<feed xmlns='http://www.w3.org/2005/Atom'>
<title>accel-ppp.git/accel-pppd/radius, branch master</title>
<subtitle>High performance PPTP/L2TP/SSTP/PPPoE/IPoE server for Linux (mirror of https://github.com/accel-ppp/accel-ppp.git)
</subtitle>
<id>https://git.amelek.net/accel-ppp/accel-ppp.git/atom?h=master</id>
<link rel='self' href='https://git.amelek.net/accel-ppp/accel-ppp.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/'/>
<updated>2026-09-28T18:50:27+00:00</updated>
<entry>
<title>Merge pull request #362 from nuclearcat/fix/ng40-additional-safeguards</title>
<updated>2026-09-28T18:50:27+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-28T18:50:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=50c54c477624d5a9b668225fde2b9844d362760a'/>
<id>urn:sha1:50c54c477624d5a9b668225fde2b9844d362760a</id>
<content type='text'>
Additional safeguards</content>
</entry>
<entry>
<title>utils: centralize max macro</title>
<updated>2026-09-09T15:42:09+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-29T23:46:44+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=78d75b1dcf0d42e6ad5ce8b7203a19e17b9c87dc'/>
<id>urn:sha1:78d75b1dcf0d42e6ad5ce8b7203a19e17b9c87dc</id>
<content type='text'>
Closes #354
</content>
</entry>
<entry>
<title>radius: validate VRF names through Access-Accept and CoA</title>
<updated>2026-09-07T19:08:04+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-07T19:08:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=e014cb2cb46f9a5778fbf8a819a1ad263a911c84'/>
<id>urn:sha1:e014cb2cb46f9a5778fbf8a819a1ad263a911c84</id>
<content type='text'>
Reject oversized and embedded-NUL VRF attributes and allocation failures.
Keep explicit CoA lengths, restrict removal to literal 0, and bound the
session API and shared interface lookup. Preserve default VRF removal.

Adapted from Ritika Chopra's accel-ppp-ng PR #40, T8611, with the same
validation boundary extended to the CoA path.

Co-authored-by: Ritika Chopra &lt;r.chopra@vyos.io&gt;
</content>
</entry>
<entry>
<title>radius: authenticate replies against the request on the wire</title>
<updated>2026-09-07T19:08:04+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-07T19:08:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=bd51fe8dbec25b1f130db3b4859895124841cfe8'/>
<id>urn:sha1:bd51fe8dbec25b1f130db3b4859895124841cfe8</id>
<content type='text'>
Verify replies before callbacks and server-health updates. Keep the secret
with the request and centralize accounting signing after server selection,
including retransmits and Accounting-On/Off. Reset the outbound
Message-Authenticator field before recalculating it on retries.

Adapted from Ritika Chopra's accel-ppp-ng PR #40, T8526/T8545, with
upstream's OpenSSL API and secret-reload ownership. Existing accounting
callback lifetime fixes are retained.

Co-authored-by: Ritika Chopra &lt;r.chopra@vyos.io&gt;
</content>
</entry>
<entry>
<title>utils: centralize unaligned integer accessors</title>
<updated>2026-09-01T06:08:47+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-01T06:08:47+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=7d4f8524f57ba0ac77e47171bebfc0370df667b1'/>
<id>urn:sha1:7d4f8524f57ba0ac77e47171bebfc0370df667b1</id>
<content type='text'>
</content>
</entry>
<entry>
<title>backup: restore scalar fields alignment-safely</title>
<updated>2026-09-01T05:55:54+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-01T05:50:26+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=cbbae583e584f83957acd99440fc67343d46b800'/>
<id>urn:sha1:cbbae583e584f83957acd99440fc67343d46b800</id>
<content type='text'>
Use memcpy for scalar backup headers and restored session, pool, and RADIUS values because variable-length tags do not guarantee native integer alignment.
</content>
</entry>
<entry>
<title>radius: harden packet integer decoding</title>
<updated>2026-09-01T05:55:54+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-01T05:50:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=e0c63e6259bb4a75468e5680fb2d10934c2d035b'/>
<id>urn:sha1:e0c63e6259bb4a75468e5680fb2d10934c2d035b</id>
<content type='text'>
Serialize integer fields via memcpy, restrict attribute parsing to the RADIUS header's declared packet length, reject undersized packet lengths, and reject truncated attribute headers.
</content>
</entry>
<entry>
<title>ipv6: assign DNS servers per session from RADIUS</title>
<updated>2026-08-12T07:42:35+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-04T15:39:51+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=58ef850d1705d88f006d761d32c55bde5205a27d'/>
<id>urn:sha1:58ef850d1705d88f006d761d32c55bde5205a27d</id>
<content type='text'>
The ipv6_nd and ipv6_dhcp modules could only advertise the DNS servers
configured in [ipv6-dns], the same set for every subscriber. RFC 6911
defines DNS-Server-IPv6-Address (attribute 169) for exactly this, and
the attribute was already in the shipped dictionary and in attr_defs.h;
nothing read it.

Give struct ap_session an ipv6_dns list, filled by the radius module
from that attribute, and have both modules advertise it when the session
has one: in the RDNSS option of the router advertisements, and in the
DNS_SERVERS option of DHCPv6 replies. Sessions without a list of their
own keep getting the configured servers, so nothing changes for anyone
not sending the attribute.

The selection is a single ipv6_dns_get() shared by both modules rather
than a copy in each: they already duplicate the whole [ipv6-dns] parser,
and two copies of a precedence rule are two chances to drift. It caps
what it returns, so neither the RDNSS option length (one byte, in units
of 8) nor the router advertisement buffer can be pushed around by what a
RADIUS server sends. The radius module caps at the same 3 servers as
[ipv6-dns] accepts and warns once when a reply carries more.

An Access-Accept which carries the attribute replaces the whole
previously assigned list rather than appending to it, so a re-authorized
session ends up with the servers of the latest reply and not with a
concatenation. One which does not carry it leaves the current list
alone, which is how the IPv4 MS-Primary-DNS-Server attribute already
behaves.

ipv6_dns_test.c covers the selection: assigned wins over configured,
empty list means "nothing assigned" rather than "no DNS", the cap holds
for both sources, and a caller with no room gets nothing rather than a
stomped buffer. Wired into the ASAN/UBSAN workflow.

Inspired by the per-session IPv6 DNS support in accel-ppp-ng (commit
2df6eb99), reimplemented against mainline's ap_session and ipdb types.
</content>
</entry>
<entry>
<title>crypto: drop the dangling crypto.h symlink and its last references</title>
<updated>2026-08-12T07:42:35+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-04T14:50:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=4e36e08e90dbd3c27f566ca396f4284b77f1bf40'/>
<id>urn:sha1:4e36e08e90dbd3c27f566ca396f4284b77f1bf40</id>
<content type='text'>
c912d090 ("crypto: Removed internal tomcat crypto.") deleted the
crypto/ tree but left accel-pppd/include/crypto.h behind, a tracked
symlink to ../../crypto/crypto.h which has pointed at nothing since.

backup_file.c still includes it, so it fails to compile with

  fatal error: crypto.h: No such file or directory

That goes unnoticed because accel-pppd/CMakeLists.txt has
ADD_SUBDIRECTORY(backup) commented out, i.e. backup_file.c is not part
of any build; the breakage only shows up for whoever re-enables it.
Include &lt;openssl/md5.h&gt; instead, which is what the file actually needs
(MD5_CTX and friends) and what c912d090 did for every file it touched.

sstp.c and radius/packet.c defer to crypto.h for the rationale behind
their OPENSSL_API_COMPAT define. Spell it out locally instead, and point
at the project wide ADD_DEFINITIONS() in the top level CMakeLists.txt
added by c1689506 ("openssl: suppress deprecated API warnings"), noting
why the local define is kept despite being redundant with it: it has to
be visible before the first OpenSSL header.

Then remove the symlink, which nothing references anymore.
</content>
</entry>
<entry>
<title>radius: fix request slot leak when queued request wakeup fails</title>
<updated>2026-07-06T09:45:36+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-07-06T09:43:08+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=1a9923a07c1283b30a5b02a1668f57015f26232e'/>
<id>urn:sha1:1a9923a07c1283b30a5b02a1668f57015f26232e</id>
<content type='text'>
req_wakeup() ignored the return value of req-&gt;send(req, 1). When a
request dequeued from the req-limit queue failed at socket setup
(__rad_req_send returns -2, e.g. under ephemeral port exhaustion or a
routing error), the server's req_cnt slot taken in
rad_server_req_exit() was never released and the request was orphaned
with no callback and no timer.

Leaked slots accumulate until req_cnt permanently saturates req-limit,
after which every request queues forever and the server is effectively
dead until restart.

Handle -2 the same way rad_server_req_enter() does: release the slot,
mark the server failed and drive the request through the regular
failover path so it either retries on another server or reports the
failure to its owner.

Signed-off-by: Denys Fedoryshchenko &lt;denys.f@collabora.com&gt;
</content>
</entry>
</feed>
