minor update to get DESTINATION filtering tests passing

This commit is contained in:
Michael Rash
2014-12-03 20:57:06 -05:00
parent c5c263c02f
commit d6dee352af
4 changed files with 13 additions and 6 deletions
+1 -1
View File
@@ -6,7 +6,7 @@ fwknop-2.6.5 (11//2014):
networks should be specified in CIDR notation (e.g. "192.168.10.0/24"),
and individual IP addresses can be specified as well. Also, multiple IP's
and/or networks can be defined as a comma separated list (e.g.
"192.168.10.0/24,10.1.1.123).
"192.168.10.0/24,10.1.1.123").
- [server] Bug fix to ensure that proper bounds are enforced when
importing digest cache files from previous fwknopd executions. This bug
was discovered through fuzzing with American Fuzzy Lop (AFL) as driven
+4 -4
View File
@@ -1752,19 +1752,19 @@ parse_access_file(fko_srv_options_t *opts)
}
int
compare_addr_list(acc_int_list_t *source_list, const uint32_t ip)
compare_addr_list(acc_int_list_t *ip_list, const uint32_t ip)
{
int match = 0;
while(source_list)
while(ip_list)
{
if((ip & source_list->mask) == (source_list->maddr & source_list->mask))
if((ip & ip_list->mask) == (ip_list->maddr & ip_list->mask))
{
match = 1;
break;
}
source_list = source_list->next;
ip_list = ip_list->next;
}
return(match);
+4 -1
View File
@@ -320,7 +320,7 @@ incoming_spa(fko_srv_options_t *opts)
inet_ntop(AF_INET, &(spa_pkt->packet_src_ip),
spadat.pkt_source_ip, sizeof(spadat.pkt_source_ip));
inet_ntop(AF_INET, &(spa_pkt->packet_dst_ip),
spadat.pkt_destination_ip, sizeof(spadat.pkt_destination_ip));
@@ -413,6 +413,9 @@ incoming_spa(fko_srv_options_t *opts)
if(! compare_addr_list(acc->source_list, ntohl(spa_pkt->packet_src_ip)) ||
(acc->destination_list != NULL && ! compare_addr_list(acc->destination_list, ntohl(spa_pkt->packet_dst_ip))))
{
log_msg(LOG_DEBUG,
"(stanza #%d) SPA packet (%s -> %s) filtered by SOURCE and/or DESTINATION criteria",
stanza_num, spadat.pkt_source_ip, spadat.pkt_destination_ip);
acc = acc->next;
continue;
}
+4
View File
@@ -133,6 +133,8 @@
"-a $cf{'hmac_spa_destination4_access'} " .
"-d $default_digest_file -p $default_pid_file $intf_str",
'fw_rule_created' => $REQUIRE_NO_NEW_RULE,
'client_pkt_tries' => 2,
'server_receive_re' => qr/SPA\spacket\s.*filtered\sby\sSOURCE.*DEST/,
'key_file' => $cf{'rc_hmac_b64_key'},
},
{
@@ -145,6 +147,8 @@
"-a $cf{'hmac_spa_destination5_access'} " .
"-d $default_digest_file -p $default_pid_file $intf_str",
'fw_rule_created' => $REQUIRE_NO_NEW_RULE,
'client_pkt_tries' => 2,
'server_receive_re' => qr/SPA\spacket\s.*filtered\sby\sSOURCE.*DEST/,
'key_file' => $cf{'rc_hmac_b64_key'},
},
{