From patchwork Fri Jul 31 10:08:09 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5193 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:77c3:b0:87d:ab56:3700 with SMTP id r3csp261608mau; Fri, 31 Jul 2026 03:08:29 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RoTyw2nabIKV2GVB/1SxFU098KQnU1W+5sltxKAgIYgDz4ErkrYjRDb+z7LxS9regaB21AnnZDaJjA=@openvpn.net X-Received: by 2002:a05:6830:3786:b0:7e6:ef1d:4aeb with SMTP id 46e09a7af769-7f189cb7429mr1481527a34.15.1785492508802; Fri, 31 Jul 2026 03:08:28 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785492508; cv=none; d=google.com; s=arc-20260327; b=DkTrwcYWCcTfBsoM+Pakc7dB5ktxr1SIPrPTKzrMlcvWgwUCEzxIEY1XirijpIaqQc 2lW8tYj8mVK2VcksPYDTZeQBJ+6z0yicIgzd5Yqr+SCYOJ+mgA3Dp/1wPlLdojJmZ9ox G5281bI7CcB+/AV0900x/7y+j2gEXWqY1sCHmQhay1BxFZtf22WYiKNCiJcIRaU5tPoc LOJuaoHE/seNZGXYKKuymWRh6V/fDMyE4ktg7OvpJCNn2euVKLQqEcUypALWvB51AEFe DRsAhTs7Z2DahH5cXCAO3bHhbcoDLNRA/ZgjD7wiLJ5TQwg8va46h5ZCRzEZbZPAHJoX +GQA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=J1IJ3pQd5DATBjDk16hz+t4G8b1lgkX9QOISOYE55Hs=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=YIYar0iZqxbzCRSlW1mRhzSJDFmOvYw7qk9FkynYMkg+FqzWEwo08yShrMyfnt/LDq Q+MrodwptzWOqN3Ezuj7NJ2IM5d8q50HCZySJ87eAYkA/dlurA+gcoxTATasEGjpa3sB 4P69a2albRgD2ZtFlBMspP48NpM4N4XjcVnVfy9Tr2D4mEpQFw7WXo1kj4TDJUnfvvd/ i4lcmdgS4zKGj6piqgoYfa+nKAxMjauQhGF9OyiIWXJZXiF1LaY7A/1ko2TIN9I5Ml7H sd8KCHarR1jdp9V2XpTz3FDDlOSqhijO7bxtedtuZtxCcpkoQme8jdczrrMQHi62H67Q KqRg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=fIL6o3l6; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=LPVNg6e4; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Vr+hxTah; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7f18f14ec17si269955a34.76.2026.07.31.03.08.28 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 31 Jul 2026 03:08:28 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=fIL6o3l6; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=LPVNg6e4; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=Vr+hxTah; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=J1IJ3pQd5DATBjDk16hz+t4G8b1lgkX9QOISOYE55Hs=; b=fIL6o3l6n1OdZBrsOTPZU6T17C PIxsgPZAAM1E1Ed6FRgXk+S5KRm6BuO5X4aWYCuE80wFLDSb2xgEDuiCBMbB85HYrNt2zuMHlEBcJ No6iWxJUzW4t+X7A2+PT4tYO/WSlSFuSBU2BVu1akqOXYFvORLbwOvXCjBEKKDLeGe3w=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wpkAD-0000Tn-EM; Fri, 31 Jul 2026 10:08:26 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wpkAC-0000Th-2j for openvpn-devel@lists.sourceforge.net; Fri, 31 Jul 2026 10:08:24 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=l+APi8LxeU+vk9HBxpvije1x2mix48GTgcA0h+OGCf8=; b=LPVNg6e4yzwkAbm5c0N5CSjNmk W2zrQFXHJw9Pnf6vuCNtJpNsj8LB+0/sWvroqRMy3ezeJ7T66oDSUb7nb0kcm/R9wyOq1IgCQzuWS OYvZb1gcNKslj5SVLVa7sE2O5Fv6MpNvFt3GNpTtdJV8uU0BU11rh/+j3sg4ojuyibs0=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=l+APi8LxeU+vk9HBxpvije1x2mix48GTgcA0h+OGCf8=; b=Vr+hxTahpfrFwcjsNPcTCDCySx RbowywzpzX4/eO5vN9tUwRUbZzY6+vYtdOQpt7pWZh9+6yLtD/o0JEC60XlwrjAbOSnRit77YLceB tFPRxoAKS36lw97+dBFTtiFA6Lkt4kTbWRY/MIJYQdB5NAWWS2x5WUZ0eGpb3emBZ2EI=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wpkAE-0000qH-DE for openvpn-devel@lists.sourceforge.net; Fri, 31 Jul 2026 10:08:24 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 66VA8Gbw003420 for ; Fri, 31 Jul 2026 12:08:16 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 66VA8Gov003419 for openvpn-devel@lists.sourceforge.net; Fri, 31 Jul 2026 12:08:16 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Fri, 31 Jul 2026 12:08:09 +0200 Message-ID: <20260731100815.3406-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Arne Schwabe This adds an additional safe guard for setups that do not use client certificates. Change-Id: Ie552084638320b3bace76be2f589013f12af3c46 Signed-off-by: Arne Schwabe Acked-by: Frank Lichtenheld Gerrit URL: https://gerrit.openvpn.net/c/openvpn [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URI: openvpn.net] 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1wpkAE-0000qH-DE Subject: [Openvpn-devel] [PATCH v15] Add check that username is identical to multi float X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1870795356997922738 X-GMAIL-MSGID: 1872224592890451983 From: Arne Schwabe This adds an additional safe guard for setups that do not use client certificates. Change-Id: Ie552084638320b3bace76be2f589013f12af3c46 Signed-off-by: Arne Schwabe Acked-by: Frank Lichtenheld Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1724 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1724 This mail reflects revision 15 of this Change. Acked-by according to Gerrit (reflected above): Frank Lichtenheld diff --git a/src/openvpn/multi.c b/src/openvpn/multi.c index 9b64598..0560ac5 100644 --- a/src/openvpn/multi.c +++ b/src/openvpn/multi.c @@ -3112,6 +3112,18 @@ goto done; } + /* do not allow if target address has a different username */ + if (m1->locked_username || m2->locked_username) + { + if (!m1->locked_username || !m2->locked_username + || strcmp(m1->locked_username, m2->locked_username) != 0) + { + msg(D_MULTI_LOW, "Disallow float to an address taken by another client %s", + multi_instance_string(ex_mi, false, &gc)); + goto done; + } + } + /* It doesn't make sense to let a peer float to the address it already * has, so we disallow it. This can happen if a DCO netlink notification * gets lost and we miss a floating step. @@ -3128,7 +3140,7 @@ msg(D_MULTI_LOW, "closing instance %s due to float collision with %s " - "using the same certificate", + "using the same certificate and username", multi_instance_string(ex_mi, false, &gc), multi_instance_string(mi, false, &gc)); multi_close_instance(m, ex_mi, false); ret = true;