]> git.ipfire.org Git - thirdparty/freeradius-server.git/log
thirdparty/freeradius-server.git
7 years agomore remove HAVE_PTHREAD_H
Alan T. DeKok [Thu, 18 Oct 2018 16:21:10 +0000 (12:21 -0400)] 
more remove HAVE_PTHREAD_H

7 years agoremove HAVE_PTHREAD_H
Alan T. DeKok [Thu, 18 Oct 2018 16:19:25 +0000 (12:19 -0400)] 
remove HAVE_PTHREAD_H

7 years agomore remove HAVE_PTHREAD_H
Alan T. DeKok [Thu, 18 Oct 2018 16:17:58 +0000 (12:17 -0400)] 
more remove HAVE_PTHREAD_H

7 years agorely on rbtree mutexes, instead of hand-rolling them
Alan T. DeKok [Thu, 18 Oct 2018 14:03:41 +0000 (10:03 -0400)] 
rely on rbtree mutexes, instead of hand-rolling them

7 years agomore pthread fixes
Alan T. DeKok [Thu, 18 Oct 2018 13:33:36 +0000 (09:33 -0400)] 
more pthread fixes

7 years agowe always have pthread here, too
Alan T. DeKok [Thu, 18 Oct 2018 13:31:41 +0000 (09:31 -0400)] 
we always have pthread here, too

7 years agowe always have pthreads
Alan T. DeKok [Thu, 18 Oct 2018 13:30:18 +0000 (09:30 -0400)] 
we always have pthreads

7 years agoMerge pull request #2332 from z-eos/master
Arran Cudbard-Bell [Wed, 17 Oct 2018 18:56:20 +0000 (14:56 -0400)] 
Merge pull request #2332 from z-eos/master

Add files via upload

7 years agorelay on the top-level Makefile to build radsniff
Alan T. DeKok [Wed, 17 Oct 2018 18:06:07 +0000 (14:06 -0400)] 
relay on the top-level Makefile to build radsniff

we don't need to regenerate radsniff.mk

7 years agoRevert "this shouldn't be in git"
Alan T. DeKok [Wed, 17 Oct 2018 18:04:02 +0000 (14:04 -0400)] 
Revert "this shouldn't be in git"

This reverts commit 759cab975259bfb3c0d407742d0414c0c762a50c.

7 years agoStupid OpenSSL compatibility fixes
Arran Cudbard-Bell [Wed, 17 Oct 2018 17:59:36 +0000 (13:59 -0400)] 
Stupid OpenSSL compatibility fixes

7 years agothis shouldn't be in git
Alan T. DeKok [Wed, 17 Oct 2018 17:53:04 +0000 (13:53 -0400)] 
this shouldn't be in git

7 years agoOpenSSL can die in a fire.
Alan T. DeKok [Wed, 17 Oct 2018 17:51:39 +0000 (13:51 -0400)] 
OpenSSL can die in a fire.

They deprecated one API.  And then added another one, which does
the same thing, but has a different name.

7 years agoRevert "add transitive linking for pre-requisite libraries"
Alan T. DeKok [Wed, 17 Oct 2018 17:30:26 +0000 (13:30 -0400)] 
Revert "add transitive linking for pre-requisite libraries"

This reverts commit 20d9dd6aae81569b07a83dc3b9ecd0e764a69773.

7 years agoRevert "link only to the server library"
Alan T. DeKok [Wed, 17 Oct 2018 17:30:25 +0000 (13:30 -0400)] 
Revert "link only to the server library"

This reverts commit 5545374b06d2ef86271d882508abfa8e5c9133f1.

7 years agoevert "simplify linking"
Alan T. DeKok [Wed, 17 Oct 2018 17:30:22 +0000 (13:30 -0400)] 
evert "simplify linking"

This reverts commit f38c372bbe3302246ec94565f01c31c677f90c49.

7 years agoRevert "simplify linking here, too"
Alan T. DeKok [Wed, 17 Oct 2018 17:30:15 +0000 (13:30 -0400)] 
Revert "simplify linking here, too"

This reverts commit 5abf2974fd04b62ee2dc94702f0dbab4481c07ae.

7 years agosimplify linking here, too
Alan T. DeKok [Wed, 17 Oct 2018 17:20:00 +0000 (13:20 -0400)] 
simplify linking here, too

7 years agosimplify linking
Alan T. DeKok [Wed, 17 Oct 2018 16:55:34 +0000 (12:55 -0400)] 
simplify linking

7 years agolink only to the server library
Alan T. DeKok [Wed, 17 Oct 2018 16:52:39 +0000 (12:52 -0400)] 
link only to the server library

which in turn links to libfreeradius-util

7 years agoadd transitive linking for pre-requisite libraries
Alan T. DeKok [Wed, 17 Oct 2018 16:30:55 +0000 (12:30 -0400)] 
add transitive linking for pre-requisite libraries

so that if we have:

radiusd -> server.a - > util.a

we don't need to link radiusd explicitly against util.a

For this step, we just add massive amounts of things to the
compiler flags.  The next step is to start pruning the build
system of libraries

7 years agoInitialise options
Arran Cudbard-Bell [Wed, 17 Oct 2018 16:50:55 +0000 (12:50 -0400)] 
Initialise options

7 years agoAdd support for PCRE2_COPY_MATCHED_SUBJECT
Arran Cudbard-Bell [Wed, 17 Oct 2018 14:07:33 +0000 (10:07 -0400)] 
Add support for PCRE2_COPY_MATCHED_SUBJECT

As per ticket here: https://bugs.exim.org/show_bug.cgi?id=2323

7 years agoclang scan nonsense
Alan T. DeKok [Wed, 17 Oct 2018 14:06:43 +0000 (10:06 -0400)] 
clang scan nonsense

7 years agoAdd files via upload 2332/head
Zeus Panchenko [Wed, 17 Oct 2018 10:58:23 +0000 (13:58 +0300)] 
Add files via upload

attributes added, minor fix of objectClass

7 years agoAdd files via upload
Zeus Panchenko [Wed, 17 Oct 2018 09:59:53 +0000 (12:59 +0300)] 
Add files via upload

duplicates are removed

7 years agodisallow struct[n]
Alan T. DeKok [Tue, 16 Oct 2018 19:13:41 +0000 (15:13 -0400)] 
disallow struct[n]

which means that we don't really care about the size of the
structs.

On encoding, if we run out of room, we just truncat the data
as with every other data type.

On decoding, if there's too little data, we just return what
data we can find.  If there's too much data, we just ignore
the extra bits.

7 years agotry to quiet analyzer
Alan T. DeKok [Tue, 16 Oct 2018 18:02:04 +0000 (14:02 -0400)] 
try to quiet analyzer

7 years agoassertion for static analyzer
Alan T. DeKok [Tue, 16 Oct 2018 17:32:33 +0000 (13:32 -0400)] 
assertion for static analyzer

7 years agofix static analysis warning
Alan T. DeKok [Tue, 16 Oct 2018 17:31:51 +0000 (13:31 -0400)] 
fix static analysis warning

7 years agoclean up process_authenticate
Alan T. DeKok [Tue, 16 Oct 2018 17:29:16 +0000 (13:29 -0400)] 
clean up process_authenticate

in order to get rid of old attribute names

7 years agoremove more unused code
Alan T. DeKok [Tue, 16 Oct 2018 17:04:03 +0000 (13:04 -0400)] 
remove more unused code

7 years agowe don't need Post-Auth-Type any more
Alan T. DeKok [Tue, 16 Oct 2018 16:59:49 +0000 (12:59 -0400)] 
we don't need Post-Auth-Type any more

the reply code has already been set by the time we're running
this module.

7 years agosimplify the code now that the old code is gone
Alan T. DeKok [Tue, 16 Oct 2018 16:57:31 +0000 (12:57 -0400)] 
simplify the code now that the old code is gone

7 years agoremove rad_postauth
Alan T. DeKok [Tue, 16 Oct 2018 16:54:07 +0000 (12:54 -0400)] 
remove rad_postauth

7 years agoremove old rad_authenticate code
Alan T. DeKok [Tue, 16 Oct 2018 16:42:22 +0000 (12:42 -0400)] 
remove old rad_authenticate code

7 years agoremove Autz-Type and Autz-Type redo
Alan T. DeKok [Tue, 16 Oct 2018 16:25:40 +0000 (12:25 -0400)] 
remove Autz-Type and Autz-Type redo

It's no longer used

7 years agoremove Connect-Rate comparison registration
Alan T. DeKok [Tue, 16 Oct 2018 14:33:45 +0000 (10:33 -0400)] 
remove Connect-Rate comparison registration

It was wrong and unused.

7 years agoinput is request list, not the attribute we need to compare
Alan T. DeKok [Tue, 16 Oct 2018 14:32:38 +0000 (10:32 -0400)] 
input is request list, not the attribute we need to compare

7 years agoinout is request list, not one attribute
Alan T. DeKok [Tue, 16 Oct 2018 14:20:23 +0000 (10:20 -0400)] 
inout is request list, not one attribute

so if the User-Name field is not at the start of the packet,
rlm_winbind would do bad things.

7 years agoremove "compare" flag.
Alan T. DeKok [Tue, 16 Oct 2018 13:48:03 +0000 (09:48 -0400)] 
remove "compare" flag.

It was only used in a few places, and in the server.  So the flag
shouldn't be universal across all dictionary attributes.

if the admin defines a comparison for a pre-existing attribute,
well, that's something we can catch via other methods

7 years agotests for struct within tlv within struct
Alan T. DeKok [Mon, 15 Oct 2018 17:59:06 +0000 (13:59 -0400)] 
tests for struct within tlv within struct

we can't do structs within structs right now.. that's also dumb,
as the fields could just be flattened

7 years agocanonicalize dictionaries using new format
Alan T. DeKok [Mon, 15 Oct 2018 15:10:00 +0000 (11:10 -0400)] 
canonicalize dictionaries using new format

to allow ".1" which means "child of previous attribute"

7 years agoadd encode / decode tests for structs
Alan T. DeKok [Mon, 15 Oct 2018 15:00:59 +0000 (11:00 -0400)] 
add encode / decode tests for structs

7 years agoallow partial OIDs in ATTRIBUTE definitions
Alan T. DeKok [Mon, 15 Oct 2018 14:56:31 +0000 (10:56 -0400)] 
allow partial OIDs in ATTRIBUTE definitions

in which case the previous attribute is used as the parent.
This makes the dictionaries MUCH simpler.  e.g.

ATTRIBUTE Unit-Struct1 241.247 struct
ATTRIBUTE Unit-Struct1-Int1 .1 integer
ATTRIBUTE Unit-Struct1-Int2 .2 integer
ATTRIBUTE Unit-Struct1-Short .3 uint16
ATTRIBUTE Unit-Struct1-String .4 string

7 years agoadded dictionary
Alan T. DeKok [Mon, 15 Oct 2018 13:15:49 +0000 (09:15 -0400)] 
added dictionary

7 years agoreturn rcode <sigh>
Alan T. DeKok [Sun, 14 Oct 2018 13:22:57 +0000 (09:22 -0400)] 
return rcode <sigh>

WiMAX has "continued" attributes, which means that the decoder
needs to decode *more* data than exists in the current attribute

7 years agoadd PROJECT_NAME to includedir path. Fixes #2331
Alan T. DeKok [Sun, 14 Oct 2018 12:56:34 +0000 (08:56 -0400)] 
add PROJECT_NAME to includedir path.  Fixes #2331

7 years agodecode fields from struct
Alan T. DeKok [Fri, 12 Oct 2018 19:53:20 +0000 (15:53 -0400)] 
decode fields from struct

7 years agoMerge pull request #2330 from z-eos/master
Arran Cudbard-Bell [Fri, 12 Oct 2018 21:31:10 +0000 (17:31 -0400)] 
Merge pull request #2330 from z-eos/master

[proposal] to add LDAP freeradius-radaact.schema

7 years agoAdd files via upload 2330/head
Zeus Panchenko [Fri, 12 Oct 2018 21:27:30 +0000 (00:27 +0300)] 
Add files via upload

7 years agoit's ssize_t
Alan T. DeKok [Fri, 12 Oct 2018 19:28:13 +0000 (15:28 -0400)] 
it's ssize_t

7 years agodecode TLVs after fixed-length structs, too
Alan T. DeKok [Fri, 12 Oct 2018 18:16:17 +0000 (14:16 -0400)] 
decode TLVs after fixed-length structs, too

7 years agoreturn attr_len, not rcode
Alan T. DeKok [Fri, 12 Oct 2018 18:02:53 +0000 (14:02 -0400)] 
return attr_len, not rcode

i.e. even if the called function decodes *less* than the attribute,
we tell the caller that it decoded *all* of the attribute.

This change ensures that if a function partially decodes an attribute,
that the caller will skip *all* of the attribute.  And not start
decoding the next attribute in the middle of the partially decoded
one.

7 years agoencode TLVs as the last field of a struct in RADIUS
Alan T. DeKok [Fri, 12 Oct 2018 14:45:59 +0000 (10:45 -0400)] 
encode TLVs as the last field of a struct in RADIUS

7 years agoclean up the code a bit
Alan T. DeKok [Fri, 12 Oct 2018 14:21:04 +0000 (10:21 -0400)] 
clean up the code a bit

7 years agoclean up the code a bit
Alan T. DeKok [Fri, 12 Oct 2018 13:58:36 +0000 (09:58 -0400)] 
clean up the code a bit

7 years agocreate and export "unknown from network" function
Alan T. DeKok [Fri, 12 Oct 2018 13:51:08 +0000 (09:51 -0400)] 
create and export "unknown from network" function

7 years agouse the correct context for moving output pairs. Fixes #2328
Alan T. DeKok [Thu, 11 Oct 2018 12:31:51 +0000 (08:31 -0400)] 
use the correct context for moving output pairs.  Fixes #2328

7 years agomove encoe struct to common function
Alan T. DeKok [Thu, 11 Oct 2018 19:57:57 +0000 (15:57 -0400)] 
move encoe struct to common function

7 years agoremove tlv_stack from encode_struct
Alan T. DeKok [Thu, 11 Oct 2018 19:53:39 +0000 (15:53 -0400)] 
remove tlv_stack from encode_struct

in preparation for making it a generic function.
After it's a generic function, we can re-add protocol-specific
encoding, with sub-TLVs

7 years agomove struct.[ch] to src/lib/util
Alan T. DeKok [Thu, 11 Oct 2018 19:32:52 +0000 (15:32 -0400)] 
move struct.[ch] to src/lib/util

which is where most things need it to be

7 years agoclean it up to do less work
Alan T. DeKok [Thu, 11 Oct 2018 18:38:21 +0000 (14:38 -0400)] 
clean it up to do less work

7 years agogot to the next VP (but not too far) when encoding structs
Alan T. DeKok [Thu, 11 Oct 2018 18:21:56 +0000 (14:21 -0400)] 
got to the next VP (but not too far) when encoding structs

7 years agomove struct decoding into it's own function
Alan T. DeKok [Thu, 11 Oct 2018 17:58:09 +0000 (13:58 -0400)] 
move struct decoding into it's own function

7 years agowe don't need decoder_ctx for struct
Alan T. DeKok [Thu, 11 Oct 2018 17:46:05 +0000 (13:46 -0400)] 
we don't need decoder_ctx for struct

7 years agoremove RADIUS knowledge from encode_struct
Alan T. DeKok [Thu, 11 Oct 2018 17:44:24 +0000 (13:44 -0400)] 
remove RADIUS knowledge from encode_struct

7 years agostructs which are variable length have "flags.length == 0"
Alan T. DeKok [Thu, 11 Oct 2018 17:22:20 +0000 (13:22 -0400)] 
structs which are variable length have "flags.length == 0"

7 years agomore sanity checking for flags of struct && their entries
Alan T. DeKok [Thu, 11 Oct 2018 17:15:49 +0000 (13:15 -0400)] 
more sanity checking for flags of struct && their entries

7 years agomake decode_struct use standard functions
Alan T. DeKok [Thu, 11 Oct 2018 17:08:26 +0000 (13:08 -0400)] 
make decode_struct use standard functions

and not RADIUS ones.  Struct entries aren't encrypted, they
shouldn't really use RADIUS-specific data types, etc.

7 years agoSilence signed/unsigned warning
Arran Cudbard-Bell [Thu, 11 Oct 2018 16:38:38 +0000 (12:38 -0400)] 
Silence signed/unsigned warning

7 years agoInclude the exec header file
Arran Cudbard-Bell [Thu, 11 Oct 2018 14:26:20 +0000 (10:26 -0400)] 
Include the exec header file

7 years agoRedundant declaration
Arran Cudbard-Bell [Thu, 11 Oct 2018 14:07:36 +0000 (10:07 -0400)] 
Redundant declaration

7 years agos/load/onload due to conflicts with stdatomic.h *sigh*
Arran Cudbard-Bell [Thu, 11 Oct 2018 13:52:35 +0000 (09:52 -0400)] 
s/load/onload due to conflicts with stdatomic.h *sigh*

More header splitting

7 years agonow that we can decode these structs, create them as structs
Alan T. DeKok [Wed, 10 Oct 2018 19:46:44 +0000 (15:46 -0400)] 
now that we can decode these structs, create them as structs

7 years agoallow variable-length fields as the last one in a struct
Alan T. DeKok [Wed, 10 Oct 2018 19:36:07 +0000 (15:36 -0400)] 
allow variable-length fields as the last one in a struct

7 years agoencode structs, too
Alan T. DeKok [Wed, 10 Oct 2018 19:32:43 +0000 (15:32 -0400)] 
encode structs, too

Instead of disallowing structural types and allowing everything
else (i.e. non-value types), we only allow value types, and
disallow everything else

7 years agodecode structs where the last entry is variable length
Alan T. DeKok [Wed, 10 Oct 2018 18:42:23 +0000 (14:42 -0400)] 
decode structs where the last entry is variable length

7 years agostruct children must be numbered consecutively.
Alan T. DeKok [Wed, 10 Oct 2018 17:43:49 +0000 (13:43 -0400)] 
struct children must be numbered consecutively.

We would prefer to not list numbers, but that's life

7 years agofix ethernet to integer conversion
Alan T. DeKok [Wed, 10 Oct 2018 14:23:21 +0000 (10:23 -0400)] 
fix ethernet to integer conversion

we can't really memcpy() an ethernet address to an integer64
attribute, because the address may be in the high bits of the
integer, or in the lowe bits, depending on endian-ness of the
host CPU.

Instead, we manually copy the bytes over, so that we're sure they
end up where we want.  Note that this is the same process used
by fr_value_box_cast_to_ethernet(). i.e. copy to the *low* bytes,
and not to the *high* bytes.

In addition, fix the unit tests to match.  Casting a string type
to ethernet isn't the right thing to do.  With the previous code,
the string type contained an ASCII representation of the ethernet
copied to the high bytes of integer64 and then printed... which
isn't at all anything useful.

The new test case prints ethernet to integer64 type, and then
casts that to ethernet.

If we want to cast from ethernet to string and back, we MUST
just copy the bytes raw / as-is, and *not* convert them to integer

7 years agofix to be pedantically correct
Alan T. DeKok [Wed, 10 Oct 2018 14:17:17 +0000 (10:17 -0400)] 
fix to be pedantically correct

the value in vp_ipaddr is in network order, not host order.
While htonl() and ntohl() are similar, using the right names
is better

7 years agoiuse the correct line number for error messages
Alan T. DeKok [Wed, 10 Oct 2018 14:13:36 +0000 (10:13 -0400)] 
iuse the correct line number for error messages

unlike v3, v4 interpreter line numbers are for the original policy,
not where they are used

7 years agouse consistent names
Alan T. DeKok [Wed, 10 Oct 2018 13:03:43 +0000 (09:03 -0400)] 
use consistent names

7 years agoMore header splitting
Arran Cudbard-Bell [Wed, 10 Oct 2018 07:07:00 +0000 (03:07 -0400)] 
More header splitting

7 years agoMore header splitting
Arran Cudbard-Bell [Tue, 9 Oct 2018 22:15:21 +0000 (15:15 -0700)] 
More header splitting

7 years agoSplit paircmp header out
Arran Cudbard-Bell [Tue, 9 Oct 2018 21:57:48 +0000 (14:57 -0700)] 
Split paircmp header out

7 years agoCherry-pick RHEL sysconfdir fixes from v3.0.x branch
Arran Cudbard-Bell [Tue, 9 Oct 2018 21:07:50 +0000 (14:07 -0700)] 
Cherry-pick RHEL sysconfdir fixes from v3.0.x branch

7 years agoCorrect goto label
Arran Cudbard-Bell [Tue, 9 Oct 2018 19:45:19 +0000 (12:45 -0700)] 
Correct goto label

7 years agoMinor formatting tweaks
Arran Cudbard-Bell [Tue, 9 Oct 2018 19:39:06 +0000 (12:39 -0700)] 
Minor formatting tweaks

7 years agoDecode M3UA_MGMT_ERROR codes, and trigger reset on M3UA_ERR_CODE_REFUSED_MANAGEMENT_B...
Arran Cudbard-Bell [Tue, 9 Oct 2018 19:38:40 +0000 (12:38 -0700)] 
Decode M3UA_MGMT_ERROR codes, and trigger reset on M3UA_ERR_CODE_REFUSED_MANAGEMENT_BLOCKING

7 years agogenerate better error messages
Alan T. DeKok [Sun, 7 Oct 2018 13:41:36 +0000 (09:41 -0400)] 
generate better error messages

7 years agoScript to upload log files to AWS S3 bucket
Arran Cudbard-Bell [Fri, 5 Oct 2018 14:29:50 +0000 (21:29 +0700)] 
Script to upload log files to AWS S3 bucket

7 years agoNeeded here too
Arran Cudbard-Bell [Fri, 5 Oct 2018 10:31:41 +0000 (17:31 +0700)] 
Needed here too

7 years agoSplit regex functions into a separate header
Arran Cudbard-Bell [Fri, 5 Oct 2018 06:47:42 +0000 (13:47 +0700)] 
Split regex functions into a separate header

7 years agoRemove redundant declaration
Arran Cudbard-Bell [Fri, 5 Oct 2018 06:24:03 +0000 (13:24 +0700)] 
Remove redundant declaration

7 years agoMore header fixes for the server library
Arran Cudbard-Bell [Fri, 5 Oct 2018 05:49:45 +0000 (12:49 +0700)] 
More header fixes for the server library

7 years agothis attribute is text, not binary. Fixes #2322
Alan T. DeKok [Thu, 4 Oct 2018 20:00:20 +0000 (16:00 -0400)] 
this attribute is text, not binary.  Fixes #2322

7 years agosimplify code
Alan T. DeKok [Thu, 4 Oct 2018 14:36:26 +0000 (10:36 -0400)] 
simplify code

the buffer almost always shrinks, so just call the function

7 years agoshrink the message, and fix compile warning
Alan T. DeKok [Thu, 4 Oct 2018 14:00:40 +0000 (10:00 -0400)] 
shrink the message, and fix compile warning

7 years agoMinor fixes
Arran Cudbard-Bell [Thu, 4 Oct 2018 13:30:06 +0000 (20:30 +0700)] 
Minor fixes