X-Git-Url: http://git.sameswireless.fr/l2tpns.git/blobdiff_plain/3aa4eda8b1e0c4abc04439affe850d33648c7472..010ee3abba7bdca41364cffe9969308a7a641909:/radius.c diff --git a/radius.c b/radius.c index ee364b2..18bdf1e 100644 --- a/radius.c +++ b/radius.c @@ -1,5 +1,5 @@ // L2TPNS Radius Stuff -// $Id: radius.c,v 1.1 2003/12/16 07:07:39 fred_nerk Exp $ +// $Id: radius.c,v 1.3 2004/05/24 04:27:11 fred_nerk Exp $ #include #include @@ -7,6 +7,7 @@ #include #include #include +#include #include #include #include @@ -16,20 +17,13 @@ #include "plugin.h" #include "util.h" -extern char *radiussecret; extern radiust *radius; extern sessiont *session; extern tunnelt *tunnel; -extern ipt radiusserver[MAXRADSERVER]; // radius servers extern u32 sessionid; -extern u8 radiusfree; -extern int radfd; -extern u8 numradiusservers; -extern char debug; -extern unsigned long default_dns1, default_dns2; extern struct Tstats *_statistics; -extern int radius_accounting; -extern uint32_t bind_address; +extern struct configt *config; +extern int *radfds; const char *radius_state(int state) { @@ -46,37 +40,66 @@ const char *radius_state(int state) // Set up socket for radius requests void initrad(void) { - radfd = socket(AF_INET, SOCK_DGRAM, UDP); + int i; + log(3, 0, 0, 0, "Creating %d sockets for RADIUS queries\n", config->num_radfds); + radfds = calloc(sizeof(int), config->num_radfds); + for (i = 0; i < config->num_radfds; i++) + { + int flags; + if (!radfds[i]) radfds[i] = socket(AF_INET, SOCK_DGRAM, UDP); + flags = fcntl(radfds[i], F_GETFL, 0); + fcntl(radfds[i], F_SETFL, flags | O_NONBLOCK); + } } -void radiusclear(u8 r, sessionidt s) +void radiusclear(u16 r, sessionidt s) { - radius[r].state = RADIUSNULL; if (s) session[s].radius = 0; - memset(&radius[r], 0, sizeof(radius[r])); - radius[r].next = radiusfree; - radiusfree = r; + memset(&radius[r], 0, sizeof(radius[r])); // radius[r].state = RADIUSNULL; +} + +int next_radius_id = 1; + +static u16 new_radius() +{ + u16 i; + int loops = 0; + for (i = next_radius_id; ; i = (i + 1) % MAXRADIUS) + { + if (radius[i].state == RADIUSNULL) + { + next_radius_id = (next_radius_id + 1) % MAXRADIUS; + return i; + } + if (next_radius_id == i) + { + if (++loops == 2) + { + log(0, 0, 0, 0, "Can't find a free radius session! This is very bad!\n"); + return 0; + } + } + } } -u8 radiusnew(sessionidt s) +u16 radiusnew(sessionidt s) { - u8 r; - if (!radiusfree) + u16 r; + if (!(r = new_radius())) { log(1, 0, s, session[s].tunnel, "No free RADIUS sessions\n"); STAT(radius_overflow); return 0; }; - r = radiusfree; - session[s].radius = r; - radiusfree = radius[r].next; memset(&radius[r], 0, sizeof(radius[r])); + session[s].radius = r; radius[r].session = s; + radius[r].state = RADIUSWAIT; return r; } // Send a RADIUS request -void radiussend(u8 r, u8 state) +void radiussend(u16 r, u8 state) { struct sockaddr_in addr; u8 b[4096]; // RADIUS packet @@ -87,19 +110,19 @@ void radiussend(u8 r, u8 state) #ifdef STAT_CALLS STAT(call_radiussend); #endif - if (!numradiusservers) + s = radius[r].session; + if (!config->numradiusservers) { - log(0, 0, 0, 0, "No RADIUS servers\n"); + log(0, 0, s, session[s].tunnel, "No RADIUS servers\n"); return; } - if (!radiussecret) + if (!*config->radiussecret) { - log(0, 0, 0, 0, "No RADIUS secret\n"); + log(0, 0, s, session[s].tunnel, "No RADIUS secret\n"); return; } - s = radius[r].session; - if (state != RADIUSAUTH && !radius_accounting) + if (state != RADIUSAUTH && !config->radius_accounting) { // Radius accounting is turned off radiusclear(r, s); @@ -110,12 +133,21 @@ void radiussend(u8 r, u8 state) radius[r].try = 0; radius[r].state = state; radius[r].retry = backoff(radius[r].try++); - log(4, 0, s, session[s].tunnel, "Send RADIUS %d state %s try %d\n", r, radius_state(radius[r].state), radius[r].try); - if (radius[r].try > numradiusservers * 2) + log(4, 0, s, session[s].tunnel, "Send RADIUS id %d sock %d state %s try %d\n", + r >> RADIUS_SHIFT, r & RADIUS_MASK, + radius_state(radius[r].state), radius[r].try); + if (radius[r].try > config->numradiusservers * 2) { if (s) { - sessionshutdown(s, "RADIUS timeout"); + if (state == RADIUSAUTH) + sessionshutdown(s, "RADIUS timeout"); + else + { + log(1, 0, s, session[s].tunnel, "RADIUS timeout, but in state %s so don't timeout session\n", + radius_states[state]); + radiusclear(r, s); + } STAT(radius_timeout); } else @@ -129,17 +161,17 @@ void radiussend(u8 r, u8 state) // contruct RADIUS access request switch (state) { - case RADIUSAUTH: - b[0] = 1; // access request - break; - case RADIUSSTART: - case RADIUSSTOP: - b[0] = 4; // accounting request - break; - default: - log(0, 0, 0, 0, "Unknown radius state %d\n", state); + case RADIUSAUTH: + b[0] = 1; // access request + break; + case RADIUSSTART: + case RADIUSSTOP: + b[0] = 4; // accounting request + break; + default: + log(0, 0, 0, 0, "Unknown radius state %d\n", state); } - b[1] = r; // identifier + b[1] = r >> RADIUS_SHIFT; // identifier memcpy(b + 4, radius[r].auth, 16); p = b + 20; if (s) @@ -177,7 +209,7 @@ void radiussend(u8 r, u8 state) { MD5_CTX ctx; MD5Init(&ctx); - MD5Update(&ctx, radiussecret, strlen(radiussecret)); + MD5Update(&ctx, config->radiussecret, strlen(config->radiussecret)); if (p) MD5Update(&ctx, pass + p - 16, 16); else @@ -280,7 +312,7 @@ void radiussend(u8 r, u8 state) // NAS-IP-Address *p = 4; p[1] = 6; - *(u32 *)(p + 2) = bind_address; + *(u32 *)(p + 2) = config->bind_address; p += p[1]; // All AVpairs added @@ -295,26 +327,26 @@ void radiussend(u8 r, u8 state) MD5Update(&ctx, b, 4); MD5Update(&ctx, z, 16); MD5Update(&ctx, b + 20, (p - b) - 20); - MD5Update(&ctx, radiussecret, strlen(radiussecret)); + MD5Update(&ctx, config->radiussecret, strlen(config->radiussecret)); MD5Final(hash, &ctx); memcpy(b + 4, hash, 16); memcpy(radius[r].auth, hash, 16); } memset(&addr, 0, sizeof(addr)); addr.sin_family = AF_INET; - *(u32 *) & addr.sin_addr = htonl(radiusserver[(radius[r].try - 1) % numradiusservers]); + *(u32 *) & addr.sin_addr = config->radiusserver[(radius[r].try - 1) % config->numradiusservers]; addr.sin_port = htons((state == RADIUSAUTH) ? RADPORT : RADAPORT); log_hex(5, "RADIUS Send", b, (p - b)); - sendto(radfd, b, p - b, 0, (void *) &addr, sizeof(addr)); + sendto(radfds[r & RADIUS_MASK], b, p - b, 0, (void *) &addr, sizeof(addr)); } // process RADIUS response -void processrad(u8 * buf, int len) +void processrad(u8 *buf, int len, char socket_index) { u8 b[MAXCONTROL]; MD5_CTX ctx; - u8 r; + u16 r; sessionidt s; tunnelidt t = 0; hasht hash; @@ -330,9 +362,10 @@ void processrad(u8 * buf, int len) return ; } len = ntohs(*(u16 *) (buf + 2)); - r = buf[1]; + r = socket_index | (buf[1] << RADIUS_SHIFT); s = radius[r].session; - log(3, 0, s, session[s].tunnel, "Received %s, radius %d response for session %u\n", radius_states[radius[r].state], r, s); + log(3, 0, s, session[s].tunnel, "Received %s, radius %d response for session %u\n", + radius_states[radius[r].state], r, s); if (!s && radius[r].state != RADIUSSTOP) { log(1, 0, s, session[s].tunnel, " Unexpected RADIUS response\n"); @@ -348,7 +381,7 @@ void processrad(u8 * buf, int len) MD5Update(&ctx, buf, 4); MD5Update(&ctx, radius[r].auth, 16); MD5Update(&ctx, buf + 20, len - 20); - MD5Update(&ctx, radiussecret, strlen(radiussecret)); + MD5Update(&ctx, config->radiussecret, strlen(config->radiussecret)); MD5Final(hash, &ctx); do { if (memcmp(hash, buf + 4, 16)) @@ -472,9 +505,12 @@ void processrad(u8 * buf, int len) } else { - log(3, 0, s, session[s].tunnel, " Radius reply contains route for %d/%d\n", - inet_toa(ip), - inet_toa(mask)); + char *ips, *masks; + ips = strdup(inet_toa(ip)); + masks = strdup(inet_toa(mask)); + log(3, 0, s, session[s].tunnel, " Radius reply contains route for %s/%s\n", ips, masks); + free(ips); + free(masks); session[s].route[routes].ip = ip; session[s].route[routes].mask = mask; routes++; @@ -534,22 +570,22 @@ void processrad(u8 * buf, int len) // Check for Assign-IP-Address if (!session[s].ip || session[s].ip == 0xFFFFFFFE) { - session[s].ip = assign_ip_address(); + assign_ip_address(s); if (session[s].ip) log(3, 0, s, t, " No IP allocated by radius. Assigned %s from pool\n", inet_toa(htonl(session[s].ip))); else - log(3, 0, s, t, " No IP allocated by radius. None available in pool\n"); + log(0, 0, s, t, " No IP allocated by radius. The IP address pool is FULL!\n"); } - if (!session[s].dns1 && default_dns1) + if (!session[s].dns1 && config->default_dns1) { - session[s].dns1 = htonl(default_dns1); - log(3, 0, s, t, " Sending dns1 = %s\n", inet_toa(default_dns1)); + session[s].dns1 = htonl(config->default_dns1); + log(3, 0, s, t, " Sending dns1 = %s\n", inet_toa(config->default_dns1)); } - if (!session[s].dns2 && default_dns2) + if (!session[s].dns2 && config->default_dns2) { - session[s].dns2 = htonl(default_dns2); - log(3, 0, s, t, " Sending dns2 = %s\n", inet_toa(default_dns2)); + session[s].dns2 = htonl(config->default_dns2); + log(3, 0, s, t, " Sending dns2 = %s\n", inet_toa(config->default_dns2)); } if (session[s].ip) @@ -566,7 +602,7 @@ void processrad(u8 * buf, int len) } else { - log(3, 0, s, t, " RADIUS response in state %d\n", radius[r].state); + log(3, 0, s, t, " RADIUS response in state %s\n", radius_states[radius[r].state]); } } while (0); @@ -575,7 +611,7 @@ void processrad(u8 * buf, int len) } // Send a retry for RADIUS/CHAP message -void radiusretry(u8 r) +void radiusretry(u16 r) { sessionidt s = radius[r].session; tunnelidt t = 0; @@ -584,31 +620,46 @@ void radiusretry(u8 r) #endif if (s) t = session[s].tunnel; - radius[r].retry = 0; + radius[r].retry = backoff(radius[r].try + 1); switch (radius[r].state) { - case RADIUSCHAP: // sending CHAP down PPP - sendchap(t, s); - break; - case RADIUSIPCP: - sendipcp(t, s); // send IPCP - break; - case RADIUSAUTH: // sending auth to RADIUS server - radiussend(r, RADIUSAUTH); - break; - case RADIUSSTART: // sending start accounting to RADIUS server - radiussend(r, RADIUSSTART); - break; - case RADIUSSTOP: // sending stop accounting to RADIUS server - radiussend(r, RADIUSSTOP); - break; - default: - case RADIUSNULL: // Not in use - case RADIUSWAIT: // waiting timeout before available, in case delayed reply from RADIUS server - // free up RADIUS task - radiusclear(r, s); - log(3, 0, s, session[s].tunnel, "Freeing up radius session %d\n", r); - break; + case RADIUSCHAP: // sending CHAP down PPP + sendchap(t, s); + break; + case RADIUSIPCP: + sendipcp(t, s); // send IPCP + break; + case RADIUSAUTH: // sending auth to RADIUS server + radiussend(r, RADIUSAUTH); + break; + case RADIUSSTART: // sending start accounting to RADIUS server + radiussend(r, RADIUSSTART); + break; + case RADIUSSTOP: // sending stop accounting to RADIUS server + radiussend(r, RADIUSSTOP); + break; + default: + case RADIUSNULL: // Not in use + case RADIUSWAIT: // waiting timeout before available, in case delayed reply from RADIUS server + // free up RADIUS task + radiusclear(r, s); + log(3, 0, s, session[s].tunnel, "Freeing up radius session %d\n", r); + break; } } +void radius_clean() +{ + int i; + + log(1, 0, 0, 0, "Cleaning radius session array\n"); + + for (i = 1; i < MAXRADIUS; i++) + { + if (radius[i].retry == 0 + || !session[radius[i].session].opened + || session[radius[i].session].die + || session[radius[i].session].tunnel == 0) + radiusclear(i, 0); + } +}