| Message ID | 20260731100815.3406-1-gert@greenie.muc.de |
|---|---|
| State | New |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:77c3:b0:87d:ab56:3700 with SMTP id r3csp261608mau;
Fri, 31 Jul 2026 03:08:29 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AHgh+RoTyw2nabIKV2GVB/1SxFU098KQnU1W+5sltxKAgIYgDz4ErkrYjRDb+z7LxS9regaB21AnnZDaJjA=@openvpn.net
X-Received: by 2002:a05:6830:3786:b0:7e6:ef1d:4aeb with SMTP id
46e09a7af769-7f189cb7429mr1481527a34.15.1785492508802;
Fri, 31 Jul 2026 03:08:28 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1785492508; cv=none;
d=google.com; s=arc-20260327;
b=DkTrwcYWCcTfBsoM+Pakc7dB5ktxr1SIPrPTKzrMlcvWgwUCEzxIEY1XirijpIaqQc
2lW8tYj8mVK2VcksPYDTZeQBJ+6z0yicIgzd5Yqr+SCYOJ+mgA3Dp/1wPlLdojJmZ9ox
G5281bI7CcB+/AV0900x/7y+j2gEXWqY1sCHmQhay1BxFZtf22WYiKNCiJcIRaU5tPoc
LOJuaoHE/seNZGXYKKuymWRh6V/fDMyE4ktg7OvpJCNn2euVKLQqEcUypALWvB51AEFe
DRsAhTs7Z2DahH5cXCAO3bHhbcoDLNRA/ZgjD7wiLJ5TQwg8va46h5ZCRzEZbZPAHJoX
+GQA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature;
bh=J1IJ3pQd5DATBjDk16hz+t4G8b1lgkX9QOISOYE55Hs=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=YIYar0iZqxbzCRSlW1mRhzSJDFmOvYw7qk9FkynYMkg+FqzWEwo08yShrMyfnt/LDq
Q+MrodwptzWOqN3Ezuj7NJ2IM5d8q50HCZySJ87eAYkA/dlurA+gcoxTATasEGjpa3sB
4P69a2albRgD2ZtFlBMspP48NpM4N4XjcVnVfy9Tr2D4mEpQFw7WXo1kj4TDJUnfvvd/
i4lcmdgS4zKGj6piqgoYfa+nKAxMjauQhGF9OyiIWXJZXiF1LaY7A/1ko2TIN9I5Ml7H
sd8KCHarR1jdp9V2XpTz3FDDlOSqhijO7bxtedtuZtxCcpkoQme8jdczrrMQHi62H67Q
KqRg==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=fIL6o3l6;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=LPVNg6e4;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=Vr+hxTah;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
46e09a7af769-7f18f14ec17si269955a34.76.2026.07.31.03.08.28
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Fri, 31 Jul 2026 03:08:28 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=fIL6o3l6;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=LPVNg6e4;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=Vr+hxTah;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=J1IJ3pQd5DATBjDk16hz+t4G8b1lgkX9QOISOYE55Hs=; b=fIL6o3l6n1OdZBrsOTPZU6T17C
PIxsgPZAAM1E1Ed6FRgXk+S5KRm6BuO5X4aWYCuE80wFLDSb2xgEDuiCBMbB85HYrNt2zuMHlEBcJ
No6iWxJUzW4t+X7A2+PT4tYO/WSlSFuSBU2BVu1akqOXYFvORLbwOvXCjBEKKDLeGe3w=;
Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com)
by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1wpkAD-0000Tn-EM;
Fri, 31 Jul 2026 10:08:26 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <gert@blue4.greenie.muc.de>) id 1wpkAC-0000Th-2j
for openvpn-devel@lists.sourceforge.net;
Fri, 31 Jul 2026 10:08:24 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=l+APi8LxeU+vk9HBxpvije1x2mix48GTgcA0h+OGCf8=; b=LPVNg6e4yzwkAbm5c0N5CSjNmk
W2zrQFXHJw9Pnf6vuCNtJpNsj8LB+0/sWvroqRMy3ezeJ7T66oDSUb7nb0kcm/R9wyOq1IgCQzuWS
OYvZb1gcNKslj5SVLVa7sE2O5Fv6MpNvFt3GNpTtdJV8uU0BU11rh/+j3sg4ojuyibs0=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=l+APi8LxeU+vk9HBxpvije1x2mix48GTgcA0h+OGCf8=; b=Vr+hxTahpfrFwcjsNPcTCDCySx
RbowywzpzX4/eO5vN9tUwRUbZzY6+vYtdOQpt7pWZh9+6yLtD/o0JEC60XlwrjAbOSnRit77YLceB
tFPRxoAKS36lw97+dBFTtiFA6Lkt4kTbWRY/MIJYQdB5NAWWS2x5WUZ0eGpb3emBZ2EI=;
Received: from [193.149.48.129] (helo=blue.greenie.muc.de)
by sfi-mx-1.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1wpkAE-0000qH-DE for openvpn-devel@lists.sourceforge.net;
Fri, 31 Jul 2026 10:08:24 +0000
Received: from blue.greenie.muc.de (localhost [127.0.0.1])
by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 66VA8Gbw003420
for <openvpn-devel@lists.sourceforge.net>; Fri, 31 Jul 2026 12:08:16 +0200
Received: (from gert@localhost)
by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 66VA8Gov003419
for openvpn-devel@lists.sourceforge.net; Fri, 31 Jul 2026 12:08:16 +0200
From: Gert Doering <gert@greenie.muc.de>
To: openvpn-devel@lists.sourceforge.net
Date: Fri, 31 Jul 2026 12:08:09 +0200
Message-ID: <20260731100815.3406-1-gert@greenie.muc.de>
X-Mailer: git-send-email 2.53.0
In-Reply-To:
<gerrit.1782134588000.Ie552084638320b3bace76be2f589013f12af3c46@gerrit.openvpn.net>
References:
<gerrit.1782134588000.Ie552084638320b3bace76be2f589013f12af3c46@gerrit.openvpn.net>
MIME-Version: 1.0
X-Spam-Score: 1.3 (+)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-1.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: From: Arne Schwabe <arne@rfc2549.org> This adds an
additional
safe guard for setups that do not use client certificates. Change-Id:
Ie552084638320b3bace76be2f589013f12af3c46
Signed-off-by: Arne Schwabe <arne@rfc2549.org> Acked-by: Frank Lichtenheld
<frank@lichtenheld.com> Gerrit URL: https://gerrit.openvpn.net/c/openvpn
[...] Content analysis details: (1.3 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information. [URI: openvpn.net]
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Headers-End: 1wpkAE-0000qH-DE
Subject: [Openvpn-devel] [PATCH v15] Add check that username is identical to
multi float
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1870795356997922738
X-GMAIL-MSGID: 1872224592890451983
|
| Series |
[Openvpn-devel,v15] Add check that username is identical to multi float
|
|
Commit Message
Gert Doering
July 31, 2026, 10:08 a.m. UTC
From: Arne Schwabe <arne@rfc2549.org> This adds an additional safe guard for setups that do not use client certificates. Change-Id: Ie552084638320b3bace76be2f589013f12af3c46 Signed-off-by: Arne Schwabe <arne@rfc2549.org> Acked-by: Frank Lichtenheld <frank@lichtenheld.com> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1724 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1724 This mail reflects revision 15 of this Change. Acked-by according to Gerrit (reflected above): Frank Lichtenheld <frank@lichtenheld.com>
Comments
"Makes sense", close one edge case... - in theory this could go to
2.7 as well, but I don't think it's so important to have, and the patch
"as it is" won't go in without all the refactoring we do not want to
have in 2.7.
Did not actually test this with floating clients with an address conflict
(hard to setup).
Technically this refers to "v15" of the patch while gerrit has a "v19",
but everything after v3 is code-identical rebases.
Your patch has been applied to the master branch.
commit d42a9912c1d62006323a12af86baa148c77592e9
Author: Arne Schwabe
Date: Fri Jul 31 12:08:09 2026 +0200
Add check that username is identical to multi float
Signed-off-by: Arne Schwabe <arne@rfc2549.org>
Acked-by: Frank Lichtenheld <frank@lichtenheld.com>
Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1724
Message-Id: <20260731100815.3406-1-gert@greenie.muc.de>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg38095.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
diff --git a/src/openvpn/multi.c b/src/openvpn/multi.c index 9b64598..0560ac5 100644 --- a/src/openvpn/multi.c +++ b/src/openvpn/multi.c @@ -3112,6 +3112,18 @@ goto done; } + /* do not allow if target address has a different username */ + if (m1->locked_username || m2->locked_username) + { + if (!m1->locked_username || !m2->locked_username + || strcmp(m1->locked_username, m2->locked_username) != 0) + { + msg(D_MULTI_LOW, "Disallow float to an address taken by another client %s", + multi_instance_string(ex_mi, false, &gc)); + goto done; + } + } + /* It doesn't make sense to let a peer float to the address it already * has, so we disallow it. This can happen if a DCO netlink notification * gets lost and we miss a floating step. @@ -3128,7 +3140,7 @@ msg(D_MULTI_LOW, "closing instance %s due to float collision with %s " - "using the same certificate", + "using the same certificate and username", multi_instance_string(ex_mi, false, &gc), multi_instance_string(mi, false, &gc)); multi_close_instance(m, ex_mi, false); ret = true;