| Message ID | 20200205124615.15758-2-domagoj@pensa.hr |
|---|---|
| State | Accepted |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net> Delivered-To: patchwork@openvpn.net Delivered-To: patchwork@openvpn.net Received: from director9.mail.ord1d.rsapps.net ([172.30.191.6]) by backend30.mail.ord1d.rsapps.net with LMTP id GCD0APa8Ol5xTQAAIUCqbw for <patchwork@openvpn.net>; Wed, 05 Feb 2020 08:02:46 -0500 Received: from proxy8.mail.ord1d.rsapps.net ([172.30.191.6]) by director9.mail.ord1d.rsapps.net with LMTP id YAPiAPa8Ol4AEQAAalYnBA ; Wed, 05 Feb 2020 08:02:46 -0500 Received: from smtp3.gate.ord1c ([172.30.191.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by proxy8.mail.ord1d.rsapps.net with LMTP id cAJCAPa8Ol5rBQAAGdz6CA ; Wed, 05 Feb 2020 08:02:46 -0500 X-Spam-Threshold: 95 X-Spam-Score: 0 X-Spam-Flag: NO X-Virus-Scanned: OK X-Orig-To: openvpnslackdevel@openvpn.net X-Originating-Ip: [216.105.38.7] Authentication-Results: smtp3.gate.ord1c.rsapps.net; iprev=pass policy.iprev="216.105.38.7"; spf=pass smtp.mailfrom="openvpn-devel-bounces@lists.sourceforge.net" smtp.helo="lists.sourceforge.net"; dkim=fail (signature verification failed) header.d=sourceforge.net; dkim=fail (signature verification failed) header.d=sf.net; dmarc=none (p=nil; dis=none) header.from=pensa.hr X-Suspicious-Flag: YES X-Classification-ID: ccf4b614-4817-11ea-95fa-842b2b47481a-1-1 Received: from [216.105.38.7] ([216.105.38.7:55260] helo=lists.sourceforge.net) by smtp3.gate.ord1c.rsapps.net (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384) id B4/56-26457-5FCBA3E5; Wed, 05 Feb 2020 08:02:45 -0500 Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.90_1) (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) id 1izKJV-0000Yq-KA; Wed, 05 Feb 2020 13:01:53 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.90_1) (envelope-from <domagoj@pensa.hr>) id 1izKJU-0000Yh-Cw for openvpn-devel@lists.sourceforge.net; Wed, 05 Feb 2020 13:01:52 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Type:Content-Transfer-Encoding:MIME-Version :References:In-Reply-To:Date:Subject:Message-ID:To:From:Sender:Reply-To:Cc: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=fiSfnLfAQKPhEAuwy0Lo30FTPLQtRF6RQCftB4QyObg=; b=NCqGeKXXZJZ60+f6DPjlxB2Qux dRK8MQIP51OV/XJw+17oey6fa44xbqiKlg/gGhFdF4tS5THZbreFfhE7bSs7gW8Hyt9bcWJp4ce2q OKRjnZ8HEG5K+Kwl6FqwSVNMT06MZSur6tHvM4e/QvW50pVSuB2RelGy52Ai7u4mDNAQ=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Type:Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Date:Subject:Message-ID:To:From:Sender:Reply-To:Cc:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=fiSfnLfAQKPhEAuwy0Lo30FTPLQtRF6RQCftB4QyObg=; b=H+vOeUGdDIake6zlJe6cpOaq4m NZO877Yi3/eMVbqg+vpeFE2Qv5jIti0u9GG+aEI4p8/rSNNy6KVCTRkj2XkrI/GLXPK1Cdxmlc48h 1ZlfJ0VRO6GsNgz4MG+YpqvquhdcjK011VOiOmZ0ePiBL+9/65W5cdLfjT135jqO54L4=; Received: from sender4-of-o51.zoho.com ([136.143.188.51]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-SHA384:256) (Exim 4.92.2) id 1izKJT-000AxR-3d for openvpn-devel@lists.sourceforge.net; Wed, 05 Feb 2020 13:01:52 +0000 Received: from localhost (31-38.dsl.iskon.hr [89.164.31.38]) by mx.zohomail.com with SMTPS id 1580906782300505.4699948723347; Wed, 5 Feb 2020 04:46:22 -0800 (PST) From: Domagoj Pensa <domagoj@pensa.hr> To: openvpn-devel@lists.sourceforge.net Message-ID: <20200205124615.15758-2-domagoj@pensa.hr> Date: Wed, 5 Feb 2020 13:46:14 +0100 X-Mailer: git-send-email 2.25.0 In-Reply-To: <20200205124615.15758-1-domagoj@pensa.hr> References: <20200205124615.15758-1-domagoj@pensa.hr> MIME-Version: 1.0 X-ZohoMailClient: External X-Spam-Report: Spam Filtering performed by mx.sourceforge.net. See http://spamassassin.org/tag/ for more details. 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: pensa.hr] -0.0 SPF_PASS SPF: sender matches SPF record 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record X-Headers-End: 1izKJT-000AxR-3d Subject: [Openvpn-devel] [PATCH 1/2] Skip DNS address validation X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: <openvpn-devel.lists.sourceforge.net> List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe> List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel> List-Post: <mailto:openvpn-devel@lists.sourceforge.net> List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help> List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe> Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox |
| Series |
Couple of fixes
|
|
Commit Message
Domagoj Pensa
Feb. 5, 2020, 1:46 a.m. UTC
When adding IPv4 DNS servers without interactive service use
"validate=no", on Windows 7 and higher, to skip time consuming automatic
address validation, that is on by default.
Fix uses adapted code from commit 786e06a
Signed-off-by: Domagoj Pensa <domagoj@pensa.hr>
---
src/openvpn/tun.c | 9 +++++++++
1 file changed, 9 insertions(+)
Comments
Hi,
Built and tested with msvc, works as expected - "validate=no" is added to
netsh command line.
There is a similar commit in Simon's repo (not yet sent to ml) :
https://github.com/rozmansi/openvpn/commit/6b746cb0bf72a75e9963cc1a037c18cfb856702a
I haven't noticed any slowness on my machine, but since fix has been
implemented separately
by two persons and there is similar code for ipv6, I am ok with that.
Acked-by: Lev Stipakov <lstipakov@gmail.com>
<div dir="ltr"><div dir="ltr">Hi,<div><br></div><div>Built and tested with msvc, works as expected - "validate=no" is added to netsh command line.</div><div><br></div><div>There is a similar commit in Simon's repo (not yet sent to ml) : <a href="https://github.com/rozmansi/openvpn/commit/6b746cb0bf72a75e9963cc1a037c18cfb856702a">https://github.com/rozmansi/openvpn/commit/6b746cb0bf72a75e9963cc1a037c18cfb856702a</a> </div><div><br></div><div>I haven't noticed any slowness on my machine, but since fix has been implemented separately</div><div>by two persons and there is similar code for ipv6, I am ok with that.</div><div><br></div><div>Acked-by: Lev Stipakov <<a href="mailto:lstipakov@gmail.com">lstipakov@gmail.com</a>></div></div></div>
Hi, On Wed, Feb 5, 2020 at 10:28 AM Lev Stipakov <lstipakov@gmail.com> wrote: > > Hi, > > Built and tested with msvc, works as expected - "validate=no" is added to netsh command line. > > There is a similar commit in Simon's repo (not yet sent to ml) : https://github.com/rozmansi/openvpn/commit/6b746cb0bf72a75e9963cc1a037c18cfb856702a > > I haven't noticed any slowness on my machine, but since fix has been implemented separately > by two persons and there is similar code for ipv6, I am ok with that. > > Acked-by: Lev Stipakov <lstipakov@gmail.com> We explicitly added validate=no for IPv6 in commit 786e06ade9f5dfad8ac360499187fa8e536d15cb for the same reason as in this patch. The ipv4 DNS code belongs to an era when this option was not available. ACK from me too. Selva > > Acked-by: Lev Stipakov <lstipakov@gmail.com> > _______________________________________________ > Openvpn-devel mailing list > Openvpn-devel@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/openvpn-devel
Hi, My thoughts exactly: as Lev pointed out: https://github.com/rozmansi/openvpn/commit/6b746cb0bf72a75e9963cc1a037c18cfb 856702a Acked-by: Simon Rozman <simon@rozman.si> Domagoj, if it's not too much for you, maybe document the reason why DNS validation is so slow in the commit message. My wording went like this: > DNS validation usually fails, as the pushed routes should be added first > to make DNS servers not part of the OpenVPN subnet reachable before > instructing Windows to use them. Maybe Gert can update the commit message when applying? One day somebody might revert that DNS validation back to default, as the long-term shot would be to upgrade the OpenVPN to setup routes first, then configure DNS servers. But then there's ValdikSS with thousands of routes in his .ovpn setup... Best regards, Simon
Hi! On Thu, Feb 06, 2020 at 09:58:37AM +0000, Simon Rozman wrote: > Hi, > > My thoughts exactly: as Lev pointed out: > https://github.com/rozmansi/openvpn/commit/6b746cb0bf72a75e9963cc1a037c18cfb > 856702a > > Acked-by: Simon Rozman <simon@rozman.si> > > Domagoj, if it's not too much for you, maybe document the reason why DNS > validation is so slow in the commit message. My wording went like this: > > > DNS validation usually fails, as the pushed routes should be added first > > to make DNS servers not part of the OpenVPN subnet reachable before > > instructing Windows to use them. > > Maybe Gert can update the commit message when applying? Absolutely, Gert can add your additional description in the commit. Regards, Domagoj
Hi! My I ask if there is anything else I can (or should) do regarding this patch? Perhaps send patch again with revised/updated description as suggested by Simon? Thank you! Regards, Domagoj
Your patch has been applied to the master branch.
Sorry for the delay, it's been a very busy month.
I have not done any testing besides "test compile", but the code looks good
and I trust Lev and Silva here.
commit 04f4b4feec2790b620419bdc4fa2c7ae4f2451bd
Author: Domagoj Pensa
Date: Wed Feb 5 13:46:14 2020 +0100
Skip DNS address validation
Signed-off-by: Domagoj Pensa <domagoj@pensa.hr>
Acked-by: Lev Stipakov <lstipakov@gmail.com>
Acked-by: Selva Nair <selva.nair@gmail.com>
Message-Id: <20200205124615.15758-2-domagoj@pensa.hr>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg19355.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
On Fri, Mar 13, 2020 at 08:17:15PM +0100, Gert Doering wrote: > Your patch has been applied to the master branch. > > Sorry for the delay, it's been a very busy month. > No problem at all. Thank you for applying patch! :) Regards, Domagoj
diff --git a/src/openvpn/tun.c b/src/openvpn/tun.c index af09e676..9f369f74 100644 --- a/src/openvpn/tun.c +++ b/src/openvpn/tun.c @@ -5216,6 +5216,7 @@ netsh_ifconfig_options(const char *type, struct gc_arena gc = gc_new(); struct argv argv = argv_new(); bool delete_first = false; + bool is_dns = !strcmp(type, "dns"); /* first check if we should delete existing DNS/WINS settings from TAP interface */ if (test_first) @@ -5259,6 +5260,14 @@ netsh_ifconfig_options(const char *type, type, flex_name, print_in_addr_t(addr_list[i], 0, &gc)); + + /* disable slow address validation on Windows 7 and higher */ + /* only for DNS */ + if (is_dns && win32_version_info() >= WIN_7) + { + argv_printf_cat(&argv, "%s", "validate=no"); + } + netsh_command(&argv, 2, M_FATAL); ++count;