mirror of
https://gitlab.com/openconnect/ocserv.git
synced 2026-10-12 01:26:48 +08:00
client stats are conveyed to master through sec-mod
That way both can keep a more accurate picture of user statistics.
This commit is contained in:
+2
-2
@@ -57,8 +57,6 @@ static char tmp[32];
|
|||||||
return "terminate";
|
return "terminate";
|
||||||
case CMD_SESSION_INFO:
|
case CMD_SESSION_INFO:
|
||||||
return "session info";
|
return "session info";
|
||||||
case CMD_CLI_STATS:
|
|
||||||
return "cli stats";
|
|
||||||
case CMD_BAN_IP:
|
case CMD_BAN_IP:
|
||||||
return "ban IP";
|
return "ban IP";
|
||||||
case CMD_BAN_IP_REPLY:
|
case CMD_BAN_IP_REPLY:
|
||||||
@@ -66,6 +64,8 @@ static char tmp[32];
|
|||||||
|
|
||||||
case SM_CMD_CLI_STATS:
|
case SM_CMD_CLI_STATS:
|
||||||
return "sm: cli stats";
|
return "sm: cli stats";
|
||||||
|
case SM_CMD_AUTH_CLI_STATS:
|
||||||
|
return "sm: auth cli stats";
|
||||||
case SM_CMD_AUTH_INIT:
|
case SM_CMD_AUTH_INIT:
|
||||||
return "sm: auth init";
|
return "sm: auth init";
|
||||||
case SM_CMD_AUTH_CONT:
|
case SM_CMD_AUTH_CONT:
|
||||||
|
|||||||
+6
-5
@@ -20,6 +20,7 @@
|
|||||||
| |
|
| |
|
||||||
| | (disconnect)
|
| | (disconnect)
|
||||||
| ---SESSION_CLOSE---> |
|
| ---SESSION_CLOSE---> |
|
||||||
|
| <-- CLI_STATS ------ |
|
||||||
|
|
||||||
*/
|
*/
|
||||||
|
|
||||||
@@ -113,11 +114,11 @@ message cli_stats_msg
|
|||||||
{
|
{
|
||||||
required uint64 bytes_in = 1;
|
required uint64 bytes_in = 1;
|
||||||
required uint64 bytes_out = 2;
|
required uint64 bytes_out = 2;
|
||||||
optional bytes sid = 3; /* only required by sec-mod */
|
optional bytes sid = 3;
|
||||||
required uint32 uptime = 4; /* sec-mod */
|
required uint32 uptime = 4;
|
||||||
optional string remote_ip = 5; /* only required by sec-mod */
|
optional string remote_ip = 5;
|
||||||
optional string ipv4 = 6; /* only required by sec-mod */
|
optional string ipv4 = 6;
|
||||||
optional string ipv6 = 7; /* only required by sec-mod */
|
optional string ipv6 = 7;
|
||||||
}
|
}
|
||||||
|
|
||||||
/* UDP_FD */
|
/* UDP_FD */
|
||||||
|
|||||||
+5
-182
@@ -163,159 +163,6 @@ struct proc_st *ctmp;
|
|||||||
return ctmp;
|
return ctmp;
|
||||||
}
|
}
|
||||||
|
|
||||||
static
|
|
||||||
int session_cmd(main_server_st * s, struct proc_st *proc, const uint8_t *cookie, unsigned cookie_size)
|
|
||||||
{
|
|
||||||
int ret, e;
|
|
||||||
SecAuthSessionMsg ireq = SEC_AUTH_SESSION_MSG__INIT;
|
|
||||||
SecAuthSessionReplyMsg *msg = NULL;
|
|
||||||
unsigned type, i;
|
|
||||||
PROTOBUF_ALLOCATOR(pa, proc);
|
|
||||||
|
|
||||||
if (cookie)
|
|
||||||
type = SM_CMD_AUTH_SESSION_OPEN;
|
|
||||||
else
|
|
||||||
type = SM_CMD_AUTH_SESSION_CLOSE;
|
|
||||||
|
|
||||||
ireq.uptime = time(0)-proc->conn_time;
|
|
||||||
ireq.has_uptime = 1;
|
|
||||||
ireq.bytes_in = proc->bytes_in;
|
|
||||||
ireq.has_bytes_in = 1;
|
|
||||||
ireq.bytes_out = proc->bytes_out;
|
|
||||||
ireq.has_bytes_out = 1;
|
|
||||||
ireq.sid.data = proc->sid;
|
|
||||||
ireq.sid.len = sizeof(proc->sid);
|
|
||||||
|
|
||||||
if (cookie) {
|
|
||||||
ireq.cookie.data = (void*)cookie;
|
|
||||||
ireq.cookie.len = cookie_size;
|
|
||||||
ireq.has_cookie = 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
mslog(s, proc, LOG_DEBUG, "sending msg %s to sec-mod", cmd_request_to_str(type));
|
|
||||||
|
|
||||||
ret = send_msg(proc, s->sec_mod_fd, type,
|
|
||||||
&ireq, (pack_size_func)sec_auth_session_msg__get_packed_size,
|
|
||||||
(pack_func)sec_auth_session_msg__pack);
|
|
||||||
if (ret < 0) {
|
|
||||||
mslog(s, proc, LOG_ERR,
|
|
||||||
"error sending message to sec-mod cmd socket");
|
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (type == SM_CMD_AUTH_SESSION_OPEN) {
|
|
||||||
ret = recv_msg(proc, s->sec_mod_fd, SM_CMD_AUTH_SESSION_REPLY,
|
|
||||||
(void *)&msg, (unpack_func) sec_auth_session_reply_msg__unpack);
|
|
||||||
if (ret < 0) {
|
|
||||||
e = errno;
|
|
||||||
mslog(s, proc, LOG_ERR, "error receiving auth reply message from sec-mod cmd socket: %s", strerror(e));
|
|
||||||
return ret;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (msg->reply != AUTH__REP__OK) {
|
|
||||||
mslog(s, proc, LOG_INFO, "could not initiate session for '%s'", proc->username);
|
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* fill in group_cfg_st */
|
|
||||||
if (msg->has_no_udp)
|
|
||||||
proc->config.no_udp = msg->no_udp;
|
|
||||||
|
|
||||||
if (msg->has_deny_roaming)
|
|
||||||
proc->config.deny_roaming = msg->deny_roaming;
|
|
||||||
|
|
||||||
if (msg->has_ipv6_prefix)
|
|
||||||
proc->config.ipv6_prefix = msg->ipv6_prefix;
|
|
||||||
|
|
||||||
if (msg->rx_per_sec)
|
|
||||||
proc->config.rx_per_sec = msg->rx_per_sec;
|
|
||||||
if (msg->tx_per_sec)
|
|
||||||
proc->config.tx_per_sec = msg->tx_per_sec;
|
|
||||||
|
|
||||||
if (msg->net_priority)
|
|
||||||
proc->config.net_priority = msg->net_priority;
|
|
||||||
|
|
||||||
if (msg->ipv4_net) {
|
|
||||||
proc->config.ipv4_network = talloc_strdup(proc, msg->ipv4_net);
|
|
||||||
}
|
|
||||||
if (msg->ipv4_netmask) {
|
|
||||||
proc->config.ipv4_netmask = talloc_strdup(proc, msg->ipv4_netmask);
|
|
||||||
}
|
|
||||||
if (msg->ipv6_net) {
|
|
||||||
proc->config.ipv6_network = talloc_strdup(proc, msg->ipv6_net);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (msg->cgroup) {
|
|
||||||
proc->config.cgroup = talloc_strdup(proc, msg->cgroup);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (msg->xml_config_file) {
|
|
||||||
proc->config.xml_config_file = talloc_strdup(proc, msg->xml_config_file);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (msg->explicit_ipv4) {
|
|
||||||
proc->config.explicit_ipv4 = talloc_strdup(proc, msg->explicit_ipv4);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (msg->explicit_ipv6) {
|
|
||||||
proc->config.explicit_ipv6 = talloc_strdup(proc, msg->explicit_ipv6);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (msg->n_routes > 0) {
|
|
||||||
proc->config.routes = talloc_size(proc, sizeof(char*)*msg->n_routes);
|
|
||||||
for (i=0;i<msg->n_routes;i++) {
|
|
||||||
proc->config.routes[i] = talloc_strdup(proc, msg->routes[i]);
|
|
||||||
}
|
|
||||||
proc->config.routes_size = msg->n_routes;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (msg->n_no_routes > 0) {
|
|
||||||
proc->config.no_routes = talloc_size(proc, sizeof(char*)*msg->n_no_routes);
|
|
||||||
for (i=0;i<msg->n_no_routes;i++) {
|
|
||||||
proc->config.no_routes[i] = talloc_strdup(proc, msg->no_routes[i]);
|
|
||||||
}
|
|
||||||
proc->config.no_routes_size = msg->n_no_routes;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (msg->n_iroutes > 0) {
|
|
||||||
proc->config.iroutes = talloc_size(proc, sizeof(char*)*msg->n_iroutes);
|
|
||||||
for (i=0;i<msg->n_iroutes;i++) {
|
|
||||||
proc->config.iroutes[i] = talloc_strdup(proc, msg->iroutes[i]);
|
|
||||||
}
|
|
||||||
proc->config.iroutes_size = msg->n_iroutes;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (msg->n_dns > 0) {
|
|
||||||
proc->config.dns = talloc_size(proc, sizeof(char*)*msg->n_dns);
|
|
||||||
for (i=0;i<msg->n_dns;i++) {
|
|
||||||
proc->config.dns[i] = talloc_strdup(proc, msg->dns[i]);
|
|
||||||
}
|
|
||||||
proc->config.dns_size = msg->n_dns;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (msg->n_nbns > 0) {
|
|
||||||
proc->config.nbns = talloc_size(proc, sizeof(char*)*msg->n_nbns);
|
|
||||||
for (i=0;i<msg->n_nbns;i++) {
|
|
||||||
proc->config.nbns[i] = talloc_strdup(proc, msg->nbns[i]);
|
|
||||||
}
|
|
||||||
proc->config.nbns_size = msg->n_nbns;
|
|
||||||
}
|
|
||||||
sec_auth_session_reply_msg__free_unpacked(msg, &pa);
|
|
||||||
}
|
|
||||||
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
int session_open(main_server_st * s, struct proc_st *proc, const uint8_t *cookie, unsigned cookie_size)
|
|
||||||
{
|
|
||||||
return session_cmd(s, proc, cookie, cookie_size);
|
|
||||||
}
|
|
||||||
|
|
||||||
int session_close(main_server_st * s, struct proc_st *proc)
|
|
||||||
{
|
|
||||||
return session_cmd(s, proc, NULL, 0);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* k: whether to kill the process
|
/* k: whether to kill the process
|
||||||
*/
|
*/
|
||||||
void remove_proc(main_server_st * s, struct proc_st *proc, unsigned k)
|
void remove_proc(main_server_st * s, struct proc_st *proc, unsigned k)
|
||||||
@@ -328,16 +175,16 @@ void remove_proc(main_server_st * s, struct proc_st *proc, unsigned k)
|
|||||||
if (k && proc->pid != -1 && proc->pid != 0)
|
if (k && proc->pid != -1 && proc->pid != 0)
|
||||||
kill(proc->pid, SIGTERM);
|
kill(proc->pid, SIGTERM);
|
||||||
|
|
||||||
remove_from_script_list(s, proc);
|
|
||||||
if (proc->status == PS_AUTH_COMPLETED) {
|
|
||||||
user_disconnected(s, proc);
|
|
||||||
}
|
|
||||||
|
|
||||||
/* close any pending sessions */
|
/* close any pending sessions */
|
||||||
if (proc->active_sid) {
|
if (proc->active_sid) {
|
||||||
session_close(s, proc);
|
session_close(s, proc);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
remove_from_script_list(s, proc);
|
||||||
|
if (proc->status == PS_AUTH_COMPLETED) {
|
||||||
|
user_disconnected(s, proc);
|
||||||
|
}
|
||||||
|
|
||||||
/* close the intercomm fd */
|
/* close the intercomm fd */
|
||||||
if (proc->fd >= 0)
|
if (proc->fd >= 0)
|
||||||
close(proc->fd);
|
close(proc->fd);
|
||||||
@@ -567,30 +414,6 @@ int handle_commands(main_server_st * s, struct proc_st *proc)
|
|||||||
tun_mtu_msg__free_unpacked(tmsg, &pa);
|
tun_mtu_msg__free_unpacked(tmsg, &pa);
|
||||||
}
|
}
|
||||||
|
|
||||||
break;
|
|
||||||
case CMD_CLI_STATS:{
|
|
||||||
CliStatsMsg *tmsg;
|
|
||||||
|
|
||||||
if (proc->status != PS_AUTH_COMPLETED) {
|
|
||||||
mslog(s, proc, LOG_ERR,
|
|
||||||
"received CLI STATS in unauthenticated state.");
|
|
||||||
ret = ERR_BAD_COMMAND;
|
|
||||||
goto cleanup;
|
|
||||||
}
|
|
||||||
|
|
||||||
tmsg = cli_stats_msg__unpack(&pa, raw_len, raw);
|
|
||||||
if (tmsg == NULL) {
|
|
||||||
mslog(s, proc, LOG_ERR, "error unpacking data");
|
|
||||||
ret = ERR_BAD_COMMAND;
|
|
||||||
goto cleanup;
|
|
||||||
}
|
|
||||||
|
|
||||||
proc->bytes_in = tmsg->bytes_in;
|
|
||||||
proc->bytes_out = tmsg->bytes_out;
|
|
||||||
|
|
||||||
cli_stats_msg__free_unpacked(tmsg, &pa);
|
|
||||||
}
|
|
||||||
|
|
||||||
break;
|
break;
|
||||||
case CMD_SESSION_INFO:{
|
case CMD_SESSION_INFO:{
|
||||||
SessionInfoMsg *tmsg;
|
SessionInfoMsg *tmsg;
|
||||||
|
|||||||
@@ -163,3 +163,180 @@ int handle_sec_mod_commands(main_server_st * s)
|
|||||||
return ret;
|
return ret;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
int session_open(main_server_st * s, struct proc_st *proc, const uint8_t *cookie, unsigned cookie_size)
|
||||||
|
{
|
||||||
|
int ret, e;
|
||||||
|
SecAuthSessionMsg ireq = SEC_AUTH_SESSION_MSG__INIT;
|
||||||
|
SecAuthSessionReplyMsg *msg = NULL;
|
||||||
|
unsigned i;
|
||||||
|
PROTOBUF_ALLOCATOR(pa, proc);
|
||||||
|
|
||||||
|
ireq.uptime = time(0)-proc->conn_time;
|
||||||
|
ireq.has_uptime = 1;
|
||||||
|
ireq.bytes_in = proc->bytes_in;
|
||||||
|
ireq.has_bytes_in = 1;
|
||||||
|
ireq.bytes_out = proc->bytes_out;
|
||||||
|
ireq.has_bytes_out = 1;
|
||||||
|
ireq.sid.data = proc->sid;
|
||||||
|
ireq.sid.len = sizeof(proc->sid);
|
||||||
|
|
||||||
|
if (cookie) {
|
||||||
|
ireq.cookie.data = (void*)cookie;
|
||||||
|
ireq.cookie.len = cookie_size;
|
||||||
|
ireq.has_cookie = 1;
|
||||||
|
}
|
||||||
|
|
||||||
|
mslog(s, proc, LOG_DEBUG, "sending msg %s to sec-mod", cmd_request_to_str(SM_CMD_AUTH_SESSION_OPEN));
|
||||||
|
|
||||||
|
ret = send_msg(proc, s->sec_mod_fd, SM_CMD_AUTH_SESSION_OPEN,
|
||||||
|
&ireq, (pack_size_func)sec_auth_session_msg__get_packed_size,
|
||||||
|
(pack_func)sec_auth_session_msg__pack);
|
||||||
|
if (ret < 0) {
|
||||||
|
mslog(s, proc, LOG_ERR,
|
||||||
|
"error sending message to sec-mod cmd socket");
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
|
||||||
|
ret = recv_msg(proc, s->sec_mod_fd, SM_CMD_AUTH_SESSION_REPLY,
|
||||||
|
(void *)&msg, (unpack_func) sec_auth_session_reply_msg__unpack);
|
||||||
|
if (ret < 0) {
|
||||||
|
e = errno;
|
||||||
|
mslog(s, proc, LOG_ERR, "error receiving auth reply message from sec-mod cmd socket: %s", strerror(e));
|
||||||
|
return ret;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (msg->reply != AUTH__REP__OK) {
|
||||||
|
mslog(s, proc, LOG_INFO, "could not initiate session for '%s'", proc->username);
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* fill in group_cfg_st */
|
||||||
|
if (msg->has_no_udp)
|
||||||
|
proc->config.no_udp = msg->no_udp;
|
||||||
|
|
||||||
|
if (msg->has_deny_roaming)
|
||||||
|
proc->config.deny_roaming = msg->deny_roaming;
|
||||||
|
|
||||||
|
if (msg->has_ipv6_prefix)
|
||||||
|
proc->config.ipv6_prefix = msg->ipv6_prefix;
|
||||||
|
|
||||||
|
if (msg->rx_per_sec)
|
||||||
|
proc->config.rx_per_sec = msg->rx_per_sec;
|
||||||
|
if (msg->tx_per_sec)
|
||||||
|
proc->config.tx_per_sec = msg->tx_per_sec;
|
||||||
|
|
||||||
|
if (msg->net_priority)
|
||||||
|
proc->config.net_priority = msg->net_priority;
|
||||||
|
|
||||||
|
if (msg->ipv4_net) {
|
||||||
|
proc->config.ipv4_network = talloc_strdup(proc, msg->ipv4_net);
|
||||||
|
}
|
||||||
|
if (msg->ipv4_netmask) {
|
||||||
|
proc->config.ipv4_netmask = talloc_strdup(proc, msg->ipv4_netmask);
|
||||||
|
}
|
||||||
|
if (msg->ipv6_net) {
|
||||||
|
proc->config.ipv6_network = talloc_strdup(proc, msg->ipv6_net);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (msg->cgroup) {
|
||||||
|
proc->config.cgroup = talloc_strdup(proc, msg->cgroup);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (msg->xml_config_file) {
|
||||||
|
proc->config.xml_config_file = talloc_strdup(proc, msg->xml_config_file);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (msg->explicit_ipv4) {
|
||||||
|
proc->config.explicit_ipv4 = talloc_strdup(proc, msg->explicit_ipv4);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (msg->explicit_ipv6) {
|
||||||
|
proc->config.explicit_ipv6 = talloc_strdup(proc, msg->explicit_ipv6);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (msg->n_routes > 0) {
|
||||||
|
proc->config.routes = talloc_size(proc, sizeof(char*)*msg->n_routes);
|
||||||
|
for (i=0;i<msg->n_routes;i++) {
|
||||||
|
proc->config.routes[i] = talloc_strdup(proc, msg->routes[i]);
|
||||||
|
}
|
||||||
|
proc->config.routes_size = msg->n_routes;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (msg->n_no_routes > 0) {
|
||||||
|
proc->config.no_routes = talloc_size(proc, sizeof(char*)*msg->n_no_routes);
|
||||||
|
for (i=0;i<msg->n_no_routes;i++) {
|
||||||
|
proc->config.no_routes[i] = talloc_strdup(proc, msg->no_routes[i]);
|
||||||
|
}
|
||||||
|
proc->config.no_routes_size = msg->n_no_routes;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (msg->n_iroutes > 0) {
|
||||||
|
proc->config.iroutes = talloc_size(proc, sizeof(char*)*msg->n_iroutes);
|
||||||
|
for (i=0;i<msg->n_iroutes;i++) {
|
||||||
|
proc->config.iroutes[i] = talloc_strdup(proc, msg->iroutes[i]);
|
||||||
|
}
|
||||||
|
proc->config.iroutes_size = msg->n_iroutes;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (msg->n_dns > 0) {
|
||||||
|
proc->config.dns = talloc_size(proc, sizeof(char*)*msg->n_dns);
|
||||||
|
for (i=0;i<msg->n_dns;i++) {
|
||||||
|
proc->config.dns[i] = talloc_strdup(proc, msg->dns[i]);
|
||||||
|
}
|
||||||
|
proc->config.dns_size = msg->n_dns;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (msg->n_nbns > 0) {
|
||||||
|
proc->config.nbns = talloc_size(proc, sizeof(char*)*msg->n_nbns);
|
||||||
|
for (i=0;i<msg->n_nbns;i++) {
|
||||||
|
proc->config.nbns[i] = talloc_strdup(proc, msg->nbns[i]);
|
||||||
|
}
|
||||||
|
proc->config.nbns_size = msg->n_nbns;
|
||||||
|
}
|
||||||
|
sec_auth_session_reply_msg__free_unpacked(msg, &pa);
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
int session_close(main_server_st * s, struct proc_st *proc)
|
||||||
|
{
|
||||||
|
int ret, e;
|
||||||
|
SecAuthSessionMsg ireq = SEC_AUTH_SESSION_MSG__INIT;
|
||||||
|
CliStatsMsg *msg = NULL;
|
||||||
|
PROTOBUF_ALLOCATOR(pa, proc);
|
||||||
|
|
||||||
|
ireq.uptime = time(0)-proc->conn_time;
|
||||||
|
ireq.has_uptime = 1;
|
||||||
|
ireq.bytes_in = proc->bytes_in;
|
||||||
|
ireq.has_bytes_in = 1;
|
||||||
|
ireq.bytes_out = proc->bytes_out;
|
||||||
|
ireq.has_bytes_out = 1;
|
||||||
|
ireq.sid.data = proc->sid;
|
||||||
|
ireq.sid.len = sizeof(proc->sid);
|
||||||
|
|
||||||
|
mslog(s, proc, LOG_DEBUG, "sending msg %s to sec-mod", cmd_request_to_str(SM_CMD_AUTH_SESSION_CLOSE));
|
||||||
|
|
||||||
|
ret = send_msg(proc, s->sec_mod_fd, SM_CMD_AUTH_SESSION_CLOSE,
|
||||||
|
&ireq, (pack_size_func)sec_auth_session_msg__get_packed_size,
|
||||||
|
(pack_func)sec_auth_session_msg__pack);
|
||||||
|
if (ret < 0) {
|
||||||
|
mslog(s, proc, LOG_ERR,
|
||||||
|
"error sending message to sec-mod cmd socket");
|
||||||
|
return -1;
|
||||||
|
}
|
||||||
|
|
||||||
|
ret = recv_msg(proc, s->sec_mod_fd, SM_CMD_AUTH_CLI_STATS,
|
||||||
|
(void *)&msg, (unpack_func) cli_stats_msg__unpack);
|
||||||
|
if (ret < 0) {
|
||||||
|
e = errno;
|
||||||
|
mslog(s, proc, LOG_ERR, "error receiving auth cli stats message from sec-mod cmd socket: %s", strerror(e));
|
||||||
|
return ret;
|
||||||
|
}
|
||||||
|
|
||||||
|
proc->bytes_in = msg->bytes_in;
|
||||||
|
proc->bytes_out = msg->bytes_out;
|
||||||
|
|
||||||
|
cli_stats_msg__free_unpacked(msg, &pa);
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|||||||
+97
-80
@@ -386,7 +386,7 @@ static void stats_add_to(stats_st *dst, stats_st *src1, stats_st *src2)
|
|||||||
}
|
}
|
||||||
|
|
||||||
static
|
static
|
||||||
int send_failed_auth_sec_reply(int cfd, sec_mod_st *sec)
|
int send_failed_session_open_reply(int cfd, sec_mod_st *sec)
|
||||||
{
|
{
|
||||||
SecAuthSessionReplyMsg rep = SEC_AUTH_SESSION_REPLY_MSG__INIT;
|
SecAuthSessionReplyMsg rep = SEC_AUTH_SESSION_REPLY_MSG__INIT;
|
||||||
void *lpool;
|
void *lpool;
|
||||||
@@ -410,10 +410,93 @@ int send_failed_auth_sec_reply(int cfd, sec_mod_st *sec)
|
|||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static
|
||||||
|
int handle_sec_auth_session_open(int cfd, sec_mod_st *sec, const SecAuthSessionMsg *req)
|
||||||
|
{
|
||||||
|
client_entry_st *e;
|
||||||
|
void *lpool;
|
||||||
|
int ret;
|
||||||
|
SecAuthSessionReplyMsg rep = SEC_AUTH_SESSION_REPLY_MSG__INIT;
|
||||||
|
|
||||||
|
if (req->sid.len != SID_SIZE) {
|
||||||
|
seclog(sec, LOG_ERR, "auth session open but with illegal sid size (%d)!",
|
||||||
|
(int)req->sid.len);
|
||||||
|
return send_failed_session_open_reply(cfd, sec);
|
||||||
|
}
|
||||||
|
|
||||||
|
e = find_client_entry(sec, req->sid.data);
|
||||||
|
if (e == NULL) {
|
||||||
|
seclog(sec, LOG_INFO, "session open but with non-existing SID!");
|
||||||
|
return send_failed_session_open_reply(cfd, sec);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (e->status != PS_AUTH_COMPLETED) {
|
||||||
|
seclog(sec, LOG_ERR, "session open received in unauthenticated client %s "SESSION_STR"!", e->auth_info.username, e->auth_info.psid);
|
||||||
|
return send_failed_session_open_reply(cfd, sec);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (e->time != -1 && time(0) > e->time + sec->config->cookie_timeout) {
|
||||||
|
seclog(sec, LOG_ERR, "session expired; denied session for user '%s' "SESSION_STR, e->auth_info.username, e->auth_info.psid);
|
||||||
|
e->status = PS_AUTH_FAILED;
|
||||||
|
return send_failed_session_open_reply(cfd, sec);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (req->has_cookie == 0 || (req->cookie.len != e->cookie_size) ||
|
||||||
|
memcmp(req->cookie.data, e->cookie, e->cookie_size) != 0) {
|
||||||
|
seclog(sec, LOG_ERR, "cookie error; denied session for user '%s' "SESSION_STR, e->auth_info.username, e->auth_info.psid);
|
||||||
|
e->status = PS_AUTH_FAILED;
|
||||||
|
return send_failed_session_open_reply(cfd, sec);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (sec->config->acct.amod != NULL && sec->config->acct.amod->open_session != NULL && e->session_is_open == 0) {
|
||||||
|
ret = sec->config->acct.amod->open_session(e->module->type, e->auth_ctx, &e->auth_info, req->sid.data, req->sid.len);
|
||||||
|
if (ret < 0) {
|
||||||
|
e->status = PS_AUTH_FAILED;
|
||||||
|
seclog(sec, LOG_INFO, "denied session for user '%s' "SESSION_STR, e->auth_info.username, e->auth_info.psid);
|
||||||
|
return send_failed_session_open_reply(cfd, sec);
|
||||||
|
} else {
|
||||||
|
e->session_is_open = 1;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
rep.reply = AUTH__REP__OK;
|
||||||
|
|
||||||
|
lpool = talloc_new(e);
|
||||||
|
if (lpool == NULL) {
|
||||||
|
return ERR_MEM;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (sec->config_module && sec->config_module->get_sup_config) {
|
||||||
|
ret = sec->config_module->get_sup_config(sec->config, e, &rep, lpool);
|
||||||
|
if (ret < 0) {
|
||||||
|
seclog(sec, LOG_ERR, "error reading additional configuration for '%s' "SESSION_STR, e->auth_info.username, e->auth_info.psid);
|
||||||
|
talloc_free(lpool);
|
||||||
|
return send_failed_session_open_reply(cfd, sec);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
ret = send_msg(lpool, cfd, SM_CMD_AUTH_SESSION_REPLY, &rep,
|
||||||
|
(pack_size_func) sec_auth_session_reply_msg__get_packed_size,
|
||||||
|
(pack_func) sec_auth_session_reply_msg__pack);
|
||||||
|
if (ret < 0) {
|
||||||
|
seclog(sec, LOG_ERR, "error in sending session reply");
|
||||||
|
exit(1); /* we cannot recover */
|
||||||
|
}
|
||||||
|
talloc_free(lpool);
|
||||||
|
|
||||||
|
seclog(sec, LOG_INFO, "initiating session for user '%s' "SESSION_STR, e->auth_info.username, e->auth_info.psid);
|
||||||
|
e->time = -1;
|
||||||
|
e->in_use++;
|
||||||
|
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
static
|
static
|
||||||
int handle_sec_auth_session_close(int cfd, sec_mod_st *sec, const SecAuthSessionMsg *req)
|
int handle_sec_auth_session_close(int cfd, sec_mod_st *sec, const SecAuthSessionMsg *req)
|
||||||
{
|
{
|
||||||
client_entry_st *e;
|
client_entry_st *e;
|
||||||
|
int ret;
|
||||||
|
CliStatsMsg rep = CLI_STATS_MSG__INIT;
|
||||||
|
|
||||||
if (req->sid.len != SID_SIZE) {
|
if (req->sid.len != SID_SIZE) {
|
||||||
seclog(sec, LOG_ERR, "auth session close but with illegal sid size (%d)!",
|
seclog(sec, LOG_ERR, "auth session close but with illegal sid size (%d)!",
|
||||||
@@ -444,6 +527,19 @@ int handle_sec_auth_session_close(int cfd, sec_mod_st *sec, const SecAuthSession
|
|||||||
e->stats.bytes_out = req->bytes_out;
|
e->stats.bytes_out = req->bytes_out;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* send reply */
|
||||||
|
rep.bytes_in = e->stats.bytes_in;
|
||||||
|
rep.bytes_out = e->stats.bytes_out;
|
||||||
|
|
||||||
|
ret = send_msg(e, cfd, SM_CMD_AUTH_CLI_STATS, &rep,
|
||||||
|
(pack_size_func) cli_stats_msg__get_packed_size,
|
||||||
|
(pack_func) cli_stats_msg__pack);
|
||||||
|
if (ret < 0) {
|
||||||
|
seclog(sec, LOG_ERR, "error in sending session stats");
|
||||||
|
exit(1); /* we cannot recover */
|
||||||
|
}
|
||||||
|
|
||||||
|
/* save total stats */
|
||||||
stats_add_to(&e->saved_stats, &e->saved_stats, &e->stats);
|
stats_add_to(&e->saved_stats, &e->saved_stats, &e->stats);
|
||||||
memset(&e->stats, 0, sizeof(e->stats));
|
memset(&e->stats, 0, sizeof(e->stats));
|
||||||
expire_client_entry(sec, e);
|
expire_client_entry(sec, e);
|
||||||
@@ -451,85 +547,6 @@ int handle_sec_auth_session_close(int cfd, sec_mod_st *sec, const SecAuthSession
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
static
|
|
||||||
int handle_sec_auth_session_open(int cfd, sec_mod_st *sec, const SecAuthSessionMsg *req)
|
|
||||||
{
|
|
||||||
client_entry_st *e;
|
|
||||||
void *lpool;
|
|
||||||
int ret;
|
|
||||||
SecAuthSessionReplyMsg rep = SEC_AUTH_SESSION_REPLY_MSG__INIT;
|
|
||||||
|
|
||||||
if (req->sid.len != SID_SIZE) {
|
|
||||||
seclog(sec, LOG_ERR, "auth session open but with illegal sid size (%d)!",
|
|
||||||
(int)req->sid.len);
|
|
||||||
return send_failed_auth_sec_reply(cfd, sec);
|
|
||||||
}
|
|
||||||
|
|
||||||
e = find_client_entry(sec, req->sid.data);
|
|
||||||
if (e == NULL) {
|
|
||||||
seclog(sec, LOG_INFO, "session open but with non-existing SID!");
|
|
||||||
return send_failed_auth_sec_reply(cfd, sec);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (e->status != PS_AUTH_COMPLETED) {
|
|
||||||
seclog(sec, LOG_ERR, "session open received in unauthenticated client %s "SESSION_STR"!", e->auth_info.username, e->auth_info.psid);
|
|
||||||
return send_failed_auth_sec_reply(cfd, sec);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (e->time != -1 && time(0) > e->time + sec->config->cookie_timeout) {
|
|
||||||
seclog(sec, LOG_ERR, "session expired; denied session for user '%s' "SESSION_STR, e->auth_info.username, e->auth_info.psid);
|
|
||||||
e->status = PS_AUTH_FAILED;
|
|
||||||
return send_failed_auth_sec_reply(cfd, sec);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (req->has_cookie == 0 || (req->cookie.len != e->cookie_size) ||
|
|
||||||
memcmp(req->cookie.data, e->cookie, e->cookie_size) != 0) {
|
|
||||||
seclog(sec, LOG_ERR, "cookie error; denied session for user '%s' "SESSION_STR, e->auth_info.username, e->auth_info.psid);
|
|
||||||
e->status = PS_AUTH_FAILED;
|
|
||||||
return send_failed_auth_sec_reply(cfd, sec);
|
|
||||||
}
|
|
||||||
|
|
||||||
if (sec->config->acct.amod != NULL && sec->config->acct.amod->open_session != NULL && e->session_is_open == 0) {
|
|
||||||
ret = sec->config->acct.amod->open_session(e->module->type, e->auth_ctx, &e->auth_info, req->sid.data, req->sid.len);
|
|
||||||
if (ret < 0) {
|
|
||||||
e->status = PS_AUTH_FAILED;
|
|
||||||
seclog(sec, LOG_INFO, "denied session for user '%s' "SESSION_STR, e->auth_info.username, e->auth_info.psid);
|
|
||||||
return send_failed_auth_sec_reply(cfd, sec);
|
|
||||||
} else {
|
|
||||||
e->session_is_open = 1;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
rep.reply = AUTH__REP__OK;
|
|
||||||
|
|
||||||
lpool = talloc_new(e);
|
|
||||||
if (lpool == NULL) {
|
|
||||||
return ERR_MEM;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (sec->config_module && sec->config_module->get_sup_config) {
|
|
||||||
ret = sec->config_module->get_sup_config(sec->config, e, &rep, lpool);
|
|
||||||
if (ret < 0) {
|
|
||||||
seclog(sec, LOG_ERR, "error reading additional configuration for '%s' "SESSION_STR, e->auth_info.username, e->auth_info.psid);
|
|
||||||
talloc_free(lpool);
|
|
||||||
return send_failed_auth_sec_reply(cfd, sec);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
ret = send_msg(lpool, cfd, SM_CMD_AUTH_SESSION_REPLY, &rep,
|
|
||||||
(pack_size_func) sec_auth_session_reply_msg__get_packed_size,
|
|
||||||
(pack_func) sec_auth_session_reply_msg__pack);
|
|
||||||
if (ret < 0) {
|
|
||||||
seclog(sec, LOG_WARNING, "error in sending session reply");
|
|
||||||
}
|
|
||||||
talloc_free(lpool);
|
|
||||||
|
|
||||||
seclog(sec, LOG_INFO, "initiating session for user '%s' "SESSION_STR, e->auth_info.username, e->auth_info.psid);
|
|
||||||
e->time = -1;
|
|
||||||
e->in_use++;
|
|
||||||
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
int handle_sec_auth_session_cmd(int cfd, sec_mod_st *sec, const SecAuthSessionMsg *req,
|
int handle_sec_auth_session_cmd(int cfd, sec_mod_st *sec, const SecAuthSessionMsg *req,
|
||||||
unsigned cmd)
|
unsigned cmd)
|
||||||
|
|||||||
@@ -143,7 +143,6 @@ typedef enum {
|
|||||||
CMD_TUN_MTU = 11,
|
CMD_TUN_MTU = 11,
|
||||||
CMD_TERMINATE = 12,
|
CMD_TERMINATE = 12,
|
||||||
CMD_SESSION_INFO = 13,
|
CMD_SESSION_INFO = 13,
|
||||||
CMD_CLI_STATS = 15,
|
|
||||||
CMD_BAN_IP = 16,
|
CMD_BAN_IP = 16,
|
||||||
CMD_BAN_IP_REPLY = 17,
|
CMD_BAN_IP_REPLY = 17,
|
||||||
|
|
||||||
@@ -161,6 +160,7 @@ typedef enum {
|
|||||||
SM_CMD_AUTH_SESSION_REPLY,
|
SM_CMD_AUTH_SESSION_REPLY,
|
||||||
SM_CMD_AUTH_BAN_IP,
|
SM_CMD_AUTH_BAN_IP,
|
||||||
SM_CMD_AUTH_BAN_IP_REPLY,
|
SM_CMD_AUTH_BAN_IP_REPLY,
|
||||||
|
SM_CMD_AUTH_CLI_STATS,
|
||||||
} cmd_request_t;
|
} cmd_request_t;
|
||||||
|
|
||||||
struct group_cfg_st {
|
struct group_cfg_st {
|
||||||
|
|||||||
Reference in New Issue
Block a user