From patchwork Mon May 18 08:58:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 4953 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:324e:b0:84a:48f:a1fd with SMTP id s14csp1628735maf; Mon, 18 May 2026 01:59:58 -0700 (PDT) X-Forwarded-Encrypted: i=2; AFNElJ/tiAi2jVMgSiw0ytl5tB5as6W+HbmmnIWzsjE/sMukLzptnjJzseV9ThqnX5uka9Za+11KtbbzyE0=@openvpn.net X-Received: by 2002:a05:6830:90b:b0:7dc:1bcd:43be with SMTP id 46e09a7af769-7e49a9379f2mr8601455a34.5.1779094798616; Mon, 18 May 2026 01:59:58 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1779094798; cv=none; d=google.com; s=arc-20240605; b=PN48CmAla7NNEJo3RXx3h7u2unSMud7fPqCwigQXnSfoyrfGqIUOaFbo/N+GsV+tlD S4bPCKFVJsoJ25NtF8hPXu9wRVI9A9ogwhEAnm2+IHp9aQwVAKs+kwWudr8kVj3IoiTm m012U2G+LKgBC+95i1rw8MVJQrELHihQ0YsWSrsahl+h7tAM449qExmhrgZIk6aVwrN7 T1zNY0mMud9UfN1birUpWiM+J30PexxPDvFDpTTnNB3Lx5BfoG67fATTYt6Mx9eUvRhy xVAvErDC4Vd6KkjhIXeGIi16sTOTVc6uKoXdYdhV2W2Sssg4uewxrKMQHA+m+uPfaeIx TwUA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=5lRsLTiBqRiAsK109Bk4VsTVPVdUVJnaQI955m4Z1OM=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=QRUw4rLuyzNSMeUssXamZcg7DRUp2DZ1HetCWJBvrfyjoduAgmpUTL0lrkFjCpK14L NBDClQtFMYCI3eIjIU+tzYhLMAe2IhkY0mQwEpngVlcKAyO8f/mP+vHfC5StUHxxTm2Y C2eF1Ou1q4vlpzcEmxms/jqNVm28HY55dxgZdx5mIhu6DqWMIyjRYIRC6m3nLi/j5C68 /LVZy59F6aOGYYlGdSog45L4mIRtR0xbrZNA5//skBBmvR+fldcfXnjyP54muYAA+cr0 2jPEy6oGH0y92nICNKyU2Chm9QOOup3EIVH4z1HW9gnucddbWUbSOpTN5z+ZThMI2+c2 ideQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=TC7HFUb2; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Oh19hSZl; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=j1EVU5gy; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=KIjmFW1J; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7e55bbdc9dcsi7267842a34.82.2026.05.18.01.59.58 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 18 May 2026 01:59:58 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=TC7HFUb2; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=Oh19hSZl; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=j1EVU5gy; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=KIjmFW1J; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=5lRsLTiBqRiAsK109Bk4VsTVPVdUVJnaQI955m4Z1OM=; b=TC7HFUb24pwDEy2fbdSn3ZbWSH diRR0waZ1/TAniaXnGxjSpQmsWMO2L7Xfqy2palFPIgSFlDqH8uurl9TMoejNYqvGKMTS3HLOvUN2 jLZb3Qh8c3ywkEW6DnWnB0UoDDxyXGduhRrfFDhXzNPV5sgUZw/JBaPv8zLjtaCBEcmo=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wOtpF-0004Sz-UM; Mon, 18 May 2026 08:59:47 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wOtpF-0004Sq-0C for openvpn-devel@lists.sourceforge.net; Mon, 18 May 2026 08:59:46 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=GT6/tjc2Km0j/DgRL1ZjowuxzDGjG5JxYKSM4bGn8Ec=; b=Oh19hSZlh5tZOHASFotk8s5b54 mtA1JOU/NqdlLG2ASLbSY+fvNz/JUsvycN9dAK3+BQeXeXApOOWNbslwYrYR6k4JzXEJeCsPvFO45 7TzTM5ORwe4MKwM3GTSdKcyfDArHcMhsNPDRzPPcu6ktKHa4KkfzB6tVFK26pnrmiqv4=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=GT6/tjc2Km0j/DgRL1ZjowuxzDGjG5JxYKSM4bGn8Ec=; b=j1EVU5gy3OsSahKGTR7ZRIrCPg G4kaGGfh9ioaoeZjZAyEVfkN2UWKIwdBRjjzwx5Ydl2SWc+uD0dqHnhEftR77Kfd09h7lXFS3m0lS sD6TKgbs6b1UrmYXKatULsjndqvnp/wV+G+m86n8ckwlOxffe+A4E7EEHT3odkM7adA8=; Received: from mout-b-206.mailbox.org ([195.10.208.51]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wOtpA-0001vv-9T for openvpn-devel@lists.sourceforge.net; Mon, 18 May 2026 08:59:46 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-206.mailbox.org (Postfix) with ESMTPS id 4gJsDz30Mnz9xT0; Mon, 18 May 2026 10:59:31 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1779094771; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=GT6/tjc2Km0j/DgRL1ZjowuxzDGjG5JxYKSM4bGn8Ec=; b=KIjmFW1JZ0yNXmgQlG/hh84QCC6JkEVlSukJlI+4aSPJuI9vy9BIwf8YkXeBC/JlNd+PMJ A7w1RDXiEJTyBKoBHeAi6caZJL8EV6Gm9oPxJzRvA5HUJr97YQWEY7GAUuwMNrKLMjkFLi 2Bq+H38F68BR1cwvAO0vp5BuXQFLQqDcKUCVHPC3hcaEbx7WcXxRrG3ChzZlHWLnBaEBSY xoQEb+CMNthea4VIhnqWuL00CgEMVRQcYzoxpTRvvnpxlAQ7ML5qtJhxoxZq2NeEC9a/Sq Ybz/F2AXny9UznJ54RK+m5to+1l2J0A4Yt0MI50xeMz0HQ2SxfJZ+/sG7wQBtw== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Mon, 18 May 2026 10:58:41 +0200 Message-ID: <20260518085908.135570-3-ralf@mandelbit.com> In-Reply-To: <20260518085908.135570-1-ralf@mandelbit.com> References: <20260518085908.135570-1-ralf@mandelbit.com> MIME-Version: 1.0 X-Rspamd-Queue-Id: 4gJsDz30Mnz9xT0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Extend ovpn-cli set_peer to pass the peer mssfix attribute. Use -1 as the selftest CLI sentinel for leaving mssfix unchanged, so existing timeout-only peer updates can keep omitting the netlink attrib [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1wOtpA-0001vv-9T Subject: [Openvpn-devel] [PATCH ovpn net-next v2 3/3] selftests: ovpn: add mssfix coverage X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: =?utf-8?q?1865516107398164547?= X-GMAIL-MSGID: =?utf-8?q?1865516107398164547?= Extend ovpn-cli set_peer to pass the peer mssfix attribute. Use -1 as the selftest CLI sentinel for leaving mssfix unchanged, so existing timeout-only peer updates can keep omitting the netlink attribute. Add an ovpn test stage that configures mssfix on each side of a peer pair and verifies the MSS advertised on TCP SYN packets seen on the tunnel device. This covers both TX-side and RX-side clamping, and also checks that an invalid non-zero MSS value is rejected. Signed-off-by: Ralf Lici --- Changes since v1 (https://lore.kernel.org/openvpn-devel/20260515075941.102225-3-ralf@mandelbit.com/): - parse mssfix into long before narrowing in ovpn-cli tools/testing/selftests/net/ovpn/ovpn-cli.c | 20 ++++- .../selftests/net/ovpn/test-close-socket.sh | 4 +- tools/testing/selftests/net/ovpn/test-mark.sh | 4 +- tools/testing/selftests/net/ovpn/test.sh | 75 +++++++++++++++++-- 4 files changed, 90 insertions(+), 13 deletions(-) diff --git a/tools/testing/selftests/net/ovpn/ovpn-cli.c b/tools/testing/selftests/net/ovpn/ovpn-cli.c index d40953375c86..67351f33e7c8 100644 --- a/tools/testing/selftests/net/ovpn/ovpn-cli.c +++ b/tools/testing/selftests/net/ovpn/ovpn-cli.c @@ -10,6 +10,7 @@ #include #include #include +#include #include #include #include @@ -129,6 +130,7 @@ struct ovpn_ctx { __u32 keepalive_interval; __u32 keepalive_timeout; + int mssfix; enum ovpn_key_direction key_dir; enum ovpn_key_slot key_slot; @@ -732,6 +734,8 @@ static int ovpn_set_peer(struct ovpn_ctx *ovpn) ovpn->keepalive_interval); NLA_PUT_U32(ctx->nl_msg, OVPN_A_PEER_KEEPALIVE_TIMEOUT, ovpn->keepalive_timeout); + if (ovpn->mssfix >= 0) + NLA_PUT_U16(ctx->nl_msg, OVPN_A_PEER_MSSFIX, ovpn->mssfix); nla_nest_end(ctx->nl_msg, attr); ret = ovpn_nl_msg_send(ctx, NULL); @@ -1730,13 +1734,15 @@ static void usage(const char *cmd) fprintf(stderr, "\tmark: socket FW mark value\n"); fprintf(stderr, - "* set_peer : set peer attributes\n"); + "* set_peer : set peer attributes\n"); fprintf(stderr, "\tiface: ovpn interface name\n"); fprintf(stderr, "\tpeer_id: peer ID of the peer to modify\n"); fprintf(stderr, "\tkeepalive_interval: interval for sending ping messages\n"); fprintf(stderr, "\tkeepalive_timeout: time after which a peer is timed out\n"); + fprintf(stderr, + "\tmssfix: TCP MSS value to clamp SYN packets to (0 disables, -1 leaves unchanged)\n"); fprintf(stderr, "* del_peer : delete peer\n"); fprintf(stderr, "\tiface: ovpn interface name\n"); @@ -2166,6 +2172,7 @@ static int ovpn_run_cmd(struct ovpn_ctx *ovpn) static int ovpn_parse_cmd_args(struct ovpn_ctx *ovpn, int argc, char *argv[]) { + long mssfix; int ret; /* no args required for LISTEN_MCAST */ @@ -2307,7 +2314,7 @@ static int ovpn_parse_cmd_args(struct ovpn_ctx *ovpn, int argc, char *argv[]) } break; case CMD_SET_PEER: - if (argc < 6) + if (argc < 7) return -EINVAL; ovpn->peer_id = strtoul(argv[3], NULL, 10); @@ -2329,6 +2336,14 @@ static int ovpn_parse_cmd_args(struct ovpn_ctx *ovpn, int argc, char *argv[]) "keepalive interval value out of range\n"); return -1; } + + errno = 0; + mssfix = strtol(argv[6], NULL, 10); + if (errno == ERANGE || mssfix < -1 || mssfix > UINT16_MAX) { + fprintf(stderr, "mssfix value out of range\n"); + return -1; + } + ovpn->mssfix = mssfix; break; case CMD_DEL_PEER: if (argc < 4) @@ -2442,6 +2457,7 @@ int main(int argc, char *argv[]) memset(&ovpn, 0, sizeof(ovpn)); ovpn.sa_family = AF_UNSPEC; ovpn.cipher = OVPN_CIPHER_ALG_NONE; + ovpn.mssfix = -1; ovpn.cmd = ovpn_parse_cmd(argv[1]); if (ovpn.cmd == CMD_INVALID) { diff --git a/tools/testing/selftests/net/ovpn/test-close-socket.sh b/tools/testing/selftests/net/ovpn/test-close-socket.sh index af1532b4d2da..091c0103bdba 100755 --- a/tools/testing/selftests/net/ovpn/test-close-socket.sh +++ b/tools/testing/selftests/net/ovpn/test-close-socket.sh @@ -41,10 +41,10 @@ ovpn_prepare_network() { peer_ns="ovpn_peer${p}" ovpn_cmd_ok "set peer0 timeout for peer ${p}" \ ip netns exec ovpn_peer0 ${OVPN_CLI} set_peer tun0 \ - ${p} 60 120 + ${p} 60 120 -1 ovpn_cmd_ok "set peer${p} timeout for peer ${p}" \ ip netns exec "${peer_ns}" ${OVPN_CLI} set_peer \ - tun${p} $((p + OVPN_ID_OFFSET)) 60 120 + tun${p} $((p + OVPN_ID_OFFSET)) 60 120 -1 done } diff --git a/tools/testing/selftests/net/ovpn/test-mark.sh b/tools/testing/selftests/net/ovpn/test-mark.sh index 5a8f47554286..11af23beea2a 100755 --- a/tools/testing/selftests/net/ovpn/test-mark.sh +++ b/tools/testing/selftests/net/ovpn/test-mark.sh @@ -54,10 +54,10 @@ ovpn_mark_prepare_network() { peer_ns="ovpn_peer${p}" ovpn_cmd_ok "set peer0 timeout for peer ${p}" \ ip netns exec ovpn_peer0 "${OVPN_CLI}" set_peer tun0 \ - "${p}" 60 120 + "${p}" 60 120 -1 ovpn_cmd_ok "set peer${p} timeout for peer ${p}" \ ip netns exec "${peer_ns}" "${OVPN_CLI}" set_peer \ - tun"${p}" $((p + OVPN_ID_OFFSET)) 60 120 + tun"${p}" $((p + OVPN_ID_OFFSET)) 60 120 -1 done } diff --git a/tools/testing/selftests/net/ovpn/test.sh b/tools/testing/selftests/net/ovpn/test.sh index c06e3135fbef..a0630034351a 100755 --- a/tools/testing/selftests/net/ovpn/test.sh +++ b/tools/testing/selftests/net/ovpn/test.sh @@ -49,10 +49,10 @@ ovpn_prepare_network() { peer_ns="ovpn_peer${p}" ovpn_cmd_ok "set peer0 timeout for peer ${p}" \ ip netns exec ovpn_peer0 ${OVPN_CLI} set_peer tun0 \ - ${p} 60 120 + ${p} 60 120 -1 ovpn_cmd_ok "set peer${p} timeout for peer ${p}" \ ip netns exec "${peer_ns}" ${OVPN_CLI} set_peer \ - tun${p} $((p + OVPN_ID_OFFSET)) 60 120 + tun${p} $((p + OVPN_ID_OFFSET)) 60 120 -1 done } @@ -142,6 +142,66 @@ ovpn_run_iperf() { wait "${iperf_pid}" || return 1 } +ovpn_run_mssfix_flow() { + local filter + local iperf_pid + local direction="$1" + local mssfix="$2" + local tcpdump_pid + + filter="tcp and src host 5.5.5.1 and dst host 5.5.5.2" + filter="${filter} and tcp[tcpflags] & tcp-syn != 0" + + ovpn_run_bg iperf_pid ip netns exec ovpn_peer1 iperf3 -1 -s + sleep 1 + + timeout 3s ip netns exec ovpn_peer1 tcpdump --immediate-mode -l -p \ + -vv -nn -i tun1 -c 1 "${filter}" 2>&1 | + grep -iq "mss ${mssfix}" & + tcpdump_pid=$! + sleep 0.3 + + ovpn_cmd_ok "run ${direction} mssfix TCP flow" \ + ip netns exec ovpn_peer0 iperf3 -t 1 -c 5.5.5.2 + + ovpn_cmd_ok "capture ${direction} mssfix TCP SYN" wait "${tcpdump_pid}" + ovpn_cmd_ok "finish ${direction} mssfix TCP server" wait "${iperf_pid}" +} + +ovpn_run_mssfix() { + local peer0_id=$((1 + OVPN_ID_OFFSET)) + + # peer0 will clamp MSS for packets exchanged with peer1 + ovpn_cmd_ok "set peer0 mssfix for peer 1" \ + ip netns exec ovpn_peer0 ${OVPN_CLI} set_peer tun0 1 \ + 60 120 900 + + ovpn_cmd_fail "reject invalid peer0 mssfix for peer 1" \ + ip netns exec ovpn_peer0 ${OVPN_CLI} set_peer tun0 1 \ + 60 120 20 + + ovpn_cmd_ok "clear peer1 mssfix for peer ${peer0_id}" \ + ip netns exec ovpn_peer1 ${OVPN_CLI} set_peer tun1 \ + "${peer0_id}" 60 120 0 + + ovpn_run_mssfix_flow "TX" 900 + + ovpn_cmd_ok "clear peer0 mssfix for peer 1" \ + ip netns exec ovpn_peer0 ${OVPN_CLI} set_peer tun0 1 \ + 60 120 0 + + # peer1 will clamp MSS for packets exchanged with peer0 + ovpn_cmd_ok "set peer1 mssfix for peer ${peer0_id}" \ + ip netns exec ovpn_peer1 ${OVPN_CLI} set_peer tun1 \ + "${peer0_id}" 60 120 901 + + ovpn_run_mssfix_flow "RX" 901 + + ovpn_cmd_ok "clear peer1 mssfix for peer ${peer0_id}" \ + ip netns exec ovpn_peer1 ${OVPN_CLI} set_peer tun1 \ + "${peer0_id}" 60 120 0 +} + ovpn_run_key_rollover() { local p local peer_ns @@ -259,11 +319,11 @@ ovpn_run_timeouts() { # Non-fatal: this may fail in some protocol modes. ovpn_cmd_mayfail "set peer0 timeout for peer ${p} (non-fatal)" \ ip netns exec ovpn_peer0 ${OVPN_CLI} set_peer tun0 \ - ${p} 3 3 + ${p} 3 3 -1 peer_ns="ovpn_peer${p}" ovpn_cmd_ok "disable timeout on peer${p} while peer0 adjusts \ state" ip netns exec "${peer_ns}" ${OVPN_CLI} set_peer \ - tun${p} $((p + OVPN_ID_OFFSET)) 0 0 + tun${p} $((p + OVPN_ID_OFFSET)) 0 0 -1 done # wait for peers to timeout sleep 5 @@ -274,7 +334,7 @@ ovpn_run_timeouts() { peer_ns="ovpn_peer${p}" ovpn_cmd_ok "set peer${p} P2P timeout" \ ip netns exec "${peer_ns}" ${OVPN_CLI} set_peer \ - tun${p} $((p + OVPN_ID_OFFSET)) 3 3 + tun${p} $((p + OVPN_ID_OFFSET)) 3 3 -1 done sleep 5 } @@ -293,9 +353,9 @@ trap ovpn_stage_err ERR ktap_print_header if [ "${OVPN_FLOAT}" == "1" ]; then - ktap_set_plan 13 + ktap_set_plan 14 else - ktap_set_plan 12 + ktap_set_plan 13 fi ovpn_cleanup @@ -307,6 +367,7 @@ ovpn_run_stage "run LAN traffic behind peer1" ovpn_run_lan_traffic [ "${OVPN_FLOAT}" == "1" ] && ovpn_run_stage "run floating peer checks" \ ovpn_run_float_mode ovpn_run_stage "run iperf throughput" ovpn_run_iperf +ovpn_run_stage "run mssfix TCP SYN clamp" ovpn_run_mssfix ovpn_run_stage "run key rollout" ovpn_run_key_rollover ovpn_run_stage "query peers" ovpn_run_queries ovpn_run_stage "query missing peer fails" ovpn_query_peer_missing