| Message ID | cover.1787925761.git.ralf@mandelbit.com |
|---|---|
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:c317:b0:87d:ab56:3700 with SMTP id jk23csp51102mab;
Fri, 28 Aug 2026 07:50:58 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AHgh+RqPZkhIp2ylaueuRl2f+QeMwBxoNLdcM0GUto4nsrkf1+6nI32MvfywvwHRFaKO5lLx5H8G0ZbPXis=@openvpn.net
X-Received: by 2002:a05:6830:43a1:b0:7e4:163:49cc with SMTP id
46e09a7af769-7f4f225dacfmr8397357a34.7.1787928658477;
Fri, 28 Aug 2026 07:50:58 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1787928658; cv=none;
d=google.com; s=arc-20260327;
b=fhXJZfAukAdhm1YYD/kxViGKj93+qqo4Zxjfhp5WoOE7mZkcMCOFLB6xOJp/+eoRZK
11Mb81g3bRxsHdpjkFQJB2XOqw02ehvUDltlzCccUD9nzDrV1HOWPkiAE7D9cvVN4cjS
aAeLTQvc5XeglXpnnzFDDaOQ/WNfPC8Qjr1mHbNbF/fLWGx1mBFTQ0TglV0e3vCLHEgD
BocSfCi9i0u1hzc9yIOJ4/TsOE9rf7pcoKh38rMsjnrTCwx1crvpiya7ow0P6yOi8E/I
M+36ZW3PRCq0goZ5J1792aurzg7LadsX+8momT8k7vGwR8IP2j2xKnm9jPGd0mi1IE1w
4ajw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20260327;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:message-id:date:to:from:dkim-signature:dkim-signature
:dkim-signature:dkim-signature;
bh=ZdbTjMHJO2IGwpsWfKYeV43xpmDP0KtkaTwivRCOlc8=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=DnuUdyS9tQRqmAXchcCCJG79wHG8ZlTYim5owKm0jtiV4FzqPSrMx65mqbWauiwNxe
wdSQnwPeKjaR4IEIf0JGQioOKQrN5igsia0WQu6L9v+RwAV7GPmbJn/n1/yWWHW/IvIn
Bjpn+UBNIRcbuBewMDfUn0cjN7FGQmHGBd9aSMk1v9+XruswBS/XQlrfOh0HYs5Q0Ou0
iclc4UBYupjDMP9InUp+CzPTEaiSiuyOpJOiiSKRd+digaTzb/1tM3GDH3tZ3aESfBWm
0qqNkpXmebDjsNR+UUa5ddFGdGTrP8gH1ZaPHeCbPTpiongst/SfLFNdUwnRZK0ut0aM
RxTQ==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=cuHjLUny;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b="UVjjWo/8";
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b="kT/uw8Yw";
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b=mKzQ5OaB;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
46e09a7af769-7f4fa9f1082si2887992a34.63.2026.08.28.07.50.57
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Fri, 28 Aug 2026 07:50:57 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=cuHjLUny;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b="UVjjWo/8";
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b="kT/uw8Yw";
dkim=neutral (body hash did not verify) header.i=@mandelbit.com
header.s=MBO0001 header.b=mKzQ5OaB;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:Message-ID:Date:To:From:Sender:Reply-To:Cc:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:In-Reply-To:References:List-Owner;
bh=ZdbTjMHJO2IGwpsWfKYeV43xpmDP0KtkaTwivRCOlc8=; b=cuHjLUnyW6kRekTwavqNHVOw5r
IeISMn5IVAF/34HLU+MHZKsRU64JBpGtOg9vlkRSsu794C15LzM9gzrKJYNRLYqxuJKyV87pIsmNu
MrKXbM6bDAk71C9MhWt3VDcEyn0XK7quG7eAPMzte34khW9wJfvze3u3JySQLPEikhCA=;
Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com)
by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1wzxuv-0000qR-8Y;
Fri, 28 Aug 2026 14:50:54 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <ralf@mandelbit.com>) id 1wzxur-0000pw-Ru
for openvpn-devel@lists.sourceforge.net;
Fri, 28 Aug 2026 14:50:51 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=A16aCKWV5NvBdTNR2ZaJArt24deyRlaROb4XtlrbbAk=; b=UVjjWo/87OwwDVtdli3DkeWgWn
p9O13kRCkcbUGMS5mrX+EGQlXIah4UcMrGujQ6ZedG0PuLZ5ZP65BICDqsHofqZ8oca+4qytVlW54
bPdTNzkoqcf3c0ZUbd9gb7KJWZYL04wly4sH3JhMLSmfPffKulmSgfgX9F1H0ZtNienc=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:Message-ID:Date:Subject:To:From:
Sender:Reply-To:Cc:Content-Type:Content-ID:Content-Description:Resent-Date:
Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To:
References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post:
List-Owner:List-Archive; bh=A16aCKWV5NvBdTNR2ZaJArt24deyRlaROb4XtlrbbAk=; b=k
T/uw8YwiR1niRYvJP36eEXWg9VI7i9AXKG8NjORJMZPsVUZ9O8TkX2aqxdO+tXSQx5ORkHR96euR+
UCZpSB13RDAtgGH5RTCJbkBvbMXVGGLxK0bi7GkquV1N9FHs5xnyBZkfs1pZ3n/nSncPNyp+NlvIb
8LnKmbVpJlfplJSU=;
Received: from mout-b-210.mailbox.org ([195.10.208.40])
by sfi-mx-2.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1wzxup-00085w-Ig for openvpn-devel@lists.sourceforge.net;
Fri, 28 Aug 2026 14:50:50 +0000
Received: from smtp102.mailbox.org (smtp102.mailbox.org
[IPv6:2001:67c:2050:b231:465::102])
(using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)
key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest
SHA256)
(No client certificate requested)
by mout-b-210.mailbox.org (Postfix) with ESMTPS id 4hWhC315NczFqqM
for <openvpn-devel@lists.sourceforge.net>;
Fri, 28 Aug 2026 16:50:39 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com;
s=MBO0001; t=1787928639;
h=from:from:reply-to:subject:subject:date:date:message-id:message-id:
to:to:cc:mime-version:mime-version:
content-transfer-encoding:content-transfer-encoding;
bh=A16aCKWV5NvBdTNR2ZaJArt24deyRlaROb4XtlrbbAk=;
b=mKzQ5OaBglWla44kWEuAEwDYCS03iNVVEJ2DvVMp6IiDJta1y3cNiUS8OZNIGvkbXcrRWb
6zB+Mtpaxa7YRF+Io5wUE1SIac+XjmU92OOZ4JLx8/L0ISKtUw34L9Zv1xoCm8rMEkVGMM
TxbUu08lWnPT+ET+OqbWpPdepUZll4n3ErA/XXDkQsKKU2+pjERzqy2B5PdJMPlFuQHDRn
9UMVmlFzZm5TaB/jIk0NDFJ+vh8Wtg6UPoMVQA1K3Nkg68ro1YLa1e3t63WGUJSvoZDTCm
xHWVN2547/iZcfAreVpA2eh4tASvoonGKLgNqqLm0bXckZJGxRbyBfsEug4CmQ==
Authentication-Results: outgoing_mbo_mout; dkim=none;
spf=pass (outgoing_mbo_mout: domain of ralf@mandelbit.com designates
2001:67c:2050:b231:465::102 as permitted sender)
smtp.mailfrom=ralf@mandelbit.com
From: Ralf Lici <ralf@mandelbit.com>
To: openvpn-devel@lists.sourceforge.net
Date: Fri, 28 Aug 2026 16:50:21 +0200
Message-ID: <cover.1787925761.git.ralf@mandelbit.com>
MIME-Version: 1.0
X-Rspamd-Queue-Id: 4hWhC315NczFqqM
X-Spam-Score: -0.2 (/)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-2.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Hi, This is v3 of a net series that fixes several related
issues in ovpn's UDP endpoint and route-cache handling. This version was
rebased
on top of net and includes suggestions from Sabrina. The former p [...]
Content analysis details: (-0.2 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature,
not necessarily valid
X-Headers-End: 1wzxup-00085w-Ig
Subject: [Openvpn-devel] [PATCH ovpn net v3 0/6] ovpn: fix UDP route cache
and endpoint handling
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: 1874779080327694473
X-GMAIL-MSGID: 1874779080327694473
|
| Series |
ovpn: fix UDP route cache and endpoint handling
|
|
Message
Ralf Lici
Aug. 28, 2026, 2:50 p.m. UTC
Hi, This is v3 of a net series that fixes several related issues in ovpn's UDP endpoint and route-cache handling. This version was rebased on top of net and includes suggestions from Sabrina. The former patch 5/5 was dropped from this series and will be sent as RFC on netdev, where it is more appropriate since it involves changes broader than ovpn alone. This series preserves IPv6 scope IDs supplied through netlink, handles unspecified source addresses correctly, invalidates cached routes when mutable socket route inputs change and avoids in-place updates of RCU-published peer binds. Support for honoring UDP sockets bound to a device or local address will follow separately for net-next, after these route-cache fixes are available there. Cheers, Ralf Lici Mandelbit Srl --- Changes since v2 https://lore.kernel.org/openvpn-devel/cover.1785308184.git.ralf@mandelbit.com/ - Split former patch 4/5 into three separate patches. (Sabrina) - Dropped former patch 5/5 from this series as it introduces IPv6 routing changes and needs to be discussed as an RFC on netdev. (Sabrina) Changes since v1 https://lore.kernel.org/openvpn-devel/cover.1785253480.git.ralf@mandelbit.com - Patch 5/5: add memory barriers around IPv6 FIB generation reads to avoid reordering on weakly ordered architectures (Sashiko). Ralf Lici (6): ovpn: preserve IPv6 scope id for netlink peer endpoints ovpn: skip UDP source validation for unspecified addresses ovpn: track UDP socket route key for peer dst cache ovpn: validate peer state before caching UDP dst ovpn: replace bind when learning local endpoint ovpn: replace bind when clearing stale local source drivers/net/ovpn/netlink.c | 6 ++ drivers/net/ovpn/peer.c | 44 ++++++----- drivers/net/ovpn/peer.h | 19 ++++- drivers/net/ovpn/udp.c | 193 +++++++++++++++++++++++++++++++++++++-------- 4 files changed, 206 insertions(+), 56 deletions(-) base-commit: 1b78070aaef63512688aebfbc82365ef9d6660f1