From c758889acd68835c0ab6b28b780212cda9e6a689 Mon Sep 17 00:00:00 2001 From: Antonio Torres Date: Fri, 25 Jun 2021 14:01:47 +0200 Subject: [PATCH 1/5] Fix python3 not being correctly linked Since Python 3.8, there is a new way to link against libpython. https://docs.python.org/3/whatsnew/3.8.html#debug-build-uses-the-same-abi-as-release-build Fixes: https://bugzilla.redhat.com/show_bug.cgi?id=1917157 Signed-off-by: Antonio Torres --- freeradius.spec | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/freeradius.spec b/freeradius.spec index fc9091e..09f5d81 100644 --- a/freeradius.spec +++ b/freeradius.spec @@ -214,9 +214,8 @@ This plugin provides the REST support for the FreeRADIUS server project. # Hack: rlm_python3 as stable; prevents building other unstable modules. sed 's/rlm_python/rlm_python3/g' src/modules/stable -i -# python3-config is broken: -# https://bugzilla.redhat.com/show_bug.cgi?id=1772988 -export PY3_LIB_DIR=%{_libdir}/"$(python3-config --configdir | sed 's#/usr/lib/##g')" +%global build_ldflags %{build_ldflags} $(python3-config --embed --libs) +export PY3_LIB_DIR="$(python3-config --configdir)" export PY3_INC_DIR="$(python3 -c 'import sysconfig; print(sysconfig.get_config_var("INCLUDEPY"))')" # In order for the above hack to stick, do a fake configure so @@ -838,6 +837,10 @@ exit 0 %attr(640,root,radiusd) %config(noreplace) /etc/raddb/mods-available/rest %changelog +* Fri Jun 25 2021 Antonio Torres - 3.0.21-8 +- Fix python3 not being correctly linked + Resolves: bz#1917157 + * Tue Aug 04 2020 Alexander Scheel - 3.0.21-7 - Fix certificate permissions after make-based generation Resolves: bz#1835249 From 8e1dc0835ed06983107f71de44bc0d39d2ebb502 Mon Sep 17 00:00:00 2001 From: Antonio Torres Date: Fri, 25 Jun 2021 14:14:47 +0200 Subject: [PATCH 2/5] Bump release number Signed-off-by: Antonio Torres --- freeradius.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/freeradius.spec b/freeradius.spec index 09f5d81..7cf5cb7 100644 --- a/freeradius.spec +++ b/freeradius.spec @@ -1,7 +1,7 @@ Summary: High-performance and highly configurable free RADIUS server Name: freeradius Version: 3.0.21 -Release: 7%{?dist} +Release: 8%{?dist} License: GPLv2+ and LGPLv2+ URL: http://www.freeradius.org/ From 53d11ad67fd1158010a45d8fbcf44c771fb35fd1 Mon Sep 17 00:00:00 2001 From: Antonio Torres Date: Thu, 15 Jul 2021 12:17:21 +0200 Subject: [PATCH 3/5] Fix coredump not being able to be enabled If resource hard limit is set to zero, then it cannot be raised again, and this causes coredump to not being able to be enabled. Signed-off-by: Antonio Torres --- ...radius-Fix-resource-hard-limit-error.patch | 32 +++++++++++++++++++ freeradius.spec | 7 +++- 2 files changed, 38 insertions(+), 1 deletion(-) create mode 100644 freeradius-Fix-resource-hard-limit-error.patch diff --git a/freeradius-Fix-resource-hard-limit-error.patch b/freeradius-Fix-resource-hard-limit-error.patch new file mode 100644 index 0000000..800c06c --- /dev/null +++ b/freeradius-Fix-resource-hard-limit-error.patch @@ -0,0 +1,32 @@ +commit 1ce4508c92493cf03ea1b3c42e83540b387884fa +Author: Antonio Torres +Date: Fri Jul 2 07:12:48 2021 -0400 +Subject: [PATCH] debug: don't set resource hard limit to zero + + Setting the resource hard limit to zero is irreversible, meaning if it + is set to zero then there is no way to set it higher. This means + enabling core dump is not possible, since setting a new resource limit + for RLIMIT_CORE would fail. By only setting the soft limit to zero, we + can disable and enable core dumps without failures. + + This fix is present in both main and 3.0.x upstream branches. + + Ticket in RHEL Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1977572 + Signed-off-by: Antonio Torres antorres@redhat.com +--- + src/lib/debug.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/src/lib/debug.c b/src/lib/debug.c +index 576bcb2a65..6330c9cb66 100644 +--- a/src/lib/debug.c ++++ b/src/lib/debug.c +@@ -599,7 +599,7 @@ int fr_set_dumpable(bool allow_core_dumps) + struct rlimit no_core; + + no_core.rlim_cur = 0; +- no_core.rlim_max = 0; ++ no_core.rlim_max = core_limits.rlim_max; + + if (setrlimit(RLIMIT_CORE, &no_core) < 0) { + fr_strerror_printf("Failed disabling core dumps: %s", fr_syserror(errno)); diff --git a/freeradius.spec b/freeradius.spec index 7cf5cb7..465565f 100644 --- a/freeradius.spec +++ b/freeradius.spec @@ -1,7 +1,7 @@ Summary: High-performance and highly configurable free RADIUS server Name: freeradius Version: 3.0.21 -Release: 8%{?dist} +Release: 9%{?dist} License: GPLv2+ and LGPLv2+ URL: http://www.freeradius.org/ @@ -25,6 +25,7 @@ Patch2: freeradius-Use-system-crypto-policy-by-default.patch Patch3: freeradius-bootstrap-create-only.patch Patch4: freeradius-no-buildtime-cert-gen.patch Patch5: freeradius-bootstrap-make-permissions.patch +Patch6: freeradius-Fix-resource-hard-limit-error.patch %global docdir %{?_pkgdocdir}%{!?_pkgdocdir:%{_docdir}/%{name}-%{version}} @@ -206,6 +207,7 @@ This plugin provides the REST support for the FreeRADIUS server project. %patch3 -p1 %patch4 -p1 %patch5 -p1 +%patch6 -p1 %build # Force compile/link options, extra security for network facing daemon @@ -837,6 +839,9 @@ exit 0 %attr(640,root,radiusd) %config(noreplace) /etc/raddb/mods-available/rest %changelog +* Fri Jul 15 2021 Antonio Torres - 3.0.21-9 +- Fix coredump not being able to be enabled + * Fri Jun 25 2021 Antonio Torres - 3.0.21-8 - Fix python3 not being correctly linked Resolves: bz#1917157 From 0ace11cd0fe800992821ad3d740be2b2afd13d28 Mon Sep 17 00:00:00 2001 From: Antonio Torres Date: Tue, 19 Oct 2021 18:29:01 +0200 Subject: [PATCH 4/5] ldap: allow to connect on partially open handle The LDAP library returns a partially open connection. Setting the 'retry' flag to true during the module inst creation and the pool start to 0 allows to connect even if the connection is not completely opened yet. Upstream commit: https://github.com/FreeRADIUS/freeradius-server/commit/21d95b268b4cf56e75064898d83123825d673818 Resolves: #1983063 Signed-off-by: Antonio Torres --- ...-to-connect-on-partially-open-handle.patch | 49 +++++++++++++++++++ freeradius.spec | 8 ++- 2 files changed, 56 insertions(+), 1 deletion(-) create mode 100644 freeradius-ldap-allow-to-connect-on-partially-open-handle.patch diff --git a/freeradius-ldap-allow-to-connect-on-partially-open-handle.patch b/freeradius-ldap-allow-to-connect-on-partially-open-handle.patch new file mode 100644 index 0000000..41755ee --- /dev/null +++ b/freeradius-ldap-allow-to-connect-on-partially-open-handle.patch @@ -0,0 +1,49 @@ +From ab6bbcc41293ae745c1607618f88e5404b98d769 Mon Sep 17 00:00:00 2001 +From: Antonio Torres +Date: Wed, 13 Oct 2021 13:29:02 +0200 +Subject: [PATCH] ldap: allow to connect on partially open handle + +The LDAP library returns a partially open connection. Setting the +'retry' flag to true during the module inst creation and the pool start +to 0 allows to connect even if the connection is not completely opened +yet. + +Upstream commit: https://github.com/FreeRADIUS/freeradius-server/commit/21d95b268b4cf56e75064898d83123825d673818 + +Signed-off-by: Antonio Torres +--- +diff --git a/src/modules/rlm_ldap/ldap.c b/src/modules/rlm_ldap/ldap.c +index f25ee9e2e0..4b6ae44afb 100644 +--- a/src/modules/rlm_ldap/ldap.c ++++ b/src/modules/rlm_ldap/ldap.c +@@ -717,7 +717,8 @@ ldap_rcode_t rlm_ldap_bind(rlm_ldap_t const *inst, REQUEST *request, ldap_handle + * For sanity, for when no connections are viable, + * and we can't make a new one. + */ +- num = retry ? fr_connection_pool_get_num(inst->pool) : 0; ++ num = 0; ++ if (inst->pool && retry) num = fr_connection_pool_get_num(inst->pool); + for (i = num; i >= 0; i--) { + #ifdef WITH_SASL + if (sasl && sasl->mech) { +@@ -758,7 +759,7 @@ ldap_rcode_t rlm_ldap_bind(rlm_ldap_t const *inst, REQUEST *request, ldap_handle + break; + + case LDAP_PROC_RETRY: +- if (retry) { ++ if (num) { + *pconn = fr_connection_reconnect(inst->pool, *pconn); + if (*pconn) { + LDAP_DBGW_REQ("Bind with %s to %s failed: %s. Got new socket, retrying...", +@@ -1563,7 +1564,7 @@ void *mod_conn_create(TALLOC_CTX *ctx, void *instance) + } + + status = rlm_ldap_bind(inst, NULL, &conn, conn->inst->admin_identity, conn->inst->admin_password, +- &(conn->inst->admin_sasl), false); ++ &(conn->inst->admin_sasl), true); + if (status != LDAP_PROC_SUCCESS) { + goto error; + } +-- +2.31.1 + diff --git a/freeradius.spec b/freeradius.spec index 465565f..ccb2b56 100644 --- a/freeradius.spec +++ b/freeradius.spec @@ -1,7 +1,7 @@ Summary: High-performance and highly configurable free RADIUS server Name: freeradius Version: 3.0.21 -Release: 9%{?dist} +Release: 10%{?dist} License: GPLv2+ and LGPLv2+ URL: http://www.freeradius.org/ @@ -26,6 +26,7 @@ Patch3: freeradius-bootstrap-create-only.patch Patch4: freeradius-no-buildtime-cert-gen.patch Patch5: freeradius-bootstrap-make-permissions.patch Patch6: freeradius-Fix-resource-hard-limit-error.patch +Patch7: freeradius-ldap-allow-to-connect-on-partially-open-handle.patch %global docdir %{?_pkgdocdir}%{!?_pkgdocdir:%{_docdir}/%{name}-%{version}} @@ -208,6 +209,7 @@ This plugin provides the REST support for the FreeRADIUS server project. %patch4 -p1 %patch5 -p1 %patch6 -p1 +%patch7 -p1 %build # Force compile/link options, extra security for network facing daemon @@ -839,6 +841,10 @@ exit 0 %attr(640,root,radiusd) %config(noreplace) /etc/raddb/mods-available/rest %changelog +* Tue Oct 19 2021 Antonio Torres - 3.0.21-10 +- Allow to connect to partially open LDAP handle + Related: rhbz#1983063 + * Fri Jul 15 2021 Antonio Torres - 3.0.21-9 - Fix coredump not being able to be enabled From 3c05eddf642c1b8e92e4782c571154b8eb3fb49c Mon Sep 17 00:00:00 2001 From: Antonio Torres Date: Tue, 19 Oct 2021 18:35:14 +0200 Subject: [PATCH 5/5] Fix bogus date in spec file Signed-off-by: Antonio Torres --- freeradius.spec | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/freeradius.spec b/freeradius.spec index ccb2b56..2df2001 100644 --- a/freeradius.spec +++ b/freeradius.spec @@ -845,7 +845,7 @@ exit 0 - Allow to connect to partially open LDAP handle Related: rhbz#1983063 -* Fri Jul 15 2021 Antonio Torres - 3.0.21-9 +* Thu Jul 15 2021 Antonio Torres - 3.0.21-9 - Fix coredump not being able to be enabled * Fri Jun 25 2021 Antonio Torres - 3.0.21-8