| Message ID | 20260430124020.23066-1-gert@greenie.muc.de |
|---|---|
| State | New |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:cc85:b0:84a:48f:a1fd with SMTP id md5csp855984mab;
Thu, 30 Apr 2026 05:40:47 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AFNElJ9IdD3VQNKed+ZBYgaslBfAzYIbUz6Oqh81G3e6Epez3uPIUMN0qrXDx0cMIL54b4KzOQCdeXaePCA=@openvpn.net
X-Received: by 2002:a05:6820:1885:b0:694:991f:62e5 with SMTP id
006d021491bc7-6967aa7a9e8mr1131622eaf.58.1777552847379;
Thu, 30 Apr 2026 05:40:47 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1777552847; cv=none;
d=google.com; s=arc-20240605;
b=jVVX95bad4EqHY/HCUBG7ZeqWU0hSa+yhFwvG+6AA0ueZ+j91tT9W037rvWVoqjj5Z
BiJALxxGJHwc9ttpoDq4gWaUHklXx4xCpG61lka3B9BeVLEXOH79BbfFLTLYoz6gPAgM
YguF4FzWagDm1LN9CFhD0fXJK0kn7XlhES3edPFe+LI/YTcNd3R6xPp6IoEikVwlVv0n
674n8OvbI4HBlsJG0kTSB5c1/9Ph2Vkj+emZ/2QVdsuVlItPn6NwSPSM5Exh+F1gR62N
SiNGXlHySR0RSWY/bJl0bIw39MIyQgZxnEoUelxFhWP4hovHsRA9ibLlYZLt2AnMCu51
r95g==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20240605;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature;
bh=wb5jtKfmflGrcK2sCeH0jEdAaao/ogw80P4Va5zUYDU=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=iHEPurKBikGtZMWbM9hxYLCdLySGpDuLfdIDLznTgs2oeeoGFS4CHSV2nQOKGLCgGi
4JVp24qOeXuDbxJX9ibKPN3RAmlPWfP2m6i7a3DnbNv8Ipo/lvHmJ6xS2cHDovEfdtr5
aCLp5+kd7jJSR7iSE9Z3bHzur10vI4mLe7g03BipCuDPgTT2pN/aeNYwLhe5byuDBtuv
EZxGzx3lnCwwmXYtLYcHaRAfN6tt6HqtRjI1L+WM6a7To9/rQoLtQ54awM3OS/rcqSHR
p2I9Rcja9K/fannnsoLRhh1HvQSJsxjeyCMCUO17cFBmBEjbNNx6TG0iWSLyPktDPrjU
cjdg==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=WiGU8kqp;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=g0zCZXbJ;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=Kz2JMolY;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
586e51a60fabf-4343742d0f2si1046204fac.260.2026.04.30.05.40.46
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Thu, 30 Apr 2026 05:40:47 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=WiGU8kqp;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=g0zCZXbJ;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=Kz2JMolY;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=wb5jtKfmflGrcK2sCeH0jEdAaao/ogw80P4Va5zUYDU=; b=WiGU8kqpxyG6w3wZ7blo1PI3Kv
saPcmcuh8vs8B2IZkckoMFLi+HWJ1TzA5fI1KfNRrBkWgVwPSbWEN5q0G6FLI4D+HdMy29k7w2oiL
tXAk3txPF6kpzF5+Ufsuljs64w4CN0MciKMc5PfmCjF/kkddyRwne4nLM/fUC0PHln9I=;
Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com)
by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1wIQh4-0003o2-DJ;
Thu, 30 Apr 2026 12:40:38 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <gert@blue4.greenie.muc.de>) id 1wIQh1-0003ns-4V
for openvpn-devel@lists.sourceforge.net;
Thu, 30 Apr 2026 12:40:35 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=lu2bZPJDuQvagfFkelXRJ3SkmNnlO7cBG30xSRAMbAw=; b=g0zCZXbJpBu+cpGMs7VxuoSglC
SJ0vR/i5RBSjdaBrMqOgZLhvm/t2SPowe6Pi4+Wkn9sRBkeUn6O8fMFinA7sghE8SwkKqPPrYf6AQ
QkTvQeXsQMTfWOkxboElzqLyWG5nHhI+WUJwGXe5DAymfe1M+uGT2lDADyZ61IbCiIt4=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=lu2bZPJDuQvagfFkelXRJ3SkmNnlO7cBG30xSRAMbAw=; b=Kz2JMolY78z7d+cdlK0532Xthv
ofocaOkLNe3B9BxHP4v73xtCExOAnYzaILtJ8YiyEKzjwRSiJsOnp4xvqEXutn72EsbXEvZVxQ/3v
maWjpKJH9gRhy9QxHAG+rke6OFQV53zT9AX3UKEzxQGCjFCQWRfpCQ5usWNoQdEQE7zE=;
Received: from [193.149.48.129] (helo=blue.greenie.muc.de)
by sfi-mx-2.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1wIQgz-0002wM-6k for openvpn-devel@lists.sourceforge.net;
Thu, 30 Apr 2026 12:40:35 +0000
Received: from blue.greenie.muc.de (localhost [127.0.0.1])
by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 63UCeLxQ023085
for <openvpn-devel@lists.sourceforge.net>; Thu, 30 Apr 2026 14:40:21 +0200
Received: (from gert@localhost)
by blue.greenie.muc.de (8.18.1/8.18.1/Submit) id 63UCeLgT023084
for openvpn-devel@lists.sourceforge.net; Thu, 30 Apr 2026 14:40:21 +0200
From: Gert Doering <gert@greenie.muc.de>
To: openvpn-devel@lists.sourceforge.net
Date: Thu, 30 Apr 2026 14:40:14 +0200
Message-ID: <20260430124020.23066-1-gert@greenie.muc.de>
X-Mailer: git-send-email 2.52.0
In-Reply-To:
<gerrit.1777503561000.I0cb093e0116e92d874162d51be777aa43674c115@gerrit.openvpn.net>
References:
<gerrit.1777503561000.I0cb093e0116e92d874162d51be777aa43674c115@gerrit.openvpn.net>
MIME-Version: 1.0
X-Spam-Score: 1.3 (+)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-1.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: From: Selva Nair <selva.nair@gmail.com> Github: fixes
OpenVPN/openvpn#1024
Change-Id: I0cb093e0116e92d874162d51be777aa43674c115 Signed-off-by: Selva
Nair <selva.nair@gmail.com> Acked-by: Frank Lichtenheld
<frank@lichtenheld.com>
Gerrit URL: https://gerrit.openvpn.net/c/openv [...]
Content analysis details: (1.3 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Headers-End: 1wIQgz-0002wM-6k
Subject: [Openvpn-devel] [PATCH v1] dns: minimalist fix for dnssec setting
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: =?utf-8?q?1863899255001397820?=
X-GMAIL-MSGID: =?utf-8?q?1863899255001397820?=
|
| Series |
[Openvpn-devel,v1] dns: minimalist fix for dnssec setting
|
|
Commit Message
Gert Doering
April 30, 2026, 12:40 p.m. UTC
From: Selva Nair <selva.nair@gmail.com> Github: fixes OpenVPN/openvpn#1024 Change-Id: I0cb093e0116e92d874162d51be777aa43674c115 Signed-off-by: Selva Nair <selva.nair@gmail.com> Acked-by: Frank Lichtenheld <frank@lichtenheld.com> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1644 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1644 This mail reflects revision 1 of this Change. Signed-off-by line for the author was added as per our policy. Acked-by according to Gerrit (reflected above): Frank Lichtenheld <frank@lichtenheld.com>
Comments
Thanks for coming up with a minimal patch quickly, until we have decided
what "we really want there" and "what windows does".
Frank has tested this, and I have fixed my testbed to actually *show* the
problem - we do windows tests, but the way I had set up the "hidden DNS
things that only resolve if --dns is applied correctly" (unbound with a
local zone) was IPSEC-agnostic - if you ask "the authoritative server"
it will always tell you "yeah, all is valid!". So now we have an unbound
recursor in front of a local bind, with no DNSSEC, and "windows with
dnssec yes" will actually fail to resolve that...
.. and with your patch, we're back to "the system tests pass", so, good.
(Staring at the change also seems to make sense, but I said so for
the other fix as well... so I'm glad we have good before/after tests
this time)
Your patch has been applied to the master and release/2.7 branch.
commit 919f5ced7d2863d51981979a336407b6e0818fcd (master)
commit 9683e1fe273db94ab92e1da2fe55c7929fa7291a (release/2.7)
Author: Selva Nair
Date: Thu Apr 30 14:40:14 2026 +0200
dns: minimalist fix for dnssec setting
Signed-off-by: Selva Nair <selva.nair@gmail.com>
Acked-by: Frank Lichtenheld <frank@lichtenheld.com>
Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1644
Message-Id: <20260430124020.23066-1-gert@greenie.muc.de>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg36797.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
diff --git a/src/openvpn/dns.c b/src/openvpn/dns.c index ce23f1f..954ed52 100644 --- a/src/openvpn/dns.c +++ b/src/openvpn/dns.c @@ -442,7 +442,7 @@ .header = { (add ? msg_add_nrpt_cfg : msg_del_nrpt_cfg), sizeof(nrpt_dns_cfg_message_t), 0 }, .iface = { .index = tt->adapter_index, .name = "" }, - .flags = server->dnssec == DNS_SECURITY_NO ? 0 : nrpt_dnssec, + .flags = server->dnssec == DNS_SECURITY_YES ? nrpt_dnssec : 0, }; strncpynt(nrpt.iface.name, tt->actual_name, sizeof(nrpt.iface.name));