| Age | Commit message (Collapse) | Author |
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
pppoe: Fix RFC2516 non-compilance in PADI tags parsing
|
|
acct: Fix losing some data on interface down due wrong sequence
|
|
Ensure accounting values include the most recent traffic sample when a session disconnects,
preventing the final interval from being dropped and avoiding under-reported totals in usage/billing.
Big thanks Dmitriy Eshenko for patch and testing
Author: Dmitriy Eshenko <dmitriy.eshenko@accel-ppp.org>
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
We currently only break out of the switch, so the for loop keeps parsing tags after TAG_END_OF_LIST (accel-pppd/ctrl/pppoe/pppoe.c: around pppoe_recv_PADI).
RFC 2516 (paragraph 5, Tag Types: End-of-List) says an End-of-List tag MAY appear in PADI/PADR and "any TAGs after an End-of-List MUST be ignored."
Since we continue processing them, this behavior is technically non-compliant with the RFC.
Same in pppoe_recv_PADR.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
OpenSSL is now mandatory.
Signed-off-by: Andrii Melnychenko <a.melnychenko@vyos.io>
|
|
Signed-off-by: Andrii Melnychenko <a.melnychenko@vyos.io>
|
|
auth_chap_md5: unused variable, mschap_error likely copy paste error, plain chap dont have errors like mschap
|
|
Sstp improvements
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
l2tp: fix buffer overflow and type errors in Calling/Called Number handling
|
|
chap dont have errors like mschap
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Suppress OpenSSL 3.0 deprecation warnings for legacy crypto APIs
|
|
Fix issues introduced in 88a2ebdb:
- Fix type declaration: uint8_t *calling[254] declared an array of 254
pointers instead of an array of 254 bytes. Remove erroneous asterisks.
- Fix buffer overflow vulnerability: L2TP AVP values can be up to 1017
bytes (L2TP_AVP_LEN_MASK - sizeof(avp_header)), but buffers were only
254(*4?) bytes. A malicious packet could cause stack buffer overflow.
Use L2TP_AVP_LEN_MASK (1023) for buffer size to handle maximum AVP length.
- Remove useless NULL checks: Stack-allocated arrays can never be NULL,
causing compiler warnings. The existence check is n > 0 / m > 1.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Not a bug, but to supress warnings.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
We are using similar approach as in other projects, easiest one,
but probably in future it will break as soon as this functions
will be removed completely.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
mempool: Fix 32-bit stats
|
|
docs: Improve ippool documentation
|
|
Improve ippool documentation based on users feedback.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
We are living in 64-bit world long time, so there is very likely mempool
stats might overflow past 4GB and report incorrect values.
Updated mempool stats to use 64-bit counters so they don’t
wrap past 4 GB and print correctly in CLI.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
This is follow-up for https://github.com/accel-ppp/accel-ppp/pull/238
Adding missing documentation update.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
SSTP: load certificate chain instead of single one
|
|
Added an explicit break after handling TAG_VENDOR_SPECIFIC,
so vendor-specific PADR tags (e.g., TR-101) no longer fall
through and get misinterpreted as other tags like TAG_PPP_MAX_PAYLOAD.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
|
|
feat(build): Add MUSL detection and conditional linking
|
|
cmd: implement show ippool command
|
|
This commit introduces the ability to detect if the project is being
built with the MUSL C library.
A new variable `MUSL` is set to `ON` if MUSL is detected, and `OFF`
otherwise. This is achieved by checking the output of `ldd --version`.
The `accel-pppd/ctrl/pppoe/CMakeLists.txt` file is updated to
conditionally link the `connlimit` library only when building with MUSL.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
|
|
Command Usage:
accel-ppp# show ippool
IP Pool Usage Report
====================
<default>
total: 16384
used: 0
available: 16384
usage: 0%
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Recently FreeRadius started to complain accel-ppp doesn't pass
BlastRADIUS check. This commit fixes that.
This commit implements protection against RADIUS blast attacks
by adding support for the Message-Authenticator attribute in
Access-Request packets. This security enhancement helps
prevent unauthorized access attempts and replay attacks
on RADIUS authentication.
- Added new configuration option `blast-protection=1`
in [radius] to enable Message-Authenticator inclusion
- Implemented HMAC-MD5 calculation for
Message-Authenticator attribute (RFC 2869)
- Modified packet building to include 18-byte Message-Authenticator
attribute when enabled
- Updated packet structure to support signing with shared secret
Enable blast protection by adding to the `[radius]` section:
```
blast-protection=1
```
When enabled, all Access-Request packets will include a
Message-Authenticator attribute with HMAC-MD5 signature,
providing cryptographic integrity verification and protection
against packet modification attacks.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
|
|
Allowed using multiple NTP servers in DHCP option 42
|
|
L2TP include calling number to calling station ID RA
|
|
|
|
|
|
I think the error handling code of `post_msg` is wrongly implemented due to coding typo. The `EPIPE` should be also considered and then return -1, just like `PPTP_write`:
https://github.com/xebd/accel-ppp/blob/1b8711cf75a7c278d99840112bc7a396398e0205/accel-pppd/ctrl/pptp/pptp.c#L539-L570
|
|
migrate from pcre to pcre2
|
|
build: fix build for entware (HAVE_GOOD_IFARP detection issue)
|
|
pppd_compat: add Framed-Interface-Id attribute support in radattr
|