| Message ID | 20260810114212.28379-1-gert@greenie.muc.de |
|---|---|
| State | New |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:21cf:b0:87d:ab56:3700 with SMTP id
t15csp2675452mae;
Mon, 10 Aug 2026 04:42:31 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AHgh+RrELGZc+g5E+gCyv6qaXXSJ/Q8QexMXC2FNzH7ow9BoXVdIxAk/cq5pULCeJhtKxpfNJJSQORrr7pc=@openvpn.net
X-Received: by 2002:a05:6820:169e:b0:6b0:5742:9c32 with SMTP id
006d021491bc7-6b05742a397mr6348292eaf.15.1786362151023;
Mon, 10 Aug 2026 04:42:31 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1786362151; cv=none;
d=google.com; s=arc-20260327;
b=kWdSfZAPpVDfEr3kkOF3FHUGPKIecqmqtmzHGnACp+Yuy/vaFVZUXC70cUmBEJoyrD
q7CdIhd+wmzJKsyd8l6tcX2EgWcJPrVbc6zyao579DkpX9ihTELJ/WE/k9NkVr6y0she
pD2z8Dyd6lBVPxCbUNrl7CAEEzLRraIkYWRWi8elwXoQa1C2jVMfdxknG5OWOeXiJnQD
jfhZdbbILfti20kO3EcVFC4/a43c5oa5lh0crZI6NUVgRz4GgYVBFNcQ1iOt7FLDT0V/
BpX3jL4va86HKqfKCidp0Q9OiCvE6EXaa7MQko/pty8TK0WLmgxYH/xcIDiGn0bKXbFx
lD3A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature;
bh=y19Hgl9oWwpyELcKt9BKuq/2OGUir5jONeT8829LKko=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=RW3690LbQOKKYyuntkqRfHpjSaJNzmKYSywytGR6zBs8yO9BjTdNeShEEvqFReLig7
R3HpFrcoem4GByu19pc+k/tDr07NfBW/IKersbLr6+e6A9e3+knpS9ZMNaAK8tRuqQ+c
WUEWsOTC18TOPPk9bqBgtL6vC/VPDebQGboYb6YwtZjRxnwdNJhuwH2PKVS+k817KohN
qgkvjwmOHHOsq2ktbpn0lcRim2IWQvWzpWCqshvRR+DzmijHO9hRpytKDdZLio0qpsB7
XU5OBc4QfC8KpggXsx2rhDWd9teYLKYP+dQk+lzxjkP09d5ALUccTyDI05YfU8OMWMbq
EDcw==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=E5JDnyKX;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=JfIVN+CI;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=SLSCSfGP;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
586e51a60fabf-459f1a74b7bsi7626797fac.101.2026.08.10.04.42.30
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Mon, 10 Aug 2026 04:42:30 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=E5JDnyKX;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b=JfIVN+CI;
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=SLSCSfGP;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=y19Hgl9oWwpyELcKt9BKuq/2OGUir5jONeT8829LKko=; b=E5JDnyKXoMHlxKuQC4kKvCquNq
PRkbQAf1cDe3G2YbGvetfN0LdL2+U/NINZboDfZI/8ynG25B7HCdvyc5qv7oQO1izrg25sAylLeZN
0MTpNlYDGheX/atQ6TCIy3e19KsA/FcOMIitUcmMX2dD7+/Dad4lBGTT17tXmIww7ye8=;
Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com)
by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1wtOOe-0005tL-3x;
Mon, 10 Aug 2026 11:42:24 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <gert@blue4.greenie.muc.de>) id 1wtOOc-0005tE-E2
for openvpn-devel@lists.sourceforge.net;
Mon, 10 Aug 2026 11:42:22 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=blWzq3PWOPO8qCbxYTJ792lEDYJPJjxIF9uVzyvsF7E=; b=JfIVN+CIw1As18OZPU7uA1vYKn
jVmzVuTgY6bDHCINIzo9KN0l4emEas/jx3jrYTAngooaOfIFQ1OEVdOLc8VgFsb/En+aKVC/08wWd
hHSde4mF0Z41IOSVqqdZvc9t2Bqdra/4LPjDiO7E6fBXNeP4E6vUJxn7K0jdEqsOQ6SU=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=blWzq3PWOPO8qCbxYTJ792lEDYJPJjxIF9uVzyvsF7E=; b=SLSCSfGPkjllRrY5TSDFxw/f09
XXRtTWw2YJhCePHO/+ZDOFmeZ22gaCRelKKrzqiijCbKpH7vgnY9rS9OkSqCe8rmbVnWneGHySOkX
0XknDyPcchiU1HLYOi1b7zNw/TDM3ziIQq9X5/iPczYRsu5h4X3xcMKmD5WHnlBcAZ3g=;
Received: from [193.149.48.129] (helo=blue.greenie.muc.de)
by sfi-mx-1.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1wtOOd-0000eJ-Q0 for openvpn-devel@lists.sourceforge.net;
Mon, 10 Aug 2026 11:42:22 +0000
Received: from blue.greenie.muc.de (localhost [127.0.0.1])
by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 67ABgDkt028403
for <openvpn-devel@lists.sourceforge.net>; Mon, 10 Aug 2026 13:42:13 +0200
Received: (from gert@localhost)
by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 67ABgDSg028402
for openvpn-devel@lists.sourceforge.net; Mon, 10 Aug 2026 13:42:13 +0200
From: Gert Doering <gert@greenie.muc.de>
To: openvpn-devel@lists.sourceforge.net
Date: Mon, 10 Aug 2026 13:42:06 +0200
Message-ID: <20260810114212.28379-1-gert@greenie.muc.de>
X-Mailer: git-send-email 2.53.0
In-Reply-To:
<gerrit.1785931793000.I728067ef08481c87c7b6918c88ebcaeeec466534@gerrit.openvpn.net>
References:
<gerrit.1785931793000.I728067ef08481c87c7b6918c88ebcaeeec466534@gerrit.openvpn.net>
MIME-Version: 1.0
X-Spam-Score: 1.3 (+)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-1.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: From: Arne Schwabe <arne@rfc2549.org> Commit 619c3e9 changed
the logic to enable xmit_hold only when c->mode is CM_CHILD_TCP. This works
for --mode server and was probably done to allow to properly work when the
server is listening on mul [...]
Content analysis details: (1.3 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Headers-End: 1wtOOd-0000eJ-Q0
Subject: [Openvpn-devel] [PATCH v4] Reenable xmit_hold when using p2p
tcp-server and tls-server
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1873136478931663517
X-GMAIL-MSGID: 1873136478931663517
|
| Series |
[Openvpn-devel,v4] Reenable xmit_hold when using p2p tcp-server and tls-server
|
|
Commit Message
Gert Doering
Aug. 10, 2026, 11:42 a.m. UTC
From: Arne Schwabe <arne@rfc2549.org> Commit 619c3e9 changed the logic to enable xmit_hold only when c->mode is CM_CHILD_TCP. This works for --mode server and was probably done to allow to properly work when the server is listening on multiple sockets and options->ce.proto cannot be used to determine if this socket is tcp or udp. Restore the logic for p2p to avoid both sides starting sending resets at the same time. Closes: openvpn/openvpn#1089 Change-Id: I728067ef08481c87c7b6918c88ebcaeeec466534 Signed-off-by: Arne Schwabe <arne@rfc2549.org> Acked-by: MaxF <max@max-fillinger.net> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1837 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1837 This mail reflects revision 4 of this Change. Acked-by according to Gerrit (reflected above): MaxF <max@max-fillinger.net>
Comments
Good find :-) - going back to the 2.6 source, this is "sort of obviously
correct" (2.6 checked for ce.proto == TCP_SERVER, which does no longer
make sense with the multisocket patch in 2.7 - which got it right for a
"p2mp --server" with a TCP socket, but the "p2p --tcp-server" case got
lost)
For a normal client or server setup this does not change anything, just
for "p2p --tcp-server". The t_server tests test that, as did MaxF's
test setup which led to GH issue 1089. And indeed, maybe I should
setup a "p2p --tcp-server --tls-crypt-v2" instance... :-)
Your patch has been applied to the master and release/2.7 branch (bugfix).
commit 603aa9698c140d15b7464af8fb83bd2aa71da680 (master)
commit c26995bf68984be140714754520c3848b8d9bcf9 (release/2.7)
Author: Arne Schwabe
Date: Mon Aug 10 13:42:06 2026 +0200
Reenable xmit_hold when using p2p tcp-server and tls-server
Signed-off-by: Arne Schwabe <arne@rfc2549.org>
Acked-by: MaxF <max@max-fillinger.net>
Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1837
Message-Id: <20260810114212.28379-1-gert@greenie.muc.de>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg38265.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
diff --git a/src/openvpn/init.c b/src/openvpn/init.c index 69d226d..08278fc2 100644 --- a/src/openvpn/init.c +++ b/src/openvpn/init.c @@ -3332,7 +3332,7 @@ /* should we not xmit any packets until we get an initial * response from client? */ - if (to.server && c->mode == CM_CHILD_TCP) + if (to.server && (c->mode == CM_CHILD_TCP || (c->mode == CM_P2P && options->ce.proto == PROTO_TCP_SERVER))) { to.xmit_hold = true; }