diff --git a/doc/openvpn.8 b/doc/openvpn.8 index 3a58317..8b601f7 100644 --- a/doc/openvpn.8 +++ b/doc/openvpn.8 @@ -5867,6 +5867,22 @@ and scripts. .\"********************************************************* .TP +.B ifconfig_ipv6_pool_remote_ip +The remote +virtual IPv6 address for the TUN/TAP tunnel taken from an +.B \-\-ifconfig-ipv6-push +directive if specified, or otherwise from +the ifconfig pool (controlled by the +.B \-\-ifconfig-ipv6-pool +config file directive). +This option is set on the server prior to execution +of the +.B \-\-client-connect +and +.B \-\-client-disconnect +scripts. +.\"********************************************************* +.TP .B link_mtu The maximum packet size (not including the IP header) of tunnel data in UDP tunnel transport mode. diff --git a/src/openvpn/manage.c b/src/openvpn/manage.c index 9f44cd9..ce5b039 100644 --- a/src/openvpn/manage.c +++ b/src/openvpn/manage.c @@ -2416,6 +2416,7 @@ env_filter_match (const char *env_str, const int env_filter_level) "dev=", "ifconfig_pool_remote_ip=", "ifconfig_pool_netmask=", + "ifconfig_ipv6_pool_remote_ip=", "time_duration=", "bytes_sent=", "bytes_received=" diff --git a/src/openvpn/multi.c b/src/openvpn/multi.c index 2839b30..ced59e5 100644 --- a/src/openvpn/multi.c +++ b/src/openvpn/multi.c @@ -1432,10 +1432,16 @@ multi_set_virtual_addr_env (struct multi_context *m, struct multi_instance *mi) } } - /* TODO: I'm not exactly sure what these environment variables are - * used for, but if we have them for IPv4, we should also have - * them for IPv6, no? - */ + setenv_del (mi->context.c2.es, "ifconfig_ipv6_pool_remote_ip"); + + if (mi->context.c2.push_ifconfig_ipv6_defined) + { + setenv_in6_addr_t (mi->context.c2.es, + "ifconfig_ipv6_pool_remote_ip", + &mi->context.c2.push_ifconfig_ipv6_local, + SA_SET_IF_NONZERO); + } + } /* diff --git a/src/openvpn/socket.c b/src/openvpn/socket.c index ed4bc6f..fbb1c34 100644 --- a/src/openvpn/socket.c +++ b/src/openvpn/socket.c @@ -2602,7 +2602,10 @@ setenv_sockaddr (struct env_set *es, const char *name_prefix, const struct openv } break; case AF_INET6: - openvpn_snprintf (name_buf, sizeof (name_buf), "%s_ip6", name_prefix); + if (flags & SA_IP_PORT) + openvpn_snprintf (name_buf, sizeof (name_buf), "%s_ip6", name_prefix); + else + openvpn_snprintf (name_buf, sizeof (name_buf), "%s", name_prefix); getnameinfo(&addr->addr.sa, sizeof (struct sockaddr_in6), buf, sizeof(buf), NULL, 0, NI_NUMERICHOST); setenv_str (es, name_buf, buf); @@ -2630,6 +2633,19 @@ setenv_in_addr_t (struct env_set *es, const char *name_prefix, in_addr_t addr, c } void +setenv_in6_addr_t (struct env_set *es, const char *name_prefix, struct in6_addr *addr, const bool flags) +{ + if ( memcmp(addr, &in6addr_any, sizeof(*addr)) != 0 || !(flags & SA_SET_IF_NONZERO)) + { + struct openvpn_sockaddr si; + CLEAR (si); + si.addr.in6.sin6_family = AF_INET6; + si.addr.in6.sin6_addr = *addr; + setenv_sockaddr (es, name_prefix, &si, flags); + } +} + +void setenv_link_socket_actual (struct env_set *es, const char *name_prefix, const struct link_socket_actual *act, diff --git a/src/openvpn/socket.h b/src/openvpn/socket.h index bffa039..c31bce9 100644 --- a/src/openvpn/socket.h +++ b/src/openvpn/socket.h @@ -420,6 +420,11 @@ void setenv_in_addr_t (struct env_set *es, in_addr_t addr, const unsigned int flags); +void setenv_in6_addr_t (struct env_set *es, + const char *name_prefix, + struct in6_addr *addr, + const bool flags); + void setenv_link_socket_actual (struct env_set *es, const char *name_prefix, const struct link_socket_actual *act,