<feed xmlns='http://www.w3.org/2005/Atom'>
<title>accel-ppp.git/accel-pppd/ctrl/pppoe, branch master</title>
<subtitle>High performance PPTP/L2TP/SSTP/PPPoE/IPoE server for Linux (mirror of https://github.com/accel-ppp/accel-ppp.git)
</subtitle>
<id>https://git.amelek.net/accel-ppp/accel-ppp.git/atom?h=master</id>
<link rel='self' href='https://git.amelek.net/accel-ppp/accel-ppp.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/'/>
<updated>2026-09-07T19:08:04+00:00</updated>
<entry>
<title>ppp: add remaining discovery and buffer reuse safeguards</title>
<updated>2026-09-07T19:08:04+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-07T19:08:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=7cf7432017bf5386e8b8907aa3abb9e6c45f12bb'/>
<id>urn:sha1:7cf7432017bf5386e8b8907aa3abb9e6c45f12bb</id>
<content type='text'>
Require exactly one PADR Service-Name, drop Echo-Requests exceeding the
negotiated MTU, and clear pooled payloads before reuse. Retain upstream's
silent malformed-PADR rejection and received-packet length checks.

Adapted from Ritika Chopra's accel-ppp-ng PR #40, T8464/T8830.

Co-authored-by: Ritika Chopra &lt;r.chopra@vyos.io&gt;
</content>
</entry>
<entry>
<title>utils: centralize unaligned integer accessors</title>
<updated>2026-09-01T06:08:47+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-01T06:08:47+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=7d4f8524f57ba0ac77e47171bebfc0370df667b1'/>
<id>urn:sha1:7d4f8524f57ba0ac77e47171bebfc0370df667b1</id>
<content type='text'>
</content>
</entry>
<entry>
<title>pppoe: decode tag integers alignment-safely</title>
<updated>2026-09-01T05:55:54+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-01T05:50:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=6c4593a87e689a83d7308efb0913a8dd9182051b'/>
<id>urn:sha1:6c4593a87e689a83d7308efb0913a8dd9182051b</id>
<content type='text'>
Read peer-controlled PPPoE tag and TR-101 integer fields through aligned temporaries, validate PPP-Max-Payload before formatting, and avoid unaligned cookie timestamp accesses.
</content>
</entry>
<entry>
<title>utils: centralize min macro</title>
<updated>2026-08-11T18:42:07+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-11T18:37:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=1c69485e1ebd17bf3cc6e8fc4728f9bdb431de94'/>
<id>urn:sha1:1c69485e1ebd17bf3cc6e8fc4728f9bdb431de94</id>
<content type='text'>
Several userspace translation units carry identical local min() definitions. Move the guarded definition to utils.h and include it from each user so there is one implementation to maintain.

The Linux min() macro lives in kernel-internal headers and is not part of the userspace UAPI. Clang/LLVM does not provide a compatible min macro either: C++ code uses std::min and Clang's similarly named operations use explicit builtin names. The userspace &lt;sys/param.h&gt; interface, where available, exposes uppercase MIN instead.

Keep the #ifndef guard to preserve the behavior of the existing local definitions and avoid redefining a lowercase min macro supplied by an unrelated third-party header.
</content>
</entry>
<entry>
<title>pppoe: check for a truncated tag header in PADI</title>
<updated>2026-08-11T18:29:49+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-11T18:29:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=86e71f2aa48d62e1c63253f0986d5f643410a263'/>
<id>urn:sha1:86e71f2aa48d62e1c63253f0986d5f643410a263</id>
<content type='text'>
The PADI tag loop read tag_len before checking that the tag header itself
fits into the declared payload length, so a PADI ending with a partial tag
made it read up to 2 bytes past the receive buffer. print_packet() and the
PADR loop already have this check, add the missing one.
</content>
</entry>
<entry>
<title>pppoe: account for the tag header in the add_tag2 bound</title>
<updated>2026-08-11T18:29:36+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-11T18:29:36+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=c32518d76569d833b0470633426ebd1f1cf029f4'/>
<id>urn:sha1:c32518d76569d833b0470633426ebd1f1cf029f4</id>
<content type='text'>
add_tag2() checked that the tag payload fits into the packet buffer, but
the memcpy() copied the 4 byte tag header as well, so the check was short
by sizeof(struct pppoe_tag) - 1 bytes.

All callers build the packet in a ETHER_MAX_LEN stack buffer and pass tags
taken from the received discovery packet. A PADI carrying a Host-Uniq tag
of 1454..1456 bytes therefore made pppoe_send_PADO() write up to 3 bytes
of peer supplied data past the end of the buffer. The PADS, PADT and error
paths are affected in the same way.

Include the tag header in the bound, and drop the tag_len &lt; 0 test which
can never be true since ntohs() returns an unsigned value.
</content>
</entry>
<entry>
<title>pppoe: fix use-after-free in mac_filter_load()</title>
<updated>2026-07-06T08:28:53+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-07-06T08:28:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=2ba4437b88dc54ebc5dea6ba1c2007b9cd4aa0e0'/>
<id>urn:sha1:2ba4437b88dc54ebc5dea6ba1c2007b9cd4aa0e0</id>
<content type='text'>
When a mac-filter file line contained an octet &gt; 255, the error path freed
the entry but kept writing to it and linked it into mac_list. Validate all
octets before allocating so invalid lines are skipped entirely.

This is not considered a security vulnerability: the mac-filter file can
only be configured by an administrator with access to the daemon config,
or the CLI, both of which require privileged access.

Fixes #307

Signed-off-by: Denys Fedoryshchenko &lt;denys.f@collabora.com&gt;
</content>
</entry>
<entry>
<title>Merge pull request #323 from nuclearcat/stability-fixes</title>
<updated>2026-06-23T15:58:26+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-06-23T15:58:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=5787a45a952c021f697b31abe0063013912d7c8b'/>
<id>urn:sha1:5787a45a952c021f697b31abe0063013912d7c8b</id>
<content type='text'>
Stability fixes</content>
</entry>
<entry>
<title>Merge pull request #315 from nuclearcat/khedor-fixes</title>
<updated>2026-06-23T15:33:09+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-06-23T15:33:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=6a2dfa19254637ac8d844550d9bd36b7467c181f'/>
<id>urn:sha1:6a2dfa19254637ac8d844550d9bd36b7467c181f</id>
<content type='text'>
Several bugfixes for problems reported by Khodor Tahech </content>
</entry>
<entry>
<title>pppoe: handle missing service-name tag</title>
<updated>2026-06-23T14:36:34+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-06-23T14:30:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=4deb615d7bd7134dd15686b9ea4239f73e20009e'/>
<id>urn:sha1:4deb615d7bd7134dd15686b9ea4239f73e20009e</id>
<content type='text'>
</content>
</entry>
</feed>
