Project

General

Profile

Actions

Bug #17100

open
GB

Captive Portal: blocked MAC addresses are not blocked when other passthru MAC entries exist (regression since 2.8.0)

Bug #17100: Captive Portal: blocked MAC addresses are not blocked when other passthru MAC entries exist (regression since 2.8.0)

Added by Gordon Bennett 2 days ago.

Status:
New
Priority:
High
Assignee:
-
Category:
Captive Portal
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
2.8.0
Affected Architecture:
All

Description

Affected version: 2.8.0 and later (including 2.9.0). Introduced alongside the passthru MAC CIDR/masking feature. Not present in versions prior to 2.8.0.

Since upgrading to 2.8.0, MAC addresses added to Captive Portal with action "Block" are silently ignored. The device can still reach and authenticate through the captive portal as if no block rule existed.

The bug is in captiveportal_blocked_mac() in /etc/inc/captiveportal.inc. In 2.8.0 this function was rewritten to support masked / CIDR style MAC entries (e.g. aa:bb:cc:00:00:00/24 to allow / block a whole range), but the rewrite introduced a bug that has persisted through 2.9.0.

No data to display

Actions

Also available in: Atom