From 764aa4e8dc55f144bdb237566a0dd75ef0c07576 Mon Sep 17 00:00:00 2001 From: Thomas De Backer Date: Mon, 8 Feb 2021 20:48:20 +0100 Subject: [PATCH 01/41] Correct interface binding Signed-off-by: Thomas De Backer --- src/net.c | 21 +++++++++++++++++---- 1 file changed, 17 insertions(+), 4 deletions(-) diff --git a/src/net.c b/src/net.c index dcc9db36..67332870 100644 --- a/src/net.c +++ b/src/net.c @@ -640,7 +640,8 @@ static int net__bind_interface(struct mosquitto__listener *listener, struct addr } } freeifaddrs(ifaddr); - log__printf(NULL, MOSQ_LOG_ERR, "Error: Interface %s not found.", listener->bind_interface); + log__printf(NULL, MOSQ_LOG_WARNING, "Warning: Interface %s does not support %s.", + listener->bind_interface, rp->ai_addr->sa_family == AF_INET ? "ipv4" : "ipv6"); return MOSQ_ERR_NOT_FOUND; } #endif @@ -654,6 +655,9 @@ static int net__socket_listen_tcp(struct mosquitto__listener *listener) char service[10]; int rc; int ss_opt = 1; +#ifndef WIN32 + bool interface_bound = false; +#endif if(!listener) return MOSQ_ERR_INVAL; @@ -718,12 +722,14 @@ static int net__socket_listen_tcp(struct mosquitto__listener *listener) #ifndef WIN32 if(listener->bind_interface){ + /* It might be possible that an interface does not support all relevant sa_families. + * We should successfully find at least one. */ if(net__bind_interface(listener, rp)){ COMPAT_CLOSE(sock); - freeaddrinfo(ainfo); - mosquitto__free(listener->socks); - return 1; + listener->sock_count--; + continue; } + interface_bound = true; } #endif @@ -745,6 +751,13 @@ static int net__socket_listen_tcp(struct mosquitto__listener *listener) } freeaddrinfo(ainfo); +#ifndef WIN32 + if(listener->bind_interface && !interface_bound){ + mosquitto__free(listener->socks); + return 1; + } +#endif + return 0; } From fd2f764d361e038eae6140a3ee16dbf5c75c299f Mon Sep 17 00:00:00 2001 From: Thomas De Backer Date: Mon, 8 Feb 2021 23:36:21 +0100 Subject: [PATCH 02/41] Check host address binding before overwriting Signed-off-by: Thomas De Backer --- src/net.c | 36 +++++++++++++++++++++++++----------- 1 file changed, 25 insertions(+), 11 deletions(-) diff --git a/src/net.c b/src/net.c index 67332870..05b56d69 100644 --- a/src/net.c +++ b/src/net.c @@ -624,23 +624,37 @@ static int net__bind_interface(struct mosquitto__listener *listener, struct addr && ifa->ifa_addr->sa_family == rp->ai_addr->sa_family){ if(rp->ai_addr->sa_family == AF_INET){ - memcpy(&((struct sockaddr_in *)rp->ai_addr)->sin_addr, - &((struct sockaddr_in *)ifa->ifa_addr)->sin_addr, - sizeof(struct in_addr)); + if(listener->host && + memcmp(&((struct sockaddr_in *)rp->ai_addr)->sin_addr, + &((struct sockaddr_in *)ifa->ifa_addr)->sin_addr, + sizeof(struct in_addr))){ + log__printf(NULL, MOSQ_LOG_WARNING, "Warning: Interface address does not match specified listener host."); + }else{ + memcpy(&((struct sockaddr_in *)rp->ai_addr)->sin_addr, + &((struct sockaddr_in *)ifa->ifa_addr)->sin_addr, + sizeof(struct in_addr)); - freeifaddrs(ifaddr); - return MOSQ_ERR_SUCCESS; + freeifaddrs(ifaddr); + return MOSQ_ERR_SUCCESS; + } }else if(rp->ai_addr->sa_family == AF_INET6){ - memcpy(&((struct sockaddr_in6 *)rp->ai_addr)->sin6_addr, - &((struct sockaddr_in6 *)ifa->ifa_addr)->sin6_addr, - sizeof(struct in6_addr)); - freeifaddrs(ifaddr); - return MOSQ_ERR_SUCCESS; + if(listener->host && + memcmp(&((struct sockaddr_in6 *)rp->ai_addr)->sin6_addr, + &((struct sockaddr_in6 *)ifa->ifa_addr)->sin6_addr, + sizeof(struct in6_addr))){ + log__printf(NULL, MOSQ_LOG_WARNING, "Warning: Interface address does not match specified listener host."); + }else{ + memcpy(&((struct sockaddr_in6 *)rp->ai_addr)->sin6_addr, + &((struct sockaddr_in6 *)ifa->ifa_addr)->sin6_addr, + sizeof(struct in6_addr)); + freeifaddrs(ifaddr); + return MOSQ_ERR_SUCCESS; + } } } } freeifaddrs(ifaddr); - log__printf(NULL, MOSQ_LOG_WARNING, "Warning: Interface %s does not support %s.", + log__printf(NULL, MOSQ_LOG_WARNING, "Warning: Interface %s does not support %s configuration.", listener->bind_interface, rp->ai_addr->sa_family == AF_INET ? "ipv4" : "ipv6"); return MOSQ_ERR_NOT_FOUND; } From 6bea9f7b32f983ea02a592d33dca2d1da4e67655 Mon Sep 17 00:00:00 2001 From: Vidar Madsen Date: Thu, 18 Feb 2021 15:34:53 +0100 Subject: [PATCH 03/41] Handle stale stored messages with conflicting message IDs. Signed-off-by: Vidar Madsen --- src/database.c | 26 ++++++++++++++++++++++++++ src/handle_publish.c | 7 +++++++ 2 files changed, 33 insertions(+) diff --git a/src/database.c b/src/database.c index db18b9f1..414d7780 100644 --- a/src/database.c +++ b/src/database.c @@ -893,6 +893,32 @@ int db__message_reconnect_reset(struct mosquitto *context) } +int db__message_remove_incoming(struct mosquitto* context, uint16_t mid) +{ + struct mosquitto_client_msg* tail, * tmp; + bool deleted = false; + + if (!context) return MOSQ_ERR_INVAL; + + DL_FOREACH_SAFE(context->msgs_in.inflight, tail, tmp) { + if (tail->mid == mid) { + if (tail->store->qos != 2) { + return MOSQ_ERR_PROTOCOL; + } + db__message_remove(&context->msgs_in, tail); + deleted = true; + } + } + + if (deleted) { + return MOSQ_ERR_SUCCESS; + } + else { + return MOSQ_ERR_NOT_FOUND; + } +} + + int db__message_release_incoming(struct mosquitto *context, uint16_t mid) { struct mosquitto_client_msg *tail, *tmp; diff --git a/src/handle_publish.c b/src/handle_publish.c index 68359b69..55fb3c20 100644 --- a/src/handle_publish.c +++ b/src/handle_publish.c @@ -285,6 +285,13 @@ int handle__publish(struct mosquitto *context) if(msg->qos > 0){ db__message_store_find(context, msg->source_mid, &stored); } + + if (stored && (stored->qos != msg->qos || stored->payloadlen != msg->payloadlen || strcmp(stored->topic, msg->topic) || memcmp(stored->payload, msg->payload, msg->payloadlen))){ + log__printf(NULL, MOSQ_LOG_WARNING, "Reused message ID from %s detected. Clearing from storage.", context->id); + db__message_remove_incoming(context, stored->mid); + stored = NULL; + } + if(!stored){ if(msg->qos == 0 || db__ready_for_flight(&context->msgs_in, msg->qos) From ebfcc84cdaa03d444eeb11339f82edbc043806e6 Mon Sep 17 00:00:00 2001 From: Vidar Madsen Date: Fri, 19 Feb 2021 13:53:50 +0100 Subject: [PATCH 04/41] Add new function to header. Minor tweaks. Signed-off-by: Vidar Madsen --- src/database.c | 1 - src/handle_publish.c | 6 +++--- src/mosquitto_broker_internal.h | 1 + 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/src/database.c b/src/database.c index 414d7780..3016df34 100644 --- a/src/database.c +++ b/src/database.c @@ -918,7 +918,6 @@ int db__message_remove_incoming(struct mosquitto* context, uint16_t mid) } } - int db__message_release_incoming(struct mosquitto *context, uint16_t mid) { struct mosquitto_client_msg *tail, *tmp; diff --git a/src/handle_publish.c b/src/handle_publish.c index 55fb3c20..75bc8f23 100644 --- a/src/handle_publish.c +++ b/src/handle_publish.c @@ -286,9 +286,9 @@ int handle__publish(struct mosquitto *context) db__message_store_find(context, msg->source_mid, &stored); } - if (stored && (stored->qos != msg->qos || stored->payloadlen != msg->payloadlen || strcmp(stored->topic, msg->topic) || memcmp(stored->payload, msg->payload, msg->payloadlen))){ - log__printf(NULL, MOSQ_LOG_WARNING, "Reused message ID from %s detected. Clearing from storage.", context->id); - db__message_remove_incoming(context, stored->mid); + if (stored && msg->source_mid != 0 && (stored->qos != msg->qos || stored->payloadlen != msg->payloadlen || strcmp(stored->topic, msg->topic) || memcmp(stored->payload, msg->payload, msg->payloadlen) )){ + log__printf(NULL, MOSQ_LOG_WARNING, "Reused message ID %u from %s detected. Clearing from storage.", msg->source_mid, context->id); + db__message_remove_incoming(context, msg->source_mid); stored = NULL; } diff --git a/src/mosquitto_broker_internal.h b/src/mosquitto_broker_internal.h index 5b88710f..78b8d0af 100644 --- a/src/mosquitto_broker_internal.h +++ b/src/mosquitto_broker_internal.h @@ -639,6 +639,7 @@ int persist__restore(void); int db__message_count(int *count); int db__message_delete_outgoing(struct mosquitto *context, uint16_t mid, enum mosquitto_msg_state expect_state, int qos); int db__message_insert(struct mosquitto *context, uint16_t mid, enum mosquitto_msg_direction dir, uint8_t qos, bool retain, struct mosquitto_msg_store *stored, mosquitto_property *properties, bool update); +int db__message_remove_incoming(struct mosquitto* context, uint16_t mid); int db__message_release_incoming(struct mosquitto *context, uint16_t mid); int db__message_update_outgoing(struct mosquitto *context, uint16_t mid, enum mosquitto_msg_state state, int qos); void db__message_dequeue_first(struct mosquitto *context, struct mosquitto_msg_data *msg_data); From 2a38b7115b605bce3e9c9bcf7c376bfce345e80c Mon Sep 17 00:00:00 2001 From: Abilio Marques Date: Fri, 26 Feb 2021 01:00:48 +0100 Subject: [PATCH 05/41] brige: fix backoff not working for remote broker returned errors Signed-off-by: Abilio Marques --- src/bridge.c | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/src/bridge.c b/src/bridge.c index d10d1269..8487dbb8 100644 --- a/src/bridge.c +++ b/src/bridge.c @@ -313,10 +313,8 @@ int bridge__connect_step3(struct mosquitto *context) rc = send__connect(context, context->keepalive, context->clean_start, NULL); if(rc == MOSQ_ERR_SUCCESS){ - bridge__backoff_reset(context); return MOSQ_ERR_SUCCESS; }else if(rc == MOSQ_ERR_ERRNO && errno == ENOTCONN){ - bridge__backoff_reset(context); return MOSQ_ERR_SUCCESS; }else{ if(rc == MOSQ_ERR_TLS){ @@ -454,10 +452,8 @@ int bridge__connect(struct mosquitto *context) rc2 = send__connect(context, context->keepalive, context->clean_start, NULL); if(rc2 == MOSQ_ERR_SUCCESS){ - bridge__backoff_reset(context); return rc; }else if(rc2 == MOSQ_ERR_ERRNO && errno == ENOTCONN){ - bridge__backoff_reset(context); return MOSQ_ERR_SUCCESS; }else{ if(rc2 == MOSQ_ERR_TLS){ @@ -562,6 +558,8 @@ int bridge__on_connect(struct mosquitto *context) } } + bridge__backoff_reset(context); + return MOSQ_ERR_SUCCESS; } From ace2aa764e19eb1fcb24fa796cebad365f09df11 Mon Sep 17 00:00:00 2001 From: Roger Light Date: Mon, 8 Mar 2021 23:57:04 +0000 Subject: [PATCH 06/41] Fix cmake epoll detection. --- ChangeLog.txt | 3 +++ src/CMakeLists.txt | 5 +++++ 2 files changed, 8 insertions(+) diff --git a/ChangeLog.txt b/ChangeLog.txt index ee2fd96b..47bda056 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -8,6 +8,9 @@ Broker: - Fix QoS 0 messages not being delivered when max_queued_bytes was configured. Closes #2123. +Build: +- Fix cmake epoll detection. + 2.0.8 - 2021-02-25 ================== diff --git a/src/CMakeLists.txt b/src/CMakeLists.txt index f283c8d0..7be39889 100644 --- a/src/CMakeLists.txt +++ b/src/CMakeLists.txt @@ -77,6 +77,11 @@ if (WITH_BUNDLED_DEPS) include_directories(${mosquitto_SOURCE_DIR} ${mosquitto_SOURCE_DIR}/deps) endif (WITH_BUNDLED_DEPS) +find_path(HAVE_SYS_EPOLL_H sys/epoll.h) +if (HAVE_SYS_EPOLL_H) + add_definitions("-DWITH_EPOLL") +endif() + option(INC_BRIDGE_SUPPORT "Include bridge support for connecting to other brokers?" ON) if (INC_BRIDGE_SUPPORT) From b7a08d5c406829a3da89bb105f18332755498ee9 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Thu, 11 Mar 2021 12:45:04 +0000 Subject: [PATCH 07/41] Fix TLS bridge/lib incorrectly connecting on invalid CA file. Closes #2130. Thanks to becz. --- ChangeLog.txt | 18 +++++++++++++++++- lib/mosquitto.c | 1 + src/bridge.c | 1 + 3 files changed, 19 insertions(+), 1 deletion(-) diff --git a/ChangeLog.txt b/ChangeLog.txt index 47bda056..ca5eccf4 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,13 +1,29 @@ -2.0.9 - 2021-03-xx +2.0.9 - 2021-03-11 ================== +Security: +- If an empty or invalid CA file was provided to the client library for + verifying the remote broker, then the initial connection would fail but + subsequent connections would succeed without verifying the remote broker + certificate. Closes #2130. +- If an empty or invalid CA file was provided to the broker for verifying the + remote broker for an outgoing bridge connection then the initial connection + would fail but subsequent connections would succeed without verifying the + remote broker certificate. Closes #2130. + Broker: +- Fix encrypted bridge connections incorrectly connecting when `bridge_cafile` + is empty or invalid. Closes #2130. - Fix `tls_version` behaviour not matching documentation. It was setting the exact TLS version to use, not the minimium TLS version to use. Closes #2110. - Fix messages to `$` prefixed topics being rejected. Closes #2111. - Fix QoS 0 messages not being delivered when max_queued_bytes was configured. Closes #2123. +Client library: +- Fix encrypted connections incorrectly connecting when the CA file passed to + `mosquitto_tls_set()` is empty or invalid. Closes #2130. + Build: - Fix cmake epoll detection. diff --git a/lib/mosquitto.c b/lib/mosquitto.c index 0dd4ac01..0d53f2e5 100644 --- a/lib/mosquitto.c +++ b/lib/mosquitto.c @@ -196,6 +196,7 @@ int mosquitto_reinitialise(struct mosquitto *mosq, const char *id, bool clean_st #ifdef WITH_TLS mosq->ssl = NULL; mosq->ssl_ctx = NULL; + mosq->ssl_ctx_defaults = true; mosq->tls_cert_reqs = SSL_VERIFY_PEER; mosq->tls_insecure = false; mosq->want_write = false; diff --git a/src/bridge.c b/src/bridge.c index d10d1269..f5158dba 100644 --- a/src/bridge.c +++ b/src/bridge.c @@ -112,6 +112,7 @@ int bridge__new(struct mosquitto__bridge *bridge) new_context->tls_alpn = new_context->bridge->tls_alpn; new_context->tls_engine = db.config->default_listener.tls_engine; new_context->tls_keyform = db.config->default_listener.tls_keyform; + new_context->ssl_ctx_defaults = true; #ifdef FINAL_WITH_TLS_PSK new_context->tls_psk_identity = new_context->bridge->tls_psk_identity; new_context->tls_psk = new_context->bridge->tls_psk; From c11a2d5a8b582d5c3a319944f47d98d9230bcc63 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Thu, 11 Mar 2021 14:00:08 +0000 Subject: [PATCH 08/41] Fix mosquitto_rr doc default version. Closes #2032. --- man/mosquitto_rr.1.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/man/mosquitto_rr.1.xml b/man/mosquitto_rr.1.xml index 27309532..a62fbc72 100644 --- a/man/mosquitto_rr.1.xml +++ b/man/mosquitto_rr.1.xml @@ -632,7 +632,7 @@ , or the more verbose , , or . - Defaults to . + Defaults to . From 88d2c74ab2871eab8dfced0b34e686f2d5496a4e Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Thu, 11 Mar 2021 15:02:31 +0000 Subject: [PATCH 09/41] Fix bridge backoff calculation. --- ChangeLog.txt | 1 + src/bridge.c | 32 ++++++++++++++++++++++++++++++-- 2 files changed, 31 insertions(+), 2 deletions(-) diff --git a/ChangeLog.txt b/ChangeLog.txt index ca5eccf4..7aefb141 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -19,6 +19,7 @@ Broker: - Fix messages to `$` prefixed topics being rejected. Closes #2111. - Fix QoS 0 messages not being delivered when max_queued_bytes was configured. Closes #2123. +- Fix bridge increasing backoff calculation. Client library: - Fix encrypted connections incorrectly connecting when the CA file passed to diff --git a/src/bridge.c b/src/bridge.c index 54425a6e..f55315fb 100644 --- a/src/bridge.c +++ b/src/bridge.c @@ -645,11 +645,11 @@ void bridge__packet_cleanup(struct mosquitto *context) packet__cleanup(&(context->in_packet)); } -static int rand_between(int base, int cap) +static int rand_between(int low, int high) { int r; util__random_bytes(&r, sizeof(int)); - return (r % (cap - base)) + base; + return (abs(r) % (high - low)) + low; } static void bridge__backoff_step(struct mosquitto *context) @@ -684,6 +684,33 @@ static void bridge__backoff_reset(struct mosquitto *context) } } + +static void bridge_check_pending(struct mosquitto *context) +{ + int err; + socklen_t len; + + if(context->state == mosq_cs_connect_pending){ + len = sizeof(int); + if(!getsockopt(context->sock, SOL_SOCKET, SO_ERROR, (char *)&err, &len)){ + if(err == 0){ + mosquitto__set_state(context, mosq_cs_new); +#if defined(WITH_ADNS) && defined(WITH_BRIDGE) + if(context->bridge){ + bridge__connect_step3(context); + } +#endif + }else if(err == ECONNREFUSED){ + do_disconnect(context, MOSQ_ERR_CONN_LOST); + return; + } + }else{ + do_disconnect(context, MOSQ_ERR_CONN_LOST); + return; + } + } +} + void bridge_check(void) { static time_t last_check = 0; @@ -702,6 +729,7 @@ void bridge_check(void) if(context->sock != INVALID_SOCKET){ mosquitto__check_keepalive(context); + bridge_check_pending(context); /* Check for bridges that are not round robin and not currently * connected to their primary broker. */ From f4d088b6d0021fbf0ac4f9c88fdafc8f74850f03 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Thu, 11 Mar 2021 15:09:38 +0000 Subject: [PATCH 10/41] Improve logging of pull request. Improve handling of invalid combinations of listener address and bind interface configurations. Closes #2081. --- ChangeLog.txt | 2 ++ src/net.c | 12 +++++++++--- 2 files changed, 11 insertions(+), 3 deletions(-) diff --git a/ChangeLog.txt b/ChangeLog.txt index 7aefb141..54d5377a 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -20,6 +20,8 @@ Broker: - Fix QoS 0 messages not being delivered when max_queued_bytes was configured. Closes #2123. - Fix bridge increasing backoff calculation. +- Improve handling of invalid combinations of listener address and bind + interface configurations. Closes #2081. Client library: - Fix encrypted connections incorrectly connecting when the CA file passed to diff --git a/src/net.c b/src/net.c index c1e3d55f..bbdb2708 100644 --- a/src/net.c +++ b/src/net.c @@ -628,7 +628,10 @@ static int net__bind_interface(struct mosquitto__listener *listener, struct addr memcmp(&((struct sockaddr_in *)rp->ai_addr)->sin_addr, &((struct sockaddr_in *)ifa->ifa_addr)->sin_addr, sizeof(struct in_addr))){ - log__printf(NULL, MOSQ_LOG_WARNING, "Warning: Interface address does not match specified listener host."); + + log__printf(NULL, MOSQ_LOG_WARNING, "Warning: Interface address for %s does not match specified listener address (%s).", + listener->bind_interface, listener->host); + return MOSQ_ERR_INVAL; }else{ memcpy(&((struct sockaddr_in *)rp->ai_addr)->sin_addr, &((struct sockaddr_in *)ifa->ifa_addr)->sin_addr, @@ -642,7 +645,10 @@ static int net__bind_interface(struct mosquitto__listener *listener, struct addr memcmp(&((struct sockaddr_in6 *)rp->ai_addr)->sin6_addr, &((struct sockaddr_in6 *)ifa->ifa_addr)->sin6_addr, sizeof(struct in6_addr))){ - log__printf(NULL, MOSQ_LOG_WARNING, "Warning: Interface address does not match specified listener host."); + + log__printf(NULL, MOSQ_LOG_WARNING, "Warning: Interface address for %s does not match specified listener address (%s).", + listener->bind_interface, listener->host); + return MOSQ_ERR_INVAL; }else{ memcpy(&((struct sockaddr_in6 *)rp->ai_addr)->sin6_addr, &((struct sockaddr_in6 *)ifa->ifa_addr)->sin6_addr, @@ -655,7 +661,7 @@ static int net__bind_interface(struct mosquitto__listener *listener, struct addr } freeifaddrs(ifaddr); log__printf(NULL, MOSQ_LOG_WARNING, "Warning: Interface %s does not support %s configuration.", - listener->bind_interface, rp->ai_addr->sa_family == AF_INET ? "ipv4" : "ipv6"); + listener->bind_interface, rp->ai_addr->sa_family == AF_INET ? "IPv4" : "IPv6"); return MOSQ_ERR_NOT_FOUND; } #endif From 720ce01faf9e40984067580e33a64e0615b651b0 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Thu, 11 Mar 2021 15:21:49 +0000 Subject: [PATCH 11/41] Minor tweaks to PR. --- src/database.c | 21 ++++++++------------- src/handle_publish.c | 7 ++++++- 2 files changed, 14 insertions(+), 14 deletions(-) diff --git a/src/database.c b/src/database.c index 0faf998e..2ba131c5 100644 --- a/src/database.c +++ b/src/database.c @@ -895,29 +895,24 @@ int db__message_reconnect_reset(struct mosquitto *context) int db__message_remove_incoming(struct mosquitto* context, uint16_t mid) { - struct mosquitto_client_msg* tail, * tmp; - bool deleted = false; + struct mosquitto_client_msg *tail, *tmp; - if (!context) return MOSQ_ERR_INVAL; + if(!context) return MOSQ_ERR_INVAL; - DL_FOREACH_SAFE(context->msgs_in.inflight, tail, tmp) { - if (tail->mid == mid) { - if (tail->store->qos != 2) { + DL_FOREACH_SAFE(context->msgs_in.inflight, tail, tmp){ + if(tail->mid == mid) { + if(tail->store->qos != 2){ return MOSQ_ERR_PROTOCOL; } db__message_remove(&context->msgs_in, tail); - deleted = true; + return MOSQ_ERR_SUCCESS; } } - if (deleted) { - return MOSQ_ERR_SUCCESS; - } - else { - return MOSQ_ERR_NOT_FOUND; - } + return MOSQ_ERR_NOT_FOUND; } + int db__message_release_incoming(struct mosquitto *context, uint16_t mid) { struct mosquitto_client_msg *tail, *tmp; diff --git a/src/handle_publish.c b/src/handle_publish.c index 75bc8f23..4686d350 100644 --- a/src/handle_publish.c +++ b/src/handle_publish.c @@ -286,7 +286,12 @@ int handle__publish(struct mosquitto *context) db__message_store_find(context, msg->source_mid, &stored); } - if (stored && msg->source_mid != 0 && (stored->qos != msg->qos || stored->payloadlen != msg->payloadlen || strcmp(stored->topic, msg->topic) || memcmp(stored->payload, msg->payload, msg->payloadlen) )){ + if(stored && msg->source_mid != 0 && + (stored->qos != msg->qos + || stored->payloadlen != msg->payloadlen + || strcmp(stored->topic, msg->topic) + || memcmp(stored->payload, msg->payload, msg->payloadlen) )){ + log__printf(NULL, MOSQ_LOG_WARNING, "Reused message ID %u from %s detected. Clearing from storage.", msg->source_mid, context->id); db__message_remove_incoming(context, msg->source_mid); stored = NULL; From 891be8c2fe0b68dda327b2ebc09342f72ad8018d Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Thu, 11 Mar 2021 19:57:51 +0000 Subject: [PATCH 12/41] Fix `max_keepalive` option not applying to keepalive=0. Closes #2117. Thanks to David Nadlinger. --- ChangeLog.txt | 2 ++ src/handle_connect.c | 4 +++- 2 files changed, 5 insertions(+), 1 deletion(-) diff --git a/ChangeLog.txt b/ChangeLog.txt index 54d5377a..3d86cc58 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -22,6 +22,8 @@ Broker: - Fix bridge increasing backoff calculation. - Improve handling of invalid combinations of listener address and bind interface configurations. Closes #2081. +- Fix `max_keepalive` option not applying to clients connecting with keepalive + set to 0. Closes #2117. Client library: - Fix encrypted connections incorrectly connecting when the CA file passed to diff --git a/src/handle_connect.c b/src/handle_connect.c index 6dfd9e3a..c3355d90 100644 --- a/src/handle_connect.c +++ b/src/handle_connect.c @@ -244,7 +244,9 @@ int connect__on_authorised(struct mosquitto *context, void *auth_data_out, uint1 goto error; } } - if(context->keepalive > db.config->max_keepalive){ + if(db.config->max_keepalive && + (context->keepalive > db.config->max_keepalive || context->keepalive == 0)){ + context->keepalive = db.config->max_keepalive; if(mosquitto_property_add_int16(&connack_props, MQTT_PROP_SERVER_KEEP_ALIVE, context->keepalive)){ rc = MOSQ_ERR_NOMEM; From f8838243fbb9689ce4195a6fbbb499ba477d1c65 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Thu, 11 Mar 2021 21:04:16 +0000 Subject: [PATCH 13/41] Fix connections retrying very rapidly in some situations. Thanks to Abilio Marques. --- ChangeLog.txt | 1 + lib/loop.c | 7 +++++++ 2 files changed, 8 insertions(+) diff --git a/ChangeLog.txt b/ChangeLog.txt index 3d86cc58..063e29a1 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -28,6 +28,7 @@ Broker: Client library: - Fix encrypted connections incorrectly connecting when the CA file passed to `mosquitto_tls_set()` is empty or invalid. Closes #2130. +- Fix connections retrying very rapidly in some situations. Build: - Fix cmake epoll detection. diff --git a/lib/loop.c b/lib/loop.c index bc2ba7f4..046dde0b 100644 --- a/lib/loop.c +++ b/lib/loop.c @@ -203,6 +203,13 @@ static int interruptible_sleep(struct mosquitto *mosq, time_t reconnect_delay) char pairbuf; int maxfd = 0; +#ifndef WIN32 + if(read(mosq->sockpairR, &pairbuf, 1) == 0){ + } +#else + recv(mosq->sockpairR, &pairbuf, 1, 0); +#endif + local_timeout.tv_sec = reconnect_delay; #ifdef HAVE_PSELECT local_timeout.tv_nsec = 0; From bb73eed557af2122f46b62e791ef5e4289a144dc Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Thu, 11 Mar 2021 22:33:01 +0000 Subject: [PATCH 14/41] Bump version number and update web pages. --- CMakeLists.txt | 2 +- config.mk | 2 +- include/mosquitto.h | 2 +- installer/mosquitto.nsi | 2 +- installer/mosquitto64.nsi | 2 +- set-version.sh | 2 +- snap/snapcraft.yaml | 2 +- www/pages/download.md | 8 +- www/posts/2021/03/version-2-0-9-released.md | 101 ++++++++++++++++++++ 9 files changed, 112 insertions(+), 11 deletions(-) create mode 100644 www/posts/2021/03/version-2-0-9-released.md diff --git a/CMakeLists.txt b/CMakeLists.txt index 489105df..4963d4ca 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -8,7 +8,7 @@ cmake_minimum_required(VERSION 3.0) cmake_policy(SET CMP0042 NEW) project(mosquitto) -set (VERSION 2.0.8) +set (VERSION 2.0.9) list(APPEND CMAKE_MODULE_PATH "${CMAKE_SOURCE_DIR}/cmake/") diff --git a/config.mk b/config.mk index 73e5cc39..d31b1160 100644 --- a/config.mk +++ b/config.mk @@ -127,7 +127,7 @@ WITH_XTREPORT=no # Also bump lib/mosquitto.h, CMakeLists.txt, # installer/mosquitto.nsi, installer/mosquitto64.nsi -VERSION=2.0.8 +VERSION=2.0.9 # Client library SO version. Bump if incompatible API/ABI changes are made. SOVERSION=1 diff --git a/include/mosquitto.h b/include/mosquitto.h index 587888a6..9aafcb32 100644 --- a/include/mosquitto.h +++ b/include/mosquitto.h @@ -66,7 +66,7 @@ extern "C" { #define LIBMOSQUITTO_MAJOR 2 #define LIBMOSQUITTO_MINOR 0 -#define LIBMOSQUITTO_REVISION 8 +#define LIBMOSQUITTO_REVISION 9 /* LIBMOSQUITTO_VERSION_NUMBER looks like 1002001 for e.g. version 1.2.1. */ #define LIBMOSQUITTO_VERSION_NUMBER (LIBMOSQUITTO_MAJOR*1000000+LIBMOSQUITTO_MINOR*1000+LIBMOSQUITTO_REVISION) diff --git a/installer/mosquitto.nsi b/installer/mosquitto.nsi index e34c7847..20487814 100644 --- a/installer/mosquitto.nsi +++ b/installer/mosquitto.nsi @@ -9,7 +9,7 @@ !define env_hklm 'HKLM "SYSTEM\CurrentControlSet\Control\Session Manager\Environment"' Name "Eclipse Mosquitto" -!define VERSION 2.0.8 +!define VERSION 2.0.9 OutFile "mosquitto-${VERSION}-install-windows-x86.exe" InstallDir "$PROGRAMFILES\mosquitto" diff --git a/installer/mosquitto64.nsi b/installer/mosquitto64.nsi index 4bd80f54..5ca2ca38 100644 --- a/installer/mosquitto64.nsi +++ b/installer/mosquitto64.nsi @@ -9,7 +9,7 @@ !define env_hklm 'HKLM "SYSTEM\CurrentControlSet\Control\Session Manager\Environment"' Name "Eclipse Mosquitto" -!define VERSION 2.0.8 +!define VERSION 2.0.9 OutFile "mosquitto-${VERSION}-install-windows-x64.exe" !include "x64.nsh" diff --git a/set-version.sh b/set-version.sh index a96b6a77..ba9b855a 100755 --- a/set-version.sh +++ b/set-version.sh @@ -2,7 +2,7 @@ MAJOR=2 MINOR=0 -REVISION=8 +REVISION=9 sed -i "s/^VERSION=.*/VERSION=${MAJOR}.${MINOR}.${REVISION}/" config.mk diff --git a/snap/snapcraft.yaml b/snap/snapcraft.yaml index 0099409a..5e8289ba 100644 --- a/snap/snapcraft.yaml +++ b/snap/snapcraft.yaml @@ -1,5 +1,5 @@ name: mosquitto -version: 2.0.8 +version: 2.0.9 summary: Eclipse Mosquitto MQTT broker description: This is a message broker that supports version 5.0, 3.1.1, and 3.1 of the MQTT protocol. diff --git a/www/pages/download.md b/www/pages/download.md index 0d16e248..c181fdca 100644 --- a/www/pages/download.md +++ b/www/pages/download.md @@ -1,7 +1,7 @@ + +Versions 2.0.9, 1.6.14, and 1.5.11 of Mosquitto have been released. These are +bugfix releases and include a minor security fix. + +# 2.0.9 + +## Security +- If an empty or invalid CA file was provided to the client library for + verifying the remote broker, then the initial connection would fail but + subsequent connections would succeed without verifying the remote broker + certificate. Closes [#2130]. +- If an empty or invalid CA file was provided to the broker for verifying the + remote broker for an outgoing bridge connection then the initial connection + would fail but subsequent connections would succeed without verifying the + remote broker certificate. Closes [#2130]. + +## Broker +- Fix encrypted bridge connections incorrectly connecting when `bridge_cafile` + is empty or invalid. Closes [#2130]. +- Fix `tls_version` behaviour not matching documentation. It was setting the + exact TLS version to use, not the minimium TLS version to use. Closes [#2110]. +- Fix messages to `$` prefixed topics being rejected. Closes [#2111]. +- Fix QoS 0 messages not being delivered when max_queued_bytes was configured. + Closes [#2123]. +- Fix bridge increasing backoff calculation. +- Improve handling of invalid combinations of listener address and bind + interface configurations. Closes [#2081]. +- Fix `max_keepalive` option not applying to clients connecting with keepalive + set to 0. Closes [#2117]. + +## Client library +- Fix encrypted connections incorrectly connecting when the CA file passed to + `mosquitto_tls_set()` is empty or invalid. Closes [#2130]. +- Fix connections retrying very rapidly in some situations. + +## Build +- Fix cmake epoll detection. + +# 1.6.14 + +## Security +- If an empty or invalid CA file was provided to the client library for + verifying the remote broker, then the initial connection would fail but + subsequent connections would succeed without verifying the remote broker + certificate. Closes [#2130]. +- If an empty or invalid CA file was provided to the broker for verifying the + remote broker for an outgoing bridge connection then the initial connection + would fail but subsequent connections would succeed without verifying the + remote broker certificate. Closes [#2130]. + +## Broker +- Fix encrypted bridge connections incorrectly connecting when `bridge_cafile` + is empty or invalid. Closes [#2130]. + +## Client library +- Fix encrypted connections incorrectly connecting when the CA file passed to + `mosquitto_tls_set()` is empty or invalid. Closes [#2130]. +- Fix connections retrying very rapidly in some situations. + +## Clients +- Fix possible loss of data in `mosquitto_pub -l` when sending multiple long + lines. Closes [#2078]. + +# 1.5.11 + +## Security +- If an empty or invalid CA file was provided to the client library for + verifying the remote broker, then the initial connection would fail but + subsequent connections would succeed without verifying the remote broker + certificate. Closes [#2130]. +- If an empty or invalid CA file was provided to the broker for verifying the + remote broker for an outgoing bridge connection then the initial connection + would fail but subsequent connections would succeed without verifying the + remote broker certificate. Closes [#2130]. + +## Broker +- Fix encrypted bridge connections incorrectly connecting when `bridge_cafile` + is empty or invalid. Closes [#2130]. + +## Client library +- Fix encrypted connections incorrectly connecting when the CA file passed to + `mosquitto_tls_set()` is empty or invalid. Closes [#2130]. + +[#2040]: https://github.com/eclipse/mosquitto/issues/2040 +[#2078]: https://github.com/eclipse/mosquitto/issues/2078 +[#2081]: https://github.com/eclipse/mosquitto/issues/2081 +[#2110]: https://github.com/eclipse/mosquitto/issues/2110 +[#2111]: https://github.com/eclipse/mosquitto/issues/2111 +[#2117]: https://github.com/eclipse/mosquitto/issues/2117 +[#2123]: https://github.com/eclipse/mosquitto/issues/2123 +[#2130]: https://github.com/eclipse/mosquitto/issues/2130 From 9f21a43eeeafdbb998409d075b986df23c18e649 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Thu, 11 Mar 2021 22:45:42 +0000 Subject: [PATCH 15/41] Update docker. --- docker/1.5-openssl/Dockerfile | 4 ++-- docker/1.5/Dockerfile | 4 ++-- docker/1.6-openssl/Dockerfile | 4 ++-- docker/1.6/Dockerfile | 4 ++-- docker/2.0-openssl/Dockerfile | 4 ++-- docker/2.0/Dockerfile | 4 ++-- 6 files changed, 12 insertions(+), 12 deletions(-) diff --git a/docker/1.5-openssl/Dockerfile b/docker/1.5-openssl/Dockerfile index 728c145e..996e69e4 100644 --- a/docker/1.5-openssl/Dockerfile +++ b/docker/1.5-openssl/Dockerfile @@ -3,8 +3,8 @@ FROM alpine:3.12 LABEL maintainer="Roger Light " \ description="Eclipse Mosquitto MQTT Broker" -ENV VERSION=1.5.10 \ - DOWNLOAD_SHA256=00d9688dffef0e2c26f3fb1486931ed5d89042d81f6d4c1dd455d63080149c20 \ +ENV VERSION=1.5.11 \ + DOWNLOAD_SHA256=4a3b8a8f5505d27a7a966dd68bfd76f1e69feb51796d1b46b7271d1bb5a1a299 \ GPG_KEYS=A0D6EEA1DCAE49A635A3B2F0779B22DFB3E717B7 \ LWS_VERSION=2.4.2 diff --git a/docker/1.5/Dockerfile b/docker/1.5/Dockerfile index 742bbaab..612bd2cc 100644 --- a/docker/1.5/Dockerfile +++ b/docker/1.5/Dockerfile @@ -3,8 +3,8 @@ FROM alpine:3.12 LABEL maintainer="Roger Light " \ description="Eclipse Mosquitto MQTT Broker" -ENV VERSION=1.5.10 \ - DOWNLOAD_SHA256=00d9688dffef0e2c26f3fb1486931ed5d89042d81f6d4c1dd455d63080149c20 \ +ENV VERSION=1.5.11 \ + DOWNLOAD_SHA256=4a3b8a8f5505d27a7a966dd68bfd76f1e69feb51796d1b46b7271d1bb5a1a299 \ GPG_KEYS=A0D6EEA1DCAE49A635A3B2F0779B22DFB3E717B7 \ LWS_VERSION=2.4.2 \ LWS_SHA256=73012d7fcf428dedccc816e83a63a01462e27819d5537b8e0d0c7264bfacfad6 diff --git a/docker/1.6-openssl/Dockerfile b/docker/1.6-openssl/Dockerfile index c26c07e6..3c09a74d 100644 --- a/docker/1.6-openssl/Dockerfile +++ b/docker/1.6-openssl/Dockerfile @@ -3,8 +3,8 @@ FROM alpine:3.12 LABEL maintainer="Roger Light " \ description="Eclipse Mosquitto MQTT Broker" -ENV VERSION=1.6.13 \ - DOWNLOAD_SHA256=ce205248dd323e4e562ff83e9e84d0f9a16f4bda87183c367c66a7163c0fc287 \ +ENV VERSION=1.6.14 \ + DOWNLOAD_SHA256=5ea7e342bfbd212a0addb915036be168040dea945e5de5fe739c43c5ff3823e4 \ GPG_KEYS=A0D6EEA1DCAE49A635A3B2F0779B22DFB3E717B7 \ LWS_VERSION=2.4.2 \ LWS_SHA256=73012d7fcf428dedccc816e83a63a01462e27819d5537b8e0d0c7264bfacfad6 diff --git a/docker/1.6/Dockerfile b/docker/1.6/Dockerfile index f8fa4fd9..86304cb8 100644 --- a/docker/1.6/Dockerfile +++ b/docker/1.6/Dockerfile @@ -3,8 +3,8 @@ FROM alpine:3.12 LABEL maintainer="Roger Light " \ description="Eclipse Mosquitto MQTT Broker" -ENV VERSION=1.6.13 \ - DOWNLOAD_SHA256=ce205248dd323e4e562ff83e9e84d0f9a16f4bda87183c367c66a7163c0fc287 \ +ENV VERSION=1.6.14 \ + DOWNLOAD_SHA256=5ea7e342bfbd212a0addb915036be168040dea945e5de5fe739c43c5ff3823e4 \ GPG_KEYS=A0D6EEA1DCAE49A635A3B2F0779B22DFB3E717B7 \ LWS_VERSION=2.4.2 \ LWS_SHA256=73012d7fcf428dedccc816e83a63a01462e27819d5537b8e0d0c7264bfacfad6 diff --git a/docker/2.0-openssl/Dockerfile b/docker/2.0-openssl/Dockerfile index 85e0ee2c..69f3467a 100644 --- a/docker/2.0-openssl/Dockerfile +++ b/docker/2.0-openssl/Dockerfile @@ -3,8 +3,8 @@ FROM alpine:3.12 LABEL maintainer="Roger Light " \ description="Eclipse Mosquitto MQTT Broker" -ENV VERSION=2.0.8 \ - DOWNLOAD_SHA256=b15da8fc4edcb91d554e1259e220ea0173ef639ceaa4b465e06feb7e125b84bf \ +ENV VERSION=2.0.9 \ + DOWNLOAD_SHA256=1b8553ef64a1cf5e4f4cfbe098330ae612adccd3d37f35b2db6f6fab501b01d4 \ GPG_KEYS=A0D6EEA1DCAE49A635A3B2F0779B22DFB3E717B7 \ LWS_VERSION=2.4.2 \ LWS_SHA256=73012d7fcf428dedccc816e83a63a01462e27819d5537b8e0d0c7264bfacfad6 \ diff --git a/docker/2.0/Dockerfile b/docker/2.0/Dockerfile index 1111687b..949e44a4 100644 --- a/docker/2.0/Dockerfile +++ b/docker/2.0/Dockerfile @@ -3,8 +3,8 @@ FROM alpine:3.12 LABEL maintainer="Roger Light " \ description="Eclipse Mosquitto MQTT Broker" -ENV VERSION=2.0.8 \ - DOWNLOAD_SHA256=b15da8fc4edcb91d554e1259e220ea0173ef639ceaa4b465e06feb7e125b84bf \ +ENV VERSION=2.0.9 \ + DOWNLOAD_SHA256=1b8553ef64a1cf5e4f4cfbe098330ae612adccd3d37f35b2db6f6fab501b01d4 \ GPG_KEYS=A0D6EEA1DCAE49A635A3B2F0779B22DFB3E717B7 \ LWS_VERSION=2.4.2 \ LWS_SHA256=73012d7fcf428dedccc816e83a63a01462e27819d5537b8e0d0c7264bfacfad6 \ From 9faf89be8d58d3903b8a43892e2c6e008d22bd86 Mon Sep 17 00:00:00 2001 From: Roger Light Date: Sun, 14 Mar 2021 19:24:56 +0000 Subject: [PATCH 16/41] Set `receive-maximum` to not exceed the `-C` message count. This is for mosquitto_sub and mosquitto_rr, to avoid potentially lost messages. Closes #2134. Thanks to Frantisek Fuka. --- ChangeLog.txt | 8 ++++++++ client/client_shared.c | 7 +++++++ 2 files changed, 15 insertions(+) diff --git a/ChangeLog.txt b/ChangeLog.txt index 063e29a1..e112c086 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,3 +1,11 @@ +2.0.10 - 2021-xx-xx +================== + +Clients: +- Set `receive-maximum` to not exceed the `-C` message count in mosquitto_sub + and mosquitto_rr, to avoid potentially lost messages. Closes #2134. + + 2.0.9 - 2021-03-11 ================== diff --git a/client/client_shared.c b/client/client_shared.c index 26755b7b..68a12b39 100644 --- a/client/client_shared.c +++ b/client/client_shared.c @@ -1321,6 +1321,13 @@ int client_opts_set(struct mosquitto *mosq, struct mosq_config *cfg) if(cfg->tcp_nodelay){ mosquitto_int_option(mosq, MOSQ_OPT_TCP_NODELAY, 1); } + + if(cfg->msg_count > 0 && cfg->msg_count < 20){ + /* 20 is the default "receive maximum" + * If we don't set this, then we can receive > msg_count messages + * before we quit.*/ + mosquitto_int_option(mosq, MOSQ_OPT_RECEIVE_MAXIMUM, cfg->msg_count); + } return MOSQ_ERR_SUCCESS; } From a6bb8d3611fe559dcd79251c9893929ee5966d50 Mon Sep 17 00:00:00 2001 From: Roger Light Date: Sun, 14 Mar 2021 19:26:41 +0000 Subject: [PATCH 17/41] Don't over write new receive-maximum if a v5 client connects. This is for when it takes over an old session. Closes #2134. Thanks to Frantisek Fuka. --- ChangeLog.txt | 4 ++++ src/handle_connect.c | 12 ++++++++++++ 2 files changed, 16 insertions(+) diff --git a/ChangeLog.txt b/ChangeLog.txt index e112c086..275594ec 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,6 +1,10 @@ 2.0.10 - 2021-xx-xx ================== +Broker: +- Don't over write new receive-maximum if a v5 client connects and takes over + an old session. Closes #2134. + Clients: - Set `receive-maximum` to not exceed the `-C` message count in mosquitto_sub and mosquitto_rr, to avoid potentially lost messages. Closes #2134. diff --git a/src/handle_connect.c b/src/handle_connect.c index c3355d90..b4cefad5 100644 --- a/src/handle_connect.c +++ b/src/handle_connect.c @@ -111,6 +111,8 @@ int connect__on_authorised(struct mosquitto *context, void *auth_data_out, uint1 uint8_t connect_ack = 0; int i; int rc; + int in_quota, out_quota; + uint16_t in_maximum, out_maximum; /* Find if this client already has an entry. This must be done *after* any security checks. */ HASH_FIND(hh_id, db.contexts_by_id, context->id, strlen(context->id), found_context); @@ -135,12 +137,22 @@ int connect__on_authorised(struct mosquitto *context, void *auth_data_out, uint1 if(found_context->msgs_in.inflight || found_context->msgs_in.queued || found_context->msgs_out.inflight || found_context->msgs_out.queued){ + in_quota = context->msgs_in.inflight_quota; + out_quota = context->msgs_out.inflight_quota; + in_maximum = context->msgs_in.inflight_maximum; + out_maximum = context->msgs_out.inflight_maximum; + memcpy(&context->msgs_in, &found_context->msgs_in, sizeof(struct mosquitto_msg_data)); memcpy(&context->msgs_out, &found_context->msgs_out, sizeof(struct mosquitto_msg_data)); memset(&found_context->msgs_in, 0, sizeof(struct mosquitto_msg_data)); memset(&found_context->msgs_out, 0, sizeof(struct mosquitto_msg_data)); + context->msgs_in.inflight_quota = in_quota; + context->msgs_out.inflight_quota = out_quota; + context->msgs_in.inflight_maximum = in_maximum; + context->msgs_out.inflight_maximum = out_maximum; + db__message_reconnect_reset(context); } context->subs = found_context->subs; From 9989a3502d0c01b87ee6ec71c858d21532853b0f Mon Sep 17 00:00:00 2001 From: Roger Light Date: Sat, 20 Mar 2021 10:33:58 +0000 Subject: [PATCH 18/41] Add link to authentication options if running in local only mode. --- src/mosquitto.c | 1 + 1 file changed, 1 insertion(+) diff --git a/src/mosquitto.c b/src/mosquitto.c index 82a61d3c..d3905ebe 100644 --- a/src/mosquitto.c +++ b/src/mosquitto.c @@ -313,6 +313,7 @@ int listeners__start_local_only(void) log__printf(NULL, MOSQ_LOG_WARNING, "Starting in local only mode. Connections will only be possible from clients running on this machine."); log__printf(NULL, MOSQ_LOG_WARNING, "Create a configuration file which defines a listener to allow remote access."); + log__printf(NULL, MOSQ_LOG_WARNING, "For more details see https://mosquitto.org/documentation/authentication-methods/"); if(db.config->cmd_port_count == 0){ rc = listeners__add_local("127.0.0.1", 1883); if(rc == MOSQ_ERR_NOMEM) return MOSQ_ERR_NOMEM; From cca41d176d94ba2480d5b5322a24ac358b45f24f Mon Sep 17 00:00:00 2001 From: Roger Light Date: Sat, 20 Mar 2021 19:16:13 +0000 Subject: [PATCH 19/41] Fix inconsistent sign in log__printf declaration. --- lib/logging_mosq.c | 5 +++-- lib/logging_mosq.h | 6 +++++- src/logging.c | 1 + src/mosquitto_broker_internal.h | 2 +- 4 files changed, 10 insertions(+), 4 deletions(-) diff --git a/lib/logging_mosq.c b/lib/logging_mosq.c index 16e9e949..24d56867 100644 --- a/lib/logging_mosq.c +++ b/lib/logging_mosq.c @@ -23,11 +23,12 @@ Contributors: #include #include +#include "logging_mosq.h" #include "mosquitto_internal.h" #include "mosquitto.h" #include "memory_mosq.h" -int log__printf(struct mosquitto *mosq, int priority, const char *fmt, ...) +int log__printf(struct mosquitto *mosq, unsigned int priority, const char *fmt, ...) { va_list va; char *s; @@ -50,7 +51,7 @@ int log__printf(struct mosquitto *mosq, int priority, const char *fmt, ...) va_end(va); s[len-1] = '\0'; /* Ensure string is null terminated. */ - mosq->on_log(mosq, mosq->userdata, priority, s); + mosq->on_log(mosq, mosq->userdata, (int)priority, s); mosquitto__free(s); } diff --git a/lib/logging_mosq.h b/lib/logging_mosq.h index 580edb8b..bc94f5f5 100644 --- a/lib/logging_mosq.h +++ b/lib/logging_mosq.h @@ -20,6 +20,10 @@ Contributors: #include "mosquitto.h" -int log__printf(struct mosquitto *mosq, unsigned int priority, const char *fmt, ...); +#ifndef __GNUC__ +#define __attribute__(attrib) +#endif + +int log__printf(struct mosquitto *mosq, unsigned int level, const char *fmt, ...) __attribute__((format(printf, 3, 4))); #endif diff --git a/src/logging.c b/src/logging.c index ff1a5b4d..915ede23 100644 --- a/src/logging.c +++ b/src/logging.c @@ -34,6 +34,7 @@ Contributors: #include #endif +#include "logging_mosq.h" #include "mosquitto_broker_internal.h" #include "memory_mosq.h" #include "misc_mosq.h" diff --git a/src/mosquitto_broker_internal.h b/src/mosquitto_broker_internal.h index 58c26bfe..6f6d48d2 100644 --- a/src/mosquitto_broker_internal.h +++ b/src/mosquitto_broker_internal.h @@ -34,6 +34,7 @@ Contributors: #include "mosquitto_broker.h" #include "mosquitto_plugin.h" #include "mosquitto.h" +#include "logging_mosq.h" #include "password_mosq.h" #include "tls_mosq.h" #include "uthash.h" @@ -709,7 +710,6 @@ int control__unregister_callback(struct mosquitto__security_options *opts, MOSQ_ * ============================================================ */ int log__init(struct mosquitto__config *config); int log__close(struct mosquitto__config *config); -int log__printf(struct mosquitto *mosq, unsigned int level, const char *fmt, ...) __attribute__((format(printf, 3, 4))); void log__internal(const char *fmt, ...) __attribute__((format(printf, 1, 2))); /* ============================================================ From 2de8c15bc988e07f77cde57fb197ea02521d63b1 Mon Sep 17 00:00:00 2001 From: Roger Light Date: Sun, 21 Mar 2021 09:17:53 +0000 Subject: [PATCH 20/41] Minor build fixes. --- ChangeLog.txt | 4 ++ apps/db_dump/db_dump.c | 1 + apps/db_dump/print.c | 11 ++-- apps/db_dump/stubs.c | 2 + apps/mosquitto_ctrl/Makefile | 2 +- apps/mosquitto_ctrl/dynsec.c | 2 +- apps/mosquitto_ctrl/mosquitto_ctrl.c | 16 +++--- apps/mosquitto_passwd/get_password.c | 4 +- apps/mosquitto_passwd/mosquitto_passwd.c | 18 +++---- client/client_shared.c | 4 +- client/pub_client.c | 8 +-- client/rr_client.c | 12 ++--- client/sub_client.c | 26 +++------ config.mk | 2 +- lib/handle_auth.c | 1 + lib/handle_disconnect.c | 1 + lib/handle_publish.c | 1 + lib/handle_suback.c | 1 + lib/misc_mosq.c | 2 + lib/misc_mosq.h | 1 + lib/net_mosq_ocsp.c | 3 +- lib/property_mosq.c | 6 +-- lib/send_connect.c | 1 + lib/send_subscribe.c | 3 +- lib/socks_mosq.c | 3 +- lib/tls_mosq.c | 2 +- plugins/auth-by-ip/mosquitto_auth_by_ip.c | 13 ++++- src/conf.c | 4 +- src/conf_includedir.c | 2 +- src/database.c | 65 ++--------------------- src/handle_connect.c | 2 +- src/logging.c | 2 +- src/loop.c | 4 +- src/mosquitto.c | 23 +++----- src/mosquitto_broker_internal.h | 11 +++- src/mux_epoll.c | 6 --- src/net.c | 2 +- src/persist.h | 2 + src/security.c | 6 +-- src/security_default.c | 4 +- src/signals.c | 2 + 41 files changed, 123 insertions(+), 162 deletions(-) diff --git a/ChangeLog.txt b/ChangeLog.txt index 275594ec..1701c5e4 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -9,6 +9,10 @@ Clients: - Set `receive-maximum` to not exceed the `-C` message count in mosquitto_sub and mosquitto_rr, to avoid potentially lost messages. Closes #2134. +Build: +- A variety of minor build related fixes, like functions not having previous + declarations. + 2.0.9 - 2021-03-11 ================== diff --git a/apps/db_dump/db_dump.c b/apps/db_dump/db_dump.c index ad6d2f7b..5ae009f2 100644 --- a/apps/db_dump/db_dump.c +++ b/apps/db_dump/db_dump.c @@ -27,6 +27,7 @@ Contributors: #include #include +#include "db_dump.h" #include #include #include diff --git a/apps/db_dump/print.c b/apps/db_dump/print.c index 84ca2ef0..bc4eac3e 100644 --- a/apps/db_dump/print.c +++ b/apps/db_dump/print.c @@ -19,6 +19,7 @@ Contributors: #include #include +#include "db_dump.h" #include #include #include @@ -142,7 +143,7 @@ static void print__properties(mosquitto_property *properties) } -void print__client(struct P_client *chunk, int length) +void print__client(struct P_client *chunk, uint32_t length) { printf("DB_CHUNK_CLIENT:\n"); printf("\tLength: %d\n", length); @@ -159,7 +160,7 @@ void print__client(struct P_client *chunk, int length) } -void print__client_msg(struct P_client_msg *chunk, int length) +void print__client_msg(struct P_client_msg *chunk, uint32_t length) { printf("DB_CHUNK_CLIENT_MSG:\n"); printf("\tLength: %d\n", length); @@ -175,8 +176,10 @@ void print__client_msg(struct P_client_msg *chunk, int length) } -void print__msg_store(struct P_msg_store *chunk, int length) +void print__msg_store(struct P_msg_store *chunk, uint32_t length) { + uint8_t *payload; + printf("DB_CHUNK_MSG_STORE:\n"); printf("\tLength: %d\n", length); printf("\tStore ID: %" PRIu64 "\n", chunk->F.store_id); @@ -190,8 +193,6 @@ void print__msg_store(struct P_msg_store *chunk, int length) printf("\tPayload Length: %d\n", chunk->F.payloadlen); printf("\tExpiry Time: %" PRIu64 "\n", chunk->F.expiry_time); - uint8_t *payload; - payload = chunk->payload; if(chunk->F.payloadlen < 256){ /* Print payloads with UTF-8 data below an arbitrary limit of 256 bytes */ diff --git a/apps/db_dump/stubs.c b/apps/db_dump/stubs.c index af00f706..8e233871 100644 --- a/apps/db_dump/stubs.c +++ b/apps/db_dump/stubs.c @@ -1,8 +1,10 @@ #include #include +#include "misc_mosq.h" #include "mosquitto_broker_internal.h" #include "mosquitto_internal.h" +#include "util_mosq.h" struct mosquitto *context__init(mosq_sock_t sock) { diff --git a/apps/mosquitto_ctrl/Makefile b/apps/mosquitto_ctrl/Makefile index 286eb449..502f0dac 100644 --- a/apps/mosquitto_ctrl/Makefile +++ b/apps/mosquitto_ctrl/Makefile @@ -12,7 +12,7 @@ LIBMOSQ:=../../lib/libmosquitto.a endif endif -LOCAL_CPPFLAGS:=-I../mosquitto_passwd +LOCAL_CPPFLAGS:=-I../mosquitto_passwd -DWITH_CJSON OBJS= mosquitto_ctrl.o \ client.o \ diff --git a/apps/mosquitto_ctrl/dynsec.c b/apps/mosquitto_ctrl/dynsec.c index fae86f43..c906cb2c 100644 --- a/apps/mosquitto_ctrl/dynsec.c +++ b/apps/mosquitto_ctrl/dynsec.c @@ -689,7 +689,7 @@ static cJSON *init_create(const char *username, const char *password, const char } /* mosquitto_ctrl dynsec init [role-name] */ -int dynsec_init(int argc, char *argv[]) +static int dynsec_init(int argc, char *argv[]) { char *filename; char *admin_user; diff --git a/apps/mosquitto_ctrl/mosquitto_ctrl.c b/apps/mosquitto_ctrl/mosquitto_ctrl.c index bda95902..b4433988 100644 --- a/apps/mosquitto_ctrl/mosquitto_ctrl.c +++ b/apps/mosquitto_ctrl/mosquitto_ctrl.c @@ -28,7 +28,7 @@ Contributors: #include "mosquitto.h" #include "mosquitto_ctrl.h" -void print_version(void) +static void print_version(void) { int major, minor, revision; @@ -36,7 +36,7 @@ void print_version(void) printf("mosquitto_ctrl version %s running on libmosquitto %d.%d.%d.\n", VERSION, major, minor, revision); } -void print_usage(void) +static void print_usage(void) { printf("mosquitto_ctrl is a tool for administering certain Mosquitto features.\n"); print_version(); @@ -51,7 +51,7 @@ int main(int argc, char *argv[]) { struct mosq_ctrl ctrl; int rc = MOSQ_ERR_SUCCESS; - FUNC_ctrl_main ctrl_main = NULL; + FUNC_ctrl_main l_ctrl_main = NULL; void *lib = NULL; char lib_name[200]; @@ -76,22 +76,22 @@ int main(int argc, char *argv[]) /* In built modules */ if(!strcasecmp(argv[0], "dynsec")){ - ctrl_main = dynsec__main; + l_ctrl_main = dynsec__main; }else{ /* Attempt external module */ snprintf(lib_name, sizeof(lib_name), "mosquitto_ctrl_%s.so", argv[0]); lib = LIB_LOAD(lib_name); if(lib){ - ctrl_main = (FUNC_ctrl_main)LIB_SYM(lib, "ctrl_main"); + l_ctrl_main = (FUNC_ctrl_main)LIB_SYM(lib, "ctrl_main"); } } - if(ctrl_main == NULL){ + if(l_ctrl_main == NULL){ fprintf(stderr, "Error: Module '%s' not supported.\n", argv[0]); rc = MOSQ_ERR_NOT_SUPPORTED; } - if(ctrl_main){ - rc = ctrl_main(argc-1, &argv[1], &ctrl); + if(l_ctrl_main){ + rc = l_ctrl_main(argc-1, &argv[1], &ctrl); if(rc < 0){ /* Usage print */ rc = 0; diff --git a/apps/mosquitto_passwd/get_password.c b/apps/mosquitto_passwd/get_password.c index a62a76cd..42842536 100644 --- a/apps/mosquitto_passwd/get_password.c +++ b/apps/mosquitto_passwd/get_password.c @@ -35,7 +35,9 @@ Contributors: # include #endif -#define MAX_BUFFER_LEN 65536 +#include "get_password.h" + +#define MAX_BUFFER_LEN 65500 #define SALT_LEN 12 void get_password__reset_term(void) diff --git a/apps/mosquitto_passwd/mosquitto_passwd.c b/apps/mosquitto_passwd/mosquitto_passwd.c index 628bcc71..5a5a04f4 100644 --- a/apps/mosquitto_passwd/mosquitto_passwd.c +++ b/apps/mosquitto_passwd/mosquitto_passwd.c @@ -52,7 +52,7 @@ Contributors: # include #endif -#define MAX_BUFFER_LEN 65536 +#define MAX_BUFFER_LEN 65500 #define SALT_LEN 12 #include "misc_mosq.h" @@ -107,7 +107,7 @@ static FILE *mpw_tmpfile(void) #endif -void print_usage(void) +static void print_usage(void) { printf("mosquitto_passwd is a tool for managing password files for mosquitto.\n\n"); printf("Usage: mosquitto_passwd [-H sha512 | -H sha512-pbkdf2] [-c | -D] passwordfile username\n"); @@ -122,7 +122,7 @@ void print_usage(void) printf("\nSee https://mosquitto.org/ for more information.\n\n"); } -int output_new_password(FILE *fptr, const char *username, const char *password, int iterations) +static int output_new_password(FILE *fptr, const char *username, const char *password, int iterations) { int rc; char *salt64 = NULL, *hash64 = NULL; @@ -255,7 +255,7 @@ static int delete_pwuser_cb(FILE *fptr, FILE *ftmp, const char *username, const return 0; } -int delete_pwuser(FILE *fptr, FILE *ftmp, const char *username) +static int delete_pwuser(FILE *fptr, FILE *ftmp, const char *username) { struct cb_helper helper; int rc; @@ -288,7 +288,7 @@ static int update_file_cb(FILE *fptr, FILE *ftmp, const char *username, const ch } } -int update_file(FILE *fptr, FILE *ftmp) +static int update_file(FILE *fptr, FILE *ftmp) { return pwfile_iterate(fptr, ftmp, update_file_cb, NULL); } @@ -315,7 +315,7 @@ static int update_pwuser_cb(FILE *fptr, FILE *ftmp, const char *username, const return rc; } -int update_pwuser(FILE *fptr, FILE *ftmp, const char *username, const char *password, int iterations) +static int update_pwuser(FILE *fptr, FILE *ftmp, const char *username, const char *password, int iterations) { struct cb_helper helper; int rc; @@ -334,7 +334,7 @@ int update_pwuser(FILE *fptr, FILE *ftmp, const char *username, const char *pass } -int copy_contents(FILE *src, FILE *dest) +static int copy_contents(FILE *src, FILE *dest) { char buf[MAX_BUFFER_LEN]; size_t len; @@ -361,7 +361,7 @@ int copy_contents(FILE *src, FILE *dest) return 0; } -int create_backup(const char *backup_file, FILE *fptr) +static int create_backup(const char *backup_file, FILE *fptr) { FILE *fbackup; @@ -380,7 +380,7 @@ int create_backup(const char *backup_file, FILE *fptr) return 0; } -void handle_sigint(int signal) +static void handle_sigint(int signal) { get_password__reset_term(); diff --git a/client/client_shared.c b/client/client_shared.c index 68a12b39..f60b98be 100644 --- a/client/client_shared.c +++ b/client/client_shared.c @@ -183,7 +183,7 @@ static int check_format(const char *str) } -void init_config(struct mosq_config *cfg, int pub_or_sub) +static void init_config(struct mosq_config *cfg, int pub_or_sub) { memset(cfg, 0, sizeof(*cfg)); cfg->port = PORT_UNDEFINED; @@ -485,7 +485,7 @@ int client_config_load(struct mosq_config *cfg, int pub_or_sub, int argc, char * return MOSQ_ERR_SUCCESS; } -int cfg_add_topic(struct mosq_config *cfg, int type, char *topic, const char *arg) +static int cfg_add_topic(struct mosq_config *cfg, int type, char *topic, const char *arg) { if(mosquitto_validate_utf8(topic, (int )strlen(topic))){ fprintf(stderr, "Error: Malformed UTF-8 in %s argument.\n\n", arg); diff --git a/client/pub_client.c b/client/pub_client.c index 8049de6e..e82d90e0 100644 --- a/client/pub_client.c +++ b/client/pub_client.c @@ -232,7 +232,7 @@ int pub_shared_init(void) } -int pub_stdin_line_loop(struct mosquitto *mosq) +static int pub_stdin_line_loop(struct mosquitto *mosq) { char *buf2; int buf_len_actual = 0; @@ -334,7 +334,7 @@ int pub_stdin_line_loop(struct mosquitto *mosq) } -int pub_other_loop(struct mosquitto *mosq) +static int pub_other_loop(struct mosquitto *mosq) { int rc; int loop_delay = 1000; @@ -387,7 +387,7 @@ void pub_shared_cleanup(void) } -void print_version(void) +static void print_version(void) { int major, minor, revision; @@ -395,7 +395,7 @@ void print_version(void) printf("mosquitto_pub version %s running on libmosquitto %d.%d.%d.\n", VERSION, major, minor, revision); } -void print_usage(void) +static void print_usage(void) { int major, minor, revision; diff --git a/client/rr_client.c b/client/rr_client.c index 2331a4ed..4b1edba4 100644 --- a/client/rr_client.c +++ b/client/rr_client.c @@ -50,8 +50,6 @@ enum rr__state { static enum rr__state client_state = rr_s_new; -extern struct mosq_config cfg; - bool process_messages = true; int msg_count = 0; struct mosquitto *g_mosq = NULL; @@ -59,7 +57,7 @@ static bool timed_out = false; static int connack_result = 0; #ifndef WIN32 -void my_signal_handler(int signum) +static void my_signal_handler(int signum) { if(signum == SIGALRM){ process_messages = false; @@ -80,7 +78,7 @@ int my_publish(struct mosquitto *mosq, int *mid, const char *topic, int payloadl } -void my_message_callback(struct mosquitto *mosq, void *obj, const struct mosquitto_message *message, const mosquitto_property *properties) +static void my_message_callback(struct mosquitto *mosq, void *obj, const struct mosquitto_message *message, const mosquitto_property *properties) { UNUSED(mosq); UNUSED(obj); @@ -151,7 +149,7 @@ void my_connect_callback(struct mosquitto *mosq, void *obj, int result, int flag } -void my_subscribe_callback(struct mosquitto *mosq, void *obj, int mid, int qos_count, const int *granted_qos) +static void my_subscribe_callback(struct mosquitto *mosq, void *obj, int mid, int qos_count, const int *granted_qos) { UNUSED(obj); UNUSED(mid); @@ -179,7 +177,7 @@ void my_publish_callback(struct mosquitto *mosq, void *obj, int mid, int reason_ } -void print_version(void) +static void print_version(void) { int major, minor, revision; @@ -187,7 +185,7 @@ void print_version(void) printf("mosquitto_rr version %s running on libmosquitto %d.%d.%d.\n", VERSION, major, minor, revision); } -void print_usage(void) +static void print_usage(void) { int major, minor, revision; diff --git a/client/sub_client.c b/client/sub_client.c index e2cebcdc..72170ab2 100644 --- a/client/sub_client.c +++ b/client/sub_client.c @@ -48,7 +48,7 @@ static int connack_result = 0; bool connack_received = false; #ifndef WIN32 -void my_signal_handler(int signum) +static void my_signal_handler(int signum) { if(signum == SIGALRM || signum == SIGTERM || signum == SIGINT){ if(connack_received){ @@ -65,19 +65,7 @@ void my_signal_handler(int signum) #endif -void my_publish_callback(struct mosquitto *mosq, void *obj, int mid, int reason_code, const mosquitto_property *properties) -{ - UNUSED(obj); - UNUSED(reason_code); - UNUSED(properties); - - if(process_messages == false && (mid == last_mid || last_mid == 0)){ - mosquitto_disconnect_v5(mosq, 0, cfg.disconnect_props); - } -} - - -void my_message_callback(struct mosquitto *mosq, void *obj, const struct mosquitto_message *message, const mosquitto_property *properties) +static void my_message_callback(struct mosquitto *mosq, void *obj, const struct mosquitto_message *message, const mosquitto_property *properties) { int i; bool res; @@ -120,7 +108,7 @@ void my_message_callback(struct mosquitto *mosq, void *obj, const struct mosquit } } -void my_connect_callback(struct mosquitto *mosq, void *obj, int result, int flags, const mosquitto_property *properties) +static void my_connect_callback(struct mosquitto *mosq, void *obj, int result, int flags, const mosquitto_property *properties) { int i; @@ -153,7 +141,7 @@ void my_connect_callback(struct mosquitto *mosq, void *obj, int result, int flag } } -void my_subscribe_callback(struct mosquitto *mosq, void *obj, int mid, int qos_count, const int *granted_qos) +static void my_subscribe_callback(struct mosquitto *mosq, void *obj, int mid, int qos_count, const int *granted_qos) { int i; bool some_sub_allowed = (granted_qos[0] < 128); @@ -177,7 +165,7 @@ void my_subscribe_callback(struct mosquitto *mosq, void *obj, int mid, int qos_c } } -void my_log_callback(struct mosquitto *mosq, void *obj, int level, const char *str) +static void my_log_callback(struct mosquitto *mosq, void *obj, int level, const char *str) { UNUSED(mosq); UNUSED(obj); @@ -186,7 +174,7 @@ void my_log_callback(struct mosquitto *mosq, void *obj, int level, const char *s printf("%s\n", str); } -void print_version(void) +static void print_version(void) { int major, minor, revision; @@ -194,7 +182,7 @@ void print_version(void) printf("mosquitto_sub version %s running on libmosquitto %d.%d.%d.\n", VERSION, major, minor, revision); } -void print_usage(void) +static void print_usage(void) { int major, minor, revision; diff --git a/config.mk b/config.mk index d31b1160..d7b14b75 100644 --- a/config.mk +++ b/config.mk @@ -148,7 +148,7 @@ ifeq ($(UNAME),SunOS) CFLAGS?=-Wall -ggdb -O2 endif else - CFLAGS?=-Wall -ggdb -O2 -Wconversion + CFLAGS?=-Wall -ggdb -O2 -Wconversion -Wextra endif STATIC_LIB_DEPS:= diff --git a/lib/handle_auth.c b/lib/handle_auth.c index e33d085d..61f3bb4f 100644 --- a/lib/handle_auth.c +++ b/lib/handle_auth.c @@ -26,6 +26,7 @@ Contributors: #include "mqtt_protocol.h" #include "packet_mosq.h" #include "property_mosq.h" +#include "read_handle.h" int handle__auth(struct mosquitto *mosq) diff --git a/lib/handle_disconnect.c b/lib/handle_disconnect.c index a0a638db..28c51845 100644 --- a/lib/handle_disconnect.c +++ b/lib/handle_disconnect.c @@ -27,6 +27,7 @@ Contributors: #include "net_mosq.h" #include "packet_mosq.h" #include "property_mosq.h" +#include "read_handle.h" #include "send_mosq.h" #include "util_mosq.h" diff --git a/lib/handle_publish.c b/lib/handle_publish.c index 40644ef3..3fec2d53 100644 --- a/lib/handle_publish.c +++ b/lib/handle_publish.c @@ -29,6 +29,7 @@ Contributors: #include "messages_mosq.h" #include "packet_mosq.h" #include "property_mosq.h" +#include "read_handle.h" #include "send_mosq.h" #include "time_mosq.h" #include "util_mosq.h" diff --git a/lib/handle_suback.c b/lib/handle_suback.c index 91a40e26..770558be 100644 --- a/lib/handle_suback.c +++ b/lib/handle_suback.c @@ -31,6 +31,7 @@ Contributors: #include "mqtt_protocol.h" #include "packet_mosq.h" #include "property_mosq.h" +#include "read_handle.h" #include "util_mosq.h" diff --git a/lib/misc_mosq.c b/lib/misc_mosq.c index e7bf0784..8f2f2d2a 100644 --- a/lib/misc_mosq.c +++ b/lib/misc_mosq.c @@ -36,6 +36,8 @@ Contributors: # include #endif +#include "misc_mosq.h" + FILE *mosquitto__fopen(const char *path, const char *mode, bool restrict_read) { diff --git a/lib/misc_mosq.h b/lib/misc_mosq.h index 233071e6..f86f5d76 100644 --- a/lib/misc_mosq.h +++ b/lib/misc_mosq.h @@ -19,6 +19,7 @@ Contributors: #define MISC_MOSQ_H #include +#include FILE *mosquitto__fopen(const char *path, const char *mode, bool restrict_read); char *misc__trimblanks(char *str); diff --git a/lib/net_mosq_ocsp.c b/lib/net_mosq_ocsp.c index 84b818c8..8c762373 100644 --- a/lib/net_mosq_ocsp.c +++ b/lib/net_mosq_ocsp.c @@ -64,10 +64,11 @@ int mosquitto__verify_ocsp_status_cb(SSL * ssl, void *arg) OCSP_BASICRESP *br = NULL; X509_STORE *st = NULL; STACK_OF(X509) *ch = NULL; + long len; UNUSED(ssl); - long len = SSL_get_tlsext_status_ocsp_resp(mosq->ssl, &p); + len = SSL_get_tlsext_status_ocsp_resp(mosq->ssl, &p); log__printf(mosq, MOSQ_LOG_DEBUG, "OCSP: SSL_get_tlsext_status_ocsp_resp returned %ld bytes", len); /* the following functions expect a const pointer */ diff --git a/lib/property_mosq.c b/lib/property_mosq.c index 8a77dbe6..0cfc9f9c 100644 --- a/lib/property_mosq.c +++ b/lib/property_mosq.c @@ -33,7 +33,7 @@ Contributors: #include "property_mosq.h" -int property__read(struct mosquitto__packet *packet, uint32_t *len, mosquitto_property *property) +static int property__read(struct mosquitto__packet *packet, uint32_t *len, mosquitto_property *property) { int rc; uint32_t property_identifier; @@ -355,7 +355,7 @@ unsigned int property__get_remaining_length(const mosquitto_property *props) } -int property__write(struct mosquitto__packet *packet, const mosquitto_property *property) +static int property__write(struct mosquitto__packet *packet, const mosquitto_property *property) { int rc; @@ -975,7 +975,7 @@ int mosquitto_property_check_all(int command, const mosquitto_property *properti return MOSQ_ERR_SUCCESS; } -const mosquitto_property *property__get_property(const mosquitto_property *proplist, int identifier, bool skip_first) +static const mosquitto_property *property__get_property(const mosquitto_property *proplist, int identifier, bool skip_first) { const mosquitto_property *p; bool is_first = true; diff --git a/lib/send_connect.c b/lib/send_connect.c index d35cd80e..d9a3257c 100644 --- a/lib/send_connect.c +++ b/lib/send_connect.c @@ -32,6 +32,7 @@ Contributors: #include "mqtt_protocol.h" #include "packet_mosq.h" #include "property_mosq.h" +#include "send_mosq.h" int send__connect(struct mosquitto *mosq, uint16_t keepalive, bool clean_session, const mosquitto_property *properties) { diff --git a/lib/send_subscribe.c b/lib/send_subscribe.c index a8e77545..9217dc5b 100644 --- a/lib/send_subscribe.c +++ b/lib/send_subscribe.c @@ -32,10 +32,11 @@ Contributors: #include "mqtt_protocol.h" #include "packet_mosq.h" #include "property_mosq.h" +#include "send_mosq.h" #include "util_mosq.h" -int send__subscribe(struct mosquitto *mosq, int *mid, int topic_count, const char **topic, int topic_qos, const mosquitto_property *properties) +int send__subscribe(struct mosquitto *mosq, int *mid, int topic_count, char *const *const topic, int topic_qos, const mosquitto_property *properties) { struct mosquitto__packet *packet = NULL; uint32_t packetlen; diff --git a/lib/socks_mosq.c b/lib/socks_mosq.c index a360d64b..ed8fe128 100644 --- a/lib/socks_mosq.c +++ b/lib/socks_mosq.c @@ -23,7 +23,7 @@ Contributors: #include #ifdef WIN32 # include -#elif __QNX__ +#elif defined(__QNX__) # include # include # include @@ -40,6 +40,7 @@ Contributors: #include "net_mosq.h" #include "packet_mosq.h" #include "send_mosq.h" +#include "socks_mosq.h" #include "util_mosq.h" #define SOCKS_AUTH_NONE 0x00U diff --git a/lib/tls_mosq.c b/lib/tls_mosq.c index bddf2ec0..13d9aa22 100644 --- a/lib/tls_mosq.c +++ b/lib/tls_mosq.c @@ -84,7 +84,7 @@ int mosquitto__server_certificate_verify(int preverify_ok, X509_STORE_CTX *ctx) } } -int mosquitto__cmp_hostname_wildcard(char *certname, const char *hostname) +static int mosquitto__cmp_hostname_wildcard(char *certname, const char *hostname) { size_t i; size_t len; diff --git a/plugins/auth-by-ip/mosquitto_auth_by_ip.c b/plugins/auth-by-ip/mosquitto_auth_by_ip.c index 6a6f6289..49cc0178 100644 --- a/plugins/auth-by-ip/mosquitto_auth_by_ip.c +++ b/plugins/auth-by-ip/mosquitto_auth_by_ip.c @@ -32,7 +32,7 @@ Contributors: * * Note that this only works on Mosquitto 2.0 or later. */ - +#include "config.h" #include #include @@ -49,6 +49,9 @@ static int basic_auth_callback(int event, void *event_data, void *userdata) struct mosquitto_evt_basic_auth *ed = event_data; const char *ip_address; + UNUSED(event); + UNUSED(userdata); + ip_address = mosquitto_client_address(ed->client); if(!strcmp(ip_address, "127.0.0.1")){ /* Only allow connections from localhost */ @@ -72,11 +75,19 @@ int mosquitto_plugin_version(int supported_version_count, const int *supported_v int mosquitto_plugin_init(mosquitto_plugin_id_t *identifier, void **user_data, struct mosquitto_opt *opts, int opt_count) { + UNUSED(user_data); + UNUSED(opts); + UNUSED(opt_count); + mosq_pid = identifier; return mosquitto_callback_register(mosq_pid, MOSQ_EVT_BASIC_AUTH, basic_auth_callback, NULL, NULL); } int mosquitto_plugin_cleanup(void *user_data, struct mosquitto_opt *opts, int opt_count) { + UNUSED(user_data); + UNUSED(opts); + UNUSED(opt_count); + return mosquitto_callback_unregister(mosq_pid, MOSQ_EVT_BASIC_AUTH, basic_auth_callback, NULL); } diff --git a/src/conf.c b/src/conf.c index 33326c0c..bc4158ae 100644 --- a/src/conf.c +++ b/src/conf.c @@ -527,7 +527,7 @@ int config__parse_args(struct mosquitto__config *config, int argc, char *argv[]) return config__check(config); } -void config__copy(struct mosquitto__config *src, struct mosquitto__config *dest) +static void config__copy(struct mosquitto__config *src, struct mosquitto__config *dest) { mosquitto__free(dest->security_options.acl_file); dest->security_options.acl_file = src->security_options.acl_file; @@ -721,7 +721,7 @@ int config__read(struct mosquitto__config *config, bool reload) } -int config__read_file_core(struct mosquitto__config *config, bool reload, struct config_recurse *cr, int level, int *lineno, FILE *fptr, char **buf, int *buflen) +static int config__read_file_core(struct mosquitto__config *config, bool reload, struct config_recurse *cr, int level, int *lineno, FILE *fptr, char **buf, int *buflen) { int rc; char *token; diff --git a/src/conf_includedir.c b/src/conf_includedir.c index 5dda0a1e..9673ca5f 100644 --- a/src/conf_includedir.c +++ b/src/conf_includedir.c @@ -50,7 +50,7 @@ Contributors: #include "mqtt_protocol.h" -int scmp_p(const void *p1, const void *p2) +static int scmp_p(const void *p1, const void *p2) { const char *s1 = *(const char **)p1; const char *s2 = *(const char **)p2; diff --git a/src/database.c b/src/database.c index 2ba131c5..88253c57 100644 --- a/src/database.c +++ b/src/database.c @@ -580,7 +580,7 @@ int db__message_update_outgoing(struct mosquitto *context, uint16_t mid, enum mo } -void db__messages_delete_list(struct mosquitto_client_msg **head) +static void db__messages_delete_list(struct mosquitto_client_msg **head) { struct mosquitto_client_msg *tail, *tmp; @@ -624,7 +624,7 @@ int db__messages_delete(struct mosquitto *context, bool force_free) int db__messages_easy_queue(struct mosquitto *context, const char *topic, uint8_t qos, uint32_t payloadlen, const void *payload, int retain, uint32_t message_expiry_interval, mosquitto_property **properties) { struct mosquitto_msg_store *stored; - char *source_id; + const char *source_id; enum mosquitto_msg_origin origin; if(!topic) return MOSQ_ERR_INVAL; @@ -752,7 +752,7 @@ int db__message_store_find(struct mosquitto *context, uint16_t mid, struct mosqu /* Called on reconnect to set outgoing messages to a sensible state and force a * retry, and to set incoming messages to expect an appropriate retry. */ -int db__message_reconnect_reset_outgoing(struct mosquitto *context) +static int db__message_reconnect_reset_outgoing(struct mosquitto *context) { struct mosquitto_client_msg *msg, *tmp; @@ -821,7 +821,7 @@ int db__message_reconnect_reset_outgoing(struct mosquitto *context) /* Called on reconnect to set incoming messages to expect an appropriate retry. */ -int db__message_reconnect_reset_incoming(struct mosquitto *context) +static int db__message_reconnect_reset_incoming(struct mosquitto *context) { struct mosquitto_client_msg *msg, *tmp; @@ -975,63 +975,6 @@ int db__message_release_incoming(struct mosquitto *context, uint16_t mid) } } -int db__message_write_inflight_in(struct mosquitto *context) -{ - struct mosquitto_client_msg *tail, *tmp; - int rc; - - if(context->state != mosq_cs_active){ - return MOSQ_ERR_SUCCESS; - } - - DL_FOREACH_SAFE(context->msgs_in.inflight, tail, tmp){ - if(tail->store->message_expiry_time){ - if(db.now_real_s > tail->store->message_expiry_time){ - /* Message is expired, must not send. */ - db__message_remove(&context->msgs_in, tail); - if(tail->qos > 0){ - util__increment_receive_quota(context); - } - continue; - } - } - - switch(tail->state){ - case mosq_ms_send_pubrec: - rc = send__pubrec(context, tail->mid, 0, NULL); - if(!rc){ - tail->state = mosq_ms_wait_for_pubrel; - }else{ - return rc; - } - break; - - case mosq_ms_resend_pubcomp: - rc = send__pubcomp(context, tail->mid, NULL); - if(!rc){ - tail->state = mosq_ms_wait_for_pubrel; - }else{ - return rc; - } - break; - - case mosq_ms_invalid: - case mosq_ms_publish_qos0: - case mosq_ms_publish_qos1: - case mosq_ms_publish_qos2: - case mosq_ms_resend_pubrel: - case mosq_ms_wait_for_puback: - case mosq_ms_wait_for_pubrec: - case mosq_ms_wait_for_pubrel: - case mosq_ms_wait_for_pubcomp: - case mosq_ms_queued: - break; - } - } - return MOSQ_ERR_SUCCESS; -} - - static int db__message_write_inflight_out_single(struct mosquitto *context, struct mosquitto_client_msg *msg) { mosquitto_property *cmsg_props = NULL, *store_props = NULL; diff --git a/src/handle_connect.c b/src/handle_connect.c index b4cefad5..b031d200 100644 --- a/src/handle_connect.c +++ b/src/handle_connect.c @@ -83,7 +83,7 @@ static char *client_id_gen(uint16_t *idlen, const char *auto_id_prefix, uint16_t /* Remove any queued messages that are no longer allowed through ACL, * assuming a possible change of username. */ -void connection_check_acl(struct mosquitto *context, struct mosquitto_client_msg **head) +static void connection_check_acl(struct mosquitto *context, struct mosquitto_client_msg **head) { struct mosquitto_client_msg *msg_tail, *tmp; diff --git a/src/logging.c b/src/logging.c index 915ede23..cfac6a20 100644 --- a/src/logging.c +++ b/src/logging.c @@ -187,7 +187,7 @@ DltLogLevelType get_dlt_level(unsigned int priority) } #endif -int log__vprintf(unsigned int priority, const char *fmt, va_list va) +static int log__vprintf(unsigned int priority, const char *fmt, va_list va) { const char *topic; int syslog_priority; diff --git a/src/loop.c b/src/loop.c index 5044e7c8..dbee55a0 100644 --- a/src/loop.c +++ b/src/loop.c @@ -133,7 +133,7 @@ static void read_message_expiry_interval(mosquitto_property **proplist, uint32_t } } -void queue_plugin_msgs(void) +static void queue_plugin_msgs(void) { struct mosquitto_message_v5 *msg, *tmp; struct mosquitto *context; @@ -279,7 +279,7 @@ int mosquitto_main_loop(struct mosquitto__listener_sock *listensock, int listens void do_disconnect(struct mosquitto *context, int reason) { - char *id; + const char *id; #ifdef WITH_WEBSOCKETS bool is_duplicate = false; #endif diff --git a/src/mosquitto.c b/src/mosquitto.c index d3905ebe..1e5baec4 100644 --- a/src/mosquitto.c +++ b/src/mosquitto.c @@ -74,13 +74,6 @@ int allow_severity = LOG_INFO; int deny_severity = LOG_INFO; #endif -void handle_sigint(int signal); -void handle_sigusr1(int signal); -void handle_sigusr2(int signal); -#ifdef SIGHUP -void handle_sighup(int signal); -#endif - /* mosquitto shouldn't run as root. * This function will attempt to change to an unprivileged user and group if * running as root. The user is given in config->user. @@ -146,7 +139,7 @@ int drop_privileges(struct mosquitto__config *config) return MOSQ_ERR_SUCCESS; } -void mosquitto__daemonise(void) +static void mosquitto__daemonise(void) { #ifndef WIN32 char *err; @@ -208,7 +201,7 @@ void listeners__reload_all_certificates(void) } -int listeners__start_single_mqtt(struct mosquitto__listener *listener) +static int listeners__start_single_mqtt(struct mosquitto__listener *listener) { int i; struct mosquitto__listener_sock *listensock_new; @@ -275,7 +268,7 @@ void listeners__add_websockets(struct lws_context *ws_context, mosq_sock_t fd) } #endif -int listeners__add_local(const char *host, uint16_t port) +static int listeners__add_local(const char *host, uint16_t port) { struct mosquitto__listener *listeners; listeners = db.config->listeners; @@ -296,7 +289,7 @@ int listeners__add_local(const char *host, uint16_t port) return MOSQ_ERR_SUCCESS; } -int listeners__start_local_only(void) +static int listeners__start_local_only(void) { /* Attempt to open listeners bound to 127.0.0.1 and ::1 only */ int i; @@ -336,7 +329,7 @@ int listeners__start_local_only(void) } -int listeners__start(void) +static int listeners__start(void) { int i; @@ -380,7 +373,7 @@ int listeners__start(void) } -void listeners__stop(void) +static void listeners__stop(void) { int i; @@ -407,7 +400,7 @@ void listeners__stop(void) } -void signal__setup(void) +static void signal__setup(void) { signal(SIGINT, handle_sigint); signal(SIGTERM, handle_sigint); @@ -425,7 +418,7 @@ void signal__setup(void) } -int pid__write(void) +static int pid__write(void) { FILE *pid; diff --git a/src/mosquitto_broker_internal.h b/src/mosquitto_broker_internal.h index 6f6d48d2..c66126c8 100644 --- a/src/mosquitto_broker_internal.h +++ b/src/mosquitto_broker_internal.h @@ -819,6 +819,16 @@ void session_expiry__remove_all(void); void session_expiry__check(void); void session_expiry__send_all(void); +/* ============================================================ + * Signals + * ============================================================ */ +void handle_sigint(int signal); +void handle_sigusr1(int signal); +void handle_sigusr2(int signal); +#ifdef SIGHUP +void handle_sighup(int signal); +#endif + /* ============================================================ * Window service and signal related functions * ============================================================ */ @@ -855,4 +865,3 @@ void xtreport(void); #endif #endif - diff --git a/src/mux_epoll.c b/src/mux_epoll.c index 6b1b2e89..dd81b7d9 100644 --- a/src/mux_epoll.c +++ b/src/mux_epoll.c @@ -106,12 +106,6 @@ int mux_epoll__init(struct mosquitto__listener_sock *listensock, int listensock_ return MOSQ_ERR_SUCCESS; } -int mux_epoll__loop_setup(void) -{ - return MOSQ_ERR_SUCCESS; -} - - int mux_epoll__add_out(struct mosquitto *context) { struct epoll_event ev; diff --git a/src/net.c b/src/net.c index bbdb2708..cbcfc677 100644 --- a/src/net.c +++ b/src/net.c @@ -427,7 +427,7 @@ int net__tls_server_ctx(struct mosquitto__listener *listener) #endif -int net__load_crl_file(struct mosquitto__listener *listener) +static int net__load_crl_file(struct mosquitto__listener *listener) { #ifdef WITH_TLS X509_STORE *store; diff --git a/src/persist.h b/src/persist.h index 21c0e679..35081770 100644 --- a/src/persist.h +++ b/src/persist.h @@ -19,6 +19,8 @@ Contributors: #ifndef PERSIST_H #define PERSIST_H +#include "mosquitto_broker_internal.h" + #define MOSQ_DB_VERSION 6 /* DB read/write */ diff --git a/src/security.c b/src/security.c index 839ec31e..98b4d962 100644 --- a/src/security.c +++ b/src/security.c @@ -47,7 +47,7 @@ void LIB_ERROR(void) } -int security__load_v2(struct mosquitto__auth_plugin *plugin, struct mosquitto_auth_opt *auth_options, int auth_option_count, void *lib) +static int security__load_v2(struct mosquitto__auth_plugin *plugin, struct mosquitto_auth_opt *auth_options, int auth_option_count, void *lib) { int rc; @@ -121,7 +121,7 @@ int security__load_v2(struct mosquitto__auth_plugin *plugin, struct mosquitto_au } -int security__load_v3(struct mosquitto__auth_plugin *plugin, struct mosquitto_opt *auth_options, int auth_option_count, void *lib) +static int security__load_v3(struct mosquitto__auth_plugin *plugin, struct mosquitto_opt *auth_options, int auth_option_count, void *lib) { int rc; @@ -194,7 +194,7 @@ int security__load_v3(struct mosquitto__auth_plugin *plugin, struct mosquitto_op } -int security__load_v4(struct mosquitto__auth_plugin *plugin, struct mosquitto_opt *auth_options, int auth_option_count, void *lib) +static int security__load_v4(struct mosquitto__auth_plugin *plugin, struct mosquitto_opt *auth_options, int auth_option_count, void *lib) { int rc; diff --git a/src/security_default.c b/src/security_default.c index ec96e319..e659e7bf 100644 --- a/src/security_default.c +++ b/src/security_default.c @@ -202,7 +202,7 @@ int mosquitto_security_cleanup_default(bool reload) } -int add__acl(struct mosquitto__security_options *security_opts, const char *user, const char *topic, int access) +static int add__acl(struct mosquitto__security_options *security_opts, const char *user, const char *topic, int access) { struct mosquitto__acl_user *acl_user=NULL, *user_tail; struct mosquitto__acl *acl, *acl_tail; @@ -298,7 +298,7 @@ int add__acl(struct mosquitto__security_options *security_opts, const char *user return MOSQ_ERR_SUCCESS; } -int add__acl_pattern(struct mosquitto__security_options *security_opts, const char *topic, int access) +static int add__acl_pattern(struct mosquitto__security_options *security_opts, const char *topic, int access) { struct mosquitto__acl *acl, *acl_tail; char *local_topic; diff --git a/src/signals.c b/src/signals.c index 9938996f..82d911be 100644 --- a/src/signals.c +++ b/src/signals.c @@ -29,6 +29,8 @@ Contributors: #include #include +#include "mosquitto_broker_internal.h" + #ifdef WITH_PERSISTENCE extern bool flag_db_backup; #endif From a5d9986cbd7c6875a779cb28ff3b91cc5b29a373 Mon Sep 17 00:00:00 2001 From: Roger Light Date: Sun, 21 Mar 2021 22:50:48 +0000 Subject: [PATCH 21/41] More compiler warning fixes. --- client/client_shared.h | 7 +++++-- plugins/dynamic-security/Makefile | 2 +- plugins/dynamic-security/json_help.c | 1 + plugins/dynamic-security/plugin.c | 4 ++-- plugins/dynamic-security/rolelist.c | 4 ++-- plugins/dynamic-security/roles.c | 2 +- plugins/dynamic-security/sub_matches_sub.c | 2 ++ 7 files changed, 14 insertions(+), 8 deletions(-) diff --git a/client/client_shared.h b/client/client_shared.h index 156c7f68..49484ff6 100644 --- a/client/client_shared.h +++ b/client/client_shared.h @@ -27,6 +27,10 @@ Contributors: # include #endif +#ifndef __GNUC__ +#define __attribute__(attrib) +#endif + /* pub_client.c modes */ #define MSGMODE_NONE 0 #define MSGMODE_CMD 1 @@ -136,6 +140,5 @@ int client_connect(struct mosquitto *mosq, struct mosq_config *cfg); int cfg_parse_property(struct mosq_config *cfg, int argc, char *argv[], int *idx); -void err_printf(const struct mosq_config *cfg, const char *fmt, ...); - +void err_printf(const struct mosq_config *cfg, const char *fmt, ...) __attribute__((format(printf, 2, 3))); #endif diff --git a/plugins/dynamic-security/Makefile b/plugins/dynamic-security/Makefile index 9ef728b1..7ef77b7b 100644 --- a/plugins/dynamic-security/Makefile +++ b/plugins/dynamic-security/Makefile @@ -3,7 +3,7 @@ include ../../config.mk .PHONY : all binary check clean reallyclean test install uninstall PLUGIN_NAME=mosquitto_dynamic_security -LOCAL_CPPFLAGS=-I../../src/ +LOCAL_CPPFLAGS=-I../../src/ -DWITH_CJSON OBJS= \ acl.o \ diff --git a/plugins/dynamic-security/json_help.c b/plugins/dynamic-security/json_help.c index e0c8178b..5331d3f9 100644 --- a/plugins/dynamic-security/json_help.c +++ b/plugins/dynamic-security/json_help.c @@ -23,6 +23,7 @@ Contributors: #include #include +#include "json_help.h" #include "mosquitto.h" diff --git a/plugins/dynamic-security/plugin.c b/plugins/dynamic-security/plugin.c index d5a8cf06..27c3904d 100644 --- a/plugins/dynamic-security/plugin.c +++ b/plugins/dynamic-security/plugin.c @@ -131,7 +131,7 @@ static int dynsec_control_callback(int event, void *event_data, void *userdata) return MOSQ_ERR_SUCCESS; } -int dynsec__process_set_default_acl_access(cJSON *j_responses, struct mosquitto *context, cJSON *command, char *correlation_data) +static int dynsec__process_set_default_acl_access(cJSON *j_responses, struct mosquitto *context, cJSON *command, char *correlation_data) { cJSON *j_actions, *j_action, *j_acltype, *j_allow; bool allow; @@ -174,7 +174,7 @@ int dynsec__process_set_default_acl_access(cJSON *j_responses, struct mosquitto } -int dynsec__process_get_default_acl_access(cJSON *j_responses, struct mosquitto *context, cJSON *command, char *correlation_data) +static int dynsec__process_get_default_acl_access(cJSON *j_responses, struct mosquitto *context, cJSON *command, char *correlation_data) { cJSON *tree, *jtmp, *j_data, *j_acls, *j_acl; const char *admin_clientid, *admin_username; diff --git a/plugins/dynamic-security/rolelist.c b/plugins/dynamic-security/rolelist.c index a8c93a96..2bc1f163 100644 --- a/plugins/dynamic-security/rolelist.c +++ b/plugins/dynamic-security/rolelist.c @@ -51,7 +51,7 @@ static int rolelist_cmp(void *a, void *b) } -void dynsec_rolelist__free_item(struct dynsec__rolelist **base_rolelist, struct dynsec__rolelist *rolelist) +static void dynsec_rolelist__free_item(struct dynsec__rolelist **base_rolelist, struct dynsec__rolelist *rolelist) { HASH_DELETE(hh, *base_rolelist, rolelist); mosquitto_free(rolelist->rolename); @@ -67,7 +67,7 @@ void dynsec_rolelist__cleanup(struct dynsec__rolelist **base_rolelist) } } -int dynsec_rolelist__remove_role(struct dynsec__rolelist **base_rolelist, const struct dynsec__role *role) +static int dynsec_rolelist__remove_role(struct dynsec__rolelist **base_rolelist, const struct dynsec__role *role) { struct dynsec__rolelist *found_rolelist; diff --git a/plugins/dynamic-security/roles.c b/plugins/dynamic-security/roles.c index fb116770..4d5accfc 100644 --- a/plugins/dynamic-security/roles.c +++ b/plugins/dynamic-security/roles.c @@ -209,7 +209,7 @@ static int insert_acl_cmp(struct dynsec__acl *a, struct dynsec__acl *b) } -int dynsec_roles__acl_load(cJSON *j_acls, const char *key, struct dynsec__acl **acllist) +static int dynsec_roles__acl_load(cJSON *j_acls, const char *key, struct dynsec__acl **acllist) { cJSON *j_acl, *j_type, *jtmp; struct dynsec__acl *acl; diff --git a/plugins/dynamic-security/sub_matches_sub.c b/plugins/dynamic-security/sub_matches_sub.c index fb913902..5f5d55a6 100644 --- a/plugins/dynamic-security/sub_matches_sub.c +++ b/plugins/dynamic-security/sub_matches_sub.c @@ -21,6 +21,8 @@ Contributors: #include #include +#include "dynamic_security.h" + static char *strtok_hier(char *str, char **saveptr) { char *c; From 91f34e084f39ba28a371c6aedcfadcfa88443759 Mon Sep 17 00:00:00 2001 From: Abilio Marques Date: Mon, 22 Mar 2021 07:46:10 +0100 Subject: [PATCH 22/41] fix duplication of messages during connect Signed-off-by: Abilio Marques --- ChangeLog.txt | 2 ++ lib/connect.c | 2 +- lib/handle_connack.c | 2 +- lib/messages_mosq.c | 20 +++++++++++--------- lib/messages_mosq.h | 2 +- 5 files changed, 16 insertions(+), 12 deletions(-) diff --git a/ChangeLog.txt b/ChangeLog.txt index 1701c5e4..880ef88a 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1787,6 +1787,8 @@ Client library: - Add support for MQTT v3.1.1. - Don't quit mosquitto_loop_forever() if broker not available on first connect. Closes bug #453293, but requires more work. +- Don't reset queued messages state on CONNACK. Fixes bug with duplicate + messages on connection. 1.3.5 - 20141008 diff --git a/lib/connect.c b/lib/connect.c index 196fde47..c668bf3e 100644 --- a/lib/connect.c +++ b/lib/connect.c @@ -189,7 +189,7 @@ static int mosquitto__reconnect(struct mosquitto *mosq, bool blocking) packet__cleanup_all(mosq); - message__reconnect_reset(mosq); + message__reconnect_reset(mosq, false); if(mosq->sock != INVALID_SOCKET){ net__socket_close(mosq); //close socket diff --git a/lib/handle_connack.c b/lib/handle_connack.c index 6dca1395..5380243d 100644 --- a/lib/handle_connack.c +++ b/lib/handle_connack.c @@ -106,7 +106,7 @@ int handle__connack(struct mosquitto *mosq) mosquitto_property_read_int32(properties, MQTT_PROP_MAXIMUM_PACKET_SIZE, &mosq->maximum_packet_size, false); mosq->msgs_out.inflight_quota = mosq->msgs_out.inflight_maximum; - message__reconnect_reset(mosq); + message__reconnect_reset(mosq, true); connack_callback(mosq, reason_code, connect_flags, properties); mosquitto_property_free_all(&properties); diff --git a/lib/messages_mosq.c b/lib/messages_mosq.c index ff28a915..8773c968 100644 --- a/lib/messages_mosq.c +++ b/lib/messages_mosq.c @@ -137,7 +137,7 @@ int message__queue(struct mosquitto *mosq, struct mosquitto_message_all *message return message__release_to_inflight(mosq, dir); } -void message__reconnect_reset(struct mosquitto *mosq) +void message__reconnect_reset(struct mosquitto *mosq, bool update_quota_only) { struct mosquitto_message_all *message, *tmp; assert(mosq); @@ -169,15 +169,17 @@ void message__reconnect_reset(struct mosquitto *mosq) message->timestamp = 0; if(mosq->msgs_out.inflight_quota != 0){ util__decrement_send_quota(mosq); - if(message->msg.qos == 1){ - message->state = mosq_ms_publish_qos1; - }else if(message->msg.qos == 2){ - if(message->state == mosq_ms_wait_for_pubrec){ - message->state = mosq_ms_publish_qos2; - }else if(message->state == mosq_ms_wait_for_pubcomp){ - message->state = mosq_ms_resend_pubrel; + if (update_quota_only == false){ + if(message->msg.qos == 1){ + message->state = mosq_ms_publish_qos1; + }else if(message->msg.qos == 2){ + if(message->state == mosq_ms_wait_for_pubrec){ + message->state = mosq_ms_publish_qos2; + }else if(message->state == mosq_ms_wait_for_pubcomp){ + message->state = mosq_ms_resend_pubrel; + } + /* Should be able to preserve state. */ } - /* Should be able to preserve state. */ } }else{ message->state = mosq_ms_invalid; diff --git a/lib/messages_mosq.h b/lib/messages_mosq.h index 5689b49e..ee5ba5cd 100644 --- a/lib/messages_mosq.h +++ b/lib/messages_mosq.h @@ -25,7 +25,7 @@ void message__cleanup_all(struct mosquitto *mosq); void message__cleanup(struct mosquitto_message_all **message); int message__delete(struct mosquitto *mosq, uint16_t mid, enum mosquitto_msg_direction dir, int qos); int message__queue(struct mosquitto *mosq, struct mosquitto_message_all *message, enum mosquitto_msg_direction dir); -void message__reconnect_reset(struct mosquitto *mosq); +void message__reconnect_reset(struct mosquitto *mosq, bool update_quota_only); int message__release_to_inflight(struct mosquitto *mosq, enum mosquitto_msg_direction dir); int message__remove(struct mosquitto *mosq, uint16_t mid, enum mosquitto_msg_direction dir, struct mosquitto_message_all **message, int qos); void message__retry_check(struct mosquitto *mosq); From dd4a64b049f21cacc6fdb8988f8e515a136a31cd Mon Sep 17 00:00:00 2001 From: Abilio Marques Date: Mon, 22 Mar 2021 08:15:47 +0100 Subject: [PATCH 23/41] fully empty socketpairR on interruptible_sleep Signed-off-by: Abilio Marques --- lib/loop.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/lib/loop.c b/lib/loop.c index 046dde0b..57252f33 100644 --- a/lib/loop.c +++ b/lib/loop.c @@ -204,10 +204,9 @@ static int interruptible_sleep(struct mosquitto *mosq, time_t reconnect_delay) int maxfd = 0; #ifndef WIN32 - if(read(mosq->sockpairR, &pairbuf, 1) == 0){ - } + while(read(mosq->sockpairR, &pairbuf, 1) > 0); #else - recv(mosq->sockpairR, &pairbuf, 1, 0); + while(recv(mosq->sockpairR, &pairbuf, 1, 0) > 0); #endif local_timeout.tv_sec = reconnect_delay; From 71366fd5698e5aacb779d3fba87f9cfed662e86a Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Tue, 23 Mar 2021 21:49:47 +0000 Subject: [PATCH 24/41] Add mosquitto_ctrl options --- www/pages/documentation/dynamic-security.md | 82 ++++++++++++++++++++- 1 file changed, 81 insertions(+), 1 deletion(-) diff --git a/www/pages/documentation/dynamic-security.md b/www/pages/documentation/dynamic-security.md index 922c38d5..fad933da 100644 --- a/www/pages/documentation/dynamic-security.md +++ b/www/pages/documentation/dynamic-security.md @@ -360,7 +360,87 @@ mosquitto_ctrl -u admin -h localhost dynsec ... It is possible to provide the admin password on the command line, but this is not recommended. -See **FIXME** for the full list of options available for `mosquitto_ctrl`. +### mosquitto_ctrl options + +* `-A address` : Bind the outgoing connection to a local ip address/hostname. + Use this argument if you need to restrict network communication to a + particular interface. +* `--cafile path-to-ca.crt` : Define the path to a file containing PEM encoded + CA certificates that are trusted. Used to enable SSL communication. See also + `--capath` +* `--capath` : Define the path to a directory containing PEM encoded CA + certificates that are trusted. Used to enable SSL communication. For + `--capath` to work correctly, the certificate files must have ".crt" as the + file ending and you must run `openssl rehash ` each time you + add/remove a certificate. See also `--cafile`. +* `--cert path-to-client.crt` : Define the path to a file containing a PEM + encoded certificate for this client, if required by the server. See also + `--key`. +* `--ciphers` : An openssl compatible list of TLS ciphers to support in the + client. See ciphers(1) for more information. +* `-d` : Enable debug messages. +* `--help` : Display usage information. +* `-h hostname` : Specify the host to connect to. Defaults to localhost. +* `-i client-id` : The id to use for this client. If not given, a client id + will be generated depending on the MQTT version being used. For v3.1.1/v3.1, + the client generates a client id in the format mosq-XXXXXXXXXXXXXXXXXX, where + the X are replaced with random alphanumeric characters. For v5.0, the client + sends a zero length client id, and the server will generate a client id for + the client. +* `--insecure` : When using certificate based encryption, this option disables + verification of the server hostname in the server certificate. This can be + useful when testing initial server configurations but makes it possible for a + malicious third party to impersonate your server through DNS spoofing, for + example. Use this option in testing only. If you need to resort to using this + option in a production environment, your setup is at fault and there is no + point using encryption. +* `--key path-to-client.key` : Define the path to a file containing a PEM + encoded private key for this client, if required by the server. See also + `--cert`. +* `-L url` : Specify specify user, password, hostname, port and topic at once + as a URL. The URL must be in the form: + `mqtt(s)://[username[:password]@]host[:port]`. If the scheme is mqtt:// then + the port defaults to 1883. If the scheme is mqtts:// then the port defaults + to 8883. +* `--nodelay` : Disable Nagle's algorithm for the socket. This means that + latency of sent messages is reduced, which is particularly noticable for + small, reasonably infrequent messages. Using this option may result in more + packets being sent than would normally be necessary. +* `-p port` : Connect to the port specified. If not given, the default of 1883 + for plain MQTT or 8883 for MQTT over TLS will be used. +* `-P password` : Provide a password to be used for authenticating with the + broker. Using this argument without also specifying a username is invalid + when using MQTT v3.1 or v3.1.1. See also the `-u` option. +* `--proxy proxy-url` : Specify a SOCKS5 proxy to connect through. "None" and + "username" authentication types are supported. The socks-url must be of the + form `socks5h://[username[:password]@]host[:port]`. The protocol prefix + socks5h means that hostnames are resolved by the proxy. The symbols %25, %3A + and %40 are URL decoded into %, : and @ respectively, if present in the + username or password. If username is not given, then no authentication is + attempted. If the port is not given, then the default of 1080 is used. +* `--psk key` : Provide the hexadecimal (no leading 0x) pre-shared-key matching + the one used on the broker to use TLS-PSK encryption support. + `--psk-identity` must also be provided to enable TLS-PSK. +* `--psk-identity identify` : The client identity to use with TLS-PSK support. + This may be used instead of a username if the broker is configured to do so. +* `-q qos` : Specify the quality of service to use for messages, from 0, 1 and + 2. Defaults to 1. +* `--quiet` : If this argument is given, no runtime errors will be printed. + This excludes any error messages given in case of invalid user input (e.g. + using `-p` without a port). +* `--tls-version version` : Choose which TLS protocol version to use when + communicating with the broker. Valid options are tlsv1.3, tlsv1.2 and + tlsv1.1. The default value is tlsv1.2. Must match the protocol version used + by the broker. +* `-u username` : Provide a username to be used for authenticating with the + broker. See also the `-P` argument. +* `--unix path` : Connect to a broker through a local unix domain socket + instead of a TCP socket. This is a replacement for `-h` and `-L`. For + example: `mosquitto_ctrl --unix /tmp/mosquitto.sock ...`. +* `-V protocol-version` : Specify which version of the MQTT protocol should be + used when connecting to the remote broker. Can be `5`, `311`, `31`, or the + more verbose `mqttv5`, `mqttv311`, or `mqttv31`. Defaults to `311`. + ## Configuring default access From e32bd8fb929c33b19e63b621416b26fdecab798a Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Thu, 25 Mar 2021 15:56:27 +0000 Subject: [PATCH 25/41] Add info on config-less docker to the generic image readme. --- docker/generic/README.md | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/docker/generic/README.md b/docker/generic/README.md index 4e0279c7..d2c20643 100644 --- a/docker/generic/README.md +++ b/docker/generic/README.md @@ -9,6 +9,19 @@ Three docker volumes have been created in the image to be used for configuration /mosquitto/log ``` +## Running without a configuration file +Mosquitto 2.0 requires you to configure listeners and authentication before it +will allow connections from anything other than the loopback interface. In the +context of a container, this means you would normally need to provide a +configuration file with your settings. + +If you wish to run mosquitto without any authentication, and without setting +any other configuration options, you can do so by using a configuration +provided in the container for this purpose: +``` +docker run -it -p 1883:1883 eclipse-mosquitto: mosquitto -c /mosquitto-no-auth.conf +``` + ## Configuration When creating a container from the image, the default configuration values are used. To use a custom configuration file, mount a **local** configuration file to `/mosquitto/config/mosquitto.conf` From 27ca78ba60fce693f94ead70088acc5e58faa14a Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Thu, 25 Mar 2021 16:20:22 +0000 Subject: [PATCH 26/41] Bring generic Dockerfile in line with 2.0-openssl. --- docker/generic/Dockerfile | 164 ++++++++++++++++++++++++-------------- 1 file changed, 102 insertions(+), 62 deletions(-) diff --git a/docker/generic/Dockerfile b/docker/generic/Dockerfile index bdda597b..5a7e8e42 100644 --- a/docker/generic/Dockerfile +++ b/docker/generic/Dockerfile @@ -1,74 +1,114 @@ -FROM alpine:edge AS build +FROM alpine:3.12 + +LABEL maintainer="Roger Light " \ + description="Eclipse Mosquitto MQTT Broker" -# A released dist version, like "1.2.3" ARG VERSION RUN test -n "${VERSION}" -RUN apk --no-cache add \ - build-base \ - c-ares-dev \ - ca-certificates \ - cjson-dev \ - curl \ - libwebsockets-dev \ - libxslt \ - openssl-dev \ - python2 \ - util-linux-dev +ENV \ + GPG_KEYS=A0D6EEA1DCAE49A635A3B2F0779B22DFB3E717B7 \ + LWS_VERSION=2.4.2 \ + LWS_SHA256=73012d7fcf428dedccc816e83a63a01462e27819d5537b8e0d0c7264bfacfad6 \ + CJSON_VERSION=1.7.14 \ + CJSON_SHA256=fb50a663eefdc76bafa80c82bc045af13b1363e8f45cec8b442007aef6a41343 -# This build procedure is based on: -# https://github.com/alpinelinux/aports/blob/master/main/mosquitto/APKBUILD -# -# If this step fails, double check the version build-arg and make sure its -# a valid published tarball at https://mosquitto.org/files/source/ -RUN mkdir -p /build /install && \ - curl -SL https://mosquitto.org/files/source/mosquitto-${VERSION}.tar.gz \ - | tar --strip=1 -xzC /build && \ - make -C /build \ - WITH_MEMORY_TRACKING=no \ - WITH_WEBSOCKETS=yes \ - WITH_SRV=yes \ - WITH_TLS_PSK=no \ - WITH_ADNS=no \ - prefix=/usr \ - binary && \ - make -C /build \ - prefix=/usr \ - DESTDIR="/install" \ - install && \ - mv /install/etc/mosquitto/mosquitto.conf.example /install/etc/mosquitto/mosquitto.conf && \ - sed -i -e 's/#log_dest stderr/log_dest syslog/' /install/etc/mosquitto/mosquitto.conf - - -# Single-layer image for the mosquitto distribution -FROM alpine:latest -LABEL maintainer="Jonathan Hanson " \ - description="Eclipse Mosquitto MQTT Broker" - -# Install the run-time dependencies -RUN apk --no-cache add \ - busybox \ - ca-certificates \ - cjson \ - openssl \ - libuuid \ - libwebsockets \ - musl - -# Copy over the built install from the earlier image layer -COPY --from=build /install / - -# Set up the mosquitto directories and the mosquitto user -RUN addgroup -S mosquitto 2>/dev/null && \ - adduser -S -D -H -h /var/empty -s /sbin/nologin -G mosquitto -g mosquitto mosquitto 2>/dev/null && \ +RUN set -x && \ + apk --no-cache add --virtual build-deps \ + build-base \ + cmake \ + gnupg \ + openssl-dev \ + util-linux-dev && \ + wget https://github.com/warmcat/libwebsockets/archive/v${LWS_VERSION}.tar.gz -O /tmp/lws.tar.gz && \ + echo "$LWS_SHA256 /tmp/lws.tar.gz" | sha256sum -c - && \ + mkdir -p /build/lws && \ + tar --strip=1 -xf /tmp/lws.tar.gz -C /build/lws && \ + rm /tmp/lws.tar.gz && \ + cd /build/lws && \ + cmake . \ + -DCMAKE_BUILD_TYPE=MinSizeRel \ + -DCMAKE_INSTALL_PREFIX=/usr \ + -DLWS_IPV6=ON \ + -DLWS_WITHOUT_BUILTIN_GETIFADDRS=ON \ + -DLWS_WITHOUT_CLIENT=ON \ + -DLWS_WITHOUT_EXTENSIONS=ON \ + -DLWS_WITHOUT_TESTAPPS=ON \ + -DLWS_WITH_SHARED=OFF \ + -DLWS_WITH_ZIP_FOPS=OFF \ + -DLWS_WITH_ZLIB=OFF && \ + make -j "$(nproc)" && \ + rm -rf /root/.cmake && \ + wget https://github.com/DaveGamble/cJSON/archive/v${CJSON_VERSION}.tar.gz -O /tmp/cjson.tar.gz && \ + echo "$CJSON_SHA256 /tmp/cjson.tar.gz" | sha256sum -c - && \ + mkdir -p /build/cjson && \ + tar --strip=1 -xf /tmp/cjson.tar.gz -C /build/cjson && \ + rm /tmp/cjson.tar.gz && \ + cd /build/cjson && \ + cmake . \ + -DCMAKE_BUILD_TYPE=MinSizeRel \ + -DBUILD_SHARED_AND_STATIC_LIBS=OFF \ + -DBUILD_SHARED_LIBS=OFF \ + -DCJSON_BUILD_SHARED_LIBS=OFF \ + -DCJSON_OVERRIDE_BUILD_SHARED_LIBS=OFF \ + -DCMAKE_INSTALL_PREFIX=/usr && \ + make -j "$(nproc)" && \ + rm -rf /root/.cmake && \ + wget https://mosquitto.org/files/source/mosquitto-${VERSION}.tar.gz -O /tmp/mosq.tar.gz && \ + wget https://mosquitto.org/files/source/mosquitto-${VERSION}.tar.gz.asc -O /tmp/mosq.tar.gz.asc && \ + export GNUPGHOME="$(mktemp -d)" && \ + found=''; \ + for server in \ + ha.pool.sks-keyservers.net \ + hkp://keyserver.ubuntu.com:80 \ + hkp://p80.pool.sks-keyservers.net:80 \ + pgp.mit.edu \ + ; do \ + echo "Fetching GPG key $GPG_KEYS from $server"; \ + gpg --keyserver "$server" --keyserver-options timeout=10 --recv-keys "$GPG_KEYS" && found=yes && break; \ + done; \ + test -z "$found" && echo >&2 "error: failed to fetch GPG key $GPG_KEYS" && exit 1; \ + gpg --batch --verify /tmp/mosq.tar.gz.asc /tmp/mosq.tar.gz && \ + gpgconf --kill all && \ + rm -rf "$GNUPGHOME" /tmp/mosq.tar.gz.asc && \ + mkdir -p /build/mosq && \ + tar --strip=1 -xf /tmp/mosq.tar.gz -C /build/mosq && \ + rm /tmp/mosq.tar.gz && \ + make -C /build/mosq -j "$(nproc)" \ + CFLAGS="-Wall -O2 -I/build/lws/include -I/build" \ + LDFLAGS="-L/build/lws/lib -L/build/cjson" \ + WITH_ADNS=no \ + WITH_DOCS=no \ + WITH_SHARED_LIBRARIES=yes \ + WITH_SRV=no \ + WITH_STRIP=yes \ + WITH_TLS_PSK=no \ + WITH_WEBSOCKETS=yes \ + prefix=/usr \ + binary && \ + addgroup -S -g 1883 mosquitto 2>/dev/null && \ + adduser -S -u 1883 -D -H -h /var/empty -s /sbin/nologin -G mosquitto -g mosquitto mosquitto 2>/dev/null && \ mkdir -p /mosquitto/config /mosquitto/data /mosquitto/log && \ - cp /etc/mosquitto/mosquitto.conf /mosquitto/config && \ - chown -R mosquitto:mosquitto /mosquitto + install -d /usr/sbin/ && \ + install -s -m755 /build/mosq/client/mosquitto_pub /usr/bin/mosquitto_pub && \ + install -s -m755 /build/mosq/client/mosquitto_rr /usr/bin/mosquitto_rr && \ + install -s -m755 /build/mosq/client/mosquitto_sub /usr/bin/mosquitto_sub && \ + install -s -m644 /build/mosq/lib/libmosquitto.so.1 /usr/lib/libmosquitto.so.1 && \ + install -s -m755 /build/mosq/src/mosquitto /usr/sbin/mosquitto && \ + install -s -m755 /build/mosq/apps/mosquitto_ctrl/mosquitto_ctrl /usr/bin/mosquitto_ctrl && \ + install -s -m755 /build/mosq/apps/mosquitto_passwd/mosquitto_passwd /usr/bin/mosquitto_passwd && \ + install -s -m755 /build/mosq/plugins/dynamic-security/mosquitto_dynamic_security.so /usr/lib/mosquitto_dynamic_security.so && \ + install -m644 /build/mosq/mosquitto.conf /mosquitto/config/mosquitto.conf && \ + chown -R mosquitto:mosquitto /mosquitto && \ + apk --no-cache add \ + ca-certificates && \ + apk del build-deps && \ + rm -rf /build -VOLUME ["/mosquitto/config", "/mosquitto/data", "/mosquitto/log"] +VOLUME ["/mosquitto/data", "/mosquitto/log"] # Set up the entry point script and default command -COPY docker-entrypoint.sh / +COPY docker-entrypoint.sh mosquitto-no-auth.conf / EXPOSE 1883 ENTRYPOINT ["/docker-entrypoint.sh"] CMD ["/usr/sbin/mosquitto", "-c", "/mosquitto/config/mosquitto.conf"] From 20e154c1dd970da7a0135164a0c68fb9e8bc19d9 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Thu, 25 Mar 2021 20:41:50 +0000 Subject: [PATCH 27/41] Add missing config file. --- docker/generic/mosquitto-no-auth.conf | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 docker/generic/mosquitto-no-auth.conf diff --git a/docker/generic/mosquitto-no-auth.conf b/docker/generic/mosquitto-no-auth.conf new file mode 100644 index 00000000..40dd92b9 --- /dev/null +++ b/docker/generic/mosquitto-no-auth.conf @@ -0,0 +1,5 @@ +# This is a Mosquitto configuration file that creates a listener on port 1883 +# that allows unauthenticated access. + +listener 1883 +allow_anonymous true From 3ac2c3ee0956104687212fbab8fbfcbf6b1addb0 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Fri, 26 Mar 2021 10:38:57 +0000 Subject: [PATCH 28/41] Improve mosquitto_ctrl documentation. --- apps/mosquitto_ctrl/dynsec.c | 2 ++ apps/mosquitto_ctrl/mosquitto_ctrl.c | 3 +- man/mosquitto_ctrl.1.xml | 22 +++++++++++-- www/pages/documentation/dynamic-security.md | 36 +++++++++++++++++++-- 4 files changed, 57 insertions(+), 6 deletions(-) diff --git a/apps/mosquitto_ctrl/dynsec.c b/apps/mosquitto_ctrl/dynsec.c index c906cb2c..8e3d7250 100644 --- a/apps/mosquitto_ctrl/dynsec.c +++ b/apps/mosquitto_ctrl/dynsec.c @@ -79,6 +79,8 @@ void dynsec__print_usage(void) printf("acltype: publishClientSend|publishClientReceive\n"); printf(" |subscribeLiteral|subscribePattern\n"); printf(" |unsubscribeLiteral|unsubscribePattern\n"); + printf("\nFor more information see:\n"); + printf(" https://mosquitto.org/documentation/dynamic-security/\n\n"); } cJSON *cJSON_AddIntToObject(cJSON * const object, const char * const name, int number) diff --git a/apps/mosquitto_ctrl/mosquitto_ctrl.c b/apps/mosquitto_ctrl/mosquitto_ctrl.c index b4433988..aa706a61 100644 --- a/apps/mosquitto_ctrl/mosquitto_ctrl.c +++ b/apps/mosquitto_ctrl/mosquitto_ctrl.c @@ -43,7 +43,8 @@ static void print_usage(void) printf("\nGeneral usage: mosquitto_ctrl \n"); printf("For module specific help use: mosquitto_ctrl help\n"); printf("\nModules available: dynsec\n"); - printf("\nSee https://mosquitto.org/man/mosquitto_ctrl-1.html for more information.\n\n"); + printf("\nFor more information see:\n"); + printf(" https://mosquitto.org/man/mosquitto_ctrl-1.html\n\n"); } diff --git a/man/mosquitto_ctrl.1.xml b/man/mosquitto_ctrl.1.xml index 1f1f29f2..e86180d9 100644 --- a/man/mosquitto_ctrl.1.xml +++ b/man/mosquitto_ctrl.1.xml @@ -17,7 +17,7 @@ mosquitto_ctrl - connection-options + connection-options | -o config-file module-name module-command command-options @@ -132,7 +132,11 @@ The options below may be given on the command line, but may also be placed in a config file located at or - with one pair of + . + The config file may be specified manually with the + + option. + The config file should have one pair of per line. The values in the config file will be used as defaults and can be overridden by using the command line. The exceptions to @@ -320,6 +324,20 @@ being sent than would normally be necessary. + + config-file + + Provide a path to a config file to load options from. The config file should have one pair of + + per line. The values in the config file will be used as defaults + and can be overridden by using the command line. The exceptions to + this are the message type options, of which only one can be + specified. Note also that currently some options cannot be negated, + e.g. . Config file lines that have a + as the first character are treated as comments + and not processed any further. + + diff --git a/www/pages/documentation/dynamic-security.md b/www/pages/documentation/dynamic-security.md index fad933da..331c2dbf 100644 --- a/www/pages/documentation/dynamic-security.md +++ b/www/pages/documentation/dynamic-security.md @@ -343,7 +343,9 @@ application. The initial configuration is the only time that `mosquitto_ctrl` does not connect to a broker to carry out the configuration. All other commands require a connection to a broker, and hence a username, password, and whatever else is -required for that particular connection. +required for that particular connection. It is strongly recommended that your +broker connection uses encryption so that your configuration, including new +passwords, is not transmitted in plain text. The connection options must be given before the `dynsec` part of the command line: @@ -357,8 +359,36 @@ For example: mosquitto_ctrl -u admin -h localhost dynsec ... ``` -It is possible to provide the admin password on the command line, but this is -not recommended. +It is possible to provide the admin password on the command line using `-P +password`, but this is not recommended. If you do not provide a password, +mosquitto_ctrl will ask you to enter the password when it is needed. + +### Using an options file + +For convenience, mosquitto_ctrl can load an options file which contains a list +of options it should use. This means you can set the encryption options, host, +admin username and any other options once and not have to add them to the +command line every time. + +mosquitto_ctrl will try to load a configuration file from a default location. +For Windows this is at `%USER_PROFILE%\mosquitto_ctrl.conf`. For other systems, +it will try `$XDG_CONFIG_HOME/mosquitto_ctrl.conf` or +`$HOME/.config/mosquitto_ctrl.conf`. + +You may override this behaviour by manually specifying an options file with +`-o `. + +The options file should contain a list of options, one per line, exactly as +they would be provided on the command line. For example: + +``` +--cafile /path/to/my/CA.crt +--certfile /path/to/my/client.crt +--keyfile /path/to/my/client.key +-u admin +-h mosquitto.example.com + +``` ### mosquitto_ctrl options From 7d214a445d1d7b06f56ca0e1e994d5db12b14d1f Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Fri, 26 Mar 2021 11:06:57 +0000 Subject: [PATCH 29/41] Fix TLS-PSK mode not working with port 8883. Closes #2152. Thanks to jetpax. --- ChangeLog.txt | 1 + client/client_shared.c | 15 ++++++++------- 2 files changed, 9 insertions(+), 7 deletions(-) diff --git a/ChangeLog.txt b/ChangeLog.txt index 880ef88a..8309cf46 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -8,6 +8,7 @@ Broker: Clients: - Set `receive-maximum` to not exceed the `-C` message count in mosquitto_sub and mosquitto_rr, to avoid potentially lost messages. Closes #2134. +- Fix TLS-PSK mode not working with port 8883. Closes #2152. Build: - A variety of minor build related fixes, like functions not having previous diff --git a/client/client_shared.c b/client/client_shared.c index f60b98be..97ee5660 100644 --- a/client/client_shared.c +++ b/client/client_shared.c @@ -1263,6 +1263,14 @@ int client_opts_set(struct mosquitto *mosq, struct mosq_config *cfg) mosquitto_lib_cleanup(); return 1; } +# ifdef FINAL_WITH_TLS_PSK + }else if(cfg->psk){ + if(mosquitto_tls_psk_set(mosq, cfg->psk, cfg->psk_identity, NULL)){ + err_printf(cfg, "Error: Problem setting TLS-PSK options.\n"); + mosquitto_lib_cleanup(); + return 1; + } +# endif }else if(cfg->port == 8883){ mosquitto_int_option(mosq, MOSQ_OPT_TLS_USE_OS_CERTS, 1); } @@ -1295,13 +1303,6 @@ int client_opts_set(struct mosquitto *mosq, struct mosq_config *cfg) mosquitto_lib_cleanup(); return 1; } -# ifdef FINAL_WITH_TLS_PSK - if(cfg->psk && mosquitto_tls_psk_set(mosq, cfg->psk, cfg->psk_identity, NULL)){ - err_printf(cfg, "Error: Problem setting TLS-PSK options.\n"); - mosquitto_lib_cleanup(); - return 1; - } -# endif if((cfg->tls_version || cfg->ciphers) && mosquitto_tls_opts_set(mosq, 1, cfg->tls_version, cfg->ciphers)){ err_printf(cfg, "Error: Problem setting TLS options, check the options are valid.\n"); mosquitto_lib_cleanup(); From 4ee03f21e34bf61dd517432b0551ef607265efda Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Mon, 29 Mar 2021 17:07:40 +0100 Subject: [PATCH 30/41] Guard against missing UNUSED. --- apps/db_dump/stubs.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/apps/db_dump/stubs.c b/apps/db_dump/stubs.c index 8e233871..42a14291 100644 --- a/apps/db_dump/stubs.c +++ b/apps/db_dump/stubs.c @@ -6,6 +6,10 @@ #include "mosquitto_internal.h" #include "util_mosq.h" +#ifndef UNUSED +# define UNUSED(A) (void)(A) +#endif + struct mosquitto *context__init(mosq_sock_t sock) { UNUSED(sock); From 117e59b7cf61d9073bb3b4cd8e22217ba0cf889e Mon Sep 17 00:00:00 2001 From: Roger Light Date: Thu, 1 Apr 2021 21:53:13 +0100 Subject: [PATCH 31/41] Fix CMake cross compile builds not finding opensslconf.h. Closes #2160. Thanks to Ozaq. --- ChangeLog.txt | 1 + plugins/auth-by-ip/CMakeLists.txt | 2 +- plugins/message-timestamp/CMakeLists.txt | 2 +- plugins/payload-modification/CMakeLists.txt | 2 +- 4 files changed, 4 insertions(+), 3 deletions(-) diff --git a/ChangeLog.txt b/ChangeLog.txt index 8309cf46..e31fbbb3 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -13,6 +13,7 @@ Clients: Build: - A variety of minor build related fixes, like functions not having previous declarations. +- Fix CMake cross compile builds not finding opensslconf.h. Closes #2160. 2.0.9 - 2021-03-11 diff --git a/plugins/auth-by-ip/CMakeLists.txt b/plugins/auth-by-ip/CMakeLists.txt index ce856715..45260bd5 100644 --- a/plugins/auth-by-ip/CMakeLists.txt +++ b/plugins/auth-by-ip/CMakeLists.txt @@ -1,5 +1,5 @@ include_directories(${mosquitto_SOURCE_DIR} ${mosquitto_SOURCE_DIR}/include - ${STDBOOL_H_PATH} ${STDINT_H_PATH}) + ${OPENSSL_INCLUDE_DIR} ${STDBOOL_H_PATH} ${STDINT_H_PATH}) add_library(mosquitto_auth_by_ip SHARED mosquitto_auth_by_ip.c) set_target_properties(mosquitto_auth_by_ip PROPERTIES diff --git a/plugins/message-timestamp/CMakeLists.txt b/plugins/message-timestamp/CMakeLists.txt index 5949a75f..e53a4bc0 100644 --- a/plugins/message-timestamp/CMakeLists.txt +++ b/plugins/message-timestamp/CMakeLists.txt @@ -1,5 +1,5 @@ include_directories(${mosquitto_SOURCE_DIR} ${mosquitto_SOURCE_DIR}/include - ${STDBOOL_H_PATH} ${STDINT_H_PATH}) + ${OPENSSL_INCLUDE_DIR} ${STDBOOL_H_PATH} ${STDINT_H_PATH}) add_library(mosquitto_message_timestamp SHARED mosquitto_message_timestamp.c) set_target_properties(mosquitto_message_timestamp PROPERTIES diff --git a/plugins/payload-modification/CMakeLists.txt b/plugins/payload-modification/CMakeLists.txt index 39878efc..a4492911 100644 --- a/plugins/payload-modification/CMakeLists.txt +++ b/plugins/payload-modification/CMakeLists.txt @@ -1,5 +1,5 @@ include_directories(${mosquitto_SOURCE_DIR} ${mosquitto_SOURCE_DIR}/include - ${STDBOOL_H_PATH} ${STDINT_H_PATH}) + ${OPENSSL_INCLUDE_DIR} ${STDBOOL_H_PATH} ${STDINT_H_PATH}) link_directories(${mosquitto_SOURCE_DIR}) add_library(mosquitto_payload_modification SHARED mosquitto_payload_modification.c) From 6ebbb4d654c02e42a07a2a2a1939711ec6efabe9 Mon Sep 17 00:00:00 2001 From: Roger Light Date: Fri, 2 Apr 2021 11:02:13 +0100 Subject: [PATCH 32/41] Fix possible socket leak. This would occur if a client was using `mosquitto_loop_start()`, then if the connection failed due to the remote server being inaccessible they called `mosquitto_loop_stop(, true)` and recreated the mosquitto object. See: https://www.eclipse.org/forums/index.php?t=rview&goto=1839865#msg_1839865 --- ChangeLog.txt | 6 ++++++ lib/net_mosq.c | 5 +---- 2 files changed, 7 insertions(+), 4 deletions(-) diff --git a/ChangeLog.txt b/ChangeLog.txt index e31fbbb3..27d3c73d 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -10,6 +10,12 @@ Clients: and mosquitto_rr, to avoid potentially lost messages. Closes #2134. - Fix TLS-PSK mode not working with port 8883. Closes #2152. +Client library: +- Fix possible socket leak. This would occur if a client was using + `mosquitto_loop_start()`, then if the connection failed due to the remote + server being inaccessible they called `mosquitto_loop_stop(, true)` and + recreated the mosquitto object. + Build: - A variety of minor build related fixes, like functions not having previous declarations. diff --git a/lib/net_mosq.c b/lib/net_mosq.c index d42d83a7..16d0e8c9 100644 --- a/lib/net_mosq.c +++ b/lib/net_mosq.c @@ -917,16 +917,13 @@ int net__socket_connect_step3(struct mosquitto *mosq, const char *host) /* Create a socket and connect it to 'ip' on port 'port'. */ int net__socket_connect(struct mosquitto *mosq, const char *host, uint16_t port, const char *bind_address, bool blocking) { - mosq_sock_t sock = INVALID_SOCKET; int rc, rc2; if(!mosq || !host) return MOSQ_ERR_INVAL; - rc = net__try_connect(host, port, &sock, bind_address, blocking); + rc = net__try_connect(host, port, &mosq->sock, bind_address, blocking); if(rc > 0) return rc; - mosq->sock = sock; - if(mosq->tcp_nodelay){ int flag = 1; if(setsockopt(mosq->sock, IPPROTO_TCP, TCP_NODELAY, (const void*)&flag, sizeof(int)) != 0){ From cde735a48005d853a5a11f6d68beb21a0b36ee55 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Sat, 3 Apr 2021 11:05:01 +0100 Subject: [PATCH 33/41] Add issue template. --- .github/issue_template.md | 21 +++++++++++++++++++++ 1 file changed, 21 insertions(+) create mode 100644 .github/issue_template.md diff --git a/.github/issue_template.md b/.github/issue_template.md new file mode 100644 index 00000000..89a90760 --- /dev/null +++ b/.github/issue_template.md @@ -0,0 +1,21 @@ + + From 6a4a547892184ac7543cfda3ee2294e26be22484 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Sat, 3 Apr 2021 11:07:30 +0100 Subject: [PATCH 34/41] Fix segfault on client sending malformed CONNACk. CVE-xxxx-xxxx: If an authenticated client connected with MQTT v5 sent a malformed CONNACK message to the broker a NULL pointer dereference occurred, most likely resulting in a segfault. This will be updated with the CVE number when it is assigned. Affects versions 2.0.0 to 2.0.9 inclusive. Closes #2163. Thanks to Bryan Pearson. --- ChangeLog.txt | 10 +++++- src/handle_connack.c | 2 +- test/broker/01-connect-connack-2163.py | 50 ++++++++++++++++++++++++++ test/broker/Makefile | 1 + test/broker/test.py | 1 + 5 files changed, 62 insertions(+), 2 deletions(-) create mode 100755 test/broker/01-connect-connack-2163.py diff --git a/ChangeLog.txt b/ChangeLog.txt index 27d3c73d..98fb4033 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -1,9 +1,17 @@ -2.0.10 - 2021-xx-xx +2.0.10 - 2021-04-03 ================== +Security: +- CVE-xxxx-xxxx: If an authenticated client connected with MQTT v5 sent a + malformed CONNACK message to the broker a NULL pointer dereference occurred, + most likely resulting in a segfault. This will be updated with the CVE + number when it is assigned. + Affects versions 2.0.0 to 2.0.9 inclusive. + Broker: - Don't over write new receive-maximum if a v5 client connects and takes over an old session. Closes #2134. +- Fix CVE-xxxx-xxxx. Closes #2163. Clients: - Set `receive-maximum` to not exceed the `-C` message count in mosquitto_sub diff --git a/src/handle_connack.c b/src/handle_connack.c index 6aacb592..573a0ab0 100644 --- a/src/handle_connack.c +++ b/src/handle_connack.c @@ -39,7 +39,7 @@ int handle__connack(struct mosquitto *context) uint16_t server_keepalive; uint8_t max_qos = 255; - if(!context){ + if(context == NULL || context->bridge == NULL){ return MOSQ_ERR_INVAL; } log__printf(NULL, MOSQ_LOG_DEBUG, "Received CONNACK on connection %s.", context->id); diff --git a/test/broker/01-connect-connack-2163.py b/test/broker/01-connect-connack-2163.py new file mode 100755 index 00000000..8f0297f1 --- /dev/null +++ b/test/broker/01-connect-connack-2163.py @@ -0,0 +1,50 @@ +#!/usr/bin/env python3 + +# Test https://github.com/eclipse/mosquitto/issues/2163 +# Does the broker cope with a malformed CONNACK sent to it after a valid CONNECT? + +from mosq_test_helper import * + +def do_test(proto_ver): + rc = 1 + keepalive = 10 + connect_packet = mosq_test.gen_connect("connect-connack-2163", keepalive=keepalive, proto_ver=proto_ver) + connack_packet = mosq_test.gen_connack(rc=0, proto_ver=proto_ver) + connack_malformed = struct.pack("BBBBB", 0x02, 0x00, 0x01, 0xE0, 0x00) + connack_malformed = struct.pack("BBBB", 0x29, 0x02, 0x00, 0x01) + pingreq_packet = mosq_test.gen_pingreq() + + port = mosq_test.get_port() + broker = mosq_test.start_broker(filename=os.path.basename(__file__), port=port) + + try: + sock = mosq_test.do_client_connect(connect_packet, connack_packet, port=port) + sock.send(connack_malformed) + try: + mosq_test.do_send_receive(sock, pingreq_packet, b"", "pingreq") + except ConnectionResetError: + pass + sock.close() + + # Does the broker still exist? + sock = mosq_test.do_client_connect(connect_packet, connack_packet, port=port) + mosq_test.do_ping(sock) + sock.close() + + rc = 0 + except mosq_test.TestError: + pass + finally: + broker.terminate() + broker.wait() + (stdo, stde) = broker.communicate() + if rc: + print(stde.decode('utf-8')) + print("proto_ver=%d" % (proto_ver)) + exit(rc) + + +do_test(proto_ver=3) +do_test(proto_ver=4) +do_test(proto_ver=5) +exit(0) diff --git a/test/broker/Makefile b/test/broker/Makefile index 01816063..c874d67b 100644 --- a/test/broker/Makefile +++ b/test/broker/Makefile @@ -22,6 +22,7 @@ test : test-compile 01 02 03 04 05 06 07 08 09 10 11 12 13 14 01 : ./01-connect-allow-anonymous.py ./01-connect-bad-packet.py + ./01-connect-connack-2163.py ./01-connect-disconnect-v5.py ./01-connect-duplicate.py ./01-connect-invalid-id-0.py diff --git a/test/broker/test.py b/test/broker/test.py index 62216203..abf94143 100755 --- a/test/broker/test.py +++ b/test/broker/test.py @@ -7,6 +7,7 @@ tests = [ #(ports required, 'path'), (1, './01-connect-allow-anonymous.py'), (1, './01-connect-bad-packet.py'), + (1, './01-connect-connack-2163.py'), (1, './01-connect-disconnect-v5.py'), (1, './01-connect-duplicate.py'), (1, './01-connect-invalid-id-0.py'), From eead0d294392b9930238cb372a047e7869144218 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Sat, 3 Apr 2021 11:15:13 +0100 Subject: [PATCH 35/41] Fix build on Solaris non-sparc. Closes #2136. Thanks to chuckunix. --- ChangeLog.txt | 1 + config.mk | 13 ++++++++++--- 2 files changed, 11 insertions(+), 3 deletions(-) diff --git a/ChangeLog.txt b/ChangeLog.txt index 98fb4033..bf9b09fd 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -28,6 +28,7 @@ Build: - A variety of minor build related fixes, like functions not having previous declarations. - Fix CMake cross compile builds not finding opensslconf.h. Closes #2160. +- Fix build on Solaris non-sparc. Closes #2136. 2.0.9 - 2021-03-11 diff --git a/config.mk b/config.mk index d7b14b75..4392adf0 100644 --- a/config.mk +++ b/config.mk @@ -140,6 +140,7 @@ DB_HTML_XSL=man/html.xsl #MANCOUNTRIES=en_GB UNAME:=$(shell uname -s) +ARCH:=$(shell uname -p) ifeq ($(UNAME),SunOS) ifeq ($(CC),cc) @@ -199,9 +200,15 @@ ifeq ($(WITH_SHARED_LIBRARIES),yes) endif ifeq ($(UNAME),SunOS) - ifeq ($(CC),cc) - LIB_CFLAGS:=$(LIB_CFLAGS) -xc99 -KPIC - else + SEDINPLACE:= + ifeq ($(ARCH),sparc) + ifeq ($(CC),cc) + LIB_CFLAGS:=$(LIB_CFLAGS) -xc99 -KPIC + else + LIB_CFLAGS:=$(LIB_CFLAGS) -fPIC + endif + endif + ifeq ($(ARCH),i386) LIB_CFLAGS:=$(LIB_CFLAGS) -fPIC endif From 983dc14f2c52741ee22e04e8b379d38153fb989e Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Sat, 3 Apr 2021 11:33:57 +0100 Subject: [PATCH 36/41] Provide help for users trying to bind to privileged ports. Closes #2098. --- src/net.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/src/net.c b/src/net.c index cbcfc677..74fdebae 100644 --- a/src/net.c +++ b/src/net.c @@ -754,6 +754,12 @@ static int net__socket_listen_tcp(struct mosquitto__listener *listener) #endif if(bind(sock, rp->ai_addr, rp->ai_addrlen) == -1){ +#if defined(__linux__) + if(errno == EACCES){ + log__printf(NULL, MOSQ_LOG_ERR, "If you are trying to bind to a privileged port (<1024), try using setcap and do not start the broker as root:"); + log__printf(NULL, MOSQ_LOG_ERR, " sudo setcap 'CAP_NET_BIND_SERVICE=+ep /usr/sbin/mosquitto'"); + } +#endif net__print_error(MOSQ_LOG_ERR, "Error: %s"); COMPAT_CLOSE(sock); freeaddrinfo(ainfo); From 54df92cdc926cc892ec199f15ac371e1843f9d06 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Sat, 3 Apr 2021 11:41:25 +0100 Subject: [PATCH 37/41] Add references to dynsec plugin in mosquitto.conf(5) Closes #2089. Thanks to YerayAlonso. --- man/mosquitto.conf.5.xml | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) diff --git a/man/mosquitto.conf.5.xml b/man/mosquitto.conf.5.xml index cd76cd5f..df110954 100644 --- a/man/mosquitto.conf.5.xml +++ b/man/mosquitto.conf.5.xml @@ -42,7 +42,8 @@ Authentication The authentication options described below allow a wide range of possibilities in conjunction with the listener options. This - section aims to clarify the possibilities. + section aims to clarify the possibilities. An overview is also available at + The simplest option is to have no authentication at all. This is the default if no other options are given. Unauthenticated encrypted support is provided by using the certificate based @@ -54,6 +55,11 @@ vulnerable to interception. Use the to control whether passwords are required globally or on a per-listener basis. + Mosquitto provides the Dynamic Security plugin which handles + username/password authentication and access control in a much + more flexible way than a password file. See + + When using certificate based encryption there are three options that affect authentication. The first is require_certificate, which may be set to true or false. If false, the SSL/TLS component of the @@ -164,6 +170,9 @@ Reloaded on reload signal. The currently loaded ACLs will be freed and reloaded. Existing subscriptions will be affected after the reload. + See also + + @@ -267,6 +276,9 @@ alongsize , the plugin checks will run after the built in checks. Not currently reloaded on reload signal. + See also + + @@ -753,7 +765,9 @@ log_timestamp_format %Y-%m-%dT%H:%M:%S Clients that are already connected will not be affected. See also - mosquitto_passwd1. + mosquitto_passwd1 and + + From e7aa0fed2f4388795d39b01a949ad8e67517b027 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Sat, 3 Apr 2021 12:00:33 +0100 Subject: [PATCH 38/41] Bump version, update web page. --- CMakeLists.txt | 2 +- config.mk | 2 +- include/mosquitto.h | 2 +- installer/mosquitto.nsi | 2 +- installer/mosquitto64.nsi | 2 +- set-version.sh | 2 +- snap/snapcraft.yaml | 2 +- www/pages/download.md | 8 ++-- www/pages/security.md | 4 +- www/posts/2021/04/version-2-0-10-released.md | 48 ++++++++++++++++++++ 10 files changed, 62 insertions(+), 12 deletions(-) create mode 100644 www/posts/2021/04/version-2-0-10-released.md diff --git a/CMakeLists.txt b/CMakeLists.txt index 4963d4ca..2a0be9b1 100644 --- a/CMakeLists.txt +++ b/CMakeLists.txt @@ -8,7 +8,7 @@ cmake_minimum_required(VERSION 3.0) cmake_policy(SET CMP0042 NEW) project(mosquitto) -set (VERSION 2.0.9) +set (VERSION 2.0.10) list(APPEND CMAKE_MODULE_PATH "${CMAKE_SOURCE_DIR}/cmake/") diff --git a/config.mk b/config.mk index 4392adf0..fe6a822a 100644 --- a/config.mk +++ b/config.mk @@ -127,7 +127,7 @@ WITH_XTREPORT=no # Also bump lib/mosquitto.h, CMakeLists.txt, # installer/mosquitto.nsi, installer/mosquitto64.nsi -VERSION=2.0.9 +VERSION=2.0.10 # Client library SO version. Bump if incompatible API/ABI changes are made. SOVERSION=1 diff --git a/include/mosquitto.h b/include/mosquitto.h index 9aafcb32..02c49fcd 100644 --- a/include/mosquitto.h +++ b/include/mosquitto.h @@ -66,7 +66,7 @@ extern "C" { #define LIBMOSQUITTO_MAJOR 2 #define LIBMOSQUITTO_MINOR 0 -#define LIBMOSQUITTO_REVISION 9 +#define LIBMOSQUITTO_REVISION 10 /* LIBMOSQUITTO_VERSION_NUMBER looks like 1002001 for e.g. version 1.2.1. */ #define LIBMOSQUITTO_VERSION_NUMBER (LIBMOSQUITTO_MAJOR*1000000+LIBMOSQUITTO_MINOR*1000+LIBMOSQUITTO_REVISION) diff --git a/installer/mosquitto.nsi b/installer/mosquitto.nsi index 20487814..437bf95f 100644 --- a/installer/mosquitto.nsi +++ b/installer/mosquitto.nsi @@ -9,7 +9,7 @@ !define env_hklm 'HKLM "SYSTEM\CurrentControlSet\Control\Session Manager\Environment"' Name "Eclipse Mosquitto" -!define VERSION 2.0.9 +!define VERSION 2.0.10 OutFile "mosquitto-${VERSION}-install-windows-x86.exe" InstallDir "$PROGRAMFILES\mosquitto" diff --git a/installer/mosquitto64.nsi b/installer/mosquitto64.nsi index 5ca2ca38..aeb8548b 100644 --- a/installer/mosquitto64.nsi +++ b/installer/mosquitto64.nsi @@ -9,7 +9,7 @@ !define env_hklm 'HKLM "SYSTEM\CurrentControlSet\Control\Session Manager\Environment"' Name "Eclipse Mosquitto" -!define VERSION 2.0.9 +!define VERSION 2.0.10 OutFile "mosquitto-${VERSION}-install-windows-x64.exe" !include "x64.nsh" diff --git a/set-version.sh b/set-version.sh index ba9b855a..af1fc52d 100755 --- a/set-version.sh +++ b/set-version.sh @@ -2,7 +2,7 @@ MAJOR=2 MINOR=0 -REVISION=9 +REVISION=10 sed -i "s/^VERSION=.*/VERSION=${MAJOR}.${MINOR}.${REVISION}/" config.mk diff --git a/snap/snapcraft.yaml b/snap/snapcraft.yaml index 5e8289ba..1ca29c0f 100644 --- a/snap/snapcraft.yaml +++ b/snap/snapcraft.yaml @@ -1,5 +1,5 @@ name: mosquitto -version: 2.0.9 +version: 2.0.10 summary: Eclipse Mosquitto MQTT broker description: This is a message broker that supports version 5.0, 3.1.1, and 3.1 of the MQTT protocol. diff --git a/www/pages/download.md b/www/pages/download.md index c181fdca..974476d3 100644 --- a/www/pages/download.md +++ b/www/pages/download.md @@ -1,7 +1,7 @@ + +Versions 2.0.10 of Mosquitto has been released. This is a security and bugfix +release. + +# Security +- CVE-xxxx-xxxx: If an authenticated client connected with MQTT v5 sent a + malformed CONNACK message to the broker a NULL pointer dereference occurred, + most likely resulting in a segfault. This will be updated with the CVE + number when it is assigned. + Affects versions 2.0.0 to 2.0.9 inclusive. + +# Broker +- Don't overwrite new receive-maximum if a v5 client connects and takes over + an old session. Closes [#2134]. +- Fix CVE-xxxx-xxxx. Closes [#2163]. + +# Clients +- Set `receive-maximum` to not exceed the `-C` message count in mosquitto_sub + and mosquitto_rr, to avoid potentially lost messages. Closes [#2134]. +- Fix TLS-PSK mode not working with port 8883. Closes [#2152]. + +# Client library +- Fix possible socket leak. This would occur if a client was using + `mosquitto_loop_start()`, then if the connection failed due to the remote + server being inaccessible they called `mosquitto_loop_stop(, true)` and + recreated the mosquitto object. + +# Build +- A variety of minor build related fixes, like functions not having previous + declarations. +- Fix CMake cross compile builds not finding opensslconf.h. Closes [#2160]. +- Fix build on Solaris non-sparc. Closes [#2136]. + +[#2134]: https://github.com/eclipse/mosquitto/issues/2134 +[#2136]: https://github.com/eclipse/mosquitto/issues/2136 +[#2152]: https://github.com/eclipse/mosquitto/issues/2152 +[#2160]: https://github.com/eclipse/mosquitto/issues/2160 +[#2163]: https://github.com/eclipse/mosquitto/issues/2163 From 1c79920d78321c69add9d6d6f879dd73387bc25e Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Sat, 3 Apr 2021 13:50:40 +0100 Subject: [PATCH 39/41] Update docker. --- docker/2.0-openssl/Dockerfile | 4 ++-- docker/2.0/Dockerfile | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/docker/2.0-openssl/Dockerfile b/docker/2.0-openssl/Dockerfile index 69f3467a..96875b04 100644 --- a/docker/2.0-openssl/Dockerfile +++ b/docker/2.0-openssl/Dockerfile @@ -3,8 +3,8 @@ FROM alpine:3.12 LABEL maintainer="Roger Light " \ description="Eclipse Mosquitto MQTT Broker" -ENV VERSION=2.0.9 \ - DOWNLOAD_SHA256=1b8553ef64a1cf5e4f4cfbe098330ae612adccd3d37f35b2db6f6fab501b01d4 \ +ENV VERSION=2.0.10 \ + DOWNLOAD_SHA256=0188f7b21b91d6d80e992b8d6116ba851468b3bd154030e8a003ed28fb6f4a44 \ GPG_KEYS=A0D6EEA1DCAE49A635A3B2F0779B22DFB3E717B7 \ LWS_VERSION=2.4.2 \ LWS_SHA256=73012d7fcf428dedccc816e83a63a01462e27819d5537b8e0d0c7264bfacfad6 \ diff --git a/docker/2.0/Dockerfile b/docker/2.0/Dockerfile index 949e44a4..7a322dde 100644 --- a/docker/2.0/Dockerfile +++ b/docker/2.0/Dockerfile @@ -3,8 +3,8 @@ FROM alpine:3.12 LABEL maintainer="Roger Light " \ description="Eclipse Mosquitto MQTT Broker" -ENV VERSION=2.0.9 \ - DOWNLOAD_SHA256=1b8553ef64a1cf5e4f4cfbe098330ae612adccd3d37f35b2db6f6fab501b01d4 \ +ENV VERSION=2.0.10 \ + DOWNLOAD_SHA256=0188f7b21b91d6d80e992b8d6116ba851468b3bd154030e8a003ed28fb6f4a44 \ GPG_KEYS=A0D6EEA1DCAE49A635A3B2F0779B22DFB3E717B7 \ LWS_VERSION=2.4.2 \ LWS_SHA256=73012d7fcf428dedccc816e83a63a01462e27819d5537b8e0d0c7264bfacfad6 \ From 34522913ea0666c4ecd765e3327f435f60572e97 Mon Sep 17 00:00:00 2001 From: "Roger A. Light" Date: Tue, 6 Apr 2021 14:41:45 +0100 Subject: [PATCH 40/41] Update Windows readme. --- README-windows.txt | 23 +++++------------------ 1 file changed, 5 insertions(+), 18 deletions(-) diff --git a/README-windows.txt b/README-windows.txt index 7bf0d954..aee672d6 100644 --- a/README-windows.txt +++ b/README-windows.txt @@ -1,18 +1,16 @@ Mosquitto for Windows ===================== -Mosquitto for Windows comes in 32-bit and 64-bit flavours. - -In both cases, the dependencies are not provided in this installer and must be -installed separately in the case that they are not already available. - +Mosquitto for Windows comes in 64-bit and 32-bit flavours. All dependencies are +provided in the installer. Capabilities ------------ Some versions of Windows have limitations on the number of concurrent -connections, set at approximately 2048 connections depending on the version of -Windows you are using. +connections. In modern versions of Windows, e.g. Windows 10 or Windows Server +2019, this is approximately 8192 connections. In earlier versions of Windows, +this limit is 2048 connections. Websockets @@ -23,7 +21,6 @@ through a statically compiled version of libwebsockets and is being distributed under the Static Linking Exception (Section 2) of the License. As a result, the content is not subject to the LGPL 2.1. -Please note that on Windows, libwebsockets limits connections to a maximum of 64 clients. Library Thread Support ---------------------- @@ -35,16 +32,6 @@ A better solution that the old pthreads-win32 is being looked into, so support will return in the future. If you need thread support, the code still supports it just fine. Support has been dropped to simplify installation. -Dependencies ------------- - -* OpenSSL - Link: http://slproweb.com/products/Win32OpenSSL.html - Install "Win32 OpenSSL 1.1.0* Light" or "Win64 OpenSSL 1.1.0* Light" - Required DLLs: libssl-1_1.dll, libcrypto-1_1.dll or libssl-1_1-x64.dll, libcrypto-1_1-x64.dll - -Please ensure that the required DLLs are on the system path, or are in the same directory as -the mosquitto executable - usually C:\Program Files (x86)\mosquitto or C:\Program Files\mosquitto. Windows Service --------------- From d5ecd9f5aa98d42e7549eea09a71a23eef241f31 Mon Sep 17 00:00:00 2001 From: Roger Light Date: Sat, 10 Apr 2021 08:28:41 +0100 Subject: [PATCH 41/41] Update CVE information. --- ChangeLog.txt | 5 ++--- www/pages/security.md | 3 ++- www/posts/2021/04/version-2-0-10-released.md | 3 ++- 3 files changed, 6 insertions(+), 5 deletions(-) diff --git a/ChangeLog.txt b/ChangeLog.txt index bf9b09fd..e6c2069d 100644 --- a/ChangeLog.txt +++ b/ChangeLog.txt @@ -2,10 +2,9 @@ ================== Security: -- CVE-xxxx-xxxx: If an authenticated client connected with MQTT v5 sent a +- CVE-2021-23980: If an authenticated client connected with MQTT v5 sent a malformed CONNACK message to the broker a NULL pointer dereference occurred, - most likely resulting in a segfault. This will be updated with the CVE - number when it is assigned. + most likely resulting in a segfault. Affects versions 2.0.0 to 2.0.9 inclusive. Broker: diff --git a/www/pages/security.md b/www/pages/security.md index 541612b9..44cd1f7c 100644 --- a/www/pages/security.md +++ b/www/pages/security.md @@ -19,7 +19,7 @@ follow the steps on [Eclipse Security] page to report it. Listed with most recent first. Further information on security related issues can be found in the [security category]. -* April 2021: CVE-xxxx-xxxx Affecting versions **2.0.0** to **2.0.9** +* April 2021: [CVE-2021-28166] Affecting versions **2.0.0** to **2.0.9** inclusive, fixed in **2.0.10**. * December 2020: Running mosquitto_passwd with the following arguments only `mosquitto_passwd -b password_file username password` would cause the @@ -69,6 +69,7 @@ can be found in the [security category]. [Eclipse Security]: https://www.eclipse.org/security/ [security category]: /blog/categories/security/ +[CVE-2021-28166]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28166 [CVE-2019-11779]: https://nvd.nist.gov/vuln/detail/CVE-2019-11779 [CVE-2019-11778]: https://nvd.nist.gov/vuln/detail/CVE-2019-11778 [CVE-2018-20145]: https://nvd.nist.gov/vuln/detail/CVE-2018-20145 diff --git a/www/posts/2021/04/version-2-0-10-released.md b/www/posts/2021/04/version-2-0-10-released.md index 26d449bb..096dc7ab 100644 --- a/www/posts/2021/04/version-2-0-10-released.md +++ b/www/posts/2021/04/version-2-0-10-released.md @@ -13,7 +13,7 @@ Versions 2.0.10 of Mosquitto has been released. This is a security and bugfix release. # Security -- CVE-xxxx-xxxx: If an authenticated client connected with MQTT v5 sent a +- [CVE-2021-23980]: If an authenticated client connected with MQTT v5 sent a malformed CONNACK message to the broker a NULL pointer dereference occurred, most likely resulting in a segfault. This will be updated with the CVE number when it is assigned. @@ -41,6 +41,7 @@ release. - Fix CMake cross compile builds not finding opensslconf.h. Closes [#2160]. - Fix build on Solaris non-sparc. Closes [#2136]. +[CVE-2021-23980]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28166 [#2134]: https://github.com/eclipse/mosquitto/issues/2134 [#2136]: https://github.com/eclipse/mosquitto/issues/2136 [#2152]: https://github.com/eclipse/mosquitto/issues/2152