Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions modules/pam_succeed_if/pam_succeed_if.c
Original file line number Diff line number Diff line change
Expand Up @@ -216,10 +216,17 @@ evaluate_ingroup(pam_handle_t *pamh, const char *user, const char *grouplist)
static const char delim[] = ":";
char const *grp = NULL;
char *group = strdup(grouplist);
struct passwd *pwd;

if (group == NULL)
return PAM_BUF_ERR;

pwd = pam_modutil_getpwnam(pamh, user);
if (pwd == NULL) {
free(group);
return PAM_USER_UNKNOWN;
}

grp = strtok_r(group, delim, &ptr);
while(grp != NULL) {
if (pam_modutil_user_in_group_nam_nam(pamh, user, grp) == 1) {
Expand All @@ -239,10 +246,17 @@ evaluate_notingroup(pam_handle_t *pamh, const char *user, const char *grouplist)
static const char delim[] = ":";
char const *grp = NULL;
char *group = strdup(grouplist);
struct passwd *pwd;

if (group == NULL)
return PAM_BUF_ERR;

pwd = pam_modutil_getpwnam(pamh, user);
if (pwd == NULL) {
free(group);
return PAM_USER_UNKNOWN;
}

grp = strtok_r(group, delim, &ptr);
while(grp != NULL) {
if (pam_modutil_user_in_group_nam_nam(pamh, user, grp) == 1) {
Expand All @@ -266,6 +280,12 @@ static int
evaluate_innetgr(const pam_handle_t* pamh SOMETIMES_UNUSED, const char *host, const char *user, const char *group)
{
#ifdef HAVE_INNETGR
struct passwd *pwd;

pwd = pam_modutil_getpwnam((pam_handle_t *)pamh, user);
if (pwd == NULL)
return PAM_USER_UNKNOWN;

if (innetgr(group, host, user, NULL) == 1)
return PAM_SUCCESS;
#else
Expand All @@ -279,6 +299,12 @@ static int
evaluate_notinnetgr(const pam_handle_t* pamh SOMETIMES_UNUSED, const char *host, const char *user, const char *group)
{
#ifdef HAVE_INNETGR
struct passwd *pwd;

pwd = pam_modutil_getpwnam((pam_handle_t *)pamh, user);
if (pwd == NULL)
return PAM_USER_UNKNOWN;

if (innetgr(group, host, user, NULL) == 0)
return PAM_SUCCESS;
#else
Expand Down