| Message ID | 20230322113408.2057-1-lstipakov@gmail.com |
|---|---|
| State | Accepted |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7300:2310:b0:9f:bfa4:120f with SMTP id r16csp3122128dye;
Wed, 22 Mar 2023 04:34:49 -0700 (PDT)
X-Google-Smtp-Source:
AK7set9y905CTcLZKsiU5WyVX3AtjydxNEGDC7ACb36XsXTxlxMYtsLG9UWa5mtODnMZM2Zu78fO
X-Received: by 2002:a17:902:e8c3:b0:19f:3e9b:7527 with SMTP id
v3-20020a170902e8c300b0019f3e9b7527mr1914037plg.61.1679484889294;
Wed, 22 Mar 2023 04:34:49 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1679484889; cv=none;
d=google.com; s=arc-20160816;
b=QMbZkXFnHj+uXLcMA0WG1atzFpusOZPovum/TEqfixWV8q4DmKNRssQTPHwHI3FKLg
p844wxEEsLlDhPS88ZeVFbyV3PT18nDZKlnL/+idQNquKe27R0sdsDqitZf/AS5wjtjf
gibxXLylTDbQCuiYbNNw2PfFX2iUJqT5GMrbk9bTG7ti1UUOEpETpGHFcmj9ZfRSj3pe
B4L3wPx0Lkj34hgkJLkuGjSXaSjjJth2XDzIeGSVQf1JP3a2dVvXz0nNkqL+s8hH7kQE
vJK9s9pjLCUxpvSuflmdl8cnMTcoU8CPw65ZU2mQfvgZA64TesDRZ96XVAexF7OH8+a8
rV+w==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20160816;
h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:message-id:date:to:from:dkim-signature:dkim-signature
:dkim-signature;
bh=cAamcTIzkFWwA1hMpJRX+NOinPLgnqwPvDpxcmwIZg0=;
b=lIdWGVENRsUg/veVydrAeQprwxSrrYxYX+lnEkTWBC3tpnb3nUCPDfR+CXdJ21u7ms
ZqhmATBuV+zFdkce6DiSrV+ERIn3MV3KWb09XZfV1QrKFO7S/RR7xmqERnOFQ4MsYCPE
VsGnJ9modFr5rV+XpzA2cjKdfB/wANFo6gZEfWvZwjc+4ztPMiD8yjMU8bAccwBCfEE1
AhDqIB8h21ZlgrAUe4+3Fqq98OlbIfyG+KnIdHFc/AsHIsdAi4IaKdPNPOXUhCphF44U
vG15Rs4AVbLF/H+NN2JNxhd1XNratdluk93qSqvM/9xWE7Jqr3cqZqRqy1vAc++8sFlr
UdgA==
ARC-Authentication-Results: i=1; mx.google.com;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=OlvHRSaO;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=QARyYyOq;
dkim=neutral (body hash did not verify) header.i=@gmail.com
header.s=20210112 header.b=IAceNolz;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com
Received: from lists.sourceforge.net ([216.105.38.7])
by mx.google.com with ESMTPS id
m16-20020a170902db1000b0019a85a69776si7139065plx.6.2023.03.22.04.34.48
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Wed, 22 Mar 2023 04:34:49 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=OlvHRSaO;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=QARyYyOq;
dkim=neutral (body hash did not verify) header.i=@gmail.com
header.s=20210112 header.b=IAceNolz;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com
Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com)
by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1pewjf-0004C6-3x;
Wed, 22 Mar 2023 11:34:31 +0000
Received: from [172.30.20.202] (helo=mx.sourceforge.net)
by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <lstipakov@gmail.com>) id 1pewje-0004Bz-DC
for openvpn-devel@lists.sourceforge.net;
Wed, 22 Mar 2023 11:34:31 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:Message-Id:
Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=OSTXJZK4it015Viz//or0fY2OKAixRY1o1nd8BPDcvk=; b=OlvHRSaO8BtMdoHVOQWJg5gSi+
uiL+4mjw2OkvS86AFOTFkBUsfZBq0v3hNe5XhO2juPrbr+ZNmR7dBXTUjH8ub3T8StrWCjXzhhU4m
M/mcUnREAOE05HEHSf83nqr8vxbfb6c83EvOdlatRD62VKdhHZ6pEDNJI0LmKDfCOrAM=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:Message-Id:Date:Subject:Cc:To:From
:Sender:Reply-To:Content-Type:Content-ID:Content-Description:Resent-Date:
Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:
References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post:
List-Owner:List-Archive; bh=OSTXJZK4it015Viz//or0fY2OKAixRY1o1nd8BPDcvk=; b=Q
ARyYyOqobAXVYnweBDXx/8+djmBuxil3SkZtMZMBBUB0PxXNI+TpMoC7qiq8vQ0Uugzx7WmaajnXa
23HRS5fIo905YpFUKagtr5FAruiCxU2lyzsHt1CKMFCNWXce8zhwTQjRM7rIgCIjD38Z+iKUHs9zK
vGz7SOUnAu6nFk9A=;
Received: from mail-lf1-f45.google.com ([209.85.167.45])
by sfi-mx-2.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.95)
id 1pewje-00072S-Eq for openvpn-devel@lists.sourceforge.net;
Wed, 22 Mar 2023 11:34:30 +0000
Received: by mail-lf1-f45.google.com with SMTP id j11so22924539lfg.13
for <openvpn-devel@lists.sourceforge.net>;
Wed, 22 Mar 2023 04:34:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=20210112; t=1679484863;
h=content-transfer-encoding:mime-version:message-id:date:subject:cc
:to:from:from:to:cc:subject:date:message-id:reply-to;
bh=OSTXJZK4it015Viz//or0fY2OKAixRY1o1nd8BPDcvk=;
b=IAceNolzTB9oUoc6xZe04/BhCzi3JOGkmYyFj0I1WGBT2/CzQSWbWYtJKa01qfeVPn
BeaUPDDSqD1DoYEykZqNQ+3Qddp9FQC4IPu1IW3gvMCb097qC/MdM/GtgiZ+nN8TG8wm
cTSe0Ow017LflX75ryb0K/KjO2NqBmwx3phht9b3QrtR2iWwZERGcZFa8gIsit06sLWk
EO6yYn63yTxxsWfJiCTiQGond7klxxdiBzy69q2W547RMtc6ynGrPEjuEfcmJIdeNiph
w+1x2yT/Qm/oRgMI2xyVwfAmoLQ2k2pcc67hOwDIuEohIilxJKLIJVcfmz+zanag1GrG
1DRw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20210112; t=1679484863;
h=content-transfer-encoding:mime-version:message-id:date:subject:cc
:to:from:x-gm-message-state:from:to:cc:subject:date:message-id
:reply-to;
bh=OSTXJZK4it015Viz//or0fY2OKAixRY1o1nd8BPDcvk=;
b=7cEj1lwzItk9/d+CxeFRjODja7nF96pFehSTUqe/6esA8ePFUGrwskBuLvzo5nkQ3a
mxvi0fERUwToW8IBh4TBACM68txmJG77pKw3Cj5iSY8OUDRbfQdzZhlewOytsFHLzgeV
VrxWaJbD2eZUkz6I2OvAeDlXiK5Ed2t5OlFUyCX4RLHVSX9u9Ggze9CvhIT12YS6YnEs
1Nhtas0nWd0VC9Orx+9Eo7IANUrSeD91O1MMEA6T+Tx2lCK3ElVNnJA3yI6odRHpC7DD
GzxfYkk2wpbzukMB+oKIZiVJ00tAwCUF68vtUrcETdGGJCm1vFJVMQLi3cdBH5reRc8U
bxQA==
X-Gm-Message-State: AO0yUKUdyDfP5t/NrrXenaLShmJJc0i+/4IsJc7hAVtTRjRXNhtrGWPb
wHmMAalKy0y/jghHHJOP6++Bzva7T44=
X-Received: by 2002:ac2:4e72:0:b0:4e9:59cd:4172 with SMTP id
y18-20020ac24e72000000b004e959cd4172mr1872124lfs.0.1679484863385;
Wed, 22 Mar 2023 04:34:23 -0700 (PDT)
Received: from localhost.localdomain ([2a00:1d50:3:0:f49d:d223:9e0f:5671])
by smtp.gmail.com with ESMTPSA id
d14-20020ac244ce000000b004db2b111bf3sm2556558lfm.21.2023.03.22.04.34.22
(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
Wed, 22 Mar 2023 04:34:23 -0700 (PDT)
From: Lev Stipakov <lstipakov@gmail.com>
To: openvpn-devel@lists.sourceforge.net
Date: Wed, 22 Mar 2023 13:34:08 +0200
Message-Id: <20230322113408.2057-1-lstipakov@gmail.com>
X-Mailer: git-send-email 2.38.1.windows.1
MIME-Version: 1.0
X-Spam-Score: -0.2 (/)
X-Spam-Report: Spam detection software,
running on the system "util-spamd-1.v13.lw.sourceforge.com",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: From: Lev Stipakov Make sure we exit if <bytes> is 0 (not
set) and no traffic was produced. According to man page and non-DCO
--inactive
implementation, we exit if amount of bytes produced is less than <bytes>
specified. DCO implementation will do off-by-ones, but we consider it as okay
sinc [...]
Content analysis details: (-0.2 points, 6.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/,
no trust [209.85.167.45 listed in list.dnswl.org]
-0.0 SPF_PASS SPF: sender matches SPF record
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail
provider [lstipakov[at]gmail.com]
0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily
valid
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from
author's domain
-0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.167.45 listed in wl.mailspike.net]
X-Headers-End: 1pewje-00072S-Eq
Subject: [Openvpn-devel] [PATCH] Fix "--inactive <time> 0" behavior for DCO
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Cc: Lev Stipakov <lev@openvpn.net>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: =?utf-8?q?1761067547416308597?=
X-GMAIL-MSGID: =?utf-8?q?1761067547416308597?=
|
| Series |
[Openvpn-devel] Fix "--inactive <time> 0" behavior for DCO
|
|
Commit Message
Lev Stipakov
March 22, 2023, 11:34 a.m. UTC
From: Lev Stipakov <lev@openvpn.net> Make sure we exit if <bytes> is 0 (not set) and no traffic was produced. According to man page and non-DCO --inactive implementation, we exit if amount of bytes produced is less than <bytes> specified. DCO implementation will do off-by-ones, but we consider it as okay since we don't want to complicate code to handle both bytes=0 and >0 cases. Change-Id: I4c089e486728a43bfe42596787c00355838311da Signed-off-by: Lev Stipakov <lev@openvpn.net> --- src/openvpn/forward.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
Comments
Acked-by: Gert Doering <gert@greenie.muc.de> Thanks. I have not actually tested this, but we've discussed this at length before - so this is "obviously correct". The problem here (for readers of the list only) is that "a single packet" is sufficient to keep the connection active if "--inactive ... 0" is used - and "0 bytes" will be "abort". With "if (new_bytes >= 0)", the condition is always true in the DCO path, even if 0 packets have been seen, so it never triggers. It does cause an off-by-one, so if the limit is "1000 bytes", on DCO it will need 1001 bytes now, while non-DCO will be fine with 1000 bytes, but we decided that generally this is not "a single byte" precise, but "lots of traffic" or "not much", so this is acceptable for a simpler condition that people can actually understand in half a year... Your patch has been applied to the master and release/2.6 branch. commit 6c64b46b15476351ca19f9a8f3cb8185aa2c7e07 (master) commit a3c9458d233d35d2afdb866aaa602bebaabf2f59 (release/2.6) Author: Lev Stipakov Date: Wed Mar 22 13:34:08 2023 +0200 Fix '--inactive <time> 0' behavior for DCO Signed-off-by: Lev Stipakov <lev@openvpn.net> Acked-by: Gert Doering <gert@greenie.muc.de> Message-Id: <20230322113408.2057-1-lstipakov@gmail.com> URL: https://www.mail-archive.com/search?l=mid&q=20230322113408.2057-1-lstipakov@gmail.com Signed-off-by: Gert Doering <gert@greenie.muc.de> -- kind regards, Gert Doering
diff --git a/src/openvpn/forward.c b/src/openvpn/forward.c index 28a96f94..b3e0ba5d 100644 --- a/src/openvpn/forward.c +++ b/src/openvpn/forward.c @@ -481,7 +481,7 @@ check_inactivity_timeout(struct context *c) int64_t tot_bytes = c->c2.tun_read_bytes + c->c2.tun_write_bytes; int64_t new_bytes = tot_bytes - c->c2.inactivity_bytes; - if (new_bytes >= c->options.inactivity_minimum_bytes) + if (new_bytes > c->options.inactivity_minimum_bytes) { c->c2.inactivity_bytes = tot_bytes; event_timeout_reset(&c->c2.inactivity_interval);