<feed xmlns='http://www.w3.org/2005/Atom'>
<title>accel-ppp.git/accel-pppd, branch master</title>
<subtitle>High performance PPTP/L2TP/SSTP/PPPoE/IPoE server for Linux (mirror of https://github.com/accel-ppp/accel-ppp.git)
</subtitle>
<id>https://git.amelek.net/accel-ppp/accel-ppp.git/atom?h=master</id>
<link rel='self' href='https://git.amelek.net/accel-ppp/accel-ppp.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/'/>
<updated>2026-10-05T23:19:48+00:00</updated>
<entry>
<title>ipv6: remove obsolete three-server DNS limit</title>
<updated>2026-10-05T23:19:48+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-27T06:16:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=2823a07df0c88e9d98472b9248f2e9c3179f6920'/>
<id>urn:sha1:2823a07df0c88e9d98472b9248f2e9c3179f6920</id>
<content type='text'>
The legacy limit matches RFC 6106's recommendation that hosts treat three learned RDNSS addresses as sufficient. That was host-side repository guidance, not a limit in the RADIUS, DHCPv6, or RDNSS encodings.

RFC 8106 obsoletes RFC 6106 and explicitly removes the recommendation to limit learned RDNSS addresses to three, leaving the number to local policy. It instead recommends the ability to store at least three addresses when DNS information comes from multiple sources.

Store both configured and per-session servers in reusable contiguous arrays. Start with a four-address, 64-byte allocation, grow geometrically, retain capacity across reload or reauthorization, and free session storage only at teardown. Bound advertised lists by actual DHCPv6 and router-advertisement packet space.

Warn when servers have to be dropped for lack of room, as the fixed limit used to, skip the DNS search list rather than write it past the end of a full advertisement, and drop the stale three-server wording from the [ipv6-dns] documentation.

Link: https://github.com/accel-ppp/accel-ppp/commit/4f562467dbdf819395e138617c2a057e02595b9e#r197212083
Link: https://www.rfc-editor.org/rfc/rfc6106.html#section-5.3.1
Link: https://www.rfc-editor.org/rfc/rfc8106.html#section-5.3.1
Link: https://www.rfc-editor.org/rfc/rfc8106.html#appendix-A
</content>
</entry>
<entry>
<title>ipv6: use a dedicated type for per-session DNS</title>
<updated>2026-10-05T23:18:41+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-27T06:14:05+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=d8084108cc750962dafcd3716f5d243de2e56418'/>
<id>urn:sha1:d8084108cc750962dafcd3716f5d243de2e56418</id>
<content type='text'>
DNS-Server-IPv6-Address carries a full IPv6 address, so storing it in
ipv6db_addr_t also carried an unused prefix length and flags. Introduce
dedicated DNS list and address types so the representation matches the data.

Suggested-by: Vladislav Grishenko &lt;566150+themiron@users.noreply.github.com&gt;
Link: https://github.com/accel-ppp/accel-ppp/commit/4f562467dbdf819395e138617c2a057e02595b9e#r197215804
</content>
</entry>
<entry>
<title>ipv6_nd: do not overrun the advertisement buffer with prefix information</title>
<updated>2026-10-05T23:18:41+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-27T10:34:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=2600050acd74bf6cea320e8d5f3c7ae09568b062'/>
<id>urn:sha1:2600050acd74bf6cea320e8d5f3c7ae09568b062</id>
<content type='text'>
The prefix information options are written into a fixed 1024 byte pool
buffer with no bound at all, one 32 byte option per address on the
session. A session carrying more than about thirty addresses therefore
writes past the end of the buffer.

Skip the prefix information of the addresses which no longer fit and warn
about them. The loop also installs the addresses on the interface, so keep
doing that regardless of how much room is left in the advertisement.
</content>
</entry>
<entry>
<title>Merge pull request #362 from nuclearcat/fix/ng40-additional-safeguards</title>
<updated>2026-09-28T18:50:27+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-28T18:50:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=50c54c477624d5a9b668225fde2b9844d362760a'/>
<id>urn:sha1:50c54c477624d5a9b668225fde2b9844d362760a</id>
<content type='text'>
Additional safeguards</content>
</entry>
<entry>
<title>utils: centralize max macro</title>
<updated>2026-09-09T15:42:09+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-08-29T23:46:44+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=78d75b1dcf0d42e6ad5ce8b7203a19e17b9c87dc'/>
<id>urn:sha1:78d75b1dcf0d42e6ad5ce8b7203a19e17b9c87dc</id>
<content type='text'>
Closes #354
</content>
</entry>
<entry>
<title>ppp: add remaining discovery and buffer reuse safeguards</title>
<updated>2026-09-07T19:08:04+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-07T19:08:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=7cf7432017bf5386e8b8907aa3abb9e6c45f12bb'/>
<id>urn:sha1:7cf7432017bf5386e8b8907aa3abb9e6c45f12bb</id>
<content type='text'>
Require exactly one PADR Service-Name, drop Echo-Requests exceeding the
negotiated MTU, and clear pooled payloads before reuse. Retain upstream's
silent malformed-PADR rejection and received-packet length checks.

Adapted from Ritika Chopra's accel-ppp-ng PR #40, T8464/T8830.

Co-authored-by: Ritika Chopra &lt;r.chopra@vyos.io&gt;
</content>
</entry>
<entry>
<title>radius: validate VRF names through Access-Accept and CoA</title>
<updated>2026-09-07T19:08:04+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-07T19:08:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=e014cb2cb46f9a5778fbf8a819a1ad263a911c84'/>
<id>urn:sha1:e014cb2cb46f9a5778fbf8a819a1ad263a911c84</id>
<content type='text'>
Reject oversized and embedded-NUL VRF attributes and allocation failures.
Keep explicit CoA lengths, restrict removal to literal 0, and bound the
session API and shared interface lookup. Preserve default VRF removal.

Adapted from Ritika Chopra's accel-ppp-ng PR #40, T8611, with the same
validation boundary extended to the CoA path.

Co-authored-by: Ritika Chopra &lt;r.chopra@vyos.io&gt;
</content>
</entry>
<entry>
<title>radius: authenticate replies against the request on the wire</title>
<updated>2026-09-07T19:08:04+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-07T19:08:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=bd51fe8dbec25b1f130db3b4859895124841cfe8'/>
<id>urn:sha1:bd51fe8dbec25b1f130db3b4859895124841cfe8</id>
<content type='text'>
Verify replies before callbacks and server-health updates. Keep the secret
with the request and centralize accounting signing after server selection,
including retransmits and Accounting-On/Off. Reset the outbound
Message-Authenticator field before recalculating it on retries.

Adapted from Ritika Chopra's accel-ppp-ng PR #40, T8526/T8545, with
upstream's OpenSSL API and secret-reload ownership. Existing accounting
callback lifetime fixes are retained.

Co-authored-by: Ritika Chopra &lt;r.chopra@vyos.io&gt;
</content>
</entry>
<entry>
<title>dhcpv6: reject malformed options and bound relay replies</title>
<updated>2026-09-07T19:08:04+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-07T19:08:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=0648072b19b509fa4ca90664344371d1cfa01935'/>
<id>urn:sha1:0648072b19b509fa4ca90664344371d1cfa01935</id>
<content type='text'>
Reject duplicate Rapid-Commit/AFTR options, validate AFTR labels, and
limit relay nesting. Measure reply space from the allocation, propagate
allocation failure through reply builders, and encode relay lengths correctly.

Adapted from Ritika Chopra's accel-ppp-ng PR #40, T8473/T8474/T8475.
Upstream already has the status, AFTR-printing and inner relay bounds fixes.

Co-authored-by: Ritika Chopra &lt;r.chopra@vyos.io&gt;
</content>
</entry>
<entry>
<title>Merge pull request #359 from nuclearcat/ipcp-ccp-delay-ack</title>
<updated>2026-09-07T17:55:02+00:00</updated>
<author>
<name>Denys Fedoryshchenko</name>
<email>denys.f@collabora.com</email>
</author>
<published>2026-09-07T17:55:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/accel-ppp/accel-ppp.git/commit/?id=c414f0a725a16cbd4c7063ff221dabb420b96df5'/>
<id>urn:sha1:c414f0a725a16cbd4c7063ff221dabb420b96df5</id>
<content type='text'>
Ipcp ccp delay ack</content>
</entry>
</feed>
