From patchwork Tue Jul 28 11:48:46 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Antonio Quartulli X-Patchwork-Id: 33 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp485509mac; Tue, 28 Jul 2026 04:49:18 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RqJK80bw9AODDgufIiu+Qz2/JVfdmv1svL9Ty/KGY/50Nza442Xzi9se9bNXcajg9+2hoO0i/1gD+I=@openvpn.net X-Received: by 2002:a05:6830:440b:b0:7e6:fdea:7aee with SMTP id 46e09a7af769-7efff2b0baamr1267426a34.24.1785239357825; Tue, 28 Jul 2026 04:49:17 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785239357; cv=none; d=google.com; s=arc-20260327; b=UK87XIulPhqkGYo+k2G/WKhA/G1FThi7/5TJimzM4vr0ZuEVKe4rSK1UpSHfqoddPL vd9BMnFUU3dG8vqWdrEqSSRNzfL+JqcWrNMuTHCWqTAUwhgZPvT6gJUDt8GLnU4diWyn wFxPBYAtguTRvlUsS4a6z350T0rhFaYXuK2Qhw1FxPMf3WV7PhtHqqIpmhp6WyMElDVp WQPl4+Qh/dTmYDmz6D5wdNZ5jzNTIm2/lRUianJyeH2AoX6TVuUrt7axbwXTNdwAgX6t sAnuJfp+HviCazoYyQMZ/VZ6jJTBP2KNp/v5tCkg7KMRFj1AJZIf8Oy6B/YLdjm7nOcs 4h3A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:message-id:date:to:from:dkim-signature:dkim-signature :dkim-signature:dkim-signature; bh=Fhh3L9pbhCiklBWg0r1Dzla9WaiSd07ACMpz2wd+mrI=; fh=BsMg/B0Yb/hS/rzP5Npz4luh0IleZm8REk1XWiWRt2A=; b=Gtgfk0i7FNEK9wHsWx+tpuk+NVRDIPaFohaE5EvBhdmZTDC35jRuI/p/kiWjQM9A8z L28PW4yyt6j/2sUfa+Q5UiVLOT9diONBd//OnJb+a5sKxzh/91SuTan2bSpcSzHPhNTi 2eX/6Ub6SPJBHjLEHXwR9qroClSWaqhBigV5DLDOJ2wDjF0bm6B1jR0ndJz48iXHHMxs OuvV1p5+pef5ZUe3OPh2HTh3Id1/DWIWqTYpN8Auhw1AXnHObyv2PwML6qOjkrclPHr/ l2WDTg6YHLiX8Ysn6+O2ONSAMMI4HBTwzUqiexyK3Y+hBlVwb4e++/6oTY5piAb/rrPn btnQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=cTNS1IFW; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=lK+Q4+Ro; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=mdGFRwxi; dkim=neutral (body hash did not verify) header.i=@unstable.cc header.s=MBO0001 header.b=N5TCA3S5; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7ee49c4309csi12484963a34.62.2026.07.28.04.49.17 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 28 Jul 2026 04:49:17 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=cTNS1IFW; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=lK+Q4+Ro; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=mdGFRwxi; dkim=neutral (body hash did not verify) header.i=@unstable.cc header.s=MBO0001 header.b=N5TCA3S5; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:Message-ID:Date:To:From:Sender:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Owner; bh=Fhh3L9pbhCiklBWg0r1Dzla9WaiSd07ACMpz2wd+mrI=; b=cTNS1IFWhdxI7tI3/98wnc7EQ+ yi+067u1ZXqTCTJgzQuna9cudfc2GTICL1sEqp+DTgPoSf/YTyugbVcPlVtNe0adUx5+rb3hM2mhk b+x7rwyXuRRXNITi+sDNfyNJDgM7GNBpbQeV1CwHfnz9lGSnZ0Eru7MN+5V1szOnwAG8=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wogJA-0005tJ-1T; Tue, 28 Jul 2026 11:49:13 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wogJ8-0005tA-Hy for openvpn-devel@lists.sourceforge.net; Tue, 28 Jul 2026 11:49:12 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=qGuiPAgXhpak0h6NKJEAHbmFnKiHeHnXPiTC1ioiUGU=; b=lK+Q4+RoPHUrMrDw+jkzqpg/Xg aIMh7TaZUZP+Ub2OgZzIvSl3Zt7eO3li7l1mjLTEe/1C4SS8KkmqSIALgY6MhBLqt3iYaiGvnK0wL ImSHTBCM5vOx+ejNtYmTpKjgLSdVxyf1UdoAYunyhnmuYHlkRI9mcls9lWjYxw5/6R9E=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:Message-ID:Date:Subject:Cc:To:From :Sender:Reply-To:Content-Type:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post: List-Owner:List-Archive; bh=qGuiPAgXhpak0h6NKJEAHbmFnKiHeHnXPiTC1ioiUGU=; b=m dGFRwxiVK9WyUoGFhXw22XUSeee1vdbdk2/QKRIVi/QRQGRofF5Las9daE251EhrPoMij5IoWeR8N o0pG8KDnCoMQtd2fTRo83jjAap7Z+rH7OCtpJOa0fcVEN7yaU5uHixvUI4qMrYNQTpq+77bGKK40v vB2E5lRtBWtYZbg4=; Received: from mout-p-202.mailbox.org ([80.241.56.172]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wogJ3-0002uh-5Y for openvpn-devel@lists.sourceforge.net; Tue, 28 Jul 2026 11:49:12 +0000 Received: from smtp1.mailbox.org (unknown [10.196.197.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-p-202.mailbox.org (Postfix) with ESMTPS id 4h8Ydn1CPczMlGr; Tue, 28 Jul 2026 13:49:01 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=unstable.cc; s=MBO0001; t=1785239341; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=qGuiPAgXhpak0h6NKJEAHbmFnKiHeHnXPiTC1ioiUGU=; b=N5TCA3S53rrOolEIZ9CkzuDSeHL5jXBsRMzHiQMbHgnjsHXED4KTNa4+H7J0jgu8+aaG99 1cXfbpzTfHEgu6XExsnPMjRNlUGX69AlRePkvNo/fRuVh7CXNO3Zz0huOJ6vIioz4xxiCW 2kav16FiW+r0LB0VpUrmEJ4jqkIWvvHG6iYQhPSjs6CiktfE/SyoWpD7T0+ux9zrVvAllo 8svDK2LbHdgkNi2vE/mLm5C0DOsgCOMNEz1Qi7gq4UFXOyzPcVQm15BE0+lsXamYmHjwNl VFbWR2lCDCj9IBSXr4RPdFvosCqIWBzH8bTVQn9asu53obaPxwVFXmTn1OBtxA== From: Antonio Quartulli To: openvpn-devel@lists.sourceforge.net Date: Tue, 28 Jul 2026 13:48:46 +0200 Message-ID: <20260728114855.1323861-1-a@unstable.cc> MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Antonio Quartulli Hi all, This is v4 of the collected ovpn fixes for net, sent here for review (and sashiko re-review) before submission to netdev as a pull request. Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_H5 RBL: Excellent reputation (+5) [80.241.56.172 listed in wl.mailspike.net] 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-Headers-End: 1wogJ3-0002uh-5Y Subject: [Openvpn-devel] [PATCH ovpn net v4 0/9] ovpn: assorted net fixes X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Antonio Quartulli Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1871959144524188309 X-GMAIL-MSGID: 1871959144524188309 From: Antonio Quartulli Hi all, This is v4 of the collected ovpn fixes for net, sent here for review (and sashiko re-review) before submission to netdev as a pull request. v3 got a sashiko review that flagged three new issues; this v4 addresses all of them. Changes since v3: * "ovpn: zero-initialize sockaddr before learning a floated endpoint": build the floated endpoint with a designated initializer instead of zeroing the whole sockaddr_storage on every received packet, so the padding is still cleared without a memset on the RX fast path * "ovpn: invalidate the UDP TX dst_cache when the flow key changes": - re-validate sport/mark in the post-lookup check as well: the TX entry check alone could let a slow resolver cache a route tagged with a sport/mark another CPU had already changed - compare bind->local against the value snapshotted before the route lookup instead of the FIB-populated fl.saddr, so caching is no longer skipped for a peer whose local address is not yet known No functional changes to the other patches. Thanks, Antonio Antonio Quartulli (9): ovpn: skip rehash for peers already removed from by_id ovpn: rehash peer in by_transp_addr table on CMD_PEER_SET ovpn: fix data race reading cached local endpoint on TX path ovpn: ensure socket is owned by ovpn before deref sk_user_data ovpn: zero-initialize sockaddr before learning a floated endpoint ovpn: hash floated peer by transport identity only ovpn: disable IPv4 redirects on MP interfaces ovpn: ensure TCP vars are initialized first ovpn: invalidate the UDP TX dst_cache when the flow key changes drivers/net/ovpn/main.c | 60 ++++++++---- drivers/net/ovpn/netlink.c | 19 +++- drivers/net/ovpn/peer.c | 196 ++++++++++++++++++++++++++++--------- drivers/net/ovpn/peer.h | 15 +++ drivers/net/ovpn/socket.c | 9 ++ drivers/net/ovpn/udp.c | 108 +++++++++++++++++--- 6 files changed, 329 insertions(+), 78 deletions(-)