From patchwork Tue Jul 28 11:48:52 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Antonio Quartulli X-Patchwork-Id: 5147 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:fd0b:b0:87d:ab56:3700 with SMTP id cw11csp485553mac; Tue, 28 Jul 2026 04:49:20 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+Rre4dARW2xpzghX8ZhQSvroeX5mJIKOodV5D+7k8LKPZGFDbjh26aGa5U1j6Re12/E6BqP8f/4wgHA=@openvpn.net X-Received: by 2002:a05:6820:88f:b0:6aa:e99d:7f7b with SMTP id 006d021491bc7-6ac96c69291mr990909eaf.18.1785239360117; Tue, 28 Jul 2026 04:49:20 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1785239360; cv=none; d=google.com; s=arc-20260327; b=C2HUtaRa5ZahU0aeuvWpHrXKfcSVOTiY4ybk54ur7ZGcc+pNB07Eb3omg6Mye7osp9 q6XKQPXM7l56cVWdEgnC4CMvZnNjwUWpjf57OSpq+6H6HCyPtvH8xKFClPBVuLECj055 OH+Sh69uECP9UQ5CU9ZaOi4BckEmtGBagq2FGfasyN3lHehvLewr6RYsvdUnsQBexKqv 07jKDWZSOZc7JUGFmMTn3jReHU/wLb5U7ipHEScgmHIelcpvMTDsKduktPvyhfi8MgZs YyQJiDw1G3wV+ZCTMj5zcQTiFcC/E2R08ExV4h8vL7ekZ+jDyNJVtNnkTmmwF7nG84xl n0fw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:cc:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature:dkim-signature; bh=gtPZ7qfVPtVPN64G95SuUKdyKRa/JTdzuD0ywsZWjTg=; fh=BsMg/B0Yb/hS/rzP5Npz4luh0IleZm8REk1XWiWRt2A=; b=jEFb25ZB12FXQwlbU4eEaRJPF/8cmD3Y6IRlNeLgS1p7avbLPhAWzcc6NA8tKhH8pA OCGY5TKD59LuQKiOG/hZLADSR+AlRo5Vcl3FuQ6xq6kHcei/+/FfFFP1GlJ38deccbnO iPrwTRhy68psMEmIelsdmkHo138IetT8OE4fAvRbIH/Jb67lyAxOaPsHpECcLNRA0cbl yuiXifK8Ktcc9fbw7ugPdhWUt+XBSVtPH77+MQC6EvqK/54dhEJ2Z6Wt/1rMoL6hFGy6 YdDHCOBnNKUKluoJfZvpmrk76F/Amc5utrIOQm06Ba66Uq8oTk6NNwa562zdq56nbWt3 597g==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=C4eIXGVY; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=iPPBWx8R; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=ZB+6niBG; dkim=neutral (body hash did not verify) header.i=@unstable.cc header.s=MBO0001 header.b=THsTy+vK; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7ee49bef0b1si13045945a34.38.2026.07.28.04.49.19 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Tue, 28 Jul 2026 04:49:20 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=C4eIXGVY; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=iPPBWx8R; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=ZB+6niBG; dkim=neutral (body hash did not verify) header.i=@unstable.cc header.s=MBO0001 header.b=THsTy+vK; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:Cc: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender :Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=gtPZ7qfVPtVPN64G95SuUKdyKRa/JTdzuD0ywsZWjTg=; b=C4eIXGVYjjO3OjzUVe9GMpeZho TEbg3/4e8jgmmZDElNHWIMugC4XCxcJiFc+g9wtBQi1Gm5PEt2Qz9kr5G64umeFOXWNeskXhuRwoB 3KJhgFtHgnAz89CRd3d2ujAMyHa2Ti5xIGCdERhGEEAyCA9m6NjBIXS0DVmuyLnbwPkE=; Received: from [127.0.0.1] (helo=sfs-ml-3.v29.lw.sourceforge.com) by sfs-ml-3.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wogJA-00066H-6m; Tue, 28 Jul 2026 11:49:16 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-3.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wogJ8-00065w-IK for openvpn-devel@lists.sourceforge.net; Tue, 28 Jul 2026 11:49:15 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=vHx0ao4c0cWDp76L5UI+a1UoZuOzW2Z88UtcUEGyHmQ=; b=iPPBWx8RpNZ//dfwbDx6Be1gb9 2xiIvM7Tn3LCB8jv9mrjJxEpjGYbQdUCtItdVuJNtWYGG+MR0xzI374aG+eMBXC827Ub06QXvaoaS zTokn0G6ePmCEj0VTAi6oghk01EcNaNc6MEGaswi/T2b5WKyXwBzeP24BjE82sA32FBY=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:Cc:To:From:Sender:Reply-To:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=vHx0ao4c0cWDp76L5UI+a1UoZuOzW2Z88UtcUEGyHmQ=; b=ZB+6niBG5rfwB+zqGXdDYjk/Ei GC8haBc10S5l0a3kRY4nfOR3esRqNPJld1WgZmNFyFXF90NobNiK3TphKiMgchRoi475aYVBt1i1X m49jnDfUzkaO2mFP+0U1TY+N8s/dvxo/Vcd78aaDDSJ1ZjTQYLMssUVqufJbFslADcqo=; Received: from mout-p-201.mailbox.org ([80.241.56.171]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wogJA-0003Bp-28 for openvpn-devel@lists.sourceforge.net; Tue, 28 Jul 2026 11:49:15 +0000 Received: from smtp1.mailbox.org (unknown [10.196.197.1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by mout-p-201.mailbox.org (Postfix) with ESMTPS id 4h8Ydr6NBPzMlD1; Tue, 28 Jul 2026 13:49:04 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=unstable.cc; s=MBO0001; t=1785239344; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=vHx0ao4c0cWDp76L5UI+a1UoZuOzW2Z88UtcUEGyHmQ=; b=THsTy+vKevb59/QMrtusm+I1LbkdXWRAykDunU/ukrnqiHoEOjw6AJcxNMad3Sz0V9YNsC ZSNV0c+/tA0dEwQ471P7hUTOoyZZ+rthDHXfYbkMIXmGObOInRE6Osyh1afeoTZX1sQdaM OLYg9fJCDQ5d2f+tdXDHlZRD2Egc4IlOLIQN0iB8Lw6uIkdLmoSc4HiAuTT1xB0AfvWo4c b3liBrnxUEm3d66HeN288vRjUwr+tVFcZ4On9NKd8tHdfhQSLsO5PsCfi+FVY2Hy1LUr2M yKNx9DufKpNwojrii3E8rGiLwErOvo5PeLRPOpGRQbuJT59Axu1tyFFFi6QSIw== From: Antonio Quartulli To: openvpn-devel@lists.sourceforge.net Date: Tue, 28 Jul 2026 13:48:52 +0200 Message-ID: <20260728114855.1323861-7-a@unstable.cc> In-Reply-To: <20260728114855.1323861-1-a@unstable.cc> References: <20260728114855.1323861-1-a@unstable.cc> MIME-Version: 1.0 X-Spam-Score: -0.2 (/) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-2.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Antonio Quartulli The by_transp_addr table is keyed on the peer's remote transport address, but the float rehash hashed bind->remote directly, while the two other sites that touch the table build a clean key first: ovp [...] Content analysis details: (-0.2 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.0 RCVD_IN_MSPIKE_H5 RBL: Excellent reputation (+5) [80.241.56.171 listed in wl.mailspike.net] 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from envelope-from domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-Headers-End: 1wogJA-0003Bp-28 Subject: [Openvpn-devel] [PATCH ovpn net v4 6/9] ovpn: hash floated peer by transport identity only X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Antonio Quartulli Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1871959147299112284 X-GMAIL-MSGID: 1871959147299112284 From: Antonio Quartulli The by_transp_addr table is keyed on the peer's remote transport address, but the float rehash hashed bind->remote directly, while the two other sites that touch the table build a clean key first: ovpn_peer_add_mp() and the lookup in ovpn_peer_get_by_transp_addr() both hash a sockaddr holding only family/address/port. For a link-local IPv6 peer, bind->remote carries sin6_scope_id (set from ipv6_iface_scope_id() when the endpoint is learned), and that field is folded into the jhash() over sizeof(struct sockaddr_in6). The lookup never sets sin6_scope_id, so after such a peer floats it is rehashed into a scope_id-dependent bucket that lookups (scope_id 0) never visit, making the peer unreachable through the by_transp_addr fallback. ovpn_peer_transp_match() only compares address and port, so the hash was keying on a field the match ignores. sin6_scope_id must stay in bind->remote because the TX path uses it as flowi6_oif, so it cannot just be cleared there. Instead build the hash key from family/address/port only, exactly like ovpn_peer_add_mp() and the lookup, so all three sites agree on the bucket. Fixes: f0281c1d3732 ("ovpn: add support for updating local or remote UDP endpoint") Signed-off-by: Antonio Quartulli --- drivers/net/ovpn/peer.c | 25 +++++++++++++++++++++---- 1 file changed, 21 insertions(+), 4 deletions(-) diff --git a/drivers/net/ovpn/peer.c b/drivers/net/ovpn/peer.c index 00971bbd3dcf..27fcc917c657 100644 --- a/drivers/net/ovpn/peer.c +++ b/drivers/net/ovpn/peer.c @@ -928,7 +928,10 @@ bool ovpn_peer_check_by_src(struct ovpn_priv *ovpn, struct sk_buff *skb, static void __ovpn_peer_hash_transp_addr(struct ovpn_peer *peer, const struct ovpn_bind *bind) { + struct sockaddr_storage sa = {}; struct hlist_nulls_head *nhead; + struct sockaddr_in6 *sa6; + struct sockaddr_in *sa4; size_t salen; lockdep_assert_held(&peer->ovpn->lock); @@ -944,12 +947,26 @@ static void __ovpn_peer_hash_transp_addr(struct ovpn_peer *peer, if (unlikely(hlist_unhashed(&peer->hash_entry_id))) return; + /* Build the hash key from the transport identity only + * (family/address/port), matching ovpn_peer_add_mp() and the lookup + * in ovpn_peer_get_by_transp_addr(). Hashing bind->remote directly + * would fold in sin6_scope_id (set on the float path but never by the + * lookup), scattering the peer into a bucket lookups cannot reach. + */ switch (bind->remote.in4.sin_family) { case AF_INET: - salen = sizeof(struct sockaddr_in); + sa4 = (struct sockaddr_in *)&sa; + sa4->sin_family = AF_INET; + sa4->sin_addr.s_addr = bind->remote.in4.sin_addr.s_addr; + sa4->sin_port = bind->remote.in4.sin_port; + salen = sizeof(*sa4); break; case AF_INET6: - salen = sizeof(struct sockaddr_in6); + sa6 = (struct sockaddr_in6 *)&sa; + sa6->sin6_family = AF_INET6; + sa6->sin6_addr = bind->remote.in6.sin6_addr; + sa6->sin6_port = bind->remote.in6.sin6_port; + salen = sizeof(*sa6); break; default: return; @@ -958,8 +975,8 @@ static void __ovpn_peer_hash_transp_addr(struct ovpn_peer *peer, /* remove old hashing (no-op if entry is not currently linked) */ hlist_nulls_del_init_rcu(&peer->hash_entry_transp_addr); /* re-add with current transport address */ - nhead = ovpn_get_hash_head(peer->ovpn->peers->by_transp_addr, - &bind->remote, salen); + nhead = ovpn_get_hash_head(peer->ovpn->peers->by_transp_addr, &sa, + salen); hlist_nulls_add_head_rcu(&peer->hash_entry_transp_addr, nhead); }