| Message ID | 20260821182442.13542-1-gert@greenie.muc.de |
|---|---|
| State | New |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:4306:b0:87d:ab56:3700 with SMTP id q6csp1554275mae;
Fri, 21 Aug 2026 11:25:01 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AHgh+RrnMB5rcBUzz0bN+yO11wVLCrfr99sB7Xj4ydW4LAiKYkENLf1Htz74HXZiechBQ/Wz7WRCxGNZ5ss=@openvpn.net
X-Received: by 2002:a05:6870:45a8:b0:456:dbed:6b60 with SMTP id
586e51a60fabf-4637f6761abmr1113821fac.1.1787336701045;
Fri, 21 Aug 2026 11:25:01 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787336701; cv=none;
d=google.com; s=arc-20260327;
b=TpSU1W7b6zZXB8KjW6jCqhRvBG8zjZ7h/Y894+TCK0Q7X6PxZIbsHmVlwjcIxCQKtm
sqSTwlhD96kp1nGj9wy5Nr19tUOxoliPXWXGY3ih+w7Q5M0tSsO7cY3QSTal/3NhFSyd
lTHXMi0qzYRGUYVbBP8/pdOPaZw3nPep0B5Y5Vy+S97XeaARXXORJ0I2KRGhI9kwYA/m
ofCh0zidujWHnaSgD7Quq9mYECVHVEqIzJuglX3nbzbZR3z1RJPuzgipAQT6S19ZF2Ws
8nDSBaBwcefofircF5YrZvXWH3m8H2jZHDikVvPIvMCQHaE8c6hlStxv3rHwewpofvDd
7Mew==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature;
bh=zSjoYOJu5YbDYWSYzPoF5jgSefVLSpdovk0DvmsR7ac=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=WetEfl7SlOV8dkxN8mAnkk1ULISjgVxfSkLFcL1FCrKnWbBuFqHwUQzoaWPCuupznW
VQfquF8EUpaP9rxpg4ARAaDhBhtjRD/JaC2gT0fm8hxPH9K8LVdfXEJzQqhSPAfBgcrH
oDcVlELhXHgXimMhNbqv09jnK5VEd9uzJLQmJJHI7aSvkmID+TCGrhRk63SixR4gCDek
AwI6U3CvAsG1eX4LpiVBGlwTRg4425PC0K1O/E3u2GGKXfJSTWqQP4lHN03Sc+OK0hMk
DvngeJ3gVIZAvxAZg9w39pBDLx/b33qvy8jqAwK3iodjGvXDWN2M+xQnkaUxhyPVnnbk
mSdg==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b="e/DqxEja";
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=iHEOddIu;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=GdglUv2D;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
586e51a60fabf-4638366d53dsi133720fac.271.2026.08.21.11.25.00
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Fri, 21 Aug 2026 11:25:00 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b="e/DqxEja";
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=iHEOddIu;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=GdglUv2D;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=zSjoYOJu5YbDYWSYzPoF5jgSefVLSpdovk0DvmsR7ac=; b=e/DqxEjaxuuC8Ty1GsuA2HiTT9
TZkQQz9uihz1U9Oysjh5imQrExKgnTOKtincdZhoEMDjeQbBrznCjyRlg7n/iavvzPiOoq1FYJpVs
/d+oMa6+p2Owoi7ii6n6fSn/6p91AeH5wYoeU4Bg8InN/BazY/BG8TrTn4nHw8TKmkOA=;
Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com)
by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1wxTvE-0006uo-4d;
Fri, 21 Aug 2026 18:24:53 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <gert@blue4.greenie.muc.de>) id 1wxTvC-0006uf-9Z
for openvpn-devel@lists.sourceforge.net;
Fri, 21 Aug 2026 18:24:51 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=no5rE22eeh/+rv+/aPRgVoJ2SPgaEeJZfeKBPyHH/+U=; b=iHEOddIuZRrjeo5SLiy6T+E45u
H4vYCjjQV+fC5jN/xVREEi0L1QrMIVt9sM4Dk0LsxuOtu03AVIJ6ruqYVz1rFt3stkI5D+Gp5L0wP
8tY16YTt/K+YxBRkZ6gXdOMem5JxY1zZG4i6x/qfvZ9fYR8d0llsnkrAoxZXMufmUWDI=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=no5rE22eeh/+rv+/aPRgVoJ2SPgaEeJZfeKBPyHH/+U=; b=GdglUv2DYIAzcdW14GKZpD2fms
rWXu37NksH+3t9QllNe2MuZpuJmvQCNggyly6pDxH7ZAI1I8WVjSE/sA0LQQXJnIw4WydooxbH72/
oncWuYBC3j0N/p5tGd2gwVuM8J6tB8srp7Zly9QbW8OwEoUTABKsceeo+JzrWSmw90cI=;
Received: from [193.149.48.129] (helo=blue.greenie.muc.de)
by sfi-mx-1.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1wxTv8-0006Tv-CZ for openvpn-devel@lists.sourceforge.net;
Fri, 21 Aug 2026 18:24:51 +0000
Received: from blue.greenie.muc.de (localhost [127.0.0.1])
by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 67LIOhe7013562
for <openvpn-devel@lists.sourceforge.net>; Fri, 21 Aug 2026 20:24:43 +0200
Received: (from gert@localhost)
by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 67LIOh4W013561
for openvpn-devel@lists.sourceforge.net; Fri, 21 Aug 2026 20:24:43 +0200
From: Gert Doering <gert@greenie.muc.de>
To: openvpn-devel@lists.sourceforge.net
Date: Fri, 21 Aug 2026 20:24:34 +0200
Message-ID: <20260821182442.13542-1-gert@greenie.muc.de>
X-Mailer: git-send-email 2.53.0
In-Reply-To:
<gerrit.1779197752000.I4068bf8175c23151298d142dc920ab89f861a411@gerrit.openvpn.net>
References:
<gerrit.1779197752000.I4068bf8175c23151298d142dc920ab89f861a411@gerrit.openvpn.net>
MIME-Version: 1.0
X-Spam-Score: 1.3 (+)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-2.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: From: Antonio Quartulli <antonio@mandelbit.com> As per
RFC768,
when the UDP checksum is zero, it means it was not computed by the source,
therefore any NAT processing along the way should leave the checksum alone
and not update it. Failing to do so [...]
Content analysis details: (1.3 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Headers-End: 1wxTv8-0006Tv-CZ
Subject: [Openvpn-devel] [PATCH v1] clinat: do not adjust UDP checksum if
zero
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1874158368733728408
X-GMAIL-MSGID: 1874158368733728408
|
| Series |
[Openvpn-devel,v1] clinat: do not adjust UDP checksum if zero
|
|
Commit Message
Gert Doering
Aug. 21, 2026, 6:24 p.m. UTC
From: Antonio Quartulli <antonio@mandelbit.com> As per RFC768, when the UDP checksum is zero, it means it was not computed by the source, therefore any NAT processing along the way should leave the checksum alone and not update it. Failing to do so would result in computing a bogus value. At the same time, if the result of updating a non-zero checksum ends up being zero, as per the same RFC, we must store its one-complement (0xFFFF) as zero is reserved for "checksum not computed", as mentioned above. Ensure our Client NAT code follows both rules. Github: closes OpenVPN/openvpn#1037 Reported-by: Jeff Salee <jeff@samjackson.com> Change-Id: I4068bf8175c23151298d142dc920ab89f861a411 Signed-off-by: Antonio Quartulli <antonio@mandelbit.com> Acked-by: Razvan Cojocaru <razvanc@mailbox.org> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1681 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1681 This mail reflects revision 1 of this Change. Acked-by according to Gerrit (reflected above): Razvan Cojocaru <razvanc@mailbox.org>
Comments
This is technically correct. There are caveats for IPv6 (namely,
zero is not allowed and a receiver is expected to drop packets with
such a checksum, RFC8200 8.1). If we don't drop, but also do not
modify the field, we're not violating this rule. On transmission,
the 0x0000->0xffff still needs to happen, so this code is correct
for IPv4 and IPv6.
I have not actually tested this, just stared at the code :-) - and we
have +2 from Razvan (thanks).
I'm applying this to release/2.7, as it's clearly a bug fix. I am not
backporting to 2.6, 2.5, 2.4 etc as it's not a security issue, and the
first report we ever had was in May this year - so it seems to hit
infrequently enough (plus --client-nat is an edge case anyway).
Your patch has been applied to the master and release/2.7 branch (bugfix).
commit c797db6225755e6d7144d433ed55d3992d8ff141 (master)
commit e1d0005ec1a15fffbebc14fcf42ad36332e3a36a (release/2.7)
Author: Antonio Quartulli
Date: Fri Aug 21 20:24:34 2026 +0200
clinat: do not adjust UDP checksum if zero
Signed-off-by: Antonio Quartulli <antonio@mandelbit.com>
Acked-by: Razvan Cojocaru <razvanc@mailbox.org>
Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1681
Message-Id: <20260821182442.13542-1-gert@greenie.muc.de>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg38581.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
diff --git a/src/openvpn/clinat.c b/src/openvpn/clinat.c index 32c1325..3724022 100644 --- a/src/openvpn/clinat.c +++ b/src/openvpn/clinat.c @@ -258,7 +258,23 @@ { if (BLENZ(ipbuf) >= sizeof(struct openvpn_iphdr) + sizeof(struct openvpn_udphdr)) { - ADJUST_CHECKSUM(accumulate, h->u.udp.check); + /* RFC 768: a UDP checksum of 0 means "no checksum computed". + * Do not run the incremental adjustment over a non-checksum, + * or we will write a bogus non-zero value into the field. + */ + if (h->u.udp.check) + { + ADJUST_CHECKSUM(accumulate, h->u.udp.check); + + if (!h->u.udp.check) + { + /* RFC 768: a computed checksum of 0 must be transmitted + * as 0xFFFF (one-complement), because 0 is reserved for + * "no checksum computed" + */ + h->u.udp.check = 0xFFFF; + } + } } } }