summaryrefslogtreecommitdiff
path: root/src/migration-scripts
diff options
context:
space:
mode:
authorRitika Chopra <r.chopra@vyos.io>2026-06-16 00:31:22 -0500
committerRitika Chopra <r.chopra@vyos.io>2026-08-12 14:50:20 -0700
commitf55f1ed843894a7eb63bec6de1bbcead9417b67a (patch)
treea6037f98e40e805a467b2dd059ca9094713cd5f5 /src/migration-scripts
parent28ea92afb73a6627c2050474187ace25bb5e3e4e (diff)
downloadvyos-1x-f55f1ed843894a7eb63bec6de1bbcead9417b67a.tar.gz
vyos-1x-f55f1ed843894a7eb63bec6de1bbcead9417b67a.zip
T8598: Accel-PPP: Add upgrade-safe migration support for calling-sid peer IID secret enforcement across PPPoE, L2TP, PPTP, and SSTP (BP 2188)
(cherry picked from commit c9314daa78418751edaab9b4da8c2e33fb1a64ed)
Diffstat (limited to 'src/migration-scripts')
-rw-r--r--src/migration-scripts/l2tp/9-to-1041
-rw-r--r--src/migration-scripts/pppoe-server/12-to-1341
-rw-r--r--src/migration-scripts/pptp/5-to-641
-rw-r--r--src/migration-scripts/sstp/6-to-741
4 files changed, 164 insertions, 0 deletions
diff --git a/src/migration-scripts/l2tp/9-to-10 b/src/migration-scripts/l2tp/9-to-10
new file mode 100644
index 000000000..84a0a65c9
--- /dev/null
+++ b/src/migration-scripts/l2tp/9-to-10
@@ -0,0 +1,41 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# Backfill IPv6 peer IID secret for legacy calling-sid configuration.
+
+from secrets import token_hex
+
+from vyos.configtree import ConfigTree
+
+base = ['vpn', 'l2tp', 'remote-access']
+peer_id_path = base + ['ppp-options', 'ipv6-peer-interface-id']
+peer_id_secret_path = base + ['ppp-options', 'ipv6-peer-interface-id-secret']
+
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ return
+
+ if not config.exists(peer_id_path):
+ return
+
+ if config.return_value(peer_id_path) != 'calling-sid':
+ return
+
+ if config.exists(peer_id_secret_path):
+ return
+
+ config.set(peer_id_secret_path, value=token_hex(32))
+
diff --git a/src/migration-scripts/pppoe-server/12-to-13 b/src/migration-scripts/pppoe-server/12-to-13
new file mode 100644
index 000000000..827f4d38f
--- /dev/null
+++ b/src/migration-scripts/pppoe-server/12-to-13
@@ -0,0 +1,41 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# Backfill IPv6 peer IID secret for legacy calling-sid configuration.
+
+from secrets import token_hex
+
+from vyos.configtree import ConfigTree
+
+base = ['service', 'pppoe-server']
+peer_id_path = base + ['ppp-options', 'ipv6-peer-interface-id']
+peer_id_secret_path = base + ['ppp-options', 'ipv6-peer-interface-id-secret']
+
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ return
+
+ if not config.exists(peer_id_path):
+ return
+
+ if config.return_value(peer_id_path) != 'calling-sid':
+ return
+
+ if config.exists(peer_id_secret_path):
+ return
+
+ config.set(peer_id_secret_path, value=token_hex(32))
+
diff --git a/src/migration-scripts/pptp/5-to-6 b/src/migration-scripts/pptp/5-to-6
new file mode 100644
index 000000000..88a857a5c
--- /dev/null
+++ b/src/migration-scripts/pptp/5-to-6
@@ -0,0 +1,41 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# Backfill IPv6 peer IID secret for legacy calling-sid configuration.
+
+from secrets import token_hex
+
+from vyos.configtree import ConfigTree
+
+base = ['vpn', 'pptp', 'remote-access']
+peer_id_path = base + ['ppp-options', 'ipv6-peer-interface-id']
+peer_id_secret_path = base + ['ppp-options', 'ipv6-peer-interface-id-secret']
+
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ return
+
+ if not config.exists(peer_id_path):
+ return
+
+ if config.return_value(peer_id_path) != 'calling-sid':
+ return
+
+ if config.exists(peer_id_secret_path):
+ return
+
+ config.set(peer_id_secret_path, value=token_hex(32))
+
diff --git a/src/migration-scripts/sstp/6-to-7 b/src/migration-scripts/sstp/6-to-7
new file mode 100644
index 000000000..f2481eb0f
--- /dev/null
+++ b/src/migration-scripts/sstp/6-to-7
@@ -0,0 +1,41 @@
+# Copyright VyOS maintainers and contributors <maintainers@vyos.io>
+#
+# This library is free software; you can redistribute it and/or
+# modify it under the terms of the GNU Lesser General Public
+# License as published by the Free Software Foundation; either
+# version 2.1 of the License, or (at your option) any later version.
+#
+# This library is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
+# Lesser General Public License for more details.
+#
+# You should have received a copy of the GNU Lesser General Public License
+# along with this library. If not, see <http://www.gnu.org/licenses/>.
+
+# Backfill IPv6 peer IID secret for legacy calling-sid configuration.
+
+from secrets import token_hex
+
+from vyos.configtree import ConfigTree
+
+base = ['vpn', 'sstp']
+peer_id_path = base + ['ppp-options', 'ipv6-peer-interface-id']
+peer_id_secret_path = base + ['ppp-options', 'ipv6-peer-interface-id-secret']
+
+
+def migrate(config: ConfigTree) -> None:
+ if not config.exists(base):
+ return
+
+ if not config.exists(peer_id_path):
+ return
+
+ if config.return_value(peer_id_path) != 'calling-sid':
+ return
+
+ if config.exists(peer_id_secret_path):
+ return
+
+ config.set(peer_id_secret_path, value=token_hex(32))
+