The FreeRADIUS server $Id: f3670dba8951ca10eb4948feb3dc3db9423a334f $
Loading...
Searching...
No Matches
connection.h
Go to the documentation of this file.
1#pragma once
2/*
3 * This program is free software; you can redistribute it and/or modify
4 * it under the terms of the GNU General Public License as published by
5 * the Free Software Foundation; either version 2 of the License, or
6 * (at your option) any later version.
7 *
8 * This program is distributed in the hope that it will be useful,
9 * but WITHOUT ANY WARRANTY; without even the implied warranty of
10 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
11 * GNU General Public License for more details.
12 *
13 * You should have received a copy of the GNU General Public License
14 * along with this program; if not, write to the Free Software
15 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
16 */
17#ifdef WITH_TLS
18/**
19 * $Id: 95dc3409fdc8c55bf6026de1c325c08b551fc9f3 $
20 *
21 * @file lib/tls/connection.h
22 * @brief Run one TLS connection from the first policy section to the last.
23 *
24 * A TLS session is the handshake. A TLS connection is the handshake, the
25 * policy which runs before and after the handshake, and the cache operations
26 * the handshake queues. fr_tls_session_t holds the handshake.
27 * fr_tls_connection_t holds the connection, and drives fr_tls_session_t.
28 *
29 * @copyright 2026 The FreeRADIUS server project
30 */
31RCSIDH(tls_connection_h, "$Id: 95dc3409fdc8c55bf6026de1c325c08b551fc9f3 $")
32
33#include "openssl_user_macros.h"
34
35#include <freeradius-devel/unlang/action.h>
36
37#include "conf.h"
38#include "session.h"
39
40#ifdef __cplusplus
41extern "C" {
42#endif
43
44/** Which part of a connection is running
45 *
46 * A connection is more than a handshake. Policy runs before the handshake
47 * and after the handshake. fr_tls_connection_push() pushes one connection
48 * frame, and the policy sections and the handshake rounds all run under the
49 * connection frame. Each state arms the next state as the repeat function of
50 * the connection frame, so the repeat function records which part runs next.
51 *
52 * The `state` field of fr_tls_connection_t records the same part for
53 * fr_tls_connection_process(). fr_tls_connection_process() runs outside of
54 * the connection frame, and so cannot read a repeat function.
55 * fr_tls_connection_process() acts only while `state` is
56 * TLS_CONNECTION_HANDSHAKE, and sets `state` to TLS_CONNECTION_COMPLETE to
57 * record that the handshake has ended.
58 */
59typedef enum {
60 TLS_CONNECTION_NEW_SESSION = 0, //!< Run `new session { ... }`.
61 TLS_CONNECTION_HANDSHAKE, //!< Run handshake rounds until the handshake ends.
62 TLS_CONNECTION_COMPLETE //!< Run the cache operations the handshake queued.
63} fr_tls_connection_state_t;
64
65/** Everything the TLS connection state machine needs
66 *
67 * The state machine is the set of functions in src/lib/tls/connection.c.
68 * Every field the state machine reads or writes lives in fr_tls_connection_t,
69 * and the state machine reads no other structure, so the caller may keep
70 * fr_tls_connection_t in whatever structure the caller chooses.
71 *
72 * The state machine performs two actions which are outside of TLS state
73 * management:
74 *
75 * - telling the calling application that the TLS connection has finished,
76 * whether the connection succeeded or failed
77 * - writing the data OpenSSL produced out to the peer
78 *
79 * Both actions belong to the application which owns the connection, so the
80 * state machine calls the `finished` and `write` callbacks rather than
81 * performing either action itself.
82 */
83typedef struct fr_tls_connection_s fr_tls_connection_t;
84
85struct fr_tls_connection_s {
86 fr_tls_conf_t *tls_conf; //!< Parsed "tls" section.
87 fr_tls_session_t *tls_session; //!< State of the handshake.
88 request_t *request; //!< Request the handshake runs under.
89
90 fr_tls_connection_state_t state; //!< Which part of the connection is running.
91 bool client; //!< Act as the client and connect to a server,
92 ///< rather than accept a connection.
93 bool idle; //!< The connection frame has yielded, and waits
94 ///< for a record.
95 bool pending; //!< A record is waiting for OpenSSL.
96 bool failed; //!< A state or the handshake failed, so the cache
97 ///< denies the session.
98
99 void *uctx; //!< Context for the callback functions below.
100
101 void (*finished)(void *uctx, fr_tls_connection_t *conn);
102 //!< Stop running the connection. Read the
103 ///< result from `conn->failed`, and anything
104 ///< else needed from `conn->tls_conf` or
105 ///< `conn->tls_session`.
106 int (*write)(void *uctx, fr_tls_connection_t *conn);
107 //!< Write what OpenSSL produced out to the
108 ///< peer. Returns < 0 on failure.
109};
110
111int fr_tls_connection_push(fr_tls_connection_t *conn);
112
113void fr_tls_connection_wake(fr_tls_connection_t *conn);
114
115void fr_tls_connection_recv(fr_tls_connection_t *conn, uint8_t const *data, size_t data_len);
116
117void fr_tls_connection_process(fr_tls_connection_t *conn);
118
119#ifdef __cplusplus
120}
121#endif
122#endif /* WITH_TLS */
#define RCSIDH(h, id)
Definition build.h:561
unsigned char uint8_t
static fr_slen_t data
Definition value.h:1367