Fix: invalid hostname ACL handling in UDPASSOC
Some checks failed
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Has been cancelled
C/C++ CI Linux / ${{ matrix.target }} (ubuntu-latest) (push) Has been cancelled
C/C++ CI MacOS / ${{ matrix.target }} (macos-15) (push) Has been cancelled
C/C++ CI Windows / ${{ matrix.target }} (windows-2022) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (macos-15) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-24.04-arm) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (ubuntu-latest) (push) Has been cancelled
C/C++ CI cmake / ${{ matrix.target }} (windows-2022) (push) Has been cancelled
C/C++ CI cmake / ubuntu-latest (wolfSSL) (push) Has been cancelled

This commit is contained in:
Vladimir Dubrovin 2026-10-01 16:57:36 +03:00
parent ffa1a05009
commit f52dc0f0b9
2 changed files with 30 additions and 1 deletions

View File

@ -288,6 +288,12 @@ int udpsockmap(struct clientparam *param, int timeo)
}
default: return 997;
}
/* As for TCP requests, a literal address is the host name,
otherwise an ACL with host names only matches any address */
if (!dstname) {
myinet_ntop(*SAFAMILY(&dst), SAADDR(&dst), dstnamebuf, sizeof(dstnamebuf));
dstname = dstnamebuf;
}
memcpy(SAPORT(&dst), base + i, 2);
i += 2;

View File

@ -5,6 +5,8 @@ def run(t):
srv = t.free_port()
sks = t.free_port()
sauth = t.free_port()
sdeny = t.free_port()
sallow = t.free_port()
t.start("socks", f"""
log
@ -24,7 +26,18 @@ def run(t):
users alice:CL:secret
allow alice
socks -p{sauth}
""", ports=[srv, sks, sauth])
flush
auth iponly
deny * * *.example.com
allow *
socks -p{sdeny}
flush
auth iponly
allow * * *.example.com
socks -p{sallow}
""", ports=[srv, sks, sauth, sdeny, sallow])
origin = f"http://127.0.0.1:{srv}"
plain = f"127.0.0.1:{sks}"
@ -62,6 +75,16 @@ def run(t):
_, second = t.socks_udp(plain, "127.0.0.1", echo, b"two")
t.ne(first, second, "a second association binds its own port")
# A datagram names its destination by address. A rule listing host names
# only has to judge it by that address as text, the way CONNECT is judged,
# rather than match whatever the address is.
reply, _ = t.socks_udp(f"127.0.0.1:{sdeny}", "127.0.0.1", echo, b"ip")
t.eq(b"echo:ip", reply,
"a deny by host name leaves datagrams to an address alone")
reply, _ = t.socks_udp(f"127.0.0.1:{sallow}", "127.0.0.1", echo, b"ip")
t.eq(None, reply,
"an allow by host name does not let datagrams to an address through")
# --- authentication ----------------------------------------------------
t.eq(200, t.socks_http(guarded, origin + "/echo",
auth=("alice", "secret")).status,