From patchwork Mon Jul 27 20:06:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Antonio Quartulli X-Patchwork-Id: 32 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:190f:b0:87d:a69c:34be with SMTP id g15csp1598644maz; Mon, 27 Jul 2026 13:07:29 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Rq4iXQgiO4JuZae7OQr3J1S9KvpDcrJsYbDlrBa6tXsL1L/AMqdGilSCqGUWaFlil372VjlHuiz6F0=@openvpn.net X-Received: by 2002:a05:6870:8122:b0:448:5591:15d7 with SMTP id 586e51a60fabf-457f281f017mr8728205fac.35.1785182849438; Mon, 27 Jul 2026 13:07:29 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785182849; cv=none; d=google.com; s=arc-20260327; b=YVLlwUNR48+ZaU+zw2SPihXlVb5wZrVb0Nl+Y7ClwICriFdr5ImyOqAjqMI3U1ti+k dqPr4gkdyPHN++EezZObi0AqBcbxonfAPAngCKlBkiLZ+TlJ5nlu0M127obM+yVlpEpT OMIlZwRiYk797LcLrNQV+8DdSgfWXSULHdkf4lSCucJUqu4VSE3DhF+9DzjCwL/p0EtC IVpIuiLTLrHzSGoHHI7SQYDAul1GMraZc4THloKr+RyVdpiC/qWDMi/hOKDwz2fx5K34 IwUTBaja48OhNYJ1kQwwCvdDGzZsijbMnQPIfXYbmWEfqNWtSuQIKol62SYAiY9AQWEG EGIA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:message-id:date:to:from:dkim-signature:dkim-signature :dkim-signature:dkim-signature; bh=28jZLIl3JKZCxzNL73I3QJV4YuPdNr6Ptc63IzhzYcw=; fh=BsMg/B0Yb/hS/rzP5Npz4luh0IleZm8REk1XWiWRt2A=; b=C+pmk1bfFlHiCC6LkRWC9vkZnLdLNHT35BZcZ1HeKpzWs1RCB4m6MnwsNxfIch/+fR FJQQM5i0v4tk0XUNZYs+Im5DQ6ZUryx1Gnt7CIDc5oouuKOpWTmz+GxhsUQQl41SGtW5 kKN28L7FLcVWuHKe2IXf+a41mDGuTtqkgf28LgPDPjI8KVHUZn7zKBIskx+/YHjXLBcn E8q3aQToPVRTJA8eUo6RdU0Q55Nm05QKFs9WkL7KHlnROLf5TLudRVYIVa666OdUMUo7 jhN2bLuHD3IEoqfxuNo7uhZMIH0I3IBgeyMzNTtWKw4q/xHInaVtFgkK7YhYcxdob9k6 Bc+g==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=DDnL+nvQ; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=m1XAyvwz; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="As/h66Ma"; dkim=neutral (body hash did not verify) header.i=@unstable.cc header.s=MBO0001 header.b=WwpNOA3s; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-457aaa0d5d9si13239642fac.373.2026.07.27.13.07.29 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 27 Jul 2026 13:07:29 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=DDnL+nvQ; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=m1XAyvwz; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b="As/h66Ma"; dkim=neutral (body hash did not verify) header.i=@unstable.cc header.s=MBO0001 header.b=WwpNOA3s; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:Message-ID:Date:To:From:Sender:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Owner; bh=28jZLIl3JKZCxzNL73I3QJV4YuPdNr6Ptc63IzhzYcw=; b=DDnL+nvQFf5pkcmE6n5Na2iaih 2Qf7VhDRkTaOivFq1OwJf1BnAqmfHuzPjTAqagnszLIc39n4Nglmp8Mjmv2QkJ513ZvtBZkU3TYqf cUF0EI9dw20/Jhm4d3n1cp5NMp08unaotYpuavhwqRGSU5NSJTbk8ynpj4BDzyVBgv1I=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1woRbe-00062l-40; Mon, 27 Jul 2026 20:07:22 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1woRbc-00062S-Ca for openvpn-devel@lists.sourceforge.net; Mon, 27 Jul 2026 20:07:21 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=nsHIO0arQKEWQI+lR5bWjye+hHkud+o0HonrHazduCs=; b=m1XAyvwz9b116TFQnge+j7NcGM 7ilIzw6kR5E+V9+PG1FiuUmQDhLoa7XYDdWS2dQFVw5FC1nYhilJkWA7fQgUUk8gjXEET57KmCxjD IHv2ev5ohZsrvslPNUgAQpBXnI0SkJ53dSLrWTD+Q/8EQqvMX0gsR7y+RvWAzeS8FWYQ=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:Message-ID:Date:Subject:Cc:To:From :Sender:Reply-To:Content-Type:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post: List-Owner:List-Archive; bh=nsHIO0arQKEWQI+lR5bWjye+hHkud+o0HonrHazduCs=; b=A s/h66MaEX/xjYkXfBcFtq5cwHcAGF2xVAw2N+fvhMy5BY6r4Jf4ZyUvlsGUfj8GFA2ZNs7lOUlVyK Y+VMVPQqRzJqikzLbBXwoTKDvtoRiHO3XouDQt20S02rDEMZr0yLOqWFmLJYTAFlm4MoL5+aSVvwJ JmDEKAmQ1bE3q/4c=; Received: from mout-p-102.mailbox.org ([80.241.56.152]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1woRbc-0001P6-Ho for openvpn-devel@lists.sourceforge.net; Mon, 27 Jul 2026 20:07:21 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [IPv6:2001:67c:2050:b231:465::102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-p-102.mailbox.org (Postfix) with ESMTPS id 4h88l44fRnzKw2c; Mon, 27 Jul 2026 22:07:12 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=unstable.cc; s=MBO0001; t=1785182832; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=nsHIO0arQKEWQI+lR5bWjye+hHkud+o0HonrHazduCs=; b=WwpNOA3s7ZDKniZLnIdkCIkQF/0s0yt54E4Ojg9CoMoYs5LWJ+61X4EZvQC4f53jh2uD/h KaRB3H1qwmT6FaY2Z6pJ1AsQ70E+knHMxcqLAcGIBwBHKBUwV5o4nB2tg/jKV5SB2ckHE6 KSy4iGKD4wzd8nwihOqa5D59xKpyGYqvS7+LDGXnuIjd5CJDgeBeAQZ3RBV3EJTzlOSaT6 UkaaUV1mfFkAJPWQGcOXxjBcf53MVggCOX2ZC4vQNy6KZuXZYhea2rmz1sv/wcAGKP8kiD Hczp/CPOj4WO8nnur00CkMDxwIp++CCGdev4TGaUfT1x8NE91Y047/kjO3we8g== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of a@unstable.cc designates 2001:67c:2050:b231:465::102 as permitted sender) smtp.mailfrom=a@unstable.cc From: Antonio Quartulli To: openvpn-devel@lists.sourceforge.net Date: Mon, 27 Jul 2026 22:06:56 +0200 Message-ID: <20260727200705.869169-1-a@unstable.cc> MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h88l44fRnzKw2c X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Antonio Quartulli Hi all, This is v3 of the collected ovpn fixes for net, sent here for review (and sashiko pre-review) before submission to netdev as a pull request. Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.0 RCVD_IN_MSPIKE_H5 RBL: Excellent reputation (+5) [80.241.56.152 listed in wl.mailspike.net] 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-Headers-End: 1woRbc-0001P6-Ho Subject: [Openvpn-devel] [PATCH ovpn net v3 0/9] ovpn: assorted net fixes X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Antonio Quartulli Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1871899891370657201 X-GMAIL-MSGID: 1871899891370657201 From: Antonio Quartulli Hi all, This is v3 of the collected ovpn fixes for net, sent here for review (and sashiko pre-review) before submission to netdev as a pull request. Changes since v2: * dropped "ovpn: tcp - fix peer reference leak on deferred deletion" (v2 5/9): the deferred-deletion reference is already taken before scheduling the work in the current tree, so the patch is no longer needed (the v2 version also introduced a TOCTOU race) * added "ovpn: invalidate the UDP TX dst_cache when the flow key changes" * "ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET": restored the peer->ovpn->lock and peer->lock acquisitions that the __ovpn_peer_hash_transp_addr() refactor had accidentally dropped from ovpn_peer_endpoints_update(); without them an MP float hit a lockdep splat and a double unlock (panic) * "ovpn: disable IPv4 redirects on MP interfaces": moved the SEND_REDIRECTS handling to ndo_open() so it is re-applied on every bring-up and survives the IPv4 in_device being recreated (e.g. after moving the interface to another netns) Thanks, Antonio Antonio Quartulli (9): ovpn: skip rehash for peers already removed from by_id ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET ovpn: fix data race reading cached local endpoint on TX path ovpn: ensure socket is owned by ovpn before deref sk_user_data ovpn: zero-initialize sockaddr before learning a floated endpoint ovpn: hash floated peer by transport identity only ovpn: disable IPv4 redirects on MP interfaces ovpn: ensure TCP vars are initialized first ovpn: invalidate the UDP TX dst_cache when the flow key changes drivers/net/ovpn/main.c | 60 +++++++++---- drivers/net/ovpn/netlink.c | 19 ++++- drivers/net/ovpn/peer.c | 167 +++++++++++++++++++++++++++++-------- drivers/net/ovpn/peer.h | 15 ++++ drivers/net/ovpn/socket.c | 9 ++ drivers/net/ovpn/udp.c | 87 +++++++++++++++---- 6 files changed, 286 insertions(+), 71 deletions(-)