From patchwork Wed Jul 22 04:47:56 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Marco Baffo X-Patchwork-Id: 5119 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:508:b0:87c:c0c2:48b6 with SMTP id y8csp2686298mae; Tue, 21 Jul 2026 21:48:50 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Ro3vqYjgUoVRx1PvKW5rvV7HnKav9cHRgRk4JyKZCffQGlks3VIHT17DsC/NOPRc+aWf69frE96ctk=@openvpn.net X-Received: by 2002:a05:6820:1c84:b0:6a1:78b0:c321 with SMTP id 006d021491bc7-6a5367e1bc5mr10998636eaf.18.1784695730437; Tue, 21 Jul 2026 21:48:50 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1784695730; cv=none; d=google.com; s=arc-20260327; b=EMp3ZND65Rxvtaiw/WHZQ7G1VaQPRoXl4FAaavLCeb6TmrXEuisAvUy0RatW2FhSQ1 yLOSv06cae5/WRqqCepMEk+NIONKiy8fuhvgEM8pPryArHuPXBk0tanMaxTUofsxqLWV VvivZMAwSjKviUjwZ/EzM+qzmdQVF1bCxH4hb44+Iq/FQzoNrl8KyvjKH01nfWFSxAmH 6k8HTiyeBbvjObPvngzKQMgNOQ4qKoxZ5Mc4asDJcUAVa5WwjwPsJaiZZlmSYlNLPXqD mVWOW7H7sb2czA61BN8pbhAjBygjt754CzcTWGYfpY2tGSn3uKtXOlhkSjx2TJRXl2eW vHsA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:message-id:date:to:from:dkim-signature:dkim-signature :dkim-signature:dkim-signature; bh=8W7S3ulzsM/AE7BhOCyyPgmrRqPPnFtvpkiHTjAdq1A=; fh=BsMg/B0Yb/hS/rzP5Npz4luh0IleZm8REk1XWiWRt2A=; b=UnQsH+GrimXnpgME3VdkEGMOl0HshXcgRCYMp746QMcdN/OY0v7cEd/RZqdWeR/HTS x0gPoQGndboYS+OlgAzWBic5y9C9Aek9w0rZRVBdOOFnw/03cbloioXseurCDywH4Xgm RMBzxdU905WC/OxrMwHdtHujtG91qO3F11piMuSeaikcCvc9bWjbSaDpcimfcTfKEBjO /ms88dsHLlAkLNxP/TXqEMsNkJ9P5k1wCUsHqMCWFZZo5jYz3imEi+sw+Idzmur83AqC yZLqZBouGH3Kggf63WnSz7dGGADn29zqxF3UJwWXDuxLf16dgf+E7zA2gPu9Xle6GwlD OH1g==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=KBfMbQJz; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=jVULH7io; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=EZTXytij; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=QfBVBM65; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 586e51a60fabf-45766e71dc1si1348910fac.11.2026.07.21.21.48.49 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 21 Jul 2026 21:48:50 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=KBfMbQJz; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=jVULH7io; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=EZTXytij; dkim=neutral (body hash did not verify) header.i=@mandelbit.com header.s=MBO0001 header.b=QfBVBM65; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:Message-ID:Date:To:From:Sender:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Owner; bh=8W7S3ulzsM/AE7BhOCyyPgmrRqPPnFtvpkiHTjAdq1A=; b=KBfMbQJzpt37O3hqpq1M95EArs NzB0AtziYGP/GyFahjjwWP65ExHq9l01oc7hc4mfSQggGMupZNSbw7t02O2T/SGoVdMXyDbXCv48b KvW9FcKb6Bls6OoMxBsX2ST03KKlzeBSvq5Ah7NBUcxIlMNAKRqhQNoJ6f7MxbHnOseA=; Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wmOsv-0001FR-UR; Wed, 22 Jul 2026 04:48:43 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wmOsf-0001F8-Bh for openvpn-devel@lists.sourceforge.net; Wed, 22 Jul 2026 04:48:27 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=ie30qSNCGFbASrL8SUlz2Epnc7sLQHyDocYbl2TxDlY=; b=jVULH7io26zSQ11ZyrrNYd8gMf We6HYm45hgdjfYNjPnoEbadO8y40aZ5v/HmqTAa0fx0s2HCuXPeBOc2djQ+c/ATTDr6TzaShW3Xaq 8VGrG66dxPU7P2AopsLuCGioSGK42Cjecbkcr3h0w4iWaFP1UMXwDOsoDAOrvvpkUHBg=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:Message-ID:Date:Subject:Cc:To:From :Sender:Reply-To:Content-Type:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post: List-Owner:List-Archive; bh=ie30qSNCGFbASrL8SUlz2Epnc7sLQHyDocYbl2TxDlY=; b=E ZTXytijFhTFaF0EyoGROJwslWIREAm6xyEkArf9FZkRnhUvS3B2ZPXpIQwyS3Bn4aydCArV5KUzLL zPbn6LVXk1+AB1CBY1UaSzEITn/tE5zgKLDIotSA8ftRdoDv+PtGnkKNlJ5dh1autHw3bRyCVKNRd VWEd9kw3SgL0gDoI=; Received: from mout-b-210.mailbox.org ([195.10.208.40]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wmOsV-0007Qu-M8 for openvpn-devel@lists.sourceforge.net; Wed, 22 Jul 2026 04:48:21 +0000 Received: from smtp102.mailbox.org (smtp102.mailbox.org [10.196.197.102]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA512) (No client certificate requested) by mout-b-210.mailbox.org (Postfix) with ESMTPS id 4h4hZt4WdqzFr6v; Wed, 22 Jul 2026 06:48:06 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mandelbit.com; s=MBO0001; t=1784695686; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=ie30qSNCGFbASrL8SUlz2Epnc7sLQHyDocYbl2TxDlY=; b=QfBVBM653o/q7ekkB3FR2eXaMkU9vO9B/KwaMYaLDLrvqATKTn3KcXv9oTU63QGkvEcyib 6OoHhzfjxK6in6pCwMXpsnxeJUxJ9Wg9EKEUVkoj4iMnG5gFHOiMLpS94NEsVIzGshmd6C OV0OU0PDSIgVLgtf8rfYZDIdr9fszgIfMy8HBmynRdWIltKIKOvMIjzAJ+3Ff7R4ccwrUz /yzg9/uqbKrK5STZnaB2S5uHQ6BFetxrvOUps/Rj6hHMjHkWQnwZTeiHPuB1SYcb0V/F1p FL/yg8lR2VLVauFmtgZ3of4f2XI0EWbAURqYqoVuH4Vox1nANqsFFoKuNsPFOw== From: Marco Baffo To: openvpn-devel@lists.sourceforge.net Date: Wed, 22 Jul 2026 06:47:56 +0200 Message-ID: <20260722044756.872870-1-marco@mandelbit.com> MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: Large keepalive values can overflow the delayed-work delay on 32-bit systems, causing the keepalive worker to be repeatedly scheduled. A correct configuration should not require such large keepalive values, and an upper limit of one day is already generous and unnecessary in practice. Limit both the keepalive interval and timeout to [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-Headers-End: 1wmOsV-0007Qu-M8 Subject: [Openvpn-devel] [PATCH ovpn net] ovpn: limit keepalive values to one day X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Antonio Quartulli Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1871389110203532848 X-GMAIL-MSGID: 1871389110203532848 Large keepalive values can overflow the delayed-work delay on 32-bit systems, causing the keepalive worker to be repeatedly scheduled. A correct configuration should not require such large keepalive values, and an upper limit of one day is already generous and unnecessary in practice. Limit both the keepalive interval and timeout to 86400 seconds. Signed-off-by: Marco Baffo --- Documentation/netlink/specs/ovpn.yaml | 4 ++++ drivers/net/ovpn/netlink-gen.c | 20 ++++++++++++++------ 2 files changed, 18 insertions(+), 6 deletions(-) diff --git a/Documentation/netlink/specs/ovpn.yaml b/Documentation/netlink/specs/ovpn.yaml index b0c782e59a32..ac50d1d7c00a 100644 --- a/Documentation/netlink/specs/ovpn.yaml +++ b/Documentation/netlink/specs/ovpn.yaml @@ -118,12 +118,16 @@ attribute-sets: doc: >- The number of seconds after which a keep alive message is sent to the peer + checks: + max: 86400 - name: keepalive-timeout type: u32 doc: >- The number of seconds from the last activity after which the peer is assumed dead + checks: + max: 86400 - name: del-reason type: u32 diff --git a/drivers/net/ovpn/netlink-gen.c b/drivers/net/ovpn/netlink-gen.c index 2147cec7c2c5..92d2fdc17c2e 100644 --- a/drivers/net/ovpn/netlink-gen.c +++ b/drivers/net/ovpn/netlink-gen.c @@ -16,6 +16,14 @@ static const struct netlink_range_validation ovpn_a_peer_id_range = { .max = 16777215ULL, }; +static const struct netlink_range_validation ovpn_a_peer_keepalive_interval_range = { + .max = 86400ULL, +}; + +static const struct netlink_range_validation ovpn_a_peer_keepalive_timeout_range = { + .max = 86400ULL, +}; + static const struct netlink_range_validation ovpn_a_peer_tx_id_range = { .max = 16777215ULL, }; @@ -68,8 +76,8 @@ const struct nla_policy ovpn_peer_nl_policy[OVPN_A_PEER_TX_ID + 1] = { [OVPN_A_PEER_LOCAL_IPV4] = { .type = NLA_BE32, }, [OVPN_A_PEER_LOCAL_IPV6] = NLA_POLICY_EXACT_LEN(16), [OVPN_A_PEER_LOCAL_PORT] = NLA_POLICY_MIN(NLA_BE16, 1), - [OVPN_A_PEER_KEEPALIVE_INTERVAL] = { .type = NLA_U32, }, - [OVPN_A_PEER_KEEPALIVE_TIMEOUT] = { .type = NLA_U32, }, + [OVPN_A_PEER_KEEPALIVE_INTERVAL] = NLA_POLICY_FULL_RANGE(NLA_U32, &ovpn_a_peer_keepalive_interval_range), + [OVPN_A_PEER_KEEPALIVE_TIMEOUT] = NLA_POLICY_FULL_RANGE(NLA_U32, &ovpn_a_peer_keepalive_timeout_range), [OVPN_A_PEER_DEL_REASON] = NLA_POLICY_MAX(NLA_U32, 4), [OVPN_A_PEER_VPN_RX_BYTES] = { .type = NLA_UINT, }, [OVPN_A_PEER_VPN_TX_BYTES] = { .type = NLA_UINT, }, @@ -97,8 +105,8 @@ const struct nla_policy ovpn_peer_new_input_nl_policy[OVPN_A_PEER_TX_ID + 1] = { [OVPN_A_PEER_VPN_IPV6] = NLA_POLICY_EXACT_LEN(16), [OVPN_A_PEER_LOCAL_IPV4] = { .type = NLA_BE32, }, [OVPN_A_PEER_LOCAL_IPV6] = NLA_POLICY_EXACT_LEN(16), - [OVPN_A_PEER_KEEPALIVE_INTERVAL] = { .type = NLA_U32, }, - [OVPN_A_PEER_KEEPALIVE_TIMEOUT] = { .type = NLA_U32, }, + [OVPN_A_PEER_KEEPALIVE_INTERVAL] = NLA_POLICY_FULL_RANGE(NLA_U32, &ovpn_a_peer_keepalive_interval_range), + [OVPN_A_PEER_KEEPALIVE_TIMEOUT] = NLA_POLICY_FULL_RANGE(NLA_U32, &ovpn_a_peer_keepalive_timeout_range), [OVPN_A_PEER_TX_ID] = NLA_POLICY_FULL_RANGE(NLA_U32, &ovpn_a_peer_tx_id_range), }; @@ -112,8 +120,8 @@ const struct nla_policy ovpn_peer_set_input_nl_policy[OVPN_A_PEER_TX_ID + 1] = { [OVPN_A_PEER_VPN_IPV6] = NLA_POLICY_EXACT_LEN(16), [OVPN_A_PEER_LOCAL_IPV4] = { .type = NLA_BE32, }, [OVPN_A_PEER_LOCAL_IPV6] = NLA_POLICY_EXACT_LEN(16), - [OVPN_A_PEER_KEEPALIVE_INTERVAL] = { .type = NLA_U32, }, - [OVPN_A_PEER_KEEPALIVE_TIMEOUT] = { .type = NLA_U32, }, + [OVPN_A_PEER_KEEPALIVE_INTERVAL] = NLA_POLICY_FULL_RANGE(NLA_U32, &ovpn_a_peer_keepalive_interval_range), + [OVPN_A_PEER_KEEPALIVE_TIMEOUT] = NLA_POLICY_FULL_RANGE(NLA_U32, &ovpn_a_peer_keepalive_timeout_range), [OVPN_A_PEER_TX_ID] = NLA_POLICY_FULL_RANGE(NLA_U32, &ovpn_a_peer_tx_id_range), };