From patchwork Wed Jul 29 07:20:31 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 35 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp1591214mac; Wed, 29 Jul 2026 00:21:01 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RpVsoCZwzEaPwf1bxl5xB5tcX9nDWnSUoU+qPTCrg8hf2vGmaVF9ZbZhwZUSsu0nRAbRqbK/8I+dc0=@openvpn.net X-Received: by 2002:a05:6820:188b:b0:696:836e:ba2b with SMTP id 006d021491bc7-6ac96970a86mr2995390eaf.11.1785309661707; Wed, 29 Jul 2026 00:21:01 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785309661; cv=none; d=google.com; s=arc-20260327; b=kEOlJCnkhWeRI0yitP40ZeA5NBWx4+5mkMDTy5sWW4/LdXsXm3TNl2RK5jer0kzdPm cWzd7a/C8Rjd3NxeVTmjbNlI/acZJzer7hdrjOqOfJ5VTBZGl07CxNo8+Z15N4xtQJ+g 42d/ksyzEDm6ZoZD7htlARo8wrdr9gwiyaV0RKNBuz6lg634lf5TGXqYkosgJMLd5MVc ud1mzClXJ+IJc8e0H/Br0aKUwD2vbkm2a6DlTYCAmH8qGc6nX8/51O5L9ZD5SVft7DI0 5T1N3D/pr8bLGmNeZxBxnkJClzwE/4xP9qY7TmNbzvdnP8T/jEg644upyyFVnzZYs2zv by/w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:message-id:date:to:from:dkim-signature:dkim-signature :dkim-signature:dkim-signature; bh=h/x3OA30QH2W6KNyuafMAj9Z6V2lddg+AGpQEGTd3j4=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=VfOePjzOYRQpBqhDkrDzPmpAePUYOfH/iwDqzp2m+2+k2sIlzClTmIvQPQUhbDYi8r yN4LiXDtx60HnE2tjiWAd5b8qcnZb0GDanPs6DrsozsIcKDo6RSXjyyfec655ppttQxo O6CSBspbUvT0/JaS0IABnWJwtwODAAY4da/EraPULQi4tZQlYSXCXWjncjUCmihrjsnS F9WVz+V2mYF2nwpV7DScV9eqXaE3OJ+FziBvl2uDMHJ4eRHF0I1HVXcUsLtIpiAMMiOq aLW4bmd3pl6ffnNygpSfZTOCK55dHySQngC0MjLyMiiHACl1GLUCb5DTdkUJPBhDEEnI 40tQ==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=fTIAEbjr; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=mEFGcaWE; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=JqUbgjWe; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=tdAJe3dN; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-45886ba887asi1985933fac.266.2026.07.29.00.21.01 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 00:21:01 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=fTIAEbjr; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=mEFGcaWE; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=JqUbgjWe; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=tdAJe3dN; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:Message-ID:Date:To:From:Sender:Reply-To:Cc:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Owner; bh=h/x3OA30QH2W6KNyuafMAj9Z6V2lddg+AGpQEGTd3j4=; b=fTIAEbjrCbs30LYIO1tfBaigp6 W25sNGrHYsV/TaFhhWxvaGofvNNRgRaQM3Q9li/SZ/Vt797DPxbPgiKHRX4r/46TwqDX84vncW5fr E5oGHcRE5UmjCUfBixNolb/6Z7dfmGoCpZtW7Cu3zIpVwAawsEN9Bdjd8ei0ZRg469hw=; Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1woyb2-0003eN-I7; Wed, 29 Jul 2026 07:20:57 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1woyb0-0003e0-PZ for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 07:20:55 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=Ju3ju7iPX9dR1zVKP/Wn2ETUUPw8gE5cGxWJGqhKnJg=; b=mEFGcaWEetXRFpbUPLw5D541n7 I0cMdPmvS63ILKMLymgYZUBZaqnJ6aPy8+/78WdtOpMgPUk+ITsu4YmlrhNg8iv3vUb0RFfzfoIMi giwHn+rtOitQHRGXk2YoHEh0S/5g7HR3vAE+j+EC1hStSMmCKKT3ymlChJEN5QpNU0Vo=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:Message-ID:Date:Subject:Cc:To:From :Sender:Reply-To:Content-Type:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post: List-Owner:List-Archive; bh=Ju3ju7iPX9dR1zVKP/Wn2ETUUPw8gE5cGxWJGqhKnJg=; b=J qUbgjWeOYwdwrxLaaW9EOv/GZ025OMJuxMGurQPHsyp/XdiPwjaUZfJynq/JM7VyUkPjqsU4kQ+12 ycyBPbbTqky6uxjEp9v/8Tco+i0QAdF4nQw3w2szcOL/jLKcfUgq5KlMKx6sO+Y/atNmemuFiudSD pskQ+gF/B9iHug4U=; Received: from mout-b-107.mailbox.org ([195.10.208.47]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1woyb0-0005D7-Ps for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 07:20:55 +0000 Received: from smtp1.mailbox.org (smtp1.mailbox.org [IPv6:2001:67c:2050:b231:465::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-107.mailbox.org (Postfix) with ESMTPS id 4h93dp6KvJz3y0f; Wed, 29 Jul 2026 09:20:46 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785309646; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=Ju3ju7iPX9dR1zVKP/Wn2ETUUPw8gE5cGxWJGqhKnJg=; b=tdAJe3dNm6jucrE8aZiCnmVNFep8yAAqMU6nAbbt7EzJJJtAFHMb9Yh5+fDe/sUPgWenST GkSOavrIJx7BWEYWt0aeZYldfqv7bNAwJmIgEEqt/Med4hXHoVAY5dNU6NCkBpbh8HcX0a cOge54iAKnWvgke+NNoKAkwH6Kotzke50QQJ5tr6i2GEt96vF1iBzLZOtXFyrB+yoX8Tgj OcIONg6hW3GPmOREyNO9L1Nzz12KNOOdCPYTZ/Vpdx3iBQfsOa8huGtROTHn1ihrlrDQxt +s94Z2l4ahzYOmj0OIwaHXmEvZrDs1wT8boLYVlTW0jKSSaioWBJj67kzuA0zg== Authentication-Results: outgoing_mbo_mout; dkim=none; spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates 2001:67c:2050:b231:465::1 as permitted sender) smtp.mailfrom=ralf@mandelbit.com From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 09:20:31 +0200 Message-ID: MIME-Version: 1.0 X-Rspamd-Queue-Id: 4h93dp6KvJz3y0f X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Hi, This is v2 of a net series that fixes several related issues in ovpn's UDP endpoint and route-cache handling. The only change since v1 is the addition of memory barriers in the last patch when reading [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-Headers-End: 1woyb0-0005D7-Ps Subject: [Openvpn-devel] [PATCH ovpn net v2 0/5] ovpn: fix UDP route cache and endpoint handling X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872032863644229887 X-GMAIL-MSGID: 1872032863644229887 Hi, This is v2 of a net series that fixes several related issues in ovpn's UDP endpoint and route-cache handling. The only change since v1 is the addition of memory barriers in the last patch when reading IPv6 route generations. Sashiko also noted that uninitialized stack memory in ss is used as a hash key for peer endpoints but this is already covered by Antonio's "ovpn: zero-initialize sockaddr before learning a floated endpoint" patch (https://lore.kernel.org/openvpn-devel/20260728114855.1323861-6-a@unstable.cc/). This series preserves IPv6 scope IDs supplied through netlink, handles unspecified source addresses correctly, invalidates cached routes when mutable socket route inputs change, avoids in-place updates of RCU-published peer binds, and prevents stale IPv6 routes from being cached across FIB updates. Support for honoring UDP sockets bound to a device or local address will follow separately for net-next, after these route-cache fixes are available there. Cheers, Ralf Lici Mandelbit Srl --- Changes since v1 https://lore.kernel.org/openvpn-devel/cover.1785253480.git.ralf@mandelbit.com - Patch 5/5: add memory barriers around IPv6 FIB generation reads to avoid reordering on weakly ordered architectures (Sashiko). Ralf Lici (5): ovpn: preserve IPv6 scope id for netlink peer endpoints ovpn: skip UDP source validation for unspecified addresses ovpn: track UDP socket route key for peer dst cache ovpn: avoid in-place updates of peer bind local address ovpn: avoid caching stale IPv6 dst after FIB changes drivers/net/ovpn/netlink.c | 6 + drivers/net/ovpn/peer.c | 37 ++++--- drivers/net/ovpn/peer.h | 19 +++- drivers/net/ovpn/udp.c | 217 +++++++++++++++++++++++++++++++------ include/net/dst_cache.h | 13 +++ net/core/dst_cache.c | 16 ++- 6 files changed, 253 insertions(+), 55 deletions(-)