| Message ID | 20230103202330.1835-2-a@unstable.cc |
|---|---|
| State | Accepted |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7300:c95:b0:82:e4b3:40a0 with SMTP id p21csp7196809dyk;
Tue, 3 Jan 2023 12:23:56 -0800 (PST)
X-Google-Smtp-Source:
AMrXdXuvpRUEncjNhw/Mc702z+BmUr+IfiH1MlicnNhL89NYP63MXybpJqH1xLqF39iC4ib4pVhm
X-Received: by 2002:a05:6a20:4e04:b0:9d:efbf:786a with SMTP id
gk4-20020a056a204e0400b0009defbf786amr51038013pzb.31.1672777436430;
Tue, 03 Jan 2023 12:23:56 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; t=1672777436; cv=none;
d=google.com; s=arc-20160816;
b=WHzJ3aLDcjhhFV+UIJmkxA2zdFdSzDM+5H32qQgWFjxpLJtd92q+tNqLNIP/dOpJ9u
4+gv20Lg/aHJ6+x4HLEgQNwmSCt1jy/AeoUZ/r/mLyqO4Iu6XVP6NbSsvQ7I4f+tfLLR
Udh062Cyp4gnWJg8xknNa/FLW3wArQqjuPmQyV9YA2GzYPsdbX3LWWU/8HCb8f7ZdJ6Z
sMIv4vGjw7QVW5r+yiISMIjs+z1so4hT/7Zf3Ba4EXFhxl0/uBAZbLe77RFKYxFFy0sx
kEfjL2UGr/DMFxIL3HnQj5vTvRJUSNcNaAWMuohkNF+5DQhdEyf0K2P9zQ099hU5hJEm
IHXg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20160816;
h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature;
bh=vw2HVF2Qvv957CpPIOYS+FHypZPy6Q6FQua+Eptcy5A=;
b=hjEKVEabConyghTNbxziZexM/LeptX/c3s6wc/h8s5Bef3gpPbYxSZ/KNaLD9DxXcd
wkgeDuojSUv6ytWil5+LSEumERqiy1LL19jTy54masMECkB0W4na1IBadAj5AtnnyYYt
qrl7IupzNgA3fyf6tmt1Jv9O+vU+nEDcuYnxeTYm4TAp0lqhY6o1/yrUB5oADcowM9ez
7Low1KFjEpadUCKVs4msIq90xFTUnvS09UhP8kaZdzWFZl2C3pZSrFF6fAmK0wz2Z9eI
cVT3kDZM6ZDK1nkK22DCcwGl1hcDa55R4cJTg16r3LIL37aTnxVE9vqheSwEneZ0dL3/
izCw==
ARC-Authentication-Results: i=1; mx.google.com;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=ORwLd+kq;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=J+HhSQkb;
dkim=fail header.i=@unstable.cc header.s=20220809-q8oc
header.b="YRtWP/Nh";
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
e2-20020a636902000000b004771126e2f7si30575802pgc.142.2023.01.03.12.23.56
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Tue, 03 Jan 2023 12:23:56 -0800 (PST)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=ORwLd+kq;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=J+HhSQkb;
dkim=fail header.i=@unstable.cc header.s=20220809-q8oc
header.b="YRtWP/Nh";
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com)
by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1pCnop-00028x-KW;
Tue, 03 Jan 2023 20:23:31 +0000
Received: from [172.30.20.202] (helo=mx.sourceforge.net)
by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <a@unstable.cc>) id 1pCnom-00028q-Dd
for openvpn-devel@lists.sourceforge.net;
Tue, 03 Jan 2023 20:23:28 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-Id:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=W7vkX7hQZgG5UvzydxWQovr08M+JJIwG52rBq9Y5NTM=; b=ORwLd+kqVGsKdq7uaJ3dY+JC0t
7t0Y/O5A+qhalvMl5kXkqwNLFJz5ois5dxlWbzZm81LoL1winmZ8Q/nX4YpTRtlZ/DbnqV1pQIhPg
Blya0PZ4SmEDT4W/FQm1L5aC4CjNQwpHn64/26bMf7LZ/ioDHTk/EGempqkcQl2RobsQ=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-Id:
Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=W7vkX7hQZgG5UvzydxWQovr08M+JJIwG52rBq9Y5NTM=; b=J+HhSQkbPyVuFN/8b65ufyKSmy
i3woXT2SODx+D+KPY4Xhrwk1EIOVTf0T5x8hvMZYFMaSvZsLBLsXAghrXsgwulmD9pY1hOi3ZwDFK
M5EG0tn5wuhPTGsZ9vP/AjM4VeNPkLAMVVJav4OtQFrZfmirTpTppQfMpZHfr0INBvPI=;
Received: from wilbur.contactoffice.com ([212.3.242.68])
by sfi-mx-2.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1pCnoe-0000lf-7R for openvpn-devel@lists.sourceforge.net;
Tue, 03 Jan 2023 20:23:28 +0000
Received: from smtpauth2.co-bxl (smtpauth2.co-bxl [10.2.0.24])
by wilbur.contactoffice.com (Postfix) with ESMTP id 110DD9FA;
Tue, 3 Jan 2023 21:23:13 +0100 (CET)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; t=1672777393;
s=20220809-q8oc; d=unstable.cc; i=a@unstable.cc;
h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References:MIME-Version:Content-Transfer-Encoding;
l=1208; bh=W7vkX7hQZgG5UvzydxWQovr08M+JJIwG52rBq9Y5NTM=;
b=YRtWP/Nh5+P49S6/H3rw6c+Y01RfslAB2tSWMtbXtBf3GBw/dvh1aKqq4MKl7rbK
rpMuEOKEEpZK/EwGYg3842CnGfN++ne/fDEc6ariu0dSccrY4daTTJrBKZLcYppr9Li
GP9FSsiqlz28I364qWzvZzcyfmHv23NQpx4FzFWOiyMRwaAIfTfR432MwGG18m17+v0
T+j7P01VaQoWQhGdmRvxIyhA7vq8O0WCmZdNUO+mTJy8dUcFMIocfqKWJqzB/9rhcM1
8vLRUJBuuoXO3TiWyd2X2Pksjf9I+RsYz1wet34SEvfllufhHvS1AYy+PZXREtCfShO
Sfp0EzaF+g==
Received: by smtp.mailfence.com with ESMTPSA ;
Tue, 3 Jan 2023 21:23:11 +0100 (CET)
From: Antonio Quartulli <a@unstable.cc>
To: openvpn-devel@lists.sourceforge.net
Date: Tue, 3 Jan 2023 21:23:29 +0100
Message-Id: <20230103202330.1835-2-a@unstable.cc>
X-Mailer: git-send-email 2.38.2
In-Reply-To: <20230103202330.1835-1-a@unstable.cc>
References: <20230103202330.1835-1-a@unstable.cc>
MIME-Version: 1.0
X-Spam-Flag: NO
X-Spam-Status: No, hits=-2.9 required=4.7 symbols=ALL_TRUSTED,
BAYES_00 device=10.2.0.20
X-ContactOffice-Account: com:375058688
X-Spam-Score: -0.9 (/)
X-Spam-Report: Spam detection software,
running on the system "util-spamd-1.v13.lw.sourceforge.com",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: multi_process_incoming_dco() is currently partly processing
messages that were actually discarded. This results in a bogus message being
printed: "Received packet for peer-id unknown to OpenVPN: -1, type 0, reason
2" Content analysis details: (-0.9 points, 6.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
-0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at https://www.dnswl.org/,
low trust [212.3.242.68 listed in list.dnswl.org]
0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record
-0.0 SPF_PASS SPF: sender matches SPF record
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from
author's domain
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily
valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
X-Headers-End: 1pCnoe-0000lf-7R
Subject: [Openvpn-devel] [PATCH 2/3] dco: bail out when no peer-specific
message is delivered
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Cc: Antonio Quartulli <a@unstable.cc>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: =?utf-8?q?1754034273212495303?=
X-GMAIL-MSGID: =?utf-8?q?1754034273212495303?=
|
| Series |
[Openvpn-devel,1/3] dco: properly re-initialize dco_del_peer_reason
|
|
Commit Message
Antonio Quartulli
Jan. 3, 2023, 8:23 p.m. UTC
multi_process_incoming_dco() is currently partly processing
messages that were actually discarded. This results in a bogus
message being printed:
"Received packet for peer-id unknown to OpenVPN: -1, type 0, reason 2"
Change the flow so that we bail out immediately when we know that no
message was truly delivered by DCO.
Currently this can be verified by chacking that the peed_is is greater
than -1.
Signed-off-by: Antonio Quartulli <a@unstable.cc>
---
src/openvpn/multi.c | 10 +++++++++-
1 file changed, 9 insertions(+), 1 deletion(-)
Comments
Am 03.01.23 um 21:23 schrieb Antonio Quartulli: > multi_process_incoming_dco() is currently partly processing > messages that were actually discarded. This results in a bogus > message being printed: > > "Received packet for peer-id unknown to OpenVPN: -1, type 0, reason 2" > > Change the flow so that we bail out immediately when we know that no > message was truly delivered by DCO. > Currently this can be verified by chacking that the peed_is is greater > than -1. I think we should somewhere properly document that peer-id = -1 has this meaning. Acked-By: Arne Schwabe <arne@rfc2549.org> Arne
I've done a bit of commit message grammar ("chacking that the peed_is")
and actually tested this one. Without the check, my DCO test server
has quite a lot of these...
Jan 7 07:24:06 ubuntu2004 tun-udp-p2mp-topology-subnet[2441339]: Received packet for peer-id unknown to OpenVPN: -1, type 0, reason 2
Jan 7 07:24:06 ubuntu2004 tun-tcp-p2mp[2441317]: Received packet for peer-id unknown to OpenVPN: -1, type 0, reason 1
with the patch these are gone. Very welcome de-noisification of my logs :-)
We do still have a bit of "logging redundancy" here... for every client
connect to instance A, p2p instance B logs 3 lines (on D_DCO_DEBUG)
Jan 7 18:35:35 ubuntu2004 tun-udp-p2p-tls-sha256[2463894]: dco_do_read
Jan 7 18:35:35 ubuntu2004 tun-udp-p2p-tls-sha256[2463894]: ovpn-dco: ignoring message (type=3) for foreign ifindex 34074
Jan 7 18:35:35 ubuntu2004 tun-udp-p2p-tls-sha256[2463894]: process_incoming_dco: received message of type 0 - ignoring
.. this is coming from forward.c::process_incoming_dco(), which I assume
is only called in the p2p case, and the first message is coming from
ovpn_handle_msg() (which is not using the __func__ paradigm... why?) - so
if we can assert that "there is no message, there is nothing to see
(and nothing to log!)" in the multi_process_incoming_dco() case - maybe
we can apply this (unwritten) function contract here as well...
Stare-at-code also agrees that if the function contract says
"if (peer_id < 0) there is no valid packet, ever", early exit is a
good way out - see my note about un-initializing the dco-> fields at
the *end* of the function for 1/3, though - in this case, no un-init...
and also Arne's comment about "is this documented anywhere?")
Your patch has been applied to the master and release/2.6 branch.
commit 388e032019ec3674b8294c856039b96fe35e5f32 (master)
commit b0dee39c353ae9479fd19e66ae07cb336d57eef8 (release/2.6)
Author: Antonio Quartulli
Date: Tue Jan 3 21:23:29 2023 +0100
dco: bail out when no peer-specific message is delivered
Signed-off-by: Antonio Quartulli <a@unstable.cc>
Acked-by: Arne Schwabe <arne@rfc2549.org>
Message-Id: <20230103202330.1835-2-a@unstable.cc>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg25882.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
diff --git a/src/openvpn/multi.c b/src/openvpn/multi.c index 27676de5..b10a6d8d 100644 --- a/src/openvpn/multi.c +++ b/src/openvpn/multi.c @@ -3270,7 +3270,15 @@ multi_process_incoming_dco(struct multi_context *m) int peer_id = dco->dco_message_peer_id; - if ((peer_id >= 0) && (peer_id < m->max_clients) && (m->instances[peer_id])) + /* no peer-specific message delivered -> nothing to process. + * bail out right away + */ + if (peer_id < 0) + { + return ret > 0; + } + + if ((peer_id < m->max_clients) && (m->instances[peer_id])) { mi = m->instances[peer_id]; if (dco->dco_message_type == OVPN_CMD_PACKET)