mirror of
https://github.com/3proxy/3proxy.git
synced 2026-10-07 20:45:48 +08:00
Fix: invalid hostname ACL handling in UDPASSOC
Some checks failed
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Has been cancelled
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-latest) (push) Has been cancelled
C/C++ CI MacOS / ${{ matrix.target }} (macos-15) (push) Has been cancelled
C/C++ CI Windows / ${{ matrix.target }} (windows-2022) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (macos-15) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-latest) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (windows-2022) (push) Has been cancelled
C/C++ CI cmake / ubuntu-latest (wolfSSL) (push) Has been cancelled
Some checks failed
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Has been cancelled
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-latest) (push) Has been cancelled
C/C++ CI MacOS / ${{ matrix.target }} (macos-15) (push) Has been cancelled
C/C++ CI Windows / ${{ matrix.target }} (windows-2022) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (macos-15) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-latest) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (windows-2022) (push) Has been cancelled
C/C++ CI cmake / ubuntu-latest (wolfSSL) (push) Has been cancelled
This commit is contained in:
parent
cd34fd45d5
commit
c703d26e54
@ -288,6 +288,12 @@ int udpsockmap(struct clientparam *param, int timeo)
|
||||
}
|
||||
default: return 997;
|
||||
}
|
||||
/* As for TCP requests, a literal address is the host name,
|
||||
otherwise an ACL with host names only matches any address */
|
||||
if (!dstname) {
|
||||
myinet_ntop(*SAFAMILY(&dst), SAADDR(&dst), dstnamebuf, sizeof(dstnamebuf));
|
||||
dstname = dstnamebuf;
|
||||
}
|
||||
memcpy(SAPORT(&dst), base + i, 2);
|
||||
i += 2;
|
||||
|
||||
|
||||
@ -5,6 +5,8 @@ def run(t):
|
||||
srv = t.free_port()
|
||||
sks = t.free_port()
|
||||
sauth = t.free_port()
|
||||
sdeny = t.free_port()
|
||||
sallow = t.free_port()
|
||||
|
||||
t.start("socks", f"""
|
||||
log
|
||||
@ -24,7 +26,18 @@ def run(t):
|
||||
users alice:CL:secret
|
||||
allow alice
|
||||
socks -p{sauth}
|
||||
""", ports=[srv, sks, sauth])
|
||||
|
||||
flush
|
||||
auth iponly
|
||||
deny * * *.example.com
|
||||
allow *
|
||||
socks -p{sdeny}
|
||||
|
||||
flush
|
||||
auth iponly
|
||||
allow * * *.example.com
|
||||
socks -p{sallow}
|
||||
""", ports=[srv, sks, sauth, sdeny, sallow])
|
||||
|
||||
origin = f"http://127.0.0.1:{srv}"
|
||||
plain = f"127.0.0.1:{sks}"
|
||||
@ -62,6 +75,16 @@ def run(t):
|
||||
_, second = t.socks_udp(plain, "127.0.0.1", echo, b"two")
|
||||
t.ne(first, second, "a second association binds its own port")
|
||||
|
||||
# A datagram names its destination by address. A rule listing host names
|
||||
# only has to judge it by that address as text, the way CONNECT is judged,
|
||||
# rather than match whatever the address is.
|
||||
reply, _ = t.socks_udp(f"127.0.0.1:{sdeny}", "127.0.0.1", echo, b"ip")
|
||||
t.eq(b"echo:ip", reply,
|
||||
"a deny by host name leaves datagrams to an address alone")
|
||||
reply, _ = t.socks_udp(f"127.0.0.1:{sallow}", "127.0.0.1", echo, b"ip")
|
||||
t.eq(None, reply,
|
||||
"an allow by host name does not let datagrams to an address through")
|
||||
|
||||
# --- authentication ----------------------------------------------------
|
||||
t.eq(200, t.socks_http(guarded, origin + "/echo",
|
||||
auth=("alice", "secret")).status,
|
||||
|
||||
Loading…
Reference in New Issue
Block a user