<feed xmlns='http://www.w3.org/2005/Atom'>
<title>accel-ppp.git/accel-pppd/ppp, branch master</title>
<subtitle>High performance PPTP/L2TP/SSTP/PPPoE/IPoE server for Linux (mirror of https://github.com/accel-ppp/accel-ppp.git)
</subtitle>
<id>https://git.amelek.net/accel-ppp/accel-ppp.git/atom?h=master</id>
<link rel='self' href='https://git.amelek.net/accel-ppp/accel-ppp.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/'/>
<updated>2026-09-07T19:08:04+00:00</updated>
<entry>
<title>ppp: add remaining discovery and buffer reuse safeguards</title>
<updated>2026-09-07T19:08:04+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-07T19:08:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=7cf7432017bf5386e8b8907aa3abb9e6c45f12bb'/>
<id>urn:sha1:7cf7432017bf5386e8b8907aa3abb9e6c45f12bb</id>
<content type='text'>
Require exactly one PADR Service-Name, drop Echo-Requests exceeding the
negotiated MTU, and clear pooled payloads before reuse. Retain upstream's
silent malformed-PADR rejection and received-packet length checks.

Adapted from Ritika Chopra's accel-ppp-ng PR #40, T8464/T8830.

Co-authored-by: Ritika Chopra &lt;r.chopra@vyos.io&gt;
</content>
</entry>
<entry>
<title>Merge pull request #359 from nuclearcat/ipcp-ccp-delay-ack</title>
<updated>2026-09-07T17:55:02+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-07T17:55:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=c414f0a725a16cbd4c7063ff221dabb420b96df5'/>
<id>urn:sha1:c414f0a725a16cbd4c7063ff221dabb420b96df5</id>
<content type='text'>
Ipcp ccp delay ack</content>
</entry>
<entry>
<title>ppp: say why a malformed ConfReq drops the session</title>
<updated>2026-09-01T06:32:30+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-01T06:32:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=4654c4a9c083780f5e151ee064e69a357c48d364'/>
<id>urn:sha1:4654c4a9c083780f5e151ee064e69a357c48d364</id>
<content type='text'>
The option walkers of lcp_recv_conf_req() and its IPCP, IPV6CP and CCP
counterparts bail out with *_OPT_FAIL as soon as an option header does not
fit in the remaining bytes or carries an impossible length, and the caller
turns that into ap_session_terminate(TERM_USER_ERROR).

The bail out happens before the "recv [LCP ConfReq id=..." line is emitted,
so the session simply disappeared with nothing in the log to point at the
peer. The ConfAck, ConfNak and ConfRej walkers break out of their loop
instead and at least close the line they had already started.

Log the offending length, option id and the number of bytes left before
returning, so a peer sending malformed options can be told apart from the
other reasons a session ends with TERM_USER_ERROR.
</content>
</entry>
<entry>
<title>ppp: bound IPCP and IPV6CP packets by the received size</title>
<updated>2026-09-01T06:31:53+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-01T06:31:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=d22666a84cc38b8018d839483db5df125fc6728b'/>
<id>urn:sha1:d22666a84cc38b8018d839483db5df125fc6728b</id>
<content type='text'>
ipcp_recv() and ipv6cp_recv() only rejected packets whose header length
field was below PPP_HEADERLEN. The upper bound was missing, so the option
walker was handed a size derived purely from the peer chosen hdr-&gt;len.

ppp-&gt;buf is a fixed 8192 byte mempool block and ppp-&gt;buf_size holds the
number of bytes actually read, so a short frame declaring hdr-&gt;len 0xffff
made the option loop run off the end of the block: it kept fetching option
headers from whatever followed in the heap and stored pointers to them in
the ropt list. The read is harmless in itself but easily reaches unmapped
memory and kills the daemon.

Reject any packet whose declared length does not fit in what was received,
the way lcp_recv() and ccp_recv() already do. The two byte slack accounts
for the protocol field that precedes the header inside the buffer, and the
existing buf_size &gt;= PPP_HEADERLEN + 2 test just above keeps the
subtraction from underflowing.
</content>
</entry>
<entry>
<title>utils: centralize unaligned integer accessors</title>
<updated>2026-09-01T06:08:47+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-01T06:08:47+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=7d4f8524f57ba0ac77e47171bebfc0370df667b1'/>
<id>urn:sha1:7d4f8524f57ba0ac77e47171bebfc0370df667b1</id>
<content type='text'>
</content>
</entry>
<entry>
<title>ipv6: avoid integer access through address bytes</title>
<updated>2026-09-01T05:55:54+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-01T05:50:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=004ec5adc7e5702c518583caef437d304932beb5'/>
<id>urn:sha1:004ec5adc7e5702c518583caef437d304932beb5</id>
<content type='text'>
Copy interface IDs and prefix words between aligned temporaries and byte arrays instead of casting IPv6 address storage to uint64_t pointers.
</content>
</entry>
<entry>
<title>ppp: cover alignment-safe MPPE prefer setup</title>
<updated>2026-09-01T05:53:54+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-01T05:44:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=d70fc819a4f7f0b54b374bfdae062e3c7d2d3cc6'/>
<id>urn:sha1:d70fc819a4f7f0b54b374bfdae062e3c7d2d3cc6</id>
<content type='text'>
Serialize the MPPE option through an aligned temporary and exercise mppe=prefer in the existing unauthenticated PPPoE session test.
</content>
</entry>
<entry>
<title>ppp: harden control packet decoding</title>
<updated>2026-09-01T05:53:54+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-01T05:43:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=028b942d2daa57b56efd61cb5cb348017fad6f05'/>
<id>urn:sha1:028b942d2daa57b56efd61cb5cb348017fad6f05</id>
<content type='text'>
Bound LCP and CCP declared lengths by the received frame, reject truncated option headers across all control protocols, and decode LCP payload integers without alignment assumptions. IPCP and IPv6CP outer frame bounds remain owned by the delayed-ack change in PR #359.
</content>
</entry>
<entry>
<title>ppp: do not answer IPCP/IPV6CP ConfReq with TermAck while CCP negotiates</title>
<updated>2026-09-01T04:13:12+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-31T23:49:13+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=354eb9214483949e86f0f8b66a531def30205646'/>
<id>urn:sha1:354eb9214483949e86f0f8b66a531def30205646</id>
<content type='text'>
When the peer's IPCP (or IPV6CP) ConfReq arrives before CCP negotiation
has finished, delay_ack is set and send_conf_ack() answers with a TermAck
instead of the ConfAck. A TermAck is only a valid response to a TermReq,
and the trick relies on the peer retransmitting its ConfReq: conformant
peers recover only after their restart timer (3 seconds added to session
setup), while some clients (MikroTik RouterOS over L2TP, see issue #353)
treat it as a failure and drop the session.

Withhold the ConfAck instead and send it as soon as CCP settles. CCP now
notifies IPCP/IPV6CP when it comes up or gives up (passive); that clears
delay_ack, brings the layer up if the FSM is already Opened, and flushes
the withheld ConfAck. Nothing is sent to the peer while CCP is still in
progress, so IP data cannot flow before MPPE is set up.

Verified with pppoe + mschap-v2: with mppe=prefer and a client that does
not require MPPE, the peer's ConfReq used to be answered with a TermAck
and the session came up 3 seconds later; now the ConfAck is emitted right
after ccp_layer_started and the session comes up immediately. mppe=require
and mppe=deny sessions are unaffected.
</content>
</entry>
<entry>
<title>utils: centralize min macro</title>
<updated>2026-08-11T18:42:07+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-11T18:37:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=1c69485e1ebd17bf3cc6e8fc4728f9bdb431de94'/>
<id>urn:sha1:1c69485e1ebd17bf3cc6e8fc4728f9bdb431de94</id>
<content type='text'>
Several userspace translation units carry identical local min() definitions. Move the guarded definition to utils.h and include it from each user so there is one implementation to maintain.

The Linux min() macro lives in kernel-internal headers and is not part of the userspace UAPI. Clang/LLVM does not provide a compatible min macro either: C++ code uses std::min and Clang's similarly named operations use explicit builtin names. The userspace &lt;sys/param.h&gt; interface, where available, exposes uppercase MIN instead.

Keep the #ifndef guard to preserve the behavior of the existing local definitions and avoid redefining a lowercase min macro supplied by an unrelated third-party header.
</content>
</entry>
</feed>
