|
version 1.1.1.1, 2012/02/21 23:32:47
|
version 1.1.1.4.2.1, 2023/09/27 11:08:01
|
|
Line 5
|
Line 5
|
| * Written by Alexander Motin <mav@FreeBSD.org> |
* Written by Alexander Motin <mav@FreeBSD.org> |
| */ |
*/ |
| |
|
| |
#define RADSRV |
| |
|
| #include "ppp.h" |
#include "ppp.h" |
| #include "radsrv.h" |
#include "radsrv.h" |
| #include "util.h" |
#include "util.h" |
| |
|
| |
#include <stdint.h> |
| #include <radlib.h> |
#include <radlib.h> |
| #include <radlib_vs.h> |
#include <radlib_vs.h> |
| |
|
|
Line 32
|
Line 36
|
| * INTERNAL FUNCTIONS |
* INTERNAL FUNCTIONS |
| */ |
*/ |
| |
|
| static int RadsrvSetCommand(Context ctx, int ac, char *av[], void *arg); | static int RadsrvSetCommand(Context ctx, int ac, const char *const av[], const void *arg); |
| |
|
| /* |
/* |
| * GLOBAL VARIABLES |
* GLOBAL VARIABLES |
|
Line 51
|
Line 55
|
| RadsrvSetCommand, NULL, 2, (void *) SET_ENABLE }, |
RadsrvSetCommand, NULL, 2, (void *) SET_ENABLE }, |
| { "disable [opt ...]", "Disable radsrv option" , |
{ "disable [opt ...]", "Disable radsrv option" , |
| RadsrvSetCommand, NULL, 2, (void *) SET_DISABLE }, |
RadsrvSetCommand, NULL, 2, (void *) SET_DISABLE }, |
| { NULL }, | { NULL, NULL, NULL, NULL, 0, NULL }, |
| }; |
}; |
| |
|
| |
|
|
Line 97 RadsrvEvent(int type, void *cookie)
|
Line 101 RadsrvEvent(int type, void *cookie)
|
| char *username = NULL, *called = NULL, *calling = NULL, *sesid = NULL; |
char *username = NULL, *called = NULL, *calling = NULL, *sesid = NULL; |
| char *msesid = NULL, *link = NULL, *bundle = NULL, *iface = NULL; |
char *msesid = NULL, *link = NULL, *bundle = NULL, *iface = NULL; |
| int nasport = -1, serv_type = 0, ifindex = -1, i; |
int nasport = -1, serv_type = 0, ifindex = -1, i; |
| u_int session_timeout = -1, idle_timeout = -1, acct_update = -1; | u_int session_timeout = UINT_MAX, idle_timeout = UINT_MAX; |
| struct in_addr ip = { -1 }; | u_int acct_update = UINT_MAX; |
| struct in_addr nas_ip = { -1 }; | struct in_addr ip = { INADDR_BROADCAST }; |
| | struct in_addr nas_ip = { INADDR_BROADCAST }; |
| char buf[64]; |
char buf[64]; |
| u_int32_t vendor; |
u_int32_t vendor; |
| u_char *state = NULL; | u_char *state = NULL, *rad_class = NULL; |
| int state_len = 0; |
int state_len = 0; |
| |
int class_len = 0; |
| int authentic = 0; |
int authentic = 0; |
| #if defined(USE_NG_BPF) || defined(USE_IPFW) |
#if defined(USE_NG_BPF) || defined(USE_IPFW) |
| struct acl **acls, *acls1; |
struct acl **acls, *acls1; |
|
Line 120 RadsrvEvent(int type, void *cookie)
|
Line 126 RadsrvEvent(int type, void *cookie)
|
| struct acl *acl_limits[ACL_DIRS]; /* traffic limits based on mpd's filters */ |
struct acl *acl_limits[ACL_DIRS]; /* traffic limits based on mpd's filters */ |
| char std_acct[ACL_DIRS][ACL_NAME_LEN]; /* Names of ACL returned in standard accounting */ |
char std_acct[ACL_DIRS][ACL_NAME_LEN]; /* Names of ACL returned in standard accounting */ |
| |
|
| |
(void)type; |
| bzero(acl_filters, sizeof(acl_filters)); |
bzero(acl_filters, sizeof(acl_filters)); |
| bzero(acl_limits, sizeof(acl_limits)); |
bzero(acl_limits, sizeof(acl_limits)); |
| bzero(std_acct, sizeof(std_acct)); |
bzero(std_acct, sizeof(std_acct)); |
|
Line 159 RadsrvEvent(int type, void *cookie)
|
Line 166 RadsrvEvent(int type, void *cookie)
|
| switch (res) { |
switch (res) { |
| case RAD_USER_NAME: |
case RAD_USER_NAME: |
| anysesid = 1; |
anysesid = 1; |
| |
if (username) |
| |
free(username); |
| username = rad_cvt_string(data, len); |
username = rad_cvt_string(data, len); |
| Log(LG_RADIUS2, ("radsrv: Got RAD_USER_NAME: %s", | Log(LG_RADIUS2, ("radsrv: Got RAD_USER_NAME: %s", username)); |
| username)); | |
| break; |
break; |
| |
case RAD_CLASS: |
| |
tmpval = Bin2Hex(data, len); |
| |
Log(LG_RADIUS2, ("radsrv: Got RAD_CLASS: %s", tmpval)); |
| |
Freee(tmpval); |
| |
class_len = len; |
| |
if (rad_class != NULL) |
| |
Freee(rad_class); |
| |
rad_class = Mdup(MB_AUTH, data, len); |
| |
break; |
| case RAD_NAS_IP_ADDRESS: |
case RAD_NAS_IP_ADDRESS: |
| nas_ip = rad_cvt_addr(data); |
nas_ip = rad_cvt_addr(data); |
| Log(LG_RADIUS2, ("radsrv: Got RAD_NAS_IP_ADDRESS: %s ", | Log(LG_RADIUS2, ("radsrv: Got RAD_NAS_IP_ADDRESS: %s", |
| inet_ntoa(nas_ip))); |
inet_ntoa(nas_ip))); |
| break; |
break; |
| case RAD_SERVICE_TYPE: |
case RAD_SERVICE_TYPE: |
|
Line 175 RadsrvEvent(int type, void *cookie)
|
Line 192 RadsrvEvent(int type, void *cookie)
|
| break; |
break; |
| case RAD_STATE: |
case RAD_STATE: |
| tmpval = Bin2Hex(data, len); |
tmpval = Bin2Hex(data, len); |
| Log(LG_RADIUS2, ("radsrv: Get RAD_STATE: 0x%s", tmpval)); | Log(LG_RADIUS2, ("radsrv: Got RAD_STATE: 0x%s", tmpval)); |
| Freee(tmpval); |
Freee(tmpval); |
| state_len = len; |
state_len = len; |
| if (state != NULL) |
if (state != NULL) |
|
Line 184 RadsrvEvent(int type, void *cookie)
|
Line 201 RadsrvEvent(int type, void *cookie)
|
| break; |
break; |
| case RAD_CALLED_STATION_ID: |
case RAD_CALLED_STATION_ID: |
| anysesid = 1; |
anysesid = 1; |
| |
if (called) |
| |
free(called); |
| called = rad_cvt_string(data, len); |
called = rad_cvt_string(data, len); |
| Log(LG_RADIUS2, ("radsrv: Got RAD_CALLED_STATION_ID: %s ", | Log(LG_RADIUS2, ("radsrv: Got RAD_CALLED_STATION_ID: %s", |
| called)); |
called)); |
| break; |
break; |
| case RAD_CALLING_STATION_ID: |
case RAD_CALLING_STATION_ID: |
| anysesid = 1; |
anysesid = 1; |
| |
if (calling) |
| |
free(calling); |
| calling = rad_cvt_string(data, len); |
calling = rad_cvt_string(data, len); |
| Log(LG_RADIUS2, ("radsrv: Got RAD_CALLING_STATION_ID: %s ", | Log(LG_RADIUS2, ("radsrv: Got RAD_CALLING_STATION_ID: %s", |
| calling)); |
calling)); |
| break; |
break; |
| case RAD_ACCT_SESSION_ID: |
case RAD_ACCT_SESSION_ID: |
| anysesid = 1; |
anysesid = 1; |
| |
if (sesid) |
| |
free(sesid); |
| sesid = rad_cvt_string(data, len); |
sesid = rad_cvt_string(data, len); |
| Log(LG_RADIUS2, ("radsrv: Got RAD_ACCT_SESSION_ID: %s ", | Log(LG_RADIUS2, ("radsrv: Got RAD_ACCT_SESSION_ID: %s", |
| sesid)); |
sesid)); |
| break; |
break; |
| case RAD_ACCT_MULTI_SESSION_ID: |
case RAD_ACCT_MULTI_SESSION_ID: |
| anysesid = 1; |
anysesid = 1; |
| |
if (msesid) |
| |
free(msesid); |
| msesid = rad_cvt_string(data, len); |
msesid = rad_cvt_string(data, len); |
| Log(LG_RADIUS2, ("radsrv: Got RAD_ACCT_MULTI_SESSION_ID: %s ", | Log(LG_RADIUS2, ("radsrv: Got RAD_ACCT_MULTI_SESSION_ID: %s", |
| msesid)); |
msesid)); |
| break; |
break; |
| case RAD_FRAMED_IP_ADDRESS: |
case RAD_FRAMED_IP_ADDRESS: |
| anysesid = 1; |
anysesid = 1; |
| ip = rad_cvt_addr(data); |
ip = rad_cvt_addr(data); |
| Log(LG_RADIUS2, ("radsrv: Got RAD_FRAMED_IP_ADDRESS: %s ", | Log(LG_RADIUS2, ("radsrv: Got RAD_FRAMED_IP_ADDRESS: %s", |
| inet_ntoa(ip))); |
inet_ntoa(ip))); |
| |
if (ip.s_addr == INADDR_BROADCAST) |
| |
Log(LG_ERR, ("radsrv: incorrect Framed-IP-Address")); |
| break; |
break; |
| case RAD_NAS_PORT: |
case RAD_NAS_PORT: |
| anysesid = 1; |
anysesid = 1; |
| nasport = rad_cvt_int(data); |
nasport = rad_cvt_int(data); |
| Log(LG_RADIUS2, ("radsrv: Got RAD_NAS_PORT: %d ", | Log(LG_RADIUS2, ("radsrv: Got RAD_NAS_PORT: %d", |
| nasport)); |
nasport)); |
| break; |
break; |
| case RAD_SESSION_TIMEOUT: |
case RAD_SESSION_TIMEOUT: |
| session_timeout = rad_cvt_int(data); |
session_timeout = rad_cvt_int(data); |
| Log(LG_RADIUS2, ("radsrv: Got RAD_SESSION_TIMEOUT: %u ", | Log(LG_RADIUS2, ("radsrv: Got RAD_SESSION_TIMEOUT: %u", |
| session_timeout)); |
session_timeout)); |
| break; |
break; |
| case RAD_IDLE_TIMEOUT: |
case RAD_IDLE_TIMEOUT: |
| idle_timeout = rad_cvt_int(data); |
idle_timeout = rad_cvt_int(data); |
| Log(LG_RADIUS2, ("radsrv: Got RAD_IDLE_TIMEOUT: %u ", | Log(LG_RADIUS2, ("radsrv: Got RAD_IDLE_TIMEOUT: %u", |
| idle_timeout)); |
idle_timeout)); |
| break; |
break; |
| case RAD_ACCT_INTERIM_INTERVAL: |
case RAD_ACCT_INTERIM_INTERVAL: |
| acct_update = rad_cvt_int(data); |
acct_update = rad_cvt_int(data); |
| Log(LG_RADIUS2, ("radsrv: Got RAD_ACCT_INTERIM_INTERVAL: %u ", | Log(LG_RADIUS2, ("radsrv: Got RAD_ACCT_INTERIM_INTERVAL: %u", |
| acct_update)); |
acct_update)); |
| break; |
break; |
| case RAD_MESSAGE_AUTHENTIC: |
case RAD_MESSAGE_AUTHENTIC: |
|
Line 239 RadsrvEvent(int type, void *cookie)
|
Line 266 RadsrvEvent(int type, void *cookie)
|
| break; |
break; |
| case RAD_VENDOR_SPECIFIC: |
case RAD_VENDOR_SPECIFIC: |
| if ((res = rad_get_vendor_attr(&vendor, &data, &len)) == -1) { |
if ((res = rad_get_vendor_attr(&vendor, &data, &len)) == -1) { |
| Log(LG_RADIUS, ("radsrv: Get vendor attr failed: %s ", | Log(LG_RADIUS, ("radsrv: Get vendor attr failed: %s", |
| rad_strerror(w->handle))); |
rad_strerror(w->handle))); |
| break; |
break; |
| } |
} |
|
Line 310 RadsrvEvent(int type, void *cookie)
|
Line 337 RadsrvEvent(int type, void *cookie)
|
| Log(LG_RADIUS2, ("radsrv: Get RAD_MPD_FILTER: %s", |
Log(LG_RADIUS2, ("radsrv: Get RAD_MPD_FILTER: %s", |
| acl)); |
acl)); |
| acl2 = strsep(&acl1, "#"); |
acl2 = strsep(&acl1, "#"); |
| i = atol(acl2); | i = atoi(acl2); |
| if (i <= 0 || i > ACL_FILTERS) { |
if (i <= 0 || i > ACL_FILTERS) { |
| Log(LG_RADIUS, ("radsrv: Wrong filter number: %i", i)); |
Log(LG_RADIUS, ("radsrv: Wrong filter number: %i", i)); |
| free(acl); |
free(acl); |
|
Line 365 RadsrvEvent(int type, void *cookie)
|
Line 392 RadsrvEvent(int type, void *cookie)
|
| strsep(&acl3, "="); |
strsep(&acl3, "="); |
| acl2 = acl1; |
acl2 = acl1; |
| strsep(&acl2, "#"); |
strsep(&acl2, "#"); |
| i = atol(acl1); | i = atoi(acl1); |
| if (i <= 0) { |
if (i <= 0) { |
| Log(LG_ERR, ("radsrv: Wrong acl number: %i", i)); |
Log(LG_ERR, ("radsrv: Wrong acl number: %i", i)); |
| free(acl); |
free(acl); |
|
Line 409 RadsrvEvent(int type, void *cookie)
|
Line 436 RadsrvEvent(int type, void *cookie)
|
| #endif /* USE_NG_BPF or USE_IPFW */ |
#endif /* USE_NG_BPF or USE_IPFW */ |
| |
|
| default: |
default: |
| Log(LG_RADIUS2, ("radsrv: Dropping vendor %d attribute: %d ", | Log(LG_RADIUS2, ("radsrv: Dropping vendor %d attribute: %d", |
| vendor, res)); |
vendor, res)); |
| break; |
break; |
| } |
} |
| break; |
break; |
| default: |
default: |
| Log(LG_RADIUS2, ("radsrv: Unknown attribute: %d ", | Log(LG_RADIUS2, ("radsrv: Unknown attribute: %d", res)); |
| res)); | |
| break; |
break; |
| } |
} |
| } |
} |
| err = 0; |
err = 0; |
| if (w->addr.u.ip4.s_addr != 0 && nas_ip.s_addr != -1 && w->addr.u.ip4.s_addr != nas_ip.s_addr) { | if (w->addr.u.ip4.s_addr != 0 && nas_ip.s_addr != INADDR_BROADCAST |
| | && w->addr.u.ip4.s_addr != nas_ip.s_addr) { |
| Log(LG_ERR, ("radsrv: incorrect NAS-IP-Address")); |
Log(LG_ERR, ("radsrv: incorrect NAS-IP-Address")); |
| err = 403; |
err = 403; |
| } else if (anysesid == 0) { |
} else if (anysesid == 0) { |
|
Line 469 RadsrvEvent(int type, void *cookie)
|
Line 496 RadsrvEvent(int type, void *cookie)
|
| continue; |
continue; |
| if (iface && (!B || strcmp(iface, B->iface.ifname))) |
if (iface && (!B || strcmp(iface, B->iface.ifname))) |
| continue; |
continue; |
| if (ifindex >= 0 && (!B || ifindex != B->iface.ifindex)) | if (ifindex >= 0 && (!B || (uint)ifindex != B->iface.ifindex)) |
| continue; |
continue; |
| if (ip.s_addr != -1 && (!B || | if (ip.s_addr != INADDR_BROADCAST && (!B || |
| ip.s_addr != B->iface.peer_addr.u.ip4.s_addr)) |
ip.s_addr != B->iface.peer_addr.u.ip4.s_addr)) |
| continue; |
continue; |
| |
|
| Log(LG_RADIUS2, ("radsrv: Matched link: %s", | Log(LG_RADIUS2, ("radsrv: Matched link: %s", L->name)); |
| L->name)); | |
| if (L->tmpl) { |
if (L->tmpl) { |
| Log(LG_ERR, ("radsrv: Impossible to affect template")); |
Log(LG_ERR, ("radsrv: Impossible to affect template")); |
| err = 504; |
err = 504; |
| continue; |
continue; |
| } |
} |
| found++; |
found++; |
| | |
| if (result == RAD_DISCONNECT_REQUEST) { |
if (result == RAD_DISCONNECT_REQUEST) { |
| RecordLinkUpDownReason(NULL, L, 0, STR_MANUALLY, NULL); |
RecordLinkUpDownReason(NULL, L, 0, STR_MANUALLY, NULL); |
| LinkClose(L); |
LinkClose(L); |
|
Line 509 RadsrvEvent(int type, void *cookie)
|
Line 535 RadsrvEvent(int type, void *cookie)
|
| ACLCopy(acl_queue, &L->lcp.auth.params.acl_queue); |
ACLCopy(acl_queue, &L->lcp.auth.params.acl_queue); |
| ACLCopy(acl_table, &L->lcp.auth.params.acl_table); |
ACLCopy(acl_table, &L->lcp.auth.params.acl_table); |
| #endif /* USE_IPFW */ |
#endif /* USE_IPFW */ |
| |
if (rad_class != NULL) { |
| |
if (L->lcp.auth.params.class != NULL) |
| |
Freee(L->lcp.auth.params.class); |
| |
L->lcp.auth.params.class = Mdup(MB_AUTH, rad_class, class_len); |
| |
L->lcp.auth.params.class_len = class_len; |
| |
} |
| #ifdef USE_NG_BPF |
#ifdef USE_NG_BPF |
| for (i = 0; i < ACL_FILTERS; i++) { |
for (i = 0; i < ACL_FILTERS; i++) { |
| ACLDestroy(L->lcp.auth.params.acl_filters[i]); |
ACLDestroy(L->lcp.auth.params.acl_filters[i]); |
|
Line 523 RadsrvEvent(int type, void *cookie)
|
Line 555 RadsrvEvent(int type, void *cookie)
|
| strcpy(L->lcp.auth.params.std_acct[0], std_acct[0]); |
strcpy(L->lcp.auth.params.std_acct[0], std_acct[0]); |
| strcpy(L->lcp.auth.params.std_acct[1], std_acct[1]); |
strcpy(L->lcp.auth.params.std_acct[1], std_acct[1]); |
| #endif |
#endif |
| if (session_timeout != -1) | if (session_timeout != UINT_MAX) |
| L->lcp.auth.params.session_timeout = session_timeout; |
L->lcp.auth.params.session_timeout = session_timeout; |
| if (idle_timeout != -1) | if (idle_timeout != UINT_MAX) |
| L->lcp.auth.params.idle_timeout = idle_timeout; |
L->lcp.auth.params.idle_timeout = idle_timeout; |
| if (acct_update != -1) { | if (acct_update != UINT_MAX) { |
| L->lcp.auth.params.acct_update = acct_update; |
L->lcp.auth.params.acct_update = acct_update; |
| /* Stop accounting update timer if running. */ |
/* Stop accounting update timer if running. */ |
| TimerStop(&L->lcp.auth.acct_timer); |
TimerStop(&L->lcp.auth.acct_timer); |
|
Line 581 RadsrvEvent(int type, void *cookie)
|
Line 613 RadsrvEvent(int type, void *cookie)
|
| cleanup: |
cleanup: |
| if (username) |
if (username) |
| free(username); |
free(username); |
| |
if (rad_class != NULL) |
| |
Freee(rad_class); |
| if (called) |
if (called) |
| free(called); |
free(called); |
| if (calling) |
if (calling) |
|
Line 627 RadsrvOpen(Radsrv w)
|
Line 661 RadsrvOpen(Radsrv w)
|
| return (-1); |
return (-1); |
| } |
} |
| |
|
| if ((w->fd = socket(PF_INET, SOCK_DGRAM, IPPROTO_UDP)) == -1) { | if ((w->fd = socket(PF_INET, socktype(SOCK_DGRAM), IPPROTO_UDP)) == -1) { |
| Perror("%s: Cannot create socket", __FUNCTION__); |
Perror("%s: Cannot create socket", __FUNCTION__); |
| return (-1); |
return (-1); |
| } |
} |
|
Line 665 RadsrvOpen(Radsrv w)
|
Line 699 RadsrvOpen(Radsrv w)
|
| s = s->next; |
s = s->next; |
| } |
} |
| |
|
| Log(LG_ERR, ("radsrv: listening on %s %d", | Log(LG_ERR, ("radsrv: listening on %s %d", |
| u_addrtoa(&w->addr,addrstr,sizeof(addrstr)), w->port)); |
u_addrtoa(&w->addr,addrstr,sizeof(addrstr)), w->port)); |
| return (0); |
return (0); |
| } |
} |
|
Line 695 RadsrvClose(Radsrv w)
|
Line 729 RadsrvClose(Radsrv w)
|
| */ |
*/ |
| |
|
| int |
int |
| RadsrvStat(Context ctx, int ac, char *av[], void *arg) | RadsrvStat(Context ctx, int ac, const char *const av[], const void *arg) |
| { |
{ |
| Radsrv w = &gRadsrv; |
Radsrv w = &gRadsrv; |
| char addrstr[64]; |
char addrstr[64]; |
| struct radiusclient_conf *client; |
struct radiusclient_conf *client; |
| |
|
| |
(void)ac; |
| |
(void)av; |
| |
(void)arg; |
| |
|
| Printf("Radsrv configuration:\r\n"); |
Printf("Radsrv configuration:\r\n"); |
| Printf("\tState : %s\r\n", w->handle ? "OPENED" : "CLOSED"); |
Printf("\tState : %s\r\n", w->handle ? "OPENED" : "CLOSED"); |
| Printf("\tSelf : %s %d\r\n", |
Printf("\tSelf : %s %d\r\n", |
|
Line 722 RadsrvStat(Context ctx, int ac, char *av[], void *arg)
|
Line 760 RadsrvStat(Context ctx, int ac, char *av[], void *arg)
|
| */ |
*/ |
| |
|
| static int |
static int |
| RadsrvSetCommand(Context ctx, int ac, char *av[], void *arg) | RadsrvSetCommand(Context ctx, int ac, const char *const av[], const void *arg) |
| { |
{ |
| Radsrv w = &gRadsrv; |
Radsrv w = &gRadsrv; |
| int port, count; |
int port, count; |