From patchwork Wed Aug 5 13:46:14 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Frank Lichtenheld X-Patchwork-Id: 5200 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:77c3:b0:87d:ab56:3700 with SMTP id r3csp6334416mau; Wed, 5 Aug 2026 06:46:29 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RqmlJiTYT+OCIQQQ7PBMGa99qn4bkqW5xUIViT8+fxh671h+yP0RpxLfWQkdxzJr7YGTeg/JIfteC8=@openvpn.net X-Received: by 2002:a05:6870:247:b0:43d:d0c:ac30 with SMTP id 586e51a60fabf-4599e55f1f8mr3630103fac.0.1785937589604; Wed, 05 Aug 2026 06:46:29 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785937589; cv=none; d=google.com; s=arc-20260327; b=sR5cHXdGUGTz19UWyrWtzLiqSitH88zo8mTiKSO/TpYSOZ2kFzYq4cBeI+z84KA/m/ l4k+dYj9ScceGA1L+4KPx006PpPqdD2hU/IiJ8jDH6winH0YaK0MxxbwXQGw1qMDPtk5 vXM18T2htB3o5stlB3XkNN+DAYGZ2Cs68gwmneynH79BiZT0ksmn4XX65sruH3gR7Mt1 hDzIL72WCHHQ6faKgkENR92g1pTjCxl+CLFXtx/uOtJ2Sa42XpJ+WsrQHxOIvUIbyj5Q edliFJidfZeEcWCM1llTQJHjCJ3jV6GQ8gVYuFuECizDvHt+DzeSnYcMB78pd4I3Qieh 2AiA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=mxZvRs4rwltseqO5Oc4OsSgKhkK1G7GFR5yEwr0gNj4=; fh=iMCTZ+M5n9Ld7lGLfUvsLXeNdrPOUWhGmJFpQaSD/2E=; b=tA0YjxfHK/Oo7HAiY/VPhdKqTI4B76cjRnPcg3G+GyarFNJgFC3Pdnbx1eFawiji5b Aeb8Fv4PwnEPVfYxlqAUS1qMMjQ1255gEtrR3l1XmH3u3da0OiZgGimx6+vo+DQfkXDf WH/OFsWpdsBC5mApjJuXx2qF1wWkriAdWN1HB3C49gr0SqrxRQ+VI11ri70VfPaPfX0b oYXOj4Dbj9QjAY9WBftEgWJjOy+xgCzcOA4EFnO4/aiegBxxAPSAyXMuzJTEyO91Q7/r ixyeJ6VFbAuLM7VzqeRG3PHtua2Hx8+gQbQHntje28Ub1pxAf7Du4yqNX1Xd6RBlAPB0 9j1w==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=MNnrVOam; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b="YOP/sJBl"; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=I6uAOLca; dkim=neutral (body hash did not verify) header.i=@lichtenheld.com header.s=MBO0001 header.b=w94cXAPL; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-4599e1bc88asi1625972fac.58.2026.08.05.06.46.29 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 05 Aug 2026 06:46:29 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=MNnrVOam; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b="YOP/sJBl"; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=I6uAOLca; dkim=neutral (body hash did not verify) header.i=@lichtenheld.com header.s=MBO0001 header.b=w94cXAPL; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=mxZvRs4rwltseqO5Oc4OsSgKhkK1G7GFR5yEwr0gNj4=; b=MNnrVOamz18hy/gYUNmCvXu6Mv L+Fw2Q1D/DrbiLvu2T9TZpJZoGpfSr7VyjCnQntKrMna/7fzi2C+8U8SBSyeh42gvXEtI6BXL3AKj Qe/gRqHvKaR6wNTHvWBeneVajmYHXzaTBxpsjaa3Rv8V4StqEWB6hfwvGpm6SqsS4B1U=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wrbwv-0000i6-AX; Wed, 05 Aug 2026 13:46:26 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wrbwu-0000hz-H6 for openvpn-devel@lists.sourceforge.net; Wed, 05 Aug 2026 13:46:25 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=Iy0xdBmxTiFOqybp8UvL2Xh71TjkR/AenFR0AGD6HnU=; b=YOP/sJBlOZRrq68mo8f8a9gYTq CjDKacgdcG0nI+AVb1dosW2tJeCOUs+8a5oPZFBesy2oKAmClu/bfSag7sdIm2pn10p+McLEay6V+ ALCWV7KKGuQ+v3CkOKXoUmPB+qGF7EFvO8Rbn2tru8rdRjy25iaN+atP+qhztxMVtngM=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=Iy0xdBmxTiFOqybp8UvL2Xh71TjkR/AenFR0AGD6HnU=; b=I6uAOLca5oevHwDL6+pMyVm1xx rOh41BbQx3d9K8R/4fWzMo0hN4Sww0jheDWW7vmrJZEqxAVTYlPvKPbf34TpDEH/tOJCz9tbC3Hrt MbYZSw8zeggFJ+C6KK9D5MQEn/NQv+rvfvMyjWGGe3q0tYb4XCnt8CoY3aN/hYNe8JP4=; Received: from mout-p-101.mailbox.org ([80.241.56.151]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wrbwy-00085W-1X for openvpn-devel@lists.sourceforge.net; Wed, 05 Aug 2026 13:46:25 +0000 Received: from smtp1.mailbox.org (smtp1.mailbox.org [10.196.197.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-p-101.mailbox.org (Postfix) with ESMTPS id 4hFWsN1YM5z8v0p; Wed, 05 Aug 2026 15:46:16 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lichtenheld.com; s=MBO0001; t=1785937576; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Iy0xdBmxTiFOqybp8UvL2Xh71TjkR/AenFR0AGD6HnU=; b=w94cXAPLwjPHD+yCoI2aXnSkBEgmZqRnoX5e40H4b68p0JAJX6vd+3l59M9MaEUnShWdWc Gzg1PnteLM7JKWQT+43YpGqmUkC0H2XT7jtonTWVMG1RXMQxWf+swwT30Xj/A9QIRfXMtb mOe8uN3Q0wpyyN8oTrudUouDcjEgwUBvqU5nQ6rTjz5q0zO6E3LqgQY68W2zLMVJp6I4zC N+rOPhUpT00AjMxAiP1teyF5x+o4EOr3k+Jynp0qK6Np2gJ+ExqNkxlOoWbWpIBA/LxrwA V7WDz01a7Kk2qvBrsPECH8I0uYgIhAXq1iGyVwgRr+Vg+kbxfT7kvjFKZ3V4DA== From: Frank Lichtenheld To: openvpn-devel@lists.sourceforge.net Date: Wed, 5 Aug 2026 15:46:14 +0200 Message-ID: <20260805134614.163847-1-frank@lichtenheld.com> In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Lev Stipakov Factor the synchronous, stateless "send a standalone control packet back to the peer that just contacted us" sequence out of send_hmac_reset_packet() into a reusable helper. No behavioural change. Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.0 RCVD_IN_MSPIKE_H5 RBL: Excellent reputation (+5) [80.241.56.151 listed in wl.mailspike.net] 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-Headers-End: 1wrbwy-00085W-1X Subject: [Openvpn-devel] [PATCH v11] mudp: extract send_standalone_reply() helper X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Antonio Quartulli , Lev Stipakov Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872691293687165102 X-GMAIL-MSGID: 1872691293687165102 From: Lev Stipakov Factor the synchronous, stateless "send a standalone control packet back to the peer that just contacted us" sequence out of send_hmac_reset_packet() into a reusable helper. No behavioural change. This lets a following commit reuse it for the out-of-band probe reply instead of duplicating the aux_buf / to_link / process_outgoing_link sequence. Change-Id: Ic75ca2ee9b59a4e11f37cd9653df268bba33889c Signed-off-by: Lev Stipakov Acked-by: Frank Lichtenheld Acked-by: Antonio Quartulli Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1743 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1743 This mail reflects revision 11 of this Change. Acked-by according to Gerrit (reflected above): Frank Lichtenheld Antonio Quartulli diff --git a/src/openvpn/mudp.c b/src/openvpn/mudp.c index 9acf297..2be085f 100644 --- a/src/openvpn/mudp.c +++ b/src/openvpn/mudp.c @@ -37,6 +37,41 @@ #include #endif +/** + * Send an already-built standalone control packet back to the peer that just + * contacted us (c2.from), synchronously and without keeping any state. + * + * We do not want to keep state for a reply to an initial/out-of-band packet, so + * we send it without queueing. If we hit EAGAIN on a busy socket the packet is + * lost and the client simply retries -- an acceptable compromise that avoids + * consuming server resources under attack. + * + * @param m the server's multi_context + * @param buf the packet to send (built by a tls_*_standalone() helper) + * @param prefix msg() prefix to set for the duration of the send + * @param detail D_MULTI_DEBUG message describing the reply + * @param sock the socket to send the reply on + */ +static void +send_standalone_reply(struct multi_context *m, struct buffer *buf, const char *prefix, + const char *detail, struct link_socket *sock) +{ + struct context *c = &m->top; + + /* dco-win server requires prepend with sockaddr, so preserve offset */ + ASSERT(buf_init(&c->c2.buffers->aux_buf, buf->offset)); + buf_copy(&c->c2.buffers->aux_buf, buf); + + msg_set_prefix(prefix); + c->c2.to_link = c->c2.buffers->aux_buf; + c->c2.to_link_addr = &c->c2.from; + msg(D_MULTI_DEBUG, "%s", detail); + process_outgoing_link(c, sock); + c->c2.to_link.len = 0; + c->c2.to_link_addr = NULL; + msg_set_prefix(NULL); +} + static void send_hmac_reset_packet(struct multi_context *m, struct tls_pre_decrypt_state *state, struct tls_auth_standalone *tas, struct session_id *sid, @@ -48,29 +83,8 @@ struct buffer buf = tls_reset_standalone(&state->tls_wrap_tmp, tas, sid, &state->peer_session_id, header, request_resend_wkc); - struct context *c = &m->top; - - /* dco-win server requires prepend with sockaddr, so preserve offset */ - ASSERT(buf_init(&c->c2.buffers->aux_buf, buf.offset)); - - buf_copy(&c->c2.buffers->aux_buf, &buf); - - /* - * We do not want to keep any state here, so we send the reply to the - * initial packet synchronously without queueing anything. - * - * If we hit EAGAIN on a busy socket, the packet will be lost and the - * client will have to retransmit its HARD_RESET. This is considered an - * acceptable compromise to avoid consuming server resources under attack. - */ - msg_set_prefix("Connection Attempt"); - c->c2.to_link = c->c2.buffers->aux_buf; - c->c2.to_link_addr = &c->c2.from; - msg(D_MULTI_DEBUG, "Reset packet from client, sending HMAC based reset challenge"); - process_outgoing_link(c, sock); - c->c2.to_link.len = 0; - c->c2.to_link_addr = NULL; - msg_set_prefix(NULL); + send_standalone_reply(m, &buf, "Connection Attempt", + "Reset packet from client, sending HMAC based reset challenge", sock); }