[Openvpn-devel] Warn user if INFO control command is too long

Frank Lichtenheld Sept. 22, 2023, 10:50 a.m. UTC
From: Lev Stipakov <lev@openvpn.net>

"INFO_PRE,..." command length is limited to 256 bytes. If the server
implementation pushes command which is too long, warn the user and
don't send the truncated command to a management client.

Signed-off-by: Lev Stipakov <lev@openvpn.net>
Acked-by: Frank Lichtenheld <frank@lichtenheld.com>

Gert Doering Sept. 22, 2023, 12:06 p.m. UTC | #1
Have not tested it beyond "test compile", but change looks reasonable.

Your patch has been applied to the master and release/2.6 branch
("make things more robust").

Author: Lev Stipakov
Date:   Fri Sep 22 12:50:55 2023 +0200

     Warn user if INFO control command is too long

     Signed-off-by: Lev Stipakov <lev@openvpn.net>
     Acked-by: Frank Lichtenheld <frank@lichtenheld.com>
     Signed-off-by: Gert Doering <gert@greenie.muc.de>

diff --git a/src/openvpn/push.c b/src/openvpn/push.c
index d468211..19849c5 100644
--- a/src/openvpn/push.c
+++ b/src/openvpn/push.c
@@ -244,8 +244,14 @@ 
          * for management greeting and we don't want to confuse the client
         struct buffer out = alloc_buf_gc(256, &gc);
-        buf_printf(&out, ">%s:%s", "INFOMSG", m);
-        management_notify_generic(management, BSTR(&out));
+        if (buf_printf(&out, ">%s:%s", "INFOMSG", m))
+        {
+            management_notify_generic(management, BSTR(&out));
+        }
+        else
+        {
+            msg(D_PUSH_ERRORS, "WARNING: Received INFO command is too long, won't notify management client.");
+        }