let entry = match CString::new(entry.to_string()).ok() { |
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
332 Some(e) => e, |
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
333 None => return, |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
334 }; |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
335 #[cfg(any(pam_impl = "LinuxPam", pam_impl = "Sun"))] |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
336 { |
155
ab8020566cd9
Only use real PAM constants for logging within `nonstick/libpam`.
Paul Fisher <paul@pfish.zone>
parents:
153
diff
changeset
|
337 let level = match level { |
ab8020566cd9
Only use real PAM constants for logging within `nonstick/libpam`.
Paul Fisher <paul@pfish.zone>
parents:
153
diff
changeset
|
338 Level::Error => libc::LOG_ERR, |
157
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
339 Level::Warn => libc::LOG_WARNING, |
155
ab8020566cd9
Only use real PAM constants for logging within `nonstick/libpam`.
Paul Fisher <paul@pfish.zone>
parents:
153
diff
changeset
|
340 Level::Info => libc::LOG_INFO, |
ab8020566cd9
Only use real PAM constants for logging within `nonstick/libpam`.
Paul Fisher <paul@pfish.zone>
parents:
153
diff
changeset
|
341 Level::Debug => libc::LOG_DEBUG, |
ab8020566cd9
Only use real PAM constants for logging within `nonstick/libpam`.
Paul Fisher <paul@pfish.zone>
parents:
153
diff
changeset
|
342 }; |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
343 _ = loc; |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
344 // SAFETY: We're calling this function with a known value. |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
345 #[cfg(pam_impl = "LinuxPam")] |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
346 unsafe { |
157
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
347 libpam_sys::pam_syslog( |
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
348 self.raw_ref(), |
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
349 level, |
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
350 b"%s\0".as_ptr().cast(), |
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
351 entry.as_ptr(), |
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
352 ) |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
353 } |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
354 #[cfg(pam_impl = "Sun")] |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
355 unsafe { |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
356 libpam_sys::__pam_log(level, b"%s\0".as_ptr().cast(), entry.as_ptr()) |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
357 } |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
358 } |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
359 #[cfg(pam_impl = "OpenPam")] |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
360 { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
361 let func = CString::new(loc.function).unwrap_or(CString::default()); |
155
ab8020566cd9
Only use real PAM constants for logging within `nonstick/libpam`.
Paul Fisher <paul@pfish.zone>
parents:
153
diff
changeset
|
362 let level = match level { |
ab8020566cd9
Only use real PAM constants for logging within `nonstick/libpam`.
Paul Fisher <paul@pfish.zone>
parents:
153
diff
changeset
|
363 Level::Error => libpam_sys::PAM_LOG_ERROR, |
157
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
364 Level::Warn => libpam_sys::PAM_LOG_NOTICE, |
155
ab8020566cd9
Only use real PAM constants for logging within `nonstick/libpam`.
Paul Fisher <paul@pfish.zone>
parents:
153
diff
changeset
|
365 Level::Info => libpam_sys::PAM_LOG_VERBOSE, |
ab8020566cd9
Only use real PAM constants for logging within `nonstick/libpam`.
Paul Fisher <paul@pfish.zone>
parents:
153
diff
changeset
|
366 Level::Debug => libpam_sys::PAM_LOG_DEBUG, |
ab8020566cd9
Only use real PAM constants for logging within `nonstick/libpam`.
Paul Fisher <paul@pfish.zone>
parents:
153
diff
changeset
|
367 }; |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
368 // SAFETY: We're calling this function with a known value. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
369 unsafe { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
370 libpam_sys::_openpam_log( |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
371 level as c_int, |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
372 func.as_ptr(), |
157
0099f2f79f86
Switch logging interface to accept fmt::Arguments.
Paul Fisher <paul@pfish.zone>
parents:
156
diff
changeset
|
373 b"%s\0".as_ptr().cast(), |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
374 entry.as_ptr(), |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
375 ) |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
376 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
377 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
378 } |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
379 } |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
380 |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
381 impl PamShared for LibPamHandle { |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
382 fn username(&mut self, prompt: Option<&OsStr>) -> Result<OsString> { |
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
383 let prompt = memory::option_cstr_os(prompt); |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
384 let mut output: *const c_char = ptr::null(); |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
385 let ret = unsafe { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
386 libpam_sys::pam_get_user( |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
387 self.raw_mut(), |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
388 &mut output, |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
389 memory::prompt_ptr(prompt.as_deref()), |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
390 ) |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
391 }; |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
392 ErrorCode::result_from(ret)?; |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
393 Ok(unsafe { memory::copy_pam_string(output).ok_or(ErrorCode::ConversationError)? }) |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
394 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
395 |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
396 fn environ(&self) -> impl EnvironMap { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
397 LibPamEnviron::new(self) |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
398 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
399 |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
400 fn environ_mut(&mut self) -> impl EnvironMapMut { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
401 LibPamEnvironMut::new(self) |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
402 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
403 |
146
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
404 fn items(&self) -> impl Items { |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
405 LibPamItems(self) |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
406 } |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
407 |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
408 fn items_mut(&mut self) -> impl ItemsMut { |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
409 LibPamItemsMut(self) |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
410 } |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
411 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
412 |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
413 impl Conversation for LibPamHandle { |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
414 fn communicate(&self, messages: &[Exchange]) { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
415 match self.conversation_item() { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
416 Ok(conv) => conv.communicate(messages), |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
417 Err(e) => { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
418 for msg in messages { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
419 msg.set_error(e) |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
420 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
421 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
422 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
423 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
424 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
425 |
146
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
426 impl ModuleClient for LibPamHandle { |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
427 fn authtok(&mut self, prompt: Option<&OsStr>) -> Result<OsString> { |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
428 self.get_authtok(prompt, ItemType::AuthTok) |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
429 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
430 |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
431 fn old_authtok(&mut self, prompt: Option<&OsStr>) -> Result<OsString> { |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
432 self.get_authtok(prompt, ItemType::OldAuthTok) |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
433 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
434 |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
435 fn get_module_data<T: 'static>(&self, key: &str) -> Option<&T> { |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
436 // It's technically unsafe to do this, but we assume that other modules |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
437 // aren't going to go out of their way to find the key we've used |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
438 // and corrupt its value's data. |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
439 let full_key = module_data_key::<T>(key); |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
440 let mut ptr: *const c_void = ptr::null(); |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
441 unsafe { |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
442 ErrorCode::result_from(libpam_sys::pam_get_data( |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
443 self.raw_ref(), |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
444 full_key.as_ptr(), |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
445 &mut ptr, |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
446 )) |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
447 .ok()?; |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
448 |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
449 (ptr as *const T).as_ref() |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
450 } |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
451 } |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
452 |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
453 fn set_module_data<T: 'static>(&mut self, key: &str, data: T) -> Result<()> { |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
454 let full_key = module_data_key::<T>(key); |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
455 let data = Box::new(data); |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
456 ErrorCode::result_from(unsafe { |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
457 libpam_sys::pam_set_data( |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
458 self.raw_mut(), |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
459 full_key.as_ptr(), |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
460 Box::into_raw(data).cast(), |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
461 drop_module_data::<T>, |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
462 ) |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
463 }) |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
464 } |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
465 |
146
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
466 fn authtok_item(&self) -> Result<Option<OsString>> { |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
467 unsafe { items::get_cstr_item(self, ItemType::AuthTok) } |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
468 } |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
469 fn old_authtok_item(&self) -> Result<Option<OsString>> { |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
470 unsafe { items::get_cstr_item(self, ItemType::OldAuthTok) } |
1bc52025156b
Split PAM items into their own separate struct.
Paul Fisher <paul@pfish.zone>
parents:
144
diff
changeset
|
471 } |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
472 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
473 |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
474 /// Constructs a type-specific, module-specific key for this data. |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
475 fn module_data_key<T: 'static>(key: &str) -> CString { |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
476 // The type ID is unique per-type. |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
477 let tid = TypeId::of::<T>(); |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
478 // The `set_data_cleanup` function lives statically inside each PAM module, |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
479 // so its address will be different between `pam_a.so` and `pam_b.so`, |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
480 // even if both modules .so files are byte-for-byte identical. |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
481 let cleanup_addr = drop_module_data::<T> as usize; |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
482 // Then, by adding the key, |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
483 let key = format!("{key:?}::{tid:?}::{cleanup_addr:016x}"); |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
484 CString::new(key).expect("null bytes somehow got into a debug string?") |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
485 } |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
486 |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
487 /// Function called at the end of a PAM session that is called to clean up |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
488 /// a value previously provided to PAM in a `pam_set_data` call. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
489 /// |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
490 /// You should never call this yourself. |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
491 extern "C" fn drop_module_data<T>(_: *mut libpam_sys::pam_handle, c_data: *mut c_void, _: c_int) { |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
492 unsafe { |
153
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
493 // Adopt the pointer into a Box and immediately drop it. |
3036f2e6a022
Add module-specific data support.
Paul Fisher <paul@pfish.zone>
parents:
148
diff
changeset
|
494 let _: Box<T> = Box::from_raw(c_data.cast()); |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
495 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
496 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
497 |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
498 // Implementations of internal functions. |
144
56b559b7ecea
Big rename: separate concepts of Transaction from Handle.
Paul Fisher <paul@pfish.zone>
parents:
143
diff
changeset
|
499 impl LibPamHandle { |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
500 #[cfg(any(pam_impl = "LinuxPam", pam_impl = "OpenPam"))] |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
501 fn get_authtok(&mut self, prompt: Option<&OsStr>, item_type: ItemType) -> Result<OsString> { |
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
502 let prompt = memory::option_cstr_os(prompt); |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
503 let mut output: *const c_char = ptr::null(); |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
504 // SAFETY: We're calling this with known-good values. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
505 let res = unsafe { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
506 libpam_sys::pam_get_authtok( |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
507 self.raw_mut(), |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
508 item_type.into(), |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
509 &mut output, |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
510 memory::prompt_ptr(prompt.as_deref()), |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
511 ) |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
512 }; |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
513 ErrorCode::result_from(res)?; |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
514 // SAFETY: We got this string from PAM. |
143
ebb71a412b58
Turn everything into OsString and Just Walk Out! for strings with nul.
Paul Fisher <paul@pfish.zone>
parents:
141
diff
changeset
|
515 unsafe { memory::copy_pam_string(output) }.ok_or(ErrorCode::ConversationError) |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
516 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
517 |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
518 #[cfg(pam_impl = "Sun")] |
156
66e662cde087
fix return type of get_authtok for weird PAMs
Paul Fisher <paul@pfish.zone>
parents:
155
diff
changeset
|
519 fn get_authtok(&mut self, prompt: Option<&OsStr>, item_type: ItemType) -> Result<OsString> { |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
520 use crate::libpam::memory::CHeapString; |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
521 use std::os::unix::ffi::OsStringExt; |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
522 // Sun's __pam_get_authtok function is a little weird and requires |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
523 // that you specify where you want the authtok to come from. |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
524 // First we see if there's an authtok already set. |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
525 let mut output: *mut c_char = ptr::null_mut(); |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
526 let result = unsafe { |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
527 libpam_sys::__pam_get_authtok( |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
528 self.raw_mut(), |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
529 libpam_sys::PAM_HANDLE, |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
530 item_type.into(), |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
531 ptr::null(), |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
532 &mut output, |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
533 ) |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
534 }; |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
535 let output = unsafe { CHeapString::from_ptr(output) }; |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
536 if result == libpam_sys::PAM_SUCCESS { |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
537 if let Some(output) = output { |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
538 return Ok(OsString::from_vec(output.to_bytes().into())); |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
539 } |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
540 } |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
541 drop(output); |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
542 let mut output: *mut c_char = ptr::null_mut(); |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
543 let prompt = memory::option_cstr_os(prompt); |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
544 let result = unsafe { |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
545 libpam_sys::__pam_get_authtok( |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
546 self.raw_mut(), |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
547 libpam_sys::PAM_PROMPT, |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
548 item_type.into(), |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
549 memory::prompt_ptr(prompt.as_deref()), |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
550 &mut output, |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
551 ) |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
552 }; |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
553 let output = unsafe { CHeapString::from_ptr(output) }; |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
554 ErrorCode::result_from(result)?; |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
555 output |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
556 .map(|s| OsString::from_vec(s.to_bytes().into())) |
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
557 .ok_or(ErrorCode::ConversationError) |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
558 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
559 |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
560 /// Gets the `PAM_CONV` item from the handle. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
561 fn conversation_item(&self) -> Result<&PamConv> { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
562 let output: *const PamConv = ptr::null_mut(); |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
563 let result = unsafe { |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
564 libpam_sys::pam_get_item( |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
565 self.raw_ref(), |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
566 ItemType::Conversation.into(), |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
567 &mut output.cast(), |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
568 ) |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
569 }; |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
570 ErrorCode::result_from(result)?; |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
571 // SAFETY: We got this result from PAM, and we're checking if it's null. |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
572 unsafe { output.as_ref() }.ok_or(ErrorCode::ConversationError) |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
573 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
574 } |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
575 |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
576 /// Identifies what is being gotten or set with `pam_get_item` |
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
577 /// or `pam_set_item`. |
159
634cd5f2ac8b
Separate logging into its own trait apart from the rest of PAM.
Paul Fisher <paul@pfish.zone>
parents:
157
diff
changeset
|
578 #[derive(Clone, Copy, PartialEq, Eq, TryFromPrimitive, IntoPrimitive)] |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
579 #[repr(i32)] |
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
580 #[non_exhaustive] // because C could give us anything! |
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
581 pub enum ItemType { |
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
582 /// The PAM service name. |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
583 Service = constants::PAM_SERVICE, |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
584 /// The user's login name. |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
585 User = constants::PAM_USER, |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
586 /// The TTY name. |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
587 Tty = constants::PAM_TTY, |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
588 /// The remote host (if applicable). |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
589 RemoteHost = constants::PAM_RHOST, |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
590 /// The conversation struct (not a CStr-based item). |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
591 Conversation = constants::PAM_CONV, |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
592 /// The authentication token (password). |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
593 AuthTok = constants::PAM_AUTHTOK, |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
594 /// The old authentication token (when changing passwords). |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
595 OldAuthTok = constants::PAM_OLDAUTHTOK, |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
596 /// The remote user's name. |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
597 RemoteUser = constants::PAM_RUSER, |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
598 /// The prompt shown when requesting a username. |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
599 UserPrompt = constants::PAM_USER_PROMPT, |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
600 #[cfg(feature = "linux-pam-ext")] |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
601 /// App-supplied function to override failure delays. |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
602 FailDelay = constants::PAM_FAIL_DELAY, |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
603 #[cfg(feature = "linux-pam-ext")] |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
604 /// X display name. |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
605 XDisplay = constants::PAM_XDISPLAY, |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
606 #[cfg(feature = "linux-pam-ext")] |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
607 /// X server authentication data. |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
608 XAuthData = constants::PAM_XAUTHDATA, |
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
609 #[cfg(feature = "linux-pam-ext")] |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
610 /// The type of `pam_get_authtok`. |
141
a508a69c068a
Remove a lot of Results from functions.
Paul Fisher <paul@pfish.zone>
parents:
134
diff
changeset
|
611 AuthTokType = constants::PAM_AUTHTOK_TYPE, |
73
ac6881304c78
Do conversations, along with way too much stuff.
Paul Fisher <paul@pfish.zone>
parents:
diff
changeset
|
612 } |