| Message ID | CAJ-EccN7eQsSaFn4MH4qRTKx+zZ-1YcGAe0XU8813p7k=W2i4g@mail.gmail.com |
|---|---|
| State | Rejected |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net> Delivered-To: patchwork@openvpn.net Delivered-To: patchwork@openvpn.net Received: from director7.mail.ord1d.rsapps.net ([172.30.191.6]) by backend30.mail.ord1d.rsapps.net (Dovecot) with LMTP id DP4nKlzu0Fo5JwAAIUCqbw for <patchwork@openvpn.net>; Fri, 13 Apr 2018 13:52:28 -0400 Received: from proxy20.mail.ord1d.rsapps.net ([172.30.191.6]) by director7.mail.ord1d.rsapps.net (Dovecot) with LMTP id wShiHFzu0FrqbwAAovjBpQ ; Fri, 13 Apr 2018 13:52:28 -0400 Received: from smtp30.gate.ord1d ([172.30.191.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by proxy20.mail.ord1d.rsapps.net with LMTP id mNgHMlzu0Fr2BwAAsk8m8w ; Fri, 13 Apr 2018 13:52:28 -0400 X-Spam-Threshold: 95 X-Spam-Score: 0 X-Spam-Flag: NO X-Virus-Scanned: OK X-Orig-To: openvpnslackdevel@openvpn.net X-Originating-Ip: [216.105.38.7] Authentication-Results: smtp30.gate.ord1d.rsapps.net; iprev=pass policy.iprev="216.105.38.7"; spf=pass smtp.mailfrom="openvpn-devel-bounces@lists.sourceforge.net" smtp.helo="lists.sourceforge.net"; dkim=fail (signature verification failed) header.d=sourceforge.net; dkim=fail (signature verification failed) header.d=sf.net; dkim=fail (signature verification failed) header.d=chromium.org; dmarc=fail (p=none; dis=none) header.from=chromium.org X-Suspicious-Flag: YES X-Classification-ID: 6e1ec938-3f43-11e8-9165-5254001e8e38-1-1 Received: from [216.105.38.7] ([216.105.38.7:4529] helo=lists.sourceforge.net) by smtp30.gate.ord1d.rsapps.net (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) (ecelerity 4.2.1.56364 r(Core:4.2.1.14)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384) id 45/43-05489-C5EE0DA5; Fri, 13 Apr 2018 13:52:28 -0400 Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.90_1) (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) id 1f72r3-0005M3-VK; Fri, 13 Apr 2018 17:51:21 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.90_1) (envelope-from <mortonm@chromium.org>) id 1f72r2-0005Lv-Pr for openvpn-devel@lists.sourceforge.net; Fri, 13 Apr 2018 17:51:20 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Type:To:Subject:Message-ID:Date:From: MIME-Version:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=9DuSWbOk616RCRFJXM8IS1JNa8XgcKDabryc3eW5mNo=; b=kBTUcFUNVljp6Q3RpTRbx4r43Q jjmKkwl7u476vqC6DtXm5YoqMJHyQYYp3Gsdu3RzA/NJBwISPqXdQMx1abjwtm247/z7VSfSLKsBm kfhp2VqGQCBN08b5EmfnTCIUXRqFnwUpgbuN4rdb5SvbVJr3c1pt4UtH/5zLjn/eMFSc=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Type:To:Subject:Message-ID:Date:From:MIME-Version:Sender:Reply-To :Cc:Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post: List-Owner:List-Archive; bh=9DuSWbOk616RCRFJXM8IS1JNa8XgcKDabryc3eW5mNo=; b=a 0PEn021tk3EJyJeRkUcbEwVgNf5kqnpUVzalGWAaLsrSJVRdckYBAScXroM3bblq41hGUt5A+n1/X vgF0F3ie1MbjBm8SlLmBjPR1GB4lA/No5VaDXXC1O3jx35txc5jZXxXWx0hcjSmkUt1lVtit9ZdcI x5zRItgRhhtueOw8=; Received: from mail-qk0-f179.google.com ([209.85.220.179]) by sfi-mx-4.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.90_1) id 1f72r0-00FJEb-V7 for openvpn-devel@lists.sourceforge.net; Fri, 13 Apr 2018 17:51:20 +0000 Received: by mail-qk0-f179.google.com with SMTP id b198so9943125qkg.9 for <openvpn-devel@lists.sourceforge.net>; Fri, 13 Apr 2018 10:51:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chromium.org; s=google; h=mime-version:from:date:message-id:subject:to; bh=9DuSWbOk616RCRFJXM8IS1JNa8XgcKDabryc3eW5mNo=; b=FcA74BfpTMtA42u5GZKwW4WfwIfisNAYz6dgcb7iB8/1uF4Ed8M6+2Jn4/k+J4Cuo/ OaQiBx9Fyul7bjnVEAoFzYwAJAC2jNU2o+Y8Vm0YnmroHopCLZqDB217KDuTm9s53kBi 1Fy0OcTX5XvgtOkS4cfj5rmu83A35FOYEocoE= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=9DuSWbOk616RCRFJXM8IS1JNa8XgcKDabryc3eW5mNo=; b=X2T42TI5ZFMQfUbEiBFYvVzDwOLTax5ugqSO8TLXXPRAXxM+Wj+8caBqw0J412fh09 dg7HBe+kqeOY6Zi8RQ/6UMa8KN3a1hcQEO1+E/K85ieH3HOyPDTseByqnB2ZNpOSTK95 dfaOti7SZ+qotUpXYlaea4GupgiU8yxiewERN4JDRPDe3UfPzXmqgC/X1yTxfC7XhnJU mpQ8lboS63z8EIEdOhVmUgfdw0NC81Agb1Lq2KdPqdohAIOpIJLZaLn+hge6/sPivsra FjU9uQdJxLqAGbmBqJc5JV6EluyPF6u0YDR1fGJ2wK1JzPJ2PSs4CHFIvBtrQbllq3Wh rvig== X-Gm-Message-State: ALQs6tAyyuqvkRNb3pp1ulBr/xrox3FFv7hUdOG1xSO4oeupxrjfEwsX w91+Uz4bLuemMSc8C1tt4DmXExWBIKZ8feuwRH48V3zeV4s= X-Google-Smtp-Source: AIpwx49eL5S5U+5MEjqJ6A2wzwakhpfuj54mScg8lfk2R7V4fQKn/GXZxKVecPseUST2gDh00TLG4PTuMyNSeF/ayV0= X-Received: by 10.55.118.4 with SMTP id r4mr5504507qkc.211.1523640184666; Fri, 13 Apr 2018 10:23:04 -0700 (PDT) MIME-Version: 1.0 Received: by 10.200.36.50 with HTTP; Fri, 13 Apr 2018 10:23:03 -0700 (PDT) From: Micah Morton <mortonm@chromium.org> Date: Fri, 13 Apr 2018 10:23:03 -0700 Message-ID: <CAJ-EccN7eQsSaFn4MH4qRTKx+zZ-1YcGAe0XU8813p7k=W2i4g@mail.gmail.com> To: openvpn-devel@lists.sourceforge.net X-Spam-Report: Spam Filtering performed by mx.sourceforge.net. See http://spamassassin.org/tag/ for more details. -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no trust [209.85.220.179 listed in list.dnswl.org] -0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3) [209.85.220.179 listed in wl.mailspike.net] -0.0 SPF_PASS SPF: sender matches SPF record 1.0 HTML_MESSAGE BODY: HTML included in message -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-Headers-End: 1f72r0-00FJEb-V7 Subject: [Openvpn-devel] [PATCH] Specify platform and version on command line. X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: <openvpn-devel.lists.sourceforge.net> List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe> List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel> List-Post: <mailto:openvpn-devel@lists.sourceforge.net> List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help> List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe> Content-Type: multipart/mixed; boundary="===============7263764134799654875==" Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox |
| Series |
[Openvpn-devel] Specify platform and version on command line.
|
|
Commit Message
Micah Morton
April 13, 2018, 7:23 a.m. UTC
From 557d2e73bf21ddb9d07b43f716c7914d610e7392 Mon Sep 17 00:00:00 2001 From: Micah Morton <mortonm@chromium.org> Date: Fri, 13 Apr 2018 09:55:22 -0700 Subject: [PATCH] Specify platform and version on command line. Add --iv-plat and --iv-plat-rel command line args, and use the values passed to these args to set IV_PLAT and IV_PLAT_REL info that is pushed to the server. IV_PLAT (platform type) is normally inferred from the build target, but it would be useful to be able to override this from the command line (e.g. for client to set platform as ChromeOS instead of Linux). IV_PLAT_REL (platform release version) would allow for pushing the platform (e.g. ChromeOS) release version to the server. This patch is written against openvpn-2.4.4. Signed-off-by: Micah Morton <mortonm@chromium.org> --- src/openvpn/init.c | 8 ++++++++ src/openvpn/options.c | 18 ++++++++++++++++++ src/openvpn/options.h | 2 ++ src/openvpn/ssl.c | 9 +++++++++ src/openvpn/ssl_common.h | 2 ++ 5 files changed, 39 insertions(+)
Comments
Hi. On Fri, Apr 13, 2018 at 1:23 PM, Micah Morton <mortonm@chromium.org> wrote: > From 557d2e73bf21ddb9d07b43f716c7914d610e7392 Mon Sep 17 00:00:00 2001 > From: Micah Morton <mortonm@chromium.org> > Date: Fri, 13 Apr 2018 09:55:22 -0700 > Subject: [PATCH] Specify platform and version on command line. > > Add --iv-plat and --iv-plat-rel command line args, and use the values > passed to these args to set IV_PLAT and IV_PLAT_REL info that is pushed > to the server. Sounds reasonable, but the new options should be documented on the man page and in the usage message that's shown to users (in options.c) and that should be included in this patch. Best regards, Jon Bullard ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot
Hi, On Fri, Apr 13, 2018 at 10:23:03AM -0700, Micah Morton wrote: > From 557d2e73bf21ddb9d07b43f716c7914d610e7392 Mon Sep 17 00:00:00 2001 > From: Micah Morton <mortonm@chromium.org> > Date: Fri, 13 Apr 2018 09:55:22 -0700 > Subject: [PATCH] Specify platform and version on command line. > > Add --iv-plat and --iv-plat-rel command line args, and use the values > passed to these args to set IV_PLAT and IV_PLAT_REL info that is pushed > to the server. > > IV_PLAT (platform type) is normally inferred from the build target, but > it would be useful to be able to override this from the command line > (e.g. for client to set platform as ChromeOS instead of Linux). > > IV_PLAT_REL (platform release version) would allow for pushing the > platform (e.g. ChromeOS) release version to the server. I'm actually less than enthusiastic about "yay, two more special-case options for OpenVPN" - and even less so to options that enable users to override a fairly well-defined meaning of IV_PLAT with an arbitrary string. Even if it's ChromeOS, compiled with #define TARGET_LINUX, IV_PLAT should reflect that. There is already "--setenv UV_anykey=value" to send arbitrary strings to the server, and in particular, IV_PLAT_VER can already be set by "--setenv IV_PLAT_VER=<version>". There's one catch to this, though - for some reason that escapes me right now we have decided that IV_PLAT_VER= and the UV_ user-defined strings are only sent if --push-peer-info is also configured on the client (while IV_GUI_VER, also settable with --setenv, is always sent). So we might want to revisit that decision. gert
@gert: From the help message: "--setenv name value : Set a custom environmental variable to pass to script." --setenv appears to set string values for scripts only, not for the main openvpn process (which is reading them in the push_peer_info() function). Starting a test openvpn server with `--setenv foo bar` and then running `strings` on /proc/PID/environ doesn't show "foo=bar". This suggests that getenv() calls in the main openvpn process that try to read these vars may return NULL. @jon: the mods to options.c in the patch above should take care of the help message (I tested it by running openvpn --help). Although good point if this is going in I should update the man page as well. On Fri, Apr 13, 2018 at 11:58 AM, Gert Doering <gert@greenie.muc.de> wrote: > Hi, > > On Fri, Apr 13, 2018 at 10:23:03AM -0700, Micah Morton wrote: > > From 557d2e73bf21ddb9d07b43f716c7914d610e7392 Mon Sep 17 00:00:00 2001 > > From: Micah Morton <mortonm@chromium.org> > > Date: Fri, 13 Apr 2018 09:55:22 -0700 > > Subject: [PATCH] Specify platform and version on command line. > > > > Add --iv-plat and --iv-plat-rel command line args, and use the values > > passed to these args to set IV_PLAT and IV_PLAT_REL info that is pushed > > to the server. > > > > IV_PLAT (platform type) is normally inferred from the build target, but > > it would be useful to be able to override this from the command line > > (e.g. for client to set platform as ChromeOS instead of Linux). > > > > IV_PLAT_REL (platform release version) would allow for pushing the > > platform (e.g. ChromeOS) release version to the server. > > I'm actually less than enthusiastic about "yay, two more special-case > options for OpenVPN" - and even less so to options that enable users > to override a fairly well-defined meaning of IV_PLAT with an arbitrary > string. Even if it's ChromeOS, compiled with #define TARGET_LINUX, > IV_PLAT should reflect that. > > There is already "--setenv UV_anykey=value" to send arbitrary strings > to the server, and in particular, IV_PLAT_VER can already be set by > "--setenv IV_PLAT_VER=<version>". > > There's one catch to this, though - for some reason that escapes me right > now we have decided that IV_PLAT_VER= and the UV_ user-defined strings > are only sent if --push-peer-info is also configured on the client > (while IV_GUI_VER, also settable with --setenv, is always sent). > > So we might want to revisit that decision. > > gert > > -- > "If was one thing all people took for granted, was conviction that if you > feed honest figures into a computer, honest figures come out. Never > doubted > it myself till I met a computer with a sense of humor." > Robert A. Heinlein, The Moon is a Harsh > Mistress > > Gert Doering - Munich, Germany > gert@greenie.muc.de > <div dir="ltr"><div><span style="color:rgb(0,0,0);font-family:Roboto,-apple-system,BlinkMacSystemFont,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:13px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:pre-wrap;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">@gert:</span></div><div><span style="color:rgb(0,0,0);font-family:Roboto,-apple-system,BlinkMacSystemFont,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:13px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:pre-wrap;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline"><br></span></div><div><span style="color:rgb(0,0,0);font-family:Roboto,-apple-system,BlinkMacSystemFont,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:13px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:pre-wrap;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">From the help message: "--setenv name value : Set a custom environmental variable to pass to script."</span></div><span style="color:rgb(0,0,0);font-family:Roboto,-apple-system,BlinkMacSystemFont,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:13px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:pre-wrap;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline"><div><span style="color:rgb(0,0,0);font-family:Roboto,-apple-system,BlinkMacSystemFont,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:13px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:pre-wrap;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline"><br></span></div>--setenv appears to set string values for scripts only, not for the main openvpn process (which is reading them in the push_peer_info() function). Starting a test openvpn server with `--setenv foo bar` and then running `strings` on /proc/PID/environ doesn't show "foo=bar". This suggests that getenv() calls in the main openvpn process that try to read these vars may return NULL.</span><br><div><span style="color:rgb(0,0,0);font-family:Roboto,-apple-system,BlinkMacSystemFont,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:13px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:pre-wrap;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline"><br></span></div><div><span style="color:rgb(0,0,0);font-family:Roboto,-apple-system,BlinkMacSystemFont,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:13px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:pre-wrap;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">@jon:</span></div><div><span style="color:rgb(0,0,0);font-family:Roboto,-apple-system,BlinkMacSystemFont,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:13px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:pre-wrap;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline"><br></span></div><div><span style="color:rgb(0,0,0);font-family:Roboto,-apple-system,BlinkMacSystemFont,"Segoe UI",Helvetica,Arial,sans-serif,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol";font-size:13px;font-style:normal;font-variant-ligatures:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:pre-wrap;word-spacing:0px;background-color:rgb(255,255,255);text-decoration-style:initial;text-decoration-color:initial;float:none;display:inline">the mods to options.c in the patch above should take care of the help message (I tested it by running openvpn --help). Although good point if this is going in I should update the man page as well.</span></div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Apr 13, 2018 at 11:58 AM, Gert Doering <span dir="ltr"><<a href="mailto:gert@greenie.muc.de" target="_blank">gert@greenie.muc.de</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hi,<br> <span class=""><br> On Fri, Apr 13, 2018 at 10:23:03AM -0700, Micah Morton wrote:<br> > From 557d2e73bf21ddb9d07b43f716c791<wbr>4d610e7392 Mon Sep 17 00:00:00 2001<br> > From: Micah Morton <<a href="mailto:mortonm@chromium.org">mortonm@chromium.org</a>><br> > Date: Fri, 13 Apr 2018 09:55:22 -0700<br> > Subject: [PATCH] Specify platform and version on command line.<br> > <br> > Add --iv-plat and --iv-plat-rel command line args, and use the values<br> > passed to these args to set IV_PLAT and IV_PLAT_REL info that is pushed<br> > to the server.<br> > <br> > IV_PLAT (platform type) is normally inferred from the build target, but<br> > it would be useful to be able to override this from the command line<br> > (e.g. for client to set platform as ChromeOS instead of Linux).<br> > <br> > IV_PLAT_REL (platform release version) would allow for pushing the<br> > platform (e.g. ChromeOS) release version to the server.<br> <br> </span>I'm actually less than enthusiastic about "yay, two more special-case<br> options for OpenVPN" - and even less so to options that enable users<br> to override a fairly well-defined meaning of IV_PLAT with an arbitrary <br> string. Even if it's ChromeOS, compiled with #define TARGET_LINUX, <br> IV_PLAT should reflect that.<br> <br> There is already "--setenv UV_anykey=value" to send arbitrary strings<br> to the server, and in particular, IV_PLAT_VER can already be set by<br> "--setenv IV_PLAT_VER=<version>".<br> <br> There's one catch to this, though - for some reason that escapes me right <br> now we have decided that IV_PLAT_VER= and the UV_ user-defined strings <br> are only sent if --push-peer-info is also configured on the client<br> (while IV_GUI_VER, also settable with --setenv, is always sent).<br> <br> So we might want to revisit that decision.<br> <span class="HOEnZb"><font color="#888888"><br> gert<br> <br> -- <br> "If was one thing all people took for granted, was conviction that if you <br> feed honest figures into a computer, honest figures come out. Never doubted <br> it myself till I met a computer with a sense of humor."<br> Robert A. Heinlein, The Moon is a Harsh Mistress<br> <br> Gert Doering - Munich, Germany <a href="mailto:gert@greenie.muc.de">gert@greenie.muc.de</a><br> </font></span></blockquote></div><br></div> ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot
Hi, On Fri, Apr 13, 2018 at 12:34:15PM -0700, Micah Morton wrote: > @gert: > > From the help message: "--setenv name value : Set a custom environmental > variable to pass to script." > > --setenv appears to set string values for scripts only, not for the main > openvpn process (which is reading them in the push_peer_info() function). > Starting a test openvpn server with `--setenv foo bar` and then running > `strings` on /proc/PID/environ doesn't show "foo=bar". This suggests that > getenv() calls in the main openvpn process that try to read these vars may > return NULL. This stuff isn't pushed into openvpn's own environment, because it does not need to. It goes into session->opt->es, which basically is a linked list of "NAME=VALUE" strings (and ssl.c / push_peer_info() walks that). When external programs are called, opt->es is put into *their* environment. gert
Am 13.04.2018 um 19:23 schrieb Micah Morton: > From 557d2e73bf21ddb9d07b43f716c7914d610e7392 Mon Sep 17 00:00:00 2001 > From: Micah Morton <mortonm@chromium.org <mailto:mortonm@chromium.org>> > Date: Fri, 13 Apr 2018 09:55:22 -0700 > Subject: [PATCH] Specify platform and version on command line. > > Add --iv-plat and --iv-plat-rel command line args, and use the values > passed to these args to set IV_PLAT and IV_PLAT_REL info that is pushed > to the server. > > IV_PLAT (platform type) is normally inferred from the build target, but > it would be useful to be able to override this from the command line > (e.g. for client to set platform as ChromeOS instead of Linux). > > IV_PLAT_REL (platform release version) would allow for pushing the > platform (e.g. ChromeOS) release version to the server. > My Android client already uses setenv IV_PLAT_VER to send platform specific information. I think setting IV_PLAT_VER (and extend that to other platforms, might be android specific at the moment) should also work for you. E.g.. setenv IV_PLAT_VER "27 8.1.0 arm64-v8a google taimen Pixel 2 XL" Arne <html> <head> <meta http-equiv="Content-Type" content="text/html; charset=utf-8"> </head> <body text="#000000" bgcolor="#FFFFFF"> <div class="moz-cite-prefix">Am 13.04.2018 um 19:23 schrieb Micah Morton:<br> </div> <blockquote type="cite" cite="mid:CAJ-EccN7eQsSaFn4MH4qRTKx+zZ-1YcGAe0XU8813p7k=W2i4g@mail.gmail.com"> <div dir="ltr"> <div>From 557d2e73bf21ddb9d07b43f716c7914d610e7392 Mon Sep 17 00:00:00 2001</div> <div>From: Micah Morton <<a href="mailto:mortonm@chromium.org" moz-do-not-send="true">mortonm@chromium.org</a>></div> <div>Date: Fri, 13 Apr 2018 09:55:22 -0700</div> <div>Subject: [PATCH] Specify platform and version on command line.</div> <div><br> </div> <div>Add --iv-plat and --iv-plat-rel command line args, and use the values</div> <div>passed to these args to set IV_PLAT and IV_PLAT_REL info that is pushed</div> <div>to the server.</div> <div><br> </div> <div>IV_PLAT (platform type) is normally inferred from the build target, but</div> <div>it would be useful to be able to override this from the command line</div> <div>(e.g. for client to set platform as ChromeOS instead of Linux).</div> <div><br> </div> <div>IV_PLAT_REL (platform release version) would allow for pushing the</div> <div>platform (e.g. ChromeOS) release version to the server.</div> <div><br> </div> </div> </blockquote> My Android client already uses <br> <br> setenv IV_PLAT_VER to send platform specific information. I think setting IV_PLAT_VER (and extend that to other platforms, might be android specific at the moment) should also work for you. E.g..<br> <br> setenv IV_PLAT_VER "27 8.1.0 arm64-v8a google taimen Pixel 2 XL"<br> <br> Arne<br> </body> </html> ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot
@gert: Good point. We should be able to use UV_* variables to do what we need. Thanks! On Fri, Apr 13, 2018 at 4:24 PM, Arne Schwabe <arne@rfc2549.org> wrote: > Am 13.04.2018 um 19:23 schrieb Micah Morton: > > From 557d2e73bf21ddb9d07b43f716c7914d610e7392 Mon Sep 17 00:00:00 2001 > From: Micah Morton <mortonm@chromium.org> > Date: Fri, 13 Apr 2018 09:55:22 -0700 > Subject: [PATCH] Specify platform and version on command line. > > Add --iv-plat and --iv-plat-rel command line args, and use the values > passed to these args to set IV_PLAT and IV_PLAT_REL info that is pushed > to the server. > > IV_PLAT (platform type) is normally inferred from the build target, but > it would be useful to be able to override this from the command line > (e.g. for client to set platform as ChromeOS instead of Linux). > > IV_PLAT_REL (platform release version) would allow for pushing the > platform (e.g. ChromeOS) release version to the server. > > My Android client already uses > > setenv IV_PLAT_VER to send platform specific information. I think setting > IV_PLAT_VER (and extend that to other platforms, might be android specific > at the moment) should also work for you. E.g.. > > setenv IV_PLAT_VER "27 8.1.0 arm64-v8a google taimen Pixel 2 XL" > > Arne > <div dir="ltr">@gert:<div><br></div><div>Good point. We should be able to use UV_* variables to do what we need.</div><div><br></div><div>Thanks!</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Apr 13, 2018 at 4:24 PM, Arne Schwabe <span dir="ltr"><<a href="mailto:arne@rfc2549.org" target="_blank">arne@rfc2549.org</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"> <div text="#000000" bgcolor="#FFFFFF"><span class=""> <div class="m_-697804746895640438moz-cite-prefix">Am 13.04.2018 um 19:23 schrieb Micah Morton:<br> </div> <blockquote type="cite"> <div dir="ltr"> <div>From 557d2e73bf21ddb9d07b43f716c791<wbr>4d610e7392 Mon Sep 17 00:00:00 2001</div> <div>From: Micah Morton <<a href="mailto:mortonm@chromium.org" target="_blank">mortonm@chromium.org</a>></div> <div>Date: Fri, 13 Apr 2018 09:55:22 -0700</div> <div>Subject: [PATCH] Specify platform and version on command line.</div> <div><br> </div> <div>Add --iv-plat and --iv-plat-rel command line args, and use the values</div> <div>passed to these args to set IV_PLAT and IV_PLAT_REL info that is pushed</div> <div>to the server.</div> <div><br> </div> <div>IV_PLAT (platform type) is normally inferred from the build target, but</div> <div>it would be useful to be able to override this from the command line</div> <div>(e.g. for client to set platform as ChromeOS instead of Linux).</div> <div><br> </div> <div>IV_PLAT_REL (platform release version) would allow for pushing the</div> <div>platform (e.g. ChromeOS) release version to the server.</div> <div><br> </div> </div> </blockquote></span> My Android client already uses <br> <br> setenv IV_PLAT_VER to send platform specific information. I think setting IV_PLAT_VER (and extend that to other platforms, might be android specific at the moment) should also work for you. E.g..<br> <br> setenv IV_PLAT_VER "27 8.1.0 arm64-v8a google taimen Pixel 2 XL"<span class="HOEnZb"><font color="#888888"><br> <br> Arne<br> </font></span></div> </blockquote></div><br></div> ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot
diff --git a/src/openvpn/init.c b/src/openvpn/init.c index 133a9f5..1cb76ad 100644 --- a/src/openvpn/init.c +++ b/src/openvpn/init.c @@ -2723,6 +2723,14 @@ do_init_crypto_tls(struct context *c, const unsigned int flags) { to.push_peer_info_detail = 0; } + if (options->iv_plat) + { + to.iv_plat = options->iv_plat; + } + if (options->iv_plat_rel) + { + to.iv_plat_rel = options->iv_plat_rel; + } #endif /* should we not xmit any packets until we get an initial diff --git a/src/openvpn/options.c b/src/openvpn/options.c index 8dee5d1..d9559a0 100644 --- a/src/openvpn/options.c +++ b/src/openvpn/options.c @@ -229,6 +229,8 @@ static const char usage_message[] = "--client-nat snat|dnat network netmask alias : on client add 1-to-1 NAT rule.\n" #ifdef ENABLE_PUSH_PEER_INFO "--push-peer-info : (client only) push client info to server.\n" + "--iv-plat: (client only) platform type.\n" + "--iv-plat-rel: (client only) platform release version.\n" #endif "--setenv name value : Set a custom environmental variable to pass to script.\n" "--setenv FORWARD_COMPATIBLE 1 : Relax config file syntax checking to allow\n" @@ -1781,6 +1783,8 @@ show_settings(const struct options *o) SHOW_BOOL(single_session); #ifdef ENABLE_PUSH_PEER_INFO SHOW_BOOL(push_peer_info); + SHOW_STR(iv_plat); + SHOW_STR(iv_plat_rel); #endif SHOW_BOOL(tls_exit); @@ -7837,6 +7841,20 @@ add_option(struct options *options, VERIFY_PERMISSION(OPT_P_GENERAL); options->push_peer_info = true; } + + else if (streq(p[0], "iv-plat") && p[1] && !p[2]) + { + VERIFY_PERMISSION(OPT_P_GENERAL); + options->iv_plat = p[1]; + } + + else if (streq(p[0], "iv-plat-rel") && p[1] && !p[2]) + { + VERIFY_PERMISSION(OPT_P_GENERAL); + options->iv_plat_rel = p[1]; + } + + #endif else if (streq(p[0], "tls-exit") && !p[1]) { diff --git a/src/openvpn/options.h b/src/openvpn/options.h index 01a7b26..9da4058 100644 --- a/src/openvpn/options.h +++ b/src/openvpn/options.h @@ -575,6 +575,8 @@ struct options #ifdef ENABLE_PUSH_PEER_INFO bool push_peer_info; + const char *iv_plat; + const char *iv_plat_rel; #endif bool tls_exit; diff --git a/src/openvpn/ssl.c b/src/openvpn/ssl.c index 0739cf7..1265177 100644 --- a/src/openvpn/ssl.c +++ b/src/openvpn/ssl.c @@ -2245,6 +2245,7 @@ push_peer_info(struct buffer *buf, struct tls_session *session) buf_printf(&out, "IV_VER=%s\n", PACKAGE_VERSION); /* push platform */ + if (session->opt->iv_plat == NULL) { #if defined(TARGET_LINUX) buf_printf(&out, "IV_PLAT=linux\n"); #elif defined(TARGET_SOLARIS) @@ -2262,6 +2263,14 @@ push_peer_info(struct buffer *buf, struct tls_session *session) #elif defined(_WIN32) buf_printf(&out, "IV_PLAT=win\n"); #endif + } else { + buf_printf(&out, "IV_PLAT=%s\n", session->opt->iv_plat); + } + + if (session->opt->iv_plat_rel != NULL) + { + buf_printf(&out, "IV_PLAT_REL=%s\n", session->opt->iv_plat_rel); + } /* support for P_DATA_V2 */ buf_printf(&out, "IV_PROTO=2\n"); diff --git a/src/openvpn/ssl_common.h b/src/openvpn/ssl_common.h index 25bffd5..d95c2ef 100644 --- a/src/openvpn/ssl_common.h +++ b/src/openvpn/ssl_common.h @@ -251,6 +251,8 @@ struct tls_options bool pull; #ifdef ENABLE_PUSH_PEER_INFO int push_peer_info_detail; + const char *iv_plat; + const char *iv_plat_rel; #endif int transition_window; int handshake_window;