]> git.ipfire.org Git - thirdparty/freeradius-server.git/log
thirdparty/freeradius-server.git
16 months agoAdd VSA to internal encoder test
Nick Porter [Fri, 23 Aug 2024 11:27:09 +0000 (12:27 +0100)] 
Add VSA to internal encoder test

16 months agoremove unused syntax
Alan T. DeKok [Thu, 22 Aug 2024 18:33:33 +0000 (14:33 -0400)] 
remove unused syntax

we used to support

foo.bar.baz = blah

as a short-hand for config

foo {
bar {
baz = blah
}
}

but that now conflicts with the non '&' attribute syntax.  Since
the old-style syntax isn't used, remove it.

16 months agoadd "listen" state for proto ldap sync
Alan T. DeKok [Thu, 22 Aug 2024 16:24:17 +0000 (12:24 -0400)] 
add "listen" state for proto ldap sync

16 months agohoise "parse rcode" to earlier in tokenize_field()
Alan T. DeKok [Thu, 22 Aug 2024 16:14:39 +0000 (12:14 -0400)] 
hoise "parse rcode" to earlier in tokenize_field()

which simplifies some of the code, and helps us prepare for
removing the leading '&' from attribute names.

update the rcode function instantiation to allow for different
data types.

add an rcode print function which prints the text version of the
rcode.

update a few tests with new results

16 months agoadd "set unlang allow" API for unit_test_map
Alan T. DeKok [Thu, 22 Aug 2024 12:41:07 +0000 (08:41 -0400)] 
add "set unlang allow" API for unit_test_map

16 months agoVSA and VENDOR attributes need the same encoder logic as TLV
Nick Porter [Thu, 22 Aug 2024 07:06:44 +0000 (08:06 +0100)] 
VSA and VENDOR attributes need the same encoder logic as TLV

Allows for %internal.encode(&Vendor-Specific) or
%internal.encode(&Vendor-Specific.Vendor) and the children will be added
correctly.

16 months agoUse current da type when walking through encoding steps
Nick Porter [Wed, 21 Aug 2024 21:08:49 +0000 (22:08 +0100)] 
Use current da type when walking through encoding steps

16 months agoadd update sections to the list, too
Alan T. DeKok [Wed, 21 Aug 2024 18:55:17 +0000 (14:55 -0400)] 
add update sections to the list, too

16 months agoremove more '&' from parsing, and move to state checks
Alan T. DeKok [Wed, 21 Aug 2024 18:08:41 +0000 (14:08 -0400)] 
remove more '&' from parsing, and move to state checks

16 months agoallow locals in a "dictionary" section.
Alan T. DeKok [Wed, 21 Aug 2024 15:15:35 +0000 (11:15 -0400)] 
allow locals in a "dictionary" section.

and make the parser even more state oriented

16 months agouse switch statement
Alan T. DeKok [Wed, 21 Aug 2024 14:05:42 +0000 (10:05 -0400)] 
use switch statement

16 months agomove migration flag to main config
Alan T. DeKok [Wed, 21 Aug 2024 11:56:59 +0000 (07:56 -0400)] 
move migration flag to main config

16 months agoset tmpl migration variable from main config flags
Alan T. DeKok [Wed, 21 Aug 2024 11:47:53 +0000 (07:47 -0400)] 
set tmpl migration variable from main config flags

16 months agoMake the compiler state oriented, instead of looking for '&'
Alan T. DeKok [Wed, 21 Aug 2024 11:44:45 +0000 (07:44 -0400)] 
Make the compiler state oriented, instead of looking for '&'

16 months agoadd state for map / update sections
Alan T. DeKok [Wed, 21 Aug 2024 11:10:17 +0000 (07:10 -0400)] 
add state for map / update sections

16 months agoallow unlang inside of virtual modules
Alan T. DeKok [Wed, 21 Aug 2024 00:00:08 +0000 (20:00 -0400)] 
allow unlang inside of virtual modules

16 months agomore "move to state orientaed" instead of hacks
Alan T. DeKok [Tue, 20 Aug 2024 23:36:33 +0000 (19:36 -0400)] 
more "move to state orientaed" instead of hacks

16 months agomake unlang parsing more explicitly state oriented
Alan T. DeKok [Tue, 20 Aug 2024 21:48:19 +0000 (17:48 -0400)] 
make unlang parsing more explicitly state oriented

16 months agochange name to be clearer
Alan T. DeKok [Tue, 20 Aug 2024 20:06:47 +0000 (16:06 -0400)] 
change name to be clearer

16 months agoexplicitly mark up sections which we know are unlang
Alan T. DeKok [Tue, 20 Aug 2024 15:55:33 +0000 (11:55 -0400)] 
explicitly mark up sections which we know are unlang

in preparation for removing the requirement to use '&'

16 months agoRange check buffer[1] to avoid tainted_data issue (CID #1419883)
James Jones [Tue, 20 Aug 2024 18:22:25 +0000 (13:22 -0500)] 
Range check buffer[1] to avoid tainted_data issue (CID #1419883)

Keeps it from falling off the edge of packet_name[]. Rather than
printing out a minimally informative "invalid" if it's out of
range, it will print the numerical value.

16 months agoRe-work test for extended regex
Nick Porter [Tue, 20 Aug 2024 09:48:11 +0000 (10:48 +0100)] 
Re-work test for extended regex

So it doesn't hang on "lean" CI builds

16 months agooriginal->flags is already in network byte order
Nick Porter [Tue, 20 Aug 2024 08:37:02 +0000 (09:37 +0100)] 
original->flags is already in network byte order

16 months agoRFC 2131 says DHCP replies copy flags from requests
Nick Porter [Mon, 19 Aug 2024 17:26:39 +0000 (18:26 +0100)] 
RFC 2131 says DHCP replies copy flags from requests

16 months agomove "set open" to common function
Alan T. DeKok [Mon, 19 Aug 2024 14:39:02 +0000 (10:39 -0400)] 
move "set open" to common function

16 months agoupdate for new fr_radius_encode() API
Alan T. DeKok [Sun, 18 Aug 2024 21:13:56 +0000 (17:13 -0400)] 
update for new fr_radius_encode() API

and call activate() from connect(), if the connection is already
open.

16 months agocall time start to bootstrap timing
Alan T. DeKok [Mon, 19 Aug 2024 13:16:19 +0000 (09:16 -0400)] 
call time start to bootstrap timing

17 months agoadd "require_enum_prefix" migration flag
Alan T. DeKok [Sat, 17 Aug 2024 12:55:42 +0000 (08:55 -0400)] 
add "require_enum_prefix" migration flag

in preparation for moving to ::enum-name everywhere, which then
lets us drop the "&" prefix for attribute names

17 months agosimplify a bit
Alan T. DeKok [Sat, 17 Aug 2024 12:55:24 +0000 (08:55 -0400)] 
simplify a bit

17 months agoallow cast to same data type to mean "print value, not enum name"
Alan T. DeKok [Fri, 16 Aug 2024 20:06:25 +0000 (16:06 -0400)] 
allow cast to same data type to mean "print value, not enum name"

because I tried to use it, and it didn't work.  So the logical
next step is to make it work.

17 months agoclean up casting a bit
Alan T. DeKok [Fri, 16 Aug 2024 13:58:46 +0000 (09:58 -0400)] 
clean up casting a bit

17 months agoComplete (and simplify) the pacification of Coverity (CD #1604613)
James Jones [Fri, 16 Aug 2024 17:27:42 +0000 (12:27 -0500)] 
Complete (and simplify) the pacification of Coverity (CD #1604613)

Handling the two-byte length case seems to have made Coverity gripe
about the one-byte case. We therefore change it so that one
Coverity-only check is done for both cases, reducing clutter.

17 months agoAdd Coverity-only check for two-byte length case (CID #1604613)
James Jones [Wed, 14 Aug 2024 21:33:52 +0000 (16:33 -0500)] 
Add Coverity-only check for two-byte length case (CID #1604613)

In fr_struct_to_network(), for structs prefixed by a length, the
length can be either one or two bytes. Space is set aside for it,
and when it comes time to encode it, you skip the appropriate number
of bytes and decrement length correspondingly. Coverity lets the one
byte length version pass without complaint, but in the two-byte
length case thinks length is 0 and hence underflows when 2 is subtracted
from it.

We add a Coverity-only check that returns an error if len < 2; it
never will be, but the check should persuade Coverity that at the
decrement, len will be at least 2.

17 months agouse the src enum for time resolution, not the dst enum
Alan T. DeKok [Wed, 14 Aug 2024 13:42:24 +0000 (09:42 -0400)] 
use the src enum for time resolution, not the dst enum

and add tests for it.

17 months agoFix crossbuild for Debian sid
Nick Porter [Wed, 14 Aug 2024 09:14:30 +0000 (10:14 +0100)] 
Fix crossbuild for Debian sid

17 months agoMore appropriate list of common cross builds
Nick Porter [Wed, 14 Aug 2024 09:08:12 +0000 (10:08 +0100)] 
More appropriate list of common cross builds

17 months agoDebian sid has OpenSSL legacy providers in an optional package
Nick Porter [Wed, 14 Aug 2024 08:21:10 +0000 (09:21 +0100)] 
Debian sid has OpenSSL legacy providers in an optional package

17 months agoAdd rlm_sql_mysql driver option to set connection character set
Nick Porter [Wed, 14 Aug 2024 07:38:53 +0000 (08:38 +0100)] 
Add rlm_sql_mysql driver option to set connection character set

17 months agoUNUSED
Nick Porter [Wed, 14 Aug 2024 07:16:18 +0000 (08:16 +0100)] 
UNUSED

17 months agoallow casting from something to specific time_delta resolutions
Alan T. DeKok [Tue, 13 Aug 2024 20:57:19 +0000 (16:57 -0400)] 
allow casting from something to specific time_delta resolutions

which creates an output value-box of type time_delta, and the
named time resolution.

Add a test.

update the calc code to include the time resolution / enumv when
doing box operations, so that we know how to properly compare things.

17 months agoadd API to get enumv for time precision
Alan T. DeKok [Tue, 13 Aug 2024 20:52:48 +0000 (16:52 -0400)] 
add API to get enumv for time precision

17 months agoupdate Acct-Delay-Time calculations
Alan T. DeKok [Tue, 13 Aug 2024 15:34:42 +0000 (11:34 -0400)] 
update Acct-Delay-Time calculations

17 months agoadd test for (date - date --> uint32)
Alan T. DeKok [Tue, 13 Aug 2024 15:33:05 +0000 (11:33 -0400)] 
add test for (date - date --> uint32)

which should come out as seconds

17 months agoremove discussion of old attribute
Alan T. DeKok [Mon, 12 Aug 2024 20:29:45 +0000 (16:29 -0400)] 
remove discussion of old attribute

17 months agoifdef around registration, too
Alan T. DeKok [Mon, 12 Aug 2024 20:16:24 +0000 (16:16 -0400)] 
ifdef around registration, too

17 months agoprint out actual attribute
Alan T. DeKok [Mon, 12 Aug 2024 20:15:09 +0000 (16:15 -0400)] 
print out actual attribute

17 months agoleave Acct-Delay-Time
Alan T. DeKok [Mon, 12 Aug 2024 17:09:06 +0000 (13:09 -0400)] 
leave Acct-Delay-Time

but don't use it for anything

17 months agoCheck for EVP_blake2s256 and EVP_blake2b512 Closes #5399
Arran Cudbard-Bell [Mon, 12 Aug 2024 13:13:29 +0000 (09:13 -0400)] 
Check for EVP_blake2s256 and EVP_blake2b512 Closes #5399

17 months agoUpdate autoconf.h.in with whatever the latest autoconf boilerplate is
Arran Cudbard-Bell [Mon, 12 Aug 2024 13:06:28 +0000 (09:06 -0400)] 
Update autoconf.h.in with whatever the latest autoconf boilerplate is

17 months agoQuiet warning
Arran Cudbard-Bell [Mon, 12 Aug 2024 12:53:56 +0000 (08:53 -0400)] 
Quiet warning

17 months agoif (!event-timestamp) event-timestamp = now - Acct-Delay-Time
Alan T. DeKok [Mon, 12 Aug 2024 12:19:19 +0000 (08:19 -0400)] 
if (!event-timestamp) event-timestamp = now - Acct-Delay-Time

17 months agowe can always retransmit Status-Server checks
Alan T. DeKok [Mon, 12 Aug 2024 02:19:13 +0000 (22:19 -0400)] 
we can always retransmit Status-Server checks

there's no benefit to re-encoding them every time.

17 months agodon't add Proxy-State to "ping" packets
Alan T. DeKok [Mon, 12 Aug 2024 02:14:29 +0000 (22:14 -0400)] 
don't add Proxy-State to "ping" packets

17 months agoremove Acct-Delay-Time
Alan T. DeKok [Mon, 12 Aug 2024 02:09:24 +0000 (22:09 -0400)] 
remove Acct-Delay-Time

If we receive an accounting packet, add Event-Timestamp if it's
not already in the packet.

If the packet contains Acct-Delay-Time, then subtract that from
Event-Timestamp, and delete Acct-Delay-Time.

Acct-Delay-Time causes too many issues with proxying and retransmissions.

17 months agoremove AcctStartDelay.
Alan T. DeKok [Mon, 12 Aug 2024 01:32:24 +0000 (21:32 -0400)] 
remove AcctStartDelay.

it hasn't ever been used, either.

17 months agoremove AcctStopDelay from Oracle and MS-SQL.
Alan T. DeKok [Mon, 12 Aug 2024 01:29:38 +0000 (21:29 -0400)] 
remove AcctStopDelay from Oracle and MS-SQL.

It hasn't been used.  Ever.

17 months agoremove unneeded code
Alan T. DeKok [Mon, 12 Aug 2024 01:13:18 +0000 (21:13 -0400)] 
remove unneeded code

17 months agoquiet compiler
Alan T. DeKok [Sun, 11 Aug 2024 22:27:07 +0000 (18:27 -0400)] 
quiet compiler

17 months agodon't set "require_message_authenticator" from AUTO for EAP
Alan T. DeKok [Sun, 11 Aug 2024 22:09:29 +0000 (18:09 -0400)] 
don't set "require_message_authenticator" from AUTO for EAP

if the request contains EAP, then the reply has to contain EAP,
and both packets have to contain Message-Authenticator

17 months agohoist Proxy-State checks to main encoder
Alan T. DeKok [Sun, 11 Aug 2024 22:06:19 +0000 (18:06 -0400)] 
hoist Proxy-State checks to main encoder

in preparation for moving rlm_radius to the new BIO code

17 months agomove "secure_transport" to common data structure
Alan T. DeKok [Sun, 11 Aug 2024 21:46:37 +0000 (17:46 -0400)] 
move "secure_transport" to common data structure

17 months agotypo
Alan T. DeKok [Sun, 11 Aug 2024 21:29:41 +0000 (17:29 -0400)] 
typo

17 months agoignore Message-Authenticator in replies
Alan T. DeKok [Sun, 11 Aug 2024 21:08:46 +0000 (17:08 -0400)] 
ignore Message-Authenticator in replies

17 months agodon't automatically add Message-Authenticator for tests
Alan T. DeKok [Sun, 11 Aug 2024 20:37:34 +0000 (16:37 -0400)] 
don't automatically add Message-Authenticator for tests

17 months agoRevert "don't use packet->vector for CHAP-Challenge"
Alan T. DeKok [Sun, 11 Aug 2024 20:32:16 +0000 (16:32 -0400)] 
Revert "don't use packet->vector for CHAP-Challenge"

This reverts commit 1df03034d952d9fa473fd9da6fae22308945d194.

17 months agomove "add Message-Authenticator" functionality to core encoder
Alan T. DeKok [Sun, 11 Aug 2024 20:30:33 +0000 (16:30 -0400)] 
move "add Message-Authenticator" functionality to core encoder

17 months agotypo
Alan T. DeKok [Sun, 11 Aug 2024 20:19:30 +0000 (16:19 -0400)] 
typo

17 months agogo to next VP on skip
Alan T. DeKok [Sun, 11 Aug 2024 20:19:18 +0000 (16:19 -0400)] 
go to next VP on skip

17 months agodon't use packet->vector for CHAP-Challenge
Alan T. DeKok [Sun, 11 Aug 2024 19:48:02 +0000 (15:48 -0400)] 
don't use packet->vector for CHAP-Challenge

use packet->data + 4

arguably the RADIUS protocol decoder should synthesize the
CHAP-Challenge if it's not in the packet, as that would make
the rest of the code simpler.

17 months agouse correct type
Alan T. DeKok [Sun, 11 Aug 2024 19:47:37 +0000 (15:47 -0400)] 
use correct type

17 months agodon't set packet->vector for non-RADIUS protocols
Alan T. DeKok [Sun, 11 Aug 2024 19:36:33 +0000 (15:36 -0400)] 
don't set packet->vector for non-RADIUS protocols

and most of those were wrong, too :(

17 months agowe no longer use packet->vector for anything DHCPv4
Alan T. DeKok [Sun, 11 Aug 2024 19:34:47 +0000 (15:34 -0400)] 
we no longer use packet->vector for anything DHCPv4

17 months agodon't smash the authentication vector
Alan T. DeKok [Sun, 11 Aug 2024 19:33:13 +0000 (15:33 -0400)] 
don't smash the authentication vector

17 months agopass dbuff && packet_ctx to encode function
Alan T. DeKok [Sun, 11 Aug 2024 18:18:25 +0000 (14:18 -0400)] 
pass dbuff && packet_ctx to encode function

which makes it easier to add more functionality

17 months agopoint to common context, instead of local struct
Alan T. DeKok [Sun, 11 Aug 2024 16:30:14 +0000 (12:30 -0400)] 
point to common context, instead of local struct

17 months agomake common context "const"
Alan T. DeKok [Sun, 11 Aug 2024 16:17:15 +0000 (12:17 -0400)] 
make common context "const"

17 months agoremove vector[] from common encode/decode context
Alan T. DeKok [Sun, 11 Aug 2024 16:11:38 +0000 (12:11 -0400)] 
remove vector[] from common encode/decode context

17 months agoremove duplicate API as part of cleanup
Alan T. DeKok [Sun, 11 Aug 2024 13:59:35 +0000 (09:59 -0400)] 
remove duplicate API as part of cleanup

there isn't much point in switching to a new API if we don't
switch to a new API

17 months agoclean up API and simplify
Alan T. DeKok [Sun, 11 Aug 2024 13:44:40 +0000 (09:44 -0400)] 
clean up API and simplify

no need to pass buffer / size twice to the receive function,
it's already in the dedup_ctx

17 months agofor simplicity, put rb node into dedup context
Alan T. DeKok [Sun, 11 Aug 2024 13:44:22 +0000 (09:44 -0400)] 
for simplicity, put rb node into dedup context

17 months agodon't encode Message-Authenticator multiple times
Alan T. DeKok [Sun, 11 Aug 2024 13:29:58 +0000 (09:29 -0400)] 
don't encode Message-Authenticator multiple times

17 months agouse pctx for packet ctx
Alan T. DeKok [Fri, 9 Aug 2024 23:22:38 +0000 (19:22 -0400)] 
use pctx for packet ctx

17 months agoallow setting CoA filter attribute name
Alan T. DeKok [Fri, 9 Aug 2024 19:48:05 +0000 (15:48 -0400)] 
allow setting CoA filter attribute name

17 months agoRevert "Add Coverity-only check to pacify it (CID #1604609)"
Alan T. DeKok [Fri, 9 Aug 2024 15:09:41 +0000 (11:09 -0400)] 
Revert "Add Coverity-only check to pacify it (CID #1604609)"

This reverts commit aa37659f220f4d0a338ab98ad4fd3110a6082fdf.

17 months agolink in radiusd -X
Alan T. DeKok [Fri, 9 Aug 2024 12:19:12 +0000 (08:19 -0400)] 
link in radiusd -X

17 months agopoint to new files
Alan T. DeKok [Fri, 9 Aug 2024 12:07:13 +0000 (08:07 -0400)] 
point to new files

17 months agoprint out only at end, to avoid dups
Alan T. DeKok [Fri, 9 Aug 2024 12:06:13 +0000 (08:06 -0400)] 
print out only at end, to avoid dups

17 months agopoint to correct link
Alan T. DeKok [Fri, 9 Aug 2024 12:03:10 +0000 (08:03 -0400)] 
point to correct link

17 months agoscript to cross-check antora files
Alan T. DeKok [Thu, 8 Aug 2024 21:33:18 +0000 (17:33 -0400)] 
script to cross-check antora files

17 months agothis is a new module
Alan T. DeKok [Thu, 8 Aug 2024 21:32:34 +0000 (17:32 -0400)] 
this is a new module

17 months agomoved to better location
Alan T. DeKok [Thu, 8 Aug 2024 21:15:10 +0000 (17:15 -0400)] 
moved to better location

17 months agoUpdate index.adoc
aBainbridge11 [Tue, 30 Jul 2024 19:54:34 +0000 (15:54 -0400)] 
Update index.adoc

17 months agoCreate Alcatel-Lucent
aBainbridge11 [Tue, 30 Jul 2024 19:45:30 +0000 (15:45 -0400)] 
Create Alcatel-Lucent

17 months agoCreate Huawei
aBainbridge11 [Tue, 30 Jul 2024 19:24:13 +0000 (15:24 -0400)] 
Create Huawei

17 months agoCreate HP
aBainbridge11 [Tue, 30 Jul 2024 19:23:27 +0000 (15:23 -0400)] 
Create HP

17 months agoUpdate cisco.adoc
aBainbridge11 [Tue, 30 Jul 2024 18:52:30 +0000 (14:52 -0400)] 
Update cisco.adoc

17 months agoCreate Alvarion
aBainbridge11 [Tue, 30 Jul 2024 18:40:02 +0000 (14:40 -0400)] 
Create Alvarion

17 months agoUpdate index.adoc
aBainbridge11 [Tue, 30 Jul 2024 18:29:53 +0000 (14:29 -0400)] 
Update index.adoc

17 months agoCreate EAP PEAP
aBainbridge11 [Tue, 30 Jul 2024 18:17:52 +0000 (14:17 -0400)] 
Create EAP PEAP

17 months agoCreate Disconnect Messages
aBainbridge11 [Tue, 30 Jul 2024 16:57:20 +0000 (12:57 -0400)] 
Create Disconnect Messages