]>
git.ipfire.org Git - thirdparty/freeradius-server.git/log
James Jones [Tue, 20 Aug 2024 18:22:25 +0000 (13:22 -0500)]
Range check buffer[1] to avoid tainted_data issue (CID #
1419883 )
Keeps it from falling off the edge of packet_name[]. Rather than
printing out a minimally informative "invalid" if it's out of
range, it will print the numerical value.
Nick Porter [Tue, 20 Aug 2024 09:48:11 +0000 (10:48 +0100)]
Re-work test for extended regex
So it doesn't hang on "lean" CI builds
Nick Porter [Tue, 20 Aug 2024 08:37:02 +0000 (09:37 +0100)]
original->flags is already in network byte order
Nick Porter [Mon, 19 Aug 2024 17:26:39 +0000 (18:26 +0100)]
RFC 2131 says DHCP replies copy flags from requests
Alan T. DeKok [Mon, 19 Aug 2024 14:39:02 +0000 (10:39 -0400)]
move "set open" to common function
Alan T. DeKok [Sun, 18 Aug 2024 21:13:56 +0000 (17:13 -0400)]
update for new fr_radius_encode() API
and call activate() from connect(), if the connection is already
open.
Alan T. DeKok [Mon, 19 Aug 2024 13:16:19 +0000 (09:16 -0400)]
call time start to bootstrap timing
Alan T. DeKok [Sat, 17 Aug 2024 12:55:42 +0000 (08:55 -0400)]
add "require_enum_prefix" migration flag
in preparation for moving to ::enum-name everywhere, which then
lets us drop the "&" prefix for attribute names
Alan T. DeKok [Sat, 17 Aug 2024 12:55:24 +0000 (08:55 -0400)]
simplify a bit
Alan T. DeKok [Fri, 16 Aug 2024 20:06:25 +0000 (16:06 -0400)]
allow cast to same data type to mean "print value, not enum name"
because I tried to use it, and it didn't work. So the logical
next step is to make it work.
Alan T. DeKok [Fri, 16 Aug 2024 13:58:46 +0000 (09:58 -0400)]
clean up casting a bit
James Jones [Fri, 16 Aug 2024 17:27:42 +0000 (12:27 -0500)]
Complete (and simplify) the pacification of Coverity (CD #
1604613 )
Handling the two-byte length case seems to have made Coverity gripe
about the one-byte case. We therefore change it so that one
Coverity-only check is done for both cases, reducing clutter.
James Jones [Wed, 14 Aug 2024 21:33:52 +0000 (16:33 -0500)]
Add Coverity-only check for two-byte length case (CID #
1604613 )
In fr_struct_to_network(), for structs prefixed by a length, the
length can be either one or two bytes. Space is set aside for it,
and when it comes time to encode it, you skip the appropriate number
of bytes and decrement length correspondingly. Coverity lets the one
byte length version pass without complaint, but in the two-byte
length case thinks length is 0 and hence underflows when 2 is subtracted
from it.
We add a Coverity-only check that returns an error if len < 2; it
never will be, but the check should persuade Coverity that at the
decrement, len will be at least 2.
Alan T. DeKok [Wed, 14 Aug 2024 13:42:24 +0000 (09:42 -0400)]
use the src enum for time resolution, not the dst enum
and add tests for it.
Nick Porter [Wed, 14 Aug 2024 09:14:30 +0000 (10:14 +0100)]
Fix crossbuild for Debian sid
Nick Porter [Wed, 14 Aug 2024 09:08:12 +0000 (10:08 +0100)]
More appropriate list of common cross builds
Nick Porter [Wed, 14 Aug 2024 08:21:10 +0000 (09:21 +0100)]
Debian sid has OpenSSL legacy providers in an optional package
Nick Porter [Wed, 14 Aug 2024 07:38:53 +0000 (08:38 +0100)]
Add rlm_sql_mysql driver option to set connection character set
Nick Porter [Wed, 14 Aug 2024 07:16:18 +0000 (08:16 +0100)]
UNUSED
Alan T. DeKok [Tue, 13 Aug 2024 20:57:19 +0000 (16:57 -0400)]
allow casting from something to specific time_delta resolutions
which creates an output value-box of type time_delta, and the
named time resolution.
Add a test.
update the calc code to include the time resolution / enumv when
doing box operations, so that we know how to properly compare things.
Alan T. DeKok [Tue, 13 Aug 2024 20:52:48 +0000 (16:52 -0400)]
add API to get enumv for time precision
Alan T. DeKok [Tue, 13 Aug 2024 15:34:42 +0000 (11:34 -0400)]
update Acct-Delay-Time calculations
Alan T. DeKok [Tue, 13 Aug 2024 15:33:05 +0000 (11:33 -0400)]
add test for (date - date --> uint32)
which should come out as seconds
Alan T. DeKok [Mon, 12 Aug 2024 20:29:45 +0000 (16:29 -0400)]
remove discussion of old attribute
Alan T. DeKok [Mon, 12 Aug 2024 20:16:24 +0000 (16:16 -0400)]
ifdef around registration, too
Alan T. DeKok [Mon, 12 Aug 2024 20:15:09 +0000 (16:15 -0400)]
print out actual attribute
Alan T. DeKok [Mon, 12 Aug 2024 17:09:06 +0000 (13:09 -0400)]
leave Acct-Delay-Time
but don't use it for anything
Arran Cudbard-Bell [Mon, 12 Aug 2024 13:13:29 +0000 (09:13 -0400)]
Check for EVP_blake2s256 and EVP_blake2b512 Closes #5399
Arran Cudbard-Bell [Mon, 12 Aug 2024 13:06:28 +0000 (09:06 -0400)]
Update autoconf.h.in with whatever the latest autoconf boilerplate is
Arran Cudbard-Bell [Mon, 12 Aug 2024 12:53:56 +0000 (08:53 -0400)]
Quiet warning
Alan T. DeKok [Mon, 12 Aug 2024 12:19:19 +0000 (08:19 -0400)]
if (!event-timestamp) event-timestamp = now - Acct-Delay-Time
Alan T. DeKok [Mon, 12 Aug 2024 02:19:13 +0000 (22:19 -0400)]
we can always retransmit Status-Server checks
there's no benefit to re-encoding them every time.
Alan T. DeKok [Mon, 12 Aug 2024 02:14:29 +0000 (22:14 -0400)]
don't add Proxy-State to "ping" packets
Alan T. DeKok [Mon, 12 Aug 2024 02:09:24 +0000 (22:09 -0400)]
remove Acct-Delay-Time
If we receive an accounting packet, add Event-Timestamp if it's
not already in the packet.
If the packet contains Acct-Delay-Time, then subtract that from
Event-Timestamp, and delete Acct-Delay-Time.
Acct-Delay-Time causes too many issues with proxying and retransmissions.
Alan T. DeKok [Mon, 12 Aug 2024 01:32:24 +0000 (21:32 -0400)]
remove AcctStartDelay.
it hasn't ever been used, either.
Alan T. DeKok [Mon, 12 Aug 2024 01:29:38 +0000 (21:29 -0400)]
remove AcctStopDelay from Oracle and MS-SQL.
It hasn't been used. Ever.
Alan T. DeKok [Mon, 12 Aug 2024 01:13:18 +0000 (21:13 -0400)]
remove unneeded code
Alan T. DeKok [Sun, 11 Aug 2024 22:27:07 +0000 (18:27 -0400)]
quiet compiler
Alan T. DeKok [Sun, 11 Aug 2024 22:09:29 +0000 (18:09 -0400)]
don't set "require_message_authenticator" from AUTO for EAP
if the request contains EAP, then the reply has to contain EAP,
and both packets have to contain Message-Authenticator
Alan T. DeKok [Sun, 11 Aug 2024 22:06:19 +0000 (18:06 -0400)]
hoist Proxy-State checks to main encoder
in preparation for moving rlm_radius to the new BIO code
Alan T. DeKok [Sun, 11 Aug 2024 21:46:37 +0000 (17:46 -0400)]
move "secure_transport" to common data structure
Alan T. DeKok [Sun, 11 Aug 2024 21:29:41 +0000 (17:29 -0400)]
typo
Alan T. DeKok [Sun, 11 Aug 2024 21:08:46 +0000 (17:08 -0400)]
ignore Message-Authenticator in replies
Alan T. DeKok [Sun, 11 Aug 2024 20:37:34 +0000 (16:37 -0400)]
don't automatically add Message-Authenticator for tests
Alan T. DeKok [Sun, 11 Aug 2024 20:32:16 +0000 (16:32 -0400)]
Revert "don't use packet->vector for CHAP-Challenge"
This reverts commit
1df03034d952d9fa473fd9da6fae22308945d194 .
Alan T. DeKok [Sun, 11 Aug 2024 20:30:33 +0000 (16:30 -0400)]
move "add Message-Authenticator" functionality to core encoder
Alan T. DeKok [Sun, 11 Aug 2024 20:19:30 +0000 (16:19 -0400)]
typo
Alan T. DeKok [Sun, 11 Aug 2024 20:19:18 +0000 (16:19 -0400)]
go to next VP on skip
Alan T. DeKok [Sun, 11 Aug 2024 19:48:02 +0000 (15:48 -0400)]
don't use packet->vector for CHAP-Challenge
use packet->data + 4
arguably the RADIUS protocol decoder should synthesize the
CHAP-Challenge if it's not in the packet, as that would make
the rest of the code simpler.
Alan T. DeKok [Sun, 11 Aug 2024 19:47:37 +0000 (15:47 -0400)]
use correct type
Alan T. DeKok [Sun, 11 Aug 2024 19:36:33 +0000 (15:36 -0400)]
don't set packet->vector for non-RADIUS protocols
and most of those were wrong, too :(
Alan T. DeKok [Sun, 11 Aug 2024 19:34:47 +0000 (15:34 -0400)]
we no longer use packet->vector for anything DHCPv4
Alan T. DeKok [Sun, 11 Aug 2024 19:33:13 +0000 (15:33 -0400)]
don't smash the authentication vector
Alan T. DeKok [Sun, 11 Aug 2024 18:18:25 +0000 (14:18 -0400)]
pass dbuff && packet_ctx to encode function
which makes it easier to add more functionality
Alan T. DeKok [Sun, 11 Aug 2024 16:30:14 +0000 (12:30 -0400)]
point to common context, instead of local struct
Alan T. DeKok [Sun, 11 Aug 2024 16:17:15 +0000 (12:17 -0400)]
make common context "const"
Alan T. DeKok [Sun, 11 Aug 2024 16:11:38 +0000 (12:11 -0400)]
remove vector[] from common encode/decode context
Alan T. DeKok [Sun, 11 Aug 2024 13:59:35 +0000 (09:59 -0400)]
remove duplicate API as part of cleanup
there isn't much point in switching to a new API if we don't
switch to a new API
Alan T. DeKok [Sun, 11 Aug 2024 13:44:40 +0000 (09:44 -0400)]
clean up API and simplify
no need to pass buffer / size twice to the receive function,
it's already in the dedup_ctx
Alan T. DeKok [Sun, 11 Aug 2024 13:44:22 +0000 (09:44 -0400)]
for simplicity, put rb node into dedup context
Alan T. DeKok [Sun, 11 Aug 2024 13:29:58 +0000 (09:29 -0400)]
don't encode Message-Authenticator multiple times
Alan T. DeKok [Fri, 9 Aug 2024 23:22:38 +0000 (19:22 -0400)]
use pctx for packet ctx
Alan T. DeKok [Fri, 9 Aug 2024 19:48:05 +0000 (15:48 -0400)]
allow setting CoA filter attribute name
Alan T. DeKok [Fri, 9 Aug 2024 15:09:41 +0000 (11:09 -0400)]
Revert "Add Coverity-only check to pacify it (CID #
1604609 )"
This reverts commit
aa37659f220f4d0a338ab98ad4fd3110a6082fdf .
Alan T. DeKok [Fri, 9 Aug 2024 12:19:12 +0000 (08:19 -0400)]
link in radiusd -X
Alan T. DeKok [Fri, 9 Aug 2024 12:07:13 +0000 (08:07 -0400)]
point to new files
Alan T. DeKok [Fri, 9 Aug 2024 12:06:13 +0000 (08:06 -0400)]
print out only at end, to avoid dups
Alan T. DeKok [Fri, 9 Aug 2024 12:03:10 +0000 (08:03 -0400)]
point to correct link
Alan T. DeKok [Thu, 8 Aug 2024 21:33:18 +0000 (17:33 -0400)]
script to cross-check antora files
Alan T. DeKok [Thu, 8 Aug 2024 21:32:34 +0000 (17:32 -0400)]
this is a new module
Alan T. DeKok [Thu, 8 Aug 2024 21:15:10 +0000 (17:15 -0400)]
moved to better location
aBainbridge11 [Tue, 30 Jul 2024 19:54:34 +0000 (15:54 -0400)]
Update index.adoc
aBainbridge11 [Tue, 30 Jul 2024 19:45:30 +0000 (15:45 -0400)]
Create Alcatel-Lucent
aBainbridge11 [Tue, 30 Jul 2024 19:24:13 +0000 (15:24 -0400)]
Create Huawei
aBainbridge11 [Tue, 30 Jul 2024 19:23:27 +0000 (15:23 -0400)]
Create HP
aBainbridge11 [Tue, 30 Jul 2024 18:52:30 +0000 (14:52 -0400)]
Update cisco.adoc
aBainbridge11 [Tue, 30 Jul 2024 18:40:02 +0000 (14:40 -0400)]
Create Alvarion
aBainbridge11 [Tue, 30 Jul 2024 18:29:53 +0000 (14:29 -0400)]
Update index.adoc
aBainbridge11 [Tue, 30 Jul 2024 18:17:52 +0000 (14:17 -0400)]
Create EAP PEAP
aBainbridge11 [Tue, 30 Jul 2024 16:57:20 +0000 (12:57 -0400)]
Create Disconnect Messages
aBainbridge11 [Mon, 29 Jul 2024 19:28:46 +0000 (15:28 -0400)]
Create Twitter
aBainbridge11 [Mon, 29 Jul 2024 19:18:27 +0000 (15:18 -0400)]
Create Stats with radsniff
aBainbridge11 [Mon, 29 Jul 2024 19:12:49 +0000 (15:12 -0400)]
Create Raduat
aBainbridge11 [Mon, 29 Jul 2024 19:08:08 +0000 (15:08 -0400)]
Create radiusd -X
aBainbridge11 [Mon, 29 Jul 2024 18:42:22 +0000 (14:42 -0400)]
Create Eduroam Configuration
aBainbridge11 [Mon, 29 Jul 2024 18:33:57 +0000 (14:33 -0400)]
Create Logging in an eduroam environment
aBainbridge11 [Mon, 29 Jul 2024 18:31:14 +0000 (14:31 -0400)]
Create EAP-SIM and EAP-AKA:
aBainbridge11 [Mon, 29 Jul 2024 16:27:22 +0000 (12:27 -0400)]
Create Troubleshooting
aBainbridge11 [Mon, 29 Jul 2024 16:05:39 +0000 (12:05 -0400)]
Create Red Hat FAQ
aBainbridge11 [Mon, 29 Jul 2024 15:09:42 +0000 (11:09 -0400)]
Create Git config management
aBainbridge11 [Fri, 26 Jul 2024 19:58:30 +0000 (15:58 -0400)]
Create FAQ
aBainbridge11 [Fri, 26 Jul 2024 18:59:19 +0000 (14:59 -0400)]
Create RADIUS Concepts
aBainbridge11 [Fri, 26 Jul 2024 16:59:27 +0000 (12:59 -0400)]
Create Wired Equivalent Privacy
aBainbridge11 [Fri, 26 Jul 2024 16:49:12 +0000 (12:49 -0400)]
Create WPA
aBainbridge11 [Fri, 26 Jul 2024 16:26:22 +0000 (12:26 -0400)]
Create RFC Compliance
aBainbridge11 [Fri, 26 Jul 2024 16:11:03 +0000 (12:11 -0400)]
Create RADIUS
aBainbridge11 [Fri, 26 Jul 2024 15:47:38 +0000 (11:47 -0400)]
Create NAC
aBainbridge11 [Fri, 26 Jul 2024 15:42:40 +0000 (11:42 -0400)]
Create NAS
aBainbridge11 [Tue, 23 Jul 2024 18:38:22 +0000 (14:38 -0400)]
Create Virtual Servers
aBainbridge11 [Tue, 23 Jul 2024 18:16:04 +0000 (14:16 -0400)]
Create Performance