summaryrefslogtreecommitdiff
path: root/accel-pppd/radius
diff options
context:
space:
mode:
Diffstat (limited to 'accel-pppd/radius')
-rw-r--r--accel-pppd/radius/packet.c7
-rw-r--r--accel-pppd/radius/radius.c50
-rw-r--r--accel-pppd/radius/radius_p.h1
3 files changed, 56 insertions, 2 deletions
diff --git a/accel-pppd/radius/packet.c b/accel-pppd/radius/packet.c
index cfc0bc29..c7e91349 100644
--- a/accel-pppd/radius/packet.c
+++ b/accel-pppd/radius/packet.c
@@ -10,8 +10,11 @@
#include <arpa/inet.h>
/*
- * Suppress OpenSSL 3.0 deprecation warnings for HMAC API.
- * See crypto.h for detailed explanation.
+ * Suppress OpenSSL 3.0 deprecation warnings for the HMAC API: it is
+ * deprecated but still functional, and still required for protocol
+ * compatibility. The project sets this for every target (see the top level
+ * CMakeLists.txt); it is repeated here because it only takes effect if it is
+ * defined before the first OpenSSL header is pulled in.
*/
#define OPENSSL_API_COMPAT 0x10100000L
#include <openssl/hmac.h>
diff --git a/accel-pppd/radius/radius.c b/accel-pppd/radius/radius.c
index cb53f59a..fa77a916 100644
--- a/accel-pppd/radius/radius.c
+++ b/accel-pppd/radius/radius.c
@@ -488,12 +488,31 @@ err:
return -1;
}
+/*
+ * Number of IPv6 DNS servers kept per session. Matches the number of dns=
+ * options the ipv6_nd and ipv6_dhcp modules accept in [ipv6-dns], and keeps
+ * the RDNSS option of a router advertisement to a sane size.
+ */
+#define MAX_DNS6_COUNT 3
+
+static void free_ipv6_dns(struct radius_pd_t *rpd)
+{
+ struct ipv6db_addr_t *a;
+
+ while (!list_empty(&rpd->ipv6_dns.addr_list)) {
+ a = list_entry(rpd->ipv6_dns.addr_list.next, typeof(*a), entry);
+ list_del(&a->entry);
+ _free(a);
+ }
+}
+
int rad_proc_attrs(struct rad_req_t *req)
{
struct ev_wins_t wins = {};
struct ev_dns_t dns = {};
struct rad_attr_t *attr;
struct ipv6db_addr_t *a;
+ int dns6_count = -1;
int res = 0;
struct radius_pd_t *rpd = req->rpd;
@@ -602,6 +621,28 @@ int rad_proc_attrs(struct rad_req_t *req)
a->addr = attr->val.ipv6prefix.prefix;
list_add_tail(&a->entry, &rpd->ipv6_dp.prefix_list);
break;
+ case DNS_Server_IPv6_Address:
+ if (dns6_count < 0) {
+ /* This reply carries a DNS server list of
+ its own, it replaces whatever a previous
+ one assigned */
+ free_ipv6_dns(rpd);
+ dns6_count = 0;
+ }
+ if (dns6_count >= MAX_DNS6_COUNT) {
+ if (dns6_count == MAX_DNS6_COUNT)
+ log_ppp_warn("radius: ignoring DNS-Server-IPv6-Address"
+ " beyond the first %i\n", MAX_DNS6_COUNT);
+ dns6_count++;
+ break;
+ }
+ a = _malloc(sizeof(*a));
+ memset(a, 0, sizeof(*a));
+ a->prefix_len = 128;
+ a->addr = attr->val.ipv6addr;
+ list_add_tail(&a->entry, &rpd->ipv6_dns.addr_list);
+ dns6_count++;
+ break;
case NAS_Port:
rpd->ses->unit_idx = attr->val.integer;
break;
@@ -635,6 +676,11 @@ int rad_proc_attrs(struct rad_req_t *req)
if (!rpd->ses->ipv6_dp && !list_empty(&rpd->ipv6_dp.prefix_list))
rpd->ses->ipv6_dp = &rpd->ipv6_dp;
+ /* Like the IPv4 DNS servers, absent attributes leave whatever a
+ previous reply assigned in place */
+ if (!list_empty(&rpd->ipv6_dns.addr_list))
+ rpd->ses->ipv6_dns = &rpd->ipv6_dns;
+
return res;
}
@@ -799,6 +845,7 @@ static void ses_starting(struct ap_session *ses)
INIT_LIST_HEAD(&rpd->plugin_list);
INIT_LIST_HEAD(&rpd->ipv6_addr.addr_list);
INIT_LIST_HEAD(&rpd->ipv6_dp.prefix_list);
+ INIT_LIST_HEAD(&rpd->ipv6_dns.addr_list);
rpd->ipv4_addr.owner = &ipdb;
rpd->ipv6_addr.owner = &ipdb;
@@ -981,6 +1028,9 @@ static void ses_finished(struct ap_session *ses)
_free(a);
}
+ ses->ipv6_dns = NULL;
+ free_ipv6_dns(rpd);
+
fr6 = rpd->fr6;
while (fr6) {
struct framed_ip6_route *next = fr6->next;
diff --git a/accel-pppd/radius/radius_p.h b/accel-pppd/radius/radius_p.h
index d3a72204..e4b84740 100644
--- a/accel-pppd/radius/radius_p.h
+++ b/accel-pppd/radius/radius_p.h
@@ -65,6 +65,7 @@ struct radius_pd_t {
struct ipv4db_item_t ipv4_addr;
struct ipv6db_item_t ipv6_addr;
struct ipv6db_prefix_t ipv6_dp;
+ struct ipv6db_item_t ipv6_dns;
int acct_interim_interval;
int acct_interim_jitter;