The FreeRADIUS server $Id: f3670dba8951ca10eb4948feb3dc3db9423a334f $
Loading...
Searching...
No Matches
pair_legacy.c
Go to the documentation of this file.
1/*
2 * This library is free software; you can redistribute it and/or
3 * modify it under the terms of the GNU Lesser General Public
4 * License as published by the Free Software Foundation; either
5 * version 2.1 of the License, or (at your option) any later version.
6 *
7 * This library is distributed in the hope that it will be useful,
8 * but WITHOUT ANY WARRANTY; without even the implied warranty of
9 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
10 * Lesser General Public License for more details.
11 *
12 * You should have received a copy of the GNU Lesser General Public
13 * License along with this library; if not, write to the Free Software
14 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
15 */
16
17/** AVP manipulation and search API
18 *
19 * @file src/lib/util/pair_legacy.c
20 *
21 * @copyright 2000,2006,2015 The FreeRADIUS server project
22 */
23RCSID("$Id: 6102cb99d02877e9d76367286263a166f018ceb9 $")
24
25#include <sys/wait.h>
26
27#include <freeradius-devel/util/dict.h>
28#include <freeradius-devel/util/pair.h>
29#include <freeradius-devel/util/pair_legacy.h>
30#include <freeradius-devel/util/proto.h>
31#include <freeradius-devel/util/regex.h>
32#include <freeradius-devel/util/syserror.h>
33
34#include <freeradius-devel/protocol/radius/rfc2865.h>
35#include <freeradius-devel/protocol/freeradius/freeradius.internal.h>
36
39 L("\t"),
40 L("\n"),
41 L(" "),
42 L("!*"),
43 L("!="),
44 L("!~"),
45 L("&&"), /* Logical operator */
46 L(")"), /* Close condition/sub-condition */
47 L("+="),
48 L("-="),
49 L(":="),
50 L("<"),
51 L("<="),
52 L("=*"),
53 L("=="),
54 L("=~"),
55 L(">"),
56 L(">="),
57 L("||"), /* Logical operator */
58 );
59
61 { L("+="), T_OP_ADD_EQ },
62 { L(":="), T_OP_SET },
63 { L("="), T_OP_EQ },
64};
66
68 { L("!*"), T_OP_CMP_FALSE },
69 { L("!="), T_OP_NE },
70 { L("!~"), T_OP_REG_NE },
71 { L("+="), T_OP_ADD_EQ },
72 { L(":="), T_OP_SET },
73 { L("<"), T_OP_LT },
74 { L("<="), T_OP_LE },
75 { L("="), T_OP_EQ },
76 { L("=*"), T_OP_CMP_TRUE },
77 { L("=="), T_OP_CMP_EQ },
78 { L("=~"), T_OP_REG_EQ },
79 { L(">"), T_OP_GT },
80 { L(">="), T_OP_GE }
81};
83
84/*
85 * Stop parsing bare words at whitespace, comma, or end of list.
86 *
87 * Note that we don't allow escaping of bare words here, as that screws up parsing of raw attributes with
88 * 0x... prefixes.
89 */
90static fr_sbuff_parse_rules_t const bareword_unquoted = {
91 .terminals = &FR_SBUFF_TERMS(
92 L(""),
93 L("\t"),
94 L("\n"),
95 L("\r"),
96 L(" "),
97 L(","),
98 L("}")
99 )
100};
101
102
104{
105 fr_sbuff_t our_in = FR_SBUFF(in);
106 char quote;
107 fr_slen_t slen;
108 fr_sbuff_parse_rules_t const *rules;
109
110 if (fr_sbuff_next_if_char(&our_in, '"')) {
112 quote = '"';
113 parse:
114 slen = fr_value_box_from_substr(vp, &vp->data, vp->da->type, vp->da, &our_in, rules);
115 } else if (fr_sbuff_next_if_char(&our_in, '\'')) {
117 quote = '\'';
118 goto parse;
119 } else if (!fr_sbuff_next_if_char(&our_in, '`')) {
120 quote = '\0';
121 rules = &bareword_unquoted;
122 goto parse;
123 /*
124 * We _sometimes_ support backticks, depending on the
125 * source of the data. This should ONLY be used on
126 * trusted input, like config files.
127 *
128 * We don't impose arbitrary limits on exec input or
129 * output, as AGAIN this should only be used on trusted
130 * input.
131 *
132 * Only the first line of output from the process is used,
133 * and no escape sequences in the output are processed.
134 */
135 } else {
136 fr_sbuff_t *exec_in;
137 size_t exec_out_buff_len = 0;
138 ssize_t exec_out_len;
139 char *exec_out = NULL;
140 FILE *fp;
141 int ret;
142
143 if (!conf->allow_exec) {
144 fr_strerror_const("Backticks are not supported here");
145 return 0;
146 }
147
148 /*
149 * Should only be used for trusted resources, so no artificial limits
150 */
151 FR_SBUFF_TALLOC_THREAD_LOCAL(&exec_in, 1024, SIZE_MAX);
152 if (fr_sbuff_out_unescape_until(NULL, exec_in, &our_in, SIZE_MAX,
154 fr_strerror_const("Failed reading backtick string");
155 return 0;
156 }
157 /*
158 * Don't exec if we know we're going to fail
159 */
160 if (!fr_sbuff_is_char(&our_in, '`')) {
161 fr_strerror_const("Unterminated backtick string");
162 return 0;
163 }
164
165 fp = popen(fr_sbuff_start(exec_in), "r");
166 if (!fp) {
167 fr_strerror_printf("Cannot execute command `%pV`: %s",
169 fr_syserror(errno));
170 return 0;
171 }
172
173 errno = 0; /* If we get EOF immediately, we don't want to emit spurious errors */
174 exec_out_len = getline(&exec_out, &exec_out_buff_len, fp);
175 if ((exec_out_len < 0) || (exec_out == NULL)) { /* defensive */
176 fr_strerror_printf("Cannot read output from command `%pV`: %s",
178 fr_syserror(errno));
179 pclose(fp);
180 return 0;
181 }
182
183 /*
184 * Protect against child writing too much data to stdout,
185 * blocking, and never exiting.
186 *
187 * This is likely overly cautious for this particular use
188 * case, but it doesn't hurt.
189 */
190 {
191 char buffer[128];
192
193 while (fread(buffer, 1, sizeof(buffer), fp) > 0) { /* discard */ }
194 }
195
196 errno = 0; /* ensure we don't have stale errno */
197 ret = pclose(fp);
198 if (ret < 0) {
199 fr_strerror_printf("Error waiting for command `%pV` to finish: %s",
201 fr_syserror(errno));
202 pclose_error:
203 free(exec_out);
204 return 0;
205 } else if (ret != 0) {
206 if (WIFEXITED(ret)) {
207 fr_strerror_printf("Command `%pV` exited with status %d",
209 WEXITSTATUS(ret));
210 } else if (WIFSIGNALED(ret)) {
211 fr_strerror_printf("Command `%pV` terminated by signal %d",
213 WTERMSIG(ret));
214 } else {
215 fr_strerror_printf("Command `%pV` terminated abnormally",
217 }
218 goto pclose_error;
219 }
220
221 /*
222 * Trim line endings
223 */
224 if (exec_out_len > 0 && exec_out[exec_out_len - 1] == '\n') exec_out[--exec_out_len] = '\0';
225 if (exec_out_len > 0 && exec_out[exec_out_len - 1] == '\r') exec_out[--exec_out_len] = '\0';
226
227 slen = fr_value_box_from_substr(vp, &vp->data, vp->da->type, vp->da,
228 &FR_SBUFF_IN(exec_out, exec_out_len), &value_parse_rules_single_quoted);
229 free(exec_out);
230 if (unlikely(slen < 0)) {
231 return 0; /* slen is parse position in the exec output*/
232 }
233
234 quote = '`';
235 }
236
237 if (slen < 0) {
238 fr_assert(slen >= -((ssize_t) 1 << 20));
239 return slen - (quote != 0);
240 }
241
242 if (quote && !fr_sbuff_next_if_char(&our_in, quote)) {
243 fr_strerror_const("Unterminated string");
244 return 0;
245 }
246
247 fr_assert(slen <= ((ssize_t) 1 << 20));
248
249 FR_SBUFF_SET_RETURN(in, &our_in);
250}
251
252/** Our version of a DA stack.
253 *
254 * @todo - add in whether or not we added / created the vp? maybe an edit list?
255 * and then we can clean up the unknown DAs, simply by talloc freeing the edit list.
256 */
257typedef struct {
258 int depth;
259 fr_dict_attr_t const *da[FR_DICT_MAX_TLV_STACK]; //!< parent for parsing
260 fr_pair_t *vp[FR_DICT_MAX_TLV_STACK]; //!< which VP we have created or found
262
263/** Parse a #fr_pair_list_t from a substring
264 *
265 * Syntax: ([raw.]|.)<name>[<.name>] op [(cast)] value...
266 *
267 * A "raw" prefix creates a raw attribute, which allows us to encode raw data which might be invalid for
268 * the given data type. Or if a "(cast)" is given, the value is parsed as the specified data type. Note
269 * that casts can only be to a "leaf" data type, and not to a structural type such as "tlv", "group",
270 * "struct", etc. The "(cast)" syntax can only be used for "raw" attributes, and not for attributes
271 * which are known. The "name" can be either a known attribute, or a numerical OID. Either way, the
272 * final attribute which is created is marked as "raw" or "unknown", and is encoded via the "raw" rules,
273 * and not as the known data type.
274 *
275 * If the first name begins with ".", then it is a _relative_ name. The attribute is created in the
276 * context of the most recently created "structural" data type.
277 *
278 * TBD - we have to determine what the heck that means...
279 *
280 * The "name" can be one or more names from the input dictionary. The names must be known, as numerical
281 * OIDs can only be used when the "raw" prefix is used.
282 *
283 * If there are multiple names (e.g. "foo.bar.baz"), then only the last name can be a "leaf" data
284 * type. All of the intermediate names must be "structural" data types.
285 *
286 * Depending on the input arguments, the operator can be a comparison operator (==, <=, etc.). Or, else
287 * it can be an assignment operator (=, +=). The "=" operator is used to assign, and the "+=" operator
288 * is used to append. No other assignment operators are permitted. Note that "+=" cannot be used with
289 * relative names (i.e. where the name begins with ".")
290 *
291 * The "value" can either be a "leaf" data type (e.g. number, IP address, etc.) or for "structural" data
292 * types it can be a sub-list. A sub-list is a set of attribute assignments which are surrounded by
293 * curly brackets "{...}". When a sub-list is specified, the contents must be either children of the
294 * parent attribute (for "tlv", "struct"), or children referenced by a "group", or internal attributes.
295 *
296 * If an intermediate "name" is an ALIAS, then the attributes are created / used as if all intermediate
297 * names were specified. i.e. ALIAS is a short-cut for names (think "soft link), but it does not change
298 * the hierarchy for normal attributes.
299 *
300 *
301 * Examples
302 * --------
303 *
304 * Name = value
305 * Leaf attributes.
306 * The value MUST be parsed as the leaf data type.
307 *
308 * Name = { children }
309 * Structural attributes.
310 * The children MUST be children of the parent.
311 * OR the children can be from the "internal" dictionary.
312 * OR for type 'group', children of the group reference (usually the dictionary root)
313 *
314 * raw.Name = 0xabcdef
315 * Raw attributes.
316 * The value MUST be a hex string.
317 *
318 * raw.Name = { children }
319 *
320 * @param[in] root where we start parsing from
321 * @param[in,out] relative where we left off, or where we should continue from
322 * @param[in] in input sbuff
323 * @return
324 * - <0 on error
325 * - 0 on no input
326 * - >0 on how many bytes of input we read
327 */
329 fr_sbuff_t *in)
330{
331 int i, components;
332 bool raw, was_unknown;
333 bool was_relative = false;
334 bool append;
335 bool keep_going;
336 fr_type_t raw_type;
337 fr_token_t op;
338 fr_slen_t slen;
339 fr_pair_t *vp;
341 fr_sbuff_marker_t lhs_m, op_m, rhs_m;
342 fr_sbuff_t our_in = FR_SBUFF(in);
343 legacy_da_stack_t da_stack = {};
344
345 if (unlikely(!root->ctx)) {
346 fr_strerror_const("Missing input context (fr_pair_parse_t)");
347 return -1;
348 }
349
350 if (unlikely(!root->da)) {
351 fr_strerror_const("Missing namespace attribute");
352 return -1;
353 }
354
355 if (unlikely(!root->list)) {
356 fr_strerror_const("Missing list");
357 return -1;
358 }
359
360 fr_sbuff_adv_past_blank(&our_in, SIZE_MAX, NULL);
361
362 if (fr_sbuff_remaining(&our_in) == 0) return 0;
363
364 /*
365 * Boot strap the relative references from the root.
366 *
367 * The comparison operations are only used for internal tests, and should not be used by
368 * administrators. So we disallow them, unless the destination list is empty. This check
369 * prevents them from being used in administrative policies.
370 */
371 if (!relative->da) {
372 if (root->allow_compare && !fr_pair_list_empty(root->list)) {
373 fr_strerror_const("Attribute comparisons can only be used when the destination list is empty");
374 return -1;
375 }
376
377 *relative = *root;
378 }
379
380#define CLEAN_DA_STACK do { if (was_unknown) { \
381 for (i = 1; i < da_stack.depth; i++) { \
382 fr_dict_attr_unknown_free(&da_stack.da[i]); \
383 } } } while (0)
384
385 /*
386 * Initialize the markers once, before the redo label, so that they are only inserted into the
387 * marker linked list once. After this, use fr_sbuff_set() to update marker positions.
388 */
389 fr_sbuff_marker(&lhs_m, &our_in);
390 fr_sbuff_marker(&op_m, &our_in);
391 fr_sbuff_marker(&rhs_m, &our_in);
392
393redo:
394 raw = false;
395 raw_type = FR_TYPE_NULL;
396 relative->last_char = 0;
397 was_unknown = false;
398 vp = NULL;
399
400 fr_sbuff_adv_past_blank(&our_in, SIZE_MAX, NULL);
401
402 /*
403 * STEP 1: Figure out if we have relative or absolute attributes.
404 *
405 * Absolute attributes start from the root list / parent.
406 * Or, when there is no previous relative setting.
407 *
408 * Relative attributes start from the input list / parent.
409 *
410 * Once we decide where we start parsing from, all subsequent operations are on the "relative"
411 * structure.
412 */
413 if (!fr_sbuff_next_if_char(&our_in, '.')) {
414 *relative = *root;
415
416 append = !was_relative;
417 was_relative = false;
418
419 /*
420 * Be nice to people who expect to use '&' everywhere.
421 */
422 (void) fr_sbuff_next_if_char(&our_in, '&');
423
424 /*
425 * Raw attributes can only be at our root.
426 *
427 * "raw.foo" means that SOME component of the OID is raw. But the starting bits might be known.
428 *
429 * Raw attributes cannot be created in the internal namespace. But an internal group can
430 * contain raw protocol attributes.
431 */
432 if (fr_sbuff_is_str_literal(&our_in, "raw.")) {
433 fr_sbuff_advance(&our_in, 4);
434 goto is_raw;
435 }
436
437 } else if (relative->da->flags.is_root) {
438 fr_strerror_const("The '.Attribute' syntax cannot be used at the root of a dictionary");
439
440 error:
442 return fr_sbuff_error(&our_in);
443
444 } else if (relative->da->type == FR_TYPE_GROUP) {
445 fr_strerror_printf("The '.Attribute' syntax cannot be used with parent %s of data type 'group'",
446 relative->da->name);
447 goto error;
448
449 } else {
450 fr_assert(relative->ctx);
451 fr_assert(relative->list);
452
453 was_relative = true;
454 append = true;
455 }
456
457 /*
458 * If the input root is an unknown attribute, then forbid internal ones, and force everything
459 * else to be raw, too.
460 */
461 if (relative->da->flags.is_unknown) {
462 is_raw:
463 raw = true;
464 }
465
466 /*
467 * Raw internal attributes don't make sense. An internal group can contain raw protocol
468 * attributes, but the group is not raw.
469 */
470 if (raw && relative->da->flags.internal) {
471 fr_strerror_const("Cannot create internal attributes which are 'raw'");
472 goto error;
473 }
474
475 /*
476 * Set the LHS marker to be after any initial '.'
477 */
478 fr_sbuff_set(&lhs_m, &our_in);
479
480 /*
481 * STEP 2: Find and check the operator.
482 *
483 * Skip over the attribute name. We need to get the operator _before_ creating the VPs.
484 */
485 components = 0;
486 do {
487 if (fr_sbuff_adv_past_allowed(&our_in, SIZE_MAX, fr_dict_attr_allowed_chars, NULL) == 0) break;
488 components++;
489 } while (fr_sbuff_next_if_char(&our_in, '.'));
490
491 /*
492 * Couldn't find anything.
493 */
494 if (!components) goto done;
495
496 fr_sbuff_set(&op_m, &our_in);
497 fr_sbuff_adv_past_blank(&our_in, SIZE_MAX, NULL);
498
499 /*
500 * Look for the operator.
501 */
502 if (relative->allow_compare) {
504 if (op == T_INVALID) {
505 fr_strerror_const("Expecting operator");
506 goto error;
507 }
508
509 /*
510 * People can use this, but it doesn't mean anything.
511 */
512 if (op == T_OP_SET) op = T_OP_EQ;
513
514 } else {
515 /*
516 * @todo - handle different operators ala v3?
517 * What is the difference between ":=" and "="? Perhaps nothing?
518 */
520 if (op == T_INVALID) {
521 fr_strerror_const("Expecting operator");
522 goto error;
523 }
524
525 /*
526 * += means "append"
527 * := menas "don't append".
528 */
529 if (op != T_OP_EQ) {
530 if (was_relative) {
531 fr_strerror_printf("The '.Attribute' syntax cannot be used along with the '%s' operator",
532 fr_tokens[op]);
533 goto error;
534 }
535 }
536
537 if (op == T_OP_ADD_EQ) {
538 append = true;
539 }
540
541 if (op == T_OP_SET) {
542 append = false;
543 }
544
545 op = T_OP_EQ;
546 }
547
548 /*
549 * Check the character after the operator. This check is only necessary to produce better error
550 * messages. i.e. We allow "=", but the user enters "==".
551 */
552 {
553 uint8_t c = fr_sbuff_uint8(&our_in, '\0');
554 static const bool invalid[SBUFF_CHAR_CLASS] = {
555 ['!'] = true, ['#'] = true, ['$'] = true, ['*'] = true,
556 ['+'] = true, ['-'] = true, ['/'] = true, ['<'] = true,
557 ['='] = true, ['>'] = true, ['?'] = true, ['|'] = true,
558 ['~'] = true,
559 };
560
561 if (c && invalid[c]) {
562 fr_strerror_printf("Invalid character '%c' after operator '%s'",
563 (char) c, fr_tokens[op]);
564 goto error;
565 }
566 }
567
568 /*
569 * Skip past whitespace, and set a marker at the RHS value. We do a quick peek at the value, to
570 * set the data type of the RHS. This allows us to parse raw TLVs.
571 */
572 fr_sbuff_adv_past_blank(&our_in, SIZE_MAX, NULL);
573
574 /*
575 * STEP 3: Try to guess the data type for "raw" attributes.
576 *
577 * If the attribute is raw, and the value of the attribute is 0x..., then we always force the raw
578 * type to be octets, even if the attribute is named and known. e.g. raw.Framed-IP-Address =
579 * 0x01.
580 *
581 * OR if the attribute is entirely unknown (and not a raw version of a known one), then we allow a
582 * cast which sets the data type.
583 */
584 if (raw) {
585 if (fr_sbuff_is_str_literal(&our_in, "0x")) {
586 raw_type = FR_TYPE_OCTETS;
587
588 } else if (fr_sbuff_next_if_char(&our_in, '(')) {
589 fr_sbuff_marker_t cast_m;
590
591 fr_sbuff_marker(&cast_m, &our_in);
592
593 fr_sbuff_out_by_longest_prefix(&slen, &raw_type, fr_type_table, &our_in, FR_TYPE_NULL);
594
595 /*
596 * The input has to be a real (non-NULL) leaf. The input shouldn't be cast to a
597 * TLV. Instead, the value should just start with '{'.
598 */
599 if (!fr_type_is_leaf(raw_type)) {
600 fr_sbuff_set(&our_in, &cast_m);
601 fr_strerror_const("Invalid data type in cast");
602 goto error;
603 }
604
605 if (!fr_sbuff_next_if_char(&our_in, ')')) {
606 fr_strerror_const("Missing ')' in cast");
607 goto error;
608 }
609
610 fr_sbuff_adv_past_blank(&our_in, SIZE_MAX, NULL);
611
612 } else if (fr_sbuff_is_char(&our_in, '{')) {
613 /*
614 * Raw attributes default to data type TLV.
615 */
616 raw_type = FR_TYPE_TLV;
617 append = false;
618 }
619 }
620
621 fr_sbuff_set(&rhs_m, &our_in);
622
623 fr_sbuff_set(&our_in, &lhs_m);
624
625 /*
626 * That we know the data type, parse each OID component. We build the DA stack from top to bottom.
627 *
628 * 0 is our relative root. 1..N are the DAs that we find or create.
629 */
630 da_stack = (legacy_da_stack_t) {
631 .da = {
632 [0] = relative->da,
633 },
634 .depth = 1,
635 };
636
637 /*
638 * STEP 4: Re-parse the attributes, building up the da_stack of #fr_dict_attr_t that we will be
639 * using as parents.
640 */
641 for (i = 1; i <= components; i++, da_stack.depth++) {
643 fr_dict_attr_t const *da = NULL;
644 fr_dict_attr_t const *da_unknown = NULL;
645 fr_dict_attr_t const *parent;
646 fr_dict_attr_t const *ref;
647 fr_type_t unknown_type;
648
649 if (da_stack.depth >= FR_DICT_MAX_TLV_STACK) {
650 fr_strerror_printf("Attributes are nested too deeply at \"%.*s\"",
651 (int) fr_sbuff_diff(&op_m, &lhs_m), fr_sbuff_current(&lhs_m));
652 goto error;
653 }
654
655 fr_sbuff_set(&lhs_m, &our_in);
656
657 /*
658 * The fr_pair_t parent might be a group, in which case the fr_dict_attr_t parent will be
659 * different.
660 */
661 parent = da_stack.da[da_stack.depth - 1];
662 if (parent->type == FR_TYPE_GROUP) {
664 fr_assert(parent != NULL);
665 }
666
667 /*
668 * Once we parse a completely unknown attribute, all of the rest of them have to be
669 * unknown, too. We cannot allow unknown TLVs to contain internal attributes, for
670 * example.
671 */
672 if (was_unknown) {
673 goto alloc_unknown;
674 }
675
676 /*
677 * Look up the name (or number). If it's found, life is easy. Otherwise, we jump
678 * through a bunch of hoops to see if we are changing dictionaries, or creating a raw OID
679 * from a number, etc.
680 */
681 slen = fr_dict_oid_component(&err, &da, parent, &our_in, &bareword_terminals);
682 if (err != FR_DICT_ATTR_OK) {
683 /*
684 * We were looking in the internal dictionary. Maybe this attribute is instead
685 * in the protocol dictionary?
686 */
687 if ((i == 1) && (relative->da->dict == relative->internal) && relative->dict) {
688 fr_assert(relative->dict != relative->internal);
689
690 /*
691 * Internal groups can be used to cache protocol data. Internal
692 * structural attributes cannot.
693 *
694 * @todo - this restriction makes sense, but maybe people want to do that
695 * anyways?
696 */
697 if (relative->da->type != FR_TYPE_GROUP) {
698 fr_strerror_printf("Internal attribute '%s' of data type '%s' cannot contain protocol attributes",
699 relative->da->name, fr_type_to_str(relative->da->type));
700 goto error;
701 }
702
703 slen = fr_dict_oid_component(&err, &da, fr_dict_root(relative->dict), &our_in, &bareword_terminals);
704 if (err == FR_DICT_ATTR_OK) {
705 ref = fr_dict_root(relative->dict);
706 goto found;
707 }
708 }
709
710 /*
711 * Try to parse the name from the internal namespace first, as this is the most
712 * likely case. Plus, if we parse the OIDs second, the errors for unknown
713 * attributes mention the protocol dictionary, and not the internal one.
714 *
715 * Raw attributes also cannot be created in the internal dictionary space.
716 */
717 if (!raw && relative->internal) {
718 /*
719 * If the current dictionary isn't internal, then look up the attribute
720 * in the internal dictionary.
721 *
722 * Buf if the current dictionary is internal, AND the internal type is
723 * GROUP, AND we we have a protocol dictionary, then allow an internal
724 * group to contain protocol attributes.
725 */
726 if (parent->dict != relative->internal) {
727 ref = fr_dict_root(relative->internal);
728
729 } else if ((da_stack.da[da_stack.depth - 1]->type == FR_TYPE_GROUP) && (root->da->dict != root->internal)) {
730 ref = fr_dict_root(root->da->dict);
731
732 } else {
733 /*
734 * Otherwise we are already in the internal dictionary, and the
735 * attribute was not found. So don't search for it again in the
736 * internal dictionary. And because we're in the internal
737 * dictionary, we don't allow raw attributes.
738 */
739 goto notfound;
740 }
741
742 slen = fr_dict_oid_component(&err, &da, ref, &our_in, &bareword_terminals);
743 if (err == FR_DICT_ATTR_OK) {
744 goto found;
745 }
746
747 goto notfound;
748 }
749
750 /*
751 * We didn't find anything, that's an error.
752 */
753 if (!raw) {
754 notfound:
755 fr_strerror_printf("Unknown attribute \"%.*s\" for parent \"%s\"",
756 (int) fr_sbuff_diff(&op_m, &our_in), fr_sbuff_current(&our_in),
757 da_stack.da[da_stack.depth - 1]->name);
758 goto error;
759 }
760
761 alloc_unknown:
762 /*
763 * We looked up raw.FOO, and FOO wasn't found. See if we can still parse it.
764 */
765 if (da_stack.da[da_stack.depth - 1]->type == FR_TYPE_GROUP) {
766 fr_strerror_printf("Cannot create 'raw' children in attribute %s of data type 'group'",
767 da_stack.da[da_stack.depth - 1]->name);
768 goto error;
769 }
770
771 /*
772 * Unknown attributes must be 'raw.1234'.
773 */
774 if (!fr_sbuff_is_digit(&our_in)) {
775 goto notfound;
776 }
777
778 /*
779 * Figure out the data type for unknown attributes. Intermediate attributes are
780 * structural. Only the final attribute is forced to "raw_type".
781 */
782 if (i < components) {
783 if (parent->type == FR_TYPE_VSA) {
784 unknown_type = FR_TYPE_VENDOR;
785 } else {
786 unknown_type = FR_TYPE_TLV;
787 }
788
789 } else if (raw_type == FR_TYPE_NULL) {
790 unknown_type = FR_TYPE_OCTETS;
791
792 } else if ((raw_type == FR_TYPE_TLV) && (parent->type == FR_TYPE_VSA)) {
793 /*
794 * We had previously parsed a known VSA, but this component is
795 * perhaps a numerical OID. Set the data type to VENDOR, so that
796 * the hierachy is correct.
797 */
798 unknown_type = FR_TYPE_VENDOR;
799
800 } else {
801 unknown_type = raw_type;
802 }
803
804 da_unknown = fr_dict_attr_unknown_afrom_oid(root->ctx, parent, &our_in, unknown_type);
805 if (!da_unknown) goto error;
806
807 da = da_unknown;
808 was_unknown = true;
809
810 goto next;
811 } /* huge block of "we didn't find a known attribute" */
812
813 /*
814 * We found the component. It MIGHT be an ALIAS which jumps down a few levels. Or, it
815 * might be a group which jumps back to the dictionary root. Or it may suddenly be an
816 * internal attribute.
817 *
818 * For an ALIAS, we need to add intermediate nodes up to the parent.
819 *
820 * For a GROUP, we need to add nodes up to the ref of the group.
821 *
822 * For internal attributes, we need to add nodes up to the root of the internal
823 * dictionary.
824 */
825 if (da->parent != parent) {
826 int j, diff;
827 fr_dict_attr_t const *up;
828
829 ref = parent;
830
831 found:
832 fr_assert(fr_dict_attr_common_parent(ref, da, true) == ref);
833
834 diff = da->depth - ref->depth;
835 fr_assert(diff >= 1);
836
837 diff--;
838
839 if ((da_stack.depth + diff) >= FR_DICT_MAX_TLV_STACK) {
840 fr_strerror_printf("Attributes are nested too deeply at \"%.*s\"",
841 (int) fr_sbuff_diff(&op_m, &lhs_m), fr_sbuff_current(&lhs_m));
842 goto error;
843 }
844
845 /*
846 * Go back up the da_stack, setting the parent.
847 */
848 up = da;
849 for (j = da_stack.depth + diff; j >= da_stack.depth; j--) {
850 da_stack.da[j] = up;
851 up = up->parent;
852 }
853
854 for (j = da_stack.depth; j <= da_stack.depth + diff; j++) {
855 fr_assert(da_stack.da[j] != NULL);
856 }
857
858 /*
859 * Record that we've added more attributes to the da_stack.
860 */
861 da_stack.depth += diff;
862 }
863
864 next:
865 /*
866 * Limit the data types that we can parse. This check is mainly to get better error
867 * messages.
868 */
869 switch (da->type) {
870 case FR_TYPE_GROUP:
871 if (raw && (raw_type != FR_TYPE_OCTETS)) {
872 fr_strerror_printf("Cannot create 'raw' attributes for data type '%s'", fr_type_to_str(da->type));
873 goto error;
874 }
875 break;
876
878 case FR_TYPE_LEAF:
879 break;
880
881 default:
882 fr_strerror_printf("Invalid data type '%s'", fr_type_to_str(da->type));
883 goto error;
884 }
885
886 /*
887 * Everything until the last component must end with a '.', because otherwise there would
888 * be no next component.
889 */
890 if (i < components) {
891 if (!fr_sbuff_next_if_char(&our_in, '.')) {
892 fr_strerror_printf("Missing '.' at \"%.*s\"",
893 (int) fr_sbuff_diff(&op_m, &lhs_m), fr_sbuff_current(&lhs_m));
894 goto error;
895 }
896
897 /*
898 * Leaf attributes cannot appear in the middle of the OID list.
899 */
900 if (fr_type_is_leaf(da->type)) {
902 fr_strerror_printf("Please remove the reference to key field '%s' from the input string",
903 da->name);
904 } else {
905 fr_strerror_printf("Leaf attribute '%s' cannot have children", da->name);
906 }
907
908 goto error;
909 }
910
911 } else if (raw && !da->flags.is_unknown) {
912 /*
913 * Only the last component can be raw. If the attribute we found isn't unknown,
914 * then create an unknown DA from the known one.
915 *
916 * We have parsed the full OID tree, *and* found a known attribute. e.g. raw.Vendor-Specific = ...
917 *
918 * For some reason, we allow: raw.Vendor-Specific = { ... }
919 *
920 * But this is what we really want: raw.Vendor-Specific = 0xabcdef
921 */
922 if ((raw_type != FR_TYPE_OCTETS) && (raw_type != da->type)) {
923 /*
924 * @todo - because it breaks a lot of the encoders.
925 */
926 fr_strerror_printf("Cannot create raw attribute %s which changes data type from %s to %s",
927 da->name, fr_type_to_str(da->type), fr_type_to_str(raw_type));
928 fr_sbuff_set(&our_in, &lhs_m);
929 goto error;
930 }
931
932 da_unknown = fr_dict_attr_unknown_alloc(root->ctx, da, raw_type);
933 if (!da_unknown) goto error;
934
935 da = da_unknown;
936 was_unknown = true;
937 }
938
939 da_stack.da[da_stack.depth] = da;
940 }
941
942 /*
943 * at least [0]=root, [1]=da, [2]=NULL
944 */
945 if (da_stack.depth <= 1) {
946 fr_strerror_const("Internal sanity check failed on depth 1");
947 return fr_sbuff_error(&our_in);
948 }
949
950 if (da_stack.depth <= components) {
951 fr_strerror_const("Internal sanity check failed on depth 2");
952 return fr_sbuff_error(&our_in);
953 }
954
955 /*
956 * STEP 5: Reset the parser to the value, and double-check if it's what we expect.
957 */
958 fr_sbuff_set(&our_in, &rhs_m);
959
960 if (fr_type_is_structural(da_stack.da[da_stack.depth - 1]->type)) {
961 if (!fr_sbuff_is_char(&our_in, '{')) {
962 fr_strerror_printf("Group list for %s MUST start with '{'", da_stack.da[da_stack.depth - 1]->name);
963 goto error;
964 }
965
966 /*
967 * The fr_pair_validate() function doesn't support operators for structural attributes,
968 * so we forbid them here.
969 */
970 if (relative->allow_compare && (op != T_OP_EQ) && (op != T_OP_CMP_EQ)) {
971 fr_strerror_printf("Structural attribute '%s' must use '=' or '==' for comparisons",
972 da_stack.da[da_stack.depth - 1]->name);
973 goto error;
974 }
975
976 /*
977 * If we have "foo = { ... }", then we just create the attribute.
978 */
979 if (components == 1) append = (op != T_OP_EQ);
980 }
981
982#if 0
983 /*
984 * STEP 5.1: Flatten the hierarchy if necessary.
985 */
986 if ((relative->da->flags.allow_flat) && (da_stack.depth > 2)) {
987 da_stack.da[1] = da_stack.da[da_stack.depth - 1];
988
989 da_stack.depth = 2;
990 }
991#endif
992
993 /*
994 * STEP 6: Use the da_stack to either find or add intermediate #fr_pair_t.
995 */
996 my = *relative;
997 for (i = 1; i < da_stack.depth; i++) {
998 fr_dict_attr_t const *da;
999
1000 da = da_stack.da[i];
1001
1002 /*
1003 * When we have a full path that contains MEMBERs of a STRUCT, we need to check ordering.
1004 * The children MUST be added in order. If we see a child that is out of order, then
1005 * that means we need to start a new parent STRUCT.
1006 */
1007 if ((da->parent->type == FR_TYPE_STRUCT) && (i > 1)) {
1008 fr_assert(da_stack.da[i - 1] == da->parent);
1009 fr_assert(da_stack.vp[i - 1] != NULL);
1010 fr_assert(my.ctx == da_stack.vp[i - 1]);
1011
1012 /*
1013 * @todo - cache the last previous child that we added? Or maybe the DA of the
1014 * last child?
1015 */
1016 for (vp = fr_pair_list_tail(my.list);
1017 vp != NULL;
1018 vp = fr_pair_list_prev(my.list, vp)) {
1019 if (!vp->da->flags.internal) break;
1020 }
1021
1022 if (vp && (vp->da->attr > da->attr)) {
1023 fr_pair_t *parent = da_stack.vp[i - 2];
1024
1025 if (parent) {
1026 if (fr_pair_append_by_da(parent, &vp, &parent->vp_group, da->parent) < 0) {
1027 goto error;
1028 }
1029 } else {
1030 if (fr_pair_append_by_da(root->ctx, &vp, root->list, da->parent) < 0) {
1031 goto error;
1032 }
1033 }
1034
1035 vp->op = T_OP_EQ;
1037 my.ctx = vp;
1038 my.list = &vp->vp_group;
1039 }
1040 }
1041
1042 /*
1043 * Everything up to the last entry must be structural.
1044 *
1045 * The last entry may be structural, or else it might be a leaf.
1046 */
1047 if (fr_type_is_structural(da->type)) {
1048 if (append) {
1050 if (vp) goto update_relative;
1051 }
1052
1053 if (fr_pair_append_by_da(my.ctx, &vp, my.list, da) < 0) {
1054 goto error;
1055 }
1056
1057 vp->op = T_OP_EQ;
1059
1060 update_relative:
1061 da_stack.vp[i] = vp;
1062
1063 my.ctx = vp;
1064 my.da = vp->da;
1065 my.list = &vp->vp_group;
1066 continue;
1067 }
1068
1069 /*
1070 * We're finally at the leaf attribute, which must be the last attribute.
1071 */
1072 fr_assert(i == (da_stack.depth - 1));
1073
1074 vp = fr_pair_afrom_da(my.ctx, da);
1075 if (!vp) goto error;
1076
1078 vp->op = op;
1079 da_stack.vp[i] = vp;
1080 }
1081
1082 /*
1083 * Intermediate nodes always use the operator '='. The final one uses the assigned operator.
1084 */
1085 fr_assert(vp != NULL);
1086 fr_assert(vp->op != T_INVALID);
1087
1088 /*
1089 * STEP 7: Parse the value, recursing if necessary.
1090 *
1091 * @todo - do all kinds of cleanups if anything fails. TBH, this really needs the edit lists,
1092 * and that might be a bit much overhead for this code.
1093 */
1094 if (fr_type_is_structural(vp->da->type)) {
1097 .dict = root->dict,
1098 .internal = root->internal,
1099 };
1100
1101 if (!fr_sbuff_next_if_char(&our_in, '{')) {
1102 fr_strerror_printf("Child list for %s MUST start with '{'", vp->da->name);
1103 goto error;
1104 }
1105
1106 fr_assert(my.ctx == vp);
1107 fr_assert(my.da == vp->da);
1108 fr_assert(my.list == &vp->vp_group);
1109 my.allow_compare = root->allow_compare;
1110 my.end_of_list = true;
1111
1112 while (true) {
1113 fr_sbuff_adv_past_blank(&our_in, SIZE_MAX, NULL);
1114
1115 if (fr_sbuff_is_char(&our_in, '}')) {
1116 break;
1117 }
1118
1119 slen = fr_pair_list_afrom_substr(&my, &child, &our_in);
1120 if (!slen) break;
1121
1122 if (slen < 0) goto error;
1123 }
1124
1125 if (!fr_sbuff_next_if_char(&our_in, '}')) {
1126 fr_strerror_const("Failed to end list with '}'");
1127 goto error;
1128 }
1129
1130 /*
1131 * This structure was the last thing we parsed. The next thing starts from here.
1132 */
1133 *relative = my;
1134
1135 } else {
1136 slen = fr_pair_value_from_substr(root, vp, &our_in);
1137 if (slen <= 0) goto error;
1138
1139 fr_pair_append(my.list, vp);
1140 }
1141
1142 PAIR_VERIFY(vp);
1143
1145
1146 fr_sbuff_adv_past_blank(&our_in, SIZE_MAX, NULL);
1147
1148 /*
1149 * STEP 8: See if we're done, or if we need to stop parsing this #fr_pair_t.
1150 *
1151 * Allow a limited set of characters after a value.
1152 *
1153 * It can be "," OR "CRLF" OR ",CRLF". But not anything else.
1154 */
1155 keep_going = false;
1156 if (fr_sbuff_next_if_char(&our_in, ',')) {
1157 fr_sbuff_adv_past_blank(&our_in, SIZE_MAX, NULL);
1158
1159 keep_going = true;
1160 relative->last_char = ',';
1161 }
1162
1163 /*
1164 * We hit the end of the parent list. There's no need to update "relative", we just return, and
1165 * let the caller end the list.
1166 *
1167 * Note that we allow trailing commas: Foo = { Bar = Baz, }
1168 *
1169 * We don't care about any trailing data.
1170 */
1171 if (relative->end_of_list && fr_sbuff_is_char(&our_in, '}')) {
1172 relative->last_char = '\0';
1173 goto done;
1174 }
1175
1176 if (relative->allow_crlf) {
1177 size_t len;
1178
1179 len = fr_sbuff_adv_past_allowed(&our_in, SIZE_MAX, sbuff_char_line_endings, NULL);
1180 if (len) {
1181 keep_going = true;
1182 if (!relative->last_char) relative->last_char = '\n';
1183 }
1184 }
1185
1186 /*
1187 * This is mainly for the detail file reader. We allow zeros as end of "attr op value". But we
1188 * also treat zeros as "don't keep going".
1189 */
1190 if (relative->allow_zeros) {
1191 while (fr_sbuff_next_if_char(&our_in, '\0')) {
1192 /* nothing */
1193 }
1194
1195 goto done;
1196 }
1197
1198 /*
1199 * There's no more input, we're done. Any next attributes will cause the input to be parsed from
1200 * the root again.
1201 */
1202 (void) fr_sbuff_extend(&our_in);
1203 if (!fr_sbuff_remaining(&our_in)) goto done;
1204
1205 /*
1206 * STEP 9: If we need to keep going, then set up the relative references based on what we've
1207 * done, and go back to start over again.
1208 *
1209 * The caller is responsible for checking whether or not we have too much data.
1210 */
1211 if (keep_going) {
1212 /*
1213 * Update the relative list for parsing the next pair.
1214 */
1215 if (fr_type_is_leaf(vp->da->type)) {
1217
1219 if (!parent) {
1220 *relative = *root;
1221
1222 } else {
1223 relative->ctx = parent;
1224 relative->da = parent->da;
1225 relative->list = &parent->vp_group;
1226 }
1227
1228 } else {
1229 relative->ctx = vp;
1230 relative->da = vp->da;
1231 relative->list = &vp->vp_group;
1232 }
1233
1234 goto redo;
1235 }
1236
1237 /*
1238 * STEP 10: Complain if we have unexpected input.
1239 *
1240 * We have more input, BUT we didn't have a comma or CRLF to explicitly finish the last pair we
1241 * read. That's a problem.
1242 */
1243 if (!relative->last_char) {
1244 size_t remaining;
1245
1246 remaining = fr_sbuff_remaining(&our_in);
1247
1248 if (remaining > 20) remaining = 20;
1249
1250 fr_strerror_printf("Unexpected text '%.*s ...' after value",
1251 (int) remaining, fr_sbuff_current(&our_in));
1252 return fr_sbuff_error(&our_in); /* da_stack has already been cleaned */
1253 }
1254
1255done:
1256 /*
1257 * STEP 11: Finally done.
1258 */
1259 FR_SBUFF_SET_RETURN(in, &our_in);
1260}
1261
1262/** Read valuepairs from the fp up to End-Of-File.
1263 *
1264 * @param[in] ctx for talloc
1265 * @param[in] dict to resolve attributes in.
1266 * @param[in,out] out where the parsed fr_pair_ts will be appended.
1267 * @param[in] fp to read valuepairs from.
1268 * @param[out] pfiledone true if file parsing complete;
1269 * @param[in] allow_exec Whether we allow `backtick` expansions.
1270 * @return
1271 * - 0 on success
1272 * - -1 on error
1273 */
1274int fr_pair_list_afrom_file(TALLOC_CTX *ctx, fr_dict_t const *dict, fr_pair_list_t *out, FILE *fp, bool *pfiledone, bool allow_exec)
1275{
1276 fr_pair_list_t tmp_list;
1277 fr_pair_parse_t root, relative;
1278 bool found = false;
1279 char buf[8192];
1280
1281 /*
1282 * Read all of the attributes on the current line.
1283 *
1284 * If we get nothing but an EOL, it's likely OK.
1285 */
1286 fr_pair_list_init(&tmp_list);
1287
1288 root = (fr_pair_parse_t) {
1289 .ctx = ctx,
1290 .da = fr_dict_root(dict),
1291 .list = &tmp_list,
1292 .dict = dict,
1293 .internal = fr_dict_internal(),
1294 .allow_crlf = true,
1295 .allow_compare = true,
1296 .allow_exec = allow_exec
1297 };
1298 relative = (fr_pair_parse_t) { };
1299
1300 while (fgets(buf, sizeof(buf), fp) != NULL) {
1301 /*
1302 * If we get a '\n' by itself, we assume that's
1303 * the end of that VP list.
1304 */
1305 if ((buf[0] == '\n') || (buf[0] == '\r')) {
1306 if (found) {
1307 *pfiledone = false;
1308 break;
1309 }
1310 continue;
1311 }
1312
1313 /*
1314 * Comments get ignored
1315 */
1316 if (buf[0] == '#') continue;
1317
1318 /*
1319 * Leave "relative" between calls, so that we can do:
1320 *
1321 * foo = {}
1322 * .bar = baz
1323 *
1324 * and get
1325 *
1326 * foo = { bar = baz }
1327 */
1328 if (fr_pair_list_afrom_substr(&root, &relative, &FR_SBUFF_IN_STR(buf)) < 0) {
1329 *pfiledone = false;
1330 fr_pair_list_free(&tmp_list);
1331 return -1;
1332 }
1333
1334 found = true;
1335 }
1336
1337#ifdef WITH_VERIFY_PTR
1338 fr_pair_list_verify(__FILE__, __LINE__, ctx, &tmp_list, true);
1339#endif
1340
1341 fr_pair_list_append(out, &tmp_list);
1342
1343 *pfiledone = true;
1344 return 0;
1345}
1346
1347
1348/** Move pairs from source list to destination list respecting operator
1349 *
1350 * @note This function does some additional magic that's probably not needed in most places. Consider using
1351 * radius_legacy_map_cmp() and radius_legacy_map_apply() instead.
1352 *
1353 * @note fr_pair_list_free should be called on the head of the source list to free
1354 * unmoved attributes (if they're no longer needed).
1355 *
1356 * @param[in,out] to destination list.
1357 * @param[in,out] from source list.
1358 * @param[in] op operator for list move.
1359 */
1361{
1362 fr_pair_t *vp, *next, *found;
1363 fr_pair_list_t head_append, head_prepend;
1364
1365 if (!to || fr_pair_list_empty(from)) return;
1366
1367 /*
1368 * We're editing the "to" list while we're adding new
1369 * attributes to it. We don't want the new attributes to
1370 * be edited, so we create an intermediate list to hold
1371 * them during the editing process.
1372 */
1373 fr_pair_list_init(&head_append);
1374
1375 /*
1376 * Any attributes that are requested to be prepended
1377 * are added to a temporary list here
1378 */
1379 fr_pair_list_init(&head_prepend);
1380
1381 /*
1382 * We're looping over the "from" list, moving some
1383 * attributes out, but leaving others in place.
1384 */
1385 for (vp = fr_pair_list_head(from); vp != NULL; vp = next) {
1386 PAIR_VERIFY(vp);
1387 next = fr_pair_list_next(from, vp);
1388
1389 /*
1390 * We never move Fall-Through.
1391 */
1392 if (fr_dict_attr_is_top_level(vp->da) && (vp->da->attr == FR_FALL_THROUGH) &&
1394 continue;
1395 }
1396
1397 /*
1398 * Unlike previous versions, we treat all other
1399 * attributes as normal. i.e. there's no special
1400 * treatment for passwords or Hint.
1401 */
1402
1403 switch (vp->op) {
1404 /*
1405 * Anything else are operators which
1406 * shouldn't occur. We ignore them, and
1407 * leave them in place.
1408 */
1409 default:
1410 continue;
1411
1412 /*
1413 * Add it to the "to" list, but only if
1414 * it doesn't already exist.
1415 */
1416 case T_OP_EQ:
1417 found = fr_pair_find_by_da(to, NULL, vp->da);
1418 if (!found) goto do_add;
1419 continue;
1420
1421 /*
1422 * Add it to the "to" list, and delete any attribute
1423 * of the same vendor/attr which already exists.
1424 */
1425 case T_OP_SET:
1426 found = fr_pair_find_by_da(to, NULL, vp->da);
1427 if (!found) goto do_add;
1428
1429 /*
1430 * Delete *all* matching attributes.
1431 */
1432 fr_pair_delete_by_da(to, found->da);
1433 goto do_add;
1434
1435 /*
1436 * Move it from the old list and add it
1437 * to the new list.
1438 */
1439 case T_OP_ADD_EQ:
1440 do_add:
1441 fr_pair_remove(from, vp);
1442 fr_pair_append(&head_append, vp);
1443 continue;
1444
1445 case T_OP_PREPEND:
1446 fr_pair_remove(from, vp);
1447 fr_pair_prepend(&head_prepend, vp);
1448 continue;
1449 }
1450 } /* loop over the "from" list. */
1451
1452 /*
1453 * If the op parameter was prepend, add the "new list
1454 * attributes first as those whose individual operator
1455 * is prepend should be prepended to the resulting list
1456 */
1457 if (op == T_OP_PREPEND) fr_pair_list_prepend(to, &head_append);
1458
1459 /*
1460 * If there are any items in the prepend list prepend
1461 * it to the "to" list
1462 */
1463 fr_pair_list_prepend(to, &head_prepend);
1464
1465 /*
1466 * If the op parameter was not prepend, take the "new"
1467 * list, and append it to the "to" list.
1468 */
1469 if (op != T_OP_PREPEND) fr_pair_list_append(to, &head_append);
1470
1471 fr_pair_list_free(from);
1472}
static int const char char buffer[256]
Definition acutest.h:576
#define RCSID(id)
Definition build.h:560
#define L(_str)
Helper for initialising arrays of string literals.
Definition build.h:228
#define unlikely(_x)
Definition build.h:455
#define NUM_ELEMENTS(_t)
Definition build.h:406
fr_dict_t * dict
Definition common.c:31
fr_dict_t const * fr_dict_by_da(fr_dict_attr_t const *da)
Attempt to locate the protocol dictionary containing an attribute.
Definition dict_util.c:2938
fr_dict_attr_t const * fr_dict_attr_common_parent(fr_dict_attr_t const *a, fr_dict_attr_t const *b, bool is_ancestor)
Find a common ancestor that two TLV type attributes share.
Definition dict_util.c:2368
bool const fr_dict_attr_allowed_chars[SBUFF_CHAR_CLASS]
Characters allowed in a single dictionary attribute name.
Definition dict_util.c:56
static fr_slen_t err
Definition dict.h:904
static fr_dict_attr_t * fr_dict_attr_unknown_afrom_oid(TALLOC_CTX *ctx, fr_dict_attr_t const *parent, fr_sbuff_t *in, fr_type_t type)
Definition dict.h:642
fr_dict_attr_t * fr_dict_attr_unknown_alloc(TALLOC_CTX *ctx, fr_dict_attr_t const *da, fr_type_t type))
Allocate an unknown DA.
fr_dict_attr_t const * fr_dict_root(fr_dict_t const *dict)
Return the root attribute of a dictionary.
Definition dict_util.c:2720
fr_dict_t const * fr_dict_internal(void)
Definition dict_util.c:5065
static bool fr_dict_attr_is_top_level(fr_dict_attr_t const *da)
Return true if this attribute is parented directly off the dictionary root.
Definition dict.h:831
#define FR_DICT_MAX_TLV_STACK
Maximum TLV stack size.
Definition dict.h:541
fr_dict_attr_err_t
Errors returned by attribute lookup functions.
Definition dict.h:341
@ FR_DICT_ATTR_OK
No error.
Definition dict.h:342
fr_slen_t fr_dict_oid_component(fr_dict_attr_err_t *err, fr_dict_attr_t const **out, fr_dict_attr_t const *parent, fr_sbuff_t *in, fr_sbuff_term_t const *tt))
Parse an OID component, resolving it to a defined attribute.
Definition dict_util.c:2545
#define fr_dict_attr_is_key_field(_da)
Definition dict.h:170
static fr_slen_t in
Definition dict.h:904
static fr_dict_attr_t const * fr_dict_attr_ref(fr_dict_attr_t const *da)
Return the reference associated with a group type attribute.
Definition dict_ext.h:149
free(array)
#define SBUFF_CHAR_CLASS
fr_type_t
@ FR_TYPE_TLV
Contains nested attributes.
@ FR_TYPE_NULL
Invalid (uninitialised) attribute type.
@ FR_TYPE_STRUCT
like TLV, but without T or L, and fixed-width children
@ FR_TYPE_VENDOR
Attribute that represents a vendor in the attribute tree.
@ FR_TYPE_VSA
Vendor-Specific, for RADIUS attribute 26.
@ FR_TYPE_OCTETS
Raw octets.
@ FR_TYPE_GROUP
A grouping of other attributes.
long int ssize_t
unsigned char uint8_t
fr_sbuff_err_t fr_sbuff_out_unescape_until(size_t *len, fr_sbuff_t *out, fr_sbuff_t *in, size_t max, fr_sbuff_term_t const *tt, fr_sbuff_unescape_rules_t const *u_rules)
ssize_t fr_slen_t
int fr_pair_append_by_da(TALLOC_CTX *ctx, fr_pair_t **out, fr_pair_list_t *list, fr_dict_attr_t const *da)
Alloc a new fr_pair_t (and append)
Definition pair.c:1417
fr_pair_t * fr_pair_find_by_da(fr_pair_list_t const *list, fr_pair_t const *prev, fr_dict_attr_t const *da)
Find the first pair with a matching da.
Definition pair.c:708
int fr_pair_append(fr_pair_list_t *list, fr_pair_t *to_add)
Add a VP to the end of the list.
Definition pair.c:1298
int fr_pair_delete_by_da(fr_pair_list_t *list, fr_dict_attr_t const *da)
Delete matching pairs from the specified list.
Definition pair.c:1642
fr_pair_t * fr_pair_parent(fr_pair_t const *vp)
Return a pointer to the parent pair.
Definition pair.c:915
fr_pair_t * fr_pair_afrom_da(TALLOC_CTX *ctx, fr_dict_attr_t const *da)
Dynamically allocate a new attribute and assign a fr_dict_attr_t.
Definition pair.c:291
void fr_pair_list_init(fr_pair_list_t *list)
Initialise a pair list header.
Definition pair.c:47
fr_pair_t * fr_pair_find_last_by_da(fr_pair_list_t const *list, fr_dict_attr_t const *da)
Find the last pair with a matching da.
Definition pair.c:731
int fr_pair_prepend(fr_pair_list_t *list, fr_pair_t *to_add)
Add a VP to the start of the list.
Definition pair.c:1267
static fr_slen_t fr_pair_value_from_substr(fr_pair_parse_t const *conf, fr_pair_t *vp, fr_sbuff_t *in)
static fr_sbuff_parse_rules_t const bareword_unquoted
Definition pair_legacy.c:90
static fr_table_num_sorted_t const pair_assignment_op_table[]
Definition pair_legacy.c:60
fr_slen_t fr_pair_list_afrom_substr(fr_pair_parse_t const *root, fr_pair_parse_t *relative, fr_sbuff_t *in)
Parse a fr_pair_list_t from a substring.
int fr_pair_list_afrom_file(TALLOC_CTX *ctx, fr_dict_t const *dict, fr_pair_list_t *out, FILE *fp, bool *pfiledone, bool allow_exec)
Read valuepairs from the fp up to End-Of-File.
void fr_pair_list_move_op(fr_pair_list_t *to, fr_pair_list_t *from, fr_token_t op)
Move pairs from source list to destination list respecting operator.
static size_t pair_comparison_op_table_len
Definition pair_legacy.c:82
fr_pair_t * vp[FR_DICT_MAX_TLV_STACK]
which VP we have created or found
#define CLEAN_DA_STACK
fr_dict_attr_t const * da[FR_DICT_MAX_TLV_STACK]
parent for parsing
static fr_table_num_sorted_t const pair_comparison_op_table[]
Definition pair_legacy.c:67
static fr_sbuff_term_t const bareword_terminals
Definition pair_legacy.c:37
static ssize_t pair_assignment_op_table_len
Definition pair_legacy.c:65
Our version of a DA stack.
TALLOC_CTX * ctx
Definition pair_legacy.h:43
bool allow_crlf
allow CRLF, and treat like comma
Definition pair_legacy.h:51
bool allow_zeros
allow '\0' as end of attribute
Definition pair_legacy.h:52
fr_dict_t const * dict
the protocol dictionary we use
Definition pair_legacy.h:47
char last_char
last character we read - ',', ' ', or 0 for EOF
Definition pair_legacy.h:59
fr_pair_list_t * list
list where output is placed
Definition pair_legacy.h:45
bool end_of_list
do we expect an end of list '}' character?
Definition pair_legacy.h:60
bool allow_compare
allow comparison operators
Definition pair_legacy.h:50
fr_dict_attr_t const * da
root da to start parsing from
Definition pair_legacy.h:44
fr_dict_t const * internal
a cached pointer to the internal dictionary
Definition pair_legacy.h:48
#define fr_assert(_expr)
Definition rad_assert.h:37
static bool done
Definition radclient.c:80
#define WIFEXITED(stat_val)
Definition radiusd.c:66
#define WEXITSTATUS(stat_val)
Definition radiusd.c:63
static rs_t * conf
Definition radsniff.c:52
size_t fr_sbuff_adv_past_allowed(fr_sbuff_t *sbuff, size_t len, bool const allowed[static SBUFF_CHAR_CLASS], fr_sbuff_term_t const *tt)
Wind position past characters in the allowed set.
Definition sbuff.c:1936
bool const sbuff_char_line_endings[SBUFF_CHAR_CLASS]
Definition sbuff.c:119
bool fr_sbuff_next_if_char(fr_sbuff_t *sbuff, char c)
Return true if the current char matches, and if it does, advance.
Definition sbuff.c:2247
#define fr_sbuff_start(_sbuff_or_marker)
#define fr_sbuff_out_by_longest_prefix(_match_len, _out, _table, _sbuff, _def)
#define fr_sbuff_is_str_literal(_sbuff, _str)
#define fr_sbuff_set(_dst, _src)
#define fr_sbuff_diff(_a, _b)
#define FR_SBUFF_IN(_start, _len_or_end)
#define fr_sbuff_current(_sbuff_or_marker)
#define FR_SBUFF_TERMS(...)
Initialise a terminal structure with a list of sorted strings.
Definition sbuff.h:190
#define fr_sbuff_extend(_sbuff_or_marker)
#define fr_sbuff_is_char(_sbuff_or_marker, _c)
#define FR_SBUFF_SET_RETURN(_dst, _src)
#define fr_sbuff_is_digit(_sbuff_or_marker)
#define fr_sbuff_uint8(_sbuff_or_marker, _eob)
#define FR_SBUFF_IN_STR(_start)
#define fr_sbuff_error(_sbuff_or_marker)
#define FR_SBUFF(_sbuff_or_marker)
#define fr_sbuff_adv_past_blank(_sbuff, _len, _tt)
#define fr_sbuff_advance(_sbuff_or_marker, _len)
#define fr_sbuff_remaining(_sbuff_or_marker)
#define fr_sbuff_used(_sbuff_or_marker)
#define FR_SBUFF_TALLOC_THREAD_LOCAL(_out, _init, _max)
Set of terminal elements.
fr_pair_t * vp
Stores an attribute, a value and various bits of other data.
Definition pair.h:68
fr_dict_attr_t const *_CONST da
Dictionary attribute defines the attribute number, vendor and type of the pair.
Definition pair.h:69
char const * fr_syserror(int num)
Guaranteed to be thread-safe version of strerror.
Definition syserror.c:243
An element in a lexicographically sorted array of name to num mappings.
Definition table.h:49
char const * fr_tokens[T_TOKEN_LAST]
Definition token.c:146
enum fr_token fr_token_t
@ T_INVALID
Definition token.h:37
@ T_OP_CMP_TRUE
Definition token.h:102
@ T_OP_EQ
Definition token.h:81
@ T_OP_SET
Definition token.h:82
@ T_OP_NE
Definition token.h:95
@ T_OP_ADD_EQ
Definition token.h:67
@ T_OP_CMP_FALSE
Definition token.h:103
@ T_OP_REG_EQ
Definition token.h:100
@ T_OP_CMP_EQ
Definition token.h:104
@ T_OP_LE
Definition token.h:98
@ T_OP_GE
Definition token.h:96
@ T_OP_GT
Definition token.h:97
@ T_OP_LT
Definition token.h:99
@ T_OP_REG_NE
Definition token.h:101
@ T_OP_PREPEND
Definition token.h:83
#define PAIR_ALLOCED(_x)
Definition pair.h:213
bool fr_pair_list_empty(fr_pair_list_t const *list)
Is a valuepair list empty.
#define PAIR_VERIFY(_x)
Definition pair.h:205
fr_pair_t * fr_pair_list_next(fr_pair_list_t const *list, fr_pair_t const *item))
Get the next item in a valuepair list after a specific entry.
Definition pair_inline.c:69
fr_pair_t * fr_pair_list_tail(fr_pair_list_t const *list)
Get the tail of a valuepair list.
Definition pair_inline.c:55
fr_pair_t * fr_pair_remove(fr_pair_list_t *list, fr_pair_t *vp)
Remove fr_pair_t from a list without freeing.
Definition pair_inline.c:93
void fr_pair_list_free(fr_pair_list_t *list)
Free memory used by a valuepair list.
void fr_pair_list_append(fr_pair_list_t *dst, fr_pair_list_t *src)
Appends a list of fr_pair_t from a temporary list to a destination list.
void fr_pair_list_prepend(fr_pair_list_t *dst, fr_pair_list_t *src)
Move a list of fr_pair_t from a temporary list to the head of a destination list.
fr_pair_t * fr_pair_list_prev(fr_pair_list_t const *list, fr_pair_t const *item))
Get the previous item in a valuepair list before a specific entry.
Definition pair_inline.c:82
fr_pair_t * fr_pair_list_head(fr_pair_list_t const *list)
Get the head of a valuepair list.
Definition pair_inline.c:42
static fr_slen_t parent
Definition pair.h:860
#define fr_strerror_printf(_fmt,...)
Log to thread local error buffer.
Definition strerror.h:64
#define fr_strerror_const(_msg)
Definition strerror.h:223
fr_table_num_ordered_t const fr_type_table[]
Map data types to names representing those types.
Definition types.c:31
#define FR_TYPE_STRUCTURAL_EXCEPT_GROUP
Definition types.h:315
#define fr_type_is_structural(_x)
Definition types.h:392
#define fr_type_is_leaf(_x)
Definition types.h:393
static char const * fr_type_to_str(fr_type_t type)
Return a static string containing the type name.
Definition types.h:454
#define FR_TYPE_LEAF
Definition types.h:317
fr_sbuff_parse_rules_t const value_parse_rules_single_quoted
Definition value.c:558
fr_slen_t fr_value_box_from_substr(TALLOC_CTX *ctx, fr_value_box_t *dst, fr_type_t dst_type, fr_dict_attr_t const *dst_enumv, fr_sbuff_t *in, fr_sbuff_parse_rules_t const *rules)
Convert string value to a fr_value_box_t type.
Definition value.c:5469
fr_sbuff_unescape_rules_t const fr_value_unescape_backtick
Definition value.c:322
fr_sbuff_parse_rules_t const value_parse_rules_double_quoted
Definition value.c:552
#define fr_box_strvalue_len(_val, _len)
Definition value.h:334
static fr_sbuff_err_t char ** out
Definition value.h:1062
static fr_sbuff_err_t char size_t * len
Definition value.h:1062