pivpn import: adds ::/0 to a full tunnel without IPv6
pivpn without IPv6 writes ALLOWED_IPS="0.0.0.0/0", so imported clients sent IPv6 around the tunnel. The import now adds ::/0 when IPv4 is a full tunnel, so the server drops IPv6 instead.
This commit is contained in:
@@ -95,6 +95,11 @@ func readPivpn(root string) (*pivpnSetup, error) {
|
|||||||
srv.ClientDefaults.AllowedIPs = append(srv.ClientDefaults.AllowedIPs, p.Masked().String())
|
srv.ClientDefaults.AllowedIPs = append(srv.ClientDefaults.AllowedIPs, p.Masked().String())
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
// pivpn without IPv6 writes only 0.0.0.0/0, so clients would send IPv6
|
||||||
|
// around the tunnel. ::/0 makes the server drop it instead.
|
||||||
|
if fullTunnel(srv.ClientDefaults.AllowedIPs, false) && !fullTunnel(srv.ClientDefaults.AllowedIPs, true) {
|
||||||
|
srv.ClientDefaults.AllowedIPs = append(srv.ClientDefaults.AllowedIPs, "::/0")
|
||||||
|
}
|
||||||
srv.ClientDefaults.Keepalive, _ = strconv.Atoi(vars["pivpnPERSISTENTKEEPALIVE"])
|
srv.ClientDefaults.Keepalive, _ = strconv.Atoi(vars["pivpnPERSISTENTKEEPALIVE"])
|
||||||
|
|
||||||
// Clients
|
// Clients
|
||||||
|
|||||||
+4
-4
@@ -33,9 +33,9 @@ func pivpnFixture(t *testing.T, ipv6 bool, clients []pivpnClient) (root string,
|
|||||||
for _, d := range []string{"etc/pivpn/wireguard", "etc/wireguard/configs", "etc/wireguard/keys"} {
|
for _, d := range []string{"etc/pivpn/wireguard", "etc/wireguard/configs", "etc/wireguard/keys"} {
|
||||||
must(os.MkdirAll(filepath.Join(root, d), 0o755))
|
must(os.MkdirAll(filepath.Join(root, d), 0o755))
|
||||||
}
|
}
|
||||||
v6 := "0"
|
v6, allowed := "0", "0.0.0.0/0"
|
||||||
if ipv6 {
|
if ipv6 {
|
||||||
v6 = "1"
|
v6, allowed = "1", "0.0.0.0/0, ::0/0"
|
||||||
}
|
}
|
||||||
vars := `USING_UFW=0
|
vars := `USING_UFW=0
|
||||||
IPv4dev=eth0
|
IPv4dev=eth0
|
||||||
@@ -53,7 +53,7 @@ subnetClass=24
|
|||||||
pivpnenableipv6=` + v6 + `
|
pivpnenableipv6=` + v6 + `
|
||||||
pivpnNETv6="fd11:5ee:bad:c0de::"
|
pivpnNETv6="fd11:5ee:bad:c0de::"
|
||||||
subnetClassv6=64
|
subnetClassv6=64
|
||||||
ALLOWED_IPS="0.0.0.0/0, ::0/0"
|
ALLOWED_IPS="` + allowed + `"
|
||||||
INSTALLED_PACKAGES=(wireguard-tools qrencode)
|
INSTALLED_PACKAGES=(wireguard-tools qrencode)
|
||||||
`
|
`
|
||||||
must(os.WriteFile(filepath.Join(root, pivpnSetupVars), []byte(vars), 0o644))
|
must(os.WriteFile(filepath.Join(root, pivpnSetupVars), []byte(vars), 0o644))
|
||||||
@@ -179,7 +179,7 @@ func TestPivpnImport(t *testing.T) {
|
|||||||
t.Fatal(err)
|
t.Fatal(err)
|
||||||
}
|
}
|
||||||
c4 := importedConfig(t, s4)
|
c4 := importedConfig(t, s4)
|
||||||
if c4.Server.IPv6Enabled || c4.Peers[0].IPv6 != "" {
|
if c4.Server.IPv6Enabled || c4.Peers[0].IPv6 != "" || strings.Join(c4.Server.ClientDefaults.AllowedIPs, ",") != "0.0.0.0/0,::/0" {
|
||||||
t.Fatalf("IPv4-only import: %+v %+v", c4.Server, c4.Peers[0])
|
t.Fatalf("IPv4-only import: %+v %+v", c4.Server, c4.Peers[0])
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user