@cryptotaxi247 / netdata-1 / commits / 518267783

netdata/daemon: SSL fix - broken compilation case when ssl library not present! (#6201)

* SSL_fix fix the compilation case the library is not present!

thiagoftsm committed Jun 3, 2019 at 19:25 UTC 5182677831814289d27afb0b48043ab63f2b6d1b
6 files changed +30 -17
libnetdata/libnetdata.h
+3 -1
@@ -298,7 +298,9 @@ extern char *netdata_configured_host_prefix;
298 #include "clocks/clocks.h"
299 #include "popen/popen.h"
300 #include "simple_pattern/simple_pattern.h"
301 -#include "socket/security.h"
301 +#ifdef ENABLE_HTTPS
302 +# include "socket/security.h"
303 +#endif
304 #include "socket/socket.h"
305 #include "config/appconfig.h"
306 #include "log/log.h"
libnetdata/socket/security.c
+5 -1
@@ -1,5 +1,7 @@
1 #include "../libnetdata.h"
2
3 +#ifdef ENABLE_HTTPS
4 +
5 SSL_CTX *netdata_cli_ctx=NULL;
6 SSL_CTX *netdata_srv_ctx=NULL;
7 const char *security_key=NULL;
@@ -212,4 +214,6 @@ int security_test_certificate(SSL *ssl){
214 ret = 0;
215 }
216 return ret;
215 -}
\ No newline at end of file
217 +}
218 +
219 +#endif
libnetdata/socket/security.h
+18 -14
@@ -1,21 +1,24 @@
1 #ifndef NETDATA_SECURITY_H
2 # define NETDATA_SECURITY_H
3
4 -# include <openssl/ssl.h>
5 -# include <openssl/err.h>
6 -# if (SSLEAY_VERSION_NUMBER >= 0x0907000L) && (OPENSSL_VERSION_NUMBER < 0x10100000L)
7 -# include <openssl/conf.h>
8 -# endif
4 +# define NETDATA_SSL_HANDSHAKE_COMPLETE 0 //All the steps were successful
5 +# define NETDATA_SSL_START 1 //Starting handshake, conn variable is NULL
6 +# define NETDATA_SSL_WANT_READ 2 //The connection wanna read from socket
7 +# define NETDATA_SSL_WANT_WRITE 4 //The connection wanna write on socket
8 +# define NETDATA_SSL_NO_HANDSHAKE 8 //Continue without encrypt connection.
9 +# define NETDATA_SSL_OPTIONAL 16 //Flag to define the HTTP request
10 +# define NETDATA_SSL_FORCE 32 //We only accepts HTTPS request
11 +# define NETDATA_SSL_INVALID_CERTIFICATE 64 //Accepts invalid certificate
12 +# define NETDATA_SSL_VALID_CERTIFICATE 128 //Accepts invalid certificate
13 +
14 +# ifdef ENABLE_HTTPS
15 +
16 +# include <openssl/ssl.h>
17 +# include <openssl/err.h>
18 +# if (SSLEAY_VERSION_NUMBER >= 0x0907000L) && (OPENSSL_VERSION_NUMBER < 0x10100000L)
19 +# include <openssl/conf.h>
20 +# endif
21
10 -#define NETDATA_SSL_HANDSHAKE_COMPLETE 0 //All the steps were successful
11 -#define NETDATA_SSL_START 1 //Starting handshake, conn variable is NULL
12 -#define NETDATA_SSL_WANT_READ 2 //The connection wanna read from socket
13 -#define NETDATA_SSL_WANT_WRITE 4 //The connection wanna write on socket
14 -#define NETDATA_SSL_NO_HANDSHAKE 8 //Continue without encrypt connection.
15 -#define NETDATA_SSL_OPTIONAL 16 //Flag to define the HTTP request
16 -#define NETDATA_SSL_FORCE 32 //We only accepts HTTPS request
17 -#define NETDATA_SSL_INVALID_CERTIFICATE 64 //Accepts invalid certificate
18 -#define NETDATA_SSL_VALID_CERTIFICATE 128 //Accepts invalid certificate
22 struct netdata_ssl{
23 SSL *conn; //SSL connection
24 int flags;
@@ -35,4 +38,5 @@ void security_start_ssl(int type);
38 int security_process_accept(SSL *ssl,int msg);
39 int security_test_certificate(SSL *ssl);
40
41 +# endif //ENABLE_HTTPS
42 #endif //NETDATA_SECURITY_H
libnetdata/socket/socket.c
+2
@@ -302,6 +302,7 @@ void listen_sockets_close(LISTEN_SOCKETS *sockets) {
302 }
303
304 WEB_CLIENT_ACL socket_ssl_acl(char *ssl){
305 +#ifdef ENABLE_HTTPS
306 if (!strcmp(ssl,"optional")){
307 netdata_use_ssl_on_http = NETDATA_SSL_OPTIONAL;
308 return WEB_CLIENT_ACL_DASHBOARD | WEB_CLIENT_ACL_REGISTRY | WEB_CLIENT_ACL_BADGE | WEB_CLIENT_ACL_MGMT | WEB_CLIENT_ACL_NETDATACONF | WEB_CLIENT_ACL_STREAMING;
@@ -310,6 +311,7 @@ WEB_CLIENT_ACL socket_ssl_acl(char *ssl){
311 netdata_use_ssl_on_stream = NETDATA_SSL_FORCE;
312 return WEB_CLIENT_ACL_DASHBOARD | WEB_CLIENT_ACL_REGISTRY | WEB_CLIENT_ACL_BADGE | WEB_CLIENT_ACL_MGMT | WEB_CLIENT_ACL_NETDATACONF | WEB_CLIENT_ACL_STREAMING;
313 }
314 +#endif
315
316 return WEB_CLIENT_ACL_NONE;
317 }
libnetdata/socket/socket.h
-1
@@ -3,7 +3,6 @@
3 #ifndef NETDATA_SOCKET_H
4 #define NETDATA_SOCKET_H
5
6 -#include <openssl/ossl_typ.h>
6 #include "../libnetdata.h"
7
8 #ifndef MAX_LISTEN_FDS
streaming/rrdpush.c
+2
@@ -1210,7 +1210,9 @@ static void *rrdpush_receiver_thread(void *ptr) {
1210 , rpt->update_every
1211 , rpt->client_ip
1212 , rpt->client_port
1213 +#ifdef ENABLE_HTTPS
1214 , &rpt->ssl
1215 +#endif
1216 );
1217
1218 netdata_thread_cleanup_pop(1);