Browse Source

Fix allowed_keys check to only apply to ETCP_INIT packets, not PING/PONG

The allowed_keys authorization was incorrectly checking all INIT-decrypted
packets including PING/PONG. Moved the check after packet type validation
so it only applies to ETCP_INIT_REQUEST/NOINIT (incoming connection requests).

Fixes test_etcp_ping and test_nat_detection failures.
congestion
Evgeny 5 months ago
parent
commit
e0ce9fefc3
  1. 50
      src/etcp_connections.c

50
src/etcp_connections.c

@ -1231,31 +1231,7 @@ void etcp_connections_read_callback_socket(socket_t sock, void* arg) {
goto ec_fr; goto ec_fr;
} }
// Check allowed keys for incoming connections // INIT decryption succeeded - process packet
struct global_config *global = &e_sock->instance->config->global;
if (!global->allowed_keys_allow_all) {
if (global->allowed_keys_count == 0) {
DEBUG_ERROR(DEBUG_CATEGORY_CONNECTION, "Connection rejected: no allowed_keys configured, allow_all=0");
errorcode=8;
goto ec_fr;
}
int found = 0;
struct CFG_ALLOWED_KEY *ak = global->allowed_keys;
while (ak) {
if (memcmp(ak->key_bin, sc.peer_public_key, SC_PUBKEY_SIZE) == 0) {
found = 1;
break;
}
ak = ak->next;
}
if (!found) {
DEBUG_ERROR(DEBUG_CATEGORY_CONNECTION, "Connection rejected: peer public key not in allowed_keys list");
errorcode=8;
goto ec_fr;
}
}
// INIT decryption succeeded - process as new incoming connection
if (pkt_len<3) { if (pkt_len<3) {
DEBUG_ERROR(DEBUG_CATEGORY_CONNECTION, "too short packet, from %s", sockaddr_storage_to_str(&addr).str); DEBUG_ERROR(DEBUG_CATEGORY_CONNECTION, "too short packet, from %s", sockaddr_storage_to_str(&addr).str);
errorcode=7; errorcode=7;
@ -1365,6 +1341,30 @@ void etcp_connections_read_callback_socket(socket_t sock, void* arg) {
goto ec_fr; goto ec_fr;
}// не init }// не init
// Check allowed keys for incoming connections
struct global_config *global = &e_sock->instance->config->global;
if (!global->allowed_keys_allow_all) {
if (global->allowed_keys_count == 0) {
DEBUG_ERROR(DEBUG_CATEGORY_CONNECTION, "Connection rejected: no allowed_keys configured, allow_all=0");
errorcode=8;
goto ec_fr;
}
int found = 0;
struct CFG_ALLOWED_KEY *ak = global->allowed_keys;
while (ak) {
if (memcmp(ak->key_bin, sc.peer_public_key, SC_PUBKEY_SIZE) == 0) {
found = 1;
break;
}
ak = ak->next;
}
if (!found) {
DEBUG_ERROR(DEBUG_CATEGORY_CONNECTION, "Connection rejected: peer public key not in allowed_keys list");
errorcode=8;
goto ec_fr;
}
}
uint32_t session_id = be32toh(*(uint32_t*)ack_hdr->session_id); uint32_t session_id = be32toh(*(uint32_t*)ack_hdr->session_id);
DEBUG_DEBUG(DEBUG_CATEGORY_CONNECTION, "INIT request session_id=%08x", session_id); DEBUG_DEBUG(DEBUG_CATEGORY_CONNECTION, "INIT request session_id=%08x", session_id);

Loading…
Cancel
Save