From patchwork Wed Jul 29 15:37:41 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ralf Lici X-Patchwork-Id: 5180 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp2131935mac; Wed, 29 Jul 2026 08:42:36 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RpXkFNeU2hNlxtQtLMytjCXSKL7BEtuMKg6HLMsnFUIcaYMtSLnsn+1RBZ4BQ5Waiu9VOUBG/1Du/k=@openvpn.net X-Received: by 2002:a05:6830:1215:b0:7e9:e961:92e9 with SMTP id 46e09a7af769-7f01410b49bmr1052973a34.4.1785339755914; Wed, 29 Jul 2026 08:42:35 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785339755; cv=none; d=google.com; s=arc-20260327; b=HUPUwaGPchgX+G2HKQRxxXyK/n8p/mzcl/wT16/O4l0NnCdG/85XW7voDPCqgXZvUV WwZokKVT1qqQ16LlmU/HRsa83wFR36Orpp/hvZkoirdV/CL5Ur9Yv1JT5qaGvKRrsOSE L5SkSANEidEw3fi83LBoALNyv+h5jlZ1TKL7JRq7fRbNFVd8tEPU9fqJJgDqrz/spflJ USQIBCvwOR3rSbtmtShcKn/6r9nGv8SDU/JU15vaIM5Q5toZ8IilRsX0iiOxuUOkRS17 uJ02NjfRcZE3/opk49GrYrQCcZJkinxdQph378OYbD5cj35knbHJRl6AwK42n6X6a+DF OYsA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=txNzFFfVBQkWDYR3vfhax3izHp5zZDYU5EDvjpSsYW0=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=SD1sN/GSt2+B0p99TYWTVbMTdVcc2PZapgWarAcuL9I02ioD+mt7qpPANDkmFbSJsk Q6SVuF1CPBPs1IIrsihEgRaoPA/oZboG3uuJtlOvI/LD/7xfUAK6/ErjvPFOaM50WfYh /RR1AKLUJ71Q60n1kdrDRTKNtFrRHAarTlMSS5UbDdN3biSSHh1xTcf3ScsXutSP8cOX YzGtWp9sVnvGj+fuvOYYpLqhONG+DM1rwvY3vCcg7Lzl+beGqzlYSCaU+ZV+u5P5U46r RQzHdxJpZxom1RN0A1Q9IDakIQIqJFlKDUhuiFIuGfhD5zFMDDqohObwlJ0m5qIduni/ 8V8w==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=LTQBMGJu; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=FvnUf76b; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=YJFwLuVr; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=yd+q9AMw; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7f00d5df29fsi2478376a34.11.2026.07.29.08.42.35 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Wed, 29 Jul 2026 08:42:35 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=LTQBMGJu; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=FvnUf76b; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=YJFwLuVr; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=yd+q9AMw; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=txNzFFfVBQkWDYR3vfhax3izHp5zZDYU5EDvjpSsYW0=; b=LTQBMGJuheETKX9uXUXyC70PV7 OirFpuEgwfom/fAIwLQLv/JGdurSJ0dh9fRilJc1UO4eIgg+IF+KixtVJFNMzVD71NVWAhbs4aMu9 M6KZlfB5nm1eK9mIv+uURSWFn9wV43j16eF4ir2P4/pZs9kuTFbiMPWYzLwaq59wtCug=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wp6QV-0000HI-Ki; Wed, 29 Jul 2026 15:42:33 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wp6QH-0000Gm-7W for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 15:42:18 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=WapK7H1NDi6EtOG50cprXW6e9N5mJDrFi0U+8naQrBk=; b=FvnUf76biez6V5iKS+MV2dDnDh bVZujNj03eHYzDagNdEvFe3j2WJIGrx+St4CYPTmGhDPXxRe8TsfTtoyjARAORJwtjQWOg2mgXo+C Z3nv+Y9vNKupwg4UJV5IgVM+jjgUQ4BdoaaD/dYLPdlqDMVBrUc2pGAoO210x9NH+9/8=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=WapK7H1NDi6EtOG50cprXW6e9N5mJDrFi0U+8naQrBk=; b=YJFwLuVrRk03YIJEnKs1EHROH1 Rus1N+k4OVmHZbjW7i+vJ2p7hY5kdBi6HuBYaXy8Yx1EQdfGEjWl0EzASxgvFx53v3V27rQQyFhuI j4/f6gX3ywR9Z68McJ0uxSdQjnrc55cNI9a1sy8nTfwy1JgMQFA6occViI9zvKf/b/XQ=; Received: from mout-b-206.mailbox.org ([195.10.208.51]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wp6QH-0001TD-JU for openvpn-devel@lists.sourceforge.net; Wed, 29 Jul 2026 15:42:18 +0000 Received: from smtp2.mailbox.org (unknown [10.196.197.2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-b-206.mailbox.org (Postfix) with ESMTPS id 4h9GmL5713zXb; Wed, 29 Jul 2026 17:42:10 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1785339730; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=WapK7H1NDi6EtOG50cprXW6e9N5mJDrFi0U+8naQrBk=; b=yd+q9AMwqB+ArkwOkdvwEOo2Y158MgikpViOtHIuZjMYIpBFpia3dj0nBXYjrQgoCkktCR xr9JqRbZl44FnmnrMos9bZdYf+UM1bPdGn2tQ/lPELK/TKovjItwO3NM9m7/IcnumaxjI2 b91L0OsVqccG+QAKwxNPQHe8IQJxXLKOfx6vQf1SiuQsd0gisuUMMBteMe0Ckqmm+Yujo0 6OzMs9ILhiA/KStVyMq9BbyfktvkVL6Nw8Y97MaIhTohP0MGSVFouBRgz5vpHofAdNMiDv Gk1vXLtoeiwRUFYPtSfsVUmTzDPXvFm+/JuUf8pcO5vRH2cb3Z5tkHrUFQ5RGg== From: Ralf Lici To: openvpn-devel@lists.sourceforge.net Date: Wed, 29 Jul 2026 17:37:41 +0200 Message-ID: <17ced9a7caee691e602e3c02f5e399aa9a35067c.1785338921.git.ralf@mandelbit.com> In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: In MP mode, ovpn uses the peer VPN addresses to select the peer for outgoing tunnel packets. Peer creation currently requires a VPN IPv4 or IPv6 attribute, but it only checks for the presence of the a [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [195.10.208.51 listed in wl.mailspike.net] X-Headers-End: 1wp6QH-0001TD-JU Subject: [Openvpn-devel] [PATCH ovpn net 3/5] ovpn: reject multipeer peers without VPN addresses X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1872064419713721038 X-GMAIL-MSGID: 1872064419713721038 In MP mode, ovpn uses the peer VPN addresses to select the peer for outgoing tunnel packets. Peer creation currently requires a VPN IPv4 or IPv6 attribute, but it only checks for the presence of the attribute and not for a usable address value. This allows userspace to create an MP peer with only unspecified VPN addresses, or to update an existing peer so that both VPN address families become unspecified. Such a peer cannot be selected through the VPN address hash tables. Reject MP peer creation or update when the resulting peer would not have at least one VPN address configured. Fixes: 1d36a36f6d53 ("ovpn: implement peer add/get/dump/delete via netlink") Signed-off-by: Ralf Lici --- drivers/net/ovpn/netlink.c | 47 +++++++++++++++++++++++++++----------- 1 file changed, 34 insertions(+), 13 deletions(-) diff --git a/drivers/net/ovpn/netlink.c b/drivers/net/ovpn/netlink.c index 79775af26fda..43e6c7a29a6f 100644 --- a/drivers/net/ovpn/netlink.c +++ b/drivers/net/ovpn/netlink.c @@ -346,8 +346,10 @@ static int ovpn_nl_peer_modify(struct ovpn_peer *peer, struct genl_info *info, int ovpn_nl_peer_new_doit(struct sk_buff *skb, struct genl_info *info) { - struct nlattr *attrs[OVPN_A_PEER_MAX + 1]; + struct in_addr vpn_addr4 = { .s_addr = INADDR_ANY }; + struct in6_addr vpn_addr6 = IN6ADDR_ANY_INIT; struct ovpn_priv *ovpn = info->user_ptr[0]; + struct nlattr *attrs[OVPN_A_PEER_MAX + 1]; struct ovpn_socket *ovpn_sock; struct socket *sock = NULL; struct ovpn_peer *peer; @@ -371,11 +373,19 @@ int ovpn_nl_peer_new_doit(struct sk_buff *skb, struct genl_info *info) return -EINVAL; /* in MP mode VPN IPs are required for selecting the right peer */ - if (ovpn->mode == OVPN_MODE_MP && !attrs[OVPN_A_PEER_VPN_IPV4] && - !attrs[OVPN_A_PEER_VPN_IPV6]) { - NL_SET_ERR_MSG_FMT_MOD(info->extack, - "VPN IP must be provided in MP mode"); - return -EINVAL; + if (ovpn->mode == OVPN_MODE_MP) { + if (attrs[OVPN_A_PEER_VPN_IPV4]) + vpn_addr4.s_addr = + nla_get_in_addr(attrs[OVPN_A_PEER_VPN_IPV4]); + if (attrs[OVPN_A_PEER_VPN_IPV6]) + vpn_addr6 = + nla_get_in6_addr(attrs[OVPN_A_PEER_VPN_IPV6]); + + if (!vpn_addr4.s_addr && ipv6_addr_any(&vpn_addr6)) { + NL_SET_ERR_MSG_FMT_MOD(info->extack, + "VPN IP must be provided in MP mode"); + return -EINVAL; + } } peer_id = nla_get_u32(attrs[OVPN_A_PEER_ID]); @@ -534,13 +544,24 @@ int ovpn_nl_peer_set_doit(struct sk_buff *skb, struct genl_info *info) if (attrs[OVPN_A_PEER_VPN_IPV6]) vpn_addr6 = nla_get_in6_addr(attrs[OVPN_A_PEER_VPN_IPV6]); - /* reject peer with conflicting VPN address */ - if ((attrs[OVPN_A_PEER_VPN_IPV4] || attrs[OVPN_A_PEER_VPN_IPV6]) && - ovpn_peer_vpn_addr_conflict(ovpn, peer, &vpn_addr4, &vpn_addr6)) { - NL_SET_ERR_MSG_FMT_MOD(info->extack, - "VPN IP is already assigned to another peer"); - ret = -EADDRINUSE; - goto unlock; + /* in MP mode VPN IPs are required for selecting the right peer */ + if (ovpn->mode == OVPN_MODE_MP && + (attrs[OVPN_A_PEER_VPN_IPV4] || attrs[OVPN_A_PEER_VPN_IPV6])) { + if (!vpn_addr4.s_addr && ipv6_addr_any(&vpn_addr6)) { + NL_SET_ERR_MSG_FMT_MOD(info->extack, + "MP peer must have at least one valid VPN IP"); + ret = -EINVAL; + goto unlock; + } + + /* reject peer with conflicting VPN address */ + if (ovpn_peer_vpn_addr_conflict(ovpn, peer, &vpn_addr4, + &vpn_addr6)) { + NL_SET_ERR_MSG_FMT_MOD(info->extack, + "VPN IP is already assigned to another peer"); + ret = -EADDRINUSE; + goto unlock; + } } ret = ovpn_nl_peer_modify(peer, info, attrs);