4314 Commits
Author SHA1 Message Date
Nikos Mavrogiannopoulos b6501f6661 Merge branch 'tmp-lease' into 'master'
Use network address as IPv6 lease start

Closes #714

See merge request openconnect/ocserv!543
2026-10-01 18:02:06 +00:00
Nikos Mavrogiannopoulos 67ae4d3ace tests: add test-ipv6-p2p for the server-side IPv6 address
Verifies that with a per-user /127 network the client is leased
network + 1 and the server takes the network address, that an explicit
IPv6 address equal to the server's /127 address is rejected, and that on
a wider network network + 1 is now leasable while the server takes the
network address. Replaces the p2p-net test, which could not connect
(ns.sh was not sourced) and had no occtl socket configured.

Relates: #714

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-29 22:12:55 +02:00
Dimitri PapadopoulosandNikos Mavrogiannopoulos 3206e11665 Use network address as IPv6 lease start
IPv6 address leases were starting at the network address + 1, following
the IPv4 convention where the network address is reserved. However,
IPv6 doesn't have such a restriction, and that behaviour is inconsistent
with IPv6 standards.

Use the IPv6 network address as the server-side tunnel address instead
of network address + 1, as described in REQ-MAIN-NET-006. This fix is
particularly important for point-to-point /127 networks with only 2
addresses. It also prevents a client with ipv6-subnet-prefix < 128 from
being leased the first subnet, which contained the server address.

This changes the server-side address of every IPv6 deployment; the
existing tests are updated accordingly.

Resolves: #714
Signed-off-by: Dimitri Papadopoulos <3350651-DimitriPapadopoulos@users.noreply.gitlab.com>
2026-09-29 22:12:55 +02:00
Nikos Mavrogiannopoulos 7fc0fb77c0 requirements: the server-side IPv6 tunnel address is the network address
Add REQ-MAIN-NET-006, the IPv6 counterpart of REQ-MAIN-NET-004: the
server takes the network address of ipv6-network, so on a /127
point-to-point network (RFC 6164) the client is leased the other address.
Document this in sample.config, noting that earlier versions used the
network address + 1.

Resolve the open OC-PROTO-CONN-007 / REQ-PROTO-CONN-007 notes: ocserv
follows "server address first" for both address families, and diverges
from the /127 recommendation for X-CSTP-Address-IP6 since it sends
ipv6-subnet-prefix.

Relates: #714

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-29 22:12:55 +02:00
Dimitri PapadopoulosandNikos Mavrogiannopoulos 51a2d887ae tests: fix the command variable names documented in ns.sh
ns.sh provides ${CMDNS1}..${CMDNS3}, not ${NSCMD1}..${NSCMD3}.

Signed-off-by: Dimitri Papadopoulos <3350651-DimitriPapadopoulos@users.noreply.gitlab.com>
2026-09-29 22:12:55 +02:00
Nikos Mavrogiannopoulos 0d3b4e82ed tests: keep the vpnc-script default route file per test run
tests/scripts/vpnc-script saved the default route to ./defaultroute,
which all tests running in parallel from build/tests share. A client
could thus restore another test's route in its own namespace ("Cannot
find device ocen1c<pid>"), leaving it without a route to the server.
Use a unique name per script.

Adds REQ-GEN-TEST-013.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-29 21:49:23 +02:00
Nikos Mavrogiannopoulos 8cb3c26dfb tests: detect network collisions from the routing table instead of ping
The generated-network subsystem accepted a network when its first host
address did not answer ping. That misses a local subnet whose other
hosts are in use, hosts that drop ICMP, and fails open when ping cannot
run at all (no CAP_NET_RAW in a container), since "no reply" and "ping
failed" look the same; each accepted draw also cost about two seconds.

Query the routing table instead: a drawn network or endpoint address is
redrawn while a route in any table lies inside it or covers it, which
includes the local addresses. Default routes and covering routes shorter
than the private block drawn from (e.g. a VPN client's 0.0.0.0/1) are
ignored. A failing ip command, or 100 rejected draws, aborts the test
instead of accepting the network. random-net.sh and random-net2.sh use
the same check for the ns.sh endpoint addresses.

Update REQ-GEN-TEST-011 accordingly, and REQ-GEN-TEST-012 to make ip a
hard dependency like ipcalc.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-29 21:48:32 +02:00
Nikos Mavrogiannopoulos d284915a77 tests: make test-iroute actually check the applied iroute
The check used a quoted right-hand side in [[ =~ ]], which bash treats
as a literal string, and a character class [vpns|tun] where an
alternation was meant; it never matched, so the test could not fail on
wrong route-add-cmd output. Compare the whole line with grep -Ex instead
and print the actual contents on failure.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-29 21:48:18 +02:00
Nikos Mavrogiannopoulos 2d240e02d3 tests: use generated networks and lint hard-coded addresses
Convert every test to REQ-GEN-TEST-010. Addresses configured on an
interface come from random-vpnnet.sh: templates use @VPNNET_BASE@ and
friends, keeping the original netmask and route formats; the vhost
tests allocate a distinct network per vhost with alloc_vpnnet4; the
firewall tests take the address of the blocked host from one; and the
RADIUS users file becomes a template materialized per test with
update_raddb(), so the tests no longer pin VPNNET to fixed ranges.
Addresses that are only data (routes, no-routes, iroutes, DNS servers,
Framed-Route, the pools of tests without a TUN device) move to
documentation ranges, keeping distinct networks distinct, and the
assertions follow; multiple-routes pushes 256 distinct routes, taken
from 198.18.0.0/15.

Add tests/check-test-addresses.py, run by the test-addresses-check job
in the preliminaries CI stage, which rejects any literal address outside
the ranges REQ-GEN-TEST-010 allows.

Relates: #714

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-29 21:48:14 +02:00
Nikos Mavrogiannopoulos 1e06cd36e0 tests: radius: use ping instead of iperf3 for the traffic step
The test only needs some traffic on the session for its accounting
checks, which require a non-zero Acct-Input-Octets. iperf3 through
the tunnel makes the worker exceed its RLIMIT_DATA headroom under
ASAN, which counts the sanitizer's shadow reservation as data.
Send pings instead.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-29 21:47:59 +02:00
Nikos Mavrogiannopoulos 7554fe920d tests: require generated VPN networks and make random-net.sh easy to use
Add REQ-GEN-TEST-010..012. Addresses a test configures on an interface
(VPN networks, explicit IPs, ...) must come from random-net.sh.
That way a test can never collide with the local network of the machine
running it.

common.sh substitutes @NAME@, @NAME_BASE@ and @NAME_ADDR@ for every
allocated network, adds @CONFIG_DIR@ and update_config_dir() to template
per-user and per-group config directories, adds update_raddb() to give a
RADIUS test a private raddb directory with a templated users file, and
fails with a clear message when a template uses a @VPN...@ placeholder
whose variable is unset, instead of producing a broken config.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-29 21:09:07 +02:00
Nikos Mavrogiannopoulos 979a1d5d99 Merge branch 'tmp-lease-ipv4' into 'master'
Fix IPv4 address lease for point-to-point /31 networks

See merge request openconnect/ocserv!559
2026-09-27 05:02:33 +00:00
Nikos Mavrogiannopoulos e6a8b6df07 ip-lease: factor the /31 netmask check into is_ipv4_p2p_mask()
Replace the duplicated mask31 byte arrays and memcmp() calls with a
single helper that compares the netmask against 255.255.255.254, and
refresh the src/ip-lease.c line citations in REQ-MAIN-NET-001/002/004.

Relates: #714

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@outlook.com>
2026-09-27 00:04:44 +02:00
Nikos Mavrogiannopoulos c588aa23f4 tests: add requirements and test for IPv4 /31 point-to-point leases
Verifies that a client with a per-user /31 network is leased the
non-network address while the server takes the network address, that
an explicit IP equal to the server's /31 address is rejected, and that
network/broadcast addresses remain reserved for /30 networks.

Relates: #714

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@outlook.com>
2026-09-27 00:01:20 +02:00
Dimitri PapadopoulosandNikos Mavrogiannopoulos cdaf2e2904 Special case for IPv4 point-to-point /31 networks
RFC 3021 makes an exception for /31 networks: the network and broadcast
addresses are not reserved, since they are not needed in a point-to-point
context, and a /31 network contains only two addresses.

In that case, start at network address instead of network address + 1.

Relates: #714
Signed-off-by: Dimitri Papadopoulos <3350651-DimitriPapadopoulos@users.noreply.gitlab.com>
2026-09-26 23:48:06 +02:00
Nikos Mavrogiannopoulos b04e591b4c requirements: fix REQ-CONFIG-INIT-003 error-path citation; add NEWS entry
Relates: #759

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-26 23:28:06 +02:00
Katie HandNikos Mavrogiannopoulos ad9d727ceb config: do not silently truncate long [vhost:NAME] names
inih truncated section names to 50 bytes, of which "vhost:" took six, so
a virtual host name longer than 43 characters was silently shortened: it
no longer matched the hostname clients send in SNI, and two hosts sharing
those first 43 characters collapsed into one. Make the section buffer size
overridable and raise it, and reject a name that cannot be stored in full
or that exceeds MAX_VHOST_NAME_LEN (253, the DNS maximum), rather than
accepting a shortened one. Covered by tests/test-vhost-name-length, which
drives ocserv -t.

Resolves: #759

Signed-off-by: Katie Hudson <41780955-Ocelot5k@users.noreply.gitlab.com>
2026-09-26 23:24:20 +02:00
Alex ProtskoandNikos Mavrogiannopoulos d651c68eff Erase the PAM password buffer after each conversation round and scrub both fixed credential buffers before releasing the PAM handle.
Resolves: #730

Signed-off-by: Alex Protsko <fidget2015@yahoo.com>
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-26 22:59:47 +02:00
Nikos Mavrogiannopoulos 6f58414656 radius: standardize on radcli library
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-20 14:37:49 +02:00
Nikos Mavrogiannopoulos 73e5c15470 agents: updated promptkit protocols and requirements
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-20 14:27:15 +02:00
Nikos Mavrogiannopoulos f16daa89ef ocserv-core-dev: improved review protocol
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-20 13:27:05 +02:00
Nikos Mavrogiannopoulos 15bda6856d requirements: document the existing testing requirement
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-19 19:50:21 +02:00
Nikos Mavrogiannopoulos 9e1e983437 requirements: prevent fragile tests from being created or merged
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-19 19:34:22 +02:00
Nikos Mavrogiannopoulos d87625ecb6 doc update
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-19 06:47:50 +02:00
Nikos Mavrogiannopoulos df2302859f REQ-GEN-STYLE-003: removed
Removed introduced by mistake requirement. This is currently
under discussion in !579.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-19 06:45:57 +02:00
Nikos Mavrogiannopoulos 4a3ef2bf5d Merge branch 'mr589-graceful-shutdown' into 'master'
sec-mod: send accounting stop on server shutdown

Closes #643

See merge request openconnect/ocserv!589
2026-09-19 04:42:41 +00:00
Alex Protsko b34ce2c7e7 sec-mod: send accounting stop on server shutdown
Close every open accounting session from the sec-mod shutdown cleanup path without waiting for individual RADIUS responses. With radcli, send one best-effort Accounting-Stop to the first configured server using zero timeout and retries; with legacy freeradius-client, skip the shutdown send rather than block termination.

Preserve accumulated counters, existing terminate causes, and the disconnect-time uptime snapshot of retained sessions. Clear the previous connection segment cause after a successful cookie resumption so an unset current cause continues to map to Lost-Service.

Document the shutdown and reconnect contracts as separate requirements and extend the RADIUS integration test to cover retained, resumed, and active sessions plus first-server-only delivery.

Resolves: #643
Signed-off-by: Alex Protsko <fidget2015@yahoo.com>
2026-09-18 20:27:35 +03:00
Nikos Mavrogiannopoulos f433b0e8fb ocserv.8: include sample.config again
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-15 08:56:06 +02:00
Nikos Mavrogiannopoulos 46cd42a465 sample.config: documented no ordering guarantee of scripts
Resolves: #758

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-15 08:56:06 +02:00
Nikos Mavrogiannopoulos 4577a2a6ba README.md: explicitly call out ipcalc
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-13 18:43:37 +02:00
Nikos Mavrogiannopoulos 0f72ed3f21 meson: added option to disable the building of tests
Resolves: #760

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-13 17:51:35 +02:00
Nikos Mavrogiannopoulos 1355717a7d requirements: updated requirement for modifying vendored code
Also adds REQ-GEN-TECH-007 requiring that general improvements to
actively-maintained vendored subtrees be sent upstream first.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-09-12 12:08:43 +02:00
Nikos Mavrogiannopoulos 96a4baf9f9 certificate validation: do not use LOG_ERR when logging a missing optional certificate
When certificate authentication is configured as optional ensure that
there is sufficient information for tracing the authentication used
but do not log under LOG_ERR a missing certificate that was not required.

Resolves: #744

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-08-15 15:19:11 +02:00
Nikos Mavrogiannopoulos 143abadd27 tests: aligned the PAM launcher variants to use the simpler approach
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-08-14 07:35:19 +02:00
Nikos Mavrogiannopoulos cf598075de tests: simplified by reducing unnecessary launch functions
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-08-14 07:20:46 +02:00
Nikos Mavrogiannopoulos 77a3208f99 Fixed regression with CISCO Anyconnect clients and TLS 1.3
Resolves: #745

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-08-12 20:58:32 +02:00
Nikos Mavrogiannopoulos 9ed4342153 sec-mod: prevent malicious clients from piling up client_entry_st per pid
Malicious clients cannot send CMD_SEC_AUTH_INIT arbitrarily: a worker's
pid has one client_entry_st attached to it. A repeated SEC_AUTH_INIT
is accepted (replacing the previous entry) only when the prior
attempt already ended in PS_AUTH_FAILED with no session attached
(in_use == 0), matching the legitimate case for it (GSSAPI/certificate
falling back to the next auth method).

Resolves: #249

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-08-12 20:56:15 +02:00
Nikos Mavrogiannopoulos be6b5deea0 proc_to_zombie: removed dead definition
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-08-02 17:26:34 +02:00
Nikos Mavrogiannopoulos 2315b91894 ocserv.8.md: corrected SYNOPSIS
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-07-29 10:42:35 +02:00
Nikos Mavrogiannopoulos 1002c6fce7 README.md: document that this is only about Intune VPN
Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-07-29 08:25:01 +02:00
Nikos Mavrogiannopoulos 77e06aec8a sec-mod, worker: harden TLS resumption cache against empty session data
A cached resume entry can end up with zero-length session_data, which is
not valid resumption data.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-07-28 08:07:07 +02:00
Nikos Mavrogiannopoulos 9e71c1b8b6 worker: use TLS 1.3 transparent rekey on TLS 1.3 CSTP sessions
TLS 1.3 has no renegotiation and provides transparent rekeys but this
was not used by the server. Instead rekey-method=ssl was silently
downgraded to new-tunnel, causing a full tunnel/TUN-device rebuild (and
a brief data-path interruption) on every rekey whenever a client
negotiated TLS 1.3.

This commit simplifies that handling by taking advantage of TLS 1.3's own
rekey mechanism instead: the server now performs the "ssl" rekey on
TLS 1.3 sessions via the standard TLS 1.3 KeyUpdate message.

TLS <= 1.2 rekey behavior (client-driven rehandshake, gated on RFC
5746 safe renegotiation) is unchanged.

Resolves: #745

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-07-28 08:07:07 +02:00
Nikos Mavrogiannopoulos 76987ccb82 tlslib, worker: remove dead code orphaned by the listen-clear-file removal
Commit 5cf457b4 ("Removed the listen-clear-file config option", Dec
2020) deleted the only code path that could ever construct a
SOCK_TYPE_UNIX worker connection, but left every branch that handled
it in place. Since then ws->session has been unconditionally non-NULL
and ws->conn_type unconditionally not SOCK_TYPE_UNIX for every worker,
making all of the following unreachable:

 - tlslib.c: recv_remaining(), _cstp_recv_packet() (the non-TLS CSTP
   reassembly path hardened in the previous commit), and
   tls_has_session_cert() (zero callers) deleted outright; cstp_cork/
   cstp_uncork/cstp_send/cstp_recv_packet/cstp_recv/cstp_close/
   cstp_fatal_close collapsed to their TLS-only body.
 - worker-http.c, worker-auth.c, worker-vpn.c, main.c: dead
   ws->session == NULL / ws->conn_type == SOCK_TYPE_UNIX branches
   removed or simplified to their live half.
 - worker-proxyproto.c: parse_ssl_tlvs() and its TLV structs/macros
   removed. This proxy-protocol SSL-CN extraction was itself only
   ever invoked from the same dead SOCK_TYPE_UNIX branch, so it has
   been as unreachable as the rest since 2020 despite a recent,
   otherwise-correct bug fix.
 - tests/cstp-recv.c deleted (exercised only the removed reassembly
   path); tests/proxyproto-v2.c trimmed to the still-live IPv6
   address-parsing regression test.
 - doc/sample.config: dropped the stale "TCP or UNIX socket" wording
   for listen-proxy-proto left over from the same 2020 removal; only
   a TCP socket is ever listened on for the proxy protocol now.

Narrows the worker's attack surface to the code paths a client can
actually reach, and removes a source of wasted maintenance effort.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-07-28 08:00:06 +02:00
Nikos Mavrogiannopoulos 879f723953 tlslib: harden recv_remaining() against truncated CSTP reads
recv_remaining() is used only on the non-TLS CSTP path (a UNIX socket
proxying plaintext CSTP in front of ocserv). On a recv() failure or
peer close mid-read, it discarded the error and returned whatever
partial byte count it had accumulated so far. Since every caller only
checks "ret <= 0" and otherwise trusts the count as a complete read,
a truncated body could come back as a positive, non-zero total that
looked like success: _cstp_recv_packet() would then report the full
8+pktlen size to its caller with only part of the buffer actually
populated from the network, feeding stale/uninitialized bytes into
parse_cstp_data() as if they were received client data.

Make the contract unambiguous: recv_remaining() now returns either
exactly the requested byte count or a negative error - never a
partial positive count a caller could mistake for success.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-07-28 08:00:06 +02:00
Nikos Mavrogiannopoulos d79eda6013 ip-util: reject routes with characters outside address/prefix syntax
ip_route_sanity_check() was a format normalizer, not a validator: any
dot-free route (all IPv6, or arbitrary text) returned success
unexamined, and a dotted-netmask IPv4 route passed through unchanged.
Since route_adddel() substitutes the validated route into
route-add-cmd/route-del-cmd and executes it via `/bin/sh -c` as root,
a route string carrying shell metacharacters that survived this check
was a root command-injection vector.

Rewrite the check to fully parse the route as an IPv4 or IPv6 address
plus prefix, or the literal keyword "default" (the documented
all-traffic-through-VPN shortcut, checked separately by config.c after
this function runs), and reject anything left over. Numeric IPv4
prefixes are still normalized to a dotted netmask as before.

Adds REQ-MAIN-SEC-008 and tests/route-sanity-check.c, confirmed
against real config/test usage (including "route = default") so the
stricter validation doesn't regress documented syntax.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-07-28 08:00:06 +02:00
Nikos Mavrogiannopoulos 5a9cddf606 main: validate AUTH_COOKIE_REQ cookie length before use
main read cookie.data[0] (to select sec_mod_instance_index) before
validating the cookie's length. A worker sending an empty cookie
unpacks with cookie.data == NULL (protobuf-c "required bytes"
semantics), so the read crashed the root main process, tearing down
every connected client.

Validate cookie.data/len immediately after unpacking, before the
first byte is read. handle_auth_cookie_req()'s own later check
remains as defense-in-depth.

Adds REQ-IPC-018.

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
2026-07-28 08:00:06 +02:00
Nikos Mavrogiannopoulos cdc9a5b5f4 Merge branch 'mr588-worker-seccomp-musl' into 'master'
worker-privs: allow munmap/mremap/madvise for isolated workers

Closes #749

See merge request openconnect/ocserv!588
2026-07-28 05:52:58 +00:00
Alex Protsko b931112cb2 worker-privs: allow munmap/mremap/madvise for isolated workers
Fix worker crashes on musl-based systems when isolate-workers = true by allowing munmap, mremap, and madvise in the worker seccomp filter.

Move seccomp coverage to Alpine CI and use oc_syslog for seccomp trap diagnostics instead of direct write()-based output.

Keep glibc backtrace diagnostics as the default and allow musl builds to select the syscall-only fallback with the assume-glibc Meson option.

Resolves: #749
Signed-off-by: Alex Protsko <fidget2015@yahoo.com>
2026-07-20 16:43:23 +03:00
Nikos Mavrogiannopoulos dde0a16df2 Merge branch 'tmp-coverity' into 'master'
Suppress Coverity Scan defect

See merge request openconnect/ocserv!596
2026-07-16 06:38:24 +00:00
DmitriiandNikos Mavrogiannopoulos df086188d7 radius: send the session ID as Acct-Session-Id in the Access-Request
RFC 2866 (5.5) allows an Access-Request to carry Acct-Session-Id and
requires the same value in the session's Accounting-Requests. Sending it
already at authentication time lets the RADIUS server correlate the two
exchanges by a single per-session key (e.g. for rlm_ippool, so concurrent
sessions of the same user from the same client do not collide on one IP
lease).

Documented as REQ-AUTH-AUTH-025, with a positive check in tests/radius
that the id sent as Acct-Session-Id in the Access-Request matches the
Accounting-Request.

Signed-off-by: Dmitrii <dimmispencer@gmail.com>
Resolves: #751
2026-07-14 21:40:23 +02:00