1 dnl Process this file with autoconf to produce a configure script.
3 AC_CONFIG_SRCDIR([conf/pam_conv1/pam_conv_y.y])
4 AC_CONFIG_AUX_DIR([build-aux])
5 AM_INIT_AUTOMAKE("Linux-PAM", 1.1.6)
7 AC_CONFIG_HEADERS([config.h])
8 AC_CONFIG_MACRO_DIR([m4])
15 dnl By default, everything under PAM is installed below /usr.
17 AC_PREFIX_DEFAULT(/usr)
19 dnl and some hacks to use /etc and /lib
20 test "${prefix}" = "NONE" && prefix="/usr"
21 if test ${prefix} = '/usr'
23 dnl If we use /usr as prefix, use /etc for config files
24 if test ${sysconfdir} = '${prefix}/etc'
28 if test ${libdir} = '${exec_prefix}/lib'
31 x86_64|ppc64|s390x|sparc64)
37 if test ${sbindir} = '${exec_prefix}/sbin'
41 dnl If we use /usr as prefix, use /usr/share/man for manual pages
42 if test ${mandir} = '${prefix}/man'
44 mandir='${prefix}/share/man'
46 dnl Add security to include directory
47 if test ${includedir} = '${prefix}/include'
49 includedir="${prefix}/include/security"
52 dnl Add /var directory
53 if test ${localstatedir} = '${prefix}/var'
61 dnl check if we should link everything static into libpam
63 AC_ARG_ENABLE(static-modules,AS_HELP_STRING([--enable-static-modules],
64 [do not make the modules dynamically loadable]),
65 STATIC_MODULES=$enableval,STATIC_MODULES=no)
66 if test "$STATIC_MODULES" != "no" ; then
67 CFLAGS="$CFLAGS -DPAM_STATIC"
68 AC_ENABLE_STATIC([yes])
69 AC_ENABLE_SHARED([no])
71 # per default don't build static libraries
72 AC_ENABLE_STATIC([no])
73 AC_ENABLE_SHARED([yes])
75 AM_CONDITIONAL([STATIC_MODULES], [test "$STATIC_MODULES" != "no"])
77 dnl Checks for programs.
78 AC_USE_SYSTEM_EXTENSIONS
94 dnl icc claims to be GCC compatible, but use other flags for warnings
95 if eval "test x$GCC = xyes -a $CC != icc"; then
102 -Wmissing-declarations \
103 -Wmissing-prototypes \
106 -Wstrict-prototypes \
111 JAPHAR_GREP_CFLAGS($flag, [ CFLAGS="$CFLAGS $flag" ])
114 dnl icc has special warning flags
115 if eval "test x$CC = xicc"; then
118 -Wmissing-prototypes \
121 -Wstrict-prototypes \
129 JAPHAR_GREP_CFLAGS($flag, [ CFLAGS="$CFLAGS $flag" ])
133 if test "x${CC_FOR_BUILD+set}" != "xset" ; then
134 if test "x$cross_compiling" = "xyes" ; then
135 AC_CHECK_PROGS(CC_FOR_BUILD, gcc cc)
140 AC_MSG_CHECKING([for CC_FOR_BUILD])
141 AC_MSG_RESULT([$CC_FOR_BUILD])
142 AC_SUBST(CC_FOR_BUILD)
144 if test "x${BUILD_CFLAGS+set}" != "xset" ; then
145 if test "x$cross_compiling" = "xyes" ; then
148 BUILD_CFLAGS=${CFLAGS}
151 AC_SUBST(BUILD_CFLAGS)
153 if test "x${BUILD_LDFLAGS+set}" != "xset" ; then
154 if test "x$cross_compiling" = "xyes" ; then
157 BUILD_LDFLAGS=${LDFLAGS}
160 AC_SUBST(BUILD_LDFLAGS)
165 dnl Check if --version-script is supported by ld
167 AC_CACHE_CHECK(for .symver assembler directive, libc_cv_asm_symver_directive,
168 [cat > conftest.s <<EOF
171 .symver _sym,sym@VERS
173 if ${CC-cc} -c $ASFLAGS conftest.s 1>&AS_MESSAGE_LOG_FD 2>&AS_MESSAGE_LOG_FD; then
174 libc_cv_asm_symver_directive=yes
176 libc_cv_asm_symver_directive=no
179 AC_CACHE_CHECK(for ld --version-script, libc_cv_ld_version_script_option, [dnl
180 if test $libc_cv_asm_symver_directive = yes; then
181 cat > conftest.s <<EOF
184 .symver _sym,sym@VERS
186 cat > conftest.map <<EOF
195 if ${CC-cc} -c $ASFLAGS conftest.s 1>&AS_MESSAGE_LOG_FD 2>&AS_MESSAGE_LOG_FD;
197 if AC_TRY_COMMAND([${CC-cc} $CFLAGS $LDFLAGS -shared
198 -o conftest.so conftest.o
199 -nostartfiles -nostdlib
200 -Wl,--version-script,conftest.map
201 1>&AS_MESSAGE_LOG_FD]);
203 libc_cv_ld_version_script_option=yes
205 libc_cv_ld_version_script_option=no
208 libc_cv_ld_version_script_option=no
211 libc_cv_ld_version_script_option=no
214 AM_CONDITIONAL([HAVE_VERSIONING],
215 [test "$libc_cv_ld_version_script_option" = "yes"])
218 dnl check for -fPIE/-pie support
220 dnl icc handles -fpie as -fp without error, so blacklist icc
222 AC_ARG_ENABLE(pie,AS_HELP_STRING([--disable-pie],
223 [disable position-independent executeables (PIE)]),
224 USE_PIE=$enableval, USE_PIE=yes)
226 AC_CACHE_CHECK(for -fpie, libc_cv_fpie, [dnl
227 cat > conftest.c <<EOF
231 if test "$USE_PIE" = "yes" -a "$CC" != "icc" &&
232 AC_TRY_COMMAND([${CC-cc} $CFLAGS $CPPFLAGS $LDFLAGS -pie -fpie
233 -o conftest conftest.c 1>&AS_MESSAGE_LOG_FD])
244 AC_SUBST(libc_cv_fpie)
246 AC_SUBST(PIE_LDFLAGS)
250 dnl options and defaults
253 AC_ARG_ENABLE([prelude],
254 AS_HELP_STRING([--disable-prelude],[do not use prelude]),
255 WITH_PRELUDE=$enableval, WITH_PRELUDE=yes)
256 if test "$WITH_PRELUDE" == "yes" ; then
257 AM_PATH_LIBPRELUDE([0.9.0])
258 if test "$LIBPRELUDE_CONFIG" != "no" ; then
259 LIBPRELUDE_CFLAGS="$LIBPRELUDE_CFLAGS -DPRELUDE=1"
263 dnl lots of debugging information goes to /var/run/pam-debug.log
264 AC_ARG_ENABLE([debug],
265 AS_HELP_STRING([--enable-debug],[specify you are building with debugging on]))
267 if test x"$enable_debug" = x"yes" ; then
268 AC_DEFINE([PAM_DEBUG],,
269 [lots of stuff gets written to /var/run/pam-debug.log])
272 AC_ARG_ENABLE(securedir,
273 AS_HELP_STRING([--enable-securedir=DIR],[path to location of PAMs @<:@default=$libdir/security@:>@]),
274 SECUREDIR=$enableval, SECUREDIR=$libdir/security)
277 AC_ARG_ENABLE([isadir],
278 AS_HELP_STRING([--enable-isadir=DIR],[path to arch-specific module files @<:@default=../../(basename of $libdir)/security@:>@]),
280 ISA=../../`basename $libdir`/security)
282 AC_DEFINE_UNQUOTED(_PAM_ISA,"$ISA",[Define to the path, relative to SECUREDIR, where PAMs specific to this architecture can be found.])
283 AC_MSG_RESULT([Defining \$ISA to "$ISA"])
285 AC_ARG_ENABLE(sconfigdir,
286 AS_HELP_STRING([--enable-sconfigdir=DIR],[path to module conf files @<:@default=$sysconfdir/security@:>@]),
287 SCONFIGDIR=$enableval, SCONFIGDIR=$sysconfdir/security)
290 AC_ARG_ENABLE(pamlocking,
291 AS_HELP_STRING([--enable-pamlocking],[configure libpam to observe a global authentication lock]))
293 if test x"$enable_pamlocking" = "xyes"; then
294 AC_DEFINE([PAM_LOCKING],,
295 [libpam should observe a global authentication lock])
298 AC_ARG_ENABLE(read-both-confs,
299 AS_HELP_STRING([--enable-read-both-confs],[read both /etc/pam.d and /etc/pam.conf files]))
301 if test x"$enable_read_both_confs" = "xyes"; then
302 AC_DEFINE([PAM_READ_BOTH_CONFS],,
303 [read both /etc/pam.d and /etc/pam.conf files])
306 AC_ARG_ENABLE([lckpwdf],
307 AS_HELP_STRING([--disable-lckpwdf],[do not use the lckpwdf function]),
308 WITH_LCKPWDF=$enableval, WITH_LCKPWDF=yes)
309 if test "$WITH_LCKPWDF" == "yes" ; then
310 AC_DEFINE([USE_LCKPWDF], 1,
311 [Define to 1 if the lckpwdf function should be used])
314 AC_CHECK_HEADERS(paths.h)
315 AC_ARG_WITH(mailspool,
316 [ --with-mailspool path to mail spool directory
317 [default _PATH_MAILDIR if defined in paths.h, otherwise /var/spool/mail]],
318 with_mailspool=${withval})
319 if test x$with_mailspool != x ; then
320 pam_mail_spool="\"$with_mailspool\""
322 AC_RUN_IFELSE([AC_LANG_SOURCE([[
330 }]])],[pam_mail_spool="_PATH_MAILDIR"],[pam_mail_spool="\"/var/spool/mail\""],[pam_mail_spool="\"/var/spool/mail\""])
332 AC_DEFINE_UNQUOTED(PAM_PATH_MAILDIR, $pam_mail_spool,
333 [Path where mails are stored])
336 [ --with-xauth additional path to check for xauth when it is called from pam_xauth
337 [added to the default of /usr/X11R6/bin/xauth, /usr/bin/xauth, /usr/bin/X11/xauth]],
338 pam_xauth_path=${withval})
339 if test x$with_xauth == x ; then
340 AC_PATH_PROG(pam_xauth_path, xauth)
341 dnl There is no sense in adding the first default path
342 if test x$pam_xauth_path == x/usr/X11R6/bin/xauth ; then
347 if test x$pam_xauth_path != x ; then
348 AC_DEFINE_UNQUOTED(PAM_PATH_XAUTH, "$pam_xauth_path",
349 [Additional path of xauth executable])
352 dnl Checks for the existence of libdl - on BSD and Tru64 its part of libc
353 AC_CHECK_LIB([dl], [dlopen], LIBDL="-ldl", LIBDL="")
357 AC_ARG_ENABLE([cracklib],
358 AS_HELP_STRING([--disable-cracklib],[do not use cracklib]),
359 WITH_CRACKLIB=$enableval, WITH_CRACKLIB=yes)
360 if test x"$WITH_CRACKLIB" != xno ; then
361 AC_CHECK_HEADERS([crack.h],
362 AC_CHECK_LIB([crack], [FascistCheck], LIBCRACK="-lcrack", LIBCRACK=""))
366 if test -n "$LIBCRACK"; then
367 AC_DEFINE([HAVE_LIBCRACK], [1], [Define to 1 if you have cracklib.])
370 AM_CONDITIONAL([HAVE_LIBCRACK], [test -n "$LIBCRACK"])
372 dnl Look for Linux Auditing library - see documentation
373 AC_ARG_ENABLE([audit],
374 AS_HELP_STRING([--disable-audit],[do not enable audit support]),
375 WITH_LIBAUDIT=$enableval, WITH_LIBAUDIT=yes)
376 if test x"$WITH_LIBAUDIT" != xno ; then
377 AC_CHECK_HEADER([libaudit.h],
378 [AC_CHECK_LIB(audit, audit_log_acct_message, LIBAUDIT=-laudit, LIBAUDIT="")
379 AC_CHECK_TYPE([struct audit_tty_status],
380 [HAVE_AUDIT_TTY_STATUS=yes],
381 [HAVE_AUDIT_TTY_STATUS=""],
382 [#include <libaudit.h>])]
384 if test ! -z "$LIBAUDIT" -a "$ac_cv_header_libaudit_h" != "no" ; then
385 AC_DEFINE([HAVE_LIBAUDIT], 1, [Define to 1 if audit support should be compiled in.])
387 if test ! -z "$HAVE_AUDIT_TTY_STATUS" ; then
388 AC_DEFINE([HAVE_AUDIT_TTY_STATUS], 1, [Define to 1 if struct audit_tty_status exists.])
394 AM_CONDITIONAL([HAVE_AUDIT_TTY_STATUS],
395 [test "x$HAVE_AUDIT_TTY_STATUS" = xyes])
397 AC_CHECK_HEADERS(xcrypt.h crypt.h)
398 AS_IF([test "x$ac_cv_header_xcrypt_h" = "xyes"],
399 [crypt_libs="xcrypt crypt"],
400 [crypt_libs="crypt"])
403 AC_SEARCH_LIBS([crypt],[$crypt_libs], LIBCRYPT="-l$ac_lib", LIBCRYPT="")
404 AC_CHECK_FUNCS(crypt_r crypt_gensalt_r)
407 if test "$LIBCRYPT" = "-lxcrypt" -a "$ac_cv_header_xcrypt_h" = "yes" ; then
408 AC_DEFINE([HAVE_LIBXCRYPT], 1, [Define to 1 if xcrypt support should be compiled in.])
411 AC_ARG_WITH([randomdev], AS_HELP_STRING([--with-randomdev=(<path>|yes|no)],[use specified random device instead of /dev/urandom or 'no' to disable]), opt_randomdev=$withval)
412 if test "$opt_randomdev" = yes -o -z "$opt_randomdev"; then
413 opt_randomdev="/dev/urandom"
414 elif test "$opt_randomdev" = no; then
417 if test -n "$opt_randomdev"; then
418 AC_DEFINE_UNQUOTED(PAM_PATH_RANDOMDEV, "$opt_randomdev", [Random device path.])
421 dnl check for libdb or libndbm as fallback. Some libndbm compat
422 dnl libraries are unuseable, so try libdb first.
424 AS_HELP_STRING([--enable-db=(db|ndbm|yes|no)],[Default behavior 'yes', which is to check for libdb first, followed by ndbm. Use 'no' to disable db support.]),
425 WITH_DB=$enableval, WITH_DB=yes)
426 AC_ARG_WITH([db-uniquename],
427 AS_HELP_STRING([--with-db-uniquename=extension],[Unique name for db libraries and functions.]))
428 if test x"$WITH_DB" != xno ; then
429 if test x"$WITH_DB" = xyes -o x"$WITH_DB" = xdb ; then
431 LIBS="$LIBS -ldb$with_db_uniquename"
432 AC_CHECK_FUNCS([db_create$with_db_uniquename db_create dbm_store$with_db_uniquename dbm_store],
433 [LIBDB="-ldb$with_db_uniquename"; break])
436 if test -z "$LIBDB" ; then
437 AC_CHECK_LIB([ndbm],[dbm_store], LIBDB="-lndbm", LIBDB="")
438 if test ! -z "$LIBDB" ; then
439 AC_CHECK_HEADERS(ndbm.h)
442 AC_CHECK_HEADERS(db.h)
446 AM_CONDITIONAL([HAVE_LIBDB], [test ! -z "$LIBDB"])
449 AS_HELP_STRING([--disable-nis], [Disable building NIS/YP support in pam_unix and pam_access]))
451 AS_IF([test "x$enable_nis" != "xno"], [
455 dnl if there's libtirpc available, prefer that over the system
457 PKG_CHECK_MODULES([libtirpc], [libtirpc], [
458 CFLAGS="$CFLAGS $libtirpc_CFLAGS"
459 LIBS="$LIBS $libtirpc_LIBS"
462 AC_SEARCH_LIBS([yp_get_default_domain], [nsl])
464 AC_CHECK_FUNCS([yp_get_default_domain yperr_string yp_master yp_bind yp_match yp_unbind])
465 AC_CHECK_HEADERS([rpc/rpc.h rpcsvc/ypclnt.h rpcsvc/yp_prot.h])
466 AC_CHECK_DECLS([getrpcport], , , [
468 # include <rpc/rpc.h>
472 NIS_CFLAGS="${CFLAGS%${old_CFLAGS}}"
473 NIS_LIBS="${LIBS%${old_LIBS}}"
479 AC_SUBST([NIS_CFLAGS])
482 AC_ARG_ENABLE([selinux],
483 AS_HELP_STRING([--disable-selinux],[do not use SELinux]),
484 WITH_SELINUX=$enableval, WITH_SELINUX=yes)
485 if test "$WITH_SELINUX" == "yes" ; then
486 AC_CHECK_LIB([selinux],[getfilecon], LIBSELINUX="-lselinux", LIBSELINUX="")
491 AM_CONDITIONAL([HAVE_LIBSELINUX], [test ! -z "$LIBSELINUX"])
492 if test ! -z "$LIBSELINUX" ; then
493 AC_DEFINE([WITH_SELINUX], 1, [Defined if SE Linux support is compiled in])
495 LIBS="$LIBS $LIBSELINUX"
496 AC_CHECK_FUNCS(setkeycreatecon)
497 AC_CHECK_FUNCS(getseuser)
501 dnl hacks for pam_smack
502 PKG_CHECK_MODULES([LIBSMACK], [libsmack])
504 dnl Checks for header files.
508 AC_CHECK_HEADERS(fcntl.h limits.h malloc.h sys/file.h sys/ioctl.h sys/time.h syslog.h net/if.h termio.h unistd.h sys/fsuid.h inittypes.h)
510 dnl For module/pam_lastlog
511 AC_CHECK_HEADERS(lastlog.h utmp.h utmpx.h)
513 dnl Checks for typedefs, structures, and compiler characteristics.
523 dnl Checks for library functions.
525 AC_PROG_GCC_TRADITIONAL
528 AC_CHECK_FUNCS(fseeko getdomainname gethostname gettimeofday lckpwdf mkdir select)
529 AC_CHECK_FUNCS(strcspn strdup strspn strstr strtol uname)
530 AC_CHECK_FUNCS(getutent_r getpwnam_r getpwuid_r getgrnam_r getgrgid_r getspnam_r)
531 AC_CHECK_FUNCS(getgrouplist getline getdelim)
532 AC_CHECK_FUNCS(inet_ntop inet_pton innetgr ruserok_af)
534 AC_CHECK_FUNCS(unshare, [UNSHARE=yes], [UNSHARE=no])
535 AM_CONDITIONAL([HAVE_UNSHARE], [test "$UNSHARE" = yes])
537 AC_ARG_ENABLE([regenerate-docu],
538 AC_HELP_STRING([--disable-regenerate-docu], [Don't re-build documentation from XML souces]),
539 [enable_docu=$enableval], [enable_docu=yes])
541 dnl Check for xsltproc
543 AC_PATH_PROG([XSLTPROC], [xsltproc])
544 if test -z "$XSLTPROC"; then
547 AC_PATH_PROG([XMLLINT], [xmllint],[/bin/true])
548 dnl check for DocBook DTD and stylesheets in the local catalog.
549 JH_CHECK_XML_CATALOG([-//OASIS//DTD DocBook XML V4.4//EN],
550 [DocBook XML DTD V4.4], [], enable_docu=no)
551 JH_CHECK_XML_CATALOG([http://docbook.sourceforge.net/release/xsl/current/manpages/docbook.xsl],
552 [DocBook XSL Stylesheets], [], enable_docu=no)
554 AC_PATH_PROG([BROWSER], [w3m])
555 if test ! -z "$BROWSER"; then
556 BROWSER="$BROWSER -T text/html -dump"
561 AC_PATH_PROG([FO2PDF], [fop])
563 AM_CONDITIONAL(ENABLE_REGENERATE_MAN, test x$enable_docu != xno)
564 AM_CONDITIONAL(ENABLE_GENERATE_PDF, test ! -z "$FO2PDF")
567 AM_GNU_GETTEXT_VERSION([0.15])
568 AM_GNU_GETTEXT([external])
569 AC_CHECK_FUNCS(dngettext)
571 AH_BOTTOM([#ifdef ENABLE_NLS
573 #define _(msgid) dgettext(PACKAGE, msgid)
574 #define N_(msgid) msgid
576 #define _(msgid) (msgid)
577 #define N_(msgid) msgid
578 #endif /* ENABLE_NLS */])
581 dnl Check for the availability of the kernel key management facility
582 dnl - The pam_keyinit module only requires the syscalls, not the error codes
584 AC_CHECK_DECL(__NR_keyctl, [have_key_syscalls=1],[have_key_syscalls=0],[#include <sys/syscall.h>])
585 AC_CHECK_DECL(ENOKEY, [have_key_errors=1],[have_key_errors=0],[#include <errno.h>])
587 HAVE_KEY_MANAGEMENT=0
588 if test $have_key_syscalls$have_key_errors = 11
590 HAVE_KEY_MANAGEMENT=1
593 if test $HAVE_KEY_MANAGEMENT = 1; then
594 AC_DEFINE([HAVE_KEY_MANAGEMENT], 1,
595 [Defined if the kernel key management facility is available])
597 AC_SUBST([HAVE_KEY_MANAGEMENT], $HAVE_KEY_MANAGEMENT)
599 AM_CONDITIONAL([HAVE_KEY_MANAGEMENT], [test "$have_key_syscalls" = 1])
601 dnl Files to be created from when we run configure
602 AC_CONFIG_FILES([Makefile libpam/Makefile libpamc/Makefile libpamc/test/Makefile \
603 libpam_misc/Makefile conf/Makefile conf/pam_conv1/Makefile \
606 modules/pam_access/Makefile modules/pam_cracklib/Makefile \
607 modules/pam_debug/Makefile modules/pam_deny/Makefile \
608 modules/pam_echo/Makefile modules/pam_env/Makefile \
609 modules/pam_faildelay/Makefile \
610 modules/pam_filter/Makefile modules/pam_filter/upperLOWER/Makefile \
611 modules/pam_ftp/Makefile modules/pam_group/Makefile \
612 modules/pam_issue/Makefile modules/pam_keyinit/Makefile \
613 modules/pam_lastlog/Makefile modules/pam_limits/Makefile \
614 modules/pam_listfile/Makefile modules/pam_localuser/Makefile \
615 modules/pam_loginuid/Makefile modules/pam_mail/Makefile \
616 modules/pam_mkhomedir/Makefile modules/pam_motd/Makefile \
617 modules/pam_namespace/Makefile \
618 modules/pam_nologin/Makefile modules/pam_permit/Makefile \
619 modules/pam_pwhistory/Makefile modules/pam_rhosts/Makefile \
620 modules/pam_rootok/Makefile modules/pam_exec/Makefile \
621 modules/pam_securetty/Makefile modules/pam_selinux/Makefile \
622 modules/pam_sepermit/Makefile \
623 modules/pam_shells/Makefile modules/pam_stress/Makefile \
624 modules/pam_succeed_if/Makefile modules/pam_tally/Makefile \
625 modules/pam_tally2/Makefile modules/pam_time/Makefile \
626 modules/pam_timestamp/Makefile modules/pam_tty_audit/Makefile \
627 modules/pam_umask/Makefile \
628 modules/pam_unix/Makefile modules/pam_userdb/Makefile \
629 modules/pam_warn/Makefile modules/pam_wheel/Makefile \
630 modules/pam_xauth/Makefile doc/Makefile doc/specs/Makefile \
631 modules/pam_smack/Makefile \
632 doc/man/Makefile doc/sag/Makefile doc/adg/Makefile \
633 doc/mwg/Makefile examples/Makefile tests/Makefile \