]> git.ipfire.org Git - thirdparty/freeradius-server.git/log
thirdparty/freeradius-server.git
13 months agoMove all rlm_crl tests to one file
Nick Porter [Tue, 17 Jun 2025 20:07:41 +0000 (21:07 +0100)] 
Move all rlm_crl tests to one file

To avoid parallel runs conflicting - OpenSSL appears to sometimes get in
a mess if there are parallel attempts to sign / revoke / create crl

13 months agoreturn fail on LHS expansion failed, too
Alan T. DeKok [Tue, 17 Jun 2025 17:11:56 +0000 (13:11 -0400)] 
return fail on LHS expansion failed, too

13 months agofailed expanding RHS xlat is an rcode FAIL
Alan T. DeKok [Tue, 17 Jun 2025 15:44:23 +0000 (11:44 -0400)] 
failed expanding RHS xlat is an rcode FAIL

13 months agoadd test to match padding commit b3f996f
Alan T. DeKok [Tue, 17 Jun 2025 11:20:19 +0000 (07:20 -0400)] 
add test to match padding commit b3f996f

13 months agoWalk over DHCPv4 padding option rather than returning NULL
Nick Porter [Tue, 17 Jun 2025 09:22:02 +0000 (10:22 +0100)] 
Walk over DHCPv4 padding option rather than returning NULL

Some clients put padding in the middle of packets - so the option we're
looking for may be after the padding.

13 months agoLook up interface packet was received on if inst->interface not set
Nick Porter [Tue, 17 Jun 2025 08:55:46 +0000 (09:55 +0100)] 
Look up interface packet was received on if inst->interface not set

Allows a DHCP server to be set to listen on 0.0.0.0 and not bound to a
specific interface to handle broadcast DHCP requests on multiple
interfaces.

13 months agoSet IP_RECVIF on BSD sockets to get interface details
Nick Porter [Mon, 16 Jun 2025 18:33:03 +0000 (19:33 +0100)] 
Set IP_RECVIF on BSD sockets to get interface details

13 months agoScheduled fuzzing: Update src/tests/fuzzer-corpus/cbor.tar
github-actions[bot] [Tue, 17 Jun 2025 04:34:25 +0000 (04:34 +0000)] 
Scheduled fuzzing: Update src/tests/fuzzer-corpus/cbor.tar

13 months agoScheduled fuzzing: Update src/tests/fuzzer-corpus/der.tar
github-actions[bot] [Tue, 17 Jun 2025 04:31:10 +0000 (04:31 +0000)] 
Scheduled fuzzing: Update src/tests/fuzzer-corpus/der.tar

13 months agoset error only if it failed
Alan T. DeKok [Mon, 16 Jun 2025 18:01:01 +0000 (14:01 -0400)] 
set error only if it failed

13 months agoAdd CHAP to radclient tests
Nick Porter [Mon, 16 Jun 2025 11:15:44 +0000 (12:15 +0100)] 
Add CHAP to radclient tests

13 months agoCreate CHAP-Challenge attribute if not set
Nick Porter [Mon, 16 Jun 2025 10:35:56 +0000 (11:35 +0100)] 
Create CHAP-Challenge attribute if not set

fr_packet_sign() re-calculates the request authenticator, so it can't be
used as CHAP-Challenge

13 months agoCHAP-Challenge is not fixed to 16 octets
Nick Porter [Mon, 16 Jun 2025 09:53:04 +0000 (10:53 +0100)] 
CHAP-Challenge is not fixed to 16 octets

RFC2865 says min length is 7

13 months agoRemove Password.Cleartext from expected radclient test output
Nick Porter [Mon, 16 Jun 2025 10:40:26 +0000 (11:40 +0100)] 
Remove Password.Cleartext from expected radclient test output

13 months agoNo need to copy User-Password to Password.Cleartext
Nick Porter [Mon, 16 Jun 2025 09:47:15 +0000 (10:47 +0100)] 
No need to copy User-Password to Password.Cleartext

13 months agoSet prefix length so address comparisons work
Nick Porter [Mon, 16 Jun 2025 08:02:05 +0000 (09:02 +0100)] 
Set prefix length so address comparisons work

fr_ipaddr_cmp() uses prefix len  to determine how many bits to compare

13 months agoAssociate a dictionary with %<proto>.decode xlats
Nick Porter [Fri, 13 Jun 2025 16:08:59 +0000 (17:08 +0100)] 
Associate a dictionary with %<proto>.decode xlats

And check that protocol decoders are only called in the correct
namespace.

13 months agoMove fr_der_decode_ctx_t definition to header
Nick Porter [Fri, 13 Jun 2025 16:00:41 +0000 (17:00 +0100)] 
Move fr_der_decode_ctx_t definition to header

So other modules can create a decode ctx when using der decoder

13 months agoMove dict_der to attrs.h
Nick Porter [Fri, 13 Jun 2025 15:43:29 +0000 (16:43 +0100)] 
Move dict_der to attrs.h

So der.h can be included in modules with their own `dict_der` without
conflicts.

13 months agoRemove unused variable
Nick Porter [Fri, 13 Jun 2025 15:35:40 +0000 (16:35 +0100)] 
Remove unused variable

13 months agoEnsure header only included once
Nick Porter [Fri, 13 Jun 2025 15:06:23 +0000 (16:06 +0100)] 
Ensure header only included once

13 months agodocs: v3-v4 markup with warning HIVE 3608
nolade [Wed, 11 Jun 2025 14:23:55 +0000 (10:23 -0400)] 
docs: v3-v4 markup with warning HIVE 3608

13 months agoif (failed expansion) --> fail
Alan T. DeKok [Mon, 9 Jun 2025 20:01:19 +0000 (16:01 -0400)] 
if (failed expansion) --> fail

unless it's followed by an "else" or "elsif".

With documentation updates and fixed tests

13 months agoprint comparisons and binary ops better
Alan T. DeKok [Tue, 10 Jun 2025 01:33:05 +0000 (21:33 -0400)] 
print comparisons and binary ops better

as FOO op BAR, not %cmp_lt(FOO, BAR)

13 months agouse ... for ignored data, as with other messages
Alan T. DeKok [Tue, 10 Jun 2025 01:32:44 +0000 (21:32 -0400)] 
use ... for ignored data, as with other messages

13 months agouse :=, to force the assignment
Alan T. DeKok [Mon, 9 Jun 2025 19:44:56 +0000 (15:44 -0400)] 
use :=, to force the assignment

13 months agoCapture Module-Failure-Message from verify certificate subrequest
Nick Porter [Fri, 13 Jun 2025 07:44:49 +0000 (08:44 +0100)] 
Capture Module-Failure-Message from verify certificate subrequest

13 months agoReport revoked certificates as errors
Nick Porter [Thu, 12 Jun 2025 18:26:12 +0000 (19:26 +0100)] 
Report revoked certificates as errors

To populate Module-Failure-Reason

13 months agoRemove redundant header
Nick Porter [Thu, 12 Jun 2025 17:03:56 +0000 (18:03 +0100)] 
Remove redundant header

13 months agoDelta CRLs can reference an older base than the current
Nick Porter [Thu, 12 Jun 2025 17:03:21 +0000 (18:03 +0100)] 
Delta CRLs can reference an older base than the current

So no need to expire the deltas when a base expires

13 months agoReport CRL numbers when there is a mis-match error
Nick Porter [Thu, 12 Jun 2025 17:01:23 +0000 (18:01 +0100)] 
Report CRL numbers when there is a mis-match error

13 months agoRemove incorrect comment
Nick Porter [Thu, 12 Jun 2025 12:06:10 +0000 (13:06 +0100)] 
Remove incorrect comment

13 months agoRemove comment - mod_load no longer initialises libcurl
Nick Porter [Thu, 12 Jun 2025 11:57:13 +0000 (12:57 +0100)] 
Remove comment - mod_load no longer initialises libcurl

13 months agoRemove unnecessary includes
Nick Porter [Thu, 12 Jun 2025 11:56:14 +0000 (12:56 +0100)] 
Remove unnecessary includes

13 months agoUse separate CRL file for each test
Nick Porter [Thu, 12 Jun 2025 07:45:25 +0000 (08:45 +0100)] 
Use separate CRL file for each test

To avoid conflicts when running in parallel

13 months agoAdd application/pkix-crl to known REST Content-Type values
Nick Porter [Thu, 12 Jun 2025 07:30:08 +0000 (08:30 +0100)] 
Add application/pkix-crl to known REST Content-Type values

13 months ago%M is supposed to be microseconds, not milliseconds
Nick Porter [Thu, 12 Jun 2025 07:19:30 +0000 (08:19 +0100)] 
%M is supposed to be microseconds, not milliseconds

13 months agoCorrect module name
Nick Porter [Wed, 11 Jun 2025 13:05:07 +0000 (14:05 +0100)] 
Correct module name

13 months agoCan't test rlm_crl if FreeRADIUS was built without SSL
Nick Porter [Wed, 11 Jun 2025 09:04:22 +0000 (10:04 +0100)] 
Can't test rlm_crl if FreeRADIUS was built without SSL

13 months agoAdd basic tests of rlm_crl
Nick Porter [Wed, 11 Jun 2025 08:01:23 +0000 (09:01 +0100)] 
Add basic tests of rlm_crl

13 months agoSet allow_core_dumps to yes for developer builds
Nick Porter [Tue, 10 Jun 2025 15:07:25 +0000 (16:07 +0100)] 
Set allow_core_dumps to yes for developer builds

Required to allow debuggers to attach to processes.

13 months agoCorrect ZSCORE check after unassigning a static IP
Nick Porter [Tue, 10 Jun 2025 14:01:12 +0000 (15:01 +0100)] 
Correct ZSCORE check after unassigning a static IP

Particularly when running under sanitizers, %l ends up in the past

13 months agoRemove stray %
Nick Porter [Tue, 10 Jun 2025 13:36:29 +0000 (14:36 +0100)] 
Remove stray %

13 months agoAllow reading binary data using rlm_exec
Nick Porter [Tue, 10 Jun 2025 09:11:41 +0000 (10:11 +0100)] 
Allow reading binary data using rlm_exec

13 months agoUpdate rlm_mruby docs from raddb
Nick Porter [Tue, 10 Jun 2025 08:20:34 +0000 (09:20 +0100)] 
Update rlm_mruby docs from raddb

13 months agoFix RHEL packaging for rlm_mruby
Nick Porter [Tue, 10 Jun 2025 08:17:35 +0000 (09:17 +0100)] 
Fix RHEL packaging for rlm_mruby

13 months agoMove sample Ruby to raddb so it gets packaged
Nick Porter [Tue, 10 Jun 2025 07:43:16 +0000 (08:43 +0100)] 
Move sample Ruby to raddb so it gets packaged

13 months agoTidy sample Ruby
Nick Porter [Tue, 10 Jun 2025 07:40:50 +0000 (08:40 +0100)] 
Tidy sample Ruby

13 months agoUpdate mruby sample config with notes on attribute access
Nick Porter [Tue, 10 Jun 2025 07:39:07 +0000 (08:39 +0100)] 
Update mruby sample config with notes on attribute access

13 months agoAdd tests of pair list access from mruby
Nick Porter [Mon, 9 Jun 2025 19:10:38 +0000 (20:10 +0100)] 
Add tests of pair list access from mruby

13 months agoDon't run instantiate module if it doesn't exist
Nick Porter [Mon, 9 Jun 2025 18:12:04 +0000 (19:12 +0100)] 
Don't run instantiate module if it doesn't exist

13 months agoAdd `append` method to mruby Pair class
Nick Porter [Mon, 9 Jun 2025 17:24:32 +0000 (18:24 +0100)] 
Add `append` method to mruby Pair class

To add an instance of an attribute

13 months agoAdd `del` method to mruby Pair class
Nick Porter [Mon, 9 Jun 2025 16:46:22 +0000 (17:46 +0100)] 
Add `del` method to mruby Pair class

13 months agoRemove redundant mruby add_vp_tuple
Nick Porter [Mon, 9 Jun 2025 16:32:35 +0000 (17:32 +0100)] 
Remove redundant mruby add_vp_tuple

13 months agoOnly allow fixednum return now mruby can set pairs directly
Nick Porter [Mon, 9 Jun 2025 16:29:26 +0000 (17:29 +0100)] 
Only allow fixednum return now mruby can set pairs directly

13 months agoRemove mruby pair list marshalling functions
Nick Porter [Mon, 9 Jun 2025 16:14:33 +0000 (17:14 +0100)] 
Remove mruby pair list marshalling functions

13 months agoReport what is being called
Nick Porter [Mon, 9 Jun 2025 16:11:13 +0000 (17:11 +0100)] 
Report what is being called

13 months agoUse mruby PairList class for passing list roots to module method
Nick Porter [Mon, 9 Jun 2025 16:10:45 +0000 (17:10 +0100)] 
Use mruby PairList class for passing list roots to module method

13 months agoAdd `method_missing` method to mruby PairList class
Nick Porter [Mon, 9 Jun 2025 16:09:16 +0000 (17:09 +0100)] 
Add `method_missing` method to mruby PairList class

To allow access to child attributes.

13 months agoAdd `set` method to mruby Pair class
Nick Porter [Mon, 9 Jun 2025 15:51:06 +0000 (16:51 +0100)] 
Add `set` method to mruby Pair class

To set pair values

13 months agoAdd `get` method to mruby Pair class
Nick Porter [Mon, 9 Jun 2025 15:49:33 +0000 (16:49 +0100)] 
Add `get` method to mruby Pair class

For getting the value of the pair.

13 months agoAdd `keys` method to mruby PairList
Nick Porter [Mon, 9 Jun 2025 15:47:47 +0000 (16:47 +0100)] 
Add `keys` method to mruby PairList

To fetch a list of child attributes

13 months agoAdd mruby Pair class
Nick Porter [Mon, 9 Jun 2025 15:40:39 +0000 (16:40 +0100)] 
Add mruby Pair class

For leaf pairs

13 months agoDefine mruby PairList class and its initialize function
Nick Porter [Mon, 9 Jun 2025 15:35:53 +0000 (16:35 +0100)] 
Define mruby PairList class and its initialize function

for holding structural pairs

13 months agoChange default mruby module name to FreeRADIUS
Nick Porter [Mon, 9 Jun 2025 15:30:57 +0000 (16:30 +0100)] 
Change default mruby module name to FreeRADIUS

13 months agoAdd Ptr class to use for passing C pointers
Nick Porter [Mon, 9 Jun 2025 15:29:51 +0000 (16:29 +0100)] 
Add Ptr class to use for passing C pointers

13 months agoDefine mruby_pair_t
Nick Porter [Mon, 9 Jun 2025 15:22:52 +0000 (16:22 +0100)] 
Define mruby_pair_t

For holding C data pointers associated with a pair in mruby objects

13 months agoDefine mruby data types and functions for accessing C data pointers
Nick Porter [Mon, 9 Jun 2025 15:14:15 +0000 (16:14 +0100)] 
Define mruby data types and functions for accessing C data pointers

13 months agoMove rlm_mruby_t definition to shared header
Nick Porter [Mon, 9 Jun 2025 15:18:10 +0000 (16:18 +0100)] 
Move rlm_mruby_t definition to shared header

13 months agoPacify Coverity (CID #1648478)
Nick Porter [Mon, 9 Jun 2025 07:48:48 +0000 (08:48 +0100)] 
Pacify Coverity (CID #1648478)

It doesn't understand about required xlat args

13 months agoCheck box is allocated (CID #1648479)
Nick Porter [Mon, 9 Jun 2025 07:45:16 +0000 (08:45 +0100)] 
Check box is allocated (CID #1648479)

13 months agoScheduled fuzzing: Update src/tests/fuzzer-corpus/radius.tar
github-actions[bot] [Mon, 9 Jun 2025 04:33:40 +0000 (04:33 +0000)] 
Scheduled fuzzing: Update src/tests/fuzzer-corpus/radius.tar

13 months agoScheduled fuzzing: Update src/tests/fuzzer-corpus/bfd.tar
github-actions[bot] [Mon, 9 Jun 2025 04:33:31 +0000 (04:33 +0000)] 
Scheduled fuzzing: Update src/tests/fuzzer-corpus/bfd.tar

13 months agoScheduled fuzzing: Update src/tests/fuzzer-corpus/dns.tar
github-actions[bot] [Mon, 9 Jun 2025 04:33:16 +0000 (04:33 +0000)] 
Scheduled fuzzing: Update src/tests/fuzzer-corpus/dns.tar

13 months agoScheduled fuzzing: Update src/tests/fuzzer-corpus/dhcpv6.tar
github-actions[bot] [Mon, 9 Jun 2025 04:32:40 +0000 (04:32 +0000)] 
Scheduled fuzzing: Update src/tests/fuzzer-corpus/dhcpv6.tar

13 months agoScheduled fuzzing: Update src/tests/fuzzer-corpus/dhcpv4.tar
github-actions[bot] [Mon, 9 Jun 2025 04:32:37 +0000 (04:32 +0000)] 
Scheduled fuzzing: Update src/tests/fuzzer-corpus/dhcpv4.tar

13 months agoScheduled fuzzing: Update src/tests/fuzzer-corpus/util.tar
github-actions[bot] [Mon, 9 Jun 2025 04:32:22 +0000 (04:32 +0000)] 
Scheduled fuzzing: Update src/tests/fuzzer-corpus/util.tar

13 months agoScheduled fuzzing: Update src/tests/fuzzer-corpus/tftp.tar
github-actions[bot] [Mon, 9 Jun 2025 04:31:47 +0000 (04:31 +0000)] 
Scheduled fuzzing: Update src/tests/fuzzer-corpus/tftp.tar

13 months agoScheduled fuzzing: Update src/tests/fuzzer-corpus/vmps.tar
github-actions[bot] [Mon, 9 Jun 2025 04:31:10 +0000 (04:31 +0000)] 
Scheduled fuzzing: Update src/tests/fuzzer-corpus/vmps.tar

13 months agoScheduled fuzzing: Update src/tests/fuzzer-corpus/tacacs.tar
github-actions[bot] [Mon, 9 Jun 2025 04:30:34 +0000 (04:30 +0000)] 
Scheduled fuzzing: Update src/tests/fuzzer-corpus/tacacs.tar

14 months agoAdd rlm_crl docs from sample config
Nick Porter [Thu, 5 Jun 2025 08:53:59 +0000 (09:53 +0100)] 
Add rlm_crl docs from sample config

14 months agoUpdate docs from raddb changes
Nick Porter [Thu, 5 Jun 2025 08:24:17 +0000 (09:24 +0100)] 
Update docs from raddb changes

14 months agoDocument %ldap.uri.attr_option
Nick Porter [Thu, 5 Jun 2025 08:20:43 +0000 (09:20 +0100)] 
Document %ldap.uri.attr_option

14 months agoAdd tests of %ldap.uri.attr_option
Nick Porter [Thu, 5 Jun 2025 08:17:00 +0000 (09:17 +0100)] 
Add tests of %ldap.uri.attr_option

14 months agoAdd %ldap.uri.attr_option
Nick Porter [Thu, 5 Jun 2025 08:16:20 +0000 (09:16 +0100)] 
Add %ldap.uri.attr_option

14 months agoPacify Coverity (CID #1648447)
Nick Porter [Thu, 5 Jun 2025 07:21:37 +0000 (08:21 +0100)] 
Pacify Coverity (CID #1648447)

14 months agoCheck return value (CID #1648446)
Nick Porter [Thu, 5 Jun 2025 07:05:12 +0000 (08:05 +0100)] 
Check return value (CID #1648446)

14 months agoCheck return code from base CRL lookup
Nick Porter [Wed, 4 Jun 2025 19:12:52 +0000 (20:12 +0100)] 
Check return code from base CRL lookup

14 months agorlm_crl requires OpenSSL to build
Nick Porter [Wed, 4 Jun 2025 19:09:42 +0000 (20:09 +0100)] 
rlm_crl requires OpenSSL to build

14 months agoAdd rlm_crl to RHEL packaging
Nick Porter [Wed, 4 Jun 2025 18:46:01 +0000 (19:46 +0100)] 
Add rlm_crl to RHEL packaging

14 months agoAllow soft failure when ldap expansion is not configured
Nick Porter [Wed, 4 Jun 2025 18:31:36 +0000 (19:31 +0100)] 
Allow soft failure when ldap expansion is not configured

14 months agoWhen a base CRL expires, expire the deltas
Nick Porter [Wed, 4 Jun 2025 10:07:45 +0000 (11:07 +0100)] 
When a base CRL expires, expire the deltas

Since deltas are changes from a base, they need to be re-fetched when
the base changes

14 months agoLimit extracted CDP to those covering all reasons
Nick Porter [Wed, 4 Jun 2025 08:31:05 +0000 (09:31 +0100)] 
Limit extracted CDP to those covering all reasons

We want the full picture for doing CRL checks - so no need to handle
segmented CRLs.

RFC5280 page 47:

When a conforming CA includes a cRLDistributionPoints extension in a
certificate, it MUST include at least one DistributionPoint that points
to a CRL that covers the certificate for all reasons.

14 months agoAdd crlNumber to dummy CRL
Nick Porter [Wed, 4 Jun 2025 08:05:49 +0000 (09:05 +0100)] 
Add crlNumber to dummy CRL

14 months agoAdd notes on CDP with ldap:/// prefix
Nick Porter [Wed, 4 Jun 2025 08:03:54 +0000 (09:03 +0100)] 
Add notes on CDP with ldap:/// prefix

14 months agoCheck for delta CRL in crl_check_serial
Nick Porter [Wed, 4 Jun 2025 07:45:27 +0000 (08:45 +0100)] 
Check for delta CRL in crl_check_serial

And fetch the delta if we don't already have it.

14 months agoReturn found crl entry from crl_check_serial
Nick Porter [Wed, 4 Jun 2025 07:40:33 +0000 (08:40 +0100)] 
Return found crl entry from crl_check_serial

So base CRL can be referenced when fetching a delta

14 months agoHaving retrieved a base CRL, check the delta if the CRL has it defined
Nick Porter [Wed, 4 Jun 2025 07:33:48 +0000 (08:33 +0100)] 
Having retrieved a base CRL, check the delta if the CRL has it defined

Deltas can have more than one URI for HA.
If none of the delta CRLs are available then re-use the same mechanism
to fetch one.

14 months agoAllow different forced expiry interval for delta CRLs
Nick Porter [Wed, 4 Jun 2025 07:08:59 +0000 (08:08 +0100)] 
Allow different forced expiry interval for delta CRLs

Typically delta CRLs are published more frequently than base ones, so
may require a shorter forced expiry interval.

14 months agoUse reference to base_crl to indicate we're reading data from a delta
Nick Porter [Wed, 4 Jun 2025 07:05:36 +0000 (08:05 +0100)] 
Use reference to base_crl to indicate we're reading data from a delta