minor update to get DESTINATION filtering tests passing
This commit is contained in:
@@ -6,7 +6,7 @@ fwknop-2.6.5 (11//2014):
|
||||
networks should be specified in CIDR notation (e.g. "192.168.10.0/24"),
|
||||
and individual IP addresses can be specified as well. Also, multiple IP's
|
||||
and/or networks can be defined as a comma separated list (e.g.
|
||||
"192.168.10.0/24,10.1.1.123).
|
||||
"192.168.10.0/24,10.1.1.123").
|
||||
- [server] Bug fix to ensure that proper bounds are enforced when
|
||||
importing digest cache files from previous fwknopd executions. This bug
|
||||
was discovered through fuzzing with American Fuzzy Lop (AFL) as driven
|
||||
|
||||
+4
-4
@@ -1752,19 +1752,19 @@ parse_access_file(fko_srv_options_t *opts)
|
||||
}
|
||||
|
||||
int
|
||||
compare_addr_list(acc_int_list_t *source_list, const uint32_t ip)
|
||||
compare_addr_list(acc_int_list_t *ip_list, const uint32_t ip)
|
||||
{
|
||||
int match = 0;
|
||||
|
||||
while(source_list)
|
||||
while(ip_list)
|
||||
{
|
||||
if((ip & source_list->mask) == (source_list->maddr & source_list->mask))
|
||||
if((ip & ip_list->mask) == (ip_list->maddr & ip_list->mask))
|
||||
{
|
||||
match = 1;
|
||||
break;
|
||||
}
|
||||
|
||||
source_list = source_list->next;
|
||||
ip_list = ip_list->next;
|
||||
}
|
||||
|
||||
return(match);
|
||||
|
||||
@@ -320,7 +320,7 @@ incoming_spa(fko_srv_options_t *opts)
|
||||
|
||||
inet_ntop(AF_INET, &(spa_pkt->packet_src_ip),
|
||||
spadat.pkt_source_ip, sizeof(spadat.pkt_source_ip));
|
||||
|
||||
|
||||
inet_ntop(AF_INET, &(spa_pkt->packet_dst_ip),
|
||||
spadat.pkt_destination_ip, sizeof(spadat.pkt_destination_ip));
|
||||
|
||||
@@ -413,6 +413,9 @@ incoming_spa(fko_srv_options_t *opts)
|
||||
if(! compare_addr_list(acc->source_list, ntohl(spa_pkt->packet_src_ip)) ||
|
||||
(acc->destination_list != NULL && ! compare_addr_list(acc->destination_list, ntohl(spa_pkt->packet_dst_ip))))
|
||||
{
|
||||
log_msg(LOG_DEBUG,
|
||||
"(stanza #%d) SPA packet (%s -> %s) filtered by SOURCE and/or DESTINATION criteria",
|
||||
stanza_num, spadat.pkt_source_ip, spadat.pkt_destination_ip);
|
||||
acc = acc->next;
|
||||
continue;
|
||||
}
|
||||
|
||||
@@ -133,6 +133,8 @@
|
||||
"-a $cf{'hmac_spa_destination4_access'} " .
|
||||
"-d $default_digest_file -p $default_pid_file $intf_str",
|
||||
'fw_rule_created' => $REQUIRE_NO_NEW_RULE,
|
||||
'client_pkt_tries' => 2,
|
||||
'server_receive_re' => qr/SPA\spacket\s.*filtered\sby\sSOURCE.*DEST/,
|
||||
'key_file' => $cf{'rc_hmac_b64_key'},
|
||||
},
|
||||
{
|
||||
@@ -145,6 +147,8 @@
|
||||
"-a $cf{'hmac_spa_destination5_access'} " .
|
||||
"-d $default_digest_file -p $default_pid_file $intf_str",
|
||||
'fw_rule_created' => $REQUIRE_NO_NEW_RULE,
|
||||
'client_pkt_tries' => 2,
|
||||
'server_receive_re' => qr/SPA\spacket\s.*filtered\sby\sSOURCE.*DEST/,
|
||||
'key_file' => $cf{'rc_hmac_b64_key'},
|
||||
},
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user