]> git.ipfire.org Git - thirdparty/freeradius-server.git/log
thirdparty/freeradius-server.git
7 years agodoc: The title should be '=' 2811/head
Jorge Pereira [Fri, 26 Jul 2019 00:53:18 +0000 (21:53 -0300)] 
doc: The title should be '='

7 years agoMerge pull request #2806 from jpereira/v4/doc6
Alan DeKok [Fri, 26 Jul 2019 14:51:29 +0000 (10:51 -0400)] 
Merge pull request #2806 from jpereira/v4/doc6

doc/all.mk: Fix the wildcard to get all *.md

7 years agodoc/all.mk: Create a soft-link between README.html -> index.html 2806/head
Jorge Pereira [Wed, 24 Jul 2019 22:33:43 +0000 (19:33 -0300)] 
doc/all.mk: Create a soft-link between README.html -> index.html

7 years agodoc/all.mk: Fix the wildcard to get all *.md
Jorge Pereira [Tue, 23 Jul 2019 23:43:07 +0000 (20:43 -0300)] 
doc/all.mk: Fix the wildcard to get all *.md

7 years agoTypo (#2808)
Terry Burton [Fri, 26 Jul 2019 09:46:41 +0000 (10:46 +0100)] 
Typo (#2808)

7 years agomake TLS 1.2 the minimum supported version.
Alan T. DeKok [Thu, 25 Jul 2019 22:22:13 +0000 (18:22 -0400)] 
make TLS 1.2 the minimum supported version.

As per https://tools.ietf.org/html/draft-ietf-tls-oldversions-deprecate-05

7 years agocopy over blank Message-Authenticator if necessary
Alan T. DeKok [Thu, 25 Jul 2019 22:15:01 +0000 (18:15 -0400)] 
copy over blank Message-Authenticator if necessary

7 years agolots more documentation for "update" statements
Alan T. DeKok [Thu, 25 Jul 2019 13:00:00 +0000 (09:00 -0400)] 
lots more documentation for "update" statements

7 years agoadd place-holders for documentation we don't yet have
Alan T. DeKok [Thu, 25 Jul 2019 12:59:41 +0000 (08:59 -0400)] 
add place-holders for documentation we don't yet have

7 years agodelete Proxy-State before adding VPs to the reply
Alan T. DeKok [Wed, 24 Jul 2019 18:35:36 +0000 (14:35 -0400)] 
delete Proxy-State before adding VPs to the reply

so our reply doesn't have the wrong Proxy-State attributes

7 years agoAdd RHEXDUMP[1-4] and RHEXDUMP_INLINE[1-4]
Arran Cudbard-Bell [Thu, 25 Jul 2019 05:06:19 +0000 (14:06 +0900)] 
Add RHEXDUMP[1-4] and RHEXDUMP_INLINE[1-4]

7 years agohandle Access-Challenge responses
Alan T. DeKok [Wed, 24 Jul 2019 11:18:50 +0000 (07:18 -0400)] 
handle Access-Challenge responses

only if the parent request is RADIUS, and the parent packet type
is Access-Request

7 years agoadd map documentation
Alan T. DeKok [Wed, 24 Jul 2019 00:21:02 +0000 (20:21 -0400)] 
add map documentation

7 years agoword smithing
Alan T. DeKok [Tue, 23 Jul 2019 23:57:07 +0000 (19:57 -0400)] 
word smithing

7 years agopoint to correct location
Alan T. DeKok [Tue, 23 Jul 2019 20:33:59 +0000 (16:33 -0400)] 
point to correct location

7 years agoMerge pull request #2804 from jpereira/v4/doc4
Alan DeKok [Tue, 23 Jul 2019 20:32:31 +0000 (16:32 -0400)] 
Merge pull request #2804 from jpereira/v4/doc4

Doc updates

7 years agoraddb/radiusd.conf.in: Fix asciidoctor error 2804/head
Jorge Pereira [Tue, 23 Jul 2019 19:53:02 +0000 (16:53 -0300)] 
raddb/radiusd.conf.in: Fix asciidoctor error

7 years agodoc: Fix links from README to README.md
Jorge Pereira [Tue, 23 Jul 2019 18:41:31 +0000 (15:41 -0300)] 
doc: Fix links from README to README.md

7 years agodoc/all.mk: Let's process all *.md
Jorge Pereira [Tue, 23 Jul 2019 18:40:38 +0000 (15:40 -0300)] 
doc/all.mk: Let's process all *.md

7 years agoMerge pull request #2802 from jpereira/v4/doc3
Alan DeKok [Tue, 23 Jul 2019 18:28:23 +0000 (14:28 -0400)] 
Merge pull request #2802 from jpereira/v4/doc3

Doc updates

7 years agoraddb/sites-available: Fix asciidoc warn/errors 2802/head
Jorge Pereira [Tue, 23 Jul 2019 00:08:18 +0000 (21:08 -0300)] 
raddb/sites-available: Fix asciidoc warn/errors

7 years agoraddb/mods-available: Fix asciidoc warn/errors
Jorge Pereira [Tue, 23 Jul 2019 00:07:48 +0000 (21:07 -0300)] 
raddb/mods-available: Fix asciidoc warn/errors

7 years agoadd dockerfiles for Debian 10
Matthew Newton [Tue, 23 Jul 2019 15:18:56 +0000 (16:18 +0100)] 
add dockerfiles for Debian 10

7 years agodoc/unlang/: Fix asciidoc warn/errors
Jorge Pereira [Tue, 23 Jul 2019 02:09:56 +0000 (23:09 -0300)] 
doc/unlang/: Fix asciidoc warn/errors

7 years agodoc: Set ':toc:' over CLI
Jorge Pereira [Tue, 23 Jul 2019 02:25:16 +0000 (23:25 -0300)] 
doc: Set ':toc:' over CLI

7 years agoadd / use "map->child"
Alan T. DeKok [Tue, 23 Jul 2019 14:42:01 +0000 (10:42 -0400)] 
add / use "map->child"

7 years agoRevert "define and allow for TMPL_TYPE_MAP"
Alan T. DeKok [Tue, 23 Jul 2019 14:25:04 +0000 (10:25 -0400)] 
Revert "define and allow for TMPL_TYPE_MAP"

This reverts commit 723d5ecd77ca252829e073964f3d8e492eb20250.

7 years agoadd "disallow_qualifiers" to parsing rules
Alan T. DeKok [Tue, 23 Jul 2019 13:54:37 +0000 (09:54 -0400)] 
add "disallow_qualifiers" to parsing rules

so that we can have groups where the inner attributes aren't
allowed to specify destination lists.  Because these attributes
are grouped, they MUST be placed into the parent group.

7 years agorename to something we can remember
Alan T. DeKok [Tue, 23 Jul 2019 13:46:52 +0000 (09:46 -0400)] 
rename to something we can remember

7 years agoadd documentation for keyed load-balance
Alan T. DeKok [Tue, 23 Jul 2019 12:54:17 +0000 (08:54 -0400)] 
add documentation for keyed load-balance

7 years agoMerge pull request #2795 from jpereira/v4/fix-xlat_explode
Alan DeKok [Tue, 23 Jul 2019 14:43:47 +0000 (10:43 -0400)] 
Merge pull request #2795 from jpereira/v4/fix-xlat_explode

Fix the %{explode:&ref <delim>} xlat function

7 years agoMerge pull request #2789 from jpereira/v4/checks1
Alan DeKok [Tue, 23 Jul 2019 14:43:31 +0000 (10:43 -0400)] 
Merge pull request #2789 from jpereira/v4/checks1

src/lib/server/cf_util.c: Check if 'CONF_ITEM' is valid

7 years agofix data types. Fixes #2803
Alan T. DeKok [Tue, 23 Jul 2019 12:40:25 +0000 (08:40 -0400)] 
fix data types.  Fixes #2803

7 years agoword smithing
Alan T. DeKok [Tue, 23 Jul 2019 02:10:09 +0000 (22:10 -0400)] 
word smithing

7 years agoCleanup LD_PRELOAD handles properly
Arran Cudbard-Bell [Tue, 23 Jul 2019 02:34:20 +0000 (11:34 +0900)] 
Cleanup LD_PRELOAD handles properly

7 years agoRevert "quiet compiler for now"
Arran Cudbard-Bell [Tue, 23 Jul 2019 01:47:12 +0000 (10:47 +0900)] 
Revert "quiet compiler for now"

Not sure why this was removed, but it is necessary to dlclose any opened handles to prevent msan producing lots of spurious output on exit, which isn't fun for anyone.

I'm sure there's a better solution.

7 years agoRemove "tainted" macros
Arran Cudbard-Bell [Tue, 23 Jul 2019 01:42:24 +0000 (10:42 +0900)] 
Remove "tainted" macros

It's not clear what type is being "tainted" here, and we are not adding tainted variants for every single static initialiser.

7 years agoMerge pull request #2801 from jpereira/v4/doc3
Alan DeKok [Mon, 22 Jul 2019 19:56:59 +0000 (15:56 -0400)] 
Merge pull request #2801 from jpereira/v4/doc3

doc/all.mk: Be able to disable/enable verbose output

7 years agodoc/all.mk: Be able to disable/enable verbose output 2801/head
Jorge Pereira [Mon, 22 Jul 2019 19:49:54 +0000 (16:49 -0300)] 
doc/all.mk: Be able to disable/enable verbose output

7 years agoMerge pull request #2800 from jpereira/v4/doc2
Alan DeKok [Mon, 22 Jul 2019 19:01:03 +0000 (15:01 -0400)] 
Merge pull request #2800 from jpereira/v4/doc2

xlat_predefined: Add missing %{sha...} and %{blake...}

7 years agouse correct logic for tests
Alan T. DeKok [Mon, 22 Jul 2019 19:00:40 +0000 (15:00 -0400)] 
use correct logic for tests

7 years agonotes for the future
Alan T. DeKok [Mon, 22 Jul 2019 19:00:28 +0000 (15:00 -0400)] 
notes for the future

7 years agoxlat_predefined: Add missing %{sha...} and %{blake...} 2800/head
Jorge Pereira [Mon, 22 Jul 2019 17:40:09 +0000 (14:40 -0300)] 
xlat_predefined: Add missing %{sha...} and %{blake...}

7 years agotighten parsing rules
Alan T. DeKok [Mon, 22 Jul 2019 17:27:06 +0000 (13:27 -0400)] 
tighten parsing rules

sub-groups with operators are only allowed in "update" sections,
and not in "map" sections

7 years agohacks to allow operators inside of grouped sections
Alan T. DeKok [Mon, 22 Jul 2019 17:11:04 +0000 (13:11 -0400)] 
hacks to allow operators inside of grouped sections

we should really switch the parser to using a local parse struct
like templates

7 years agosimpler method of skipping strings
Alan T. DeKok [Mon, 22 Jul 2019 17:00:05 +0000 (13:00 -0400)] 
simpler method of skipping strings

7 years agoparse sub-maps
Alan T. DeKok [Mon, 22 Jul 2019 16:21:51 +0000 (12:21 -0400)] 
parse sub-maps

7 years agoword smithing and updates
Alan T. DeKok [Mon, 22 Jul 2019 16:18:45 +0000 (12:18 -0400)] 
word smithing and updates

7 years agodefine and allow for TMPL_TYPE_MAP
Alan T. DeKok [Mon, 22 Jul 2019 15:53:05 +0000 (11:53 -0400)] 
define and allow for TMPL_TYPE_MAP

in preparation for allowing grouped attributes.

7 years agoallow "foo = { ...}" in parser
Alan T. DeKok [Mon, 22 Jul 2019 13:01:41 +0000 (09:01 -0400)] 
allow "foo = { ...}" in parser

in preparation for allowing grouped attributes

7 years agoremove support for LM-Password. Fixes #2799
Alan T. DeKok [Sun, 21 Jul 2019 11:59:15 +0000 (07:59 -0400)] 
remove support for LM-Password.  Fixes #2799

No one has used this in years, and it isn't secure.

7 years agoinclude more adoc files
Alan T. DeKok [Sat, 20 Jul 2019 11:53:47 +0000 (07:53 -0400)] 
include more adoc files

7 years agocleanups and add toc
Alan T. DeKok [Sat, 20 Jul 2019 11:44:40 +0000 (07:44 -0400)] 
cleanups and add toc

7 years agominor cleanups
Alan T. DeKok [Sat, 20 Jul 2019 11:09:42 +0000 (07:09 -0400)] 
minor cleanups

* the footer doesn't need a "home" link.
* move the ToC to the left sidebar, which makes the real content
  more prominent
* move the "home" link to the top right of the page, where it
  is less visible, but is still useful

7 years agocomment out post-proxy
Alan T. DeKok [Fri, 19 Jul 2019 16:50:07 +0000 (12:50 -0400)] 
comment out post-proxy

it's not used in v4.  But we still may want the code for reference

7 years agoremove bounds checks for small integers
Alan T. DeKok [Fri, 19 Jul 2019 16:47:40 +0000 (12:47 -0400)] 
remove bounds checks for small integers

we can always represent 8 / 16 / 32-bit integers in a Lua integer

7 years agocheck for dv. CID #1445245
Alan T. DeKok [Fri, 19 Jul 2019 16:45:13 +0000 (12:45 -0400)] 
check for dv.  CID #1445245

7 years agoMerge pull request #2798 from jpereira/v4/doc1
Alan DeKok [Sat, 20 Jul 2019 10:56:23 +0000 (06:56 -0400)] 
Merge pull request #2798 from jpereira/v4/doc1

Some doc updates

7 years agoman: Remove deprecated %{base64tohex:} 2798/head
Jorge Pereira [Sat, 20 Jul 2019 00:25:51 +0000 (21:25 -0300)] 
man: Remove deprecated %{base64tohex:}

7 years agodoc: Update doc/unlang/xlat_predefined
Jorge Pereira [Sat, 20 Jul 2019 00:25:09 +0000 (21:25 -0300)] 
doc: Update doc/unlang/xlat_predefined

7 years agodoc: Add :toc:
Jorge Pereira [Sat, 20 Jul 2019 00:24:36 +0000 (21:24 -0300)] 
doc: Add :toc:

7 years agodoc: Unlang - Some fixes, added header to home
Jorge Pereira [Sat, 13 Jul 2019 01:21:04 +0000 (22:21 -0300)] 
doc: Unlang - Some fixes, added header to home

7 years agodoc: Add .gitignore
Jorge Pereira [Sat, 13 Jul 2019 01:20:23 +0000 (22:20 -0300)] 
doc: Add .gitignore

7 years agodoc: Add 'index' for howto folder
Jorge Pereira [Sat, 13 Jul 2019 01:19:58 +0000 (22:19 -0300)] 
doc: Add 'index' for howto folder

7 years agodoc: Add 'header' include
Jorge Pereira [Sat, 13 Jul 2019 01:19:30 +0000 (22:19 -0300)] 
doc: Add 'header' include

7 years agodoc: Add link for the CC license
Jorge Pereira [Sat, 13 Jul 2019 01:17:32 +0000 (22:17 -0300)] 
doc: Add link for the CC license

7 years agoFix the %{explode:&ref <delim>} xlat function 2795/head
Jorge Pereira [Fri, 19 Jul 2019 02:17:05 +0000 (23:17 -0300)] 
Fix the %{explode:&ref <delim>} xlat function

As the documentation says %{explode:&ref <delim>}, let's inform
the user that the delim should be a single char

7 years agoBetter way of passing in arguments to CHECK_ZEROED
Jorge Pereira [Sat, 20 Jul 2019 01:35:23 +0000 (22:35 -0300)] 
Better way of passing in arguments to CHECK_ZEROED

7 years agoPass in _vpt
Arran Cudbard-Bell [Fri, 19 Jul 2019 23:53:06 +0000 (08:53 +0900)] 
Pass in _vpt

7 years agoMerge pull request #2796 from jpereira/v4/leak2
Alan DeKok [Fri, 19 Jul 2019 18:08:57 +0000 (14:08 -0400)] 
Merge pull request #2796 from jpereira/v4/leak2

xlat: Fix minor leak in %{explode:}

7 years agosrc/lib/server/cf_util.c: Check if 'CONF_ITEM' is valid 2789/head
Jorge Pereira [Thu, 18 Jul 2019 14:23:47 +0000 (11:23 -0300)] 
src/lib/server/cf_util.c: Check if 'CONF_ITEM' is valid

7 years agoxlat: Fix minor leak in %{explode:} 2796/head
Jorge Pereira [Fri, 19 Jul 2019 17:29:17 +0000 (14:29 -0300)] 
xlat: Fix minor leak in %{explode:}

7 years agocheck return code. CID #1445239
Alan T. DeKok [Fri, 19 Jul 2019 14:03:23 +0000 (10:03 -0400)] 
check return code.  CID #1445239

7 years agoremove dead code. CID #1445235
Alan T. DeKok [Fri, 19 Jul 2019 14:02:34 +0000 (10:02 -0400)] 
remove dead code.  CID #1445235

7 years agocheck return code. CID #1445247
Alan T. DeKok [Fri, 19 Jul 2019 13:59:30 +0000 (09:59 -0400)] 
check return code.  CID #1445247

7 years agodisable setting of -soname on Linux
Alan T. DeKok [Fri, 19 Jul 2019 13:58:10 +0000 (09:58 -0400)] 
disable setting of -soname on Linux

it appears to break the build.

7 years agorequest is always non-NULL. CID #1445231
Alan T. DeKok [Fri, 19 Jul 2019 13:53:26 +0000 (09:53 -0400)] 
request is always non-NULL.  CID #1445231

7 years agoignore the return code. We can't do anything about it. CID #1445218
Alan T. DeKok [Fri, 19 Jul 2019 13:51:41 +0000 (09:51 -0400)] 
ignore the return code.  We can't do anything about it.  CID #1445218

7 years agolock on more error paths. CID #1445200
Alan T. DeKok [Fri, 19 Jul 2019 13:49:57 +0000 (09:49 -0400)] 
lock on more error paths.  CID #1445200

7 years agocheck return code. CID #1445234
Alan T. DeKok [Fri, 19 Jul 2019 13:41:25 +0000 (09:41 -0400)] 
check return code.  CID #1445234

7 years agowe don't care about the return value here. CID #1445232
Alan T. DeKok [Fri, 19 Jul 2019 13:40:21 +0000 (09:40 -0400)] 
we don't care about the return value here.  CID #1445232

7 years agouse the install path, too
Alan T. DeKok [Fri, 19 Jul 2019 13:29:53 +0000 (09:29 -0400)] 
use the install path, too

7 years agodisable soname on Linux until we do more testing
Alan T. DeKok [Fri, 19 Jul 2019 13:12:31 +0000 (09:12 -0400)] 
disable soname on Linux until we do more testing

7 years agoadd version information to shared libraries. Helps with #1774
Alan T. DeKok [Fri, 19 Jul 2019 12:01:30 +0000 (08:01 -0400)] 
add version information to shared libraries. Helps with #1774

7 years agoadd -soname on non-apple systems. Helps with #1774
Alan T. DeKok [Fri, 19 Jul 2019 11:50:48 +0000 (07:50 -0400)] 
add -soname on non-apple systems.  Helps with #1774

7 years agoquiet compiler for now
Alan T. DeKok [Fri, 19 Jul 2019 10:58:11 +0000 (06:58 -0400)] 
quiet compiler for now

We don't care much about leaking dl handles on exit.

7 years agocheck for oom. CID #1445646
Alan T. DeKok [Fri, 19 Jul 2019 01:14:06 +0000 (21:14 -0400)] 
check for oom.  CID #1445646

7 years agoremember the libraries we dlopen'd. CID #1445213
Alan T. DeKok [Fri, 19 Jul 2019 01:10:48 +0000 (21:10 -0400)] 
remember the libraries we dlopen'd.  CID #1445213

7 years agouse vpt->data as the start. CID #1448186
Alan T. DeKok [Fri, 19 Jul 2019 01:06:09 +0000 (21:06 -0400)] 
use vpt->data as the start.  CID #1448186

because we're using sizeof(vpt->data) elsewhere

7 years agocheck return code. CID #1445244
Alan T. DeKok [Fri, 19 Jul 2019 01:02:53 +0000 (21:02 -0400)] 
check return code.  CID #1445244

7 years agocopy trailing zero. CID #1448184
Alan T. DeKok [Fri, 19 Jul 2019 01:01:04 +0000 (21:01 -0400)] 
copy trailing zero.  CID #1448184

7 years agocheck for memory allocation. CID #1448180
Alan T. DeKok [Fri, 19 Jul 2019 00:59:17 +0000 (20:59 -0400)] 
check for memory allocation.  CID #1448180

7 years agoreturn on first found library. CID #1445213
Alan T. DeKok [Thu, 18 Jul 2019 18:19:30 +0000 (14:19 -0400)] 
return on first found library.  CID #1445213

7 years agojust box a normal string, not a tainted one.
Alan T. DeKok [Thu, 18 Jul 2019 16:47:31 +0000 (12:47 -0400)] 
just box a normal string, not a tainted one.

the previous commit fixes the printing routine to always escape
strings when they're being printed.

When tokenizing xlat strings, we presume (for now) that the input
is always safe.  i.e. we don't allow %{%{User-Name}}.

If we do need to allow xlat parsing from tainted sources, then the
entire xlat API needs to be updated to mark the input with a
tainted flag

7 years agoRevert "Respect the taint value of boxes being fed to logging functions"
Alan T. DeKok [Thu, 18 Jul 2019 16:42:22 +0000 (12:42 -0400)] 
Revert "Respect the taint value of boxes being fed to logging functions"

This reverts commit 012865619f8001b0903fa129ac44cff22e91fadd.

tainting and escaping are independent things.  A tainted string
should still be escapted for \n and \t.

And for printing, we don't really care much about the taint flag.

* Code printing things to strings still needs \n and \r to be
  escaped.
* Code copying value_boxes should use the value box copy functions,
  which respects the taintng flag

7 years agoremove unnecessary "if"
Alan T. DeKok [Thu, 18 Jul 2019 16:31:08 +0000 (12:31 -0400)] 
remove unnecessary "if"

7 years agoMerge pull request #2793 from jpereira/v4/fix-rlmcsv2
Alan DeKok [Thu, 18 Jul 2019 14:20:28 +0000 (10:20 -0400)] 
Merge pull request #2793 from jpereira/v4/fix-rlmcsv2

rlm_csv: Fix 'map csv {}' test

7 years agoMerge pull request #2790 from jpereira/v4/fix-vbox
Alan DeKok [Thu, 18 Jul 2019 14:19:57 +0000 (10:19 -0400)] 
Merge pull request #2790 from jpereira/v4/fix-vbox

Add fr_box_tainted()/fr_box_tainted_len() to respect taint values

7 years agoAdd fr_box_tainted()/fr_box_tainted_len() to respect taint values 2790/head
Jorge Pereira [Wed, 17 Jul 2019 17:56:40 +0000 (14:56 -0300)] 
Add fr_box_tainted()/fr_box_tainted_len() to respect taint values

The new both macros have an extra field to set the "taint" state.

7 years agorlm_csv: Fix 'map csv {}' test 2793/head
Jorge Pereira [Wed, 17 Jul 2019 20:39:19 +0000 (17:39 -0300)] 
rlm_csv: Fix 'map csv {}' test

As described in the csv_map_verify() in rlm_csv.c

"Left hand side of map must be an attribute or list"