]>
git.ipfire.org Git - thirdparty/freeradius-server.git/log
Arran Cudbard-Bell [Tue, 23 Jan 2024 22:53:07 +0000 (16:53 -0600)]
Use better type to hash/trie/rb mappings
Arran Cudbard-Bell [Tue, 23 Jan 2024 22:35:43 +0000 (16:35 -0600)]
Fix integer (and other) comparisons for switch
Alan T. DeKok [Tue, 23 Jan 2024 21:32:38 +0000 (16:32 -0500)]
address coverity issues
Alan T. DeKok [Tue, 23 Jan 2024 19:30:00 +0000 (14:30 -0500)]
allow domain sockets to be opened as root
which is likely imperfect, but whatever
Alan T. DeKok [Tue, 23 Jan 2024 19:27:47 +0000 (14:27 -0500)]
remove old / unused commented-out config items
Alan T. DeKok [Tue, 23 Jan 2024 19:23:41 +0000 (14:23 -0500)]
make reply checks more stringent
Alan T. DeKok [Tue, 23 Jan 2024 19:21:04 +0000 (14:21 -0500)]
remove unused macro
Alan T. DeKok [Tue, 23 Jan 2024 18:55:55 +0000 (13:55 -0500)]
move to using bios for at least part of the control socket
Nick Porter [Tue, 23 Jan 2024 17:05:09 +0000 (17:05 +0000)]
Remove setting of Message-Success-Message from sqlippool
Equivalent functionality can be done by observing the module return code
and use of xlats.
Alan T. DeKok [Tue, 23 Jan 2024 17:04:53 +0000 (12:04 -0500)]
use new defs
Alan T. DeKok [Tue, 23 Jan 2024 16:22:55 +0000 (11:22 -0500)]
split encode / decode context into two different fields
and add a common context with secret, etc.
Alan T. DeKok [Tue, 23 Jan 2024 14:19:40 +0000 (09:19 -0500)]
allow opening /dev/stdout and /dev/stderr
Alan T. DeKok [Tue, 23 Jan 2024 13:59:17 +0000 (08:59 -0500)]
Linux has AF_FILE==AF_LOCAL
so use our own AF_FILE_BIO
Alan T. DeKok [Tue, 23 Jan 2024 13:51:44 +0000 (08:51 -0500)]
add support for file IO in bios
Alan T. DeKok [Tue, 23 Jan 2024 13:50:50 +0000 (08:50 -0500)]
use AF_LOCAL, as AF_UNIX is deprecated
Alan T. DeKok [Tue, 23 Jan 2024 13:19:10 +0000 (08:19 -0500)]
just call write()
Alan T. DeKok [Tue, 23 Jan 2024 13:04:17 +0000 (08:04 -0500)]
add cfg to alloc routine, too
Alan T. DeKok [Tue, 23 Jan 2024 12:55:04 +0000 (07:55 -0500)]
<sigh>
Alan T. DeKok [Tue, 23 Jan 2024 12:33:51 +0000 (07:33 -0500)]
might as well cache cfg, too
Alan T. DeKok [Tue, 23 Jan 2024 12:30:43 +0000 (07:30 -0500)]
try to quiet the static analyzer
Alan T. DeKok [Tue, 23 Jan 2024 02:38:27 +0000 (21:38 -0500)]
don't return things which are missing in NDEBUG builds
Alan T. DeKok [Tue, 23 Jan 2024 02:27:16 +0000 (21:27 -0500)]
this is unused
add it back in when we fix it, and start using it
Alan T. DeKok [Tue, 23 Jan 2024 02:25:20 +0000 (21:25 -0500)]
only need this for debug builds
Alan T. DeKok [Tue, 23 Jan 2024 02:24:13 +0000 (21:24 -0500)]
shut up stupid compiler
Alan T. DeKok [Tue, 23 Jan 2024 02:11:19 +0000 (21:11 -0500)]
more quiet static analysis
Alan T. DeKok [Tue, 23 Jan 2024 00:42:26 +0000 (19:42 -0500)]
and more build fixes
Arran Cudbard-Bell [Tue, 23 Jan 2024 00:25:51 +0000 (18:25 -0600)]
...and RPM fixes
Alan T. DeKok [Tue, 23 Jan 2024 00:22:13 +0000 (19:22 -0500)]
and more build fixes
Arran Cudbard-Bell [Tue, 23 Jan 2024 00:18:49 +0000 (18:18 -0600)]
Don't apply body restrictions to xlat calls
Alan T. DeKok [Tue, 23 Jan 2024 00:06:06 +0000 (19:06 -0500)]
more build fixes
Alan T. DeKok [Mon, 22 Jan 2024 23:58:45 +0000 (18:58 -0500)]
clang on OSX does not produce nearly enough errors.
CI produces many more errors and complaints.
Alan T. DeKok [Mon, 22 Jan 2024 23:44:41 +0000 (18:44 -0500)]
First pass at bio handlers.
The FD bio works. The others are "compile tested"
Alan T. DeKok [Mon, 22 Jan 2024 22:09:01 +0000 (17:09 -0500)]
we don't need these fields. The bio code has been updated
Alan T. DeKok [Mon, 22 Jan 2024 21:35:38 +0000 (16:35 -0500)]
start moving more code to centralized RADIUS library
Alan T. DeKok [Mon, 22 Jan 2024 19:31:07 +0000 (14:31 -0500)]
document source of fast rng
Arran Cudbard-Bell [Mon, 22 Jan 2024 22:33:53 +0000 (16:33 -0600)]
Rename json xlat functions
Alan T. DeKok [Mon, 22 Jan 2024 19:02:09 +0000 (14:02 -0500)]
call the correct function
Alan T. DeKok [Mon, 22 Jan 2024 18:51:51 +0000 (13:51 -0500)]
t_rules may be NULL. CID
1558812
Alan T. DeKok [Mon, 22 Jan 2024 14:25:49 +0000 (09:25 -0500)]
just trust /dev/random
there's little utility in mixing in other data
Alan T. DeKok [Mon, 22 Jan 2024 14:19:18 +0000 (09:19 -0500)]
minor cleanups
Alan T. DeKok [Mon, 22 Jan 2024 14:08:01 +0000 (09:08 -0500)]
rename functions for clarity
in preparation for allowing forced seeds
Alan T. DeKok [Mon, 22 Jan 2024 13:04:00 +0000 (08:04 -0500)]
no need to call encode / sign / write. just call fr_radius_send()
Nick Porter [Mon, 22 Jan 2024 18:04:53 +0000 (18:04 +0000)]
Revert to main eapol_test repo
We only pull from the repo if we don't have a cached copy, so don't pull
very often.
Arran Cudbard-Bell [Sat, 20 Jan 2024 15:09:06 +0000 (09:09 -0600)]
Invalid comment
Arran Cudbard-Bell [Sat, 20 Jan 2024 02:48:47 +0000 (20:48 -0600)]
Don't reallocate the uri escape ctx on every request
Arran Cudbard-Bell [Sat, 20 Jan 2024 02:26:19 +0000 (20:26 -0600)]
Major rework in rlm_rest
- Remove all synchronous expansions. data, uri, username, password are now passed in as a call_envs
- Perform uri escaping within call_env evaluation for module section calls
- Split config items into request/response sections, and document which config items can't be used as xlats
- Remove legacy uri expansion and escaping
- Have test json-api endpoints echo back headers, args, and body data, and fix up xlat tests to check what we sent over
- Start of response header parsing and output
- Support taking body data, and headers, from ANY tmpl type not just xlats
Arran Cudbard-Bell [Sat, 20 Jan 2024 02:20:42 +0000 (20:20 -0600)]
Remove orphaned params
Arran Cudbard-Bell [Sat, 20 Jan 2024 02:19:09 +0000 (20:19 -0600)]
Make fr_uri_escape work as a value box escape function
No major changes here, we just record the current uri_part in a new fr_uri_escape_ctx_t struct. The original function is retained as fr_uri_escape_list which processes a list of value boxes.
Arran Cudbard-Bell [Sat, 20 Jan 2024 02:18:02 +0000 (20:18 -0600)]
Don't crash when decoding empty base64 strings
Arran Cudbard-Bell [Sat, 20 Jan 2024 02:17:46 +0000 (20:17 -0600)]
Add "secret" call_env flag. Not currently respected because we don't print anything, but we don't want to lose the secret flag during conversions
Arran Cudbard-Bell [Sat, 20 Jan 2024 02:17:15 +0000 (20:17 -0600)]
Wordsmithing
Arran Cudbard-Bell [Sat, 20 Jan 2024 02:17:03 +0000 (20:17 -0600)]
Better assert message for bad quoting type
Arran Cudbard-Bell [Sat, 20 Jan 2024 02:14:22 +0000 (20:14 -0600)]
Add support for ephemeral uctx initialisation
Allow escape functions to return error codes
Arran Cudbard-Bell [Sat, 20 Jan 2024 01:17:36 +0000 (19:17 -0600)]
Don't print out certificate messages if there are no certificates
Arran Cudbard-Bell [Fri, 19 Jan 2024 00:11:25 +0000 (18:11 -0600)]
Make the openresty setup script work on macOS with homebrew
James Jones [Fri, 19 Jan 2024 18:57:03 +0000 (12:57 -0600)]
Remove dead code (CID #
1504016 )
In fr_value_box_from_substr(), the first switch on dst_type handles
the FR_TYPE_COMBO_IP_{ADDR, PREFIX} cases, so that dst_type can't
have those values when the second switch on dst_type is executed.
Nick Porter [Fri, 19 Jan 2024 10:41:23 +0000 (10:41 +0000)]
Remove un-used module option
Nick Porter [Fri, 19 Jan 2024 09:48:55 +0000 (09:48 +0000)]
Debian sid has removed fakeroot from build-essential
Nick Porter [Thu, 18 Jan 2024 18:09:04 +0000 (18:09 +0000)]
Correct documentation
Nick Porter [Thu, 18 Jan 2024 17:57:58 +0000 (17:57 +0000)]
Better English
Nick Porter [Thu, 18 Jan 2024 17:57:36 +0000 (17:57 +0000)]
Reduce boilerplate
Nick Porter [Thu, 18 Jan 2024 17:56:15 +0000 (17:56 +0000)]
Remove legacy sqlippool single letter expansions
Nick Porter [Thu, 18 Jan 2024 17:43:36 +0000 (17:43 +0000)]
Ensure IP updated is from the correct pool
In case IPs exist in more than one pool.
Nick Porter [Thu, 18 Jan 2024 17:38:51 +0000 (17:38 +0000)]
Remove use of %I expansion from sqlippool queries
Nick Porter [Thu, 18 Jan 2024 17:03:06 +0000 (17:03 +0000)]
sqlite3_prepare functions prepare only the next query in the string
and return a pointer to the character after what was parsed - so this
provides a more robust method of parsing the SQL to execute than simply
looking for ';' followed by '\n' or '\0'.
E.g. if there are comments which end the line with a ';' that fails with
the old parsing.
In addition, if there were ';' in data inside a string, the previous
parsing would have thrown away the portion of the string before that.
Nick Porter [Thu, 18 Jan 2024 10:07:48 +0000 (10:07 +0000)]
Use method names consistent with rlm_redis_ippool
Nick Porter [Thu, 18 Jan 2024 10:06:16 +0000 (10:06 +0000)]
Ensure values are strings before attempting SQL escaping
Alan T. DeKok [Thu, 18 Jan 2024 17:51:50 +0000 (12:51 -0500)]
always set event list. Should help with #5270
Alan T. DeKok [Thu, 18 Jan 2024 16:29:51 +0000 (11:29 -0500)]
add FreeRADIUS VSA for Acct-Unique-Session-Id
James Jones [Tue, 31 Oct 2023 17:22:01 +0000 (12:22 -0500)]
Hoist some fr_radius_ok() calls above decode() (CID #
1544988 , #
1503910 )
This should make show coverity that the packet and length are
validated before being passed to decode().
James Jones [Tue, 7 Nov 2023 18:54:54 +0000 (12:54 -0600)]
Tweak mod_read() range check on packet code (CID #
1419883 ?)
buffer[0] is used as index into fr_radius_packet_names[], so
allowing FR_PACKET_CODE_MAX will fall off the end. This may
placate coverity, but I believe it is needed in any case.
James Jones [Wed, 8 Nov 2023 22:29:49 +0000 (16:29 -0600)]
Make IN_RANGE_INTEGER_*() nontrivial iff it can actually fail (CID #
1445201 )
The range check can only fail if PTRDIFF_MAX < INT64_MAX. Since
that's not the case for the Coverity run, you get a defect of the
result_independent_of_operands flavor, just like the range checks
for fr_sbuff_out_[u]int64() used to.
The floating point version, I believe, will notice +/-infinity
and denormalized numbers, so Coverity wouldn't complain about it.
James Jones [Mon, 4 Dec 2023 19:02:21 +0000 (13:02 -0600)]
Start converting remaining unlang function calls to new syntax
James Jones [Tue, 17 Oct 2023 20:33:00 +0000 (15:33 -0500)]
Try to make coverity recognize range check on len (CID #
1448182 )
James Jones [Thu, 5 Oct 2023 18:45:42 +0000 (13:45 -0500)]
Deal with remaining toctou defect (CID #
1503910 )
Fabrice Fontaine [Thu, 11 Jan 2024 16:38:41 +0000 (17:38 +0100)]
src/modules/rlm_python: fix build with -Ofast
Stripping logic wrongly translates -Ofast into ast resulting in the
following build failure:
configure: /home/fabrice/buildroot/output/host/powerpc64-buildroot-linux-gnu/sysroot/usr/bin/python3-config's cflags were "-I/home/fabrice/buildroot/output/host/powerpc64-buildroot-linux-gnu/sysroot/usr/include/python3.11 -I/home/fabrice/buildroot/output/host/powerpc64-buildroot-linux-gnu/sysroot/usr/include/python3.11 -Wsign-compare -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -Ofast -g0 -D_FORTIFY_SOURCE=2 -DNDEBUG -g -fwrapv -O3 -Wall"
configure: Sanitized cflags were " -isystem/home/fabrice/buildroot/output/host/powerpc64-buildroot-linux-gnu/sysroot/usr/include/python3.11 -isystem/home/fabrice/buildroot/output/host/powerpc64-buildroot-linux-gnu/sysroot/usr/include/python3.11 -D_LARGEFILE_SOURCE -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 ast -D_FORTIFY_SOURCE=2 -fwrapv "
[...]
powerpc64-buildroot-linux-gnu-gcc.br_real: error: ast: linker input file not found: No such file or directory
Fixes:
- http://autobuild.buildroot.org/results/
904c43241b99a8d848c1891cb5af132a291311b4
Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Arran Cudbard-Bell [Wed, 17 Jan 2024 17:41:40 +0000 (11:41 -0600)]
Setting local variables from mapping sections does seem to work...
Alan T. DeKok [Wed, 17 Jan 2024 02:20:14 +0000 (21:20 -0500)]
lowercase. Manual port of
8f4fcd3dc4
James Jones [Thu, 11 Jan 2024 20:25:20 +0000 (14:25 -0600)]
Quote parameter of ldap.memberof
James Jones [Fri, 12 Jan 2024 21:30:08 +0000 (15:30 -0600)]
Attempt to fix test_condition_levels_max() issue
test_condition_levels_max() seemingly randomly fails the check for
preq_a->{completed, freed} being true. It happens to work locally,
so submitting to try to provoke it again.
Previous trunk tests needed virtual time to pass to work, so we're
trying that here.
James Jones [Mon, 27 Nov 2023 20:19:23 +0000 (14:19 -0600)]
Annotate return when exfile_open() fails (CID #
1206498 , #
1206499 )
Unfortunately, this is in the callers of exfile_open(), not
exfile_open() itself. Coverity doesn't notice that the mutex
is unlocked in exfile_open() if it fails, and we haven't been
able to model it, hence the annotations.
James Jones [Mon, 27 Nov 2023 19:52:00 +0000 (13:52 -0600)]
Annotate missing unlock in connection_spawn() (CID #
1414434 )
Coverity insists on unlocking mutexes in the same function
invocation the lock occurs in, but there are times when you
want exclusive use of a resource and thus lock it on allocation
and free on release, hence the annotation.
James Jones [Thu, 16 Nov 2023 20:42:44 +0000 (14:42 -0600)]
Revise a couple of uses of FR_TYPE_STRUCTURAL
FR_TYPE_STRUCTURAL has a name of the same form as the values of
fr_type_t, but is carefully #defined so it can appear in a switch
statement looking like a single value but underneath expanding to
multiple cases, making some of its uses counterintuitive.
Alan T. DeKok [Mon, 15 Jan 2024 18:53:15 +0000 (13:53 -0500)]
add missing '}'. Fixes #5264
Nick Porter [Fri, 12 Jan 2024 14:53:56 +0000 (14:53 +0000)]
More Tmp- attribute removal from tests
Nick Porter [Fri, 12 Jan 2024 12:23:34 +0000 (12:23 +0000)]
Remove Tmp- attributes from unit tests
Nick Porter [Thu, 11 Jan 2024 18:27:47 +0000 (18:27 +0000)]
Use triggers to detect readiness for LDAP sync tests
Already working for rfc4533 - no reason they should have issues for
other directories.
Nick Porter [Thu, 11 Jan 2024 17:48:10 +0000 (17:48 +0000)]
Better failure messages
Nick Porter [Thu, 11 Jan 2024 17:46:04 +0000 (17:46 +0000)]
Remove Tmp- attributes from LDAP sync tests
Nick Porter [Thu, 11 Jan 2024 17:42:56 +0000 (17:42 +0000)]
Minimise number of LDAP connections starting
Nick Porter [Thu, 11 Jan 2024 17:42:11 +0000 (17:42 +0000)]
Add cookie to LDAP sync start debug
Alan T. DeKok [Thu, 11 Jan 2024 16:27:06 +0000 (11:27 -0500)]
add "-t timeout" to radsniff
So that it will exit cleanly after a given timeout
Alan T. DeKok [Thu, 11 Jan 2024 14:06:27 +0000 (09:06 -0500)]
unix sockets need permissions, uid, and gid
Arran Cudbard-Bell [Thu, 11 Jan 2024 15:10:40 +0000 (10:10 -0500)]
'by' is not a name component
Nick Porter [Thu, 11 Jan 2024 11:21:10 +0000 (11:21 +0000)]
Assign tmpl on heap for async expansion
Nick Porter [Thu, 11 Jan 2024 10:44:28 +0000 (10:44 +0000)]
Fix ldap-setup CI script
Arran Cudbard-Bell [Wed, 10 Jan 2024 22:27:01 +0000 (17:27 -0500)]
Decrease trunk management verbosity
Alan T. DeKok [Wed, 10 Jan 2024 22:24:41 +0000 (17:24 -0500)]
add more debugging
Alan T. DeKok [Wed, 10 Jan 2024 14:48:52 +0000 (09:48 -0500)]
use type (SOCK_STREAM or SOCK_DGRAM) instead of IPPROTO
fr_socket_t can allegedly describe unix sockets. So let's get
started down that path.
Alan T. DeKok [Wed, 10 Jan 2024 13:05:05 +0000 (08:05 -0500)]
we can transition init -> connected
for connected datagram sockets, connect() generally returns "OK"
immediately.