From patchwork Tue Sep 15 16:38:47 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5347 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:6446:b0:8a0:ea1f:253a with SMTP id n6csp5155065mag; Tue, 15 Sep 2026 09:39:10 -0700 (PDT) X-Forwarded-Encrypted: i=2; AKwUvBwMT+FXHQqGHmBdlQR8jGSwtaYv+5O40YwEFVAHIfBfujgeoyzxSLcjXkpYL2SUNUQjeZEr3d4MoY0=@openvpn.net X-Received: by 2002:a05:6808:250d:b0:4c5:238e:b163 with SMTP id 5614622812f47-4c9aaeb53b8mr1412735b6e.29.1789490350216; Tue, 15 Sep 2026 09:39:10 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1789490350; cv=none; d=google.com; s=arc-20260327; b=Y3Vhxd+HY9st5MkEXgSr+M6uo4h00m8FYgqolmdzvuA9qFn5aVjviqntFVWgwvWEQR VyDhlUVZNB9/iDWJ/JhHC2IXzntV1n7UfIB+jN4wYaE3aoIeHftFUCJyG7xEDxeDvpI+ rWRleVkyyfYkn1lRIHKlySgV6nhZ8ZQS4yfu62GoU6e+hJI1Y0ew/Aomx40F0nCaJizr HqxhXcHUW9zKJ3paDq2eZ6yL7bJr+zFoXvrApspPsP90KyAInNNctXOzMNR/ya5wV7xP GDQZa0jjkTqkPrvf9Pfz8FMRujDp1R8xTXN+wAr0xrS3hjj4BfQDSwmU9H2PeUIWMLVy 4QRQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=19Bs2Iw8v7p3uZctTnxHBwyOtReLGSlbqgbRoERdSIQ=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=QSIr7OHR71iGkaj5b+gJNXHjxsCM63vnVj8dkdLZl4gOHmg6yaQWwO+nTUf5BmyEiF 7jwoIgpD4eXjkZJ10x0Kugxyvp1NGN27KBK8XayEVi8we53uniS8hxjJjUKbQbiNGY3G DwnaqdjFa5nqrzbWUr4+X171jTh4Z18bJphQH9cAzB4QuNXJPhulsQFqEQBPuv8Hrf3J PB154HIVFMnTsDh0N87t9ZEPiF7mBLNh42CWApLrb7tpKmOk6RGQDOy3Ul5Pu8YzU1kX he+7sK8yC1Gd4qiwQDGVxiVRp5PpYghUly3pmUaekl+dkeVrZH10fPNpieBxOMvE5jbV FVVw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=ip3RafIj; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=X1YoGywz; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="mZTBI/lz"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-48429ccb2e1si130595fac.84.2026.09.15.09.39.08 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 15 Sep 2026 09:39:09 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=ip3RafIj; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=X1YoGywz; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="mZTBI/lz"; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=19Bs2Iw8v7p3uZctTnxHBwyOtReLGSlbqgbRoERdSIQ=; b=ip3RafIjEsoVR4kIRd0BrHuxjT rkwr3pukV5P/kgjlEVnJ8p0h1PAuS6EHx8psdVbhFBQvHvwBz5K8n2ibrlP6g8GYtKGOtSOj884Kj lZyINIDgvBfCZUw8ZsIujSVkTLm9JutGfWFufDUIzuvn/fOdYk1ZmQwBhp83iq4LGgAY=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1x6WBS-0004AV-VE; Tue, 15 Sep 2026 16:39:03 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1x6WBR-0004AO-Kf for openvpn-devel@lists.sourceforge.net; Tue, 15 Sep 2026 16:39:02 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=y38S8YptZAmD25uDvwoFOD/1V6Zd8A7UsfgYRvykmDU=; b=X1YoGywz/1urOv/DF4Og+Ox/+6 0h/3Isnh0PWPmrF9zqrJUOTHFr6VZ/9Zw3cLBjHDLO/rADKOv0gasYTlrDmhJQd2OWRReiWG0O1Cd KDGGIe22HLdQ04wb6Y3pCXuawjrUAWPSTuJtC4QBIm0waO9pnw7+BcPHrTKJuZ0izR34=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=y38S8YptZAmD25uDvwoFOD/1V6Zd8A7UsfgYRvykmDU=; b=mZTBI/lz+tRNrgOoFmPFBmdgTg E+3yQZ/8Q7lXLi/9cuKhUz0T62TaFUcAI47fKJg4mtO/EPysIXPfF4Qw5cLJgZZhltz+pBi9LpNRU Wlh4uTA51Saq3kD6vq2mnxKlJwpl/EbffbuFwuaeq9LIe6zo7miQdP0jZa3E5Xy9FtBo=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1x6WBQ-00014P-Ms for openvpn-devel@lists.sourceforge.net; Tue, 15 Sep 2026 16:39:02 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 68FGcrRG003504 for ; Tue, 15 Sep 2026 18:38:53 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 68FGcrP3003503 for openvpn-devel@lists.sourceforge.net; Tue, 15 Sep 2026 18:38:53 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Tue, 15 Sep 2026 18:38:47 +0200 Message-ID: <20260915163852.3477-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Arne Schwabe The current code relies on the condition if state.server_session_id is defined to decide if session_skip_to_pre_start should be used. Instead explicitly return the intent and use that to decide if session_skip_to_pre_start should be called. Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_DNSWL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to DNSWL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#DnsBlocklists-dnsbl-block for more information. [193.149.48.129 listed in list.dnswl.org] 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1x6WBQ-00014P-Ms Subject: [Openvpn-devel] [PATCH v10] Make required action returned from pre_decrypt_verdict more explicit X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1873776588285143382 X-GMAIL-MSGID: 1876416633378225577 From: Arne Schwabe The current code relies on the condition if state.server_session_id is defined to decide if session_skip_to_pre_start should be used. Instead explicitly return the intent and use that to decide if session_skip_to_pre_start should be called. Change-Id: Iccdd4cfad090c565aac27e16cdaa9871106c2f89 Signed-off-by: Arne Schwabe Acked-by: Razvan Cojocaru Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1826 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1826 This mail reflects revision 10 of this Change. Signed-off-by line for the author was added as per our policy. Acked-by according to Gerrit (reflected above): Razvan Cojocaru diff --git a/src/openvpn/mudp.c b/src/openvpn/mudp.c index de3d467..88b0091 100644 --- a/src/openvpn/mudp.c +++ b/src/openvpn/mudp.c @@ -87,9 +87,28 @@ "Reset packet from client, sending HMAC based reset challenge", sock); } +/** + * Verdict if this packet should create a new session. If a packet is invalid + * or we send out an HMAC based challenge, we do not want to create a new + * session. + */ +enum pre_decrypt_verdict +{ + /** This packet should not create a new session */ + PRE_DECRYPT_NO_ACTION, + /** This packet creates a new session on the first packet on the session. + * We only do this for legacy tls-crypt-v2 clients that do not work with + * the HMAC cookie challenge approach where we need to keep the client + * specific tls-crypt key to be able to decrypt the third packet */ + PRE_DECRYPT_CREATE_SESSION, + /** Creates a new session. The HMAC challenge has been already completed + * and the first two packets of the three way handshake are skipped in + * the session setup */ + PRE_DECRYPT_CREATE_SESSION_SKIP +}; -/* Returns true if this packet should create a new session */ -static bool +/** Returns a verdict if this packet should create a new session */ +static enum pre_decrypt_verdict do_pre_decrypt_check(struct multi_context *m, struct tls_pre_decrypt_state *state, struct mroute_addr addr, struct link_socket *sock) { @@ -111,7 +130,7 @@ * responses */ if (!reflect_filter_rate_limit_check(m->initial_rate_limiter)) { - return false; + return PRE_DECRYPT_NO_ACTION; } } @@ -136,7 +155,7 @@ calculate_session_id_hmac(state->peer_session_id, from, hmac_key, handwindow, 0); send_hmac_reset_packet(m, state, tas, &sid, true, sock); - return false; + return PRE_DECRYPT_NO_ACTION; } else { @@ -153,11 +172,11 @@ "ignoring connection attempt from old client (%s)", peer); gc_free(&gc); - return false; + return PRE_DECRYPT_NO_ACTION; } else { - return true; + return PRE_DECRYPT_CREATE_SESSION; } } } @@ -170,7 +189,7 @@ send_hmac_reset_packet(m, state, tas, &sid, false, sock); /* We have a reply do not create a new session */ - return false; + return PRE_DECRYPT_NO_ACTION; } else if (verdict == VERDICT_VALID_CONTROL_V1 || verdict == VERDICT_VALID_ACK_V1 || verdict == VERDICT_VALID_WKC_V1) @@ -181,6 +200,7 @@ bool pkt_is_ack = (verdict == VERDICT_VALID_ACK_V1); bool ret = check_session_hmac_and_pkt_id(state, from, hmac_key, handwindow, pkt_is_ack); + enum pre_decrypt_verdict action = PRE_DECRYPT_NO_ACTION; const char *peer = print_link_socket_actual(&m->top.c2.from, &gc); uint8_t pkt_firstbyte = *BPTR(&m->top.c2.buf); @@ -198,14 +218,15 @@ "Valid packet (%s) with HMAC challenge from peer (%s), " "accepting new connection.", packet_opcode_name(op), peer); + action = PRE_DECRYPT_CREATE_SESSION_SKIP; } gc_free(&gc); - return ret; + return action; } /* VERDICT_INVALID */ - return false; + return PRE_DECRYPT_NO_ACTION; } /** @@ -220,9 +241,6 @@ struct link_socket *sock, struct mroute_addr *real) { - struct hash *hash = m->hash; - struct tls_pre_decrypt_state state = { 0 }; - struct multi_instance *mi = NULL; struct gc_arena gc = gc_new(); if (m->deferred_shutdown_signal.signal_received) @@ -231,8 +249,17 @@ "MULTI: Connection attempt from %s ignored while server is " "shutting down", mroute_addr_print(real, &gc)); + gc_free(&gc); + return NULL; } - else if (do_pre_decrypt_check(m, &state, *real, sock)) + + struct hash *hash = m->hash; + struct tls_pre_decrypt_state state = { 0 }; + struct multi_instance *mi = NULL; + + enum pre_decrypt_verdict verdict = do_pre_decrypt_check(m, &state, *real, sock); + + if (verdict != PRE_DECRYPT_NO_ACTION) { /* This is an unknown session but with valid tls-auth/tls-crypt * (or no auth at all). If this is the initial packet of a @@ -255,14 +282,14 @@ mi->did_real_hash = true; multi_assign_peer_id(m, mi); - /* If we have a session id already, ensure that the - * state is using the same */ - if (session_id_defined(&state.server_session_id) - && session_id_defined((&state.peer_session_id))) + struct tls_session *session = + &mi->context.c2.tls_multi->session[TM_INITIAL]; + + if (verdict == PRE_DECRYPT_CREATE_SESSION_SKIP) { + /* This verdict is only possible if we have a peer session ID */ + ASSERT(session_id_defined(&state.peer_session_id)); mi->context.c2.tls_multi->n_sessions++; - struct tls_session *session = - &mi->context.c2.tls_multi->session[TM_INITIAL]; session_skip_to_pre_start(session, &state, &m->top.c2.from); } }