diff --git a/net/freeradius-client/Makefile b/net/freeradius-client/Makefile index 015a888f0226..6007532e0579 100644 --- a/net/freeradius-client/Makefile +++ b/net/freeradius-client/Makefile @@ -1,19 +1,20 @@ PORTNAME= freeradius-client -PORTVERSION= 1.1.7 -PORTREVISION= 0 +PORTVERSION= 1.1.8 CATEGORIES= net -MASTER_SITES= ftp://ftp.freeradius.org/pub/freeradius/ \ - ftp://ftp.suntel.com.tr/pub/freeradius/ MAINTAINER= netch@portaone.com COMMENT= Client library and basic utilities for RADIUS AAA -WWW= http://wiki.freeradius.org/Radiusclient +WWW= https://wiki.freeradius.org/project/Radiusclient + +USES= gmake libtool +USE_GITHUB= yes +GH_ACCOUNT= FreeRADIUS +GH_TAGNAME= release_1_1_8 GNU_CONFIGURE= yes INSTALL_TARGET= install-strip -USES= gmake libtool USE_LDCONFIG= yes -CONFLICTS= radiusclient-ng +CONFLICTS_INSTALL= radiusclient .include diff --git a/net/freeradius-client/distinfo b/net/freeradius-client/distinfo index 4f8c60f4a4ff..54cf3a7c6ada 100644 --- a/net/freeradius-client/distinfo +++ b/net/freeradius-client/distinfo @@ -1,3 +1,3 @@ -TIMESTAMP = 1582553895 -SHA256 (freeradius-client-1.1.7.tar.gz) = eada2861b8f4928e3ac6b5bbfe11e92cd6cdcacfce40cae1085e77c1b6add0e9 -SIZE (freeradius-client-1.1.7.tar.gz) = 433141 +TIMESTAMP = 1787125448 +SHA256 (FreeRADIUS-freeradius-client-1.1.8-release_1_1_8_GH0.tar.gz) = 6ac0ad2dfbba01ebfe829472b0709afc22f810b86c005f5abc9db7b609eb6beb +SIZE (FreeRADIUS-freeradius-client-1.1.8-release_1_1_8_GH0.tar.gz) = 439294 diff --git a/net/freeradius-client/files/patch-configure b/net/freeradius-client/files/patch-configure index c361fa31a30f..d15ead56b2e7 100644 --- a/net/freeradius-client/files/patch-configure +++ b/net/freeradius-client/files/patch-configure @@ -1,22 +1,22 @@ ---- configure.orig 2015-01-19 16:18:26 UTC +--- configure.orig 2021-07-29 14:49:30 UTC +++ configure -@@ -12503,19 +12503,6 @@ fi +@@ -12499,19 +12499,6 @@ $as_echo_n "checking gethostbyaddr_r() syntax... " >&6 gethostbyaddrrstyle="" { $as_echo "$as_me:${as_lineno-$LINENO}: checking gethostbyaddr_r() syntax" >&5 $as_echo_n "checking gethostbyaddr_r() syntax... " >&6; } -case "$host" in -*-freebsd*) - -$as_echo "#define GETHOSTBYADDR_R /**/" >>confdefs.h - - -$as_echo "#define GETHOSTBYADDRRSTYLE_BSD /**/" >>confdefs.h - - gethostbyaddrrstyle=BSD - { $as_echo "$as_me:${as_lineno-$LINENO}: WARNING: FreeBSD overridden to BSD-style" >&5 -$as_echo "$as_me: WARNING: FreeBSD overridden to BSD-style" >&2;} - ;; -esac if test "x$gethostbyaddrrstyle" = "x"; then cat confdefs.h - <<_ACEOF >conftest.$ac_ext /* end confdefs.h. */ diff --git a/net/freeradius-client/files/patch-include_freeradius-client.h b/net/freeradius-client/files/patch-include_freeradius-client.h new file mode 100644 index 000000000000..ec549bbb4f16 --- /dev/null +++ b/net/freeradius-client/files/patch-include_freeradius-client.h @@ -0,0 +1,15 @@ +Fix vendor-specific attributes length validation: vendor-specific +attributes need additional room for the VSA header. + +Obtained from: https://github.com/FreeRADIUS/freeradius-client/commit/40d5f543e8240de39f5780c99355ddc2f5726bde + +--- include/freeradius-client.h.orig 2021-07-29 14:49:30 UTC ++++ include/freeradius-client.h +@@ -53,6 +53,7 @@ + #define AUTH_PASS_LEN (7 * 16) /* multiple of 16 */ + #define AUTH_ID_LEN 64 + #define AUTH_STRING_LEN 253 /* maximum of 253 */ ++#define VSA_HEADER_LEN 6 /* vendor-specific attribute header: type(1) + length(1) + vendor-id(4) */ + + #define BUFFER_LEN 8192 + diff --git a/net/freeradius-client/files/patch-lib__config.c b/net/freeradius-client/files/patch-lib__config.c index fd564f2c8e21..0c1ffeb9679f 100644 --- a/net/freeradius-client/files/patch-lib__config.c +++ b/net/freeradius-client/files/patch-lib__config.c @@ -1,55 +1,31 @@ ---- lib/config.c.orig 2015-01-19 16:18:26 UTC +--- lib/config.c.orig 2021-07-29 14:49:30 UTC +++ lib/config.c -@@ -106,7 +106,7 @@ static int set_option_srv(char const *filename, int li +@@ -107,7 +107,7 @@ static int set_option_srv(char const *filename, int li serv = (SERVER *) option->val; if (serv == NULL) { DEBUG(LOG_ERR, "option->val / server is NULL, allocating memory"); - serv = malloc(sizeof(*serv)); + serv = calloc(1, sizeof(*serv)); if (serv == NULL) { rc_log(LOG_CRIT, "read_config: out of memory"); free(p_dupe); -@@ -319,8 +319,8 @@ rc_config_init(rc_handle *rh) +@@ -360,8 +360,8 @@ rc_handle *rc_config_init(rc_handle *rh) acct = find_option(rh, "acctserver", OT_ANY); auth = find_option(rh, "authserver", OT_ANY); - authservers = malloc(sizeof(SERVER)); - acctservers = malloc(sizeof(SERVER)); + authservers = calloc(1, sizeof(SERVER)); + acctservers = calloc(1, sizeof(SERVER)); if(authservers == NULL || acctservers == NULL) { -@@ -504,7 +504,7 @@ int rc_conf_int(rc_handle const *rh, char const *optna +@@ -541,7 +541,7 @@ int rc_conf_int(rc_handle const *rh, char const *optna if (option != NULL) { if (option->val) { - return *((int *)option->val); + return option->val ? *((int *)option->val) : 0; } else { rc_log(LOG_ERR, "rc_conf_int: config option %s was not set", optname); return 0; -@@ -545,17 +545,21 @@ int test_config(rc_handle const *rh, char const *filen - struct stat st; - char *file; - #endif -+ SERVER *srv = NULL; - -- if (!(rc_conf_srv(rh, "authserver")->max)) -+ srv = rc_conf_srv(rh, "authserver"); -+ if (!srv || !srv->max) - { - rc_log(LOG_ERR,"%s: no authserver specified", filename); - return -1; - } -- if (!(rc_conf_srv(rh, "acctserver")->max)) -+ srv = rc_conf_srv(rh, "acctserver"); -+ if (!srv || !srv->max) - { - rc_log(LOG_ERR,"%s: no acctserver specified", filename); - return -1; - } -+ - if (!rc_conf_str(rh, "servers")) - { - rc_log(LOG_ERR,"%s: no servers file specified", filename); diff --git a/net/freeradius-client/files/patch-lib__ip_util.c b/net/freeradius-client/files/patch-lib__ip_util.c deleted file mode 100644 index 1f2e72d19836..000000000000 --- a/net/freeradius-client/files/patch-lib__ip_util.c +++ /dev/null @@ -1,39 +0,0 @@ ---- lib/ip_util.c.orig 2015-01-19 16:18:26 UTC -+++ lib/ip_util.c -@@ -348,6 +348,36 @@ uint32_t rc_own_bind_ipaddress(rc_handle *rh) - } - - /* -+ * Function: rc_nasaddress -+ * -+ * Purpose: get the IP address to be declared as NAS-Address -+ * for sending requests in host order -+ * -+ * Returns: IP address, or 0 if didn't specified -+ * -+ */ -+ -+uint32_t rc_nasaddress(rc_handle *rh) -+{ -+ const char *cs; -+ char hostname[256]; -+ uint32_t rval; -+ -+ cs = rc_conf_str(rh, "nasaddr"); -+ if (cs == NULL || 0 == strcmp(cs, "*")) -+ return 0; -+ -+ strncpy(hostname, cs, sizeof(hostname)); -+ hostname[sizeof(hostname) - 1] = '\0'; -+ if ((rval = rc_get_ipaddr(hostname)) == 0) { -+ rc_log(LOG_ERR, "rc_own_ipaddress: couldn't get IP address from bindaddr"); -+ rval = INADDR_ANY; -+ } -+ -+ return rval; -+} -+ -+/* - * Function: rc_get_srcaddr - * - * Purpose: given remote address find local address which the diff --git a/net/freeradius-client/files/patch-lib__options.h b/net/freeradius-client/files/patch-lib__options.h index d0d444479e11..b0bbd24a7f92 100644 --- a/net/freeradius-client/files/patch-lib__options.h +++ b/net/freeradius-client/files/patch-lib__options.h @@ -1,10 +1,10 @@ ---- lib/options.h.orig 2015-01-19 16:18:26 UTC +--- lib/options.h.orig 2021-07-29 14:49:30 UTC +++ lib/options.h -@@ -50,6 +50,7 @@ static OPTION config_options_default[] = { +@@ -49,6 +49,7 @@ static OPTION config_options_default[] = { {"radius_retries", OT_INT, ST_UNDEF, NULL}, {"radius_deadtime", OT_INT, ST_UNDEF, NULL}, {"bindaddr", OT_STR, ST_UNDEF, NULL}, +{"nasaddr", OT_STR, ST_UNDEF, NULL}, /* local options */ {"login_local", OT_STR, ST_UNDEF, NULL}, }; diff --git a/net/freeradius-client/files/patch-lib_avpair.c b/net/freeradius-client/files/patch-lib_avpair.c new file mode 100644 index 000000000000..9e3a3368d223 --- /dev/null +++ b/net/freeradius-client/files/patch-lib_avpair.c @@ -0,0 +1,137 @@ +Make rc_avpair_gen() iterative. Response attributes were parsed +recursively without a depth limit, before the response authenticator +was verified, so a spoofed reply with many attributes could exhaust +the stack of a threaded caller. + +Upstream issue: https://github.com/FreeRADIUS/freeradius-client/issues/134 +Obtained from: https://github.com/FreeRADIUS/freeradius-client/commit/a82f7bf548750e4937fbb833372cf65577ea0c6b + +--- lib/avpair.c.orig 2021-07-29 14:49:30 UTC ++++ lib/avpair.c +@@ -175,45 +175,41 @@ VALUE_PAIR *rc_avpair_new (rc_handle const *rh, uint32 + * @note Uses recursion. + * + * @param rh a handle to parsed configuration. +- * @param pair a pointer to a #VALUE_PAIR structure. ++ * @param next a pointer to the next #VALUE_PAIR structure. + * @param ptr the value (e.g., the actual username). + * @param length the length of ptr, or -1 if to calculate (in case of strings). + * @param vendorpec The vendor ID in case of a vendor specific value - 0 otherwise. + * @return value_pair list or %NULL on failure. + */ +-VALUE_PAIR *rc_avpair_gen(rc_handle const *rh, VALUE_PAIR *pair, unsigned char const *ptr, ++VALUE_PAIR *rc_avpair_gen(rc_handle const *rh, VALUE_PAIR *next, unsigned char const *ptr, + int length, uint32_t vendorpec) + { + int attrlen, x_len; + unsigned char const *x_ptr; + uint32_t attribute, lvalue; + DICT_ATTR *attr; +- VALUE_PAIR *rpair; ++ VALUE_PAIR *head, **last, *pair; + char buffer[(AUTH_STRING_LEN * 2) + 1]; + /* For hex string conversion. */ + char hex[3]; + ++ head = NULL; ++ last = &head; ++ ++next_attribute: + if (length < 2) { + rc_log(LOG_ERR, "rc_avpair_gen: received attribute with " + "invalid length"); +- goto shithappens; ++ goto error; + } + attrlen = ptr[1]; + if (length < attrlen || attrlen < 2) { + rc_log(LOG_ERR, "rc_avpair_gen: received attribute with " + "invalid length"); +- goto shithappens; ++ goto error; + } + +- /* Advance to the next attribute and process recursively */ +- if (length != attrlen) { +- pair = rc_avpair_gen(rh, pair, ptr + attrlen, length - attrlen, +- vendorpec); +- if ((pair == NULL) && (vendorpec != 0)) +- return NULL; +- } +- +- /* Actual processing */ ++ /* decode the attribute */ + attribute = ptr[0]; + ptr += 2; + attrlen -= 2; +@@ -233,9 +229,15 @@ VALUE_PAIR *rc_avpair_gen(rc_handle const *rh, VALUE_P + "attribute with unknown Vendor-Id %d", vendorpec); + goto skipit; + } +- /* Process recursively */ +- return rc_avpair_gen(rh, pair, ptr + 4, attrlen - 4, +- vendorpec); ++ ++ /* Process recursively, because VSAs */ ++ pair = rc_avpair_gen(rh, NULL, ptr + 4, attrlen - 4, ++ vendorpec); ++ if (!pair) goto skipit; ++ ++ *last = pair; ++ while (*last) last = &((*last)->next); ++ goto skipit; + } + + /* Normal */ +@@ -260,16 +262,16 @@ VALUE_PAIR *rc_avpair_gen(rc_handle const *rh, VALUE_P + goto skipit; + } + +- rpair = malloc(sizeof(*rpair)); +- if (rpair == NULL) { ++ pair = malloc(sizeof(*pair)); ++ if (pair == NULL) { + rc_log(LOG_CRIT, "rc_avpair_gen: out of memory"); +- goto shithappens; ++ goto error; + } +- memset(rpair, '\0', sizeof(*rpair)); ++ memset(pair, '\0', sizeof(*pair)); + +- /* Insert this new pair at the beginning of the list */ +- rpair->next = pair; +- pair = rpair; ++ /* Insert this new pair at the end of the list */ ++ *last = pair; ++ last = &(pair->next); + strcpy(pair->name, attr->name); + pair->vendor = attr->vendor; + pair->attribute = attr->value; +@@ -329,13 +331,21 @@ skipit: + } + + skipit: +- return pair; ++ /* ++ * Skip the attribute ++ */ ++ ptr += attrlen; ++ length -= (attrlen + 2); + +-shithappens: +- while (pair != NULL) { +- rpair = pair->next; +- free(pair); +- pair = rpair; ++ if (!length) return head; ++ ++ goto next_attribute; ++ ++error: ++ while (head != NULL) { ++ pair = head->next; ++ free(head); ++ head = pair; + } + return NULL; + }