mirror of
https://gitlab.com/openconnect/ocserv.git
synced 2026-10-12 01:26:48 +08:00
when reading IPv4 routes ensure they are read/converted to proper format
This commit is contained in:
@@ -571,6 +571,59 @@ struct msghdr mh = {
|
||||
return ret;
|
||||
}
|
||||
|
||||
/* check whether a route is on the expected format, and if it cannot be
|
||||
* fixed, then returns a negative code.
|
||||
*
|
||||
* The expected format by clients for IPv4 is xxx.xxx.xxx.xxx/xxx.xxx.xxx.xxx, i.e.,
|
||||
* this function converts xxx.xxx.xxx.xxx/prefix to the above for IPv4.
|
||||
*/
|
||||
int ip_route_sanity_check(void *pool, char **_route)
|
||||
{
|
||||
char *p;
|
||||
unsigned prefix;
|
||||
char *route = *_route, *n;
|
||||
char *slash_ptr, *pstr;
|
||||
|
||||
/* this check is valid for IPv4 only */
|
||||
p = strchr(route, '.');
|
||||
if (p == NULL)
|
||||
return 0;
|
||||
|
||||
p = strchr(p, '/');
|
||||
if (p == NULL) {
|
||||
fprintf(stderr, "route '%s' in wrong format, use xxx.xxx.xxx.xxx/xxx.xxx.xxx.xxx\n", route);
|
||||
return -1;
|
||||
}
|
||||
slash_ptr = p;
|
||||
p++;
|
||||
|
||||
/* if we are in dotted notation exit */
|
||||
if (strchr(p, '.') != 0)
|
||||
return 0;
|
||||
|
||||
/* we are most likely in the xxx.xxx.xxx.xxx/prefix format */
|
||||
prefix = atoi(p);
|
||||
|
||||
pstr = ipv4_prefix_to_mask(pool, prefix);
|
||||
if (pstr == NULL) {
|
||||
fprintf(stderr, "cannot figure format of route '%s'\n", route);
|
||||
return -1;
|
||||
}
|
||||
|
||||
*slash_ptr = 0;
|
||||
|
||||
n = talloc_asprintf(pool, "%s/%s", route, pstr);
|
||||
if (n == NULL) {
|
||||
fprintf(stderr, "memory error\n");
|
||||
return -1;
|
||||
}
|
||||
*_route = n;
|
||||
|
||||
talloc_free(pstr);
|
||||
talloc_free(route);
|
||||
return 0;
|
||||
}
|
||||
|
||||
#ifndef HAVE_STRLCPY
|
||||
|
||||
/*
|
||||
|
||||
@@ -42,6 +42,8 @@ void *_talloc_size2(void *ctx, size_t size);
|
||||
void set_non_block(int fd);
|
||||
void set_block(int fd);
|
||||
|
||||
int ip_route_sanity_check(void *pool, char **_route);
|
||||
|
||||
ssize_t force_write(int sockfd, const void *buf, size_t len);
|
||||
ssize_t force_read(int sockfd, void *buf, size_t len);
|
||||
ssize_t force_read_timeout(int sockfd, void *buf, size_t len, unsigned sec);
|
||||
|
||||
+15
-5
@@ -574,11 +574,13 @@ static void parse_kkdcp(struct cfg_st *config, char **urlfw, unsigned urlfw_size
|
||||
}
|
||||
#endif
|
||||
|
||||
|
||||
static void append_iroutes_from_file(struct cfg_st *config, const char *file)
|
||||
{
|
||||
tOptionValue const * pov;
|
||||
const tOptionValue* val;
|
||||
int ret;
|
||||
unsigned j;
|
||||
|
||||
pov = configFileLoad(file);
|
||||
if (pov == NULL)
|
||||
@@ -594,6 +596,12 @@ static void append_iroutes_from_file(struct cfg_st *config, const char *file)
|
||||
fprintf(stderr, "Error loading iroute from %s\n", file);
|
||||
}
|
||||
|
||||
for (j=0;j<config->known_iroutes_size;j++) {
|
||||
if (ip_route_sanity_check(config->known_iroutes, &config->known_iroutes[j]) != 0)
|
||||
exit(1);
|
||||
}
|
||||
|
||||
|
||||
exit:
|
||||
optionUnloadNested(pov);
|
||||
return;
|
||||
@@ -616,11 +624,6 @@ static void load_iroutes(struct cfg_st *config)
|
||||
} while(r != NULL);
|
||||
}
|
||||
closedir(dir);
|
||||
unsigned i;
|
||||
for (i=0;i<config->known_iroutes_size;i++){
|
||||
fprintf(stderr, "iroute: %s\n", config->known_iroutes[i]);
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
static void parse_cfg_file(void *pool, const char* file, struct perm_cfg_st *perm_config, unsigned reload)
|
||||
@@ -954,6 +957,9 @@ size_t urlfw_size = 0;
|
||||
|
||||
READ_MULTI_LINE("route", config->network.routes, config->network.routes_size);
|
||||
for (j=0;j<config->network.routes_size;j++) {
|
||||
if (ip_route_sanity_check(config->network.routes, &config->network.routes[j]) != 0)
|
||||
exit(1);
|
||||
|
||||
if (strcmp(config->network.routes[j], "0.0.0.0/0") == 0 ||
|
||||
strcmp(config->network.routes[j], "default") == 0) {
|
||||
/* set default route */
|
||||
@@ -965,6 +971,10 @@ size_t urlfw_size = 0;
|
||||
}
|
||||
|
||||
READ_MULTI_LINE("no-route", config->network.no_routes, config->network.no_routes_size);
|
||||
for (j=0;j<config->network.no_routes_size;j++) {
|
||||
if (ip_route_sanity_check(config->network.no_routes, &config->network.no_routes[j]) != 0)
|
||||
exit(1);
|
||||
}
|
||||
|
||||
READ_STRING("default-select-group", config->default_select_group);
|
||||
READ_TF("auto-select-group", auto_select_group, 0);
|
||||
|
||||
+26
-1
@@ -151,6 +151,8 @@ int parse_group_cfg_file(struct cfg_st *global_config,
|
||||
tOptionValue const * pov;
|
||||
const tOptionValue* val, *prev;
|
||||
unsigned prefix = 0;
|
||||
int ret;
|
||||
unsigned j;
|
||||
|
||||
pov = configFileLoad(file);
|
||||
if (pov == NULL) {
|
||||
@@ -179,6 +181,27 @@ unsigned prefix = 0;
|
||||
READ_RAW_MULTI_LINE("no-route", msg->no_routes, msg->n_no_routes);
|
||||
READ_RAW_MULTI_LINE("iroute", msg->iroutes, msg->n_iroutes);
|
||||
|
||||
for (j=0;j<msg->n_routes;j++) {
|
||||
if (ip_route_sanity_check(msg->routes, &msg->routes[j]) != 0) {
|
||||
ret = ERR_READ_CONFIG;
|
||||
goto fail;
|
||||
}
|
||||
}
|
||||
|
||||
for (j=0;j<msg->n_iroutes;j++) {
|
||||
if (ip_route_sanity_check(msg->iroutes, &msg->iroutes[j]) != 0) {
|
||||
ret = ERR_READ_CONFIG;
|
||||
goto fail;
|
||||
}
|
||||
}
|
||||
|
||||
for (j=0;j<msg->n_no_routes;j++) {
|
||||
if (ip_route_sanity_check(msg->no_routes, &msg->no_routes[j]) != 0) {
|
||||
ret = ERR_READ_CONFIG;
|
||||
goto fail;
|
||||
}
|
||||
}
|
||||
|
||||
READ_RAW_MULTI_LINE("dns", msg->dns, msg->n_dns);
|
||||
if (msg->n_dns == 0) {
|
||||
/* try aliases */
|
||||
@@ -229,9 +252,11 @@ unsigned prefix = 0;
|
||||
|
||||
READ_RAW_STRING("user-profile", msg->xml_config_file);
|
||||
|
||||
ret = 0;
|
||||
fail:
|
||||
optionUnloadNested(pov);
|
||||
|
||||
return 0;
|
||||
return ret;
|
||||
}
|
||||
|
||||
static int read_sup_config_file(struct cfg_st *global_config,
|
||||
|
||||
@@ -73,6 +73,10 @@ static int get_sup_config(struct cfg_st *cfg, client_entry_st *entry,
|
||||
}
|
||||
}
|
||||
|
||||
for (i=0;i<msg->n_routes;i++) {
|
||||
ip_route_sanity_check(msg->routes, &msg->routes[i]);
|
||||
}
|
||||
|
||||
if (pctx->ipv4_dns1[0] != 0)
|
||||
dns++;
|
||||
if (pctx->ipv4_dns2[0] != 0)
|
||||
|
||||
Reference in New Issue
Block a user