1*10b5fe87SSascha Wildner /*-
2*10b5fe87SSascha Wildner  * Copyright (c) 2002-2003 Networks Associates Technology, Inc.
3*10b5fe87SSascha Wildner  * Copyright (c) 2004-2011 Dag-Erling Smørgrav
4*10b5fe87SSascha Wildner  * All rights reserved.
5*10b5fe87SSascha Wildner  *
6*10b5fe87SSascha Wildner  * This software was developed for the FreeBSD Project by ThinkSec AS and
7*10b5fe87SSascha Wildner  * Network Associates Laboratories, the Security Research Division of
8*10b5fe87SSascha Wildner  * Network Associates, Inc.  under DARPA/SPAWAR contract N66001-01-C-8035
9*10b5fe87SSascha Wildner  * ("CBOSS"), as part of the DARPA CHATS research program.
10*10b5fe87SSascha Wildner  *
11*10b5fe87SSascha Wildner  * Redistribution and use in source and binary forms, with or without
12*10b5fe87SSascha Wildner  * modification, are permitted provided that the following conditions
13*10b5fe87SSascha Wildner  * are met:
14*10b5fe87SSascha Wildner  * 1. Redistributions of source code must retain the above copyright
15*10b5fe87SSascha Wildner  *    notice, this list of conditions and the following disclaimer.
16*10b5fe87SSascha Wildner  * 2. Redistributions in binary form must reproduce the above copyright
17*10b5fe87SSascha Wildner  *    notice, this list of conditions and the following disclaimer in the
18*10b5fe87SSascha Wildner  *    documentation and/or other materials provided with the distribution.
19*10b5fe87SSascha Wildner  * 3. The name of the author may not be used to endorse or promote
20*10b5fe87SSascha Wildner  *    products derived from this software without specific prior written
21*10b5fe87SSascha Wildner  *    permission.
22*10b5fe87SSascha Wildner  *
23*10b5fe87SSascha Wildner  * THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
24*10b5fe87SSascha Wildner  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
25*10b5fe87SSascha Wildner  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
26*10b5fe87SSascha Wildner  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
27*10b5fe87SSascha Wildner  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
28*10b5fe87SSascha Wildner  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
29*10b5fe87SSascha Wildner  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
30*10b5fe87SSascha Wildner  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
31*10b5fe87SSascha Wildner  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
32*10b5fe87SSascha Wildner  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
33*10b5fe87SSascha Wildner  * SUCH DAMAGE.
34*10b5fe87SSascha Wildner  *
35*10b5fe87SSascha Wildner  * $OpenPAM: openpam_log.c 938 2017-04-30 21:34:42Z des $
36*10b5fe87SSascha Wildner  */
37*10b5fe87SSascha Wildner 
38*10b5fe87SSascha Wildner #ifdef HAVE_CONFIG_H
39*10b5fe87SSascha Wildner # include "config.h"
40*10b5fe87SSascha Wildner #endif
41*10b5fe87SSascha Wildner 
42*10b5fe87SSascha Wildner #include <errno.h>
43*10b5fe87SSascha Wildner #include <stdarg.h>
44*10b5fe87SSascha Wildner #include <stdio.h>
45*10b5fe87SSascha Wildner #include <stdlib.h>
46*10b5fe87SSascha Wildner #include <syslog.h>
47*10b5fe87SSascha Wildner 
48*10b5fe87SSascha Wildner #include <security/pam_appl.h>
49*10b5fe87SSascha Wildner 
50*10b5fe87SSascha Wildner #include "openpam_impl.h"
51*10b5fe87SSascha Wildner #include "openpam_asprintf.h"
52*10b5fe87SSascha Wildner 
53*10b5fe87SSascha Wildner int openpam_debug = 0;
54*10b5fe87SSascha Wildner 
55*10b5fe87SSascha Wildner #if !defined(openpam_log)
56*10b5fe87SSascha Wildner 
57*10b5fe87SSascha Wildner /*
58*10b5fe87SSascha Wildner  * OpenPAM extension
59*10b5fe87SSascha Wildner  *
60*10b5fe87SSascha Wildner  * Log a message through syslog
61*10b5fe87SSascha Wildner  */
62*10b5fe87SSascha Wildner 
63*10b5fe87SSascha Wildner void
openpam_log(int level,const char * fmt,...)64*10b5fe87SSascha Wildner openpam_log(int level, const char *fmt, ...)
65*10b5fe87SSascha Wildner {
66*10b5fe87SSascha Wildner 	va_list ap;
67*10b5fe87SSascha Wildner 	int priority;
68*10b5fe87SSascha Wildner 	int serrno;
69*10b5fe87SSascha Wildner 
70*10b5fe87SSascha Wildner 	switch (level) {
71*10b5fe87SSascha Wildner 	case PAM_LOG_LIBDEBUG:
72*10b5fe87SSascha Wildner 	case PAM_LOG_DEBUG:
73*10b5fe87SSascha Wildner 		if (!openpam_debug)
74*10b5fe87SSascha Wildner 			return;
75*10b5fe87SSascha Wildner 		priority = LOG_DEBUG;
76*10b5fe87SSascha Wildner 		break;
77*10b5fe87SSascha Wildner 	case PAM_LOG_VERBOSE:
78*10b5fe87SSascha Wildner 		priority = LOG_INFO;
79*10b5fe87SSascha Wildner 		break;
80*10b5fe87SSascha Wildner 	case PAM_LOG_NOTICE:
81*10b5fe87SSascha Wildner 		priority = LOG_NOTICE;
82*10b5fe87SSascha Wildner 		break;
83*10b5fe87SSascha Wildner 	case PAM_LOG_ERROR:
84*10b5fe87SSascha Wildner 	default:
85*10b5fe87SSascha Wildner 		priority = LOG_ERR;
86*10b5fe87SSascha Wildner 		break;
87*10b5fe87SSascha Wildner 	}
88*10b5fe87SSascha Wildner 	serrno = errno;
89*10b5fe87SSascha Wildner 	va_start(ap, fmt);
90*10b5fe87SSascha Wildner 	vsyslog(priority, fmt, ap);
91*10b5fe87SSascha Wildner 	va_end(ap);
92*10b5fe87SSascha Wildner 	errno = serrno;
93*10b5fe87SSascha Wildner }
94*10b5fe87SSascha Wildner 
95*10b5fe87SSascha Wildner #else
96*10b5fe87SSascha Wildner 
97*10b5fe87SSascha Wildner void
_openpam_log(int level,const char * func,const char * fmt,...)98*10b5fe87SSascha Wildner _openpam_log(int level, const char *func, const char *fmt, ...)
99*10b5fe87SSascha Wildner {
100*10b5fe87SSascha Wildner 	va_list ap;
101*10b5fe87SSascha Wildner 	char *format;
102*10b5fe87SSascha Wildner 	int priority;
103*10b5fe87SSascha Wildner 	int serrno;
104*10b5fe87SSascha Wildner 
105*10b5fe87SSascha Wildner 	switch (level) {
106*10b5fe87SSascha Wildner 	case PAM_LOG_LIBDEBUG:
107*10b5fe87SSascha Wildner 	case PAM_LOG_DEBUG:
108*10b5fe87SSascha Wildner 		if (!openpam_debug)
109*10b5fe87SSascha Wildner 			return;
110*10b5fe87SSascha Wildner 		priority = LOG_DEBUG;
111*10b5fe87SSascha Wildner 		break;
112*10b5fe87SSascha Wildner 	case PAM_LOG_VERBOSE:
113*10b5fe87SSascha Wildner 		priority = LOG_INFO;
114*10b5fe87SSascha Wildner 		break;
115*10b5fe87SSascha Wildner 	case PAM_LOG_NOTICE:
116*10b5fe87SSascha Wildner 		priority = LOG_NOTICE;
117*10b5fe87SSascha Wildner 		break;
118*10b5fe87SSascha Wildner 	case PAM_LOG_ERROR:
119*10b5fe87SSascha Wildner 	default:
120*10b5fe87SSascha Wildner 		priority = LOG_ERR;
121*10b5fe87SSascha Wildner 		break;
122*10b5fe87SSascha Wildner 	}
123*10b5fe87SSascha Wildner 	serrno = errno;
124*10b5fe87SSascha Wildner 	va_start(ap, fmt);
125*10b5fe87SSascha Wildner 	if (asprintf(&format, "in %s(): %s", func, fmt) > 0) {
126*10b5fe87SSascha Wildner 		errno = serrno;
127*10b5fe87SSascha Wildner 		vsyslog(priority, format, ap);
128*10b5fe87SSascha Wildner 		FREE(format);
129*10b5fe87SSascha Wildner 	} else {
130*10b5fe87SSascha Wildner 		errno = serrno;
131*10b5fe87SSascha Wildner 		vsyslog(priority, fmt, ap);
132*10b5fe87SSascha Wildner 	}
133*10b5fe87SSascha Wildner 	va_end(ap);
134*10b5fe87SSascha Wildner 	errno = serrno;
135*10b5fe87SSascha Wildner }
136*10b5fe87SSascha Wildner 
137*10b5fe87SSascha Wildner #endif
138*10b5fe87SSascha Wildner 
139*10b5fe87SSascha Wildner /**
140*10b5fe87SSascha Wildner  * The =openpam_log function logs messages using =syslog.
141*10b5fe87SSascha Wildner  * It is primarily intended for internal use by the library and modules.
142*10b5fe87SSascha Wildner  *
143*10b5fe87SSascha Wildner  * The =level argument indicates the importance of the message.
144*10b5fe87SSascha Wildner  * The following levels are defined:
145*10b5fe87SSascha Wildner  *
146*10b5fe87SSascha Wildner  *	=PAM_LOG_LIBDEBUG:
147*10b5fe87SSascha Wildner  *		Debugging messages.
148*10b5fe87SSascha Wildner  *		For internal use only.
149*10b5fe87SSascha Wildner  *	=PAM_LOG_DEBUG:
150*10b5fe87SSascha Wildner  *		Debugging messages.
151*10b5fe87SSascha Wildner  *		These messages are normally not logged unless the global
152*10b5fe87SSascha Wildner  *		integer variable :openpam_debug is set to a non-zero
153*10b5fe87SSascha Wildner  *		value, in which case they are logged with a =syslog
154*10b5fe87SSascha Wildner  *		priority of =LOG_DEBUG.
155*10b5fe87SSascha Wildner  *	=PAM_LOG_VERBOSE:
156*10b5fe87SSascha Wildner  *		Information about the progress of the authentication
157*10b5fe87SSascha Wildner  *		process, or other non-essential messages.
158*10b5fe87SSascha Wildner  *		These messages are logged with a =syslog priority of
159*10b5fe87SSascha Wildner  *		=LOG_INFO.
160*10b5fe87SSascha Wildner  *	=PAM_LOG_NOTICE:
161*10b5fe87SSascha Wildner  *		Messages relating to non-fatal errors.
162*10b5fe87SSascha Wildner  *		These messages are logged with a =syslog priority of
163*10b5fe87SSascha Wildner  *		=LOG_NOTICE.
164*10b5fe87SSascha Wildner  *	=PAM_LOG_ERROR:
165*10b5fe87SSascha Wildner  *		Messages relating to serious errors.
166*10b5fe87SSascha Wildner  *		These messages are logged with a =syslog priority of
167*10b5fe87SSascha Wildner  *		=LOG_ERR.
168*10b5fe87SSascha Wildner  *
169*10b5fe87SSascha Wildner  * The remaining arguments are a =printf format string and the
170*10b5fe87SSascha Wildner  * corresponding arguments.
171*10b5fe87SSascha Wildner  *
172*10b5fe87SSascha Wildner  * The =openpam_log function does not modify the value of :errno.
173*10b5fe87SSascha Wildner  */
174