Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
89 changes: 68 additions & 21 deletions modules/db_postgres/README
Original file line number Diff line number Diff line change
Expand Up @@ -53,15 +53,16 @@ Chapter 1. Admin Guide
1.2.1. OpenSIPS Modules

The following modules must be loaded before this module:
* No dependencies on other OpenSIPS modules.

tls_wolfssl - if use_tls=1 is specified
tls_mgm - if use_tls=1 is specified

1.2.2. External Libraries or Applications

The following libraries or applications must be installed
before running OpenSIPS with this module loaded:
* PostgreSQL library - e.g., libpq5.
* PostgreSQL devel library - to compile the module (e.g.,
libpq-dev).
* PostgreSQL devel library - to compile the module (e.g., libpq-dev).

1.3. Exported Parameters

Expand Down Expand Up @@ -100,7 +101,7 @@ modparam("db_postgres", "max_db_queries", 2)
succeed, OpenSIPS will block until the connection becomes back
available and gets successfully established. This is the
default behavior of the library and is the behavior prior to
the adition of this parameter.
the addition of this parameter.

Default value is 5.

Expand All @@ -109,6 +110,51 @@ modparam("db_postgres", "max_db_queries", 2)
modparam("db_postgres", "timeout", 2)
...

1.3.4. use_tls (integer)

Warning: wolfSSL is the required TLS/SSL Library

This feature is not compatible with OpenSSL for the reasons defined in
https://blog.opensips.org/2021/02/11/exploring-ssl-tls-libraries-for-opensips-3-2

Setting this parameter will allow you to use TLS for PostgreSQL
connections. In order to enable TLS for a specific connection,
you can use the "tls_domain=dom_name" URL parameter in the
db_url of the respective OpenSIPS module. This should be placed
at the end of the URL after the '?' character.

When using this parameter, you must also ensure that tls_mgm is
loaded and properly configured. Refer to the the module for
additional info regarding TLS client domains.

Note that if you want to use this feature, the TLS domain must
be provisioned in the configuration file, NOT in the database.
In case you are loading TLS certificates from the database, you
must at least define one domain in the configuration script, to
use for the initial connection to the DB.

Also, you can NOT enable TLS for the connection to the database
of the tls_mgm module itself.

Default value is 0 (not enabled)

Example 1.6. Set the use_tls parameter
...
loadmodule "tls_wolfssl"
loadmodule "tls_mgm"
loadmodule "db_postgres"
...
modparam("tls_mgm", "client_domain", "dom1")
modparam("tls_mgm", "certificate", "[dom1]/etc/pki/tls/certs/opensips.pem")
modparam("tls_mgm", "private_key", "[dom1]/etc/pki/tls/private/opensips.key")
modparam("tls_mgm", "ca_list", "[dom1]/etc/pki/tls/certs/ca.pem")
...
modparam("db_postgres", "use_tls", 1)
...
loadmodule "usrloc"
modparam("usrloc", "db_url", "postgres://root:1234@localhost/opensips?tls_domain=dom1")
...

1.4. Exported Functions

NONE
Expand All @@ -135,9 +181,9 @@ Chapter 2. Contributors
9. Klaus Darilion 10 6 139 67
10. Vlad Paiu (@vladpaiu) 9 7 102 34

All remaining contributors: Ancuta Onofrei, Norman Brandinger,
Maksym Sobolyev (@sobomax), Vlad Patrascu (@rvlad-patrascu),
Andrei Pelinescu-Onciul, Dusan Klinec (@ph4r05), Eseanu Marius
All remaining contributors: Ancuta Onofrei, Maksym Sobolyev
(@sobomax), Vlad Patrascu (@rvlad-patrascu), Andrei
Pelinescu-Onciul, Dusan Klinec (@ph4r05), Eseanu Marius
Cristian (@eseanucristian), Ruslan Bukin, Ryan Bullock
(@rrb3942), Konstantin Bokarius, Razvan Pistolea, Aron
Podrigal, Dan Pascu (@danpascu), Peter Lemenkov (@lemenkov),
Expand All @@ -163,7 +209,7 @@ Chapter 2. Contributors

Table 2.2. Most recently active contributors^(1) to this module
Name Commit Activity
1. Norman Brandinger (@NormB) Aug 2006 - Aug 2021
1. Norm Brandinger (@NormB) Oct 2006 - Jul 2021
2. Razvan Crainea (@razvancrainea) Oct 2011 - Sep 2019
3. Dan Pascu (@danpascu) May 2019 - May 2019
4. Liviu Chircu (@liviuchircu) Sep 2012 - May 2019
Expand All @@ -173,14 +219,14 @@ Chapter 2. Contributors
8. Vlad Paiu (@vladpaiu) Jan 2011 - Feb 2019
9. Peter Lemenkov (@lemenkov) Jun 2018 - Jun 2018
10. Jarrod Baumann (@jarrodb) Mar 2016 - Mar 2016
11. Dusan Klinec (@ph4r05) Dec 2015 - Dec 2015

All remaining contributors: Dusan Klinec (@ph4r05), Aron
Podrigal, Eseanu Marius Cristian (@eseanucristian), Razvan
Pistolea, Ruslan Bukin, Henning Westerholt (@henningw),
Daniel-Constantin Mierla (@miconda), Konstantin Bokarius, Edson
Gellert Schubert, Ancuta Onofrei, Klaus Darilion, Norman
Brandinger, Maksym Sobolyev (@sobomax), Jan Janak (@janakj),
Greg Fausak, Andrei Pelinescu-Onciul.
All remaining contributors: Aron Podrigal, Eseanu Marius
Cristian (@eseanucristian), Razvan Pistolea, Ruslan Bukin,
Henning Westerholt (@henningw), Daniel-Constantin Mierla
(@miconda), Konstantin Bokarius, Edson Gellert Schubert, Ancuta
Onofrei, Klaus Darilion, Maksym Sobolyev (@sobomax), Jan Janak
(@janakj), Greg Fausak, Andrei Pelinescu-Onciul.

(1) including any documentation-related commits, excluding
merge commits
Expand All @@ -189,12 +235,13 @@ Chapter 3. Documentation

3.1. Contributors

Last edited by: Liviu Chircu (@liviuchircu), Razvan Crainea
(@razvancrainea), Peter Lemenkov (@lemenkov), Aron Podrigal,
Eseanu Marius Cristian (@eseanucristian), Bogdan-Andrei Iancu
(@bogdan-iancu), Vlad Paiu (@vladpaiu), Daniel-Constantin
Mierla (@miconda), Konstantin Bokarius, Edson Gellert Schubert,
Henning Westerholt (@henningw), Jan Janak (@janakj).
Last edited by: Norm Brandinger (@NormB) Liviu Chircu
(@liviuchircu), Razvan Crainea (@razvancrainea), Peter
Lemenkov (@lemenkov), Aron Podrigal, Eseanu Marius Cristian
(@eseanucristian), Bogdan-Andrei Iancu (@bogdan-iancu),
Vlad Paiu (@vladpaiu), Daniel-Constantin Mierla (@miconda),
Konstantin Bokarius, Edson Gellert Schubert, Henning
Westerholt (@henningw), Jan Janak (@janakj).

Documentation Copyrights:

Expand Down
37 changes: 31 additions & 6 deletions modules/db_postgres/db_postgres.c
Original file line number Diff line number Diff line change
Expand Up @@ -31,11 +31,12 @@
#include "../../db/db_con.h"
#include "../../db/db.h"
#include "../../db/db_cap.h"
#include "../tls_mgm/api.h"
#include "dbase.h"
#include "db_postgres.h"

int db_postgres_exec_query_threshold = 0; /* Warning in case DB query
takes too long disabled by default*/
takes too long disabled by default*/
int max_db_queries = 2;
int pq_timeout = DEFAULT_PSQL_TIMEOUT;

Expand All @@ -51,22 +52,35 @@ static cmd_export_t cmds[] = {
{0,0,{{0,0,0}},0}
};

struct tls_mgm_binds tls_api;
struct tls_domain *tls_dom;
int use_tls = 0;

/*
* Exported parameters
*/
static param_export_t params[] = {
{"exec_query_threshold", INT_PARAM, &db_postgres_exec_query_threshold},
{"max_db_queries", INT_PARAM, &max_db_queries},
{"timeout", INT_PARAM, &pq_timeout},
{"use_tls", INT_PARAM, &use_tls},
{0, 0, 0}
};

static module_dependency_t *get_deps_use_tls(param_export_t *param)
{
if (*(int *)param->param_pointer == 0)
return NULL;

return alloc_module_dep(MOD_TYPE_DEFAULT, "tls_mgm", DEP_ABORT);
}

static dep_export_t deps = {
{ /* OpenSIPS module dependencies */
{ MOD_TYPE_DEFAULT, "tls_mgm", DEP_SILENT },
{ MOD_TYPE_NULL, NULL, 0 },
},
{ /* modparam dependencies */
{ "use_tls", get_deps_use_tls },
{ NULL, NULL },
},
};
Expand Down Expand Up @@ -98,19 +112,31 @@ struct module_exports exports = {
static int mod_init(void)
{
LM_INFO("initializing...\n");

if(max_db_queries < 1){
LM_WARN("Invalid number for max_db_queries\n");
max_db_queries = 2;
}


if (use_tls && load_tls_mgm_api(&tls_api) != 0) {
LM_ERR("failed to load tls_mgm API!\n");
return -1;
}

if (use_tls && module_loaded("tls_openssl")) {
LM_ERR("use_tls and tls_openssl are incompatible. Instead, use tls_wolfssl\n");
return -1;
}

return 0;
}

int db_postgres_bind_api(const str* mod, db_func_t *dbb)
{
if(dbb==NULL)
if(!dbb) {
LM_ERR("%.*s dbb parameter is NULL\n", mod->len, mod->s);
return -1;
}

memset(dbb, 0, sizeof(db_func_t));

Expand All @@ -132,4 +158,3 @@ int db_postgres_bind_api(const str* mod, db_func_t *dbb)
dbb->cap |= DB_CAP_MULTIPLE_INSERT;
return 0;
}

4 changes: 4 additions & 0 deletions modules/db_postgres/db_postgres.h
Original file line number Diff line number Diff line change
Expand Up @@ -29,4 +29,8 @@
#define DEFAULT_PSQL_TIMEOUT 5
extern int pq_timeout;

extern int use_tls;

extern struct tls_mgm_binds tls_api;

#endif /* DB_POSTGRES_H */
6 changes: 3 additions & 3 deletions modules/db_postgres/dbase.c
Original file line number Diff line number Diff line change
Expand Up @@ -473,7 +473,7 @@ int db_postgres_free_result(db_con_t* _con, db_res_t* _r)
* _op: operators
* _v: values of the keys that must match
* _c: column names to return
* _n: nmber of key=values pairs to compare
* _n: number of key=values pairs to compare
* _nc: number of columns to return
* _o: order by the specified column
*/
Expand Down Expand Up @@ -503,7 +503,7 @@ int db_postgres_raw_query(const db_con_t* _h, const str* _s, db_res_t** _r)
*
* Input:
* db_con_t* _con Structure representing the database connection
* db_res_t** _r pointer to a structure represending the result set
* db_res_t** _r pointer to a structure representing the result set
*
* Output:
* return 0: If the status of the last command produced a result set and,
Expand All @@ -516,7 +516,7 @@ int db_postgres_raw_query(const db_con_t* _h, const str* _s, db_res_t** _r)
* Notes:
* A new result structure is allocated on every call to this routine.
*
* If this routine returns 0, it is the callers responsbility to free the
* If this routine returns 0, it is the callers' responsibility to free the
* result structure. If this routine returns < 0, then the result structure
* is freed before returning to the caller.
*
Expand Down
3 changes: 0 additions & 3 deletions modules/db_postgres/dbase.h
Original file line number Diff line number Diff line change
Expand Up @@ -42,10 +42,8 @@
/**
* Postgres default timeout
*/
#define DEFAULT_POSTGRES_TIMEOUT 5
extern int pg_timeout;


/**
* Initialize database connection
*/
Expand All @@ -61,7 +59,6 @@ void db_postgres_close(db_con_t* _h);
*/
int db_postgres_store_result(const db_con_t* _h, db_res_t** _r);


/**
* Free all memory allocated by get_result
*/
Expand Down
52 changes: 52 additions & 0 deletions modules/db_postgres/doc/db_postgres_admin.xml
Original file line number Diff line number Diff line change
Expand Up @@ -112,6 +112,58 @@ modparam("db_postgres", "max_db_queries", 2)
...
modparam("db_postgres", "timeout", 2)
...
</programlisting>
</example>
</section>

<section id="param_use_tls" xreflabel="use_tls">
<title><varname>use_tls</varname> (integer)</title>
<para>
Warning: the <emphasis>tls_openssl</emphasis> module cannot be used
when setting this parameter. Use the <emphasis>tls_wolfssl</emphasis>
module instead if a TLS/SSL Library is required.
</para>
<para>
Setting this parameter will allow you to use TLS for PostgreSQL connections.
In order to enable TLS for a specific connection, you can use the
"tls_domain=<emphasis>dom_name</emphasis>" URL parameter in the db_url of
the respective OpenSIPS module. This should be placed at the end of the
URL after the '?' character.
</para>
<para>
When using this parameter, you must also ensure that
<emphasis>tls_mgm</emphasis> is loaded and properly configured. Refer to
the the module for additional info regarding TLS client domains.
</para>
<para>
Note that if you want to use this feature, the TLS domain must be
provisioned in the configuration file, <emphasis>NOT</emphasis> in
the database. In case you are loading TLS certificates from the
database, you must at least define one domain in the
configuration script, to use for the initial connection to the DB.
</para>
<para>
Also, you can <emphasis>NOT</emphasis> enable TLS for the connection
to the database of the <emphasis>tls_mgm</emphasis> module itself.
</para>
<para>
<emphasis>
Default value is <emphasis role='bold'>0</emphasis> (not enabled)
</emphasis>
</para>
<example>
<title>Set the <varname>use_tls</varname> parameter</title>
<programlisting format="linespecific">
...
modparam("tls_mgm", "client_domain", "dom1")
modparam("tls_mgm", "certificate", "[dom1]/etc/pki/tls/certs/opensips.pem")
modparam("tls_mgm", "private_key", "[dom1]/etc/pki/tls/private/opensips.key")
modparam("tls_mgm", "ca_list", "[dom1]/etc/pki/tls/certs/ca.pem")
...
modparam("db_postgres", "use_tls", 1)
...
modparam("usrloc", "db_url", "postgres://root:1234@localhost/opensips?tls_domain=dom1")
...
</programlisting>
</example>
</section>
Expand Down
Loading