From patchwork Mon Aug 17 13:16:28 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5246 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:798a:b0:87d:ab56:3700 with SMTP id o10csp2914225maz; Mon, 17 Aug 2026 06:16:47 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RqtegfiK0FgDKGU/sC7UwlYqoIgtyTDweoZn+Pp6lqudAtFEMVZn49B1TfMR7yvuPalfbCZuyYsZWA=@openvpn.net X-Received: by 2002:a05:6820:1895:b0:6ae:8ee4:e01f with SMTP id 006d021491bc7-6b0d5fb5eccmr22172173eaf.4.1786972606956; Mon, 17 Aug 2026 06:16:46 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1786972606; cv=none; d=google.com; s=arc-20260327; b=Og0BQU9S0bVE7q089wt7KiT03Ui9TbLkyd5iV+XQ5AZSL/pv8rQU4MP8calQgYwOMN TjEVoujPF9qdoonfduMXgiwYC1cmDy5A/Pq68y2qreBUZkqrfyUf5BW8TuwboLo3/zTq Tv+KA5pBjR37/gW3jiDzCT8Jzyfv/+EOcBap+Zr/rNrO29MhenCbLONo2r6UuOo+CQ0G MwuVYLH5Q2C9NVvIeVBj0TRRgiiA6cpcE1rlhpcHYQp0UMj/VWmsvytdn2S4db6O8yrj fgguDpZb5miCV/wrO6UtscIp7Mu+CE7WUeyP4fbf8E1/gbdLiZixDujSkFFEIp8aA/uQ Z8lA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=ZRC0mo7wj6lBOBwJvpwNSuo9J5kYKg+qNwxUECaS5vg=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=EfHv3q1K3dwKbyTzZCn67CWh0xxXc4PJJDGaEazrR3WJapQoPl4/XStiOrsYTW2f/F gffhXU4UA0mudWBfYsb3FffYZQCvjSpbZj4a7qfQxrgzFxUXAA99HCsLw1pCd6zsnvyl +KqJCxnJXlrqY7ZXd+tABtY1ZCsrqvxUDybily5ID/pmVjemNgkIhw+Nq8otYOsUqZER +5Uxoy7ZmtTx5yMqwvyhhzHEdcib78/jXPX0zUaC06qnFTIKG8VJAjLXSKM/URw44Bn0 GRWTVt653l9zJ5oFEMcBoHdcHv1Po8AA65EGAK2LqTNKf+ES9ps51QZUxSRx3whj2XUm C5bA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b="Pv2/4g4X"; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b="k8EJ/zX7"; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=AGkgu8Di; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-45f22e9b482si1412746fac.288.2026.08.17.06.16.46 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 17 Aug 2026 06:16:46 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b="Pv2/4g4X"; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b="k8EJ/zX7"; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=AGkgu8Di; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=ZRC0mo7wj6lBOBwJvpwNSuo9J5kYKg+qNwxUECaS5vg=; b=Pv2/4g4XuVnBoWDMV7hEHTdT0p NAbKENBy9s3yAYDGl9m+baKqVi6HPdoDxU8T7Wxc2gm9b/aP6y/TO+syfcm9r/81+i7TsDGjwn7BR IMnNdGoE42Wl9Cng2qWGZX4DH8TmuzJUlUSOvOHIP7mbM/Pw/+FKW5ClSeeHJUz16x2c=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wvxCl-0006TF-9F; Mon, 17 Aug 2026 13:16:44 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wvxCj-0006T7-LO for openvpn-devel@lists.sourceforge.net; Mon, 17 Aug 2026 13:16:42 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=nkNqtIQpSZrRySXT0j8DDEjJIaM+s2xtltgTtSy/bRc=; b=k8EJ/zX71RohruzsQPhuArfv/E P+cN1m5FkT/bDNQerX5JjTBshndZQVO7NCBjsK00/7uG1FzHDY2Lfcmnng1/bMHK7HPf95VCYqR+4 /qOwbzkbWQSa1bx8WiCjSNUEJBYR1EpZw0l4+lXGQlu+/HYDpsQ3a0UTLT+P6D0BKJKg=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=nkNqtIQpSZrRySXT0j8DDEjJIaM+s2xtltgTtSy/bRc=; b=AGkgu8DiLNTmU5jSZRH3xczbLY 4Lj+MydZH2H2Ytv1YjuObum4BRIafBQXeDZlGUSRoJgKf3ayNgLsZuwEeWHezdYfk1YKpC1kbLDoA Pdoc2/Kq4Uf6X78EXB6mEIIBHBSV5peMCvXEpleSjgvi7eNbB2f3xgNb5wY9t9JRXhz4=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wvxCi-0008T8-FX for openvpn-devel@lists.sourceforge.net; Mon, 17 Aug 2026 13:16:42 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 67HDGYwq021700 for ; Mon, 17 Aug 2026 15:16:34 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 67HDGXVZ021699 for openvpn-devel@lists.sourceforge.net; Mon, 17 Aug 2026 15:16:33 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Mon, 17 Aug 2026 15:16:28 +0200 Message-ID: <20260817131633.21659-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Arne Schwabe The current code relies on the condition if state.server_session_id is defined to decide if session_skip_to_pre_start should be used. Instead explicitly return the intent and use that to decide if session_skip_to_pre_start should be called. Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1wvxCi-0008T8-FX Subject: [Openvpn-devel] [PATCH v9] Make required action returned from pre_decrypt_verdict more explicit X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1873776588285143382 X-GMAIL-MSGID: 1873776588285143382 From: Arne Schwabe The current code relies on the condition if state.server_session_id is defined to decide if session_skip_to_pre_start should be used. Instead explicitly return the intent and use that to decide if session_skip_to_pre_start should be called. Change-Id: Iccdd4cfad090c565aac27e16cdaa9871106c2f89 Signed-off-by: Arne Schwabe Acked-by: Razvan Cojocaru Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1826 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1826 This mail reflects revision 9 of this Change. Signed-off-by line for the author was added as per our policy. Acked-by according to Gerrit (reflected above): Razvan Cojocaru diff --git a/src/openvpn/mudp.c b/src/openvpn/mudp.c index 632b064..b370b6b 100644 --- a/src/openvpn/mudp.c +++ b/src/openvpn/mudp.c @@ -87,9 +87,24 @@ "Reset packet from client, sending HMAC based reset challenge", sock); } +/** + * Verdict if this packet should create a new session. If a packet is invalid + * or we send out an HMAC based challenge, we do not want to create a new + * session. + */ +enum pre_decrypt_verdict +{ + /** This packet should not create a new session */ + PRE_DECRYPT_NO_ACTION, + /** This packet creates a new session normally */ + PRE_DECRYPT_CREATE_SESSION, + /** Create a new session but skip the first two packets of + * the three way handshake */ + PRE_DECRYPT_CREATE_SESSION_SKIP +}; -/* Returns true if this packet should create a new session */ -static bool +/** Returns a verdict if this packet should create a new session */ +static enum pre_decrypt_verdict do_pre_decrypt_check(struct multi_context *m, struct tls_pre_decrypt_state *state, struct mroute_addr addr, struct link_socket *sock) { @@ -111,7 +126,7 @@ * responses */ if (!reflect_filter_rate_limit_check(m->initial_rate_limiter)) { - return false; + return PRE_DECRYPT_NO_ACTION; } } @@ -136,7 +151,7 @@ calculate_session_id_hmac(state->peer_session_id, from, hmac_key, handwindow, 0); send_hmac_reset_packet(m, state, tas, &sid, true, sock); - return false; + return PRE_DECRYPT_NO_ACTION; } else { @@ -153,11 +168,11 @@ "ignoring connection attempt from old client (%s)", peer); gc_free(&gc); - return false; + return PRE_DECRYPT_NO_ACTION; } else { - return true; + return PRE_DECRYPT_CREATE_SESSION; } } } @@ -170,7 +185,7 @@ send_hmac_reset_packet(m, state, tas, &sid, false, sock); /* We have a reply do not create a new session */ - return false; + return PRE_DECRYPT_NO_ACTION; } else if (verdict == VERDICT_VALID_CONTROL_V1 || verdict == VERDICT_VALID_ACK_V1 || verdict == VERDICT_VALID_WKC_V1) @@ -181,6 +196,7 @@ bool pkt_is_ack = (verdict == VERDICT_VALID_ACK_V1); bool ret = check_session_hmac_and_pkt_id(state, from, hmac_key, handwindow, pkt_is_ack); + enum pre_decrypt_verdict action = PRE_DECRYPT_NO_ACTION; const char *peer = print_link_socket_actual(&m->top.c2.from, &gc); uint8_t pkt_firstbyte = *BPTR(&m->top.c2.buf); @@ -198,14 +214,15 @@ "Valid packet (%s) with HMAC challenge from peer (%s), " "accepting new connection.", packet_opcode_name(op), peer); + action = PRE_DECRYPT_CREATE_SESSION_SKIP; } gc_free(&gc); - return ret; + return action; } /* VERDICT_INVALID */ - return false; + return PRE_DECRYPT_NO_ACTION; } /** @@ -220,9 +237,6 @@ struct link_socket *sock, struct mroute_addr *real) { - struct hash *hash = m->hash; - struct tls_pre_decrypt_state state = { 0 }; - struct multi_instance *mi = NULL; struct gc_arena gc = gc_new(); if (m->deferred_shutdown_signal.signal_received) @@ -231,8 +245,17 @@ "MULTI: Connection attempt from %s ignored while server is " "shutting down", mroute_addr_print(real, &gc)); + gc_free(&gc); + return NULL; } - else if (do_pre_decrypt_check(m, &state, *real, sock)) + + struct hash *hash = m->hash; + struct tls_pre_decrypt_state state = { 0 }; + struct multi_instance *mi = NULL; + + enum pre_decrypt_verdict verdict = do_pre_decrypt_check(m, &state, *real, sock); + + if (verdict != PRE_DECRYPT_NO_ACTION) { /* This is an unknown session but with valid tls-auth/tls-crypt * (or no auth at all). If this is the initial packet of a @@ -255,14 +278,14 @@ mi->did_real_hash = true; multi_assign_peer_id(m, mi); - /* If we have a session id already, ensure that the - * state is using the same */ - if (session_id_defined(&state.server_session_id) - && session_id_defined((&state.peer_session_id))) + struct tls_session *session = + &mi->context.c2.tls_multi->session[TM_INITIAL]; + + if (verdict == PRE_DECRYPT_CREATE_SESSION_SKIP) { + /* This verdict is only possible if we have a peer session ID */ + ASSERT(session_id_defined(&state.peer_session_id)); mi->context.c2.tls_multi->n_sessions++; - struct tls_session *session = - &mi->context.c2.tls_multi->session[TM_INITIAL]; session_skip_to_pre_start(session, &state, &m->top.c2.from); } }