From patchwork Fri Aug 21 18:24:34 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5264 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:4306:b0:87d:ab56:3700 with SMTP id q6csp1554275mae; Fri, 21 Aug 2026 11:25:01 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RrnMB5rcBUzz0bN+yO11wVLCrfr99sB7Xj4ydW4LAiKYkENLf1Htz74HXZiechBQ/Wz7WRCxGNZ5ss=@openvpn.net X-Received: by 2002:a05:6870:45a8:b0:456:dbed:6b60 with SMTP id 586e51a60fabf-4637f6761abmr1113821fac.1.1787336701045; Fri, 21 Aug 2026 11:25:01 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1787336701; cv=none; d=google.com; s=arc-20260327; b=TpSU1W7b6zZXB8KjW6jCqhRvBG8zjZ7h/Y894+TCK0Q7X6PxZIbsHmVlwjcIxCQKtm sqSTwlhD96kp1nGj9wy5Nr19tUOxoliPXWXGY3ih+w7Q5M0tSsO7cY3QSTal/3NhFSyd lTHXMi0qzYRGUYVbBP8/pdOPaZw3nPep0B5Y5Vy+S97XeaARXXORJ0I2KRGhI9kwYA/m ofCh0zidujWHnaSgD7Quq9mYECVHVEqIzJuglX3nbzbZR3z1RJPuzgipAQT6S19ZF2Ws 8nDSBaBwcefofircF5YrZvXWH3m8H2jZHDikVvPIvMCQHaE8c6hlStxv3rHwewpofvDd 7Mew== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=zSjoYOJu5YbDYWSYzPoF5jgSefVLSpdovk0DvmsR7ac=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=WetEfl7SlOV8dkxN8mAnkk1ULISjgVxfSkLFcL1FCrKnWbBuFqHwUQzoaWPCuupznW VQfquF8EUpaP9rxpg4ARAaDhBhtjRD/JaC2gT0fm8hxPH9K8LVdfXEJzQqhSPAfBgcrH oDcVlELhXHgXimMhNbqv09jnK5VEd9uzJLQmJJHI7aSvkmID+TCGrhRk63SixR4gCDek AwI6U3CvAsG1eX4LpiVBGlwTRg4425PC0K1O/E3u2GGKXfJSTWqQP4lHN03Sc+OK0hMk DvngeJ3gVIZAvxAZg9w39pBDLx/b33qvy8jqAwK3iodjGvXDWN2M+xQnkaUxhyPVnnbk mSdg==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b="e/DqxEja"; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=iHEOddIu; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=GdglUv2D; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-4638366d53dsi133720fac.271.2026.08.21.11.25.00 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Fri, 21 Aug 2026 11:25:00 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b="e/DqxEja"; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=iHEOddIu; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=GdglUv2D; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=zSjoYOJu5YbDYWSYzPoF5jgSefVLSpdovk0DvmsR7ac=; b=e/DqxEjaxuuC8Ty1GsuA2HiTT9 TZkQQz9uihz1U9Oysjh5imQrExKgnTOKtincdZhoEMDjeQbBrznCjyRlg7n/iavvzPiOoq1FYJpVs /d+oMa6+p2Owoi7ii6n6fSn/6p91AeH5wYoeU4Bg8InN/BazY/BG8TrTn4nHw8TKmkOA=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wxTvE-0006uo-4d; Fri, 21 Aug 2026 18:24:53 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wxTvC-0006uf-9Z for openvpn-devel@lists.sourceforge.net; Fri, 21 Aug 2026 18:24:51 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=no5rE22eeh/+rv+/aPRgVoJ2SPgaEeJZfeKBPyHH/+U=; b=iHEOddIuZRrjeo5SLiy6T+E45u H4vYCjjQV+fC5jN/xVREEi0L1QrMIVt9sM4Dk0LsxuOtu03AVIJ6ruqYVz1rFt3stkI5D+Gp5L0wP 8tY16YTt/K+YxBRkZ6gXdOMem5JxY1zZG4i6x/qfvZ9fYR8d0llsnkrAoxZXMufmUWDI=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=no5rE22eeh/+rv+/aPRgVoJ2SPgaEeJZfeKBPyHH/+U=; b=GdglUv2DYIAzcdW14GKZpD2fms rWXu37NksH+3t9QllNe2MuZpuJmvQCNggyly6pDxH7ZAI1I8WVjSE/sA0LQQXJnIw4WydooxbH72/ oncWuYBC3j0N/p5tGd2gwVuM8J6tB8srp7Zly9QbW8OwEoUTABKsceeo+JzrWSmw90cI=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wxTv8-0006Tv-CZ for openvpn-devel@lists.sourceforge.net; Fri, 21 Aug 2026 18:24:51 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 67LIOhe7013562 for ; Fri, 21 Aug 2026 20:24:43 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 67LIOh4W013561 for openvpn-devel@lists.sourceforge.net; Fri, 21 Aug 2026 20:24:43 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Fri, 21 Aug 2026 20:24:34 +0200 Message-ID: <20260821182442.13542-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Antonio Quartulli As per RFC768, when the UDP checksum is zero, it means it was not computed by the source, therefore any NAT processing along the way should leave the checksum alone and not update it. Failing to do so [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1wxTv8-0006Tv-CZ Subject: [Openvpn-devel] [PATCH v1] clinat: do not adjust UDP checksum if zero X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1874158368733728408 X-GMAIL-MSGID: 1874158368733728408 From: Antonio Quartulli As per RFC768, when the UDP checksum is zero, it means it was not computed by the source, therefore any NAT processing along the way should leave the checksum alone and not update it. Failing to do so would result in computing a bogus value. At the same time, if the result of updating a non-zero checksum ends up being zero, as per the same RFC, we must store its one-complement (0xFFFF) as zero is reserved for "checksum not computed", as mentioned above. Ensure our Client NAT code follows both rules. Github: closes OpenVPN/openvpn#1037 Reported-by: Jeff Salee Change-Id: I4068bf8175c23151298d142dc920ab89f861a411 Signed-off-by: Antonio Quartulli Acked-by: Razvan Cojocaru Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1681 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1681 This mail reflects revision 1 of this Change. Acked-by according to Gerrit (reflected above): Razvan Cojocaru diff --git a/src/openvpn/clinat.c b/src/openvpn/clinat.c index 32c1325..3724022 100644 --- a/src/openvpn/clinat.c +++ b/src/openvpn/clinat.c @@ -258,7 +258,23 @@ { if (BLENZ(ipbuf) >= sizeof(struct openvpn_iphdr) + sizeof(struct openvpn_udphdr)) { - ADJUST_CHECKSUM(accumulate, h->u.udp.check); + /* RFC 768: a UDP checksum of 0 means "no checksum computed". + * Do not run the incremental adjustment over a non-checksum, + * or we will write a bogus non-zero value into the field. + */ + if (h->u.udp.check) + { + ADJUST_CHECKSUM(accumulate, h->u.udp.check); + + if (!h->u.udp.check) + { + /* RFC 768: a computed checksum of 0 must be transmitted + * as 0xFFFF (one-complement), because 0 is reserved for + * "no checksum computed" + */ + h->u.udp.check = 0xFFFF; + } + } } } }