From patchwork Fri Jul 24 05:55:23 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5126 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6384:b0:87d:a69c:34be with SMTP id i4csp1188353mag; Thu, 23 Jul 2026 22:55:48 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RqdUZ4plJxaKkQtgh9s5F8soVG+VmYkuVU7M6ATpFdBUuMDtkH6TMZTOyJN+0dov8CH5haAv/iKRbI=@openvpn.net X-Received: by 2002:a05:6871:6012:b0:455:ade8:79bf with SMTP id 586e51a60fabf-457a0b379d7mr3152942fac.5.1784872547977; Thu, 23 Jul 2026 22:55:47 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1784872547; cv=none; d=google.com; s=arc-20260327; b=QF2Pk2JXV2UCGnNA3BNQx31tWMl2cQcr3JjfxQQf3baIljqQ0p7N49HE7D+PjwrTIa J2474qwqrd51Kdc0o09bRf4dULQo4J/9KoML9ughpQQ3p1eJv6rrBOM2WijuD5Hz79l2 5D2mN6p7gbNf+w+cZSYdhh7AH+L7P3kW9Upao1Sm4NBoGuABPOrSjzoxgCgUn43KXV+L qX0yGIRROP0KCV3H/xFvLcJErfnVvhbuGBlQQnXkBeV3IGVCrdhJ9clTrGNFkTpxlPFK 0VD/+CDAE3pZAXvmuHk2VZ+on1oG6EIczA87iOxU9pWtfhSZ2+Gy73e3OlK8Q8xHi49s rfeg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=6J//GGDYWzgh9mPsLVpD27DZ2xQF79qZRtu7Zt6Q+s0=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=F+0rCtm2WYRxPQrtbv8Dnplg+ECimpA9Mitk4QSPud7LlXwc0+J/moJ7m7+lrh8ze+ fjBtVVWagKv0U7H1p0bhXwD6QfE2WaLsx40Th8SY9w4eafSf+QhpQO/M11YIPqfEbY// NdF81GfHLmwpL1XynFdkXEGUTmOFWcHA4ljF617nn7KoTOnmTpX9dkqrbkokc98tj8o4 xGha/r0sHrgi0tGzJS8k73lTPvl44maUwWDxuGVeRqavr1+WHu9M2bbDieVg/hqTaOXf 8M7aDcVtt0dQ4jutGsd4h+OCr7rfdk/UxRAwE/3UX+X8yXTSwjYTzvSq0RTZQJ1audgr /Uxg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=A4tKUbB4; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=dY8YLUZu; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=OigNfz00; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-457aa190e45si3068773fac.31.2026.07.23.22.55.47 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 23 Jul 2026 22:55:47 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=A4tKUbB4; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=dY8YLUZu; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=OigNfz00; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=6J//GGDYWzgh9mPsLVpD27DZ2xQF79qZRtu7Zt6Q+s0=; b=A4tKUbB48+24NRImR5krXaV7uB kd5DDieBp6dC2r7UVCl8G0HMfrSRcmapzXafV/YwomTLOiLAnY8kegqJR/eldPHQ1HWxFOdEVcyfX 4OcrAGnkoAqAd1cTXPER8VD/t/0283mVEhrUnQlfrFP68P9/fM6KS8r2ug6fQ6BJB+lI=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wn8sl-0005S3-Hj; Fri, 24 Jul 2026 05:55:40 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wn8sk-0005Rv-00 for openvpn-devel@lists.sourceforge.net; Fri, 24 Jul 2026 05:55:38 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=3ZZmOfDTL1fGlk1r2Fr21fYHQsyD+0OXUlJBThBKIn4=; b=dY8YLUZuKwGDUVkMYXEX0kt0bW CuiZBnYevQF/m9EBNHgejSmvfaVoiftUZHxNjM3H/SEq4ZImqeBS5NFyx8S0WHoUrBALw4H5VYBI4 8TH+2RrWpgxxuU/CDjGMKpw4ie7bs8x5ytmb8WRLvTUgnL996wnLTbwFHTqFCtyjPyFw=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=3ZZmOfDTL1fGlk1r2Fr21fYHQsyD+0OXUlJBThBKIn4=; b=OigNfz00WFfMUfRPJa0CHSunHb Jk8s682zYCfwHk4SFIfXcQOkbjzK+t+wHVw7wtzAc9q1jgSVeQ6fVADGtwDYX7GD6zhNy5mwmmKWg fMN3Dhbsj0A/jCujI0Grfer74TCy/RnILgSozjlqxKh9iBEb5f16rAluubVIFMoPEwNg=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wn8sm-0002c5-O2 for openvpn-devel@lists.sourceforge.net; Fri, 24 Jul 2026 05:55:38 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 66O5tUFM001401 for ; Fri, 24 Jul 2026 07:55:30 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 66O5tUBG001395 for openvpn-devel@lists.sourceforge.net; Fri, 24 Jul 2026 07:55:30 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Fri, 24 Jul 2026 07:55:23 +0200 Message-ID: <20260724055529.1376-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Antonio Quartulli With this change, OpenVPN can be launched without specifying any --dev option and it will start a `tun` (L3) tunnel with the interface named `tunX`. As before, this behaviour can be changed using --de [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1wn8sm-0002c5-O2 Subject: [Openvpn-devel] [PATCH v3] options: make `tun` the default for `--dev` X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1871574517007934939 X-GMAIL-MSGID: 1871574517007934939 From: Antonio Quartulli With this change, OpenVPN can be launched without specifying any --dev option and it will start a `tun` (L3) tunnel with the interface named `tunX`. As before, this behaviour can be changed using --dev or --dev-type. Existing configs won't see any behavioural change as they all had to contain at least one --dev directive. Change-Id: I0ca7b5b7ec1a01acaad222c99db137c94c88555a Signed-off-by: Antonio Quartulli Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1537 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1537 This mail reflects revision 3 of this Change. Acked-by according to Gerrit (reflected above): diff --git a/doc/man-sections/examples.rst b/doc/man-sections/examples.rst index 80ef2df..416e576 100644 --- a/doc/man-sections/examples.rst +++ b/doc/man-sections/examples.rst @@ -63,6 +63,10 @@ Example 1: A simple tunnel without security (not recommended) ------------------------------------------------------------- +Since :code:`tun` is the default device type, ``--dev`` is optional; when it +is omitted OpenVPN creates a dynamically-named ``tunX`` device. The examples +below still name the device (``--dev tun1``) explicitly for clarity. + On bob:: openvpn --remote alice.example.com --dev tun1 \ diff --git a/doc/man-sections/vpn-network-options.rst b/doc/man-sections/vpn-network-options.rst index 33ebedb..960c6ad 100644 --- a/doc/man-sections/vpn-network-options.rst +++ b/doc/man-sections/vpn-network-options.rst @@ -50,6 +50,10 @@ :code:`null` or an arbitrary name string (:code:`X` can be omitted for a dynamic device.) + If neither ``--dev`` nor ``--dev-type`` is specified, OpenVPN defaults to + :code:`tun`, i.e. it creates a dynamically-named :code:`tunX` device and + runs a layer-3 tunnel. + See examples section below for an example on setting up a TUN device. You must use either tun devices on both ends of the connection or tap diff --git a/sample/sample-config-files/client.conf b/sample/sample-config-files/client.conf index 53b8027..1806b24 100644 --- a/sample/sample-config-files/client.conf +++ b/sample/sample-config-files/client.conf @@ -20,6 +20,8 @@ # On most systems, the VPN will not function # unless you partially or fully disable # the firewall for the TUN/TAP interface. +# "tun" is the default device type, so the +# "dev tun" line below is optional. ;dev tap dev tun diff --git a/sample/sample-config-files/server.conf b/sample/sample-config-files/server.conf index 8943c34..924fb96 100644 --- a/sample/sample-config-files/server.conf +++ b/sample/sample-config-files/server.conf @@ -49,6 +49,8 @@ # On most systems, the VPN will not function # unless you partially or fully disable/open # the firewall for the TUN/TAP interface. +# "tun" is the default device type, so the +# "dev tun" line below is optional. ;dev tap dev tun diff --git a/src/openvpn/options.c b/src/openvpn/options.c index 87218d4..d4cc158 100644 --- a/src/openvpn/options.c +++ b/src/openvpn/options.c @@ -189,7 +189,8 @@ " or --socks-proxy" " is used).\n" "--nobind : Do not bind to local address and port.\n" - "--dev tunX|tapX : tun/tap device (X can be omitted for dynamic device.\n" + "--dev tunX|tapX : tun/tap device (X can be omitted for dynamic device).\n" + " Defaults to \"tun\" if neither --dev nor --dev-type is given.\n" "--dev-type dt : Which device type are we using? (dt = tun or tap) Use\n" " this option only if the tun/tap device used with --dev\n" " does not begin with \"tun\" or \"tap\".\n" @@ -801,6 +802,7 @@ gc_init(&o->dns_options.gc); o->mode = MODE_POINT_TO_POINT; + o->dev = "tun"; o->topology = TOP_UNDEF; o->ce.proto = PROTO_UDP; o->ce.af = AF_UNSPEC;