| Age | Commit message (Collapse) | Author |
|
ci: add tests execution with asan and ubsan
|
|
|
|
ci: add build in debian:forky container
|
|
|
|
feat(build): Add MUSL detection and conditional linking
|
|
cmd: implement show ippool command
|
|
ipoe: dhcp: Fix username for noauth session
|
|
This commit introduces the ability to detect if the project is being
built with the MUSL C library.
A new variable `MUSL` is set to `ON` if MUSL is detected, and `OFF`
otherwise. This is achieved by checking the output of `ldd --version`.
The `accel-pppd/ctrl/pppoe/CMakeLists.txt` file is updated to
conditionally link the `connlimit` library only when building with MUSL.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
|
|
Command Usage:
accel-ppp# show ippool
IP Pool Usage Report
====================
<default>
total: 16384
used: 0
available: 16384
usage: 0%
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Add RADIUS blast attack protection with Message-Authenticator
|
|
ci: add fedora:rawhide build to build with latest kernel
|
|
|
|
Recently FreeRadius started to complain accel-ppp doesn't pass
BlastRADIUS check. This commit fixes that.
This commit implements protection against RADIUS blast attacks
by adding support for the Message-Authenticator attribute in
Access-Request packets. This security enhancement helps
prevent unauthorized access attempts and replay attacks
on RADIUS authentication.
- Added new configuration option `blast-protection=1`
in [radius] to enable Message-Authenticator inclusion
- Implemented HMAC-MD5 calculation for
Message-Authenticator attribute (RFC 2869)
- Modified packet building to include 18-byte Message-Authenticator
attribute when enabled
- Updated packet structure to support signing with shared secret
Enable blast protection by adding to the `[radius]` section:
```
blast-protection=1
```
When enabled, all Access-Request packets will include a
Message-Authenticator attribute with HMAC-MD5 signature,
providing cryptographic integrity verification and protection
against packet modification attacks.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Add build fixes
|
|
NETIF_F_NETNS_LOCAL existed in <=6.11, then converted to
dev->netns_local, and then renamed to netns_immutable in
0c493da86374dffff7505e67289ad75b21f5b301.
This commit address this properly.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
del_timer() was renamed to timer_delete() by commit bb663f0f3c396c6d
(“timers: Rename del_timer() to timer_delete()”) authored by Thomas Gleixner
on 23 Nov 2022, merged via the timers/core branch and included in the Linux
6.2-rc1 merge window; the change therefore reached users with the Linux 6.2
final release on 19 Feb 2023.
(The legacy inline wrappers del_timer() / del_timer_sync() stayed in place
for compatibility until they were dropped by the tree-wide cleanup commit
8fa7292fee5c on 5 Apr 2025, merged for Linux 6.15-rc1.)
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
ci: remove ubuntu 20 builds due to EOL of Standard Support
|
|
|
|
(workflows): Ubuntu 20.04 is deprecated, removing it
|
|
ipoe: fixed DHCP option 42 (ntp servers)
|
|
This tests failing now with following message:
```
This is a scheduled Ubuntu 20.04 retirement.
Ubuntu 20.04 LTS runner will be removed on 2025-04-15.
For more details, see https://github.com/actions/runner-images/issues/11101
```
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
|
|
Allowed using multiple NTP servers in DHCP option 42
|
|
L2TP include calling number to calling station ID RA
|
|
ipv6: Add DHCPv6 Confirm processing
|
|
|
|
ci: update alpine links
|
|
|
|
|
|
ci: run tests on x86_32 platform (alpine vm)
|
|
ipoe: fix driver for kernel 6.12 (NETIF_F_NETNS_LOCAL)
|
|
Closes: https://github.com/accel-ppp/accel-ppp/issues/217
Ref: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=05c1280a2bcfca187fe7fa90bb240602cf54af0a
Ref: https://github.com/torvalds/linux/commit/05c1280a2bcfca187fe7fa90bb240602cf54af0a
Reported-By: https://github.com/axe-kenig
|
|
|
|
ci: fix build on alpine be (s390x)
|
|
ci: add build in ubuntu:devel container
|
|
bump libpcre, disable chap_secrets in tests
|
|
Building in ubuntu:devel container might help to find the issues
related to newest kernels and other software updates
|
|
tests,ci: disable chap-secrets related tests on alpine
|
|
radius and chap-secrets can't work together due to musl library limiations
This patch disables chap-secrets related tests on alpine
ref: https://github.com/accel-ppp/accel-ppp/pull/190#issuecomment-2331036461
|
|
tests: add ipoe shared + chap-secrets auth, add ipoe+chap-secrets + lua
|
|
|
|
Fix post_msg implementation bug
|
|
ci: run tests on alpine s390x (big-endian)
|
|
I think the error handling code of `post_msg` is wrongly implemented due to coding typo. The `EPIPE` should be also considered and then return -1, just like `PPTP_write`:
https://github.com/xebd/accel-ppp/blob/1b8711cf75a7c278d99840112bc7a396398e0205/accel-pppd/ctrl/pptp/pptp.c#L539-L570
|
|
ci: fix testing on debian13 (pytest install issues)
|
|
|
|
migrate from pcre to pcre2
|
|
build: fix build for entware (HAVE_GOOD_IFARP detection issue)
|
|
pppd_compat: add Framed-Interface-Id attribute support in radattr
|