2 * command.c Command socket processing.
6 * This program is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 2 of the License, or
9 * (at your option) any later version.
11 * This program is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, write to the Free Software
18 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
20 * Copyright 2008 The FreeRADIUS server project
21 * Copyright 2008 Alan DeKok <aland@deployingradius.com>
24 #ifdef WITH_COMMAND_SOCKET
26 #include <freeradius-devel/modpriv.h>
27 #include <freeradius-devel/conffile.h>
33 #ifdef HAVE_SYS_STAT_H
45 typedef struct fr_command_table_t fr_command_table_t;
47 typedef int (*fr_command_func_t)(rad_listen_t *, int, char *argv[]);
49 struct fr_command_table_t {
52 fr_command_func_t func;
53 fr_command_table_t *table;
56 #define COMMAND_BUFFER_SIZE (1024)
58 typedef struct fr_command_socket_t {
67 char buffer[COMMAND_BUFFER_SIZE];
68 } fr_command_socket_t;
70 static const CONF_PARSER command_config[] = {
71 { "socket", PW_TYPE_STRING_PTR,
72 offsetof(fr_command_socket_t, path), NULL, "${run_dir}/radiusd.sock"},
73 { "uid", PW_TYPE_STRING_PTR,
74 offsetof(fr_command_socket_t, uid_name), NULL, NULL},
75 { "gid", PW_TYPE_STRING_PTR,
76 offsetof(fr_command_socket_t, gid_name), NULL, NULL},
78 { NULL, -1, 0, NULL, NULL } /* end the list */
81 static ssize_t cprintf(rad_listen_t *listener, const char *fmt, ...)
83 __attribute__ ((format (printf, 2, 3)))
87 #ifndef HAVE_GETPEEREID
88 static int getpeereid(int s, uid_t *euid, gid_t *egid)
94 socklen_t cl = sizeof(cr);
96 if (getsockopt(s, SOL_SOCKET, SO_PEERCRED, &cr, &cl) < 0) {
103 #endif /* SO_PEERCRED */
105 #endif /* HAVE_GETPEEREID */
108 static int fr_server_domain_socket(const char *path)
113 struct sockaddr_un salocal;
117 if (len >= sizeof(salocal.sun_path)) {
118 radlog(L_ERR, "Path too long in socket filename.");
122 if ((sockfd = socket(AF_UNIX, SOCK_STREAM, 0)) < 0) {
123 radlog(L_ERR, "Failed creating socket: %s",
128 memset(&salocal, 0, sizeof(salocal));
129 salocal.sun_family = AF_UNIX;
130 memcpy(salocal.sun_path, path, len); /* not zero terminated */
132 socklen = sizeof(salocal.sun_family) + len;
137 if (stat(path, &buf) < 0) {
138 if (errno != ENOENT) {
139 radlog(L_ERR, "Failed to stat %s: %s",
140 path, strerror(errno));
145 * FIXME: Check the enclosing directory?
147 } else { /* it exists */
148 if (!S_ISREG(buf.st_mode)
150 && !S_ISSOCK(buf.st_mode)
153 radlog(L_ERR, "Cannot turn %s into socket", path);
158 * Refuse to open sockets not owned by us.
160 if (buf.st_uid != geteuid()) {
161 radlog(L_ERR, "We do not own %s", path);
168 * FIXME: stat it, first, to see who owns it,
169 * and who owns the directory above it.
171 if (unlink(path) < 0) {
172 radlog(L_ERR, "Failed to delete %s: %s",
173 path, strerror(errno));
177 if (bind(sockfd, (struct sockaddr *)&salocal, socklen) < 0) {
178 radlog(L_ERR, "Failed binding to %s: %s",
179 path, strerror(errno));
185 * FIXME: There's a race condition here. But Linux
186 * doesn't seem to permit fchmod on domain sockets.
188 if (chmod(path, S_IRUSR | S_IWUSR | S_IRGRP | S_IWGRP) < 0) {
189 radlog(L_ERR, "Failed setting permissions on %s: %s",
190 path, strerror(errno));
195 if (listen(sockfd, 8) < 0) {
196 radlog(L_ERR, "Failed listening to %s: %s",
197 path, strerror(errno));
206 if ((flags = fcntl(sockfd, F_GETFL, NULL)) < 0) {
207 radlog(L_ERR, "Failure getting socket flags: %s",
214 if( fcntl(sockfd, F_SETFL, flags) < 0) {
215 radlog(L_ERR, "Failure setting socket flags: %s",
227 static ssize_t cprintf(rad_listen_t *listener, const char *fmt, ...)
234 len = vsnprintf(buffer, sizeof(buffer), fmt, ap);
237 if (listener->status == RAD_LISTEN_STATUS_CLOSED) return 0;
239 len = write(listener->fd, buffer, len);
241 listener->status = RAD_LISTEN_STATUS_CLOSED;
242 event_new_fd(listener);
246 * FIXME: Keep writing until done?
251 static int command_hup(rad_listen_t *listener, int argc, char *argv[])
254 module_instance_t *mi;
257 radius_signal_self(RADIUS_SIGNAL_SELF_HUP);
261 cs = cf_section_find("modules");
264 mi = find_module_instance(cs, argv[0], 0);
266 cprintf(listener, "ERROR: No such module \"%s\"\n", argv[0]);
270 if ((mi->entry->module->type & RLM_TYPE_HUP_SAFE) == 0) {
271 cprintf(listener, "ERROR: Module %s cannot be hup'd\n",
276 if (!module_hup_module(mi->cs, mi, time(NULL))) {
277 cprintf(listener, "ERROR: Failed to reload module\n");
281 return 1; /* success */
284 static int command_terminate(UNUSED rad_listen_t *listener,
285 UNUSED int argc, UNUSED char *argv[])
287 radius_signal_self(RADIUS_SIGNAL_SELF_TERM);
289 return 1; /* success */
292 extern time_t fr_start_time;
294 static int command_uptime(rad_listen_t *listener,
295 UNUSED int argc, UNUSED char *argv[])
299 CTIME_R(&fr_start_time, buffer, sizeof(buffer));
300 cprintf(listener, "Up since %s", buffer); /* no \r\n */
302 return 1; /* success */
305 static const char *tabs = "\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t";
308 * FIXME: Recurse && indent?
310 static void cprint_conf_parser(rad_listen_t *listener, int indent, CONF_SECTION *cs,
316 const char *name1 = cf_section_name1(cs);
317 const char *name2 = cf_section_name2(cs);
318 const CONF_PARSER *variables = cf_section_parse_table(cs);
322 cprintf(listener, "%.*s%s %s {\n", indent, tabs, name1, name2);
324 cprintf(listener, "%.*s%s {\n", indent, tabs, name1);
332 if (variables) for (i = 0; variables[i].name != NULL; i++) {
334 * No base struct offset, data must be the pointer.
335 * If data doesn't exist, ignore the entry, there
336 * must be something wrong.
339 if (!variables[i].data) {
343 data = variables[i].data;;
345 } else if (variables[i].data) {
346 data = variables[i].data;;
349 data = (((char *)base) + variables[i].offset);
352 switch (variables[i].type) {
354 cprintf(listener, "%.*s%s = ?\n", indent, tabs,
358 case PW_TYPE_INTEGER:
359 cprintf(listener, "%.*s%s = %u\n", indent, tabs,
360 variables[i].name, *(int *) data);
364 inet_ntop(AF_INET, data, buffer, sizeof(buffer));
367 case PW_TYPE_IPV6ADDR:
368 inet_ntop(AF_INET6, data, buffer, sizeof(buffer));
371 case PW_TYPE_BOOLEAN:
372 cprintf(listener, "%.*s%s = %s\n", indent, tabs,
374 ((*(int *) data) == 0) ? "no" : "yes");
377 case PW_TYPE_STRING_PTR:
378 case PW_TYPE_FILENAME:
380 * FIXME: Escape things in the string!
382 if (*(char **) data) {
383 cprintf(listener, "%.*s%s = \"%s\"\n", indent, tabs,
384 variables[i].name, *(char **) data);
386 cprintf(listener, "%.*s%s = \n", indent, tabs,
396 cprintf(listener, "%.*s}\n", indent, tabs);
399 static int command_show_module_config(rad_listen_t *listener, int argc, char *argv[])
402 module_instance_t *mi;
405 cprintf(listener, "ERROR: No module name was given\n");
409 cs = cf_section_find("modules");
412 mi = find_module_instance(cs, argv[0], 0);
414 cprintf(listener, "ERROR: No such module \"%s\"\n", argv[0]);
418 cprint_conf_parser(listener, 0, mi->cs, mi->insthandle);
420 return 1; /* success */
423 static const char *method_names[RLM_COMPONENT_COUNT] = {
435 static int command_show_module_methods(rad_listen_t *listener, int argc, char *argv[])
439 const module_instance_t *mi;
443 cprintf(listener, "ERROR: No module name was given\n");
447 cs = cf_section_find("modules");
450 mi = find_module_instance(cs, argv[0], 0);
452 cprintf(listener, "ERROR: No such module \"%s\"\n", argv[0]);
456 mod = mi->entry->module;
458 for (i = 0; i < RLM_COMPONENT_COUNT; i++) {
459 if (mod->methods[i]) cprintf(listener, "\t%s\n", method_names[i]);
462 return 1; /* success */
466 static int command_show_module_flags(rad_listen_t *listener, int argc, char *argv[])
469 const module_instance_t *mi;
473 cprintf(listener, "ERROR: No module name was given\n");
477 cs = cf_section_find("modules");
480 mi = find_module_instance(cs, argv[0], 0);
482 cprintf(listener, "ERROR: No such module \"%s\"\n", argv[0]);
486 mod = mi->entry->module;
488 if ((mod->type & RLM_TYPE_THREAD_SAFE) != 0)
489 cprintf(listener, "\tthread-safe\n");
492 if ((mod->type & RLM_TYPE_CHECK_CONFIG_SAFE) != 0)
493 cprintf(listener, "\twill-check-config\n");
496 if ((mod->type & RLM_TYPE_HUP_SAFE) != 0)
497 cprintf(listener, "\treload-on-hup\n");
499 return 1; /* success */
504 * Show all loaded modules
506 static int command_show_modules(rad_listen_t *listener, UNUSED int argc, UNUSED char *argv[])
508 CONF_SECTION *cs, *subcs;
510 cs = cf_section_find("modules");
514 while ((subcs = cf_subsection_find_next(cs, subcs, NULL)) != NULL) {
515 const char *name1 = cf_section_name1(subcs);
516 const char *name2 = cf_section_name2(subcs);
518 module_instance_t *mi;
521 mi = find_module_instance(cs, name2, 0);
524 cprintf(listener, "\t%s (%s)\n", name2, name1);
526 mi = find_module_instance(cs, name1, 0);
529 cprintf(listener, "\t%s\n", name1);
533 return 1; /* success */
536 static int command_show_xml(rad_listen_t *listener, UNUSED int argc, UNUSED char *argv[])
539 FILE *fp = fdopen(dup(listener->fd), "a");
542 cprintf(listener, "ERROR: Can't dup %s\n", strerror(errno));
547 cprintf(listener, "ERROR: <reference> is required\n");
551 ci = cf_reference_item(mainconfig.config, mainconfig.config, argv[0]);
553 cprintf(listener, "ERROR: No such item <reference>\n");
557 if (cf_item_is_section(ci)) {
558 cf_section2xml(fp, cf_itemtosection(ci));
560 } else if (cf_item_is_pair(ci)) {
561 cf_pair2xml(fp, cf_itemtopair(ci));
564 cprintf(listener, "ERROR: No such item <reference>\n");
571 return 1; /* success */
575 static fr_command_table_t command_table_show_module[] = {
577 "show module config <module> - show configuration for <module>",
578 command_show_module_config, NULL },
580 "show module flags <module> - show other module properties",
581 command_show_module_flags, NULL },
583 "shows list of loaded modules",
584 command_show_modules, NULL },
586 "show module methods <module> - show sections where <module> may be used",
587 command_show_module_methods, NULL },
589 { NULL, NULL, NULL, NULL }
593 static fr_command_table_t command_table_show[] = {
595 "show config <module> - show configuration for module",
596 command_show_module_config, NULL },
598 "show module <command> - do sub-command of module",
599 NULL, command_table_show_module },
601 "show modules - shows list of loaded modules",
602 command_show_modules, NULL },
604 "show uptime - shows time at which server started",
605 command_uptime, NULL },
607 "show xml <reference> - Prints out configuration as XML",
608 command_show_xml, NULL },
609 { NULL, NULL, NULL, NULL }
613 static int command_set_module_config(rad_listen_t *listener, int argc, char *argv[])
618 module_instance_t *mi;
619 const CONF_PARSER *variables;
623 cprintf(listener, "ERROR: No module name or variable was given\n");
627 cs = cf_section_find("modules");
630 mi = find_module_instance(cs, argv[0], 0);
632 cprintf(listener, "ERROR: No such module \"%s\"\n", argv[0]);
636 if ((mi->entry->module->type & RLM_TYPE_HUP_SAFE) == 0) {
637 cprintf(listener, "ERROR: Cannot change configuration of module as it is cannot be HUP'd.\n");
641 variables = cf_section_parse_table(mi->cs);
643 cprintf(listener, "ERROR: Cannot find configuration for module\n");
648 for (i = 0; variables[i].name != NULL; i++) {
650 * FIXME: Recurse into sub-types somehow...
652 if (variables[i].type == PW_TYPE_SUBSECTION) continue;
654 if (strcmp(variables[i].name, argv[1]) == 0) {
661 cprintf(listener, "ERROR: No such variable \"%s\"\n", argv[1]);
665 i = rcode; /* just to be safe */
668 * It's not part of the dynamic configuration. The module
669 * needs to re-parse && validate things.
671 if (variables[i].data) {
672 cprintf(listener, "ERROR: Variable cannot be dynamically updated\n");
676 data = ((char *) mi->insthandle) + variables[i].offset;
678 cp = cf_pair_find(mi->cs, argv[1]);
682 * Replace the OLD value in the configuration file with
685 * FIXME: Parse argv[2] depending on it's data type!
686 * If it's a string, look for leading single/double quotes,
687 * end then call tokenize functions???
689 cf_pair_replace(mi->cs, cp, argv[2]);
691 rcode = cf_item_parse(mi->cs, argv[1], variables[i].type,
694 cprintf(listener, "ERROR: Failed to parse value\n");
698 return 1; /* success */
702 static fr_command_table_t command_table_set_module[] = {
704 "set module config <module> variable value - set configuration for <module>",
705 command_set_module_config, NULL },
707 { NULL, NULL, NULL, NULL }
711 static fr_command_table_t command_table_set[] = {
712 { "module", NULL, NULL, command_table_set_module },
714 { NULL, NULL, NULL, NULL }
718 static fr_command_table_t command_table[] = {
720 "hup [module] - sends a HUP signal to the server, or optionally to one module",
723 "terminate - terminates the server, and causes it to exit",
724 command_terminate, NULL },
725 { "show", NULL, NULL, command_table_show },
726 { "set", NULL, NULL, command_table_set },
728 { NULL, NULL, NULL, NULL }
733 * FIXME: Unix domain sockets!
735 static int command_socket_parse(CONF_SECTION *cs, rad_listen_t *this)
737 fr_command_socket_t *sock;
741 if (cf_section_parse(cs, sock, command_config) < 0) {
745 #if defined(HAVE_GETPEEREID) || defined (SO_PEERCRED)
746 if (sock->uid_name) {
749 pw = getpwnam(sock->uid_name);
751 radlog(L_ERR, "Failed getting uid for %s: %s",
752 sock->uid_name, strerror(errno));
756 sock->uid = pw->pw_uid;
759 if (sock->gid_name) {
762 gr = getgrnam(sock->gid_name);
764 radlog(L_ERR, "Failed getting gid for %s: %s",
765 sock->gid_name, strerror(errno));
768 sock->gid = gr->gr_gid;
771 #else /* can't get uid or gid of connecting user */
773 if (sock->uid_name || sock->gid_name) {
774 radlog(L_ERR, "System does not support uid or gid authentication for sockets");
781 * FIXME: check for absolute pathnames?
782 * check for uid/gid on the other end...
785 this->fd = fr_server_domain_socket(sock->path);
793 static int command_socket_print(rad_listen_t *this, char *buffer, size_t bufsize)
795 fr_command_socket_t *sock = this->data;
797 snprintf(buffer, bufsize, "command file %s", sock->path);
803 * String split routine. Splits an input string IN PLACE
804 * into pieces, based on spaces.
806 static int str2argv(char *str, char **argv, int max_argc)
811 if (argc >= max_argc) return argc;
814 * Chop out comments early.
821 while ((*str == ' ') ||
824 (*str == '\n')) *(str++) = '\0';
826 if (!*str) return argc;
835 (*str != '\n')) str++;
841 #define MAX_ARGV (16)
844 * Check if an incoming request is "ok"
846 * It takes packets, not requests. It sees if the packet looks
847 * OK. If so, it does a number of sanity checks on it.
849 static int command_domain_recv(rad_listen_t *listener,
850 UNUSED RAD_REQUEST_FUNP *pfun,
851 UNUSED REQUEST **prequest)
856 char *my_argv[MAX_ARGV], **argv;
857 fr_command_table_t *table;
858 fr_command_socket_t *co = listener->data;
864 len = recv(listener->fd, co->buffer + co->offset,
865 sizeof(co->buffer) - co->offset - 1, 0);
866 if (len == 0) goto close_socket; /* clean close */
869 if ((errno == EAGAIN) || (errno == EINTR)) {
878 if ((co->offset == 0) && (co->buffer[0] == 0x04)) {
880 listener->status = RAD_LISTEN_STATUS_CLOSED;
881 event_new_fd(listener);
886 * See if there are multiple lines in the buffer.
888 p = co->buffer + co->offset;
891 for (c = 0; c < len; c++) {
892 if ((*p == '\r') || (*p == '\n')) {
897 * FIXME: do real buffering...
898 * handling of CTRL-C, etc.
903 * \r \n followed by ASCII...
914 * Saw CR/LF. Set next element, and exit.
917 co->next = p - co->buffer;
921 if (co->offset >= (ssize_t) (sizeof(co->buffer) - 1)) {
922 radlog(L_ERR, "Line too long!");
929 argc = str2argv(co->buffer, my_argv, MAX_ARGV);
930 if (argc == 0) goto do_next;
933 for (len = 0; len <= co->offset; len++) {
934 if (co->buffer[len] < 0x20) {
935 co->buffer[len] = '\0';
941 * Hard-code exit && quit.
943 if ((strcmp(argv[0], "exit") == 0) ||
944 (strcmp(argv[0], "quit") == 0)) goto close_socket;
948 if (strcmp(argv[0], "login") != 0) {
949 cprintf(listener, "ERROR: Login required\n");
954 cprintf(listener, "ERROR: login <user> <password>\n");
959 * FIXME: Generate && process fake RADIUS request.
961 if ((strcmp(argv[1], "root") == 0) &&
962 (strcmp(argv[2], "password") == 0)) {
963 strlcpy(co->user, argv[1], sizeof(co->user));
967 cprintf(listener, "ERROR: Login incorrect\n");
972 table = command_table;
975 for (i = 0; table[i].command != NULL; i++) {
976 if (strcmp(table[i].command, argv[0]) == 0) {
977 if (table[i].table) {
979 * This is the last argument, but
980 * there's a sub-table. Print help.
984 table = table[i].table;
990 table = table[i].table;
995 rcode = table[i].func(listener,
1005 if ((strcmp(argv[0], "help") == 0) ||
1006 (strcmp(argv[0], "?") == 0)) {
1008 for (i = 0; table[i].command != NULL; i++) {
1009 if (table[i].help) {
1010 cprintf(listener, "%s\n",
1013 cprintf(listener, "%s <command> - do sub-command of %s\n",
1014 table[i].command, table[i].command);
1020 cprintf(listener, "ERROR: Unknown command \"%s\"\r\n",
1025 cprintf(listener, "radmin> ");
1027 if (co->next <= co->offset) {
1030 memmove(co->buffer, co->buffer + co->next,
1031 co->offset - co->next);
1032 co->offset -= co->next;
1039 static int command_domain_accept(rad_listen_t *listener,
1040 UNUSED RAD_REQUEST_FUNP *pfun,
1041 UNUSED REQUEST **prequest)
1047 struct sockaddr_storage src;
1048 fr_command_socket_t *sock = listener->data;
1050 salen = sizeof(src);
1052 DEBUG2(" ... new connection request on command socket.");
1054 newfd = accept(listener->fd, (struct sockaddr *) &src, &salen);
1057 * Non-blocking sockets must handle this.
1059 if (errno == EWOULDBLOCK) {
1063 DEBUG2(" ... failed to accept connection.");
1068 * Perform user authentication.
1070 if (sock->uid_name || sock->gid_name) {
1074 if (getpeereid(listener->fd, &uid, &gid) < 0) {
1075 radlog(L_ERR, "Failed getting peer credentials for %s: %s",
1076 sock->path, strerror(errno));
1081 if (sock->uid_name && (sock->uid != uid)) {
1082 radlog(L_ERR, "Unauthorized connection to %s from uid %ld",
1083 sock->path, (long int) uid);
1088 if (sock->gid_name && (sock->gid != gid)) {
1089 radlog(L_ERR, "Unauthorized connection to %s from gid %ld",
1090 sock->path, (long int) gid);
1097 * Write 32-bit magic number && version information.
1099 magic = htonl(0xf7eead15);
1100 if (write(newfd, &magic, 4) < 0) {
1101 radlog(L_ERR, "Failed writing initial data to socket: %s",
1106 magic = htonl(1); /* protocol version */
1107 if (write(newfd, &magic, 4) < 0) {
1108 radlog(L_ERR, "Failed writing initial data to socket: %s",
1116 * Add the new listener.
1118 this = listen_alloc(listener->type);
1119 if (!this) return -1;
1122 * Copy everything, including the pointer to the socket
1126 memcpy(this, listener, sizeof(*this));
1127 this->status = RAD_LISTEN_STATUS_INIT;
1129 this->data = sock; /* fix it back */
1132 sock->user[0] = '\0';
1133 sock->path = ((fr_command_socket_t *) listener->data)->path;
1136 this->recv = command_domain_recv;
1139 * Tell the event loop that we have a new FD
1148 * Send an authentication response packet
1150 static int command_domain_send(UNUSED rad_listen_t *listener,
1151 UNUSED REQUEST *request)
1157 static int command_socket_encode(UNUSED rad_listen_t *listener,
1158 UNUSED REQUEST *request)
1164 static int command_socket_decode(UNUSED rad_listen_t *listener,
1165 UNUSED REQUEST *request)
1170 #endif /* WITH_COMMAND_SOCKET */