<feed xmlns='http://www.w3.org/2005/Atom'>
<title>accel-ppp.git/accel-pppd/ctrl/sstp, branch master</title>
<subtitle>High performance PPTP/L2TP/SSTP/PPPoE/IPoE server for Linux (mirror of https://github.com/accel-ppp/accel-ppp.git)
</subtitle>
<id>https://git.amelek.net/accel-ppp/accel-ppp.git/atom?h=master</id>
<link rel='self' href='https://git.amelek.net/accel-ppp/accel-ppp.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/'/>
<updated>2026-09-09T15:42:09+00:00</updated>
<entry>
<title>utils: centralize max macro</title>
<updated>2026-09-09T15:42:09+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-29T23:46:44+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=78d75b1dcf0d42e6ad5ce8b7203a19e17b9c87dc'/>
<id>urn:sha1:78d75b1dcf0d42e6ad5ce8b7203a19e17b9c87dc</id>
<content type='text'>
Closes #354
</content>
</entry>
<entry>
<title>Merge pull request #352 from nuclearcat/stability-fixes</title>
<updated>2026-08-14T20:04:24+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-14T20:04:24+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=15b4c1dc052f6682a5480d2e8de4b7ab12f5ed8c'/>
<id>urn:sha1:15b4c1dc052f6682a5480d2e8de4b7ab12f5ed8c</id>
<content type='text'>
Stability fixes and function unification</content>
</entry>
<entry>
<title>crypto: drop the dangling crypto.h symlink and its last references</title>
<updated>2026-08-12T07:42:35+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-04T14:50:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=4e36e08e90dbd3c27f566ca396f4284b77f1bf40'/>
<id>urn:sha1:4e36e08e90dbd3c27f566ca396f4284b77f1bf40</id>
<content type='text'>
c912d090 ("crypto: Removed internal tomcat crypto.") deleted the
crypto/ tree but left accel-pppd/include/crypto.h behind, a tracked
symlink to ../../crypto/crypto.h which has pointed at nothing since.

backup_file.c still includes it, so it fails to compile with

  fatal error: crypto.h: No such file or directory

That goes unnoticed because accel-pppd/CMakeLists.txt has
ADD_SUBDIRECTORY(backup) commented out, i.e. backup_file.c is not part
of any build; the breakage only shows up for whoever re-enables it.
Include &lt;openssl/md5.h&gt; instead, which is what the file actually needs
(MD5_CTX and friends) and what c912d090 did for every file it touched.

sstp.c and radius/packet.c defer to crypto.h for the rationale behind
their OPENSSL_API_COMPAT define. Spell it out locally instead, and point
at the project wide ADD_DEFINITIONS() in the top level CMakeLists.txt
added by c1689506 ("openssl: suppress deprecated API warnings"), noting
why the local define is kept despite being redundant with it: it has to
be visible before the first OpenSSL header.

Then remove the symlink, which nothing references anymore.
</content>
</entry>
<entry>
<title>utils: centralize min macro</title>
<updated>2026-08-11T18:42:07+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-11T18:37:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=1c69485e1ebd17bf3cc6e8fc4728f9bdb431de94'/>
<id>urn:sha1:1c69485e1ebd17bf3cc6e8fc4728f9bdb431de94</id>
<content type='text'>
Several userspace translation units carry identical local min() definitions. Move the guarded definition to utils.h and include it from each user so there is one implementation to maintain.

The Linux min() macro lives in kernel-internal headers and is not part of the userspace UAPI. Clang/LLVM does not provide a compatible min macro either: C++ code uses std::min and Clang's similarly named operations use explicit builtin names. The userspace &lt;sys/param.h&gt; interface, where available, exposes uppercase MIN instead.

Keep the #ifndef guard to preserve the behavior of the existing local definitions and avoid redefining a lowercase min macro supplied by an unrelated third-party header.
</content>
</entry>
<entry>
<title>sstp: reject packets shorter than header</title>
<updated>2026-08-09T19:57:20+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-08T23:08:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=1719b4ab756158f4a102bcf5036ff250d67ed015'/>
<id>urn:sha1:1719b4ab756158f4a102bcf5036ff250d67ed015</id>
<content type='text'>
A peer can send an SSTP packet with a zero encoded length and an unknown packet type. The receive dispatcher accepts the unknown type, after which buf_pull() consumes no data and the handler loops forever on the same packet, monopolizing a Triton worker.

Reject all packet lengths smaller than the SSTP header before dispatch so malformed packets close the connection without entering the non-progressing loop.
</content>
</entry>
<entry>
<title>sstp: add ppposeq transport to avoid userspace HDLC framing</title>
<updated>2026-08-04T20:41:46+00:00</updated>
<author>
<name>Vladislav Grishenko</name>
<email>themiron@mail.ru</email>
</author>
<published>2026-07-30T10:48:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=3b08133ee131bca35b10bcc133f6adaf5d125c21'/>
<id>urn:sha1:3b08133ee131bca35b10bcc133f6adaf5d125c21</id>
<content type='text'>
A pty is a byte stream, so the tty flip buffer merges frames written
back to back and sstp has to re-delimit them with async HDLC escaping
and a CRC-16 FCS. On a 1452-byte payload that is ~3600 ns per frame,
most of it spent on the FCS.

PPPOSEQ is a pppox protocol whose socket is the ppp endpoint itself,
so one datagram is one frame and no framing is needed at all. The
same payload takes ~380 ns per frame, about 9 times less. Requires
kernel 2.6.37, the first with PX_MAX_PROTO 3, whose remaining slot
it claims.
Supported kernels are from 2.6.37 to 7.2.

The new ppp-mode option selects the transport; auto, the default,
falls back to async when the module is unavailable, so hosts with
prebuilt kernels are unaffected.

PPP_SYNC is removed, being disabled and unfixable over a pty: frame
boundaries cannot be recovered from the stream, and coalescing cannot
be prevented since frames arrive from the network stack.
</content>
</entry>
<entry>
<title>sstp: enforce standard http replies w/o body</title>
<updated>2026-08-02T15:08:11+00:00</updated>
<author>
<name>Vladislav Grishenko</name>
<email>themiron@mail.ru</email>
</author>
<published>2026-08-02T14:37:05+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=4ac0b4f396825441042ecfbbb3850ce765ae3686'/>
<id>urn:sha1:4ac0b4f396825441042ecfbbb3850ce765ae3686</id>
<content type='text'>
fixes http client warnings (curl):
    &lt; HTTP/1.1 404 Not Found
    &lt; Date: Sun, 02 Aug 2026 14:05:21 GMT
    * no chunk, no close, no size. Assume close to signal end
</content>
</entry>
<entry>
<title>sstp: flush queued output on disconnect</title>
<updated>2026-08-02T14:36:00+00:00</updated>
<author>
<name>Vladislav Grishenko</name>
<email>themiron@mail.ru</email>
</author>
<published>2026-07-26T10:01:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=cbc1527ec446dcaa5b338db1f34d5789a162115c'/>
<id>urn:sha1:cbc1527ec446dcaa5b338db1f34d5789a162115c</id>
<content type='text'>
Drain out_queue to the stream in sstp_disconnect before closing, so a
queued response is sent before the connection is torn down. Best-effort,
non-blocking, via a sstp_flush() helper that mirrors sstp_write.

Fixes: 635ab1b7
</content>
</entry>
<entry>
<title>Revert "Fixes the issue #124 HTTP replay for non SSTP query"</title>
<updated>2026-08-02T14:36:00+00:00</updated>
<author>
<name>Vladislav Grishenko</name>
<email>themiron@mail.ru</email>
</author>
<published>2026-07-26T09:56:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=e9df37a8518548a6de415909eb90466d7a836f5e'/>
<id>urn:sha1:e9df37a8518548a6de415909eb90466d7a836f5e</id>
<content type='text'>
Reverts 635ab1b7, e7a03684, 382b02b6, 4fbba471 on
accel-pppd/ctrl/sstp/sstp.c:

  - http_send_response: sstp_send(buf) || sstp_write(&amp;hnd) -&gt; sstp_send(buf)
  - http_handler: drop the r/return 1 path
  - sstp_read: drop else if (n &gt; 0) return 1
  - remove the sstp_write forward decl
</content>
</entry>
<entry>
<title>sstp: express escape buffer bound as one invariant</title>
<updated>2026-07-26T08:19:24+00:00</updated>
<author>
<name>Vladislav Grishenko</name>
<email>themiron@mail.ru</email>
</author>
<published>2026-07-26T08:19:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=fd2cd2bce6328264ce9cb9bc371d7349319724a8'/>
<id>urn:sha1:fd2cd2bce6328264ce9cb9bc371d7349319724a8</id>
<content type='text'>
(size + PPP_FCSLEN) * 2 + 2 equals 8b781b94's size*2 + 2 + PPP_FCSLEN*2
but can't collapse back to the 1801847a under-allocating form.
</content>
</entry>
</feed>
