]>
git.ipfire.org Git - thirdparty/freeradius-server.git/log
Alan T. DeKok [Sat, 18 Jan 2025 20:45:25 +0000 (15:45 -0500)]
update test and docs in preparation for removing '&'
Alan T. DeKok [Sat, 18 Jan 2025 19:11:14 +0000 (14:11 -0500)]
Use :: for enum name
Alan T. DeKok [Sat, 18 Jan 2025 17:18:37 +0000 (12:18 -0500)]
require hard-coded RHS for legacy =* and !* operators.
The recommendation for decades has been to use =*ANY or !*ANY.
We now make it official.
Without that check, the "no &" code will expect the RHS to be
an attribute reference, and will fail.
Update the documentation to match.
Alan T. DeKok [Sat, 18 Jan 2025 16:53:48 +0000 (11:53 -0500)]
we don't need "module" here
Alan T. DeKok [Sat, 18 Jan 2025 16:34:58 +0000 (11:34 -0500)]
swap back to default "no" for tmpl_require_enum_prefix
and update the command-line parser to set the global variable
Alan T. DeKok [Fri, 17 Jan 2025 16:08:09 +0000 (11:08 -0500)]
might as well include the Juniper dictionary
Alan T. DeKok [Fri, 17 Jan 2025 15:57:10 +0000 (10:57 -0500)]
Use / require '@' in subrequest, when changing namespaces
Alan T. DeKok [Fri, 17 Jan 2025 14:32:31 +0000 (09:32 -0500)]
Remove '&'
perl -p -i -e 's/([^&])&([a-zA-Z0-9])/$1$2/g' $(git grep -l '&' src/tests/keywords | egrep -v '\.mk')
with an edit for radiusd.conf
Alan T. DeKok [Thu, 16 Jan 2025 21:12:51 +0000 (16:12 -0500)]
require_enum_prefix=yes is now the default
so we don't need it in the configurations.
Alan T. DeKok [Thu, 16 Jan 2025 20:45:35 +0000 (15:45 -0500)]
swap to "require_enum_prefix = yes" by default.
Hopefully some tests will pass. :)
Alan T. DeKok [Thu, 16 Jan 2025 16:43:04 +0000 (11:43 -0500)]
signal handlers are async. CID #
1638648
Alan T. DeKok [Thu, 16 Jan 2025 16:28:55 +0000 (11:28 -0500)]
quiet coverity
stop using multiple intermediate variables, and just switch to
using p / end, as with almost everything else.
Alan T. DeKok [Wed, 15 Jan 2025 18:58:26 +0000 (13:58 -0500)]
RADIUS can only have 64K packets max. Shuts up Coverity
Alan T. DeKok [Wed, 15 Jan 2025 16:13:12 +0000 (11:13 -0500)]
correct type size check.
not everything is RADIUS
Alan T. DeKok [Wed, 15 Jan 2025 16:02:38 +0000 (11:02 -0500)]
fix up header now that we use BEGIN PROTOCOL
Alan T. DeKok [Wed, 15 Jan 2025 15:49:52 +0000 (10:49 -0500)]
move modification code to locked region. CID #
1638648
Alan T. DeKok [Wed, 15 Jan 2025 14:54:36 +0000 (09:54 -0500)]
alive_clients may be cleaned up out of order
Though arguably this shouldn't happen. For now, just fix the
crash on exit. We don't need to debug the issue if we're moving
to the new BIO code.
James Jones [Thu, 14 Mar 2024 16:10:28 +0000 (11:10 -0500)]
Typo
Alan T. DeKok [Tue, 14 Jan 2025 21:30:52 +0000 (16:30 -0500)]
move raddb to reference
it's not it's own thing, it's part of the reference for the
server.
move the files
git mv doc/antora/modules/raddb/pages doc/antora/modules/references/pages/raddb
fix up the cross refs
perl -p -i -e 's,xref:raddb:,xref:reference:raddb/,' $(git grep -l xref:raddb .)
fix up doc/all.mk with change thingies
move raddb/nav.adoc into references/nav.adoc, with one more level of nesting
Alan T. DeKok [Mon, 13 Jan 2025 21:21:52 +0000 (16:21 -0500)]
we can't set da->type until later, or else things complain
Alan T. DeKok [Mon, 13 Jan 2025 20:50:39 +0000 (15:50 -0500)]
might as well set da->dict, too
Alan T. DeKok [Mon, 13 Jan 2025 20:49:58 +0000 (15:49 -0500)]
pass da_p to type_parse()
so that it can update or add extensions.
Alan T. DeKok [Mon, 13 Jan 2025 20:49:13 +0000 (15:49 -0500)]
pass da_p
ethan-thompson [Mon, 13 Jan 2025 19:02:58 +0000 (14:02 -0500)]
fix: Updated reference to attr.type_parse to use the dict of the decode context, since the da dict is not set until shortly after this call is made.
Signed-off-by: ethan-thompson <ethan.thompson@networkradius.com>
Alan T. DeKok [Mon, 13 Jan 2025 14:57:37 +0000 (09:57 -0500)]
remove unused code
should not have been commited with fix
713622c9eaa72
nolade [Thu, 9 Jan 2025 22:07:48 +0000 (17:07 -0500)]
minor updates README.md & install_deps.sh - added link , reworded some lines
Added details to steps, add hyperlinks, updated layout with headers (TOC)
Remove zip instructions
Nick Porter [Mon, 13 Jan 2025 10:15:52 +0000 (10:15 +0000)]
Include timeout duration in debug message
Nick Porter [Mon, 13 Jan 2025 10:13:56 +0000 (10:13 +0000)]
Copy shortname after dynamic client is defined
github-actions[bot] [Mon, 13 Jan 2025 09:34:58 +0000 (09:34 +0000)]
Scheduled fuzzing: Update src/tests/fuzzer-corpus/cbor.tar
Alan T. DeKok [Sun, 12 Jan 2025 22:46:22 +0000 (17:46 -0500)]
initialize vals. CID #
1638739
James Jones [Sun, 12 Jan 2025 20:52:03 +0000 (14:52 -0600)]
give ret the appropriate type (CID #
1604602 ) (#5429)
Declaring ret as ssize_t, the value fr_aka_sim_encode() returns,
avoids the overflow_const error.
James Jones [Sun, 12 Jan 2025 20:51:22 +0000 (14:51 -0600)]
Handle edge case in fr_rand_init() and, we suspect, oveflow (CID #
1604611 ) (#5434)
To handle the rare case of not filling fr_rand_pool.randrsl in a single read,
adjust the location passed to read() to skip what was read in a previous
interation. This is done in a way consistent with the handling of this case
in 3.x, which should also deal with the overflow_sink complaint from Coverity.
James Jones [Sun, 12 Jan 2025 20:49:36 +0000 (14:49 -0600)]
Annotate return_overflow in mod_write() (CID #
1604620 ) (#5437)
This is arguably another example of trying to return a value not
representable in the function return type. It's highly unlikely that
anyone will pass a buffer of more than SSIZE_MAX bytes, but Coverity
apparently doesn't consider that.
CIDs #
1604605 and #
1604616 explicitly do return error values not
representable as int, but a ridiculously large buffer allocation will
fail long before anyone calls mod_write(), so we annotate.
James Jones [Sun, 12 Jan 2025 20:49:14 +0000 (14:49 -0600)]
Annotate return_overflow in fr_writev() (CID #
1604625 ) (#5438)
In theory, iovcnt and the amounts written could total to more than
SSIZE_MAX, and when Coverity is looking at fr_writev() rather than
its callers it can't tell. We therefore annotate.
James Jones [Sun, 12 Jan 2025 20:48:53 +0000 (14:48 -0600)]
Move coverity-only check ahead of first use (CID #
1635782 ) (#5474)
The check that dctx->dict is non-NULL has to appear before
the first dereference of dctx->dict.
James Jones [Sun, 12 Jan 2025 20:48:01 +0000 (14:48 -0600)]
Switch Coverity-only code to assert (CID #
1619299 ) (#5441)
fr_nbo_from_uint64v() does not have an error return--it doesn't
need one. The buffers are big enough, the "| 0x80" means it will
always use as least one byte, so fr_high_bit_pos() won't return 0
even if num == 0. So adding a bogus error return check for Coverity
actually misleads Coverity about any call to fr_nbo_from_uint64v(),
making it the probable cause of the CID.
Co-authored-by: Arran Cudbard-Bell <a.cudbardb@freeradius.org>
Alan T. DeKok [Sun, 12 Jan 2025 14:50:27 +0000 (09:50 -0500)]
quiet a number of coverity issues
Alan T. DeKok [Sun, 12 Jan 2025 14:25:29 +0000 (09:25 -0500)]
copy is_set fields, too
Alan T. DeKok [Sat, 11 Jan 2025 15:11:38 +0000 (10:11 -0500)]
shut up coverity. CID #
1604620
Alan T. DeKok [Sat, 11 Jan 2025 15:04:01 +0000 (10:04 -0500)]
tweak code to satisfy coverity #
1633838
Nick Porter [Sun, 12 Jan 2025 14:24:14 +0000 (14:24 +0000)]
Pacify Coverity (#CID
1638651 )
Coverity doesn't understand that the limit on the number of parsed
digits prevents an overflow.
Nick Porter [Sun, 12 Jan 2025 14:02:39 +0000 (14:02 +0000)]
Add DR_TACACS_CODE_DO_NOT_RESPOND to TACACS process_state (#CID
1638274 )
Alan T. DeKok [Sat, 11 Jan 2025 14:27:15 +0000 (09:27 -0500)]
better handle dynamic clients for connected sockets
don't run "new client" on every connection
Alan T. DeKok [Sat, 11 Jan 2025 13:40:05 +0000 (08:40 -0500)]
no need for destructor
alive clients are talloc'd from the thread, so freeing the thread
will free the clients
Alan T. DeKok [Sat, 11 Jan 2025 01:44:43 +0000 (20:44 -0500)]
clean up messages for BlastRADIUS issues
Alan T. DeKok [Fri, 10 Jan 2025 21:44:23 +0000 (16:44 -0500)]
set "yes" to "1" and "auto" to "2"
The configuration file parsing code parses things before it knows
their data types. Which means that "yes" gets parsed as data type
"bool", with value "1". It then gets cast to "uint8_t" when
processing the require-ma attribute. Which just happens to have
"auto" as "1", and "yes" as "2".
Rather than redoing all of the parsing code, we just set "yes"
to "1", which is much safer.
Alan T. DeKok [Fri, 10 Jan 2025 20:42:02 +0000 (15:42 -0500)]
correct check
Alan T. DeKok [Fri, 10 Jan 2025 20:34:02 +0000 (15:34 -0500)]
we shouldn't need to require "add client" or "deny client"
but at least print out what we're doing
Alan T. DeKok [Fri, 10 Jan 2025 14:30:55 +0000 (09:30 -0500)]
correct checks in dict_attr_allow_dup()
so that it actually checks for dups.
Alan T. DeKok [Fri, 10 Jan 2025 14:10:46 +0000 (09:10 -0500)]
clearer errors
Alan T. DeKok [Thu, 9 Jan 2025 21:40:58 +0000 (16:40 -0500)]
call SSL_set_connect_state() when starting client context
Alan T. DeKok [Thu, 9 Jan 2025 19:36:53 +0000 (14:36 -0500)]
added missing dictionaries
Alan T. DeKok [Thu, 9 Jan 2025 19:01:29 +0000 (14:01 -0500)]
update as per recent feature additions
Nick Porter [Fri, 10 Jan 2025 11:35:34 +0000 (11:35 +0000)]
Add dynamic client processing to TACACS state machine
Nick Porter [Fri, 10 Jan 2025 11:34:53 +0000 (11:34 +0000)]
No need to re-write attributes for TACACS dynamic clients
As we haven't done a packet decode, the request pair list will be empty.
Nick Porter [Fri, 10 Jan 2025 11:33:14 +0000 (11:33 +0000)]
Initial packets from TACACS+ dynamic clients can't be decoded
As we don't know the shared secret yet - so just set a sensible packet
code and skip the decode.
Nick Porter [Fri, 10 Jan 2025 09:48:39 +0000 (09:48 +0000)]
Bump PostgreSQL version for FreeBSD tests
Nick Porter [Fri, 10 Jan 2025 09:33:03 +0000 (09:33 +0000)]
Pop box from list before manipulation
fr_value_box_strdup re-initialises the box, which clears the list
pointers, meaning list_remove won't work.
Alan T. DeKok [Wed, 8 Jan 2025 20:15:07 +0000 (15:15 -0500)]
update docs for OSX
Alan T. DeKok [Wed, 8 Jan 2025 20:09:11 +0000 (15:09 -0500)]
port from v3.2.x
Alan T. DeKok [Wed, 8 Jan 2025 16:25:10 +0000 (11:25 -0500)]
sort help text
Alan T. DeKok [Sun, 5 Jan 2025 13:59:40 +0000 (08:59 -0500)]
rename to --show-config. Fixes #5442
This avoids conflict with clang's --config option.
We should probably instead have a special "--" option which
signifies "end of jlibtool options.
Arguably jlibtool should have
Nick Porter [Wed, 8 Jan 2025 16:13:02 +0000 (16:13 +0000)]
Add libfreeradius-bio-config.so to Debian packaging
Alan T. DeKok [Wed, 8 Jan 2025 13:58:37 +0000 (08:58 -0500)]
add examples as per Juniper documentation
Alan T. DeKok [Tue, 7 Jan 2025 20:01:56 +0000 (15:01 -0500)]
add write_pause API
so that we can pause / buffer / resume writes for possible
performance improvements
Nick Porter [Wed, 8 Jan 2025 09:54:00 +0000 (09:54 +0000)]
Add test of += operator in LDAP update
Nick Porter [Wed, 8 Jan 2025 09:48:12 +0000 (09:48 +0000)]
Add test of LDAP binary data update
And validation that empty / missing expansions don't produce updates
Nick Porter [Wed, 8 Jan 2025 09:16:21 +0000 (09:16 +0000)]
Skip LDAP updates when tmpl produces zero length output
Nick Porter [Wed, 8 Jan 2025 09:11:15 +0000 (09:11 +0000)]
Skip LDAP updates when tmpl produces no boxes
Nick Porter [Tue, 7 Jan 2025 15:16:50 +0000 (15:16 +0000)]
LDAPMod arrays can be dynamically created
Removing the arbitrary limit
Nick Porter [Tue, 7 Jan 2025 15:12:43 +0000 (15:12 +0000)]
Update LDAP accounting / send module calls in tests
These now need to be ldap.accounting.<acct status type> or
ldap.send.<packet type>
Nick Porter [Tue, 7 Jan 2025 15:03:36 +0000 (15:03 +0000)]
Amend LDAP test config to match new update section layout
Nick Porter [Tue, 7 Jan 2025 14:47:39 +0000 (14:47 +0000)]
Use call_env
Nick Porter [Tue, 7 Jan 2025 14:42:16 +0000 (14:42 +0000)]
Use call_env
Nick Porter [Tue, 7 Jan 2025 14:29:40 +0000 (14:29 +0000)]
Update sample LDAP module config with new structure
Nick Porter [Tue, 7 Jan 2025 14:28:10 +0000 (14:28 +0000)]
Remove old LDAP accounting section handling
Nick Porter [Tue, 7 Jan 2025 14:19:32 +0000 (14:19 +0000)]
Use call_env to populate LDAP modification maps
Nick Porter [Tue, 7 Jan 2025 14:06:40 +0000 (14:06 +0000)]
Add return values to doxygen comments
Nick Porter [Tue, 7 Jan 2025 13:30:22 +0000 (13:30 +0000)]
LDAP modifies do have a result which can be checked for errors
Nick Porter [Mon, 6 Jan 2025 19:57:00 +0000 (19:57 +0000)]
Add call_env parsing of LDAP mods
Mods are parsed from
<name 1> {
<name 2> {
update {
...
}
}
}
Nick Porter [Mon, 6 Jan 2025 12:08:22 +0000 (12:08 +0000)]
Comment corrections
Nick Porter [Mon, 6 Jan 2025 11:50:06 +0000 (11:50 +0000)]
Better error reporting for missing queries
Nick Porter [Mon, 6 Jan 2025 10:31:18 +0000 (10:31 +0000)]
Correct comment
Alan T. DeKok [Mon, 6 Jan 2025 23:44:47 +0000 (18:44 -0500)]
add callback to parse protocol-specific data types
Alan T. DeKok [Mon, 30 Dec 2024 16:12:53 +0000 (11:12 -0500)]
unify error path
James Jones [Mon, 6 Jan 2025 16:30:01 +0000 (10:30 -0600)]
Move to a single Python script that implements dd (#5444)
This will pro9bably be the schema for any future commands added to
gdb and lldb.
James Jones [Mon, 6 Jan 2025 16:29:38 +0000 (10:29 -0600)]
Don't directly use buffer set in sbuff (CID #
1634622 ) (#5460)
Another case of an uninitialized local buffer used in an sbuff but
referenced by name to print out. Coverity complains about it, not
recognizing the the sbuff operation puts a value there. Referencing
the start of the sbuff gets the same effect without complaint.
James Jones [Wed, 2 Oct 2024 18:28:45 +0000 (13:28 -0500)]
adoc typo
James Jones [Thu, 3 Oct 2024 12:28:41 +0000 (07:28 -0500)]
Another typo
github-actions[bot] [Sun, 5 Jan 2025 09:35:07 +0000 (09:35 +0000)]
Scheduled fuzzing: Update src/tests/fuzzer-corpus/dhcpv6.tar
github-actions[bot] [Sun, 5 Jan 2025 09:35:01 +0000 (09:35 +0000)]
Scheduled fuzzing: Update src/tests/fuzzer-corpus/radius.tar
github-actions[bot] [Sun, 5 Jan 2025 09:34:44 +0000 (09:34 +0000)]
Scheduled fuzzing: Update src/tests/fuzzer-corpus/tacacs.tar
github-actions[bot] [Sun, 5 Jan 2025 09:34:40 +0000 (09:34 +0000)]
Scheduled fuzzing: Update src/tests/fuzzer-corpus/dns.tar
github-actions[bot] [Sun, 5 Jan 2025 09:34:35 +0000 (09:34 +0000)]
Scheduled fuzzing: Update src/tests/fuzzer-corpus/dhcpv4.tar
github-actions[bot] [Sun, 5 Jan 2025 09:34:25 +0000 (09:34 +0000)]
Scheduled fuzzing: Update src/tests/fuzzer-corpus/bfd.tar
github-actions[bot] [Sun, 5 Jan 2025 09:34:22 +0000 (09:34 +0000)]
Scheduled fuzzing: Update src/tests/fuzzer-corpus/util.tar
github-actions[bot] [Sun, 5 Jan 2025 09:34:19 +0000 (09:34 +0000)]
Scheduled fuzzing: Update src/tests/fuzzer-corpus/tftp.tar
github-actions[bot] [Sun, 5 Jan 2025 09:34:16 +0000 (09:34 +0000)]
Scheduled fuzzing: Update src/tests/fuzzer-corpus/vmps.tar
Nick Porter [Fri, 3 Jan 2025 18:15:35 +0000 (18:15 +0000)]
Rework extraction of pairs from Subject Alternate Name
Some valid certificates have been seen where X509_get_ext_by_NID() fails
to find the SAN extension even though it is present.
The extension is then found when walking the list of extensions.
Nick Porter [Thu, 2 Jan 2025 19:23:33 +0000 (19:23 +0000)]
Attempt to parse unknown extensions when extracting