<feed xmlns='http://www.w3.org/2005/Atom'>
<title>accel-ppp.git/accel-pppd/ctrl/pppoe, branch sstp-alloc-invariant</title>
<subtitle>High performance PPTP/L2TP/SSTP/PPPoE/IPoE server for Linux (mirror of https://github.com/accel-ppp/accel-ppp.git)
</subtitle>
<id>https://git.amelek.net/accel-ppp/accel-ppp.git/atom?h=sstp-alloc-invariant</id>
<link rel='self' href='https://git.amelek.net/accel-ppp/accel-ppp.git/atom?h=sstp-alloc-invariant'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/'/>
<updated>2026-07-06T08:28:53+00:00</updated>
<entry>
<title>pppoe: fix use-after-free in mac_filter_load()</title>
<updated>2026-07-06T08:28:53+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-07-06T08:28:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=2ba4437b88dc54ebc5dea6ba1c2007b9cd4aa0e0'/>
<id>urn:sha1:2ba4437b88dc54ebc5dea6ba1c2007b9cd4aa0e0</id>
<content type='text'>
When a mac-filter file line contained an octet &gt; 255, the error path freed
the entry but kept writing to it and linked it into mac_list. Validate all
octets before allocating so invalid lines are skipped entirely.

This is not considered a security vulnerability: the mac-filter file can
only be configured by an administrator with access to the daemon config,
or the CLI, both of which require privileged access.

Fixes #307

Signed-off-by: Denys Fedoryshchenko &lt;denys.f@collabora.com&gt;
</content>
</entry>
<entry>
<title>Merge pull request #323 from nuclearcat/stability-fixes</title>
<updated>2026-06-23T15:58:26+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-06-23T15:58:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=5787a45a952c021f697b31abe0063013912d7c8b'/>
<id>urn:sha1:5787a45a952c021f697b31abe0063013912d7c8b</id>
<content type='text'>
Stability fixes</content>
</entry>
<entry>
<title>Merge pull request #315 from nuclearcat/khedor-fixes</title>
<updated>2026-06-23T15:33:09+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-06-23T15:33:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=6a2dfa19254637ac8d844550d9bd36b7467c181f'/>
<id>urn:sha1:6a2dfa19254637ac8d844550d9bd36b7467c181f</id>
<content type='text'>
Several bugfixes for problems reported by Khodor Tahech </content>
</entry>
<entry>
<title>pppoe: handle missing service-name tag</title>
<updated>2026-06-23T14:36:34+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-06-23T14:30:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=4deb615d7bd7134dd15686b9ea4239f73e20009e'/>
<id>urn:sha1:4deb615d7bd7134dd15686b9ea4239f73e20009e</id>
<content type='text'>
</content>
</entry>
<entry>
<title>openssl: suppress deprecated API warnings</title>
<updated>2026-06-10T18:28:29+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-06-10T14:15:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=c1689506bbc27f498612ca69648876599ded7d7c'/>
<id>urn:sha1:c1689506bbc27f498612ca69648876599ded7d7c</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Rejecting any PADR lacking a Service-Name tag (RFC 2516 compliance)</title>
<updated>2026-05-29T05:58:41+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-05-29T05:58:41+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=f8dfbeca348d9f4eb794cdf3756a94f2d0acc730'/>
<id>urn:sha1:f8dfbeca348d9f4eb794cdf3756a94f2d0acc730</id>
<content type='text'>
Signed-off-by: Denys Fedoryshchenko &lt;denys.f@collabora.com&gt;
</content>
</entry>
<entry>
<title>pppoe/disc: drop packets with unsupported PPPoE type</title>
<updated>2026-05-23T08:41:36+00:00</updated>
<author>
<name>khedor</name>
<email>khedor@gmail.com</email>
</author>
<published>2026-05-22T17:15:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=028e2090389d2b8968dfb30e4d956264718613e5'/>
<id>urn:sha1:028e2090389d2b8968dfb30e4d956264718613e5</id>
<content type='text'>
The unsupported-PPPoE-type branch in disc_read() logs a warning but
falls through to forward() instead of dropping the packet. Compare
with the unsupported-version branch immediately above, which has the
same shape but continues:

    if (hdr-&gt;ver != 1) {
        if (conf_verbose)
            log_warn(...unsupported version...);
        continue;
    }

    if (hdr-&gt;type != 1) {
        if (conf_verbose)
            log_warn(...unsupported type...);
        /* falls through into forward() */
    }

Add the missing continue so malformed packets are dropped instead of
processed.

Signed-off-by: khedor &lt;khedor@gmail.com&gt;
</content>
</entry>
<entry>
<title>pppoe/disc: fix free_net memmove count and overlap handling</title>
<updated>2026-05-23T08:41:36+00:00</updated>
<author>
<name>khedor</name>
<email>khedor@gmail.com</email>
</author>
<published>2026-05-22T17:15:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=a68821aecb2fecfc7c35fd5d49867f202d64df7f'/>
<id>urn:sha1:a68821aecb2fecfc7c35fd5d49867f202d64df7f</id>
<content type='text'>
free_net() compacts the nets[] array by sliding entries left after
removing one:

    memcpy(nets + i, nets + i + 1, net_cnt - i - 1);

Two bugs:

  1. The count is a raw element count, not a byte count. nets[] holds
     'struct disc_net *' pointers, so only (net_cnt - i - 1) bytes are
     moved instead of (net_cnt - i - 1) * sizeof(nets[0]). On the usual
     8-byte-pointer build, 7 of every 8 surviving pointers are lost,
     leaving uninitialised holes in the array.

  2. Source and destination overlap (nets + i and nets + i + 1), so
     memcpy is undefined behaviour. The correct primitive is memmove.

Switch to memmove and multiply the count by sizeof(nets[0]).

Signed-off-by: khedor &lt;khedor@gmail.com&gt;
</content>
</entry>
<entry>
<title>pppoe/disc: fix init_net allocation size</title>
<updated>2026-05-23T08:41:36+00:00</updated>
<author>
<name>khedor</name>
<email>khedor@gmail.com</email>
</author>
<published>2026-05-22T17:14:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=4823556fbbadcd5205175d423ebca627dc317843'/>
<id>urn:sha1:4823556fbbadcd5205175d423ebca627dc317843</id>
<content type='text'>
In init_net(), the buffer for struct disc_net was sized as

    n = _malloc(sizeof(*net) + (HASH_BITS + 1) * sizeof(struct tree));

but 'net' is the const struct ap_net * argument, not the disc_net being
allocated. sizeof(*net) is therefore sizeof(struct ap_net), which is
substantially smaller than sizeof(struct disc_net). Every field of *n
written past the ap_net-sized prefix (ctx, hnd, net, refs, etc.) lands
in unallocated heap memory.

Use sizeof(*n) so the allocation matches the actual destination type.

Signed-off-by: khedor &lt;khedor@gmail.com&gt;
</content>
</entry>
<entry>
<title>strip: Fix invalid parsing</title>
<updated>2026-05-21T12:50:42+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-05-21T12:50:42+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=1b67ba0785a847eee6adb69b7e68995c33803805'/>
<id>urn:sha1:1b67ba0785a847eee6adb69b7e68995c33803805</id>
<content type='text'>
strip() memmove count was one short, dropping the NULL  terminator;
dpado_parse error path leaked already-parsed range entries.
Also affects ipoe.

Since strip is identical in both, we can place fixed common function in utils.

Reported-by: Khedor &lt;khedor@gmail.com&gt;
Signed-off-by: Denys Fedoryshchenko &lt;denys.f@collabora.com&gt;
</content>
</entry>
</feed>
